#cve

2026-01-28

Fortinet confirms active exploitation of FortiCloud SSO auth bypass (CVE-2026-24858, CVSS 9.4).
Cross-customer access via trusted SSO paths observed.

SSO now blocked for vulnerable versions - patching required.

technadu.com/fortinet-temporar

#InfoSec #Fortinet #CVE #IdentitySecurity

Fortinet Temporarily Disables FortiCloud SSO Following Active Exploitation
AllAboutSecurityallaboutsecurity
2026-01-28

WinRAR-Schwachstelle CVE-2025-8088: Staatsakteure und Cyberkriminelle nutzen SicherheitslΓΌcke massiv aus

Bei CVE-2025-8088 handelt es sich um eine hochriskante Path-Traversal-Schwachstelle, die Angreifer durch Manipulation von Alternate Data Streams (ADS) ausnutzen kΓΆnnen.

all-about-security.de/winrar-s


TheHackerWirethehackerwire
2026-01-28

πŸ”΄ CVE-2026-1056 - Critical (9.8)

The Snow Monkey Forms plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the 'generate_user_dirpath' function in all versions up to, and including, 12.0.3. This makes it possible for unauthent...

πŸ”— thehackerwire.com/vulnerabilit

CVE Alert: CVE-2026-1056
2026-01-28

πŸ”΄ CVE-2026-1056 - Critical (9.8)

The Snow Monkey Forms plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the 'generate_user_dirpath' function in all versions up to, and including, 12.0.3. This makes it possible for unauthenticated attackers to delete arbitrary files on the ...

πŸ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity

CVE Alert: CVE-2026-1056
TheHackerWirethehackerwire
2026-01-28

🟠 CVE-2026-24842 - High (8.2)

node-tar,a Tar for Node.js, contains a vulnerability in versions prior to 7.5.7 where the security check for hardlink entries uses different path resolution semantics than the actual hardlink creation logic. This mismatch allows an attacker to cra...

πŸ”— thehackerwire.com/vulnerabilit

CVE Alert: CVE-2026-24842
TheHackerWirethehackerwire
2026-01-28

🟠 CVE-2025-14386 - High (8.8)

The Search Atlas SEO – Premier SEO Plugin for One-Click WP Publishing & Integrated AI Optimization plugin for WordPress is vulnerable to authentication bypass due to a missing capability check on the 'generate_sso_url' and 'validate_sso_token' f...

πŸ”— thehackerwire.com/vulnerabilit

CVE Alert: CVE-2025-14386
2026-01-28

πŸ”΄ CVE-2026-24838 - Critical (9.1)

DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. Prior to versions 9.13.10 and 10.2.0, module title supports richtext which could include scripts that would execute in certain scenarios. Versions 9.13.10 and 10.2.0 contain a fix for th...

πŸ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity

CVE Alert: CVE-2026-24838
2026-01-28

🟠 CVE-2025-14386 - High (8.8)

The Search Atlas SEO – Premier SEO Plugin for One-Click WP Publishing & Integrated AI Optimization plugin for WordPress is vulnerable to authentication bypass due to a missing capability check on the 'generate_sso_url' and 'validate_sso_token' functions in versions 2.4.4 to 2.5.12. This makes i...

πŸ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity

CVE Alert: CVE-2025-14386
TheHackerWirethehackerwire
2026-01-28

🟠 CVE-2026-1280 - High (7.5)

The Frontend File Manager Plugin for WordPress is vulnerable to unauthorized file sharing due to a missing capability check on the 'wpfm_send_file_in_email' AJAX action in all versions up to, and including, 23.5. This makes it possible for unauthe...

πŸ”— thehackerwire.com/vulnerabilit

CVE Alert: CVE-2026-1280
2026-01-28

🟠 CVE-2026-1280 - High (7.5)

The Frontend File Manager Plugin for WordPress is vulnerable to unauthorized file sharing due to a missing capability check on the 'wpfm_send_file_in_email' AJAX action in all versions up to, and including, 23.5. This makes it possible for unauthenticated attackers to share arbitrary uploaded fil...

πŸ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity

CVE Alert: CVE-2026-1280
TheHackerWirethehackerwire
2026-01-28

🟠 CVE-2026-0844 - High (8.8)

The Simple User Registration plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 6.7 due to insufficient restriction on the 'profile_save_field' function. This makes it possible for authenticated attackers,...

πŸ”— thehackerwire.com/vulnerabilit

CVE Alert: CVE-2026-0844
2026-01-28

🟠 CVE-2026-0844 - High (8.8)

The Simple User Registration plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 6.7 due to insufficient restriction on the 'profile_save_field' function. This makes it possible for authenticated attackers, with minimal permissions such as a subscriber, to...

πŸ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity

CVE Alert: CVE-2026-0844
2026-01-28

🚨 Lambda Watchdog CVE Report 🚨
Latest AWS Lambda image scan detected 20 CVEs across 27 images:
β€’ πŸ”΄ Critical: 0
β€’ 🟠 High: 11
β€’ 🟑 Medium: 5
β€’ πŸ”΅ Low: 4

Check the full report πŸ‘‰ lambdawatchdog.com/
#AWS #Lambda #CVE #CloudSecurity #Serverless

2026-01-28

🚨 Lambda Watchdog CVE Report 🚨
Latest AWS Lambda image scan detected 20 CVEs across 27 images:
β€’ πŸ”΄ Critical: 0
β€’ 🟠 High: 11
β€’ 🟑 Medium: 5
β€’ πŸ”΅ Low: 4

Check the full report πŸ‘‰ lambdawatchdog.com/
#AWS #Lambda #CVE #CloudSecurity #Serverless

Lambda Watchdoglambdawatchdog
2026-01-28

🚨 Lambda Watchdog CVE Report 🚨
Latest AWS Lambda image scan detected 20 CVEs across 27 images:
β€’ πŸ”΄ Critical: 0
β€’ 🟠 High: 11
β€’ 🟑 Medium: 5
β€’ πŸ”΅ Low: 4

Check the full report πŸ‘‰ lambdawatchdog.com/

TheHackerWirethehackerwire
2026-01-28

🟠 CVE-2025-40536 - High (8.1)

SolarWinds Web Help Desk was found to be susceptible to a security control bypass vulnerability that if exploited, could allow an unauthenticated attacker to gain access to certain restricted functionality.

πŸ”— thehackerwire.com/vulnerabilit

CVE Alert: CVE-2025-40536
2026-01-28

🟠 CVE-2025-40536 - High (8.1)

SolarWinds Web Help Desk was found to be susceptible to a security control bypass vulnerability that if exploited, could allow an unauthenticated attacker to gain access to certain restricted functionality.

πŸ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity

CVE Alert: CVE-2025-40536
RedPacket SecurityRedPacketSecurity
2026-01-28

CVE Alert: CVE-2025-14610 - bloompixel - TableMaster for Elementor – Advanced Responsive Tables for Elementor - redpacketsecurity.com/cve-aler

-2025-14610 -for-elementor-advanced-responsive-tables-for-elementor

RedPacket SecurityRedPacketSecurity
2026-01-28

Client Info

Server: https://mastodon.social
Version: 2025.07
Repository: https://github.com/cyevgeniy/lmst