🛡️ 每日安全情报
🛡️ AI 安全情报日报 · 2026-09-01
_2026-09-01 · 共筛出 140 条 ≥4★_
1. 95.02%漏洞成功率 | 绿盟科技NSFOCUS AI斩获CyberGym全球第一 🔓 📄 ★★★★★
📋 绿盟君 2026-08-31 18:00 北京 以下文章来源于:绿盟科技 绿盟科技 绿盟科技 官方微信 见证中国AI安全力量 在AI安全能力国际权威基准测试 CyberGym 全球榜单中,绿盟科技自主研发的NSFOCUS AI漏洞挖掘智能体
2. AI_HACKING exploit 🔓 ★★★★★
📋 Exploit.
3. Artifactory 路径穿越:当 Docker 缓存撞上制品库边界 🔓 ★★★★★
📋 本文围绕JFrog Artifactory路径穿越漏洞(CVE-2026-66384)展开,指出该问题源于缓存 […]
4. CVE-2007-4559 exploit 🔓 ★★★★★
📋 Exploit for CVE-2007-4559. CVSS 9.8.
5. CVE-2008-5416 exploit 🔓 ★★★★★
📋 Exploit for CVE-2008-5416. CVSS 9.
6. CVE-2014-4140 exploit 🔓 ★★★★★
📋 Exploit for CVE-2014-4140. CVSS 4.3.
7. CVE-2017-9096-iText-XXE exploit 🔓 ★★★★★
📋 Exploit for CVE-2017-9096. CVSS 8.8.
8. CVE-2018-16763 exploit 🔓 ★★★★★
📋 Exploit for CVE-2018-16763. CVSS 9.8.
9. CVE-2018-1999002 exploit 🔓 ★★★★★
📋 Exploit for CVE-2018-1999002. CVSS 7.5.
10. CVE-2019-0986 exploit 🔓 ★★★★★
📋 Exploit for CVE-2019-0986. CVSS 7.1.
11. CVE-2019-1221 exploit 🔓 ★★★★★
📋 Exploit for CVE-2019-1221. CVSS 7.6.
12. CVE-2019-13633 exploit 🔓 ★★★★★
📋 Exploit for CVE-2019-13633. CVSS 6.1.
13. CVE-2019-14439 exploit 🔓 ★★★★★
📋 Exploit for CVE-2019-14439. CVSS 7.5.
14. CVE-2019-9766 exploit 🔓 ★★★★★
📋 Exploit for CVE-2019-9766. CVSS 7.8.
15. CVE-2020-0609 exploit 🔓 ★★★★★
📋 Exploit for CVE-2020-0609. CVSS 10.
---
其他 125 条:
- CVE-2020-0688 exploit (5★)
- CVE-2020-1472 exploit (5★)
- CVE-2020-1956 exploit (5★)
- CVE-2020-5902-F5BigIP exploit (5★)
- CVE-2020-8209 exploit (5★)
- CVE-2020-9496 exploit (5★)
- CVE-2021-26855-exploit-Exchange (5★)
- CVE-2021-3131 exploit (5★)
- CVE-2021-3156-Exp exploit (5★)
- CVE-2021-32724-Target exploit (5★)
- CVE-2021-33044 exploit (5★)
- CVE-2022-0778-POC exploit (5★)
- CVE-2022-37706 exploit (5★)
- CVE-2022-41080 exploit (5★)
- CVE-2023-0669 exploit (5★)
- CVE-2023-23192 exploit (5★)
- CVE-2023-24055_PoC exploit (5★)
- CVE-2023-25157 exploit (5★)
- CVE-2023-25194 exploit (5★)
- CVE-2023-26984 exploit (5★)
- CVE-2023-27524 exploit (5★)
- CVE-2023-30533 exploit (5★)
- CVE-2023-32243 exploit (5★)
- CVE-2023-33246 exploit (5★)
- CVE-2023-38831 exploit (5★)
- CVE-2023-43346-Quick-CMS-Stored-XSS---Languages-Backend exploit (5★)
- CVE-2023-46818-Exploit (5★)
- CVE-2023-49970 exploit (5★)
- CVE-2024-13513.py exploit (5★)
- CVE-2024-1512 exploit (5★)
- CVE-2024-25641---Cacti exploit (5★)
- CVE-2024-28000 exploit (5★)
- CVE-2024-28515 exploit (5★)
- CVE-2024-29269 exploit (5★)
- CVE-2024-32002 exploit (5★)
- CVE-2024-34222 exploit (5★)
- CVE-2024-4157-SSRF-RCE-Reverse-Shell exploit (5★)
- CVE-2024-42009-PoC exploit (5★)
- CVE-2024-4295-Poc exploit (5★)
- CVE-2024-49138-POC exploit (5★)
- CVE-2024-5084 exploit (5★)
- CVE-2024-50986 exploit (5★)
- CVE-2024-6028-Poc exploit (5★)
- CVE-2024-6387 exploit (5★)
- CVE-2025-24813 exploit (5★)
- CVE-2025-27591-Below exploit (5★)
- CVE-2025-3248 exploit (5★)
- CVE-2025-49113-Roundcube_1.6.10 exploit (5★)
- CVE-2025-52399-SQLi-Institute-of-Current-Students exploit (5★)
- CVE-2025-53770 exploit (5★)
- CVE-2025-54782 exploit (5★)
- CVE-2025-59287 exploit (5★)
- CVE-2025-8110 exploit (5★)
- CVE-2026-31278 exploit (5★)
- CVE-2026-5076 exploit (5★)
- Claude-ExternalPentest exploit (5★)
- Cobalt Strike插件之CVE-2020-0796提权脚本开发 (5★)
- DLL_Injection_On_VLC exploit (5★)
- Dnstracer-1.9-Fix exploit (5★)
- Exploit for Classic Buffer Overflow in Cisco Adaptive_Security_Appliance_Software (5★)
- Exploit for Code Injection in Redhat Richfaces (5★)
- Exploit for Cross-site Scripting in Interzen Zencrm (5★)
- FBIntelPy exploit (5★)
- FiberBreak exploit (5★)
- Follina-CVE-2022-30190-POC exploit (5★)
- Ghost-Path-Traversal-CVE-2023-32235- exploit (5★)
- MSDT_CVE-2022-30190 exploit (5★)
- MSF_PassSpray_Wordlist_Generator exploit (5★)
- Mini_httpd-CVE-2018-18778 exploit (5★)
- Next.js 爆出新漏洞,不用登录实现命令执行(POC已公开) (5★)
