Aug 14, 2026
Vendor advisory
High-risk advisory
CVE-2026-53653
Composer · getgrav/grav
Grav: Unauthenticated denial of service via unbounded image derivative dimensions
Operator check
Check whether getgrav/grav is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. CVSS score: 8.7. EPSS probability: 0.3%; percentile: 23%.
Read brief →
Aug 14, 2026
Vendor advisory
High-risk advisory
CVE-2026-35511
Go · github.com/authorizerdev/authorizer
Authorizer: Zero-click account takeover via OAuth identity linking to unverified email accounts
Operator check
Check whether github.com/authorizerdev/authorizer is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. CVSS score: 8.7.
Read brief →
Aug 14, 2026
Vendor advisory
High-risk advisory
CVE-2026-53657
Go · github.com/lima-vm/lima/v2
Lima: An arbitrary user in a QEMU VM could gain the root privilege in the VM via the guest agent socket
Operator check
Check whether github.com/lima-vm/lima/v2 is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. EPSS probability: 0.1%; percentile: 3%.
Read brief →
Aug 14, 2026
Vendor advisory
High-risk advisory
CVE-2026-53660
Maven · org.openidentityplatform.openam:openam-core
OpenAM Insecure SSO Cookie Initialization
Operator check
Check whether org.openidentityplatform.openam:openam-core is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. CVSS score: 7.0.
Read brief →
Aug 14, 2026
Vendor advisory
High-risk advisory
CVE-2026-55153
Maven · com.mchange:mchange-commons-java
mchange-commons-java contains elements susceptible to abuse via JNDI injection and "deserialization gadgets"
Operator check
Check whether com.mchange:mchange-commons-java is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. EPSS probability: 0.3%; percentile: 26%.
Read brief →
Aug 14, 2026
Vendor advisory
Critical vendor advisory
CVE-2026-73678
MindsDB · Minds Platform version 26.1.0 and earlier
MindsDB Minds Platform version 26.1.0 and earlier contains an unauthenticated remote code execution vulnerability that allows unauthenticated attackers to execute arbitrary OS commands by submitting crafted prompts to the unprotected POST /api/v1/responses/ endpoint, which reaches the Anton agent's scratchpad tool that calls exec() on attacker-influenced Python source without sandboxing. Attackers can first configure their own LLM API key through the unauthenticated PUT /api/v1/settings/ endpoint, then POST a prompt directing the agent to invoke the scratchpad tool with arbitrary Python code,
Operator check
Review CVE-2026-73678 in your asset inventory. Apply patches per vendor guidance and verify Minds Platform version 26.1.0 and earlier is not exposed. CVSS score: 10.0.
Read brief →
Aug 14, 2026
Vendor advisory
High-risk advisory
CVE-2026-35219
npm · @budibase/server
Budibase: SSRF in Automation Steps - Webhook, Zapier, N8N, Slack, Discord Bypass IP Blacklist
Operator check
Check whether @budibase/server is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. CVSS score: 7.1.
Read brief →
Aug 14, 2026
Vendor advisory
High-risk advisory
CVE-2026-55157
npm · @ooples/token-optimizer-mcp
Token Optimizer MCP: OS command injection in smart_user via username in get-user-info
Operator check
Check whether @ooples/token-optimizer-mcp is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.
Read brief →
Aug 13, 2026
Vendor advisory
High-risk advisory
CVE-2026-55072
Composer · pimcore/pimcore
Pimcore: ClassDefinition UID regex missing end anchor allows SQL injection via Block.php unquoted table name
Operator check
Check whether pimcore/pimcore is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.
Read brief →
Aug 13, 2026
Vendor advisory
Critical vendor advisory
CVE-2026-73532
Fluent · Forms Pro 6.2.7
Fluent Forms Pro 6.2.7 contains an embedded malicious code vulnerability introduced via a tampered plugin build served through a decommissioned update server. The tampered build introduced a rogue PHP file (libs/class-license-sync.php), loaded via a require_once directive added to fluentformpro.php, that established a backdoor REST API endpoint, dropped persistent PHP files in mu-plugins and uploads directories, installed a passwordless administrator account, and registered scheduled tasks that survived plugin removal.
Operator check
Review CVE-2026-73532 in your asset inventory. Apply patches per vendor guidance and verify Forms Pro 6.2.7 is not exposed. CVSS score: 9.8.
Read brief →
Aug 13, 2026
Vendor advisory
High-risk advisory
CVE-2026-54526
Go · github.com/argoproj/argo-workflows/v4
Argo Workflows: ArtifactGC.PodSpecPatch bypasses Strict/Secure template reference allow-list (Incomplete fix for CVE-2026-31892)
Operator check
Check whether github.com/argoproj/argo-workflows/v4 is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. CVSS score: 8.9. EPSS probability: 0.4%; percentile: 29%.
Read brief →
Aug 13, 2026
Vendor advisory
Critical vendor advisory
CVE-2026-73533
Ninja · Tables Pro 5.2.11
Ninja Tables Pro 5.2.11 contains an embedded malicious code vulnerability introduced via a tampered plugin build served through a decommissioned update server. The tampered build introduced a rogue PHP file (app/Library/updater/NinjaTableDataSync.php) that established a backdoor REST API endpoint, dropped persistent PHP files in mu-plugins and uploads directories, installed a passwordless administrator account, and registered scheduled tasks that survived plugin removal.
Operator check
Review CVE-2026-73533 in your asset inventory. Apply patches per vendor guidance and verify Tables Pro 5.2.11 is not exposed. CVSS score: 9.8.
Read brief →
Aug 13, 2026
Vendor advisory
High-risk advisory
CVE-2026-73654
npm · @trigger.dev/core
Trigger.dev: Prototype pollution via run metadata operations → process-wide cross-tenant DoS
Operator check
Check whether @trigger.dev/core is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.
Read brief →
Aug 13, 2026
Vendor advisory
High-risk advisory
CVE-2026-12243
PyPI · nltk
nltk: Arbitrary File Read via Path Traversal in nltk.data.load() through Percent-Encoded Sequences
Operator check
Check whether nltk is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. EPSS probability: 0.6%; percentile: 45%.
Read brief →
Aug 13, 2026
Vendor advisory
High-risk advisory
PyPI · atomic-agents-stack
atomic-agents-stack: Dashboard HTTP server path traversal allows arbitrary file read
Operator check
Check whether atomic-agents-stack is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. CVSS score: 8.2.
Read brief →
Aug 12, 2026
Vendor advisory
High-risk advisory
CVE-2026-32257
Composer · winter/wn-backend-module
Winter: Stored XSS through Brand Settings custom styles
Operator check
Check whether winter/wn-backend-module is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.
Read brief →
Aug 12, 2026
Vendor advisory
High-risk advisory
CVE-2026-32258
Composer · winter/wn-backend-module
Winter: Stored XSS through Editor Settings custom styles
Operator check
Check whether winter/wn-backend-module is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.
Read brief →
Aug 12, 2026
Vendor advisory
High-risk advisory
CVE-2026-35445
Composer · winter/wn-backend-module
Winter: Authenticated backend users can bypass Users controller permission checks
Operator check
Check whether winter/wn-backend-module is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. CVSS score: 7.1.
Read brief →
Aug 12, 2026
Vendor advisory
High-risk advisory
CVE-2026-54917
Go · github.com/seaweedfs/seaweedfs
SeaweedFS: Path traversal in the S3 and Iceberg REST gateways allows cross-bucket access
Operator check
Check whether github.com/seaweedfs/seaweedfs is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. CVSS score: 7.8. EPSS probability: 0.4%; percentile: 31%.
Read brief →
Aug 12, 2026
Vendor advisory
Critical vendor advisory
CVE-2026-16860
Ibm · I
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to execute arbitrary code due to an uncontrolled search path element.
Operator check
Review CVE-2026-16860 in your asset inventory. Apply patches per vendor guidance and verify I is not exposed. CVSS score: 9.9. EPSS probability: 0.5%; percentile: 38%.
Read brief →
Aug 12, 2026
Vendor advisory
Critical vendor advisory
CVE-2026-17276
Ibm · I
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to escalate privileges due to improper authorization in the handling of high-authority threads.
Operator check
Review CVE-2026-17276 in your asset inventory. Apply patches per vendor guidance and verify I is not exposed. CVSS score: 9.6. EPSS probability: 0.2%; percentile: 16%.
Read brief →
Aug 12, 2026
Vendor advisory
High-risk advisory
CVE-2026-48798
NuGet · SSH.NET
SSH.NET: ScpClient Recursive Download Allows Arbitrary File Write via Server-Controlled SCP Filenames
Operator check
Check whether SSH.NET is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.
Read brief →
Aug 12, 2026
Vendor advisory
High-risk advisory
NuGet · SIPSorcery
SIPSorcery vulnerable to Denial of Service via out-of-bounds read in SCTP SACK chunk parsing
Operator check
Check whether SIPSorcery is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.
Read brief →
Aug 12, 2026
Vendor advisory
High-risk advisory
NuGet · SIPSorcery
SIPSorcery: Malformed UDP datagram crashes TurnServer receive loop with no restart, disabling TURN UDP relay for all clients (DoS)
Operator check
Check whether SIPSorcery is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.
Read brief →
Aug 12, 2026
Vendor advisory
High-risk advisory
CVE-2026-52776
PyPI · compliance-trestle
compliance-trestle has an URLSecurityValidator SSRF allowlist bypass via IPv4-mapped IPv6 and 0.0.0.0
Operator check
Check whether compliance-trestle is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. CVSS score: 8.6.
Read brief →
Aug 12, 2026
Vendor advisory
High-risk advisory
CVE-2026-55071
PyPI · stata-mcp
MCP-for-Stata: Stata Command Injection via Unsanitized `package` in `ado_package_install`
Operator check
Check whether stata-mcp is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.
Read brief →
Aug 12, 2026
Vendor advisory
High-risk advisory
CVE-2026-55074
PyPI · ansible-jailexec
Ansible FreeBSD Jail Connection Plugin: Jail escape via symlink following in put_file (host-side root mv)
Operator check
Check whether ansible-jailexec is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. CVSS score: 7.3.
Read brief →
Aug 12, 2026
Vendor advisory
High-risk advisory
CVE-2026-46369
Rust · nimiq-blockchain
nimiq-blockchain: Validity store off by one error
Operator check
Check whether nimiq-blockchain is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.
Read brief →
Aug 11, 2026
KEV
Known exploited
CVE-2026-20349
Cisco · Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD)
Cisco Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD) contain a heap inspection vulnerability that could allow an unauthenticated, remote attacker to cause the device to reload unexpectedly, resulting in a denial of service (DoS) condition.
Operator check
Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
Read brief →
Aug 11, 2026
Vendor advisory
High-risk advisory
CVE-2026-73080
Go · github.com/seaweedfs/seaweedfs
SeaweedFS: Unauthenticated SSRF with response read-back via VolumeServer.FetchAndWriteNeedle
Operator check
Check whether github.com/seaweedfs/seaweedfs is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.
Read brief →
Aug 11, 2026
KEV
Known exploited
CVE-2026-72898
Metabase · Metabase
Metabase contains a SQL Injection vulnerability that allows an unauthenticated remote attacker to inject arbitrary SQL into the Metabase application database, which can give them administrator access to the instance. From there, the attacker could change the application configuration, steal stored credentials for the connected databases, read any data accessible through those connections, and export data.
Operator check
Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
Read brief →
Aug 11, 2026
Patch Tuesday
High-risk advisory
CVE-2026-49179
Microsoft · Windows Active Directory
Improper neutralization of special elements used in a command ('command injection') in Windows Active Directory allows an unauthorized attacker to execute code over a network. Published in August 2026 Security Updates. MSRC exploitability: Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation Unlikely.
Operator check
Review the Microsoft Security Update Guide entry for CVE-2026-49179. Confirm whether Windows Active Directory is deployed, then apply the current security update or documented mitigation. CVSS score: 8.8.
Read brief →
Aug 11, 2026
Patch Tuesday
High-risk advisory
CVE-2026-58650
Microsoft · Visual Studio Code
Authorization bypass through user-controlled key in Visual Studio Code allows an unauthorized attacker to bypass a security feature locally. Published in August 2026 Security Updates. MSRC exploitability: Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation More Likely.
Operator check
Review the Microsoft Security Update Guide entry for CVE-2026-58650. Confirm whether Visual Studio Code is deployed, then apply the current security update or documented mitigation. CVSS score: 7.8.
Read brief →
Aug 11, 2026
Patch Tuesday
High-risk advisory
CVE-2026-59113
Microsoft · Visual Studio Code
Missing authorization in Visual Studio Code allows an unauthorized attacker to execute code over a network. Published in August 2026 Security Updates. MSRC exploitability: Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation Less Likely.
Operator check
Review the Microsoft Security Update Guide entry for CVE-2026-59113. Confirm whether Visual Studio Code is deployed, then apply the current security update or documented mitigation. CVSS score: 8.8.
Read brief →
Aug 11, 2026
Patch Tuesday
Critical vendor advisory
CVE-2026-59124
Microsoft · Microsoft High Performance Computing (HPC) Pack
Deserialization of untrusted data in Microsoft High Performance Computing (HPC) Pack allows an unauthorized attacker to execute code over a network. Published in August 2026 Security Updates. MSRC exploitability: Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation More Likely.
Operator check
Review the Microsoft Security Update Guide entry for CVE-2026-59124. Confirm whether Microsoft High Performance Computing (HPC) Pack is deployed, then apply the current security update or documented mitigation. CVSS score: 9.8.
Read brief →
Aug 11, 2026
Patch Tuesday
High-risk advisory
CVE-2026-59132
Microsoft · Windows TCP/IP
Null pointer dereference in Windows TCP/IP allows an unauthorized attacker to deny service over a network. Published in August 2026 Security Updates. MSRC exploitability: Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation More Likely.
Operator check
Review the Microsoft Security Update Guide entry for CVE-2026-59132. Confirm whether Windows TCP/IP is deployed, then apply the current security update or documented mitigation. CVSS score: 7.5.
Read brief →
Aug 11, 2026
Patch Tuesday
High-risk advisory
CVE-2026-59133
Microsoft · Microsoft High Performance Computing (HPC) Pack
Execution with unnecessary privileges in Microsoft High Performance Computing (HPC) Pack allows an authorized attacker to elevate privileges over a network. Published in August 2026 Security Updates. MSRC exploitability: Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation More Likely.
Operator check
Review the Microsoft Security Update Guide entry for CVE-2026-59133. Confirm whether Microsoft High Performance Computing (HPC) Pack is deployed, then apply the current security update or documented mitigation. CVSS score: 8.8.
Read brief →
Aug 11, 2026
Patch Tuesday
High-risk advisory
CVE-2026-61348
Microsoft · Windows Ancillary Function Driver for WinSock
Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally. Published in August 2026 Security Updates. MSRC exploitability: Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation More Likely.
Operator check
Review the Microsoft Security Update Guide entry for CVE-2026-61348. Confirm whether Windows Ancillary Function Driver for WinSock is deployed, then apply the current security update or documented mitigation. CVSS score: 7.0.
Read brief →
Aug 11, 2026
Patch Tuesday
High-risk advisory
CVE-2026-61925
Microsoft · Windows Installer
Incorrect authorization in Windows Installer allows an authorized attacker to elevate privileges locally. Published in August 2026 Security Updates. MSRC exploitability: Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation More Likely.
Operator check
Review the Microsoft Security Update Guide entry for CVE-2026-61925. Confirm whether Windows Installer is deployed, then apply the current security update or documented mitigation. CVSS score: 7.8.
Read brief →
Aug 11, 2026
Patch Tuesday
High-risk advisory
CVE-2026-61930
Microsoft · Windows Kernel
Heap-based buffer overflow in Windows Kernel allows an authorized attacker to elevate privileges locally. Published in August 2026 Security Updates. MSRC exploitability: Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation More Likely.
Operator check
Review the Microsoft Security Update Guide entry for CVE-2026-61930. Confirm whether Windows Kernel is deployed, then apply the current security update or documented mitigation. CVSS score: 7.8.
Read brief →
Aug 11, 2026
Patch Tuesday
High-risk advisory
CVE-2026-62688
Microsoft · Windows MIDI Service Module
Heap-based buffer overflow in Windows MIDI Service Module allows an authorized attacker to elevate privileges locally. Published in August 2026 Security Updates. MSRC exploitability: Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation More Likely.
Operator check
Review the Microsoft Security Update Guide entry for CVE-2026-62688. Confirm whether Windows MIDI Service Module is deployed, then apply the current security update or documented mitigation. CVSS score: 7.8.
Read brief →
Aug 11, 2026
Patch Tuesday
High-risk advisory
CVE-2026-62696
Microsoft · Windows Program Compatibility Assistant Service
Integer underflow (wrap or wraparound) in Windows Program Compatibility Assistant Service allows an authorized attacker to elevate privileges locally. Published in August 2026 Security Updates. MSRC exploitability: Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation More Likely.
Operator check
Review the Microsoft Security Update Guide entry for CVE-2026-62696. Confirm whether Windows Program Compatibility Assistant Service is deployed, then apply the current security update or documented mitigation. CVSS score: 7.8.
Read brief →
Aug 11, 2026
Patch Tuesday
High-risk advisory
CVE-2026-62712
Microsoft · Windows Win32K
Heap-based buffer overflow in Windows Win32K allows an authorized attacker to elevate privileges locally. Published in August 2026 Security Updates. MSRC exploitability: Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation More Likely.
Operator check
Review the Microsoft Security Update Guide entry for CVE-2026-62712. Confirm whether Windows Win32K is deployed, then apply the current security update or documented mitigation. CVSS score: 7.8. EPSS probability: 0.4%; percentile: 32%.
Read brief →
Aug 11, 2026
Patch Tuesday
High-risk advisory
CVE-2026-62713
Microsoft · Windows Cloud Files Mini Filter Driver
Heap-based buffer overflow in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges locally. Published in August 2026 Security Updates. MSRC exploitability: Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation More Likely.
Operator check
Review the Microsoft Security Update Guide entry for CVE-2026-62713. Confirm whether Windows Cloud Files Mini Filter Driver is deployed, then apply the current security update or documented mitigation. CVSS score: 7.8.
Read brief →
Aug 11, 2026
Patch Tuesday
High-risk advisory
CVE-2026-62827
Microsoft · Microsoft Office SharePoint
Improper authentication in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a network. Published in August 2026 Security Updates. MSRC exploitability: Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation Less Likely.
Operator check
Review the Microsoft Security Update Guide entry for CVE-2026-62827. Confirm whether Microsoft Office SharePoint is deployed, then apply the current security update or documented mitigation. CVSS score: 8.8.
Read brief →
Aug 11, 2026
Patch Tuesday
Critical vendor advisory
CVE-2026-62873
Microsoft · Microsoft 365 Admin Center
Improper verification of cryptographic signature in Microsoft 365 Admin Center allows an unauthorized attacker to elevate privileges over a network. Published in August 2026 Security Updates. MSRC exploitability: Publicly Disclosed:No;Exploited:No;Latest Software Release:N/A.
Operator check
Review the Microsoft Security Update Guide entry for CVE-2026-62873. Confirm whether Microsoft 365 Admin Center is deployed, then apply the current security update or documented mitigation. CVSS score: 9.8. EPSS probability: 0.3%; percentile: 27%.
Read brief →
Aug 11, 2026
Patch Tuesday
Critical vendor advisory
CVE-2026-63508
Microsoft · Microsoft Planetary Computer Pro
Missing authentication for critical function in Microsoft Planetary Computer Pro allows an unauthorized attacker to elevate privileges over a network. Published in August 2026 Security Updates. MSRC exploitability: Publicly Disclosed:No;Exploited:No;Latest Software Release:N/A.
Operator check
Review the Microsoft Security Update Guide entry for CVE-2026-63508. Confirm whether Microsoft Planetary Computer Pro is deployed, then apply the current security update or documented mitigation. CVSS score: 10.0. EPSS probability: 0.4%; percentile: 36%.
Read brief →
Aug 11, 2026
Patch Tuesday
High-risk advisory
CVE-2026-63514
Microsoft · Microsoft Office SharePoint
Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. Published in August 2026 Security Updates. MSRC exploitability: Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation Less Likely.
Operator check
Review the Microsoft Security Update Guide entry for CVE-2026-63514. Confirm whether Microsoft Office SharePoint is deployed, then apply the current security update or documented mitigation. CVSS score: 8.8.
Read brief →
Aug 11, 2026
Patch Tuesday
High-risk advisory
CVE-2026-63520
Microsoft · Microsoft Office SharePoint
Improper input validation in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network. Published in August 2026 Security Updates. MSRC exploitability: Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation More Likely.
Operator check
Review the Microsoft Security Update Guide entry for CVE-2026-63520. Confirm whether Microsoft Office SharePoint is deployed, then apply the current security update or documented mitigation. CVSS score: 8.1.
Read brief →
Aug 11, 2026
Patch Tuesday
High-risk advisory
CVE-2026-65768
Microsoft · Microsoft Teams for Android
Improper limitation of a pathname to a restricted directory ('path traversal') in Microsoft Teams for Android allows an unauthorized attacker to execute code over a network. Published in August 2026 Security Updates. MSRC exploitability: Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation Less Likely.
Operator check
Review the Microsoft Security Update Guide entry for CVE-2026-65768. Confirm whether Microsoft Teams for Android is deployed, then apply the current security update or documented mitigation. CVSS score: 8.8.
Read brief →
Aug 11, 2026
KEV
Known exploited
CVE-2026-68820
Microsoft · Windows Ancillary Function Driver for WinSock
Microsoft Windows Ancillary Function Driver for WinSock contains a use-after-free vulnerability that allows an authorized attacker to elevate privileges locally.
Operator check
Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
Read brief →
Aug 11, 2026
Vendor advisory
High-risk advisory
CVE-2026-62871
NuGet · Microsoft.WindowsDesktop.App.Runtime.win-arm64
Microsoft Security Advisory CVE-2026-62871 – .NET Elevation of Privilege Vulnerability
Operator check
Check whether Microsoft.WindowsDesktop.App.Runtime.win-arm64 is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.
Read brief →
Aug 11, 2026
Vendor advisory
High-risk advisory
CVE-2026-62886
NuGet · Microsoft.WindowsDesktop.App.Runtime.win-arm64
Microsoft Security Advisory CVE-2026-62886 – .NET Elevation of Privilege Vulnerability
Operator check
Check whether Microsoft.WindowsDesktop.App.Runtime.win-arm64 is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.
Read brief →
Aug 11, 2026
Vendor advisory
High-risk advisory
CVE-2026-62897
NuGet · Microsoft.WindowsDesktop.App.Runtime.win-arm64
Microsoft Security Advisory CVE-2026-62897 – .NET Remote Code Execution Vulnerability
Operator check
Check whether Microsoft.WindowsDesktop.App.Runtime.win-arm64 is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.
Read brief →
Aug 11, 2026
Vendor advisory
High-risk advisory
CVE-2026-62898
NuGet · Microsoft.NETCore.App.Runtime.win-arm64
Microsoft Security Advisory CVE-2026-62898 – .NET Information Disclosure Vulnerability
Operator check
Check whether Microsoft.NETCore.App.Runtime.win-arm64 is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.
Read brief →
Aug 11, 2026
Vendor advisory
High-risk advisory
CVE-2026-62901
NuGet · Microsoft.NETCore.App.Runtime.win-arm64
Microsoft Security Advisory CVE-2026-62901 – .NET Denial of Service Vulnerability
Operator check
Check whether Microsoft.NETCore.App.Runtime.win-arm64 is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.
Read brief →
Aug 11, 2026
Vendor advisory
High-risk advisory
CVE-2026-70354
NuGet · Microsoft.WindowsDesktop.App.Runtime.win-arm64
Microsoft Security Advisory CVE-2026-70354 – .NET Core Remote Code Execution Vulnerability
Operator check
Check whether Microsoft.WindowsDesktop.App.Runtime.win-arm64 is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.
Read brief →
Aug 11, 2026
Coordinated disclosure
Patch review
TCG · TPM 2.0 reference code
Overview Two vulnerabilities have been identified in the Trusted Platform Module (TPM) 2.0 reference implementation: CVE-2026-6726 – Information leakage via falsified TPM keys. CVE-2026-6727 – A timing side-channel vulnerability in RSA OAEP decryption. An attacker with privileged access to a TPM command interface may be able to exploit these vulnerabilities by sending specially crafted TPM commands. Successful exploitation could allow the attacker to decrypt ciphertexts encrypted to affected TPM-managed RSA keys, including the RSA Endorsement Key (EK), or obtain credentials for falsified TPM keys, enabling forged TPM 2.0 attestations. These vulnerabilities are also documented by the Trusted Computing Group (TCG) in advisories - TCGVRT010 and TCGVRT0011 : Description Trusted Platform Module (TPM) technology provides hardware-backed... Related CVEs: CVE-2026-6726, CVE-2026-6727.
Operator check
Review the CERT/CC Vulnerability Note and compare the affected vendor and product list against your inventory. Apply vendor fixes or compensating controls for TPM 2.0 reference code where available.
Read brief →
Aug 10, 2026
Coordinated disclosure
Patch review
Opencart · ecommerce platform
Overview The OpenCart v4.2.0.0 extension installer contains a directory traversal vulnerability. The extension installation process extracts uploaded .zip files then uses the zip entry filenames as filesystem paths, without validating that the resolved path stays inside the intended directory. This vulnerability is tracked as CVE-2026-18412. Description OpenCart is a free, open‑source e‑commerce solution designed to help businesses build and manage online stores. OpenCart extensions are uploaded as zip files with .ocmod.zip extensions. Upon installation, the OpenCart v4.2.0.0 extension installer extracts these zip files, but does not validate that the extracted paths stay inside the intended extraction directory. An attacker can craft a malicious extension containing file path traversal sequences, such as ../ . With this vulnerability... Related CVEs: CVE-2026-18412.
Operator check
Review the CERT/CC Vulnerability Note and compare the affected vendor and product list against your inventory. Apply vendor fixes or compensating controls for ecommerce platform where available.
Read brief →
Aug 9, 2026
Vendor advisory
Critical vendor advisory
CVE-2026-71984
MSI · Radix AXE6600 router firmware version v781521
MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the urlfilter function that allows remote attackers to execute arbitrary commands on the affected device. Attackers can exploit the urlfilter function to inject malicious commands and obtain root privileges on the underlying system.
Operator check
Review CVE-2026-71984 in your asset inventory. Apply patches per vendor guidance and verify Radix AXE6600 router firmware version v781521 is not exposed. CVSS score: 9.8.
Read brief →
Aug 9, 2026
Vendor advisory
Critical vendor advisory
CVE-2026-71985
MSI · Radix AXE6600 router firmware version v781521
MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the accesscontrol function that allows remote attackers to execute arbitrary commands on the affected device. Attackers can exploit this vulnerability through the accesscontrol function to execute malicious commands and obtain root privileges on the underlying system.
Operator check
Review CVE-2026-71985 in your asset inventory. Apply patches per vendor guidance and verify Radix AXE6600 router firmware version v781521 is not exposed. CVSS score: 9.8.
Read brief →
Aug 9, 2026
Vendor advisory
Critical vendor advisory
CVE-2026-71986
MSI · Radix AXE6600 router firmware version v781521
MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the dmz function that allows remote attackers to execute arbitrary commands on the affected device. Attackers can exploit this vulnerability through the dmz function to execute malicious commands and obtain root privileges on the underlying system.
Operator check
Review CVE-2026-71986 in your asset inventory. Apply patches per vendor guidance and verify Radix AXE6600 router firmware version v781521 is not exposed. CVSS score: 9.8.
Read brief →
Aug 9, 2026
Vendor advisory
Critical vendor advisory
CVE-2026-71987
MSI · Radix AXE6600 router firmware version v781521
MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the alg function that allows remote attackers to execute arbitrary commands on the affected device. Attackers can exploit this vulnerability through the alg function to execute malicious commands and obtain root privileges on the underlying system.
Operator check
Review CVE-2026-71987 in your asset inventory. Apply patches per vendor guidance and verify Radix AXE6600 router firmware version v781521 is not exposed. CVSS score: 9.8.
Read brief →
Aug 9, 2026
Vendor advisory
Critical vendor advisory
CVE-2026-71988
MSI · Radix AXE6600 router firmware version v781521
MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the portFw function that allows remote attackers to execute arbitrary commands on the affected device. Attackers can exploit this vulnerability through the alg function to execute malicious commands and obtain root privileges on the underlying system.
Operator check
Review CVE-2026-71988 in your asset inventory. Apply patches per vendor guidance and verify Radix AXE6600 router firmware version v781521 is not exposed. CVSS score: 9.8.
Read brief →
Aug 9, 2026
Vendor advisory
Critical vendor advisory
CVE-2026-71989
MSI · Radix AXE6600 router firmware version v781521
MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the porTrigger function that allows remote attackers to execute arbitrary commands on the affected device. Attackers can exploit this vulnerability through the alg function to execute malicious commands and obtain root privileges on the underlying system.
Operator check
Review CVE-2026-71989 in your asset inventory. Apply patches per vendor guidance and verify Radix AXE6600 router firmware version v781521 is not exposed. CVSS score: 9.8.
Read brief →
Aug 9, 2026
Vendor advisory
Critical vendor advisory
CVE-2026-71990
MSI · Radix AXE6600 router firmware version v781521
MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the TelnetSSH function used for SSH configuration that allows remote attackers to execute arbitrary commands on the affected device. Attackers can exploit this vulnerability through the SSH configuration interface to inject malicious commands and obtain root privileges on the underlying system.
Operator check
Review CVE-2026-71990 in your asset inventory. Apply patches per vendor guidance and verify Radix AXE6600 router firmware version v781521 is not exposed. CVSS score: 9.8.
Read brief →
Aug 9, 2026
Vendor advisory
Critical vendor advisory
CVE-2026-71991
MSI · Radix AXE6600 router firmware version v781521
MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the TelnetSSH function used for Telnet configuration that allows remote attackers to execute arbitrary commands on the affected device. Attackers can exploit this vulnerability through the Telnet configuration interface to inject malicious commands and obtain root privileges on the underlying system.
Operator check
Review CVE-2026-71991 in your asset inventory. Apply patches per vendor guidance and verify Radix AXE6600 router firmware version v781521 is not exposed. CVSS score: 9.8.
Read brief →
Aug 9, 2026
Vendor advisory
Critical vendor advisory
CVE-2026-71992
MSI · Radix AXE6600 router firmware version v781521
MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the macfilter function that allows remote attackers to execute arbitrary commands on the affected device. Attackers can exploit the macfilter function to inject malicious commands and obtain root privileges on the underlying system.
Operator check
Review CVE-2026-71992 in your asset inventory. Apply patches per vendor guidance and verify Radix AXE6600 router firmware version v781521 is not exposed. CVSS score: 9.8.
Read brief →
Aug 9, 2026
Vendor advisory
Critical vendor advisory
CVE-2026-71993
MSI · Radix AXE6600 router firmware version v781521
MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the openvpn function that allows remote attackers to execute arbitrary commands on the affected device. Attackers can exploit the macfilter function to inject malicious commands and obtain root privileges on the underlying system.
Operator check
Review CVE-2026-71993 in your asset inventory. Apply patches per vendor guidance and verify Radix AXE6600 router firmware version v781521 is not exposed. CVSS score: 9.8.
Read brief →
Aug 8, 2026
Vendor advisory
Critical vendor advisory
CVE-2026-71944
D-Link · DWR-M961 devices with hardware version C1 and firmware
D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injection vulnerability in the /boafrm/formLtefotaUpgradeQuectel interface. A remote attacker can inject arbitrary malicious commands into the fota_url field, resulting in command execution with root privileges.
Operator check
Review CVE-2026-71944 in your asset inventory. Apply patches per vendor guidance and verify DWR-M961 devices with hardware version C1 and firmware is not exposed. CVSS score: 9.8.
Read brief →
Aug 8, 2026
Vendor advisory
Critical vendor advisory
CVE-2026-71956
D-Link · DWR-M961 devices with hardware version C1 and software
D-Link DWR-M961 devices with hardware version C1 and software version 1.1.2_C1_202602110044 contain a command injection vulnerability in the app.cgi interface. A remote attacker can inject arbitrary malicious commands into the netDig.ping.dst field, resulting in command execution with root privileges.
Operator check
Review CVE-2026-71956 in your asset inventory. Apply patches per vendor guidance and verify DWR-M961 devices with hardware version C1 and software is not exposed. CVSS score: 9.8.
Read brief →
Aug 8, 2026
Vendor advisory
Critical vendor advisory
CVE-2026-71957
D-Link · DWR-M961 devices with hardware version C1 and software
D-Link DWR-M961 devices with hardware version C1 and software version 1.1.2_C1_202602110044 contain a buffer overflow vulnerability in the app.cgi interface. A remote attacker can write an overly long string to the netAcc.addlist[].name field and execute arbitrary commands by crafting a specific payload, or cause the device to crash.
Operator check
Review CVE-2026-71957 in your asset inventory. Apply patches per vendor guidance and verify DWR-M961 devices with hardware version C1 and software is not exposed. CVSS score: 9.8.
Read brief →
Aug 8, 2026
Vendor advisory
Critical vendor advisory
CVE-2026-71958
D-Link · DWR-M961 devices with hardware version C1 and software
D-Link DWR-M961 devices with hardware version C1 and software version 1.1.2_C1_202602110044 contain a buffer overflow vulnerability in the quicksetup.cgi interface. A remote attacker can write overly long strings to the test4, ssid2, and username fields and execute arbitrary commands by crafting a specific payload, or cause the device to crash.
Operator check
Review CVE-2026-71958 in your asset inventory. Apply patches per vendor guidance and verify DWR-M961 devices with hardware version C1 and software is not exposed. CVSS score: 9.8.
Read brief →
Aug 8, 2026
Vendor advisory
Critical vendor advisory
CVE-2026-71983
MSI · Radix AXE6600 router firmware version v781521
MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the wps.cgi interface that allows remote attackers to execute arbitrary commands by injecting malicious input through the pin2g, pin5g, or pin6g parameters. Attackers can exploit these unsanitized parameters to execute arbitrary commands on the affected device and obtain root privileges.
Operator check
Review CVE-2026-71983 in your asset inventory. Apply patches per vendor guidance and verify Radix AXE6600 router firmware version v781521 is not exposed. CVSS score: 9.8.
Read brief →
Aug 7, 2026
Vendor advisory
High-risk advisory
CVE-2026-63221
Composer · codeigniter4/framework
CodeIgniter: SQL injection in Query Builder deleteBatch() when used with where() conditions
Operator check
Check whether codeigniter4/framework is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. EPSS probability: 0.4%; percentile: 30%.
Read brief →
Aug 7, 2026
Vendor advisory
High-risk advisory
CVE-2026-63222
Composer · codeigniter4/framework
CodeIgniter: Path traversal in UploadedFile::move() when using client-provided filenames
Operator check
Check whether codeigniter4/framework is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. EPSS probability: 0.4%; percentile: 37%.
Read brief →
Aug 7, 2026
Vendor advisory
High-risk advisory
CVE-2026-63223
Composer · codeigniter4/framework
CodeIgniter: Uploaded file extension validation bypass in `is_image` and `mime_in` rules
Operator check
Check whether codeigniter4/framework is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. EPSS probability: 0.5%; percentile: 40%.
Read brief →
Aug 7, 2026
Vendor advisory
Critical vendor advisory
Composer · craftcms/cms
Craft CMS: Passkey login accepts replayed WebAuthn assertions
Operator check
Check whether craftcms/cms is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. CVSS score: 9.1.
Read brief →
Aug 7, 2026
Vendor advisory
Critical vendor advisory
CVE-2026-56793
Dell · Openmanage Server Administrator
Dell OpenManage Server Administrator, versions prior to 11.1.0.2, contains an Improper Authentication vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Unauthorized access.
Operator check
Review CVE-2026-56793 in your asset inventory. Apply patches per vendor guidance and verify Openmanage Server Administrator is not exposed. CVSS score: 7.7.
Read brief →
Aug 7, 2026
Coordinated disclosure
Patch review
GitHub · repository for updates and install the latest
Overview A heap buffer overflow vulnerability exists in the stb TrueType library created by nothings. Exploitation of this vulnerability can occur when handling malformed font data and may lead to both Denial of Service (DoS) and Information Disclosure. Description The nothings stb repository, versions 1.26 and earlier, contains a collection of single-file public domain and MIT-licensed libraries for C/C++ projects. CVE-2026-18497 A heap buffer overflow vulnerability exists in the stbtt_GetGlyphShape() function within the stb_truetype.h library when handling malformed TrueType Font (TTF) data. The issue occurs during glyph contour parsing. The function iterates based on the number of contour endpoints specified in endPtsOfContours , but does not validate that the points pointer remains within the bounds of the glyph data buffer. As a... Related CVEs: CVE-2026-18497.
Operator check
Review the CERT/CC Vulnerability Note and compare the affected vendor and product list against your inventory. Apply vendor fixes or compensating controls for repository for updates and install the latest where available.
Read brief →
Aug 7, 2026
Vendor advisory
High-risk advisory
CVE-2026-71556
Go · github.com/go-git/go-git/v5
go-git: Worktree operations may follow symlinks
Operator check
Check whether github.com/go-git/go-git/v5 is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.
Read brief →
Aug 7, 2026
Vendor advisory
High-risk advisory
CVE-2026-15895
npm · jsii-diff
jsii-diff: Command Injection via npm: package argument
Operator check
Check whether jsii-diff is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. CVSS score: 8.4. EPSS probability: 0.6%; percentile: 47%.
Read brief →
Aug 7, 2026
Vendor advisory
High-risk advisory
CVE-2026-71851
npm · crypto-js
crypto-js: Insufficient Entropy in Cryptographic Secret Generation via Vulnerable CryptoJS Dependency Chain
Operator check
Check whether crypto-js is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.
Read brief →
Aug 7, 2026
KEV
Known exploited
CVE-2026-8037
Progress · LoadMaster
Progress LoadMaster contains a command injection vulnerability that allows an un-authenticated attacker to execute arbitrary commands on the LoadMaster appliance by exploiting unsanitized input in multiple command endpoints.
Operator check
Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
Read brief →
Aug 7, 2026
Vendor advisory
High-risk advisory
CVE-2026-67422
PyPI · pymdown-extensions
pymdown-extensions: exponential-backtracking ReDoS in caret, tilde, betterem, and magiclink inline processors
Operator check
Check whether pymdown-extensions is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. EPSS probability: 0.6%; percentile: 45%.
Read brief →
Aug 7, 2026
Vendor advisory
High-risk advisory
PyPI · GitPython
GitPython: Unguarded git read-tree option forwarding in IndexFile.from_tree/reset/merge_tree enables arbitrary file overwrite
Operator check
Check whether GitPython is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.
Read brief →
Aug 7, 2026
Vendor advisory
High-risk advisory
PyPI · GitPython
GitPython: Unguarded git option forwarding in Repo.init enables arbitrary command execution via --template clone hooks
Operator check
Check whether GitPython is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.
Read brief →
Aug 7, 2026
Vendor advisory
High-risk advisory
PyPI · GitPython
GitPython: Arbitrary Git Repository Creation Outside the Working Tree via Unvalidated .gitmodules Submodule Name in GitPython
Operator check
Check whether GitPython is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.
Read brief →
Aug 7, 2026
Vendor advisory
High-risk advisory
PyPI · GitPython
GitPython: git-config OPTION-name injection via =/#/whitespace bypasses name validator, enabling forged core.sshCommand/hooksPath (RCE)
Operator check
Check whether GitPython is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.
Read brief →
Aug 7, 2026
Vendor advisory
High-risk advisory
PyPI · GitPython
GitPython: Unsafe git option guard bypass via split_single_char_options=False short-option token smuggling enables command execution
Operator check
Check whether GitPython is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.
Read brief →
Aug 6, 2026
Vendor advisory
High-risk advisory
CVE-2026-64665
Composer · statamic/cms
Statamic: Account takeover via OAuth email matching without email-verification check
Operator check
Check whether statamic/cms is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.
Read brief →
Aug 6, 2026
Vendor advisory
High-risk advisory
CVE-2026-67434
Composer · squizlabs/php_codesniffer
PHP_CodeSniffer gitblame report command injection via crafted filename
Operator check
Check whether squizlabs/php_codesniffer is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. CVSS score: 7.3.
Read brief →
Aug 6, 2026
Vendor advisory
High-risk advisory
CVE-2026-71488
Composer · league/commonmark
league/commonmark: Quadratic-time denial of service when parsing crafted Markdown
Operator check
Check whether league/commonmark is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.
Read brief →
Aug 6, 2026
Vendor advisory
High-risk advisory
Composer · craftcms/cms
Craft CMS: Authenticated RCE via `condition.config` JSON cleanse bypass
Operator check
Check whether craftcms/cms is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. CVSS score: 8.7.
Read brief →
Aug 6, 2026
Vendor advisory
High-risk advisory
Composer · craftcms/cms
Craft CMS: Authenticated RCE through Twig sandbox escape
Operator check
Check whether craftcms/cms is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. CVSS score: 8.7.
Read brief →
Aug 6, 2026
Vendor advisory
High-risk advisory
Composer · league/commonmark
league/commonmark: Denial of service via adjacent inline attribute blocks
Operator check
Check whether league/commonmark is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.
Read brief →
Aug 6, 2026
Vendor advisory
High-risk advisory
Composer · league/commonmark
league/commonmark: Denial of service via duplicate footnote definitions
Operator check
Check whether league/commonmark is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.
Read brief →
Aug 6, 2026
Vendor advisory
High-risk advisory
Composer · league/commonmark
league/commonmark: Denial of service via colliding heading slugs
Operator check
Check whether league/commonmark is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.
Read brief →
Aug 6, 2026
Vendor advisory
High-risk advisory
Composer · craftcms/cms
Craft CMS: Arbitrary user password reset leading to administrator account takeover
Operator check
Check whether craftcms/cms is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.
Read brief →
Aug 6, 2026
Coordinated disclosure
Patch review
Content · Security Policy (CSP) enforcement. When a calendar invite
Overview A cross-site scripting (XSS) vulnerability in Alinto SOGo v5.12.7 allows attackers to achieve remote code execution by embedding malicious SVG (Scalable Vector Graphics) objects in ICS (iCalendar) invitations. The vulnerability has been actively exploited in the wild, as confirmed by VirusTotal sightings. Description Alinto SOGo is an open-source webmail and groupware platform for email, calendars, contacts, and shared scheduling. It is primarily used by organizations seeking a self-hosted interface solution for existing mail infrastructure. CVE-2026-8496 The vulnerability exists in SOGo’s handling of ICS files, where the DESCRIPTION field is rendered without proper sanitization or Content Security Policy (CSP) enforcement. When a calendar invite contains an SVG payload, such as , with JavaScript event handlers, the browser... Related CVEs: CVE-2026-8496.
Operator check
Review the CERT/CC Vulnerability Note and compare the affected vendor and product list against your inventory. Apply vendor fixes or compensating controls for Security Policy (CSP) enforcement. When a calendar invite where available.
Read brief →
Aug 6, 2026
Vendor advisory
Critical vendor advisory
CVE-2026-54489
Dell · Virtual Storage Integrator
Dell Virtual Storage Integrator for VMware vSphere Client, versions prior to 10.11.1.0, contain(s) a Sensitive Information Disclosure vulnerability. An unauthenticated remote attacker could potentially exploit this vulnerability, leading to information disclosure and session hijacking. This vulnerability is considered critical as it allows an unauthenticated attacker to obtain active session credentials and fully impersonate authenticated users, including administrators. Dell recommends customers to upgrade at the earliest opportunity.
Operator check
Review CVE-2026-54489 in your asset inventory. Apply patches per vendor guidance and verify Virtual Storage Integrator is not exposed. CVSS score: 9.1. EPSS probability: 0.4%; percentile: 32%.
Read brief →
Aug 6, 2026
Vendor advisory
High-risk advisory
CVE-2026-65600
Go · github.com/traefik/traefik/v2
Traefik: Authentication Bypass via Path Traversal in ReplacePathRegex Middleware
Operator check
Check whether github.com/traefik/traefik/v2 is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. EPSS probability: 0.7%; percentile: 49%.
Read brief →
Aug 6, 2026
Vendor advisory
High-risk advisory
CVE-2026-67309
Go · github.com/traefik/traefik/v3
Traefik: Kubernetes Ingress NGINX RewriteTarget Path Traversal Allows Route-Level Authentication Bypass
Operator check
Check whether github.com/traefik/traefik/v3 is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. CVSS score: 7.8. EPSS probability: 0.5%; percentile: 40%.
Read brief →
Aug 6, 2026
Vendor advisory
High-risk advisory
CVE-2026-71324
Go · github.com/traefik/traefik/v2
Traefik: Cross-user response poisoning via proxied CONNECT on Traefik's shared backend keep-alive pool
Operator check
Check whether github.com/traefik/traefik/v2 is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. CVSS score: 7.0.
Read brief →
Aug 6, 2026
Vendor advisory
High-risk advisory
CVE-2026-71327
Go · github.com/traefik/traefik/v3
Traefik: Gateway API route identity collision allows cross-namespace backend hijacking
Operator check
Check whether github.com/traefik/traefik/v3 is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.
Read brief →
Aug 6, 2026
Patch Tuesday
Critical vendor advisory
CVE-2026-34191
Microsoft · Mariner
Apache Portable Runtime Utility: SQL Injection in apr_dbd_oracle Published in August 2026 Early Security Updates.
Operator check
Review the Microsoft Security Update Guide entry for CVE-2026-34191. Confirm whether Mariner is deployed, then apply the current security update or documented mitigation. CVSS score: 9.1. EPSS probability: 0.4%; percentile: 29%.
Read brief →
Aug 6, 2026
Patch Tuesday
High-risk advisory
CVE-2026-49163
Microsoft · Application Insights Profiler
Improper limitation of a pathname to a restricted directory ('path traversal') in Application Insights Profiler allows an authorized attacker to elevate privileges over a network. Published in August 2026 Early Security Updates. MSRC exploitability: Publicly Disclosed:No;Exploited:No.
Operator check
Review the Microsoft Security Update Guide entry for CVE-2026-49163. Confirm whether Application Insights Profiler is deployed, then apply the current security update or documented mitigation. CVSS score: 8.8. EPSS probability: 0.6%; percentile: 46%.
Read brief →
Aug 6, 2026
Patch Tuesday
Critical vendor advisory
CVE-2026-50481
Microsoft · Azure Active Directory
Modification of assumed-immutable data (maid) in Azure Active Directory allows an authorized attacker to elevate privileges over a network. Published in August 2026 Early Security Updates. MSRC exploitability: Publicly Disclosed:No;Exploited:No;Latest Software Release:N/A.
Operator check
Review the Microsoft Security Update Guide entry for CVE-2026-50481. Confirm whether Azure Active Directory is deployed, then apply the current security update or documented mitigation. CVSS score: 9.9. EPSS probability: 0.5%; percentile: 37%.
Read brief →
Aug 6, 2026
Patch Tuesday
Critical vendor advisory
CVE-2026-50515
Microsoft · Azure Service Bus
Deserialization of untrusted data in Azure Service Bus allows an authorized attacker to execute code over a network. Published in August 2026 Early Security Updates. MSRC exploitability: Publicly Disclosed:No;Exploited:No;Latest Software Release:N/A.
Operator check
Review the Microsoft Security Update Guide entry for CVE-2026-50515. Confirm whether Azure Service Bus is deployed, then apply the current security update or documented mitigation. CVSS score: 9.9. EPSS probability: 0.9%; percentile: 57%.
Read brief →
Aug 6, 2026
Patch Tuesday
Critical vendor advisory
CVE-2026-50516
Microsoft · Microsoft Azure Kubernetes Service
Missing authentication for critical function in Microsoft Azure Kubernetes Service allows an unauthorized attacker to elevate privileges over a network. Published in August 2026 Early Security Updates. MSRC exploitability: Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation Less Likely.
Operator check
Review the Microsoft Security Update Guide entry for CVE-2026-50516. Confirm whether Microsoft Azure Kubernetes Service is deployed, then apply the current security update or documented mitigation. CVSS score: 9.4.
Read brief →
Aug 6, 2026
Patch Tuesday
Critical vendor advisory
CVE-2026-50540
Microsoft · Mariner
Kata Containers: Config Path Annotation Arbitrary File Loading Published in August 2026 Early Security Updates.
Operator check
Review the Microsoft Security Update Guide entry for CVE-2026-50540. Confirm whether Mariner is deployed, then apply the current security update or documented mitigation. CVSS score: 9.6. EPSS probability: 0.4%; percentile: 31%.
Read brief →
Aug 6, 2026
Patch Tuesday
Critical vendor advisory
CVE-2026-56161
Microsoft · Azure Logic Apps
Improper access control in Azure Logic Apps allows an authorized attacker to disclose information over a network. Published in August 2026 Early Security Updates. MSRC exploitability: Publicly Disclosed:No;Exploited:No;Latest Software Release:N/A.
Operator check
Review the Microsoft Security Update Guide entry for CVE-2026-56161. Confirm whether Azure Logic Apps is deployed, then apply the current security update or documented mitigation. CVSS score: 9.6. EPSS probability: 0.4%; percentile: 32%.
Read brief →
Aug 6, 2026
Patch Tuesday
Critical vendor advisory
CVE-2026-56162
Microsoft · Azure SQL Database
Improper authentication in Azure SQL Database allows an unauthorized attacker to elevate privileges over a network. Published in August 2026 Early Security Updates. MSRC exploitability: Publicly Disclosed:No;Exploited:No;Latest Software Release:N/A.
Operator check
Review the Microsoft Security Update Guide entry for CVE-2026-56162. Confirm whether Azure SQL Database is deployed, then apply the current security update or documented mitigation. CVSS score: 10.0. EPSS probability: 0.5%; percentile: 40%.
Read brief →
Aug 6, 2026
Patch Tuesday
Critical vendor advisory
CVE-2026-59115
Microsoft · Microsoft Entra Provisioning Service (SyncFabric)
'.../...//' in Microsoft Entra Provisioning Service (SyncFabric) allows an authorized attacker to elevate privileges over a network. Published in August 2026 Early Security Updates. MSRC exploitability: Publicly Disclosed:No;Exploited:No;Latest Software Release:N/A.
Operator check
Review the Microsoft Security Update Guide entry for CVE-2026-59115. Confirm whether Microsoft Entra Provisioning Service (SyncFabric) is deployed, then apply the current security update or documented mitigation. CVSS score: 9.9. EPSS probability: 0.6%; percentile: 47%.
Read brief →
Aug 6, 2026
Patch Tuesday
Critical vendor advisory
CVE-2026-59118
Microsoft · Microsoft Power Apps
Improper authorization in Microsoft Power Apps allows an unauthorized attacker to elevate privileges over a network. Published in August 2026 Early Security Updates. MSRC exploitability: Publicly Disclosed:No;Exploited:No;Latest Software Release:N/A.
Operator check
Review the Microsoft Security Update Guide entry for CVE-2026-59118. Confirm whether Microsoft Power Apps is deployed, then apply the current security update or documented mitigation. CVSS score: 9.3. EPSS probability: 0.4%; percentile: 33%.
Read brief →
Aug 6, 2026
Patch Tuesday
Critical vendor advisory
CVE-2026-62830
Microsoft · Azure SRE Agent
Missing authorization in Azure SRE Agent allows an authorized attacker to elevate privileges over a network. Published in August 2026 Early Security Updates. MSRC exploitability: Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation Less Likely.
Operator check
Review the Microsoft Security Update Guide entry for CVE-2026-62830. Confirm whether Azure SRE Agent is deployed, then apply the current security update or documented mitigation. CVSS score: 9.9. EPSS probability: 0.4%; percentile: 35%.
Read brief →
Aug 6, 2026
Patch Tuesday
High-risk advisory
CVE-2026-62836
Microsoft · Azure SQL Managed Instance
Improper restriction of communication channel to intended endpoints in Azure SQL Managed Instance allows an unauthorized attacker to elevate privileges over a network. Published in August 2026 Early Security Updates. MSRC exploitability: Publicly Disclosed:No;Exploited:No;Latest Software Release:N/A.
Operator check
Review the Microsoft Security Update Guide entry for CVE-2026-62836. Confirm whether Azure SQL Managed Instance is deployed, then apply the current security update or documented mitigation. CVSS score: 8.7. EPSS probability: 0.4%; percentile: 29%.
Read brief →
Aug 6, 2026
Patch Tuesday
High-risk advisory
CVE-2026-62869
Microsoft · Azure Entra ID
Insufficient verification of data authenticity in Azure Entra ID allows an authorized attacker to perform spoofing over a network. Published in August 2026 Early Security Updates. MSRC exploitability: Publicly Disclosed:No;Exploited:No;Latest Software Release:N/A.
Operator check
Review the Microsoft Security Update Guide entry for CVE-2026-62869. Confirm whether Azure Entra ID is deployed, then apply the current security update or documented mitigation. CVSS score: 8.8.
Read brief →
Aug 6, 2026
Patch Tuesday
Critical vendor advisory
CVE-2026-62896
Microsoft · Microsoft Teams
Improper authentication in Microsoft Teams allows an authorized attacker to elevate privileges over a network. Published in August 2026 Early Security Updates. MSRC exploitability: Publicly Disclosed:No;Exploited:No;Latest Software Release:N/A.
