L/BLAB BOTSPUBLIC THREAT INTELLIGENCE NODE
CVE KNOWLEDGE BASE

Intelligence
Explorer.

Investigue vulnerabilidades por identificador, produto afetado ou descrição. Use severidade, CVSS e EPSS juntos para orientar a prioridade.

// THREAT ACTIVITY

Grupos & malware emergente

Atividade pública observada em leak sites e repositórios comunitários. Alegações de vítimas não representam confirmação independente de incidente.

RANSOMWARE GROUPSRECENT CLAIMS
thegentlemen26 menções
qilin10 menções
UmBra8 menções
Eclipse5 menções
SilentRansomGroup5 menções
Panzer4 menções
incransom4 menções
Black X3 menções
akira3 menções
arcusmedia3 menções
INFOSTEALERSOBSERVED

Sem famílias correlacionadas no recorte recente.

RECENT RANSOMWARE CLAIMSRANSOMWARE.LIVE
DeadlockSaber1US · Not Found · 2026-10-09
Deadlockidi pharmaES · Healthcare · 2026-10-09
safepayhoteldelfinolugano.chCH · Hospitality · 2026-10-09
safepaydwi-bau.deDE · Other · 2026-10-09
PanzerSupreme EnergySG · Energy & Utilities · 2026-10-09
Panzersolutend— · Technology · 2026-10-09
qilinVadeto GroupSE · Not Found · 2026-10-09
rhysidaAnne Arundel CountyUS · Government & Defense · 2026-10-09
threeamfleetworksinc.comUS · Transportation · 2026-10-09
qilinTepcompFI · Technology · 2026-10-09
interlockShalom Christian AcademyUS · Education · 2026-10-09
anubisMynd— · Healthcare · 2026-10-09
MALWARE FAMILIES / 7 DAYSMALWAREBAZAAR
Configure a Auth-Key gratuita do abuse.ch para habilitar detecções recentes do MalwareBazaar.

FONTES: RANSOMWARE.LIVE + MALWAREBAZAAR / ABUSE.CH · CACHE 1H

14535 REGISTROS ENCONTRADOSFEED 2026-10-06
CVE-2026-96757CRITICAL

orval before 8.29.0 fails to escape OpenAPI media-type keys when emitting them into single-quoted Content-Type string literals in generated code. Attackers can inject JavaScript through crafted media-type keys in OpenAPI specifications that executes when generated fetch operations or mock resolvers are invoked.

AFFECTED SURFACEProduct not specified
CVSS 9.3EPSS 0.57%
CVE-2026-96756CRITICAL

orval versions before 8.30.0 contain a code injection vulnerability in the @orval/core factory generator that fails to escape date default values in new Date() calls. Attackers can inject arbitrary expressions through apostrophes in OpenAPI schema defaults to execute code with the privileges of the consumer process when factoryMethods and useDates options are enabled.

AFFECTED SURFACEProduct not specified
CVSS 9.2EPSS 0.48%
CVE-2026-96755CRITICAL

orval versions 8.14.0 through 8.28.1 contain a code injection vulnerability in the @orval/effect generator that converts OpenAPI schema defaults into template literals. Attackers can inject arbitrary JavaScript expressions via schema defaults containing ${...} syntax, which are executed at module scope when the generated code is built or imported.

AFFECTED SURFACEProduct not specified
CVSS 9.3EPSS 0.42%
CVE-2026-96754CRITICAL

orval versions before 8.29.0 contain a code injection vulnerability in the @orval/hono generator that fails to escape OpenAPI path values in single-quoted route literals. Attackers can craft an OpenAPI document with an apostrophe in a static path segment to inject arbitrary JavaScript code that executes when the generated TypeScript module is imported.

AFFECTED SURFACEProduct not specified
CVSS 9.3EPSS 0.43%
CVE-2026-96656HIGH

Plex Media Server before 1.43.3.10861 allows an admin user to write arbitrary files that may be executed on load. The preference TranscoderH264Options is appended verbatim to x264's option string on every transcode. At startup, all .so files are run without signature, execute bit, or symbol checks.

AFFECTED SURFACEProduct not specified
CVSS 8.6EPSS 0.34%
CVE-2026-96655MEDIUM

Plex Media Server before 1.43.3.10861 allows an authenticated user to request arbitrary internal or external addresses via the '/video/:/transcode/universal' path parameter.

AFFECTED SURFACEProduct not specified
CVSS 5.3EPSS 0.20%
CVE-2026-96654MEDIUM

Plex Media Server before 1.43.3.10861 does not correctly neutralize URL values included in 'searchOne,' allowing an attacker to call other plugins' functions and supply their own parameters.

