<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:dc="http://purl.org/dc/elements/1.1/">
  <channel>
    <title>DEV Community: Freedom Coder</title>
    <description>The latest articles on DEV Community by Freedom Coder (@freedom-coder).</description>
    <link>https://dev.to/freedom-coder</link>
    <image>
      <url>https://media2.dev.to/dynamic/image/width=90,height=90,fit=cover,gravity=auto,format=auto/https:%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Fuser%2Fprofile_image%2F3057520%2F80e0c6d9-1160-4c3a-9af3-cdf5c163c85b.png</url>
      <title>DEV Community: Freedom Coder</title>
      <link>https://dev.to/freedom-coder</link>
    </image>
    <atom:link rel="self" type="application/rss+xml" href="https://dev.to/feed/freedom-coder"/>
    <language>en</language>
    <item>
      <title>CVE-2023-48788: Fortinet FortiClient EMS SQL Injection Vulnerability</title>
      <dc:creator>Freedom Coder</dc:creator>
      <pubDate>Fri, 19 Jun 2026 03:35:11 +0000</pubDate>
      <link>https://dev.to/freedom-coder/cve-2023-48788-fortinet-forticlient-ems-sql-injection-vulnerability-141f</link>
      <guid>https://dev.to/freedom-coder/cve-2023-48788-fortinet-forticlient-ems-sql-injection-vulnerability-141f</guid>
      <description>&lt;h3&gt;
  
  
  CVE ID
&lt;/h3&gt;

&lt;p&gt;CVE-2023-48788&lt;/p&gt;

&lt;h3&gt;
  
  
  Vulnerability Name
&lt;/h3&gt;

&lt;p&gt;Fortinet FortiClient EMS SQL Injection Vulnerability&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;Project: &lt;strong&gt;Fortinet&lt;/strong&gt;
&lt;/li&gt;
&lt;li&gt;Product: &lt;strong&gt;FortiClient EMS&lt;/strong&gt;
&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;
  
  
  Date
&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;Date Added: 2024-03-25&lt;/li&gt;
&lt;li&gt;Due Date: 2024-04-15&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;
  
  
  Description
&lt;/h3&gt;

&lt;p&gt;Fortinet FortiClient EMS contains a SQL injection vulnerability that allows an unauthenticated attacker to execute commands as SYSTEM via specifically crafted requests.&lt;/p&gt;

&lt;h3&gt;
  
  
  Known To Be Used in Ransomware Campaigns?
&lt;/h3&gt;

&lt;p&gt;Known&lt;/p&gt;

&lt;h3&gt;
  
  
  Action
&lt;/h3&gt;

&lt;p&gt;Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.&lt;/p&gt;

&lt;h3&gt;
  
  
  Additional Notes
&lt;/h3&gt;

&lt;p&gt;&lt;a href="https://www.fortiguard.com/psirt/FG-IR-24-007" rel="noopener noreferrer"&gt;https://www.fortiguard.com/psirt/FG-IR-24-007&lt;/a&gt;;  &lt;a href="https://nvd.nist.gov/vuln/detail/CVE-2023-48788" rel="noopener noreferrer"&gt;https://nvd.nist.gov/vuln/detail/CVE-2023-48788&lt;/a&gt;&lt;/p&gt;

&lt;h3&gt;
  
  
  Related Security News
&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;&lt;a href="https://www.scyscan.com/news/inc-ransomware-emerges-as-major-raas-threat-in-2026-with-830-victims-since-2023/" rel="noopener noreferrer"&gt;INC Ransomware Emerges as Major RaaS Threat in 2026 with 830+ Victims Since 2023&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://www.scyscan.com/news/badpilot-network-hacking-campaign-fuels-russian-sandworm-attacks/" rel="noopener noreferrer"&gt;BadPilot network hacking campaign fuels Russian SandWorm attacks&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://www.scyscan.com/news/microsoft-russias-sandworm-apt-exploits-edge-bugs-globally/" rel="noopener noreferrer"&gt;Microsoft: Russia's Sandworm APT Exploits Edge Bugs Globally&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://www.scyscan.com/news/microsoft-uncovers-sandworm-subgroups-global-cyber-attacks-spanning-15-countries/" rel="noopener noreferrer"&gt;Microsoft Uncovers Sandworm Subgroup's Global Cyber Attacks Spanning 15+ Countries&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://www.scyscan.com/news/chinese-hackers-use-ghostspider-malware-to-hack-telecoms-across-12-countries/" rel="noopener noreferrer"&gt;Chinese Hackers Use GHOSTSPIDER Malware to Hack Telecoms Across 12+ Countries&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://www.scyscan.com/news/salt-typhoon-hackers-backdoor-telcos-with-new-ghostspider-malware/" rel="noopener noreferrer"&gt;Salt Typhoon hackers backdoor telcos with new GhostSpider malware&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://www.scyscan.com/news/ransomware-gangs-use-lockbits-fame-to-intimidate-victims-in-latest-attacks/" rel="noopener noreferrer"&gt;Ransomware Gangs Use LockBit's Fame to Intimidate Victims in Latest Attacks&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://www.scyscan.com/news/ransomhub-ransomware-group-targets-210-victims-across-critical-sectors/" rel="noopener noreferrer"&gt;RansomHub Ransomware Group Targets 210 Victims Across Critical Sectors&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;
  
  
  More CVEs Info
&lt;/h3&gt;

&lt;p&gt;&lt;a href="https://www.scyscan.com/cves/" rel="noopener noreferrer"&gt;Common Vulnerabilities &amp;amp; Exposures (CVE) List&lt;/a&gt;&lt;/p&gt;

</description>
      <category>fortinet</category>
      <category>forticlientems</category>
      <category>cybersecurity</category>
      <category>vulnerability</category>
    </item>
    <item>
      <title>CVE-2026-20253: Splunk Enterprise Missing Authentication for Critical Function Vulnerability</title>
      <dc:creator>Freedom Coder</dc:creator>
      <pubDate>Thu, 18 Jun 2026 22:01:30 +0000</pubDate>
      <link>https://dev.to/freedom-coder/cve-2026-20253-splunk-enterprise-missing-authentication-for-critical-function-vulnerability-25f7</link>
      <guid>https://dev.to/freedom-coder/cve-2026-20253-splunk-enterprise-missing-authentication-for-critical-function-vulnerability-25f7</guid>
      <description>&lt;h3&gt;
  
