L/BLAB BOTSPUBLIC THREAT INTELLIGENCE NODE
CVE KNOWLEDGE BASE

Intelligence
Explorer.

Investigue vulnerabilidades por identificador, produto afetado ou descrição. Use severidade, CVSS e EPSS juntos para orientar a prioridade.

// THREAT ACTIVITY

Grupos & malware emergente

Atividade pública observada em leak sites e repositórios comunitários. Alegações de vítimas não representam confirmação independente de incidente.

RANSOMWARE GROUPSRECENT CLAIMS
lamashtu10 menções
Storm9 menções
thegentlemen8 menções
akira7 menções
Booba Project6 menções
incransom6 menções
krybit6 menções
qilin5 menções
rhysida5 menções
Wallstreet4 menções
INFOSTEALERSOBSERVED

Sem famílias correlacionadas no recorte recente.

RECENT RANSOMWARE CLAIMSRANSOMWARE.LIVE
qilinGenesis Credit ManagementUS · Financial Services · 2026-10-03
netrunnerPrecon Marine Inc— · Transportation · 2026-10-03
rhysidaSkaff Group— · Other · 2026-10-03
WallstreetSt. Francis Healthcare Systems of HawaiiUS · Healthcare · 2026-10-03
WallstreetWorld Cup 2034SA · Other · 2026-10-03
akiraThe Official Collegeof Architects of León (COAL)MX · Professional Services · 2026-10-03
Spiralsseven seas groupAE · Transportation · 2026-10-03
qilinThai Lion AirTH · Transportation · 2026-10-02
rhysidaMat Bao CorporationVN · Technology · 2026-10-02
rhysidaElectro Heat Sweden ABSE · Energy & Utilities · 2026-10-02
PanzerPaessolucoesBR · Other · 2026-10-02
thegentlemenGerrity StoneUS · Manufacturing · 2026-10-03
MALWARE FAMILIES / 7 DAYSMALWAREBAZAAR
Configure a Auth-Key gratuita do abuse.ch para habilitar detecções recentes do MalwareBazaar.

FONTES: RANSOMWARE.LIVE + MALWAREBAZAAR / ABUSE.CH · CACHE 1H

11641 REGISTROS ENCONTRADOSFEED 2026-09-29
CVE-2026-75884CRITICAL

A flaw was found in AWX. The container group pod_spec_override field uses an incomplete blocklist that only restricts automountServiceAccountToken, allowing injection of initContainers, serviceAccountName overrides, and projected service account token volumes. An AAP platform administrator can exploit this to escalate privileges to OpenShift namespace-level access and exfiltrate namespace secrets.

AFFECTED SURFACEProduct not specified
CVSS 9.1EPSS 0.41%
CVE-2026-68492HIGH

An untrusted search path vulnerability in Plesk from 18.0.34 before 18.0.80.8 and 18.0.81 before 18.0.81.1 allows remote authenticated users to execute arbitrary code as root via the "Plesk RESTful API" extension from 2.4.2 before 2.4.7.

AFFECTED SURFACEProduct not specified
CVSS 8.7EPSS 0.38%
CVE-2026-68490HIGH

Incorrect permission assignment allows local users to obtain sensitive CalDAV/CardDAV information belonging to other accounts.

AFFECTED SURFACEProduct not specified
CVSS 8.2EPSS 0.14%
CVE-2026-67238HIGH

RabbitMQ is a messaging and streaming broker. Prior to versions 4.2.7 and 4.3.1, rabbit_pid_codec:decompose_from_binary/1 parses a caller-supplied ETF-encoded binary and calls binary_to_atom(Node, utf8) on the node-name field. It is reached from rabbit_volatile_queue:pid_from_name/2, which is invoked for any queue name / routing key beginning amq.rabbitmq.reply-to.. The CandidateNodes membership check happens after the atom is created, and the surrounding try/catch cannot reclaim atoms (they are never GC'd). binary_to_existing_atom is not used. Any authenticated AMQP client can crash the entire Erlang VM (all vhosts, all connections) with ~1M cheap requests. Preconditions include Authenticated AMQP 0-9-1 connection to any vhost No per-connection rate limit low enough to make ~1M operations infeasible. This issue is fixed in versions 4.2.7 and 4.3.1.

