Infosec Trending Feed
Daily-updated intelligence feed tracking CVEs, zero-days, exploit releases, bug bounty writeups, breach reports, red-team research, hacking tools, and real-time infosec trends from leading sources worldwide.
Updated on: 7:05 AM IST, 19 Sep 2026
(6 hour(s) ago)
The last-24-hour sweep is still running.
The rapid source sweep is still running; I’ll provide the completed Markdown artifact when it finishes.
The source sweep is still running; I’ll write the verified markdown once it completes.
The ten source-specific collectors are still running; I’ll assemble new_updates.md when their results arrive.
NIST NVD
- CVE-2026-93603 - CVSS 10.0 sandbox escape in vm2 through 3.12.0 caused by improper handling of a nullish
thisreceiver in the apply trap. - CVE-2026-93605 - CVSS 10.0 vm2 NodeVM sandbox escape allows access to
child_processand arbitrary command execution. - CVE-2025-15399 - CVSS 10.0 IBM Common Licensing Agent and ART products are vulnerable to CSRF enabling unauthorized actions.
- CVE-2026-10747 - CVSS 10.0 IBM MQ Appliance heap buffer overflow may enable unauthenticated denial of service or arbitrary code execution.
- CVE-2023-54399 - CVSS 9.8 Hongjing e-HR contains unauthenticated SQL injection in the
/servlet/codesettreeendpoint. - CVE-2026-75878 - CVSS 9.1 IBM Sterling File Gateway authentication bypass permits acquisition of a fully authenticated session through an unvalidated SSO header.
- CVE-2026-80441 - CVSS 9.8 IBM Guardium Data Protection has an unauthenticated second-order SQL injection vulnerability.
- CVE-2026-80442 - CVSS 9.9 IBM Guardium Data Protection has authenticated OS command injection in certificate export functionality.
- CVE-2026-81657 - CVSS 9.8 IBM Guardium Data Protection is vulnerable to unauthenticated arbitrary code execution through insecure deserialization.
- CVE-2026-82340 - CVSS 9.8 IBM Guardium Data Protection has unauthenticated insecure deserialization and attacker-controlled reflective method dispatch in its CAS listener.
- CVE-2026-82832 - CVSS 9.6 IBM Guardium Data Protection permits authenticated arbitrary code execution through improper neutralization of input during web page generation.
- CVE-2026-82967 - CVSS 9.8 IBM Guardium Data Protection authentication bypass allows unauthenticated remote access past IP-based controls.
- CVE-2026-84064 - CVSS 9.9 IBM Guardium Data Protection permits authenticated arbitrary SQL command execution.
- CVE-2026-84073 - CVSS 9.1 IBM Guardium Data Protection permits authenticated arbitrary SQL command execution.
- CVE-2026-84075 - CVSS 9.9 IBM Guardium Data Protection lacks authentication for ChangeTrackerServlet operations.
- CVE-2026-84078 - CVSS 9.9 IBM Guardium Data Protection lacks authentication for LoadBalancerServlet operations.
- CVE-2026-84082 - CVSS 9.8 IBM Guardium Data Protection permits unauthenticated arbitrary SQL command execution.
- CVE-2026-93839 - CVSS 9.8 LightLLM authentication bypass allows unauthenticated attackers to register arbitrary nodes through
/pd_register. - CVE-2026-93738 - CVSS 9.9 Totolink A3002MU buffer overflow in
formSchedulecan be triggered through crafted input. - CVE-2026-75885 - CVSS 9.3 OpenShift console unauthenticated devfile endpoints allow crafted payloads that can lead to SSRF and related impact.
- CVE-2026-93739 - CVSS 9.9 Totolink A3002MU buffer overflow in
formWlAccan be triggered through thesubmit-urlparameter. - CVE-2026-93740 - CVSS 10.0 Totolink A3002MU buffer overflow in
formWlEncryptcan be triggered through crafted input.
GitHub Search
- sullivanian4/cvekrd - CVE-named repository created and updated on 2026-09-19 within the collection window.
- garciachristine88/cvetpw - CVE-named repository created and updated on 2026-09-19 within the collection window.
- Cchristian42/ANA_500-ePortfolio - Repository created on 2026-09-19 and describes analysis of NVD CVE data.
GhostTroops/TOP
- ghostlock-app - TOP snapshot dated 2026-09-18 lists this one-tap execution project associated with CVE-2026-43499.
- CVE-2026-21858 - TOP snapshot dated 2026-09-18 lists this n8n unauthenticated arbitrary-file-read-to-RCE chain.
- Root-My-Galaxy - TOP snapshot dated 2026-09-18 lists this KSU installer project associated with CVE-2026-43499.
- cve-2026-41940-PoC - TOP snapshot dated 2026-09-18 lists this cPanel and WHM authentication-bypass tool.
- CVE-2026-75604-poc - TOP snapshot dated 2026-09-18 lists this Next.js Windows RCE proof of concept.
- Next.js-RSC-RCE-Scanner-CVE-2025-66478 - TOP snapshot dated 2026-09-18 lists this scanner for detecting affected Next.js versions.
The last-24-hours intelligence sweep is still running.
⚠️ This content is automatically collected by an AI bot from public web sources and may contain inaccuracies.
Developed by @win3zz