Signal is active with 1 mentions in latest observed window
Immediate actions
Patch affected systems immediately
Recommended action window: Monitor and triage in normal cycle
NVD description
SiYuan versions before v3.7.4 fail to mask sensitive configuration fields in the /api/system/getConf endpoint, allowing anonymous or publish-reader users to obtain the session-cookie signing key, OS username via pandoc path, and encrypted-notebook key material. Attackers can forge and tamper with session cookies to impersonate users, and on instances without access-auth codes configured, escalate to administrator privileges.
🔴 SiYuan Note, Information Disclosure, #CVE-2026-72793 (Critical) -DC-Sep2026-2214
https://dailycve.com/siyuan-note-information-disclosure-cve-2026-72793-critical-dc-sep2026-2214/
Post summary
The message alerts that SiYuan Note has a critical information disclosure vulnerability (CVE‑2026‑72793) and provides a link to a daily CVE article, but no further technical or exploit details are given.
A leaked cookie signing key isn’t “just config exposure.” It can turn session trust into an attacker-controlled boundary. SiYuan users: patch CVE-2026-72793.
https://ekofyi.com/blog/siyuan-cve-2026-72793-cookie-signing-key-exposure
Post summary
The post announces the discovery of a cookie signing key exposure in SiYuan (CVE‑2026‑72793) and urges users to apply the available patch, linking to a detailed blog post for more information.
NewNormal Security turns the last 24 hours of CVEs into new detections, every day.
𝗗𝗮𝗶𝗹𝘆 𝗖𝗩𝗘 𝗥𝗲𝗽𝗼𝗿𝘁 — 13 Aug 2026
𝗔𝗹𝗿𝗲𝗮𝗱𝘆 𝗰𝗼𝘃𝗲𝗿𝗲𝗱 by NewScan:
🔑 Config endpoint that hands out its session-signing key — anyone who can reach the port mints a valid session and reads every notebook (SiYuan CVE-2026-72793, CVE-2026-72794)
𝗔𝗱𝗱𝗲𝗱 to NewScan 𝘁𝗼𝗱𝗮𝘆:
🖥️ Unauthenticated SCADA/HMI project read — an anonymous request pulls the plant's screens and the addresses of every device behind them (FUXA CVE-2026-47717)
⚡ Sandbox escape in an AI agent builder — code runs on the host holding every model key and DB credential the flows use, and two of them need no login (Flowise CVE-2026-73483, CVE-2026-73485)
Test your stack with NewScan — free, self-hosted:
https://newnormalsecurity.com/newscan?utm_source=x&utm_medium=social&utm_campaign=daily-cve
#infosec#AppSec#RCE#CSO#REDTEAM
Post summary
The daily CVE report introduces several new vulnerabilities with technical details, but does not provide PoC, exploit code, active exploitation evidence, or patch information.