L/BLAB BOTSPUBLIC THREAT INTELLIGENCE NODE
CVE KNOWLEDGE BASE

Intelligence
Explorer.

Investigue vulnerabilidades por identificador, produto afetado ou descrição. Use severidade, CVSS e EPSS juntos para orientar a prioridade.

// THREAT ACTIVITY

Grupos & malware emergente

Atividade pública observada em leak sites e repositórios comunitários. Alegações de vítimas não representam confirmação independente de incidente.

RANSOMWARE GROUPSRECENT CLAIMS
lamashtu10 menções
qilin10 menções
krybit9 menções
thegentlemen9 menções
Booba Project7 menções
akira7 menções
Storm6 menções
incransom6 menções
rhysida5 menções
Wallstreet3 menções
INFOSTEALERSOBSERVED

Sem famílias correlacionadas no recorte recente.

RECENT RANSOMWARE CLAIMSRANSOMWARE.LIVE
emperadorOMUR HIRDAVAT LTDTR · Manufacturing · 2026-10-04
qilinChadwick SwitchboardsAU · Manufacturing · 2026-10-04
qilinEmserES · Manufacturing · 2026-10-04
qilinCotesmaCL · Manufacturing · 2026-10-04
direwolfSoftruckBR · Technology · 2026-10-04
StormNipigon District Memorial HospitalCA · Healthcare · 2026-10-04
krybiteuroditel.comFR · Technology · 2026-10-04
krybitsuperpack.com.coCO · Retail & E-Commerce · 2026-10-04
krybitdaralteb.comIR · Healthcare · 2026-10-04
qilinUnident GroupUS · Other · 2026-10-04
qilinMutsumi GroupJP · Manufacturing · 2026-10-04
thegentlemenCenter State EngineeringUS · Manufacturing · 2026-10-04
MALWARE FAMILIES / 7 DAYSMALWAREBAZAAR
Configure a Auth-Key gratuita do abuse.ch para habilitar detecções recentes do MalwareBazaar.

FONTES: RANSOMWARE.LIVE + MALWAREBAZAAR / ABUSE.CH · CACHE 1H

11641 REGISTROS ENCONTRADOSFEED 2026-09-29
CVE-2026-95845HIGH

Moquette is a lightweight Java MQTT broker. Prior to 0.18.1, the broker does not enforce a maximum length for pending per-session message queues. When a fast publisher sends messages to a slow subscriber whose in-flight window is full, queued messages can accumulate without bound in memory or persistent storage. Remote clients can use this condition to exhaust broker resources and cause a denial of service. This issue is fixed in version 0.18.1.

AFFECTED SURFACEmoquette moquette
CVSS 8.7EPSS 0.36%
CVE-2026-95844HIGH

Moquette is a lightweight Java MQTT broker. Prior to 0.18.1, Moquette does not limit the depth of topic names and topic filters before processing them through recursive CTrie insertion and matching operations. A remote client can publish or subscribe with a deeply nested topic, causing a StackOverflowError that disrupts session processing and can deny service to broker clients. This issue is fixed in version 0.18.1.

AFFECTED SURFACEmoquette moquette
CVSS 8.7EPSS 0.36%
CVE-2026-95843HIGH

Moquette is a lightweight Java MQTT broker. Prior to 0.18.1, PostOffice.subscribe parses a shared-subscription filter through SharedSubscriptionUtils.extractShareName before validating the complete $share/{shareName}/{topicFilter} structure. A remote client can send a filter such as $share/grp without a topic-filter portion, causing a StringIndexOutOfBoundsException while calculating the share name. The exception terminates command handling on the shared session event loop and can deny service to other client sessions assigned to that loop. This issue is fixed in version 0.18.1.

AFFECTED SURFACEmoquette moquette
CVSS 8.7EPSS 0.43%
CVE-2026-95842HIGH

Moquette is a lightweight Java MQTT broker. Prior to 0.18.1, SessionEventLoop.run catches only InterruptedException, and SessionEventLoopGroup does not restart a terminated loop. An MQTT command that raises an uncaught exception can terminate an event loop shared by multiple client sessions, preventing every co-located client from processing PUBLISH, SUBSCRIBE, PUBACK, and other commands. An attacker can select client IDs that map across the available loops to disrupt session processing for the entire broker. This issue is fixed in version 0.18.1.

