PLAINTEXT REPORT / CVE Newly published vulnerabilities and exploits. High volume by nature, which is why it lives here and not on the front page. Updated 2026-09-18 11:30 UTC. Showing the last 24h. Inspired by brutalist.report, but for infosec news. Proud supporter of the small web. An Intergalactic Robots production. https://intergalacticrobots.app/ OFFENSIVE SEQUENCE ------------------ * [28m] CVE-2026-56595: CWE-942 Permissive Cross-domain Security Policy with Untrusted Domains in HCL Software HCL BigFix Service Management https://www.cve.org/CVERecord?id=CVE-2026-56595 * [28m] CVE-2026-40537: Server-Side Request Forgery (SSRF) in Synology DiskStation Manager (DSM) https://www.cve.org/CVERecord?id=CVE-2026-40537 * [28m] CVE-2026-40534: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in Synology DiskStation Manager (DSM) https://www.cve.org/CVERecord?id=CVE-2026-40534 * [28m] CVE-2026-40530: Improper Neutralization of CRLF Sequences ('CRLF Injection') in Synology DiskStation Manager (DSM) https://www.cve.org/CVERecord?id=CVE-2026-40530 * [28m] Microsoft Patches 18 Vulnerabilities in AI, Cloud Products https://radar.offseq.com/threat/microsoft-patches-18-vulnerabilities-in-ai-cloud-products-da5634e28897852b * [43m] CVE-2026-92976: CWE-613 Insufficient session expiration in T-Systems TAO https://www.cve.org/CVERecord?id=CVE-2026-92976 * [43m] CVE-2026-40539: Improper Certificate Validation in Synology DiskStation Manager (DSM) https://www.cve.org/CVERecord?id=CVE-2026-40539 * [43m] CVE-2026-21822: CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in HCL Software HCL AppScan 360° https://www.cve.org/CVERecord?id=CVE-2026-21822 * [58m] CVE-2026-93561: CWE-1035 in Red Hat Red Hat build of Apache Camel for Spring Boot 4 https://www.cve.org/CVERecord?id=CVE-2026-93561 * [1h] NightmareStresser DDoS Service Disrupted in International Operation https://radar.offseq.com/threat/nightmarestresser-ddos-service-disrupted-in-international-operation-32949c66be4cef55 * [1h] A Vault with a Heap-View: The Uncomfortable Space Between AgentCore Harness and Identity https://radar.offseq.com/threat/a-vault-with-a-heap-view-the-uncomfortable-space-between-agentcore-harness-and-identity-5be2c3e8dc3c811e * [1h] Brevo Supply Chain Attack Injects Malware Into 100,000 Websites https://radar.offseq.com/threat/brevo-supply-chain-attack-injects-malware-into-100000-websites-ab3a6e0b4e53290e * [1h] CVE-2026-40538: Improper Restriction of Excessive Authentication Attempts in Synology DiskStation Manager (DSM) https://www.cve.org/CVERecord?id=CVE-2026-40538 * [1h] CVE-2026-90884: CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in brechtvds WP Recipe Maker https://www.cve.org/CVERecord?id=CVE-2026-90884 * [1h] CVE-2026-87915: CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in danieliser Popup Maker – Boost Sales, Conversions, Optins, Subscribers with the Ultimate WP Popup Builder https://www.cve.org/CVERecord?id=CVE-2026-87915 * [1h] CVE-2026-18405: CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in jegtheme Jeg Kit for Elementor – Powerful Addons for Elementor, Widgets & Templates for WordPress https://www.cve.org/CVERecord?id=CVE-2026-18405 * [1h] CVE-2026-15797: CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in danieliser Popup Maker – Boost Sales, Conversions, Optins, Subscribers with the Ultimate WP Popup Builder https://www.cve.org/CVERecord?id=CVE-2026-15797 * [1h] CVE-2026-87743: Incorrect Behavior Order: Authorization Before Parsing and Canonicalization in Red Hat Exploit Intelligence https://www.cve.org/CVERecord?id=CVE-2026-87743 * [1h] CVE-2026-15579: CWE-787: Out-of-bounds Write in Moxa TN-4500B Series https://www.cve.org/CVERecord?id=CVE-2026-15579 * [1h] New Check Point flaw lets hackers execute code with root privileges https://radar.offseq.com/threat/new-check-point-flaw-lets-hackers-execute-code-with-root-privileges-00056aa571ef0004 * [2h] BlackCore’s Influence Operations for Hire https://radar.offseq.com/threat/blackcores-influence-operations-for-hire-c94004b57b26cacc * [2h] Beware the SparroWock: The backdoor that bites, the commands that catch https://radar.offseq.com/threat/beware-the-sparrowock-the-backdoor-that-bites-the-commands-that-catch-c3b77993cb1c038c * [2h] Ready, Settra, Go: New Settra Ransomware Variant Deploys MeshAgent RMM https://radar.offseq.com/threat/ready-settra-go-new-settra-ransomware-variant-deploys-meshagent-rmm-6d9fb129e970c80b * [2h] T-Mobile rewards points expiry