L/BLAB BOTSPUBLIC THREAT INTELLIGENCE NODE
CVE KNOWLEDGE BASE

Intelligence
Explorer.

Investigue vulnerabilidades por identificador, produto afetado ou descrição. Use severidade, CVSS e EPSS juntos para orientar a prioridade.

// THREAT ACTIVITY

Grupos & malware emergente

Atividade pública observada em leak sites e repositórios comunitários. Alegações de vítimas não representam confirmação independente de incidente.

RANSOMWARE GROUPSRECENT CLAIMS
lamashtu10 menções
qilin10 menções
krybit9 menções
thegentlemen9 menções
Booba Project7 menções
akira7 menções
incransom6 menções
Storm5 menções
rhysida5 menções
play4 menções
INFOSTEALERSOBSERVED

Sem famílias correlacionadas no recorte recente.

RECENT RANSOMWARE CLAIMSRANSOMWARE.LIVE
playBold Spring NurseryUS · Agriculture and Food Production · 2026-10-04
playSilicon Valley GlassUS · Manufacturing · 2026-10-04
emperadorOMUR HIRDAVAT LTDTR · Manufacturing · 2026-10-04
qilinChadwick SwitchboardsAU · Manufacturing · 2026-10-04
qilinEmserES · Manufacturing · 2026-10-04
qilinCotesmaCL · Manufacturing · 2026-10-04
direwolfSoftruckBR · Technology · 2026-10-04
StormNipigon District Memorial HospitalCA · Healthcare · 2026-10-04
krybiteuroditel.comFR · Technology · 2026-10-04
krybitsuperpack.com.coCO · Retail & E-Commerce · 2026-10-04
krybitdaralteb.comIR · Healthcare · 2026-10-04
qilinUnident GroupUS · Other · 2026-10-04
MALWARE FAMILIES / 7 DAYSMALWAREBAZAAR
Configure a Auth-Key gratuita do abuse.ch para habilitar detecções recentes do MalwareBazaar.

FONTES: RANSOMWARE.LIVE + MALWAREBAZAAR / ABUSE.CH · CACHE 1H

11641 REGISTROS ENCONTRADOSFEED 2026-09-29
CVE-2026-91809HIGH

A use-after-free vulnerability exists in Foxit PDF Editor/Reader’s handling of malformed PDF form fields. Improper validation during field-name traversal may cause the application to access a released object, resulting in an application crash.

AFFECTED SURFACEProduct not specified
CVSS 7.8EPSS 0.12%
CVE-2026-91808MEDIUM

A heap-based out-of-bounds read vulnerability exists in Foxit PDF Editor Reader’s handling of PDF image objects with inconsistent compression metadata. Insufficient validation during image decoding may result in an undersized buffer and an out-of-bounds read during rendering, causing an application crash.

AFFECTED SURFACEProduct not specified
CVSS 6.1EPSS 0.11%
CVE-2026-91807MEDIUM

A heap-based out-of-bounds read vulnerability exists in Foxit PDF Editor/Reader’s handling of malformed image soft-mask data. Insufficient validation of the soft-mask data attribute during image parsing may cause an arithmetic underflow, resulting in an out-of-bounds read and application crash.

AFFECTED SURFACEProduct not specified
CVSS 6.1EPSS 0.11%
CVE-2026-91806HIGH

A use-after-free vulnerability exists in Foxit PDF Editor/Reader’s handling of PDF form fields. Embedded JavaScript may access form-field references after the corresponding fields have been released, resulting in an application crash.

AFFECTED SURFACEProduct not specified
CVSS 7.8EPSS 0.12%
CVE-2026-91805HIGH

A use-after-free vulnerability exists in Foxit PDF Editor/Reader’s PDF page-tree handling. A specially crafted PDF can trigger page-structure changes during rendering, causing the application to access released page objects and resulting in memory corruption and an application crash.

AFFECTED SURFACEProduct not specified
CVSS 7.8EPSS 0.12%
CVE-2026-91804HIGH

A heap-based out-of-bounds write vulnerability exists in Foxit PDF Editor/Reader’s rendering of Circle annotations with malformed Cloudy appearance streams in specially crafted PDF files. Insufficient validation of the appearance geometry can result in memory corruption and application crashes.

AFFECTED SURFACEProduct not specified
CVSS 7.8EPSS 0.12%
CVE-2026-91803HIGH

A local privilege escalation vulnerability exists in the updater of Foxit PDF Editor/Reader due to unsafe loading of dynamic-link libraries from a user-writable directory during high-privilege operations. A local attacker could exploit this issue to execute code with elevated privileges.

AFFECTED SURFACEProduct not specified
CVSS 8.8EPSS 0.12%
CVE-2026-91802HIGH

A heap-based out-of-bounds write vulnerability exists in Foxit PDF Editor/Reader’s WebP image decoding due to improper handling of bitmap stride and target buffer formats. Successful exploitation could result in an application crash.

AFFECTED SURFACEProduct not specified
CVSS 7.8EPSS 0.12%
CVE-2026-91801HIGH

A path traversal vulnerability exists in Foxit PDF Editor/Reader's handling of embedded PDF resources. Insufficient validation of resource file paths may allow files to be written outside their intended locations, potentially enabling arbitrary code execution.

