Threat Intelligence Database
Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threat Intelligence
Click on any threat for detailed analysis and mitigation recommendations
0 CVE-2026-89087 is a high-severity vulnerability in the OCaml cstruct package before version 6.3.0. It involves improper handling of indexes, categorized under CWE-573 (Improper Following of Specification by Caller). This flaw can lead to impacts on confidentiality, integrity, and availability. The vulnerability has a CVSS 3.1 base score of 7.3, indicating a significant risk if exploited. No explicit patch or remediation details are provided in the available data. Join the discussion | CVE Database V5 | 09/10/2026, 19:55:44 UTC Added: 09/10/2026, 20:02:25 UTC |
0 CVE-2026-89086 is a critical vulnerability in the OCaml jose package before version 0.11.0. The flaw involves improper verification of RSA cryptographic signatures, where the library only checks that PKCS #1 decoding succeeds but does not perform the necessary validation steps involving the public key. This can lead to acceptance of invalid signatures. Join the discussion | CVE Database V5 | 09/10/2026, 19:52:47 UTC Added: 09/10/2026, 20:02:25 UTC |
A missing authorization vulnerability in OpenNMS Horizon allows configuration changes without authentication. The Spring Security policy for the /api/v2 REST API defines authorization rules for every HTTP method except PATCH, so the shipped @PATCH configuration endpoints for event configuration and SNMP data collection (which enable and disable event definitions and data-collection sources) are reachable with no authorization enforced. An unauthenticated attacker able to reach the web UI can disable event definitions and SNMP data collection, suppressing event and alarm generation and stopping metric collection - silently degrading monitoring and detection - with the change persisted and reloaded into the running system. The solution is to upgrade to Horizon 36.0.4 or newer. Meridian and Horizon installation instructions state that they are intended for installation within an organization's private networks and should not be directly accessible from the Internet. Join the discussion | CVE Database V5 | 09/10/2026, 19:36:21 UTC Added: 09/10/2026, 19:47:27 UTC |
Surfshark VPN experienced a security breach due to a misconfigured internal test server exposed to the internet. Hackers accessed this server and a separate proxy server used for content-accessibility optimization. The breach exposed service configurations, build-related credentials, system binaries, and code history, but did not affect production infrastructure or customer data. Surfshark confirmed no sensitive user information, VPN traffic, or encryption keys were compromised. The incident was detected on August 31, contained by September 2, and fully remediated shortly after. Surfshark rotated credentials, revoked tokens, and enhanced security controls and monitoring. Users are not required to take action but should remain vigilant for suspicious activity. MediumBreach Join the discussion | Bleeping Computer | 09/10/2026, 19:15:07 UTC Added: 09/10/2026, 19:20:22 UTC |
0 CVE-2026-88062 is a critical code injection vulnerability in diegosouzapw OmniRoute versions 3.8.49 and earlier. The vulnerability exists in the POST /api/acp/agents endpoint, which accepts attacker-controlled inputs that are insufficiently sanitized before being executed. Under certain configurations, including when requireLogin is false or during initial bootstrap, remote anonymous attackers can execute arbitrary code in the server container. No fixed version is currently available. Join the discussion | CVE Database V5 | 09/10/2026, 19:14:17 UTC Added: 09/10/2026, 19:41:56 UTC |
A Cross-Site Request Forgery (CSRF) vulnerability exists in santifer career-ops versions prior to 0.8.0. The local web dashboard exposed command-spawning and user-file-writing API routes without validating request origins or restricting access to loopback addresses. This allowed malicious web pages in other browser tabs or local network clients to send unauthorized requests, resulting in unauthenticated command execution as the dashboard user. The issue is fixed in version 0.8.0. Join the discussion | CVE Database V5 | 09/10/2026, 19:08:23 UTC Added: 09/10/2026, 19:41:56 UTC |
The Microsoft Excel KB5002914 security update released in September 2026 has caused issues with copy-and-paste operations and formula dragging for some users. The problem affects multiple Office versions including 2016 through 2024 and both MSI and Click-to-Run installations. Users report that uninstalling or rolling back the update restores normal functionality. No official Microsoft fix or workaround has been confirmed yet. MediumNews Join the discussion | Bleeping Computer | 09/10/2026, 19:07:33 UTC Added: 09/10/2026, 19:20:22 UTC |
0 The consul-template library is vulnerable to an information disclosure issue in its error handling path that may allow Vault secret values to appear in template error messages, log output, and downstream surfaces such as Nomad task events. This vulnerability (CVE-2026-87993) is fixed in consul-template 0.43.0. Join the discussion | CVE Database V5 | 09/10/2026, 19:00:08 UTC Added: 09/10/2026, 19:17:16 UTC |
Consul and Consul Enterprise are vulnerable to an authorization bypass in the Connect service mesh that may allow a service to reach a destination it is not authorized to access. When building Envoy RBAC rules to enforce Connect intentions, Consul did not correctly escape certain characters in service names, namespaces, and partitions, causing the generated authorization rules to match more broadly than intended. This vulnerability (CVE-2026-88021) is fixed in Consul 2.0.4 and Consul Enterprise 1.21.18, 1.22.12 and 2.0.4. Join the discussion | CVE Database V5 | 09/10/2026, 18:58:26 UTC Added: 09/10/2026, 19:17:16 UTC |
Consul and Consul Enterprise are vulnerable to an authorization bypass in the catalog deregistration path that may allow a local ACL token to delete peer-imported catalog objects. A caller with {{service:write}} or {{node:write}} permission may exploit this issue to remove services, checks, or nodes imported from a peered cluster without holding authority over the peer origin. This vulnerability (CVE-2026-87107) is fixed in Consul 2.0.4 and Consul Enterprise 1.21.18, 1.22.12 and 2.0.4. Join the discussion | CVE Database V5 | 09/10/2026, 18:57:35 UTC Added: 09/10/2026, 19:17:16 UTC |
Showing 1 to 10 of 129400 results