L/BLAB BOTSPUBLIC THREAT INTELLIGENCE NODE
CVE KNOWLEDGE BASE

Intelligence
Explorer.

Investigue vulnerabilidades por identificador, produto afetado ou descrição. Use severidade, CVSS e EPSS juntos para orientar a prioridade.

// THREAT ACTIVITY

Grupos & malware emergente

Atividade pública observada em leak sites e repositórios comunitários. Alegações de vítimas não representam confirmação independente de incidente.

RANSOMWARE GROUPSRECENT CLAIMS
thegentlemen23 menções
qilin11 menções
UmBra9 menções
Eclipse5 menções
SilentRansomGroup5 menções
Panzer4 menções
incransom4 menções
Black X3 menções
akira3 menções
arcusmedia3 menções
INFOSTEALERSOBSERVED

Sem famílias correlacionadas no recorte recente.

RECENT RANSOMWARE CLAIMSRANSOMWARE.LIVE
dragonforceTEXMA International Co., LtdTW · Manufacturing · 2026-10-10
thegentlemenRoyal Thai Air ForceTH · Government & Defense · 2026-10-10
UmBraHelwan University (HITU)EG · Education · 2026-10-10
RedactDexComUS · Healthcare · 2026-10-10
qilinACI Proyectos SASCO · Other · 2026-10-10
exitiumKOIKE Sanso Kogoyo Co. Ltd.JP · Manufacturing · 2026-10-10
rhysidaGress Clark Young & SchoepperUS · Professional Services · 2026-10-10
qilinGlenhardie Country ClubUS · Hospitality · 2026-10-10
qilinLD ConstructoraCL · Manufacturing · 2026-10-10
DeadlockSaber1US · Not Found · 2026-10-09
Deadlockidi pharmaES · Healthcare · 2026-10-09
safepayhoteldelfinolugano.chCH · Hospitality · 2026-10-09
MALWARE FAMILIES / 7 DAYSMALWAREBAZAAR
Configure a Auth-Key gratuita do abuse.ch para habilitar detecções recentes do MalwareBazaar.

FONTES: RANSOMWARE.LIVE + MALWAREBAZAAR / ABUSE.CH · CACHE 1H

14535 REGISTROS ENCONTRADOSFEED 2026-10-06
CVE-2026-88416ANALYSIS

MCMS 6.1.1 through 6.2.1 has a SQL injection vulnerability in the custom model/form import feature.

AFFECTED SURFACEProduct not specified
CVSS N/DEPSS 0.19%
CVE-2026-88350ANALYSIS

An integer overflow vulnerability exists in MPack 1.1.1 in mpack_node_cstr_alloc() and mpack_node_utf8_cstr_alloc().

AFFECTED SURFACEProduct not specified
CVSS N/DEPSS 0.15%
CVE-2026-88345HIGH

An out-of-bounds read vulnerability exists in the schema lexer of flatcc 4c3b999e. When an exact-length FlatBuffers schema ends with an unterminated quotation mark, the C-string scanning logic in lex() dereferences the input pointer after it has reached the end of the buffer. A specially crafted schema can trigger a one-byte heap buffer over-read, resulting in application crash and denial of service.

AFFECTED SURFACEProduct not specified
CVSS 7.5EPSS 0.41%
CVE-2026-88344HIGH

An out-of-bounds read vulnerability exists in the schema lexer of flatcc 4c3b999e. When an exact-length FlatBuffers schema buffer ends with a digit, the integer digit-scan loop in lex() advances past the end of the input buffer and dereferences the out-of-bounds pointer. A specially crafted schema can trigger a one-byte heap buffer over-read, resulting in application crash and denial of service.

AFFECTED SURFACEProduct not specified
CVSS 7.5EPSS 0.40%
CVE-2026-88341MEDIUM

A reachable assertion vulnerability exists in YARA 4.5.8 when loading crafted .yrc compiled rule files. An attacker can provide a malicious file with an invalid arena configuration (num_buffers=0) that triggers an assertion failure in yr_arena_get_ptr(), causing the application to terminate.

AFFECTED SURFACEProduct not specified
CVSS 5.5EPSS 0.17%
CVE-2026-88340HIGH

An invalid pointer release vulnerability exists in YARA 4.5.8 during deserialization of compiled .yrc rule files. The vulnerability is caused by insufficient validation of external-variable pointers, which may lead to invalid free in yr_rules_destroy() or wild pointer access in yr_object_create(). An attacker can provide a specially crafted .yrc file that causes memory corruption and application crash.

