CuraSec

tag: Cve · 29 items

2026-08-28 · The Hacker News · source ↗ #cve#rce#cpanel
  • Engineer — Act: A public PoC exists for a root-level RCE in cPanel and WHM affecting all supported versions — update cPanel/WHM to the patched release immediately and verify no unauthorized access occurred on any exposed panels.
  • SOC/IR — Plan: With a public PoC now available, write or enable detections for anomalous root-process spawning from cPanel/WHM processes and unusual web requests to the cPanel/WHM management interfaces before exploitation campaigns begin.
  • Leader — Skip
  • Signals: CVE-2026-65643 — CISA KEV: not listed, EPSS n/a, public PoC on GitHub
2026-08-18 · The Hacker News · source ↗ #wordpress#rce#cve
  • Engineer — Act: A public PoC exists for this unauthenticated file upload RCE (CVSS 9.8) affecting 600,000+ WordPress installs; update Forminator Forms to the patched version immediately and verify no malicious PHP files were uploaded to wp-content directories.
  • SOC/IR — Plan: With a public PoC available, exploitation attempts are likely imminent; build or tune WAF/SIEM rules to detect unauthenticated multipart file upload requests to Forminator endpoints and alert on unexpected PHP file creation under wp-content.
  • Leader — Skip
  • Signals: CVE-2026-15748 — CISA KEV: not listed, EPSS n/a, public PoC on GitHub
2026-08-15 · BleepingComputer · source ↗ #macos#cryptomining#cve
  • Engineer — Act: Active exploitation with public PoC — audit your macOS fleet for Screen Sharing (VNC) exposure and apply Apple’s patch immediately; disable Screen Sharing on hosts where it isn’t required.
  • SOC/IR — Act: Hunt for unexpected xmrig or Monero miner processes on macOS endpoints and check for anomalous outbound connections to mining pools since the PoC went public.
  • Leader — Learn: Active cryptomining campaign on macOS is unlikely to require board-level action, but confirms macOS is not a safe-harbor — useful context for endpoint policy discussions.
2026-08-13 · BleepingComputer · source ↗ #adobe-commerce#cve#active-exploitation
  • Engineer — Act: Active exploitation attempts against CVE-2026-71362 in Adobe Commerce and Magento have been observed despite low EPSS — if you run either platform, patch immediately and audit recent customer authentication logs for signs of account takeover.
  • SOC/IR — Plan: No IOCs or ATT&CK-mapped TTPs are available yet, but active exploitation is reported; build or tune detections for anomalous authentication patterns and privilege changes on Commerce/Magento instances in your estate.
  • Leader — Plan: If your organization or a key e-commerce vendor runs Adobe Commerce or Magento, confirm patching status this week and assess whether customer account data may have been exposed, given the reported exploitation activity.
  • Signals: CVE-2026-71362 — CISA KEV: not listed, EPSS 0.00, no public PoC found
2026-08-12 · The Hacker News · source ↗ #sharepoint#rce#cve
  • Engineer — Act: Public PoC on GitHub for a CVSS 9.1 unauthenticated RCE across SharePoint Server Subscription Edition, 2019, and 2016 means exploitation risk is immediate even without KEV listing; apply Microsoft’s patch for CVE-2026-55040 across all affected on-prem SharePoint instances this week.
  • SOC/IR — Plan: No confirmed in-the-wild exploitation yet (EPSS 0.02, no KEV), but a public PoC for unauthenticated RCE warrants building SharePoint-specific detections now — hunt for anomalous unauthenticated requests to SharePoint REST/SOAP endpoints and tune alerts on privilege escalation patterns in SharePoint audit logs before active campaigns emerge.
  • Leader — Plan: A CVSS 9.1 unauthenticated RCE with public PoC against widely deployed SharePoint Server warrants confirming on-prem SharePoint scope with your team and ensuring patch prioritization this sprint — escalate to Act if exploitation is observed in the wild.
  • Signals: CVE-2026-55040 — CISA KEV: not listed, EPSS 0.02, public PoC on GitHub
2026-08-12 · The Hacker News · source ↗ #cisco#network-security#cve
  • Engineer — Act: CISA KEV listed, actively exploited in the wild, and a public PoC exists — patch Cisco ASA and FTD software immediately per Cisco’s advisory for CVE-2026-20349; perimeter firewall availability is at direct risk from unauthenticated remote attackers.