Operator check
Review the Microsoft Security Update Guide entry for CVE-2026-62896. Confirm whether Microsoft Teams is deployed, then apply the current security update or documented mitigation. CVSS score: 9.6. EPSS probability: 0.4%; percentile: 32%.
Read brief →
Aug 6, 2026
Patch Tuesday
High-risk advisory
CVE-2026-62918
Microsoft · Microsoft Teams
Improper verification of cryptographic signature in Microsoft Teams allows an unauthorized attacker to perform spoofing over a network. Published in August 2026 Early Security Updates. MSRC exploitability: Publicly Disclosed:No;Exploited:No;Latest Software Release:N/A.
Operator check
Review the Microsoft Security Update Guide entry for CVE-2026-62918. Confirm whether Microsoft Teams is deployed, then apply the current security update or documented mitigation. CVSS score: 7.5. EPSS probability: 0.3%; percentile: 22%.
Read brief →
Aug 6, 2026
Patch Tuesday
High-risk advisory
CVE-2026-63522
Microsoft · Azure SQL Database
Incorrect permission assignment for critical resource in Azure SQL Database allows an authorized attacker to elevate privileges locally. Published in August 2026 Early Security Updates. MSRC exploitability: Publicly Disclosed:No;Exploited:No;Latest Software Release:N/A.
Operator check
Review the Microsoft Security Update Guide entry for CVE-2026-63522. Confirm whether Azure SQL Database is deployed, then apply the current security update or documented mitigation. CVSS score: 7.8.
Read brief →
Aug 6, 2026
Patch Tuesday
Critical vendor advisory
CVE-2026-64562
Microsoft · Mariner
KVM: nVMX: Hide shadow VMCS right after VMCLEAR Published in August 2026 Early Security Updates.
Operator check
Review the Microsoft Security Update Guide entry for CVE-2026-64562. Confirm whether Mariner is deployed, then apply the current security update or documented mitigation. CVSS score: 9.8. EPSS probability: 0.2%; percentile: 5%.
Read brief →
Aug 6, 2026
Patch Tuesday
Critical vendor advisory
CVE-2026-64564
Microsoft · Mariner
sctp: don't free the ASCONF's own transport in DEL-IP processing Published in August 2026 Early Security Updates.
Operator check
Review the Microsoft Security Update Guide entry for CVE-2026-64564. Confirm whether Mariner is deployed, then apply the current security update or documented mitigation. CVSS score: 9.8. EPSS probability: 0.2%; percentile: 8%.
Read brief →
Aug 6, 2026
Patch Tuesday
Critical vendor advisory
CVE-2026-64565
Microsoft · Mariner
Input: ims-pcu - fix heap-buffer-overflow in ims_pcu_process_data() Published in August 2026 Early Security Updates.
Operator check
Review the Microsoft Security Update Guide entry for CVE-2026-64565. Confirm whether Mariner is deployed, then apply the current security update or documented mitigation. CVSS score: 9.8. EPSS probability: 0.2%; percentile: 7%.
Read brief →
Aug 6, 2026
Patch Tuesday
Critical vendor advisory
CVE-2026-64584
Microsoft · Mariner
usb: gadget: f_midi: cancel pending IN work before freeing the midi object Published in August 2026 Early Security Updates.
Operator check
Review the Microsoft Security Update Guide entry for CVE-2026-64584. Confirm whether Mariner is deployed, then apply the current security update or documented mitigation. CVSS score: 9.8. EPSS probability: 0.2%; percentile: 5%.
Read brief →
Aug 6, 2026
Patch Tuesday
Critical vendor advisory
CVE-2026-64593
Microsoft · Mariner
btrfs: do not trim a device which is not writeable Published in August 2026 Early Security Updates.
Operator check
Review the Microsoft Security Update Guide entry for CVE-2026-64593. Confirm whether Mariner is deployed, then apply the current security update or documented mitigation. CVSS score: 9.8. EPSS probability: 0.2%; percentile: 6%.
Read brief →
Aug 6, 2026
Patch Tuesday
Critical vendor advisory
CVE-2026-64594
Microsoft · Mariner
usb: gadget: f_fs: initialize reset_work at allocation time Published in August 2026 Early Security Updates.
Operator check
Review the Microsoft Security Update Guide entry for CVE-2026-64594. Confirm whether Mariner is deployed, then apply the current security update or documented mitigation. CVSS score: 9.8. EPSS probability: 0.2%; percentile: 6%.
Read brief →
Aug 6, 2026
Patch Tuesday
Critical vendor advisory
CVE-2026-65667
Microsoft · Microsoft Teams
Missing authorization in Microsoft Teams allows an unauthorized attacker to elevate privileges over a network. Published in August 2026 Early Security Updates. MSRC exploitability: Publicly Disclosed:No;Exploited:No;Latest Software Release:N/A.
Operator check
Review the Microsoft Security Update Guide entry for CVE-2026-65667. Confirm whether Microsoft Teams is deployed, then apply the current security update or documented mitigation. CVSS score: 10.0. EPSS probability: 0.5%; percentile: 37%.
Read brief →
Aug 6, 2026
Patch Tuesday
High-risk advisory
CVE-2026-65668
Microsoft · Microsoft Purview eDiscovery
Improper access control in Microsoft Purview eDiscovery allows an authorized attacker to elevate privileges over a network. Published in August 2026 Early Security Updates. MSRC exploitability: Publicly Disclosed:No;Exploited:No;Latest Software Release:N/A.
Operator check
Review the Microsoft Security Update Guide entry for CVE-2026-65668. Confirm whether Microsoft Purview eDiscovery is deployed, then apply the current security update or documented mitigation. CVSS score: 8.8. EPSS probability: 0.4%; percentile: 35%.
Read brief →
Aug 6, 2026
Patch Tuesday
High-risk advisory
CVE-2026-68480
Microsoft · Mariner
x86/bugs: Make Safe-RET robust against interrupt injection Published in August 2026 Early Security Updates.
Operator check
Review the Microsoft Security Update Guide entry for CVE-2026-68480. Confirm whether Mariner is deployed, then apply the current security update or documented mitigation. CVSS score: 8.8. EPSS probability: 0.2%; percentile: 10%.
Read brief →
Aug 6, 2026
Patch Tuesday
Critical vendor advisory
CVE-2026-68823
Microsoft · Azure Confidential Ledger
Exposed dangerous method or function in Azure Confidential Ledger allows an authorized attacker to execute code over a network. Published in August 2026 Early Security Updates. MSRC exploitability: Publicly Disclosed:No;Exploited:No;Latest Software Release:N/A.
Operator check
Review the Microsoft Security Update Guide entry for CVE-2026-68823. Confirm whether Azure Confidential Ledger is deployed, then apply the current security update or documented mitigation. CVSS score: 9.1. EPSS probability: 0.5%; percentile: 41%.
Read brief →
Aug 6, 2026
Patch Tuesday
Critical vendor advisory
CVE-2026-70332
Microsoft · Microsoft Office SharePoint
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network. Published in August 2026 Early Security Updates. MSRC exploitability: Publicly Disclosed:No;Exploited:No;Latest Software Release:N/A.
Operator check
Review the Microsoft Security Update Guide entry for CVE-2026-70332. Confirm whether Microsoft Office SharePoint is deployed, then apply the current security update or documented mitigation. CVSS score: 9.6. EPSS probability: 0.4%; percentile: 36%.
Read brief →
Aug 6, 2026
Vendor advisory
High-risk advisory
CVE-2026-16633
npm · pdfjs-dist
PDF.js: Arbitrary JavaScript execution upon opening a malicious PDF
Operator check
Check whether pdfjs-dist is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. CVSS score: 8.6.
Read brief →
Aug 6, 2026
Vendor advisory
High-risk advisory
CVE-2026-71476
npm · nx
Nx: Zip-Slip in the self-hosted remote cache
Operator check
Check whether nx is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. CVSS score: 8.7.
Read brief →
Aug 6, 2026
Vendor advisory
High-risk advisory
npm · js-yaml
JS-YAML: Quadratic CPU consumption in !!omap resolution (3.x and 4.x) — CVE-2026-59870 fix not backported
Operator check
Check whether js-yaml is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.
Read brief →
Aug 6, 2026
Vendor advisory
High-risk advisory
npm · ngx-extended-pdf-viewer
ngx-extended-pdf-viewer bundles a version of pdf.js vulnerable to CVE-2026-16633
Operator check
Check whether ngx-extended-pdf-viewer is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. CVSS score: 8.6.
Read brief →
Aug 5, 2026
Vendor advisory
High-risk advisory
CVE-2026-54572
Go · github.com/rclone/rclone
rclone: Unvalidated symlink target in local `--links` — arbitrary file write from an untrusted remote
Operator check
Check whether github.com/rclone/rclone is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. EPSS probability: 0.3%; percentile: 23%.
Read brief →
Aug 5, 2026
Vendor advisory
High-risk advisory
CVE-2026-59733
Go · github.com/rclone/rclone
rclone `serve restic --private-repos` authorization bypass: `..` in the URL path lets an authenticated user read, overwrite and delete other users' repositories
Operator check
Check whether github.com/rclone/rclone is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. EPSS probability: 0.4%; percentile: 35%.
Read brief →
Aug 5, 2026
Vendor advisory
High-risk advisory
CVE-2026-71309
Go · github.com/rclone/rclone
rclone: Incomplete path validation allows backend root escape in serve restic
Operator check
Check whether github.com/rclone/rclone is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. CVSS score: 8.6.
Read brief →
Aug 5, 2026
Vendor advisory
High-risk advisory
CVE-2026-71312
Go · github.com/rclone/rclone
rclone: PowerShell Smart-Quote Filename Injection Enables SFTP Server-Side Command Execution
Operator check
Check whether github.com/rclone/rclone is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.
Read brief →
Aug 5, 2026
KEV
Known exploited
CVE-2026-63077
JetBrains · TeamCity
JetBrains TeamCity contains a deserialization of untrusted data vulnerability that could allow unauthenticated remote code execution via the agent polling protocol.
Operator check
Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
Read brief →
Aug 5, 2026
Vendor advisory
Critical vendor advisory
CVE-2026-8470
Langflow · Langflow
IBM Langflow OSS 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, and 1.0.0 through 1.10.3 use Python's non-cryptographic random module for generating Fernet encryption keys from user secrets under 32 characters. The deterministic Mersenne Twister PRNG produces identical keys for identical seeds, allowing attackers to reproduce encryption keys and decrypt stored API keys and authentication tokens.
Operator check
Review CVE-2026-8470 in your asset inventory. Apply patches per vendor guidance and verify Langflow is not exposed. CVSS score: 7.4. EPSS probability: 0.1%; percentile: 1%.
Read brief →
Aug 5, 2026
Vendor advisory
Critical vendor advisory
CVE-2026-9205
Langflow · Langflow
IBM Langflow OSS contains a weak cryptographic key derivation vulnerability in the ensure_fernet_key() function.
Operator check
Review CVE-2026-9205 in your asset inventory. Apply patches per vendor guidance and verify Langflow is not exposed. CVSS score: 7.4. EPSS probability: 0.2%; percentile: 11%.
Read brief →
Aug 5, 2026
Vendor advisory
High-risk advisory
CVE-2026-70601
npm · electron
Electron: Context isolation bypass via Function.prototype.bind hijack
Operator check
Check whether electron is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.
Read brief →
Aug 5, 2026
Vendor advisory
High-risk advisory
CVE-2026-70604
npm · electron
Electron: Custom protocol with supportFetchAPI but not corsEnabled allows cross-origin reads
Operator check
Check whether electron is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.
Read brief →
Aug 5, 2026
Vendor advisory
High-risk advisory
CVE-2026-70608
npm · electron
Electron: Sandboxed iframe can bypass the allow-popups restriction via the OpenURL navigation path
Operator check
Check whether electron is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.
Read brief →
Aug 5, 2026
Vendor advisory
High-risk advisory
CVE-2026-71314
npm · nuxt
Nuxt: Unauthenticated out-of-memory crash via unbounded v-for expansion in island rendering
Operator check
Check whether nuxt is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.
Read brief →
Aug 5, 2026
Vendor advisory
High-risk advisory
CVE-2026-71315
npm · nuxt
Nuxt route rules silently dropped for mixed-case paths, bypassing appMiddleware auth gates (incomplete fix for CVE-2026-53721)
Operator check
Check whether nuxt is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.
Read brief →
Aug 5, 2026
Vendor advisory
High-risk advisory
CVE-2026-71316
npm · nuxt
Nuxt runtime payload cache discloses another user's SSR data across users and to unauthenticated clients
Operator check
Check whether nuxt is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.
Read brief →
Aug 5, 2026
Vendor advisory
High-risk advisory
CVE-2026-71319
npm · @nuxt/devtools
Unauthenticated Nuxt DevTools RPC allows arbitrary command execution on the developer's host
Operator check
Check whether @nuxt/devtools is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.
Read brief →
Aug 5, 2026
Vendor advisory
High-risk advisory
CVE-2026-71320
npm · nuxt
Nuxt: Server-Side Remote Code Execution via Runtime Template Injection in Nuxt Server Island Props
Operator check
Check whether nuxt is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.
Read brief →
Aug 5, 2026
Vendor advisory
High-risk advisory
CVE-2026-71321
npm · nuxt
Nuxt: Unauthenticated CPU exhaustion parsing and hashing the Nuxt island endpoint body before hash validation
Operator check
Check whether nuxt is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.
Read brief →
Aug 4, 2026
KEV
Known exploited
CVE-2026-34486
Apache · Tomcat
Apache Tomcat contains a missing encryption of sensitive data vulnerability that allows the bypass of the EncryptInterceptor.
Operator check
Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
Read brief →
Aug 4, 2026
KEV
Known exploited
CVE-2026-9198
IBM · Langflow
Langflow contains a code injection vulnerability that allows unauthenticated attackers to achieve full remote code execution on default Langflow deployments.
Operator check
Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
Read brief →
Aug 4, 2026
Vendor advisory
Critical vendor advisory
CVE-2026-70552
MaxSite · CMS 109.5 and earlier
MaxSite CMS 109.5 and earlier contains an authentication bypass vulnerability in the AJAX dispatcher that allows unauthenticated attackers to access admin-gated endpoints by supplying any X-Requested-With header and requesting a base64-encoded path resolving to any *-ajax.php file in the codebase. Attackers can exploit this dispatcher bypass to reach privileged plugin endpoints without credentials, enabling actions such as manipulating poll states and vote counts, and amplifying the impact of any dangerous operation performed by admin-only ajax files across the plugin tree.
Operator check
Review CVE-2026-70552 in your asset inventory. Apply patches per vendor guidance and verify CMS 109.5 and earlier is not exposed. CVSS score: 9.8.
Read brief →
Aug 4, 2026
Vendor advisory
Critical vendor advisory
CVE-2026-70553
MaxSite · CMS
MaxSite CMS contains a remote code execution vulnerability that allows unauthenticated attackers to inject arbitrary PHP code into the application configuration file by submitting crafted POST requests to the install endpoint after installation is complete. Attackers can supply a malicious db_dbprefix value containing a single quote to break out of a PHP string literal in application/config/database.php, appending attacker-controlled PHP statements that are executed by the web server on every subsequent request, resulting in persistent unauthenticated remote code execution as the web-server pr
Operator check
Review CVE-2026-70553 in your asset inventory. Apply patches per vendor guidance and verify CMS is not exposed. CVSS score: 9.8.
Read brief →
Aug 4, 2026
Vendor advisory
Critical vendor advisory
CVE-2026-70554
MaxSite · CMS
MaxSite CMS contains a PHP object injection vulnerability that allows unauthenticated attackers to execute arbitrary code by passing attacker-controlled serialized data in the maxsite_comuser cookie directly to unserialize() without validation or class allowlisting. Attackers can craft a malicious serialized PHP object payload delivered in a single HTTP request to trigger magic methods during object graph reconstruction, enabling property-oriented programming attacks or remote code execution via available gadget chains such as those targeting SoapClient or Imagick extensions.
Operator check
Review CVE-2026-70554 in your asset inventory. Apply patches per vendor guidance and verify CMS is not exposed. CVSS score: 9.8.
Read brief →
Aug 4, 2026
KEV
Known exploited
CVE-2026-18556
N-able · N-central
N-able N-central contains an authentication bypass using an alternate path or channel that allows for authentication bypass.
Operator check
Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
Read brief →
Aug 4, 2026
Vendor advisory
High-risk advisory
CVE-2026-53950
npm · @tryghost/activitypub
XSS in Ghost's ActivityPub client
Operator check
Check whether @tryghost/activitypub is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. EPSS probability: 0.2%; percentile: 11%.
Read brief →
Aug 4, 2026
Vendor advisory
Critical vendor advisory
CVE-2026-69251
npm · flowise
Flowise RCE via TypeORM DataSource
Operator check
Check whether flowise is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. CVSS score: 9.0.
Read brief →
Aug 4, 2026
Vendor advisory
High-risk advisory
CVE-2026-69252
npm · flowise
Flowise: Missing authorization on `/api/v1/files` allows low-privileged API keys to list and delete files across workspaces within the same organization
Operator check
Check whether flowise is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. CVSS score: 7.2.
Read brief →
Aug 4, 2026
Vendor advisory
Critical vendor advisory
CVE-2026-69253
npm · flowise
Flowise Sandbox Escape to RCE
Operator check
Check whether flowise is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. CVSS score: 9.0.
Read brief →
Aug 4, 2026
Vendor advisory
Critical vendor advisory
CVE-2026-69254
npm · flowise
Flowise: RCE via NodeVM Sandbox Escape in executeJavaScriptCode() nodeVMOptions Override
Operator check
Check whether flowise is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. CVSS score: 9.4.
Read brief →
Aug 4, 2026
Vendor advisory
Critical vendor advisory
CVE-2026-69255
npm · flowise
Flowise: CSV Agent Remote Code Execution via Pyodide Code Injection — Root Shell Verified
Operator check
Check whether flowise is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. CVSS score: 9.2.
Read brief →
Aug 4, 2026
Vendor advisory
Critical vendor advisory
CVE-2026-69256
npm · flowise-components
Flowise: Remote Code Execution Vulnerability in CSVAgent
Operator check
Check whether flowise-components is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. CVSS score: 9.4.
Read brief →
Aug 4, 2026
Vendor advisory
High-risk advisory
CVE-2026-69257
npm · flowise
Flowise: SSRF Protection Bypass via IPv4-Mapped IPv6 Addresses
Operator check
Check whether flowise is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. CVSS score: 7.6.
Read brief →
Aug 4, 2026
Vendor advisory
High-risk advisory
CVE-2026-69258
npm · flowise
Flowise: Unauthenticated Property Injection into Flow Execution Context via Ungated `overrideConfig` Spread in Prediction API
Operator check
Check whether flowise is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. CVSS score: 8.8.
Read brief →
Aug 4, 2026
Vendor advisory
Critical vendor advisory
CVE-2026-69259
npm · flowise
Flowise RCE via SQLite Record Manager Node
Operator check
Check whether flowise is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. CVSS score: 9.4.
Read brief →
Aug 4, 2026
Vendor advisory
High-risk advisory
CVE-2026-69262
npm · flowise
Flowise: `DELETE /api/v1/chatflows/:id` does not validate resource type, allowing `agentflows:delete` and `chatflows:delete` to delete each other’s flow type
Operator check
Check whether flowise is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. CVSS score: 7.1.
Read brief →
Aug 4, 2026
Vendor advisory
High-risk advisory
CVE-2026-69263
npm · flowise
Flowise: CVE-2025-8943 Patch Bypass: npm_config_yes bypasses MCP environment variable blocklist (Unauthenticated RCE)
Operator check
Check whether flowise is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. CVSS score: 8.7.
Read brief →
Aug 4, 2026
Vendor advisory
Critical vendor advisory
CVE-2026-69264
npm · flowise
Flowise: RCE via CSVAgent csvFile data URI base64 segment is interpolated into Python source without validation
Operator check
Check whether flowise is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. CVSS score: 9.4.
Read brief →
Aug 4, 2026
Vendor advisory
Critical vendor advisory
CVE-2026-70470
npm · flowise
Flowise: Pyodide validator Unicode homoglyph bypass leads to RCE
Operator check
Check whether flowise is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. CVSS score: 9.5.
Read brief →
Aug 4, 2026
Vendor advisory
High-risk advisory
CVE-2026-70471
npm · flowise
Flowise: RBAC Bypass Leading to Unauthorized Workspace Variables Disclosure
Operator check
Check whether flowise is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. CVSS score: 7.1.
Read brief →
Aug 4, 2026
Vendor advisory
High-risk advisory
CVE-2026-70472
npm · flowise
Flowise: Cross-workspace credential IDOR in openai-assistants-vector-store
Operator check
Check whether flowise is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. CVSS score: 7.1.
Read brief →
Aug 4, 2026
Vendor advisory
High-risk advisory
CVE-2026-70473
npm · flowise
Flowise: Information Disclosure in GET /api/v1/upsert-history returns the entire server-wide upsert history
Operator check
Check whether flowise is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. CVSS score: 8.3.
Read brief →
Aug 4, 2026
Vendor advisory
High-risk advisory
CVE-2026-70474
npm · flowise
Flowise: Cross-Workspace OAuth2 Credential Metadata Leak
Operator check
Check whether flowise is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. CVSS score: 7.6.
Read brief →
Aug 4, 2026
Vendor advisory
High-risk advisory
CVE-2026-70475
npm · flowise
Flowise: Missing Authorization on Execution Update Endpoint
Operator check
Check whether flowise is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. CVSS score: 7.1.
Read brief →
Aug 4, 2026
Vendor advisory
High-risk advisory
CVE-2026-70476
npm · flowise
Flowise: Broken Access Control in Stripe Subscription Endpoints Allows Cross-Tenant Billing Manipulation
Operator check
Check whether flowise is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. CVSS score: 8.3.
Read brief →
Aug 4, 2026
Vendor advisory
Critical vendor advisory
CVE-2026-70477
npm · flowise
Flowise: CSV Agent Prompt Injection Remote Code Execution Vulnerability
Operator check
Check whether flowise is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. CVSS score: 9.5.
Read brief →
Aug 4, 2026
Vendor advisory
Critical vendor advisory
CVE-2026-70478
npm · flowise
Flowise: Unauthenticated OAuth2 token refresh endpoint returns access tokens — enables token theft for any connected service
Operator check
Check whether flowise is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. CVSS score: 9.2.
Read brief →
Aug 4, 2026
Vendor advisory
High-risk advisory
npm · flowise-components
Flowise: Authenticated arbitrary file write in the `S3 Directory` document loader via unsanitized S3 object keys
Operator check
Check whether flowise-components is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. CVSS score: 7.2.
Read brief →
Aug 4, 2026
Vendor advisory
Critical vendor advisory
CVE-2026-61515
Puwell · IP Camera firmware
Puwell IP Camera firmware versions 2.x through 4.x contains an unauthenticated command injection vulnerability that allows remote attackers to execute arbitrary operating system commands by sending a crafted JSON payload to the DebugShell interface exposed on TCP port 34567. Attackers can exploit the lack of authentication and input sanitization in the binary protocol service to pass arbitrary commands directly to the underlying operating system, achieving root-level code execution and complete device compromise.
Operator check
Review CVE-2026-61515 in your asset inventory. Apply patches per vendor guidance and verify IP Camera firmware is not exposed. CVSS score: 9.8.
Read brief →
Aug 4, 2026
Vendor advisory
High-risk advisory
CVE-2026-70479
PyPI · open-webui
Open WebUI: SSRF into internal services via unvalidated sub-resource requests in the Playwright web loader
Operator check
Check whether open-webui is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.
Read brief →
Aug 4, 2026
Vendor advisory
High-risk advisory
CVE-2026-70482
PyPI · open-webui
Open WebUI: Account takeover via OAuth token exchange accepting tokens issued to any client
Operator check
Check whether open-webui is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.
Read brief →
Aug 4, 2026
Vendor advisory
High-risk advisory
CVE-2026-70485
PyPI · open-webui
Open WebUI: Any authenticated user can reach internal services and cloud metadata via NAT64-encoded URLs
Operator check
Check whether open-webui is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.
Read brief →
Aug 4, 2026
Vendor advisory
High-risk advisory
CVE-2026-70486
PyPI · open-webui
Open WebUI: Same-origin XSS to account takeover via terminal file-preview iframe hardcoding allow-same-origin
Operator check
Check whether open-webui is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.
Read brief →
Aug 4, 2026
Vendor advisory
High-risk advisory
CVE-2026-70492
PyPI · open-webui
Open WebUI: Stored XSS via unescaped KaTeX render-error fallback in rendered messages
Operator check
Check whether open-webui is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.
Read brief →
Aug 4, 2026
Vendor advisory
High-risk advisory
CVE-2026-70494
PyPI · open-webui
Open WebUI: A folder write-collaborator can permanently delete the owner's chats by deleting a shared subfolder
Operator check
Check whether open-webui is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.
Read brief →
Aug 3, 2026
Vendor advisory
Critical vendor advisory
CVE-2026-68979
Apache · Nifi
Apache NiFI 1.10.0 through 2.10.0 provide a Parameter Context update REST API method that does not enforce authorization checking on components referencing Parameter values. Updating a Parameter Context can change parameter values that affect referencing components, but framework authorization was limited to read and write privileges on the Parameter Context itself. As a result of the missing authorization, an authenticated user authorized to modify a Parameter Context, but not authorized on referencing components, could alter Parameter values affecting those components. In deployments where a
Operator check
Review CVE-2026-68979 in your asset inventory. Apply patches per vendor guidance and verify Nifi is not exposed. CVSS score: 9.8. EPSS probability: 0.4%; percentile: 28%.
Read brief →
Aug 3, 2026
Vendor advisory
Critical vendor advisory
CVE-2026-68980
Apache · Nifi
Apache NiFi 2.0.0 through 2.10.0 support creating, reading, and deleting Assets associated with Parameter Contexts through the REST API. The framework authorizes asset deletion against the owning Parameter Context using the supplied Parameter Context Identifier and Asset Identifier. The framework performed authorized based on the supplied Parameter Context Identifier without verifying the requested Identifier against the stored Identifier. Apache NiFi installations that do not implement different levels of authorization across Parameter Contexts are not subject to this vulnerability, because t
Operator check
Review CVE-2026-68980 in your asset inventory. Apply patches per vendor guidance and verify Nifi is not exposed. CVSS score: 9.1. EPSS probability: 0.3%; percentile: 18%.
Read brief →
Aug 3, 2026
Vendor advisory
High-risk advisory
CVE-2026-69246
Composer · guzzlehttp/guzzle
Guzzle: Noncanonical host can bypass host-based checks
Operator check
Check whether guzzlehttp/guzzle is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.
Read brief →
Aug 3, 2026
Vendor advisory
Critical vendor advisory
CVE-2026-41452
Krayin · CRM 2.2.4
Krayin CRM 2.2.4 contains a missing authentication vulnerability in the installer middleware that allows unauthenticated remote attackers to overwrite the primary administrator account by sending a crafted HTTP POST request with the X-Requested-With: XMLHttpRequest header to bypass the CanInstall middleware redirect check. Attackers can supply arbitrary name, email, and password values to the admin-config-setup endpoint, which performs an unauthenticated updateOrInsert targeting the hardcoded administrator user ID, enabling full administrative access to all CRM data.
Operator check
Review CVE-2026-41452 in your asset inventory. Apply patches per vendor guidance and verify CRM 2.2.4 is not exposed. CVSS score: 9.8.
Read brief →
Aug 3, 2026
KEV
Known exploited
CVE-2026-18577
N-able · N-central
N-able N-central contains an authentication bypass using an alternate path or channel allows for authentication bypass and account takeover in N-central. This vulnerability is the result of an incomplete patch for CVE-2026-18556.
Operator check
Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
Read brief →
Aug 3, 2026
Vendor advisory
High-risk advisory
CVE-2026-13697
npm · undici
undici vulnerable to cross-user information disclosure and parse-time crash via degenerate private cache directives
Operator check
Check whether undici is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. EPSS probability: 0.3%; percentile: 19%.
Read brief →
Aug 3, 2026
Vendor advisory
High-risk advisory
CVE-2026-18446
npm · fast-uri
fast-uri vulnerable to host confusion via backslash authority introducer
Operator check
Check whether fast-uri is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. EPSS probability: 0.2%; percentile: 13%.
Read brief →
Aug 3, 2026
Vendor advisory
High-risk advisory
CVE-2026-68945
npm · @angular/common
Angular: Cache-Key Ambiguity in HttpTransferCache Leading to Cross-Request Response Reuse and State Poisoning
Operator check
Check whether @angular/common is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. CVSS score: 8.8.
Read brief →
Aug 3, 2026
Vendor advisory
High-risk advisory
CVE-2026-69149
npm · @angular/platform-server
Angular SSR: Missing Fallback Raw-Content Serialization Escaping leads to Cross-Site Scripting (XSS)
Operator check
Check whether @angular/platform-server is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. CVSS score: 8.6.
Read brief →
Aug 3, 2026
Vendor advisory
High-risk advisory
CVE-2026-69151
npm · @angular/compiler
Angular i18n: Cross-Site Scripting (XSS) via event-handler attributes
Operator check
Check whether @angular/compiler is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. CVSS score: 7.6.
Read brief →
Aug 3, 2026
Vendor advisory
High-risk advisory
CVE-2026-69152
npm · brace-expansion
brace-expansion: DoS via unbounded intermediate arrays, bypassing the CVE-2026-14257 mitigation
Operator check
Check whether brace-expansion is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.
Read brief →
Aug 3, 2026
Vendor advisory
High-risk advisory
CVE-2026-69185
npm · socket.io-parser
Socket.IO: Zero-attachment Memory Exhaustion
Operator check
Check whether socket.io-parser is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.
Read brief →
Aug 3, 2026
Vendor advisory
High-risk advisory
CVE-2026-69192
npm · ip-address
ip-address: Address4 decodes leading-zero octets as decimal while resolvers decode them as octal, allowing SSRF and trust-boundary bypass
Operator check
Check whether ip-address is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. CVSS score: 7.7.
Read brief →
Aug 3, 2026
Vendor advisory
High-risk advisory
CVE-2026-69240
npm · sequelize
Sequelize: SQL Injection (Oracle DB)
Operator check
Check whether sequelize is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.
Read brief →
Aug 3, 2026
Vendor advisory
High-risk advisory
CVE-2026-69244
PyPI · aiohttp
AIOHTTP: Out-of-bounds heap read in C HTTP response parser error path (malformed chunked response)
Operator check
Check whether aiohttp is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. CVSS score: 7.1.
Read brief →
Aug 3, 2026
Vendor advisory
High-risk advisory
CVE-2026-69247
PyPI · cryptography
cryptography: PKCS#7 EnvelopedData decryption exposes a Bleichenbacher oracle through distinguishable errors and timing
Operator check
Check whether cryptography is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. CVSS score: 8.2.
Read brief →
Aug 3, 2026
Vendor advisory
High-risk advisory
CVE-2026-69249
PyPI · cryptography
python-cryptography: Duplicate self-signed intermediates can cause exponential path-building
Operator check
Check whether cryptography is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. CVSS score: 8.7.
Read brief →
Aug 3, 2026
Vendor advisory
High-risk advisory
PyPI · GitPython
GitPython: Unguarded git option forwarding in IndexFile.checkout() and TagReference.create() enables arbitrary file overwrite and arbitrary file read
Operator check
Check whether GitPython is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.
Read brief →
Jul 31, 2026
Vendor advisory
High-risk advisory
CVE-2026-53599
Composer · redaxo/source
Redaxo has a Mediapool isAllowedExtension bypass via multi-segment filename that leads to authenticated RCE on Apache mod_php multi-extension handlers
Operator check
Check whether redaxo/source is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.
Read brief →
Jul 31, 2026
Vendor advisory
High-risk advisory
CVE-2026-68500
Composer · sylius/mollie-plugin
Sylius Mollie Plugin vulnerable to payment status forgery via the payment webhook
Operator check
Check whether sylius/mollie-plugin is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. EPSS probability: 0.4%; percentile: 31%.
Read brief →
Jul 31, 2026
Vendor advisory
High-risk advisory
CVE-2026-52855
Go · github.com/pterodactyl/wings
Wings exposes node configuration secrets through egg configuration-file templating
Operator check
Check whether github.com/pterodactyl/wings is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.
Read brief →
Jul 31, 2026
Vendor advisory
High-risk advisory
CVE-2026-52856
Go · github.com/pterodactyl/wings
Wings: Maliciously crafted packet during SFTP connection handshake causes denial of service
Operator check
Check whether github.com/pterodactyl/wings is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. EPSS probability: 0.3%; percentile: 26%.
Read brief →
Jul 31, 2026
Vendor advisory
High-risk advisory
CVE-2026-54725
Go · github.com/bank-vaults/vault-secrets-webhook
vault-addr annotation SSRF -- webhook makes outbound HTTP call to attacker URL during admission; vault-serviceaccount enables cluster-wide SA token theft via TokenRequest API
Operator check
Check whether github.com/bank-vaults/vault-secrets-webhook is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.
Read brief →
Jul 31, 2026
Vendor advisory
High-risk advisory
CVE-2026-54910
Go · github.com/gtsteffaniak/filebrowser/backend
FileBrowser Quantum's path traversal issue in subtitle handler allows any authenticated user to read arbitrary files
Operator check
Check whether github.com/gtsteffaniak/filebrowser/backend is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. EPSS probability: 0.3%; percentile: 23%.
Read brief →
Jul 31, 2026
Vendor advisory
High-risk advisory
CVE-2026-41695
Maven · org.springframework.data:spring-data-commons
Spring Data: Unbounded property-path cache keyed by externally-supplied path string
Operator check
Check whether org.springframework.data:spring-data-commons is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. EPSS probability: 0.4%; percentile: 29%.
Read brief →
Jul 31, 2026
Vendor advisory
High-risk advisory
CVE-2026-56819
Maven · io.netty:netty-codec-http2
Netty: HTTP/2 decompression leaks ByteBuf reference count when the decompressor channel is already closed (Direct memory leak / OOM DoS)
Operator check
Check whether io.netty:netty-codec-http2 is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. EPSS probability: 0.4%; percentile: 29%.
Read brief →
Jul 31, 2026
Coordinated disclosure
Patch review
Multiple vendors · VPS.org one-click deployment templates contain multiple vulnerabilities
Overview VPS.org's one-click deployment templates provision services with default passwords and predefined network bindings instead of generating randomized secrets or applying per-deployment hardening measures. Description VPS.org is a cloud and virtual private server hosting provider that offers a library of templates for quickly provisioning common applications and services. Multiple vulnerabilities exist in the one-click deployment templates feature. These vulnerabilities stem from the same root cause: content is directly instantiated from static templates, using default passwords and static secrets with no deployment-specific randomization or interface-binding hardening at provisioning time. CVE-2026-16503 The Supabase template provides an instance of PostgreSQL that is bound to all network interfaces (0.0.0.0:5432) and uses the... Related CVEs: CVE-2026-16503, CVE-2026-16504.
Operator check
Review the CERT/CC Vulnerability Note and compare the affected vendor and product list against your inventory. Apply vendor fixes or compensating controls for VPS.org one-click deployment templates contain multiple vulnerabilities where available.
Read brief →
Jul 31, 2026
Vendor advisory
High-risk advisory
CVE-2026-52887
npm · @nocobase/plugin-notification-in-app-message
NocoBase: SQL injection in /api/myInAppChannels:list filter to PG-superuser RCE
Operator check
Check whether @nocobase/plugin-notification-in-app-message is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. EPSS probability: 0.6%; percentile: 45%.
Read brief →
Jul 31, 2026
Vendor advisory
High-risk advisory
CVE-2026-53608
npm · @apostrophecms/seo
@apostrophecms/seo Vulnerable to Stored XSS via Unsanitized Google Analytics / GTM ID Injected into Script Tag
Operator check
Check whether @apostrophecms/seo is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. EPSS probability: 0.2%; percentile: 11%.
Read brief →
Jul 31, 2026
Vendor advisory
High-risk advisory
CVE-2026-53609
npm · apostrophe
Apostrophe has Server-Side Prototype Pollution in apos.util.set via patch operators that leads to process-wide authorization bypass
Operator check
Check whether apostrophe is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. EPSS probability: 0.2%; percentile: 15%.
Read brief →
Jul 31, 2026
Vendor advisory
High-risk advisory
CVE-2026-54729
npm · dssrf
dssrf: any users using 1.1.1.1 DNS is impacted by SSRF
Operator check
Check whether dssrf is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. CVSS score: 8.7.
Read brief →
Jul 31, 2026
Vendor advisory
High-risk advisory
CVE-2026-54737
npm · @phun-ky/defaults-deep
@phun-ky/defaults-deep Has a Prototype Pollution issue via Unsafe Recursive Property Merging
Operator check
Check whether @phun-ky/defaults-deep is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.
Read brief →
Jul 31, 2026
Vendor advisory
High-risk advisory
CVE-2026-55100
npm · hashi-vault-js
hashi-vault-js has a path traversal and query parameter injection
Operator check
Check whether hashi-vault-js is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. CVSS score: 8.7.
Read brief →
Jul 31, 2026
Vendor advisory
High-risk advisory
CVE-2026-58263
npm · jodit
Jodit Editor: Mutation XSS in jodit clean-html via a MathML/style rawtext carrier
Operator check
Check whether jodit is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. EPSS probability: 0.2%; percentile: 8%.
Read brief →
Jul 31, 2026
Vendor advisory
High-risk advisory
npm · @dynatrace-oss/dynatrace-mcp-server
`@dynatrace-oss/dynatrace-mcp-server` has Unauthenticated HTTP MCP Tool Invocation
Operator check
Check whether @dynatrace-oss/dynatrace-mcp-server is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.
Read brief →
Jul 31, 2026
Vendor advisory
High-risk advisory
CVE-2026-12061
PyPI · nltk
Natural Language Toolkit (NLTK): ReDoS in NLTK ReviewsCorpusReader FEATURES regex
Operator check
Check whether nltk is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.
Read brief →
Jul 31, 2026
Vendor advisory
High-risk advisory
CVE-2026-12072
PyPI · nltk
Natural Language Toolkit (NLTK): Path Traversal in NKJPCorpusReader leads to Arbitrary File Read and bypasses the nltk.pathsec sandbox (ENFORCE=True)
Operator check
Check whether nltk is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.
Read brief →
Jul 31, 2026
Vendor advisory
High-risk advisory
CVE-2026-12074
PyPI · nltk
Natural Language Toolkit (NLTK) has path traversal in FramenetCorpusReader.frame() that allows arbitrary XML file read, bypassing the nltk.pathsec sandbox (ENFORCE=True)
Operator check
Check whether nltk is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.
Read brief →
Jul 31, 2026
Vendor advisory
High-risk advisory
CVE-2026-12075
PyPI · nltk
Natural Language Toolkit (NLTK): DNS-rebinding SSRF filter bypass in nltk.pathsec.urlopen (nltk.download / nltk.data.load) defeats ENFORCE mode
Operator check
Check whether nltk is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.
Read brief →
Jul 31, 2026
Vendor advisory
High-risk advisory
CVE-2026-53500
PyPI · thumbor
Thumbor treats ALLOWED_SOURCES string patterns as unescaped regex, allowing hostname bypass via wildcard dot
Operator check
Check whether thumbor is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.
Read brief →
Jul 31, 2026
Vendor advisory
High-risk advisory
CVE-2026-53501
PyPI · thumbor
Thumbor has HMAC validation bypass via multiple .replace() calls when removing URL signature
Operator check
Check whether thumbor is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.
Read brief →
Jul 31, 2026
Vendor advisory
High-risk advisory
CVE-2026-53502
PyPI · thumbor
Thumbor has path traversal via post-validation URL decoding bypass in file_loader
Operator check
Check whether thumbor is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. CVSS score: 8.7.
Read brief →
Jul 31, 2026
Vendor advisory
High-risk advisory
CVE-2026-53503
PyPI · thumbor
Thumbor convolution filter allows divide-by-zero in C extension leading to remote DoS
Operator check
Check whether thumbor is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.
Read brief →
Jul 31, 2026
Vendor advisory
High-risk advisory
CVE-2026-53504
PyPI · thumbor
Thumbor has Regex Denial of Service (ReDoS) in `convolution` filter
Operator check
Check whether thumbor is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.
Read brief →
Jul 31, 2026
Vendor advisory
High-risk advisory
CVE-2026-53505
PyPI · thumbor
Thumbor proportion filter allows unbounded post-transform resize leading to remote DoS
Operator check
Check whether thumbor is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.
Read brief →
Jul 31, 2026
Vendor advisory
High-risk advisory
CVE-2026-53510
RubyGems · savon
Savon::Model evaluates WSDL operation names as Ruby source
Operator check
Check whether savon is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.
Read brief →
Jul 30, 2026
Vendor advisory
High-risk advisory
CVE-2026-67437
Go · github.com/OliveTin/OliveTin
OliveTin: Unauthenticated DoS via OAuth2 State Memory Exhaustion (Unbounded Map Growth)
Operator check
Check whether github.com/OliveTin/OliveTin is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. EPSS probability: 0.4%; percentile: 28%.
Read brief →
Jul 30, 2026
Coordinated disclosure
Patch review
Multiple vendors · foreUP golf management platform's web API
Overview Two vulnerabilities in the REST API were found in Golf Compete foreUP. The first exposes the merchant, Finix, API credentials directly in customer record responses, allowing any user to obtain and use the payment processor account. The second is a missing object-level authorization check, which lets a user retrieve any other customer's full profile, payment token, and transaction history by changing the golfer_id in the request path. Description Golf Compete foreUP provides cloud-based golf course management software to over 2,000 golf courses. They offer tools that allow the management of customers, inventory, tee times, food & beverages, marketing, billing, etc. The vulnerabilities identified are listed below. CVE-2026-15657 A vulnerability in the foreUP customer REST API exposes merchant credentials. Each customer record... Related CVEs: CVE-2026-15657, CVE-2026-15658.
Operator check
Review the CERT/CC Vulnerability Note and compare the affected vendor and product list against your inventory. Apply vendor fixes or compensating controls for foreUP golf management platform's web API where available.
Read brief →
Jul 30, 2026
Vendor advisory
Critical vendor advisory
CVE-2025-4318
npm · @aws-amplify/codegen-ui-react
AWS Amplify Studio UI Component Properties Has an Input Validation Issue
Operator check
Check whether @aws-amplify/codegen-ui-react is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. CVSS score: 9.5. EPSS probability: 0.9%; percentile: 57%.
Read brief →
Jul 30, 2026
Vendor advisory
High-risk advisory
CVE-2026-54722
npm · dssrf
dssrf has an SSRF bypass with remove_at_symbol_in_string
Operator check
Check whether dssrf is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. CVSS score: 8.7.
Read brief →
Jul 30, 2026
Vendor advisory
Critical vendor advisory
CVE-2026-66418
OpenClaw · Dashboard v3.0.0
OpenClaw Dashboard v3.0.0 contains a stored cross-site scripting vulnerability that allows unauthenticated remote attackers to inject arbitrary HTML and script payloads by submitting a crafted username in a failed login POST request, which is recorded verbatim in the audit log. When an administrator opens the notification panel, the unescaped log entry is rendered via innerHTML with a permissive Content-Security-Policy allowing inline event handlers, enabling the attacker-supplied payload to execute in the administrator's session and interact with authenticated endpoints including agent instru
Operator check
Review CVE-2026-66418 in your asset inventory. Apply patches per vendor guidance and verify Dashboard v3.0.0 is not exposed. CVSS score: 9.3.
Read brief →
Jul 30, 2026
Vendor advisory
Critical vendor advisory
CVE-2026-66421
OpenClaw · Dashboard
OpenClaw Dashboard contains a stored cross-site scripting vulnerability that allows unauthenticated remote attackers to execute arbitrary JavaScript in the administrator's browser session by injecting HTML markup into agent transcript messages processed through the sessions API. Attackers can craft a message containing inline event handler payloads such as an img tag with an onerror attribute within the 60-character rendering budget, which is stored in the session transcript and interpolated unsanitized into innerHTML on the default landing page, allowing theft of session tokens and unauthoriz
Operator check
Review CVE-2026-66421 in your asset inventory. Apply patches per vendor guidance and verify Dashboard is not exposed. CVSS score: 9.3.
Read brief →
Jul 30, 2026
Vendor advisory
High-risk advisory
CVE-2026-67424
PyPI · flyto-core
Flyto2 Core: Guarded HTTP modules follow redirects into internal space without per-hop SSRF revalidation
Operator check
Check whether flyto-core is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. EPSS probability: 0.2%; percentile: 15%.
Read brief →
Jul 30, 2026
Vendor advisory
High-risk advisory
CVE-2026-67425
PyPI · flyto-core
Flyto2 Core: LLM/API keys leak to an attacker-controlled base_url
Operator check
Check whether flyto-core is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. EPSS probability: 0.3%; percentile: 24%.
Read brief →
Jul 30, 2026
Vendor advisory
High-risk advisory
CVE-2026-67426
PyPI · flyto-core
Flyto2 Core: Unauthenticated flyto-verification /run: callback_url SSRF and internal runner-secret exfiltration
Operator check
Check whether flyto-core is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. EPSS probability: 0.3%; percentile: 21%.
Read brief →
Jul 30, 2026
Vendor advisory
High-risk advisory
CVE-2026-67427
PyPI · flyto-core
Flyto2 Core: ${env.VAR} interpolation reads any env secret despite env.get being denylisted
Operator check
Check whether flyto-core is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. EPSS probability: 0.3%; percentile: 27%.
Read brief →
Jul 30, 2026
Vendor advisory
High-risk advisory
CVE-2026-67428
PyPI · flyto-core
Flyto2 Core: Multiple HTTP-family modules fetch client-controlled URLs without the SSRF guard their siblings apply (SSRF to internal/metadata)
Operator check
Check whether flyto-core is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. EPSS probability: 0.3%; percentile: 26%.
Read brief →
Jul 30, 2026
Vendor advisory
High-risk advisory
CVE-2026-67429
PyPI · flyto-core
Flyto2 Core: Arbitrary file write via image.download (and other file-writing modules)
Operator check
Check whether flyto-core is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. EPSS probability: 0.5%; percentile: 40%.
Read brief →
Jul 30, 2026
Vendor advisory
Critical vendor advisory
CVE-2026-66066
RubyGems · activestorage
Active Storage has possible arbitrary file read and remote code execution in Active Storage variant processing
Operator check
Check whether activestorage is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. CVSS score: 9.5.
Read brief →
Jul 30, 2026
Vendor advisory
High-risk advisory
CVE-2026-67431
RubyGems · mcp
MCP Ruby SDK: Ruby SSE Session Poisoning
Operator check
Check whether mcp is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. CVSS score: 8.3. EPSS probability: 0.3%; percentile: 20%.
Read brief →
Jul 30, 2026
Vendor advisory
High-risk advisory
CVE-2026-67432
RubyGems · mcp
MCP Ruby SDK: Unbounded JSON-RPC request body causes uncontrolled memory allocation in StreamableHTTPTransport
Operator check
Check whether mcp is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. EPSS probability: 0.4%; percentile: 36%.
Read brief →
Jul 30, 2026
Coordinated disclosure
Patch review
SGLang · SGLang
Overview Six vulnerabilities have been discovered within the SGLang project, including remote code execution (RCE), server-side request forgery (SSRF), local file read, credential leakage, and model weight exfiltration on a target server. Exploitation does not require authentication in most cases, and some vulnerabilities require only network access with no API keys or user credentials. At the time of publication, no patches are available from the project maintainers, and coordination attempts have been unsuccessful. Description SGLang is an open-source framework for serving large language models (LLMs) and multimodal AI models, supporting models such as Qwen, DeepSeek, Mistral, and Skywork, and is compatible with OpenAI APIs. Six vulnerabilities have been discovered within the tool and are tracked as follows: CVE-2026-15969 SGLang... Related CVEs: CVE-2026-14890, CVE-2026-15969, CVE-2026-15971, CVE-2026-15974.
Operator check
Review the CERT/CC Vulnerability Note and compare the affected vendor and product list against your inventory. Apply vendor fixes or compensating controls for SGLang where available.
Read brief →
Jul 29, 2026
Vendor advisory
Critical vendor advisory
CVE-2026-41939
Care · Everywhere Gateway 14.3.10
Care Everywhere Gateway 14.3.10 contains a hard-coded credentials vulnerability in the bundled WildFly 8.2.0.Final management interface that allows unauthenticated remote attackers to gain administrative access by using default credentials identical across all installations. Attackers can authenticate to the exposed WildFly management console on port 20990 and deploy a malicious Web Application Archive file through the Deployments interface to achieve remote code execution as the Windows machine account. Version 14.x.x was declared end-of-life (EOL) in 2017 and future releases have addressed t
Operator check
Review CVE-2026-41939 in your asset inventory. Apply patches per vendor guidance and verify Everywhere Gateway 14.3.10 is not exposed. CVSS score: 9.8.
Read brief →
Jul 29, 2026
KEV
Known exploited
CVE-2026-20316
Cisco · Secure Firewall Management Center (FMC)
Cisco Secure Firewall Management Center (FMC) formerly known as Firepower Management Center contains a use of hard-coded password vulnerability that could allow an unauthenticated, remote attacker to log in to an affected device using a low-privileged account to access sensitive data within the impacted systems.
Operator check
Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
Read brief →
Jul 29, 2026
Vendor advisory
High-risk advisory
CVE-2026-55651
Composer · alextselegidis/easyappointments
Easy!Appointments Vulnerable to Appointments Takeover via Excessive Data Exposure
Operator check
Check whether alextselegidis/easyappointments is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. EPSS probability: 0.2%; percentile: 8%.
Read brief →
Jul 29, 2026
Coordinated disclosure
Patch review
Develar · app-builder (zipx.Unzip) via Symlink Following on macOS (APFS)
Overview A vulnerability in the zipx.Unzip extraction routine of Develar’s app-builder allows an attacker to overwrite arbitrary files on macOS using Apple File System (APFS). The issue arises from a combination of Unicode normalization collisions and unsafe symlink-following behavior. APFS treats certain Unicode equivalent filenames as identical (e.g., ß ↔ ss), while app builder performs no canonical normalization before validating or writing paths. Description Develar’s app-builder is a command‑line build tool used heavily in the Electron ecosystem to package, sign, notarize, and produce distributable application bundles for macOS, Windows, and Linux. It is popular because it is a transitive dependency of electron-builder, one of the most widely used packaging tools for Electron apps. The vulnerability arises from how the zipx.Unzip...
Operator check
Review the CERT/CC Vulnerability Note and compare the affected vendor and product list against your inventory. Apply vendor fixes or compensating controls for app-builder (zipx.Unzip) via Symlink Following on macOS (APFS) where available.
Read brief →
Jul 29, 2026
Vendor advisory
High-risk advisory
CVE-2026-49755
erlang · req
Req vulnerable to unbounded archive/compression extraction triggered by response content-type
Operator check
Check whether req is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. CVSS score: 8.2. EPSS probability: 0.4%; percentile: 36%.
Read brief →
Jul 29, 2026
Vendor advisory
High-risk advisory
CVE-2026-54680
Go · github.com/kube-logging/logging-operator
Logging operator has Fluentd configuration injection that allows remote code execution
Operator check
Check whether github.com/kube-logging/logging-operator is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.
Read brief →
Jul 29, 2026
Vendor advisory
High-risk advisory
CVE-2026-54693
Go · github.com/zitadel/zitadel
ZITADEL Users Can Self-Verify Email/Phone via API
Operator check
Check whether github.com/zitadel/zitadel is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. CVSS score: 8.2.
Read brief →
Jul 29, 2026
Vendor advisory
High-risk advisory
CVE-2026-54735
Go · github.com/prebid/prebid-server/v4
prebid-server's request forgery vulnerability allows for possible host environment data extraction
Operator check
Check whether github.com/prebid/prebid-server/v4 is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.
Read brief →
Jul 29, 2026
Vendor advisory
High-risk advisory
Go · github.com/tinfoil-factory/netfoil
netfoil: Incorrect block responses could lead to localhost traffic
Operator check
Check whether github.com/tinfoil-factory/netfoil is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. CVSS score: 7.4.
Read brief →
Jul 29, 2026
Vendor advisory
High-risk advisory
CVE-2026-50559
Maven · io.quarkus:quarkus-vertx-http
Quarkus: Authentication/Authorization Bypass via Advanced Path Normalization Vulnerabilities
Operator check
Check whether io.quarkus:quarkus-vertx-http is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. EPSS probability: 0.5%; percentile: 38%.
Read brief →
Jul 29, 2026
Vendor advisory
High-risk advisory
CVE-2026-54078
Maven · org.verapdf:validation-model
veraPDF Validation XXE via Rich Text
Operator check
Check whether org.verapdf:validation-model is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. CVSS score: 8.7.
Read brief →
Jul 29, 2026
Vendor advisory
High-risk advisory
CVE-2026-54079
Maven · org.verapdf:validation-model
veraPDF Validation XXE via XFA
Operator check
Check whether org.verapdf:validation-model is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. CVSS score: 8.7.
Read brief →
Jul 29, 2026
Vendor advisory
High-risk advisory
CVE-2026-11393
npm · @aws/agentcore
AgentCore CLI Bedrock Agent Import Vulnerable to Code Injection via Improper Triple-Quote Escaping
Operator check
Check whether @aws/agentcore is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. CVSS score: 8.8. EPSS probability: 0.3%; percentile: 25%.
