⤷ Title: CVE-2026-21580: Stored XSS Hits Atlassian Confluence
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Wed, 19 Aug 2026 06:39:11 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Atlassian #Confluence #Confluence Vulnerability #CVE_2026_21580 #CVE_2026_21582 #Jira Service Management #Stored XSS
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Wed, 19 Aug 2026 06:39:11 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Atlassian #Confluence #Confluence Vulnerability #CVE_2026_21580 #CVE_2026_21582 #Jira Service Management #Stored XSS
Daily CyberSecurity
CVE-2026-21580: Stored XSS Hits Atlassian Confluence
TL;DR Atlassian patched two high-severity flaws in its self-hosted products. The first, CVE-2026-21580, is a stored XSS bug in Confluence. This Confluence vulnerability scores a CVSS of 8.6 and ne…
⤷ Title: CVE-2026–40901: DataEase Root RCE via Unfiltered Quartz Deserialization
════════════════════════
𐀪 Author: Guidancewhite
════════════════════════
ⴵ Time: Wed, 19 Aug 2026 06:57:55 GMT
════════════════════════
⌗ Tags: #sql_injection #rce #vulnerability #database #java
════════════════════════
𐀪 Author: Guidancewhite
════════════════════════
ⴵ Time: Wed, 19 Aug 2026 06:57:55 GMT
════════════════════════
⌗ Tags: #sql_injection #rce #vulnerability #database #java
Medium
CVE-2026–40901: DataEase Root RCE via Unfiltered Quartz Deserialization
1. Overview
⤷ Title: CVE-2026-18051 (CVSS 10): Unauthenticated Arbitrary File Write Hits 900k W3 Total Cache Sites
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Wed, 19 Aug 2026 08:53:14 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Arbitrary File Write #CVE_2026_18051 #Path Traversal #W3 Total Cache #wordpress #WordPress Plugin #wpscan
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Wed, 19 Aug 2026 08:53:14 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Arbitrary File Write #CVE_2026_18051 #Path Traversal #W3 Total Cache #wordpress #WordPress Plugin #wpscan
Daily CyberSecurity
CVE-2026-18051 (CVSS 10): Unauthenticated Arbitrary File Write Hits 900k W3 Total Cache Sites
TL;DR A critical W3 Total Cache vulnerability lets unauthenticated attackers write files anywhere on the server. Tracked as CVE-2026-18051, it earns the top CVSS score of 10. The plugin runs on mo…
⤷ Title: 737 Chrome VPN and proxy extensions were found routing traffic to malicious proxies
════════════════════════
𐀪 Author: Stanislav Klevtsov
════════════════════════
ⴵ Time: Wed, 19 Aug 2026 09:31:23 GMT
════════════════════════
⌗ Tags: #security #vulnerability #infosec #cybersecurity
════════════════════════
𐀪 Author: Stanislav Klevtsov
════════════════════════
ⴵ Time: Wed, 19 Aug 2026 09:31:23 GMT
════════════════════════
⌗ Tags: #security #vulnerability #infosec #cybersecurity
Medium
737 Chrome VPN and proxy extensions were found routing traffic to malicious proxies
The campaign mainly targeted russian-speaking users by faking established VPN and privacy brands, including Proton VPN, NordVPN, and…
⤷ Title: Nmap — TryHackMe Room Writeup
════════════════════════
𐀪 Author: Nizam Uddin
════════════════════════
ⴵ Time: Wed, 19 Aug 2026 09:42:34 GMT
════════════════════════
⌗ Tags: #vulnerability_assessment #cybersecurity #network_scanning #nmap #penetration_testing
════════════════════════
𐀪 Author: Nizam Uddin
════════════════════════
ⴵ Time: Wed, 19 Aug 2026 09:42:34 GMT
════════════════════════
⌗ Tags: #vulnerability_assessment #cybersecurity #network_scanning #nmap #penetration_testing
Medium
Nmap — TryHackMe Room Writeup
Welcome to my Nmap room writeup! 📃🔐
⤷ Title: CVE-2026-19490 (CVSS 9.3): NetScaler Authentication Bypass Flaw Patched
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Wed, 19 Aug 2026 15:21:47 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Authentication Bypass #Citrix #CVE_2026_19489 #CVE_2026_19490 #NetScaler #NetScaler ADC #NetScaler Gateway
