Live public feed

Vulnerability briefs ready for triage.

PatchBrief monitors CISA KEV, MSRC, NVD, GitHub Security Advisories, CERT/CC notes, Exploit-DB, and EPSS-enriched vulnerability signals.

1081 items
Aug 14, 2026 Vendor advisory High-risk advisory CVE-2026-53653

Grav: Unauthenticated denial of service via unbounded image derivative dimensions

Composer · getgrav/grav

Grav: Unauthenticated denial of service via unbounded image derivative dimensions

Operator check

Check whether getgrav/grav is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. CVSS score: 8.7. EPSS probability: 0.3%; percentile: 23%.

Read brief →
Aug 14, 2026 Vendor advisory High-risk advisory CVE-2026-35511

Authorizer: Zero-click account takeover via OAuth identity linking to unverified email accounts

Go · github.com/authorizerdev/authorizer

Authorizer: Zero-click account takeover via OAuth identity linking to unverified email accounts

Operator check

Check whether github.com/authorizerdev/authorizer is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. CVSS score: 8.7.

Read brief →
Aug 14, 2026 Vendor advisory High-risk advisory CVE-2026-53657

Lima: An arbitrary user in a QEMU VM could gain the root privilege in the VM via the guest agent socket

Go · github.com/lima-vm/lima/v2

Lima: An arbitrary user in a QEMU VM could gain the root privilege in the VM via the guest agent socket

Operator check

Check whether github.com/lima-vm/lima/v2 is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. EPSS probability: 0.1%; percentile: 3%.

Read brief →
Aug 14, 2026 Vendor advisory High-risk advisory CVE-2026-53660

OpenAM Insecure SSO Cookie Initialization

Maven · org.openidentityplatform.openam:openam-core

OpenAM Insecure SSO Cookie Initialization

Operator check

Check whether org.openidentityplatform.openam:openam-core is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. CVSS score: 7.0.

Read brief →
Aug 14, 2026 Vendor advisory High-risk advisory CVE-2026-55153

mchange-commons-java contains elements susceptible to abuse via JNDI injection and "deserialization gadgets"

Maven · com.mchange:mchange-commons-java

mchange-commons-java contains elements susceptible to abuse via JNDI injection and "deserialization gadgets"

Operator check

Check whether com.mchange:mchange-commons-java is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. EPSS probability: 0.3%; percentile: 26%.

Read brief →
Aug 14, 2026 Vendor advisory Critical vendor advisory CVE-2026-73678

MindsDB Minds Platform version 26.1.0 and earlier — CVE-2026-73678 (Critical)

MindsDB · Minds Platform version 26.1.0 and earlier

MindsDB Minds Platform version 26.1.0 and earlier contains an unauthenticated remote code execution vulnerability that allows unauthenticated attackers to execute arbitrary OS commands by submitting crafted prompts to the unprotected POST /api/v1/responses/ endpoint, which reaches the Anton agent's scratchpad tool that calls exec() on attacker-influenced Python source without sandboxing. Attackers can first configure their own LLM API key through the unauthenticated PUT /api/v1/settings/ endpoint, then POST a prompt directing the agent to invoke the scratchpad tool with arbitrary Python code,

Operator check

Review CVE-2026-73678 in your asset inventory. Apply patches per vendor guidance and verify Minds Platform version 26.1.0 and earlier is not exposed. CVSS score: 10.0.

Read brief →
Aug 14, 2026 Vendor advisory High-risk advisory CVE-2026-35219

Budibase: SSRF in Automation Steps - Webhook, Zapier, N8N, Slack, Discord Bypass IP Blacklist

npm · @budibase/server

Budibase: SSRF in Automation Steps - Webhook, Zapier, N8N, Slack, Discord Bypass IP Blacklist

Operator check

Check whether @budibase/server is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. CVSS score: 7.1.

Read brief →
Aug 14, 2026 Vendor advisory High-risk advisory CVE-2026-55157

Token Optimizer MCP: OS command injection in smart_user via username in get-user-info

npm · @ooples/token-optimizer-mcp

Token Optimizer MCP: OS command injection in smart_user via username in get-user-info

Operator check

Check whether @ooples/token-optimizer-mcp is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.

Read brief →
Aug 13, 2026 Vendor advisory High-risk advisory CVE-2026-55072

Pimcore: ClassDefinition UID regex missing end anchor allows SQL injection via Block.php unquoted table name

Composer · pimcore/pimcore

Pimcore: ClassDefinition UID regex missing end anchor allows SQL injection via Block.php unquoted table name

Operator check

Check whether pimcore/pimcore is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.

Read brief →
Aug 13, 2026 Vendor advisory Critical vendor advisory CVE-2026-73532

Fluent Forms Pro 6.2.7 — CVE-2026-73532 (Critical)

Fluent · Forms Pro 6.2.7

Fluent Forms Pro 6.2.7 contains an embedded malicious code vulnerability introduced via a tampered plugin build served through a decommissioned update server. The tampered build introduced a rogue PHP file (libs/class-license-sync.php), loaded via a require_once directive added to fluentformpro.php, that established a backdoor REST API endpoint, dropped persistent PHP files in mu-plugins and uploads directories, installed a passwordless administrator account, and registered scheduled tasks that survived plugin removal.

Operator check

Review CVE-2026-73532 in your asset inventory. Apply patches per vendor guidance and verify Forms Pro 6.2.7 is not exposed. CVSS score: 9.8.

Read brief →
Aug 13, 2026 Vendor advisory High-risk advisory CVE-2026-54526

Argo Workflows: ArtifactGC.PodSpecPatch bypasses Strict/Secure template reference allow-list (Incomplete fix for CVE-...

Go · github.com/argoproj/argo-workflows/v4

Argo Workflows: ArtifactGC.PodSpecPatch bypasses Strict/Secure template reference allow-list (Incomplete fix for CVE-2026-31892)

Operator check

Check whether github.com/argoproj/argo-workflows/v4 is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. CVSS score: 8.9. EPSS probability: 0.4%; percentile: 29%.

Read brief →
Aug 13, 2026 Vendor advisory Critical vendor advisory CVE-2026-73533

Ninja Tables Pro 5.2.11 — CVE-2026-73533 (Critical)

Ninja · Tables Pro 5.2.11

Ninja Tables Pro 5.2.11 contains an embedded malicious code vulnerability introduced via a tampered plugin build served through a decommissioned update server. The tampered build introduced a rogue PHP file (app/Library/updater/NinjaTableDataSync.php) that established a backdoor REST API endpoint, dropped persistent PHP files in mu-plugins and uploads directories, installed a passwordless administrator account, and registered scheduled tasks that survived plugin removal.

Operator check

Review CVE-2026-73533 in your asset inventory. Apply patches per vendor guidance and verify Tables Pro 5.2.11 is not exposed. CVSS score: 9.8.

Read brief →
Aug 13, 2026 Vendor advisory High-risk advisory CVE-2026-73654

Trigger.dev: Prototype pollution via run metadata operations → process-wide cross-tenant DoS

npm · @trigger.dev/core

Trigger.dev: Prototype pollution via run metadata operations → process-wide cross-tenant DoS

Operator check

Check whether @trigger.dev/core is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.

Read brief →
Aug 13, 2026 Vendor advisory High-risk advisory CVE-2026-12243

nltk: Arbitrary File Read via Path Traversal in nltk.data.load() through Percent-Encoded Sequences

PyPI · nltk

nltk: Arbitrary File Read via Path Traversal in nltk.data.load() through Percent-Encoded Sequences

Operator check

Check whether nltk is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. EPSS probability: 0.6%; percentile: 45%.

Read brief →
Aug 13, 2026 Vendor advisory High-risk advisory

atomic-agents-stack: Dashboard HTTP server path traversal allows arbitrary file read

PyPI · atomic-agents-stack

atomic-agents-stack: Dashboard HTTP server path traversal allows arbitrary file read

Operator check

Check whether atomic-agents-stack is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. CVSS score: 8.2.

Read brief →
Aug 12, 2026 Vendor advisory High-risk advisory CVE-2026-32257

Winter: Stored XSS through Brand Settings custom styles

Composer · winter/wn-backend-module

Winter: Stored XSS through Brand Settings custom styles

Operator check

Check whether winter/wn-backend-module is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.

Read brief →
Aug 12, 2026 Vendor advisory High-risk advisory CVE-2026-32258

Winter: Stored XSS through Editor Settings custom styles

Composer · winter/wn-backend-module

Winter: Stored XSS through Editor Settings custom styles

Operator check

Check whether winter/wn-backend-module is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.

Read brief →
Aug 12, 2026 Vendor advisory High-risk advisory CVE-2026-35445

Winter: Authenticated backend users can bypass Users controller permission checks

Composer · winter/wn-backend-module

Winter: Authenticated backend users can bypass Users controller permission checks

Operator check

Check whether winter/wn-backend-module is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. CVSS score: 7.1.

Read brief →
Aug 12, 2026 Vendor advisory High-risk advisory CVE-2026-54917

SeaweedFS: Path traversal in the S3 and Iceberg REST gateways allows cross-bucket access

Go · github.com/seaweedfs/seaweedfs

SeaweedFS: Path traversal in the S3 and Iceberg REST gateways allows cross-bucket access

Operator check

Check whether github.com/seaweedfs/seaweedfs is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. CVSS score: 7.8. EPSS probability: 0.4%; percentile: 31%.

Read brief →
Aug 12, 2026 Vendor advisory Critical vendor advisory CVE-2026-16860

Ibm I — CVE-2026-16860 (Critical)

Ibm · I

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to execute arbitrary code due to an uncontrolled search path element.

Operator check

Review CVE-2026-16860 in your asset inventory. Apply patches per vendor guidance and verify I is not exposed. CVSS score: 9.9. EPSS probability: 0.5%; percentile: 38%.

Read brief →
Aug 12, 2026 Vendor advisory Critical vendor advisory CVE-2026-17276

Ibm I — CVE-2026-17276 (Critical)

Ibm · I

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to escalate privileges due to improper authorization in the handling of high-authority threads.

Operator check

Review CVE-2026-17276 in your asset inventory. Apply patches per vendor guidance and verify I is not exposed. CVSS score: 9.6. EPSS probability: 0.2%; percentile: 16%.

Read brief →
Aug 12, 2026 Vendor advisory High-risk advisory CVE-2026-48798

SSH.NET: ScpClient Recursive Download Allows Arbitrary File Write via Server-Controlled SCP Filenames

NuGet · SSH.NET

SSH.NET: ScpClient Recursive Download Allows Arbitrary File Write via Server-Controlled SCP Filenames

Operator check

Check whether SSH.NET is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.

Read brief →
Aug 12, 2026 Vendor advisory High-risk advisory

SIPSorcery vulnerable to Denial of Service via out-of-bounds read in SCTP SACK chunk parsing

NuGet · SIPSorcery

SIPSorcery vulnerable to Denial of Service via out-of-bounds read in SCTP SACK chunk parsing

Operator check

Check whether SIPSorcery is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.

Read brief →
Aug 12, 2026 Vendor advisory High-risk advisory

SIPSorcery: Malformed UDP datagram crashes TurnServer receive loop with no restart, disabling TURN UDP relay for all ...

NuGet · SIPSorcery

SIPSorcery: Malformed UDP datagram crashes TurnServer receive loop with no restart, disabling TURN UDP relay for all clients (DoS)

Operator check

Check whether SIPSorcery is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.

Read brief →
Aug 12, 2026 Vendor advisory High-risk advisory CVE-2026-52776

compliance-trestle has an URLSecurityValidator SSRF allowlist bypass via IPv4-mapped IPv6 and 0.0.0.0

PyPI · compliance-trestle

compliance-trestle has an URLSecurityValidator SSRF allowlist bypass via IPv4-mapped IPv6 and 0.0.0.0

Operator check

Check whether compliance-trestle is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. CVSS score: 8.6.

Read brief →
Aug 12, 2026 Vendor advisory High-risk advisory CVE-2026-55071

MCP-for-Stata: Stata Command Injection via Unsanitized `package` in `ado_package_install`

PyPI · stata-mcp

MCP-for-Stata: Stata Command Injection via Unsanitized `package` in `ado_package_install`

Operator check

Check whether stata-mcp is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.

Read brief →
Aug 12, 2026 Vendor advisory High-risk advisory CVE-2026-55074

Ansible FreeBSD Jail Connection Plugin: Jail escape via symlink following in put_file (host-side root mv)

PyPI · ansible-jailexec

Ansible FreeBSD Jail Connection Plugin: Jail escape via symlink following in put_file (host-side root mv)

Operator check

Check whether ansible-jailexec is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. CVSS score: 7.3.

Read brief →
Aug 11, 2026 KEV Known exploited CVE-2026-20349

Cisco Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD) Heap Inspection Vuln...

Cisco · Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD)

Cisco Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD) contain a heap inspection vulnerability that could allow an unauthenticated, remote attacker to cause the device to reload unexpectedly, resulting in a denial of service (DoS) condition.

Operator check

Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

Read brief →
Aug 11, 2026 Vendor advisory High-risk advisory CVE-2026-73080

SeaweedFS: Unauthenticated SSRF with response read-back via VolumeServer.FetchAndWriteNeedle

Go · github.com/seaweedfs/seaweedfs

SeaweedFS: Unauthenticated SSRF with response read-back via VolumeServer.FetchAndWriteNeedle

Operator check

Check whether github.com/seaweedfs/seaweedfs is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.

Read brief →
Aug 11, 2026 KEV Known exploited CVE-2026-72898

Metabase SQL Injection Vulnerability

Metabase · Metabase

Metabase contains a SQL Injection vulnerability that allows an unauthenticated remote attacker to inject arbitrary SQL into the Metabase application database, which can give them administrator access to the instance. From there, the attacker could change the application configuration, steal stored credentials for the connected databases, read any data accessible through those connections, and export data.

Operator check

Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

Read brief →
Aug 11, 2026 Patch Tuesday High-risk advisory CVE-2026-49179

Windows Active Directory Domain Services Remote Code Execution Vulnerability

Microsoft · Windows Active Directory

Improper neutralization of special elements used in a command ('command injection') in Windows Active Directory allows an unauthorized attacker to execute code over a network. Published in August 2026 Security Updates. MSRC exploitability: Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation Unlikely.

Operator check

Review the Microsoft Security Update Guide entry for CVE-2026-49179. Confirm whether Windows Active Directory is deployed, then apply the current security update or documented mitigation. CVSS score: 8.8.

Read brief →
Aug 11, 2026 Patch Tuesday High-risk advisory CVE-2026-58650

Visual Studio Code Security Feature Bypass Vulnerability

Microsoft · Visual Studio Code

Authorization bypass through user-controlled key in Visual Studio Code allows an unauthorized attacker to bypass a security feature locally. Published in August 2026 Security Updates. MSRC exploitability: Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation More Likely.

Operator check

Review the Microsoft Security Update Guide entry for CVE-2026-58650. Confirm whether Visual Studio Code is deployed, then apply the current security update or documented mitigation. CVSS score: 7.8.

Read brief →
Aug 11, 2026 Patch Tuesday High-risk advisory CVE-2026-59113

Visual Studio Code Remote Code Execution Vulnerability

Microsoft · Visual Studio Code

Missing authorization in Visual Studio Code allows an unauthorized attacker to execute code over a network. Published in August 2026 Security Updates. MSRC exploitability: Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation Less Likely.

Operator check

Review the Microsoft Security Update Guide entry for CVE-2026-59113. Confirm whether Visual Studio Code is deployed, then apply the current security update or documented mitigation. CVSS score: 8.8.

Read brief →
Aug 11, 2026 Patch Tuesday Critical vendor advisory CVE-2026-59124

Microsoft High Performance Computing (HPC) Pack Remote Code Execution Vulnerability

Microsoft · Microsoft High Performance Computing (HPC) Pack

Deserialization of untrusted data in Microsoft High Performance Computing (HPC) Pack allows an unauthorized attacker to execute code over a network. Published in August 2026 Security Updates. MSRC exploitability: Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation More Likely.

Operator check

Review the Microsoft Security Update Guide entry for CVE-2026-59124. Confirm whether Microsoft High Performance Computing (HPC) Pack is deployed, then apply the current security update or documented mitigation. CVSS score: 9.8.

Read brief →
Aug 11, 2026 Patch Tuesday High-risk advisory CVE-2026-59132

Windows TCP/IP Denial of Service Vulnerability

Microsoft · Windows TCP/IP

Null pointer dereference in Windows TCP/IP allows an unauthorized attacker to deny service over a network. Published in August 2026 Security Updates. MSRC exploitability: Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation More Likely.

Operator check

Review the Microsoft Security Update Guide entry for CVE-2026-59132. Confirm whether Windows TCP/IP is deployed, then apply the current security update or documented mitigation. CVSS score: 7.5.

Read brief →
Aug 11, 2026 Patch Tuesday High-risk advisory CVE-2026-59133

Microsoft High Performance Computing (HPC) Pack Elevation of Privilege Vulnerability

Microsoft · Microsoft High Performance Computing (HPC) Pack

Execution with unnecessary privileges in Microsoft High Performance Computing (HPC) Pack allows an authorized attacker to elevate privileges over a network. Published in August 2026 Security Updates. MSRC exploitability: Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation More Likely.

Operator check

Review the Microsoft Security Update Guide entry for CVE-2026-59133. Confirm whether Microsoft High Performance Computing (HPC) Pack is deployed, then apply the current security update or documented mitigation. CVSS score: 8.8.

Read brief →
Aug 11, 2026 Patch Tuesday High-risk advisory CVE-2026-61348

Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability

Microsoft · Windows Ancillary Function Driver for WinSock

Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally. Published in August 2026 Security Updates. MSRC exploitability: Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation More Likely.

Operator check

Review the Microsoft Security Update Guide entry for CVE-2026-61348. Confirm whether Windows Ancillary Function Driver for WinSock is deployed, then apply the current security update or documented mitigation. CVSS score: 7.0.

Read brief →
Aug 11, 2026 Patch Tuesday High-risk advisory CVE-2026-61925

Windows Installer Elevation of Privilege Vulnerability

Microsoft · Windows Installer

Incorrect authorization in Windows Installer allows an authorized attacker to elevate privileges locally. Published in August 2026 Security Updates. MSRC exploitability: Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation More Likely.

Operator check

Review the Microsoft Security Update Guide entry for CVE-2026-61925. Confirm whether Windows Installer is deployed, then apply the current security update or documented mitigation. CVSS score: 7.8.

Read brief →
Aug 11, 2026 Patch Tuesday High-risk advisory CVE-2026-61930

Windows Kernel Elevation of Privilege Vulnerability

Microsoft · Windows Kernel

Heap-based buffer overflow in Windows Kernel allows an authorized attacker to elevate privileges locally. Published in August 2026 Security Updates. MSRC exploitability: Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation More Likely.

Operator check

Review the Microsoft Security Update Guide entry for CVE-2026-61930. Confirm whether Windows Kernel is deployed, then apply the current security update or documented mitigation. CVSS score: 7.8.

Read brief →
Aug 11, 2026 Patch Tuesday High-risk advisory CVE-2026-62688

Windows MIDI Service Module Elevation of Privileges Vulnerability

Microsoft · Windows MIDI Service Module

Heap-based buffer overflow in Windows MIDI Service Module allows an authorized attacker to elevate privileges locally. Published in August 2026 Security Updates. MSRC exploitability: Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation More Likely.

Operator check

Review the Microsoft Security Update Guide entry for CVE-2026-62688. Confirm whether Windows MIDI Service Module is deployed, then apply the current security update or documented mitigation. CVSS score: 7.8.

Read brief →
Aug 11, 2026 Patch Tuesday High-risk advisory CVE-2026-62696

Windows Program Compatibility Assistant Service Elevation of Privilege Vulnerability

Microsoft · Windows Program Compatibility Assistant Service

Integer underflow (wrap or wraparound) in Windows Program Compatibility Assistant Service allows an authorized attacker to elevate privileges locally. Published in August 2026 Security Updates. MSRC exploitability: Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation More Likely.

Operator check

Review the Microsoft Security Update Guide entry for CVE-2026-62696. Confirm whether Windows Program Compatibility Assistant Service is deployed, then apply the current security update or documented mitigation. CVSS score: 7.8.

Read brief →
Aug 11, 2026 Patch Tuesday High-risk advisory CVE-2026-62712

Windows Win32k Elevation of Privilege Vulnerability

Microsoft · Windows Win32K

Heap-based buffer overflow in Windows Win32K allows an authorized attacker to elevate privileges locally. Published in August 2026 Security Updates. MSRC exploitability: Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation More Likely.

Operator check

Review the Microsoft Security Update Guide entry for CVE-2026-62712. Confirm whether Windows Win32K is deployed, then apply the current security update or documented mitigation. CVSS score: 7.8. EPSS probability: 0.4%; percentile: 32%.

Read brief →
Aug 11, 2026 Patch Tuesday High-risk advisory CVE-2026-62713

Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability

Microsoft · Windows Cloud Files Mini Filter Driver

Heap-based buffer overflow in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges locally. Published in August 2026 Security Updates. MSRC exploitability: Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation More Likely.

Operator check

Review the Microsoft Security Update Guide entry for CVE-2026-62713. Confirm whether Windows Cloud Files Mini Filter Driver is deployed, then apply the current security update or documented mitigation. CVSS score: 7.8.

Read brief →
Aug 11, 2026 Patch Tuesday High-risk advisory CVE-2026-62827

Microsoft SharePoint Server Elevation of Privilege Vulnerability

Microsoft · Microsoft Office SharePoint

Improper authentication in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a network. Published in August 2026 Security Updates. MSRC exploitability: Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation Less Likely.

Operator check

Review the Microsoft Security Update Guide entry for CVE-2026-62827. Confirm whether Microsoft Office SharePoint is deployed, then apply the current security update or documented mitigation. CVSS score: 8.8.

Read brief →
Aug 11, 2026 Patch Tuesday Critical vendor advisory CVE-2026-62873

Microsoft 365 Admin Center Elevation of Privilege Vulnerability

Microsoft · Microsoft 365 Admin Center

Improper verification of cryptographic signature in Microsoft 365 Admin Center allows an unauthorized attacker to elevate privileges over a network. Published in August 2026 Security Updates. MSRC exploitability: Publicly Disclosed:No;Exploited:No;Latest Software Release:N/A.

Operator check

Review the Microsoft Security Update Guide entry for CVE-2026-62873. Confirm whether Microsoft 365 Admin Center is deployed, then apply the current security update or documented mitigation. CVSS score: 9.8. EPSS probability: 0.3%; percentile: 27%.

Read brief →
Aug 11, 2026 Patch Tuesday Critical vendor advisory CVE-2026-63508

Microsoft Planetary Computer Pro Elevation of Privilege Vulnerability

Microsoft · Microsoft Planetary Computer Pro

Missing authentication for critical function in Microsoft Planetary Computer Pro allows an unauthorized attacker to elevate privileges over a network. Published in August 2026 Security Updates. MSRC exploitability: Publicly Disclosed:No;Exploited:No;Latest Software Release:N/A.

Operator check

Review the Microsoft Security Update Guide entry for CVE-2026-63508. Confirm whether Microsoft Planetary Computer Pro is deployed, then apply the current security update or documented mitigation. CVSS score: 10.0. EPSS probability: 0.4%; percentile: 36%.

Read brief →
Aug 11, 2026 Patch Tuesday High-risk advisory CVE-2026-63514

Microsoft SharePoint Server Remote Code Execution Vulnerability

Microsoft · Microsoft Office SharePoint

Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. Published in August 2026 Security Updates. MSRC exploitability: Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation Less Likely.

Operator check

Review the Microsoft Security Update Guide entry for CVE-2026-63514. Confirm whether Microsoft Office SharePoint is deployed, then apply the current security update or documented mitigation. CVSS score: 8.8.

Read brief →
Aug 11, 2026 Patch Tuesday High-risk advisory CVE-2026-63520

Microsoft SharePoint Server Remote Code Execution Vulnerability

Microsoft · Microsoft Office SharePoint

Improper input validation in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network. Published in August 2026 Security Updates. MSRC exploitability: Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation More Likely.

Operator check

Review the Microsoft Security Update Guide entry for CVE-2026-63520. Confirm whether Microsoft Office SharePoint is deployed, then apply the current security update or documented mitigation. CVSS score: 8.1.

Read brief →
Aug 11, 2026 Patch Tuesday High-risk advisory CVE-2026-65768

Microsoft Teams Remote Code Execution Vulnerability

Microsoft · Microsoft Teams for Android

Improper limitation of a pathname to a restricted directory ('path traversal') in Microsoft Teams for Android allows an unauthorized attacker to execute code over a network. Published in August 2026 Security Updates. MSRC exploitability: Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation Less Likely.

Operator check

Review the Microsoft Security Update Guide entry for CVE-2026-65768. Confirm whether Microsoft Teams for Android is deployed, then apply the current security update or documented mitigation. CVSS score: 8.8.

Read brief →
Aug 11, 2026 KEV Known exploited CVE-2026-68820

Microsoft Windows Ancillary Function Driver for WinSock Use-After-Free Vulnerability

Microsoft · Windows Ancillary Function Driver for WinSock

Microsoft Windows Ancillary Function Driver for WinSock contains a use-after-free vulnerability that allows an authorized attacker to elevate privileges locally.

Operator check

Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

Read brief →
Aug 11, 2026 Vendor advisory High-risk advisory CVE-2026-62871

Microsoft Security Advisory CVE-2026-62871 – .NET Elevation of Privilege Vulnerability

NuGet · Microsoft.WindowsDesktop.App.Runtime.win-arm64

Microsoft Security Advisory CVE-2026-62871 – .NET Elevation of Privilege Vulnerability

Operator check

Check whether Microsoft.WindowsDesktop.App.Runtime.win-arm64 is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.

Read brief →
Aug 11, 2026 Vendor advisory High-risk advisory CVE-2026-62886

Microsoft Security Advisory CVE-2026-62886 – .NET Elevation of Privilege Vulnerability

NuGet · Microsoft.WindowsDesktop.App.Runtime.win-arm64

Microsoft Security Advisory CVE-2026-62886 – .NET Elevation of Privilege Vulnerability

Operator check

Check whether Microsoft.WindowsDesktop.App.Runtime.win-arm64 is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.

Read brief →
Aug 11, 2026 Vendor advisory High-risk advisory CVE-2026-62897

Microsoft Security Advisory CVE-2026-62897 – .NET Remote Code Execution Vulnerability

NuGet · Microsoft.WindowsDesktop.App.Runtime.win-arm64

Microsoft Security Advisory CVE-2026-62897 – .NET Remote Code Execution Vulnerability

Operator check

Check whether Microsoft.WindowsDesktop.App.Runtime.win-arm64 is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.

Read brief →
Aug 11, 2026 Vendor advisory High-risk advisory CVE-2026-62898

Microsoft Security Advisory CVE-2026-62898 – .NET Information Disclosure Vulnerability

NuGet · Microsoft.NETCore.App.Runtime.win-arm64

Microsoft Security Advisory CVE-2026-62898 – .NET Information Disclosure Vulnerability

Operator check

Check whether Microsoft.NETCore.App.Runtime.win-arm64 is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.

Read brief →
Aug 11, 2026 Vendor advisory High-risk advisory CVE-2026-62901

Microsoft Security Advisory CVE-2026-62901 – .NET Denial of Service Vulnerability

NuGet · Microsoft.NETCore.App.Runtime.win-arm64

Microsoft Security Advisory CVE-2026-62901 – .NET Denial of Service Vulnerability

Operator check

Check whether Microsoft.NETCore.App.Runtime.win-arm64 is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.

Read brief →
Aug 11, 2026 Vendor advisory High-risk advisory CVE-2026-70354

Microsoft Security Advisory CVE-2026-70354 – .NET Core Remote Code Execution Vulnerability

NuGet · Microsoft.WindowsDesktop.App.Runtime.win-arm64

Microsoft Security Advisory CVE-2026-70354 – .NET Core Remote Code Execution Vulnerability

Operator check

Check whether Microsoft.WindowsDesktop.App.Runtime.win-arm64 is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.

Read brief →
Aug 11, 2026 Coordinated disclosure Patch review

VU#431093: TCG TPM 2.0 reference code found vulnerable to information leakage and timing side-channel attacks

TCG · TPM 2.0 reference code

Overview Two vulnerabilities have been identified in the Trusted Platform Module (TPM) 2.0 reference implementation: CVE-2026-6726 – Information leakage via falsified TPM keys. CVE-2026-6727 – A timing side-channel vulnerability in RSA OAEP decryption. An attacker with privileged access to a TPM command interface may be able to exploit these vulnerabilities by sending specially crafted TPM commands. Successful exploitation could allow the attacker to decrypt ciphertexts encrypted to affected TPM-managed RSA keys, including the RSA Endorsement Key (EK), or obtain credentials for falsified TPM keys, enabling forged TPM 2.0 attestations. These vulnerabilities are also documented by the Trusted Computing Group (TCG) in advisories - TCGVRT010 and TCGVRT0011 : Description Trusted Platform Module (TPM) technology provides hardware-backed... Related CVEs: CVE-2026-6726, CVE-2026-6727.

Operator check

Review the CERT/CC Vulnerability Note and compare the affected vendor and product list against your inventory. Apply vendor fixes or compensating controls for TPM 2.0 reference code where available.

Read brief →
Aug 10, 2026 Coordinated disclosure Patch review

VU#614868: Opencart ecommerce platform contains directory traversal vulnerability

Opencart · ecommerce platform

Overview The OpenCart v4.2.0.0 extension installer contains a directory traversal vulnerability. The extension installation process extracts uploaded .zip files then uses the zip entry filenames as filesystem paths, without validating that the resolved path stays inside the intended directory. This vulnerability is tracked as CVE-2026-18412. Description OpenCart is a free, open‑source e‑commerce solution designed to help businesses build and manage online stores. OpenCart extensions are uploaded as zip files with .ocmod.zip extensions. Upon installation, the OpenCart v4.2.0.0 extension installer extracts these zip files, but does not validate that the extracted paths stay inside the intended extraction directory. An attacker can craft a malicious extension containing file path traversal sequences, such as ../ . With this vulnerability... Related CVEs: CVE-2026-18412.

Operator check

Review the CERT/CC Vulnerability Note and compare the affected vendor and product list against your inventory. Apply vendor fixes or compensating controls for ecommerce platform where available.

Read brief →
Aug 9, 2026 Vendor advisory Critical vendor advisory CVE-2026-71984

MSI Radix AXE6600 router firmware version v781521 — CVE-2026-71984 (Critical)

MSI · Radix AXE6600 router firmware version v781521

MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the urlfilter function that allows remote attackers to execute arbitrary commands on the affected device. Attackers can exploit the urlfilter function to inject malicious commands and obtain root privileges on the underlying system.

Operator check

Review CVE-2026-71984 in your asset inventory. Apply patches per vendor guidance and verify Radix AXE6600 router firmware version v781521 is not exposed. CVSS score: 9.8.

Read brief →
Aug 9, 2026 Vendor advisory Critical vendor advisory CVE-2026-71985

MSI Radix AXE6600 router firmware version v781521 — CVE-2026-71985 (Critical)

MSI · Radix AXE6600 router firmware version v781521

MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the accesscontrol function that allows remote attackers to execute arbitrary commands on the affected device. Attackers can exploit this vulnerability through the accesscontrol function to execute malicious commands and obtain root privileges on the underlying system.

Operator check

Review CVE-2026-71985 in your asset inventory. Apply patches per vendor guidance and verify Radix AXE6600 router firmware version v781521 is not exposed. CVSS score: 9.8.

Read brief →
Aug 9, 2026 Vendor advisory Critical vendor advisory CVE-2026-71986

MSI Radix AXE6600 router firmware version v781521 — CVE-2026-71986 (Critical)

MSI · Radix AXE6600 router firmware version v781521

MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the dmz function that allows remote attackers to execute arbitrary commands on the affected device. Attackers can exploit this vulnerability through the dmz function to execute malicious commands and obtain root privileges on the underlying system.

Operator check

Review CVE-2026-71986 in your asset inventory. Apply patches per vendor guidance and verify Radix AXE6600 router firmware version v781521 is not exposed. CVSS score: 9.8.

Read brief →
Aug 9, 2026 Vendor advisory Critical vendor advisory CVE-2026-71987

MSI Radix AXE6600 router firmware version v781521 — CVE-2026-71987 (Critical)

MSI · Radix AXE6600 router firmware version v781521

MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the alg function that allows remote attackers to execute arbitrary commands on the affected device. Attackers can exploit this vulnerability through the alg function to execute malicious commands and obtain root privileges on the underlying system.

Operator check

Review CVE-2026-71987 in your asset inventory. Apply patches per vendor guidance and verify Radix AXE6600 router firmware version v781521 is not exposed. CVSS score: 9.8.

Read brief →
Aug 9, 2026 Vendor advisory Critical vendor advisory CVE-2026-71988

MSI Radix AXE6600 router firmware version v781521 — CVE-2026-71988 (Critical)

MSI · Radix AXE6600 router firmware version v781521

MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the portFw function that allows remote attackers to execute arbitrary commands on the affected device. Attackers can exploit this vulnerability through the alg function to execute malicious commands and obtain root privileges on the underlying system.

Operator check

Review CVE-2026-71988 in your asset inventory. Apply patches per vendor guidance and verify Radix AXE6600 router firmware version v781521 is not exposed. CVSS score: 9.8.

Read brief →
Aug 9, 2026 Vendor advisory Critical vendor advisory CVE-2026-71989

MSI Radix AXE6600 router firmware version v781521 — CVE-2026-71989 (Critical)

MSI · Radix AXE6600 router firmware version v781521

MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the porTrigger function that allows remote attackers to execute arbitrary commands on the affected device. Attackers can exploit this vulnerability through the alg function to execute malicious commands and obtain root privileges on the underlying system.

Operator check

Review CVE-2026-71989 in your asset inventory. Apply patches per vendor guidance and verify Radix AXE6600 router firmware version v781521 is not exposed. CVSS score: 9.8.

Read brief →
Aug 9, 2026 Vendor advisory Critical vendor advisory CVE-2026-71990

MSI Radix AXE6600 router firmware version v781521 — CVE-2026-71990 (Critical)

MSI · Radix AXE6600 router firmware version v781521

MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the TelnetSSH function used for SSH configuration that allows remote attackers to execute arbitrary commands on the affected device. Attackers can exploit this vulnerability through the SSH configuration interface to inject malicious commands and obtain root privileges on the underlying system.

Operator check

Review CVE-2026-71990 in your asset inventory. Apply patches per vendor guidance and verify Radix AXE6600 router firmware version v781521 is not exposed. CVSS score: 9.8.

Read brief →
Aug 9, 2026 Vendor advisory Critical vendor advisory CVE-2026-71991

MSI Radix AXE6600 router firmware version v781521 — CVE-2026-71991 (Critical)

MSI · Radix AXE6600 router firmware version v781521

MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the TelnetSSH function used for Telnet configuration that allows remote attackers to execute arbitrary commands on the affected device. Attackers can exploit this vulnerability through the Telnet configuration interface to inject malicious commands and obtain root privileges on the underlying system.

Operator check

Review CVE-2026-71991 in your asset inventory. Apply patches per vendor guidance and verify Radix AXE6600 router firmware version v781521 is not exposed. CVSS score: 9.8.

Read brief →
Aug 9, 2026 Vendor advisory Critical vendor advisory CVE-2026-71992

MSI Radix AXE6600 router firmware version v781521 — CVE-2026-71992 (Critical)

MSI · Radix AXE6600 router firmware version v781521

MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the macfilter function that allows remote attackers to execute arbitrary commands on the affected device. Attackers can exploit the macfilter function to inject malicious commands and obtain root privileges on the underlying system.

Operator check

Review CVE-2026-71992 in your asset inventory. Apply patches per vendor guidance and verify Radix AXE6600 router firmware version v781521 is not exposed. CVSS score: 9.8.

Read brief →
Aug 9, 2026 Vendor advisory Critical vendor advisory CVE-2026-71993

MSI Radix AXE6600 router firmware version v781521 — CVE-2026-71993 (Critical)

MSI · Radix AXE6600 router firmware version v781521

MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the openvpn function that allows remote attackers to execute arbitrary commands on the affected device. Attackers can exploit the macfilter function to inject malicious commands and obtain root privileges on the underlying system.

Operator check

Review CVE-2026-71993 in your asset inventory. Apply patches per vendor guidance and verify Radix AXE6600 router firmware version v781521 is not exposed. CVSS score: 9.8.

Read brief →
Aug 8, 2026 Vendor advisory Critical vendor advisory CVE-2026-71944

D-Link DWR-M961 devices with hardware version C1 and firmware — CVE-2026-71944 (Critical)

D-Link · DWR-M961 devices with hardware version C1 and firmware

D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injection vulnerability in the /boafrm/formLtefotaUpgradeQuectel interface. A remote attacker can inject arbitrary malicious commands into the fota_url field, resulting in command execution with root privileges.

Operator check

Review CVE-2026-71944 in your asset inventory. Apply patches per vendor guidance and verify DWR-M961 devices with hardware version C1 and firmware is not exposed. CVSS score: 9.8.

Read brief →
Aug 8, 2026 Vendor advisory Critical vendor advisory CVE-2026-71956

D-Link DWR-M961 devices with hardware version C1 and software — CVE-2026-71956 (Critical)

D-Link · DWR-M961 devices with hardware version C1 and software

D-Link DWR-M961 devices with hardware version C1 and software version 1.1.2_C1_202602110044 contain a command injection vulnerability in the app.cgi interface. A remote attacker can inject arbitrary malicious commands into the netDig.ping.dst field, resulting in command execution with root privileges.

Operator check

Review CVE-2026-71956 in your asset inventory. Apply patches per vendor guidance and verify DWR-M961 devices with hardware version C1 and software is not exposed. CVSS score: 9.8.

Read brief →
Aug 8, 2026 Vendor advisory Critical vendor advisory CVE-2026-71957

D-Link DWR-M961 devices with hardware version C1 and software — CVE-2026-71957 (Critical)

D-Link · DWR-M961 devices with hardware version C1 and software

D-Link DWR-M961 devices with hardware version C1 and software version 1.1.2_C1_202602110044 contain a buffer overflow vulnerability in the app.cgi interface. A remote attacker can write an overly long string to the netAcc.addlist[].name field and execute arbitrary commands by crafting a specific payload, or cause the device to crash.

Operator check

Review CVE-2026-71957 in your asset inventory. Apply patches per vendor guidance and verify DWR-M961 devices with hardware version C1 and software is not exposed. CVSS score: 9.8.

Read brief →
Aug 8, 2026 Vendor advisory Critical vendor advisory CVE-2026-71958

D-Link DWR-M961 devices with hardware version C1 and software — CVE-2026-71958 (Critical)

D-Link · DWR-M961 devices with hardware version C1 and software

D-Link DWR-M961 devices with hardware version C1 and software version 1.1.2_C1_202602110044 contain a buffer overflow vulnerability in the quicksetup.cgi interface. A remote attacker can write overly long strings to the test4, ssid2, and username fields and execute arbitrary commands by crafting a specific payload, or cause the device to crash.

Operator check

Review CVE-2026-71958 in your asset inventory. Apply patches per vendor guidance and verify DWR-M961 devices with hardware version C1 and software is not exposed. CVSS score: 9.8.

Read brief →
Aug 8, 2026 Vendor advisory Critical vendor advisory CVE-2026-71983

MSI Radix AXE6600 router firmware version v781521 — CVE-2026-71983 (Critical)

MSI · Radix AXE6600 router firmware version v781521

MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the wps.cgi interface that allows remote attackers to execute arbitrary commands by injecting malicious input through the pin2g, pin5g, or pin6g parameters. Attackers can exploit these unsanitized parameters to execute arbitrary commands on the affected device and obtain root privileges.

Operator check

Review CVE-2026-71983 in your asset inventory. Apply patches per vendor guidance and verify Radix AXE6600 router firmware version v781521 is not exposed. CVSS score: 9.8.

Read brief →
Aug 7, 2026 Vendor advisory High-risk advisory CVE-2026-63221

CodeIgniter: SQL injection in Query Builder deleteBatch() when used with where() conditions

Composer · codeigniter4/framework

CodeIgniter: SQL injection in Query Builder deleteBatch() when used with where() conditions

Operator check

Check whether codeigniter4/framework is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. EPSS probability: 0.4%; percentile: 30%.

Read brief →
Aug 7, 2026 Vendor advisory High-risk advisory CVE-2026-63222

CodeIgniter: Path traversal in UploadedFile::move() when using client-provided filenames

Composer · codeigniter4/framework

CodeIgniter: Path traversal in UploadedFile::move() when using client-provided filenames

Operator check

Check whether codeigniter4/framework is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. EPSS probability: 0.4%; percentile: 37%.

Read brief →
Aug 7, 2026 Vendor advisory High-risk advisory CVE-2026-63223

CodeIgniter: Uploaded file extension validation bypass in `is_image` and `mime_in` rules

Composer · codeigniter4/framework

CodeIgniter: Uploaded file extension validation bypass in `is_image` and `mime_in` rules

Operator check

Check whether codeigniter4/framework is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. EPSS probability: 0.5%; percentile: 40%.

Read brief →
Aug 7, 2026 Vendor advisory Critical vendor advisory CVE-2026-56793

Dell Openmanage Server Administrator — CVE-2026-56793 (Critical)

Dell · Openmanage Server Administrator

Dell OpenManage Server Administrator, versions prior to 11.1.0.2, contains an Improper Authentication vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Unauthorized access.

Operator check

Review CVE-2026-56793 in your asset inventory. Apply patches per vendor guidance and verify Openmanage Server Administrator is not exposed. CVSS score: 7.7.

Read brief →
Aug 7, 2026 Coordinated disclosure Patch review

VU#987105: The nothings stb TrueType library, up to version 1.26, contains a heap buffer overflow vulnerability

GitHub · repository for updates and install the latest

Overview A heap buffer overflow vulnerability exists in the stb TrueType library created by nothings. Exploitation of this vulnerability can occur when handling malformed font data and may lead to both Denial of Service (DoS) and Information Disclosure. Description The nothings stb repository, versions 1.26 and earlier, contains a collection of single-file public domain and MIT-licensed libraries for C/C++ projects. CVE-2026-18497 A heap buffer overflow vulnerability exists in the stbtt_GetGlyphShape() function within the stb_truetype.h library when handling malformed TrueType Font (TTF) data. The issue occurs during glyph contour parsing. The function iterates based on the number of contour endpoints specified in endPtsOfContours , but does not validate that the points pointer remains within the bounds of the glyph data buffer. As a... Related CVEs: CVE-2026-18497.

Operator check

Review the CERT/CC Vulnerability Note and compare the affected vendor and product list against your inventory. Apply vendor fixes or compensating controls for repository for updates and install the latest where available.

Read brief →
Aug 7, 2026 Vendor advisory High-risk advisory CVE-2026-15895

jsii-diff: Command Injection via npm: package argument

npm · jsii-diff

jsii-diff: Command Injection via npm: package argument

Operator check

Check whether jsii-diff is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. CVSS score: 8.4. EPSS probability: 0.6%; percentile: 47%.

Read brief →
Aug 7, 2026 Vendor advisory High-risk advisory CVE-2026-71851

crypto-js: Insufficient Entropy in Cryptographic Secret Generation via Vulnerable CryptoJS Dependency Chain

npm · crypto-js

crypto-js: Insufficient Entropy in Cryptographic Secret Generation via Vulnerable CryptoJS Dependency Chain

Operator check

Check whether crypto-js is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.

Read brief →
Aug 7, 2026 KEV Known exploited CVE-2026-8037

Progress LoadMaster Command Injection Vulnerability

Progress · LoadMaster

Progress LoadMaster contains a command injection vulnerability that allows an un-authenticated attacker to execute arbitrary commands on the LoadMaster appliance by exploiting unsanitized input in multiple command endpoints.

Operator check

Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

Read brief →
Aug 7, 2026 Vendor advisory High-risk advisory CVE-2026-67422

pymdown-extensions: exponential-backtracking ReDoS in caret, tilde, betterem, and magiclink inline processors

PyPI · pymdown-extensions

pymdown-extensions: exponential-backtracking ReDoS in caret, tilde, betterem, and magiclink inline processors

Operator check

Check whether pymdown-extensions is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. EPSS probability: 0.6%; percentile: 45%.

Read brief →
Aug 7, 2026 Vendor advisory High-risk advisory

GitPython: Unguarded git read-tree option forwarding in IndexFile.from_tree/reset/merge_tree enables arbitrary file o...

PyPI · GitPython

GitPython: Unguarded git read-tree option forwarding in IndexFile.from_tree/reset/merge_tree enables arbitrary file overwrite

Operator check

Check whether GitPython is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.

Read brief →
Aug 7, 2026 Vendor advisory High-risk advisory

GitPython: Unguarded git option forwarding in Repo.init enables arbitrary command execution via --template clone hooks

PyPI · GitPython

GitPython: Unguarded git option forwarding in Repo.init enables arbitrary command execution via --template clone hooks

Operator check

Check whether GitPython is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.

Read brief →
Aug 7, 2026 Vendor advisory High-risk advisory

GitPython: Arbitrary Git Repository Creation Outside the Working Tree via Unvalidated .gitmodules Submodule Name in G...

PyPI · GitPython

GitPython: Arbitrary Git Repository Creation Outside the Working Tree via Unvalidated .gitmodules Submodule Name in GitPython

Operator check

Check whether GitPython is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.

Read brief →
Aug 7, 2026 Vendor advisory High-risk advisory

GitPython: git-config OPTION-name injection via =/#/whitespace bypasses name validator, enabling forged core.sshComma...

PyPI · GitPython

GitPython: git-config OPTION-name injection via =/#/whitespace bypasses name validator, enabling forged core.sshCommand/hooksPath (RCE)

Operator check

Check whether GitPython is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.

Read brief →
Aug 7, 2026 Vendor advisory High-risk advisory

GitPython: Unsafe git option guard bypass via split_single_char_options=False short-option token smuggling enables co...

PyPI · GitPython

GitPython: Unsafe git option guard bypass via split_single_char_options=False short-option token smuggling enables command execution

Operator check

Check whether GitPython is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.

Read brief →
Aug 6, 2026 Vendor advisory High-risk advisory CVE-2026-64665

Statamic: Account takeover via OAuth email matching without email-verification check

Composer · statamic/cms

Statamic: Account takeover via OAuth email matching without email-verification check

Operator check

Check whether statamic/cms is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.

Read brief →
Aug 6, 2026 Vendor advisory High-risk advisory CVE-2026-67434

PHP_CodeSniffer gitblame report command injection via crafted filename

Composer · squizlabs/php_codesniffer

PHP_CodeSniffer gitblame report command injection via crafted filename

Operator check

Check whether squizlabs/php_codesniffer is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. CVSS score: 7.3.

Read brief →
Aug 6, 2026 Vendor advisory High-risk advisory CVE-2026-71488

league/commonmark: Quadratic-time denial of service when parsing crafted Markdown

Composer · league/commonmark

league/commonmark: Quadratic-time denial of service when parsing crafted Markdown

Operator check

Check whether league/commonmark is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.

Read brief →
Aug 6, 2026 Vendor advisory High-risk advisory

Craft CMS: Arbitrary user password reset leading to administrator account takeover

Composer · craftcms/cms

Craft CMS: Arbitrary user password reset leading to administrator account takeover

Operator check

Check whether craftcms/cms is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.

Read brief →
Aug 6, 2026 Coordinated disclosure Patch review

VU#487613: Alinto SOGo v5.12.7 vulnerable to cross-site scripting via malformed ICS calendar invitations

Content · Security Policy (CSP) enforcement. When a calendar invite

Overview A cross-site scripting (XSS) vulnerability in Alinto SOGo v5.12.7 allows attackers to achieve remote code execution by embedding malicious SVG (Scalable Vector Graphics) objects in ICS (iCalendar) invitations. The vulnerability has been actively exploited in the wild, as confirmed by VirusTotal sightings. Description Alinto SOGo is an open-source webmail and groupware platform for email, calendars, contacts, and shared scheduling. It is primarily used by organizations seeking a self-hosted interface solution for existing mail infrastructure. CVE-2026-8496 The vulnerability exists in SOGo’s handling of ICS files, where the DESCRIPTION field is rendered without proper sanitization or Content Security Policy (CSP) enforcement. When a calendar invite contains an SVG payload, such as , with JavaScript event handlers, the browser... Related CVEs: CVE-2026-8496.

Operator check

Review the CERT/CC Vulnerability Note and compare the affected vendor and product list against your inventory. Apply vendor fixes or compensating controls for Security Policy (CSP) enforcement. When a calendar invite where available.

Read brief →
Aug 6, 2026 Vendor advisory Critical vendor advisory CVE-2026-54489

Dell Virtual Storage Integrator — CVE-2026-54489 (Critical)

Dell · Virtual Storage Integrator

Dell Virtual Storage Integrator for VMware vSphere Client, versions prior to 10.11.1.0, contain(s) a Sensitive Information Disclosure vulnerability. An unauthenticated remote attacker could potentially exploit this vulnerability, leading to information disclosure and session hijacking. This vulnerability is considered critical as it allows an unauthenticated attacker to obtain active session credentials and fully impersonate authenticated users, including administrators. Dell recommends customers to upgrade at the earliest opportunity.

Operator check

Review CVE-2026-54489 in your asset inventory. Apply patches per vendor guidance and verify Virtual Storage Integrator is not exposed. CVSS score: 9.1. EPSS probability: 0.4%; percentile: 32%.

Read brief →
Aug 6, 2026 Vendor advisory High-risk advisory CVE-2026-65600

Traefik: Authentication Bypass via Path Traversal in ReplacePathRegex Middleware

Go · github.com/traefik/traefik/v2

Traefik: Authentication Bypass via Path Traversal in ReplacePathRegex Middleware

Operator check

Check whether github.com/traefik/traefik/v2 is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. EPSS probability: 0.7%; percentile: 49%.

Read brief →
Aug 6, 2026 Vendor advisory High-risk advisory CVE-2026-67309

Traefik: Kubernetes Ingress NGINX RewriteTarget Path Traversal Allows Route-Level Authentication Bypass

Go · github.com/traefik/traefik/v3

Traefik: Kubernetes Ingress NGINX RewriteTarget Path Traversal Allows Route-Level Authentication Bypass

Operator check

Check whether github.com/traefik/traefik/v3 is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. CVSS score: 7.8. EPSS probability: 0.5%; percentile: 40%.

Read brief →
Aug 6, 2026 Vendor advisory High-risk advisory CVE-2026-71324

Traefik: Cross-user response poisoning via proxied CONNECT on Traefik's shared backend keep-alive pool

Go · github.com/traefik/traefik/v2

Traefik: Cross-user response poisoning via proxied CONNECT on Traefik's shared backend keep-alive pool

Operator check

Check whether github.com/traefik/traefik/v2 is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. CVSS score: 7.0.

Read brief →
Aug 6, 2026 Vendor advisory High-risk advisory CVE-2026-71327

Traefik: Gateway API route identity collision allows cross-namespace backend hijacking

Go · github.com/traefik/traefik/v3

Traefik: Gateway API route identity collision allows cross-namespace backend hijacking

Operator check

Check whether github.com/traefik/traefik/v3 is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.

Read brief →
Aug 6, 2026 Patch Tuesday Critical vendor advisory CVE-2026-34191

Apache Portable Runtime Utility: SQL Injection in apr_dbd_oracle

Microsoft · Mariner

Apache Portable Runtime Utility: SQL Injection in apr_dbd_oracle Published in August 2026 Early Security Updates.

Operator check

Review the Microsoft Security Update Guide entry for CVE-2026-34191. Confirm whether Mariner is deployed, then apply the current security update or documented mitigation. CVSS score: 9.1. EPSS probability: 0.4%; percentile: 29%.

Read brief →
Aug 6, 2026 Patch Tuesday High-risk advisory CVE-2026-49163

Application Insights Profiler Elevation of Privilege Vulnerability

Microsoft · Application Insights Profiler

Improper limitation of a pathname to a restricted directory ('path traversal') in Application Insights Profiler allows an authorized attacker to elevate privileges over a network. Published in August 2026 Early Security Updates. MSRC exploitability: Publicly Disclosed:No;Exploited:No.

Operator check

Review the Microsoft Security Update Guide entry for CVE-2026-49163. Confirm whether Application Insights Profiler is deployed, then apply the current security update or documented mitigation. CVSS score: 8.8. EPSS probability: 0.6%; percentile: 46%.

Read brief →
Aug 6, 2026 Patch Tuesday Critical vendor advisory CVE-2026-50481

Azure Active Directory Elevation of Privilege Vulnerability

Microsoft · Azure Active Directory

Modification of assumed-immutable data (maid) in Azure Active Directory allows an authorized attacker to elevate privileges over a network. Published in August 2026 Early Security Updates. MSRC exploitability: Publicly Disclosed:No;Exploited:No;Latest Software Release:N/A.

Operator check

Review the Microsoft Security Update Guide entry for CVE-2026-50481. Confirm whether Azure Active Directory is deployed, then apply the current security update or documented mitigation. CVSS score: 9.9. EPSS probability: 0.5%; percentile: 37%.

Read brief →
Aug 6, 2026 Patch Tuesday Critical vendor advisory CVE-2026-50515

Azure Service Bus Remote Code Execution Vulnerability

Microsoft · Azure Service Bus

Deserialization of untrusted data in Azure Service Bus allows an authorized attacker to execute code over a network. Published in August 2026 Early Security Updates. MSRC exploitability: Publicly Disclosed:No;Exploited:No;Latest Software Release:N/A.

Operator check

Review the Microsoft Security Update Guide entry for CVE-2026-50515. Confirm whether Azure Service Bus is deployed, then apply the current security update or documented mitigation. CVSS score: 9.9. EPSS probability: 0.9%; percentile: 57%.

Read brief →
Aug 6, 2026 Patch Tuesday Critical vendor advisory CVE-2026-50516

Microsoft Azure Kubernetes Service Elevation of Privilege Vulnerability

Microsoft · Microsoft Azure Kubernetes Service

Missing authentication for critical function in Microsoft Azure Kubernetes Service allows an unauthorized attacker to elevate privileges over a network. Published in August 2026 Early Security Updates. MSRC exploitability: Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation Less Likely.

Operator check

Review the Microsoft Security Update Guide entry for CVE-2026-50516. Confirm whether Microsoft Azure Kubernetes Service is deployed, then apply the current security update or documented mitigation. CVSS score: 9.4.

Read brief →
Aug 6, 2026 Patch Tuesday Critical vendor advisory CVE-2026-50540

Kata Containers: Config Path Annotation Arbitrary File Loading

Microsoft · Mariner

Kata Containers: Config Path Annotation Arbitrary File Loading Published in August 2026 Early Security Updates.

Operator check

Review the Microsoft Security Update Guide entry for CVE-2026-50540. Confirm whether Mariner is deployed, then apply the current security update or documented mitigation. CVSS score: 9.6. EPSS probability: 0.4%; percentile: 31%.

Read brief →
Aug 6, 2026 Patch Tuesday Critical vendor advisory CVE-2026-56161

Azure Logic Apps Information Disclosure Vulnerability

Microsoft · Azure Logic Apps

Improper access control in Azure Logic Apps allows an authorized attacker to disclose information over a network. Published in August 2026 Early Security Updates. MSRC exploitability: Publicly Disclosed:No;Exploited:No;Latest Software Release:N/A.

Operator check

Review the Microsoft Security Update Guide entry for CVE-2026-56161. Confirm whether Azure Logic Apps is deployed, then apply the current security update or documented mitigation. CVSS score: 9.6. EPSS probability: 0.4%; percentile: 32%.

Read brief →
Aug 6, 2026 Patch Tuesday Critical vendor advisory CVE-2026-56162

Azure SQL Database Elevation of Privilege Vulnerability

Microsoft · Azure SQL Database

Improper authentication in Azure SQL Database allows an unauthorized attacker to elevate privileges over a network. Published in August 2026 Early Security Updates. MSRC exploitability: Publicly Disclosed:No;Exploited:No;Latest Software Release:N/A.

Operator check

Review the Microsoft Security Update Guide entry for CVE-2026-56162. Confirm whether Azure SQL Database is deployed, then apply the current security update or documented mitigation. CVSS score: 10.0. EPSS probability: 0.5%; percentile: 40%.

Read brief →
Aug 6, 2026 Patch Tuesday Critical vendor advisory CVE-2026-59115

Microsoft Entra Provisioning Service Elevation of Privilege Vulnerability

Microsoft · Microsoft Entra Provisioning Service (SyncFabric)

'.../...//' in Microsoft Entra Provisioning Service (SyncFabric) allows an authorized attacker to elevate privileges over a network. Published in August 2026 Early Security Updates. MSRC exploitability: Publicly Disclosed:No;Exploited:No;Latest Software Release:N/A.

Operator check

Review the Microsoft Security Update Guide entry for CVE-2026-59115. Confirm whether Microsoft Entra Provisioning Service (SyncFabric) is deployed, then apply the current security update or documented mitigation. CVSS score: 9.9. EPSS probability: 0.6%; percentile: 47%.

Read brief →
Aug 6, 2026 Patch Tuesday Critical vendor advisory CVE-2026-59118

Microsoft Power Apps Elevation of Privilege Vulnerability

Microsoft · Microsoft Power Apps

Improper authorization in Microsoft Power Apps allows an unauthorized attacker to elevate privileges over a network. Published in August 2026 Early Security Updates. MSRC exploitability: Publicly Disclosed:No;Exploited:No;Latest Software Release:N/A.

Operator check

Review the Microsoft Security Update Guide entry for CVE-2026-59118. Confirm whether Microsoft Power Apps is deployed, then apply the current security update or documented mitigation. CVSS score: 9.3. EPSS probability: 0.4%; percentile: 33%.

Read brief →
Aug 6, 2026 Patch Tuesday Critical vendor advisory CVE-2026-62830

Azure SRE Agent Elevation of Privilege Vulnerability

Microsoft · Azure SRE Agent

Missing authorization in Azure SRE Agent allows an authorized attacker to elevate privileges over a network. Published in August 2026 Early Security Updates. MSRC exploitability: Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation Less Likely.

Operator check

Review the Microsoft Security Update Guide entry for CVE-2026-62830. Confirm whether Azure SRE Agent is deployed, then apply the current security update or documented mitigation. CVSS score: 9.9. EPSS probability: 0.4%; percentile: 35%.

Read brief →
Aug 6, 2026 Patch Tuesday High-risk advisory CVE-2026-62836

Azure SQL Managed Instance Elevation of Privilege Vulnerability

Microsoft · Azure SQL Managed Instance

Improper restriction of communication channel to intended endpoints in Azure SQL Managed Instance allows an unauthorized attacker to elevate privileges over a network. Published in August 2026 Early Security Updates. MSRC exploitability: Publicly Disclosed:No;Exploited:No;Latest Software Release:N/A.

Operator check

Review the Microsoft Security Update Guide entry for CVE-2026-62836. Confirm whether Azure SQL Managed Instance is deployed, then apply the current security update or documented mitigation. CVSS score: 8.7. EPSS probability: 0.4%; percentile: 29%.

Read brief →
Aug 6, 2026 Patch Tuesday High-risk advisory CVE-2026-62869

Azure Entra ID Spoofing Vulnerability

Microsoft · Azure Entra ID

Insufficient verification of data authenticity in Azure Entra ID allows an authorized attacker to perform spoofing over a network. Published in August 2026 Early Security Updates. MSRC exploitability: Publicly Disclosed:No;Exploited:No;Latest Software Release:N/A.

Operator check

Review the Microsoft Security Update Guide entry for CVE-2026-62869. Confirm whether Azure Entra ID is deployed, then apply the current security update or documented mitigation. CVSS score: 8.8.

Read brief →
Aug 6, 2026 Patch Tuesday Critical vendor advisory CVE-2026-62896

Microsoft Teams Elevation of Privilege Vulnerability

Microsoft · Microsoft Teams

Improper authentication in Microsoft Teams allows an authorized attacker to elevate privileges over a network. Published in August 2026 Early Security Updates. MSRC exploitability: Publicly Disclosed:No;Exploited:No;Latest Software Release:N/A.

Operator check

Review the Microsoft Security Update Guide entry for CVE-2026-62896. Confirm whether Microsoft Teams is deployed, then apply the current security update or documented mitigation. CVSS score: 9.6. EPSS probability: 0.4%; percentile: 32%.

