⤷ Title: Comment2Shell: WordPress’te Yorumlardan Sistemi Ele Geçirmeye Giden Yol (CVE-2026–93485)
════════════════════════
𐀪 Author: Dogukan İSPİRLİ
════════════════════════
ⴵ Time: Sat, 26 Sep 2026 20:29:07 GMT
════════════════════════
⌗ Tags: #wordpress #rce_vulnerability #remote_code_execution #wordpress_exploitation #xss_vulnerability
════════════════════════
𐀪 Author: Dogukan İSPİRLİ
════════════════════════
ⴵ Time: Sat, 26 Sep 2026 20:29:07 GMT
════════════════════════
⌗ Tags: #wordpress #rce_vulnerability #remote_code_execution #wordpress_exploitation #xss_vulnerability
Medium
Comment2Shell: WordPress’te Yorumlardan Sistemi Ele Geçirmeye Giden Yol (CVE-2026–93485)
WordPress son günlerin en çok konuşulan güvenlik açıklarından biri, sıradan bir blog yorumunu sunucu üzerinde komut çalıştırmaya…
⤷ Title: Citrix NetScaler Zero-Day RCE Flaws Exploited, Patches Released
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Sun, 27 Sep 2026 16:17:31 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Active Exploitation #Citrix NetScaler #CVE_2026_88771 #CVE_2026_88772 #NetScaler Gateway #NetScaler zero_day #Remote Code Execution #VPN security #watchTowr
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Sun, 27 Sep 2026 16:17:31 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Active Exploitation #Citrix NetScaler #CVE_2026_88771 #CVE_2026_88772 #NetScaler Gateway #NetScaler zero_day #Remote Code Execution #VPN security #watchTowr
Daily CyberSecurity
Citrix NetScaler Zero-Day RCE Flaws Exploited, Patches Released
TL;DR Two Citrix NetScaler zero-day flaws allowing remote code execution have been exploited in the wild. The alert began with a leaked NCSC-NL pre-notification and was echoed by watchTowr and Kev…
⤷ Title: PostgreSQL RCE Vulnerability Details and PoC Disclosed
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Tue, 29 Sep 2026 00:19:57 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CVE_2026_15742 #cybersecurity #database security #fuzzystrmatch #PostgreSQL #Remote Code Execution
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Tue, 29 Sep 2026 00:19:57 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CVE_2026_15742 #cybersecurity #database security #fuzzystrmatch #PostgreSQL #Remote Code Execution
Daily CyberSecurity
PostgreSQL RCE Vulnerability Details and PoC Disclosed
TL;DR PostgreSQL developers patched a critical integer wraparound flaw in the fuzzystrmatch module. This PostgreSQL RCE vulnerability permits low-privileged database users to execute arbitrary com…
⤷ Title: Citrix NetScaler Zero-Day Flaws Exploited: Patch Now
════════════════════════
𐀪 Author: Nam Phong
════════════════════════
ⴵ Time: Tue, 29 Sep 2026 03:49:01 +0000
════════════════════════
⌗ Tags: #Vulnerability #CISA KEV #Citrix #CVE_2026_88771 #CVE_2026_88772 #NetScaler #remote code execution #VPN Security #zero_day
════════════════════════
𐀪 Author: Nam Phong
════════════════════════
ⴵ Time: Tue, 29 Sep 2026 03:49:01 +0000
════════════════════════
⌗ Tags: #Vulnerability #CISA KEV #Citrix #CVE_2026_88771 #CVE_2026_88772 #NetScaler #remote code execution #VPN Security #zero_day
Information Security News
Citrix NetScaler Zero-Day Flaws Exploited: Patch Now
Attackers Need No Password The latest attacks on Citrix NetScaler require no password at all. Citrix has disclosed two critical zero-day flaws in NetScaler ADC and NetScaler Gateway. Attackers can…
⤷ Title: Apache Karaf Vulnerabilities Let Low-Privilege Users Reach Admin and Code Execution
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Tue, 29 Sep 2026 04:28:16 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Apache Karaf #Apache Karaf vulnerabilities #CVE_2026_91012 #CVE_2026_91048 #CVE_2026_92142 #JMX #privilege escalation #Remote Code Execution
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Tue, 29 Sep 2026 04:28:16 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Apache Karaf #Apache Karaf vulnerabilities #CVE_2026_91012 #CVE_2026_91048 #CVE_2026_92142 #JMX #privilege escalation #Remote Code Execution
Daily CyberSecurity
Apache Karaf Vulnerabilities Let Low-Privilege Users Reach Admin and Code Execution
TL;DR The Apache Karaf project has fixed four Apache Karaf vulnerabilities in version 4.4.12. Two are rated important and two moderate. Each lets a user with a low-privilege role, such as “v…
⤷ Title: Octopus Server Flaw CVE-2026-101169 Allows Code Execution via Insecure Deserialization