AFFECTED SURFACEProduct not specified
CVSS 7.8EPSS 0.15%
CVE-2026-91800HIGH

A local privilege escalation vulnerability exists in the installer of Foxit PDF Editor for macOS due to insufficient validation of a user-modifiable configuration value during high-privilege upgrades. A local attacker could exploit this issue to execute arbitrary commands with root privileges.

AFFECTED SURFACEProduct not specified
CVSS 8.8EPSS 0.10%
CVE-2026-91799HIGH

A use-after-free vulnerability exists in Foxit PDF Editor/Reader’s handling of JavaScript array objects. A specially crafted PDF may cause the application to access a released object during array processing, potentially resulting in application crashes or arbitrary code execution.

AFFECTED SURFACEProduct not specified
CVSS 7.8EPSS 0.13%
CVE-2026-91798HIGH

A local privilege escalation vulnerability exists in the update daemon of Foxit PDF Editor/Reader due to an insecure permission configuration that allows the configuration file to be modified by regular users, which may lead to arbitrary script execution with higher privileges.

AFFECTED SURFACEProduct not specified
CVSS 8.8EPSS 0.10%
CVE-2026-91797HIGH

Foxit PDF Editor/Reader failed to validate the directory traversal path in the attachment file name, resulting in malicious attachments being able to be written to directories outside the expected secure area when the PDF is opened.

AFFECTED SURFACEProduct not specified
CVSS 7.8EPSS 0.21%
CVE-2026-91796MEDIUM

The interface of Foxit PDF Editor/Reader lacks the permission verification for secure reading mode, which allows specially crafted PDFs to trigger external SMB authentication without any security prompts and thereby leak the hash of the user's credentials.

AFFECTED SURFACEProduct not specified
CVSS 6.1EPSS 0.12%
CVE-2026-91795HIGH

Foxit PDF Editor/Reader's FileOpen plugin did not adequately validate certain encryption metadata in specially crafted PDF files. This could leave an internal pointer in an invalid state, resulting in chained read and write access violations and potentially enabling arbitrary code execution.

AFFECTED SURFACEProduct not specified
CVSS 7.8EPSS 0.08%
CVE-2026-91794HIGH

An out-of-bounds write vulnerability exists in the PDF rendering process of Foxit PDF Editor/Reader due to insufficient consistency and boundary validation when processing malformed color space data, which may cause the program to crash and potentially lead to remote code execution.

AFFECTED SURFACEProduct not specified
CVSS 7.8EPSS 0.16%
CVE-2026-91793HIGH

When opening a specially crafted PDF, Foxit PDF Editor/Reader executes scripts that modify annotation rich-text attributes containing malformed font data. During subsequent annotation appearance reconstruction, it accesses an object after it has been released, resulting in a use-after-free condition and an application crash.

AFFECTED SURFACEProduct not specified
CVSS 7.8EPSS 0.12%
CVE-2026-91792HIGH

When processing a specially crafted PDF, Foxit PDF Editor/Reader may perform reentrant zoom and layout operations through page- and annotation-related JavaScript actions. This can cause the application to access page objects after they have been released, resulting in a use-after-free condition and an application crash.

AFFECTED SURFACEProduct not specified
CVSS 7.8EPSS 0.12%
CVE-2026-91791HIGH

When processing a specially crafted PDF file, Foxit PDF Editor/Reader may encounter a reentrant execution condition involving JavaScript triggered by page-visibility events. This can cause the application to access a released page-view object while calculating annotation boundaries, resulting in an invalid memory read and application crash.

AFFECTED SURFACEProduct not specified
CVSS 7.8EPSS 0.14%
CVE-2026-91790HIGH

When rendering the page image, Foxit PDF Editor/Reader fails to perform validation on image objects whose optional content attributes are malformed. As a result, the program may access an already-freed internal data structure, triggering a crash due to UAF.

AFFECTED SURFACEProduct not specified
CVSS 7.8EPSS 0.12%
CVE-2026-91789HIGH

Foxit PDF Editor/Reader’s U3D/GIF texture decoding path contained insufficient validation of image dimensions and related size information. Under certain conditions, this could lead to an incorrectly sized memory allocation and a subsequent out-of-bounds write during pixel processing, potentially resulting in remote code execution.

AFFECTED SURFACEProduct not specified
CVSS 7.8EPSS 0.16%
CVE-2026-91788MEDIUM

When implementing the JavaScript interface, Foxit PDF Editor/Reader did not perform the attribute authorization checks required by the specification. As a result, a trusted malicious PDF could potentially access sensitive content from other documents within the same process and transmit it externally.

AFFECTED SURFACEProduct not specified
CVSS 4.7EPSS 0.10%
CVE-2026-50228MEDIUM

An unauthenticated local attacker can connect to the Electron DevTools endpoint exposed by Acer NitroSense software (versions up to and including 5.2.63) on localhost TCP port 9993. Because Chromium remote debugging is enabled in the production application, the attacker can execute JavaScript in the privileged application context and achieve arbitrary code execution.

AFFECTED SURFACEProduct not specified
CVSS 6.1EPSS 0.13%
CVE-2026-50227MEDIUM

An unauthenticated local attacker can connect to the MQTT broker over its localhost WebSocket endpoint in Acer NitroSense software (versions up to and including 5.2.62). This allows the attacker to invoke exposed ddsc RPC functions, including child_process.execSync(), resulting in arbitrary command execution in the application context.

AFFECTED SURFACEProduct not specified
CVSS 6.1EPSS 0.35%