Read brief →
Aug 6, 2026 Patch Tuesday High-risk advisory CVE-2026-62918

Microsoft Teams Spoofing Vulnerability

Microsoft · Microsoft Teams

Improper verification of cryptographic signature in Microsoft Teams allows an unauthorized attacker to perform spoofing over a network. Published in August 2026 Early Security Updates. MSRC exploitability: Publicly Disclosed:No;Exploited:No;Latest Software Release:N/A.

Operator check

Review the Microsoft Security Update Guide entry for CVE-2026-62918. Confirm whether Microsoft Teams is deployed, then apply the current security update or documented mitigation. CVSS score: 7.5. EPSS probability: 0.3%; percentile: 22%.

Read brief →
Aug 6, 2026 Patch Tuesday High-risk advisory CVE-2026-63522

Azure SQL Database Elevation of Privilege Vulnerability

Microsoft · Azure SQL Database

Incorrect permission assignment for critical resource in Azure SQL Database allows an authorized attacker to elevate privileges locally. Published in August 2026 Early Security Updates. MSRC exploitability: Publicly Disclosed:No;Exploited:No;Latest Software Release:N/A.

Operator check

Review the Microsoft Security Update Guide entry for CVE-2026-63522. Confirm whether Azure SQL Database is deployed, then apply the current security update or documented mitigation. CVSS score: 7.8.

Read brief →
Aug 6, 2026 Patch Tuesday Critical vendor advisory CVE-2026-64562

KVM: nVMX: Hide shadow VMCS right after VMCLEAR

Microsoft · Mariner

KVM: nVMX: Hide shadow VMCS right after VMCLEAR Published in August 2026 Early Security Updates.

Operator check

Review the Microsoft Security Update Guide entry for CVE-2026-64562. Confirm whether Mariner is deployed, then apply the current security update or documented mitigation. CVSS score: 9.8. EPSS probability: 0.2%; percentile: 5%.

Read brief →
Aug 6, 2026 Patch Tuesday Critical vendor advisory CVE-2026-64564

sctp: don't free the ASCONF's own transport in DEL-IP processing

Microsoft · Mariner

sctp: don't free the ASCONF's own transport in DEL-IP processing Published in August 2026 Early Security Updates.

Operator check

Review the Microsoft Security Update Guide entry for CVE-2026-64564. Confirm whether Mariner is deployed, then apply the current security update or documented mitigation. CVSS score: 9.8. EPSS probability: 0.2%; percentile: 8%.

Read brief →
Aug 6, 2026 Patch Tuesday Critical vendor advisory CVE-2026-64565

Input: ims-pcu - fix heap-buffer-overflow in ims_pcu_process_data()

Microsoft · Mariner

Input: ims-pcu - fix heap-buffer-overflow in ims_pcu_process_data() Published in August 2026 Early Security Updates.

Operator check

Review the Microsoft Security Update Guide entry for CVE-2026-64565. Confirm whether Mariner is deployed, then apply the current security update or documented mitigation. CVSS score: 9.8. EPSS probability: 0.2%; percentile: 7%.

Read brief →
Aug 6, 2026 Patch Tuesday Critical vendor advisory CVE-2026-64584

usb: gadget: f_midi: cancel pending IN work before freeing the midi object

Microsoft · Mariner

usb: gadget: f_midi: cancel pending IN work before freeing the midi object Published in August 2026 Early Security Updates.

Operator check

Review the Microsoft Security Update Guide entry for CVE-2026-64584. Confirm whether Mariner is deployed, then apply the current security update or documented mitigation. CVSS score: 9.8. EPSS probability: 0.2%; percentile: 5%.

Read brief →
Aug 6, 2026 Patch Tuesday Critical vendor advisory CVE-2026-64593

btrfs: do not trim a device which is not writeable

Microsoft · Mariner

btrfs: do not trim a device which is not writeable Published in August 2026 Early Security Updates.

Operator check

Review the Microsoft Security Update Guide entry for CVE-2026-64593. Confirm whether Mariner is deployed, then apply the current security update or documented mitigation. CVSS score: 9.8. EPSS probability: 0.2%; percentile: 6%.

Read brief →
Aug 6, 2026 Patch Tuesday Critical vendor advisory CVE-2026-64594

usb: gadget: f_fs: initialize reset_work at allocation time

Microsoft · Mariner

usb: gadget: f_fs: initialize reset_work at allocation time Published in August 2026 Early Security Updates.

Operator check

Review the Microsoft Security Update Guide entry for CVE-2026-64594. Confirm whether Mariner is deployed, then apply the current security update or documented mitigation. CVSS score: 9.8. EPSS probability: 0.2%; percentile: 6%.

Read brief →
Aug 6, 2026 Patch Tuesday Critical vendor advisory CVE-2026-65667

Microsoft Teams Elevation of Privilege Vulnerability

Microsoft · Microsoft Teams

Missing authorization in Microsoft Teams allows an unauthorized attacker to elevate privileges over a network. Published in August 2026 Early Security Updates. MSRC exploitability: Publicly Disclosed:No;Exploited:No;Latest Software Release:N/A.

Operator check

Review the Microsoft Security Update Guide entry for CVE-2026-65667. Confirm whether Microsoft Teams is deployed, then apply the current security update or documented mitigation. CVSS score: 10.0. EPSS probability: 0.5%; percentile: 37%.

Read brief →
Aug 6, 2026 Patch Tuesday High-risk advisory CVE-2026-65668

Microsoft Purview eDiscovery Elevation of Privilege Vulnerability

Microsoft · Microsoft Purview eDiscovery

Improper access control in Microsoft Purview eDiscovery allows an authorized attacker to elevate privileges over a network. Published in August 2026 Early Security Updates. MSRC exploitability: Publicly Disclosed:No;Exploited:No;Latest Software Release:N/A.

Operator check

Review the Microsoft Security Update Guide entry for CVE-2026-65668. Confirm whether Microsoft Purview eDiscovery is deployed, then apply the current security update or documented mitigation. CVSS score: 8.8. EPSS probability: 0.4%; percentile: 35%.

Read brief →
Aug 6, 2026 Patch Tuesday High-risk advisory CVE-2026-68480

x86/bugs: Make Safe-RET robust against interrupt injection

Microsoft · Mariner

x86/bugs: Make Safe-RET robust against interrupt injection Published in August 2026 Early Security Updates.

Operator check

Review the Microsoft Security Update Guide entry for CVE-2026-68480. Confirm whether Mariner is deployed, then apply the current security update or documented mitigation. CVSS score: 8.8. EPSS probability: 0.2%; percentile: 10%.

Read brief →
Aug 6, 2026 Patch Tuesday Critical vendor advisory CVE-2026-68823

Azure Confidential Ledger Remote Code Execution Vulnerability

Microsoft · Azure Confidential Ledger

Exposed dangerous method or function in Azure Confidential Ledger allows an authorized attacker to execute code over a network. Published in August 2026 Early Security Updates. MSRC exploitability: Publicly Disclosed:No;Exploited:No;Latest Software Release:N/A.

Operator check

Review the Microsoft Security Update Guide entry for CVE-2026-68823. Confirm whether Azure Confidential Ledger is deployed, then apply the current security update or documented mitigation. CVSS score: 9.1. EPSS probability: 0.5%; percentile: 41%.

Read brief →
Aug 6, 2026 Patch Tuesday Critical vendor advisory CVE-2026-70332

Microsoft Office SharePoint Spoofing Vulnerability

Microsoft · Microsoft Office SharePoint

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network. Published in August 2026 Early Security Updates. MSRC exploitability: Publicly Disclosed:No;Exploited:No;Latest Software Release:N/A.

Operator check

Review the Microsoft Security Update Guide entry for CVE-2026-70332. Confirm whether Microsoft Office SharePoint is deployed, then apply the current security update or documented mitigation. CVSS score: 9.6. EPSS probability: 0.4%; percentile: 36%.

Read brief →
Aug 6, 2026 Vendor advisory High-risk advisory CVE-2026-16633

PDF.js: Arbitrary JavaScript execution upon opening a malicious PDF

npm · pdfjs-dist

PDF.js: Arbitrary JavaScript execution upon opening a malicious PDF

Operator check

Check whether pdfjs-dist is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. CVSS score: 8.6.

Read brief →
Aug 6, 2026 Vendor advisory High-risk advisory

JS-YAML: Quadratic CPU consumption in !!omap resolution (3.x and 4.x) — CVE-2026-59870 fix not backported

npm · js-yaml

JS-YAML: Quadratic CPU consumption in !!omap resolution (3.x and 4.x) — CVE-2026-59870 fix not backported

Operator check

Check whether js-yaml is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.

Read brief →
Aug 6, 2026 Vendor advisory High-risk advisory

ngx-extended-pdf-viewer bundles a version of pdf.js vulnerable to CVE-2026-16633

npm · ngx-extended-pdf-viewer

ngx-extended-pdf-viewer bundles a version of pdf.js vulnerable to CVE-2026-16633

Operator check

Check whether ngx-extended-pdf-viewer is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. CVSS score: 8.6.

Read brief →
Aug 5, 2026 Vendor advisory High-risk advisory CVE-2026-54572

rclone: Unvalidated symlink target in local `--links` — arbitrary file write from an untrusted remote

Go · github.com/rclone/rclone

rclone: Unvalidated symlink target in local `--links` — arbitrary file write from an untrusted remote

Operator check

Check whether github.com/rclone/rclone is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. EPSS probability: 0.3%; percentile: 23%.

Read brief →
Aug 5, 2026 Vendor advisory High-risk advisory CVE-2026-59733

rclone `serve restic --private-repos` authorization bypass: `..` in the URL path lets an authenticated user read, ove...

Go · github.com/rclone/rclone

rclone `serve restic --private-repos` authorization bypass: `..` in the URL path lets an authenticated user read, overwrite and delete other users' repositories

Operator check

Check whether github.com/rclone/rclone is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. EPSS probability: 0.4%; percentile: 35%.

Read brief →
Aug 5, 2026 Vendor advisory High-risk advisory CVE-2026-71309

rclone: Incomplete path validation allows backend root escape in serve restic

Go · github.com/rclone/rclone

rclone: Incomplete path validation allows backend root escape in serve restic

Operator check

Check whether github.com/rclone/rclone is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. CVSS score: 8.6.

Read brief →
Aug 5, 2026 Vendor advisory High-risk advisory CVE-2026-71312

rclone: PowerShell Smart-Quote Filename Injection Enables SFTP Server-Side Command Execution

Go · github.com/rclone/rclone

rclone: PowerShell Smart-Quote Filename Injection Enables SFTP Server-Side Command Execution

Operator check

Check whether github.com/rclone/rclone is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.

Read brief →
Aug 5, 2026 KEV Known exploited CVE-2026-63077

JetBrains TeamCity Deserialization of Untrusted Data Vulnerability

JetBrains · TeamCity

JetBrains TeamCity contains a deserialization of untrusted data vulnerability that could allow unauthenticated remote code execution via the agent polling protocol.

Operator check

Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

Read brief →
Aug 5, 2026 Vendor advisory Critical vendor advisory CVE-2026-8470

Langflow Langflow — CVE-2026-8470 (Critical)

Langflow · Langflow

IBM Langflow OSS 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, and 1.0.0 through 1.10.3 use Python's non-cryptographic random module for generating Fernet encryption keys from user secrets under 32 characters. The deterministic Mersenne Twister PRNG produces identical keys for identical seeds, allowing attackers to reproduce encryption keys and decrypt stored API keys and authentication tokens.

Operator check

Review CVE-2026-8470 in your asset inventory. Apply patches per vendor guidance and verify Langflow is not exposed. CVSS score: 7.4. EPSS probability: 0.1%; percentile: 1%.

Read brief →
Aug 5, 2026 Vendor advisory Critical vendor advisory CVE-2026-9205

Langflow Langflow — CVE-2026-9205 (Critical)

Langflow · Langflow

IBM Langflow OSS contains a weak cryptographic key derivation vulnerability in the ensure_fernet_key() function.

Operator check

Review CVE-2026-9205 in your asset inventory. Apply patches per vendor guidance and verify Langflow is not exposed. CVSS score: 7.4. EPSS probability: 0.2%; percentile: 11%.

Read brief →
Aug 5, 2026 Vendor advisory High-risk advisory CVE-2026-70604

Electron: Custom protocol with supportFetchAPI but not corsEnabled allows cross-origin reads

npm · electron

Electron: Custom protocol with supportFetchAPI but not corsEnabled allows cross-origin reads

Operator check

Check whether electron is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.

Read brief →
Aug 5, 2026 Vendor advisory High-risk advisory CVE-2026-70608

Electron: Sandboxed iframe can bypass the allow-popups restriction via the OpenURL navigation path

npm · electron

Electron: Sandboxed iframe can bypass the allow-popups restriction via the OpenURL navigation path

Operator check

Check whether electron is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.

Read brief →
Aug 5, 2026 Vendor advisory High-risk advisory CVE-2026-71314

Nuxt: Unauthenticated out-of-memory crash via unbounded v-for expansion in island rendering

npm · nuxt

Nuxt: Unauthenticated out-of-memory crash via unbounded v-for expansion in island rendering

Operator check

Check whether nuxt is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.

Read brief →
Aug 5, 2026 Vendor advisory High-risk advisory CVE-2026-71315

Nuxt route rules silently dropped for mixed-case paths, bypassing appMiddleware auth gates (incomplete fix for CVE-20...

npm · nuxt

Nuxt route rules silently dropped for mixed-case paths, bypassing appMiddleware auth gates (incomplete fix for CVE-2026-53721)

Operator check

Check whether nuxt is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.

Read brief →
Aug 5, 2026 Vendor advisory High-risk advisory CVE-2026-71316

Nuxt runtime payload cache discloses another user's SSR data across users and to unauthenticated clients

npm · nuxt

Nuxt runtime payload cache discloses another user's SSR data across users and to unauthenticated clients

Operator check

Check whether nuxt is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.

Read brief →
Aug 5, 2026 Vendor advisory High-risk advisory CVE-2026-71319

Unauthenticated Nuxt DevTools RPC allows arbitrary command execution on the developer's host

npm · @nuxt/devtools

Unauthenticated Nuxt DevTools RPC allows arbitrary command execution on the developer's host

Operator check

Check whether @nuxt/devtools is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.

Read brief →
Aug 5, 2026 Vendor advisory High-risk advisory CVE-2026-71320

Nuxt: Server-Side Remote Code Execution via Runtime Template Injection in Nuxt Server Island Props

npm · nuxt

Nuxt: Server-Side Remote Code Execution via Runtime Template Injection in Nuxt Server Island Props

Operator check

Check whether nuxt is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.

Read brief →
Aug 5, 2026 Vendor advisory High-risk advisory CVE-2026-71321

Nuxt: Unauthenticated CPU exhaustion parsing and hashing the Nuxt island endpoint body before hash validation

npm · nuxt

Nuxt: Unauthenticated CPU exhaustion parsing and hashing the Nuxt island endpoint body before hash validation

Operator check

Check whether nuxt is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.

Read brief →
Aug 4, 2026 KEV Known exploited CVE-2026-34486

Apache Tomcat Missing Encryption of Sensitive Data Vulnerability

Apache · Tomcat

Apache Tomcat contains a missing encryption of sensitive data vulnerability that allows the bypass of the EncryptInterceptor.

Operator check

Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

Read brief →
Aug 4, 2026 KEV Known exploited CVE-2026-9198

IBM Langflow Code Injection Vulnerability

IBM · Langflow

Langflow contains a code injection vulnerability that allows unauthenticated attackers to achieve full remote code execution on default Langflow deployments.

Operator check

Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

Read brief →
Aug 4, 2026 Vendor advisory Critical vendor advisory CVE-2026-70552

MaxSite CMS 109.5 and earlier — CVE-2026-70552 (Critical)

MaxSite · CMS 109.5 and earlier

MaxSite CMS 109.5 and earlier contains an authentication bypass vulnerability in the AJAX dispatcher that allows unauthenticated attackers to access admin-gated endpoints by supplying any X-Requested-With header and requesting a base64-encoded path resolving to any *-ajax.php file in the codebase. Attackers can exploit this dispatcher bypass to reach privileged plugin endpoints without credentials, enabling actions such as manipulating poll states and vote counts, and amplifying the impact of any dangerous operation performed by admin-only ajax files across the plugin tree.

Operator check

Review CVE-2026-70552 in your asset inventory. Apply patches per vendor guidance and verify CMS 109.5 and earlier is not exposed. CVSS score: 9.8.

Read brief →
Aug 4, 2026 Vendor advisory Critical vendor advisory CVE-2026-70553

MaxSite CMS — CVE-2026-70553 (Critical)

MaxSite · CMS

MaxSite CMS contains a remote code execution vulnerability that allows unauthenticated attackers to inject arbitrary PHP code into the application configuration file by submitting crafted POST requests to the install endpoint after installation is complete. Attackers can supply a malicious db_dbprefix value containing a single quote to break out of a PHP string literal in application/config/database.php, appending attacker-controlled PHP statements that are executed by the web server on every subsequent request, resulting in persistent unauthenticated remote code execution as the web-server pr

Operator check

Review CVE-2026-70553 in your asset inventory. Apply patches per vendor guidance and verify CMS is not exposed. CVSS score: 9.8.

Read brief →
Aug 4, 2026 Vendor advisory Critical vendor advisory CVE-2026-70554

MaxSite CMS — CVE-2026-70554 (Critical)

MaxSite · CMS

MaxSite CMS contains a PHP object injection vulnerability that allows unauthenticated attackers to execute arbitrary code by passing attacker-controlled serialized data in the maxsite_comuser cookie directly to unserialize() without validation or class allowlisting. Attackers can craft a malicious serialized PHP object payload delivered in a single HTTP request to trigger magic methods during object graph reconstruction, enabling property-oriented programming attacks or remote code execution via available gadget chains such as those targeting SoapClient or Imagick extensions.

Operator check

Review CVE-2026-70554 in your asset inventory. Apply patches per vendor guidance and verify CMS is not exposed. CVSS score: 9.8.

Read brief →
Aug 4, 2026 KEV Known exploited CVE-2026-18556

N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability

N-able · N-central

N-able N-central contains an authentication bypass using an alternate path or channel that allows for authentication bypass.

Operator check

Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

Read brief →
Aug 4, 2026 Vendor advisory High-risk advisory CVE-2026-69252

Flowise: Missing authorization on `/api/v1/files` allows low-privileged API keys to list and delete files across work...

npm · flowise

Flowise: Missing authorization on `/api/v1/files` allows low-privileged API keys to list and delete files across workspaces within the same organization

Operator check

Check whether flowise is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. CVSS score: 7.2.

Read brief →
Aug 4, 2026 Vendor advisory Critical vendor advisory CVE-2026-69254

Flowise: RCE via NodeVM Sandbox Escape in executeJavaScriptCode() nodeVMOptions Override

npm · flowise

Flowise: RCE via NodeVM Sandbox Escape in executeJavaScriptCode() nodeVMOptions Override

Operator check

Check whether flowise is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. CVSS score: 9.4.

Read brief →
Aug 4, 2026 Vendor advisory Critical vendor advisory CVE-2026-69255

Flowise: CSV Agent Remote Code Execution via Pyodide Code Injection — Root Shell Verified

npm · flowise

Flowise: CSV Agent Remote Code Execution via Pyodide Code Injection — Root Shell Verified

Operator check

Check whether flowise is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. CVSS score: 9.2.

Read brief →
Aug 4, 2026 Vendor advisory Critical vendor advisory CVE-2026-69256

Flowise: Remote Code Execution Vulnerability in CSVAgent

npm · flowise-components

Flowise: Remote Code Execution Vulnerability in CSVAgent

Operator check

Check whether flowise-components is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. CVSS score: 9.4.

Read brief →
Aug 4, 2026 Vendor advisory High-risk advisory CVE-2026-69258

Flowise: Unauthenticated Property Injection into Flow Execution Context via Ungated `overrideConfig` Spread in Predic...

npm · flowise

Flowise: Unauthenticated Property Injection into Flow Execution Context via Ungated `overrideConfig` Spread in Prediction API

Operator check

Check whether flowise is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. CVSS score: 8.8.

Read brief →
Aug 4, 2026 Vendor advisory High-risk advisory CVE-2026-69262

Flowise: `DELETE /api/v1/chatflows/:id` does not validate resource type, allowing `agentflows:delete` and `chatflows:...

npm · flowise

Flowise: `DELETE /api/v1/chatflows/:id` does not validate resource type, allowing `agentflows:delete` and `chatflows:delete` to delete each other’s flow type

Operator check

Check whether flowise is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. CVSS score: 7.1.

Read brief →
Aug 4, 2026 Vendor advisory High-risk advisory CVE-2026-69263

Flowise: CVE-2025-8943 Patch Bypass: npm_config_yes bypasses MCP environment variable blocklist (Unauthenticated RCE)

npm · flowise

Flowise: CVE-2025-8943 Patch Bypass: npm_config_yes bypasses MCP environment variable blocklist (Unauthenticated RCE)

Operator check

Check whether flowise is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. CVSS score: 8.7.

Read brief →
Aug 4, 2026 Vendor advisory Critical vendor advisory CVE-2026-69264

Flowise: RCE via CSVAgent csvFile data URI base64 segment is interpolated into Python source without validation

npm · flowise

Flowise: RCE via CSVAgent csvFile data URI base64 segment is interpolated into Python source without validation

Operator check

Check whether flowise is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. CVSS score: 9.4.

Read brief →
Aug 4, 2026 Vendor advisory Critical vendor advisory CVE-2026-70470

Flowise: Pyodide validator Unicode homoglyph bypass leads to RCE

npm · flowise

Flowise: Pyodide validator Unicode homoglyph bypass leads to RCE

Operator check

Check whether flowise is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. CVSS score: 9.5.

Read brief →
Aug 4, 2026 Vendor advisory High-risk advisory CVE-2026-70471

Flowise: RBAC Bypass Leading to Unauthorized Workspace Variables Disclosure

npm · flowise

Flowise: RBAC Bypass Leading to Unauthorized Workspace Variables Disclosure

Operator check

Check whether flowise is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. CVSS score: 7.1.

Read brief →
Aug 4, 2026 Vendor advisory High-risk advisory CVE-2026-70472

Flowise: Cross-workspace credential IDOR in openai-assistants-vector-store

npm · flowise

Flowise: Cross-workspace credential IDOR in openai-assistants-vector-store

Operator check

Check whether flowise is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. CVSS score: 7.1.

Read brief →
Aug 4, 2026 Vendor advisory High-risk advisory CVE-2026-70473

Flowise: Information Disclosure in GET /api/v1/upsert-history returns the entire server-wide upsert history

npm · flowise

Flowise: Information Disclosure in GET /api/v1/upsert-history returns the entire server-wide upsert history

Operator check

Check whether flowise is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. CVSS score: 8.3.

Read brief →
Aug 4, 2026 Vendor advisory High-risk advisory CVE-2026-70476

Flowise: Broken Access Control in Stripe Subscription Endpoints Allows Cross-Tenant Billing Manipulation

npm · flowise

Flowise: Broken Access Control in Stripe Subscription Endpoints Allows Cross-Tenant Billing Manipulation

Operator check

Check whether flowise is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. CVSS score: 8.3.

Read brief →
Aug 4, 2026 Vendor advisory Critical vendor advisory CVE-2026-70477

Flowise: CSV Agent Prompt Injection Remote Code Execution Vulnerability

npm · flowise

Flowise: CSV Agent Prompt Injection Remote Code Execution Vulnerability

Operator check

Check whether flowise is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. CVSS score: 9.5.

Read brief →
Aug 4, 2026 Vendor advisory Critical vendor advisory CVE-2026-70478

Flowise: Unauthenticated OAuth2 token refresh endpoint returns access tokens — enables token theft for any connected ...

npm · flowise

Flowise: Unauthenticated OAuth2 token refresh endpoint returns access tokens — enables token theft for any connected service

Operator check

Check whether flowise is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. CVSS score: 9.2.

Read brief →
Aug 4, 2026 Vendor advisory High-risk advisory

Flowise: Authenticated arbitrary file write in the `S3 Directory` document loader via unsanitized S3 object keys

npm · flowise-components

Flowise: Authenticated arbitrary file write in the `S3 Directory` document loader via unsanitized S3 object keys

Operator check

Check whether flowise-components is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. CVSS score: 7.2.

Read brief →
Aug 4, 2026 Vendor advisory Critical vendor advisory CVE-2026-61515

Puwell IP Camera firmware — CVE-2026-61515 (Critical)

Puwell · IP Camera firmware

Puwell IP Camera firmware versions 2.x through 4.x contains an unauthenticated command injection vulnerability that allows remote attackers to execute arbitrary operating system commands by sending a crafted JSON payload to the DebugShell interface exposed on TCP port 34567. Attackers can exploit the lack of authentication and input sanitization in the binary protocol service to pass arbitrary commands directly to the underlying operating system, achieving root-level code execution and complete device compromise.

Operator check

Review CVE-2026-61515 in your asset inventory. Apply patches per vendor guidance and verify IP Camera firmware is not exposed. CVSS score: 9.8.

Read brief →
Aug 4, 2026 Vendor advisory High-risk advisory CVE-2026-70479

Open WebUI: SSRF into internal services via unvalidated sub-resource requests in the Playwright web loader

PyPI · open-webui

Open WebUI: SSRF into internal services via unvalidated sub-resource requests in the Playwright web loader

Operator check

Check whether open-webui is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.

Read brief →
Aug 4, 2026 Vendor advisory High-risk advisory CVE-2026-70482

Open WebUI: Account takeover via OAuth token exchange accepting tokens issued to any client

PyPI · open-webui

Open WebUI: Account takeover via OAuth token exchange accepting tokens issued to any client

Operator check

Check whether open-webui is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.

Read brief →
Aug 4, 2026 Vendor advisory High-risk advisory CVE-2026-70485

Open WebUI: Any authenticated user can reach internal services and cloud metadata via NAT64-encoded URLs

PyPI · open-webui

Open WebUI: Any authenticated user can reach internal services and cloud metadata via NAT64-encoded URLs

Operator check

Check whether open-webui is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.

Read brief →
Aug 4, 2026 Vendor advisory High-risk advisory CVE-2026-70486

Open WebUI: Same-origin XSS to account takeover via terminal file-preview iframe hardcoding allow-same-origin

PyPI · open-webui

Open WebUI: Same-origin XSS to account takeover via terminal file-preview iframe hardcoding allow-same-origin

Operator check

Check whether open-webui is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.

Read brief →
Aug 4, 2026 Vendor advisory High-risk advisory CVE-2026-70492

Open WebUI: Stored XSS via unescaped KaTeX render-error fallback in rendered messages

PyPI · open-webui

Open WebUI: Stored XSS via unescaped KaTeX render-error fallback in rendered messages

Operator check

Check whether open-webui is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.

Read brief →
Aug 4, 2026 Vendor advisory High-risk advisory CVE-2026-70494

Open WebUI: A folder write-collaborator can permanently delete the owner's chats by deleting a shared subfolder

PyPI · open-webui

Open WebUI: A folder write-collaborator can permanently delete the owner's chats by deleting a shared subfolder

Operator check

Check whether open-webui is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.

Read brief →
Aug 3, 2026 Vendor advisory Critical vendor advisory CVE-2026-68979

Apache Nifi — CVE-2026-68979 (Critical)

Apache · Nifi

Apache NiFI 1.10.0 through 2.10.0 provide a Parameter Context update REST API method that does not enforce authorization checking on components referencing Parameter values. Updating a Parameter Context can change parameter values that affect referencing components, but framework authorization was limited to read and write privileges on the Parameter Context itself. As a result of the missing authorization, an authenticated user authorized to modify a Parameter Context, but not authorized on referencing components, could alter Parameter values affecting those components. In deployments where a

Operator check

Review CVE-2026-68979 in your asset inventory. Apply patches per vendor guidance and verify Nifi is not exposed. CVSS score: 9.8. EPSS probability: 0.4%; percentile: 28%.

Read brief →
Aug 3, 2026 Vendor advisory Critical vendor advisory CVE-2026-68980

Apache Nifi — CVE-2026-68980 (Critical)

Apache · Nifi

Apache NiFi 2.0.0 through 2.10.0 support creating, reading, and deleting Assets associated with Parameter Contexts through the REST API. The framework authorizes asset deletion against the owning Parameter Context using the supplied Parameter Context Identifier and Asset Identifier. The framework performed authorized based on the supplied Parameter Context Identifier without verifying the requested Identifier against the stored Identifier. Apache NiFi installations that do not implement different levels of authorization across Parameter Contexts are not subject to this vulnerability, because t

Operator check

Review CVE-2026-68980 in your asset inventory. Apply patches per vendor guidance and verify Nifi is not exposed. CVSS score: 9.1. EPSS probability: 0.3%; percentile: 18%.

Read brief →
Aug 3, 2026 Vendor advisory Critical vendor advisory CVE-2026-41452

Krayin CRM 2.2.4 — CVE-2026-41452 (Critical)

Krayin · CRM 2.2.4

Krayin CRM 2.2.4 contains a missing authentication vulnerability in the installer middleware that allows unauthenticated remote attackers to overwrite the primary administrator account by sending a crafted HTTP POST request with the X-Requested-With: XMLHttpRequest header to bypass the CanInstall middleware redirect check. Attackers can supply arbitrary name, email, and password values to the admin-config-setup endpoint, which performs an unauthenticated updateOrInsert targeting the hardcoded administrator user ID, enabling full administrative access to all CRM data.

Operator check

Review CVE-2026-41452 in your asset inventory. Apply patches per vendor guidance and verify CRM 2.2.4 is not exposed. CVSS score: 9.8.

Read brief →
Aug 3, 2026 KEV Known exploited CVE-2026-18577

N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability

N-able · N-central

N-able N-central contains an authentication bypass using an alternate path or channel allows for authentication bypass and account takeover in N-central. This vulnerability is the result of an incomplete patch for CVE-2026-18556.

Operator check

Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

Read brief →
Aug 3, 2026 Vendor advisory High-risk advisory CVE-2026-13697

undici vulnerable to cross-user information disclosure and parse-time crash via degenerate private cache directives

npm · undici

undici vulnerable to cross-user information disclosure and parse-time crash via degenerate private cache directives

Operator check

Check whether undici is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. EPSS probability: 0.3%; percentile: 19%.

Read brief →
Aug 3, 2026 Vendor advisory High-risk advisory CVE-2026-18446

fast-uri vulnerable to host confusion via backslash authority introducer

npm · fast-uri

fast-uri vulnerable to host confusion via backslash authority introducer

Operator check

Check whether fast-uri is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. EPSS probability: 0.2%; percentile: 13%.

Read brief →
Aug 3, 2026 Vendor advisory High-risk advisory CVE-2026-68945

Angular: Cache-Key Ambiguity in HttpTransferCache Leading to Cross-Request Response Reuse and State Poisoning

npm · @angular/common

Angular: Cache-Key Ambiguity in HttpTransferCache Leading to Cross-Request Response Reuse and State Poisoning

Operator check

Check whether @angular/common is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. CVSS score: 8.8.

Read brief →
Aug 3, 2026 Vendor advisory High-risk advisory CVE-2026-69149

Angular SSR: Missing Fallback Raw-Content Serialization Escaping leads to Cross-Site Scripting (XSS)

npm · @angular/platform-server

Angular SSR: Missing Fallback Raw-Content Serialization Escaping leads to Cross-Site Scripting (XSS)

Operator check

Check whether @angular/platform-server is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. CVSS score: 8.6.

Read brief →
Aug 3, 2026 Vendor advisory High-risk advisory CVE-2026-69151

Angular i18n: Cross-Site Scripting (XSS) via event-handler attributes

npm · @angular/compiler

Angular i18n: Cross-Site Scripting (XSS) via event-handler attributes

Operator check

Check whether @angular/compiler is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. CVSS score: 7.6.

Read brief →
Aug 3, 2026 Vendor advisory High-risk advisory CVE-2026-69152

brace-expansion: DoS via unbounded intermediate arrays, bypassing the CVE-2026-14257 mitigation

npm · brace-expansion

brace-expansion: DoS via unbounded intermediate arrays, bypassing the CVE-2026-14257 mitigation

Operator check

Check whether brace-expansion is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.

Read brief →
Aug 3, 2026 Vendor advisory High-risk advisory CVE-2026-69192

ip-address: Address4 decodes leading-zero octets as decimal while resolvers decode them as octal, allowing SSRF and t...

npm · ip-address

ip-address: Address4 decodes leading-zero octets as decimal while resolvers decode them as octal, allowing SSRF and trust-boundary bypass

Operator check

Check whether ip-address is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. CVSS score: 7.7.

Read brief →
Aug 3, 2026 Vendor advisory High-risk advisory CVE-2026-69244

AIOHTTP: Out-of-bounds heap read in C HTTP response parser error path (malformed chunked response)

PyPI · aiohttp

AIOHTTP: Out-of-bounds heap read in C HTTP response parser error path (malformed chunked response)

Operator check

Check whether aiohttp is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. CVSS score: 7.1.

Read brief →
Aug 3, 2026 Vendor advisory High-risk advisory CVE-2026-69247

cryptography: PKCS#7 EnvelopedData decryption exposes a Bleichenbacher oracle through distinguishable errors and timing

PyPI · cryptography

cryptography: PKCS#7 EnvelopedData decryption exposes a Bleichenbacher oracle through distinguishable errors and timing

Operator check

Check whether cryptography is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. CVSS score: 8.2.

Read brief →
Aug 3, 2026 Vendor advisory High-risk advisory CVE-2026-69249

python-cryptography: Duplicate self-signed intermediates can cause exponential path-building

PyPI · cryptography

python-cryptography: Duplicate self-signed intermediates can cause exponential path-building

Operator check

Check whether cryptography is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. CVSS score: 8.7.

Read brief →
Aug 3, 2026 Vendor advisory High-risk advisory

GitPython: Unguarded git option forwarding in IndexFile.checkout() and TagReference.create() enables arbitrary file o...

PyPI · GitPython

GitPython: Unguarded git option forwarding in IndexFile.checkout() and TagReference.create() enables arbitrary file overwrite and arbitrary file read

Operator check

Check whether GitPython is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.

Read brief →
Jul 31, 2026 Vendor advisory High-risk advisory CVE-2026-53599

Redaxo has a Mediapool isAllowedExtension bypass via multi-segment filename that leads to authenticated RCE on Apache...

Composer · redaxo/source

Redaxo has a Mediapool isAllowedExtension bypass via multi-segment filename that leads to authenticated RCE on Apache mod_php multi-extension handlers

Operator check

Check whether redaxo/source is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.

Read brief →
Jul 31, 2026 Vendor advisory High-risk advisory CVE-2026-68500

Sylius Mollie Plugin vulnerable to payment status forgery via the payment webhook

Composer · sylius/mollie-plugin

Sylius Mollie Plugin vulnerable to payment status forgery via the payment webhook

Operator check

Check whether sylius/mollie-plugin is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. EPSS probability: 0.4%; percentile: 31%.

Read brief →
Jul 31, 2026 Vendor advisory High-risk advisory CVE-2026-52855

Wings exposes node configuration secrets through egg configuration-file templating

Go · github.com/pterodactyl/wings

Wings exposes node configuration secrets through egg configuration-file templating

Operator check

Check whether github.com/pterodactyl/wings is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.

Read brief →
Jul 31, 2026 Vendor advisory High-risk advisory CVE-2026-52856

Wings: Maliciously crafted packet during SFTP connection handshake causes denial of service

Go · github.com/pterodactyl/wings

Wings: Maliciously crafted packet during SFTP connection handshake causes denial of service

Operator check

Check whether github.com/pterodactyl/wings is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. EPSS probability: 0.3%; percentile: 26%.

Read brief →
Jul 31, 2026 Vendor advisory High-risk advisory CVE-2026-54725

vault-addr annotation SSRF -- webhook makes outbound HTTP call to attacker URL during admission; vault-serviceaccount...

Go · github.com/bank-vaults/vault-secrets-webhook

vault-addr annotation SSRF -- webhook makes outbound HTTP call to attacker URL during admission; vault-serviceaccount enables cluster-wide SA token theft via TokenRequest API

Operator check

Check whether github.com/bank-vaults/vault-secrets-webhook is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.

Read brief →
Jul 31, 2026 Vendor advisory High-risk advisory CVE-2026-54910

FileBrowser Quantum's path traversal issue in subtitle handler allows any authenticated user to read arbitrary files

Go · github.com/gtsteffaniak/filebrowser/backend

FileBrowser Quantum's path traversal issue in subtitle handler allows any authenticated user to read arbitrary files

Operator check

Check whether github.com/gtsteffaniak/filebrowser/backend is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. EPSS probability: 0.3%; percentile: 23%.

Read brief →
Jul 31, 2026 Vendor advisory High-risk advisory CVE-2026-41695

Spring Data: Unbounded property-path cache keyed by externally-supplied path string

Maven · org.springframework.data:spring-data-commons

Spring Data: Unbounded property-path cache keyed by externally-supplied path string

Operator check

Check whether org.springframework.data:spring-data-commons is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. EPSS probability: 0.4%; percentile: 29%.

Read brief →
Jul 31, 2026 Vendor advisory High-risk advisory CVE-2026-56819

Netty: HTTP/2 decompression leaks ByteBuf reference count when the decompressor channel is already closed (Direct mem...

Maven · io.netty:netty-codec-http2

Netty: HTTP/2 decompression leaks ByteBuf reference count when the decompressor channel is already closed (Direct memory leak / OOM DoS)

Operator check

Check whether io.netty:netty-codec-http2 is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. EPSS probability: 0.4%; percentile: 29%.

Read brief →
Jul 31, 2026 Coordinated disclosure Patch review

VU#243636: VPS.org one-click deployment templates contain multiple vulnerabilities

Multiple vendors · VPS.org one-click deployment templates contain multiple vulnerabilities

Overview VPS.org's one-click deployment templates provision services with default passwords and predefined network bindings instead of generating randomized secrets or applying per-deployment hardening measures. Description VPS.org is a cloud and virtual private server hosting provider that offers a library of templates for quickly provisioning common applications and services. Multiple vulnerabilities exist in the one-click deployment templates feature. These vulnerabilities stem from the same root cause: content is directly instantiated from static templates, using default passwords and static secrets with no deployment-specific randomization or interface-binding hardening at provisioning time. CVE-2026-16503 The Supabase template provides an instance of PostgreSQL that is bound to all network interfaces (0.0.0.0:5432) and uses the... Related CVEs: CVE-2026-16503, CVE-2026-16504.

Operator check

Review the CERT/CC Vulnerability Note and compare the affected vendor and product list against your inventory. Apply vendor fixes or compensating controls for VPS.org one-click deployment templates contain multiple vulnerabilities where available.

Read brief →
Jul 31, 2026 Vendor advisory High-risk advisory CVE-2026-52887

NocoBase: SQL injection in /api/myInAppChannels:list filter to PG-superuser RCE

npm · @nocobase/plugin-notification-in-app-message

NocoBase: SQL injection in /api/myInAppChannels:list filter to PG-superuser RCE

Operator check

Check whether @nocobase/plugin-notification-in-app-message is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. EPSS probability: 0.6%; percentile: 45%.

Read brief →
Jul 31, 2026 Vendor advisory High-risk advisory CVE-2026-53608

@apostrophecms/seo Vulnerable to Stored XSS via Unsanitized Google Analytics / GTM ID Injected into Script Tag

npm · @apostrophecms/seo

@apostrophecms/seo Vulnerable to Stored XSS via Unsanitized Google Analytics / GTM ID Injected into Script Tag

Operator check

Check whether @apostrophecms/seo is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. EPSS probability: 0.2%; percentile: 11%.

Read brief →
Jul 31, 2026 Vendor advisory High-risk advisory CVE-2026-53609

Apostrophe has Server-Side Prototype Pollution in apos.util.set via patch operators that leads to process-wide author...

npm · apostrophe

Apostrophe has Server-Side Prototype Pollution in apos.util.set via patch operators that leads to process-wide authorization bypass

Operator check

Check whether apostrophe is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. EPSS probability: 0.2%; percentile: 15%.

Read brief →
Jul 31, 2026 Vendor advisory High-risk advisory CVE-2026-54737

@phun-ky/defaults-deep Has a Prototype Pollution issue via Unsafe Recursive Property Merging

npm · @phun-ky/defaults-deep

@phun-ky/defaults-deep Has a Prototype Pollution issue via Unsafe Recursive Property Merging

Operator check

Check whether @phun-ky/defaults-deep is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.

Read brief →
Jul 31, 2026 Vendor advisory High-risk advisory CVE-2026-55100

hashi-vault-js has a path traversal and query parameter injection

npm · hashi-vault-js

hashi-vault-js has a path traversal and query parameter injection

Operator check

Check whether hashi-vault-js is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. CVSS score: 8.7.

Read brief →
Jul 31, 2026 Vendor advisory High-risk advisory CVE-2026-58263

Jodit Editor: Mutation XSS in jodit clean-html via a MathML/style rawtext carrier

npm · jodit

Jodit Editor: Mutation XSS in jodit clean-html via a MathML/style rawtext carrier

Operator check

Check whether jodit is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. EPSS probability: 0.2%; percentile: 8%.

Read brief →
Jul 31, 2026 Vendor advisory High-risk advisory

`@dynatrace-oss/dynatrace-mcp-server` has Unauthenticated HTTP MCP Tool Invocation

npm · @dynatrace-oss/dynatrace-mcp-server

`@dynatrace-oss/dynatrace-mcp-server` has Unauthenticated HTTP MCP Tool Invocation

Operator check

Check whether @dynatrace-oss/dynatrace-mcp-server is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.

Read brief →
Jul 31, 2026 Vendor advisory High-risk advisory CVE-2026-12061

Natural Language Toolkit (NLTK): ReDoS in NLTK ReviewsCorpusReader FEATURES regex

PyPI · nltk

Natural Language Toolkit (NLTK): ReDoS in NLTK ReviewsCorpusReader FEATURES regex

Operator check

Check whether nltk is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.

Read brief →
Jul 31, 2026 Vendor advisory High-risk advisory CVE-2026-12072

Natural Language Toolkit (NLTK): Path Traversal in NKJPCorpusReader leads to Arbitrary File Read and bypasses the nlt...

PyPI · nltk

Natural Language Toolkit (NLTK): Path Traversal in NKJPCorpusReader leads to Arbitrary File Read and bypasses the nltk.pathsec sandbox (ENFORCE=True)

Operator check

Check whether nltk is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.

Read brief →
Jul 31, 2026 Vendor advisory High-risk advisory CVE-2026-12074

Natural Language Toolkit (NLTK) has path traversal in FramenetCorpusReader.frame() that allows arbitrary XML file rea...

PyPI · nltk

Natural Language Toolkit (NLTK) has path traversal in FramenetCorpusReader.frame() that allows arbitrary XML file read, bypassing the nltk.pathsec sandbox (ENFORCE=True)

Operator check

Check whether nltk is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.

Read brief →
Jul 31, 2026 Vendor advisory High-risk advisory CVE-2026-12075

Natural Language Toolkit (NLTK): DNS-rebinding SSRF filter bypass in nltk.pathsec.urlopen (nltk.download / nltk.data....

PyPI · nltk

Natural Language Toolkit (NLTK): DNS-rebinding SSRF filter bypass in nltk.pathsec.urlopen (nltk.download / nltk.data.load) defeats ENFORCE mode

Operator check

Check whether nltk is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.

Read brief →
Jul 31, 2026 Vendor advisory High-risk advisory CVE-2026-53500

Thumbor treats ALLOWED_SOURCES string patterns as unescaped regex, allowing hostname bypass via wildcard dot

PyPI · thumbor

Thumbor treats ALLOWED_SOURCES string patterns as unescaped regex, allowing hostname bypass via wildcard dot

Operator check

Check whether thumbor is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.

Read brief →
Jul 31, 2026 Vendor advisory High-risk advisory CVE-2026-53501

Thumbor has HMAC validation bypass via multiple .replace() calls when removing URL signature

PyPI · thumbor

Thumbor has HMAC validation bypass via multiple .replace() calls when removing URL signature

Operator check

Check whether thumbor is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.

Read brief →
Jul 31, 2026 Vendor advisory High-risk advisory CVE-2026-53502

Thumbor has path traversal via post-validation URL decoding bypass in file_loader

PyPI · thumbor

Thumbor has path traversal via post-validation URL decoding bypass in file_loader

Operator check

Check whether thumbor is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. CVSS score: 8.7.

Read brief →
Jul 31, 2026 Vendor advisory High-risk advisory CVE-2026-53503

Thumbor convolution filter allows divide-by-zero in C extension leading to remote DoS

PyPI · thumbor

Thumbor convolution filter allows divide-by-zero in C extension leading to remote DoS

Operator check

Check whether thumbor is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.

Read brief →
Jul 31, 2026 Vendor advisory High-risk advisory CVE-2026-53505

Thumbor proportion filter allows unbounded post-transform resize leading to remote DoS

PyPI · thumbor

Thumbor proportion filter allows unbounded post-transform resize leading to remote DoS

Operator check

Check whether thumbor is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.

Read brief →
Jul 30, 2026 Vendor advisory High-risk advisory CVE-2026-67437

OliveTin: Unauthenticated DoS via OAuth2 State Memory Exhaustion (Unbounded Map Growth)

Go · github.com/OliveTin/OliveTin

OliveTin: Unauthenticated DoS via OAuth2 State Memory Exhaustion (Unbounded Map Growth)

Operator check

Check whether github.com/OliveTin/OliveTin is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. EPSS probability: 0.4%; percentile: 28%.

Read brief →
Jul 30, 2026 Coordinated disclosure Patch review

VU#790363: foreUP golf management platform's web API contains multiple vulnerabilities

Multiple vendors · foreUP golf management platform's web API

Overview Two vulnerabilities in the REST API were found in Golf Compete foreUP. The first exposes the merchant, Finix, API credentials directly in customer record responses, allowing any user to obtain and use the payment processor account. The second is a missing object-level authorization check, which lets a user retrieve any other customer's full profile, payment token, and transaction history by changing the golfer_id in the request path. Description Golf Compete foreUP provides cloud-based golf course management software to over 2,000 golf courses. They offer tools that allow the management of customers, inventory, tee times, food & beverages, marketing, billing, etc. The vulnerabilities identified are listed below. CVE-2026-15657 A vulnerability in the foreUP customer REST API exposes merchant credentials. Each customer record... Related CVEs: CVE-2026-15657, CVE-2026-15658.

Operator check

Review the CERT/CC Vulnerability Note and compare the affected vendor and product list against your inventory. Apply vendor fixes or compensating controls for foreUP golf management platform's web API where available.

Read brief →
Jul 30, 2026 Vendor advisory Critical vendor advisory CVE-2025-4318

AWS Amplify Studio UI Component Properties Has an Input Validation Issue

npm · @aws-amplify/codegen-ui-react

AWS Amplify Studio UI Component Properties Has an Input Validation Issue

Operator check

Check whether @aws-amplify/codegen-ui-react is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. CVSS score: 9.5. EPSS probability: 0.9%; percentile: 57%.

Read brief →
Jul 30, 2026 Vendor advisory Critical vendor advisory CVE-2026-66418

OpenClaw Dashboard v3.0.0 — CVE-2026-66418 (Critical)

OpenClaw · Dashboard v3.0.0

OpenClaw Dashboard v3.0.0 contains a stored cross-site scripting vulnerability that allows unauthenticated remote attackers to inject arbitrary HTML and script payloads by submitting a crafted username in a failed login POST request, which is recorded verbatim in the audit log. When an administrator opens the notification panel, the unescaped log entry is rendered via innerHTML with a permissive Content-Security-Policy allowing inline event handlers, enabling the attacker-supplied payload to execute in the administrator's session and interact with authenticated endpoints including agent instru

Operator check

Review CVE-2026-66418 in your asset inventory. Apply patches per vendor guidance and verify Dashboard v3.0.0 is not exposed. CVSS score: 9.3.

Read brief →
Jul 30, 2026 Vendor advisory Critical vendor advisory CVE-2026-66421

OpenClaw Dashboard — CVE-2026-66421 (Critical)

OpenClaw · Dashboard

OpenClaw Dashboard contains a stored cross-site scripting vulnerability that allows unauthenticated remote attackers to execute arbitrary JavaScript in the administrator's browser session by injecting HTML markup into agent transcript messages processed through the sessions API. Attackers can craft a message containing inline event handler payloads such as an img tag with an onerror attribute within the 60-character rendering budget, which is stored in the session transcript and interpolated unsanitized into innerHTML on the default landing page, allowing theft of session tokens and unauthoriz

Operator check

Review CVE-2026-66421 in your asset inventory. Apply patches per vendor guidance and verify Dashboard is not exposed. CVSS score: 9.3.

Read brief →
Jul 30, 2026 Vendor advisory High-risk advisory CVE-2026-67424

Flyto2 Core: Guarded HTTP modules follow redirects into internal space without per-hop SSRF revalidation

PyPI · flyto-core

Flyto2 Core: Guarded HTTP modules follow redirects into internal space without per-hop SSRF revalidation

Operator check

Check whether flyto-core is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. EPSS probability: 0.2%; percentile: 15%.

Read brief →
Jul 30, 2026 Vendor advisory High-risk advisory CVE-2026-67425

Flyto2 Core: LLM/API keys leak to an attacker-controlled base_url

PyPI · flyto-core

Flyto2 Core: LLM/API keys leak to an attacker-controlled base_url

Operator check

Check whether flyto-core is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. EPSS probability: 0.3%; percentile: 24%.

Read brief →
Jul 30, 2026 Vendor advisory High-risk advisory CVE-2026-67426

Flyto2 Core: Unauthenticated flyto-verification /run: callback_url SSRF and internal runner-secret exfiltration

PyPI · flyto-core

Flyto2 Core: Unauthenticated flyto-verification /run: callback_url SSRF and internal runner-secret exfiltration

Operator check

Check whether flyto-core is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. EPSS probability: 0.3%; percentile: 21%.

Read brief →
Jul 30, 2026 Vendor advisory High-risk advisory CVE-2026-67427

Flyto2 Core: ${env.VAR} interpolation reads any env secret despite env.get being denylisted

PyPI · flyto-core

Flyto2 Core: ${env.VAR} interpolation reads any env secret despite env.get being denylisted

Operator check

Check whether flyto-core is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. EPSS probability: 0.3%; percentile: 27%.

Read brief →
Jul 30, 2026 Vendor advisory High-risk advisory CVE-2026-67428

Flyto2 Core: Multiple HTTP-family modules fetch client-controlled URLs without the SSRF guard their siblings apply (S...

PyPI · flyto-core

Flyto2 Core: Multiple HTTP-family modules fetch client-controlled URLs without the SSRF guard their siblings apply (SSRF to internal/metadata)

Operator check

Check whether flyto-core is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. EPSS probability: 0.3%; percentile: 26%.

Read brief →
Jul 30, 2026 Vendor advisory High-risk advisory CVE-2026-67429

Flyto2 Core: Arbitrary file write via image.download (and other file-writing modules)

PyPI · flyto-core

Flyto2 Core: Arbitrary file write via image.download (and other file-writing modules)

Operator check

Check whether flyto-core is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. EPSS probability: 0.5%; percentile: 40%.

Read brief →
Jul 30, 2026 Vendor advisory Critical vendor advisory CVE-2026-66066

Active Storage has possible arbitrary file read and remote code execution in Active Storage variant processing

RubyGems · activestorage

Active Storage has possible arbitrary file read and remote code execution in Active Storage variant processing

Operator check

Check whether activestorage is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. CVSS score: 9.5.

Read brief →
Jul 30, 2026 Vendor advisory High-risk advisory CVE-2026-67432

MCP Ruby SDK: Unbounded JSON-RPC request body causes uncontrolled memory allocation in StreamableHTTPTransport

RubyGems · mcp

MCP Ruby SDK: Unbounded JSON-RPC request body causes uncontrolled memory allocation in StreamableHTTPTransport

Operator check

Check whether mcp is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. EPSS probability: 0.4%; percentile: 36%.

Read brief →
Jul 30, 2026 Coordinated disclosure Patch review

VU#281278: SGLang contains six different vulnerabilities including RCE, data exfiltration, and credential disclosure

SGLang · SGLang

Overview Six vulnerabilities have been discovered within the SGLang project, including remote code execution (RCE), server-side request forgery (SSRF), local file read, credential leakage, and model weight exfiltration on a target server. Exploitation does not require authentication in most cases, and some vulnerabilities require only network access with no API keys or user credentials. At the time of publication, no patches are available from the project maintainers, and coordination attempts have been unsuccessful. Description SGLang is an open-source framework for serving large language models (LLMs) and multimodal AI models, supporting models such as Qwen, DeepSeek, Mistral, and Skywork, and is compatible with OpenAI APIs. Six vulnerabilities have been discovered within the tool and are tracked as follows: CVE-2026-15969 SGLang... Related CVEs: CVE-2026-14890, CVE-2026-15969, CVE-2026-15971, CVE-2026-15974.

Operator check

Review the CERT/CC Vulnerability Note and compare the affected vendor and product list against your inventory. Apply vendor fixes or compensating controls for SGLang where available.

Read brief →
Jul 29, 2026 Vendor advisory Critical vendor advisory CVE-2026-41939

Care Everywhere Gateway 14.3.10 — CVE-2026-41939 (Critical)

Care · Everywhere Gateway 14.3.10

Care Everywhere Gateway 14.3.10 contains a hard-coded credentials vulnerability in the bundled WildFly 8.2.0.Final management interface that allows unauthenticated remote attackers to gain administrative access by using default credentials identical across all installations. Attackers can authenticate to the exposed WildFly management console on port 20990 and deploy a malicious Web Application Archive file through the Deployments interface to achieve remote code execution as the Windows machine account. Version 14.x.x was declared end-of-life (EOL) in 2017 and future releases have addressed t

Operator check

Review CVE-2026-41939 in your asset inventory. Apply patches per vendor guidance and verify Everywhere Gateway 14.3.10 is not exposed. CVSS score: 9.8.

Read brief →
Jul 29, 2026 KEV Known exploited CVE-2026-20316

Cisco Secure Firewall Management Center Use of Hard-coded Password Vulnerability

Cisco · Secure Firewall Management Center (FMC)

Cisco Secure Firewall Management Center (FMC) formerly known as Firepower Management Center contains a use of hard-coded password vulnerability that could allow an unauthenticated, remote attacker to log in to an affected device using a low-privileged account to access sensitive data within the impacted systems.

Operator check

Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

Read brief →
Jul 29, 2026 Vendor advisory High-risk advisory CVE-2026-55651

Easy!Appointments Vulnerable to Appointments Takeover via Excessive Data Exposure

Composer · alextselegidis/easyappointments

Easy!Appointments Vulnerable to Appointments Takeover via Excessive Data Exposure

Operator check

Check whether alextselegidis/easyappointments is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. EPSS probability: 0.2%; percentile: 8%.

Read brief →
Jul 29, 2026 Coordinated disclosure Patch review

VU#293714: Arbitrary File Overwrite in Develar app-builder (zipx.Unzip) via Symlink Following on macOS (APFS)

Develar · app-builder (zipx.Unzip) via Symlink Following on macOS (APFS)

Overview A vulnerability in the zipx.Unzip extraction routine of Develar’s app-builder allows an attacker to overwrite arbitrary files on macOS using Apple File System (APFS). The issue arises from a combination of Unicode normalization collisions and unsafe symlink-following behavior. APFS treats certain Unicode equivalent filenames as identical (e.g., ß ↔ ss), while app builder performs no canonical normalization before validating or writing paths. Description Develar’s app-builder is a command‑line build tool used heavily in the Electron ecosystem to package, sign, notarize, and produce distributable application bundles for macOS, Windows, and Linux. It is popular because it is a transitive dependency of electron-builder, one of the most widely used packaging tools for Electron apps. The vulnerability arises from how the zipx.Unzip...

Operator check

Review the CERT/CC Vulnerability Note and compare the affected vendor and product list against your inventory. Apply vendor fixes or compensating controls for app-builder (zipx.Unzip) via Symlink Following on macOS (APFS) where available.

Read brief →
Jul 29, 2026 Vendor advisory High-risk advisory CVE-2026-49755

Req vulnerable to unbounded archive/compression extraction triggered by response content-type

erlang · req

Req vulnerable to unbounded archive/compression extraction triggered by response content-type

Operator check

Check whether req is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. CVSS score: 8.2. EPSS probability: 0.4%; percentile: 36%.

Read brief →
Jul 29, 2026 Vendor advisory High-risk advisory CVE-2026-54680

Logging operator has Fluentd configuration injection that allows remote code execution

Go · github.com/kube-logging/logging-operator

Logging operator has Fluentd configuration injection that allows remote code execution

Operator check

Check whether github.com/kube-logging/logging-operator is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.

Read brief →
Jul 29, 2026 Vendor advisory High-risk advisory CVE-2026-54693

ZITADEL Users Can Self-Verify Email/Phone via API

Go · github.com/zitadel/zitadel

ZITADEL Users Can Self-Verify Email/Phone via API

Operator check

Check whether github.com/zitadel/zitadel is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. CVSS score: 8.2.

Read brief →
Jul 29, 2026 Vendor advisory High-risk advisory CVE-2026-54735

prebid-server's request forgery vulnerability allows for possible host environment data extraction

Go · github.com/prebid/prebid-server/v4

prebid-server's request forgery vulnerability allows for possible host environment data extraction

Operator check

Check whether github.com/prebid/prebid-server/v4 is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.

Read brief →
Jul 29, 2026 Vendor advisory High-risk advisory

netfoil: Incorrect block responses could lead to localhost traffic

Go · github.com/tinfoil-factory/netfoil

netfoil: Incorrect block responses could lead to localhost traffic

Operator check

Check whether github.com/tinfoil-factory/netfoil is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. CVSS score: 7.4.

Read brief →
Jul 29, 2026 Vendor advisory High-risk advisory CVE-2026-50559

Quarkus: Authentication/Authorization Bypass via Advanced Path Normalization Vulnerabilities

Maven · io.quarkus:quarkus-vertx-http

Quarkus: Authentication/Authorization Bypass via Advanced Path Normalization Vulnerabilities

Operator check

Check whether io.quarkus:quarkus-vertx-http is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. EPSS probability: 0.5%; percentile: 38%.

Read brief →
Jul 29, 2026 Vendor advisory High-risk advisory CVE-2026-11393

AgentCore CLI Bedrock Agent Import Vulnerable to Code Injection via Improper Triple-Quote Escaping

npm · @aws/agentcore

AgentCore CLI Bedrock Agent Import Vulnerable to Code Injection via Improper Triple-Quote Escaping

Operator check

Check whether @aws/agentcore is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. CVSS score: 8.8. EPSS probability: 0.3%; percentile: 25%.

Read brief →
Jul 29, 2026 Vendor advisory High-risk advisory CVE-2026-54660

swagger-typescript-api vulnerable to authorization-token exfiltration via spec `$ref`

npm · swagger-typescript-api

swagger-typescript-api vulnerable to authorization-token exfiltration via spec `$ref`

Operator check

Check whether swagger-typescript-api is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.

Read brief →
Jul 29, 2026 Vendor advisory High-risk advisory CVE-2026-54661

swagger-typescript-api vulnerable to code injection via unescaped `servers[0].url` in axios http-client template

npm · swagger-typescript-api

swagger-typescript-api vulnerable to code injection via unescaped `servers[0].url` in axios http-client template

Operator check

Check whether swagger-typescript-api is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.

Read brief →
Jul 29, 2026 Vendor advisory High-risk advisory CVE-2026-54662

swagger-typescript-api vulnerable to code injection via unescaped `servers[0].url` in fetch http-client template

npm · swagger-typescript-api

swagger-typescript-api vulnerable to code injection via unescaped `servers[0].url` in fetch http-client template

Operator check

Check whether swagger-typescript-api is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.

Read brief →
Jul 29, 2026 Vendor advisory High-risk advisory CVE-2026-54664

swagger-typescript-api vulnerable to code injection via unescaped enum string values

npm · swagger-typescript-api

swagger-typescript-api vulnerable to code injection via unescaped enum string values

Operator check

Check whether swagger-typescript-api is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.

Read brief →
Jul 29, 2026 Vendor advisory High-risk advisory CVE-2026-54666

swagger-typescript-api vulnerable to code injection via unescaped OpenAPI path strings in generated method bodies

npm · swagger-typescript-api

swagger-typescript-api vulnerable to code injection via unescaped OpenAPI path strings in generated method bodies

Operator check

Check whether swagger-typescript-api is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.

