L/BLAB BOTSPUBLIC THREAT INTELLIGENCE NODE
CVE KNOWLEDGE BASE

Intelligence
Explorer.

Investigue vulnerabilidades por identificador, produto afetado ou descrição. Use severidade, CVSS e EPSS juntos para orientar a prioridade.

// THREAT ACTIVITY

Grupos & malware emergente

Atividade pública observada em leak sites e repositórios comunitários. Alegações de vítimas não representam confirmação independente de incidente.

RANSOMWARE GROUPSRECENT CLAIMS
qilin17 menções
safepay10 menções
Booba Project5 menções
everest5 menções
BYOD4 menções
SilentRansomGroup4 menções
incransom4 menções
lamashtu4 menções
N0n3 menções
Panzer3 menções
INFOSTEALERSOBSERVED

Sem famílias correlacionadas no recorte recente.

RECENT RANSOMWARE CLAIMSRANSOMWARE.LIVE
qilinEPTISAES · Professional Services · 2026-10-07
SilentRansomGroupAndersen Group— · Professional Services · 2026-10-06
UmBraBeni Suef Technological University – BTUEG · Education · 2026-10-06
PanzerEDFelectronics— · Manufacturing · 2026-10-06
incransomarchitekt-vondanwitz.deDE · Professional Services · 2026-10-07
incransomharborpacific.comUS · Transportation · 2026-10-07
incransomacmestamping.comUS · Manufacturing · 2026-10-07
qilinBNYH— · Financial Services · 2026-10-06
qilinCiftay Insaat Taahhut Ve Ticaret Anonim SirketiTR · Manufacturing · 2026-10-06
Vexy RansomwareKOOKABARRA JUICEAU · Retail & E-Commerce · 2026-10-06
PanzerSweetRushUS · Professional Services · 2026-10-06
incransommagnals.comUS · Other · 2026-10-06
MALWARE FAMILIES / 7 DAYSMALWAREBAZAAR
Configure a Auth-Key gratuita do abuse.ch para habilitar detecções recentes do MalwareBazaar.

FONTES: RANSOMWARE.LIVE + MALWAREBAZAAR / ABUSE.CH · CACHE 1H

14535 REGISTROS ENCONTRADOSFEED 2026-10-06
CVE-2026-100418MEDIUM

Flame through 2.4.0 contains an information exposure vulnerability in the unauthenticated GET /api/config endpoint that returns the entire configuration object without field redaction. Attackers can retrieve the stored weather API key and internal operational settings by sending a single unauthenticated request to consume provider quota or access sensitive configuration data.

AFFECTED SURFACEProduct not specified
CVSS 6.9EPSS 0.34%
CVE-2026-100383MEDIUM

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia Foundation Mediawiki - WikiLambda Extension allows Cross-Site Scripting (XSS). This issue affects Mediawiki - WikiLambda Extension: 1.47.0-alpha. The issue has been remediated on the `master` branch.

AFFECTED SURFACEProduct not specified
CVSS 4.8EPSS 0.32%
CVE-2026-100382CRITICAL

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Wikimedia Foundation Mediawiki - ExternalData Extension allows OS Command Injection. This issue affects Mediawiki - ExternalData Extension: from * before 3.7.

AFFECTED SURFACEProduct not specified
CVSS 10.0EPSS 0.95%
CVE-2026-100381MEDIUM

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia Foundation Mediawiki - UploadWizard Extension allows Cross-Site Scripting (XSS). This issue affects Mediawiki - UploadWizard Extension: from * before 1.46.1, 1.45.5, 1.43.10.

AFFECTED SURFACEProduct not specified
CVSS 5.3EPSS 0.33%
CVE-2026-9313ANALYSIS

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

AFFECTED SURFACEProduct not specified
CVSS N/DEPSS 0.00%
CVE-2026-96879MEDIUM

Improper removal of sensitive information before storage or transfer vulnerability in Wikimedia Foundation's Mediawiki - FlaggedRevs extension through 1.46.0.

