<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0">
  <channel>
    <title>PatchBrief</title>
    <link>https://www.patchbrief.org/feed.html</link>
    <description>Short operator-ready briefs on public vulnerability advisories, known exploited vulnerabilities, vendor updates, and threat activity.</description>
    <lastBuildDate>Mon, 17 Aug 2026 10:27:02 +0000</lastBuildDate>
    <language>en</language>
    <item>
      <title>Grav: Unauthenticated denial of service via unbounded image derivative dimensions</title>
      <link>https://www.patchbrief.org/items/2026-08-composer-cve-2026-53653.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-08-composer-cve-2026-53653.html</guid>
      <pubDate>Fri, 14 Aug 2026 00:00:00 +0000</pubDate>
      <description>Grav: Unauthenticated denial of service via unbounded image derivative dimensions</description>
    </item>
    <item>
      <title>Authorizer: Zero-click account takeover via OAuth identity linking to unverified email accounts</title>
      <link>https://www.patchbrief.org/items/2026-08-go-cve-2026-35511.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-08-go-cve-2026-35511.html</guid>
      <pubDate>Fri, 14 Aug 2026 00:00:00 +0000</pubDate>
      <description>Authorizer: Zero-click account takeover via OAuth identity linking to unverified email accounts</description>
    </item>
    <item>
      <title>Lima: An arbitrary user in a QEMU VM could gain the root privilege in the VM via the guest agent socket</title>
      <link>https://www.patchbrief.org/items/2026-08-go-cve-2026-53657.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-08-go-cve-2026-53657.html</guid>
      <pubDate>Fri, 14 Aug 2026 00:00:00 +0000</pubDate>
      <description>Lima: An arbitrary user in a QEMU VM could gain the root privilege in the VM via the guest agent socket</description>
    </item>
    <item>
      <title>OpenAM Insecure SSO Cookie Initialization</title>
      <link>https://www.patchbrief.org/items/2026-08-maven-cve-2026-53660.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-08-maven-cve-2026-53660.html</guid>
      <pubDate>Fri, 14 Aug 2026 00:00:00 +0000</pubDate>
      <description>OpenAM Insecure SSO Cookie Initialization</description>
    </item>
    <item>
      <title>mchange-commons-java contains elements susceptible to abuse via JNDI injection and "deserialization gadgets"</title>
      <link>https://www.patchbrief.org/items/2026-08-maven-cve-2026-55153.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-08-maven-cve-2026-55153.html</guid>
      <pubDate>Fri, 14 Aug 2026 00:00:00 +0000</pubDate>
      <description>mchange-commons-java contains elements susceptible to abuse via JNDI injection and "deserialization gadgets"</description>
    </item>
    <item>
      <title>MindsDB Minds Platform version 26.1.0 and earlier — CVE-2026-73678 (Critical)</title>
      <link>https://www.patchbrief.org/items/2026-08-mindsdb-cve-2026-73678.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-08-mindsdb-cve-2026-73678.html</guid>
      <pubDate>Fri, 14 Aug 2026 00:00:00 +0000</pubDate>
      <description>MindsDB Minds Platform version 26.1.0 and earlier contains an unauthenticated remote code execution vulnerability that allows unauthenticated attackers to execute arbitrary OS commands by submitting crafted prompts to the unprotected POST /api/v1/responses/ endpoint, which reaches the Anton agent's scratchpad tool that calls exec() on attacker-influenced Python source without sandboxing. Attackers can first configure their own LLM API key through the unauthenticated PUT /api/v1/settings/ endpoint, then POST a prompt directing the agent to invoke the scratchpad tool with arbitrary Python code,</description>
    </item>
    <item>
      <title>Budibase: SSRF in Automation Steps - Webhook, Zapier, N8N, Slack, Discord Bypass IP Blacklist</title>
      <link>https://www.patchbrief.org/items/2026-08-npm-cve-2026-35219.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-08-npm-cve-2026-35219.html</guid>
      <pubDate>Fri, 14 Aug 2026 00:00:00 +0000</pubDate>
      <description>Budibase: SSRF in Automation Steps - Webhook, Zapier, N8N, Slack, Discord Bypass IP Blacklist</description>
    </item>
    <item>
      <title>Token Optimizer MCP: OS command injection in smart_user via username in get-user-info</title>
      <link>https://www.patchbrief.org/items/2026-08-npm-cve-2026-55157.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-08-npm-cve-2026-55157.html</guid>
      <pubDate>Fri, 14 Aug 2026 00:00:00 +0000</pubDate>
      <description>Token Optimizer MCP: OS command injection in smart_user via username in get-user-info</description>
    </item>
    <item>
      <title>Pimcore: ClassDefinition UID regex missing end anchor allows SQL injection via Block.php unquoted table name</title>
      <link>https://www.patchbrief.org/items/2026-08-composer-cve-2026-55072.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-08-composer-cve-2026-55072.html</guid>
      <pubDate>Thu, 13 Aug 2026 00:00:00 +0000</pubDate>
      <description>Pimcore: ClassDefinition UID regex missing end anchor allows SQL injection via Block.php unquoted table name</description>
    </item>
    <item>
      <title>Fluent Forms Pro 6.2.7 — CVE-2026-73532 (Critical)</title>
      <link>https://www.patchbrief.org/items/2026-08-fluent-cve-2026-73532.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-08-fluent-cve-2026-73532.html</guid>
      <pubDate>Thu, 13 Aug 2026 00:00:00 +0000</pubDate>
      <description>Fluent Forms Pro 6.2.7 contains an embedded malicious code vulnerability introduced via a tampered plugin build served through a decommissioned update server. The tampered build introduced a rogue PHP file (libs/class-license-sync.php), loaded via a require_once directive added to fluentformpro.php, that established a backdoor REST API endpoint, dropped persistent PHP files in mu-plugins and uploads directories, installed a passwordless administrator account, and registered scheduled tasks that survived plugin removal.</description>
    </item>
    <item>
      <title>Argo Workflows: ArtifactGC.PodSpecPatch bypasses Strict/Secure template reference allow-list (Incomplete fix for CVE-...</title>
      <link>https://www.patchbrief.org/items/2026-08-go-cve-2026-54526.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-08-go-cve-2026-54526.html</guid>
      <pubDate>Thu, 13 Aug 2026 00:00:00 +0000</pubDate>
      <description>Argo Workflows: ArtifactGC.PodSpecPatch bypasses Strict/Secure template reference allow-list (Incomplete fix for CVE-2026-31892)</description>
    </item>
    <item>
      <title>Ninja Tables Pro 5.2.11 — CVE-2026-73533 (Critical)</title>
      <link>https://www.patchbrief.org/items/2026-08-ninja-cve-2026-73533.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-08-ninja-cve-2026-73533.html</guid>
      <pubDate>Thu, 13 Aug 2026 00:00:00 +0000</pubDate>
      <description>Ninja Tables Pro 5.2.11 contains an embedded malicious code vulnerability introduced via a tampered plugin build served through a decommissioned update server. The tampered build introduced a rogue PHP file (app/Library/updater/NinjaTableDataSync.php) that established a backdoor REST API endpoint, dropped persistent PHP files in mu-plugins and uploads directories, installed a passwordless administrator account, and registered scheduled tasks that survived plugin removal.</description>
    </item>
    <item>
      <title>Trigger.dev: Prototype pollution via run metadata operations → process-wide cross-tenant DoS</title>
      <link>https://www.patchbrief.org/items/2026-08-npm-cve-2026-73654.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-08-npm-cve-2026-73654.html</guid>
      <pubDate>Thu, 13 Aug 2026 00:00:00 +0000</pubDate>
      <description>Trigger.dev: Prototype pollution via run metadata operations → process-wide cross-tenant DoS</description>
    </item>
    <item>
      <title>nltk: Arbitrary File Read via Path Traversal in nltk.data.load() through Percent-Encoded Sequences</title>
      <link>https://www.patchbrief.org/items/2026-08-pypi-cve-2026-12243.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-08-pypi-cve-2026-12243.html</guid>
      <pubDate>Thu, 13 Aug 2026 00:00:00 +0000</pubDate>
      <description>nltk: Arbitrary File Read via Path Traversal in nltk.data.load() through Percent-Encoded Sequences</description>
    </item>
    <item>
      <title>atomic-agents-stack: Dashboard HTTP server path traversal allows arbitrary file read</title>
      <link>https://www.patchbrief.org/items/2026-08-pypi-ghsa-rm43-82j9-r4mj.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-08-pypi-ghsa-rm43-82j9-r4mj.html</guid>
      <pubDate>Thu, 13 Aug 2026 00:00:00 +0000</pubDate>
      <description>atomic-agents-stack: Dashboard HTTP server path traversal allows arbitrary file read</description>
    </item>
    <item>
      <title>Winter: Stored XSS through Brand Settings custom styles</title>
      <link>https://www.patchbrief.org/items/2026-08-composer-cve-2026-32257.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-08-composer-cve-2026-32257.html</guid>
      <pubDate>Wed, 12 Aug 2026 00:00:00 +0000</pubDate>
      <description>Winter: Stored XSS through Brand Settings custom styles</description>
    </item>
    <item>
      <title>Winter: Stored XSS through Editor Settings custom styles</title>
      <link>https://www.patchbrief.org/items/2026-08-composer-cve-2026-32258.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-08-composer-cve-2026-32258.html</guid>
      <pubDate>Wed, 12 Aug 2026 00:00:00 +0000</pubDate>
      <description>Winter: Stored XSS through Editor Settings custom styles</description>
    </item>
    <item>
      <title>Winter: Authenticated backend users can bypass Users controller permission checks</title>
      <link>https://www.patchbrief.org/items/2026-08-composer-cve-2026-35445.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-08-composer-cve-2026-35445.html</guid>
      <pubDate>Wed, 12 Aug 2026 00:00:00 +0000</pubDate>
      <description>Winter: Authenticated backend users can bypass Users controller permission checks</description>
    </item>
    <item>
      <title>SeaweedFS: Path traversal in the S3 and Iceberg REST gateways allows cross-bucket access</title>
      <link>https://www.patchbrief.org/items/2026-08-go-cve-2026-54917.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-08-go-cve-2026-54917.html</guid>
      <pubDate>Wed, 12 Aug 2026 00:00:00 +0000</pubDate>
      <description>SeaweedFS: Path traversal in the S3 and Iceberg REST gateways allows cross-bucket access</description>
    </item>
    <item>
      <title>Ibm I — CVE-2026-16860 (Critical)</title>
      <link>https://www.patchbrief.org/items/2026-08-ibm-cve-2026-16860.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-08-ibm-cve-2026-16860.html</guid>
      <pubDate>Wed, 12 Aug 2026 00:00:00 +0000</pubDate>
      <description>IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to execute arbitrary code due to an uncontrolled search path element.</description>
    </item>
    <item>
      <title>Ibm I — CVE-2026-17276 (Critical)</title>
      <link>https://www.patchbrief.org/items/2026-08-ibm-cve-2026-17276.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-08-ibm-cve-2026-17276.html</guid>
      <pubDate>Wed, 12 Aug 2026 00:00:00 +0000</pubDate>
      <description>IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to escalate privileges due to improper authorization in the handling of high-authority threads.</description>
    </item>
    <item>
      <title>SSH.NET: ScpClient Recursive Download Allows Arbitrary File Write via Server-Controlled SCP Filenames</title>
      <link>https://www.patchbrief.org/items/2026-08-nuget-cve-2026-48798.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-08-nuget-cve-2026-48798.html</guid>
      <pubDate>Wed, 12 Aug 2026 00:00:00 +0000</pubDate>
      <description>SSH.NET: ScpClient Recursive Download Allows Arbitrary File Write via Server-Controlled SCP Filenames</description>
    </item>
    <item>
      <title>SIPSorcery vulnerable to Denial of Service via out-of-bounds read in SCTP SACK chunk parsing</title>
      <link>https://www.patchbrief.org/items/2026-08-nuget-ghsa-jwjp-4649-v8jp.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-08-nuget-ghsa-jwjp-4649-v8jp.html</guid>
      <pubDate>Wed, 12 Aug 2026 00:00:00 +0000</pubDate>
      <description>SIPSorcery vulnerable to Denial of Service via out-of-bounds read in SCTP SACK chunk parsing</description>
    </item>
    <item>
      <title>SIPSorcery: Malformed UDP datagram crashes TurnServer receive loop with no restart, disabling TURN UDP relay for all ...</title>
      <link>https://www.patchbrief.org/items/2026-08-nuget-ghsa-pfvm-w89x-94jw.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-08-nuget-ghsa-pfvm-w89x-94jw.html</guid>
      <pubDate>Wed, 12 Aug 2026 00:00:00 +0000</pubDate>
      <description>SIPSorcery: Malformed UDP datagram crashes TurnServer receive loop with no restart, disabling TURN UDP relay for all clients (DoS)</description>
    </item>
    <item>
      <title>compliance-trestle has an URLSecurityValidator SSRF allowlist bypass via IPv4-mapped IPv6 and 0.0.0.0</title>
      <link>https://www.patchbrief.org/items/2026-08-pypi-cve-2026-52776.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-08-pypi-cve-2026-52776.html</guid>
      <pubDate>Wed, 12 Aug 2026 00:00:00 +0000</pubDate>
      <description>compliance-trestle has an URLSecurityValidator SSRF allowlist bypass via IPv4-mapped IPv6 and 0.0.0.0</description>
    </item>
    <item>
      <title>MCP-for-Stata: Stata Command Injection via Unsanitized `package` in `ado_package_install`</title>
      <link>https://www.patchbrief.org/items/2026-08-pypi-cve-2026-55071.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-08-pypi-cve-2026-55071.html</guid>
      <pubDate>Wed, 12 Aug 2026 00:00:00 +0000</pubDate>
      <description>MCP-for-Stata: Stata Command Injection via Unsanitized `package` in `ado_package_install`</description>
    </item>
    <item>
      <title>Ansible FreeBSD Jail Connection Plugin: Jail escape via symlink following in put_file (host-side root mv)</title>
      <link>https://www.patchbrief.org/items/2026-08-pypi-cve-2026-55074.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-08-pypi-cve-2026-55074.html</guid>
      <pubDate>Wed, 12 Aug 2026 00:00:00 +0000</pubDate>
      <description>Ansible FreeBSD Jail Connection Plugin: Jail escape via symlink following in put_file (host-side root mv)</description>
    </item>
    <item>
      <title>nimiq-blockchain: Validity store off by one error</title>
      <link>https://www.patchbrief.org/items/2026-08-rust-cve-2026-46369.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-08-rust-cve-2026-46369.html</guid>
      <pubDate>Wed, 12 Aug 2026 00:00:00 +0000</pubDate>
      <description>nimiq-blockchain: Validity store off by one error</description>
    </item>
    <item>
      <title>Cisco Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD) Heap Inspection Vuln...</title>
      <link>https://www.patchbrief.org/items/2026-08-cisco-cve-2026-20349.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-08-cisco-cve-2026-20349.html</guid>
      <pubDate>Tue, 11 Aug 2026 00:00:00 +0000</pubDate>
      <description>Cisco Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD) contain a heap inspection vulnerability that could allow an unauthenticated, remote attacker to cause the device to reload unexpectedly, resulting in a denial of service (DoS) condition.</description>
    </item>
    <item>
      <title>SeaweedFS: Unauthenticated SSRF with response read-back via VolumeServer.FetchAndWriteNeedle</title>
      <link>https://www.patchbrief.org/items/2026-08-go-cve-2026-73080.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-08-go-cve-2026-73080.html</guid>
      <pubDate>Tue, 11 Aug 2026 00:00:00 +0000</pubDate>
      <description>SeaweedFS: Unauthenticated SSRF with response read-back via VolumeServer.FetchAndWriteNeedle</description>
    </item>
    <item>
      <title>Metabase SQL Injection Vulnerability</title>
      <link>https://www.patchbrief.org/items/2026-08-metabase-cve-2026-72898.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-08-metabase-cve-2026-72898.html</guid>
      <pubDate>Tue, 11 Aug 2026 00:00:00 +0000</pubDate>
      <description>Metabase contains a SQL Injection vulnerability that allows an unauthenticated remote attacker to inject arbitrary SQL into the Metabase application database, which can give them administrator access to the instance. From there, the attacker could change the application configuration, steal stored credentials for the connected databases, read any data accessible through those connections, and export data.</description>
    </item>
    <item>
      <title>Windows Active Directory Domain Services Remote Code Execution Vulnerability</title>
      <link>https://www.patchbrief.org/items/2026-08-microsoft-cve-2026-49179.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-08-microsoft-cve-2026-49179.html</guid>
      <pubDate>Tue, 11 Aug 2026 00:00:00 +0000</pubDate>
      <description>Improper neutralization of special elements used in a command ('command injection') in Windows Active Directory allows an unauthorized attacker to execute code over a network. Published in August 2026 Security Updates. MSRC exploitability: Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation Unlikely.</description>
    </item>
    <item>
      <title>Visual Studio Code Security Feature Bypass Vulnerability</title>
      <link>https://www.patchbrief.org/items/2026-08-microsoft-cve-2026-58650.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-08-microsoft-cve-2026-58650.html</guid>
      <pubDate>Tue, 11 Aug 2026 00:00:00 +0000</pubDate>
      <description>Authorization bypass through user-controlled key in Visual Studio Code allows an unauthorized attacker to bypass a security feature locally. Published in August 2026 Security Updates. MSRC exploitability: Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation More Likely.</description>
    </item>
    <item>
      <title>Visual Studio Code Remote Code Execution Vulnerability</title>
      <link>https://www.patchbrief.org/items/2026-08-microsoft-cve-2026-59113.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-08-microsoft-cve-2026-59113.html</guid>
      <pubDate>Tue, 11 Aug 2026 00:00:00 +0000</pubDate>
      <description>Missing authorization in Visual Studio Code allows an unauthorized attacker to execute code over a network. Published in August 2026 Security Updates. MSRC exploitability: Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation Less Likely.</description>
    </item>
    <item>
      <title>Microsoft High Performance Computing (HPC) Pack Remote Code Execution Vulnerability</title>
      <link>https://www.patchbrief.org/items/2026-08-microsoft-cve-2026-59124.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-08-microsoft-cve-2026-59124.html</guid>
      <pubDate>Tue, 11 Aug 2026 00:00:00 +0000</pubDate>
      <description>Deserialization of untrusted data in Microsoft High Performance Computing (HPC) Pack allows an unauthorized attacker to execute code over a network. Published in August 2026 Security Updates. MSRC exploitability: Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation More Likely.</description>
    </item>
    <item>
      <title>Windows TCP/IP Denial of Service Vulnerability</title>
      <link>https://www.patchbrief.org/items/2026-08-microsoft-cve-2026-59132.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-08-microsoft-cve-2026-59132.html</guid>
      <pubDate>Tue, 11 Aug 2026 00:00:00 +0000</pubDate>
      <description>Null pointer dereference in Windows TCP/IP allows an unauthorized attacker to deny service over a network. Published in August 2026 Security Updates. MSRC exploitability: Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation More Likely.</description>
    </item>
    <item>
      <title>Microsoft High Performance Computing (HPC) Pack Elevation of Privilege Vulnerability</title>
      <link>https://www.patchbrief.org/items/2026-08-microsoft-cve-2026-59133.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-08-microsoft-cve-2026-59133.html</guid>
      <pubDate>Tue, 11 Aug 2026 00:00:00 +0000</pubDate>
      <description>Execution with unnecessary privileges in Microsoft High Performance Computing (HPC) Pack allows an authorized attacker to elevate privileges over a network. Published in August 2026 Security Updates. MSRC exploitability: Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation More Likely.</description>
    </item>
    <item>
      <title>Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability</title>
      <link>https://www.patchbrief.org/items/2026-08-microsoft-cve-2026-61348.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-08-microsoft-cve-2026-61348.html</guid>
      <pubDate>Tue, 11 Aug 2026 00:00:00 +0000</pubDate>
      <description>Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally. Published in August 2026 Security Updates. MSRC exploitability: Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation More Likely.</description>
    </item>
    <item>
      <title>Windows Installer Elevation of Privilege Vulnerability</title>
      <link>https://www.patchbrief.org/items/2026-08-microsoft-cve-2026-61925.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-08-microsoft-cve-2026-61925.html</guid>
      <pubDate>Tue, 11 Aug 2026 00:00:00 +0000</pubDate>
      <description>Incorrect authorization in Windows Installer allows an authorized attacker to elevate privileges locally. Published in August 2026 Security Updates. MSRC exploitability: Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation More Likely.</description>
    </item>
    <item>
      <title>Windows Kernel Elevation of Privilege Vulnerability</title>
      <link>https://www.patchbrief.org/items/2026-08-microsoft-cve-2026-61930.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-08-microsoft-cve-2026-61930.html</guid>
      <pubDate>Tue, 11 Aug 2026 00:00:00 +0000</pubDate>
      <description>Heap-based buffer overflow in Windows Kernel allows an authorized attacker to elevate privileges locally. Published in August 2026 Security Updates. MSRC exploitability: Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation More Likely.</description>
    </item>
    <item>
      <title>Windows MIDI Service Module Elevation of Privileges Vulnerability</title>
      <link>https://www.patchbrief.org/items/2026-08-microsoft-cve-2026-62688.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-08-microsoft-cve-2026-62688.html</guid>
      <pubDate>Tue, 11 Aug 2026 00:00:00 +0000</pubDate>
      <description>Heap-based buffer overflow in Windows MIDI Service Module allows an authorized attacker to elevate privileges locally. Published in August 2026 Security Updates. MSRC exploitability: Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation More Likely.</description>
    </item>
    <item>
      <title>Windows Program Compatibility Assistant Service Elevation of Privilege Vulnerability</title>
      <link>https://www.patchbrief.org/items/2026-08-microsoft-cve-2026-62696.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-08-microsoft-cve-2026-62696.html</guid>
      <pubDate>Tue, 11 Aug 2026 00:00:00 +0000</pubDate>
      <description>Integer underflow (wrap or wraparound) in Windows Program Compatibility Assistant Service allows an authorized attacker to elevate privileges locally. Published in August 2026 Security Updates. MSRC exploitability: Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation More Likely.</description>
    </item>
    <item>
      <title>Windows Win32k Elevation of Privilege Vulnerability</title>
      <link>https://www.patchbrief.org/items/2026-08-microsoft-cve-2026-62712.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-08-microsoft-cve-2026-62712.html</guid>
      <pubDate>Tue, 11 Aug 2026 00:00:00 +0000</pubDate>
      <description>Heap-based buffer overflow in Windows Win32K allows an authorized attacker to elevate privileges locally. Published in August 2026 Security Updates. MSRC exploitability: Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation More Likely.</description>
    </item>
    <item>
      <title>Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability</title>
      <link>https://www.patchbrief.org/items/2026-08-microsoft-cve-2026-62713.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-08-microsoft-cve-2026-62713.html</guid>
      <pubDate>Tue, 11 Aug 2026 00:00:00 +0000</pubDate>
      <description>Heap-based buffer overflow in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges locally. Published in August 2026 Security Updates. MSRC exploitability: Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation More Likely.</description>
    </item>
    <item>
      <title>Microsoft SharePoint Server Elevation of Privilege Vulnerability</title>
      <link>https://www.patchbrief.org/items/2026-08-microsoft-cve-2026-62827.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-08-microsoft-cve-2026-62827.html</guid>
      <pubDate>Tue, 11 Aug 2026 00:00:00 +0000</pubDate>
      <description>Improper authentication in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a network. Published in August 2026 Security Updates. MSRC exploitability: Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation Less Likely.</description>
    </item>
    <item>
      <title>Microsoft 365 Admin Center Elevation of Privilege Vulnerability</title>
      <link>https://www.patchbrief.org/items/2026-08-microsoft-cve-2026-62873.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-08-microsoft-cve-2026-62873.html</guid>
      <pubDate>Tue, 11 Aug 2026 00:00:00 +0000</pubDate>
      <description>Improper verification of cryptographic signature in Microsoft 365 Admin Center allows an unauthorized attacker to elevate privileges over a network. Published in August 2026 Security Updates. MSRC exploitability: Publicly Disclosed:No;Exploited:No;Latest Software Release:N/A.</description>
    </item>
    <item>
      <title>Microsoft Planetary Computer Pro Elevation of Privilege Vulnerability</title>
      <link>https://www.patchbrief.org/items/2026-08-microsoft-cve-2026-63508.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-08-microsoft-cve-2026-63508.html</guid>
      <pubDate>Tue, 11 Aug 2026 00:00:00 +0000</pubDate>
      <description>Missing authentication for critical function in Microsoft Planetary Computer Pro allows an unauthorized attacker to elevate privileges over a network. Published in August 2026 Security Updates. MSRC exploitability: Publicly Disclosed:No;Exploited:No;Latest Software Release:N/A.</description>
    </item>
    <item>
      <title>Microsoft SharePoint Server Remote Code Execution Vulnerability</title>
      <link>https://www.patchbrief.org/items/2026-08-microsoft-cve-2026-63514.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-08-microsoft-cve-2026-63514.html</guid>
      <pubDate>Tue, 11 Aug 2026 00:00:00 +0000</pubDate>
      <description>Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. Published in August 2026 Security Updates. MSRC exploitability: Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation Less Likely.</description>
    </item>
    <item>
      <title>Microsoft SharePoint Server Remote Code Execution Vulnerability</title>
      <link>https://www.patchbrief.org/items/2026-08-microsoft-cve-2026-63520.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-08-microsoft-cve-2026-63520.html</guid>
      <pubDate>Tue, 11 Aug 2026 00:00:00 +0000</pubDate>
      <description>Improper input validation in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network. Published in August 2026 Security Updates. MSRC exploitability: Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation More Likely.</description>
    </item>
    <item>
      <title>Microsoft Teams Remote Code Execution Vulnerability</title>
      <link>https://www.patchbrief.org/items/2026-08-microsoft-cve-2026-65768.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-08-microsoft-cve-2026-65768.html</guid>
      <pubDate>Tue, 11 Aug 2026 00:00:00 +0000</pubDate>
      <description>Improper limitation of a pathname to a restricted directory ('path traversal') in Microsoft Teams for Android allows an unauthorized attacker to execute code over a network. Published in August 2026 Security Updates. MSRC exploitability: Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation Less Likely.</description>
    </item>
    <item>
      <title>Microsoft Windows Ancillary Function Driver for WinSock Use-After-Free Vulnerability</title>
      <link>https://www.patchbrief.org/items/2026-08-microsoft-cve-2026-68820.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-08-microsoft-cve-2026-68820.html</guid>
      <pubDate>Tue, 11 Aug 2026 00:00:00 +0000</pubDate>
      <description>Microsoft Windows Ancillary Function Driver for WinSock contains a use-after-free vulnerability that allows an authorized attacker to elevate privileges locally.</description>
    </item>
    <item>
      <title>Microsoft Security Advisory CVE-2026-62871 – .NET Elevation of Privilege Vulnerability</title>
      <link>https://www.patchbrief.org/items/2026-08-nuget-cve-2026-62871.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-08-nuget-cve-2026-62871.html</guid>
      <pubDate>Tue, 11 Aug 2026 00:00:00 +0000</pubDate>
      <description>Microsoft Security Advisory CVE-2026-62871 – .NET Elevation of Privilege Vulnerability</description>
    </item>
    <item>
      <title>Microsoft Security Advisory CVE-2026-62886 – .NET Elevation of Privilege Vulnerability</title>
      <link>https://www.patchbrief.org/items/2026-08-nuget-cve-2026-62886.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-08-nuget-cve-2026-62886.html</guid>
      <pubDate>Tue, 11 Aug 2026 00:00:00 +0000</pubDate>
      <description>Microsoft Security Advisory CVE-2026-62886 – .NET Elevation of Privilege Vulnerability</description>
    </item>
    <item>
      <title>Microsoft Security Advisory CVE-2026-62897 – .NET Remote Code Execution Vulnerability</title>
      <link>https://www.patchbrief.org/items/2026-08-nuget-cve-2026-62897.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-08-nuget-cve-2026-62897.html</guid>
      <pubDate>Tue, 11 Aug 2026 00:00:00 +0000</pubDate>
      <description>Microsoft Security Advisory CVE-2026-62897 – .NET Remote Code Execution Vulnerability</description>
    </item>
    <item>
      <title>Microsoft Security Advisory CVE-2026-62898 – .NET Information Disclosure Vulnerability</title>
      <link>https://www.patchbrief.org/items/2026-08-nuget-cve-2026-62898.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-08-nuget-cve-2026-62898.html</guid>
      <pubDate>Tue, 11 Aug 2026 00:00:00 +0000</pubDate>
      <description>Microsoft Security Advisory CVE-2026-62898 – .NET Information Disclosure Vulnerability</description>
    </item>
    <item>
      <title>Microsoft Security Advisory CVE-2026-62901 – .NET Denial of Service Vulnerability</title>
      <link>https://www.patchbrief.org/items/2026-08-nuget-cve-2026-62901.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-08-nuget-cve-2026-62901.html</guid>
      <pubDate>Tue, 11 Aug 2026 00:00:00 +0000</pubDate>
      <description>Microsoft Security Advisory CVE-2026-62901 – .NET Denial of Service Vulnerability</description>
    </item>
    <item>
      <title>Microsoft Security Advisory CVE-2026-70354 – .NET Core Remote Code Execution Vulnerability</title>
      <link>https://www.patchbrief.org/items/2026-08-nuget-cve-2026-70354.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-08-nuget-cve-2026-70354.html</guid>
      <pubDate>Tue, 11 Aug 2026 00:00:00 +0000</pubDate>
      <description>Microsoft Security Advisory CVE-2026-70354 – .NET Core Remote Code Execution Vulnerability</description>
    </item>
    <item>
      <title>VU#431093: TCG TPM 2.0 reference code found vulnerable to information leakage and timing side-channel attacks</title>
      <link>https://www.patchbrief.org/items/2026-08-tcg-vu-431093.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-08-tcg-vu-431093.html</guid>
      <pubDate>Tue, 11 Aug 2026 00:00:00 +0000</pubDate>
      <description>Overview Two vulnerabilities have been identified in the Trusted Platform Module (TPM) 2.0 reference implementation: CVE-2026-6726 – Information leakage via falsified TPM keys. CVE-2026-6727 – A timing side-channel vulnerability in RSA OAEP decryption. An attacker with privileged access to a TPM command interface may be able to exploit these vulnerabilities by sending specially crafted TPM commands. Successful exploitation could allow the attacker to decrypt ciphertexts encrypted to affected TPM-managed RSA keys, including the RSA Endorsement Key (EK), or obtain credentials for falsified TPM keys, enabling forged TPM 2.0 attestations. These vulnerabilities are also documented by the Trusted Computing Group (TCG) in advisories - TCGVRT010 and TCGVRT0011 : Description Trusted Platform Module (TPM) technology provides hardware-backed... Related CVEs: CVE-2026-6726, CVE-2026-6727.</description>
    </item>
    <item>
      <title>VU#614868: Opencart ecommerce platform contains directory traversal vulnerability</title>
      <link>https://www.patchbrief.org/items/2026-08-opencart-vu-614868.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-08-opencart-vu-614868.html</guid>
      <pubDate>Mon, 10 Aug 2026 00:00:00 +0000</pubDate>
      <description>Overview The OpenCart v4.2.0.0 extension installer contains a directory traversal vulnerability. The extension installation process extracts uploaded .zip files then uses the zip entry filenames as filesystem paths, without validating that the resolved path stays inside the intended directory. This vulnerability is tracked as CVE-2026-18412. Description OpenCart is a free, open‑source e‑commerce solution designed to help businesses build and manage online stores. OpenCart extensions are uploaded as zip files with .ocmod.zip extensions. Upon installation, the OpenCart v4.2.0.0 extension installer extracts these zip files, but does not validate that the extracted paths stay inside the intended extraction directory. An attacker can craft a malicious extension containing file path traversal sequences, such as ../ . With this vulnerability... Related CVEs: CVE-2026-18412.</description>
    </item>
    <item>
      <title>MSI Radix AXE6600 router firmware version v781521 — CVE-2026-71984 (Critical)</title>
      <link>https://www.patchbrief.org/items/2026-08-msi-cve-2026-71984.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-08-msi-cve-2026-71984.html</guid>
      <pubDate>Sun, 09 Aug 2026 00:00:00 +0000</pubDate>
      <description>MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the urlfilter function that allows remote attackers to execute arbitrary commands on the affected device. Attackers can exploit the urlfilter function to inject malicious commands and obtain root privileges on the underlying system.</description>
    </item>
    <item>
      <title>MSI Radix AXE6600 router firmware version v781521 — CVE-2026-71985 (Critical)</title>
      <link>https://www.patchbrief.org/items/2026-08-msi-cve-2026-71985.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-08-msi-cve-2026-71985.html</guid>
      <pubDate>Sun, 09 Aug 2026 00:00:00 +0000</pubDate>
      <description>MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the accesscontrol function that allows remote attackers to execute arbitrary commands on the affected device. Attackers can exploit this vulnerability through the accesscontrol function to execute malicious commands and obtain root privileges on the underlying system.</description>
    </item>
    <item>
      <title>MSI Radix AXE6600 router firmware version v781521 — CVE-2026-71986 (Critical)</title>
      <link>https://www.patchbrief.org/items/2026-08-msi-cve-2026-71986.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-08-msi-cve-2026-71986.html</guid>
      <pubDate>Sun, 09 Aug 2026 00:00:00 +0000</pubDate>
      <description>MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the dmz function that allows remote attackers to execute arbitrary commands on the affected device. Attackers can exploit this vulnerability through the dmz function to execute malicious commands and obtain root privileges on the underlying system.</description>
    </item>
    <item>
      <title>MSI Radix AXE6600 router firmware version v781521 — CVE-2026-71987 (Critical)</title>
      <link>https://www.patchbrief.org/items/2026-08-msi-cve-2026-71987.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-08-msi-cve-2026-71987.html</guid>
      <pubDate>Sun, 09 Aug 2026 00:00:00 +0000</pubDate>
      <description>MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the alg function that allows remote attackers to execute arbitrary commands on the affected device. Attackers can exploit this vulnerability through the alg function to execute malicious commands and obtain root privileges on the underlying system.</description>
    </item>
    <item>
      <title>MSI Radix AXE6600 router firmware version v781521 — CVE-2026-71988 (Critical)</title>
      <link>https://www.patchbrief.org/items/2026-08-msi-cve-2026-71988.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-08-msi-cve-2026-71988.html</guid>
      <pubDate>Sun, 09 Aug 2026 00:00:00 +0000</pubDate>
      <description>MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the portFw function that allows remote attackers to execute arbitrary commands on the affected device. Attackers can exploit this vulnerability through the alg function to execute malicious commands and obtain root privileges on the underlying system.</description>
    </item>
    <item>
      <title>MSI Radix AXE6600 router firmware version v781521 — CVE-2026-71989 (Critical)</title>
      <link>https://www.patchbrief.org/items/2026-08-msi-cve-2026-71989.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-08-msi-cve-2026-71989.html</guid>
      <pubDate>Sun, 09 Aug 2026 00:00:00 +0000</pubDate>
      <description>MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the porTrigger function that allows remote attackers to execute arbitrary commands on the affected device. Attackers can exploit this vulnerability through the alg function to execute malicious commands and obtain root privileges on the underlying system.</description>
    </item>
    <item>
      <title>MSI Radix AXE6600 router firmware version v781521 — CVE-2026-71990 (Critical)</title>
      <link>https://www.patchbrief.org/items/2026-08-msi-cve-2026-71990.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-08-msi-cve-2026-71990.html</guid>
      <pubDate>Sun, 09 Aug 2026 00:00:00 +0000</pubDate>
      <description>MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the TelnetSSH function used for SSH configuration that allows remote attackers to execute arbitrary commands on the affected device. Attackers can exploit this vulnerability through the SSH configuration interface to inject malicious commands and obtain root privileges on the underlying system.</description>
    </item>
    <item>
      <title>MSI Radix AXE6600 router firmware version v781521 — CVE-2026-71991 (Critical)</title>
      <link>https://www.patchbrief.org/items/2026-08-msi-cve-2026-71991.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-08-msi-cve-2026-71991.html</guid>
      <pubDate>Sun, 09 Aug 2026 00:00:00 +0000</pubDate>
      <description>MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the TelnetSSH function used for Telnet configuration that allows remote attackers to execute arbitrary commands on the affected device. Attackers can exploit this vulnerability through the Telnet configuration interface to inject malicious commands and obtain root privileges on the underlying system.</description>
    </item>
    <item>
      <title>MSI Radix AXE6600 router firmware version v781521 — CVE-2026-71992 (Critical)</title>
      <link>https://www.patchbrief.org/items/2026-08-msi-cve-2026-71992.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-08-msi-cve-2026-71992.html</guid>
      <pubDate>Sun, 09 Aug 2026 00:00:00 +0000</pubDate>
      <description>MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the macfilter function that allows remote attackers to execute arbitrary commands on the affected device. Attackers can exploit the macfilter function to inject malicious commands and obtain root privileges on the underlying system.</description>
    </item>
    <item>
      <title>MSI Radix AXE6600 router firmware version v781521 — CVE-2026-71993 (Critical)</title>
      <link>https://www.patchbrief.org/items/2026-08-msi-cve-2026-71993.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-08-msi-cve-2026-71993.html</guid>
      <pubDate>Sun, 09 Aug 2026 00:00:00 +0000</pubDate>
      <description>MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the openvpn function that allows remote attackers to execute arbitrary commands on the affected device. Attackers can exploit the macfilter function to inject malicious commands and obtain root privileges on the underlying system.</description>
    </item>
    <item>
      <title>D-Link DWR-M961 devices with hardware version C1 and firmware — CVE-2026-71944 (Critical)</title>
      <link>https://www.patchbrief.org/items/2026-08-d-link-cve-2026-71944.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-08-d-link-cve-2026-71944.html</guid>
      <pubDate>Sat, 08 Aug 2026 00:00:00 +0000</pubDate>
      <description>D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injection vulnerability in the /boafrm/formLtefotaUpgradeQuectel interface. A remote attacker can inject arbitrary malicious commands into the fota_url field, resulting in command execution with root privileges.</description>
    </item>
    <item>
      <title>D-Link DWR-M961 devices with hardware version C1 and software — CVE-2026-71956 (Critical)</title>
      <link>https://www.patchbrief.org/items/2026-08-d-link-cve-2026-71956.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-08-d-link-cve-2026-71956.html</guid>
      <pubDate>Sat, 08 Aug 2026 00:00:00 +0000</pubDate>
      <description>D-Link DWR-M961 devices with hardware version C1 and software version 1.1.2_C1_202602110044 contain a command injection vulnerability in the app.cgi interface. A remote attacker can inject arbitrary malicious commands into the netDig.ping.dst field, resulting in command execution with root privileges.</description>
    </item>
    <item>
      <title>D-Link DWR-M961 devices with hardware version C1 and software — CVE-2026-71957 (Critical)</title>
      <link>https://www.patchbrief.org/items/2026-08-d-link-cve-2026-71957.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-08-d-link-cve-2026-71957.html</guid>
      <pubDate>Sat, 08 Aug 2026 00:00:00 +0000</pubDate>
      <description>D-Link DWR-M961 devices with hardware version C1 and software version 1.1.2_C1_202602110044 contain a buffer overflow vulnerability in the app.cgi interface. A remote attacker can write an overly long string to the netAcc.addlist[].name field and execute arbitrary commands by crafting a specific payload, or cause the device to crash.</description>
    </item>
    <item>
      <title>D-Link DWR-M961 devices with hardware version C1 and software — CVE-2026-71958 (Critical)</title>
      <link>https://www.patchbrief.org/items/2026-08-d-link-cve-2026-71958.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-08-d-link-cve-2026-71958.html</guid>
      <pubDate>Sat, 08 Aug 2026 00:00:00 +0000</pubDate>
      <description>D-Link DWR-M961 devices with hardware version C1 and software version 1.1.2_C1_202602110044 contain a buffer overflow vulnerability in the quicksetup.cgi interface. A remote attacker can write overly long strings to the test4, ssid2, and username fields and execute arbitrary commands by crafting a specific payload, or cause the device to crash.</description>
    </item>
    <item>
      <title>MSI Radix AXE6600 router firmware version v781521 — CVE-2026-71983 (Critical)</title>
      <link>https://www.patchbrief.org/items/2026-08-msi-cve-2026-71983.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-08-msi-cve-2026-71983.html</guid>
      <pubDate>Sat, 08 Aug 2026 00:00:00 +0000</pubDate>
      <description>MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the wps.cgi interface that allows remote attackers to execute arbitrary commands by injecting malicious input through the pin2g, pin5g, or pin6g parameters. Attackers can exploit these unsanitized parameters to execute arbitrary commands on the affected device and obtain root privileges.</description>
    </item>
    <item>
      <title>CodeIgniter: SQL injection in Query Builder deleteBatch() when used with where() conditions</title>
      <link>https://www.patchbrief.org/items/2026-08-composer-cve-2026-63221.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-08-composer-cve-2026-63221.html</guid>
      <pubDate>Fri, 07 Aug 2026 00:00:00 +0000</pubDate>
      <description>CodeIgniter: SQL injection in Query Builder deleteBatch() when used with where() conditions</description>
    </item>
    <item>
      <title>CodeIgniter: Path traversal in UploadedFile::move() when using client-provided filenames</title>
      <link>https://www.patchbrief.org/items/2026-08-composer-cve-2026-63222.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-08-composer-cve-2026-63222.html</guid>
      <pubDate>Fri, 07 Aug 2026 00:00:00 +0000</pubDate>
      <description>CodeIgniter: Path traversal in UploadedFile::move() when using client-provided filenames</description>
    </item>
    <item>
      <title>CodeIgniter: Uploaded file extension validation bypass in `is_image` and `mime_in` rules</title>
      <link>https://www.patchbrief.org/items/2026-08-composer-cve-2026-63223.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-08-composer-cve-2026-63223.html</guid>
      <pubDate>Fri, 07 Aug 2026 00:00:00 +0000</pubDate>
      <description>CodeIgniter: Uploaded file extension validation bypass in `is_image` and `mime_in` rules</description>
    </item>
    <item>
      <title>Craft CMS: Passkey login accepts replayed WebAuthn assertions</title>
      <link>https://www.patchbrief.org/items/2026-08-composer-ghsa-wg23-69c2-gjc8.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-08-composer-ghsa-wg23-69c2-gjc8.html</guid>
      <pubDate>Fri, 07 Aug 2026 00:00:00 +0000</pubDate>
      <description>Craft CMS: Passkey login accepts replayed WebAuthn assertions</description>
    </item>
    <item>
      <title>Dell Openmanage Server Administrator — CVE-2026-56793 (Critical)</title>
      <link>https://www.patchbrief.org/items/2026-08-dell-cve-2026-56793.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-08-dell-cve-2026-56793.html</guid>
      <pubDate>Fri, 07 Aug 2026 00:00:00 +0000</pubDate>
      <description>Dell OpenManage Server Administrator, versions prior to 11.1.0.2, contains an Improper Authentication vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Unauthorized access.</description>
    </item>
    <item>
      <title>VU#987105: The nothings stb TrueType library, up to version 1.26, contains a heap buffer overflow vulnerability</title>
      <link>https://www.patchbrief.org/items/2026-08-github-vu-987105.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-08-github-vu-987105.html</guid>
      <pubDate>Fri, 07 Aug 2026 00:00:00 +0000</pubDate>
      <description>Overview A heap buffer overflow vulnerability exists in the stb TrueType library created by nothings. Exploitation of this vulnerability can occur when handling malformed font data and may lead to both Denial of Service (DoS) and Information Disclosure. Description The nothings stb repository, versions 1.26 and earlier, contains a collection of single-file public domain and MIT-licensed libraries for C/C++ projects. CVE-2026-18497 A heap buffer overflow vulnerability exists in the stbtt_GetGlyphShape() function within the stb_truetype.h library when handling malformed TrueType Font (TTF) data. The issue occurs during glyph contour parsing. The function iterates based on the number of contour endpoints specified in endPtsOfContours , but does not validate that the points pointer remains within the bounds of the glyph data buffer. As a... Related CVEs: CVE-2026-18497.</description>
    </item>
    <item>
      <title>go-git: Worktree operations may follow symlinks</title>
      <link>https://www.patchbrief.org/items/2026-08-go-cve-2026-71556.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-08-go-cve-2026-71556.html</guid>
