Real-time vulnerability trends from news, Mastodon, and Bluesky
Real-time vulnerability trends from news, Mastodon, and Bluesky
5,526
Tracked CVEs
266
News Articles
2,366
Mastodon Posts
5,770
Bluesky Posts
Vulnerability: CVE-2026-88779 is an unauthenticated denial-of-service vulnerability affecting Citrix NetScaler ADC and NetScaler Gateway, particularly impacting systems configured for SAML single sign-on. The flaw affects ADC versions before 14.1-73.41, 13.1-64.28, 14.1-73.41 FIPS, and 13.1-37.282, as well as Gateway versions before 14.1-73.41 and 13.1-64.28.
Trending: The vulnerability is receiving significant attention across security communities due to its high CVSS score of 8.7, unauthenticated attack vector, and lack of available workarounds, prompting urgent patching recommendations. Social media discussions emphasize the widespread nature of affected enterprise gateway configurations and the critical need for immediate updates to patched versions.
Vulnerability: Rejetto HFS versions 3.0.0 through 3.2.0 use a non-cryptographic Math.random() generator to derive session-cookie signing keys and disclose generator outputs to unauthenticated clients during login. A remote attacker can reconstruct the generator's state from login responses, forge valid administrator session cookies, and achieve remote code execution through the server_code configuration feature.
Trending: The vulnerability is receiving attention on security-focused social media platforms following its recent publication on July 13, 2026, with posts highlighting the critical nature of the flaw that allows attackers to steal administrator sessions and take full control of affected HFS servers.
Vulnerability: CVE-2023-28252 is an elevation of privilege vulnerability in the Windows Common Log File System (CLFS) Driver that allows attackers to gain elevated privileges on affected Windows systems.
Trending: The vulnerability is trending due to reports that the Brain Cipher threat group, which emerged in July 2024, is suspected of exploiting CVE-2023-28252 in their operations using a leaked build of LockBit Black ransomware.
Vulnerability: Payload, a free and open source headless content management system, contains an access control bypass in versions before 3.90.0 and canary versions before 4.0.0-canary.34. An attacker can submit requests to a specific update endpoint that modifies collection documents without enforcing collection or field-level access control when orderable is enabled on a collection or join field.
Trending: The vulnerability is receiving significant attention across security-focused social media platforms with a critical CVSS score of 9.8, with multiple cybersecurity news outlets and vulnerability tracking accounts sharing the disclosure shortly after its publication on October 6, 2026.
Vulnerability: Plane is an open-source project management tool that contains a Full Read Server-Side Request Forgery (SSRF) vulnerability in the "Add Link" feature prior to version 1.2.2. An authenticated attacker with general user privileges can send arbitrary GET requests to the internal network and exfiltrate sensitive data from internal services and cloud metadata endpoints.
Trending: The vulnerability is trending due to reports that the initial fix in version 1.2.2 was incomplete, with the SSRF vulnerability in work-item link unfurling remaining exploitable in version 1.3.1 GA release, allowing any authenticated project member to continue exploiting the flaw.
Vulnerability: CVE-2026-86360 is a critical flaw in Dell System Update (DSU) with a CVSS score of 9.6 that allows attackers to execute code with root privileges. Dell addressed this vulnerability along with four other bugs in DSU version 2.3.0.0.
Trending: The vulnerability is gaining attention due to its critical severity rating and the potential for remote code execution as root, prompting security advisories urging immediate patching of affected Dell System Update installations.
Vulnerability: Weak authorization in Microsoft Exchange Server allows an authenticated attacker to elevate privileges over a network.
Trending: CVE-2026-96940 is receiving attention on social media platforms with a HIGH severity rating of 8.8, following its publication on October 2, 2026.
Vulnerability: Plane, an open-source project management tool prior to version 1.4.0, contains hardcoded and publicly known SECRET_KEY and LIVE_SERVER_SECRET_KEY values in community deployment manifests that are not randomized by default setup scripts. This allows attackers with knowledge of these keys to forge Django-signed values to compromise accounts and sessions, or bypass live-service authentication on unchanged community deployments.
Trending: CVE-2026-105641 is receiving attention across social media platforms with a critical CVSS score of 9.8, with multiple security news outlets and infosec communities sharing alerts about the vulnerability on Bluesky and Mastodon.
