IntelFreed Cybersecurity Intelligence Weather Report

LATEST

Aggregated cybersecurity reporting, advisories and research. 1,388 matching records.
AUTO-POLL // 2026-10-05 23:35 UTC
CYBER INTEL TEMPERATURE
TODAY'S AGGREGATED INTELLIGENCE
COOL
COOL WARM ELEVATED HOT CRITICAL
P5 / P100
7-DAY C.I.T. REPORT
CYBER CONDITIONS // DAILY C.I.T. READINGS
TODAY → 6 DAYS AGO
TODAY
Oct 5

RANSOMWARE
P5
P5
COOL // 48 ARTICLES
SUN
Oct 4

RANSOMWARE
P10
P10
WARM // 11 ARTICLES
SAT
Oct 3

RANSOMWARE
P4
P4
COOL // 14 ARTICLES
FRI
Oct 2

RANSOMWARE
P7
P7
COOL // 46 ARTICLES
THU
Oct 1

RANSOMWARE
P8
P8
COOL // 63 ARTICLES
WED
Sep 30

RANSOMWARE
P10
P10
WARM // 59 ARTICLES
TUE
Sep 29

RANSOMWARE
P4
P4
COOL // 68 ARTICLES
RESET
2026-07-15 16:00 UTC
Vendor Research

Cisco RoomOS Security Hardening Release: July 2026

Cisco Security Advisories · indexed 2026-08-15 14:33 UTC

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco RoomOS engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple internally discovered vulnerabilities. These vulnerabilities were found during internal testing and are not known to be actively exploited. To assist customers in patching and to streamline the disclosure process, Cisco has grouped these issues by the…

VulnerabilitiesCVE-2026-20150CVE-2026-20153CVE-2026-20156CVE-2026-20157CVE-2026-20158CVE-2026-20187
P30
2026-07-15 16:00 UTC
Vendor Research

Cisco Identity Services Engine Path Traversal Vulnerability

Cisco Security Advisories · indexed 2026-08-15 14:33 UTC

A vulnerability in Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) could allow an authenticated, remote attacker to perform path traversal attacks on the underlying operating system to either read or delete arbitrary files. To exploit this vulnerability, the attacker must have valid administrative credentials. This vulnerability is due to improper validation of user-supplied input. An attacker could exploit this vulnerability by sending a crafted HTTP req…

VulnerabilitiesCVE-2026-20146
P5
2026-07-15 14:00 UTC
Vendor Research

The Risk of Exposed Cloud Functions and How to Harden

Google Threat Intelligence / Mandiant · Mandiant · indexed 2026-08-15 18:55 UTC

Written by: Corné de Jong Introduction Mandiant security assessments frequently identify publicly exposed serverless applications that lack authentication, often as a result of specific business requirements. Serverless deployments typically run custom-developed code that incorporates third-party packages, making them targets for a wide range of application-level attacks, including: Local and Remote File Inclusion (LFI/RFI) Command Injection Successful exploitation of these vulnerabilities can …

AI SecurityAppleCloud SecurityMalwareThreat ActorsVulnerabilities
P15
2026-07-15 13:14 UTC
Vendor Research

CVE-2026-15409, CVE-2026-15410: SonicWall SMA 1000 zero-day vulnerabilities exploited in the wild

Tenable Cyber Exposure Alerts · Scott Caveza · indexed 2026-08-15 18:55 UTC

SonicWall patched two recently exploited zero-day vulnerabilities in its SMA 1000 Series secure remote access appliances which may have been chained for unauthenticated remote code execution.Key takeawaysCVE-2026-15409 and CVE-2026-15410 are a pair of exploited vulnerabilities that may have been chained together to allow for code execution on SonicWall SMA1000 series appliances. Zero-day exploitation of these vulnerabilities has been observed and confirmed by SonicWall. Patches and indicators o…

Cloud SecurityNetwork SecurityRansomwareSecurity ResearchThreat ActorsThreat IntelligenceVulnerabilitiesCVE-2026-15409CVE-2026-15410
P100
2026-07-15 05:00 UTC
Other

ZDI-26-444: 7-Zip XZ Decompression Heap-based Buffer Overflow Remote Code Execution Vulnerability

Zero Day Initiative · indexed 2026-09-07 17:35 UTC

This vulnerability allows remote attackers to execute arbitrary code on affected installations of 7-Zip. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.0. The following CVEs are assigned: CVE-2026-14266.

VulnerabilitiesCVE-2026-14266
P20
2026-07-15 05:00 UTC
Other

ZDI-26-440: Fuji Electric Tellus pcid64 Driver Untrusted Pointer Dereference Denial of Service Vulnerability

Zero Day Initiative · indexed 2026-09-07 17:35 UTC

This vulnerability allows local attackers to create a denial-of-service condition on affected installations of Fuji Electric Tellus. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 5.5. The following CVEs are assigned: CVE-2026-8108.

