Alertas de Deblanco

avisos de seguridad: Magento, Drupal y Linux, en un sitio

Actualizado: 13/09/2026 15:15 UTC

Linux (Debian) 12/09/2026 00:00 UTC

DSA-6497-1 xorg-server - security update

Several vulnerabilities were discovered in the Xorg X server, which may result in privilege escalation if the X server is running privileged. https://security-tracker.debian.org/tracker/DSA-6497-1

Fuente: Debian Security

Linux (Debian) CVSS 8.1 · alto 12/09/2026 00:00 UTC

DSA-6496-1 nginx - security update

Multiple vulnerabilities were discovered in nginx, a high-performance web and reverse proxy server, which may result in denial of service, memory disclosure or potentially the execution of arbitrary code. CVE-2026-42533 A heap buffer overflow was discovered in the nginx script engine. It can be triggered when a map directive performs regular expression matching and a string expression references c

Fuente: Debian Security · CVE-2026-42533

Linux (Debian) 11/09/2026 00:00 UTC

DSA-6495-1 spip - security update

Several vulnerabilities were discovered in SPIP, a website engine for publishing, which could result in unauthenticated remote code execution. https://security-tracker.debian.org/tracker/DSA-6495-1

Fuente: Debian Security

Linux (Debian) 11/09/2026 00:00 UTC

DSA-6494-1 kamailio - security update

Multiple security vulnerabilities were discovered in the Kamailio SIP server, which could result in denial of service. https://security-tracker.debian.org/tracker/DSA-6494-1

Fuente: Debian Security

Linux (Debian) 11/09/2026 00:00 UTC

DSA-6493-1 libevent - security update

Several vulnerabilities were discovered in libevent, an asynchronous event notification library. The HTTP implementation (evhttp) handled Transfer-Encoding and Content-Length headers, chunked-encoding line terminators, header line folding and chunked trailers too permissively, which could allow HTTP request smuggling, header injection or access control bypass when a libevent-based server or client

Fuente: Debian Security

Linux (Debian) 10/09/2026 00:00 UTC

DSA-6492-1 ruby-rack - security update

Multiple security issues were found in Rack, an interface for developing web applications in Ruby, which could result in denial of service, information disclosure, spoofing or bypass of access restrictions. https://security-tracker.debian.org/tracker/DSA-6492-1

Fuente: Debian Security

Drupal ⚠ posible crítico 09/09/2026 17:24 UTC

Ultimate Table Field - Critical - Access bypass - SA-CONTRIB-2026-153

Project: Ultimate Table Field Project machine name: ultimate_table_field Date: 2026-September-09 Security risk: Critical 15 ∕ 25 AC:None/A:None/CI:None/II:Some/E:Theoretical/TD:All Vulnerability: Access bypass Affected versions: <1.1.1 || >=2.0.0 <2.0.1 CVE IDs: CVE-2026-87955 Description: The Ultimate Table Field module enables you to store table data in a field and edit each table cell through a

Fuente: Drupal.org · CVE-2026-87955

Drupal ⚠ posible crítico 09/09/2026 17:24 UTC

Taxonomy Term Glossary - Critical - Access bypass - SA-CONTRIB-2026-152

Project: Taxonomy Term Glossary Project machine name: term_glossary Date: 2026-September-09 Security risk: Critical 15 ∕ 25 AC:None/A:None/CI:Some/II:None/E:Theoretical/TD:All Vulnerability: Access bypass Affected versions: <4.6.0 CVE IDs: CVE-2026-87954 Description: This module adds automatic highlighting of taxonomy terms in content. The module doesn't sufficiently check access on taxonomy terms

Fuente: Drupal.org · CVE-2026-87954

Drupal 09/09/2026 17:23 UTC

SAML SSO - Service Provider - Moderately critical - Server Side Request Forgery - SA-CONTRIB-2026-151

Project: SAML SSO - Service Provider Project machine name: miniorange_saml Date: 2026-September-09 Security risk: Moderately critical 11 ∕ 25 AC:Complex/A:Admin/CI:Some/II:Some/E:Theoretical/TD:Default Vulnerability: Server Side Request Forgery Affected versions: <3.2.0 CVE IDs: CVE-2026-87953 Description: This module allows you to configure your Drupal site as a SAML 2.0 Service Provider so that

Fuente: Drupal.org · CVE-2026-87953

Drupal 09/09/2026 17:23 UTC

SAML SSO - Service Provider - Moderately critical - Insufficient replay protection - SA-CONTRIB-2026-150

Project: SAML SSO - Service Provider Project machine name: miniorange_saml Date: 2026-September-09 Security risk: Moderately critical 10 ∕ 25 AC:Complex/A:User/CI:None/II:Some/E:Theoretical/TD:All Vulnerability: Insufficient replay protection Affected versions: <3.2.0 CVE IDs: CVE-2026-87952 Description: This module allows you to configure your Drupal site as a SAML 2.0 Service Provider so that us

Fuente: Drupal.org · CVE-2026-87952

Drupal 09/09/2026 17:22 UTC

SAML SSO - Service Provider - Moderately critical - Information disclosure - SA-CONTRIB-2026-149

Project: SAML SSO - Service Provider Project machine name: miniorange_saml Date: 2026-September-09 Security risk: Moderately critical 12 ∕ 25 AC:Basic/A:Admin/CI:Some/II:Some/E:Theoretical/TD:Default Vulnerability: Information disclosure Affected versions: <3.2.0 CVE IDs: CVE-2026-87951 Description: This module allows you to configure your Drupal site as a SAML 2.0 Service Provider so that users c

Fuente: Drupal.org · CVE-2026-87951

Drupal 09/09/2026 17:22 UTC

SAML SSO - Service Provider - Moderately critical - Embedded credentials - SA-CONTRIB-2026-148

Project: SAML SSO - Service Provider Project machine name: miniorange_saml Date: 2026-September-09 Security risk: Moderately critical 13 ∕ 25 AC:None/A:None/CI:Some/II:None/E:Theoretical/TD:Uncommon Vulnerability: Embedded credentials Affected versions: <3.2.0 CVE IDs: CVE-2026-87950 Description: This module allows you to configure your Drupal site as a SAML 2.0 Service Provider so that users can

Fuente: Drupal.org · CVE-2026-87950

Drupal 09/09/2026 17:22 UTC

SAML SSO - Service Provider - Moderately critical - Cross-site scripting - SA-CONTRIB-2026-147

Project: SAML SSO - Service Provider Project machine name: miniorange_saml Date: 2026-September-09 Security risk: Moderately critical 12 ∕ 25 AC:Complex/A:Admin/CI:Some/II:Some/E:Theoretical/TD:All Vulnerability: Cross-site scripting Affected versions: <3.2.0 CVE IDs: CVE-2026-87949 Description: This module allows you to configure your Drupal site as a SAML 2.0 Service Provider so that users can a

Fuente: Drupal.org · CVE-2026-87949

Drupal 09/09/2026 17:21 UTC

SAML SSO - Service Provider - Moderately critical - Cross-site scripting - SA-CONTRIB-2026-146

Project: SAML SSO - Service Provider Project machine name: miniorange_saml Date: 2026-September-09 Security risk: Moderately critical 13 ∕ 25 AC:Basic/A:Admin/CI:Some/II:Some/E:Theoretical/TD:All Vulnerability: Cross-site scripting Affected versions: <3.2.0 CVE IDs: CVE-2026-87948 Description: This module allows you to configure your Drupal site as a SAML 2.0 Service Provider so that users can aut

Fuente: Drupal.org · CVE-2026-87948

Drupal 09/09/2026 17:21 UTC

SAML SSO - Service Provider - Moderately critical - Authentication bypass - SA-CONTRIB-2026-145

Project: SAML SSO - Service Provider Project machine name: miniorange_saml Date: 2026-September-09 Security risk: Moderately critical 14 ∕ 25 AC:Complex/A:None/CI:Some/II:Some/E:Theoretical/TD:Default Vulnerability: Authentication bypass Affected versions: <3.2.0 CVE IDs: CVE-2026-87947 Description: This module allows you to configure your Drupal site as a SAML 2.0 Service Provider so that users c

Fuente: Drupal.org · CVE-2026-87947

Drupal 09/09/2026 17:21 UTC

SAML SSO - Service Provider - Critical - Weak cryptographic practices - SA-CONTRIB-2026-144

Project: SAML SSO - Service Provider Project machine name: miniorange_saml Date: 2026-September-09 Security risk: Critical 15 ∕ 25 AC:Complex/A:None/CI:Some/II:Some/E:Theoretical/TD:All Vulnerability: Weak cryptographic practices Affected versions: <3.2.0 CVE IDs: CVE-2026-87946 Description: This module allows you to configure your Drupal site as a SAML 2.0 Service Provider so that users can authe

