IntelFreed Cybersecurity Intelligence Weather Report

LATEST

Aggregated cybersecurity reporting, advisories and research. 1,373 matching records.
AUTO-POLL // 2026-10-04 09:50 UTC
CYBER INTEL TEMPERATURE
TODAY'S AGGREGATED INTELLIGENCE
COOL
COOL WARM ELEVATED HOT CRITICAL
P9 / P100
7-DAY C.I.T. REPORT
CYBER CONDITIONS // DAILY C.I.T. READINGS
TODAY → 6 DAYS AGO
TODAY
Oct 4

RANSOMWARE
P9
P9
COOL // 5 ARTICLES
SAT
Oct 3

RANSOMWARE
P4
P4
COOL // 14 ARTICLES
FRI
Oct 2

RANSOMWARE
P7
P7
COOL // 46 ARTICLES
THU
Oct 1

RANSOMWARE
P8
P8
COOL // 63 ARTICLES
WED
Sep 30

RANSOMWARE
P10
P10
WARM // 59 ARTICLES
TUE
Sep 29

RANSOMWARE
P4
P4
COOL // 68 ARTICLES
MON
Sep 28

RANSOMWARE
P7
P7
COOL // 52 ARTICLES
RESET
2026-09-23 08:33 UTC
Security Journalism

Arista Urges Immediate Patching of Exploited VCO Zero-Day

Security Week · Ionut Arghire · indexed 2026-09-23 08:50 UTC

Remote attackers could trigger the critical-severity flaw to access privileged internal functionality. The post Arista Urges Immediate Patching of Exploited VCO Zero-Day appeared first on SecurityWeek.

Vulnerabilities
P25
2026-09-23 08:29 UTC
Security Journalism

F5 Patches Critical BIG-IP APM Zero-Day Exploited for Unauthenticated RCE on OAuth Servers

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-23 08:45 UTC

Attackers are exploiting a critical flaw in F5 BIG-IP Access Policy Manager (APM) that lets them run code on a BIG-IP system without logging in, F5 says. The flaw, CVE-2026-94127, affects only systems in which APM serves as an OAuth authorization server, issuing access tokens to applications. F5 disclosed it in an advisory on September 22 and has released engineering hotfixes.

VulnerabilitiesCVE-2026-94127
P55
2026-09-23 08:29 UTC
Security Journalism

Chinese Hackers Exploit Chrome-Windows Zero-Day Chain to Deploy CLEANGULP Malware

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-23 08:45 UTC

A Chinese threat actor codenamed UTA0565 has been observed exploiting the recently disclosed Google Chrome-Microsoft Windows exploit chain as zero-days through fake websites. The attacks, detected on September 3 and 4, 2026, involved the chaining of two vulnerabilities in Chrome (CVE-2026-85046, CVE-2026-87491) and one impacting Windows Advanced Local Procedure Call (CVE-2026-85880) to break

MalwareMicrosoftThreat ActorsVulnerabilitiesCVE-2026-85046CVE-2026-85880CVE-2026-87491
P30
2026-09-23 07:36 UTC
Other

CVE-2026-87902: how close is your WordPress to remote code execution?

Security Affairs · Pierluigi Paganini · indexed 2026-09-23 07:50 UTC

WordPress 7.1.2 fixes an unauthenticated file inclusion bug active since version 4.7, patchable but exploitable into remote code execution. WordPress 7.1.2 shipped on September 22 address an unauthenticated local file inclusion, tracked as CVE-2026-87902 (CVSS score of 9.2), which stems of how the CMS resolves page templates, with a real path to remote code execution. […]

VulnerabilitiesCVE-2026-87902
P20
2026-09-23 07:34 UTC
Security Journalism

Critical F5 BIG-IP Vulnerability Exploited as Zero-Day

Security Week · Ionut Arghire · indexed 2026-09-23 07:50 UTC

Unauthenticated attackers could send malicious traffic to BIG-IP to achieve remote code execution. The post Critical F5 BIG-IP Vulnerability Exploited as Zero-Day appeared first on SecurityWeek.

