IntelFreed Cybersecurity Intelligence Weather Report

LATEST

Aggregated cybersecurity reporting, advisories and research. 1,456 matching records.
AUTO-POLL // 2026-10-10 02:00 UTC
CYBER INTEL TEMPERATURE
TODAY'S AGGREGATED INTELLIGENCE
WARM
COOL WARM ELEVATED HOT CRITICAL
P15 / P100
7-DAY C.I.T. REPORT
CYBER CONDITIONS // DAILY C.I.T. READINGS
TODAY → 6 DAYS AGO
TODAY
Oct 10

RANSOMWARE
P15
P15
WARM // 1 ARTICLE
FRI
Oct 9

RANSOMWARE
P4
P4
COOL // 67 ARTICLES
THU
Oct 8

RANSOMWARE
P3
P3
COOL // 62 ARTICLES
WED
Oct 7

RANSOMWARE
P5
P5
COOL // 86 ARTICLES
TUE
Oct 6

RANSOMWARE
P3
P3
COOL // 61 ARTICLES
MON
Oct 5

RANSOMWARE
P5
P5
COOL // 48 ARTICLES
SUN
Oct 4

RANSOMWARE
P10
P10
WARM // 11 ARTICLES
RESET
2026-09-16 16:00 UTC
Vendor Research

Cisco Identity Services Engine 802.1X Session Hijack and Information Disclosure Vulnerabilities

Cisco Security Advisories · indexed 2026-09-16 16:40 UTC

Multiple vulnerabilities in Cisco Identity Services Engine (ISE) could allow an unauthenticated, local attacker to either conduct an authentication bypass or disclose sensitive information. For more information about these vulnerabilities, see the Details section of this advisory. Cisco has released software updates that address these vulnerabilities. There are no workarounds that address these vulnerabilities. This advisory is available at the following link:https://sec.cloudapps.cisco.com/sec…

VulnerabilitiesCVE-2026-20071CVE-2026-20072
P15
2026-09-16 16:00 UTC
Vendor Research

Cisco ThousandEyes Virtual Appliance Authenticated Web Interface Command Injection Vulnerability

Cisco Security Advisories · indexed 2026-09-16 16:40 UTC

A vulnerability in the web-based management interface of Cisco ThousandEyes Virtual Appliance could allow an authenticated, remote attacker to inject arbitrary operating system commands. This vulnerability is due to improper validation of user-supplied input to the web-based management interface. An attacker could exploit this vulnerability by saving configuration details that contain malicious values. A successful exploit could allow the attacker to execute arbitrary operating system commands …

VulnerabilitiesCVE-2026-20350
P5
2026-09-16 16:00 UTC
Vendor Research

Cisco Secure Firewall Threat Defense Software Snort 2 SSL/TLS Denial of Service Vulnerability

Cisco Security Advisories · indexed 2026-09-16 16:40 UTC

A vulnerability in SSL/TLS certificate parsing in the Snort 2 Detection Engine of Cisco Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause the Snort 2 Detection Engine to restart. This vulnerability is due to incomplete validation of the SSL certificate. An attacker could exploit this vulnerability by sending a crafted SSL connection setup request to be parsed by Snort 2. A successful exploit could allow the attacker to cause the Snort 2 Detec…

Network SecurityVulnerabilitiesCVE-2026-20290
P5
2026-09-16 16:00 UTC
Vendor Research

Cisco Identity Services Engine Multiple Path Traversal Vulnerabilities

Cisco Security Advisories · indexed 2026-09-16 16:40 UTC

Multiple vulnerabilities in Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) could allow a remote attacker to conduct path traversal attacks on an affected device. For more information about these vulnerabilities, see the Details section of this advisory. Cisco has released software updates that address these vulnerabilities. There are no workarounds that address these vulnerabilities. This advisory is available at the following link:https://sec.cloudapps.…

VulnerabilitiesCVE-2026-76431CVE-2026-76432CVE-2026-76433CVE-2026-76434
P5
2026-09-16 16:00 UTC
Vendor Research

Cisco Secure Firewall Management Center Software sftunnel Root Arbitrary Code Execution Vulnerability