Read brief →
Jul 29, 2026
Vendor advisory
High-risk advisory
CVE-2026-54660
npm · swagger-typescript-api
swagger-typescript-api vulnerable to authorization-token exfiltration via spec `$ref`
Operator check
Check whether swagger-typescript-api is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.
Read brief →
Jul 29, 2026
Vendor advisory
High-risk advisory
CVE-2026-54661
npm · swagger-typescript-api
swagger-typescript-api vulnerable to code injection via unescaped `servers[0].url` in axios http-client template
Operator check
Check whether swagger-typescript-api is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.
Read brief →
Jul 29, 2026
Vendor advisory
High-risk advisory
CVE-2026-54662
npm · swagger-typescript-api
swagger-typescript-api vulnerable to code injection via unescaped `servers[0].url` in fetch http-client template
Operator check
Check whether swagger-typescript-api is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.
Read brief →
Jul 29, 2026
Vendor advisory
High-risk advisory
CVE-2026-54664
npm · swagger-typescript-api
swagger-typescript-api vulnerable to code injection via unescaped enum string values
Operator check
Check whether swagger-typescript-api is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.
Read brief →
Jul 29, 2026
Vendor advisory
High-risk advisory
CVE-2026-54666
npm · swagger-typescript-api
swagger-typescript-api vulnerable to code injection via unescaped OpenAPI path strings in generated method bodies
Operator check
Check whether swagger-typescript-api is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.
Read brief →
Jul 29, 2026
Coordinated disclosure
Patch review
OPeNDAP · Hyrax
Overview A vulnerability has been discovered in the OPeNDAP Hyrax software solution. A remote attacker with the ability to submit crafted requests to an affected Hyrax instance could cause the application to communicate with unauthorized remote systems. Under certain conditions, the vulnerability may also result in the unintended disclosure of user authentication tokens to unauthorized destinations. Description CVE-2026-16637 OPeNDAP Hyrax is vulnerable to Server Side Request Forgery (SSRF) and credential disclosure via unvalidated HTTP redirects that bypass the AllowedHosts allowlist and leak Earthdata headers (User-Id, Echo-Token) to attacker-controlled endpoints. OPeNDAP Hyrax is an open-source data server software that enables remote access to scientific datasets over the internet using the OPeNDAP protocol. It allows users to query... Related CVEs: CVE-2026-16637.
Operator check
Review the CERT/CC Vulnerability Note and compare the affected vendor and product list against your inventory. Apply vendor fixes or compensating controls for Hyrax where available.
Read brief →
Jul 29, 2026
Vendor advisory
High-risk advisory
CVE-2026-54574
PyPI · proot-distro
`proot-distro install` has a Symlink Escape (Arbitrary Host File Write) via Malicious Tar Archive
Operator check
Check whether proot-distro is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.
Read brief →
Jul 29, 2026
Vendor advisory
High-risk advisory
CVE-2026-54727
PyPI · proot-distro
proot-distro has a Container Isolation Bypass via Crafted Restore Archive
Operator check
Check whether proot-distro is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.
Read brief →
Jul 28, 2026
Vendor advisory
High-risk advisory
CVE-2026-54588
Composer · poweradmin/poweradmin
Poweradmin has Host Header Injection in OIDC redirect_uri, SAML ACS/SLO URL, and Logout Redirect Construction.
Operator check
Check whether poweradmin/poweradmin is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. EPSS probability: 0.3%; percentile: 24%.
Read brief →
Jul 28, 2026
Vendor advisory
High-risk advisory
CVE-2026-54593
Composer · pterodactyl/panel
Pterodactyl's improper JWT scoping allows subuser to upload files when not explicitly granted `file.create` permissions
Operator check
Check whether pterodactyl/panel is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.
Read brief →
Jul 28, 2026
Vendor advisory
High-risk advisory
CVE-2026-61609
Composer · pterodactyl/panel
Pterodactyl's shared global rate-limit key on login and 2FA checkpoint enables unauthenticated panel-wide authentication lockout (DoS)
Operator check
Check whether pterodactyl/panel is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.
Read brief →
Jul 28, 2026
Vendor advisory
High-risk advisory
CVE-2026-50567
Go · github.com/fission/fission
Fission: Zip Slip in pkg/utils/zip.go:Unarchive allows fetcher to write outside the destination directory
Operator check
Check whether github.com/fission/fission is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. EPSS probability: 0.3%; percentile: 22%.
Read brief →
Jul 28, 2026
Vendor advisory
High-risk advisory
CVE-2026-50570
Go · github.com/fission/fission
Fission: Incomplete capability denylist in Environment/Function PodSpec validation allows tenant-added CAP_SYS_TIME and cross-tenant node wall-clock corruption
Operator check
Check whether github.com/fission/fission is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. EPSS probability: 0.3%; percentile: 20%.
Read brief →
Jul 28, 2026
Vendor advisory
High-risk advisory
CVE-2026-54638
Go · github.com/gotd/td
td has pre-auth denial of service via unbounded memory allocation in proto.UnencryptedMessage.Decode
Operator check
Check whether github.com/gotd/td is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.
Read brief →
Jul 28, 2026
Vendor advisory
High-risk advisory
CVE-2026-54650
Go · github.com/bablilayoub/openhole
openhole-server vulnerable to path traversal via URL-decoded request path
Operator check
Check whether github.com/bablilayoub/openhole is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.
Read brief →
Jul 28, 2026
Vendor advisory
High-risk advisory
CVE-2026-54719
Go · github.com/patrickhener/goshs
goshs: File-based .goshs ACL authorization bypass via the ?bulk zip-download route (unauthenticated read; residual of GHSA-wvhv-qcqf-f3cx)
Operator check
Check whether github.com/patrickhener/goshs is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.
Read brief →
Jul 28, 2026
Vendor advisory
High-risk advisory
CVE-2026-62325
Go · github.com/patrickhener/goshs/v2
goshs SFTP authentication bypass via empty password (incomplete fix of CVE-2026-40884)
Operator check
Check whether github.com/patrickhener/goshs/v2 is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.
Read brief →
Jul 28, 2026
Vendor advisory
High-risk advisory
CVE-2026-64863
Go · goshs.de/goshs/v2
goshs --no-delete WebDAV MOVE bypass allows file deletion/overwrite
Operator check
Check whether goshs.de/goshs/v2 is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.
Read brief →
Jul 28, 2026
Coordinated disclosure
Patch review
LAN-side · management interface
Overview Firmware versions 2.7.7 and earlier of the Arris BGW210-700 residential gateway contain an authentication bypass vulnerability, tracked as CVE-2026-16771, that allows any unauthenticated LAN-side user to read sensitive configuration data and modify device settings through web management endpoints. Although this vulnerability was recently discovered, the majority of in-service gateways are not expected to be running the affected version. Only devices that have not received automated ISP-managed firmware updates since version 2.7.7 in 2020 are vulnerable. Description The Arris BGW210-700 is a residential gateway used widely in AT&T deployments to provide routing, wireless networking, and wide-area network (WAN) connectivity for home users. The device exposes a browser-based management interface on the local-area network (LAN) side... Related CVEs: CVE-2026-16771.
Operator check
Review the CERT/CC Vulnerability Note and compare the affected vendor and product list against your inventory. Apply vendor fixes or compensating controls for management interface where available.
Read brief →
Jul 28, 2026
Vendor advisory
High-risk advisory
CVE-2026-54609
Maven · com.quietterminal:qti-neon
QTINeon has unauthenticated relay-to-host amplification via unbounded RECONNECT_REQUEST forwarding
Operator check
Check whether com.quietterminal:qti-neon is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.
Read brief →
Jul 28, 2026
Vendor advisory
High-risk advisory
CVE-2026-54639
npm · style-dictionary
Style Dictionary - Prototype Pollution in convertTokenData utility function
Operator check
Check whether style-dictionary is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. EPSS probability: 0.1%; percentile: 3%.
Read brief →
Jul 28, 2026
Vendor advisory
High-risk advisory
CVE-2026-54658
npm · @hypequery/clickhouse
@hypequery/clickhouse has SQL Injection in parameter escaping that allows arbitrary SQL execution
Operator check
Check whether @hypequery/clickhouse is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.
Read brief →
Jul 28, 2026
Vendor advisory
High-risk advisory
CVE-2026-32203
NuGet · System.Security.Cryptography.Xml
Microsoft Security Advisory CVE-2026-32203 – .NET and Visual Studio Denial of Service Vulnerability
Operator check
Check whether System.Security.Cryptography.Xml is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. EPSS probability: 1.6%; percentile: 73%.
Read brief →
Jul 28, 2026
Vendor advisory
High-risk advisory
CVE-2026-54632
NuGet · SIPSorcery
SIPSorcery: Malformed UDP packet on the RTP/ICE socket can remotely terminate a media session (DoS)
Operator check
Check whether SIPSorcery is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.
Read brief →
Jul 28, 2026
Vendor advisory
High-risk advisory
CVE-2026-54621
PyPI · datamodel-code-generator
`datamodel-code-generator` vulnerable to code injection via unescaped carriage return in GraphQL Union description
Operator check
Check whether datamodel-code-generator is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.
Read brief →
Jul 28, 2026
Vendor advisory
High-risk advisory
CVE-2026-54635
PyPI · pytonapi
pytonapi has a Webhook Custom Path Authentication Bypass
Operator check
Check whether pytonapi is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.
Read brief →
Jul 28, 2026
Vendor advisory
High-risk advisory
CVE-2026-54653
PyPI · datamodel-code-generator
`datamodel-code-generator` vulnerable to code injection in via attacker-controlled `default_factory` schema field
Operator check
Check whether datamodel-code-generator is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.
Read brief →
Jul 28, 2026
Vendor advisory
High-risk advisory
CVE-2026-54654
PyPI · datamodel-code-generator
`datamodel-code-generator` vulnerable to code injection via unescaped carriage return in `--extra-template-data` `comment` field
Operator check
Check whether datamodel-code-generator is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.
Read brief →
Jul 28, 2026
Vendor advisory
High-risk advisory
CVE-2026-54655
PyPI · datamodel-code-generator
`datamodel-code-generator` vulnerable to code execution on import via `x-python-type` JSON-Schema extension in datamodel-code-generator
Operator check
Check whether datamodel-code-generator is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.
Read brief →
Jul 28, 2026
Vendor advisory
High-risk advisory
CVE-2026-54656
PyPI · datamodel-code-generator
`datamodel-code-generator` vulnerable to code execution on import via unescaped `validators` entries in --extra-template-data
Operator check
Check whether datamodel-code-generator is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.
Read brief →
Jul 28, 2026
Vendor advisory
High-risk advisory
CVE-2026-54690
PyPI · datamodel-code-generator
datamodel-code-generator vulnerable to SSRF via JSON-Schema `$ref` to HTTP URL (silent by default)
Operator check
Check whether datamodel-code-generator is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.
Read brief →
Jul 28, 2026
Vendor advisory
High-risk advisory
CVE-2026-54691
PyPI · datamodel-code-generator
datamodel-code-generator vulnerable to SSRF via --url: no host/IP validation, follows redirects
Operator check
Check whether datamodel-code-generator is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.
Read brief →
Jul 28, 2026
Vendor advisory
High-risk advisory
CVE-2026-55389
PyPI · datamodel-code-generator
datamodel-code-generator vulnerable to arbitrary local file read via JSON-Schema `$ref` (`file://` and `../` traversal), bypassing `--no-allow-remote-refs`
Operator check
Check whether datamodel-code-generator is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.
Read brief →
Jul 28, 2026
Vendor advisory
High-risk advisory
CVE-2026-55390
PyPI · datamodel-code-generator
datamodel-code-generator vulnerable to arbitrary local file read via XSD `schemaLocation` (`xs:include`/`xs:import`) path traversal, with no remote-ref gate
Operator check
Check whether datamodel-code-generator is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.
Read brief →
Jul 28, 2026
Vendor advisory
High-risk advisory
CVE-2026-55391
PyPI · datamodel-code-generator
datamodel-code-generator vulnerable to SSRF protection bypass via DNS rebinding
Operator check
Check whether datamodel-code-generator is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.
Read brief →
Jul 28, 2026
Vendor advisory
High-risk advisory
CVE-2026-55415
PyPI · datamodel-code-generator
datamodel-code-generator vulnerable to code injection via `x-python-import` / `customTypePath` in generated import statements
Operator check
Check whether datamodel-code-generator is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.
Read brief →
Jul 28, 2026
Vendor advisory
High-risk advisory
CVE-2026-54603
RubyGems · oauth2
OAuth2::Client#request: Protocol-relative redirect Location overrides authority, leaking bearer Authorization to attacker host
Operator check
Check whether oauth2 is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.
Read brief →
Jul 28, 2026
Vendor advisory
High-risk advisory
CVE-2026-54605
RubyGems · oauth
OAuth: Cross-origin token-request redirects can expose signed request metadata
Operator check
Check whether oauth is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.
Read brief →
Jul 28, 2026
Vendor advisory
Critical vendor advisory
CVE-2026-46428
Rust · lettre
lettre has TLS hostname verification disabled when using Boring TLS backend
Operator check
Check whether lettre is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. CVSS score: 9.1. EPSS probability: 0.2%; percentile: 9%.
Read brief →
Jul 27, 2026
Vendor advisory
Critical vendor advisory
CVE-2026-48144
Apache · Thrift
Improper Validation of Certificate with Host Mismatch vulnerability in Apache Thrift c_glib bindings. This issue affects Apache Thrift: before 0.24.0. Users are recommended to upgrade to version 0.24.0, which fixes the issue.
Operator check
Review CVE-2026-48144 in your asset inventory. Apply patches per vendor guidance and verify Thrift is not exposed. CVSS score: 9.1.
Read brief →
Jul 27, 2026
Vendor advisory
Critical vendor advisory
CVE-2026-55971
Apache · Thrift
Heap-based Buffer Overflow vulnerability in Apache Thrift C++ bindings. This issue affects Apache Thrift: before 0.24.0. Users are recommended to upgrade to version 0.24.0, which fixes the issue.
Operator check
Review CVE-2026-55971 in your asset inventory. Apply patches per vendor guidance and verify Thrift is not exposed. CVSS score: 9.8.
Read brief →
Jul 27, 2026
Vendor advisory
Critical vendor advisory
CVE-2026-58023
Apache · Thrift
Out-of-bounds Read vulnerability in Apache Thrift c_glib bindings. This issue affects Apache Thrift: before 0.24.0. Users are recommended to upgrade to version 0.24.0, which fixes the issue.
Operator check
Review CVE-2026-58023 in your asset inventory. Apply patches per vendor guidance and verify Thrift is not exposed. CVSS score: 9.1.
Read brief →
Jul 27, 2026
Vendor advisory
Critical vendor advisory
CVE-2026-58662
Apache · Thrift
Improper Validation of Specified Quantity in Input, Out-of-bounds Read vulnerability in Apache Thrift C++ bindings. This issue affects Apache Thrift: before 0.24.0. Users are recommended to upgrade to version 0.24.0, which fixes the issue.
Operator check
Review CVE-2026-58662 in your asset inventory. Apply patches per vendor guidance and verify Thrift is not exposed. CVSS score: 9.1.
Read brief →
Jul 27, 2026
KEV
Known exploited
CVE-2026-16812
Arista · VeloCloud Orchestrator
Arista VeloCloud Orchestrator On-Prem contains an OS command injection vulnerability that may allow a remote attacker to access privileged internal functionality and impact the VCO host. Successful exploitation may compromise the confidentiality, integrity, and availability of the orchestrator and data managed by the orchestrator.
Operator check
Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
Read brief →
Jul 27, 2026
KEV
Known exploited
CVE-2025-68686
Fortinet · FortiOS
Fortinet FortiOS contains an exposure of sensitive information to an unauthorized actor vulnerability. This may allow a remote unauthenticated attacker to bypass the patch developed for the symbolic link persistency mechanism observed in some post-exploit cases, via crafted HTTP requests. An attacker would need first to have compromised the product via another vulnerability, at filesystem level.
Operator check
Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
Read brief →
Jul 24, 2026
Vendor advisory
High-risk advisory
Composer · pheditor/pheditor
Pheditor: Authentication Bypass in Forced Password-Change Flow via Unverified Current Password
Operator check
Check whether pheditor/pheditor is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.
Read brief →
Jul 24, 2026
Vendor advisory
High-risk advisory
Go · go.etcd.io/etcd/v3
etcd: `tlsListener.acceptLoop` spawns unbounded handshake goroutines with no deadline
Operator check
Check whether go.etcd.io/etcd/v3 is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. CVSS score: 8.7.
Read brief →
Jul 24, 2026
Vendor advisory
High-risk advisory
Go · github.com/jandedobbeleer/oh-my-posh
Oh My Posh: Arbitrary command execution via template injection in the path segment
Operator check
Check whether github.com/jandedobbeleer/oh-my-posh is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.
Read brief →
Jul 24, 2026
Vendor advisory
High-risk advisory
Go · github.com/OpenListTeam/OpenList/v4
OpenList: Authenticated users can rename files outside their base path via batch rename `src_name` traversal
Operator check
Check whether github.com/OpenListTeam/OpenList/v4 is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.
Read brief →
Jul 24, 2026
Vendor advisory
High-risk advisory
Go · github.com/getkin/kin-openapi
kin-openapi: ValidationHandler.Load() Fail-Open Authentication Bypass via NoopAuthenticationFunc Default
Operator check
Check whether github.com/getkin/kin-openapi is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.
Read brief →
Jul 24, 2026
Vendor advisory
High-risk advisory
Go · go.etcd.io/etcd/v3
etcd: Watch API authorization bypass via open-ended range requests
Operator check
Check whether go.etcd.io/etcd/v3 is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. CVSS score: 7.1.
Read brief →
Jul 24, 2026
Vendor advisory
Critical vendor advisory
CVE-2026-62263
Maven · org.openidentityplatform.openam:openam-auth-webauthn
OpenAM: WebAuthn Java deserialization RCE via ObjectInputFilter depth>1 bypass
Operator check
Check whether org.openidentityplatform.openam:openam-auth-webauthn is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. CVSS score: 9.2.
Read brief →
Jul 24, 2026
Vendor advisory
High-risk advisory
CVE-2026-62379
Maven · org.openidentityplatform.openam:openam-core
OpenAM: Unauthenticated Remote Code Execution via Class.forName in AuthXMLUtils.createCustomCallback
Operator check
Check whether org.openidentityplatform.openam:openam-core is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.
Read brief →
Jul 24, 2026
Vendor advisory
High-risk advisory
Maven · org.http4s:blaze-http_2.13
blaze: Chunked-body trailer fields promoted into Request.headers in blaze-server (front-end header-sanitization bypass)
Operator check
Check whether org.http4s:blaze-http_2.13 is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.
Read brief →
Jul 24, 2026
Vendor advisory
High-risk advisory
Maven · org.openidentityplatform.opendj:opendj-dsml-servlet
OpenDJ unauthenticated SSRF, local file read and unbounded-read DoS in the DSMLv2 gateway
Operator check
Check whether org.openidentityplatform.opendj:opendj-dsml-servlet is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.
Read brief →
Jul 24, 2026
Vendor advisory
High-risk advisory
Maven · org.http4s:http4s-blaze-server_2.13
blaze: Unbounded WebSocket message aggregation in http4s-blaze-server
Operator check
Check whether org.http4s:http4s-blaze-server_2.13 is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.
Read brief →
Jul 24, 2026
Vendor advisory
High-risk advisory
Maven · org.omnifaces:omnifaces
OmniFaces: Forged combined-resource IDs and related output/push boundaries
Operator check
Check whether org.omnifaces:omnifaces is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.
Read brief →
Jul 24, 2026
Vendor advisory
High-risk advisory
Maven · org.http4s:http4s-blaze-server_2.13
blaze: Multiple HTTP/1.1 request-smuggling primitives in blaze's Java wire parser
Operator check
Check whether org.http4s:http4s-blaze-server_2.13 is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.
Read brief →
Jul 24, 2026
Vendor advisory
High-risk advisory
Maven · org.openidentityplatform.opendj:opendj-server-legacy
OpenDJ SASL PLAIN authzid bypassing the proxy ACI scope check
Operator check
Check whether org.openidentityplatform.opendj:opendj-server-legacy is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.
Read brief →
Jul 24, 2026
Vendor advisory
High-risk advisory
CVE-2026-59940
npm · seroval
seroval: `seroval.fromJSON()` Promise resolver type confusion invokes attacker-controlled methods during deserialization
Operator check
Check whether seroval is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.
Read brief →
Jul 24, 2026
Vendor advisory
High-risk advisory
npm · velocityjs
Velocity.js: Remote Code Execution via property-read to Function constructor (bypass of GHSA-j658-c2gf-x6pq fix)
Operator check
Check whether velocityjs is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.
Read brief →
Jul 24, 2026
Vendor advisory
High-risk advisory
npm · shescape
Shescape: Quadratic-time denial of service in the flag-protection
Operator check
Check whether shescape is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. CVSS score: 8.7.
Read brief →
Jul 24, 2026
Vendor advisory
Critical vendor advisory
npm · @budibase/server
Budibase: OIDC SSO account takeover: incoming identity linked by email without checking email_verified
Operator check
Check whether @budibase/server is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. CVSS score: 9.0.
Read brief →
Jul 24, 2026
Vendor advisory
High-risk advisory
npm · @budibase/server
Budibase: Unauthenticated REST Datasource Credential Theft via Cross-Origin Auth Leak
Operator check
Check whether @budibase/server is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.
Read brief →
Jul 24, 2026
Vendor advisory
High-risk advisory
npm · @budibase/server
Budibase: SQL Injection via `multipleStatements: true`
Operator check
Check whether @budibase/server is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.
Read brief →
Jul 24, 2026
Vendor advisory
High-risk advisory
npm · @better-auth/scim
@better-auth/scim: account takeover and stale access via SCIM provider-id collision
Operator check
Check whether @better-auth/scim is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.
Read brief →
Jul 24, 2026
Vendor advisory
High-risk advisory
npm · sm-crypto
sm-crypto: Predictable SM2 key generation in Node.js: default RNG uses Math.random + wall clock
Operator check
Check whether sm-crypto is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.
Read brief →
Jul 24, 2026
Vendor advisory
High-risk advisory
npm · @prompty/core
Prompty: Server-Side Template Injection to Remote Code Execution in the @prompty/core Nunjucks Renderer
Operator check
Check whether @prompty/core is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.
Read brief →
Jul 24, 2026
Vendor advisory
Critical vendor advisory
npm · shescape
Shescape: Shell injection via unescaped parentheses on Windows with CMD
Operator check
Check whether shescape is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. CVSS score: 9.2.
Read brief →
Jul 24, 2026
Vendor advisory
Critical vendor advisory
CVE-2026-59864
NuGet · Microsoft.OpenApi.Kiota
Microsoft Kiota: Path/URL injection into generated Copilot plugin manifest via x-ai-* extensions
Operator check
Check whether Microsoft.OpenApi.Kiota is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. CVSS score: 9.3. EPSS probability: 1.3%; percentile: 67%.
Read brief →
Jul 24, 2026
Vendor advisory
Critical vendor advisory
CVE-2026-59865
NuGet · Microsoft.OpenApi.Kiota
Microsoft Kiota: Command injection via x-ms-kiota-info dependencyInstallCommand surfaced by `kiota info`
Operator check
Check whether Microsoft.OpenApi.Kiota is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. CVSS score: 9.3. EPSS probability: 3.2%; percentile: 87%.
Read brief →
Jul 24, 2026
Vendor advisory
High-risk advisory
CVE-2026-16584
PyPI · awslabs.aws-api-mcp-server
AWS API MCP Server Security Policy Bypass via Startup Initialization Failure
Operator check
Check whether awslabs.aws-api-mcp-server is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. CVSS score: 7.3. EPSS probability: 0.1%; percentile: 3%.
Read brief →
Jul 24, 2026
Vendor advisory
High-risk advisory
CVE-2026-16796
PyPI · bedrock-agentcore
AWS Bedrock AgentCore: Improper neutralization of argument delimiters in the Python SDK install_packages()
Operator check
Check whether bedrock-agentcore is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. CVSS score: 8.4. EPSS probability: 0.3%; percentile: 25%.
Read brief →
Jul 24, 2026
Vendor advisory
High-risk advisory
PyPI · libp2p
libp2p: yamux connection DoS via oversized data frame
Operator check
Check whether libp2p is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.
Read brief →
Jul 24, 2026
Vendor advisory
High-risk advisory
CVE-2026-16756
Rust · aws-smithy-http-server
Smithy-RS: Allocation of resources without limits in the default aws-smithy-http-server serve() path allows unauthenticated Slowloris denial of service
Operator check
Check whether aws-smithy-http-server is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. CVSS score: 8.7. EPSS probability: 0.4%; percentile: 34%.
Read brief →
Jul 23, 2026
Vendor advisory
High-risk advisory
CVE-2026-59931
Composer · phpoffice/phpspreadsheet
PHPSpreadsheet: SSRF bypass via HTTP redirect in WEBSERVICE() domain whitelist
Operator check
Check whether phpoffice/phpspreadsheet is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.
Read brief →
Jul 23, 2026
Vendor advisory
High-risk advisory
CVE-2026-59932
Composer · phpoffice/phpspreadsheet
PHPSpreadsheet: Gnumeric reader unbounded gzip expansion causes memory exhaustion
Operator check
Check whether phpoffice/phpspreadsheet is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.
Read brief →
Jul 23, 2026
Vendor advisory
High-risk advisory
CVE-2026-59933
Composer · phpoffice/phpspreadsheet
PHPSpreadsheet: XLS/OLE sector-chain self-loop causes memory exhaustion
Operator check
Check whether phpoffice/phpspreadsheet is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.
Read brief →
Jul 23, 2026
Coordinated disclosure
Patch review
Logto · Identity Platform
Overview The Logto platform contains multiple vulnerabilities affecting the identity‑processing pipeline. These flaws reduce the reliability of authentication and authorization decisions and may allow attackers to bypass account‑ownership checks, skip MFA, replay externally issued SSO responses, or submit identity assertions without proper cryptographic or validity checks. Collectively, the issues create several paths for unauthorized access across both local and federated sign‑in flows. Description Developed by Silverhand Inc., Logto is an identity and access management system for software as a service (SaaS) and AI applications. It provides multi‑tenant authentication, single sign-on (SSO), role-based access control (RBAC), support for openId connect (OIDC), open authorization (OAuth) 2.1, and Security Assertion Markup Language (SAML)... Related CVEs: CVE-2026-15611, CVE-2026-15612, CVE-2026-15614, CVE-2026-15615.
Operator check
Review the CERT/CC Vulnerability Note and compare the affected vendor and product list against your inventory. Apply vendor fixes or compensating controls for Identity Platform where available.
Read brief →
Jul 23, 2026
Vendor advisory
High-risk advisory
CVE-2026-45623
npm · postcss
PostCSS: Arbitrary file read and information disclosure via attacker-controlled sourceMappingURL in CSS comments
Operator check
Check whether postcss is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.
Read brief →
Jul 23, 2026
Vendor advisory
High-risk advisory
CVE-2026-47219
npm · find-my-way
find-my-way: DDoS with HTTP2
Operator check
Check whether find-my-way is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.
Read brief →
Jul 23, 2026
Vendor advisory
Critical vendor advisory
npm · @auth/core
Auth.js: Email normalizer validates the address before Unicode normalization, allowing a homoglyph @ bypass
Operator check
Check whether @auth/core is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. CVSS score: 9.1.
Read brief →
Jul 23, 2026
Vendor advisory
Critical vendor advisory
npm · next-auth
Auth.js: Configuration errors can cause existence-based auth checks to fail open (auth object populated with an error)
Operator check
Check whether next-auth is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. CVSS score: 9.1.
Read brief →
Jul 23, 2026
Vendor advisory
High-risk advisory
npm · @auth/core
Auth.js: getToken() throws an uncaught exception on malformed Bearer authorization headers
Operator check
Check whether @auth/core is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.
Read brief →
Jul 23, 2026
Vendor advisory
High-risk advisory
CVE-2026-59935
PyPI · pypdf
pypdf: Possible infinite loop for not terminated inline images (ASCII85 and ASCIIHex filter)
Operator check
Check whether pypdf is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. CVSS score: 8.7. EPSS probability: 0.4%; percentile: 28%.
Read brief →
Jul 23, 2026
Vendor advisory
High-risk advisory
CVE-2026-59936
PyPI · pypdf
pypdf: Possible infinite loop for not terminated inline images
Operator check
Check whether pypdf is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. CVSS score: 8.7. EPSS probability: 0.3%; percentile: 27%.
Read brief →
Jul 22, 2026
Coordinated disclosure
Patch review
Analog · Way Picturall Quad Compact Mark II
Overview Version 3.5.8 of Analog Way's Picturall Quad Compact Mark II server contains a local privilege escalation vulnerability, tracked as CVE-2026-14985, due to improper privilege delegation and insufficient input validation in a maintenance script. Description The Picturall Quad Compact Mark II is a compact, heavy-duty 8K media server developed by Analog Way for video playback and content management in professional audiovisual environments. The core firmware includes a maintenance script called create_local_installer.sh , and the default script permission allows the low-privileged user, picmedia , to execute it as root and without a password. An attacker creates a malicious Ext4 disk image that contains the file, picturall-version.txt , with a directory traversal string and a payload file. create_local_installer.sh reads input from... Related CVEs: CVE-2026-14985.
Operator check
Review the CERT/CC Vulnerability Note and compare the affected vendor and product list against your inventory. Apply vendor fixes or compensating controls for Way Picturall Quad Compact Mark II where available.
Read brief →
Jul 22, 2026
KEV
Known exploited
CVE-2026-16232
Check Point · SmartConsole
Check Point SmartConsole contains an improper authentication vulnerability which could allow an unauthenticated remote attacker to obtain an application login token and use it to authenticate with full administrative privileges.
Operator check
Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
Read brief →
Jul 22, 2026
Coordinated disclosure
Patch review
Duplicati · backup software v2.3.0.1
Overview Duplicati v2.3.0.1 is vulnerable to arbitrary code execution when installed outside the default C:\Program Files\Duplicati 2\ directory. An attacker with local user privileges who can write files to the Duplicati installation directory can execute arbitrary code by placing malicious files, such as DLLs, in that directory. To mitigate this vulnerability, install Duplicati in the default C:\Program Files\ directory or update to the latest fixed version. Description Duplicati is a free, open-source backup solution that stores data across cloud and local storage platforms. On Windows, Duplicati is distributed as an MSI installer. By default, the installer deploys the application to C:\Program Files\Duplicati 2\ , where the directory inherits the standard protected ACLs provided by Windows. The following vulnerability affects... Related CVEs: CVE-2026-16157.
Operator check
Review the CERT/CC Vulnerability Note and compare the affected vendor and product list against your inventory. Apply vendor fixes or compensating controls for backup software v2.3.0.1 where available.
Read brief →
Jul 22, 2026
Vendor advisory
High-risk advisory
CVE-2024-7708
Maven · org.eclipse.jetty:jetty-server
Eclipse Jetty: DoS attack triggering OutOfMemory with 100-Continue requests
Operator check
Check whether org.eclipse.jetty:jetty-server is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. EPSS probability: 0.3%; percentile: 17%.
Read brief →
Jul 22, 2026
Vendor advisory
High-risk advisory
CVE-2026-10050
Maven · org.eclipse.jetty:jetty-security
Eclipse Jetty Digest Authentication: ISO-8859-1 lossy encoding allows authentication bypass via character substitution
Operator check
Check whether org.eclipse.jetty:jetty-security is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. CVSS score: 8.7.
Read brief →
Jul 22, 2026
KEV
Known exploited
CVE-2026-50522
Microsoft · SharePoint
Microsoft SharePoint contains a deserialization of untrusted data vulnerability which could allow an unauthorized attacker to execute code over a network.
Operator check
Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
Read brief →
Jul 22, 2026
Vendor advisory
Critical vendor advisory
CVE-2026-50252
Nlnetlabs · Unbound
In NLnet Labs Unbound 1.4.22 up to and including 1.25.1, UDP source port is randomized and intended to serve as a secret value that increases the entropy of DNS transactions. When resolver load balancing policies depend on the source port while their outcome is revealed this secrecy is undermined. The vulnerability arises when the load balancing policy is consistent with respect to the incoming source UDP port and IP address while heavily depending on the incoming source UDP port as a randomization source. When the SO_REUSEPORT configuration option is enabled ('so-reuseport: yes') in Unbound (
Operator check
Review CVE-2026-50252 in your asset inventory. Apply patches per vendor guidance and verify Unbound is not exposed. CVSS score: 9.3. EPSS probability: 0.1%; percentile: 2%.
Read brief →
Jul 22, 2026
Vendor advisory
High-risk advisory
CVE-2026-64641
npm · next
Next.js: Denial of Service in App Router using Server Actions
Operator check
Check whether next is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. CVSS score: 8.2.
Read brief →
Jul 22, 2026
Vendor advisory
High-risk advisory
CVE-2026-64642
npm · next
Next.js: Middleware / Proxy bypass in App Router applications using Turbopack and single locale
Operator check
Check whether next is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. CVSS score: 8.3.
Read brief →
Jul 22, 2026
Vendor advisory
High-risk advisory
CVE-2026-64645
npm · next
Next.js: Server-Side Request Forgery in rewrites via attacker-controlled destination hostname
Operator check
Check whether next is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. CVSS score: 8.3.
Read brief →
Jul 22, 2026
Vendor advisory
High-risk advisory
CVE-2026-64649
npm · next
Next.js: Server-Side Request Forgery in Server Actions on custom servers
Operator check
Check whether next is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. CVSS score: 8.3.
Read brief →
Jul 22, 2026
Vendor advisory
High-risk advisory
CVE-2026-65016
npm · n8n
n8n: SSO Instance-Role Provisioning Allows Privilege Escalation to Instance Owner
Operator check
Check whether n8n is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. CVSS score: 7.7.
Read brief →
Jul 22, 2026
Vendor advisory
High-risk advisory
npm · n8n
n8n: Send Email Node Arbitrary File Read and SSRF via Nodemailer Content-Object Type Confusion
Operator check
Check whether n8n is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. CVSS score: 8.2.
Read brief →
Jul 22, 2026
Vendor advisory
High-risk advisory
npm · n8n
n8n: Bypass "Allowed HTTP Request Domains" Credential Restriction in Multiple AI and LLM Nodes
Operator check
Check whether n8n is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. CVSS score: 7.1.
Read brief →
Jul 22, 2026
Vendor advisory
High-risk advisory
npm · n8n
n8n: Credential Authorization Bypass via Expression in HTTP Request Node `genericAuthType`
Operator check
Check whether n8n is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. CVSS score: 7.1.
Read brief →
Jul 22, 2026
Vendor advisory
High-risk advisory
npm · n8n
n8n: Account Takeover via Unverified Email Claim in Token Exchange Embed Login
Operator check
Check whether n8n is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. CVSS score: 8.9.
Read brief →
Jul 22, 2026
Vendor advisory
High-risk advisory
npm · n8n
n8n: Shared-Workflow Editor Can Exfiltrate Credentials via Inline Sub-Workflow JSON
Operator check
Check whether n8n is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. CVSS score: 7.2.
Read brief →
Jul 22, 2026
Vendor advisory
High-risk advisory
npm · n8n
n8n: Git Node fetch/pull/pushTags Operations Bypass Sandbox Path Restriction
Operator check
Check whether n8n is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. CVSS score: 7.1.
Read brief →
Jul 22, 2026
Vendor advisory
High-risk advisory
npm · n8n
n8n: Expression sandbox escape via arrow-function bodies enabling command execution
Operator check
Check whether n8n is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. CVSS score: 8.7.
Read brief →
Jul 22, 2026
Vendor advisory
High-risk advisory
npm · n8n
n8n: Authenticated code execution in the n8n Git node
Operator check
Check whether n8n is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. CVSS score: 8.7.
Read brief →
Jul 22, 2026
Vendor advisory
High-risk advisory
npm · n8n
n8n: Edit Image Node Format Injection Allows Arbitrary File Write
Operator check
Check whether n8n is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. CVSS score: 7.7.
Read brief →
Jul 22, 2026
Vendor advisory
High-risk advisory
npm · n8n
n8n: Prototype Pollution via Dot-Notation Field Names Leads To Instance-Wide Denial of Service
Operator check
Check whether n8n is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. CVSS score: 7.1.
Read brief →
Jul 22, 2026
Vendor advisory
High-risk advisory
CVE-2026-59822
PyPI · litellm
LiteLLM: MCP Authentication Bypass via OAuth2 Passthrough Fallback
Operator check
Check whether litellm is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. CVSS score: 8.8. EPSS probability: 0.2%; percentile: 16%.
Read brief →
Jul 22, 2026
Vendor advisory
High-risk advisory
PyPI · jupyterlab
JupyterLab: Image viewer allows XSS when opening malicious image in new browser tab
Operator check
Check whether jupyterlab is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. CVSS score: 7.5.
Read brief →
Jul 22, 2026
Vendor advisory
High-risk advisory
PyPI · jupyterlab
JupyterLab: Cross-site scripting (XSS) via crafted settings file (`overrides.json`)
Operator check
Check whether jupyterlab is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. CVSS score: 8.6.
Read brief →
Jul 21, 2026
KEV
Known exploited
CVE-2021-27137
DD-WRT · DD-WRT
DD-WRT contains a stack-based buffer overflow vulnerability that could allow an unauthenticated attacker to overflow an internal buffer used by UPnP and trigger a code execution vulnerability.
Operator check
Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
Read brief →
Jul 21, 2026
Vendor advisory
High-risk advisory
CVE-2026-20779
Go · code.gitea.io/gitea
Gitea: TOTP TOCTOU race on web 2FA paths + missing replay check on Basic-Auth `X-Gitea-OTP` surface
Operator check
Check whether code.gitea.io/gitea is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. EPSS probability: 0.5%; percentile: 38%.
Read brief →
Jul 21, 2026
Vendor advisory
High-risk advisory
CVE-2026-20896
Go · code.gitea.io/gitea
Gitea Docker image: `REVERSE_PROXY_TRUSTED_PROXIES = *` default lets any source IP impersonate any user via `X-WEBAUTH-USER`
Operator check
Check whether code.gitea.io/gitea is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. EPSS probability: 0.8%; percentile: 52%.
Read brief →
Jul 21, 2026
Vendor advisory
High-risk advisory
CVE-2026-22874
Go · code.gitea.io/gitea
Gitea: Incomplete SSRF Protection in Webhook and Migration Allow-list Default Filter
Operator check
Check whether code.gitea.io/gitea is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. EPSS probability: 0.5%; percentile: 37%.
Read brief →
Jul 21, 2026
Vendor advisory
High-risk advisory
CVE-2026-24451
Go · code.gitea.io/gitea
Gitea: Fork Synchronization Continues After Parent Repository Changes from Public to Private
Operator check
Check whether code.gitea.io/gitea is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. EPSS probability: 0.5%; percentile: 39%.
Read brief →
Jul 21, 2026
Vendor advisory
High-risk advisory
CVE-2026-25038
Go · code.gitea.io/gitea
Gitea: Unauthorized Access to Labels of Private Organizations
Operator check
Check whether code.gitea.io/gitea is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. EPSS probability: 0.5%; percentile: 39%.
Read brief →
Jul 21, 2026
Vendor advisory
High-risk advisory
CVE-2026-27775
Go · code.gitea.io/gitea
Gitea: Cached Per-Branch Permission Check in Pre-Receive Hook Allows Full Repository Write
Operator check
Check whether code.gitea.io/gitea is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. EPSS probability: 0.5%; percentile: 41%.
Read brief →
Jul 21, 2026
Vendor advisory
High-risk advisory
CVE-2026-54481
Go · code.gitea.io/gitea
Gitea: Internal API HTTP client hardcodes InsecureSkipVerify:true with no config override
Operator check
Check whether code.gitea.io/gitea is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.
Read brief →
Jul 21, 2026
Vendor advisory
High-risk advisory
CVE-2026-55987
Go · code.gitea.io/gitea
Gitea: OAuth2 sign-in reactivates an administrator-deactivated account on auth sources without refresh tokens (incomplete fix of #38009)
Operator check
Check whether code.gitea.io/gitea is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.
Read brief →
Jul 21, 2026
Vendor advisory
Critical vendor advisory
CVE-2026-56750
Go · code.gitea.io/gitea
Gitea Remember-Me Token Theft Not Invalidating Attacker Session
Operator check
Check whether code.gitea.io/gitea is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. CVSS score: 9.1.
Read brief →
Jul 21, 2026
Vendor advisory
High-risk advisory
CVE-2026-58314
Go · code.gitea.io/gitea
Gitea: Two SSRF findings
Operator check
Check whether code.gitea.io/gitea is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.
Read brief →
Jul 21, 2026
Vendor advisory
High-risk advisory
CVE-2026-58419
Go · code.gitea.io/gitea
Gitea: Notification API leaks private issue metadata after access revocation
Operator check
Check whether code.gitea.io/gitea is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. EPSS probability: 0.3%; percentile: 22%.
Read brief →
Jul 21, 2026
Vendor advisory
High-risk advisory
CVE-2026-58421
Go · code.gitea.io/gitea
Gitea: Unauthenticated ReDoS via CODEOWNERS pattern matching allows denial of service
Operator check
Check whether code.gitea.io/gitea is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. EPSS probability: 0.3%; percentile: 25%.
Read brief →
Jul 21, 2026
Vendor advisory
High-risk advisory
CVE-2026-58422
Go · code.gitea.io/gitea
Gitea: Improper authorization on OAuth sign-in callback silently re-enables administrator-disabled accounts
Operator check
Check whether code.gitea.io/gitea is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. CVSS score: 7.6. EPSS probability: 0.3%; percentile: 27%.
Read brief →
Jul 21, 2026
Vendor advisory
High-risk advisory
CVE-2026-58423
Go · code.gitea.io/gitea
Gitea: LFS authentication bypass via malformed SSH sub-verb allows unauthorized read access to private repositories
Operator check
Check whether code.gitea.io/gitea is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. EPSS probability: 0.3%; percentile: 23%.
Read brief →
Jul 21, 2026
Vendor advisory
High-risk advisory
CVE-2026-58424
Go · code.gitea.io/gitea
Gitea: Permanent Fork PR Workflow Approval Gate Bypass
Operator check
Check whether code.gitea.io/gitea is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. EPSS probability: 0.2%; percentile: 10%.
Read brief →
Jul 21, 2026
Vendor advisory
High-risk advisory
CVE-2026-58426
Go · code.gitea.io/gitea
Gitea Actions Artifacts V4 signed URL HMAC ambiguity allows cross-repository artifact read and cross-task upload-state write
Operator check
Check whether code.gitea.io/gitea is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. EPSS probability: 0.2%; percentile: 7%.
Read brief →
Jul 21, 2026
Vendor advisory
High-risk advisory
CVE-2026-58436
Go · code.gitea.io/gitea
Gitea: ParseAcceptLanguage quadratic-time DoS via Locale middleware on unauthenticated requests
Operator check
Check whether code.gitea.io/gitea is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. CVSS score: 8.7.
Read brief →
Jul 21, 2026
Vendor advisory
High-risk advisory
CVE-2026-58437
Go · code.gitea.io/gitea
Gitea: Repository Visibility Manipulation via Git Push Options
Operator check
Check whether code.gitea.io/gitea is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.
Read brief →
Jul 21, 2026
Vendor advisory
High-risk advisory
CVE-2026-58443
Go · code.gitea.io/gitea
Gitea: Public-only repository tokens can update private PR head branches
Operator check
Check whether code.gitea.io/gitea is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.
Read brief →
Jul 21, 2026
Vendor advisory
High-risk advisory
Go · google.golang.org/grpc
gRPC-Go: xDS RBAC and HTTP/2 Vulnerabilities
Operator check
Check whether google.golang.org/grpc is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. CVSS score: 8.8.
Read brief →
Jul 21, 2026
KEV
Known exploited
CVE-2026-0770
Langflow · Langflow
Langflow contains an inclusion of functionality from untrusted control sphere vulnerability that allows remote attackers to execute arbitrary code on affected installations.
Operator check
Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
Read brief →
Jul 21, 2026
Vendor advisory
Critical vendor advisory
CVE-2016-20096
Linknat · VOS3000 and VOS2009
Linknat VOS3000 and VOS2009 through version 2.1.2.0 contain an unauthenticated SQL injection vulnerability that allows remote attackers to execute arbitrary SQL commands by manipulating the name parameter in a POST request to the login endpoint. Attackers can inject malicious SQL through the login form and retrieve injected query results from a subsequent session request, enabling extraction of plaintext credentials and other database content with DBA-level privileges.
Operator check
Review CVE-2016-20096 in your asset inventory. Apply patches per vendor guidance and verify VOS3000 and VOS2009 is not exposed. CVSS score: 9.8.
Read brief →
Jul 21, 2026
Vendor advisory
High-risk advisory
Maven · com.fasterxml.jackson.core:jackson-core
jackson-core: Async parser maxNumberLength bypass via chunked digit accumulation (incomplete fix for GHSA-72hv-8253-57qq)
Operator check
Check whether com.fasterxml.jackson.core:jackson-core is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. CVSS score: 8.7.
Read brief →
Jul 21, 2026
Vendor advisory
High-risk advisory
CVE-2026-16221
npm · fast-uri
fast-uri vulnerable to host confusion via literal backslash authority delimiter
Operator check
Check whether fast-uri is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. EPSS probability: 0.2%; percentile: 13%.
Read brief →
Jul 21, 2026
Vendor advisory
High-risk advisory
CVE-2026-59891
npm · @sigstore/oci
Credential confusion in @sigstore/oci can leak registry credentials to an attacker-controlled registry
Operator check
Check whether @sigstore/oci is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. EPSS probability: 0.3%; percentile: 24%.
Read brief →
Jul 21, 2026
Vendor advisory
High-risk advisory
npm · fast-xml-parser
fast-xml-parser: Repeated DOCTYPE declarations reset entity expansion limits
Operator check
Check whether fast-xml-parser is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. CVSS score: 8.7.
Read brief →
Jul 21, 2026
Vendor advisory
High-risk advisory
npm · sharp
sharp inherited vulnerabilities in libvips: CVE-2026-33327, CVE-2026-33328, CVE-2026-35590, CVE-2026-35591
Operator check
Check whether sharp is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. CVSS score: 7.0.
Read brief →
Jul 21, 2026
Vendor advisory
High-risk advisory
npm · @vitest/browser
@vitest/browser: Browser Mode provider commands bypass the file-access permission gate
Operator check
Check whether @vitest/browser is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.
Read brief →
Jul 21, 2026
Coordinated disclosure
Patch review
Plane · Plane
Overview The project management tool Plane, versions 1.3.0 and earlier, contains a multi-tenant authorization bypass vulnerability in its asset-management API that allows unauthorized users to access, delete, or duplicate assets that belong to other workspaces. Description Plane is an open-source project management platform that provides multi-tenant workspace isolation for users to track issues, monitor progress, and manage workflows. The platform's API supports uploading, retrieving, deleting, and duplicating files associated with issues and tasks within a workspace. CVE-2026-15342 Plane's asset-management API endpoints accept workspace slugs and asset identifiers as path parameters, but do not verify that the requesting user is authorized to access the specified workspace. As a result, an authenticated user in one workspace can supply... Related CVEs: CVE-2026-15342.
Operator check
Review the CERT/CC Vulnerability Note and compare the affected vendor and product list against your inventory. Apply vendor fixes or compensating controls for Plane where available.
Read brief →
Jul 21, 2026
Vendor advisory
High-risk advisory
PyPI · gitpython
GitPython: Environment-variable exfiltration via os.path.expandvars() on Repo.clone_from() URL
Operator check
Check whether gitpython is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.
Read brief →
Jul 21, 2026
KEV
Known exploited
CVE-2026-60137
WordPress · Core
WordPress Core contains a SQL injection vulnerability when a plugin or theme passes untrusted input to the parameter. This vulnerability can be chained with CVE-2026-63030 to allow an unauthenticated attacker to gain remote code execution on default WordPress installations.
Operator check
Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
Read brief →
Jul 21, 2026
KEV
Known exploited
CVE-2026-63030
WordPress · Core
WordPress Core contains an interpretation conflict vulnerability that could allow an attacker to perform SQL Injection and achieve Remote Code Execution. This vulnerability can be chained with CVE-2026-60137.
Operator check
Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
Read brief →
Jul 20, 2026
Vendor advisory
High-risk advisory
CVE-2026-54560
Go · github.com/cloudreve/Cloudreve/v4
Cloudreve: OAuth access tokens bypass scope enforcement due to missing client_id claim
Operator check
Check whether github.com/cloudreve/Cloudreve/v4 is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. EPSS probability: 0.2%; percentile: 16%.
Read brief →
Jul 20, 2026
Vendor advisory
High-risk advisory
CVE-2026-55667
Go · github.com/filebrowser/filebrowser/v2
File Browser: Out-of-scope file deletion by a Create-only scoped user via symlink-following RemoveAll in upload failure-cleanup
Operator check
Check whether github.com/filebrowser/filebrowser/v2 is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. EPSS probability: 0.4%; percentile: 28%.
Read brief →
Jul 20, 2026
Vendor advisory
High-risk advisory
CVE-2026-62685
Go · github.com/filebrowser/filebrowser/v2
File Browser: Colliding username normalization gives two users the same home directory
Operator check
Check whether github.com/filebrowser/filebrowser/v2 is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. EPSS probability: 0.3%; percentile: 24%.
Read brief →
Jul 20, 2026
Vendor advisory
Critical vendor advisory
CVE-2026-41521
Neutrinolabs · Xrdp
xrdp is an open source RDP server. Versions 0.10.6 and prior contain an integer overflow vulnerability when processing screen update messages within the vnc-any connection mode. A malicious remote VNC server can send crafted image dimensions that cause an integer overflow during memory buffer size calculation, resulting in an undersized allocation. Subsequent processing of the incoming image data using the original oversized parameters leads to an out-of-bounds read. An unauthenticated remote attacker could exploit this flaw to disclose sensitive information from the heap memory or cause a den
Operator check
Review CVE-2026-41521 in your asset inventory. Apply patches per vendor guidance and verify Xrdp is not exposed. CVSS score: 8.2. EPSS probability: 0.6%; percentile: 45%.
Read brief →
Jul 20, 2026
Vendor advisory
High-risk advisory
CVE-2026-13311
npm · shell-quote
shell-quote: Quadratic-complexity Denial of Service in `parse()` (CWE-407)
Operator check
Check whether shell-quote is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. CVSS score: 8.7. EPSS probability: 0.4%; percentile: 28%.
Read brief →
Jul 20, 2026
Vendor advisory
High-risk advisory
CVE-2026-59725
npm · engine.io
Socket.IO: Engine.IO Polling Transport Connection Exhaustion
Operator check
Check whether engine.io is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. EPSS probability: 0.4%; percentile: 28%.
Read brief →
Jul 20, 2026
Vendor advisory
High-risk advisory
CVE-2026-59731
npm · astro
Astro: Authorization Bypass via Decode Iteration Limit and Rewrite Path Canonicalization Mismatch
Operator check
Check whether astro is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. EPSS probability: 0.3%; percentile: 19%.
Read brief →
Jul 20, 2026
Vendor advisory
High-risk advisory
CVE-2026-59869
npm · js-yaml
js-yaml: YAML merge-key chains can force quadratic CPU consumption
Operator check
Check whether js-yaml is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. EPSS probability: 0.4%; percentile: 29%.
Read brief →
Jul 20, 2026
Vendor advisory
High-risk advisory
CVE-2026-59874
npm · tar
node-tar: Negative tar entry size causes infinite loop in archive replace
Operator check
Check whether tar is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. CVSS score: 8.7. EPSS probability: 0.4%; percentile: 28%.
Read brief →
Jul 20, 2026
Vendor advisory
High-risk advisory
CVE-2026-61835
npm · directus
Directus: SSRF Protection Bypass via 0.0.0.0 in File Import
Operator check
Check whether directus is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. EPSS probability: 0.2%; percentile: 16%.
Read brief →
Jul 20, 2026
Vendor advisory
High-risk advisory
CVE-2026-61836
npm · directus
Directus: Authorization-dependent response served from unsegmented cache key
Operator check
Check whether directus is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. EPSS probability: 0.3%; percentile: 20%.
Read brief →
Jul 20, 2026
Vendor advisory
High-risk advisory
npm · axios
Axios Node HTTP adapter can use an inherited proxy after interceptor config cloning
Operator check
Check whether axios is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. CVSS score: 8.3.
Read brief →
Jul 20, 2026
Vendor advisory
High-risk advisory
CVE-2026-47302
NuGet · System.Security.Cryptography.Xml
Microsoft Security Advisory CVE-2026-47302 – .NET Denial of Service Vulnerability
Operator check
Check whether System.Security.Cryptography.Xml is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. EPSS probability: 0.8%; percentile: 53%.
Read brief →
Jul 20, 2026
Vendor advisory
High-risk advisory
CVE-2026-47304
NuGet · System.Security.Cryptography.Xml
Microsoft Security Advisory CVE-2026-47304 – .NET Security Feature Bypass Vulnerability
Operator check
Check whether System.Security.Cryptography.Xml is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. EPSS probability: 0.2%; percentile: 10%.
Read brief →
Jul 20, 2026
Vendor advisory
High-risk advisory
CVE-2026-50524
NuGet · Microsoft.NetCore.App.Runtime.linux-arm
Microsoft Security Advisory CVE-2026-50524 – .NET Denial of Service Vulnerability
Operator check
Check whether Microsoft.NetCore.App.Runtime.linux-arm is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. EPSS probability: 0.6%; percentile: 47%.
