<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:dc="http://purl.org/dc/elements/1.1/">
  <channel>
    <title>DEV Community: Freedom Coder</title>
    <description>The latest articles on DEV Community by Freedom Coder (@freedom-coder).</description>
    <link>https://dev.to/freedom-coder</link>
    <image>
      <url>https://media2.dev.to/dynamic/image/width=90,height=90,fit=cover,gravity=auto,format=auto/https:%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Fuser%2Fprofile_image%2F3057520%2F80e0c6d9-1160-4c3a-9af3-cdf5c163c85b.png</url>
      <title>DEV Community: Freedom Coder</title>
      <link>https://dev.to/freedom-coder</link>
    </image>
    <atom:link rel="self" type="application/rss+xml" href="https://dev.to/feed/freedom-coder"/>
    <language>en</language>
    <item>
      <title>CVE-2026-72529: TrueConf Server Missing Authentication for Critical Function Vulnerability</title>
      <dc:creator>Freedom Coder</dc:creator>
      <pubDate>Thu, 20 Aug 2026 19:06:05 +0000</pubDate>
      <link>https://dev.to/freedom-coder/cve-2026-72529-trueconf-server-missing-authentication-for-critical-function-vulnerability-3dc9</link>
      <guid>https://dev.to/freedom-coder/cve-2026-72529-trueconf-server-missing-authentication-for-critical-function-vulnerability-3dc9</guid>
      <description>&lt;h3&gt;
  
  
  CVE ID
&lt;/h3&gt;

&lt;p&gt;CVE-2026-72529&lt;/p&gt;

&lt;h3&gt;
  
  
  Vulnerability Name
&lt;/h3&gt;

&lt;p&gt;TrueConf Server Missing Authentication for Critical Function Vulnerability&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;Project: &lt;strong&gt;TrueConf&lt;/strong&gt;
&lt;/li&gt;
&lt;li&gt;Product: &lt;strong&gt;Server&lt;/strong&gt;
&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;
  
  
  Date
&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;Date Added: 2026-08-20&lt;/li&gt;
&lt;li&gt;Due Date: 2026-08-23&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;
  
  
  Description
&lt;/h3&gt;

&lt;p&gt;TrueConf Server contains a missing authentication for critical function vulnerability which could allow a remote unauthorized attacker with network access via port 4307/TCP to execute an arbitrary script.&lt;/p&gt;

&lt;h3&gt;
  
  
  Known To Be Used in Ransomware Campaigns?
&lt;/h3&gt;

&lt;p&gt;Unknown&lt;/p&gt;

&lt;h3&gt;
  
  
  Action
&lt;/h3&gt;

&lt;p&gt;Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.&lt;/p&gt;

&lt;h3&gt;
  
  
  Additional Notes
&lt;/h3&gt;

&lt;p&gt;&lt;a href="https://trueconf.com/blog/news/security-fixes-updates-and-advisories" rel="noopener noreferrer"&gt;https://trueconf.com/blog/news/security-fixes-updates-and-advisories&lt;/a&gt; ; &lt;a href="https://ics-cert.kaspersky.com/advisories/2026/08/11/trueconf-server-missing-authentication-for-critical-function/" rel="noopener noreferrer"&gt;https://ics-cert.kaspersky.com/advisories/2026/08/11/trueconf-server-missing-authentication-for-critical-function/&lt;/a&gt; ; BOD 26-04: &lt;a href="https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk" rel="noopener noreferrer"&gt;https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk&lt;/a&gt; ; Forensics Triage Requirements: &lt;a href="https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk" rel="noopener noreferrer"&gt;https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk&lt;/a&gt; ; &lt;a href="https://nvd.nist.gov/vuln/detail/CVE-2026-72529" rel="noopener noreferrer"&gt;https://nvd.nist.gov/vuln/detail/CVE-2026-72529&lt;/a&gt;&lt;/p&gt;

&lt;h3&gt;
  
  
  Related Security News
&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;&lt;a href="https://www.scyscan.com/news/cisa-orders-feds-to-patch-actively-exploited-trueconf-server-flaws/" rel="noopener noreferrer"&gt;CISA orders feds to patch actively exploited TrueConf Server flaws&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;
  
  
  More CVEs Info
&lt;/h3&gt;

&lt;p&gt;&lt;a href="https://www.scyscan.com/cves/" rel="noopener noreferrer"&gt;Common Vulnerabilities &amp;amp; Exposures (CVE) List&lt;/a&gt;&lt;/p&gt;

</description>
      <category>trueconf</category>
      <category>server</category>
      <category>cybersecurity</category>
      <category>vulnerability</category>
    </item>
    <item>
      <title>CVE-2026-72530: TrueConf Server Code Injection Vulnerability</title>
      <dc:creator>Freedom Coder</dc:creator>
      <pubDate>Thu, 20 Aug 2026 19:01:04 +0000</pubDate>
      <link>https://dev.to/freedom-coder/cve-2026-72530-trueconf-server-code-injection-vulnerability-8f3</link>
      <guid>https://dev.to/freedom-coder/cve-2026-72530-trueconf-server-code-injection-vulnerability-8f3</guid>
      <description>&lt;h3&gt;
  
  
  CVE ID
&lt;/h3&gt;

&lt;p&gt;CVE-2026-72530&lt;/p&gt;

&lt;h3&gt;
  
  
  Vulnerability Name
&lt;/h3&gt;

&lt;p&gt;TrueConf Server Code Injection Vulnerability&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;Project: &lt;strong&gt;TrueConf&lt;/strong&gt;
&lt;/li&gt;
&lt;li&gt;Product: &lt;strong&gt;Server&lt;/strong&gt;
&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;
  