Fuente: Drupal.org · CVE-2026-87946

Drupal 09/09/2026 17:20 UTC

SAML SSO - Service Provider - Critical - Open redirect - SA-CONTRIB-2026-143

Project: SAML SSO - Service Provider Project machine name: miniorange_saml Date: 2026-September-09 Security risk: Critical 16 ∕ 25 AC:Basic/A:None/CI:Some/II:Some/E:Theoretical/TD:All Vulnerability: Open redirect Affected versions: <3.2.0 CVE IDs: CVE-2026-87945 Description: This module allows you to configure your Drupal site as a SAML 2.0 Service Provider so that users can authenticate through a

Fuente: Drupal.org · CVE-2026-87945

Drupal 09/09/2026 17:20 UTC

SAML SSO - Service Provider - Critical - Improper certificate validation - SA-CONTRIB-2026-142

Project: SAML SSO - Service Provider Project machine name: miniorange_saml Date: 2026-September-09 Security risk: Critical 15 ∕ 25 AC:Complex/A:None/CI:Some/II:Some/E:Theoretical/TD:All Vulnerability: Improper certificate validation Affected versions: <3.2.0 CVE IDs: CVE-2026-87944 Description: This module allows you to configure your Drupal site as a SAML 2.0 Service Provider so that users can au

Fuente: Drupal.org · CVE-2026-87944

Drupal 09/09/2026 17:19 UTC

SAML SSO - Service Provider - Critical - Improper access control - SA-CONTRIB-2026-141

Project: SAML SSO - Service Provider Project machine name: miniorange_saml Date: 2026-September-09 Security risk: Critical 18 ∕ 25 AC:None/A:None/CI:Some/II:Some/E:Theoretical/TD:All Vulnerability: Improper access control Affected versions: <3.2.0 CVE IDs: CVE-2026-87943 Description: This module allows you to configure your Drupal site as a SAML 2.0 Service Provider so that users can authenticate

Fuente: Drupal.org · CVE-2026-87943

Drupal 09/09/2026 17:19 UTC

SafeDelete - Moderately critical - Cross-site scripting - SA-CONTRIB-2026-140

Project: SafeDelete Project machine name: safedelete Date: 2026-September-09 Security risk: Moderately critical 12 ∕ 25 AC:Basic/A:User/CI:Some/II:Some/E:Theoretical/TD:Uncommon Vulnerability: Cross-site scripting Affected versions: <1.0.88 CVE IDs: CVE-2026-87942 Description: This module enables you to manage content deletion and provides reports for identifying orphaned content. The module doesn

Fuente: Drupal.org · CVE-2026-87942

Drupal ⚠ posible crítico 09/09/2026 17:18 UTC

Patreon - Critical - Unsupported - SA-CONTRIB-2026-139

Project: Patreon Project machine name: patreon Date: 2026-September-09 Security risk: Critical 16 ∕ 25 AC:Complex/A:Admin/CI:All/II:All/E:Theoretical/TD:All Vulnerability: Unsupported CVE IDs: CVE-2026-87941 Description: The Drupal Security Team is marking this project unsupported. There is a known security issue with the project that has not been fixed by the maintainer. If you would like to main

Fuente: Drupal.org · CVE-2026-87941

Drupal 09/09/2026 17:17 UTC

Key auth - Moderately critical - Access bypass - SA-CONTRIB-2026-138

Project: Key auth Project machine name: key_auth Date: 2026-September-09 Security risk: Moderately critical 13 ∕ 25 AC:Basic/A:User/CI:Some/II:Some/E:Theoretical/TD:Default Vulnerability: Access bypass Affected versions: <2.2.4 CVE IDs: CVE-2026-87940 Description: This module enables you to add key-based authentication on a per-user basis. The module doesn't cache per user, potentially allowing an

Fuente: Drupal.org · CVE-2026-87940

Drupal 09/09/2026 17:16 UTC

Feed Block - Moderately critical - Cross-site scripting - SA-CONTRIB-2026-137

Project: Feed Block Project machine name: feed_block Date: 2026-September-09 Security risk: Moderately critical 13 ∕ 25 AC:Complex/A:User/CI:Some/II:Some/E:Theoretical/TD:All Vulnerability: Cross-site scripting Affected versions: <2.0.2 || >=3.0.0 <3.0.2 CVE IDs: CVE-2026-87939 Description: The Feed Block module provides a block content type that displays items pulled from a remote RSS/Atom feed.

Fuente: Drupal.org · CVE-2026-87939

Drupal ⚠ posible crítico 09/09/2026 17:16 UTC

CSP log - Critical - SQL Injection - SA-CONTRIB-2026-136

Project: CSP log Project machine name: csp_log Date: 2026-September-09 Security risk: Critical 15 ∕ 25 AC:Basic/A:Admin/CI:All/II:Some/E:Theoretical/TD:All Vulnerability: SQL Injection Affected versions: <1.0.2 CVE IDs: CVE-2026-87938 Description: The CSP Log module enhances any module that adds the CSP header to a site, by providing a reporting endpoint, custom storage, and aggregated reports tha

Fuente: Drupal.org · CVE-2026-87938

Drupal 09/09/2026 17:15 UTC

Central Authentication System (CAS) Server - Moderately critical - Open redirect - SA-CONTRIB-2026-135

Project: Central Authentication System (CAS) Server Project machine name: cas_server Date: 2026-September-09 Security risk: Moderately critical 10 ∕ 25 AC:Basic/A:None/CI:None/II:None/E:Theoretical/TD:All Vulnerability: Open redirect Affected versions: <2.0.4 || >=2.1.0 <2.1.3 CVE IDs: CVE-2026-87937 Description: This module enables you to turn a Drupal install into the Central Authentication Syst

Fuente: Drupal.org · CVE-2026-87937

Drupal ⚠ posible crítico 09/09/2026 17:14 UTC

amazee.ai Private AI Provider - Critical - SQL injection - SA-CONTRIB-2026-134

Project: amazee.ai Private AI Provider Project machine name: ai_provider_amazeeio Date: 2026-September-09 Security risk: Critical 17 ∕ 25 AC:Complex/A:None/CI:All/II:Some/E:Proof/TD:Default Vulnerability: SQL injection Affected versions: <1.3.7 || >=1.4.0 <1.4.3 CVE IDs: CVE-2026-87936 Description: Update 2026-09-11: Increased risk score to reflect publicly documented methods for developing exploi

Fuente: Drupal.org · CVE-2026-87936

Linux (Debian) 09/09/2026 00:00 UTC

DSA-6491-1 slurm-wlm - security update

Several vulnerabilities were discovered in the Slurm Workload Manager, a cluster resource management and job scheduling system, which may result in privilege escalation, SQL injection in the accounting database, deletion of files outside the container spool directory, bypass of credential verification for shared objects transferred with sbcast, or denial of service. https://security-tracker.debian

Fuente: Debian Security

Linux (Debian) 08/09/2026 00:00 UTC

DSA-6490-1 fort-validator - security update

Qi Wang and Jianjun Chen discovered that FORT validator, a RPKI validation service, performed incomplete validation of RRDP notifications, which could result in denial of service via cache poisoning. For additional details please refer to the upstream advisory at https://github.com/NICMx/FORT-validator/security/advisories/GHSA-qfm3-577x-rh54 https://security-tracker.debian.org/tracker/DSA-6490-1

Fuente: Debian Security

Linux (Debian) 08/09/2026 00:00 UTC

DSA-6489-1 gst-plugins-base1.0 - security update

An buffer overflow was discovered in the OPUS audio decoder of the GStreamer media framework, which may result in denial of service or potentially the execution of arbitrary code if a malformed audio file is processed. https://security-tracker.debian.org/tracker/DSA-6489-1

Fuente: Debian Security

Linux (Debian) 07/09/2026 00:00 UTC

DSA-6488-1 jbig2dec - security update

It was discovered that missing input sanitising in the JBIG2 decoder library could result in denial of service. https://security-tracker.debian.org/tracker/DSA-6488-1

Fuente: Debian Security

Linux (Debian) CVSS 5.9 · medio 07/09/2026 00:00 UTC

DSA-6487-1 strongswan - security update

Multiple vulnerabilities were found in strongSwan, an IKE/IPsec suite. CVE-2026-78123 An undefined memory access vulnerability in the openssl plugin when handling PKCS#7 containers, that can result in a crash. CVE-2026-78124 A memory leak in the openssl plugin during the enumeration of certificates in PKCS#7 containers. CVE-2026-78126 A NULL-pointer dereference vulnerability in the eap-aka plugin

Fuente: Debian Security · CVE-2026-78123

Linux (Debian) 06/09/2026 00:00 UTC

DSA-6486-1 libde265 - security update

Two security issues were discovered in libde265, an implementation of the H.265 video codec which may result in denial of service or potentially the execution of arbitrary code if a malformed media file is processed. https://security-tracker.debian.org/tracker/DSA-6486-1

Fuente: Debian Security

Linux (Debian) 06/09/2026 00:00 UTC

DSA-6485-1 tryton-server - security update

Two security vulnerabilities were discovered in the server of the Tryton application platform, which could lead to arbitrary command execution via malformed email/report templates. https://security-tracker.debian.org/tracker/DSA-6485-1

Fuente: Debian Security

Linux (Debian) 05/09/2026 00:00 UTC

DSA-6484-1 chromium - security update

Security issues were discovered in Chromium which could result in the execution of arbitrary code, denial of service, or information disclosure. https://security-tracker.debian.org/tracker/DSA-6484-1

