Security Center
安全情报屋
报告类型 当前榜单
情报总数 80 条
板块条数 80 条
生成时间 09-01 00:00
📚 安全情报馆 · 2026-09-01
4 块

🛡️ 每日安全情报

🛡️ AI 安全情报日报 · 2026-09-01

_2026-09-01 · 共筛出 140 条 ≥4★_

1. 95.02%漏洞成功率 | 绿盟科技NSFOCUS AI斩获CyberGym全球第一 🔓 📄 ★★★★★

📋 绿盟君 2026-08-31 18:00 北京 以下文章来源于:绿盟科技 绿盟科技 绿盟科技 官方微信 见证中国AI安全力量 在AI安全能力国际权威基准测试 CyberGym 全球榜单中,绿盟科技自主研发的NSFOCUS AI漏洞挖掘智能体

2. AI_HACKING exploit 🔓 ★★★★★

📋 Exploit.

3. Artifactory 路径穿越:当 Docker 缓存撞上制品库边界 🔓 ★★★★★

📋 本文围绕JFrog Artifactory路径穿越漏洞(CVE-2026-66384)展开,指出该问题源于缓存 […]

4. CVE-2007-4559 exploit 🔓 ★★★★★

📋 Exploit for CVE-2007-4559. CVSS 9.8.

5. CVE-2008-5416 exploit 🔓 ★★★★★

📋 Exploit for CVE-2008-5416. CVSS 9.

6. CVE-2014-4140 exploit 🔓 ★★★★★

📋 Exploit for CVE-2014-4140. CVSS 4.3.

7. CVE-2017-9096-iText-XXE exploit 🔓 ★★★★★

📋 Exploit for CVE-2017-9096. CVSS 8.8.

8. CVE-2018-16763 exploit 🔓 ★★★★★

📋 Exploit for CVE-2018-16763. CVSS 9.8.

9. CVE-2018-1999002 exploit 🔓 ★★★★★

📋 Exploit for CVE-2018-1999002. CVSS 7.5.

10. CVE-2019-0986 exploit 🔓 ★★★★★

📋 Exploit for CVE-2019-0986. CVSS 7.1.

11. CVE-2019-1221 exploit 🔓 ★★★★★

📋 Exploit for CVE-2019-1221. CVSS 7.6.

12. CVE-2019-13633 exploit 🔓 ★★★★★

📋 Exploit for CVE-2019-13633. CVSS 6.1.

13. CVE-2019-14439 exploit 🔓 ★★★★★

📋 Exploit for CVE-2019-14439. CVSS 7.5.

14. CVE-2019-9766 exploit 🔓 ★★★★★

📋 Exploit for CVE-2019-9766. CVSS 7.8.

15. CVE-2020-0609 exploit 🔓 ★★★★★

📋 Exploit for CVE-2020-0609. CVSS 10.

---

其他 125 条

🚨 漏洞预警

🔴 CRITICAL · 44 条

1. CVE-2026-73819 `CVSS 9.8`

🎯 受影响:The affected Ebyte

📋 简介:The affected Ebyte

product's vendor configuration utility permits access to administrative

functions without verifying the operator's identity under certain

credential conditions.

🔗 参考:

2. CVE-2026-82874 `CVSS 9.9`

🎯 受影响:ToolJet

📋 简介:ToolJet before v3.16.208 fails to validate that authenticated users belong to the organization specified in the organizationId path parameter of tooljet-db endpoints, allowing any Builder user to read, modify, and delete tables across tenant boundaries.

🔗 参考:

3. CVE-2026-82870 `CVSS 9.6`

🎯 受影响:ToolJet

📋 简介:ToolJet before v3.16.208 fails to validate organizationId ownership in database write and destroy routes, allowing any builder-role user to create, alter, or drop tables in other organizations' databases.

🔗 参考:

4. CVE-2026-77966 `CVSS 8.8`

🎯 受影响:The affected Ebyte

📋 简介:The affected Ebyte

product does not provide separation between limited and administrative

management functions.

