Threat Intelligence Database
Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threat Intelligence
Click on any threat for detailed analysis and mitigation recommendations
CVE-2026-63252: CWE-401 in Eclipse Foundation Eclipse MiloCVE-2026-63252 0 In Eclipse Milo versions 0.6.0 through 1.1.4, UASC server transport handlers fail to release retained partial message chunks when a channel disconnects, allowing a remote unauthenticated client to exhaust pooled direct memory by repeatedly sending incomplete chunks and disconnecting, potentially terminating the server. Join the discussion | CVE Database V5 | 08/04/2026, 12:03:18 UTC Added: 08/04/2026, 12:33:19 UTC |
CVE-2026-63248: CWE-862 in Eclipse Foundation Eclipse MiloCVE-2026-63248 0 In Eclipse Milo versions 0.6.0 through 1.1.4, OPC UA server diagnostics nodes do not enforce access authorization. An anonymous client can enable diagnostics over a None/None endpoint without a certificate; with a trusted client application certificate over SignAndEncrypt, it can read security diagnostics for other active sessions, exposing usernames, login history, authentication mechanisms, security modes and policies, and public client certificates. Join the discussion | CVE Database V5 | 08/04/2026, 12:07:43 UTC Added: 08/04/2026, 12:33:19 UTC |
CVE-2026-62927: CWE-863 in Eclipse Foundation Eclipse MiloCVE-2026-62927 0 In Eclipse Milo versions 1.0.0 through 1.1.4, the Call service dispatches the original mixed batch to address-space handlers after calculating authorization, allowing an anonymous or otherwise low-privileged client to execute a denied method by batching it with an allowed method. Join the discussion | CVE Database V5 | 08/04/2026, 11:57:59 UTC Added: 08/04/2026, 12:33:19 UTC |
CVE-2026-61387: CWE-460 in Eclipse Foundation Eclipse MiloCVE-2026-61387 0 In Eclipse Milo versions 1.0.0 through 1.1.4, monitored-item quota accounting is not exception-safe: if item creation fails with an unchecked error, the server-global reservation is not restored. Deeply nested PubSub ExtensionObjects in a `CreateMonitoredItems` event filter can trigger a `StackOverflowError` during decoding, allowing an unauthenticated remote client to exhaust a finite global monitored-item quota and prevent all clients from creating new monitored items until restart. Existing monitored items and other server functions remain unaffected. Join the discussion | CVE Database V5 | 08/04/2026, 11:52:38 UTC Added: 08/04/2026, 12:33:19 UTC |
CVE-2026-60007: CWE-204 in Eclipse Foundation Eclipse MiloCVE-2026-60007 0 In Eclipse Milo versions 0.6.0 through 1.1.4, username-token processing returns distinguishable errors for invalid RSA PKCS#1 v1.5 padding and other authentication failures, allowing an on-path attacker who captures a victim's `Basic128Rsa15`-encrypted username token to use repeated unauthenticated `ActivateSession` requests as a padding oracle, recover the victim's password, and authenticate with the recovered credentials. Join the discussion | CVE Database V5 | 08/04/2026, 11:55:41 UTC Added: 08/04/2026, 12:33:19 UTC |
CVE-2026-58080: CWE-862 in Eclipse Foundation Eclipse MiloCVE-2026-58080 0 In Eclipse Milo versions 1.0.0 through 1.1.4, `OpcUaServerConfig.copy()` fails to preserve a configured `RoleMapper`. On servers that rely on role permissions and construct the running configuration through `copy()`, sessions receive no role IDs and the default access controller skips role-permission checks, allowing an anonymous client where anonymous sessions are permitted to read role-permission metadata, invoke protected methods, or delete protected nodes. Join the discussion | CVE Database V5 | 08/04/2026, 12:05:10 UTC Added: 08/04/2026, 12:33:19 UTC |
Showing 1 to 6 of 6 results