L/BLAB BOTSPUBLIC THREAT INTELLIGENCE NODE
CVE KNOWLEDGE BASE

Intelligence
Explorer.

Investigue vulnerabilidades por identificador, produto afetado ou descrição. Use severidade, CVSS e EPSS juntos para orientar a prioridade.

// THREAT ACTIVITY

Grupos & malware emergente

Atividade pública observada em leak sites e repositórios comunitários. Alegações de vítimas não representam confirmação independente de incidente.

RANSOMWARE GROUPSRECENT CLAIMS
thegentlemen26 menções
qilin10 menções
UmBra8 menções
Eclipse5 menções
SilentRansomGroup5 menções
Panzer4 menções
incransom4 menções
Black X3 menções
akira3 menções
arcusmedia3 menções
INFOSTEALERSOBSERVED

Sem famílias correlacionadas no recorte recente.

RECENT RANSOMWARE CLAIMSRANSOMWARE.LIVE
DeadlockSaber1US · Not Found · 2026-10-09
Deadlockidi pharmaES · Healthcare · 2026-10-09
safepayhoteldelfinolugano.chCH · Hospitality · 2026-10-09
safepaydwi-bau.deDE · Other · 2026-10-09
PanzerSupreme EnergySG · Energy & Utilities · 2026-10-09
Panzersolutend— · Technology · 2026-10-09
qilinVadeto GroupSE · Not Found · 2026-10-09
rhysidaAnne Arundel CountyUS · Government & Defense · 2026-10-09
threeamfleetworksinc.comUS · Transportation · 2026-10-09
qilinTepcompFI · Technology · 2026-10-09
interlockShalom Christian AcademyUS · Education · 2026-10-09
anubisMynd— · Healthcare · 2026-10-09
MALWARE FAMILIES / 7 DAYSMALWAREBAZAAR
Configure a Auth-Key gratuita do abuse.ch para habilitar detecções recentes do MalwareBazaar.

FONTES: RANSOMWARE.LIVE + MALWAREBAZAAR / ABUSE.CH · CACHE 1H

14535 REGISTROS ENCONTRADOSFEED 2026-10-06
CVE-2026-61814HIGH

Jawn is an open source JSON parser. Prior to 1.7.0, Jawn's AsyncParser can perform quadratic work when a single JSON token is delivered across many small chunks because each absorb call rescans the incomplete token from the start. A remote attacker who controls untrusted JSON input and its chunk sizes can exhaust CPU resources and cause denial of service in applications using AsyncParser. This issue is fixed in version 1.7.0.

AFFECTED SURFACEProduct not specified
CVSS 7.5EPSS 0.57%
CVE-2026-61695HIGH

Wire provides gRPC and protocol buffers for Android, Kotlin, Swift, and Java. Prior to 6.4.1 and 7.0.0-alpha04, Wire's Swift runtime ProtoReader.skipGroup(expectedEndTag:unknownFieldsWriter:) accepts a negative length for a LENGTH_DELIMITED field inside an unknown START_GROUP field. ProtoReader.readData() forwards the negative count to ReadBuffer.readData(count:), whose upper-bound-only check permits the value to reach Foundation Data(bytes:count:) and trigger an unrecoverable process trap instead of a catchable ProtoDecoder.Error. Any Swift process decoding untrusted protobuf bytes can be crashed without authentication, user interaction, or knowledge of the target schema. This issue is fixed in versions 6.4.1 and 7.0.0-alpha04.

AFFECTED SURFACEProduct not specified
CVSS 7.5EPSS 0.58%
CVE-2026-59990HIGH

Jawn is an open source JSON parser. Prior to 1.7.0, Jawn parse methods accept arbitrarily deep JSON array and object nesting without a depth limit, allowing a remote attacker who can submit untrusted JSON to grow parser contexts until the JVM heap is exhausted. The resulting java.lang.OutOfMemoryError is a fatal Scala error that is not ordinarily handled by scala.util.Try or cats.effect.IO, causing denial of service. This issue is fixed in version 1.7.0.

