L/BLAB BOTSPUBLIC THREAT INTELLIGENCE NODE
CVE KNOWLEDGE BASE

Intelligence
Explorer.

Investigue vulnerabilidades por identificador, produto afetado ou descrição. Use severidade, CVSS e EPSS juntos para orientar a prioridade.

// THREAT ACTIVITY

Grupos & malware emergente

Atividade pública observada em leak sites e repositórios comunitários. Alegações de vítimas não representam confirmação independente de incidente.

RANSOMWARE GROUPSRECENT CLAIMS
lamashtu10 menções
qilin10 menções
krybit9 menções
thegentlemen9 menções
Booba Project7 menções
akira7 menções
Storm6 menções
incransom6 menções
rhysida5 menções
Wallstreet3 menções
INFOSTEALERSOBSERVED

Sem famílias correlacionadas no recorte recente.

RECENT RANSOMWARE CLAIMSRANSOMWARE.LIVE
emperadorOMUR HIRDAVAT LTDTR · Manufacturing · 2026-10-04
qilinChadwick SwitchboardsAU · Manufacturing · 2026-10-04
qilinEmserES · Manufacturing · 2026-10-04
qilinCotesmaCL · Manufacturing · 2026-10-04
direwolfSoftruckBR · Technology · 2026-10-04
StormNipigon District Memorial HospitalCA · Healthcare · 2026-10-04
krybiteuroditel.comFR · Technology · 2026-10-04
krybitsuperpack.com.coCO · Retail & E-Commerce · 2026-10-04
krybitdaralteb.comIR · Healthcare · 2026-10-04
qilinUnident GroupUS · Other · 2026-10-04
qilinMutsumi GroupJP · Manufacturing · 2026-10-04
thegentlemenCenter State EngineeringUS · Manufacturing · 2026-10-04
MALWARE FAMILIES / 7 DAYSMALWAREBAZAAR
Configure a Auth-Key gratuita do abuse.ch para habilitar detecções recentes do MalwareBazaar.

FONTES: RANSOMWARE.LIVE + MALWAREBAZAAR / ABUSE.CH · CACHE 1H

11641 REGISTROS ENCONTRADOSFEED 2026-09-29
CVE-2026-73586MEDIUM

Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.16, contains an Insufficient Session Expiration vulnerability. A low privileged attacker with adjacent network access could potentially exploit this vulnerability, leading to Elevation of privileges, Protection mechanism bypass, and Unauthorized access.

AFFECTED SURFACEdell policy manager for secure connect gateway
CVSS 6.4EPSS 0.11%
CVE-2026-71178LOW

Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.16, contains an Use of Non-Canonical URL Paths for Authorization Decisions vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Unauthorized access.

AFFECTED SURFACEdell policy manager for secure connect gateway
CVSS 3.7EPSS 0.16%
CVE-2026-71177MEDIUM

Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.16, contains an Improper Restriction of Rendered UI Layers or Frames vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Elevation of privileges and Session theft.

AFFECTED SURFACEdell policy manager for secure connect gateway
CVSS 5.4EPSS 0.14%
CVE-2026-63002MEDIUM

REDAXO is a PHP-based content management system. Prior to 5.21.2, redaxo/src/addons/mediapool/pages/sync.php inserts filenames held in $diffFiles from the media filesystem into the Mediapool Sync page without rex_escape(). An attacker who can place an unregistered file with HTML metacharacters in the media directory can execute script in the browser of a backend user with media[sync] permission when that user opens the Sync page, enabling session theft or unauthorized backend actions. This issue is fixed in version 5.21.2.

AFFECTED SURFACEProduct not specified
CVSS 4.8EPSS 0.18%
CVE-2026-63001MEDIUM

REDAXO is a PHP-based content management system. Prior to 5.21.2, the mediaIsInUse() handler in redaxo/src/addons/media_manager/lib/media_manager.php inserts a Media Manager type name into raw backend warning HTML without escaping it when invoked through MEDIA_IS_IN_USE. An administrator with Media Manager access can store HTML in a type name, and the payload executes in another administrator's browser when that administrator tries to delete media referenced by the type's effects, enabling session theft or unauthorized backend actions. This issue is fixed in version 5.21.2.

