CVE-2026-93952: Improper Input Validation in VeloCloud Orchestrator, 10.0 Rating 🔥
A recently disclosed improper input validation vulnerability in on-premises VeloCloud Orchestrator (VCO) allows a remote attacker to access privileged internal functionality and impact the VCO host. This vulnerability is known to be actively exploited in the wild!
Search at Netlas.io:
👉 Link: https://nt.ls/Z9gGT
👉 Dork: http.body:"single-spa-application:@velocloud/vco-header" OR http.body:"vco/branding.css" OR http.body:"vco/favicon"
Vendor's advisory:
https://www.arista.com/en/support/advisories-notices/security-advisory/24765-security-advisory-0183
A recently disclosed improper input validation vulnerability in on-premises VeloCloud Orchestrator (VCO) allows a remote attacker to access privileged internal functionality and impact the VCO host. This vulnerability is known to be actively exploited in the wild!
Search at Netlas.io:
👉 Link: https://nt.ls/Z9gGT
👉 Dork: http.body:"single-spa-application:@velocloud/vco-header" OR http.body:"vco/branding.css" OR http.body:"vco/favicon"
Vendor's advisory:
https://www.arista.com/en/support/advisories-notices/security-advisory/24765-security-advisory-0183
🔥3❤1
CVE-2026-87902: Path Traversal in WordPress leading to RCE, 9.2 Rating 🔥
Another newly disclosed WordPress RCE vulnerability allows an unauthenticated attacker to execute arbitrary code under specific server conditions.
Search at Netlas.io:
👉 Link: https://nt.ls/B4TJE
👉 Dork: tag.name:"wordpress"
Vendor's advisory:
https://github.com/WordPress/wordpress-develop/security/advisories/GHSA-7hp8-65ch-5whp
Another newly disclosed WordPress RCE vulnerability allows an unauthenticated attacker to execute arbitrary code under specific server conditions.
Search at Netlas.io:
👉 Link: https://nt.ls/B4TJE
👉 Dork: tag.name:"wordpress"
Vendor's advisory:
https://github.com/WordPress/wordpress-develop/security/advisories/GHSA-7hp8-65ch-5whp
🔥2❤1👾1
CVE-2026-88804: Unauthenticated update of public UI settings leading to stored XSS in Rancher, 9.4 Rating 🔥
An unauthenticated attacker can plant malicious content that runs in the browser of anyone visiting the Rancher login page. This can leak the local administrator bootstrap password or hijack an active admin session, leading to complete control of the Rancher installation and its managed downstream clusters.
Search at Netlas.io:
👉 Link: https://nt.ls/dtxM5
👉 Dork: http.favicon.hash_sha256:2d7adbc74e7c8941927d04e702acbff577d219fef8617c8c3014d34ae395525b OR http.body:"<title>Rancher</title>" OR http.unknown_headers.key:"x_api_cattle_auth"
Vendor's advisory:
https://github.com/rancher/rancher/security/advisories/GHSA-992f-xh8r-jg2f
An unauthenticated attacker can plant malicious content that runs in the browser of anyone visiting the Rancher login page. This can leak the local administrator bootstrap password or hijack an active admin session, leading to complete control of the Rancher installation and its managed downstream clusters.
Search at Netlas.io:
👉 Link: https://nt.ls/dtxM5
👉 Dork: http.favicon.hash_sha256:2d7adbc74e7c8941927d04e702acbff577d219fef8617c8c3014d34ae395525b OR http.body:"<title>Rancher</title>" OR http.unknown_headers.key:"x_api_cattle_auth"
Vendor's advisory:
https://github.com/rancher/rancher/security/advisories/GHSA-992f-xh8r-jg2f
❤1🔥1
CVE-2026-13016 and others: Multiple vulnerabilities in ServiceNow, up to 9.3 Rating 🔥
Recently disclosed vulnerabilities in ServiceNow include an unauthenticated SQL injection flaw and multiple authorization bypasses.
Search at Netlas.io:
👉 Link: https://nt.ls/BxHZZ
👉 Dork: http.body:"<title>ServiceNow</title>" OR http.favicon.hash_sha256:41b71be5f4ce761e9772c2a5ab8afe5b3e7cfb56226597fc406155b868531a0e OR http.headers.set_cookie:"glide_user"
Vendor's advisory:
https://support.servicenow.com/kb?id=kb_article_view&sysparm_article=KB3159623
Recently disclosed vulnerabilities in ServiceNow include an unauthenticated SQL injection flaw and multiple authorization bypasses.