AFFECTED SURFACEmoquette moquette
CVSS 8.7EPSS 0.43%
CVE-2026-93349HIGH

Frictionless before 5.19.1 contains an OS command injection vulnerability in the explore console command that allows an attacker who supplies a crafted Data Package descriptor to execute arbitrary operating system commands as the user who explores it. Attackers can place shell metacharacters in resource path values within a datapackage.json descriptor, which are passed unsanitized to os.system through a shell, causing arbitrary command execution in the victim's security context when they run the explore command against the untrusted package. This vulnerability was also addressed in version 5.20.0rc2 of the pre-release branch.

AFFECTED SURFACEProduct not specified
CVSS 8.6EPSS 2.12%
CVE-2026-88832HIGH

BusyBox romfs volume ID parsing uses unbounded strlen on attacker-controlled metadata, causing a heap buffer overflow when processing crafted filesystem images.

AFFECTED SURFACEProduct not specified
CVSS 7.3EPSS 0.13%
CVE-2026-88830HIGH

A unit confusion in BusyBox TLS Montgomery reduction buffer allocation causes a pre-authentication heap buffer overflow when processing a crafted ClientKeyExchange message.

AFFECTED SURFACEProduct not specified
CVSS 7.5EPSS 0.35%
CVE-2026-85724CRITICAL

Moquette is a lightweight Java MQTT broker. Prior to 0.18.1, when pattern-based ACL rules are configured, AuthorizationsCollector.canDoOperation substitutes client ID and username values directly into rules containing %c or %u and then treats the result as an MQTT topic filter. A client that uses + or # in either identity can broaden the substituted filter and gain cross-tenant read and write access. A # identity can also produce an invalid filter that triggers a NullPointerException in Topic.match and disrupts session processing. This issue is fixed in version 0.18.1.

AFFECTED SURFACEmoquette moquette
CVSS 9.6EPSS 0.27%
CVE-2026-6669MEDIUM

Missing upper bound on the key derivation iteration count accepted during SCRAM authentication to a backend server in PgBouncer through 1.25.2 allows a malicious or compromised PostgreSQL backend to cause uncontrolled CPU consumption in PgBouncer. The resulting key derivation cannot be interrupted in frontend builds such as PgBouncer. Because PgBouncer serves all clients from a single process, one backend can in this way stop it from serving traffic for every other database and client it is pooling, so the failure of a single backend is not contained.

AFFECTED SURFACEProduct not specified
CVSS 5.9EPSS 0.31%
CVE-2026-6668HIGH

Integer overflow in the packet buffer growth logic in PgBouncer through 1.25.2 allows an unauthenticated remote attacker to cause a denial of service. Sufficiently large input makes the buffer size computation overflow, leaving the growth loop unable to terminate. Because PgBouncer serves all clients from a single process, this saturates a CPU core and stalls every pooled connection until the process is killed. Both unauthenticated and authenticated code paths can reach the overflow.

AFFECTED SURFACEProduct not specified
CVSS 7.5EPSS 0.40%
CVE-2026-19888HIGH

Missing validation of a mandatory attribute in the SCRAM client-final-message parser in PgBouncer through 1.25.2 allows an unauthenticated remote attacker to crash the process. A malformed message can make the parser report success while leaving a required value unset, which is then dereferenced as a NULL pointer. The crash occurs before any credential is verified, so no valid account is required. Because PgBouncer serves all clients from a single process, this terminates every pooled connection.

AFFECTED SURFACEProduct not specified
CVSS 7.5EPSS 0.39%
CVE-2025-63564CRITICAL

SQL injection vulnerability in Moodle Socialwall plugin v.3.0 through v.3.3 allows an attacker to execute arbitrary code via crafted HTTP requests

AFFECTED SURFACEProduct not specified
CVSS 9.8EPSS 0.51%
CVE-2026-96675MEDIUM

alsa-lib through 1.2.16.1 contains a denial of service vulnerability in the multi PCM plugin that fails to validate sparse binding indices before array access. Attackers can supply a malicious ALSA configuration file with sparse bindings to trigger an out-of-bounds array read and assertion failure, causing the application to abort.

