L/BLAB BOTSPUBLIC THREAT INTELLIGENCE NODE
CVE KNOWLEDGE BASE

Intelligence
Explorer.

Investigue vulnerabilidades por identificador, produto afetado ou descrição. Use severidade, CVSS e EPSS juntos para orientar a prioridade.

// THREAT ACTIVITY

Grupos & malware emergente

Atividade pública observada em leak sites e repositórios comunitários. Alegações de vítimas não representam confirmação independente de incidente.

RANSOMWARE GROUPSRECENT CLAIMS
lamashtu10 menções
qilin10 menções
krybit9 menções
thegentlemen9 menções
Booba Project7 menções
Storm7 menções
akira7 menções
incransom6 menções
rhysida5 menções
Wallstreet3 menções
INFOSTEALERSOBSERVED

Sem famílias correlacionadas no recorte recente.

RECENT RANSOMWARE CLAIMSRANSOMWARE.LIVE
qilinChadwick SwitchboardsAU · Manufacturing · 2026-10-04
qilinEmserES · Manufacturing · 2026-10-04
qilinCotesmaCL · Manufacturing · 2026-10-04
direwolfSoftruckBR · Technology · 2026-10-04
StormNipigon District Memorial HospitalCA · Healthcare · 2026-10-04
krybiteuroditel.comFR · Technology · 2026-10-04
krybitsuperpack.com.coCO · Retail & E-Commerce · 2026-10-04
krybitdaralteb.comIR · Healthcare · 2026-10-04
qilinUnident GroupUS · Other · 2026-10-04
qilinMutsumi GroupJP · Manufacturing · 2026-10-04
thegentlemenCenter State EngineeringUS · Manufacturing · 2026-10-04
qilinGenesis Credit ManagementUS · Financial Services · 2026-10-03
MALWARE FAMILIES / 7 DAYSMALWAREBAZAAR
Configure a Auth-Key gratuita do abuse.ch para habilitar detecções recentes do MalwareBazaar.

FONTES: RANSOMWARE.LIVE + MALWAREBAZAAR / ABUSE.CH · CACHE 1H

11641 REGISTROS ENCONTRADOSFEED 2026-09-29
CVE-2026-71465LOW

RunAdHocCommand.build_args() appends limit as bare positional (args.append(limit)) instead of using args.extend(['-l', limit]) like RunJob. A limit beginning with - is parsed as an ansible CLI option. Currently limited to short-circuit flags (--version, --help) since injected element displaces required pattern positional. Would escalate if ansible-core ever defaults pattern.

AFFECTED SURFACEProduct not specified
CVSS 3.1EPSS 0.21%
CVE-2026-71464LOW

LaunchConfigurationBaseSerializer.scm_branch has no validate_scm_branch() leading-dash check, unlike Project/JobTemplate/JobLaunch serializers. Schedule and WFJT Node accept --upload-pack=/bin/id as scm_branch. Currently blocked at runtime by jobs.py:1502 ValueError check (defense-in-depth), but the API validation gap means sole reliance on a task-layer guard. Refactoring that guard away would promote this to RCE.

AFFECTED SURFACEProduct not specified
CVSS 3.1EPSS 0.21%
CVE-2026-71463LOW

Notification template Jinja AST whitelist only inspects static Getattr nodes. Dynamic subscripts (job['job'+'_env']) and {% if job.id > 100 %} conditional gating bypass both the AST check and the test-render (stub has small job.id). At runtime, the gated branch executes and exceptions write full tracebacks into notification body, which is POSTed to attacker-controlled webhook URL. Leaks install paths, Python version, source line numbers.

AFFECTED SURFACEProduct not specified
CVSS 2.7EPSS 0.27%
CVE-2026-71462MEDIUM

StringListPathField.to_internal_value() calls os.path.exists() on unbounded user-supplied paths. 200 vs 400 response reveals existence of arbitrary absolute paths on the controller-web pod. Tenant superuser can confirm /etc/tower/SECRET_KEY, k8s service-account token, receptor sockets, ConfigMap mount points. Mainly impactful on managed AAP (ansiblecloud.com) where tenant admin != host admin.

