Security Center
安全情报屋
报告类型 当前榜单
情报总数 95 条
板块条数 95 条
生成时间 08-30 00:00
📚 安全情报馆 · 2026-08-30
4 块

🛡️ 每日安全情报

🛡️ AI 安全情报日报 · 2026-08-30

_2026-08-30 · 共筛出 198 条 ≥4★_

1. -CVE-2018-0834-aab-aar exploit 🔓 ★★★★★

📋 Exploit for CVE-2018-0834. CVSS 9.3.

2. AVBypass exploit 🔓 ★★★★★

📋 Exploit.

3. Android-PIN-Bruteforce exploit 🔓 ★★★★★

📋 Exploit.

4. Better-CVE-2022-29464 exploit 🔓 ★★★★★

📋 Exploit for CVE-2022-29464. CVSS 10.

5. Burp_Collector exploit 🔓 ★★★★★

📋 Exploit.

6. C4 exploit 🔓 ★★★★★

📋 Exploit.

7. CANToolz exploit 🔓 ★★★★★

📋 Exploit.

8. CVE-2014-0226-poc exploit 🔓 ★★★★★

📋 Exploit for CVE-2014-0226. CVSS 6.8.

9. CVE-2016-2098 exploit 🔓 ★★★★★

📋 Exploit for CVE-2016-2098. CVSS 7.5.

10. CVE-2019-10685 exploit 🔓 ★★★★★

📋 Exploit for CVE-2019-10685. CVSS 6.1.

11. CVE-2019-11043 exploit 🔓 ★★★★★

📋 Exploit for CVE-2019-11043. CVSS 9.8.

12. CVE-2019-11581 exploit 🔓 ★★★★★

📋 Exploit for CVE-2019-11581. CVSS 9.8.

13. CVE-2020-0601_PoC exploit 🔓 ★★★★★

📋 Exploit for CVE-2020-0601. CVSS 8.1.

14. CVE-2020-17527-Tomcat exploit 🔓 ★★★★★

📋 Exploit for CVE-2020-17527. CVSS 7.5.

15. CVE-2020-2038 exploit 🔓 ★★★★★

📋 Exploit for CVE-2020-2038. CVSS 9.

---

其他 183 条

🚨 漏洞预警

🔴 CRITICAL · 59 条

1. CVE-2026-81578 🔥 `CVSS 8.8`

🎯 受影响:An improper access control vulnerability exists in the web management interface of PaperCut MF and P

📋 简介:An improper access control vulnerability exists in the web management interface of PaperCut MF and PaperCut NG.

🔗 参考:

2. CVE-2021-21972 🔥 ⚡近期活跃 `CVSS 10.0`

🎯 受影响:The vSphere Client (HTML5) contains a remote code execution vulnerability in a vCenter Server plugin

📋 简介:The vSphere Client (HTML5) contains a remote code execution vulnerability in a vCenter Server plugin.

🔗 参考:

3. CVE-2026-82266 `CVSS 9.8`

🎯 受影响:Redpanda through 26.2.2 binds the Admin API to 0.0.0.0:9644 with admin_api_require_auth defaulting t

📋 简介:Redpanda through 26.2.2 binds the Admin API to 0.0.0.0:9644 with admin_api_require_auth defaulting to false, treating unauthenticated requests as superusers.

🔗 参考:

4. CVE-2026-82448 `CVSS 9.8`

🎯 受影响:Shinobi

📋 简介:Shinobi before commit 5a76c74f contains a hardcoded connection key in the child node service that allows unauthenticated attackers to execute arbitrary database queries.

🔗 参考:

5. CVE-2021-29442 🔥 ⚡近期活跃 `CVSS 8.6`

🎯 受影响:Nacos

📋 简介:Nacos is a platform designed for dynamic service discovery and configuration and service management.