- PHP filters和CVE-2024-2961组合:从文件读取到RCE (5★)
- Pyrescom-Termod-PoC exploit (5★)
- Quartz-1 exploit (5★)
- React2Shell exploit (5★)
- Rusty-Playground exploit (5★)
- SMBGhost_AutomateExploitation (5★)
- SSRF漏洞基础 (5★)
- SafeVault exploit (5★)
- Satellian-CVE-2020-7980 exploit (5★)
- ServiceNow 三个满分漏洞可使未认证攻击者执行代码和 SQL (5★)
- ShatteredFTP exploit (5★)
- TFC-Chrome-v8-bug-CVE-2021-38001-poc exploit (5★)
- The Windows Security App (5★)
- Trust-Decision-Security exploit (5★)
- Vulnerable-to-Debian-OpenSSL-bug-CVE-2008-0166 exploit (5★)
- Weblogic IIOP反序列化漏洞CVE-2020-2551复现 (5★)
- Windows本地提权漏洞CVE-2020-1313复现 (5★)
- browser-xpi-malware-scanner exploit (5★)
- coeus-ci exploit (5★)
- cve-2016-0040 exploit (5★)
- cve-2017-7494 exploit (5★)
- cve-2019-5736-poc exploit (5★)
- cve-2021-33909 exploit (5★)
- cve-2022-44268 exploit (5★)
- cve-2023-41564-research exploit (5★)
- cve-2025-39682 exploit (5★)
- dlink-dir610-exploits (5★)
- external_aac_AOSP10_r33_CVE-2022-20130 exploit (5★)
- external_expact_AOSP10_r33_CVE-2022-25315 exploit (5★)
- frameworks_native_AOSP-10_r33_CVE-2023-21118 exploit (5★)
- google-poc exploit (5★)
- hashID exploit (5★)
- imagemagick-CVE-2022-44268 exploit (5★)
- insect exploit (5★)
- js2py-Sandbox-Escape-CVE-2024-28397-RCE exploit (5★)
- log4j-finder exploit (5★)
- offsec-lab exploit (5★)
- osv-scanner exploit (5★)
- platform_frameworks_base_CVE-2023-20918 exploit (5★)
- redteam-skill exploit (5★)
- s2-067-CVE-2024-53677 exploit (5★)
- safeshell exploit (5★)
- sudo_exploit (5★)
- tac_plus-pre-auth-rce exploit (5★)
- voron-crypto exploit (5★)
- xwiki-15.10.8-reverse-shell-cve-2025-24893 exploit (5★)
- 每日安全动态推送(26/8/31) (5★)
- 紧急安全预警|(腾达)Tenda HG10曝CVSS 10.0未认证RCE漏洞,公开PoC可获取Root权限 (5★)
- 美酝酿对华算力“云端管制”,管的竟是东南亚数据中心? (5★)
- Introducing Adaptive Intelligence: undermining the economics of every bot attack (4★)
- The Hugging Face hack could indicate cultural issues at OpenAI (4★)
- ValleyRAT Backdoor Hides in Signed Adware That Users Add to Antivirus Exclusions (4★)
- a16z押注“机器时代”:AI的瓶颈,正在向模型以下转移 (4★)
- 全新OpenClaw 2.0发布:龙虾史上最大更新,已无人关心 (4★)
- 大模型没有秘笈:腾讯混元4背后站着GLM-5核心研究员 (4★)
🚨 漏洞预警
🔴 CRITICAL · 44 条
1. CVE-2026-73819 `CVSS 9.8`
🎯 受影响:The affected Ebyte
📋 简介:The affected Ebyte
product's vendor configuration utility permits access to administrative
functions without verifying the operator's identity under certain
credential conditions.
🔗 参考:
- https://nvd.nist.gov/vuln/detail/CVE-2026-73819
- https://www.cisa.gov/news-events/ics-advisories/icsa-26-237-06
- https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-237-06.json
2. CVE-2026-82874 `CVSS 9.9`
🎯 受影响:ToolJet
📋 简介:ToolJet before v3.16.208 fails to validate that authenticated users belong to the organization specified in the organizationId path parameter of tooljet-db endpoints, allowing any Builder user to read, modify, and delete tables across tenant boundaries.
🔗 参考:
- https://nvd.nist.gov/vuln/detail/CVE-2026-82874
- https://github.com/ToolJet/ToolJet/security/advisories/GHSA-w3hx-rg9g-mw5c
- https://www.vulncheck.com/advisories/tooljet-before-3.16.208-cross-tenant-authorization-bypass-via-tooljet-db
3. CVE-2026-82870 `CVSS 9.6`
🎯 受影响:ToolJet
📋 简介:ToolJet before v3.16.208 fails to validate organizationId ownership in database write and destroy routes, allowing any builder-role user to create, alter, or drop tables in other organizations' databases.
🔗 参考:
- https://nvd.nist.gov/vuln/detail/CVE-2026-82870
- https://github.com/ToolJet/ToolJet/security/advisories/GHSA-xr3w-r926-xfmm
- https://www.vulncheck.com/advisories/tooljet-before-3.16.208-cross-tenant-database-manipulation
4. CVE-2026-77966 `CVSS 8.8`
🎯 受影响:The affected Ebyte
📋 简介:The affected Ebyte
product does not provide separation between limited and administrative
management functions.