AFFECTED SURFACEProduct not specified
CVSS 7.6EPSS 0.25%
CVE-2026-88339MEDIUM

A NULL pointer dereference vulnerability exists in the gf_sg_vrml_field_clone() function of GPAC 2d7da22e (26.08-DEV). The vulnerability occurs when cloning a PROTO default SFImage field with a NULL source pointer. An attacker can provide a specially crafted input file that triggers the condition, resulting in application crash and denial of service.

AFFECTED SURFACEProduct not specified
CVSS 5.5EPSS 0.17%
CVE-2026-87121CRITICAL

lwIP TCP/IP Stack MQTT is vulnerable to an out-of-bounds write, which may allow an attacker to gain full code execution on the device.

AFFECTED SURFACEProduct not specified
CVSS 9.3EPSS 0.53%
CVE-2026-83805MEDIUM

Nautobot is a Network Source of Truth and Network Automation Platform. From 3.0.0 until 3.1.8, the generic ApprovalWorkflowStageResponse create endpoint does not enforce approver-group membership, change permission on the object under review, or the one-response-per-user restriction applied by the intended approve and deny actions. A user with only extras.add_approvalworkflowstageresponse can submit approved responses directly, while writable user and state fields permit responses to be attributed to arbitrary users. These forged responses can satisfy min_approvers, approve the workflow, and activate its gated ScheduledJob without a legitimate approver. This issue is fixed in version 3.1.8.

AFFECTED SURFACEProduct not specified
CVSS 6.4EPSS 0.22%
CVE-2026-83801MEDIUM

Nautobot is a Network Source of Truth and Network Automation Platform. Prior to 2.4.37 and 3.1.8, a user with extras.add_relationship or extras.change_relationship permission can store HTML or JavaScript in a Relationship description, and a user with dcim.add_modulefamily or dcim.change_modulefamily permission can store it in a Module Family name. Nautobot assigns these values to form field help_text rendered by render_field.html through Django's |safe filter without adequate neutralization. The stored content executes in the authenticated browser session of any user, including an administrator or superuser, who opens an affected create or edit form. This can enable actions as the victim, session or token theft, and further privilege escalation. This issue is fixed in versions 2.4.37 and 3.1.8.

AFFECTED SURFACEProduct not specified
CVSS 5.4EPSS 0.22%
CVE-2026-79767MEDIUM

Gardener implements the automated management and operation of Kubernetes clusters as a service. Prior to 1.142.6, 1.143.3, 1.144.2, and 1.145.0, the customverbauthorizer admission plugin's mustCheckProjectMembers manage-members check compares changes to User subjects but does not account for Group or ServiceAccount subjects in Project.spec.members. A project administrator who lacks manage-members permission can add arbitrary Group or ServiceAccount subjects, including the system:authenticated Group, and thereby grant broad project access. The resulting access can include Shoots, Secrets, and cloud provider credentials. This issue is fixed in versions 1.142.6, 1.143.3, 1.144.2, and 1.145.0.

AFFECTED SURFACEProduct not specified
CVSS 5.5EPSS 0.39%
CVE-2026-77322HIGH

SIPGO is a library for writing SIP services in the GO language. Prior to 1.4.3, WSConnection.Read in sip/transport_ws.go creates a wsutil.Reader without setting MaxFrameSize, allowing NextFrame to accept a client-controlled header.Length before ParseMaxMessageLength is applied. An unauthenticated WS or WSS peer can send a frame header declaring an extremely large payload, causing an oversized allocation or a makeslice length panic before the payload is read and crashing or exhausting memory in the server process. This issue is fixed in version 1.4.3.

AFFECTED SURFACEProduct not specified
CVSS 7.5EPSS 0.52%
CVE-2026-76717MEDIUM

A vulnerability exists in the Analytics and Location Engine (ALE) API that may allow for the disclosure of sensitive information. An unauthenticated remote attacker could exploit this vulnerability by providing specially crafted input to a specific API endpoint. Successful exploitation could result in the disclosure of sensitive user information, including password hashes, which could be used to facilitate further attacks.

AFFECTED SURFACEarubanetworks analytics and location engine
CVSS 5.3EPSS 0.42%
CVE-2026-76716MEDIUM

Multiple vulnerabilities exist in the Analytics and Location Engine (ALE) that may allow for unauthorized access or denial of service. An unauthenticated remote attacker could exploit these vulnerabilities by sending specially crafted input or leveraging improper security configurations. Successful exploitation could result in a denial of service condition or unauthorized access to sensitive information.