🔗 参考:

6. CVE-2026-82456 `CVSS 10`

🎯 受影响:argocd-mcp 0.8.0 binds its HTTP transport to every network interface and accepts MCP sessions withou

📋 简介:argocd-mcp 0.8.0 binds its HTTP transport to every network interface and accepts MCP sessions without requiring caller credentials when ARGOCD_API_TOKEN is configured.

🔗 参考:

7. CVE-2026-3627 `CVSS 9.1`

🎯 受影响:IBM Concert 1.0.0 through 2.3.1

📋 简介:IBM Concert 1.0.0 through 2.3.1 is vulnerable to SQL injection.

🔗 参考:

8. CVE-2026-82286 🔥 `CVSS 8.8`

🎯 受影响:gpt-crawler through 1.5.1 fails to validate the outputFileName parameter in the POST /crawl endpoint

📋 简介:gpt-crawler through 1.5.1 fails to validate the outputFileName parameter in the POST /crawl endpoint, allowing unauthenticated attackers to write arbitrary files to any filesystem path.

🔗 参考:

9. CVE-2026-82017 `CVSS 8.6`

🎯 受影响:IGEL OS 12

📋 简介:IGEL OS 12 before 12.7.6 and IGEL OS 11 before 11.11.150 contain a boot registry parameter injection vulnerability that allows attackers with physical access to execute arbitrary Linux loader parameters by writing to an unencrypted and unsigned configuration area read by the s...

🔗 参考:

10. CVE-2026-82283 `CVSS 8.6`

🎯 受影响:VoltAgent through 2.1.20 fails to validate conversation ownership in memory API handlers, allowing a

📋 简介:VoltAgent through 2.1.20 fails to validate conversation ownership in memory API handlers, allowing authenticated users to access other users' conversations.

🔗 参考:

11. CVE-2026-54745 `CVSS 10`

🎯 受影响:Kubeflow Pipelines enables users to build and deploy portable, scalable machine learning workflows.

📋 简介:Kubeflow Pipelines enables users to build and deploy portable, scalable machine learning workflows.

🔗 参考:

12. CVE-2026-18527 `CVSS 9.9`

🎯 受影响:IBM Administration Runtime Expert for i 1R1M0 IBM Application Runtime Expert (ARE) for i could allow

📋 简介:IBM Administration Runtime Expert for i 1R1M0 IBM Application Runtime Expert (ARE) for i could allow a remote attacker to gain elevated privileges, caused by ARE GUI component processing.

🔗 参考:

13. CVE-2026-82078 🔥 `CVSS 9.4`

🎯 受影响:An unsafe dynamic class loading vulnerability exists in the database connection utilities of PaperCu

📋 简介:An unsafe dynamic class loading vulnerability exists in the database connection utilities of PaperCut MF and PaperCut NG.

🔗 参考:

14. CVE-2026-82291 `CVSS 8.1`

🎯 受影响:HeyForm

📋 简介:HeyForm before 3.0.0-rc.8 reflects the request Origin header in CORS responses while allowing credentials, enabling cross-origin requests with authentication.

🔗 参考:

15. CVE-2026-19295 `CVSS 9.9`

🎯 受影响:IBM Langflow OSS 1.0.0 through 1.11.1

📋 简介:IBM Langflow OSS 1.0.0 through 1.11.1 allows an authenticated attacker to execute arbitrary operating system commands in the server process by saving a flow with a crafted type field value and triggering a build of a wrapper flow that references it.

🔗 参考:

16. CVE-2026-82466 `CVSS 9.4`

🎯 受影响:Rodauth

📋 简介:Rodauth before 2.46.0 contains an authentication bypass vulnerability in the webauthn_login route that allows logged-in users to authenticate as any other account.

🔗 参考:

17. CVE-2026-19286 `CVSS 9.8`

🎯 受影响:IBM Langflow OSS 1.0.0 through 1.11.1 could

📋 简介:IBM Langflow OSS 1.0.0 through 1.11.1 could allow a remote attacker to execute arbitrary code due to improper enforcement of security restrictions on the A2A public endpoint.