texts are a phishing scam https://radar.offseq.com/threat/t-mobile-rewards-points-expiry-texts-are-a-phishing-scam-29ab887c51c32650 * [2h] Brevo supply chain attack hits 100k+ sites with Wordpress backdoors and Clickfix malware https://radar.offseq.com/threat/brevo-supply-chain-attack-hits-100k-sites-with-wordpress-backdoors-and-clickfix-malware-961727023928c9ac VULDB ----- * [1h] CVE-2026-93559 | Forget-C Jellyfish AI Short Drama Studio up to 0.3.2 FastAPI dependencies.py missing authentication (Issue 37) https://www.cve.org/CVERecord?id=CVE-2026-93559 * [2h] CVE-2026-83561 | Complianz GDPR/CCPA Cookie Consent Banner Plugin up to 7.5.4 on WordPress Elementor Cookie Blocker Regex cross site scripting (EUVD-2026-82792) https://www.cve.org/CVERecord?id=CVE-2026-83561 * [2h] CVE-2026-56597 | HCL BigFix Service Management 27 information disclosure https://www.cve.org/CVERecord?id=CVE-2026-56597 * [2h] CVE-2026-56590 | HCL BigFix Service Management 27 unrestricted upload https://www.cve.org/CVERecord?id=CVE-2026-56590 * [2h] CVE-2026-93534 | spatie Scotty up to 1.4.2 Self Update SelfUpdater.php SelfUpdater::update code download (Issue 21) https://www.cve.org/CVERecord?id=CVE-2026-93534 * [2h] CVE-2026-93533 | spatie Scotty up to 1.4.4 Doctor Command DoctorCommand.php checkRemoteTools host os command injection (Issue 20) https://www.cve.org/CVERecord?id=CVE-2026-93533 * [2h] CVE-2026-6205 | Synology DiskStation Manager up to 7.4-90074 Upload API unrestricted upload https://www.cve.org/CVERecord?id=CVE-2026-6205 * [2h] CVE-2026-56592 | HCL BigFix Service Management 27 Login Interface improper authentication https://www.cve.org/CVERecord?id=CVE-2026-56592 * [2h] CVE-2026-85410 | pixarlabs Master Addons for Elementor Plugin up to 3.2.2 on WordPress popup_id authorization (EUVD-2026-82793) https://www.cve.org/CVERecord?id=CVE-2026-85410 * [2h] CVE-2026-93532 | gedelumbung HospitalManagement up to c2d45543789a3887067d3915f69d44cfc2cf76a8 Password Change password.php simpan kode_user/username improper authentication https://www.cve.org/CVERecord?id=CVE-2026-93532 * [2h] CVE-2026-93531 | gedelumbung HospitalManagement up to c2d45543789a3887067d3915f69d44cfc2cf76a8 cross-site request forgery https://www.cve.org/CVERecord?id=CVE-2026-93531 * [2h] CVE-2026-4036 | Synology DiskStation Manager up to 7.2.0/7.2.2-72806-6/7.3.2-86009-1 Sharing API sql injection https://www.cve.org/CVERecord?id=CVE-2026-4036 * [2h] CVE-2026-40533 | Synology DiskStation Manager up to 7.2.0/7.2.2-72806-6/7.3.2-86009-1 Desktop API information disclosure (EUVD-2026-82794) https://www.cve.org/CVERecord?id=CVE-2026-40533 * [2h] CVE-2026-21848 | HCL BigFix Service Management 23 access control https://www.cve.org/CVERecord?id=CVE-2026-21848 * [2h] CVE-2026-40536 | Synology DiskStation Manager up to 7.2.0/7.2.2-72806-6/7.3.2-86009-1 Audio API path traversal (EUVD-2026-82790) https://www.cve.org/CVERecord?id=CVE-2026-40536 * [2h] CVE-2026-40535 | Synology DiskStation Manager up to 7.2.0/7.2.2-72806-6/7.3.2-86009-1 Desktop API path traversal (EUVD-2026-82795) https://www.cve.org/CVERecord?id=CVE-2026-40535 * [2h] CVE-2026-40532 | Synology DiskStation Manager up to 7.2.0/7.2.2-72806-6/7.3.2-86009-1 Wallpaper Path information disclosure (EUVD-2026-82788) https://www.cve.org/CVERecord?id=CVE-2026-40532 * [2h] CVE-2026-40531 | Synology DiskStation Manager up to 7.2.0/7.2.2-72806-6/7.3.2-86009-1 File Operation integer overflow https://www.cve.org/CVERecord?id=CVE-2026-40531 * [2h] CVE-2026-13623 | Synology DiskStation Manager Theme API cross site scripting https://www.cve.org/CVERecord?id=CVE-2026-13623 * [2h] CVE-2025-13533 | wipeoutmedia CSS & JavaScript Toolbox Plugin up to 12.0.6 on WordPress Assignment Engine cross site scripting (EUVD-2025-210931) https://www.cve.org/CVERecord?id=CVE-2025-13533 * [2h] CVE-2026-13683 | Synology DiskStation Manager EventScheduler API sql injection https://www.cve.org/CVERecord?id=CVE-2026-13683 * [2h] CVE-2026-13684 | Synology DiskStation Manager up to 7.4-90074 SCGI encoding error https://www.cve.org/CVERecord?id=CVE-2026-13684 * [2h] CVE-2026-13639 | Synology DiskStation Manager up to 7.4-90074 Login Logic entropy https://www.cve.org/CVERecord?id=CVE-2026-13639 * [2h] CVE-2026-13673 | Synology DiskStation Manager up to 7.4-90074 LDAP API permission https://www.cve.org/CVERecord?id=CVE-2026-13673 * [2h] CVE-2026-13635 | Synology DiskStation Manager Auth API information disclosure https://www.cve.org/CVERecord?id=CVE-2026-13635