Read brief →
Jul 29, 2026 Coordinated disclosure Patch review

VU#305509: OPeNDAP Hyrax is vulnerable to SSRF and Credential Disclosure

OPeNDAP · Hyrax

Overview A vulnerability has been discovered in the OPeNDAP Hyrax software solution. A remote attacker with the ability to submit crafted requests to an affected Hyrax instance could cause the application to communicate with unauthorized remote systems. Under certain conditions, the vulnerability may also result in the unintended disclosure of user authentication tokens to unauthorized destinations. Description CVE-2026-16637 OPeNDAP Hyrax is vulnerable to Server Side Request Forgery (SSRF) and credential disclosure via unvalidated HTTP redirects that bypass the AllowedHosts allowlist and leak Earthdata headers (User-Id, Echo-Token) to attacker-controlled endpoints. OPeNDAP Hyrax is an open-source data server software that enables remote access to scientific datasets over the internet using the OPeNDAP protocol. It allows users to query... Related CVEs: CVE-2026-16637.

Operator check

Review the CERT/CC Vulnerability Note and compare the affected vendor and product list against your inventory. Apply vendor fixes or compensating controls for Hyrax where available.

Read brief →
Jul 29, 2026 Vendor advisory High-risk advisory CVE-2026-54574

`proot-distro install` has a Symlink Escape (Arbitrary Host File Write) via Malicious Tar Archive

PyPI · proot-distro

`proot-distro install` has a Symlink Escape (Arbitrary Host File Write) via Malicious Tar Archive

Operator check

Check whether proot-distro is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.

Read brief →
Jul 29, 2026 Vendor advisory High-risk advisory CVE-2026-54727

proot-distro has a Container Isolation Bypass via Crafted Restore Archive

PyPI · proot-distro

proot-distro has a Container Isolation Bypass via Crafted Restore Archive

Operator check

Check whether proot-distro is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.

Read brief →
Jul 28, 2026 Vendor advisory High-risk advisory CVE-2026-54588

Poweradmin has Host Header Injection in OIDC redirect_uri, SAML ACS/SLO URL, and Logout Redirect Construction.

Composer · poweradmin/poweradmin

Poweradmin has Host Header Injection in OIDC redirect_uri, SAML ACS/SLO URL, and Logout Redirect Construction.

Operator check

Check whether poweradmin/poweradmin is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. EPSS probability: 0.3%; percentile: 24%.

Read brief →
Jul 28, 2026 Vendor advisory High-risk advisory CVE-2026-54593

Pterodactyl's improper JWT scoping allows subuser to upload files when not explicitly granted `file.create` permissions

Composer · pterodactyl/panel

Pterodactyl's improper JWT scoping allows subuser to upload files when not explicitly granted `file.create` permissions

Operator check

Check whether pterodactyl/panel is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.

Read brief →
Jul 28, 2026 Vendor advisory High-risk advisory CVE-2026-61609

Pterodactyl's shared global rate-limit key on login and 2FA checkpoint enables unauthenticated panel-wide authenticat...

Composer · pterodactyl/panel

Pterodactyl's shared global rate-limit key on login and 2FA checkpoint enables unauthenticated panel-wide authentication lockout (DoS)

Operator check

Check whether pterodactyl/panel is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.

Read brief →
Jul 28, 2026 Vendor advisory High-risk advisory CVE-2026-50567

Fission: Zip Slip in pkg/utils/zip.go:Unarchive allows fetcher to write outside the destination directory

Go · github.com/fission/fission

Fission: Zip Slip in pkg/utils/zip.go:Unarchive allows fetcher to write outside the destination directory

Operator check

Check whether github.com/fission/fission is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. EPSS probability: 0.3%; percentile: 22%.

Read brief →
Jul 28, 2026 Vendor advisory High-risk advisory CVE-2026-50570

Fission: Incomplete capability denylist in Environment/Function PodSpec validation allows tenant-added CAP_SYS_TIME a...

Go · github.com/fission/fission

Fission: Incomplete capability denylist in Environment/Function PodSpec validation allows tenant-added CAP_SYS_TIME and cross-tenant node wall-clock corruption

Operator check

Check whether github.com/fission/fission is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. EPSS probability: 0.3%; percentile: 20%.

Read brief →
Jul 28, 2026 Vendor advisory High-risk advisory CVE-2026-54638

td has pre-auth denial of service via unbounded memory allocation in proto.UnencryptedMessage.Decode

Go · github.com/gotd/td

td has pre-auth denial of service via unbounded memory allocation in proto.UnencryptedMessage.Decode

Operator check

Check whether github.com/gotd/td is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.

Read brief →
Jul 28, 2026 Vendor advisory High-risk advisory CVE-2026-54650

openhole-server vulnerable to path traversal via URL-decoded request path

Go · github.com/bablilayoub/openhole

openhole-server vulnerable to path traversal via URL-decoded request path

Operator check

Check whether github.com/bablilayoub/openhole is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.

Read brief →
Jul 28, 2026 Vendor advisory High-risk advisory CVE-2026-54719

goshs: File-based .goshs ACL authorization bypass via the ?bulk zip-download route (unauthenticated read; residual of...

Go · github.com/patrickhener/goshs

goshs: File-based .goshs ACL authorization bypass via the ?bulk zip-download route (unauthenticated read; residual of GHSA-wvhv-qcqf-f3cx)

Operator check

Check whether github.com/patrickhener/goshs is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.

Read brief →
Jul 28, 2026 Vendor advisory High-risk advisory CVE-2026-62325

goshs SFTP authentication bypass via empty password (incomplete fix of CVE-2026-40884)

Go · github.com/patrickhener/goshs/v2

goshs SFTP authentication bypass via empty password (incomplete fix of CVE-2026-40884)

Operator check

Check whether github.com/patrickhener/goshs/v2 is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.

Read brief →
Jul 28, 2026 Vendor advisory High-risk advisory CVE-2026-64863

goshs --no-delete WebDAV MOVE bypass allows file deletion/overwrite

Go · goshs.de/goshs/v2

goshs --no-delete WebDAV MOVE bypass allows file deletion/overwrite

Operator check

Check whether goshs.de/goshs/v2 is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.

Read brief →
Jul 28, 2026 Coordinated disclosure Patch review

VU#141367: AT&T's Arris BGW210-700 gateway contains authentication bypass vulnerability in LAN-side management interface

LAN-side · management interface

Overview Firmware versions 2.7.7 and earlier of the Arris BGW210-700 residential gateway contain an authentication bypass vulnerability, tracked as CVE-2026-16771, that allows any unauthenticated LAN-side user to read sensitive configuration data and modify device settings through web management endpoints. Although this vulnerability was recently discovered, the majority of in-service gateways are not expected to be running the affected version. Only devices that have not received automated ISP-managed firmware updates since version 2.7.7 in 2020 are vulnerable. Description The Arris BGW210-700 is a residential gateway used widely in AT&T deployments to provide routing, wireless networking, and wide-area network (WAN) connectivity for home users. The device exposes a browser-based management interface on the local-area network (LAN) side... Related CVEs: CVE-2026-16771.

Operator check

Review the CERT/CC Vulnerability Note and compare the affected vendor and product list against your inventory. Apply vendor fixes or compensating controls for management interface where available.

Read brief →
Jul 28, 2026 Vendor advisory High-risk advisory CVE-2026-54609

QTINeon has unauthenticated relay-to-host amplification via unbounded RECONNECT_REQUEST forwarding

Maven · com.quietterminal:qti-neon

QTINeon has unauthenticated relay-to-host amplification via unbounded RECONNECT_REQUEST forwarding

Operator check

Check whether com.quietterminal:qti-neon is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.

Read brief →
Jul 28, 2026 Vendor advisory High-risk advisory CVE-2026-54639

Style Dictionary - Prototype Pollution in convertTokenData utility function

npm · style-dictionary

Style Dictionary - Prototype Pollution in convertTokenData utility function

Operator check

Check whether style-dictionary is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. EPSS probability: 0.1%; percentile: 3%.

Read brief →
Jul 28, 2026 Vendor advisory High-risk advisory CVE-2026-54658

@hypequery/clickhouse has SQL Injection in parameter escaping that allows arbitrary SQL execution

npm · @hypequery/clickhouse

@hypequery/clickhouse has SQL Injection in parameter escaping that allows arbitrary SQL execution

Operator check

Check whether @hypequery/clickhouse is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.

Read brief →
Jul 28, 2026 Vendor advisory High-risk advisory CVE-2026-32203

Microsoft Security Advisory CVE-2026-32203 – .NET and Visual Studio Denial of Service Vulnerability

NuGet · System.Security.Cryptography.Xml

Microsoft Security Advisory CVE-2026-32203 – .NET and Visual Studio Denial of Service Vulnerability

Operator check

Check whether System.Security.Cryptography.Xml is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. EPSS probability: 1.6%; percentile: 73%.

Read brief →
Jul 28, 2026 Vendor advisory High-risk advisory CVE-2026-54632

SIPSorcery: Malformed UDP packet on the RTP/ICE socket can remotely terminate a media session (DoS)

NuGet · SIPSorcery

SIPSorcery: Malformed UDP packet on the RTP/ICE socket can remotely terminate a media session (DoS)

Operator check

Check whether SIPSorcery is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.

Read brief →
Jul 28, 2026 Vendor advisory High-risk advisory CVE-2026-54621

`datamodel-code-generator` vulnerable to code injection via unescaped carriage return in GraphQL Union description

PyPI · datamodel-code-generator

`datamodel-code-generator` vulnerable to code injection via unescaped carriage return in GraphQL Union description

Operator check

Check whether datamodel-code-generator is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.

Read brief →
Jul 28, 2026 Vendor advisory High-risk advisory CVE-2026-54653

`datamodel-code-generator` vulnerable to code injection in via attacker-controlled `default_factory` schema field

PyPI · datamodel-code-generator

`datamodel-code-generator` vulnerable to code injection in via attacker-controlled `default_factory` schema field

Operator check

Check whether datamodel-code-generator is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.

Read brief →
Jul 28, 2026 Vendor advisory High-risk advisory CVE-2026-54654

`datamodel-code-generator` vulnerable to code injection via unescaped carriage return in `--extra-template-data` `com...

PyPI · datamodel-code-generator

`datamodel-code-generator` vulnerable to code injection via unescaped carriage return in `--extra-template-data` `comment` field

Operator check

Check whether datamodel-code-generator is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.

Read brief →
Jul 28, 2026 Vendor advisory High-risk advisory CVE-2026-54655

`datamodel-code-generator` vulnerable to code execution on import via `x-python-type` JSON-Schema extension in datamo...

PyPI · datamodel-code-generator

`datamodel-code-generator` vulnerable to code execution on import via `x-python-type` JSON-Schema extension in datamodel-code-generator

Operator check

Check whether datamodel-code-generator is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.

Read brief →
Jul 28, 2026 Vendor advisory High-risk advisory CVE-2026-54656

`datamodel-code-generator` vulnerable to code execution on import via unescaped `validators` entries in --extra-templ...

PyPI · datamodel-code-generator

`datamodel-code-generator` vulnerable to code execution on import via unescaped `validators` entries in --extra-template-data

Operator check

Check whether datamodel-code-generator is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.

Read brief →
Jul 28, 2026 Vendor advisory High-risk advisory CVE-2026-54690

datamodel-code-generator vulnerable to SSRF via JSON-Schema `$ref` to HTTP URL (silent by default)

PyPI · datamodel-code-generator

datamodel-code-generator vulnerable to SSRF via JSON-Schema `$ref` to HTTP URL (silent by default)

Operator check

Check whether datamodel-code-generator is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.

Read brief →
Jul 28, 2026 Vendor advisory High-risk advisory CVE-2026-54691

datamodel-code-generator vulnerable to SSRF via --url: no host/IP validation, follows redirects

PyPI · datamodel-code-generator

datamodel-code-generator vulnerable to SSRF via --url: no host/IP validation, follows redirects

Operator check

Check whether datamodel-code-generator is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.

Read brief →
Jul 28, 2026 Vendor advisory High-risk advisory CVE-2026-55389

datamodel-code-generator vulnerable to arbitrary local file read via JSON-Schema `$ref` (`file://` and `../` traversa...

PyPI · datamodel-code-generator

datamodel-code-generator vulnerable to arbitrary local file read via JSON-Schema `$ref` (`file://` and `../` traversal), bypassing `--no-allow-remote-refs`

Operator check

Check whether datamodel-code-generator is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.

Read brief →
Jul 28, 2026 Vendor advisory High-risk advisory CVE-2026-55390

datamodel-code-generator vulnerable to arbitrary local file read via XSD `schemaLocation` (`xs:include`/`xs:import`) ...

PyPI · datamodel-code-generator

datamodel-code-generator vulnerable to arbitrary local file read via XSD `schemaLocation` (`xs:include`/`xs:import`) path traversal, with no remote-ref gate

Operator check

Check whether datamodel-code-generator is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.

Read brief →
Jul 28, 2026 Vendor advisory High-risk advisory CVE-2026-55391

datamodel-code-generator vulnerable to SSRF protection bypass via DNS rebinding

PyPI · datamodel-code-generator

datamodel-code-generator vulnerable to SSRF protection bypass via DNS rebinding

Operator check

Check whether datamodel-code-generator is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.

Read brief →
Jul 28, 2026 Vendor advisory High-risk advisory CVE-2026-55415

datamodel-code-generator vulnerable to code injection via `x-python-import` / `customTypePath` in generated import st...

PyPI · datamodel-code-generator

datamodel-code-generator vulnerable to code injection via `x-python-import` / `customTypePath` in generated import statements

Operator check

Check whether datamodel-code-generator is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.

Read brief →
Jul 28, 2026 Vendor advisory High-risk advisory CVE-2026-54603

OAuth2::Client#request: Protocol-relative redirect Location overrides authority, leaking bearer Authorization to atta...

RubyGems · oauth2

OAuth2::Client#request: Protocol-relative redirect Location overrides authority, leaking bearer Authorization to attacker host

Operator check

Check whether oauth2 is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.

Read brief →
Jul 28, 2026 Vendor advisory High-risk advisory CVE-2026-54605

OAuth: Cross-origin token-request redirects can expose signed request metadata

RubyGems · oauth

OAuth: Cross-origin token-request redirects can expose signed request metadata

Operator check

Check whether oauth is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.

Read brief →
Jul 28, 2026 Vendor advisory Critical vendor advisory CVE-2026-46428

lettre has TLS hostname verification disabled when using Boring TLS backend

Rust · lettre

lettre has TLS hostname verification disabled when using Boring TLS backend

Operator check

Check whether lettre is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. CVSS score: 9.1. EPSS probability: 0.2%; percentile: 9%.

Read brief →
Jul 27, 2026 Vendor advisory Critical vendor advisory CVE-2026-48144

Apache Thrift — CVE-2026-48144 (Critical)

Apache · Thrift

Improper Validation of Certificate with Host Mismatch vulnerability in Apache Thrift c_glib bindings. This issue affects Apache Thrift: before 0.24.0. Users are recommended to upgrade to version 0.24.0, which fixes the issue.

Operator check

Review CVE-2026-48144 in your asset inventory. Apply patches per vendor guidance and verify Thrift is not exposed. CVSS score: 9.1.

Read brief →
Jul 27, 2026 Vendor advisory Critical vendor advisory CVE-2026-55971

Apache Thrift — CVE-2026-55971 (Critical)

Apache · Thrift

Heap-based Buffer Overflow vulnerability in Apache Thrift C++ bindings. This issue affects Apache Thrift: before 0.24.0. Users are recommended to upgrade to version 0.24.0, which fixes the issue.

Operator check

Review CVE-2026-55971 in your asset inventory. Apply patches per vendor guidance and verify Thrift is not exposed. CVSS score: 9.8.

Read brief →
Jul 27, 2026 Vendor advisory Critical vendor advisory CVE-2026-58023

Apache Thrift — CVE-2026-58023 (Critical)

Apache · Thrift

Out-of-bounds Read vulnerability in Apache Thrift c_glib bindings. This issue affects Apache Thrift: before 0.24.0. Users are recommended to upgrade to version 0.24.0, which fixes the issue.

Operator check

Review CVE-2026-58023 in your asset inventory. Apply patches per vendor guidance and verify Thrift is not exposed. CVSS score: 9.1.

Read brief →
Jul 27, 2026 Vendor advisory Critical vendor advisory CVE-2026-58662

Apache Thrift — CVE-2026-58662 (Critical)

Apache · Thrift

Improper Validation of Specified Quantity in Input, Out-of-bounds Read vulnerability in Apache Thrift C++ bindings. This issue affects Apache Thrift: before 0.24.0. Users are recommended to upgrade to version 0.24.0, which fixes the issue.

Operator check

Review CVE-2026-58662 in your asset inventory. Apply patches per vendor guidance and verify Thrift is not exposed. CVSS score: 9.1.

Read brief →
Jul 27, 2026 KEV Known exploited CVE-2026-16812

Arista VeloCloud Orchestrator On-Prem OS Command Injection Vulnerability

Arista · VeloCloud Orchestrator

Arista VeloCloud Orchestrator On-Prem contains an OS command injection vulnerability that may allow a remote attacker to access privileged internal functionality and impact the VCO host. Successful exploitation may compromise the confidentiality, integrity, and availability of the orchestrator and data managed by the orchestrator.

Operator check

Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

Read brief →
Jul 27, 2026 KEV Known exploited CVE-2025-68686

Fortinet FortiOS Exposure of Sensitive Information to an Unauthorized Actor Vulnerability

Fortinet · FortiOS

Fortinet FortiOS contains an exposure of sensitive information to an unauthorized actor vulnerability. This may allow a remote unauthenticated attacker to bypass the patch developed for the symbolic link persistency mechanism observed in some post-exploit cases, via crafted HTTP requests. An attacker would need first to have compromised the product via another vulnerability, at filesystem level.

Operator check

Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

Read brief →
Jul 24, 2026 Vendor advisory High-risk advisory

Pheditor: Authentication Bypass in Forced Password-Change Flow via Unverified Current Password

Composer · pheditor/pheditor

Pheditor: Authentication Bypass in Forced Password-Change Flow via Unverified Current Password

Operator check

Check whether pheditor/pheditor is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.

Read brief →
Jul 24, 2026 Vendor advisory High-risk advisory

etcd: `tlsListener.acceptLoop` spawns unbounded handshake goroutines with no deadline

Go · go.etcd.io/etcd/v3

etcd: `tlsListener.acceptLoop` spawns unbounded handshake goroutines with no deadline

Operator check

Check whether go.etcd.io/etcd/v3 is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. CVSS score: 8.7.

Read brief →
Jul 24, 2026 Vendor advisory High-risk advisory

Oh My Posh: Arbitrary command execution via template injection in the path segment

Go · github.com/jandedobbeleer/oh-my-posh

Oh My Posh: Arbitrary command execution via template injection in the path segment

Operator check

Check whether github.com/jandedobbeleer/oh-my-posh is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.

Read brief →
Jul 24, 2026 Vendor advisory High-risk advisory

OpenList: Authenticated users can rename files outside their base path via batch rename `src_name` traversal

Go · github.com/OpenListTeam/OpenList/v4

OpenList: Authenticated users can rename files outside their base path via batch rename `src_name` traversal

Operator check

Check whether github.com/OpenListTeam/OpenList/v4 is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.

Read brief →
Jul 24, 2026 Vendor advisory High-risk advisory

kin-openapi: ValidationHandler.Load() Fail-Open Authentication Bypass via NoopAuthenticationFunc Default

Go · github.com/getkin/kin-openapi

kin-openapi: ValidationHandler.Load() Fail-Open Authentication Bypass via NoopAuthenticationFunc Default

Operator check

Check whether github.com/getkin/kin-openapi is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.

Read brief →
Jul 24, 2026 Vendor advisory Critical vendor advisory CVE-2026-62263

OpenAM: WebAuthn Java deserialization RCE via ObjectInputFilter depth>1 bypass

Maven · org.openidentityplatform.openam:openam-auth-webauthn

OpenAM: WebAuthn Java deserialization RCE via ObjectInputFilter depth>1 bypass

Operator check

Check whether org.openidentityplatform.openam:openam-auth-webauthn is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. CVSS score: 9.2.

Read brief →
Jul 24, 2026 Vendor advisory High-risk advisory CVE-2026-62379

OpenAM: Unauthenticated Remote Code Execution via Class.forName in AuthXMLUtils.createCustomCallback

Maven · org.openidentityplatform.openam:openam-core

OpenAM: Unauthenticated Remote Code Execution via Class.forName in AuthXMLUtils.createCustomCallback

Operator check

Check whether org.openidentityplatform.openam:openam-core is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.

Read brief →
Jul 24, 2026 Vendor advisory High-risk advisory

blaze: Chunked-body trailer fields promoted into Request.headers in blaze-server (front-end header-sanitization bypass)

Maven · org.http4s:blaze-http_2.13

blaze: Chunked-body trailer fields promoted into Request.headers in blaze-server (front-end header-sanitization bypass)

Operator check

Check whether org.http4s:blaze-http_2.13 is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.

Read brief →
Jul 24, 2026 Vendor advisory High-risk advisory

OpenDJ unauthenticated SSRF, local file read and unbounded-read DoS in the DSMLv2 gateway

Maven · org.openidentityplatform.opendj:opendj-dsml-servlet

OpenDJ unauthenticated SSRF, local file read and unbounded-read DoS in the DSMLv2 gateway

Operator check

Check whether org.openidentityplatform.opendj:opendj-dsml-servlet is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.

Read brief →
Jul 24, 2026 Vendor advisory High-risk advisory

blaze: Unbounded WebSocket message aggregation in http4s-blaze-server

Maven · org.http4s:http4s-blaze-server_2.13

blaze: Unbounded WebSocket message aggregation in http4s-blaze-server

Operator check

Check whether org.http4s:http4s-blaze-server_2.13 is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.

Read brief →
Jul 24, 2026 Vendor advisory High-risk advisory

OmniFaces: Forged combined-resource IDs and related output/push boundaries

Maven · org.omnifaces:omnifaces

OmniFaces: Forged combined-resource IDs and related output/push boundaries

Operator check

Check whether org.omnifaces:omnifaces is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.

Read brief →
Jul 24, 2026 Vendor advisory High-risk advisory

blaze: Multiple HTTP/1.1 request-smuggling primitives in blaze's Java wire parser

Maven · org.http4s:http4s-blaze-server_2.13

blaze: Multiple HTTP/1.1 request-smuggling primitives in blaze's Java wire parser

Operator check

Check whether org.http4s:http4s-blaze-server_2.13 is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.

Read brief →
Jul 24, 2026 Vendor advisory High-risk advisory

OpenDJ SASL PLAIN authzid bypassing the proxy ACI scope check

Maven · org.openidentityplatform.opendj:opendj-server-legacy

OpenDJ SASL PLAIN authzid bypassing the proxy ACI scope check

Operator check

Check whether org.openidentityplatform.opendj:opendj-server-legacy is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.

Read brief →
Jul 24, 2026 Vendor advisory High-risk advisory CVE-2026-59940

seroval: `seroval.fromJSON()` Promise resolver type confusion invokes attacker-controlled methods during deserialization

npm · seroval

seroval: `seroval.fromJSON()` Promise resolver type confusion invokes attacker-controlled methods during deserialization

Operator check

Check whether seroval is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.

Read brief →
Jul 24, 2026 Vendor advisory High-risk advisory

Velocity.js: Remote Code Execution via property-read to Function constructor (bypass of GHSA-j658-c2gf-x6pq fix)

npm · velocityjs

Velocity.js: Remote Code Execution via property-read to Function constructor (bypass of GHSA-j658-c2gf-x6pq fix)

Operator check

Check whether velocityjs is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.

Read brief →
Jul 24, 2026 Vendor advisory Critical vendor advisory

Budibase: OIDC SSO account takeover: incoming identity linked by email without checking email_verified

npm · @budibase/server

Budibase: OIDC SSO account takeover: incoming identity linked by email without checking email_verified

Operator check

Check whether @budibase/server is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. CVSS score: 9.0.

Read brief →
Jul 24, 2026 Vendor advisory High-risk advisory

Budibase: Unauthenticated REST Datasource Credential Theft via Cross-Origin Auth Leak

npm · @budibase/server

Budibase: Unauthenticated REST Datasource Credential Theft via Cross-Origin Auth Leak

Operator check

Check whether @budibase/server is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.

Read brief →
Jul 24, 2026 Vendor advisory High-risk advisory

@better-auth/scim: account takeover and stale access via SCIM provider-id collision

npm · @better-auth/scim

@better-auth/scim: account takeover and stale access via SCIM provider-id collision

Operator check

Check whether @better-auth/scim is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.

Read brief →
Jul 24, 2026 Vendor advisory High-risk advisory

sm-crypto: Predictable SM2 key generation in Node.js: default RNG uses Math.random + wall clock

npm · sm-crypto

sm-crypto: Predictable SM2 key generation in Node.js: default RNG uses Math.random + wall clock

Operator check

Check whether sm-crypto is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.

Read brief →
Jul 24, 2026 Vendor advisory High-risk advisory

Prompty: Server-Side Template Injection to Remote Code Execution in the @prompty/core Nunjucks Renderer

npm · @prompty/core

Prompty: Server-Side Template Injection to Remote Code Execution in the @prompty/core Nunjucks Renderer

Operator check

Check whether @prompty/core is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.

Read brief →
Jul 24, 2026 Vendor advisory Critical vendor advisory CVE-2026-59864

Microsoft Kiota: Path/URL injection into generated Copilot plugin manifest via x-ai-* extensions

NuGet · Microsoft.OpenApi.Kiota

Microsoft Kiota: Path/URL injection into generated Copilot plugin manifest via x-ai-* extensions

Operator check

Check whether Microsoft.OpenApi.Kiota is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. CVSS score: 9.3. EPSS probability: 1.3%; percentile: 67%.

Read brief →
Jul 24, 2026 Vendor advisory Critical vendor advisory CVE-2026-59865

Microsoft Kiota: Command injection via x-ms-kiota-info dependencyInstallCommand surfaced by `kiota info`

NuGet · Microsoft.OpenApi.Kiota

Microsoft Kiota: Command injection via x-ms-kiota-info dependencyInstallCommand surfaced by `kiota info`

Operator check

Check whether Microsoft.OpenApi.Kiota is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. CVSS score: 9.3. EPSS probability: 3.2%; percentile: 87%.

Read brief →
Jul 24, 2026 Vendor advisory High-risk advisory CVE-2026-16584

AWS API MCP Server Security Policy Bypass via Startup Initialization Failure

PyPI · awslabs.aws-api-mcp-server

AWS API MCP Server Security Policy Bypass via Startup Initialization Failure

Operator check

Check whether awslabs.aws-api-mcp-server is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. CVSS score: 7.3. EPSS probability: 0.1%; percentile: 3%.

Read brief →
Jul 24, 2026 Vendor advisory High-risk advisory CVE-2026-16796

AWS Bedrock AgentCore: Improper neutralization of argument delimiters in the Python SDK install_packages()

PyPI · bedrock-agentcore

AWS Bedrock AgentCore: Improper neutralization of argument delimiters in the Python SDK install_packages()

Operator check

Check whether bedrock-agentcore is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. CVSS score: 8.4. EPSS probability: 0.3%; percentile: 25%.

Read brief →
Jul 24, 2026 Vendor advisory High-risk advisory CVE-2026-16756

Smithy-RS: Allocation of resources without limits in the default aws-smithy-http-server serve() path allows unauthent...

Rust · aws-smithy-http-server

Smithy-RS: Allocation of resources without limits in the default aws-smithy-http-server serve() path allows unauthenticated Slowloris denial of service

Operator check

Check whether aws-smithy-http-server is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. CVSS score: 8.7. EPSS probability: 0.4%; percentile: 34%.

Read brief →
Jul 23, 2026 Vendor advisory High-risk advisory CVE-2026-59931

PHPSpreadsheet: SSRF bypass via HTTP redirect in WEBSERVICE() domain whitelist

Composer · phpoffice/phpspreadsheet

PHPSpreadsheet: SSRF bypass via HTTP redirect in WEBSERVICE() domain whitelist

Operator check

Check whether phpoffice/phpspreadsheet is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.

Read brief →
Jul 23, 2026 Vendor advisory High-risk advisory CVE-2026-59932

PHPSpreadsheet: Gnumeric reader unbounded gzip expansion causes memory exhaustion

Composer · phpoffice/phpspreadsheet

PHPSpreadsheet: Gnumeric reader unbounded gzip expansion causes memory exhaustion

Operator check

Check whether phpoffice/phpspreadsheet is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.

Read brief →
Jul 23, 2026 Vendor advisory High-risk advisory CVE-2026-59933

PHPSpreadsheet: XLS/OLE sector-chain self-loop causes memory exhaustion

Composer · phpoffice/phpspreadsheet

PHPSpreadsheet: XLS/OLE sector-chain self-loop causes memory exhaustion

Operator check

Check whether phpoffice/phpspreadsheet is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.

Read brief →
Jul 23, 2026 Coordinated disclosure Patch review

VU#492466: Logto Identity Platform has authentication and authorization failures in core protocol handling

Logto · Identity Platform

Overview The Logto platform contains multiple vulnerabilities affecting the identity‑processing pipeline. These flaws reduce the reliability of authentication and authorization decisions and may allow attackers to bypass account‑ownership checks, skip MFA, replay externally issued SSO responses, or submit identity assertions without proper cryptographic or validity checks. Collectively, the issues create several paths for unauthorized access across both local and federated sign‑in flows. Description Developed by Silverhand Inc., Logto is an identity and access management system for software as a service (SaaS) and AI applications. It provides multi‑tenant authentication, single sign-on (SSO), role-based access control (RBAC), support for openId connect (OIDC), open authorization (OAuth) 2.1, and Security Assertion Markup Language (SAML)... Related CVEs: CVE-2026-15611, CVE-2026-15612, CVE-2026-15614, CVE-2026-15615.

Operator check

Review the CERT/CC Vulnerability Note and compare the affected vendor and product list against your inventory. Apply vendor fixes or compensating controls for Identity Platform where available.

Read brief →
Jul 23, 2026 Vendor advisory High-risk advisory CVE-2026-45623

PostCSS: Arbitrary file read and information disclosure via attacker-controlled sourceMappingURL in CSS comments

npm · postcss

PostCSS: Arbitrary file read and information disclosure via attacker-controlled sourceMappingURL in CSS comments

Operator check

Check whether postcss is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.

Read brief →
Jul 23, 2026 Vendor advisory Critical vendor advisory

Auth.js: Email normalizer validates the address before Unicode normalization, allowing a homoglyph @ bypass

npm · @auth/core

Auth.js: Email normalizer validates the address before Unicode normalization, allowing a homoglyph @ bypass

Operator check

Check whether @auth/core is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. CVSS score: 9.1.

Read brief →
Jul 23, 2026 Vendor advisory Critical vendor advisory

Auth.js: Configuration errors can cause existence-based auth checks to fail open (auth object populated with an error)

npm · next-auth

Auth.js: Configuration errors can cause existence-based auth checks to fail open (auth object populated with an error)

Operator check

Check whether next-auth is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. CVSS score: 9.1.

Read brief →
Jul 23, 2026 Vendor advisory High-risk advisory

Auth.js: getToken() throws an uncaught exception on malformed Bearer authorization headers

npm · @auth/core

Auth.js: getToken() throws an uncaught exception on malformed Bearer authorization headers

Operator check

Check whether @auth/core is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.

Read brief →
Jul 23, 2026 Vendor advisory High-risk advisory CVE-2026-59935

pypdf: Possible infinite loop for not terminated inline images (ASCII85 and ASCIIHex filter)

PyPI · pypdf

pypdf: Possible infinite loop for not terminated inline images (ASCII85 and ASCIIHex filter)

Operator check

Check whether pypdf is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. CVSS score: 8.7. EPSS probability: 0.4%; percentile: 28%.

Read brief →
Jul 23, 2026 Vendor advisory High-risk advisory CVE-2026-59936

pypdf: Possible infinite loop for not terminated inline images

PyPI · pypdf

pypdf: Possible infinite loop for not terminated inline images

Operator check

Check whether pypdf is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. CVSS score: 8.7. EPSS probability: 0.3%; percentile: 27%.

Read brief →
Jul 22, 2026 Coordinated disclosure Patch review

VU#360868: Analog Way Picturall Quad Compact Mark II contains a local privilege escalation vulnerability

Analog · Way Picturall Quad Compact Mark II

Overview Version 3.5.8 of Analog Way's Picturall Quad Compact Mark II server contains a local privilege escalation vulnerability, tracked as CVE-2026-14985, due to improper privilege delegation and insufficient input validation in a maintenance script. Description The Picturall Quad Compact Mark II is a compact, heavy-duty 8K media server developed by Analog Way for video playback and content management in professional audiovisual environments. The core firmware includes a maintenance script called create_local_installer.sh , and the default script permission allows the low-privileged user, picmedia , to execute it as root and without a password. An attacker creates a malicious Ext4 disk image that contains the file, picturall-version.txt , with a directory traversal string and a payload file. create_local_installer.sh reads input from... Related CVEs: CVE-2026-14985.

Operator check

Review the CERT/CC Vulnerability Note and compare the affected vendor and product list against your inventory. Apply vendor fixes or compensating controls for Way Picturall Quad Compact Mark II where available.

Read brief →
Jul 22, 2026 KEV Known exploited CVE-2026-16232

Check Point SmartConsole Improper Authentication Vulnerability

Check Point · SmartConsole

Check Point SmartConsole contains an improper authentication vulnerability which could allow an unauthenticated remote attacker to obtain an application login token and use it to authenticate with full administrative privileges.

Operator check

Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

Read brief →
Jul 22, 2026 Coordinated disclosure Patch review

VU#847406: Duplicati backup software v2.3.0.1 is vulnerable to an incorrect permission assignment vulnerability

Duplicati · backup software v2.3.0.1

Overview Duplicati v2.3.0.1 is vulnerable to arbitrary code execution when installed outside the default C:\Program Files\Duplicati 2\ directory. An attacker with local user privileges who can write files to the Duplicati installation directory can execute arbitrary code by placing malicious files, such as DLLs, in that directory. To mitigate this vulnerability, install Duplicati in the default C:\Program Files\ directory or update to the latest fixed version. Description Duplicati is a free, open-source backup solution that stores data across cloud and local storage platforms. On Windows, Duplicati is distributed as an MSI installer. By default, the installer deploys the application to C:\Program Files\Duplicati 2\ , where the directory inherits the standard protected ACLs provided by Windows. The following vulnerability affects... Related CVEs: CVE-2026-16157.

Operator check

Review the CERT/CC Vulnerability Note and compare the affected vendor and product list against your inventory. Apply vendor fixes or compensating controls for backup software v2.3.0.1 where available.

Read brief →
Jul 22, 2026 Vendor advisory High-risk advisory CVE-2024-7708

Eclipse Jetty: DoS attack triggering OutOfMemory with 100-Continue requests

Maven · org.eclipse.jetty:jetty-server

Eclipse Jetty: DoS attack triggering OutOfMemory with 100-Continue requests

Operator check

Check whether org.eclipse.jetty:jetty-server is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. EPSS probability: 0.3%; percentile: 17%.

Read brief →
Jul 22, 2026 Vendor advisory High-risk advisory CVE-2026-10050

Eclipse Jetty Digest Authentication: ISO-8859-1 lossy encoding allows authentication bypass via character substitution

Maven · org.eclipse.jetty:jetty-security

Eclipse Jetty Digest Authentication: ISO-8859-1 lossy encoding allows authentication bypass via character substitution

Operator check

Check whether org.eclipse.jetty:jetty-security is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. CVSS score: 8.7.

Read brief →
Jul 22, 2026 KEV Known exploited CVE-2026-50522

Microsoft SharePoint Deserialization of Untrusted Data Vulnerability

Microsoft · SharePoint

Microsoft SharePoint contains a deserialization of untrusted data vulnerability which could allow an unauthorized attacker to execute code over a network.

Operator check

Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

Read brief →
Jul 22, 2026 Vendor advisory Critical vendor advisory CVE-2026-50252

Nlnetlabs Unbound — CVE-2026-50252 (Critical)

Nlnetlabs · Unbound

In NLnet Labs Unbound 1.4.22 up to and including 1.25.1, UDP source port is randomized and intended to serve as a secret value that increases the entropy of DNS transactions. When resolver load balancing policies depend on the source port while their outcome is revealed this secrecy is undermined. The vulnerability arises when the load balancing policy is consistent with respect to the incoming source UDP port and IP address while heavily depending on the incoming source UDP port as a randomization source. When the SO_REUSEPORT configuration option is enabled ('so-reuseport: yes') in Unbound (

Operator check

Review CVE-2026-50252 in your asset inventory. Apply patches per vendor guidance and verify Unbound is not exposed. CVSS score: 9.3. EPSS probability: 0.1%; percentile: 2%.

Read brief →
Jul 22, 2026 Vendor advisory High-risk advisory CVE-2026-64642

Next.js: Middleware / Proxy bypass in App Router applications using Turbopack and single locale

npm · next

Next.js: Middleware / Proxy bypass in App Router applications using Turbopack and single locale

Operator check

Check whether next is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. CVSS score: 8.3.

Read brief →
Jul 22, 2026 Vendor advisory High-risk advisory CVE-2026-64645

Next.js: Server-Side Request Forgery in rewrites via attacker-controlled destination hostname

npm · next

Next.js: Server-Side Request Forgery in rewrites via attacker-controlled destination hostname

Operator check

Check whether next is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. CVSS score: 8.3.

Read brief →
Jul 22, 2026 Vendor advisory High-risk advisory CVE-2026-64649

Next.js: Server-Side Request Forgery in Server Actions on custom servers

npm · next

Next.js: Server-Side Request Forgery in Server Actions on custom servers

Operator check

Check whether next is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. CVSS score: 8.3.

Read brief →
Jul 22, 2026 Vendor advisory High-risk advisory CVE-2026-65016

n8n: SSO Instance-Role Provisioning Allows Privilege Escalation to Instance Owner

npm · n8n

n8n: SSO Instance-Role Provisioning Allows Privilege Escalation to Instance Owner

Operator check

Check whether n8n is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. CVSS score: 7.7.

Read brief →
Jul 22, 2026 Vendor advisory High-risk advisory

n8n: Send Email Node Arbitrary File Read and SSRF via Nodemailer Content-Object Type Confusion

npm · n8n

n8n: Send Email Node Arbitrary File Read and SSRF via Nodemailer Content-Object Type Confusion

Operator check

Check whether n8n is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. CVSS score: 8.2.

Read brief →
Jul 22, 2026 Vendor advisory High-risk advisory

n8n: Bypass "Allowed HTTP Request Domains" Credential Restriction in Multiple AI and LLM Nodes

npm · n8n

n8n: Bypass "Allowed HTTP Request Domains" Credential Restriction in Multiple AI and LLM Nodes

Operator check

Check whether n8n is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. CVSS score: 7.1.

Read brief →
Jul 22, 2026 Vendor advisory High-risk advisory

n8n: Credential Authorization Bypass via Expression in HTTP Request Node `genericAuthType`

npm · n8n

n8n: Credential Authorization Bypass via Expression in HTTP Request Node `genericAuthType`

Operator check

Check whether n8n is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. CVSS score: 7.1.

Read brief →
Jul 22, 2026 Vendor advisory High-risk advisory

n8n: Prototype Pollution via Dot-Notation Field Names Leads To Instance-Wide Denial of Service

npm · n8n

n8n: Prototype Pollution via Dot-Notation Field Names Leads To Instance-Wide Denial of Service

Operator check

Check whether n8n is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. CVSS score: 7.1.

Read brief →
Jul 22, 2026 Vendor advisory High-risk advisory CVE-2026-59822

LiteLLM: MCP Authentication Bypass via OAuth2 Passthrough Fallback

PyPI · litellm

LiteLLM: MCP Authentication Bypass via OAuth2 Passthrough Fallback

Operator check

Check whether litellm is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. CVSS score: 8.8. EPSS probability: 0.2%; percentile: 16%.

Read brief →
Jul 22, 2026 Vendor advisory High-risk advisory

JupyterLab: Image viewer allows XSS when opening malicious image in new browser tab

PyPI · jupyterlab

JupyterLab: Image viewer allows XSS when opening malicious image in new browser tab

Operator check

Check whether jupyterlab is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. CVSS score: 7.5.

Read brief →
Jul 22, 2026 Vendor advisory High-risk advisory

JupyterLab: Cross-site scripting (XSS) via crafted settings file (`overrides.json`)

PyPI · jupyterlab

JupyterLab: Cross-site scripting (XSS) via crafted settings file (`overrides.json`)

Operator check

Check whether jupyterlab is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. CVSS score: 8.6.

Read brief →
Jul 21, 2026 KEV Known exploited CVE-2021-27137

DD-WRT Stack-Based Buffer Overflow Vulnerability

DD-WRT · DD-WRT

DD-WRT contains a stack-based buffer overflow vulnerability that could allow an unauthenticated attacker to overflow an internal buffer used by UPnP and trigger a code execution vulnerability.

Operator check

Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

Read brief →
Jul 21, 2026 Vendor advisory High-risk advisory CVE-2026-20779

Gitea: TOTP TOCTOU race on web 2FA paths + missing replay check on Basic-Auth `X-Gitea-OTP` surface

Go · code.gitea.io/gitea

Gitea: TOTP TOCTOU race on web 2FA paths + missing replay check on Basic-Auth `X-Gitea-OTP` surface

Operator check

Check whether code.gitea.io/gitea is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. EPSS probability: 0.5%; percentile: 38%.

Read brief →
Jul 21, 2026 Vendor advisory High-risk advisory CVE-2026-20896

Gitea Docker image: `REVERSE_PROXY_TRUSTED_PROXIES = *` default lets any source IP impersonate any user via `X-WEBAUT...

Go · code.gitea.io/gitea

Gitea Docker image: `REVERSE_PROXY_TRUSTED_PROXIES = *` default lets any source IP impersonate any user via `X-WEBAUTH-USER`

Operator check

Check whether code.gitea.io/gitea is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. EPSS probability: 0.8%; percentile: 52%.

Read brief →
Jul 21, 2026 Vendor advisory High-risk advisory CVE-2026-22874

Gitea: Incomplete SSRF Protection in Webhook and Migration Allow-list Default Filter

Go · code.gitea.io/gitea

Gitea: Incomplete SSRF Protection in Webhook and Migration Allow-list Default Filter

Operator check

Check whether code.gitea.io/gitea is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. EPSS probability: 0.5%; percentile: 37%.

Read brief →
Jul 21, 2026 Vendor advisory High-risk advisory CVE-2026-24451

Gitea: Fork Synchronization Continues After Parent Repository Changes from Public to Private

Go · code.gitea.io/gitea

Gitea: Fork Synchronization Continues After Parent Repository Changes from Public to Private

Operator check

Check whether code.gitea.io/gitea is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. EPSS probability: 0.5%; percentile: 39%.

Read brief →
Jul 21, 2026 Vendor advisory High-risk advisory CVE-2026-25038

Gitea: Unauthorized Access to Labels of Private Organizations

Go · code.gitea.io/gitea

Gitea: Unauthorized Access to Labels of Private Organizations

Operator check

Check whether code.gitea.io/gitea is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. EPSS probability: 0.5%; percentile: 39%.

Read brief →
Jul 21, 2026 Vendor advisory High-risk advisory CVE-2026-27775

Gitea: Cached Per-Branch Permission Check in Pre-Receive Hook Allows Full Repository Write

Go · code.gitea.io/gitea

Gitea: Cached Per-Branch Permission Check in Pre-Receive Hook Allows Full Repository Write

Operator check

Check whether code.gitea.io/gitea is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. EPSS probability: 0.5%; percentile: 41%.

Read brief →
Jul 21, 2026 Vendor advisory High-risk advisory CVE-2026-54481

Gitea: Internal API HTTP client hardcodes InsecureSkipVerify:true with no config override

Go · code.gitea.io/gitea

Gitea: Internal API HTTP client hardcodes InsecureSkipVerify:true with no config override

Operator check

Check whether code.gitea.io/gitea is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.

Read brief →
Jul 21, 2026 Vendor advisory High-risk advisory CVE-2026-55987

Gitea: OAuth2 sign-in reactivates an administrator-deactivated account on auth sources without refresh tokens (incomp...

Go · code.gitea.io/gitea

Gitea: OAuth2 sign-in reactivates an administrator-deactivated account on auth sources without refresh tokens (incomplete fix of #38009)

Operator check

Check whether code.gitea.io/gitea is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.

Read brief →
Jul 21, 2026 Vendor advisory Critical vendor advisory CVE-2026-56750

Gitea Remember-Me Token Theft Not Invalidating Attacker Session

Go · code.gitea.io/gitea

Gitea Remember-Me Token Theft Not Invalidating Attacker Session

Operator check

Check whether code.gitea.io/gitea is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. CVSS score: 9.1.

Read brief →
Jul 21, 2026 Vendor advisory High-risk advisory CVE-2026-58419

Gitea: Notification API leaks private issue metadata after access revocation

Go · code.gitea.io/gitea

Gitea: Notification API leaks private issue metadata after access revocation

Operator check

Check whether code.gitea.io/gitea is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. EPSS probability: 0.3%; percentile: 22%.

Read brief →
Jul 21, 2026 Vendor advisory High-risk advisory CVE-2026-58421

Gitea: Unauthenticated ReDoS via CODEOWNERS pattern matching allows denial of service

Go · code.gitea.io/gitea

Gitea: Unauthenticated ReDoS via CODEOWNERS pattern matching allows denial of service

Operator check

Check whether code.gitea.io/gitea is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. EPSS probability: 0.3%; percentile: 25%.

Read brief →
Jul 21, 2026 Vendor advisory High-risk advisory CVE-2026-58422

Gitea: Improper authorization on OAuth sign-in callback silently re-enables administrator-disabled accounts

Go · code.gitea.io/gitea

Gitea: Improper authorization on OAuth sign-in callback silently re-enables administrator-disabled accounts

Operator check

Check whether code.gitea.io/gitea is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. CVSS score: 7.6. EPSS probability: 0.3%; percentile: 27%.

Read brief →
Jul 21, 2026 Vendor advisory High-risk advisory CVE-2026-58423

Gitea: LFS authentication bypass via malformed SSH sub-verb allows unauthorized read access to private repositories

Go · code.gitea.io/gitea

Gitea: LFS authentication bypass via malformed SSH sub-verb allows unauthorized read access to private repositories

Operator check

Check whether code.gitea.io/gitea is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. EPSS probability: 0.3%; percentile: 23%.

Read brief →
Jul 21, 2026 Vendor advisory High-risk advisory CVE-2026-58424

Gitea: Permanent Fork PR Workflow Approval Gate Bypass

Go · code.gitea.io/gitea

Gitea: Permanent Fork PR Workflow Approval Gate Bypass

Operator check

Check whether code.gitea.io/gitea is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. EPSS probability: 0.2%; percentile: 10%.

Read brief →
Jul 21, 2026 Vendor advisory High-risk advisory CVE-2026-58426

Gitea Actions Artifacts V4 signed URL HMAC ambiguity allows cross-repository artifact read and cross-task upload-stat...

Go · code.gitea.io/gitea

Gitea Actions Artifacts V4 signed URL HMAC ambiguity allows cross-repository artifact read and cross-task upload-state write

Operator check

Check whether code.gitea.io/gitea is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. EPSS probability: 0.2%; percentile: 7%.

Read brief →
Jul 21, 2026 Vendor advisory High-risk advisory CVE-2026-58436

Gitea: ParseAcceptLanguage quadratic-time DoS via Locale middleware on unauthenticated requests

Go · code.gitea.io/gitea

Gitea: ParseAcceptLanguage quadratic-time DoS via Locale middleware on unauthenticated requests

Operator check

Check whether code.gitea.io/gitea is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. CVSS score: 8.7.

Read brief →
Jul 21, 2026 Vendor advisory High-risk advisory CVE-2026-58437

Gitea: Repository Visibility Manipulation via Git Push Options

Go · code.gitea.io/gitea

Gitea: Repository Visibility Manipulation via Git Push Options

Operator check

Check whether code.gitea.io/gitea is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.

Read brief →
Jul 21, 2026 Vendor advisory High-risk advisory CVE-2026-58443

Gitea: Public-only repository tokens can update private PR head branches

Go · code.gitea.io/gitea

Gitea: Public-only repository tokens can update private PR head branches

Operator check

Check whether code.gitea.io/gitea is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.

Read brief →
Jul 21, 2026 KEV Known exploited CVE-2026-0770

Langflow Inclusion of Functionality from Untrusted Control Sphere Vulnerability

Langflow · Langflow

Langflow contains an inclusion of functionality from untrusted control sphere vulnerability that allows remote attackers to execute arbitrary code on affected installations.

Operator check

Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

Read brief →
Jul 21, 2026 Vendor advisory Critical vendor advisory CVE-2016-20096

Linknat VOS3000 and VOS2009 — CVE-2016-20096 (Critical)

Linknat · VOS3000 and VOS2009

Linknat VOS3000 and VOS2009 through version 2.1.2.0 contain an unauthenticated SQL injection vulnerability that allows remote attackers to execute arbitrary SQL commands by manipulating the name parameter in a POST request to the login endpoint. Attackers can inject malicious SQL through the login form and retrieve injected query results from a subsequent session request, enabling extraction of plaintext credentials and other database content with DBA-level privileges.

Operator check

Review CVE-2016-20096 in your asset inventory. Apply patches per vendor guidance and verify VOS3000 and VOS2009 is not exposed. CVSS score: 9.8.

Read brief →
Jul 21, 2026 Vendor advisory High-risk advisory

jackson-core: Async parser maxNumberLength bypass via chunked digit accumulation (incomplete fix for GHSA-72hv-8253-5...

Maven · com.fasterxml.jackson.core:jackson-core

jackson-core: Async parser maxNumberLength bypass via chunked digit accumulation (incomplete fix for GHSA-72hv-8253-57qq)

Operator check

Check whether com.fasterxml.jackson.core:jackson-core is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. CVSS score: 8.7.

Read brief →
Jul 21, 2026 Vendor advisory High-risk advisory CVE-2026-16221

fast-uri vulnerable to host confusion via literal backslash authority delimiter

npm · fast-uri

fast-uri vulnerable to host confusion via literal backslash authority delimiter

Operator check

Check whether fast-uri is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. EPSS probability: 0.2%; percentile: 13%.

Read brief →
Jul 21, 2026 Vendor advisory High-risk advisory CVE-2026-59891

Credential confusion in @sigstore/oci can leak registry credentials to an attacker-controlled registry

npm · @sigstore/oci

Credential confusion in @sigstore/oci can leak registry credentials to an attacker-controlled registry

Operator check

Check whether @sigstore/oci is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. EPSS probability: 0.3%; percentile: 24%.

Read brief →
Jul 21, 2026 Vendor advisory High-risk advisory

fast-xml-parser: Repeated DOCTYPE declarations reset entity expansion limits

npm · fast-xml-parser

fast-xml-parser: Repeated DOCTYPE declarations reset entity expansion limits

Operator check

Check whether fast-xml-parser is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. CVSS score: 8.7.

Read brief →
Jul 21, 2026 Vendor advisory High-risk advisory

sharp inherited vulnerabilities in libvips: CVE-2026-33327, CVE-2026-33328, CVE-2026-35590, CVE-2026-35591

npm · sharp

sharp inherited vulnerabilities in libvips: CVE-2026-33327, CVE-2026-33328, CVE-2026-35590, CVE-2026-35591

Operator check

Check whether sharp is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. CVSS score: 7.0.

Read brief →
Jul 21, 2026 Vendor advisory High-risk advisory

@vitest/browser: Browser Mode provider commands bypass the file-access permission gate

npm · @vitest/browser

@vitest/browser: Browser Mode provider commands bypass the file-access permission gate

Operator check

Check whether @vitest/browser is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.

Read brief →
Jul 21, 2026 Coordinated disclosure Patch review

VU#762226: Plane contains multi-tenant authorization bypass vulnerability

Plane · Plane

Overview The project management tool Plane, versions 1.3.0 and earlier, contains a multi-tenant authorization bypass vulnerability in its asset-management API that allows unauthorized users to access, delete, or duplicate assets that belong to other workspaces. Description Plane is an open-source project management platform that provides multi-tenant workspace isolation for users to track issues, monitor progress, and manage workflows. The platform's API supports uploading, retrieving, deleting, and duplicating files associated with issues and tasks within a workspace. CVE-2026-15342 Plane's asset-management API endpoints accept workspace slugs and asset identifiers as path parameters, but do not verify that the requesting user is authorized to access the specified workspace. As a result, an authenticated user in one workspace can supply... Related CVEs: CVE-2026-15342.

Operator check

Review the CERT/CC Vulnerability Note and compare the affected vendor and product list against your inventory. Apply vendor fixes or compensating controls for Plane where available.

Read brief →
Jul 21, 2026 Vendor advisory High-risk advisory

GitPython: Environment-variable exfiltration via os.path.expandvars() on Repo.clone_from() URL

PyPI · gitpython

GitPython: Environment-variable exfiltration via os.path.expandvars() on Repo.clone_from() URL

Operator check

Check whether gitpython is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.

Read brief →
Jul 21, 2026 KEV Known exploited CVE-2026-60137

WordPress Core SQL Injection Vulnerability

WordPress · Core

WordPress Core contains a SQL injection vulnerability when a plugin or theme passes untrusted input to the parameter. This vulnerability can be chained with CVE-2026-63030 to allow an unauthenticated attacker to gain remote code execution on default WordPress installations.

Operator check

Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

Read brief →
Jul 21, 2026 KEV Known exploited CVE-2026-63030

WordPress Core Interpretation Conflict Vulnerability

WordPress · Core

WordPress Core contains an interpretation conflict vulnerability that could allow an attacker to perform SQL Injection and achieve Remote Code Execution. This vulnerability can be chained with CVE-2026-60137.

Operator check

Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

Read brief →
Jul 20, 2026 Vendor advisory High-risk advisory CVE-2026-54560

Cloudreve: OAuth access tokens bypass scope enforcement due to missing client_id claim

Go · github.com/cloudreve/Cloudreve/v4

Cloudreve: OAuth access tokens bypass scope enforcement due to missing client_id claim

Operator check

Check whether github.com/cloudreve/Cloudreve/v4 is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. EPSS probability: 0.2%; percentile: 16%.

Read brief →
Jul 20, 2026 Vendor advisory High-risk advisory CVE-2026-55667

File Browser: Out-of-scope file deletion by a Create-only scoped user via symlink-following RemoveAll in upload failu...

Go · github.com/filebrowser/filebrowser/v2

File Browser: Out-of-scope file deletion by a Create-only scoped user via symlink-following RemoveAll in upload failure-cleanup

Operator check

Check whether github.com/filebrowser/filebrowser/v2 is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. EPSS probability: 0.4%; percentile: 28%.

Read brief →
Jul 20, 2026 Vendor advisory High-risk advisory CVE-2026-62685

File Browser: Colliding username normalization gives two users the same home directory

Go · github.com/filebrowser/filebrowser/v2

File Browser: Colliding username normalization gives two users the same home directory

Operator check

Check whether github.com/filebrowser/filebrowser/v2 is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. EPSS probability: 0.3%; percentile: 24%.

Read brief →
Jul 20, 2026 Vendor advisory Critical vendor advisory CVE-2026-41521

Neutrinolabs Xrdp — CVE-2026-41521 (Critical)

Neutrinolabs · Xrdp

xrdp is an open source RDP server. Versions 0.10.6 and prior contain an integer overflow vulnerability when processing screen update messages within the vnc-any connection mode. A malicious remote VNC server can send crafted image dimensions that cause an integer overflow during memory buffer size calculation, resulting in an undersized allocation. Subsequent processing of the incoming image data using the original oversized parameters leads to an out-of-bounds read. An unauthenticated remote attacker could exploit this flaw to disclose sensitive information from the heap memory or cause a den

Operator check

Review CVE-2026-41521 in your asset inventory. Apply patches per vendor guidance and verify Xrdp is not exposed. CVSS score: 8.2. EPSS probability: 0.6%; percentile: 45%.

Read brief →
Jul 20, 2026 Vendor advisory High-risk advisory CVE-2026-13311

shell-quote: Quadratic-complexity Denial of Service in `parse()` (CWE-407)

npm · shell-quote

shell-quote: Quadratic-complexity Denial of Service in `parse()` (CWE-407)

Operator check

Check whether shell-quote is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. CVSS score: 8.7. EPSS probability: 0.4%; percentile: 28%.

Read brief →
Jul 20, 2026 Vendor advisory High-risk advisory CVE-2026-59725

Socket.IO: Engine.IO Polling Transport Connection Exhaustion

npm · engine.io

Socket.IO: Engine.IO Polling Transport Connection Exhaustion

Operator check

Check whether engine.io is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. EPSS probability: 0.4%; percentile: 28%.

Read brief →
Jul 20, 2026 Vendor advisory High-risk advisory CVE-2026-59731

Astro: Authorization Bypass via Decode Iteration Limit and Rewrite Path Canonicalization Mismatch

npm · astro

Astro: Authorization Bypass via Decode Iteration Limit and Rewrite Path Canonicalization Mismatch

Operator check

Check whether astro is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. EPSS probability: 0.3%; percentile: 19%.

Read brief →
Jul 20, 2026 Vendor advisory High-risk advisory CVE-2026-59869

js-yaml: YAML merge-key chains can force quadratic CPU consumption

npm · js-yaml

js-yaml: YAML merge-key chains can force quadratic CPU consumption

Operator check

Check whether js-yaml is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. EPSS probability: 0.4%; percentile: 29%.

Read brief →
Jul 20, 2026 Vendor advisory High-risk advisory CVE-2026-59874

node-tar: Negative tar entry size causes infinite loop in archive replace

npm · tar

node-tar: Negative tar entry size causes infinite loop in archive replace

Operator check

Check whether tar is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. CVSS score: 8.7. EPSS probability: 0.4%; percentile: 28%.

Read brief →
Jul 20, 2026 Vendor advisory High-risk advisory CVE-2026-61835

Directus: SSRF Protection Bypass via 0.0.0.0 in File Import

npm · directus

Directus: SSRF Protection Bypass via 0.0.0.0 in File Import

Operator check

Check whether directus is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. EPSS probability: 0.2%; percentile: 16%.

Read brief →
Jul 20, 2026 Vendor advisory High-risk advisory CVE-2026-61836

Directus: Authorization-dependent response served from unsegmented cache key

npm · directus

Directus: Authorization-dependent response served from unsegmented cache key

Operator check

Check whether directus is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. EPSS probability: 0.3%; percentile: 20%.

Read brief →
Jul 20, 2026 Vendor advisory High-risk advisory

Axios Node HTTP adapter can use an inherited proxy after interceptor config cloning

npm · axios

Axios Node HTTP adapter can use an inherited proxy after interceptor config cloning

Operator check

Check whether axios is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. CVSS score: 8.3.

Read brief →
Jul 20, 2026 Vendor advisory High-risk advisory CVE-2026-47302

Microsoft Security Advisory CVE-2026-47302 – .NET Denial of Service Vulnerability

NuGet · System.Security.Cryptography.Xml

Microsoft Security Advisory CVE-2026-47302 – .NET Denial of Service Vulnerability

Operator check

Check whether System.Security.Cryptography.Xml is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. EPSS probability: 0.8%; percentile: 53%.

Read brief →
Jul 20, 2026 Vendor advisory High-risk advisory CVE-2026-47304

Microsoft Security Advisory CVE-2026-47304 – .NET Security Feature Bypass Vulnerability

NuGet · System.Security.Cryptography.Xml

Microsoft Security Advisory CVE-2026-47304 – .NET Security Feature Bypass Vulnerability

Operator check

Check whether System.Security.Cryptography.Xml is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. EPSS probability: 0.2%; percentile: 10%.

Read brief →
Jul 20, 2026 Vendor advisory High-risk advisory CVE-2026-50524

Microsoft Security Advisory CVE-2026-50524 – .NET Denial of Service Vulnerability

NuGet · Microsoft.NetCore.App.Runtime.linux-arm

Microsoft Security Advisory CVE-2026-50524 – .NET Denial of Service Vulnerability

Operator check

Check whether Microsoft.NetCore.App.Runtime.linux-arm is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. EPSS probability: 0.6%; percentile: 47%.