  
  Date
&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;Date Added: 2026-08-20&lt;/li&gt;
&lt;li&gt;Due Date: 2026-09-03&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;
  
  
  Description
&lt;/h3&gt;

&lt;p&gt;TrueConf Server contains a code injection vulnerability that could allow an unauthorized remote attacker with network access via port 4307/TCP to use a specially crafted script to break out of the isolated environment and execute arbitrary code on the host system.&lt;/p&gt;

&lt;h3&gt;
  
  
  Known To Be Used in Ransomware Campaigns?
&lt;/h3&gt;

&lt;p&gt;Unknown&lt;/p&gt;

&lt;h3&gt;
  
  
  Action
&lt;/h3&gt;

&lt;p&gt;Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.&lt;/p&gt;

&lt;h3&gt;
  
  
  Additional Notes
&lt;/h3&gt;

&lt;p&gt;&lt;a href="https://trueconf.com/blog/news/security-fixes-updates-and-advisories" rel="noopener noreferrer"&gt;https://trueconf.com/blog/news/security-fixes-updates-and-advisories&lt;/a&gt; ; &lt;a href="https://ics-cert.kaspersky.com/advisories/2026/08/11/trueconf-server-breakout-from-isolated-environment/" rel="noopener noreferrer"&gt;https://ics-cert.kaspersky.com/advisories/2026/08/11/trueconf-server-breakout-from-isolated-environment/&lt;/a&gt; ; BOD 26-04: &lt;a href="https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk" rel="noopener noreferrer"&gt;https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk&lt;/a&gt; ; Forensics Triage Requirements: &lt;a href="https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk" rel="noopener noreferrer"&gt;https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk&lt;/a&gt; ; &lt;a href="https://nvd.nist.gov/vuln/detail/CVE-2026-72530" rel="noopener noreferrer"&gt;https://nvd.nist.gov/vuln/detail/CVE-2026-72530&lt;/a&gt;&lt;/p&gt;

&lt;h3&gt;
  
  
  Related Security News
&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;&lt;a href="https://www.scyscan.com/news/cisa-orders-feds-to-patch-actively-exploited-trueconf-server-flaws/" rel="noopener noreferrer"&gt;CISA orders feds to patch actively exploited TrueConf Server flaws&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;
  
  
  More CVEs Info
&lt;/h3&gt;

&lt;p&gt;&lt;a href="https://www.scyscan.com/cves/" rel="noopener noreferrer"&gt;Common Vulnerabilities &amp;amp; Exposures (CVE) List&lt;/a&gt;&lt;/p&gt;

</description>
      <category>trueconf</category>
      <category>server</category>
      <category>cybersecurity</category>
      <category>vulnerability</category>
    </item>
    <item>
      <title>CVE-2026-64849: MLflow Server-Side Request Forgery Vulnerability</title>
      <dc:creator>Freedom Coder</dc:creator>
      <pubDate>Wed, 19 Aug 2026 22:01:04 +0000</pubDate>
      <link>https://dev.to/freedom-coder/cve-2026-64849-mlflow-server-side-request-forgery-vulnerability-4ken</link>
      <guid>https://dev.to/freedom-coder/cve-2026-64849-mlflow-server-side-request-forgery-vulnerability-4ken</guid>
      <description>&lt;h3&gt;
  
  
  CVE ID
&lt;/h3&gt;

&lt;p&gt;CVE-2026-64849&lt;/p&gt;

&lt;h3&gt;
  
  
  Vulnerability Name
&lt;/h3&gt;

&lt;p&gt;MLflow Server-Side Request Forgery Vulnerability&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;Project: &lt;strong&gt;MLflow&lt;/strong&gt;
&lt;/li&gt;
&lt;li&gt;Product: &lt;strong&gt;MLflow&lt;/strong&gt;
&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;
  
  
  Date
&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;Date Added: 2026-08-19&lt;/li&gt;
&lt;li&gt;Due Date: 2026-09-02&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;
  
  
  Description
&lt;/h3&gt;

&lt;p&gt;MLflow contains a server-side request forgery vulnerability that can allow attackers to reach internal or cloud metadata services and receive response_status and response_body.&lt;/p&gt;

&lt;h3&gt;
  
  
  Known To Be Used in Ransomware Campaigns?
&lt;/h3&gt;

&lt;p&gt;Unknown&lt;/p&gt;

&lt;h3&gt;
  
  
  Action
&lt;/h3&gt;

&lt;p&gt;Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.&lt;/p&gt;

&lt;h3&gt;
  
  
  Additional Notes
&lt;/h3&gt;

&lt;p&gt;&lt;a href="https://github.com/mlflow/mlflow/pull/24258" rel="noopener noreferrer"&gt;https://github.com/mlflow/mlflow/pull/24258&lt;/a&gt; ; &lt;a href="https://github.com/mlflow/mlflow/issues/24179" rel="noopener noreferrer"&gt;https://github.com/mlflow/mlflow/issues/24179&lt;/a&gt; ; BOD 26-04: &lt;a href="https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk" rel="noopener noreferrer"&gt;https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk&lt;/a&gt; ; Forensics Triage Requirements: &lt;a href="https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk" rel="noopener noreferrer"&gt;https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk&lt;/a&gt; ; &lt;a href="https://nvd.nist.gov/vuln/detail/CVE-2026-64849" rel="noopener noreferrer"&gt;https://nvd.nist.gov/vuln/detail/CVE-2026-64849&lt;/a&gt;&lt;/p&gt;