Read brief →
Jul 20, 2026
Vendor advisory
High-risk advisory
CVE-2026-50525
NuGet · System.Security.Cryptography.Xml
Microsoft Security Advisory CVE-2026-50525 – .NET Denial of Service Vulnerability
Operator check
Check whether System.Security.Cryptography.Xml is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. EPSS probability: 0.6%; percentile: 46%.
Read brief →
Jul 20, 2026
Vendor advisory
High-risk advisory
CVE-2026-50528
NuGet · Microsoft.NetCore.App.Runtime.linux-arm
Microsoft Security Advisory CVE-2026-50528 – .NET Security Feature Bypass Vulnerability
Operator check
Check whether Microsoft.NetCore.App.Runtime.linux-arm is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. EPSS probability: 0.4%; percentile: 35%.
Read brief →
Jul 20, 2026
Vendor advisory
High-risk advisory
CVE-2026-50648
NuGet · System.Security.Cryptography.Xml
Microsoft Security Advisory CVE-2026-50648 – .NET Denial of Service Vulnerability
Operator check
Check whether System.Security.Cryptography.Xml is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. EPSS probability: 0.6%; percentile: 46%.
Read brief →
Jul 20, 2026
Vendor advisory
High-risk advisory
CVE-2026-50651
NuGet · Microsoft.NetCore.App.Runtime.linux-arm
Microsoft Security Advisory CVE-2026-50651 – .NET Denial of Service Vulnerability
Operator check
Check whether Microsoft.NetCore.App.Runtime.linux-arm is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. EPSS probability: 0.6%; percentile: 46%.
Read brief →
Jul 20, 2026
Vendor advisory
High-risk advisory
CVE-2026-57108
NuGet · Microsoft.NetCore.App.Runtime.linux-arm
Microsoft Security Advisory CVE-2026-57108 – .NET Denial of Service Vulnerability
Operator check
Check whether Microsoft.NetCore.App.Runtime.linux-arm is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. EPSS probability: 1.1%; percentile: 62%.
Read brief →
Jul 20, 2026
Vendor advisory
High-risk advisory
CVE-2026-59197
PyPI · Pillow
Pillow: Heap out-of-bounds write in `ImageFilter.RankFilter` via integer overflow in `ImagingExpand`
Operator check
Check whether Pillow is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. EPSS probability: 0.4%; percentile: 32%.
Read brief →
Jul 20, 2026
Vendor advisory
High-risk advisory
CVE-2026-59199
PyPI · Pillow
Pillow: Heap out-of-bounds write `Image.paste()` / `Image.crop()` via signed coordinate overflow
Operator check
Check whether Pillow is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. EPSS probability: 0.4%; percentile: 31%.
Read brief →
Jul 20, 2026
Vendor advisory
High-risk advisory
CVE-2026-59200
PyPI · Pillow
Pillow: Decompression Bomb DoS via PdfParser.PdfStream.decode()
Operator check
Check whether Pillow is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. EPSS probability: 0.4%; percentile: 27%.
Read brief →
Jul 20, 2026
Vendor advisory
High-risk advisory
CVE-2026-59204
PyPI · pillow
Pillow JPEG2000 tiled decode retains a growing scratch buffer and can be used for denial of service
Operator check
Check whether pillow is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. CVSS score: 8.7. EPSS probability: 0.4%; percentile: 32%.
Read brief →
Jul 20, 2026
Vendor advisory
High-risk advisory
CVE-2026-59205
PyPI · pillow
Pillow: Controlled heap out-of-bounds write in Pillow `ImageCmsTransform.apply()` via output mode mismatch
Operator check
Check whether pillow is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. EPSS probability: 0.4%; percentile: 31%.
Read brief →
Jul 20, 2026
Vendor advisory
High-risk advisory
CVE-2026-59922
PyPI · mistune
Mistune plugins/formatting: quadratic-time parsing on long runs of `~~x~~`, `==x==`, and `^^x^^` markers (strikethrough / mark / insert)
Operator check
Check whether mistune is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. EPSS probability: 0.4%; percentile: 29%.
Read brief →
Jul 20, 2026
Vendor advisory
High-risk advisory
CVE-2026-59925
PyPI · mistune
Mistune inline_parser: quadratic-time parsing on long runs of `**x**` and `***x***` emphasis pairs
Operator check
Check whether mistune is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. EPSS probability: 0.4%; percentile: 28%.
Read brief →
Jul 20, 2026
Vendor advisory
High-risk advisory
CVE-2026-59928
PyPI · mistune
Mistune block_parser: quadratic-time parsing on long lists of repeated reference-link definitions
Operator check
Check whether mistune is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. EPSS probability: 0.4%; percentile: 29%.
Read brief →
Jul 20, 2026
Vendor advisory
High-risk advisory
CVE-2026-61736
PyPI · lightrag-hku
LightRAG: CORS Wildcard + Credentials Enables Any-Origin Credentialed Requests
Operator check
Check whether lightrag-hku is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. EPSS probability: 0.3%; percentile: 23%.
Read brief →
Jul 20, 2026
Vendor advisory
Critical vendor advisory
CVE-2026-61740
PyPI · lightrag-hku
LightRAG is Vulnerable to Authentication Bypass: hardcoded DEFAULT_TOKEN_SECRET and public /auth-status defeat LIGHTRAG_API_KEY protection
Operator check
Check whether lightrag-hku is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. CVSS score: 9.3. EPSS probability: 0.4%; percentile: 30%.
Read brief →
Jul 17, 2026
Vendor advisory
High-risk advisory
CVE-2026-27771
Go · code.gitea.io/gitea
Gitea has insufficient permission checks for Composer package source links
Operator check
Check whether code.gitea.io/gitea is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. EPSS probability: 40.7%; percentile: 98%.
Read brief →
Jul 17, 2026
Vendor advisory
High-risk advisory
Go · github.com/zalando/skipper
Skipper: Incomplete fix for CVE-2026-50197: an oversized body can bypass OPA deny-on-presence Rego policies
Operator check
Check whether github.com/zalando/skipper is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.
Read brief →
Jul 17, 2026
Vendor advisory
Critical vendor advisory
CVE-2026-9135
IBM · Langflow OSS 1.0.0
IBM Langflow OSS 1.0.0 through 1.10.0 Langflow versions up to 1.9.2 (commit 94981c443d4918517b9e8163d70fc598dc33a32d) contain a code injection vulnerability in the Policies component's ToolGuard integration that bypasses the allow_custom_components=false security control. The vulnerability exists because the validation mechanism only checks the main component source code in node_template["code"]["value"] but fails to validate dynamic CodeInput fields that store generated ToolGuard Python files. Attackers can embed malicious Python code in these unvalidated dynamic fields, which are persisted i
Operator check
Review CVE-2026-9135 in your asset inventory. Apply patches per vendor guidance and verify Langflow OSS 1.0.0 is not exposed. CVSS score: 9.9.
Read brief →
Jul 17, 2026
Vendor advisory
High-risk advisory
CVE-2026-11400
Maven · software.amazon.jdbc:aws-advanced-jdbc-wrapper
AWS-JDBC Wrapper: Privilege Escalation in Aurora PostgreSQL instance
Operator check
Check whether software.amazon.jdbc:aws-advanced-jdbc-wrapper is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. CVSS score: 8.6. EPSS probability: 0.3%; percentile: 22%.
Read brief →
Jul 17, 2026
Vendor advisory
High-risk advisory
CVE-2026-53597
npm · @prompty/core
Prompty: Arbitrary code execution via JavaScript frontmatter in TypeScript loader
Operator check
Check whether @prompty/core is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. CVSS score: 8.7. EPSS probability: 0.9%; percentile: 57%.
Read brief →
Jul 17, 2026
Vendor advisory
High-risk advisory
CVE-2026-55177
npm · @tak-ps/cloudtak
CloudTAK: Authenticated full-read SSRF in the /api/esri* routes — user-controlled URL fetched with no IP-classification guard
Operator check
Check whether @tak-ps/cloudtak is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. CVSS score: 7.6.
Read brief →
Jul 17, 2026
Vendor advisory
High-risk advisory
CVE-2026-53598
PyPI · prompty
Prompty: Arbitrary file read via file reference expansion
Operator check
Check whether prompty is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. EPSS probability: 1.1%; percentile: 61%.
Read brief →
Jul 17, 2026
Vendor advisory
High-risk advisory
CVE-2026-54234
PyPI · vllm
vLLM has Remote DoS via Invalid Recovered Token Reinjection
Operator check
Check whether vllm is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. EPSS probability: 0.3%; percentile: 27%.
Read brief →
Jul 17, 2026
Vendor advisory
High-risk advisory
CVE-2026-54547
PyPI · meta-ads-mcp
meta-ads-mcp: X-Pipeboard-Token Header Auth Bypass Reuses Operator Meta Token
Operator check
Check whether meta-ads-mcp is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.
Read brief →
Jul 17, 2026
Vendor advisory
High-risk advisory
CVE-2026-54549
PyPI · meta-ads-mcp
meta-ads-mcp: Server-Side Request Forgery (SSRF) in `upload_ad_image` via Unrestricted `image_url` Fetch
Operator check
Check whether meta-ads-mcp is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.
Read brief →
Jul 17, 2026
Vendor advisory
High-risk advisory
CVE-2026-54552
PyPI · sh
sh _uid does not drop supplementary groups (incomplete privilege drop)
Operator check
Check whether sh is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.
Read brief →
Jul 17, 2026
Vendor advisory
High-risk advisory
CVE-2026-54567
PyPI · Flask-Reuploaded
Flask-Reuploaded: Extension-denylist bypass via case-folding asymmetry in name-override path (incomplete-fix variant of CVE-2026-27641)
Operator check
Check whether Flask-Reuploaded is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.
Read brief →
Jul 17, 2026
Vendor advisory
High-risk advisory
CVE-2026-55574
PyPI · vllm
vLLM: ReDoS via structured_outputs.regex compiled without timeout in xgrammar and outlines backends
Operator check
Check whether vllm is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. CVSS score: 8.7. EPSS probability: 0.3%; percentile: 25%.
Read brief →
Jul 16, 2026
Vendor advisory
High-risk advisory
CVE-2026-54540
Composer · pheditor/pheditor
Pheditor has an authenticated terminal command whitelist bypass
Operator check
Check whether pheditor/pheditor is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.
Read brief →
Jul 16, 2026
Vendor advisory
High-risk advisory
CVE-2026-55578
Composer · pheditor/pheditor
Pheditor: Incomplete command sanitization in terminal feature allows RCE via pipe operator, backtick substitution, and newline injection
Operator check
Check whether pheditor/pheditor is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.
Read brief →
Jul 16, 2026
Vendor advisory
High-risk advisory
CVE-2026-55579
Composer · pheditor/pheditor
Pheditor: Hardcoded default password 'admin' with no forced change enables full application compromise
Operator check
Check whether pheditor/pheditor is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.
Read brief →
Jul 16, 2026
KEV
Known exploited
CVE-2026-25089
Fortinet · FortiSandbox
Fortinet FortiSandbox, FortiSandbox Cloud, and FortiSandbox PaaS contain an OS command injection vulnerability that allows an unauthenticated attacker to execute unauthorized commands via specifically crafted HTTP requests.
Operator check
Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
Read brief →
Jul 16, 2026
KEV
Known exploited
CVE-2026-39808
Fortinet · FortiSandbox
Fortinet FortiSandbox contains an OS command injection vulnerability that could allow an unauthenticated attacker to execute unauthorized code or commands via crafted HTTP requests.
Operator check
Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
Read brief →
Jul 16, 2026
Vendor advisory
High-risk advisory
CVE-2026-52833
Go · github.com/nuclio/nuclio
Nuclio: Unsanitized runtimeAttributes.repositories injected into Groovy build.gradle leads to build-time RCE
Operator check
Check whether github.com/nuclio/nuclio is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.
Read brief →
Jul 16, 2026
Vendor advisory
High-risk advisory
CVE-2026-53713
Go · github.com/envoyproxy/gateway
Envoy Gateway: Authentication Bypass via Improper Input Validation in EnvoyExtensionPolicy Lua Allows Secret Disclosure
Operator check
Check whether github.com/envoyproxy/gateway is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.
Read brief →
Jul 16, 2026
Vendor advisory
High-risk advisory
CVE-2026-53714
Go · github.com/envoyproxy/gateway
Envoy Gateway: xDS Control Plane Information Disclosure when operating in GatewayNamespaceMode
Operator check
Check whether github.com/envoyproxy/gateway is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.
Read brief →
Jul 16, 2026
Vendor advisory
Critical vendor advisory
CVE-2026-56453
Hcltech · Dfxanalytics
HCL DFXAnalytics is affected by an Account Takeover via Response Manipulation vulnerability. A remote attacker can intercept and alter the contents of the server's HTTP responses before they reach the client application, allowing them to manipulate the authentication or authorization logic to bypass controls and gain unauthorized access to targeted user accounts.
Operator check
Review CVE-2026-56453 in your asset inventory. Apply patches per vendor guidance and verify Dfxanalytics is not exposed. CVSS score: 5.5. EPSS probability: 0.2%; percentile: 6%.
Read brief →
Jul 16, 2026
Coordinated disclosure
Patch review
HTTP/2 · servers via stalled flow-control conditions
Overview A denial-of-service (DoS) vulnerability exists in some HTTP/2 server implementations that fail to adequately limit resource consumption when buffering response data under stalled flow-control conditions. A remote, unauthenticated attacker can trigger memory exhaustion and service interruption by using standard flow-control parameters such as SETTINGS_INITIAL_WINDOW_SIZE = 0 to stall outbound data for multiple simultaneous request streams. Description HTTP/2 is a widely used application-layer protocol that supports multiplexing, header compression, and flow-control mechanisms to regulate the transmission of data between web browsers and servers. Flow control is designed to prevent senders from overwhelming receivers and relies on client-advertised window sizes to determine the maximum volume of unacknowledged data that can be in...
Operator check
Review the CERT/CC Vulnerability Note and compare the affected vendor and product list against your inventory. Apply vendor fixes or compensating controls for servers via stalled flow-control conditions where available.
Read brief →
Jul 16, 2026
Vendor advisory
High-risk advisory
CVE-2026-54076
Maven · com.arcadedb:arcadedb-engine
ArcadeDB: Read-only users can mutate database schema (incomplete fix of CVE-2026-44221)
Operator check
Check whether com.arcadedb:arcadedb-engine is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.
Read brief →
Jul 16, 2026
Vendor advisory
High-risk advisory
CVE-2026-54077
Maven · com.arcadedb:arcadedb-engine
ArcadeDB: IMPORT DATABASE allows SSRF and arbitrary local file read by authenticated users
Operator check
Check whether com.arcadedb:arcadedb-engine is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.
Read brief →
Jul 16, 2026
Vendor advisory
High-risk advisory
Maven · com.arcadedb:arcadedb-server
ArcadeDB: Privilege escalation via reader role in /api/v1/command JS scripting language — arbitrary host file read
Operator check
Check whether com.arcadedb:arcadedb-server is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.
Read brief →
Jul 16, 2026
Vendor advisory
High-risk advisory
Maven · com.arcadedb:arcadedb-engine
ArcadeDB: Scripting authorization gate (GHSA-48qw-824m-86pr) bypassed via SQL DEFINE FUNCTION ... LANGUAGE js
Operator check
Check whether com.arcadedb:arcadedb-engine is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. CVSS score: 8.7.
Read brief →
Jul 16, 2026
Vendor advisory
High-risk advisory
Maven · com.arcadedb:arcadedb-server
ArcadeDB has cross-database IDOR: /ts/*, /batch/*, Prometheus and Grafana handlers bypass authorization
Operator check
Check whether com.arcadedb:arcadedb-server is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. CVSS score: 7.1.
Read brief →
Jul 16, 2026
Vendor advisory
High-risk advisory
Maven · com.arcadedb:arcadedb-engine
ArcadeDB: Trigger scripts run with java.lang.* allowed, enabling OS command execution (RCE)
Operator check
Check whether com.arcadedb:arcadedb-engine is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. CVSS score: 8.6.
Read brief →
Jul 16, 2026
Vendor advisory
High-risk advisory
CVE-2026-52869
PyPI · mcp
MCP Python SDK: HTTP transports serve session requests without verifying the authenticated principal
Operator check
Check whether mcp is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. EPSS probability: 0.3%; percentile: 16%.
Read brief →
Jul 16, 2026
Vendor advisory
High-risk advisory
CVE-2026-52870
PyPI · mcp
MCP Python SDK: Experimental task handlers allow any client to access and cancel other clients' tasks
Operator check
Check whether mcp is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. EPSS probability: 0.2%; percentile: 13%.
Read brief →
Jul 16, 2026
Vendor advisory
High-risk advisory
CVE-2026-59950
PyPI · mcp
MCP Python SDK: WebSocket server transport does not support Host/Origin validation
Operator check
Check whether mcp is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. CVSS score: 7.6. EPSS probability: 0.2%; percentile: 8%.
Read brief →
Jul 16, 2026
Coordinated disclosure
Patch review
SGLang · SGLang
Overview A Pickle deserialization vulnerability has been discovered within the SGLang project , enabling an attacker to perform remote code execution (RCE) on the target vulnerable server. In order for an attacker to exploit this vulnerability, the expert-parallel backup subsystem must be enabled, and an attacker must have network access to the SGLang service. No patch is available at this time, and no response was obtained from the project maintainers during coordination. Description SGLang is an open-source framework for serving large language models (LLMs) and multimodal AI models, supporting models such as Qwen, DeepSeek, Mistral, and Skywork, and is compatible with OpenAI APIs. A vulnerability has been discovered within the tool and is tracked as follows: CVE-2026-14890 SGLang uses an expert-parallel backup subsystem designed to... Related CVEs: CVE-2026-14890, CVE-2026-7301, CVE-2026-7304.
Operator check
Review the CERT/CC Vulnerability Note and compare the affected vendor and product list against your inventory. Apply vendor fixes or compensating controls for SGLang where available.
Read brief →
Jul 16, 2026
Vendor advisory
Critical vendor advisory
CVE-2026-44596
Spaceapplications · Yamcs
Yamcs is a mission control framework. Prior to 5.12.7, the authentication endpoint POST /auth/token in yamcs-core, handled by yamcs-core/src/main/java/org/yamcs/http/auth/AuthHandler.java, lacked any rate limiting, account lockout, or failed-attempt throttling, so an unauthenticated remote attacker could perform unlimited password-guessing attempts against any user account, significantly increasing the risk of successful brute-force attacks. This issue is fixed in versions 5.12.7 and 5.13.0.
Operator check
Review CVE-2026-44596 in your asset inventory. Apply patches per vendor guidance and verify Yamcs is not exposed. CVSS score: 6.5. EPSS probability: 1.4%; percentile: 69%.
Read brief →
Jul 15, 2026
Vendor advisory
Critical vendor advisory
CVE-2026-47156
Composer · mantisbt/mantisbt
MantisBT: SOAP API Authentication Bypass with Privilege Escalation to Administrator
Operator check
Check whether mantisbt/mantisbt is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. CVSS score: 9.3.
Read brief →
Jul 15, 2026
Vendor advisory
Critical vendor advisory
CVE-2026-52847
Composer · mantisbt/mantisbt
MantisBT: Reflected XSS in admin/install.php
Operator check
Check whether mantisbt/mantisbt is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. CVSS score: 9.2.
Read brief →
Jul 15, 2026
Vendor advisory
Critical vendor advisory
CVE-2026-52881
Composer · mantisbt/mantisbt
MantisBT: Reflected XSS in admin/install.php via unescaped printf
Operator check
Check whether mantisbt/mantisbt is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. CVSS score: 9.2.
Read brief →
Jul 15, 2026
Vendor advisory
High-risk advisory
CVE-2026-54491
Composer · phanan/koel
Koel: Incomplete fix for CVE-2026-47260 — systemic SSRF in podcast & radio fetch paths
Operator check
Check whether phanan/koel is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.
Read brief →
Jul 15, 2026
Vendor advisory
High-risk advisory
CVE-2026-62944
Composer · mantisbt/mantisbt
MantisBT: Stored XSS in print_all_bug_page_word.php
Operator check
Check whether mantisbt/mantisbt is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. CVSS score: 8.6.
Read brief →
Jul 15, 2026
Vendor advisory
High-risk advisory
CVE-2026-54451
erlang · protobuf
Protobuf: Unbounded recursion depth in embedded-message decoding
Operator check
Check whether protobuf is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. CVSS score: 8.2.
Read brief →
Jul 15, 2026
Vendor advisory
High-risk advisory
CVE-2026-50274
Go · github.com/DataDog/dd-trace-go
dd-trace-go: Improper parsing of W3C baggage headers may lead to DoS
Operator check
Check whether github.com/DataDog/dd-trace-go is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.
Read brief →
Jul 15, 2026
Vendor advisory
High-risk advisory
CVE-2026-50285
Go · github.com/pomerium/pomerium
Pomerium Pre-Auth Memory Exhaustion via Unbounded zstd Decompression in HPKE Callback
Operator check
Check whether github.com/pomerium/pomerium is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.
Read brief →
Jul 15, 2026
KEV
Known exploited
CVE-2023-4346
KNX Association · KNX Protocol Connection Authorization Option 1
KNX Association KNX Protocol Connection Authorization Option 1 contains an overly restrictive account lockout mechanism vulnerability that could allow an attacker to purge all devices without additional security options enabled and set a BCU key to lock the device.
Operator check
Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
Read brief →
Jul 15, 2026
Vendor advisory
High-risk advisory
CVE-2026-50270
Maven · com.datadoghq:dd-java-agent
dd-trace-java: Improper parsing of W3C baggage headers may lead to DoS
Operator check
Check whether com.datadoghq:dd-java-agent is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.
Read brief →
Jul 15, 2026
Vendor advisory
High-risk advisory
CVE-2026-50272
npm · dd-trace
dd-trace-js: Improper parsing of W3C baggage headers may lead to DoS
Operator check
Check whether dd-trace is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.
Read brief →
Jul 15, 2026
Vendor advisory
High-risk advisory
CVE-2026-50289
npm · systeminformation
systeminformation: OS command injection in networkInterfaces() via interfaces(5) source-directive path on Linux
Operator check
Check whether systeminformation is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. CVSS score: 8.7.
Read brief →
Jul 15, 2026
Vendor advisory
Critical vendor advisory
CVE-2026-54466
npm · websocket-driver
websocket-driver: Message corruption via abuse of protocol length headers
Operator check
Check whether websocket-driver is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. CVSS score: 9.2.
Read brief →
Jul 15, 2026
Vendor advisory
High-risk advisory
CVE-2026-54504
npm · @andrea9293/mcp-documentation-server
@andrea9293/mcp-documentation-server: Web UI API binds to all interfaces without authentication by default
Operator check
Check whether @andrea9293/mcp-documentation-server is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.
Read brief →
Jul 15, 2026
Vendor advisory
High-risk advisory
npm · obsidian-local-rest-api
obsidian-local-rest-api: Authenticated path traversal via URL-encoded %2F in /vault/{path} — arbitrary host file read/write/delete
Operator check
Check whether obsidian-local-rest-api is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.
Read brief →
Jul 15, 2026
Vendor advisory
High-risk advisory
CVE-2026-50273
NuGet · Datadog.Trace
dd-trace-dotnet: Improper parsing of W3C baggage headers may lead to DoS
Operator check
Check whether Datadog.Trace is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.
Read brief →
Jul 15, 2026
Vendor advisory
Critical vendor advisory
CVE-2026-56398
Openwebui · Open Webui
Open WebUI before 0.9.5 contains a stored cross-site scripting vulnerability in the OAuth authentication flow where the picture claim URL MIME type is inferred from file extension rather than Content-Type header, allowing SVG files to bypass the profile image validator and be stored as data URIs. Authenticated users who visit the profile image endpoint receive attacker-controlled SVG content with inline disposition and no default security headers, enabling script execution in the same origin to steal authentication tokens and achieve account takeover.
Operator check
Review CVE-2026-56398 in your asset inventory. Apply patches per vendor guidance and verify Open Webui is not exposed. CVSS score: 7.3. EPSS probability: 0.3%; percentile: 26%.
Read brief →
Jul 15, 2026
Vendor advisory
Critical vendor advisory
CVE-2026-56400
Openwebui · Open Webui
open-webui before 0.3.14 contains a cross-origin resource sharing misconfiguration allowing arbitrary origins with allow_origins=* and authenticated requests to the /api/v1/functions endpoint. Attackers can execute arbitrary code on the openwebui instance by crafting malicious cross-site requests from attacker-controlled websites when an admin user visits them.
Operator check
Review CVE-2026-56400 in your asset inventory. Apply patches per vendor guidance and verify Open Webui is not exposed. CVSS score: 8.3. EPSS probability: 0.3%; percentile: 20%.
Read brief →
Jul 15, 2026
KEV
Known exploited
CVE-2026-46817
Oracle · E-Business Suite
Oracle E-Business Suite contains an improper privilege management vulnerability that allows an unauthenticated attacker with network access via HTTP to compromise Oracle Payments. Successful attacks of this vulnerability can result in takeover of Oracle Payments.
Operator check
Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
Read brief →
Jul 15, 2026
Coordinated disclosure
Patch review
Pegatron · Tdelo64.sys
Overview A privilege escalation vulnerability exists in the tdeio64.sys driver due to an unprotected input/output control (IOCTL) dispatch routine that fails to validate the origin and permissions of user-supplied requests. An unprivileged local attacker can abuse exposed IOCTL dispatch routines [RM1.1][MB1.2]to perform arbitrary kernel memory read and write operations, ultimately obtaining NT AUTHORITY\SYSTEM privileges and compromising the security of the affected system. Description The tdeio64.sys driver distributed by Pegatron Corporation, a Taiwanese electronics manufacturer that produces motherboards and OEM components, is a Windows Driver Model (WDM) driver that provides low-level access to system I/O ports and hardware components. The driver exposes the \\.\TdeIo device interface and processes privileged IOTL requests without... Related CVEs: CVE-2026-14960, CVE-2026-14961.
Operator check
Review the CERT/CC Vulnerability Note and compare the affected vendor and product list against your inventory. Apply vendor fixes or compensating controls for Tdelo64.sys where available.
Read brief →
Jul 15, 2026
Vendor advisory
High-risk advisory
CVE-2026-50271
PyPI · ddtrace
dd-trace-py: Improper parsing of W3C baggage headers may lead to DoS
Operator check
Check whether ddtrace is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.
Read brief →
Jul 15, 2026
Vendor advisory
High-risk advisory
CVE-2026-54449
PyPI · langbot
LangBot: Authenticated RCE Via MCP Configuration
Operator check
Check whether langbot is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.
Read brief →
Jul 15, 2026
Vendor advisory
High-risk advisory
CVE-2026-54457
PyPI · tensorzero
TensorZero Gateway: Arbitrary file read and SSRF in internal object storage endpoint
Operator check
Check whether tensorzero is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.
Read brief →
Jul 15, 2026
Vendor advisory
High-risk advisory
PyPI · django-haystack
django-haystack: Remote Code Execution via `eval()` in Elasticsearch Result Deserialization
Operator check
Check whether django-haystack is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. CVSS score: 8.7.
Read brief →
Jul 15, 2026
Coordinated disclosure
Patch review
RSA-PKCS · and ED25519 Implementations
Overview Two distinct cryptographic signature verification vulnerabilities exist in Digital Bazaar node-forge, a widely used JavaScript library implementing cryptographic primitives for Node.js and browser environments. These vulnerabilities allow attackers to forge RSA (PKCS#1 v1.5) and Ed25519 signatures under specific, exploitable conditions. Description Both vulnerabilities stem from insufficient enforcement of canonical cryptographic structures during verification: in the RSA case, non-standard ASN.1 encodings and undersized padding are accepted; in the Ed25519 case, non-canonical signature scalars are not rejected. As a result, node-forge accepts signatures that appear valid internally but are rejected by industry-standard libraries such as OpenSSL and Node.js’s native crypto module. The vulnerabilities affect node-forge versions... Related CVEs: CVE-2026-33894, CVE-2026-33895.
Operator check
Review the CERT/CC Vulnerability Note and compare the affected vendor and product list against your inventory. Apply vendor fixes or compensating controls for and ED25519 Implementations where available.
Read brief →
Jul 15, 2026
Vendor advisory
High-risk advisory
CVE-2026-50276
RubyGems · datadog
dd-trace-rb: Improper parsing of W3C baggage headers may lead to DoS
Operator check
Check whether datadog is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.
Read brief →
Jul 15, 2026
Vendor advisory
High-risk advisory
CVE-2026-54498
RubyGems · view_component
ViewComponent: around_render HTML-Safety Bypass
Operator check
Check whether view_component is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.
Read brief →
Jul 14, 2026
Vendor advisory
Critical vendor advisory
CVE-2026-47984
Adobe · Commerce
Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass security measures and gain unauthorized read and write access. Exploitation of this issue does not require user interaction.
Operator check
Review CVE-2026-47984 in your asset inventory. Apply patches per vendor guidance and verify Commerce is not exposed. CVSS score: 8.2. EPSS probability: 0.5%; percentile: 41%.
Read brief →
Jul 14, 2026
Vendor advisory
Critical vendor advisory
CVE-2026-47988
Adobe · Commerce
Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass security measures and gain unauthorized read and write access. Exploitation of this issue does not require user interaction.
Operator check
Review CVE-2026-47988 in your asset inventory. Apply patches per vendor guidance and verify Commerce is not exposed. CVSS score: 8.6. EPSS probability: 0.5%; percentile: 42%.
Read brief →
Jul 14, 2026
Vendor advisory
Critical vendor advisory
CVE-2026-48284
Adobe · Coldfusion
ColdFusion is affected by an Improper Input Validation vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue does not require user interaction. Scope is changed.
Operator check
Review CVE-2026-48284 in your asset inventory. Apply patches per vendor guidance and verify Coldfusion is not exposed. CVSS score: 9.6. EPSS probability: 2.2%; percentile: 80%.
Read brief →
Jul 14, 2026
Vendor advisory
Critical vendor advisory
CVE-2026-48319
Adobe · Coldfusion
ColdFusion is affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue does not require user interaction. Scope is changed.
Operator check
Review CVE-2026-48319 in your asset inventory. Apply patches per vendor guidance and verify Coldfusion is not exposed. CVSS score: 9.1. EPSS probability: 0.9%; percentile: 57%.
Read brief →
Jul 14, 2026
Vendor advisory
Critical vendor advisory
CVE-2026-48320
Adobe · Coldfusion
ColdFusion is affected by a reflected Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this vulnerability to inject malicious scripts into a web page, potentially gaining elevated access or control over the victim's account or session. Exploitation of this issue requires user interaction in that a victim must open a malicious file. Scope is changed.
Operator check
Review CVE-2026-48320 in your asset inventory. Apply patches per vendor guidance and verify Coldfusion is not exposed. CVSS score: 8.5. EPSS probability: 3.8%; percentile: 89%.
Read brief →
Jul 14, 2026
Vendor advisory
Critical vendor advisory
CVE-2026-48321
Adobe · Coldfusion
ColdFusion is affected by an Incorrect Authorization vulnerability that could result in privilege escalation. An attacker could leverage this vulnerability to gain unauthorized read and write access. Exploitation of this issue does not require user interaction. Scope is changed.
Operator check
Review CVE-2026-48321 in your asset inventory. Apply patches per vendor guidance and verify Coldfusion is not exposed. CVSS score: 9.3. EPSS probability: 0.2%; percentile: 15%.
Read brief →
Jul 14, 2026
Vendor advisory
Critical vendor advisory
CVE-2026-48356
Adobe · Commerce
Adobe Commerce is affected by an Unrestricted Upload of File with Dangerous Type vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to inject malicious scripts into a web page, potentially gaining elevated access or control over the victim's account or session. Exploitation of this issue requires user interaction in that a victim must visit a maliciously crafted URL or interact with a compromised web page. Scope is changed.
Operator check
Review CVE-2026-48356 in your asset inventory. Apply patches per vendor guidance and verify Commerce is not exposed. CVSS score: 9.6. EPSS probability: 28.3%; percentile: 98%.
Read brief →
Jul 14, 2026
Vendor advisory
Critical vendor advisory
CVE-2026-48358
Adobe · Commerce
Adobe Commerce is affected by an Improper Encoding or Escaping of Output vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue does not require user interaction. Scope is changed.
Operator check
Review CVE-2026-48358 in your asset inventory. Apply patches per vendor guidance and verify Commerce is not exposed. CVSS score: 9.1. EPSS probability: 0.9%; percentile: 56%.
Read brief →
Jul 14, 2026
Vendor advisory
Critical vendor advisory
CVE-2026-58319
Apache · Doris
Certain Apache Doris FE HTTP REST administrative APIs were accessible without proper authentication. An unauthenticated attacker with network access to the FE HTTP service could perform unauthorized administrative operations, potentially affecting cluster integrity and availability and leading to cluster instability or denial of service. This issue affects Apache Doris versions prior to 3.1.0. Users are advised to upgrade to Apache Doris 3.1.0 or later.
Operator check
Review CVE-2026-58319 in your asset inventory. Apply patches per vendor guidance and verify Doris is not exposed. CVSS score: 9.1. EPSS probability: 0.3%; percentile: 17%.
Read brief →
Jul 14, 2026
Vendor advisory
Critical vendor advisory
CVE-2026-62390
Apache · Kylin
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Kylin. A backend API refreshing table catalog may cause the injection to the generated SQL. This issue affects Apache Kylin: from 4 through 5.0.3. Users are recommended to upgrade to version 5.0.4, which fixes the issue.
Operator check
Review CVE-2026-62390 in your asset inventory. Apply patches per vendor guidance and verify Kylin is not exposed. CVSS score: 9.8.
Read brief →
Jul 14, 2026
Vendor advisory
Critical vendor advisory
CVE-2026-62392
Apache · Kylin
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Apache Kylin. A backend API may bring job config parameters to OS command line. This issue affects Apache Kylin: from 4 through 5.0.3. Users are recommended to upgrade to version 5.0.4, which fixes the issue.
Operator check
Review CVE-2026-62392 in your asset inventory. Apply patches per vendor guidance and verify Kylin is not exposed. CVSS score: 9.8.
Read brief →
Jul 14, 2026
Vendor advisory
High-risk advisory
CVE-2026-45262
Composer · facturascripts/facturascripts
FacturaScripts: Authenticated SQL injection in the FacturaScripts REST API filter parameter via parenthesis bypass in `Where::sqlColumn`
Operator check
Check whether facturascripts/facturascripts is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.
Read brief →
Jul 14, 2026
Vendor advisory
High-risk advisory
CVE-2026-45263
Composer · facturascripts/facturascripts
FacturaScripts: CSV formula injection in CSVExport allows authenticated low-priv users to plant payloads that execute when an admin opens the export
Operator check
Check whether facturascripts/facturascripts is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.
Read brief →
Jul 14, 2026
Vendor advisory
High-risk advisory
CVE-2026-45693
Composer · facturascripts/facturascripts
FacturaScripts: Unauthenticated Path Traversal in Static File Controllers Reads Private MyFiles Documents
Operator check
Check whether facturascripts/facturascripts is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.
Read brief →
Jul 14, 2026
Vendor advisory
Critical vendor advisory
CVE-2026-52824
Composer · kimai/kimai
Kimai: Default APP_SECRET in Docker Image Enables Cookie Forgery and Account Takeover
Operator check
Check whether kimai/kimai is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. CVSS score: 9.1.
Read brief →
Jul 14, 2026
Vendor advisory
High-risk advisory
CVE-2026-52827
Composer · kimai/kimai
Kimai: Pre-2FA KIMAI_SESSION cookie grants full authenticated REST API access, bypassing TOTP
Operator check
Check whether kimai/kimai is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. CVSS score: 7.1.
Read brief →
Jul 14, 2026
Vendor advisory
High-risk advisory
CVE-2026-54087
Composer · easycorp/easyadmin-bundle
EasyAdmin: Stored Cross-Site Scripting (XSS) via uploaded files served inline in FileField and ImageField
Operator check
Check whether easycorp/easyadmin-bundle is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.
Read brief →
Jul 14, 2026
Vendor advisory
High-risk advisory
Composer · facturascripts/facturascripts
FacturaScripts: Path traversal in UploadedFile::move() via getClientOriginalName() — arbitrary file write outside MyFiles/ leading to RCE
Operator check
Check whether facturascripts/facturascripts is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.
Read brief →
Jul 14, 2026
Vendor advisory
Critical vendor advisory
CVE-2026-59836
Fortinet · Forticlientems
A improper certificate validation vulnerability in Fortinet FortiClientEMS 7.4.3 through 7.4.5, FortiClientEMS 7.4.0 through 7.4.1, FortiClientEMS 7.2 all versions may allow attacker to information disclosure via <insert attack vector here>
Operator check
Review CVE-2026-59836 in your asset inventory. Apply patches per vendor guidance and verify Forticlientems is not exposed. CVSS score: 7.5. EPSS probability: 0.1%; percentile: 2%.
Read brief →
Jul 14, 2026
Vendor advisory
High-risk advisory
CVE-2026-44300
Go · github.com/opencost/opencost
OpenCost ServiceKey Endpoint Unauthorized Credential Overwrite/Injection
Operator check
Check whether github.com/opencost/opencost is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. CVSS score: 8.8.
Read brief →
Jul 14, 2026
Vendor advisory
High-risk advisory
CVE-2026-50006
Go · github.com/julien040/anyquery
Anyquery: Arbitrary File Write (AFW) which could lead to Remote Code Execution (RCE) via Unrestricted ATTACH DATABASE in Server Mode
Operator check
Check whether github.com/julien040/anyquery is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.
Read brief →
Jul 14, 2026
Vendor advisory
High-risk advisory
CVE-2026-50013
Go · github.com/SpectoLabs/hoverfly
Hoverfly: Process Crash via Concurrent Map Write Race Condition in Diff Mode
Operator check
Check whether github.com/SpectoLabs/hoverfly is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.
Read brief →
Jul 14, 2026
Vendor advisory
High-risk advisory
CVE-2026-50125
Go · github.com/StacklokLabs/mkp
MKP: Unbounded Pod Log Read via Attacker-Controlled `limitBytes`/`tailLines` Causes Memory Exhaustion
Operator check
Check whether github.com/StacklokLabs/mkp is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.
Read brief →
Jul 14, 2026
Vendor advisory
High-risk advisory
CVE-2026-50141
Go · go.woodpecker-ci.org/woodpecker/v3
Woodpecker gRPC agent_id metadata can be spoofed- cross-tenant agent impersonation
Operator check
Check whether go.woodpecker-ci.org/woodpecker/v3 is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. CVSS score: 7.1. EPSS probability: 0.2%; percentile: 16%.
Read brief →
Jul 14, 2026
Vendor advisory
High-risk advisory
CVE-2026-50158
Go · github.com/eat-pray-ai/yutu
yutu: Arbitrary File Write via MCP `caption-download` Tool
Operator check
Check whether github.com/eat-pray-ai/yutu is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.
Read brief →
Jul 14, 2026
Vendor advisory
High-risk advisory
CVE-2026-53603
Go · github.com/forgekeep/nebula-mesh
nebula-mesh: Operator session tokens stored in plaintext in the database
Operator check
Check whether github.com/forgekeep/nebula-mesh is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. CVSS score: 7.1.
Read brief →
Jul 14, 2026
Vendor advisory
High-risk advisory
CVE-2026-53604
Go · github.com/forgekeep/nebula-mesh
nebula-mesh: CA private key not zeroized on web mobile-bundle error paths
Operator check
Check whether github.com/forgekeep/nebula-mesh is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. CVSS score: 8.7.
Read brief →
Jul 14, 2026
Vendor advisory
High-risk advisory
CVE-2026-54448
Go · github.com/aquasecurity/trivy
Trivy: Helm chart tar bomb causes OOM via unbounded io.ReadAll in parser
Operator check
Check whether github.com/aquasecurity/trivy is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. CVSS score: 8.7. EPSS probability: 0.2%; percentile: 16%.
Read brief →
Jul 14, 2026
Vendor advisory
High-risk advisory
CVE-2026-54628
Go · github.com/julien040/anyquery
Anyquery: Server-Side Request Forgery (SSRF) via Unrestricted SQLite Virtual Table Modules in Server Mode
Operator check
Check whether github.com/julien040/anyquery is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.
Read brief →
Jul 14, 2026
Vendor advisory
High-risk advisory
CVE-2026-54629
Go · github.com/julien040/anyquery
Anyquery: Local File Read (LFR) via Unrestricted SQLite Virtual Table Modules in Server Mode
Operator check
Check whether github.com/julien040/anyquery is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.
Read brief →
Jul 14, 2026
Vendor advisory
High-risk advisory
CVE-2026-61549
Go · go.woodpecker-ci.org/woodpecker/v3
Woodpecker: Privilege escalation via unrestricted serviceAccountName in the Kubernetes backend
Operator check
Check whether go.woodpecker-ci.org/woodpecker/v3 is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. CVSS score: 8.2.
Read brief →
Jul 14, 2026
Vendor advisory
High-risk advisory
CVE-2026-61699
Go · github.com/forgekeep/nebula-mesh
nebula-mesh: Certificate revocation is never enforced at the mesh
Operator check
Check whether github.com/forgekeep/nebula-mesh is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.
Read brief →
Jul 14, 2026
Vendor advisory
High-risk advisory
Go · github.com/forgekeep/nebula-mesh
Nebula-mesh allows non-admin operators to disable webhook SSRF protection via `allow_private`
Operator check
Check whether github.com/forgekeep/nebula-mesh is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.
Read brief →
Jul 14, 2026
Vendor advisory
High-risk advisory
Go · github.com/lin-snow/ech0
Ech0: ParseAcceptLanguage `_` separator bypass enables ~70x CPU amplification via Accept-Language header in i18n.Middleware
Operator check
Check whether github.com/lin-snow/ech0 is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. CVSS score: 8.7.
Read brief →
Jul 14, 2026
Vendor advisory
High-risk advisory
Go · github.com/almeidapaulopt/tsdproxy
TsDProxy: X-Forwarded-For header injection allows IP spoofing in proxied requests to backend services
Operator check
Check whether github.com/almeidapaulopt/tsdproxy is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.
Read brief →
Jul 14, 2026
Vendor advisory
High-risk advisory
CVE-2026-44891
Maven · io.netty:netty-codec-stomp
Netty: Denial of Service via Unbounded Headers in StompSubframeDecoder
Operator check
Check whether io.netty:netty-codec-stomp is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.
Read brief →
Jul 14, 2026
Patch Tuesday
High-risk advisory
CVE-2026-14380
Microsoft · Mariner
DBI versions before 1.650 for Perl are vulnerable to code injection via caller-influenced Profile Published in July 2026 Security Updates.
Operator check
Review the Microsoft Security Update Guide entry for CVE-2026-14380. Confirm whether Mariner is deployed, then apply the current security update or documented mitigation. CVSS score: 8.8. EPSS probability: 0.5%; percentile: 39%.
Read brief →
Jul 14, 2026
Patch Tuesday
Critical vendor advisory
CVE-2026-14740
Microsoft · Mariner
DBI versions before 1.650 for Perl read one byte out-of-bounds in preparse when deleting an initial SQL comment Published in July 2026 Security Updates.
Operator check
Review the Microsoft Security Update Guide entry for CVE-2026-14740. Confirm whether Mariner is deployed, then apply the current security update or documented mitigation. CVSS score: 9.1. EPSS probability: 0.4%; percentile: 33%.
Read brief →
Jul 14, 2026
Patch Tuesday
Critical vendor advisory
CVE-2026-15043
Microsoft · Mariner
DBI::SQL::Nano versions from 1.42 before 1.651 for Perl have inverted <= and >= SQL operators on text Published in July 2026 Security Updates.
Operator check
Review the Microsoft Security Update Guide entry for CVE-2026-15043. Confirm whether Mariner is deployed, then apply the current security update or documented mitigation. CVSS score: 9.8. EPSS probability: 0.5%; percentile: 40%.
Read brief →
Jul 14, 2026
Patch Tuesday
Critical vendor advisory
CVE-2026-38968
Microsoft · Mariner
ntopng through 6.6 is vulnerable to Predictable Session Identifier which can lead to Session Hijacking. HTTP session identifiers in src/HTTPserver.cpp use weak time-seeded pseudo-randomness during session creation. As a result, fresh authenticated logins can receive deterministic or colliding session cookies under attacker-controlled timing. Published in July 2026 Security Updates.
Operator check
Review the Microsoft Security Update Guide entry for CVE-2026-38968. Confirm whether Mariner is deployed, then apply the current security update or documented mitigation. CVSS score: 9.8. EPSS probability: 0.4%; percentile: 30%.
Read brief →
Jul 14, 2026
Patch Tuesday
High-risk advisory
CVE-2026-42982
Microsoft · Windows Secure Kernel Mode
Improper validation of consistency within input in Windows Secure Kernel Mode allows an authorized attacker to elevate privileges locally. Published in July 2026 Security Updates. MSRC exploitability: Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation Less Likely.
Operator check
Review the Microsoft Security Update Guide entry for CVE-2026-42982. Confirm whether Windows Secure Kernel Mode is deployed, then apply the current security update or documented mitigation. CVSS score: 7.8.
Read brief →
Jul 14, 2026
Patch Tuesday
Critical vendor advisory
CVE-2026-42990
Microsoft · SQL Server ODBC driver
Heap-based buffer overflow in SQL Server ODBC driver allows an unauthorized attacker to execute code over a network. Published in July 2026 Security Updates. MSRC exploitability: Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation Unlikely.
Operator check
Review the Microsoft Security Update Guide entry for CVE-2026-42990. Confirm whether SQL Server ODBC driver is deployed, then apply the current security update or documented mitigation. CVSS score: 9.8.
Read brief →
Jul 14, 2026
Patch Tuesday
High-risk advisory
CVE-2026-47300
Microsoft · ASP.NET Core
Incorrect implementation of authentication algorithm in ASP.NET Core allows an authorized attacker to elevate privileges over a network. Published in July 2026 Security Updates. MSRC exploitability: Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation Less Likely.
Operator check
Review the Microsoft Security Update Guide entry for CVE-2026-47300. Confirm whether ASP.NET Core is deployed, then apply the current security update or documented mitigation. CVSS score: 8.8.
Read brief →
Jul 14, 2026
Patch Tuesday
High-risk advisory
CVE-2026-47303
Microsoft · ASP.NET Core
Authentication bypass by assumed-immutable data in ASP.NET Core allows an authorized attacker to elevate privileges over a network. Published in July 2026 Security Updates. MSRC exploitability: Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation Less Likely.
Operator check
Review the Microsoft Security Update Guide entry for CVE-2026-47303. Confirm whether ASP.NET Core is deployed, then apply the current security update or documented mitigation. CVSS score: 8.8.
Read brief →
Jul 14, 2026
Patch Tuesday
Critical vendor advisory
CVE-2026-48561
Microsoft · Microsoft Copilot
Improper neutralization of special elements used in a command ('command injection') in Microsoft Copilot allows an unauthorized attacker to execute code over a network. Published in July 2026 Security Updates. MSRC exploitability: Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation Less Likely.
Operator check
Review the Microsoft Security Update Guide entry for CVE-2026-48561. Confirm whether Microsoft Copilot is deployed, then apply the current security update or documented mitigation. CVSS score: 9.6.
Read brief →
Jul 14, 2026
Patch Tuesday
High-risk advisory
CVE-2026-49164
Microsoft · Active Directory Domain Services
Heap-based buffer overflow in Active Directory Domain Services allows an unauthorized attacker to execute code over a network. Published in July 2026 Security Updates. MSRC exploitability: Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation Unlikely.
Operator check
Review the Microsoft Security Update Guide entry for CVE-2026-49164. Confirm whether Active Directory Domain Services is deployed, then apply the current security update or documented mitigation. CVSS score: 8.1.
Read brief →
Jul 14, 2026
Patch Tuesday
High-risk advisory
CVE-2026-49170
Microsoft · Windows StateRepository API
Insufficient granularity of access control in Windows StateRepository API allows an authorized attacker to elevate privileges locally. Published in July 2026 Security Updates. MSRC exploitability: Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation More Likely.
Operator check
Review the Microsoft Security Update Guide entry for CVE-2026-49170. Confirm whether Windows StateRepository API is deployed, then apply the current security update or documented mitigation. CVSS score: 7.8.
Read brief →
Jul 14, 2026
Patch Tuesday
Critical vendor advisory
CVE-2026-49172
Microsoft · Windows FTP Service
Heap-based buffer overflow in Windows FTP Service allows an unauthorized attacker to execute code over a network. Published in July 2026 Security Updates. MSRC exploitability: Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation Less Likely.
Operator check
Review the Microsoft Security Update Guide entry for CVE-2026-49172. Confirm whether Windows FTP Service is deployed, then apply the current security update or documented mitigation. CVSS score: 9.8.
Read brief →
Jul 14, 2026
Patch Tuesday
High-risk advisory
CVE-2026-50663
Microsoft · Age of Empires II: Definitive Edition Game
Relative path traversal in Age of Empires II: Definitive Edition Game allows an unauthorized attacker to execute code over a network. Published in July 2026 Security Updates. MSRC exploitability: Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation Less Likely.
Operator check
Review the Microsoft Security Update Guide entry for CVE-2026-50663. Confirm whether Age of Empires II: Definitive Edition Game is deployed, then apply the current security update or documented mitigation. CVSS score: 8.8.
Read brief →
Jul 14, 2026
Vendor advisory
Critical vendor advisory
CVE-2026-50694
Microsoft · Windows 10 1607
Use after free in Windows Secure Socket Tunneling Protocol (SSTP) allows an unauthorized attacker to execute code over a network.
Operator check
Review CVE-2026-50694 in your asset inventory. Apply patches per vendor guidance and verify Windows 10 1607 is not exposed. CVSS score: 8.1. EPSS probability: 0.6%; percentile: 45%.
Read brief →
Jul 14, 2026
Patch Tuesday
High-risk advisory
CVE-2026-54107
Microsoft · Windows Win32K
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Win32K allows an authorized attacker to elevate privileges locally. Published in July 2026 Security Updates. MSRC exploitability: Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation Less Likely.
Operator check
Review the Microsoft Security Update Guide entry for CVE-2026-54107. Confirm whether Windows Win32K is deployed, then apply the current security update or documented mitigation. CVSS score: 8.8.
Read brief →
Jul 14, 2026
Patch Tuesday
Critical vendor advisory
CVE-2026-54990
Microsoft · Remote Desktop Client
Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network. Published in July 2026 Security Updates. MSRC exploitability: Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation Less Likely.
Operator check
Review the Microsoft Security Update Guide entry for CVE-2026-54990. Confirm whether Remote Desktop Client is deployed, then apply the current security update or documented mitigation. CVSS score: 9.8.
Read brief →
Jul 14, 2026
Patch Tuesday
High-risk advisory
CVE-2026-56000
Microsoft · Mariner
xorg-x11-server / xwayland GLX contextTags Use-After-Free in CommonMakeCurrent() Published in July 2026 Security Updates.
Operator check
Review the Microsoft Security Update Guide entry for CVE-2026-56000. Confirm whether Mariner is deployed, then apply the current security update or documented mitigation. EPSS probability: 0.2%; percentile: 9%.
Read brief →
Jul 14, 2026
KEV
Known exploited
CVE-2026-56155
Microsoft · Active Directory Federation Services
Microsoft Active Directory Federation Services contains an insufficient granularity of access control vulnerability that allows an authorized attacker to elevate privileges locally.
Operator check
Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
Read brief →
Jul 14, 2026
KEV
Known exploited
CVE-2026-56164
Microsoft · SharePoint Server
Microsoft SharePoint contains a missing authentication for critical function vulnerability that allows an unauthorized attacker to elevate privileges over a network.
Operator check
Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
Read brief →
Jul 14, 2026
Patch Tuesday
Critical vendor advisory
CVE-2026-57433
Microsoft · Mariner
Storable versions before 3.41 for Perl have a signed integer overflow when deserializing a crafted SX_HOOK record Published in July 2026 Security Updates.
Operator check
Review the Microsoft Security Update Guide entry for CVE-2026-57433. Confirm whether Mariner is deployed, then apply the current security update or documented mitigation. CVSS score: 9.8. EPSS probability: 0.3%; percentile: 27%.
Read brief →
Jul 14, 2026
Patch Tuesday
High-risk advisory
CVE-2026-58253
Microsoft · Mariner
NATS Server: Route API Auth Bypass Published in July 2026 Security Updates.
Operator check
Review the Microsoft Security Update Guide entry for CVE-2026-58253. Confirm whether Mariner is deployed, then apply the current security update or documented mitigation. CVSS score: 8.8. EPSS probability: 0.4%; percentile: 29%.
Read brief →
Jul 14, 2026
Vendor advisory
Critical vendor advisory
CVE-2026-58594
Microsoft · Windows 10 1607
Integer overflow or wraparound in Windows RDP allows an unauthorized attacker to execute code over a network.
Operator check
Review CVE-2026-58594 in your asset inventory. Apply patches per vendor guidance and verify Windows 10 1607 is not exposed. CVSS score: 8.8. EPSS probability: 0.8%; percentile: 52%.