Read brief →
Jul 20, 2026 Vendor advisory High-risk advisory CVE-2026-50525

Microsoft Security Advisory CVE-2026-50525 – .NET Denial of Service Vulnerability

NuGet · System.Security.Cryptography.Xml

Microsoft Security Advisory CVE-2026-50525 – .NET Denial of Service Vulnerability

Operator check

Check whether System.Security.Cryptography.Xml is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. EPSS probability: 0.6%; percentile: 46%.

Read brief →
Jul 20, 2026 Vendor advisory High-risk advisory CVE-2026-50528

Microsoft Security Advisory CVE-2026-50528 – .NET Security Feature Bypass Vulnerability

NuGet · Microsoft.NetCore.App.Runtime.linux-arm

Microsoft Security Advisory CVE-2026-50528 – .NET Security Feature Bypass Vulnerability

Operator check

Check whether Microsoft.NetCore.App.Runtime.linux-arm is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. EPSS probability: 0.4%; percentile: 35%.

Read brief →
Jul 20, 2026 Vendor advisory High-risk advisory CVE-2026-50648

Microsoft Security Advisory CVE-2026-50648 – .NET Denial of Service Vulnerability

NuGet · System.Security.Cryptography.Xml

Microsoft Security Advisory CVE-2026-50648 – .NET Denial of Service Vulnerability

Operator check

Check whether System.Security.Cryptography.Xml is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. EPSS probability: 0.6%; percentile: 46%.

Read brief →
Jul 20, 2026 Vendor advisory High-risk advisory CVE-2026-50651

Microsoft Security Advisory CVE-2026-50651 – .NET Denial of Service Vulnerability

NuGet · Microsoft.NetCore.App.Runtime.linux-arm

Microsoft Security Advisory CVE-2026-50651 – .NET Denial of Service Vulnerability

Operator check

Check whether Microsoft.NetCore.App.Runtime.linux-arm is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. EPSS probability: 0.6%; percentile: 46%.

Read brief →
Jul 20, 2026 Vendor advisory High-risk advisory CVE-2026-57108

Microsoft Security Advisory CVE-2026-57108 – .NET Denial of Service Vulnerability

NuGet · Microsoft.NetCore.App.Runtime.linux-arm

Microsoft Security Advisory CVE-2026-57108 – .NET Denial of Service Vulnerability

Operator check

Check whether Microsoft.NetCore.App.Runtime.linux-arm is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. EPSS probability: 1.1%; percentile: 62%.

Read brief →
Jul 20, 2026 Vendor advisory High-risk advisory CVE-2026-59197

Pillow: Heap out-of-bounds write in `ImageFilter.RankFilter` via integer overflow in `ImagingExpand`

PyPI · Pillow

Pillow: Heap out-of-bounds write in `ImageFilter.RankFilter` via integer overflow in `ImagingExpand`

Operator check

Check whether Pillow is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. EPSS probability: 0.4%; percentile: 32%.

Read brief →
Jul 20, 2026 Vendor advisory High-risk advisory CVE-2026-59199

Pillow: Heap out-of-bounds write `Image.paste()` / `Image.crop()` via signed coordinate overflow

PyPI · Pillow

Pillow: Heap out-of-bounds write `Image.paste()` / `Image.crop()` via signed coordinate overflow

Operator check

Check whether Pillow is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. EPSS probability: 0.4%; percentile: 31%.

Read brief →
Jul 20, 2026 Vendor advisory High-risk advisory CVE-2026-59200

Pillow: Decompression Bomb DoS via PdfParser.PdfStream.decode()

PyPI · Pillow

Pillow: Decompression Bomb DoS via PdfParser.PdfStream.decode()

Operator check

Check whether Pillow is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. EPSS probability: 0.4%; percentile: 27%.

Read brief →
Jul 20, 2026 Vendor advisory High-risk advisory CVE-2026-59204

Pillow JPEG2000 tiled decode retains a growing scratch buffer and can be used for denial of service

PyPI · pillow

Pillow JPEG2000 tiled decode retains a growing scratch buffer and can be used for denial of service

Operator check

Check whether pillow is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. CVSS score: 8.7. EPSS probability: 0.4%; percentile: 32%.

Read brief →
Jul 20, 2026 Vendor advisory High-risk advisory CVE-2026-59205

Pillow: Controlled heap out-of-bounds write in Pillow `ImageCmsTransform.apply()` via output mode mismatch

PyPI · pillow

Pillow: Controlled heap out-of-bounds write in Pillow `ImageCmsTransform.apply()` via output mode mismatch

Operator check

Check whether pillow is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. EPSS probability: 0.4%; percentile: 31%.

Read brief →
Jul 20, 2026 Vendor advisory High-risk advisory CVE-2026-59922

Mistune plugins/formatting: quadratic-time parsing on long runs of `~~x~~`, `==x==`, and `^^x^^` markers (strikethrou...

PyPI · mistune

Mistune plugins/formatting: quadratic-time parsing on long runs of `~~x~~`, `==x==`, and `^^x^^` markers (strikethrough / mark / insert)

Operator check

Check whether mistune is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. EPSS probability: 0.4%; percentile: 29%.

Read brief →
Jul 20, 2026 Vendor advisory High-risk advisory CVE-2026-59925

Mistune inline_parser: quadratic-time parsing on long runs of `**x**` and `***x***` emphasis pairs

PyPI · mistune

Mistune inline_parser: quadratic-time parsing on long runs of `**x**` and `***x***` emphasis pairs

Operator check

Check whether mistune is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. EPSS probability: 0.4%; percentile: 28%.

Read brief →
Jul 20, 2026 Vendor advisory High-risk advisory CVE-2026-59928

Mistune block_parser: quadratic-time parsing on long lists of repeated reference-link definitions

PyPI · mistune

Mistune block_parser: quadratic-time parsing on long lists of repeated reference-link definitions

Operator check

Check whether mistune is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. EPSS probability: 0.4%; percentile: 29%.

Read brief →
Jul 20, 2026 Vendor advisory High-risk advisory CVE-2026-61736

LightRAG: CORS Wildcard + Credentials Enables Any-Origin Credentialed Requests

PyPI · lightrag-hku

LightRAG: CORS Wildcard + Credentials Enables Any-Origin Credentialed Requests

Operator check

Check whether lightrag-hku is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. EPSS probability: 0.3%; percentile: 23%.

Read brief →
Jul 20, 2026 Vendor advisory Critical vendor advisory CVE-2026-61740

LightRAG is Vulnerable to Authentication Bypass: hardcoded DEFAULT_TOKEN_SECRET and public /auth-status defeat LIGHTR...

PyPI · lightrag-hku

LightRAG is Vulnerable to Authentication Bypass: hardcoded DEFAULT_TOKEN_SECRET and public /auth-status defeat LIGHTRAG_API_KEY protection

Operator check

Check whether lightrag-hku is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. CVSS score: 9.3. EPSS probability: 0.4%; percentile: 30%.

Read brief →
Jul 17, 2026 Vendor advisory High-risk advisory CVE-2026-27771

Gitea has insufficient permission checks for Composer package source links

Go · code.gitea.io/gitea

Gitea has insufficient permission checks for Composer package source links

Operator check

Check whether code.gitea.io/gitea is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. EPSS probability: 40.7%; percentile: 98%.

Read brief →
Jul 17, 2026 Vendor advisory High-risk advisory

Skipper: Incomplete fix for CVE-2026-50197: an oversized body can bypass OPA deny-on-presence Rego policies

Go · github.com/zalando/skipper

Skipper: Incomplete fix for CVE-2026-50197: an oversized body can bypass OPA deny-on-presence Rego policies

Operator check

Check whether github.com/zalando/skipper is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.

Read brief →
Jul 17, 2026 Vendor advisory Critical vendor advisory CVE-2026-9135

IBM Langflow OSS 1.0.0 — CVE-2026-9135 (Critical)

IBM · Langflow OSS 1.0.0

IBM Langflow OSS 1.0.0 through 1.10.0 Langflow versions up to 1.9.2 (commit 94981c443d4918517b9e8163d70fc598dc33a32d) contain a code injection vulnerability in the Policies component's ToolGuard integration that bypasses the allow_custom_components=false security control. The vulnerability exists because the validation mechanism only checks the main component source code in node_template["code"]["value"] but fails to validate dynamic CodeInput fields that store generated ToolGuard Python files. Attackers can embed malicious Python code in these unvalidated dynamic fields, which are persisted i

Operator check

Review CVE-2026-9135 in your asset inventory. Apply patches per vendor guidance and verify Langflow OSS 1.0.0 is not exposed. CVSS score: 9.9.

Read brief →
Jul 17, 2026 Vendor advisory High-risk advisory CVE-2026-11400

AWS-JDBC Wrapper: Privilege Escalation in Aurora PostgreSQL instance

Maven · software.amazon.jdbc:aws-advanced-jdbc-wrapper

AWS-JDBC Wrapper: Privilege Escalation in Aurora PostgreSQL instance

Operator check

Check whether software.amazon.jdbc:aws-advanced-jdbc-wrapper is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. CVSS score: 8.6. EPSS probability: 0.3%; percentile: 22%.

Read brief →
Jul 17, 2026 Vendor advisory High-risk advisory CVE-2026-53597

Prompty: Arbitrary code execution via JavaScript frontmatter in TypeScript loader

npm · @prompty/core

Prompty: Arbitrary code execution via JavaScript frontmatter in TypeScript loader

Operator check

Check whether @prompty/core is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. CVSS score: 8.7. EPSS probability: 0.9%; percentile: 57%.

Read brief →
Jul 17, 2026 Vendor advisory High-risk advisory CVE-2026-55177

CloudTAK: Authenticated full-read SSRF in the /api/esri* routes — user-controlled URL fetched with no IP-classificati...

npm · @tak-ps/cloudtak

CloudTAK: Authenticated full-read SSRF in the /api/esri* routes — user-controlled URL fetched with no IP-classification guard

Operator check

Check whether @tak-ps/cloudtak is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. CVSS score: 7.6.

Read brief →
Jul 17, 2026 Vendor advisory High-risk advisory CVE-2026-53598

Prompty: Arbitrary file read via file reference expansion

PyPI · prompty

Prompty: Arbitrary file read via file reference expansion

Operator check

Check whether prompty is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. EPSS probability: 1.1%; percentile: 61%.

Read brief →
Jul 17, 2026 Vendor advisory High-risk advisory CVE-2026-54234

vLLM has Remote DoS via Invalid Recovered Token Reinjection

PyPI · vllm

vLLM has Remote DoS via Invalid Recovered Token Reinjection

Operator check

Check whether vllm is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. EPSS probability: 0.3%; percentile: 27%.

Read brief →
Jul 17, 2026 Vendor advisory High-risk advisory CVE-2026-54547

meta-ads-mcp: X-Pipeboard-Token Header Auth Bypass Reuses Operator Meta Token

PyPI · meta-ads-mcp

meta-ads-mcp: X-Pipeboard-Token Header Auth Bypass Reuses Operator Meta Token

Operator check

Check whether meta-ads-mcp is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.

Read brief →
Jul 17, 2026 Vendor advisory High-risk advisory CVE-2026-54549

meta-ads-mcp: Server-Side Request Forgery (SSRF) in `upload_ad_image` via Unrestricted `image_url` Fetch

PyPI · meta-ads-mcp

meta-ads-mcp: Server-Side Request Forgery (SSRF) in `upload_ad_image` via Unrestricted `image_url` Fetch

Operator check

Check whether meta-ads-mcp is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.

Read brief →
Jul 17, 2026 Vendor advisory High-risk advisory CVE-2026-54567

Flask-Reuploaded: Extension-denylist bypass via case-folding asymmetry in name-override path (incomplete-fix variant ...

PyPI · Flask-Reuploaded

Flask-Reuploaded: Extension-denylist bypass via case-folding asymmetry in name-override path (incomplete-fix variant of CVE-2026-27641)

Operator check

Check whether Flask-Reuploaded is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.

Read brief →
Jul 17, 2026 Vendor advisory High-risk advisory CVE-2026-55574

vLLM: ReDoS via structured_outputs.regex compiled without timeout in xgrammar and outlines backends

PyPI · vllm

vLLM: ReDoS via structured_outputs.regex compiled without timeout in xgrammar and outlines backends

Operator check

Check whether vllm is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. CVSS score: 8.7. EPSS probability: 0.3%; percentile: 25%.

Read brief →
Jul 16, 2026 Vendor advisory High-risk advisory CVE-2026-54540

Pheditor has an authenticated terminal command whitelist bypass

Composer · pheditor/pheditor

Pheditor has an authenticated terminal command whitelist bypass

Operator check

Check whether pheditor/pheditor is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.

Read brief →
Jul 16, 2026 Vendor advisory High-risk advisory CVE-2026-55578

Pheditor: Incomplete command sanitization in terminal feature allows RCE via pipe operator, backtick substitution, an...

Composer · pheditor/pheditor

Pheditor: Incomplete command sanitization in terminal feature allows RCE via pipe operator, backtick substitution, and newline injection

Operator check

Check whether pheditor/pheditor is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.

Read brief →
Jul 16, 2026 Vendor advisory High-risk advisory CVE-2026-55579

Pheditor: Hardcoded default password 'admin' with no forced change enables full application compromise

Composer · pheditor/pheditor

Pheditor: Hardcoded default password 'admin' with no forced change enables full application compromise

Operator check

Check whether pheditor/pheditor is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.

Read brief →
Jul 16, 2026 KEV Known exploited CVE-2026-25089

Fortinet FortiSandbox OS Command Injection Vulnerability

Fortinet · FortiSandbox

Fortinet FortiSandbox, FortiSandbox Cloud, and FortiSandbox PaaS contain an OS command injection vulnerability that allows an unauthenticated attacker to execute unauthorized commands via specifically crafted HTTP requests.

Operator check

Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

Read brief →
Jul 16, 2026 KEV Known exploited CVE-2026-39808

Fortinet FortiSandbox OS Command Injection Vulnerability

Fortinet · FortiSandbox

Fortinet FortiSandbox contains an OS command injection vulnerability that could allow an unauthenticated attacker to execute unauthorized code or commands via crafted HTTP requests.

Operator check

Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

Read brief →
Jul 16, 2026 Vendor advisory High-risk advisory CVE-2026-52833

Nuclio: Unsanitized runtimeAttributes.repositories injected into Groovy build.gradle leads to build-time RCE

Go · github.com/nuclio/nuclio

Nuclio: Unsanitized runtimeAttributes.repositories injected into Groovy build.gradle leads to build-time RCE

Operator check

Check whether github.com/nuclio/nuclio is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.

Read brief →
Jul 16, 2026 Vendor advisory High-risk advisory CVE-2026-53713

Envoy Gateway: Authentication Bypass via Improper Input Validation in EnvoyExtensionPolicy Lua Allows Secret Disclosure

Go · github.com/envoyproxy/gateway

Envoy Gateway: Authentication Bypass via Improper Input Validation in EnvoyExtensionPolicy Lua Allows Secret Disclosure

Operator check

Check whether github.com/envoyproxy/gateway is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.

Read brief →
Jul 16, 2026 Vendor advisory High-risk advisory CVE-2026-53714

Envoy Gateway: xDS Control Plane Information Disclosure when operating in GatewayNamespaceMode

Go · github.com/envoyproxy/gateway

Envoy Gateway: xDS Control Plane Information Disclosure when operating in GatewayNamespaceMode

Operator check

Check whether github.com/envoyproxy/gateway is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.

Read brief →
Jul 16, 2026 Vendor advisory Critical vendor advisory CVE-2026-56453

Hcltech Dfxanalytics — CVE-2026-56453 (Critical)

Hcltech · Dfxanalytics

HCL DFXAnalytics is affected by an Account Takeover via Response Manipulation vulnerability. A remote attacker can intercept and alter the contents of the server's HTTP responses before they reach the client application, allowing them to manipulate the authentication or authorization logic to bypass controls and gain unauthorized access to targeted user accounts.

Operator check

Review CVE-2026-56453 in your asset inventory. Apply patches per vendor guidance and verify Dfxanalytics is not exposed. CVSS score: 5.5. EPSS probability: 0.2%; percentile: 6%.

Read brief →
Jul 16, 2026 Coordinated disclosure Patch review

VU#885548: Denial-of-service vulnerability in HTTP/2 servers via stalled flow-control conditions

HTTP/2 · servers via stalled flow-control conditions

Overview A denial-of-service (DoS) vulnerability exists in some HTTP/2 server implementations that fail to adequately limit resource consumption when buffering response data under stalled flow-control conditions. A remote, unauthenticated attacker can trigger memory exhaustion and service interruption by using standard flow-control parameters such as SETTINGS_INITIAL_WINDOW_SIZE = 0 to stall outbound data for multiple simultaneous request streams. Description HTTP/2 is a widely used application-layer protocol that supports multiplexing, header compression, and flow-control mechanisms to regulate the transmission of data between web browsers and servers. Flow control is designed to prevent senders from overwhelming receivers and relies on client-advertised window sizes to determine the maximum volume of unacknowledged data that can be in...

Operator check

Review the CERT/CC Vulnerability Note and compare the affected vendor and product list against your inventory. Apply vendor fixes or compensating controls for servers via stalled flow-control conditions where available.

Read brief →
Jul 16, 2026 Vendor advisory High-risk advisory CVE-2026-54076

ArcadeDB: Read-only users can mutate database schema (incomplete fix of CVE-2026-44221)

Maven · com.arcadedb:arcadedb-engine

ArcadeDB: Read-only users can mutate database schema (incomplete fix of CVE-2026-44221)

Operator check

Check whether com.arcadedb:arcadedb-engine is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.

Read brief →
Jul 16, 2026 Vendor advisory High-risk advisory CVE-2026-54077

ArcadeDB: IMPORT DATABASE allows SSRF and arbitrary local file read by authenticated users

Maven · com.arcadedb:arcadedb-engine

ArcadeDB: IMPORT DATABASE allows SSRF and arbitrary local file read by authenticated users

Operator check

Check whether com.arcadedb:arcadedb-engine is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.

Read brief →
Jul 16, 2026 Vendor advisory High-risk advisory

ArcadeDB: Privilege escalation via reader role in /api/v1/command JS scripting language — arbitrary host file read

Maven · com.arcadedb:arcadedb-server

ArcadeDB: Privilege escalation via reader role in /api/v1/command JS scripting language — arbitrary host file read

Operator check

Check whether com.arcadedb:arcadedb-server is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.

Read brief →
Jul 16, 2026 Vendor advisory High-risk advisory

ArcadeDB: Scripting authorization gate (GHSA-48qw-824m-86pr) bypassed via SQL DEFINE FUNCTION ... LANGUAGE js

Maven · com.arcadedb:arcadedb-engine

ArcadeDB: Scripting authorization gate (GHSA-48qw-824m-86pr) bypassed via SQL DEFINE FUNCTION ... LANGUAGE js

Operator check

Check whether com.arcadedb:arcadedb-engine is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. CVSS score: 8.7.

Read brief →
Jul 16, 2026 Vendor advisory High-risk advisory

ArcadeDB has cross-database IDOR: /ts/*, /batch/*, Prometheus and Grafana handlers bypass authorization

Maven · com.arcadedb:arcadedb-server

ArcadeDB has cross-database IDOR: /ts/*, /batch/*, Prometheus and Grafana handlers bypass authorization

Operator check

Check whether com.arcadedb:arcadedb-server is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. CVSS score: 7.1.

Read brief →
Jul 16, 2026 Vendor advisory High-risk advisory

ArcadeDB: Trigger scripts run with java.lang.* allowed, enabling OS command execution (RCE)

Maven · com.arcadedb:arcadedb-engine

ArcadeDB: Trigger scripts run with java.lang.* allowed, enabling OS command execution (RCE)

Operator check

Check whether com.arcadedb:arcadedb-engine is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. CVSS score: 8.6.

Read brief →
Jul 16, 2026 Vendor advisory High-risk advisory CVE-2026-52869

MCP Python SDK: HTTP transports serve session requests without verifying the authenticated principal

PyPI · mcp

MCP Python SDK: HTTP transports serve session requests without verifying the authenticated principal

Operator check

Check whether mcp is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. EPSS probability: 0.3%; percentile: 16%.

Read brief →
Jul 16, 2026 Vendor advisory High-risk advisory CVE-2026-52870

MCP Python SDK: Experimental task handlers allow any client to access and cancel other clients' tasks

PyPI · mcp

MCP Python SDK: Experimental task handlers allow any client to access and cancel other clients' tasks

Operator check

Check whether mcp is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. EPSS probability: 0.2%; percentile: 13%.

Read brief →
Jul 16, 2026 Vendor advisory High-risk advisory CVE-2026-59950

MCP Python SDK: WebSocket server transport does not support Host/Origin validation

PyPI · mcp

MCP Python SDK: WebSocket server transport does not support Host/Origin validation

Operator check

Check whether mcp is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. CVSS score: 7.6. EPSS probability: 0.2%; percentile: 8%.

Read brief →
Jul 16, 2026 Coordinated disclosure Patch review

VU#326070: SGLang contains a vulnerable pickle deserialization vulnerability through the expert-parallel subsystem

SGLang · SGLang

Overview A Pickle deserialization vulnerability has been discovered within the SGLang project , enabling an attacker to perform remote code execution (RCE) on the target vulnerable server. In order for an attacker to exploit this vulnerability, the expert-parallel backup subsystem must be enabled, and an attacker must have network access to the SGLang service. No patch is available at this time, and no response was obtained from the project maintainers during coordination. Description SGLang is an open-source framework for serving large language models (LLMs) and multimodal AI models, supporting models such as Qwen, DeepSeek, Mistral, and Skywork, and is compatible with OpenAI APIs. A vulnerability has been discovered within the tool and is tracked as follows: CVE-2026-14890 SGLang uses an expert-parallel backup subsystem designed to... Related CVEs: CVE-2026-14890, CVE-2026-7301, CVE-2026-7304.

Operator check

Review the CERT/CC Vulnerability Note and compare the affected vendor and product list against your inventory. Apply vendor fixes or compensating controls for SGLang where available.

Read brief →
Jul 16, 2026 Vendor advisory Critical vendor advisory CVE-2026-44596

Spaceapplications Yamcs — CVE-2026-44596 (Critical)

Spaceapplications · Yamcs

Yamcs is a mission control framework. Prior to 5.12.7, the authentication endpoint POST /auth/token in yamcs-core, handled by yamcs-core/src/main/java/org/yamcs/http/auth/AuthHandler.java, lacked any rate limiting, account lockout, or failed-attempt throttling, so an unauthenticated remote attacker could perform unlimited password-guessing attempts against any user account, significantly increasing the risk of successful brute-force attacks. This issue is fixed in versions 5.12.7 and 5.13.0.

Operator check

Review CVE-2026-44596 in your asset inventory. Apply patches per vendor guidance and verify Yamcs is not exposed. CVSS score: 6.5. EPSS probability: 1.4%; percentile: 69%.

Read brief →
Jul 15, 2026 Vendor advisory Critical vendor advisory CVE-2026-47156

MantisBT: SOAP API Authentication Bypass with Privilege Escalation to Administrator

Composer · mantisbt/mantisbt

MantisBT: SOAP API Authentication Bypass with Privilege Escalation to Administrator

Operator check

Check whether mantisbt/mantisbt is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. CVSS score: 9.3.

Read brief →
Jul 15, 2026 Vendor advisory Critical vendor advisory CVE-2026-52881

MantisBT: Reflected XSS in admin/install.php via unescaped printf

Composer · mantisbt/mantisbt

MantisBT: Reflected XSS in admin/install.php via unescaped printf

Operator check

Check whether mantisbt/mantisbt is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. CVSS score: 9.2.

Read brief →
Jul 15, 2026 Vendor advisory High-risk advisory CVE-2026-54491

Koel: Incomplete fix for CVE-2026-47260 — systemic SSRF in podcast & radio fetch paths

Composer · phanan/koel

Koel: Incomplete fix for CVE-2026-47260 — systemic SSRF in podcast & radio fetch paths

Operator check

Check whether phanan/koel is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.

Read brief →
Jul 15, 2026 Vendor advisory High-risk advisory CVE-2026-62944

MantisBT: Stored XSS in print_all_bug_page_word.php

Composer · mantisbt/mantisbt

MantisBT: Stored XSS in print_all_bug_page_word.php

Operator check

Check whether mantisbt/mantisbt is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. CVSS score: 8.6.

Read brief →
Jul 15, 2026 Vendor advisory High-risk advisory CVE-2026-54451

Protobuf: Unbounded recursion depth in embedded-message decoding

erlang · protobuf

Protobuf: Unbounded recursion depth in embedded-message decoding

Operator check

Check whether protobuf is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. CVSS score: 8.2.

Read brief →
Jul 15, 2026 Vendor advisory High-risk advisory CVE-2026-50274

dd-trace-go: Improper parsing of W3C baggage headers may lead to DoS

Go · github.com/DataDog/dd-trace-go

dd-trace-go: Improper parsing of W3C baggage headers may lead to DoS

Operator check

Check whether github.com/DataDog/dd-trace-go is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.

Read brief →
Jul 15, 2026 Vendor advisory High-risk advisory CVE-2026-50285

Pomerium Pre-Auth Memory Exhaustion via Unbounded zstd Decompression in HPKE Callback

Go · github.com/pomerium/pomerium

Pomerium Pre-Auth Memory Exhaustion via Unbounded zstd Decompression in HPKE Callback

Operator check

Check whether github.com/pomerium/pomerium is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.

Read brief →
Jul 15, 2026 KEV Known exploited CVE-2023-4346

KNX Association KNX Protocol Connection Authorization Option 1 Overly Restrictive Account Lockout Mechanism Vulnerabi...

KNX Association · KNX Protocol Connection Authorization Option 1

KNX Association KNX Protocol Connection Authorization Option 1 contains an overly restrictive account lockout mechanism vulnerability that could allow an attacker to purge all devices without additional security options enabled and set a BCU key to lock the device.

Operator check

Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

Read brief →
Jul 15, 2026 Vendor advisory High-risk advisory CVE-2026-50270

dd-trace-java: Improper parsing of W3C baggage headers may lead to DoS

Maven · com.datadoghq:dd-java-agent

dd-trace-java: Improper parsing of W3C baggage headers may lead to DoS

Operator check

Check whether com.datadoghq:dd-java-agent is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.

Read brief →
Jul 15, 2026 Vendor advisory High-risk advisory CVE-2026-50289

systeminformation: OS command injection in networkInterfaces() via interfaces(5) source-directive path on Linux

npm · systeminformation

systeminformation: OS command injection in networkInterfaces() via interfaces(5) source-directive path on Linux

Operator check

Check whether systeminformation is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. CVSS score: 8.7.

Read brief →
Jul 15, 2026 Vendor advisory Critical vendor advisory CVE-2026-54466

websocket-driver: Message corruption via abuse of protocol length headers

npm · websocket-driver

websocket-driver: Message corruption via abuse of protocol length headers

Operator check

Check whether websocket-driver is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. CVSS score: 9.2.

Read brief →
Jul 15, 2026 Vendor advisory High-risk advisory CVE-2026-54504

@andrea9293/mcp-documentation-server: Web UI API binds to all interfaces without authentication by default

npm · @andrea9293/mcp-documentation-server

@andrea9293/mcp-documentation-server: Web UI API binds to all interfaces without authentication by default

Operator check

Check whether @andrea9293/mcp-documentation-server is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.

Read brief →
Jul 15, 2026 Vendor advisory High-risk advisory

obsidian-local-rest-api: Authenticated path traversal via URL-encoded %2F in /vault/{path} — arbitrary host file read...

npm · obsidian-local-rest-api

obsidian-local-rest-api: Authenticated path traversal via URL-encoded %2F in /vault/{path} — arbitrary host file read/write/delete

Operator check

Check whether obsidian-local-rest-api is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.

Read brief →
Jul 15, 2026 Vendor advisory High-risk advisory CVE-2026-50273

dd-trace-dotnet: Improper parsing of W3C baggage headers may lead to DoS

NuGet · Datadog.Trace

dd-trace-dotnet: Improper parsing of W3C baggage headers may lead to DoS

Operator check

Check whether Datadog.Trace is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.

Read brief →
Jul 15, 2026 Vendor advisory Critical vendor advisory CVE-2026-56398

Openwebui Open Webui — CVE-2026-56398 (Critical)

Openwebui · Open Webui

Open WebUI before 0.9.5 contains a stored cross-site scripting vulnerability in the OAuth authentication flow where the picture claim URL MIME type is inferred from file extension rather than Content-Type header, allowing SVG files to bypass the profile image validator and be stored as data URIs. Authenticated users who visit the profile image endpoint receive attacker-controlled SVG content with inline disposition and no default security headers, enabling script execution in the same origin to steal authentication tokens and achieve account takeover.

Operator check

Review CVE-2026-56398 in your asset inventory. Apply patches per vendor guidance and verify Open Webui is not exposed. CVSS score: 7.3. EPSS probability: 0.3%; percentile: 26%.

Read brief →
Jul 15, 2026 Vendor advisory Critical vendor advisory CVE-2026-56400

Openwebui Open Webui — CVE-2026-56400 (Critical)

Openwebui · Open Webui

open-webui before 0.3.14 contains a cross-origin resource sharing misconfiguration allowing arbitrary origins with allow_origins=* and authenticated requests to the /api/v1/functions endpoint. Attackers can execute arbitrary code on the openwebui instance by crafting malicious cross-site requests from attacker-controlled websites when an admin user visits them.

Operator check

Review CVE-2026-56400 in your asset inventory. Apply patches per vendor guidance and verify Open Webui is not exposed. CVSS score: 8.3. EPSS probability: 0.3%; percentile: 20%.

Read brief →
Jul 15, 2026 KEV Known exploited CVE-2026-46817

Oracle E-Business Suite Improper Privilege Management Vulnerability

Oracle · E-Business Suite

Oracle E-Business Suite contains an improper privilege management vulnerability that allows an unauthenticated attacker with network access via HTTP to compromise Oracle Payments. Successful attacks of this vulnerability can result in takeover of Oracle Payments.

Operator check

Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

Read brief →
Jul 15, 2026 Coordinated disclosure Patch review

VU#529388: Privilege escalation vulnerability via unprotected IOCTL interface in Pegatron Tdelo64.sys

Pegatron · Tdelo64.sys

Overview A privilege escalation vulnerability exists in the tdeio64.sys driver due to an unprotected input/output control (IOCTL) dispatch routine that fails to validate the origin and permissions of user-supplied requests. An unprivileged local attacker can abuse exposed IOCTL dispatch routines [RM1.1][MB1.2]to perform arbitrary kernel memory read and write operations, ultimately obtaining NT AUTHORITY\SYSTEM privileges and compromising the security of the affected system. Description The tdeio64.sys driver distributed by Pegatron Corporation, a Taiwanese electronics manufacturer that produces motherboards and OEM components, is a Windows Driver Model (WDM) driver that provides low-level access to system I/O ports and hardware components. The driver exposes the \\.\TdeIo device interface and processes privileged IOTL requests without... Related CVEs: CVE-2026-14960, CVE-2026-14961.

Operator check

Review the CERT/CC Vulnerability Note and compare the affected vendor and product list against your inventory. Apply vendor fixes or compensating controls for Tdelo64.sys where available.

Read brief →
Jul 15, 2026 Vendor advisory High-risk advisory CVE-2026-54457

TensorZero Gateway: Arbitrary file read and SSRF in internal object storage endpoint

PyPI · tensorzero

TensorZero Gateway: Arbitrary file read and SSRF in internal object storage endpoint

Operator check

Check whether tensorzero is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.

Read brief →
Jul 15, 2026 Vendor advisory High-risk advisory

django-haystack: Remote Code Execution via `eval()` in Elasticsearch Result Deserialization

PyPI · django-haystack

django-haystack: Remote Code Execution via `eval()` in Elasticsearch Result Deserialization

Operator check

Check whether django-haystack is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. CVSS score: 8.7.

Read brief →
Jul 15, 2026 Coordinated disclosure Patch review

VU#725167: node-forge Signature Forgery Vulnerabilities in RSA-PKCS and ED25519 Implementations

RSA-PKCS · and ED25519 Implementations

Overview Two distinct cryptographic signature verification vulnerabilities exist in Digital Bazaar node-forge, a widely used JavaScript library implementing cryptographic primitives for Node.js and browser environments. These vulnerabilities allow attackers to forge RSA (PKCS#1 v1.5) and Ed25519 signatures under specific, exploitable conditions. Description Both vulnerabilities stem from insufficient enforcement of canonical cryptographic structures during verification: in the RSA case, non-standard ASN.1 encodings and undersized padding are accepted; in the Ed25519 case, non-canonical signature scalars are not rejected. As a result, node-forge accepts signatures that appear valid internally but are rejected by industry-standard libraries such as OpenSSL and Node.js’s native crypto module. The vulnerabilities affect node-forge versions... Related CVEs: CVE-2026-33894, CVE-2026-33895.

Operator check

Review the CERT/CC Vulnerability Note and compare the affected vendor and product list against your inventory. Apply vendor fixes or compensating controls for and ED25519 Implementations where available.

Read brief →
Jul 15, 2026 Vendor advisory High-risk advisory CVE-2026-50276

dd-trace-rb: Improper parsing of W3C baggage headers may lead to DoS

RubyGems · datadog

dd-trace-rb: Improper parsing of W3C baggage headers may lead to DoS

Operator check

Check whether datadog is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.

Read brief →
Jul 14, 2026 Vendor advisory Critical vendor advisory CVE-2026-47984

Adobe Commerce — CVE-2026-47984 (Critical)

Adobe · Commerce

Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass security measures and gain unauthorized read and write access. Exploitation of this issue does not require user interaction.

Operator check

Review CVE-2026-47984 in your asset inventory. Apply patches per vendor guidance and verify Commerce is not exposed. CVSS score: 8.2. EPSS probability: 0.5%; percentile: 41%.

Read brief →
Jul 14, 2026 Vendor advisory Critical vendor advisory CVE-2026-47988

Adobe Commerce — CVE-2026-47988 (Critical)

Adobe · Commerce

Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass security measures and gain unauthorized read and write access. Exploitation of this issue does not require user interaction.

Operator check

Review CVE-2026-47988 in your asset inventory. Apply patches per vendor guidance and verify Commerce is not exposed. CVSS score: 8.6. EPSS probability: 0.5%; percentile: 42%.

Read brief →
Jul 14, 2026 Vendor advisory Critical vendor advisory CVE-2026-48284

Adobe Coldfusion — CVE-2026-48284 (Critical)

Adobe · Coldfusion

ColdFusion is affected by an Improper Input Validation vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue does not require user interaction. Scope is changed.

Operator check

Review CVE-2026-48284 in your asset inventory. Apply patches per vendor guidance and verify Coldfusion is not exposed. CVSS score: 9.6. EPSS probability: 2.2%; percentile: 80%.

Read brief →
Jul 14, 2026 Vendor advisory Critical vendor advisory CVE-2026-48319

Adobe Coldfusion — CVE-2026-48319 (Critical)

Adobe · Coldfusion

ColdFusion is affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue does not require user interaction. Scope is changed.

Operator check

Review CVE-2026-48319 in your asset inventory. Apply patches per vendor guidance and verify Coldfusion is not exposed. CVSS score: 9.1. EPSS probability: 0.9%; percentile: 57%.

Read brief →
Jul 14, 2026 Vendor advisory Critical vendor advisory CVE-2026-48320

Adobe Coldfusion — CVE-2026-48320 (Critical)

Adobe · Coldfusion

ColdFusion is affected by a reflected Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this vulnerability to inject malicious scripts into a web page, potentially gaining elevated access or control over the victim's account or session. Exploitation of this issue requires user interaction in that a victim must open a malicious file. Scope is changed.

Operator check

Review CVE-2026-48320 in your asset inventory. Apply patches per vendor guidance and verify Coldfusion is not exposed. CVSS score: 8.5. EPSS probability: 3.8%; percentile: 89%.

Read brief →
Jul 14, 2026 Vendor advisory Critical vendor advisory CVE-2026-48321

Adobe Coldfusion — CVE-2026-48321 (Critical)

Adobe · Coldfusion

ColdFusion is affected by an Incorrect Authorization vulnerability that could result in privilege escalation. An attacker could leverage this vulnerability to gain unauthorized read and write access. Exploitation of this issue does not require user interaction. Scope is changed.

Operator check

Review CVE-2026-48321 in your asset inventory. Apply patches per vendor guidance and verify Coldfusion is not exposed. CVSS score: 9.3. EPSS probability: 0.2%; percentile: 15%.

Read brief →
Jul 14, 2026 Vendor advisory Critical vendor advisory CVE-2026-48356

Adobe Commerce — CVE-2026-48356 (Critical)

Adobe · Commerce

Adobe Commerce is affected by an Unrestricted Upload of File with Dangerous Type vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to inject malicious scripts into a web page, potentially gaining elevated access or control over the victim's account or session. Exploitation of this issue requires user interaction in that a victim must visit a maliciously crafted URL or interact with a compromised web page. Scope is changed.

Operator check

Review CVE-2026-48356 in your asset inventory. Apply patches per vendor guidance and verify Commerce is not exposed. CVSS score: 9.6. EPSS probability: 28.3%; percentile: 98%.

Read brief →
Jul 14, 2026 Vendor advisory Critical vendor advisory CVE-2026-48358

Adobe Commerce — CVE-2026-48358 (Critical)

Adobe · Commerce

Adobe Commerce is affected by an Improper Encoding or Escaping of Output vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue does not require user interaction. Scope is changed.

Operator check

Review CVE-2026-48358 in your asset inventory. Apply patches per vendor guidance and verify Commerce is not exposed. CVSS score: 9.1. EPSS probability: 0.9%; percentile: 56%.

Read brief →
Jul 14, 2026 Vendor advisory Critical vendor advisory CVE-2026-58319

Apache Doris — CVE-2026-58319 (Critical)

Apache · Doris

Certain Apache Doris FE HTTP REST administrative APIs were accessible without proper authentication. An unauthenticated attacker with network access to the FE HTTP service could perform unauthorized administrative operations, potentially affecting cluster integrity and availability and leading to cluster instability or denial of service. This issue affects Apache Doris versions prior to 3.1.0. Users are advised to upgrade to Apache Doris 3.1.0 or later.

Operator check

Review CVE-2026-58319 in your asset inventory. Apply patches per vendor guidance and verify Doris is not exposed. CVSS score: 9.1. EPSS probability: 0.3%; percentile: 17%.

Read brief →
Jul 14, 2026 Vendor advisory Critical vendor advisory CVE-2026-62390

Apache Kylin — CVE-2026-62390 (Critical)

Apache · Kylin

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Kylin. A backend API refreshing table catalog may cause the injection to the generated SQL. This issue affects Apache Kylin: from 4 through 5.0.3. Users are recommended to upgrade to version 5.0.4, which fixes the issue.

Operator check

Review CVE-2026-62390 in your asset inventory. Apply patches per vendor guidance and verify Kylin is not exposed. CVSS score: 9.8.

Read brief →
Jul 14, 2026 Vendor advisory Critical vendor advisory CVE-2026-62392

Apache Kylin — CVE-2026-62392 (Critical)

Apache · Kylin

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Apache Kylin. A backend API may bring job config parameters to OS command line. This issue affects Apache Kylin: from 4 through 5.0.3. Users are recommended to upgrade to version 5.0.4, which fixes the issue.

Operator check

Review CVE-2026-62392 in your asset inventory. Apply patches per vendor guidance and verify Kylin is not exposed. CVSS score: 9.8.

Read brief →
Jul 14, 2026 Vendor advisory High-risk advisory CVE-2026-45262

FacturaScripts: Authenticated SQL injection in the FacturaScripts REST API filter parameter via parenthesis bypass in...

Composer · facturascripts/facturascripts

FacturaScripts: Authenticated SQL injection in the FacturaScripts REST API filter parameter via parenthesis bypass in `Where::sqlColumn`

Operator check

Check whether facturascripts/facturascripts is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.

Read brief →
Jul 14, 2026 Vendor advisory High-risk advisory CVE-2026-45263

FacturaScripts: CSV formula injection in CSVExport allows authenticated low-priv users to plant payloads that execute...

Composer · facturascripts/facturascripts

FacturaScripts: CSV formula injection in CSVExport allows authenticated low-priv users to plant payloads that execute when an admin opens the export

Operator check

Check whether facturascripts/facturascripts is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.

Read brief →
Jul 14, 2026 Vendor advisory High-risk advisory CVE-2026-45693

FacturaScripts: Unauthenticated Path Traversal in Static File Controllers Reads Private MyFiles Documents

Composer · facturascripts/facturascripts

FacturaScripts: Unauthenticated Path Traversal in Static File Controllers Reads Private MyFiles Documents

Operator check

Check whether facturascripts/facturascripts is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.

Read brief →
Jul 14, 2026 Vendor advisory Critical vendor advisory CVE-2026-52824

Kimai: Default APP_SECRET in Docker Image Enables Cookie Forgery and Account Takeover

Composer · kimai/kimai

Kimai: Default APP_SECRET in Docker Image Enables Cookie Forgery and Account Takeover

Operator check

Check whether kimai/kimai is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. CVSS score: 9.1.

Read brief →
Jul 14, 2026 Vendor advisory High-risk advisory CVE-2026-52827

Kimai: Pre-2FA KIMAI_SESSION cookie grants full authenticated REST API access, bypassing TOTP

Composer · kimai/kimai

Kimai: Pre-2FA KIMAI_SESSION cookie grants full authenticated REST API access, bypassing TOTP

Operator check

Check whether kimai/kimai is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. CVSS score: 7.1.

Read brief →
Jul 14, 2026 Vendor advisory High-risk advisory CVE-2026-54087

EasyAdmin: Stored Cross-Site Scripting (XSS) via uploaded files served inline in FileField and ImageField

Composer · easycorp/easyadmin-bundle

EasyAdmin: Stored Cross-Site Scripting (XSS) via uploaded files served inline in FileField and ImageField

Operator check

Check whether easycorp/easyadmin-bundle is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.

Read brief →
Jul 14, 2026 Vendor advisory High-risk advisory

FacturaScripts: Path traversal in UploadedFile::move() via getClientOriginalName() — arbitrary file write outside MyF...

Composer · facturascripts/facturascripts

FacturaScripts: Path traversal in UploadedFile::move() via getClientOriginalName() — arbitrary file write outside MyFiles/ leading to RCE

Operator check

Check whether facturascripts/facturascripts is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.

Read brief →
Jul 14, 2026 Vendor advisory Critical vendor advisory CVE-2026-59836

Fortinet Forticlientems — CVE-2026-59836 (Critical)

Fortinet · Forticlientems

A improper certificate validation vulnerability in Fortinet FortiClientEMS 7.4.3 through 7.4.5, FortiClientEMS 7.4.0 through 7.4.1, FortiClientEMS 7.2 all versions may allow attacker to information disclosure via <insert attack vector here>

Operator check

Review CVE-2026-59836 in your asset inventory. Apply patches per vendor guidance and verify Forticlientems is not exposed. CVSS score: 7.5. EPSS probability: 0.1%; percentile: 2%.

Read brief →
Jul 14, 2026 Vendor advisory High-risk advisory CVE-2026-44300

OpenCost ServiceKey Endpoint Unauthorized Credential Overwrite/Injection

Go · github.com/opencost/opencost

OpenCost ServiceKey Endpoint Unauthorized Credential Overwrite/Injection

Operator check

Check whether github.com/opencost/opencost is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. CVSS score: 8.8.

Read brief →
Jul 14, 2026 Vendor advisory High-risk advisory CVE-2026-50006

Anyquery: Arbitrary File Write (AFW) which could lead to Remote Code Execution (RCE) via Unrestricted ATTACH DATABASE...

Go · github.com/julien040/anyquery

Anyquery: Arbitrary File Write (AFW) which could lead to Remote Code Execution (RCE) via Unrestricted ATTACH DATABASE in Server Mode

Operator check

Check whether github.com/julien040/anyquery is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.

Read brief →
Jul 14, 2026 Vendor advisory High-risk advisory CVE-2026-50013

Hoverfly: Process Crash via Concurrent Map Write Race Condition in Diff Mode

Go · github.com/SpectoLabs/hoverfly

Hoverfly: Process Crash via Concurrent Map Write Race Condition in Diff Mode

Operator check

Check whether github.com/SpectoLabs/hoverfly is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.

Read brief →
Jul 14, 2026 Vendor advisory High-risk advisory CVE-2026-50125

MKP: Unbounded Pod Log Read via Attacker-Controlled `limitBytes`/`tailLines` Causes Memory Exhaustion

Go · github.com/StacklokLabs/mkp

MKP: Unbounded Pod Log Read via Attacker-Controlled `limitBytes`/`tailLines` Causes Memory Exhaustion

Operator check

Check whether github.com/StacklokLabs/mkp is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.

Read brief →
Jul 14, 2026 Vendor advisory High-risk advisory CVE-2026-50141

Woodpecker gRPC agent_id metadata can be spoofed- cross-tenant agent impersonation

Go · go.woodpecker-ci.org/woodpecker/v3

Woodpecker gRPC agent_id metadata can be spoofed- cross-tenant agent impersonation

Operator check

Check whether go.woodpecker-ci.org/woodpecker/v3 is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. CVSS score: 7.1. EPSS probability: 0.2%; percentile: 16%.

Read brief →
Jul 14, 2026 Vendor advisory High-risk advisory CVE-2026-50158

yutu: Arbitrary File Write via MCP `caption-download` Tool

Go · github.com/eat-pray-ai/yutu

yutu: Arbitrary File Write via MCP `caption-download` Tool

Operator check

Check whether github.com/eat-pray-ai/yutu is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.

Read brief →
Jul 14, 2026 Vendor advisory High-risk advisory CVE-2026-53603

nebula-mesh: Operator session tokens stored in plaintext in the database

Go · github.com/forgekeep/nebula-mesh

nebula-mesh: Operator session tokens stored in plaintext in the database

Operator check

Check whether github.com/forgekeep/nebula-mesh is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. CVSS score: 7.1.

Read brief →
Jul 14, 2026 Vendor advisory High-risk advisory CVE-2026-53604

nebula-mesh: CA private key not zeroized on web mobile-bundle error paths

Go · github.com/forgekeep/nebula-mesh

nebula-mesh: CA private key not zeroized on web mobile-bundle error paths

Operator check

Check whether github.com/forgekeep/nebula-mesh is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. CVSS score: 8.7.

Read brief →
Jul 14, 2026 Vendor advisory High-risk advisory CVE-2026-54448

Trivy: Helm chart tar bomb causes OOM via unbounded io.ReadAll in parser

Go · github.com/aquasecurity/trivy

Trivy: Helm chart tar bomb causes OOM via unbounded io.ReadAll in parser

Operator check

Check whether github.com/aquasecurity/trivy is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. CVSS score: 8.7. EPSS probability: 0.2%; percentile: 16%.

Read brief →
Jul 14, 2026 Vendor advisory High-risk advisory CVE-2026-54628

Anyquery: Server-Side Request Forgery (SSRF) via Unrestricted SQLite Virtual Table Modules in Server Mode

Go · github.com/julien040/anyquery

Anyquery: Server-Side Request Forgery (SSRF) via Unrestricted SQLite Virtual Table Modules in Server Mode

Operator check

Check whether github.com/julien040/anyquery is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.

Read brief →
Jul 14, 2026 Vendor advisory High-risk advisory CVE-2026-54629

Anyquery: Local File Read (LFR) via Unrestricted SQLite Virtual Table Modules in Server Mode

Go · github.com/julien040/anyquery

Anyquery: Local File Read (LFR) via Unrestricted SQLite Virtual Table Modules in Server Mode

Operator check

Check whether github.com/julien040/anyquery is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.

Read brief →
Jul 14, 2026 Vendor advisory High-risk advisory CVE-2026-61549

Woodpecker: Privilege escalation via unrestricted serviceAccountName in the Kubernetes backend

Go · go.woodpecker-ci.org/woodpecker/v3

Woodpecker: Privilege escalation via unrestricted serviceAccountName in the Kubernetes backend

Operator check

Check whether go.woodpecker-ci.org/woodpecker/v3 is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. CVSS score: 8.2.

Read brief →
Jul 14, 2026 Vendor advisory High-risk advisory CVE-2026-61699

nebula-mesh: Certificate revocation is never enforced at the mesh

Go · github.com/forgekeep/nebula-mesh

nebula-mesh: Certificate revocation is never enforced at the mesh

Operator check

Check whether github.com/forgekeep/nebula-mesh is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.

Read brief →
Jul 14, 2026 Vendor advisory High-risk advisory

Nebula-mesh allows non-admin operators to disable webhook SSRF protection via `allow_private`

Go · github.com/forgekeep/nebula-mesh

Nebula-mesh allows non-admin operators to disable webhook SSRF protection via `allow_private`

Operator check

Check whether github.com/forgekeep/nebula-mesh is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.

Read brief →
Jul 14, 2026 Vendor advisory High-risk advisory

Ech0: ParseAcceptLanguage `_` separator bypass enables ~70x CPU amplification via Accept-Language header in i18n.Midd...

Go · github.com/lin-snow/ech0

Ech0: ParseAcceptLanguage `_` separator bypass enables ~70x CPU amplification via Accept-Language header in i18n.Middleware

Operator check

Check whether github.com/lin-snow/ech0 is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. CVSS score: 8.7.

Read brief →
Jul 14, 2026 Vendor advisory High-risk advisory

TsDProxy: X-Forwarded-For header injection allows IP spoofing in proxied requests to backend services

Go · github.com/almeidapaulopt/tsdproxy

TsDProxy: X-Forwarded-For header injection allows IP spoofing in proxied requests to backend services

Operator check

Check whether github.com/almeidapaulopt/tsdproxy is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.

Read brief →
Jul 14, 2026 Vendor advisory High-risk advisory CVE-2026-44891

Netty: Denial of Service via Unbounded Headers in StompSubframeDecoder

Maven · io.netty:netty-codec-stomp

Netty: Denial of Service via Unbounded Headers in StompSubframeDecoder

Operator check

Check whether io.netty:netty-codec-stomp is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.

Read brief →
Jul 14, 2026 Patch Tuesday High-risk advisory CVE-2026-14380

DBI versions before 1.650 for Perl are vulnerable to code injection via caller-influenced Profile

Microsoft · Mariner

DBI versions before 1.650 for Perl are vulnerable to code injection via caller-influenced Profile Published in July 2026 Security Updates.

Operator check

Review the Microsoft Security Update Guide entry for CVE-2026-14380. Confirm whether Mariner is deployed, then apply the current security update or documented mitigation. CVSS score: 8.8. EPSS probability: 0.5%; percentile: 39%.

Read brief →
Jul 14, 2026 Patch Tuesday Critical vendor advisory CVE-2026-14740

DBI versions before 1.650 for Perl read one byte out-of-bounds in preparse when deleting an initial SQL comment

Microsoft · Mariner

DBI versions before 1.650 for Perl read one byte out-of-bounds in preparse when deleting an initial SQL comment Published in July 2026 Security Updates.

Operator check

Review the Microsoft Security Update Guide entry for CVE-2026-14740. Confirm whether Mariner is deployed, then apply the current security update or documented mitigation. CVSS score: 9.1. EPSS probability: 0.4%; percentile: 33%.

Read brief →
Jul 14, 2026 Patch Tuesday Critical vendor advisory CVE-2026-15043

DBI::SQL::Nano versions from 1.42 before 1.651 for Perl have inverted <= and >= SQL operators on text

Microsoft · Mariner

DBI::SQL::Nano versions from 1.42 before 1.651 for Perl have inverted <= and >= SQL operators on text Published in July 2026 Security Updates.

Operator check

Review the Microsoft Security Update Guide entry for CVE-2026-15043. Confirm whether Mariner is deployed, then apply the current security update or documented mitigation. CVSS score: 9.8. EPSS probability: 0.5%; percentile: 40%.

Read brief →
Jul 14, 2026 Patch Tuesday Critical vendor advisory CVE-2026-38968

ntopng through 6.6 is vulnerable to Predictable Session Identifier which can lead to Session Hijacking. HTTP session ...

Microsoft · Mariner

ntopng through 6.6 is vulnerable to Predictable Session Identifier which can lead to Session Hijacking. HTTP session identifiers in src/HTTPserver.cpp use weak time-seeded pseudo-randomness during session creation. As a result, fresh authenticated logins can receive deterministic or colliding session cookies under attacker-controlled timing. Published in July 2026 Security Updates.

Operator check

Review the Microsoft Security Update Guide entry for CVE-2026-38968. Confirm whether Mariner is deployed, then apply the current security update or documented mitigation. CVSS score: 9.8. EPSS probability: 0.4%; percentile: 30%.

Read brief →
Jul 14, 2026 Patch Tuesday High-risk advisory CVE-2026-42982

Windows Secure Kernel Mode Elevation of Privilege Vulnerability

Microsoft · Windows Secure Kernel Mode

Improper validation of consistency within input in Windows Secure Kernel Mode allows an authorized attacker to elevate privileges locally. Published in July 2026 Security Updates. MSRC exploitability: Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation Less Likely.

Operator check

Review the Microsoft Security Update Guide entry for CVE-2026-42982. Confirm whether Windows Secure Kernel Mode is deployed, then apply the current security update or documented mitigation. CVSS score: 7.8.

Read brief →
Jul 14, 2026 Patch Tuesday Critical vendor advisory CVE-2026-42990

SQL Server ODBC driver Elevation of Privilege Vulnerability

Microsoft · SQL Server ODBC driver

Heap-based buffer overflow in SQL Server ODBC driver allows an unauthorized attacker to execute code over a network. Published in July 2026 Security Updates. MSRC exploitability: Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation Unlikely.

Operator check

Review the Microsoft Security Update Guide entry for CVE-2026-42990. Confirm whether SQL Server ODBC driver is deployed, then apply the current security update or documented mitigation. CVSS score: 9.8.

Read brief →
Jul 14, 2026 Patch Tuesday High-risk advisory CVE-2026-47300

ASP.NET Core Elevation of Privilege Vulnerability

Microsoft · ASP.NET Core

Incorrect implementation of authentication algorithm in ASP.NET Core allows an authorized attacker to elevate privileges over a network. Published in July 2026 Security Updates. MSRC exploitability: Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation Less Likely.

Operator check

Review the Microsoft Security Update Guide entry for CVE-2026-47300. Confirm whether ASP.NET Core is deployed, then apply the current security update or documented mitigation. CVSS score: 8.8.

Read brief →
Jul 14, 2026 Patch Tuesday High-risk advisory CVE-2026-47303

ASP.NET Core Elevation of Privilege Vulnerability

Microsoft · ASP.NET Core

Authentication bypass by assumed-immutable data in ASP.NET Core allows an authorized attacker to elevate privileges over a network. Published in July 2026 Security Updates. MSRC exploitability: Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation Less Likely.

Operator check

Review the Microsoft Security Update Guide entry for CVE-2026-47303. Confirm whether ASP.NET Core is deployed, then apply the current security update or documented mitigation. CVSS score: 8.8.

Read brief →
Jul 14, 2026 Patch Tuesday Critical vendor advisory CVE-2026-48561

Microsoft Copilot Remote Code Execution Vulnerability

Microsoft · Microsoft Copilot

Improper neutralization of special elements used in a command ('command injection') in Microsoft Copilot allows an unauthorized attacker to execute code over a network. Published in July 2026 Security Updates. MSRC exploitability: Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation Less Likely.

Operator check

Review the Microsoft Security Update Guide entry for CVE-2026-48561. Confirm whether Microsoft Copilot is deployed, then apply the current security update or documented mitigation. CVSS score: 9.6.

Read brief →
Jul 14, 2026 Patch Tuesday High-risk advisory CVE-2026-49164

Windows Active Directory Domain Services Remote Code Execution Vulnerability

Microsoft · Active Directory Domain Services

Heap-based buffer overflow in Active Directory Domain Services allows an unauthorized attacker to execute code over a network. Published in July 2026 Security Updates. MSRC exploitability: Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation Unlikely.

Operator check

Review the Microsoft Security Update Guide entry for CVE-2026-49164. Confirm whether Active Directory Domain Services is deployed, then apply the current security update or documented mitigation. CVSS score: 8.1.

Read brief →
Jul 14, 2026 Patch Tuesday High-risk advisory CVE-2026-49170

Windows StateRepository API Server file Elevation of Privilege Vulnerability

Microsoft · Windows StateRepository API

Insufficient granularity of access control in Windows StateRepository API allows an authorized attacker to elevate privileges locally. Published in July 2026 Security Updates. MSRC exploitability: Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation More Likely.

Operator check

Review the Microsoft Security Update Guide entry for CVE-2026-49170. Confirm whether Windows StateRepository API is deployed, then apply the current security update or documented mitigation. CVSS score: 7.8.

Read brief →
Jul 14, 2026 Patch Tuesday Critical vendor advisory CVE-2026-49172

Windows FTP Service Remote Code Execution Vulnerability

Microsoft · Windows FTP Service

Heap-based buffer overflow in Windows FTP Service allows an unauthorized attacker to execute code over a network. Published in July 2026 Security Updates. MSRC exploitability: Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation Less Likely.

Operator check

Review the Microsoft Security Update Guide entry for CVE-2026-49172. Confirm whether Windows FTP Service is deployed, then apply the current security update or documented mitigation. CVSS score: 9.8.

Read brief →
Jul 14, 2026 Patch Tuesday High-risk advisory CVE-2026-50663

Game: Age of Empires II: Definitive Edition Remote Code Execution Vulnerability

Microsoft · Age of Empires II: Definitive Edition Game

Relative path traversal in Age of Empires II: Definitive Edition Game allows an unauthorized attacker to execute code over a network. Published in July 2026 Security Updates. MSRC exploitability: Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation Less Likely.

Operator check

Review the Microsoft Security Update Guide entry for CVE-2026-50663. Confirm whether Age of Empires II: Definitive Edition Game is deployed, then apply the current security update or documented mitigation. CVSS score: 8.8.

Read brief →
Jul 14, 2026 Vendor advisory Critical vendor advisory CVE-2026-50694

Microsoft Windows 10 1607 — CVE-2026-50694 (Critical)

Microsoft · Windows 10 1607

Use after free in Windows Secure Socket Tunneling Protocol (SSTP) allows an unauthorized attacker to execute code over a network.

Operator check

Review CVE-2026-50694 in your asset inventory. Apply patches per vendor guidance and verify Windows 10 1607 is not exposed. CVSS score: 8.1. EPSS probability: 0.6%; percentile: 45%.

Read brief →
Jul 14, 2026 Patch Tuesday High-risk advisory CVE-2026-54107

Windows Win32k Elevation of Privilege Vulnerability

Microsoft · Windows Win32K

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Win32K allows an authorized attacker to elevate privileges locally. Published in July 2026 Security Updates. MSRC exploitability: Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation Less Likely.

Operator check

Review the Microsoft Security Update Guide entry for CVE-2026-54107. Confirm whether Windows Win32K is deployed, then apply the current security update or documented mitigation. CVSS score: 8.8.

Read brief →
Jul 14, 2026 Patch Tuesday Critical vendor advisory CVE-2026-54990

Remote Desktop Client Remote Code Execution Vulnerability

Microsoft · Remote Desktop Client

Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network. Published in July 2026 Security Updates. MSRC exploitability: Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation Less Likely.

Operator check

Review the Microsoft Security Update Guide entry for CVE-2026-54990. Confirm whether Remote Desktop Client is deployed, then apply the current security update or documented mitigation. CVSS score: 9.8.

Read brief →
Jul 14, 2026 Patch Tuesday High-risk advisory CVE-2026-56000

xorg-x11-server / xwayland GLX contextTags Use-After-Free in CommonMakeCurrent()

Microsoft · Mariner

xorg-x11-server / xwayland GLX contextTags Use-After-Free in CommonMakeCurrent() Published in July 2026 Security Updates.

Operator check

Review the Microsoft Security Update Guide entry for CVE-2026-56000. Confirm whether Mariner is deployed, then apply the current security update or documented mitigation. EPSS probability: 0.2%; percentile: 9%.

Read brief →
Jul 14, 2026 KEV Known exploited CVE-2026-56155

Microsoft Active Directory Federation Services Insufficient Granularity of Access Control Vulnerability

Microsoft · Active Directory Federation Services

Microsoft Active Directory Federation Services contains an insufficient granularity of access control vulnerability that allows an authorized attacker to elevate privileges locally.

Operator check

Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

Read brief →
Jul 14, 2026 KEV Known exploited CVE-2026-56164

Microsoft SharePoint Server Missing Authentication for Critical Function Vulnerability

Microsoft · SharePoint Server

Microsoft SharePoint contains a missing authentication for critical function vulnerability that allows an unauthorized attacker to elevate privileges over a network.

