๐ต๏ธ RESEARCH & DEEP DIVES
-
SiYuan before v3.7.4 affected by 11 authentication, XSS and RCE flaws
CVE-2026-73041CVE-2026-73042CVE-2026-73043CVE-2026-73044CVE-2026-73045CVE-2026-73046CVE-2026-73047CVE-2026-73050CVE-2026-73052CVE-2026-73053CVE-2026-73054SiYuan versions before 3.7.4 contain 11 vulnerabilities.- SiYuan users running versions before 3.7.4 are affected; version 3.7.4 is not affected.
- The flaws include authentication bypasses, brute-force weaknesses, information exposure, stored XSS, server-side template injection and remote code execution.
- Affected features include WebSocket access, HTTP Basic Auth, published files, attribute views, document icons, menu metadata, PDF annotations and template calculations.
- Attackers can use duplicated WebSocket query parameters, crafted HTML or hex-encoded markup, malicious database values and Go templates to trigger unauthorized access or code execution.
- CVE-2026-73041 through CVE-2026-73047, CVE-2026-73050 and CVE-2026-73052 through CVE-2026-73054 are associated with the release. ๐ Source: github.com ยท ๐ Coverage: thehackerwire.com ยท ๐ via CVE ThreatInt, thehackerwire.com (discovered) (+11)
-
Evooo1Bot Mirai Variant Targets Internet-Facing Edge Devices FortiGuard Labs identified Evooo1Bot, a Mirai-derived Linux botnet targeting internet-facing edge devices.
- Linux routers and edge devices from Alcatel, D-Link, Mitsubishi Electric, Netgear, Tenda and Telesquare are targeted.
- Exploited flaws include CVE-2007-3010, CVE-2016-6277, CVE-2018-14558, CVE-2019-14931 and CVE-2020-10987.
- Additional targets include CVE-2021-46422, CVE-2022-37055, CVE-2024-29269, CVE-2025-10123 and CVE-2025-55583.
- Payloads use 91.92.40[.]118/wget.sh to install architecture-specific binaries.
- The botnet adds encrypted C2, SSH brute-force scanning, credential sniffing, honeypot evasion and SOCKS relay capabilities. ๐ Coverage: securityboulevard.com ยท ๐ via securityboulevard.com (discovered)
๐ CVEs & KEV
- CVE-2026-74764 โ CVSS 10.0 โ Path Traversal in TAR Archive Extraction Allows Arbitrary File Write in Pando...
- CVE-2026-73053 โ CVSS 9.4 โ SiYuan before v3.7.4 Cross-Site Scripting via unicode2EmojiSiYuan versions be...
- CVE-2026-73052 โ CVSS 9.4 โ SiYuan before v3.7.4 Stored XSS via Attribute-View Field NamesSiYuan before v...
- CVE-2026-73050 โ CVSS 9.4 โ SiYuan before v3.7.4 Stored XSS via select option colorSiYuan versions before...
- CVE-2026-73044 โ CVSS 9.4 โ SiYuan before v3.7.4 Stored Cross-Site Scripting via Column WidthSiYuan versi...
- [CVE-2026-73043](https://cve.threatint.com