  • SOC/IR — Act: Active exploitation of an edge security appliance warrants an assume-breach sweep — hunt for anomalous or malformed HTTP requests targeting ASA/FTD management interfaces and investigate any unexplained firewall availability incidents since this KEV listing date.
  • Leader — Plan: A CISA KEV-confirmed flaw in widely deployed perimeter firewalls is a priority patching event — confirm your engineering team has this on the sprint and assess whether any availability SLAs tied to ASA/FTD deployments are at risk; DoS scope limits board-level urgency but warrants direct follow-up with the team.
  • Signals: CVE-2026-20349 — CISA KEV: listed, EPSS n/a, public PoC on GitHub
2026-08-09 · The Hacker News · source ↗ #cve#load-balancer#active-exploitation
  • Engineer — Act: CISA KEV-listed, EPSS 0.99, public PoC, and 792 confirmed exploit attempts make this an emergency patch. Apply the Progress Kemp LoadMaster patch immediately or isolate the appliance from untrusted networks until patched.
  • SOC/IR — Act: Active exploitation of a perimeter load balancer warrants an assume-breach sweep — hunt for command injection patterns in LoadMaster access logs since the first reported attempts, and check downstream hosts for lateral movement indicators.
  • Leader — Act: CISA KEV listing plus confirmed active exploitation makes this a board-question-level appliance vulnerability; confirm this week whether LoadMaster is in your environment and verify engineering has patched or isolated affected instances.
  • Signals: CVE-2026-8037 — CISA KEV: listed, EPSS 0.99, public PoC on GitHub
2026-08-07 · HN (cve) · source ↗ #kvm#hypervisor-escape#cve
  • Engineer — Act: A public PoC for a guest-to-host escape in KVM/x86 exists on GitHub — this breaks VM isolation and affects any Linux host using KVM (cloud workloads, CI runners, on-prem virtualization). Identify your kernel version, check vendor advisories for a patched kernel, and prioritize upgrading hypervisor hosts.
  • SOC/IR — Learn: No active exploitation or published IOCs yet, so no immediate hunt is warranted; however, understanding the escape class is useful for future detection design around anomalous host-side activity originating from guest processes.
  • Leader — Skip
  • Signals: CVE-2026-64561 — CISA KEV: not listed, EPSS 0.00, public PoC on GitHub, reported by 2 collected sources
2026-08-04 · BleepingComputer · source ↗ #cve#auth-bypass#active-exploitation
  • Engineer — Act: CVE-2026-18577 is CISA KEV-listed with a public PoC and confirmed active exploitation — patch N-central immediately to the vendor-specified fixed version, and audit logs for unauthorized access since the vulnerability affects both hosted and on-premises deployments.
  • SOC/IR — Act: Active exploitation of N-central means assume-breach posture for any org running it — sweep for anomalous authentication events on N-central servers and hunt for lateral movement originating from managed endpoints, as compromise of an RMM tool gives attackers broad access to managed devices.
  • Leader — Act: N-central is an RMM platform used by MSPs; if your organization or any MSP managing your environment runs it, request an immediate attestation of patch status and review whether threat actors could have used it as a pivot into your estate — this is the type of systemic MSP-chain risk worth a brief to leadership this week.
  • Signals: CVE-2026-18577 — CISA KEV: listed, EPSS 0.01, public PoC on GitHub, reported by 2 collected sources
2026-07-29 · The Hacker News · source ↗ #browser-rce#firefox#cve
  • Engineer — Act: A public PoC on GitHub for a no-interaction arbitrary code execution flaw in Firefox’s renderer means drive-by exploitation is immediately practical; update Firefox to 151.0.3 across all managed endpoints and verify Tor Browser is similarly patched or blocked.
  • SOC/IR — Plan: With a public PoC now circulating, watering-hole operators may weaponize this quickly; build or tune detections for unexpected child processes spawned from the Firefox renderer process and prepare a hunt query scoped to the weeks before the 151.0.3 fix shipped.
  • Leader — Skip
  • Signals: CVE-2026-10702 — CISA KEV: not listed, EPSS 0.01, public PoC on GitHub
2026-07-23 · The Hacker News · source ↗ #browser-extension#cve#data-exposure
  • Engineer — Plan: The patched Adobe Acrobat Chrome extension (CVE-2026-48294) could allow malicious sites to silently read WhatsApp Web session data; public PoC exists but EPSS is 0.01 and KEV-unlisted. Audit enterprise browser policies and confirm the extension has been updated to the patched version across managed endpoints.