Vulnerabilities
P40
2026-09-23 07:04 UTC
Security Journalism

Critical Next.js ImageResponse Flaw Can Lead to Server Code Execution via Crafted SVG Input

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-23 07:35 UTC

A new security vulnerability in Next.js could allow attackers to run code on a server via ImageResponse, the feature that generates Open Graph and other social preview images, Vercel said. The risk applies when an app puts values an attacker controls, such as text read from the request URL, into the image. Vercel, which develops Next.js, fixed the flaw on September 22 in version

Vulnerabilities
P0
2026-09-23 06:14 UTC
Security Journalism

Check Point Patches Exploited Management Server Zero-Day

Security Week · Ionut Arghire · indexed 2026-09-23 06:15 UTC

The critical-severity flaw could allow unauthenticated attackers to upload and execute arbitrary scripts. The post Check Point Patches Exploited Management Server Zero-Day appeared first on SecurityWeek.

Vulnerabilities
P25
2026-09-23 05:00 UTC
Other

ZDI-26-748: Luxion KeyShot BIP File Parsing Uncontrolled Search Path Element Remote Code Execution Vulnerability

Zero Day Initiative · indexed 2026-09-23 22:30 UTC

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Luxion KeyShot. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-92202.

VulnerabilitiesCVE-2026-92202
P20
2026-09-23 05:00 UTC
Other

ZDI-26-747: Wireshark RF4CE Packet Parsing Buffer Overflow Remote Code Execution Vulnerability

Zero Day Initiative · indexed 2026-09-23 22:30 UTC

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Wireshark. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-96417.

VulnerabilitiesCVE-2026-96417
P20
2026-09-23 05:00 UTC
Other

ZDI-26-746: Foxit PDF Reader Annotation Use-After-Free Remote Code Execution Vulnerability

Zero Day Initiative · indexed 2026-09-23 22:30 UTC

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-91818.

VulnerabilitiesCVE-2026-91818
P20
2026-09-23 05:00 UTC
Other

ZDI-26-745: Foxit PDF Reader AcroForm Out-of-Bounds Read Remote Code Execution Vulnerability

Zero Day Initiative · indexed 2026-09-23 22:30 UTC

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-91817.

VulnerabilitiesCVE-2026-91817
P20
2026-09-23 05:00 UTC
Other

ZDI-26-744: Foxit PDF Reader AcroForm Use-After-Free Remote Code Execution Vulnerability

Zero Day Initiative · indexed 2026-09-23 22:30 UTC

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-91816.

VulnerabilitiesCVE-2026-91816
P20
2026-09-23 05:00 UTC
Other

ZDI-26-743: Foxit PDF Reader JPEG2000 Parsing Memory Corruption Remote Code Execution Vulnerability

Zero Day Initiative · indexed 2026-09-23 22:30 UTC

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-91815.

VulnerabilitiesCVE-2026-91815
P20
2026-09-23 05:00 UTC
Other

ZDI-26-742: Foxit PDF Reader FoxitUpdater Race Condition Local Privilege Escalation Vulnerability

Zero Day Initiative · indexed 2026-09-23 22:30 UTC

This vulnerability allows local attackers to escalate privileges on affected installations of Foxit PDF Reader. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-91813.

VulnerabilitiesCVE-2026-91813
P15
2026-09-23 05:00 UTC
Other

ZDI-26-741: Foxit PDF Reader FoxitUpdater Improper Certificate Validation Local Privilege Escalation Vulnerability

Zero Day Initiative · indexed 2026-09-23 22:30 UTC

This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Foxit PDF Reader. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.1. The following CVEs are assigned: CVE-2026-91812.

VulnerabilitiesCVE-2026-91812
P15
2026-09-23 05:00 UTC
Other

ZDI-26-740: Foxit PDF Reader PRC Stream Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability

Zero Day Initiative · indexed 2026-09-23 22:30 UTC

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-91811.

VulnerabilitiesCVE-2026-91811
P20
2026-09-23 05:00 UTC
Other

ZDI-26-739: Foxit PDF Reader Doc Object Out-Of-Bounds Read Information Disclosure Vulnerability

Zero Day Initiative · indexed 2026-09-23 22:30 UTC

This vulnerability allows remote attackers to disclose sensitive information on affected installations of Foxit PDF Reader. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 3.3. The following CVEs are assigned: CVE-2026-91810.

VulnerabilitiesCVE-2026-91810
P5
2026-09-23 05:00 UTC
Other

ZDI-26-738: Foxit PDF Reader Annotation Use-After-Free Information Disclosure Vulnerability

Zero Day Initiative · indexed 2026-09-23 22:30 UTC

This vulnerability allows remote attackers to disclose sensitive information on affected installations of Foxit PDF Reader. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 3.3. The following CVEs are assigned: CVE-2026-91809.