AFFECTED SURFACEProduct not specified
CVSS 4.1EPSS 0.26%
CVE-2026-71461MEDIUM

HostList.list() catches bare Exception and returns str(e) verbatim. Via host_filter, any authenticated user triggers Django FieldError (leaking complete Host model relation graph including internal reverse accessors) or PostgreSQL DataError (leaking raw database error strings). Two primitives: credential__search=x dumps ORM schema, name__regex=[bad reflects PostgreSQL errors.

AFFECTED SURFACEProduct not specified
CVSS 4.3EPSS 0.21%
CVE-2026-71460MEDIUM

/api/v2/config/ is protected only by IsAuthenticated. license_info (account_number, subscription_id, pool_id, sku, support_level, instance counts) returned to any authenticated user. The superuser/auditor gate only covers project_base_dir/project_local_paths/custom_virtualenvs, not license_info. Enables social engineering against Red Hat support and estate sizing reconnaissance.

AFFECTED SURFACEProduct not specified
CVSS 4.3EPSS 0.22%
CVE-2026-71459MEDIUM

JobJobEventsChildrenSummary view has no model/parent_model. ModelAccessPermission.check_get_permissions() falls through (returns True) for any authenticated user. The view uses raw get_object_or_404(Job, pk) without DRF object-level permission check. Zero-privilege user reads event tree structure, event_processing_finished status, and enumerates Job IDs platform-wide via 200/404 oracle. Sibling endpoint /jobs/{id}/job_events/ correctly returns 403.

AFFECTED SURFACEProduct not specified
CVSS 5.0EPSS 0.28%
CVE-2026-71458MEDIUM

URLModificationMiddleware resolves named-URL lookups against unfiltered Model.objects before RBAC. The 403→404 shim only rewrites 403 responses, leaving the pk=0 miss path with a different 404 detail string. Differential "Not found." vs "No <Model> matches..." reveals whether a named resource (org, credential, inventory, host) exists anywhere on the platform. Enables cross-tenant internal hostname enumeration.

AFFECTED SURFACEProduct not specified
CVSS 5.0EPSS 0.30%
CVE-2026-63132CRITICAL

OpenBao is an open source identity-based secrets management system. Prior to 2.6.0, OpenBao's handleLogicalRecovery path in http/logical.go compared the highly privileged recovery token with ordinary string equality. A remote unauthenticated attacker able to make repeated recovery mode requests and measure response timing could infer the recovery token. The recovered token could then authorize recovery mode operations that read or modify OpenBao data. This issue is fixed in version 2.6.0.

AFFECTED SURFACEProduct not specified
CVSS 9.2EPSS 0.50%
CVE-2026-63131MEDIUM

OpenBao is an open source identity-based secrets management system. Prior to 2.6.0, OpenBao's vault/policy/acl.go could evaluate a broader wildcard ACL grant before more-specific trailing-wildcard ACL paths with capabilities = ["deny"] for a LIST operation. When a parent path permitted LIST and a child path was denied, the trailing-slash lookup could therefore allow listing the denied path. Other operation types are outside the repository advisory's affected scope. This issue is fixed in version 2.6.0.

AFFECTED SURFACEProduct not specified
CVSS 6.0EPSS 0.35%
CVE-2026-61814HIGH

Jawn is an open source JSON parser. Prior to 1.7.0, Jawn's AsyncParser can perform quadratic work when a single JSON token is delivered across many small chunks because each absorb call rescans the incomplete token from the start. A remote attacker who controls untrusted JSON input and its chunk sizes can exhaust CPU resources and cause denial of service in applications using AsyncParser. This issue is fixed in version 1.7.0.

AFFECTED SURFACEProduct not specified
CVSS 7.5EPSS 0.57%
CVE-2026-61695HIGH

Wire provides gRPC and protocol buffers for Android, Kotlin, Swift, and Java. Prior to 6.4.1 and 7.0.0-alpha04, Wire's Swift runtime ProtoReader.skipGroup(expectedEndTag:unknownFieldsWriter:) accepts a negative length for a LENGTH_DELIMITED field inside an unknown START_GROUP field. ProtoReader.readData() forwards the negative count to ReadBuffer.readData(count:), whose upper-bound-only check permits the value to reach Foundation Data(bytes:count:) and trigger an unrecoverable process trap instead of a catchable ProtoDecoder.Error. Any Swift process decoding untrusted protobuf bytes can be crashed without authentication, user interaction, or knowledge of the target schema. This issue is fixed in versions 6.4.1 and 7.0.0-alpha04.