Read brief →
Jul 14, 2026
Vendor advisory
Critical vendor advisory
CVE-2026-58617
Microsoft · 365 Copilot
Improper access control in Microsoft 365 Copilot for iOS allows an unauthorized attacker to elevate privileges over a network.
Operator check
Review CVE-2026-58617 in your asset inventory. Apply patches per vendor guidance and verify 365 Copilot is not exposed. CVSS score: 8.1. EPSS probability: 0.7%; percentile: 48%.
Read brief →
Jul 14, 2026
Vendor advisory
Critical vendor advisory
CVE-2026-58644
Microsoft · Sharepoint Server
Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network.
Operator check
Review CVE-2026-58644 in your asset inventory. Apply patches per vendor guidance and verify Sharepoint Server is not exposed. CVSS score: 9.8. EPSS probability: 1.3%; percentile: 68%.
Read brief →
Jul 14, 2026
Patch Tuesday
High-risk advisory
CVE-2026-59873
Microsoft · Mariner
node-tar: Decompression/parse DoS via unlimited input Published in July 2026 Security Updates.
Operator check
Review the Microsoft Security Update Guide entry for CVE-2026-59873. Confirm whether Mariner is deployed, then apply the current security update or documented mitigation. CVSS score: 7.5. EPSS probability: 0.4%; percentile: 28%.
Read brief →
Jul 14, 2026
Patch Tuesday
Critical vendor advisory
CVE-2026-60082
Microsoft · Mariner
DBI versions before 1.651 for Perl do not enforce statement handle consistency with the row Published in July 2026 Security Updates.
Operator check
Review the Microsoft Security Update Guide entry for CVE-2026-60082. Confirm whether Mariner is deployed, then apply the current security update or documented mitigation. CVSS score: 9.1. EPSS probability: 0.7%; percentile: 47%.
Read brief →
Jul 14, 2026
Patch Tuesday
Critical vendor advisory
CVE-2026-8924
Microsoft · Mariner
trailing dot domain super cookie Published in July 2026 Security Updates.
Operator check
Review the Microsoft Security Update Guide entry for CVE-2026-8924. Confirm whether Mariner is deployed, then apply the current security update or documented mitigation. CVSS score: 9.1. EPSS probability: 0.6%; percentile: 47%.
Read brief →
Jul 14, 2026
Patch Tuesday
Critical vendor advisory
CVE-2026-8926
Microsoft · Mariner
password leak with netrc and user in URL Published in July 2026 Security Updates.
Operator check
Review the Microsoft Security Update Guide entry for CVE-2026-8926. Confirm whether Mariner is deployed, then apply the current security update or documented mitigation. CVSS score: 9.1. EPSS probability: 0.6%; percentile: 45%.
Read brief →
Jul 14, 2026
Patch Tuesday
Critical vendor advisory
CVE-2026-9547
Microsoft · Mariner
SSH improper host validation Published in July 2026 Security Updates.
Operator check
Review the Microsoft Security Update Guide entry for CVE-2026-9547. Confirm whether Mariner is deployed, then apply the current security update or documented mitigation. CVSS score: 9.1. EPSS probability: 0.5%; percentile: 40%.
Read brief →
Jul 14, 2026
Vendor advisory
High-risk advisory
CVE-2026-50131
npm · @fedify/fedify
Fedify has an incomplete SSRF mitigation after GHSA-p9cg-vqcc-grcx: validatePublicUrl allows special-use IPv4 ranges
Operator check
Check whether @fedify/fedify is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. EPSS probability: 0.3%; percentile: 19%.
Read brief →
Jul 14, 2026
Vendor advisory
High-risk advisory
CVE-2026-54052
npm · n8n-mcp
n8n-MCP: Cross-tenant access to workflow version backups in multi-tenant HTTP deployments
Operator check
Check whether n8n-mcp is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.
Read brief →
Jul 14, 2026
Vendor advisory
High-risk advisory
npm · tidgi
TidGi Desktop Remote Code Execution via Malicious TiddlyWiki Repository Import — Tiddler Startup Module Auto-Execution
Operator check
Check whether tidgi is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.
Read brief →
Jul 14, 2026
Vendor advisory
Critical vendor advisory
CVE-2026-24227
Nvidia · Tensorrt
NVIDIA TensorRT for contains a vulnerability where a user might cause a deserialization of untrusted data. A successful exploit of this vulnerability might lead to code execution.
Operator check
Review CVE-2026-24227 in your asset inventory. Apply patches per vendor guidance and verify Tensorrt is not exposed. CVSS score: 5.3. EPSS probability: 0.5%; percentile: 38%.
Read brief →
Jul 14, 2026
Vendor advisory
High-risk advisory
CVE-2026-54446
PyPI · netlicensing-mcp
NetLicensing-MCP: Unauthenticated Use of Server-Side NetLicensing API Key in HTTP Mode
Operator check
Check whether netlicensing-mcp is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.
Read brief →
Jul 14, 2026
Vendor advisory
Critical vendor advisory
CVE-2026-45063
Sensiolabs · Symfony
Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 5.4.52, 6.4.40, 7.4.12, and 8.0.12, X509Authenticator extracts the user identifier from $_SERVER['SSL_CLIENT_S_DN'] with an unanchored regex that matches emailAddress= anywhere in the distinguished name, allowing an attacker with a trusted certificate containing emailAddress=victim inside another RDN value such as CN to authenticate as the victim. This issue is fixed in versions 5.4.52, 6.4.40, 7.4.12, and 8.0.12.
Operator check
Review CVE-2026-45063 in your asset inventory. Apply patches per vendor guidance and verify Symfony is not exposed. CVSS score: 9.1. EPSS probability: 0.3%; percentile: 26%.
Read brief →
Jul 14, 2026
Vendor advisory
Critical vendor advisory
CVE-2026-45069
Sensiolabs · Symfony
Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 6.4.40, 7.4.12, and 8.0.12, OidcTokenHandler::verifyClaims() registered audience (aud), issuer (iss), and expiry (exp) checkers but did not pass the mandatory claims list to ClaimCheckerManager::check(), so a validly signed JWT that omitted those claims could pass verification. This issue is fixed in versions 6.4.40, 7.4.12, and 8.0.12.
Operator check
Review CVE-2026-45069 in your asset inventory. Apply patches per vendor guidance and verify Symfony is not exposed. CVSS score: 9.1. EPSS probability: 0.2%; percentile: 15%.
Read brief →
Jul 14, 2026
Vendor advisory
Critical vendor advisory
CVE-2026-47767
Sensiolabs · Symfony
Symfony is a PHP framework for web and console applications and a set of reusable PHP components. From 5.4.46 until 5.4.52, 6.4.40, 7.4.12, and 8.0.12, the CVE-2024-50340 fix gated runtime argv parsing on empty($_GET), but parse_str() and the web SAPI can disagree, allowing a crafted query string to leave $_GET empty while $_SERVER['argv'] still carries attacker-controlled --env or --no-debug flags that change APP_ENV or APP_DEBUG. This issue is fixed in versions 5.4.52, 6.4.40, 7.4.12, and 8.0.12.
Operator check
Review CVE-2026-47767 in your asset inventory. Apply patches per vendor guidance and verify Symfony is not exposed. CVSS score: 9.8. EPSS probability: 0.3%; percentile: 25%.
Read brief →
Jul 14, 2026
KEV
Known exploited
CVE-2026-15409
SonicWall · SMA1000 Appliances
SonicWall SMA1000 Appliances contain a server-side request forgery vulnerability that could allow a remote unauthenticated attacker to potentially cause the appliance to make requests to unintended location.
Operator check
Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
Read brief →
Jul 14, 2026
KEV
Known exploited
CVE-2026-15410
SonicWall · SMA1000 Appliances
SonicWall SMA1000 Appliances contain a code injection vulnerability which in specific conditions could potentially enable a remote authenticated attacker as administrator to execute arbitrary OS commands.
Operator check
Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
Read brief →
Jul 13, 2026
KEV
Known exploited
CVE-2008-4128
Cisco · IOS
Cisco IOS 12.4 contains multiple cross-site forgery vulnerabilities that allows remote attackers to execute arbitrary commands via (1) a certain "show privilege" command to the /level/15/exec/- URI, and (2) a certain "alias exec" command to the /level/15/exec/-/configure/http URI.
Operator check
Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
Read brief →
Jul 13, 2026
Vendor advisory
Critical vendor advisory
CVE-2026-47677
Composer · facturascripts/facturascripts
FacturaScripts: Account takeover of any 2FA-enabled user
Operator check
Check whether facturascripts/facturascripts is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. CVSS score: 9.3.
Read brief →
Jul 13, 2026
Vendor advisory
High-risk advisory
CVE-2026-48118
Composer · nukeviet/nukeviet
NukeViet: Unauthenticated Reflected XSS in Comment Module
Operator check
Check whether nukeviet/nukeviet is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.
Read brief →
Jul 13, 2026
Vendor advisory
High-risk advisory
CVE-2026-49259
Composer · nukeviet/nukeviet
NukeViet: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Operator check
Check whether nukeviet/nukeviet is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.
Read brief →
Jul 13, 2026
Vendor advisory
High-risk advisory
CVE-2026-54064
Composer · nukeviet/nukeviet
NukeViet: Multiple Anti-XSS Filter Bypasses Leading to Stored XSS in News Module
Operator check
Check whether nukeviet/nukeviet is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.
Read brief →
Jul 13, 2026
Vendor advisory
High-risk advisory
CVE-2026-54065
Composer · nukeviet/nukeviet
NukeViet: Path Traversal to Arbitrary File Deletion in Edit Comment Function
Operator check
Check whether nukeviet/nukeviet is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.
Read brief →
Jul 13, 2026
Vendor advisory
High-risk advisory
CVE-2026-55372
Composer · nukeviet/nukeviet
NukeViet: Pre-authentication SSRF via X-Forwarded-Host
Operator check
Check whether nukeviet/nukeviet is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.
Read brief →
Jul 13, 2026
Vendor advisory
Critical vendor advisory
CVE-2026-40468
Fossies · Gawk
Integer overflow vulnerability has been found in "builtin.c" program file of gawk. This issue may lead to memory exhaustion on the hosting operating system and could be used to overwrite gawk heap metadata and objects with attacker-controlled bytes. It affects gawk in versions 5.4.0 and below.
Operator check
Review CVE-2026-40468 in your asset inventory. Apply patches per vendor guidance and verify Gawk is not exposed. CVSS score: 9.1.
Read brief →
Jul 13, 2026
Vendor advisory
Critical vendor advisory
CVE-2026-40469
Fossies · Gawk
Integer overflow vulnerability has been found in "builtin.c" program file of gawk (do_sub() routine). This issue could be used to overwrite gawk heap metadata and objects causing the program to crash. It affects 32-bit builds of gawk in versions 5.4.0 and below.
Operator check
Review CVE-2026-40469 in your asset inventory. Apply patches per vendor guidance and verify Gawk is not exposed. CVSS score: 9.1.
Read brief →
Jul 13, 2026
Vendor advisory
High-risk advisory
CVE-2026-59954
Maven · com.ctrip.framework.apollo:apollo
Apollo ConfigService access key authentication bypass via appId parsing and non-canonical matching
Operator check
Check whether com.ctrip.framework.apollo:apollo is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.
Read brief →
Jul 13, 2026
Vendor advisory
High-risk advisory
CVE-2026-59955
Maven · com.ctrip.framework.apollo:apollo
Apollo ConfigService access key authentication bypass via raw config file appId parsing
Operator check
Check whether com.ctrip.framework.apollo:apollo is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.
Read brief →
Jul 13, 2026
Vendor advisory
Critical vendor advisory
CVE-2026-57830
Ollyo · Helix Ultimate
The Joomla extension Helix Ultimate is vulnerable to an unauthenticated arbitrary file deletion.
Operator check
Review CVE-2026-57830 in your asset inventory. Apply patches per vendor guidance and verify Helix Ultimate is not exposed. CVSS score: 9.1. EPSS probability: 0.2%; percentile: 15%.
Read brief →
Jul 13, 2026
Vendor advisory
Critical vendor advisory
CVE-2026-13221
Perl · Perl
Perl versions through 5.43.9 produce silently incorrect regular expression matches when an alternation of more than 65535 fixed string branches is compiled into a trie in Perl_study_chunk. When such branches are combined into a trie, the delta between the first branch and the shared tail is stored in a 16-bit field. A branch count above 65535 overflows the field, and the trie's match decision table is truncated with no warning or error. A pattern of this shape produces false positive matches (matching strings it should not) and false negative matches (failing to match strings it should). Whe
Operator check
Review CVE-2026-13221 in your asset inventory. Apply patches per vendor guidance and verify Perl is not exposed. CVSS score: 9.1. EPSS probability: 0.2%; percentile: 11%.
Read brief →
Jul 13, 2026
Vendor advisory
High-risk advisory
CVE-2026-45579
PyPI · DIRAC
DIRAC is vulnerable to RCE in RequestManager due to eval on untrusted input
Operator check
Check whether DIRAC is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.
Read brief →
Jul 13, 2026
Vendor advisory
High-risk advisory
CVE-2026-61667
PyPI · DIRAC
DIRAC is vulnerable to RCE in FileCatalog DatasetManager via SQL injection + eval
Operator check
Check whether DIRAC is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.
Read brief →
Jul 13, 2026
Vendor advisory
High-risk advisory
CVE-2026-61668
PyPI · DIRAC
DIRAC: Pilot code downloaded over unverified HTTPS connection
Operator check
Check whether DIRAC is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.
Read brief →
Jul 13, 2026
Vendor advisory
High-risk advisory
PyPI · DIRAC
DIRAC: SQL injection and lack of access control in PilotManager service
Operator check
Check whether DIRAC is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.
Read brief →
Jul 13, 2026
Vendor advisory
High-risk advisory
PyPI · json-repair
json_repair: Circular JSON Schema `$ref` causes unbounded CPU DoS
Operator check
Check whether json-repair is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.
Read brief →
Jul 13, 2026
Vendor advisory
High-risk advisory
CVE-2026-45378
RubyGems · decidim-verifications
Decidim: Verification documents can be downloaded through reusable links
Operator check
Check whether decidim-verifications is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.
Read brief →
Jul 13, 2026
Vendor advisory
High-risk advisory
CVE-2026-45414
RubyGems · decidim
Decidim: JWT-backed authentication can be replayed across organizations
Operator check
Check whether decidim is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.
Read brief →
Jul 13, 2026
Vendor advisory
Critical vendor advisory
CVE-2026-61498
Vitec · Flamingo 4.12.2
Vitec Flamingo 4.12.2 contains an unauthenticated OS command injection vulnerability in the admin/ajax/gen_graphs.php endpoint that allows remote unauthenticated attackers to execute arbitrary commands by supplying shell metacharacters in the start, end, key, or format HTTP GET parameters. Attackers can exploit the lack of input sanitization in the graph generation script, which passes user-supplied values directly to shell commands via passthru(), to execute arbitrary OS commands with root privileges due to the web server context having passwordless sudo access.
Operator check
Review CVE-2026-61498 in your asset inventory. Apply patches per vendor guidance and verify Flamingo 4.12.2 is not exposed. CVSS score: 9.8.
Read brief →
Jul 11, 2026
Vendor advisory
Critical vendor advisory
CVE-2026-56372
Imagemagick · Imagemagick
ImageMagick before 7.1.2-19 contains a heap buffer overflow vulnerability in the magnify operation that allows attackers to read out of bounds memory. An unrecognized magnify:method value triggers an out of bounds read, potentially exposing sensitive information or causing denial of service.
Operator check
Review CVE-2026-56372 in your asset inventory. Apply patches per vendor guidance and verify Imagemagick is not exposed. CVSS score: 3.3. EPSS probability: 0.1%; percentile: 2%.
Read brief →
Jul 10, 2026
KEV
Known exploited
CVE-2026-56291
Balbooa · Forms
Balbooa Forms contains an unrestricted upload of file with dangerous type vulnerability that allows an unauthenticated arbitrary file upload which could allow uploading of executable files leading to full RCE.
Operator check
Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
Read brief →
Jul 10, 2026
Vendor advisory
High-risk advisory
CVE-2026-54159
Composer · prestashop/ps_facetedsearch
prestashop/ps_facetedsearch: PHP Object Injection in faceted search cache allows unauthenticated RCE
Operator check
Check whether prestashop/ps_facetedsearch is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.
Read brief →
Jul 10, 2026
Vendor advisory
High-risk advisory
Composer · notrinos/notrinos-erp
NotrinosERP: Authenticated arbitrary file upload leads to remote code execution via HRM employee "Documents" (doc_file)
Operator check
Check whether notrinos/notrinos-erp is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.
Read brief →
Jul 10, 2026
Vendor advisory
High-risk advisory
CVE-2026-48594
erlang · tesla
Tesla has decompression bomb on response body
Operator check
Check whether tesla is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. CVSS score: 8.2. EPSS probability: 0.3%; percentile: 25%.
Read brief →
Jul 10, 2026
Vendor advisory
High-risk advisory
CVE-2026-48595
erlang · tesla
Tesla: Authorization header leaks on cross-origin redirect via case-sensitive filtering
Operator check
Check whether tesla is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. CVSS score: 8.2. EPSS probability: 0.4%; percentile: 32%.
Read brief →
Jul 10, 2026
Vendor advisory
High-risk advisory
CVE-2026-48597
erlang · tesla
Tesla vulnerable to atom exhaustion via untrusted URL scheme
Operator check
Check whether tesla is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. CVSS score: 8.2. EPSS probability: 0.3%; percentile: 22%.
Read brief →
Jul 10, 2026
Vendor advisory
High-risk advisory
CVE-2026-50551
Go · github.com/siyuan-note/siyuan/kernel
SiYuan: Stored XSS to RCE via Unsanitized Attribute View Asset Cell Content
Operator check
Check whether github.com/siyuan-note/siyuan/kernel is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. EPSS probability: 0.4%; percentile: 35%.
Read brief →
Jul 10, 2026
Vendor advisory
High-risk advisory
CVE-2026-54063
Go · github.com/xuri/excelize/v2
Excelize: Unbounded Row Index Allocation in Worksheet Parser (checkSheet OOM/Panic DoS)
Operator check
Check whether github.com/xuri/excelize/v2 is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.
Read brief →
Jul 10, 2026
Vendor advisory
High-risk advisory
CVE-2026-54066
Go · github.com/siyuan-note/siyuan/kernel
SiYuan: Path Traversal via Double URL Encoding in /assets/*path (publish mode arbitrary file─read), Incomplete fix of CVE-2026-41894
Operator check
Check whether github.com/siyuan-note/siyuan/kernel is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. EPSS probability: 1.9%; percentile: 77%.
Read brief →
Jul 10, 2026
Vendor advisory
High-risk advisory
CVE-2026-54067
Go · github.com/siyuan-note/siyuan/kernel
SiYuan: Stored XSS to RCE via CSS-snippet <style> breakout in renderSnippet()
Operator check
Check whether github.com/siyuan-note/siyuan/kernel is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. EPSS probability: 0.3%; percentile: 23%.
Read brief →
Jul 10, 2026
Vendor advisory
Critical vendor advisory
CVE-2026-54069
Go · github.com/siyuan-note/siyuan/kernel
SiYuan: Unauthenticated Admin API Access via Blanket chrome-extension:// Origin Allowlist
Operator check
Check whether github.com/siyuan-note/siyuan/kernel is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. CVSS score: 9.2. EPSS probability: 0.6%; percentile: 45%.
Read brief →
Jul 10, 2026
Vendor advisory
High-risk advisory
CVE-2026-54070
Go · github.com/siyuan-note/siyuan/kernel
SiYuan: Stored XSS in Bazaar marketplace via package README event handlers
Operator check
Check whether github.com/siyuan-note/siyuan/kernel is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. EPSS probability: 0.2%; percentile: 8%.
Read brief →
Jul 10, 2026
Vendor advisory
High-risk advisory
CVE-2026-54072
Go · github.com/authorizerdev/authorizer
Authorizer: Unvalidated redirect_uri in /authorize leaks OAuth2 tokens to attacker-controlled URL
Operator check
Check whether github.com/authorizerdev/authorizer is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.
Read brief →
Jul 10, 2026
Vendor advisory
Critical vendor advisory
CVE-2026-54088
Go · github.com/filebrowser/filebrowser/v2
File Browser: Command Injection via Authentication Hook Shell Substitution (Pre-Authentication RCE)
Operator check
Check whether github.com/filebrowser/filebrowser/v2 is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. CVSS score: 9.3. EPSS probability: 0.5%; percentile: 41%.
Read brief →
Jul 10, 2026
Vendor advisory
High-risk advisory
CVE-2026-54089
Go · github.com/filebrowser/filebrowser/v2
File Browser: Authentication Bypass via Proxy Auth Header Forgery
Operator check
Check whether github.com/filebrowser/filebrowser/v2 is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. EPSS probability: 0.3%; percentile: 26%.
Read brief →
Jul 10, 2026
Vendor advisory
High-risk advisory
CVE-2026-54158
Go · github.com/siyuan-note/siyuan/kernel
SiYuan: Stored XSS to RCE via attribute-view cell rendering in genAVValueHTML()
Operator check
Check whether github.com/siyuan-note/siyuan/kernel is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. EPSS probability: 0.3%; percentile: 21%.
Read brief →
Jul 10, 2026
Vendor advisory
High-risk advisory
CVE-2026-54174
Go · chainguard.dev/apko
melange: Incomplete package integrity verification allows data section substitution
Operator check
Check whether chainguard.dev/apko is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.
Read brief →
Jul 10, 2026
Vendor advisory
High-risk advisory
Go · github.com/almeidapaulopt/tsdproxy
TSDProxy: Internal proxy auth token forwarded to backend services enables management API escalation
Operator check
Check whether github.com/almeidapaulopt/tsdproxy is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.
Read brief →
Jul 10, 2026
KEV
Known exploited
CVE-2026-48939
iCagenda · iCagenda
iCagenda contains an unrestricted upload of file with dangerous type vulnerability that allows the upload of arbitrary files in the file attachment feature, ultimately resulting in PHP code upload and execution.
Operator check
Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
Read brief →
Jul 10, 2026
Vendor advisory
Critical vendor advisory
CVE-2026-59792
Jetbrains · Intellij Idea
In JetBrains IntelliJ IDEA before 2026.1.4, 2026.2 code execution via path traversal in project workspace ID handling was possible
Operator check
Review CVE-2026-59792 in your asset inventory. Apply patches per vendor guidance and verify Intellij Idea is not exposed. CVSS score: 9.6.
Read brief →
Jul 10, 2026
Vendor advisory
Critical vendor advisory
CVE-2026-61459
MCP · Server Kubernetes
MCP Server Kubernetes before 3.9.0 contains an argument injection vulnerability in structured tools (kubectl_get, kubectl_describe, kubectl_delete) that allows attackers to bypass the assertNoDangerousFlags security check by supplying resourceType and name parameters with leading dashes. Attackers can inject the --server flag to redirect kubectl commands to an attacker-controlled API server, causing the operator's bearer token to be transmitted externally and enabling full cluster compromise.
Operator check
Review CVE-2026-61459 in your asset inventory. Apply patches per vendor guidance and verify Server Kubernetes is not exposed. CVSS score: 9.8.
Read brief →
Jul 10, 2026
Vendor advisory
High-risk advisory
CVE-2026-49866
npm · @libp2p/gossipsub
libp2p: CPU DoS via oversized IHAVE and IWANT control message arrays
Operator check
Check whether @libp2p/gossipsub is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. EPSS probability: 0.4%; percentile: 36%.
Read brief →
Jul 10, 2026
Vendor advisory
High-risk advisory
npm · safeinstall-cli
SafeInstall agent guard shell parsing can miss raw package execution
Operator check
Check whether safeinstall-cli is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.
Read brief →
Jul 10, 2026
Vendor advisory
High-risk advisory
CVE-2026-54071
PyPI · BabelDOC
BabelDOC: Arbitrary Code Execution via CMap Pickle Deserialization in babeldoc/pdfminer/cmapdb.py
Operator check
Check whether BabelDOC is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.
Read brief →
Jul 10, 2026
Vendor advisory
High-risk advisory
PyPI · mcp-atlassian
mcp-atlassian: Arbitrary file read via missing path validation in confluence_upload_attachment
Operator check
Check whether mcp-atlassian is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.
Read brief →
Jul 10, 2026
Vendor advisory
High-risk advisory
PyPI · clauster
Clauster: Non-loopback deployments can serve the dashboard unauthenticated when auth.enabled is unset
Operator check
Check whether clauster is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. CVSS score: 8.7.
Read brief →
Jul 10, 2026
Vendor advisory
High-risk advisory
PyPI · mcp-atlassian
mcp-atlassian: Arbitrary server-side file read via attachment upload
Operator check
Check whether mcp-atlassian is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.
Read brief →
Jul 10, 2026
Vendor advisory
High-risk advisory
Rust · exploration
`exploration` was removed from crates.io for malicious code
Operator check
Check whether exploration is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.
Read brief →
Jul 10, 2026
Coordinated disclosure
Patch review
Users · are advised to update their
Overview GNU Wget, versions 1.25.0 and earlier, contains a server-side request forgery (SSRF) vulnerability in its implementation of FTP passive mode. Because Wget does not properly validate IP addresses obtained from PASV responses, an attacker-controlled FTP endpoint can redirect the client’s connection to arbitrary IPs, potentially exposing internal network host and service responses. This vulnerability has been remediated in a recent update by GNU; see the Solutions section below for resolution guidance. Description GNU Wget is a widely used command-line utility for retrieving content over HTTP, HTTPS, and FTP. When operating over FTP in passive mode, Wget relies on the server’s PASV response to determine which IP address and port to use for the data connection. CVE-2026-15146 GNU Wget does not validate the IP address provided by an... Related CVEs: CVE-2021-40491, CVE-2026-15146.
Operator check
Review the CERT/CC Vulnerability Note and compare the affected vendor and product list against your inventory. Apply vendor fixes or compensating controls for are advised to update their where available.
Read brief →
Jul 9, 2026
Vendor advisory
High-risk advisory
CVE-2026-52762
Composer · yeswiki/yeswiki
YesWiki: Authenticated (Admin) Server-Side Template Injection to Remote Code Execution via Bazar Semantic Templates
Operator check
Check whether yeswiki/yeswiki is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. CVSS score: 7.1.
Read brief →
Jul 9, 2026
Vendor advisory
High-risk advisory
CVE-2026-52766
Composer · yeswiki/yeswiki
YesWiki vulnerable to unauthenticated arbitrary page deletion via `{{erasespamedcomments}}` action
Operator check
Check whether yeswiki/yeswiki is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.
Read brief →
Jul 9, 2026
Vendor advisory
High-risk advisory
CVE-2026-52767
Composer · yeswiki/yeswiki
YesWiki Vulnerable to Unauthenticated ActivityPub Signature-Verification Bypass via `!openssl_verify(...)` accepting `int(-1)`
Operator check
Check whether yeswiki/yeswiki is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.
Read brief →
Jul 9, 2026
Vendor advisory
High-risk advisory
CVE-2026-52769
Composer · yeswiki/yeswiki
YesWiki has Unauthenticated Server-Side Request Forgery via ActivityPub `Signature.keyId`
Operator check
Check whether yeswiki/yeswiki is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.
Read brief →
Jul 9, 2026
Vendor advisory
High-risk advisory
CVE-2026-52770
Composer · yeswiki/yeswiki
YesWiki: SQL Injection possible through public Bazar entry-listing APIs via numeric `query`/`queries` filters
Operator check
Check whether yeswiki/yeswiki is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.
Read brief →
Jul 9, 2026
Vendor advisory
High-risk advisory
CVE-2026-52771
Composer · yeswiki/yeswiki
YesWiki: Second-Order SQL Injection in Page Delete API via Unescaped Page Tag (`ApiController::deletePage`)
Operator check
Check whether yeswiki/yeswiki is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.
Read brief →
Jul 9, 2026
Vendor advisory
High-risk advisory
CVE-2026-52775
Composer · yeswiki/yeswiki
YesWiki has Authenticated SQL Injection via ReactionManager
Operator check
Check whether yeswiki/yeswiki is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.
Read brief →
Jul 9, 2026
Vendor advisory
Critical vendor advisory
CVE-2026-52777
Composer · yeswiki/yeswiki
YesWiki Vulnerable to Authenticated PHP Object Injection in BazarImportAction via unserialize
Operator check
Check whether yeswiki/yeswiki is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. CVSS score: 9.4.
Read brief →
Jul 9, 2026
Vendor advisory
High-risk advisory
CVE-2026-52778
Composer · yeswiki/yeswiki
YesWiki has Unsafe eval() in its Formula Calculato, Leading to Remote Code Execution & Denial of Service
Operator check
Check whether yeswiki/yeswiki is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. EPSS probability: 0.6%; percentile: 43%.
Read brief →
Jul 9, 2026
Vendor advisory
High-risk advisory
CVE-2026-53932
Composer · wnx/laravel-backup-restore
laravel-backup-restore has an OS Command Injection during database restore
Operator check
Check whether wnx/laravel-backup-restore is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.
Read brief →
Jul 9, 2026
Vendor advisory
High-risk advisory
Composer · craftcms/cms
Craft CMS: RCE via missing cleanseConfig in FieldsController::actionRenderCardPreview
Operator check
Check whether craftcms/cms is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. CVSS score: 8.6.
Read brief →
Jul 9, 2026
Vendor advisory
High-risk advisory
CVE-2026-48862
erlang · mint
mint: Unbounded streams map growth via PUSH_PROMISE without follow-up HEADERS
Operator check
Check whether mint is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. CVSS score: 8.2. EPSS probability: 0.4%; percentile: 30%.
Read brief →
Jul 9, 2026
Vendor advisory
High-risk advisory
CVE-2026-49754
erlang · mint
mint: Unbounded CONTINUATION/HEADERS frame accumulation (CONTINUATION flood)
Operator check
Check whether mint is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. CVSS score: 8.2. EPSS probability: 0.4%; percentile: 30%.
Read brief →
Jul 9, 2026
Vendor advisory
High-risk advisory
CVE-2026-50553
Go · github.com/enchant97/note-mark/backend
Note Mark: Path traversal via unsanitized book/note slug in migrate export (sibling of GHSA-g49p)
Operator check
Check whether github.com/enchant97/note-mark/backend is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. CVSS score: 8.6.
Read brief →
Jul 9, 2026
Vendor advisory
Critical vendor advisory
CVE-2026-58122
Hermes · WebUI
Hermes WebUI before 0.51.307 contains an authentication bypass vulnerability that allows unauthenticated remote attackers to circumvent local-origin IP restrictions on onboarding endpoints by supplying a spoofed X-Forwarded-For header with a loopback address. Attackers can exploit this bypass to perform server-side request forgery against internal services including cloud metadata endpoints, overwrite LLM provider configuration and API keys with attacker-controlled values, or initiate OAuth device-code flows to obtain persistent access tokens stored in auth.json.
Operator check
Review CVE-2026-58122 in your asset inventory. Apply patches per vendor guidance and verify WebUI is not exposed. CVSS score: 9.1.
Read brief →
Jul 9, 2026
Vendor advisory
Critical vendor advisory
CVE-2026-58123
Hermes · WebUI
Hermes WebUI before 0.51.788 contains an unauthenticated remote code execution vulnerability that allows remote attackers to execute arbitrary shell commands by accessing the embedded terminal API endpoints without credentials. Attackers can create a session, attach a PTY shell, and write arbitrary commands through the terminal input endpoint to achieve full command execution as the server process user via four sequential unauthenticated HTTP requests.
Operator check
Review CVE-2026-58123 in your asset inventory. Apply patches per vendor guidance and verify WebUI is not exposed. CVSS score: 9.8.
Read brief →
Jul 9, 2026
Vendor advisory
High-risk advisory
CVE-2026-49485
Maven · ca.uhn.hapi.fhir:org.hl7.fhir.dstu2
org.hl7.fhir.core: ReDoS via FHIRPath matches()/replaceMatches() in FHIR Validator HTTP Endpoint
Operator check
Check whether ca.uhn.hapi.fhir:org.hl7.fhir.dstu2 is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.
Read brief →
Jul 9, 2026
Vendor advisory
High-risk advisory
Maven · io.micronaut:micronaut-http-client
Micronaut doesn't set a maximum redirect count for its HTTP Client, enabling infinite loop DoS
Operator check
Check whether io.micronaut:micronaut-http-client is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.
Read brief →
Jul 9, 2026
Vendor advisory
Critical vendor advisory
CVE-2026-59214
Openwebui · Open Webui
Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. Prior to 0.10.0, Open WebUI runs client-side Python with Pyodide in a same-origin web worker, allowing stored chat payloads that use pyodide.http.pyfetch or the js module fetch and XMLHttpRequest APIs to issue authenticated same-origin requests when a victim clicks Run, which can reach admin-only endpoints and execute server-side code through configured tools. This issue is fixed in version 0.10.0.
Operator check
Review CVE-2026-59214 in your asset inventory. Apply patches per vendor guidance and verify Open Webui is not exposed. CVSS score: 7.3. EPSS probability: 0.2%; percentile: 16%.
Read brief →
Jul 9, 2026
Coordinated disclosure
Patch review
PayRange · Android app
Overview PayRange is a mobile payment app that allows users to pay for vending machines, laundromats, and other unattended machines using a smartphone with Bluetooth. Two vulnerabilities were discovered in version 7.0.7 of the PayRange app that is available in the Google Play store. Description A vulnerability (CVE-2026-13462) exists in the PayRange Android app that causes invalid SSL certificates to be accepted in application WebViews. A second vulnerability (CVE-2026-13461) exists that allows the injection of JavaScript, which can be used to escape the WebView sandbox and perform a number of dangerous actions on the user's device. These vulnerabilities were discovered in version 7.0.7 of the PayRange app. The PayRange app bypasses Android's SSL trust chain and accepts certificates that match any of the following rules (including... Related CVEs: CVE-2026-13461, CVE-2026-13462.
Operator check
Review the CERT/CC Vulnerability Note and compare the affected vendor and product list against your inventory. Apply vendor fixes or compensating controls for Android app where available.
Read brief →
Jul 9, 2026
Vendor advisory
High-risk advisory
CVE-2026-49476
PyPI · soupsieve
Soup Sieve has Memory Exhaustion via Large Comma-Separated Selector Lists
Operator check
Check whether soupsieve is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.
Read brief →
Jul 9, 2026
Vendor advisory
High-risk advisory
CVE-2026-49477
PyPI · soupsieve
Soup Sieve: Regular Expression Denial of Service (ReDoS) via Selector Parser
Operator check
Check whether soupsieve is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.
Read brief →
Jul 9, 2026
Vendor advisory
High-risk advisory
CVE-2026-49851
PyPI · mistune
Mistune: Potential DoS via quadratic-time parsing in parse_link_text
Operator check
Check whether mistune is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. CVSS score: 8.7. EPSS probability: 0.4%; percentile: 27%.
Read brief →
Jul 9, 2026
Vendor advisory
High-risk advisory
PyPI · phantom-audio
Phantom: Arbitrary file write and decode-bomb DoS via unconfined MCP tool paths
Operator check
Check whether phantom-audio is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.
Read brief →
Jul 9, 2026
Vendor advisory
High-risk advisory
CVE-2026-53727
RubyGems · css_parser
Ruby CSS Parser: SSRF and Local File Disclosure in `CssParser::Parser#read_remote_file`
Operator check
Check whether css_parser is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. CVSS score: 8.9.
Read brief →
Jul 9, 2026
Coordinated disclosure
Patch review
Xerte · Online Toolkit
Overview Two vulnerabilities have been discovered in Xerte Online Toolkits, an open-source e-learning authoring toolsuite intended for the creation of learning materials within a web browser. CVE-2026-14261 tracks the persistence of the /setup/ directory after installation, which allows an unauthenticated attacker to reconfigure the application to point to a remote database they control in order to gain administrative access. CVE-2026-12116 tracks an editable antivirus binary path that can be redirected to a PHP interpreter, causing uploaded files to be executed as PHP code and resulting in remote code execution (RCE). Version v3.15.5 or v3.14.6 of Xerte Online Toolkits fixes these vulnerabilities. Description Xerte Online Toolkits is a suite of a free, open-source e-learning authoring tools that allows users to make educational... Related CVEs: CVE-2026-12116, CVE-2026-14261.
Operator check
Review the CERT/CC Vulnerability Note and compare the affected vendor and product list against your inventory. Apply vendor fixes or compensating controls for Online Toolkit where available.
Read brief →
Jul 8, 2026
Vendor advisory
Critical vendor advisory
CVE-2026-58480
Blocksy · Companion Pro plugin for WordPress
Blocksy Companion Pro plugin for WordPress before 2.1.47 contains an unauthenticated arbitrary file upload vulnerability that allows attackers to upload executable files by bypassing extension validation in the save_attachments function exposed through the Advanced Reviews feature. Attackers can exploit the Custom Fonts extension's flawed strpos() substring check by uploading double-extension filenames such as shell.woff2.php, causing the validation to pass on the substring match while the web server executes the file as PHP, achieving remote code execution.
Operator check
Review CVE-2026-58480 in your asset inventory. Apply patches per vendor guidance and verify Companion Pro plugin for WordPress is not exposed. CVSS score: 9.8.
Read brief →
Jul 8, 2026
Vendor advisory
High-risk advisory
CVE-2026-50197
Go · github.com/zalando/skipper
Skipper: opaAuthorizeRequestWithBody filter bypasses OPA policy on Transfer-Encoding — chunked / HTTP/2 requests
Operator check
Check whether github.com/zalando/skipper is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.
Read brief →
Jul 8, 2026
Vendor advisory
High-risk advisory
CVE-2026-52831
Go · github.com/nuclio/nuclio
Nuclio: Unsanitized cron trigger event headers/body injected into CronJob shell command leads to persistent RCE
Operator check
Check whether github.com/nuclio/nuclio is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.
Read brief →
Jul 8, 2026
Vendor advisory
High-risk advisory
CVE-2026-53649
Go · github.com/BishopFox/joro
Joro: Unauthenticated Cross-Origin Plugin Upload Leads to RCE
Operator check
Check whether github.com/BishopFox/joro is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.
Read brief →
Jul 8, 2026
Vendor advisory
Critical vendor advisory
CVE-2026-3144
Ibm · Api Connect
IBM API Connect 12.1.0.0 through 12.1.0.3 uses default credentials which could allow an attacker to gain unauthorized access to the application before the system enforces a credential update.
Operator check
Review CVE-2026-3144 in your asset inventory. Apply patches per vendor guidance and verify Api Connect is not exposed. CVSS score: 8.1. EPSS probability: 0.4%; percentile: 29%.
Read brief →
Jul 8, 2026
Vendor advisory
Critical vendor advisory
CVE-2026-9074
Ibm · Api Connect
IBM API Connect 10.0.8.0 through 10.0.8.9 and 12.1.0.0 through 12.1.0.3 contains an unauthenticated SQL injection vulnerability in the password reset functionality.
Operator check
Review CVE-2026-9074 in your asset inventory. Apply patches per vendor guidance and verify Api Connect is not exposed. CVSS score: 9.1. EPSS probability: 0.4%; percentile: 35%.
Read brief →
Jul 8, 2026
Vendor advisory
High-risk advisory
CVE-2026-49464
Maven · nl.nl-portal:taak
NL Portal: IDOR allows any authenticated user to complete and tamper with another user's taak
Operator check
Check whether nl.nl-portal:taak is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.
Read brief →
Jul 8, 2026
Vendor advisory
High-risk advisory
CVE-2026-49832
Maven · org.dspace:dspace-api
DSpace has possible Remote Code Execution (RCE) through Velocity Templates used by LDN
Operator check
Check whether org.dspace:dspace-api is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.
Read brief →
Jul 8, 2026
Vendor advisory
Critical vendor advisory
CVE-2026-60002
Openbsd · Openssh
ssh in OpenSSH before 10.4 can have a use-after-free when a server changes its host key during a key re-exchange. (This outcome occurs only on the client side.)
Operator check
Review CVE-2026-60002 in your asset inventory. Apply patches per vendor guidance and verify Openssh is not exposed. CVSS score: 7.7. EPSS probability: 0.3%; percentile: 16%.
Read brief →
Jul 8, 2026
Vendor advisory
Critical vendor advisory
CVE-2026-8649
Progress · Moveit Transfer
Improper Neutralization of Special Elements in Data Query Logic vulnerability in Progress MOVEit Transfer (Custom Reports modules). This issue affects MOVEit Transfer: before 2025.0.7, from 2025.1.0 before 2025.1.3.
Operator check
Review CVE-2026-8649 in your asset inventory. Apply patches per vendor guidance and verify Moveit Transfer is not exposed. CVSS score: 6.4. EPSS probability: 0.2%; percentile: 13%.
Read brief →
Jul 8, 2026
Vendor advisory
Critical vendor advisory
CVE-2026-8801
Progress · Moveit Transfer
Path equivalence: vulnerability in Progress MOVEit Transfer (File Upload modules). This issue affects MOVEit Transfer: before 2025.0.8, from 2025.1.0 before 2025.1.4.
Operator check
Review CVE-2026-8801 in your asset inventory. Apply patches per vendor guidance and verify Moveit Transfer is not exposed. CVSS score: 3.5. EPSS probability: 0.3%; percentile: 16%.
Read brief →
Jul 8, 2026
Vendor advisory
High-risk advisory
CVE-2026-49471
PyPI · serena-agent
Serena: Unauthenticated Flask dashboard on fixed port enables DNS rebinding → memory poisoning → RCE
Operator check
Check whether serena-agent is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. EPSS probability: 0.2%; percentile: 15%.
Read brief →
Jul 8, 2026
Vendor advisory
High-risk advisory
CVE-2026-49825
PyPI · lxml_html_clean
`lxml_html_clean.Cleaner` does not strip `javascript:` URLs from namespaced URL attributes
Operator check
Check whether lxml_html_clean is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.
Read brief →
Jul 8, 2026
Coordinated disclosure
Patch review
Unrestricted · Disclosure of Full User Records The Adalo database API
Overview Adalo’s no‑code application platform exposes complete user records through its database API for all applications built on both V1 and V2. Due to a platform-level flaw, authenticated users can retrieve full user data belonging to any Adalo application, regardless of configuration. This issue affects more than one million applications and placing developers and their end users at risk of data exposure that they cannot prevent or remediate. Description Adalo is a Software-as-a-Service (SaaS) provider for building no-code applications. In theory, each application or tenant (customer) is logically isolated with separate databases, users, and configurations. CVE-2026-10706 Unrestricted Disclosure of Full User Records The Adalo database API contains a flaw which allows the backend to return complete user records for every list... Related CVEs: CVE-2026-10706, CVE-2026-10708.
Operator check
Review the CERT/CC Vulnerability Note and compare the affected vendor and product list against your inventory. Apply vendor fixes or compensating controls for Disclosure of Full User Records The Adalo database API where available.
Read brief →
Jul 7, 2026
KEV
Known exploited
CVE-2026-48282
Adobe · ColdFusion
Adobe ColdFusion contains a path traversal vulnerability that could lead to arbitrary code execution in the context of the current user.
Operator check
Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
Read brief →
Jul 7, 2026
Vendor advisory
Critical vendor advisory
CVE-2026-27823
Composer · egroupware/egroupware
EGroupware has a Remote Code Execution Vulnerability
Operator check
Check whether egroupware/egroupware is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. CVSS score: 9.3.
Read brief →
Jul 7, 2026
Vendor advisory
High-risk advisory
CVE-2026-40187
Composer · egroupware/egroupware
EGroupware has Authenticated RCE via Malicious eTemplate Upload
Operator check
Check whether egroupware/egroupware is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. CVSS score: 8.6.
Read brief →
Jul 7, 2026
Vendor advisory
Critical vendor advisory
CVE-2026-13020
Esri · Portal For Arcgis
A Weak Password Recovery Mechanism for Forgotten Password exists in Esri Portal for ArcGIS versions 12.1 and earlier on Windows, Linux and Kubernetes. A remote, unauthorized attacker may assume ownership of a user’s account by manipulating this mechanism. ArcGIS Administrators should configure an email server with ArcGIS Enterprise to facilitate user self-service password recovery. The ability for an administrator to reset a user’s password remains unchanged.
Operator check
Review CVE-2026-13020 in your asset inventory. Apply patches per vendor guidance and verify Portal For Arcgis is not exposed. CVSS score: 8.1. EPSS probability: 0.2%; percentile: 13%.
Read brief →
Jul 7, 2026
Vendor advisory
High-risk advisory
CVE-2026-33655
Go · github.com/QuantumNous/new-api
New API: SSRF Protection Bypass via Unresolved Hostname in Notification URLs
Operator check
Check whether github.com/QuantumNous/new-api is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.
Read brief →
Jul 7, 2026
Vendor advisory
High-risk advisory
CVE-2026-53552
Go · github.com/zhenorzz/goploy
Goploy: Cross-namespace IDOR and RCE via body-supplied row id in project and project_file handlers
Operator check
Check whether github.com/zhenorzz/goploy is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.
Read brief →
Jul 7, 2026
Vendor advisory
High-risk advisory
CVE-2026-53553
Go · github.com/zhenorzz/goploy
Goploy: Arbitrary File Read via Path Traversal in /deploy/fileDiff allows Remote Server Compromise
Operator check
Check whether github.com/zhenorzz/goploy is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.
Read brief →
Jul 7, 2026
KEV
Known exploited
CVE-2026-56290
Joomlack · Page Builder
Joomlack Page Builder contains an improper access control vulnerability that could allow for remote code execution via unauthenticated arbitrary file upload.
Operator check
Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
Read brief →
Jul 7, 2026
KEV
Known exploited
CVE-2026-48908
JoomShaper · SP Page Builder
JoomShaper SP Page Builder contains an unrestricted upload of file with dangerous type vulnerability that allows unauthenticated users to upload arbitrary files, ultimately resulting in the upload and execution of PHP code.
Operator check
Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
Read brief →
Jul 7, 2026
KEV
Known exploited
CVE-2026-55255
Langflow · Langflow
Langflow contains an authorization bypass through user-controlled key vulnerability which allows an authenticated attacker to execute any flow belonging to another user by specifying the victim's flow ID in the request.
Operator check
Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
Read brief →
Jul 7, 2026
Vendor advisory
High-risk advisory
CVE-2026-34151
Maven · org.xwiki.platform:xwiki-platform-oldcore
XWiki Platform Old Core: Resource path traversal via /skin/ action endpoint in Jetty 12+
Operator check
Check whether org.xwiki.platform:xwiki-platform-oldcore is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. CVSS score: 8.2.
Read brief →
Jul 7, 2026
Vendor advisory
High-risk advisory
CVE-2026-53512
npm · better-auth
Better Auth: OAuth refresh-token replay via missing client authentication on oidc-provider and mcp plugins
Operator check
Check whether better-auth is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.
Read brief →
Jul 7, 2026
Vendor advisory
High-risk advisory
CVE-2026-53513
npm · @better-auth/sso
@better-auth/sso provider registration has server-side request forgery via unvalidated OIDC endpoints
Operator check
Check whether @better-auth/sso is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.
Read brief →
Jul 7, 2026
Vendor advisory
High-risk advisory
CVE-2026-53514
npm · better-auth
Better Auth vulnerable to unauthorized invitation acceptance via unverified email match in organization plugin
Operator check
Check whether better-auth is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.
Read brief →
Jul 7, 2026
Vendor advisory
High-risk advisory
CVE-2026-53516
npm · better-auth
Better Auth has an account takeover issue via OAuth auto-link to unverified pre-registered email
Operator check
Check whether better-auth is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.
Read brief →
Jul 7, 2026
Vendor advisory
High-risk advisory
CVE-2026-53517
npm · @better-auth/oauth-provider
Better Auth: OAuth refresh-token rotation forks the token family on concurrent redemption
Operator check
Check whether @better-auth/oauth-provider is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. CVSS score: 7.6.
Read brief →
Jul 7, 2026
Vendor advisory
High-risk advisory
CVE-2026-53518
npm · @better-auth/oauth-provider
@better-auth/oauth-provider's OAuth authorization-code grant allows concurrent redemption when two token requests race the find-then-delete primitive
Operator check
Check whether @better-auth/oauth-provider is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. CVSS score: 7.6.
Read brief →
Jul 7, 2026
Vendor advisory
High-risk advisory
npm · better-auth
Better Auth has stored XSS in the auth-server origin via javascript: redirect_uri in oidc-provider and mcp
Operator check
Check whether better-auth is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.
Read brief →
Jul 7, 2026
Vendor advisory
High-risk advisory
npm · better-auth
Better Auth has insecure cryptographic defaults in oidcProvider: alg=none advertised and plain PKCE accepted by default
Operator check
Check whether better-auth is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.
Read brief →
Jul 7, 2026
Vendor advisory
High-risk advisory
npm · @better-auth/scim
@better-auth/scim: Account/provider takeover via missing owner binding on non-org SCIM providers
Operator check
Check whether @better-auth/scim is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.
Read brief →
Jul 7, 2026
Vendor advisory
High-risk advisory
CVE-2025-46719
PyPI · open-webui
Open WebUI vulnerable to stored XSS via unescaped markdown token in MarkdownTokens.svelte leading to full account takeover and RCE via functions
Operator check
Check whether open-webui is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. CVSS score: 7.4. EPSS probability: 0.4%; percentile: 35%.
Read brief →
Jul 7, 2026
Vendor advisory
High-risk advisory
CVE-2026-26192
PyPI · open-webui
Open WebUI vulnerable to Stored XSS via iFrame in citations model
Operator check
Check whether open-webui is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. EPSS probability: 0.2%; percentile: 9%.
Read brief →
Jul 7, 2026
Vendor advisory
High-risk advisory
CVE-2026-26193
PyPI · open-webui
Open WebUI vulnerable to Stored XSS via iFrame embeds in response messages
Operator check
Check whether open-webui is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. EPSS probability: 0.2%; percentile: 10%.
Read brief →
Jul 7, 2026
Vendor advisory
High-risk advisory
CVE-2026-53530
Rust · ratex-parser
ratex-parser panics on `\verb` with a multibyte delimiter (UTF-8 byte-boundary slice)
Operator check
Check whether ratex-parser is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. CVSS score: 8.7.
Read brief →
Jul 7, 2026
Vendor advisory
High-risk advisory
Rust · uucore
uutils coreutils: cp/install/mv/ln --suffix alone does not enable backup mode (silent data loss vs GNU)
Operator check
Check whether uucore is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. CVSS score: 7.0.
Read brief →
Jul 6, 2026
Vendor advisory
Critical vendor advisory
CVE-2026-40139
Beyondtrust · Privileged Remote Access
A critical pre-authentication vulnerability exists in the authentication subsystem of BeyondTrust Remote Support. Improper processing of authentication requests may allow an unauthenticated remote attacker to bypass access controls and gain unauthorized access to the appliance, including accounts with elevated privileges. Exploitation requires a specific authentication configuration to be enabled.
Operator check
Review CVE-2026-40139 in your asset inventory. Apply patches per vendor guidance and verify Privileged Remote Access is not exposed. CVSS score: 9.8. EPSS probability: 0.7%; percentile: 49%.
Read brief →
Jul 6, 2026
Vendor advisory
Critical vendor advisory
CVE-2026-40141
Beyondtrust · Privileged Remote Access
A high-severity vulnerability exists in a web application component of BeyondTrust Remote Support and Privileged Remote Access related to the processing of certain input parameters. Insufficient validation of user-supplied input may allow an authenticated attacker with limited privileges to access unintended resources or data beyond their authorization scope. Exploitation is restricted to accounts with specific permissions.
Operator check
Review CVE-2026-40141 in your asset inventory. Apply patches per vendor guidance and verify Privileged Remote Access is not exposed. CVSS score: 9.9. EPSS probability: 0.4%; percentile: 33%.
Read brief →
Jul 6, 2026
Vendor advisory
High-risk advisory
CVE-2026-52889
Composer · verbb/formie
Formie Hidden field defaults vulnerable to Server-Side Template Injection
Operator check
Check whether verbb/formie is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.
Read brief →
Jul 6, 2026
Vendor advisory
High-risk advisory
CVE-2026-55790
Composer · craftcms/cms
Craft CMS: DOM XSS via GitHub issue title in CraftSupport widget
Operator check
Check whether craftcms/cms is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. CVSS score: 7.4. EPSS probability: 0.3%; percentile: 23%.
Read brief →
Jul 6, 2026
Vendor advisory
High-risk advisory
CVE-2026-55794
Composer · craftcms/cms
Craft CMS: Potential authenticated Remote Code Execution via referrer redirect
Operator check
Check whether craftcms/cms is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. CVSS score: 8.7. EPSS probability: 0.3%; percentile: 21%.
Read brief →
Jul 6, 2026
Vendor advisory
Critical vendor advisory
CVE-2026-9182
Esri · Arcgis Server
ArcGIS Server contains an unrestricted file upload vulnerability. An unauthenticated attacker could exploit this issue by uploading a crafted file to the affected endpoint. Successful exploitation could allow arbitrary file upload.
Operator check
Review CVE-2026-9182 in your asset inventory. Apply patches per vendor guidance and verify Arcgis Server is not exposed. CVSS score: 5.3. EPSS probability: 0.2%; percentile: 13%.
Read brief →
Jul 6, 2026
Vendor advisory
High-risk advisory
CVE-2026-49445
Go · github.com/cilium/cilium
Cilium vulnerable to sensitive information disclosure and cluster disruption via local Envoy admin socket access
Operator check
Check whether github.com/cilium/cilium is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.