AFFECTED SURFACEProduct not specified
CVSS 6.9EPSS 0.22%
CVE-2026-96652MEDIUM

Plex Media Server before 1.43.3.10861 allows SSRF via '/player/timeline'. An attacker using any X-Plex-Token value can include a full URL in the 'protocol' parameter and force the Plex server to POST to the attacker's chosen destination.

AFFECTED SURFACEProduct not specified
CVSS 5.3EPSS 0.20%
CVE-2026-96651HIGH

Plex Media Server before 1.43.3.10861 builds a file path from the url parameter without checking it for ../ sequences, allowing path traversal via '/system/agents/media/get'. A remote attacker with a valid session token could read any file that the target user can access. This access includes the PlexOnlineToken, which grants control of the Plex account and server. A LAN-adjacent attacker with a client-supplied X-Forwarded-For header could exploit the same issue.

AFFECTED SURFACEProduct not specified
CVSS 7.1EPSS 0.41%
CVE-2026-96514MEDIUM

A weakness has been identified in Neethuharii CafeManagement. Impacted is an unknown function of the file CafePortalLogin.php of the component Login Handler. This manipulation of the argument uname causes sql injection. It is possible to initiate the attack remotely. The exploit has been made available to the public and could be used for attacks. This product is using a rolling release to provide continious delivery. Therefore, no version details for affected nor updated releases are available. The vendor was contacted early about this disclosure but did not respond in any way.

AFFECTED SURFACEProduct not specified
CVSS 5.5EPSS 0.25%
CVE-2026-96513MEDIUM

A security flaw has been discovered in Neethuharii CafeManagement. This issue affects some unknown processing of the file AddProductCode.php. The manipulation of the argument image results in unrestricted upload. The attack may be performed from remote. The exploit has been released to the public and may be used for attacks. This product utilizes a rolling release system for continuous delivery, and as such, version information for affected or updated releases is not disclosed. The vendor was contacted early about this disclosure but did not respond in any way.

AFFECTED SURFACEProduct not specified
CVSS 5.5EPSS 0.28%
CVE-2026-95848CRITICAL

Moquette is a lightweight Java MQTT broker. Prior to 0.18.1, when a configured authenticator or authorizator class cannot be loaded, Server.initializeAuthenticator and Server.initializeAuthorizatorPolicy treat the failure as though no custom class was configured and fall back to AcceptAllAuthenticator or PermitAllAuthorizatorPolicy. A misspelled class name, missing dependency, constructor failure, or classpath problem can therefore start the broker with authentication or authorization disabled even though the operator configured those controls. This issue is fixed in version 0.18.1.

AFFECTED SURFACEmoquette moquette
CVSS 9.3EPSS 0.42%
CVE-2026-95847HIGH

Moquette is a lightweight Java MQTT broker. Prior to 0.18.1, H2PersistentQueue derives a session's message-map name as queue_ plus the client ID and its metadata-map name as queue_ plus the client ID plus _meta. A durable session whose client ID ends in _meta can therefore make its message map collide with another client's metadata map. The colliding sessions read and write the same H2 MVStore map with incompatible value types, which can corrupt queue head and tail data and cause message loss, misdelivery, failed queue reloads, or exposure of queued content across sessions. This issue is fixed in version 0.18.1.

AFFECTED SURFACEmoquette moquette
CVSS 8.8EPSS 0.34%
CVE-2026-95846HIGH

Moquette is a lightweight Java MQTT broker. Prior to 0.18.1, PostOffice.publishWill publishes a client's Last-Will message without applying the canWrite authorization and reserved-topic checks used for a normal PUBLISH. A client can configure a Will for a topic that the client is not permitted to write and cause the broker to publish the unauthorized message when the client disconnects unexpectedly. This issue allows unauthorized message injection into restricted topics. This issue is fixed in version 0.18.1.

AFFECTED SURFACEmoquette moquette
CVSS 8.7EPSS 0.27%
CVE-2026-95845HIGH

Moquette is a lightweight Java MQTT broker. Prior to 0.18.1, the broker does not enforce a maximum length for pending per-session message queues. When a fast publisher sends messages to a slow subscriber whose in-flight window is full, queued messages can accumulate without bound in memory or persistent storage. Remote clients can use this condition to exhaust broker resources and cause a denial of service. This issue is fixed in version 0.18.1.

