L/BLAB BOTSPUBLIC THREAT INTELLIGENCE NODE
CVE KNOWLEDGE BASE

Intelligence
Explorer.

Investigue vulnerabilidades por identificador, produto afetado ou descrição. Use severidade, CVSS e EPSS juntos para orientar a prioridade.

// THREAT ACTIVITY

Grupos & malware emergente

Atividade pública observada em leak sites e repositórios comunitários. Alegações de vítimas não representam confirmação independente de incidente.

RANSOMWARE GROUPSRECENT CLAIMS
lamashtu10 menções
Storm9 menções
thegentlemen8 menções
akira7 menções
Booba Project6 menções
incransom6 menções
krybit6 menções
qilin5 menções
rhysida5 menções
Wallstreet4 menções
INFOSTEALERSOBSERVED

Sem famílias correlacionadas no recorte recente.

RECENT RANSOMWARE CLAIMSRANSOMWARE.LIVE
qilinGenesis Credit ManagementUS · Financial Services · 2026-10-03
netrunnerPrecon Marine Inc— · Transportation · 2026-10-03
rhysidaSkaff Group— · Other · 2026-10-03
WallstreetSt. Francis Healthcare Systems of HawaiiUS · Healthcare · 2026-10-03
WallstreetWorld Cup 2034SA · Other · 2026-10-03
akiraThe Official Collegeof Architects of León (COAL)MX · Professional Services · 2026-10-03
Spiralsseven seas groupAE · Transportation · 2026-10-03
qilinThai Lion AirTH · Transportation · 2026-10-02
rhysidaMat Bao CorporationVN · Technology · 2026-10-02
rhysidaElectro Heat Sweden ABSE · Energy & Utilities · 2026-10-02
PanzerPaessolucoesBR · Other · 2026-10-02
thegentlemenGerrity StoneUS · Manufacturing · 2026-10-03
MALWARE FAMILIES / 7 DAYSMALWAREBAZAAR
Configure a Auth-Key gratuita do abuse.ch para habilitar detecções recentes do MalwareBazaar.

FONTES: RANSOMWARE.LIVE + MALWAREBAZAAR / ABUSE.CH · CACHE 1H

11641 REGISTROS ENCONTRADOSFEED 2026-09-29
CVE-2026-77703MEDIUM

Key exchange without entity authentication vulnerability in HAVELSAN Inc. Liman Render Engine allows Adversary in the Middle (AiTM). This issue affects Liman Render Engine: from 1.0 before 1.2-75.

AFFECTED SURFACEProduct not specified
CVSS 5.9EPSS 0.24%
CVE-2026-73064LOW

In Mbed TLS 3.2.0 though 3.6.6 and 4.0.0 through 4.1.0, an attacker who can cause an entropy source to fail can remove or inject bytes into the start of the TLS stream. This only affects TLS 1.3 servers.

AFFECTED SURFACEProduct not specified
CVSS 2.9EPSS 0.10%
CVE-2026-6544MEDIUM

IBM Concert 1.0.0 through 3.0.0 allows recursive copying of directories without proper controls which can lead to unintentional inclusion of sensitive or unnecessary files and increased attack surface.

AFFECTED SURFACEibm concertlinux linux kernel
CVSS 6.2EPSS 0.12%
CVE-2026-65422MEDIUM

A flaw in the authorization mechanism for Media Gateway API in Genetec Security Center may allow a user with no playback privileges to generate video thumbnails.

AFFECTED SURFACEProduct not specified
CVSS 6.5EPSS 0.20%
CVE-2026-58008HIGH

Stack-based buffer overflow vulnerability in Altera Trusted Firmware on HPS allows Exploitation of Improperly Configured or Implemented Memory Protections. This issue affects Trusted Firmware: through socfpga_v2.14.0.

AFFECTED SURFACEProduct not specified
CVSS 8.3EPSS 0.11%
CVE-2026-58007HIGH

Untrusted pointer dereference vulnerability in Altera Trusted Firmware on HPS allows Exploitation of Improperly Configured or Implemented Memory Protections. This issue affects Trusted Firmware: through socfpga_v2.14.0.

AFFECTED SURFACEProduct not specified
CVSS 8.3EPSS 0.11%
CVE-2026-58006HIGH

Untrusted pointer dereference vulnerability in Altera Trusted Firmware on HPS allows Exploitation of Improperly Configured or Implemented Memory Protections. This issue affects Trusted Firmware: through socfpga_v2.14.0.

AFFECTED SURFACEProduct not specified
CVSS 8.3EPSS 0.11%
CVE-2026-58005HIGH

Out-of-bounds read vulnerability in Altera Trusted Firmware on HPS allows Privilege Escalation and Overflow Buffers. This issue affects Trusted Firmware: through socfpga_v2.14.0.

AFFECTED SURFACEProduct not specified
CVSS 8.3EPSS 0.11%
CVE-2026-58004HIGH

Out-of-bounds read vulnerability in Altera Trusted Firmware on HPS allows Privilege Escalation and Overflow Buffers. This issue affects Trusted Firmware: through socfpga_v2.14.0.

AFFECTED SURFACEProduct not specified
CVSS 8.3EPSS 0.11%
CVE-2026-56736HIGH

phpMyFAQ is an open source FAQ web application. A stored cross-site scripting (XSS) vulnerability in versions prior to 4.2.0-alpha allows any unauthenticated user (or low-privileged registered user) to inject arbitrary JavaScript that executes in an administrator's browser when they review or edit a user-submitted FAQ entry. This leads to admin account takeover via session theft. The vulnerability exists because `html_entity_decode()` converts HTML entities into executable HTML after `strip_tags()` has already passed them through, and the admin template renders the content with Twig's `|raw` filter without any output sanitization. Version 4.2.0-alpha fixes the issue.

