L/BLAB BOTSPUBLIC THREAT INTELLIGENCE NODE
CVE KNOWLEDGE BASE

Intelligence
Explorer.

Investigue vulnerabilidades por identificador, produto afetado ou descrição. Use severidade, CVSS e EPSS juntos para orientar a prioridade.

// THREAT ACTIVITY

Grupos & malware emergente

Atividade pública observada em leak sites e repositórios comunitários. Alegações de vítimas não representam confirmação independente de incidente.

RANSOMWARE GROUPSRECENT CLAIMS
qilin14 menções
incransom8 menções
safepay8 menções
Wallstreet7 menções
threeam7 menções
everest6 menções
emperador5 menções
medusalocker4 menções
thegentlemen4 menções
Panzer3 menções
INFOSTEALERSOBSERVED

Sem famílias correlacionadas no recorte recente.

RECENT RANSOMWARE CLAIMSRANSOMWARE.LIVE
netrunnerM*** P**** M***MY · Not Found · 2026-09-28
qilinArnold CenterUS · Not Found · 2026-09-28
threeamsafescaffolding.netGB · Manufacturing · 2026-09-28
threeamcoosalud.comCO · Healthcare · 2026-09-28
threeampistonespersan.com.arAR · Manufacturing · 2026-09-28
threeammidwestbit.comUS · Technology · 2026-09-28
threeamapexus.comUS · Technology · 2026-09-28
threeambhn-expertise.comDE · Professional Services · 2026-09-28
threeamstjames.wa.edu.auAU · Education · 2026-09-28
DoommageddonGoodrich Logistics— · Transportation · 2026-09-28
DoommageddonChem Process Systems Pvt. Ltd.IN · Manufacturing · 2026-09-28
playStarr Whitehouse Landscape ArchitectsUS · Professional Services · 2026-09-28
MALWARE FAMILIES / 7 DAYSMALWAREBAZAAR
Configure a Auth-Key gratuita do abuse.ch para habilitar detecções recentes do MalwareBazaar.

FONTES: RANSOMWARE.LIVE + MALWAREBAZAAR / ABUSE.CH · CACHE 1H

8621 REGISTROS ENCONTRADOSFEED 2026-09-22
CVE-2026-93589MEDIUM

ImageMagick before 7.1.2-31 and 6.9.13-56 contains a division-by-zero flaw in the FLIF encoder. An incorrect value for ticks per second in the image being encoded causes a divide-by-zero and crashes the encoder, resulting in a denial of service. The issue is fixed in 7.1.2-31 and 6.9.13-56.

AFFECTED SURFACEProduct not specified
CVSS 6.3EPSS 0.29%
CVE-2026-93588LOW

ImageMagick before 7.1.2-31 and before 6.9.13-56 contains a NULL pointer dereference in the PNM coder. When the coder reaches a memory (resource) limit at a specific point during processing, the failed allocation is not handled and a NULL pointer is dereferenced, which can lead to a denial of service (application crash) when processing a specially crafted or sufficiently large PNM image.

AFFECTED SURFACEProduct not specified
CVSS 2.3EPSS 0.26%
CVE-2026-93587MEDIUM

ImageMagick before 7.1.2-31 and before 6.9.13-56 contains a policy bypass in the PCD (and, per the upstream advisory, CUBE and HALD) coder: when a specific command line option is supplied, the decoder does not check a configured resource limit, which can result in extra memory allocation. A local user able to pass command line options to ImageMagick can therefore exceed the intended memory policy limit, causing a limited availability impact. The issue is fixed in 7.1.2-31 and 6.9.13-56.

AFFECTED SURFACEProduct not specified
CVSS 4.8EPSS 0.11%
CVE-2026-93586LOW

ImageMagick before 7.1.2-31 and before 6.9.13-56 contains a use-after-free vulnerability in the ImagesToBlob method, caused by a pointer that is not updated correctly. Exploitation may result in a limited availability impact (e.g., a crash of the affected process). The issue is fixed in versions 7.1.2-31 and 6.9.13-56.

AFFECTED SURFACEProduct not specified
CVSS 2.1EPSS 0.11%
CVE-2026-93560HIGH

A flaw was found in the Netty STOMP codec. A remote attacker could send a specially crafted STOMP frame with a content-length header exceeding the maximum integer value. This integer truncation vulnerability could lead to an infinite decode loop, causing a Denial of Service (DoS) by exhausting memory and CPU resources.

AFFECTED SURFACEProduct not specified
CVSS 7.5EPSS 0.41%
CVE-2026-93504MEDIUM

A vulnerability has been found in SveltyCMS 0.0.6. This affects an unknown part of the file src/routes/api/[...path]/+server.ts of the component User Attribute Update Endpoint. Such manipulation leads to improper access controls. It is possible to launch the attack remotely. The name of the patch is 05b4f9efeb79e9d72a693232334d7529687f896f. It is advisable to implement a patch to correct this issue.

