Skip to main content

Threat Intelligence Database

Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Package: pkg:generic/fastjson2

Threat Intelligence

Click on any threat for detailed analysis and mitigation recommendations

IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to a security bypass due to improper authentication controls. A local attacker could exploit this vulnerability to escalate privileges and gain unauthorized access to protected resources.

Join the discussion

IBM Langflow OSS 1.0.0 through 1.11.5 Langflow could allow an authenticated attacker to access sensitive files belonging to other users due to improper access control in the File/Read File component. When executing flows through the /api/v1/run/advanced/{flow_id} endpoint, the application allows component inputs to reference storage paths using arbitrary user or flow identifiers without verifying ownership. An attacker with low‑privileged authenticated access can supply a crafted file path pointing to another user’s storage namespace, causing the backend to read and return the contents of files uploaded by other users. This vulnerability bypasses intended authorization checks enforced by the file management API and may result in unauthorized disclosure of sensitive user data.

Join the discussion

IBM WebSphere Application Server versions 8.5 and 9.0 contain a vulnerability where an authenticated user with a low-privilege administrative role can modify security configurations. This improper privilege management could lead to denial of service but does not impact confidentiality or integrity. The vulnerability has a medium severity rating with a CVSS score of 6.3.

Join the discussion

CVE-2026-3096 is an improper input validation vulnerability in WSO2 API Control Plane web portals. It allows external links to be opened in a new browser tab while the originating window retains access to the new page under certain configurations. This can enable an attacker to manipulate the original trusted application window after a user clicks a malicious external link, potentially redirecting users to phishing sites or enabling unauthorized actions within the trusted site context. The vulnerability has a medium severity with a CVSS score of 4.7.

Join the discussion

Suricata versions from 8.0.0 up to but not including 8.0.5 contain a use-after-free vulnerability in the decompress transform pipeline when certain detection transforms are chained. This flaw can cause Suricata to crash during network traffic processing if a malicious rule chains 'gunzip' or 'zlib_deflate' with a max-size greater than 4096 after another transform. Version 8.0.5 includes a fix for this issue. A temporary workaround is to avoid such rule chains until the update is applied.

Join the discussion

The September 2026 cumulative updates for Windows Server 2019, 2022, and 2025 are causing Remote Desktop Services (RDS) failures. After installing these updates, RDS initially works but then starts failing after a few hours or after users log out, preventing new connections and causing existing sessions to hang. Some administrators report that the only way to restore functionality is a hard reset. Rolling back the updates restores RDS functionality but removes the security fixes. Microsoft has not yet confirmed the cause or provided a fix.

Join the discussion

CVE-2026-89089 is a SQL injection vulnerability in the JasperReports-based reporting feature of OpenNMS Meridian and Horizon. A low-privileged authenticated user can exploit this by supplying a crafted DATE_FORMAT parameter to certain default-enabled reports via the REST API, allowing arbitrary SQL execution. This can lead to unauthorized reading of sensitive database information such as provisioning credentials and SNMP community strings. The vulnerability affects specific versions of Meridian and Horizon and has a CVSS score of 6.5 (medium severity).

Join the discussion

Kevin Mandia, founder of Mandiant and a cybersecurity veteran with over 30 years of experience, has been appointed to Amazon's board of directors. His extensive background includes leadership roles in incident response, threat intelligence, and cybersecurity advisory committees. This appointment aims to strengthen Amazon's cybersecurity expertise at the board level as the company navigates evolving cyber risks, including those related to advances in artificial intelligence. There is no indication of a security vulnerability or threat associated with this news.

LowNews
Join the discussion

CVE-2026-76652 is an authenticated path traversal vulnerability in TP-Link TL-MR6400 v8 and Archer MR600 (v2, v3, v5) routers. It arises from insufficient validation of user-supplied file information in the file upload functionality. An authenticated attacker could upload crafted files that are written outside the intended directory. This could lead to overwriting or modifying files accessible to the affected service. There is no evidence of arbitrary code execution from this vulnerability. The CVSS 4.8 score indicates medium severity.

Join the discussion

CVE-2026-76653 is a medium severity vulnerability in TP-Link TL-MR6400 v8 and Archer MR600 (v2, v3, v5) devices. It involves missing authentication in VPN configuration management, allowing remote unauthenticated attackers to access and modify VPN configuration without valid credentials. This improper access control could lead to disclosure and unauthorized modification of VPN settings.

Join the discussion

Showing 1 to 10 of 129397 results

Filters:Package: pkg:generic/fastjson2
Page 1 of 12940
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses