PULSE
EN VIVO29señales / 24h
FEED
ransomincransom reclama a sslf.local · US · Not Foundransomqilin reclama a TenSparrows · US · Not Foundransomcmdorganization reclama a Collge Mont Notre-Dame de Sherbrooke · CA · Educationransomqilin reclama a Db Tarimsal Enerji · TR · Agriculture and Food Productionransomcmdorganization reclama a Rondout Electric · US · Energy & Utilitiesransomqilin reclama a Byonyks · US · Technologyransomqilin reclama a Prenisac · US · Not Foundransomqilin reclama a Excel Consultores · MX · Professional Servicesransomqilin reclama a Affinity Capital · US · Financial Servicesransomkairos reclama a Warwick Fabrics · NZ · Manufacturingransomgunra reclama a Siam Stabilizers and Chemicals Co., Ltd. / SSC · TH · Manufacturingransomqilin reclama a Adpo · Otherransomqilin reclama a servitelco · CL · Technologyransomqilin reclama a Orimar · BE · Otherransomincransom reclama a sslf.local · US · Not Foundransomqilin reclama a TenSparrows · US · Not Foundransomcmdorganization reclama a Collge Mont Notre-Dame de Sherbrooke · CA · Educationransomqilin reclama a Db Tarimsal Enerji · TR · Agriculture and Food Productionransomcmdorganization reclama a Rondout Electric · US · Energy & Utilitiesransomqilin reclama a Byonyks · US · Technologyransomqilin reclama a Prenisac · US · Not Foundransomqilin reclama a Excel Consultores · MX · Professional Servicesransomqilin reclama a Affinity Capital · US · Financial Servicesransomkairos reclama a Warwick Fabrics · NZ · Manufacturingransomgunra reclama a Siam Stabilizers and Chemicals Co., Ltd. / SSC · TH · Manufacturingransomqilin reclama a Adpo · Otherransomqilin reclama a servitelco · CL · Technologyransomqilin reclama a Orimar · BE · Other
← Todos los CVEs
CVE Watch30 jul 2026

CVE-2026-16970

The IRIS web application in version 2.4.26 and possibly others contains a logout functionality which is ineffective. Stolen session cookies

CVSS

4.2

Medio

EPSS

KEV

Exploit Today

0

0-100

Publicado: 30 jul 2026 · Última mod.: 30 jul 2026 · CWE-613

EPSS · 30d

Sin historial EPSS suficiente todavía.

Descripción técnica

The IRIS web application in version 2.4.26 and possibly others contains a logout functionality which is ineffective. Stolen session cookies can therefore be misused for a long time.

Referencias oficiales
CVEs relacionados
CVECVSSEPSSKEVRExplotTítuloVis.
CVE-2026-664004.8 MED
0Grav Login Plugin versions before 3.8.13 contain an insufficient session expiration vulnerability in TokenStorage.php where the findTriplet() method fails to properly validate Remember Me token timestamps. Attackers with a captured Remember Me cookie can authenticate indefinitely instead of the configured timeout period, as the expiry check compares an array to a scalar value which always evaluates incorrectly in PHP.23h
CVE-2026-149968.2 ALT
13.3%
4IBM Aspera Faspex 5 5.0.0 through 5.0.15.4 has addressed a vulnerability related to session management.1d
CVE-2026-159677.5 ALT
8.0%
2Insufficient session expiration vulnerability in Progress MOVEit Transfer. This issue affects MOVEit Transfer: before 2025.1.5, from 2026.0.0 before 2026.0.3.2d
CVE-2026-648297.4 ALT
18.8%
6Question2Answer through 1.8.8 contains a session invalidation vulnerability that allows attackers with a previously obtained remember-me cookie to retain authenticated access by exploiting the forgot-password reset flow's failure to clear the sessioncode field in qa-include/app/users-edit.php. While the normal password-change flow in qa-include/pages/account.php explicitly clears the sessioncode to invalidate persistent qa_session cookies, the forgot-password handler qa_finish_reset_user() omits this step, allowing any valid persistent cookie issued before the reset to continue authenticating the account after the password reset completes.7d
CVE-2026-565833.1 BAJ
3.8%
1HCL MyCloud was affected with Concurrent Login Vulnerability. It may increase the risk of unauthorized access, session hijacking, and account misuse.8d
CVE-2026-637534.3 MED
10.6%
3SurrealDB before 3.1.0 fails to refresh authentication state in LIVE SELECT subscriptions when session state changes. Attackers can continue receiving real-time notifications under revoked or expired session credentials until the connection closes.7d