AFFECTED SURFACEProduct not specified
CVSS 5.3EPSS 0.35%
CVE-2026-93019CRITICAL

Imager versions before 1.036 for Perl exit the process reading a TGA with a colour map length of 32768 or more in tga_palette_read. The reader unpacks the two-byte colour map length into a signed short, so a length of 32768 or more becomes negative. tga_palette_read() casts that value to size_t and asks mymalloc() for a size near SIZE_MAX. The allocation fails and Imager's allocator calls exit(3). Reading an attacker-supplied file through Imager->read() triggers an uncatchable exit.

AFFECTED SURFACEProduct not specified
CVSS 9.1EPSS 0.61%
CVE-2026-93018ANALYSIS

Imager versions before 1.036 for Perl disclose uninitialised heap memory reading a paletted image with pixel indexes past its colour map in i_gpix_p and i_glin_p. The palette is allocated uninitialised, and only the entries a reader adds count as populated. The TGA reader stores pixel indexes without checking them against the colour map. i_gpix_p() rejects only an index greater than the count, so an index equal to it reads the first unpopulated entry, and getpixel() returns it. i_glin_p() skips any index at or beyond the count without writing that pixel to the caller's buffer. The palette-to-RGB conversion reads each row through an uninitialised buffer, so those pixels of the converted image hold prior heap contents. Reading an attacker-supplied image through Imager->read() and then fetching its pixels or converting it to RGB discloses process heap memory.

AFFECTED SURFACEProduct not specified
CVSS N/DEPSS 0.18%
CVE-2026-88623ANALYSIS

NUUO Network Video Recorder 2.0.0 is vulnerable to arbitrary file read. In up.php, the url parameter submitted by the user via POST is received, and fopen() is used to open the URL in binary read-only mode. The content is then written to the /tmp/ directory, with the filename derived from basename() of the URL. This operation requires no authentication.

AFFECTED SURFACEProduct not specified
CVSS N/DEPSS 0.20%
CVE-2026-88622HIGH

NUUO Network Video Recorder 2.0.0 is vulnerable to Command Injection in handle_import_privilege.php.

AFFECTED SURFACEProduct not specified
CVSS 8.8EPSS 1.09%
CVE-2026-79294MEDIUM

Cross Site Scripting vulnerability in Moonshot AI Kimi version as of 2026-07-18 allows a remote attacker to execute arbitrary code via the HTML artifact Preview rendering; public Share view component

AFFECTED SURFACEProduct not specified
CVSS 6.1EPSS 0.51%
CVE-2026-62282MEDIUM

OpenCVE is a vulnerability intelligence platform. Prior to 3.0.0, OpenCVE notification testing for Webhook and Slack integrations does not sufficiently validate user-supplied HTTP or HTTPS destinations. An authenticated user with permission to configure notification channels can trigger requests to hosts reachable from the OpenCVE server, including internal network resources, localhost interfaces, link-local addresses, and cloud metadata services, and retrieve information from reachable HTTP services. This issue is fixed in version 3.0.0.

AFFECTED SURFACEProduct not specified
CVSS 6.5EPSS 0.33%
CVE-2023-5778CRITICAL

Improper handling of length parameter inconsistency vulnerability in ABB Freelance Controller DCP, ABB Freelance Controller AC700, ABB Freelance Controller AC800, and ABB Freelance Controller AC900. This issue affects Freelance Controller DCP: through 2013, 2013 SP1, 2016, 2016 SP1, 2019, and 2019 SP1; Freelance Controller AC700: through 2013, 2013 SP1, 2016, 2016 SP1, 2019, and 2019 SP1; Freelance Controller AC800: through 2013, 2013 SP1, 2016, 2016 SP1, 2019, and 2019 SP1; Freelance Controller AC900: through 2013, 2013 SP1, 2016, 2016 SP1, 2019, and 2019 SP1.

AFFECTED SURFACEProduct not specified
CVSS 9.2EPSS 0.29%
CVE-2026-93492MEDIUM

A flaw was found in Netty's HTTP/2 HpackEncoder. A remote attacker can exploit this by sending HTTP/2 SETTINGS frames with a very large MAX_HEADER_TABLE_SIZE. This causes the HpackEncoder to store an excessive number of unique headers, leading to increased CPU usage and memory consumption, ultimately resulting in a Denial of Service (DoS).

AFFECTED SURFACEProduct not specified
CVSS 5.3EPSS 0.30%
CVE-2026-93491HIGH

A flaw was found in Netty's HttpServerCodec. A remote, unauthenticated attacker can exploit this vulnerability by pipelining HTTP/1.1 requests on a single connection and withholding reads. This action causes the methodOverflowQueue to grow without limit, leading to unbounded heap memory consumption and a denial of service due to memory exhaustion.