&lt;h3&gt;
  
  
  Related Security News
&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;&lt;a href="https://www.scyscan.com/news/cisa-warns-of-hackers-exploiting-critical-mlflow-vulnerability/" rel="noopener noreferrer"&gt;CISA warns of hackers exploiting critical MLflow vulnerability&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;
  
  
  More CVEs Info
&lt;/h3&gt;

&lt;p&gt;&lt;a href="https://www.scyscan.com/cves/" rel="noopener noreferrer"&gt;Common Vulnerabilities &amp;amp; Exposures (CVE) List&lt;/a&gt;&lt;/p&gt;

</description>
      <category>mlflow</category>
      <category>cybersecurity</category>
      <category>vulnerability</category>
    </item>
    <item>
      <title>CVE-2021-33045: Dahua IP Camera Authentication Bypass Vulnerability</title>
      <dc:creator>Freedom Coder</dc:creator>
      <pubDate>Wed, 19 Aug 2026 17:37:56 +0000</pubDate>
      <link>https://dev.to/freedom-coder/cve-2021-33045-dahua-ip-camera-authentication-bypass-vulnerability-2fpl</link>
      <guid>https://dev.to/freedom-coder/cve-2021-33045-dahua-ip-camera-authentication-bypass-vulnerability-2fpl</guid>
      <description>&lt;h3&gt;
  
  
  CVE ID
&lt;/h3&gt;

&lt;p&gt;CVE-2021-33045&lt;/p&gt;

&lt;h3&gt;
  
  
  Vulnerability Name
&lt;/h3&gt;

&lt;p&gt;Dahua IP Camera Authentication Bypass Vulnerability&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;Project: &lt;strong&gt;Dahua&lt;/strong&gt;
&lt;/li&gt;
&lt;li&gt;Product: &lt;strong&gt;IP Camera Firmware&lt;/strong&gt;
&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;
  
  
  Date
&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;Date Added: 2024-08-21&lt;/li&gt;
&lt;li&gt;Due Date: 2024-09-11&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;
  
  
  Description
&lt;/h3&gt;

&lt;p&gt;Dahua IP cameras and related products contain an authentication bypass vulnerability when the loopback device is specified by the client during authentication.&lt;/p&gt;

&lt;h3&gt;
  
  
  Known To Be Used in Ransomware Campaigns?
&lt;/h3&gt;

&lt;p&gt;Unknown&lt;/p&gt;

&lt;h3&gt;
  
  
  Action
&lt;/h3&gt;

&lt;p&gt;Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.&lt;/p&gt;

&lt;h3&gt;
  
  
  Additional Notes
&lt;/h3&gt;

&lt;p&gt;&lt;a href="https://www.dahuasecurity.com/aboutUs/trustedCenter/details/582" rel="noopener noreferrer"&gt;https://www.dahuasecurity.com/aboutUs/trustedCenter/details/582&lt;/a&gt;; &lt;a href="https://nvd.nist.gov/vuln/detail/CVE-2021-33045" rel="noopener noreferrer"&gt;https://nvd.nist.gov/vuln/detail/CVE-2021-33045&lt;/a&gt;&lt;/p&gt;

&lt;h3&gt;
  
  
  Related Security News
&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;&lt;a href="https://www.scyscan.com/news/hackers-compromise-14500-dahua-web-cameras-in-35-day-campaign/" rel="noopener noreferrer"&gt;Hackers compromise 14,500 Dahua web cameras in 35-day campaign&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://www.scyscan.com/news/hackers-compromised-14500-dahua-devices-using-credential-attacks-auth-bypasses-and-p2p/" rel="noopener noreferrer"&gt;Hackers Compromised 14,500+ Dahua Devices Using Credential Attacks, Auth Bypasses, and P2P&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://www.scyscan.com/news/cisa-urges-federal-agencies-to-patch-versa-director-vulnerability-by-september/" rel="noopener noreferrer"&gt;CISA Urges Federal Agencies to Patch Versa Director Vulnerability by September&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;
  
  
  More CVEs Info
&lt;/h3&gt;

&lt;p&gt;&lt;a href="https://www.scyscan.com/cves/" rel="noopener noreferrer"&gt;Common Vulnerabilities &amp;amp; Exposures (CVE) List&lt;/a&gt;&lt;/p&gt;

</description>
      <category>dahua</category>
      <category>ipcamerafirmware</category>
      <category>cybersecurity</category>
      <category>vulnerability</category>
    </item>
    <item>
      <title>CVE-2021-27101: Accellion FTA SQL Injection Vulnerability</title>
      <dc:creator>Freedom Coder</dc:creator>
      <pubDate>Wed, 19 Aug 2026 17:32:19 +0000</pubDate>
      <link>https://dev.to/freedom-coder/cve-2021-27101-accellion-fta-sql-injection-vulnerability-2k96</link>
      <guid>https://dev.to/freedom-coder/cve-2021-27101-accellion-fta-sql-injection-vulnerability-2k96</guid>
      <description>&lt;h3&gt;
  
  
  CVE ID
&lt;/h3&gt;

&lt;p&gt;CVE-2021-27101&lt;/p&gt;

&lt;h3&gt;
  
  
  Vulnerability Name
&lt;/h3&gt;

&lt;p&gt;Accellion FTA SQL Injection Vulnerability&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;Project: &lt;strong&gt;Accellion&lt;/strong&gt;
&lt;/li&gt;
&lt;li&gt;Product: &lt;strong&gt;FTA&lt;/strong&gt;
&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;
  
  
  Date
&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;Date Added: 2021-11-03&lt;/li&gt;
&lt;li&gt;Due Date: 2021-11-17&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;
  