      <pubDate>Fri, 07 Aug 2026 00:00:00 +0000</pubDate>
      <description>go-git: Worktree operations may follow symlinks</description>
    </item>
    <item>
      <title>jsii-diff: Command Injection via npm: package argument</title>
      <link>https://www.patchbrief.org/items/2026-08-npm-cve-2026-15895.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-08-npm-cve-2026-15895.html</guid>
      <pubDate>Fri, 07 Aug 2026 00:00:00 +0000</pubDate>
      <description>jsii-diff: Command Injection via npm: package argument</description>
    </item>
    <item>
      <title>crypto-js: Insufficient Entropy in Cryptographic Secret Generation via Vulnerable CryptoJS Dependency Chain</title>
      <link>https://www.patchbrief.org/items/2026-08-npm-cve-2026-71851.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-08-npm-cve-2026-71851.html</guid>
      <pubDate>Fri, 07 Aug 2026 00:00:00 +0000</pubDate>
      <description>crypto-js: Insufficient Entropy in Cryptographic Secret Generation via Vulnerable CryptoJS Dependency Chain</description>
    </item>
    <item>
      <title>Progress LoadMaster Command Injection Vulnerability</title>
      <link>https://www.patchbrief.org/items/2026-08-progress-cve-2026-8037.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-08-progress-cve-2026-8037.html</guid>
      <pubDate>Fri, 07 Aug 2026 00:00:00 +0000</pubDate>
      <description>Progress LoadMaster contains a command injection vulnerability that allows an un-authenticated attacker to execute arbitrary commands on the LoadMaster appliance by exploiting unsanitized input in multiple command endpoints.</description>
    </item>
    <item>
      <title>pymdown-extensions: exponential-backtracking ReDoS in caret, tilde, betterem, and magiclink inline processors</title>
      <link>https://www.patchbrief.org/items/2026-08-pypi-cve-2026-67422.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-08-pypi-cve-2026-67422.html</guid>
      <pubDate>Fri, 07 Aug 2026 00:00:00 +0000</pubDate>
      <description>pymdown-extensions: exponential-backtracking ReDoS in caret, tilde, betterem, and magiclink inline processors</description>
    </item>
    <item>
      <title>GitPython: Unguarded git read-tree option forwarding in IndexFile.from_tree/reset/merge_tree enables arbitrary file o...</title>
      <link>https://www.patchbrief.org/items/2026-08-pypi-ghsa-4gmw-gg2m-w46p.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-08-pypi-ghsa-4gmw-gg2m-w46p.html</guid>
      <pubDate>Fri, 07 Aug 2026 00:00:00 +0000</pubDate>
      <description>GitPython: Unguarded git read-tree option forwarding in IndexFile.from_tree/reset/merge_tree enables arbitrary file overwrite</description>
    </item>
    <item>
      <title>GitPython: Unguarded git option forwarding in Repo.init enables arbitrary command execution via --template clone hooks</title>
      <link>https://www.patchbrief.org/items/2026-08-pypi-ghsa-9rj7-rf2p-w77r.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-08-pypi-ghsa-9rj7-rf2p-w77r.html</guid>
      <pubDate>Fri, 07 Aug 2026 00:00:00 +0000</pubDate>
      <description>GitPython: Unguarded git option forwarding in Repo.init enables arbitrary command execution via --template clone hooks</description>
    </item>
    <item>
      <title>GitPython: Arbitrary Git Repository Creation Outside the Working Tree via Unvalidated .gitmodules Submodule Name in G...</title>
      <link>https://www.patchbrief.org/items/2026-08-pypi-ghsa-hmq2-w58f-27jc.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-08-pypi-ghsa-hmq2-w58f-27jc.html</guid>
      <pubDate>Fri, 07 Aug 2026 00:00:00 +0000</pubDate>
      <description>GitPython: Arbitrary Git Repository Creation Outside the Working Tree via Unvalidated .gitmodules Submodule Name in GitPython</description>
    </item>
    <item>
      <title>GitPython: git-config OPTION-name injection via =/#/whitespace bypasses name validator, enabling forged core.sshComma...</title>
      <link>https://www.patchbrief.org/items/2026-08-pypi-ghsa-jm78-9fvv-mhgr.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-08-pypi-ghsa-jm78-9fvv-mhgr.html</guid>
      <pubDate>Fri, 07 Aug 2026 00:00:00 +0000</pubDate>
      <description>GitPython: git-config OPTION-name injection via =/#/whitespace bypasses name validator, enabling forged core.sshCommand/hooksPath (RCE)</description>
    </item>
    <item>
      <title>GitPython: Unsafe git option guard bypass via split_single_char_options=False short-option token smuggling enables co...</title>
      <link>https://www.patchbrief.org/items/2026-08-pypi-ghsa-wvpp-8hx9-p66j.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-08-pypi-ghsa-wvpp-8hx9-p66j.html</guid>
      <pubDate>Fri, 07 Aug 2026 00:00:00 +0000</pubDate>
      <description>GitPython: Unsafe git option guard bypass via split_single_char_options=False short-option token smuggling enables command execution</description>
    </item>
    <item>
      <title>Statamic: Account takeover via OAuth email matching without email-verification check</title>
      <link>https://www.patchbrief.org/items/2026-08-composer-cve-2026-64665.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-08-composer-cve-2026-64665.html</guid>
      <pubDate>Thu, 06 Aug 2026 00:00:00 +0000</pubDate>
      <description>Statamic: Account takeover via OAuth email matching without email-verification check</description>
    </item>
    <item>
      <title>PHP_CodeSniffer gitblame report command injection via crafted filename</title>
      <link>https://www.patchbrief.org/items/2026-08-composer-cve-2026-67434.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-08-composer-cve-2026-67434.html</guid>
      <pubDate>Thu, 06 Aug 2026 00:00:00 +0000</pubDate>
      <description>PHP_CodeSniffer gitblame report command injection via crafted filename</description>
    </item>
    <item>
      <title>league/commonmark: Quadratic-time denial of service when parsing crafted Markdown</title>
      <link>https://www.patchbrief.org/items/2026-08-composer-cve-2026-71488.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-08-composer-cve-2026-71488.html</guid>
      <pubDate>Thu, 06 Aug 2026 00:00:00 +0000</pubDate>
      <description>league/commonmark: Quadratic-time denial of service when parsing crafted Markdown</description>
    </item>
    <item>
      <title>Craft CMS: Authenticated RCE via `condition.config` JSON cleanse bypass</title>
      <link>https://www.patchbrief.org/items/2026-08-composer-ghsa-265m-7826-wjqm.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-08-composer-ghsa-265m-7826-wjqm.html</guid>
      <pubDate>Thu, 06 Aug 2026 00:00:00 +0000</pubDate>
      <description>Craft CMS: Authenticated RCE via `condition.config` JSON cleanse bypass</description>
    </item>
    <item>
      <title>Craft CMS: Authenticated RCE through Twig sandbox escape</title>
      <link>https://www.patchbrief.org/items/2026-08-composer-ghsa-f5wm-88jv-g5hx.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-08-composer-ghsa-f5wm-88jv-g5hx.html</guid>
      <pubDate>Thu, 06 Aug 2026 00:00:00 +0000</pubDate>
      <description>Craft CMS: Authenticated RCE through Twig sandbox escape</description>
    </item>
    <item>
      <title>league/commonmark: Denial of service via adjacent inline attribute blocks</title>
      <link>https://www.patchbrief.org/items/2026-08-composer-ghsa-g2gp-3wwq-f4ph.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-08-composer-ghsa-g2gp-3wwq-f4ph.html</guid>
      <pubDate>Thu, 06 Aug 2026 00:00:00 +0000</pubDate>
      <description>league/commonmark: Denial of service via adjacent inline attribute blocks</description>
    </item>
    <item>
      <title>league/commonmark:  Denial of service via duplicate footnote definitions</title>
      <link>https://www.patchbrief.org/items/2026-08-composer-ghsa-jfm3-95jq-q3rf.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-08-composer-ghsa-jfm3-95jq-q3rf.html</guid>
      <pubDate>Thu, 06 Aug 2026 00:00:00 +0000</pubDate>
      <description>league/commonmark: Denial of service via duplicate footnote definitions</description>
    </item>
    <item>
      <title>league/commonmark: Denial of service via colliding heading slugs</title>
      <link>https://www.patchbrief.org/items/2026-08-composer-ghsa-mh25-x5hq-wrqp.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-08-composer-ghsa-mh25-x5hq-wrqp.html</guid>
      <pubDate>Thu, 06 Aug 2026 00:00:00 +0000</pubDate>
      <description>league/commonmark: Denial of service via colliding heading slugs</description>
    </item>
    <item>
      <title>Craft CMS: Arbitrary user password reset leading to administrator account takeover</title>
      <link>https://www.patchbrief.org/items/2026-08-composer-ghsa-p8x7-9vfw-p7vc.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-08-composer-ghsa-p8x7-9vfw-p7vc.html</guid>
      <pubDate>Thu, 06 Aug 2026 00:00:00 +0000</pubDate>
      <description>Craft CMS: Arbitrary user password reset leading to administrator account takeover</description>
    </item>
    <item>
      <title>VU#487613: Alinto SOGo v5.12.7 vulnerable to cross-site scripting via malformed ICS calendar invitations</title>
      <link>https://www.patchbrief.org/items/2026-08-content-vu-487613.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-08-content-vu-487613.html</guid>
      <pubDate>Thu, 06 Aug 2026 00:00:00 +0000</pubDate>
      <description>Overview A cross-site scripting (XSS) vulnerability in Alinto SOGo v5.12.7 allows attackers to achieve remote code execution by embedding malicious SVG (Scalable Vector Graphics) objects in ICS (iCalendar) invitations. The vulnerability has been actively exploited in the wild, as confirmed by VirusTotal sightings. Description Alinto SOGo is an open-source webmail and groupware platform for email, calendars, contacts, and shared scheduling. It is primarily used by organizations seeking a self-hosted interface solution for existing mail infrastructure. CVE-2026-8496 The vulnerability exists in SOGo’s handling of ICS files, where the DESCRIPTION field is rendered without proper sanitization or Content Security Policy (CSP) enforcement. When a calendar invite contains an SVG payload, such as , with JavaScript event handlers, the browser... Related CVEs: CVE-2026-8496.</description>
    </item>
    <item>
      <title>Dell Virtual Storage Integrator — CVE-2026-54489 (Critical)</title>
      <link>https://www.patchbrief.org/items/2026-08-dell-cve-2026-54489.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-08-dell-cve-2026-54489.html</guid>
      <pubDate>Thu, 06 Aug 2026 00:00:00 +0000</pubDate>
      <description>Dell Virtual Storage Integrator for VMware vSphere Client, versions prior to 10.11.1.0, contain(s) a Sensitive Information Disclosure vulnerability. An unauthenticated remote attacker could potentially exploit this vulnerability, leading to information disclosure and session hijacking. This vulnerability is considered critical as it allows an unauthenticated attacker to obtain active session credentials and fully impersonate authenticated users, including administrators. Dell recommends customers to upgrade at the earliest opportunity.</description>
    </item>
    <item>
      <title>Traefik: Authentication Bypass via Path Traversal in ReplacePathRegex Middleware</title>
      <link>https://www.patchbrief.org/items/2026-08-go-cve-2026-65600.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-08-go-cve-2026-65600.html</guid>
      <pubDate>Thu, 06 Aug 2026 00:00:00 +0000</pubDate>
      <description>Traefik: Authentication Bypass via Path Traversal in ReplacePathRegex Middleware</description>
    </item>
    <item>
      <title>Traefik: Kubernetes Ingress NGINX RewriteTarget Path Traversal Allows Route-Level Authentication Bypass</title>
      <link>https://www.patchbrief.org/items/2026-08-go-cve-2026-67309.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-08-go-cve-2026-67309.html</guid>
      <pubDate>Thu, 06 Aug 2026 00:00:00 +0000</pubDate>
      <description>Traefik: Kubernetes Ingress NGINX RewriteTarget Path Traversal Allows Route-Level Authentication Bypass</description>
    </item>
    <item>
      <title>Traefik: Cross-user response poisoning via proxied CONNECT on Traefik's shared backend keep-alive pool</title>
      <link>https://www.patchbrief.org/items/2026-08-go-cve-2026-71324.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-08-go-cve-2026-71324.html</guid>
      <pubDate>Thu, 06 Aug 2026 00:00:00 +0000</pubDate>
      <description>Traefik: Cross-user response poisoning via proxied CONNECT on Traefik's shared backend keep-alive pool</description>
    </item>
    <item>
      <title>Traefik: Gateway API route identity collision allows cross-namespace backend hijacking</title>
      <link>https://www.patchbrief.org/items/2026-08-go-cve-2026-71327.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-08-go-cve-2026-71327.html</guid>
      <pubDate>Thu, 06 Aug 2026 00:00:00 +0000</pubDate>
      <description>Traefik: Gateway API route identity collision allows cross-namespace backend hijacking</description>
    </item>
    <item>
      <title>Apache Portable Runtime Utility: SQL Injection in apr_dbd_oracle</title>
      <link>https://www.patchbrief.org/items/2026-08-microsoft-cve-2026-34191.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-08-microsoft-cve-2026-34191.html</guid>
      <pubDate>Thu, 06 Aug 2026 00:00:00 +0000</pubDate>
      <description>Apache Portable Runtime Utility: SQL Injection in apr_dbd_oracle Published in August 2026 Early Security Updates.</description>
    </item>
    <item>
      <title>Application Insights Profiler Elevation of Privilege Vulnerability</title>
      <link>https://www.patchbrief.org/items/2026-08-microsoft-cve-2026-49163.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-08-microsoft-cve-2026-49163.html</guid>
      <pubDate>Thu, 06 Aug 2026 00:00:00 +0000</pubDate>
      <description>Improper limitation of a pathname to a restricted directory ('path traversal') in Application Insights Profiler allows an authorized attacker to elevate privileges over a network. Published in August 2026 Early Security Updates. MSRC exploitability: Publicly Disclosed:No;Exploited:No.</description>
    </item>
    <item>
      <title>Azure Active Directory Elevation of Privilege Vulnerability</title>
      <link>https://www.patchbrief.org/items/2026-08-microsoft-cve-2026-50481.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-08-microsoft-cve-2026-50481.html</guid>
      <pubDate>Thu, 06 Aug 2026 00:00:00 +0000</pubDate>
      <description>Modification of assumed-immutable data (maid) in Azure Active Directory allows an authorized attacker to elevate privileges over a network. Published in August 2026 Early Security Updates. MSRC exploitability: Publicly Disclosed:No;Exploited:No;Latest Software Release:N/A.</description>
    </item>
    <item>
      <title>Azure Service Bus Remote Code Execution Vulnerability</title>
      <link>https://www.patchbrief.org/items/2026-08-microsoft-cve-2026-50515.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-08-microsoft-cve-2026-50515.html</guid>
      <pubDate>Thu, 06 Aug 2026 00:00:00 +0000</pubDate>
      <description>Deserialization of untrusted data in Azure Service Bus allows an authorized attacker to execute code over a network. Published in August 2026 Early Security Updates. MSRC exploitability: Publicly Disclosed:No;Exploited:No;Latest Software Release:N/A.</description>
    </item>
    <item>
      <title>Microsoft Azure Kubernetes Service Elevation of Privilege Vulnerability</title>
      <link>https://www.patchbrief.org/items/2026-08-microsoft-cve-2026-50516.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-08-microsoft-cve-2026-50516.html</guid>
      <pubDate>Thu, 06 Aug 2026 00:00:00 +0000</pubDate>
      <description>Missing authentication for critical function in Microsoft Azure Kubernetes Service allows an unauthorized attacker to elevate privileges over a network. Published in August 2026 Early Security Updates. MSRC exploitability: Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation Less Likely.</description>
    </item>
    <item>
      <title>Kata Containers: Config Path Annotation Arbitrary File Loading</title>
      <link>https://www.patchbrief.org/items/2026-08-microsoft-cve-2026-50540.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-08-microsoft-cve-2026-50540.html</guid>
      <pubDate>Thu, 06 Aug 2026 00:00:00 +0000</pubDate>
      <description>Kata Containers: Config Path Annotation Arbitrary File Loading Published in August 2026 Early Security Updates.</description>
    </item>
    <item>
      <title>Azure Logic Apps Information Disclosure Vulnerability</title>
      <link>https://www.patchbrief.org/items/2026-08-microsoft-cve-2026-56161.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-08-microsoft-cve-2026-56161.html</guid>
      <pubDate>Thu, 06 Aug 2026 00:00:00 +0000</pubDate>
      <description>Improper access control in Azure Logic Apps allows an authorized attacker to disclose information over a network. Published in August 2026 Early Security Updates. MSRC exploitability: Publicly Disclosed:No;Exploited:No;Latest Software Release:N/A.</description>
    </item>
    <item>
      <title>Azure SQL Database Elevation of Privilege Vulnerability</title>
      <link>https://www.patchbrief.org/items/2026-08-microsoft-cve-2026-56162.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-08-microsoft-cve-2026-56162.html</guid>
      <pubDate>Thu, 06 Aug 2026 00:00:00 +0000</pubDate>
      <description>Improper authentication in Azure SQL Database allows an unauthorized attacker to elevate privileges over a network. Published in August 2026 Early Security Updates. MSRC exploitability: Publicly Disclosed:No;Exploited:No;Latest Software Release:N/A.</description>
    </item>
    <item>
      <title>Microsoft Entra Provisioning Service Elevation of Privilege Vulnerability</title>
      <link>https://www.patchbrief.org/items/2026-08-microsoft-cve-2026-59115.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-08-microsoft-cve-2026-59115.html</guid>
      <pubDate>Thu, 06 Aug 2026 00:00:00 +0000</pubDate>
      <description>'.../...//' in Microsoft Entra Provisioning Service (SyncFabric) allows an authorized attacker to elevate privileges over a network. Published in August 2026 Early Security Updates. MSRC exploitability: Publicly Disclosed:No;Exploited:No;Latest Software Release:N/A.</description>
    </item>
    <item>
      <title>Microsoft Power Apps Elevation of Privilege Vulnerability</title>
      <link>https://www.patchbrief.org/items/2026-08-microsoft-cve-2026-59118.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-08-microsoft-cve-2026-59118.html</guid>
      <pubDate>Thu, 06 Aug 2026 00:00:00 +0000</pubDate>
      <description>Improper authorization in Microsoft Power Apps allows an unauthorized attacker to elevate privileges over a network. Published in August 2026 Early Security Updates. MSRC exploitability: Publicly Disclosed:No;Exploited:No;Latest Software Release:N/A.</description>
    </item>
    <item>
      <title>Azure SRE Agent Elevation of Privilege Vulnerability</title>
      <link>https://www.patchbrief.org/items/2026-08-microsoft-cve-2026-62830.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-08-microsoft-cve-2026-62830.html</guid>
      <pubDate>Thu, 06 Aug 2026 00:00:00 +0000</pubDate>
      <description>Missing authorization in Azure SRE Agent allows an authorized attacker to elevate privileges over a network. Published in August 2026 Early Security Updates. MSRC exploitability: Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation Less Likely.</description>
    </item>
    <item>
      <title>Azure SQL Managed Instance Elevation of Privilege Vulnerability</title>
      <link>https://www.patchbrief.org/items/2026-08-microsoft-cve-2026-62836.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-08-microsoft-cve-2026-62836.html</guid>
      <pubDate>Thu, 06 Aug 2026 00:00:00 +0000</pubDate>
      <description>Improper restriction of communication channel to intended endpoints in Azure SQL Managed Instance allows an unauthorized attacker to elevate privileges over a network. Published in August 2026 Early Security Updates. MSRC exploitability: Publicly Disclosed:No;Exploited:No;Latest Software Release:N/A.</description>
    </item>
    <item>
      <title>Azure Entra ID Spoofing Vulnerability</title>
      <link>https://www.patchbrief.org/items/2026-08-microsoft-cve-2026-62869.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-08-microsoft-cve-2026-62869.html</guid>
      <pubDate>Thu, 06 Aug 2026 00:00:00 +0000</pubDate>
      <description>Insufficient verification of data authenticity in Azure Entra ID allows an authorized attacker to perform spoofing over a network. Published in August 2026 Early Security Updates. MSRC exploitability: Publicly Disclosed:No;Exploited:No;Latest Software Release:N/A.</description>
    </item>
    <item>
      <title>Microsoft Teams Elevation of Privilege Vulnerability</title>
      <link>https://www.patchbrief.org/items/2026-08-microsoft-cve-2026-62896.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-08-microsoft-cve-2026-62896.html</guid>
      <pubDate>Thu, 06 Aug 2026 00:00:00 +0000</pubDate>
      <description>Improper authentication in Microsoft Teams allows an authorized attacker to elevate privileges over a network. Published in August 2026 Early Security Updates. MSRC exploitability: Publicly Disclosed:No;Exploited:No;Latest Software Release:N/A.</description>
    </item>
    <item>
      <title>Microsoft Teams Spoofing Vulnerability</title>
      <link>https://www.patchbrief.org/items/2026-08-microsoft-cve-2026-62918.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-08-microsoft-cve-2026-62918.html</guid>
      <pubDate>Thu, 06 Aug 2026 00:00:00 +0000</pubDate>
      <description>Improper verification of cryptographic signature in Microsoft Teams allows an unauthorized attacker to perform spoofing over a network. Published in August 2026 Early Security Updates. MSRC exploitability: Publicly Disclosed:No;Exploited:No;Latest Software Release:N/A.</description>
    </item>
    <item>
      <title>Azure SQL Database Elevation of Privilege Vulnerability</title>
      <link>https://www.patchbrief.org/items/2026-08-microsoft-cve-2026-63522.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-08-microsoft-cve-2026-63522.html</guid>
      <pubDate>Thu, 06 Aug 2026 00:00:00 +0000</pubDate>
      <description>Incorrect permission assignment for critical resource in Azure SQL Database allows an authorized attacker to elevate privileges locally. Published in August 2026 Early Security Updates. MSRC exploitability: Publicly Disclosed:No;Exploited:No;Latest Software Release:N/A.</description>
    </item>
    <item>
      <title>KVM: nVMX: Hide shadow VMCS right after VMCLEAR</title>
      <link>https://www.patchbrief.org/items/2026-08-microsoft-cve-2026-64562.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-08-microsoft-cve-2026-64562.html</guid>
      <pubDate>Thu, 06 Aug 2026 00:00:00 +0000</pubDate>
      <description>KVM: nVMX: Hide shadow VMCS right after VMCLEAR Published in August 2026 Early Security Updates.</description>
    </item>
    <item>
      <title>sctp: don't free the ASCONF's own transport in DEL-IP processing</title>
      <link>https://www.patchbrief.org/items/2026-08-microsoft-cve-2026-64564.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-08-microsoft-cve-2026-64564.html</guid>
      <pubDate>Thu, 06 Aug 2026 00:00:00 +0000</pubDate>
      <description>sctp: don't free the ASCONF's own transport in DEL-IP processing Published in August 2026 Early Security Updates.</description>
    </item>
    <item>
      <title>Input: ims-pcu - fix heap-buffer-overflow in ims_pcu_process_data()</title>
      <link>https://www.patchbrief.org/items/2026-08-microsoft-cve-2026-64565.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-08-microsoft-cve-2026-64565.html</guid>
      <pubDate>Thu, 06 Aug 2026 00:00:00 +0000</pubDate>
      <description>Input: ims-pcu - fix heap-buffer-overflow in ims_pcu_process_data() Published in August 2026 Early Security Updates.</description>
    </item>
    <item>
      <title>usb: gadget: f_midi: cancel pending IN work before freeing the midi object</title>
      <link>https://www.patchbrief.org/items/2026-08-microsoft-cve-2026-64584.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-08-microsoft-cve-2026-64584.html</guid>
      <pubDate>Thu, 06 Aug 2026 00:00:00 +0000</pubDate>
      <description>usb: gadget: f_midi: cancel pending IN work before freeing the midi object Published in August 2026 Early Security Updates.</description>
    </item>
    <item>
      <title>btrfs: do not trim a device which is not writeable</title>
      <link>https://www.patchbrief.org/items/2026-08-microsoft-cve-2026-64593.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-08-microsoft-cve-2026-64593.html</guid>
      <pubDate>Thu, 06 Aug 2026 00:00:00 +0000</pubDate>
      <description>btrfs: do not trim a device which is not writeable Published in August 2026 Early Security Updates.</description>
    </item>
    <item>
      <title>usb: gadget: f_fs: initialize reset_work at allocation time</title>
      <link>https://www.patchbrief.org/items/2026-08-microsoft-cve-2026-64594.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-08-microsoft-cve-2026-64594.html</guid>
      <pubDate>Thu, 06 Aug 2026 00:00:00 +0000</pubDate>
      <description>usb: gadget: f_fs: initialize reset_work at allocation time Published in August 2026 Early Security Updates.</description>
    </item>
    <item>
      <title>Microsoft Teams Elevation of Privilege Vulnerability</title>
      <link>https://www.patchbrief.org/items/2026-08-microsoft-cve-2026-65667.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-08-microsoft-cve-2026-65667.html</guid>
      <pubDate>Thu, 06 Aug 2026 00:00:00 +0000</pubDate>
      <description>Missing authorization in Microsoft Teams allows an unauthorized attacker to elevate privileges over a network. Published in August 2026 Early Security Updates. MSRC exploitability: Publicly Disclosed:No;Exploited:No;Latest Software Release:N/A.</description>
    </item>
    <item>
      <title>Microsoft Purview eDiscovery Elevation of Privilege Vulnerability</title>
      <link>https://www.patchbrief.org/items/2026-08-microsoft-cve-2026-65668.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-08-microsoft-cve-2026-65668.html</guid>
      <pubDate>Thu, 06 Aug 2026 00:00:00 +0000</pubDate>
      <description>Improper access control in Microsoft Purview eDiscovery allows an authorized attacker to elevate privileges over a network. Published in August 2026 Early Security Updates. MSRC exploitability: Publicly Disclosed:No;Exploited:No;Latest Software Release:N/A.</description>
    </item>
    <item>
      <title>x86/bugs: Make Safe-RET robust against interrupt injection</title>
      <link>https://www.patchbrief.org/items/2026-08-microsoft-cve-2026-68480.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-08-microsoft-cve-2026-68480.html</guid>
      <pubDate>Thu, 06 Aug 2026 00:00:00 +0000</pubDate>
      <description>x86/bugs: Make Safe-RET robust against interrupt injection Published in August 2026 Early Security Updates.</description>
    </item>
    <item>
      <title>Azure Confidential Ledger Remote Code Execution Vulnerability</title>
      <link>https://www.patchbrief.org/items/2026-08-microsoft-cve-2026-68823.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-08-microsoft-cve-2026-68823.html</guid>
      <pubDate>Thu, 06 Aug 2026 00:00:00 +0000</pubDate>
      <description>Exposed dangerous method or function in Azure Confidential Ledger allows an authorized attacker to execute code over a network. Published in August 2026 Early Security Updates. MSRC exploitability: Publicly Disclosed:No;Exploited:No;Latest Software Release:N/A.</description>
    </item>
    <item>
      <title>Microsoft Office SharePoint Spoofing Vulnerability</title>
      <link>https://www.patchbrief.org/items/2026-08-microsoft-cve-2026-70332.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-08-microsoft-cve-2026-70332.html</guid>
      <pubDate>Thu, 06 Aug 2026 00:00:00 +0000</pubDate>
      <description>Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network. Published in August 2026 Early Security Updates. MSRC exploitability: Publicly Disclosed:No;Exploited:No;Latest Software Release:N/A.</description>
    </item>
    <item>
      <title>PDF.js: Arbitrary JavaScript execution upon opening a malicious PDF</title>
      <link>https://www.patchbrief.org/items/2026-08-npm-cve-2026-16633.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-08-npm-cve-2026-16633.html</guid>
      <pubDate>Thu, 06 Aug 2026 00:00:00 +0000</pubDate>
      <description>PDF.js: Arbitrary JavaScript execution upon opening a malicious PDF</description>
    </item>
    <item>
      <title>Nx: Zip-Slip in the self-hosted remote cache</title>
      <link>https://www.patchbrief.org/items/2026-08-npm-cve-2026-71476.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-08-npm-cve-2026-71476.html</guid>
      <pubDate>Thu, 06 Aug 2026 00:00:00 +0000</pubDate>
      <description>Nx: Zip-Slip in the self-hosted remote cache</description>
    </item>
    <item>
      <title>JS-YAML: Quadratic CPU consumption in !!omap resolution (3.x and 4.x) — CVE-2026-59870 fix not backported</title>
      <link>https://www.patchbrief.org/items/2026-08-npm-ghsa-5p4m-2wfm-xmqj.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-08-npm-ghsa-5p4m-2wfm-xmqj.html</guid>
      <pubDate>Thu, 06 Aug 2026 00:00:00 +0000</pubDate>
      <description>JS-YAML: Quadratic CPU consumption in !!omap resolution (3.x and 4.x) — CVE-2026-59870 fix not backported</description>
    </item>
    <item>
      <title>ngx-extended-pdf-viewer bundles a version of pdf.js vulnerable to CVE-2026-16633</title>
      <link>https://www.patchbrief.org/items/2026-08-npm-ghsa-w9hm-4m3m-fxmm.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-08-npm-ghsa-w9hm-4m3m-fxmm.html</guid>
      <pubDate>Thu, 06 Aug 2026 00:00:00 +0000</pubDate>
      <description>ngx-extended-pdf-viewer bundles a version of pdf.js vulnerable to CVE-2026-16633</description>
    </item>
    <item>
      <title>rclone: Unvalidated symlink target in local `--links` — arbitrary file write from an untrusted remote</title>
      <link>https://www.patchbrief.org/items/2026-08-go-cve-2026-54572.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-08-go-cve-2026-54572.html</guid>
      <pubDate>Wed, 05 Aug 2026 00:00:00 +0000</pubDate>
      <description>rclone: Unvalidated symlink target in local `--links` — arbitrary file write from an untrusted remote</description>
    </item>
    <item>
      <title>rclone `serve restic --private-repos` authorization bypass: `..` in the URL path lets an authenticated user read, ove...</title>
      <link>https://www.patchbrief.org/items/2026-08-go-cve-2026-59733.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-08-go-cve-2026-59733.html</guid>
      <pubDate>Wed, 05 Aug 2026 00:00:00 +0000</pubDate>
      <description>rclone `serve restic --private-repos` authorization bypass: `..` in the URL path lets an authenticated user read, overwrite and delete other users' repositories</description>
    </item>
    <item>
      <title>rclone: Incomplete path validation allows backend root escape in serve restic</title>
      <link>https://www.patchbrief.org/items/2026-08-go-cve-2026-71309.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-08-go-cve-2026-71309.html</guid>
      <pubDate>Wed, 05 Aug 2026 00:00:00 +0000</pubDate>
      <description>rclone: Incomplete path validation allows backend root escape in serve restic</description>
    </item>
    <item>
      <title>rclone: PowerShell Smart-Quote Filename Injection Enables SFTP Server-Side Command Execution</title>
      <link>https://www.patchbrief.org/items/2026-08-go-cve-2026-71312.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-08-go-cve-2026-71312.html</guid>
      <pubDate>Wed, 05 Aug 2026 00:00:00 +0000</pubDate>
      <description>rclone: PowerShell Smart-Quote Filename Injection Enables SFTP Server-Side Command Execution</description>
    </item>
    <item>
      <title>JetBrains TeamCity Deserialization of Untrusted Data Vulnerability</title>
      <link>https://www.patchbrief.org/items/2026-08-jetbrains-cve-2026-63077.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-08-jetbrains-cve-2026-63077.html</guid>
      <pubDate>Wed, 05 Aug 2026 00:00:00 +0000</pubDate>
      <description>JetBrains TeamCity contains a deserialization of untrusted data vulnerability that could allow unauthenticated remote code execution via the agent polling protocol.</description>
    </item>
    <item>
      <title>Langflow Langflow — CVE-2026-8470 (Critical)</title>
      <link>https://www.patchbrief.org/items/2026-08-langflow-cve-2026-8470.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-08-langflow-cve-2026-8470.html</guid>
      <pubDate>Wed, 05 Aug 2026 00:00:00 +0000</pubDate>
      <description>IBM Langflow OSS 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, and 1.0.0 through 1.10.3 use Python's non-cryptographic random module for generating Fernet encryption keys from user secrets under 32 characters. The deterministic Mersenne Twister PRNG produces identical keys for identical seeds, allowing attackers to reproduce encryption keys and decrypt stored API keys and authentication tokens.</description>
    </item>
    <item>
      <title>Langflow Langflow — CVE-2026-9205 (Critical)</title>
      <link>https://www.patchbrief.org/items/2026-08-langflow-cve-2026-9205.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-08-langflow-cve-2026-9205.html</guid>
      <pubDate>Wed, 05 Aug 2026 00:00:00 +0000</pubDate>
      <description>IBM Langflow OSS contains a weak cryptographic key derivation vulnerability in the ensure_fernet_key() function.</description>
    </item>
    <item>
      <title>Electron: Context isolation bypass via Function.prototype.bind hijack</title>
      <link>https://www.patchbrief.org/items/2026-08-npm-cve-2026-70601.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-08-npm-cve-2026-70601.html</guid>
      <pubDate>Wed, 05 Aug 2026 00:00:00 +0000</pubDate>
      <description>Electron: Context isolation bypass via Function.prototype.bind hijack</description>
    </item>
    <item>
      <title>Electron: Custom protocol with supportFetchAPI but not corsEnabled allows cross-origin reads</title>
      <link>https://www.patchbrief.org/items/2026-08-npm-cve-2026-70604.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-08-npm-cve-2026-70604.html</guid>
      <pubDate>Wed, 05 Aug 2026 00:00:00 +0000</pubDate>
      <description>Electron: Custom protocol with supportFetchAPI but not corsEnabled allows cross-origin reads</description>
    </item>
    <item>
      <title>Electron: Sandboxed iframe can bypass the allow-popups restriction via the OpenURL navigation path</title>
      <link>https://www.patchbrief.org/items/2026-08-npm-cve-2026-70608.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-08-npm-cve-2026-70608.html</guid>
      <pubDate>Wed, 05 Aug 2026 00:00:00 +0000</pubDate>
      <description>Electron: Sandboxed iframe can bypass the allow-popups restriction via the OpenURL navigation path</description>
    </item>
    <item>
      <title>Nuxt: Unauthenticated out-of-memory crash via unbounded v-for expansion in island rendering</title>
      <link>https://www.patchbrief.org/items/2026-08-npm-cve-2026-71314.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-08-npm-cve-2026-71314.html</guid>
      <pubDate>Wed, 05 Aug 2026 00:00:00 +0000</pubDate>
      <description>Nuxt: Unauthenticated out-of-memory crash via unbounded v-for expansion in island rendering</description>
    </item>
    <item>
      <title>Nuxt route rules silently dropped for mixed-case paths, bypassing appMiddleware auth gates (incomplete fix for CVE-20...</title>
      <link>https://www.patchbrief.org/items/2026-08-npm-cve-2026-71315.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-08-npm-cve-2026-71315.html</guid>
      <pubDate>Wed, 05 Aug 2026 00:00:00 +0000</pubDate>
      <description>Nuxt route rules silently dropped for mixed-case paths, bypassing appMiddleware auth gates (incomplete fix for CVE-2026-53721)</description>
    </item>
    <item>
      <title>Nuxt runtime payload cache discloses another user's SSR data across users and to unauthenticated clients</title>
      <link>https://www.patchbrief.org/items/2026-08-npm-cve-2026-71316.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-08-npm-cve-2026-71316.html</guid>
      <pubDate>Wed, 05 Aug 2026 00:00:00 +0000</pubDate>
      <description>Nuxt runtime payload cache discloses another user's SSR data across users and to unauthenticated clients</description>
    </item>
    <item>
      <title>Unauthenticated Nuxt DevTools RPC allows arbitrary command execution on the developer's host</title>
      <link>https://www.patchbrief.org/items/2026-08-npm-cve-2026-71319.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-08-npm-cve-2026-71319.html</guid>
      <pubDate>Wed, 05 Aug 2026 00:00:00 +0000</pubDate>
      <description>Unauthenticated Nuxt DevTools RPC allows arbitrary command execution on the developer's host</description>
    </item>
    <item>
      <title>Nuxt: Server-Side Remote Code Execution via Runtime Template Injection in Nuxt Server Island Props</title>
      <link>https://www.patchbrief.org/items/2026-08-npm-cve-2026-71320.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-08-npm-cve-2026-71320.html</guid>
      <pubDate>Wed, 05 Aug 2026 00:00:00 +0000</pubDate>
      <description>Nuxt: Server-Side Remote Code Execution via Runtime Template Injection in Nuxt Server Island Props</description>
    </item>
    <item>
      <title>Nuxt: Unauthenticated CPU exhaustion parsing and hashing the Nuxt island endpoint body before hash validation</title>
      <link>https://www.patchbrief.org/items/2026-08-npm-cve-2026-71321.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-08-npm-cve-2026-71321.html</guid>
      <pubDate>Wed, 05 Aug 2026 00:00:00 +0000</pubDate>
      <description>Nuxt: Unauthenticated CPU exhaustion parsing and hashing the Nuxt island endpoint body before hash validation</description>
    </item>
    <item>
      <title>Apache Tomcat Missing Encryption of Sensitive Data Vulnerability</title>
      <link>https://www.patchbrief.org/items/2026-08-apache-cve-2026-34486.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-08-apache-cve-2026-34486.html</guid>
      <pubDate>Tue, 04 Aug 2026 00:00:00 +0000</pubDate>
      <description>Apache Tomcat contains a missing encryption of sensitive data vulnerability that allows the bypass of the EncryptInterceptor.</description>
    </item>
    <item>
      <title>IBM Langflow Code Injection Vulnerability</title>
      <link>https://www.patchbrief.org/items/2026-08-ibm-cve-2026-9198.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-08-ibm-cve-2026-9198.html</guid>
      <pubDate>Tue, 04 Aug 2026 00:00:00 +0000</pubDate>
      <description>Langflow contains a code injection vulnerability that allows unauthenticated attackers to achieve full remote code execution on default Langflow deployments.</description>
    </item>
    <item>
      <title>MaxSite CMS 109.5 and earlier — CVE-2026-70552 (Critical)</title>
      <link>https://www.patchbrief.org/items/2026-08-maxsite-cve-2026-70552.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-08-maxsite-cve-2026-70552.html</guid>
      <pubDate>Tue, 04 Aug 2026 00:00:00 +0000</pubDate>
      <description>MaxSite CMS 109.5 and earlier contains an authentication bypass vulnerability in the AJAX dispatcher that allows unauthenticated attackers to access admin-gated endpoints by supplying any X-Requested-With header and requesting a base64-encoded path resolving to any *-ajax.php file in the codebase. Attackers can exploit this dispatcher bypass to reach privileged plugin endpoints without credentials, enabling actions such as manipulating poll states and vote counts, and amplifying the impact of any dangerous operation performed by admin-only ajax files across the plugin tree.</description>
    </item>
    <item>
      <title>MaxSite CMS — CVE-2026-70553 (Critical)</title>
      <link>https://www.patchbrief.org/items/2026-08-maxsite-cve-2026-70553.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-08-maxsite-cve-2026-70553.html</guid>
      <pubDate>Tue, 04 Aug 2026 00:00:00 +0000</pubDate>
      <description>MaxSite CMS contains a remote code execution vulnerability that allows unauthenticated attackers to inject arbitrary PHP code into the application configuration file by submitting crafted POST requests to the install endpoint after installation is complete. Attackers can supply a malicious db_dbprefix value containing a single quote to break out of a PHP string literal in application/config/database.php, appending attacker-controlled PHP statements that are executed by the web server on every subsequent request, resulting in persistent unauthenticated remote code execution as the web-server pr</description>
    </item>
    <item>
      <title>MaxSite CMS — CVE-2026-70554 (Critical)</title>
      <link>https://www.patchbrief.org/items/2026-08-maxsite-cve-2026-70554.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-08-maxsite-cve-2026-70554.html</guid>
      <pubDate>Tue, 04 Aug 2026 00:00:00 +0000</pubDate>
      <description>MaxSite CMS contains a PHP object injection vulnerability that allows unauthenticated attackers to execute arbitrary code by passing attacker-controlled serialized data in the maxsite_comuser cookie directly to unserialize() without validation or class allowlisting. Attackers can craft a malicious serialized PHP object payload delivered in a single HTTP request to trigger magic methods during object graph reconstruction, enabling property-oriented programming attacks or remote code execution via available gadget chains such as those targeting SoapClient or Imagick extensions.</description>
    </item>
    <item>
      <title>N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability</title>
      <link>https://www.patchbrief.org/items/2026-08-n-able-cve-2026-18556.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-08-n-able-cve-2026-18556.html</guid>
      <pubDate>Tue, 04 Aug 2026 00:00:00 +0000</pubDate>
      <description>N-able N-central contains an authentication bypass using an alternate path or channel that allows for authentication bypass.</description>
    </item>
    <item>
      <title>XSS in Ghost's ActivityPub client</title>
      <link>https://www.patchbrief.org/items/2026-08-npm-cve-2026-53950.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-08-npm-cve-2026-53950.html</guid>
      <pubDate>Tue, 04 Aug 2026 00:00:00 +0000</pubDate>
      <description>XSS in Ghost's ActivityPub client</description>
    </item>
    <item>
      <title>Flowise RCE via TypeORM DataSource</title>
      <link>https://www.patchbrief.org/items/2026-08-npm-cve-2026-69251.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-08-npm-cve-2026-69251.html</guid>
      <pubDate>Tue, 04 Aug 2026 00:00:00 +0000</pubDate>
      <description>Flowise RCE via TypeORM DataSource</description>
    </item>
    <item>
      <title>Flowise: Missing authorization on `/api/v1/files` allows low-privileged API keys to list and delete files across work...</title>
      <link>https://www.patchbrief.org/items/2026-08-npm-cve-2026-69252.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-08-npm-cve-2026-69252.html</guid>
      <pubDate>Tue, 04 Aug 2026 00:00:00 +0000</pubDate>
      <description>Flowise: Missing authorization on `/api/v1/files` allows low-privileged API keys to list and delete files across workspaces within the same organization</description>
    </item>
    <item>
      <title>Flowise Sandbox Escape to RCE</title>
      <link>https://www.patchbrief.org/items/2026-08-npm-cve-2026-69253.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-08-npm-cve-2026-69253.html</guid>
      <pubDate>Tue, 04 Aug 2026 00:00:00 +0000</pubDate>
      <description>Flowise Sandbox Escape to RCE</description>
    </item>
    <item>
      <title>Flowise: RCE via NodeVM Sandbox Escape in executeJavaScriptCode() nodeVMOptions Override</title>
      <link>https://www.patchbrief.org/items/2026-08-npm-cve-2026-69254.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-08-npm-cve-2026-69254.html</guid>
      <pubDate>Tue, 04 Aug 2026 00:00:00 +0000</pubDate>
      <description>Flowise: RCE via NodeVM Sandbox Escape in executeJavaScriptCode() nodeVMOptions Override</description>
    </item>
    <item>
      <title>Flowise: CSV Agent Remote Code Execution via Pyodide Code Injection — Root Shell Verified</title>
      <link>https://www.patchbrief.org/items/2026-08-npm-cve-2026-69255.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-08-npm-cve-2026-69255.html</guid>
      <pubDate>Tue, 04 Aug 2026 00:00:00 +0000</pubDate>
      <description>Flowise: CSV Agent Remote Code Execution via Pyodide Code Injection — Root Shell Verified</description>
    </item>
    <item>
      <title>Flowise: Remote Code Execution Vulnerability in CSVAgent</title>
      <link>https://www.patchbrief.org/items/2026-08-npm-cve-2026-69256.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-08-npm-cve-2026-69256.html</guid>
      <pubDate>Tue, 04 Aug 2026 00:00:00 +0000</pubDate>
      <description>Flowise: Remote Code Execution Vulnerability in CSVAgent</description>
    </item>
    <item>
      <title>Flowise: SSRF Protection Bypass via IPv4-Mapped IPv6 Addresses</title>
      <link>https://www.patchbrief.org/items/2026-08-npm-cve-2026-69257.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-08-npm-cve-2026-69257.html</guid>
      <pubDate>Tue, 04 Aug 2026 00:00:00 +0000</pubDate>
      <description>Flowise: SSRF Protection Bypass via IPv4-Mapped IPv6 Addresses</description>
    </item>
    <item>
      <title>Flowise: Unauthenticated Property Injection into Flow Execution Context via Ungated `overrideConfig` Spread in Predic...</title>
      <link>https://www.patchbrief.org/items/2026-08-npm-cve-2026-69258.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-08-npm-cve-2026-69258.html</guid>
      <pubDate>Tue, 04 Aug 2026 00:00:00 +0000</pubDate>
      <description>Flowise: Unauthenticated Property Injection into Flow Execution Context via Ungated `overrideConfig` Spread in Prediction API</description>
    </item>
    <item>
      <title>Flowise RCE via SQLite Record Manager Node</title>
      <link>https://www.patchbrief.org/items/2026-08-npm-cve-2026-69259.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-08-npm-cve-2026-69259.html</guid>
      <pubDate>Tue, 04 Aug 2026 00:00:00 +0000</pubDate>
      <description>Flowise RCE via SQLite Record Manager Node</description>
    </item>
    <item>
      <title>Flowise: `DELETE /api/v1/chatflows/:id` does not validate resource type, allowing `agentflows:delete` and `chatflows:...</title>
      <link>https://www.patchbrief.org/items/2026-08-npm-cve-2026-69262.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-08-npm-cve-2026-69262.html</guid>
      <pubDate>Tue, 04 Aug 2026 00:00:00 +0000</pubDate>
      <description>Flowise: `DELETE /api/v1/chatflows/:id` does not validate resource type, allowing `agentflows:delete` and `chatflows:delete` to delete each other’s flow type</description>
    </item>
    <item>
      <title>Flowise: CVE-2025-8943 Patch Bypass: npm_config_yes bypasses MCP environment variable blocklist (Unauthenticated RCE)</title>
      <link>https://www.patchbrief.org/items/2026-08-npm-cve-2026-69263.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-08-npm-cve-2026-69263.html</guid>
      <pubDate>Tue, 04 Aug 2026 00:00:00 +0000</pubDate>
      <description>Flowise: CVE-2025-8943 Patch Bypass: npm_config_yes bypasses MCP environment variable blocklist (Unauthenticated RCE)</description>
    </item>
    <item>
      <title>Flowise: RCE via CSVAgent csvFile data URI base64 segment is interpolated into Python source without validation</title>
      <link>https://www.patchbrief.org/items/2026-08-npm-cve-2026-69264.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-08-npm-cve-2026-69264.html</guid>
      <pubDate>Tue, 04 Aug 2026 00:00:00 +0000</pubDate>
      <description>Flowise: RCE via CSVAgent csvFile data URI base64 segment is interpolated into Python source without validation</description>
    </item>
    <item>
      <title>Flowise: Pyodide validator Unicode homoglyph bypass leads to RCE</title>
