> infrastructure security
for people who build things
Tracking vulnerabilities, supply chain attacks, and threat intelligence that matters to engineers running real infrastructure.
Dell Container Storage Modules: Two CVSS 10 Missing-Authentication Flaws Expose Kubernetes Storage Admin Credentials
Dell's DSA-2026-448 fixes two maximum-severity missing-authentication bugs in the CSM Authorization module that let unauthenticated attackers take over storage arrays behind Kubernetes clusters.
MikroTik RouterOS CVE-2026-84411: Pre-Auth Integer Underflow in Web Management Gives Root RCE
CISA's ICS advisory ICSA-26-272-06 flags a CVSS 9.8 pre-authentication integer underflow in the RouterOS web management service that a single crafted HTTP request can turn into root code execution or a crash.
Warlock Ransomware Crew Keeps Breaking In Through SharePoint, Hits Water and Telecom Operators
Symantec ties the China-linked Storm-2603 (Longlegs) crew to new Warlock ransomware intrusions at a water utility and a telecom, using SharePoint access, a vulnerable K7 driver, VS Code tunnels and SYSVOL deployment.
FortiMail CVE-2026-104286: Unauthenticated Path Traversal Exploited as Zero-Day
Fortinet confirms in-the-wild exploitation of CVE-2026-104286, a CVSS 9.8 path traversal in FortiMail that lets unauthenticated attackers write arbitrary files. Patches are not yet released; CISA set a October 4 deadline.
TeamViewer Patches Five High-Severity Flaws, Including Remote Session Access Control Bypass to RCE
TeamViewer bulletin TV-2026-1010 fixes five high-severity client and host flaws, led by CVE-2026-92370, a remote-session access control bypass that can lead to code execution. Update to 15.82.
Cisco Catalyst SD-WAN Manager CVE-2026-76504: Unauthenticated Admin API Access Exploited
Cisco confirms in-the-wild exploitation of CVE-2026-76504, a CVSS 9.8 URL-encoding auth bypass that hands unauthenticated attackers admin API access on Catalyst SD-WAN Manager. No workaround; CISA added it to KEV.
CVE-2026-89775: KVM/arm64 Nested-Virtualization Bug Gives Guests Read-Write Access to Host Kernel Memory
A type-truncation bug in KVM/arm64's stage-1 page-table walk lets a guest keep a writable mapping to a freed host kernel page, enabling guest-to-host escape on ARM64 hosts with nested virtualization enabled.
Branch Target Reuse: New Spectre v2 Variant Leaks Linux Root Password Hash Through the cBPF JIT
VUSec's Branch Target Reuse abuses stale indirect-branch predictions over freed JIT memory to leak a root password hash from Linux in 3-5 minutes; kernel fixes for CVE-2026-64507 and CVE-2026-64508 are merged.
MemTensor MemOS Packages Backdoored with sckit, a Go Credential-Stealing Worm, on npm and PyPI
Malicious releases of MemTensor's MemOS OpenClaw plugin (npm) and MemoryOS (PyPI) deliver sckit, a cross-platform Go implant that steals 13 credential types and carries worm templates for npm, PyPI and GitHub Actions.
Cloudflare Containers Bug Let One Tenant Read Another Tenant's Disk Data
A misconfigured Linux dm-thin storage pool let any Cloudflare Workers Paid customer recover unzeroed residual disk blocks from other tenants' Containers, Sandboxes, and Browser Rendering instances — exposing SQLite databases, .env files, and credentials.
CVE-2026-88771 & CVE-2026-88772: Unauthenticated RCE Zero-Days Hit Every NetScaler Deployment
Citrix confirms two NetScaler ADC/Gateway zero-days under active exploitation — one an unauthenticated command-execution bug present in every default configuration, the other a DTLS memory overflow enabled by default on VPN virtual servers.
The Skeleton Key Problem: Why 2026's Worst RCEs All Trace Back to a String Literal
SolarWinds ARM, ManageEngine, ASUS Control Center, Cisco FMC, Dell SCG, and a Tenda router backdoor all failed the same way this year: a secret baked into shipped code instead of generated per install. CWE-798 isn't a legacy bug class — it's still how management planes get owned.
Two Malicious CPAN Modules Smuggle a Python Backdoor Inside a Fake Certificate File
Crypt::SelfCertificate and IO::Socket::SSL::SelfCertificate, two CPAN distributions for generating self-signed certs, shipped versions that hide obfuscated Python code inside a sample cert.pem and execute it as a remote-fetch loader.
CVE-2026-100706: Kyverno Path-Encoding Bug Lets Any Namespace Tenant Reach Cluster Admin
A validation/execution mismatch in Kyverno's apiCall path handling lets a low-privilege namespace tenant use percent-encoded traversal segments to register a cluster-wide mutating webhook and escalate to cluster admin. CVSS 9.9, fixed in 1.19.1.
CISA Adds SharePoint CVE-2026-65660 to KEV: SafeControls Bypass Enables Authenticated RCE
CISA confirmed active exploitation of CVE-2026-65660, a SharePoint code-injection bug that bypasses the SafeControls allowlist, letting a low-privilege authenticated user register arbitrary .NET classes and run code as the farm service account.
WordPress Core CVE-2026-87902: Unauthenticated Path Traversal to RCE via pearcmd, Exploited Within Hours
An unauthenticated path traversal bug in WordPress Core's page-template resolution (CVE-2026-87902) lets attackers include arbitrary PHP files and chain to RCE via pearcmd — mass scanning began within five hours of the patch, and CISA added it to KEV on September 25.
CVE-2026-71362: Unauthenticated Account Takeover Hits Adobe Commerce and Magento, Now on CISA KEV
CISA added CVE-2026-71362 to KEV after Sansec confirmed active exploitation. A session-identity bug lets an unauthenticated attacker hijack any customer's Adobe Commerce or Magento account — no credentials, no interaction.
CVE-2026-86708: ManageEngine Shipped a Live GCP Service-Account Key Inside Its Public Installer
CVE-2026-86708 (CVSS 10.0): Zoho's ManageEngine Applications Manager Linux installer shipped a hard-coded, over-privileged Google Cloud service-account key that anyone who downloaded the installer could extract and use to impersonate the account.
CVE-2026-93952: Actively Exploited CVSS 10 Flaw Hands Attackers Privileged Access to Arista's VeloCloud Orchestrator
A maximum-severity input validation flaw in Arista's VeloCloud Orchestrator lets attackers who hold only the public half of an edge device's certificate reach privileged internal functionality on the SD-WAN control plane — and it's already being exploited in the wild.
CVE-2026-80521: Unpatched Ubuntu AF_UNIX Race Lets Containers Escape to Host Root
A public exploit for CVE-2026-80521, a use-after-free race in the Linux kernel's AF_UNIX socket garbage collector, lets an unprivileged process inside a default Docker or Kubernetes container break out to root on the host — and Ubuntu still hasn't shipped the fix.