This TSUBAME Report Overflow series discuss monitoring trends of overseas TSUBAME sensors and other activities which the Internet Threat Monitoring Quarterly Reports do not include. This article covers the monitoring results for the period October to December 2025. Suspicious Packets...
Microsoft has disclosed a new security vulnerability impacting on-premise versions of Exchange Server that it said has come under active exploitation in the wild.
The vulnerability, tracked as CVE-2026-42897 (CVSS score: 8.1), has been described as a spoofing bug stemming from a cross-site scripting flaw. An anonymous researcher has been credited with discovering and reporting the issue.
"
A vulnerability was found in Fujitsu Musetheque. It has been classified as problematic. Affected by this issue is some unknown functionality. The manipulation leads to cross-site request forgery.
This vulnerability is referenced as CVE-2026-28761. Remote exploitation of the attack is possible. No exploit is available.
A vulnerability was found in mlflow up to 3.9.x and classified as critical. Affected by this vulnerability is the function _find_fastapi_validator of the component Job API. Executing a manipulation can lead to authentication bypass by primary weakness.
The identification of this vulnerability is CVE-2026-2652. The attack may be launched remotely. There is no exploit available.
It is suggested to upgrade the affected component.
A vulnerability has been found in Fujitsu Musetheque up to 2203.0 and classified as problematic. Affected is an unknown function. Performing a manipulation results in cross site scripting.
This vulnerability was named CVE-2026-24662. The attack may be initiated remotely. There is no available exploit.
A vulnerability, which was classified as critical, was found in Linux Kernel up to 6.12.87/6.18.29/7.0.6/7.1-rc2. This impacts the function smb_inherit_dacl of the component ksmbd. Such manipulation leads to buffer overflow.
This vulnerability is uniquely identified as CVE-2026-43490. The attack can only be initiated within the local network. No exploit exists.
You should upgrade the affected component.
A vulnerability, which was classified as critical, has been found in Rapid7 Metasploit Pro 5.0.0. This affects an unknown function of the file postgres.exe of the component metasploitPostgreSQL Service. This manipulation causes inclusion of functionality from untrusted control sphere.
This vulnerability is handled as CVE-2026-7373. It is possible to launch the attack on the local host. There is not any exploit available.
A vulnerability identified as problematic has been detected in AMD MI-25, Instinct MI250, Instinct MI210, Radeon PRO V520 and Radeon PRO V620. This affects an unknown part. This manipulation of the argument input causes improper handling of insufficient privileges.
This vulnerability is registered as CVE-2025-54511. Remote exploitation of the attack is possible. No exploit is available.
You should upgrade the affected component.