AFFECTED SURFACEProduct not specified
CVSS 6.9EPSS 0.25%
CVE-2026-91769MEDIUM

PHP's OpenSSL stream peer verification checks the certificate's subjectAltName entries first and, whenever no entry matches, falls back to the Common Name. RFC 6125 requires the CN to be ignored once the certificate presents any service identity, so a certificate carrying a non-matching DNS SAN was still accepted when its CN matched the requested peer_name. A certificate trusted by the client for one name can therefore be used to impersonate another.

AFFECTED SURFACEProduct not specified
CVSS 4.3EPSS 0.14%
CVE-2026-91767MEDIUM

php_openssl_matches_wildcard_name() in ext/openssl/xp_ssl.c underflows the length argument passed to memchr() when a TLS server certificate presents a wildcard name whose literal characters are together longer than the hostname being verified. A malicious server presenting such a certificate makes the PHP client read up to SIZE_MAX bytes past the end of a heap allocation. The path is reachable from any default client stream, because verify_peer_name is enabled by default.

AFFECTED SURFACEProduct not specified
CVSS 6.5EPSS 0.15%
CVE-2026-91766MEDIUM

When the http:// stream wrapper follows a redirect it forwards the user-supplied Authorization, Cookie and Proxy-Authorization headers unchanged, even when the redirect target is a different host, a different port, or a downgrade from HTTPS to HTTP. A server that can steer a redirect therefore receives credentials that were only meant for the original origin. This is the same class of issue that libcurl fixed in 7.58.0 ( CVE-2018-1000007 https://github.com/advisories/GHSA-g7x2-hrfp-pv5f ).

AFFECTED SURFACEProduct not specified
CVSS 5.9EPSS 0.34%
CVE-2026-91765HIGH

cleanup_xml_node() in the SOAP XML parser recurses once per XML nesting level with no depth limit. An unauthenticated attacker can post a SOAP request containing tens of thousands of nested elements to any SoapServer endpoint, exhaust the stack and crash the process. The same unbounded recursion exists in the SOAP value decoder and in the WSDL node search helper.

AFFECTED SURFACEProduct not specified
CVSS 7.5EPSS 0.52%
CVE-2026-6103MEDIUM

phar_tar_number() parses the octal size field of a TAR header into a uint32_t with no overflow check. The field is 11 octal digits wide and holds values up to 0x1FFFFFFFF, so a size above 0xFFFFFFFF silently wraps. The parser then skips the wrong number of data blocks and interprets attacker-controlled file content as the next TAR header, which lets a crafted archive inject entries that PharData reports and extracts as if they were genuine.

AFFECTED SURFACEProduct not specified
CVSS 4.3EPSS 0.17%
CVE-2026-57864ANALYSIS

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

AFFECTED SURFACEProduct not specified
CVSS N/DEPSS 0.00%
CVE-2026-57443HIGH

SCBE-AETHERMOORE is a geometric AI governance and evaluation framework. Starting in version 4.0.2 and prior to version 4.2.1, the AetherBrowser API server (`scripts/aetherbrowser/api_server.py`) exposes the `POST /api/ops/check-email` endpoint without any authentication. Any remote attacker can call this endpoint and trigger execution of the `email_reader.py` subprocess, which connects to configured ProtonMail or Gmail accounts via IMAP and returns email metadata (sender, subject, body snippet) in the JSON response. The server binds to `0.0.0.0:8100` by default with CORS set to `allow_origins=["*"]`, making it reachable from any network or browser origin. Version 4.2.1 patches the issue.

AFFECTED SURFACEProduct not specified
CVSS 7.5EPSS 0.57%
CVE-2026-17545MEDIUM

On Windows, PHP's filesystem and stream APIs do not reject reserved device names such as CON, PRN, AUX, NUL, COM1 to COM9, LPT1 to LPT9, CONIN$ and CONOUT$ when they appear as a component of a path. An attacker-controlled filename therefore reaches CreateFileW() and opens a device instead of the regular file the application expected, which can block or hang the request and exhaust worker processes.