Cisco Security Advisories · indexed 2026-09-16 16:05 UTC

A vulnerability in the sftunnel inter-device communication protocol of Cisco Secure Firewall Management Center (FMC) Software could allow an authenticated, remote attacker to execute arbitrary commands as root. This vulnerability exists because a registered sftunnel peer has incorrect permissions to write an arbitrary file to any location on the device. An attacker could exploit this vulnerability by hijacking the sftunnel communication connection or being a valid registered sftunnel peer and s…

Network SecurityVulnerabilitiesCVE-2026-20324
P5
2026-09-16 16:00 UTC
Vendor Research

Cisco Secure Firewall Management Center Software Java Deserialization Remote Code Execution Vulnerability

Cisco Security Advisories · indexed 2026-09-16 16:05 UTC

A vulnerability in the External Database Access feature of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated, remote attacker to execute arbitrary commands as root on an affected device. This vulnerability is due to insecure deserialization of a user-supplied Java byte stream from a host that is configured in the external database access list. An attacker could exploit this vulnerability by sending a crafted, serialized Java byte stream to a specific TCP port…

Network SecurityVulnerabilitiesCVE-2026-20242
P20
2026-09-16 16:00 UTC
Vendor Research

Cisco Identity Services Engine Remote Code Execution Vulnerabilities

Cisco Security Advisories · indexed 2026-09-16 16:05 UTC

Multiple vulnerabilities in Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to execute arbitrary commands on the underlying operating system of an affected device. To exploit these vulnerabilities, the attacker must have valid administrative credentials. For more information about these vulnerabilities, see the Details section of this advisory. Cisco has released software updates that address these vulnerabilities. There are no workarounds that address these v…

VulnerabilitiesCVE-2026-20176CVE-2026-20211CVE-2026-20307
P20
2026-09-16 16:00 UTC
Vendor Research

Cisco Identity Services Engine Authenticated Remote Code Execution and API Vulnerabilities

Cisco Security Advisories · indexed 2026-09-16 16:05 UTC

Multiple vulnerabilities in Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to conduct SQL injections, modify data, or execute arbitrary commands on the underlying operating system on an affected device. For more information about these vulnerabilities, see the Details section of this advisory. Note: For CVE-2026-20282 and CVE-2026-20283, Cisco has assigned a Security Impact Rating (SIR) of High rather than Medium as the scores indicate. The reason is that it …

VulnerabilitiesCVE-2026-20282CVE-2026-20283CVE-2026-20284
P20
2026-09-16 16:00 UTC
Vendor Research

Cisco Identity Services Engine Vulnerabilities

Cisco Security Advisories · indexed 2026-09-16 16:05 UTC

Multiple vulnerabilities in Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) could allow a remote attacker to bypass authentication to the REST API, achieve remote code execution, perform SQL injection, and conduct XML External Entity injection attacks on an affected device. For more information about these vulnerabilities, see the Details section of this advisory. Cisco has released software updates that address these vulnerabilities. There are no workaro…

VulnerabilitiesCVE-2026-76423CVE-2026-76424CVE-2026-76425CVE-2026-76426CVE-2026-76427CVE-2026-76428
P20
2026-09-16 16:00 UTC
Vendor Research

Cisco Secure Firewall Management Center Software Vulnerabilities

Cisco Security Advisories · indexed 2026-09-16 16:05 UTC

Multiple vulnerabilities in Cisco Secure Firewall Management Center (FMC) Software could allow a remote attacker to gain root access, download sensitive files, perform a SQL injection attack, or cause a denial of service (DoS) condition. For more information about these vulnerabilities, see the Details section of this advisory. Cisco has released software updates that address these vulnerabilities. There are no workarounds that address these vulnerabilities. This advisory is available at the fo…

Network SecurityVulnerabilitiesCVE-2026-20340CVE-2026-20341CVE-2026-20342CVE-2026-20343CVE-2026-20344
P5
2026-09-16 16:00 UTC
Vendor Research