AFFECTED SURFACEarubanetworks analytics and location engine
CVSS 5.3EPSS 0.51%
CVE-2026-76715HIGH

A vulnerability in an administrative component of Analytics and Location Engine (ALE) is vulnerable to a man-in-the-middle (MitM) attack. Successful exploitation of this vulnerability could allow an unauthenticated remote attacker to execute arbitrary code with root privileges on the affected appliance.

AFFECTED SURFACEarubanetworks analytics and location engine
CVSS 7.1EPSS 0.26%
CVE-2026-76714HIGH

Vulnerabilities in the Analytics and Location Engine web interface allows remote authenticated users to run arbitrary commands on the underlying host. A successful exploit could allow an attacker to execute arbitrary commands as root on the underlying operating system leading to complete system compromise.

AFFECTED SURFACEarubanetworks analytics and location engine
CVSS 7.2EPSS 0.84%
CVE-2026-76713HIGH

A vulnerability exists in the maintenance restore functionality of Analytics and Location Engine (ALE). Successful exploitation of this vulnerability could allow an authenticated remote attacker to gain unauthorized access to the file system with root privileges, potentially resulting in full system compromise.

AFFECTED SURFACEarubanetworks analytics and location engine
CVSS 7.2EPSS 0.55%
CVE-2026-76712HIGH

A vulnerability exists in the Analytics and Location Engine (ALE) that may allow for unauthorized access, information disclosure, or denial of service. An unauthenticated remote attacker could exploit the vulnerable system by sending specially crafted input or intercepting network communications. Successful exploitation could result in the disclosure of sensitive information, bypass of security controls, or a denial of service condition on the affected system.

AFFECTED SURFACEarubanetworks analytics and location engine
CVSS 7.3EPSS 0.41%
CVE-2026-76711HIGH

A vulnerability exists in an Analytics and Location Engine (ALE) component where the impacted process improperly processes incoming socket connections. An unauthenticated remote attacker could exploit this vulnerability by providing specially crafted input during the connection process. Successful exploitation could result in unauthorized data injection.

AFFECTED SURFACEarubanetworks analytics and location engine
CVSS 7.5EPSS 0.46%
CVE-2026-76710HIGH

A vulnerability exists in the Analytics and Location Engine (ALE) management interface that may allow for the disclosure of sensitive information. An unauthenticated remote attacker could exploit this vulnerability by sending specially crafted requests to certain internal endpoints. Successful exploitation could result in the disclosure of sensitive site hierarchy, infrastructure details, and client device information.

AFFECTED SURFACEarubanetworks analytics and location engine
CVSS 7.5EPSS 0.54%
CVE-2026-76709CRITICAL

A vulnerability exists in the internal administrative component of Analytics and Location Engine (ALE). Successful exploitation of this vulnerability could allow an unauthenticated remote attacker to gain unauthorized write access to the file system with elevated privileges, potentially resulting in full system compromise.

AFFECTED SURFACEarubanetworks analytics and location engine
CVSS 9.8EPSS 0.59%
CVE-2026-76708CRITICAL

A vulnerability exists in the Analytics and Location Engine (ALE) where the application and underlying operating system use default, hard-coded credentials for several administrative and system accounts. An unauthenticated remote attacker could exploit this vulnerability by attempting to log in using these known default credentials. Successful exploitation could result in an attacker gaining unauthorized access to the application's management interface and the underlying operating system, potentially leading to full system compromise.

AFFECTED SURFACEarubanetworks analytics and location engine
CVSS 9.8EPSS 0.59%
CVE-2026-75432ANALYSIS

An issue in yaml-cpp 0.9.0 allows a remote attacker to obtain sensitive information via the src/scanner.cpp, Scanner::PopIndent(), and Scanner::PushIndentTo() components

AFFECTED SURFACEProduct not specified
CVSS N/DEPSS 0.22%
CVE-2026-65829MEDIUM

MPXJ is an open source library to read and write project plans from a variety of file formats and databases. From 7.3.0 until 16.5.0, reading a suitably crafted Primavera P3 PRX or SureTrak STX file can cause MPXJ to write files to arbitrary locations in the filesystem. This issue is fixed in version 16.5.0.

AFFECTED SURFACEProduct not specified
CVSS 5.3EPSS 0.34%