L/BLAB BOTSPUBLIC THREAT INTELLIGENCE NODE
CVE KNOWLEDGE BASE

Intelligence
Explorer.

Investigue vulnerabilidades por identificador, produto afetado ou descrição. Use severidade, CVSS e EPSS juntos para orientar a prioridade.

// THREAT ACTIVITY

Grupos & malware emergente

Atividade pública observada em leak sites e repositórios comunitários. Alegações de vítimas não representam confirmação independente de incidente.

RANSOMWARE GROUPSRECENT CLAIMS
qilin14 menções
incransom8 menções
safepay8 menções
Wallstreet7 menções
threeam7 menções
everest6 menções
emperador5 menções
medusalocker4 menções
thegentlemen4 menções
Panzer3 menções
INFOSTEALERSOBSERVED

Sem famílias correlacionadas no recorte recente.

RECENT RANSOMWARE CLAIMSRANSOMWARE.LIVE
netrunnerM*** P**** M***MY · Not Found · 2026-09-28
qilinArnold CenterUS · Not Found · 2026-09-28
threeamsafescaffolding.netGB · Manufacturing · 2026-09-28
threeamcoosalud.comCO · Healthcare · 2026-09-28
threeampistonespersan.com.arAR · Manufacturing · 2026-09-28
threeammidwestbit.comUS · Technology · 2026-09-28
threeamapexus.comUS · Technology · 2026-09-28
threeambhn-expertise.comDE · Professional Services · 2026-09-28
threeamstjames.wa.edu.auAU · Education · 2026-09-28
DoommageddonGoodrich Logistics— · Transportation · 2026-09-28
DoommageddonChem Process Systems Pvt. Ltd.IN · Manufacturing · 2026-09-28
playStarr Whitehouse Landscape ArchitectsUS · Professional Services · 2026-09-28
MALWARE FAMILIES / 7 DAYSMALWAREBAZAAR
Configure a Auth-Key gratuita do abuse.ch para habilitar detecções recentes do MalwareBazaar.

FONTES: RANSOMWARE.LIVE + MALWAREBAZAAR / ABUSE.CH · CACHE 1H

8621 REGISTROS ENCONTRADOSFEED 2026-09-22
CVE-2026-11381HIGH

IBM MQ could allow an authenticated attacker to cause a denial of service or potentially execute arbitrary code due to improper validation of message distribution list structures.

AFFECTED SURFACEProduct not specified
CVSS 8.8EPSS 0.59%
CVE-2026-11378HIGH

IBM MQ could allow an authenticated attacker to cause a denial of service or potentially execute arbitrary code due to an integer overflow in distribution list processing.

AFFECTED SURFACEProduct not specified
CVSS 8.8EPSS 0.59%
CVE-2026-11375HIGH

IBM MQ could allow an authenticated attacker to cause a denial of service or potentially execute arbitrary code due to a stack buffer overflow when processing XA transaction identifiers.

AFFECTED SURFACEProduct not specified
CVSS 8.8EPSS 0.60%
CVE-2026-10858CRITICAL

IBM MQ for HPE NonStop 8.1.0 through 8.1.0.40 could allow an authenticated attacker to cause a denial of service or potentially execute arbitrary code due to a heap buffer underflow when processing multi-segment messages.

AFFECTED SURFACEProduct not specified
CVSS 9.9EPSS 0.33%
CVE-2026-10853HIGH

IBM MQ could allow an authenticated attacker with cluster access to cause a denial of service or potentially execute arbitrary code due to improper validation of cluster command message lengths.

AFFECTED SURFACEProduct not specified
CVSS 7.5EPSS 0.36%
CVE-2026-10841MEDIUM

IBM WebSphere Application Server 8.5, 9.0, and Liberty are vulnerable to HTTP request smuggling.

AFFECTED SURFACEProduct not specified
CVSS 4.2EPSS 0.21%
CVE-2026-10751HIGH

IBM MQ Java and JMS client libraries could allow an authenticated attacker to execute arbitrary code on client applications due to a deserialization filter bypass in exception handling.

AFFECTED SURFACEProduct not specified
CVSS 7.5EPSS 0.51%
CVE-2026-10747CRITICAL

IBM MQ Appliance could allow a remote attacker to cause a denial of service or potentially execute arbitrary code due to a heap buffer overflow in protocol message processing before authentication.

AFFECTED SURFACEProduct not specified
CVSS 10.0EPSS 0.52%
CVE-2026-10744HIGH

IBM MQ for HPE NonStop 8.1.0 through 8.1.0.40 could allow an authenticated attacker to cause a denial of service or potentially escalate privileges due to an integer overflow in MQINQ request validation.

AFFECTED SURFACEProduct not specified
CVSS 7.5EPSS 0.27%
CVE-2026-10575HIGH

IBM MQ could allow an authenticated attacker to cause a denial of service or potentially escalate privileges due to a heap buffer overflow when processing MQPUT operations with malformed distribution headers.