  
  CVE ID
&lt;/h3&gt;

&lt;p&gt;CVE-2026-20253&lt;/p&gt;

&lt;h3&gt;
  
  
  Vulnerability Name
&lt;/h3&gt;

&lt;p&gt;Splunk Enterprise Missing Authentication for Critical Function Vulnerability&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;Project: &lt;strong&gt;Splunk&lt;/strong&gt;
&lt;/li&gt;
&lt;li&gt;Product: &lt;strong&gt;Enterprise&lt;/strong&gt;
&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;
  
  
  Date
&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;Date Added: 2026-06-18&lt;/li&gt;
&lt;li&gt;Due Date: 2026-06-21&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;
  
  
  Description
&lt;/h3&gt;

&lt;p&gt;Splunk Enterprise contains a missing authentication for critical function vulnerability which could allow an unauthenticated user to create or truncate arbitrary files through a PostgreSQL sidecar service endpoint.&lt;/p&gt;

&lt;h3&gt;
  
  
  Known To Be Used in Ransomware Campaigns?
&lt;/h3&gt;

&lt;p&gt;Unknown&lt;/p&gt;

&lt;h3&gt;
  
  
  Action
&lt;/h3&gt;

&lt;p&gt;Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.&lt;/p&gt;

&lt;h3&gt;
  
  
  Additional Notes
&lt;/h3&gt;

&lt;p&gt;&lt;a href="https://advisory.splunk.com/advisories/SVD-2026-0603" rel="noopener noreferrer"&gt;https://advisory.splunk.com/advisories/SVD-2026-0603&lt;/a&gt; ; BOD 26-04: &lt;a href="https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk" rel="noopener noreferrer"&gt;https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk&lt;/a&gt; ; Forensics Triage Requirements: &lt;a href="https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk" rel="noopener noreferrer"&gt;https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk&lt;/a&gt; ; &lt;a href="https://nvd.nist.gov/vuln/detail/CVE-2026-20253" rel="noopener noreferrer"&gt;https://nvd.nist.gov/vuln/detail/CVE-2026-20253&lt;/a&gt;&lt;/p&gt;

&lt;h3&gt;
  
  
  Related Security News
&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;&lt;a href="https://www.scyscan.com/news/cisa-splunk-enterprise-flaw-actively-exploited-patch-by-sunday/" rel="noopener noreferrer"&gt;CISA: Splunk Enterprise flaw actively exploited, patch by Sunday&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://www.scyscan.com/news/unauthenticated-rce-in-splunk-enterprise-under-active-attack-cve-2026-20253/" rel="noopener noreferrer"&gt;Unauthenticated RCE in Splunk Enterprise under active attack (CVE-2026-20253)&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;
  
  
  More CVEs Info
&lt;/h3&gt;

&lt;p&gt;&lt;a href="https://www.scyscan.com/cves/" rel="noopener noreferrer"&gt;Common Vulnerabilities &amp;amp; Exposures (CVE) List&lt;/a&gt;&lt;/p&gt;

</description>
      <category>splunk</category>
      <category>enterprise</category>
      <category>cybersecurity</category>
      <category>vulnerability</category>
    </item>
    <item>
      <title>CVE-2026-48907: Widget Factory Joomla Content Editor Improper Access Control Vulnerability</title>
      <dc:creator>Freedom Coder</dc:creator>
      <pubDate>Wed, 17 Jun 2026 19:01:35 +0000</pubDate>
      <link>https://dev.to/freedom-coder/cve-2026-48907-widget-factory-joomla-content-editor-improper-access-control-vulnerability-4dbf</link>
      <guid>https://dev.to/freedom-coder/cve-2026-48907-widget-factory-joomla-content-editor-improper-access-control-vulnerability-4dbf</guid>
      <description>&lt;h3&gt;
  
  
  CVE ID
&lt;/h3&gt;

&lt;p&gt;CVE-2026-48907&lt;/p&gt;

&lt;h3&gt;
  
  
  Vulnerability Name
&lt;/h3&gt;

&lt;p&gt;Widget Factory Joomla Content Editor Improper Access Control Vulnerability&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;Project: &lt;strong&gt;Widget Factory&lt;/strong&gt;
&lt;/li&gt;
&lt;li&gt;Product: *&lt;em&gt;Joomla Content Editor *&lt;/em&gt;
&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;
  
  
  Date
&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;Date Added: 2026-06-16&lt;/li&gt;
&lt;li&gt;Due Date: 2026-06-19&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;
  
  
  Description
&lt;/h3&gt;

&lt;p&gt;Widget Factory Joomla Content Editor contains an improper access control vulnerability which could allow for upload and execution of PHP code via the creation of new editor profiles for unauthenticated users. &lt;/p&gt;

&lt;h3&gt;
  
  
  Known To Be Used in Ransomware Campaigns?
&lt;/h3&gt;

&lt;p&gt;Unknown&lt;/p&gt;

&lt;h3&gt;
  
  
  Action
&lt;/h3&gt;

&lt;p&gt;Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.&lt;/p&gt;

&lt;h3&gt;
  
  
  Additional Notes
&lt;/h3&gt;

&lt;p&gt;&lt;a href="https://www.joomlacontenteditor.net/news/jce-security-update-and-a-free-patch-for-older-sites" rel="noopener noreferrer"&gt;https://www.joomlacontenteditor.net/news/jce-security-update-and-a-free-patch-for-older-sites&lt;/a&gt; ; &lt;a href="https://www.joomlacontenteditor.net/support/changelog/editor" rel="noopener noreferrer"&gt;https://www.joomlacontenteditor.net/support/changelog/editor&lt;/a&gt; ; BOD 26-04: &lt;a href="https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk" rel="noopener noreferrer"&gt;https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk&lt;/a&gt; ; Forensics Triage Requirements: &lt;a href="https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk" rel="noopener noreferrer"&gt;https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk&lt;/a&gt; ; &lt;a href="https://nvd.nist.gov/vuln/detail/CVE-2026-48907" rel="noopener noreferrer"&gt;https://nvd.nist.gov/vuln/detail/CVE-2026-48907&lt;/a&gt;&lt;/p&gt;