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Tue, 29 Sep 2026 09:44:08 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CVE_2026_101169 #DevSecOps #Insecure Deserialization #Octopus Deploy #Octopus Server #Octopus Server vulnerability #Remote Code Execution
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Tue, 29 Sep 2026 09:44:08 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CVE_2026_101169 #DevSecOps #Insecure Deserialization #Octopus Deploy #Octopus Server #Octopus Server vulnerability #Remote Code Execution
Daily CyberSecurity
Octopus Server Flaw CVE-2026-101169 Allows Code Execution via Insecure Deserialization
TL;DR Octopus Deploy has fixed a high-severity Octopus Server vulnerability, CVE-2026-101169. An authenticated user who can edit an Environment or Project can run arbitrary code in the server proc…
⤷ Title: Critical MikroTik RouterOS Flaw CVE-2026-84411 Allows Unauthenticated Root RCE
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Tue, 29 Sep 2026 20:10:23 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CISA #CVE_2026_84411 #Integer Underflow #MikroTik #MikroTik RouterOS vulnerability #Remote Code Execution #RouterOS
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Tue, 29 Sep 2026 20:10:23 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CISA #CVE_2026_84411 #Integer Underflow #MikroTik #MikroTik RouterOS vulnerability #Remote Code Execution #RouterOS
Daily CyberSecurity
Critical MikroTik RouterOS Flaw CVE-2026-84411 Allows Unauthenticated Root RCE
TL;DR CISA published advisory ICSA-26-272-06 on September 29, 2026, for a critical MikroTik RouterOS vulnerability, CVE-2026-84411. A single crafted HTTP request can give an unauthenticated attack…
⤷ Title: JupyterLab Desktop Flaw CVE-2026-102530 Turns a Malicious Server URL Into Code Execution
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Wed, 30 Sep 2026 01:46:44 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Cross_Site Scripting #CVE_2026_102530 #Electron #JupyterLab #JupyterLab Desktop #JupyterLab Desktop vulnerability #Remote Code Execution
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Wed, 30 Sep 2026 01:46:44 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Cross_Site Scripting #CVE_2026_102530 #Electron #JupyterLab #JupyterLab Desktop #JupyterLab Desktop vulnerability #Remote Code Execution
Daily CyberSecurity
JupyterLab Desktop Flaw CVE-2026-102530 Turns a Malicious Server URL Into Code Execution
TL;DR A JupyterLab Desktop vulnerability, CVE-2026-102530, rated CVSS 9.4, lets a malicious server URL run code on a user’s computer. The app displayed remote server URLs without sanitizing …
⤷ Title: HPE Patches 18 Instant ON Access Point Vulnerabilities, Five Rated Critical
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Wed, 30 Sep 2026 03:36:26 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #access point security #CVE_2026_76721 #CVE_2026_76722 #HPE #HPE Instant ON vulnerabilities #HPE Networking #Instant On #Remote Code Execution
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Wed, 30 Sep 2026 03:36:26 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #access point security #CVE_2026_76721 #CVE_2026_76722 #HPE #HPE Instant ON vulnerabilities #HPE Networking #Instant On #Remote Code Execution
Daily CyberSecurity
HPE Patches 18 Instant ON Access Point Vulnerabilities, Five Rated Critical
TL;DR HPE Networking disclosed 18 HPE Instant ON vulnerabilities on September 29, 2026, in its Instant ON access points. Five are rated Critical, and the two worst score CVSS 9.8 with unauthentica…
⤷ Title: WatchGuard Patches 14 Fireware OS Vulnerabilities, Including CVSS 9.2 RCE
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Wed, 30 Sep 2026 02:38:48 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CVE_2026_86131 #Firebox #Fireware OS #Fireware OS vulnerabilities #Remote Code Execution #VPN security #WatchGuard
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Wed, 30 Sep 2026 02:38:48 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CVE_2026_86131 #Firebox #Fireware OS #Fireware OS vulnerabilities #Remote Code Execution #VPN security #WatchGuard
Daily CyberSecurity
WatchGuard Patches 14 Fireware OS Vulnerabilities, Including CVSS 9.2 RCE
TL;DR WatchGuard disclosed 14 Fireware OS vulnerabilities on September 29, 2026, affecting its Firebox firewalls. The worst, CVE-2026-86131, scores CVSS 9.2 and allows remote code execution in cer…