  
  Description
&lt;/h3&gt;

&lt;p&gt;Accellion FTA contains a SQL injection vulnerability exploited via a crafted host header in a request to document_root.html.&lt;/p&gt;

&lt;h3&gt;
  
  
  Known To Be Used in Ransomware Campaigns?
&lt;/h3&gt;

&lt;p&gt;Known&lt;/p&gt;

&lt;h3&gt;
  
  
  Action
&lt;/h3&gt;

&lt;p&gt;Apply updates per vendor instructions.&lt;/p&gt;

&lt;h3&gt;
  
  
  Additional Notes
&lt;/h3&gt;

&lt;p&gt;&lt;a href="https://nvd.nist.gov/vuln/detail/CVE-2021-27101" rel="noopener noreferrer"&gt;https://nvd.nist.gov/vuln/detail/CVE-2021-27101&lt;/a&gt;&lt;/p&gt;

&lt;h3&gt;
  
  
  Related Security News
&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;&lt;a href="https://www.scyscan.com/news/clop-linked-windchill-web-shell-decrypts-credentials-and-maps-engineering-data/" rel="noopener noreferrer"&gt;Clop-Linked Windchill Web Shell Decrypts Credentials and Maps Engineering Data&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;
  
  
  More CVEs Info
&lt;/h3&gt;

&lt;p&gt;&lt;a href="https://www.scyscan.com/cves/" rel="noopener noreferrer"&gt;Common Vulnerabilities &amp;amp; Exposures (CVE) List&lt;/a&gt;&lt;/p&gt;

</description>
      <category>accellion</category>
      <category>fta</category>
      <category>cybersecurity</category>
      <category>vulnerability</category>
    </item>
    <item>
      <title>CVE-2026-65400: Apple macOS Improper Authentication Vulnerability</title>
      <dc:creator>Freedom Coder</dc:creator>
      <pubDate>Tue, 18 Aug 2026 19:08:37 +0000</pubDate>
      <link>https://dev.to/freedom-coder/cve-2026-65400-apple-macos-improper-authentication-vulnerability-4ll6</link>
      <guid>https://dev.to/freedom-coder/cve-2026-65400-apple-macos-improper-authentication-vulnerability-4ll6</guid>
      <description>&lt;h3&gt;
  
  
  CVE ID
&lt;/h3&gt;

&lt;p&gt;CVE-2026-65400&lt;/p&gt;

&lt;h3&gt;
  
  
  Vulnerability Name
&lt;/h3&gt;

&lt;p&gt;Apple macOS Improper Authentication Vulnerability&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;Project: &lt;strong&gt;Apple&lt;/strong&gt;
&lt;/li&gt;
&lt;li&gt;Product: &lt;strong&gt;macOS&lt;/strong&gt;
&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;
  
  
  Date
&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;Date Added: 2026-08-18&lt;/li&gt;
&lt;li&gt;Due Date: 2026-08-21&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;
  
  
  Description
&lt;/h3&gt;

&lt;p&gt;Apple macOS contains an improper authentication vulnerability that could allow an attacker on the network to authenticate to Screen Sharing without valid credentials.&lt;/p&gt;

&lt;h3&gt;
  
  
  Known To Be Used in Ransomware Campaigns?
&lt;/h3&gt;

&lt;p&gt;Unknown&lt;/p&gt;

&lt;h3&gt;
  
  
  Action
&lt;/h3&gt;

&lt;p&gt;Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.&lt;/p&gt;

&lt;h3&gt;
  
  
  Additional Notes
&lt;/h3&gt;

&lt;p&gt;&lt;a href="https://support.apple.com/en-us/148170" rel="noopener noreferrer"&gt;https://support.apple.com/en-us/148170&lt;/a&gt;; &lt;a href="https://support.apple.com/en-us/148171" rel="noopener noreferrer"&gt;https://support.apple.com/en-us/148171&lt;/a&gt;; &lt;a href="https://support.apple.com/en-us/148172" rel="noopener noreferrer"&gt;https://support.apple.com/en-us/148172&lt;/a&gt; ; BOD 26-04: &lt;a href="https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk" rel="noopener noreferrer"&gt;https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk&lt;/a&gt; ; Forensics Triage Requirements: &lt;a href="https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk" rel="noopener noreferrer"&gt;https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk&lt;/a&gt; ; &lt;a href="https://nvd.nist.gov/vuln/detail/CVE-2026-65400" rel="noopener noreferrer"&gt;https://nvd.nist.gov/vuln/detail/CVE-2026-65400&lt;/a&gt;&lt;/p&gt;

&lt;h3&gt;
  
  
  Related Security News
&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;&lt;a href="https://www.scyscan.com/news/critical-macos-sharepoint-vcenter-and-microsoft-ike-flaws-under-active-exploitation/" rel="noopener noreferrer"&gt;Critical macOS, SharePoint, vCenter, and Microsoft IKE Flaws Under Active Exploitation&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;
  
  
  More CVEs Info
&lt;/h3&gt;

&lt;p&gt;&lt;a href="https://www.scyscan.com/cves/" rel="noopener noreferrer"&gt;Common Vulnerabilities &amp;amp; Exposures (CVE) List&lt;/a&gt;&lt;/p&gt;