AFFECTED SURFACEmoquette moquette
CVSS 8.7EPSS 0.36%
CVE-2026-95844HIGH

Moquette is a lightweight Java MQTT broker. Prior to 0.18.1, Moquette does not limit the depth of topic names and topic filters before processing them through recursive CTrie insertion and matching operations. A remote client can publish or subscribe with a deeply nested topic, causing a StackOverflowError that disrupts session processing and can deny service to broker clients. This issue is fixed in version 0.18.1.

AFFECTED SURFACEmoquette moquette
CVSS 8.7EPSS 0.36%
CVE-2026-95843HIGH

Moquette is a lightweight Java MQTT broker. Prior to 0.18.1, PostOffice.subscribe parses a shared-subscription filter through SharedSubscriptionUtils.extractShareName before validating the complete $share/{shareName}/{topicFilter} structure. A remote client can send a filter such as $share/grp without a topic-filter portion, causing a StringIndexOutOfBoundsException while calculating the share name. The exception terminates command handling on the shared session event loop and can deny service to other client sessions assigned to that loop. This issue is fixed in version 0.18.1.

AFFECTED SURFACEmoquette moquette
CVSS 8.7EPSS 0.43%
CVE-2026-95842HIGH

Moquette is a lightweight Java MQTT broker. Prior to 0.18.1, SessionEventLoop.run catches only InterruptedException, and SessionEventLoopGroup does not restart a terminated loop. An MQTT command that raises an uncaught exception can terminate an event loop shared by multiple client sessions, preventing every co-located client from processing PUBLISH, SUBSCRIBE, PUBACK, and other commands. An attacker can select client IDs that map across the available loops to disrupt session processing for the entire broker. This issue is fixed in version 0.18.1.

AFFECTED SURFACEmoquette moquette
CVSS 8.7EPSS 0.43%
CVE-2026-93349HIGH

Frictionless before 5.19.1 contains an OS command injection vulnerability in the explore console command that allows an attacker who supplies a crafted Data Package descriptor to execute arbitrary operating system commands as the user who explores it. Attackers can place shell metacharacters in resource path values within a datapackage.json descriptor, which are passed unsanitized to os.system through a shell, causing arbitrary command execution in the victim's security context when they run the explore command against the untrusted package. This vulnerability was also addressed in version 5.20.0rc2 of the pre-release branch.

AFFECTED SURFACEProduct not specified
CVSS 8.6EPSS 2.12%
CVE-2026-88832HIGH

BusyBox romfs volume ID parsing uses unbounded strlen on attacker-controlled metadata, causing a heap buffer overflow when processing crafted filesystem images.

AFFECTED SURFACEProduct not specified
CVSS 7.3EPSS 0.13%
CVE-2026-88830HIGH

A unit confusion in BusyBox TLS Montgomery reduction buffer allocation causes a pre-authentication heap buffer overflow when processing a crafted ClientKeyExchange message.

AFFECTED SURFACEProduct not specified
CVSS 7.5EPSS 0.35%
CVE-2026-85724CRITICAL

Moquette is a lightweight Java MQTT broker. Prior to 0.18.1, when pattern-based ACL rules are configured, AuthorizationsCollector.canDoOperation substitutes client ID and username values directly into rules containing %c or %u and then treats the result as an MQTT topic filter. A client that uses + or # in either identity can broaden the substituted filter and gain cross-tenant read and write access. A # identity can also produce an invalid filter that triggers a NullPointerException in Topic.match and disrupts session processing. This issue is fixed in version 0.18.1.

AFFECTED SURFACEmoquette moquette
CVSS 9.6EPSS 0.27%
CVE-2026-6669MEDIUM

Missing upper bound on the key derivation iteration count accepted during SCRAM authentication to a backend server in PgBouncer through 1.25.2 allows a malicious or compromised PostgreSQL backend to cause uncontrolled CPU consumption in PgBouncer. The resulting key derivation cannot be interrupted in frontend builds such as PgBouncer. Because PgBouncer serves all clients from a single process, one backend can in this way stop it from serving traffic for every other database and client it is pooling, so the failure of a single backend is not contained.

AFFECTED SURFACEProduct not specified
CVSS 5.9EPSS 0.31%
CVE-2026-6668HIGH

Integer overflow in the packet buffer growth logic in PgBouncer through 1.25.2 allows an unauthenticated remote attacker to cause a denial of service. Sufficiently large input makes the buffer size computation overflow, leaving the growth loop unable to terminate. Because PgBouncer serves all clients from a single process, this saturates a CPU core and stalls every pooled connection until the process is killed. Both unauthenticated and authenticated code paths can reach the overflow.

AFFECTED SURFACEProduct not specified
CVSS 7.5EPSS 0.40%