🔗 参考:

5. CVE-2026-82639 `CVSS 8.7`

🎯 受影响:NextChat

📋 简介:NextChat versions from 2.15.8 through 2.16.1 contain an improper URL validation vulnerability in the proxy endpoint that allows attackers to obtain the server's OpenAI API key.

🔗 参考:

6. CVE-2026-82863 `CVSS 8.7`

🎯 受影响:@hulumi/baseline versions before 1.3.2 fail to fully detect CloudTrail selector tampering events, re

📋 简介:@hulumi/baseline versions before 1.3.2 fail to fully detect CloudTrail selector tampering events, reducing audit logging configuration change coverage.

🔗 参考:

7. CVE-2026-82645 `CVSS 9.2`

🎯 受影响:AVideo (current commit e01e41ecc and earlier) exposes stream credentials through the plugin/Live/vie

📋 简介:AVideo (current commit e01e41ecc and earlier) exposes stream credentials through the plugin/Live/view/Live_restreams/getLiveKey.json.php endpoint.

🔗 参考:

8. CVE-2026-79748 `CVSS 9.9`

🎯 受影响:MCPHub

📋 简介:MCPHub is a unified hub for centrally managing and dynamically orchestrating multiple MCP servers/APIs into separate endpoints with flexible routing strategies.

🔗 参考:

9. CVE-2026-82954 `CVSS 9.9`

🎯 受影响:A vulnerability was detected in Dokploy up to 0.29.7. This issue affects the function writeTraefikConfigInPath of the file packages/server/src/utils/traefik/application.ts of the component Settings. T

📋 简介:A vulnerability was detected in Dokploy up to 0.29.7.

🔗 参考:

10. CVE-2026-82854 `CVSS 9.8`

🎯 受影响:Nodemailer

📋 简介:Nodemailer before 8.0.4 is vulnerable to SMTP command injection through the unsanitized envelope.size parameter.

🔗 参考:

11. CVE-2026-82856 `CVSS 9.8`

🎯 受影响:@hulumi/policies versions before 1.3.2 fail to properly validate set-qualified AWS IAM condition ope

📋 简介:@hulumi/policies versions before 1.3.2 fail to properly validate set-qualified AWS IAM condition operators in GitHub OIDC trust policies.

🔗 参考:

12. CVE-2026-81780 `CVSS 10`

🎯 受影响:Unauthenticated Arbitrary File Upload in Hash Form <= 1.4.2 versions.

📋 简介:Unauthenticated Arbitrary File Upload in Hash Form <= 1.4.2 versions.

🔗 参考:

13. CVE-2026-19410 `CVSS 9.4`

🎯 受影响:An Incorrect Authorization vulnerability in GitHub Trigger Comment Control in Google Cloud Build

📋 简介:An Incorrect Authorization vulnerability in GitHub Trigger Comment Control in Google Cloud Build prior to 2026-06-24 on Google Cloud Platform allows a remote attacker to execute unreviewed code in the build environment using webhook suppression.

🔗 参考:

14. CVE-2026-58574 `CVSS 9.8`

🎯 受影响:Dell PowerStore

📋 简介:Dell PowerStore contains a Missing Authentication for Critical Function vulnerability.

🔗 参考:

15. CVE-2026-59111 `CVSS 9.3`

🎯 受影响:Improper neutralization of special elements used in an OS command ('OS command injection') vulnerabi

📋 简介:Improper neutralization of special elements used in an OS command ('OS command injection') vulnerability in Digitální a informační agentura (DIA) eObčanka-Identifikace on MacOS enables an attacker to register a custom URL scheme (czeeopauth://) for parameterized application ex...

🔗 参考:

16. CVE-2026-82226 `CVSS 9.8`

🎯 受影响:Unauthenticated PHP Object Injection in Tickera <= 3.6.0.2 versions.

📋 简介:Unauthenticated PHP Object Injection in Tickera <= 3.6.0.2 versions.

🔗 参考:

17. CVE-2026-82807 `CVSS 9.3`

🎯 受影响:A vulnerability was determined in ieungSoft Ultra RAMDisk Pro 1.82. This issue affects some unknown

📋 简介:A vulnerability was determined in ieungSoft Ultra RAMDisk Pro 1.82.