🔗 参考:
- https://nvd.nist.gov/vuln/detail/CVE-2026-77966
- https://www.cisa.gov/news-events/ics-advisories/icsa-26-237-06
- https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-237-06.json
5. CVE-2026-82639 `CVSS 8.7`
🎯 受影响:NextChat
📋 简介:NextChat versions from 2.15.8 through 2.16.1 contain an improper URL validation vulnerability in the proxy endpoint that allows attackers to obtain the server's OpenAI API key.
🔗 参考:
- https://nvd.nist.gov/vuln/detail/CVE-2026-82639
- https://github.com/ChatGPTNextWeb/NextChat/issues/6814
- https://github.com/ChatGPTNextWeb/NextChat
- https://github.com/ChatGPTNextWeb/NextChat/blob/v2.16.1/app/api/proxy.ts
- https://www.vulncheck.com/advisories/nextchat-2.15.8-through-2.16.1-openai-api-key-disclosure
6. CVE-2026-82863 `CVSS 8.7`
🎯 受影响:@hulumi/baseline versions before 1.3.2 fail to fully detect CloudTrail selector tampering events, re
📋 简介:@hulumi/baseline versions before 1.3.2 fail to fully detect CloudTrail selector tampering events, reducing audit logging configuration change coverage.
🔗 参考:
- https://nvd.nist.gov/vuln/detail/CVE-2026-82863
- https://github.com/kerberosmansour/hulumi/security/advisories/GHSA-gfp8-mp24-5vxg
- https://www.vulncheck.com/advisories/hulumi-baseline-before-1.3.2-cloudtrail-selector-tampering-detection
7. CVE-2026-82645 `CVSS 9.2`
🎯 受影响:AVideo (current commit e01e41ecc and earlier) exposes stream credentials through the plugin/Live/vie
📋 简介:AVideo (current commit e01e41ecc and earlier) exposes stream credentials through the plugin/Live/view/Live_restreams/getLiveKey.json.php endpoint.
🔗 参考:
- https://nvd.nist.gov/vuln/detail/CVE-2026-82645
- https://github.com/WWBN/AVideo/security/advisories/GHSA-c4w3-h888-7ccv
- https://www.vulncheck.com/advisories/avideo-unauthenticated-stream-credential-disclosure-via-forgeable-token
8. CVE-2026-79748 `CVSS 9.9`
🎯 受影响:MCPHub
📋 简介:MCPHub is a unified hub for centrally managing and dynamically orchestrating multiple MCP servers/APIs into separate endpoints with flexible routing strategies.
🔗 参考:
- https://nvd.nist.gov/vuln/detail/CVE-2026-79748
- https://github.com/samanhappy/mcphub/security/advisories/GHSA-mx89-jjx9-gjr8
- https://github.com/samanhappy/mcphub/pull/770
- https://github.com/samanhappy/mcphub/releases/tag/v0.12.15
9. CVE-2026-82954 `CVSS 9.9`
🎯 受影响:A vulnerability was detected in Dokploy up to 0.29.7. This issue affects the function writeTraefikConfigInPath of the file packages/server/src/utils/traefik/application.ts of the component Settings. T
📋 简介:A vulnerability was detected in Dokploy up to 0.29.7.
🔗 参考:
- https://nvd.nist.gov/vuln/detail/CVE-2026-82954
- https://vuldb.com/vuln/397303
- https://vuldb.com/vuln/397303/cti
- https://vuldb.com/cve/CVE-2026-82954
- https://vuldb.com/submit/879844
10. CVE-2026-82854 `CVSS 9.8`
🎯 受影响:Nodemailer
📋 简介:Nodemailer before 8.0.4 is vulnerable to SMTP command injection through the unsanitized envelope.size parameter.
🔗 参考:
- https://nvd.nist.gov/vuln/detail/CVE-2026-82854
- https://github.com/nodemailer/nodemailer/security/advisories/GHSA-c7w3-x93f-qmm8
- https://www.vulncheck.com/advisories/nodemailer-before-8.0.3-smtp-command-injection-via-envelope-size
11. CVE-2026-82856 `CVSS 9.8`
🎯 受影响:@hulumi/policies versions before 1.3.2 fail to properly validate set-qualified AWS IAM condition ope
📋 简介:@hulumi/policies versions before 1.3.2 fail to properly validate set-qualified AWS IAM condition operators in GitHub OIDC trust policies.
🔗 参考:
- https://nvd.nist.gov/vuln/detail/CVE-2026-82856
- https://github.com/kerberosmansour/hulumi/security/advisories/GHSA-q2f7-m237-v562
- https://www.vulncheck.com/advisories/hulumi-policies-before-1.3.2-oidc-trust-policy-bypass
12. CVE-2026-81780 `CVSS 10`
🎯 受影响:Unauthenticated Arbitrary File Upload in Hash Form <= 1.4.2 versions.
📋 简介:Unauthenticated Arbitrary File Upload in Hash Form <= 1.4.2 versions.
🔗 参考:
- https://nvd.nist.gov/vuln/detail/CVE-2026-81780
- https://patchstack.com/database/wordpress/plugin/hash-form/vulnerability/wordpress-hash-form-plugin-1-4-2-arbitrary-file-upload-vulnerability?_s_id=cve
13. CVE-2026-19410 `CVSS 9.4`
🎯 受影响:An Incorrect Authorization vulnerability in GitHub Trigger Comment Control in Google Cloud Build
📋 简介:An Incorrect Authorization vulnerability in GitHub Trigger Comment Control in Google Cloud Build prior to 2026-06-24 on Google Cloud Platform allows a remote attacker to execute unreviewed code in the build environment using webhook suppression.
