Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.

Threat Intelligence Database

Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.

Threat Intelligence

Click on any threat for detailed analysis and mitigation recommendations

CVE-2026-17598: CWE-915 Improperly Controlled Modification of Dynamically-Determined Object Attributes in Sonatype Nexus Repository 3CVE-2026-17598
0

Sonatype Nexus Repository 3 contains a vulnerability where internal configuration keys are not properly filtered from user-supplied task properties when creating or updating scheduled tasks via the administrative UI. This flaw allows an account with permission to create at least one scheduled task type to supply crafted properties that overwrite the configuration of an unrelated existing task instead of creating a new one.

Join the discussion
CVE-2026-17603: CWE-94 Improper Control of Generation of Code ('Code Injection') in Sonatype Nexus Repository 3CVE-2026-17603
0

Nexus Repository 3 did not sufficiently restrict which HikariCP connection-pool properties could be set through the DataStore configuration API. A user holding the nx-datastores-update permission could set the connectionInitSql property to execute arbitrary SQL against the configured database on every new connection. On the default H2 database backend, this could be leveraged to achieve remote code execution as the Nexus process user.

Join the discussion
CVE-2026-17595: CWE-497 Exposure of Sensitive System Information to an Unauthorized Control Sphere in Sonatype Nexus Repository 3CVE-2026-17595
0

Nexus Repository 3 did not fully sandbox JEXL expressions used in Content Selectors. An account holding the nexus:selectors:create permission could construct an expression that read Java object properties not intended to be exposed to the expression engine, disclosing internal JVM class metadata such as class and classloader names. This issue does not permit method invocation, object construction, or arbitrary code execution. This has been fixed by restricting property access in the JEXL sandbox to the intended data types.

Join the discussion
CVE-2026-17594: CWE-863 Incorrect Authorization in Sonatype Nexus Repository 3CVE-2026-17594
0

Nexus Repository 3 CE/Pro versions 3.0.0 through 3.94.x contain an incorrect authorization vulnerability (CWE-863) in the repository-creation user interface. An individual user account holding a delegated repository-admin privilege scoped to a specific repository format could create a repository of a different, unauthorized format, because authorization was checked against one request field while a separate, attacker-controlled field determined the repository format actually created. This does not affect the anonymous user, which cannot hold this privilege by default. Fixed in version 3.95.0.

Join the discussion
CVE-2026-14644: CWE-843 Access of Resource Using Incompatible Type ('Type Confusion') in Sonatype Nexus Repository 3CVE-2026-14644
0

Nexus Repository 3 contained a privilege escalation vulnerability in the REST privileges API. An authenticated user with permission to manage privileges could, under certain role configurations, escalate their own access to full administrator by exploiting a type-confusion flaw in the privilege update endpoint.

Join the discussion

Showing 1 to 5 of 5 results

Filters:Package: pkg:maven/com.sonatype.nexus/nexus-repository-manager
Page 1 of 1
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses