Linux (Debian)
12/09/2026 00:00 UTC
Several vulnerabilities were discovered in the Xorg X server, which may result in privilege escalation if the X server is running privileged. https://security-tracker.debian.org/tracker/DSA-6497-1
Fuente: Debian Security
Linux (Debian)
CVSS 8.1 · alto
12/09/2026 00:00 UTC
Multiple vulnerabilities were discovered in nginx, a high-performance web and reverse proxy server, which may result in denial of service, memory disclosure or potentially the execution of arbitrary code. CVE-2026-42533 A heap buffer overflow was discovered in the nginx script engine. It can be triggered when a map directive performs regular expression matching and a string expression references c
Fuente: Debian Security · CVE-2026-42533
Linux (Debian)
11/09/2026 00:00 UTC
Several vulnerabilities were discovered in SPIP, a website engine for publishing, which could result in unauthenticated remote code execution. https://security-tracker.debian.org/tracker/DSA-6495-1
Fuente: Debian Security
Linux (Debian)
11/09/2026 00:00 UTC
Multiple security vulnerabilities were discovered in the Kamailio SIP server, which could result in denial of service. https://security-tracker.debian.org/tracker/DSA-6494-1
Fuente: Debian Security
Linux (Debian)
11/09/2026 00:00 UTC
Several vulnerabilities were discovered in libevent, an asynchronous event notification library. The HTTP implementation (evhttp) handled Transfer-Encoding and Content-Length headers, chunked-encoding line terminators, header line folding and chunked trailers too permissively, which could allow HTTP request smuggling, header injection or access control bypass when a libevent-based server or client
Fuente: Debian Security
Linux (Debian)
10/09/2026 00:00 UTC
Multiple security issues were found in Rack, an interface for developing web applications in Ruby, which could result in denial of service, information disclosure, spoofing or bypass of access restrictions. https://security-tracker.debian.org/tracker/DSA-6492-1
Fuente: Debian Security
Drupal
⚠ posible crítico
09/09/2026 17:24 UTC
Project: Ultimate Table Field Project machine name: ultimate_table_field Date: 2026-September-09 Security risk: Critical 15 ∕ 25 AC:None/A:None/CI:None/II:Some/E:Theoretical/TD:All Vulnerability: Access bypass Affected versions: <1.1.1 || >=2.0.0 <2.0.1 CVE IDs: CVE-2026-87955 Description: The Ultimate Table Field module enables you to store table data in a field and edit each table cell through a
Fuente: Drupal.org · CVE-2026-87955
Drupal
⚠ posible crítico
09/09/2026 17:24 UTC
Project: Taxonomy Term Glossary Project machine name: term_glossary Date: 2026-September-09 Security risk: Critical 15 ∕ 25 AC:None/A:None/CI:Some/II:None/E:Theoretical/TD:All Vulnerability: Access bypass Affected versions: <4.6.0 CVE IDs: CVE-2026-87954 Description: This module adds automatic highlighting of taxonomy terms in content. The module doesn't sufficiently check access on taxonomy terms
Fuente: Drupal.org · CVE-2026-87954
Drupal
09/09/2026 17:23 UTC
Project: SAML SSO - Service Provider Project machine name: miniorange_saml Date: 2026-September-09 Security risk: Moderately critical 11 ∕ 25 AC:Complex/A:Admin/CI:Some/II:Some/E:Theoretical/TD:Default Vulnerability: Server Side Request Forgery Affected versions: <3.2.0 CVE IDs: CVE-2026-87953 Description: This module allows you to configure your Drupal site as a SAML 2.0 Service Provider so that
Fuente: Drupal.org · CVE-2026-87953
Drupal
09/09/2026 17:23 UTC
Project: SAML SSO - Service Provider Project machine name: miniorange_saml Date: 2026-September-09 Security risk: Moderately critical 10 ∕ 25 AC:Complex/A:User/CI:None/II:Some/E:Theoretical/TD:All Vulnerability: Insufficient replay protection Affected versions: <3.2.0 CVE IDs: CVE-2026-87952 Description: This module allows you to configure your Drupal site as a SAML 2.0 Service Provider so that us
Fuente: Drupal.org · CVE-2026-87952
Drupal
09/09/2026 17:22 UTC
Project: SAML SSO - Service Provider Project machine name: miniorange_saml Date: 2026-September-09 Security risk: Moderately critical 12 ∕ 25 AC:Basic/A:Admin/CI:Some/II:Some/E:Theoretical/TD:Default Vulnerability: Information disclosure Affected versions: <3.2.0 CVE IDs: CVE-2026-87951 Description: This module allows you to configure your Drupal site as a SAML 2.0 Service Provider so that users c
Fuente: Drupal.org · CVE-2026-87951
Drupal
09/09/2026 17:22 UTC
Project: SAML SSO - Service Provider Project machine name: miniorange_saml Date: 2026-September-09 Security risk: Moderately critical 13 ∕ 25 AC:None/A:None/CI:Some/II:None/E:Theoretical/TD:Uncommon Vulnerability: Embedded credentials Affected versions: <3.2.0 CVE IDs: CVE-2026-87950 Description: This module allows you to configure your Drupal site as a SAML 2.0 Service Provider so that users can
Fuente: Drupal.org · CVE-2026-87950
Drupal
09/09/2026 17:22 UTC
Project: SAML SSO - Service Provider Project machine name: miniorange_saml Date: 2026-September-09 Security risk: Moderately critical 12 ∕ 25 AC:Complex/A:Admin/CI:Some/II:Some/E:Theoretical/TD:All Vulnerability: Cross-site scripting Affected versions: <3.2.0 CVE IDs: CVE-2026-87949 Description: This module allows you to configure your Drupal site as a SAML 2.0 Service Provider so that users can a
Fuente: Drupal.org · CVE-2026-87949
Drupal
09/09/2026 17:21 UTC
Project: SAML SSO - Service Provider Project machine name: miniorange_saml Date: 2026-September-09 Security risk: Moderately critical 13 ∕ 25 AC:Basic/A:Admin/CI:Some/II:Some/E:Theoretical/TD:All Vulnerability: Cross-site scripting Affected versions: <3.2.0 CVE IDs: CVE-2026-87948 Description: This module allows you to configure your Drupal site as a SAML 2.0 Service Provider so that users can aut
Fuente: Drupal.org · CVE-2026-87948
Drupal
09/09/2026 17:21 UTC
Project: SAML SSO - Service Provider Project machine name: miniorange_saml Date: 2026-September-09 Security risk: Moderately critical 14 ∕ 25 AC:Complex/A:None/CI:Some/II:Some/E:Theoretical/TD:Default Vulnerability: Authentication bypass Affected versions: <3.2.0 CVE IDs: CVE-2026-87947 Description: This module allows you to configure your Drupal site as a SAML 2.0 Service Provider so that users c
Fuente: Drupal.org · CVE-2026-87947
Drupal
09/09/2026 17:21 UTC
Project: SAML SSO - Service Provider Project machine name: miniorange_saml Date: 2026-September-09 Security risk: Critical 15 ∕ 25 AC:Complex/A:None/CI:Some/II:Some/E:Theoretical/TD:All Vulnerability: Weak cryptographic practices Affected versions: <3.2.0 CVE IDs: CVE-2026-87946 Description: This module allows you to configure your Drupal site as a SAML 2.0 Service Provider so that users can authe
Fuente: Drupal.org · CVE-2026-87946
Drupal
09/09/2026 17:20 UTC
Project: SAML SSO - Service Provider Project machine name: miniorange_saml Date: 2026-September-09 Security risk: Critical 16 ∕ 25 AC:Basic/A:None/CI:Some/II:Some/E:Theoretical/TD:All Vulnerability: Open redirect Affected versions: <3.2.0 CVE IDs: CVE-2026-87945 Description: This module allows you to configure your Drupal site as a SAML 2.0 Service Provider so that users can authenticate through a
Fuente: Drupal.org · CVE-2026-87945
Drupal
09/09/2026 17:20 UTC
Project: SAML SSO - Service Provider Project machine name: miniorange_saml Date: 2026-September-09 Security risk: Critical 15 ∕ 25 AC:Complex/A:None/CI:Some/II:Some/E:Theoretical/TD:All Vulnerability: Improper certificate validation Affected versions: <3.2.0 CVE IDs: CVE-2026-87944 Description: This module allows you to configure your Drupal site as a SAML 2.0 Service Provider so that users can au
Fuente: Drupal.org · CVE-2026-87944
Drupal
09/09/2026 17:19 UTC
Project: SAML SSO - Service Provider Project machine name: miniorange_saml Date: 2026-September-09 Security risk: Critical 18 ∕ 25 AC:None/A:None/CI:Some/II:Some/E:Theoretical/TD:All Vulnerability: Improper access control Affected versions: <3.2.0 CVE IDs: CVE-2026-87943 Description: This module allows you to configure your Drupal site as a SAML 2.0 Service Provider so that users can authenticate
Fuente: Drupal.org · CVE-2026-87943
Drupal
09/09/2026 17:19 UTC
Project: SafeDelete Project machine name: safedelete Date: 2026-September-09 Security risk: Moderately critical 12 ∕ 25 AC:Basic/A:User/CI:Some/II:Some/E:Theoretical/TD:Uncommon Vulnerability: Cross-site scripting Affected versions: <1.0.88 CVE IDs: CVE-2026-87942 Description: This module enables you to manage content deletion and provides reports for identifying orphaned content. The module doesn
Fuente: Drupal.org · CVE-2026-87942
Drupal
⚠ posible crítico
09/09/2026 17:18 UTC
Project: Patreon Project machine name: patreon Date: 2026-September-09 Security risk: Critical 16 ∕ 25 AC:Complex/A:Admin/CI:All/II:All/E:Theoretical/TD:All Vulnerability: Unsupported CVE IDs: CVE-2026-87941 Description: The Drupal Security Team is marking this project unsupported. There is a known security issue with the project that has not been fixed by the maintainer. If you would like to main
Fuente: Drupal.org · CVE-2026-87941
Drupal
09/09/2026 17:17 UTC
Project: Key auth Project machine name: key_auth Date: 2026-September-09 Security risk: Moderately critical 13 ∕ 25 AC:Basic/A:User/CI:Some/II:Some/E:Theoretical/TD:Default Vulnerability: Access bypass Affected versions: <2.2.4 CVE IDs: CVE-2026-87940 Description: This module enables you to add key-based authentication on a per-user basis. The module doesn't cache per user, potentially allowing an
Fuente: Drupal.org · CVE-2026-87940
Drupal
09/09/2026 17:16 UTC
Project: Feed Block Project machine name: feed_block Date: 2026-September-09 Security risk: Moderately critical 13 ∕ 25 AC:Complex/A:User/CI:Some/II:Some/E:Theoretical/TD:All Vulnerability: Cross-site scripting Affected versions: <2.0.2 || >=3.0.0 <3.0.2 CVE IDs: CVE-2026-87939 Description: The Feed Block module provides a block content type that displays items pulled from a remote RSS/Atom feed.
Fuente: Drupal.org · CVE-2026-87939
Drupal
⚠ posible crítico
09/09/2026 17:16 UTC
Project: CSP log Project machine name: csp_log Date: 2026-September-09 Security risk: Critical 15 ∕ 25 AC:Basic/A:Admin/CI:All/II:Some/E:Theoretical/TD:All Vulnerability: SQL Injection Affected versions: <1.0.2 CVE IDs: CVE-2026-87938 Description: The CSP Log module enhances any module that adds the CSP header to a site, by providing a reporting endpoint, custom storage, and aggregated reports tha
Fuente: Drupal.org · CVE-2026-87938
Drupal
09/09/2026 17:15 UTC
Project: Central Authentication System (CAS) Server Project machine name: cas_server Date: 2026-September-09 Security risk: Moderately critical 10 ∕ 25 AC:Basic/A:None/CI:None/II:None/E:Theoretical/TD:All Vulnerability: Open redirect Affected versions: <2.0.4 || >=2.1.0 <2.1.3 CVE IDs: CVE-2026-87937 Description: This module enables you to turn a Drupal install into the Central Authentication Syst
Fuente: Drupal.org · CVE-2026-87937
Drupal
⚠ posible crítico
09/09/2026 17:14 UTC
Project: amazee.ai Private AI Provider Project machine name: ai_provider_amazeeio Date: 2026-September-09 Security risk: Critical 17 ∕ 25 AC:Complex/A:None/CI:All/II:Some/E:Proof/TD:Default Vulnerability: SQL injection Affected versions: <1.3.7 || >=1.4.0 <1.4.3 CVE IDs: CVE-2026-87936 Description: Update 2026-09-11: Increased risk score to reflect publicly documented methods for developing exploi
Fuente: Drupal.org · CVE-2026-87936
Linux (Debian)
09/09/2026 00:00 UTC
Several vulnerabilities were discovered in the Slurm Workload Manager, a cluster resource management and job scheduling system, which may result in privilege escalation, SQL injection in the accounting database, deletion of files outside the container spool directory, bypass of credential verification for shared objects transferred with sbcast, or denial of service. https://security-tracker.debian
Fuente: Debian Security
Linux (Debian)
08/09/2026 00:00 UTC
Qi Wang and Jianjun Chen discovered that FORT validator, a RPKI validation service, performed incomplete validation of RRDP notifications, which could result in denial of service via cache poisoning. For additional details please refer to the upstream advisory at https://github.com/NICMx/FORT-validator/security/advisories/GHSA-qfm3-577x-rh54 https://security-tracker.debian.org/tracker/DSA-6490-1
Fuente: Debian Security
Linux (Debian)
08/09/2026 00:00 UTC
An buffer overflow was discovered in the OPUS audio decoder of the GStreamer media framework, which may result in denial of service or potentially the execution of arbitrary code if a malformed audio file is processed. https://security-tracker.debian.org/tracker/DSA-6489-1
Fuente: Debian Security
Linux (Debian)
07/09/2026 00:00 UTC
It was discovered that missing input sanitising in the JBIG2 decoder library could result in denial of service. https://security-tracker.debian.org/tracker/DSA-6488-1
Fuente: Debian Security
Linux (Debian)
CVSS 5.9 · medio
07/09/2026 00:00 UTC
Multiple vulnerabilities were found in strongSwan, an IKE/IPsec suite. CVE-2026-78123 An undefined memory access vulnerability in the openssl plugin when handling PKCS#7 containers, that can result in a crash. CVE-2026-78124 A memory leak in the openssl plugin during the enumeration of certificates in PKCS#7 containers. CVE-2026-78126 A NULL-pointer dereference vulnerability in the eap-aka plugin
Fuente: Debian Security · CVE-2026-78123
Linux (Debian)
06/09/2026 00:00 UTC
Two security issues were discovered in libde265, an implementation of the H.265 video codec which may result in denial of service or potentially the execution of arbitrary code if a malformed media file is processed. https://security-tracker.debian.org/tracker/DSA-6486-1
Fuente: Debian Security
Linux (Debian)
06/09/2026 00:00 UTC
Two security vulnerabilities were discovered in the server of the Tryton application platform, which could lead to arbitrary command execution via malformed email/report templates. https://security-tracker.debian.org/tracker/DSA-6485-1
Fuente: Debian Security
Magento / e-commerce
CVSS 10.0 · crítico
05/09/2026 00:00 UTC
Developing investigation. Sansec is publishing early because stores are being compromised right now. The threat actors are quickly iterating so we update this article with new indicators as we lear...