Read brief →
Jul 6, 2026
Vendor advisory
High-risk advisory
CVE-2026-55075
Go · github.com/coder/coder/v2
Coder vulnerable to OIDC account takeover via email-based user matching and email_verified bypass
Operator check
Check whether github.com/coder/coder/v2 is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.
Read brief →
Jul 6, 2026
Vendor advisory
High-risk advisory
CVE-2026-55076
Go · github.com/coder/coder/v2
Coder's OIDC email_verified type coercion bypass enables account takeover via unverified email linking
Operator check
Check whether github.com/coder/coder/v2 is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.
Read brief →
Jul 6, 2026
Vendor advisory
High-risk advisory
CVE-2026-55077
Go · github.com/coder/coder/v2
Coder: User-admin role can reset owner account password
Operator check
Check whether github.com/coder/coder/v2 is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.
Read brief →
Jul 6, 2026
Vendor advisory
High-risk advisory
CVE-2026-55427
Go · github.com/coder/coder/v2
Coder vulnerable to SSH config injection via unsanitized server-supplied values in `coder config-ssh`
Operator check
Check whether github.com/coder/coder/v2 is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.
Read brief →
Jul 6, 2026
Vendor advisory
High-risk advisory
CVE-2026-55428
Go · github.com/coder/coder/v2
Coder: Route hijacking through lack of validation of agent-supplied AllowedIPs in tailnet coordinator
Operator check
Check whether github.com/coder/coder/v2 is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.
Read brief →
Jul 6, 2026
Vendor advisory
High-risk advisory
CVE-2026-55429
Go · github.com/coder/coder/v2
Coder's workspace app upsert allows cross-workspace agent rebinding via user-controlled app ID
Operator check
Check whether github.com/coder/coder/v2 is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.
Read brief →
Jul 6, 2026
Vendor advisory
High-risk advisory
CVE-2026-55431
Go · github.com/coder/coder/v2
Coder's session token leaked to arbitrary hosts via `coder open app` for external workspace apps
Operator check
Check whether github.com/coder/coder/v2 is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.
Read brief →
Jul 6, 2026
Vendor advisory
High-risk advisory
CVE-2026-55436
Go · github.com/coder/coder/v2
Coder's AI Bridge Proxy skips TLS certificate verification in default configuration
Operator check
Check whether github.com/coder/coder/v2 is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.
Read brief →
Jul 6, 2026
Vendor advisory
High-risk advisory
Go · github.com/coder/coder/v2
Coder's workspace agent API insecure redirect handling allowed cross-agent file read and write
Operator check
Check whether github.com/coder/coder/v2 is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.
Read brief →
Jul 6, 2026
Vendor advisory
High-risk advisory
CVE-2026-54640
Maven · io.openremote:openremote-agent
OpenRemote has an incomplete fix for CVE-2026-40882: XXE in KNXProtocol.startAssetImport() allows arbitrary file read via unprotected XMLInputFactory
Operator check
Check whether io.openremote:openremote-agent is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.
Read brief →
Jul 6, 2026
Vendor advisory
High-risk advisory
CVE-2026-54641
Maven · io.openremote:openremote-manager
OpenRemote has Cross-Realm User Information Disclosure in UserResourceImpl
Operator check
Check whether io.openremote:openremote-manager is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.
Read brief →
Jul 6, 2026
Vendor advisory
High-risk advisory
Maven · io.openremote:openremote-manager
OpenRemote has Authenticated SQL Injection via Datapoint Crosstab Export
Operator check
Check whether io.openremote:openremote-manager is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. CVSS score: 7.2.
Read brief →
Jul 6, 2026
Vendor advisory
High-risk advisory
CVE-2026-53486
npm · @xhmikosr/decompress
Decompress: Archive extraction can create files and links outside of the target directory
Operator check
Check whether @xhmikosr/decompress is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.
Read brief →
Jul 6, 2026
Vendor advisory
High-risk advisory
CVE-2026-55500
npm · 9router
9routers has Exposure of Sensitive Information and Unprotected Database Import/Export, Allowing Complete Credential Theft and Database Takeover
Operator check
Check whether 9router is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.
Read brief →
Jul 6, 2026
Vendor advisory
High-risk advisory
CVE-2026-55501
npm · 9router
9router: Login brute-force protection bypass via spoofed X-Forwarded-For header
Operator check
Check whether 9router is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.
Read brief →
Jul 6, 2026
Vendor advisory
High-risk advisory
npm · 9router
9router has unauthenticated CRUD on /api/providers and Full API Key Leak via /api/usage/stats
Operator check
Check whether 9router is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.
Read brief →
Jul 6, 2026
Coordinated disclosure
Patch review
Overview · HP Printers in the Deskjet 2800 Series running firmware
Overview HP Printers in the Deskjet 2800 Series running firmware version CVE-2026-13753 . This vulnerability allows unauthenticated access to the printer's webserver API endpoints, exposing Wi-Fi credentials, management configuration details, and sensitive security data normally restricted to administrative users. Description Modern HP printers provide a web-based management interface for configuring content such as Wi-Fi Direct settings, SNMP management access, and device security options. When accessed normally through the browser interface, these pages explicitly require administrator credentials before sensitive information is displayed. This information is protected because, for example, Wi-Fi Direct controls the printer's direct wireless connectivity, and SNMP configuration settings can reveal detailed information about the... Related CVEs: CVE-2026-13753.
Operator check
Review the CERT/CC Vulnerability Note and compare the affected vendor and product list against your inventory. Apply vendor fixes or compensating controls for HP Printers in the Deskjet 2800 Series running firmware where available.
Read brief →
Jul 6, 2026
Vendor advisory
Critical vendor advisory
CVE-2026-54760
PyPI · langroid
Langroid: SQLChatAgent dangerous-function blocklist can be bypassed with quoted or schema-qualified pg_read_file calls
Operator check
Check whether langroid is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. CVSS score: 9.3.
Read brief →
Jul 6, 2026
Vendor advisory
High-risk advisory
CVE-2026-54769
PyPI · langroid
Langroid: Sandbox Escape to Remote Code Execution via Incomplete `eval()` Mitigation in TableChatAgent
Operator check
Check whether langroid is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.
Read brief →
Jul 6, 2026
Vendor advisory
High-risk advisory
CVE-2026-54771
PyPI · langroid
Langroid: handle_message() executes user-supplied tool JSON without sender verification
Operator check
Check whether langroid is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.
Read brief →
Jul 6, 2026
Vendor advisory
High-risk advisory
CVE-2026-55426
PyPI · linuxfabrik-lib
Linuxfabrik Monitoring Plugins have local privilege escalation using embedded command
Operator check
Check whether linuxfabrik-lib is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.
Read brief →
Jul 6, 2026
Vendor advisory
Critical vendor advisory
CVE-2026-55615
PyPI · langroid
Langroid: Neo4jChatAgent executes LLM-generated Cypher without validation (prompt-to-Cypher injection; config-conditional RCE), mirroring the SQLChatAgent bug fixed in CVE-2026-25879
Operator check
Check whether langroid is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. CVSS score: 9.2.
Read brief →
Jul 6, 2026
Vendor advisory
High-risk advisory
CVE-2026-55786
PyPI · flyto-core
flyto-core has Unauthenticated Command Execution via HTTP MCP `execute_module`
Operator check
Check whether flyto-core is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.
Read brief →
Jul 6, 2026
Vendor advisory
High-risk advisory
CVE-2026-55787
PyPI · flyto-core
flyto-core has SSRF guard bypass via IPv6 transition addresses (IPv4-mapped / 6to4 / NAT64) in validate_url_ssrf
Operator check
Check whether flyto-core is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.
Read brief →
Jul 6, 2026
Vendor advisory
High-risk advisory
CVE-2026-35338
Rust · uu_chmod
chmod: --preserve-root bypassed by any path that resolves to root (e.g. /../)
Operator check
Check whether uu_chmod is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. EPSS probability: 0.2%; percentile: 7%.
Read brief →
Jul 6, 2026
Vendor advisory
High-risk advisory
CVE-2026-35341
Rust · uu_mkfifo
mkfifo: permissions of an existing file are changed after FIFO creation fails
Operator check
Check whether uu_mkfifo is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. EPSS probability: 0.2%; percentile: 6%.
Read brief →
Jul 6, 2026
Vendor advisory
High-risk advisory
CVE-2026-54496
Rust · zebrad
Zebra: Missing copy constraint in halo2_gadgets variable-base scalar multiplication allows under-constrained base, breaking Orchard Action circuit soundness
Operator check
Check whether zebrad is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.
Read brief →
Jul 6, 2026
Coordinated disclosure
Patch review
Tenda · firmware (multiple
Overview Several versions of Tenda firmware contain an undocumented authentication backdoor that grants administrative access to the devices' web management interfaces. An attacker can expoit this vulnerability, tracked as CVE-2026-11405, to bypass the password verification process and obtain full administrative control without valid credentials. Affected Versions: * US_FH1201V1.0BR_V1.2.0.14(408)_EN_TD * US_W15EV1.0br_V15.11.0.5(1068_1567_841)_EN_TDE * US_AC10V1.0re_V15.03.06.46_multi_TDE01 * US_AC5V1.0RTL_V15.03.06.48_multi_TDE01 * US_AC6V2.0RTL_V15.03.06.51_multi_T Description Tenda is a supplier of home and business network devices such as routers, switches, wireless access points, and video surveillance equipment. Most of these devices include web-based interfaces that allow users to perform configuration and management operations... Related CVEs: CVE-2026-11405.
Operator check
Review the CERT/CC Vulnerability Note and compare the affected vendor and product list against your inventory. Apply vendor fixes or compensating controls for firmware (multiple where available.
Read brief →
Jul 6, 2026
Vendor advisory
Critical vendor advisory
CVE-2026-54763
Traefik · Traefik
Traefik is an HTTP reverse proxy and load balancer. Prior to v2.11.51, v3.6.22, and v3.7.6, Traefik's BasicAuth, DigestAuth, and ForwardAuth middlewares strip canonical-cased spoofed identity headers before writing Traefik's own value, but do not account for underscore-variant header names, which many backends normalize identically to dashed forms. An attacker able to reach a protected route can inject an underscore-variant header that survives Traefik's stripping and reaches the backend alongside, or on the unauthenticated ForwardAuth authResponseHeaders path instead of, the value Traefik int
Operator check
Review CVE-2026-54763 in your asset inventory. Apply patches per vendor guidance and verify Traefik is not exposed. CVSS score: 10.0. EPSS probability: 0.3%; percentile: 19%.
Read brief →
Jul 2, 2026
Vendor advisory
Critical vendor advisory
CVE-2026-59099
Apereo · CAS 7.3.0
Apereo CAS 7.3.0 before 8.0.0-RC6 contains a cryptographic vulnerability that allows remote unauthenticated attackers to recover plaintext conversation state by exploiting AES-GCM initialization vector reuse across the server lifetime. Attackers can collect multiple client-side webflow execution tokens from the unauthenticated login page and perform known-plaintext analysis to decrypt the webflow conversation state due to keystream reuse caused by a fixed all-zero IV paired with the same encryption key.
Operator check
Review CVE-2026-59099 in your asset inventory. Apply patches per vendor guidance and verify CAS 7.3.0 is not exposed. CVSS score: 9.1. EPSS probability: 0.4%; percentile: 28%.
Read brief →
Jul 2, 2026
Vendor advisory
High-risk advisory
CVE-2026-49283
Composer · simplesamlphp/saml2
SimpleSAMLphp HTTP-Artifact TLS validator confusion allows cross-IdP authentication bypass
Operator check
Check whether simplesamlphp/saml2 is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.
Read brief →
Jul 2, 2026
Vendor advisory
High-risk advisory
CVE-2026-49284
Composer · simplesamlphp/simplesamlphp
SimpleSAMLphp SP accepts a response from an unexpected IdP when unsigned `Response/InResponseTo` is combined with a signed assertion lacking `SubjectConfirmationData/InResponseTo`
Operator check
Check whether simplesamlphp/simplesamlphp is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.
Read brief →
Jul 2, 2026
Vendor advisory
High-risk advisory
CVE-2026-49289
Composer · simplesamlphp/saml2
SimpleSAMLphp has Possible DoS via XPath Transform
Operator check
Check whether simplesamlphp/saml2 is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.
Read brief →
Jul 2, 2026
Vendor advisory
High-risk advisory
CVE-2026-50281
Composer · craftcms/cms
Craft CMS's mass assignment via id in newAttributes during bulk duplicate overwrites existing elements
Operator check
Check whether craftcms/cms is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. CVSS score: 7.1. EPSS probability: 0.3%; percentile: 17%.
Read brief →
Jul 2, 2026
Vendor advisory
High-risk advisory
CVE-2026-50282
Composer · craftcms/cms
Craft CMS Vulnerable to Unauthorized Deletion of Destination Folders During Forced Moves
Operator check
Check whether craftcms/cms is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. CVSS score: 7.1. EPSS probability: 0.2%; percentile: 11%.
Read brief →
Jul 2, 2026
Vendor advisory
High-risk advisory
CVE-2026-9558
Composer · mautic/core
Mautic has Server-Side Template Injection (SSTI) in Theme Templates
Operator check
Check whether mautic/core is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. EPSS probability: 0.4%; percentile: 35%.
Read brief →
Jul 2, 2026
Vendor advisory
High-risk advisory
CVE-2026-9559
Composer · mautic/core
Mautic vulnerable to Path Traversal via Campaign Import
Operator check
Check whether mautic/core is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. EPSS probability: 0.6%; percentile: 44%.
Read brief →
Jul 2, 2026
Vendor advisory
High-risk advisory
CVE-2026-9808
Composer · mautic/core
Mautic has an Authorization Bypass in API v2 Endpoints
Operator check
Check whether mautic/core is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. EPSS probability: 0.2%; percentile: 10%.
Read brief →
Jul 2, 2026
Vendor advisory
High-risk advisory
CVE-2026-9809
Composer · mautic/core
Mautic has Stored Cross-Site Scripting (XSS) in Projects Component
Operator check
Check whether mautic/core is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. EPSS probability: 0.2%; percentile: 6%.
Read brief →
Jul 2, 2026
Vendor advisory
High-risk advisory
CVE-2026-46599
Go · golang.org/x/image
golang.org/x/image/tiff has excessive resource consumption in PackBits decompression
Operator check
Check whether golang.org/x/image is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. EPSS probability: 0.4%; percentile: 27%.
Read brief →
Jul 2, 2026
Vendor advisory
High-risk advisory
CVE-2026-52792
Go · github.com/xyproto/algernon
Algernon vulnerable to server-side script source disclosure on Windows via NTFS filename
Operator check
Check whether github.com/xyproto/algernon is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. CVSS score: 8.7.
Read brief →
Jul 2, 2026
Coordinated disclosure
Patch review
Little · Orbits GameFirst Anti-Cheat
Overview The GamersFirst Anti-Cheat (GFAC) driver GFAC.sys contains multiple local privilege escalations and denial-of-service vulnerabilities stemming from insecure handling of user-controlled input through a minifilter communication port. A local attacker can abuse these flaws to perform arbitrary kernel memory writes, obtain privilege escalation to SYSTEM, or trigger a system crash. Description GFAC is a proprietary anti-cheat software developed by video game publisher Little Orbit. GFAC includes a kernel-mode driver, GFAC_Sys_x64.sys , that exposes privileged functionality to user-mode applications through a minifilter communication port. Although these low-level interfaces are necessary for the software's operation, vulnerabilities can arise if user-mode access is not properly restricted and validated. CVE-2026-12166... Related CVEs: CVE-2026-12166, CVE-2026-12167, CVE-2026-12168.
Operator check
Review the CERT/CC Vulnerability Note and compare the affected vendor and product list against your inventory. Apply vendor fixes or compensating controls for Orbits GameFirst Anti-Cheat where available.
Read brief →
Jul 2, 2026
Vendor advisory
High-risk advisory
CVE-2026-2092
Maven · org.keycloak:keycloak-services
Keycloak: Unauthorized access via improper validation of encrypted SAML assertions
Operator check
Check whether org.keycloak:keycloak-services is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. EPSS probability: 0.2%; percentile: 15%.
Read brief →
Jul 2, 2026
Vendor advisory
High-risk advisory
CVE-2026-54617
Maven · pro.gravit.launcher:launchserver-api
LaunchServer FileServerHandler has an unauthenticated path traversal issue
Operator check
Check whether pro.gravit.launcher:launchserver-api is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.
Read brief →
Jul 2, 2026
Patch Tuesday
High-risk advisory
CVE-2026-26145
Microsoft · Azure Synapse
Improper access control in Azure Synapse allows an authorized attacker to elevate privileges over a network. Published in July 2026 Early Security Updates. MSRC exploitability: Publicly Disclosed:No;Exploited:No;Latest Software Release:N/A.
Operator check
Review the Microsoft Security Update Guide entry for CVE-2026-26145. Confirm whether Azure Synapse is deployed, then apply the current security update or documented mitigation. CVSS score: 4.8.
Read brief →
Jul 2, 2026
Patch Tuesday
Critical vendor advisory
CVE-2026-41106
Microsoft · M365 Copilot
Url redirection to untrusted site ('open redirect') in M365 Copilot allows an unauthorized attacker to elevate privileges over a network. Published in July 2026 Early Security Updates. MSRC exploitability: Publicly Disclosed:No;Exploited:No;Latest Software Release:N/A.
Operator check
Review the Microsoft Security Update Guide entry for CVE-2026-41106. Confirm whether M365 Copilot is deployed, then apply the current security update or documented mitigation. CVSS score: 9.3.
Read brief →
Jul 2, 2026
Patch Tuesday
Critical vendor advisory
CVE-2026-45499
Microsoft · Azure OpenAI
Server-side request forgery (ssrf) in Azure OpenAI allows an authorized attacker to elevate privileges over a network. Published in July 2026 Early Security Updates. MSRC exploitability: Publicly Disclosed:No;Exploited:No;Latest Software Release:N/A.
Operator check
Review the Microsoft Security Update Guide entry for CVE-2026-45499. Confirm whether Azure OpenAI is deployed, then apply the current security update or documented mitigation. CVSS score: 9.9.
Read brief →
Jul 2, 2026
Patch Tuesday
High-risk advisory
CVE-2026-54998
Microsoft · Microsoft Exchange Online
Incorrect authorization in Microsoft Exchange Online allows an authorized attacker to elevate privileges over a network. Published in July 2026 Early Security Updates. MSRC exploitability: Publicly Disclosed:No;Exploited:No;Latest Software Release:N/A.
Operator check
Review the Microsoft Security Update Guide entry for CVE-2026-54998. Confirm whether Microsoft Exchange Online is deployed, then apply the current security update or documented mitigation. CVSS score: 8.8.
Read brief →
Jul 2, 2026
Patch Tuesday
High-risk advisory
CVE-2026-56645
Microsoft · Microsoft Edge (Chromium-based)
Heap-based buffer overflow in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network. Published in July 2026 Early Security Updates. MSRC exploitability: Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation Less Likely.
Operator check
Review the Microsoft Security Update Guide entry for CVE-2026-56645. Confirm whether Microsoft Edge (Chromium-based) is deployed, then apply the current security update or documented mitigation. CVSS score: 8.8.
Read brief →
Jul 2, 2026
Patch Tuesday
Critical vendor advisory
CVE-2026-57100
Microsoft · Microsoft Entra Provisioning Service (SyncFabric)
Server-side request forgery (ssrf) in Microsoft Entra Provisioning Service (SyncFabric) allows an authorized attacker to elevate privileges over a network. Published in July 2026 Early Security Updates. MSRC exploitability: Publicly Disclosed:No;Exploited:No;Latest Software Release:N/A.
Operator check
Review the Microsoft Security Update Guide entry for CVE-2026-57100. Confirm whether Microsoft Entra Provisioning Service (SyncFabric) is deployed, then apply the current security update or documented mitigation. CVSS score: 9.9.
Read brief →
Jul 2, 2026
Patch Tuesday
High-risk advisory
CVE-2026-57974
Microsoft · Microsoft Edge (Chromium-based)
Integer overflow or wraparound in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network. Published in July 2026 Early Security Updates. MSRC exploitability: Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation Unlikely.
Operator check
Review the Microsoft Security Update Guide entry for CVE-2026-57974. Confirm whether Microsoft Edge (Chromium-based) is deployed, then apply the current security update or documented mitigation. CVSS score: 8.8.
Read brief →
Jul 2, 2026
Patch Tuesday
High-risk advisory
CVE-2026-57981
Microsoft · Microsoft Edge (Chromium-based)
Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network. Published in July 2026 Early Security Updates. MSRC exploitability: Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation Unlikely.
Operator check
Review the Microsoft Security Update Guide entry for CVE-2026-57981. Confirm whether Microsoft Edge (Chromium-based) is deployed, then apply the current security update or documented mitigation. CVSS score: 8.8.
Read brief →
Jul 2, 2026
Patch Tuesday
Critical vendor advisory
CVE-2026-58289
Microsoft · Microsoft Edge (Chromium-based)
Access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network. Published in July 2026 Early Security Updates. MSRC exploitability: Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation Unlikely.
Operator check
Review the Microsoft Security Update Guide entry for CVE-2026-58289. Confirm whether Microsoft Edge (Chromium-based) is deployed, then apply the current security update or documented mitigation. CVSS score: 9.0.
Read brief →
Jul 2, 2026
Vendor advisory
High-risk advisory
CVE-2026-49352
npm · 9router
9router's Hardcoded Default fallback JWT Secret Allows Authentication Bypass
Operator check
Check whether 9router is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.
Read brief →
Jul 2, 2026
Vendor advisory
High-risk advisory
CVE-2026-49353
npm · 9router
9router has an Incomplete Fix: Local-Only Access Gate Bypass in 9router via Host Header SpoofING
Operator check
Check whether 9router is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.
Read brief →
Jul 2, 2026
Vendor advisory
High-risk advisory
CVE-2026-52746
npm · jsonata
jsonata: Malicious inputs to "$toMillis" function can cause resource exhaustion
Operator check
Check whether jsonata is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.
Read brief →
Jul 2, 2026
Vendor advisory
High-risk advisory
npm · @asymmetric-effort/nogginlessdom
@asymmetric-effort/nogginlessdom's Path Traversal in matchFileSnapshot allows arbitrary file write
Operator check
Check whether @asymmetric-effort/nogginlessdom is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. CVSS score: 8.7.
Read brief →
Jul 2, 2026
Vendor advisory
Critical vendor advisory
npm · 9router
9router: Missing Authorization and OS Command Injection
Operator check
Check whether 9router is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. CVSS score: 9.2.
Read brief →
Jul 2, 2026
Vendor advisory
Critical vendor advisory
npm · openclaw
OpenClaw: QQBot admin commands could skip DM-only and allowFrom policy
Operator check
Check whether openclaw is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. CVSS score: 9.3.
Read brief →
Jul 2, 2026
Vendor advisory
High-risk advisory
CVE-2026-50194
NuGet · Steeltoe.Management.Endpoint
Steeltoe vulnerable to management-port isolation bypass via spoofed Host header
Operator check
Check whether Steeltoe.Management.Endpoint is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. EPSS probability: 0.2%; percentile: 15%.
Read brief →
Jul 2, 2026
Vendor advisory
High-risk advisory
CVE-2026-50196
NuGet · Steeltoe.Discovery.Eureka
Steeltoe.Discovery.Eureka: Unrecognized DataCenterInfo.Name poisons entire registry fetch
Operator check
Check whether Steeltoe.Discovery.Eureka is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. EPSS probability: 0.3%; percentile: 26%.
Read brief →
Jul 2, 2026
Vendor advisory
High-risk advisory
CVE-2026-50200
NuGet · Steeltoe.Management.Endpoint
Steeltoe's env sanitizer misses connection strings — leaks embedded DB passwords
Operator check
Check whether Steeltoe.Management.Endpoint is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. EPSS probability: 0.2%; percentile: 8%.
Read brief →
Jul 2, 2026
Vendor advisory
High-risk advisory
CVE-2026-49360
PyPI · recce
Recce server has unauthenticated SQL execution that allows local file read/write through DuckDB
Operator check
Check whether recce is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. CVSS score: 7.8.
Read brief →
Jul 2, 2026
Vendor advisory
High-risk advisory
CVE-2026-50027
PyPI · mcp-memory-service
mcp-memory-service: Missing Authentication on Document API Endpoints Allows Unauthenticated Memory Read/Write/Delete
Operator check
Check whether mcp-memory-service is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.
Read brief →
Jul 2, 2026
Vendor advisory
High-risk advisory
CVE-2026-52817
PyPI · linuxfabrik-lib
Linuxfabrik Monitoring Plugins: Sudoers may be able to obtain privilege escalation via /usr/bin/apt-get arguments
Operator check
Check whether linuxfabrik-lib is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. CVSS score: 7.0.
Read brief →
Jul 2, 2026
Vendor advisory
High-risk advisory
CVE-2026-52830
PyPI · fast-mcp-telegram
fast-mcp-telegram: Bearer token path traversal bypasses reserved Telegram session protection
Operator check
Check whether fast-mcp-telegram is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.
Read brief →
Jul 2, 2026
Vendor advisory
Critical vendor advisory
CVE-2026-52735
Rust · zebra-script
zebrad has consensus divergence via P2SH sigop undercount in pure-Rust disabled-opcode parser
Operator check
Check whether zebra-script is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. CVSS score: 9.3.
Read brief →
Jul 2, 2026
Vendor advisory
High-risk advisory
CVE-2026-52736
Rust · zebra-state
Zebra has block suppression via NU5 same-header body poisoning of sent-hash cache
Operator check
Check whether zebra-state is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. CVSS score: 8.7.
Read brief →
Jul 2, 2026
Vendor advisory
High-risk advisory
CVE-2026-52829
Rust · zebra-network
Zebra Address Book Aborted by IPv4-Mapped Mempool Misbehavior Update
Operator check
Check whether zebra-network is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.
Read brief →
Jul 2, 2026
Vendor advisory
High-risk advisory
CVE-2026-52834
Rust · jxl-grid
jxl-grid on 32-bit platforms has an out-of-bounds writes due to integer overflow
Operator check
Check whether jxl-grid is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.
Read brief →
Jul 1, 2026
Vendor advisory
High-risk advisory
CVE-2026-49981
Composer · twig/twig
Twig: Sandbox filter, tag and function allow-list bypass when sandbox state changes between renders for a cached `Template`
Operator check
Check whether twig/twig is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. CVSS score: 8.7.
Read brief →
Jul 1, 2026
Vendor advisory
High-risk advisory
CVE-2026-49457
erlang · quic
QUIC has Broken TLS verification
Operator check
Check whether quic is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.
Read brief →
Jul 1, 2026
Vendor advisory
Critical vendor advisory
CVE-2026-41052
Go · github.com/rancher/rancher
Rancher has Privilege Escalation from Project Owner to Host
Operator check
Check whether github.com/rancher/rancher is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. CVSS score: 9.4. EPSS probability: 0.3%; percentile: 23%.
Read brief →
Jul 1, 2026
Vendor advisory
High-risk advisory
CVE-2026-41053
Go · github.com/rancher/rancher
Rancher has over-inclusive team membership expansion in GitHub App authentication provider
Operator check
Check whether github.com/rancher/rancher is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. EPSS probability: 0.4%; percentile: 29%.
Read brief →
Jul 1, 2026
Vendor advisory
High-risk advisory
CVE-2026-44935
Go · github.com/rancher/fleet
Rancher Fleet vulnerable to cross namespace secret disclosure via unvalidated `valuesFrom` references in Helm Deployer
Operator check
Check whether github.com/rancher/fleet is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.
Read brief →
Jul 1, 2026
Vendor advisory
High-risk advisory
CVE-2026-44937
Go · github.com/rancher/fleet
Rancher Fleet has Unauthenticated Webhook: Regex Injection via Unsanitized Repository URL Components
Operator check
Check whether github.com/rancher/fleet is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.
Read brief →
Jul 1, 2026
Vendor advisory
High-risk advisory
CVE-2026-44938
Go · github.com/rancher/fleet
Fleet has PSS Bypass through addLabelsFromOptions in Fleet Agent
Operator check
Check whether github.com/rancher/fleet is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.
Read brief →
Jul 1, 2026
Vendor advisory
Critical vendor advisory
CVE-2026-44939
Go · github.com/rancher/rancher
Rancher vulnerable to command injection through unsanitized YAML parameter
Operator check
Check whether github.com/rancher/rancher is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. CVSS score: 9.4. EPSS probability: 1.1%; percentile: 62%.
Read brief →
Jul 1, 2026
Vendor advisory
High-risk advisory
CVE-2026-49998
Go · github.com/centrifugal/centrifugo/v6
Centrifugo's dynamic JWKS key cache keyed only by `kid` allows cross-issuer JWT authentication bypass
Operator check
Check whether github.com/centrifugal/centrifugo/v6 is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.
Read brief →
Jul 1, 2026
Vendor advisory
High-risk advisory
CVE-2026-50138
Go · goshs.de/goshs/v2
goshs: WebDAV listener ignores --read-only, --upload-only, and --no-delete mode flags
Operator check
Check whether goshs.de/goshs/v2 is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.
Read brief →
Jul 1, 2026
Vendor advisory
High-risk advisory
CVE-2026-50151
Go · oras.land/oras-go/v2
oras-go blob upload vulnerable to credential forwarding via unvalidated Location header
Operator check
Check whether oras.land/oras-go/v2 is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.
Read brief →
Jul 1, 2026
Vendor advisory
High-risk advisory
CVE-2026-50163
Go · oras.land/oras-go/v2
`oras-go` tar extraction: Hardlink entry with relative Linkname escapes extract dir via process CWD resolution
Operator check
Check whether oras.land/oras-go/v2 is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.
Read brief →
Jul 1, 2026
Vendor advisory
Critical vendor advisory
CVE-2026-50195
Linuxfoundation · Containerd
containerd is an open-source container runtime. Versions prior to 2.3.2, 2.2.5 and 2.1.9 contain a vulnerability in the CRI checkpoint import process where it fails to validate the image references specified within a checkpoint image's configuration. An attacker with permissions to create pods can use a crafted checkpoint image to force containerd to pull a malicious image and assign it an arbitrary local tag, thereby poisoning the node's local image cache. Subsequently, if other pods on the same node attempt to use the poisoned tag with an IfNotPresent (or Never) pull policy, they will unknow
Operator check
Review CVE-2026-50195 in your asset inventory. Apply patches per vendor guidance and verify Containerd is not exposed. CVSS score: 9.9. EPSS probability: 0.4%; percentile: 27%.
Read brief →
Jul 1, 2026
Vendor advisory
Critical vendor advisory
CVE-2026-53492
Linuxfoundation · Containerd
containerd is an open-source container runtime. In Versions prior to 2.3.2, 2.2.5 and 2.1.9, the CRI implementation improperly trusts Container Device Interface (CDI) annotations found within untrusted checkpoint image metadata during container restoration. When restoring a container from a checkpoint, containerd preserves CDI-related annotations from the checkpoint archive rather than relying solely on the pod's create-time specification. This allows a user with pod creation permissions to bypass standard Kubernetes resource allocation and device plugin enforcement, injecting arbitrary CDI ed
Operator check
Review CVE-2026-53492 in your asset inventory. Apply patches per vendor guidance and verify Containerd is not exposed. CVSS score: 9.6. EPSS probability: 0.4%; percentile: 33%.
Read brief →
Jul 1, 2026
Vendor advisory
High-risk advisory
CVE-2026-53712
Maven · com.ongres.scram:scram-client
OnGres SCRAM silent channel-binding authentication downgrade via unsupported certificate algorithms
Operator check
Check whether com.ongres.scram:scram-client is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. CVSS score: 8.2.
Read brief →
Jul 1, 2026
Vendor advisory
High-risk advisory
CVE-2026-9795
Maven · org.keycloak:keycloak-services
Keycloak has privilege escalation via improper scope mapping enforcement
Operator check
Check whether org.keycloak:keycloak-services is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. EPSS probability: 0.3%; percentile: 21%.
Read brief →
Jul 1, 2026
KEV
Known exploited
CVE-2026-45659
Microsoft · SharePoint Server
Microsoft SharePoint Server contains a deserialization of untrusted data vulnerability which allows an authorized attacker to execute code over a network.
Operator check
Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
Read brief →
Jul 1, 2026
Vendor advisory
High-risk advisory
CVE-2026-48815
npm · sigstore
sigstore's `certificateOIDs` verification constraints are silently dropped and never enforced
Operator check
Check whether sigstore is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.
Read brief →
Jul 1, 2026
Vendor advisory
High-risk advisory
CVE-2026-49857
npm · auth-fetch-mcp
auth-fetch-mcp has SSRF Protection Bypass via IPv4-mapped IPv6 Loopback
Operator check
Check whether auth-fetch-mcp is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.
Read brief →
Jul 1, 2026
Vendor advisory
High-risk advisory
CVE-2026-49864
npm · wetty
wetty vulnerable to DOM XSS via file-download filename
Operator check
Check whether wetty is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. CVSS score: 8.6.
Read brief →
Jul 1, 2026
Vendor advisory
High-risk advisory
CVE-2026-49987
npm · repomix
repomix Vulnerable to Command Injection (RCE) via `--remote-branch` Argument Injection
Operator check
Check whether repomix is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.
Read brief →
Jul 1, 2026
Vendor advisory
High-risk advisory
CVE-2026-50143
npm · @apify/actors-mcp-server
Apify Model Context Protocol (MCP) server: Actor MCP path authority injection leaks Apify token
Operator check
Check whether @apify/actors-mcp-server is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.
Read brief →
Jul 1, 2026
Vendor advisory
High-risk advisory
CVE-2026-53943
npm · ghost
Ghost: Cache-poisoning XSS in Ghost frontend via x-ghost-preview header
Operator check
Check whether ghost is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. EPSS probability: 0.2%; percentile: 16%.
Read brief →
Jul 1, 2026
Vendor advisory
High-risk advisory
CVE-2026-49986
PyPI · neuro-cortex-memory
Cortex has Untrusted Project Bootstrap Code Execution via `CLAUDE_PROJECT_DIR`
Operator check
Check whether neuro-cortex-memory is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. CVSS score: 7.1.
Read brief →
Jul 1, 2026
Vendor advisory
High-risk advisory
RubyGems · pay
pay-rails/pay: non-constant-time HMAC comparison in Paddle Billing webhook signature verifier
Operator check
Check whether pay is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.
Read brief →
Jul 1, 2026
Vendor advisory
High-risk advisory
Rust · surrealdb
SurrealDB: HTTP RPC Session Race Condition Allows Privilege Escalation
Operator check
Check whether surrealdb is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.
Read brief →
Jul 1, 2026
Vendor advisory
High-risk advisory
Rust · surrealdb
SurrealDB: HTTP /rpc `sessions` method leaks attached session UUIDs, enabling full session hijack by anonymous callers
Operator check
Check whether surrealdb is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.
Read brief →
Jul 1, 2026
Vendor advisory
High-risk advisory
Rust · surrealdb
SurrealDB has Denial of Service in JSON parser due to nested objects
Operator check
Check whether surrealdb is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.
Read brief →
Jul 1, 2026
Vendor advisory
High-risk advisory
Rust · surrealdb
SurrealDB has unauthenticated remote DoS via malformed RPC `use` call
Operator check
Check whether surrealdb is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.
Read brief →
Jul 1, 2026
Vendor advisory
Critical vendor advisory
CVE-2026-58457
Shenzhen · Aitemi M300 Wi-Fi Repeater (hardware model MT02)
Shenzhen Aitemi M300 Wi-Fi Repeater (hardware model MT02) contains an unauthenticated OS command injection vulnerability that allows network-adjacent attackers to execute arbitrary shell commands by injecting unsanitized input through the smacfilter_conf handler in the commuos web backend. Attackers can append semicolon-delimited payloads to the name, enable, or mac GET parameters, which are passed without sanitization into sprintf() to build uci shell commands executed via doSystemCmdComlib(), granting full root-level control of the device.
Operator check
Review CVE-2026-58457 in your asset inventory. Apply patches per vendor guidance and verify Aitemi M300 Wi-Fi Repeater (hardware model MT02) is not exposed. CVSS score: 9.8.
Read brief →
Jun 30, 2026
Vendor advisory
Critical vendor advisory
CVE-2026-48286
Adobe · Campaign Classic (ACC)
Adobe Campaign Classic (ACC) versions 7.4.3 build 9396 and earlier are affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue does not require user interaction. Scope is changed.
Operator check
Review CVE-2026-48286 in your asset inventory. Apply patches per vendor guidance and verify Campaign Classic (ACC) is not exposed. CVSS score: 10.0.
Read brief →
Jun 30, 2026
Vendor advisory
Critical vendor advisory
CVE-2026-8452
Citrix · Netscaler Application Delivery Controller
Memory overflow vulnerability NetScaler ADC and NetScaler Gateway leading to unpredictable or erroneous behavior and Denial of Service if the appliance is configured as a Gateway (SSL VPN, ICA Proxy, CVPN, RDP Proxy) or AAA virtual server
Operator check
Review CVE-2026-8452 in your asset inventory. Apply patches per vendor guidance and verify Netscaler Application Delivery Controller is not exposed. CVSS score: 9.8. EPSS probability: 0.4%; percentile: 32%.
Read brief →
Jun 30, 2026
Vendor advisory
Critical vendor advisory
CVE-2026-8655
Citrix · Netscaler Application Delivery Controller
Multiple Memory overflow vulnerabilities in NetScaler ADC and NetScaler Gateway leading to unpredictable or erroneous behavior and Denial of Service if NetScaler ADC is configured as an LB of type Oracle OR NetScaler ADC is configured as a DNS Proxy OR NetScaler ADC is configured as a DNS recursive resolver deployment
Operator check
Review CVE-2026-8655 in your asset inventory. Apply patches per vendor guidance and verify Netscaler Application Delivery Controller is not exposed. CVSS score: 9.8. EPSS probability: 0.4%; percentile: 30%.
Read brief →
Jun 30, 2026
Vendor advisory
High-risk advisory
CVE-2026-47198
Composer · paymenter/paymenter
Paymenter has URL parameter injection that bypasses paid plan limits at checkout
Operator check
Check whether paymenter/paymenter is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.
Read brief →
Jun 30, 2026
Vendor advisory
Critical vendor advisory
CVE-2026-58016
Gnome · Glib
A flaw was found in GLib. A state confusion issue exists in g_dbus_node_info_new_for_xml() in the gio/gdbusintrospection.c file when processing malformed D-Bus introspection XML, specifically with a <node> element nested within other elements like <method>, <signal>, <property> or <arg>. This issue can cause an unsigned integer overflow and lead to an out-of-bounds read, resulting in a denial of service.
Operator check
Review CVE-2026-58016 in your asset inventory. Apply patches per vendor guidance and verify Glib is not exposed. CVSS score: 7.5. EPSS probability: 0.3%; percentile: 26%.
Read brief →
Jun 30, 2026
Vendor advisory
High-risk advisory
CVE-2026-49478
Go · github.com/sigstore/fulcio
Fulcio has OIDC Discovery Redirect Following Allows SSRF and JWKS Substitution for Meta-Issuer Paths, with Kubernetes Service-Account Token Leakage
Operator check
Check whether github.com/sigstore/fulcio is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.
Read brief →
Jun 30, 2026
Vendor advisory
High-risk advisory
CVE-2026-49821
Go · github.com/fission/fission
Fission: Cross-namespace Environment reference in Package allows build-time command execution and SA token exfiltration
Operator check
Check whether github.com/fission/fission is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. EPSS probability: 0.2%; percentile: 14%.
Read brief →
Jun 30, 2026
Vendor advisory
High-risk advisory
CVE-2026-49822
Go · github.com/fission/fission
Fission: Cross-namespace event leakage via KubernetesWatchTrigger allows persistent tenant surveillance
Operator check
Check whether github.com/fission/fission is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. EPSS probability: 0.2%; percentile: 14%.
Read brief →
Jun 30, 2026
Vendor advisory
High-risk advisory
CVE-2026-49823
Go · github.com/fission/fission
Fission: Cross-namespace Package read via unvalidated PackageRef in Function admission webhook
Operator check
Check whether github.com/fission/fission is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. EPSS probability: 0.3%; percentile: 18%.
Read brief →
Jun 30, 2026
Vendor advisory
High-risk advisory
CVE-2026-49824
Go · github.com/fission/fission
Fission: Cross-namespace Environment reference via unvalidated EnvironmentRef in Function admission webhook
Operator check
Check whether github.com/fission/fission is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. EPSS probability: 0.2%; percentile: 13%.
Read brief →
Jun 30, 2026
Vendor advisory
High-risk advisory
CVE-2026-50545
Go · github.com/fission/fission
Fission Environment CRD PodSpec Injection Leading to Node Escape and Cluster Takeover
Operator check
Check whether github.com/fission/fission is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. EPSS probability: 0.3%; percentile: 22%.
Read brief →
Jun 30, 2026
Vendor advisory
High-risk advisory
CVE-2026-50563
Go · github.com/fission/fission
Fission Container Executor Function PodSpec Injection Leading to Node Escape
Operator check
Check whether github.com/fission/fission is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. EPSS probability: 0.3%; percentile: 19%.
Read brief →
Jun 30, 2026
Vendor advisory
High-risk advisory
CVE-2026-50564
Go · github.com/fission/fission
Fission Environment CRD podspec passthrough enables hostPID/hostNetwork/privileged pods, node escape
Operator check
Check whether github.com/fission/fission is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. EPSS probability: 0.3%; percentile: 19%.
Read brief →
Jun 30, 2026
Vendor advisory
High-risk advisory
CVE-2026-50566
Go · github.com/fission/fission
Fission: Environment Runtime.Container and Builder.Container SecurityContext bypass allows privileged pod creation
Operator check
Check whether github.com/fission/fission is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. EPSS probability: 0.3%; percentile: 21%.
Read brief →
Jun 30, 2026
Vendor advisory
High-risk advisory
Go · github.com/kahiteam/kahi
Kahi has privilege-drop and socket/log permission issues
Operator check
Check whether github.com/kahiteam/kahi is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.
Read brief →
Jun 30, 2026
Vendor advisory
High-risk advisory
Go · github.com/fission/fission
Fission: MessageQueueTrigger scaler manager materializes Secret values into Deployment envvars and accepts arbitrary user PodSpec
Operator check
Check whether github.com/fission/fission is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.
Read brief →
Jun 30, 2026
Vendor advisory
Critical vendor advisory
CVE-2026-13775
Google · Chrome
Use after free in GPU in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)
Operator check
Review CVE-2026-13775 in your asset inventory. Apply patches per vendor guidance and verify Chrome is not exposed. CVSS score: 9.8. EPSS probability: 0.2%; percentile: 13%.
Read brief →
Jun 30, 2026
Vendor advisory
Critical vendor advisory
CVE-2026-13776
Google · Chrome
Type Confusion in Dawn in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)
Operator check
Review CVE-2026-13776 in your asset inventory. Apply patches per vendor guidance and verify Chrome is not exposed. CVSS score: 9.8. EPSS probability: 0.2%; percentile: 15%.
Read brief →
Jun 30, 2026
Vendor advisory
Critical vendor advisory
CVE-2026-13780
Google · Chrome
Insufficient validation of untrusted input in ANGLE in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)
Operator check
Review CVE-2026-13780 in your asset inventory. Apply patches per vendor guidance and verify Chrome is not exposed. CVSS score: 9.6. EPSS probability: 0.2%; percentile: 13%.
Read brief →
Jun 30, 2026
Vendor advisory
Critical vendor advisory
CVE-2026-13781
Google · Chrome
Insufficient validation of untrusted input in Skia in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)
Operator check
Review CVE-2026-13781 in your asset inventory. Apply patches per vendor guidance and verify Chrome is not exposed. CVSS score: 9.6. EPSS probability: 0.2%; percentile: 13%.
Read brief →
Jun 30, 2026
Vendor advisory
Critical vendor advisory
CVE-2026-13782
Google · Chrome
Use after free in Browser in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)
Operator check
Review CVE-2026-13782 in your asset inventory. Apply patches per vendor guidance and verify Chrome is not exposed. CVSS score: 10.0. EPSS probability: 0.2%; percentile: 11%.
Read brief →
Jun 30, 2026
Vendor advisory
Critical vendor advisory
CVE-2026-13785
Google · Chrome
Use after free in Bluetooth in Google Chrome on Mac prior to 150.0.7871.47 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)
Operator check
Review CVE-2026-13785 in your asset inventory. Apply patches per vendor guidance and verify Chrome is not exposed. CVSS score: 9.6. EPSS probability: 0.2%; percentile: 13%.
Read brief →
Jun 30, 2026
Vendor advisory
Critical vendor advisory
CVE-2026-14101
Google · Chrome
Insufficient policy enforcement in Sandbox in Google Chrome on Mac prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Low)
Operator check
Review CVE-2026-14101 in your asset inventory. Apply patches per vendor guidance and verify Chrome is not exposed. CVSS score: 9.6. EPSS probability: 0.2%; percentile: 13%.
Read brief →
Jun 30, 2026
Vendor advisory
Critical vendor advisory
CVE-2026-14104
Google · Chrome
Insufficient validation of untrusted input in WebAppInstalls in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Low)
Operator check
Review CVE-2026-14104 in your asset inventory. Apply patches per vendor guidance and verify Chrome is not exposed. CVSS score: 9.8. EPSS probability: 0.3%; percentile: 26%.
Read brief →
Jun 30, 2026
Vendor advisory
Critical vendor advisory
CVE-2026-56700
Grav · CMS
Grav CMS before 2.0.0-beta.2 contains multiple code-execution vulnerabilities. Three unsafe unserialize() calls - in Scheduler\JobQueue, Framework\Cache\Adapter\FileCache, and Session - deserialize untrusted data without restricting allowed classes, enabling PHP object injection and, via a gadget chain, arbitrary code execution where an attacker controls the serialized input. Additionally, InstallCommand's git clone operation passes the branch, url, and path parameters into a shell command without escaping, allowing OS command injection via plugin/theme installation (which requires admin acces
Operator check
Review CVE-2026-56700 in your asset inventory. Apply patches per vendor guidance and verify CMS is not exposed. CVSS score: 9.8.
Read brief →
Jun 30, 2026
Vendor advisory
Critical vendor advisory
CVE-2026-10140
IBM · Langflow OSS 1.0.0
IBM Langflow OSS 1.0.0 through 1.10.0 voice mode contains improper shared-state handling that allows reuse of API clients across tenant boundaries. An authenticated attacker can manipulate cache state to cause requests from other users to be processed using incorrect upstream API credentials, leading to cross-tenant billing and accountability misattribution.
Operator check
Review CVE-2026-10140 in your asset inventory. Apply patches per vendor guidance and verify Langflow OSS 1.0.0 is not exposed. CVSS score: 9.6.
Read brief →
Jun 30, 2026
Vendor advisory
Critical vendor advisory
CVE-2026-11541
Ibm · Websphere Application Server
IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.6 are affected by an HTTP request smuggling vulnerability.
Operator check
Review CVE-2026-11541 in your asset inventory. Apply patches per vendor guidance and verify Websphere Application Server is not exposed. CVSS score: 7.4. EPSS probability: 0.3%; percentile: 26%.
Read brief →
Jun 30, 2026
Vendor advisory
Critical vendor advisory
CVE-2026-11546
Ibm · Websphere Application Server
IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.7 is affected by a server-side request forgery vulnerability with the adminCenter-1.0 feature enabled.
Operator check
Review CVE-2026-11546 in your asset inventory. Apply patches per vendor guidance and verify Websphere Application Server is not exposed. CVSS score: 7.1. EPSS probability: 0.2%; percentile: 12%.
Read brief →
Jun 30, 2026
Vendor advisory
Critical vendor advisory
CVE-2026-11714
Ibm · Websphere Application Server
IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.7 is affected by a server-side request forgery vulnerability with the apiDiscovery-1.0 feature enabled.
Operator check
Review CVE-2026-11714 in your asset inventory. Apply patches per vendor guidance and verify Websphere Application Server is not exposed. CVSS score: 8.5. EPSS probability: 0.2%; percentile: 8%.
Read brief →
Jun 30, 2026
Vendor advisory
Critical vendor advisory
CVE-2026-13449
Ibm · Business Automation Manager
IBM Business Automation Manager Open Editions 9.0.0 through 9.4.2 is vulnerable to an XML external entity injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources.
Operator check
Review CVE-2026-13449 in your asset inventory. Apply patches per vendor guidance and verify Business Automation Manager is not exposed. CVSS score: 7.6. EPSS probability: 0.4%; percentile: 31%.
Read brief →
Jun 30, 2026
Vendor advisory
Critical vendor advisory
CVE-2026-13772
Ibm · Websphere Extreme Scale
IBM WebSphere Extreme Scale 8.6.1.0 through 8.6.1.6 's Object Query Language engine resolves attacker-supplied class names via Class.forName() and invokes their constructors with no allow-list at three distinct sinks (SELECT NEW, enum literals, and reflection-based comparators); an authenticated remote attacker who can influence an application-built OQL query string can execute arbitrary constructors on the WAS JVM, and a SELECT DISTINCT variant using planted grid values fires the same gadget post-readObject in a manner that survives JEP-290 serialization filters across grid node boundaries
Operator check
Review CVE-2026-13772 in your asset inventory. Apply patches per vendor guidance and verify Websphere Extreme Scale is not exposed. CVSS score: 7.5. EPSS probability: 0.3%; percentile: 18%.
Read brief →
Jun 30, 2026
Vendor advisory
Critical vendor advisory
CVE-2026-13773
Ibm · Websphere Extreme Scale
IBM WebSphere Extreme Scale 8.6.1.0 through 8.6.1.6 Approximately 50 generated CORBA stub classes in WebSphere eXtreme Scale's ogclient.jar call ORB.string_to_object() on an attacker-controlled IOR string during Java deserialization, turning any unfiltered ObjectInputStream sink in WAS into outbound IIOP SSRF to an attacker-chosen host; when chained with the IBM ORB's getUserException class-instantiation flaw (WAS-26), this SSRF escalates to remote code execution on the calling JVM.
Operator check
Review CVE-2026-13773 in your asset inventory. Apply patches per vendor guidance and verify Websphere Extreme Scale is not exposed. CVSS score: 6.0. EPSS probability: 3.0%; percentile: 86%.
Read brief →
Jun 30, 2026
Vendor advisory
Critical vendor advisory
CVE-2026-10560
Langflow · Langflow
IBM Langflow OSS 1.0.0 through 1.9.6 contains a missing authentication vulnerability in /api/v1/build_public_tmp/ endpoints that allows an unauthenticated attacker to read build event data or cancel jobs using a valid job identifier, resulting in information disclosure and denial of service.
Operator check
Review CVE-2026-10560 in your asset inventory. Apply patches per vendor guidance and verify Langflow is not exposed. CVSS score: 8.2. EPSS probability: 0.3%; percentile: 16%.
Read brief →
Jun 30, 2026
Vendor advisory
Critical vendor advisory
CVE-2026-7663
Langflow · Langflow
IBM Langflow OSS 1.0.0 through 1.9.6 could allow unauthenticated attackers to access protected MCP project resources and execute MCP operations due to improper authorization enforcement in the Streamable MCP transport endpoint.
Operator check
Review CVE-2026-7663 in your asset inventory. Apply patches per vendor guidance and verify Langflow is not exposed. CVSS score: 9.1. EPSS probability: 0.2%; percentile: 15%.
Read brief →
Jun 30, 2026
Vendor advisory
Critical vendor advisory
CVE-2026-14241
Mozilla · Firefox
Memory safety bugs present in Firefox 152.0.3. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 152.0.4.
Operator check
Review CVE-2026-14241 in your asset inventory. Apply patches per vendor guidance and verify Firefox is not exposed. CVSS score: 9.8. EPSS probability: 0.1%; percentile: 4%.
Read brief →
Jun 30, 2026
Vendor advisory
High-risk advisory
CVE-2026-48795
npm · @adonisjs/bodyparser
@adonisjs/bodyparser has an incomplete fix for CVE-2026-25754
Operator check
Check whether @adonisjs/bodyparser is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.
Read brief →
Jun 30, 2026
Vendor advisory
High-risk advisory
CVE-2026-49473
npm · @cedar-policy/authorization-for-expressjs
@cedar-policy/authorization-for-expressjs has an authorization bypass via query string manipulation
Operator check
Check whether @cedar-policy/authorization-for-expressjs is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.
Read brief →
Jun 30, 2026
Vendor advisory
High-risk advisory
CVE-2026-49451
NuGet · Microsoft.OpenAPI
Microsoft.OpenAPI: Circular schema references may terminate OpenAPI parsing
Operator check
Check whether Microsoft.OpenAPI is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.
Read brief →
Jun 30, 2026
Vendor advisory
Critical vendor advisory
CVE-2026-58138
Orkes · Conductor 3.21.21
Orkes Conductor 3.21.21 before 3.30.2 contains an unauthenticated remote code execution vulnerability that allows remote attackers to execute arbitrary OS commands by submitting inline workflow definitions containing malicious JavaScript or Python expressions to the workflow API endpoint prior to authentication. Attackers can exploit unsandboxed GraalVM evaluators configured with HostAccess.ALL or allowAllAccess(true) through INLINE, LAMBDA, DO_WHILE, and SWITCH task types to invoke arbitrary system commands via Java reflection or direct subprocess calls.