AFFECTED SURFACEProduct not specified
CVSS 4.8EPSS 0.11%
CVE-2026-96674MEDIUM

alsa-lib through 1.2.16.1 computes combined topology element size using 32-bit arithmetic in src/topology/ctl.c, allowing integer overflow that defeats bounds checks. Attackers can supply crafted topology files that wrap size calculations, causing the decoder to read beyond the topology buffer and potentially leak sensitive data or crash the application.

AFFECTED SURFACEProduct not specified
CVSS 4.8EPSS 0.11%
CVE-2026-96673HIGH

Photoview through 2.4.0 contains an SQL injection vulnerability in the album download route that allows unauthenticated attackers to inject SQL by manipulating the album_id path segment. Attackers can supply crafted SQL expressions in the album_id parameter to extract arbitrary data from the database using time-based or blind injection techniques.

AFFECTED SURFACEProduct not specified
CVSS 8.7EPSS 0.42%
CVE-2026-96672MEDIUM

Frappe ERPNext versions before 16.34.1 fail to validate that Financial Report Template calculation_formula values reference whitelisted methods before passing them to frappe.call(). Accounts Managers can supply arbitrary dotted Python paths to invoke non-whitelisted internal server-side methods and read their return values.

AFFECTED SURFACEProduct not specified
CVSS 5.3EPSS 0.22%
CVE-2026-93769HIGH

HumHub 1.18.5 is affected by a stored cross-site scripting (XSS) vulnerability that allows any user holding the delegated, non-system-administrator Manage Users permission (admin_manage_users) to inject persistent HTML/JavaScript into a Profile Field Category title.

AFFECTED SURFACEProduct not specified
CVSS 7.2EPSS 0.28%
CVE-2026-79310HIGH

webpy web.py 0.76 is vulnerable to server-side template injection (SSTI). The template engine can be tricked into executing attacker-controlled template code that built-in security checks are designed to reject. When an application precompiles templates from a directory the attacker can write to and later renders them through the precompiled template loader, the sandbox is bypassed and the attacker's code runs, resulting in arbitrary Python code execution and OS command execution on the server.

AFFECTED SURFACEProduct not specified
CVSS 8.5EPSS 0.72%
CVE-2026-79306MEDIUM

CyberPanel v1.9.1 contains a path traversal vulnerability in the compress method exposed through the /filemanager/controller endpoint. An authenticated remote attacker with ownership of any configured domain can supply absolute or otherwise out-of-scope file paths in the listOfFiles JSON property, together with attacker-controlled basePath and compressedFileName values, in a method=compress request. Because the application validates only domain ownership and does not canonicalize or restrict these paths to the authorized site directory, the backend appends them to zip or tar archive commands and executes them as the website externalApp user, allowing disclosure of arbitrary readable files through the generated archive.

AFFECTED SURFACEProduct not specified
CVSS 6.5EPSS 0.48%
CVE-2026-79304MEDIUM

CyberPanel 1.9.1 contains a path traversal vulnerability in the readFileContents method of the /filemanager/controller endpoint. An authenticated remote attacker with ownership of any configured domain can supply an arbitrary absolute or out-of-scope path in the fileName JSON property. Because authorization validates only domainName and does not canonicalize or restrict fileName to that domain's home directory, the application returns the contents of files readable by the CyberPanel execution identity.

AFFECTED SURFACEProduct not specified
CVSS 6.5EPSS 0.54%
CVE-2026-6327MEDIUM

IBM Concert 1.0.0 through 3.0.0 could allow an unauthorized user to inject data into log messages due to improper neutralization of special elements when written to log files.

AFFECTED SURFACEibm concertlinux linux kernel
CVSS 4.3EPSS 0.17%
CVE-2026-4921LOW

IBM Guardium Data Protection 12.2 could allow an administrative user to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system.

AFFECTED SURFACEProduct not specified
CVSS 2.7EPSS 0.19%
CVE-2026-3626MEDIUM

IBM Concert 1.0.0 through 3.0.0 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system.

AFFECTED SURFACEibm concertlinux linux kernel
CVSS 5.3EPSS 0.24%
CVE-2026-19267MEDIUM

IBM Financial Transaction Manager (FTM) for RedHat OpenShift is vulnerable to missing authentication on the Business Rules Manager commands REST endpoint (`CommandsResource.java:31`). A local actor can invoke unauthenticated commands to cause resource exhaustionand halt business-rule management functions.

AFFECTED SURFACEProduct not specified
CVSS 6.2EPSS 0.12%