🔗 参考:

18. CVE-2026-80600 `CVSS 9.8`

🎯 受影响:Linux kernel

📋 简介:In the Linux kernel, the following vulnerability has been resolved:

batman-adv: dat: acquire ARP hw source only after skb realloc

The pskb_may_pull() called by batadv_get_vid() could reallocate the buffer

behind the skb.

🔗 参考:

19. CVE-2026-80609 `CVSS 9.8`

🎯 受影响:Linux kernel

📋 简介:In the Linux kernel, the following vulnerability has been resolved:

qede: fix out-of-bounds check for cqe->len_list[]

Move index check before element access.

🔗 参考:

20. CVE-2026-80612 `CVSS 9.8`

🎯 受影响:Linux kernel

📋 简介:In the Linux kernel, the following vulnerability has been resolved:

net: lwtunnel: Drop skb metadata before LWT encapsulation

skb metadata is meant for passing information between XDP and TC.

🔗 参考:

21. CVE-2026-80617 `CVSS 9.8`

🎯 受影响:Linux kernel

📋 简介:In the Linux kernel, the following vulnerability has been resolved:

net: airoha: fix foe_check_time allocation size

foe_check_time is declared as u16 pointer but was allocated with

only ppe_num_entries bytes instead of ppe_num_entries * sizeof(u16).

🔗 参考:

22. CVE-2026-80630 `CVSS 9.8`

🎯 受影响:Linux kernel

📋 简介:In the Linux kernel, the following vulnerability has been resolved:

net/sched: sch_fq_codel: Do not call qdisc_tree_reduce_backlog during peek before restoring qlen

Whenever fq_codel drops packets during peek, it calls

qdisc_tree_reduce_backlog.

🔗 参考:

23. CVE-2026-80634 `CVSS 9.8`

🎯 受影响:Linux kernel

📋 简介:In the Linux kernel, the following vulnerability has been resolved:

netfilter: flowtable: avoid num_encaps underflow on bridge VLAN untag

The DEV_PATH_BR_VLAN_UNTAG case post-decrements info->num_encaps

inside WARN_ON_ONCE(). num_encaps is u8, so if it's already 0 the

decrem...

🔗 参考:

24. CVE-2026-80668 `CVSS 9.8`

🎯 受影响:Linux kernel

📋 简介:In the Linux kernel, the following vulnerability has been resolved:

netfilter: nf_conntrack_expect: use conntrack GC to reap expectations

This patch replaces the timer API by GC worker approach for

expectations, as it already happened in many other subsystems.

🔗 参考:

25. CVE-2026-80673 `CVSS 9.8`

🎯 受影响:Linux kernel

📋 简介:In the Linux kernel, the following vulnerability has been resolved:

ntfs: bound the look-ahead attribute-list entry in ntfs_external_attr_find()

When resolving an attribute lookup with a non-zero @lowest_vcn,

ntfs_external_attr_find() peeks at the next $ATTRIBUTE_LIST entry ...

🔗 参考:

26. CVE-2026-80674 `CVSS 9.8`

🎯 受影响:Linux kernel

📋 简介:In the Linux kernel, the following vulnerability has been resolved:

ntfs: validate resident attribute lists and harden the validator

A base inode's $ATTRIBUTE_LIST is sanity-checked by load_attribute_list()

only on the non-resident path; ntfs_read_locked_inode() copies a *re...

🔗 参考:

27. CVE-2026-80681 `CVSS 9.8`

🎯 受影响:Linux kernel

📋 简介:In the Linux kernel, the following vulnerability has been resolved:

vxlan: re-fetch eth header after route_shortcircuit()

Before route_shortcircuit(), the eth header pointer is cached from eth_hdr(skb).

🔗 参考:

28. CVE-2026-80694 `CVSS 9.8`

🎯 受影响:Linux kernel

📋 简介:In the Linux kernel, the following vulnerability has been resolved:

net: ethernet: mtk_eth_soc: pass eth to mtk_handle_irq_rx in poll_controller

mtk_handle_irq_rx expects a struct mtk_eth * (matching the request_irq

cookie), but mtk_poll_controller incorrectly passed the net...

