# cve

Published articles for cve.

This is one page of public article previews, not the complete archive. Follow Next page to continue. Summaries are not the original full articles.

## Libreboot 20241206, 11th revision released! (fixes to GRUB regressions)

DevFeed: [Libreboot 20241206, 11th revision released! (fixes to GRUB regressions)](<https://devfeed.tech/articles/libreboot-20241206-11th-revision-released-fixes-to-grub-regressions-32721.md>)

Original publisher: [Read original article](<https://libreboot.org/news/libreboot20241206rev11.html>)

Author: Leah Rowe

Published: 2026-09-17T04:32:50.666044Z

Content type: release

Language: en

Sources: [News about Libreboot releases and development](<https://devfeed.tech/sources/news-about-libreboot-releases-and-development.md>)

Topics: [libreboot](<https://devfeed.tech/topics/libreboot.md>), [releases](<https://devfeed.tech/topics/releases.md>), [coreboot](<https://devfeed.tech/topics/coreboot.md>), [systems](<https://devfeed.tech/topics/systems.md>)

Tags: [bios](<https://devfeed.tech/tags/bios.md>), [canoeboot](<https://devfeed.tech/tags/canoeboot.md>), [coreboot](<https://devfeed.tech/tags/coreboot.md>), [cve](<https://devfeed.tech/tags/cve.md>), [free-software](<https://devfeed.tech/tags/free-software.md>), [grub](<https://devfeed.tech/tags/grub.md>), [libre](<https://devfeed.tech/tags/libre.md>), [libreboot](<https://devfeed.tech/tags/libreboot.md>), [open-source](<https://devfeed.tech/tags/open-source.md>), [opensource](<https://devfeed.tech/tags/opensource.md>), [regression](<https://devfeed.tech/tags/regression.md>), [release](<https://devfeed.tech/tags/release.md>), [uefi](<https://devfeed.tech/tags/uefi.md>)

### AI overview

Libreboot 20241206 revision 11 is announced as a stable-release revision containing fixes for regressions introduced in revision 10, including GRUB and filesystem-driver issues that could prevent very large files from loading or systems from booting.

### Source excerpt

Article: Libreboot 20241206, 11th revision released! (fixes to GRUB regressions) Web link: https://libreboot.org/news/libreboot20241206rev11.html

## Keycloak 26.7.4 released

DevFeed: [Keycloak 26.7.4 released](<https://devfeed.tech/articles/keycloak-26-7-4-released-31792.md>)

Original publisher: [Read original article](<https://www.keycloak.org/2026/09/keycloak-2674-released>)

Author: Keycloak Team

Published: 2026-09-16T00:00:00Z

Content type: release

Language: en

Sources: [Keycloak Blog](<https://devfeed.tech/sources/keycloak-blog.md>)

Topics: [Keycloak](<https://devfeed.tech/topics/keycloak.md>), [Security](<https://devfeed.tech/topics/security.md>), [Quarkus](<https://devfeed.tech/topics/quarkus.md>), [MariaDB](<https://devfeed.tech/topics/mariadb.md>), [MySQL](<https://devfeed.tech/topics/mysql.md>), [saml](<https://devfeed.tech/topics/saml.md>)

Tags: [cve](<https://devfeed.tech/tags/cve.md>), [idm](<https://devfeed.tech/tags/idm.md>), [kerberos](<https://devfeed.tech/tags/kerberos.md>), [keycloak](<https://devfeed.tech/tags/keycloak.md>), [keycloak-release](<https://devfeed.tech/tags/keycloak-release.md>), [ldap](<https://devfeed.tech/tags/ldap.md>), [mariadb](<https://devfeed.tech/tags/mariadb.md>), [mysql](<https://devfeed.tech/tags/mysql.md>), [openid-connect](<https://devfeed.tech/tags/openid-connect.md>), [quarkus](<https://devfeed.tech/tags/quarkus.md>), [release](<https://devfeed.tech/tags/release.md>), [saml](<https://devfeed.tech/tags/saml.md>), [security](<https://devfeed.tech/tags/security.md>), [sso](<https://devfeed.tech/tags/sso.md>)

### AI overview

Keycloak 26.7.4 was released on September 16, 2026. The release includes security fixes for several CVEs, an upgrade to Quarkus 3.33.3.2, and fixes for performance, testing, documentation, administration, and UI issues.

### Source excerpt

To download the release go to Keycloak downloads. Upgrading Before upgrading refer to the migration guide for a complete list of changes. All resolved issues Security fixes #52834 [CVE-2026-90997] Default MySQL/MariaDB row counts make stateless replay gates accept reused artifacts #52835 [CVE-2026-79651] Keycloak Unauthenticated Denial of Service via Unbounded Locale Caching #52836 [CVE-2026-74909] Incomplete fix: percent-encoded semicolon bypasses matrix parameter stripping in PathMatcher #52837 [CVE-2026-19607] Username Takeover Leading to Account Lockout #52838 [CVE-2026-17526] Privilege escalation: the "impersonation" role can impersonate a realm administrator #52839 [CVE-2026-18212] SAML Redirect DEFLATE helpers leak native zlib state Enhancements #52354 Upgrade to Quarkus 3.33.3.2 dist/quarkus Bugs #49635 Performance issue with 26.6.2 dist/quarkus #51102 Flaky test: org.keycloak.testsuite.oauth.AccessTokenTest#accessTokenRequest ci #52015 New links errors for https://quarkus.io/guides docs #52172 Cached `RealmAdapter.isUserManagedAccessAllowed()` returns `isEnabled()` infinispan #52173 `realm_client` is computed into a client's attributes and then persisted on save admin/api #52233 Oracle 19 full client OCI driver crashes on startup since 26.6.0 -- SQLFeatureNotSupportedException on setNetworkTimeout dist/quarkus #52241 Clicking on a sub group in the admin console throws an exception admin/ui #52283 Flaky test SessionRestServiceTest.testGetDevicesSessions testsuite #52430 Flaky test: userprofile.spec.ts fails with timeout on "no-users-found-empty-action" in serial suite testsuite