Fuente: Debian Security

Linux (Debian) 04/09/2026 00:00 UTC

DSA-6483-1 thunderbird - security update

Multiple security issues were discovered in Thunderbird, which could result in the execution of arbitrary code or information disclosure. https://security-tracker.debian.org/tracker/DSA-6483-1

Fuente: Debian Security

Linux (Debian) 03/09/2026 00:00 UTC

DSA-6482-1 chromium - security update

Security issues were discovered in Chromium which could result in the execution of arbitrary code, denial of service, or information disclosure. https://security-tracker.debian.org/tracker/DSA-6482-1

Fuente: Debian Security

Drupal 02/09/2026 16:39 UTC

Webform Submissions Delete - Moderately critical - Access bypass - SA-CONTRIB-2026-133

Project: Webform Submissions Delete Project machine name: webform_submissions_delete Date: 2026-September-02 Security risk: Moderately critical 13 ∕ 25 AC:Basic/A:None/CI:None/II:Some/E:Theoretical/TD:All Vulnerability: Access bypass Affected versions: <1.2.0 CVE IDs: CVE-2026-84921 Description: This module enables you to delete Webform submissions in bulk using a specified date range. The module

Fuente: Drupal.org · CVE-2026-84921

Drupal ⚠ posible crítico 02/09/2026 16:38 UTC

Unpublished Node Permissions - Critical - Access bypass - SA-CONTRIB-2026-132

Project: Unpublished Node Permissions Project machine name: unpublished_node_permissions Date: 2026-September-02 Security risk: Critical 15 ∕ 25 AC:None/A:None/CI:Some/II:None/E:Theoretical/TD:All Vulnerability: Access bypass Affected versions: <1.8.0 CVE IDs: CVE-2026-84920 Description: This module creates permissions per node content type to control access to unpublished content. The module has

Fuente: Drupal.org · CVE-2026-84920

Drupal 02/09/2026 16:37 UTC

PhotoSwipe - Responsive JavaScript Modal Image Gallery - Moderately critical - Cross-site scripting - SA-CONTRIB-2026-131

Project: PhotoSwipe - Responsive JavaScript Modal Image Gallery Project machine name: photoswipe Date: 2026-September-02 Security risk: Moderately critical 14 ∕ 25 AC:Basic/A:User/CI:Some/II:Some/E:Theoretical/TD:All Vulnerability: Cross-site scripting Affected versions: <5.0.9 CVE IDs: CVE-2026-84919 Description: This module enables you to add dynamic caption support to PhotoSwipe image galleries

Fuente: Drupal.org · CVE-2026-84919

Drupal 02/09/2026 16:36 UTC

Monobank payment API - Moderately critical - Access bypass - SA-CONTRIB-2026-130

Project: Monobank payment API Project machine name: monobank Date: 2026-September-02 Security risk: Moderately critical 12 ∕ 25 AC:Complex/A:None/CI:None/II:Some/E:Theoretical/TD:All Vulnerability: Access bypass Affected versions: <1.0.3 CVE IDs: CVE-2026-84918 Description: The Monobank payment API module provides integration with Monobank acquiring payments. The module did not verify the Monobank

Fuente: Drupal.org · CVE-2026-84918

Drupal 02/09/2026 16:35 UTC

Media Library Importer - Moderately critical - Access bypass - SA-CONTRIB-2026-129

Project: Media Library Importer Project machine name: media_library_importer Date: 2026-September-02 Security risk: Moderately critical 11 ∕ 25 AC:Basic/A:User/CI:Some/II:None/E:Theoretical/TD:All Vulnerability: Access bypass Affected versions: <2.1.6 CVE IDs: CVE-2026-81163 Description: A module to import media files into media library. The import folder is a plain textfield with no validation. P

Fuente: Drupal.org · CVE-2026-81163

Drupal 02/09/2026 16:34 UTC

Mailer Plus Log - Moderately critical - Access bypass - SA-CONTRIB-2026-128

Project: Mailer Plus Log Project machine name: symfony_mailer_log Date: 2026-September-02 Security risk: Moderately critical 12 ∕ 25 AC:Basic/A:Admin/CI:Some/II:Some/E:Theoretical/TD:Default Vulnerability: Access bypass Affected versions: <1.2.7 CVE IDs: CVE-2026-16648 Description: This module enables you to log the emails sent by Mailer Plus as content entities, so they can be reviewed at Reports

Fuente: Drupal.org · CVE-2026-16648

Drupal ⚠ posible crítico 02/09/2026 16:33 UTC

Jsonapi Role Access - Critical - Access bypass - SA-CONTRIB-2026-127

Project: Jsonapi Role Access Project machine name: jsonapi_role_access Date: 2026-September-02 Security risk: Critical 16 ∕ 25 AC:Basic/A:None/CI:Some/II:Some/E:Theoretical/TD:All Vulnerability: Access bypass Affected versions: <2.0.2 CVE IDs: CVE-2026-84917 Description: This module enables you to restrict access to JSON:API routes based on specific user roles. The module doesn't sufficiently enfo

Fuente: Drupal.org · CVE-2026-84917

Drupal 02/09/2026 16:32 UTC

Islandora - Moderately critical - Access bypass - SA-CONTRIB-2026-126

Project: Islandora Project machine name: islandora Date: 2026-September-02 Security risk: Moderately critical 12 ∕ 25 AC:Complex/A:None/CI:Some/II:None/E:Theoretical/TD:All Vulnerability: Access bypass Affected versions: <2.19.0 CVE IDs: CVE-2026-84916 Description: This islandora_advanced_search sub module enables AJAX updates for advanced search, facet, and search result blocks. The module doesn'

Fuente: Drupal.org · CVE-2026-84916

Drupal ⚠ posible crítico 02/09/2026 16:31 UTC

Email Verification / SMS Verification / OTP Verification - Critical - Cross Site Scripting - SA-CONTRIB-2026-125

Project: Email Verification / SMS Verification / OTP Verification Project machine name: otp_verification Date: 2026-September-02 Security risk: Critical 16 ∕ 25 AC:Basic/A:None/CI:Some/II:Some/E:Theoretical/TD:All Vulnerability: Cross Site Scripting Affected versions: <2.4.0 CVE IDs: CVE-2026-84924 Description: This module enables you to add an extra layer of verification for user registration. Th

Fuente: Drupal.org · CVE-2026-84924

Drupal ⚠ posible crítico 02/09/2026 16:30 UTC

Email Verification / SMS Verification / OTP Verification - Critical - Access Bypass - SA-CONTRIB-2026-124

Project: Email Verification / SMS Verification / OTP Verification Project machine name: otp_verification Date: 2026-September-02 Security risk: Critical 16 ∕ 25 AC:Basic/A:None/CI:Some/II:Some/E:Theoretical/TD:All Vulnerability: Access Bypass Affected versions: <2.4.0 CVE IDs: CVE-2026-84923 Description: This module enables you to add extra layer of verification for user registration. The module d

Fuente: Drupal.org · CVE-2026-84923

Drupal 02/09/2026 16:29 UTC

Component blocks - Moderately critical - Cross site scripting - SA-CONTRIB-2026-123

Project: Component blocks Project machine name: component_blocks Date: 2026-September-02 Security risk: Moderately critical 14 ∕ 25 AC:Basic/A:User/CI:Some/II:Some/E:Theoretical/TD:All Vulnerability: Cross site scripting Affected versions: <1.2.7 CVE IDs: CVE-2026-84915 Description: This module enables you use UI Patterns with blocks, for use in Layout Builder. The module doesn't sufficiently vali

Fuente: Drupal.org · CVE-2026-84915

Drupal ⚠ posible crítico 02/09/2026 16:29 UTC

Calculate Working Days - Critical - Access bypass - SA-CONTRIB-2026-122

Project: Calculate Working Days Project machine name: calculate_working_days Date: 2026-September-02 Security risk: Critical 15 ∕ 25 AC:None/A:None/CI:None/II:Some/E:Theoretical/TD:All Vulnerability: Access bypass Affected versions: <2.0.3 CVE IDs: CVE-2026-84914 Description: Calculate Working Days allows you to calculate working days between 2 dates. This module doesn't sufficiently restrict acce

Fuente: Drupal.org · CVE-2026-84914

Drupal 02/09/2026 16:28 UTC

AI translate - Moderately critical - Access Bypass - SA-CONTRIB-2026-121

Project: AI translate Project machine name: ai_translate Date: 2026-September-02 Security risk: Moderately critical 13 ∕ 25 AC:Basic/A:User/CI:Some/II:Some/E:Theoretical/TD:Default Vulnerability: Access Bypass Affected versions: <1.3.2 || >=1.4.0 <1.4.1 CVE IDs: CVE-2026-84913 Description: This module enables you to automatically translate entities. The module doesn't sufficiently check access on

Fuente: Drupal.org · CVE-2026-84913

Drupal 02/09/2026 16:27 UTC

AI (Artificial Intelligence) - Moderately critical - Access Bypass - SA-CONTRIB-2026-120