AFFECTED SURFACEProduct not specified
CVSS 4.8EPSS 0.18%
CVE-2026-63000MEDIUM

REDAXO is a PHP-based content management system. Prior to 5.21.2, rex_api_install_package_update in redaxo/src/addons/install/lib/api/api_package_update.php inherits the false default from rex_api_function::requiresCsrfProtection() instead of requiring a CSRF token. An unauthenticated attacker can cause a logged-in administrator's browser to request a selected package update from the configured REDAXO package server, changing installed addon code or disrupting the site without the administrator's intent. This issue is fixed in version 5.21.2.

AFFECTED SURFACEProduct not specified
CVSS 6.4EPSS 0.13%
CVE-2026-62998MEDIUM

REDAXO is a PHP-based content management system. Prior to 5.21.2, rex_list::getSortColumn() in redaxo/src/core/lib/list.php accepts the sort request parameter without checking whether setColumnSortable() registered the requested column. An authenticated backend user can make prepareQuery() add an escaped but unauthorized ORDER BY identifier, allowing error-based enumeration of columns in joined tables and ordering by unselected sensitive fields such as rex_user.password. This issue is fixed in version 5.21.2.

AFFECTED SURFACEProduct not specified
CVSS 4.3EPSS 0.27%
CVE-2026-61834MEDIUM

scim-patch is a library for applying SCIM patch operations. Prior to 0.9.2, navigate() reads inherited properties and assign() uses prototype-chain membership checks while resolving attacker-controlled SCIM PATCH paths. A path or one of the dotted value keys beginning with an inherited property such as toString can therefore traverse into a shared built-in function object and add attacker-controlled properties, causing process-global mutation that may affect application logic reading inherited-method properties. This issue is fixed in version 0.9.2.

AFFECTED SURFACEProduct not specified
CVSS 4.3EPSS 0.28%
CVE-2026-61413MEDIUM

Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.16, contains an Improper Privilege Management vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Unauthorized access.

AFFECTED SURFACEdell policy manager for secure connect gateway
CVSS 6.8EPSS 0.21%
CVE-2026-55610HIGH

InvoiceShelf is an open-source web & mobile app that helps track expenses, payments and create professional invoices and estimates. Prior to version 2.4.1, in InvoiceShelf's multi-company installations, any user who is an Owner of one company can read and overwrite any user account in any other company on the same installation. `GET/PUT /api/v1/users/{user}` resolves the target `User` by global primary key, and `UserPolicy` checks only that the requester owns their own header-company — it never verifies that the target user belongs to that company. This allows cross-tenant disclosure of user data and full account takeover (email/password overwrite + company re-assignment). Version 2.4.1 fixes the issue.

AFFECTED SURFACEProduct not specified
CVSS 8.7EPSS 0.30%
CVE-2026-96560CRITICAL

LightLLM through 1.2.0 contains a remote code execution vulnerability in the KV-transfer worker when started with --pd_trans_mode nccl, which exposes an unauthenticated RPyC control channel that deserializes attacker-supplied data. Attackers can send malicious pickled objects to the exposed RPyC ThreadedServer to execute arbitrary code with the privileges of the LightLLM service account.

AFFECTED SURFACEProduct not specified
CVSS 9.3EPSS 0.65%
CVE-2026-96559ANALYSIS

Rejected reason: This ID was for testing

AFFECTED SURFACEProduct not specified
CVSS N/DEPSS 0.00%
CVE-2026-96512HIGH

A flaw was found in sudo. When sudoers rules use NOTBEFORE or NOTAFTER time-based access restrictions with timestamps that omit the trailing 'Z' timezone indicator, the time evaluation relies on the TZ environment variable inherited from the calling user. Because sudo is a setuid-root program, an unprivileged local user can set TZ to an extreme timezone offset to shift the authorization window by up to approximately 25 hours, causing expired rules to be treated as valid. This allows the user to execute commands outside the intended time window. Authentication is not bypassed; only the time-based authorization check is affected.

