Netlas.io
2.32K subscribers
427 photos
3 videos
568 links
Explore the latest in cybersecurity with Netlas.io. Stay ahead with updates on high-profile vulnerabilities, expert tutorials, essential safety tips, and the latest Netlas developments.
Download Telegram
Authentication bypass in Proxmox VE with public exploit and active exploitation, no CVE assigned yet ❗️

A recently disclosed vulnerability in EOL releases of Proxmox VE allows unauthenticated remote attackers to log in as root without a password. Public PoC now exists! This vulnerability is being actively exploited in the wild!

Search at Netlas.io:
πŸ‘‰ Link: https://nt.ls/qLCVL
πŸ‘‰ Dork: tag.name:"proxmox_ve"

Vendor's advisory:
https://forum.proxmox.com/threads/proxmox-virtual-environment-security-advisories.149331/page-4#-subject-psa-2026-00043-1-authentication-bypass-in-eol-proxmox-ve-7-release
πŸ”₯3❀1
CVE-2026-84645: RCE in Jenkins, 8.8 rating ‍πŸ”₯

Jenkins disclosed numerous vulnerabilities in its security advisory. The most dangerous one allows remote code execution through unsafe deserialization.

Search at Netlas.io:
πŸ‘‰ Link: https://nt.ls/7bpLG
πŸ‘‰ Dork: tag.name:"jenkins"

Vendor's advisory :
https://www.jenkins.io/security/advisory/2026-09-02/
πŸ”₯2❀1
CVE-2026-85602: Grav Form Plugin reCAPTCHA v3 Authentication Bypass, 9.3 rating ‍πŸ”₯

The Grav Form plugin selects which reCAPTCHA version to use for validation based solely on the presence of a specific response field key in the submitted payload. This allows an anonymous attacker to bypass reCAPTCHA v3 bot protection.

Search at Netlas.io:
πŸ‘‰ Link: https://nt.ls/VcB4a
πŸ‘‰ Dork: tag.name:"grav"

Vendor's advisory :
https://github.com/getgrav/grav/security/advisories/GHSA-89j6-8h38-2cc3
πŸ”₯4❀1
CVE-2026-67276 and others: MikroTik RouterOS vulnerabilities exploited in the wild (MikroTrick), up to 9.2 rating ‍πŸ”₯

Recently disclosed vulnerabilities in MikroTik RouterOS allow an attacker to take full control of the device without authentication if the device supports remote access via the SSH protocol. These vulnerabilities are being actively exploited in the wild!

Search at Netlas.io:
πŸ‘‰ Link: https://nt.ls/318sx
πŸ‘‰ Dork: tag.name:"mikrotik"

Vendor's advisory :
https://mikrotik.com/supportsec/september-2026-vulnerability/
πŸ”₯2❀1
CVE-2026-75650: Adobe Commerce and Magento Open Source RCE vulnerability (StyleSmuggler) exploited in the wild, 10.0 rating ‍πŸ”₯

Recently disclosed vulnerability in Adobe Commerce and Magento Open Source allows an unauthenticated attacker to execute arbitrary code. This vulnerability is being actively exploited in the wild!

Search at Netlas.io:
πŸ‘‰ Link: https://nt.ls/bX5dx
πŸ‘‰ Dork: tag.name:"magento"

Read more :
https://sansec.io/research/stylesmuggler-0day
❀1πŸ”₯1
CVE-2026-44756: A memory corruption vulnerability in SAP (OVERPASS), 10.0 rating ‍πŸ”₯

A recently disclosed memory corruption vulnerability, which resides in the SAP kernel's processing of the Extended Passport (EPP), allows unauthenticated attackers to run arbitrary OS commands on the SAP host with SAP administrative privileges, potentially leading to a total compromise of underlying business data and processes.

Search at Netlas.io:
πŸ‘‰ Link: https://nt.ls/U7K8V
πŸ‘‰ Dork: http.headers.server:"SAP"

Read more :
https://onapsis.com/blog/sap-overpass-remediation/
❀3πŸ”₯3
CVE-2026-67401: SQL Injection Vulnerability in cPanel, 9.9 Rating πŸ”₯

A vulnerability in cPanel's EmailTrack component allows an authenticated attacker with mail-related privileges to create arbitrary files on the server via SQL injection. This may lead to code execution as the root user, giving the attacker full control of the server.

