π¨ ACTIVE EXPLOITATION
- CISA adds critical Oracle proxy plug-in flaw to KEV catalog
CVE-2026-21962CISA lists a critical Oracle proxy plug-in vulnerability in its KEV catalog.- Oracle HTTP Server and Oracle WebLogic Server Proxy Plug-in customers are affected.
- CVE-2026-21962 is an improper access control flaw with a CVSS score of 10.0.
- Affected versions are 12.2.1.4.0, 14.1.1.0.0 and 14.1.2.0.0; IIS is affected only at 12.2.1.4.0.
- An unauthenticated attacker can exploit the flaw remotely over HTTP to access or modify critical data. π Source: oracle.com Β· π Coverage: nvd.nist.gov Β· π via CISA KEV
π΅οΈ RESEARCH & DEEP DIVES
- Fake GTA 6 Demo Sites Distribute Vidar Infostealer
Fake GTA 6 demo sites are distributing the Vidar infostealer.
- GTA 6 fans searching for leaks, demos, or PC builds are targeted.
- Fake Rockstar-branded sites deliver a 1.1 MB gta6_installer.exe instead of a game.
- The Vidar sample steals browser passwords, cookies, authenticated sessions, history, autofill data, and FTP credentials.
- βPlay Nowβ links and copied Rockstar Extended Look promotions lead to the malware download.
- Observed IOCs include SHA-256 a8f19d598e6a49d8510d73d41fc445246755ed321c2f76985a463a9fef537eb0 and gta6demo[.]asia, gta6demo[.]eu, and gta6demo[.]us. π Source: cnet.com Β· π Coverage: malwarebytes.com Β· π via securityboulevard.com (discovered)
π CVEs & KEV
-
CVE-2026-71933 β CVSS 8.8 β DrayTek VigorSwitch Multiple Models Missing Authorization in Syslog Functions...
-
CVE-2026-9254 β CVSS 8.7 β Command Injection Vulnerability in Parent Control of Multiple TP-Link Archer ...
-
CVE-2026-71943 β CVSS 8.6 β DrayTek VigorSwitch Multiple Models OS Command Injection via setDevNetMultipl...
-
CVE-2026-71942 β CVSS 8.6 β DrayTek VigorSwitch Multiple Models Buffer Overflow via mail_mailalertMultipl...
-
CVE-2026-71941 β CVSS 8.6 β DrayTek VigorSwitch Multiple Models Buffer Overflow via diag_logmailMultiple ...
-
CVE-2026-71940 β CVSS 8.6 β DrayTek VigorSwitch Multiple Models Buffer Overflow via acl_general_setup Edi...
-
CVE-2026-71939 β CVSS 8.6 β DrayTek VigorSwitch Multiple Models Buffer Overflow via acl_general_setup Add...
-
CVE-2026-71938 β CVSS 8.6 β DrayTek VigorSwitch Multiple Models Buffer Overflow via switch_lan_gvrpMultip...
-
CVE-2026-71937 β CVSS 8.6 β DrayTek VigorSwitch Multiple Models Buffer Overflow via poe_schedule_profileM...
-
CVE-2026-71936 β CVSS 8.6 β DrayTek VigorSwitch Multiple Models Buffer Overflow via sysrebootMultiple Dra...
-
CVE-2026-71935 β CVSS 8.6 β DrayTek VigorSwitch Multiple Models Buffer Overflow via webBackupActionMultip...
-
CVE-2026-71934 β CVSS 8.6 β DrayTek VigorSwitch Multiple Models Buffer Overflow via pingtraceMultiple Dra...
-
CVE-2026-71931 β CVSS 8.6 β DrayTek VigorSwitch Multiple Models OS Command Injection via tftp_upgradeMult...
-
CVE-2026-71930 β CVSS 8.6 β DrayTek VigorSwitch Multiple Models OS Command Injection via setTimeMultiple ...
-
CVE-2026-71929 β CVSS 8.6 β DrayTek VigorSwitch Multiple Models OS Command Injection via setDevProtoMulti...
-
CVE-2026-16348 β CVSS 8.5 β Command Injection Vulnerability in VPN connection of Archer BE800An authentic...
-
CVE-2026-71932 β CVSS 6.9 β DrayTek VigorSwitch Multiple Models Path Traversal via getSyslogFileMultiple ...
-
CVE-2026-34491 β CVSS 6.1 β Improper neutralization of input during web page generation ('cross-site scri...
-
CVE-2026-78475 β CVSS 6.1 β Gimp: unbounded stack vla and 21-byte stack over-read in pix (esm) loaderA fl...