L/BLAB BOTSPUBLIC THREAT INTELLIGENCE NODE
CVE KNOWLEDGE BASE

Intelligence
Explorer.

Investigue vulnerabilidades por identificador, produto afetado ou descrição. Use severidade, CVSS e EPSS juntos para orientar a prioridade.

// THREAT ACTIVITY

Grupos & malware emergente

Atividade pública observada em leak sites e repositórios comunitários. Alegações de vítimas não representam confirmação independente de incidente.

RANSOMWARE GROUPSRECENT CLAIMS
qilin14 menções
incransom8 menções
safepay8 menções
Wallstreet7 menções
threeam7 menções
everest6 menções
emperador5 menções
medusalocker4 menções
N0n3 menções
Panzer3 menções
INFOSTEALERSOBSERVED

Sem famílias correlacionadas no recorte recente.

RECENT RANSOMWARE CLAIMSRANSOMWARE.LIVE
N0nPrecision Facades LtdGB · Manufacturing · 2026-09-29
netrunnerM*** P**** M***MY · Not Found · 2026-09-28
lockbit5camorim.com.brBR · Retail & E-Commerce · 2026-09-29
qilinArnold CenterUS · Not Found · 2026-09-28
threeamsafescaffolding.netGB · Manufacturing · 2026-09-28
threeamcoosalud.comCO · Healthcare · 2026-09-28
threeampistonespersan.com.arAR · Manufacturing · 2026-09-28
threeammidwestbit.comUS · Technology · 2026-09-28
threeamapexus.comUS · Technology · 2026-09-28
threeambhn-expertise.comDE · Professional Services · 2026-09-28
threeamstjames.wa.edu.auAU · Education · 2026-09-28
DoommageddonGoodrich Logistics— · Transportation · 2026-09-28
MALWARE FAMILIES / 7 DAYSMALWAREBAZAAR
Configure a Auth-Key gratuita do abuse.ch para habilitar detecções recentes do MalwareBazaar.

FONTES: RANSOMWARE.LIVE + MALWAREBAZAAR / ABUSE.CH · CACHE 1H

8621 REGISTROS ENCONTRADOSFEED 2026-09-22
CVE-2026-93450HIGH

go-openapi/swag jsonutils before 0.27.1 contains a stack overflow vulnerability in ordered JSON parsing and serialization due to unbounded recursion with no depth limit. Remote unauthenticated attackers can submit deeply nested JSON documents to services accepting OpenAPI specifications, causing fatal stack overflow that terminates the process and all in-flight requests.

AFFECTED SURFACEProduct not specified
CVSS 8.7EPSS 0.66%
CVE-2026-93309LOW

A vulnerability was determined in O-RAN-SC SMO OAM 2025-06-10. Affected by this issue is some unknown functionality of the component VES Collector. Executing a manipulation can lead to allocation of resources. The attack may be launched remotely. The exploit has been publicly disclosed and may be utilized. The project was informed of the problem early through a bug report but has not responded yet.

AFFECTED SURFACEProduct not specified
CVSS 2.1EPSS 0.30%
CVE-2026-93308LOW

A vulnerability was found in O-RAN-SC SMO OAM 2025-06-10. Affected by this vulnerability is an unknown functionality of the component VES Collector. Performing a manipulation results in allocation of resources. The attack may be initiated remotely. The exploit has been made public and could be used. The project was informed of the problem early through a bug report but has not responded yet.

AFFECTED SURFACEProduct not specified
CVSS 2.1EPSS 0.30%
CVE-2026-85887HIGH

Incorrect permission assignment for critical resource in M365 Copilot allows an authorized attacker to disclose information over a network.

AFFECTED SURFACEProduct not specified
CVSS 7.7EPSS 0.48%
CVE-2026-85878CRITICAL

Improper authorization in Azure Database for PostgreSQL allows an authorized attacker to elevate privileges over a network.

AFFECTED SURFACEProduct not specified
CVSS 9.9EPSS 0.55%
CVE-2026-83946HIGH

Improper neutralization of input during web page generation ('cross-site scripting') in Azure Portal allows an unauthorized attacker to perform spoofing over a network.

AFFECTED SURFACEProduct not specified
CVSS 8.2EPSS 0.39%
CVE-2026-69843CRITICAL

Authentication bypass by spoofing in Microsoft Fabric allows an unauthorized attacker to elevate privileges over a network.

AFFECTED SURFACEProduct not specified
CVSS 10.0EPSS 0.62%
CVE-2026-62874CRITICAL

Insufficient verification of data authenticity in Azure Billing allows an unauthorized attacker to elevate privileges over a network.