Operator check
Review CVE-2026-58138 in your asset inventory. Apply patches per vendor guidance and verify Conductor 3.21.21 is not exposed. CVSS score: 9.8.
Read brief →
Jun 30, 2026
Vendor advisory
High-risk advisory
CVE-2025-10996
PyPI · openbabel
Open Babel has heap buffer overflow in SMILES OBSmilesParser::ParseSmiles
Operator check
Check whether openbabel is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. EPSS probability: 0.2%; percentile: 13%.
Read brief →
Jun 29, 2026
Vendor advisory
High-risk advisory
CVE-2026-44840
Go · github.com/dgraph-io/dgraph/v25
Dgraph Vulnerable to DQL Injection via checkUserPassword GraphQL Query
Operator check
Check whether github.com/dgraph-io/dgraph/v25 is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.
Read brief →
Jun 29, 2026
Vendor advisory
Critical vendor advisory
CVE-2026-11720
Google · Mcp Toolbox For Databases
A path traversal vulnerability exists in the HTTP tool URL builder of googleapis/mcp-toolbox. When constructing downstream API requests, the URL builder substitutes user-controlled pathParams into the configured tool path and parses the resulting string as a relative URL. While it checks that the input does not alter the scheme, host, or user info, it relies on ResolveReference for the final URL resolution. Because dot segments (../) are normalized during this resolution step, an attacker can supply path parameters containing directory traversal sequences to escape the operator-configured pat
Operator check
Review CVE-2026-11720 in your asset inventory. Apply patches per vendor guidance and verify Mcp Toolbox For Databases is not exposed. CVSS score: 9.1. EPSS probability: 0.4%; percentile: 29%.
Read brief →
Jun 29, 2026
Vendor advisory
High-risk advisory
CVE-2026-47424
Maven · org.openidentityplatform.openam:openam-scripting
OpenAM Authenticated RCE via Groovy Sandbox Escape
Operator check
Check whether org.openidentityplatform.openam:openam-scripting is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. CVSS score: 7.5.
Read brief →
Jun 29, 2026
Vendor advisory
High-risk advisory
CVE-2026-47426
Maven · org.openidentityplatform.openam:openam-oauth2
OpenAM OAuth Client Impersonation via JWKS Resolver Cache
Operator check
Check whether org.openidentityplatform.openam:openam-oauth2 is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. CVSS score: 7.1.
Read brief →
Jun 29, 2026
KEV
Known exploited
CVE-2026-48558
SimpleHelp · SimpleHelp
SimpleHelp contains an authentication bypass vulnerability in the OIDC authentication flow. When OIDC authentication is configured, identity tokens submitted during login are accepted without verifying their cryptographic signature. In a vulnerable configuration, a remote, unauthenticated attacker can submit a forged token containing arbitrary identity claims to obtain a fully authenticated technician session. In some configurations, this may also allow bypass of multi-factor authentication.
Operator check
Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
Read brief →
Jun 29, 2026
Vendor advisory
Critical vendor advisory
CVE-2026-13751
Snowflake · Snowflake Cli
Improper handling of untrusted remote references in Snowflake CLI versions prior to 3.19 allowed server-side request forgery. The SQL statement reader's !source/!load directives could reference remote URLs that were retrieved at runtime without sufficient restriction on the request destination. By supplying crafted SQL content processed through a vulnerable command path, an attacker could cause the victim's environment to issue unintended outbound requests to internal or otherwise non-public network locations, and could cause remote SQL content to be retrieved and executed in the context of th
Operator check
Review CVE-2026-13751 in your asset inventory. Apply patches per vendor guidance and verify Snowflake Cli is not exposed. CVSS score: 4.1. EPSS probability: 0.1%; percentile: 1%.
Read brief →
Jun 27, 2026
Vendor advisory
High-risk advisory
npm · pnpm
pnpm: `patch-remove` could delete project-selected files outside the patches directory
Operator check
Check whether pnpm is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.
Read brief →
Jun 27, 2026
Vendor advisory
High-risk advisory
npm · pnpm
pnpm: Hoisted install imports lockfile alias outside node_modules
Operator check
Check whether pnpm is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.
Read brief →
Jun 27, 2026
Vendor advisory
High-risk advisory
npm · pnpm
pnpm: Path traversal in configDependencies env lockfile allows symlink creation outside node_modules/.pnpm-config
Operator check
Check whether pnpm is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.
Read brief →
Jun 26, 2026
Vendor advisory
Critical vendor advisory
CVE-2026-54636
Dokku · Dokku
Dokku is a docker-powered PaaS. Prior to 0.38.7, the cron plugin utilizes commands in the app.json file to manage system cron running as the Dokku user. An app.json cron command utilizing special shell characters - including, but not limited to, > or ; - can break out of the Docker container and execute commands on the host as the Dokku user. This vulnerability is fixed in 0.38.7.
Operator check
Review CVE-2026-54636 in your asset inventory. Apply patches per vendor guidance and verify Dokku is not exposed. CVSS score: 9.0.
Read brief →
Jun 26, 2026
Vendor advisory
High-risk advisory
CVE-2026-49454
erlang · relyra
Relyra SAML SignatureValue not cryptographically verified -> authentication bypass
Operator check
Check whether relyra is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. EPSS probability: 0.1%; percentile: 3%.
Read brief →
Jun 26, 2026
Vendor advisory
High-risk advisory
erlang · ex_aws_sns
ex_aws_sns: Trusted-attacker `SigningCertURL` permits complete SNS signature bypass
Operator check
Check whether ex_aws_sns is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. CVSS score: 8.7.
Read brief →
Jun 26, 2026
Vendor advisory
High-risk advisory
CVE-2026-48749
Go · github.com/lxc/incus/v7/cmd/incusd
Incus has an arbitrary file read+write on host via rootfs/ symlink in malicious image
Operator check
Check whether github.com/lxc/incus/v7/cmd/incusd is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.
Read brief →
Jun 26, 2026
Vendor advisory
High-risk advisory
CVE-2026-48750
Go · github.com/lxc/incus/v7/cmd/incusd
Incus has an arbitrary file write on host via `exec-output` symlink in crafted image
Operator check
Check whether github.com/lxc/incus/v7/cmd/incusd is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.
Read brief →
Jun 26, 2026
Vendor advisory
High-risk advisory
CVE-2026-48751
Go · github.com/lxc/incus/v7/cmd/incusd
Incus has a restricted project bypass leading to arbitrary command execution
Operator check
Check whether github.com/lxc/incus/v7/cmd/incusd is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.
Read brief →
Jun 26, 2026
Vendor advisory
High-risk advisory
CVE-2026-48752
Go · github.com/lxc/incus/v7/cmd/incusd
Incus has arbitrary file read+write on host via templates/ symlink in malicious image
Operator check
Check whether github.com/lxc/incus/v7/cmd/incusd is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.
Read brief →
Jun 26, 2026
Vendor advisory
High-risk advisory
CVE-2026-48753
Go · github.com/lxc/incus/v7/cmd/incusd
Incus has an arbitrary file write via path traversal in S3 multipart upload
Operator check
Check whether github.com/lxc/incus/v7/cmd/incusd is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.
Read brief →
Jun 26, 2026
Vendor advisory
High-risk advisory
CVE-2026-48755
Go · github.com/lxc/incus/v7/cmd/incusd
Incus has an argument injection in backup compression algorithm leading to AFW and ACE
Operator check
Check whether github.com/lxc/incus/v7/cmd/incusd is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.
Read brief →
Jun 26, 2026
Vendor advisory
High-risk advisory
CVE-2026-48769
Go · github.com/lxc/incus/v7/cmd/incusd
Incus has an arbitrary file write on its client due to trusted image hash
Operator check
Check whether github.com/lxc/incus/v7/cmd/incusd is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.
Read brief →
Jun 26, 2026
Vendor advisory
High-risk advisory
CVE-2026-49338
Go · go.senan.xyz/gonic
Subsonic API: any authenticated user can delete or read any other user's playlist (IDOR)
Operator check
Check whether go.senan.xyz/gonic is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. EPSS probability: 0.2%; percentile: 6%.
Read brief →
Jun 26, 2026
Vendor advisory
High-risk advisory
CVE-2026-49339
Go · go.senan.xyz/gonic
gonic: Path Traversal in playlist `id` bypasses ownership check, enabling any user to read/delete other users' playlists
Operator check
Check whether go.senan.xyz/gonic is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. EPSS probability: 0.3%; percentile: 17%.
Read brief →
Jun 26, 2026
Vendor advisory
High-risk advisory
CVE-2026-49340
Go · go.senan.xyz/gonic
gonic has arbitrary file write in createPlaylist: any authenticated user can write playlist M3U content to attacker-controlled path on the host
Operator check
Check whether go.senan.xyz/gonic is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. EPSS probability: 0.3%; percentile: 18%.
Read brief →
Jun 26, 2026
Vendor advisory
High-risk advisory
CVE-2026-53519
Go · github.com/nezhahq/nezha
Nezha Monitoring: Pre-auth path traversal via /dashboard.. prefix confusion leaks jwt_secret_key
Operator check
Check whether github.com/nezhahq/nezha is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. EPSS probability: 0.5%; percentile: 36%.
Read brief →
Jun 26, 2026
Vendor advisory
High-risk advisory
Go · github.com/nezhahq/nezha
Nezha vulnerable to cross-tenant terminal/file-manager session hijack via WebSocket stream UUID without ownership check
Operator check
Check whether github.com/nezhahq/nezha is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.
Read brief →
Jun 26, 2026
Vendor advisory
High-risk advisory
Go · github.com/blnkfinance/blnk
Blnk has an API key authorization bypass in owner and scope enforcement
Operator check
Check whether github.com/blnkfinance/blnk is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.
Read brief →
Jun 26, 2026
Vendor advisory
Critical vendor advisory
CVE-2026-53914
Jetbrains · Kotlin
In JetBrains Kotlin before 2.4.20 code execution was possible via unsafe deserialization in the build cache metadata
Operator check
Review CVE-2026-53914 in your asset inventory. Apply patches per vendor guidance and verify Kotlin is not exposed. CVSS score: 6.7. EPSS probability: 0.1%; percentile: 2%.
Read brief →
Jun 26, 2026
Vendor advisory
Critical vendor advisory
CVE-2026-57926
Jetbrains · Youtrack
In JetBrains YouTrack before 2026.2.16593 the websandbox bridge was vulnerable to a prototype pollution attack
Operator check
Review CVE-2026-57926 in your asset inventory. Apply patches per vendor guidance and verify Youtrack is not exposed. CVSS score: 2.6. EPSS probability: 0.4%; percentile: 32%.
Read brief →
Jun 26, 2026
Vendor advisory
Critical vendor advisory
CVE-2026-48930
Nodejs · Node.Js
A flaw in Node.js TLS hostname handling can cause Embedded-nul hostnames can lead to silent authority rebinding due to c-string truncation in resolver bindings. This vulnerability affects all supported release lines: **Node.js 22**, **Node.js 24**, and **Node.js 26**.
Operator check
Review CVE-2026-48930 in your asset inventory. Apply patches per vendor guidance and verify Node.Js is not exposed. CVSS score: 9.8. EPSS probability: 0.3%; percentile: 20%.
Read brief →
Jun 26, 2026
Vendor advisory
High-risk advisory
CVE-2026-49252
npm · @deepstream/server
deepstream is vulnerable to prototype pollution
Operator check
Check whether @deepstream/server is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. EPSS probability: 0.3%; percentile: 19%.
Read brief →
Jun 26, 2026
Vendor advisory
High-risk advisory
CVE-2026-49293
npm · js-toml
js-toml vulnerable to CPU exhaustion via O(n^2) BigInt construction on radix-prefixed integer literals
Operator check
Check whether js-toml is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. EPSS probability: 0.4%; percentile: 33%.
Read brief →
Jun 26, 2026
Vendor advisory
High-risk advisory
CVE-2026-50015
npm · pnpm
pnpm Vulnerable to Arbitrary File Write/Delete via Malicious Patch File (Path Traversal)
Operator check
Check whether pnpm is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. EPSS probability: 0.2%; percentile: 16%.
Read brief →
Jun 26, 2026
Vendor advisory
High-risk advisory
CVE-2026-50016
npm · pnpm
pnpm: Transitive dependency alias path traversal allows project path override via symlink replacement
Operator check
Check whether pnpm is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. EPSS probability: 0.3%; percentile: 23%.
Read brief →
Jun 26, 2026
Vendor advisory
High-risk advisory
CVE-2026-55487
npm · pnpm
pnpm: Manifest identity spoof satisfies allowBuilds and runs attacker lifecycle
Operator check
Check whether pnpm is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. EPSS probability: 0.1%; percentile: 2%.
Read brief →
Jun 26, 2026
Vendor advisory
High-risk advisory
CVE-2026-55697
npm · pnpm
pnpm: Repository-controlled configDependencies can select a pacquet native install engine
Operator check
Check whether pnpm is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. EPSS probability: 0.1%; percentile: 2%.
Read brief →
Jun 26, 2026
Vendor advisory
High-risk advisory
CVE-2026-55698
npm · pnpm
pnpm: Project env lockfile can short-circuit package-manager resolution and execute lockfile-selected pnpm bytes
Operator check
Check whether pnpm is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. EPSS probability: 0.2%; percentile: 7%.
Read brief →
Jun 26, 2026
Vendor advisory
High-risk advisory
CVE-2026-55700
npm · pnpm
pnpm: `stage download` writes outside its destination directory via manifest name/version traversal
Operator check
Check whether pnpm is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. EPSS probability: 0.3%; percentile: 17%.
Read brief →
Jun 26, 2026
Vendor advisory
Critical vendor advisory
CVE-2026-48797
PyPI · backpropagate
Backpropagate: backprop ui --auth and backprop ui --share do not enforce authentication
Operator check
Check whether backpropagate is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. CVSS score: 9.3. EPSS probability: 0.3%; percentile: 24%.
Read brief →
Jun 26, 2026
Vendor advisory
High-risk advisory
CVE-2026-49257
PyPI · mcp-pinot-server
mcp-pinot: Unauthenticated tool invocation via default oauth_enabled=False + host 0.0.0.0 bind
Operator check
Check whether mcp-pinot-server is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. EPSS probability: 0.5%; percentile: 39%.
Read brief →
Jun 26, 2026
Vendor advisory
High-risk advisory
PyPI · semantic-router
semantic-router exposed to compromised litellm wheel (CVE-2026-42208) via unbounded transitive pin
Operator check
Check whether semantic-router is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.
Read brief →
Jun 26, 2026
Vendor advisory
High-risk advisory
CVE-2026-44024
RubyGems · fluentd
Fluentd is Vulnerable to Remote Code Execution (RCE) via Arbitrary File Write in `${tag}` Placeholder
Operator check
Check whether fluentd is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.
Read brief →
Jun 26, 2026
Vendor advisory
Critical vendor advisory
CVE-2026-2053
Wso2 · Api Manager
The WSO2 API Manager's message flow component, when processing WS-Addressing headers, does not sufficiently validate or restrict user-controlled input within these headers. This omission allows an attacker to manipulate WS-Addressing headers to specify arbitrary destinations for server-initiated requests. Successful exploitation allows an unauthenticated attacker to control the destination of server-initiated requests originating from the WSO2 API Manager. This direct control can enable unauthorized access to internal network resources or services that would typically be inaccessible from ext
Operator check
Review CVE-2026-2053 in your asset inventory. Apply patches per vendor guidance and verify Api Manager is not exposed. CVSS score: 8.3. EPSS probability: 0.2%; percentile: 10%.
Read brief →
Jun 25, 2026
Vendor advisory
Critical vendor advisory
CVE-2026-50548
Anysphere · Cursor
Cursor is a code editor built for programming with AI. Prior to 3.0, Cursor runs agent terminal commands in a sandbox by default, and the sandbox grants write access to the command's working directory. A flaw was identified in how the agent could modify the working_directory parameter, which could cause the sandbox to include writable paths outside the intended workspace. A malicious agent could set working_directory to a sensitive location and write arbitrary files outside the workspace under the user's privileges. This enables non-sandboxed Remote Code Execution — for example by overwriting
Operator check
Review CVE-2026-50548 in your asset inventory. Apply patches per vendor guidance and verify Cursor is not exposed. CVSS score: 9.8. EPSS probability: 0.5%; percentile: 40%.
Read brief →
Jun 25, 2026
Vendor advisory
Critical vendor advisory
CVE-2026-50549
Anysphere · Cursor
Cursor is a code editor built for programming with AI. Prior to 3.0, Cursor runs agent terminal commands in a sandbox by default. Before a Write, the agent canonicalizes the target path to confirm it stays inside the workspace, but when canonicalization fails it falls back to the original path and writes without approval. A malicious agent can create an in-workspace symlink that points outside the workspace and force canonicalization to fail — either because the target does not exist or because read permission is removed from the path — so the agent writes through the symlink to an arbitrary l
Operator check
Review CVE-2026-50549 in your asset inventory. Apply patches per vendor guidance and verify Cursor is not exposed. CVSS score: 9.8. EPSS probability: 0.5%; percentile: 40%.
Read brief →
Jun 25, 2026
Vendor advisory
Critical vendor advisory
CVE-2026-40079
Cacti · Cacti
Cacti is an open source performance and fault management framework. Versions 1.2.30 and prior are vulnerable to Command Injection due to lack of sanitization in the escape_command() function. The escape_command() function at lib/rrd.php is a no-op: it returns $command unchanged. The command line built by rrdtool_function_graph() is passed through this function and then to shell_exec($full_commandline). The risk is in __rrd_execute() where text_format values from graph templates (which may contain host variable substitutions) reach shell_exec without adequate escaping. This issue has been addre
Operator check
Review CVE-2026-40079 in your asset inventory. Apply patches per vendor guidance and verify Cacti is not exposed. CVSS score: 9.8. EPSS probability: 0.9%; percentile: 56%.
Read brief →
Jun 25, 2026
KEV
Known exploited
CVE-2026-20230
Cisco · Unified Communications Manager
Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communications Manager Session Management Edition (Unified CM SME) contain a server-side request forgery (SSRF) Vulnerability that could allow an unauthenticated, remote attacker to write files to the underlying operating system that could be used later to elevate to root.
Operator check
Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
Read brief →
Jun 25, 2026
Vendor advisory
High-risk advisory
CVE-2026-48505
Composer · filament/filament
Filament: Multi-factor authentication (app) recovery codes can still be used multiple times via concurrent submission
Operator check
Check whether filament/filament is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. EPSS probability: 0.2%; percentile: 9%.
Read brief →
Jun 25, 2026
Vendor advisory
Critical vendor advisory
CVE-2026-56123
Dest Unreach · Socat
socat versions 1.8.0.0 through 1.8.1.1 contain a heap-based buffer overflow vulnerability that allows a malicious SOCKS5 proxy server to overwrite adjacent heap memory by exploiting a sign-extension flaw in the DOMAINNAME reply parser. During connection setup, the domain name length byte is read through a signed char field causing a negative bytes_to_read value that is implicitly converted to size_t, resulting in an unbounded heap write into the 262-byte reply buffer with attacker-controlled size and content.
Operator check
Review CVE-2026-56123 in your asset inventory. Apply patches per vendor guidance and verify Socat is not exposed. CVSS score: 8.1. EPSS probability: 0.3%; percentile: 21%.
Read brief →
Jun 25, 2026
Vendor advisory
High-risk advisory
CVE-2026-39829
Go · golang.org/x/crypto/ssh
golang.org/x/crypto/ssh: Invoking pathological RSA/DSA parameters may cause DoS
Operator check
Check whether golang.org/x/crypto/ssh is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. EPSS probability: 0.3%; percentile: 22%.
Read brief →
Jun 25, 2026
Vendor advisory
High-risk advisory
CVE-2026-39830
Go · golang.org/x/crypto/ssh
golang.org/x/crypto/ssh: Invoking client can cause server deadlock on unexpected responses
Operator check
Check whether golang.org/x/crypto/ssh is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. EPSS probability: 0.4%; percentile: 31%.
Read brief →
Jun 25, 2026
Vendor advisory
High-risk advisory
CVE-2026-39831
Go · golang.org/x/crypto/ssh
golang.org/x/crypto/ssh: FIDO/U2F security key physical presence check can be bypassed
Operator check
Check whether golang.org/x/crypto/ssh is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. EPSS probability: 0.4%; percentile: 29%.
Read brief →
Jun 25, 2026
Vendor advisory
High-risk advisory
CVE-2026-39832
Go · golang.org/x/crypto/ssh/agent
golang.org/x/crypto/ssh/agent doesn't drop invoking agent constraints when forwarding keys
Operator check
Check whether golang.org/x/crypto/ssh/agent is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. EPSS probability: 0.4%; percentile: 32%.
Read brief →
Jun 25, 2026
Vendor advisory
High-risk advisory
CVE-2026-39833
Go · golang.org/x/crypto/ssh/agent
golang.org/x/crypto/ssh/agent doesn't enforce invoking key constraints
Operator check
Check whether golang.org/x/crypto/ssh/agent is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. EPSS probability: 0.4%; percentile: 28%.
Read brief →
Jun 25, 2026
Vendor advisory
High-risk advisory
CVE-2026-39834
Go · golang.org/x/crypto/ssh
golang.org/x/crypto/ssh vulnerable to infinite loop on large channel writes
Operator check
Check whether golang.org/x/crypto/ssh is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. EPSS probability: 0.5%; percentile: 37%.
Read brief →
Jun 25, 2026
Vendor advisory
High-risk advisory
CVE-2026-42508
Go · golang.org/x/crypto/ssh/knownhosts
golang.org/x/crypto/ssh/knownhosts vulnerable to auth bypass via unenforced @revoked status
Operator check
Check whether golang.org/x/crypto/ssh/knownhosts is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. EPSS probability: 0.4%; percentile: 29%.
Read brief →
Jun 25, 2026
Vendor advisory
High-risk advisory
CVE-2026-46595
Go · golang.org/x/crypto/ssh
golang.org/x/crypto/ssh: Invoking VerifiedPublicKeyCallback permissions skip enforcement
Operator check
Check whether golang.org/x/crypto/ssh is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. EPSS probability: 0.4%; percentile: 30%.
Read brief →
Jun 25, 2026
Vendor advisory
High-risk advisory
CVE-2026-46597
Go · golang.org/x/crypto/ssh
golang.org/x/crypto/ssh: Invoking byte arithmetic causes underflow and panic
Operator check
Check whether golang.org/x/crypto/ssh is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. EPSS probability: 0.4%; percentile: 28%.
Read brief →
Jun 25, 2026
Vendor advisory
High-risk advisory
CVE-2026-48702
Go · github.com/sigstore/rekor
Rekor has an OOM Condition due to Unbounded gzip Decompression in Alpine APK Parsing Logic
Operator check
Check whether github.com/sigstore/rekor is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.
Read brief →
Jun 25, 2026
Vendor advisory
High-risk advisory
Go · github.com/go-chi/chi/middleware
chi's RealIP Middleware allows IP spoofing via unvalidated X-Forwarded-For header
Operator check
Check whether github.com/go-chi/chi/middleware is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. CVSS score: 7.7.
Read brief →
Jun 25, 2026
Vendor advisory
High-risk advisory
CVE-2026-48713
npm · i18next-fs-backend
i18next-fs-backend vulnerable to prototype pollution via crafted missing-key string
Operator check
Check whether i18next-fs-backend is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. EPSS probability: 0.4%; percentile: 33%.
Read brief →
Jun 25, 2026
Vendor advisory
High-risk advisory
CVE-2026-48714
npm · i18next-http-middleware
i18next-http-middleware: MissingKeyHandler does not reject keys whose segments contain prototype-polluting names
Operator check
Check whether i18next-http-middleware is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. EPSS probability: 0.4%; percentile: 33%.
Read brief →
Jun 25, 2026
Vendor advisory
High-risk advisory
CVE-2026-48502
NuGet · MessagePack
MessagePack-CSharp: Denial of service vulnerabilities can swamp the CPU or crash the process with stack and heap overflows
Operator check
Check whether MessagePack is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. CVSS score: 8.2. EPSS probability: 0.3%; percentile: 17%.
Read brief →
Jun 25, 2026
Vendor advisory
High-risk advisory
CVE-2026-48506
NuGet · MessagePack
MessagePack-CSharp: MessagePackReader.Skip can recurse without enforcing maximum object graph depth
Operator check
Check whether MessagePack is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. EPSS probability: 0.3%; percentile: 19%.
Read brief →
Jun 25, 2026
Vendor advisory
High-risk advisory
CVE-2026-49218
NuGet · Magick.NET-Q16-AnyCPU
ImageMagick: Policy Bypass in DCM decoder could result in image with invalid dimensions
Operator check
Check whether Magick.NET-Q16-AnyCPU is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. EPSS probability: 0.3%; percentile: 18%.
Read brief →
Jun 25, 2026
Vendor advisory
High-risk advisory
CVE-2026-53460
NuGet · Magick.NET-Q16-AnyCPU
ImageMagick: Policy Bypass can Trigger an Out-of-Memory condition
Operator check
Check whether Magick.NET-Q16-AnyCPU is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. EPSS probability: 0.3%; percentile: 18%.
Read brief →
Jun 25, 2026
Vendor advisory
High-risk advisory
CVE-2026-53461
NuGet · Magick.NET-Q16-AnyCPU
ImageMagick has out-of-bounds write in ICON decoder due to incorrect loop
Operator check
Check whether Magick.NET-Q16-AnyCPU is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. EPSS probability: 0.3%; percentile: 18%.
Read brief →
Jun 25, 2026
KEV
Known exploited
CVE-2026-12569
PTC · Windchill and FlexPLM
PTC Windchill and FlexPLM contains an improper input validation vulnerability allowing an unauthenticated, remote attacker to execute arbitrary code by sending a malicious request to the network.
Operator check
Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
Read brief →
Jun 25, 2026
Vendor advisory
High-risk advisory
CVE-2026-48508
PyPI · lemur
Lemur has an authorization bypass in StrictRolePermission / AuthorityCreatorPermission
Operator check
Check whether lemur is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.
Read brief →
Jun 25, 2026
Vendor advisory
High-risk advisory
CVE-2026-55166
PyPI · lemur
Lemur: ACME SSRF + creator-equality IDOR lead to AWS IAM/PKI compromise
Operator check
Check whether lemur is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.
Read brief →
Jun 25, 2026
Vendor advisory
High-risk advisory
CVE-2026-9291
PyPI · amazon-braket-sdk
amazon-braket-sdk vulnerable to Insecure Deserialization via pickle.loads()
Operator check
Check whether amazon-braket-sdk is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. CVSS score: 7.5. EPSS probability: 0.4%; percentile: 30%.
Read brief →
Jun 25, 2026
Vendor advisory
Critical vendor advisory
CVE-2026-56786
Rtklib · Rtklib
RTKLIB through 2.4.3 contains an out-of-bounds write vulnerability in decode_type1033 function that fails to clamp length counters to destination buffer size, allowing up to 191-byte overflow into fixed 64-byte descriptor fields. An attacker controlling an NTRIP or serial RTCM3 correction stream can craft a valid CRC-bearing type-1033 message to corrupt adjacent rtcm_t object members, potentially achieving arbitrary code execution or denial of service.
Operator check
Review CVE-2026-56786 in your asset inventory. Apply patches per vendor guidance and verify Rtklib is not exposed. CVSS score: 9.8. EPSS probability: 0.4%; percentile: 32%.
Read brief →
Jun 25, 2026
Vendor advisory
Critical vendor advisory
CVE-2026-6094
Wolfssl · Wolfssl
Heap buffer overread in wc_PKCS7_DecodeEnvelopedData when parsing crafted PKCS7 EnvelopedData. This could theoretically be triggered by attacker-supplied data delivered via S/MIME or CMS.
Operator check
Review CVE-2026-6094 in your asset inventory. Apply patches per vendor guidance and verify Wolfssl is not exposed. CVSS score: 9.1. EPSS probability: 0.3%; percentile: 18%.
Read brief →
Jun 25, 2026
Vendor advisory
Critical vendor advisory
CVE-2026-7531
Wolfssl · Wolfssl
Use-after-free in PQC hybrid key-share handling. This is an incomplete-fix follow-up to CVE-2026-5460 (released in 5.9.1): a malicious TLS 1.3 server sending a truncated PQC hybrid KeyShare can still trigger the error cleanup path to operate on freed memory.
Operator check
Review CVE-2026-7531 in your asset inventory. Apply patches per vendor guidance and verify Wolfssl is not exposed. CVSS score: 9.8. EPSS probability: 0.3%; percentile: 20%.
Read brief →
Jun 24, 2026
Vendor advisory
Critical vendor advisory
CVE-2026-55455
Appsmith · Appsmith
Appsmith is a platform to build admin panels, internal tools, and dashboards. Prior to 2.1, the outbound HTTP host filter applied by WebClientUtils (used by the REST API and GraphQL datasource plugins) validates hosts against an exact-match string denylist. The comprehensive address-class check (loopback, any-local, link-local, fc00::/7) exists only on a separate code path used by SMTP, not by the HTTP plugin path. As a result, an authenticated user can craft outbound requests that reach loopback-bound services inside the container. This vulnerability is fixed in 2.1.
Operator check
Review CVE-2026-55455 in your asset inventory. Apply patches per vendor guidance and verify Appsmith is not exposed. CVSS score: 9.1. EPSS probability: 0.2%; percentile: 13%.
Read brief →
Jun 24, 2026
Vendor advisory
Critical vendor advisory
CVE-2026-39948
Cacti · Cacti
Cacti is an open source performance and fault management framework. In versions 1.2.30 and prior, the rfilter request parameter is retrieved via the raw accessor grv() (rather than gfrv() with FILTER_VALIDATE_IS_REGEX validation) and concatenated directly into RLIKE SQL clauses in lib/html_graph.php and lib/html_tree.php, which are reachable pre-authentication through graph_view.php on installations with guest graph viewing enabled. Because the unbalanced-quote payload bypasses the regex validation that would otherwise reject it, an unauthenticated attacker can inject arbitrary SQL to compromi
Operator check
Review CVE-2026-39948 in your asset inventory. Apply patches per vendor guidance and verify Cacti is not exposed. CVSS score: 9.8. EPSS probability: 0.4%; percentile: 34%.
Read brief →
Jun 24, 2026
Vendor advisory
High-risk advisory
CVE-2026-48708
Go · github.com/OliveTin/OliveTin
OliveTin has a Concurrent Template Parsing Race Condition which Leads to Cross-Request Command Contamination
Operator check
Check whether github.com/OliveTin/OliveTin is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. EPSS probability: 0.3%; percentile: 27%.
Read brief →
Jun 24, 2026
Vendor advisory
Critical vendor advisory
CVE-2026-45051
Maven · org.openidentityplatform.openam:openam-auth-webauthn
OpenAM: Pre-auth RCE via Java Deserialization in WebAuthn Authenticator Storage
Operator check
Check whether org.openidentityplatform.openam:openam-auth-webauthn is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. CVSS score: 9.2.
Read brief →
Jun 24, 2026
Vendor advisory
Critical vendor advisory
CVE-2026-45052
Maven · org.openidentityplatform.openam:openam-federation-library
OpenAM Pre-auth User Profile Tampering via Anonymous SOAP Authn in Liberty IDPP/Discovery Endpoints
Operator check
Check whether org.openidentityplatform.openam:openam-federation-library is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. CVSS score: 9.3.
Read brief →
Jun 24, 2026
Vendor advisory
Critical vendor advisory
CVE-2026-56351
N8N · N8N
n8n before version 2.4.0 contains a sql injection vulnerability in MySQL, PostgreSQL, and Microsoft SQL nodes that allows authenticated users to inject arbitrary SQL through unescaped identifier values in node configuration parameters. Attackers with workflow creation permissions can supply specially crafted table or column names to execute unauthorized database commands and compromise data integrity.
Operator check
Review CVE-2026-56351 in your asset inventory. Apply patches per vendor guidance and verify N8N is not exposed. CVSS score: 8.2. EPSS probability: 0.2%; percentile: 12%.
Read brief →
Jun 24, 2026
Vendor advisory
Critical vendor advisory
CVE-2026-54906
Rubyconcurrency · Concurrent Ruby
concurrent-ruby is a modern concurrency tools for Ruby. Prior to 1.3.7, Concurrent::ReadWriteLock#release_write_lock does not verify that the calling thread acquired the write lock. Any thread with access to the lock object can release an active write lock held by another thread. A second writer can then enter its critical section while the first writer is still running. Concurrent::ReadWriteLock#release_read_lock also decrements the shared counter even when no read lock is held. Calling it on a fresh lock changes the counter from 0 to -1, after which normal read acquisition raises Concurrent:
Operator check
Review CVE-2026-54906 in your asset inventory. Apply patches per vendor guidance and verify Concurrent Ruby is not exposed. CVSS score: 9.8. EPSS probability: 0.1%; percentile: 0%.
Read brief →
Jun 23, 2026
Vendor advisory
High-risk advisory
CVE-2026-48507
Composer · snipe/snipe-it
Snipe-IT: Bulk editing users allowed `ldap_import` and `activated_in` bulk editing users
Operator check
Check whether snipe/snipe-it is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. EPSS probability: 0.2%; percentile: 9%.
Read brief →
Jun 23, 2026
Vendor advisory
High-risk advisory
CVE-2026-54329
Composer · snipe/snipe-it
Snipe-IT API Vulnerable to Cross-Tenant Accessory Injection
Operator check
Check whether snipe/snipe-it is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.
Read brief →
Jun 23, 2026
Vendor advisory
High-risk advisory
CVE-2026-55173
Composer · wwbn/avideo
AVideo has an incomplete fix of CVE-2026-33482: sanitizeFFmpegCommand still allows a single '&' (background operator), giving OS command execution at the same execAsync sh -c sink
Operator check
Check whether wwbn/avideo is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.
Read brief →
Jun 23, 2026
Vendor advisory
High-risk advisory
CVE-2026-48126
Go · github.com/xyproto/algernon
Algernon: Host header path traversal in --domain mode reads files and runs Lua from parent dir
Operator check
Check whether github.com/xyproto/algernon is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. EPSS probability: 0.3%; percentile: 25%.
Read brief →
Jun 23, 2026
Vendor advisory
High-risk advisory
CVE-2026-52806
Go · gogs.io/gogs
Gogs vulnerable to RCE via git rebase --exec argument injection in pull request merge
Operator check
Check whether gogs.io/gogs is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.
Read brief →
Jun 23, 2026
Vendor advisory
High-risk advisory
CVE-2026-52807
Go · gogs.io/gogs
Gogs has DOM-based XSS via Milestone Name on New Issue Page
Operator check
Check whether gogs.io/gogs is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.
Read brief →
Jun 23, 2026
Vendor advisory
High-risk advisory
CVE-2026-52808
Go · gogs.io/gogs
Gogs's write-level collaborators can mutate admin-only repository settings via API
Operator check
Check whether gogs.io/gogs is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.
Read brief →
Jun 23, 2026
Vendor advisory
High-risk advisory
CVE-2026-52810
Go · gogs.io/gogs
Gogs allows users to write to readonly repositories using receive-pack + service=git-upload-pack confusion
Operator check
Check whether gogs.io/gogs is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. CVSS score: 7.1.
Read brief →
Jun 23, 2026
Vendor advisory
Critical vendor advisory
CVE-2026-52811
Go · gogs.io/gogs
Gogs: UploadRepoFiles writes outside repo working tree via committed parent sym
Operator check
Check whether gogs.io/gogs is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. CVSS score: 9.0.
Read brief →
Jun 23, 2026
Vendor advisory
High-risk advisory
CVE-2026-52812
Go · gogs.io/gogs
Gogs: LFS dedupe path leaks private repo content across tenants
Operator check
Check whether gogs.io/gogs is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. CVSS score: 7.1.
Read brief →
Jun 23, 2026
Vendor advisory
High-risk advisory
CVE-2026-52813
Go · gogs.io/gogs
Gogs has Path Traversal in organization name that results in RCE through Git hooks
Operator check
Check whether gogs.io/gogs is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.
Read brief →
Jun 23, 2026
KEV
Known exploited
CVE-2025-67038
Lantronix · EDS5000
Lantronix EDS5000 contains a code injection vulnerability that could allow attackers to inject arbitrary OS commands into the username parameter. Injected commands are executed with root privileges.
Operator check
Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
Read brief →
Jun 23, 2026
Vendor advisory
High-risk advisory
CVE-2026-45048
Maven · org.openidentityplatform.openam:openam-core
OpenAM Authenticated Privilege Escalation via Raw Token Disclosure Session RPC
Operator check
Check whether org.openidentityplatform.openam:openam-core is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.
Read brief →
Jun 23, 2026
Vendor advisory
High-risk advisory
CVE-2026-45049
Maven · org.openidentityplatform.openam:openam-federation
OpenAM Unauthenticated Session Hijacking via Information Exposure in CDCServlet
Operator check
Check whether org.openidentityplatform.openam:openam-federation is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.
Read brief →
Jun 23, 2026
Vendor advisory
High-risk advisory
CVE-2026-54512
Maven · com.fasterxml.jackson.core:jackson-databind
jackson-databind has a PolymorphicTypeValidator bypass via generic type parameters that allows arbitrary class instantiation
Operator check
Check whether com.fasterxml.jackson.core:jackson-databind is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.
Read brief →
Jun 23, 2026
Vendor advisory
High-risk advisory
CVE-2026-54513
Maven · com.fasterxml.jackson.core:jackson-databind
jackson-databind has an array subtype allowlist bypass in BasicPolymorphicTypeValidator (allowIfSubTypeIsArray)
Operator check
Check whether com.fasterxml.jackson.core:jackson-databind is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.
Read brief →
Jun 23, 2026
Vendor advisory
Critical vendor advisory
CVE-2026-44789
N8N · N8N
n8n is an open source workflow automation platform. Prior to 1.123.43, 2.22.1, and 2.20.7, an authenticated user with permission to create or modify workflows could achieve global prototype pollution via an unvalidated pagination parameter in the HTTP Request node. Combined with other techniques this could lead to RCE on the instance. This vulnerability is fixed in 1.123.43, 2.22.1, and 2.20.7.
Operator check
Review CVE-2026-44789 in your asset inventory. Apply patches per vendor guidance and verify N8N is not exposed. CVSS score: 9.9. EPSS probability: 0.5%; percentile: 40%.
Read brief →
Jun 23, 2026
Vendor advisory
Critical vendor advisory
CVE-2026-44791
N8N · N8N
n8n is an open source workflow automation platform. Prior to 1.123.43, 2.22.1, and 2.20.7, an authenticated user with permission to create or modify workflows could bypass the patch for CVE-2026-42232 in the XML node. When combined with other nodes, this could lead to RCE on the n8n host. This vulnerability is fixed in 1.123.43, 2.22.1, and 2.20.7.
Operator check
Review CVE-2026-44791 in your asset inventory. Apply patches per vendor guidance and verify N8N is not exposed. CVSS score: 9.9. EPSS probability: 0.5%; percentile: 41%.
Read brief →
Jun 23, 2026
Vendor advisory
Critical vendor advisory
CVE-2026-44792
N8N · N8N
n8n is an open source workflow automation platform. Prior to 1.123.43, 2.22.1, and 2.20.7, an attacker with write access to the git repository connected to an n8n Source Control configuration could commit a malicious Data Table JSON file containing a crafted column name. When an administrator performed a Source Control Pull, n8n imported the file and could lead to SQL injection on the internal PostgreSQL instance. Exploitation requires the n8n instance uses PostgreSQL as its database backend, the Source Control feature is enabled and connected to a repository the attacker can write to, and an
Operator check
Review CVE-2026-44792 in your asset inventory. Apply patches per vendor guidance and verify N8N is not exposed. CVSS score: 9.0. EPSS probability: 0.4%; percentile: 27%.
Read brief →
Jun 23, 2026
Vendor advisory
Critical vendor advisory
CVE-2026-54305
N8N · N8N
n8n is an open source workflow automation platform. Prior to 1.123.55, 2.25.7, and 2.26.2, three EE endpoints used by the Dynamic Credentials feature accepted any authenticated n8n session without performing per-resource ownership or scope checks on the target workflow or credential. An authenticated user with no project membership or credential sharing relationship could enumerate credential identifiers, names, and types referenced by any private workflow in the instance, initiate an OAuth authorization flow against another user's credential to overwrite its stored tokens with tokens bound to
Operator check
Review CVE-2026-54305 in your asset inventory. Apply patches per vendor guidance and verify N8N is not exposed. CVSS score: 9.9. EPSS probability: 0.3%; percentile: 25%.
Read brief →
Jun 23, 2026
Vendor advisory
Critical vendor advisory
CVE-2026-54307
N8N · N8N
n8n is an open source workflow automation platform. Prior to 1.123.55, 2.25.7, and 2.26.2, a member-level user with editor access to a shared workflow could reference credentials they do not own via specific public API endpoints. Credential ownership checks were only enforced partially leading to cross-user credential access. This issue affects instances where workflow sharing is enabled and at least one workflow has been shared with a member-level user as an Editor. This vulnerability is fixed in 1.123.55, 2.25.7, and 2.26.2.
Operator check
Review CVE-2026-54307 in your asset inventory. Apply patches per vendor guidance and verify N8N is not exposed. CVSS score: 9.6. EPSS probability: 0.3%; percentile: 24%.
Read brief →
Jun 23, 2026
Vendor advisory
Critical vendor advisory
CVE-2026-54309
N8N · N8N
n8n is an open source workflow automation platform. Prior to 2.25.7 and 2.26.2, when @n8n/mcp-browser is run in HTTP transport mode, the MCP endpoint accepts session initialization and tool invocation requests without any authentication. Any network-reachable client, or any website visited by the user, can establish an MCP session and invoke browser-control tools. Where the n8n AI Browser Bridge extension is installed and a browser connection is active, an unauthenticated caller can access browser-control capabilities including navigation, JavaScript evaluation, and cookie and storage access a
Operator check
Review CVE-2026-54309 in your asset inventory. Apply patches per vendor guidance and verify N8N is not exposed. CVSS score: 10.0. EPSS probability: 0.4%; percentile: 33%.
Read brief →
Jun 23, 2026
Vendor advisory
Critical vendor advisory
CVE-2026-54310
N8N · N8N
n8n is an open source workflow automation platform. Prior to 2.25.7 and 2.26.2, an authenticated user with permission to create or modify workflows could supply a crafted parameters to the TimescaleDB and/or legacy Postgres v1 node's allowing arbitrary SQL to be injected and executed against the connected database within the privileges of the configured database account. This vulnerability is fixed in 2.25.7 and 2.26.2.
Operator check
Review CVE-2026-54310 in your asset inventory. Apply patches per vendor guidance and verify N8N is not exposed. CVSS score: 9.9. EPSS probability: 0.3%; percentile: 23%.
Read brief →
Jun 23, 2026
Vendor advisory
High-risk advisory
CVE-2026-54350
npm · @budibase/server
Budibase has nonymous NoSQL operator injection via published-app query templates
Operator check
Check whether @budibase/server is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.
Read brief →
Jun 23, 2026
Vendor advisory
High-risk advisory
CVE-2026-53925
PyPI · glances
Glances has arbitrary file write and command execution via `secure_popen` redirection and chaining operators in AMP command configuration
Operator check
Check whether glances is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.
Read brief →
Jun 23, 2026
Vendor advisory
High-risk advisory
CVE-2026-54134
PyPI · OctoPrint
OctoPrint has possible file exfiltration via query parameters on upload endpoints
Operator check
Check whether OctoPrint is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. CVSS score: 7.0.
Read brief →
Jun 23, 2026
Vendor advisory
High-risk advisory
CVE-2026-55488
PyPI · motioneye
motionEye's Absolute Path Traversal in Media File Handlers Allows Arbitrary File Read
Operator check
Check whether motioneye is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.
Read brief →
Jun 23, 2026
Vendor advisory
Critical vendor advisory
PyPI · motioneye
motionEye Partial Authentication Bypass: Unauthenticated Admin Credential Theft via Path Traversal
Operator check
Check whether motioneye is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. CVSS score: 10.0.
Read brief →
Jun 23, 2026
Vendor advisory
High-risk advisory
PyPI · motioneye
motionEye: LFI → pass‑the‑hash admin → unsafe restore → unauth action exec (RCE)
Operator check
Check whether motioneye is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.
Read brief →
Jun 23, 2026
Vendor advisory
High-risk advisory
CVE-2026-55441
Rust · mise
Mise vulnerable to arbitrary command execution via task-include files in an untrusted, config-less repository
Operator check
Check whether mise is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.
Read brief →
Jun 23, 2026
KEV
Known exploited
CVE-2026-34908
Ubiquiti · UniFi OS
Ubiquiti UniFi OS contains an improper access control vulnerability which could allow a malicious actor with access to the network to make unauthorized changes to the system.
Operator check
Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
Read brief →
Jun 23, 2026
KEV
Known exploited
CVE-2026-34909
Ubiquiti · UniFi OS
Ubiquiti UniFi OS contains a path traversal vulnerability which could allow a malicious actor with access to the network to access files on the underlying system that could be manipulated to access an underlying account.
Operator check
Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
Read brief →
Jun 23, 2026
KEV
Known exploited
CVE-2026-34910
Ubiquiti · UniFi OS
Ubiquiti UniFi OS contains an improper input validation vulnerability which could allow a malicious actor with access to the network to conduct command injection.
Operator check
Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
Read brief →
Jun 22, 2026
Vendor advisory
High-risk advisory
CVE-2025-58048
Composer · paymenter/paymenter
Paymenter vulnerable to Remote Code Execution via public file uploads
Operator check
Check whether paymenter/paymenter is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. EPSS probability: 0.4%; percentile: 29%.
Read brief →
Jun 22, 2026
Coordinated disclosure
Patch review
FastStone · Image Viewer 8.3.0.0
Overview Two vulnerabilities have been identified in FastStone Image Viewer 8.3 that may allow remote code execution or control-flow corruption when processing specially crafted image files. The affected components include the JPEG 2000 (JP2) parser and the PSD file parser. An attacker can exploit these vulnerabilities by causing the application to automatically or interactively process malicious image files. Description FastStone Image Viewer is a software tool for browsing, editing, and managing images, offering features like full‑screen viewing, batch processing, red‑eye removal, and a wide range of editing effects. It supports virtually all major image and RAW formats and includes conveniences like slideshows, comparison tools, scanner support, and screen capture. CVE-2026-30040 A critical heap-based buffer overflow vulnerability... Related CVEs: CVE-2026-30040, CVE-2026-30041.
Operator check
Review the CERT/CC Vulnerability Note and compare the affected vendor and product list against your inventory. Apply vendor fixes or compensating controls for Image Viewer 8.3.0.0 where available.
Read brief →
Jun 22, 2026
Vendor advisory
Critical vendor advisory
CVE-2026-8646
Ibm · Websphere Application Server
IBM WebSphere Application Server 9.0 and 8.5 and IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.6 are vulnerable to HTTP request smuggling. A remote attacker could smuggle a specially crafted request to the application server thereby allowing the attacker to bypass security controls, spoof identity, escalate privilege, and expose sensitive information.
Operator check
Review CVE-2026-8646 in your asset inventory. Apply patches per vendor guidance and verify Websphere Application Server is not exposed. CVSS score: 7.4. EPSS probability: 0.4%; percentile: 27%.
Read brief →
Jun 22, 2026
Vendor advisory
Critical vendor advisory
CVE-2026-9006
Ibm · Websphere Application Server
IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to server-side request forgery (SSRF) with the Ajax Proxy configured. This may allow an attacker to send unauthorized requests from the system, resulting in a security bypass or information disclosure.
Operator check
Review CVE-2026-9006 in your asset inventory. Apply patches per vendor guidance and verify Websphere Application Server is not exposed. CVSS score: 7.4. EPSS probability: 0.2%; percentile: 14%.
Read brief →
Jun 22, 2026
Vendor advisory
Critical vendor advisory
CVE-2026-9072
Ibm · I
IBM i 7.6, 7.5, 7.4, and 7.3, IBM WebSphere Application Server, and IBM WebSphere Application Server Liberty - when using Intelligent Management with the WebSphere WebServer Plug-in component - are vulnerable to remote code execution and denial of service. This vulnerability can be exploited when an attacker impersonates backend servers and sends crafted responses to the plug-in.
Operator check
Review CVE-2026-9072 in your asset inventory. Apply patches per vendor guidance and verify I is not exposed. CVSS score: 8.1. EPSS probability: 0.4%; percentile: 30%.
Read brief →
Jun 22, 2026
Vendor advisory
Critical vendor advisory
CVE-2026-49468
Litellm · Litellm
LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. Prior to 1.84.0, This vulnerability is fixed in 1.84.0.
Operator check
Review CVE-2026-49468 in your asset inventory. Apply patches per vendor guidance and verify Litellm is not exposed. CVSS score: 9.8. EPSS probability: 0.4%; percentile: 31%.
Read brief →
Jun 22, 2026
Vendor advisory
High-risk advisory
CVE-2026-44179
Maven · com.xwiki.pro:xwiki-pro-macros
xwiki-pro-macros has remote code execution from page title and content via excerpt-include macro
Operator check
Check whether com.xwiki.pro:xwiki-pro-macros is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.
Read brief →
Jun 22, 2026
Vendor advisory
High-risk advisory
CVE-2026-44203
Maven · org.openidentityplatform.openam:openam-oauth2
OpenAM has pre-auth Reflected XSS in OAuth2 / OIDC response_mode=form_post via state parameter (FormPostResponse.ftl)
Operator check
Check whether org.openidentityplatform.openam:openam-oauth2 is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.
Read brief →
Jun 22, 2026
Vendor advisory
Critical vendor advisory
CVE-2026-46495
Maven · org.openidentityplatform.opendj:opendj-server-legacy
OpenDJ Pre-Auth RCE via Java Deserialization in JMX RMI
Operator check
Check whether org.openidentityplatform.opendj:opendj-server-legacy is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. CVSS score: 9.2.
Read brief →
Jun 22, 2026
Vendor advisory
Critical vendor advisory
CVE-2026-48509
Messagepack · Messagepack
MessagePack for C# is a MessagePack serializer for C#. Prior to 2.5.301 and 3.1.7, the parameterless MessagePackInputFormatter() constructor uses default serializer options, which resolve to MessagePackSerializerOptions.Standard with MessagePackSecurity.TrustedData. The formatter is designed for ASP.NET Core MVC request bodies, which commonly cross an HTTP trust boundary. This insecure default can expose applications to denial-of-service attacks that MessagePackSecurity.UntrustedData is intended to mitigate, such as hash-collision attacks against dictionary-like model properties. This vulnerab
Operator check
Review CVE-2026-48509 in your asset inventory. Apply patches per vendor guidance and verify Messagepack is not exposed. CVSS score: 9.1. EPSS probability: 0.2%; percentile: 13%.
Read brief →
Jun 22, 2026
Coordinated disclosure
Patch review
Microsoft · WinRE
Overview Microsoft Windows Recovery Environment (WinRE) provides a mechanism for recovering and repairing Windows systems using an alternate boot environment. Under certain platform implementations, access to WinRE may allow an attacker to bypass firmware security controls, including administrator-configured UEFI/BIOS passwords. An attacker with physical or administrative access to a device may be able to leverage WinRE-related boot mechanisms to circumvent firmware protections and gain unauthorized access to system resources. Description Microsoft Windows versions 10 and 11 include the WinRE capability, a recovery platform that supports features such as the F11 recovery menu and the Reset this PC functionalities. WinRE is commonly used for system recovery, troubleshooting, and remote support scenarios. When WinRE is invoked, the system...
Operator check
Review the CERT/CC Vulnerability Note and compare the affected vendor and product list against your inventory. Apply vendor fixes or compensating controls for WinRE where available.
Read brief →
Jun 22, 2026
Vendor advisory
Critical vendor advisory
CVE-2026-56348
N8N · N8N
n8n before 2.20.0 contains a credential exfiltration vulnerability in the POST /rest/dynamic-node-parameters/options endpoint that allows authenticated users to bypass Allowed HTTP Request Domains restrictions. Attackers with credential access can cause the n8n server to issue HTTP requests with credentials to unauthorized hosts, exfiltrating sensitive authentication data.
Operator check
Review CVE-2026-56348 in your asset inventory. Apply patches per vendor guidance and verify N8N is not exposed. CVSS score: 9.1. EPSS probability: 0.2%; percentile: 16%.
Read brief →
Jun 22, 2026
Vendor advisory
High-risk advisory
CVE-2026-48170
npm · scim-patch
scimPatch vulnerable to prototype pollution via unfiltered keys in patch
Operator check
Check whether scim-patch is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.
Read brief →
Jun 22, 2026
Vendor advisory
High-risk advisory
CVE-2026-54352
npm · @budibase/server
Budibase has arbitrary file read by workspace-builder via PWA-zip symlink upload
Operator check
Check whether @budibase/server is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.
Read brief →
Jun 22, 2026
Vendor advisory
Critical vendor advisory
CVE-2026-46488
PyPI · motioneye
motionEye: Authentication possible via password hash
Operator check
Check whether motioneye is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. CVSS score: 9.1.
Read brief →
Jun 22, 2026
Vendor advisory
High-risk advisory
CVE-2026-33646
Rust · mise
Mise Vulnerable to Arbitrary Code Execution via Tera Templates in .tool-versions Files (Trust Bypass)
Operator check
Check whether mise is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.
