ZeroHour

Search: “http”

12 stories in the last 30d

USN-8571-2: Apache HTTP Server regression

Ubuntu issues USN-8571-2 fixing an Apache HTTP Server regression that prevented startup when HTTP/2 proxying was enabled.

Ubuntu released USN-8571-2 to fix a regression introduced by USN-8571-1 in Apache HTTP Server. The earlier fix was incomplete due to a missing library symbol, causing Apache to fail to start when HTTP/2 proxying was enabled. The original advisory addressed CVE-2026-33007, a memory-handling flaw in mod_authn_socache allowing remote denial of service, and an HTTP response splitting vulnerability affecting multiple modules, credited to Pavel Kohout, Arkadi Vainbrand, Haruki Oyama, Merih Mengisteab, and Dawit Jeong.

Ubuntu Security Noticesupdated · 6h agofirst · 6d agoAdvisory 15 sourcesCVE-2026-330071

CVE-2026-73191: Apache Syncope: CAS service URL injection via Forwarded HTTP headers

Apache Syncope SRA CVE-2026-73191 enables CAS service URL injection via Forwarded HTTP headers.

Apache Syncope disclosed CVE-2026-73191, a moderate-rated open redirect vulnerability in the Syncope SRA. When the SRA is configured for CAS authentication, the target Apereo CAS service URL can be manipulated through Forwarded HTTP headers, redirecting users to an untrusted site. The flaw affects syncope-sra in versions 3.0.0-M0 through 3.0.16, 4.0.0-M0 through 4.0.7, and 4.1.0-M0 through 4.1.2. Users should upgrade to fixed releases.

oss-security · 2d agoVulnerabilityCVE-2026-73191

Muhstik Botnet Attacks Tomato Routers to Harvest New IoT Devices

Unit 42 found a Muhstik botnet variant brute-forcing Tomato router web authentication to harvest IoT devices for crypto mining and DDoS attacks.

Palo Alto Networks Unit 42 researchers in December 2019 identified a new Muhstik botnet variant scanning Tomato routers on TCP 8080 and brute-forcing default admin credentials, targeting roughly 4,600 exposed devices found via Shodan. The variant also scans WordPress and Webuzo installations and exploits the Oracle WebLogic deserialization flaw CVE-2019-2725 for unauthenticated remote code execution. Muhstik, active since March 2018, self-propagates like a worm and typically monetizes infections through cryptocurrency mining and DDoS attacks controlled via an IRC C2 channel.

Palo Alto Unit 42 · 28d agoMalware in the wildCVE-2019-2725

Cisco Desk Phone 9800 Series, IP Phone 7800 and 8800 Series, and Video Phone 8875 with SIP Software Denial of Service Vulnerability

Cisco warns of a DoS flaw in SIP software on Desk Phone 9800 and IP Phone 7800/8800 series from improper HTTP packet memory handling.

Cisco disclosed a denial of service vulnerability affecting Desk Phone 9800 Series, IP Phone 7800 and 8800 Series, and Video Phone 8875 devices running Cisco SIP Software. An unauthenticated remote attacker can send a continuous stream of crafted HTTP packets, causing sustained memory consumption until the device becomes unresponsive. A manual reboot is required to recover an affected device. No CVE identifier was listed in the advisory text.

Cisco Security Advisories · 14d agoAdvisory

Cisco Identity Services Engine Authorization Bypass Vulnerabilities

Cisco fixed authorization bypass flaws in ISE and ISE-PIC web management letting authenticated admins modify file descriptions via crafted HTTP requests.

Multiple vulnerabilities in the web-based management interface of Cisco Identity Services Engine and ISE Passive Identity Connector result from missing server-side validation of Administrator permissions. An authenticated remote attacker with valid Administrator credentials can submit crafted HTTP requests to modify descriptions of files on specific pages. Cisco has released software updates addressing the issues.

Cisco Security Advisories · 10h agoAdvisory 15 sources

Cisco BroadWorks CommPilot Application Software Authorization Bypass Vulnerability

Cisco patched a BroadWorks CommPilot authorization bypass letting low-privileged authenticated users alter device configurations via crafted HTTP requests.