Project: AI (Artificial Intelligence) Project machine name: ai Date: 2026-September-02 Security risk: Moderately critical 13 ∕ 25 AC:Basic/A:User/CI:Some/II:Some/E:Theoretical/TD:Default Vulnerability: Access Bypass Affected versions: <1.3.13 || >=1.4.0 <1.4.8 CVE IDs: CVE-2026-84912 Description: This submodule AI Translate enables you to automatically translate entities. The module doesn't suffic

Fuente: Drupal.org · CVE-2026-84912

Drupal 02/09/2026 16:26 UTC

AI (Artificial Intelligence) - Moderately critical - Cross site scripting - SA-CONTRIB-2026-119

Project: AI (Artificial Intelligence) Project machine name: ai Date: 2026-September-02 Security risk: Moderately critical 10 ∕ 25 AC:Complex/A:Admin/CI:Some/II:Some/E:Theoretical/TD:Uncommon Vulnerability: Cross site scripting Affected versions: <1.3.13 || >=1.4.0 <1.4.8 CVE IDs: CVE-2026-84911 Description: This AI Chatbot module enables you to have a Chatbot using assistants to help you with your

Fuente: Drupal.org · CVE-2026-84911

Drupal 02/09/2026 16:25 UTC

Advanced Search - Moderately critical - Access bypass - SA-CONTRIB-2026-118

Project: Advanced Search Project machine name: advanced_search Date: 2026-September-02 Security risk: Moderately critical 12 ∕ 25 AC:Complex/A:None/CI:Some/II:None/E:Theoretical/TD:All Vulnerability: Access bypass Affected versions: <2.4.5 CVE IDs: CVE-2026-84910 Description: This module enables AJAX updates for advanced search, facet, and search result blocks. The module doesn’t sufficiently chec

Fuente: Drupal.org · CVE-2026-84910

Linux (Debian) 02/09/2026 00:00 UTC

DSA-6481-1 firefox-esr - security update

Multiple security issues have been found in the Mozilla Firefox web browser, which could potentially result in the execution of arbitrary code, sandbox escape or privilege escalation. https://security-tracker.debian.org/tracker/DSA-6481-1

Fuente: Debian Security

Linux (Debian) 01/09/2026 00:00 UTC

DSA-6480-1 keystone - security update

Multiple vulnerabilities were discovered in Keystone, the OpenStack identity service, which may result in authorisation bypass or information disclosure. https://security-tracker.debian.org/tracker/DSA-6480-1

Fuente: Debian Security

Linux (Debian) 30/08/2026 00:00 UTC

DSA-6479-1 roundcube - security update

Multiple vulnerabilities were discovered in roundcube, a skinnable AJAX based webmail solution for IMAP servers, which could result in cross-site scripting, SSRF bypass, information disclosure, privilege escalation, denial of service or remote code execution. https://security-tracker.debian.org/tracker/DSA-6479-1

Fuente: Debian Security

Linux (Debian) 30/08/2026 00:00 UTC

DSA-6478-1 starlette - security update

Several vulnerabilities were discovered in starlette, a lightweight ASGI framework/toolkit, which could result in bypass of authorization checks or denial of service. https://security-tracker.debian.org/tracker/DSA-6478-1

Fuente: Debian Security

Linux (Debian) 29/08/2026 00:00 UTC

DSA-6477-1 linux - security update

Several vulnerabilities have been discovered in the Linux kernel that may lead to a privilege escalation, denial of service or information leaks. https://security-tracker.debian.org/tracker/DSA-6477-1

Fuente: Debian Security

Linux (Debian) 27/08/2026 00:00 UTC

DSA-6476-1 chromium - security update

Security issues were discovered in Chromium which could result in the execution of arbitrary code, denial of service, or information disclosure. https://security-tracker.debian.org/tracker/DSA-6476-1

Fuente: Debian Security

Linux (Debian) 27/08/2026 00:00 UTC

DSA-6475-1 suricata-update - security update

Guillem Lefait discovered a path traversal attack in suricata-update, a tool for updating Suricata rules, which allowed malformed rules to overwrite files on the system. https://security-tracker.debian.org/tracker/DSA-6475-1

Fuente: Debian Security

Linux (Debian) 27/08/2026 00:00 UTC

DSA-6474-1 cockpit - security update

Two security vulnerabilities were discovered in Cockpit, a web console for Linux servers, which could result in the execution of arbitrary code or denial of service. https://security-tracker.debian.org/tracker/DSA-6474-1

Fuente: Debian Security

Linux (Debian) 27/08/2026 00:00 UTC

DSA-6473-1 libdbi-perl - security update

Several vulnerabilities were discovered in libdbi-perl, a Perl framework that provides a common interface to access various backend databases in a uniform manner, which could result in denial of service, path traversal, bypass of file-backed filters or the execution of arbitrary code. https://security-tracker.debian.org/tracker/DSA-6473-1

Fuente: Debian Security

Linux (Debian) 27/08/2026 00:00 UTC

DSA-6472-1 bubblewrap - security update

A symlink traversal vulnerability was discovered in bubblewrap, a low-level unprivileged sandboxing tool used by Flatpak and other projects, which could result in sandbox escape by malicious/compromised Flatpak apps. https://security-tracker.debian.org/tracker/DSA-6472-1

Fuente: Debian Security

Linux (Debian) 27/08/2026 00:00 UTC

DSA-6471-1 wireshark - security update

Multiple vulnerabilities have been discocvered in Wireshark, a network protocol analyzer which could result in denial of service or the execution of arbitrary code. https://security-tracker.debian.org/tracker/DSA-6471-1

Fuente: Debian Security

Linux (Debian) 27/08/2026 00:00 UTC

DSA-6470-1 gimp - security update

Several vulnerabilities were discovered in GIMP, the GNU Image Manipulation Program, which could result in denial of service or potentially the execution of arbitrary code if malformed PSP, TIFF, DDS, PSD, SGI, FLI, FITS or ICNS files are opened. https://security-tracker.debian.org/tracker/DSA-6470-1

Fuente: Debian Security

Linux (Debian) 27/08/2026 00:00 UTC

DSA-6469-1 xrdp - security update

Multiple vulnerabilities were discovered in xrdp, a Remote Desktop Protocol (RDP) server, which may result in denial of service, information disclosure, privilege escalation or the execution of arbitrary code. Several of these issues are exploitable by an unauthenticated remote attacker. This update also changes two defaults, as part of the fixes: * Alternate shells supplied by the client are now

Fuente: Debian Security

Drupal CVSS 6.1 · medio 26/08/2026 17:45 UTC

Slick Carousel - Moderately critical - Cross Site Scripting - SA-CONTRIB-2026-117

Project: Slick Carousel Project machine name: slick Date: 2026-August-26 Security risk: Moderately critical 12 ∕ 25 AC:Basic/A:Admin/CI:Some/II:Some/E:Theoretical/TD:Default Vulnerability: Cross Site Scripting Affected versions: <2.1.0 CVE IDs: CVE-2026-81160 Description: Slick UI, a sub-module of Slick, enables you to add Slick option sets that may contain HTML for carousel buttons. Previous rele

Fuente: Drupal.org · CVE-2026-81160

Drupal CVSS 6.1 · medio 26/08/2026 17:44 UTC

Monster Menus - Moderately critical - Cross-site Scripting - SA-CONTRIB-2026-116

Project: Monster Menus Project machine name: monster_menus Date: 2026-August-26 Security risk: Moderately critical 13 ∕ 25 AC:Basic/A:User/CI:Some/II:Some/E:Theoretical/TD:Default Vulnerability: Cross-site Scripting Affected versions: <9.5.3 CVE IDs: CVE-2026-81201 Description: This module enables you to create one or more multisites with highly granular page permissions. The module doesn't suffic

Fuente: Drupal.org · CVE-2026-81201

Drupal CVSS 5.3 · medio 26/08/2026 17:43 UTC

LDAP / Active Directory Integration - Moderately critical - Information Disclosure - SA-CONTRIB-2026-115

Project: LDAP / Active Directory Integration Project machine name: ldap_auth Date: 2026-August-26 Security risk: Moderately critical 14 ∕ 25 AC:Basic/A:None/CI:Some/II:None/E:Proof/TD:All Vulnerability: Information Disclosure Affected versions: <2.2.1 CVE IDs: CVE-2026-81205 Description: This module enables users to authenticate using LDAP or Active Directory credentials. The module does not suffi

Fuente: Drupal.org · CVE-2026-81205

Drupal CVSS 5.4 · medio 26/08/2026 17:42 UTC

Entity PDF - Moderately critical - Access bypass - SA-CONTRIB-2026-114

Project: Entity PDF Project machine name: entity_pdf Date: 2026-August-26 Security risk: Moderately critical 13 ∕ 25 AC:None/A:User/CI:Some/II:None/E:Theoretical/TD:All Vulnerability: Access bypass Affected versions: <2.1.5 CVE IDs: CVE-2026-81164 Description: The Entity PDF module can create a PDF from any entity based on any View mode. This module does not check entity view access when fetching