AFFECTED SURFACEProduct not specified
CVSS 7.5EPSS 0.44%
CVE-2026-93488HIGH

A flaw was found in Netty. SpdySessionHandler accepts an unlimited number of concurrent remote-initiated streams because localConcurrentStreams defaults to Integer.MAX_VALUE and the handler provides no API to change it. A remote peer can open a SPDY connection and send a large number of SYN_STREAM frames with FLAG_FIN=0, causing unbounded heap and direct memory allocation that can lead to JVM OutOfMemoryError and a denial of service.

AFFECTED SURFACEProduct not specified
CVSS 7.5EPSS 0.46%
CVE-2026-28199MEDIUM

An authenticated user with access to the NetBackup Flex OS management shell could read arbitrary files from the underlying operating system by supplying a specially crafted path argument to a diagnostic command. Successful exploitation could expose sensitive system configuration and credential material stored on the appliance.

AFFECTED SURFACEProduct not specified
CVSS 4.8EPSS 0.07%
CVE-2026-28198CRITICAL

An authenticated, low-privileged user with access to the NetBackup Flex OS management shell could bypass the cryptographic signature verification step of a privileged support command by supplying a specially formed access credential. Successful exploitation grants the attacker an unrestricted root shell with full control over the Flex appliance host and all hosted containers, completely compromising confidentiality, integrity, and availability.

AFFECTED SURFACEProduct not specified
CVSS 9.4EPSS 0.20%
CVE-2026-28197CRITICAL

An authenticated, low-privileged user with access to the NetBackup Flex OS management shell could supply a specially crafted input to a privileged administrative command, causing it to execute arbitrary code with root-level permissions. Successful exploitation grants the attacker unrestricted control over the Flex appliance host and all hosted containers, fully compromising confidentiality, integrity, and availability.

AFFECTED SURFACEProduct not specified
CVSS 9.4EPSS 0.37%
CVE-2026-21806LOW

HCL BigFix Service Management is affected by an Administrative Session Concurrency vulnerability. The application allows multiple simultaneous authenticated sessions for the same administrative account, which could enable an unauthorized attacker to predict or hijack valid session identifiers. Successful exploitation allows an attacker to compromise affected administrative sessions and execute actions with full privileged user permissions.

AFFECTED SURFACEProduct not specified
CVSS 3.1EPSS 0.15%
CVE-2026-93578MEDIUM

A flaw was found in Netty's Online Certificate Status Protocol (OCSP) Client. The client fails to verify the 'id-kp-OCSPSigning' Extended Key Usage (EKU) in OCSP responder certificates. A remote attacker, holding any valid certificate issued by the same Certificate Authority (CA), can exploit this by forging 'GOOD' OCSP responses for revoked certificates. This bypasses certificate revocation checks, allowing applications using Netty's OCSP Client to accept certificates that should have been revoked, leading to an authorization bypass.

AFFECTED SURFACEProduct not specified
CVSS 5.9EPSS 0.23%
CVE-2026-93575HIGH

A flaw was found in Netty's MqttDecoder. An unauthenticated remote attacker can exploit this vulnerability by sending a specially crafted MQTT CONNECT packet. The decoder fails to properly validate the 'Properties Length' against the 'Remaining Length', allowing an attacker to bypass size limits. This leads to excessive memory and CPU consumption, resulting in a denial of service (DoS) due to an OutOfMemoryError.

AFFECTED SURFACEProduct not specified
CVSS 7.5EPSS 0.39%
CVE-2026-93572HIGH

A flaw was found in Netty's `RedisArrayAggregator` component. A remote attacker can exploit this vulnerability by sending specially crafted nested Redis (RESP) array headers. This can cause the `RedisArrayAggregator` to eagerly preallocate a large amount of heap memory, leading to heap memory exhaustion and a Denial of Service (DoS) for applications using `RedisDecoder` with `RedisArrayAggregator` on untrusted traffic.

AFFECTED SURFACEProduct not specified
CVSS 7.5EPSS 0.34%
CVE-2026-93563HIGH

A flaw was found in Netty's `SmtpResponseDecoder` component. A remote attacker, acting as a malicious or man-in-the-middle (MITM) SMTP server, could exploit this by sending a specially crafted, unbounded multi-line SMTP response without a terminator. This vulnerability leads to unbounded memory accumulation within the client's Java Virtual Machine (JVM) heap, causing an `OutOfMemoryError` and a denial of service (DoS) due to a process crash.

AFFECTED SURFACEProduct not specified
CVSS 7.5EPSS 0.33%