Vulnerability: The Crayons plugin for SPIP before 3.5.0 contains a missing authorization vulnerability that allows unauthenticated attackers to modify arbitrary editable object fields by omitting the secu_ anti-forgery parameter in crayons_store.php. Attackers can chain this flaw to write malicious .html skeleton files, disclose sensitive configuration files, and execute arbitrary PHP code as the web-server user.
Trending: The vulnerability is receiving attention across social media platforms including Bluesky and Mastodon, with security researchers flagging it as critical with a CVSS score of 9.3-9.8 due to its severity and the ease with which unauthenticated attackers can exploit it to achieve remote code execution.
Vulnerability: CVE-2026-105845 is a SQL injection vulnerability in Payload, a free and open source headless content management system, affecting versions 3.0.0 before 3.88.0 and canary versions before 4.0.0-canary.27. Untrusted users who can query readable collections through dynamic filters or joins can exploit this vulnerability in the SQLite and Postgres adapters.
Trending: The vulnerability is receiving significant attention across social media platforms including Bluesky and Mastodon, with multiple security accounts sharing alerts about its critical severity rating of 9.8. The widespread coverage indicates active awareness in the infosec community regarding the need for users to update to patched versions.
Vulnerability: Smarty before version 4.5.8 and 5.x before 5.8.5 contains a code injection vulnerability in the extends:/multi-component template inheritance feature where the nocache_hash is not properly restored, allowing attackers to inject forged SmartyNocache markers that execute arbitrary PHP code for remote code execution.
Trending: The vulnerability is receiving significant attention across social media platforms with security researchers emphasizing its critical severity and urging immediate patching to versions 4.5.8 or 5.8.5, with proof-of-concept code reportedly available in vendor advisories.
Vulnerability: A supply chain attack was discovered in xz upstream tarballs starting with version 5.6.0, where malicious code was injected into the liblzma build process through obfuscated test files. This compromised library can intercept and modify data interactions for any software linked against it.
Trending: The vulnerability has attracted significant security community attention and analysis, with detailed technical breakdowns examining the sophisticated supply chain attack methodology used to compromise the widely-used xz compression library.
Vulnerability: CVE-2026-30242 is a Server-Side Request Forgery (SSRF) vulnerability in Plane, an open-source project management tool prior to version 1.2.3. The webhook URL validation insufficiently restricts internal network addresses, allowing workspace administrators to create webhooks pointing to private/internal networks and retrieve responses from those addresses.
Trending: The vulnerability is receiving attention following the disclosure of a subsequent bypass (EUVD-2026-92526) affecting version 1.4.0, where the initial fix was found to validate webhook IP addresses only at creation time rather than at delivery, allowing attackers to potentially circumvent the patch through timing-based attacks.
Vulnerability: CVE-2026-15307 is a critical vulnerability in Django 5.2 before 5.2.17 and 6.0 before 6.0.8 affecting GeoDjango spatial lookups. The vulnerability allows arbitrary file writing and remote code execution through unsafe parsing of spatial lookup values passed to the GDALRaster constructor, including untrusted input from Django admin query strings.
Trending: The vulnerability is trending as part of a batch of multiple Django CVEs (CVE-2026-15307, CVE-2026-15337, CVE-2026-15830, and CVE-2026-15920) being discussed in infosec communities, indicating coordinated disclosure or simultaneous discovery of multiple Django security issues.
Vulnerability: CVE-2026-103066 is an SQL Injection vulnerability in WP BASE Booking (wp-base-booking-of-appointments-services-and-events) that allows blind SQL injection attacks. The vulnerability affects WP BASE Booking versions through 6.4.0.
Trending: The vulnerability is receiving attention across social media platforms including Bluesky and Mastodon, with security news outlets like The Hacker Wire reporting on it as a high-severity issue (CVSS 8.5) and tagging it with infosec and cybersecurity hashtags.
Vulnerability: Plane, an open-source project management tool, contains an incomplete fix for a Server-Side Request Forgery (SSRF) vulnerability in work-item link unfurling prior to version 1.4.0. Authenticated project members can exploit this to make the server fetch attacker-selected internal targets, including cloud metadata endpoints, and read response bodies returned as link titles or favicons.