🔗 参考:
- https://nvd.nist.gov/vuln/detail/CVE-2026-19410
- https://docs.cloud.google.com/build/docs/release-notes#August_24_2026
14. CVE-2026-58574 `CVSS 9.8`
🎯 受影响:Dell PowerStore
📋 简介:Dell PowerStore contains a Missing Authentication for Critical Function vulnerability.
🔗 参考:
- https://nvd.nist.gov/vuln/detail/CVE-2026-58574
- https://www.dell.com/support/kbdoc/en-us/000497829/dsa-2026-330-dell-powerstore-t-security-update-for-multiple-vulnerabilities
15. CVE-2026-59111 `CVSS 9.3`
🎯 受影响:Improper neutralization of special elements used in an OS command ('OS command injection') vulnerabi
📋 简介:Improper neutralization of special elements used in an OS command ('OS command injection') vulnerability in Digitální a informační agentura (DIA) eObčanka-Identifikace on MacOS enables an attacker to register a custom URL scheme (czeeopauth://) for parameterized application ex...
🔗 参考:
- https://nvd.nist.gov/vuln/detail/CVE-2026-59111
- https://info.identita.gov.cz/eop/BezpecnostniOznameni/CVE-2026-59111.aspx
16. CVE-2026-82226 `CVSS 9.8`
🎯 受影响:Unauthenticated PHP Object Injection in Tickera <= 3.6.0.2 versions.
📋 简介:Unauthenticated PHP Object Injection in Tickera <= 3.6.0.2 versions.
🔗 参考:
- https://nvd.nist.gov/vuln/detail/CVE-2026-82226
- https://patchstack.com/database/wordpress/plugin/tickera-event-ticketing-system/vulnerability/wordpress-tickera-plugin-3-6-0-2-php-object-injection-vulnerability?_s_id=cve
17. CVE-2026-82807 `CVSS 9.3`
🎯 受影响:A vulnerability was determined in ieungSoft Ultra RAMDisk Pro 1.82. This issue affects some unknown
📋 简介:A vulnerability was determined in ieungSoft Ultra RAMDisk Pro 1.82.
🔗 参考:
- https://nvd.nist.gov/vuln/detail/CVE-2026-82807
- https://vuldb.com/vuln/397226
- https://vuldb.com/vuln/397226/cti
- https://vuldb.com/cve/CVE-2026-82807
- https://vuldb.com/submit/864537
18. CVE-2026-81293 `CVSS 9.3`
🎯 受影响:Unauthenticated SQL Injection in WP Data Access <= 5.5.81 versions.
📋 简介:Unauthenticated SQL Injection in WP Data Access <= 5.5.81 versions.
🔗 参考:
- https://nvd.nist.gov/vuln/detail/CVE-2026-81293
- https://patchstack.com/database/wordpress/plugin/wp-data-access/vulnerability/wordpress-wp-data-access-plugin-5-5-81-sql-injection-vulnerability?_s_id=cve
19. CVE-2026-81756 `CVSS 9.3`
🎯 受影响:Unauthenticated SQL Injection in Smart Marketing SMS and Newsletters Forms <= 5.1.24 versions.
📋 简介:Unauthenticated SQL Injection in Smart Marketing SMS and Newsletters Forms <= 5.1.24 versions.
🔗 参考:
- https://nvd.nist.gov/vuln/detail/CVE-2026-81756
- https://patchstack.com/database/wordpress/plugin/smart-marketing-for-wp/vulnerability/wordpress-smart-marketing-sms-and-newsletters-forms-plugin-5-1-24-sql-injection-vulnerability?_s_id=cve
20. CVE-2026-81763 `CVSS 9.3`
🎯 受影响:Unauthenticated SQL Injection in Throws SPAM Away <= 3.8.2 versions.
📋 简介:Unauthenticated SQL Injection in Throws SPAM Away <= 3.8.2 versions.
🔗 参考:
- https://nvd.nist.gov/vuln/detail/CVE-2026-81763
- https://patchstack.com/database/wordpress/plugin/throws-spam-away/vulnerability/wordpress-throws-spam-away-plugin-3-8-2-sql-injection-vulnerability?_s_id=cve
21. CVE-2026-82857 `CVSS 9.8`
🎯 受影响:hulumi
📋 简介:hulumi versions before v1.3.2 contain a privilege escalation vulnerability in the weekly integration IAM policy that allows role lifecycle operations on af-e2e-* roles without sufficient boundary restrictions.
🔗 参考:
- https://nvd.nist.gov/vuln/detail/CVE-2026-82857
- https://github.com/kerberosmansour/hulumi/security/advisories/GHSA-35qr-vx94-m5x3
- https://www.vulncheck.com/advisories/hulumi-before-1.3.2-privilege-escalation-via-iam-policy
22. CVE-2026-53552 `CVSS 9.6`
🎯 受影响:Goploy
📋 简介:Goploy is an open-source automation deployment system.
🔗 参考:
- https://nvd.nist.gov/vuln/detail/CVE-2026-53552
- https://github.com/zhenorzz/goploy/security/advisories/GHSA-26rh-24rg-j3vv
23. CVE-2026-81779 `CVSS 10`
🎯 受影响:Improper Validation of Specified Quantity in Input vulnerability in Silk Themes Newspapers X
📋 简介:Improper Validation of Specified Quantity in Input vulnerability in Silk Themes Newspapers X allows Malicious Software Implanted.
🔗 参考:
- https://nvd.nist.gov/vuln/detail/CVE-2026-81779
- https://patchstack.com/database/wordpress/theme/newspapers-x/vulnerability/wordpress-newspapers-x-theme-1-0-46-1-0-48-backdoor-vulnerability?_s_id=cve
24. CVE-2026-82970 `CVSS 10`
🎯 受影响:Unrestricted Upload of File with Dangerous Type vulnerability in WP Legal Pages WP Cookie Notice for
📋 简介:Unrestricted Upload of File with Dangerous Type vulnerability in WP Legal Pages WP Cookie Notice for GDPR, CCPA & ePrivacy Consent allows Using Malicious Files.