Fuente: Drupal.org · CVE-2026-81164

Drupal CVSS 5.3 · medio 26/08/2026 17:41 UTC

Entity API - Moderately critical - Information disclosure - SA-CONTRIB-2026-113

Project: Entity API Project machine name: entity Date: 2026-August-26 Security risk: Moderately critical 12 ∕ 25 AC:Basic/A:None/CI:Some/II:None/E:Theoretical/TD:Default Vulnerability: Information disclosure Affected versions: <1.8.0 CVE IDs: CVE-2026-81158 Description: The Entity API module extends the Drupal core entity API to provide a unified way to deal with entities and their properties. The

Fuente: Drupal.org · CVE-2026-81158

Drupal CVSS 5.3 · medio 26/08/2026 17:40 UTC

DXPR Builder: The AI Visual Page Builder for Drupal - Moderately critical - Information Disclosure - SA-CONTRIB-2026-112

Project: DXPR Builder: The Best Editing (AI) Experience for Drupal Project machine name: dxpr_builder Date: 2026-August-26 Security risk: Moderately critical 14 ∕ 25 AC:None/A:None/CI:Some/II:None/E:Theoretical/TD:Default Vulnerability: Information Disclosure Affected versions: <2.8.1 CVE IDs: CVE-2026-81162 Description: The DXPR Builder module provides a visual / AI page builder for Drupal. The m

Fuente: Drupal.org · CVE-2026-81162

Drupal CVSS 4.1 · medio 26/08/2026 17:39 UTC

Disable Login Page - Moderately critical - Access bypass - SA-CONTRIB-2026-111

Project: Disable Login Page Project machine name: disable_login Date: 2026-August-26 Security risk: Moderately critical 13 ∕ 25 AC:None/A:None/CI:None/II:None/E:Proof/TD:All Vulnerability: Access bypass Affected versions: <1.1.4 CVE IDs: CVE-2026-16647 Description: This module enables you to disable access to the /user/login form unless a secret key is provided. The module does not invalidate the

Fuente: Drupal.org · CVE-2026-16647

Drupal CVSS 5.7 · medio 26/08/2026 17:38 UTC

Disable Login Page - Moderately critical - Access bypass - SA-CONTRIB-2026-110

Project: Disable Login Page Project machine name: disable_login Date: 2026-August-26 Security risk: Moderately critical 13 ∕ 25 AC:Basic/A:None/CI:Some/II:None/E:Theoretical/TD:All Vulnerability: Access bypass Affected versions: <1.1.4 CVE IDs: CVE-2026-18260 Description: This module enables you to disable access to the /user/login form unless a secret key is provided. The module does not sufficie

Fuente: Drupal.org · CVE-2026-18260

Drupal CVSS 5.3 · medio 26/08/2026 17:38 UTC

Digital Signage Framework - Moderately critical - Access bypass - SA-CONTRIB-2026-109

Project: Digital Signage Framework Project machine name: digital_signage_framework Date: 2026-August-26 Security risk: Moderately critical 13 ∕ 25 AC:Basic/A:None/CI:Some/II:None/E:Theoretical/TD:All Vulnerability: Access bypass Affected versions: <2.6.1 CVE IDs: CVE-2026-81166 Description: The Digital Signage Framework module provides a route that signage devices can call to refresh dynamic block

Fuente: Drupal.org · CVE-2026-81166

Drupal CVSS 5.3 · medio 26/08/2026 17:37 UTC

Data field - Moderately critical - Information disclosure - SA-CONTRIB-2026-108

Project: Data field Project machine name: datafield Date: 2026-August-26 Security risk: Moderately critical 13 ∕ 25 AC:Basic/A:None/CI:Some/II:None/E:Theoretical/TD:All Vulnerability: Information disclosure Affected versions: <2.0.13 CVE IDs: CVE-2026-81269 Description: This module enables you to store structured data in configurable fields and expose Data Field values through JSON endpoints. The

Fuente: Drupal.org · CVE-2026-81269

Drupal CVSS 3.3 26/08/2026 17:36 UTC

Content Moderation Notifications - Moderately critical - Access bypass - SA-CONTRIB-2026-107

Project: Content Moderation Notifications Project machine name: content_moderation_notifications Date: 2026-August-26 Security risk: Moderately critical 12 ∕ 25 AC:Basic/A:Admin/CI:Some/II:Some/E:Theoretical/TD:Default Vulnerability: Access bypass Affected versions: <3.9.0 CVE IDs: CVE-2026-81161 Description: The module provides a permission that allows users to configure email templates containin

Fuente: Drupal.org · CVE-2026-81161

Drupal CVSS 3.7 26/08/2026 17:35 UTC

Commerce CyberSource - Moderately critical - Insufficient input validation - SA-CONTRIB-2026-106

Project: Commerce CyberSource Project machine name: commerce_cybersource Date: 2026-August-26 Security risk: Moderately critical 11 ∕ 25 AC:Complex/A:None/CI:None/II:Some/E:Theoretical/TD:Default Vulnerability: Insufficient input validation Affected versions: <1.10.0 CVE IDs: CVE-2026-81159 Description: This module integrates Drupal Commerce with the CyberSource payment gateway. The module does no

Fuente: Drupal.org · CVE-2026-81159

Drupal CVSS 3.7 26/08/2026 17:34 UTC

CAPTCHA Protected Page - Moderately critical - Cookie Forgery - SA-CONTRIB-2026-105

Project: CAPTCHA Protected Page Project machine name: captcha_protected_page Date: 2026-August-26 Security risk: Moderately critical 12 ∕ 25 AC:Complex/A:None/CI:Some/II:None/E:Theoretical/TD:All Vulnerability: Cookie Forgery Affected versions: <1.0.2 CVE IDs: CVE-2026-81168 Description: This module enables site administrators to require CAPTCHA confirmation on specific pages. The module does not

Fuente: Drupal.org · CVE-2026-81168

Drupal CVSS 5.3 · medio 26/08/2026 17:33 UTC

Blazy - Less critical - Access bypass - SA-CONTRIB-2026-104

Project: Blazy Project machine name: blazy Date: 2026-August-26 Security risk: Less critical 9 ∕ 25 AC:Basic/A:User/CI:Some/II:None/E:Theoretical/TD:Uncommon Vulnerability: Access bypass Affected versions: <3.0.18 CVE IDs: CVE-2026-81165 Description: This module enables users to display a field of a target entity through a Blazy Filter plugin shortcode. The module does not consistently check entit

Fuente: Drupal.org · CVE-2026-81165

Linux (Debian) 26/08/2026 00:00 UTC

DSA-6468-1 emacs - security update

Two security issues were discovered in GNU Emacs, which could result in the execution of arbitrary code when opening a malformed file and denial of service when processing malformed PBM/PPM/PGM images. https://security-tracker.debian.org/tracker/DSA-6468-1

Fuente: Debian Security

Magento / e-commerce CVSS 9.1 · crítico 11/08/2026 00:00 UTC

Adobe patches critical Magento account takeover (APSB26-92)

Adobe has released isolated security patches for APSB26-92 for Adobe Commerce and Magento Open Source.The update fixes seven vulnerabilities. Five are rated Critical, including CVE-2026-71362, an ...

Fuente: Sansec · CVE-2026-71362

Magento / e-commerce ⚠ posible crítico 02/07/2026 00:00 UTC

Amasty patches dozens of Magento extensions, 2 critical

Update August 25, 2026: This advisory now lists additional high-severity extensions.Update August 13, 2026: This advisory now lists medium and low-severity extensions.Update August 10, 2026: This...

Fuente: Sansec

Magento / e-commerce ⚠ posible crítico 17/06/2026 00:00 UTC

Unauthenticated remote code execution in JTL Shop

JTL responded fast and has released fixes for every supported branch: versions 5.5.4, 5.6.2 and 5.7.2, plus a back-patch covering 5.0.0 through 5.7.0. Every store owner running JTL Shop 5.2.0 or la...

Fuente: Sansec

Magento / e-commerce 13/06/2026 00:00 UTC

OptinMonster supply chain attack hits 1.2 million sites

Sansec discovered an active supply-chain attack hitting over 1.2 million sites that use the popular OptinMonster, TrustPulse and PushEngage Wordpress plugins, all operated by Wordpress giant Awesom...

Fuente: Sansec

Magento / e-commerce 04/06/2026 00:00 UTC

Magecart skimmer turns Stripe into a malware command server

The skimmer never loads from a domain the attacker controls. The loader, the payload, and the stolen cards all flow through two domains every store already trusts: Google Tag Manager and Stripe.Bo...

Fuente: Sansec

Magento / e-commerce 01/06/2026 00:00 UTC

Sansec adds support for Sylius 1 & 2

Sansec is proud to add Sylius to our list of supported platforms. Sansec eComscan now integrates with Sylius 1 and Sylius 2 and will run deep searches to hunt for malware & vulnerabilities.Whi...