A vulnerability in the web-based management interface of Cisco BroadWorks CommPilot Application Software is caused by missing authorization checks. An authenticated remote attacker with low privileges can send crafted HTTP requests to alter configurations on select pages. Cisco has released software updates and no workarounds are available.

Cisco Security Advisories · 10h agoAdvisory

USN-8757-1: cgit vulnerability

Ubuntu USN-8757-1 fixes cgit path-handling flaw letting remote attackers read files outside repositories during HTTP cloning.

Ubuntu Security Notice USN-8757-1 addresses a cgit vulnerability in which repository paths are incorrectly handled when HTTP cloning is enabled. A remote attacker could exploit the flaw to access files outside the repository and obtain sensitive information. The notice provides no CVE identifier or exploitation details.

Ubuntu Security Notices · 2d agoAdvisory

Open Redirect on FortiSIEM

Fortinet disclosed an open redirect flaw (CVSS 2.8) in FortiSIEM allowing authenticated attackers to redirect users to arbitrary websites via crafted HTTP requests.

Fortinet advisory FG-IR-26-169 covers an open redirect vulnerability (CWE-601) in FortiSIEM, rated CVSSv3 2.8. An authenticated attacker can cause a redirection to any website via specially crafted HTTP requests. The advisory was revised on 2026-09-08.

Fortinet PSIRT · 8d agoAdvisory

Scans for Proxmox Servers, (Wed, Sep 9th)

SANS observed increased scanning and brute-force attacks on port 8006 targeting unsupported Proxmox VE 7 servers after a recent vulnerability advisory.

SANS Internet Storm Center reported a bump in scans for port 8006 and additional brute-force traffic against Proxmox VE servers following a Proxmox advisory about a vulnerability in older releases. The flaw only affects Proxmox VE version 7, which has been unsupported for a couple of years. Observed activity includes POST requests to /api2/json/access/ticket with root@pam usernames and weak passwords, fingerprinting requests, and POSTs to /api2/extjs/access/ticket; failed logins return 401 status codes and non-TLS POSTs return 308 redirects.

SANS Internet Storm Center · 7d agoExploit / PoC

Null Pointer Dereference in Log Report

Fortinet patched a low-severity null pointer dereference (CVSS 2.5) in FortiOS, FortiProxy, and FortiPAM that lets authenticated attackers crash the httpsd daemon.

Fortinet advisory FG-IR-26-173 describes a NULL pointer dereference vulnerability (CWE-476) in FortiOS, FortiProxy, and FortiPAM, scored CVSSv3 2.5. An authenticated attacker can crash the httpsd daemon via crafted HTTP requests, causing a denial of service. The advisory was revised on 2026-09-08.

Fortinet PSIRT · 8d agoAdvisory

Cisco Industrial Ethernet 1000 Series Switches Denial of Service Vulnerability

Cisco released a fix for a management-plane flooding DoS in IE-1000 switches that can make the device manager, SSH, or API inaccessible.

Insufficient protection against management plane flooding in Cisco Industrial Ethernet 1000 Series Switches allows an unauthenticated remote attacker to send high-rate ICMP, SSH, or HTTP traffic, raising CPU usage and causing a denial-of-service condition on the device manager web GUI, SSH, or API. Data traffic through the device is not affected. Cisco has released software updates to address the issue.

Cisco Security Advisories · 28d agoAdvisory

Eleethub: A Cryptocurrency Mining Botnet with Rootkit for Self

Unit 42 uncovered Eleethub, a Perl-based Bitcoin mining botnet using a crafted rootkit and libprocesshider to evade detection, still under development with few infections.

Unit 42 discovered an under-development Perl Shellbot campaign that mines Bitcoin using xmrig and emech while evading detection via a rootkit that replaces the ps tool and the LD_PRELOAD-based libprocesshider.so library. Infected devices download a malicious shell script, connect to IRC-based C2 at eleethub.com and the UnderNet network, and can receive commands for UDP/TCP floods, port scans, and HTTP attacks. The botnet can affect Unix systems and Windows 10 hosts running a Linux subsystem, and its operators use the 'Los Zetas' branding, though they are unlikely to be the Mexican drug cartel. Researchers found only a few compromised 'zombies' before the campaign expanded.

Palo Alto Unit 42 · 28d agoMalware in the wild