🔗 参考:

18. CVE-2026-81293 `CVSS 9.3`

🎯 受影响:Unauthenticated SQL Injection in WP Data Access <= 5.5.81 versions.

📋 简介:Unauthenticated SQL Injection in WP Data Access <= 5.5.81 versions.

🔗 参考:

19. CVE-2026-81756 `CVSS 9.3`

🎯 受影响:Unauthenticated SQL Injection in Smart Marketing SMS and Newsletters Forms <= 5.1.24 versions.

📋 简介:Unauthenticated SQL Injection in Smart Marketing SMS and Newsletters Forms <= 5.1.24 versions.

🔗 参考:

20. CVE-2026-81763 `CVSS 9.3`

🎯 受影响:Unauthenticated SQL Injection in Throws SPAM Away <= 3.8.2 versions.

📋 简介:Unauthenticated SQL Injection in Throws SPAM Away <= 3.8.2 versions.

🔗 参考:

21. CVE-2026-82857 `CVSS 9.8`

🎯 受影响:hulumi

📋 简介:hulumi versions before v1.3.2 contain a privilege escalation vulnerability in the weekly integration IAM policy that allows role lifecycle operations on af-e2e-* roles without sufficient boundary restrictions.

🔗 参考:

22. CVE-2026-53552 `CVSS 9.6`

🎯 受影响:Goploy

📋 简介:Goploy is an open-source automation deployment system.

🔗 参考:

23. CVE-2026-81779 `CVSS 10`

🎯 受影响:Improper Validation of Specified Quantity in Input vulnerability in Silk Themes Newspapers X

📋 简介:Improper Validation of Specified Quantity in Input vulnerability in Silk Themes Newspapers X allows Malicious Software Implanted.

🔗 参考:

24. CVE-2026-82970 `CVSS 10`

🎯 受影响:Unrestricted Upload of File with Dangerous Type vulnerability in WP Legal Pages WP Cookie Notice for

📋 简介:Unrestricted Upload of File with Dangerous Type vulnerability in WP Legal Pages WP Cookie Notice for GDPR, CCPA & ePrivacy Consent allows Using Malicious Files.

🔗 参考:

25. CVE-2026-82971 `CVSS 10`

🎯 受影响:A vulnerability was determined in QVidium Opera11 3.3.2a26-Ax4x-opera11. This affects an unknown par

📋 简介:A vulnerability was determined in QVidium Opera11 3.3.2a26-Ax4x-opera11.

🔗 参考:

26. CVE-2026-82689 `CVSS 9.9`

🎯 受影响:A vulnerability was detected in D-Link DNS-320L, DNS-327L, DNS-340L and DNS-345 up to 20260717. Affe

📋 简介:A vulnerability was detected in D-Link DNS-320L, DNS-327L, DNS-340L and DNS-345 up to 20260717.

🔗 参考:

27. CVE-2026-82692 `CVSS 9.9`

🎯 受影响:A vulnerability was found in D-Link DNS-340L and DNS-345 up to 20260717. This affects an unknown par

📋 简介:A vulnerability was found in D-Link DNS-340L and DNS-345 up to 20260717.

🔗 参考:

28. CVE-2026-83524 `CVSS 9.9`

🎯 受影响:A security vulnerability has been detected in RedPort Optimizer wXa-203, Optimizer wXa-213 and Optim

📋 简介:A security vulnerability has been detected in RedPort Optimizer wXa-203, Optimizer wXa-213 and Optimizer wXa-223 up to 20260704.

🔗 参考:

29. CVE-2026-76133 `CVSS 9.8`

🎯 受影响:The affected Ebyte

📋 简介:The affected Ebyte

product

uses a deprecated hashing algorithm in an authentication-related

operation.

🔗 参考:

30. CVE-2026-82855 `CVSS 9.8`

🎯 受影响:@hulumi/policies versions before 1.3.2 contain an evidence validation bypass vulnerability in Cloudf

📋 简介:@hulumi/policies versions before 1.3.2 contain an evidence validation bypass vulnerability in Cloudflare and deployment-governance validators that allows attackers to suppress violations by submitting unrelated compliant evidence.