Fuente: Sansec

Magento / e-commerce ⚠ posible crítico 26/05/2026 00:00 UTC

Critical vulnerability in Mirasvit Cache Warmer for Magento

Sansec discovered an unauthenticated PHP object injection vulnerability in Mirasvit Cache Warmer, a full-page cache extension for Magento and Adobe Commerce. Any storefront request carrying a craft...

Fuente: Sansec

Magento / e-commerce 10/04/2026 00:00 UTC

ClickFix malware hits DoD cybersecurity vendor homepage

The vendor is currently running a ClickFix clipboard hijacker on its own homepage. The vendor sells network exposure management and attack-path analysis to Fortune 500 enterprises, the US Departmen...

Fuente: Sansec

Magento / e-commerce 07/04/2026 00:00 UTC

SVG Onload Tag Hides Magecart Skimmer on 99 Stores

In the early hours of April 7th, nearly 100 Magento stores got mass-infected with a "double-tap" skimmer: a credit card stealer hidden inside an invisible SVG element. Sansec found stolen...

Fuente: Sansec

Magento / e-commerce 30/03/2026 00:00 UTC

Mass PolyShell attack wave hits 471 stores in one hour

Sansec is tracking a mass exploitation wave of the PolyShell vulnerability that hit hundreds of online stores within a single hour today. The attacks are ongoing: new victims appear every minute.N...

Fuente: Sansec

Magento / e-commerce ⚠ posible crítico 17/03/2026 00:00 UTC

PolyShell: unrestricted file upload in Magento and Adobe Commerce

Sansec discovered and named the PolyShell vulnerability: a critical flaw in Magento's REST API that lets unauthenticated attackers upload executable files to any store. The attack uses a polyglot (...

Fuente: Sansec

Magento / e-commerce 20/02/2026 00:00 UTC

Digital skimmer hits global supermarket chain

The affected company, with about €100 billion in annual revenue and over 10,000 stores across 25 countries, runs some of its ecommerce operations on the PrestaShop platform. As of publication, the ...

Fuente: Sansec

Magento / e-commerce 18/02/2026 00:00 UTC

Building a faster YARA engine in pure Go

YARA is the industry standard for pattern matching in malware detection. Maintained by VirusTotal, it powers threat detection at nearly every security vendor. At Sansec, we rely on YARA for eComsca...

Fuente: Sansec

Magento / e-commerce ⚠ posible crítico 22/01/2026 00:00 UTC

Claude finds 353 zero-days on Packagist

Open source ecosystems have a long tail security problem. Python, Ruby, Javascript, PHP: these ecosystems have millions of packages. The top 100 packages get scrutinized. The next 5,000, not so muc...

Fuente: Sansec

Magento / e-commerce 16/01/2026 00:00 UTC

The billion-dollar security.txt problem

Yesterday, Sansec discovered an active keylogger at an external site of one of America's largest banks. The malware was harvesting private information from over 200,000 potential victims. We detect...

Fuente: Sansec

Magento / e-commerce 15/01/2026 00:00 UTC

Keylogger targets 200,000+ employees at major US bank

Update Jan 15th: the malware appears to have been removed. It was live for about 18 hoursSansec detected a keylogger on the employee store of one of America's largest banks. The site serves over 2...

Fuente: Sansec

Magento / e-commerce 12/01/2026 00:00 UTC

ConnectPOS leaked Github secrets for years

Sansec researchers discovered that ConnectPOS, a popular Point of Sale solution, had been exposing a GitHub Personal Access Token (PAT) in their public installation instructions for over four years...

Fuente: Sansec

Magento / e-commerce ⚠ posible crítico 15/12/2025 00:00 UTC

Critical backdoor found in MGT Varnish extension

NameMgt_VarnishVulnerable1.0.10 and earlierFixed in1.1.0Sansec researchers discovered a critical vulnerability in the popular Varnish module for Magento. This module, develope...

Fuente: Sansec

Magento / e-commerce CVSS 9.1 · crítico 22/10/2025 00:00 UTC

SessionReaper attacks have started, 3 in 5 stores still vulnerable

Six weeks after Adobe's emergency patch for SessionReaper (CVE-2025-54236), the vulnerability has entered active exploitation. Sansec Shield detected and blocked the first real-world attacks today,...

Fuente: Sansec · CVE-2025-54236

Magento / e-commerce CVSS 8.4 · alto 12/06/2025 00:00 UTC

Adobe patches critical Magento admin takeover via menu injection

Adobe has just released several security fixes for its Commerce (Magento) platform and one of them is critical (CVE-2025-47110). Adobe urges merchants to patch within 72 hours (highest priority).S...

Fuente: Sansec · CVE-2025-47110

Magento / e-commerce 01/05/2025 00:00 UTC

Backdoor found in popular ecommerce components

Hundreds of stores, including a $40 billion multinational, are running backdoored versions of popular ecommerce software. We found that the backdoor is actively used since at least April 20th. Sans...

Fuente: Sansec

Magento / e-commerce 03/04/2025 00:00 UTC

Found defunct.dat on your site? You've got a problem.

The Sansec Shield WAF detected mass scans for "defunct.dat" and "qfile" files this week. As it turns out, these files contain connection keys that can be used to launch a GSocke...

Fuente: Sansec

Magento / e-commerce 17/03/2025 00:00 UTC

You have 2 weeks left to set up CSP for your store

The new PCI-DSS regulations that will come into effect after March 31st, 2025, require merchants to monitor scripts on their payment pages to prevent digital skimming attacks*. The use of Conte...

Fuente: Sansec

Magento / e-commerce 06/03/2025 00:00 UTC

Merchants left guessing at last-minute PCI-DSS u-turn

It's insanity that we still don't have clarity(Clean_Anteater992)They have to be kidding me (sawer82)It's clusterf after clusterf (andrew_barratt)The Payment Card Industry Security Stan...

Fuente: Sansec

Magento / e-commerce ⚠ posible crítico 12/02/2025 00:00 UTC

Magento Security Release APSB25-08 [Impact Analysis]

APSB25-08 released on Feb 11th, 2025Critical Adobe Commerce/Magento security patches have just been released (CVSS 9.4/10)New versions: 2.4.4-p12, 2.4.5-p11, 2.4.6-p9, 2.4.7-p4, additionally 2.4....

Fuente: Sansec

Magento / e-commerce 03/02/2025 00:00 UTC

Sorry, client-side security does not work

Merchants spend millions of dollars on client-side security solutions to prevent digital skimming attacks. Companies are rushing to implement these tools, often driven by PCI requirements. But here...

Fuente: Sansec

Magento / e-commerce 31/12/2024 00:00 UTC

Google services abused in skimming campaigns

Google TranslateAttackers are using Google Translate’s page functionality to execute malicious JavaScript files, as demonstrated below:<script src="https://translate.google.co.in/translat...

Fuente: Sansec

Magento / e-commerce ⚠ posible crítico 16/09/2024 00:00 UTC

CosmicSting attack & defense overview

ImplicationsCosmicSting targets a critical bug in the Adobe Commerce and Magento platforms. Bad actors use it to read any of your files, such as passwords and other secrets. The typical attack str...

Fuente: Sansec

Magento / e-commerce CVSS 9.8 · crítico 27/08/2024 00:00 UTC

Persistent backdoors injected on Adobe Commerce via new CosmicSting attack

CosmicSting (CVE-2024-34102) allows arbitrary file reading on unpatched systems. When combined with CNEXT (CVE-2024-2961), threat actors can escalate to remote code execution, taking over the entir...

Fuente: Sansec · CVE-2024-34102

Magento / e-commerce 12/07/2024 00:00 UTC

CosmicSting attacks have started hitting major stores

API AbuseAs CosmicSting enables attackers to read any file, attackers can steal Magento's secret encryption key. This encryption key can generate JSON Web Tokens with full administrative API acces...

Fuente: Sansec

Magento / e-commerce 25/06/2024 00:00 UTC

Polyfill supply chain attack hits 100K+ sites

Update June 28th: We are flagging more domains that have been used by the same actor to spread malware since at least June 2023: bootcdn.net, bootcss.com, staticfile.net, staticfile.org, unionad...

Fuente: Sansec

Magento / e-commerce 18/06/2024 00:00 UTC

CosmicSting attack threatens 75% of Adobe Commerce stores

Update June 27th: Adobe has now provided an official, isolated fix that can be applied to installations without requiring upgrade.Update June 27th: our partner Hypernode as actually observed the ...

Fuente: Sansec

Magento / e-commerce 04/04/2024 00:00 UTC

Persistent Magento backdoor hidden in XML

The following XML code was found in the layout_update database table and is responsible for periodic reinfections of your system.Attackers combine the Magento layout parser with the beberlei/asse...

Fuente: Sansec

Magento / e-commerce 08/03/2024 00:00 UTC

Sansec joins forces with Google's VirusTotal

In January we announced our partnership with Europol and today, we are proud to be recognized by Google as experts in eCommerce security.Sansec and Google have agreed on a data exchange and we tru...

Fuente: Sansec

Magento / e-commerce 09/01/2024 00:00 UTC

Sansec and Europol counter online skimming

In a strategic alliance, Europol, the European Union Agency for Cybersecurity (ENISA), law enforcement from 17 nations, and key private sector entities such as Sansec, have aligned to counteract th...