      <link>https://www.patchbrief.org/items/2026-08-npm-cve-2026-70470.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-08-npm-cve-2026-70470.html</guid>
      <pubDate>Tue, 04 Aug 2026 00:00:00 +0000</pubDate>
      <description>Flowise: Pyodide validator Unicode homoglyph bypass leads to RCE</description>
    </item>
    <item>
      <title>Flowise: RBAC Bypass Leading to Unauthorized Workspace Variables Disclosure</title>
      <link>https://www.patchbrief.org/items/2026-08-npm-cve-2026-70471.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-08-npm-cve-2026-70471.html</guid>
      <pubDate>Tue, 04 Aug 2026 00:00:00 +0000</pubDate>
      <description>Flowise: RBAC Bypass Leading to Unauthorized Workspace Variables Disclosure</description>
    </item>
    <item>
      <title>Flowise: Cross-workspace credential IDOR in openai-assistants-vector-store</title>
      <link>https://www.patchbrief.org/items/2026-08-npm-cve-2026-70472.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-08-npm-cve-2026-70472.html</guid>
      <pubDate>Tue, 04 Aug 2026 00:00:00 +0000</pubDate>
      <description>Flowise: Cross-workspace credential IDOR in openai-assistants-vector-store</description>
    </item>
    <item>
      <title>Flowise: Information Disclosure in GET /api/v1/upsert-history returns the entire server-wide upsert history</title>
      <link>https://www.patchbrief.org/items/2026-08-npm-cve-2026-70473.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-08-npm-cve-2026-70473.html</guid>
      <pubDate>Tue, 04 Aug 2026 00:00:00 +0000</pubDate>
      <description>Flowise: Information Disclosure in GET /api/v1/upsert-history returns the entire server-wide upsert history</description>
    </item>
    <item>
      <title>Flowise: Cross-Workspace OAuth2 Credential Metadata Leak</title>
      <link>https://www.patchbrief.org/items/2026-08-npm-cve-2026-70474.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-08-npm-cve-2026-70474.html</guid>
      <pubDate>Tue, 04 Aug 2026 00:00:00 +0000</pubDate>
      <description>Flowise: Cross-Workspace OAuth2 Credential Metadata Leak</description>
    </item>
    <item>
      <title>Flowise: Missing Authorization on Execution Update Endpoint</title>
      <link>https://www.patchbrief.org/items/2026-08-npm-cve-2026-70475.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-08-npm-cve-2026-70475.html</guid>
      <pubDate>Tue, 04 Aug 2026 00:00:00 +0000</pubDate>
      <description>Flowise: Missing Authorization on Execution Update Endpoint</description>
    </item>
    <item>
      <title>Flowise: Broken Access Control in Stripe Subscription Endpoints Allows Cross-Tenant Billing Manipulation</title>
      <link>https://www.patchbrief.org/items/2026-08-npm-cve-2026-70476.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-08-npm-cve-2026-70476.html</guid>
      <pubDate>Tue, 04 Aug 2026 00:00:00 +0000</pubDate>
      <description>Flowise: Broken Access Control in Stripe Subscription Endpoints Allows Cross-Tenant Billing Manipulation</description>
    </item>
    <item>
      <title>Flowise: CSV Agent Prompt Injection Remote Code Execution Vulnerability</title>
      <link>https://www.patchbrief.org/items/2026-08-npm-cve-2026-70477.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-08-npm-cve-2026-70477.html</guid>
      <pubDate>Tue, 04 Aug 2026 00:00:00 +0000</pubDate>
      <description>Flowise: CSV Agent Prompt Injection Remote Code Execution Vulnerability</description>
    </item>
    <item>
      <title>Flowise: Unauthenticated OAuth2 token refresh endpoint returns access tokens — enables token theft for any connected ...</title>
      <link>https://www.patchbrief.org/items/2026-08-npm-cve-2026-70478.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-08-npm-cve-2026-70478.html</guid>
      <pubDate>Tue, 04 Aug 2026 00:00:00 +0000</pubDate>
      <description>Flowise: Unauthenticated OAuth2 token refresh endpoint returns access tokens — enables token theft for any connected service</description>
    </item>
    <item>
      <title>Flowise: Authenticated arbitrary file write in the `S3 Directory` document loader via unsanitized S3 object keys</title>
      <link>https://www.patchbrief.org/items/2026-08-npm-ghsa-88pr-878c-24wf.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-08-npm-ghsa-88pr-878c-24wf.html</guid>
      <pubDate>Tue, 04 Aug 2026 00:00:00 +0000</pubDate>
      <description>Flowise: Authenticated arbitrary file write in the `S3 Directory` document loader via unsanitized S3 object keys</description>
    </item>
    <item>
      <title>Puwell IP Camera firmware — CVE-2026-61515 (Critical)</title>
      <link>https://www.patchbrief.org/items/2026-08-puwell-cve-2026-61515.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-08-puwell-cve-2026-61515.html</guid>
      <pubDate>Tue, 04 Aug 2026 00:00:00 +0000</pubDate>
      <description>Puwell IP Camera firmware versions 2.x through 4.x contains an unauthenticated command injection vulnerability that allows remote attackers to execute arbitrary operating system commands by sending a crafted JSON payload to the DebugShell interface exposed on TCP port 34567. Attackers can exploit the lack of authentication and input sanitization in the binary protocol service to pass arbitrary commands directly to the underlying operating system, achieving root-level code execution and complete device compromise.</description>
    </item>
    <item>
      <title>Open WebUI: SSRF into internal services via unvalidated sub-resource requests in the Playwright web loader</title>
      <link>https://www.patchbrief.org/items/2026-08-pypi-cve-2026-70479.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-08-pypi-cve-2026-70479.html</guid>
      <pubDate>Tue, 04 Aug 2026 00:00:00 +0000</pubDate>
      <description>Open WebUI: SSRF into internal services via unvalidated sub-resource requests in the Playwright web loader</description>
    </item>
    <item>
      <title>Open WebUI: Account takeover via OAuth token exchange accepting tokens issued to any client</title>
      <link>https://www.patchbrief.org/items/2026-08-pypi-cve-2026-70482.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-08-pypi-cve-2026-70482.html</guid>
      <pubDate>Tue, 04 Aug 2026 00:00:00 +0000</pubDate>
      <description>Open WebUI: Account takeover via OAuth token exchange accepting tokens issued to any client</description>
    </item>
    <item>
      <title>Open WebUI: Any authenticated user can reach internal services and cloud metadata via NAT64-encoded URLs</title>
      <link>https://www.patchbrief.org/items/2026-08-pypi-cve-2026-70485.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-08-pypi-cve-2026-70485.html</guid>
      <pubDate>Tue, 04 Aug 2026 00:00:00 +0000</pubDate>
      <description>Open WebUI: Any authenticated user can reach internal services and cloud metadata via NAT64-encoded URLs</description>
    </item>
    <item>
      <title>Open WebUI: Same-origin XSS to account takeover via terminal file-preview iframe hardcoding allow-same-origin</title>
      <link>https://www.patchbrief.org/items/2026-08-pypi-cve-2026-70486.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-08-pypi-cve-2026-70486.html</guid>
      <pubDate>Tue, 04 Aug 2026 00:00:00 +0000</pubDate>
      <description>Open WebUI: Same-origin XSS to account takeover via terminal file-preview iframe hardcoding allow-same-origin</description>
    </item>
    <item>
      <title>Open WebUI: Stored XSS via unescaped KaTeX render-error fallback in rendered messages</title>
      <link>https://www.patchbrief.org/items/2026-08-pypi-cve-2026-70492.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-08-pypi-cve-2026-70492.html</guid>
      <pubDate>Tue, 04 Aug 2026 00:00:00 +0000</pubDate>
      <description>Open WebUI: Stored XSS via unescaped KaTeX render-error fallback in rendered messages</description>
    </item>
    <item>
      <title>Open WebUI: A folder write-collaborator can permanently delete the owner's chats by deleting a shared subfolder</title>
      <link>https://www.patchbrief.org/items/2026-08-pypi-cve-2026-70494.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-08-pypi-cve-2026-70494.html</guid>
      <pubDate>Tue, 04 Aug 2026 00:00:00 +0000</pubDate>
      <description>Open WebUI: A folder write-collaborator can permanently delete the owner's chats by deleting a shared subfolder</description>
    </item>
    <item>
      <title>Apache Nifi — CVE-2026-68979 (Critical)</title>
      <link>https://www.patchbrief.org/items/2026-08-apache-cve-2026-68979.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-08-apache-cve-2026-68979.html</guid>
      <pubDate>Mon, 03 Aug 2026 00:00:00 +0000</pubDate>
      <description>Apache NiFI 1.10.0 through 2.10.0 provide a Parameter Context update REST API method that does not enforce authorization checking on components referencing Parameter values. Updating a Parameter Context can change parameter values that affect referencing components, but framework authorization was limited to read and write privileges on the Parameter Context itself. As a result of the missing authorization, an authenticated user authorized to modify a Parameter Context, but not authorized on referencing components, could alter Parameter values affecting those components. In deployments where a</description>
    </item>
    <item>
      <title>Apache Nifi — CVE-2026-68980 (Critical)</title>
      <link>https://www.patchbrief.org/items/2026-08-apache-cve-2026-68980.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-08-apache-cve-2026-68980.html</guid>
      <pubDate>Mon, 03 Aug 2026 00:00:00 +0000</pubDate>
      <description>Apache NiFi 2.0.0 through 2.10.0 support creating, reading, and deleting Assets associated with Parameter Contexts through the REST API. The framework authorizes asset deletion against the owning Parameter Context using the supplied Parameter Context Identifier and Asset Identifier. The framework performed authorized based on the supplied Parameter Context Identifier without verifying the requested Identifier against the stored Identifier. Apache NiFi installations that do not implement different levels of authorization across Parameter Contexts are not subject to this vulnerability, because t</description>
    </item>
    <item>
      <title>Guzzle: Noncanonical host can bypass host-based checks</title>
      <link>https://www.patchbrief.org/items/2026-08-composer-cve-2026-69246.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-08-composer-cve-2026-69246.html</guid>
      <pubDate>Mon, 03 Aug 2026 00:00:00 +0000</pubDate>
      <description>Guzzle: Noncanonical host can bypass host-based checks</description>
    </item>
    <item>
      <title>Krayin CRM 2.2.4 — CVE-2026-41452 (Critical)</title>
      <link>https://www.patchbrief.org/items/2026-08-krayin-cve-2026-41452.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-08-krayin-cve-2026-41452.html</guid>
      <pubDate>Mon, 03 Aug 2026 00:00:00 +0000</pubDate>
      <description>Krayin CRM 2.2.4 contains a missing authentication vulnerability in the installer middleware that allows unauthenticated remote attackers to overwrite the primary administrator account by sending a crafted HTTP POST request with the X-Requested-With: XMLHttpRequest header to bypass the CanInstall middleware redirect check. Attackers can supply arbitrary name, email, and password values to the admin-config-setup endpoint, which performs an unauthenticated updateOrInsert targeting the hardcoded administrator user ID, enabling full administrative access to all CRM data.</description>
    </item>
    <item>
      <title>N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability</title>
      <link>https://www.patchbrief.org/items/2026-08-n-able-cve-2026-18577.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-08-n-able-cve-2026-18577.html</guid>
      <pubDate>Mon, 03 Aug 2026 00:00:00 +0000</pubDate>
      <description>N-able N-central contains an authentication bypass using an alternate path or channel allows for authentication bypass and account takeover in N-central. This vulnerability is the result of an incomplete patch for CVE-2026-18556.</description>
    </item>
    <item>
      <title>undici vulnerable to cross-user information disclosure and parse-time crash via degenerate private cache directives</title>
      <link>https://www.patchbrief.org/items/2026-08-npm-cve-2026-13697.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-08-npm-cve-2026-13697.html</guid>
      <pubDate>Mon, 03 Aug 2026 00:00:00 +0000</pubDate>
      <description>undici vulnerable to cross-user information disclosure and parse-time crash via degenerate private cache directives</description>
    </item>
    <item>
      <title>fast-uri vulnerable to host confusion via backslash authority introducer</title>
      <link>https://www.patchbrief.org/items/2026-08-npm-cve-2026-18446.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-08-npm-cve-2026-18446.html</guid>
      <pubDate>Mon, 03 Aug 2026 00:00:00 +0000</pubDate>
      <description>fast-uri vulnerable to host confusion via backslash authority introducer</description>
    </item>
    <item>
      <title>Angular: Cache-Key Ambiguity in HttpTransferCache Leading to Cross-Request Response Reuse and State Poisoning</title>
      <link>https://www.patchbrief.org/items/2026-08-npm-cve-2026-68945.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-08-npm-cve-2026-68945.html</guid>
      <pubDate>Mon, 03 Aug 2026 00:00:00 +0000</pubDate>
      <description>Angular: Cache-Key Ambiguity in HttpTransferCache Leading to Cross-Request Response Reuse and State Poisoning</description>
    </item>
    <item>
      <title>Angular SSR: Missing Fallback Raw-Content Serialization Escaping leads to Cross-Site Scripting (XSS)</title>
      <link>https://www.patchbrief.org/items/2026-08-npm-cve-2026-69149.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-08-npm-cve-2026-69149.html</guid>
      <pubDate>Mon, 03 Aug 2026 00:00:00 +0000</pubDate>
      <description>Angular SSR: Missing Fallback Raw-Content Serialization Escaping leads to Cross-Site Scripting (XSS)</description>
    </item>
    <item>
      <title>Angular i18n: Cross-Site Scripting (XSS) via event-handler attributes</title>
      <link>https://www.patchbrief.org/items/2026-08-npm-cve-2026-69151.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-08-npm-cve-2026-69151.html</guid>
      <pubDate>Mon, 03 Aug 2026 00:00:00 +0000</pubDate>
      <description>Angular i18n: Cross-Site Scripting (XSS) via event-handler attributes</description>
    </item>
    <item>
      <title>brace-expansion: DoS via unbounded intermediate arrays, bypassing the CVE-2026-14257 mitigation</title>
      <link>https://www.patchbrief.org/items/2026-08-npm-cve-2026-69152.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-08-npm-cve-2026-69152.html</guid>
      <pubDate>Mon, 03 Aug 2026 00:00:00 +0000</pubDate>
      <description>brace-expansion: DoS via unbounded intermediate arrays, bypassing the CVE-2026-14257 mitigation</description>
    </item>
    <item>
      <title>Socket.IO: Zero-attachment Memory Exhaustion</title>
      <link>https://www.patchbrief.org/items/2026-08-npm-cve-2026-69185.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-08-npm-cve-2026-69185.html</guid>
      <pubDate>Mon, 03 Aug 2026 00:00:00 +0000</pubDate>
      <description>Socket.IO: Zero-attachment Memory Exhaustion</description>
    </item>
    <item>
      <title>ip-address: Address4 decodes leading-zero octets as decimal while resolvers decode them as octal, allowing SSRF and t...</title>
      <link>https://www.patchbrief.org/items/2026-08-npm-cve-2026-69192.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-08-npm-cve-2026-69192.html</guid>
      <pubDate>Mon, 03 Aug 2026 00:00:00 +0000</pubDate>
      <description>ip-address: Address4 decodes leading-zero octets as decimal while resolvers decode them as octal, allowing SSRF and trust-boundary bypass</description>
    </item>
    <item>
      <title>Sequelize: SQL Injection (Oracle DB)</title>
      <link>https://www.patchbrief.org/items/2026-08-npm-cve-2026-69240.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-08-npm-cve-2026-69240.html</guid>
      <pubDate>Mon, 03 Aug 2026 00:00:00 +0000</pubDate>
      <description>Sequelize: SQL Injection (Oracle DB)</description>
    </item>
    <item>
      <title>AIOHTTP: Out-of-bounds heap read in C HTTP response parser error path (malformed chunked response)</title>
      <link>https://www.patchbrief.org/items/2026-08-pypi-cve-2026-69244.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-08-pypi-cve-2026-69244.html</guid>
      <pubDate>Mon, 03 Aug 2026 00:00:00 +0000</pubDate>
      <description>AIOHTTP: Out-of-bounds heap read in C HTTP response parser error path (malformed chunked response)</description>
    </item>
    <item>
      <title>cryptography: PKCS#7 EnvelopedData decryption exposes a Bleichenbacher oracle through distinguishable errors and timing</title>
      <link>https://www.patchbrief.org/items/2026-08-pypi-cve-2026-69247.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-08-pypi-cve-2026-69247.html</guid>
      <pubDate>Mon, 03 Aug 2026 00:00:00 +0000</pubDate>
      <description>cryptography: PKCS#7 EnvelopedData decryption exposes a Bleichenbacher oracle through distinguishable errors and timing</description>
    </item>
    <item>
      <title>python-cryptography: Duplicate self-signed intermediates can cause exponential path-building</title>
      <link>https://www.patchbrief.org/items/2026-08-pypi-cve-2026-69249.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-08-pypi-cve-2026-69249.html</guid>
      <pubDate>Mon, 03 Aug 2026 00:00:00 +0000</pubDate>
      <description>python-cryptography: Duplicate self-signed intermediates can cause exponential path-building</description>
    </item>
    <item>
      <title>GitPython: Unguarded git option forwarding in IndexFile.checkout() and TagReference.create() enables arbitrary file o...</title>
      <link>https://www.patchbrief.org/items/2026-08-pypi-ghsa-3f7w-8rr8-f37f.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-08-pypi-ghsa-3f7w-8rr8-f37f.html</guid>
      <pubDate>Mon, 03 Aug 2026 00:00:00 +0000</pubDate>
      <description>GitPython: Unguarded git option forwarding in IndexFile.checkout() and TagReference.create() enables arbitrary file overwrite and arbitrary file read</description>
    </item>
    <item>
      <title>Redaxo has a Mediapool isAllowedExtension bypass via multi-segment filename that leads to authenticated RCE on Apache...</title>
      <link>https://www.patchbrief.org/items/2026-07-composer-cve-2026-53599.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-composer-cve-2026-53599.html</guid>
      <pubDate>Fri, 31 Jul 2026 00:00:00 +0000</pubDate>
      <description>Redaxo has a Mediapool isAllowedExtension bypass via multi-segment filename that leads to authenticated RCE on Apache mod_php multi-extension handlers</description>
    </item>
    <item>
      <title>Sylius Mollie Plugin vulnerable to payment status forgery via the payment webhook</title>
      <link>https://www.patchbrief.org/items/2026-07-composer-cve-2026-68500.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-composer-cve-2026-68500.html</guid>
      <pubDate>Fri, 31 Jul 2026 00:00:00 +0000</pubDate>
      <description>Sylius Mollie Plugin vulnerable to payment status forgery via the payment webhook</description>
    </item>
    <item>
      <title>Wings exposes node configuration secrets through egg configuration-file templating</title>
      <link>https://www.patchbrief.org/items/2026-07-go-cve-2026-52855.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-go-cve-2026-52855.html</guid>
      <pubDate>Fri, 31 Jul 2026 00:00:00 +0000</pubDate>
      <description>Wings exposes node configuration secrets through egg configuration-file templating</description>
    </item>
    <item>
      <title>Wings: Maliciously crafted packet during SFTP connection handshake causes denial of service</title>
      <link>https://www.patchbrief.org/items/2026-07-go-cve-2026-52856.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-go-cve-2026-52856.html</guid>
      <pubDate>Fri, 31 Jul 2026 00:00:00 +0000</pubDate>
      <description>Wings: Maliciously crafted packet during SFTP connection handshake causes denial of service</description>
    </item>
    <item>
      <title>vault-addr annotation SSRF -- webhook makes outbound HTTP call to attacker URL during admission; vault-serviceaccount...</title>
      <link>https://www.patchbrief.org/items/2026-07-go-cve-2026-54725.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-go-cve-2026-54725.html</guid>
      <pubDate>Fri, 31 Jul 2026 00:00:00 +0000</pubDate>
      <description>vault-addr annotation SSRF -- webhook makes outbound HTTP call to attacker URL during admission; vault-serviceaccount enables cluster-wide SA token theft via TokenRequest API</description>
    </item>
    <item>
      <title>FileBrowser Quantum's path traversal issue in subtitle handler allows any authenticated user to read arbitrary files</title>
      <link>https://www.patchbrief.org/items/2026-07-go-cve-2026-54910.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-go-cve-2026-54910.html</guid>
      <pubDate>Fri, 31 Jul 2026 00:00:00 +0000</pubDate>
      <description>FileBrowser Quantum's path traversal issue in subtitle handler allows any authenticated user to read arbitrary files</description>
    </item>
    <item>
      <title>Spring Data: Unbounded property-path cache keyed by externally-supplied path string</title>
      <link>https://www.patchbrief.org/items/2026-07-maven-cve-2026-41695.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-maven-cve-2026-41695.html</guid>
      <pubDate>Fri, 31 Jul 2026 00:00:00 +0000</pubDate>
      <description>Spring Data: Unbounded property-path cache keyed by externally-supplied path string</description>
    </item>
    <item>
      <title>Netty: HTTP/2 decompression leaks ByteBuf reference count when the decompressor channel is already closed (Direct mem...</title>
      <link>https://www.patchbrief.org/items/2026-07-maven-cve-2026-56819.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-maven-cve-2026-56819.html</guid>
      <pubDate>Fri, 31 Jul 2026 00:00:00 +0000</pubDate>
      <description>Netty: HTTP/2 decompression leaks ByteBuf reference count when the decompressor channel is already closed (Direct memory leak / OOM DoS)</description>
    </item>
    <item>
      <title>VU#243636: VPS.org one-click deployment templates contain multiple vulnerabilities</title>
      <link>https://www.patchbrief.org/items/2026-07-multiple-vendors-vu-243636.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-multiple-vendors-vu-243636.html</guid>
      <pubDate>Fri, 31 Jul 2026 00:00:00 +0000</pubDate>
      <description>Overview VPS.org's one-click deployment templates provision services with default passwords and predefined network bindings instead of generating randomized secrets or applying per-deployment hardening measures. Description VPS.org is a cloud and virtual private server hosting provider that offers a library of templates for quickly provisioning common applications and services. Multiple vulnerabilities exist in the one-click deployment templates feature. These vulnerabilities stem from the same root cause: content is directly instantiated from static templates, using default passwords and static secrets with no deployment-specific randomization or interface-binding hardening at provisioning time. CVE-2026-16503 The Supabase template provides an instance of PostgreSQL that is bound to all network interfaces (0.0.0.0:5432) and uses the... Related CVEs: CVE-2026-16503, CVE-2026-16504.</description>
    </item>
    <item>
      <title>NocoBase: SQL injection in /api/myInAppChannels:list filter to PG-superuser RCE</title>
      <link>https://www.patchbrief.org/items/2026-07-npm-cve-2026-52887.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-npm-cve-2026-52887.html</guid>
      <pubDate>Fri, 31 Jul 2026 00:00:00 +0000</pubDate>
      <description>NocoBase: SQL injection in /api/myInAppChannels:list filter to PG-superuser RCE</description>
    </item>
    <item>
      <title>@apostrophecms/seo Vulnerable to Stored XSS via Unsanitized Google Analytics / GTM ID Injected into Script Tag</title>
      <link>https://www.patchbrief.org/items/2026-07-npm-cve-2026-53608.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-npm-cve-2026-53608.html</guid>
      <pubDate>Fri, 31 Jul 2026 00:00:00 +0000</pubDate>
      <description>@apostrophecms/seo Vulnerable to Stored XSS via Unsanitized Google Analytics / GTM ID Injected into Script Tag</description>
    </item>
    <item>
      <title>Apostrophe has Server-Side Prototype Pollution in apos.util.set via patch operators that leads to process-wide author...</title>
      <link>https://www.patchbrief.org/items/2026-07-npm-cve-2026-53609.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-npm-cve-2026-53609.html</guid>
      <pubDate>Fri, 31 Jul 2026 00:00:00 +0000</pubDate>
      <description>Apostrophe has Server-Side Prototype Pollution in apos.util.set via patch operators that leads to process-wide authorization bypass</description>
    </item>
    <item>
      <title>dssrf: any users using 1.1.1.1 DNS is impacted by SSRF</title>
      <link>https://www.patchbrief.org/items/2026-07-npm-cve-2026-54729.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-npm-cve-2026-54729.html</guid>
      <pubDate>Fri, 31 Jul 2026 00:00:00 +0000</pubDate>
      <description>dssrf: any users using 1.1.1.1 DNS is impacted by SSRF</description>
    </item>
    <item>
      <title>@phun-ky/defaults-deep Has a Prototype Pollution issue via Unsafe Recursive Property Merging</title>
      <link>https://www.patchbrief.org/items/2026-07-npm-cve-2026-54737.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-npm-cve-2026-54737.html</guid>
      <pubDate>Fri, 31 Jul 2026 00:00:00 +0000</pubDate>
      <description>@phun-ky/defaults-deep Has a Prototype Pollution issue via Unsafe Recursive Property Merging</description>
    </item>
    <item>
      <title>hashi-vault-js has a path traversal and query parameter injection</title>
      <link>https://www.patchbrief.org/items/2026-07-npm-cve-2026-55100.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-npm-cve-2026-55100.html</guid>
      <pubDate>Fri, 31 Jul 2026 00:00:00 +0000</pubDate>
      <description>hashi-vault-js has a path traversal and query parameter injection</description>
    </item>
    <item>
      <title>Jodit Editor: Mutation XSS in jodit clean-html via a MathML/style rawtext carrier</title>
      <link>https://www.patchbrief.org/items/2026-07-npm-cve-2026-58263.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-npm-cve-2026-58263.html</guid>
      <pubDate>Fri, 31 Jul 2026 00:00:00 +0000</pubDate>
      <description>Jodit Editor: Mutation XSS in jodit clean-html via a MathML/style rawtext carrier</description>
    </item>
    <item>
      <title>`@dynatrace-oss/dynatrace-mcp-server` has Unauthenticated HTTP MCP Tool Invocation</title>
      <link>https://www.patchbrief.org/items/2026-07-npm-ghsa-p7w7-4929-vpj5.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-npm-ghsa-p7w7-4929-vpj5.html</guid>
      <pubDate>Fri, 31 Jul 2026 00:00:00 +0000</pubDate>
      <description>`@dynatrace-oss/dynatrace-mcp-server` has Unauthenticated HTTP MCP Tool Invocation</description>
    </item>
    <item>
      <title>Natural Language Toolkit (NLTK): ReDoS in NLTK ReviewsCorpusReader FEATURES regex</title>
      <link>https://www.patchbrief.org/items/2026-07-pypi-cve-2026-12061.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-pypi-cve-2026-12061.html</guid>
      <pubDate>Fri, 31 Jul 2026 00:00:00 +0000</pubDate>
      <description>Natural Language Toolkit (NLTK): ReDoS in NLTK ReviewsCorpusReader FEATURES regex</description>
    </item>
    <item>
      <title>Natural Language Toolkit (NLTK): Path Traversal in NKJPCorpusReader leads to Arbitrary File Read and bypasses the nlt...</title>
      <link>https://www.patchbrief.org/items/2026-07-pypi-cve-2026-12072.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-pypi-cve-2026-12072.html</guid>
      <pubDate>Fri, 31 Jul 2026 00:00:00 +0000</pubDate>
      <description>Natural Language Toolkit (NLTK): Path Traversal in NKJPCorpusReader leads to Arbitrary File Read and bypasses the nltk.pathsec sandbox (ENFORCE=True)</description>
    </item>
    <item>
      <title>Natural Language Toolkit (NLTK) has path traversal in FramenetCorpusReader.frame() that allows arbitrary XML file rea...</title>
      <link>https://www.patchbrief.org/items/2026-07-pypi-cve-2026-12074.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-pypi-cve-2026-12074.html</guid>
      <pubDate>Fri, 31 Jul 2026 00:00:00 +0000</pubDate>
      <description>Natural Language Toolkit (NLTK) has path traversal in FramenetCorpusReader.frame() that allows arbitrary XML file read, bypassing the nltk.pathsec sandbox (ENFORCE=True)</description>
    </item>
    <item>
      <title>Natural Language Toolkit (NLTK): DNS-rebinding SSRF filter bypass in nltk.pathsec.urlopen (nltk.download / nltk.data....</title>
      <link>https://www.patchbrief.org/items/2026-07-pypi-cve-2026-12075.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-pypi-cve-2026-12075.html</guid>
      <pubDate>Fri, 31 Jul 2026 00:00:00 +0000</pubDate>
      <description>Natural Language Toolkit (NLTK): DNS-rebinding SSRF filter bypass in nltk.pathsec.urlopen (nltk.download / nltk.data.load) defeats ENFORCE mode</description>
    </item>
    <item>
      <title>Thumbor treats ALLOWED_SOURCES string patterns as unescaped regex, allowing hostname bypass via wildcard dot</title>
      <link>https://www.patchbrief.org/items/2026-07-pypi-cve-2026-53500.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-pypi-cve-2026-53500.html</guid>
      <pubDate>Fri, 31 Jul 2026 00:00:00 +0000</pubDate>
      <description>Thumbor treats ALLOWED_SOURCES string patterns as unescaped regex, allowing hostname bypass via wildcard dot</description>
    </item>
    <item>
      <title>Thumbor has HMAC validation bypass via multiple .replace() calls when removing URL signature</title>
      <link>https://www.patchbrief.org/items/2026-07-pypi-cve-2026-53501.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-pypi-cve-2026-53501.html</guid>
      <pubDate>Fri, 31 Jul 2026 00:00:00 +0000</pubDate>
      <description>Thumbor has HMAC validation bypass via multiple .replace() calls when removing URL signature</description>
    </item>
    <item>
      <title>Thumbor has path traversal via post-validation URL decoding bypass in file_loader</title>
      <link>https://www.patchbrief.org/items/2026-07-pypi-cve-2026-53502.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-pypi-cve-2026-53502.html</guid>
      <pubDate>Fri, 31 Jul 2026 00:00:00 +0000</pubDate>
      <description>Thumbor has path traversal via post-validation URL decoding bypass in file_loader</description>
    </item>
    <item>
      <title>Thumbor convolution filter allows divide-by-zero in C extension leading to remote DoS</title>
      <link>https://www.patchbrief.org/items/2026-07-pypi-cve-2026-53503.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-pypi-cve-2026-53503.html</guid>
      <pubDate>Fri, 31 Jul 2026 00:00:00 +0000</pubDate>
      <description>Thumbor convolution filter allows divide-by-zero in C extension leading to remote DoS</description>
    </item>
    <item>
      <title>Thumbor has Regex Denial of Service (ReDoS) in `convolution` filter</title>
      <link>https://www.patchbrief.org/items/2026-07-pypi-cve-2026-53504.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-pypi-cve-2026-53504.html</guid>
      <pubDate>Fri, 31 Jul 2026 00:00:00 +0000</pubDate>
      <description>Thumbor has Regex Denial of Service (ReDoS) in `convolution` filter</description>
    </item>
    <item>
      <title>Thumbor proportion filter allows unbounded post-transform resize leading to remote DoS</title>
      <link>https://www.patchbrief.org/items/2026-07-pypi-cve-2026-53505.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-pypi-cve-2026-53505.html</guid>
      <pubDate>Fri, 31 Jul 2026 00:00:00 +0000</pubDate>
      <description>Thumbor proportion filter allows unbounded post-transform resize leading to remote DoS</description>
    </item>
    <item>
      <title>Savon::Model evaluates WSDL operation names as Ruby source</title>
      <link>https://www.patchbrief.org/items/2026-07-rubygems-cve-2026-53510.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-rubygems-cve-2026-53510.html</guid>
      <pubDate>Fri, 31 Jul 2026 00:00:00 +0000</pubDate>
      <description>Savon::Model evaluates WSDL operation names as Ruby source</description>
    </item>
    <item>
      <title>OliveTin: Unauthenticated DoS via OAuth2 State Memory Exhaustion (Unbounded Map Growth)</title>
      <link>https://www.patchbrief.org/items/2026-07-go-cve-2026-67437.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-go-cve-2026-67437.html</guid>
      <pubDate>Thu, 30 Jul 2026 00:00:00 +0000</pubDate>
      <description>OliveTin: Unauthenticated DoS via OAuth2 State Memory Exhaustion (Unbounded Map Growth)</description>
    </item>
    <item>
      <title>VU#790363: foreUP golf management platform's web API contains multiple vulnerabilities</title>
      <link>https://www.patchbrief.org/items/2026-07-multiple-vendors-vu-790363.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-multiple-vendors-vu-790363.html</guid>
      <pubDate>Thu, 30 Jul 2026 00:00:00 +0000</pubDate>
      <description>Overview Two vulnerabilities in the REST API were found in Golf Compete foreUP. The first exposes the merchant, Finix, API credentials directly in customer record responses, allowing any user to obtain and use the payment processor account. The second is a missing object-level authorization check, which lets a user retrieve any other customer's full profile, payment token, and transaction history by changing the golfer_id in the request path. Description Golf Compete foreUP provides cloud-based golf course management software to over 2,000 golf courses. They offer tools that allow the management of customers, inventory, tee times, food &amp; beverages, marketing, billing, etc. The vulnerabilities identified are listed below. CVE-2026-15657 A vulnerability in the foreUP customer REST API exposes merchant credentials. Each customer record... Related CVEs: CVE-2026-15657, CVE-2026-15658.</description>
    </item>
    <item>
      <title>AWS Amplify Studio UI Component Properties Has an Input Validation Issue</title>
      <link>https://www.patchbrief.org/items/2026-07-npm-cve-2025-4318.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-npm-cve-2025-4318.html</guid>
      <pubDate>Thu, 30 Jul 2026 00:00:00 +0000</pubDate>
      <description>AWS Amplify Studio UI Component Properties Has an Input Validation Issue</description>
    </item>
    <item>
      <title>dssrf has an SSRF bypass with remove_at_symbol_in_string</title>
      <link>https://www.patchbrief.org/items/2026-07-npm-cve-2026-54722.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-npm-cve-2026-54722.html</guid>
      <pubDate>Thu, 30 Jul 2026 00:00:00 +0000</pubDate>
      <description>dssrf has an SSRF bypass with remove_at_symbol_in_string</description>
    </item>
    <item>
      <title>OpenClaw Dashboard v3.0.0 — CVE-2026-66418 (Critical)</title>
      <link>https://www.patchbrief.org/items/2026-07-openclaw-cve-2026-66418.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-openclaw-cve-2026-66418.html</guid>
      <pubDate>Thu, 30 Jul 2026 00:00:00 +0000</pubDate>
      <description>OpenClaw Dashboard v3.0.0 contains a stored cross-site scripting vulnerability that allows unauthenticated remote attackers to inject arbitrary HTML and script payloads by submitting a crafted username in a failed login POST request, which is recorded verbatim in the audit log. When an administrator opens the notification panel, the unescaped log entry is rendered via innerHTML with a permissive Content-Security-Policy allowing inline event handlers, enabling the attacker-supplied payload to execute in the administrator's session and interact with authenticated endpoints including agent instru</description>
    </item>
    <item>
      <title>OpenClaw Dashboard — CVE-2026-66421 (Critical)</title>
      <link>https://www.patchbrief.org/items/2026-07-openclaw-cve-2026-66421.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-openclaw-cve-2026-66421.html</guid>
      <pubDate>Thu, 30 Jul 2026 00:00:00 +0000</pubDate>
      <description>OpenClaw Dashboard contains a stored cross-site scripting vulnerability that allows unauthenticated remote attackers to execute arbitrary JavaScript in the administrator's browser session by injecting HTML markup into agent transcript messages processed through the sessions API. Attackers can craft a message containing inline event handler payloads such as an img tag with an onerror attribute within the 60-character rendering budget, which is stored in the session transcript and interpolated unsanitized into innerHTML on the default landing page, allowing theft of session tokens and unauthoriz</description>
    </item>
    <item>
      <title>Flyto2 Core: Guarded HTTP modules follow redirects into internal space without per-hop SSRF revalidation</title>
      <link>https://www.patchbrief.org/items/2026-07-pypi-cve-2026-67424.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-pypi-cve-2026-67424.html</guid>
      <pubDate>Thu, 30 Jul 2026 00:00:00 +0000</pubDate>
      <description>Flyto2 Core: Guarded HTTP modules follow redirects into internal space without per-hop SSRF revalidation</description>
    </item>
    <item>
      <title>Flyto2 Core: LLM/API keys leak to an attacker-controlled base_url</title>
      <link>https://www.patchbrief.org/items/2026-07-pypi-cve-2026-67425.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-pypi-cve-2026-67425.html</guid>
      <pubDate>Thu, 30 Jul 2026 00:00:00 +0000</pubDate>
      <description>Flyto2 Core: LLM/API keys leak to an attacker-controlled base_url</description>
    </item>
    <item>
      <title>Flyto2 Core: Unauthenticated flyto-verification /run: callback_url SSRF and internal runner-secret exfiltration</title>
      <link>https://www.patchbrief.org/items/2026-07-pypi-cve-2026-67426.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-pypi-cve-2026-67426.html</guid>
      <pubDate>Thu, 30 Jul 2026 00:00:00 +0000</pubDate>
      <description>Flyto2 Core: Unauthenticated flyto-verification /run: callback_url SSRF and internal runner-secret exfiltration</description>
    </item>
    <item>
      <title>Flyto2 Core: ${env.VAR} interpolation reads any env secret despite env.get being denylisted</title>
      <link>https://www.patchbrief.org/items/2026-07-pypi-cve-2026-67427.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-pypi-cve-2026-67427.html</guid>
      <pubDate>Thu, 30 Jul 2026 00:00:00 +0000</pubDate>
      <description>Flyto2 Core: ${env.VAR} interpolation reads any env secret despite env.get being denylisted</description>
    </item>
    <item>
      <title>Flyto2 Core: Multiple HTTP-family modules fetch client-controlled URLs without the SSRF guard their siblings apply (S...</title>
      <link>https://www.patchbrief.org/items/2026-07-pypi-cve-2026-67428.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-pypi-cve-2026-67428.html</guid>
      <pubDate>Thu, 30 Jul 2026 00:00:00 +0000</pubDate>
      <description>Flyto2 Core: Multiple HTTP-family modules fetch client-controlled URLs without the SSRF guard their siblings apply (SSRF to internal/metadata)</description>
    </item>
    <item>
      <title>Flyto2 Core: Arbitrary file write via image.download (and other file-writing modules)</title>
      <link>https://www.patchbrief.org/items/2026-07-pypi-cve-2026-67429.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-pypi-cve-2026-67429.html</guid>
      <pubDate>Thu, 30 Jul 2026 00:00:00 +0000</pubDate>
      <description>Flyto2 Core: Arbitrary file write via image.download (and other file-writing modules)</description>
    </item>
    <item>
      <title>Active Storage has possible arbitrary file read and remote code execution in Active Storage variant processing</title>
      <link>https://www.patchbrief.org/items/2026-07-rubygems-cve-2026-66066.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-rubygems-cve-2026-66066.html</guid>
      <pubDate>Thu, 30 Jul 2026 00:00:00 +0000</pubDate>
      <description>Active Storage has possible arbitrary file read and remote code execution in Active Storage variant processing</description>
    </item>
    <item>
      <title>MCP Ruby SDK: Ruby SSE Session Poisoning</title>
      <link>https://www.patchbrief.org/items/2026-07-rubygems-cve-2026-67431.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-rubygems-cve-2026-67431.html</guid>
      <pubDate>Thu, 30 Jul 2026 00:00:00 +0000</pubDate>
      <description>MCP Ruby SDK: Ruby SSE Session Poisoning</description>
    </item>
    <item>
      <title>MCP Ruby SDK: Unbounded JSON-RPC request body causes uncontrolled memory allocation in StreamableHTTPTransport</title>
      <link>https://www.patchbrief.org/items/2026-07-rubygems-cve-2026-67432.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-rubygems-cve-2026-67432.html</guid>
      <pubDate>Thu, 30 Jul 2026 00:00:00 +0000</pubDate>
      <description>MCP Ruby SDK: Unbounded JSON-RPC request body causes uncontrolled memory allocation in StreamableHTTPTransport</description>
    </item>
    <item>
      <title>VU#281278: SGLang contains six different vulnerabilities including RCE, data exfiltration, and credential disclosure</title>
      <link>https://www.patchbrief.org/items/2026-07-sglang-vu-281278.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-sglang-vu-281278.html</guid>
      <pubDate>Thu, 30 Jul 2026 00:00:00 +0000</pubDate>
      <description>Overview Six vulnerabilities have been discovered within the SGLang project, including remote code execution (RCE), server-side request forgery (SSRF), local file read, credential leakage, and model weight exfiltration on a target server. Exploitation does not require authentication in most cases, and some vulnerabilities require only network access with no API keys or user credentials. At the time of publication, no patches are available from the project maintainers, and coordination attempts have been unsuccessful. Description SGLang is an open-source framework for serving large language models (LLMs) and multimodal AI models, supporting models such as Qwen, DeepSeek, Mistral, and Skywork, and is compatible with OpenAI APIs. Six vulnerabilities have been discovered within the tool and are tracked as follows: CVE-2026-15969 SGLang... Related CVEs: CVE-2026-14890, CVE-2026-15969, CVE-2026-15971, CVE-2026-15974.</description>
    </item>
    <item>
      <title>Care Everywhere Gateway 14.3.10 — CVE-2026-41939 (Critical)</title>
      <link>https://www.patchbrief.org/items/2026-07-care-cve-2026-41939.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-care-cve-2026-41939.html</guid>
      <pubDate>Wed, 29 Jul 2026 00:00:00 +0000</pubDate>
      <description>Care Everywhere Gateway 14.3.10 contains a hard-coded credentials vulnerability in the bundled WildFly 8.2.0.Final management interface that allows unauthenticated remote attackers to gain administrative access by using default credentials identical across all installations. Attackers can authenticate to the exposed WildFly management console on port 20990 and deploy a malicious Web Application Archive file through the Deployments interface to achieve remote code execution as the Windows machine account. Version 14.x.x was declared end-of-life (EOL) in 2017 and future releases have addressed t</description>
    </item>
    <item>
      <title>Cisco Secure Firewall Management Center Use of Hard-coded Password Vulnerability</title>
      <link>https://www.patchbrief.org/items/2026-07-cisco-cve-2026-20316.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-cisco-cve-2026-20316.html</guid>
      <pubDate>Wed, 29 Jul 2026 00:00:00 +0000</pubDate>
      <description>Cisco Secure Firewall Management Center (FMC) formerly known as Firepower Management Center contains a use of hard-coded password vulnerability that could allow an unauthenticated, remote attacker to log in to an affected device using a low-privileged account to access sensitive data within the impacted systems.</description>
    </item>
    <item>
      <title>Easy!Appointments Vulnerable to Appointments Takeover via Excessive Data Exposure</title>
      <link>https://www.patchbrief.org/items/2026-07-composer-cve-2026-55651.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-composer-cve-2026-55651.html</guid>
      <pubDate>Wed, 29 Jul 2026 00:00:00 +0000</pubDate>
      <description>Easy!Appointments Vulnerable to Appointments Takeover via Excessive Data Exposure</description>
    </item>
    <item>
      <title>VU#293714: Arbitrary File Overwrite in Develar app-builder (zipx.Unzip) via Symlink Following on macOS (APFS)</title>
      <link>https://www.patchbrief.org/items/2026-07-develar-vu-293714.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-develar-vu-293714.html</guid>
      <pubDate>Wed, 29 Jul 2026 00:00:00 +0000</pubDate>
      <description>Overview A vulnerability in the zipx.Unzip extraction routine of Develar’s app-builder allows an attacker to overwrite arbitrary files on macOS using Apple File System (APFS). The issue arises from a combination of Unicode normalization collisions and unsafe symlink-following behavior. APFS treats certain Unicode equivalent filenames as identical (e.g., ß ↔ ss), while app builder performs no canonical normalization before validating or writing paths. Description Develar’s app-builder is a command‑line build tool used heavily in the Electron ecosystem to package, sign, notarize, and produce distributable application bundles for macOS, Windows, and Linux. It is popular because it is a transitive dependency of electron-builder, one of the most widely used packaging tools for Electron apps. The vulnerability arises from how the zipx.Unzip...</description>
    </item>
    <item>
      <title>Req vulnerable to unbounded archive/compression extraction triggered by response content-type</title>
      <link>https://www.patchbrief.org/items/2026-07-erlang-cve-2026-49755.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-erlang-cve-2026-49755.html</guid>
      <pubDate>Wed, 29 Jul 2026 00:00:00 +0000</pubDate>
      <description>Req vulnerable to unbounded archive/compression extraction triggered by response content-type</description>
    </item>
    <item>
      <title>Logging operator has Fluentd configuration injection that allows remote code execution</title>
      <link>https://www.patchbrief.org/items/2026-07-go-cve-2026-54680.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-go-cve-2026-54680.html</guid>
      <pubDate>Wed, 29 Jul 2026 00:00:00 +0000</pubDate>
      <description>Logging operator has Fluentd configuration injection that allows remote code execution</description>
    </item>
    <item>
      <title>ZITADEL Users Can Self-Verify Email/Phone via API</title>
      <link>https://www.patchbrief.org/items/2026-07-go-cve-2026-54693.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-go-cve-2026-54693.html</guid>
      <pubDate>Wed, 29 Jul 2026 00:00:00 +0000</pubDate>
      <description>ZITADEL Users Can Self-Verify Email/Phone via API</description>
    </item>
    <item>
      <title>prebid-server's request forgery vulnerability allows for possible host environment data extraction</title>
      <link>https://www.patchbrief.org/items/2026-07-go-cve-2026-54735.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-go-cve-2026-54735.html</guid>
      <pubDate>Wed, 29 Jul 2026 00:00:00 +0000</pubDate>
      <description>prebid-server's request forgery vulnerability allows for possible host environment data extraction</description>
    </item>
    <item>
      <title>netfoil: Incorrect block responses could lead to localhost traffic</title>
      <link>https://www.patchbrief.org/items/2026-07-go-ghsa-xvg2-cgv6-6h7v.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-go-ghsa-xvg2-cgv6-6h7v.html</guid>
      <pubDate>Wed, 29 Jul 2026 00:00:00 +0000</pubDate>
      <description>netfoil: Incorrect block responses could lead to localhost traffic</description>
    </item>
    <item>
      <title>Quarkus: Authentication/Authorization Bypass via Advanced Path Normalization Vulnerabilities</title>