AFFECTED SURFACEProduct not specified
CVSS 7.1EPSS 0.33%
CVE-2026-66079HIGH

RabbitMQ is a messaging and streaming broker. Prior to versions 3.13.15, 4.0.20, 4.1.11, and 4.2.6, parse_array_primitive/2 for constructor 0x45 (list0) returns an element with byte-width B = 0. The enclosing array32 parser at line 148 reads a 4-byte Count from the wire and loops Count times consuming B bytes each , with B = 0, no input is consumed and the loop builds a list of Count empty elements bounded only by the 32-bit field. The SASL-mechanisms / SASL-init frame is parsed by amqp10_framing:decode_bin/1 from rabbit_amqp_reader.erl:412 before authentication completes. The pre-auth incoming_max_frame_size (default 8192 bytes) caps the frame, not the Count field, so a 19-byte payload with Count = 0xFFFFFFFF is accepted. No max_heap_size is set on the reader process. An unauthenticated network attacker can crash any RabbitMQ node that has the AMQP 1.0 listener enabled (default port 5672) by sending a single ~19-byte frame. The reader process attempts to build a list of ~4 billion empty elements, exhausting heap memory and terminating the Erlang VM. All tenants and protocols on the node lose service. Preconditions include Network reachability to the AMQP listener (port 5672, enabled by default) No authentication required. This issue is fixed in versions 3.13.15, 4.0.20, 4.1.11, and 4.2.6.

AFFECTED SURFACEProduct not specified
CVSS 8.2EPSS 0.32%
CVE-2026-66076LOW

RabbitMQ is a messaging and streaming broker. Prior to versions 3.13.15, 4.0.20, 4.1.11, 4.2.6, and 4.3.0, is_authorized/2 calls rabbit_mgmt_util:is_authorized/2, which checks only the management tag, instead of is_authorized_vhost/2. The /api/queues/quorum/:vhost/:queue/status handler reads the vhost from the path without checking that the user can access it. Any management-tagged user can therefore read Raft status, including leader, members, term, and commit index, for quorum queues in inaccessible vhosts, exposing cross-tenant queue names and cluster topology. The management plugin must be enabled and the attacker must have a management tag. This issue is fixed in versions 3.13.15, 4.0.20, 4.1.11, 4.2.6, and 4.3.0.

AFFECTED SURFACEProduct not specified
CVSS 2.3EPSS 0.27%
CVE-2026-66070HIGH

RabbitMQ is a messaging and streaming broker. Prior to versions 3.13.17, 4.0.22, 4.1.13, and 4.2.6, match_origin/1 returned the bare reflected Origin and allowed credentials even when the wildcard "" was configured, so the response echoed the attacker's origin together with Access-Control-Allow-Credentials. The affected code is rabbit_mgmt_cors.erl. When the management plugin is configured with a wildcard CORS origin (cors_allow_origins = ""), the handler reflects the request Origin back in Access-Control-Allow-Origin and also sends Access-Control-Allow-Credentials: true. A malicious web page that a signed-in administrator visits can then use that administrator's cached HTTP Basic credentials to issue authenticated, state-changing requests to the management API. Preconditions include The management plugin is configured with the wildcard cors_allow_origins = "*", which is an explicit operator misconfiguration A target administrator has a cached HTTP Basic-auth session in the browser. This issue is fixed in versions 3.13.17, 4.0.22, 4.1.13, and 4.2.6.

AFFECTED SURFACEProduct not specified
CVSS 7.6EPSS 0.41%
CVE-2026-96872LOW

Improper handling of insufficient permissions or privileges vulnerability in The Wikimedia Foundation Mediawiki - WikiLambda Extension on Linux, MacOS, and Windows allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects Mediawiki - WikiLambda Extension: before 1.47.0.

AFFECTED SURFACEProduct not specified
CVSS 2.9EPSS 0.23%
CVE-2026-96770CRITICAL

All published s2s-proxy versions through 0.2.2 are affected. In versions 0.1.16 through 0.2.2, TLS server listeners use Go's RequireAnyClientCert mode when skipCAVerification is false. This mode checks that the client holds the certificate's private key but does not verify the certificate against the configured CA. An attacker can therefore use a self-signed certificate and key to establish a TLS and yamux connection, then invoke RPCs allowed by the proxy's configuration and Temporal credentials. No certificate or private key trusted by the deployment, and no Temporal credential, is required.

AFFECTED SURFACEProduct not specified
CVSS 9.3EPSS 0.25%
CVE-2026-96549LOW

A vulnerability has been found in sfturing hosp_order up to 627f426331da8086ce8fff2017d65b1ddef384f8. This vulnerability affects unknown code of the file ssm_pro/src/main/java/cn/sfturing/service/impl/CommonUserServiceImpl.java. Such manipulation leads to cleartext storage of sensitive information. The attack can only be performed from a local environment. The exploit has been disclosed to the public and may be used. This product takes the approach of rolling releases to provide continious delivery. Therefore, version details for affected and updated releases are not available. The project was informed of the problem early through an issue report but has not responded yet.

