L/BLAB BOTSPUBLIC THREAT INTELLIGENCE NODE
CVE KNOWLEDGE BASE

Intelligence
Explorer.

Investigue vulnerabilidades por identificador, produto afetado ou descrição. Use severidade, CVSS e EPSS juntos para orientar a prioridade.

// THREAT ACTIVITY

Grupos & malware emergente

Atividade pública observada em leak sites e repositórios comunitários. Alegações de vítimas não representam confirmação independente de incidente.

RANSOMWARE GROUPSRECENT CLAIMS
lamashtu11 menções
qilin10 menções
krybit9 menções
Booba Project7 menções
akira7 menções
thegentlemen7 menções
incransom6 menções
N0n4 menções
Storm4 menções
emperador4 menções
INFOSTEALERSOBSERVED

Sem famílias correlacionadas no recorte recente.

RECENT RANSOMWARE CLAIMSRANSOMWARE.LIVE
emperadorMETROCOLOR S.A.— · Manufacturing · 2026-10-05
lamashtuFluge AudiovisualesES · Other · 2026-10-05
lamashtuBender TribunenbauDE · Manufacturing · 2026-10-05
lamashtuTRANS LOGROÑO SOCIEDAD ANONIMAES · Transportation · 2026-10-05
lamashtuGrupo Industrial TauroMX · Manufacturing · 2026-10-05
N0nCompany #3US · Technology · 2026-10-05
N0nCompany #2CA · Financial Services · 2026-10-05
N0nCompany #1US · Healthcare · 2026-10-05
auroraThomas Y. Pickett & Co., Inc.US · Professional Services · 2026-10-05
playBold Spring NurseryUS · Agriculture and Food Production · 2026-10-04
playSilicon Valley GlassUS · Manufacturing · 2026-10-04
emperadorOMUR HIRDAVAT LTDTR · Manufacturing · 2026-10-04
MALWARE FAMILIES / 7 DAYSMALWAREBAZAAR
Configure a Auth-Key gratuita do abuse.ch para habilitar detecções recentes do MalwareBazaar.

FONTES: RANSOMWARE.LIVE + MALWAREBAZAAR / ABUSE.CH · CACHE 1H

11641 REGISTROS ENCONTRADOSFEED 2026-09-29
CVE-2026-76909LOW

Unleash is an open-source feature management platform. Prior to 8.0.3, the change-request approval email template at src/mailtemplates/requested-cr-approval/requested-cr-approval.html.mustache renders the user-controlled changeRequestTitle, requesterName, and requesterEmail values without HTML escaping, and sendRequestedCRApprovalEmail passes those values to Mustache rendering. A project member who can create a change request when approval emails are enabled can inject HTML into an approver's notification, allowing forged links, tracking content, or visually altered email content. This issue is fixed in version 8.0.3.

AFFECTED SURFACEProduct not specified
CVSS 2.1EPSS 0.27%
CVE-2026-75101MEDIUM

An authorization bypass vulnerability was identified in GitHub Enterprise Server that allowed any authenticated user of the instance to read the raw diff or patch of pull requests in private repositories without authorization. Access tokens for raw pull request diffs and patches were scoped to the repository name and pull request number rather than to a globally unique repository identifier, so an attacker who created a repository and pull request matching a target's repository name and pull request number could use a token for their own repository to retrieve the private pull request's contents. Exploitation required the attacker to know the target repository's name and a valid pull request number. This vulnerability affected all versions of GitHub Enterprise Server prior to 3.22 and was fixed in versions 3.17.21, 3.18.15, 3.19.12, 3.20.8, and 3.21.6. This vulnerability was reported via the GitHub Bug Bounty program.

AFFECTED SURFACEProduct not specified
CVSS 6.0EPSS 0.45%
CVE-2026-67615HIGH

openEQUELLA before 2026.1.0 contains an authenticated remote code execution vulnerability that allows any authenticated non-guest user to execute arbitrary code by exploiting Java deserialization in the HTTP invoker endpoint at /invoker/*. Attackers can bypass the class-name denylist enforced by PluginAwareObjectInputStream by nesting a serialized payload inside a java.security.SignedObject, causing the inner stream to be deserialized by a separate ObjectInputStream that does not apply the denylist, ultimately reaching a JNDI sink and enabling code execution.

AFFECTED SURFACEProduct not specified
CVSS 8.7EPSS 0.54%
CVE-2026-62364LOW

wlc is a Weblate command-line client using Weblate's REST API. Prior to 2.0.1, automatically discovered configuration from .weblate, .weblate.ini, or weblate.ini can select the API URL while an unscoped API token is supplied through WLC_KEY or --key without a matching WLC_URL or --url. When wlc runs in an untrusted repository, pull request checkout, or directory with untrusted ancestor configuration, it can send the token to an attacker-controlled project-configured URL. URL-scoped keys in [keys] are not affected. This issue is fixed in version 2.0.1.