AFFECTED SURFACEProduct not specified
CVSS 10.0EPSS 0.32%
CVE-2026-2585MEDIUM

The Brizy – Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘rootAttributes’ parameter in all versions up to, and including, 2.8.14 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

AFFECTED SURFACEProduct not specified
CVSS 6.4EPSS 0.16%
CVE-2026-18441MEDIUM

The Appointment Booking Plugin – LatePoint | Calendar & Scheduling for WordPress plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 5.6.9 via the set_customer_object due to missing validation on a user controlled key. This makes it possible for unauthenticated attackers to enumerate arbitrary customer records and disclose personally identifiable information - including first name, last name, email address, and phone number - by iterating the customer[id] parameter. This issue is exploitable only when the site is configured with customer authentication disabled (guest checkout enabled).

AFFECTED SURFACEProduct not specified
CVSS 4.3EPSS 0.24%
CVE-2026-93436HIGH

vLLM through 0.29.0 fails to properly clean up decode-side metadata for rejected inference requests in prefill/decode disaggregated deployments. Remote attackers can submit requests with max_tokens=0 to exhaust decode-worker memory without bound until the worker restarts.

AFFECTED SURFACEProduct not specified
CVSS 8.7EPSS 0.54%
CVE-2026-93435HIGH

redis-parser through 3.0.0 contains a denial of service vulnerability in the RESP protocol parser that allows malicious Redis endpoints to crash the client process through unbounded recursion on nested arrays. Attackers can send crafted RESP byte streams with repeated array headers that exhaust the V8 call stack, causing an uncaught RangeError that terminates the Node.js process without triggering error handling callbacks.

AFFECTED SURFACEProduct not specified
CVSS 8.7EPSS 0.45%
CVE-2026-87886HIGH

Local privilege escalation due to insecure file permissions. The following products are affected: Acronis Backup plugin for cPanel & WHM (Linux) before build 1.9.3.1021, Acronis Backup extension for Plesk (Linux) before build 1.8.11.638, Acronis Backup plugin for DirectAdmin (Linux) before build 1.2.3.238.

AFFECTED SURFACEacronis acronis backuplinux linux kernel
CVSS 7.8EPSS 0.25%
CVE-2026-87701CRITICAL

Improper neutralization of special elements in output used by a downstream component ('injection') in Azure Cosmos DB allows an authorized attacker to elevate privileges over a network.

AFFECTED SURFACEProduct not specified
CVSS 9.6EPSS 0.44%
CVE-2026-85917HIGH

Server-side request forgery (ssrf) in Azure AI Foundry allows an unauthorized attacker to elevate privileges over a network.

AFFECTED SURFACEProduct not specified
CVSS 7.5EPSS 0.55%
CVE-2026-85889CRITICAL

Missing authentication for critical function in Azure AI Foundry allows an unauthorized attacker to elevate privileges over a network.

AFFECTED SURFACEProduct not specified
CVSS 10.0EPSS 0.49%
CVE-2026-85885CRITICAL

Improper neutralization of special elements used in a command ('command injection') in M365 Copilot allows an authorized attacker to elevate privileges over a network.

AFFECTED SURFACEProduct not specified
CVSS 9.9EPSS 0.53%
CVE-2026-83944CRITICAL

Improper access control in Azure Logic Apps allows an unauthorized attacker to elevate privileges over a network.

AFFECTED SURFACEProduct not specified
CVSS 10.0EPSS 0.45%
CVE-2026-78501HIGH

Improper neutralization of special elements used in a command ('command injection') in Microsoft 365 Copilot's Business Chat allows an unauthorized attacker to disclose information over a network.

AFFECTED SURFACEProduct not specified
CVSS 7.4EPSS 0.49%
CVE-2026-77903CRITICAL

Authentication bypass by spoofing in Microsoft Dataverse allows an unauthorized attacker to elevate privileges over a network.

AFFECTED SURFACEProduct not specified
CVSS 9.0EPSS 0.38%
CVE-2026-70200CRITICAL

Improper limitation of a pathname to a restricted directory ('path traversal') in Azure Logic Apps allows an unauthorized attacker to elevate privileges over a network.

AFFECTED SURFACEProduct not specified
CVSS 10.0EPSS 0.58%
CVE-2026-70009CRITICAL

Improper limitation of a pathname to a restricted directory ('path traversal') in Azure Arc allows an unauthorized attacker to elevate privileges over a network.

AFFECTED SURFACEProduct not specified
CVSS 9.3EPSS 0.47%
CVE-2026-69865CRITICAL

Authorization bypass through user-controlled key in Microsoft Container Registry allows an unauthorized attacker to elevate privileges over a network.

AFFECTED SURFACEProduct not specified
CVSS 10.0EPSS 0.45%
CVE-2026-69399CRITICAL

Azure Arc Elevation of Privilege Vulnerability

AFFECTED SURFACEProduct not specified
CVSS 10.0EPSS 0.49%