Threat Intelligence Database
Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threat Intelligence
Click on any threat for detailed analysis and mitigation recommendations
CVE-2026-55622 is an improper access control vulnerability in the lxc incus project. It allows an attacker who knows the name of a project and an instance within it, but lacks authorization, to copy that instance to a different project. This flaw arises because the source instance is loaded without verifying the caller's permission to view it. The vulnerability could lead to unauthorized access to secrets stored in instances. The issue affects incus versions prior to 7.2.0 and has a high severity rating with a CVSS score of 7.7. Join the discussion | CVE Database V5 | 08/28/2026, 18:57:27 UTC Added: 08/21/2026, 15:08:25 UTC |
CVE-2026-55621 is an improper access control vulnerability in the lxc incus project. It allows an attacker who knows the name of a project and a custom volume within that project, but lacks authorization, to copy that custom volume into another project they control. This occurs because the system does not verify the attacker's permission to view the source volume before copying. The vulnerability could lead to unauthorized access to secrets stored in custom volumes. Exploitation requires access to the same server where the volume resides. A proof-of-concept script demonstrates how to perform the unauthorized copy. The vulnerability affects incus versions prior to 7.2.0 and has a CVSS 3.1 score of 7.7 (high severity). Join the discussion | CVE Database V5 | 08/28/2026, 18:52:05 UTC Added: 08/21/2026, 15:08:25 UTC |
Incus is a system container and virtual machine manager. Prior to version 7.3.0, a malicious image containing a `metadata.yaml` symlink pointing to an arbitrary host path allows an authenticated Incus user to read or overwrite any file on the host as root via the instance metadata API. The `exec-output` and `templates/` paths were patched in a prior release using `Lstat` rejection and `os.OpenRoot` confinement; `metadata.yaml` was not included in either patch and remains exploitable. Version 7.3.0 patches the issue. Join the discussion | CVE Database V5 | 08/21/2026, 14:53:26 UTC Added: 08/21/2026, 15:08:24 UTC |
0 Incus is a system container and virtual machine manager. Prior to version 7.3.0, an unprivileged, project-confined Incus user (a non-admin TLS/RBAC identity with `can_create_images` and `can_create_instances`) can execute arbitrary code as root on the host. A crafted image ships `backup.yaml` as a symlink to a host file. When the root daemon writes the instance's backup file, it follows the symlink. Version 7.3.0 patches the issue. Join the discussion | CVE Database V5 | 08/21/2026, 14:49:16 UTC Added: 08/21/2026, 15:08:24 UTC |
Incus is a system container and virtual machine manager. Prior to version 7.3.0, when copying an instance across projects, the project restriction check (`AllowInstanceCreation`) runs BEFORE the source instance's configuration is merged into the request. Dangerous configuration keys (including `security.privileged`, `raw.lxc`, `raw.apparmor`) from the source instance are merged AFTER the check passes, bypassing all project restrictions on the target project. Version 7.3.0 patches the issue. Join the discussion | CVE Database V5 | 08/21/2026, 14:47:56 UTC Added: 08/21/2026, 15:08:25 UTC |
0 Incus is a system container and virtual machine manager. Prior to version 7.3.0, when migrating an instance to another cluster member, user-supplied configuration overrides (including security-critical keys like `security.privileged` and `raw.lxc`) are applied without any project restriction enforcement, allowing a restricted project user to escalate to a privileged container and escape to the host. Version 7.3.0 patches the issue. Join the discussion | CVE Database V5 | 08/21/2026, 14:47:13 UTC Added: 08/21/2026, 15:08:25 UTC |
0 Incus is a system container and virtual machine manager. Prior to version 7.3.0, improper validation of user-provided `block.create_options` in storage volume configuration leads to argument injection in the constructed filesystem creation command line. This allows a project-scoped user to inject arbitrary arguments into the binary executed as root. Version 7.3.0 patches the issue. Join the discussion | CVE Database V5 | 08/21/2026, 14:45:35 UTC Added: 08/21/2026, 15:08:25 UTC |
CVE-2026-62313 is an authorization vulnerability in the Incus container and virtual machine manager prior to version 7.3.0. The issue allows users to bypass project-level restrictions intended to enforce isolated privilege containers by omitting a specific configuration key. This results in containers sharing the host's UID/GID map rather than having isolated mappings, weakening tenant isolation. The vulnerability is patched in version 7.3.0. Join the discussion | CVE Database V5 | 08/21/2026, 14:44:27 UTC Added: 08/21/2026, 15:08:25 UTC |
CVE-2026-47753 is a medium severity vulnerability in Incus, a system container and virtual machine manager. Prior to version 7.1.0, a nil-pointer dereference exists in the CreateInstanceFromBackup function within the storage backend. An authenticated user with permission to create instances can remotely trigger this by uploading a crafted backup tarball, causing the Incus daemon to panic and crash. This results in denial of service affecting all projects on the cluster member. Version 7.1.0 includes a patch that addresses this issue. Join the discussion | CVE Database V5 | 08/21/2026, 14:14:12 UTC Added: 08/21/2026, 14:23:35 UTC |
0 Incus is a system container and virtual machine manager. Prior to version 7.0.0, uploads of large amount of data by authenticated users can run the Incus server out of disk space, potentially taking down the host system. The impact here is limited for anyone using storage.images_volume and storage.backups_volume as those users will have large uploads be stored on those volumes rather than directly on the host filesystem. This is the default behavior on IncusOS. This issue has been patched in version 7.0.0. Join the discussion | CVE Database V5 | 05/07/2026, 13:09:34 UTC Added: 05/07/2026, 14:36:50 UTC |
Showing 1 to 10 of 27 results