</description>
      <category>apple</category>
      <category>macos</category>
      <category>cybersecurity</category>
      <category>vulnerability</category>
    </item>
    <item>
      <title>CVE-2026-55040: Microsoft SharePoint Weak Authentication Vulnerability</title>
      <dc:creator>Freedom Coder</dc:creator>
      <pubDate>Tue, 18 Aug 2026 19:06:06 +0000</pubDate>
      <link>https://dev.to/freedom-coder/cve-2026-55040-microsoft-sharepoint-weak-authentication-vulnerability-2gk8</link>
      <guid>https://dev.to/freedom-coder/cve-2026-55040-microsoft-sharepoint-weak-authentication-vulnerability-2gk8</guid>
      <description>&lt;h3&gt;
  
  
  CVE ID
&lt;/h3&gt;

&lt;p&gt;CVE-2026-55040&lt;/p&gt;

&lt;h3&gt;
  
  
  Vulnerability Name
&lt;/h3&gt;

&lt;p&gt;Microsoft SharePoint Weak Authentication Vulnerability&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;Project: &lt;strong&gt;Microsoft&lt;/strong&gt;
&lt;/li&gt;
&lt;li&gt;Product: &lt;strong&gt;SharePoint&lt;/strong&gt;
&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;
  
  
  Date
&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;Date Added: 2026-08-18&lt;/li&gt;
&lt;li&gt;Due Date: 2026-08-21&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;
  
  
  Description
&lt;/h3&gt;

&lt;p&gt;Microsoft SharePoint contains a weak authentication vulnerability which allows an unauthorized attacker to bypass a security feature over a network.&lt;/p&gt;

&lt;h3&gt;
  
  
  Known To Be Used in Ransomware Campaigns?
&lt;/h3&gt;

&lt;p&gt;Unknown&lt;/p&gt;

&lt;h3&gt;
  
  
  Action
&lt;/h3&gt;

&lt;p&gt;Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.&lt;/p&gt;

&lt;h3&gt;
  
  
  Additional Notes
&lt;/h3&gt;

&lt;p&gt;&lt;a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-55040" rel="noopener noreferrer"&gt;https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-55040&lt;/a&gt; ; BOD 26-04: &lt;a href="https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk" rel="noopener noreferrer"&gt;https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk&lt;/a&gt; ; Forensics Triage Requirements: &lt;a href="https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk" rel="noopener noreferrer"&gt;https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk&lt;/a&gt; ; &lt;a href="https://nvd.nist.gov/vuln/detail/CVE-2026-55040" rel="noopener noreferrer"&gt;https://nvd.nist.gov/vuln/detail/CVE-2026-55040&lt;/a&gt;&lt;/p&gt;

&lt;h3&gt;
  
  
  Related Security News
&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;&lt;a href="https://www.scyscan.com/news/critical-macos-sharepoint-vcenter-and-microsoft-ike-flaws-under-active-exploitation/" rel="noopener noreferrer"&gt;Critical macOS, SharePoint, vCenter, and Microsoft IKE Flaws Under Active Exploitation&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;
  
  
  More CVEs Info
&lt;/h3&gt;

&lt;p&gt;&lt;a href="https://www.scyscan.com/cves/" rel="noopener noreferrer"&gt;Common Vulnerabilities &amp;amp; Exposures (CVE) List&lt;/a&gt;&lt;/p&gt;

</description>
      <category>microsoft</category>
      <category>sharepoint</category>
      <category>cybersecurity</category>
      <category>vulnerability</category>
    </item>
    <item>
      <title>CVE-2026-59310: Broadcom VMware vCenter Path Traversal Vulnerability</title>
      <dc:creator>Freedom Coder</dc:creator>
      <pubDate>Tue, 18 Aug 2026 19:03:35 +0000</pubDate>
      <link>https://dev.to/freedom-coder/cve-2026-59310-broadcom-vmware-vcenter-path-traversal-vulnerability-57ja</link>
      <guid>https://dev.to/freedom-coder/cve-2026-59310-broadcom-vmware-vcenter-path-traversal-vulnerability-57ja</guid>
      <description>&lt;h3&gt;
  
  
  CVE ID
&lt;/h3&gt;

&lt;p&gt;CVE-2026-59310&lt;/p&gt;

&lt;h3&gt;
  
  
  Vulnerability Name
&lt;/h3&gt;

&lt;p&gt;Broadcom VMware vCenter Path Traversal Vulnerability&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;Project: &lt;strong&gt;Broadcom&lt;/strong&gt;
&lt;/li&gt;
&lt;li&gt;Product: &lt;strong&gt;VMware vCenter&lt;/strong&gt;
&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;
  
  
  Date
&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;Date Added: 2026-08-18&lt;/li&gt;
&lt;li&gt;Due Date: 2026-08-21&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;
  
  
  Description
&lt;/h3&gt;

&lt;p&gt;Broadcom VMware vCenter contains a path traversal vulnerability which could allow a threat actor with network access to vCenter to execute arbitrary code.&lt;/p&gt;

&lt;h3&gt;
  
  
  Known To Be Used in Ransomware Campaigns?
&lt;/h3&gt;

&lt;p&gt;Unknown&lt;/p&gt;

&lt;h3&gt;
  
  
  Action
&lt;/h3&gt;

&lt;p&gt;Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.&lt;/p&gt;

&lt;h3&gt;
  
  
  Additional Notes
&lt;/h3&gt;

&lt;p&gt;&lt;a href="https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/38017" rel="noopener noreferrer"&gt;https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/38017&lt;/a&gt; ; BOD 26-04: &lt;a href="https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk" rel="noopener noreferrer"&gt;https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk&lt;/a&gt; ; Forensics Triage Requirements: &lt;a href="https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk" rel="noopener noreferrer"&gt;https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk&lt;/a&gt; ; &lt;a href="https://nvd.nist.gov/vuln/detail/CVE-2026-59310" rel="noopener noreferrer"&gt;https://nvd.nist.gov/vuln/detail/CVE-2026-59310&lt;/a&gt;&lt;/p&gt;

