216.73.216.226

Threat intelligence dashboard

Today's CVEs, attack reports, and CISA KEV — CVSS, EPSS, and MITRE context at a glance.

Attack reports – last 7 days · through Tuesday 30 June 2026 (26)

Vulnerabilities today (6)

Sorted by CVSS severity (highest first)

8.1 High

The IPv6 Neighbor Discovery handlers in subsys/net/ip/ipv6_nbr.c (handle_ra_input, handle_ns_input, handle_na_input) used an incorrect boolean expression that combined the RFC 4861 validity checks …

Attack vector
ADJACENT_NETWORK
Complexity
LOW
Published
30/06/2026
7.7 High

Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.471, Coolify server and project lookups are …

Attack vector
NETWORK
Complexity
LOW
Published
30/06/2026
7.5 High

Zephyr's HTTP server (subsys/net/lib/http) provides a static-filesystem resource type (HTTP_RESOURCE_TYPE_STATIC_FS, available when CONFIG_FILE_SYSTEM is enabled) that serves files from a configured root …

Attack vector
NETWORK
Complexity
LOW
Published
30/06/2026
6.2 Medium

mcumgr_serial_process_frag() in subsys/mgmt/mcumgr/transport/src/serial_util.c calls net_buf_reset() on the result of smp_packet_alloc() before checking it for NULL. smp_packet_alloc() uses net_buf_alloc(K_NO_WAIT) against the shared MCUmgr …

Attack vector
LOCAL
Complexity
LOW
Published
30/06/2026
5.3 Medium

The USB CDC-NCM device class (subsys/usb/device_next/class/usbd_cdc_ncm.c) ignores the return value of usbd_ep_enqueue() in its ethernet transmit callback cdc_ncm_send(). When the enqueue fails, …

Attack vector
ADJACENT_NETWORK
Complexity
HIGH
Published
30/06/2026
4.8 Medium

Strapi users-permissions plugin fails to restrict JWT algorithms when plugin::users-permissions.jwt.algorithm is not explicitly configured, allowing acceptance of HS384 and HS512 tokens alongside …

Attack vector
NETWORK
Complexity
HIGH
Published
30/06/2026