L/BLAB BOTSPUBLIC THREAT INTELLIGENCE NODE
CVE KNOWLEDGE BASE

Intelligence
Explorer.

Investigue vulnerabilidades por identificador, produto afetado ou descrição. Use severidade, CVSS e EPSS juntos para orientar a prioridade.

// THREAT ACTIVITY

Grupos & malware emergente

Atividade pública observada em leak sites e repositórios comunitários. Alegações de vítimas não representam confirmação independente de incidente.

RANSOMWARE GROUPSRECENT CLAIMS
qilin10 menções
krybit9 menções
Booba Project7 menções
akira7 menções
thegentlemen7 menções
incransom6 menções
lamashtu5 menções
N0n4 menções
Storm4 menções
emperador4 menções
INFOSTEALERSOBSERVED

Sem famílias correlacionadas no recorte recente.

RECENT RANSOMWARE CLAIMSRANSOMWARE.LIVE
DoommageddonENKA SchoolsTR · Education · 2026-10-05
DoommageddonCam Group LLC— · Other · 2026-10-05
medusalockerMillensysBR · Technology · 2026-10-05
medusalockerRueegseggeragCH · Not Found · 2026-10-05
emperadorPANCARIBBEAN LOGISTICS GROUPTT · Transportation · 2026-10-05
emperadorMETROCOLOR S.A.— · Manufacturing · 2026-10-05
lamashtuFluge AudiovisualesES · Other · 2026-10-05
lamashtuBender TribunenbauDE · Manufacturing · 2026-10-05
lamashtuTRANS LOGROÑO SOCIEDAD ANONIMAES · Transportation · 2026-10-05
lamashtuGrupo Industrial TauroMX · Manufacturing · 2026-10-05
auroraInfomedia A/SDK · Technology · 2026-10-05
N0nCompany #3US · Technology · 2026-10-05
MALWARE FAMILIES / 7 DAYSMALWAREBAZAAR
Configure a Auth-Key gratuita do abuse.ch para habilitar detecções recentes do MalwareBazaar.

FONTES: RANSOMWARE.LIVE + MALWAREBAZAAR / ABUSE.CH · CACHE 1H

11641 REGISTROS ENCONTRADOSFEED 2026-09-29
CVE-2026-91130CRITICAL

Home Assistant is open source home automation software focused on local control and privacy. Prior to 2026.7.0, the Statistics Graph card in src/components/chart/statistics-chart.ts passed entity names through getStatisticLabel and computeStateName and interpolated param.seriesName into ECharts tooltip HTML without escaping. An authenticated user or an integration that supplies a malicious default entity name could cause script-related HTML to execute when a viewer hovered over a data point. Mean, State, Sum, and Change fields in the default Line chart configuration were affected, while Bar charts were not. This issue is fixed in version 2026.7.0.

AFFECTED SURFACEProduct not specified
CVSS 9.3EPSS 0.39%
CVE-2026-91129MEDIUM

Home Assistant is open source home automation software focused on local control and privacy. Prior to 2026.2.3, the IPP integration automatically processed unauthenticated _ipp._tcp.local mDNS announcements in homeassistant/components/ipp/config_flow.py, where async_step_zeroconf passed attacker-controlled host, port, and base_path values to validate_input for printer metadata retrieval. Because the shared HTTP client followed attacker-controlled cross-origin redirects without blocking loopback targets, a local-network attacker could redirect the request to 127.0.0.1 or another internal service without user interaction or prior IPP configuration. This issue is fixed in version 2026.2.3.

AFFECTED SURFACEProduct not specified
CVSS 5.4EPSS 0.20%
CVE-2026-89277MEDIUM

CAI Content Credentials is affected by an Integer Overflow or Wraparound vulnerability that could result in an application denial-of-service. An attacker could exploit this vulnerability to crash the application, leading to a denial-of-service condition. Exploitation of this issue requires user interaction in that a victim must visit a maliciously crafted URL or interact with a compromised web page.

AFFECTED SURFACEProduct not specified
CVSS 5.5EPSS 0.25%
CVE-2026-88415HIGH

MCMS 6.1.1 through 6.2.1 is vulnerable to stored Cross-Site Scripting (XSS). The article content field `contentDetails` is excluded from the global XSS filter.

AFFECTED SURFACEProduct not specified
CVSS 8.7EPSS 0.31%
CVE-2026-88414CRITICAL

MCMS 6.1.1 through 6.2.1 contains a SQL injection vulnerability in the PageAction.verify endpoint (GET /ms/mdiy/page/verify.do).

AFFECTED SURFACEProduct not specified
CVSS 9.8EPSS 0.41%
CVE-2026-84396MEDIUM

InDesign Desktop is affected by a NULL Pointer Dereference vulnerability that could result in an application denial-of-service. An attacker could exploit this vulnerability to crash the application, leading to a denial-of-service condition. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

AFFECTED SURFACEProduct not specified
CVSS 5.5EPSS 0.14%
CVE-2026-84395HIGH

Premiere Pro is affected by a Server-Side Request Forgery (SSRF) vulnerability that could result in privilege escalation potentially resulting in unauthorized write access. Exploitation of this issue does not require user interaction. Scope is changed.

AFFECTED SURFACEProduct not specified
CVSS 7.1EPSS 0.25%
CVE-2026-83964MEDIUM

Adobe Connect is affected by an Improper Certificate Validation vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to disclose sensitive information. Exploitation of this issue does not require user interaction.