🔗 参考:
- https://nvd.nist.gov/vuln/detail/CVE-2026-82970
- https://patchstack.com/database/wordpress/plugin/gdpr-cookie-consent/vulnerability/wordpress-wp-cookie-notice-for-gdpr-ccpa-eprivacy-consent-plugin-4-4-1-arbitrary-file-upload-vulnerability?_s_id=cve
25. CVE-2026-82971 `CVSS 10`
🎯 受影响:A vulnerability was determined in QVidium Opera11 3.3.2a26-Ax4x-opera11. This affects an unknown par
📋 简介:A vulnerability was determined in QVidium Opera11 3.3.2a26-Ax4x-opera11.
🔗 参考:
- https://nvd.nist.gov/vuln/detail/CVE-2026-82971
- https://vuldb.com/vuln/397334
- https://vuldb.com/vuln/397334/cti
- https://vuldb.com/cve/CVE-2026-82971
- https://vuldb.com/submit/880050
26. CVE-2026-82689 `CVSS 9.9`
🎯 受影响:A vulnerability was detected in D-Link DNS-320L, DNS-327L, DNS-340L and DNS-345 up to 20260717. Affe
📋 简介:A vulnerability was detected in D-Link DNS-320L, DNS-327L, DNS-340L and DNS-345 up to 20260717.
🔗 参考:
- https://nvd.nist.gov/vuln/detail/CVE-2026-82689
- https://vuldb.com/vuln/397177
- https://vuldb.com/vuln/397177/cti
- https://vuldb.com/cve/CVE-2026-82689
- https://vuldb.com/submit/894201
27. CVE-2026-82692 `CVSS 9.9`
🎯 受影响:A vulnerability was found in D-Link DNS-340L and DNS-345 up to 20260717. This affects an unknown par
📋 简介:A vulnerability was found in D-Link DNS-340L and DNS-345 up to 20260717.
🔗 参考:
- https://nvd.nist.gov/vuln/detail/CVE-2026-82692
- https://vuldb.com/vuln/397180
- https://vuldb.com/vuln/397180/cti
- https://vuldb.com/cve/CVE-2026-82692
- https://vuldb.com/submit/894211
28. CVE-2026-83524 `CVSS 9.9`
🎯 受影响:A security vulnerability has been detected in RedPort Optimizer wXa-203, Optimizer wXa-213 and Optim
📋 简介:A security vulnerability has been detected in RedPort Optimizer wXa-203, Optimizer wXa-213 and Optimizer wXa-223 up to 20260704.
🔗 参考:
- https://nvd.nist.gov/vuln/detail/CVE-2026-83524
- https://vuldb.com/vuln/397374
- https://vuldb.com/vuln/397374/cti
- https://vuldb.com/cve/CVE-2026-83524
- https://vuldb.com/submit/880051
29. CVE-2026-76133 `CVSS 9.8`
🎯 受影响:The affected Ebyte
📋 简介:The affected Ebyte
product
uses a deprecated hashing algorithm in an authentication-related
operation.
🔗 参考:
- https://nvd.nist.gov/vuln/detail/CVE-2026-76133
- https://www.cisa.gov/news-events/ics-advisories/icsa-26-237-06
- https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-237-06.json
30. CVE-2026-82855 `CVSS 9.8`
🎯 受影响:@hulumi/policies versions before 1.3.2 contain an evidence validation bypass vulnerability in Cloudf
📋 简介:@hulumi/policies versions before 1.3.2 contain an evidence validation bypass vulnerability in Cloudflare and deployment-governance validators that allows attackers to suppress violations by submitting unrelated compliant evidence.
🔗 参考:
- https://nvd.nist.gov/vuln/detail/CVE-2026-82855
- https://github.com/kerberosmansour/hulumi/security/advisories/GHSA-59f3-7227-wmh4
- https://www.vulncheck.com/advisories/hulumi-policies-before-1.3.2-evidence-validation-bypass
31. CVE-2026-82858 `CVSS 9.8`
🎯 受影响:@hulumi/drift versions before 1.3.2 accept externally supplied execute plans without sufficient prov
📋 简介:@hulumi/drift versions before 1.3.2 accept externally supplied execute plans without sufficient provenance validation, allowing untrusted reconciliation input to be treated as trusted.
🔗 参考:
- https://nvd.nist.gov/vuln/detail/CVE-2026-82858
- https://github.com/kerberosmansour/hulumi/security/advisories/GHSA-2ffm-hxrq-qqmm
- https://www.vulncheck.com/advisories/hulumi-drift-before-1.3.2-unsafe-execute-plan-acceptance
32. CVE-2026-82859 `CVSS 9.8`
🎯 受影响:hulumi
📋 简介:hulumi versions before v1.3.2 contain a deployment SCP template that allows tag-on-create bypasses for hulumi:iac-role protections.
🔗 参考:
- https://nvd.nist.gov/vuln/detail/CVE-2026-82859
- https://github.com/kerberosmansour/hulumi/security/advisories/GHSA-86q4-r5j3-ff5c
- https://www.vulncheck.com/advisories/hulumi-before-1.3.2-scp-template-tag-on-create-bypass
33. CVE-2026-82860 `CVSS 9.8`
🎯 受影响:@hulumi/policies versions before 1.3.2 fail to fully inspect inline and attached IAM policy evidence
📋 简介:@hulumi/policies versions before 1.3.2 fail to fully inspect inline and attached IAM policy evidence for the administrator-policy guardrail.
🔗 参考:
- https://nvd.nist.gov/vuln/detail/CVE-2026-82860
- https://github.com/kerberosmansour/hulumi/security/advisories/GHSA-4xrh-5m3m-328w
- https://www.vulncheck.com/advisories/hulumi-policies-before-1.3.2-admin-policy-bypass
34. CVE-2026-49003 `CVSS 9.6`
🎯 受影响:Attackers can exploit command injection vulnerabilities to delete core system runtime files, causing
📋 简介:Attackers can exploit command injection vulnerabilities to delete core system runtime files, causing the monitoring module to crash and become paralyzed; simultaneously, they can obtain root privileges to steal configuration passwords such as SNMP, thereby tampering with criti...