&lt;h3&gt;
  
  
  Related Security News
&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;&lt;a href="https://www.scyscan.com/news/cisa-warns-of-actively-exploited-joomla-jce-flaw-allowing-php-code-execution/" rel="noopener noreferrer"&gt;CISA Warns of Actively Exploited Joomla JCE Flaw Allowing PHP Code Execution&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://www.scyscan.com/news/cisa-orders-feds-to-patch-max-severity-joomla-plugin-flaw-by-friday/" rel="noopener noreferrer"&gt;CISA orders feds to patch max severity Joomla plugin flaw by Friday&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;
  
  
  More CVEs Info
&lt;/h3&gt;

&lt;p&gt;&lt;a href="https://www.scyscan.com/cves/" rel="noopener noreferrer"&gt;Common Vulnerabilities &amp;amp; Exposures (CVE) List&lt;/a&gt;&lt;/p&gt;

</description>
      <category>widgetfactory</category>
      <category>joomlacontenteditor</category>
      <category>cybersecurity</category>
      <category>vulnerability</category>
    </item>
    <item>
      <title>CVE-2026-20262: Cisco Catalyst SD-WAN Manager Directory or Path Traversal Vulnerability</title>
      <dc:creator>Freedom Coder</dc:creator>
      <pubDate>Tue, 16 Jun 2026 16:06:23 +0000</pubDate>
      <link>https://dev.to/freedom-coder/cve-2026-20262-cisco-catalyst-sd-wan-manager-directory-or-path-traversal-vulnerability-5hdp</link>
      <guid>https://dev.to/freedom-coder/cve-2026-20262-cisco-catalyst-sd-wan-manager-directory-or-path-traversal-vulnerability-5hdp</guid>
      <description>&lt;h3&gt;
  
  
  CVE ID
&lt;/h3&gt;

&lt;p&gt;CVE-2026-20262&lt;/p&gt;

&lt;h3&gt;
  
  
  Vulnerability Name
&lt;/h3&gt;

&lt;p&gt;Cisco Catalyst SD-WAN Manager Directory or Path Traversal Vulnerability&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;Project: &lt;strong&gt;Cisco&lt;/strong&gt;
&lt;/li&gt;
&lt;li&gt;Product: &lt;strong&gt;Catalyst SD-WAN Manager&lt;/strong&gt;
&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;
  
  
  Date
&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;Date Added: 2026-06-15&lt;/li&gt;
&lt;li&gt;Due Date: 2026-06-29&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;
  
  
  Description
&lt;/h3&gt;

&lt;p&gt;Cisco Catalyst SD-WAN Manager contains a directory or path traversal vulnerability that could allow an authenticated, remote attacker to create a file or overwrite any file on the filesystem of an affected system.&lt;/p&gt;

&lt;h3&gt;
  
  
  Known To Be Used in Ransomware Campaigns?
&lt;/h3&gt;

&lt;p&gt;Unknown&lt;/p&gt;

&lt;h3&gt;
  
  
  Action
&lt;/h3&gt;

&lt;p&gt;Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.&lt;/p&gt;

&lt;h3&gt;
  
  
  Additional Notes
&lt;/h3&gt;

&lt;p&gt;&lt;a href="https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sdwan-arbfw-c2rZvQ" rel="noopener noreferrer"&gt;https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sdwan-arbfw-c2rZvQ&lt;/a&gt; ; BOD 26-04: &lt;a href="https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk" rel="noopener noreferrer"&gt;https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk&lt;/a&gt; ; Forensics Triage Requirements: &lt;a href="https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk" rel="noopener noreferrer"&gt;https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk&lt;/a&gt; ; &lt;a href="https://nvd.nist.gov/vuln/detail/CVE-2026-20262" rel="noopener noreferrer"&gt;https://nvd.nist.gov/vuln/detail/CVE-2026-20262&lt;/a&gt;&lt;/p&gt;

&lt;h3&gt;
  
  
  Related Security News
&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;&lt;a href="https://www.scyscan.com/news/cisco-releases-security-updates-for-actively-exploited-sd-wan-manager-flaw/" rel="noopener noreferrer"&gt;Cisco Releases Security Updates for Actively Exploited SD-WAN Manager Flaw&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;
  
  
  More CVEs Info
&lt;/h3&gt;

&lt;p&gt;&lt;a href="https://www.scyscan.com/cves/" rel="noopener noreferrer"&gt;Common Vulnerabilities &amp;amp; Exposures (CVE) List&lt;/a&gt;&lt;/p&gt;

</description>
      <category>cisco</category>
      <category>catalystsdwanmanager</category>
      <category>cybersecurity</category>
      <category>vulnerability</category>
    </item>
    <item>
      <title>CVE-2026-54420: LiteSpeed cPanel Plugin UNIX Symbolic Link (Symlink) Following Vulnerability</title>
      <dc:creator>Freedom Coder</dc:creator>
      <pubDate>Tue, 16 Jun 2026 16:01:22 +0000</pubDate>
      <link>https://dev.to/freedom-coder/cve-2026-54420-litespeed-cpanel-plugin-unix-symbolic-link-symlink-following-vulnerability-372a</link>
      <guid>https://dev.to/freedom-coder/cve-2026-54420-litespeed-cpanel-plugin-unix-symbolic-link-symlink-following-vulnerability-372a</guid>
      <description>&lt;h3&gt;
  
  
  CVE ID
&lt;/h3&gt;

&lt;p&gt;CVE-2026-54420&lt;/p&gt;

&lt;h3&gt;
  
  
  Vulnerability Name
&lt;/h3&gt;

&lt;p&gt;LiteSpeed cPanel Plugin UNIX Symbolic Link (Symlink) Following Vulnerability&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;Project: &lt;strong&gt;LiteSpeed&lt;/strong&gt;
&lt;/li&gt;
&lt;li&gt;Product: &lt;strong&gt;cPanel Plugin&lt;/strong&gt;
&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;
  