🔗 参考:

31. CVE-2026-82858 `CVSS 9.8`

🎯 受影响:@hulumi/drift versions before 1.3.2 accept externally supplied execute plans without sufficient prov

📋 简介:@hulumi/drift versions before 1.3.2 accept externally supplied execute plans without sufficient provenance validation, allowing untrusted reconciliation input to be treated as trusted.

🔗 参考:

32. CVE-2026-82859 `CVSS 9.8`

🎯 受影响:hulumi

📋 简介:hulumi versions before v1.3.2 contain a deployment SCP template that allows tag-on-create bypasses for hulumi:iac-role protections.

🔗 参考:

33. CVE-2026-82860 `CVSS 9.8`

🎯 受影响:@hulumi/policies versions before 1.3.2 fail to fully inspect inline and attached IAM policy evidence

📋 简介:@hulumi/policies versions before 1.3.2 fail to fully inspect inline and attached IAM policy evidence for the administrator-policy guardrail.

🔗 参考:

34. CVE-2026-49003 `CVSS 9.6`

🎯 受影响:Attackers can exploit command injection vulnerabilities to delete core system runtime files, causing

📋 简介:Attackers can exploit command injection vulnerabilities to delete core system runtime files, causing the monitoring module to crash and become paralyzed; simultaneously, they can obtain root privileges to steal configuration passwords such as SNMP, thereby tampering with criti...

🔗 参考:

35. CVE-2026-82688 `CVSS 9.4`

🎯 受影响:A security vulnerability has been detected in D-Link DNS-340L and DNS-345 1.01B04/1.03B06/1.04.B02/1

📋 简介:A security vulnerability has been detected in D-Link DNS-340L and DNS-345 1.01B04/1.03B06/1.04.B02/1.05b04.

🔗 参考:

36. CVE-2026-82690 `CVSS 9.4`

🎯 受影响:A flaw has been found in D-Link DNS-327L and DNS-340L up to 20260717. Affected by this vulnerability

📋 简介:A flaw has been found in D-Link DNS-327L and DNS-340L up to 20260717.

🔗 参考:

37. CVE-2026-82691 `CVSS 9.4`

🎯 受影响:A vulnerability has been found in D-Link DNS-320L, DNS-327L, DNS-340L and DNS-345 up to 20260717. Af

📋 简介:A vulnerability has been found in D-Link DNS-320L, DNS-327L, DNS-340L and DNS-345 up to 20260717.

🔗 参考:

38. CVE-2026-82628 `CVSS 9.3`

🎯 受影响:A vulnerability was found in Colorful iGameCenter 2.0.0.81. This vulnerability affects the function

📋 简介:A vulnerability was found in Colorful iGameCenter 2.0.0.81.

🔗 参考:

39. CVE-2026-82653 `CVSS 9.3`

🎯 受影响:SiYuan

📋 简介:SiYuan before v3.8.1 contains a stored cross-site scripting vulnerability in confirmDialog() where unescaped package names and notebook names are interpolated directly into innerHTML assignments.

🔗 参考:

40. CVE-2026-82654 `CVSS 9.3`

🎯 受影响:SiYuan

📋 简介:SiYuan before v3.8.1 fails to properly escape block name, alias, and memo fields in hint, backlink, and breadcrumb rendering functions.

🔗 参考:

41. CVE-2026-82876 `CVSS 9.3`

🎯 受影响:Phison PS3111-S11 controller firmware verifies RSA signatures using a public modulus embedded within

📋 简介:Phison PS3111-S11 controller firmware verifies RSA signatures using a public modulus embedded within the firmware image itself rather than anchored in immutable storage.

🔗 参考:

42. CVE-2026-82908 `CVSS 9.3`

🎯 受影响:A vulnerability was found in MSI Dragon Center up to 2.0.155.0. Affected by this vulnerability

📋 简介:A vulnerability was found in MSI Dragon Center up to 2.0.155.0.