AFFECTED SURFACEProduct not specified
CVSS 7.5EPSS 0.62%
CVE-2026-55632MEDIUM

GoCD is a continuous deliver server. From 20.2.0 until 26.1.0, the internal pipeline structure API used for autocompletion while editing pipeline, template, environment, and user-preference configuration returns its users-and-roles mode to regular authenticated users without requiring an administrator role. A lower-privileged user can enumerate configured user names and available role names, which can facilitate attacks against those users. The response does not reveal which roles are assigned to each user, and the endpoint cannot modify data. This issue is fixed in version 26.1.0.

AFFECTED SURFACEProduct not specified
CVSS 4.3EPSS 0.29%
CVE-2026-55456ANALYSIS

Rejected reason: This CVE is a duplicate of another CVE.

AFFECTED SURFACEProduct not specified
CVSS N/DEPSS 0.00%
CVE-2026-52744MEDIUM

GoCD is a continuous deliver server. From 20.2.0 until 26.1.0, the internal GoCD UI fetch-artifact auto-suggestion API at /go/api/internal/pipelines/**/upstream does not adequately authorize access to upstream dependency data. An authenticated user can retrieve inter-pipeline dependency hierarchy details and user-defined pipeline, stage, job, and artifact plugin reference names that the user cannot otherwise view in the UI. The endpoint is read-only and does not permit modification of pipeline data. This issue is fixed in version 26.1.0.

AFFECTED SURFACEProduct not specified
CVSS 5.3EPSS 0.43%
CVE-2026-91775HIGH

LimeSurvey fails to safely encode attacker-controlled content from a crafted .lss survey file when displaying import warnings, resulting in XSS in the administrative interface.

AFFECTED SURFACEProduct not specified
CVSS 7.4EPSS 0.38%
CVE-2026-88840MEDIUM

BusyBox TLS get_client_hello() reads past the end of the input buffer when parsing a truncated ClientHello message.

AFFECTED SURFACEProduct not specified
CVSS 5.3EPSS 0.21%
CVE-2026-88839MEDIUM

BusyBox passwd/group tokenize() references a stale endpoint pointer after trimming, causing an out-of-bounds write of heap pointers.

AFFECTED SURFACEProduct not specified
CVSS 6.7EPSS 0.12%
CVE-2026-88837MEDIUM

BusyBox httpd treats yescrypt ($y$) password hashes as plaintext during Basic Authentication, inverting the authentication check.

AFFECTED SURFACEProduct not specified
CVSS 6.5EPSS 0.27%
CVE-2026-88835MEDIUM

BusyBox dpkg read_package_field() steps past a NUL terminator on malformed .deb packages, causing an out-of-bounds heap read.

AFFECTED SURFACEProduct not specified
CVSS 6.1EPSS 0.12%
CVE-2026-88831MEDIUM

BusyBox httpd IP deny rules with invalid CIDR prefix lengths fail open, leaving a parsed IP with a zeroed mask so the rule matches no clients.

AFFECTED SURFACEProduct not specified
CVSS 5.3EPSS 0.24%
CVE-2026-86938HIGH

A DLL hijacking vulnerability in the FileMaker Pro installer for Windows allowed a local user to execute arbitrary code with elevated administrator privileges by placing a malicious DLL file in the installer directory. This vulnerability is addressed in FileMaker Pro version 26.0.3.

AFFECTED SURFACEProduct not specified
CVSS 7.3EPSS 0.10%
CVE-2026-86934CRITICAL

An authorization bypass vulnerability in the FileMaker Server Web Publishing Engine allowed requests containing an extended privilege header to bypass the disabled Custom Web Publishing with XML setting and access the XML Web Publishing interface. This vulnerability is addressed in FileMaker Server version 26.0.3.

AFFECTED SURFACEProduct not specified
CVSS 9.1EPSS 0.33%
CVE-2026-86930CRITICAL

An out-of-bounds read vulnerability in FileMaker Server for Linux allowed an attacker uploading a specially crafted image file to a container field to disclose process memory during thumbnail generation in FileMaker WebDirect. This vulnerability is addressed in FileMaker Server version 26.0.3.