AFFECTED SURFACEProduct not specified
CVSS 7.5EPSS 0.58%
CVE-2026-59990HIGH

Jawn is an open source JSON parser. Prior to 1.7.0, Jawn parse methods accept arbitrarily deep JSON array and object nesting without a depth limit, allowing a remote attacker who can submit untrusted JSON to grow parser contexts until the JVM heap is exhausted. The resulting java.lang.OutOfMemoryError is a fatal Scala error that is not ordinarily handled by scala.util.Try or cats.effect.IO, causing denial of service. This issue is fixed in version 1.7.0.

AFFECTED SURFACEProduct not specified
CVSS 7.5EPSS 0.62%
CVE-2026-55632MEDIUM

GoCD is a continuous deliver server. From 20.2.0 until 26.1.0, the internal pipeline structure API used for autocompletion while editing pipeline, template, environment, and user-preference configuration returns its users-and-roles mode to regular authenticated users without requiring an administrator role. A lower-privileged user can enumerate configured user names and available role names, which can facilitate attacks against those users. The response does not reveal which roles are assigned to each user, and the endpoint cannot modify data. This issue is fixed in version 26.1.0.

AFFECTED SURFACEProduct not specified
CVSS 4.3EPSS 0.29%
CVE-2026-55456ANALYSIS

Rejected reason: This CVE is a duplicate of another CVE.

AFFECTED SURFACEProduct not specified
CVSS N/DEPSS 0.00%
CVE-2026-52744MEDIUM

GoCD is a continuous deliver server. From 20.2.0 until 26.1.0, the internal GoCD UI fetch-artifact auto-suggestion API at /go/api/internal/pipelines/**/upstream does not adequately authorize access to upstream dependency data. An authenticated user can retrieve inter-pipeline dependency hierarchy details and user-defined pipeline, stage, job, and artifact plugin reference names that the user cannot otherwise view in the UI. The endpoint is read-only and does not permit modification of pipeline data. This issue is fixed in version 26.1.0.

AFFECTED SURFACEProduct not specified
CVSS 5.3EPSS 0.43%
CVE-2026-91775HIGH

LimeSurvey fails to safely encode attacker-controlled content from a crafted .lss survey file when displaying import warnings, resulting in XSS in the administrative interface.

AFFECTED SURFACEProduct not specified
CVSS 7.4EPSS 0.38%
CVE-2026-88840MEDIUM

BusyBox TLS get_client_hello() reads past the end of the input buffer when parsing a truncated ClientHello message.

AFFECTED SURFACEProduct not specified
CVSS 5.3EPSS 0.21%
CVE-2026-88839MEDIUM

BusyBox passwd/group tokenize() references a stale endpoint pointer after trimming, causing an out-of-bounds write of heap pointers.

AFFECTED SURFACEProduct not specified
CVSS 6.7EPSS 0.12%
CVE-2026-88837MEDIUM

BusyBox httpd treats yescrypt ($y$) password hashes as plaintext during Basic Authentication, inverting the authentication check.

AFFECTED SURFACEProduct not specified
CVSS 6.5EPSS 0.27%
CVE-2026-88835MEDIUM

BusyBox dpkg read_package_field() steps past a NUL terminator on malformed .deb packages, causing an out-of-bounds heap read.

AFFECTED SURFACEProduct not specified
CVSS 6.1EPSS 0.12%
CVE-2026-88831MEDIUM

BusyBox httpd IP deny rules with invalid CIDR prefix lengths fail open, leaving a parsed IP with a zeroed mask so the rule matches no clients.

AFFECTED SURFACEProduct not specified
CVSS 5.3EPSS 0.24%
CVE-2026-86938HIGH

A DLL hijacking vulnerability in the FileMaker Pro installer for Windows allowed a local user to execute arbitrary code with elevated administrator privileges by placing a malicious DLL file in the installer directory. This vulnerability is addressed in FileMaker Pro version 26.0.3.

AFFECTED SURFACEProduct not specified
CVSS 7.3EPSS 0.10%
CVE-2026-86934CRITICAL

An authorization bypass vulnerability in the FileMaker Server Web Publishing Engine allowed requests containing an extended privilege header to bypass the disabled Custom Web Publishing with XML setting and access the XML Web Publishing interface. This vulnerability is addressed in FileMaker Server version 26.0.3.

AFFECTED SURFACEProduct not specified
CVSS 9.1EPSS 0.33%