## Emacs arbitrary code execution flaw

DevFeed: [Emacs arbitrary code execution flaw](<https://devfeed.tech/articles/emacs-arbitrary-code-execution-flaw-21541.md>)

Original publisher: [Read original article](<https://lwn.net/Articles/1094224/>)

Author: jzb

Published: 2026-09-14T15:20:00Z

Content type: news

Language: en

Sources: [LWN.net](<https://devfeed.tech/sources/lwn-net.md>)

Topics: [Lisp](<https://devfeed.tech/topics/lisp.md>), [vulnerability](<https://devfeed.tech/topics/vulnerability.md>), [Maintainers](<https://devfeed.tech/topics/maintainers.md>)

Tags: [cve](<https://devfeed.tech/tags/cve.md>), [emacs](<https://devfeed.tech/tags/emacs.md>), [maintainers](<https://devfeed.tech/tags/maintainers.md>), [release](<https://devfeed.tech/tags/release.md>), [vulnerability](<https://devfeed.tech/tags/vulnerability.md>)

### AI overview

An incomplete fix for the Emacs arbitrary code execution flaw CVE-2024-53920 has been identified. Viewing or editing untrusted files in modes other than Emacs's Lisp mode can also trigger arbitrary code execution. The issue affects Emacs 24 and newer, with a minimal fix queued for Emacs 31.2; upstream maintainers do not expect to backport it to older releases.

### Source excerpt

Sean Whitton has announced that the original fix for an arbitrary code execution flaw in Emacs (CVE-2024-53920) was incomplete. Bas Alberts discovered that viewing or editing untrusted files in modes other than Emacs's Lisp mode can also result in arbitrary code execution. This problem affects all Emacs versions affected by CVE-2024-53920. This means Emacs 24 and newer, and possibly also older versions. A minimal fix, attached, is queued up for release with Emacs 31.2. We (the Emacs upstream maintainers) don't expect to backport the fix to older Emacs releases ourselves. LWN covered the original vulnerability in December 2024.

## Security Week 2638: опасные уязвимости в роутерах MikroTik

DevFeed: [Security Week 2638: опасные уязвимости в роутерах MikroTik](<https://devfeed.tech/articles/security-week-2638-mikrotik-23095.md>)

Original publisher: [Read original article](<https://habr.com/ru/companies/kaspersky/articles/1082108/>)

Author: Kaspersky\_Lab ("Лаборатория Касперского")

Published: 2026-09-14T15:06:43Z

Content type: news

Language: ru

Sources: ["Лаборатория Касперского" RU](<https://devfeed.tech/sources/ru-2.md>)

Topics: [MikroTik](<https://devfeed.tech/topics/mikrotik.md>), [Security](<https://devfeed.tech/topics/security.md>), [CVE-2026-86060](<https://devfeed.tech/topics/cve-2026-86060.md>), [ssh](<https://devfeed.tech/topics/ssh.md>)

Tags: [2026](<https://devfeed.tech/tags/2026.md>), [chromium](<https://devfeed.tech/tags/chromium.md>), [cve](<https://devfeed.tech/tags/cve.md>), [cve-2026-86060](<https://devfeed.tech/tags/cve-2026-86060.md>), [gpt](<https://devfeed.tech/tags/gpt.md>), [microsoft](<https://devfeed.tech/tags/microsoft.md>), [mikrotik](<https://devfeed.tech/tags/mikrotik.md>), [openai](<https://devfeed.tech/tags/openai.md>), [security](<https://devfeed.tech/tags/security.md>), [ssh](<https://devfeed.tech/tags/ssh.md>), [tag-9fe8963de219](<https://devfeed.tech/tags/tag-9fe8963de219.md>)

### AI overview

The article reports three vulnerabilities in MikroTik routers, including SSH authentication bypass, privilege escalation, and a denial-of-service issue. Two vulnerabilities were actively exploited, and MikroTik released patches for affected RouterOS versions. The report also describes AI-assisted vulnerability discovery involving OpenAI GPT models and briefly mentions vulnerabilities in WeChat and a large Microsoft patch release involving Chromium.

### Source excerpt

На прошлой неделе команда CERT из Польши обнародовала информацию о трех уязвимостях в роутерах MikroTik, две из которых активно используются в реальных атаках как минимум со второго сентября. Взлом роутеров возможен в том случае, если на устройстве разрешен доступ по протоколу SSH из Интернета. По данным на пятое сентября в сети наблюдалось более 122 тысяч потенциально уязвимых устройств. Две наиболее опасные уязвимости имеют одинаковый рейтинг 9,2 балла по шкале CVSS. Проблема CVE-2026-67276 позволяет обойти аутентификацию по SSH в том случае, если атакующему известно имя пользователя и модуль публичного ключа. Ошибка CVE-2026-86060, в свою очередь, открывает возможность эскалации привилегий при использовании имени пользователя, содержащего некорректные символы. Читать далее

## RBP Tracker: Counting the CVE IDs the CVE List Cannot See

DevFeed: [RBP Tracker: Counting the CVE IDs the CVE List Cannot See](<https://devfeed.tech/articles/rbp-tracker-counting-the-cve-ids-the-cve-list-cannot-see-27481.md>)

Original publisher: [Read original article](<https://jerrygamblin.com/2026/09/14/rbp-tracker-counting-the-cve-ids-the-cve-list-cannot-see/>)