AFFECTED SURFACEProduct not specified
CVSS 2.3EPSS 0.08%
CVE-2026-94574HIGH

A local cross-user code execution vulnerability exists in GNU wget (Windows builds from eternallybored.org) due to a hardcoded configuration file path (C:\msys64) that is writable by unprivileged users, allowing for arbitrary code execution via the use_askpass directive, potentially allowing local privilege escalation.

AFFECTED SURFACEProduct not specified
CVSS 7.8EPSS 0.12%
CVE-2026-89282CRITICAL

The Apache Lounge Windows distribution of Apache HTTP Server build contains an insecure installation directory permissions vulnerability through its default install directory on C:\, which inherits write access for Authenticated Users.

AFFECTED SURFACEProduct not specified
CVSS 9.1EPSS 0.27%
CVE-2026-89281HIGH

The Apache Lounge Windows distribution of Apache HTTP Server build contains a hardcoded configuration path vulnerability within openssl.cnf path that can allow local code execution.

AFFECTED SURFACEProduct not specified
CVSS 8.4EPSS 0.12%
CVE-2026-88624CRITICAL

Missing path validation in the Worktree.remove component of openCode v1.18.26 allows attackers to execute arbitrary recursive directory deletion via a crafted payload.

AFFECTED SURFACEProduct not specified
CVSS 9.1EPSS 0.34%
CVE-2026-88419HIGH

An unrestricted upload of files with a dangerous type in the thumbnail-upload endpoint (/index.php?m=member&f=article&v=thumbUpload) of WuzhiCMS 5.0.0 allows an authenticated low-privileged member to upload a crafted .php file and execute arbitrary PHP code on the server, because the stored file extension is taken verbatim from the client-supplied filename with no extension allowlist or content validation and the file is written to the web-accessible uploadfile/ directory, from which the web server executes PHP.

AFFECTED SURFACEProduct not specified
CVSS 8.8EPSS 0.48%
CVE-2026-88418HIGH

CMSimple 5.24 ships with CSRF protection disabled by default, which turns csrfProtection() into a no-op on every state-changing admin request, and it does not send the csrf_token hidden field in admin forms. Because administrator authentication is cookie-only and no CSRF token is enforced, an unauthenticated attacker can induce a logged-in administrator's browser to issue a forged content-save request with a text payload containing a scripting marker. The marker is stored verbatim into content/content.php; on every subsequent page view evaluate_cmsimple_scripting() (functions.php) executes the marker body with PHP eval() — for all visitors, including unauthenticated ones. This yields persistent remote code execution on the web server.

AFFECTED SURFACEProduct not specified
CVSS 8.8EPSS 0.25%
CVE-2026-88416ANALYSIS

MCMS 6.1.1 through 6.2.1 has a SQL injection vulnerability in the custom model/form import feature.

AFFECTED SURFACEProduct not specified
CVSS N/DEPSS 0.19%
CVE-2026-88350ANALYSIS

An integer overflow vulnerability exists in MPack 1.1.1 in mpack_node_cstr_alloc() and mpack_node_utf8_cstr_alloc().

AFFECTED SURFACEProduct not specified
CVSS N/DEPSS 0.15%
CVE-2026-88345HIGH

An out-of-bounds read vulnerability exists in the schema lexer of flatcc 4c3b999e. When an exact-length FlatBuffers schema ends with an unterminated quotation mark, the C-string scanning logic in lex() dereferences the input pointer after it has reached the end of the buffer. A specially crafted schema can trigger a one-byte heap buffer over-read, resulting in application crash and denial of service.

AFFECTED SURFACEProduct not specified
CVSS 7.5EPSS 0.41%
CVE-2026-88344HIGH

An out-of-bounds read vulnerability exists in the schema lexer of flatcc 4c3b999e. When an exact-length FlatBuffers schema buffer ends with a digit, the integer digit-scan loop in lex() advances past the end of the input buffer and dereferences the out-of-bounds pointer. A specially crafted schema can trigger a one-byte heap buffer over-read, resulting in application crash and denial of service.

AFFECTED SURFACEProduct not specified
CVSS 7.5EPSS 0.40%
CVE-2026-88341MEDIUM

A reachable assertion vulnerability exists in YARA 4.5.8 when loading crafted .yrc compiled rule files. An attacker can provide a malicious file with an invalid arena configuration (num_buffers=0) that triggers an assertion failure in yr_arena_get_ptr(), causing the application to terminate.

AFFECTED SURFACEProduct not specified
CVSS 5.5EPSS 0.17%
CVE-2026-88340HIGH

An invalid pointer release vulnerability exists in YARA 4.5.8 during deserialization of compiled .yrc rule files. The vulnerability is caused by insufficient validation of external-variable pointers, which may lead to invalid free in yr_rules_destroy() or wild pointer access in yr_object_create(). An attacker can provide a specially crafted .yrc file that causes memory corruption and application crash.