Trending: The vulnerability is being actively shared across social media platforms including Bluesky and Mastodon by security news outlets, with a CVSS score of 7.7 (High severity) being highlighted in multiple posts promoting awareness of the incomplete patch in the v1.3.1 GA release.
Vulnerability: Plane, an open-source project management tool prior to version 1.4.0, contains an authentication bypass vulnerability in its project invitation system. An attacker can enumerate pending invitations, register an account using an invited email address without verification, and gain unauthorized access to target workspaces and projects.
Trending: The vulnerability is being actively shared across security-focused social media platforms including Bluesky and Mastodon, with security news outlets highlighting its high severity rating (8.2) and the straightforward exploitation path it presents.
Vulnerability: Plane is an open-source project management tool that prior to version 1.4.0 contains a stored cross-site scripting (XSS) vulnerability in IntakeIssuePublicViewSet.create. Any authenticated user can plant arbitrary HTML in projects with published DeployBoards and intake enabled, which executes JavaScript and exfiltrates API tokens when clicked by project members or viewers.
Trending: CVE-2026-104979 is being shared across social media platforms including Bluesky and Mastodon with a CVSS score of 8.7 (High severity), indicating active awareness and discussion of this vulnerability in the infosec community.
Vulnerability: A critical OS command injection vulnerability exists in TOTOLINK X6000R firmware version 9.4.0cu.652_B20230116, located in the firmware_check function of /cgi-bin/cstecgi.cgi. Remote unauthenticated attackers can manipulate the file_name argument to execute arbitrary OS commands and gain full control of affected devices.
Trending: The vulnerability is receiving attention across social media platforms due to its critical severity rating and the ease of exploitation—remote attackers require no authentication to compromise devices. Security researchers are actively alerting the community to restrict interface access and monitor the vulnerable endpoint.
Vulnerability: Plane, an open-source project management tool prior to version 1.4.0, contains a server-side request forgery vulnerability in its OAuth avatar synchronization flow. The vulnerability allows attackers to fetch avatar URLs that redirect to internal-only resources without proper IP validation, enabling exfiltration of internally fetched content through the public assets API.
Trending: The vulnerability is receiving attention across security-focused social media platforms including Bluesky and Mastodon, with security news outlets like The Hacker Wire reporting on the high-severity issue (CVSS 7.6) and its availability in patched version 1.4.0.
Vulnerability: Plane, an open-source project management tool prior to version 1.4.0, contains a stored XSS vulnerability where authenticated low-privilege workspace members can upload malicious SVG files as attachments. When victims open the presigned URL to these files, embedded JavaScript executes in the application's security context, potentially leading to account takeover.
Trending: The vulnerability is receiving attention across security-focused social media platforms including Bluesky and Mastodon, with security researchers and news outlets highlighting its high severity rating (8.7) and the risk it poses to workspace administrators and other users who interact with uploaded files.
Vulnerability: Plane, an open-source project management tool prior to version 1.4.0, contains an authorization bypass vulnerability in its asset endpoints that allows workspace members to download assets from private projects and unauthenticated users to retrieve assets from unpublished or private projects when the asset UUID is known.
Trending: The vulnerability is being actively shared across security-focused social media platforms including Bluesky and Mastodon, with security news outlets like The Hacker Wire highlighting its high severity rating (7.5) and distribution through security hashtags and vulnerability tracking services.
Vulnerability: Plane is an open-source project management tool that prior to version 1.3.0 contains an authorization flaw in the ProjectMemberViewSet.partial_update method. Any project member, including users with the lowest GUEST role, can modify another project member's role, allowing guests to demote administrators and members and deny them project control.
Trending: The vulnerability is being actively shared across social media platforms including Bluesky and Mastodon with a high severity rating of 8.1, with security news outlets like The Hacker Wire highlighting the issue to the infosec community.
Vulnerability: Plane, an open-source project management tool prior to version 1.4.0, trusts unverified email addresses from Gitea OAuth and self-managed GitLab OAuth deployments without confirming ownership, allowing attackers to hijack existing user accounts by setting an OAuth identity's email to a victim's address and gaining unauthorized access.
Trending: The vulnerability is receiving attention across social media platforms due to its critical CVSS 9.1 severity rating and the account takeover risk it poses, with security-focused accounts actively sharing alerts and technical details about the flaw.