🔗 参考:
- https://nvd.nist.gov/vuln/detail/CVE-2026-49003
- https://support.zte.com.cn/zte-iccp-isupport-webui/bulletin/detail/874505866159002595
35. CVE-2026-82688 `CVSS 9.4`
🎯 受影响:A security vulnerability has been detected in D-Link DNS-340L and DNS-345 1.01B04/1.03B06/1.04.B02/1
📋 简介:A security vulnerability has been detected in D-Link DNS-340L and DNS-345 1.01B04/1.03B06/1.04.B02/1.05b04.
🔗 参考:
- https://nvd.nist.gov/vuln/detail/CVE-2026-82688
- https://vuldb.com/vuln/397176
- https://vuldb.com/vuln/397176/cti
- https://vuldb.com/cve/CVE-2026-82688
- https://vuldb.com/submit/894190
36. CVE-2026-82690 `CVSS 9.4`
🎯 受影响:A flaw has been found in D-Link DNS-327L and DNS-340L up to 20260717. Affected by this vulnerability
📋 简介:A flaw has been found in D-Link DNS-327L and DNS-340L up to 20260717.
🔗 参考:
- https://nvd.nist.gov/vuln/detail/CVE-2026-82690
- https://vuldb.com/vuln/397178
- https://vuldb.com/vuln/397178/cti
- https://vuldb.com/cve/CVE-2026-82690
- https://vuldb.com/submit/894209
37. CVE-2026-82691 `CVSS 9.4`
🎯 受影响:A vulnerability has been found in D-Link DNS-320L, DNS-327L, DNS-340L and DNS-345 up to 20260717. Af
📋 简介:A vulnerability has been found in D-Link DNS-320L, DNS-327L, DNS-340L and DNS-345 up to 20260717.
🔗 参考:
- https://nvd.nist.gov/vuln/detail/CVE-2026-82691
- https://vuldb.com/vuln/397179
- https://vuldb.com/vuln/397179/cti
- https://vuldb.com/cve/CVE-2026-82691
- https://vuldb.com/submit/894210
38. CVE-2026-82628 `CVSS 9.3`
🎯 受影响:A vulnerability was found in Colorful iGameCenter 2.0.0.81. This vulnerability affects the function
📋 简介:A vulnerability was found in Colorful iGameCenter 2.0.0.81.
🔗 参考:
- https://nvd.nist.gov/vuln/detail/CVE-2026-82628
- https://vuldb.com/vuln/397126
- https://vuldb.com/vuln/397126/cti
- https://vuldb.com/cve/CVE-2026-82628
- https://vuldb.com/submit/893754
39. CVE-2026-82653 `CVSS 9.3`
🎯 受影响:SiYuan
📋 简介:SiYuan before v3.8.1 contains a stored cross-site scripting vulnerability in confirmDialog() where unescaped package names and notebook names are interpolated directly into innerHTML assignments.
🔗 参考:
- https://nvd.nist.gov/vuln/detail/CVE-2026-82653
- https://github.com/siyuan-note/siyuan/security/advisories/GHSA-hvwp-43j9-4xgf
- https://www.vulncheck.com/advisories/siyuan-before-3.8.1-stored-xss-via-confirmdialog
40. CVE-2026-82654 `CVSS 9.3`
🎯 受影响:SiYuan
📋 简介:SiYuan before v3.8.1 fails to properly escape block name, alias, and memo fields in hint, backlink, and breadcrumb rendering functions.
🔗 参考:
- https://nvd.nist.gov/vuln/detail/CVE-2026-82654
- https://github.com/siyuan-note/siyuan/security/advisories/GHSA-hf87-qh3j-3p88
- https://www.vulncheck.com/advisories/siyuan-before-3.8.1-stored-xss-via-block-name
41. CVE-2026-82876 `CVSS 9.3`
🎯 受影响:Phison PS3111-S11 controller firmware verifies RSA signatures using a public modulus embedded within
📋 简介:Phison PS3111-S11 controller firmware verifies RSA signatures using a public modulus embedded within the firmware image itself rather than anchored in immutable storage.
🔗 参考:
- https://nvd.nist.gov/vuln/detail/CVE-2026-82876
- https://trulycrisp.github.io/drivefirmware/phison_s11/
- https://github.com/trulycrisp/psychite
- https://www.vulncheck.com/advisories/phison-ps3111-s11-controller-firmware-signature-verification-bypass
42. CVE-2026-82908 `CVSS 9.3`
🎯 受影响:A vulnerability was found in MSI Dragon Center up to 2.0.155.0. Affected by this vulnerability
📋 简介:A vulnerability was found in MSI Dragon Center up to 2.0.155.0.
🔗 参考:
- https://nvd.nist.gov/vuln/detail/CVE-2026-82908
- https://vuldb.com/vuln/397288
- https://vuldb.com/vuln/397288/cti
- https://vuldb.com/cve/CVE-2026-82908
- https://vuldb.com/submit/877502
43. CVE-2026-82872 `CVSS 9.1`
🎯 受影响:ToolJet
📋 简介:ToolJet before v3.16.208 fails to validate that the path organizationId matches the authenticated user's workspace before performing ToolJet DB table operations.
🔗 参考:
- https://nvd.nist.gov/vuln/detail/CVE-2026-82872
- https://github.com/ToolJet/ToolJet/security/advisories/GHSA-2jhv-482p-4php
- https://www.vulncheck.com/advisories/tooljet-before-3.16.208-cross-workspace-authorization-bypass
44. CVE-2026-82680 `CVSS 9`
🎯 受影响:A weakness has been identified in D-Link DSM-G600 1.01. This affects an unknown function of the file
📋 简介:A weakness has been identified in D-Link DSM-G600 1.01.
