Visualização normal

Antes de ontemCybersecurity News
  • ✇Cybersecurity News
  • CVE-2026-9586: Switchvox RCE Exploited in the Wild Do Son
    CVE-2026-9586, a critical Sangoma Switchvox vulnerability, is exploited in the wild, giving unauthenticated attackers SQL injection and remote code execution. Related Posts: Critical Google Chrome Vulnerabilities Patched in New Update CVE-2026-80047: Hugging Face Transformers Library Vulnerability CVE-2026-68162: Linux Kernel Root Escalation PoC Public The post CVE-2026-9586: Switchvox RCE Exploited in the Wild appeared first on Daily CyberSecurity.
     
  • ✇Cybersecurity News
  • CVE-2026-18885 (CVSS 10): ServiceNow Code Injection and SQL Injection Flaws Patched Do Son
    ServiceNow patched CVE-2026-18885, CVE-2026-18886, and CVE-2026-74820, code injection and SQL injection flaws rated CVSS 10, plus a CVSS 8.7 bug. Related Posts: Critical MongoDB Security Vulnerabilities Require Immediate Patching CVE-2026-73125: Ebyte NA111-M Flaws Let Attackers Fully Compromise the Device D-Link DIR-X1860Z Flaw Lets Attackers Change the Admin Password Without Login The post CVE-2026-18885 (CVSS 10): ServiceNow Code Injection and SQL Injection Flaws Patched appeared first on
     
  • ✇Cybersecurity News
  • CVE-2026-20030: Cisco Crosswork SQL Command Injection Scores CVSS 10.0 Do Son
    Cisco patches a Crosswork SQL injection flaw, CVE-2026-20030, rated CVSS 10.0. A BroadWorks XXE bug (CVE-2026-20320) also gets a fix. Related Posts: CVE-2026-47301: PoC Exploit Achieves SYSTEM-Level Code Execution in SCCM CVE-2026-66780 (CVSS 9.9): MITM Flaw Hits Red Hat ACM CVE-2026-76404: Critical Remote Code Execution Hits Splunk MCP Server App (CVSS 9.1) The post CVE-2026-20030: Cisco Crosswork SQL Command Injection Scores CVSS 10.0 appeared first on Daily CyberSecurity.
     
  • ✇Cybersecurity News
  • CVE-2026-0075: PoC Discloses Android EoP With No User Interaction Do Son
    A public PoC for CVE-2026-0075 exposes an Android elevation of privilege in ContactsProvider2 with no user interaction. Details are now disclosed. Related Posts: CVE-2026-47301: PoC Exploit Achieves SYSTEM-Level Code Execution in SCCM CVE-2026-66780 (CVSS 9.9): MITM Flaw Hits Red Hat ACM CVE-2026-76404: Critical Remote Code Execution Hits Splunk MCP Server App (CVSS 9.1) The post CVE-2026-0075: PoC Discloses Android EoP With No User Interaction appeared first on Daily CyberSecurity.
     
  • ✇Cybersecurity News
  • GeoServer Unauthenticated SQL Injection (CVSS 9.8) Exploited in the Wild, PoC Public Do Son
    A GeoServer unauthenticated SQL injection (CVSS 9.8) is exploited in the wild. A public PoC reaches RCE. Patch GeoServer now. Related Posts: CVE-2026-71290: Apache HttpClient Flaw Lets Attackers Intercept and Modify Traffic (CVSS 9.1) PoC Discloses for CVE-2026-64849: watchTowr Sees Attacks on MLflow SSRF CVE-2026-75045: Unauthenticated Attacker Could Download YouTrack Database Backups The post GeoServer Unauthenticated SQL Injection (CVSS 9.8) Exploited in the Wild, PoC Public appeared first
     
  • ✇Cybersecurity News
  • CVE-2025-41771: SQL Injection Flaw Hits Phoenix Contact PLCnext Do Son
    Phoenix Contact patched three PLCnext flaws, including CVE-2025-41771, which lets an attacker execute unauthorized SQL queries, plus a CVSS 9.8 RCE bug. Related Posts: Apache Struts Patches Five Flaws Including Unauthenticated DoS Bugs Roundcube Patches RCE and SSRF Flaws in 1.6.18 and 1.7.3 CVE-2026-15826: User Profile Builder Bug Under Active Attack, Grants Full Admin Takeover (CVSS 9.8) The post CVE-2025-41771: SQL Injection Flaw Hits Phoenix Contact PLCnext appeared first on Daily CyberSe
     
  • ✇Security Affairs
  • GeoServer Zero-Day Is Already Being Probed. That’s the Problem Pierluigi Paganini
    GeoServer faces an unpatched zero-day enabling SQL injection and potentially RCE, with attackers already probing exposed systems. A newly disclosed GeoServer zero-day is already attracting active exploitation attempts, and there is no patch available yet. Organisations running the open-source geospatial platform should check their exposure. A security researcher with the handler q1uf3ng discloded the vulnerability that has yet to be assigned a CVE identifier. 实话说今天是非常不开心的一天 实际上最近一段时间
     

GeoServer Zero-Day Is Already Being Probed. That’s the Problem

15 de Agosto de 2026, 04:18

GeoServer faces an unpatched zero-day enabling SQL injection and potentially RCE, with attackers already probing exposed systems.

