PULSE
EN VIVO54señales / 24h
FEED
ransomsection9 reclama a ******.net.br · BR · Financial Servicesransomsection9 reclama a ******.com.br · BR · Otherransomsection9 reclama a ********.com.br · BR · Not Foundransomglobal secret group reclama a Prism Telecom · FI · Technologyransomglobal secret group reclama a Cipher Dynamics · IN · Technologyransomglobal secret group reclama a Stratos Network · AE · Technologyransomglobal secret group reclama a OmniLink AG · DE · Technologyransomglobal secret group reclama a Vertex Systems · US · Technologyransomglobal secret group reclama a Nexon Corp. · KR · Technologyransomglobal secret group reclama a Farmers Mutual Fire Insurance · US · Financial Servicesransomglobal secret group reclama a West Sixth Law · US · Professional Servicesransomglobal secret group reclama a Baker Business & Tax Solutions · US · Professional Servicesransomglobal secret group reclama a Carpets Direct · US · Retail & E-Commerceransomglobal secret group reclama a AnyWeather · US · Technologyransomsection9 reclama a ******.net.br · BR · Financial Servicesransomsection9 reclama a ******.com.br · BR · Otherransomsection9 reclama a ********.com.br · BR · Not Foundransomglobal secret group reclama a Prism Telecom · FI · Technologyransomglobal secret group reclama a Cipher Dynamics · IN · Technologyransomglobal secret group reclama a Stratos Network · AE · Technologyransomglobal secret group reclama a OmniLink AG · DE · Technologyransomglobal secret group reclama a Vertex Systems · US · Technologyransomglobal secret group reclama a Nexon Corp. · KR · Technologyransomglobal secret group reclama a Farmers Mutual Fire Insurance · US · Financial Servicesransomglobal secret group reclama a West Sixth Law · US · Professional Servicesransomglobal secret group reclama a Baker Business & Tax Solutions · US · Professional Servicesransomglobal secret group reclama a Carpets Direct · US · Retail & E-Commerceransomglobal secret group reclama a AnyWeather · US · Technology
← Todos los CVEs
CVE Watch24 jul 2026

CVE-2026-61892

Weintek cMT3092X HMI allows a non-privileged user to modify tokens to escalate privileges.

CVSS

8.8

Alto

EPSS

0.3%

p20

KEV

Exploit Today

6

0-100

Publicado: 24 jul 2026 · Última mod.: 24 jul 2026 · CWE-732

EPSS · 30d

Sin historial EPSS suficiente todavía.

Descripción técnica

Weintek cMT3092X HMI allows a non-privileged user to modify tokens to escalate privileges.

Referencias oficiales
CVEs relacionados
CVECVSSEPSSKEVRExplotTítuloVis.
CVE-2026-625196.3 MED
16.4%
5Vulnerability in the Oracle Succession planning product of Oracle E-Business Suite (component: Succession plan). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Succession planning. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Succession planning accessible data as well as unauthorized read access to a subset of Oracle Succession planning accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Succession planning. CVSS 3.1 Base Score 6.3 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L).3d
CVE-2026-611869.4 CRÍ
30.4%
9Vulnerability in the Oracle Agile Engineering Data Management product of Oracle Supply Chain (component: Install). The supported version that is affected is 6.2.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Agile Engineering Data Management. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Agile Engineering Data Management accessible data as well as unauthorized read access to a subset of Oracle Agile Engineering Data Management accessible data and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Agile Engineering Data Management. CVSS 3.1 Base Score 9.4 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:H).3d
CVE-2026-611559.1 CRÍ
36.8%
11Vulnerability in the Oracle Commerce Guided Search Platform Services product of Oracle Commerce (component: Forge). The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Commerce Guided Search Platform Services. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Commerce Guided Search Platform Services accessible data and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Commerce Guided Search Platform Services. CVSS 3.1 Base Score 9.1 (Confidentiality and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H).3d
CVE-2026-606597.1 ALT
2.5%
1Vulnerability in the Oracle Solaris product of Oracle Systems (component: Filesystems). The supported version that is affected is 11.4. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Solaris executes to compromise Oracle Solaris. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Solaris accessible data and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Solaris. CVSS 3.1 Base Score 7.1 (Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H).2d
CVE-2026-633587.3 ALT
1.6%
0FileGator accepts arbitrary Unix permission values via the '/chmoditems' API endpoint and passes the value directly to PHP's native 'chmod()' function through 'octdec()' conversion, with no validation. This allows an authenticated user with 'chmod' permission to upgrade their privileges to root.4d
CVE-2026-448787.2 ALT
33.8%
10A vulnerability in the web-based management interface of an ECOS device could allow a highly privileged, authenticated remote attacker to access the device's filesystem. Successful exploitation of this vulnerability could allow an attacker to access sensitive files and tamper with or delete system data.3d