VulnerabilitiesCVE-2026-8108
P5
2026-07-15 05:00 UTC
Other

ZDI-26-439: Fuji Electric Tellus pcid64 Driver Exposed Dangerous Method Local Privilege Escalation Vulnerability

Zero Day Initiative · indexed 2026-09-07 17:35 UTC

This vulnerability allows local attackers to escalate privileges on affected installations of Fuji Electric Tellus. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-8108.

VulnerabilitiesCVE-2026-8108
P15
2026-07-15 05:00 UTC
Other

ZDI-26-438: Rockwell Automation Arena Simulation DOE File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability

Zero Day Initiative · indexed 2026-09-07 17:35 UTC

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Rockwell Automation Arena Simulation. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-6071.

VulnerabilitiesCVE-2026-6071
P20
2026-07-15 05:00 UTC
Other

ZDI-26-437: (Pwn2Own) Autel MaxiCharger AC Elite Home WebSockets Integer Underflow Remote Code Execution Vulnerability

Zero Day Initiative · indexed 2026-09-07 17:35 UTC

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Autel MaxiCharger AC Elite Home EV chargers. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 8.1. The following CVEs are assigned: CVE-2026-13308.

VulnerabilitiesCVE-2026-13308
P20
2026-07-15 05:00 UTC
Other

ZDI-26-436: (Pwn2Own) Autel MaxiCharger AC Elite Home USB Heap-based Buffer Overflow Arbitrary Code Execution Vulnerability

Zero Day Initiative · indexed 2026-09-07 17:35 UTC

This vulnerability allows physically present attackers to execute arbitrary code on affected installations of Autel MaxiCharger AC Elite Home EV chargers. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 6.8. The following CVEs are assigned: CVE-2026-13307.

VulnerabilitiesCVE-2026-13307
P5
2026-07-15 05:00 UTC
Other

ZDI-26-435: (Pwn2Own) Autel MaxiCharger AC Elite Home NFC Stack-based Buffer Overflow Arbitrary Code Execution Vulnerability

Zero Day Initiative · indexed 2026-09-07 17:35 UTC

This vulnerability allows physically present attackers to execute arbitrary code on affected installations of Autel MaxiCharger AC Elite Home EV chargers. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 6.8. The following CVEs are assigned: CVE-2026-13309.

VulnerabilitiesCVE-2026-13309
P5
2026-07-15 05:00 UTC
Other

ZDI-26-434: (Pwn2Own) Autel MaxiCharger AC Elite Home USB Authentication Bypass Vulnerability

Zero Day Initiative · indexed 2026-09-07 17:35 UTC

This vulnerability allows physically present attackers to bypass authentication on affected installations of Autel MaxiCharger AC Elite Home EV chargers. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 4.3. The following CVEs are assigned: CVE-2026-13306.

VulnerabilitiesCVE-2026-13306
P15
2026-07-15 05:00 UTC
Other

ZDI-26-433: (Pwn2Own) Autel MaxiCharger AC Elite Home Software Update Improper Verification of Cryptographic Signature Arbitrary Code Execution Vulnerability

Zero Day Initiative · indexed 2026-09-07 17:35 UTC

This vulnerability allows physically present attackers to execute arbitrary code on affected installations of Autel MaxiCharger AC Elite Home EV chargers. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 6.4. The following CVEs are assigned: CVE-2026-13305.

VulnerabilitiesCVE-2026-13305
P5
2026-07-15 05:00 UTC
Other

ZDI-26-432: G DATA Total Security Backup Service Link Following Local Privilege Escalation Vulnerability

Zero Day Initiative · indexed 2026-09-07 17:35 UTC

This vulnerability allows local attackers to escalate privileges on affected installations of G DATA Total Security. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-13268.

VulnerabilitiesCVE-2026-13268
P15
2026-07-15 05:00 UTC
Other

ZDI-26-431: ASUS Business Manager Service Client-Side Authentication Local Privilege Escalation Vulnerability

Zero Day Initiative · indexed 2026-09-07 17:35 UTC

This vulnerability allows local attackers to escalate privileges on affected installations of ASUS Business Manager. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-8921.

VulnerabilitiesCVE-2026-8921
P15
2026-07-15 05:00 UTC
Other

ZDI-26-430: MSI Center NTIOLib_X64 Origin Validation Error Local Privilege Escalation Vulnerability

Zero Day Initiative · indexed 2026-09-07 17:35 UTC

This vulnerability allows local attackers to escalate privileges on affected installations of MSI Center. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-6102.