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Wed, 19 Aug 2026 15:21:47 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Authentication Bypass #Citrix #CVE_2026_19489 #CVE_2026_19490 #NetScaler #NetScaler ADC #NetScaler Gateway
Daily CyberSecurity
CVE-2026-19490 (CVSS 9.3): NetScaler Authentication Bypass Flaw Patched
TL;DR Citrix patched a critical NetScaler authentication bypass tracked as CVE-2026-19490. It scores 9.3 on CVSS v4. A second flaw, CVE-2026-19489, can cause denial of service. Why it matters NetS…
⤷ Title: Vault Secrets Operator Flaw CVE-2026-8715 Enables Privilege Escalation
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Wed, 19 Aug 2026 14:03:42 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #AppRole #Arbitrary File Read #CVE_2026_8715 #HashiCorp #Kubernetes #privilege escalation #RBAC #Vault Secrets Operator
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Wed, 19 Aug 2026 14:03:42 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #AppRole #Arbitrary File Read #CVE_2026_8715 #HashiCorp #Kubernetes #privilege escalation #RBAC #Vault Secrets Operator
Daily CyberSecurity
Vault Secrets Operator Flaw CVE-2026-8715 Enables Privilege Escalation
HashiCorp disclosed a Vault Secrets Operator vulnerability this week. Then, the bug, tracked as CVE-2026-8715, scores a 9.6 on the CVSS scale. It can lead to privilege escalation inside a Kubernet…
⤷ Title: CVE-2026-66792 (CVSS 9.9): Red Hat ACM Flaw Allows Full Compromise of the Managed Cluster
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Wed, 19 Aug 2026 13:44:58 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CVE_2026_66792 #CVE_2026_66795 #CVE_2026_71472 #Kubernetes #privilege escalation #Red Hat ACM
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Wed, 19 Aug 2026 13:44:58 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CVE_2026_66792 #CVE_2026_66795 #CVE_2026_71472 #Kubernetes #privilege escalation #Red Hat ACM
Daily CyberSecurity
CVE-2026-66792 (CVSS 9.9): Red Hat ACM Flaw Allows Full Compromise of the Managed Cluster
TL;DR Red Hat disclosed three critical flaws in its multicluster Kubernetes products. The most severe, CVE-2026-66792, scores a CVSS 9.9. It lets a privileged user on a managed cluster escalate to…
⤷ Title: CVE-2026-0075: PoC Discloses Android EoP With No User Interaction
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Wed, 19 Aug 2026 13:26:29 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #android #ContactsProvider2 #CVE_2026_0075 #Elevation of Privilege #proof_of_concept #sql injection
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Wed, 19 Aug 2026 13:26:29 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #android #ContactsProvider2 #CVE_2026_0075 #Elevation of Privilege #proof_of_concept #sql injection
Daily CyberSecurity
CVE-2026-0075: PoC Discloses Android EoP With No User Interaction
TL;DR Google patched CVE-2026-0075, an Android elevation of privilege flaw in ContactsProvider2. The bug can expose the contacts database through SQL injection, with no user interaction required. …
⤷ Title: IBM Db2 Mirror for i Hit by CVE-2026-17186 RCE Flaw (CVSS 9.9)
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Wed, 19 Aug 2026 13:15:45 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Authentication Bypass #Command Injection #CVE_2026_17182 #CVE_2026_17184 #CVE_2026_17186 #Db2 Mirror for i #IBM #IBM i #Path Traversal #Remote Code Execution
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Wed, 19 Aug 2026 13:15:45 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Authentication Bypass #Command Injection #CVE_2026_17182 #CVE_2026_17184 #CVE_2026_17186 #Db2 Mirror for i #IBM #IBM i #Path Traversal #Remote Code Execution
Daily CyberSecurity
IBM Db2 Mirror for i Hit by CVE-2026-17186 RCE Flaw (CVSS 9.9)
IBM patched 18 flaws in Db2 Mirror for i this week. The worst bug lets a remote attacker run system commands without logging in. IBM Db2 Mirror RCE risk reaches a CVSS score of 9.9. Also, several …