🔐
FeliCa IC Chips Exposed by Missing Cryptographic Step
Organizations using affected FeliCa-based devices should identify impacted hardware and apply vendor guidance or replacement plans as soon as practical. Prioritize systems where chip integrity or stored data is security-sensitive.
CVE-2026-59776 is a Missing Cryptographic Step (CWE-325) vulnerability affecting certain FeliCa IC chips shipped in or before 2017. The flaw may allow attackers to read or tamper with information stored on the chip if exploited. The vulnerability is rated HIGH with a CVSS score of 7.0.
🔗 Read more 🔗
Source: NVD
💥
Zyxel Router Command Injection Enables OS Command Execution
Administrators running affected Zyxel firmware should update quickly. Exploitation requires admin access, but successful attacks result in full command execution.
CVE-2026-6952 is a post-authentication command injection vulnerability in the ‘LogServer’ field of the syslog component of Zyxel AX7501-B1 firmware through 5.17(ABPC.7.2)C0. An authenticated administrator can execute operating system commands on the affected device. The vulnerability is rated HIGH with a CVSS score of 7.2.
🔗 Read more 🔗
Source: NVD
📤
Public D-Link NAS Upload Flaw Allows Remote File Uploads
Anyone operating this NAS version should patch or isolate it immediately. The presence of a public exploit significantly increases the urgency.
CVE-2026-16332 affects D-Link DNS-320 1.0.2 and allows unrestricted file upload through the /mydlink/multi_uploadify.php endpoint by manipulating the Filedata[] argument. The attack can be performed remotely, and a public exploit is available. The vulnerability is rated HIGH with a CVSS score of 7.3.
🔗 Read more 🔗
Source: NVD
📁
D-Link DNS-320 Faces Another Remote Upload Vulnerability
Patch or remove exposed devices from the internet as soon as possible. Public exploit availability makes this a high-priority remediation.
CVE-2026-16331 impacts D-Link DNS-320 1.0.2 through the /web/function/save_ajax.php endpoint, where manipulation of the ‘Malicious Handler’ argument leads to unrestricted upload. The attack is remotely exploitable, and the exploit has been disclosed publicly. The vulnerability is rated HIGH with a CVSS score of 7.3.
🔗 Read more 🔗
Source: NVD
⚠️
D-Link DNS-320 Upload Endpoint Vulnerable to Remote Abuse
Systems running the affected firmware should be updated or isolated immediately. Public exploit availability raises the likelihood of opportunistic attacks.
CVE-2026-16330 affects D-Link DNS-320 1.0.2 and enables unrestricted upload through the /web/jquery/uploader/uploadify.php component. The vulnerability can be exploited remotely, and exploit code has been made public. The vulnerability is rated HIGH with a CVSS score of 7.3.
🔗 Read more 🔗
Source: NVD
📦
Remote File Upload Bug Hits D-Link DNS-320
Patch affected NAS devices without delay, especially if internet accessible. Public exploit disclosure increases operational risk.
CVE-2026-16329 is an unrestricted upload vulnerability in D-Link DNS-320 1.0.2 affecting /photo_center/php/uploadify.php. By manipulating the ‘Malicious Handler’ argument, attackers can perform remote uploads. The exploit is publicly available, and the vulnerability is rated HIGH with a CVSS score of 7.3.
🔗 Read more 🔗
Source: NVD
🚨
Netty SPDY Header Processing Can Trigger Resource Exhaustion
Developers and operators using affected Netty releases should upgrade promptly. Internet-facing services using SPDY are the highest priority.
CVE-2026-55833 affects Netty before versions 4.1.136.Final and 4.2.16.Final. A flaw in SPDY header decoding allows a remote peer to trigger excessive CPU and memory consumption by sending highly compressed header blocks that expand significantly during processing. The vulnerability is rated HIGH with a CVSS score of 7.5.
🔗 Read more 🔗
Source: NVD
🧠
Netty SPDY SETTINGS Parsing Can Exhaust Heap Memory
Upgrade affected Netty deployments as soon as possible, particularly public-facing services that process SPDY traffic. This issue can be abused remotely for denial-of-service.
CVE-2026-55831 affects Netty before versions 4.1.136.Final and 4.2.16.Final. A remote SPDY peer can send a crafted SETTINGS frame that forces excessive map allocations and heap growth, leading to resource exhaustion. The vulnerability is rated HIGH with a CVSS score of 7.5.
🔗 Read more 🔗
Source: NVD
📂
D-Link DNS-320 Remote Upload Flaw Publicly Disclosed
Patch affected devices immediately or remove them from external exposure. Public exploit availability makes this issue especially urgent.
CVE-2026-16327 affects D-Link DNS-320 1.0.2 through the /web/web_file/upload.php endpoint, where manipulation of the File argument enables unrestricted upload. The attack is remotely exploitable, and the exploit has been publicly disclosed. The vulnerability is rated HIGH with a CVSS score of 7.3.
🔗 Read more 🔗
Source: NVD
🔥
Critical AVideo Command Injection Bypasses Previous Fix
Anyone running vulnerable AVideo instances should patch immediately. This is a critical remote command execution issue with severe compromise potential.
CVE-2026-64625 affects AVideo before version 29.0 and is an incomplete fix regression for CVE-2026-45578. Attackers can inject arbitrary operating system commands through the Live plugin on_publish.php endpoint despite escapeshellarg() protection. The vulnerability is rated CRITICAL with a CVSS score of 9.8.
🔗 Read more 🔗
Source: NVD
📄
Malicious RDP Files Can Abuse FreeRDP Command Parsing
Organizations distributing or opening RDP files should update FreeRDP promptly. Treat untrusted RDP files as potentially dangerous until patched.
CVE-2026-64624 affects FreeRDP before version 3.28.0. Specially crafted RDP files can inject command-line options to execute arbitrary commands, bypass certificate validation, or expose local filesystems without user interaction. The vulnerability is rated HIGH with a CVSS score of 7.8.
🔗 Read more 🔗
Source: NVD
🤖
AgenticMail Prompt Injection Grants Privileged AI Actions
Teams using the affected AgenticMail components should upgrade immediately. Any deployment exposing inbound email workflows to privileged AI agents should treat this as a high-priority fix.
CVE-2026-57495 affects @agenticmail/claudecode prior to version 0.2.39, @agenticmail/codex prior to version 0.1.33, @agenticmail/core prior to version 0.9.43, and @agenticmail/openclaw prior to version 0.5.71. An inbound email handling flaw allows indirect prompt injection that resumes a privileged Claude Code session without verifying the sender, potentially giving attacker-controlled input access to a highly privileged agent. The vulnerability is rated HIGH with a CVSS score of 8.2.
🔗 Read more 🔗
Source: NVD