Fuente: Sansec · CVE-2026-75650
Linux (Debian)
05/09/2026 00:00 UTC
Security issues were discovered in Chromium which could result in the execution of arbitrary code, denial of service, or information disclosure. https://security-tracker.debian.org/tracker/DSA-6484-1
Fuente: Debian Security
Linux (Debian)
04/09/2026 00:00 UTC
Multiple security issues were discovered in Thunderbird, which could result in the execution of arbitrary code or information disclosure. https://security-tracker.debian.org/tracker/DSA-6483-1
Fuente: Debian Security
Linux (Debian)
03/09/2026 00:00 UTC
Security issues were discovered in Chromium which could result in the execution of arbitrary code, denial of service, or information disclosure. https://security-tracker.debian.org/tracker/DSA-6482-1
Fuente: Debian Security
Drupal
02/09/2026 16:39 UTC
Project: Webform Submissions Delete Project machine name: webform_submissions_delete Date: 2026-September-02 Security risk: Moderately critical 13 ∕ 25 AC:Basic/A:None/CI:None/II:Some/E:Theoretical/TD:All Vulnerability: Access bypass Affected versions: <1.2.0 CVE IDs: CVE-2026-84921 Description: This module enables you to delete Webform submissions in bulk using a specified date range. The module
Fuente: Drupal.org · CVE-2026-84921
Drupal
⚠ posible crítico
02/09/2026 16:38 UTC
Project: Unpublished Node Permissions Project machine name: unpublished_node_permissions Date: 2026-September-02 Security risk: Critical 15 ∕ 25 AC:None/A:None/CI:Some/II:None/E:Theoretical/TD:All Vulnerability: Access bypass Affected versions: <1.8.0 CVE IDs: CVE-2026-84920 Description: This module creates permissions per node content type to control access to unpublished content. The module has
Fuente: Drupal.org · CVE-2026-84920
Drupal
02/09/2026 16:37 UTC
Project: PhotoSwipe - Responsive JavaScript Modal Image Gallery Project machine name: photoswipe Date: 2026-September-02 Security risk: Moderately critical 14 ∕ 25 AC:Basic/A:User/CI:Some/II:Some/E:Theoretical/TD:All Vulnerability: Cross-site scripting Affected versions: <5.0.9 CVE IDs: CVE-2026-84919 Description: This module enables you to add dynamic caption support to PhotoSwipe image galleries
Fuente: Drupal.org · CVE-2026-84919
Drupal
02/09/2026 16:36 UTC
Project: Monobank payment API Project machine name: monobank Date: 2026-September-02 Security risk: Moderately critical 12 ∕ 25 AC:Complex/A:None/CI:None/II:Some/E:Theoretical/TD:All Vulnerability: Access bypass Affected versions: <1.0.3 CVE IDs: CVE-2026-84918 Description: The Monobank payment API module provides integration with Monobank acquiring payments. The module did not verify the Monobank
Fuente: Drupal.org · CVE-2026-84918
Drupal
02/09/2026 16:35 UTC
Project: Media Library Importer Project machine name: media_library_importer Date: 2026-September-02 Security risk: Moderately critical 11 ∕ 25 AC:Basic/A:User/CI:Some/II:None/E:Theoretical/TD:All Vulnerability: Access bypass Affected versions: <2.1.6 CVE IDs: CVE-2026-81163 Description: A module to import media files into media library. The import folder is a plain textfield with no validation. P
Fuente: Drupal.org · CVE-2026-81163
Drupal
02/09/2026 16:34 UTC
Project: Mailer Plus Log Project machine name: symfony_mailer_log Date: 2026-September-02 Security risk: Moderately critical 12 ∕ 25 AC:Basic/A:Admin/CI:Some/II:Some/E:Theoretical/TD:Default Vulnerability: Access bypass Affected versions: <1.2.7 CVE IDs: CVE-2026-16648 Description: This module enables you to log the emails sent by Mailer Plus as content entities, so they can be reviewed at Reports
Fuente: Drupal.org · CVE-2026-16648
Drupal
⚠ posible crítico
02/09/2026 16:33 UTC
Project: Jsonapi Role Access Project machine name: jsonapi_role_access Date: 2026-September-02 Security risk: Critical 16 ∕ 25 AC:Basic/A:None/CI:Some/II:Some/E:Theoretical/TD:All Vulnerability: Access bypass Affected versions: <2.0.2 CVE IDs: CVE-2026-84917 Description: This module enables you to restrict access to JSON:API routes based on specific user roles. The module doesn't sufficiently enfo
Fuente: Drupal.org · CVE-2026-84917
Drupal
02/09/2026 16:32 UTC
Project: Islandora Project machine name: islandora Date: 2026-September-02 Security risk: Moderately critical 12 ∕ 25 AC:Complex/A:None/CI:Some/II:None/E:Theoretical/TD:All Vulnerability: Access bypass Affected versions: <2.19.0 CVE IDs: CVE-2026-84916 Description: This islandora_advanced_search sub module enables AJAX updates for advanced search, facet, and search result blocks. The module doesn'
Fuente: Drupal.org · CVE-2026-84916
Drupal
⚠ posible crítico
02/09/2026 16:31 UTC
Project: Email Verification / SMS Verification / OTP Verification Project machine name: otp_verification Date: 2026-September-02 Security risk: Critical 16 ∕ 25 AC:Basic/A:None/CI:Some/II:Some/E:Theoretical/TD:All Vulnerability: Cross Site Scripting Affected versions: <2.4.0 CVE IDs: CVE-2026-84924 Description: This module enables you to add an extra layer of verification for user registration. Th
Fuente: Drupal.org · CVE-2026-84924
Drupal
⚠ posible crítico
02/09/2026 16:30 UTC
Project: Email Verification / SMS Verification / OTP Verification Project machine name: otp_verification Date: 2026-September-02 Security risk: Critical 16 ∕ 25 AC:Basic/A:None/CI:Some/II:Some/E:Theoretical/TD:All Vulnerability: Access Bypass Affected versions: <2.4.0 CVE IDs: CVE-2026-84923 Description: This module enables you to add extra layer of verification for user registration. The module d
Fuente: Drupal.org · CVE-2026-84923
Drupal
02/09/2026 16:29 UTC
Project: Component blocks Project machine name: component_blocks Date: 2026-September-02 Security risk: Moderately critical 14 ∕ 25 AC:Basic/A:User/CI:Some/II:Some/E:Theoretical/TD:All Vulnerability: Cross site scripting Affected versions: <1.2.7 CVE IDs: CVE-2026-84915 Description: This module enables you use UI Patterns with blocks, for use in Layout Builder. The module doesn't sufficiently vali
Fuente: Drupal.org · CVE-2026-84915
Drupal
⚠ posible crítico
02/09/2026 16:29 UTC
Project: Calculate Working Days Project machine name: calculate_working_days Date: 2026-September-02 Security risk: Critical 15 ∕ 25 AC:None/A:None/CI:None/II:Some/E:Theoretical/TD:All Vulnerability: Access bypass Affected versions: <2.0.3 CVE IDs: CVE-2026-84914 Description: Calculate Working Days allows you to calculate working days between 2 dates. This module doesn't sufficiently restrict acce
Fuente: Drupal.org · CVE-2026-84914
Drupal
02/09/2026 16:28 UTC
Project: AI translate Project machine name: ai_translate Date: 2026-September-02 Security risk: Moderately critical 13 ∕ 25 AC:Basic/A:User/CI:Some/II:Some/E:Theoretical/TD:Default Vulnerability: Access Bypass Affected versions: <1.3.2 || >=1.4.0 <1.4.1 CVE IDs: CVE-2026-84913 Description: This module enables you to automatically translate entities. The module doesn't sufficiently check access on
Fuente: Drupal.org · CVE-2026-84913
Drupal
02/09/2026 16:27 UTC
Project: AI (Artificial Intelligence) Project machine name: ai Date: 2026-September-02 Security risk: Moderately critical 13 ∕ 25 AC:Basic/A:User/CI:Some/II:Some/E:Theoretical/TD:Default Vulnerability: Access Bypass Affected versions: <1.3.13 || >=1.4.0 <1.4.8 CVE IDs: CVE-2026-84912 Description: This submodule AI Translate enables you to automatically translate entities. The module doesn't suffic
Fuente: Drupal.org · CVE-2026-84912
Drupal
02/09/2026 16:26 UTC
Project: AI (Artificial Intelligence) Project machine name: ai Date: 2026-September-02 Security risk: Moderately critical 10 ∕ 25 AC:Complex/A:Admin/CI:Some/II:Some/E:Theoretical/TD:Uncommon Vulnerability: Cross site scripting Affected versions: <1.3.13 || >=1.4.0 <1.4.8 CVE IDs: CVE-2026-84911 Description: This AI Chatbot module enables you to have a Chatbot using assistants to help you with your
