L/BLAB BOTSPUBLIC THREAT INTELLIGENCE NODE
CVE KNOWLEDGE BASE

Intelligence
Explorer.

Investigue vulnerabilidades por identificador, produto afetado ou descrição. Use severidade, CVSS e EPSS juntos para orientar a prioridade.

// THREAT ACTIVITY

Grupos & malware emergente

Atividade pública observada em leak sites e repositórios comunitários. Alegações de vítimas não representam confirmação independente de incidente.

RANSOMWARE GROUPSRECENT CLAIMS
qilin14 menções
incransom8 menções
safepay8 menções
Wallstreet7 menções
threeam7 menções
everest6 menções
emperador5 menções
medusalocker4 menções
thegentlemen4 menções
Panzer3 menções
INFOSTEALERSOBSERVED

Sem famílias correlacionadas no recorte recente.

RECENT RANSOMWARE CLAIMSRANSOMWARE.LIVE
netrunnerM*** P**** M***MY · Not Found · 2026-09-28
qilinArnold CenterUS · Not Found · 2026-09-28
threeamsafescaffolding.netGB · Manufacturing · 2026-09-28
threeamcoosalud.comCO · Healthcare · 2026-09-28
threeampistonespersan.com.arAR · Manufacturing · 2026-09-28
threeammidwestbit.comUS · Technology · 2026-09-28
threeamapexus.comUS · Technology · 2026-09-28
threeambhn-expertise.comDE · Professional Services · 2026-09-28
threeamstjames.wa.edu.auAU · Education · 2026-09-28
DoommageddonGoodrich Logistics— · Transportation · 2026-09-28
DoommageddonChem Process Systems Pvt. Ltd.IN · Manufacturing · 2026-09-28
playStarr Whitehouse Landscape ArchitectsUS · Professional Services · 2026-09-28
MALWARE FAMILIES / 7 DAYSMALWAREBAZAAR
Configure a Auth-Key gratuita do abuse.ch para habilitar detecções recentes do MalwareBazaar.

FONTES: RANSOMWARE.LIVE + MALWAREBAZAAR / ABUSE.CH · CACHE 1H

8621 REGISTROS ENCONTRADOSFEED 2026-09-22
CVE-2026-84071HIGH

IBM Guardium Data Protection 12.2 is vulnerable to OS command injection in the Universal Connector plugin upload functionality. A privileged authenticated attacker can provide a malicious filename that is incorporated into a shell command executed by the application, potentially resulting in arbitrary command execution with root-level privileges.

AFFECTED SURFACEProduct not specified
CVSS 7.2EPSS 1.45%
CVE-2026-84070HIGH

IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to execute arbitrary code due to improper neutralization of input during web page generation.

AFFECTED SURFACEProduct not specified
CVSS 8.9EPSS 0.32%
CVE-2026-84064CRITICAL

IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to execute arbitrary SQL commands due to improper neutralization of special elements used in an SQL command.

AFFECTED SURFACEProduct not specified
CVSS 9.9EPSS 0.37%
CVE-2026-84036HIGH

IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to bypass security restrictions due to improper authorization.

AFFECTED SURFACEProduct not specified
CVSS 7.4EPSS 0.26%
CVE-2026-84034HIGH

IBM Guardium Data Protection 12.2 is vulnerable to a hardcoded credentials vulnerability in the hardware_assess/obstore binaries. A low-privileged authenticated user can recover hardcoded product master secrets, potentially resulting in unauthorized access to the internal database and compromise of sensitive system information.

AFFECTED SURFACEProduct not specified
CVSS 8.8EPSS 0.25%
CVE-2026-84031CRITICAL

IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to execute arbitrary code due to improper neutralization of input during web page generation.

AFFECTED SURFACEProduct not specified
CVSS 9.0EPSS 0.33%
CVE-2026-82967CRITICAL

IBM Guardium Data Protection 12.2 is vulnerable to an authentication bypass that allows an unauthenticated remote attacker to bypass IP-based access controls and access the Guardium management interface.

AFFECTED SURFACEProduct not specified
CVSS 9.8EPSS 0.43%
CVE-2026-82896HIGH

IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to traverse directories on the system due to a path traversal vulnerability.

AFFECTED SURFACEProduct not specified
CVSS 7.6EPSS 0.36%
CVE-2026-82893HIGH

IBM Guardium Data Protection 12.2 could allow a local attacker to gain elevated privileges due to improper privilege management.

AFFECTED SURFACEProduct not specified
CVSS 7.8EPSS 0.11%
CVE-2026-82892HIGH

IBM Guardium Data Protection 12.2 could allow a remote attacker to execute arbitrary commands due to improper neutralization of special elements used in an OS command.