VulnerabilitiesCVE-2026-6102
P15
2026-07-15 05:00 UTC
Other

ZDI-26-429: NVIDIA NeMo Framework Deserialization of Untrusted Data Remote Code Execution Vulnerability

Zero Day Initiative · indexed 2026-09-07 17:35 UTC

This vulnerability allows remote attackers to execute arbitrary code on affected installations of NVIDIA NeMo Framework. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-24157.

VulnerabilitiesCVE-2026-24157
P20
2026-07-15 05:00 UTC
Other

ZDI-26-428: WatchGuard FireWare OS admd Stack-based Buffer Overflow Remote Code Execution Vulnerability

Zero Day Initiative · indexed 2026-09-07 17:35 UTC

This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of WatchGuard FireWare OS. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.5. The following CVEs are assigned: CVE-2026-8247.

VulnerabilitiesCVE-2026-8247
P20
2026-07-15 05:00 UTC
Other

ZDI-26-427: WatchGuard FireWare OS iked ike2_hmac Null Pointer Dereference Denial-of-Service Vulnerability

Zero Day Initiative · indexed 2026-09-07 17:35 UTC

This vulnerability allows remote attackers to create a denial-of-service condition on affected installations of WatchGuard FireWare OS. Authentication is not required to exploit this vulnerability, but only systems using VPN with IKEv2 are vulnerable. The ZDI has assigned a CVSS rating of 5.9. The following CVEs are assigned: CVE-2026-13084.

Network SecurityVulnerabilitiesCVE-2026-13084
P5
2026-07-15 05:00 UTC
Other

ZDI-26-425: OpenSSL OCSP Stapling Verification Double Free Remote Code Execution Vulnerability

Zero Day Initiative · indexed 2026-09-07 17:35 UTC

This vulnerability allows remote attackers to execute arbitrary code on affected installations of OpenSSL. User interaction is required to exploit this vulnerability in that the target must make a request to a malicious server. The ZDI has assigned a CVSS rating of 7.5. The following CVEs are assigned: CVE-2026-35188.

VulnerabilitiesCVE-2026-35188
P20
2026-07-15 05:00 UTC
Other

ZDI-26-424: Synology DiskStation DS925+ MailPlus Improper Restriction of Communication Channel to Intended Endpoints Vulnerability

Zero Day Initiative · indexed 2026-09-07 17:35 UTC

This vulnerability allows network-adjacent attackers to access the Redis instance on affected installations of Synology DiskStation DS925+ devices. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 4.3. The following CVEs are assigned: CVE-2026-13135.

VulnerabilitiesCVE-2026-13135
P5
2026-07-15 05:00 UTC
Other

ZDI-26-423: Synology DiskStation DS925+ MailPlus Redis Weak Cryptography for Passwords Remote Code Execution Vulnerability

Zero Day Initiative · indexed 2026-09-07 17:35 UTC

This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Synology DiskStation DS925+ devices. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 8.8. The following CVEs are assigned: CVE-2025-15660.

VulnerabilitiesCVE-2025-15660
P20
2026-07-15 05:00 UTC
Other

ZDI-26-422: Samsung rlottie Numeric Truncation Remote Code Execution Vulnerability

Zero Day Initiative · indexed 2026-09-07 17:35 UTC

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Samsung rlottie. Interaction with the rlottie library is required to exploit this vulnerability but attack vectors may vary depending on the implementation. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-15551.

VulnerabilitiesCVE-2026-15551
P20
2026-07-15 05:00 UTC
Other

ZDI-26-421: Cisco Identity Services Engine validFileNameOrPath Directory Traversal Information Disclosure Vulnerability

Zero Day Initiative · indexed 2026-09-07 17:35 UTC

This vulnerability allows remote attackers to disclose sensitive information on affected installations of Cisco Identity Services Engine. Authentication is required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 5.5. The following CVEs are assigned: CVE-2026-20146.

VulnerabilitiesCVE-2026-20146
P5
2026-07-15 05:00 UTC
Other

ZDI-26-420: Adobe Creative Cloud AGSService Incorrect Permission Assignment Local Privilege Escalation Vulnerability

Zero Day Initiative · indexed 2026-09-07 17:35 UTC

This vulnerability allows local attackers to escalate privileges on affected installations of Adobe Creative Cloud Desktop Application. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-48344.

VulnerabilitiesCVE-2026-48344
P15
2026-07-15 05:00 UTC
Other

ZDI-26-419: Adobe Creative Cloud AdobeUpdateService Uncontrolled Search Path Element Local Privilege Escalation Vulnerability

Zero Day Initiative · indexed 2026-09-07 17:35 UTC

This vulnerability allows local attackers to escalate privileges on affected installations of Adobe Creative Cloud. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.0. The following CVEs are assigned: CVE-2026-48272.

VulnerabilitiesCVE-2026-48272
P15
34 35 36 37 38