Author: jgamblin

Published: 2026-09-14T14:16:42Z

Content type: article

Language: en

Sources: [Jerry Gamblin](<https://devfeed.tech/sources/jerry-gamblin.md>)

Topics: [data](<https://devfeed.tech/topics/data.md>), [NVD](<https://devfeed.tech/topics/nvd.md>), [API](<https://devfeed.tech/topics/api.md>), [GitHub](<https://devfeed.tech/topics/github.md>)

Tags: [api](<https://devfeed.tech/tags/api.md>), [cve](<https://devfeed.tech/tags/cve.md>), [cve-list](<https://devfeed.tech/tags/cve-list.md>), [data](<https://devfeed.tech/tags/data.md>), [ids](<https://devfeed.tech/tags/ids.md>), [list](<https://devfeed.tech/tags/list.md>), [nvd](<https://devfeed.tech/tags/nvd.md>), [report](<https://devfeed.tech/tags/report.md>), [scanner](<https://devfeed.tech/tags/scanner.md>), [source](<https://devfeed.tech/tags/source.md>), [state](<https://devfeed.tech/tags/state.md>), [uncategorized](<https://devfeed.tech/tags/uncategorized.md>)

### AI overview

The article examines a corrected RogoLabs tracker for Reserved but Public CVE IDs. It explains that the CVE Services API returns 404 for reserved IDs, while a separate unauthenticated endpoint reveals their RESERVED state. The tracker lists IDs from public advisory feeds and describes how reserved records are absent from the bulk CVE List until publication.

### Source excerpt

A new RogoLabs site lists Reserved but Public CVE IDs: 2,315 of them on September 14, drawn from 17 public advisory feeds, refreshed every six hours, and held a week before they appear. The first version of this tracker reported that none of the CVE IDs it found existed in the CVE List, in any ... Read more

## Uptime Kuma 2.5.4 Patches Critical JSONata Code Execution Flaw

DevFeed: [Uptime Kuma 2.5.4 Patches Critical JSONata Code Execution Flaw](<https://devfeed.tech/articles/uptime-kuma-2-5-4-patches-critical-jsonata-code-execution-flaw-17352.md>)

Original publisher: [Read original article](<https://selfhostlab.io/uptime-kuma-2-5-4-security-release/>)

Author: Christian Rakoot

Published: 2026-09-14T06:55:25Z

Content type: article

Language: en

Sources: [Self Host Lab](<https://devfeed.tech/sources/self-host-lab.md>)

Topics: [Security](<https://devfeed.tech/topics/security.md>), [vulnerability](<https://devfeed.tech/topics/vulnerability.md>), [Monitoring](<https://devfeed.tech/topics/monitoring.md>), [configuration](<https://devfeed.tech/topics/configuration.md>)

Tags: [2026](<https://devfeed.tech/tags/2026.md>), [cve](<https://devfeed.tech/tags/cve.md>), [dependency](<https://devfeed.tech/tags/dependency.md>), [monitoring](<https://devfeed.tech/tags/monitoring.md>), [monitoring-news](<https://devfeed.tech/tags/monitoring-news.md>), [news](<https://devfeed.tech/tags/news.md>), [security](<https://devfeed.tech/tags/security.md>), [update](<https://devfeed.tech/tags/update.md>), [uptime-kuma-2-5-4](<https://devfeed.tech/tags/uptime-kuma-2-5-4.md>), [vulnerability](<https://devfeed.tech/tags/vulnerability.md>)

### AI overview

Uptime Kuma 2.5.4 fixes a critical JSONata vulnerability that could enable arbitrary code execution on the monitor host, along with a second denial-of-service issue. The release updates jsonata to 2.2.2 and also adds an SFTP monitor type and three notification providers.

### Source excerpt

Uptime Kuma 2.5.4 patches a critical-rated code execution flaw in the JSONata library (CVE-2026-77415, CVSS 9.3) plus a second denial-of-service fix, and adds an SFTP monitor type and three new notification providers. Here's what the flaw actually requires to exploit, and how to update.

## \[remote\] CVE-2026-80428 Unauthenticated PHP Object Injection via Shibboleth - ILIAS \< 9.22, 10.0 \< 10.10, 11.0 \< 11.3 - RCE

DevFeed: [\[remote\] CVE-2026-80428 Unauthenticated PHP Object Injection via Shibboleth - ILIAS \< 9.22, 10.0 \< 10.10, 11.0 \< 11.3 - RCE](<https://devfeed.tech/articles/remote-cve-2026-80428-unauthenticated-php-object-injection-via-shibboleth-ilias-9-22-10-0-10-10-11-0-11-3-rce-34775.md>)

Original publisher: [Read original article](<https://www.exploit-db.com/exploits/52682>)

Author: DigiProSec

Published: 2026-09-11T00:00:00Z

Content type: news

Language: en

Sources: [Exploit-DB.com RSS Feed](<https://devfeed.tech/sources/exploit-db-com-rss-feed.md>)

Topics: [Exploit](<https://devfeed.tech/topics/exploit.md>), [PHP](<https://devfeed.tech/topics/php.md>)

Tags: [cve](<https://devfeed.tech/tags/cve.md>), [cve-2026-80428](<https://devfeed.tech/tags/cve-2026-80428.md>), [exploit](<https://devfeed.tech/tags/exploit.md>), [multiple](<https://devfeed.tech/tags/multiple.md>), [object](<https://devfeed.tech/tags/object.md>), [php](<https://devfeed.tech/tags/php.md>), [rce](<https://devfeed.tech/tags/rce.md>), [remote](<https://devfeed.tech/tags/remote.md>)

### AI overview

CVE-2026-80428 is an unauthenticated PHP object injection vulnerability via Shibboleth in ILIAS versions earlier than 9.22, 10.10, and 11.3, with remote code execution indicated.

