PULSE
FEED
ransomqilin reclama a Arnold Center · US · Not Foundransomincransom reclama a bakemyday.se · SE · Retail & E-Commerceransomthreeam reclama a safescaffolding.net · GB · Manufacturingransomthreeam reclama a coosalud.com · CO · Healthcareransomthreeam reclama a pistonespersan.com.ar · AR · Manufacturingransomthreeam reclama a midwestbit.com · US · Technologyransomthreeam reclama a apexus.com · US · Technologyransomthreeam reclama a bhn-expertise.com · DE · Professional Servicesransomthreeam reclama a stjames.wa.edu.au · AU · Educationransomdoommageddon reclama a Goodrich Logistics · Transportationransomdoommageddon reclama a Chem Process Systems Pvt. Ltd. · IN · Manufacturingransomplay reclama a Starr Whitehouse Landscape Architects · US · Professional Servicesransomplay reclama a Ever Ready First Aid · US · Healthcareransommedusalocker reclama a PKSF — Palli Karma-Sahayak Foundation · BD · Financial Servicesransomqilin reclama a Arnold Center · US · Not Foundransomincransom reclama a bakemyday.se · SE · Retail & E-Commerceransomthreeam reclama a safescaffolding.net · GB · Manufacturingransomthreeam reclama a coosalud.com · CO · Healthcareransomthreeam reclama a pistonespersan.com.ar · AR · Manufacturingransomthreeam reclama a midwestbit.com · US · Technologyransomthreeam reclama a apexus.com · US · Technologyransomthreeam reclama a bhn-expertise.com · DE · Professional Servicesransomthreeam reclama a stjames.wa.edu.au · AU · Educationransomdoommageddon reclama a Goodrich Logistics · Transportationransomdoommageddon reclama a Chem Process Systems Pvt. Ltd. · IN · Manufacturingransomplay reclama a Starr Whitehouse Landscape Architects · US · Professional Servicesransomplay reclama a Ever Ready First Aid · US · Healthcareransommedusalocker reclama a PKSF — Palli Karma-Sahayak Foundation · BD · Financial Services
← Todos los CVEs
CVE Watch28 sept 2026

CVE-2026-100903

A vulnerability was identified in ООО НПО Ритм GEOritm up to 2.45.1. This affects an unknown part of the file /restapi/objects/obj-groups of

CVSS

5.3

Medio

EPSS

—

KEV

—

Exploit Today

—

0-100

Publicado: 28 sept 2026 · Última mod.: 28 sept 2026 · CWE-287 · CWE-306

EPSS · 30d

Sin historial EPSS suficiente todavía.

Descripción técnica

A vulnerability was identified in ООО НПО Ритм GEOritm up to 2.45.1. This affects an unknown part of the file /restapi/objects/obj-groups of the component REST API. Such manipulation of the argument objectId leads to missing authentication. The attack can be launched remotely. The exploit is publicly available and might be used. Upgrading to version 2.46 is able to mitigate this issue. It is advisable to upgrade the affected component. The vendor confirms: "In August 2026, NPO Ritm received an official vulnerability notification from the Russian Federal Service for Technical and Export Control (FSTEC Russia). The vulnerability was registered under identifier BDU:2026-11235. Following our internal investigation, we confirmed the vulnerability and implemented the necessary security fixes. The vulnerability has been fixed on our hosted GEO.RITM server at geo.ritm.ru. The fix has also been included in GEO.RITM version 2.46, which is already being distributed to our customers."

Referencias oficiales
CVEs relacionados
CVECVSSEPSSKEVRExplotTítuloVis.
CVE-2026-499949.1 CRÍ
—
———Bluehood monitors local bluetooth activity. Prior to version 0.7.1, when auth_enabled is set in Bluehood, only the HTML page handlers enforced session validation. The /api/* handlers (settings, devices, groups, per-device endpoints including /api/device/{mac}/notes) called no auth check at all. A network attacker reachable on the dashboard port could read Bluetooth tracking data and modify application state — including the heartbeat URL, prune retention, device groups, and per-device notes — without a session cookie. This issue has been patched in version 0.7.1.8h
CVE-2026-91154—
—
———Missing Authentication for Critical Function (CWE-306) in the product cache revalidation Server Action (src/app/actions.ts, revalidateProducts) in MarcosCamara01 Ecommerce Template before commit ec97209 allows a remote, unauthenticated attacker to force expiration of the entire storefront product cache at will. The file declares "use server" at file scope, so every exported function compiles into a POST-invokable Server Action; revalidateProducts calls updateTag("products") with no session or role check, unlike the read-only actions in the same file which are safe by construction. Two client components under src/components/admin import the function, which causes its Server Action id to be compiled into a public /_next/static chunk that the application's admin middleware (proxy.ts) does not gate, so any unauthenticated user can extract that id from the public bundle and invoke the action directly. With cacheComponents enabled, the entire storefront (home, categories, product pages, search) is served from "use cache" entries produced by getAllProducts, getCategoryProducts and getProduct, all tagged products with an hours-long cacheLife. Repeated unauthenticated invocation of revalidateProducts keeps that cache permanently cold, forcing every visitor's request to read the full product catalog from Postgres instead of serving from cache, degrading storefront availability at near-zero attacker cost.8h
CVE-2026-10107710.0 CRÍ
—
———A flaw has been found in Netcore NR289-GE 1.4.5102. This impacts the function process_request of the component boa_temp Handler. This manipulation causes missing authentication. The attack is possible to be carried out remotely. The exploit has been published and may be used. The vendor was contacted early about this disclosure but did not respond in any way.10h
CVE-2026-935395.4 MED
—
———A vulnerability was discovered in Fleet's Git webhook receiver (the gitjob webhook service). When a webhook secret is not configured, incoming webhook requests are accepted without verification, and processing a request can change the spec.pollingInterval field of a matching GitRepo resource in any namespace. A caller with network access to the webhook service and no Kubernetes credentials can therefore alter GitRepo configuration outside the namespaces they are authorized for.  This only affects SUSE Rancher Fleet 0.16 before 0.16.2, older versions are not affected.9h
CVE-2026-1010738.3 ALT
—
———A security flaw has been discovered in Netcore NR289-GE 1.4.5102. Impacted is an unknown function of the file /bin/boa of the component CGI Dispatcher. Performing a manipulation results in improper authentication. The attack may be initiated remotely. The exploit has been released to the public and may be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.11h
CVE-2026-82930—
—
———mH-DEVELOPER smart home module does not verify tokens in its authorization middleware, leaving all HTTP API and WebSocket endpoints accessible without authentication. An unauthenticated attacker on the LAN can query these endpoints, access system information, and send raw control commands to manipulate building automation devices. This issue was fixed in version 3.0.309h