      <link>https://www.patchbrief.org/items/2026-07-maven-cve-2026-50559.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-maven-cve-2026-50559.html</guid>
      <pubDate>Wed, 29 Jul 2026 00:00:00 +0000</pubDate>
      <description>Quarkus: Authentication/Authorization Bypass via Advanced Path Normalization Vulnerabilities</description>
    </item>
    <item>
      <title>veraPDF Validation XXE via Rich Text</title>
      <link>https://www.patchbrief.org/items/2026-07-maven-cve-2026-54078.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-maven-cve-2026-54078.html</guid>
      <pubDate>Wed, 29 Jul 2026 00:00:00 +0000</pubDate>
      <description>veraPDF Validation XXE via Rich Text</description>
    </item>
    <item>
      <title>veraPDF Validation XXE via XFA</title>
      <link>https://www.patchbrief.org/items/2026-07-maven-cve-2026-54079.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-maven-cve-2026-54079.html</guid>
      <pubDate>Wed, 29 Jul 2026 00:00:00 +0000</pubDate>
      <description>veraPDF Validation XXE via XFA</description>
    </item>
    <item>
      <title>AgentCore CLI Bedrock Agent Import Vulnerable to Code Injection via Improper Triple-Quote Escaping</title>
      <link>https://www.patchbrief.org/items/2026-07-npm-cve-2026-11393.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-npm-cve-2026-11393.html</guid>
      <pubDate>Wed, 29 Jul 2026 00:00:00 +0000</pubDate>
      <description>AgentCore CLI Bedrock Agent Import Vulnerable to Code Injection via Improper Triple-Quote Escaping</description>
    </item>
    <item>
      <title>swagger-typescript-api vulnerable to authorization-token exfiltration via spec `$ref`</title>
      <link>https://www.patchbrief.org/items/2026-07-npm-cve-2026-54660.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-npm-cve-2026-54660.html</guid>
      <pubDate>Wed, 29 Jul 2026 00:00:00 +0000</pubDate>
      <description>swagger-typescript-api vulnerable to authorization-token exfiltration via spec `$ref`</description>
    </item>
    <item>
      <title>swagger-typescript-api vulnerable to code injection via unescaped `servers[0].url` in axios http-client template</title>
      <link>https://www.patchbrief.org/items/2026-07-npm-cve-2026-54661.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-npm-cve-2026-54661.html</guid>
      <pubDate>Wed, 29 Jul 2026 00:00:00 +0000</pubDate>
      <description>swagger-typescript-api vulnerable to code injection via unescaped `servers[0].url` in axios http-client template</description>
    </item>
    <item>
      <title>swagger-typescript-api vulnerable to code injection via unescaped `servers[0].url` in fetch http-client template</title>
      <link>https://www.patchbrief.org/items/2026-07-npm-cve-2026-54662.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-npm-cve-2026-54662.html</guid>
      <pubDate>Wed, 29 Jul 2026 00:00:00 +0000</pubDate>
      <description>swagger-typescript-api vulnerable to code injection via unescaped `servers[0].url` in fetch http-client template</description>
    </item>
    <item>
      <title>swagger-typescript-api vulnerable to code injection via unescaped enum string values</title>
      <link>https://www.patchbrief.org/items/2026-07-npm-cve-2026-54664.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-npm-cve-2026-54664.html</guid>
      <pubDate>Wed, 29 Jul 2026 00:00:00 +0000</pubDate>
      <description>swagger-typescript-api vulnerable to code injection via unescaped enum string values</description>
    </item>
    <item>
      <title>swagger-typescript-api vulnerable to code injection via unescaped OpenAPI path strings in generated method bodies</title>
      <link>https://www.patchbrief.org/items/2026-07-npm-cve-2026-54666.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-npm-cve-2026-54666.html</guid>
      <pubDate>Wed, 29 Jul 2026 00:00:00 +0000</pubDate>
      <description>swagger-typescript-api vulnerable to code injection via unescaped OpenAPI path strings in generated method bodies</description>
    </item>
    <item>
      <title>VU#305509: OPeNDAP Hyrax is vulnerable to SSRF and Credential Disclosure</title>
      <link>https://www.patchbrief.org/items/2026-07-opendap-vu-305509.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-opendap-vu-305509.html</guid>
      <pubDate>Wed, 29 Jul 2026 00:00:00 +0000</pubDate>
      <description>Overview A vulnerability has been discovered in the OPeNDAP Hyrax software solution. A remote attacker with the ability to submit crafted requests to an affected Hyrax instance could cause the application to communicate with unauthorized remote systems. Under certain conditions, the vulnerability may also result in the unintended disclosure of user authentication tokens to unauthorized destinations. Description CVE-2026-16637 OPeNDAP Hyrax is vulnerable to Server Side Request Forgery (SSRF) and credential disclosure via unvalidated HTTP redirects that bypass the AllowedHosts allowlist and leak Earthdata headers (User-Id, Echo-Token) to attacker-controlled endpoints. OPeNDAP Hyrax is an open-source data server software that enables remote access to scientific datasets over the internet using the OPeNDAP protocol. It allows users to query... Related CVEs: CVE-2026-16637.</description>
    </item>
    <item>
      <title>`proot-distro install` has a Symlink Escape (Arbitrary Host File Write) via Malicious Tar Archive</title>
      <link>https://www.patchbrief.org/items/2026-07-pypi-cve-2026-54574.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-pypi-cve-2026-54574.html</guid>
      <pubDate>Wed, 29 Jul 2026 00:00:00 +0000</pubDate>
      <description>`proot-distro install` has a Symlink Escape (Arbitrary Host File Write) via Malicious Tar Archive</description>
    </item>
    <item>
      <title>proot-distro has a Container Isolation Bypass via Crafted Restore Archive</title>
      <link>https://www.patchbrief.org/items/2026-07-pypi-cve-2026-54727.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-pypi-cve-2026-54727.html</guid>
      <pubDate>Wed, 29 Jul 2026 00:00:00 +0000</pubDate>
      <description>proot-distro has a Container Isolation Bypass via Crafted Restore Archive</description>
    </item>
    <item>
      <title>Poweradmin has Host Header Injection in OIDC redirect_uri, SAML ACS/SLO URL, and Logout Redirect Construction.</title>
      <link>https://www.patchbrief.org/items/2026-07-composer-cve-2026-54588.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-composer-cve-2026-54588.html</guid>
      <pubDate>Tue, 28 Jul 2026 00:00:00 +0000</pubDate>
      <description>Poweradmin has Host Header Injection in OIDC redirect_uri, SAML ACS/SLO URL, and Logout Redirect Construction.</description>
    </item>
    <item>
      <title>Pterodactyl's improper JWT scoping allows subuser to upload files when not explicitly granted `file.create` permissions</title>
      <link>https://www.patchbrief.org/items/2026-07-composer-cve-2026-54593.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-composer-cve-2026-54593.html</guid>
      <pubDate>Tue, 28 Jul 2026 00:00:00 +0000</pubDate>
      <description>Pterodactyl's improper JWT scoping allows subuser to upload files when not explicitly granted `file.create` permissions</description>
    </item>
    <item>
      <title>Pterodactyl's shared global rate-limit key on login and 2FA checkpoint enables unauthenticated panel-wide authenticat...</title>
      <link>https://www.patchbrief.org/items/2026-07-composer-cve-2026-61609.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-composer-cve-2026-61609.html</guid>
      <pubDate>Tue, 28 Jul 2026 00:00:00 +0000</pubDate>
      <description>Pterodactyl's shared global rate-limit key on login and 2FA checkpoint enables unauthenticated panel-wide authentication lockout (DoS)</description>
    </item>
    <item>
      <title>Fission: Zip Slip in pkg/utils/zip.go:Unarchive allows fetcher to write outside the destination directory</title>
      <link>https://www.patchbrief.org/items/2026-07-go-cve-2026-50567.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-go-cve-2026-50567.html</guid>
      <pubDate>Tue, 28 Jul 2026 00:00:00 +0000</pubDate>
      <description>Fission: Zip Slip in pkg/utils/zip.go:Unarchive allows fetcher to write outside the destination directory</description>
    </item>
    <item>
      <title>Fission: Incomplete capability denylist in Environment/Function PodSpec validation allows tenant-added CAP_SYS_TIME a...</title>
      <link>https://www.patchbrief.org/items/2026-07-go-cve-2026-50570.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-go-cve-2026-50570.html</guid>
      <pubDate>Tue, 28 Jul 2026 00:00:00 +0000</pubDate>
      <description>Fission: Incomplete capability denylist in Environment/Function PodSpec validation allows tenant-added CAP_SYS_TIME and cross-tenant node wall-clock corruption</description>
    </item>
    <item>
      <title>td has pre-auth denial of service via unbounded memory allocation in proto.UnencryptedMessage.Decode</title>
      <link>https://www.patchbrief.org/items/2026-07-go-cve-2026-54638.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-go-cve-2026-54638.html</guid>
      <pubDate>Tue, 28 Jul 2026 00:00:00 +0000</pubDate>
      <description>td has pre-auth denial of service via unbounded memory allocation in proto.UnencryptedMessage.Decode</description>
    </item>
    <item>
      <title>openhole-server vulnerable to path traversal via URL-decoded request path</title>
      <link>https://www.patchbrief.org/items/2026-07-go-cve-2026-54650.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-go-cve-2026-54650.html</guid>
      <pubDate>Tue, 28 Jul 2026 00:00:00 +0000</pubDate>
      <description>openhole-server vulnerable to path traversal via URL-decoded request path</description>
    </item>
    <item>
      <title>goshs: File-based .goshs ACL authorization bypass via the ?bulk zip-download route (unauthenticated read; residual of...</title>
      <link>https://www.patchbrief.org/items/2026-07-go-cve-2026-54719.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-go-cve-2026-54719.html</guid>
      <pubDate>Tue, 28 Jul 2026 00:00:00 +0000</pubDate>
      <description>goshs: File-based .goshs ACL authorization bypass via the ?bulk zip-download route (unauthenticated read; residual of GHSA-wvhv-qcqf-f3cx)</description>
    </item>
    <item>
      <title>goshs SFTP authentication bypass via empty password (incomplete fix of CVE-2026-40884)</title>
      <link>https://www.patchbrief.org/items/2026-07-go-cve-2026-62325.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-go-cve-2026-62325.html</guid>
      <pubDate>Tue, 28 Jul 2026 00:00:00 +0000</pubDate>
      <description>goshs SFTP authentication bypass via empty password (incomplete fix of CVE-2026-40884)</description>
    </item>
    <item>
      <title>goshs --no-delete WebDAV MOVE bypass allows file deletion/overwrite</title>
      <link>https://www.patchbrief.org/items/2026-07-go-cve-2026-64863.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-go-cve-2026-64863.html</guid>
      <pubDate>Tue, 28 Jul 2026 00:00:00 +0000</pubDate>
      <description>goshs --no-delete WebDAV MOVE bypass allows file deletion/overwrite</description>
    </item>
    <item>
      <title>VU#141367: AT&amp;T's Arris BGW210-700 gateway contains authentication bypass vulnerability in LAN-side management interface</title>
      <link>https://www.patchbrief.org/items/2026-07-lan-side-vu-141367.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-lan-side-vu-141367.html</guid>
      <pubDate>Tue, 28 Jul 2026 00:00:00 +0000</pubDate>
      <description>Overview Firmware versions 2.7.7 and earlier of the Arris BGW210-700 residential gateway contain an authentication bypass vulnerability, tracked as CVE-2026-16771, that allows any unauthenticated LAN-side user to read sensitive configuration data and modify device settings through web management endpoints. Although this vulnerability was recently discovered, the majority of in-service gateways are not expected to be running the affected version. Only devices that have not received automated ISP-managed firmware updates since version 2.7.7 in 2020 are vulnerable. Description The Arris BGW210-700 is a residential gateway used widely in AT&amp;T deployments to provide routing, wireless networking, and wide-area network (WAN) connectivity for home users. The device exposes a browser-based management interface on the local-area network (LAN) side... Related CVEs: CVE-2026-16771.</description>
    </item>
    <item>
      <title>QTINeon has unauthenticated relay-to-host amplification via unbounded RECONNECT_REQUEST forwarding</title>
      <link>https://www.patchbrief.org/items/2026-07-maven-cve-2026-54609.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-maven-cve-2026-54609.html</guid>
      <pubDate>Tue, 28 Jul 2026 00:00:00 +0000</pubDate>
      <description>QTINeon has unauthenticated relay-to-host amplification via unbounded RECONNECT_REQUEST forwarding</description>
    </item>
    <item>
      <title>Style Dictionary - Prototype Pollution in convertTokenData utility function</title>
      <link>https://www.patchbrief.org/items/2026-07-npm-cve-2026-54639.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-npm-cve-2026-54639.html</guid>
      <pubDate>Tue, 28 Jul 2026 00:00:00 +0000</pubDate>
      <description>Style Dictionary - Prototype Pollution in convertTokenData utility function</description>
    </item>
    <item>
      <title>@hypequery/clickhouse has SQL Injection in parameter escaping that allows arbitrary SQL execution</title>
      <link>https://www.patchbrief.org/items/2026-07-npm-cve-2026-54658.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-npm-cve-2026-54658.html</guid>
      <pubDate>Tue, 28 Jul 2026 00:00:00 +0000</pubDate>
      <description>@hypequery/clickhouse has SQL Injection in parameter escaping that allows arbitrary SQL execution</description>
    </item>
    <item>
      <title>Microsoft Security Advisory CVE-2026-32203 – .NET and Visual Studio Denial of Service Vulnerability</title>
      <link>https://www.patchbrief.org/items/2026-07-nuget-cve-2026-32203.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-nuget-cve-2026-32203.html</guid>
      <pubDate>Tue, 28 Jul 2026 00:00:00 +0000</pubDate>
      <description>Microsoft Security Advisory CVE-2026-32203 – .NET and Visual Studio Denial of Service Vulnerability</description>
    </item>
    <item>
      <title>SIPSorcery: Malformed UDP packet on the RTP/ICE socket can remotely terminate a media session (DoS)</title>
      <link>https://www.patchbrief.org/items/2026-07-nuget-cve-2026-54632.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-nuget-cve-2026-54632.html</guid>
      <pubDate>Tue, 28 Jul 2026 00:00:00 +0000</pubDate>
      <description>SIPSorcery: Malformed UDP packet on the RTP/ICE socket can remotely terminate a media session (DoS)</description>
    </item>
    <item>
      <title>`datamodel-code-generator` vulnerable to code injection via unescaped carriage return in GraphQL Union description</title>
      <link>https://www.patchbrief.org/items/2026-07-pypi-cve-2026-54621.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-pypi-cve-2026-54621.html</guid>
      <pubDate>Tue, 28 Jul 2026 00:00:00 +0000</pubDate>
      <description>`datamodel-code-generator` vulnerable to code injection via unescaped carriage return in GraphQL Union description</description>
    </item>
    <item>
      <title>pytonapi has a Webhook Custom Path Authentication Bypass</title>
      <link>https://www.patchbrief.org/items/2026-07-pypi-cve-2026-54635.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-pypi-cve-2026-54635.html</guid>
      <pubDate>Tue, 28 Jul 2026 00:00:00 +0000</pubDate>
      <description>pytonapi has a Webhook Custom Path Authentication Bypass</description>
    </item>
    <item>
      <title>`datamodel-code-generator` vulnerable to code injection in via attacker-controlled `default_factory` schema field</title>
      <link>https://www.patchbrief.org/items/2026-07-pypi-cve-2026-54653.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-pypi-cve-2026-54653.html</guid>
      <pubDate>Tue, 28 Jul 2026 00:00:00 +0000</pubDate>
      <description>`datamodel-code-generator` vulnerable to code injection in via attacker-controlled `default_factory` schema field</description>
    </item>
    <item>
      <title>`datamodel-code-generator` vulnerable to code injection via unescaped carriage return in `--extra-template-data` `com...</title>
      <link>https://www.patchbrief.org/items/2026-07-pypi-cve-2026-54654.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-pypi-cve-2026-54654.html</guid>
      <pubDate>Tue, 28 Jul 2026 00:00:00 +0000</pubDate>
      <description>`datamodel-code-generator` vulnerable to code injection via unescaped carriage return in `--extra-template-data` `comment` field</description>
    </item>
    <item>
      <title>`datamodel-code-generator` vulnerable to code execution on import via `x-python-type` JSON-Schema extension in datamo...</title>
      <link>https://www.patchbrief.org/items/2026-07-pypi-cve-2026-54655.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-pypi-cve-2026-54655.html</guid>
      <pubDate>Tue, 28 Jul 2026 00:00:00 +0000</pubDate>
      <description>`datamodel-code-generator` vulnerable to code execution on import via `x-python-type` JSON-Schema extension in datamodel-code-generator</description>
    </item>
    <item>
      <title>`datamodel-code-generator` vulnerable to code execution on import via unescaped `validators` entries in --extra-templ...</title>
      <link>https://www.patchbrief.org/items/2026-07-pypi-cve-2026-54656.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-pypi-cve-2026-54656.html</guid>
      <pubDate>Tue, 28 Jul 2026 00:00:00 +0000</pubDate>
      <description>`datamodel-code-generator` vulnerable to code execution on import via unescaped `validators` entries in --extra-template-data</description>
    </item>
    <item>
      <title>datamodel-code-generator vulnerable to SSRF via JSON-Schema `$ref` to HTTP URL (silent by default)</title>
      <link>https://www.patchbrief.org/items/2026-07-pypi-cve-2026-54690.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-pypi-cve-2026-54690.html</guid>
      <pubDate>Tue, 28 Jul 2026 00:00:00 +0000</pubDate>
      <description>datamodel-code-generator vulnerable to SSRF via JSON-Schema `$ref` to HTTP URL (silent by default)</description>
    </item>
    <item>
      <title>datamodel-code-generator vulnerable to SSRF via --url: no host/IP validation, follows redirects</title>
      <link>https://www.patchbrief.org/items/2026-07-pypi-cve-2026-54691.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-pypi-cve-2026-54691.html</guid>
      <pubDate>Tue, 28 Jul 2026 00:00:00 +0000</pubDate>
      <description>datamodel-code-generator vulnerable to SSRF via --url: no host/IP validation, follows redirects</description>
    </item>
    <item>
      <title>datamodel-code-generator vulnerable to arbitrary local file read via JSON-Schema `$ref` (`file://` and `../` traversa...</title>
      <link>https://www.patchbrief.org/items/2026-07-pypi-cve-2026-55389.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-pypi-cve-2026-55389.html</guid>
      <pubDate>Tue, 28 Jul 2026 00:00:00 +0000</pubDate>
      <description>datamodel-code-generator vulnerable to arbitrary local file read via JSON-Schema `$ref` (`file://` and `../` traversal), bypassing `--no-allow-remote-refs`</description>
    </item>
    <item>
      <title>datamodel-code-generator vulnerable to arbitrary local file read via XSD `schemaLocation` (`xs:include`/`xs:import`) ...</title>
      <link>https://www.patchbrief.org/items/2026-07-pypi-cve-2026-55390.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-pypi-cve-2026-55390.html</guid>
      <pubDate>Tue, 28 Jul 2026 00:00:00 +0000</pubDate>
      <description>datamodel-code-generator vulnerable to arbitrary local file read via XSD `schemaLocation` (`xs:include`/`xs:import`) path traversal, with no remote-ref gate</description>
    </item>
    <item>
      <title>datamodel-code-generator vulnerable to SSRF protection bypass via DNS rebinding</title>
      <link>https://www.patchbrief.org/items/2026-07-pypi-cve-2026-55391.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-pypi-cve-2026-55391.html</guid>
      <pubDate>Tue, 28 Jul 2026 00:00:00 +0000</pubDate>
      <description>datamodel-code-generator vulnerable to SSRF protection bypass via DNS rebinding</description>
    </item>
    <item>
      <title>datamodel-code-generator vulnerable to code injection via `x-python-import` / `customTypePath` in generated import st...</title>
      <link>https://www.patchbrief.org/items/2026-07-pypi-cve-2026-55415.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-pypi-cve-2026-55415.html</guid>
      <pubDate>Tue, 28 Jul 2026 00:00:00 +0000</pubDate>
      <description>datamodel-code-generator vulnerable to code injection via `x-python-import` / `customTypePath` in generated import statements</description>
    </item>
    <item>
      <title>OAuth2::Client#request: Protocol-relative redirect Location overrides authority, leaking bearer Authorization to atta...</title>
      <link>https://www.patchbrief.org/items/2026-07-rubygems-cve-2026-54603.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-rubygems-cve-2026-54603.html</guid>
      <pubDate>Tue, 28 Jul 2026 00:00:00 +0000</pubDate>
      <description>OAuth2::Client#request: Protocol-relative redirect Location overrides authority, leaking bearer Authorization to attacker host</description>
    </item>
    <item>
      <title>OAuth: Cross-origin token-request redirects can expose signed request metadata</title>
      <link>https://www.patchbrief.org/items/2026-07-rubygems-cve-2026-54605.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-rubygems-cve-2026-54605.html</guid>
      <pubDate>Tue, 28 Jul 2026 00:00:00 +0000</pubDate>
      <description>OAuth: Cross-origin token-request redirects can expose signed request metadata</description>
    </item>
    <item>
      <title>lettre has TLS hostname verification disabled when using Boring TLS backend</title>
      <link>https://www.patchbrief.org/items/2026-07-rust-cve-2026-46428.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-rust-cve-2026-46428.html</guid>
      <pubDate>Tue, 28 Jul 2026 00:00:00 +0000</pubDate>
      <description>lettre has TLS hostname verification disabled when using Boring TLS backend</description>
    </item>
    <item>
      <title>Apache Thrift — CVE-2026-48144 (Critical)</title>
      <link>https://www.patchbrief.org/items/2026-07-apache-cve-2026-48144.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-apache-cve-2026-48144.html</guid>
      <pubDate>Mon, 27 Jul 2026 00:00:00 +0000</pubDate>
      <description>Improper Validation of Certificate with Host Mismatch vulnerability in Apache Thrift c_glib bindings. This issue affects Apache Thrift: before 0.24.0. Users are recommended to upgrade to version 0.24.0, which fixes the issue.</description>
    </item>
    <item>
      <title>Apache Thrift — CVE-2026-55971 (Critical)</title>
      <link>https://www.patchbrief.org/items/2026-07-apache-cve-2026-55971.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-apache-cve-2026-55971.html</guid>
      <pubDate>Mon, 27 Jul 2026 00:00:00 +0000</pubDate>
      <description>Heap-based Buffer Overflow vulnerability in Apache Thrift C++ bindings. This issue affects Apache Thrift: before 0.24.0. Users are recommended to upgrade to version 0.24.0, which fixes the issue.</description>
    </item>
    <item>
      <title>Apache Thrift — CVE-2026-58023 (Critical)</title>
      <link>https://www.patchbrief.org/items/2026-07-apache-cve-2026-58023.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-apache-cve-2026-58023.html</guid>
      <pubDate>Mon, 27 Jul 2026 00:00:00 +0000</pubDate>
      <description>Out-of-bounds Read vulnerability in Apache Thrift c_glib bindings. This issue affects Apache Thrift: before 0.24.0. Users are recommended to upgrade to version 0.24.0, which fixes the issue.</description>
    </item>
    <item>
      <title>Apache Thrift — CVE-2026-58662 (Critical)</title>
      <link>https://www.patchbrief.org/items/2026-07-apache-cve-2026-58662.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-apache-cve-2026-58662.html</guid>
      <pubDate>Mon, 27 Jul 2026 00:00:00 +0000</pubDate>
      <description>Improper Validation of Specified Quantity in Input, Out-of-bounds Read vulnerability in Apache Thrift C++ bindings. This issue affects Apache Thrift: before 0.24.0. Users are recommended to upgrade to version 0.24.0, which fixes the issue.</description>
    </item>
    <item>
      <title>Arista VeloCloud Orchestrator On-Prem OS Command Injection Vulnerability</title>
      <link>https://www.patchbrief.org/items/2026-07-arista-cve-2026-16812.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-arista-cve-2026-16812.html</guid>
      <pubDate>Mon, 27 Jul 2026 00:00:00 +0000</pubDate>
      <description>Arista VeloCloud Orchestrator On-Prem contains an OS command injection vulnerability that may allow a remote attacker to access privileged internal functionality and impact the VCO host. Successful exploitation may compromise the confidentiality, integrity, and availability of the orchestrator and data managed by the orchestrator.</description>
    </item>
    <item>
      <title>Fortinet FortiOS Exposure of Sensitive Information to an Unauthorized Actor Vulnerability</title>
      <link>https://www.patchbrief.org/items/2026-07-fortinet-cve-2025-68686.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-fortinet-cve-2025-68686.html</guid>
      <pubDate>Mon, 27 Jul 2026 00:00:00 +0000</pubDate>
      <description>Fortinet FortiOS contains an exposure of sensitive information to an unauthorized actor vulnerability. This may allow a remote unauthenticated attacker to bypass the patch developed for the symbolic link persistency mechanism observed in some post-exploit cases, via crafted HTTP requests. An attacker would need first to have compromised the product via another vulnerability, at filesystem level.</description>
    </item>
    <item>
      <title>Pheditor: Authentication Bypass in Forced Password-Change Flow via Unverified Current Password</title>
      <link>https://www.patchbrief.org/items/2026-07-composer-ghsa-f25v-x6vr-962g.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-composer-ghsa-f25v-x6vr-962g.html</guid>
      <pubDate>Fri, 24 Jul 2026 00:00:00 +0000</pubDate>
      <description>Pheditor: Authentication Bypass in Forced Password-Change Flow via Unverified Current Password</description>
    </item>
    <item>
      <title>etcd: `tlsListener.acceptLoop` spawns unbounded handshake goroutines with no deadline</title>
      <link>https://www.patchbrief.org/items/2026-07-go-ghsa-6vch-q96h-7gc3.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-go-ghsa-6vch-q96h-7gc3.html</guid>
      <pubDate>Fri, 24 Jul 2026 00:00:00 +0000</pubDate>
      <description>etcd: `tlsListener.acceptLoop` spawns unbounded handshake goroutines with no deadline</description>
    </item>
    <item>
      <title>Oh My Posh: Arbitrary command execution via template injection in the path segment</title>
      <link>https://www.patchbrief.org/items/2026-07-go-ghsa-6xj8-qv9j-xcjq.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-go-ghsa-6xj8-qv9j-xcjq.html</guid>
      <pubDate>Fri, 24 Jul 2026 00:00:00 +0000</pubDate>
      <description>Oh My Posh: Arbitrary command execution via template injection in the path segment</description>
    </item>
    <item>
      <title>OpenList: Authenticated users can rename files outside their base path via batch rename `src_name` traversal</title>
      <link>https://www.patchbrief.org/items/2026-07-go-ghsa-95cv-r8x4-vh75.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-go-ghsa-95cv-r8x4-vh75.html</guid>
      <pubDate>Fri, 24 Jul 2026 00:00:00 +0000</pubDate>
      <description>OpenList: Authenticated users can rename files outside their base path via batch rename `src_name` traversal</description>
    </item>
    <item>
      <title>kin-openapi: ValidationHandler.Load() Fail-Open Authentication Bypass via NoopAuthenticationFunc Default</title>
      <link>https://www.patchbrief.org/items/2026-07-go-ghsa-r277-6w6q-xmqw.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-go-ghsa-r277-6w6q-xmqw.html</guid>
      <pubDate>Fri, 24 Jul 2026 00:00:00 +0000</pubDate>
      <description>kin-openapi: ValidationHandler.Load() Fail-Open Authentication Bypass via NoopAuthenticationFunc Default</description>
    </item>
    <item>
      <title>etcd: Watch API authorization bypass via open-ended range requests</title>
      <link>https://www.patchbrief.org/items/2026-07-go-ghsa-xg4h-6gfc-h4m8.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-go-ghsa-xg4h-6gfc-h4m8.html</guid>
      <pubDate>Fri, 24 Jul 2026 00:00:00 +0000</pubDate>
      <description>etcd: Watch API authorization bypass via open-ended range requests</description>
    </item>
    <item>
      <title>OpenAM: WebAuthn Java deserialization RCE via ObjectInputFilter depth&gt;1 bypass</title>
      <link>https://www.patchbrief.org/items/2026-07-maven-cve-2026-62263.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-maven-cve-2026-62263.html</guid>
      <pubDate>Fri, 24 Jul 2026 00:00:00 +0000</pubDate>
      <description>OpenAM: WebAuthn Java deserialization RCE via ObjectInputFilter depth&gt;1 bypass</description>
    </item>
    <item>
      <title>OpenAM: Unauthenticated Remote Code Execution via Class.forName in AuthXMLUtils.createCustomCallback</title>
      <link>https://www.patchbrief.org/items/2026-07-maven-cve-2026-62379.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-maven-cve-2026-62379.html</guid>
      <pubDate>Fri, 24 Jul 2026 00:00:00 +0000</pubDate>
      <description>OpenAM: Unauthenticated Remote Code Execution via Class.forName in AuthXMLUtils.createCustomCallback</description>
    </item>
    <item>
      <title>blaze: Chunked-body trailer fields promoted into Request.headers in blaze-server (front-end header-sanitization bypass)</title>
      <link>https://www.patchbrief.org/items/2026-07-maven-ghsa-46q4-43ph-c6fr.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-maven-ghsa-46q4-43ph-c6fr.html</guid>
      <pubDate>Fri, 24 Jul 2026 00:00:00 +0000</pubDate>
      <description>blaze: Chunked-body trailer fields promoted into Request.headers in blaze-server (front-end header-sanitization bypass)</description>
    </item>
    <item>
      <title>OpenDJ unauthenticated SSRF, local file read and unbounded-read DoS in the DSMLv2 gateway</title>
      <link>https://www.patchbrief.org/items/2026-07-maven-ghsa-68r5-9hpg-7qw9.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-maven-ghsa-68r5-9hpg-7qw9.html</guid>
      <pubDate>Fri, 24 Jul 2026 00:00:00 +0000</pubDate>
      <description>OpenDJ unauthenticated SSRF, local file read and unbounded-read DoS in the DSMLv2 gateway</description>
    </item>
    <item>
      <title>blaze: Unbounded WebSocket message aggregation in http4s-blaze-server</title>
      <link>https://www.patchbrief.org/items/2026-07-maven-ghsa-7ppr-r889-mcf2.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-maven-ghsa-7ppr-r889-mcf2.html</guid>
      <pubDate>Fri, 24 Jul 2026 00:00:00 +0000</pubDate>
      <description>blaze: Unbounded WebSocket message aggregation in http4s-blaze-server</description>
    </item>
    <item>
      <title>OmniFaces: Forged combined-resource IDs and related output/push boundaries</title>
      <link>https://www.patchbrief.org/items/2026-07-maven-ghsa-fp43-vj7g-pg92.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-maven-ghsa-fp43-vj7g-pg92.html</guid>
      <pubDate>Fri, 24 Jul 2026 00:00:00 +0000</pubDate>
      <description>OmniFaces: Forged combined-resource IDs and related output/push boundaries</description>
    </item>
    <item>
      <title>blaze: Multiple HTTP/1.1 request-smuggling primitives in blaze's Java wire parser</title>
      <link>https://www.patchbrief.org/items/2026-07-maven-ghsa-mhvj-jhpq-885v.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-maven-ghsa-mhvj-jhpq-885v.html</guid>
      <pubDate>Fri, 24 Jul 2026 00:00:00 +0000</pubDate>
      <description>blaze: Multiple HTTP/1.1 request-smuggling primitives in blaze's Java wire parser</description>
    </item>
    <item>
      <title>OpenDJ SASL PLAIN authzid bypassing the proxy ACI scope check</title>
      <link>https://www.patchbrief.org/items/2026-07-maven-ghsa-p279-2cqp-84jg.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-maven-ghsa-p279-2cqp-84jg.html</guid>
      <pubDate>Fri, 24 Jul 2026 00:00:00 +0000</pubDate>
      <description>OpenDJ SASL PLAIN authzid bypassing the proxy ACI scope check</description>
    </item>
    <item>
      <title>seroval: `seroval.fromJSON()` Promise resolver type confusion invokes attacker-controlled methods during deserialization</title>
      <link>https://www.patchbrief.org/items/2026-07-npm-cve-2026-59940.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-npm-cve-2026-59940.html</guid>
      <pubDate>Fri, 24 Jul 2026 00:00:00 +0000</pubDate>
      <description>seroval: `seroval.fromJSON()` Promise resolver type confusion invokes attacker-controlled methods during deserialization</description>
    </item>
    <item>
      <title>Velocity.js: Remote Code Execution via property-read to Function constructor (bypass of GHSA-j658-c2gf-x6pq fix)</title>
      <link>https://www.patchbrief.org/items/2026-07-npm-ghsa-7gfh-x38p-prh3.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-npm-ghsa-7gfh-x38p-prh3.html</guid>
      <pubDate>Fri, 24 Jul 2026 00:00:00 +0000</pubDate>
      <description>Velocity.js: Remote Code Execution via property-read to Function constructor (bypass of GHSA-j658-c2gf-x6pq fix)</description>
    </item>
    <item>
      <title>Shescape: Quadratic-time denial of service in the flag-protection</title>
      <link>https://www.patchbrief.org/items/2026-07-npm-ghsa-gm3r-q2wp-hw87.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-npm-ghsa-gm3r-q2wp-hw87.html</guid>
      <pubDate>Fri, 24 Jul 2026 00:00:00 +0000</pubDate>
      <description>Shescape: Quadratic-time denial of service in the flag-protection</description>
    </item>
    <item>
      <title>Budibase: OIDC SSO account takeover: incoming identity linked by email without checking email_verified</title>
      <link>https://www.patchbrief.org/items/2026-07-npm-ghsa-hp6v-6jw7-gv2f.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-npm-ghsa-hp6v-6jw7-gv2f.html</guid>
      <pubDate>Fri, 24 Jul 2026 00:00:00 +0000</pubDate>
      <description>Budibase: OIDC SSO account takeover: incoming identity linked by email without checking email_verified</description>
    </item>
    <item>
      <title>Budibase: Unauthenticated REST Datasource Credential Theft via Cross-Origin Auth Leak</title>
      <link>https://www.patchbrief.org/items/2026-07-npm-ghsa-mqhr-6j6h-74p5.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-npm-ghsa-mqhr-6j6h-74p5.html</guid>
      <pubDate>Fri, 24 Jul 2026 00:00:00 +0000</pubDate>
      <description>Budibase: Unauthenticated REST Datasource Credential Theft via Cross-Origin Auth Leak</description>
    </item>
    <item>
      <title>Budibase: SQL Injection via `multipleStatements: true`</title>
      <link>https://www.patchbrief.org/items/2026-07-npm-ghsa-q6x4-v3qx-85qw.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-npm-ghsa-q6x4-v3qx-85qw.html</guid>
      <pubDate>Fri, 24 Jul 2026 00:00:00 +0000</pubDate>
      <description>Budibase: SQL Injection via `multipleStatements: true`</description>
    </item>
    <item>
      <title>@better-auth/scim: account takeover and stale access via SCIM provider-id collision</title>
      <link>https://www.patchbrief.org/items/2026-07-npm-ghsa-rjg6-39jm-rgg4.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-npm-ghsa-rjg6-39jm-rgg4.html</guid>
      <pubDate>Fri, 24 Jul 2026 00:00:00 +0000</pubDate>
      <description>@better-auth/scim: account takeover and stale access via SCIM provider-id collision</description>
    </item>
    <item>
      <title>sm-crypto: Predictable SM2 key generation in Node.js: default RNG uses Math.random + wall clock</title>
      <link>https://www.patchbrief.org/items/2026-07-npm-ghsa-vh45-f885-3848.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-npm-ghsa-vh45-f885-3848.html</guid>
      <pubDate>Fri, 24 Jul 2026 00:00:00 +0000</pubDate>
      <description>sm-crypto: Predictable SM2 key generation in Node.js: default RNG uses Math.random + wall clock</description>
    </item>
    <item>
      <title>Prompty: Server-Side Template Injection to Remote Code Execution in the @prompty/core Nunjucks Renderer</title>
      <link>https://www.patchbrief.org/items/2026-07-npm-ghsa-w28w-gp39-m4p6.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-npm-ghsa-w28w-gp39-m4p6.html</guid>
      <pubDate>Fri, 24 Jul 2026 00:00:00 +0000</pubDate>
      <description>Prompty: Server-Side Template Injection to Remote Code Execution in the @prompty/core Nunjucks Renderer</description>
    </item>
    <item>
      <title>Shescape: Shell injection via unescaped parentheses on Windows with CMD</title>
      <link>https://www.patchbrief.org/items/2026-07-npm-ghsa-w4hw-qcx7-56pr.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-npm-ghsa-w4hw-qcx7-56pr.html</guid>
      <pubDate>Fri, 24 Jul 2026 00:00:00 +0000</pubDate>
      <description>Shescape: Shell injection via unescaped parentheses on Windows with CMD</description>
    </item>
    <item>
      <title>Microsoft Kiota: Path/URL injection into generated Copilot plugin manifest via x-ai-* extensions</title>
      <link>https://www.patchbrief.org/items/2026-07-nuget-cve-2026-59864.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-nuget-cve-2026-59864.html</guid>
      <pubDate>Fri, 24 Jul 2026 00:00:00 +0000</pubDate>
      <description>Microsoft Kiota: Path/URL injection into generated Copilot plugin manifest via x-ai-* extensions</description>
    </item>
    <item>
      <title>Microsoft Kiota: Command injection via x-ms-kiota-info dependencyInstallCommand surfaced by `kiota info`</title>
      <link>https://www.patchbrief.org/items/2026-07-nuget-cve-2026-59865.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-nuget-cve-2026-59865.html</guid>
      <pubDate>Fri, 24 Jul 2026 00:00:00 +0000</pubDate>
      <description>Microsoft Kiota: Command injection via x-ms-kiota-info dependencyInstallCommand surfaced by `kiota info`</description>
    </item>
    <item>
      <title>AWS API MCP Server Security Policy Bypass via Startup Initialization Failure</title>
      <link>https://www.patchbrief.org/items/2026-07-pypi-cve-2026-16584.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-pypi-cve-2026-16584.html</guid>
      <pubDate>Fri, 24 Jul 2026 00:00:00 +0000</pubDate>
      <description>AWS API MCP Server Security Policy Bypass via Startup Initialization Failure</description>
    </item>
    <item>
      <title>AWS Bedrock AgentCore: Improper neutralization of argument delimiters in the Python SDK install_packages()</title>
      <link>https://www.patchbrief.org/items/2026-07-pypi-cve-2026-16796.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-pypi-cve-2026-16796.html</guid>
      <pubDate>Fri, 24 Jul 2026 00:00:00 +0000</pubDate>
      <description>AWS Bedrock AgentCore: Improper neutralization of argument delimiters in the Python SDK install_packages()</description>
    </item>
    <item>
      <title>libp2p: yamux connection DoS via oversized data frame</title>
      <link>https://www.patchbrief.org/items/2026-07-pypi-ghsa-hmj8-5xmh-5573.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-pypi-ghsa-hmj8-5xmh-5573.html</guid>
      <pubDate>Fri, 24 Jul 2026 00:00:00 +0000</pubDate>
      <description>libp2p: yamux connection DoS via oversized data frame</description>
    </item>
    <item>
      <title>Smithy-RS: Allocation of resources without limits in the default aws-smithy-http-server serve() path allows unauthent...</title>
      <link>https://www.patchbrief.org/items/2026-07-rust-cve-2026-16756.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-rust-cve-2026-16756.html</guid>
      <pubDate>Fri, 24 Jul 2026 00:00:00 +0000</pubDate>
      <description>Smithy-RS: Allocation of resources without limits in the default aws-smithy-http-server serve() path allows unauthenticated Slowloris denial of service</description>
    </item>
    <item>
      <title>PHPSpreadsheet: SSRF bypass via HTTP redirect in WEBSERVICE() domain whitelist</title>
      <link>https://www.patchbrief.org/items/2026-07-composer-cve-2026-59931.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-composer-cve-2026-59931.html</guid>
      <pubDate>Thu, 23 Jul 2026 00:00:00 +0000</pubDate>
      <description>PHPSpreadsheet: SSRF bypass via HTTP redirect in WEBSERVICE() domain whitelist</description>
    </item>
    <item>
      <title>PHPSpreadsheet: Gnumeric reader unbounded gzip expansion causes memory exhaustion</title>
      <link>https://www.patchbrief.org/items/2026-07-composer-cve-2026-59932.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-composer-cve-2026-59932.html</guid>
      <pubDate>Thu, 23 Jul 2026 00:00:00 +0000</pubDate>
      <description>PHPSpreadsheet: Gnumeric reader unbounded gzip expansion causes memory exhaustion</description>
    </item>
    <item>
      <title>PHPSpreadsheet: XLS/OLE sector-chain self-loop causes memory exhaustion</title>
      <link>https://www.patchbrief.org/items/2026-07-composer-cve-2026-59933.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-composer-cve-2026-59933.html</guid>
      <pubDate>Thu, 23 Jul 2026 00:00:00 +0000</pubDate>
      <description>PHPSpreadsheet: XLS/OLE sector-chain self-loop causes memory exhaustion</description>
    </item>
    <item>
      <title>VU#492466: Logto Identity Platform has authentication and authorization failures in core protocol handling</title>
      <link>https://www.patchbrief.org/items/2026-07-logto-vu-492466.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-logto-vu-492466.html</guid>
      <pubDate>Thu, 23 Jul 2026 00:00:00 +0000</pubDate>
      <description>Overview The Logto platform contains multiple vulnerabilities affecting the identity‑processing pipeline. These flaws reduce the reliability of authentication and authorization decisions and may allow attackers to bypass account‑ownership checks, skip MFA, replay externally issued SSO responses, or submit identity assertions without proper cryptographic or validity checks. Collectively, the issues create several paths for unauthorized access across both local and federated sign‑in flows. Description Developed by Silverhand Inc., Logto is an identity and access management system for software as a service (SaaS) and AI applications. It provides multi‑tenant authentication, single sign-on (SSO), role-based access control (RBAC), support for openId connect (OIDC), open authorization (OAuth) 2.1, and Security Assertion Markup Language (SAML)... Related CVEs: CVE-2026-15611, CVE-2026-15612, CVE-2026-15614, CVE-2026-15615.</description>
    </item>
    <item>
      <title>PostCSS: Arbitrary file read and information disclosure via attacker-controlled sourceMappingURL in CSS comments</title>
      <link>https://www.patchbrief.org/items/2026-07-npm-cve-2026-45623.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-npm-cve-2026-45623.html</guid>
      <pubDate>Thu, 23 Jul 2026 00:00:00 +0000</pubDate>
      <description>PostCSS: Arbitrary file read and information disclosure via attacker-controlled sourceMappingURL in CSS comments</description>
    </item>
    <item>
      <title>find-my-way: DDoS with HTTP2</title>
      <link>https://www.patchbrief.org/items/2026-07-npm-cve-2026-47219.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-npm-cve-2026-47219.html</guid>
      <pubDate>Thu, 23 Jul 2026 00:00:00 +0000</pubDate>
      <description>find-my-way: DDoS with HTTP2</description>
    </item>
    <item>
      <title>Auth.js: Email normalizer validates the address before Unicode normalization, allowing a homoglyph @ bypass</title>
      <link>https://www.patchbrief.org/items/2026-07-npm-ghsa-7rqj-j65f-68wh.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-npm-ghsa-7rqj-j65f-68wh.html</guid>
      <pubDate>Thu, 23 Jul 2026 00:00:00 +0000</pubDate>
      <description>Auth.js: Email normalizer validates the address before Unicode normalization, allowing a homoglyph @ bypass</description>
    </item>
    <item>
      <title>Auth.js: Configuration errors can cause existence-based auth checks to fail open (auth object populated with an error)</title>
      <link>https://www.patchbrief.org/items/2026-07-npm-ghsa-8fpg-xm3f-6cx3.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-npm-ghsa-8fpg-xm3f-6cx3.html</guid>
      <pubDate>Thu, 23 Jul 2026 00:00:00 +0000</pubDate>
      <description>Auth.js: Configuration errors can cause existence-based auth checks to fail open (auth object populated with an error)</description>
    </item>
    <item>
      <title>Auth.js: getToken() throws an uncaught exception on malformed Bearer authorization headers</title>
      <link>https://www.patchbrief.org/items/2026-07-npm-ghsa-xmf8-cvqr-rfgj.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-npm-ghsa-xmf8-cvqr-rfgj.html</guid>
      <pubDate>Thu, 23 Jul 2026 00:00:00 +0000</pubDate>
      <description>Auth.js: getToken() throws an uncaught exception on malformed Bearer authorization headers</description>
    </item>
    <item>
      <title>pypdf: Possible infinite loop for not terminated inline images (ASCII85 and ASCIIHex filter)</title>
      <link>https://www.patchbrief.org/items/2026-07-pypi-cve-2026-59935.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-pypi-cve-2026-59935.html</guid>
      <pubDate>Thu, 23 Jul 2026 00:00:00 +0000</pubDate>
      <description>pypdf: Possible infinite loop for not terminated inline images (ASCII85 and ASCIIHex filter)</description>
    </item>
    <item>
      <title>pypdf: Possible infinite loop for not terminated inline images</title>
      <link>https://www.patchbrief.org/items/2026-07-pypi-cve-2026-59936.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-pypi-cve-2026-59936.html</guid>
      <pubDate>Thu, 23 Jul 2026 00:00:00 +0000</pubDate>
      <description>pypdf: Possible infinite loop for not terminated inline images</description>
    </item>
    <item>
      <title>VU#360868: Analog Way Picturall Quad Compact Mark II contains a local privilege escalation vulnerability</title>
      <link>https://www.patchbrief.org/items/2026-07-analog-vu-360868.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-analog-vu-360868.html</guid>
      <pubDate>Wed, 22 Jul 2026 00:00:00 +0000</pubDate>
      <description>Overview Version 3.5.8 of Analog Way's Picturall Quad Compact Mark II server contains a local privilege escalation vulnerability, tracked as CVE-2026-14985, due to improper privilege delegation and insufficient input validation in a maintenance script. Description The Picturall Quad Compact Mark II is a compact, heavy-duty 8K media server developed by Analog Way for video playback and content management in professional audiovisual environments. The core firmware includes a maintenance script called create_local_installer.sh , and the default script permission allows the low-privileged user, picmedia , to execute it as root and without a password. An attacker creates a malicious Ext4 disk image that contains the file, picturall-version.txt , with a directory traversal string and a payload file. create_local_installer.sh reads input from... Related CVEs: CVE-2026-14985.</description>
    </item>
    <item>
      <title>Check Point SmartConsole Improper Authentication Vulnerability</title>
      <link>https://www.patchbrief.org/items/2026-07-check-point-cve-2026-16232.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-check-point-cve-2026-16232.html</guid>
      <pubDate>Wed, 22 Jul 2026 00:00:00 +0000</pubDate>
      <description>Check Point SmartConsole contains an improper authentication vulnerability which could allow an unauthenticated remote attacker to obtain an application login token and use it to authenticate with full administrative privileges.</description>
    </item>
    <item>
      <title>VU#847406: Duplicati backup software v2.3.0.1 is vulnerable to an incorrect permission assignment vulnerability</title>
      <link>https://www.patchbrief.org/items/2026-07-duplicati-vu-847406.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-duplicati-vu-847406.html</guid>
      <pubDate>Wed, 22 Jul 2026 00:00:00 +0000</pubDate>
