L/BLAB BOTSPUBLIC THREAT INTELLIGENCE NODE
CVE KNOWLEDGE BASE

Intelligence
Explorer.

Investigue vulnerabilidades por identificador, produto afetado ou descrição. Use severidade, CVSS e EPSS juntos para orientar a prioridade.

// THREAT ACTIVITY

Grupos & malware emergente

Atividade pública observada em leak sites e repositórios comunitários. Alegações de vítimas não representam confirmação independente de incidente.

RANSOMWARE GROUPSRECENT CLAIMS
qilin13 menções
safepay10 menções
krybit9 menções
Booba Project7 menções
thegentlemen6 menções
Storm4 menções
emperador4 menções
lamashtu4 menções
BYOD3 menções
N0n3 menções
INFOSTEALERSOBSERVED

Sem famílias correlacionadas no recorte recente.

RECENT RANSOMWARE CLAIMSRANSOMWARE.LIVE
SilentRansomGroupA...n— · Not Found · 2026-10-05
netrunnerM** A******* G********** O******* a** P***** S****** A*********US · Not Found · 2026-10-05
qilinGlobal Security ConceptsUS · Professional Services · 2026-10-05
safepaydd-automation.chCZ · Technology · 2026-10-05
safepaystuecheli.chCH · Retail & E-Commerce · 2026-10-05
safepaybwi-bau.deDE · Professional Services · 2026-10-05
safepayhalservice.itIT · Professional Services · 2026-10-05
safepaygrundens.comUS · Retail & E-Commerce · 2026-10-05
safepayt-systems.comDE · Technology · 2026-10-05
SilentRansomGroupNelson Mullins Riley & ScarboroughUS · Professional Services · 2026-10-05
SilentRansomGroupSheppard, Mullin, Richter & HamptonUS · Professional Services · 2026-10-05
Global Secret GroupTurn5US · Other · 2026-10-05
MALWARE FAMILIES / 7 DAYSMALWAREBAZAAR
Configure a Auth-Key gratuita do abuse.ch para habilitar detecções recentes do MalwareBazaar.

FONTES: RANSOMWARE.LIVE + MALWAREBAZAAR / ABUSE.CH · CACHE 1H

11641 REGISTROS ENCONTRADOSFEED 2026-09-29
CVE-2026-94424CRITICAL

A vulnerability has been found in Moore Threads MTT S80 Driver Package up to 340.150. Impacted is the function sub_140001000 in the library mtdispkm64.sys of the component IOCTL Handler. The manipulation leads to heap-based buffer overflow. An attack has to be approached locally. The vendor was contacted early about this disclosure but did not respond in any way.

AFFECTED SURFACEProduct not specified
CVSS 9.3EPSS 0.00%
CVE-2026-93433MEDIUM

A flaw was found in libstoragemgmt. An attacker with control over a local or virtual storage device could provide specially crafted SCSI (Small Computer System Interface) Vital Product Data (VPD) page 0x80 data. This malformed data, specifically an untrusted page length field, can lead to a stack buffer overflow in the `_sg_parse_vpd_80()` function during serial number parsing. Successful exploitation could result in a denial of service by crashing or destabilizing the process querying the serial number.

AFFECTED SURFACEProduct not specified
CVSS 5.5EPSS 0.00%
CVE-2026-88746ANALYSIS

idccms V1.70 is vulnerable to Cross Site Scripting (XSS) in /admin/makeDiy_deal.php.

AFFECTED SURFACEProduct not specified
CVSS N/DEPSS 0.00%
CVE-2026-88745ANALYSIS

EMLOG-Pro 2.6.29 contains a XSS vulnerability that enables attackers to upload a malicious shell.

AFFECTED SURFACEProduct not specified
CVSS N/DEPSS 0.00%
CVE-2026-88467ANALYSIS

CRMEB Knowledge-Paid System crmeb_zzff_class 1.4.4 has a backend verification function that returns the wrong type of value, causing errors and leaking sensitive information.