Fuente: Sansec

Magento / e-commerce 18/12/2023 00:00 UTC

Magento wish list exploit bypasses WAF protection

In recent weeks, Sansec observed a spike in hacked Magento 2 stores. Our investigations led to a (likely) single attacker, who used a combination of clever techniques to bypass WAFs and competing t...

Fuente: Sansec

Magento / e-commerce 10/11/2023 00:00 UTC

Is your store’s newsletter being used for phishing?

Cybercriminals in eCommerce are diversifying their targets, now aiming at entire customer databases instead of just stealing credit cards. A recent incident revealed this trend: a hacked Magento ad...

Fuente: Sansec

Magento / e-commerce 22/08/2023 00:00 UTC

Malware Persistence via Telegram and GitHub

Attackers are devising ingenious methods to prolong their skimming activities, aiming for sustained persistence.The usual tactics, techniques, and procedures (TTP) include the creation of disposab...

Fuente: Sansec

Magento / e-commerce 09/05/2023 00:00 UTC

Postponed Exfiltration Evades Detection

The domain gtag-analytics.com has recently emerged as a threat, employing various cunning techniques to evade detection and targeting unsuspecting users, but what makes it especially deceptive is i...

Fuente: Sansec

Magento / e-commerce 07/02/2023 00:00 UTC

Sansec analysis: 12% of online stores leak private backups

It is a common practice to make ad-hoc backups during store platform maintenance. The problem, however, is that these backups often end up in a public folder. Perhaps the administrator intended to ...

Fuente: Sansec

Magento / e-commerce CVSS 9.8 · crítico 17/01/2023 00:00 UTC

Vendors defeat Magento security patch (+ simple check)

BackgroundAdobe’s fix to CVE-2022-24086 was to remove “smart” mail templates. Many vendors were caught off guard and had to revert to the original functionality. In doing so, they unknowingly expo...

Fuente: Sansec · CVE-2022-24086

Magento / e-commerce 21/12/2022 00:00 UTC

Fake Klaviyo accounts added to Magento

Magento 2 template hacks have been raging since a month or two, and Sansec is closely tracking any new attack payloads. So far, we observed about 20 different payloads which all added a basic PHP b...

Fuente: Sansec

Magento / e-commerce 15/11/2022 00:00 UTC

Adobe Commerce merchants to be hit with TrojanOrders this season

After a quiet summer, the number of attacks targeting the mail template vulnerability in Magento 2 and Adobe Commerce is rising fast. Merchants and developers should be on the lookout for TrojanOrd...

Fuente: Sansec

Magento / e-commerce 07/11/2022 00:00 UTC

Extortion of Magento merchants

Related: many stores are occassionally contacted by "security researchers" who claim to have found a vulnerability and want a "bounty" to disclose it. In 99% of these cases, the...

Fuente: Sansec

Magento / e-commerce 22/09/2022 00:00 UTC

Surge in Magento 2 template attacks

Currently, Sansec eComscan is the only malware scanner that detects the injected remote access trojan (see Virustotal).223sam.jpg attackAll of the observed attacks have been interactive, possibly...

Fuente: Sansec

Magento / e-commerce 13/09/2022 00:00 UTC

Magento vendor Fishpig hacked, backdoors added

Update 2022-09-13 FishPig has confirmed the incident and published a status page. It recommends customers to upgrade and/or reinstall all FishPig modules.Sansec discovered malware in the Fishpig ...

Fuente: Sansec

Magento / e-commerce CVSS 9.8 · crítico 14/02/2022 00:00 UTC

Magento 2 critical vulnerability (CVE-2022-24086 & CVE-2022-24087)

Update Feb 21st, 2022: Sansec has observed the first actual attacks in the wild. Patch now! Unfortunately, this validates our previous prediction that abuse would start within days. Attacks are com...

Fuente: Sansec · CVE-2022-24086

Magento / e-commerce 08/02/2022 00:00 UTC

NaturalFreshMall: a Magento Mass Hack

More than 350 ecommerce stores infected with malware in a single day.Today our global crawler discovered 374 ecommerce stores infected with the same strain of malware. 370 of these stores load the ...

Fuente: Sansec

Magento / e-commerce ⚠ posible crítico 13/12/2021 00:00 UTC

Magento and the Log4j vulnerability

Updated Dec 20th. This article describes how Magento is affected by the critical log4j vulnerability, and what you can (and should) do to prevent a hack.A critical vulnerability in the popular Log...

Fuente: Sansec

Magento / e-commerce 01/12/2021 00:00 UTC

NginRAT parasite targets Nginx

Last week we exposed the CronRAT eCommerce malware, which is controlled by a Chinese server. Out of curiosity, we wrote a "custom" RAT client and waited for commands from the far east. Ev...

Fuente: Sansec

Magento / e-commerce 24/11/2021 00:00 UTC

CronRAT malware hides behind February 31st

At this time of year we typically see a surge in eCommerce attacks and new malware. Last week we analyzed a clever malware attacking online stores, and today we expose another, much more sophistica...

Fuente: Sansec

Magento / e-commerce 18/11/2021 00:00 UTC

New linux_avp malware hits eCommerce sites

A merchant recently reached out to us, after hiring two forensic companies but still having malware on his store. As we appreciate a challenge, our team got started and quickly discovered an intric...

Fuente: Sansec

Magento / e-commerce 18/02/2021 00:00 UTC

Google Apps Script used to steal data

The Google business application platform Apps Script is used to funnel stolen personal data, Sansec learned. Attackers use the reputation of the trusted Google domain script.google.com to evade mal...

Fuente: Sansec

Magento / e-commerce 24/12/2020 00:00 UTC

Fake payment page before checkout on Shopify and BigCommerce

Once the data is intercepted and exfiltrated, the attackers display an error message and the customer is redirected to the real payment page. Customers probably just enter their details again and i...

Fuente: Sansec

Magento / e-commerce 18/12/2020 00:00 UTC

eCommerce trojan accidentally leaks victims

Sansec discovered a clever remote access trojan (RAT) that has been hiding in the alleys of hacked eCommerce servers. Despite the advanced setup, perpetrators mistakenly left a list of victim store...

Fuente: Sansec

Magento / e-commerce 02/12/2020 00:00 UTC

Hackers exploit security flaw right before Black Friday

The affected stores were all running the older Magento 2.2, which is unsupported since December 2019.In addition to the injected flaw, attackers used a hybrid skimming architecture, with front and...

Fuente: Sansec

Magento / e-commerce 26/11/2020 00:00 UTC

Payment skimmer hides in social media buttons

Researchers at Sansec have uncovered a novel technique to inject payment skimmers onto checkout pages. This new malware has two parts: a concealed payload and a decoder, of which the latter reads t...

Fuente: Sansec

Magento / e-commerce 14/09/2020 00:00 UTC

Cardbleed: 3% of Magento install base hacked

Update Sept 18: Cardbleed has infected 2806 Magento1 stores so far (3% of total install base)Over the weekend, almost two thousand Magento 1 stores across the world have been hacked in the larges...

Fuente: Sansec

Magento / e-commerce 06/07/2020 00:00 UTC

North Korean hackers are skimming US and European shoppers

Previously, North Korean hacking activity was mostly restricted to banks and South Korean crypto markets^cryptohack, covert cyber operations that earned hackers $2 billion, according to a 2019 Unit...

Fuente: Sansec

Magento / e-commerce 22/06/2020 00:00 UTC

Digital skimmer runs entirely on Google, defeats CSP

A newly discovered skimming campaign runs entirely on Google servers, Sansec research shows. The novel malware sends stolen credit cards directly to Google Analytics, evading security controls like...

Fuente: Sansec

Magento / e-commerce 15/06/2020 00:00 UTC

Lockdown: Stores closed, online stores hacked

While an international retail chain closed its physical stores, attackers hacked its online presence, Sansec research shows. Following common Magecart malpractice, payment skimmers were injected an...

Fuente: Sansec

Magento / e-commerce 08/05/2020 00:00 UTC

Magento 1 still PCI compliant after 1 July 2020?

Magento 1 will no longer receive official updates & security fixes per July 1st, 2020 (the end-of-life, or EOL date). Merchants are urged to upgrade to Magento 2, but for many stores this deadl...

Fuente: Sansec

Magento / e-commerce 20/02/2020 00:00 UTC

Maxcluster and Sansec partner to secure German stores

Utrecht, February 20; Sansec is proud to announce that it hasformed a long-term strategic partnership with maxcluster to bring itsindustry-leading anti-malware technology to the German e-commerce...

Fuente: Sansec

Magento / e-commerce 25/01/2020 00:00 UTC

Indonesian Magecart hackers arrested

The Indonesian police announced on Friday that they have arrested three alleged Magecart hackers on December 20th. The suspects are from Jakarta and Yogyakarta and are 23, 26 and 35 years old. Afte...

Fuente: Sansec

Magento / e-commerce 02/12/2019 00:00 UTC

Payment skimmers have impersonated Sansec

Payment skimmers are hiding their malpractice by impersonating our Sansec anti-skimming service. They have registered malicious domains sansec.us and sanguinelab.net, even using a fake address in A...