A newly disclosed GeoServer zero-day is already attracting active exploitation attempts, and there is no patch available yet. Organisations running the open-source geospatial platform should check their exposure.

A security researcher with the handler q1uf3ng discloded the vulnerability that has yet to be assigned a CVE identifier.

实话说今天是非常不开心的一天 实际上最近一段时间我都非常沮丧 各种事情
所以我公布一个0day 希望让你们心情变的开心

GeoServer jsonArrayContains 未授权 SQL 注入 数据库sa的情况下理所当然的可以rce pic.twitter.com/0uTUyMNYU4

— 秋风 (@q1uf3ng) August 12, 2026

The flaw lies in the jsonArrayContains functionality and allows unauthorised SQL injection. Under some configurations, especially where the service can reach a privileged database account, that path may lead to remote code execution

The vulnerability has yet to be assigned a CVE identifier.

The issue was publicly disclosed on 12 August 2026. Within hours, watchTowr said it had begun seeing exploitation attempts, with hundreds of probes coming from a small number of IP addresses.

“Within hours of public disclosure, we began observing exploitation attempts and have since recorded hundreds of attempts originating from a small number of source IP addresses. Yet another example of how quickly attackers move once a vulnerability enters the public domain,” said WatchTowr’s Jake Knott.

That timing matters. Once a proof of concept or enough technical detail is public, attackers don’t need to wait for a polished exploit. They can scan broadly, trigger errors, compare responses, and build a list of systems worth revisiting later. It’s reconnaissance with an error message as a compass.

Threat actors are probing vulnerable GeoServer systems, but no follow-up activity has been observed yet. However, researchers warn exploitation could soon escalate.

“However, this is unlikely to remain the case for long: GeoServer has a track record of being targeted and exploited at scale, with multiple vulnerabilities listed in CISA’s Known Exploited Vulnerabilities catalog,” Knott added.

“With no patch currently available and exploitation already underway, organizations running GeoServer should take this vulnerability seriously and, where possible, identify exposed instances, restrict public access, and monitor for a vendor fix,”

Attackers are probing GeoServer systems for the unpatched zero-day, triggering errors to identify vulnerable targets before likely exploitation.

GeoServer is a popular platform for publishing and sharing geographic data through web services. It appears in public-sector portals, environmental platforms, mapping projects, utilities, transport systems, research institutions, and internal business applications. That makes a remotely reachable instance more than a technical footnote; it may expose geospatial information, backend services, credentials, or a route into a wider network.

The absence of a patch changes the usual response. Teams cannot simply schedule an update and move on. They need to identify every GeoServer instance, determine whether it is internet-facing, restrict access wherever possible, inspect logs for unusual requests and database errors, and limit the permissions available to the application’s database account.

This is also not GeoServer’s first encounter with active exploitation. In 2024, attackers used the critical GeoServer GeoTools vulnerability CVE-2024-36401 (CVSS score of 9.8), to pull compromised systems into DDoS and cryptocurrency-mining botnets and residential proxy networks. That history does not prove that every exposed instance will be compromised this time, but it does make complacency hard to defend.

The practical priority is exposure reduction. Put GeoServer behind a VPN, a reverse proxy, IP allow-listing, or another access-control layer if the service does not need to be public. If public access is unavoidable, treat it as a temporary high-risk exception, watch it closely, and prepare to apply the vendor fix as soon as it arrives.

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, zero-day)

  • ✇Cybersecurity News
  • Metabase SQL Injection Zero-Day (CVSS 10) Exploited Do Son
    A critical Metabase SQL injection zero-day (CVSS 10) is exploited in the wild. Unauthenticated attackers gain admin access. Patch now. Related Posts: CVE-2026-27912: PoC Released for SYSTEM Privilege Flaw CVE-2026-58231 (CVSS 10.0) and Code Injection RCE Flaws Top SAP August 2026 Patch Day Windows PnP Attack Chain Turns a USB Plug Into SYSTEM: Details and PoC Now Public The post Metabase SQL Injection Zero-Day (CVSS 10) Exploited appeared first on Daily CyberSecurity.
     
❌
❌