Vulnerability: Ghost, a Node.js content management system, contains a vulnerability in its bundled image processing library's SVG handling affecting versions 6.56.0 through 6.67.0. Staff users, including Contributors, could create a bookmark card for an attacker-controlled website to execute arbitrary commands on the Ghost server.
Trending: The vulnerability is receiving attention across security-focused social media platforms including Bluesky and Mastodon, with security news outlets like The Hacker Wire reporting on the high-severity issue (CVSS 8.8) and its fix in version 6.67.0.
Vulnerability: Ghost, a Node.js content management system, contains a stored script injection vulnerability affecting versions 2.1.0 through 6.64.0. Embedding URLs from attacker-controlled websites could result in untrusted scripts being stored in post content, potentially executing in the Ghost editor, published sites, and newsletter emails to compromise staff user admin sessions.
Trending: The vulnerability is being actively shared across social media platforms including Bluesky and Mastodon by security news outlets, with a CVSS score of 8.1 (High severity) and coverage from security research communities highlighting the risk to Ghost administrators.
Vulnerability: Ghost, a Node.js content management system, contains a privilege escalation vulnerability affecting versions 4.39.0 through 6.64.0. Staff users with permission to view staff invites could discover secret tokens of pending invites, including those for higher-privileged roles, allowing them to escalate their own privileges by accepting such invites.
Trending: The vulnerability is being actively shared across security-focused social media platforms including Bluesky and Mastodon, with multiple posts from security news outlets highlighting its high severity rating (7.5) and the privilege escalation risk it poses to Ghost installations.
Vulnerability: Penpot prior to version 2.18.0 contains a command injection vulnerability in its SVG exporter where attacker-controlled fill-color values are executed through child_process.exec, allowing arbitrary command execution with the exporter service's privileges. The vulnerability can be exploited by users with file editing permissions or through valid public share links to malicious files.
Trending: The vulnerability is receiving attention across security-focused social media platforms including Bluesky and Mastodon, where it is being flagged as a critical severity issue (CVSS 9.9) and shared within the infosec community with recommendations to update to version 2.18.0.
Vulnerability: CVE-2026-105697 is a critical command injection vulnerability in Langflow before version 1.10.3 that allows arbitrary OS command execution through the MCP stdio transport. Any user with access to MCP server settings or the MCP Tools component can inject malicious commands that execute on the Langflow host with the privileges of the Langflow process user, with exploitation possible without authentication on instances using the default LANGFLOW_AUTO_LOGIN=true configuration.
Trending: The vulnerability is receiving attention across security-focused social media platforms including Bluesky and Mastodon, where it has been flagged as a critical severity issue (CVSS 9.9) by security news outlets, driving awareness of the need to upgrade to patched versions 1.10.3 or later.
Vulnerability: Langflow prior to version 1.9.0 contains a Remote Code Execution (RCE) vulnerability that allows any authenticated user to execute arbitrary commands on the server by adding an MCP server with "Stdio" transport, due to unsanitized command input passed directly to bash with no validation or sandboxing.
Trending: The vulnerability is receiving attention across security-focused social media platforms including Bluesky and Mastodon, where it is being shared with a critical severity rating of 9.9, indicating widespread awareness in the infosec community.
Vulnerability: CVE-2026-45524 is a sandbox escape vulnerability in WifiPermissionsUtil.java caused by a missing permission check in the isSystem function. This vulnerability affects Tenda products and could lead to local escalation of privilege without requiring additional execution privileges or user interaction.
Trending: The vulnerability is receiving attention across social media platforms including Bluesky and Mastodon, where it has been shared with a CVSS score of 8.8 (High severity). The posts highlight the critical nature of the vulnerability due to its ease of exploitation and lack of user interaction requirements.
Vulnerability: An out-of-bounds write vulnerability due to integer overflow exists in the rw_t4t_update_file function of rw_t4t.cc, affecting Tenda products. This vulnerability could lead to local escalation of privilege without requiring additional execution privileges or user interaction.
Trending: The vulnerability is receiving attention across security-focused social media platforms including Bluesky and Mastodon, with security news outlets like The Hacker Wire reporting on it with a CVSS score of 7.8 (High severity). The posts highlight the critical nature of the flaw due to its ability to enable privilege escalation without user interaction.