      <description>Overview Duplicati v2.3.0.1 is vulnerable to arbitrary code execution when installed outside the default C:\Program Files\Duplicati 2\ directory. An attacker with local user privileges who can write files to the Duplicati installation directory can execute arbitrary code by placing malicious files, such as DLLs, in that directory. To mitigate this vulnerability, install Duplicati in the default C:\Program Files\ directory or update to the latest fixed version. Description Duplicati is a free, open-source backup solution that stores data across cloud and local storage platforms. On Windows, Duplicati is distributed as an MSI installer. By default, the installer deploys the application to C:\Program Files\Duplicati 2\ , where the directory inherits the standard protected ACLs provided by Windows. The following vulnerability affects... Related CVEs: CVE-2026-16157.</description>
    </item>
    <item>
      <title>Eclipse Jetty: DoS attack triggering OutOfMemory with 100-Continue requests</title>
      <link>https://www.patchbrief.org/items/2026-07-maven-cve-2024-7708.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-maven-cve-2024-7708.html</guid>
      <pubDate>Wed, 22 Jul 2026 00:00:00 +0000</pubDate>
      <description>Eclipse Jetty: DoS attack triggering OutOfMemory with 100-Continue requests</description>
    </item>
    <item>
      <title>Eclipse Jetty Digest Authentication: ISO-8859-1 lossy encoding allows authentication bypass via character substitution</title>
      <link>https://www.patchbrief.org/items/2026-07-maven-cve-2026-10050.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-maven-cve-2026-10050.html</guid>
      <pubDate>Wed, 22 Jul 2026 00:00:00 +0000</pubDate>
      <description>Eclipse Jetty Digest Authentication: ISO-8859-1 lossy encoding allows authentication bypass via character substitution</description>
    </item>
    <item>
      <title>Microsoft SharePoint Deserialization of Untrusted Data Vulnerability</title>
      <link>https://www.patchbrief.org/items/2026-07-microsoft-cve-2026-50522.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-microsoft-cve-2026-50522.html</guid>
      <pubDate>Wed, 22 Jul 2026 00:00:00 +0000</pubDate>
      <description>Microsoft SharePoint contains a deserialization of untrusted data vulnerability which could allow an unauthorized attacker to execute code over a network.</description>
    </item>
    <item>
      <title>Nlnetlabs Unbound — CVE-2026-50252 (Critical)</title>
      <link>https://www.patchbrief.org/items/2026-07-nlnetlabs-cve-2026-50252.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-nlnetlabs-cve-2026-50252.html</guid>
      <pubDate>Wed, 22 Jul 2026 00:00:00 +0000</pubDate>
      <description>In NLnet Labs Unbound 1.4.22 up to and including 1.25.1, UDP source port is randomized and intended to serve as a secret value that increases the entropy of DNS transactions. When resolver load balancing policies depend on the source port while their outcome is revealed this secrecy is undermined. The vulnerability arises when the load balancing policy is consistent with respect to the incoming source UDP port and IP address while heavily depending on the incoming source UDP port as a randomization source. When the SO_REUSEPORT configuration option is enabled ('so-reuseport: yes') in Unbound (</description>
    </item>
    <item>
      <title>Next.js: Denial of Service in App Router using Server Actions</title>
      <link>https://www.patchbrief.org/items/2026-07-npm-cve-2026-64641.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-npm-cve-2026-64641.html</guid>
      <pubDate>Wed, 22 Jul 2026 00:00:00 +0000</pubDate>
      <description>Next.js: Denial of Service in App Router using Server Actions</description>
    </item>
    <item>
      <title>Next.js: Middleware / Proxy bypass in App Router applications using Turbopack and single locale</title>
      <link>https://www.patchbrief.org/items/2026-07-npm-cve-2026-64642.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-npm-cve-2026-64642.html</guid>
      <pubDate>Wed, 22 Jul 2026 00:00:00 +0000</pubDate>
      <description>Next.js: Middleware / Proxy bypass in App Router applications using Turbopack and single locale</description>
    </item>
    <item>
      <title>Next.js: Server-Side Request Forgery in rewrites via attacker-controlled destination hostname</title>
      <link>https://www.patchbrief.org/items/2026-07-npm-cve-2026-64645.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-npm-cve-2026-64645.html</guid>
      <pubDate>Wed, 22 Jul 2026 00:00:00 +0000</pubDate>
      <description>Next.js: Server-Side Request Forgery in rewrites via attacker-controlled destination hostname</description>
    </item>
    <item>
      <title>Next.js: Server-Side Request Forgery in Server Actions on custom servers</title>
      <link>https://www.patchbrief.org/items/2026-07-npm-cve-2026-64649.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-npm-cve-2026-64649.html</guid>
      <pubDate>Wed, 22 Jul 2026 00:00:00 +0000</pubDate>
      <description>Next.js: Server-Side Request Forgery in Server Actions on custom servers</description>
    </item>
    <item>
      <title>n8n: SSO Instance-Role Provisioning Allows Privilege Escalation to Instance Owner</title>
      <link>https://www.patchbrief.org/items/2026-07-npm-cve-2026-65016.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-npm-cve-2026-65016.html</guid>
      <pubDate>Wed, 22 Jul 2026 00:00:00 +0000</pubDate>
      <description>n8n: SSO Instance-Role Provisioning Allows Privilege Escalation to Instance Owner</description>
    </item>
    <item>
      <title>n8n: Send Email Node Arbitrary File Read and SSRF via Nodemailer Content-Object Type Confusion</title>
      <link>https://www.patchbrief.org/items/2026-07-npm-ghsa-2x35-3fw4-9jr4.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-npm-ghsa-2x35-3fw4-9jr4.html</guid>
      <pubDate>Wed, 22 Jul 2026 00:00:00 +0000</pubDate>
      <description>n8n: Send Email Node Arbitrary File Read and SSRF via Nodemailer Content-Object Type Confusion</description>
    </item>
    <item>
      <title>n8n: Bypass "Allowed HTTP Request Domains" Credential Restriction in Multiple AI and LLM Nodes</title>
      <link>https://www.patchbrief.org/items/2026-07-npm-ghsa-64xh-79j6-r5v8.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-npm-ghsa-64xh-79j6-r5v8.html</guid>
      <pubDate>Wed, 22 Jul 2026 00:00:00 +0000</pubDate>
      <description>n8n: Bypass "Allowed HTTP Request Domains" Credential Restriction in Multiple AI and LLM Nodes</description>
    </item>
    <item>
      <title>n8n: Credential Authorization Bypass via Expression in HTTP Request Node `genericAuthType`</title>
      <link>https://www.patchbrief.org/items/2026-07-npm-ghsa-6qc9-mqvw-jg7x.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-npm-ghsa-6qc9-mqvw-jg7x.html</guid>
      <pubDate>Wed, 22 Jul 2026 00:00:00 +0000</pubDate>
      <description>n8n: Credential Authorization Bypass via Expression in HTTP Request Node `genericAuthType`</description>
    </item>
    <item>
      <title>n8n: Account Takeover via Unverified Email Claim in Token Exchange Embed Login</title>
      <link>https://www.patchbrief.org/items/2026-07-npm-ghsa-8342-988q-86cr.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-npm-ghsa-8342-988q-86cr.html</guid>
      <pubDate>Wed, 22 Jul 2026 00:00:00 +0000</pubDate>
      <description>n8n: Account Takeover via Unverified Email Claim in Token Exchange Embed Login</description>
    </item>
    <item>
      <title>n8n: Shared-Workflow Editor Can Exfiltrate Credentials via Inline Sub-Workflow JSON</title>
      <link>https://www.patchbrief.org/items/2026-07-npm-ghsa-cj9h-qx8g-pq2g.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-npm-ghsa-cj9h-qx8g-pq2g.html</guid>
      <pubDate>Wed, 22 Jul 2026 00:00:00 +0000</pubDate>
      <description>n8n: Shared-Workflow Editor Can Exfiltrate Credentials via Inline Sub-Workflow JSON</description>
    </item>
    <item>
      <title>n8n: Git Node fetch/pull/pushTags Operations Bypass Sandbox Path Restriction</title>
      <link>https://www.patchbrief.org/items/2026-07-npm-ghsa-gf29-4f56-r2jf.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-npm-ghsa-gf29-4f56-r2jf.html</guid>
      <pubDate>Wed, 22 Jul 2026 00:00:00 +0000</pubDate>
      <description>n8n: Git Node fetch/pull/pushTags Operations Bypass Sandbox Path Restriction</description>
    </item>
    <item>
      <title>n8n: Expression sandbox escape via arrow-function bodies enabling command execution</title>
      <link>https://www.patchbrief.org/items/2026-07-npm-ghsa-gv7g-jm28-cr3m.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-npm-ghsa-gv7g-jm28-cr3m.html</guid>
      <pubDate>Wed, 22 Jul 2026 00:00:00 +0000</pubDate>
      <description>n8n: Expression sandbox escape via arrow-function bodies enabling command execution</description>
    </item>
    <item>
      <title>n8n: Authenticated code execution in the n8n Git node</title>
      <link>https://www.patchbrief.org/items/2026-07-npm-ghsa-rcv6-pvrj-4xcg.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-npm-ghsa-rcv6-pvrj-4xcg.html</guid>
      <pubDate>Wed, 22 Jul 2026 00:00:00 +0000</pubDate>
      <description>n8n: Authenticated code execution in the n8n Git node</description>
    </item>
    <item>
      <title>n8n: Edit Image Node Format Injection Allows Arbitrary File Write</title>
      <link>https://www.patchbrief.org/items/2026-07-npm-ghsa-xmc9-4f2h-jf9c.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-npm-ghsa-xmc9-4f2h-jf9c.html</guid>
      <pubDate>Wed, 22 Jul 2026 00:00:00 +0000</pubDate>
      <description>n8n: Edit Image Node Format Injection Allows Arbitrary File Write</description>
    </item>
    <item>
      <title>n8n: Prototype Pollution via Dot-Notation Field Names Leads To Instance-Wide Denial of Service</title>
      <link>https://www.patchbrief.org/items/2026-07-npm-ghsa-xwx6-jjhv-84p8.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-npm-ghsa-xwx6-jjhv-84p8.html</guid>
      <pubDate>Wed, 22 Jul 2026 00:00:00 +0000</pubDate>
      <description>n8n: Prototype Pollution via Dot-Notation Field Names Leads To Instance-Wide Denial of Service</description>
    </item>
    <item>
      <title>LiteLLM: MCP Authentication Bypass via OAuth2 Passthrough Fallback</title>
      <link>https://www.patchbrief.org/items/2026-07-pypi-cve-2026-59822.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-pypi-cve-2026-59822.html</guid>
      <pubDate>Wed, 22 Jul 2026 00:00:00 +0000</pubDate>
      <description>LiteLLM: MCP Authentication Bypass via OAuth2 Passthrough Fallback</description>
    </item>
    <item>
      <title>JupyterLab: Image viewer allows XSS when opening malicious image in new browser tab</title>
      <link>https://www.patchbrief.org/items/2026-07-pypi-ghsa-gx64-gj6p-pc4c.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-pypi-ghsa-gx64-gj6p-pc4c.html</guid>
      <pubDate>Wed, 22 Jul 2026 00:00:00 +0000</pubDate>
      <description>JupyterLab: Image viewer allows XSS when opening malicious image in new browser tab</description>
    </item>
    <item>
      <title>JupyterLab: Cross-site scripting (XSS) via crafted settings file (`overrides.json`)</title>
      <link>https://www.patchbrief.org/items/2026-07-pypi-ghsa-pppj-hq3g-57pj.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-pypi-ghsa-pppj-hq3g-57pj.html</guid>
      <pubDate>Wed, 22 Jul 2026 00:00:00 +0000</pubDate>
      <description>JupyterLab: Cross-site scripting (XSS) via crafted settings file (`overrides.json`)</description>
    </item>
    <item>
      <title>DD-WRT Stack-Based Buffer Overflow Vulnerability</title>
      <link>https://www.patchbrief.org/items/2026-07-dd-wrt-cve-2021-27137.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-dd-wrt-cve-2021-27137.html</guid>
      <pubDate>Tue, 21 Jul 2026 00:00:00 +0000</pubDate>
      <description>DD-WRT contains a stack-based buffer overflow vulnerability that could allow an unauthenticated attacker to overflow an internal buffer used by UPnP and trigger a code execution vulnerability.</description>
    </item>
    <item>
      <title>Gitea: TOTP TOCTOU race on web 2FA paths + missing replay check on Basic-Auth `X-Gitea-OTP` surface</title>
      <link>https://www.patchbrief.org/items/2026-07-go-cve-2026-20779.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-go-cve-2026-20779.html</guid>
      <pubDate>Tue, 21 Jul 2026 00:00:00 +0000</pubDate>
      <description>Gitea: TOTP TOCTOU race on web 2FA paths + missing replay check on Basic-Auth `X-Gitea-OTP` surface</description>
    </item>
    <item>
      <title>Gitea Docker image: `REVERSE_PROXY_TRUSTED_PROXIES = *` default lets any source IP impersonate any user via `X-WEBAUT...</title>
      <link>https://www.patchbrief.org/items/2026-07-go-cve-2026-20896.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-go-cve-2026-20896.html</guid>
      <pubDate>Tue, 21 Jul 2026 00:00:00 +0000</pubDate>
      <description>Gitea Docker image: `REVERSE_PROXY_TRUSTED_PROXIES = *` default lets any source IP impersonate any user via `X-WEBAUTH-USER`</description>
    </item>
    <item>
      <title>Gitea: Incomplete SSRF Protection in Webhook and Migration Allow-list Default Filter</title>
      <link>https://www.patchbrief.org/items/2026-07-go-cve-2026-22874.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-go-cve-2026-22874.html</guid>
      <pubDate>Tue, 21 Jul 2026 00:00:00 +0000</pubDate>
      <description>Gitea: Incomplete SSRF Protection in Webhook and Migration Allow-list Default Filter</description>
    </item>
    <item>
      <title>Gitea: Fork Synchronization Continues After Parent Repository Changes from Public to Private</title>
      <link>https://www.patchbrief.org/items/2026-07-go-cve-2026-24451.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-go-cve-2026-24451.html</guid>
      <pubDate>Tue, 21 Jul 2026 00:00:00 +0000</pubDate>
      <description>Gitea: Fork Synchronization Continues After Parent Repository Changes from Public to Private</description>
    </item>
    <item>
      <title>Gitea: Unauthorized Access to Labels of Private Organizations</title>
      <link>https://www.patchbrief.org/items/2026-07-go-cve-2026-25038.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-go-cve-2026-25038.html</guid>
      <pubDate>Tue, 21 Jul 2026 00:00:00 +0000</pubDate>
      <description>Gitea: Unauthorized Access to Labels of Private Organizations</description>
    </item>
    <item>
      <title>Gitea: Cached Per-Branch Permission Check in Pre-Receive Hook Allows Full Repository Write</title>
      <link>https://www.patchbrief.org/items/2026-07-go-cve-2026-27775.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-go-cve-2026-27775.html</guid>
      <pubDate>Tue, 21 Jul 2026 00:00:00 +0000</pubDate>
      <description>Gitea: Cached Per-Branch Permission Check in Pre-Receive Hook Allows Full Repository Write</description>
    </item>
    <item>
      <title>Gitea: Internal API HTTP client hardcodes InsecureSkipVerify:true with no config override</title>
      <link>https://www.patchbrief.org/items/2026-07-go-cve-2026-54481.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-go-cve-2026-54481.html</guid>
      <pubDate>Tue, 21 Jul 2026 00:00:00 +0000</pubDate>
      <description>Gitea: Internal API HTTP client hardcodes InsecureSkipVerify:true with no config override</description>
    </item>
    <item>
      <title>Gitea: OAuth2 sign-in reactivates an administrator-deactivated account on auth sources without refresh tokens (incomp...</title>
      <link>https://www.patchbrief.org/items/2026-07-go-cve-2026-55987.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-go-cve-2026-55987.html</guid>
      <pubDate>Tue, 21 Jul 2026 00:00:00 +0000</pubDate>
      <description>Gitea: OAuth2 sign-in reactivates an administrator-deactivated account on auth sources without refresh tokens (incomplete fix of #38009)</description>
    </item>
    <item>
      <title>Gitea Remember-Me Token Theft Not Invalidating Attacker Session</title>
      <link>https://www.patchbrief.org/items/2026-07-go-cve-2026-56750.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-go-cve-2026-56750.html</guid>
      <pubDate>Tue, 21 Jul 2026 00:00:00 +0000</pubDate>
      <description>Gitea Remember-Me Token Theft Not Invalidating Attacker Session</description>
    </item>
    <item>
      <title>Gitea: Two SSRF findings</title>
      <link>https://www.patchbrief.org/items/2026-07-go-cve-2026-58314.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-go-cve-2026-58314.html</guid>
      <pubDate>Tue, 21 Jul 2026 00:00:00 +0000</pubDate>
      <description>Gitea: Two SSRF findings</description>
    </item>
    <item>
      <title>Gitea: Notification API leaks private issue metadata after access revocation</title>
      <link>https://www.patchbrief.org/items/2026-07-go-cve-2026-58419.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-go-cve-2026-58419.html</guid>
      <pubDate>Tue, 21 Jul 2026 00:00:00 +0000</pubDate>
      <description>Gitea: Notification API leaks private issue metadata after access revocation</description>
    </item>
    <item>
      <title>Gitea: Unauthenticated ReDoS via CODEOWNERS pattern matching allows denial of service</title>
      <link>https://www.patchbrief.org/items/2026-07-go-cve-2026-58421.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-go-cve-2026-58421.html</guid>
      <pubDate>Tue, 21 Jul 2026 00:00:00 +0000</pubDate>
      <description>Gitea: Unauthenticated ReDoS via CODEOWNERS pattern matching allows denial of service</description>
    </item>
    <item>
      <title>Gitea: Improper authorization on OAuth sign-in callback silently re-enables administrator-disabled accounts</title>
      <link>https://www.patchbrief.org/items/2026-07-go-cve-2026-58422.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-go-cve-2026-58422.html</guid>
      <pubDate>Tue, 21 Jul 2026 00:00:00 +0000</pubDate>
      <description>Gitea: Improper authorization on OAuth sign-in callback silently re-enables administrator-disabled accounts</description>
    </item>
    <item>
      <title>Gitea: LFS authentication bypass via malformed SSH sub-verb allows unauthorized read access to private repositories</title>
      <link>https://www.patchbrief.org/items/2026-07-go-cve-2026-58423.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-go-cve-2026-58423.html</guid>
      <pubDate>Tue, 21 Jul 2026 00:00:00 +0000</pubDate>
      <description>Gitea: LFS authentication bypass via malformed SSH sub-verb allows unauthorized read access to private repositories</description>
    </item>
    <item>
      <title>Gitea: Permanent Fork PR Workflow Approval Gate Bypass</title>
      <link>https://www.patchbrief.org/items/2026-07-go-cve-2026-58424.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-go-cve-2026-58424.html</guid>
      <pubDate>Tue, 21 Jul 2026 00:00:00 +0000</pubDate>
      <description>Gitea: Permanent Fork PR Workflow Approval Gate Bypass</description>
    </item>
    <item>
      <title>Gitea Actions Artifacts V4 signed URL HMAC ambiguity allows cross-repository artifact read and cross-task upload-stat...</title>
      <link>https://www.patchbrief.org/items/2026-07-go-cve-2026-58426.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-go-cve-2026-58426.html</guid>
      <pubDate>Tue, 21 Jul 2026 00:00:00 +0000</pubDate>
      <description>Gitea Actions Artifacts V4 signed URL HMAC ambiguity allows cross-repository artifact read and cross-task upload-state write</description>
    </item>
    <item>
      <title>Gitea: ParseAcceptLanguage quadratic-time DoS via Locale middleware on unauthenticated requests</title>
      <link>https://www.patchbrief.org/items/2026-07-go-cve-2026-58436.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-go-cve-2026-58436.html</guid>
      <pubDate>Tue, 21 Jul 2026 00:00:00 +0000</pubDate>
      <description>Gitea: ParseAcceptLanguage quadratic-time DoS via Locale middleware on unauthenticated requests</description>
    </item>
    <item>
      <title>Gitea: Repository Visibility Manipulation via Git Push Options</title>
      <link>https://www.patchbrief.org/items/2026-07-go-cve-2026-58437.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-go-cve-2026-58437.html</guid>
      <pubDate>Tue, 21 Jul 2026 00:00:00 +0000</pubDate>
      <description>Gitea: Repository Visibility Manipulation via Git Push Options</description>
    </item>
    <item>
      <title>Gitea: Public-only repository tokens can update private PR head branches</title>
      <link>https://www.patchbrief.org/items/2026-07-go-cve-2026-58443.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-go-cve-2026-58443.html</guid>
      <pubDate>Tue, 21 Jul 2026 00:00:00 +0000</pubDate>
      <description>Gitea: Public-only repository tokens can update private PR head branches</description>
    </item>
    <item>
      <title>gRPC-Go: xDS RBAC and HTTP/2 Vulnerabilities</title>
      <link>https://www.patchbrief.org/items/2026-07-go-ghsa-hrxh-6v49-42gf.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-go-ghsa-hrxh-6v49-42gf.html</guid>
      <pubDate>Tue, 21 Jul 2026 00:00:00 +0000</pubDate>
      <description>gRPC-Go: xDS RBAC and HTTP/2 Vulnerabilities</description>
    </item>
    <item>
      <title>Langflow Inclusion of Functionality from Untrusted Control Sphere Vulnerability</title>
      <link>https://www.patchbrief.org/items/2026-07-langflow-cve-2026-0770.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-langflow-cve-2026-0770.html</guid>
      <pubDate>Tue, 21 Jul 2026 00:00:00 +0000</pubDate>
      <description>Langflow contains an inclusion of functionality from untrusted control sphere vulnerability that allows remote attackers to execute arbitrary code on affected installations.</description>
    </item>
    <item>
      <title>Linknat VOS3000 and VOS2009 — CVE-2016-20096 (Critical)</title>
      <link>https://www.patchbrief.org/items/2026-07-linknat-cve-2016-20096.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-linknat-cve-2016-20096.html</guid>
      <pubDate>Tue, 21 Jul 2026 00:00:00 +0000</pubDate>
      <description>Linknat VOS3000 and VOS2009 through version 2.1.2.0 contain an unauthenticated SQL injection vulnerability that allows remote attackers to execute arbitrary SQL commands by manipulating the name parameter in a POST request to the login endpoint. Attackers can inject malicious SQL through the login form and retrieve injected query results from a subsequent session request, enabling extraction of plaintext credentials and other database content with DBA-level privileges.</description>
    </item>
    <item>
      <title>jackson-core: Async parser maxNumberLength bypass via chunked digit accumulation (incomplete fix for GHSA-72hv-8253-5...</title>
      <link>https://www.patchbrief.org/items/2026-07-maven-ghsa-r7wm-3cxj-wff9.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-maven-ghsa-r7wm-3cxj-wff9.html</guid>
      <pubDate>Tue, 21 Jul 2026 00:00:00 +0000</pubDate>
      <description>jackson-core: Async parser maxNumberLength bypass via chunked digit accumulation (incomplete fix for GHSA-72hv-8253-57qq)</description>
    </item>
    <item>
      <title>fast-uri vulnerable to host confusion via literal backslash authority delimiter</title>
      <link>https://www.patchbrief.org/items/2026-07-npm-cve-2026-16221.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-npm-cve-2026-16221.html</guid>
      <pubDate>Tue, 21 Jul 2026 00:00:00 +0000</pubDate>
      <description>fast-uri vulnerable to host confusion via literal backslash authority delimiter</description>
    </item>
    <item>
      <title>Credential confusion in @sigstore/oci can leak registry credentials to an attacker-controlled registry</title>
      <link>https://www.patchbrief.org/items/2026-07-npm-cve-2026-59891.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-npm-cve-2026-59891.html</guid>
      <pubDate>Tue, 21 Jul 2026 00:00:00 +0000</pubDate>
      <description>Credential confusion in @sigstore/oci can leak registry credentials to an attacker-controlled registry</description>
    </item>
    <item>
      <title>fast-xml-parser: Repeated DOCTYPE declarations reset entity expansion limits</title>
      <link>https://www.patchbrief.org/items/2026-07-npm-ghsa-8r6m-32jq-jx6q.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-npm-ghsa-8r6m-32jq-jx6q.html</guid>
      <pubDate>Tue, 21 Jul 2026 00:00:00 +0000</pubDate>
      <description>fast-xml-parser: Repeated DOCTYPE declarations reset entity expansion limits</description>
    </item>
    <item>
      <title>sharp inherited vulnerabilities in libvips: CVE-2026-33327, CVE-2026-33328, CVE-2026-35590, CVE-2026-35591</title>
      <link>https://www.patchbrief.org/items/2026-07-npm-ghsa-f88m-g3jw-g9cj.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-npm-ghsa-f88m-g3jw-g9cj.html</guid>
      <pubDate>Tue, 21 Jul 2026 00:00:00 +0000</pubDate>
      <description>sharp inherited vulnerabilities in libvips: CVE-2026-33327, CVE-2026-33328, CVE-2026-35590, CVE-2026-35591</description>
    </item>
    <item>
      <title>@vitest/browser: Browser Mode provider commands bypass the file-access permission gate</title>
      <link>https://www.patchbrief.org/items/2026-07-npm-ghsa-p63j-vcc4-9vmv.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-npm-ghsa-p63j-vcc4-9vmv.html</guid>
      <pubDate>Tue, 21 Jul 2026 00:00:00 +0000</pubDate>
      <description>@vitest/browser: Browser Mode provider commands bypass the file-access permission gate</description>
    </item>
    <item>
      <title>VU#762226: Plane contains multi-tenant authorization bypass vulnerability</title>
      <link>https://www.patchbrief.org/items/2026-07-plane-vu-762226.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-plane-vu-762226.html</guid>
      <pubDate>Tue, 21 Jul 2026 00:00:00 +0000</pubDate>
      <description>Overview The project management tool Plane, versions 1.3.0 and earlier, contains a multi-tenant authorization bypass vulnerability in its asset-management API that allows unauthorized users to access, delete, or duplicate assets that belong to other workspaces. Description Plane is an open-source project management platform that provides multi-tenant workspace isolation for users to track issues, monitor progress, and manage workflows. The platform's API supports uploading, retrieving, deleting, and duplicating files associated with issues and tasks within a workspace. CVE-2026-15342 Plane's asset-management API endpoints accept workspace slugs and asset identifiers as path parameters, but do not verify that the requesting user is authorized to access the specified workspace. As a result, an authenticated user in one workspace can supply... Related CVEs: CVE-2026-15342.</description>
    </item>
    <item>
      <title>GitPython: Environment-variable exfiltration via os.path.expandvars() on Repo.clone_from() URL</title>
      <link>https://www.patchbrief.org/items/2026-07-pypi-ghsa-rwj8-pgh3-r573.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-pypi-ghsa-rwj8-pgh3-r573.html</guid>
      <pubDate>Tue, 21 Jul 2026 00:00:00 +0000</pubDate>
      <description>GitPython: Environment-variable exfiltration via os.path.expandvars() on Repo.clone_from() URL</description>
    </item>
    <item>
      <title>WordPress Core SQL Injection Vulnerability</title>
      <link>https://www.patchbrief.org/items/2026-07-wordpress-cve-2026-60137.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-wordpress-cve-2026-60137.html</guid>
      <pubDate>Tue, 21 Jul 2026 00:00:00 +0000</pubDate>
      <description>WordPress Core contains a SQL injection vulnerability when a plugin or theme passes untrusted input to the parameter. This vulnerability can be chained with CVE-2026-63030 to allow an unauthenticated attacker to gain remote code execution on default WordPress installations.</description>
    </item>
    <item>
      <title>WordPress Core Interpretation Conflict Vulnerability</title>
      <link>https://www.patchbrief.org/items/2026-07-wordpress-cve-2026-63030.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-wordpress-cve-2026-63030.html</guid>
      <pubDate>Tue, 21 Jul 2026 00:00:00 +0000</pubDate>
      <description>WordPress Core contains an interpretation conflict vulnerability that could allow an attacker to perform SQL Injection and achieve Remote Code Execution. This vulnerability can be chained with CVE-2026-60137.</description>
    </item>
    <item>
      <title>Cloudreve: OAuth access tokens bypass scope enforcement due to missing client_id claim</title>
      <link>https://www.patchbrief.org/items/2026-07-go-cve-2026-54560.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-go-cve-2026-54560.html</guid>
      <pubDate>Mon, 20 Jul 2026 00:00:00 +0000</pubDate>
      <description>Cloudreve: OAuth access tokens bypass scope enforcement due to missing client_id claim</description>
    </item>
    <item>
      <title>File Browser: Out-of-scope file deletion by a Create-only scoped user via symlink-following RemoveAll in upload failu...</title>
      <link>https://www.patchbrief.org/items/2026-07-go-cve-2026-55667.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-go-cve-2026-55667.html</guid>
      <pubDate>Mon, 20 Jul 2026 00:00:00 +0000</pubDate>
      <description>File Browser: Out-of-scope file deletion by a Create-only scoped user via symlink-following RemoveAll in upload failure-cleanup</description>
    </item>
    <item>
      <title>File Browser: Colliding username normalization gives two users the same home directory</title>
      <link>https://www.patchbrief.org/items/2026-07-go-cve-2026-62685.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-go-cve-2026-62685.html</guid>
      <pubDate>Mon, 20 Jul 2026 00:00:00 +0000</pubDate>
      <description>File Browser: Colliding username normalization gives two users the same home directory</description>
    </item>
    <item>
      <title>Neutrinolabs Xrdp — CVE-2026-41521 (Critical)</title>
      <link>https://www.patchbrief.org/items/2026-07-neutrinolabs-cve-2026-41521.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-neutrinolabs-cve-2026-41521.html</guid>
      <pubDate>Mon, 20 Jul 2026 00:00:00 +0000</pubDate>
      <description>xrdp is an open source RDP server. Versions 0.10.6 and prior contain an integer overflow vulnerability when processing screen update messages within the vnc-any connection mode. A malicious remote VNC server can send crafted image dimensions that cause an integer overflow during memory buffer size calculation, resulting in an undersized allocation. Subsequent processing of the incoming image data using the original oversized parameters leads to an out-of-bounds read. An unauthenticated remote attacker could exploit this flaw to disclose sensitive information from the heap memory or cause a den</description>
    </item>
    <item>
      <title>shell-quote: Quadratic-complexity Denial of Service in `parse()` (CWE-407)</title>
      <link>https://www.patchbrief.org/items/2026-07-npm-cve-2026-13311.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-npm-cve-2026-13311.html</guid>
      <pubDate>Mon, 20 Jul 2026 00:00:00 +0000</pubDate>
      <description>shell-quote: Quadratic-complexity Denial of Service in `parse()` (CWE-407)</description>
    </item>
    <item>
      <title>Socket.IO: Engine.IO Polling Transport Connection Exhaustion</title>
      <link>https://www.patchbrief.org/items/2026-07-npm-cve-2026-59725.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-npm-cve-2026-59725.html</guid>
      <pubDate>Mon, 20 Jul 2026 00:00:00 +0000</pubDate>
      <description>Socket.IO: Engine.IO Polling Transport Connection Exhaustion</description>
    </item>
    <item>
      <title>Astro: Authorization Bypass via Decode Iteration Limit and Rewrite Path Canonicalization Mismatch</title>
      <link>https://www.patchbrief.org/items/2026-07-npm-cve-2026-59731.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-npm-cve-2026-59731.html</guid>
      <pubDate>Mon, 20 Jul 2026 00:00:00 +0000</pubDate>
      <description>Astro: Authorization Bypass via Decode Iteration Limit and Rewrite Path Canonicalization Mismatch</description>
    </item>
    <item>
      <title>js-yaml: YAML merge-key chains can force quadratic CPU consumption</title>
      <link>https://www.patchbrief.org/items/2026-07-npm-cve-2026-59869.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-npm-cve-2026-59869.html</guid>
      <pubDate>Mon, 20 Jul 2026 00:00:00 +0000</pubDate>
      <description>js-yaml: YAML merge-key chains can force quadratic CPU consumption</description>
    </item>
    <item>
      <title>node-tar: Negative tar entry size causes infinite loop in archive replace</title>
      <link>https://www.patchbrief.org/items/2026-07-npm-cve-2026-59874.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-npm-cve-2026-59874.html</guid>
      <pubDate>Mon, 20 Jul 2026 00:00:00 +0000</pubDate>
      <description>node-tar: Negative tar entry size causes infinite loop in archive replace</description>
    </item>
    <item>
      <title>Directus: SSRF Protection Bypass via 0.0.0.0 in File Import</title>
      <link>https://www.patchbrief.org/items/2026-07-npm-cve-2026-61835.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-npm-cve-2026-61835.html</guid>
      <pubDate>Mon, 20 Jul 2026 00:00:00 +0000</pubDate>
      <description>Directus: SSRF Protection Bypass via 0.0.0.0 in File Import</description>
    </item>
    <item>
      <title>Directus: Authorization-dependent response served from unsegmented cache key</title>
      <link>https://www.patchbrief.org/items/2026-07-npm-cve-2026-61836.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-npm-cve-2026-61836.html</guid>
      <pubDate>Mon, 20 Jul 2026 00:00:00 +0000</pubDate>
      <description>Directus: Authorization-dependent response served from unsegmented cache key</description>
    </item>
    <item>
      <title>Axios Node HTTP adapter can use an inherited proxy after interceptor config cloning</title>
      <link>https://www.patchbrief.org/items/2026-07-npm-ghsa-gcfj-64vw-6mp9.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-npm-ghsa-gcfj-64vw-6mp9.html</guid>
      <pubDate>Mon, 20 Jul 2026 00:00:00 +0000</pubDate>
      <description>Axios Node HTTP adapter can use an inherited proxy after interceptor config cloning</description>
    </item>
    <item>
      <title>Microsoft Security Advisory CVE-2026-47302 – .NET Denial of Service Vulnerability</title>
      <link>https://www.patchbrief.org/items/2026-07-nuget-cve-2026-47302.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-nuget-cve-2026-47302.html</guid>
      <pubDate>Mon, 20 Jul 2026 00:00:00 +0000</pubDate>
      <description>Microsoft Security Advisory CVE-2026-47302 – .NET Denial of Service Vulnerability</description>
    </item>
    <item>
      <title>Microsoft Security Advisory CVE-2026-47304 – .NET Security Feature Bypass Vulnerability</title>
      <link>https://www.patchbrief.org/items/2026-07-nuget-cve-2026-47304.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-nuget-cve-2026-47304.html</guid>
      <pubDate>Mon, 20 Jul 2026 00:00:00 +0000</pubDate>
      <description>Microsoft Security Advisory CVE-2026-47304 – .NET Security Feature Bypass Vulnerability</description>
    </item>
    <item>
      <title>Microsoft Security Advisory CVE-2026-50524 – .NET Denial of Service Vulnerability</title>
      <link>https://www.patchbrief.org/items/2026-07-nuget-cve-2026-50524.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-nuget-cve-2026-50524.html</guid>
      <pubDate>Mon, 20 Jul 2026 00:00:00 +0000</pubDate>
      <description>Microsoft Security Advisory CVE-2026-50524 – .NET Denial of Service Vulnerability</description>
    </item>
    <item>
      <title>Microsoft Security Advisory CVE-2026-50525 – .NET Denial of Service Vulnerability</title>
      <link>https://www.patchbrief.org/items/2026-07-nuget-cve-2026-50525.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-nuget-cve-2026-50525.html</guid>
      <pubDate>Mon, 20 Jul 2026 00:00:00 +0000</pubDate>
      <description>Microsoft Security Advisory CVE-2026-50525 – .NET Denial of Service Vulnerability</description>
    </item>
    <item>
      <title>Microsoft Security Advisory CVE-2026-50528 – .NET Security Feature Bypass Vulnerability</title>
      <link>https://www.patchbrief.org/items/2026-07-nuget-cve-2026-50528.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-nuget-cve-2026-50528.html</guid>
      <pubDate>Mon, 20 Jul 2026 00:00:00 +0000</pubDate>
      <description>Microsoft Security Advisory CVE-2026-50528 – .NET Security Feature Bypass Vulnerability</description>
    </item>
    <item>
      <title>Microsoft Security Advisory CVE-2026-50648 – .NET Denial of Service Vulnerability</title>
      <link>https://www.patchbrief.org/items/2026-07-nuget-cve-2026-50648.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-nuget-cve-2026-50648.html</guid>
      <pubDate>Mon, 20 Jul 2026 00:00:00 +0000</pubDate>
      <description>Microsoft Security Advisory CVE-2026-50648 – .NET Denial of Service Vulnerability</description>
    </item>
    <item>
      <title>Microsoft Security Advisory CVE-2026-50651 – .NET Denial of Service Vulnerability</title>
      <link>https://www.patchbrief.org/items/2026-07-nuget-cve-2026-50651.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-nuget-cve-2026-50651.html</guid>
      <pubDate>Mon, 20 Jul 2026 00:00:00 +0000</pubDate>
      <description>Microsoft Security Advisory CVE-2026-50651 – .NET Denial of Service Vulnerability</description>
    </item>
    <item>
      <title>Microsoft Security Advisory CVE-2026-57108 – .NET Denial of Service Vulnerability</title>
      <link>https://www.patchbrief.org/items/2026-07-nuget-cve-2026-57108.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-nuget-cve-2026-57108.html</guid>
      <pubDate>Mon, 20 Jul 2026 00:00:00 +0000</pubDate>
      <description>Microsoft Security Advisory CVE-2026-57108 – .NET Denial of Service Vulnerability</description>
    </item>
    <item>
      <title>Pillow: Heap out-of-bounds write in `ImageFilter.RankFilter` via integer overflow in `ImagingExpand`</title>
      <link>https://www.patchbrief.org/items/2026-07-pypi-cve-2026-59197.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-pypi-cve-2026-59197.html</guid>
      <pubDate>Mon, 20 Jul 2026 00:00:00 +0000</pubDate>
      <description>Pillow: Heap out-of-bounds write in `ImageFilter.RankFilter` via integer overflow in `ImagingExpand`</description>
    </item>
    <item>
      <title>Pillow: Heap out-of-bounds write `Image.paste()` / `Image.crop()` via signed coordinate overflow</title>
      <link>https://www.patchbrief.org/items/2026-07-pypi-cve-2026-59199.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-pypi-cve-2026-59199.html</guid>
      <pubDate>Mon, 20 Jul 2026 00:00:00 +0000</pubDate>
      <description>Pillow: Heap out-of-bounds write `Image.paste()` / `Image.crop()` via signed coordinate overflow</description>
    </item>
    <item>
      <title>Pillow: Decompression Bomb DoS via PdfParser.PdfStream.decode()</title>
      <link>https://www.patchbrief.org/items/2026-07-pypi-cve-2026-59200.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-pypi-cve-2026-59200.html</guid>
      <pubDate>Mon, 20 Jul 2026 00:00:00 +0000</pubDate>
      <description>Pillow: Decompression Bomb DoS via PdfParser.PdfStream.decode()</description>
    </item>
    <item>
      <title>Pillow JPEG2000 tiled decode retains a growing scratch buffer and can be used for denial of service</title>
      <link>https://www.patchbrief.org/items/2026-07-pypi-cve-2026-59204.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-pypi-cve-2026-59204.html</guid>
      <pubDate>Mon, 20 Jul 2026 00:00:00 +0000</pubDate>
      <description>Pillow JPEG2000 tiled decode retains a growing scratch buffer and can be used for denial of service</description>
    </item>
    <item>
      <title>Pillow: Controlled heap out-of-bounds write in Pillow `ImageCmsTransform.apply()` via output mode mismatch</title>
      <link>https://www.patchbrief.org/items/2026-07-pypi-cve-2026-59205.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-pypi-cve-2026-59205.html</guid>
      <pubDate>Mon, 20 Jul 2026 00:00:00 +0000</pubDate>
      <description>Pillow: Controlled heap out-of-bounds write in Pillow `ImageCmsTransform.apply()` via output mode mismatch</description>
    </item>
    <item>
      <title>Mistune plugins/formatting: quadratic-time parsing on long runs of `~~x~~`, `==x==`, and `^^x^^` markers (strikethrou...</title>
      <link>https://www.patchbrief.org/items/2026-07-pypi-cve-2026-59922.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-pypi-cve-2026-59922.html</guid>
      <pubDate>Mon, 20 Jul 2026 00:00:00 +0000</pubDate>
      <description>Mistune plugins/formatting: quadratic-time parsing on long runs of `~~x~~`, `==x==`, and `^^x^^` markers (strikethrough / mark / insert)</description>
    </item>
    <item>
      <title>Mistune inline_parser: quadratic-time parsing on long runs of `**x**` and `***x***` emphasis pairs</title>
      <link>https://www.patchbrief.org/items/2026-07-pypi-cve-2026-59925.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-pypi-cve-2026-59925.html</guid>
      <pubDate>Mon, 20 Jul 2026 00:00:00 +0000</pubDate>
      <description>Mistune inline_parser: quadratic-time parsing on long runs of `**x**` and `***x***` emphasis pairs</description>
    </item>
    <item>
      <title>Mistune block_parser: quadratic-time parsing on long lists of repeated reference-link definitions</title>
      <link>https://www.patchbrief.org/items/2026-07-pypi-cve-2026-59928.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-pypi-cve-2026-59928.html</guid>
      <pubDate>Mon, 20 Jul 2026 00:00:00 +0000</pubDate>
      <description>Mistune block_parser: quadratic-time parsing on long lists of repeated reference-link definitions</description>
    </item>
    <item>
      <title>LightRAG: CORS Wildcard + Credentials Enables Any-Origin Credentialed Requests</title>
      <link>https://www.patchbrief.org/items/2026-07-pypi-cve-2026-61736.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-pypi-cve-2026-61736.html</guid>
      <pubDate>Mon, 20 Jul 2026 00:00:00 +0000</pubDate>
      <description>LightRAG: CORS Wildcard + Credentials Enables Any-Origin Credentialed Requests</description>
    </item>
    <item>
      <title>LightRAG is Vulnerable to Authentication Bypass: hardcoded DEFAULT_TOKEN_SECRET and public /auth-status defeat LIGHTR...</title>
      <link>https://www.patchbrief.org/items/2026-07-pypi-cve-2026-61740.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-pypi-cve-2026-61740.html</guid>
      <pubDate>Mon, 20 Jul 2026 00:00:00 +0000</pubDate>
      <description>LightRAG is Vulnerable to Authentication Bypass: hardcoded DEFAULT_TOKEN_SECRET and public /auth-status defeat LIGHTRAG_API_KEY protection</description>
    </item>
    <item>
      <title>Gitea has insufficient permission checks for Composer package source links</title>
      <link>https://www.patchbrief.org/items/2026-07-go-cve-2026-27771.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-go-cve-2026-27771.html</guid>
      <pubDate>Fri, 17 Jul 2026 00:00:00 +0000</pubDate>
      <description>Gitea has insufficient permission checks for Composer package source links</description>
    </item>
    <item>
      <title>Skipper: Incomplete fix for CVE-2026-50197: an oversized body can bypass OPA deny-on-presence Rego policies</title>
      <link>https://www.patchbrief.org/items/2026-07-go-ghsa-8qqm-fp2q-v734.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-go-ghsa-8qqm-fp2q-v734.html</guid>
      <pubDate>Fri, 17 Jul 2026 00:00:00 +0000</pubDate>
      <description>Skipper: Incomplete fix for CVE-2026-50197: an oversized body can bypass OPA deny-on-presence Rego policies</description>
    </item>
    <item>
      <title>IBM Langflow OSS 1.0.0 — CVE-2026-9135 (Critical)</title>
      <link>https://www.patchbrief.org/items/2026-07-ibm-cve-2026-9135.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-ibm-cve-2026-9135.html</guid>
      <pubDate>Fri, 17 Jul 2026 00:00:00 +0000</pubDate>
      <description>IBM Langflow OSS 1.0.0 through 1.10.0 Langflow versions up to 1.9.2 (commit 94981c443d4918517b9e8163d70fc598dc33a32d) contain a code injection vulnerability in the Policies component's ToolGuard integration that bypasses the allow_custom_components=false security control. The vulnerability exists because the validation mechanism only checks the main component source code in node_template["code"]["value"] but fails to validate dynamic CodeInput fields that store generated ToolGuard Python files. Attackers can embed malicious Python code in these unvalidated dynamic fields, which are persisted i</description>
    </item>
    <item>
      <title>AWS-JDBC Wrapper: Privilege Escalation in Aurora PostgreSQL instance</title>
      <link>https://www.patchbrief.org/items/2026-07-maven-cve-2026-11400.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-maven-cve-2026-11400.html</guid>
      <pubDate>Fri, 17 Jul 2026 00:00:00 +0000</pubDate>
      <description>AWS-JDBC Wrapper: Privilege Escalation in Aurora PostgreSQL instance</description>
    </item>
    <item>
      <title>Prompty: Arbitrary code execution via JavaScript frontmatter in TypeScript loader</title>
      <link>https://www.patchbrief.org/items/2026-07-npm-cve-2026-53597.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-npm-cve-2026-53597.html</guid>
      <pubDate>Fri, 17 Jul 2026 00:00:00 +0000</pubDate>
      <description>Prompty: Arbitrary code execution via JavaScript frontmatter in TypeScript loader</description>
    </item>
    <item>
      <title>CloudTAK: Authenticated full-read SSRF in the /api/esri* routes — user-controlled URL fetched with no IP-classificati...</title>
      <link>https://www.patchbrief.org/items/2026-07-npm-cve-2026-55177.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-npm-cve-2026-55177.html</guid>
      <pubDate>Fri, 17 Jul 2026 00:00:00 +0000</pubDate>
      <description>CloudTAK: Authenticated full-read SSRF in the /api/esri* routes — user-controlled URL fetched with no IP-classification guard</description>
    </item>
    <item>
      <title>Prompty: Arbitrary file read via file reference expansion</title>
      <link>https://www.patchbrief.org/items/2026-07-pypi-cve-2026-53598.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-pypi-cve-2026-53598.html</guid>
      <pubDate>Fri, 17 Jul 2026 00:00:00 +0000</pubDate>
      <description>Prompty: Arbitrary file read via file reference expansion</description>
    </item>
    <item>
      <title>vLLM has Remote DoS via Invalid Recovered Token Reinjection</title>
      <link>https://www.patchbrief.org/items/2026-07-pypi-cve-2026-54234.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-pypi-cve-2026-54234.html</guid>
      <pubDate>Fri, 17 Jul 2026 00:00:00 +0000</pubDate>
      <description>vLLM has Remote DoS via Invalid Recovered Token Reinjection</description>
    </item>
    <item>
      <title>meta-ads-mcp: X-Pipeboard-Token Header Auth Bypass Reuses Operator Meta Token</title>
      <link>https://www.patchbrief.org/items/2026-07-pypi-cve-2026-54547.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-pypi-cve-2026-54547.html</guid>
      <pubDate>Fri, 17 Jul 2026 00:00:00 +0000</pubDate>
      <description>meta-ads-mcp: X-Pipeboard-Token Header Auth Bypass Reuses Operator Meta Token</description>
    </item>
    <item>
      <title>meta-ads-mcp: Server-Side Request Forgery (SSRF) in `upload_ad_image` via Unrestricted `image_url` Fetch</title>
      <link>https://www.patchbrief.org/items/2026-07-pypi-cve-2026-54549.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-pypi-cve-2026-54549.html</guid>
      <pubDate>Fri, 17 Jul 2026 00:00:00 +0000</pubDate>
      <description>meta-ads-mcp: Server-Side Request Forgery (SSRF) in `upload_ad_image` via Unrestricted `image_url` Fetch</description>
    </item>
    <item>
      <title>sh _uid does not drop supplementary groups (incomplete privilege drop)</title>
      <link>https://www.patchbrief.org/items/2026-07-pypi-cve-2026-54552.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-pypi-cve-2026-54552.html</guid>
      <pubDate>Fri, 17 Jul 2026 00:00:00 +0000</pubDate>
      <description>sh _uid does not drop supplementary groups (incomplete privilege drop)</description>
    </item>
    <item>
      <title>Flask-Reuploaded: Extension-denylist bypass via case-folding asymmetry in name-override path (incomplete-fix variant ...</title>
      <link>https://www.patchbrief.org/items/2026-07-pypi-cve-2026-54567.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-pypi-cve-2026-54567.html</guid>
