ZeroHour
Security Affairspublished ()ingested @securityaffairs

Security Affairs newsletter Round 583 by Pierluigi Paganini – INTERNATIONAL EDITION

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2026-20245
Command Injection as Root in Cisco Catalyst SD-WAN Manager

Cisco Catalyst SD-WAN Manager (formerly SD-WAN vManage) contains an improper encoding or escaping of output flaw (CWE-116) in its handling of user-supplied files. An attacker who already has authenticated access to the system can trigger it by supplying a crafted file, because the file's contents are not properly escaped before being processed. Successful exploitation yields arbitrary command execution with root privileges, giving the attacker full control of the SD-WAN management platform. Organizations running Cisco Catalyst SD-WAN Manager/vManage to manage their SD-WAN fabric are affected. The flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2026-06-09, indicating active exploitation, though no public proof-of-concept is known and ransomware use has not been confirmed.

Do: Apply the fixed release per Cisco's security advisory (specific fixed versions are not included in the available data), and prioritize this patch given the KEV listing. Because the flaw requires authenticated local access, restrict management-plane access to trusted administrators and networks, review privileged accounts on the manager, and audit the system for unexpected processes or changes. Federal agencies must follow the KEV required action under BOD 22-01 (mitigate per vendor instructions or discontinue use).

7.825% KEV
  • Cisco Catalyst SD-WAN Manager (formerly SD-WAN vManage)
largeon the order of tens of thousands of deployments worldwide
CVE-2026-20971
Use After Free in PROCA driver prior to SMR Jan-2026 Release 1 allows local attackers to potentially execute arbitrary code.

Use After Free in PROCA driver prior to SMR Jan-2026 Release 1 allows local attackers to potentially execute arbitrary code.

NVD description · AI analysis pending
7.3<1%
  • samsung android
CVE-2026-43503
In the Linux kernel, the following vulnerability has been resolved:

In the Linux kernel, the following vulnerability has been resolved: net: skbuff: propagate shared-frag marker through frag-transfer helpers Two frag-transfer helpers (__pskb_copy_fclone() and skb_shift()) fail to propagate the SKBFL_SHARED_FRAG bit in skb_shinfo()->flags when moving frags from source to destination. __pskb_copy_fclone() defers the rest of the shinfo metadata to skb_copy_header() after copying frag descriptors, but that helper only carries over gso_{size,segs, type} and never touches skb_shinfo()->flags; skb_shift() moves frag descriptors directly and leaves flags untouched. As a result, the destination skb keeps a reference to the same externally-owned or page-cache-backed pages while reporting skb_has_shared_frag() as false. The mismatch is harmful in any in-place writer that uses skb_has_shared_frag() to decide whether shared pages must be detoured through skb_cow_data(). ESP input is one such writer (esp4.c, esp6.c), and a single nft 'dup to ' rule -- or any other nf_dup_ipv4() / xt_TEE caller -- is enough to land a pskb_copy()'d skb in esp_input() with the marker stripped, letting an unprivileged user write into the page cache of a root-owned read-only file via authencesn-ESN stray writes. Set SKBFL_SHARED_FRAG on the destination whenever frag descriptors were actually moved from the source. skb_copy() and skb_copy_expand() share skb_copy_header() too but linearize all paged data into freshly allocated head storage and emerge with nr_frags == 0, so skb_has_shared_frag() returns false on its own; they need no change. The same omission exists in skb_gro_receive() and skb_gro_receive_list(). The former moves the incoming skb's frag descriptors into the accumulator's last sub-skb via two paths (a direct frag-move loop and the head_frag + memcpy path); the latter chains the incoming skb whole onto p's frag_list. Downstream skb_segment() reads only skb_shinfo(p)->flags, and skb_segment_list() reuses each sub-skb's shinfo as the nskb -- both p and lp must carry the marker. The same omission also exists in tcp_clone_payload(), which builds an MTU probe skb by moving frag descriptors from skbs on sk_write_queue into a freshly allocated nskb. The helper falls into the same family and warrants the same fix for consistency; no TCP TX-side in-place writer is currently known to reach a user page through this gap, but a future consumer depending on the marker would regress silently. The same omission exists in skb_segment(): the per-iteration flag merge takes only head_skb's flag, and the inner switch that rebinds frag_skb to list_skb on head_skb-frags exhaustion does not fold the new frag_skb's flag into nskb. Fold frag_skb's flag at both sites so segments drawing frags from frag_list members carry the marker.

NVD description · AI analysis pending
8.8<1%
  • linux linux kernel
CVE-2026-47729
Squid is a caching proxy for the Web.