AFFECTED SURFACEadobe connectapple macosmicrosoft windowsadobe connect for mobile
CVSS 6.2EPSS 0.22%
CVE-2026-83963HIGH

Substance3D - Modeler is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

AFFECTED SURFACEadobe substance 3d modeler
CVSS 7.8EPSS 0.14%
CVE-2026-83962HIGH

Substance3D - Modeler is affected by a Stack-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

AFFECTED SURFACEadobe substance 3d modeler
CVSS 7.8EPSS 0.17%
CVE-2026-82000CRITICAL

Adobe Experience Manager Forms JEE is affected by a Server-Side Request Forgery (SSRF) vulnerability that could result in privilege escalation. A low-privileged attacker could exploit this vulnerability to gain elevated access to internal resources. Exploitation of this issue does not require user interaction. Scope is changed.

AFFECTED SURFACEProduct not specified
CVSS 9.6EPSS 0.73%
CVE-2026-81999HIGH

Adobe Experience Manager Forms JEE is affected by a Server-Side Request Forgery (SSRF) vulnerability that could result in privilege escalation. An attacker with high privileges could exploit this vulnerability to gain elevated access to internal resources. Exploitation of this issue does not require user interaction. Scope is changed.

AFFECTED SURFACEProduct not specified
CVSS 8.7EPSS 0.81%
CVE-2026-81998HIGH

Substance3D - Modeler is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

AFFECTED SURFACEadobe substance 3d modeler
CVSS 7.8EPSS 0.14%
CVE-2026-81995CRITICAL

Adobe Experience Manager Forms JEE is affected by an Improper Input Validation vulnerability that could result in arbitrary code execution in the context of the current user. An attacker with high privileges could exploit this vulnerability to execute arbitrary code. Exploitation of this issue does not require user interaction. Scope is changed.

AFFECTED SURFACEProduct not specified
CVSS 9.1EPSS 1.24%
CVE-2026-79906HIGH

Substance3D - Modeler is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

AFFECTED SURFACEadobe substance 3d modeler
CVSS 7.8EPSS 0.14%
CVE-2026-77558HIGH

A malicious actor with access to the network could exploit an Out-of-bounds Read vulnerability found in certain UniFi gateway devices to execute a Denial of Service (DoS) attack on the device.

AFFECTED SURFACEProduct not specified
CVSS 7.5EPSS 0.46%
CVE-2026-77556HIGH

A malicious actor with access to the network could exploit an Out-of-bounds Read vulnerability found in certain UniFi gateway devices to execute a Denial of Service (DoS) attack on the device.

AFFECTED SURFACEProduct not specified
CVSS 7.5EPSS 0.46%
CVE-2026-77555HIGH

A malicious actor with access to the network could exploit an Out-of-bounds Write vulnerability found in certain UniFi gateway devices to execute a Denial of Service (DoS) attack on the device.

AFFECTED SURFACEProduct not specified
CVSS 7.5EPSS 0.46%
CVE-2026-77544HIGH

A malicious actor with access to the network could exploit an Out-of-bounds Write vulnerability found in certain UniFi gateway devices to execute a Denial of Service (DoS) attack on the device.

AFFECTED SURFACEProduct not specified
CVSS 7.5EPSS 0.46%
CVE-2026-77399MEDIUM

icalendar is an RFC 5545 compatible parser and generator of iCalendar files for Python. From 6.1.0 until 7.2.2, vInt.from_ical accepts an attacker-controlled VALARM REPEAT value and applications that request alarm times can eagerly expand it without an application-level limit. Alarms.times and Alarms.active reach the unbounded expansion in versions starting with 6.1.0, while Alarm.triggers adds a second affected path starting with 7.0.0. Parsing alone does not trigger the issue, but accessing these properties can consume excessive CPU time and heap memory and terminate or stall a service. This issue is fixed in version 7.2.2.

AFFECTED SURFACEProduct not specified
CVSS 6.5EPSS 0.31%
CVE-2026-77272MEDIUM

MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to 0.22.0, the OAuth error query parameter is passed to CallbackHandler._send_response in oauth_setup.py and interpolated into an HTML page without escaping. A crafted authorization callback can inject markup or script that executes in the browser of a user completing the OAuth flow. This issue is fixed in version 0.22.0.

AFFECTED SURFACEmcp-atlassian mcp atlassian
CVSS 5.4EPSS 0.25%
CVE-2026-77269MEDIUM

MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to 0.22.0, the remediation for CVE-2026-27825 protects download destinations but does not constrain source paths used by attachment uploads. A caller can provide an absolute or traversal file_path and cause the server to upload the selected local file. The advisory traces the vulnerable input and processing flow through upload_attachment, file_path, and CVE-2026-27825, which identify the affected entry points, controls, and code paths. This issue is fixed in version 0.22.0.

AFFECTED SURFACEmcp-atlassian mcp atlassian
CVSS 6.5EPSS 0.38%
CVE-2026-77268MEDIUM

MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to 0.22.0, the OAuth fallback token directory and JSON file are created without explicit owner-only modes. Local users or processes with access through the resulting group or world permission bits can read access and refresh tokens and reuse the associated Atlassian session. The advisory traces the vulnerable input and processing flow through ~/.mcp-atlassian, oauth-<client_id>.json, access_token, and refresh_token, which identify the affected entry points, controls, and code paths. This issue is fixed in version 0.22.0.

AFFECTED SURFACEProduct not specified
CVSS 5.5EPSS 0.11%
CVE-2026-77266MEDIUM

MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to 0.22.0, upload_attachment accepts absolute paths and traversal sequences without constraining the resolved path to the server workspace. An MCP caller with attachment access can read a chosen server-local file and exfiltrate it through Jira or Confluence. The advisory traces the vulnerable input and processing flow through upload_attachment, file_path, and path traversal, which identify the affected entry points, controls, and code paths. This issue is fixed in version 0.22.0.

AFFECTED SURFACEmcp-atlassian mcp atlassian
CVSS 6.5EPSS 0.44%