<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Critical-Vulnerability on CuraSec</title><link>https://curasec.metacog.co.kr/tags/critical-vulnerability/</link><description>Recent content in Critical-Vulnerability on CuraSec</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Fri, 28 Aug 2026 21:21:40 +0000</lastBuildDate><atom:link href="https://curasec.metacog.co.kr/tags/critical-vulnerability/index.xml" rel="self" type="application/rss+xml"/><item><title>Cosmos EVM shared module exploited across six blockchains, patch to 0.6.2</title><link>https://curasec.metacog.co.kr/insights/2026-08-28-cosmos-evm-flaw-exploited-after-cosmos-labs-knew-every-block/</link><pubDate>Fri, 28 Aug 2026 21:21:40 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-08-28-cosmos-evm-flaw-exploited-after-cosmos-labs-knew-every-block/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Plan:&lt;/strong> If your organization runs any Cosmos EVM-based chain, treat this as Act: the shared module (GHSA-7g4w-cg88-2cq2) was actively exploited Aug 20–25 and must be patched to ≥ 0.6.2; for most enterprise stacks this is niche software, making this a conditional urgent patch rather than a universal action.&lt;/li>
&lt;li>&lt;strong>SOC/IR — Learn:&lt;/strong> Active fund-drain exploitation across six blockchains signals a real threat actor capability against Cosmos EVM infrastructure, but the summary provides no IOCs, ATT&amp;amp;CK-mappable TTPs, or detection artifacts; file for context and watch for follow-on threat intel with actionable indicators.&lt;/li>
&lt;li>&lt;strong>Leader — Plan:&lt;/strong> Assess whether your organization has custody, treasury, or operational exposure to any of the six affected Cosmos EVM chains, and request incident attestation and remediation status from relevant blockchain service providers this quarter.&lt;/li>
&lt;/ul></description></item><item><title>ServiceNow Patches Three CVSS 10.0 Flaws Allowing Unauth RCE and SQLi</title><link>https://curasec.metacog.co.kr/insights/2026-08-28-three-cvss-10-0-servicenow-flaws-could-let-unauthenticated-a/</link><pubDate>Fri, 28 Aug 2026 21:21:40 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-08-28-three-cvss-10-0-servicenow-flaws-could-let-unauthenticated-a/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Plan:&lt;/strong> Three unauthenticated RCE/SQLi flaws at maximum severity demand prompt action, but no KEV listing or public PoC elevates this to Act yet. If running self-hosted ServiceNow, apply the patch this week and verify hosted instances received the automated update.&lt;/li>
&lt;li>&lt;strong>SOC/IR — Skip&lt;/strong>&lt;/li>
&lt;li>&lt;strong>Leader — Plan:&lt;/strong> Three CVSS 10.0 flaws in a widely deployed ITSM platform warrant confirming whether your organization runs self-hosted ServiceNow and ensuring the patch was applied; hosted tenants should receive confirmation from ServiceNow that their instances were updated.&lt;/li>
&lt;/ul></description></item><item><title>Critical GitLab GraphQL Flaw Lets Unauthenticated Attackers Delete Projects</title><link>https://curasec.metacog.co.kr/insights/2026-08-18-critical-gitlab-graphql-flaw-could-let-unauthenticated-attac/</link><pubDate>Tue, 18 Aug 2026 11:37:25 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-08-18-critical-gitlab-graphql-flaw-could-let-unauthenticated-attac/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Act:&lt;/strong> A public PoC on GitHub for a CVSS 9.4 unauthenticated flaw sharply raises exploitation risk even without KEV listing; patch GitLab CE/EE to the vendor&amp;rsquo;s latest patched release this week and verify no public GraphQL endpoints are exposed without authentication.&lt;/li>
&lt;li>&lt;strong>SOC/IR — Act:&lt;/strong> With a public PoC already circulating, hunt for unauthenticated GraphQL mutation requests targeting GitLab&amp;rsquo;s project or user-data endpoints, and alert on anomalous project deletion or modification events since the vulnerability disclosure date.&lt;/li>