🔗 参考:

43. CVE-2026-82872 `CVSS 9.1`

🎯 受影响:ToolJet

📋 简介:ToolJet before v3.16.208 fails to validate that the path organizationId matches the authenticated user's workspace before performing ToolJet DB table operations.

🔗 参考:

44. CVE-2026-82680 `CVSS 9`

🎯 受影响:A weakness has been identified in D-Link DSM-G600 1.01. This affects an unknown function of the file

📋 简介:A weakness has been identified in D-Link DSM-G600 1.01.

🔗 参考:

🟠 HIGH · 10 条

1. CVE-2026-56718 `CVSS 8.7`

🎯 受影响:AJCloud AJY IPC firmware

📋 简介:AJCloud AJY IPC firmware prior to version 01.10715.11.37 contains a path traversal vulnerability in the jdbhttpd web service that allows unauthenticated remote attackers to read arbitrary files with root privileges by supplying path traversal sequences in the HTTP request URI.

🔗 参考:

2. CVE-2026-81636 `CVSS 8.7`

🎯 受影响:Allocation of Resources Without Limits or Throttling vulnerability in ash-project ash_graphql allows

📋 简介:Allocation of Resources Without Limits or Throttling vulnerability in ash-project ash_graphql allows an unauthenticated client to bypass the configured GraphQL query-complexity limit and force an unbounded database read.

🔗 参考:

3. CVE-2026-82638 `CVSS 8.7`

🎯 受影响:jina-ai reader disables its private-address guard outside Google Cloud deployments, allowing unauthe

📋 简介:jina-ai reader disables its private-address guard outside Google Cloud deployments, allowing unauthenticated attackers to perform server-side request forgery.

🔗 参考:

4. CVE-2026-82635 `CVSS 8.8`

🎯 受影响:Pake

📋 简介:Pake before 3.13.1 joins the JavaScript-supplied filename for the download_file Tauri command onto the user's Downloads directory with no sanitization.

🔗 参考:

5. CVE-2026-82641 `CVSS 8.8`

🎯 受影响:keploy

📋 简介:keploy versions 3.1.0 through 3.6.25 bind the agent control-plane HTTP server to all interfaces without authentication, exposing endpoints that stream TLS session keys and traffic data.

🔗 参考:

6. CVE-2026-82642 `CVSS 8.8`

🎯 受影响:Readest

📋 简介:Readest is an open-source e-book reader built on Tauri.

🔗 参考:

7. CVE-2026-83497 `CVSS 8.8`

🎯 受影响:Unrestricted deserialization of untrusted data in the cursor pagination component in the OpenSearch SQL plugin

📋 简介:Unrestricted deserialization of untrusted data in the cursor pagination component in the OpenSearch SQL plugin allows a remote authenticated user with basic read/search permissions to execute arbitrary code on the server by sending a crafted cursor parameter to the plugins/sql...

🔗 参考:

8. CVE-2026-82880 `CVSS 8.7`

🎯 受影响:YaCy Search Server through 1.941

📋 简介:YaCy Search Server through 1.941 contains an XML external entity injection vulnerability in SVG, FreeMind, and OpenSearch parsers that fail to disable external entity resolution.

🔗 参考:

9. CVE-2026-81889 `CVSS 8.6`

🎯 受影响:elFinder

📋 简介:elFinder is an open-source file manager for web, written in JavaScript using jQuery UI.

🔗 参考:

10. CVE-2026-77956 `CVSS 8.9`

🎯 受影响:Improper Control of Generation of Code (Code Injection) vulnerability in ash-project ash_ai allows a

📋 简介:Improper Control of Generation of Code (Code Injection) vulnerability in ash-project ash_ai allows a remote, unauthenticated client to execute arbitrary Elixir code.