Search at Netlas.io:
πŸ‘‰ Link: https://nt.ls/dIEpd
πŸ‘‰ Dork: http.title:cpanel OR http.headers.set_cookie:"cprelogin" OR http.headers.set_cookie:"cpsession"

Vendor's advisory:
https://support.cpanel.net/hc/en-us/articles/43187903921559-Security-CVE-2026-67401-SQL-Injection-Vulnerability-in-cPanel-s-EmailTrack-Functionality-September-8-2026
πŸ”₯3❀1πŸ‘Ύ1
CVE-2026-85102 and CVE-2026-85103: Two RCE Vulnerabilities in Check Point Products, 9.8 Rating πŸ”₯

Two critical VPN-related vulnerabilities recently disclosed in Check Point Security Gateways, firewall appliances, and the Security Management Server could allow unauthenticated remote code execution under specific conditions. Both vulnerabilities exist in the way the products handle VPN certificates.

Search at Netlas.io:
πŸ‘‰ Link: https://nt.ls/hJmZ6
πŸ‘‰ Dork: http.headers.server:"CPWS" OR http.favicon.hash_sha256:78bd48391c96c6ac257e74e109783cc2750b39ea144a849f8d830f4f8f279267 OR http.favicon.hash_sha256:475a554d9a6c971ebf248fe45bcecafbab2b663edd7f080486a995c877dd1216 OR http.body:"TITLE>GAiA</TITLE>" OR path:"/sslvpn/Login/Login" OR http.headers.set_cookie:"CheckCookieSupport"

Vendor's advisory:
https://community.checkpoint.com/t5/General-Topics/Action-Required-Critical-Security-Advisory-VPN-Vulnerabilities/td-p/281995
πŸ”₯3❀1
πŸ”Œ Plug & Pwn: Mapping the Windows PnP Auto-Install Attack Surface

Windows Plug & Play can automatically install signed vendor software with SYSTEM privileges. With RDP USB redirection, this attack surface may also be reachable remotely β€” no physical USB device required.

Look at how this attack works and how Netlas can help map exposed RDP infrastructure.

πŸ‘‰ https://netlas.io/blog/windows_pnp_auto_install_attack_surface/
πŸ”₯6πŸ‘4❀1
CVE-2026-78006 & CVE-2026-78159: Two unauthenticated vulnerability chains leading to RCE in The Events Calendar Plugin for WordPress, 9.8 Rating πŸ”₯

Two critical vulnerabilities were recently disclosed in The Events Calendar Plugin for WordPress. The first uses PHP Object Injection to execute arbitrary OS commands on the underlying server. The second allows an unauthenticated attacker to reset an administrator’s password, after which the attacker can upload a malicious plugin and take complete control of the site. The first vulnerability (CVE-2026-78006) is already being exploited in the wild!

Search at Netlas.io:
πŸ‘‰ Link: https://nt.ls/mEm8O
πŸ‘‰ Dork: http.body:"plugins/the-events-calendar"

Read more:
https://www.wordfence.com/blog/2026/09/wordfence-argus-identifies-two-critical-unauthenticated-vulnerability-chains-leading-to-remote-code-execution-in-the-events-calendar-plugin/
❀1πŸ”₯1
CVE-2026-61642: Request smuggling is possible in Squid proxy, 7.7 Rating πŸ”₯

A recently disclosed vulnerability in Squid proxy allows a trusted client to poison the web cache and store arbitrary malicious content at any URL, which can then be delivered to other clients in response to their future requests.

Search at Netlas.io:
πŸ‘‰ Link: https://nt.ls/B7WF8
πŸ‘‰ Dork: http.headers.server:"squid"

Read more:
https://github.com/squid-cache/squid/security/advisories/GHSA-537g-4gfh-w7m6
❀1πŸ”₯1