  • SOC/IR — Learn: No active exploitation campaign or IOCs published; the HermeticReader attack chain demonstrates how a privileged browser extension can be abused to silently cross-read web app data — useful context for evaluating browser extension detection coverage but no immediate hunt or rule-write warranted.
  • Leader — Skip
  • Signals: CVE-2026-48294 — CISA KEV: not listed, EPSS 0.01, public PoC on GitHub
2026-07-22 · The Hacker News · source ↗ #ransomware#pan-os#cve
  • Engineer — Act: CVE-2026-0257 is CISA KEV-listed with EPSS 0.87 and a public PoC; Qilin actors are actively using it as initial access via PAN-OS portal and gateway. Patch PAN-OS to the fixed release immediately and audit gateway/portal access logs for unauthorized sessions since June 2026.
  • SOC/IR — Act: Qilin (Agenda) ransomware operators are actively exploiting PAN-OS edge devices as a beachhead — assume-breach sweep is warranted on any PAN-OS-fronted environment. Hunt for Qilin TTPs and lateral movement artifacts dating back to June 2026, and tune EDR/SIEM detections for Agenda ransomware staging behavior.
  • Leader — Act: Qilin ransomware is actively deploying via a widely-used firewall/VPN product; this is board-question-level exposure if your organization runs PAN-OS. Confirm patch status with your engineering team this week and prepare a brief for leadership on whether any environment may have been affected during the June 2026 exploitation window.
  • Signals: CVE-2026-0257 — CISA KEV: listed, EPSS 0.87, public PoC on GitHub
2026-07-21 · HN (vulnerability) · source ↗ #privilege-escalation#cve#linux
  • Engineer — Plan: A privilege escalation CVE in OpenClaw warrants patching, but with no KEV listing, public PoC, or EPSS signal in the enrichment data, exploitation pressure is unconfirmed — schedule a patch to the latest fixed version within your normal critical-patch window and verify if OpenClaw is present in your environment.
  • SOC/IR — Skip
  • Leader — Skip
2026-07-21 · BleepingComputer · source ↗ #ai-coding-tools#sandbox-escape#cve
  • Engineer — Plan: Patches are available for Cursor, Codex, and Gemini CLI; update all three and audit any AI agent file-write permissions to ensure automated pipelines don’t blindly execute AI-generated scripts. No active exploitation is reported and no KEV/PoC signals present, so this is patch-cycle priority rather than emergency.
  • SOC/IR — Learn: The attack class — an AI agent writing files that trusted host tools later execute — is a novel indirect execution path worth understanding for future detection work, but this disclosure provides no IOCs, no ATT&CK mapping, and no evidence of in-the-wild exploitation to act on now.
  • Leader — Plan: Multiple widely-used AI coding assistants were found to have sandbox escapes; inventory which tools developers are using, confirm patched versions are deployed, and this quarter establish a policy requiring approved-tool lists and update cadence for AI development tooling before broader enterprise rollout.
2026-07-20 · The Hacker News · source ↗ #nginx#rce#cve
  • Engineer — Act: NGINX is near-universal in cloud stacks and a public PoC already exists on GitHub, lowering the bar for exploitation despite low EPSS. Upgrade to nginx 1.30.4 (stable) or 1.31.3 (mainline), or NGINX Plus 37.0.3.1, before the PoC matures into a weaponized exploit.
  • SOC/IR — Skip
  • Leader — Skip
  • Signals: CVE-2026-42533 — CISA KEV: not listed, EPSS 0.01, public PoC on GitHub
2026-07-16 · The Hacker News · source ↗ #browser-security#cve#patch
  • Engineer — Act: CVE-2026-15719 has a public PoC on GitHub and Mozilla acknowledges public exploit code exists; update Firefox to the patched release immediately across all managed endpoints and developer workstations.
  • SOC/IR — Plan: With public exploit code confirmed for Firefox WebAssembly and DOM navigation flaws, build or tune detections for browser exploitation patterns (unusual child processes, suspicious renderer crashes) and prepare to hunt if active exploitation is reported.
  • Leader — Skip
  • Signals: CVE-2026-15718 — CISA KEV: not listed, EPSS 0.00, no public PoC found · CVE-2026-15719 — CISA KEV: not listed, EPSS 0.00, public PoC on GitHub
2026-07-14 · HN (security) · source ↗ #dns#cve#network-infrastructure
  • Engineer — Plan: Dnsmasq is embedded in Kubernetes nodes, containers, and network appliances at scale; six CERT-issued serious CVEs warrant auditing all deployments and scheduling patches as soon as vendor-specific builds are available — no exploitation signals yet, but the network-accessible attack surface (DNS/DHCP) is historically high-value.