AFFECTED SURFACEProduct not specified
CVSS N/DEPSS 0.00%
CVE-2026-88412MEDIUM

An integer overflow in the _BulkInsert_ReadProperty component (/bulk_insert.c) of FalkorDB (Redis module) v4.20.1 allows attackers to cause a Denial of Service (DoS) via a crafted input.

AFFECTED SURFACEProduct not specified
CVSS 5.3EPSS 0.00%
CVE-2026-88411HIGH

Improper error handling in the GRAPH.EFFECT component (/effects/effects_apply.c) of FalkorDB (Redis module) v4.20.1 leads to a Denial of Service (DoS) within the application.

AFFECTED SURFACEProduct not specified
CVSS 7.5EPSS 0.00%
CVE-2026-88410HIGH

The graph.UDF in FalkorDB (Redis module) v4.20.1 to v4.20.4 is not registered as a write command, leading to unexpected behavior within the application.

AFFECTED SURFACEProduct not specified
CVSS 7.1EPSS 0.00%
CVE-2026-88409HIGH

FalkorDB (Redis module) v4.20.1 to v4.20.4 was discovered to contain a buffer overflow in the _Decode_GrB_Matrix function (/v19/decode_matrix.c). This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input.

AFFECTED SURFACEProduct not specified
CVSS 8.8EPSS 0.00%
CVE-2026-88408MEDIUM

FalkorDB (Redis module) v4.20.1 to v4.20.4 was discovered to contain a stack overflow in the _GetGroup() function (/ops/op_aggregate.c). This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input.

AFFECTED SURFACEProduct not specified
CVSS 6.5EPSS 0.00%
CVE-2026-88407HIGH

An out-of-bounds read in the node_token_count/relation_token_count component of FalkorDB (Redis module) v4.20.1 to v4.20.4 allows attackers to cause a Denial of Service (DoS) via a crafted input.

AFFECTED SURFACEProduct not specified
CVSS 7.5EPSS 0.00%
CVE-2026-88406HIGH

FalkorDB (Redis module) v4.20.1 to v4.20.4 was discovered to contain a stack overflow in the _ValidateUnion_Clauses function (/ast/ast_validations.c). This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input.

AFFECTED SURFACEProduct not specified
CVSS 7.5EPSS 0.00%
CVE-2026-88405ANALYSIS

A remote code execution (RCE) vulnerability in the RemoteRegisterFunctionService function (/remote/remote-register-function.service.ts) of Univer v1.0.0-alpha.2 allows attackers to execute arbitrary code via a crafted payload.

AFFECTED SURFACEProduct not specified
CVSS N/DEPSS 0.00%
CVE-2026-88404ANALYSIS

A remote code execution (RCE) vulnerability in the UniscriptExecutionService.execute() function (/services/script-execution.service.ts) of Univer v1.0.0-alpha.2 allows attackers to execute arbitrary code via a crafted payload.

AFFECTED SURFACEProduct not specified
CVSS N/DEPSS 0.00%
CVE-2026-88403ANALYSIS

A Server-Side Request Forgery (SSRF) in the serverRequest function of nocobase v2.1.21 allows authenticated attackers to scan internal resources via a crafted HTTP request.

AFFECTED SURFACEProduct not specified
CVSS N/DEPSS 0.00%
CVE-2026-88402ANALYSIS

A SQL injection vulnerability in the checkSQL function of nocobase v2.1.21 allows attackers to access sesntive database information via injecting crafted SQL statements.

AFFECTED SURFACEProduct not specified
CVSS N/DEPSS 0.00%
CVE-2026-79919MEDIUM

MaxKB is an open-source AI assistant for enterprise. Prior to version 2.10.6-lts, function-library code running under the LD_PRELOAD sandbox can invoke ctypes.CDLL from an importlib.abc.MetaPathFinder callback so the dlopen call-stack heuristic sees a Python import frame, then use unhooked dlsym with RTLD_NEXT to resolve glibc's real syscall and bypass the sandbox syscall blacklist. An authenticated workspace member can consequently read or write files, execute processes, or access networks as the sandbox user. This issue is fixed in version 2.10.6-lts.