🔗 参考:
- https://nvd.nist.gov/vuln/detail/CVE-2026-82680
- https://vuldb.com/vuln/397175
- https://vuldb.com/vuln/397175/cti
- https://vuldb.com/cve/CVE-2026-82680
- https://vuldb.com/submit/894188
🟠 HIGH · 10 条
1. CVE-2026-56718 `CVSS 8.7`
🎯 受影响:AJCloud AJY IPC firmware
📋 简介:AJCloud AJY IPC firmware prior to version 01.10715.11.37 contains a path traversal vulnerability in the jdbhttpd web service that allows unauthenticated remote attackers to read arbitrary files with root privileges by supplying path traversal sequences in the HTTP request URI.
🔗 参考:
- https://nvd.nist.gov/vuln/detail/CVE-2026-56718
- https://www.ajcloud.net/
- https://www.vulncheck.com/advisories/ajcloud-ajy-ipc-firmware-path-traversal-via-jdbhttpd
2. CVE-2026-81636 `CVSS 8.7`
🎯 受影响:Allocation of Resources Without Limits or Throttling vulnerability in ash-project ash_graphql allows
📋 简介:Allocation of Resources Without Limits or Throttling vulnerability in ash-project ash_graphql allows an unauthenticated client to bypass the configured GraphQL query-complexity limit and force an unbounded database read.
🔗 参考:
- https://nvd.nist.gov/vuln/detail/CVE-2026-81636
- https://github.com/ash-project/ash_graphql/security/advisories/GHSA-mwc4-r9fc-h6mg
- https://cna.erlef.org/cves/CVE-2026-81636.html
- https://osv.dev/vulnerability/EEF-CVE-2026-81636
- https://github.com/ash-project/ash_graphql/commit/c3229f6a65cbabb32fd7ffcac881922d1b3b30ad
3. CVE-2026-82638 `CVSS 8.7`
🎯 受影响:jina-ai reader disables its private-address guard outside Google Cloud deployments, allowing unauthe
📋 简介:jina-ai reader disables its private-address guard outside Google Cloud deployments, allowing unauthenticated attackers to perform server-side request forgery.
🔗 参考:
- https://nvd.nist.gov/vuln/detail/CVE-2026-82638
- https://github.com/jina-ai/reader/issues/1253
- https://github.com/jina-ai/reader
- https://github.com/jina-ai/reader/blob/1574bfd380d249c86c82db4dace0d9c8fe17e2b1/src/services/misc.ts
- https://www.vulncheck.com/advisories/jina-ai-reader-server-side-request-forgery-via-disabled-private-address-guard
4. CVE-2026-82635 `CVSS 8.8`
🎯 受影响:Pake
📋 简介:Pake before 3.13.1 joins the JavaScript-supplied filename for the download_file Tauri command onto the user's Downloads directory with no sanitization.
🔗 参考:
- https://nvd.nist.gov/vuln/detail/CVE-2026-82635
- https://github.com/tw93/Pake/commit/a5463a84d6e36705ee0dd1886cf0e4b5a75b0ab4
- https://github.com/tw93/Pake/releases/tag/V3.13.1
- https://github.com/tw93/Pake
5. CVE-2026-82641 `CVSS 8.8`
🎯 受影响:keploy
📋 简介:keploy versions 3.1.0 through 3.6.25 bind the agent control-plane HTTP server to all interfaces without authentication, exposing endpoints that stream TLS session keys and traffic data.
🔗 参考:
- https://nvd.nist.gov/vuln/detail/CVE-2026-82641
- https://github.com/keploy/keploy/issues/4394
- https://github.com/keploy/keploy
- https://github.com/keploy/keploy/blob/v3.6.25/pkg/agent/routes/server.go
- https://github.com/keploy/keploy/commit/a6257d2b3184b85eb30edad345464aa292297b83
6. CVE-2026-82642 `CVSS 8.8`
🎯 受影响:Readest
📋 简介:Readest is an open-source e-book reader built on Tauri.
🔗 参考:
- https://nvd.nist.gov/vuln/detail/CVE-2026-82642
- https://github.com/readest/readest/security/advisories/GHSA-p4x7-pf2c-xrvj
- https://github.com/readest/readest/pull/4762
- https://github.com/readest/readest/commit/005aa2d6157a34049bf45641c06861d606a85edb
- https://github.com/readest/readest/releases/tag/v0.11.16
7. CVE-2026-83497 `CVSS 8.8`
🎯 受影响:Unrestricted deserialization of untrusted data in the cursor pagination component in the OpenSearch SQL plugin
📋 简介:Unrestricted deserialization of untrusted data in the cursor pagination component in the OpenSearch SQL plugin allows a remote authenticated user with basic read/search permissions to execute arbitrary code on the server by sending a crafted cursor parameter to the plugins/sql...
🔗 参考:
- https://nvd.nist.gov/vuln/detail/CVE-2026-83497
- https://opensearch.org/artifacts/by-version/#release-3-7-0
- https://opensearch.org/artifacts/by-version/#release-2-19-6
- https://aws.amazon.com/security/security-bulletins/2026-092-aws/
8. CVE-2026-82880 `CVSS 8.7`
🎯 受影响:YaCy Search Server through 1.941
📋 简介:YaCy Search Server through 1.941 contains an XML external entity injection vulnerability in SVG, FreeMind, and OpenSearch parsers that fail to disable external entity resolution.