  
  Date
&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;Date Added: 2026-06-15&lt;/li&gt;
&lt;li&gt;Due Date: 2026-06-18&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;
  
  
  Description
&lt;/h3&gt;

&lt;p&gt;LiteSpeed cPanel plugin contains a UNIX symbolic link (Symlink) following vulnerability that could allow a user with FTP or web shell access on a shared hosting server running CloudLinux/CageFS.&lt;/p&gt;

&lt;h3&gt;
  
  
  Known To Be Used in Ransomware Campaigns?
&lt;/h3&gt;

&lt;p&gt;Unknown&lt;/p&gt;

&lt;h3&gt;
  
  
  Action
&lt;/h3&gt;

&lt;p&gt;Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.&lt;/p&gt;

&lt;h3&gt;
  
  
  Additional Notes
&lt;/h3&gt;

&lt;p&gt;&lt;a href="https://blog.litespeedtech.com/2026/06/01/security-update-for-litespeed-cpanel-plugin-2/" rel="noopener noreferrer"&gt;https://blog.litespeedtech.com/2026/06/01/security-update-for-litespeed-cpanel-plugin-2/&lt;/a&gt; ; BOD 26-04: &lt;a href="https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk" rel="noopener noreferrer"&gt;https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk&lt;/a&gt; ; Forensics Triage Requirements: &lt;a href="https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk" rel="noopener noreferrer"&gt;https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk&lt;/a&gt; ; &lt;a href="https://nvd.nist.gov/vuln/detail/CVE-2026-54420" rel="noopener noreferrer"&gt;https://nvd.nist.gov/vuln/detail/CVE-2026-54420&lt;/a&gt;&lt;/p&gt;

&lt;h3&gt;
  
  
  Related Security News
&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;&lt;a href="https://www.scyscan.com/news/cisa-warns-of-another-cpanel-plugin-flaw-exploited-in-attacks/" rel="noopener noreferrer"&gt;CISA warns of another cPanel plugin flaw exploited in attacks&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://www.scyscan.com/news/cisa-flags-litespeed-cpanel-plugin-flaw-exploited-for-root-privilege-escalation/" rel="noopener noreferrer"&gt;CISA Flags LiteSpeed cPanel Plugin Flaw Exploited for Root Privilege Escalation&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;
  
  
  More CVEs Info
&lt;/h3&gt;

&lt;p&gt;&lt;a href="https://www.scyscan.com/cves/" rel="noopener noreferrer"&gt;Common Vulnerabilities &amp;amp; Exposures (CVE) List&lt;/a&gt;&lt;/p&gt;

</description>
      <category>litespeed</category>
      <category>cpanelplugin</category>
      <category>cybersecurity</category>
      <category>vulnerability</category>
    </item>
    <item>
      <title>CVE-2024-20399: Cisco NX-OS Command Injection Vulnerability</title>
      <dc:creator>Freedom Coder</dc:creator>
      <pubDate>Fri, 12 Jun 2026 20:35:04 +0000</pubDate>
      <link>https://dev.to/freedom-coder/cve-2024-20399-cisco-nx-os-command-injection-vulnerability-542e</link>
      <guid>https://dev.to/freedom-coder/cve-2024-20399-cisco-nx-os-command-injection-vulnerability-542e</guid>
      <description>&lt;h3&gt;
  
  
  CVE ID
&lt;/h3&gt;

&lt;p&gt;CVE-2024-20399&lt;/p&gt;

&lt;h3&gt;
  
  
  Vulnerability Name
&lt;/h3&gt;

&lt;p&gt;Cisco NX-OS Command Injection Vulnerability&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;Project: &lt;strong&gt;Cisco&lt;/strong&gt;
&lt;/li&gt;
&lt;li&gt;Product: &lt;strong&gt;NX-OS&lt;/strong&gt;
&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;
  
  
  Date
&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;Date Added: 2024-07-02&lt;/li&gt;
&lt;li&gt;Due Date: 2024-07-23&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;
  
  
  Description
&lt;/h3&gt;

&lt;p&gt;Cisco NX-OS contains a command injection vulnerability in the command line interface (CLI) that could allow an authenticated, local attacker to execute commands as root on the underlying operating system of an affected device.&lt;/p&gt;

&lt;h3&gt;
  
  
  Known To Be Used in Ransomware Campaigns?
&lt;/h3&gt;

&lt;p&gt;Unknown&lt;/p&gt;

&lt;h3&gt;
  
  
  Action
&lt;/h3&gt;

&lt;p&gt;Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.&lt;/p&gt;

&lt;h3&gt;
  
  
  Additional Notes
&lt;/h3&gt;

&lt;p&gt;&lt;a href="https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-nxos-cmd-injection-xD9OhyOP" rel="noopener noreferrer"&gt;https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-nxos-cmd-injection-xD9OhyOP&lt;/a&gt;;   &lt;a href="https://nvd.nist.gov/vuln/detail/CVE-2024-20399" rel="noopener noreferrer"&gt;https://nvd.nist.gov/vuln/detail/CVE-2024-20399&lt;/a&gt;&lt;/p&gt;

&lt;h3&gt;
  
  
  Related Security News
&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;&lt;a href="https://www.scyscan.com/news/china-linked-hackers-backdoored-linux-login-software-to-hide-for-nearly-a-decade/" rel="noopener noreferrer"&gt;China-Linked Hackers Backdoored Linux Login Software to Hide for Nearly a Decade&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://www.scyscan.com/news/cisco-bug-lets-hackers-run-commands-as-root-on-uwrb-access-points/" rel="noopener noreferrer"&gt;Cisco bug lets hackers run commands as root on UWRB access points&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://www.scyscan.com/news/cisco-warns-of-backdoor-admin-account-in-smart-licensing-utility/" rel="noopener noreferrer"&gt;Cisco warns of backdoor admin account in Smart Licensing Utility&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://www.scyscan.com/news/chinese-hackers-exploit-zero-day-cisco-switch-flaw-to-gain-system-control/" rel="noopener noreferrer"&gt;Chinese Hackers Exploit Zero-Day Cisco Switch Flaw to Gain System Control&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://www.scyscan.com/news/exploit-released-for-cisco-ssm-bug-allowing-admin-password-changes/" rel="noopener noreferrer"&gt;Exploit released for Cisco SSM bug allowing admin password changes&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://www.scyscan.com/news/cisco-ssm-on-prem-bug-lets-hackers-change-any-users-password/" rel="noopener noreferrer"&gt;Cisco SSM On-Prem bug lets hackers change any user's password&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://www.scyscan.com/news/cisa-urges-devs-to-weed-out-os-command-injection-vulnerabilities/" rel="noopener noreferrer"&gt;CISA urges devs to weed out OS command injection vulnerabilities&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://www.scyscan.com/news/chinese-hackers-exploiting-cisco-switches-zero-day-to-deliver-malware/" rel="noopener noreferrer"&gt;Chinese Hackers Exploiting Cisco Switches Zero-Day to Deliver Malware&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://www.scyscan.com/news/cisco-warns-of-nx-os-zero-day-exploited-to-deploy-custom-malware/" rel="noopener noreferrer"&gt;Cisco warns of NX-OS zero-day exploited to deploy custom malware&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;
  