Fuente: Drupal.org · CVE-2026-84911
Drupal
02/09/2026 16:25 UTC
Project: Advanced Search Project machine name: advanced_search Date: 2026-September-02 Security risk: Moderately critical 12 ∕ 25 AC:Complex/A:None/CI:Some/II:None/E:Theoretical/TD:All Vulnerability: Access bypass Affected versions: <2.4.5 CVE IDs: CVE-2026-84910 Description: This module enables AJAX updates for advanced search, facet, and search result blocks. The module doesn’t sufficiently chec
Fuente: Drupal.org · CVE-2026-84910
Linux (Debian)
02/09/2026 00:00 UTC
Multiple security issues have been found in the Mozilla Firefox web browser, which could potentially result in the execution of arbitrary code, sandbox escape or privilege escalation. https://security-tracker.debian.org/tracker/DSA-6481-1
Fuente: Debian Security
Linux (Debian)
01/09/2026 00:00 UTC
Multiple vulnerabilities were discovered in Keystone, the OpenStack identity service, which may result in authorisation bypass or information disclosure. https://security-tracker.debian.org/tracker/DSA-6480-1
Fuente: Debian Security
Linux (Debian)
30/08/2026 00:00 UTC
Multiple vulnerabilities were discovered in roundcube, a skinnable AJAX based webmail solution for IMAP servers, which could result in cross-site scripting, SSRF bypass, information disclosure, privilege escalation, denial of service or remote code execution. https://security-tracker.debian.org/tracker/DSA-6479-1
Fuente: Debian Security
Linux (Debian)
30/08/2026 00:00 UTC
Several vulnerabilities were discovered in starlette, a lightweight ASGI framework/toolkit, which could result in bypass of authorization checks or denial of service. https://security-tracker.debian.org/tracker/DSA-6478-1
Fuente: Debian Security
Linux (Debian)
29/08/2026 00:00 UTC
Several vulnerabilities have been discovered in the Linux kernel that may lead to a privilege escalation, denial of service or information leaks. https://security-tracker.debian.org/tracker/DSA-6477-1
Fuente: Debian Security
Linux (Debian)
27/08/2026 00:00 UTC
Security issues were discovered in Chromium which could result in the execution of arbitrary code, denial of service, or information disclosure. https://security-tracker.debian.org/tracker/DSA-6476-1
Fuente: Debian Security
Linux (Debian)
27/08/2026 00:00 UTC
Guillem Lefait discovered a path traversal attack in suricata-update, a tool for updating Suricata rules, which allowed malformed rules to overwrite files on the system. https://security-tracker.debian.org/tracker/DSA-6475-1
Fuente: Debian Security
Linux (Debian)
27/08/2026 00:00 UTC
Two security vulnerabilities were discovered in Cockpit, a web console for Linux servers, which could result in the execution of arbitrary code or denial of service. https://security-tracker.debian.org/tracker/DSA-6474-1
Fuente: Debian Security
Linux (Debian)
27/08/2026 00:00 UTC
Several vulnerabilities were discovered in libdbi-perl, a Perl framework that provides a common interface to access various backend databases in a uniform manner, which could result in denial of service, path traversal, bypass of file-backed filters or the execution of arbitrary code. https://security-tracker.debian.org/tracker/DSA-6473-1
Fuente: Debian Security
Linux (Debian)
27/08/2026 00:00 UTC
A symlink traversal vulnerability was discovered in bubblewrap, a low-level unprivileged sandboxing tool used by Flatpak and other projects, which could result in sandbox escape by malicious/compromised Flatpak apps. https://security-tracker.debian.org/tracker/DSA-6472-1
Fuente: Debian Security
Linux (Debian)
27/08/2026 00:00 UTC
Multiple vulnerabilities have been discocvered in Wireshark, a network protocol analyzer which could result in denial of service or the execution of arbitrary code. https://security-tracker.debian.org/tracker/DSA-6471-1
Fuente: Debian Security
Linux (Debian)
27/08/2026 00:00 UTC
Several vulnerabilities were discovered in GIMP, the GNU Image Manipulation Program, which could result in denial of service or potentially the execution of arbitrary code if malformed PSP, TIFF, DDS, PSD, SGI, FLI, FITS or ICNS files are opened. https://security-tracker.debian.org/tracker/DSA-6470-1
Fuente: Debian Security
Linux (Debian)
27/08/2026 00:00 UTC
Multiple vulnerabilities were discovered in xrdp, a Remote Desktop Protocol (RDP) server, which may result in denial of service, information disclosure, privilege escalation or the execution of arbitrary code. Several of these issues are exploitable by an unauthenticated remote attacker. This update also changes two defaults, as part of the fixes: * Alternate shells supplied by the client are now
Fuente: Debian Security
Drupal
CVSS 6.1 · medio
26/08/2026 17:45 UTC
Project: Slick Carousel Project machine name: slick Date: 2026-August-26 Security risk: Moderately critical 12 ∕ 25 AC:Basic/A:Admin/CI:Some/II:Some/E:Theoretical/TD:Default Vulnerability: Cross Site Scripting Affected versions: <2.1.0 CVE IDs: CVE-2026-81160 Description: Slick UI, a sub-module of Slick, enables you to add Slick option sets that may contain HTML for carousel buttons. Previous rele
Fuente: Drupal.org · CVE-2026-81160
Drupal
CVSS 6.1 · medio
26/08/2026 17:44 UTC
Project: Monster Menus Project machine name: monster_menus Date: 2026-August-26 Security risk: Moderately critical 13 ∕ 25 AC:Basic/A:User/CI:Some/II:Some/E:Theoretical/TD:Default Vulnerability: Cross-site Scripting Affected versions: <9.5.3 CVE IDs: CVE-2026-81201 Description: This module enables you to create one or more multisites with highly granular page permissions. The module doesn't suffic
Fuente: Drupal.org · CVE-2026-81201
Drupal
CVSS 5.3 · medio
26/08/2026 17:43 UTC
Project: LDAP / Active Directory Integration Project machine name: ldap_auth Date: 2026-August-26 Security risk: Moderately critical 14 ∕ 25 AC:Basic/A:None/CI:Some/II:None/E:Proof/TD:All Vulnerability: Information Disclosure Affected versions: <2.2.1 CVE IDs: CVE-2026-81205 Description: This module enables users to authenticate using LDAP or Active Directory credentials. The module does not suffi
Fuente: Drupal.org · CVE-2026-81205
Drupal
CVSS 5.4 · medio
26/08/2026 17:42 UTC
Project: Entity PDF Project machine name: entity_pdf Date: 2026-August-26 Security risk: Moderately critical 13 ∕ 25 AC:None/A:User/CI:Some/II:None/E:Theoretical/TD:All Vulnerability: Access bypass Affected versions: <2.1.5 CVE IDs: CVE-2026-81164 Description: The Entity PDF module can create a PDF from any entity based on any View mode. This module does not check entity view access when fetching
Fuente: Drupal.org · CVE-2026-81164
Drupal
CVSS 5.3 · medio
26/08/2026 17:41 UTC
Project: Entity API Project machine name: entity Date: 2026-August-26 Security risk: Moderately critical 12 ∕ 25 AC:Basic/A:None/CI:Some/II:None/E:Theoretical/TD:Default Vulnerability: Information disclosure Affected versions: <1.8.0 CVE IDs: CVE-2026-81158 Description: The Entity API module extends the Drupal core entity API to provide a unified way to deal with entities and their properties. The
Fuente: Drupal.org · CVE-2026-81158
Drupal
CVSS 5.3 · medio
26/08/2026 17:40 UTC
Project: DXPR Builder: The Best Editing (AI) Experience for Drupal Project machine name: dxpr_builder Date: 2026-August-26 Security risk: Moderately critical 14 ∕ 25 AC:None/A:None/CI:Some/II:None/E:Theoretical/TD:Default Vulnerability: Information Disclosure Affected versions: <2.8.1 CVE IDs: CVE-2026-81162 Description: The DXPR Builder module provides a visual / AI page builder for Drupal. The m