Squid is a caching proxy for the Web. Prior to 7.6, due to an improper validation of syntactic correctness of input in the FTP gateway (src/clients/FtpGateway.cc), Squid is vulnerable to an out-of-bounds read: when a listing entry date in the TypeA or TypeB directory-listing formats is not followed by a filename, parsing was not restricted to the input buffer, so a trusted client accessing a misbehaving FTP server through Squid's gateway feature could read memory from random unrelated transactions. This issue is fixed in version 7.6.

NVD description · AI analysis pending
6.52%
  • squid-cache squid
Full article535 words · extracted from securityaffairs.com · click to collapse

A new round of the weekly Security Affairs newsletter has arrived! Every week, the best security articles from Security Affairs are free in your email box.

Enjoy a new round of the weekly SecurityAffairs newsletter, including the international press.

International Press – Newsletter

Cybercrime

The Broker Behind FortiBleed: Anatomy of a Russian-Speaking Access Operation  

Security News This Week: Hackers Claim to Leak Stolen Madison Square Garden Data 

Scaling cybercrime disruption through innovation and AI

Global cyber strike disrupts SocGholish, Amadey, and StealC malware networks

Third Defendant Sentenced To Prison For Hacking Fantasy Sports And Betting Website    

ACE, UEFA, UC3 and Mexican Authorities Disrupt Major PirloTV-Linked Sports Piracy Ring Serving Latin America

India’s Tata Electronics hit by cyber breach claiming to expose Apple, Tesla trade secrets     

Polymarket to Refund Users After Hackers Steal $3M in Frontend Attack      

Photo ZIP campaign targeting hospitality industry delivers Node.js implant for persistent access  

Malware

More Than 4,000 Legacy Routers Compromised by AryStinger, Turned into Global Attack Proxies for Hackers  

A VBScript campaign distributed through WhatsApp deploying RMM software 

Prinz Eugen ransomware: a deep dive into a new Go-based encryptor

Backdoor.Mistic: New Backdoor May be Linked to Ransomware Access Broker  

Miasma Mini Shai-Hulud Hits LeoPlatform npm Packages and GitHub Actions, Expands to the Go Ecosystem  

Hacking

Introducing usbliter8 

Squidbleed (CVE-2026-47729) Heartbleed’s ancient cousin, hiding in Squid since 1997  

PSA: Supply Chain Compromise Targets ShapedPlugin, Backdoored Pro Plugins Distributed via Official Channels  

DifyTap: Zafran discovers how attackers can silently wiretap AI data across tenants on a platform powering 1M+ apps  

When Defenses Become Attack Surface: CVE-2026-20971, a Samsung Kernel UAF  

Zero-Day Exploitation of Vulnerability (CVE-2026-20245) in Cisco Catalyst SD-WAN Manager   

AISLE Discovers 6 New CVEs in curl, Including the Oldest Issue Ever Reported 

A new unpatchable flaw in Apple chips opens the door to an iPhone jailbreak  

Elite network says it was hacked after members’ personal data was left exposed  

New Linux pedit COW Exploit Enables Root Access by Poisoning Cached Binaries

Dissecting and Exploiting Linux LPE Variant: DirtyClone (CVE-2026-43503)  

Intelligence and Information Warfare  

Claude Fable 5 Resurfaces in Android App as NSA Breach Testimony Reshapes Ban  

From package to postinstall payload: Inside the Mastra npm supply chain compromise by Sapphire Sleet

Five Eyes cyber security agencies statement The AI shift in cyber risk: why leaders must act now   

Weaponized AI: Inside The Criminal Ecosystem Fueling The Fifth Wave of Cybercrime  

macOS.Gaslight | Rust Backdoor Turns Prompt Injection on the Analyst, Not the Sandbox  

Russia Breaks Into Human Rights Activist’s Phone With Cellebrite 

CL-STA-1062 Targets Southeast Asian Governments and Critical Infrastructure

Russian Intelligence Services Continue to Target Commercial Messaging Applications  

Cybersecurity

Deutsche Bahn halts trains nationwide amid IT meltdown

How to Disappear From the Internet in 7 Days 

The quantum threat: Navigating cryptographic risks in a new computing era

Dozens of America’s largest companies have no simple way to report security flaws      

Xsolis Data Breach Affects 1.4 Million Individuals  

‘Wake-up call’: Europe reacts to Anthropic halting access to its Fable 5 and Mythos 5 AI models  

Meta Pauses Employee-Tracking Program Following Internal Data Leak 

State of SDLC Security 2026 

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, newsletter)



you might also like

leave a comment

Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/194372/security/security-affairs-newsletter-round-583-by-pierluigi-paganini-international-edition.html