Read brief →
Jun 18, 2026
Coordinated disclosure
Patch review
Multiple vendors · Vendor-signed UEFI applications
Overview Multiple vendor-signed UEFI applications are vulnerable to Secure Boot bypass via a "Bring Your Own Vulnerable Driver" (BYOVD)-style attack. If a target system trusts the affected vendor’s certificate, an attacker can exploit these applications to execute arbitrary code during the early pre-boot phase before the operating system initializes. To mitigate this risk, system administrators should apply updates to the UEFI Forbidden Signature Database (DBX) that revoke trust in the affected vendor-signed binaries, preventing these vulnerable applications from executing during the boot process. Description The Unified Extensible Firmware Interface ( UEFI ) standard defines the modern firmware architecture used to initialize hardware and transfer control to the operating system during system startup. On systems with Secure Boot...
Operator check
Review the CERT/CC Vulnerability Note and compare the affected vendor and product list against your inventory. Apply vendor fixes or compensating controls for Vendor-signed UEFI applications where available.
Read brief →
Jun 18, 2026
KEV
Known exploited
CVE-2026-20253
Splunk · Enterprise
Splunk Enterprise contains a missing authentication for critical function vulnerability which could allow an unauthenticated user to create or truncate arbitrary files through a PostgreSQL sidecar service endpoint.
Operator check
Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
Read brief →
Jun 17, 2026
Vendor advisory
Critical vendor advisory
CVE-2026-32966
Apache · Dolphinscheduler
DataSource API Missing Authorization Check Leads to Arbitrary Data Source Metadata Disclosure in Apache DolphinScheduler.
This issue affects Apache DolphinScheduler: before 3.4.2.
Users are recommended to upgrade to version 3.4.2, which fixes the issue.
Operator check
Review CVE-2026-32966 in your asset inventory. Apply patches per vendor guidance and verify Dolphinscheduler is not exposed. CVSS score: 9.8.
Read brief →
Jun 17, 2026
Vendor advisory
Critical vendor advisory
CVE-2026-32967
Apache · Dolphinscheduler
Incorrect Authorization vulnerability of `/v2` experimental interface in Apache DolphinScheduler.
This issue affects Apache DolphinScheduler: before 3.4.2.
Users are recommended to upgrade to version 3.4.2, which fixes the issue.
Operator check
Review CVE-2026-32967 in your asset inventory. Apply patches per vendor guidance and verify Dolphinscheduler is not exposed. CVSS score: 9.1.
Read brief →
Jun 17, 2026
Vendor advisory
Critical vendor advisory
CVE-2026-49268
Apache · Shiro
A remote attacker can inject LDAP special characters into the Distinguished Name (DN) construction in DefaultLdapRealm class. User-supplied username input is directly concatenated into the LDAP DN template without any escaping of RFC 2253 special characters. This allows an attacker to manipulate the DN structure used for LDAP bind authentication, potentially bypassing authentication or impersonating other users.
This issue affects all Apache Shiro versions through 2.2.0, and 3.0.0-alpha-1 when using DefaultLdapRealm
Upgrade to Apache Shiro 2.2.1 or 3.0.0-alpha-2 or later, which fixes the issu
Operator check
Review CVE-2026-49268 in your asset inventory. Apply patches per vendor guidance and verify Shiro is not exposed. CVSS score: 9.1.
Read brief →
Jun 17, 2026
Coordinated disclosure
Patch review
SignalRGB · kernel driver
Overview The SignalRGB kernel driver, SignalIo.sys , contains two vulnerabilities involving improper access control and unsafe memory handling. The device object is created with an overly permissive Discretionary Access Control List (DACL) that allows user-mode processes to access privileged hardware operations through input/output control (IOCTL) commands. Additionally, several IOCTL handlers are susceptible to NULL pointer dereference conditions, which further enables low-privilege users to trigger kernel crashes and cause Denial of Service (DoS). Version 1.3.7.0 of the SignalRGB driver remediates these vulnerabilities. Description SignalRGB is a Windows application used for RGB lighting control and hardware monitoring. Its kernel component, SignalIo.sys , provides the low-level interfaces required to access and interact with hardware... Related CVEs: CVE-2026-8049, CVE-2026-8050.
Operator check
Review the CERT/CC Vulnerability Note and compare the affected vendor and product list against your inventory. Apply vendor fixes or compensating controls for kernel driver where available.
Read brief →
Jun 16, 2026
KEV
Known exploited
CVE-2026-48907
Widget Factory · Joomla Content Editor
Widget Factory Joomla Content Editor contains an improper access control vulnerability which could allow for upload and execution of PHP code via the creation of new editor profiles for unauthenticated users.
Operator check
Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
Read brief →
Jun 15, 2026
KEV
Known exploited
CVE-2026-20262
Cisco · Catalyst SD-WAN Manager
Cisco Catalyst SD-WAN Manager contains a directory or path traversal vulnerability that could allow an authenticated, remote attacker to create a file or overwrite any file on the filesystem of an affected system.
Operator check
Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
Read brief →
Jun 15, 2026
KEV
Known exploited
CVE-2026-54420
LiteSpeed · cPanel Plugin
LiteSpeed cPanel plugin contains a UNIX symbolic link (Symlink) following vulnerability that could allow a user with FTP or web shell access on a shared hosting server running CloudLinux/CageFS.
Operator check
Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
Read brief →
Jun 12, 2026
KEV
Known exploited
CVE-2026-35273
Oracle · PeopleSoft Enterprise PeopleTools
Oracle PeopleSoft Enterprise PeopleTools contains a missing authentication for critical function vulnerability which could allow an unauthenticated attacker to obtain takeover of PeopleSoft Enterprise PeopleTools.
Operator check
Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
Read brief →
Jun 11, 2026
KEV
Known exploited
CVE-2026-10520
Ivanti · Sentry
Ivanti Sentry (formerly known as MobileIron Sentry) contains an OS command injection vulnerability which could allow a remote unauthenticated user to achieve root-level remote code execution. This vulnerability can be successfully exploited in cases where the Sentry appliance is in an unmanaged state with its endpoints externally reachable. The use of mTLS with EPMM or restricted HTTPS access through Neurons for MDM makes interfaces inaccessible to external actors.
Operator check
Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
Read brief →
Jun 11, 2026
Coordinated disclosure
Patch review
Multiple vendors · crypton-x509-validation Haskell libraries do not enforce X.509 NameConstraints
Overview A vulnerability has been discovered in the Haskell TLS software stack, commonly used by applications built in the Haskell programming language to securely connect to servers over the internet. Specifically, the libraries "crypton-x509-validation" fail to enforce a key security feature called NameConstraints, a standard defined in RFC 5280 that helps organizations control which domains a certificate authority (CA) is allowed to issue certificates for. This vulnerability allows an attacker with access to the sub-CA to create certificates that will validate successfully with any Haskell TLS connection, allowing the attacker access to full session visibility. Version 1.91 for crypton-x509-validation have been released to address the vulnerability, tracked as CVE-2026-9648. Description Haskell is a programming language often used in... Related CVEs: CVE-2026-9648.
Operator check
Review the CERT/CC Vulnerability Note and compare the affected vendor and product list against your inventory. Apply vendor fixes or compensating controls for crypton-x509-validation Haskell libraries do not enforce X.509 NameConstraints where available.
Read brief →
Jun 9, 2026
KEV
Known exploited
CVE-2026-7473
Arista · Extensible Operating System
Arista Extensible Operating System (EOS) contains an incomplete comparison with missing factors vulnerability when the switch incorrectly decapsulate and forwards other unexpected tunneled packet with a destination IP matching its configured decapsulation IP.
Operator check
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Read brief →
Jun 9, 2026
KEV
Known exploited
CVE-2026-20245
Cisco · Catalyst SD-WAN Manager
Cisco Catalyst SD-WAN Manager formerly SD-WAN vManage contains an improper encoding or escaping of output vulnerability. This vulnerability could allow an authenticated, local attacker to execute arbitrary commands as root by supplying a crafted file to the affected system.
Operator check
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Read brief →
Jun 9, 2026
KEV
Known exploited
CVE-2026-11645
Google · Chromium V8
Google Chromium V8 out-of-bounds read and write vulnerability that could allow a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.
Operator check
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Read brief →
Jun 9, 2026
Patch Tuesday
High-risk advisory
CVE-2026-32174
Microsoft · Azure Bot Service
Improper authentication in Azure Bot Service allows an authorized attacker to elevate privileges over a network. Published in June 2026 Security Updates. MSRC exploitability: Publicly Disclosed:No;Exploited:No.
Operator check
Review the Microsoft Security Update Guide entry for CVE-2026-32174. Confirm whether Azure Bot Service is deployed, then apply the current security update or documented mitigation. CVSS score: 7.7. EPSS probability: 0.4%; percentile: 29%.
Read brief →
Jun 9, 2026
Patch Tuesday
High-risk advisory
CVE-2026-32208
Microsoft · Microsoft Edge (Chromium-based)
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Edge (Chromium-based) allows an authorized attacker to perform spoofing over a network. Published in June 2026 Security Updates. MSRC exploitability: Publicly Disclosed:No;Exploited:No;Latest Software Release:N/A.
Operator check
Review the Microsoft Security Update Guide entry for CVE-2026-32208. Confirm whether Microsoft Edge (Chromium-based) is deployed, then apply the current security update or documented mitigation. CVSS score: 8.8. EPSS probability: 0.3%; percentile: 20%.
Read brief →
Jun 9, 2026
Patch Tuesday
High-risk advisory
CVE-2026-42895
Microsoft · Microsoft Copilot
Improper neutralization of special elements used in a command ('command injection') in Microsoft Copilot allows an unauthorized attacker to perform tampering over a network. Published in June 2026 Security Updates. MSRC exploitability: Publicly Disclosed:No;Exploited:No;Latest Software Release:N/A.
Operator check
Review the Microsoft Security Update Guide entry for CVE-2026-42895. Confirm whether Microsoft Copilot is deployed, then apply the current security update or documented mitigation. CVSS score: 6.5. EPSS probability: 0.4%; percentile: 30%.
Read brief →
Jun 9, 2026
Patch Tuesday
High-risk advisory
CVE-2026-45472
Microsoft · Microsoft Office
Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally. Published in June 2026 Security Updates. MSRC exploitability: Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation Less Likely.
Operator check
Review the Microsoft Security Update Guide entry for CVE-2026-45472. Confirm whether Microsoft Office is deployed, then apply the current security update or documented mitigation. CVSS score: 8.4. EPSS probability: 0.3%; percentile: 26%.
Read brief →
Jun 9, 2026
Patch Tuesday
High-risk advisory
CVE-2026-45474
Microsoft · Microsoft Office
Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally. Published in June 2026 Security Updates. MSRC exploitability: Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation Less Likely.
Operator check
Review the Microsoft Security Update Guide entry for CVE-2026-45474. Confirm whether Microsoft Office is deployed, then apply the current security update or documented mitigation. CVSS score: 8.4. EPSS probability: 0.4%; percentile: 28%.
Read brief →
Jun 9, 2026
Patch Tuesday
Critical vendor advisory
CVE-2026-45480
Microsoft · Azure Active Directory
Improper authentication in Azure Active Directory allows an unauthorized attacker to elevate privileges over a network. Published in June 2026 Security Updates. MSRC exploitability: Publicly Disclosed:No;Exploited:No;Latest Software Release:N/A.
Operator check
Review the Microsoft Security Update Guide entry for CVE-2026-45480. Confirm whether Azure Active Directory is deployed, then apply the current security update or documented mitigation. CVSS score: 10.0. EPSS probability: 0.6%; percentile: 43%.
Read brief →
Jun 9, 2026
Patch Tuesday
High-risk advisory
CVE-2026-47633
Microsoft · Cost Management Interactive Experiences
Exposure of sensitive information to an unauthorized actor in Cost Management Interactive Experiences allows an unauthorized attacker to disclose information over a network. Published in June 2026 Security Updates. MSRC exploitability: Publicly Disclosed:No;Exploited:No;Latest Software Release:N/A.
Operator check
Review the Microsoft Security Update Guide entry for CVE-2026-47633. Confirm whether Cost Management Interactive Experiences is deployed, then apply the current security update or documented mitigation. CVSS score: 7.5. EPSS probability: 0.6%; percentile: 43%.
Read brief →
Jun 9, 2026
Patch Tuesday
High-risk advisory
CVE-2026-47644
Microsoft · Copilot Chat (Microsoft Edge)
Improper neutralization of special elements in output used by a downstream component ('injection') in Copilot Chat (Microsoft Edge) allows an unauthorized attacker to disclose information over a network. Published in June 2026 Security Updates. MSRC exploitability: Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation Less Likely.
Operator check
Review the Microsoft Security Update Guide entry for CVE-2026-47644. Confirm whether Copilot Chat (Microsoft Edge) is deployed, then apply the current security update or documented mitigation. CVSS score: 6.5. EPSS probability: 0.7%; percentile: 50%.
Read brief →
Jun 9, 2026
Patch Tuesday
High-risk advisory
CVE-2026-47655
Microsoft · Microsoft Graph
Exposure of sensitive information to an unauthorized actor in Microsoft Graph allows an authorized attacker to disclose information over a network. Published in June 2026 Security Updates. MSRC exploitability: Publicly Disclosed:No;Exploited:No;Latest Software Release:N/A.
Operator check
Review the Microsoft Security Update Guide entry for CVE-2026-47655. Confirm whether Microsoft Graph is deployed, then apply the current security update or documented mitigation. CVSS score: 6.5. EPSS probability: 0.8%; percentile: 50%.
Read brief →
Jun 9, 2026
Patch Tuesday
Critical vendor advisory
CVE-2026-54130
Microsoft · M365 Copilot
Missing authentication for critical function in M365 Copilot allows an unauthorized attacker to disclose information over a network. Published in June 2026 Security Updates. MSRC exploitability: Publicly Disclosed:No;Exploited:No;Latest Software Release:N/A.
Operator check
Review the Microsoft Security Update Guide entry for CVE-2026-54130. Confirm whether M365 Copilot is deployed, then apply the current security update or documented mitigation. CVSS score: 9.8. EPSS probability: 0.5%; percentile: 39%.
Read brief →
Jun 9, 2026
Coordinated disclosure
Patch review
UEFI · applications and drivers must be cryptographically signed and verified
Overview Microsoft-signed UEFI bootloaders of the open-source shim project, primarily from version 0.9 and earlier, were identified as vulnerable to Secure Boot bypass. To mitigate this risk, the affected bootloaders will be added to the Microsoft UEFI Forbidden Signature Database (DBX). Once the DBX update is applied, these bootloaders will no longer be trusted for execution during the boot process. An attacker could exploit these vulnerable shim bootloaders using a Bring Your Own Vulnerable Driver (BYOVD)-style technique to execute arbitrary code during the early boot phase, prior to operating system initialization, thereby bypassing Secure Boot protections. Description The Unified Extensible Firmware Interface (UEFI) standard defines the modern firmware architecture used to initialize hardware and transfer control to the operating... Related CVEs: CVE-2026-10797, CVE-2026-8863.
Operator check
Review the CERT/CC Vulnerability Note and compare the affected vendor and product list against your inventory. Apply vendor fixes or compensating controls for applications and drivers must be cryptographically signed and verified where available.
Read brief →
Jun 8, 2026
KEV
Known exploited
CVE-2026-42271
BerriAI · LiteLLM
BerriAI LiteLLM contains a command injection vulnerability that could allow any authenticated user, including holders of low-privilege internal-user keys, to run arbitrary commands on the host.
Operator check
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Read brief →
Jun 8, 2026
KEV
Known exploited
CVE-2026-50751
Check Point · Security Gateway
Check Point Security Gateway contains an improper authentication vulnerability in IKEv1 key exchange that could allow an unauthenticated remote attacker to bypass user authentication and establish a remote access VPN connection without a valid user password.
Operator check
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Read brief →
Jun 5, 2026
KEV
Known exploited
CVE-2026-28318
SolarWinds · Serv-U
SolarWinds Serv-U contains an uncontrolled resource consumption vulnerability that allows specially crafted POST requests using the Content-Encoding: deflate header to crash the Serv-U service without authentication.
Operator check
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Read brief →
Jun 3, 2026
KEV
Known exploited
CVE-2026-45247
Mirasvit · Mirasvit Full Page Cache Warmer
Mirasvit Full Page Cache Warmer contains a deserialization of untrusted data vulnerability that could allow unauthenticated attackers to achieve remote code execution by supplying a crafted serialized PHP object in the CacheWarmer cookie.
Operator check
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Read brief →
Jun 3, 2026
Coordinated disclosure
Patch review
Securly · Chrome Extension
Overview Version 3.0.7 of the Securly Chrome Extension contains multiple vulnerabilities involving insecure data transmission, weak cryptography, and improper access control. These issues may expose sensitive filtering rules, enable the manipulation of downloaded configuration files, and allow unauthenticated access to protected resources. An attacker could exploit these weakness to steal configuration information, induce a Denial of Service (DoS), or modify content blocking rules for student users. Description The Securly Chrome Extension is a browser add-on commonly used in K–12 school-managed Chromebooks to enforce internet safety policies, filter or block websites, and provide activity monitoring for students. It is an element of the Securly classroom management platform, which helps schools comply with web filtering requirements and... Related CVEs: CVE-2026-8874, CVE-2026-8876, CVE-2026-8878, CVE-2026-8879.
Operator check
Review the CERT/CC Vulnerability Note and compare the affected vendor and product list against your inventory. Apply vendor fixes or compensating controls for Chrome Extension where available.
Read brief →
Jun 2, 2026
KEV
Known exploited
CVE-2025-48595
Android · Framework
Android Framework contains an integer overflow vulnerability that allows for code execution that could allow for local privilege escalation.
Operator check
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Read brief →
Jun 2, 2026
Coordinated disclosure
Patch review
Appsmiths · SQL Query autocomplete renderer
Overview A stored cross-site scripting (XSS) vulnerability has been discovered in Appsmith, specifically in the CodeMirror based SQL query editor’s autocomplete renderer. CVE-2026-7299 has been assigned to track the vulnerability. An attacker with developer level access to a shared PostgreSQL datasource can inject arbitrary JavaScript by creating malicious database objects whose names contain XSS payloads. Successful exploitation leads to arbitrary JavaScript execution in the browser of any workspace member who triggers SQL autocomplete, enabling session hijacking, privilege escalation, or credential theft. Version 2.1 of Appsmith fixes CVE-2026-7299. Description Appsmith is an open source, low code platform intended to allow developers to build internal tools, dashboards, and applications using a UI builder, database and API... Related CVEs: CVE-2026-7299.
Operator check
Review the CERT/CC Vulnerability Note and compare the affected vendor and product list against your inventory. Apply vendor fixes or compensating controls for SQL Query autocomplete renderer where available.
Read brief →
Jun 2, 2026
Coordinated disclosure
Patch review
Collibra · Agent
Overview The Collibra Platform Agent contains vulnerabilities that can be chained by a remote, unauthenticated attacker to achieve remote code execution. An attacker can exploit these issues by uploading a crafted ZIP archive that writes attacker-controlled files to arbitrary locations on the server once extracted, resulting in code execution. Description Collibra Platform (CP) and Collibra Platform Self-Hosted (CPSH), an enterprise grade, cloud-based platform designed to help organizations locate, understand, trust, and manage their data assets. The Collibra Agent of CP and CPSH that is installed on the host system is an independent service that listens on different port than the web interface and have the following vulnerabilities. CVE-2026-10622 Privileged REST endpoints exposed under /rest/* do not properly enforce authentication or... Related CVEs: CVE-2026-10621, CVE-2026-10622.
Operator check
Review the CERT/CC Vulnerability Note and compare the affected vendor and product list against your inventory. Apply vendor fixes or compensating controls for Agent where available.
Read brief →
Jun 2, 2026
KEV
Known exploited
CVE-2022-0492
Linux · Kernel
Linux Kernel contains an improper authentication vulnerability which could allow for privilege escalation via the cgroups v1 release_agent feature.
Operator check
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Read brief →
Jun 2, 2026
Coordinated disclosure
Patch review
Verizon · VoLTE Deployments
Overview VoLTE deployments on Verizon’s IMS network have operated without negotiated SIP integrity protection. In observed test conditions, SIP signaling—including registration, call setup, and messaging—traveled without IPsec ESP encapsulation and without SIP Security Agreement headers, exposing it to interception and modification by on-path attackers. Recent carrier configuration updates, including Apple’s iOS 26.5 carrier bundle released on May 11, 2026, include IMS IPsec–related settings. However, such configuration entries do not confirm active deployment, successful negotiation, or functional protection in production. Description CVE-2026-10629 Verizon IMS deployments were observed transmitting SIP signaling without integrity protection. REGISTER exchanges lacked Security-Client, Security-Server, and Security-Verify headers, and no... Related CVEs: CVE-2026-10629.
Operator check
Review the CERT/CC Vulnerability Note and compare the affected vendor and product list against your inventory. Apply vendor fixes or compensating controls for VoLTE Deployments where available.
Read brief →
Jun 1, 2026
KEV
Known exploited
CVE-2024-21182
Oracle · WebLogic Server
Oracle WebLogic contains an unspecified vulnerability that could allow an unauthenticated attacker with network access via T3, IIOP to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle WebLogic Server accessible data.
Operator check
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Read brief →
May 29, 2026
KEV
Known exploited
CVE-2026-0257
Palo Alto Networks · PAN-OS
Palo Alto Networks PAN-OS contains an authentication bypass vulnerability that allows attackers to bypass security restrictions and establish an unauthorized VPN connection.
Operator check
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Read brief →
May 27, 2026
KEV
Known exploited
CVE-2026-8398
Daemon · Daemon Tools Lite
Daemon Tools contains an unspecified vulnerability that has a high impact on confidentiality, integrity, and availability.
Operator check
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Read brief →
May 27, 2026
KEV
Known exploited
CVE-2026-48027
Nx · Nx Console
Nx Console contains an embedded malicious code vulnerability that allowed a malicious version of Nx Console to be published. The compromised extension fetched an obfuscated payload that could harvested credentials from multiple sources on disk and in memory.
Operator check
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Read brief →
May 27, 2026
KEV
Known exploited
CVE-2026-45321
TanStack · TanStack
TanStack contains an unspecified vulnerability that allowed malicious versions of the product to be published to the npm registry to publish credential-stealing malware under a trusted identity.
Operator check
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Read brief →
May 26, 2026
KEV
Known exploited
CVE-2026-48172
LiteSpeed · cPanel Plugin
LiteSpeed cPanel Plugin contains privilege escalation vulnerability that is exposed via the user-end cPanel plugin, which can be abused by any cPanel user account to execute arbitrary scripts with root privileges.
Operator check
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Read brief →
May 22, 2026
KEV
Known exploited
CVE-2026-9082
Drupal · Core
Drupal Core contains a SQL injection vulnerability that could allow for privilege escalation and remote code execution via specially crafted requests sent with the database abstraction API.
Operator check
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Read brief →
May 21, 2026
KEV
Known exploited
CVE-2025-34291
Langflow · Langflow
Langflow contains an origin validation error vulnerability in which an overly permissive CORS configuration combined with a refresh token cookie configured as SameSite=None allows a malicious webpage to perform cross-origin requests that include credentials and successfully call the refresh endpoint. This could allow the attacker to execute arbitrary code and achieve full system compromise via obtained tokens that permit access to authenticated endpoints.
Operator check
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Read brief →
May 21, 2026
KEV
Known exploited
CVE-2026-34926
Trend Micro · Apex One
Trend Micro Apex One (on-premise) contains a directory traversal vulnerability that could allow a pre-authenticated local attacker to modify a key table on the server to inject malicious code to deploy to agents on affected installations.
Operator check
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Read brief →
May 20, 2026
KEV
Known exploited
CVE-2009-3459
Adobe · Acrobat and Reader
Adobe Acrobat and Reader contain a heap-based buffer overflow vulnerability which could allow remote attackers to execute arbitrary code via a crafted PDF file that triggers memory corruption.
Operator check
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Read brief →
May 20, 2026
KEV
Known exploited
CVE-2008-4250
Microsoft · Windows
Microsoft Windows contains a buffer overflow vulnerability in the Windows Server Service that allows remote attackers to execute arbitrary code via a crafted RPC request that triggers an overflow during path canonicalization.
Operator check
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Read brief →
May 20, 2026
KEV
Known exploited
CVE-2009-1537
Microsoft · DirectX
Microsoft DirectX contains a NULL byte overwrite vulnerability in the QuickTime Movie Parser Filter in quartz.dll in DirectShow which could allow remote attackers to execute arbitrary code via a crafted QuickTime media file.
Operator check
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Read brief →
May 20, 2026
KEV
Known exploited
CVE-2010-0249
Microsoft · Internet Explorer
Microsoft Internet Explorer contains an use-after-free vulnerability that could allow remote attackers to execute arbitrary code by accessing a pointer associated with a deleted object. The impacted product could be end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue product utilization.
Operator check
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Read brief →
May 20, 2026
KEV
Known exploited
CVE-2010-0806
Microsoft · Internet Explorer
Microsoft Internet Explorer contains an use-after-free vulnerability that could allow remote attackers to execute arbitrary code via vectors involving access to an invalid pointer after the deletion of an object. The impacted product could be end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue product utilization.
Operator check
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Read brief →
May 20, 2026
KEV
Known exploited
CVE-2026-41091
Microsoft · Defender
Microsoft Defender contains a link following vulnerability that allows an authorized attacker to elevate privileges locally.
Operator check
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Read brief →
May 20, 2026
KEV
Known exploited
CVE-2026-45498
Microsoft · Defender
Microsoft Defender contains an unspecified vulnerability that allows for denial of service.
Operator check
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Read brief →
May 15, 2026
KEV
Known exploited
CVE-2026-42897
Microsoft · Microsoft
Microsoft Exchange Server contains a cross-site scripting vulnerability during web page generation in Outlook Web Access and when certain interaction conditions are met, arbitrary JavaScript can be executed in the browser context.
Operator check
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Read brief →
May 14, 2026
KEV
Known exploited
CVE-2026-20182
Cisco · Catalyst SD-WAN
Cisco Catalyst SD-WAN Controller & Manager contain an authentication bypass vulnerability that allows an unauthenticated, remote attacker to bypass authentication and obtain administrative privileges on an affected system.
Operator check
Please adhere to CISA’s guidelines to assess exposure and mitigate risks associated with Cisco SD-WAN devices as outlined in CISA’s Emergency Directive 26-03 (URL listed below in Notes) and CISA’s Hunt & Hardening Guidance for Cisco SD-WAN Devices (URL listed below in Notes). Adhere to the applicable BOD 22-01 guidance for cloud services or discontinue use of the product if mitigations are not available.
Read brief →
May 8, 2026
KEV
Known exploited
CVE-2026-42208
BerriAI · LiteLLM
BerriAI LiteLLM contains a SQL injection vulnerability that allows an attacker to read data from the proxy's database and potentially modify it, leading to unauthorized access to the proxy and the credentials it manages.
Operator check
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Read brief →
May 7, 2026
KEV
Known exploited
CVE-2026-6973
Ivanti · Endpoint Manager Mobile (EPMM)
Ivanti Endpoint Manager Mobile (EPMM) contains an improper input validation vulnerability that allows a remotely authenticated user with administrative access to achieve remote code execution.
Operator check
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Read brief →
May 6, 2026
KEV
Known exploited
CVE-2026-0300
Palo Alto Networks · PAN-OS
Palo Alto Networks PAN-OS contains an out-of-bounds write vulnerability in the User-ID Authentication Portal (aka Captive Portal) service that can allow an unauthenticated attacker to execute arbitrary code with root privileges on the PA-Series and VM-Series firewalls by sending specially crafted packets.
Operator check
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. Until the vendor releases an official fix, the following workaround should be implemented: - Restrict User-ID Authentication Portal access to only trusted zones. - Disable User-ID Authentication Portal if not required. 5/13/2026: Palo Alto has released a variety of patches. If these are relevant to your environment, please apply the designated patch.
Read brief →
May 1, 2026
KEV
Known exploited
CVE-2026-31431
Linux · Kernel
Linux Kernel contains an incorrect resource transfer between spheres vulnerability that could allow for privilege escalation.
Operator check
"Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Read brief →
Apr 30, 2026
KEV
Known exploited
CVE-2026-41940
WebPros · cPanel & WHM and WP2 (WordPress Squared)
WebPros cPanel & WHM (WebHost Manager) and WP2 (WordPress Squared) contain an authentication bypass vulnerability in the login flow that allows unauthenticated remote attackers to gain unauthorized access to the control panel.
Operator check
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Read brief →
Apr 28, 2026
KEV
Known exploited
CVE-2024-1708
ConnectWise · ScreenConnect
ConnectWise ScreenConnect contains a path traversal vulnerability which could allow an attacker to execute remote code or directly impact confidential data and critical systems.
Operator check
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Read brief →
Apr 28, 2026
KEV
Known exploited
CVE-2026-32202
Microsoft · Windows
Microsoft Windows Shell contains a protection mechanism failure vulnerability that allows an unauthorized attacker to perform spoofing over a network.
Operator check
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Read brief →
Apr 24, 2026
KEV
Known exploited
CVE-2025-29635
D-Link · DIR-823X
D-Link DIR-823X contains a command injection vulnerability that allows an authorized attacker to execute arbitrary commands on remote devices by sending a POST request to /goform/set_prohibiting via the corresponding function. The impacted product could be end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue product utilization.
Operator check
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Read brief →
Apr 24, 2026
KEV
Known exploited
CVE-2024-7399
Samsung · MagicINFO 9 Server
Samsung MagicINFO 9 Server contains a path traversal vulnerability that could allow an attacker to write arbitrary files as system authority.
Operator check
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Read brief →
Apr 24, 2026
KEV
Known exploited
CVE-2024-57726
SimpleHelp · SimpleHelp
SimpleHelp contains a missing authorization vulnerability that could allow low-privileged technicians to create API keys with excessive permissions. These API keys can be used to escalate privileges to the server admin role.
Operator check
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Read brief →
Apr 24, 2026
KEV
Known exploited
CVE-2024-57728
SimpleHelp · SimpleHelp
SimpleHelp contains a path traversal vulnerability that allows admin users to upload arbitrary files anywhere on the file system by uploading a crafted zip file (i.e. zip slip). This can be exploited to execute arbitrary code on the host in the context of the SimpleHelp server user.
Operator check
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Read brief →
Apr 23, 2026
KEV
Known exploited
CVE-2026-39987
Marimo · Marimo
Marimo contains an pre-authorization remote code execution vulnerability, allowing an unauthenticated attacked to shell access and execute arbitrary system commands.
Operator check
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Read brief →
Apr 22, 2026
KEV
Known exploited
CVE-2026-33825
Microsoft · Defender
Microsoft Defender contains an insufficient granularity of access control vulnerability that could allow an authorized attacker to escalate privileges locally.
Operator check
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Read brief →
Apr 20, 2026
KEV
Known exploited
CVE-2026-20122
Cisco · Catalyst SD-WAN Manger
Cisco Catalyst SD-WAN Manager contains an incorrect use of privileged APIs vulnerability due to improper file handling on the API interface of an affected system. An attacker could exploit this vulnerability by uploading a malicious file on the local file system. A successful exploit could allow the attacker to overwrite arbitrary files on the affected system and gain vmanage user privileges.
Operator check
Please adhere to CISA’s guidelines to assess exposure and mitigate risks associated with Cisco SD-WAN devices as outlines in CISA’s Emergency Directive 26-03 (URL listed below in Notes) and CISA’s “Hunt & Hardening Guidance for Cisco SD-WAN Devices (URL listed below in Notes). Adhere to the applicable BOD 22-01 guidance for cloud services or discontinue use of the product if mitigations are not available.
Read brief →
Apr 20, 2026
KEV
Known exploited
CVE-2026-20128
Cisco · Catalyst SD-WAN Manager
Cisco Catalyst SD-WAN Manager contains a storing passwords in a recoverable format vulnerability that allows an authenticated, local attacker to gain DCA user privileges by accessing a credential file for the DCA user on the filesystem as a low-privileged user.
Operator check
Please adhere to CISA’s guidelines to assess exposure and mitigate risks associated with Cisco SD-WAN devices as outlines in CISA’s Emergency Directive 26-03 (URL listed below in Notes) and CISA’s “Hunt & Hardening Guidance for Cisco SD-WAN Devices (URL listed below in Notes). Adhere to the applicable BOD 22-01 guidance for cloud services or discontinue use of the product if mitigations are not available.
Read brief →
Apr 20, 2026
KEV
Known exploited
CVE-2026-20133
Cisco · Catalyst SD-WAN Manager
Cisco Catalyst SD-WAN Manager contains an exposure of sensitive information to an unauthorized actor vulnerability that could allow remote attackers to view sensitive information on affected systems.
Operator check
Please adhere to CISA’s guidelines to assess exposure and mitigate risks associated with Cisco SD-WAN devices as outlines in CISA’s Emergency Directive 26-03 (URL listed below in Notes) and CISA’s “Hunt & Hardening Guidance for Cisco SD-WAN Devices (URL listed below in Notes). Adhere to the applicable BOD 22-01 guidance for cloud services or discontinue use of the product if mitigations are not available.
Read brief →
Apr 20, 2026
KEV
Known exploited
CVE-2024-27199
JetBrains · TeamCity
JetBrains TeamCity contains a relative path traversal vulnerability that could allow limited admin actions to be performed.
Operator check
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Read brief →
Apr 20, 2026
KEV
Known exploited
CVE-2025-2749
Kentico · Kentico Xperience
Kentico Xperience contains a path traversal vulnerability that could allow an authenticated user's Staging Sync Server to upload arbitrary data to path relative locations.
Operator check
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Read brief →
Apr 20, 2026
KEV
Known exploited
CVE-2023-27351
PaperCut · NG/MF
PaperCut NG/MF contains an improper authentication vulnerability that could allow remote attackers to bypass authentication on affected installations via the SecurityRequestFilter class.
Operator check
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Read brief →
Apr 20, 2026
KEV
Known exploited
CVE-2025-32975
Quest · KACE Systems Management Appliance (SMA)
Quest KACE Systems Management Appliance (SMA) contains an improper authentication vulnerability that could allow attackers to impersonate legitimate users without valid credentials.
Operator check
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Read brief →
Apr 20, 2026
KEV
Known exploited
CVE-2025-48700
Synacor · Zimbra Collaboration Suite (ZCS)
Synacor Zimbra Collaboration Suite (ZCS) contains a cross-site scripting vulnerability that could allow attackers to execute arbitrary JavaScript within the user's session, potentially leading to unauthorized access to sensitive information.
Operator check
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Read brief →
Apr 16, 2026
KEV
Known exploited
CVE-2026-34197
Apache · ActiveMQ
Apache ActiveMQ contains an improper input validation vulnerability that allows for code injection.
Operator check
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Read brief →
Apr 14, 2026
KEV
Known exploited
CVE-2009-0238
Microsoft · Office
Microsoft Office Excel contains a remote code execution vulnerability that could allow an attacker to take complete control of an affected system if a user opens a specially crafted Excel file that includes a malformed object.
Operator check
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Read brief →
Apr 14, 2026
KEV
Known exploited
CVE-2026-32201
Microsoft · SharePoint Server
Microsoft SharePoint Server contains an improper input validation vulnerability that allows an unauthorized attacker to perform spoofing over a network.
Operator check
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Read brief →
Apr 13, 2026
KEV
Known exploited
CVE-2020-9715
Adobe · Acrobat
Adobe Acrobat contains a use-after-free vulnerability that allows for code execution
Operator check
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Read brief →
Apr 13, 2026
KEV
Known exploited
CVE-2026-34621
Adobe · Acrobat and Reader
Adobe Acrobat and Reader contain a prototype pollution vulnerability that allows for arbitrary code execution.
Operator check
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Read brief →
Apr 13, 2026
KEV
Known exploited
CVE-2026-21643
Fortinet · FortiClient EMS
Fortinet FortiClient EMS contains a SQL injection vulnerability that may allow an unauthenticated attacker to execute unauthorized code or commands via specifically crafted HTTP requests.
Operator check
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Read brief →
Apr 13, 2026
KEV
Known exploited
CVE-2012-1854
Microsoft · Visual Basic for Applications (VBA)
Microsoft Visual Basic for Applications (VBA) contains an insecure library loading vulnerability that could allow for remote code execution.
Operator check
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Read brief →
Apr 13, 2026
KEV
Known exploited
CVE-2023-21529
Microsoft · Exchange Server
Microsoft Exchange Server contains a deserialization of untrusted data that allows an authenticated attacker to achieve remote code execution.
Operator check
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Read brief →
Apr 13, 2026
KEV
Known exploited
CVE-2023-36424
Microsoft · Windows
Microsoft Windows Common Log File System Driver contains an out-of-bounds read vulnerability that could allow a threat actor for privileges escalation
Operator check
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Read brief →
Apr 13, 2026
KEV
Known exploited
CVE-2025-60710
Microsoft · Windows
Microsoft Windows contains a link following vulnerability that allows for privilege escalation
Operator check
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Read brief →
Apr 8, 2026
KEV
Known exploited
CVE-2026-1340
Ivanti · Endpoint Manager Mobile (EPMM)
Ivanti Endpoint Manager Mobile (EPMM) contains a code injection vulnerability that could allow attackers to achieve unauthenticated remote code execution.
Operator check
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Read brief →
Apr 6, 2026
KEV
Known exploited
CVE-2026-35616
Fortinet · FortiClient EMS
Fortinet FortiClient EMS contains an improper access control vulnerability that may allow an unauthenticated attacker to execute unauthorized code or commands via crafted requests.
Operator check
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Read brief →
Apr 2, 2026
KEV
Known exploited
CVE-2026-3502
TrueConf · Client
TrueConf Client contains a download of code without integrity check vulnerability. An attacker who is able to influence the update delivery path can substitute a tampered update payload. If the payload is executed or installed by the updater, this may result in arbitrary code execution in the context of the updating process or user.
Operator check
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Read brief →
Apr 1, 2026
KEV
Known exploited
CVE-2026-5281
Google · Dawn
Google Dawn contains an use-after-free vulnerability that could allow a remote attacker who had compromised the renderer process to execute arbitrary code via a crafted HTML page. This vulnerability could affect multiple Chromium-based products including, but not limited to, Google Chrome, Microsoft Edge, and Opera.
Operator check
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Read brief →
Mar 30, 2026
KEV
Known exploited
CVE-2026-3055
Citrix · NetScaler
Citrix NetScaler ADC (formerly Citrix ADC), NetScaler Gateway (formerly Citrix Gateway) and NetScaler ADC FIPS and NDcPP contain an out-of-bounds reads vulnerability when configured as a SAML IDP leading to memory overread.
Operator check
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Read brief →
Mar 27, 2026
KEV
Known exploited
CVE-2025-53521
F5 · BIG-IP
F5 BIG-IP APM contains a stack-based buffer overflow vulnerability that could allow a threat actor to achieve remote code execution.
Operator check
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Read brief →
Mar 26, 2026
KEV
Known exploited
CVE-2026-33634
Aquasecurity · Trivy
Aquasecurity Trivy contains an embedded malicious code vulnerability that could allow an attacker to gain access to everything in the CI/CD environment, including all tokens, SSH keys, cloud credentials, database passwords, and any sensitive configuration in memory.
Operator check
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Read brief →
Mar 25, 2026
KEV
Known exploited
CVE-2026-33017
Langflow · Langflow
Langflow contains a code injection vulnerability that could allow building public flows without requiring authentication.
Operator check
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Read brief →
Mar 24, 2026
Vendor advisory
Critical vendor advisory
CVE-2026-33211
Linuxfoundation · Tekton Pipelines
Tekton Pipelines project provides k8s-style resources for declaring CI/CD-style pipelines. Starting in version 1.0.0 and prior to versions 1.0.1, 1.3.3, 1.6.1, 1.9.2, and 1.10.2, the Tekton Pipelines git resolver is vulnerable to path traversal via the `pathInRepo` parameter. A tenant with permission to create `ResolutionRequests` (e.g. by creating `TaskRuns` or `PipelineRuns` that use the git resolver) can read arbitrary files from the resolver pod's filesystem, including ServiceAccount tokens. The file contents are returned base64-encoded in `resolutionrequest.status.data`. Versions 1.0.1, 1
Operator check
Review CVE-2026-33211 in your asset inventory. Apply patches per vendor guidance and verify Tekton Pipelines is not exposed. CVSS score: 9.6.
Read brief →
Mar 24, 2026
Vendor advisory
Critical vendor advisory
CVE-2026-33854
Molotovcherry · Android-Imagemagick7
Out-of-bounds Write vulnerability in MolotovCherry Android-ImageMagick7.This issue affects Android-ImageMagick7: before 7.1.2-10.
Operator check
Review CVE-2026-33854 in your asset inventory. Apply patches per vendor guidance and verify Android-Imagemagick7 is not exposed. CVSS score: 8.8.
Read brief →
Mar 24, 2026
Vendor advisory
Critical vendor advisory
CVE-2026-4688
Mozilla · Firefox
Sandbox escape due to use-after-free in the Disability Access APIs component. This vulnerability was fixed in Firefox 149, Firefox ESR 140.9, Thunderbird 149, and Thunderbird 140.9.
Operator check
Review CVE-2026-4688 in your asset inventory. Apply patches per vendor guidance and verify Firefox is not exposed. CVSS score: 10.0.
Read brief →
Mar 24, 2026
Vendor advisory
Critical vendor advisory
CVE-2026-4689
Mozilla · Firefox
Sandbox escape due to incorrect boundary conditions, integer overflow in the XPCOM component. This vulnerability was fixed in Firefox 149, Firefox ESR 115.34, Firefox ESR 140.9, Thunderbird 149, and Thunderbird 140.9.
Operator check
Review CVE-2026-4689 in your asset inventory. Apply patches per vendor guidance and verify Firefox is not exposed. CVSS score: 10.0.
Read brief →
Mar 24, 2026
Vendor advisory
Critical vendor advisory
CVE-2026-4691
Mozilla · Firefox
Use-after-free in the CSS Parsing and Computation component. This vulnerability was fixed in Firefox 149, Firefox ESR 115.34, Firefox ESR 140.9, Thunderbird 149, and Thunderbird 140.9.
Operator check
Review CVE-2026-4691 in your asset inventory. Apply patches per vendor guidance and verify Firefox is not exposed. CVSS score: 9.8.
Read brief →
Mar 24, 2026
Vendor advisory
Critical vendor advisory
CVE-2026-4692
Mozilla · Firefox
Sandbox escape in the Responsive Design Mode component. This vulnerability was fixed in Firefox 149, Firefox ESR 115.34, Firefox ESR 140.9, Thunderbird 149, and Thunderbird 140.9.
Operator check
Review CVE-2026-4692 in your asset inventory. Apply patches per vendor guidance and verify Firefox is not exposed. CVSS score: 10.0.
Read brief →
Mar 24, 2026
Vendor advisory
Critical vendor advisory
CVE-2026-4696
Mozilla · Firefox
Use-after-free in the Layout: Text and Fonts component. This vulnerability was fixed in Firefox 149, Firefox ESR 115.34, Firefox ESR 140.9, Thunderbird 149, and Thunderbird 140.9.
Operator check
Review CVE-2026-4696 in your asset inventory. Apply patches per vendor guidance and verify Firefox is not exposed. CVSS score: 9.8.
Read brief →
Mar 24, 2026
Vendor advisory
Critical vendor advisory
CVE-2026-4698
Mozilla · Firefox
JIT miscompilation in the JavaScript Engine: JIT component. This vulnerability was fixed in Firefox 149, Firefox ESR 115.34, Firefox ESR 140.9, Thunderbird 149, and Thunderbird 140.9.
Operator check
Review CVE-2026-4698 in your asset inventory. Apply patches per vendor guidance and verify Firefox is not exposed. CVSS score: 9.8.
Read brief →
Mar 24, 2026
Vendor advisory
Critical vendor advisory
CVE-2026-4700
Mozilla · Firefox
Mitigation bypass in the Networking: HTTP component. This vulnerability was fixed in Firefox 149, Firefox ESR 140.9, Thunderbird 149, and Thunderbird 140.9.
Operator check
Review CVE-2026-4700 in your asset inventory. Apply patches per vendor guidance and verify Firefox is not exposed. CVSS score: 9.8.
Read brief →
Mar 24, 2026
Vendor advisory
Critical vendor advisory
CVE-2026-4701
Mozilla · Firefox
Use-after-free in the JavaScript Engine component. This vulnerability was fixed in Firefox 149, Firefox ESR 140.9, Thunderbird 149, and Thunderbird 140.9.
Operator check
Review CVE-2026-4701 in your asset inventory. Apply patches per vendor guidance and verify Firefox is not exposed. CVSS score: 9.8.
Read brief →
Mar 24, 2026
Vendor advisory
Critical vendor advisory
CVE-2026-4702
Mozilla · Firefox
JIT miscompilation in the JavaScript Engine component. This vulnerability was fixed in Firefox 149, Firefox ESR 140.9, Thunderbird 149, and Thunderbird 140.9.
Operator check
Review CVE-2026-4702 in your asset inventory. Apply patches per vendor guidance and verify Firefox is not exposed. CVSS score: 9.8.
Read brief →
Mar 24, 2026
Vendor advisory
Critical vendor advisory
CVE-2026-4705
Mozilla · Firefox
Undefined behavior in the WebRTC: Signaling component. This vulnerability was fixed in Firefox 149, Firefox ESR 140.9, Thunderbird 149, and Thunderbird 140.9.
Operator check
Review CVE-2026-4705 in your asset inventory. Apply patches per vendor guidance and verify Firefox is not exposed. CVSS score: 9.8.
Read brief →
Mar 24, 2026
Vendor advisory
Critical vendor advisory
CVE-2026-33195
Rubyonrails · Rails
Active Storage allows users to attach cloud and local files in Rails applications. Prior to versions 8.1.2.1, 8.0.4.1, and 7.2.3.1, Active Storage's `DiskService#path_for` does not validate that the resolved filesystem path remains within the storage root directory. If a blob key containing path traversal sequences (e.g. `../`) is used, it could allow reading, writing, or deleting arbitrary files on the server. Blob keys are expected to be trusted strings, but some applications could be passing user input as keys and would be affected. Versions 8.1.2.1, 8.0.4.1, and 7.2.3.1 contain a patch.
Operator check
Review CVE-2026-33195 in your asset inventory. Apply patches per vendor guidance and verify Rails is not exposed. CVSS score: 9.8.
Read brief →
Mar 24, 2026
Vendor advisory
Critical vendor advisory
CVE-2026-33202
Rubyonrails · Rails
Active Storage allows users to attach cloud and local files in Rails applications. Prior to versions 8.1.2.1, 8.0.4.1, and 7.2.3.1, Active Storage's `DiskService#delete_prefixed` passes blob keys directly to `Dir.glob` without escaping glob metacharacters. If a blob key contains attacker-controlled input or custom-generated keys with glob metacharacters, it may be possible to delete unintended files from the storage directory. Versions 8.1.2.1, 8.0.4.1, and 7.2.3.1 contain a patch.
Operator check
Review CVE-2026-33202 in your asset inventory. Apply patches per vendor guidance and verify Rails is not exposed. CVSS score: 9.1.
Read brief →
Mar 23, 2026
Vendor advisory
Critical vendor advisory
CVE-2026-4579
Code-Projects · Simple Laundry System
A vulnerability was identified in code-projects Simple Laundry System 1.0. The issue affects /viewdetail.php in the Parameters Handler component. The manipulation of the argument serviceId leads to sql injection. Remote exploitation of the attack is possible. The exploit is publicly available and might be used.
Operator check
Review CVE-2026-4579 in your asset inventory. Apply patches per vendor guidance and verify Simple Laundry System is not exposed. CVSS score: 7.3.
Read brief →
Mar 23, 2026
Vendor advisory
Critical vendor advisory
CVE-2026-4580
Code-Projects · Simple Laundry System
A security flaw has been discovered in code-projects Simple Laundry System 1.0. The issue affects /checkupdatestatus.php in the Parameters Handler component. The manipulation of the argument serviceId results in sql injection. The attack can be executed remotely. The exploit has been released to the public and may be used for attacks.
Operator check
Review CVE-2026-4580 in your asset inventory. Apply patches per vendor guidance and verify Simple Laundry System is not exposed. CVSS score: 7.3.
Read brief →
Mar 23, 2026
Vendor advisory
Critical vendor advisory
CVE-2026-4581
Code-Projects · Simple Laundry System
A weakness has been identified in code-projects Simple Laundry System 1.0. The issue affects /checklogin.php in the Parameters Handler component. This manipulation of the argument Username causes sql injection. The attack is possible to be carried out remotely. The exploit has been made available to the public and could be used for attacks.
Operator check
Review CVE-2026-4581 in your asset inventory. Apply patches per vendor guidance and verify Simple Laundry System is not exposed. CVSS score: 7.3.
Read brief →
Mar 23, 2026
Vendor advisory
Critical vendor advisory
CVE-2026-4600
Jsrsasign Project · Jsrsasign
Versions of the package jsrsasign before 11.1.1 are vulnerable to Improper Verification of Cryptographic Signature via the DSA domain-parameter validation in KJUR.crypto.DSA.setPublic (and the related DSA/X509 verification flow in src/dsa-2.0.js). An attacker can forge DSA signatures or X.509 certificates that X509.verifySignature() accepts by supplying malicious domain parameters such as g=1, y=1, and a fixed r=1, which make the verification equation true for any hash.
Operator check
Review CVE-2026-4600 in your asset inventory. Apply patches per vendor guidance and verify Jsrsasign is not exposed. CVSS score: 7.4.
Read brief →
Mar 23, 2026
Vendor advisory
Critical vendor advisory
CVE-2026-4601
Jsrsasign Project · Jsrsasign
Versions of the package jsrsasign before 11.1.1 are vulnerable to Missing Cryptographic Step via the KJUR.crypto.DSA.signWithMessageHash process in the DSA signing implementation. An attacker can recover the private key by forcing r or s to be zero, so the library emits an invalid signature without retrying, and then solves for x from the resulting signature.
Operator check
Review CVE-2026-4601 in your asset inventory. Apply patches per vendor guidance and verify Jsrsasign is not exposed. CVSS score: 8.7.
Read brief →
Mar 23, 2026
Vendor advisory
Critical vendor advisory
CVE-2026-30849
Mantisbt · Mantisbt
Mantis Bug Tracker (MantisBT) is an open source issue tracker. Versions prior to 2.28.1 running on MySQL family databases are affected by an authentication bypass vulnerability in the SOAP API, as a result of an improper type checking on the password parameter. Other database backends are not affected, as they do not perform implicit type conversion from string to integer. Using a crafted SOAP envelope, an attacker knowing the victim's username is able to login to the SOAP API with their account without knowledge of the actual password, and execute any API function they have access to. Version
Operator check
Review CVE-2026-30849 in your asset inventory. Apply patches per vendor guidance and verify Mantisbt is not exposed. CVSS score: 9.8.
Read brief →
Mar 23, 2026
Vendor advisory
Critical vendor advisory
CVE-2026-31848
Nexxtsolutions · Nebula300Plus Firmware
Nexxt Solutions Nebula 300+ firmware through version 12.01.01.37 uses the ecos_pw cookie for authentication, which contains Base64-encoded credential data combined with a static suffix. Because the encoding is reversible and lacks integrity protection, an attacker can reconstruct or forge a valid cookie value without proper authentication. This allows unauthorized administrative access to protected endpoints.
Operator check
Review CVE-2026-31848 in your asset inventory. Apply patches per vendor guidance and verify Nebula300Plus Firmware is not exposed. CVSS score: 9.8.
Read brief →
Mar 23, 2026
Vendor advisory
Critical vendor advisory
CVE-2026-31851
Nexxtsolutions · Nebula300Plus Firmware
Nexxt Solutions Nebula 300+ firmware through version 12.01.01.37 does not implement rate limiting or account lockout mechanisms on authentication interfaces. An attacker can perform unlimited authentication attempts against endpoints that rely on credential validation, enabling brute-force attacks to guess administrative credentials without restriction.
Operator check
Review CVE-2026-31851 in your asset inventory. Apply patches per vendor guidance and verify Nebula300Plus Firmware is not exposed. CVSS score: 9.8.
Read brief →
Mar 23, 2026
Vendor advisory
Critical vendor advisory
CVE-2026-32913
Openclaw · Openclaw
OpenClaw before 2026.3.7 contains an improper header validation vulnerability in fetchWithSsrFGuard that forwards custom authorization headers across cross-origin redirects. Attackers can trigger redirects to different origins to intercept sensitive headers like X-Api-Key and Private-Token intended for the original destination.
Operator check
Review CVE-2026-32913 in your asset inventory. Apply patches per vendor guidance and verify Openclaw is not exposed. CVSS score: 9.3.
Read brief →
Mar 23, 2026
Vendor advisory
Critical vendor advisory
CVE-2026-33297
Wwbn · Avideo
WWBN AVideo is an open source video platform. Prior to version 26.0, the `setPassword.json.php` endpoint in the CustomizeUser plugin allows administrators to set a channel password for any user. Due to a logic error in how the submitted password value is processed, any password containing non-numeric characters is silently coerced to the integer zero before being stored. This means that regardless of the intended password, the stored channel password becomes 0, which any visitor can trivially guess to bypass channel-level access control. Version 26.0 contains a patch for the issue.
Operator check
Review CVE-2026-33297 in your asset inventory. Apply patches per vendor guidance and verify Avideo is not exposed. CVSS score: 9.1.
Read brief →
No briefs match this filter.