🔗 参考:

---

新发现 160 条 · 热度升级 0 条 · 🔥=高热度/有 PoC · 🆙=昨日已推、今日热度升级

📊 GitHub 热榜

🏆 GitHub 月榜 · 2026-09(本月第一个工作日)

1. omacom/omarchy

📋 Beautiful, Modern &amp; Opinionated Linux

2. freestylefly/awesome-gpt-image-2

📋 Prompt as Code | GPT-Image2 工业级提示词引擎与模板库,530+ 个案例逆向工程,20+ 套工业级模板,并提炼出Skills,持续更新中

3. TencentCloud/TencentDB-Agent-Memory

📋 TencentDB Agent Memory is a team-level memory hub for AI Agents — turning conversations, docs, and code into four reusable memory assets (Chat Memory, Skill, LLM-Wiki, Code-Graph) that are governed, shared, and equipped across agents and frameworks.

4. anthropics/claude-plugins-community

📋 Community plugin marketplace for Claude Cowork and Claude Code. Read-only mirror — submit plugins at clau.de/plugin-directory-submission.

5. firecrawl/pdf-inspector

📋 Fast Rust library for PDF inspection, classification, and text extraction. Intelligently detects scanned vs text-based PDFs to enable smart routing decisions.

6. tt-a1i/archify

📋 Agent skill for beautiful, verifiable architecture, workflow, sequence, data-flow, and lifecycle diagrams—self-contained HTML with motion and crisp export.

7. cactus-compute/needle

📋 14MB foundation model for tiny devices; phones, wearables, smart home, and robots.

8. volcengine/OpenViking

📋 Self-evolving Context Database for AI Agents. Unify Agent Memory, Knowledge RAG and Skills.

9. AprilNEA/OpenLogi

📋 ⚡️A native, local-first alternative to Logitech Options+, written in Rust 🦀 — remap buttons, DPI, and SmartShift over HID++. No account, no telemetry.

10. zhaoxuya520/reverse-skill

📋 Reverse Engineering / Authorized Penetration Testing / Security Research Skill Router Pack AI-powered routing + On-demand toolchain bootstrapping + Self-evolving knowledge base Supports Claude Code, Kiro, Cursor, Cline, and other AI coding clients 逆向/渗透/安全技能路由包 - AI 自动路由 + 按需自举工具链 + 自动进化经验库 | 支持 Claude Code / Kiro / Cursor / Cline 等代码 AI 客户端

🤖 AI 总结分析

今日整体形势呈现“Web 应用高危漏洞集中爆发 + AI Agent 基础设施风险抬头”的双重特征:漏洞预警列出 10 条 CVSS≥7.5 记录,其中 8 条为满分,热点集中在 WordPress 插件未授权文件上传、路由器/物联网设备认证缺失与命令注入,同时 MCPHub 的 MCP 管理 API 暴露 9.9 分漏洞。GitHub 热榜上 AI Agent 插件、记忆中枢与轻量模型持续升温,风险面正从传统 Web 向智能体基础设施扩展。

在漏洞预警源中,最值得关注的是 CVE-2026-81780(Hash Form ≤1.4.2 未授权任意文件上传)与 CVE-2026-82970(WP Cookie Notice 插件任意文件上传),两者均为 CVSS 10 且影响广泛 WordPress 站点,攻击者可植入恶意文件直接控制站点。另一个应重视的是 CVE-2026-79748,影响 MCPHub 0.12.15 之前版本的 API 路径,属于新兴 AI Agent 编排层的高危暴露。

今日安全情报源因 FreshRSS 认证返回 401 未授权导致拉取失败,暂无新增情报产出;这一故障本身意味着监控链路出现认证失效,应尽快修复,否则可能形成威胁情报盲区。

GitHub 热榜中,anthropics/claude-plugins-community 社区插件市场和 TencentCloud/TencentDB-Agent-Memoryvolcengine/OpenViking 等 Agent 记忆与技能中枢项目热度明显,说明 AI Agent 组件正快速生态化,但集中管理插件、记忆和技能也会扩大供应链与数据泄露面,与 MCPHub 漏洞形成呼应;firecrawl/pdf-inspector 则体现对 PDF 恶意文件检测的实际需求。

今天应优先核查并升级 Hash FormWP Cookie Notice 插件、将 MCPHub 更新至 0.12.15 以上,并限制这些上传接口与 MCP API 的公网暴露,防止满分漏洞被批量利用。