AFFECTED SURFACEProduct not specified
CVSS 1.9EPSS 0.08%
CVE-2026-96548LOW

A flaw has been found in sfturing hosp_order up to 627f426331da8086ce8fff2017d65b1ddef384f8. This affects an unknown part of the file ssm_pro/src/main/resources/jdbc.properties. This manipulation causes hard-coded credentials. It is possible to initiate the attack remotely. The attack's complexity is rated as high. It is indicated that the exploitability is difficult. The exploit has been published and may be used. This product is using a rolling release to provide continious delivery. Therefore, no version details for affected nor updated releases are available. The project was informed of the problem early through an issue report but has not responded yet.

AFFECTED SURFACEProduct not specified
CVSS 2.9EPSS 0.26%
CVE-2026-96546LOW

A one-byte out-of-bounds heap read flaw was found in GIMP's uncompressed DDS image loader. When a user opens an uncompressed DDS image, the file-dds plug-in performs an unconditional one-byte look-ahead after processing the final pixel. This may cause the plug-in to crash if the byte immediately following the pixel buffer is inaccessible; no information disclosure or code execution has been demonstrated.

AFFECTED SURFACEProduct not specified
CVSS 2.5EPSS 0.11%
CVE-2026-96545MEDIUM

An out-of-bounds heap read flaw was found in GIMP's TIM image loader. When a user opens a crafted 4bpp TIM image that causes promotion to an RGBA layer, the file-tim plug-in allocates an undersized row buffer but processes it using the larger RGBA row size. This can copy adjacent heap contents into the decoded image and may crash the plug-in.

AFFECTED SURFACEProduct not specified
CVSS 4.4EPSS 0.18%
CVE-2026-96541HIGH

A denial-of-service flaw was found in gnome-remote-desktop. An unauthenticated remote attacker can open RDP connections without completing the handshake and retain the connection-throttling slots indefinitely because no pre-authentication handshake deadline is enforced. By exhausting the global connection limit, an attacker can prevent new RDP clients from connecting until a holding socket is closed.

AFFECTED SURFACEProduct not specified
CVSS 7.5EPSS 0.79%
CVE-2026-95604HIGH

Unauthenticated Broken Access Control in Loops & Logic <= 4.2.4 versions.

AFFECTED SURFACEProduct not specified
CVSS 7.5EPSS 0.33%
CVE-2026-95603HIGH

Shop manager PHP Object Injection in Reycob Product Import Export <= 2.3.0 versions.

AFFECTED SURFACEProduct not specified
CVSS 7.2EPSS 0.40%
CVE-2026-95602MEDIUM

Authorization Bypass Through User-Controlled Key vulnerability in YITH YITH WooCommerce Request A Quote allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects YITH WooCommerce Request A Quote: from n/a before 4.46.1.

AFFECTED SURFACEProduct not specified
CVSS 6.5EPSS 0.28%
CVE-2026-95601CRITICAL

Unauthenticated SQL Injection in Product Filter by WBW <= 3.1.7 versions.

AFFECTED SURFACEProduct not specified
CVSS 9.3EPSS 0.25%
CVE-2026-95600MEDIUM

Unauthenticated Sensitive Data Exposure in TrustedLogin Connector <= 2.0.3 versions.

AFFECTED SURFACEProduct not specified
CVSS 5.3EPSS 0.25%
CVE-2026-95593HIGH

Editor SQL Injection in Ultimeter <= 3.0.8 versions.

AFFECTED SURFACEProduct not specified
CVSS 7.6EPSS 0.29%
CVE-2026-95592MEDIUM

Unauthenticated Insecure Direct Object References (IDOR) in Team <= 6.0.0 versions.

AFFECTED SURFACEProduct not specified
CVSS 5.3EPSS 0.24%
CVE-2026-95590HIGH

Subscriber SQL Injection in Tainacan <= 1.2.0 versions.

AFFECTED SURFACEProduct not specified
CVSS 7.1EPSS 0.29%
CVE-2026-95586MEDIUM

Contributor Cross Site Scripting (XSS) in Ultimate Addons for Contact Form 7 <= 3.5.50 versions.

AFFECTED SURFACEProduct not specified
CVSS 6.5EPSS 0.16%
CVE-2026-95530MEDIUM

Subscriber Cross Site Scripting (XSS) in PixelYourSite – Your smart PIXEL (TAG) Manager <= 11.4.1 versions.

AFFECTED SURFACEProduct not specified
CVSS 6.5EPSS 0.21%