      <pubDate>Fri, 17 Jul 2026 00:00:00 +0000</pubDate>
      <description>Flask-Reuploaded: Extension-denylist bypass via case-folding asymmetry in name-override path (incomplete-fix variant of CVE-2026-27641)</description>
    </item>
    <item>
      <title>vLLM: ReDoS via structured_outputs.regex compiled without timeout in xgrammar and outlines backends</title>
      <link>https://www.patchbrief.org/items/2026-07-pypi-cve-2026-55574.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-pypi-cve-2026-55574.html</guid>
      <pubDate>Fri, 17 Jul 2026 00:00:00 +0000</pubDate>
      <description>vLLM: ReDoS via structured_outputs.regex compiled without timeout in xgrammar and outlines backends</description>
    </item>
    <item>
      <title>Pheditor has an authenticated terminal command whitelist bypass</title>
      <link>https://www.patchbrief.org/items/2026-07-composer-cve-2026-54540.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-composer-cve-2026-54540.html</guid>
      <pubDate>Thu, 16 Jul 2026 00:00:00 +0000</pubDate>
      <description>Pheditor has an authenticated terminal command whitelist bypass</description>
    </item>
    <item>
      <title>Pheditor: Incomplete command sanitization in terminal feature allows RCE via pipe operator, backtick substitution, an...</title>
      <link>https://www.patchbrief.org/items/2026-07-composer-cve-2026-55578.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-composer-cve-2026-55578.html</guid>
      <pubDate>Thu, 16 Jul 2026 00:00:00 +0000</pubDate>
      <description>Pheditor: Incomplete command sanitization in terminal feature allows RCE via pipe operator, backtick substitution, and newline injection</description>
    </item>
    <item>
      <title>Pheditor: Hardcoded default password 'admin' with no forced change enables full application compromise</title>
      <link>https://www.patchbrief.org/items/2026-07-composer-cve-2026-55579.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-composer-cve-2026-55579.html</guid>
      <pubDate>Thu, 16 Jul 2026 00:00:00 +0000</pubDate>
      <description>Pheditor: Hardcoded default password 'admin' with no forced change enables full application compromise</description>
    </item>
    <item>
      <title>Fortinet FortiSandbox OS Command Injection Vulnerability</title>
      <link>https://www.patchbrief.org/items/2026-07-fortinet-cve-2026-25089.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-fortinet-cve-2026-25089.html</guid>
      <pubDate>Thu, 16 Jul 2026 00:00:00 +0000</pubDate>
      <description>Fortinet FortiSandbox, FortiSandbox Cloud, and FortiSandbox PaaS contain an OS command injection vulnerability that allows an unauthenticated attacker to execute unauthorized commands via specifically crafted HTTP requests.</description>
    </item>
    <item>
      <title>Fortinet FortiSandbox OS Command Injection Vulnerability</title>
      <link>https://www.patchbrief.org/items/2026-07-fortinet-cve-2026-39808.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-fortinet-cve-2026-39808.html</guid>
      <pubDate>Thu, 16 Jul 2026 00:00:00 +0000</pubDate>
      <description>Fortinet FortiSandbox contains an OS command injection vulnerability that could allow an unauthenticated attacker to execute unauthorized code or commands via crafted HTTP requests.</description>
    </item>
    <item>
      <title>Nuclio: Unsanitized runtimeAttributes.repositories injected into Groovy build.gradle leads to build-time RCE</title>
      <link>https://www.patchbrief.org/items/2026-07-go-cve-2026-52833.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-go-cve-2026-52833.html</guid>
      <pubDate>Thu, 16 Jul 2026 00:00:00 +0000</pubDate>
      <description>Nuclio: Unsanitized runtimeAttributes.repositories injected into Groovy build.gradle leads to build-time RCE</description>
    </item>
    <item>
      <title>Envoy Gateway: Authentication Bypass via Improper Input Validation in EnvoyExtensionPolicy Lua Allows Secret Disclosure</title>
      <link>https://www.patchbrief.org/items/2026-07-go-cve-2026-53713.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-go-cve-2026-53713.html</guid>
      <pubDate>Thu, 16 Jul 2026 00:00:00 +0000</pubDate>
      <description>Envoy Gateway: Authentication Bypass via Improper Input Validation in EnvoyExtensionPolicy Lua Allows Secret Disclosure</description>
    </item>
    <item>
      <title>Envoy Gateway: xDS Control Plane Information Disclosure when operating in GatewayNamespaceMode</title>
      <link>https://www.patchbrief.org/items/2026-07-go-cve-2026-53714.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-go-cve-2026-53714.html</guid>
      <pubDate>Thu, 16 Jul 2026 00:00:00 +0000</pubDate>
      <description>Envoy Gateway: xDS Control Plane Information Disclosure when operating in GatewayNamespaceMode</description>
    </item>
    <item>
      <title>Hcltech Dfxanalytics — CVE-2026-56453 (Critical)</title>
      <link>https://www.patchbrief.org/items/2026-07-hcltech-cve-2026-56453.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-hcltech-cve-2026-56453.html</guid>
      <pubDate>Thu, 16 Jul 2026 00:00:00 +0000</pubDate>
      <description>HCL DFXAnalytics is affected by an Account Takeover via Response Manipulation vulnerability. A remote attacker can intercept and alter the contents of the server's HTTP responses before they reach the client application, allowing them to manipulate the authentication or authorization logic to bypass controls and gain unauthorized access to targeted user accounts.</description>
    </item>
    <item>
      <title>VU#885548: Denial-of-service vulnerability in HTTP/2 servers via stalled flow-control conditions</title>
      <link>https://www.patchbrief.org/items/2026-07-http-2-vu-885548.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-http-2-vu-885548.html</guid>
      <pubDate>Thu, 16 Jul 2026 00:00:00 +0000</pubDate>
      <description>Overview A denial-of-service (DoS) vulnerability exists in some HTTP/2 server implementations that fail to adequately limit resource consumption when buffering response data under stalled flow-control conditions. A remote, unauthenticated attacker can trigger memory exhaustion and service interruption by using standard flow-control parameters such as SETTINGS_INITIAL_WINDOW_SIZE = 0 to stall outbound data for multiple simultaneous request streams. Description HTTP/2 is a widely used application-layer protocol that supports multiplexing, header compression, and flow-control mechanisms to regulate the transmission of data between web browsers and servers. Flow control is designed to prevent senders from overwhelming receivers and relies on client-advertised window sizes to determine the maximum volume of unacknowledged data that can be in...</description>
    </item>
    <item>
      <title>ArcadeDB: Read-only users can mutate database schema (incomplete fix of CVE-2026-44221)</title>
      <link>https://www.patchbrief.org/items/2026-07-maven-cve-2026-54076.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-maven-cve-2026-54076.html</guid>
      <pubDate>Thu, 16 Jul 2026 00:00:00 +0000</pubDate>
      <description>ArcadeDB: Read-only users can mutate database schema (incomplete fix of CVE-2026-44221)</description>
    </item>
    <item>
      <title>ArcadeDB: IMPORT DATABASE allows SSRF and arbitrary local file read by authenticated users</title>
      <link>https://www.patchbrief.org/items/2026-07-maven-cve-2026-54077.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-maven-cve-2026-54077.html</guid>
      <pubDate>Thu, 16 Jul 2026 00:00:00 +0000</pubDate>
      <description>ArcadeDB: IMPORT DATABASE allows SSRF and arbitrary local file read by authenticated users</description>
    </item>
    <item>
      <title>ArcadeDB: Privilege escalation via reader role in /api/v1/command JS scripting language — arbitrary host file read</title>
      <link>https://www.patchbrief.org/items/2026-07-maven-ghsa-48qw-824m-86pr.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-maven-ghsa-48qw-824m-86pr.html</guid>
      <pubDate>Thu, 16 Jul 2026 00:00:00 +0000</pubDate>
      <description>ArcadeDB: Privilege escalation via reader role in /api/v1/command JS scripting language — arbitrary host file read</description>
    </item>
    <item>
      <title>ArcadeDB: Scripting authorization gate (GHSA-48qw-824m-86pr) bypassed via SQL DEFINE FUNCTION ... LANGUAGE js</title>
      <link>https://www.patchbrief.org/items/2026-07-maven-ghsa-vwjc-v7x7-cm6g.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-maven-ghsa-vwjc-v7x7-cm6g.html</guid>
      <pubDate>Thu, 16 Jul 2026 00:00:00 +0000</pubDate>
      <description>ArcadeDB: Scripting authorization gate (GHSA-48qw-824m-86pr) bypassed via SQL DEFINE FUNCTION ... LANGUAGE js</description>
    </item>
    <item>
      <title>ArcadeDB has cross-database IDOR: /ts/*, /batch/*, Prometheus and Grafana handlers bypass authorization</title>
      <link>https://www.patchbrief.org/items/2026-07-maven-ghsa-x8mg-6r4p-87pf.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-maven-ghsa-x8mg-6r4p-87pf.html</guid>
      <pubDate>Thu, 16 Jul 2026 00:00:00 +0000</pubDate>
      <description>ArcadeDB has cross-database IDOR: /ts/*, /batch/*, Prometheus and Grafana handlers bypass authorization</description>
    </item>
    <item>
      <title>ArcadeDB: Trigger scripts run with java.lang.* allowed, enabling OS command execution (RCE)</title>
      <link>https://www.patchbrief.org/items/2026-07-maven-ghsa-x9f9-r4m8-9xc2.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-maven-ghsa-x9f9-r4m8-9xc2.html</guid>
      <pubDate>Thu, 16 Jul 2026 00:00:00 +0000</pubDate>
      <description>ArcadeDB: Trigger scripts run with java.lang.* allowed, enabling OS command execution (RCE)</description>
    </item>
    <item>
      <title>MCP Python SDK: HTTP transports serve session requests without verifying the authenticated principal</title>
      <link>https://www.patchbrief.org/items/2026-07-pypi-cve-2026-52869.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-pypi-cve-2026-52869.html</guid>
      <pubDate>Thu, 16 Jul 2026 00:00:00 +0000</pubDate>
      <description>MCP Python SDK: HTTP transports serve session requests without verifying the authenticated principal</description>
    </item>
    <item>
      <title>MCP Python SDK: Experimental task handlers allow any client to access and cancel other clients' tasks</title>
      <link>https://www.patchbrief.org/items/2026-07-pypi-cve-2026-52870.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-pypi-cve-2026-52870.html</guid>
      <pubDate>Thu, 16 Jul 2026 00:00:00 +0000</pubDate>
      <description>MCP Python SDK: Experimental task handlers allow any client to access and cancel other clients' tasks</description>
    </item>
    <item>
      <title>MCP Python SDK: WebSocket server transport does not support Host/Origin validation</title>
      <link>https://www.patchbrief.org/items/2026-07-pypi-cve-2026-59950.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-pypi-cve-2026-59950.html</guid>
      <pubDate>Thu, 16 Jul 2026 00:00:00 +0000</pubDate>
      <description>MCP Python SDK: WebSocket server transport does not support Host/Origin validation</description>
    </item>
    <item>
      <title>VU#326070: SGLang contains a vulnerable pickle deserialization vulnerability through the expert-parallel subsystem</title>
      <link>https://www.patchbrief.org/items/2026-07-sglang-vu-326070.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-sglang-vu-326070.html</guid>
      <pubDate>Thu, 16 Jul 2026 00:00:00 +0000</pubDate>
      <description>Overview A Pickle deserialization vulnerability has been discovered within the SGLang project , enabling an attacker to perform remote code execution (RCE) on the target vulnerable server. In order for an attacker to exploit this vulnerability, the expert-parallel backup subsystem must be enabled, and an attacker must have network access to the SGLang service. No patch is available at this time, and no response was obtained from the project maintainers during coordination. Description SGLang is an open-source framework for serving large language models (LLMs) and multimodal AI models, supporting models such as Qwen, DeepSeek, Mistral, and Skywork, and is compatible with OpenAI APIs. A vulnerability has been discovered within the tool and is tracked as follows: CVE-2026-14890 SGLang uses an expert-parallel backup subsystem designed to... Related CVEs: CVE-2026-14890, CVE-2026-7301, CVE-2026-7304.</description>
    </item>
    <item>
      <title>Spaceapplications Yamcs — CVE-2026-44596 (Critical)</title>
      <link>https://www.patchbrief.org/items/2026-07-spaceapplications-cve-2026-44596.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-spaceapplications-cve-2026-44596.html</guid>
      <pubDate>Thu, 16 Jul 2026 00:00:00 +0000</pubDate>
      <description>Yamcs is a mission control framework. Prior to 5.12.7, the authentication endpoint POST /auth/token in yamcs-core, handled by yamcs-core/src/main/java/org/yamcs/http/auth/AuthHandler.java, lacked any rate limiting, account lockout, or failed-attempt throttling, so an unauthenticated remote attacker could perform unlimited password-guessing attempts against any user account, significantly increasing the risk of successful brute-force attacks. This issue is fixed in versions 5.12.7 and 5.13.0.</description>
    </item>
    <item>
      <title>MantisBT: SOAP API Authentication Bypass with Privilege Escalation to Administrator</title>
      <link>https://www.patchbrief.org/items/2026-07-composer-cve-2026-47156.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-composer-cve-2026-47156.html</guid>
      <pubDate>Wed, 15 Jul 2026 00:00:00 +0000</pubDate>
      <description>MantisBT: SOAP API Authentication Bypass with Privilege Escalation to Administrator</description>
    </item>
    <item>
      <title>MantisBT: Reflected XSS in admin/install.php</title>
      <link>https://www.patchbrief.org/items/2026-07-composer-cve-2026-52847.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-composer-cve-2026-52847.html</guid>
      <pubDate>Wed, 15 Jul 2026 00:00:00 +0000</pubDate>
      <description>MantisBT: Reflected XSS in admin/install.php</description>
    </item>
    <item>
      <title>MantisBT: Reflected XSS in admin/install.php via unescaped printf</title>
      <link>https://www.patchbrief.org/items/2026-07-composer-cve-2026-52881.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-composer-cve-2026-52881.html</guid>
      <pubDate>Wed, 15 Jul 2026 00:00:00 +0000</pubDate>
      <description>MantisBT: Reflected XSS in admin/install.php via unescaped printf</description>
    </item>
    <item>
      <title>Koel: Incomplete fix for CVE-2026-47260 — systemic SSRF in podcast &amp; radio fetch paths</title>
      <link>https://www.patchbrief.org/items/2026-07-composer-cve-2026-54491.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-composer-cve-2026-54491.html</guid>
      <pubDate>Wed, 15 Jul 2026 00:00:00 +0000</pubDate>
      <description>Koel: Incomplete fix for CVE-2026-47260 — systemic SSRF in podcast &amp; radio fetch paths</description>
    </item>
    <item>
      <title>MantisBT: Stored XSS in print_all_bug_page_word.php</title>
      <link>https://www.patchbrief.org/items/2026-07-composer-cve-2026-62944.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-composer-cve-2026-62944.html</guid>
      <pubDate>Wed, 15 Jul 2026 00:00:00 +0000</pubDate>
      <description>MantisBT: Stored XSS in print_all_bug_page_word.php</description>
    </item>
    <item>
      <title>Protobuf: Unbounded recursion depth in embedded-message decoding</title>
      <link>https://www.patchbrief.org/items/2026-07-erlang-cve-2026-54451.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-erlang-cve-2026-54451.html</guid>
      <pubDate>Wed, 15 Jul 2026 00:00:00 +0000</pubDate>
      <description>Protobuf: Unbounded recursion depth in embedded-message decoding</description>
    </item>
    <item>
      <title>dd-trace-go: Improper parsing of W3C baggage headers may lead to DoS</title>
      <link>https://www.patchbrief.org/items/2026-07-go-cve-2026-50274.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-go-cve-2026-50274.html</guid>
      <pubDate>Wed, 15 Jul 2026 00:00:00 +0000</pubDate>
      <description>dd-trace-go: Improper parsing of W3C baggage headers may lead to DoS</description>
    </item>
    <item>
      <title>Pomerium Pre-Auth Memory Exhaustion via Unbounded zstd Decompression in HPKE Callback</title>
      <link>https://www.patchbrief.org/items/2026-07-go-cve-2026-50285.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-go-cve-2026-50285.html</guid>
      <pubDate>Wed, 15 Jul 2026 00:00:00 +0000</pubDate>
      <description>Pomerium Pre-Auth Memory Exhaustion via Unbounded zstd Decompression in HPKE Callback</description>
    </item>
    <item>
      <title>KNX Association KNX Protocol Connection Authorization Option 1 Overly Restrictive Account Lockout Mechanism Vulnerabi...</title>
      <link>https://www.patchbrief.org/items/2026-07-knx-association-cve-2023-4346.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-knx-association-cve-2023-4346.html</guid>
      <pubDate>Wed, 15 Jul 2026 00:00:00 +0000</pubDate>
      <description>KNX Association KNX Protocol Connection Authorization Option 1 contains an overly restrictive account lockout mechanism vulnerability that could allow an attacker to purge all devices without additional security options enabled and set a BCU key to lock the device.</description>
    </item>
    <item>
      <title>dd-trace-java: Improper parsing of W3C baggage headers may lead to DoS</title>
      <link>https://www.patchbrief.org/items/2026-07-maven-cve-2026-50270.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-maven-cve-2026-50270.html</guid>
      <pubDate>Wed, 15 Jul 2026 00:00:00 +0000</pubDate>
      <description>dd-trace-java: Improper parsing of W3C baggage headers may lead to DoS</description>
    </item>
    <item>
      <title>dd-trace-js: Improper parsing of W3C baggage headers may lead to DoS</title>
      <link>https://www.patchbrief.org/items/2026-07-npm-cve-2026-50272.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-npm-cve-2026-50272.html</guid>
      <pubDate>Wed, 15 Jul 2026 00:00:00 +0000</pubDate>
      <description>dd-trace-js: Improper parsing of W3C baggage headers may lead to DoS</description>
    </item>
    <item>
      <title>systeminformation: OS command injection in networkInterfaces() via interfaces(5) source-directive path on Linux</title>
      <link>https://www.patchbrief.org/items/2026-07-npm-cve-2026-50289.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-npm-cve-2026-50289.html</guid>
      <pubDate>Wed, 15 Jul 2026 00:00:00 +0000</pubDate>
      <description>systeminformation: OS command injection in networkInterfaces() via interfaces(5) source-directive path on Linux</description>
    </item>
    <item>
      <title>websocket-driver: Message corruption via abuse of protocol length headers</title>
      <link>https://www.patchbrief.org/items/2026-07-npm-cve-2026-54466.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-npm-cve-2026-54466.html</guid>
      <pubDate>Wed, 15 Jul 2026 00:00:00 +0000</pubDate>
      <description>websocket-driver: Message corruption via abuse of protocol length headers</description>
    </item>
    <item>
      <title>@andrea9293/mcp-documentation-server: Web UI API binds to all interfaces without authentication by default</title>
      <link>https://www.patchbrief.org/items/2026-07-npm-cve-2026-54504.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-npm-cve-2026-54504.html</guid>
      <pubDate>Wed, 15 Jul 2026 00:00:00 +0000</pubDate>
      <description>@andrea9293/mcp-documentation-server: Web UI API binds to all interfaces without authentication by default</description>
    </item>
    <item>
      <title>obsidian-local-rest-api: Authenticated path traversal via URL-encoded %2F in /vault/{path} — arbitrary host file read...</title>
      <link>https://www.patchbrief.org/items/2026-07-npm-ghsa-62gx-5q78-wrvx.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-npm-ghsa-62gx-5q78-wrvx.html</guid>
      <pubDate>Wed, 15 Jul 2026 00:00:00 +0000</pubDate>
      <description>obsidian-local-rest-api: Authenticated path traversal via URL-encoded %2F in /vault/{path} — arbitrary host file read/write/delete</description>
    </item>
    <item>
      <title>dd-trace-dotnet: Improper parsing of W3C baggage headers may lead to DoS</title>
      <link>https://www.patchbrief.org/items/2026-07-nuget-cve-2026-50273.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-nuget-cve-2026-50273.html</guid>
      <pubDate>Wed, 15 Jul 2026 00:00:00 +0000</pubDate>
      <description>dd-trace-dotnet: Improper parsing of W3C baggage headers may lead to DoS</description>
    </item>
    <item>
      <title>Openwebui Open Webui — CVE-2026-56398 (Critical)</title>
      <link>https://www.patchbrief.org/items/2026-07-openwebui-cve-2026-56398.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-openwebui-cve-2026-56398.html</guid>
      <pubDate>Wed, 15 Jul 2026 00:00:00 +0000</pubDate>
      <description>Open WebUI before 0.9.5 contains a stored cross-site scripting vulnerability in the OAuth authentication flow where the picture claim URL MIME type is inferred from file extension rather than Content-Type header, allowing SVG files to bypass the profile image validator and be stored as data URIs. Authenticated users who visit the profile image endpoint receive attacker-controlled SVG content with inline disposition and no default security headers, enabling script execution in the same origin to steal authentication tokens and achieve account takeover.</description>
    </item>
    <item>
      <title>Openwebui Open Webui — CVE-2026-56400 (Critical)</title>
      <link>https://www.patchbrief.org/items/2026-07-openwebui-cve-2026-56400.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-openwebui-cve-2026-56400.html</guid>
      <pubDate>Wed, 15 Jul 2026 00:00:00 +0000</pubDate>
      <description>open-webui before 0.3.14 contains a cross-origin resource sharing misconfiguration allowing arbitrary origins with allow_origins=* and authenticated requests to the /api/v1/functions endpoint. Attackers can execute arbitrary code on the openwebui instance by crafting malicious cross-site requests from attacker-controlled websites when an admin user visits them.</description>
    </item>
    <item>
      <title>Oracle E-Business Suite Improper Privilege Management Vulnerability</title>
      <link>https://www.patchbrief.org/items/2026-07-oracle-cve-2026-46817.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-oracle-cve-2026-46817.html</guid>
      <pubDate>Wed, 15 Jul 2026 00:00:00 +0000</pubDate>
      <description>Oracle E-Business Suite contains an improper privilege management vulnerability that allows an unauthenticated attacker with network access via HTTP to compromise Oracle Payments. Successful attacks of this vulnerability can result in takeover of Oracle Payments.</description>
    </item>
    <item>
      <title>VU#529388: Privilege escalation vulnerability via unprotected IOCTL interface in Pegatron Tdelo64.sys</title>
      <link>https://www.patchbrief.org/items/2026-07-pegatron-vu-529388.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-pegatron-vu-529388.html</guid>
      <pubDate>Wed, 15 Jul 2026 00:00:00 +0000</pubDate>
      <description>Overview A privilege escalation vulnerability exists in the tdeio64.sys driver due to an unprotected input/output control (IOCTL) dispatch routine that fails to validate the origin and permissions of user-supplied requests. An unprivileged local attacker can abuse exposed IOCTL dispatch routines [RM1.1][MB1.2]to perform arbitrary kernel memory read and write operations, ultimately obtaining NT AUTHORITY\SYSTEM privileges and compromising the security of the affected system. Description The tdeio64.sys driver distributed by Pegatron Corporation, a Taiwanese electronics manufacturer that produces motherboards and OEM components, is a Windows Driver Model (WDM) driver that provides low-level access to system I/O ports and hardware components. The driver exposes the \\.\TdeIo device interface and processes privileged IOTL requests without... Related CVEs: CVE-2026-14960, CVE-2026-14961.</description>
    </item>
    <item>
      <title>dd-trace-py: Improper parsing of W3C baggage headers may lead to DoS</title>
      <link>https://www.patchbrief.org/items/2026-07-pypi-cve-2026-50271.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-pypi-cve-2026-50271.html</guid>
      <pubDate>Wed, 15 Jul 2026 00:00:00 +0000</pubDate>
      <description>dd-trace-py: Improper parsing of W3C baggage headers may lead to DoS</description>
    </item>
    <item>
      <title>LangBot: Authenticated RCE Via MCP Configuration</title>
      <link>https://www.patchbrief.org/items/2026-07-pypi-cve-2026-54449.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-pypi-cve-2026-54449.html</guid>
      <pubDate>Wed, 15 Jul 2026 00:00:00 +0000</pubDate>
      <description>LangBot: Authenticated RCE Via MCP Configuration</description>
    </item>
    <item>
      <title>TensorZero Gateway: Arbitrary file read and SSRF in internal object storage endpoint</title>
      <link>https://www.patchbrief.org/items/2026-07-pypi-cve-2026-54457.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-pypi-cve-2026-54457.html</guid>
      <pubDate>Wed, 15 Jul 2026 00:00:00 +0000</pubDate>
      <description>TensorZero Gateway: Arbitrary file read and SSRF in internal object storage endpoint</description>
    </item>
    <item>
      <title>django-haystack: Remote Code Execution via `eval()` in Elasticsearch Result Deserialization</title>
      <link>https://www.patchbrief.org/items/2026-07-pypi-ghsa-r3hx-x5rh-p9vv.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-pypi-ghsa-r3hx-x5rh-p9vv.html</guid>
      <pubDate>Wed, 15 Jul 2026 00:00:00 +0000</pubDate>
      <description>django-haystack: Remote Code Execution via `eval()` in Elasticsearch Result Deserialization</description>
    </item>
    <item>
      <title>VU#725167: node-forge Signature Forgery Vulnerabilities in RSA-PKCS and ED25519 Implementations</title>
      <link>https://www.patchbrief.org/items/2026-07-rsa-pkcs-vu-725167.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-rsa-pkcs-vu-725167.html</guid>
      <pubDate>Wed, 15 Jul 2026 00:00:00 +0000</pubDate>
      <description>Overview Two distinct cryptographic signature verification vulnerabilities exist in Digital Bazaar node-forge, a widely used JavaScript library implementing cryptographic primitives for Node.js and browser environments. These vulnerabilities allow attackers to forge RSA (PKCS#1 v1.5) and Ed25519 signatures under specific, exploitable conditions. Description Both vulnerabilities stem from insufficient enforcement of canonical cryptographic structures during verification: in the RSA case, non-standard ASN.1 encodings and undersized padding are accepted; in the Ed25519 case, non-canonical signature scalars are not rejected. As a result, node-forge accepts signatures that appear valid internally but are rejected by industry-standard libraries such as OpenSSL and Node.js’s native crypto module. The vulnerabilities affect node-forge versions... Related CVEs: CVE-2026-33894, CVE-2026-33895.</description>
    </item>
    <item>
      <title>dd-trace-rb: Improper parsing of W3C baggage headers may lead to DoS</title>
      <link>https://www.patchbrief.org/items/2026-07-rubygems-cve-2026-50276.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-rubygems-cve-2026-50276.html</guid>
      <pubDate>Wed, 15 Jul 2026 00:00:00 +0000</pubDate>
      <description>dd-trace-rb: Improper parsing of W3C baggage headers may lead to DoS</description>
    </item>
    <item>
      <title>ViewComponent: around_render HTML-Safety Bypass</title>
      <link>https://www.patchbrief.org/items/2026-07-rubygems-cve-2026-54498.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-rubygems-cve-2026-54498.html</guid>
      <pubDate>Wed, 15 Jul 2026 00:00:00 +0000</pubDate>
      <description>ViewComponent: around_render HTML-Safety Bypass</description>
    </item>
    <item>
      <title>Adobe Commerce — CVE-2026-47984 (Critical)</title>
      <link>https://www.patchbrief.org/items/2026-07-adobe-cve-2026-47984.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-adobe-cve-2026-47984.html</guid>
      <pubDate>Tue, 14 Jul 2026 00:00:00 +0000</pubDate>
      <description>Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass security measures and gain unauthorized read and write access. Exploitation of this issue does not require user interaction.</description>
    </item>
    <item>
      <title>Adobe Commerce — CVE-2026-47988 (Critical)</title>
      <link>https://www.patchbrief.org/items/2026-07-adobe-cve-2026-47988.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-adobe-cve-2026-47988.html</guid>
      <pubDate>Tue, 14 Jul 2026 00:00:00 +0000</pubDate>
      <description>Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass security measures and gain unauthorized read and write access. Exploitation of this issue does not require user interaction.</description>
    </item>
    <item>
      <title>Adobe Coldfusion — CVE-2026-48284 (Critical)</title>
      <link>https://www.patchbrief.org/items/2026-07-adobe-cve-2026-48284.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-adobe-cve-2026-48284.html</guid>
      <pubDate>Tue, 14 Jul 2026 00:00:00 +0000</pubDate>
      <description>ColdFusion is affected by an Improper Input Validation vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue does not require user interaction. Scope is changed.</description>
    </item>
    <item>
      <title>Adobe Coldfusion — CVE-2026-48319 (Critical)</title>
      <link>https://www.patchbrief.org/items/2026-07-adobe-cve-2026-48319.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-adobe-cve-2026-48319.html</guid>
      <pubDate>Tue, 14 Jul 2026 00:00:00 +0000</pubDate>
      <description>ColdFusion is affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue does not require user interaction. Scope is changed.</description>
    </item>
    <item>
      <title>Adobe Coldfusion — CVE-2026-48320 (Critical)</title>
      <link>https://www.patchbrief.org/items/2026-07-adobe-cve-2026-48320.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-adobe-cve-2026-48320.html</guid>
      <pubDate>Tue, 14 Jul 2026 00:00:00 +0000</pubDate>
      <description>ColdFusion is affected by a reflected Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this vulnerability to inject malicious scripts into a web page, potentially gaining elevated access or control over the victim's account or session. Exploitation of this issue requires user interaction in that a victim must open a malicious file. Scope is changed.</description>
    </item>
    <item>
      <title>Adobe Coldfusion — CVE-2026-48321 (Critical)</title>
      <link>https://www.patchbrief.org/items/2026-07-adobe-cve-2026-48321.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-adobe-cve-2026-48321.html</guid>
      <pubDate>Tue, 14 Jul 2026 00:00:00 +0000</pubDate>
      <description>ColdFusion is affected by an Incorrect Authorization vulnerability that could result in privilege escalation. An attacker could leverage this vulnerability to gain unauthorized read and write access. Exploitation of this issue does not require user interaction. Scope is changed.</description>
    </item>
    <item>
      <title>Adobe Commerce — CVE-2026-48356 (Critical)</title>
      <link>https://www.patchbrief.org/items/2026-07-adobe-cve-2026-48356.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-adobe-cve-2026-48356.html</guid>
      <pubDate>Tue, 14 Jul 2026 00:00:00 +0000</pubDate>
      <description>Adobe Commerce is affected by an Unrestricted Upload of File with Dangerous Type vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to inject malicious scripts into a web page, potentially gaining elevated access or control over the victim's account or session. Exploitation of this issue requires user interaction in that a victim must visit a maliciously crafted URL or interact with a compromised web page. Scope is changed.</description>
    </item>
    <item>
      <title>Adobe Commerce — CVE-2026-48358 (Critical)</title>
      <link>https://www.patchbrief.org/items/2026-07-adobe-cve-2026-48358.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-adobe-cve-2026-48358.html</guid>
      <pubDate>Tue, 14 Jul 2026 00:00:00 +0000</pubDate>
      <description>Adobe Commerce is affected by an Improper Encoding or Escaping of Output vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue does not require user interaction. Scope is changed.</description>
    </item>
    <item>
      <title>Apache Doris — CVE-2026-58319 (Critical)</title>
      <link>https://www.patchbrief.org/items/2026-07-apache-cve-2026-58319.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-apache-cve-2026-58319.html</guid>
      <pubDate>Tue, 14 Jul 2026 00:00:00 +0000</pubDate>
      <description>Certain Apache Doris FE HTTP REST administrative APIs were accessible without proper authentication. An unauthenticated attacker with network access to the FE HTTP service could perform unauthorized administrative operations, potentially affecting cluster integrity and availability and leading to cluster instability or denial of service. This issue affects Apache Doris versions prior to 3.1.0. Users are advised to upgrade to Apache Doris 3.1.0 or later.</description>
    </item>
    <item>
      <title>Apache Kylin — CVE-2026-62390 (Critical)</title>
      <link>https://www.patchbrief.org/items/2026-07-apache-cve-2026-62390.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-apache-cve-2026-62390.html</guid>
      <pubDate>Tue, 14 Jul 2026 00:00:00 +0000</pubDate>
      <description>Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Kylin. A backend API refreshing table catalog may cause the injection to the generated SQL. This issue affects Apache Kylin: from 4 through 5.0.3. Users are recommended to upgrade to version 5.0.4, which fixes the issue.</description>
    </item>
    <item>
      <title>Apache Kylin — CVE-2026-62392 (Critical)</title>
      <link>https://www.patchbrief.org/items/2026-07-apache-cve-2026-62392.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-apache-cve-2026-62392.html</guid>
      <pubDate>Tue, 14 Jul 2026 00:00:00 +0000</pubDate>
      <description>Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Apache Kylin. A backend API may bring job config parameters to OS command line. This issue affects Apache Kylin: from 4 through 5.0.3. Users are recommended to upgrade to version 5.0.4, which fixes the issue.</description>
    </item>
    <item>
      <title>FacturaScripts: Authenticated SQL injection in the FacturaScripts REST API filter parameter via parenthesis bypass in...</title>
      <link>https://www.patchbrief.org/items/2026-07-composer-cve-2026-45262.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-composer-cve-2026-45262.html</guid>
      <pubDate>Tue, 14 Jul 2026 00:00:00 +0000</pubDate>
      <description>FacturaScripts: Authenticated SQL injection in the FacturaScripts REST API filter parameter via parenthesis bypass in `Where::sqlColumn`</description>
    </item>
    <item>
      <title>FacturaScripts: CSV formula injection in CSVExport allows authenticated low-priv users to plant payloads that execute...</title>
      <link>https://www.patchbrief.org/items/2026-07-composer-cve-2026-45263.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-composer-cve-2026-45263.html</guid>
      <pubDate>Tue, 14 Jul 2026 00:00:00 +0000</pubDate>
      <description>FacturaScripts: CSV formula injection in CSVExport allows authenticated low-priv users to plant payloads that execute when an admin opens the export</description>
    </item>
    <item>
      <title>FacturaScripts: Unauthenticated Path Traversal in Static File Controllers Reads Private MyFiles Documents</title>
      <link>https://www.patchbrief.org/items/2026-07-composer-cve-2026-45693.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-composer-cve-2026-45693.html</guid>
      <pubDate>Tue, 14 Jul 2026 00:00:00 +0000</pubDate>
      <description>FacturaScripts: Unauthenticated Path Traversal in Static File Controllers Reads Private MyFiles Documents</description>
    </item>
    <item>
      <title>Kimai: Default APP_SECRET in Docker Image Enables Cookie Forgery and Account Takeover</title>
      <link>https://www.patchbrief.org/items/2026-07-composer-cve-2026-52824.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-composer-cve-2026-52824.html</guid>
      <pubDate>Tue, 14 Jul 2026 00:00:00 +0000</pubDate>
      <description>Kimai: Default APP_SECRET in Docker Image Enables Cookie Forgery and Account Takeover</description>
    </item>
    <item>
      <title>Kimai: Pre-2FA KIMAI_SESSION cookie grants full authenticated REST API access, bypassing TOTP</title>
      <link>https://www.patchbrief.org/items/2026-07-composer-cve-2026-52827.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-composer-cve-2026-52827.html</guid>
      <pubDate>Tue, 14 Jul 2026 00:00:00 +0000</pubDate>
      <description>Kimai: Pre-2FA KIMAI_SESSION cookie grants full authenticated REST API access, bypassing TOTP</description>
    </item>
    <item>
      <title>EasyAdmin: Stored Cross-Site Scripting (XSS) via uploaded files served inline in FileField and ImageField</title>
      <link>https://www.patchbrief.org/items/2026-07-composer-cve-2026-54087.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-composer-cve-2026-54087.html</guid>
      <pubDate>Tue, 14 Jul 2026 00:00:00 +0000</pubDate>
      <description>EasyAdmin: Stored Cross-Site Scripting (XSS) via uploaded files served inline in FileField and ImageField</description>
    </item>
    <item>
      <title>FacturaScripts: Path traversal in UploadedFile::move() via getClientOriginalName() — arbitrary file write outside MyF...</title>
      <link>https://www.patchbrief.org/items/2026-07-composer-ghsa-hgjx-r89m-m7v4.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-composer-ghsa-hgjx-r89m-m7v4.html</guid>
      <pubDate>Tue, 14 Jul 2026 00:00:00 +0000</pubDate>
      <description>FacturaScripts: Path traversal in UploadedFile::move() via getClientOriginalName() — arbitrary file write outside MyFiles/ leading to RCE</description>
    </item>
    <item>
      <title>Fortinet Forticlientems — CVE-2026-59836 (Critical)</title>
      <link>https://www.patchbrief.org/items/2026-07-fortinet-cve-2026-59836.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-fortinet-cve-2026-59836.html</guid>
      <pubDate>Tue, 14 Jul 2026 00:00:00 +0000</pubDate>
      <description>A improper certificate validation vulnerability in Fortinet FortiClientEMS 7.4.3 through 7.4.5, FortiClientEMS 7.4.0 through 7.4.1, FortiClientEMS 7.2 all versions may allow attacker to information disclosure via &lt;insert attack vector here&gt;</description>
    </item>
    <item>
      <title>OpenCost ServiceKey Endpoint Unauthorized Credential Overwrite/Injection</title>
      <link>https://www.patchbrief.org/items/2026-07-go-cve-2026-44300.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-go-cve-2026-44300.html</guid>
      <pubDate>Tue, 14 Jul 2026 00:00:00 +0000</pubDate>
      <description>OpenCost ServiceKey Endpoint Unauthorized Credential Overwrite/Injection</description>
    </item>
    <item>
      <title>Anyquery: Arbitrary File Write (AFW) which could lead to Remote Code Execution (RCE) via Unrestricted ATTACH DATABASE...</title>
      <link>https://www.patchbrief.org/items/2026-07-go-cve-2026-50006.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-go-cve-2026-50006.html</guid>
      <pubDate>Tue, 14 Jul 2026 00:00:00 +0000</pubDate>
      <description>Anyquery: Arbitrary File Write (AFW) which could lead to Remote Code Execution (RCE) via Unrestricted ATTACH DATABASE in Server Mode</description>
    </item>
    <item>
      <title>Hoverfly: Process Crash via Concurrent Map Write Race Condition in Diff Mode</title>
      <link>https://www.patchbrief.org/items/2026-07-go-cve-2026-50013.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-go-cve-2026-50013.html</guid>
      <pubDate>Tue, 14 Jul 2026 00:00:00 +0000</pubDate>
      <description>Hoverfly: Process Crash via Concurrent Map Write Race Condition in Diff Mode</description>
    </item>
    <item>
      <title>MKP: Unbounded Pod Log Read via Attacker-Controlled `limitBytes`/`tailLines` Causes Memory Exhaustion</title>
      <link>https://www.patchbrief.org/items/2026-07-go-cve-2026-50125.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-go-cve-2026-50125.html</guid>
      <pubDate>Tue, 14 Jul 2026 00:00:00 +0000</pubDate>
      <description>MKP: Unbounded Pod Log Read via Attacker-Controlled `limitBytes`/`tailLines` Causes Memory Exhaustion</description>
    </item>
    <item>
      <title>Woodpecker gRPC agent_id metadata can be spoofed- cross-tenant agent impersonation</title>
      <link>https://www.patchbrief.org/items/2026-07-go-cve-2026-50141.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-go-cve-2026-50141.html</guid>
      <pubDate>Tue, 14 Jul 2026 00:00:00 +0000</pubDate>
      <description>Woodpecker gRPC agent_id metadata can be spoofed- cross-tenant agent impersonation</description>
    </item>
    <item>
      <title>yutu: Arbitrary File Write via MCP `caption-download` Tool</title>
      <link>https://www.patchbrief.org/items/2026-07-go-cve-2026-50158.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-go-cve-2026-50158.html</guid>
      <pubDate>Tue, 14 Jul 2026 00:00:00 +0000</pubDate>
      <description>yutu: Arbitrary File Write via MCP `caption-download` Tool</description>
    </item>
    <item>
      <title>nebula-mesh: Operator session tokens stored in plaintext in the database</title>
      <link>https://www.patchbrief.org/items/2026-07-go-cve-2026-53603.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-go-cve-2026-53603.html</guid>
      <pubDate>Tue, 14 Jul 2026 00:00:00 +0000</pubDate>
      <description>nebula-mesh: Operator session tokens stored in plaintext in the database</description>
    </item>
    <item>
      <title>nebula-mesh: CA private key not zeroized on web mobile-bundle error paths</title>
      <link>https://www.patchbrief.org/items/2026-07-go-cve-2026-53604.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-go-cve-2026-53604.html</guid>
      <pubDate>Tue, 14 Jul 2026 00:00:00 +0000</pubDate>
      <description>nebula-mesh: CA private key not zeroized on web mobile-bundle error paths</description>
    </item>
    <item>
      <title>Trivy: Helm chart tar bomb causes OOM via unbounded io.ReadAll in parser</title>
      <link>https://www.patchbrief.org/items/2026-07-go-cve-2026-54448.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-go-cve-2026-54448.html</guid>
      <pubDate>Tue, 14 Jul 2026 00:00:00 +0000</pubDate>
      <description>Trivy: Helm chart tar bomb causes OOM via unbounded io.ReadAll in parser</description>
    </item>
    <item>
      <title>Anyquery: Server-Side Request Forgery (SSRF) via Unrestricted SQLite Virtual Table Modules in Server Mode</title>
      <link>https://www.patchbrief.org/items/2026-07-go-cve-2026-54628.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-go-cve-2026-54628.html</guid>
      <pubDate>Tue, 14 Jul 2026 00:00:00 +0000</pubDate>
      <description>Anyquery: Server-Side Request Forgery (SSRF) via Unrestricted SQLite Virtual Table Modules in Server Mode</description>
    </item>
    <item>
      <title>Anyquery: Local File Read (LFR) via Unrestricted SQLite Virtual Table Modules in Server Mode</title>
      <link>https://www.patchbrief.org/items/2026-07-go-cve-2026-54629.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-go-cve-2026-54629.html</guid>
      <pubDate>Tue, 14 Jul 2026 00:00:00 +0000</pubDate>
      <description>Anyquery: Local File Read (LFR) via Unrestricted SQLite Virtual Table Modules in Server Mode</description>
    </item>
    <item>
      <title>Woodpecker: Privilege escalation via unrestricted serviceAccountName in the Kubernetes backend</title>
      <link>https://www.patchbrief.org/items/2026-07-go-cve-2026-61549.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-go-cve-2026-61549.html</guid>
      <pubDate>Tue, 14 Jul 2026 00:00:00 +0000</pubDate>
      <description>Woodpecker: Privilege escalation via unrestricted serviceAccountName in the Kubernetes backend</description>
    </item>
    <item>
      <title>nebula-mesh: Certificate revocation is never enforced at the mesh</title>
      <link>https://www.patchbrief.org/items/2026-07-go-cve-2026-61699.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-go-cve-2026-61699.html</guid>
      <pubDate>Tue, 14 Jul 2026 00:00:00 +0000</pubDate>
      <description>nebula-mesh: Certificate revocation is never enforced at the mesh</description>
    </item>
    <item>
      <title>Nebula-mesh allows non-admin operators to disable webhook SSRF protection via `allow_private`</title>
      <link>https://www.patchbrief.org/items/2026-07-go-ghsa-7rx3-5wx3-5v76.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-go-ghsa-7rx3-5wx3-5v76.html</guid>
      <pubDate>Tue, 14 Jul 2026 00:00:00 +0000</pubDate>
      <description>Nebula-mesh allows non-admin operators to disable webhook SSRF protection via `allow_private`</description>
    </item>
    <item>
      <title>Ech0: ParseAcceptLanguage `_` separator bypass enables ~70x CPU amplification via Accept-Language header in i18n.Midd...</title>
      <link>https://www.patchbrief.org/items/2026-07-go-ghsa-mqxv-9rm6-w8qc.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-go-ghsa-mqxv-9rm6-w8qc.html</guid>
      <pubDate>Tue, 14 Jul 2026 00:00:00 +0000</pubDate>
      <description>Ech0: ParseAcceptLanguage `_` separator bypass enables ~70x CPU amplification via Accept-Language header in i18n.Middleware</description>
    </item>
    <item>
      <title>TsDProxy: X-Forwarded-For header injection allows IP spoofing in proxied requests to backend services</title>
      <link>https://www.patchbrief.org/items/2026-07-go-ghsa-pqg7-v6wh-3pfp.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-go-ghsa-pqg7-v6wh-3pfp.html</guid>
      <pubDate>Tue, 14 Jul 2026 00:00:00 +0000</pubDate>
      <description>TsDProxy: X-Forwarded-For header injection allows IP spoofing in proxied requests to backend services</description>
    </item>
    <item>
      <title>Netty: Denial of Service via Unbounded Headers in StompSubframeDecoder</title>
      <link>https://www.patchbrief.org/items/2026-07-maven-cve-2026-44891.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-maven-cve-2026-44891.html</guid>
      <pubDate>Tue, 14 Jul 2026 00:00:00 +0000</pubDate>
      <description>Netty: Denial of Service via Unbounded Headers in StompSubframeDecoder</description>
    </item>
    <item>
      <title>DBI versions before 1.650 for Perl are vulnerable to code injection via caller-influenced Profile</title>
      <link>https://www.patchbrief.org/items/2026-07-microsoft-cve-2026-14380.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-microsoft-cve-2026-14380.html</guid>
      <pubDate>Tue, 14 Jul 2026 00:00:00 +0000</pubDate>
      <description>DBI versions before 1.650 for Perl are vulnerable to code injection via caller-influenced Profile Published in July 2026 Security Updates.</description>
    </item>
    <item>
      <title>DBI versions before 1.650 for Perl read one byte out-of-bounds in preparse when deleting an initial SQL comment</title>
      <link>https://www.patchbrief.org/items/2026-07-microsoft-cve-2026-14740.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-microsoft-cve-2026-14740.html</guid>
      <pubDate>Tue, 14 Jul 2026 00:00:00 +0000</pubDate>
      <description>DBI versions before 1.650 for Perl read one byte out-of-bounds in preparse when deleting an initial SQL comment Published in July 2026 Security Updates.</description>
    </item>
    <item>
      <title>DBI::SQL::Nano versions from 1.42 before 1.651 for Perl have inverted &lt;= and &gt;= SQL operators on text</title>
      <link>https://www.patchbrief.org/items/2026-07-microsoft-cve-2026-15043.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-microsoft-cve-2026-15043.html</guid>
      <pubDate>Tue, 14 Jul 2026 00:00:00 +0000</pubDate>
      <description>DBI::SQL::Nano versions from 1.42 before 1.651 for Perl have inverted &lt;= and &gt;= SQL operators on text Published in July 2026 Security Updates.</description>
    </item>
    <item>