Operator check

Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

Read brief →
Jul 14, 2026 Patch Tuesday Critical vendor advisory CVE-2026-57433

Storable versions before 3.41 for Perl have a signed integer overflow when deserializing a crafted SX_HOOK record

Microsoft · Mariner

Storable versions before 3.41 for Perl have a signed integer overflow when deserializing a crafted SX_HOOK record Published in July 2026 Security Updates.

Operator check

Review the Microsoft Security Update Guide entry for CVE-2026-57433. Confirm whether Mariner is deployed, then apply the current security update or documented mitigation. CVSS score: 9.8. EPSS probability: 0.3%; percentile: 27%.

Read brief →
Jul 14, 2026 Patch Tuesday High-risk advisory CVE-2026-58253

NATS Server: Route API Auth Bypass

Microsoft · Mariner

NATS Server: Route API Auth Bypass Published in July 2026 Security Updates.

Operator check

Review the Microsoft Security Update Guide entry for CVE-2026-58253. Confirm whether Mariner is deployed, then apply the current security update or documented mitigation. CVSS score: 8.8. EPSS probability: 0.4%; percentile: 29%.

Read brief →
Jul 14, 2026 Vendor advisory Critical vendor advisory CVE-2026-58594

Microsoft Windows 10 1607 — CVE-2026-58594 (Critical)

Microsoft · Windows 10 1607

Integer overflow or wraparound in Windows RDP allows an unauthorized attacker to execute code over a network.

Operator check

Review CVE-2026-58594 in your asset inventory. Apply patches per vendor guidance and verify Windows 10 1607 is not exposed. CVSS score: 8.8. EPSS probability: 0.8%; percentile: 52%.

Read brief →
Jul 14, 2026 Vendor advisory Critical vendor advisory CVE-2026-58617

Microsoft 365 Copilot — CVE-2026-58617 (Critical)

Microsoft · 365 Copilot

Improper access control in Microsoft 365 Copilot for iOS allows an unauthorized attacker to elevate privileges over a network.

Operator check

Review CVE-2026-58617 in your asset inventory. Apply patches per vendor guidance and verify 365 Copilot is not exposed. CVSS score: 8.1. EPSS probability: 0.7%; percentile: 48%.

Read brief →
Jul 14, 2026 Vendor advisory Critical vendor advisory CVE-2026-58644

Microsoft Sharepoint Server — CVE-2026-58644 (Critical)

Microsoft · Sharepoint Server

Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network.

Operator check

Review CVE-2026-58644 in your asset inventory. Apply patches per vendor guidance and verify Sharepoint Server is not exposed. CVSS score: 9.8. EPSS probability: 1.3%; percentile: 68%.

Read brief →
Jul 14, 2026 Patch Tuesday High-risk advisory CVE-2026-59873

node-tar: Decompression/parse DoS via unlimited input

Microsoft · Mariner

node-tar: Decompression/parse DoS via unlimited input Published in July 2026 Security Updates.

Operator check

Review the Microsoft Security Update Guide entry for CVE-2026-59873. Confirm whether Mariner is deployed, then apply the current security update or documented mitigation. CVSS score: 7.5. EPSS probability: 0.4%; percentile: 28%.

Read brief →
Jul 14, 2026 Patch Tuesday Critical vendor advisory CVE-2026-60082

DBI versions before 1.651 for Perl do not enforce statement handle consistency with the row

Microsoft · Mariner

DBI versions before 1.651 for Perl do not enforce statement handle consistency with the row Published in July 2026 Security Updates.

Operator check

Review the Microsoft Security Update Guide entry for CVE-2026-60082. Confirm whether Mariner is deployed, then apply the current security update or documented mitigation. CVSS score: 9.1. EPSS probability: 0.7%; percentile: 47%.

Read brief →
Jul 14, 2026 Patch Tuesday Critical vendor advisory CVE-2026-8924

trailing dot domain super cookie

Microsoft · Mariner

trailing dot domain super cookie Published in July 2026 Security Updates.

Operator check

Review the Microsoft Security Update Guide entry for CVE-2026-8924. Confirm whether Mariner is deployed, then apply the current security update or documented mitigation. CVSS score: 9.1. EPSS probability: 0.6%; percentile: 47%.

Read brief →
Jul 14, 2026 Patch Tuesday Critical vendor advisory CVE-2026-8926

password leak with netrc and user in URL

Microsoft · Mariner

password leak with netrc and user in URL Published in July 2026 Security Updates.

Operator check

Review the Microsoft Security Update Guide entry for CVE-2026-8926. Confirm whether Mariner is deployed, then apply the current security update or documented mitigation. CVSS score: 9.1. EPSS probability: 0.6%; percentile: 45%.

Read brief →
Jul 14, 2026 Patch Tuesday Critical vendor advisory CVE-2026-9547

SSH improper host validation

Microsoft · Mariner

SSH improper host validation Published in July 2026 Security Updates.

Operator check

Review the Microsoft Security Update Guide entry for CVE-2026-9547. Confirm whether Mariner is deployed, then apply the current security update or documented mitigation. CVSS score: 9.1. EPSS probability: 0.5%; percentile: 40%.

Read brief →
Jul 14, 2026 Vendor advisory High-risk advisory CVE-2026-50131

Fedify has an incomplete SSRF mitigation after GHSA-p9cg-vqcc-grcx: validatePublicUrl allows special-use IPv4 ranges

npm · @fedify/fedify

Fedify has an incomplete SSRF mitigation after GHSA-p9cg-vqcc-grcx: validatePublicUrl allows special-use IPv4 ranges

Operator check

Check whether @fedify/fedify is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. EPSS probability: 0.3%; percentile: 19%.

Read brief →
Jul 14, 2026 Vendor advisory High-risk advisory CVE-2026-54052

n8n-MCP: Cross-tenant access to workflow version backups in multi-tenant HTTP deployments

npm · n8n-mcp

n8n-MCP: Cross-tenant access to workflow version backups in multi-tenant HTTP deployments

Operator check

Check whether n8n-mcp is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.

Read brief →
Jul 14, 2026 Vendor advisory High-risk advisory

TidGi Desktop Remote Code Execution via Malicious TiddlyWiki Repository Import — Tiddler Startup Module Auto-Execution

npm · tidgi

TidGi Desktop Remote Code Execution via Malicious TiddlyWiki Repository Import — Tiddler Startup Module Auto-Execution

Operator check

Check whether tidgi is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.

Read brief →
Jul 14, 2026 Vendor advisory Critical vendor advisory CVE-2026-24227

Nvidia Tensorrt — CVE-2026-24227 (Critical)

Nvidia · Tensorrt

NVIDIA TensorRT for contains a vulnerability where a user might cause a deserialization of untrusted data. A successful exploit of this vulnerability might lead to code execution.

Operator check

Review CVE-2026-24227 in your asset inventory. Apply patches per vendor guidance and verify Tensorrt is not exposed. CVSS score: 5.3. EPSS probability: 0.5%; percentile: 38%.

Read brief →
Jul 14, 2026 Vendor advisory High-risk advisory CVE-2026-54446

NetLicensing-MCP: Unauthenticated Use of Server-Side NetLicensing API Key in HTTP Mode

PyPI · netlicensing-mcp

NetLicensing-MCP: Unauthenticated Use of Server-Side NetLicensing API Key in HTTP Mode

Operator check

Check whether netlicensing-mcp is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.

Read brief →
Jul 14, 2026 Vendor advisory Critical vendor advisory CVE-2026-45063

Sensiolabs Symfony — CVE-2026-45063 (Critical)

Sensiolabs · Symfony

Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 5.4.52, 6.4.40, 7.4.12, and 8.0.12, X509Authenticator extracts the user identifier from $_SERVER['SSL_CLIENT_S_DN'] with an unanchored regex that matches emailAddress= anywhere in the distinguished name, allowing an attacker with a trusted certificate containing emailAddress=victim inside another RDN value such as CN to authenticate as the victim. This issue is fixed in versions 5.4.52, 6.4.40, 7.4.12, and 8.0.12.

Operator check

Review CVE-2026-45063 in your asset inventory. Apply patches per vendor guidance and verify Symfony is not exposed. CVSS score: 9.1. EPSS probability: 0.3%; percentile: 26%.

Read brief →
Jul 14, 2026 Vendor advisory Critical vendor advisory CVE-2026-45069

Sensiolabs Symfony — CVE-2026-45069 (Critical)

Sensiolabs · Symfony

Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 6.4.40, 7.4.12, and 8.0.12, OidcTokenHandler::verifyClaims() registered audience (aud), issuer (iss), and expiry (exp) checkers but did not pass the mandatory claims list to ClaimCheckerManager::check(), so a validly signed JWT that omitted those claims could pass verification. This issue is fixed in versions 6.4.40, 7.4.12, and 8.0.12.

Operator check

Review CVE-2026-45069 in your asset inventory. Apply patches per vendor guidance and verify Symfony is not exposed. CVSS score: 9.1. EPSS probability: 0.2%; percentile: 15%.

Read brief →
Jul 14, 2026 Vendor advisory Critical vendor advisory CVE-2026-47767

Sensiolabs Symfony — CVE-2026-47767 (Critical)

Sensiolabs · Symfony

Symfony is a PHP framework for web and console applications and a set of reusable PHP components. From 5.4.46 until 5.4.52, 6.4.40, 7.4.12, and 8.0.12, the CVE-2024-50340 fix gated runtime argv parsing on empty($_GET), but parse_str() and the web SAPI can disagree, allowing a crafted query string to leave $_GET empty while $_SERVER['argv'] still carries attacker-controlled --env or --no-debug flags that change APP_ENV or APP_DEBUG. This issue is fixed in versions 5.4.52, 6.4.40, 7.4.12, and 8.0.12.

Operator check

Review CVE-2026-47767 in your asset inventory. Apply patches per vendor guidance and verify Symfony is not exposed. CVSS score: 9.8. EPSS probability: 0.3%; percentile: 25%.

Read brief →
Jul 14, 2026 KEV Known exploited CVE-2026-15409

SonicWall SMA1000 Appliances Server-Side Request Forgery Vulnerability

SonicWall · SMA1000 Appliances

SonicWall SMA1000 Appliances contain a server-side request forgery vulnerability that could allow a remote unauthenticated attacker to potentially cause the appliance to make requests to unintended location.

Operator check

Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

Read brief →
Jul 14, 2026 KEV Known exploited CVE-2026-15410

SonicWall SMA1000 Appliances Code Injection Vulnerability

SonicWall · SMA1000 Appliances

SonicWall SMA1000 Appliances contain a code injection vulnerability which in specific conditions could potentially enable a remote authenticated attacker as administrator to execute arbitrary OS commands.

Operator check

Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

Read brief →
Jul 13, 2026 KEV Known exploited CVE-2008-4128

Cisco IOS Cross-Site Request Forgery Vulnerability

Cisco · IOS

Cisco IOS 12.4 contains multiple cross-site forgery vulnerabilities that allows remote attackers to execute arbitrary commands via (1) a certain "show privilege" command to the /level/15/exec/- URI, and (2) a certain "alias exec" command to the /level/15/exec/-/configure/http URI.

Operator check

Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

Read brief →
Jul 13, 2026 Vendor advisory Critical vendor advisory CVE-2026-47677

FacturaScripts: Account takeover of any 2FA-enabled user

Composer · facturascripts/facturascripts

FacturaScripts: Account takeover of any 2FA-enabled user

Operator check

Check whether facturascripts/facturascripts is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. CVSS score: 9.3.

Read brief →
Jul 13, 2026 Vendor advisory High-risk advisory CVE-2026-49259

NukeViet: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Composer · nukeviet/nukeviet

NukeViet: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Operator check

Check whether nukeviet/nukeviet is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.

Read brief →
Jul 13, 2026 Vendor advisory High-risk advisory CVE-2026-54064

NukeViet: Multiple Anti-XSS Filter Bypasses Leading to Stored XSS in News Module

Composer · nukeviet/nukeviet

NukeViet: Multiple Anti-XSS Filter Bypasses Leading to Stored XSS in News Module

Operator check

Check whether nukeviet/nukeviet is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.

Read brief →
Jul 13, 2026 Vendor advisory High-risk advisory CVE-2026-54065

NukeViet: Path Traversal to Arbitrary File Deletion in Edit Comment Function

Composer · nukeviet/nukeviet

NukeViet: Path Traversal to Arbitrary File Deletion in Edit Comment Function

Operator check

Check whether nukeviet/nukeviet is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.

Read brief →
Jul 13, 2026 Vendor advisory Critical vendor advisory CVE-2026-40468

Fossies Gawk — CVE-2026-40468 (Critical)

Fossies · Gawk

Integer overflow vulnerability has been found in "builtin.c" program file of gawk. This issue may lead to memory exhaustion on the hosting operating system and could be used to overwrite gawk heap metadata and objects with attacker-controlled bytes. It affects gawk in versions 5.4.0 and below.

Operator check

Review CVE-2026-40468 in your asset inventory. Apply patches per vendor guidance and verify Gawk is not exposed. CVSS score: 9.1.

Read brief →
Jul 13, 2026 Vendor advisory Critical vendor advisory CVE-2026-40469

Fossies Gawk — CVE-2026-40469 (Critical)

Fossies · Gawk

Integer overflow vulnerability has been found in "builtin.c" program file of gawk (do_sub() routine). This issue could be used to overwrite gawk heap metadata and objects causing the program to crash. It affects 32-bit builds of gawk in versions 5.4.0 and below.

Operator check

Review CVE-2026-40469 in your asset inventory. Apply patches per vendor guidance and verify Gawk is not exposed. CVSS score: 9.1.

Read brief →
Jul 13, 2026 Vendor advisory High-risk advisory CVE-2026-59954

Apollo ConfigService access key authentication bypass via appId parsing and non-canonical matching

Maven · com.ctrip.framework.apollo:apollo

Apollo ConfigService access key authentication bypass via appId parsing and non-canonical matching

Operator check

Check whether com.ctrip.framework.apollo:apollo is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.

Read brief →
Jul 13, 2026 Vendor advisory High-risk advisory CVE-2026-59955

Apollo ConfigService access key authentication bypass via raw config file appId parsing

Maven · com.ctrip.framework.apollo:apollo

Apollo ConfigService access key authentication bypass via raw config file appId parsing

Operator check

Check whether com.ctrip.framework.apollo:apollo is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.

Read brief →
Jul 13, 2026 Vendor advisory Critical vendor advisory CVE-2026-13221

Perl Perl — CVE-2026-13221 (Critical)

Perl · Perl

Perl versions through 5.43.9 produce silently incorrect regular expression matches when an alternation of more than 65535 fixed string branches is compiled into a trie in Perl_study_chunk. When such branches are combined into a trie, the delta between the first branch and the shared tail is stored in a 16-bit field. A branch count above 65535 overflows the field, and the trie's match decision table is truncated with no warning or error. A pattern of this shape produces false positive matches (matching strings it should not) and false negative matches (failing to match strings it should). Whe

Operator check

Review CVE-2026-13221 in your asset inventory. Apply patches per vendor guidance and verify Perl is not exposed. CVSS score: 9.1. EPSS probability: 0.2%; percentile: 11%.

Read brief →
Jul 13, 2026 Vendor advisory High-risk advisory CVE-2026-45579

DIRAC is vulnerable to RCE in RequestManager due to eval on untrusted input

PyPI · DIRAC

DIRAC is vulnerable to RCE in RequestManager due to eval on untrusted input

Operator check

Check whether DIRAC is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.

Read brief →
Jul 13, 2026 Vendor advisory High-risk advisory CVE-2026-61667

DIRAC is vulnerable to RCE in FileCatalog DatasetManager via SQL injection + eval

PyPI · DIRAC

DIRAC is vulnerable to RCE in FileCatalog DatasetManager via SQL injection + eval

Operator check

Check whether DIRAC is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.

Read brief →
Jul 13, 2026 Vendor advisory High-risk advisory CVE-2026-45378

Decidim: Verification documents can be downloaded through reusable links

RubyGems · decidim-verifications

Decidim: Verification documents can be downloaded through reusable links

Operator check

Check whether decidim-verifications is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.

Read brief →
Jul 13, 2026 Vendor advisory High-risk advisory CVE-2026-45414

Decidim: JWT-backed authentication can be replayed across organizations

RubyGems · decidim

Decidim: JWT-backed authentication can be replayed across organizations

Operator check

Check whether decidim is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.

Read brief →
Jul 13, 2026 Vendor advisory Critical vendor advisory CVE-2026-61498

Vitec Flamingo 4.12.2 — CVE-2026-61498 (Critical)

Vitec · Flamingo 4.12.2

Vitec Flamingo 4.12.2 contains an unauthenticated OS command injection vulnerability in the admin/ajax/gen_graphs.php endpoint that allows remote unauthenticated attackers to execute arbitrary commands by supplying shell metacharacters in the start, end, key, or format HTTP GET parameters. Attackers can exploit the lack of input sanitization in the graph generation script, which passes user-supplied values directly to shell commands via passthru(), to execute arbitrary OS commands with root privileges due to the web server context having passwordless sudo access.

Operator check

Review CVE-2026-61498 in your asset inventory. Apply patches per vendor guidance and verify Flamingo 4.12.2 is not exposed. CVSS score: 9.8.

Read brief →
Jul 11, 2026 Vendor advisory Critical vendor advisory CVE-2026-56372

Imagemagick Imagemagick — CVE-2026-56372 (Critical)

Imagemagick · Imagemagick

ImageMagick before 7.1.2-19 contains a heap buffer overflow vulnerability in the magnify operation that allows attackers to read out of bounds memory. An unrecognized magnify:method value triggers an out of bounds read, potentially exposing sensitive information or causing denial of service.

Operator check

Review CVE-2026-56372 in your asset inventory. Apply patches per vendor guidance and verify Imagemagick is not exposed. CVSS score: 3.3. EPSS probability: 0.1%; percentile: 2%.

Read brief →
Jul 10, 2026 KEV Known exploited CVE-2026-56291

Balbooa Forms Unrestricted Upload of File with Dangerous Type Vulnerability

Balbooa · Forms

Balbooa Forms contains an unrestricted upload of file with dangerous type vulnerability that allows an unauthenticated arbitrary file upload which could allow uploading of executable files leading to full RCE.

Operator check

Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

Read brief →
Jul 10, 2026 Vendor advisory High-risk advisory CVE-2026-54159

prestashop/ps_facetedsearch: PHP Object Injection in faceted search cache allows unauthenticated RCE

Composer · prestashop/ps_facetedsearch

prestashop/ps_facetedsearch: PHP Object Injection in faceted search cache allows unauthenticated RCE

Operator check

Check whether prestashop/ps_facetedsearch is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.

Read brief →
Jul 10, 2026 Vendor advisory High-risk advisory

NotrinosERP: Authenticated arbitrary file upload leads to remote code execution via HRM employee "Documents" (doc_file)

Composer · notrinos/notrinos-erp

NotrinosERP: Authenticated arbitrary file upload leads to remote code execution via HRM employee "Documents" (doc_file)

Operator check

Check whether notrinos/notrinos-erp is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.

Read brief →
Jul 10, 2026 Vendor advisory High-risk advisory CVE-2026-48594

Tesla has decompression bomb on response body

erlang · tesla

Tesla has decompression bomb on response body

Operator check

Check whether tesla is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. CVSS score: 8.2. EPSS probability: 0.3%; percentile: 25%.

Read brief →
Jul 10, 2026 Vendor advisory High-risk advisory CVE-2026-48595

Tesla: Authorization header leaks on cross-origin redirect via case-sensitive filtering

erlang · tesla

Tesla: Authorization header leaks on cross-origin redirect via case-sensitive filtering

Operator check

Check whether tesla is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. CVSS score: 8.2. EPSS probability: 0.4%; percentile: 32%.

Read brief →
Jul 10, 2026 Vendor advisory High-risk advisory CVE-2026-48597

Tesla vulnerable to atom exhaustion via untrusted URL scheme

erlang · tesla

Tesla vulnerable to atom exhaustion via untrusted URL scheme

Operator check

Check whether tesla is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. CVSS score: 8.2. EPSS probability: 0.3%; percentile: 22%.

Read brief →
Jul 10, 2026 Vendor advisory High-risk advisory CVE-2026-50551

SiYuan: Stored XSS to RCE via Unsanitized Attribute View Asset Cell Content

Go · github.com/siyuan-note/siyuan/kernel

SiYuan: Stored XSS to RCE via Unsanitized Attribute View Asset Cell Content

Operator check

Check whether github.com/siyuan-note/siyuan/kernel is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. EPSS probability: 0.4%; percentile: 35%.

Read brief →
Jul 10, 2026 Vendor advisory High-risk advisory CVE-2026-54063

Excelize: Unbounded Row Index Allocation in Worksheet Parser (checkSheet OOM/Panic DoS)

Go · github.com/xuri/excelize/v2

Excelize: Unbounded Row Index Allocation in Worksheet Parser (checkSheet OOM/Panic DoS)

Operator check

Check whether github.com/xuri/excelize/v2 is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.

Read brief →
Jul 10, 2026 Vendor advisory High-risk advisory CVE-2026-54066

SiYuan: Path Traversal via Double URL Encoding in /assets/*path (publish mode arbitrary file─read), Incomplete fix ...

Go · github.com/siyuan-note/siyuan/kernel

SiYuan: Path Traversal via Double URL Encoding in /assets/*path (publish mode arbitrary file─read), Incomplete fix of CVE-2026-41894

Operator check

Check whether github.com/siyuan-note/siyuan/kernel is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. EPSS probability: 1.9%; percentile: 77%.

Read brief →
Jul 10, 2026 Vendor advisory High-risk advisory CVE-2026-54067

SiYuan: Stored XSS to RCE via CSS-snippet <style> breakout in renderSnippet()

Go · github.com/siyuan-note/siyuan/kernel

SiYuan: Stored XSS to RCE via CSS-snippet <style> breakout in renderSnippet()

Operator check

Check whether github.com/siyuan-note/siyuan/kernel is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. EPSS probability: 0.3%; percentile: 23%.

Read brief →
Jul 10, 2026 Vendor advisory Critical vendor advisory CVE-2026-54069

SiYuan: Unauthenticated Admin API Access via Blanket chrome-extension:// Origin Allowlist

Go · github.com/siyuan-note/siyuan/kernel

SiYuan: Unauthenticated Admin API Access via Blanket chrome-extension:// Origin Allowlist

Operator check

Check whether github.com/siyuan-note/siyuan/kernel is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. CVSS score: 9.2. EPSS probability: 0.6%; percentile: 45%.

Read brief →
Jul 10, 2026 Vendor advisory High-risk advisory CVE-2026-54070

SiYuan: Stored XSS in Bazaar marketplace via package README event handlers

Go · github.com/siyuan-note/siyuan/kernel

SiYuan: Stored XSS in Bazaar marketplace via package README event handlers

Operator check

Check whether github.com/siyuan-note/siyuan/kernel is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. EPSS probability: 0.2%; percentile: 8%.

Read brief →
Jul 10, 2026 Vendor advisory High-risk advisory CVE-2026-54072

Authorizer: Unvalidated redirect_uri in /authorize leaks OAuth2 tokens to attacker-controlled URL

Go · github.com/authorizerdev/authorizer

Authorizer: Unvalidated redirect_uri in /authorize leaks OAuth2 tokens to attacker-controlled URL

Operator check

Check whether github.com/authorizerdev/authorizer is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.

Read brief →
Jul 10, 2026 Vendor advisory Critical vendor advisory CVE-2026-54088

File Browser: Command Injection via Authentication Hook Shell Substitution (Pre-Authentication RCE)

Go · github.com/filebrowser/filebrowser/v2

File Browser: Command Injection via Authentication Hook Shell Substitution (Pre-Authentication RCE)

Operator check

Check whether github.com/filebrowser/filebrowser/v2 is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. CVSS score: 9.3. EPSS probability: 0.5%; percentile: 41%.

Read brief →
Jul 10, 2026 Vendor advisory High-risk advisory CVE-2026-54089

File Browser: Authentication Bypass via Proxy Auth Header Forgery

Go · github.com/filebrowser/filebrowser/v2

File Browser: Authentication Bypass via Proxy Auth Header Forgery

Operator check

Check whether github.com/filebrowser/filebrowser/v2 is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. EPSS probability: 0.3%; percentile: 26%.

Read brief →
Jul 10, 2026 Vendor advisory High-risk advisory CVE-2026-54158

SiYuan: Stored XSS to RCE via attribute-view cell rendering in genAVValueHTML()

Go · github.com/siyuan-note/siyuan/kernel

SiYuan: Stored XSS to RCE via attribute-view cell rendering in genAVValueHTML()

Operator check

Check whether github.com/siyuan-note/siyuan/kernel is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. EPSS probability: 0.3%; percentile: 21%.

Read brief →
Jul 10, 2026 Vendor advisory High-risk advisory CVE-2026-54174

melange: Incomplete package integrity verification allows data section substitution

Go · chainguard.dev/apko

melange: Incomplete package integrity verification allows data section substitution

Operator check

Check whether chainguard.dev/apko is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.

Read brief →
Jul 10, 2026 Vendor advisory High-risk advisory

TSDProxy: Internal proxy auth token forwarded to backend services enables management API escalation

Go · github.com/almeidapaulopt/tsdproxy

TSDProxy: Internal proxy auth token forwarded to backend services enables management API escalation

Operator check

Check whether github.com/almeidapaulopt/tsdproxy is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.

Read brief →
Jul 10, 2026 KEV Known exploited CVE-2026-48939

iCagenda Unrestricted Upload of File with Dangerous Type Vulnerability

iCagenda · iCagenda

iCagenda contains an unrestricted upload of file with dangerous type vulnerability that allows the upload of arbitrary files in the file attachment feature, ultimately resulting in PHP code upload and execution.

Operator check

Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

Read brief →
Jul 10, 2026 Vendor advisory Critical vendor advisory CVE-2026-61459

MCP Server Kubernetes — CVE-2026-61459 (Critical)

MCP · Server Kubernetes

MCP Server Kubernetes before 3.9.0 contains an argument injection vulnerability in structured tools (kubectl_get, kubectl_describe, kubectl_delete) that allows attackers to bypass the assertNoDangerousFlags security check by supplying resourceType and name parameters with leading dashes. Attackers can inject the --server flag to redirect kubectl commands to an attacker-controlled API server, causing the operator's bearer token to be transmitted externally and enabling full cluster compromise.

Operator check

Review CVE-2026-61459 in your asset inventory. Apply patches per vendor guidance and verify Server Kubernetes is not exposed. CVSS score: 9.8.

Read brief →
Jul 10, 2026 Vendor advisory High-risk advisory CVE-2026-49866

libp2p: CPU DoS via oversized IHAVE and IWANT control message arrays

npm · @libp2p/gossipsub

libp2p: CPU DoS via oversized IHAVE and IWANT control message arrays

Operator check

Check whether @libp2p/gossipsub is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. EPSS probability: 0.4%; percentile: 36%.

Read brief →
Jul 10, 2026 Vendor advisory High-risk advisory CVE-2026-54071

BabelDOC: Arbitrary Code Execution via CMap Pickle Deserialization in babeldoc/pdfminer/cmapdb.py

PyPI · BabelDOC

BabelDOC: Arbitrary Code Execution via CMap Pickle Deserialization in babeldoc/pdfminer/cmapdb.py

Operator check

Check whether BabelDOC is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.

Read brief →
Jul 10, 2026 Vendor advisory High-risk advisory

mcp-atlassian: Arbitrary file read via missing path validation in confluence_upload_attachment

PyPI · mcp-atlassian

mcp-atlassian: Arbitrary file read via missing path validation in confluence_upload_attachment

Operator check

Check whether mcp-atlassian is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.

Read brief →
Jul 10, 2026 Vendor advisory High-risk advisory

Clauster: Non-loopback deployments can serve the dashboard unauthenticated when auth.enabled is unset

PyPI · clauster

Clauster: Non-loopback deployments can serve the dashboard unauthenticated when auth.enabled is unset

Operator check

Check whether clauster is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. CVSS score: 8.7.

Read brief →
Jul 10, 2026 Coordinated disclosure Patch review

VU#564823: GNU Wget enables SSRF via unvalidated FTP PASV IPs

Users · are advised to update their

Overview GNU Wget, versions 1.25.0 and earlier, contains a server-side request forgery (SSRF) vulnerability in its implementation of FTP passive mode. Because Wget does not properly validate IP addresses obtained from PASV responses, an attacker-controlled FTP endpoint can redirect the client’s connection to arbitrary IPs, potentially exposing internal network host and service responses. This vulnerability has been remediated in a recent update by GNU; see the Solutions section below for resolution guidance. Description GNU Wget is a widely used command-line utility for retrieving content over HTTP, HTTPS, and FTP. When operating over FTP in passive mode, Wget relies on the server’s PASV response to determine which IP address and port to use for the data connection. CVE-2026-15146 GNU Wget does not validate the IP address provided by an... Related CVEs: CVE-2021-40491, CVE-2026-15146.

Operator check

Review the CERT/CC Vulnerability Note and compare the affected vendor and product list against your inventory. Apply vendor fixes or compensating controls for are advised to update their where available.

Read brief →
Jul 9, 2026 Vendor advisory High-risk advisory CVE-2026-52762

YesWiki: Authenticated (Admin) Server-Side Template Injection to Remote Code Execution via Bazar Semantic Templates

Composer · yeswiki/yeswiki

YesWiki: Authenticated (Admin) Server-Side Template Injection to Remote Code Execution via Bazar Semantic Templates

Operator check

Check whether yeswiki/yeswiki is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. CVSS score: 7.1.

Read brief →
Jul 9, 2026 Vendor advisory High-risk advisory CVE-2026-52766

YesWiki vulnerable to unauthenticated arbitrary page deletion via `{{erasespamedcomments}}` action

Composer · yeswiki/yeswiki

YesWiki vulnerable to unauthenticated arbitrary page deletion via `{{erasespamedcomments}}` action

Operator check

Check whether yeswiki/yeswiki is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.

Read brief →
Jul 9, 2026 Vendor advisory High-risk advisory CVE-2026-52767

YesWiki Vulnerable to Unauthenticated ActivityPub Signature-Verification Bypass via `!openssl_verify(...)` accepting ...

Composer · yeswiki/yeswiki

YesWiki Vulnerable to Unauthenticated ActivityPub Signature-Verification Bypass via `!openssl_verify(...)` accepting `int(-1)`

Operator check

Check whether yeswiki/yeswiki is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.

Read brief →
Jul 9, 2026 Vendor advisory High-risk advisory CVE-2026-52769

YesWiki has Unauthenticated Server-Side Request Forgery via ActivityPub `Signature.keyId`

Composer · yeswiki/yeswiki

YesWiki has Unauthenticated Server-Side Request Forgery via ActivityPub `Signature.keyId`

Operator check

Check whether yeswiki/yeswiki is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.

Read brief →
Jul 9, 2026 Vendor advisory High-risk advisory CVE-2026-52770

YesWiki: SQL Injection possible through public Bazar entry-listing APIs via numeric `query`/`queries` filters

Composer · yeswiki/yeswiki

YesWiki: SQL Injection possible through public Bazar entry-listing APIs via numeric `query`/`queries` filters

Operator check

Check whether yeswiki/yeswiki is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.

Read brief →
Jul 9, 2026 Vendor advisory High-risk advisory CVE-2026-52771

YesWiki: Second-Order SQL Injection in Page Delete API via Unescaped Page Tag (`ApiController::deletePage`)

Composer · yeswiki/yeswiki

YesWiki: Second-Order SQL Injection in Page Delete API via Unescaped Page Tag (`ApiController::deletePage`)

Operator check

Check whether yeswiki/yeswiki is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.

Read brief →
Jul 9, 2026 Vendor advisory Critical vendor advisory CVE-2026-52777

YesWiki Vulnerable to Authenticated PHP Object Injection in BazarImportAction via unserialize

Composer · yeswiki/yeswiki

YesWiki Vulnerable to Authenticated PHP Object Injection in BazarImportAction via unserialize

Operator check

Check whether yeswiki/yeswiki is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. CVSS score: 9.4.

Read brief →
Jul 9, 2026 Vendor advisory High-risk advisory CVE-2026-52778

YesWiki has Unsafe eval() in its Formula Calculato, Leading to Remote Code Execution & Denial of Service

Composer · yeswiki/yeswiki

YesWiki has Unsafe eval() in its Formula Calculato, Leading to Remote Code Execution & Denial of Service

Operator check

Check whether yeswiki/yeswiki is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. EPSS probability: 0.6%; percentile: 43%.

Read brief →
Jul 9, 2026 Vendor advisory High-risk advisory CVE-2026-53932

laravel-backup-restore has an OS Command Injection during database restore

Composer · wnx/laravel-backup-restore

laravel-backup-restore has an OS Command Injection during database restore

Operator check

Check whether wnx/laravel-backup-restore is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.

Read brief →
Jul 9, 2026 Vendor advisory High-risk advisory

Craft CMS: RCE via missing cleanseConfig in FieldsController::actionRenderCardPreview

Composer · craftcms/cms

Craft CMS: RCE via missing cleanseConfig in FieldsController::actionRenderCardPreview

Operator check

Check whether craftcms/cms is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. CVSS score: 8.6.

Read brief →
Jul 9, 2026 Vendor advisory High-risk advisory CVE-2026-48862

mint: Unbounded streams map growth via PUSH_PROMISE without follow-up HEADERS

erlang · mint

mint: Unbounded streams map growth via PUSH_PROMISE without follow-up HEADERS

Operator check

Check whether mint is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. CVSS score: 8.2. EPSS probability: 0.4%; percentile: 30%.

Read brief →
Jul 9, 2026 Vendor advisory High-risk advisory CVE-2026-49754

mint: Unbounded CONTINUATION/HEADERS frame accumulation (CONTINUATION flood)

erlang · mint

mint: Unbounded CONTINUATION/HEADERS frame accumulation (CONTINUATION flood)

Operator check

Check whether mint is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. CVSS score: 8.2. EPSS probability: 0.4%; percentile: 30%.

Read brief →
Jul 9, 2026 Vendor advisory High-risk advisory CVE-2026-50553

Note Mark: Path traversal via unsanitized book/note slug in migrate export (sibling of GHSA-g49p)

Go · github.com/enchant97/note-mark/backend

Note Mark: Path traversal via unsanitized book/note slug in migrate export (sibling of GHSA-g49p)

Operator check

Check whether github.com/enchant97/note-mark/backend is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. CVSS score: 8.6.

Read brief →
Jul 9, 2026 Vendor advisory Critical vendor advisory CVE-2026-58122

Hermes WebUI — CVE-2026-58122 (Critical)

Hermes · WebUI

Hermes WebUI before 0.51.307 contains an authentication bypass vulnerability that allows unauthenticated remote attackers to circumvent local-origin IP restrictions on onboarding endpoints by supplying a spoofed X-Forwarded-For header with a loopback address. Attackers can exploit this bypass to perform server-side request forgery against internal services including cloud metadata endpoints, overwrite LLM provider configuration and API keys with attacker-controlled values, or initiate OAuth device-code flows to obtain persistent access tokens stored in auth.json.

Operator check

Review CVE-2026-58122 in your asset inventory. Apply patches per vendor guidance and verify WebUI is not exposed. CVSS score: 9.1.

Read brief →
Jul 9, 2026 Vendor advisory Critical vendor advisory CVE-2026-58123

Hermes WebUI — CVE-2026-58123 (Critical)

Hermes · WebUI

Hermes WebUI before 0.51.788 contains an unauthenticated remote code execution vulnerability that allows remote attackers to execute arbitrary shell commands by accessing the embedded terminal API endpoints without credentials. Attackers can create a session, attach a PTY shell, and write arbitrary commands through the terminal input endpoint to achieve full command execution as the server process user via four sequential unauthenticated HTTP requests.

Operator check

Review CVE-2026-58123 in your asset inventory. Apply patches per vendor guidance and verify WebUI is not exposed. CVSS score: 9.8.

Read brief →
Jul 9, 2026 Vendor advisory High-risk advisory CVE-2026-49485

org.hl7.fhir.core: ReDoS via FHIRPath matches()/replaceMatches() in FHIR Validator HTTP Endpoint

Maven · ca.uhn.hapi.fhir:org.hl7.fhir.dstu2

org.hl7.fhir.core: ReDoS via FHIRPath matches()/replaceMatches() in FHIR Validator HTTP Endpoint

Operator check

Check whether ca.uhn.hapi.fhir:org.hl7.fhir.dstu2 is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.

Read brief →
Jul 9, 2026 Vendor advisory High-risk advisory

Micronaut doesn't set a maximum redirect count for its HTTP Client, enabling infinite loop DoS

Maven · io.micronaut:micronaut-http-client

Micronaut doesn't set a maximum redirect count for its HTTP Client, enabling infinite loop DoS

Operator check

Check whether io.micronaut:micronaut-http-client is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.

Read brief →
Jul 9, 2026 Vendor advisory Critical vendor advisory CVE-2026-59214

Openwebui Open Webui — CVE-2026-59214 (Critical)

Openwebui · Open Webui

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. Prior to 0.10.0, Open WebUI runs client-side Python with Pyodide in a same-origin web worker, allowing stored chat payloads that use pyodide.http.pyfetch or the js module fetch and XMLHttpRequest APIs to issue authenticated same-origin requests when a victim clicks Run, which can reach admin-only endpoints and execute server-side code through configured tools. This issue is fixed in version 0.10.0.

Operator check

Review CVE-2026-59214 in your asset inventory. Apply patches per vendor guidance and verify Open Webui is not exposed. CVSS score: 7.3. EPSS probability: 0.2%; percentile: 16%.

Read brief →
Jul 9, 2026 Coordinated disclosure Patch review

VU#152953: PayRange Android app version 7.0.7 contains multiple vulnerabilities

PayRange · Android app

Overview PayRange is a mobile payment app that allows users to pay for vending machines, laundromats, and other unattended machines using a smartphone with Bluetooth. Two vulnerabilities were discovered in version 7.0.7 of the PayRange app that is available in the Google Play store. Description A vulnerability (CVE-2026-13462) exists in the PayRange Android app that causes invalid SSL certificates to be accepted in application WebViews. A second vulnerability (CVE-2026-13461) exists that allows the injection of JavaScript, which can be used to escape the WebView sandbox and perform a number of dangerous actions on the user's device. These vulnerabilities were discovered in version 7.0.7 of the PayRange app. The PayRange app bypasses Android's SSL trust chain and accepts certificates that match any of the following rules (including... Related CVEs: CVE-2026-13461, CVE-2026-13462.

Operator check

Review the CERT/CC Vulnerability Note and compare the affected vendor and product list against your inventory. Apply vendor fixes or compensating controls for Android app where available.

Read brief →
Jul 9, 2026 Vendor advisory High-risk advisory CVE-2026-49476

Soup Sieve has Memory Exhaustion via Large Comma-Separated Selector Lists

PyPI · soupsieve

Soup Sieve has Memory Exhaustion via Large Comma-Separated Selector Lists

Operator check

Check whether soupsieve is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.

Read brief →
Jul 9, 2026 Vendor advisory High-risk advisory CVE-2026-49477

Soup Sieve: Regular Expression Denial of Service (ReDoS) via Selector Parser

PyPI · soupsieve

Soup Sieve: Regular Expression Denial of Service (ReDoS) via Selector Parser

Operator check

Check whether soupsieve is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.

Read brief →
Jul 9, 2026 Vendor advisory High-risk advisory CVE-2026-49851

Mistune: Potential DoS via quadratic-time parsing in parse_link_text

PyPI · mistune

Mistune: Potential DoS via quadratic-time parsing in parse_link_text

Operator check

Check whether mistune is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. CVSS score: 8.7. EPSS probability: 0.4%; percentile: 27%.

Read brief →
Jul 9, 2026 Vendor advisory High-risk advisory CVE-2026-53727

Ruby CSS Parser: SSRF and Local File Disclosure in `CssParser::Parser#read_remote_file`

RubyGems · css_parser

Ruby CSS Parser: SSRF and Local File Disclosure in `CssParser::Parser#read_remote_file`

Operator check

Check whether css_parser is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. CVSS score: 8.9.

Read brief →
Jul 9, 2026 Coordinated disclosure Patch review

VU#734812: Xerte Online Toolkit contains an authentication bypass that allows for RCE

Xerte · Online Toolkit

Overview Two vulnerabilities have been discovered in Xerte Online Toolkits, an open-source e-learning authoring toolsuite intended for the creation of learning materials within a web browser. CVE-2026-14261 tracks the persistence of the /setup/ directory after installation, which allows an unauthenticated attacker to reconfigure the application to point to a remote database they control in order to gain administrative access. CVE-2026-12116 tracks an editable antivirus binary path that can be redirected to a PHP interpreter, causing uploaded files to be executed as PHP code and resulting in remote code execution (RCE). Version v3.15.5 or v3.14.6 of Xerte Online Toolkits fixes these vulnerabilities. Description Xerte Online Toolkits is a suite of a free, open-source e-learning authoring tools that allows users to make educational... Related CVEs: CVE-2026-12116, CVE-2026-14261.

Operator check

Review the CERT/CC Vulnerability Note and compare the affected vendor and product list against your inventory. Apply vendor fixes or compensating controls for Online Toolkit where available.

Read brief →
Jul 8, 2026 Vendor advisory Critical vendor advisory CVE-2026-58480

Blocksy Companion Pro plugin for WordPress — CVE-2026-58480 (Critical)

Blocksy · Companion Pro plugin for WordPress

Blocksy Companion Pro plugin for WordPress before 2.1.47 contains an unauthenticated arbitrary file upload vulnerability that allows attackers to upload executable files by bypassing extension validation in the save_attachments function exposed through the Advanced Reviews feature. Attackers can exploit the Custom Fonts extension's flawed strpos() substring check by uploading double-extension filenames such as shell.woff2.php, causing the validation to pass on the substring match while the web server executes the file as PHP, achieving remote code execution.

Operator check

Review CVE-2026-58480 in your asset inventory. Apply patches per vendor guidance and verify Companion Pro plugin for WordPress is not exposed. CVSS score: 9.8.

Read brief →
Jul 8, 2026 Vendor advisory High-risk advisory CVE-2026-50197

Skipper: opaAuthorizeRequestWithBody filter bypasses OPA policy on Transfer-Encoding — chunked / HTTP/2 requests

Go · github.com/zalando/skipper

Skipper: opaAuthorizeRequestWithBody filter bypasses OPA policy on Transfer-Encoding — chunked / HTTP/2 requests

Operator check

Check whether github.com/zalando/skipper is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.

Read brief →
Jul 8, 2026 Vendor advisory High-risk advisory CVE-2026-52831

Nuclio: Unsanitized cron trigger event headers/body injected into CronJob shell command leads to persistent RCE

Go · github.com/nuclio/nuclio

Nuclio: Unsanitized cron trigger event headers/body injected into CronJob shell command leads to persistent RCE

Operator check

Check whether github.com/nuclio/nuclio is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.

Read brief →
Jul 8, 2026 Vendor advisory High-risk advisory CVE-2026-53649

Joro: Unauthenticated Cross-Origin Plugin Upload Leads to RCE

Go · github.com/BishopFox/joro

Joro: Unauthenticated Cross-Origin Plugin Upload Leads to RCE

Operator check

Check whether github.com/BishopFox/joro is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.

Read brief →
Jul 8, 2026 Vendor advisory Critical vendor advisory CVE-2026-3144

Ibm Api Connect — CVE-2026-3144 (Critical)

Ibm · Api Connect

IBM API Connect 12.1.0.0 through 12.1.0.3 uses default credentials which could allow an attacker to gain unauthorized access to the application before the system enforces a credential update.

Operator check

Review CVE-2026-3144 in your asset inventory. Apply patches per vendor guidance and verify Api Connect is not exposed. CVSS score: 8.1. EPSS probability: 0.4%; percentile: 29%.

Read brief →
Jul 8, 2026 Vendor advisory Critical vendor advisory CVE-2026-9074

Ibm Api Connect — CVE-2026-9074 (Critical)

Ibm · Api Connect

IBM API Connect 10.0.8.0 through 10.0.8.9 and 12.1.0.0 through 12.1.0.3 contains an unauthenticated SQL injection vulnerability in the password reset functionality.

Operator check

Review CVE-2026-9074 in your asset inventory. Apply patches per vendor guidance and verify Api Connect is not exposed. CVSS score: 9.1. EPSS probability: 0.4%; percentile: 35%.

Read brief →
Jul 8, 2026 Vendor advisory High-risk advisory CVE-2026-49464

NL Portal: IDOR allows any authenticated user to complete and tamper with another user's taak

Maven · nl.nl-portal:taak

NL Portal: IDOR allows any authenticated user to complete and tamper with another user's taak

Operator check

Check whether nl.nl-portal:taak is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.

Read brief →
Jul 8, 2026 Vendor advisory High-risk advisory CVE-2026-49832

DSpace has possible Remote Code Execution (RCE) through Velocity Templates used by LDN

Maven · org.dspace:dspace-api

DSpace has possible Remote Code Execution (RCE) through Velocity Templates used by LDN

Operator check

Check whether org.dspace:dspace-api is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.

Read brief →
Jul 8, 2026 Vendor advisory Critical vendor advisory CVE-2026-60002

Openbsd Openssh — CVE-2026-60002 (Critical)

Openbsd · Openssh

ssh in OpenSSH before 10.4 can have a use-after-free when a server changes its host key during a key re-exchange. (This outcome occurs only on the client side.)

Operator check

Review CVE-2026-60002 in your asset inventory. Apply patches per vendor guidance and verify Openssh is not exposed. CVSS score: 7.7. EPSS probability: 0.3%; percentile: 16%.

Read brief →
Jul 8, 2026 Vendor advisory Critical vendor advisory CVE-2026-8649

Progress Moveit Transfer — CVE-2026-8649 (Critical)

Progress · Moveit Transfer

Improper Neutralization of Special Elements in Data Query Logic vulnerability in Progress MOVEit Transfer (Custom Reports modules). This issue affects MOVEit Transfer: before 2025.0.7, from 2025.1.0 before 2025.1.3.

Operator check

Review CVE-2026-8649 in your asset inventory. Apply patches per vendor guidance and verify Moveit Transfer is not exposed. CVSS score: 6.4. EPSS probability: 0.2%; percentile: 13%.

Read brief →
Jul 8, 2026 Vendor advisory Critical vendor advisory CVE-2026-8801

Progress Moveit Transfer — CVE-2026-8801 (Critical)

Progress · Moveit Transfer

Path equivalence: vulnerability in Progress MOVEit Transfer (File Upload modules). This issue affects MOVEit Transfer: before 2025.0.8, from 2025.1.0 before 2025.1.4.

Operator check

Review CVE-2026-8801 in your asset inventory. Apply patches per vendor guidance and verify Moveit Transfer is not exposed. CVSS score: 3.5. EPSS probability: 0.3%; percentile: 16%.

Read brief →
Jul 8, 2026 Vendor advisory High-risk advisory CVE-2026-49471

Serena: Unauthenticated Flask dashboard on fixed port enables DNS rebinding → memory poisoning → RCE

PyPI · serena-agent

Serena: Unauthenticated Flask dashboard on fixed port enables DNS rebinding → memory poisoning → RCE

Operator check

Check whether serena-agent is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. EPSS probability: 0.2%; percentile: 15%.

Read brief →
Jul 8, 2026 Vendor advisory High-risk advisory CVE-2026-49825

`lxml_html_clean.Cleaner` does not strip `javascript:` URLs from namespaced URL attributes

PyPI · lxml_html_clean

`lxml_html_clean.Cleaner` does not strip `javascript:` URLs from namespaced URL attributes

Operator check

Check whether lxml_html_clean is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.

Read brief →
Jul 8, 2026 Coordinated disclosure Patch review

VU#849433: Adalo Database API Enables Cross-App User Data Extraction via Over-Fetching and Missing Authorization Cont...

Unrestricted · Disclosure of Full User Records The Adalo database API

Overview Adalo’s no‑code application platform exposes complete user records through its database API for all applications built on both V1 and V2. Due to a platform-level flaw, authenticated users can retrieve full user data belonging to any Adalo application, regardless of configuration. This issue affects more than one million applications and placing developers and their end users at risk of data exposure that they cannot prevent or remediate. Description Adalo is a Software-as-a-Service (SaaS) provider for building no-code applications. In theory, each application or tenant (customer) is logically isolated with separate databases, users, and configurations. CVE-2026-10706 Unrestricted Disclosure of Full User Records The Adalo database API contains a flaw which allows the backend to return complete user records for every list... Related CVEs: CVE-2026-10706, CVE-2026-10708.

Operator check

Review the CERT/CC Vulnerability Note and compare the affected vendor and product list against your inventory. Apply vendor fixes or compensating controls for Disclosure of Full User Records The Adalo database API where available.

Read brief →
Jul 7, 2026 KEV Known exploited CVE-2026-48282

Adobe ColdFusion Path Traversal Vulnerability

Adobe · ColdFusion

Adobe ColdFusion contains a path traversal vulnerability that could lead to arbitrary code execution in the context of the current user.

Operator check

Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

Read brief →
Jul 7, 2026 Vendor advisory Critical vendor advisory CVE-2026-27823

EGroupware has a Remote Code Execution Vulnerability

Composer · egroupware/egroupware

EGroupware has a Remote Code Execution Vulnerability

Operator check

Check whether egroupware/egroupware is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. CVSS score: 9.3.

Read brief →
Jul 7, 2026 Vendor advisory High-risk advisory CVE-2026-40187

EGroupware has Authenticated RCE via Malicious eTemplate Upload

Composer · egroupware/egroupware

EGroupware has Authenticated RCE via Malicious eTemplate Upload

Operator check

Check whether egroupware/egroupware is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. CVSS score: 8.6.

Read brief →
Jul 7, 2026 Vendor advisory Critical vendor advisory CVE-2026-13020

Esri Portal For Arcgis — CVE-2026-13020 (Critical)

Esri · Portal For Arcgis

A Weak Password Recovery Mechanism for Forgotten Password exists in Esri Portal for ArcGIS versions 12.1 and earlier on Windows, Linux and Kubernetes. A remote, unauthorized attacker may assume ownership of a user’s account by manipulating this mechanism. ArcGIS Administrators should configure an email server with ArcGIS Enterprise to facilitate user self-service password recovery. The ability for an administrator to reset a user’s password remains unchanged.

Operator check

Review CVE-2026-13020 in your asset inventory. Apply patches per vendor guidance and verify Portal For Arcgis is not exposed. CVSS score: 8.1. EPSS probability: 0.2%; percentile: 13%.

Read brief →
Jul 7, 2026 Vendor advisory High-risk advisory CVE-2026-33655

New API: SSRF Protection Bypass via Unresolved Hostname in Notification URLs

Go · github.com/QuantumNous/new-api

New API: SSRF Protection Bypass via Unresolved Hostname in Notification URLs

Operator check

Check whether github.com/QuantumNous/new-api is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.

Read brief →
Jul 7, 2026 Vendor advisory High-risk advisory CVE-2026-53552

Goploy: Cross-namespace IDOR and RCE via body-supplied row id in project and project_file handlers

Go · github.com/zhenorzz/goploy

Goploy: Cross-namespace IDOR and RCE via body-supplied row id in project and project_file handlers

Operator check

Check whether github.com/zhenorzz/goploy is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.

Read brief →
Jul 7, 2026 Vendor advisory High-risk advisory CVE-2026-53553

Goploy: Arbitrary File Read via Path Traversal in /deploy/fileDiff allows Remote Server Compromise

Go · github.com/zhenorzz/goploy

Goploy: Arbitrary File Read via Path Traversal in /deploy/fileDiff allows Remote Server Compromise

Operator check

Check whether github.com/zhenorzz/goploy is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.

Read brief →
Jul 7, 2026 KEV Known exploited CVE-2026-56290

Joomlack Page Builder Improper Access Control Vulnerability

Joomlack · Page Builder

Joomlack Page Builder contains an improper access control vulnerability that could allow for remote code execution via unauthenticated arbitrary file upload.

Operator check

Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

Read brief →
Jul 7, 2026 KEV Known exploited CVE-2026-48908

JoomShaper SP Page Builder Unrestricted Upload of File with Dangerous Type Vulnerability

JoomShaper · SP Page Builder

JoomShaper SP Page Builder contains an unrestricted upload of file with dangerous type vulnerability that allows unauthenticated users to upload arbitrary files, ultimately resulting in the upload and execution of PHP code.

Operator check

Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

Read brief →
Jul 7, 2026 KEV Known exploited CVE-2026-55255

Langflow Authorization Bypass Through User-Controlled Key Vulnerability

Langflow · Langflow

Langflow contains an authorization bypass through user-controlled key vulnerability which allows an authenticated attacker to execute any flow belonging to another user by specifying the victim's flow ID in the request.

Operator check

Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

Read brief →
Jul 7, 2026 Vendor advisory High-risk advisory CVE-2026-34151

XWiki Platform Old Core: Resource path traversal via /skin/ action endpoint in Jetty 12+

Maven · org.xwiki.platform:xwiki-platform-oldcore

XWiki Platform Old Core: Resource path traversal via /skin/ action endpoint in Jetty 12+

Operator check

Check whether org.xwiki.platform:xwiki-platform-oldcore is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. CVSS score: 8.2.

Read brief →
Jul 7, 2026 Vendor advisory High-risk advisory CVE-2026-53512

Better Auth: OAuth refresh-token replay via missing client authentication on oidc-provider and mcp plugins

npm · better-auth

Better Auth: OAuth refresh-token replay via missing client authentication on oidc-provider and mcp plugins

Operator check

Check whether better-auth is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.

Read brief →
Jul 7, 2026 Vendor advisory High-risk advisory CVE-2026-53513

@better-auth/sso provider registration has server-side request forgery via unvalidated OIDC endpoints

npm · @better-auth/sso

@better-auth/sso provider registration has server-side request forgery via unvalidated OIDC endpoints

Operator check

Check whether @better-auth/sso is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.

Read brief →
Jul 7, 2026 Vendor advisory High-risk advisory CVE-2026-53514

Better Auth vulnerable to unauthorized invitation acceptance via unverified email match in organization plugin

npm · better-auth

Better Auth vulnerable to unauthorized invitation acceptance via unverified email match in organization plugin

Operator check

Check whether better-auth is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.

Read brief →
Jul 7, 2026 Vendor advisory High-risk advisory CVE-2026-53516

Better Auth has an account takeover issue via OAuth auto-link to unverified pre-registered email

npm · better-auth

Better Auth has an account takeover issue via OAuth auto-link to unverified pre-registered email

Operator check

Check whether better-auth is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.

Read brief →
Jul 7, 2026 Vendor advisory High-risk advisory CVE-2026-53517

Better Auth: OAuth refresh-token rotation forks the token family on concurrent redemption

npm · @better-auth/oauth-provider

Better Auth: OAuth refresh-token rotation forks the token family on concurrent redemption

Operator check

Check whether @better-auth/oauth-provider is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. CVSS score: 7.6.

Read brief →
Jul 7, 2026 Vendor advisory High-risk advisory CVE-2026-53518

@better-auth/oauth-provider's OAuth authorization-code grant allows concurrent redemption when two token requests rac...

npm · @better-auth/oauth-provider

@better-auth/oauth-provider's OAuth authorization-code grant allows concurrent redemption when two token requests race the find-then-delete primitive

Operator check

Check whether @better-auth/oauth-provider is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. CVSS score: 7.6.

Read brief →
Jul 7, 2026 Vendor advisory High-risk advisory

Better Auth has stored XSS in the auth-server origin via javascript: redirect_uri in oidc-provider and mcp

npm · better-auth

Better Auth has stored XSS in the auth-server origin via javascript: redirect_uri in oidc-provider and mcp

Operator check

Check whether better-auth is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.

Read brief →
Jul 7, 2026 Vendor advisory High-risk advisory

Better Auth has insecure cryptographic defaults in oidcProvider: alg=none advertised and plain PKCE accepted by default

npm · better-auth

Better Auth has insecure cryptographic defaults in oidcProvider: alg=none advertised and plain PKCE accepted by default

Operator check

Check whether better-auth is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.

Read brief →
Jul 7, 2026 Vendor advisory High-risk advisory

@better-auth/scim: Account/provider takeover via missing owner binding on non-org SCIM providers

npm · @better-auth/scim

@better-auth/scim: Account/provider takeover via missing owner binding on non-org SCIM providers

Operator check

Check whether @better-auth/scim is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.

Read brief →
Jul 7, 2026 Vendor advisory High-risk advisory CVE-2025-46719

Open WebUI vulnerable to stored XSS via unescaped markdown token in MarkdownTokens.svelte leading to full account tak...

PyPI · open-webui

Open WebUI vulnerable to stored XSS via unescaped markdown token in MarkdownTokens.svelte leading to full account takeover and RCE via functions

Operator check

Check whether open-webui is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. CVSS score: 7.4. EPSS probability: 0.4%; percentile: 35%.

Read brief →
Jul 7, 2026 Vendor advisory High-risk advisory CVE-2026-26192

Open WebUI vulnerable to Stored XSS via iFrame in citations model

PyPI · open-webui

Open WebUI vulnerable to Stored XSS via iFrame in citations model

Operator check

Check whether open-webui is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. EPSS probability: 0.2%; percentile: 9%.

Read brief →
Jul 7, 2026 Vendor advisory High-risk advisory CVE-2026-26193

Open WebUI vulnerable to Stored XSS via iFrame embeds in response messages

PyPI · open-webui

Open WebUI vulnerable to Stored XSS via iFrame embeds in response messages

Operator check

Check whether open-webui is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. EPSS probability: 0.2%; percentile: 10%.

Read brief →
Jul 7, 2026 Vendor advisory High-risk advisory CVE-2026-53530

ratex-parser panics on `\verb` with a multibyte delimiter (UTF-8 byte-boundary slice)

Rust · ratex-parser

ratex-parser panics on `\verb` with a multibyte delimiter (UTF-8 byte-boundary slice)

Operator check

Check whether ratex-parser is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. CVSS score: 8.7.

Read brief →
Jul 7, 2026 Vendor advisory High-risk advisory

uutils coreutils: cp/install/mv/ln --suffix alone does not enable backup mode (silent data loss vs GNU)

Rust · uucore

uutils coreutils: cp/install/mv/ln --suffix alone does not enable backup mode (silent data loss vs GNU)

Operator check

Check whether uucore is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. CVSS score: 7.0.

Read brief →
Jul 6, 2026 Vendor advisory Critical vendor advisory CVE-2026-40139

Beyondtrust Privileged Remote Access — CVE-2026-40139 (Critical)

Beyondtrust · Privileged Remote Access

A critical pre-authentication vulnerability exists in the authentication subsystem of BeyondTrust Remote Support. Improper processing of authentication requests may allow an unauthenticated remote attacker to bypass access controls and gain unauthorized access to the appliance, including accounts with elevated privileges. Exploitation requires a specific authentication configuration to be enabled.

Operator check

Review CVE-2026-40139 in your asset inventory. Apply patches per vendor guidance and verify Privileged Remote Access is not exposed. CVSS score: 9.8. EPSS probability: 0.7%; percentile: 49%.

Read brief →
Jul 6, 2026 Vendor advisory Critical vendor advisory CVE-2026-40141

Beyondtrust Privileged Remote Access — CVE-2026-40141 (Critical)

Beyondtrust · Privileged Remote Access

A high-severity vulnerability exists in a web application component of BeyondTrust Remote Support and Privileged Remote Access related to the processing of certain input parameters. Insufficient validation of user-supplied input may allow an authenticated attacker with limited privileges to access unintended resources or data beyond their authorization scope. Exploitation is restricted to accounts with specific permissions.

Operator check

Review CVE-2026-40141 in your asset inventory. Apply patches per vendor guidance and verify Privileged Remote Access is not exposed. CVSS score: 9.9. EPSS probability: 0.4%; percentile: 33%.

Read brief →
Jul 6, 2026 Vendor advisory High-risk advisory CVE-2026-52889

Formie Hidden field defaults vulnerable to Server-Side Template Injection

Composer · verbb/formie

Formie Hidden field defaults vulnerable to Server-Side Template Injection

Operator check

Check whether verbb/formie is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.

Read brief →
Jul 6, 2026 Vendor advisory High-risk advisory CVE-2026-55790

Craft CMS: DOM XSS via GitHub issue title in CraftSupport widget

Composer · craftcms/cms

Craft CMS: DOM XSS via GitHub issue title in CraftSupport widget

Operator check

Check whether craftcms/cms is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. CVSS score: 7.4. EPSS probability: 0.3%; percentile: 23%.

