CuraSec

tag: Critical-Cve · 4 items

2026-08-27 · The Hacker News · source ↗ #nextjs#rce#critical-cve
  • Engineer — Act: Public PoC on GitHub for unauthenticated RCE in a ubiquitous web framework clears the bar for immediate action — upgrade Next.js to the patched release now, prioritizing any Windows-hosted deployments and any apps accepting untrusted image uploads.
  • SOC/IR — Plan: With a public PoC and no KEV listing yet, build detections for suspicious AVIF uploads and Windows-style path traversal sequences (e.g. ..) in HTTP requests targeting Next.js routes before active exploitation begins.
  • Leader — Plan: Two critical unauthenticated RCE flaws with public PoC in a widely-deployed framework warrant confirming this quarter that your engineering teams have inventoried Next.js usage and applied patches — flag for a status check if any customer-facing apps are affected.
  • Signals: CVE-2026-75604 — CISA KEV: not listed, EPSS n/a, public PoC on GitHub
2026-08-21 · The Hacker News · source ↗ #cisco#critical-cve#patch
  • Engineer — Plan: Five CVSS 10.0 flaws are severe on paper, but no KEV listing, PoC, or active exploitation is signaled — schedule patching of Crosswork Data Gateway, Crosswork Network Controller, Crosswork Planning, and Secure Workload this cycle rather than as emergency response.
  • SOC/IR — Skip
  • Leader — Skip
  • Engineer — Act: Four KEV-listed critical vulns across platforms you likely run — patch macOS (CVE-2026-65400, CVSS 9.8), SharePoint, vCenter, and Microsoft IKE immediately; a public PoC exists for the macOS flaw, making exploitation trivial.
  • SOC/IR — Act: Active exploitation of vCenter and SharePoint warrants an assume-breach sweep — hunt for post-exploitation activity (credential dumping, lateral movement) on these systems dating back at least 30 days, and tune detections for anomalous SharePoint API calls and vCenter admin actions.
  • Leader — Act: KEV-listed active exploitation across macOS endpoints, SharePoint, and vCenter is a systemic risk event — confirm patch status and exposure scope with engineering this week, and be prepared to brief leadership if any of these systems host sensitive data or are business-critical.
  • Signals: CVE-2026-65400 — CISA KEV: listed, EPSS 0.00, public PoC on GitHub
  • Engineer — Act: cPanel/WHM is widely deployed by hosting providers and MSPs; CISA KEV listing plus EPSS 0.98 and public PoC confirm active exploitation risk. Patch to the vendor-released fixed version immediately and audit for signs of unauthorized access in cPanel/WHM logs.
  • SOC/IR — Act: With a public PoC and KEV listing, opportunistic exploitation is underway — sweep for anomalous cPanel/WHM authentication events and unexpected admin account creation since the PoC publication date, and tune detections for unauthenticated access patterns on WHM ports.
  • Leader — Plan: If your organization or any managed-hosting vendor uses cPanel/WHM, confirm patching status and request attestation this week; the KEV listing signals broad exploitation, but direct board escalation is warranted only if you host customer data on affected systems.
  • Signals: CVE-2026-41940 — CISA KEV: listed, EPSS 0.98, public PoC on GitHub