### Source excerpt

CVE-2026-80428 Unauthenticated PHP Object Injection via Shibboleth - ILIAS < 9.22, 10.0 < 10.10, 11.0 < 11.3 - RCE

## September 2026 Security Updates #1 for XCP-ng 8.3 LTS

DevFeed: [September 2026 Security Updates #1 for XCP-ng 8.3 LTS](<https://devfeed.tech/articles/september-2026-security-updates-1-for-xcp-ng-8-3-lts-12827.md>)

Original publisher: [Read original article](<https://xcp-ng.org/blog/2026/09/08/september-2026-security-updates-1-for-xcp-ng-8-3-lts/>)

Author: David Morel

Published: 2026-09-08T14:07:29Z

Content type: article

Language: en

Sources: [XCP-ng Blog](<https://devfeed.tech/sources/xcp-ng-blog.md>)

Topics: [Security](<https://devfeed.tech/topics/security.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [DDoS](<https://devfeed.tech/topics/ddos.md>), [Memory Leaks](<https://devfeed.tech/topics/memory-leaks.md>)

Tags: [2026](<https://devfeed.tech/tags/2026.md>), [cve](<https://devfeed.tech/tags/cve.md>), [lts](<https://devfeed.tech/tags/lts.md>), [maintenance-updates](<https://devfeed.tech/tags/maintenance-updates.md>), [memory-leak](<https://devfeed.tech/tags/memory-leak.md>), [release](<https://devfeed.tech/tags/release.md>), [security](<https://devfeed.tech/tags/security.md>), [september-2026](<https://devfeed.tech/tags/september-2026.md>), [updates](<https://devfeed.tech/tags/updates.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>)

### AI overview

This article announces September 2026 security updates for XCP-ng 8.3 LTS. The fixes address vulnerabilities in Xen, oxenstored, and Tapdisk, including memory leaks, denial-of-service conditions, and out-of-bounds accesses that could allow code execution with administrator privileges in dom0. One Xen issue does not affect supported XCP-ng 8.3 LTS installations and is deferred for defense in depth.

### Source excerpt

New security and maintenance updates are available for XCP-ng 8.3 LTS. This includes update to Xen, oxenstored and blktap.

## How financial services companies can modernize their software supply chain

DevFeed: [How financial services companies can modernize their software supply chain](<https://devfeed.tech/articles/how-financial-services-companies-can-modernize-their-software-supply-chain-13089.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/how-financial-services-companies-can-modernize-their-software-supply-chain>)

Published: 2026-09-04T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [supply-chain-security](<https://devfeed.tech/topics/supply-chain-security.md>), [open-source-security](<https://devfeed.tech/topics/open-source-security.md>), [Security](<https://devfeed.tech/topics/security.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [Business Security](<https://devfeed.tech/topics/business-security.md>)

Tags: [cve](<https://devfeed.tech/tags/cve.md>), [dependency](<https://devfeed.tech/tags/dependency.md>), [financial-services](<https://devfeed.tech/tags/financial-services.md>), [legacy](<https://devfeed.tech/tags/legacy.md>), [security](<https://devfeed.tech/tags/security.md>), [software-supply-chain-security](<https://devfeed.tech/tags/software-supply-chain-security.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>)

### AI overview

This article argues that financial services organizations should modernize software supply chain security while preserving business-critical systems. It explains that legacy infrastructure, regulatory obligations, and downtime concerns have encouraged deferred vulnerability remediation, but AI-assisted exploitation is making that risk increasingly dangerous.

### Source excerpt

Modernize your financial software supply chain without disrupting critical systems. See how trusted open source reduces risk without major migrations.

## \[webapps\] Metabase 0.61.0 - Authenticated Remote Code Execution

DevFeed: [\[webapps\] Metabase 0.61.0 - Authenticated Remote Code Execution](<https://devfeed.tech/articles/webapps-metabase-0-61-0-authenticated-remote-code-execution-34773.md>)

Original publisher: [Read original article](<https://www.exploit-db.com/exploits/52680>)

Author: Gutierre0x80

Published: 2026-09-03T00:00:00Z

Content type: article

Language: en

Sources: [Exploit-DB.com RSS Feed](<https://devfeed.tech/sources/exploit-db-com-rss-feed.md>)

Topics: [Exploit](<https://devfeed.tech/topics/exploit.md>), [webapps](<https://devfeed.tech/topics/webapps.md>)

Tags: [2026](<https://devfeed.tech/tags/2026.md>), [cve](<https://devfeed.tech/tags/cve.md>), [cve-2026-59827](<https://devfeed.tech/tags/cve-2026-59827.md>), [execution](<https://devfeed.tech/tags/execution.md>), [exploit](<https://devfeed.tech/tags/exploit.md>), [multiple](<https://devfeed.tech/tags/multiple.md>), [remote](<https://devfeed.tech/tags/remote.md>), [remote-code-execution](<https://devfeed.tech/tags/remote-code-execution.md>), [webapps](<https://devfeed.tech/tags/webapps.md>)

### AI overview

An Exploit-DB entry identifies authenticated remote code execution affecting Metabase 0.61.0 and associates it with CVE-2026-59827.