&lt;h3&gt;
  
  
  Related Security News
&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;&lt;a href="https://www.scyscan.com/news/critical-macos-sharepoint-vcenter-and-microsoft-ike-flaws-under-active-exploitation/" rel="noopener noreferrer"&gt;Critical macOS, SharePoint, vCenter, and Microsoft IKE Flaws Under Active Exploitation&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;
  
  
  More CVEs Info
&lt;/h3&gt;

&lt;p&gt;&lt;a href="https://www.scyscan.com/cves/" rel="noopener noreferrer"&gt;Common Vulnerabilities &amp;amp; Exposures (CVE) List&lt;/a&gt;&lt;/p&gt;

</description>
      <category>broadcom</category>
      <category>vmwarevcenter</category>
      <category>cybersecurity</category>
      <category>vulnerability</category>
    </item>
    <item>
      <title>CVE-2025-62593: Ray-Project Ray Code Injection Vulnerability</title>
      <dc:creator>Freedom Coder</dc:creator>
      <pubDate>Mon, 17 Aug 2026 19:01:03 +0000</pubDate>
      <link>https://dev.to/freedom-coder/cve-2025-62593-ray-project-ray-code-injection-vulnerability-p4b</link>
      <guid>https://dev.to/freedom-coder/cve-2025-62593-ray-project-ray-code-injection-vulnerability-p4b</guid>
      <description>&lt;h3&gt;
  
  
  CVE ID
&lt;/h3&gt;

&lt;p&gt;CVE-2025-62593&lt;/p&gt;

&lt;h3&gt;
  
  
  Vulnerability Name
&lt;/h3&gt;

&lt;p&gt;Ray-Project Ray Code Injection Vulnerability&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;Project: &lt;strong&gt;Ray-Project&lt;/strong&gt;
&lt;/li&gt;
&lt;li&gt;Product: &lt;strong&gt;Ray&lt;/strong&gt;
&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;
  
  
  Date
&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;Date Added: 2026-08-17&lt;/li&gt;
&lt;li&gt;Due Date: 2026-08-20&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;
  
  
  Description
&lt;/h3&gt;

&lt;p&gt;Ray-Project Ray contains a code injection vulnerability that could allow remote code execution. Developers using Ray as a development tool may be exposed to this vulnerability exploitable through Firefox and Safari.&lt;/p&gt;

&lt;h3&gt;
  
  
  Known To Be Used in Ransomware Campaigns?
&lt;/h3&gt;

&lt;p&gt;Unknown&lt;/p&gt;

&lt;h3&gt;
  
  
  Action
&lt;/h3&gt;

&lt;p&gt;Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.&lt;/p&gt;

&lt;h3&gt;
  
  
  Additional Notes
&lt;/h3&gt;

&lt;p&gt;&lt;a href="https://github.com/ray-project/ray/security/advisories/GHSA-q279-jhrf-cc6v" rel="noopener noreferrer"&gt;https://github.com/ray-project/ray/security/advisories/GHSA-q279-jhrf-cc6v&lt;/a&gt; ; &lt;a href="https://github.com/ray-project/ray/commit/70e7c72780bdec075dba6cad1afe0832772bfe09" rel="noopener noreferrer"&gt;https://github.com/ray-project/ray/commit/70e7c72780bdec075dba6cad1afe0832772bfe09&lt;/a&gt; ; BOD 26-04: &lt;a href="https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk" rel="noopener noreferrer"&gt;https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk&lt;/a&gt; ; Forensics Triage Requirements: &lt;a href="https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk" rel="noopener noreferrer"&gt;https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk&lt;/a&gt; ; &lt;a href="https://nvd.nist.gov/vuln/detail/CVE-2025-62593" rel="noopener noreferrer"&gt;https://nvd.nist.gov/vuln/detail/CVE-2025-62593&lt;/a&gt;&lt;/p&gt;

&lt;h3&gt;
  
  
  Related Security News
&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;&lt;a href="https://www.scyscan.com/news/cisa-flags-actively-exploited-ray-flaw-that-can-trigger-browser-based-rce/" rel="noopener noreferrer"&gt;CISA Flags Actively Exploited Ray Flaw That Can Trigger Browser-Based RCE&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;
  
  
  More CVEs Info
&lt;/h3&gt;

&lt;p&gt;&lt;a href="https://www.scyscan.com/cves/" rel="noopener noreferrer"&gt;Common Vulnerabilities &amp;amp; Exposures (CVE) List&lt;/a&gt;&lt;/p&gt;

</description>
      <category>rayproject</category>
      <category>ray</category>
      <category>cybersecurity</category>
      <category>vulnerability</category>
    </item>
    <item>
      <title>CVE-2026-72898: Metabase SQL Injection Vulnerability</title>
      <dc:creator>Freedom Coder</dc:creator>
      <pubDate>Fri, 14 Aug 2026 19:07:46 +0000</pubDate>
      <link>https://dev.to/freedom-coder/cve-2026-72898-metabase-sql-injection-vulnerability-50ge</link>
      <guid>https://dev.to/freedom-coder/cve-2026-72898-metabase-sql-injection-vulnerability-50ge</guid>
      <description>&lt;h3&gt;
  
  
  CVE ID
&lt;/h3&gt;

&lt;p&gt;CVE-2026-72898&lt;/p&gt;

&lt;h3&gt;
  
  
  Vulnerability Name
&lt;/h3&gt;