Fuente: Drupal.org · CVE-2026-81162
Drupal
CVSS 4.1 · medio
26/08/2026 17:39 UTC
Project: Disable Login Page Project machine name: disable_login Date: 2026-August-26 Security risk: Moderately critical 13 ∕ 25 AC:None/A:None/CI:None/II:None/E:Proof/TD:All Vulnerability: Access bypass Affected versions: <1.1.4 CVE IDs: CVE-2026-16647 Description: This module enables you to disable access to the /user/login form unless a secret key is provided. The module does not invalidate the
Fuente: Drupal.org · CVE-2026-16647
Drupal
CVSS 5.7 · medio
26/08/2026 17:38 UTC
Project: Disable Login Page Project machine name: disable_login Date: 2026-August-26 Security risk: Moderately critical 13 ∕ 25 AC:Basic/A:None/CI:Some/II:None/E:Theoretical/TD:All Vulnerability: Access bypass Affected versions: <1.1.4 CVE IDs: CVE-2026-18260 Description: This module enables you to disable access to the /user/login form unless a secret key is provided. The module does not sufficie
Fuente: Drupal.org · CVE-2026-18260
Drupal
CVSS 5.3 · medio
26/08/2026 17:38 UTC
Project: Digital Signage Framework Project machine name: digital_signage_framework Date: 2026-August-26 Security risk: Moderately critical 13 ∕ 25 AC:Basic/A:None/CI:Some/II:None/E:Theoretical/TD:All Vulnerability: Access bypass Affected versions: <2.6.1 CVE IDs: CVE-2026-81166 Description: The Digital Signage Framework module provides a route that signage devices can call to refresh dynamic block
Fuente: Drupal.org · CVE-2026-81166
Drupal
CVSS 5.3 · medio
26/08/2026 17:37 UTC
Project: Data field Project machine name: datafield Date: 2026-August-26 Security risk: Moderately critical 13 ∕ 25 AC:Basic/A:None/CI:Some/II:None/E:Theoretical/TD:All Vulnerability: Information disclosure Affected versions: <2.0.13 CVE IDs: CVE-2026-81269 Description: This module enables you to store structured data in configurable fields and expose Data Field values through JSON endpoints. The
Fuente: Drupal.org · CVE-2026-81269
Drupal
CVSS 3.3
26/08/2026 17:36 UTC
Project: Content Moderation Notifications Project machine name: content_moderation_notifications Date: 2026-August-26 Security risk: Moderately critical 12 ∕ 25 AC:Basic/A:Admin/CI:Some/II:Some/E:Theoretical/TD:Default Vulnerability: Access bypass Affected versions: <3.9.0 CVE IDs: CVE-2026-81161 Description: The module provides a permission that allows users to configure email templates containin
Fuente: Drupal.org · CVE-2026-81161
Drupal
CVSS 3.7
26/08/2026 17:35 UTC
Project: Commerce CyberSource Project machine name: commerce_cybersource Date: 2026-August-26 Security risk: Moderately critical 11 ∕ 25 AC:Complex/A:None/CI:None/II:Some/E:Theoretical/TD:Default Vulnerability: Insufficient input validation Affected versions: <1.10.0 CVE IDs: CVE-2026-81159 Description: This module integrates Drupal Commerce with the CyberSource payment gateway. The module does no
Fuente: Drupal.org · CVE-2026-81159
Drupal
CVSS 3.7
26/08/2026 17:34 UTC
Project: CAPTCHA Protected Page Project machine name: captcha_protected_page Date: 2026-August-26 Security risk: Moderately critical 12 ∕ 25 AC:Complex/A:None/CI:Some/II:None/E:Theoretical/TD:All Vulnerability: Cookie Forgery Affected versions: <1.0.2 CVE IDs: CVE-2026-81168 Description: This module enables site administrators to require CAPTCHA confirmation on specific pages. The module does not
Fuente: Drupal.org · CVE-2026-81168
Drupal
CVSS 5.3 · medio
26/08/2026 17:33 UTC
Project: Blazy Project machine name: blazy Date: 2026-August-26 Security risk: Less critical 9 ∕ 25 AC:Basic/A:User/CI:Some/II:None/E:Theoretical/TD:Uncommon Vulnerability: Access bypass Affected versions: <3.0.18 CVE IDs: CVE-2026-81165 Description: This module enables users to display a field of a target entity through a Blazy Filter plugin shortcode. The module does not consistently check entit
Fuente: Drupal.org · CVE-2026-81165
Linux (Debian)
26/08/2026 00:00 UTC
Two security issues were discovered in GNU Emacs, which could result in the execution of arbitrary code when opening a malformed file and denial of service when processing malformed PBM/PPM/PGM images. https://security-tracker.debian.org/tracker/DSA-6468-1
Fuente: Debian Security
Magento / e-commerce
25/08/2026 00:00 UTC
Shopware merchants should update to 6.7.13.1 or 6.6.10.23 immediately. Sansec discovered and confirmed the vulnerability in Shopware 6.7.12.2, the latest stable release at the time of testing.An a...
Fuente: Sansec
Magento / e-commerce
CVSS 9.1 · crítico
11/08/2026 00:00 UTC
Adobe has released isolated security patches for APSB26-92 for Adobe Commerce and Magento Open Source.The update fixes seven vulnerabilities. Five are rated Critical, including CVE-2026-71362, an ...
Fuente: Sansec · CVE-2026-71362
Magento / e-commerce
⚠ posible crítico
02/07/2026 00:00 UTC
Update August 25, 2026: This advisory now lists additional high-severity extensions.Update August 13, 2026: This advisory now lists medium and low-severity extensions.Update August 10, 2026: This...
Fuente: Sansec
Magento / e-commerce
⚠ posible crítico
17/06/2026 00:00 UTC
JTL responded fast and has released fixes for every supported branch: versions 5.5.4, 5.6.2 and 5.7.2, plus a back-patch covering 5.0.0 through 5.7.0. Every store owner running JTL Shop 5.2.0 or la...
Fuente: Sansec
Magento / e-commerce
13/06/2026 00:00 UTC
Sansec discovered an active supply-chain attack hitting over 1.2 million sites that use the popular OptinMonster, TrustPulse and PushEngage Wordpress plugins, all operated by Wordpress giant Awesom...
Fuente: Sansec
Magento / e-commerce
12/06/2026 00:00 UTC
Amasty Order Attributes contains an unauthenticated arbitrary file upload vulnerability. An attacker can upload a file of any type and name to the store's media directory with no login, no session ...
Fuente: Sansec
Magento / e-commerce
04/06/2026 00:00 UTC
The skimmer never loads from a domain the attacker controls. The loader, the payload, and the stolen cards all flow through two domains every store already trusts: Google Tag Manager and Stripe.Bo...
Fuente: Sansec
Magento / e-commerce
02/06/2026 00:00 UTC
A skimming operation tracked as GorgonAgora is running over 4,800 fake storefronts that impersonate real brands and steal payment data from anyone who checks out. An independent researcher has been...
Fuente: Sansec
Magento / e-commerce
01/06/2026 00:00 UTC
Sansec is proud to add Sylius to our list of supported platforms. Sansec eComscan now integrates with Sylius 1 and Sylius 2 and will run deep searches to hunt for malware & vulnerabilities.Whi...
Fuente: Sansec
Magento / e-commerce
⚠ posible crítico
26/05/2026 00:00 UTC
Sansec discovered an unauthenticated PHP object injection vulnerability in Mirasvit Cache Warmer, a full-page cache extension for Magento and Adobe Commerce. Any storefront request carrying a craft...
Fuente: Sansec
Magento / e-commerce
⚠ posible crítico
14/05/2026 00:00 UTC
Sansec is tracking active attacks against Funnel Builder by FunnelKit, a checkout and upsell plugin used on 40,000+ WooCommerce stores. All versions before 3.15.0.3 let unauthenticated attackers in...
Fuente: Sansec
Magento / e-commerce
13/05/2026 00:00 UTC
Update May 13th: GitHub has temporarily rolled back the new token format rollout. According to the Composer maintainers, that leaves a few days to update Composer in CI before the rollout resumes n...
Fuente: Sansec
Magento / e-commerce
14/04/2026 00:00 UTC
The affected stores span 27 countries, with France, Italy, Poland, and the Czech Republic accounting for the majority. Among them: a multi-billion dollar fashion retailer, two French university boo...
