#CVE-2026
Incident Report: CVE-2026-LGTM

nesbitt.io/2026/06/26/i...
Incident Report: CVE-2026-LGTM
A series of unfortunate agents.
nesbitt.io
June 26, 2026 at 10:58 AM
CVE-2026-0573, CVE-2027-0420, CVE-2025-1152124
March 21, 2025 at 6:02 PM
CISA has confirmed two bugs in Citrix NetScaler are being exploited in active cyberattacks, CVE-2026-88771 and CVE-2026-88772, in a rare weekend drop of security news. www.cisa.gov/known-exploi...

Citrix has a support base article, confirming exploitation. support.citrix.com/support-home...
September 27, 2026 at 7:58 PM
yay, my 13th (14th?) chrome cve!!
chromereleases.googleblog.com/2026/07/stab...
July 30, 2026 at 10:57 AM
microsoft hat es fertig gebracht eine remote code execution lücke mit dem cve-score von 8,8 IN NOTEPAD REINZUBASTELN WEIL SIE ES AI-IFIZIERT HABEN?!
February 11, 2026 at 2:16 PM
🎉 Go 1.26.1 and 1.25.8 are released!

🔏 Security: Includes security fixes for the standard library (CVE-2026-25679, CVE-2026-27137, CVE-2026-27138, CVE-2026-27139, CVE-2026-27142).

📢 Announcement: groups.google.com/g/golang-ann...

📦 Download: go.dev/dl/#go1.26.1

#golang
March 6, 2026 at 1:19 AM
🔴 CVE-2026-55083 - Critical (9.1)

DHIS2 is a flexible information system for data capture, management, validation, analytics and vi...

https://www.thehackerwire.com/vulnerability/CVE-2026-55083/

#infosec #cybersecurity #CVE #vulnerability #security #patchstack
October 1, 2026 at 7:31 PM
🟠 CVE-2026-55230 - High (8.7)

Vvveb is a powerful and easy to use CMS with page builder to build websites, blogs or ecommerce s...

https://www.thehackerwire.com/vulnerability/CVE-2026-55230/

#infosec #cybersecurity #CVE #vulnerability #security #patchstack
October 1, 2026 at 7:31 PM
vulnerability in SSH yaaay

nvd.nist.gov/vuln/detail/...
NVD - CVE-2026-55200
nvd.nist.gov
June 24, 2026 at 4:56 PM
beautiful women called CVE-2026-22774 in my dms
January 15, 2026 at 8:54 PM
Ach, diese Ansammlung aus Plugins und Themes, auch bekannt als WordPress, hat mal wieder irgendwelche Wehwehchen. 😂
Attackers Exploit WordPress CVE-2026-87902 Within Hours of Disclosure
Attackers are exploiting WordPress CVE-2026-87902 to include pearcmd.php and write PHP files when specific theme and server conditions are met.
thehackernews.com
September 24, 2026 at 6:35 PM
"the kernel.org CNA has CVE-2026-100000 reserved"

🍾

/ @gregkh
September 25, 2026 at 1:30 PM
A timeline of Citrix NetScaler CVE-2026-88771, from the CVE reservation on Sep 10 to public disclosure on Sep 27, including the exploitation attempts GreyNoise observed on Sep 24.

🔗 Full analysis: www.greynoise.io/blog/swarmin...
September 29, 2026 at 3:02 PM
CVE-2026-20841: Improper neutralization of special elements used in a command ('command injection') in Windows Notepad App allows an unauthorized attacker to execute code over a network.
www.cve.org/CVERecord?id...

Bild via icy.wyvern.rip/notes/ail8j9...
February 11, 2026 at 10:14 AM
🟠 CVE-2026-97297 - High (7.6)

Subscriber Broken Access Control in Gratisfaction <= 4.6.3 versions.

https://www.thehackerwire.com/vulnerability/CVE-2026-97297/

#infosec #cybersecurity #CVE #vulnerability #security #patchstack
October 1, 2026 at 4:32 PM
yay i got my 10th chrome cve!!
i wrote a pretty fun patch for this one too
chromereleases.googleblog.com/2026/03/stab...
March 12, 2026 at 12:08 PM
Microsoft Threat Intelligence identified and tracked exploitation of CVE-2026-73570, an unauthenticated OS command injection vulnerability affecting internet-facing mail servers that enabled compromise without authentication or user interaction. msft.it/63324aYk4n
Unauthenticated command injection on internet-facing mail servers: tracking CVE-2026-73570 | Microsoft Security Blog
Microsoft Threat Intelligence examines CVE-2026-73570 exploitation in Zimbra, including observed attack paths, detection opportunities, and mitigation guidance.
msft.it
September 30, 2026 at 4:35 PM
🟠 CVE-2026-68496 - High (7.5)

The Smile parser in FasterXML jackson-dataformats-binary never invokes StreamReadConstraints.vali...

https://www.thehackerwire.com/vulnerability/CVE-2026-68496/

#infosec #cybersecurity #CVE #vulnerability #security #patchstack
October 1, 2026 at 7:01 PM
Linux is most secure OS. Yes. It's perfectly safe…

- Dirty Cow (CVE-2016-5195)
- Dirty Pipe (CVE-2022-0847)
- io_uring UAF (CVE-2022-2602)
- Copy Fail (CVE-2026-31431)
- Dirty Frag (CVE-2026-43284
- Fragnesia (CVE-2026-46300)

… so you have that many methods to recover your root password. 😂
May 14, 2026 at 6:32 PM
Excellent article en français sur la faille Dirty Frag aka la double CVE-2026-43284 et CVE-2026-43500 !
Je vous recommande grandement sa lecture !

blog.marcfredericgomez.fr/dirty-frag-c...

#Linux #LPE #DirtyFrag
Dirty Frag (CVE-2026-43284 et CVE-2026-43500) – Blog de Marc Frédéric GOMEZ
blog.marcfredericgomez.fr
May 9, 2026 at 7:34 AM
🟠 CVE-2026-79899 - High (7.9)

Fortra BoKS Manager contains an insecure temporary file vulnerability in bccgethostcert. The util...

https://www.thehackerwire.com/vulnerability/CVE-2026-79899/

#infosec #cybersecurity #CVE #vulnerability #security #patchstack
October 1, 2026 at 5:04 PM
two chrome cves this month, yay!
chromereleases.googleblog.com/2026/04/stab...
April 8, 2026 at 9:37 PM
🟠 CVE-2026-68495 - High (7.5)

The CBOR parser in FasterXML jackson-dataformats-binary never invokes StreamReadConstraints.valid...

https://www.thehackerwire.com/vulnerability/CVE-2026-68495/

#infosec #cybersecurity #CVE #vulnerability #security #patchstack
October 1, 2026 at 7:01 PM
🟠 CVE-2026-95588 - High (8.6)

Unauthenticated Arbitrary File Deletion in AcyMailing SMTP Newsletter <= 11.0.5 versions.

https://www.thehackerwire.com/vulnerability/CVE-2026-95588/

#infosec #cybersecurity #CVE #vulnerability #security #patchstack
October 1, 2026 at 5:04 PM