⤷ Title: CVE-2026-55040 PoC Released for SharePoint Authentication Bypass
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Wed, 12 Aug 2026 06:14:17 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Authentication Bypass #CVE_2026_55040 #JWT #proof_of_concept #Rapid7 #Sharepoint
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Wed, 12 Aug 2026 06:14:17 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Authentication Bypass #CVE_2026_55040 #JWT #proof_of_concept #Rapid7 #Sharepoint
Daily CyberSecurity
CVE-2026-55040 PoC Released for SharePoint Authentication Bypass
TL;DR Rapid7 has published a technical analysis and a working proof-of-concept for CVE-2026-55040. The flaw is a critical SharePoint authentication bypass that lets a remote, unauthenticated attac…
⤷ Title: CVE-2021–35042 : Django QuerySet.order_by() SQL Injection
════════════════════════
𐀪 Author: Arya Utomo
════════════════════════
ⴵ Time: Wed, 12 Aug 2026 08:21:07 GMT
════════════════════════
⌗ Tags: #programming #penetration_testing #cve #cybersecurity
════════════════════════
𐀪 Author: Arya Utomo
════════════════════════
ⴵ Time: Wed, 12 Aug 2026 08:21:07 GMT
════════════════════════
⌗ Tags: #programming #penetration_testing #cve #cybersecurity
Medium
CVE-2021–35042 : Django QuerySet.order_by() SQL Injection
1. Ringkasan Eksekutif
⤷ Title: CVE-2026-71319: Nuxt DevTools Flaw With 7.3 Million Monthly Downloads Allows Arbitrary Command Execution, CVSS 9.6
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Wed, 12 Aug 2026 13:18:48 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Arbitrary Command Execution #CVE_2026_71319 #CVSS 9.6 #Nuxt #Nuxt DevTools #RPC #Vue.js
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Wed, 12 Aug 2026 13:18:48 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Arbitrary Command Execution #CVE_2026_71319 #CVSS 9.6 #Nuxt #Nuxt DevTools #RPC #Vue.js
Daily CyberSecurity
CVE-2026-71319: Nuxt DevTools Flaw With 7.3 Million Monthly Downloads Allows Arbitrary Command Execution, CVSS 9.6
TL;DR A critical Nuxt DevTools vulnerability lets an attacker run arbitrary commands on a developer’s machine. Tracked as CVE-2026-71319, it scores 9.6 on CVSS. The Nuxt package sees more th…
⤷ Title: CVE-2026-61515: Unauthenticated Command Injection in Puwell IP Cameras, PoC Exploit Code Publicly Disclosed
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Wed, 12 Aug 2026 12:44:57 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Authentication Bypass #Command Injection #CVE_2026_61514 #CVE_2026_61515 #IOT #IP Camera #Puwell
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Wed, 12 Aug 2026 12:44:57 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Authentication Bypass #Command Injection #CVE_2026_61514 #CVE_2026_61515 #IOT #IP Camera #Puwell
Daily CyberSecurity
CVE-2026-61515: Unauthenticated Command Injection in Puwell IP Cameras, PoC Exploit Code Publicly Disclosed
TL;DR Two critical Puwell IP Camera vulnerabilities now have public details and proof-of-concept exploit code. Both score 9.3 on the CVSS scale. Together they let a remote attacker bypass login an…
⤷ Title: CVE-2026-67261: Dell VSI RCE Flaw Scores CVSS 9.8
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Wed, 12 Aug 2026 14:15:56 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Command Injection #CVE_2026_54489 #CVE_2026_67261 #Dell VSI #Remote Code Execution #VMware vSphere
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Wed, 12 Aug 2026 14:15:56 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Command Injection #CVE_2026_54489 #CVE_2026_67261 #Dell VSI #Remote Code Execution #VMware vSphere
Daily CyberSecurity
CVE-2026-67261: Dell VSI RCE Flaw Scores CVSS 9.8
TL;DR Dell patched two critical flaws in Virtual Storage Integrator (VSI) for VMware vSphere Client. The worst, CVE-2026-67261, allows unauthenticated remote code execution as root, scoring CVSS 9…