Fuente: Sansec
Magento / e-commerce
10/04/2026 00:00 UTC
The vendor is currently running a ClickFix clipboard hijacker on its own homepage. The vendor sells network exposure management and attack-path analysis to Fortune 500 enterprises, the US Departmen...
Fuente: Sansec
Magento / e-commerce
07/04/2026 00:00 UTC
In the early hours of April 7th, nearly 100 Magento stores got mass-infected with a "double-tap" skimmer: a credit card stealer hidden inside an invisible SVG element. Sansec found stolen...
Fuente: Sansec
Magento / e-commerce
30/03/2026 00:00 UTC
Sansec is tracking a mass exploitation wave of the PolyShell vulnerability that hit hundreds of online stores within a single hour today. The attacks are ongoing: new victims appear every minute.N...
Fuente: Sansec
Magento / e-commerce
24/03/2026 00:00 UTC
What sets this attack apart is the skimmer itself. Instead of the usual HTTP requests or image beacons, this malware uses WebRTC DataChannels to load its payload and exfiltrate stolen payment data....
Fuente: Sansec
Magento / e-commerce
⚠ posible crítico
17/03/2026 00:00 UTC
Sansec discovered and named the PolyShell vulnerability: a critical flaw in Magento's REST API that lets unauthenticated attackers upload executable files to any store. The attack uses a polyglot (...
Fuente: Sansec
Magento / e-commerce
20/02/2026 00:00 UTC
The affected company, with about €100 billion in annual revenue and over 10,000 stores across 25 countries, runs some of its ecommerce operations on the PrestaShop platform. As of publication, the ...
Fuente: Sansec
Magento / e-commerce
18/02/2026 00:00 UTC
YARA is the industry standard for pattern matching in malware detection. Maintained by VirusTotal, it powers threat detection at nearly every security vendor. At Sansec, we rely on YARA for eComsca...
Fuente: Sansec
Magento / e-commerce
11/02/2026 00:00 UTC
Rob Aimes alerted us to malicious GitHub repositories targeting Magento developers. The repos pose as legitimate tools but deliver Windows malware: a RAT and keylogger bundled as a LuaJIT package. ...
Fuente: Sansec
Magento / e-commerce
⚠ posible crítico
22/01/2026 00:00 UTC
Open source ecosystems have a long tail security problem. Python, Ruby, Javascript, PHP: these ecosystems have millions of packages. The top 100 packages get scrutinized. The next 5,000, not so muc...
Fuente: Sansec
Magento / e-commerce
16/01/2026 00:00 UTC
Yesterday, Sansec discovered an active keylogger at an external site of one of America's largest banks. The malware was harvesting private information from over 200,000 potential victims. We detect...
Fuente: Sansec
Magento / e-commerce
15/01/2026 00:00 UTC
Update Jan 15th: the malware appears to have been removed. It was live for about 18 hoursSansec detected a keylogger on the employee store of one of America's largest banks. The site serves over 2...
Fuente: Sansec
Magento / e-commerce
12/01/2026 00:00 UTC
Sansec researchers discovered that ConnectPOS, a popular Point of Sale solution, had been exposing a GitHub Personal Access Token (PAT) in their public installation instructions for over four years...
Fuente: Sansec
Magento / e-commerce
⚠ posible crítico
15/12/2025 00:00 UTC
NameMgt_VarnishVulnerable1.0.10 and earlierFixed in1.1.0Sansec researchers discovered a critical vulnerability in the popular Varnish module for Magento. This module, develope...
Fuente: Sansec
Magento / e-commerce
CVSS 9.1 · crítico
22/10/2025 00:00 UTC
Six weeks after Adobe's emergency patch for SessionReaper (CVE-2025-54236), the vulnerability has entered active exploitation. Sansec Shield detected and blocked the first real-world attacks today,...
Fuente: Sansec · CVE-2025-54236
Magento / e-commerce
CVSS 9.1 · crítico
08/09/2025 00:00 UTC
October 22nd: mass SessionReaper attacks have startedIn August 2025, a critical (CVSS 9.1) flaw was discovered in all versions of Adobe Commerce and Magento. The bug, named "SessionReaper&q...
Fuente: Sansec · CVE-2025-54236
Magento / e-commerce
CVSS 8.4 · alto
12/06/2025 00:00 UTC
Adobe has just released several security fixes for its Commerce (Magento) platform and one of them is critical (CVE-2025-47110). Adobe urges merchants to patch within 72 hours (highest priority).S...
Fuente: Sansec · CVE-2025-47110
Magento / e-commerce
01/05/2025 00:00 UTC
Hundreds of stores, including a $40 billion multinational, are running backdoored versions of popular ecommerce software. We found that the backdoor is actively used since at least April 20th. Sans...
Fuente: Sansec
Magento / e-commerce
03/04/2025 00:00 UTC
The Sansec Shield WAF detected mass scans for "defunct.dat" and "qfile" files this week. As it turns out, these files contain connection keys that can be used to launch a GSocke...
Fuente: Sansec
Magento / e-commerce
17/03/2025 00:00 UTC
The new PCI-DSS regulations that will come into effect after March 31st, 2025, require merchants to monitor scripts on their payment pages to prevent digital skimming attacks*. The use of Conte...
Fuente: Sansec
Magento / e-commerce
06/03/2025 00:00 UTC
It's insanity that we still don't have clarity(Clean_Anteater992)They have to be kidding me (sawer82)It's clusterf after clusterf (andrew_barratt)The Payment Card Industry Security Stan...
Fuente: Sansec
Magento / e-commerce
⚠ posible crítico
12/02/2025 00:00 UTC
APSB25-08 released on Feb 11th, 2025Critical Adobe Commerce/Magento security patches have just been released (CVSS 9.4/10)New versions: 2.4.4-p12, 2.4.5-p11, 2.4.6-p9, 2.4.7-p4, additionally 2.4....
Fuente: Sansec
Magento / e-commerce
03/02/2025 00:00 UTC
Merchants spend millions of dollars on client-side security solutions to prevent digital skimming attacks. Companies are rushing to implement these tools, often driven by PCI requirements. But here...
Fuente: Sansec
Magento / e-commerce
31/12/2024 00:00 UTC
Google TranslateAttackers are using Google Translate’s page functionality to execute malicious JavaScript files, as demonstrated below:<script src="https://translate.google.co.in/translat...
Fuente: Sansec
Magento / e-commerce
CVSS 9.8 · crítico
01/10/2024 00:00 UTC
Sansec research shows that seven different groups have been hacking into 4275 online stores since the publication of CVE-2024-34102 (also known as CosmicSting) on June 11th. Despite ongoing warning...
Fuente: Sansec · CVE-2024-34102
Magento / e-commerce
⚠ posible crítico
16/09/2024 00:00 UTC
ImplicationsCosmicSting targets a critical bug in the Adobe Commerce and Magento platforms. Bad actors use it to read any of your files, such as passwords and other secrets. The typical attack str...
Fuente: Sansec
Magento / e-commerce
CVSS 9.8 · crítico
27/08/2024 00:00 UTC
CosmicSting (CVE-2024-34102) allows arbitrary file reading on unpatched systems. When combined with CNEXT (CVE-2024-2961), threat actors can escalate to remote code execution, taking over the entir...
Fuente: Sansec · CVE-2024-34102
Magento / e-commerce
12/07/2024 00:00 UTC
API AbuseAs CosmicSting enables attackers to read any file, attackers can steal Magento's secret encryption key. This encryption key can generate JSON Web Tokens with full administrative API acces...
Fuente: Sansec
Magento / e-commerce
25/06/2024 00:00 UTC
Update June 28th: We are flagging more domains that have been used by the same actor to spread malware since at least June 2023: bootcdn.net, bootcss.com, staticfile.net, staticfile.org, unionad...
Fuente: Sansec
Magento / e-commerce
18/06/2024 00:00 UTC
Update June 27th: Adobe has now provided an official, isolated fix that can be applied to installations without requiring upgrade.Update June 27th: our partner Hypernode as actually observed the ...
Fuente: Sansec
Magento / e-commerce
04/04/2024 00:00 UTC
The following XML code was found in the layout_update database table and is responsible for periodic reinfections of your system.Attackers combine the Magento layout parser with the beberlei/asse...