AFFECTED SURFACEProduct not specified
CVSS 8.8EPSS 0.48%
CVE-2026-10030HIGH

IBM MQ Console allows authenticated non-administrative users to create and start queue managers due to improper authorization checks.

AFFECTED SURFACEProduct not specified
CVSS 7.1EPSS 0.23%
CVE-2026-10027HIGH

IBM MQ could allow a remote attacker to cause a denial of service or execute arbitrary code due to a buffer overflow when processing malformed compressed data on channels configured with compression enabled.

AFFECTED SURFACEProduct not specified
CVSS 8.1EPSS 0.37%
CVE-2025-61682HIGH

Semantic MediaWiki is a free, open-source extension to MediaWiki that lets users store and query data within the wiki's pages. Versions starting in 3.1.0 and prior to 7.0.0 insert the unsanitized value of a data attribute into the DOM as HTML, allowing for stored XSS through wikitext. Version 7.0.0 patches the issue.

AFFECTED SURFACEProduct not specified
CVSS 8.6EPSS 0.29%
CVE-2025-53837CRITICAL

XWiki Rendering is a generic rendering system that converts textual input in a given syntax (wiki syntax, HTML, etc) into another syntax (XHTML, etc). Prior to versions 14.10.2 and 15.0 RC1, any user who can edit their own user profile or any other document can execute arbitrary script macros including Groovy and Python macros that allow remote code execution including unrestricted read and write access to all wiki contents. The reason is that rendering output is included as content of HTML macros without further escaping and it is thus possible to close the HTML macro and inject script macros that are executed with programming rights. This has been patched in XWiki 14.10.2 and 15.0 RC1 by making sure that rendering output cannot close the surrounding HTML macro. A possible workaround is available. It is, in principle, possible to add escaping to all places where rendering output is used in wiki documents, but at the moment there is no list of them.

AFFECTED SURFACEProduct not specified
CVSS 9.9EPSS 0.64%
CVE-2025-36421MEDIUM

IBM Controller 11.0.0 through 11.0.1 FP7, and 11.1.0 through 11.1.3 FP1 transmits data in clear text that could allow an attacker to obtain sensitive information using man in the middle techniques.

AFFECTED SURFACEProduct not specified
CVSS 5.9EPSS 0.20%
CVE-2025-36178MEDIUM

IBM Controller 11.0.0 through 11.0.1 FP7, and 11.1.0 through 11.1.3 FP1 could allow an authenticated user to bypass input validation due to improper validation of client-side input of file size.

AFFECTED SURFACEProduct not specified
CVSS 5.4EPSS 0.34%
CVE-2025-36147MEDIUM

IBM Financial Transaction Manager for SWIFT Services for Multiplatforms 3.2.4.0 through 3.2.4.16 is vulnerable to cross-site scripting. This vulnerability allows an unauthenticated attacker to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.

AFFECTED SURFACEProduct not specified
CVSS 6.1EPSS 0.27%
CVE-2025-36076MEDIUM

IBM Cognos Analytics 12.1.0 through 12.1.3 FP1, and 12.0.4 through 12.0.4 FP2 stores sensitive information in source code could be used by an authenticated user in further attacks against the system.

AFFECTED SURFACEProduct not specified
CVSS 4.3EPSS 0.29%
CVE-2025-36045MEDIUM

IBM TS4300 1.1.0.1 through 1.7.1.1 could allow an authenticated user to cause a denial of service in the email service due to improper control of interaction frequency.

AFFECTED SURFACEProduct not specified
CVSS 4.3EPSS 0.26%
CVE-2025-33147MEDIUM

IBM Cognos Analytics 12.1.0 through 12.1.3 FP1, and 12.0.4 through 12.0.4 FP2 could allow an attacker on a shared network to obtain sensitive information caused by insecure network communication.

AFFECTED SURFACEProduct not specified
CVSS 5.9EPSS 0.21%
CVE-2025-33141MEDIUM

IBM QRadar 7.5.0 through 7.5.0 UP15 Interim Fix 006 could allow an authenticated user to obtain sensitive information from backup files due to incorrect permissions assignment.

AFFECTED SURFACEProduct not specified
CVSS 6.5EPSS 0.38%
CVE-2025-15399CRITICAL

IBM Common Licensing Agent 9.0, Agent 9.0.0.1, Agent 9.0.0.2, ART 9.0, ART 9.0.0.1, and ART 9.0.0.2 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts.

AFFECTED SURFACEProduct not specified
CVSS 10.0EPSS 0.25%
CVE-2025-14754HIGH

IBM Cloud Pak for Data 5.1.2 could allow an authenticated user to execute arbitrary commands with elevated privileges on the system due to improper validation of user supplied input.

AFFECTED SURFACEibm cloud pak for data
CVSS 8.8EPSS 0.65%
CVE-2025-14753HIGH

IBM Cloud Pak for Data 5.1.2 could allow a remote attacker to traverse directories on the system. An attacker could send a specially crafted URL request containing "dot dot" sequences (/../) to view arbitrary files on the system.

AFFECTED SURFACEProduct not specified
CVSS 7.5EPSS 0.62%