AFFECTED SURFACEProduct not specified
CVSS 9.1EPSS 0.29%
CVE-2026-86926HIGH

A heap buffer overflow vulnerability in the FileMaker Server database engine block parsing routine allowed a maliciously crafted .fmp12 database file to cause memory corruption, potentially leading to arbitrary code execution. This vulnerability is addressed in FileMaker Server version 26.0.3.

AFFECTED SURFACEProduct not specified
CVSS 7.8EPSS 0.13%
CVE-2026-86867MEDIUM

Cinnamon's Kotaemon (all versions up to and including v0.12.0) multi-user chat interface contains multiple vulnerabilities due to incorrect authorization and improper access controls. There are four handler methods in `libs/ktem/ktem/pages/chat/control.py` that load a Conversation record by its ID without comparing the requester's `user_id` to the conversation's owner `Conversation.user`. This allows any authenticated user to perform the following actions: 1. Read other user's chat transcripts, RAG retrieval history, AI-generated plots, and chat suggestions. 2. Permanently delete another user's conversation. 3. Rename another user's conversation. 4. Overwrite another user's conversation's chat suggestion list.

AFFECTED SURFACEProduct not specified
CVSS 6.5EPSS 0.18%
CVE-2026-18944ANALYSIS

Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2026-18944. Reason: This candidate is a reservation duplicate of CVE-2026-18944. Notes: All CVE users should reference CVE-2026-18944 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage.

AFFECTED SURFACEProduct not specified
CVSS N/DEPSS 0.00%
CVE-2026-96808HIGH

In Flatpak before 1.18.1, the revokefs writer, used by the flatpak-system-helper to receive repository data from unprivileged callers, validated file paths by rejecting literal .. components but did not prevent symlink traversal. A malicious local user in an active local session could obtain two revokefs sessions via the system helper, create a symlink in one session pointing into the other session's directory, and retain a file descriptor through that symlink. This allowed the attacker to modify files belonging to a different revokefs session after they had been validated and imported by the system helper. In particular, an attacker could use this to tamper with ostree commit objects in the system repository after they passed signature verification, enabling root-controlled file writes to attacker-chosen paths and local root privilege escalation.

AFFECTED SURFACEProduct not specified
CVSS 7.4EPSS 0.12%
CVE-2026-96807MEDIUM

In Flatpak before 1.18.1, a malicious sandboxed app can replace ~/.var/app/$appid/.ld.so with a symlink, causing regenerate_ld_cache to write files at an arbitrary location. The filenames and content are not attacker controlled, making this hard to exploit.

AFFECTED SURFACEProduct not specified
CVSS 4.0EPSS 0.12%
CVE-2026-96804HIGH

MLflow's statsmodel flavor, versions 2.1.0 to 3.14.0, omits the MLFLOW_ALLOW_PICKLE_DESERIALIZATION=False security control entirely in _load_model(), which allows a remote attacker to execute arbitrary code via a crafted MLmodel artifact.

AFFECTED SURFACEProduct not specified
CVSS 8.8EPSS 0.42%
CVE-2026-96775HIGH

MLflow's dspy flavor, versions >= 2.0, applies the MLFLOW_ALLOW_PICKLE_DESERIALIZATION=False security control only when the model_path ends in .pkl, which allows a remote attacker to execute arbitrary code via a crafted MLmodel artifact.

AFFECTED SURFACEProduct not specified
CVSS 8.8EPSS 0.39%
CVE-2026-96759CRITICAL

orval before 8.29.0 fails to escape the operationId parameter when emitting it into generated TanStack Query mutator options metadata objects. Attackers can inject arbitrary JavaScript code through a crafted operationId in an OpenAPI specification that executes when generated hooks are called.

AFFECTED SURFACEProduct not specified
CVSS 9.3EPSS 0.43%
CVE-2026-96758CRITICAL

orval @orval/core before 8.28.0 contains a code injection vulnerability in the form-data serializer that fails to escape multipart property names in generated template literals. Attackers can inject ${...} expressions into OpenAPI schema property names that execute as live interpolation when the generated client builds FormData bodies with consumer process privileges.

AFFECTED SURFACEProduct not specified
CVSS 9.3EPSS 0.54%