Fuente: Sansec

Magento / e-commerce 25/10/2019 00:00 UTC

American Cancer Society hit by payment skimmer

Digital skimming groups (aka Magecart) hit another low, as they successfully targeted the American Cancer Society last night. Our skimmer detectors found a piece of malicious code embedded on the C...

Fuente: Sansec

Magento / e-commerce 07/10/2019 00:00 UTC

Magento security extentions vendor got hacked

The store of a US Magento extension vendor was found compromised. Attackers had write access to the server selling extensions. We are awaiting a statement on the integrity of downloaded software.O...

Fuente: Sansec

Magento / e-commerce 17/08/2019 00:00 UTC

FBI recommends eCommerce malware protection

The FBI warns small and medium-sized businesses and government agencies against the threat of e-skimming. E-skimming occurs when cyber criminals inject malicious code onto a website.Read the origi...

Fuente: Sansec

Magento / e-commerce 12/08/2019 00:00 UTC

Sansec at Europol training: 50,000+ stores hacked

Cementing itself as a global force in the protection against eCommerce fraud, Sansec has been invited to speak at the fifth edition of Europol’s Training Course on Payment Card Fraud Forensic Inves...

Fuente: Sansec

Magento / e-commerce 01/08/2019 00:00 UTC

PCI-SSC/RHISAC quote Sansec: 20% stores reinfected

The PCI Security Standards Council and the Retail & Hospitality ISAC alert merchants to the threat of digital skimming. In its report, it quotes Sansec research, which has found that about 20% ...

Fuente: Sansec

Magento / e-commerce ⚠ posible crítico 10/05/2019 00:00 UTC

Critical Magento 2 flaw exploited within 16 hours

The number of hacked Magento 2 stores spiked in the last four weeks, after a critical security flaw was discovered in March and criminals stole admin passwords within 16 hours. Merchants are advise...

Fuente: Sansec

Magento / e-commerce 29/04/2019 00:00 UTC

Sports brand Puma infected with advanced malware

After the NBA Hawks got skimmed last week, this time Puma's Australian customers are cannon fodder for Magecart thieves. Anyone who ordered a pair of sneakers online, had their name, address and cr...

Fuente: Sansec

Magento / e-commerce 29/04/2019 00:00 UTC

57 payment gateways from Germany to Brazil targeted

Sansec discovered a polymorphic skimmer that works with 57 different payment gateways. It has global reach, affecting payment systems from Germany to Brazil. It is by far the most advanced skimmer ...

Fuente: Sansec

Magento / e-commerce 24/04/2019 00:00 UTC

Credit cards of Atlanta Hawks fans stolen

MageCart attacks on online stores surged last year, culminating in the hack of British Airways and Ticketmaster. This year the trend continues with another high-profile target. The Atlanta Hawks sh...

Fuente: Sansec

Magento / e-commerce ⚠ posible crítico 29/01/2019 00:00 UTC

Bad extensions now main source of Magento hacks: a solution!

In October last year Sansec discovered several Magento extension 0days. As it turns out, this was only the tip of the iceberg: today, insecure 3rd party extensions are used to hack into thousands o...

Fuente: Sansec

Magento / e-commerce 20/01/2019 00:00 UTC

Large sites hacked via Adminer database tool

This week Sansec discovered that large ecommerce and government sites got hacked via the Adminer database tool. As it turns out, the root cause is a protocol flaw in MySQL. Curiously, it is describ...

Fuente: Sansec

Magento / e-commerce 17/01/2019 00:00 UTC

PHP tool 'Adminer' leaks passwords

Update 2019-01-20: the root cause is a protocol flaw in MySQL.Adminer is a popular PHP tool to administer MySQL and PostgreSQL databases. However, it can be lured to disclose arbitrary files. Atta...

Fuente: Sansec

Magento / e-commerce 20/11/2018 00:00 UTC

Competing digital skimmers sabotage each other

Skimmers found to subtly sabotage each others fraud operations.Competition is grim in the online skimming business (aka "MageCart"). The aggressive MagentoCore skimmer was previously obs...

Fuente: Sansec

Magento / e-commerce 12/11/2018 00:00 UTC

Merchants struggle with MageCart reinfections

1 in 5 compromised merchants get reinfected, average skimming operation lasts 13 daysMageCart, the notorious actors behind massive online card skimming, has been busy. And so have we: our crawlers...

Fuente: Sansec

Magento / e-commerce 30/10/2018 00:00 UTC

Backdoor found in Webgility

Update Nov 23rd: Webgility has released a patch and a public statement, urging all customers to upgrade to version 345.Update Nov 30th: Webgility has discovered another security issue and urges al...

Fuente: Sansec

Magento / e-commerce ⚠ posible crítico 23/10/2018 00:00 UTC

Unpublished security flaws (0days) massively exploited

Online credit card theft has been all over the news: criminals inject hidden card stealers on legitimate checkout pages. But how are they are able to inject anything in the first place? As it turns...

Fuente: Sansec

Magento / e-commerce 15/10/2018 00:00 UTC

German political party store hacked before election

The store of German political party CSU (www.csu-shop.de) contains an identity skimmer that was planted on or before Oct 5th, right before the Bavarian election on Oct 14th. Personal identifyable i...

Fuente: Sansec

Magento / e-commerce 04/10/2018 00:00 UTC

MageCart: now with tripwire

Back in 2016, Magecart skimmers would evade detection by sleeping if any developer tools were found running. Then, their malware would 404 without correct Referer or User-Agent header. And now, Mag...

Fuente: Sansec

Magento / e-commerce 18/09/2018 00:00 UTC

ABS-CBN next in series of high profile breaches

While Filipinos are recovering from typhoon Mangkhut, another misfortune awaits them online. We found their broadcasting giant ABS-CBN − a $740 million conglomerate & top-500 global Internet de...

Fuente: Sansec

Magento / e-commerce 06/09/2018 00:00 UTC

Is your Google Analytics code malicious?

Would you - a webdeveloper - get alarmed if you found the following code on your website? Probably not, as Google Analytics is embedded in pretty much every website these days:<script type=&quo...

Fuente: Sansec

Magento / e-commerce 30/08/2018 00:00 UTC

MagentoCore group hacks 7,339 stores and counting

A single group is responsible for planting skimmers on 7339 individual stores in the last 6 months. The MagentoCore skimmer is now the most successful to date.Update 2018-09-07: Because Google Chr...

Fuente: Sansec

Magento / e-commerce 28/12/2017 00:00 UTC

Hackers breached Magento through helpdesk

Magento merchants have recently received messages like this:Hey, I strongly recommend you to make a redesign! Please contact me if you need a good designer! -- knockers@yahoo.comUpon closer exa...

Fuente: Sansec

Magento / e-commerce 07/11/2017 00:00 UTC

Cryptojacking found on 2496 online stores

Does your laptop get hot when visiting your favorite shop? You computer is likely mining cryptocurrencies to the benefit of a cyberthief.Cryptojacking - running crypto mining software in the brow...

Fuente: Sansec

Magento / e-commerce 02/05/2017 00:00 UTC

Why ordering HTTP headers is important

If you code against Akamai hosted sites, you could be rejected because your HTTP library sends request headers in the wrong order. In fact, most libraries use undefined order, as the IETF specifica...

Fuente: Sansec

Magento / e-commerce 21/04/2017 00:00 UTC

Warning: fake Magento patch 9789 contains virus

Update May 21st: a similar phishing mail circulates about a fake patch SUPEE-1798.Update Apr 22nd: added reference to Neutrino Bot and POS systemsThis week a mail was sent out to announce the ne...

Fuente: Sansec

Magento / e-commerce 12/04/2017 00:00 UTC

A Magento breach analysis: part 1

Part of a series where Magento security professionals share their case notes, so that we can ultimately distill a set of best practices, tools and workflow.Part of the job of running the MageRepor...

Fuente: Sansec

Magento / e-commerce 07/04/2017 00:00 UTC

An OpenCart/Magento hacking dashboard

This post shows how sophisticated Magento hacking operations have become nowadays.While investigating a bruteforced Magento store, we noticed that the hacker logged in using a curious referrer sit...

Fuente: Sansec

Magento / e-commerce 14/02/2017 00:00 UTC

Self-healing malware restores itself after deletion

Regular Javascript-based malware is normally injected in the static header or footer HTML definitions in the database. Cleaning these records used to be sufficient to get rid of the malware. But no...

Fuente: Sansec

Magento / e-commerce 01/12/2016 00:00 UTC

Visbot malware found on 6691 stores [analysis]

Visbot is one of the oldest Magecart payment skimmers: it steals customer data and credit cards. The first case was documented as early as March 2015. But being publicly discussed did not stop it f...

Fuente: Sansec

Magento / e-commerce 17/11/2015 00:00 UTC

Criminals have rewired 3,500 online stores

Criminals have secretly rewired 3,500 online stores to continuously harvest credit card numbers. The fraud can be traced back as far as May 12th 2015, so if you have bought something at one of thes...

Fuente: Sansec