🔗 参考:

29. CVE-2026-80714 `CVSS 9.8`

🎯 受影响:Linux kernel

📋 简介:In the Linux kernel, the following vulnerability has been resolved:

ipvs: do not propagate one-packet flag to synced conns

Synced connections can be created before their destination exists.

🔗 参考:

30. CVE-2026-82277 `CVSS 9.8`

🎯 受影响:Argo Rollouts dashboard through 1.10.0 binds to all interfaces and exposes mutating Rollout operatio

📋 简介:Argo Rollouts dashboard through 1.10.0 binds to all interfaces and exposes mutating Rollout operations without authentication, authorization, or CSRF protection.

🔗 参考:

31. CVE-2026-55068 `CVSS 9.3`

🎯 受影响:free5GC

📋 简介:free5GC is an open-source implementation of the 5G core network.

🔗 参考:

32. CVE-2026-55378 `CVSS 9.3`

🎯 受影响:JS Recon

📋 简介:JS Recon is a JavaScript enumeration and SAST tool.

🔗 参考:

33. CVE-2026-80671 `CVSS 9.3`

🎯 受影响:Linux kernel

📋 简介:In the Linux kernel, the following vulnerability has been resolved:

perf sched: Fix register_pid() overflow, strcpy, and BUG_ON

register_pid() has several issues when processing untrusted perf.data:

1.

🔗 参考:

34. CVE-2026-80684 `CVSS 9.3`

🎯 受影响:Linux kernel

📋 简介:In the Linux kernel, the following vulnerability has been resolved:

KVM: s390: pci: Fix NULL dereference on AIBV allocation failure

The airq_iv_create() can return NULL on failure, but the return value was

never checked.

🔗 参考:

35. CVE-2026-80693 `CVSS 9.3`

🎯 受影响:Linux kernel

📋 简介:In the Linux kernel, the following vulnerability has been resolved:

idpf: bound interrupt-vector register fill to the allocated array

idpf_get_reg_intr_vecs() fills the caller-allocated reg_vals[] array from

the VIRTCHNL2_OP_ALLOC_VECTORS reply in adapter->req_vec_chunks, bo...

🔗 参考:

36. CVE-2026-82082 `CVSS 9.8`

🎯 受影响:NUMail developed by Green-Computing has an OS Command Injection vulnerability. Unauthenticated remot

📋 简介:NUMail developed by Green-Computing has an OS Command Injection vulnerability.

🔗 参考:

37. CVE-2026-82329 `CVSS 9.8`

🎯 受影响:JFrog Artifactory

📋 简介:JFrog Artifactory contains an authentication weakness that, under default configuration, may allow an unauthenticated attacker with network access to obtain administrative privileges.

🔗 参考:

38. CVE-2026-82452 `CVSS 9.8`

🎯 受影响:rust-iot-platform through commit 5df942ab

📋 简介:rust-iot-platform through commit 5df942ab contains an authentication bypass vulnerability where most REST API routes lack authentication guards in their handler signatures.

🔗 参考:

39. CVE-2026-80603 `CVSS 9.1`

🎯 受影响:Linux kernel

📋 简介:In the Linux kernel, the following vulnerability has been resolved:

netfilter: nf_conntrack_irc: fix parse_dcc() off-by-one OOB read

parse_dcc() treats data_end as an inclusive end pointer, but its only

caller passes data_limit = ib_ptr + datalen, which points one past the

l...

🔗 参考:

40. CVE-2026-80670 `CVSS 9.1`

🎯 受影响:Linux kernel

📋 简介:In the Linux kernel, the following vulnerability has been resolved:

perf tools: Use perf_env__get_cpu_topology() in machine__resolve()

machine__resolve() accesses env->cpu[al->cpu].socket_id after checking

al->cpu >= 0 and env->cpu != NULL, but without validating al->cpu

aga...