      <title>ntopng through 6.6 is vulnerable to Predictable Session Identifier which can lead to Session Hijacking. HTTP session ...</title>
      <link>https://www.patchbrief.org/items/2026-07-microsoft-cve-2026-38968.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-microsoft-cve-2026-38968.html</guid>
      <pubDate>Tue, 14 Jul 2026 00:00:00 +0000</pubDate>
      <description>ntopng through 6.6 is vulnerable to Predictable Session Identifier which can lead to Session Hijacking. HTTP session identifiers in src/HTTPserver.cpp use weak time-seeded pseudo-randomness during session creation. As a result, fresh authenticated logins can receive deterministic or colliding session cookies under attacker-controlled timing. Published in July 2026 Security Updates.</description>
    </item>
    <item>
      <title>Windows Secure Kernel Mode Elevation of Privilege Vulnerability</title>
      <link>https://www.patchbrief.org/items/2026-07-microsoft-cve-2026-42982.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-microsoft-cve-2026-42982.html</guid>
      <pubDate>Tue, 14 Jul 2026 00:00:00 +0000</pubDate>
      <description>Improper validation of consistency within input in Windows Secure Kernel Mode allows an authorized attacker to elevate privileges locally. Published in July 2026 Security Updates. MSRC exploitability: Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation Less Likely.</description>
    </item>
    <item>
      <title>SQL Server ODBC driver Elevation of Privilege Vulnerability</title>
      <link>https://www.patchbrief.org/items/2026-07-microsoft-cve-2026-42990.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-microsoft-cve-2026-42990.html</guid>
      <pubDate>Tue, 14 Jul 2026 00:00:00 +0000</pubDate>
      <description>Heap-based buffer overflow in SQL Server ODBC driver allows an unauthorized attacker to execute code over a network. Published in July 2026 Security Updates. MSRC exploitability: Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation Unlikely.</description>
    </item>
    <item>
      <title>ASP.NET Core Elevation of Privilege Vulnerability</title>
      <link>https://www.patchbrief.org/items/2026-07-microsoft-cve-2026-47300.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-microsoft-cve-2026-47300.html</guid>
      <pubDate>Tue, 14 Jul 2026 00:00:00 +0000</pubDate>
      <description>Incorrect implementation of authentication algorithm in ASP.NET Core allows an authorized attacker to elevate privileges over a network. Published in July 2026 Security Updates. MSRC exploitability: Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation Less Likely.</description>
    </item>
    <item>
      <title>ASP.NET Core Elevation of Privilege Vulnerability</title>
      <link>https://www.patchbrief.org/items/2026-07-microsoft-cve-2026-47303.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-microsoft-cve-2026-47303.html</guid>
      <pubDate>Tue, 14 Jul 2026 00:00:00 +0000</pubDate>
      <description>Authentication bypass by assumed-immutable data in ASP.NET Core allows an authorized attacker to elevate privileges over a network. Published in July 2026 Security Updates. MSRC exploitability: Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation Less Likely.</description>
    </item>
    <item>
      <title>Microsoft Copilot Remote Code Execution Vulnerability</title>
      <link>https://www.patchbrief.org/items/2026-07-microsoft-cve-2026-48561.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-microsoft-cve-2026-48561.html</guid>
      <pubDate>Tue, 14 Jul 2026 00:00:00 +0000</pubDate>
      <description>Improper neutralization of special elements used in a command ('command injection') in Microsoft Copilot allows an unauthorized attacker to execute code over a network. Published in July 2026 Security Updates. MSRC exploitability: Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation Less Likely.</description>
    </item>
    <item>
      <title>Windows Active Directory Domain Services Remote Code Execution Vulnerability</title>
      <link>https://www.patchbrief.org/items/2026-07-microsoft-cve-2026-49164.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-microsoft-cve-2026-49164.html</guid>
      <pubDate>Tue, 14 Jul 2026 00:00:00 +0000</pubDate>
      <description>Heap-based buffer overflow in Active Directory Domain Services allows an unauthorized attacker to execute code over a network. Published in July 2026 Security Updates. MSRC exploitability: Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation Unlikely.</description>
    </item>
    <item>
      <title>Windows StateRepository API Server file Elevation of Privilege Vulnerability</title>
      <link>https://www.patchbrief.org/items/2026-07-microsoft-cve-2026-49170.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-microsoft-cve-2026-49170.html</guid>
      <pubDate>Tue, 14 Jul 2026 00:00:00 +0000</pubDate>
      <description>Insufficient granularity of access control in Windows StateRepository API allows an authorized attacker to elevate privileges locally. Published in July 2026 Security Updates. MSRC exploitability: Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation More Likely.</description>
    </item>
    <item>
      <title>Windows FTP Service Remote Code Execution Vulnerability</title>
      <link>https://www.patchbrief.org/items/2026-07-microsoft-cve-2026-49172.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-microsoft-cve-2026-49172.html</guid>
      <pubDate>Tue, 14 Jul 2026 00:00:00 +0000</pubDate>
      <description>Heap-based buffer overflow in Windows FTP Service allows an unauthorized attacker to execute code over a network. Published in July 2026 Security Updates. MSRC exploitability: Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation Less Likely.</description>
    </item>
    <item>
      <title>Game: Age of Empires II: Definitive Edition Remote Code Execution Vulnerability</title>
      <link>https://www.patchbrief.org/items/2026-07-microsoft-cve-2026-50663.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-microsoft-cve-2026-50663.html</guid>
      <pubDate>Tue, 14 Jul 2026 00:00:00 +0000</pubDate>
      <description>Relative path traversal in Age of Empires II: Definitive Edition Game allows an unauthorized attacker to execute code over a network. Published in July 2026 Security Updates. MSRC exploitability: Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation Less Likely.</description>
    </item>
    <item>
      <title>Microsoft Windows 10 1607 — CVE-2026-50694 (Critical)</title>
      <link>https://www.patchbrief.org/items/2026-07-microsoft-cve-2026-50694.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-microsoft-cve-2026-50694.html</guid>
      <pubDate>Tue, 14 Jul 2026 00:00:00 +0000</pubDate>
      <description>Use after free in Windows Secure Socket Tunneling Protocol (SSTP) allows an unauthorized attacker to execute code over a network.</description>
    </item>
    <item>
      <title>Windows Win32k Elevation of Privilege Vulnerability</title>
      <link>https://www.patchbrief.org/items/2026-07-microsoft-cve-2026-54107.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-microsoft-cve-2026-54107.html</guid>
      <pubDate>Tue, 14 Jul 2026 00:00:00 +0000</pubDate>
      <description>Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Win32K allows an authorized attacker to elevate privileges locally. Published in July 2026 Security Updates. MSRC exploitability: Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation Less Likely.</description>
    </item>
    <item>
      <title>Remote Desktop Client Remote Code Execution Vulnerability</title>
      <link>https://www.patchbrief.org/items/2026-07-microsoft-cve-2026-54990.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-microsoft-cve-2026-54990.html</guid>
      <pubDate>Tue, 14 Jul 2026 00:00:00 +0000</pubDate>
      <description>Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network. Published in July 2026 Security Updates. MSRC exploitability: Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation Less Likely.</description>
    </item>
    <item>
      <title>xorg-x11-server / xwayland GLX contextTags Use-After-Free in CommonMakeCurrent()</title>
      <link>https://www.patchbrief.org/items/2026-07-microsoft-cve-2026-56000.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-microsoft-cve-2026-56000.html</guid>
      <pubDate>Tue, 14 Jul 2026 00:00:00 +0000</pubDate>
      <description>xorg-x11-server / xwayland GLX contextTags Use-After-Free in CommonMakeCurrent() Published in July 2026 Security Updates.</description>
    </item>
    <item>
      <title>Microsoft Active Directory Federation Services Insufficient Granularity of Access Control Vulnerability</title>
      <link>https://www.patchbrief.org/items/2026-07-microsoft-cve-2026-56155.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-microsoft-cve-2026-56155.html</guid>
      <pubDate>Tue, 14 Jul 2026 00:00:00 +0000</pubDate>
      <description>Microsoft Active Directory Federation Services contains an insufficient granularity of access control vulnerability that allows an authorized attacker to elevate privileges locally.</description>
    </item>
    <item>
      <title>Microsoft SharePoint Server Missing Authentication for Critical Function Vulnerability</title>
      <link>https://www.patchbrief.org/items/2026-07-microsoft-cve-2026-56164.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-microsoft-cve-2026-56164.html</guid>
      <pubDate>Tue, 14 Jul 2026 00:00:00 +0000</pubDate>
      <description>Microsoft SharePoint contains a missing authentication for critical function vulnerability that allows an unauthorized attacker to elevate privileges over a network.</description>
    </item>
    <item>
      <title>Storable versions before 3.41 for Perl have a signed integer overflow when deserializing a crafted SX_HOOK record</title>
      <link>https://www.patchbrief.org/items/2026-07-microsoft-cve-2026-57433.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-microsoft-cve-2026-57433.html</guid>
      <pubDate>Tue, 14 Jul 2026 00:00:00 +0000</pubDate>
      <description>Storable versions before 3.41 for Perl have a signed integer overflow when deserializing a crafted SX_HOOK record Published in July 2026 Security Updates.</description>
    </item>
    <item>
      <title>NATS Server: Route API Auth Bypass</title>
      <link>https://www.patchbrief.org/items/2026-07-microsoft-cve-2026-58253.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-microsoft-cve-2026-58253.html</guid>
      <pubDate>Tue, 14 Jul 2026 00:00:00 +0000</pubDate>
      <description>NATS Server: Route API Auth Bypass Published in July 2026 Security Updates.</description>
    </item>
    <item>
      <title>Microsoft Windows 10 1607 — CVE-2026-58594 (Critical)</title>
      <link>https://www.patchbrief.org/items/2026-07-microsoft-cve-2026-58594.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-microsoft-cve-2026-58594.html</guid>
      <pubDate>Tue, 14 Jul 2026 00:00:00 +0000</pubDate>
      <description>Integer overflow or wraparound in Windows RDP allows an unauthorized attacker to execute code over a network.</description>
    </item>
    <item>
      <title>Microsoft 365 Copilot — CVE-2026-58617 (Critical)</title>
      <link>https://www.patchbrief.org/items/2026-07-microsoft-cve-2026-58617.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-microsoft-cve-2026-58617.html</guid>
      <pubDate>Tue, 14 Jul 2026 00:00:00 +0000</pubDate>
      <description>Improper access control in Microsoft 365 Copilot for iOS allows an unauthorized attacker to elevate privileges over a network.</description>
    </item>
    <item>
      <title>Microsoft Sharepoint Server — CVE-2026-58644 (Critical)</title>
      <link>https://www.patchbrief.org/items/2026-07-microsoft-cve-2026-58644.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-microsoft-cve-2026-58644.html</guid>
      <pubDate>Tue, 14 Jul 2026 00:00:00 +0000</pubDate>
      <description>Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network.</description>
    </item>
    <item>
      <title>node-tar: Decompression/parse DoS via unlimited input</title>
      <link>https://www.patchbrief.org/items/2026-07-microsoft-cve-2026-59873.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-microsoft-cve-2026-59873.html</guid>
      <pubDate>Tue, 14 Jul 2026 00:00:00 +0000</pubDate>
      <description>node-tar: Decompression/parse DoS via unlimited input Published in July 2026 Security Updates.</description>
    </item>
    <item>
      <title>DBI versions before 1.651 for Perl do not enforce statement handle consistency with the row</title>
      <link>https://www.patchbrief.org/items/2026-07-microsoft-cve-2026-60082.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-microsoft-cve-2026-60082.html</guid>
      <pubDate>Tue, 14 Jul 2026 00:00:00 +0000</pubDate>
      <description>DBI versions before 1.651 for Perl do not enforce statement handle consistency with the row Published in July 2026 Security Updates.</description>
    </item>
    <item>
      <title>trailing dot domain super cookie</title>
      <link>https://www.patchbrief.org/items/2026-07-microsoft-cve-2026-8924.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-microsoft-cve-2026-8924.html</guid>
      <pubDate>Tue, 14 Jul 2026 00:00:00 +0000</pubDate>
      <description>trailing dot domain super cookie Published in July 2026 Security Updates.</description>
    </item>
    <item>
      <title>password leak with netrc and user in URL</title>
      <link>https://www.patchbrief.org/items/2026-07-microsoft-cve-2026-8926.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-microsoft-cve-2026-8926.html</guid>
      <pubDate>Tue, 14 Jul 2026 00:00:00 +0000</pubDate>
      <description>password leak with netrc and user in URL Published in July 2026 Security Updates.</description>
    </item>
    <item>
      <title>SSH improper host validation</title>
      <link>https://www.patchbrief.org/items/2026-07-microsoft-cve-2026-9547.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-microsoft-cve-2026-9547.html</guid>
      <pubDate>Tue, 14 Jul 2026 00:00:00 +0000</pubDate>
      <description>SSH improper host validation Published in July 2026 Security Updates.</description>
    </item>
    <item>
      <title>Fedify has an incomplete SSRF mitigation after GHSA-p9cg-vqcc-grcx: validatePublicUrl allows special-use IPv4 ranges</title>
      <link>https://www.patchbrief.org/items/2026-07-npm-cve-2026-50131.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-npm-cve-2026-50131.html</guid>
      <pubDate>Tue, 14 Jul 2026 00:00:00 +0000</pubDate>
      <description>Fedify has an incomplete SSRF mitigation after GHSA-p9cg-vqcc-grcx: validatePublicUrl allows special-use IPv4 ranges</description>
    </item>
    <item>
      <title>n8n-MCP: Cross-tenant access to workflow version backups in multi-tenant HTTP deployments</title>
      <link>https://www.patchbrief.org/items/2026-07-npm-cve-2026-54052.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-npm-cve-2026-54052.html</guid>
      <pubDate>Tue, 14 Jul 2026 00:00:00 +0000</pubDate>
      <description>n8n-MCP: Cross-tenant access to workflow version backups in multi-tenant HTTP deployments</description>
    </item>
    <item>
      <title>TidGi Desktop Remote Code Execution via Malicious TiddlyWiki Repository Import — Tiddler Startup Module Auto-Execution</title>
      <link>https://www.patchbrief.org/items/2026-07-npm-ghsa-9hc2-hjx8-q6pv.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-npm-ghsa-9hc2-hjx8-q6pv.html</guid>
      <pubDate>Tue, 14 Jul 2026 00:00:00 +0000</pubDate>
      <description>TidGi Desktop Remote Code Execution via Malicious TiddlyWiki Repository Import — Tiddler Startup Module Auto-Execution</description>
    </item>
    <item>
      <title>Nvidia Tensorrt — CVE-2026-24227 (Critical)</title>
      <link>https://www.patchbrief.org/items/2026-07-nvidia-cve-2026-24227.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-nvidia-cve-2026-24227.html</guid>
      <pubDate>Tue, 14 Jul 2026 00:00:00 +0000</pubDate>
      <description>NVIDIA TensorRT for contains a vulnerability where a user might cause a deserialization of untrusted data. A successful exploit of this vulnerability might lead to code execution.</description>
    </item>
    <item>
      <title>NetLicensing-MCP: Unauthenticated Use of Server-Side NetLicensing API Key in HTTP Mode</title>
      <link>https://www.patchbrief.org/items/2026-07-pypi-cve-2026-54446.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-pypi-cve-2026-54446.html</guid>
      <pubDate>Tue, 14 Jul 2026 00:00:00 +0000</pubDate>
      <description>NetLicensing-MCP: Unauthenticated Use of Server-Side NetLicensing API Key in HTTP Mode</description>
    </item>
    <item>
      <title>Sensiolabs Symfony — CVE-2026-45063 (Critical)</title>
      <link>https://www.patchbrief.org/items/2026-07-sensiolabs-cve-2026-45063.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-sensiolabs-cve-2026-45063.html</guid>
      <pubDate>Tue, 14 Jul 2026 00:00:00 +0000</pubDate>
      <description>Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 5.4.52, 6.4.40, 7.4.12, and 8.0.12, X509Authenticator extracts the user identifier from $_SERVER['SSL_CLIENT_S_DN'] with an unanchored regex that matches emailAddress= anywhere in the distinguished name, allowing an attacker with a trusted certificate containing emailAddress=victim inside another RDN value such as CN to authenticate as the victim. This issue is fixed in versions 5.4.52, 6.4.40, 7.4.12, and 8.0.12.</description>
    </item>
    <item>
      <title>Sensiolabs Symfony — CVE-2026-45069 (Critical)</title>
      <link>https://www.patchbrief.org/items/2026-07-sensiolabs-cve-2026-45069.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-sensiolabs-cve-2026-45069.html</guid>
      <pubDate>Tue, 14 Jul 2026 00:00:00 +0000</pubDate>
      <description>Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 6.4.40, 7.4.12, and 8.0.12, OidcTokenHandler::verifyClaims() registered audience (aud), issuer (iss), and expiry (exp) checkers but did not pass the mandatory claims list to ClaimCheckerManager::check(), so a validly signed JWT that omitted those claims could pass verification. This issue is fixed in versions 6.4.40, 7.4.12, and 8.0.12.</description>
    </item>
    <item>
      <title>Sensiolabs Symfony — CVE-2026-47767 (Critical)</title>
      <link>https://www.patchbrief.org/items/2026-07-sensiolabs-cve-2026-47767.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-sensiolabs-cve-2026-47767.html</guid>
      <pubDate>Tue, 14 Jul 2026 00:00:00 +0000</pubDate>
      <description>Symfony is a PHP framework for web and console applications and a set of reusable PHP components. From 5.4.46 until 5.4.52, 6.4.40, 7.4.12, and 8.0.12, the CVE-2024-50340 fix gated runtime argv parsing on empty($_GET), but parse_str() and the web SAPI can disagree, allowing a crafted query string to leave $_GET empty while $_SERVER['argv'] still carries attacker-controlled --env or --no-debug flags that change APP_ENV or APP_DEBUG. This issue is fixed in versions 5.4.52, 6.4.40, 7.4.12, and 8.0.12.</description>
    </item>
    <item>
      <title>SonicWall SMA1000 Appliances Server-Side Request Forgery Vulnerability</title>
      <link>https://www.patchbrief.org/items/2026-07-sonicwall-cve-2026-15409.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-sonicwall-cve-2026-15409.html</guid>
      <pubDate>Tue, 14 Jul 2026 00:00:00 +0000</pubDate>
      <description>SonicWall SMA1000 Appliances contain a server-side request forgery vulnerability that could allow a remote unauthenticated attacker to potentially cause the appliance to make requests to unintended location.</description>
    </item>
    <item>
      <title>SonicWall SMA1000 Appliances Code Injection Vulnerability</title>
      <link>https://www.patchbrief.org/items/2026-07-sonicwall-cve-2026-15410.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-sonicwall-cve-2026-15410.html</guid>
      <pubDate>Tue, 14 Jul 2026 00:00:00 +0000</pubDate>
      <description>SonicWall SMA1000 Appliances contain a code injection vulnerability which in specific conditions could potentially enable a remote authenticated attacker as administrator to execute arbitrary OS commands.</description>
    </item>
    <item>
      <title>Cisco IOS Cross-Site Request Forgery Vulnerability</title>
      <link>https://www.patchbrief.org/items/2026-07-cisco-cve-2008-4128.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-cisco-cve-2008-4128.html</guid>
      <pubDate>Mon, 13 Jul 2026 00:00:00 +0000</pubDate>
      <description>Cisco IOS 12.4 contains multiple cross-site forgery vulnerabilities that allows remote attackers to execute arbitrary commands via (1) a certain "show privilege" command to the /level/15/exec/- URI, and (2) a certain "alias exec" command to the /level/15/exec/-/configure/http URI.</description>
    </item>
    <item>
      <title>FacturaScripts: Account takeover of any 2FA-enabled user</title>
      <link>https://www.patchbrief.org/items/2026-07-composer-cve-2026-47677.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-composer-cve-2026-47677.html</guid>
      <pubDate>Mon, 13 Jul 2026 00:00:00 +0000</pubDate>
      <description>FacturaScripts: Account takeover of any 2FA-enabled user</description>
    </item>
    <item>
      <title>NukeViet: Unauthenticated Reflected XSS in Comment Module</title>
      <link>https://www.patchbrief.org/items/2026-07-composer-cve-2026-48118.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-composer-cve-2026-48118.html</guid>
      <pubDate>Mon, 13 Jul 2026 00:00:00 +0000</pubDate>
      <description>NukeViet: Unauthenticated Reflected XSS in Comment Module</description>
    </item>
    <item>
      <title>NukeViet: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')</title>
      <link>https://www.patchbrief.org/items/2026-07-composer-cve-2026-49259.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-composer-cve-2026-49259.html</guid>
      <pubDate>Mon, 13 Jul 2026 00:00:00 +0000</pubDate>
      <description>NukeViet: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')</description>
    </item>
    <item>
      <title>NukeViet: Multiple Anti-XSS Filter Bypasses Leading to Stored XSS in News Module</title>
      <link>https://www.patchbrief.org/items/2026-07-composer-cve-2026-54064.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-composer-cve-2026-54064.html</guid>
      <pubDate>Mon, 13 Jul 2026 00:00:00 +0000</pubDate>
      <description>NukeViet: Multiple Anti-XSS Filter Bypasses Leading to Stored XSS in News Module</description>
    </item>
    <item>
      <title>NukeViet: Path Traversal to Arbitrary File Deletion in Edit Comment Function</title>
      <link>https://www.patchbrief.org/items/2026-07-composer-cve-2026-54065.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-composer-cve-2026-54065.html</guid>
      <pubDate>Mon, 13 Jul 2026 00:00:00 +0000</pubDate>
      <description>NukeViet: Path Traversal to Arbitrary File Deletion in Edit Comment Function</description>
    </item>
    <item>
      <title>NukeViet: Pre-authentication SSRF via X-Forwarded-Host</title>
      <link>https://www.patchbrief.org/items/2026-07-composer-cve-2026-55372.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-composer-cve-2026-55372.html</guid>
      <pubDate>Mon, 13 Jul 2026 00:00:00 +0000</pubDate>
      <description>NukeViet: Pre-authentication SSRF via X-Forwarded-Host</description>
    </item>
    <item>
      <title>Fossies Gawk — CVE-2026-40468 (Critical)</title>
      <link>https://www.patchbrief.org/items/2026-07-fossies-cve-2026-40468.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-fossies-cve-2026-40468.html</guid>
      <pubDate>Mon, 13 Jul 2026 00:00:00 +0000</pubDate>
      <description>Integer overflow vulnerability has been found in "builtin.c" program file of gawk. This issue may lead to memory exhaustion on the hosting operating system and could be used to overwrite gawk heap metadata and objects with attacker-controlled bytes. It affects gawk in versions 5.4.0 and below.</description>
    </item>
    <item>
      <title>Fossies Gawk — CVE-2026-40469 (Critical)</title>
      <link>https://www.patchbrief.org/items/2026-07-fossies-cve-2026-40469.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-fossies-cve-2026-40469.html</guid>
      <pubDate>Mon, 13 Jul 2026 00:00:00 +0000</pubDate>
      <description>Integer overflow vulnerability has been found in "builtin.c" program file of gawk (do_sub() routine). This issue could be used to overwrite gawk heap metadata and objects causing the program to crash. It affects 32-bit builds of gawk in versions 5.4.0 and below.</description>
    </item>
    <item>
      <title>Apollo ConfigService access key authentication bypass via appId parsing and non-canonical matching</title>
      <link>https://www.patchbrief.org/items/2026-07-maven-cve-2026-59954.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-maven-cve-2026-59954.html</guid>
      <pubDate>Mon, 13 Jul 2026 00:00:00 +0000</pubDate>
      <description>Apollo ConfigService access key authentication bypass via appId parsing and non-canonical matching</description>
    </item>
    <item>
      <title>Apollo ConfigService access key authentication bypass via raw config file appId parsing</title>
      <link>https://www.patchbrief.org/items/2026-07-maven-cve-2026-59955.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-maven-cve-2026-59955.html</guid>
      <pubDate>Mon, 13 Jul 2026 00:00:00 +0000</pubDate>
      <description>Apollo ConfigService access key authentication bypass via raw config file appId parsing</description>
    </item>
    <item>
      <title>Ollyo Helix Ultimate — CVE-2026-57830 (Critical)</title>
      <link>https://www.patchbrief.org/items/2026-07-ollyo-cve-2026-57830.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-ollyo-cve-2026-57830.html</guid>
      <pubDate>Mon, 13 Jul 2026 00:00:00 +0000</pubDate>
      <description>The Joomla extension Helix Ultimate is vulnerable to an unauthenticated arbitrary file deletion.</description>
    </item>
    <item>
      <title>Perl Perl — CVE-2026-13221 (Critical)</title>
      <link>https://www.patchbrief.org/items/2026-07-perl-cve-2026-13221.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-perl-cve-2026-13221.html</guid>
      <pubDate>Mon, 13 Jul 2026 00:00:00 +0000</pubDate>
      <description>Perl versions through 5.43.9 produce silently incorrect regular expression matches when an alternation of more than 65535 fixed string branches is compiled into a trie in Perl_study_chunk. When such branches are combined into a trie, the delta between the first branch and the shared tail is stored in a 16-bit field. A branch count above 65535 overflows the field, and the trie's match decision table is truncated with no warning or error. A pattern of this shape produces false positive matches (matching strings it should not) and false negative matches (failing to match strings it should). Whe</description>
    </item>
    <item>
      <title>DIRAC is vulnerable to RCE in RequestManager due to eval on untrusted input</title>
      <link>https://www.patchbrief.org/items/2026-07-pypi-cve-2026-45579.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-pypi-cve-2026-45579.html</guid>
      <pubDate>Mon, 13 Jul 2026 00:00:00 +0000</pubDate>
      <description>DIRAC is vulnerable to RCE in RequestManager due to eval on untrusted input</description>
    </item>
    <item>
      <title>DIRAC is vulnerable to RCE in FileCatalog DatasetManager via SQL injection + eval</title>
      <link>https://www.patchbrief.org/items/2026-07-pypi-cve-2026-61667.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-pypi-cve-2026-61667.html</guid>
      <pubDate>Mon, 13 Jul 2026 00:00:00 +0000</pubDate>
      <description>DIRAC is vulnerable to RCE in FileCatalog DatasetManager via SQL injection + eval</description>
    </item>
    <item>
      <title>DIRAC: Pilot code downloaded over unverified HTTPS connection</title>
      <link>https://www.patchbrief.org/items/2026-07-pypi-cve-2026-61668.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-pypi-cve-2026-61668.html</guid>
      <pubDate>Mon, 13 Jul 2026 00:00:00 +0000</pubDate>
      <description>DIRAC: Pilot code downloaded over unverified HTTPS connection</description>
    </item>
    <item>
      <title>DIRAC: SQL injection and lack of access control in PilotManager service</title>
      <link>https://www.patchbrief.org/items/2026-07-pypi-ghsa-7xw9-549r-8jrc.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-pypi-ghsa-7xw9-549r-8jrc.html</guid>
      <pubDate>Mon, 13 Jul 2026 00:00:00 +0000</pubDate>
      <description>DIRAC: SQL injection and lack of access control in PilotManager service</description>
    </item>
    <item>
      <title>json_repair: Circular JSON Schema `$ref` causes unbounded CPU DoS</title>
      <link>https://www.patchbrief.org/items/2026-07-pypi-ghsa-xf7x-x43h-rpqh.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-pypi-ghsa-xf7x-x43h-rpqh.html</guid>
      <pubDate>Mon, 13 Jul 2026 00:00:00 +0000</pubDate>
      <description>json_repair: Circular JSON Schema `$ref` causes unbounded CPU DoS</description>
    </item>
    <item>
      <title>Decidim: Verification documents can be downloaded through reusable links</title>
      <link>https://www.patchbrief.org/items/2026-07-rubygems-cve-2026-45378.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-rubygems-cve-2026-45378.html</guid>
      <pubDate>Mon, 13 Jul 2026 00:00:00 +0000</pubDate>
      <description>Decidim: Verification documents can be downloaded through reusable links</description>
    </item>
    <item>
      <title>Decidim: JWT-backed authentication can be replayed across organizations</title>
      <link>https://www.patchbrief.org/items/2026-07-rubygems-cve-2026-45414.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-rubygems-cve-2026-45414.html</guid>
      <pubDate>Mon, 13 Jul 2026 00:00:00 +0000</pubDate>
      <description>Decidim: JWT-backed authentication can be replayed across organizations</description>
    </item>
    <item>
      <title>Vitec Flamingo 4.12.2 — CVE-2026-61498 (Critical)</title>
      <link>https://www.patchbrief.org/items/2026-07-vitec-cve-2026-61498.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-vitec-cve-2026-61498.html</guid>
      <pubDate>Mon, 13 Jul 2026 00:00:00 +0000</pubDate>
      <description>Vitec Flamingo 4.12.2 contains an unauthenticated OS command injection vulnerability in the admin/ajax/gen_graphs.php endpoint that allows remote unauthenticated attackers to execute arbitrary commands by supplying shell metacharacters in the start, end, key, or format HTTP GET parameters. Attackers can exploit the lack of input sanitization in the graph generation script, which passes user-supplied values directly to shell commands via passthru(), to execute arbitrary OS commands with root privileges due to the web server context having passwordless sudo access.</description>
    </item>
    <item>
      <title>Imagemagick Imagemagick — CVE-2026-56372 (Critical)</title>
      <link>https://www.patchbrief.org/items/2026-07-imagemagick-cve-2026-56372.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-imagemagick-cve-2026-56372.html</guid>
      <pubDate>Sat, 11 Jul 2026 00:00:00 +0000</pubDate>
      <description>ImageMagick before 7.1.2-19 contains a heap buffer overflow vulnerability in the magnify operation that allows attackers to read out of bounds memory. An unrecognized magnify:method value triggers an out of bounds read, potentially exposing sensitive information or causing denial of service.</description>
    </item>
    <item>
      <title>Balbooa Forms Unrestricted Upload of File with Dangerous Type Vulnerability</title>
      <link>https://www.patchbrief.org/items/2026-07-balbooa-cve-2026-56291.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-balbooa-cve-2026-56291.html</guid>
      <pubDate>Fri, 10 Jul 2026 00:00:00 +0000</pubDate>
      <description>Balbooa Forms contains an unrestricted upload of file with dangerous type vulnerability that allows an unauthenticated arbitrary file upload which could allow uploading of executable files leading to full RCE.</description>
    </item>
    <item>
      <title>prestashop/ps_facetedsearch: PHP Object Injection in faceted search cache allows unauthenticated RCE</title>
      <link>https://www.patchbrief.org/items/2026-07-composer-cve-2026-54159.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-composer-cve-2026-54159.html</guid>
      <pubDate>Fri, 10 Jul 2026 00:00:00 +0000</pubDate>
      <description>prestashop/ps_facetedsearch: PHP Object Injection in faceted search cache allows unauthenticated RCE</description>
    </item>
    <item>
      <title>NotrinosERP: Authenticated arbitrary file upload leads to remote code execution via HRM employee "Documents" (doc_file)</title>
      <link>https://www.patchbrief.org/items/2026-07-composer-ghsa-qv4m-m73m-8hj7.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-composer-ghsa-qv4m-m73m-8hj7.html</guid>
      <pubDate>Fri, 10 Jul 2026 00:00:00 +0000</pubDate>
      <description>NotrinosERP: Authenticated arbitrary file upload leads to remote code execution via HRM employee "Documents" (doc_file)</description>
    </item>
    <item>
      <title>Tesla has decompression bomb on response body</title>
      <link>https://www.patchbrief.org/items/2026-07-erlang-cve-2026-48594.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-erlang-cve-2026-48594.html</guid>
      <pubDate>Fri, 10 Jul 2026 00:00:00 +0000</pubDate>
      <description>Tesla has decompression bomb on response body</description>
    </item>
    <item>
      <title>Tesla: Authorization header leaks on cross-origin redirect via case-sensitive filtering</title>
      <link>https://www.patchbrief.org/items/2026-07-erlang-cve-2026-48595.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-erlang-cve-2026-48595.html</guid>
      <pubDate>Fri, 10 Jul 2026 00:00:00 +0000</pubDate>
      <description>Tesla: Authorization header leaks on cross-origin redirect via case-sensitive filtering</description>
    </item>
    <item>
      <title>Tesla vulnerable to atom exhaustion via untrusted URL scheme</title>
      <link>https://www.patchbrief.org/items/2026-07-erlang-cve-2026-48597.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-erlang-cve-2026-48597.html</guid>
      <pubDate>Fri, 10 Jul 2026 00:00:00 +0000</pubDate>
      <description>Tesla vulnerable to atom exhaustion via untrusted URL scheme</description>
    </item>
    <item>
      <title>SiYuan: Stored XSS to RCE via Unsanitized Attribute View Asset Cell Content</title>
      <link>https://www.patchbrief.org/items/2026-07-go-cve-2026-50551.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-go-cve-2026-50551.html</guid>
      <pubDate>Fri, 10 Jul 2026 00:00:00 +0000</pubDate>
      <description>SiYuan: Stored XSS to RCE via Unsanitized Attribute View Asset Cell Content</description>
    </item>
    <item>
      <title>Excelize: Unbounded Row Index Allocation in Worksheet Parser (checkSheet OOM/Panic DoS)</title>
      <link>https://www.patchbrief.org/items/2026-07-go-cve-2026-54063.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-go-cve-2026-54063.html</guid>
      <pubDate>Fri, 10 Jul 2026 00:00:00 +0000</pubDate>
      <description>Excelize: Unbounded Row Index Allocation in Worksheet Parser (checkSheet OOM/Panic DoS)</description>
    </item>
    <item>
      <title>SiYuan: Path Traversal via Double URL Encoding in /assets/*path (publish mode arbitrary   file─read), Incomplete fix ...</title>
      <link>https://www.patchbrief.org/items/2026-07-go-cve-2026-54066.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-go-cve-2026-54066.html</guid>
      <pubDate>Fri, 10 Jul 2026 00:00:00 +0000</pubDate>
      <description>SiYuan: Path Traversal via Double URL Encoding in /assets/*path (publish mode arbitrary file─read), Incomplete fix of CVE-2026-41894</description>
    </item>
    <item>
      <title>SiYuan: Stored XSS to RCE via CSS-snippet &lt;style&gt; breakout in renderSnippet()</title>
      <link>https://www.patchbrief.org/items/2026-07-go-cve-2026-54067.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-go-cve-2026-54067.html</guid>
      <pubDate>Fri, 10 Jul 2026 00:00:00 +0000</pubDate>
      <description>SiYuan: Stored XSS to RCE via CSS-snippet &lt;style&gt; breakout in renderSnippet()</description>
    </item>
    <item>
      <title>SiYuan: Unauthenticated Admin API Access via Blanket chrome-extension:// Origin Allowlist</title>
      <link>https://www.patchbrief.org/items/2026-07-go-cve-2026-54069.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-go-cve-2026-54069.html</guid>
      <pubDate>Fri, 10 Jul 2026 00:00:00 +0000</pubDate>
      <description>SiYuan: Unauthenticated Admin API Access via Blanket chrome-extension:// Origin Allowlist</description>
    </item>
    <item>
      <title>SiYuan: Stored XSS in Bazaar marketplace via package README event handlers</title>
      <link>https://www.patchbrief.org/items/2026-07-go-cve-2026-54070.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-go-cve-2026-54070.html</guid>
      <pubDate>Fri, 10 Jul 2026 00:00:00 +0000</pubDate>
      <description>SiYuan: Stored XSS in Bazaar marketplace via package README event handlers</description>
    </item>
    <item>
      <title>Authorizer: Unvalidated redirect_uri in /authorize leaks OAuth2 tokens to attacker-controlled URL</title>
      <link>https://www.patchbrief.org/items/2026-07-go-cve-2026-54072.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-go-cve-2026-54072.html</guid>
      <pubDate>Fri, 10 Jul 2026 00:00:00 +0000</pubDate>
      <description>Authorizer: Unvalidated redirect_uri in /authorize leaks OAuth2 tokens to attacker-controlled URL</description>
    </item>
    <item>
      <title>File Browser: Command Injection via Authentication Hook Shell Substitution (Pre-Authentication RCE)</title>
      <link>https://www.patchbrief.org/items/2026-07-go-cve-2026-54088.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-go-cve-2026-54088.html</guid>
      <pubDate>Fri, 10 Jul 2026 00:00:00 +0000</pubDate>
      <description>File Browser: Command Injection via Authentication Hook Shell Substitution (Pre-Authentication RCE)</description>
    </item>
    <item>
      <title>File Browser: Authentication Bypass via Proxy Auth Header Forgery</title>
      <link>https://www.patchbrief.org/items/2026-07-go-cve-2026-54089.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-go-cve-2026-54089.html</guid>
      <pubDate>Fri, 10 Jul 2026 00:00:00 +0000</pubDate>
      <description>File Browser: Authentication Bypass via Proxy Auth Header Forgery</description>
    </item>
    <item>
      <title>SiYuan: Stored XSS to RCE via attribute-view cell rendering in genAVValueHTML()</title>
      <link>https://www.patchbrief.org/items/2026-07-go-cve-2026-54158.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-go-cve-2026-54158.html</guid>
      <pubDate>Fri, 10 Jul 2026 00:00:00 +0000</pubDate>
      <description>SiYuan: Stored XSS to RCE via attribute-view cell rendering in genAVValueHTML()</description>
    </item>
    <item>
      <title>melange: Incomplete package integrity verification allows data section substitution</title>
      <link>https://www.patchbrief.org/items/2026-07-go-cve-2026-54174.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-go-cve-2026-54174.html</guid>
      <pubDate>Fri, 10 Jul 2026 00:00:00 +0000</pubDate>
      <description>melange: Incomplete package integrity verification allows data section substitution</description>
    </item>
    <item>
      <title>TSDProxy: Internal proxy auth token forwarded to backend services enables management API escalation</title>
      <link>https://www.patchbrief.org/items/2026-07-go-ghsa-g936-7jqj-mwv8.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-go-ghsa-g936-7jqj-mwv8.html</guid>
      <pubDate>Fri, 10 Jul 2026 00:00:00 +0000</pubDate>
      <description>TSDProxy: Internal proxy auth token forwarded to backend services enables management API escalation</description>
    </item>
    <item>
      <title>iCagenda Unrestricted Upload of File with Dangerous Type Vulnerability</title>
      <link>https://www.patchbrief.org/items/2026-07-icagenda-cve-2026-48939.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-icagenda-cve-2026-48939.html</guid>
      <pubDate>Fri, 10 Jul 2026 00:00:00 +0000</pubDate>
      <description>iCagenda contains an unrestricted upload of file with dangerous type vulnerability that allows the upload of arbitrary files in the file attachment feature, ultimately resulting in PHP code upload and execution.</description>
    </item>
    <item>
      <title>Jetbrains Intellij Idea — CVE-2026-59792 (Critical)</title>
      <link>https://www.patchbrief.org/items/2026-07-jetbrains-cve-2026-59792.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-jetbrains-cve-2026-59792.html</guid>
      <pubDate>Fri, 10 Jul 2026 00:00:00 +0000</pubDate>
      <description>In JetBrains IntelliJ IDEA before 2026.1.4, 2026.2 code execution via path traversal in project workspace ID handling was possible</description>
    </item>
    <item>
      <title>MCP Server Kubernetes — CVE-2026-61459 (Critical)</title>
      <link>https://www.patchbrief.org/items/2026-07-mcp-cve-2026-61459.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-mcp-cve-2026-61459.html</guid>
      <pubDate>Fri, 10 Jul 2026 00:00:00 +0000</pubDate>
      <description>MCP Server Kubernetes before 3.9.0 contains an argument injection vulnerability in structured tools (kubectl_get, kubectl_describe, kubectl_delete) that allows attackers to bypass the assertNoDangerousFlags security check by supplying resourceType and name parameters with leading dashes. Attackers can inject the --server flag to redirect kubectl commands to an attacker-controlled API server, causing the operator's bearer token to be transmitted externally and enabling full cluster compromise.</description>
    </item>
    <item>
      <title>libp2p: CPU DoS via oversized IHAVE and IWANT control message arrays</title>
      <link>https://www.patchbrief.org/items/2026-07-npm-cve-2026-49866.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-npm-cve-2026-49866.html</guid>
      <pubDate>Fri, 10 Jul 2026 00:00:00 +0000</pubDate>
      <description>libp2p: CPU DoS via oversized IHAVE and IWANT control message arrays</description>
    </item>
    <item>
      <title>SafeInstall agent guard shell parsing can miss raw package execution</title>
      <link>https://www.patchbrief.org/items/2026-07-npm-ghsa-xrmc-c5cg-rv7x.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-npm-ghsa-xrmc-c5cg-rv7x.html</guid>
      <pubDate>Fri, 10 Jul 2026 00:00:00 +0000</pubDate>
      <description>SafeInstall agent guard shell parsing can miss raw package execution</description>
    </item>
    <item>
      <title>BabelDOC: Arbitrary Code Execution via CMap Pickle Deserialization in babeldoc/pdfminer/cmapdb.py</title>
      <link>https://www.patchbrief.org/items/2026-07-pypi-cve-2026-54071.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-pypi-cve-2026-54071.html</guid>
      <pubDate>Fri, 10 Jul 2026 00:00:00 +0000</pubDate>
      <description>BabelDOC: Arbitrary Code Execution via CMap Pickle Deserialization in babeldoc/pdfminer/cmapdb.py</description>
    </item>
    <item>
      <title>mcp-atlassian: Arbitrary file read via missing path validation in confluence_upload_attachment</title>
      <link>https://www.patchbrief.org/items/2026-07-pypi-ghsa-g5r6-gv6m-f5jv.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-pypi-ghsa-g5r6-gv6m-f5jv.html</guid>
      <pubDate>Fri, 10 Jul 2026 00:00:00 +0000</pubDate>
      <description>mcp-atlassian: Arbitrary file read via missing path validation in confluence_upload_attachment</description>
    </item>
    <item>
      <title>Clauster: Non-loopback deployments can serve the dashboard unauthenticated when auth.enabled is unset</title>
      <link>https://www.patchbrief.org/items/2026-07-pypi-ghsa-h4g2-xfmw-q2c9.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-pypi-ghsa-h4g2-xfmw-q2c9.html</guid>
      <pubDate>Fri, 10 Jul 2026 00:00:00 +0000</pubDate>
      <description>Clauster: Non-loopback deployments can serve the dashboard unauthenticated when auth.enabled is unset</description>
    </item>
    <item>
      <title>mcp-atlassian: Arbitrary server-side file read via attachment upload</title>
      <link>https://www.patchbrief.org/items/2026-07-pypi-ghsa-wm45-qh3g-v83f.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-pypi-ghsa-wm45-qh3g-v83f.html</guid>
      <pubDate>Fri, 10 Jul 2026 00:00:00 +0000</pubDate>
      <description>mcp-atlassian: Arbitrary server-side file read via attachment upload</description>
    </item>
    <item>
      <title>`exploration` was removed from crates.io for malicious code</title>
      <link>https://www.patchbrief.org/items/2026-07-rust-ghsa-99j7-fhr2-xfj4.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-rust-ghsa-99j7-fhr2-xfj4.html</guid>
      <pubDate>Fri, 10 Jul 2026 00:00:00 +0000</pubDate>
      <description>`exploration` was removed from crates.io for malicious code</description>
    </item>
    <item>
      <title>VU#564823: GNU Wget enables SSRF via unvalidated FTP PASV IPs</title>
      <link>https://www.patchbrief.org/items/2026-07-users-vu-564823.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-users-vu-564823.html</guid>
      <pubDate>Fri, 10 Jul 2026 00:00:00 +0000</pubDate>
      <description>Overview GNU Wget, versions 1.25.0 and earlier, contains a server-side request forgery (SSRF) vulnerability in its implementation of FTP passive mode. Because Wget does not properly validate IP addresses obtained from PASV responses, an attacker-controlled FTP endpoint can redirect the client’s connection to arbitrary IPs, potentially exposing internal network host and service responses. This vulnerability has been remediated in a recent update by GNU; see the Solutions section below for resolution guidance. Description GNU Wget is a widely used command-line utility for retrieving content over HTTP, HTTPS, and FTP. When operating over FTP in passive mode, Wget relies on the server’s PASV response to determine which IP address and port to use for the data connection. CVE-2026-15146 GNU Wget does not validate the IP address provided by an... Related CVEs: CVE-2021-40491, CVE-2026-15146.</description>
    </item>
    <item>
      <title>YesWiki: Authenticated (Admin) Server-Side Template Injection to Remote Code Execution via Bazar Semantic Templates</title>
      <link>https://www.patchbrief.org/items/2026-07-composer-cve-2026-52762.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-composer-cve-2026-52762.html</guid>
      <pubDate>Thu, 09 Jul 2026 00:00:00 +0000</pubDate>
      <description>YesWiki: Authenticated (Admin) Server-Side Template Injection to Remote Code Execution via Bazar Semantic Templates</description>
    </item>
    <item>
      <title>YesWiki vulnerable to unauthenticated arbitrary page deletion via `{{erasespamedcomments}}` action</title>
      <link>https://www.patchbrief.org/items/2026-07-composer-cve-2026-52766.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-composer-cve-2026-52766.html</guid>
      <pubDate>Thu, 09 Jul 2026 00:00:00 +0000</pubDate>
      <description>YesWiki vulnerable to unauthenticated arbitrary page deletion via `{{erasespamedcomments}}` action</description>
    </item>
    <item>
      <title>YesWiki Vulnerable to Unauthenticated ActivityPub Signature-Verification Bypass via `!openssl_verify(...)` accepting ...</title>
      <link>https://www.patchbrief.org/items/2026-07-composer-cve-2026-52767.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-composer-cve-2026-52767.html</guid>
      <pubDate>Thu, 09 Jul 2026 00:00:00 +0000</pubDate>
      <description>YesWiki Vulnerable to Unauthenticated ActivityPub Signature-Verification Bypass via `!openssl_verify(...)` accepting `int(-1)`</description>
    </item>
    <item>
      <title>YesWiki has Unauthenticated Server-Side Request Forgery via ActivityPub `Signature.keyId`</title>
      <link>https://www.patchbrief.org/items/2026-07-composer-cve-2026-52769.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-composer-cve-2026-52769.html</guid>
      <pubDate>Thu, 09 Jul 2026 00:00:00 +0000</pubDate>
      <description>YesWiki has Unauthenticated Server-Side Request Forgery via ActivityPub `Signature.keyId`</description>
    </item>
    <item>
      <title>YesWiki: SQL Injection possible through public Bazar entry-listing APIs via numeric `query`/`queries` filters</title>