### Source excerpt

Metabase 0.61.0 - Authenticated Remote Code Execution

## \[webapps\] FreePBX 17.0.2 - Remote Code Execution (RCE)

DevFeed: [\[webapps\] FreePBX 17.0.2 - Remote Code Execution (RCE)](<https://devfeed.tech/articles/webapps-freepbx-17-0-2-remote-code-execution-rce-34774.md>)

Original publisher: [Read original article](<https://www.exploit-db.com/exploits/52681>)

Author: Jared Brits

Published: 2026-09-03T00:00:00Z

Content type: article

Language: en

Sources: [Exploit-DB.com RSS Feed](<https://devfeed.tech/sources/exploit-db-com-rss-feed.md>)

Topics: [Exploit](<https://devfeed.tech/topics/exploit.md>), [webapps](<https://devfeed.tech/topics/webapps.md>), [Code](<https://devfeed.tech/topics/code.md>)

Tags: [cve](<https://devfeed.tech/tags/cve.md>), [cve-2025-57819](<https://devfeed.tech/tags/cve-2025-57819.md>), [exploit](<https://devfeed.tech/tags/exploit.md>), [multiple](<https://devfeed.tech/tags/multiple.md>), [platform](<https://devfeed.tech/tags/platform.md>), [remote-code-execution](<https://devfeed.tech/tags/remote-code-execution.md>), [webapps](<https://devfeed.tech/tags/webapps.md>)

### AI overview

An exploit entry describing remote code execution affecting FreePBX 17.0.2, associated with CVE-2025-57819.

### Source excerpt

FreePBX 17.0.2 - Remote Code Execution (RCE)

## curl 8.22.0

DevFeed: [curl 8.22.0](<https://devfeed.tech/articles/curl-8-22-0-18904.md>)

Original publisher: [Read original article](<https://daniel.haxx.se/blog/2026/09/02/curl-8-22-0/>)

Author: Daniel Stenberg

Published: 2026-09-02T05:52:46Z

Content type: release

Language: en

Sources: [Daniel Stenberg](<https://devfeed.tech/sources/daniel-stenberg.md>)

Topics: [cURL](<https://devfeed.tech/topics/curl.md>), [Security](<https://devfeed.tech/topics/security.md>), [HTTP](<https://devfeed.tech/topics/http.md>), [openssl](<https://devfeed.tech/topics/openssl.md>), [API](<https://devfeed.tech/topics/api.md>), [TLS (Transport Layer Security)](<https://devfeed.tech/topics/tls.md>), [Command-line interface](<https://devfeed.tech/topics/cli.md>)

Tags: [bugfixes](<https://devfeed.tech/tags/bugfixes.md>), [command-line](<https://devfeed.tech/tags/command-line.md>), [curl](<https://devfeed.tech/tags/curl.md>), [curl-and-libcurl](<https://devfeed.tech/tags/curl-and-libcurl.md>), [cve](<https://devfeed.tech/tags/cve.md>), [cves](<https://devfeed.tech/tags/cves.md>), [http](<https://devfeed.tech/tags/http.md>), [openssl](<https://devfeed.tech/tags/openssl.md>), [release](<https://devfeed.tech/tags/release.md>), [security](<https://devfeed.tech/tags/security.md>), [tls](<https://devfeed.tech/tags/tls.md>)

### AI overview

The curl 8.22.0 release includes six changes, 302 bug fixes, and nine curl/libcurl security fixes plus one wcurl fix. It adds Apple GSS Framework support, API guards, experimental HTTP Message Signatures support, and Apple fast UDP, while blocking NTLM fallback in SPNEGO and dropping TLS-SRP support.

### Source excerpt

Welcome to this new release. Get it as always from https://curl.se. If you rather want a security-patched older release branch, stay tuned for the follow-up Rock-solid curl announcement within a few days. Release presentation Numbers the 276th release6 changes70 days (total: 10,887)302 bugfixes (total: 14,489)525 commits (total: 39,608)0 new public libcurl function (total: 100)4 new ... Continue reading curl 8.22.0 ->

## \[hardware\] Fullhan FH8626V100 - Multiple Vulnerabilities

DevFeed: [\[hardware\] Fullhan FH8626V100 - Multiple Vulnerabilities](<https://devfeed.tech/articles/hardware-fullhan-fh8626v100-multiple-vulnerabilities-34767.md>)

Original publisher: [Read original article](<https://www.exploit-db.com/exploits/52674>)

Author: Amir Aliu

Published: 2026-09-02T00:00:00Z

Content type: article

Language: en

Sources: [Exploit-DB.com RSS Feed](<https://devfeed.tech/sources/exploit-db-com-rss-feed.md>)

Topics: [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [Exploit](<https://devfeed.tech/topics/exploit.md>), [Hardware](<https://devfeed.tech/topics/hardware.md>)

Tags: [cve](<https://devfeed.tech/tags/cve.md>), [cve-2026-51407cve-2026-51406cve-2026-51405cve-2026-51404cve-2026-51403cve-2026-51402](<https://devfeed.tech/tags/cve-2026-51407cve-2026-51406cve-2026-51405cve-2026-51404cve-2026-51403cve-2026-51402.md>), [exploit](<https://devfeed.tech/tags/exploit.md>), [hardware](<https://devfeed.tech/tags/hardware.md>), [multiple](<https://devfeed.tech/tags/multiple.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>)

### AI overview

This exploit record concerns multiple vulnerabilities in the Fullhan FH8626V100 hardware platform. It lists CVE-2026-51407 through CVE-2026-51402.

### Source excerpt

Fullhan FH8626V100 - Multiple Vulnerabilities

## \[webapps\] Langflow 1.10.0 - RCE

DevFeed: [\[webapps\] Langflow 1.10.0 - RCE](<https://devfeed.tech/articles/webapps-langflow-1-10-0-rce-34768.md>)

Original publisher: [Read original article](<https://www.exploit-db.com/exploits/52675>)

Author: Richard Howe

Published: 2026-09-02T00:00:00Z

Content type: article

Language: en

Sources: [Exploit-DB.com RSS Feed](<https://devfeed.tech/sources/exploit-db-com-rss-feed.md>)

Topics: [webapps](<https://devfeed.tech/topics/webapps.md>), [Exploit](<https://devfeed.tech/topics/exploit.md>)

Tags: [2026](<https://devfeed.tech/tags/2026.md>), [cve](<https://devfeed.tech/tags/cve.md>), [cve-2026-9198](<https://devfeed.tech/tags/cve-2026-9198.md>), [exploit](<https://devfeed.tech/tags/exploit.md>), [multiple](<https://devfeed.tech/tags/multiple.md>), [platform](<https://devfeed.tech/tags/platform.md>), [rce](<https://devfeed.tech/tags/rce.md>), [webapps](<https://devfeed.tech/tags/webapps.md>)

### AI overview

An entry describing a remote code execution exploit affecting Langflow 1.10.0, identified as CVE-2026-9198.

