Cyber Code RED
2 subscribers
16 links
Real time cyber threat notifications
Download Telegram
Channel created
Channel photo updated
P1 · CVE-2025-39682
Linux Kernel Improper Check for Unusual or Exceptional Conditions Vulnerability

CVE-2025-39682 affects Linux Kernel. EPSS 0.0288 (percentile 0.86382), scored 2026-10-03. Listed in CISA KEV, added 2026-09-18.

Severity 80.0/100 · EPSS 0.0288 · KEV: yes
Verified · CISA Known Exploited Vulnerabilities Catalog (JSON), FIRST EPSS daily exploit-probability
https://cybercodered.org/item/cve-cve-2025-39682.html
P1 · CVE-2025-39964
Linux Kernel Race Condition Vulnerability

CVE-2025-39964 affects Linux Kernel. EPSS 0.00996 (percentile 0.61394), scored 2026-10-03. Listed in CISA KEV, added 2026-09-18.

Severity 80.0/100 · EPSS 0.00996 · KEV: yes
Verified · CISA Known Exploited Vulnerabilities Catalog (JSON), FIRST EPSS daily exploit-probability
https://cybercodered.org/item/cve-cve-2025-39964.html
P1 · CVE-2026-102489
Zammad GmbH Zammad Session Fixation Vulnerability

CVE-2026-102489 affects Zammad GmbH Zammad. EPSS 0.01396 (percentile 0.71464), scored 2026-10-03. Listed in CISA KEV, added 2026-10-02.

Severity 80.0/100 · EPSS 0.01396 · KEV: yes
Verified · CISA Known Exploited Vulnerabilities Catalog (JSON), FIRST EPSS daily exploit-probability
https://cybercodered.org/item/cve-cve-2026-102489.html
P1 · CVE-2026-102490
Zammad GmbH Zammad Improper Privilege Management Vulnerability

CVE-2026-102490 affects Zammad GmbH Zammad. EPSS 0.00629 (percentile 0.48335), scored 2026-10-03. Listed in CISA KEV, added 2026-10-02.

Severity 80.0/100 · EPSS 0.00629 · KEV: yes
Verified · CISA Known Exploited Vulnerabilities Catalog (JSON), FIRST EPSS daily exploit-probability
https://cybercodered.org/item/cve-cve-2026-102490.html
P1 · CVE-2026-104286
Fortinet warns of critical FortiMail flaw exploited in zero-day attacks

CVE-2026-104286 affects Fortinet FortiMail. EPSS 0.02201 (percentile 0.81912), scored 2026-10-03. Listed in CISA KEV, added 2026-10-01.

Severity 80.0/100 · EPSS 0.02201 · KEV: yes
Verified · BleepingComputer, CISA Known Exploited Vulnerabilities Catalog (JSON), FIRST EPSS daily exploit-probability
https://cybercodered.org/item/cve-cve-2026-104286.html
P1 · CVE-2026-53266
Linux Kernel Out-of-Bounds Write Vulnerability

CVE-2026-53266 affects Linux Kernel. EPSS 0.00827 (percentile 0.55987), scored 2026-10-03. Listed in CISA KEV, added 2026-09-18.

Severity 80.0/100 · EPSS 0.00827 · KEV: yes
Verified · CISA Known Exploited Vulnerabilities Catalog (JSON), FIRST EPSS daily exploit-probability
https://cybercodered.org/item/cve-cve-2026-53266.html
P1 · CVE-2026-5430
WSO2 Multiple Products Path Traversal Vulnerability

CVE-2026-5430 affects WSO2 Multiple Products. EPSS 0.00588 (percentile 0.46253), scored 2026-10-03. Listed in CISA KEV, added 2026-09-24.

Severity 80.0/100 · EPSS 0.00588 · KEV: yes
Verified · CISA Known Exploited Vulnerabilities Catalog (JSON), FIRST EPSS daily exploit-probability
https://cybercodered.org/item/cve-cve-2026-5430.html
P1 · CVE-2026-58704
Google Pixel Improper Authorization Vulnerability

CVE-2026-58704 affects Google Pixel. EPSS 0.00591 (percentile 0.46391), scored 2026-10-03. Listed in CISA KEV, added 2026-09-16.

Severity 80.0/100 · EPSS 0.00591 · KEV: yes
Verified · CISA Known Exploited Vulnerabilities Catalog (JSON), FIRST EPSS daily exploit-probability
https://cybercodered.org/item/cve-cve-2026-58704.html
P1 · CVE-2026-65660
Microsoft SharePoint Code Injection Vulnerability

CVE-2026-65660 affects Microsoft SharePoint. EPSS 0.02101 (percentile 0.81063), scored 2026-10-03. Listed in CISA KEV, added 2026-09-25.