VulnerabilitiesCVE-2026-91809
P5
2026-09-23 05:00 UTC
Other

ZDI-26-737: Foxit PDF Reader JPEG File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability

Zero Day Initiative · indexed 2026-09-23 22:30 UTC

This vulnerability allows remote attackers to disclose sensitive information on affected installations of Foxit PDF Reader. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 3.3. The following CVEs are assigned: CVE-2026-91808.

VulnerabilitiesCVE-2026-91808
P5
2026-09-23 05:00 UTC
Other

ZDI-26-736: Foxit PDF Reader PDF File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability

Zero Day Initiative · indexed 2026-09-23 22:30 UTC

This vulnerability allows remote attackers to disclose sensitive information on affected installations of Foxit PDF Reader. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 3.3. The following CVEs are assigned: CVE-2026-91807.

VulnerabilitiesCVE-2026-91807
P5
2026-09-23 05:00 UTC
Other

ZDI-26-735: Foxit PDF Reader Doc Object Use-After-Free Information Disclosure Vulnerability

Zero Day Initiative · indexed 2026-09-23 22:30 UTC

This vulnerability allows remote attackers to disclose sensitive information on affected installations of Foxit PDF Reader. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 3.3. The following CVEs are assigned: CVE-2026-91806.

VulnerabilitiesCVE-2026-91806
P5
2026-09-23 05:00 UTC
Other

ZDI-26-725: Foxit PDF Reader Doc Object Use-After-Free Information Disclosure Vulnerability

Zero Day Initiative · indexed 2026-09-23 22:10 UTC

This vulnerability allows remote attackers to disclose sensitive information on affected installations of Foxit PDF Reader. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 3.3. The following CVEs are assigned: CVE-2026-57256.

VulnerabilitiesCVE-2026-57256
P5
2026-09-23 05:00 UTC
Other

ZDI-26-724: Foxit PDF Reader Annotation Use-After-Free Remote Code Execution Vulnerability

Zero Day Initiative · indexed 2026-09-23 22:10 UTC

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-91792.

VulnerabilitiesCVE-2026-91792
P20
2026-09-23 05:00 UTC
Other

ZDI-26-723: Foxit PDF Reader Doc Object Use-After-Free Information Disclosure Vulnerability

Zero Day Initiative · indexed 2026-09-23 22:10 UTC

This vulnerability allows remote attackers to disclose sensitive information on affected installations of Foxit PDF Reader. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 3.3. The following CVEs are assigned: CVE-2026-91790.

VulnerabilitiesCVE-2026-91790
P5
2026-09-23 05:00 UTC
Other

ZDI-26-722: Foxit PDF Reader Annotation Use-After-Free Remote Code Execution Vulnerability

Zero Day Initiative · indexed 2026-09-23 22:10 UTC

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-91791.

VulnerabilitiesCVE-2026-91791
P20
2026-09-23 05:00 UTC
Other

ZDI-26-721: Foxit PDF Reader U3D File Parsing Integer Overflow Remote Code Execution Vulnerability

Zero Day Initiative · indexed 2026-09-23 22:10 UTC

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-91789.

VulnerabilitiesCVE-2026-91789
P20
2026-09-23 05:00 UTC
Other

ZDI-26-720: Foxit PDF Reader activeDocs Missing Authorization Information Disclosure Vulnerability

Zero Day Initiative · indexed 2026-09-23 22:10 UTC

This vulnerability allows remote attackers to disclose sensitive information on affected installations of Foxit PDF Reader. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 4.7. The following CVEs are assigned: CVE-2026-91788.

VulnerabilitiesCVE-2026-91788
P5
2026-09-23 05:00 UTC
Other

ZDI-26-734: Foxit PDF Reader RichMedia Annotation Directory Traversal Remote Code Execution Vulnerability

Zero Day Initiative · indexed 2026-09-23 22:10 UTC

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-91801.

VulnerabilitiesCVE-2026-91801
P20
2026-09-23 05:00 UTC
Other

ZDI-26-733: Foxit PDF Reader Portfolio Directory Traversal Remote Code Execution Vulnerability

Zero Day Initiative · indexed 2026-09-23 22:10 UTC

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-91797.

VulnerabilitiesCVE-2026-91797
P20
4 5 6 7 8