AFFECTED SURFACEProduct not specified
CVSS 6.9EPSS 0.32%
CVE-2026-10758HIGH

Esri LERC is an open-source image or raster format which supports rapid encoding and decoding for any pixel type. A Heap based Out-of-Bounds Write via Integer Overflow in LERC versions 4.1.0 and earlier may allow a remote, unauthenticated attacker who can pass specifically crafted attacker controlled imagery to an application that uses LERC to crash the application, leading to a denial of service.

AFFECTED SURFACEProduct not specified
CVSS 7.5EPSS 0.33%
CVE-2026-100417LOW

RustDesk before 1.5.0 on Windows fails to enforce the one-way file transfer option against peer clipboard file requests, allowing authenticated peers to read files from the host clipboard. Attackers can send FormatDataRequest and FileContentsRequest messages to retrieve copied files by guessing the FileGroupDescriptorW format identifier.

AFFECTED SURFACEProduct not specified
CVSS 2.3EPSS 0.21%
CVE-2026-100391HIGH

MediaFlow Proxy through 2.4.9 contains a server-side request forgery vulnerability in the /proxy routes due to missing and incomplete destination validation in the d query parameter. Remote attackers can supply arbitrary internal URLs including loopback and cloud metadata endpoints to read full responses from the proxy server.

AFFECTED SURFACEProduct not specified
CVSS 8.8EPSS 0.31%
CVE-2026-100390CRITICAL

Zoraxy versions 3.2.3 through 3.3.4 fail to properly parse IPv6 addresses in the RemoteAddr field when setting forwarded headers. Unauthenticated attackers connecting over IPv6 can supply arbitrary X-Forwarded-For values to spoof their source IP and bypass authorization provider IP-based access controls.

AFFECTED SURFACEProduct not specified
CVSS 9.1EPSS 0.29%
CVE-2026-100389CRITICAL

GestSup versions before 3.2.61 contain a remote code execution vulnerability in the basic IMAP connector's attachment handling that fails to skip blocked file extensions. Unauthenticated attackers can send emails with PHP attachments to monitored mailboxes, which are written to the web-accessible upload/ticket directory and executed when accessed.

AFFECTED SURFACEProduct not specified
CVSS 9.2EPSS 0.57%
CVE-2026-100388MEDIUM

RustDesk versions before 1.5.0 fail to properly validate file transfer permissions on incoming file clipboard messages in the Cliprdr message handler on Linux and macOS. Authenticated remote peers with disabled file transfer permissions can place files onto the host clipboard and retrieve copied files and contents from the process-wide clipboard cache.

AFFECTED SURFACEProduct not specified
CVSS 5.3EPSS 0.18%
CVE-2026-100387HIGH

pgPointcloud through 1.2.5 contains a heap out-of-bounds read vulnerability in dimensional patch WKB deserialization that allows authenticated database users to read adjacent heap memory. Attackers can supply crafted pcpatch values with attacker-controlled size fields to copy heap memory into stored patches for exfiltration or crash the PostgreSQL backend.

AFFECTED SURFACEProduct not specified
CVSS 7.2EPSS 0.32%
CVE-2026-100380MEDIUM

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia Foundation Mediawiki - Wikibase Extension allows Cross-Site Scripting (XSS). This issue affects Mediawiki - Wikibase Extension: from * before 1.46.1, 1.45.5, 1.43.10.

AFFECTED SURFACEProduct not specified
CVSS 5.3EPSS 0.33%
CVE-2026-100379MEDIUM

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Wikimedia Foundation Wikipedia Android App allows Accessing/Intercepting/Modifying HTTP Cookies. This issue affects Wikipedia Android App: main.

AFFECTED SURFACEProduct not specified
CVSS 5.3EPSS 0.32%
CVE-2026-100378MEDIUM

Missing Authorization vulnerability in Wikimedia Foundation Mediawiki - Translate Extension allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects Mediawiki - Translate Extension: from * before 1.46.1, 1.45.5, 1.43.10.

AFFECTED SURFACEProduct not specified
CVSS 5.3EPSS 0.27%