L/BLAB BOTSPUBLIC THREAT INTELLIGENCE NODE
CVE KNOWLEDGE BASE

Intelligence
Explorer.

Investigue vulnerabilidades por identificador, produto afetado ou descrição. Use severidade, CVSS e EPSS juntos para orientar a prioridade.

// THREAT ACTIVITY

Grupos & malware emergente

Atividade pública observada em leak sites e repositórios comunitários. Alegações de vítimas não representam confirmação independente de incidente.

RANSOMWARE GROUPSRECENT CLAIMS
thegentlemen26 menções
qilin10 menções
UmBra8 menções
Eclipse5 menções
SilentRansomGroup5 menções
Panzer4 menções
incransom4 menções
Black X3 menções
akira3 menções
arcusmedia3 menções
INFOSTEALERSOBSERVED

Sem famílias correlacionadas no recorte recente.

RECENT RANSOMWARE CLAIMSRANSOMWARE.LIVE
DeadlockSaber1US · Not Found · 2026-10-09
Deadlockidi pharmaES · Healthcare · 2026-10-09
safepayhoteldelfinolugano.chCH · Hospitality · 2026-10-09
safepaydwi-bau.deDE · Other · 2026-10-09
PanzerSupreme EnergySG · Energy & Utilities · 2026-10-09
Panzersolutend— · Technology · 2026-10-09
qilinVadeto GroupSE · Not Found · 2026-10-09
rhysidaAnne Arundel CountyUS · Government & Defense · 2026-10-09
threeamfleetworksinc.comUS · Transportation · 2026-10-09
qilinTepcompFI · Technology · 2026-10-09
interlockShalom Christian AcademyUS · Education · 2026-10-09
anubisMynd— · Healthcare · 2026-10-09
MALWARE FAMILIES / 7 DAYSMALWAREBAZAAR
Configure a Auth-Key gratuita do abuse.ch para habilitar detecções recentes do MalwareBazaar.

FONTES: RANSOMWARE.LIVE + MALWAREBAZAAR / ABUSE.CH · CACHE 1H

14535 REGISTROS ENCONTRADOSFEED 2026-10-06
CVE-2026-4637MEDIUM

Paessler PRTG Network Monitor before version 26.2.120.1449 is affected by a reflected Cross-Site Scripting (XSS) vulnerability. When a request is made for a non-existent resource ending in \".htm\", the web interface returns an HTTP 403 \"Forbidden Path\" error page that echoes the requested URL path into the HTML response body without proper output encoding or sanitization. An unauthenticated, remote attacker can craft a URL containing an HTML/JavaScript payload in the path (e.g. https:////welcome.htm) and, once a victim with an active PRTG session opens the crafted link, execute arbitrary JavaScript in the security context of the PRTG web interface. Because the PRTG session cookie is not protected with the HttpOnly attribute, successful exploitation allows the attacker to read and exfiltrate the victim's session cookie, potentially leading to session hijacking.

AFFECTED SURFACEProduct not specified
CVSS 5.1EPSS 0.55%
CVE-2026-18335MEDIUM

The Kirki – Freeform Page Builder, Website Builder & Customizer plugin for WordPress is vulnerable to Blind Server-Side Request Forgery in all versions up to, and including, 6.2.0 via the 'kirki_data' Parameter. This makes it possible for unauthenticated attackers to make web requests to arbitrary locations originating from the web application and can be used to query and modify information from internal services.

AFFECTED SURFACEProduct not specified
CVSS 5.4EPSS 0.26%
CVE-2026-15731MEDIUM

The WP Multilang – Translation and Multilingual Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the post content in all versions up to, and including, 2.4.31 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

AFFECTED SURFACEProduct not specified
CVSS 6.4EPSS 0.25%
CVE-2026-12227CRITICAL

The Visual Composer Website Builder plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 45.16.0 via the `vcv-template` parameter. This makes it possible for unauthenticated attackers to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where images and other “safe” file types can be uploaded and included.

AFFECTED SURFACEProduct not specified
CVSS 9.8EPSS 2.87%
CVE-2026-97185HIGH

A flaw was found in GIMP. When processing a specially crafted GIMPressionist preset file, the plug-in does not properly validate vector indices before writing into fixed-size arrays. This can lead to an out-of-bounds write, corrupting memory. An attacker could exploit this by convincing a user to load a malicious preset file, potentially causing a crash or enabling arbitrary code execution.

AFFECTED SURFACEProduct not specified
CVSS 7.8EPSS 0.13%
CVE-2026-85682HIGH

The YOP Poll plugin for WordPress is vulnerable to Origin Validation Error in all versions up to, and including, 7.0.10. This is due to the plugin transmitting a wp_rest nonce to window.opener via postMessage() with a wildcard targetOrigin. This makes it possible for unauthenticated attackers to steal a REST nonce scoped to a logged-in Administrator and use it to change the Administrator's email address and password, resulting in full account takeover. The Administrator must open an attacker-controlled page in order to exploit this vulnerability.

AFFECTED SURFACEProduct not specified
CVSS 8.8EPSS 0.14%
CVE-2026-78313MEDIUM

Improper Access Control in DIAEnergie. This issue affects DIAEnergie: before 1.11.00.022.

AFFECTED SURFACEProduct not specified
CVSS 6.5EPSS 0.46%
CVE-2026-78312CRITICAL

Path Traversal in DIAEnergie. This issue affects DIAEnergie: before 1.11.00.022.