🔗 参考:
- https://nvd.nist.gov/vuln/detail/CVE-2026-82880
- https://github.com/yacy/yacy_search_server/issues/818
- https://github.com/yacy/yacy_search_server/commit/3c3a307e8b7a0ebbc4d1e6b10898b52e15c0cd44
- https://github.com/yacy/yacy_search_server/blob/Release_1.941/source/net/yacy/document/parser/images/svgParser.java#L72
- https://github.com/yacy/yacy_search_server/blob/Release_1.941/source/net/yacy/document/parser/mmParser.java#L66
9. CVE-2026-81889 `CVSS 8.6`
🎯 受影响:elFinder
📋 简介:elFinder is an open-source file manager for web, written in JavaScript using jQuery UI.
🔗 参考:
- https://nvd.nist.gov/vuln/detail/CVE-2026-81889
- https://github.com/Studio-42/elFinder/security/advisories/GHSA-8x3q-jpjh-qh5c
- https://github.com/Studio-42/elFinder/commit/191372c1bbebbd36fb55af79a84b9984861390ff
- https://github.com/Studio-42/elFinder/commit/6d997386cd0f1abab4706c220b46b0aea0ecff51
- https://github.com/Studio-42/elFinder/releases/tag/2.1.70
10. CVE-2026-77956 `CVSS 8.9`
🎯 受影响:Improper Control of Generation of Code (Code Injection) vulnerability in ash-project ash_ai allows a
📋 简介:Improper Control of Generation of Code (Code Injection) vulnerability in ash-project ash_ai allows a remote, unauthenticated client to execute arbitrary Elixir code.
🔗 参考:
- https://nvd.nist.gov/vuln/detail/CVE-2026-77956
- https://github.com/ash-project/ash_ai/security/advisories/GHSA-2g59-hg7m-qc83
- https://cna.erlef.org/cves/CVE-2026-77956.html
- https://osv.dev/vulnerability/EEF-CVE-2026-77956
- https://github.com/ash-project/ash_ai/commit/e9948254b5659c1143b73dc2f59f457931e64514
---
新发现 160 条 · 热度升级 0 条 · 🔥=高热度/有 PoC · 🆙=昨日已推、今日热度升级
📊 GitHub 热榜
🏆 GitHub 月榜 · 2026-09(本月第一个工作日)
📋 Beautiful, Modern & Opinionated Linux
2. freestylefly/awesome-gpt-image-2
📋 Prompt as Code | GPT-Image2 工业级提示词引擎与模板库,530+ 个案例逆向工程,20+ 套工业级模板,并提炼出Skills,持续更新中
3. TencentCloud/TencentDB-Agent-Memory
📋 TencentDB Agent Memory is a team-level memory hub for AI Agents — turning conversations, docs, and code into four reusable memory assets (Chat Memory, Skill, LLM-Wiki, Code-Graph) that are governed, shared, and equipped across agents and frameworks.
4. anthropics/claude-plugins-community
📋 Community plugin marketplace for Claude Cowork and Claude Code. Read-only mirror — submit plugins at clau.de/plugin-directory-submission.
📋 Fast Rust library for PDF inspection, classification, and text extraction. Intelligently detects scanned vs text-based PDFs to enable smart routing decisions.
📋 Agent skill for beautiful, verifiable architecture, workflow, sequence, data-flow, and lifecycle diagrams—self-contained HTML with motion and crisp export.
📋 14MB foundation model for tiny devices; phones, wearables, smart home, and robots.
📋 Self-evolving Context Database for AI Agents. Unify Agent Memory, Knowledge RAG and Skills.
📋 ⚡️A native, local-first alternative to Logitech Options+, written in Rust 🦀 — remap buttons, DPI, and SmartShift over HID++. No account, no telemetry.
📋 Reverse Engineering / Authorized Penetration Testing / Security Research Skill Router Pack AI-powered routing + On-demand toolchain bootstrapping + Self-evolving knowledge base Supports Claude Code, Kiro, Cursor, Cline, and other AI coding clients 逆向/渗透/安全技能路由包 - AI 自动路由 + 按需自举工具链 + 自动进化经验库 | 支持 Claude Code / Kiro / Cursor / Cline 等代码 AI 客户端
🤖 AI 总结分析
今日整体形势呈现“Web 应用高危漏洞集中爆发 + AI Agent 基础设施风险抬头”的双重特征:漏洞预警列出 10 条 CVSS≥7.5 记录,其中 8 条为满分,热点集中在 WordPress 插件未授权文件上传、路由器/物联网设备认证缺失与命令注入,同时 MCPHub 的 MCP 管理 API 暴露 9.9 分漏洞。GitHub 热榜上 AI Agent 插件、记忆中枢与轻量模型持续升温,风险面正从传统 Web 向智能体基础设施扩展。
在漏洞预警源中,最值得关注的是 CVE-2026-81780(Hash Form ≤1.4.2 未授权任意文件上传)与 CVE-2026-82970(WP Cookie Notice 插件任意文件上传),两者均为 CVSS 10 且影响广泛 WordPress 站点,攻击者可植入恶意文件直接控制站点。另一个应重视的是 CVE-2026-79748,影响 MCPHub 0.12.15 之前版本的 API 路径,属于新兴 AI Agent 编排层的高危暴露。
今日安全情报源因 FreshRSS 认证返回 401 未授权导致拉取失败,暂无新增情报产出;这一故障本身意味着监控链路出现认证失效,应尽快修复,否则可能形成威胁情报盲区。
GitHub 热榜中,anthropics/claude-plugins-community 社区插件市场和 TencentCloud/TencentDB-Agent-Memory、volcengine/OpenViking 等 Agent 记忆与技能中枢项目热度明显,说明 AI Agent 组件正快速生态化,但集中管理插件、记忆和技能也会扩大供应链与数据泄露面,与 MCPHub 漏洞形成呼应;firecrawl/pdf-inspector 则体现对 PDF 恶意文件检测的实际需求。
今天应优先核查并升级 Hash Form 与 WP Cookie Notice 插件、将 MCPHub 更新至 0.12.15 以上,并限制这些上传接口与 MCP API 的公网暴露,防止满分漏洞被批量利用。