Search at Netlas.io:
👉 Link: https://nt.ls/BxHZZ
👉 Dork: http.body:"<title>ServiceNow</title>" OR http.favicon.hash_sha256:41b71be5f4ce761e9772c2a5ab8afe5b3e7cfb56226597fc406155b868531a0e OR http.headers.set_cookie:"glide_user"
Vendor's advisory:
https://support.servicenow.com/kb?id=kb_article_view&sysparm_article=KB3159623
🔥2❤1
CVE-2026-88771 & CVE-2026-88772: RCE and/or DoS in Citrix NetScaler ADC and NetScaler Gateway, both rated 9.5 🔥
Citrix disclosed two exploited vulnerabilities. The first (CVE-2026-88771) allows an unauthenticated attacker to run arbitrary commands. It affects all NetScaler ADC and NetScaler Gateway deployments. The second (CVE-2026-88772) leads to RCE or DoS. It affects appliances with DTLS enabled. These vulnerabilities are already being actively exploited in the wild, and PoCs exist!
Search at Netlas.io:
👉 Link: https://nt.ls/m5KaR
👉 Dork (NetScaler Gateway): http.title:"citrix gateway" OR http.headers.set_cookie:"pwcount" OR http.favicon.hash_sha256:7b2fe2b7235b6645998edcae988ce1edaac40764c202abc3a4766db1b8ae6360 OR http.favicon.hash_sha256:3e8f8b98d8fe34a5e627c3033f0940777144effe4b5f588c67bfc6ba3bf106fa
Vendor's advisory:
https://support.citrix.com/support-home/kbsearch/article?articleNumber=CTX697096
Citrix disclosed two exploited vulnerabilities. The first (CVE-2026-88771) allows an unauthenticated attacker to run arbitrary commands. It affects all NetScaler ADC and NetScaler Gateway deployments. The second (CVE-2026-88772) leads to RCE or DoS. It affects appliances with DTLS enabled. These vulnerabilities are already being actively exploited in the wild, and PoCs exist!
Search at Netlas.io:
👉 Link: https://nt.ls/m5KaR
👉 Dork (NetScaler Gateway): http.title:"citrix gateway" OR http.headers.set_cookie:"pwcount" OR http.favicon.hash_sha256:7b2fe2b7235b6645998edcae988ce1edaac40764c202abc3a4766db1b8ae6360 OR http.favicon.hash_sha256:3e8f8b98d8fe34a5e627c3033f0940777144effe4b5f588c67bfc6ba3bf106fa
Vendor's advisory:
https://support.citrix.com/support-home/kbsearch/article?articleNumber=CTX697096
❤1🔥1
CVE-2026-63292 and others: Multiple vulnerabilities in Apache HTTP Server, up to 9.8 rating 🔥
Apache Software Foundation disclosed 20 new vulnerabilities. The most severe can lead to RCE, arbitrary code execution via stack-based buffer overflow, and DoS/potential RCE via use-after-free. Memory corruption, privilege escalation, and info disclosure bugs were also patched.
Search at Netlas.io:
👉 Link: https://nt.ls/fFMkT
👉 Dork: tag.name:"apache"
Vendor's advisory:
https://httpd.apache.org/security/vulnerabilities_24.html
Apache Software Foundation disclosed 20 new vulnerabilities. The most severe can lead to RCE, arbitrary code execution via stack-based buffer overflow, and DoS/potential RCE via use-after-free. Memory corruption, privilege escalation, and info disclosure bugs were also patched.
Search at Netlas.io:
👉 Link: https://nt.ls/fFMkT
👉 Dork: tag.name:"apache"
Vendor's advisory:
https://httpd.apache.org/security/vulnerabilities_24.html
❤3🔥2
CVE-2026-96940: EoP vulnerability in MS Exchange Server, 8.8 rating 🔥
Microsoft has updated its September 2026 Exchange Server security updates, addressing only one new vulnerability. It allows an authenticated attacker to elevate privileges over a network and gain unauthorized access to other users' mailboxes within the same organization.
Search at Netlas.io:
👉 Link: https://nt.ls/L5NIL
👉 Dork: tag.name:"microsoft_exchange"
Vendor's advisory:
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-96940
Microsoft has updated its September 2026 Exchange Server security updates, addressing only one new vulnerability. It allows an authenticated attacker to elevate privileges over a network and gain unauthorized access to other users' mailboxes within the same organization.
Search at Netlas.io:
👉 Link: https://nt.ls/L5NIL
👉 Dork: tag.name:"microsoft_exchange"
Vendor's advisory:
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-96940
🔥3❤1
CVE-2026-88779: DoS vulnerability in Citrix NetScaler ADC & Gateway, 8.7 rating 🔥
A recently disclosed memory overflow vulnerability in NetScaler ADC and NetScaler Gateway can lead to Denial of Service when configured as a SAML SP or IdP. This vulnerability is being actively exploited in the wild!