  
  More CVEs Info
&lt;/h3&gt;

&lt;p&gt;&lt;a href="https://www.scyscan.com/cves/" rel="noopener noreferrer"&gt;Common Vulnerabilities &amp;amp; Exposures (CVE) List&lt;/a&gt;&lt;/p&gt;

</description>
      <category>cisco</category>
      <category>nxos</category>
      <category>cybersecurity</category>
      <category>vulnerability</category>
    </item>
    <item>
      <title>CVE-2026-10520: Ivanti Sentry OS Command Injection Vulnerability</title>
      <dc:creator>Freedom Coder</dc:creator>
      <pubDate>Fri, 12 Jun 2026 04:01:05 +0000</pubDate>
      <link>https://dev.to/freedom-coder/cve-2026-10520-ivanti-sentry-os-command-injection-vulnerability-325l</link>
      <guid>https://dev.to/freedom-coder/cve-2026-10520-ivanti-sentry-os-command-injection-vulnerability-325l</guid>
      <description>&lt;h3&gt;
  
  
  CVE ID
&lt;/h3&gt;

&lt;p&gt;CVE-2026-10520&lt;/p&gt;

&lt;h3&gt;
  
  
  Vulnerability Name
&lt;/h3&gt;

&lt;p&gt;Ivanti Sentry OS Command Injection Vulnerability&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;Project: &lt;strong&gt;Ivanti&lt;/strong&gt;
&lt;/li&gt;
&lt;li&gt;Product: &lt;strong&gt;Sentry&lt;/strong&gt;
&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;
  
  
  Date
&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;Date Added: 2026-06-11&lt;/li&gt;
&lt;li&gt;Due Date: 2026-06-14&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;
  
  
  Description
&lt;/h3&gt;

&lt;p&gt;Ivanti Sentry (formerly known as MobileIron Sentry) contains an OS command injection vulnerability which could allow a remote unauthenticated user to achieve root-level remote code execution. This vulnerability can be successfully exploited in cases where the Sentry appliance is in an unmanaged state with its endpoints externally reachable. The use of mTLS with EPMM or restricted HTTPS access through Neurons for MDM makes interfaces inaccessible to external actors.&lt;/p&gt;

&lt;h3&gt;
  
  
  Known To Be Used in Ransomware Campaigns?
&lt;/h3&gt;

&lt;p&gt;Unknown&lt;/p&gt;

&lt;h3&gt;
  
  
  Action
&lt;/h3&gt;

&lt;p&gt;Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.&lt;/p&gt;

&lt;h3&gt;
  
  
  Additional Notes
&lt;/h3&gt;

&lt;p&gt;&lt;a href="https://hub.ivanti.com/s/article/Security-Advisory-Ivanti-Sentry-CVE-2026-10520-CVE-2026-10523?language=en_US" rel="noopener noreferrer"&gt;https://hub.ivanti.com/s/article/Security-Advisory-Ivanti-Sentry-CVE-2026-10520-CVE-2026-10523?language=en_US&lt;/a&gt; ; BOD 26-04: &lt;a href="https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk" rel="noopener noreferrer"&gt;https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk&lt;/a&gt; ; Forensics Triage Requirements: &lt;a href="https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk" rel="noopener noreferrer"&gt;https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk&lt;/a&gt; ; &lt;a href="https://nvd.nist.gov/vuln/detail/CVE-2026-10520" rel="noopener noreferrer"&gt;https://nvd.nist.gov/vuln/detail/CVE-2026-10520&lt;/a&gt;&lt;/p&gt;

&lt;h3&gt;
  
  
  Related Security News
&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;&lt;a href="https://www.scyscan.com/news/cisa-orders-feds-to-patch-actively-exploited-ivanti-flaw-by-sunday/" rel="noopener noreferrer"&gt;CISA orders feds to patch actively exploited Ivanti flaw by Sunday&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://www.scyscan.com/news/max-severity-ivanti-sentry-vulnerability-now-exploited-in-attacks/" rel="noopener noreferrer"&gt;Max severity Ivanti Sentry vulnerability now exploited in attacks&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;
  
  
  More CVEs Info
&lt;/h3&gt;

&lt;p&gt;&lt;a href="https://www.scyscan.com/cves/" rel="noopener noreferrer"&gt;Common Vulnerabilities &amp;amp; Exposures (CVE) List&lt;/a&gt;&lt;/p&gt;

</description>
      <category>ivanti</category>
      <category>sentry</category>
      <category>cybersecurity</category>
      <category>vulnerability</category>
    </item>
    <item>
      <title>CVE-2026-33017: Langflow Code Injection Vulnerability</title>
      <dc:creator>Freedom Coder</dc:creator>
      <pubDate>Wed, 10 Jun 2026 16:38:10 +0000</pubDate>
      <link>https://dev.to/freedom-coder/cve-2026-33017-langflow-code-injection-vulnerability-58pb</link>
      <guid>https://dev.to/freedom-coder/cve-2026-33017-langflow-code-injection-vulnerability-58pb</guid>
      <description>&lt;h3&gt;
  
  
  CVE ID
&lt;/h3&gt;

&lt;p&gt;CVE-2026-33017&lt;/p&gt;