  • SOC/IR — Skip
  • Leader — Learn: Noteworthy as a potential systemic risk given dnsmasq’s ubiquity in Linux and embedded network gear, but without confirmed exploitation or a Log4Shell-scale event there is no leadership action required today — confirm teams are tracking patches.
2026-07-12 · HN (cve) · source ↗ #minio#cve#supply-chain
  • Engineer — Plan: MinIO is widely deployed as self-hosted S3-compatible storage in Kubernetes environments; the vendor’s refusal to ship patched Docker images means the standard docker pull update path will not remediate CVE-2025-62506. Engineers running MinIO via Docker should plan to build from source or use official binary releases to obtain the fix, and track the issue — public PoC raises exposure even at EPSS 0.01.
  • SOC/IR — Skip
  • Leader — Learn: The vendor’s policy of withholding patched Docker images is a meaningful vendor security posture signal worth noting in vendor risk reviews if MinIO is in your stack, but low EPSS and no KEV listing mean this does not rise to executive action yet.
  • Signals: CVE-2025-62506 — CISA KEV: not listed, EPSS 0.01, public PoC on GitHub
2026-07-12 · HN (cve) · source ↗ #linux-kernel#rust#cve
  • Engineer — Learn: Notable milestone — Rust in the kernel is not immune to CVEs; no exploitation signals, PoC, or KEV listing, so no immediate patching action, but worth tracking this new vulnerability class as Rust kernel code expands.
  • SOC/IR — Skip
  • Leader — Skip
2026-07-12 · HN (cve) · source ↗ #langchain#cve#supply-chain
  • Engineer — Act: A public PoC exists for this critical langchain-core flaw, making exploitation practical for any AI pipeline that processes untrusted input; audit Python environments and upgrade langchain-core to the patched release immediately.
  • SOC/IR — Plan: No active exploitation campaign observed (EPSS 0.14, not KEV-listed), but the public PoC warrants building detections for anomalous subprocess or file-system activity spawned from LangChain worker processes before exploitation picks up.
  • Leader — Skip
  • Signals: CVE-2025-68664 — CISA KEV: not listed, EPSS 0.14, public PoC on GitHub
  • Engineer — Learn: High community engagement (712 HN points) suggests a substantive technical incident post-mortem worth reading, but the summary contains no software names, patch targets, or affected versions — read the full post to determine if it touches systems you run.
  • SOC/IR — Learn: No IOCs, TTPs, or detection surface are visible in the summary; if the linked post-mortem contains campaign or exploitation details, revisit for detection value after reading.
  • Leader — Skip
  • Engineer — Act: GoAnywhere MFT is a common enterprise managed-file-transfer appliance; CISA KEV listing plus EPSS 1.00 plus a public GitHub PoC means exploitation is active now. Patch to the vendor-fixed release immediately or take the instance offline until patching is complete.
  • SOC/IR — Act: Prior GoAnywhere exploitation by Cl0p hit hundreds of organizations; treat any unpatched instance as potentially compromised. Hunt for anomalous outbound transfers, newly created admin accounts, and lateral movement originating from GoAnywhere servers since the PoC became public.
  • Leader — Act: The 2023 Cl0p GoAnywhere campaign was a marquee supply-chain breach; this CVE matches or exceeds that severity signal (EPSS 1.00, KEV-listed). Confirm this week whether your org or critical MFT vendors run GoAnywhere and obtain patch attestations before history repeats.
  • Signals: CVE-2025-10035 — CISA KEV: listed, EPSS 1.00, public PoC on GitHub
  • Engineer — Act: EPSS 0.93 plus a public GitHub PoC makes exploitation practical now — patch the Linux kernel to the distro-provided fixed package (check RHEL, Ubuntu, Debian advisories) across all Linux hosts and container base images within your patch window.
  • SOC/IR — Act: With a public PoC and EPSS 0.93, exploitation attempts are likely imminent; hunt for anomalous privilege escalation events on Linux endpoints since PoC publication and tune EDR/SIEM rules for kernel LPE behavior patterns.
  • Leader — Plan: A second high-severity Linux LPE with a public PoC in eight days signals a pattern worth tracking; confirm your Linux patch cadence will address this within days and assess the size of your externally accessible Linux estate.