&lt;p&gt;Metabase SQL Injection Vulnerability&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;Project: &lt;strong&gt;Metabase&lt;/strong&gt;
&lt;/li&gt;
&lt;li&gt;Product: &lt;strong&gt;Metabase&lt;/strong&gt;
&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;
  
  
  Date
&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;Date Added: 2026-08-11&lt;/li&gt;
&lt;li&gt;Due Date: 2026-08-14&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;
  
  
  Description
&lt;/h3&gt;

&lt;p&gt;Metabase contains a SQL Injection vulnerability that allows an unauthenticated remote attacker to inject arbitrary SQL into the Metabase application database, which can give them administrator access to the instance. From there, the attacker could change the application configuration, steal stored credentials for the connected databases, read any data accessible through those connections, and export data.&lt;/p&gt;

&lt;h3&gt;
  
  
  Known To Be Used in Ransomware Campaigns?
&lt;/h3&gt;

&lt;p&gt;Unknown&lt;/p&gt;

&lt;h3&gt;
  
  
  Action
&lt;/h3&gt;

&lt;p&gt;Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.&lt;/p&gt;

&lt;h3&gt;
  
  
  Additional Notes
&lt;/h3&gt;

&lt;p&gt;&lt;a href="https://www.metabase.com/blog/security-update" rel="noopener noreferrer"&gt;https://www.metabase.com/blog/security-update&lt;/a&gt; ; &lt;a href="https://github.com/metabase/metabase/security/advisories/GHSA-vwf4-m7j8-wcjf" rel="noopener noreferrer"&gt;https://github.com/metabase/metabase/security/advisories/GHSA-vwf4-m7j8-wcjf&lt;/a&gt; ; BOD 26-04: &lt;a href="https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk" rel="noopener noreferrer"&gt;https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk&lt;/a&gt; ; Forensics Triage Requirements: &lt;a href="https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk" rel="noopener noreferrer"&gt;https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk&lt;/a&gt; ; &lt;a href="https://nvd.nist.gov/vuln/detail/CVE-2026-72898" rel="noopener noreferrer"&gt;https://nvd.nist.gov/vuln/detail/CVE-2026-72898&lt;/a&gt;&lt;/p&gt;

&lt;h3&gt;
  
  
  More CVEs Info
&lt;/h3&gt;

&lt;p&gt;&lt;a href="https://www.scyscan.com/cves/" rel="noopener noreferrer"&gt;Common Vulnerabilities &amp;amp; Exposures (CVE) List&lt;/a&gt;&lt;/p&gt;

</description>
      <category>metabase</category>
      <category>cybersecurity</category>
      <category>vulnerability</category>
    </item>
    <item>
      <title>CVE-2025-24472: Fortinet FortiOS and FortiProxy Authentication Bypass Vulnerability</title>
      <dc:creator>Freedom Coder</dc:creator>
      <pubDate>Tue, 11 Aug 2026 18:30:05 +0000</pubDate>
      <link>https://dev.to/freedom-coder/cve-2025-24472-fortinet-fortios-and-fortiproxy-authentication-bypass-vulnerability-3fa1</link>
      <guid>https://dev.to/freedom-coder/cve-2025-24472-fortinet-fortios-and-fortiproxy-authentication-bypass-vulnerability-3fa1</guid>
      <description>&lt;h3&gt;
  
  
  CVE ID
&lt;/h3&gt;

&lt;p&gt;CVE-2025-24472&lt;/p&gt;

&lt;h3&gt;
  
  
  Vulnerability Name
&lt;/h3&gt;

&lt;p&gt;Fortinet FortiOS and FortiProxy Authentication Bypass Vulnerability&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;Project: &lt;strong&gt;Fortinet&lt;/strong&gt;
&lt;/li&gt;
&lt;li&gt;Product: &lt;strong&gt;FortiOS and FortiProxy&lt;/strong&gt;
&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;
  
  
  Date
&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;Date Added: 2025-03-18&lt;/li&gt;
&lt;li&gt;Due Date: 2025-04-08&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;
  
  
  Description
&lt;/h3&gt;

&lt;p&gt;Fortinet FortiOS and FortiProxy contain an authentication bypass vulnerability that allows a remote attacker to gain super-admin privileges via crafted CSF proxy requests.&lt;/p&gt;

&lt;h3&gt;
  
  
  Known To Be Used in Ransomware Campaigns?
&lt;/h3&gt;

&lt;p&gt;Known&lt;/p&gt;

&lt;h3&gt;
  
  
  Action
&lt;/h3&gt;

&lt;p&gt;Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.&lt;/p&gt;

&lt;h3&gt;
  
  
  Additional Notes
&lt;/h3&gt;

&lt;p&gt;&lt;a href="https://fortiguard.fortinet.com/psirt/FG-IR-24-535" rel="noopener noreferrer"&gt;https://fortiguard.fortinet.com/psirt/FG-IR-24-535&lt;/a&gt; ; &lt;a href="https://nvd.nist.gov/vuln/detail/CVE-2025-24472" rel="noopener noreferrer"&gt;https://nvd.nist.gov/vuln/detail/CVE-2025-24472&lt;/a&gt;&lt;/p&gt;

&lt;h3&gt;
  