&lt;h3&gt;
  
  
  Vulnerability Name
&lt;/h3&gt;

&lt;p&gt;Langflow Code Injection Vulnerability&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;Project: &lt;strong&gt;Langflow&lt;/strong&gt;
&lt;/li&gt;
&lt;li&gt;Product: &lt;strong&gt;Langflow&lt;/strong&gt;
&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;
  
  
  Date
&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;Date Added: 2026-03-25&lt;/li&gt;
&lt;li&gt;Due Date: 2026-04-08&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;
  
  
  Description
&lt;/h3&gt;

&lt;p&gt;Langflow contains a code injection vulnerability that could allow building public flows without requiring authentication.&lt;/p&gt;

&lt;h3&gt;
  
  
  Known To Be Used in Ransomware Campaigns?
&lt;/h3&gt;

&lt;p&gt;Unknown&lt;/p&gt;

&lt;h3&gt;
  
  
  Action
&lt;/h3&gt;

&lt;p&gt;Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.&lt;/p&gt;

&lt;h3&gt;
  
  
  Additional Notes
&lt;/h3&gt;

&lt;p&gt;&lt;a href="https://github.com/langflow-ai/langflow/security/advisories/GHSA-vwmf-pq79-vjvx" rel="noopener noreferrer"&gt;https://github.com/langflow-ai/langflow/security/advisories/GHSA-vwmf-pq79-vjvx&lt;/a&gt; ; &lt;a href="https://nvd.nist.gov/vuln/detail/CVE-2026-33017" rel="noopener noreferrer"&gt;https://nvd.nist.gov/vuln/detail/CVE-2026-33017&lt;/a&gt;&lt;/p&gt;

&lt;h3&gt;
  
  
  Related Security News
&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;&lt;a href="https://www.scyscan.com/news/langflow-vulnerability-cve-2026-5027-exploited-for-unauthenticated-rce/" rel="noopener noreferrer"&gt;Langflow Vulnerability CVE-2026-5027 Exploited for Unauthenticated RCE&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://www.scyscan.com/news/path-traversal-flaw-in-ai-dev-platform-langflow-exploited-in-attacks/" rel="noopener noreferrer"&gt;Path traversal flaw in AI dev platform Langflow exploited in attacks&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://www.scyscan.com/news/unpatched-langflow-flaw-cve-2026-5027-exploited-for-unauthenticated-rce/" rel="noopener noreferrer"&gt;Unpatched Langflow Flaw CVE-2026-5027 Exploited for Unauthenticated RCE&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://www.scyscan.com/news/cisa-sounds-alarm-on-langflow-rce-trivy-supply-chain-compromise-after-rapid-exploitation/" rel="noopener noreferrer"&gt;CISA sounds alarm on Langflow RCE, Trivy supply chain compromise after rapid exploitation&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://www.scyscan.com/news/langchain-langgraph-flaws-expose-files-secrets-databases-in-widely-used-ai-frameworks/" rel="noopener noreferrer"&gt;LangChain, LangGraph Flaws Expose Files, Secrets, Databases in Widely Used AI Frameworks&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://www.scyscan.com/news/cisa-new-langflow-flaw-actively-exploited-to-hijack-ai-workflows/" rel="noopener noreferrer"&gt;CISA: New Langflow flaw actively exploited to hijack AI workflows&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;
  
  
  More CVEs Info
&lt;/h3&gt;

&lt;p&gt;&lt;a href="https://www.scyscan.com/cves/" rel="noopener noreferrer"&gt;Common Vulnerabilities &amp;amp; Exposures (CVE) List&lt;/a&gt;&lt;/p&gt;

</description>
      <category>langflow</category>
      <category>cybersecurity</category>
      <category>vulnerability</category>
    </item>
    <item>
      <title>CVE-2026-50751: Check Point Security Gateway Improper Authentication Vulnerability</title>
      <dc:creator>Freedom Coder</dc:creator>
      <pubDate>Tue, 09 Jun 2026 19:08:38 +0000</pubDate>
      <link>https://dev.to/freedom-coder/cve-2026-50751-check-point-security-gateway-improper-authentication-vulnerability-3ig6</link>
      <guid>https://dev.to/freedom-coder/cve-2026-50751-check-point-security-gateway-improper-authentication-vulnerability-3ig6</guid>
      <description>&lt;h3&gt;
  
  
  CVE ID
&lt;/h3&gt;

&lt;p&gt;CVE-2026-50751&lt;/p&gt;

&lt;h3&gt;
  
  
  Vulnerability Name
&lt;/h3&gt;

&lt;p&gt;Check Point Security Gateway Improper Authentication Vulnerability&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;Project: &lt;strong&gt;Check Point&lt;/strong&gt;
&lt;/li&gt;
&lt;li&gt;Product: &lt;strong&gt;Security Gateway&lt;/strong&gt;
&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;
  
  
  Date
&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;Date Added: 2026-06-08&lt;/li&gt;
&lt;li&gt;Due Date: 2026-06-11&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;
  
  
  Description
&lt;/h3&gt;

&lt;p&gt;Check Point Security Gateway contains an improper authentication vulnerability in IKEv1 key exchange that could allow an unauthenticated remote attacker to bypass user authentication and establish a remote access VPN connection without a valid user password.&lt;/p&gt;

&lt;h3&gt;
  
  
  Known To Be Used in Ransomware Campaigns?
&lt;/h3&gt;

&lt;p&gt;Known&lt;/p&gt;

&lt;h3&gt;
  
  
  Action
&lt;/h3&gt;

&lt;p&gt;Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.&lt;/p&gt;

&lt;h3&gt;
  
  
  Additional Notes
&lt;/h3&gt;