&lt;li>&lt;strong>Leader — Plan:&lt;/strong> Confirm whether the organization runs self-hosted GitLab and ensure engineering has a same-week patching commitment; unauthorized source-code deletion or tampering carries supply-chain and business-continuity implications worth a brief status check with the team.&lt;/li>
&lt;li>&lt;strong>Signals:&lt;/strong> CVE-2026-19478 — CISA KEV: not listed, EPSS n/a, public PoC on GitHub&lt;/li>
&lt;/ul></description></item><item><title>Adobe Patches Three CVSS 10.0 Flaws in ColdFusion, Commerce, Campaign Classic</title><link>https://curasec.metacog.co.kr/insights/2026-08-12-adobe-patches-three-cvss-10-0-coldfusion-and-campaign-classi/</link><pubDate>Wed, 12 Aug 2026 11:57:00 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-08-12-adobe-patches-three-cvss-10-0-coldfusion-and-campaign-classi/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Plan:&lt;/strong> CVSS 10.0 OS command injection in ColdFusion and companion critical flaws in Commerce and Campaign Classic warrant prioritized patching this sprint. No KEV listing or public PoC yet, but severity justifies treating this ahead of routine patch cycles — apply Adobe&amp;rsquo;s August updates to all three products immediately.&lt;/li>
&lt;li>&lt;strong>SOC/IR — Skip&lt;/strong>&lt;/li>
&lt;li>&lt;strong>Leader — Skip&lt;/strong>&lt;/li>
&lt;li>&lt;strong>Signals:&lt;/strong> CVE-2026-48362 — CISA KEV: not listed, EPSS n/a, no public PoC found&lt;/li>
&lt;/ul></description></item><item><title>TeamCity On-Premises Critical RCE CVE-2026-63077 (CVSS 9.8)</title><link>https://curasec.metacog.co.kr/insights/2026-07-28-critical-teamcity-flaw-could-let-attackers-run-os-commands-w/</link><pubDate>Tue, 28 Jul 2026 13:01:43 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-07-28-critical-teamcity-flaw-could-let-attackers-run-os-commands-w/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Act:&lt;/strong> A public PoC on GitHub combined with a CVSS 9.8 unauthenticated RCE makes exploitation imminent — patch all on-premises TeamCity instances to 2025.11.7 or 2026.1.3 immediately; Cloud instances are already remediated.&lt;/li>
&lt;li>&lt;strong>SOC/IR — Act:&lt;/strong> With a public PoC now available, begin hunting for unauthenticated requests to TeamCity build/run endpoints and review build agent logs for unexpected OS command execution patterns since the PoC publication date.&lt;/li>
&lt;li>&lt;strong>Leader — Plan:&lt;/strong> Confirm whether your organization runs TeamCity On-Premises and verify the engineering team has prioritized emergency patching this week — a compromise of CI/CD pipelines carries supply-chain risk that could generate customer or board questions if exploitation is later confirmed.&lt;/li>
&lt;li>&lt;strong>Signals:&lt;/strong> CVE-2026-63077 — CISA KEV: not listed, EPSS n/a, public PoC on GitHub&lt;/li>
&lt;/ul></description></item><item><title>SAP Patches CVSS 9.9 NetWeaver ABAP Out-of-Bounds Write Flaw</title><link>https://curasec.metacog.co.kr/insights/2026-07-15-sap-patches-cvss-9-9-netweaver-abap-flaw-that-could-expose-o/</link><pubDate>Wed, 15 Jul 2026 12:11:39 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-07-15-sap-patches-cvss-9-9-netweaver-abap-flaw-that-could-expose-o/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Plan:&lt;/strong> SAP NetWeaver ABAP is widely deployed in enterprise environments and this authenticated out-of-bounds write carries a 9.9 CVSS; no KEV listing, EPSS near zero, and no public PoC mean there&amp;rsquo;s no immediate exploitation pressure, but apply SAP&amp;rsquo;s July 2026 security patches in your next maintenance window.&lt;/li>
&lt;li>&lt;strong>SOC/IR — Skip&lt;/strong>&lt;/li>
&lt;li>&lt;strong>Leader — Skip&lt;/strong>&lt;/li>
&lt;li>&lt;strong>Signals:&lt;/strong> CVE-2026-44747 — CISA KEV: not listed, EPSS 0.00, no public PoC found&lt;/li>
&lt;/ul></description></item></channel></rss>