Fuente: Sansec
Magento / e-commerce
08/03/2024 00:00 UTC
In January we announced our partnership with Europol and today, we are proud to be recognized by Google as experts in eCommerce security.Sansec and Google have agreed on a data exchange and we tru...
Fuente: Sansec
Magento / e-commerce
09/01/2024 00:00 UTC
In a strategic alliance, Europol, the European Union Agency for Cybersecurity (ENISA), law enforcement from 17 nations, and key private sector entities such as Sansec, have aligned to counteract th...
Fuente: Sansec
Magento / e-commerce
18/12/2023 00:00 UTC
In recent weeks, Sansec observed a spike in hacked Magento 2 stores. Our investigations led to a (likely) single attacker, who used a combination of clever techniques to bypass WAFs and competing t...
Fuente: Sansec
Magento / e-commerce
10/11/2023 00:00 UTC
Cybercriminals in eCommerce are diversifying their targets, now aiming at entire customer databases instead of just stealing credit cards. A recent incident revealed this trend: a hacked Magento ad...
Fuente: Sansec
Magento / e-commerce
22/08/2023 00:00 UTC
Attackers are devising ingenious methods to prolong their skimming activities, aiming for sustained persistence.The usual tactics, techniques, and procedures (TTP) include the creation of disposab...
Fuente: Sansec
Magento / e-commerce
09/05/2023 00:00 UTC
The domain gtag-analytics.com has recently emerged as a threat, employing various cunning techniques to evade detection and targeting unsuspecting users, but what makes it especially deceptive is i...
Fuente: Sansec
Magento / e-commerce
07/02/2023 00:00 UTC
It is a common practice to make ad-hoc backups during store platform maintenance. The problem, however, is that these backups often end up in a public folder. Perhaps the administrator intended to ...
Fuente: Sansec
Magento / e-commerce
CVSS 9.8 · crítico
17/01/2023 00:00 UTC
BackgroundAdobe’s fix to CVE-2022-24086 was to remove “smart” mail templates. Many vendors were caught off guard and had to revert to the original functionality. In doing so, they unknowingly expo...
Fuente: Sansec · CVE-2022-24086
Magento / e-commerce
21/12/2022 00:00 UTC
Magento 2 template hacks have been raging since a month or two, and Sansec is closely tracking any new attack payloads. So far, we observed about 20 different payloads which all added a basic PHP b...
Fuente: Sansec
Magento / e-commerce
15/11/2022 00:00 UTC
After a quiet summer, the number of attacks targeting the mail template vulnerability in Magento 2 and Adobe Commerce is rising fast. Merchants and developers should be on the lookout for TrojanOrd...
Fuente: Sansec
Magento / e-commerce
07/11/2022 00:00 UTC
Related: many stores are occassionally contacted by "security researchers" who claim to have found a vulnerability and want a "bounty" to disclose it. In 99% of these cases, the...
Fuente: Sansec
Magento / e-commerce
22/09/2022 00:00 UTC
Currently, Sansec eComscan is the only malware scanner that detects the injected remote access trojan (see Virustotal).223sam.jpg attackAll of the observed attacks have been interactive, possibly...
Fuente: Sansec
Magento / e-commerce
13/09/2022 00:00 UTC
Update 2022-09-13 FishPig has confirmed the incident and published a status page. It recommends customers to upgrade and/or reinstall all FishPig modules.Sansec discovered malware in the Fishpig ...
Fuente: Sansec
Magento / e-commerce
CVSS 9.8 · crítico
14/02/2022 00:00 UTC
Update Feb 21st, 2022: Sansec has observed the first actual attacks in the wild. Patch now! Unfortunately, this validates our previous prediction that abuse would start within days. Attacks are com...
Fuente: Sansec · CVE-2022-24086
Magento / e-commerce
08/02/2022 00:00 UTC
More than 350 ecommerce stores infected with malware in a single day.Today our global crawler discovered 374 ecommerce stores infected with the same strain of malware. 370 of these stores load the ...
Fuente: Sansec
Magento / e-commerce
⚠ posible crítico
13/12/2021 00:00 UTC
Updated Dec 20th. This article describes how Magento is affected by the critical log4j vulnerability, and what you can (and should) do to prevent a hack.A critical vulnerability in the popular Log...
Fuente: Sansec
Magento / e-commerce
01/12/2021 00:00 UTC
Last week we exposed the CronRAT eCommerce malware, which is controlled by a Chinese server. Out of curiosity, we wrote a "custom" RAT client and waited for commands from the far east. Ev...
Fuente: Sansec
Magento / e-commerce
24/11/2021 00:00 UTC
At this time of year we typically see a surge in eCommerce attacks and new malware. Last week we analyzed a clever malware attacking online stores, and today we expose another, much more sophistica...
Fuente: Sansec
Magento / e-commerce
18/11/2021 00:00 UTC
A merchant recently reached out to us, after hiring two forensic companies but still having malware on his store. As we appreciate a challenge, our team got started and quickly discovered an intric...
Fuente: Sansec
Magento / e-commerce
18/02/2021 00:00 UTC
The Google business application platform Apps Script is used to funnel stolen personal data, Sansec learned. Attackers use the reputation of the trusted Google domain script.google.com to evade mal...
Fuente: Sansec
Magento / e-commerce
24/12/2020 00:00 UTC
Once the data is intercepted and exfiltrated, the attackers display an error message and the customer is redirected to the real payment page. Customers probably just enter their details again and i...
Fuente: Sansec
Magento / e-commerce
18/12/2020 00:00 UTC
Sansec discovered a clever remote access trojan (RAT) that has been hiding in the alleys of hacked eCommerce servers. Despite the advanced setup, perpetrators mistakenly left a list of victim store...
Fuente: Sansec
Magento / e-commerce
02/12/2020 00:00 UTC
The affected stores were all running the older Magento 2.2, which is unsupported since December 2019.In addition to the injected flaw, attackers used a hybrid skimming architecture, with front and...
Fuente: Sansec
Magento / e-commerce
26/11/2020 00:00 UTC
Researchers at Sansec have uncovered a novel technique to inject payment skimmers onto checkout pages. This new malware has two parts: a concealed payload and a decoder, of which the latter reads t...
Fuente: Sansec
Magento / e-commerce
14/09/2020 00:00 UTC
Update Sept 18: Cardbleed has infected 2806 Magento1 stores so far (3% of total install base)Over the weekend, almost two thousand Magento 1 stores across the world have been hacked in the larges...
Fuente: Sansec
Magento / e-commerce
06/07/2020 00:00 UTC
Previously, North Korean hacking activity was mostly restricted to banks and South Korean crypto markets^cryptohack, covert cyber operations that earned hackers $2 billion, according to a 2019 Unit...
Fuente: Sansec
Magento / e-commerce
22/06/2020 00:00 UTC
A newly discovered skimming campaign runs entirely on Google servers, Sansec research shows. The novel malware sends stolen credit cards directly to Google Analytics, evading security controls like...
Fuente: Sansec
Magento / e-commerce
15/06/2020 00:00 UTC
While an international retail chain closed its physical stores, attackers hacked its online presence, Sansec research shows. Following common Magecart malpractice, payment skimmers were injected an...
Fuente: Sansec
Magento / e-commerce
28/05/2020 00:00 UTC
Over a 100 thousands Magento 1 stores will be running after Adobe terminates support in June (end-of-life). Many merchants need more time to transition to Magento 2 or another platform. No need to ...
Fuente: Sansec
Magento / e-commerce
08/05/2020 00:00 UTC
Magento 1 will no longer receive official updates & security fixes per July 1st, 2020 (the end-of-life, or EOL date). Merchants are urged to upgrade to Magento 2, but for many stores this deadl...
Fuente: Sansec
Magento / e-commerce
25/02/2020 00:00 UTC
Sansec, a global leader in eCommerce security, reveals that hackers successfully infiltrated an online printing platform for more than two and a half years. Our research shows that crooks ran keylo...
Fuente: Sansec
Magento / e-commerce
20/02/2020 00:00 UTC
Utrecht, February 20; Sansec is proud to announce that it hasformed a long-term strategic partnership with maxcluster to bring itsindustry-leading anti-malware technology to the German e-commerce...