AFFECTED SURFACEProduct not specified
CVSS 7.6EPSS 0.25%
CVE-2026-88339MEDIUM

A NULL pointer dereference vulnerability exists in the gf_sg_vrml_field_clone() function of GPAC 2d7da22e (26.08-DEV). The vulnerability occurs when cloning a PROTO default SFImage field with a NULL source pointer. An attacker can provide a specially crafted input file that triggers the condition, resulting in application crash and denial of service.

AFFECTED SURFACEProduct not specified
CVSS 5.5EPSS 0.17%
CVE-2026-87121CRITICAL

lwIP TCP/IP Stack MQTT is vulnerable to an out-of-bounds write, which may allow an attacker to gain full code execution on the device.

AFFECTED SURFACEProduct not specified
CVSS 9.3EPSS 0.53%
CVE-2026-83805MEDIUM

Nautobot is a Network Source of Truth and Network Automation Platform. From 3.0.0 until 3.1.8, the generic ApprovalWorkflowStageResponse create endpoint does not enforce approver-group membership, change permission on the object under review, or the one-response-per-user restriction applied by the intended approve and deny actions. A user with only extras.add_approvalworkflowstageresponse can submit approved responses directly, while writable user and state fields permit responses to be attributed to arbitrary users. These forged responses can satisfy min_approvers, approve the workflow, and activate its gated ScheduledJob without a legitimate approver. This issue is fixed in version 3.1.8.

AFFECTED SURFACEProduct not specified
CVSS 6.4EPSS 0.22%
CVE-2026-83801MEDIUM

Nautobot is a Network Source of Truth and Network Automation Platform. Prior to 2.4.37 and 3.1.8, a user with extras.add_relationship or extras.change_relationship permission can store HTML or JavaScript in a Relationship description, and a user with dcim.add_modulefamily or dcim.change_modulefamily permission can store it in a Module Family name. Nautobot assigns these values to form field help_text rendered by render_field.html through Django's |safe filter without adequate neutralization. The stored content executes in the authenticated browser session of any user, including an administrator or superuser, who opens an affected create or edit form. This can enable actions as the victim, session or token theft, and further privilege escalation. This issue is fixed in versions 2.4.37 and 3.1.8.

AFFECTED SURFACEProduct not specified
CVSS 5.4EPSS 0.22%
CVE-2026-79767MEDIUM

Gardener implements the automated management and operation of Kubernetes clusters as a service. Prior to 1.142.6, 1.143.3, 1.144.2, and 1.145.0, the customverbauthorizer admission plugin's mustCheckProjectMembers manage-members check compares changes to User subjects but does not account for Group or ServiceAccount subjects in Project.spec.members. A project administrator who lacks manage-members permission can add arbitrary Group or ServiceAccount subjects, including the system:authenticated Group, and thereby grant broad project access. The resulting access can include Shoots, Secrets, and cloud provider credentials. This issue is fixed in versions 1.142.6, 1.143.3, 1.144.2, and 1.145.0.

AFFECTED SURFACEProduct not specified
CVSS 5.5EPSS 0.39%
CVE-2026-77322HIGH

SIPGO is a library for writing SIP services in the GO language. Prior to 1.4.3, WSConnection.Read in sip/transport_ws.go creates a wsutil.Reader without setting MaxFrameSize, allowing NextFrame to accept a client-controlled header.Length before ParseMaxMessageLength is applied. An unauthenticated WS or WSS peer can send a frame header declaring an extremely large payload, causing an oversized allocation or a makeslice length panic before the payload is read and crashing or exhausting memory in the server process. This issue is fixed in version 1.4.3.

AFFECTED SURFACEProduct not specified
CVSS 7.5EPSS 0.52%
CVE-2026-76717MEDIUM

A vulnerability exists in the Analytics and Location Engine (ALE) API that may allow for the disclosure of sensitive information. An unauthenticated remote attacker could exploit this vulnerability by providing specially crafted input to a specific API endpoint. Successful exploitation could result in the disclosure of sensitive user information, including password hashes, which could be used to facilitate further attacks.

AFFECTED SURFACEarubanetworks analytics and location engine
CVSS 5.3EPSS 0.42%
CVE-2026-76716MEDIUM

Multiple vulnerabilities exist in the Analytics and Location Engine (ALE) that may allow for unauthorized access or denial of service. An unauthenticated remote attacker could exploit these vulnerabilities by sending specially crafted input or leveraging improper security configurations. Successful exploitation could result in a denial of service condition or unauthorized access to sensitive information.

AFFECTED SURFACEarubanetworks analytics and location engine
CVSS 5.3EPSS 0.51%