Read brief →
Jul 6, 2026 Vendor advisory High-risk advisory CVE-2026-55794

Craft CMS: Potential authenticated Remote Code Execution via referrer redirect

Composer · craftcms/cms

Craft CMS: Potential authenticated Remote Code Execution via referrer redirect

Operator check

Check whether craftcms/cms is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. CVSS score: 8.7. EPSS probability: 0.3%; percentile: 21%.

Read brief →
Jul 6, 2026 Vendor advisory Critical vendor advisory CVE-2026-9182

Esri Arcgis Server — CVE-2026-9182 (Critical)

Esri · Arcgis Server

ArcGIS Server contains an unrestricted file upload vulnerability. An unauthenticated attacker could exploit this issue by uploading a crafted file to the affected endpoint. Successful exploitation could allow arbitrary file upload.

Operator check

Review CVE-2026-9182 in your asset inventory. Apply patches per vendor guidance and verify Arcgis Server is not exposed. CVSS score: 5.3. EPSS probability: 0.2%; percentile: 13%.

Read brief →
Jul 6, 2026 Vendor advisory High-risk advisory CVE-2026-49445

Cilium vulnerable to sensitive information disclosure and cluster disruption via local Envoy admin socket access

Go · github.com/cilium/cilium

Cilium vulnerable to sensitive information disclosure and cluster disruption via local Envoy admin socket access

Operator check

Check whether github.com/cilium/cilium is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.

Read brief →
Jul 6, 2026 Vendor advisory High-risk advisory CVE-2026-55075

Coder vulnerable to OIDC account takeover via email-based user matching and email_verified bypass

Go · github.com/coder/coder/v2

Coder vulnerable to OIDC account takeover via email-based user matching and email_verified bypass

Operator check

Check whether github.com/coder/coder/v2 is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.

Read brief →
Jul 6, 2026 Vendor advisory High-risk advisory CVE-2026-55076

Coder's OIDC email_verified type coercion bypass enables account takeover via unverified email linking

Go · github.com/coder/coder/v2

Coder's OIDC email_verified type coercion bypass enables account takeover via unverified email linking

Operator check

Check whether github.com/coder/coder/v2 is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.

Read brief →
Jul 6, 2026 Vendor advisory High-risk advisory CVE-2026-55077

Coder: User-admin role can reset owner account password

Go · github.com/coder/coder/v2

Coder: User-admin role can reset owner account password

Operator check

Check whether github.com/coder/coder/v2 is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.

Read brief →
Jul 6, 2026 Vendor advisory High-risk advisory CVE-2026-55427

Coder vulnerable to SSH config injection via unsanitized server-supplied values in `coder config-ssh`

Go · github.com/coder/coder/v2

Coder vulnerable to SSH config injection via unsanitized server-supplied values in `coder config-ssh`

Operator check

Check whether github.com/coder/coder/v2 is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.

Read brief →
Jul 6, 2026 Vendor advisory High-risk advisory CVE-2026-55428

Coder: Route hijacking through lack of validation of agent-supplied AllowedIPs in tailnet coordinator

Go · github.com/coder/coder/v2

Coder: Route hijacking through lack of validation of agent-supplied AllowedIPs in tailnet coordinator

Operator check

Check whether github.com/coder/coder/v2 is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.

Read brief →
Jul 6, 2026 Vendor advisory High-risk advisory CVE-2026-55429

Coder's workspace app upsert allows cross-workspace agent rebinding via user-controlled app ID

Go · github.com/coder/coder/v2

Coder's workspace app upsert allows cross-workspace agent rebinding via user-controlled app ID

Operator check

Check whether github.com/coder/coder/v2 is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.

Read brief →
Jul 6, 2026 Vendor advisory High-risk advisory CVE-2026-55431

Coder's session token leaked to arbitrary hosts via `coder open app` for external workspace apps

Go · github.com/coder/coder/v2

Coder's session token leaked to arbitrary hosts via `coder open app` for external workspace apps

Operator check

Check whether github.com/coder/coder/v2 is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.

Read brief →
Jul 6, 2026 Vendor advisory High-risk advisory CVE-2026-55436

Coder's AI Bridge Proxy skips TLS certificate verification in default configuration

Go · github.com/coder/coder/v2

Coder's AI Bridge Proxy skips TLS certificate verification in default configuration

Operator check

Check whether github.com/coder/coder/v2 is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.

Read brief →
Jul 6, 2026 Vendor advisory High-risk advisory

Coder's workspace agent API insecure redirect handling allowed cross-agent file read and write

Go · github.com/coder/coder/v2

Coder's workspace agent API insecure redirect handling allowed cross-agent file read and write

Operator check

Check whether github.com/coder/coder/v2 is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.

Read brief →
Jul 6, 2026 Vendor advisory High-risk advisory CVE-2026-54640

OpenRemote has an incomplete fix for CVE-2026-40882: XXE in KNXProtocol.startAssetImport() allows arbitrary file read...

Maven · io.openremote:openremote-agent

OpenRemote has an incomplete fix for CVE-2026-40882: XXE in KNXProtocol.startAssetImport() allows arbitrary file read via unprotected XMLInputFactory

Operator check

Check whether io.openremote:openremote-agent is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.

Read brief →
Jul 6, 2026 Vendor advisory High-risk advisory CVE-2026-54641

OpenRemote has Cross-Realm User Information Disclosure in UserResourceImpl

Maven · io.openremote:openremote-manager

OpenRemote has Cross-Realm User Information Disclosure in UserResourceImpl

Operator check

Check whether io.openremote:openremote-manager is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.

Read brief →
Jul 6, 2026 Vendor advisory High-risk advisory

OpenRemote has Authenticated SQL Injection via Datapoint Crosstab Export

Maven · io.openremote:openremote-manager

OpenRemote has Authenticated SQL Injection via Datapoint Crosstab Export

Operator check

Check whether io.openremote:openremote-manager is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. CVSS score: 7.2.

Read brief →
Jul 6, 2026 Vendor advisory High-risk advisory CVE-2026-53486

Decompress: Archive extraction can create files and links outside of the target directory

npm · @xhmikosr/decompress

Decompress: Archive extraction can create files and links outside of the target directory

Operator check

Check whether @xhmikosr/decompress is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.

Read brief →
Jul 6, 2026 Vendor advisory High-risk advisory CVE-2026-55500

9routers has Exposure of Sensitive Information and Unprotected Database Import/Export, Allowing Complete Credential T...

npm · 9router

9routers has Exposure of Sensitive Information and Unprotected Database Import/Export, Allowing Complete Credential Theft and Database Takeover

Operator check

Check whether 9router is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.

Read brief →
Jul 6, 2026 Vendor advisory High-risk advisory CVE-2026-55501

9router: Login brute-force protection bypass via spoofed X-Forwarded-For header

npm · 9router

9router: Login brute-force protection bypass via spoofed X-Forwarded-For header

Operator check

Check whether 9router is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.

Read brief →
Jul 6, 2026 Vendor advisory High-risk advisory

9router has unauthenticated CRUD on /api/providers and Full API Key Leak via /api/usage/stats

npm · 9router

9router has unauthenticated CRUD on /api/providers and Full API Key Leak via /api/usage/stats

Operator check

Check whether 9router is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.

Read brief →
Jul 6, 2026 Coordinated disclosure Patch review

VU#828543: HP Deskjet 2800 Printer Series Webservers contain Missing Authorization Vulnerability

Overview · HP Printers in the Deskjet 2800 Series running firmware

Overview HP Printers in the Deskjet 2800 Series running firmware version CVE-2026-13753 . This vulnerability allows unauthenticated access to the printer's webserver API endpoints, exposing Wi-Fi credentials, management configuration details, and sensitive security data normally restricted to administrative users. Description Modern HP printers provide a web-based management interface for configuring content such as Wi-Fi Direct settings, SNMP management access, and device security options. When accessed normally through the browser interface, these pages explicitly require administrator credentials before sensitive information is displayed. This information is protected because, for example, Wi-Fi Direct controls the printer's direct wireless connectivity, and SNMP configuration settings can reveal detailed information about the... Related CVEs: CVE-2026-13753.

Operator check

Review the CERT/CC Vulnerability Note and compare the affected vendor and product list against your inventory. Apply vendor fixes or compensating controls for HP Printers in the Deskjet 2800 Series running firmware where available.

Read brief →
Jul 6, 2026 Vendor advisory Critical vendor advisory CVE-2026-54760

Langroid: SQLChatAgent dangerous-function blocklist can be bypassed with quoted or schema-qualified pg_read_file calls

PyPI · langroid

Langroid: SQLChatAgent dangerous-function blocklist can be bypassed with quoted or schema-qualified pg_read_file calls

Operator check

Check whether langroid is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. CVSS score: 9.3.

Read brief →
Jul 6, 2026 Vendor advisory High-risk advisory CVE-2026-54769

Langroid: Sandbox Escape to Remote Code Execution via Incomplete `eval()` Mitigation in TableChatAgent

PyPI · langroid

Langroid: Sandbox Escape to Remote Code Execution via Incomplete `eval()` Mitigation in TableChatAgent

Operator check

Check whether langroid is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.

Read brief →
Jul 6, 2026 Vendor advisory High-risk advisory CVE-2026-54771

Langroid: handle_message() executes user-supplied tool JSON without sender verification

PyPI · langroid

Langroid: handle_message() executes user-supplied tool JSON without sender verification

Operator check

Check whether langroid is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.

Read brief →
Jul 6, 2026 Vendor advisory High-risk advisory CVE-2026-55426

Linuxfabrik Monitoring Plugins have local privilege escalation using embedded command

PyPI · linuxfabrik-lib

Linuxfabrik Monitoring Plugins have local privilege escalation using embedded command

Operator check

Check whether linuxfabrik-lib is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.

Read brief →
Jul 6, 2026 Vendor advisory Critical vendor advisory CVE-2026-55615

Langroid: Neo4jChatAgent executes LLM-generated Cypher without validation (prompt-to-Cypher injection; config-conditi...

PyPI · langroid

Langroid: Neo4jChatAgent executes LLM-generated Cypher without validation (prompt-to-Cypher injection; config-conditional RCE), mirroring the SQLChatAgent bug fixed in CVE-2026-25879

Operator check

Check whether langroid is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. CVSS score: 9.2.

Read brief →
Jul 6, 2026 Vendor advisory High-risk advisory CVE-2026-55786

flyto-core has Unauthenticated Command Execution via HTTP MCP `execute_module`

PyPI · flyto-core

flyto-core has Unauthenticated Command Execution via HTTP MCP `execute_module`

Operator check

Check whether flyto-core is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.

Read brief →
Jul 6, 2026 Vendor advisory High-risk advisory CVE-2026-55787

flyto-core has SSRF guard bypass via IPv6 transition addresses (IPv4-mapped / 6to4 / NAT64) in validate_url_ssrf

PyPI · flyto-core

flyto-core has SSRF guard bypass via IPv6 transition addresses (IPv4-mapped / 6to4 / NAT64) in validate_url_ssrf

Operator check

Check whether flyto-core is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.

Read brief →
Jul 6, 2026 Vendor advisory High-risk advisory CVE-2026-35338

chmod: --preserve-root bypassed by any path that resolves to root (e.g. /../)

Rust · uu_chmod

chmod: --preserve-root bypassed by any path that resolves to root (e.g. /../)

Operator check

Check whether uu_chmod is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. EPSS probability: 0.2%; percentile: 7%.

Read brief →
Jul 6, 2026 Vendor advisory High-risk advisory CVE-2026-35341

mkfifo: permissions of an existing file are changed after FIFO creation fails

Rust · uu_mkfifo

mkfifo: permissions of an existing file are changed after FIFO creation fails

Operator check

Check whether uu_mkfifo is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. EPSS probability: 0.2%; percentile: 6%.

Read brief →
Jul 6, 2026 Vendor advisory High-risk advisory CVE-2026-54496

Zebra: Missing copy constraint in halo2_gadgets variable-base scalar multiplication allows under-constrained base, br...

Rust · zebrad

Zebra: Missing copy constraint in halo2_gadgets variable-base scalar multiplication allows under-constrained base, breaking Orchard Action circuit soundness

Operator check

Check whether zebrad is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.

Read brief →
Jul 6, 2026 Coordinated disclosure Patch review

VU#213560: Tenda firmware (multiple versions) contains hidden authentication backdoor

Tenda · firmware (multiple

Overview Several versions of Tenda firmware contain an undocumented authentication backdoor that grants administrative access to the devices' web management interfaces. An attacker can expoit this vulnerability, tracked as CVE-2026-11405, to bypass the password verification process and obtain full administrative control without valid credentials. Affected Versions: * US_FH1201V1.0BR_V1.2.0.14(408)_EN_TD * US_W15EV1.0br_V15.11.0.5(1068_1567_841)_EN_TDE * US_AC10V1.0re_V15.03.06.46_multi_TDE01 * US_AC5V1.0RTL_V15.03.06.48_multi_TDE01 * US_AC6V2.0RTL_V15.03.06.51_multi_T Description Tenda is a supplier of home and business network devices such as routers, switches, wireless access points, and video surveillance equipment. Most of these devices include web-based interfaces that allow users to perform configuration and management operations... Related CVEs: CVE-2026-11405.

Operator check

Review the CERT/CC Vulnerability Note and compare the affected vendor and product list against your inventory. Apply vendor fixes or compensating controls for firmware (multiple where available.

Read brief →
Jul 6, 2026 Vendor advisory Critical vendor advisory CVE-2026-54763

Traefik Traefik — CVE-2026-54763 (Critical)

Traefik · Traefik

Traefik is an HTTP reverse proxy and load balancer. Prior to v2.11.51, v3.6.22, and v3.7.6, Traefik's BasicAuth, DigestAuth, and ForwardAuth middlewares strip canonical-cased spoofed identity headers before writing Traefik's own value, but do not account for underscore-variant header names, which many backends normalize identically to dashed forms. An attacker able to reach a protected route can inject an underscore-variant header that survives Traefik's stripping and reaches the backend alongside, or on the unauthenticated ForwardAuth authResponseHeaders path instead of, the value Traefik int

Operator check

Review CVE-2026-54763 in your asset inventory. Apply patches per vendor guidance and verify Traefik is not exposed. CVSS score: 10.0. EPSS probability: 0.3%; percentile: 19%.

Read brief →
Jul 2, 2026 Vendor advisory Critical vendor advisory CVE-2026-59099

Apereo CAS 7.3.0 — CVE-2026-59099 (Critical)

Apereo · CAS 7.3.0

Apereo CAS 7.3.0 before 8.0.0-RC6 contains a cryptographic vulnerability that allows remote unauthenticated attackers to recover plaintext conversation state by exploiting AES-GCM initialization vector reuse across the server lifetime. Attackers can collect multiple client-side webflow execution tokens from the unauthenticated login page and perform known-plaintext analysis to decrypt the webflow conversation state due to keystream reuse caused by a fixed all-zero IV paired with the same encryption key.

Operator check

Review CVE-2026-59099 in your asset inventory. Apply patches per vendor guidance and verify CAS 7.3.0 is not exposed. CVSS score: 9.1. EPSS probability: 0.4%; percentile: 28%.

Read brief →
Jul 2, 2026 Vendor advisory High-risk advisory CVE-2026-49283

SimpleSAMLphp HTTP-Artifact TLS validator confusion allows cross-IdP authentication bypass

Composer · simplesamlphp/saml2

SimpleSAMLphp HTTP-Artifact TLS validator confusion allows cross-IdP authentication bypass

Operator check

Check whether simplesamlphp/saml2 is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.

Read brief →
Jul 2, 2026 Vendor advisory High-risk advisory CVE-2026-49284

SimpleSAMLphp SP accepts a response from an unexpected IdP when unsigned `Response/InResponseTo` is combined with a s...

Composer · simplesamlphp/simplesamlphp

SimpleSAMLphp SP accepts a response from an unexpected IdP when unsigned `Response/InResponseTo` is combined with a signed assertion lacking `SubjectConfirmationData/InResponseTo`

Operator check

Check whether simplesamlphp/simplesamlphp is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.

Read brief →
Jul 2, 2026 Vendor advisory High-risk advisory CVE-2026-50281

Craft CMS's mass assignment via id in newAttributes during bulk duplicate overwrites existing elements

Composer · craftcms/cms

Craft CMS's mass assignment via id in newAttributes during bulk duplicate overwrites existing elements

Operator check

Check whether craftcms/cms is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. CVSS score: 7.1. EPSS probability: 0.3%; percentile: 17%.

Read brief →
Jul 2, 2026 Vendor advisory High-risk advisory CVE-2026-50282

Craft CMS Vulnerable to Unauthorized Deletion of Destination Folders During Forced Moves

Composer · craftcms/cms

Craft CMS Vulnerable to Unauthorized Deletion of Destination Folders During Forced Moves

Operator check

Check whether craftcms/cms is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. CVSS score: 7.1. EPSS probability: 0.2%; percentile: 11%.

Read brief →
Jul 2, 2026 Vendor advisory High-risk advisory CVE-2026-9558

Mautic has Server-Side Template Injection (SSTI) in Theme Templates

Composer · mautic/core

Mautic has Server-Side Template Injection (SSTI) in Theme Templates

Operator check

Check whether mautic/core is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. EPSS probability: 0.4%; percentile: 35%.

Read brief →
Jul 2, 2026 Vendor advisory High-risk advisory CVE-2026-9559

Mautic vulnerable to Path Traversal via Campaign Import

Composer · mautic/core

Mautic vulnerable to Path Traversal via Campaign Import

Operator check

Check whether mautic/core is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. EPSS probability: 0.6%; percentile: 44%.

Read brief →
Jul 2, 2026 Vendor advisory High-risk advisory CVE-2026-9808

Mautic has an Authorization Bypass in API v2 Endpoints

Composer · mautic/core

Mautic has an Authorization Bypass in API v2 Endpoints

Operator check

Check whether mautic/core is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. EPSS probability: 0.2%; percentile: 10%.

Read brief →
Jul 2, 2026 Vendor advisory High-risk advisory CVE-2026-9809

Mautic has Stored Cross-Site Scripting (XSS) in Projects Component

Composer · mautic/core

Mautic has Stored Cross-Site Scripting (XSS) in Projects Component

Operator check

Check whether mautic/core is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. EPSS probability: 0.2%; percentile: 6%.

Read brief →
Jul 2, 2026 Vendor advisory High-risk advisory CVE-2026-46599

golang.org/x/image/tiff has excessive resource consumption in PackBits decompression

Go · golang.org/x/image

golang.org/x/image/tiff has excessive resource consumption in PackBits decompression

Operator check

Check whether golang.org/x/image is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. EPSS probability: 0.4%; percentile: 27%.

Read brief →
Jul 2, 2026 Vendor advisory High-risk advisory CVE-2026-52792

Algernon vulnerable to server-side script source disclosure on Windows via NTFS filename

Go · github.com/xyproto/algernon

Algernon vulnerable to server-side script source disclosure on Windows via NTFS filename

Operator check

Check whether github.com/xyproto/algernon is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. CVSS score: 8.7.

Read brief →
Jul 2, 2026 Coordinated disclosure Patch review

VU#639124: Multiple local privilege escalation vulnerabilities in Little Orbits GameFirst Anti-Cheat

Little · Orbits GameFirst Anti-Cheat

Overview The GamersFirst Anti-Cheat (GFAC) driver GFAC.sys contains multiple local privilege escalations and denial-of-service vulnerabilities stemming from insecure handling of user-controlled input through a minifilter communication port. A local attacker can abuse these flaws to perform arbitrary kernel memory writes, obtain privilege escalation to SYSTEM, or trigger a system crash. Description GFAC is a proprietary anti-cheat software developed by video game publisher Little Orbit. GFAC includes a kernel-mode driver, GFAC_Sys_x64.sys , that exposes privileged functionality to user-mode applications through a minifilter communication port. Although these low-level interfaces are necessary for the software's operation, vulnerabilities can arise if user-mode access is not properly restricted and validated. CVE-2026-12166... Related CVEs: CVE-2026-12166, CVE-2026-12167, CVE-2026-12168.

Operator check

Review the CERT/CC Vulnerability Note and compare the affected vendor and product list against your inventory. Apply vendor fixes or compensating controls for Orbits GameFirst Anti-Cheat where available.

Read brief →
Jul 2, 2026 Vendor advisory High-risk advisory CVE-2026-2092

Keycloak: Unauthorized access via improper validation of encrypted SAML assertions

Maven · org.keycloak:keycloak-services

Keycloak: Unauthorized access via improper validation of encrypted SAML assertions

Operator check

Check whether org.keycloak:keycloak-services is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. EPSS probability: 0.2%; percentile: 15%.

Read brief →
Jul 2, 2026 Vendor advisory High-risk advisory CVE-2026-54617

LaunchServer FileServerHandler has an unauthenticated path traversal issue

Maven · pro.gravit.launcher:launchserver-api

LaunchServer FileServerHandler has an unauthenticated path traversal issue

Operator check

Check whether pro.gravit.launcher:launchserver-api is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.

Read brief →
Jul 2, 2026 Patch Tuesday High-risk advisory CVE-2026-26145

Microsoft Azure Synapse Elevation of Privilege Vulnerability

Microsoft · Azure Synapse

Improper access control in Azure Synapse allows an authorized attacker to elevate privileges over a network. Published in July 2026 Early Security Updates. MSRC exploitability: Publicly Disclosed:No;Exploited:No;Latest Software Release:N/A.

Operator check

Review the Microsoft Security Update Guide entry for CVE-2026-26145. Confirm whether Azure Synapse is deployed, then apply the current security update or documented mitigation. CVSS score: 4.8.

Read brief →
Jul 2, 2026 Patch Tuesday Critical vendor advisory CVE-2026-41106

Microsoft 365 Copilot Elevation of Privilege Vulnerability

Microsoft · M365 Copilot

Url redirection to untrusted site ('open redirect') in M365 Copilot allows an unauthorized attacker to elevate privileges over a network. Published in July 2026 Early Security Updates. MSRC exploitability: Publicly Disclosed:No;Exploited:No;Latest Software Release:N/A.

Operator check

Review the Microsoft Security Update Guide entry for CVE-2026-41106. Confirm whether M365 Copilot is deployed, then apply the current security update or documented mitigation. CVSS score: 9.3.

Read brief →
Jul 2, 2026 Patch Tuesday Critical vendor advisory CVE-2026-45499

Azure OpenAI Elevation of Privilege Vulnerability

Microsoft · Azure OpenAI

Server-side request forgery (ssrf) in Azure OpenAI allows an authorized attacker to elevate privileges over a network. Published in July 2026 Early Security Updates. MSRC exploitability: Publicly Disclosed:No;Exploited:No;Latest Software Release:N/A.

Operator check

Review the Microsoft Security Update Guide entry for CVE-2026-45499. Confirm whether Azure OpenAI is deployed, then apply the current security update or documented mitigation. CVSS score: 9.9.

Read brief →
Jul 2, 2026 Patch Tuesday High-risk advisory CVE-2026-54998

Microsoft Exchange Online Elevation of Privilege Vulnerability

Microsoft · Microsoft Exchange Online

Incorrect authorization in Microsoft Exchange Online allows an authorized attacker to elevate privileges over a network. Published in July 2026 Early Security Updates. MSRC exploitability: Publicly Disclosed:No;Exploited:No;Latest Software Release:N/A.

Operator check

Review the Microsoft Security Update Guide entry for CVE-2026-54998. Confirm whether Microsoft Exchange Online is deployed, then apply the current security update or documented mitigation. CVSS score: 8.8.

Read brief →
Jul 2, 2026 Patch Tuesday High-risk advisory CVE-2026-56645

Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability

Microsoft · Microsoft Edge (Chromium-based)

Heap-based buffer overflow in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network. Published in July 2026 Early Security Updates. MSRC exploitability: Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation Less Likely.

Operator check

Review the Microsoft Security Update Guide entry for CVE-2026-56645. Confirm whether Microsoft Edge (Chromium-based) is deployed, then apply the current security update or documented mitigation. CVSS score: 8.8.

Read brief →
Jul 2, 2026 Patch Tuesday Critical vendor advisory CVE-2026-57100

Microsoft Entra Provisioning Service Elevation of Privilege Vulnerability

Microsoft · Microsoft Entra Provisioning Service (SyncFabric)

Server-side request forgery (ssrf) in Microsoft Entra Provisioning Service (SyncFabric) allows an authorized attacker to elevate privileges over a network. Published in July 2026 Early Security Updates. MSRC exploitability: Publicly Disclosed:No;Exploited:No;Latest Software Release:N/A.

Operator check

Review the Microsoft Security Update Guide entry for CVE-2026-57100. Confirm whether Microsoft Entra Provisioning Service (SyncFabric) is deployed, then apply the current security update or documented mitigation. CVSS score: 9.9.

Read brief →
Jul 2, 2026 Patch Tuesday High-risk advisory CVE-2026-57974

Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability

Microsoft · Microsoft Edge (Chromium-based)

Integer overflow or wraparound in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network. Published in July 2026 Early Security Updates. MSRC exploitability: Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation Unlikely.

Operator check

Review the Microsoft Security Update Guide entry for CVE-2026-57974. Confirm whether Microsoft Edge (Chromium-based) is deployed, then apply the current security update or documented mitigation. CVSS score: 8.8.

Read brief →
Jul 2, 2026 Patch Tuesday High-risk advisory CVE-2026-57981

Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability

Microsoft · Microsoft Edge (Chromium-based)

Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network. Published in July 2026 Early Security Updates. MSRC exploitability: Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation Unlikely.

Operator check

Review the Microsoft Security Update Guide entry for CVE-2026-57981. Confirm whether Microsoft Edge (Chromium-based) is deployed, then apply the current security update or documented mitigation. CVSS score: 8.8.

Read brief →
Jul 2, 2026 Patch Tuesday Critical vendor advisory CVE-2026-58289

Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability

Microsoft · Microsoft Edge (Chromium-based)

Access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network. Published in July 2026 Early Security Updates. MSRC exploitability: Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation Unlikely.

Operator check

Review the Microsoft Security Update Guide entry for CVE-2026-58289. Confirm whether Microsoft Edge (Chromium-based) is deployed, then apply the current security update or documented mitigation. CVSS score: 9.0.

Read brief →
Jul 2, 2026 Vendor advisory High-risk advisory CVE-2026-49352

9router's Hardcoded Default fallback JWT Secret Allows Authentication Bypass

npm · 9router

9router's Hardcoded Default fallback JWT Secret Allows Authentication Bypass

Operator check

Check whether 9router is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.

Read brief →
Jul 2, 2026 Vendor advisory High-risk advisory CVE-2026-49353

9router has an Incomplete Fix: Local-Only Access Gate Bypass in 9router via Host Header SpoofING

npm · 9router

9router has an Incomplete Fix: Local-Only Access Gate Bypass in 9router via Host Header SpoofING

Operator check

Check whether 9router is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.

Read brief →
Jul 2, 2026 Vendor advisory High-risk advisory CVE-2026-52746

jsonata: Malicious inputs to "$toMillis" function can cause resource exhaustion

npm · jsonata

jsonata: Malicious inputs to "$toMillis" function can cause resource exhaustion

Operator check

Check whether jsonata is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.

Read brief →
Jul 2, 2026 Vendor advisory High-risk advisory

@asymmetric-effort/nogginlessdom's Path Traversal in matchFileSnapshot allows arbitrary file write

npm · @asymmetric-effort/nogginlessdom

@asymmetric-effort/nogginlessdom's Path Traversal in matchFileSnapshot allows arbitrary file write

Operator check

Check whether @asymmetric-effort/nogginlessdom is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. CVSS score: 8.7.

Read brief →
Jul 2, 2026 Vendor advisory High-risk advisory CVE-2026-50194

Steeltoe vulnerable to management-port isolation bypass via spoofed Host header

NuGet · Steeltoe.Management.Endpoint

Steeltoe vulnerable to management-port isolation bypass via spoofed Host header

Operator check

Check whether Steeltoe.Management.Endpoint is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. EPSS probability: 0.2%; percentile: 15%.

Read brief →
Jul 2, 2026 Vendor advisory High-risk advisory CVE-2026-50196

Steeltoe.Discovery.Eureka: Unrecognized DataCenterInfo.Name poisons entire registry fetch

NuGet · Steeltoe.Discovery.Eureka

Steeltoe.Discovery.Eureka: Unrecognized DataCenterInfo.Name poisons entire registry fetch

Operator check

Check whether Steeltoe.Discovery.Eureka is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. EPSS probability: 0.3%; percentile: 26%.

Read brief →
Jul 2, 2026 Vendor advisory High-risk advisory CVE-2026-50200

Steeltoe's env sanitizer misses connection strings — leaks embedded DB passwords

NuGet · Steeltoe.Management.Endpoint

Steeltoe's env sanitizer misses connection strings — leaks embedded DB passwords

Operator check

Check whether Steeltoe.Management.Endpoint is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. EPSS probability: 0.2%; percentile: 8%.

Read brief →
Jul 2, 2026 Vendor advisory High-risk advisory CVE-2026-49360

Recce server has unauthenticated SQL execution that allows local file read/write through DuckDB

PyPI · recce

Recce server has unauthenticated SQL execution that allows local file read/write through DuckDB

Operator check

Check whether recce is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. CVSS score: 7.8.

Read brief →
Jul 2, 2026 Vendor advisory High-risk advisory CVE-2026-50027

mcp-memory-service: Missing Authentication on Document API Endpoints Allows Unauthenticated Memory Read/Write/Delete

PyPI · mcp-memory-service

mcp-memory-service: Missing Authentication on Document API Endpoints Allows Unauthenticated Memory Read/Write/Delete

Operator check

Check whether mcp-memory-service is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.

Read brief →
Jul 2, 2026 Vendor advisory High-risk advisory CVE-2026-52817

Linuxfabrik Monitoring Plugins: Sudoers may be able to obtain privilege escalation via /usr/bin/apt-get arguments

PyPI · linuxfabrik-lib

Linuxfabrik Monitoring Plugins: Sudoers may be able to obtain privilege escalation via /usr/bin/apt-get arguments

Operator check

Check whether linuxfabrik-lib is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. CVSS score: 7.0.

Read brief →
Jul 2, 2026 Vendor advisory High-risk advisory CVE-2026-52830

fast-mcp-telegram: Bearer token path traversal bypasses reserved Telegram session protection

PyPI · fast-mcp-telegram

fast-mcp-telegram: Bearer token path traversal bypasses reserved Telegram session protection

Operator check

Check whether fast-mcp-telegram is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.

Read brief →
Jul 2, 2026 Vendor advisory Critical vendor advisory CVE-2026-52735

zebrad has consensus divergence via P2SH sigop undercount in pure-Rust disabled-opcode parser

Rust · zebra-script

zebrad has consensus divergence via P2SH sigop undercount in pure-Rust disabled-opcode parser

Operator check

Check whether zebra-script is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. CVSS score: 9.3.

Read brief →
Jul 2, 2026 Vendor advisory High-risk advisory CVE-2026-52736

Zebra has block suppression via NU5 same-header body poisoning of sent-hash cache

Rust · zebra-state

Zebra has block suppression via NU5 same-header body poisoning of sent-hash cache

Operator check

Check whether zebra-state is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. CVSS score: 8.7.

Read brief →
Jul 2, 2026 Vendor advisory High-risk advisory CVE-2026-52829

Zebra Address Book Aborted by IPv4-Mapped Mempool Misbehavior Update

Rust · zebra-network

Zebra Address Book Aborted by IPv4-Mapped Mempool Misbehavior Update

Operator check

Check whether zebra-network is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.

Read brief →
Jul 2, 2026 Vendor advisory High-risk advisory CVE-2026-52834

jxl-grid on 32-bit platforms has an out-of-bounds writes due to integer overflow

Rust · jxl-grid

jxl-grid on 32-bit platforms has an out-of-bounds writes due to integer overflow

Operator check

Check whether jxl-grid is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.

Read brief →
Jul 1, 2026 Vendor advisory High-risk advisory CVE-2026-49981

Twig: Sandbox filter, tag and function allow-list bypass when sandbox state changes between renders for a cached `Tem...

Composer · twig/twig

Twig: Sandbox filter, tag and function allow-list bypass when sandbox state changes between renders for a cached `Template`

Operator check

Check whether twig/twig is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. CVSS score: 8.7.

Read brief →
Jul 1, 2026 Vendor advisory Critical vendor advisory CVE-2026-41052

Rancher has Privilege Escalation from Project Owner to Host

Go · github.com/rancher/rancher

Rancher has Privilege Escalation from Project Owner to Host

Operator check

Check whether github.com/rancher/rancher is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. CVSS score: 9.4. EPSS probability: 0.3%; percentile: 23%.

Read brief →
Jul 1, 2026 Vendor advisory High-risk advisory CVE-2026-41053

Rancher has over-inclusive team membership expansion in GitHub App authentication provider

Go · github.com/rancher/rancher

Rancher has over-inclusive team membership expansion in GitHub App authentication provider

Operator check

Check whether github.com/rancher/rancher is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. EPSS probability: 0.4%; percentile: 29%.

Read brief →
Jul 1, 2026 Vendor advisory High-risk advisory CVE-2026-44935

Rancher Fleet vulnerable to cross namespace secret disclosure via unvalidated `valuesFrom` references in Helm Deployer

Go · github.com/rancher/fleet

Rancher Fleet vulnerable to cross namespace secret disclosure via unvalidated `valuesFrom` references in Helm Deployer

Operator check

Check whether github.com/rancher/fleet is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.

Read brief →
Jul 1, 2026 Vendor advisory High-risk advisory CVE-2026-44937

Rancher Fleet has Unauthenticated Webhook: Regex Injection via Unsanitized Repository URL Components

Go · github.com/rancher/fleet

Rancher Fleet has Unauthenticated Webhook: Regex Injection via Unsanitized Repository URL Components

Operator check

Check whether github.com/rancher/fleet is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.

Read brief →
Jul 1, 2026 Vendor advisory High-risk advisory CVE-2026-44938

Fleet has PSS Bypass through addLabelsFromOptions in Fleet Agent

Go · github.com/rancher/fleet

Fleet has PSS Bypass through addLabelsFromOptions in Fleet Agent

Operator check

Check whether github.com/rancher/fleet is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.

Read brief →
Jul 1, 2026 Vendor advisory Critical vendor advisory CVE-2026-44939

Rancher vulnerable to command injection through unsanitized YAML parameter

Go · github.com/rancher/rancher

Rancher vulnerable to command injection through unsanitized YAML parameter

Operator check

Check whether github.com/rancher/rancher is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. CVSS score: 9.4. EPSS probability: 1.1%; percentile: 62%.

Read brief →
Jul 1, 2026 Vendor advisory High-risk advisory CVE-2026-49998

Centrifugo's dynamic JWKS key cache keyed only by `kid` allows cross-issuer JWT authentication bypass

Go · github.com/centrifugal/centrifugo/v6

Centrifugo's dynamic JWKS key cache keyed only by `kid` allows cross-issuer JWT authentication bypass

Operator check

Check whether github.com/centrifugal/centrifugo/v6 is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.

Read brief →
Jul 1, 2026 Vendor advisory High-risk advisory CVE-2026-50138

goshs: WebDAV listener ignores --read-only, --upload-only, and --no-delete mode flags

Go · goshs.de/goshs/v2

goshs: WebDAV listener ignores --read-only, --upload-only, and --no-delete mode flags

Operator check

Check whether goshs.de/goshs/v2 is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.

Read brief →
Jul 1, 2026 Vendor advisory High-risk advisory CVE-2026-50151

oras-go blob upload vulnerable to credential forwarding via unvalidated Location header

Go · oras.land/oras-go/v2

oras-go blob upload vulnerable to credential forwarding via unvalidated Location header

Operator check

Check whether oras.land/oras-go/v2 is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.

Read brief →
Jul 1, 2026 Vendor advisory High-risk advisory CVE-2026-50163

`oras-go` tar extraction: Hardlink entry with relative Linkname escapes extract dir via process CWD resolution

Go · oras.land/oras-go/v2

`oras-go` tar extraction: Hardlink entry with relative Linkname escapes extract dir via process CWD resolution

Operator check

Check whether oras.land/oras-go/v2 is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.

Read brief →
Jul 1, 2026 Vendor advisory Critical vendor advisory CVE-2026-50195

Linuxfoundation Containerd — CVE-2026-50195 (Critical)

Linuxfoundation · Containerd

containerd is an open-source container runtime. Versions prior to 2.3.2, 2.2.5 and 2.1.9 contain a vulnerability in the CRI checkpoint import process where it fails to validate the image references specified within a checkpoint image's configuration. An attacker with permissions to create pods can use a crafted checkpoint image to force containerd to pull a malicious image and assign it an arbitrary local tag, thereby poisoning the node's local image cache. Subsequently, if other pods on the same node attempt to use the poisoned tag with an IfNotPresent (or Never) pull policy, they will unknow

Operator check

Review CVE-2026-50195 in your asset inventory. Apply patches per vendor guidance and verify Containerd is not exposed. CVSS score: 9.9. EPSS probability: 0.4%; percentile: 27%.

Read brief →
Jul 1, 2026 Vendor advisory Critical vendor advisory CVE-2026-53492

Linuxfoundation Containerd — CVE-2026-53492 (Critical)

Linuxfoundation · Containerd

containerd is an open-source container runtime. In Versions prior to 2.3.2, 2.2.5 and 2.1.9, the CRI implementation improperly trusts Container Device Interface (CDI) annotations found within untrusted checkpoint image metadata during container restoration. When restoring a container from a checkpoint, containerd preserves CDI-related annotations from the checkpoint archive rather than relying solely on the pod's create-time specification. This allows a user with pod creation permissions to bypass standard Kubernetes resource allocation and device plugin enforcement, injecting arbitrary CDI ed

Operator check

Review CVE-2026-53492 in your asset inventory. Apply patches per vendor guidance and verify Containerd is not exposed. CVSS score: 9.6. EPSS probability: 0.4%; percentile: 33%.

Read brief →
Jul 1, 2026 Vendor advisory High-risk advisory CVE-2026-53712

OnGres SCRAM silent channel-binding authentication downgrade via unsupported certificate algorithms

Maven · com.ongres.scram:scram-client

OnGres SCRAM silent channel-binding authentication downgrade via unsupported certificate algorithms

Operator check

Check whether com.ongres.scram:scram-client is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. CVSS score: 8.2.

Read brief →
Jul 1, 2026 Vendor advisory High-risk advisory CVE-2026-9795

Keycloak has privilege escalation via improper scope mapping enforcement

Maven · org.keycloak:keycloak-services

Keycloak has privilege escalation via improper scope mapping enforcement

Operator check

Check whether org.keycloak:keycloak-services is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. EPSS probability: 0.3%; percentile: 21%.

Read brief →
Jul 1, 2026 KEV Known exploited CVE-2026-45659

Microsoft SharePoint Server Deserialization of Untrusted Data Vulnerability

Microsoft · SharePoint Server

Microsoft SharePoint Server contains a deserialization of untrusted data vulnerability which allows an authorized attacker to execute code over a network.

Operator check

Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

Read brief →
Jul 1, 2026 Vendor advisory High-risk advisory CVE-2026-48815

sigstore's `certificateOIDs` verification constraints are silently dropped and never enforced

npm · sigstore

sigstore's `certificateOIDs` verification constraints are silently dropped and never enforced

Operator check

Check whether sigstore is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.

Read brief →
Jul 1, 2026 Vendor advisory High-risk advisory CVE-2026-49857

auth-fetch-mcp has SSRF Protection Bypass via IPv4-mapped IPv6 Loopback

npm · auth-fetch-mcp

auth-fetch-mcp has SSRF Protection Bypass via IPv4-mapped IPv6 Loopback

Operator check

Check whether auth-fetch-mcp is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.

Read brief →
Jul 1, 2026 Vendor advisory High-risk advisory CVE-2026-49987

repomix Vulnerable to Command Injection (RCE) via `--remote-branch` Argument Injection

npm · repomix

repomix Vulnerable to Command Injection (RCE) via `--remote-branch` Argument Injection

Operator check

Check whether repomix is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.

Read brief →
Jul 1, 2026 Vendor advisory High-risk advisory CVE-2026-50143

Apify Model Context Protocol (MCP) server: Actor MCP path authority injection leaks Apify token

npm · @apify/actors-mcp-server

Apify Model Context Protocol (MCP) server: Actor MCP path authority injection leaks Apify token

Operator check

Check whether @apify/actors-mcp-server is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.

Read brief →
Jul 1, 2026 Vendor advisory High-risk advisory CVE-2026-53943

Ghost: Cache-poisoning XSS in Ghost frontend via x-ghost-preview header

npm · ghost

Ghost: Cache-poisoning XSS in Ghost frontend via x-ghost-preview header

Operator check

Check whether ghost is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. EPSS probability: 0.2%; percentile: 16%.

Read brief →
Jul 1, 2026 Vendor advisory High-risk advisory CVE-2026-49986

Cortex has Untrusted Project Bootstrap Code Execution via `CLAUDE_PROJECT_DIR`

PyPI · neuro-cortex-memory

Cortex has Untrusted Project Bootstrap Code Execution via `CLAUDE_PROJECT_DIR`

Operator check

Check whether neuro-cortex-memory is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. CVSS score: 7.1.

Read brief →
Jul 1, 2026 Vendor advisory High-risk advisory

pay-rails/pay: non-constant-time HMAC comparison in Paddle Billing webhook signature verifier

RubyGems · pay

pay-rails/pay: non-constant-time HMAC comparison in Paddle Billing webhook signature verifier

Operator check

Check whether pay is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.

Read brief →
Jul 1, 2026 Vendor advisory High-risk advisory

SurrealDB: HTTP /rpc `sessions` method leaks attached session UUIDs, enabling full session hijack by anonymous callers

Rust · surrealdb

SurrealDB: HTTP /rpc `sessions` method leaks attached session UUIDs, enabling full session hijack by anonymous callers

Operator check

Check whether surrealdb is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.

Read brief →
Jul 1, 2026 Vendor advisory Critical vendor advisory CVE-2026-58457

Shenzhen Aitemi M300 Wi-Fi Repeater (hardware model MT02) — CVE-2026-58457 (Critical)

Shenzhen · Aitemi M300 Wi-Fi Repeater (hardware model MT02)

Shenzhen Aitemi M300 Wi-Fi Repeater (hardware model MT02) contains an unauthenticated OS command injection vulnerability that allows network-adjacent attackers to execute arbitrary shell commands by injecting unsanitized input through the smacfilter_conf handler in the commuos web backend. Attackers can append semicolon-delimited payloads to the name, enable, or mac GET parameters, which are passed without sanitization into sprintf() to build uci shell commands executed via doSystemCmdComlib(), granting full root-level control of the device.

Operator check

Review CVE-2026-58457 in your asset inventory. Apply patches per vendor guidance and verify Aitemi M300 Wi-Fi Repeater (hardware model MT02) is not exposed. CVSS score: 9.8.

Read brief →
Jun 30, 2026 Vendor advisory Critical vendor advisory CVE-2026-48286

Adobe Campaign Classic (ACC) — CVE-2026-48286 (Critical)

Adobe · Campaign Classic (ACC)

Adobe Campaign Classic (ACC) versions 7.4.3 build 9396 and earlier are affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue does not require user interaction. Scope is changed.

Operator check

Review CVE-2026-48286 in your asset inventory. Apply patches per vendor guidance and verify Campaign Classic (ACC) is not exposed. CVSS score: 10.0.

Read brief →
Jun 30, 2026 Vendor advisory Critical vendor advisory CVE-2026-8452

Citrix Netscaler Application Delivery Controller — CVE-2026-8452 (Critical)

Citrix · Netscaler Application Delivery Controller

Memory overflow vulnerability NetScaler ADC and NetScaler Gateway leading to unpredictable or erroneous behavior and Denial of Service if the appliance is configured as a Gateway (SSL VPN, ICA Proxy, CVPN, RDP Proxy) or AAA virtual server

Operator check

Review CVE-2026-8452 in your asset inventory. Apply patches per vendor guidance and verify Netscaler Application Delivery Controller is not exposed. CVSS score: 9.8. EPSS probability: 0.4%; percentile: 32%.

Read brief →
Jun 30, 2026 Vendor advisory Critical vendor advisory CVE-2026-8655

Citrix Netscaler Application Delivery Controller — CVE-2026-8655 (Critical)

Citrix · Netscaler Application Delivery Controller

Multiple Memory overflow vulnerabilities in NetScaler ADC and NetScaler Gateway leading to unpredictable or erroneous behavior and Denial of Service if NetScaler ADC is configured as an LB of type Oracle OR NetScaler ADC is configured as a DNS Proxy OR NetScaler ADC is configured as a DNS recursive resolver deployment

Operator check

Review CVE-2026-8655 in your asset inventory. Apply patches per vendor guidance and verify Netscaler Application Delivery Controller is not exposed. CVSS score: 9.8. EPSS probability: 0.4%; percentile: 30%.

Read brief →
Jun 30, 2026 Vendor advisory High-risk advisory CVE-2026-47198

Paymenter has URL parameter injection that bypasses paid plan limits at checkout

Composer · paymenter/paymenter

Paymenter has URL parameter injection that bypasses paid plan limits at checkout

Operator check

Check whether paymenter/paymenter is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.

Read brief →
Jun 30, 2026 Vendor advisory Critical vendor advisory CVE-2026-58016

Gnome Glib — CVE-2026-58016 (Critical)

Gnome · Glib

A flaw was found in GLib. A state confusion issue exists in g_dbus_node_info_new_for_xml() in the gio/gdbusintrospection.c file when processing malformed D-Bus introspection XML, specifically with a <node> element nested within other elements like <method>, <signal>, <property> or <arg>. This issue can cause an unsigned integer overflow and lead to an out-of-bounds read, resulting in a denial of service.

Operator check

Review CVE-2026-58016 in your asset inventory. Apply patches per vendor guidance and verify Glib is not exposed. CVSS score: 7.5. EPSS probability: 0.3%; percentile: 26%.

Read brief →
Jun 30, 2026 Vendor advisory High-risk advisory CVE-2026-49478

Fulcio has OIDC Discovery Redirect Following Allows SSRF and JWKS Substitution for Meta-Issuer Paths, with Kubernetes...

Go · github.com/sigstore/fulcio

Fulcio has OIDC Discovery Redirect Following Allows SSRF and JWKS Substitution for Meta-Issuer Paths, with Kubernetes Service-Account Token Leakage

Operator check

Check whether github.com/sigstore/fulcio is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.

Read brief →
Jun 30, 2026 Vendor advisory High-risk advisory CVE-2026-49821

Fission: Cross-namespace Environment reference in Package allows build-time command execution and SA token exfiltration

Go · github.com/fission/fission

Fission: Cross-namespace Environment reference in Package allows build-time command execution and SA token exfiltration

Operator check

Check whether github.com/fission/fission is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. EPSS probability: 0.2%; percentile: 14%.

Read brief →
Jun 30, 2026 Vendor advisory High-risk advisory CVE-2026-49822

Fission: Cross-namespace event leakage via KubernetesWatchTrigger allows persistent tenant surveillance

Go · github.com/fission/fission

Fission: Cross-namespace event leakage via KubernetesWatchTrigger allows persistent tenant surveillance

Operator check

Check whether github.com/fission/fission is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. EPSS probability: 0.2%; percentile: 14%.

Read brief →
Jun 30, 2026 Vendor advisory High-risk advisory CVE-2026-49823

Fission: Cross-namespace Package read via unvalidated PackageRef in Function admission webhook

Go · github.com/fission/fission

Fission: Cross-namespace Package read via unvalidated PackageRef in Function admission webhook

Operator check

Check whether github.com/fission/fission is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. EPSS probability: 0.3%; percentile: 18%.

Read brief →
Jun 30, 2026 Vendor advisory High-risk advisory CVE-2026-49824

Fission: Cross-namespace Environment reference via unvalidated EnvironmentRef in Function admission webhook

Go · github.com/fission/fission

Fission: Cross-namespace Environment reference via unvalidated EnvironmentRef in Function admission webhook

Operator check

Check whether github.com/fission/fission is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. EPSS probability: 0.2%; percentile: 13%.

Read brief →
Jun 30, 2026 Vendor advisory High-risk advisory CVE-2026-50545

Fission Environment CRD PodSpec Injection Leading to Node Escape and Cluster Takeover

Go · github.com/fission/fission

Fission Environment CRD PodSpec Injection Leading to Node Escape and Cluster Takeover

Operator check

Check whether github.com/fission/fission is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. EPSS probability: 0.3%; percentile: 22%.

Read brief →
Jun 30, 2026 Vendor advisory High-risk advisory CVE-2026-50563

Fission Container Executor Function PodSpec Injection Leading to Node Escape

Go · github.com/fission/fission

Fission Container Executor Function PodSpec Injection Leading to Node Escape

Operator check

Check whether github.com/fission/fission is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. EPSS probability: 0.3%; percentile: 19%.

Read brief →
Jun 30, 2026 Vendor advisory High-risk advisory CVE-2026-50564

Fission Environment CRD podspec passthrough enables hostPID/hostNetwork/privileged pods, node escape

Go · github.com/fission/fission

Fission Environment CRD podspec passthrough enables hostPID/hostNetwork/privileged pods, node escape

Operator check

Check whether github.com/fission/fission is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. EPSS probability: 0.3%; percentile: 19%.

Read brief →
Jun 30, 2026 Vendor advisory High-risk advisory CVE-2026-50566

Fission: Environment Runtime.Container and Builder.Container SecurityContext bypass allows privileged pod creation

Go · github.com/fission/fission

Fission: Environment Runtime.Container and Builder.Container SecurityContext bypass allows privileged pod creation

Operator check

Check whether github.com/fission/fission is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. EPSS probability: 0.3%; percentile: 21%.

Read brief →
Jun 30, 2026 Vendor advisory High-risk advisory

Fission: MessageQueueTrigger scaler manager materializes Secret values into Deployment envvars and accepts arbitrary ...

Go · github.com/fission/fission

Fission: MessageQueueTrigger scaler manager materializes Secret values into Deployment envvars and accepts arbitrary user PodSpec

Operator check

Check whether github.com/fission/fission is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.

Read brief →
Jun 30, 2026 Vendor advisory Critical vendor advisory CVE-2026-13775

Google Chrome — CVE-2026-13775 (Critical)

Google · Chrome

Use after free in GPU in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)

Operator check

Review CVE-2026-13775 in your asset inventory. Apply patches per vendor guidance and verify Chrome is not exposed. CVSS score: 9.8. EPSS probability: 0.2%; percentile: 13%.

Read brief →
Jun 30, 2026 Vendor advisory Critical vendor advisory CVE-2026-13776

Google Chrome — CVE-2026-13776 (Critical)

Google · Chrome

Type Confusion in Dawn in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)

Operator check

Review CVE-2026-13776 in your asset inventory. Apply patches per vendor guidance and verify Chrome is not exposed. CVSS score: 9.8. EPSS probability: 0.2%; percentile: 15%.

Read brief →
Jun 30, 2026 Vendor advisory Critical vendor advisory CVE-2026-13780

Google Chrome — CVE-2026-13780 (Critical)

Google · Chrome

Insufficient validation of untrusted input in ANGLE in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)

Operator check

Review CVE-2026-13780 in your asset inventory. Apply patches per vendor guidance and verify Chrome is not exposed. CVSS score: 9.6. EPSS probability: 0.2%; percentile: 13%.

Read brief →
Jun 30, 2026 Vendor advisory Critical vendor advisory CVE-2026-13781

Google Chrome — CVE-2026-13781 (Critical)

Google · Chrome

Insufficient validation of untrusted input in Skia in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)

Operator check

Review CVE-2026-13781 in your asset inventory. Apply patches per vendor guidance and verify Chrome is not exposed. CVSS score: 9.6. EPSS probability: 0.2%; percentile: 13%.

Read brief →
Jun 30, 2026 Vendor advisory Critical vendor advisory CVE-2026-13782

Google Chrome — CVE-2026-13782 (Critical)

Google · Chrome

Use after free in Browser in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)

Operator check

Review CVE-2026-13782 in your asset inventory. Apply patches per vendor guidance and verify Chrome is not exposed. CVSS score: 10.0. EPSS probability: 0.2%; percentile: 11%.

Read brief →
Jun 30, 2026 Vendor advisory Critical vendor advisory CVE-2026-13785

Google Chrome — CVE-2026-13785 (Critical)

Google · Chrome

Use after free in Bluetooth in Google Chrome on Mac prior to 150.0.7871.47 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)

Operator check

Review CVE-2026-13785 in your asset inventory. Apply patches per vendor guidance and verify Chrome is not exposed. CVSS score: 9.6. EPSS probability: 0.2%; percentile: 13%.

Read brief →
Jun 30, 2026 Vendor advisory Critical vendor advisory CVE-2026-14101

Google Chrome — CVE-2026-14101 (Critical)

Google · Chrome

Insufficient policy enforcement in Sandbox in Google Chrome on Mac prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Low)

Operator check

Review CVE-2026-14101 in your asset inventory. Apply patches per vendor guidance and verify Chrome is not exposed. CVSS score: 9.6. EPSS probability: 0.2%; percentile: 13%.

Read brief →
Jun 30, 2026 Vendor advisory Critical vendor advisory CVE-2026-14104

Google Chrome — CVE-2026-14104 (Critical)

Google · Chrome

Insufficient validation of untrusted input in WebAppInstalls in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Low)

Operator check

Review CVE-2026-14104 in your asset inventory. Apply patches per vendor guidance and verify Chrome is not exposed. CVSS score: 9.8. EPSS probability: 0.3%; percentile: 26%.

Read brief →
Jun 30, 2026 Vendor advisory Critical vendor advisory CVE-2026-56700

Grav CMS — CVE-2026-56700 (Critical)

Grav · CMS

Grav CMS before 2.0.0-beta.2 contains multiple code-execution vulnerabilities. Three unsafe unserialize() calls - in Scheduler\JobQueue, Framework\Cache\Adapter\FileCache, and Session - deserialize untrusted data without restricting allowed classes, enabling PHP object injection and, via a gadget chain, arbitrary code execution where an attacker controls the serialized input. Additionally, InstallCommand's git clone operation passes the branch, url, and path parameters into a shell command without escaping, allowing OS command injection via plugin/theme installation (which requires admin acces

Operator check

Review CVE-2026-56700 in your asset inventory. Apply patches per vendor guidance and verify CMS is not exposed. CVSS score: 9.8.

Read brief →
Jun 30, 2026 Vendor advisory Critical vendor advisory CVE-2026-10140

IBM Langflow OSS 1.0.0 — CVE-2026-10140 (Critical)

IBM · Langflow OSS 1.0.0

IBM Langflow OSS 1.0.0 through 1.10.0 voice mode contains improper shared-state handling that allows reuse of API clients across tenant boundaries. An authenticated attacker can manipulate cache state to cause requests from other users to be processed using incorrect upstream API credentials, leading to cross-tenant billing and accountability misattribution.

Operator check

Review CVE-2026-10140 in your asset inventory. Apply patches per vendor guidance and verify Langflow OSS 1.0.0 is not exposed. CVSS score: 9.6.

Read brief →
Jun 30, 2026 Vendor advisory Critical vendor advisory CVE-2026-11541

Ibm Websphere Application Server — CVE-2026-11541 (Critical)

Ibm · Websphere Application Server

IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.6 are affected by an HTTP request smuggling vulnerability.

Operator check

Review CVE-2026-11541 in your asset inventory. Apply patches per vendor guidance and verify Websphere Application Server is not exposed. CVSS score: 7.4. EPSS probability: 0.3%; percentile: 26%.

Read brief →
Jun 30, 2026 Vendor advisory Critical vendor advisory CVE-2026-11546

Ibm Websphere Application Server — CVE-2026-11546 (Critical)

Ibm · Websphere Application Server

IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.7 is affected by a server-side request forgery vulnerability with the adminCenter-1.0 feature enabled.

Operator check

Review CVE-2026-11546 in your asset inventory. Apply patches per vendor guidance and verify Websphere Application Server is not exposed. CVSS score: 7.1. EPSS probability: 0.2%; percentile: 12%.

Read brief →
Jun 30, 2026 Vendor advisory Critical vendor advisory CVE-2026-11714

Ibm Websphere Application Server — CVE-2026-11714 (Critical)

Ibm · Websphere Application Server

IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.7 is affected by a server-side request forgery vulnerability with the apiDiscovery-1.0 feature enabled.

Operator check

Review CVE-2026-11714 in your asset inventory. Apply patches per vendor guidance and verify Websphere Application Server is not exposed. CVSS score: 8.5. EPSS probability: 0.2%; percentile: 8%.

Read brief →
Jun 30, 2026 Vendor advisory Critical vendor advisory CVE-2026-13449

Ibm Business Automation Manager — CVE-2026-13449 (Critical)

Ibm · Business Automation Manager

IBM Business Automation Manager Open Editions 9.0.0 through 9.4.2 is vulnerable to an XML external entity injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources.

Operator check

Review CVE-2026-13449 in your asset inventory. Apply patches per vendor guidance and verify Business Automation Manager is not exposed. CVSS score: 7.6. EPSS probability: 0.4%; percentile: 31%.

Read brief →
Jun 30, 2026 Vendor advisory Critical vendor advisory CVE-2026-13772

Ibm Websphere Extreme Scale — CVE-2026-13772 (Critical)

Ibm · Websphere Extreme Scale

IBM WebSphere Extreme Scale 8.6.1.0 through 8.6.1.6 's Object Query Language engine resolves attacker-supplied class names via Class.forName() and invokes their constructors with no allow-list at three distinct sinks (SELECT NEW, enum literals, and reflection-based comparators); an authenticated remote attacker who can influence an application-built OQL query string can execute arbitrary constructors on the WAS JVM, and a SELECT DISTINCT variant using planted grid values fires the same gadget post-readObject in a manner that survives JEP-290 serialization filters across grid node boundaries

Operator check

Review CVE-2026-13772 in your asset inventory. Apply patches per vendor guidance and verify Websphere Extreme Scale is not exposed. CVSS score: 7.5. EPSS probability: 0.3%; percentile: 18%.

Read brief →
Jun 30, 2026 Vendor advisory Critical vendor advisory CVE-2026-13773

Ibm Websphere Extreme Scale — CVE-2026-13773 (Critical)

Ibm · Websphere Extreme Scale

IBM WebSphere Extreme Scale 8.6.1.0 through 8.6.1.6 Approximately 50 generated CORBA stub classes in WebSphere eXtreme Scale's ogclient.jar call ORB.string_to_object() on an attacker-controlled IOR string during Java deserialization, turning any unfiltered ObjectInputStream sink in WAS into outbound IIOP SSRF to an attacker-chosen host; when chained with the IBM ORB's getUserException class-instantiation flaw (WAS-26), this SSRF escalates to remote code execution on the calling JVM.

Operator check

Review CVE-2026-13773 in your asset inventory. Apply patches per vendor guidance and verify Websphere Extreme Scale is not exposed. CVSS score: 6.0. EPSS probability: 3.0%; percentile: 86%.

Read brief →
Jun 30, 2026 Vendor advisory Critical vendor advisory CVE-2026-10560

Langflow Langflow — CVE-2026-10560 (Critical)

Langflow · Langflow

IBM Langflow OSS 1.0.0 through 1.9.6 contains a missing authentication vulnerability in /api/v1/build_public_tmp/ endpoints that allows an unauthenticated attacker to read build event data or cancel jobs using a valid job identifier, resulting in information disclosure and denial of service.

Operator check

Review CVE-2026-10560 in your asset inventory. Apply patches per vendor guidance and verify Langflow is not exposed. CVSS score: 8.2. EPSS probability: 0.3%; percentile: 16%.

Read brief →
Jun 30, 2026 Vendor advisory Critical vendor advisory CVE-2026-7663

Langflow Langflow — CVE-2026-7663 (Critical)

Langflow · Langflow

IBM Langflow OSS 1.0.0 through 1.9.6 could allow unauthenticated attackers to access protected MCP project resources and execute MCP operations due to improper authorization enforcement in the Streamable MCP transport endpoint.

Operator check

Review CVE-2026-7663 in your asset inventory. Apply patches per vendor guidance and verify Langflow is not exposed. CVSS score: 9.1. EPSS probability: 0.2%; percentile: 15%.