  
  Related Security News
&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;&lt;a href="https://www.scyscan.com/news/gunra-ransomware-exploits-fortinet-fortios-fortiproxy-flaws-to-breach-networks/" rel="noopener noreferrer"&gt;Gunra Ransomware Exploits Fortinet FortiOS, FortiProxy Flaws to Breach Networks&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://www.scyscan.com/news/us-and-south-korea-warn-of-gunra-ransomware-targeting-govt-agencies/" rel="noopener noreferrer"&gt;US and South Korea warn of Gunra ransomware targeting govt agencies&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://www.scyscan.com/news/gunra-ransomware-exploits-fortinet-and-schneider-electric-flaws-to-breach-networks/" rel="noopener noreferrer"&gt;Gunra Ransomware Exploits Fortinet and Schneider Electric Flaws to Breach Networks&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://www.scyscan.com/news/hackers-abuse-russian-bulletproof-host-proton66-for-global-attacks-and-malware-delivery/" rel="noopener noreferrer"&gt;Hackers Abuse Russian Bulletproof Host Proton66 for Global Attacks and Malware Delivery&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://www.scyscan.com/news/critical-fortiswitch-flaw-lets-hackers-change-admin-passwords-remotely/" rel="noopener noreferrer"&gt;Critical FortiSwitch flaw lets hackers change admin passwords remotely&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://www.scyscan.com/news/vanhelsing-raas-launch-3-victims-5k-entry-fee-multi-os-and-double-extortion-tactics/" rel="noopener noreferrer"&gt;VanHelsing RaaS Launch: 3 Victims, $5K Entry Fee, Multi-OS, and Double Extortion Tactics&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;
  
  
  More CVEs Info
&lt;/h3&gt;

&lt;p&gt;&lt;a href="https://www.scyscan.com/cves/" rel="noopener noreferrer"&gt;Common Vulnerabilities &amp;amp; Exposures (CVE) List&lt;/a&gt;&lt;/p&gt;

</description>
      <category>fortinet</category>
      <category>fortiosandfortiproxy</category>
      <category>cybersecurity</category>
      <category>vulnerability</category>
    </item>
    <item>
      <title>CVE-2023-43208: NextGen Healthcare Mirth Connect Deserialization of Untrusted Data Vulnerability</title>
      <dc:creator>Freedom Coder</dc:creator>
      <pubDate>Mon, 10 Aug 2026 19:35:39 +0000</pubDate>
      <link>https://dev.to/freedom-coder/cve-2023-43208-nextgen-healthcare-mirth-connect-deserialization-of-untrusted-data-vulnerability-3l8e</link>
      <guid>https://dev.to/freedom-coder/cve-2023-43208-nextgen-healthcare-mirth-connect-deserialization-of-untrusted-data-vulnerability-3l8e</guid>
      <description>&lt;h3&gt;
  
  
  CVE ID
&lt;/h3&gt;

&lt;p&gt;CVE-2023-43208&lt;/p&gt;

&lt;h3&gt;
  
  
  Vulnerability Name
&lt;/h3&gt;

&lt;p&gt;NextGen Healthcare Mirth Connect Deserialization of Untrusted Data Vulnerability&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;Project: &lt;strong&gt;NextGen Healthcare&lt;/strong&gt;
&lt;/li&gt;
&lt;li&gt;Product: &lt;strong&gt;Mirth Connect&lt;/strong&gt;
&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;
  
  
  Date
&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;Date Added: 2024-05-20&lt;/li&gt;
&lt;li&gt;Due Date: 2024-06-10&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;
  
  
  Description
&lt;/h3&gt;

&lt;p&gt;NextGen Healthcare Mirth Connect contains a deserialization of untrusted data vulnerability that allows for unauthenticated remote code execution via a specially crafted request.&lt;/p&gt;

&lt;h3&gt;
  
  
  Known To Be Used in Ransomware Campaigns?
&lt;/h3&gt;

&lt;p&gt;Known&lt;/p&gt;

&lt;h3&gt;
  
  
  Action
&lt;/h3&gt;

&lt;p&gt;Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.&lt;/p&gt;

&lt;h3&gt;
  
  
  Additional Notes
&lt;/h3&gt;

&lt;p&gt;This vulnerability affects a common open-source component, third-party library, or a protocol used by different products. Please check with specific vendors for information on patching status.   For more information, please see: &lt;a href="https://github.com/nextgenhealthcare/connect/wiki/4.4.1---What%27s-New" rel="noopener noreferrer"&gt;https://github.com/nextgenhealthcare/connect/wiki/4.4.1---What%27s-New&lt;/a&gt; ;  &lt;a href="https://nvd.nist.gov/vuln/detail/CVE-2023-43208" rel="noopener noreferrer"&gt;https://nvd.nist.gov/vuln/detail/CVE-2023-43208&lt;/a&gt;&lt;/p&gt;

&lt;h3&gt;
  
  
  Related Security News
&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;&lt;a href="https://www.scyscan.com/news/china-linked-hackers-deploy-new-stormencryptor-ransomware-likely-via-n-central-flaw/" rel="noopener noreferrer"&gt;China-Linked Hackers Deploy New StormEncryptor Ransomware, Likely via N-central Flaw&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://www.scyscan.com/news/hhs-pledges-50m-for-autonomous-vulnerability-management-solution-for-hospitals/" rel="noopener noreferrer"&gt;HHS pledges $50M for autonomous vulnerability management solution for hospitals&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;
  
  
  More CVEs Info
&lt;/h3&gt;

&lt;p&gt;&lt;a href="https://www.scyscan.com/cves/" rel="noopener noreferrer"&gt;Common Vulnerabilities &amp;amp; Exposures (CVE) List&lt;/a&gt;&lt;/p&gt;

</description>
      <category>nextgenhealthcare</category>
      <category>mirthconnect</category>
      <category>cybersecurity</category>
      <category>vulnerability</category>
    </item>
  </channel>
</rss>