&lt;p&gt;&lt;a href="https://blog.checkpoint.com/security/check-point-releases-important-hotfix-for-vulnerabilities-in-deprecated-ikev1-vpn-protocol/" rel="noopener noreferrer"&gt;https://blog.checkpoint.com/security/check-point-releases-important-hotfix-for-vulnerabilities-in-deprecated-ikev1-vpn-protocol/&lt;/a&gt; ; &lt;a href="https://support.checkpoint.com/results/sk/sk185033?_gl=1*1wqeqhc*_gcl_au*MTI1MzE5MjI2LjE3ODA5MzQ1NTM" rel="noopener noreferrer"&gt;https://support.checkpoint.com/results/sk/sk185033?_gl=1*1wqeqhc*_gcl_au*MTI1MzE5MjI2LjE3ODA5MzQ1NTM&lt;/a&gt;. ; &lt;a href="https://nvd.nist.gov/vuln/detail/CVE-2026-50751" rel="noopener noreferrer"&gt;https://nvd.nist.gov/vuln/detail/CVE-2026-50751&lt;/a&gt;&lt;/p&gt;

&lt;h3&gt;
  
  
  Related Security News
&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;&lt;a href="https://www.scyscan.com/news/researchers-release-details-poc-for-exploited-check-point-vpn-flaw-cve-2026-50751/" rel="noopener noreferrer"&gt;Researchers release details, PoC for exploited Check Point VPN flaw (CVE-2026-50751)&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;
  
  
  More CVEs Info
&lt;/h3&gt;

&lt;p&gt;&lt;a href="https://www.scyscan.com/cves/" rel="noopener noreferrer"&gt;Common Vulnerabilities &amp;amp; Exposures (CVE) List&lt;/a&gt;&lt;/p&gt;

</description>
      <category>checkpoint</category>
      <category>securitygateway</category>
      <category>cybersecurity</category>
      <category>vulnerability</category>
    </item>
    <item>
      <title>CVE-2026-20245: Cisco Catalyst SD-WAN Manager Improper Encoding or Escaping of Output Vulnerability</title>
      <dc:creator>Freedom Coder</dc:creator>
      <pubDate>Tue, 09 Jun 2026 19:06:07 +0000</pubDate>
      <link>https://dev.to/freedom-coder/cve-2026-20245-cisco-catalyst-sd-wan-manager-improper-encoding-or-escaping-of-output-vulnerability-3bfa</link>
      <guid>https://dev.to/freedom-coder/cve-2026-20245-cisco-catalyst-sd-wan-manager-improper-encoding-or-escaping-of-output-vulnerability-3bfa</guid>
      <description>&lt;h3&gt;
  
  
  CVE ID
&lt;/h3&gt;

&lt;p&gt;CVE-2026-20245&lt;/p&gt;

&lt;h3&gt;
  
  
  Vulnerability Name
&lt;/h3&gt;

&lt;p&gt;Cisco Catalyst SD-WAN Manager Improper Encoding or Escaping of Output Vulnerability&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;Project: &lt;strong&gt;Cisco&lt;/strong&gt;
&lt;/li&gt;
&lt;li&gt;Product: &lt;strong&gt;Catalyst SD-WAN Manager&lt;/strong&gt;
&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;
  
  
  Date
&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;Date Added: 2026-06-09&lt;/li&gt;
&lt;li&gt;Due Date: 2026-06-23&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;
  
  
  Description
&lt;/h3&gt;

&lt;p&gt;Cisco Catalyst SD-WAN Manager formerly SD-WAN vManage contains an improper encoding or escaping of output vulnerability. This vulnerability could allow an authenticated, local attacker to execute arbitrary commands as root by supplying a crafted file to the affected system.&lt;/p&gt;

&lt;h3&gt;
  
  
  Known To Be Used in Ransomware Campaigns?
&lt;/h3&gt;

&lt;p&gt;Unknown&lt;/p&gt;

&lt;h3&gt;
  
  
  Action
&lt;/h3&gt;

&lt;p&gt;Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.&lt;/p&gt;

&lt;h3&gt;
  
  
  Additional Notes
&lt;/h3&gt;

&lt;p&gt;&lt;a href="https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sdwan-privesc-4uxFrdzx" rel="noopener noreferrer"&gt;https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sdwan-privesc-4uxFrdzx&lt;/a&gt; ; &lt;a href="https://nvd.nist.gov/vuln/detail/CVE-2026-20245" rel="noopener noreferrer"&gt;https://nvd.nist.gov/vuln/detail/CVE-2026-20245&lt;/a&gt;&lt;/p&gt;

&lt;h3&gt;
  
  
  Related Security News
&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;&lt;a href="https://www.scyscan.com/news/cisco-releases-security-updates-for-actively-exploited-sd-wan-manager-flaw/" rel="noopener noreferrer"&gt;Cisco Releases Security Updates for Actively Exploited SD-WAN Manager Flaw&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://www.scyscan.com/news/cisco-fixes-sd-wan-vmanage-flaw-exploited-in-zero-day-attacks/" rel="noopener noreferrer"&gt;Cisco fixes SD-WAN vManage flaw exploited in zero-day attacks&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://www.scyscan.com/news/cisa-adds-cisco-chrome-and-arista-flaws-to-kev-catalog-amid-active-exploitation/" rel="noopener noreferrer"&gt;CISA Adds Cisco, Chrome, and Arista Flaws to KEV Catalog Amid Active Exploitation&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;
  
  
  More CVEs Info
&lt;/h3&gt;

&lt;p&gt;&lt;a href="https://www.scyscan.com/cves/" rel="noopener noreferrer"&gt;Common Vulnerabilities &amp;amp; Exposures (CVE) List&lt;/a&gt;&lt;/p&gt;

</description>
      <category>cisco</category>
      <category>catalystsdwanmanager</category>
      <category>cybersecurity</category>
      <category>vulnerability</category>
    </item>
    <item>
      <title>CVE-2026-7473: Arista Extensible Operating System Incomplete Comparison with Missing Factors Vulnerability</title>
      <dc:creator>Freedom Coder</dc:creator>
      <pubDate>Tue, 09 Jun 2026 19:03:36 +0000</pubDate>
      <link>https://dev.to/freedom-coder/cve-2026-7473-arista-extensible-operating-system-incomplete-comparison-with-missing-factors-54pe</link>
      <guid>https://dev.to/freedom-coder/cve-2026-7473-arista-extensible-operating-system-incomplete-comparison-with-missing-factors-54pe</guid>
      <description>&lt;h3&gt;
  
  
  CVE ID
&lt;/h3&gt;

&lt;p&gt;CVE-2026-7473&lt;/p&gt;