### Source excerpt

Langflow 1.10.0 - RCE

## \[webapps\] Ghost\_CMS 6.19.0 - Remote Code Execution

DevFeed: [\[webapps\] Ghost\_CMS 6.19.0 - Remote Code Execution](<https://devfeed.tech/articles/webapps-ghost-cms-6-19-0-remote-code-execution-34769.md>)

Original publisher: [Read original article](<https://www.exploit-db.com/exploits/52676>)

Author: Maksim Rogov

Published: 2026-09-02T00:00:00Z

Content type: article

Language: en

Sources: [Exploit-DB.com RSS Feed](<https://devfeed.tech/sources/exploit-db-com-rss-feed.md>)

Topics: [Exploit](<https://devfeed.tech/topics/exploit.md>), [webapps](<https://devfeed.tech/topics/webapps.md>)

Tags: [cve](<https://devfeed.tech/tags/cve.md>), [cve-2026-29053](<https://devfeed.tech/tags/cve-2026-29053.md>), [exploit](<https://devfeed.tech/tags/exploit.md>), [multiple](<https://devfeed.tech/tags/multiple.md>), [remote-code-execution](<https://devfeed.tech/tags/remote-code-execution.md>), [webapps](<https://devfeed.tech/tags/webapps.md>)

### AI overview

An Exploit Database entry identifies a remote code execution exploit affecting Ghost_CMS 6.19.0, associated with CVE-2026-29053 and listed for multiple platforms.

### Source excerpt

Ghost_CMS 6.19.0 - Remote Code Execution

## Abliterated Models Show Verdict Bias in FreeBSD Kernel Bug Hunting

DevFeed: [Abliterated Models Show Verdict Bias in FreeBSD Kernel Bug Hunting](<https://devfeed.tech/articles/don-t-let-abliteration-abliterate-your-bug-hunting-discovering-verdict-bias-in-uncensored-models-39717.md>)

Original publisher: [Read original article](<https://clearbluejar.github.io/posts/does-abliteration-skew-your-bug-hunting/>)

Author: clearbluejar

Published: 2026-09-01T06:00:00Z

Content type: article

Language: en

Sources: [clearbluejar](<https://devfeed.tech/sources/clearbluejar.md>)

Topics: [freebsd](<https://devfeed.tech/topics/freebsd.md>), [vulnerability](<https://devfeed.tech/topics/vulnerability.md>), [bug](<https://devfeed.tech/topics/bug.md>), [Kernel](<https://devfeed.tech/topics/kernel.md>), [gemma4](<https://devfeed.tech/topics/gemma4.md>), [Testing](<https://devfeed.tech/topics/testing.md>), [gemma](<https://devfeed.tech/topics/gemma.md>)

Tags: [bug](<https://devfeed.tech/tags/bug.md>), [bug-hunting](<https://devfeed.tech/tags/bug-hunting.md>), [cve](<https://devfeed.tech/tags/cve.md>), [false-positives](<https://devfeed.tech/tags/false-positives.md>), [freebsd](<https://devfeed.tech/tags/freebsd.md>), [gemma](<https://devfeed.tech/tags/gemma.md>), [gemma-4](<https://devfeed.tech/tags/gemma-4.md>), [kernel](<https://devfeed.tech/tags/kernel.md>), [llms](<https://devfeed.tech/tags/llms.md>), [testing](<https://devfeed.tech/tags/testing.md>), [vulnerability](<https://devfeed.tech/tags/vulnerability.md>), [vulnerability-research](<https://devfeed.tech/tags/vulnerability-research.md>)

### AI overview

The article examines local abliterated open-weight models during vulnerability scanning of FreeBSD kernel source. Compared with base models of the same family and size, the modified models produced substantially more candidate and VALID findings, including false positives, while the most aggressive build did not surface the real CVE in a 28-file scan. The article describes this tendency as verdict bias: a greater willingness to return positive findings under uncertainty.

### Source excerpt

Abliterated models never refuse, which makes them tempting for bug hunting. But on the same kernel source, they graduate three to four times as many findings to VALID, including false positives the base correctly rejects, and across a 28-file scan of FreeBSD's sys/rpc the most aggressive build never surfaced the real CVE at all.

## Wolf CMS 0.8.3.1 RCE Exploit (CVE-2026-67206)

DevFeed: [Wolf CMS 0.8.3.1 RCE Exploit (CVE-2026-67206)](<https://devfeed.tech/articles/webapps-wolf-cms-0-8-3-1-rce-v-34765.md>)

Original publisher: [Read original article](<https://www.exploit-db.com/exploits/52672>)

Author: Balachandar Gowrisankar

Published: 2026-09-01T00:00:00Z

Content type: article

Language: en

Sources: [Exploit-DB.com RSS Feed](<https://devfeed.tech/sources/exploit-db-com-rss-feed.md>)

Topics: [Content Management System](<https://devfeed.tech/topics/cms.md>), [Exploit](<https://devfeed.tech/topics/exploit.md>)

Tags: [cms](<https://devfeed.tech/tags/cms.md>), [cve](<https://devfeed.tech/tags/cve.md>), [cve-2026-67206](<https://devfeed.tech/tags/cve-2026-67206.md>), [exploit](<https://devfeed.tech/tags/exploit.md>), [multiple](<https://devfeed.tech/tags/multiple.md>), [platform](<https://devfeed.tech/tags/platform.md>), [rce](<https://devfeed.tech/tags/rce.md>), [webapps](<https://devfeed.tech/tags/webapps.md>)

### AI overview

An exploit entry for Wolf CMS 0.8.3.1 describing a remote code execution issue identified as CVE-2026-67206.