⤷ Title: GitLab Patch Release Fixes 13 Flaws, Including High-Severity XSS Bugs
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Wed, 12 Aug 2026 23:57:16 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CVE_2026_15217 #CVE_2026_15423 #DevSecOps #gitlab #GitLab patch release #XSS
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Wed, 12 Aug 2026 23:57:16 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CVE_2026_15217 #CVE_2026_15423 #DevSecOps #gitlab #GitLab patch release #XSS
Daily CyberSecurity
GitLab Patch Release Fixes 13 Flaws, Including High-Severity XSS Bugs
TL;DR GitLab shipped a new patch release on August 12, 2026. Versions 19.2.2, 19.1.4, and 19.0.6 fix 13 security flaws across Community and Enterprise Edition. The most severe are high-rated cross…
⤷ Title: Hunting Exchange Server 0day like a detective
════════════════════════
𐀪 Author: Jang
════════════════════════
ⴵ Time: Thu, 13 Aug 2026 04:45:43 GMT
════════════════════════
⌗ Tags: #exchange #cve_2026_62911 #servers #rce
════════════════════════
𐀪 Author: Jang
════════════════════════
ⴵ Time: Thu, 13 Aug 2026 04:45:43 GMT
════════════════════════
⌗ Tags: #exchange #cve_2026_62911 #servers #rce
Medium
Hunting Exchange Server 0day like a detective
It has been a while since my last blog post, not because I didn’t do anything (or I?), I just don’t have any time/ any motivation to start…
⤷ Title: CVE-2026-65640: WordPress 7.0.4 Fixes Remote Code Execution
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Thu, 13 Aug 2026 07:34:53 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CVE_2026_65640 #Ghostscript #Imagick #Remote Code Execution #Web Security #wordpress
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Thu, 13 Aug 2026 07:34:53 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CVE_2026_65640 #Ghostscript #Imagick #Remote Code Execution #Web Security #wordpress
Daily CyberSecurity
CVE-2026-65640: WordPress 7.0.4 Fixes Remote Code Execution
TL;DR WordPress released version 7.0.4 on August 12, 2026, as a security-only update. It fixes CVE-2026-65640, an authenticated remote code execution flaw rated CVSS 8.8. The bug affects sites tha…
⤷ Title: CVE-2026-43723: Apple mediaremoted Flaw Lets Apps Gain Root Privileges, PoC Exploit Code Publicly Disclosed
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Thu, 13 Aug 2026 13:15:50 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Apple #CVE_2026_43723 #ios #macOS #mediaremoted #privilege escalation #root
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Thu, 13 Aug 2026 13:15:50 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Apple #CVE_2026_43723 #ios #macOS #mediaremoted #privilege escalation #root
Daily CyberSecurity
CVE-2026-43723: Apple mediaremoted Flaw Lets Apps Gain Root Privileges, PoC Exploit Code Publicly Disclosed
TL;DR Apple patched a flaw that let a local app gain root privileges through the mediaremoted service. Tracked as CVE-2026-43723, it carries a CVSS score of 7.8. Both the technical details and pro…
⤷ Title: Critical Vulnerability Alert: Unauthenticated SQL Injection in Metabase (CVE-2026–72898)
════════════════════════
𐀪 Author: Synthex
════════════════════════
ⴵ Time: Thu, 13 Aug 2026 17:02:43 GMT
════════════════════════
⌗ Tags: #vulnerability_analysis #cybersecurity #sql_injection #cve_2026_72898 #application_security
════════════════════════
𐀪 Author: Synthex
════════════════════════
ⴵ Time: Thu, 13 Aug 2026 17:02:43 GMT
════════════════════════
⌗ Tags: #vulnerability_analysis #cybersecurity #sql_injection #cve_2026_72898 #application_security
Medium
🚨 Critical Vulnerability Alert: Unauthenticated SQL Injection in Metabase (CVE-2026–72898)
In early August 2026, a maximum-severity security flaw tracked as CVE-2026–72898 (GitHub Advisory: GHSA-vwf4-m7j8-wcjf) was publicly…