Read brief →
Jun 30, 2026 Vendor advisory Critical vendor advisory CVE-2026-14241

Mozilla Firefox — CVE-2026-14241 (Critical)

Mozilla · Firefox

Memory safety bugs present in Firefox 152.0.3. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 152.0.4.

Operator check

Review CVE-2026-14241 in your asset inventory. Apply patches per vendor guidance and verify Firefox is not exposed. CVSS score: 9.8. EPSS probability: 0.1%; percentile: 4%.

Read brief →
Jun 30, 2026 Vendor advisory High-risk advisory CVE-2026-48795

@adonisjs/bodyparser has an incomplete fix for CVE-2026-25754

npm · @adonisjs/bodyparser

@adonisjs/bodyparser has an incomplete fix for CVE-2026-25754

Operator check

Check whether @adonisjs/bodyparser is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.

Read brief →
Jun 30, 2026 Vendor advisory High-risk advisory CVE-2026-49473

@cedar-policy/authorization-for-expressjs has an authorization bypass via query string manipulation

npm · @cedar-policy/authorization-for-expressjs

@cedar-policy/authorization-for-expressjs has an authorization bypass via query string manipulation

Operator check

Check whether @cedar-policy/authorization-for-expressjs is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.

Read brief →
Jun 30, 2026 Vendor advisory High-risk advisory CVE-2026-49451

Microsoft.OpenAPI: Circular schema references may terminate OpenAPI parsing

NuGet · Microsoft.OpenAPI

Microsoft.OpenAPI: Circular schema references may terminate OpenAPI parsing

Operator check

Check whether Microsoft.OpenAPI is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.

Read brief →
Jun 30, 2026 Vendor advisory Critical vendor advisory CVE-2026-58138

Orkes Conductor 3.21.21 — CVE-2026-58138 (Critical)

Orkes · Conductor 3.21.21

Orkes Conductor 3.21.21 before 3.30.2 contains an unauthenticated remote code execution vulnerability that allows remote attackers to execute arbitrary OS commands by submitting inline workflow definitions containing malicious JavaScript or Python expressions to the workflow API endpoint prior to authentication. Attackers can exploit unsandboxed GraalVM evaluators configured with HostAccess.ALL or allowAllAccess(true) through INLINE, LAMBDA, DO_WHILE, and SWITCH task types to invoke arbitrary system commands via Java reflection or direct subprocess calls.

Operator check

Review CVE-2026-58138 in your asset inventory. Apply patches per vendor guidance and verify Conductor 3.21.21 is not exposed. CVSS score: 9.8.

Read brief →
Jun 30, 2026 Vendor advisory High-risk advisory CVE-2025-10996

Open Babel has heap buffer overflow in SMILES OBSmilesParser::ParseSmiles

PyPI · openbabel

Open Babel has heap buffer overflow in SMILES OBSmilesParser::ParseSmiles

Operator check

Check whether openbabel is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. EPSS probability: 0.2%; percentile: 13%.

Read brief →
Jun 29, 2026 Vendor advisory High-risk advisory CVE-2026-44840

Dgraph Vulnerable to DQL Injection via checkUserPassword GraphQL Query

Go · github.com/dgraph-io/dgraph/v25

Dgraph Vulnerable to DQL Injection via checkUserPassword GraphQL Query

Operator check

Check whether github.com/dgraph-io/dgraph/v25 is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.

Read brief →
Jun 29, 2026 Vendor advisory Critical vendor advisory CVE-2026-11720

Google Mcp Toolbox For Databases — CVE-2026-11720 (Critical)

Google · Mcp Toolbox For Databases

A path traversal vulnerability exists in the HTTP tool URL builder of googleapis/mcp-toolbox. When constructing downstream API requests, the URL builder substitutes user-controlled pathParams into the configured tool path and parses the resulting string as a relative URL. While it checks that the input does not alter the scheme, host, or user info, it relies on ResolveReference for the final URL resolution. Because dot segments (../) are normalized during this resolution step, an attacker can supply path parameters containing directory traversal sequences to escape the operator-configured pat

Operator check

Review CVE-2026-11720 in your asset inventory. Apply patches per vendor guidance and verify Mcp Toolbox For Databases is not exposed. CVSS score: 9.1. EPSS probability: 0.4%; percentile: 29%.

Read brief →
Jun 29, 2026 Vendor advisory High-risk advisory CVE-2026-47424

OpenAM Authenticated RCE via Groovy Sandbox Escape

Maven · org.openidentityplatform.openam:openam-scripting

OpenAM Authenticated RCE via Groovy Sandbox Escape

Operator check

Check whether org.openidentityplatform.openam:openam-scripting is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. CVSS score: 7.5.

Read brief →
Jun 29, 2026 Vendor advisory High-risk advisory CVE-2026-47426

OpenAM OAuth Client Impersonation via JWKS Resolver Cache

Maven · org.openidentityplatform.openam:openam-oauth2

OpenAM OAuth Client Impersonation via JWKS Resolver Cache

Operator check

Check whether org.openidentityplatform.openam:openam-oauth2 is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. CVSS score: 7.1.

Read brief →
Jun 29, 2026 KEV Known exploited CVE-2026-48558

SimpleHelp Authentication Bypass Vulnerability

SimpleHelp · SimpleHelp

SimpleHelp contains an authentication bypass vulnerability in the OIDC authentication flow. When OIDC authentication is configured, identity tokens submitted during login are accepted without verifying their cryptographic signature. In a vulnerable configuration, a remote, unauthenticated attacker can submit a forged token containing arbitrary identity claims to obtain a fully authenticated technician session. In some configurations, this may also allow bypass of multi-factor authentication.

Operator check

Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

Read brief →
Jun 29, 2026 Vendor advisory Critical vendor advisory CVE-2026-13751

Snowflake Snowflake Cli — CVE-2026-13751 (Critical)

Snowflake · Snowflake Cli

Improper handling of untrusted remote references in Snowflake CLI versions prior to 3.19 allowed server-side request forgery. The SQL statement reader's !source/!load directives could reference remote URLs that were retrieved at runtime without sufficient restriction on the request destination. By supplying crafted SQL content processed through a vulnerable command path, an attacker could cause the victim's environment to issue unintended outbound requests to internal or otherwise non-public network locations, and could cause remote SQL content to be retrieved and executed in the context of th

Operator check

Review CVE-2026-13751 in your asset inventory. Apply patches per vendor guidance and verify Snowflake Cli is not exposed. CVSS score: 4.1. EPSS probability: 0.1%; percentile: 1%.

Read brief →
Jun 27, 2026 Vendor advisory High-risk advisory

pnpm: Path traversal in configDependencies env lockfile allows symlink creation outside node_modules/.pnpm-config

npm · pnpm

pnpm: Path traversal in configDependencies env lockfile allows symlink creation outside node_modules/.pnpm-config

Operator check

Check whether pnpm is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.

Read brief →
Jun 26, 2026 Vendor advisory Critical vendor advisory CVE-2026-54636

Dokku Dokku — CVE-2026-54636 (Critical)

Dokku · Dokku

Dokku is a docker-powered PaaS. Prior to 0.38.7, the cron plugin utilizes commands in the app.json file to manage system cron running as the Dokku user. An app.json cron command utilizing special shell characters - including, but not limited to, > or ; - can break out of the Docker container and execute commands on the host as the Dokku user. This vulnerability is fixed in 0.38.7.

Operator check

Review CVE-2026-54636 in your asset inventory. Apply patches per vendor guidance and verify Dokku is not exposed. CVSS score: 9.0.

Read brief →
Jun 26, 2026 Vendor advisory High-risk advisory CVE-2026-49454

Relyra SAML SignatureValue not cryptographically verified -> authentication bypass

erlang · relyra

Relyra SAML SignatureValue not cryptographically verified -> authentication bypass

Operator check

Check whether relyra is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. EPSS probability: 0.1%; percentile: 3%.

Read brief →
Jun 26, 2026 Vendor advisory High-risk advisory

ex_aws_sns: Trusted-attacker `SigningCertURL` permits complete SNS signature bypass

erlang · ex_aws_sns

ex_aws_sns: Trusted-attacker `SigningCertURL` permits complete SNS signature bypass

Operator check

Check whether ex_aws_sns is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. CVSS score: 8.7.

Read brief →
Jun 26, 2026 Vendor advisory High-risk advisory CVE-2026-48749

Incus has an arbitrary file read+write on host via rootfs/ symlink in malicious image

Go · github.com/lxc/incus/v7/cmd/incusd

Incus has an arbitrary file read+write on host via rootfs/ symlink in malicious image

Operator check

Check whether github.com/lxc/incus/v7/cmd/incusd is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.

Read brief →
Jun 26, 2026 Vendor advisory High-risk advisory CVE-2026-48750

Incus has an arbitrary file write on host via `exec-output` symlink in crafted image

Go · github.com/lxc/incus/v7/cmd/incusd

Incus has an arbitrary file write on host via `exec-output` symlink in crafted image

Operator check

Check whether github.com/lxc/incus/v7/cmd/incusd is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.

Read brief →
Jun 26, 2026 Vendor advisory High-risk advisory CVE-2026-48751

Incus has a restricted project bypass leading to arbitrary command execution

Go · github.com/lxc/incus/v7/cmd/incusd

Incus has a restricted project bypass leading to arbitrary command execution

Operator check

Check whether github.com/lxc/incus/v7/cmd/incusd is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.

Read brief →
Jun 26, 2026 Vendor advisory High-risk advisory CVE-2026-48752

Incus has arbitrary file read+write on host via templates/ symlink in malicious image

Go · github.com/lxc/incus/v7/cmd/incusd

Incus has arbitrary file read+write on host via templates/ symlink in malicious image

Operator check

Check whether github.com/lxc/incus/v7/cmd/incusd is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.

Read brief →
Jun 26, 2026 Vendor advisory High-risk advisory CVE-2026-48753

Incus has an arbitrary file write via path traversal in S3 multipart upload

Go · github.com/lxc/incus/v7/cmd/incusd

Incus has an arbitrary file write via path traversal in S3 multipart upload

Operator check

Check whether github.com/lxc/incus/v7/cmd/incusd is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.

Read brief →
Jun 26, 2026 Vendor advisory High-risk advisory CVE-2026-48755

Incus has an argument injection in backup compression algorithm leading to AFW and ACE

Go · github.com/lxc/incus/v7/cmd/incusd

Incus has an argument injection in backup compression algorithm leading to AFW and ACE

Operator check

Check whether github.com/lxc/incus/v7/cmd/incusd is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.

Read brief →
Jun 26, 2026 Vendor advisory High-risk advisory CVE-2026-48769

Incus has an arbitrary file write on its client due to trusted image hash

Go · github.com/lxc/incus/v7/cmd/incusd

Incus has an arbitrary file write on its client due to trusted image hash

Operator check

Check whether github.com/lxc/incus/v7/cmd/incusd is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.

Read brief →
Jun 26, 2026 Vendor advisory High-risk advisory CVE-2026-49338

Subsonic API: any authenticated user can delete or read any other user's playlist (IDOR)

Go · go.senan.xyz/gonic

Subsonic API: any authenticated user can delete or read any other user's playlist (IDOR)

Operator check

Check whether go.senan.xyz/gonic is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. EPSS probability: 0.2%; percentile: 6%.

Read brief →
Jun 26, 2026 Vendor advisory High-risk advisory CVE-2026-49339

gonic: Path Traversal in playlist `id` bypasses ownership check, enabling any user to read/delete other users' playlists

Go · go.senan.xyz/gonic

gonic: Path Traversal in playlist `id` bypasses ownership check, enabling any user to read/delete other users' playlists

Operator check

Check whether go.senan.xyz/gonic is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. EPSS probability: 0.3%; percentile: 17%.

Read brief →
Jun 26, 2026 Vendor advisory High-risk advisory CVE-2026-49340

gonic has arbitrary file write in createPlaylist: any authenticated user can write playlist M3U content to attacker-c...

Go · go.senan.xyz/gonic

gonic has arbitrary file write in createPlaylist: any authenticated user can write playlist M3U content to attacker-controlled path on the host

Operator check

Check whether go.senan.xyz/gonic is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. EPSS probability: 0.3%; percentile: 18%.

Read brief →
Jun 26, 2026 Vendor advisory High-risk advisory CVE-2026-53519

Nezha Monitoring: Pre-auth path traversal via /dashboard.. prefix confusion leaks jwt_secret_key

Go · github.com/nezhahq/nezha

Nezha Monitoring: Pre-auth path traversal via /dashboard.. prefix confusion leaks jwt_secret_key

Operator check

Check whether github.com/nezhahq/nezha is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. EPSS probability: 0.5%; percentile: 36%.

Read brief →
Jun 26, 2026 Vendor advisory High-risk advisory

Nezha vulnerable to cross-tenant terminal/file-manager session hijack via WebSocket stream UUID without ownership check

Go · github.com/nezhahq/nezha

Nezha vulnerable to cross-tenant terminal/file-manager session hijack via WebSocket stream UUID without ownership check

Operator check

Check whether github.com/nezhahq/nezha is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.

Read brief →
Jun 26, 2026 Vendor advisory High-risk advisory

Blnk has an API key authorization bypass in owner and scope enforcement

Go · github.com/blnkfinance/blnk

Blnk has an API key authorization bypass in owner and scope enforcement

Operator check

Check whether github.com/blnkfinance/blnk is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.

Read brief →
Jun 26, 2026 Vendor advisory Critical vendor advisory CVE-2026-53914

Jetbrains Kotlin — CVE-2026-53914 (Critical)

Jetbrains · Kotlin

In JetBrains Kotlin before 2.4.20 code execution was possible via unsafe deserialization in the build cache metadata

Operator check

Review CVE-2026-53914 in your asset inventory. Apply patches per vendor guidance and verify Kotlin is not exposed. CVSS score: 6.7. EPSS probability: 0.1%; percentile: 2%.

Read brief →
Jun 26, 2026 Vendor advisory Critical vendor advisory CVE-2026-48930

Nodejs Node.Js — CVE-2026-48930 (Critical)

Nodejs · Node.Js

A flaw in Node.js TLS hostname handling can cause Embedded-nul hostnames can lead to silent authority rebinding due to c-string truncation in resolver bindings. This vulnerability affects all supported release lines: **Node.js 22**, **Node.js 24**, and **Node.js 26**.

Operator check

Review CVE-2026-48930 in your asset inventory. Apply patches per vendor guidance and verify Node.Js is not exposed. CVSS score: 9.8. EPSS probability: 0.3%; percentile: 20%.

Read brief →
Jun 26, 2026 Vendor advisory High-risk advisory CVE-2026-49252

deepstream is vulnerable to prototype pollution

npm · @deepstream/server

deepstream is vulnerable to prototype pollution

Operator check

Check whether @deepstream/server is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. EPSS probability: 0.3%; percentile: 19%.

Read brief →
Jun 26, 2026 Vendor advisory High-risk advisory CVE-2026-49293

js-toml vulnerable to CPU exhaustion via O(n^2) BigInt construction on radix-prefixed integer literals

npm · js-toml

js-toml vulnerable to CPU exhaustion via O(n^2) BigInt construction on radix-prefixed integer literals

Operator check

Check whether js-toml is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. EPSS probability: 0.4%; percentile: 33%.

Read brief →
Jun 26, 2026 Vendor advisory High-risk advisory CVE-2026-50015

pnpm Vulnerable to Arbitrary File Write/Delete via Malicious Patch File (Path Traversal)

npm · pnpm

pnpm Vulnerable to Arbitrary File Write/Delete via Malicious Patch File (Path Traversal)

Operator check

Check whether pnpm is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. EPSS probability: 0.2%; percentile: 16%.

Read brief →
Jun 26, 2026 Vendor advisory High-risk advisory CVE-2026-50016

pnpm: Transitive dependency alias path traversal allows project path override via symlink replacement

npm · pnpm

pnpm: Transitive dependency alias path traversal allows project path override via symlink replacement

Operator check

Check whether pnpm is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. EPSS probability: 0.3%; percentile: 23%.

Read brief →
Jun 26, 2026 Vendor advisory High-risk advisory CVE-2026-55487

pnpm: Manifest identity spoof satisfies allowBuilds and runs attacker lifecycle

npm · pnpm

pnpm: Manifest identity spoof satisfies allowBuilds and runs attacker lifecycle

Operator check

Check whether pnpm is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. EPSS probability: 0.1%; percentile: 2%.

Read brief →
Jun 26, 2026 Vendor advisory High-risk advisory CVE-2026-55697

pnpm: Repository-controlled configDependencies can select a pacquet native install engine

npm · pnpm

pnpm: Repository-controlled configDependencies can select a pacquet native install engine

Operator check

Check whether pnpm is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. EPSS probability: 0.1%; percentile: 2%.

Read brief →
Jun 26, 2026 Vendor advisory High-risk advisory CVE-2026-55698

pnpm: Project env lockfile can short-circuit package-manager resolution and execute lockfile-selected pnpm bytes

npm · pnpm

pnpm: Project env lockfile can short-circuit package-manager resolution and execute lockfile-selected pnpm bytes

Operator check

Check whether pnpm is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. EPSS probability: 0.2%; percentile: 7%.

Read brief →
Jun 26, 2026 Vendor advisory High-risk advisory CVE-2026-55700

pnpm: `stage download` writes outside its destination directory via manifest name/version traversal

npm · pnpm

pnpm: `stage download` writes outside its destination directory via manifest name/version traversal

Operator check

Check whether pnpm is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. EPSS probability: 0.3%; percentile: 17%.

Read brief →
Jun 26, 2026 Vendor advisory Critical vendor advisory CVE-2026-48797

Backpropagate: backprop ui --auth and backprop ui --share do not enforce authentication

PyPI · backpropagate

Backpropagate: backprop ui --auth and backprop ui --share do not enforce authentication

Operator check

Check whether backpropagate is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. CVSS score: 9.3. EPSS probability: 0.3%; percentile: 24%.

Read brief →
Jun 26, 2026 Vendor advisory High-risk advisory CVE-2026-49257

mcp-pinot: Unauthenticated tool invocation via default oauth_enabled=False + host 0.0.0.0 bind

PyPI · mcp-pinot-server

mcp-pinot: Unauthenticated tool invocation via default oauth_enabled=False + host 0.0.0.0 bind

Operator check

Check whether mcp-pinot-server is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. EPSS probability: 0.5%; percentile: 39%.

Read brief →
Jun 26, 2026 Vendor advisory High-risk advisory

semantic-router exposed to compromised litellm wheel (CVE-2026-42208) via unbounded transitive pin

PyPI · semantic-router

semantic-router exposed to compromised litellm wheel (CVE-2026-42208) via unbounded transitive pin

Operator check

Check whether semantic-router is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.

Read brief →
Jun 26, 2026 Vendor advisory High-risk advisory CVE-2026-44024

Fluentd is Vulnerable to Remote Code Execution (RCE) via Arbitrary File Write in `${tag}` Placeholder

RubyGems · fluentd

Fluentd is Vulnerable to Remote Code Execution (RCE) via Arbitrary File Write in `${tag}` Placeholder

Operator check

Check whether fluentd is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.

Read brief →
Jun 26, 2026 Vendor advisory Critical vendor advisory CVE-2026-2053

Wso2 Api Manager — CVE-2026-2053 (Critical)

Wso2 · Api Manager

The WSO2 API Manager's message flow component, when processing WS-Addressing headers, does not sufficiently validate or restrict user-controlled input within these headers. This omission allows an attacker to manipulate WS-Addressing headers to specify arbitrary destinations for server-initiated requests. Successful exploitation allows an unauthenticated attacker to control the destination of server-initiated requests originating from the WSO2 API Manager. This direct control can enable unauthorized access to internal network resources or services that would typically be inaccessible from ext

Operator check

Review CVE-2026-2053 in your asset inventory. Apply patches per vendor guidance and verify Api Manager is not exposed. CVSS score: 8.3. EPSS probability: 0.2%; percentile: 10%.

Read brief →
Jun 25, 2026 Vendor advisory Critical vendor advisory CVE-2026-50548

Anysphere Cursor — CVE-2026-50548 (Critical)

Anysphere · Cursor

Cursor is a code editor built for programming with AI. Prior to 3.0, Cursor runs agent terminal commands in a sandbox by default, and the sandbox grants write access to the command's working directory. A flaw was identified in how the agent could modify the working_directory parameter, which could cause the sandbox to include writable paths outside the intended workspace. A malicious agent could set working_directory to a sensitive location and write arbitrary files outside the workspace under the user's privileges. This enables non-sandboxed Remote Code Execution — for example by overwriting

Operator check

Review CVE-2026-50548 in your asset inventory. Apply patches per vendor guidance and verify Cursor is not exposed. CVSS score: 9.8. EPSS probability: 0.5%; percentile: 40%.

Read brief →
Jun 25, 2026 Vendor advisory Critical vendor advisory CVE-2026-50549

Anysphere Cursor — CVE-2026-50549 (Critical)

Anysphere · Cursor

Cursor is a code editor built for programming with AI. Prior to 3.0, Cursor runs agent terminal commands in a sandbox by default. Before a Write, the agent canonicalizes the target path to confirm it stays inside the workspace, but when canonicalization fails it falls back to the original path and writes without approval. A malicious agent can create an in-workspace symlink that points outside the workspace and force canonicalization to fail — either because the target does not exist or because read permission is removed from the path — so the agent writes through the symlink to an arbitrary l

Operator check

Review CVE-2026-50549 in your asset inventory. Apply patches per vendor guidance and verify Cursor is not exposed. CVSS score: 9.8. EPSS probability: 0.5%; percentile: 40%.

Read brief →
Jun 25, 2026 Vendor advisory Critical vendor advisory CVE-2026-40079

Cacti Cacti — CVE-2026-40079 (Critical)

Cacti · Cacti

Cacti is an open source performance and fault management framework. Versions 1.2.30 and prior are vulnerable to Command Injection due to lack of sanitization in the escape_command() function. The escape_command() function at lib/rrd.php is a no-op: it returns $command unchanged. The command line built by rrdtool_function_graph() is passed through this function and then to shell_exec($full_commandline). The risk is in __rrd_execute() where text_format values from graph templates (which may contain host variable substitutions) reach shell_exec without adequate escaping. This issue has been addre

Operator check

Review CVE-2026-40079 in your asset inventory. Apply patches per vendor guidance and verify Cacti is not exposed. CVSS score: 9.8. EPSS probability: 0.9%; percentile: 56%.

Read brief →
Jun 25, 2026 KEV Known exploited CVE-2026-20230

Cisco Unified Communications Manager Server-Side Request Forgery (SSRF) Vulnerability

Cisco · Unified Communications Manager

Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communications Manager Session Management Edition (Unified CM SME) contain a server-side request forgery (SSRF) Vulnerability that could allow an unauthenticated, remote attacker to write files to the underlying operating system that could be used later to elevate to root.

Operator check

Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

Read brief →
Jun 25, 2026 Vendor advisory High-risk advisory CVE-2026-48505

Filament: Multi-factor authentication (app) recovery codes can still be used multiple times via concurrent submission

Composer · filament/filament

Filament: Multi-factor authentication (app) recovery codes can still be used multiple times via concurrent submission

Operator check

Check whether filament/filament is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. EPSS probability: 0.2%; percentile: 9%.

Read brief →
Jun 25, 2026 Vendor advisory Critical vendor advisory CVE-2026-56123

Dest Unreach Socat — CVE-2026-56123 (Critical)

Dest Unreach · Socat

socat versions 1.8.0.0 through 1.8.1.1 contain a heap-based buffer overflow vulnerability that allows a malicious SOCKS5 proxy server to overwrite adjacent heap memory by exploiting a sign-extension flaw in the DOMAINNAME reply parser. During connection setup, the domain name length byte is read through a signed char field causing a negative bytes_to_read value that is implicitly converted to size_t, resulting in an unbounded heap write into the 262-byte reply buffer with attacker-controlled size and content.

Operator check

Review CVE-2026-56123 in your asset inventory. Apply patches per vendor guidance and verify Socat is not exposed. CVSS score: 8.1. EPSS probability: 0.3%; percentile: 21%.

Read brief →
Jun 25, 2026 Vendor advisory High-risk advisory CVE-2026-39829

golang.org/x/crypto/ssh: Invoking pathological RSA/DSA parameters may cause DoS

Go · golang.org/x/crypto/ssh

golang.org/x/crypto/ssh: Invoking pathological RSA/DSA parameters may cause DoS

Operator check

Check whether golang.org/x/crypto/ssh is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. EPSS probability: 0.3%; percentile: 22%.

Read brief →
Jun 25, 2026 Vendor advisory High-risk advisory CVE-2026-39830

golang.org/x/crypto/ssh: Invoking client can cause server deadlock on unexpected responses

Go · golang.org/x/crypto/ssh

golang.org/x/crypto/ssh: Invoking client can cause server deadlock on unexpected responses

Operator check

Check whether golang.org/x/crypto/ssh is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. EPSS probability: 0.4%; percentile: 31%.

Read brief →
Jun 25, 2026 Vendor advisory High-risk advisory CVE-2026-39831

golang.org/x/crypto/ssh: FIDO/U2F security key physical presence check can be bypassed

Go · golang.org/x/crypto/ssh

golang.org/x/crypto/ssh: FIDO/U2F security key physical presence check can be bypassed

Operator check

Check whether golang.org/x/crypto/ssh is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. EPSS probability: 0.4%; percentile: 29%.

Read brief →
Jun 25, 2026 Vendor advisory High-risk advisory CVE-2026-39832

golang.org/x/crypto/ssh/agent doesn't drop invoking agent constraints when forwarding keys

Go · golang.org/x/crypto/ssh/agent

golang.org/x/crypto/ssh/agent doesn't drop invoking agent constraints when forwarding keys

Operator check

Check whether golang.org/x/crypto/ssh/agent is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. EPSS probability: 0.4%; percentile: 32%.

Read brief →
Jun 25, 2026 Vendor advisory High-risk advisory CVE-2026-39833

golang.org/x/crypto/ssh/agent doesn't enforce invoking key constraints

Go · golang.org/x/crypto/ssh/agent

golang.org/x/crypto/ssh/agent doesn't enforce invoking key constraints

Operator check

Check whether golang.org/x/crypto/ssh/agent is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. EPSS probability: 0.4%; percentile: 28%.

Read brief →
Jun 25, 2026 Vendor advisory High-risk advisory CVE-2026-39834

golang.org/x/crypto/ssh vulnerable to infinite loop on large channel writes

Go · golang.org/x/crypto/ssh

golang.org/x/crypto/ssh vulnerable to infinite loop on large channel writes

Operator check

Check whether golang.org/x/crypto/ssh is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. EPSS probability: 0.5%; percentile: 37%.

Read brief →
Jun 25, 2026 Vendor advisory High-risk advisory CVE-2026-42508

golang.org/x/crypto/ssh/knownhosts vulnerable to auth bypass via unenforced @revoked status

Go · golang.org/x/crypto/ssh/knownhosts

golang.org/x/crypto/ssh/knownhosts vulnerable to auth bypass via unenforced @revoked status

Operator check

Check whether golang.org/x/crypto/ssh/knownhosts is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. EPSS probability: 0.4%; percentile: 29%.

Read brief →
Jun 25, 2026 Vendor advisory High-risk advisory CVE-2026-46595

golang.org/x/crypto/ssh: Invoking VerifiedPublicKeyCallback permissions skip enforcement

Go · golang.org/x/crypto/ssh

golang.org/x/crypto/ssh: Invoking VerifiedPublicKeyCallback permissions skip enforcement

Operator check

Check whether golang.org/x/crypto/ssh is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. EPSS probability: 0.4%; percentile: 30%.

Read brief →
Jun 25, 2026 Vendor advisory High-risk advisory CVE-2026-46597

golang.org/x/crypto/ssh: Invoking byte arithmetic causes underflow and panic

Go · golang.org/x/crypto/ssh

golang.org/x/crypto/ssh: Invoking byte arithmetic causes underflow and panic

Operator check

Check whether golang.org/x/crypto/ssh is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. EPSS probability: 0.4%; percentile: 28%.

Read brief →
Jun 25, 2026 Vendor advisory High-risk advisory CVE-2026-48702

Rekor has an OOM Condition due to Unbounded gzip Decompression in Alpine APK Parsing Logic

Go · github.com/sigstore/rekor

Rekor has an OOM Condition due to Unbounded gzip Decompression in Alpine APK Parsing Logic

Operator check

Check whether github.com/sigstore/rekor is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.

Read brief →
Jun 25, 2026 Vendor advisory High-risk advisory

chi's RealIP Middleware allows IP spoofing via unvalidated X-Forwarded-For header

Go · github.com/go-chi/chi/middleware

chi's RealIP Middleware allows IP spoofing via unvalidated X-Forwarded-For header

Operator check

Check whether github.com/go-chi/chi/middleware is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. CVSS score: 7.7.

Read brief →
Jun 25, 2026 Vendor advisory High-risk advisory CVE-2026-48713

i18next-fs-backend vulnerable to prototype pollution via crafted missing-key string

npm · i18next-fs-backend

i18next-fs-backend vulnerable to prototype pollution via crafted missing-key string

Operator check

Check whether i18next-fs-backend is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. EPSS probability: 0.4%; percentile: 33%.

Read brief →
Jun 25, 2026 Vendor advisory High-risk advisory CVE-2026-48714

i18next-http-middleware: MissingKeyHandler does not reject keys whose segments contain prototype-polluting names

npm · i18next-http-middleware

i18next-http-middleware: MissingKeyHandler does not reject keys whose segments contain prototype-polluting names

Operator check

Check whether i18next-http-middleware is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. EPSS probability: 0.4%; percentile: 33%.

Read brief →
Jun 25, 2026 Vendor advisory High-risk advisory CVE-2026-48502

MessagePack-CSharp: Denial of service vulnerabilities can swamp the CPU or crash the process with stack and heap over...

NuGet · MessagePack

MessagePack-CSharp: Denial of service vulnerabilities can swamp the CPU or crash the process with stack and heap overflows

Operator check

Check whether MessagePack is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. CVSS score: 8.2. EPSS probability: 0.3%; percentile: 17%.

Read brief →
Jun 25, 2026 Vendor advisory High-risk advisory CVE-2026-48506

MessagePack-CSharp: MessagePackReader.Skip can recurse without enforcing maximum object graph depth

NuGet · MessagePack

MessagePack-CSharp: MessagePackReader.Skip can recurse without enforcing maximum object graph depth

Operator check

Check whether MessagePack is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. EPSS probability: 0.3%; percentile: 19%.

Read brief →
Jun 25, 2026 Vendor advisory High-risk advisory CVE-2026-49218

ImageMagick: Policy Bypass in DCM decoder could result in image with invalid dimensions

NuGet · Magick.NET-Q16-AnyCPU

ImageMagick: Policy Bypass in DCM decoder could result in image with invalid dimensions

Operator check

Check whether Magick.NET-Q16-AnyCPU is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. EPSS probability: 0.3%; percentile: 18%.

Read brief →
Jun 25, 2026 Vendor advisory High-risk advisory CVE-2026-53460

ImageMagick: Policy Bypass can Trigger an Out-of-Memory condition

NuGet · Magick.NET-Q16-AnyCPU

ImageMagick: Policy Bypass can Trigger an Out-of-Memory condition

Operator check

Check whether Magick.NET-Q16-AnyCPU is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. EPSS probability: 0.3%; percentile: 18%.

Read brief →
Jun 25, 2026 Vendor advisory High-risk advisory CVE-2026-53461

ImageMagick has out-of-bounds write in ICON decoder due to incorrect loop

NuGet · Magick.NET-Q16-AnyCPU

ImageMagick has out-of-bounds write in ICON decoder due to incorrect loop

Operator check

Check whether Magick.NET-Q16-AnyCPU is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. EPSS probability: 0.3%; percentile: 18%.

Read brief →
Jun 25, 2026 KEV Known exploited CVE-2026-12569

PTC Windchill and FlexPLM Improper Input Validation Vulnerability

PTC · Windchill and FlexPLM

PTC Windchill and FlexPLM contains an improper input validation vulnerability allowing an unauthenticated, remote attacker to execute arbitrary code by sending a malicious request to the network.

Operator check

Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

Read brief →
Jun 25, 2026 Vendor advisory High-risk advisory CVE-2026-48508

Lemur has an authorization bypass in StrictRolePermission / AuthorityCreatorPermission

PyPI · lemur

Lemur has an authorization bypass in StrictRolePermission / AuthorityCreatorPermission

Operator check

Check whether lemur is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.

Read brief →
Jun 25, 2026 Vendor advisory High-risk advisory CVE-2026-9291

amazon-braket-sdk vulnerable to Insecure Deserialization via pickle.loads()

PyPI · amazon-braket-sdk

amazon-braket-sdk vulnerable to Insecure Deserialization via pickle.loads()

Operator check

Check whether amazon-braket-sdk is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. CVSS score: 7.5. EPSS probability: 0.4%; percentile: 30%.

Read brief →
Jun 25, 2026 Vendor advisory Critical vendor advisory CVE-2026-56786

Rtklib Rtklib — CVE-2026-56786 (Critical)

Rtklib · Rtklib

RTKLIB through 2.4.3 contains an out-of-bounds write vulnerability in decode_type1033 function that fails to clamp length counters to destination buffer size, allowing up to 191-byte overflow into fixed 64-byte descriptor fields. An attacker controlling an NTRIP or serial RTCM3 correction stream can craft a valid CRC-bearing type-1033 message to corrupt adjacent rtcm_t object members, potentially achieving arbitrary code execution or denial of service.

Operator check

Review CVE-2026-56786 in your asset inventory. Apply patches per vendor guidance and verify Rtklib is not exposed. CVSS score: 9.8. EPSS probability: 0.4%; percentile: 32%.

Read brief →
Jun 25, 2026 Vendor advisory Critical vendor advisory CVE-2026-6094

Wolfssl Wolfssl — CVE-2026-6094 (Critical)

Wolfssl · Wolfssl

Heap buffer overread in wc_PKCS7_DecodeEnvelopedData when parsing crafted PKCS7 EnvelopedData. This could theoretically be triggered by attacker-supplied data delivered via S/MIME or CMS.

Operator check

Review CVE-2026-6094 in your asset inventory. Apply patches per vendor guidance and verify Wolfssl is not exposed. CVSS score: 9.1. EPSS probability: 0.3%; percentile: 18%.

Read brief →
Jun 25, 2026 Vendor advisory Critical vendor advisory CVE-2026-7531

Wolfssl Wolfssl — CVE-2026-7531 (Critical)

Wolfssl · Wolfssl

Use-after-free in PQC hybrid key-share handling. This is an incomplete-fix follow-up to CVE-2026-5460 (released in 5.9.1): a malicious TLS 1.3 server sending a truncated PQC hybrid KeyShare can still trigger the error cleanup path to operate on freed memory.

Operator check

Review CVE-2026-7531 in your asset inventory. Apply patches per vendor guidance and verify Wolfssl is not exposed. CVSS score: 9.8. EPSS probability: 0.3%; percentile: 20%.

Read brief →
Jun 24, 2026 Vendor advisory Critical vendor advisory CVE-2026-55455

Appsmith Appsmith — CVE-2026-55455 (Critical)

Appsmith · Appsmith

Appsmith is a platform to build admin panels, internal tools, and dashboards. Prior to 2.1, the outbound HTTP host filter applied by WebClientUtils (used by the REST API and GraphQL datasource plugins) validates hosts against an exact-match string denylist. The comprehensive address-class check (loopback, any-local, link-local, fc00::/7) exists only on a separate code path used by SMTP, not by the HTTP plugin path. As a result, an authenticated user can craft outbound requests that reach loopback-bound services inside the container. This vulnerability is fixed in 2.1.

Operator check

Review CVE-2026-55455 in your asset inventory. Apply patches per vendor guidance and verify Appsmith is not exposed. CVSS score: 9.1. EPSS probability: 0.2%; percentile: 13%.

Read brief →
Jun 24, 2026 Vendor advisory Critical vendor advisory CVE-2026-39948

Cacti Cacti — CVE-2026-39948 (Critical)

Cacti · Cacti

Cacti is an open source performance and fault management framework. In versions 1.2.30 and prior, the rfilter request parameter is retrieved via the raw accessor grv() (rather than gfrv() with FILTER_VALIDATE_IS_REGEX validation) and concatenated directly into RLIKE SQL clauses in lib/html_graph.php and lib/html_tree.php, which are reachable pre-authentication through graph_view.php on installations with guest graph viewing enabled. Because the unbalanced-quote payload bypasses the regex validation that would otherwise reject it, an unauthenticated attacker can inject arbitrary SQL to compromi

Operator check

Review CVE-2026-39948 in your asset inventory. Apply patches per vendor guidance and verify Cacti is not exposed. CVSS score: 9.8. EPSS probability: 0.4%; percentile: 34%.

Read brief →
Jun 24, 2026 Vendor advisory High-risk advisory CVE-2026-48708

OliveTin has a Concurrent Template Parsing Race Condition which Leads to Cross-Request Command Contamination

Go · github.com/OliveTin/OliveTin

OliveTin has a Concurrent Template Parsing Race Condition which Leads to Cross-Request Command Contamination

Operator check

Check whether github.com/OliveTin/OliveTin is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. EPSS probability: 0.3%; percentile: 27%.

Read brief →
Jun 24, 2026 Vendor advisory Critical vendor advisory CVE-2026-45051

OpenAM: Pre-auth RCE via Java Deserialization in WebAuthn Authenticator Storage

Maven · org.openidentityplatform.openam:openam-auth-webauthn

OpenAM: Pre-auth RCE via Java Deserialization in WebAuthn Authenticator Storage

Operator check

Check whether org.openidentityplatform.openam:openam-auth-webauthn is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. CVSS score: 9.2.

Read brief →
Jun 24, 2026 Vendor advisory Critical vendor advisory CVE-2026-45052

OpenAM Pre-auth User Profile Tampering via Anonymous SOAP Authn in Liberty IDPP/Discovery Endpoints

Maven · org.openidentityplatform.openam:openam-federation-library

OpenAM Pre-auth User Profile Tampering via Anonymous SOAP Authn in Liberty IDPP/Discovery Endpoints

Operator check

Check whether org.openidentityplatform.openam:openam-federation-library is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. CVSS score: 9.3.

Read brief →
Jun 24, 2026 Vendor advisory Critical vendor advisory CVE-2026-56351

N8N N8N — CVE-2026-56351 (Critical)

N8N · N8N

n8n before version 2.4.0 contains a sql injection vulnerability in MySQL, PostgreSQL, and Microsoft SQL nodes that allows authenticated users to inject arbitrary SQL through unescaped identifier values in node configuration parameters. Attackers with workflow creation permissions can supply specially crafted table or column names to execute unauthorized database commands and compromise data integrity.

Operator check

Review CVE-2026-56351 in your asset inventory. Apply patches per vendor guidance and verify N8N is not exposed. CVSS score: 8.2. EPSS probability: 0.2%; percentile: 12%.

Read brief →
Jun 24, 2026 Vendor advisory Critical vendor advisory CVE-2026-54906

Rubyconcurrency Concurrent Ruby — CVE-2026-54906 (Critical)

Rubyconcurrency · Concurrent Ruby

concurrent-ruby is a modern concurrency tools for Ruby. Prior to 1.3.7, Concurrent::ReadWriteLock#release_write_lock does not verify that the calling thread acquired the write lock. Any thread with access to the lock object can release an active write lock held by another thread. A second writer can then enter its critical section while the first writer is still running. Concurrent::ReadWriteLock#release_read_lock also decrements the shared counter even when no read lock is held. Calling it on a fresh lock changes the counter from 0 to -1, after which normal read acquisition raises Concurrent:

Operator check

Review CVE-2026-54906 in your asset inventory. Apply patches per vendor guidance and verify Concurrent Ruby is not exposed. CVSS score: 9.8. EPSS probability: 0.1%; percentile: 0%.

Read brief →
Jun 23, 2026 Vendor advisory High-risk advisory CVE-2026-48507

Snipe-IT: Bulk editing users allowed `ldap_import` and `activated_in` bulk editing users

Composer · snipe/snipe-it

Snipe-IT: Bulk editing users allowed `ldap_import` and `activated_in` bulk editing users

Operator check

Check whether snipe/snipe-it is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. EPSS probability: 0.2%; percentile: 9%.

Read brief →
Jun 23, 2026 Vendor advisory High-risk advisory CVE-2026-55173

AVideo has an incomplete fix of CVE-2026-33482: sanitizeFFmpegCommand still allows a single '&' (background operator)...

Composer · wwbn/avideo

AVideo has an incomplete fix of CVE-2026-33482: sanitizeFFmpegCommand still allows a single '&' (background operator), giving OS command execution at the same execAsync sh -c sink

Operator check

Check whether wwbn/avideo is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.

Read brief →
Jun 23, 2026 Vendor advisory High-risk advisory CVE-2026-48126

Algernon: Host header path traversal in --domain mode reads files and runs Lua from parent dir

Go · github.com/xyproto/algernon

Algernon: Host header path traversal in --domain mode reads files and runs Lua from parent dir

Operator check

Check whether github.com/xyproto/algernon is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. EPSS probability: 0.3%; percentile: 25%.

Read brief →
Jun 23, 2026 Vendor advisory High-risk advisory CVE-2026-52806

Gogs vulnerable to RCE via git rebase --exec argument injection in pull request merge

Go · gogs.io/gogs

Gogs vulnerable to RCE via git rebase --exec argument injection in pull request merge

Operator check

Check whether gogs.io/gogs is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.

Read brief →
Jun 23, 2026 Vendor advisory High-risk advisory CVE-2026-52808

Gogs's write-level collaborators can mutate admin-only repository settings via API

Go · gogs.io/gogs

Gogs's write-level collaborators can mutate admin-only repository settings via API

Operator check

Check whether gogs.io/gogs is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.

Read brief →
Jun 23, 2026 Vendor advisory High-risk advisory CVE-2026-52810

Gogs allows users to write to readonly repositories using receive-pack + service=git-upload-pack confusion

Go · gogs.io/gogs

Gogs allows users to write to readonly repositories using receive-pack + service=git-upload-pack confusion

Operator check

Check whether gogs.io/gogs is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. CVSS score: 7.1.

Read brief →
Jun 23, 2026 Vendor advisory Critical vendor advisory CVE-2026-52811

Gogs: UploadRepoFiles writes outside repo working tree via committed parent sym

Go · gogs.io/gogs

Gogs: UploadRepoFiles writes outside repo working tree via committed parent sym

Operator check

Check whether gogs.io/gogs is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. CVSS score: 9.0.

Read brief →
Jun 23, 2026 Vendor advisory High-risk advisory CVE-2026-52812

Gogs: LFS dedupe path leaks private repo content across tenants

Go · gogs.io/gogs

Gogs: LFS dedupe path leaks private repo content across tenants

Operator check

Check whether gogs.io/gogs is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. CVSS score: 7.1.

Read brief →
Jun 23, 2026 Vendor advisory High-risk advisory CVE-2026-52813

Gogs has Path Traversal in organization name that results in RCE through Git hooks

Go · gogs.io/gogs

Gogs has Path Traversal in organization name that results in RCE through Git hooks

Operator check

Check whether gogs.io/gogs is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.

Read brief →
Jun 23, 2026 KEV Known exploited CVE-2025-67038

Lantronix EDS5000 Code Injection Vulnerability

Lantronix · EDS5000

Lantronix EDS5000 contains a code injection vulnerability that could allow attackers to inject arbitrary OS commands into the username parameter. Injected commands are executed with root privileges.

Operator check

Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

Read brief →
Jun 23, 2026 Vendor advisory High-risk advisory CVE-2026-45048

OpenAM Authenticated Privilege Escalation via Raw Token Disclosure Session RPC

Maven · org.openidentityplatform.openam:openam-core

OpenAM Authenticated Privilege Escalation via Raw Token Disclosure Session RPC

Operator check

Check whether org.openidentityplatform.openam:openam-core is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.

Read brief →
Jun 23, 2026 Vendor advisory High-risk advisory CVE-2026-45049

OpenAM Unauthenticated Session Hijacking via Information Exposure in CDCServlet

Maven · org.openidentityplatform.openam:openam-federation

OpenAM Unauthenticated Session Hijacking via Information Exposure in CDCServlet

Operator check

Check whether org.openidentityplatform.openam:openam-federation is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.

Read brief →
Jun 23, 2026 Vendor advisory High-risk advisory CVE-2026-54512

jackson-databind has a PolymorphicTypeValidator bypass via generic type parameters that allows arbitrary class instan...

Maven · com.fasterxml.jackson.core:jackson-databind

jackson-databind has a PolymorphicTypeValidator bypass via generic type parameters that allows arbitrary class instantiation

Operator check

Check whether com.fasterxml.jackson.core:jackson-databind is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.

Read brief →
Jun 23, 2026 Vendor advisory High-risk advisory CVE-2026-54513

jackson-databind has an array subtype allowlist bypass in BasicPolymorphicTypeValidator (allowIfSubTypeIsArray)

Maven · com.fasterxml.jackson.core:jackson-databind

jackson-databind has an array subtype allowlist bypass in BasicPolymorphicTypeValidator (allowIfSubTypeIsArray)

Operator check

Check whether com.fasterxml.jackson.core:jackson-databind is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.

Read brief →
Jun 23, 2026 Vendor advisory Critical vendor advisory CVE-2026-44789

N8N N8N — CVE-2026-44789 (Critical)

N8N · N8N

n8n is an open source workflow automation platform. Prior to 1.123.43, 2.22.1, and 2.20.7, an authenticated user with permission to create or modify workflows could achieve global prototype pollution via an unvalidated pagination parameter in the HTTP Request node. Combined with other techniques this could lead to RCE on the instance. This vulnerability is fixed in 1.123.43, 2.22.1, and 2.20.7.

Operator check

Review CVE-2026-44789 in your asset inventory. Apply patches per vendor guidance and verify N8N is not exposed. CVSS score: 9.9. EPSS probability: 0.5%; percentile: 40%.

Read brief →
Jun 23, 2026 Vendor advisory Critical vendor advisory CVE-2026-44791

N8N N8N — CVE-2026-44791 (Critical)

N8N · N8N

n8n is an open source workflow automation platform. Prior to 1.123.43, 2.22.1, and 2.20.7, an authenticated user with permission to create or modify workflows could bypass the patch for CVE-2026-42232 in the XML node. When combined with other nodes, this could lead to RCE on the n8n host. This vulnerability is fixed in 1.123.43, 2.22.1, and 2.20.7.

Operator check

Review CVE-2026-44791 in your asset inventory. Apply patches per vendor guidance and verify N8N is not exposed. CVSS score: 9.9. EPSS probability: 0.5%; percentile: 41%.

Read brief →
Jun 23, 2026 Vendor advisory Critical vendor advisory CVE-2026-44792

N8N N8N — CVE-2026-44792 (Critical)

N8N · N8N

n8n is an open source workflow automation platform. Prior to 1.123.43, 2.22.1, and 2.20.7, an attacker with write access to the git repository connected to an n8n Source Control configuration could commit a malicious Data Table JSON file containing a crafted column name. When an administrator performed a Source Control Pull, n8n imported the file and could lead to SQL injection on the internal PostgreSQL instance. Exploitation requires the n8n instance uses PostgreSQL as its database backend, the Source Control feature is enabled and connected to a repository the attacker can write to, and an

Operator check

Review CVE-2026-44792 in your asset inventory. Apply patches per vendor guidance and verify N8N is not exposed. CVSS score: 9.0. EPSS probability: 0.4%; percentile: 27%.

Read brief →
Jun 23, 2026 Vendor advisory Critical vendor advisory CVE-2026-54305

N8N N8N — CVE-2026-54305 (Critical)

N8N · N8N

n8n is an open source workflow automation platform. Prior to 1.123.55, 2.25.7, and 2.26.2, three EE endpoints used by the Dynamic Credentials feature accepted any authenticated n8n session without performing per-resource ownership or scope checks on the target workflow or credential. An authenticated user with no project membership or credential sharing relationship could enumerate credential identifiers, names, and types referenced by any private workflow in the instance, initiate an OAuth authorization flow against another user's credential to overwrite its stored tokens with tokens bound to

Operator check

Review CVE-2026-54305 in your asset inventory. Apply patches per vendor guidance and verify N8N is not exposed. CVSS score: 9.9. EPSS probability: 0.3%; percentile: 25%.

Read brief →
Jun 23, 2026 Vendor advisory Critical vendor advisory CVE-2026-54307

N8N N8N — CVE-2026-54307 (Critical)

N8N · N8N

n8n is an open source workflow automation platform. Prior to 1.123.55, 2.25.7, and 2.26.2, a member-level user with editor access to a shared workflow could reference credentials they do not own via specific public API endpoints. Credential ownership checks were only enforced partially leading to cross-user credential access. This issue affects instances where workflow sharing is enabled and at least one workflow has been shared with a member-level user as an Editor. This vulnerability is fixed in 1.123.55, 2.25.7, and 2.26.2.

Operator check

Review CVE-2026-54307 in your asset inventory. Apply patches per vendor guidance and verify N8N is not exposed. CVSS score: 9.6. EPSS probability: 0.3%; percentile: 24%.

Read brief →
Jun 23, 2026 Vendor advisory Critical vendor advisory CVE-2026-54309

N8N N8N — CVE-2026-54309 (Critical)

N8N · N8N

n8n is an open source workflow automation platform. Prior to 2.25.7 and 2.26.2, when @n8n/mcp-browser is run in HTTP transport mode, the MCP endpoint accepts session initialization and tool invocation requests without any authentication. Any network-reachable client, or any website visited by the user, can establish an MCP session and invoke browser-control tools. Where the n8n AI Browser Bridge extension is installed and a browser connection is active, an unauthenticated caller can access browser-control capabilities including navigation, JavaScript evaluation, and cookie and storage access a

Operator check

Review CVE-2026-54309 in your asset inventory. Apply patches per vendor guidance and verify N8N is not exposed. CVSS score: 10.0. EPSS probability: 0.4%; percentile: 33%.

Read brief →
Jun 23, 2026 Vendor advisory Critical vendor advisory CVE-2026-54310

N8N N8N — CVE-2026-54310 (Critical)

N8N · N8N

n8n is an open source workflow automation platform. Prior to 2.25.7 and 2.26.2, an authenticated user with permission to create or modify workflows could supply a crafted parameters to the TimescaleDB and/or legacy Postgres v1 node's allowing arbitrary SQL to be injected and executed against the connected database within the privileges of the configured database account. This vulnerability is fixed in 2.25.7 and 2.26.2.

Operator check

Review CVE-2026-54310 in your asset inventory. Apply patches per vendor guidance and verify N8N is not exposed. CVSS score: 9.9. EPSS probability: 0.3%; percentile: 23%.

Read brief →
Jun 23, 2026 Vendor advisory High-risk advisory CVE-2026-54350

Budibase has nonymous NoSQL operator injection via published-app query templates

npm · @budibase/server

Budibase has nonymous NoSQL operator injection via published-app query templates

Operator check

Check whether @budibase/server is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.

Read brief →
Jun 23, 2026 Vendor advisory High-risk advisory CVE-2026-53925

Glances has arbitrary file write and command execution via `secure_popen` redirection and chaining operators in AMP c...

PyPI · glances

Glances has arbitrary file write and command execution via `secure_popen` redirection and chaining operators in AMP command configuration

Operator check

Check whether glances is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.

Read brief →
Jun 23, 2026 Vendor advisory High-risk advisory CVE-2026-54134

OctoPrint has possible file exfiltration via query parameters on upload endpoints

PyPI · OctoPrint

OctoPrint has possible file exfiltration via query parameters on upload endpoints

Operator check

Check whether OctoPrint is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. CVSS score: 7.0.

Read brief →
Jun 23, 2026 Vendor advisory High-risk advisory CVE-2026-55488

motionEye's Absolute Path Traversal in Media File Handlers Allows Arbitrary File Read

PyPI · motioneye

motionEye's Absolute Path Traversal in Media File Handlers Allows Arbitrary File Read

Operator check

Check whether motioneye is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.

Read brief →
Jun 23, 2026 Vendor advisory Critical vendor advisory

motionEye Partial Authentication Bypass: Unauthenticated Admin Credential Theft via Path Traversal

PyPI · motioneye

motionEye Partial Authentication Bypass: Unauthenticated Admin Credential Theft via Path Traversal

Operator check

Check whether motioneye is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. CVSS score: 10.0.

Read brief →
Jun 23, 2026 Vendor advisory High-risk advisory

motionEye: LFI → pass‑the‑hash admin → unsafe restore → unauth action exec (RCE)

PyPI · motioneye

motionEye: LFI → pass‑the‑hash admin → unsafe restore → unauth action exec (RCE)

Operator check

Check whether motioneye is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.

Read brief →
Jun 23, 2026 Vendor advisory High-risk advisory CVE-2026-55441

Mise vulnerable to arbitrary command execution via task-include files in an untrusted, config-less repository

Rust · mise

Mise vulnerable to arbitrary command execution via task-include files in an untrusted, config-less repository

Operator check

Check whether mise is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.

Read brief →
Jun 23, 2026 KEV Known exploited CVE-2026-34908

Ubiquiti UniFi OS Improper Access Control Vulnerability

Ubiquiti · UniFi OS

Ubiquiti UniFi OS contains an improper access control vulnerability which could allow a malicious actor with access to the network to make unauthorized changes to the system.

Operator check

Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

Read brief →
Jun 23, 2026 KEV Known exploited CVE-2026-34909

Ubiquiti UniFi OS Path Traversal Vulnerability

Ubiquiti · UniFi OS

Ubiquiti UniFi OS contains a path traversal vulnerability which could allow a malicious actor with access to the network to access files on the underlying system that could be manipulated to access an underlying account.

Operator check

Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

Read brief →
Jun 23, 2026 KEV Known exploited CVE-2026-34910

Ubiquiti UniFi OS Improper Input Validation Vulnerability

Ubiquiti · UniFi OS

Ubiquiti UniFi OS contains an improper input validation vulnerability which could allow a malicious actor with access to the network to conduct command injection.

Operator check

Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

Read brief →
Jun 22, 2026 Vendor advisory High-risk advisory CVE-2025-58048

Paymenter vulnerable to Remote Code Execution via public file uploads

Composer · paymenter/paymenter

Paymenter vulnerable to Remote Code Execution via public file uploads

Operator check

Check whether paymenter/paymenter is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. EPSS probability: 0.4%; percentile: 29%.

Read brief →
Jun 22, 2026 Coordinated disclosure Patch review

VU#936962: Multiple file parsing vulnerabilities in FastStone Image Viewer 8.3.0.0

FastStone · Image Viewer 8.3.0.0

Overview Two vulnerabilities have been identified in FastStone Image Viewer 8.3 that may allow remote code execution or control-flow corruption when processing specially crafted image files. The affected components include the JPEG 2000 (JP2) parser and the PSD file parser. An attacker can exploit these vulnerabilities by causing the application to automatically or interactively process malicious image files. Description FastStone Image Viewer is a software tool for browsing, editing, and managing images, offering features like full‑screen viewing, batch processing, red‑eye removal, and a wide range of editing effects. It supports virtually all major image and RAW formats and includes conveniences like slideshows, comparison tools, scanner support, and screen capture. CVE-2026-30040 A critical heap-based buffer overflow vulnerability... Related CVEs: CVE-2026-30040, CVE-2026-30041.

Operator check

Review the CERT/CC Vulnerability Note and compare the affected vendor and product list against your inventory. Apply vendor fixes or compensating controls for Image Viewer 8.3.0.0 where available.

Read brief →
Jun 22, 2026 Vendor advisory Critical vendor advisory CVE-2026-8646

Ibm Websphere Application Server — CVE-2026-8646 (Critical)

Ibm · Websphere Application Server

IBM WebSphere Application Server 9.0 and 8.5 and IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.6 are vulnerable to HTTP request smuggling. A remote attacker could smuggle a specially crafted request to the application server thereby allowing the attacker to bypass security controls, spoof identity, escalate privilege, and expose sensitive information.

Operator check

Review CVE-2026-8646 in your asset inventory. Apply patches per vendor guidance and verify Websphere Application Server is not exposed. CVSS score: 7.4. EPSS probability: 0.4%; percentile: 27%.

Read brief →
Jun 22, 2026 Vendor advisory Critical vendor advisory CVE-2026-9006

Ibm Websphere Application Server — CVE-2026-9006 (Critical)

Ibm · Websphere Application Server

IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to server-side request forgery (SSRF) with the Ajax Proxy configured. This may allow an attacker to send unauthorized requests from the system, resulting in a security bypass or information disclosure.

Operator check

Review CVE-2026-9006 in your asset inventory. Apply patches per vendor guidance and verify Websphere Application Server is not exposed. CVSS score: 7.4. EPSS probability: 0.2%; percentile: 14%.

Read brief →
Jun 22, 2026 Vendor advisory Critical vendor advisory CVE-2026-9072

Ibm I — CVE-2026-9072 (Critical)

Ibm · I

IBM i 7.6, 7.5, 7.4, and 7.3, IBM WebSphere Application Server, and IBM WebSphere Application Server Liberty - when using Intelligent Management with the WebSphere WebServer Plug-in component - are vulnerable to remote code execution and denial of service. This vulnerability can be exploited when an attacker impersonates backend servers and sends crafted responses to the plug-in.

Operator check

Review CVE-2026-9072 in your asset inventory. Apply patches per vendor guidance and verify I is not exposed. CVSS score: 8.1. EPSS probability: 0.4%; percentile: 30%.

Read brief →
Jun 22, 2026 Vendor advisory Critical vendor advisory CVE-2026-49468

Litellm Litellm — CVE-2026-49468 (Critical)

Litellm · Litellm

LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. Prior to 1.84.0, This vulnerability is fixed in 1.84.0.

Operator check

Review CVE-2026-49468 in your asset inventory. Apply patches per vendor guidance and verify Litellm is not exposed. CVSS score: 9.8. EPSS probability: 0.4%; percentile: 31%.

Read brief →
Jun 22, 2026 Vendor advisory High-risk advisory CVE-2026-44179

xwiki-pro-macros has remote code execution from page title and content via excerpt-include macro

Maven · com.xwiki.pro:xwiki-pro-macros

xwiki-pro-macros has remote code execution from page title and content via excerpt-include macro

Operator check

Check whether com.xwiki.pro:xwiki-pro-macros is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.

Read brief →
Jun 22, 2026 Vendor advisory High-risk advisory CVE-2026-44203

OpenAM has pre-auth Reflected XSS in OAuth2 / OIDC response_mode=form_post via state parameter (FormPostResponse.ftl)

Maven · org.openidentityplatform.openam:openam-oauth2

OpenAM has pre-auth Reflected XSS in OAuth2 / OIDC response_mode=form_post via state parameter (FormPostResponse.ftl)

Operator check

Check whether org.openidentityplatform.openam:openam-oauth2 is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.

Read brief →
Jun 22, 2026 Vendor advisory Critical vendor advisory CVE-2026-46495

OpenDJ Pre-Auth RCE via Java Deserialization in JMX RMI

Maven · org.openidentityplatform.opendj:opendj-server-legacy

OpenDJ Pre-Auth RCE via Java Deserialization in JMX RMI

Operator check

Check whether org.openidentityplatform.opendj:opendj-server-legacy is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available. CVSS score: 9.2.

Read brief →
Jun 22, 2026 Vendor advisory Critical vendor advisory CVE-2026-48509

Messagepack Messagepack — CVE-2026-48509 (Critical)

Messagepack · Messagepack

MessagePack for C# is a MessagePack serializer for C#. Prior to 2.5.301 and 3.1.7, the parameterless MessagePackInputFormatter() constructor uses default serializer options, which resolve to MessagePackSerializerOptions.Standard with MessagePackSecurity.TrustedData. The formatter is designed for ASP.NET Core MVC request bodies, which commonly cross an HTTP trust boundary. This insecure default can expose applications to denial-of-service attacks that MessagePackSecurity.UntrustedData is intended to mitigate, such as hash-collision attacks against dictionary-like model properties. This vulnerab

Operator check

Review CVE-2026-48509 in your asset inventory. Apply patches per vendor guidance and verify Messagepack is not exposed. CVSS score: 9.1. EPSS probability: 0.2%; percentile: 13%.

