Latest news
-
Vulnerabilities via oss-security
CVE-2026-82546: Apache Roller: Stored cross-site scripting through incoming Trackback links
Posted by David M. Johnson on Sep 25 Severity: Moderate CVSS 3.1: 6.1 (medium) CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N Affected versions: - Apache Roller 6.1.5…
-
Vulnerabilities via oss-security
CVE-2026-82387: Apache Roller: Stored cross-site scripting via uploaded media content type
Posted by David M. Johnson on Sep 25 Severity: Moderate CVSS 3.1: 5.4 (medium) CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N Affected versions: - Apache Roller 6.1.5…
-
Vulnerabilities via BleepingComputer
Kiteworks urges 6-hour server shutdown over potential zero-day attacks
Secure file-sharing software company Kiteworks is urging customers worldwide to temporarily shut down their servers on Saturday for a six-hour window after receiving…
-
Vulnerabilities via oss-security
CVE-2026-82386: Apache Roller: XML external entity processing in OPML bookmark import
Posted by David M. Johnson on Sep 25 Severity: Important CVSS 3.1: 7.7 (high) CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N Affected versions: - Apache Roller 6.1.5…
-
Vulnerabilities via oss-security
CVE-2026-82385: Apache Roller: Weblog template include escapes the Velocity sandbox and reads classpath files
Posted by David M. Johnson on Sep 25 Severity: Important CVSS 3.1: 6.5 (medium) CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N Affected versions: - Apache Roller 6.1.5…
-
Vulnerabilities via oss-security
CVE-2026-82384: Apache Roller: Unauthenticated deserialization in the XML-RPC endpoint
Posted by David M. Johnson on Sep 25 Severity: Critical CVSS 3.1: 9.8 (critical) CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H Affected versions: - Apache Roller 6.1.5…
-
Vulnerabilities via oss-security
CVE-2026-82383: Apache Roller: Anonymous setup action allows frontpage configuration tampering
Posted by David M. Johnson on Sep 25 Severity: Important CVSS 3.1: 8.2 (high) CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:L Affected versions: - Apache Roller 6.1.5…
-
Vulnerabilities via oss-security
CVE-2026-82382: Apache Roller: Reflected cross-site scripting in the frontpage directory parameter
Posted by David M. Johnson on Sep 25 Severity: Moderate CVSS 3.1: 6.1 (medium) CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N Affected versions: - Apache Roller 6.1.5…
-
Vulnerabilities via oss-security
CVE-2026-82381: Apache Roller: Stored cross-site scripting in the authoring UI
Posted by David M. Johnson on Sep 25 Severity: Important CVSS 3.1: 5.4 (medium) CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N Affected versions: - Apache Roller 6.1.5…
-
Threat Intel via CyberScoop
Army soldier sentenced for spree of attacks on AT&T, Snowflake and other major companies
A former Army soldier responsible for a series of attacks and extortion attempts on telecom companies, including AT&T, was sentenced to 70 months in prison, the Justice…
-
Vulnerabilities via oss-security
CVE-2026-82380: Apache Roller: CSRF protection bypass via self-generated salt validation
Posted by David M. Johnson on Sep 25 Severity: Important CVSS 3.1: 8.1 (high) CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H Affected versions: - Apache Roller 6.1.5…
-
Vulnerabilities via oss-security
CVE-2026-82379: Apache Roller: WSSE digest authentication headers can be replayed
Posted by David M. Johnson on Sep 25 Severity: Moderate CVSS 3.1: 7.7 (high) CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L Affected versions: - Apache Roller 6.1.5…
-
Vulnerabilities via oss-security
CVE-2026-82378: Apache Roller: OAuth authorization endpoint trusts request-supplied identity
Posted by David M. Johnson on Sep 25 Severity: Moderate CVSS 3.1: 9.0 (critical) CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H Affected versions: - Apache Roller 6.1.5…
-
Vulnerabilities via oss-security
CVE-2026-82377: Apache Roller: Missing weblog authorization in XML-RPC Blogger/MetaWeblog handlers
Posted by David M. Johnson on Sep 25 Severity: Moderate CVSS 3.1: 9.9 (critical) CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H Affected versions: - Apache Roller 6.1.5…
-
Vulnerabilities via oss-security
CVE-2026-82376: Apache Roller: XML external entity processing in trackback response parser
Posted by David M. Johnson on Sep 25 Severity: Important CVSS 3.1: 7.7 (high) CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N Affected versions: - Apache Roller 6.1.5…
-
Vulnerabilities via oss-security
CVE-2026-82375: Apache Roller: Server-side request forgery via entry trackback and enclosure URLs
Posted by David M. Johnson on Sep 25 Severity: Moderate CVSS 3.1: 7.4 (high) CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:L Affected versions: - Apache Roller 6.1.5…
-
Vulnerabilities via oss-security
CVE-2026-82348: Apache Roller: Cross-weblog resource tampering via unscoped authoring lookups
Posted by David M. Johnson on Sep 25 Severity: Important CVSS 3.1: 7.7 (high) CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:L/I:H/A:L Affected versions: - Apache Roller 6.1.5…
-
Threat Intel via Schneier on Security
Friday Squid Blogging: Participatory Squid Dissection in October in Tennessee
I feel like someone who reads this blog will want to go to this: Families are invited to dive into the fascinating world of marine biology during an exciting, hands-on…
-
Vulnerabilities via Security Affairs
U.S. CISA adds Microsoft SharePoint and Mikrotik RouterOS flaws to its Known Exploited Vulnerabilities catalog
U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Microsoft SharePoint and Mikrotik RouterOS flaws flaws to its Known Exploited Vulnerabilities catalog…
-
Ransomware via BleepingComputer
ShinyHunters hacked Clop leak site using Grav CMS path traversal flaw
The Clop ransomware gang has moved its data leak site to a new Tor address after confirming its previous server was compromised and defaced through an unpatched Grav CMS…