Vulnerability: CVE-2026-49933 is a control-flow hijack vulnerability in the handle_le_monitor_device_event function of msft.cc affecting the privileged Bluetooth process, caused by an uninitialized pointer dereference that could lead to local escalation of privilege without requiring additional execution privileges or user interaction.
Trending: The vulnerability is being shared across security-focused social media platforms including Bluesky and Mastodon with a CVSS score of 7.8 (High severity), gaining attention from the infosec community through posts from security news aggregators.
Vulnerability: In multiple functions of MessageQueueBase.h, there is a possible out of bounds read due to an incorrect bounds check. This could lead to local escalation of privilege with no additional execution privileges needed.
Trending: The vulnerability is being shared across security-focused social media platforms including Bluesky and Mastodon with a CVSS score of 7.8 (High severity), gaining attention in the infosec community through posts from security news aggregators.
Vulnerability: CVE-2026-55266 is an out-of-bounds write vulnerability in the qsort function of libufdt_sysdeps_vendor.c caused by resource exhaustion. The vulnerability could lead to local escalation of privilege and requires no additional execution privileges or user interaction for exploitation.
Trending: The vulnerability is receiving attention across social media platforms including Bluesky and Mastodon, with security researchers and infosec communities sharing alerts about its high severity rating (7.8) and discussing its implications for affected systems.
Vulnerability: A memory safety issue exists in FilterCapturedPacket of snoop_logger.cc due to improper input validation, potentially allowing local escalation of privilege without requiring additional execution privileges or user interaction.
Trending: The vulnerability is receiving attention across security-focused social media platforms including Bluesky and Mastodon, with security researchers and news outlets sharing details about its high severity rating (7.8) and no-interaction exploitation requirements.
Vulnerability: In cfg2prop of btif_storage.cc, there is a possible out-of-bounds write due to a heap buffer overflow that could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.
Trending: CVE-2026-58835 is receiving attention across security-focused social media platforms including Bluesky and Mastodon, with posts highlighting its high severity rating (8.8) and the critical nature of the remote code execution risk without requiring user interaction or elevated privileges.
Vulnerability: CVE-2026-58841 is a permission bypass vulnerability in multiple functions of VirtualAudioControllerTest.java caused by a logic error that could lead to local escalation of privilege without requiring additional execution privileges or user interaction.
Trending: The vulnerability is gaining attention on social media platforms including Bluesky and Mastodon, with security researchers sharing alerts about its high severity rating (7.8) and the potential for privilege escalation attacks.
Vulnerability: CVE-2026-58854 is a memory corruption vulnerability caused by type confusion in multiple locations that could lead to local escalation of privilege without requiring additional execution privileges or user interaction.
Trending: The vulnerability is receiving attention across social media platforms including Bluesky and Mastodon, with security researchers and infosec communities sharing alerts about its high severity rating (7.8) and the fact that exploitation requires no user interaction.
Vulnerability: Joplin Server prior to version 3.7.7 contains a cross-site scripting vulnerability in its GET /shares/:id?resource_id= route that allows low-privileged users to publish malicious SVG attachments with empty titles. When victims open the public share, the embedded script executes in the application origin, potentially allowing attackers to access sensitive data and perform unauthorized actions with the victim's session.
Trending: The vulnerability is gaining attention in security circles due to its CVSS 7.6 severity rating and the ability to execute arbitrary scripts in the application origin, enabling CSRF attacks and unauthorized access to administrative data. Security researchers are actively discussing the vulnerability across social media platforms and recommending immediate updates to version 3.7.7 once patches are released.
Vulnerability: Camunda 7.24.0 before 7.24.15 contains an incorrect authorization vulnerability in the Admin web application's first-run setup endpoint, where SetupResource incorrectly determines setup availability by counting only direct members of the camunda-admin group rather than recognizing all configured administrators. An unauthenticated remote attacker can exploit this logic flaw to create a new administrator account and achieve account takeover with potential process deployment or script execution capabilities.
Trending: The vulnerability is receiving attention across social media platforms including Bluesky and Mastodon, with security researchers and infosec communities sharing alerts about the high-severity flaw (CVSS 8.1) and the availability of patches for affected versions.
