Threat Intelligence Database
Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threat Intelligence
Click on any threat for detailed analysis and mitigation recommendations
CVE-2026-76403: The software does not validate, or incorrectly validates, a certificate. in Splunk Splunk Connect for KafkaCVE-2026-76403 0 CVE-2026-76403 is a vulnerability in Splunk Connect for Kafka versions 2.2 where the software does not properly validate certificates during Kerberos authentication with HTTP Event Collector. This flaw allows an unauthenticated attacker positioned in the network path to read or modify data sent from the connector. The issue arises because the Kerberos authentication path does not enforce the configured certificate validation options when constructing the HTTP client. Join the discussion | CVE Database V5 | 08/19/2026, 21:35:16 UTC Added: 08/19/2026, 21:38:41 UTC |
CVE-2026-76402: The web server receives a URL or similar request from an upstream component and retrieves the contents of this URL, but it does not sufficiently ensure that the request is being sent to the expected destination. in Splunk Splunk Connect for KafkaCVE-2026-76402 0 CVE-2026-76402 affects Splunk Connect for Kafka versions 2.2. An unauthenticated attacker with access to the Kafka Connect REST API can configure a non-secure HTTP Event Collector endpoint in Splunk Enterprise. This misconfiguration causes the connector to send authentication credentials to an attacker-controlled server, exposing sensitive credentials and allowing limited alteration of event delivery. The vulnerability arises because the HTTP Event Collector endpoint validation does not enforce secure transport by default. Join the discussion | CVE Database V5 | 08/19/2026, 21:35:16 UTC Added: 08/19/2026, 21:38:41 UTC |
CVE-2026-76401: An algorithm in a product has an inefficient worst-case computational complexity that may be detrimental to system performance and can be triggered by an attacker, typically using crafted manipulations that ensure that the worst case is being reached. in Splunk Splunk Connect for KafkaCVE-2026-76401 0 CVE-2026-76401 is a medium severity vulnerability in Splunk Connect for Kafka versions below 2.2.7. An unauthenticated attacker with access to the Kafka Connect REST API can supply crafted regular expressions for timestamp extraction that cause inefficient processing. This triggers a worst-case computational complexity scenario, blocking a Kafka Connect worker thread and stopping event delivery for the affected connector. Join the discussion | CVE Database V5 | 08/19/2026, 21:35:15 UTC Added: 08/19/2026, 21:38:41 UTC |
CVE-2026-76400: The software does not properly control the allocation and maintenance of a limited resource thereby enabling an actor to influence the amount of resources consumed, eventually leading to the exhaustion of available resources. in Splunk Splunk Connect for KafkaCVE-2026-76400 0 CVE-2026-76400 is a medium severity vulnerability in Splunk Connect for Kafka versions below 2.2.7. It allows an unauthenticated user with access to the Kafka Connect REST API to cause resource exhaustion by triggering unbounded retries of failed event batches due to improper retry limit handling in HTTP Event Collector delivery. This can lead to denial of service by exhausting available resources. Join the discussion | CVE Database V5 | 08/19/2026, 21:35:15 UTC Added: 08/19/2026, 21:38:41 UTC |
Showing 1 to 4 of 4 results