Read brief →
Jun 22, 2026 Coordinated disclosure Patch review

VU#226679: Microsoft WinRE allows for bypass of UEFI/BIOS password enforcement

Microsoft · WinRE

Overview Microsoft Windows Recovery Environment (WinRE) provides a mechanism for recovering and repairing Windows systems using an alternate boot environment. Under certain platform implementations, access to WinRE may allow an attacker to bypass firmware security controls, including administrator-configured UEFI/BIOS passwords. An attacker with physical or administrative access to a device may be able to leverage WinRE-related boot mechanisms to circumvent firmware protections and gain unauthorized access to system resources. Description Microsoft Windows versions 10 and 11 include the WinRE capability, a recovery platform that supports features such as the F11 recovery menu and the Reset this PC functionalities. WinRE is commonly used for system recovery, troubleshooting, and remote support scenarios. When WinRE is invoked, the system...

Operator check

Review the CERT/CC Vulnerability Note and compare the affected vendor and product list against your inventory. Apply vendor fixes or compensating controls for WinRE where available.

Read brief →
Jun 22, 2026 Vendor advisory Critical vendor advisory CVE-2026-56348

N8N N8N — CVE-2026-56348 (Critical)

N8N · N8N

n8n before 2.20.0 contains a credential exfiltration vulnerability in the POST /rest/dynamic-node-parameters/options endpoint that allows authenticated users to bypass Allowed HTTP Request Domains restrictions. Attackers with credential access can cause the n8n server to issue HTTP requests with credentials to unauthorized hosts, exfiltrating sensitive authentication data.

Operator check

Review CVE-2026-56348 in your asset inventory. Apply patches per vendor guidance and verify N8N is not exposed. CVSS score: 9.1. EPSS probability: 0.2%; percentile: 16%.

Read brief →
Jun 22, 2026 Vendor advisory High-risk advisory CVE-2026-48170

scimPatch vulnerable to prototype pollution via unfiltered keys in patch

npm · scim-patch

scimPatch vulnerable to prototype pollution via unfiltered keys in patch

Operator check

Check whether scim-patch is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.

Read brief →
Jun 22, 2026 Vendor advisory High-risk advisory CVE-2026-54352

Budibase has arbitrary file read by workspace-builder via PWA-zip symlink upload

npm · @budibase/server

Budibase has arbitrary file read by workspace-builder via PWA-zip symlink upload

Operator check

Check whether @budibase/server is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.

Read brief →
Jun 22, 2026 Vendor advisory High-risk advisory CVE-2026-33646

Mise Vulnerable to Arbitrary Code Execution via Tera Templates in .tool-versions Files (Trust Bypass)

Rust · mise

Mise Vulnerable to Arbitrary Code Execution via Tera Templates in .tool-versions Files (Trust Bypass)

Operator check

Check whether mise is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.

Read brief →
Jun 18, 2026 Coordinated disclosure Patch review

VU#457458: Vendor-signed UEFI applications found vulnerable to Secure Boot bypass

Multiple vendors · Vendor-signed UEFI applications

Overview Multiple vendor-signed UEFI applications are vulnerable to Secure Boot bypass via a "Bring Your Own Vulnerable Driver" (BYOVD)-style attack. If a target system trusts the affected vendor’s certificate, an attacker can exploit these applications to execute arbitrary code during the early pre-boot phase before the operating system initializes. To mitigate this risk, system administrators should apply updates to the UEFI Forbidden Signature Database (DBX) that revoke trust in the affected vendor-signed binaries, preventing these vulnerable applications from executing during the boot process. Description The Unified Extensible Firmware Interface ( UEFI ) standard defines the modern firmware architecture used to initialize hardware and transfer control to the operating system during system startup. On systems with Secure Boot...

Operator check

Review the CERT/CC Vulnerability Note and compare the affected vendor and product list against your inventory. Apply vendor fixes or compensating controls for Vendor-signed UEFI applications where available.

Read brief →
Jun 18, 2026 KEV Known exploited CVE-2026-20253

Splunk Enterprise Missing Authentication for Critical Function Vulnerability

Splunk · Enterprise

Splunk Enterprise contains a missing authentication for critical function vulnerability which could allow an unauthenticated user to create or truncate arbitrary files through a PostgreSQL sidecar service endpoint.

Operator check

Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

Read brief →
Jun 17, 2026 Vendor advisory Critical vendor advisory CVE-2026-32966

Apache Dolphinscheduler — CVE-2026-32966 (Critical)

Apache · Dolphinscheduler

DataSource API Missing Authorization Check Leads to Arbitrary Data Source Metadata Disclosure in Apache DolphinScheduler. This issue affects Apache DolphinScheduler: before 3.4.2. Users are recommended to upgrade to version 3.4.2, which fixes the issue.

Operator check

Review CVE-2026-32966 in your asset inventory. Apply patches per vendor guidance and verify Dolphinscheduler is not exposed. CVSS score: 9.8.

Read brief →
Jun 17, 2026 Vendor advisory Critical vendor advisory CVE-2026-32967

Apache Dolphinscheduler — CVE-2026-32967 (Critical)

Apache · Dolphinscheduler

Incorrect Authorization vulnerability of `/v2` experimental interface in Apache DolphinScheduler. This issue affects Apache DolphinScheduler: before 3.4.2. Users are recommended to upgrade to version 3.4.2, which fixes the issue.

Operator check

Review CVE-2026-32967 in your asset inventory. Apply patches per vendor guidance and verify Dolphinscheduler is not exposed. CVSS score: 9.1.

Read brief →
Jun 17, 2026 Vendor advisory Critical vendor advisory CVE-2026-49268

Apache Shiro — CVE-2026-49268 (Critical)

Apache · Shiro

A remote attacker can inject LDAP special characters into the Distinguished Name (DN) construction in DefaultLdapRealm class. User-supplied username input is directly concatenated into the LDAP DN template without any escaping of RFC 2253 special characters. This allows an attacker to manipulate the DN structure used for LDAP bind authentication, potentially bypassing authentication or impersonating other users. This issue affects all Apache Shiro versions through 2.2.0, and 3.0.0-alpha-1 when using DefaultLdapRealm Upgrade to Apache Shiro 2.2.1 or 3.0.0-alpha-2 or later, which fixes the issu

Operator check

Review CVE-2026-49268 in your asset inventory. Apply patches per vendor guidance and verify Shiro is not exposed. CVSS score: 9.1.

Read brief →
Jun 17, 2026 Coordinated disclosure Patch review

VU#380058: SignalRGB kernel driver contains improper access control and IOCTL vulnerabilities

SignalRGB · kernel driver

Overview The SignalRGB kernel driver, SignalIo.sys , contains two vulnerabilities involving improper access control and unsafe memory handling. The device object is created with an overly permissive Discretionary Access Control List (DACL) that allows user-mode processes to access privileged hardware operations through input/output control (IOCTL) commands. Additionally, several IOCTL handlers are susceptible to NULL pointer dereference conditions, which further enables low-privilege users to trigger kernel crashes and cause Denial of Service (DoS). Version 1.3.7.0 of the SignalRGB driver remediates these vulnerabilities. Description SignalRGB is a Windows application used for RGB lighting control and hardware monitoring. Its kernel component, SignalIo.sys , provides the low-level interfaces required to access and interact with hardware... Related CVEs: CVE-2026-8049, CVE-2026-8050.

Operator check

Review the CERT/CC Vulnerability Note and compare the affected vendor and product list against your inventory. Apply vendor fixes or compensating controls for kernel driver where available.

Read brief →
Jun 16, 2026 KEV Known exploited CVE-2026-48907

Widget Factory Joomla Content Editor Improper Access Control Vulnerability

Widget Factory · Joomla Content Editor

Widget Factory Joomla Content Editor contains an improper access control vulnerability which could allow for upload and execution of PHP code via the creation of new editor profiles for unauthenticated users.

Operator check

Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

Read brief →
Jun 15, 2026 KEV Known exploited CVE-2026-20262

Cisco Catalyst SD-WAN Manager Directory or Path Traversal Vulnerability

Cisco · Catalyst SD-WAN Manager

Cisco Catalyst SD-WAN Manager contains a directory or path traversal vulnerability that could allow an authenticated, remote attacker to create a file or overwrite any file on the filesystem of an affected system.

Operator check

Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

Read brief →
Jun 15, 2026 KEV Known exploited CVE-2026-54420

LiteSpeed cPanel Plugin UNIX Symbolic Link (Symlink) Following Vulnerability

LiteSpeed · cPanel Plugin

LiteSpeed cPanel plugin contains a UNIX symbolic link (Symlink) following vulnerability that could allow a user with FTP or web shell access on a shared hosting server running CloudLinux/CageFS.

Operator check

Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

Read brief →
Jun 12, 2026 KEV Known exploited CVE-2026-35273

Oracle PeopleSoft Enterprise PeopleTools Missing Authentication for Critical Function Vulnerability

Oracle · PeopleSoft Enterprise PeopleTools

Oracle PeopleSoft Enterprise PeopleTools contains a missing authentication for critical function vulnerability which could allow an unauthenticated attacker to obtain takeover of PeopleSoft Enterprise PeopleTools.

Operator check

Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

Read brief →
Jun 11, 2026 KEV Known exploited CVE-2026-10520

Ivanti Sentry OS Command Injection Vulnerability

Ivanti · Sentry

Ivanti Sentry (formerly known as MobileIron Sentry) contains an OS command injection vulnerability which could allow a remote unauthenticated user to achieve root-level remote code execution. This vulnerability can be successfully exploited in cases where the Sentry appliance is in an unmanaged state with its endpoints externally reachable. The use of mTLS with EPMM or restricted HTTPS access through Neurons for MDM makes interfaces inaccessible to external actors.

Operator check

Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

Read brief →
Jun 11, 2026 Coordinated disclosure Patch review

VU#862559: crypton-x509-validation Haskell libraries do not enforce X.509 NameConstraints

Multiple vendors · crypton-x509-validation Haskell libraries do not enforce X.509 NameConstraints

Overview A vulnerability has been discovered in the Haskell TLS software stack, commonly used by applications built in the Haskell programming language to securely connect to servers over the internet. Specifically, the libraries "crypton-x509-validation" fail to enforce a key security feature called NameConstraints, a standard defined in RFC 5280 that helps organizations control which domains a certificate authority (CA) is allowed to issue certificates for. This vulnerability allows an attacker with access to the sub-CA to create certificates that will validate successfully with any Haskell TLS connection, allowing the attacker access to full session visibility. Version 1.91 for crypton-x509-validation have been released to address the vulnerability, tracked as CVE-2026-9648. Description Haskell is a programming language often used in... Related CVEs: CVE-2026-9648.

Operator check

Review the CERT/CC Vulnerability Note and compare the affected vendor and product list against your inventory. Apply vendor fixes or compensating controls for crypton-x509-validation Haskell libraries do not enforce X.509 NameConstraints where available.

Read brief →
Jun 9, 2026 KEV Known exploited CVE-2026-7473

Arista Extensible Operating System Incomplete Comparison with Missing Factors Vulnerability

Arista · Extensible Operating System

Arista Extensible Operating System (EOS) contains an incomplete comparison with missing factors vulnerability when the switch incorrectly decapsulate and forwards other unexpected tunneled packet with a destination IP matching its configured decapsulation IP.

Operator check

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Read brief →
Jun 9, 2026 KEV Known exploited CVE-2026-20245

Cisco Catalyst SD-WAN Manager Improper Encoding or Escaping of Output Vulnerability

Cisco · Catalyst SD-WAN Manager

Cisco Catalyst SD-WAN Manager formerly SD-WAN vManage contains an improper encoding or escaping of output vulnerability. This vulnerability could allow an authenticated, local attacker to execute arbitrary commands as root by supplying a crafted file to the affected system.

Operator check

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Read brief →
Jun 9, 2026 KEV Known exploited CVE-2026-11645

Google Chromium V8 Out-of-Bounds Read and Write Vulnerability

Google · Chromium V8

Google Chromium V8 out-of-bounds read and write vulnerability that could allow a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.

Operator check

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Read brief →
Jun 9, 2026 Patch Tuesday High-risk advisory CVE-2026-32174

Azure Bot Service Elevation of Privilege Vulnerability

Microsoft · Azure Bot Service

Improper authentication in Azure Bot Service allows an authorized attacker to elevate privileges over a network. Published in June 2026 Security Updates. MSRC exploitability: Publicly Disclosed:No;Exploited:No.

Operator check

Review the Microsoft Security Update Guide entry for CVE-2026-32174. Confirm whether Azure Bot Service is deployed, then apply the current security update or documented mitigation. CVSS score: 7.7. EPSS probability: 0.4%; percentile: 29%.

Read brief →
Jun 9, 2026 Patch Tuesday High-risk advisory CVE-2026-32208

Microsoft Edge (Chromium-based) Spoofing Vulnerability

Microsoft · Microsoft Edge (Chromium-based)

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Edge (Chromium-based) allows an authorized attacker to perform spoofing over a network. Published in June 2026 Security Updates. MSRC exploitability: Publicly Disclosed:No;Exploited:No;Latest Software Release:N/A.

Operator check

Review the Microsoft Security Update Guide entry for CVE-2026-32208. Confirm whether Microsoft Edge (Chromium-based) is deployed, then apply the current security update or documented mitigation. CVSS score: 8.8. EPSS probability: 0.3%; percentile: 20%.

Read brief →
Jun 9, 2026 Patch Tuesday High-risk advisory CVE-2026-42895

Microsoft Copilot Tampering Vulnerability

Microsoft · Microsoft Copilot

Improper neutralization of special elements used in a command ('command injection') in Microsoft Copilot allows an unauthorized attacker to perform tampering over a network. Published in June 2026 Security Updates. MSRC exploitability: Publicly Disclosed:No;Exploited:No;Latest Software Release:N/A.

Operator check

Review the Microsoft Security Update Guide entry for CVE-2026-42895. Confirm whether Microsoft Copilot is deployed, then apply the current security update or documented mitigation. CVSS score: 6.5. EPSS probability: 0.4%; percentile: 30%.

Read brief →
Jun 9, 2026 Patch Tuesday High-risk advisory CVE-2026-45472

Microsoft Office Remote Code Execution Vulnerability

Microsoft · Microsoft Office

Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally. Published in June 2026 Security Updates. MSRC exploitability: Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation Less Likely.

Operator check

Review the Microsoft Security Update Guide entry for CVE-2026-45472. Confirm whether Microsoft Office is deployed, then apply the current security update or documented mitigation. CVSS score: 8.4. EPSS probability: 0.3%; percentile: 26%.

Read brief →
Jun 9, 2026 Patch Tuesday High-risk advisory CVE-2026-45474

Microsoft Office Remote Code Execution Vulnerability

Microsoft · Microsoft Office

Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally. Published in June 2026 Security Updates. MSRC exploitability: Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation Less Likely.

Operator check

Review the Microsoft Security Update Guide entry for CVE-2026-45474. Confirm whether Microsoft Office is deployed, then apply the current security update or documented mitigation. CVSS score: 8.4. EPSS probability: 0.4%; percentile: 28%.

Read brief →
Jun 9, 2026 Patch Tuesday Critical vendor advisory CVE-2026-45480

Azure Active Directory Elevation of Privilege Vulnerability

Microsoft · Azure Active Directory

Improper authentication in Azure Active Directory allows an unauthorized attacker to elevate privileges over a network. Published in June 2026 Security Updates. MSRC exploitability: Publicly Disclosed:No;Exploited:No;Latest Software Release:N/A.

Operator check

Review the Microsoft Security Update Guide entry for CVE-2026-45480. Confirm whether Azure Active Directory is deployed, then apply the current security update or documented mitigation. CVSS score: 10.0. EPSS probability: 0.6%; percentile: 43%.

Read brief →
Jun 9, 2026 Patch Tuesday High-risk advisory CVE-2026-47633

Microsoft Cost Management Information Disclosure Vulnerability

Microsoft · Cost Management Interactive Experiences

Exposure of sensitive information to an unauthorized actor in Cost Management Interactive Experiences allows an unauthorized attacker to disclose information over a network. Published in June 2026 Security Updates. MSRC exploitability: Publicly Disclosed:No;Exploited:No;Latest Software Release:N/A.

Operator check

Review the Microsoft Security Update Guide entry for CVE-2026-47633. Confirm whether Cost Management Interactive Experiences is deployed, then apply the current security update or documented mitigation. CVSS score: 7.5. EPSS probability: 0.6%; percentile: 43%.

Read brief →
Jun 9, 2026 Patch Tuesday High-risk advisory CVE-2026-47644

Copilot Chat (Microsoft Edge) Information Disclosure Vulnerability

Microsoft · Copilot Chat (Microsoft Edge)

Improper neutralization of special elements in output used by a downstream component ('injection') in Copilot Chat (Microsoft Edge) allows an unauthorized attacker to disclose information over a network. Published in June 2026 Security Updates. MSRC exploitability: Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation Less Likely.

Operator check

Review the Microsoft Security Update Guide entry for CVE-2026-47644. Confirm whether Copilot Chat (Microsoft Edge) is deployed, then apply the current security update or documented mitigation. CVSS score: 6.5. EPSS probability: 0.7%; percentile: 50%.

Read brief →
Jun 9, 2026 Patch Tuesday High-risk advisory CVE-2026-47655

Microsoft Graph Information Disclosure Vulnerability

Microsoft · Microsoft Graph

Exposure of sensitive information to an unauthorized actor in Microsoft Graph allows an authorized attacker to disclose information over a network. Published in June 2026 Security Updates. MSRC exploitability: Publicly Disclosed:No;Exploited:No;Latest Software Release:N/A.

Operator check

Review the Microsoft Security Update Guide entry for CVE-2026-47655. Confirm whether Microsoft Graph is deployed, then apply the current security update or documented mitigation. CVSS score: 6.5. EPSS probability: 0.8%; percentile: 50%.

Read brief →
Jun 9, 2026 Patch Tuesday Critical vendor advisory CVE-2026-54130

M365 Copilot Information Disclosure Vulnerability

Microsoft · M365 Copilot

Missing authentication for critical function in M365 Copilot allows an unauthorized attacker to disclose information over a network. Published in June 2026 Security Updates. MSRC exploitability: Publicly Disclosed:No;Exploited:No;Latest Software Release:N/A.

Operator check

Review the Microsoft Security Update Guide entry for CVE-2026-54130. Confirm whether M365 Copilot is deployed, then apply the current security update or documented mitigation. CVSS score: 9.8. EPSS probability: 0.5%; percentile: 39%.

Read brief →
Jun 9, 2026 Coordinated disclosure Patch review

VU#616257: Microsoft-signed UEFI shim bootloaders vulnerable to Secure Boot bypass

UEFI · applications and drivers must be cryptographically signed and verified

Overview Microsoft-signed UEFI bootloaders of the open-source shim project, primarily from version 0.9 and earlier, were identified as vulnerable to Secure Boot bypass. To mitigate this risk, the affected bootloaders will be added to the Microsoft UEFI Forbidden Signature Database (DBX). Once the DBX update is applied, these bootloaders will no longer be trusted for execution during the boot process. An attacker could exploit these vulnerable shim bootloaders using a Bring Your Own Vulnerable Driver (BYOVD)-style technique to execute arbitrary code during the early boot phase, prior to operating system initialization, thereby bypassing Secure Boot protections. Description The Unified Extensible Firmware Interface (UEFI) standard defines the modern firmware architecture used to initialize hardware and transfer control to the operating... Related CVEs: CVE-2026-10797, CVE-2026-8863.

Operator check

Review the CERT/CC Vulnerability Note and compare the affected vendor and product list against your inventory. Apply vendor fixes or compensating controls for applications and drivers must be cryptographically signed and verified where available.

Read brief →
Jun 8, 2026 KEV Known exploited CVE-2026-42271

BerriAI LiteLLM Command Injection Vulnerability

BerriAI · LiteLLM

BerriAI LiteLLM contains a command injection vulnerability that could allow any authenticated user, including holders of low-privilege internal-user keys, to run arbitrary commands on the host.

Operator check

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Read brief →
Jun 8, 2026 KEV Known exploited CVE-2026-50751

Check Point Security Gateway Improper Authentication Vulnerability

Check Point · Security Gateway

Check Point Security Gateway contains an improper authentication vulnerability in IKEv1 key exchange that could allow an unauthenticated remote attacker to bypass user authentication and establish a remote access VPN connection without a valid user password.

Operator check

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Read brief →
Jun 5, 2026 KEV Known exploited CVE-2026-28318

SolarWinds Serv-U Uncontrolled Resource Consumption Vulnerability

SolarWinds · Serv-U

SolarWinds Serv-U contains an uncontrolled resource consumption vulnerability that allows specially crafted POST requests using the Content-Encoding: deflate header to crash the Serv-U service without authentication.

Operator check

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Read brief →
Jun 3, 2026 KEV Known exploited CVE-2026-45247

Mirasvit Full Page Cache Warmer Deserialization of Untrusted Data Vulnerability

Mirasvit · Mirasvit Full Page Cache Warmer

Mirasvit Full Page Cache Warmer contains a deserialization of untrusted data vulnerability that could allow unauthenticated attackers to achieve remote code execution by supplying a crafted serialized PHP object in the CacheWarmer cookie.

Operator check

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Read brief →
Jun 3, 2026 Coordinated disclosure Patch review

VU#595768: Securly Chrome Extension contains multiple weak encryption and access control vulnerabilities

Securly · Chrome Extension

Overview Version 3.0.7 of the Securly Chrome Extension contains multiple vulnerabilities involving insecure data transmission, weak cryptography, and improper access control. These issues may expose sensitive filtering rules, enable the manipulation of downloaded configuration files, and allow unauthenticated access to protected resources. An attacker could exploit these weakness to steal configuration information, induce a Denial of Service (DoS), or modify content blocking rules for student users. Description The Securly Chrome Extension is a browser add-on commonly used in K–12 school-managed Chromebooks to enforce internet safety policies, filter or block websites, and provide activity monitoring for students. It is an element of the Securly classroom management platform, which helps schools comply with web filtering requirements and... Related CVEs: CVE-2026-8874, CVE-2026-8876, CVE-2026-8878, CVE-2026-8879.

Operator check

Review the CERT/CC Vulnerability Note and compare the affected vendor and product list against your inventory. Apply vendor fixes or compensating controls for Chrome Extension where available.

Read brief →
Jun 2, 2026 Coordinated disclosure Patch review

VU#265691: Appsmiths SQL Query autocomplete renderer contains a cross site scripting vulnerability

Appsmiths · SQL Query autocomplete renderer

Overview A stored cross-site scripting (XSS) vulnerability has been discovered in Appsmith, specifically in the CodeMirror based SQL query editor’s autocomplete renderer. CVE-2026-7299 has been assigned to track the vulnerability. An attacker with developer level access to a shared PostgreSQL datasource can inject arbitrary JavaScript by creating malicious database objects whose names contain XSS payloads. Successful exploitation leads to arbitrary JavaScript execution in the browser of any workspace member who triggers SQL autocomplete, enabling session hijacking, privilege escalation, or credential theft. Version 2.1 of Appsmith fixes CVE-2026-7299. Description Appsmith is an open source, low code platform intended to allow developers to build internal tools, dashboards, and applications using a UI builder, database and API... Related CVEs: CVE-2026-7299.

Operator check

Review the CERT/CC Vulnerability Note and compare the affected vendor and product list against your inventory. Apply vendor fixes or compensating controls for SQL Query autocomplete renderer where available.

Read brief →
Jun 2, 2026 Coordinated disclosure Patch review

VU#873170: Collibra Agent contains improper authentication and path traversal vulnerabilities

Collibra · Agent

Overview The Collibra Platform Agent contains vulnerabilities that can be chained by a remote, unauthenticated attacker to achieve remote code execution. An attacker can exploit these issues by uploading a crafted ZIP archive that writes attacker-controlled files to arbitrary locations on the server once extracted, resulting in code execution. Description Collibra Platform (CP) and Collibra Platform Self-Hosted (CPSH), an enterprise grade, cloud-based platform designed to help organizations locate, understand, trust, and manage their data assets. The Collibra Agent of CP and CPSH that is installed on the host system is an independent service that listens on different port than the web interface and have the following vulnerabilities. CVE-2026-10622 Privileged REST endpoints exposed under /rest/* do not properly enforce authentication or... Related CVEs: CVE-2026-10621, CVE-2026-10622.

Operator check

Review the CERT/CC Vulnerability Note and compare the affected vendor and product list against your inventory. Apply vendor fixes or compensating controls for Agent where available.

Read brief →
Jun 2, 2026 Coordinated disclosure Patch review

VU#615987: Missing IPsec Integrity Protection for IMS SIP Signaling in Verizon VoLTE Deployments

Verizon · VoLTE Deployments

Overview VoLTE deployments on Verizon’s IMS network have operated without negotiated SIP integrity protection. In observed test conditions, SIP signaling—including registration, call setup, and messaging—traveled without IPsec ESP encapsulation and without SIP Security Agreement headers, exposing it to interception and modification by on-path attackers. Recent carrier configuration updates, including Apple’s iOS 26.5 carrier bundle released on May 11, 2026, include IMS IPsec–related settings. However, such configuration entries do not confirm active deployment, successful negotiation, or functional protection in production. Description CVE-2026-10629 Verizon IMS deployments were observed transmitting SIP signaling without integrity protection. REGISTER exchanges lacked Security-Client, Security-Server, and Security-Verify headers, and no... Related CVEs: CVE-2026-10629.

Operator check

Review the CERT/CC Vulnerability Note and compare the affected vendor and product list against your inventory. Apply vendor fixes or compensating controls for VoLTE Deployments where available.

Read brief →
Jun 1, 2026 KEV Known exploited CVE-2024-21182

Oracle WebLogic Server Unspecified Vulnerability

Oracle · WebLogic Server

Oracle WebLogic contains an unspecified vulnerability that could allow an unauthenticated attacker with network access via T3, IIOP to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle WebLogic Server accessible data.

Operator check

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Read brief →
May 29, 2026 KEV Known exploited CVE-2026-0257

Palo Alto Networks PAN-OS Authentication Bypass Vulnerability

Palo Alto Networks · PAN-OS

Palo Alto Networks PAN-OS contains an authentication bypass vulnerability that allows attackers to bypass security restrictions and establish an unauthorized VPN connection.

Operator check

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Read brief →
May 27, 2026 KEV Known exploited CVE-2026-48027

Nx Console Embedded Malicious Code Vulnerability

Nx · Nx Console

Nx Console contains an embedded malicious code vulnerability that allowed a malicious version of Nx Console to be published. The compromised extension fetched an obfuscated payload that could harvested credentials from multiple sources on disk and in memory.

Operator check

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Read brief →
May 27, 2026 KEV Known exploited CVE-2026-45321

TanStack Unspecified Vulnerability

TanStack · TanStack

TanStack contains an unspecified vulnerability that allowed malicious versions of the product to be published to the npm registry to publish credential-stealing malware under a trusted identity.

Operator check

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Read brief →
May 26, 2026 KEV Known exploited CVE-2026-48172

LiteSpeed cPanel Plugin Privilege Escalation Vulnerability

LiteSpeed · cPanel Plugin

LiteSpeed cPanel Plugin contains privilege escalation vulnerability that is exposed via the user-end cPanel plugin, which can be abused by any cPanel user account to execute arbitrary scripts with root privileges.

Operator check

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Read brief →
May 22, 2026 KEV Known exploited CVE-2026-9082

Drupal Core SQL Injection Vulnerability

Drupal · Core

Drupal Core contains a SQL injection vulnerability that could allow for privilege escalation and remote code execution via specially crafted requests sent with the database abstraction API.

Operator check

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Read brief →
May 21, 2026 KEV Known exploited CVE-2025-34291

Langflow Origin Validation Error Vulnerability

Langflow · Langflow

Langflow contains an origin validation error vulnerability in which an overly permissive CORS configuration combined with a refresh token cookie configured as SameSite=None allows a malicious webpage to perform cross-origin requests that include credentials and successfully call the refresh endpoint. This could allow the attacker to execute arbitrary code and achieve full system compromise via obtained tokens that permit access to authenticated endpoints.

Operator check

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Read brief →
May 21, 2026 KEV Known exploited CVE-2026-34926

Trend Micro Apex One (On-Premise) Directory Traversal Vulnerability

Trend Micro · Apex One

Trend Micro Apex One (on-premise) contains a directory traversal vulnerability that could allow a pre-authenticated local attacker to modify a key table on the server to inject malicious code to deploy to agents on affected installations.

Operator check

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Read brief →
May 20, 2026 KEV Known exploited CVE-2009-3459

Adobe Acrobat and Reader Heap-Based Buffer Overflow Vulnerability

Adobe · Acrobat and Reader

Adobe Acrobat and Reader contain a heap-based buffer overflow vulnerability which could allow remote attackers to execute arbitrary code via a crafted PDF file that triggers memory corruption.

Operator check

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Read brief →
May 20, 2026 KEV Known exploited CVE-2008-4250

Microsoft Windows Buffer Overflow Vulnerability

Microsoft · Windows

Microsoft Windows contains a buffer overflow vulnerability in the Windows Server Service that allows remote attackers to execute arbitrary code via a crafted RPC request that triggers an overflow during path canonicalization.

Operator check

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Read brief →
May 20, 2026 KEV Known exploited CVE-2009-1537

Microsoft DirectX NULL Byte Overwrite Vulnerability

Microsoft · DirectX

Microsoft DirectX contains a NULL byte overwrite vulnerability in the QuickTime Movie Parser Filter in quartz.dll in DirectShow which could allow remote attackers to execute arbitrary code via a crafted QuickTime media file.

Operator check

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Read brief →
May 20, 2026 KEV Known exploited CVE-2010-0249

Microsoft Internet Explorer Use-After-Free Vulnerability

Microsoft · Internet Explorer

Microsoft Internet Explorer contains an use-after-free vulnerability that could allow remote attackers to execute arbitrary code by accessing a pointer associated with a deleted object. The impacted product could be end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue product utilization.

Operator check

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Read brief →
May 20, 2026 KEV Known exploited CVE-2010-0806

Microsoft Internet Explorer Use-After-Free Vulnerability

Microsoft · Internet Explorer

Microsoft Internet Explorer contains an use-after-free vulnerability that could allow remote attackers to execute arbitrary code via vectors involving access to an invalid pointer after the deletion of an object. The impacted product could be end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue product utilization.

Operator check

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Read brief →
May 15, 2026 KEV Known exploited CVE-2026-42897

Microsoft Exchange Server Cross-Site Scripting Vulnerability

Microsoft · Microsoft

Microsoft Exchange Server contains a cross-site scripting vulnerability during web page generation in Outlook Web Access and when certain interaction conditions are met, arbitrary JavaScript can be executed in the browser context.

Operator check

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Read brief →
May 14, 2026 KEV Known exploited CVE-2026-20182

Cisco Catalyst SD-WAN Controller Authentication Bypass Vulnerability

Cisco · Catalyst SD-WAN

Cisco Catalyst SD-WAN Controller & Manager contain an authentication bypass vulnerability that allows an unauthenticated, remote attacker to bypass authentication and obtain administrative privileges on an affected system.

Operator check

Please adhere to CISA’s guidelines to assess exposure and mitigate risks associated with Cisco SD-WAN devices as outlined in CISA’s Emergency Directive 26-03 (URL listed below in Notes) and CISA’s Hunt & Hardening Guidance for Cisco SD-WAN Devices (URL listed below in Notes). Adhere to the applicable BOD 22-01 guidance for cloud services or discontinue use of the product if mitigations are not available.

Read brief →
May 8, 2026 KEV Known exploited CVE-2026-42208

BerriAI LiteLLM SQL Injection Vulnerability

BerriAI · LiteLLM

BerriAI LiteLLM contains a SQL injection vulnerability that allows an attacker to read data from the proxy's database and potentially modify it, leading to unauthorized access to the proxy and the credentials it manages.

Operator check

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Read brief →
May 7, 2026 KEV Known exploited CVE-2026-6973

Ivanti Endpoint Manager Mobile (EPMM) Improper Input Validation Vulnerability

Ivanti · Endpoint Manager Mobile (EPMM)

Ivanti Endpoint Manager Mobile (EPMM) contains an improper input validation vulnerability that allows a remotely authenticated user with administrative access to achieve remote code execution.

Operator check

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Read brief →
May 6, 2026 KEV Known exploited CVE-2026-0300

Palo Alto Networks PAN-OS Out-of-bounds Write Vulnerability

Palo Alto Networks · PAN-OS

Palo Alto Networks PAN-OS contains an out-of-bounds write vulnerability in the User-ID Authentication Portal (aka Captive Portal) service that can allow an unauthenticated attacker to execute arbitrary code with root privileges on the PA-Series and VM-Series firewalls by sending specially crafted packets.

Operator check

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. Until the vendor releases an official fix, the following workaround should be implemented: - Restrict User-ID Authentication Portal access to only trusted zones. - Disable User-ID Authentication Portal if not required. 5/13/2026: Palo Alto has released a variety of patches. If these are relevant to your environment, please apply the designated patch.

Read brief →
Apr 30, 2026 KEV Known exploited CVE-2026-41940

WebPros cPanel & WHM and WP2 (WordPress Squared) Missing Authentication for Critical Function Vulnerability

WebPros · cPanel & WHM and WP2 (WordPress Squared)

WebPros cPanel & WHM (WebHost Manager) and WP2 (WordPress Squared) contain an authentication bypass vulnerability in the login flow that allows unauthenticated remote attackers to gain unauthorized access to the control panel.

Operator check

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Read brief →
Apr 28, 2026 KEV Known exploited CVE-2024-1708

ConnectWise ScreenConnect Path Traversal Vulnerability

ConnectWise · ScreenConnect

ConnectWise ScreenConnect contains a path traversal vulnerability which could allow an attacker to execute remote code or directly impact confidential data and critical systems.

Operator check

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Read brief →
Apr 28, 2026 KEV Known exploited CVE-2026-32202

Microsoft Windows Protection Mechanism Failure Vulnerability

Microsoft · Windows

Microsoft Windows Shell contains a protection mechanism failure vulnerability that allows an unauthorized attacker to perform spoofing over a network.

Operator check

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Read brief →
Apr 24, 2026 KEV Known exploited CVE-2025-29635

D-Link DIR-823X Command Injection Vulnerability

D-Link · DIR-823X

D-Link DIR-823X contains a command injection vulnerability that allows an authorized attacker to execute arbitrary commands on remote devices by sending a POST request to /goform/set_prohibiting via the corresponding function. The impacted product could be end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue product utilization.

Operator check

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Read brief →
Apr 24, 2026 KEV Known exploited CVE-2024-7399

Samsung MagicINFO 9 Server Path Traversal Vulnerability

Samsung · MagicINFO 9 Server

Samsung MagicINFO 9 Server contains a path traversal vulnerability that could allow an attacker to write arbitrary files as system authority.

Operator check

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Read brief →
Apr 24, 2026 KEV Known exploited CVE-2024-57726

SimpleHelp Missing Authorization Vulnerability

SimpleHelp · SimpleHelp

SimpleHelp contains a missing authorization vulnerability that could allow low-privileged technicians to create API keys with excessive permissions. These API keys can be used to escalate privileges to the server admin role.

Operator check

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Read brief →
Apr 24, 2026 KEV Known exploited CVE-2024-57728

SimpleHelp Path Traversal Vulnerability

SimpleHelp · SimpleHelp

SimpleHelp contains a path traversal vulnerability that allows admin users to upload arbitrary files anywhere on the file system by uploading a crafted zip file (i.e. zip slip). This can be exploited to execute arbitrary code on the host in the context of the SimpleHelp server user.

Operator check

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Read brief →
Apr 23, 2026 KEV Known exploited CVE-2026-39987

Marimo Remote Code Execution Vulnerability

Marimo · Marimo

Marimo contains an pre-authorization remote code execution vulnerability, allowing an unauthenticated attacked to shell access and execute arbitrary system commands.

Operator check

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Read brief →
Apr 22, 2026 KEV Known exploited CVE-2026-33825

Microsoft Defender Insufficient Granularity of Access Control Vulnerability

Microsoft · Defender

Microsoft Defender contains an insufficient granularity of access control vulnerability that could allow an authorized attacker to escalate privileges locally.

Operator check

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Read brief →
Apr 20, 2026 KEV Known exploited CVE-2026-20122

Cisco Catalyst SD-WAN Manager Incorrect Use of Privileged APIs Vulnerability

Cisco · Catalyst SD-WAN Manger

Cisco Catalyst SD-WAN Manager contains an incorrect use of privileged APIs vulnerability due to improper file handling on the API interface of an affected system. An attacker could exploit this vulnerability by uploading a malicious file on the local file system. A successful exploit could allow the attacker to overwrite arbitrary files on the affected system and gain vmanage user privileges.

Operator check

Please adhere to CISA’s guidelines to assess exposure and mitigate risks associated with Cisco SD-WAN devices as outlines in CISA’s Emergency Directive 26-03 (URL listed below in Notes) and CISA’s “Hunt & Hardening Guidance for Cisco SD-WAN Devices (URL listed below in Notes). Adhere to the applicable BOD 22-01 guidance for cloud services or discontinue use of the product if mitigations are not available.

Read brief →
Apr 20, 2026 KEV Known exploited CVE-2026-20128

Cisco Catalyst SD-WAN Manager Storing Passwords in a Recoverable Format Vulnerability

Cisco · Catalyst SD-WAN Manager

Cisco Catalyst SD-WAN Manager contains a storing passwords in a recoverable format vulnerability that allows an authenticated, local attacker to gain DCA user privileges by accessing a credential file for the DCA user on the filesystem as a low-privileged user.

Operator check

Please adhere to CISA’s guidelines to assess exposure and mitigate risks associated with Cisco SD-WAN devices as outlines in CISA’s Emergency Directive 26-03 (URL listed below in Notes) and CISA’s “Hunt & Hardening Guidance for Cisco SD-WAN Devices (URL listed below in Notes). Adhere to the applicable BOD 22-01 guidance for cloud services or discontinue use of the product if mitigations are not available.

Read brief →
Apr 20, 2026 KEV Known exploited CVE-2026-20133

Cisco Catalyst SD-WAN Manager Exposure of Sensitive Information to an Unauthorized Actor Vulnerability

Cisco · Catalyst SD-WAN Manager

Cisco Catalyst SD-WAN Manager contains an exposure of sensitive information to an unauthorized actor vulnerability that could allow remote attackers to view sensitive information on affected systems.

Operator check

Please adhere to CISA’s guidelines to assess exposure and mitigate risks associated with Cisco SD-WAN devices as outlines in CISA’s Emergency Directive 26-03 (URL listed below in Notes) and CISA’s “Hunt & Hardening Guidance for Cisco SD-WAN Devices (URL listed below in Notes). Adhere to the applicable BOD 22-01 guidance for cloud services or discontinue use of the product if mitigations are not available.

Read brief →
Apr 20, 2026 KEV Known exploited CVE-2025-2749

Kentico Xperience Path Traversal Vulnerability

Kentico · Kentico Xperience

Kentico Xperience contains a path traversal vulnerability that could allow an authenticated user's Staging Sync Server to upload arbitrary data to path relative locations.

Operator check

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Read brief →
Apr 20, 2026 KEV Known exploited CVE-2023-27351

PaperCut NG/MF Improper Authentication Vulnerability

PaperCut · NG/MF

PaperCut NG/MF contains an improper authentication vulnerability that could allow remote attackers to bypass authentication on affected installations via the SecurityRequestFilter class.

Operator check

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Read brief →
Apr 20, 2026 KEV Known exploited CVE-2025-32975

Quest KACE Systems Management Appliance (SMA) Improper Authentication Vulnerability

Quest · KACE Systems Management Appliance (SMA)

Quest KACE Systems Management Appliance (SMA) contains an improper authentication vulnerability that could allow attackers to impersonate legitimate users without valid credentials.

Operator check

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Read brief →
Apr 20, 2026 KEV Known exploited CVE-2025-48700

Synacor Zimbra Collaboration Suite (ZCS) Cross-site Scripting Vulnerability

Synacor · Zimbra Collaboration Suite (ZCS)

Synacor Zimbra Collaboration Suite (ZCS) contains a cross-site scripting vulnerability that could allow attackers to execute arbitrary JavaScript within the user's session, potentially leading to unauthorized access to sensitive information.

Operator check

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Read brief →
Apr 14, 2026 KEV Known exploited CVE-2009-0238

Microsoft Office Remote Code Execution

Microsoft · Office

Microsoft Office Excel contains a remote code execution vulnerability that could allow an attacker to take complete control of an affected system if a user opens a specially crafted Excel file that includes a malformed object.

Operator check

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Read brief →
Apr 14, 2026 KEV Known exploited CVE-2026-32201

Microsoft SharePoint Server Improper Input Validation Vulnerability

Microsoft · SharePoint Server

Microsoft SharePoint Server contains an improper input validation vulnerability that allows an unauthorized attacker to perform spoofing over a network.

Operator check

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Read brief →
Apr 13, 2026 KEV Known exploited CVE-2026-21643

Fortinet FortiClient EMS SQL Injection Vulnerability

Fortinet · FortiClient EMS

Fortinet FortiClient EMS contains a SQL injection vulnerability that may allow an unauthenticated attacker to execute unauthorized code or commands via specifically crafted HTTP requests.

Operator check

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Read brief →
Apr 13, 2026 KEV Known exploited CVE-2012-1854

Microsoft Visual Basic for Applications Insecure Library Loading Vulnerability

Microsoft · Visual Basic for Applications (VBA)

Microsoft Visual Basic for Applications (VBA) contains an insecure library loading vulnerability that could allow for remote code execution.

Operator check

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Read brief →
Apr 13, 2026 KEV Known exploited CVE-2023-21529

Microsoft Exchange Server Deserialization of Untrusted Data Vulnerability

Microsoft · Exchange Server

Microsoft Exchange Server contains a deserialization of untrusted data that allows an authenticated attacker to achieve remote code execution.

Operator check

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Read brief →
Apr 13, 2026 KEV Known exploited CVE-2023-36424

Microsoft Windows Out-of-Bounds Read Vulnerability

Microsoft · Windows

Microsoft Windows Common Log File System Driver contains an out-of-bounds read vulnerability that could allow a threat actor for privileges escalation

Operator check

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Read brief →
Apr 8, 2026 KEV Known exploited CVE-2026-1340

Ivanti Endpoint Manager Mobile (EPMM) Code Injection Vulnerability

Ivanti · Endpoint Manager Mobile (EPMM)

Ivanti Endpoint Manager Mobile (EPMM) contains a code injection vulnerability that could allow attackers to achieve unauthenticated remote code execution.

Operator check

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Read brief →
Apr 6, 2026 KEV Known exploited CVE-2026-35616

Fortinet FortiClient EMS Improper Access Control Vulnerability

Fortinet · FortiClient EMS

Fortinet FortiClient EMS contains an improper access control vulnerability that may allow an unauthenticated attacker to execute unauthorized code or commands via crafted requests.

Operator check

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Read brief →
Apr 2, 2026 KEV Known exploited CVE-2026-3502

TrueConf Client Download of Code Without Integrity Check Vulnerability

TrueConf · Client

TrueConf Client contains a download of code without integrity check vulnerability. An attacker who is able to influence the update delivery path can substitute a tampered update payload. If the payload is executed or installed by the updater, this may result in arbitrary code execution in the context of the updating process or user.

Operator check

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Read brief →
Apr 1, 2026 KEV Known exploited CVE-2026-5281

Google Dawn Use-After-Free Vulnerability

Google · Dawn

Google Dawn contains an use-after-free vulnerability that could allow a remote attacker who had compromised the renderer process to execute arbitrary code via a crafted HTML page. This vulnerability could affect multiple Chromium-based products including, but not limited to, Google Chrome, Microsoft Edge, and Opera.

Operator check

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Read brief →
Mar 30, 2026 KEV Known exploited CVE-2026-3055

Citrix NetScaler Out-of-Bounds Read Vulnerability

Citrix · NetScaler

Citrix NetScaler ADC (formerly Citrix ADC), NetScaler Gateway (formerly Citrix Gateway) and NetScaler ADC FIPS and NDcPP contain an out-of-bounds reads vulnerability when configured as a SAML IDP leading to memory overread.

Operator check

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Read brief →
Mar 26, 2026 KEV Known exploited CVE-2026-33634

Aquasecurity Trivy Embedded Malicious Code Vulnerability

Aquasecurity · Trivy

Aquasecurity Trivy contains an embedded malicious code vulnerability that could allow an attacker to gain access to everything in the CI/CD environment, including all tokens, SSH keys, cloud credentials, database passwords, and any sensitive configuration in memory.

Operator check

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Read brief →
Mar 25, 2026 KEV Known exploited CVE-2026-33017

Langflow Code Injection Vulnerability

Langflow · Langflow

Langflow contains a code injection vulnerability that could allow building public flows without requiring authentication.

Operator check

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Read brief →
Mar 24, 2026 Vendor advisory Critical vendor advisory CVE-2026-33211

Linuxfoundation Tekton Pipelines — CVE-2026-33211 (Critical)

Linuxfoundation · Tekton Pipelines

Tekton Pipelines project provides k8s-style resources for declaring CI/CD-style pipelines. Starting in version 1.0.0 and prior to versions 1.0.1, 1.3.3, 1.6.1, 1.9.2, and 1.10.2, the Tekton Pipelines git resolver is vulnerable to path traversal via the `pathInRepo` parameter. A tenant with permission to create `ResolutionRequests` (e.g. by creating `TaskRuns` or `PipelineRuns` that use the git resolver) can read arbitrary files from the resolver pod's filesystem, including ServiceAccount tokens. The file contents are returned base64-encoded in `resolutionrequest.status.data`. Versions 1.0.1, 1

Operator check

Review CVE-2026-33211 in your asset inventory. Apply patches per vendor guidance and verify Tekton Pipelines is not exposed. CVSS score: 9.6.

Read brief →
Mar 24, 2026 Vendor advisory Critical vendor advisory CVE-2026-33854

Molotovcherry Android-Imagemagick7 — CVE-2026-33854 (Critical)

Molotovcherry · Android-Imagemagick7

Out-of-bounds Write vulnerability in MolotovCherry Android-ImageMagick7.This issue affects Android-ImageMagick7: before 7.1.2-10.

Operator check

Review CVE-2026-33854 in your asset inventory. Apply patches per vendor guidance and verify Android-Imagemagick7 is not exposed. CVSS score: 8.8.

Read brief →
Mar 24, 2026 Vendor advisory Critical vendor advisory CVE-2026-4688

Mozilla Firefox — CVE-2026-4688 (Critical)

Mozilla · Firefox

Sandbox escape due to use-after-free in the Disability Access APIs component. This vulnerability was fixed in Firefox 149, Firefox ESR 140.9, Thunderbird 149, and Thunderbird 140.9.

Operator check

Review CVE-2026-4688 in your asset inventory. Apply patches per vendor guidance and verify Firefox is not exposed. CVSS score: 10.0.

Read brief →
Mar 24, 2026 Vendor advisory Critical vendor advisory CVE-2026-4689

Mozilla Firefox — CVE-2026-4689 (Critical)

Mozilla · Firefox

Sandbox escape due to incorrect boundary conditions, integer overflow in the XPCOM component. This vulnerability was fixed in Firefox 149, Firefox ESR 115.34, Firefox ESR 140.9, Thunderbird 149, and Thunderbird 140.9.

Operator check

Review CVE-2026-4689 in your asset inventory. Apply patches per vendor guidance and verify Firefox is not exposed. CVSS score: 10.0.

Read brief →
Mar 24, 2026 Vendor advisory Critical vendor advisory CVE-2026-4691

Mozilla Firefox — CVE-2026-4691 (Critical)

Mozilla · Firefox

Use-after-free in the CSS Parsing and Computation component. This vulnerability was fixed in Firefox 149, Firefox ESR 115.34, Firefox ESR 140.9, Thunderbird 149, and Thunderbird 140.9.

Operator check

Review CVE-2026-4691 in your asset inventory. Apply patches per vendor guidance and verify Firefox is not exposed. CVSS score: 9.8.

Read brief →
Mar 24, 2026 Vendor advisory Critical vendor advisory CVE-2026-4692

Mozilla Firefox — CVE-2026-4692 (Critical)

Mozilla · Firefox

Sandbox escape in the Responsive Design Mode component. This vulnerability was fixed in Firefox 149, Firefox ESR 115.34, Firefox ESR 140.9, Thunderbird 149, and Thunderbird 140.9.

Operator check

Review CVE-2026-4692 in your asset inventory. Apply patches per vendor guidance and verify Firefox is not exposed. CVSS score: 10.0.

Read brief →
Mar 24, 2026 Vendor advisory Critical vendor advisory CVE-2026-4696

Mozilla Firefox — CVE-2026-4696 (Critical)

Mozilla · Firefox

Use-after-free in the Layout: Text and Fonts component. This vulnerability was fixed in Firefox 149, Firefox ESR 115.34, Firefox ESR 140.9, Thunderbird 149, and Thunderbird 140.9.

Operator check

Review CVE-2026-4696 in your asset inventory. Apply patches per vendor guidance and verify Firefox is not exposed. CVSS score: 9.8.

Read brief →
Mar 24, 2026 Vendor advisory Critical vendor advisory CVE-2026-4698

Mozilla Firefox — CVE-2026-4698 (Critical)

Mozilla · Firefox

JIT miscompilation in the JavaScript Engine: JIT component. This vulnerability was fixed in Firefox 149, Firefox ESR 115.34, Firefox ESR 140.9, Thunderbird 149, and Thunderbird 140.9.

Operator check

Review CVE-2026-4698 in your asset inventory. Apply patches per vendor guidance and verify Firefox is not exposed. CVSS score: 9.8.

Read brief →
Mar 24, 2026 Vendor advisory Critical vendor advisory CVE-2026-4700

Mozilla Firefox — CVE-2026-4700 (Critical)

Mozilla · Firefox

Mitigation bypass in the Networking: HTTP component. This vulnerability was fixed in Firefox 149, Firefox ESR 140.9, Thunderbird 149, and Thunderbird 140.9.

Operator check

Review CVE-2026-4700 in your asset inventory. Apply patches per vendor guidance and verify Firefox is not exposed. CVSS score: 9.8.

Read brief →
Mar 24, 2026 Vendor advisory Critical vendor advisory CVE-2026-4701

Mozilla Firefox — CVE-2026-4701 (Critical)

Mozilla · Firefox

Use-after-free in the JavaScript Engine component. This vulnerability was fixed in Firefox 149, Firefox ESR 140.9, Thunderbird 149, and Thunderbird 140.9.

Operator check

Review CVE-2026-4701 in your asset inventory. Apply patches per vendor guidance and verify Firefox is not exposed. CVSS score: 9.8.

Read brief →
Mar 24, 2026 Vendor advisory Critical vendor advisory CVE-2026-4702

Mozilla Firefox — CVE-2026-4702 (Critical)

Mozilla · Firefox

JIT miscompilation in the JavaScript Engine component. This vulnerability was fixed in Firefox 149, Firefox ESR 140.9, Thunderbird 149, and Thunderbird 140.9.

Operator check

Review CVE-2026-4702 in your asset inventory. Apply patches per vendor guidance and verify Firefox is not exposed. CVSS score: 9.8.

Read brief →
Mar 24, 2026 Vendor advisory Critical vendor advisory CVE-2026-4705

Mozilla Firefox — CVE-2026-4705 (Critical)

Mozilla · Firefox

Undefined behavior in the WebRTC: Signaling component. This vulnerability was fixed in Firefox 149, Firefox ESR 140.9, Thunderbird 149, and Thunderbird 140.9.

Operator check

Review CVE-2026-4705 in your asset inventory. Apply patches per vendor guidance and verify Firefox is not exposed. CVSS score: 9.8.

Read brief →
Mar 24, 2026 Vendor advisory Critical vendor advisory CVE-2026-33195

Rubyonrails Rails — CVE-2026-33195 (Critical)

Rubyonrails · Rails

Active Storage allows users to attach cloud and local files in Rails applications. Prior to versions 8.1.2.1, 8.0.4.1, and 7.2.3.1, Active Storage's `DiskService#path_for` does not validate that the resolved filesystem path remains within the storage root directory. If a blob key containing path traversal sequences (e.g. `../`) is used, it could allow reading, writing, or deleting arbitrary files on the server. Blob keys are expected to be trusted strings, but some applications could be passing user input as keys and would be affected. Versions 8.1.2.1, 8.0.4.1, and 7.2.3.1 contain a patch.

Operator check

Review CVE-2026-33195 in your asset inventory. Apply patches per vendor guidance and verify Rails is not exposed. CVSS score: 9.8.

Read brief →
Mar 24, 2026 Vendor advisory Critical vendor advisory CVE-2026-33202

Rubyonrails Rails — CVE-2026-33202 (Critical)

Rubyonrails · Rails

Active Storage allows users to attach cloud and local files in Rails applications. Prior to versions 8.1.2.1, 8.0.4.1, and 7.2.3.1, Active Storage's `DiskService#delete_prefixed` passes blob keys directly to `Dir.glob` without escaping glob metacharacters. If a blob key contains attacker-controlled input or custom-generated keys with glob metacharacters, it may be possible to delete unintended files from the storage directory. Versions 8.1.2.1, 8.0.4.1, and 7.2.3.1 contain a patch.

Operator check

Review CVE-2026-33202 in your asset inventory. Apply patches per vendor guidance and verify Rails is not exposed. CVSS score: 9.1.

Read brief →
Mar 23, 2026 Vendor advisory Critical vendor advisory CVE-2026-4579

Code-Projects Simple Laundry System — CVE-2026-4579 (Critical)

Code-Projects · Simple Laundry System

A vulnerability was identified in code-projects Simple Laundry System 1.0. The issue affects /viewdetail.php in the Parameters Handler component. The manipulation of the argument serviceId leads to sql injection. Remote exploitation of the attack is possible. The exploit is publicly available and might be used.

Operator check

Review CVE-2026-4579 in your asset inventory. Apply patches per vendor guidance and verify Simple Laundry System is not exposed. CVSS score: 7.3.

Read brief →
Mar 23, 2026 Vendor advisory Critical vendor advisory CVE-2026-4580

Code-Projects Simple Laundry System — CVE-2026-4580 (Critical)

Code-Projects · Simple Laundry System

A security flaw has been discovered in code-projects Simple Laundry System 1.0. The issue affects /checkupdatestatus.php in the Parameters Handler component. The manipulation of the argument serviceId results in sql injection. The attack can be executed remotely. The exploit has been released to the public and may be used for attacks.

Operator check

Review CVE-2026-4580 in your asset inventory. Apply patches per vendor guidance and verify Simple Laundry System is not exposed. CVSS score: 7.3.

Read brief →
Mar 23, 2026 Vendor advisory Critical vendor advisory CVE-2026-4581

Code-Projects Simple Laundry System — CVE-2026-4581 (Critical)

Code-Projects · Simple Laundry System

A weakness has been identified in code-projects Simple Laundry System 1.0. The issue affects /checklogin.php in the Parameters Handler component. This manipulation of the argument Username causes sql injection. The attack is possible to be carried out remotely. The exploit has been made available to the public and could be used for attacks.

Operator check

Review CVE-2026-4581 in your asset inventory. Apply patches per vendor guidance and verify Simple Laundry System is not exposed. CVSS score: 7.3.

Read brief →
Mar 23, 2026 Vendor advisory Critical vendor advisory CVE-2026-4600

Jsrsasign Project Jsrsasign — CVE-2026-4600 (Critical)

Jsrsasign Project · Jsrsasign

Versions of the package jsrsasign before 11.1.1 are vulnerable to Improper Verification of Cryptographic Signature via the DSA domain-parameter validation in KJUR.crypto.DSA.setPublic (and the related DSA/X509 verification flow in src/dsa-2.0.js). An attacker can forge DSA signatures or X.509 certificates that X509.verifySignature() accepts by supplying malicious domain parameters such as g=1, y=1, and a fixed r=1, which make the verification equation true for any hash.

Operator check

Review CVE-2026-4600 in your asset inventory. Apply patches per vendor guidance and verify Jsrsasign is not exposed. CVSS score: 7.4.

Read brief →
Mar 23, 2026 Vendor advisory Critical vendor advisory CVE-2026-4601

Jsrsasign Project Jsrsasign — CVE-2026-4601 (Critical)

Jsrsasign Project · Jsrsasign

Versions of the package jsrsasign before 11.1.1 are vulnerable to Missing Cryptographic Step via the KJUR.crypto.DSA.signWithMessageHash process in the DSA signing implementation. An attacker can recover the private key by forcing r or s to be zero, so the library emits an invalid signature without retrying, and then solves for x from the resulting signature.

Operator check

Review CVE-2026-4601 in your asset inventory. Apply patches per vendor guidance and verify Jsrsasign is not exposed. CVSS score: 8.7.

Read brief →
Mar 23, 2026 Vendor advisory Critical vendor advisory CVE-2026-30849

Mantisbt Mantisbt — CVE-2026-30849 (Critical)

Mantisbt · Mantisbt

Mantis Bug Tracker (MantisBT) is an open source issue tracker. Versions prior to 2.28.1 running on MySQL family databases are affected by an authentication bypass vulnerability in the SOAP API, as a result of an improper type checking on the password parameter. Other database backends are not affected, as they do not perform implicit type conversion from string to integer. Using a crafted SOAP envelope, an attacker knowing the victim's username is able to login to the SOAP API with their account without knowledge of the actual password, and execute any API function they have access to. Version

Operator check

Review CVE-2026-30849 in your asset inventory. Apply patches per vendor guidance and verify Mantisbt is not exposed. CVSS score: 9.8.

Read brief →
Mar 23, 2026 Vendor advisory Critical vendor advisory CVE-2026-31848

Nexxtsolutions Nebula300Plus Firmware — CVE-2026-31848 (Critical)

Nexxtsolutions · Nebula300Plus Firmware

Nexxt Solutions Nebula 300+ firmware through version 12.01.01.37 uses the ecos_pw cookie for authentication, which contains Base64-encoded credential data combined with a static suffix. Because the encoding is reversible and lacks integrity protection, an attacker can reconstruct or forge a valid cookie value without proper authentication. This allows unauthorized administrative access to protected endpoints.

Operator check

Review CVE-2026-31848 in your asset inventory. Apply patches per vendor guidance and verify Nebula300Plus Firmware is not exposed. CVSS score: 9.8.

Read brief →
Mar 23, 2026 Vendor advisory Critical vendor advisory CVE-2026-31851

Nexxtsolutions Nebula300Plus Firmware — CVE-2026-31851 (Critical)

Nexxtsolutions · Nebula300Plus Firmware

Nexxt Solutions Nebula 300+ firmware through version 12.01.01.37 does not implement rate limiting or account lockout mechanisms on authentication interfaces. An attacker can perform unlimited authentication attempts against endpoints that rely on credential validation, enabling brute-force attacks to guess administrative credentials without restriction.

Operator check

Review CVE-2026-31851 in your asset inventory. Apply patches per vendor guidance and verify Nebula300Plus Firmware is not exposed. CVSS score: 9.8.

Read brief →
Mar 23, 2026 Vendor advisory Critical vendor advisory CVE-2026-32913

Openclaw Openclaw — CVE-2026-32913 (Critical)

Openclaw · Openclaw

OpenClaw before 2026.3.7 contains an improper header validation vulnerability in fetchWithSsrFGuard that forwards custom authorization headers across cross-origin redirects. Attackers can trigger redirects to different origins to intercept sensitive headers like X-Api-Key and Private-Token intended for the original destination.

Operator check

Review CVE-2026-32913 in your asset inventory. Apply patches per vendor guidance and verify Openclaw is not exposed. CVSS score: 9.3.

Read brief →
Mar 23, 2026 Vendor advisory Critical vendor advisory CVE-2026-33297

Wwbn Avideo — CVE-2026-33297 (Critical)

Wwbn · Avideo

WWBN AVideo is an open source video platform. Prior to version 26.0, the `setPassword.json.php` endpoint in the CustomizeUser plugin allows administrators to set a channel password for any user. Due to a logic error in how the submitted password value is processed, any password containing non-numeric characters is silently coerced to the integer zero before being stored. This means that regardless of the intended password, the stored channel password becomes 0, which any visitor can trivially guess to bypass channel-level access control. Version 26.0 contains a patch for the issue.

Operator check

Review CVE-2026-33297 in your asset inventory. Apply patches per vendor guidance and verify Avideo is not exposed. CVSS score: 9.1.

Read brief →
No briefs match this filter.

Free

Get the weekly signal by email.

The exploited CVEs, critical advisories, and open-source security items most worth reviewing.

Pro — $9/mo

Daily delivery + watched-vendor alerts.

Get the right briefs delivered when vendors or packages you care about appear in the pipeline.

Upgrade to Pro →