Related Threat Clusters
-
Critical OS Command Injection Vulnerability in wg-easy 15.3.0 Disclosed
A severe OS command injection vulnerability (CVE-2026-72603) has been identified in wg-easy version 15.3.0. This flaw allows authenticated users with clients.create permission to inject newline-delimited WireGuard…
4 articles · Updated August 11, 2026 -
Ubiquiti Patches Critical Vulnerabilities in UniFi OS Exposing Remote Attacks
Ubiquiti has issued security updates for five critical vulnerabilities in UniFi OS, including three maximum severity flaws (CVE-2026-34908, CVE-2026-34909, CVE-2026-34910) that allow remote attackers to execute…
51 articles · Updated May 22, 2026 -
Critical Command Injection and DoS Vulnerabilities in openSUSE pcp
Recent updates for openSUSE's pcp software have addressed multiple critical vulnerabilities, including command injection and denial-of-service (DoS) issues. The vulnerabilities, identified as CVE-2026-16524,…
11 articles · Updated August 6, 2026 -
Critical OS Command Injection Vulnerability in Atlassian Bamboo Disclosed
Atlassian has announced two critical vulnerabilities in its Bamboo Data Center and Server product, including a severe OS command injection flaw (CVE-2026-21571) and a high-severity denial-of-service issue. The command…
2 articles · Updated April 22, 2026 -
Multiple Critical Vulnerabilities Exploited in SonicWall and SharePoint Systems
In July 2026, several critical vulnerabilities were exploited, impacting SonicWall SMA1000 appliances and SharePoint servers. Two zero-day vulnerabilities, CVE-2026-15409 and CVE-2026-15410, were discovered in SonicWall…
2 articles · Updated July 28, 2026 -
Critical Command Injection Vulnerabilities in MSI Radix AXE6600 Router Firmware
MSI Radix AXE6600 router firmware version v781521 has multiple command injection vulnerabilities, identified as CVE-2026-71993, CVE-2026-71992, and CVE-2026-71987. These flaws allow unauthenticated remote attackers to…
4 articles · Updated August 9, 2026 -
Critical Command Injection Vulnerability in D-Link DWR-M961 Devices
A critical command injection vulnerability, CVE-2026-71954, has been identified in D-Link DWR-M961 devices with hardware version C1 and firmware versions prior to 1.1.5_C1_202607071108. This vulnerability allows…
2 articles · Updated August 9, 2026 -
Critical Vulnerabilities in Rocky Linux Affecting Multiple Components
Rocky Linux has released multiple security updates addressing critical vulnerabilities across various components, including 389-ds-base, HPLIP, and dracut. The vulnerabilities include a denial-of-service (DoS) issue in…
846 articles · Updated June 19, 2026 -
Critical Security Updates for Python 3.13 in Fedora Address Multiple Vulnerabilities
On June 21, 2026, Fedora released critical security updates for Python 3.13, addressing multiple vulnerabilities. The updates include fixes for CVE-2026-1502, CVE-2026-6100, CVE-2026-4786, CVE-2026-7210, and…
9 articles · Updated June 21, 2026 -
Critical Vulnerabilities in Tenable Security Center Prompt Urgent Patch Release
Tenable has released Security Center Patch SC202607.1 to address multiple vulnerabilities in third-party components, including Apache, OpenSSL, PostgreSQL, PHP, and Redis. The patch resolves critical issues such as SQL…
2 articles · Updated July 21, 2026
Recent Intelligence Reports
- openSUSE Wicked Important Indirect Shell Command Injection Fix 2026-3840 — Linuxsecurity · August 28, 2026
- CC-4837 — Digital.Nhs.Uk · August 27, 2026
- Ubiquiti patches three max severity security vulnerabilities — Bleepingcomputer · August 26, 2026
- Inyección de comandos en Apache CloudStack permite a operadores ejecutar código en hipervisores KVM — Ciberseguridadlatam · August 23, 2026
- Snowflake GitHub Actions Flaw Lets Crafted Issues Trigger Command Injection — Thehackernews · August 17, 2026
- 74 — cwe.mitre.org · August 17, 2026
- wg-easy wg-easy - OS Command InjectionAn OS command injection vulnerability i... CVE: New / 18h An OS command injection vulnerability in wg-easy 15.3.0 allows users with the clients.create permission to execute arbitrary commands as root by injecting newline-delimited WireGuard PostUp directives into the client name field. The client name is written to the WireGuard configuration file without neutralizing newline characters, allowing injection of arbitrary directives that are executed by wg-quic — cve.threatint.com · August 12, 2026
- CVE-2026-72862 - Exploits & Severity — Feedly · August 11, 2026