AFFECTED SURFACEProduct not specified
CVSS 7.8EPSS 0.13%
CVE-2026-86708CRITICAL

ZohoCorp ManageEngine Applications Manager versions 182200 and below were vulnerable to exposure of a Google Cloud service-account private key in the Applications Manager installer, which could allow an unauthenticated attacker to impersonate the service account and access or modify associated cloud resources.

AFFECTED SURFACEProduct not specified
CVSS 10.0EPSS 1.24%
CVE-2026-86683HIGH

ZohoCorp ManageEngine Applications Manager versions 182000 and below allowed a low-privileged user to change the proxy settings.

AFFECTED SURFACEProduct not specified
CVSS 8.1EPSS 0.68%
CVE-2026-86681HIGH

ZohoCorp ManageEngine Applications Manager versions 182200 and below were vulnerable to a permissions validation issue that allowed low-privileged users to execute administrator-configured MBean actions on monitors outside their assigned scope.

AFFECTED SURFACEProduct not specified
CVSS 7.6EPSS 0.46%
CVE-2026-86679HIGH

ZohoCorp ManageEngine Applications Manager versions 182000 and below were vulnerable to a permissions validation issue that allowed a low-privileged user to delete service monitors outside their assigned scope.

AFFECTED SURFACEProduct not specified
CVSS 7.1EPSS 0.78%
CVE-2026-86678HIGH

ZohoCorp ManageEngine Applications Manager versions 182000 and below allowed a low-privileged user to obtain an administrator’s API key and use it to perform administrator-level actions.

AFFECTED SURFACEProduct not specified
CVSS 8.8EPSS 0.68%
CVE-2026-86677HIGH

ZohoCorp ManageEngine Applications Manager versions 182000 and below allowed a low-privileged user to run unauthorized SQL commands, potentially gaining administrator access and remote code execution.

AFFECTED SURFACEProduct not specified
CVSS 8.8EPSS 2.02%
CVE-2026-59167CRITICAL

SunEditor is a lightweight and powerful WYSIWYG editor in vanilla JavaScript with no dependencies. Prior to 2.47.11, the sanitizer in src/lib/core.js does not consistently reject namespaced or custom HTML elements, allowing event-handler attributes to remain on crafted elements. When an application renders attacker-controlled editor content and a user interacts with the element, the retained handler can execute script in the application's browser origin, enabling stored cross-site scripting, data exposure, or unauthorized browser-context actions. This issue is fixed in version 2.47.11.

AFFECTED SURFACEProduct not specified
CVSS 10.0EPSS 0.39%
CVE-2026-18179MEDIUM

IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote attacker to clear active chat sessions due to improper authorization.

AFFECTED SURFACEProduct not specified
CVSS 6.5EPSS 0.24%
CVE-2026-18177HIGH

IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote attacker to execute unauthorized payment actions due to missing authorization checks.

AFFECTED SURFACEProduct not specified
CVSS 7.1EPSS 0.18%
CVE-2026-12974HIGH

A Security Policy Bypass vulnerability exists in Forcepoint Security Engine (NGFW). This issue affects Forcepoint Security Engine (NGFW): from 7.1.0 through 7.1.13, from 7.3.0 through 7.3.1, 7.3.3, from 7.4.0 through 7.4.1, and 7.5.0.

AFFECTED SURFACEProduct not specified
CVSS 7.9EPSS 0.29%
CVE-2026-95676HIGH

A missing/improper authentication vulnerability in the WatchGuard AuthPoint Gateway's LDAP Sync first-factor authentication allows a remote attacker to bypass single-factor password verification under non-default operating conditions. Additional authentication factors still apply.

AFFECTED SURFACEProduct not specified
CVSS 7.4EPSS 0.50%