AFFECTED SURFACEProduct not specified
CVSS 9.1EPSS 0.34%
CVE-2026-78311HIGH

SQL Injection vulnerability in DIAEnergie. This issue affects DIAEnergie: before 1.11.00.022.

AFFECTED SURFACEProduct not specified
CVSS 8.8EPSS 0.24%
CVE-2026-78310MEDIUM

Authorization Bypass Through User-Controlled Key in DIAEnergie. This issue affects DIAEnergie: before 1.11.00.022.

AFFECTED SURFACEProduct not specified
CVSS 4.3EPSS 0.21%
CVE-2026-78309HIGH

SQL Injection vulnerability in DIAEnergie. This issue affects DIAEnergie: before 1.11.00.022.

AFFECTED SURFACEProduct not specified
CVSS 8.8EPSS 0.24%
CVE-2026-78308CRITICAL

Improper Authentication vulnerability in DIAEnergie allows Authentication Bypass. This issue affects DIAEnergie: before 1.11.00.022.

AFFECTED SURFACEProduct not specified
CVSS 9.8EPSS 0.35%
CVE-2026-77193HIGH

The eesy_ID2WP – Publish InDesign HTML5 plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 1.0.3 via the `id2wp_path` parameter. This makes it possible for unauthenticated attackers to read the contents of arbitrary files on the server, which can contain sensitive information.

AFFECTED SURFACEProduct not specified
CVSS 7.5EPSS 0.36%
CVE-2026-97181MEDIUM

GPM LIGHT developed by ezGlobal has a Sensitive Data Exposure vulnerability. Unauthenticated remote attackers can directly access system logs.

AFFECTED SURFACEProduct not specified
CVSS 6.9EPSS 0.26%
CVE-2026-87739MEDIUM

An improper authentication vulnerability in PaperCut MF/NG allows an unauthenticated, remote attacker to trigger report generation. By submitting report generation requests without valid credentials, an attacker can generate reports and gain unauthorized access to sensitive information.

AFFECTED SURFACEProduct not specified
CVSS 6.9EPSS 0.38%
CVE-2026-82077HIGH

An improper limitation of a pathname to a restricted directory (path traversal) vulnerability in the Scan-to-Fax component of PaperCut NG and PaperCut MF allows an authenticated administrator to execute arbitrary commands on the underlying host via crafted fax provider settings.

AFFECTED SURFACEProduct not specified
CVSS 7.3EPSS 0.74%
CVE-2026-81645MEDIUM

Out-of-bounds read vulnerability in the graphics module. Successful exploitation of this vulnerability may affect availability.

AFFECTED SURFACEProduct not specified
CVSS 5.9EPSS 0.09%
CVE-2026-11744LOW

An input validation vulnerability exists in the PaperCut Hive embedded application for Ricoh devices. The application fails to properly sanitize input received during the NFC card reading process before passing it to the application's web view interface. A local attacker with physical access to the device and a specially crafted NFC card or emulator could exploit this flaw to execute arbitrary code within the context of the application's user interface. This could result in unauthorized actions or information disclosure.

AFFECTED SURFACEProduct not specified
CVSS 3.8EPSS 0.17%
CVE-2026-97177MEDIUM

A flaw was found in the user update mechanism of the Keycloak Admin REST API. When Fine-Grained Admin Permissions are enabled, the system fails to check for specific password reset authorizations during a general user profile update. This allows a delegated administrator, who should be restricted from resetting passwords, to change a user's credentials and take over their account.

AFFECTED SURFACEProduct not specified
CVSS 6.6EPSS 0.24%
CVE-2026-97176MEDIUM

A flaw was found in the Level of Authentication enforcement mechanism of Keycloak, an identity and access management solution. The issue occurs when a client specifically requires a higher security level for a user who already has an active session at a lower level. Due to a logic error in how session re-evaluations are handled, Keycloak may incorrectly issue a token at the lower security level instead of enforcing the required higher level, potentially allowing unauthorized access to sensitive resources that rely on these security claims.

AFFECTED SURFACEProduct not specified
CVSS 4.2EPSS 0.17%
CVE-2026-97168ANALYSIS

Rejected reason: it is a suggestion

AFFECTED SURFACEProduct not specified
CVSS N/DEPSS 0.00%
CVE-2026-93662MEDIUM

The Events Manager WordPress plugin before 7.4.5 does not force the scope of its logged-in event and location search when a caller supplies their own owner value, letting a low-privileged user read other accounts' unpublished, pending or trashed event and venue content, including full street addresses.

AFFECTED SURFACEProduct not specified
CVSS 4.3EPSS 0.18%
CVE-2026-93661LOW

The Events Manager WordPress plugin before 7.4.5 does not stop a ticket-update request from replacing the identifiers of the ticket it was authorized against, letting a user who can manage one event's tickets overwrite and reassign any ticket on the site to their own event.

AFFECTED SURFACEProduct not specified
CVSS 2.7EPSS 0.17%
CVE-2026-89005MEDIUM

The WPeMatico RSS Feed Fetcher WordPress plugin before 2.8.26 does not sanitise and escape one of its campaign configuration fields when a certain feature is enabled, which allows users with the Contributor role and above to perform Stored Cross-Site Scripting attacks that execute in the session of any higher-privileged user who later views the campaign.

AFFECTED SURFACEProduct not specified
CVSS 6.8EPSS 0.24%