### Source excerpt

Wolf CMS 0.8.3.1 - RCE v

## \[webapps\] Grav CMS 2.0.7 - RCE

DevFeed: [\[webapps\] Grav CMS 2.0.7 - RCE](<https://devfeed.tech/articles/webapps-grav-cms-2-0-7-rce-34762.md>)

Original publisher: [Read original article](<https://www.exploit-db.com/exploits/52669>)

Author: zer0dayf

Published: 2026-09-01T00:00:00Z

Content type: article

Language: en

Sources: [Exploit-DB.com RSS Feed](<https://devfeed.tech/sources/exploit-db-com-rss-feed.md>)

Topics: [Content Management System](<https://devfeed.tech/topics/cms.md>), [Exploit](<https://devfeed.tech/topics/exploit.md>)

Tags: [2026](<https://devfeed.tech/tags/2026.md>), [cms](<https://devfeed.tech/tags/cms.md>), [cve](<https://devfeed.tech/tags/cve.md>), [cve-2026-65008](<https://devfeed.tech/tags/cve-2026-65008.md>), [exploit](<https://devfeed.tech/tags/exploit.md>), [multiple](<https://devfeed.tech/tags/multiple.md>), [platform](<https://devfeed.tech/tags/platform.md>), [rce](<https://devfeed.tech/tags/rce.md>), [webapps](<https://devfeed.tech/tags/webapps.md>)

### AI overview

An Exploit Database entry identifies a remote code execution exploit affecting Grav CMS 2.0.7 and references CVE-2026-65008.

### Source excerpt

Grav CMS 2.0.7 - RCE

## \[webapps\] EasyAppointments 1.5.1 - Blind SQL Injection

DevFeed: [\[webapps\] EasyAppointments 1.5.1 - Blind SQL Injection](<https://devfeed.tech/articles/webapps-easyappointments-1-5-1-blind-sql-injection-34760.md>)

Original publisher: [Read original article](<https://www.exploit-db.com/exploits/52667>)

Author: Michael Chesang

Published: 2026-09-01T00:00:00Z

Content type: article

Language: en

Sources: [Exploit-DB.com RSS Feed](<https://devfeed.tech/sources/exploit-db-com-rss-feed.md>)

Topics: [SQL](<https://devfeed.tech/topics/sql.md>), [Exploit](<https://devfeed.tech/topics/exploit.md>)

Tags: [cve](<https://devfeed.tech/tags/cve.md>), [cve-2025-50455](<https://devfeed.tech/tags/cve-2025-50455.md>), [exploit](<https://devfeed.tech/tags/exploit.md>), [multiple](<https://devfeed.tech/tags/multiple.md>), [sql](<https://devfeed.tech/tags/sql.md>), [webapps](<https://devfeed.tech/tags/webapps.md>)

### AI overview

An Exploit Database entry describes a blind SQL injection affecting EasyAppointments 1.5.1, identified as CVE-2025-50455.

### Source excerpt

EasyAppointments 1.5.1 - Blind SQL Injection

## \[webapps\] miniOrange 5.4.3 - Unauthenticated Auth Bypass

DevFeed: [\[webapps\] miniOrange 5.4.3 - Unauthenticated Auth Bypass](<https://devfeed.tech/articles/webapps-miniorange-5-4-3-unauthenticated-auth-bypass-34761.md>)

Original publisher: [Read original article](<https://www.exploit-db.com/exploits/52668>)

Author: zer0dayf

Published: 2026-09-01T00:00:00Z

Content type: article

Language: en

Sources: [Exploit-DB.com RSS Feed](<https://devfeed.tech/sources/exploit-db-com-rss-feed.md>)

Topics: [Exploit](<https://devfeed.tech/topics/exploit.md>)

Tags: [auth](<https://devfeed.tech/tags/auth.md>), [bypass](<https://devfeed.tech/tags/bypass.md>), [cve](<https://devfeed.tech/tags/cve.md>), [cve-2026-15013](<https://devfeed.tech/tags/cve-2026-15013.md>), [exploit](<https://devfeed.tech/tags/exploit.md>), [multiple](<https://devfeed.tech/tags/multiple.md>), [platform](<https://devfeed.tech/tags/platform.md>), [webapps](<https://devfeed.tech/tags/webapps.md>)

### AI overview

The entry identifies an unauthenticated authentication bypass affecting miniOrange 5.4.3, tracked as CVE-2026-15013. It is categorized as a web application exploit for multiple platforms.

