TOPIC ARCHIVE

Security & vulnerabilities

Selected Security & vulnerabilities developments from public primary sources.

P0
CISA Known Exploited Vulnerabilities

CVE-2026-48027: Nx Console Embedded Malicious Code Vulnerability

Nx Console contains an embedded malicious code vulnerability that allowed a malicious version of Nx Console to be published. The compromised extension fetched an obfuscated payload that could harvested credentials from multiple sources on…

P0
CISA Known Exploited Vulnerabilities

CVE-2026-45321: TanStack Unspecified Vulnerability

TanStack contains an unspecified vulnerability that allowed malicious versions of the product to be published to the npm registry to publish credential-stealing malware under a trusted identity.;Required action: Apply mitigations per vendo…

P0
CISA Known Exploited Vulnerabilities

CVE-2024-1708: ConnectWise ScreenConnect Path Traversal Vulnerability

ConnectWise ScreenConnect contains a path traversal vulnerability which could allow an attacker to execute remote code or directly impact confidential data and critical systems.;Required action: Apply mitigations per vendor instructions, f…

P0
CISA Known Exploited Vulnerabilities

CVE-2024-57728: SimpleHelp Path Traversal Vulnerability

SimpleHelp contains a path traversal vulnerability that allows admin users to upload arbitrary files anywhere on the file system by uploading a crafted zip file (i.e. zip slip). This can be exploited to execute arbitrary code on the host i…

P0
CISA Known Exploited Vulnerabilities

CVE-2024-57726: SimpleHelp Missing Authorization Vulnerability

SimpleHelp contains a missing authorization vulnerability that could allow low-privileged technicians to create API keys with excessive permissions. These API keys can be used to escalate privileges to the server admin role.;Required actio…

P0
CISA Known Exploited Vulnerabilities

CVE-2023-27351: PaperCut NG/MF Improper Authentication Vulnerability

PaperCut NG/MF contains an improper authentication vulnerability that could allow remote attackers to bypass authentication on affected installations via the SecurityRequestFilter class.;Required action: Apply mitigations per vendor instru…

P0
CISA Known Exploited Vulnerabilities

CVE-2024-27199: JetBrains TeamCity Relative Path Traversal Vulnerability

JetBrains TeamCity contains a relative path traversal vulnerability that could allow limited admin actions to be performed.;Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services…

P0
CISA Known Exploited Vulnerabilities

CVE-2025-61882: Oracle E-Business Suite Unspecified Vulnerability

Oracle E-Business Suite contains an unspecified vulnerability in the BI Publisher Integration component. The vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Concurrent Processing. Successful…