&lt;h3&gt;
  
  
  Vulnerability Name
&lt;/h3&gt;

&lt;p&gt;Arista Extensible Operating System Incomplete Comparison with Missing Factors Vulnerability&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;Project: &lt;strong&gt;Arista&lt;/strong&gt;
&lt;/li&gt;
&lt;li&gt;Product: &lt;strong&gt;Extensible Operating System&lt;/strong&gt;
&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;
  
  
  Date
&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;Date Added: 2026-06-09&lt;/li&gt;
&lt;li&gt;Due Date: 2026-06-23&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;
  
  
  Description
&lt;/h3&gt;

&lt;p&gt;Arista Extensible Operating System (EOS) contains an incomplete comparison with missing factors vulnerability when the switch incorrectly decapsulate and forwards other unexpected tunneled packet with a destination IP matching its configured decapsulation IP.&lt;/p&gt;

&lt;h3&gt;
  
  
  Known To Be Used in Ransomware Campaigns?
&lt;/h3&gt;

&lt;p&gt;Unknown&lt;/p&gt;

&lt;h3&gt;
  
  
  Action
&lt;/h3&gt;

&lt;p&gt;Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.&lt;/p&gt;

&lt;h3&gt;
  
  
  Additional Notes
&lt;/h3&gt;

&lt;p&gt;&lt;a href="https://www.arista.com/en/support/advisories-notices/security-advisory/24005-security-advisory-0137" rel="noopener noreferrer"&gt;https://www.arista.com/en/support/advisories-notices/security-advisory/24005-security-advisory-0137&lt;/a&gt; ; &lt;a href="https://nvd.nist.gov/vuln/detail/CVE-2026-7473" rel="noopener noreferrer"&gt;https://nvd.nist.gov/vuln/detail/CVE-2026-7473&lt;/a&gt;&lt;/p&gt;

&lt;h3&gt;
  
  
  Related Security News
&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;&lt;a href="https://www.scyscan.com/news/cisa-adds-cisco-chrome-and-arista-flaws-to-kev-catalog-amid-active-exploitation/" rel="noopener noreferrer"&gt;CISA Adds Cisco, Chrome, and Arista Flaws to KEV Catalog Amid Active Exploitation&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;
  
  
  More CVEs Info
&lt;/h3&gt;

&lt;p&gt;&lt;a href="https://www.scyscan.com/cves/" rel="noopener noreferrer"&gt;Common Vulnerabilities &amp;amp; Exposures (CVE) List&lt;/a&gt;&lt;/p&gt;

</description>
      <category>arista</category>
      <category>extensibleoperatingsystem</category>
      <category>cybersecurity</category>
      <category>vulnerability</category>
    </item>
    <item>
      <title>CVE-2026-11645: Google Chromium V8 Out-of-Bounds Read and Write Vulnerability</title>
      <dc:creator>Freedom Coder</dc:creator>
      <pubDate>Tue, 09 Jun 2026 19:01:05 +0000</pubDate>
      <link>https://dev.to/freedom-coder/cve-2026-11645-google-chromium-v8-out-of-bounds-read-and-write-vulnerability-4k1m</link>
      <guid>https://dev.to/freedom-coder/cve-2026-11645-google-chromium-v8-out-of-bounds-read-and-write-vulnerability-4k1m</guid>
      <description>&lt;h3&gt;
  
  
  CVE ID
&lt;/h3&gt;

&lt;p&gt;CVE-2026-11645&lt;/p&gt;

&lt;h3&gt;
  
  
  Vulnerability Name
&lt;/h3&gt;

&lt;p&gt;Google Chromium V8 Out-of-Bounds Read and Write Vulnerability&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;Project: &lt;strong&gt;Google&lt;/strong&gt;
&lt;/li&gt;
&lt;li&gt;Product: &lt;strong&gt;Chromium V8&lt;/strong&gt;
&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;
  
  
  Date
&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;Date Added: 2026-06-09&lt;/li&gt;
&lt;li&gt;Due Date: 2026-06-23&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;
  
  
  Description
&lt;/h3&gt;

&lt;p&gt;Google Chromium V8 out-of-bounds read and write vulnerability that could allow a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.&lt;/p&gt;

&lt;h3&gt;
  
  
  Known To Be Used in Ransomware Campaigns?
&lt;/h3&gt;

&lt;p&gt;Unknown&lt;/p&gt;

&lt;h3&gt;
  
  
  Action
&lt;/h3&gt;

&lt;p&gt;Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.&lt;/p&gt;

&lt;h3&gt;
  
  
  Additional Notes
&lt;/h3&gt;

&lt;p&gt;&lt;a href="https://chromereleases.googleblog.com/2026/06/stable-channel-update-for-desktop_0153744567.html" rel="noopener noreferrer"&gt;https://chromereleases.googleblog.com/2026/06/stable-channel-update-for-desktop_0153744567.html&lt;/a&gt; ; &lt;a href="https://issues.chromium.org/issues/506689381" rel="noopener noreferrer"&gt;https://issues.chromium.org/issues/506689381&lt;/a&gt; ; &lt;a href="https://nvd.nist.gov/vuln/detail/CVE-2026-11645" rel="noopener noreferrer"&gt;https://nvd.nist.gov/vuln/detail/CVE-2026-11645&lt;/a&gt;&lt;/p&gt;

&lt;h3&gt;
  
  
  Related Security News
&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;&lt;a href="https://www.scyscan.com/news/cisa-adds-cisco-chrome-and-arista-flaws-to-kev-catalog-amid-active-exploitation/" rel="noopener noreferrer"&gt;CISA Adds Cisco, Chrome, and Arista Flaws to KEV Catalog Amid Active Exploitation&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;
  
  
  More CVEs Info
&lt;/h3&gt;

&lt;p&gt;&lt;a href="https://www.scyscan.com/cves/" rel="noopener noreferrer"&gt;Common Vulnerabilities &amp;amp; Exposures (CVE) List&lt;/a&gt;&lt;/p&gt;

</description>
      <category>google</category>
      <category>chromiumv8</category>
      <category>cybersecurity</category>
      <category>vulnerability</category>
    </item>
  </channel>
</rss>