AFFECTED SURFACEProduct not specified
CVSS 8.1EPSS 0.39%
CVE-2026-82890MEDIUM

IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to execute arbitrary JavaScript code due to improper neutralization of input during web page generation.

AFFECTED SURFACEProduct not specified
CVSS 5.9EPSS 0.26%
CVE-2026-82887HIGH

IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to execute arbitrary commands due to improper neutralization of special elements used in an OS command.

AFFECTED SURFACEProduct not specified
CVSS 8.8EPSS 0.41%
CVE-2026-82885HIGH

IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to gain elevated privileges due to missing authorization in the REST API.

AFFECTED SURFACEProduct not specified
CVSS 8.8EPSS 0.28%
CVE-2026-82832CRITICAL

IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to execute arbitrary code due to improper neutralization of input during web page generation.

AFFECTED SURFACEProduct not specified
CVSS 9.6EPSS 0.38%
CVE-2026-82340CRITICAL

IBM Guardium Data Protection 12.2 is vulnerable to unauthenticated insecure deserialization and attacker-controlled reflective method dispatch in the Change Audit System (CAS) listener. A network attacker able to reach TCP port 16017 may submit crafted serialized messages and potentially cause unintended code execution in the Guardium appliance.

AFFECTED SURFACEProduct not specified
CVSS 9.8EPSS 0.51%
CVE-2026-81937HIGH

IBM Guardium Data Protection 12.2 is vulnerable to a command injection vulnerability in the import remotelog_config file CLI command. A highly privileged authenticated user can inject shell commands through the filename parameter, potentially resulting in arbitrary command execution with root privileges and impact to the confidentiality, integrity, and availability of the affected system.

AFFECTED SURFACEProduct not specified
CVSS 7.2EPSS 1.45%
CVE-2026-81933HIGH

IBM Guardium Data Protection 12.2 is vulnerable to a SQL injection vulnerability in the Analytic Grid Service Handler. A low-privileged authenticated user can inject SQL statements through the analytic cases grid endpoint, potentially resulting in unauthorized access to sensitive data and impact to the confidentiality, integrity, and availability of the affected system.

AFFECTED SURFACEProduct not specified
CVSS 8.8EPSS 0.32%
CVE-2026-81669HIGH

IBM Guardium Data Protection 12.2 is vulnerable to a command injection vulnerability in the create csr wildcard CLI command. An authenticated privileged CLI user can inject arbitrary shell commands through the alias input, resulting in command execution with root privileges.

AFFECTED SURFACEProduct not specified
CVSS 7.2EPSS 1.32%
CVE-2026-81657CRITICAL

IBM Guardium Data Protection 12.2 could allow a remote unauthenticated attacker to execute arbitrary code on the system due to the deserialization of untrusted data.

AFFECTED SURFACEProduct not specified
CVSS 9.8EPSS 0.58%
CVE-2026-81656HIGH

IBM Guardium Data Protection 12.2 is vulnerable to a SQL injection vulnerability in the New Query Builder REST Processor. A low-privileged authenticated user can inject SQL statements through the newQueryBuilder REST endpoint, potentially resulting in unauthorized access to data and impact to the confidentiality, integrity, and availability of the affected system.

AFFECTED SURFACEProduct not specified
CVSS 8.8EPSS 0.29%
CVE-2026-81626HIGH

IBM Guardium Data Protection 12.2 is vulnerable to a SQL injection vulnerability in the Load Balancer Groups component. An unauthenticated user can inject SQL statements through the Load Balancer Servlet endpoint, potentially resulting in unauthorized access to data and impact to the confidentiality, integrity, and availability of the affected system.

AFFECTED SURFACEProduct not specified
CVSS 8.6EPSS 0.27%
CVE-2026-81623MEDIUM

IBM Guardium Data Protection 12.2 could allow an authenticated user to execute arbitrary commands with low user privileges on the system due to improper validation of user supplied input.

AFFECTED SURFACEProduct not specified
CVSS 6.3EPSS 0.26%
CVE-2026-80442CRITICAL

IBM Guardium Data Protection 12.2 is vulnerable to an authenticated OS command injection vulnerability in the exportCertificate functionality. Successful exploitation could allow an attacker to execute unauthorized commands and impact the confidentiality, integrity, and availability of the affected system.

AFFECTED SURFACEProduct not specified
CVSS 9.9EPSS 0.63%
CVE-2026-80441CRITICAL

IBM Guardium Data Protection 12.2 is vulnerable to an unauthenticated second-order SQL injection vulnerability in the generateInsertQuery functionality of change-tracker-data.sql. A remote attacker could inject malicious SQL that is subsequently processed by the application, potentially resulting in compromise of the confidentiality, integrity, and availability of the affected system.

AFFECTED SURFACEProduct not specified
CVSS 9.8EPSS 0.38%