Infosec Trending Feed

Daily-updated intelligence feed tracking CVEs, zero-days, exploit releases, bug bounty writeups, breach reports, red-team research, hacking tools, and real-time infosec trends from leading sources worldwide.

Updated on: 7:05 AM IST, 19 Sep 2026 (6 hour(s) ago)

The last-24-hour sweep is still running.

The rapid source sweep is still running; I’ll provide the completed Markdown artifact when it finishes.

The source sweep is still running; I’ll write the verified markdown once it completes.

The ten source-specific collectors are still running; I’ll assemble new_updates.md when their results arrive.

NIST NVD

  • CVE-2026-93603 - CVSS 10.0 sandbox escape in vm2 through 3.12.0 caused by improper handling of a nullish this receiver in the apply trap.
  • CVE-2026-93605 - CVSS 10.0 vm2 NodeVM sandbox escape allows access to child_process and arbitrary command execution.
  • CVE-2025-15399 - CVSS 10.0 IBM Common Licensing Agent and ART products are vulnerable to CSRF enabling unauthorized actions.
  • CVE-2026-10747 - CVSS 10.0 IBM MQ Appliance heap buffer overflow may enable unauthenticated denial of service or arbitrary code execution.
  • CVE-2023-54399 - CVSS 9.8 Hongjing e-HR contains unauthenticated SQL injection in the /servlet/codesettree endpoint.
  • CVE-2026-75878 - CVSS 9.1 IBM Sterling File Gateway authentication bypass permits acquisition of a fully authenticated session through an unvalidated SSO header.
  • CVE-2026-80441 - CVSS 9.8 IBM Guardium Data Protection has an unauthenticated second-order SQL injection vulnerability.
  • CVE-2026-80442 - CVSS 9.9 IBM Guardium Data Protection has authenticated OS command injection in certificate export functionality.
  • CVE-2026-81657 - CVSS 9.8 IBM Guardium Data Protection is vulnerable to unauthenticated arbitrary code execution through insecure deserialization.
  • CVE-2026-82340 - CVSS 9.8 IBM Guardium Data Protection has unauthenticated insecure deserialization and attacker-controlled reflective method dispatch in its CAS listener.
  • CVE-2026-82832 - CVSS 9.6 IBM Guardium Data Protection permits authenticated arbitrary code execution through improper neutralization of input during web page generation.
  • CVE-2026-82967 - CVSS 9.8 IBM Guardium Data Protection authentication bypass allows unauthenticated remote access past IP-based controls.
  • CVE-2026-84064 - CVSS 9.9 IBM Guardium Data Protection permits authenticated arbitrary SQL command execution.
  • CVE-2026-84073 - CVSS 9.1 IBM Guardium Data Protection permits authenticated arbitrary SQL command execution.
  • CVE-2026-84075 - CVSS 9.9 IBM Guardium Data Protection lacks authentication for ChangeTrackerServlet operations.
  • CVE-2026-84078 - CVSS 9.9 IBM Guardium Data Protection lacks authentication for LoadBalancerServlet operations.
  • CVE-2026-84082 - CVSS 9.8 IBM Guardium Data Protection permits unauthenticated arbitrary SQL command execution.
  • CVE-2026-93839 - CVSS 9.8 LightLLM authentication bypass allows unauthenticated attackers to register arbitrary nodes through /pd_register.
  • CVE-2026-93738 - CVSS 9.9 Totolink A3002MU buffer overflow in formSchedule can be triggered through crafted input.
  • CVE-2026-75885 - CVSS 9.3 OpenShift console unauthenticated devfile endpoints allow crafted payloads that can lead to SSRF and related impact.
  • CVE-2026-93739 - CVSS 9.9 Totolink A3002MU buffer overflow in formWlAc can be triggered through the submit-url parameter.
  • CVE-2026-93740 - CVSS 10.0 Totolink A3002MU buffer overflow in formWlEncrypt can be triggered through crafted input.

GitHub Search

GhostTroops/TOP

  • ghostlock-app - TOP snapshot dated 2026-09-18 lists this one-tap execution project associated with CVE-2026-43499.
  • CVE-2026-21858 - TOP snapshot dated 2026-09-18 lists this n8n unauthenticated arbitrary-file-read-to-RCE chain.
  • Root-My-Galaxy - TOP snapshot dated 2026-09-18 lists this KSU installer project associated with CVE-2026-43499.
  • cve-2026-41940-PoC - TOP snapshot dated 2026-09-18 lists this cPanel and WHM authentication-bypass tool.
  • CVE-2026-75604-poc - TOP snapshot dated 2026-09-18 lists this Next.js Windows RCE proof of concept.
  • Next.js-RSC-RCE-Scanner-CVE-2025-66478 - TOP snapshot dated 2026-09-18 lists this scanner for detecting affected Next.js versions.

The last-24-hours intelligence sweep is still running.

⚠️ This content is automatically collected by an AI bot from public web sources and may contain inaccuracies.


Developed by @win3zz