Unchecked symbolic link targets in the Ouch archive extraction tool pose a risk of arbitrary file writes
An attacker can craft an archive containing malicious symbolic links and use links pointing outside the root directory to perform unauthorized writes when a user extracts it. Older versions lack strict validation that symbolic link targets remain within the extraction root and allow later entries to overwrite symbolic links created by earlier entries. This compromises file system integrity and may lead to configuration tampering or privilege escalation.
Component
Ouch is an efficient command-line archive tool written in Rust. Its core functions include creating and extracting mainstream archive formats such as tar and zip, with the aim of providing fast and secure local file management. By parsing archive metadata and reconstructing file structures, the component supports system-level data backup and software distribution.
Type
Improper Link Resolution Before File Access (CWE-59)
Upgrade to the latest stable version containing the security patch. Ensure that all symbolic link target paths undergo strict allowlist validation and root directory isolation checks during extraction, and prohibit unauthorized writes to external files to block these escape attacks.
CVE Intelligence
2
CVE-2026-106126
CVSS
9.9 Critical
2026-10-09
Command injection in Tenable Identity Exposure allows remote code execution with SYSTEM privileges
The Active Directory Events Listener component of Tenable Identity Exposure (SaaS) contains a command injection flaw caused by improper neutralization of special elements used in operating system commands (CWE-78). An authenticated attacker with low privileges can exploit the vulnerability to execute arbitrary commands with SYSTEM privileges on the PDCe (primary domain controller emulator). The attack can be launched over the network with low complexity and no user interaction. Successful exploitation severely affects confidentiality, integrity, and availability. All unpatched Tenable Identity Exposure deployments are affected. An attacker only needs a low-privilege account to trigger the vulnerability and obtain the highest system privileges.
Component
Tenable Identity Exposure is a SaaS-based identity security platform that monitors and analyzes identity-related events in Active Directory to help organizations detect anomalous behavior and potential threats.
Risks
Privilege escalation: An attacker can escalate directly from a low-privilege account to the highest SYSTEM privileges, completely bypassing access controls
Complete system control: An attacker can execute arbitrary commands on the PDCe, leading to data disclosure, tampering, or destruction, and potentially control of the entire domain environment
Remote exploitation: The attack takes place over the network without physical access or complex user interaction, making it easy to automate
Strictly restrict network access to Active Directory Events Listener and enforce the principle of least privilege
Monitor abnormal command execution on the PDCe and deploy an intrusion detection system to identify potential command injection attacks
CVE-2026-77900
CVSS
9.8 Critical
2026-10-09
Missing authentication for a critical function in Azure App Service allows remote code execution
Azure App Service contains a missing authentication for critical function flaw (CWE-306) because critical functions lack an authentication mechanism. An unauthorized attacker can execute code directly over the network, threatening the service's confidentiality, integrity, and availability. An authentication bypass vulnerability exists in Azure App Service under certain function invocation scenarios. An attacker can trigger it without any credentials, leading to remote code execution or data disclosure. All unpatched Azure App Service instances are affected, including cloud deployments. An attacker only needs to send a crafted request over the network to exploit the vulnerability, with no user interaction required, and can gain remote control.
Component
Azure App Service is a fully managed Web application hosting service provided by Microsoft's Azure cloud platform. It supports multiple programming languages and frameworks for building and hosting Web applications, mobile backends, and REST APIs.
Risks
Complete system control: An attacker can exploit the vulnerability to execute arbitrary code on an affected Azure App Service instance and gain control of the server
Data disclosure and tampering: With high impacts on confidentiality, integrity, and availability, an attacker can read, modify, or delete sensitive data
Unauthenticated remote attack: An attacker needs no authentication credentials and only requires network access to launch an attack, with low exploitation difficulty
Immediately review and update Azure App Service configuration to ensure that strong authentication is enabled for critical functions
Monitor network traffic and block abnormal requests from unknown sources
Enforce the principle of least privilege and limit the service's exposed attack surface
Package Poisoning
7
Package Poisoning
npm2026-10-09
@dransay/logger@99.0.0
flagged as malicious
The component was found to communicate with a domain associated with malicious activity and execute one or more commands associated with malicious behavior.
MD5
3131a04093e8dd025efc4d39dd8ed235
Package Poisoning
npm2026-10-09
@dransay/phone-fix-test@99.0.0
flagged as malicious
The component was found to communicate with a domain associated with malicious activity and execute one or more commands associated with malicious behavior.
MD5
a881fd667c43fdd6bcd1b29c22977d9d
Package Poisoning
npm2026-10-09
@dransay/secrets@99.0.0
flagged as malicious
The component was found to communicate with a domain associated with malicious activity and execute one or more commands associated with malicious behavior.
MD5
1aaa2a214bdc592973491a0ff3352ad2
Package Poisoning
npm2026-10-09
dransay@99.0.0
flagged as malicious
The component was found to communicate with a domain associated with malicious activity and execute one or more commands associated with malicious behavior.
MD5
0277db6c1b1659d22ac67625744a6a6a
Package Poisoning
npm2026-10-09
@kxafunc/xbails@0.0.8
flagged as malicious
Through package.json, the component aliases the libsignal dependency to a mutable latest version from a nonstandard publisher. The lack of version pinning and integrity checks allows an attacker to execute arbitrary code in the Signal end-to-end encryption path and access identity keys, prekeys, and plaintext messages.
MD5
508b193b3530fa3444d807e88a9ee55f
Package Poisoning
PyPI2026-10-09
kafka-helmsman@99.0.1
flagged as malicious
The component was found to communicate with a domain associated with malicious activity and execute one or more commands associated with malicious behavior.
MD5
95fd10a2179b8c31d0de2cbd8913de78
Package Poisoning
PyPI2026-10-09
kafka-roller@99.0.3
flagged as malicious
The component was found to communicate with a domain associated with malicious activity and execute one or more commands associated with malicious behavior.