Fuente: Sansec
Magento / e-commerce
25/01/2020 00:00 UTC
The Indonesian police announced on Friday that they have arrested three alleged Magecart hackers on December 20th. The suspects are from Jakarta and Yogyakarta and are 23, 26 and 35 years old. Afte...
Fuente: Sansec
Magento / e-commerce
02/12/2019 00:00 UTC
Payment skimmers are hiding their malpractice by impersonating our Sansec anti-skimming service. They have registered malicious domains sansec.us and sanguinelab.net, even using a fake address in A...
Fuente: Sansec
Magento / e-commerce
25/10/2019 00:00 UTC
Digital skimming groups (aka Magecart) hit another low, as they successfully targeted the American Cancer Society last night. Our skimmer detectors found a piece of malicious code embedded on the C...
Fuente: Sansec
Magento / e-commerce
07/10/2019 00:00 UTC
The store of a US Magento extension vendor was found compromised. Attackers had write access to the server selling extensions. We are awaiting a statement on the integrity of downloaded software.O...
Fuente: Sansec
Magento / e-commerce
17/08/2019 00:00 UTC
The FBI warns small and medium-sized businesses and government agencies against the threat of e-skimming. E-skimming occurs when cyber criminals inject malicious code onto a website.Read the origi...
Fuente: Sansec
Magento / e-commerce
12/08/2019 00:00 UTC
Cementing itself as a global force in the protection against eCommerce fraud, Sansec has been invited to speak at the fifth edition of Europol’s Training Course on Payment Card Fraud Forensic Inves...
Fuente: Sansec
Magento / e-commerce
01/08/2019 00:00 UTC
The PCI Security Standards Council and the Retail & Hospitality ISAC alert merchants to the threat of digital skimming. In its report, it quotes Sansec research, which has found that about 20% ...
Fuente: Sansec
Magento / e-commerce
⚠ posible crítico
10/05/2019 00:00 UTC
The number of hacked Magento 2 stores spiked in the last four weeks, after a critical security flaw was discovered in March and criminals stole admin passwords within 16 hours. Merchants are advise...
Fuente: Sansec
Magento / e-commerce
29/04/2019 00:00 UTC
After the NBA Hawks got skimmed last week, this time Puma's Australian customers are cannon fodder for Magecart thieves. Anyone who ordered a pair of sneakers online, had their name, address and cr...
Fuente: Sansec
Magento / e-commerce
29/04/2019 00:00 UTC
Sansec discovered a polymorphic skimmer that works with 57 different payment gateways. It has global reach, affecting payment systems from Germany to Brazil. It is by far the most advanced skimmer ...
Fuente: Sansec
Magento / e-commerce
24/04/2019 00:00 UTC
MageCart attacks on online stores surged last year, culminating in the hack of British Airways and Ticketmaster. This year the trend continues with another high-profile target. The Atlanta Hawks sh...
Fuente: Sansec
Magento / e-commerce
⚠ posible crítico
29/01/2019 00:00 UTC
In October last year Sansec discovered several Magento extension 0days. As it turns out, this was only the tip of the iceberg: today, insecure 3rd party extensions are used to hack into thousands o...
Fuente: Sansec
Magento / e-commerce
20/01/2019 00:00 UTC
This week Sansec discovered that large ecommerce and government sites got hacked via the Adminer database tool. As it turns out, the root cause is a protocol flaw in MySQL. Curiously, it is describ...
Fuente: Sansec
Magento / e-commerce
17/01/2019 00:00 UTC
Update 2019-01-20: the root cause is a protocol flaw in MySQL.Adminer is a popular PHP tool to administer MySQL and PostgreSQL databases. However, it can be lured to disclose arbitrary files. Atta...
Fuente: Sansec
Magento / e-commerce
20/11/2018 00:00 UTC
Skimmers found to subtly sabotage each others fraud operations.Competition is grim in the online skimming business (aka "MageCart"). The aggressive MagentoCore skimmer was previously obs...
Fuente: Sansec
Magento / e-commerce
12/11/2018 00:00 UTC
1 in 5 compromised merchants get reinfected, average skimming operation lasts 13 daysMageCart, the notorious actors behind massive online card skimming, has been busy. And so have we: our crawlers...
Fuente: Sansec
Magento / e-commerce
30/10/2018 00:00 UTC
Update Nov 23rd: Webgility has released a patch and a public statement, urging all customers to upgrade to version 345.Update Nov 30th: Webgility has discovered another security issue and urges al...
Fuente: Sansec
Magento / e-commerce
⚠ posible crítico
23/10/2018 00:00 UTC
Online credit card theft has been all over the news: criminals inject hidden card stealers on legitimate checkout pages. But how are they are able to inject anything in the first place? As it turns...
Fuente: Sansec
Magento / e-commerce
15/10/2018 00:00 UTC
The store of German political party CSU (www.csu-shop.de) contains an identity skimmer that was planted on or before Oct 5th, right before the Bavarian election on Oct 14th. Personal identifyable i...
Fuente: Sansec
Magento / e-commerce
04/10/2018 00:00 UTC
Back in 2016, Magecart skimmers would evade detection by sleeping if any developer tools were found running. Then, their malware would 404 without correct Referer or User-Agent header. And now, Mag...
Fuente: Sansec
Magento / e-commerce
18/09/2018 00:00 UTC
While Filipinos are recovering from typhoon Mangkhut, another misfortune awaits them online. We found their broadcasting giant ABS-CBN − a $740 million conglomerate & top-500 global Internet de...
Fuente: Sansec
Magento / e-commerce
06/09/2018 00:00 UTC
Would you - a webdeveloper - get alarmed if you found the following code on your website? Probably not, as Google Analytics is embedded in pretty much every website these days:<script type=&quo...
Fuente: Sansec
Magento / e-commerce
30/08/2018 00:00 UTC
A single group is responsible for planting skimmers on 7339 individual stores in the last 6 months. The MagentoCore skimmer is now the most successful to date.Update 2018-09-07: Because Google Chr...
Fuente: Sansec
Magento / e-commerce
28/12/2017 00:00 UTC
Magento merchants have recently received messages like this:Hey, I strongly recommend you to make a redesign! Please contact me if you need a good designer! -- knockers@yahoo.comUpon closer exa...
Fuente: Sansec
Magento / e-commerce
07/11/2017 00:00 UTC
Does your laptop get hot when visiting your favorite shop? You computer is likely mining cryptocurrencies to the benefit of a cyberthief.Cryptojacking - running crypto mining software in the brow...
Fuente: Sansec
Magento / e-commerce
02/05/2017 00:00 UTC
If you code against Akamai hosted sites, you could be rejected because your HTTP library sends request headers in the wrong order. In fact, most libraries use undefined order, as the IETF specifica...
Fuente: Sansec
Magento / e-commerce
21/04/2017 00:00 UTC
Update May 21st: a similar phishing mail circulates about a fake patch SUPEE-1798.Update Apr 22nd: added reference to Neutrino Bot and POS systemsThis week a mail was sent out to announce the ne...
Fuente: Sansec
Magento / e-commerce
12/04/2017 00:00 UTC
Part of a series where Magento security professionals share their case notes, so that we can ultimately distill a set of best practices, tools and workflow.Part of the job of running the MageRepor...
Fuente: Sansec
Magento / e-commerce
07/04/2017 00:00 UTC
This post shows how sophisticated Magento hacking operations have become nowadays.While investigating a bruteforced Magento store, we noticed that the hacker logged in using a curious referrer sit...
Fuente: Sansec
Magento / e-commerce
14/02/2017 00:00 UTC
Regular Javascript-based malware is normally injected in the static header or footer HTML definitions in the database. Cleaning these records used to be sufficient to get rid of the malware. But no...
Fuente: Sansec
Magento / e-commerce
01/12/2016 00:00 UTC
Visbot is one of the oldest Magecart payment skimmers: it steals customer data and credit cards. The first case was documented as early as March 2015. But being publicly discussed did not stop it f...
Fuente: Sansec
Magento / e-commerce
17/11/2015 00:00 UTC
Criminals have secretly rewired 3,500 online stores to continuously harvest credit card numbers. The fraud can be traced back as far as May 12th 2015, so if you have bought something at one of thes...
Fuente: Sansec