Severity 80.0/100 · EPSS 0.02101 · KEV: yes
Verified · CISA Known Exploited Vulnerabilities Catalog (JSON), FIRST EPSS daily exploit-probability
https://cybercodered.org/item/cve-cve-2026-65660.html
P1 · CVE-2026-67279
Mikrotik RouterOS Improper Enforcement of Behavioral Workflow Vulnerability

CVE-2026-67279 affects MikroTik RouterOS. EPSS 0.01027 (percentile 0.62388), scored 2026-10-03. Listed in CISA KEV, added 2026-09-25.

Severity 80.0/100 · EPSS 0.01027 · KEV: yes
Verified · CISA Known Exploited Vulnerabilities Catalog (JSON), FIRST EPSS daily exploit-probability
https://cybercodered.org/item/cve-cve-2026-67279.html
BREAKING · Corroborated · BleepingComputer · The Hacker News · The Record
Warlock ransomware targets critical infrastructure

Warlock ransomware is targeting critical infrastructure. Targets include water and telecommunications operators. The attacks span Portuguese- and Spanish-speaking countries. The campaign exploits SharePoint flaws to disable security tools and deploy ransomware.

Corroborating sources:
BleepingComputer — https://www.bleepingcomputer.com/news/security/warlock-ransomware-breach-sharepoint-in-water-telecom-operator-attacks/ · 2026-10-02T18:33:01+00:00
The Hacker News — https://thehackernews.com/2026/10/warlock-exploits-sharepoint-flaws-to.html · 2026-10-03T14:36:33+00:00
The Record — https://therecord.media/warlock-ransomware-used-in-critical-infrastructure-attacks · 2026-10-02T14:05:00+00:00
https://cybercodered.org/story/story-714f2de259ad19a1285a8996.html
NEWS · Corroborated · BleepingComputer · The Hacker News
Critical RCE in GitLab AI Gateway patched

GitLab AI Gateway has a critical remote code execution flaw affecting self-hosted servers. Attackers can execute commands on affected systems.

Administrators running GitLab AI Gateway should apply the vendor's security updates.

Corroborating sources:
BleepingComputer — https://www.bleepingcomputer.com/news/security/gitlab-warns-of-critical-rce-vulnerability-in-ai-gateway-service/ · 2026-10-02T16:20:05+00:00
The Hacker News — https://thehackernews.com/2026/10/gitlab-patches-critical-self-hosted-ai.html · 2026-10-02T17:33:31+00:00
https://cybercodered.org/story/story-1c0db18b53893eeab151c207.html
NEWS · Corroborated · BleepingComputer · The Hacker News
Dell CSM flaws give attackers admin access

Security flaws in Dell CSM allow unauthenticated administrative access and root access on Kubernetes nodes. The flaws carry the highest severity rating.

Administrators running Dell CSM should apply the vendor's security updates.

Corroborating sources:
BleepingComputer — https://www.bleepingcomputer.com/news/security/new-max-severity-dell-csm-flaws-give-hackers-admin-privileges/ · 2026-10-02T12:37:40+00:00
The Hacker News — https://thehackernews.com/2026/10/dell-csm-flaws-enable-unauthenticated.html · 2026-10-02T17:02:12+00:00
https://cybercodered.org/story/story-d882ddba48791d15df3709cb.html
BREAKING · Corroborated · BleepingComputer · CISA Known Exploited Vulnerabilities Catalog · P1
Netscaler zero-day exploited in attacks

A zero-day vulnerability in Netscaler is being exploited in attacks.

Administrators running Netscaler should apply the vendor's security updates.

Corroborating sources:
BleepingComputer — https://www.bleepingcomputer.com/news/security/citrix-patches-netscaler-saml-zero-day-exploited-in-attacks/ · 2026-10-04T21:58:01+00:00
CISA Known Exploited Vulnerabilities Catalog — https://www.cisa.gov/known-exploited-vulnerabilities-catalog · 2026-10-04T00:00:00+00:00
https://cybercodered.org/story/story-3242cbb0e67d375b51221fcc.html
BREAKING · Single wire · Developing · Reuters
South Korean president orders probe into data leaks across financial industry

South Korean president orders probe into data leaks across financial industry.

Financial Services Commission (FSC) Chairman Lee Eog-weon convened an emergency meeting with financial industry associations, regulators and executives from affected institutions on Sunday, warning that the sector must respond with the highest level of vigilance, the FSC said in a statement.

Sources:
Reuters — https://www.cnbctv18.com/world/south-korean-president-orders-probe-into-data-leaks-across-financial-industry-20004120.htm · 2026-10-04T09:00:48+00:00
https://cybercodered.org/story/story-0050dced4aafb95ce61073ce.html