### Source excerpt

miniOrange 5.4.3 - Unauthenticated Auth Bypass

## \[webapps\] Linksys E1200\_2.0.04 - Unauthenticated OS Command Injection

DevFeed: [\[webapps\] Linksys E1200\_2.0.04 - Unauthenticated OS Command Injection](<https://devfeed.tech/articles/webapps-linksys-e1200-2-0-04-unauthenticated-os-command-injection-34753.md>)

Original publisher: [Read original article](<https://www.exploit-db.com/exploits/52660>)

Author: jarrett

Published: 2026-08-31T00:00:00Z

Content type: article

Language: en

Sources: [Exploit-DB.com RSS Feed](<https://devfeed.tech/sources/exploit-db-com-rss-feed.md>)

Topics: [Exploit](<https://devfeed.tech/topics/exploit.md>), [Hardware](<https://devfeed.tech/topics/hardware.md>), [webapps](<https://devfeed.tech/topics/webapps.md>)

Tags: [command](<https://devfeed.tech/tags/command.md>), [cve](<https://devfeed.tech/tags/cve.md>), [cve-2025-60689](<https://devfeed.tech/tags/cve-2025-60689.md>), [exploit](<https://devfeed.tech/tags/exploit.md>), [hardware](<https://devfeed.tech/tags/hardware.md>), [os](<https://devfeed.tech/tags/os.md>), [platform](<https://devfeed.tech/tags/platform.md>), [webapps](<https://devfeed.tech/tags/webapps.md>)

### AI overview

This exploit listing identifies an unauthenticated OS command injection affecting Linksys E1200 version 2.0.04 and references CVE-2025-60689.

### Source excerpt

Linksys E1200_2.0.04 - Unauthenticated OS Command Injection

## \[webapps\] CubeCart 6.7.4 - Stored XSS

DevFeed: [\[webapps\] CubeCart 6.7.4 - Stored XSS](<https://devfeed.tech/articles/webapps-cubecart-6-7-4-stored-xss-34755.md>)

Original publisher: [Read original article](<https://www.exploit-db.com/exploits/52662>)

Author: Mikail KOCADAĞ

Published: 2026-08-31T00:00:00Z

Content type: article

Language: en

Sources: [Exploit-DB.com RSS Feed](<https://devfeed.tech/sources/exploit-db-com-rss-feed.md>)

Topics: [XSS](<https://devfeed.tech/topics/xss.md>), [Exploit](<https://devfeed.tech/topics/exploit.md>)

Tags: [cve](<https://devfeed.tech/tags/cve.md>), [cve-2026-54645](<https://devfeed.tech/tags/cve-2026-54645.md>), [exploit](<https://devfeed.tech/tags/exploit.md>), [multiple](<https://devfeed.tech/tags/multiple.md>), [platform](<https://devfeed.tech/tags/platform.md>), [stored](<https://devfeed.tech/tags/stored.md>), [webapps](<https://devfeed.tech/tags/webapps.md>), [xss](<https://devfeed.tech/tags/xss.md>)

### AI overview

An exploit entry for CubeCart 6.7.4 describing a stored cross-site scripting vulnerability identified as CVE-2026-54645. It is categorized as a web applications exploit for multiple platforms.

### Source excerpt

CubeCart 6.7.4 - Stored XSS

## \[webapps\] Langflow 1.8.4 - Path Traversal to Remote Code Execution

DevFeed: [\[webapps\] Langflow 1.8.4 - Path Traversal to Remote Code Execution](<https://devfeed.tech/articles/webapps-langflow-1-8-4-path-traversal-to-remote-code-execution-34752.md>)

Original publisher: [Read original article](<https://www.exploit-db.com/exploits/52659>)

Author: cardosource

Published: 2026-08-31T00:00:00Z

Content type: article

Language: en

Sources: [Exploit-DB.com RSS Feed](<https://devfeed.tech/sources/exploit-db-com-rss-feed.md>)

Topics: [Exploit](<https://devfeed.tech/topics/exploit.md>)

Tags: [cve](<https://devfeed.tech/tags/cve.md>), [cve-2026-5027](<https://devfeed.tech/tags/cve-2026-5027.md>), [exploit](<https://devfeed.tech/tags/exploit.md>), [multiple](<https://devfeed.tech/tags/multiple.md>), [remote-code-execution](<https://devfeed.tech/tags/remote-code-execution.md>), [webapps](<https://devfeed.tech/tags/webapps.md>)

### AI overview

An exploit record identifies a path traversal vulnerability in Langflow 1.8.4 that can lead to remote code execution. It references CVE-2026-5027.

### Source excerpt

Langflow 1.8.4 - Path Traversal to Remote Code Execution

## \[webapps\] C-MOR 6.0104 - Cross-Site Scripting (XSS)

DevFeed: [\[webapps\] C-MOR 6.0104 - Cross-Site Scripting (XSS)](<https://devfeed.tech/articles/webapps-c-mor-6-0104-cross-site-scripting-xss-34758.md>)

Original publisher: [Read original article](<https://www.exploit-db.com/exploits/52665>)

Author: Samir Shamdin

Published: 2026-08-31T00:00:00Z

Content type: article

Language: en

Sources: [Exploit-DB.com RSS Feed](<https://devfeed.tech/sources/exploit-db-com-rss-feed.md>)

Topics: [webapps](<https://devfeed.tech/topics/webapps.md>), [XSS](<https://devfeed.tech/topics/xss.md>), [Exploit](<https://devfeed.tech/topics/exploit.md>), [Hardware](<https://devfeed.tech/topics/hardware.md>)

Tags: [cve](<https://devfeed.tech/tags/cve.md>), [cve-2026-51133](<https://devfeed.tech/tags/cve-2026-51133.md>), [exploit](<https://devfeed.tech/tags/exploit.md>), [hardware](<https://devfeed.tech/tags/hardware.md>), [webapps](<https://devfeed.tech/tags/webapps.md>), [xss](<https://devfeed.tech/tags/xss.md>)

### AI overview

A C-MOR 6.0104 entry documenting a Cross-Site Scripting (XSS) exploit identified as CVE-2026-51133.

### Source excerpt

C-MOR 6.0104 - Cross-Site Scripting (XSS)

[Next page](<https://devfeed.tech/tags/cve.md?cursor=WyIyMDI2LTA4LTMxVDAwOjAwOjAwKzAwOjAwIiwgIjgyYjc0MGJkLTA2MjktNDQ0NS1hYjExLWZmZjQ2N2FlYmY4YiJd>)