🔗 参考:

41. CVE-2026-82454 `CVSS 9.3`

🎯 受影响:The Omnivore API (packages/api) before the fix in commit abf53d6 contains an authentication bypass i

📋 简介:The Omnivore API (packages/api) before the fix in commit abf53d6 contains an authentication bypass in Apple sign-in token verification.

🔗 参考:

42. CVE-2026-82244 `CVSS 9.4`

🎯 受影响:Budibase

📋 简介:Budibase versions before 3.41.3 contain a remote code execution vulnerability in plugin handling that allows authenticated admin users to execute arbitrary code by uploading a malicious plugin tarball.

🔗 参考:

43. CVE-2026-55565 `CVSS 9.9`

🎯 受影响:Yamcs

📋 简介:Yamcs is a mission control framework.

🔗 参考:

44. CVE-2026-55634 `CVSS 9.9`

🎯 受影响:Pimcore

📋 简介:Pimcore is an Open Source Data & Experience Management Platform.

🔗 参考:

45. CVE-2026-55559 `CVSS 9.8`

🎯 受影响:Yamcs

📋 简介:Yamcs is a mission control framework.

🔗 参考:

46. CVE-2026-78032 `CVSS 9.8`

🎯 受影响:SOY CMS

📋 简介:SOY CMS contains an issue with deserialization of untrusted data.

🔗 参考:

47. CVE-2026-82460 `CVSS 9.8`

🎯 受影响:Cloud Commander

📋 简介:Cloud Commander before 19.20.2 contains a directory traversal vulnerability in REST file-operation and markdown endpoints that fails to properly validate path normalization.

🔗 参考:

48. CVE-2026-54754 `CVSS 9.6`

🎯 受影响:Klever-Go

📋 简介:Klever-Go is the Go implementation of the Klever blockchain protocol.

🔗 参考:

49. CVE-2026-54755 `CVSS 9.6`

🎯 受影响:Klever-Go

📋 简介:Klever-Go is the Go implementation of the Klever blockchain protocol.

🔗 参考:

50. CVE-2026-55220 `CVSS 9.3`

🎯 受影响:Pimcore

📋 简介:Pimcore is an Open Source Data & Experience Management Platform.

🔗 参考:

51. CVE-2026-82090 `CVSS 9.2`

🎯 受影响:Pocket through 8.33.0.0

📋 简介:Pocket through 8.33.0.0 allows XSS because "Save to Pocket" injects external HTML into the DOM.

🔗 参考:

52. CVE-2026-18918 `CVSS 9.1`

🎯 受影响:In Eclipse Lyo

📋 简介:In Eclipse Lyo versions 2.0.0 to 7.0.0, OAuth server authorization checks can be bypassed when the 2-legged auth is supported by the server.

🔗 参考:

53. CVE-2026-42007 `CVSS 9.1`

🎯 受影响:An attacker that has valid credentials can use a Sieve script with the editheader extension to trigg

📋 简介:An attacker that has valid credentials can use a Sieve script with the editheader extension to trigger a use-after-free in the mail editing code, and to write memory contents beyond the intended buffer into the delivered mail.

🔗 参考:

54. CVE-2026-55247 `CVSS 9.1`

🎯 受影响:plone.app.event provides the event content type for Plone. Prior to

📋 简介:plone.app.event provides the event content type for Plone.

🔗 参考:

55. CVE-2026-55248 `CVSS 9.1`

🎯 受影响:plone.app.portlets provides portlets and a Plone-specific user interface for plone.portlets. Prior t

📋 简介:plone.app.portlets provides portlets and a Plone-specific user interface for plone.portlets.

🔗 参考:

56. CVE-2026-55511 `CVSS 9.1`

🎯 受影响:Yamcs

📋 简介:Yamcs is a mission control framework.

🔗 参考:

57. CVE-2026-82281 `CVSS 9.1`

🎯 受影响:Kotaemon through 0.12.0 fails to properly validate conversation ownership in select_conv, delete_con

📋 简介:Kotaemon through 0.12.0 fails to properly validate conversation ownership in select_conv, delete_conv, rename_conv, and on_set_public_conversation functions in control.py.