Cisco Identity Services Engine Hardening Release: September 2026

Cisco Security Advisories · indexed 2026-09-16 16:05 UTC

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) engineering teams have conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered vulnerabilities. These vulnerabilities were found during internal testing. One of them is known to be actively exploited. For more information, see Cisco I…

VulnerabilitiesCVE-2026-20130CVE-2026-20192CVE-2026-20194CVE-2026-20234CVE-2026-20237CVE-2026-20287
P40
2026-09-16 16:00 UTC
Vendor Research

Cisco Identity Services Engine Command Injection Vulnerabilities

Cisco Security Advisories · indexed 2026-09-16 16:05 UTC

Multiple vulnerabilities in Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) could allow an authenticated, remote attacker to perform command injection attacks on an affected device and execute arbitrary commands as the root user. To exploit these vulnerabilities, the attacker must have valid administrative credentials. For more information about these vulnerabilities, see the Details section of this advisory. Cisco has released software updates that addre…

VulnerabilitiesCVE-2026-20305CVE-2026-20306
P5
2026-09-16 16:00 UTC
Vendor Research

Cisco Identity Services Engine Authentication Bypass Vulnerability

Cisco Security Advisories · indexed 2026-09-16 16:05 UTC

A vulnerability in an API of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to bypass authentication. This vulnerability is due to insufficient authentication control on an API endpoint. An attacker could exploit this vulnerability by sending a crafted request to an affected API endpoint. A successful exploit could allow the attacker to gain unauthorized access to the affected device by bypassing the web-based management interface. Cisco has released softwa…

VulnerabilitiesCVE-2026-76460
P15
2026-09-16 16:00 UTC
Vendor Research

Cisco Secure Firewall Management Center Software Vulnerabilities

Cisco Security Advisories · indexed 2026-09-16 16:05 UTC

Multiple vulnerabilities in Cisco Secure Firewall Management Center (FMC) Software could allow a remote attacker to gain root access and perform session forgery or session impersonation. For more information about these vulnerabilities, see the Details section of this advisory. Cisco has released software updates that address these vulnerabilities. There are no workarounds that address these vulnerabilities. This advisory is available at the following link:https://sec.cloudapps.cisco.com/securi…

Network SecurityVulnerabilitiesCVE-2026-76412CVE-2026-76413CVE-2026-76420
P5
2026-09-16 16:00 UTC
Vendor Research

Cisco Nexus Dashboard Software Security Hardening Release: September 2026

Cisco Security Advisories · indexed 2026-09-16 16:05 UTC

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Nexus Dashboard engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered vulnerabilities. These vulnerabilities were found during internal testing and are not known to be actively exploited. To assist customers in patching and streamline the disclosure process, Cisco has grouped these issues by …

VulnerabilitiesCVE-2026-20322CVE-2026-20325CVE-2026-20326CVE-2026-20360CVE-2026-20361CVE-2026-76409
P30
2026-09-16 15:50 UTC
Security Journalism

Attackers Exploit Issabel Framework Flaw Enabling Unauthenticated OS Command Execution

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-16 16:25 UTC

A critical security flaw in Issabel Framework, a web-based framework for the open-source unified communications PBX software, has come under active exploitation. The vulnerability in question is CVE-2026-89026 (CVSS v3.1 score: 9.8/CVSS v4.0 score: 9.3), which can allow an unauthenticated remote attacker to execute arbitrary operating system (OS) commands by taking advantage of a hard-coded

VulnerabilitiesCVE-2026-89026
P5
2026-09-16 14:20 UTC
Vendor Research

ScadaLTS Multiple Vulnerabilities

Tenable Research Advisories · Joshua Martinelle · indexed 2026-09-16 15:00 UTC

ScadaLTS Multiple Vulnerabilities ScadaLTS is an open-source, web-based SCADA/HMI application. Version 2.8.1-release-candidate build 0 is affected by multiple vulnerabilities:CVE-2026-84858: Authenticated Remote Code Execution via Scripting Sandbox Bypass (AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)The DWR "DataSourceEditDwr" class exposes the "validateScript" method that compiles and executes attacker-supplied JavaScript via the Rhino scripting engine. There are no authorization checks on this method…

