Index
Search
Search the public record. Drafts and scheduled notes are not included.
news
IBM MQ patches CVE-2026-10747 and CVE-2026-10858
IBM published critical MQ fixes: CVE-2026-10747 is CVSS 10.0 pre-auth protocol heap overflow on the listener path, and CVE-2026-10858 is CVSS 9.9 authenticated multi-segment heap underflow on NonStop and Appliance. No KEV listing and no public PoC confirmed.
Published 30m ago
news
Goose recipe command execution is CVE-2026-85623
VulnCheck published CVE-2026-85623 / GHSA-rh2p-fw5h-rc3m for Goose: recipe stdio extensions and retry checks can run shell commands the unicode recipe scan does not inspect. CVSS 3.1 8.8. Goose 1.52.0 ships a Desktop consent-before-session fix. A public PoC exists. Not in CISA KEV.
Published 58m ago
research
Reading the Next.js ImageResponse advisory
CVE-2026-94545 is a Satori escaping bug that Vercel says can become code execution in Node.js next/og. The only published numeric score is 5.3. Next.js 16.3.6 is the fix. A public PoC exists.
Published 5h ago
news
The Gotenberg public PoC is not a confirmed RCE
CVE-2026-40281 has a public repository and a CVSS 10.0 score. The vendor advisory describes unauthenticated file move, overwrite, and link creation inside the container. Code execution is not the published impact.
Published 6h ago
CVE-2026-104711
OGNL injection in the legacy RESTful action mapper
RCE
Published 19h ago
research
How ThreatWire records a vulnerability
The status on a ThreatWire card is an editorial claim. Unknown stays unknown until a public source confirms a PoC, an exploit, or active use.
Published 34h ago
threats
Reading ransomware claims without amplifying them
A leak-site post is a claim. Victim impact, data theft, and encryption are separate facts and stay unmarked until a better source exists.
Published 2d ago
CVE-2026-94545
Satori SVG injection affecting Next.js ImageResponse
RCE
Published 6d ago
CVE-2026-96748
PyMongo connection-string host injection
Other
Published 11d ago
CVE-2026-10747
IBM MQ pre-auth heap overflow in protocol message processing
RCE
Published 18 Sept 2026
CVE-2026-85623
Goose recipe stdio extensions run commands without scan coverage
RCE
Published 4 Sept 2026