AFFECTED SURFACEProduct not specified
CVSS 6.3EPSS 0.00%
CVE-2026-79918MEDIUM

MaxKB is an open-source AI assistant for enterprise. Prior to version 2.10.6-lts, the ToolExecutor LD_PRELOAD sandbox hooks execve, execvpe, and execveat to prevent subprocess creation but does not hook fexecve. An authenticated attacker able to execute tool code can call fexecve to start a process outside the sandbox's intended subprocess policy. This issue is fixed in version 2.10.6-lts.

AFFECTED SURFACEProduct not specified
CVSS 6.3EPSS 0.00%
CVE-2026-79917MEDIUM

MaxKB is an open-source AI assistant for enterprise. In 2.7.0 through 2.10.4-lts, POST /chat/api/{application_id}/chat/{chat_id}/share_chat verifies that a conversation exists but does not verify that it belongs to the authenticated chat_user_id or to the application bound to the caller's token. An attacker with any chat token and a known victim chat_id can create an unauthenticated public ChatShareLink exposing the victim's conversation and can create PublicFileAccess state that makes associated files retrievable without credentials, with no available revoke path. No fixed version is available as of this review.

AFFECTED SURFACEProduct not specified
CVSS 6.5EPSS 0.00%
CVE-2026-79916CRITICAL

MaxKB is an open-source AI assistant for enterprise. Prior to 2.10.5-lts, authenticated workspace members can inject control characters into AWS Bedrock access_key_id and secret_access_key fields that _update_aws_credentials writes to /root/.aws/credentials without safe parsing. An attacker can append a new AWS profile containing credential_process, then select that profile during a later model-validation request so botocore executes an attacker-controlled command as root. This vulnerability is fixed in 2.10.5-lts.

AFFECTED SURFACEProduct not specified
CVSS 9.1EPSS 0.00%
CVE-2026-79317ANALYSIS

A session invalidation flaw exists in x-ui 0.3.2. The full user object is stored in a client-side signed cookie, and authentication only checks that a user object can be retrieved from the cookie without re-validating against the database or any session version. When an administrator changes the username or password, previously issued session cookies are not revoked, so an attacker who holds a pre-change admin cookie can continue accessing and operating the management interface after the credentials have been rotated.

AFFECTED SURFACEProduct not specified
CVSS N/DEPSS 0.00%
CVE-2026-79316ANALYSIS

An improper access control vulnerability exists in x-ui 0.3.2. Any authenticated panel user can modify the xray configuration template through the settings interface and trigger a panel restart, causing the xray management gRPC service, which is bound to loopback by default, to be regenerated and bound to non-loopback addresses. This expands the reachable surface of the management interface beyond its intended local-only boundary.

AFFECTED SURFACEProduct not specified
CVSS N/DEPSS 0.00%
CVE-2026-77525MEDIUM

MaxKB is an open-source AI assistant for enterprise. In 2.10.2-lts and earlier, management chat-record routes authorize the path application_id but load records using global chat_id and chat_record_id values without confirming that the chat belongs to the authorized application. A normal user in the same workspace who knows the chat_id of a persisted non-debug record for a victim's published application can place it under a separate attacker-owned application path to read victim chat records. An attacker with an owned knowledge base and document can also use add_knowledge to copy victim answers while updating the victim record's improve_paragraph_id_list. No fixed version is available as of this review.

AFFECTED SURFACEProduct not specified
CVSS 4.2EPSS 0.00%
CVE-2026-77523HIGH

MaxKB is an open-source AI assistant for enterprise. In version 2.10.3-lts and earlier, the model parameter form route authorizes the path workspace but ModelSerializer.ModelParams loads and saves a Model by id alone without including workspace_id in the query. An authenticated user with model read permission in an attacker-controlled workspace can supply a known victim model_id to read or overwrite the victim's model_params_form in another workspace, potentially altering workflows that use those defaults. No fixed version is available as of this review.

AFFECTED SURFACEProduct not specified
CVSS 7.4EPSS 0.00%