AFFECTED SURFACEProduct not specified
CVSS 8.2EPSS 0.24%
CVE-2026-52001ANALYSIS

An issue in geelen mcp-remote 0.1.18 through 0.1.38 allows a remote attacker to obtain sensitive information via the SSE transport eventSourceInit fetch wrapper " src/lib/utils.ts

AFFECTED SURFACEProduct not specified
CVSS N/DEPSS 0.25%
CVE-2026-51997HIGH

An issue in geelen mcp-remote 0.1.16 through 0.1.38 allows a remote attacker to execute arbitrary code via the open() functions

AFFECTED SURFACEProduct not specified
CVSS 8.8EPSS 0.53%
CVE-2026-51996CRITICAL

An issue in geelen mcp-remote 0.1.16 through 0.1.38 allows a remote attacker to execute arbitrary code via the src/lib/utils.ts and the getServerUrlHash function

AFFECTED SURFACEProduct not specified
CVSS 9.8EPSS 0.78%
CVE-2026-51995HIGH

An issue in geelen mcp-remote 0.1.32 through 0.1.38 allows a remote attacker to obtain sensitive information via the src/lib/authorization-server-metadata.ts, src/lib/utils.ts components

AFFECTED SURFACEProduct not specified
CVSS 7.5EPSS 0.47%
CVE-2026-51994CRITICAL

mcp-remote versions 0.1.32 through 0.1.38 are vulnerable to Server-Side Request Forgery (SSRF) via the resource_metadata URL extracted from a remote MCP server's WWW-Authenticate header

AFFECTED SURFACEProduct not specified
CVSS 9.1EPSS 0.35%
CVE-2026-19492LOW

IBM PowerVM Hypervisor FW1120.00 through FW1120.01, FW1110.00 through FW1110.31, and FW1060.00 through FW1060.81 is affected by a vulnerability in a hypervisor call interface. An attacker with root access to a guest partition can read a limited amount of hypervisor memory, potentially exposing sensitive data belonging to the hypervisor or other guest partitions hosted on the same system, resulting in a confidentiality impact. The attacker has no control over which memory contents are returned. This vulnerability is of particular concern in multi-tenant environments where guests may run arbitrary OS images.

AFFECTED SURFACEProduct not specified
CVSS 3.2EPSS 0.11%
CVE-2026-18870MEDIUM

IBM PowerVM Hypervisor FW1120.00 through FW1120.01, FW1110.00 through FW1110.31, FW1060.00 through FW1060.81, and FW950.00 through FW950.H3 could allow a remote attacker to obtain sensitive information due to an out-of-bounds read.

AFFECTED SURFACEProduct not specified
CVSS 4.3EPSS 0.18%
CVE-2026-13467HIGH

Out-of-bounds write vulnerability in Altera Trusted Firmware on HPS allows Exploitation of Improperly Configured or Implemented Memory Protections. This issue affects Trusted Firmware: through socfpga_v2.14.0.

AFFECTED SURFACEProduct not specified
CVSS 8.3EPSS 0.11%
CVE-2026-13466HIGH

Incorrect calculation of buffer size vulnerability in Altera Trusted Firmware on HPS allows Overflow Buffers. This issue affects Trusted Firmware: through socfpga_v2.14.0.

AFFECTED SURFACEProduct not specified
CVSS 8.3EPSS 0.11%
CVE-2026-13465HIGH

Stack-based buffer overflow vulnerability in Altera Trusted Firmware on HPS allows Exploitation of Improperly Configured or Implemented Memory Protections. This issue affects Trusted Firmware: through socfpga_v2.14.0.

AFFECTED SURFACEProduct not specified
CVSS 8.3EPSS 0.11%
CVE-2026-12559HIGH

A Stored Cross-Site Scripting (XSS) vulnerability has been identified in OpenText Vendor Invoice Management for SAP Solutions Capture Validation application. Under certain conditions, this issue could allow execution of unauthorized script content in a user's browser, potentially impacting confidentiality and integrity of information processed through the application.

AFFECTED SURFACEProduct not specified
CVSS 7.3EPSS 0.39%
CVE-2026-97360CRITICAL

HFS2 version 2.4.0 and earlier contains an unauthenticated arbitrary file access vulnerability that allows unauthenticated attackers to read, write, append, and delete files anywhere the HFS service account has filesystem access outside the shared folder. Attackers can exploit the macro dispatcher's lack of authorization model combined with the path resolver's failure to confine absolute paths to manipulate the template engine and compromise the confidentiality, integrity, and availability of the host.

AFFECTED SURFACEProduct not specified
CVSS 10.0EPSS 0.32%
CVE-2026-97359CRITICAL

HFS2 version 2.4.0 and earlier contains a template injection vulnerability in the multipart upload handler that allows unauthenticated attackers to achieve remote code execution by embedding malicious template syntax in a filename. Attackers can craft a filename containing a closing template quoting sequence followed by an exec macro, which bypasses the authorization check in the dispatcher to execute arbitrary commands on the underlying host system.

AFFECTED SURFACEProduct not specified
CVSS 10.0EPSS 0.78%
CVE-2026-97062MEDIUM

Aureus ERP through 1.6.0 stores uploaded SVG files on its public disk and serves them from the application origin, allowing authenticated users to upload malicious SVG files containing JavaScript. Attackers can craft SVG files with script elements that execute in the application's origin when the file URL is opened directly, enabling session cookie theft and CSRF token exfiltration.

AFFECTED SURFACEProduct not specified
CVSS 5.1EPSS 0.22%