Vulnerability: A Deserialization of Untrusted Data vulnerability in PressTigers Simple Event Planner (versions through 1.5.7) allows Object Injection attacks. This flaw enables attackers to inject malicious objects through unsafe deserialization processes.
Trending: The vulnerability is gaining attention across security-focused social media platforms including Bluesky and Mastodon, with security researchers and infosec communities sharing alerts about this high-severity issue (CVSS 8.8) and promoting awareness through hashtags like #CVE and #vulnerability.
Vulnerability: A stack-based buffer overflow vulnerability exists in Tenda AC5 firmware version 02.03.01.111_multi in the /goform/setWifi endpoint's Wifi Handler component. Remote attackers can exploit this vulnerability through manipulation of the wifiPwd argument to potentially execute arbitrary code.
Trending: The vulnerability is receiving attention across social media platforms due to reports of remote code execution capability and the absence of an available patch. Security researchers are recommending users restrict remote access and implement monitoring for active exploitation attempts.
Vulnerability: An unauthenticated SQL injection vulnerability exists in Porto Theme - Functionality versions 3.9.3 and earlier, allowing attackers to execute arbitrary SQL commands without authentication.
Trending: The vulnerability is receiving critical attention on social media due to its high severity (CVSS 9.3), with security researchers highlighting the unauthenticated nature of the exploit and noting that patch status remains unconfirmed, prompting immediate calls to restrict access.
Vulnerability: Dell OpenManage Integration with Microsoft Windows Admin Center versions prior to 3.7.0 contains an OS Command Injection vulnerability that allows a low-privileged remote attacker to achieve remote code execution.
Trending: The vulnerability is receiving attention across social media platforms with a high severity rating of 8.8, with security news outlets and infosec communities actively sharing information about the flaw on Bluesky and Mastodon.
Vulnerability: The MCP TypeScript SDK contains an OAuth credential binding vulnerability affecting versions 1.12.0 through 1.30.x and 2.0.x through 2.1.x. A malicious or compromised MCP server could redirect OAuth credentials (refresh tokens, client secrets, or signed assertions) to an attacker-controlled authorization server without user interaction, affecting applications using the SDK as an MCP client with certain OAuth provider configurations.
Trending: The vulnerability is receiving security community attention on social media platforms including Bluesky and Mastodon, with posts highlighting its high severity rating (7.5) and distribution through security news aggregators like The Hacker Wire.
Vulnerability: CVE-2026-105857 is a critical remote code execution vulnerability in Payload CMS's form-builder plugin (versions before 3.90.0 and canary versions before 4.0.0-canary.34) that allows attackers to execute code remotely on servers through crafted form submissions.
Trending: The vulnerability is receiving attention across social media platforms including Bluesky and Mastodon, where security researchers and news outlets are flagging it as a critical severity issue requiring immediate patching.
Vulnerability: CVE-2026-105858 is a remote code execution vulnerability in Payload, a free and open source headless content management system. Versions before 3.90.0 and canary versions before 4.0.0-canary.34 are affected when local authentication is enabled and no initial user has been created, allowing a crafted request to the public first-register operation to execute code remotely.
Trending: The vulnerability is receiving attention across social media platforms including Bluesky and Mastodon, with security researchers and infosec communities sharing alerts about the high-severity issue (CVSS 8.1) and directing users to patch information.
Vulnerability: Payload, a free and open source headless content management system, contains an SVG upload sanitization bypass in versions before 3.90.0 and canary versions before 4.0.0-canary.34 that allows malicious SVGs to execute attacker-controlled JavaScript when downloaded and opened by users.
Trending: The vulnerability is receiving attention across security-focused social media platforms including Bluesky and Mastodon, with posts highlighting its high severity rating (8.7) and distribution through security news outlets like The Hacker Wire.
Vulnerability: Payload, a free and open source headless content management system, contains a vulnerability in versions before 3.90.0 and canary versions before 4.0.0-canary.34 where authenticated users with upload management permissions can cause unintended file deletion outside the configured upload directory, resulting in data loss or service disruption.
Trending: The vulnerability is receiving attention across security-focused social media platforms including Bluesky and Mastodon, with security news outlets like The Hacker Wire reporting on the high-severity issue (CVSS 8.1) and available patches.