  • Signals: CVE-2026-43284 — CISA KEV: not listed, EPSS 0.93, public PoC on GitHub
2026-07-12 · HN (cve) · source ↗ #rce#exim#cve
  • Engineer — Act: Unauthenticated RCE on a widely-deployed internet-facing MTA with a public PoC on GitHub demands immediate action regardless of low EPSS — Exim has a history of mass exploitation. Patch Exim to the version addressing CVE-2026-45185; if no patch is yet available, restrict SMTP exposure at the network layer while tracking vendor advisory.
  • SOC/IR — Plan: No active exploitation confirmed in enrichment signals, but a public PoC for pre-auth RCE on an internet-facing mail server shortens the window — build or stage Exim-specific detections (unusual child processes spawned from the Exim process, unexpected outbound connections from mail servers) before exploitation ramps up.
  • Leader — Skip
  • Signals: CVE-2026-45185 — CISA KEV: not listed, EPSS 0.01, public PoC on GitHub
  • Engineer — Act: CISA KEV listed, EPSS 0.96, and public PoC on GitHub — exploitation is active and practical. Identify your container runtime version, patch to the fixed release immediately, and audit container environments for signs of exploitation.
  • SOC/IR — Act: Active exploitation confirmed via CISA KEV; hunt for container escape and unexpected privilege escalation events in your EDR and container logs since the PoC dropped in early May 2026, and tune detections for abnormal rootless container behavior.
  • Leader — Plan: CISA KEV listing and near-perfect EPSS signal active exploitation in the wild; confirm with engineering that all container runtime deployments are on a patched version and add this to the sprint’s prioritized patch list.
  • Signals: CVE-2026-31431 — CISA KEV: listed, EPSS 0.96, public PoC on GitHub
2026-07-12 · HN (cve) · source ↗ #cve#macos#kernel
  • Engineer — Plan: Kernel privilege-escalation vulnerability with a public PoC but EPSS of 0.01 and no KEV listing indicates no active exploitation yet; apply the Apple security update for macOS 26.5 in your next patching cycle, prioritizing any macOS-based CI/CD or developer endpoints where LPE would be high-impact.
  • SOC/IR — Skip
  • Leader — Skip
  • Signals: CVE-2026-28952 — CISA KEV: not listed, EPSS 0.01, public PoC on GitHub
  • Engineer — Act: Public PoC exists for a symlink-based sandbox escape in Claude Code, which engineers and CI/CD pipelines commonly run; update Claude Code to the patched release immediately and audit any pipelines that invoke it with elevated filesystem access.
  • SOC/IR — Learn: Low EPSS (0.01) and no active exploitation campaign; no IOCs or ATT&CK-mappable TTPs are provided, but the symlink sandbox-escape technique is worth noting if Claude Code runs in monitored developer environments.
  • Leader — Skip
  • Signals: CVE-2026-39861 — CISA KEV: not listed, EPSS 0.01, public PoC on GitHub
2026-07-12 · HN (cve) · source ↗ #browser-security#zero-day#cve
  • Engineer — Act: KEV-listed zero-day actively exploited in Chrome’s CSS engine; update Chrome/Chromium to the patched stable release immediately and verify managed browsers in your fleet are on the latest version.
  • SOC/IR — Act: Active in-the-wild exploitation means assume-breach posture for any endpoint running unpatched Chrome; hunt for suspicious child processes or unusual network connections from Chrome since the February 2026 stable release date, and check EDR telemetry for exploitation indicators.
  • Leader — Plan: CISA KEV listing confirms active exploitation of a Chrome browser zero-day; validate that your IT/engineering teams have a forced browser-update mechanism and confirm rollout completion — this is routine but warrants a status check given KEV designation.
  • Signals: CVE-2026-2441 — CISA KEV: listed, EPSS 0.22, public PoC on GitHub
2026-07-10 · HN (cve) · source ↗ #kvm#vm-escape#cve
  • Engineer — Plan: Public PoC exists for a guest-to-host VM escape in KVM/x86, meaning any Linux host running KVM hypervisors is potentially exposed; patch your kernel to a fixed version once available and audit whether untrusted VMs run on shared KVM hosts.
  • SOC/IR — Learn: No active exploitation or IOCs reported yet; monitor for exploitation activity targeting KVM hosts, but no detection work is actionable until TTPs or exploitation patterns emerge.
  • Leader — Skip
  • Signals: CVE-2026-53359 — CISA KEV: not listed, EPSS 0.00, public PoC on GitHub