🔗 参考:

58. CVE-2026-40541 `CVSS 9`

🎯 受影响:An improper neutralization of input during web page generation ('Cross-site Scripting') vulnerabilit

📋 简介:An improper neutralization of input during web page generation ('Cross-site Scripting') vulnerability in extract domain in Synology Chat Server before 2.4.5-22148 allows remote authenticated users, via a UI interaction, to read or write arbitrary files and conduct denial-of-se...

🔗 参考:

59. CVE-2026-82021 `CVSS 9`

🎯 受影响:Hermes Agent 0.18.2

📋 简介:Hermes Agent 0.18.2 prior to 0.19.0 contains a supply chain vulnerability in its bundled MCP catalog that allows a remote attacker to execute arbitrary code by compromising a third-party upstream repository referenced via a mutable branch rather than a pinned commit SHA.

🔗 参考:

🟠 HIGH · 10 条

1. CVE-2026-80628 `CVSS 7.8`

🎯 受影响:Linux kernel

📋 简介:In the Linux kernel, the following vulnerability has been resolved:

ALSA: seq: oss: Serialize readq reset state with q->lock

snd_seq_oss_readq_clear() resets qlen, head, and tail without

q->lock even though the normal reader and producer paths serialize the

same ring state u...

🔗 参考:

2. CVE-2026-82282 `CVSS 8.8`

🎯 受影响:Atlantis through 0.47.1 fails to authenticate the /github-app/setup endpoint, allowing unauthenticat

📋 简介:Atlantis through 0.47.1 fails to authenticate the /github-app/setup endpoint, allowing unauthenticated attackers to access GitHub App credentials.

🔗 参考:

3. CVE-2026-81517 `CVSS 8.7`

🎯 受影响:An unauthenticated party able to reach the port of a MongoDB Connector for BI (mongosqld) instance m

📋 简介:An unauthenticated party able to reach the port of a MongoDB Connector for BI (mongosqld) instance may generate enough routine connection log activity to exhaust the storage backing the configured log path.

🔗 参考:

4. CVE-2026-55066 `CVSS 7.1`

🎯 受影响:Vikunja

📋 简介:Vikunja is an open-source self-hosted task management platform.

🔗 参考:

5. CVE-2026-55848 `CVSS 8.6`

🎯 受影响:mapfish-print

📋 简介:mapfish-print is a component of MapFish for printing templated cartographic maps.

🔗 参考:

6. CVE-2026-82271 `CVSS 7.1`

🎯 受影响:R2R through 3.6.5 fails to properly validate user ownership in conversation update and message handl

📋 简介:R2R through 3.6.5 fails to properly validate user ownership in conversation update and message handlers, allowing authenticated users to modify other users' conversations.

🔗 参考:

7. CVE-2026-82280 `CVSS 7.1`

🎯 受影响:Quivr through 0.0.322 fails to validate ownership in prompt endpoints, allowing authenticated users

📋 简介:Quivr through 0.0.322 fails to validate ownership in prompt endpoints, allowing authenticated users to modify any prompt by identifier.

🔗 参考:

8. CVE-2026-82450 `CVSS 8.8`

🎯 受影响:BookStack

📋 简介:BookStack before 26.05.4 contains a remote code execution vulnerability in the portable ZIP import functionality that allows users with Import Content and Create Books permissions to upload a PHP polyglot file as a book cover.

🔗 参考:

9. CHROME-87.0.4280.66 🔥 `CVSS 4.3`

🎯 受影响:Chrome 87.0.4280.66 安全更新包含 1 个漏洞,其中最高 CVSS 4.3:Side-channel information leakage in graphics in Googl

📋 简介:Chrome 87.0.4280.66 安全更新包含 1 个漏洞,其中最高 CVSS 4.3:Side-channel information leakage in graphics in Google Chrome prior to 87.0.4280.66 allowed a remote attacker to leak cr。涉及 CVE:CVE-2020-16012。

🔗 参考:

10. CVE-2026-55484 `CVSS 7.5`

🎯 受影响:ALOS HTTP

📋 简介:ALOS HTTP is a Linux-first Go web framework and application server built around a custom networking stack.