Search at Netlas.io:
👉 Link: https://nt.ls/1PpoX
👉 Dork (NetScaler ADC): http.headers.set_cookie:"citrix_ns_id" OR http.headers.set_cookie:"ns_af" OR http.headers.set_cookie:"NSC_" OR http.headers.set_cookie:"NSC_ESNS"
👉 Dork (NetScaler Gateway): http.title:"citrix gateway" OR http.headers.set_cookie:"pwcount" OR http.favicon.hash_sha256:7b2fe2b7235b6645998edcae988ce1edaac40764c202abc3a4766db1b8ae6360 OR http.favicon.hash_sha256:3e8f8b98d8fe34a5e627c3033f0940777144effe4b5f588c67bfc6ba3bf106fa
Vendor's advisory:
https://support.citrix.com/support-home/kbsearch/article?articleNumber=CTX697174
A recently disclosed memory overflow vulnerability in NetScaler ADC and NetScaler Gateway can lead to Denial of Service when configured as a SAML SP or IdP. This vulnerability is being actively exploited in the wild!
Search at Netlas.io:
👉 Link: https://nt.ls/1PpoX
👉 Dork (NetScaler ADC): http.headers.set_cookie:"citrix_ns_id" OR http.headers.set_cookie:"ns_af" OR http.headers.set_cookie:"NSC_" OR http.headers.set_cookie:"NSC_ESNS"
👉 Dork (NetScaler Gateway): http.title:"citrix gateway" OR http.headers.set_cookie:"pwcount" OR http.favicon.hash_sha256:7b2fe2b7235b6645998edcae988ce1edaac40764c202abc3a4766db1b8ae6360 OR http.favicon.hash_sha256:3e8f8b98d8fe34a5e627c3033f0940777144effe4b5f588c67bfc6ba3bf106fa
Vendor's advisory:
https://support.citrix.com/support-home/kbsearch/article?articleNumber=CTX697174
❤2🔥2
🎯 Netlas v1.10
Track changes in your attack surface with the new private scan comparison. See which targets, services, and CVE matches appeared, disappeared, or changed.
✔ Compare scans in the UI and via API
✔ Rebuild attack surfaces with clearer guidance and fewer questions
✔ Discover building automation devices with KNXnet/IP support
✔ Explore host references with linked_hosts
✔ Try experimental misconfiguration detection, initially focused on SQL services
👉 Full changelog: https://docs.netlas.io/changelog/
Track changes in your attack surface with the new private scan comparison. See which targets, services, and CVE matches appeared, disappeared, or changed.
✔ Compare scans in the UI and via API
✔ Rebuild attack surfaces with clearer guidance and fewer questions
✔ Discover building automation devices with KNXnet/IP support
✔ Explore host references with linked_hosts
✔ Try experimental misconfiguration detection, initially focused on SQL services
👉 Full changelog: https://docs.netlas.io/changelog/
docs.netlas.io
Changelog - Netlas Docs
Explore the latest updates, enhancements, and fixes on the Netlas platform. Stay informed with our Changelog for all product and feature developments.
🔥7
CVE-2026-106445 & CVE-2026-106446: Two RCE flaws in Handlebars.js, up to 9.8 rating 🔥
Two recently disclosed vulnerabilities in Handlebars.js allow an attacker to run arbitrary JavaScript on the server. Both the technical details and PoC exploit code are now public!
Search at Netlas.io:
👉 Link: https://nt.ls/KMYBH
👉 Dork: tag.name:"handlebars"
Vendor's advisory:
https://github.com/handlebars-lang/handlebars.js/security/advisories
Two recently disclosed vulnerabilities in Handlebars.js allow an attacker to run arbitrary JavaScript on the server. Both the technical details and PoC exploit code are now public!
Search at Netlas.io:
👉 Link: https://nt.ls/KMYBH
👉 Dork: tag.name:"handlebars"
Vendor's advisory:
https://github.com/handlebars-lang/handlebars.js/security/advisories
❤3🔥1
CVE-2026-76268 and others: Multiple vulnerabilities in Splunk Enterprise, up to 9.8 rating 🔥
Splunk has disclosed multiple vulnerabilities in Splunk Enterprise. The most serious is CVE-2026-76268, which allows an unauthenticated attacker to execute operating system commands through the Patroni REST API.
Search at Netlas.io:
👉 Link: https://nt.ls/GWmyZ
👉 Dork: http.title:"login - splunk" OR http.headers.server:"splunkd" OR http.unknown_headers.key:"x_splunk_version"
Vendor's advisory:
https://advisory.splunk.com/advisories/SVD-2026-1001
Splunk has disclosed multiple vulnerabilities in Splunk Enterprise. The most serious is CVE-2026-76268, which allows an unauthenticated attacker to execute operating system commands through the Patroni REST API.
Search at Netlas.io:
👉 Link: https://nt.ls/GWmyZ
👉 Dork: http.title:"login - splunk" OR http.headers.server:"splunkd" OR http.unknown_headers.key:"x_splunk_version"
Vendor's advisory:
https://advisory.splunk.com/advisories/SVD-2026-1001
🔥3❤2👾1