ICS / OTVulnerabilitiesCVE-2026-84858CVE-2026-84859CVE-2026-84860
P20
2026-09-16 13:43 UTC
Other

Google Patches Pixel Modem Zero-Day Exploited in Targeted Attacks

Security Affairs · Pierluigi Paganini · indexed 2026-09-16 14:15 UTC

Google has patched a high-severity zero-day in the Pixel cellular modem after finding evidence that the vulnerability was exploited in limited, targeted attacks. Google has released its September 2026 Pixel security update, addressing a large set of vulnerabilities, including a high-severity flaw, tracked as CVE-2026-58704 (CVSS score of 8.0), in the cellular modem that has […]

VulnerabilitiesCVE-2026-58704
P30
2026-09-16 11:15 UTC
Security Journalism

Google Patches Pixel Modem Flaw Amid Signs of Limited Targeted Exploitation

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-16 11:45 UTC

Google has disclosed that a high-severity security flaw in its Pixel Cellular Modem has come under exploitation in the wild. The vulnerability, tracked as CVE-2026-58704 (CVSS score: 8.0), is a privilege escalation flaw. "In Cellular Modem, there is a possible permission bypass due to a logic error in the code," according to a description of the bug in the NIST National Vulnerability Database

VulnerabilitiesCVE-2026-58704
P35
2026-09-16 11:15 UTC
Security Journalism

Threat Intelligence Alone Won't Close the Exploitation Gap

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-16 11:45 UTC

A leaked credential shows up in a criminal marketplace, or a vulnerability gets a disclosure advisory, and either one can be weaponized against a real target before most security teams have triaged the alert. Attackers are combining that kind of intelligence with AI-assisted exploitation to accelerate the path from exposure to breach faster than most security programs are built to react.

Threat IntelligenceVulnerabilities
P0
2026-09-16 11:11 UTC
Security Journalism

Hackuity Raises $19 Million for AI-Powered Vulnerability Management

Security Week · SecurityWeek News · indexed 2026-09-16 11:20 UTC

The company will use the new capital to expand its vulnerability operations platform and support international growth. The post Hackuity Raises $19 Million for AI-Powered Vulnerability Management appeared first on SecurityWeek.

Vulnerabilities
P0
2026-09-16 11:08 UTC
Security Journalism

Acronis cPanel Backup Plugin Vulnerability Exploited in Targeted Attacks

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-16 11:45 UTC

Acronis has warned that a high-severity security flaw in its Backup plugin for cPanel and Web Host Manager (WHM) deployments has been exploited in the wild. The vulnerability, tracked as CVE-2026-87886 (CVSS score: 7.8), is described as a case of local privilege escalation due to insecure file permissions. It affects the following versions - Acronis Backup plugin for cPanel & WHM (Linux

LinuxVulnerabilitiesCVE-2026-87886
P35
2026-09-16 05:48 UTC
Security Journalism

Attackers Exploit WooCommerce Wholesale Lead Capture Flaw to Plant PHP Web Shells

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-16 06:40 UTC

Threat actors are exploiting a critical security flaw in WooCommerce Wholesale Lead Capture, a premium WordPress plugin that has more than 6,000 active installs. "This vulnerability can be leveraged by unauthenticated attackers to upload arbitrary files, including PHP backdoors, and achieve remote code execution," Wordfence said. The WordPress security company said it has blocked over

MalwareThreat ActorsVulnerabilities
P15
2026-09-16 05:18 UTC
Security Journalism

Active Exploitation Attempts Target WSO2 API Manager JWT Bypass With Forged Admin Tokens

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-16 06:40 UTC

A critical security flaw in WSO2 API Manager has come under active exploitation in the wild, according to findings from watchTowr. The vulnerability, tracked as CVE-2026-5430 (CVSS score: 9.8/10.0), is a case of improper verification of a cryptographic signature that could result in account takeover. Hacktron Team has been credited with discovering and reporting the flaw. "JWT authentication

VulnerabilitiesCVE-2026-5430
P25
12 13 14 15 16