🔗 参考:

---

新发现 232 条 · 热度升级 0 条 · 🔥=高热度/有 PoC · 🆙=昨日已推、今日热度升级

📊 GitHub 热榜

📊 GitHub 日榜 · 2026-08-30

1. tt-a1i/archify

📋 Agent skill for beautiful, verifiable architecture, workflow, sequence, data-flow, and lifecycle diagrams—self-contained HTML with motion and crisp export.

2. bilawalsidhu/gods-eye-view

📋 A spy satellite simulator in your browser, except the data is real. Live open source spatial intelligence on a photorealistic 3D globe.

3. K-Dense-AI/scientific-agent-skills

📋 Turn any AI agent into an AI Scientist. The #1 Agent Skills library for science, used by 190,000+ scientists worldwide. 165 ready-to-use validated skills plus 100+ scientific databases covering biology, chemistry, medicine, and drug discovery. Compatible with Cursor, Claude Code, Codex, Pi, Antigravity, and the open Agent Skills standard.

4. tailscale/tailcat

📋 like netcat, but over Tailscale's data plane, without Tailscale's control plane

5. THU-MAIC/OpenMAIC

📋 Open Multi-Agent Interactive Classroom — Get an immersive, multi-agent learning experience in just one click

6. p-e-w/heretic

📋 Fully automatic censorship removal for language models

7. bigskysoftware/htmx

📋 </> htmx - high power tools for HTML

8. JetBrains/go-modern-guidelines

📋 Help AI coding agents write modern Go

9. ComposioHQ/awesome-claude-skills

📋 A curated list of awesome Claude Skills, resources, and tools for customizing Claude AI workflows

10. calesthio/OpenMontage

📋 World's first open-source, agentic video production system. 12 production pipelines, 100+ tools, 700+ agent skill and production-knowledge files. Turn your AI coding assistant into a full video production studio.

🤖 AI 总结分析

今日整体形势:高危漏洞预警收录59条CRITICAL,风险偏高。热点集中在访问控制缺失、默认配置暴露与认证绕过,涉及MCP、流数据平台和打印管理;旧漏洞如vCenter、Nacos出现活跃利用迹象,技术趋势明显向AI/Agent相关基础设施蔓延。

漏洞预警中,CVE-2026-82456(argocd-mcp 0.8.0,CVSS 10)最值得警惕:配置ARGOCD_API_TOKEN后HTTP传输仍接受未认证MCP会话,等于把Argo CD编排能力暴露给匿名调用,直接放大Agent供应链风险。CVE-2026-82266(Redpanda 26.2.2,CVSS 9.8)同样高危,Admin API默认绑定0.0.0.0:9644且无需认证,未认证请求被当作超级用户,暴露即可能接管数据平台。此外,CVE-2026-81578(PaperCut MF/NG)访问控制漏洞和近期活跃的CVE-2021-21972(vCenter RCE)提示老漏洞与勒索路径仍在被利用。

安全情报源今日无新增条目,不等于威胁下降,漏洞预警仍是今天的主要风险输入。

GitHub热榜显示Agent技能库集中爆发:K-Dense-AI/scientific-agent-skills宣称超过19万科学家使用、提供165项技能,ComposioHQ/awesome-claude-skillsarchify都在扩展AI代理工作流,OpenMAIC提供多智能体课堂。这类工具普遍依赖MCP与外部API,今天argocd-mcp的未认证漏洞恰好说明该扩张可能快于安全加固。

行动建议:今天优先排查所有公网可达的argocd-mcpRedpanda实例,立即关闭默认无认证或收紧网络访问,并检查是否因配置ARGOCD_API_TOKEN而误暴露MCP端口。