      <link>https://www.patchbrief.org/items/2026-07-composer-cve-2026-52770.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-composer-cve-2026-52770.html</guid>
      <pubDate>Thu, 09 Jul 2026 00:00:00 +0000</pubDate>
      <description>YesWiki: SQL Injection possible through public Bazar entry-listing APIs via numeric `query`/`queries` filters</description>
    </item>
    <item>
      <title>YesWiki: Second-Order SQL Injection in Page Delete API via Unescaped Page Tag (`ApiController::deletePage`)</title>
      <link>https://www.patchbrief.org/items/2026-07-composer-cve-2026-52771.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-composer-cve-2026-52771.html</guid>
      <pubDate>Thu, 09 Jul 2026 00:00:00 +0000</pubDate>
      <description>YesWiki: Second-Order SQL Injection in Page Delete API via Unescaped Page Tag (`ApiController::deletePage`)</description>
    </item>
    <item>
      <title>YesWiki has Authenticated SQL Injection via ReactionManager</title>
      <link>https://www.patchbrief.org/items/2026-07-composer-cve-2026-52775.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-composer-cve-2026-52775.html</guid>
      <pubDate>Thu, 09 Jul 2026 00:00:00 +0000</pubDate>
      <description>YesWiki has Authenticated SQL Injection via ReactionManager</description>
    </item>
    <item>
      <title>YesWiki Vulnerable to Authenticated PHP Object Injection in BazarImportAction via unserialize</title>
      <link>https://www.patchbrief.org/items/2026-07-composer-cve-2026-52777.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-composer-cve-2026-52777.html</guid>
      <pubDate>Thu, 09 Jul 2026 00:00:00 +0000</pubDate>
      <description>YesWiki Vulnerable to Authenticated PHP Object Injection in BazarImportAction via unserialize</description>
    </item>
    <item>
      <title>YesWiki has Unsafe eval() in its Formula Calculato, Leading to Remote Code Execution &amp; Denial of Service</title>
      <link>https://www.patchbrief.org/items/2026-07-composer-cve-2026-52778.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-composer-cve-2026-52778.html</guid>
      <pubDate>Thu, 09 Jul 2026 00:00:00 +0000</pubDate>
      <description>YesWiki has Unsafe eval() in its Formula Calculato, Leading to Remote Code Execution &amp; Denial of Service</description>
    </item>
    <item>
      <title>laravel-backup-restore has an OS Command Injection during database restore</title>
      <link>https://www.patchbrief.org/items/2026-07-composer-cve-2026-53932.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-composer-cve-2026-53932.html</guid>
      <pubDate>Thu, 09 Jul 2026 00:00:00 +0000</pubDate>
      <description>laravel-backup-restore has an OS Command Injection during database restore</description>
    </item>
    <item>
      <title>Craft CMS: RCE via missing cleanseConfig in FieldsController::actionRenderCardPreview</title>
      <link>https://www.patchbrief.org/items/2026-07-composer-ghsa-86vw-x4ww-x467.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-composer-ghsa-86vw-x4ww-x467.html</guid>
      <pubDate>Thu, 09 Jul 2026 00:00:00 +0000</pubDate>
      <description>Craft CMS: RCE via missing cleanseConfig in FieldsController::actionRenderCardPreview</description>
    </item>
    <item>
      <title>mint: Unbounded streams map growth via PUSH_PROMISE without follow-up HEADERS</title>
      <link>https://www.patchbrief.org/items/2026-07-erlang-cve-2026-48862.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-erlang-cve-2026-48862.html</guid>
      <pubDate>Thu, 09 Jul 2026 00:00:00 +0000</pubDate>
      <description>mint: Unbounded streams map growth via PUSH_PROMISE without follow-up HEADERS</description>
    </item>
    <item>
      <title>mint: Unbounded CONTINUATION/HEADERS frame accumulation (CONTINUATION flood)</title>
      <link>https://www.patchbrief.org/items/2026-07-erlang-cve-2026-49754.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-erlang-cve-2026-49754.html</guid>
      <pubDate>Thu, 09 Jul 2026 00:00:00 +0000</pubDate>
      <description>mint: Unbounded CONTINUATION/HEADERS frame accumulation (CONTINUATION flood)</description>
    </item>
    <item>
      <title>Note Mark: Path traversal via unsanitized book/note slug in migrate export (sibling of GHSA-g49p)</title>
      <link>https://www.patchbrief.org/items/2026-07-go-cve-2026-50553.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-go-cve-2026-50553.html</guid>
      <pubDate>Thu, 09 Jul 2026 00:00:00 +0000</pubDate>
      <description>Note Mark: Path traversal via unsanitized book/note slug in migrate export (sibling of GHSA-g49p)</description>
    </item>
    <item>
      <title>Hermes WebUI — CVE-2026-58122 (Critical)</title>
      <link>https://www.patchbrief.org/items/2026-07-hermes-cve-2026-58122.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-hermes-cve-2026-58122.html</guid>
      <pubDate>Thu, 09 Jul 2026 00:00:00 +0000</pubDate>
      <description>Hermes WebUI before 0.51.307 contains an authentication bypass vulnerability that allows unauthenticated remote attackers to circumvent local-origin IP restrictions on onboarding endpoints by supplying a spoofed X-Forwarded-For header with a loopback address. Attackers can exploit this bypass to perform server-side request forgery against internal services including cloud metadata endpoints, overwrite LLM provider configuration and API keys with attacker-controlled values, or initiate OAuth device-code flows to obtain persistent access tokens stored in auth.json.</description>
    </item>
    <item>
      <title>Hermes WebUI — CVE-2026-58123 (Critical)</title>
      <link>https://www.patchbrief.org/items/2026-07-hermes-cve-2026-58123.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-hermes-cve-2026-58123.html</guid>
      <pubDate>Thu, 09 Jul 2026 00:00:00 +0000</pubDate>
      <description>Hermes WebUI before 0.51.788 contains an unauthenticated remote code execution vulnerability that allows remote attackers to execute arbitrary shell commands by accessing the embedded terminal API endpoints without credentials. Attackers can create a session, attach a PTY shell, and write arbitrary commands through the terminal input endpoint to achieve full command execution as the server process user via four sequential unauthenticated HTTP requests.</description>
    </item>
    <item>
      <title>org.hl7.fhir.core: ReDoS via FHIRPath matches()/replaceMatches() in FHIR Validator HTTP Endpoint</title>
      <link>https://www.patchbrief.org/items/2026-07-maven-cve-2026-49485.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-maven-cve-2026-49485.html</guid>
      <pubDate>Thu, 09 Jul 2026 00:00:00 +0000</pubDate>
      <description>org.hl7.fhir.core: ReDoS via FHIRPath matches()/replaceMatches() in FHIR Validator HTTP Endpoint</description>
    </item>
    <item>
      <title>Micronaut doesn't set a maximum redirect count for its HTTP Client, enabling infinite loop DoS</title>
      <link>https://www.patchbrief.org/items/2026-07-maven-ghsa-387m-935m-c4vw.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-maven-ghsa-387m-935m-c4vw.html</guid>
      <pubDate>Thu, 09 Jul 2026 00:00:00 +0000</pubDate>
      <description>Micronaut doesn't set a maximum redirect count for its HTTP Client, enabling infinite loop DoS</description>
    </item>
    <item>
      <title>Openwebui Open Webui — CVE-2026-59214 (Critical)</title>
      <link>https://www.patchbrief.org/items/2026-07-openwebui-cve-2026-59214.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-openwebui-cve-2026-59214.html</guid>
      <pubDate>Thu, 09 Jul 2026 00:00:00 +0000</pubDate>
      <description>Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. Prior to 0.10.0, Open WebUI runs client-side Python with Pyodide in a same-origin web worker, allowing stored chat payloads that use pyodide.http.pyfetch or the js module fetch and XMLHttpRequest APIs to issue authenticated same-origin requests when a victim clicks Run, which can reach admin-only endpoints and execute server-side code through configured tools. This issue is fixed in version 0.10.0.</description>
    </item>
    <item>
      <title>VU#152953: PayRange Android app version 7.0.7 contains multiple vulnerabilities</title>
      <link>https://www.patchbrief.org/items/2026-07-payrange-vu-152953.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-payrange-vu-152953.html</guid>
      <pubDate>Thu, 09 Jul 2026 00:00:00 +0000</pubDate>
      <description>Overview PayRange is a mobile payment app that allows users to pay for vending machines, laundromats, and other unattended machines using a smartphone with Bluetooth. Two vulnerabilities were discovered in version 7.0.7 of the PayRange app that is available in the Google Play store. Description A vulnerability (CVE-2026-13462) exists in the PayRange Android app that causes invalid SSL certificates to be accepted in application WebViews. A second vulnerability (CVE-2026-13461) exists that allows the injection of JavaScript, which can be used to escape the WebView sandbox and perform a number of dangerous actions on the user's device. These vulnerabilities were discovered in version 7.0.7 of the PayRange app. The PayRange app bypasses Android's SSL trust chain and accepts certificates that match any of the following rules (including... Related CVEs: CVE-2026-13461, CVE-2026-13462.</description>
    </item>
    <item>
      <title>Soup Sieve has Memory Exhaustion via Large Comma-Separated Selector Lists</title>
      <link>https://www.patchbrief.org/items/2026-07-pypi-cve-2026-49476.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-pypi-cve-2026-49476.html</guid>
      <pubDate>Thu, 09 Jul 2026 00:00:00 +0000</pubDate>
      <description>Soup Sieve has Memory Exhaustion via Large Comma-Separated Selector Lists</description>
    </item>
    <item>
      <title>Soup Sieve: Regular Expression Denial of Service (ReDoS) via Selector Parser</title>
      <link>https://www.patchbrief.org/items/2026-07-pypi-cve-2026-49477.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-pypi-cve-2026-49477.html</guid>
      <pubDate>Thu, 09 Jul 2026 00:00:00 +0000</pubDate>
      <description>Soup Sieve: Regular Expression Denial of Service (ReDoS) via Selector Parser</description>
    </item>
    <item>
      <title>Mistune: Potential DoS via quadratic-time parsing in parse_link_text</title>
      <link>https://www.patchbrief.org/items/2026-07-pypi-cve-2026-49851.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-pypi-cve-2026-49851.html</guid>
      <pubDate>Thu, 09 Jul 2026 00:00:00 +0000</pubDate>
      <description>Mistune: Potential DoS via quadratic-time parsing in parse_link_text</description>
    </item>
    <item>
      <title>Phantom: Arbitrary file write and decode-bomb DoS via unconfined MCP tool paths</title>
      <link>https://www.patchbrief.org/items/2026-07-pypi-ghsa-52vm-mxx8-f227.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-pypi-ghsa-52vm-mxx8-f227.html</guid>
      <pubDate>Thu, 09 Jul 2026 00:00:00 +0000</pubDate>
      <description>Phantom: Arbitrary file write and decode-bomb DoS via unconfined MCP tool paths</description>
    </item>
    <item>
      <title>Ruby CSS Parser: SSRF and Local File Disclosure in `CssParser::Parser#read_remote_file`</title>
      <link>https://www.patchbrief.org/items/2026-07-rubygems-cve-2026-53727.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-rubygems-cve-2026-53727.html</guid>
      <pubDate>Thu, 09 Jul 2026 00:00:00 +0000</pubDate>
      <description>Ruby CSS Parser: SSRF and Local File Disclosure in `CssParser::Parser#read_remote_file`</description>
    </item>
    <item>
      <title>VU#734812: Xerte Online Toolkit contains an authentication bypass that allows for RCE</title>
      <link>https://www.patchbrief.org/items/2026-07-xerte-vu-734812.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-xerte-vu-734812.html</guid>
      <pubDate>Thu, 09 Jul 2026 00:00:00 +0000</pubDate>
      <description>Overview Two vulnerabilities have been discovered in Xerte Online Toolkits, an open-source e-learning authoring toolsuite intended for the creation of learning materials within a web browser. CVE-2026-14261 tracks the persistence of the /setup/ directory after installation, which allows an unauthenticated attacker to reconfigure the application to point to a remote database they control in order to gain administrative access. CVE-2026-12116 tracks an editable antivirus binary path that can be redirected to a PHP interpreter, causing uploaded files to be executed as PHP code and resulting in remote code execution (RCE). Version v3.15.5 or v3.14.6 of Xerte Online Toolkits fixes these vulnerabilities. Description Xerte Online Toolkits is a suite of a free, open-source e-learning authoring tools that allows users to make educational... Related CVEs: CVE-2026-12116, CVE-2026-14261.</description>
    </item>
    <item>
      <title>Blocksy Companion Pro plugin for WordPress — CVE-2026-58480 (Critical)</title>
      <link>https://www.patchbrief.org/items/2026-07-blocksy-cve-2026-58480.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-blocksy-cve-2026-58480.html</guid>
      <pubDate>Wed, 08 Jul 2026 00:00:00 +0000</pubDate>
      <description>Blocksy Companion Pro plugin for WordPress before 2.1.47 contains an unauthenticated arbitrary file upload vulnerability that allows attackers to upload executable files by bypassing extension validation in the save_attachments function exposed through the Advanced Reviews feature. Attackers can exploit the Custom Fonts extension's flawed strpos() substring check by uploading double-extension filenames such as shell.woff2.php, causing the validation to pass on the substring match while the web server executes the file as PHP, achieving remote code execution.</description>
    </item>
    <item>
      <title>Skipper: opaAuthorizeRequestWithBody filter bypasses OPA policy on Transfer-Encoding — chunked / HTTP/2 requests</title>
      <link>https://www.patchbrief.org/items/2026-07-go-cve-2026-50197.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-go-cve-2026-50197.html</guid>
      <pubDate>Wed, 08 Jul 2026 00:00:00 +0000</pubDate>
      <description>Skipper: opaAuthorizeRequestWithBody filter bypasses OPA policy on Transfer-Encoding — chunked / HTTP/2 requests</description>
    </item>
    <item>
      <title>Nuclio: Unsanitized cron trigger event headers/body injected into CronJob shell command leads to persistent RCE</title>
      <link>https://www.patchbrief.org/items/2026-07-go-cve-2026-52831.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-go-cve-2026-52831.html</guid>
      <pubDate>Wed, 08 Jul 2026 00:00:00 +0000</pubDate>
      <description>Nuclio: Unsanitized cron trigger event headers/body injected into CronJob shell command leads to persistent RCE</description>
    </item>
    <item>
      <title>Joro: Unauthenticated Cross-Origin Plugin Upload Leads to RCE</title>
      <link>https://www.patchbrief.org/items/2026-07-go-cve-2026-53649.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-go-cve-2026-53649.html</guid>
      <pubDate>Wed, 08 Jul 2026 00:00:00 +0000</pubDate>
      <description>Joro: Unauthenticated Cross-Origin Plugin Upload Leads to RCE</description>
    </item>
    <item>
      <title>Ibm Api Connect — CVE-2026-3144 (Critical)</title>
      <link>https://www.patchbrief.org/items/2026-07-ibm-cve-2026-3144.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-ibm-cve-2026-3144.html</guid>
      <pubDate>Wed, 08 Jul 2026 00:00:00 +0000</pubDate>
      <description>IBM API Connect 12.1.0.0 through 12.1.0.3 uses default credentials which could allow an attacker to gain unauthorized access to the application before the system enforces a credential update.</description>
    </item>
    <item>
      <title>Ibm Api Connect — CVE-2026-9074 (Critical)</title>
      <link>https://www.patchbrief.org/items/2026-07-ibm-cve-2026-9074.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-ibm-cve-2026-9074.html</guid>
      <pubDate>Wed, 08 Jul 2026 00:00:00 +0000</pubDate>
      <description>IBM API Connect 10.0.8.0 through 10.0.8.9 and 12.1.0.0 through 12.1.0.3 contains an unauthenticated SQL injection vulnerability in the password reset functionality.</description>
    </item>
    <item>
      <title>NL Portal: IDOR allows any authenticated user to complete and tamper with another user's taak</title>
      <link>https://www.patchbrief.org/items/2026-07-maven-cve-2026-49464.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-maven-cve-2026-49464.html</guid>
      <pubDate>Wed, 08 Jul 2026 00:00:00 +0000</pubDate>
      <description>NL Portal: IDOR allows any authenticated user to complete and tamper with another user's taak</description>
    </item>
    <item>
      <title>DSpace has possible Remote Code Execution (RCE)  through Velocity Templates used by LDN</title>
      <link>https://www.patchbrief.org/items/2026-07-maven-cve-2026-49832.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-maven-cve-2026-49832.html</guid>
      <pubDate>Wed, 08 Jul 2026 00:00:00 +0000</pubDate>
      <description>DSpace has possible Remote Code Execution (RCE) through Velocity Templates used by LDN</description>
    </item>
    <item>
      <title>Openbsd Openssh — CVE-2026-60002 (Critical)</title>
      <link>https://www.patchbrief.org/items/2026-07-openbsd-cve-2026-60002.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-openbsd-cve-2026-60002.html</guid>
      <pubDate>Wed, 08 Jul 2026 00:00:00 +0000</pubDate>
      <description>ssh in OpenSSH before 10.4 can have a use-after-free when a server changes its host key during a key re-exchange. (This outcome occurs only on the client side.)</description>
    </item>
    <item>
      <title>Progress Moveit Transfer — CVE-2026-8649 (Critical)</title>
      <link>https://www.patchbrief.org/items/2026-07-progress-cve-2026-8649.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-progress-cve-2026-8649.html</guid>
      <pubDate>Wed, 08 Jul 2026 00:00:00 +0000</pubDate>
      <description>Improper Neutralization of Special Elements in Data Query Logic vulnerability in Progress MOVEit Transfer (Custom Reports modules). This issue affects MOVEit Transfer: before 2025.0.7, from 2025.1.0 before 2025.1.3.</description>
    </item>
    <item>
      <title>Progress Moveit Transfer — CVE-2026-8801 (Critical)</title>
      <link>https://www.patchbrief.org/items/2026-07-progress-cve-2026-8801.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-progress-cve-2026-8801.html</guid>
      <pubDate>Wed, 08 Jul 2026 00:00:00 +0000</pubDate>
      <description>Path equivalence: vulnerability in Progress MOVEit Transfer (File Upload modules). This issue affects MOVEit Transfer: before 2025.0.8, from 2025.1.0 before 2025.1.4.</description>
    </item>
    <item>
      <title>Serena: Unauthenticated Flask dashboard on fixed port enables DNS rebinding → memory poisoning → RCE</title>
      <link>https://www.patchbrief.org/items/2026-07-pypi-cve-2026-49471.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-pypi-cve-2026-49471.html</guid>
      <pubDate>Wed, 08 Jul 2026 00:00:00 +0000</pubDate>
      <description>Serena: Unauthenticated Flask dashboard on fixed port enables DNS rebinding → memory poisoning → RCE</description>
    </item>
    <item>
      <title>`lxml_html_clean.Cleaner` does not strip `javascript:` URLs from namespaced URL attributes</title>
      <link>https://www.patchbrief.org/items/2026-07-pypi-cve-2026-49825.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-pypi-cve-2026-49825.html</guid>
      <pubDate>Wed, 08 Jul 2026 00:00:00 +0000</pubDate>
      <description>`lxml_html_clean.Cleaner` does not strip `javascript:` URLs from namespaced URL attributes</description>
    </item>
    <item>
      <title>VU#849433: Adalo Database API Enables Cross-App User Data Extraction via Over-Fetching and Missing Authorization Cont...</title>
      <link>https://www.patchbrief.org/items/2026-07-unrestricted-vu-849433.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-unrestricted-vu-849433.html</guid>
      <pubDate>Wed, 08 Jul 2026 00:00:00 +0000</pubDate>
      <description>Overview Adalo’s no‑code application platform exposes complete user records through its database API for all applications built on both V1 and V2. Due to a platform-level flaw, authenticated users can retrieve full user data belonging to any Adalo application, regardless of configuration. This issue affects more than one million applications and placing developers and their end users at risk of data exposure that they cannot prevent or remediate. Description Adalo is a Software-as-a-Service (SaaS) provider for building no-code applications. In theory, each application or tenant (customer) is logically isolated with separate databases, users, and configurations. CVE-2026-10706 Unrestricted Disclosure of Full User Records The Adalo database API contains a flaw which allows the backend to return complete user records for every list... Related CVEs: CVE-2026-10706, CVE-2026-10708.</description>
    </item>
    <item>
      <title>Adobe ColdFusion Path Traversal Vulnerability</title>
      <link>https://www.patchbrief.org/items/2026-07-adobe-cve-2026-48282.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-adobe-cve-2026-48282.html</guid>
      <pubDate>Tue, 07 Jul 2026 00:00:00 +0000</pubDate>
      <description>Adobe ColdFusion contains a path traversal vulnerability that could lead to arbitrary code execution in the context of the current user.</description>
    </item>
    <item>
      <title>EGroupware has a Remote Code Execution Vulnerability</title>
      <link>https://www.patchbrief.org/items/2026-07-composer-cve-2026-27823.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-composer-cve-2026-27823.html</guid>
      <pubDate>Tue, 07 Jul 2026 00:00:00 +0000</pubDate>
      <description>EGroupware has a Remote Code Execution Vulnerability</description>
    </item>
    <item>
      <title>EGroupware has Authenticated RCE via Malicious eTemplate Upload</title>
      <link>https://www.patchbrief.org/items/2026-07-composer-cve-2026-40187.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-composer-cve-2026-40187.html</guid>
      <pubDate>Tue, 07 Jul 2026 00:00:00 +0000</pubDate>
      <description>EGroupware has Authenticated RCE via Malicious eTemplate Upload</description>
    </item>
    <item>
      <title>Esri Portal For Arcgis — CVE-2026-13020 (Critical)</title>
      <link>https://www.patchbrief.org/items/2026-07-esri-cve-2026-13020.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-esri-cve-2026-13020.html</guid>
      <pubDate>Tue, 07 Jul 2026 00:00:00 +0000</pubDate>
      <description>A Weak Password Recovery Mechanism for Forgotten Password exists in Esri Portal for ArcGIS versions 12.1 and earlier on Windows, Linux and Kubernetes. A remote, unauthorized attacker may assume ownership of a user’s account by manipulating this mechanism. ArcGIS Administrators should configure an email server with ArcGIS Enterprise to facilitate user self-service password recovery. The ability for an administrator to reset a user’s password remains unchanged.</description>
    </item>
    <item>
      <title>New API: SSRF Protection Bypass via Unresolved Hostname in Notification URLs</title>
      <link>https://www.patchbrief.org/items/2026-07-go-cve-2026-33655.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-go-cve-2026-33655.html</guid>
      <pubDate>Tue, 07 Jul 2026 00:00:00 +0000</pubDate>
      <description>New API: SSRF Protection Bypass via Unresolved Hostname in Notification URLs</description>
    </item>
    <item>
      <title>Goploy: Cross-namespace IDOR and RCE via body-supplied row id in project and project_file handlers</title>
      <link>https://www.patchbrief.org/items/2026-07-go-cve-2026-53552.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-go-cve-2026-53552.html</guid>
      <pubDate>Tue, 07 Jul 2026 00:00:00 +0000</pubDate>
      <description>Goploy: Cross-namespace IDOR and RCE via body-supplied row id in project and project_file handlers</description>
    </item>
    <item>
      <title>Goploy: Arbitrary File Read via Path Traversal in /deploy/fileDiff allows Remote Server Compromise</title>
      <link>https://www.patchbrief.org/items/2026-07-go-cve-2026-53553.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-go-cve-2026-53553.html</guid>
      <pubDate>Tue, 07 Jul 2026 00:00:00 +0000</pubDate>
      <description>Goploy: Arbitrary File Read via Path Traversal in /deploy/fileDiff allows Remote Server Compromise</description>
    </item>
    <item>
      <title>Joomlack Page Builder Improper Access Control Vulnerability</title>
      <link>https://www.patchbrief.org/items/2026-07-joomlack-cve-2026-56290.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-joomlack-cve-2026-56290.html</guid>
      <pubDate>Tue, 07 Jul 2026 00:00:00 +0000</pubDate>
      <description>Joomlack Page Builder contains an improper access control vulnerability that could allow for remote code execution via unauthenticated arbitrary file upload.</description>
    </item>
    <item>
      <title>JoomShaper SP Page Builder Unrestricted Upload of File with Dangerous Type Vulnerability</title>
      <link>https://www.patchbrief.org/items/2026-07-joomshaper-cve-2026-48908.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-joomshaper-cve-2026-48908.html</guid>
      <pubDate>Tue, 07 Jul 2026 00:00:00 +0000</pubDate>
      <description>JoomShaper SP Page Builder contains an unrestricted upload of file with dangerous type vulnerability that allows unauthenticated users to upload arbitrary files, ultimately resulting in the upload and execution of PHP code.</description>
    </item>
    <item>
      <title>Langflow Authorization Bypass Through User-Controlled Key Vulnerability</title>
      <link>https://www.patchbrief.org/items/2026-07-langflow-cve-2026-55255.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-langflow-cve-2026-55255.html</guid>
      <pubDate>Tue, 07 Jul 2026 00:00:00 +0000</pubDate>
      <description>Langflow contains an authorization bypass through user-controlled key vulnerability which allows an authenticated attacker to execute any flow belonging to another user by specifying the victim's flow ID in the request.</description>
    </item>
    <item>
      <title>XWiki Platform Old Core: Resource path traversal via /skin/ action endpoint in Jetty 12+</title>
      <link>https://www.patchbrief.org/items/2026-07-maven-cve-2026-34151.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-maven-cve-2026-34151.html</guid>
      <pubDate>Tue, 07 Jul 2026 00:00:00 +0000</pubDate>
      <description>XWiki Platform Old Core: Resource path traversal via /skin/ action endpoint in Jetty 12+</description>
    </item>
    <item>
      <title>Better Auth: OAuth refresh-token replay via missing client authentication on oidc-provider and mcp plugins</title>
      <link>https://www.patchbrief.org/items/2026-07-npm-cve-2026-53512.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-npm-cve-2026-53512.html</guid>
      <pubDate>Tue, 07 Jul 2026 00:00:00 +0000</pubDate>
      <description>Better Auth: OAuth refresh-token replay via missing client authentication on oidc-provider and mcp plugins</description>
    </item>
    <item>
      <title>@better-auth/sso provider registration has server-side request forgery via unvalidated OIDC endpoints</title>
      <link>https://www.patchbrief.org/items/2026-07-npm-cve-2026-53513.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-npm-cve-2026-53513.html</guid>
      <pubDate>Tue, 07 Jul 2026 00:00:00 +0000</pubDate>
      <description>@better-auth/sso provider registration has server-side request forgery via unvalidated OIDC endpoints</description>
    </item>
    <item>
      <title>Better Auth vulnerable to unauthorized invitation acceptance via unverified email match in organization plugin</title>
      <link>https://www.patchbrief.org/items/2026-07-npm-cve-2026-53514.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-npm-cve-2026-53514.html</guid>
      <pubDate>Tue, 07 Jul 2026 00:00:00 +0000</pubDate>
      <description>Better Auth vulnerable to unauthorized invitation acceptance via unverified email match in organization plugin</description>
    </item>
    <item>
      <title>Better Auth has an account takeover issue via OAuth auto-link to unverified pre-registered email</title>
      <link>https://www.patchbrief.org/items/2026-07-npm-cve-2026-53516.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-npm-cve-2026-53516.html</guid>
      <pubDate>Tue, 07 Jul 2026 00:00:00 +0000</pubDate>
      <description>Better Auth has an account takeover issue via OAuth auto-link to unverified pre-registered email</description>
    </item>
    <item>
      <title>Better Auth: OAuth refresh-token rotation forks the token family on concurrent redemption</title>
      <link>https://www.patchbrief.org/items/2026-07-npm-cve-2026-53517.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-npm-cve-2026-53517.html</guid>
      <pubDate>Tue, 07 Jul 2026 00:00:00 +0000</pubDate>
      <description>Better Auth: OAuth refresh-token rotation forks the token family on concurrent redemption</description>
    </item>
    <item>
      <title>@better-auth/oauth-provider's OAuth authorization-code grant allows concurrent redemption when two token requests rac...</title>
      <link>https://www.patchbrief.org/items/2026-07-npm-cve-2026-53518.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-npm-cve-2026-53518.html</guid>
      <pubDate>Tue, 07 Jul 2026 00:00:00 +0000</pubDate>
      <description>@better-auth/oauth-provider's OAuth authorization-code grant allows concurrent redemption when two token requests race the find-then-delete primitive</description>
    </item>
    <item>
      <title>Better Auth has stored XSS in the auth-server origin via javascript: redirect_uri in oidc-provider and mcp</title>
      <link>https://www.patchbrief.org/items/2026-07-npm-ghsa-86j7-9j95-vpqj.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-npm-ghsa-86j7-9j95-vpqj.html</guid>
      <pubDate>Tue, 07 Jul 2026 00:00:00 +0000</pubDate>
      <description>Better Auth has stored XSS in the auth-server origin via javascript: redirect_uri in oidc-provider and mcp</description>
    </item>
    <item>
      <title>Better Auth has insecure cryptographic defaults in oidcProvider: alg=none advertised and plain PKCE accepted by default</title>
      <link>https://www.patchbrief.org/items/2026-07-npm-ghsa-9h47-pqcx-hjr4.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-npm-ghsa-9h47-pqcx-hjr4.html</guid>
      <pubDate>Tue, 07 Jul 2026 00:00:00 +0000</pubDate>
      <description>Better Auth has insecure cryptographic defaults in oidcProvider: alg=none advertised and plain PKCE accepted by default</description>
    </item>
    <item>
      <title>@better-auth/scim: Account/provider takeover via missing owner binding on non-org SCIM providers</title>
      <link>https://www.patchbrief.org/items/2026-07-npm-ghsa-j8v8-g9cx-5qf4.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-npm-ghsa-j8v8-g9cx-5qf4.html</guid>
      <pubDate>Tue, 07 Jul 2026 00:00:00 +0000</pubDate>
      <description>@better-auth/scim: Account/provider takeover via missing owner binding on non-org SCIM providers</description>
    </item>
    <item>
      <title>Open WebUI vulnerable to stored XSS via unescaped markdown token in MarkdownTokens.svelte leading to full account tak...</title>
      <link>https://www.patchbrief.org/items/2026-07-pypi-cve-2025-46719.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-pypi-cve-2025-46719.html</guid>
      <pubDate>Tue, 07 Jul 2026 00:00:00 +0000</pubDate>
      <description>Open WebUI vulnerable to stored XSS via unescaped markdown token in MarkdownTokens.svelte leading to full account takeover and RCE via functions</description>
    </item>
    <item>
      <title>Open WebUI vulnerable to Stored XSS via iFrame in citations model</title>
      <link>https://www.patchbrief.org/items/2026-07-pypi-cve-2026-26192.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-pypi-cve-2026-26192.html</guid>
      <pubDate>Tue, 07 Jul 2026 00:00:00 +0000</pubDate>
      <description>Open WebUI vulnerable to Stored XSS via iFrame in citations model</description>
    </item>
    <item>
      <title>Open WebUI vulnerable to Stored XSS via iFrame embeds in response messages</title>
      <link>https://www.patchbrief.org/items/2026-07-pypi-cve-2026-26193.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-pypi-cve-2026-26193.html</guid>
      <pubDate>Tue, 07 Jul 2026 00:00:00 +0000</pubDate>
      <description>Open WebUI vulnerable to Stored XSS via iFrame embeds in response messages</description>
    </item>
    <item>
      <title>ratex-parser panics on `\verb` with a multibyte delimiter (UTF-8 byte-boundary slice)</title>
      <link>https://www.patchbrief.org/items/2026-07-rust-cve-2026-53530.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-rust-cve-2026-53530.html</guid>
      <pubDate>Tue, 07 Jul 2026 00:00:00 +0000</pubDate>
      <description>ratex-parser panics on `\verb` with a multibyte delimiter (UTF-8 byte-boundary slice)</description>
    </item>
    <item>
      <title>uutils coreutils: cp/install/mv/ln --suffix alone does not enable backup mode (silent data loss vs GNU)</title>
      <link>https://www.patchbrief.org/items/2026-07-rust-ghsa-fqf6-gxhh-2xhw.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-rust-ghsa-fqf6-gxhh-2xhw.html</guid>
      <pubDate>Tue, 07 Jul 2026 00:00:00 +0000</pubDate>
      <description>uutils coreutils: cp/install/mv/ln --suffix alone does not enable backup mode (silent data loss vs GNU)</description>
    </item>
    <item>
      <title>Beyondtrust Privileged Remote Access — CVE-2026-40139 (Critical)</title>
      <link>https://www.patchbrief.org/items/2026-07-beyondtrust-cve-2026-40139.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-beyondtrust-cve-2026-40139.html</guid>
      <pubDate>Mon, 06 Jul 2026 00:00:00 +0000</pubDate>
      <description>A critical pre-authentication vulnerability exists in the authentication subsystem of BeyondTrust Remote Support. Improper processing of authentication requests may allow an unauthenticated remote attacker to bypass access controls and gain unauthorized access to the appliance, including accounts with elevated privileges. Exploitation requires a specific authentication configuration to be enabled.</description>
    </item>
    <item>
      <title>Beyondtrust Privileged Remote Access — CVE-2026-40141 (Critical)</title>
      <link>https://www.patchbrief.org/items/2026-07-beyondtrust-cve-2026-40141.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-beyondtrust-cve-2026-40141.html</guid>
      <pubDate>Mon, 06 Jul 2026 00:00:00 +0000</pubDate>
      <description>A high-severity vulnerability exists in a web application component of BeyondTrust Remote Support and Privileged Remote Access related to the processing of certain input parameters. Insufficient validation of user-supplied input may allow an authenticated attacker with limited privileges to access unintended resources or data beyond their authorization scope. Exploitation is restricted to accounts with specific permissions.</description>
    </item>
    <item>
      <title>Formie Hidden field defaults vulnerable to Server-Side Template Injection</title>
      <link>https://www.patchbrief.org/items/2026-07-composer-cve-2026-52889.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-composer-cve-2026-52889.html</guid>
      <pubDate>Mon, 06 Jul 2026 00:00:00 +0000</pubDate>
      <description>Formie Hidden field defaults vulnerable to Server-Side Template Injection</description>
    </item>
    <item>
      <title>Craft CMS: DOM XSS via GitHub issue title in CraftSupport widget</title>
      <link>https://www.patchbrief.org/items/2026-07-composer-cve-2026-55790.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-composer-cve-2026-55790.html</guid>
      <pubDate>Mon, 06 Jul 2026 00:00:00 +0000</pubDate>
      <description>Craft CMS: DOM XSS via GitHub issue title in CraftSupport widget</description>
    </item>
    <item>
      <title>Craft CMS: Potential authenticated Remote Code Execution via referrer redirect</title>
      <link>https://www.patchbrief.org/items/2026-07-composer-cve-2026-55794.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-composer-cve-2026-55794.html</guid>
      <pubDate>Mon, 06 Jul 2026 00:00:00 +0000</pubDate>
      <description>Craft CMS: Potential authenticated Remote Code Execution via referrer redirect</description>
    </item>
    <item>
      <title>Esri Arcgis Server — CVE-2026-9182 (Critical)</title>
      <link>https://www.patchbrief.org/items/2026-07-esri-cve-2026-9182.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-esri-cve-2026-9182.html</guid>
      <pubDate>Mon, 06 Jul 2026 00:00:00 +0000</pubDate>
      <description>ArcGIS Server contains an unrestricted file upload vulnerability. An unauthenticated attacker could exploit this issue by uploading a crafted file to the affected endpoint. Successful exploitation could allow arbitrary file upload.</description>
    </item>
    <item>
      <title>Cilium vulnerable to sensitive information disclosure and cluster disruption via local Envoy admin socket access</title>
      <link>https://www.patchbrief.org/items/2026-07-go-cve-2026-49445.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-go-cve-2026-49445.html</guid>
      <pubDate>Mon, 06 Jul 2026 00:00:00 +0000</pubDate>
      <description>Cilium vulnerable to sensitive information disclosure and cluster disruption via local Envoy admin socket access</description>
    </item>
    <item>
      <title>Coder vulnerable to OIDC account takeover via email-based user matching and email_verified bypass</title>
      <link>https://www.patchbrief.org/items/2026-07-go-cve-2026-55075.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-go-cve-2026-55075.html</guid>
      <pubDate>Mon, 06 Jul 2026 00:00:00 +0000</pubDate>
      <description>Coder vulnerable to OIDC account takeover via email-based user matching and email_verified bypass</description>
    </item>
    <item>
      <title>Coder's OIDC email_verified type coercion bypass enables account takeover via unverified email linking</title>
      <link>https://www.patchbrief.org/items/2026-07-go-cve-2026-55076.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-go-cve-2026-55076.html</guid>
      <pubDate>Mon, 06 Jul 2026 00:00:00 +0000</pubDate>
      <description>Coder's OIDC email_verified type coercion bypass enables account takeover via unverified email linking</description>
    </item>
    <item>
      <title>Coder: User-admin role can reset owner account password</title>
      <link>https://www.patchbrief.org/items/2026-07-go-cve-2026-55077.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-go-cve-2026-55077.html</guid>
      <pubDate>Mon, 06 Jul 2026 00:00:00 +0000</pubDate>
      <description>Coder: User-admin role can reset owner account password</description>
    </item>
    <item>
      <title>Coder vulnerable to SSH config injection via unsanitized server-supplied values in `coder config-ssh`</title>
      <link>https://www.patchbrief.org/items/2026-07-go-cve-2026-55427.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-go-cve-2026-55427.html</guid>
      <pubDate>Mon, 06 Jul 2026 00:00:00 +0000</pubDate>
      <description>Coder vulnerable to SSH config injection via unsanitized server-supplied values in `coder config-ssh`</description>
    </item>
    <item>
      <title>Coder: Route hijacking through lack of validation of agent-supplied AllowedIPs in tailnet coordinator</title>
      <link>https://www.patchbrief.org/items/2026-07-go-cve-2026-55428.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-go-cve-2026-55428.html</guid>
      <pubDate>Mon, 06 Jul 2026 00:00:00 +0000</pubDate>
      <description>Coder: Route hijacking through lack of validation of agent-supplied AllowedIPs in tailnet coordinator</description>
    </item>
    <item>
      <title>Coder's workspace app upsert allows cross-workspace agent rebinding via user-controlled app ID</title>
      <link>https://www.patchbrief.org/items/2026-07-go-cve-2026-55429.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-go-cve-2026-55429.html</guid>
      <pubDate>Mon, 06 Jul 2026 00:00:00 +0000</pubDate>
      <description>Coder's workspace app upsert allows cross-workspace agent rebinding via user-controlled app ID</description>
    </item>
    <item>
      <title>Coder's session token leaked to arbitrary hosts via `coder open app` for external workspace apps</title>
      <link>https://www.patchbrief.org/items/2026-07-go-cve-2026-55431.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-go-cve-2026-55431.html</guid>
      <pubDate>Mon, 06 Jul 2026 00:00:00 +0000</pubDate>
      <description>Coder's session token leaked to arbitrary hosts via `coder open app` for external workspace apps</description>
    </item>
    <item>
      <title>Coder's AI Bridge Proxy skips TLS certificate verification in default configuration</title>
      <link>https://www.patchbrief.org/items/2026-07-go-cve-2026-55436.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-go-cve-2026-55436.html</guid>
      <pubDate>Mon, 06 Jul 2026 00:00:00 +0000</pubDate>
      <description>Coder's AI Bridge Proxy skips TLS certificate verification in default configuration</description>
    </item>
    <item>
      <title>Coder's workspace agent API insecure redirect handling allowed cross-agent file read and write</title>
      <link>https://www.patchbrief.org/items/2026-07-go-ghsa-qrwj-vh9x-gw5v.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-go-ghsa-qrwj-vh9x-gw5v.html</guid>
      <pubDate>Mon, 06 Jul 2026 00:00:00 +0000</pubDate>
      <description>Coder's workspace agent API insecure redirect handling allowed cross-agent file read and write</description>
    </item>
    <item>
      <title>OpenRemote has an incomplete fix for CVE-2026-40882: XXE in KNXProtocol.startAssetImport() allows arbitrary file read...</title>
      <link>https://www.patchbrief.org/items/2026-07-maven-cve-2026-54640.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-maven-cve-2026-54640.html</guid>
      <pubDate>Mon, 06 Jul 2026 00:00:00 +0000</pubDate>
      <description>OpenRemote has an incomplete fix for CVE-2026-40882: XXE in KNXProtocol.startAssetImport() allows arbitrary file read via unprotected XMLInputFactory</description>
    </item>
    <item>
      <title>OpenRemote has Cross-Realm User Information Disclosure in UserResourceImpl</title>
      <link>https://www.patchbrief.org/items/2026-07-maven-cve-2026-54641.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-maven-cve-2026-54641.html</guid>
      <pubDate>Mon, 06 Jul 2026 00:00:00 +0000</pubDate>
      <description>OpenRemote has Cross-Realm User Information Disclosure in UserResourceImpl</description>
    </item>
    <item>
      <title>OpenRemote has Authenticated SQL Injection via Datapoint Crosstab Export</title>
      <link>https://www.patchbrief.org/items/2026-07-maven-ghsa-cgfv-jrfp-2r7v.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-maven-ghsa-cgfv-jrfp-2r7v.html</guid>
      <pubDate>Mon, 06 Jul 2026 00:00:00 +0000</pubDate>
      <description>OpenRemote has Authenticated SQL Injection via Datapoint Crosstab Export</description>
    </item>
    <item>
      <title>Decompress: Archive extraction can create files and links outside of the target directory</title>
      <link>https://www.patchbrief.org/items/2026-07-npm-cve-2026-53486.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-npm-cve-2026-53486.html</guid>
      <pubDate>Mon, 06 Jul 2026 00:00:00 +0000</pubDate>
      <description>Decompress: Archive extraction can create files and links outside of the target directory</description>
    </item>
    <item>
      <title>9routers has Exposure of Sensitive Information and Unprotected Database Import/Export, Allowing Complete Credential T...</title>
      <link>https://www.patchbrief.org/items/2026-07-npm-cve-2026-55500.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-npm-cve-2026-55500.html</guid>
      <pubDate>Mon, 06 Jul 2026 00:00:00 +0000</pubDate>
      <description>9routers has Exposure of Sensitive Information and Unprotected Database Import/Export, Allowing Complete Credential Theft and Database Takeover</description>
    </item>
    <item>
      <title>9router: Login brute-force protection bypass via spoofed X-Forwarded-For header</title>
      <link>https://www.patchbrief.org/items/2026-07-npm-cve-2026-55501.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-npm-cve-2026-55501.html</guid>
      <pubDate>Mon, 06 Jul 2026 00:00:00 +0000</pubDate>
      <description>9router: Login brute-force protection bypass via spoofed X-Forwarded-For header</description>
    </item>
    <item>
      <title>9router has unauthenticated CRUD on /api/providers and Full API Key Leak via /api/usage/stats</title>
      <link>https://www.patchbrief.org/items/2026-07-npm-ghsa-vjc7-jrh9-9j86.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-npm-ghsa-vjc7-jrh9-9j86.html</guid>
      <pubDate>Mon, 06 Jul 2026 00:00:00 +0000</pubDate>
      <description>9router has unauthenticated CRUD on /api/providers and Full API Key Leak via /api/usage/stats</description>
    </item>
    <item>
      <title>VU#828543: HP Deskjet 2800 Printer Series Webservers contain Missing Authorization Vulnerability</title>
      <link>https://www.patchbrief.org/items/2026-07-overview-vu-828543.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-overview-vu-828543.html</guid>
      <pubDate>Mon, 06 Jul 2026 00:00:00 +0000</pubDate>
      <description>Overview HP Printers in the Deskjet 2800 Series running firmware version CVE-2026-13753 . This vulnerability allows unauthenticated access to the printer's webserver API endpoints, exposing Wi-Fi credentials, management configuration details, and sensitive security data normally restricted to administrative users. Description Modern HP printers provide a web-based management interface for configuring content such as Wi-Fi Direct settings, SNMP management access, and device security options. When accessed normally through the browser interface, these pages explicitly require administrator credentials before sensitive information is displayed. This information is protected because, for example, Wi-Fi Direct controls the printer's direct wireless connectivity, and SNMP configuration settings can reveal detailed information about the... Related CVEs: CVE-2026-13753.</description>
    </item>
    <item>
      <title>Langroid: SQLChatAgent dangerous-function blocklist can be bypassed with quoted or schema-qualified pg_read_file calls</title>
      <link>https://www.patchbrief.org/items/2026-07-pypi-cve-2026-54760.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-pypi-cve-2026-54760.html</guid>
      <pubDate>Mon, 06 Jul 2026 00:00:00 +0000</pubDate>
      <description>Langroid: SQLChatAgent dangerous-function blocklist can be bypassed with quoted or schema-qualified pg_read_file calls</description>
    </item>
    <item>
      <title>Langroid: Sandbox Escape to Remote Code Execution via Incomplete `eval()` Mitigation in TableChatAgent</title>
      <link>https://www.patchbrief.org/items/2026-07-pypi-cve-2026-54769.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-pypi-cve-2026-54769.html</guid>
      <pubDate>Mon, 06 Jul 2026 00:00:00 +0000</pubDate>
      <description>Langroid: Sandbox Escape to Remote Code Execution via Incomplete `eval()` Mitigation in TableChatAgent</description>
    </item>
    <item>
      <title>Langroid: handle_message() executes user-supplied tool JSON without sender verification</title>
      <link>https://www.patchbrief.org/items/2026-07-pypi-cve-2026-54771.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-pypi-cve-2026-54771.html</guid>
      <pubDate>Mon, 06 Jul 2026 00:00:00 +0000</pubDate>
      <description>Langroid: handle_message() executes user-supplied tool JSON without sender verification</description>
    </item>
    <item>
      <title>Linuxfabrik Monitoring Plugins have local privilege escalation using embedded command</title>
      <link>https://www.patchbrief.org/items/2026-07-pypi-cve-2026-55426.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-pypi-cve-2026-55426.html</guid>
      <pubDate>Mon, 06 Jul 2026 00:00:00 +0000</pubDate>
      <description>Linuxfabrik Monitoring Plugins have local privilege escalation using embedded command</description>
    </item>
    <item>
      <title>Langroid: Neo4jChatAgent executes LLM-generated Cypher without validation (prompt-to-Cypher injection; config-conditi...</title>
      <link>https://www.patchbrief.org/items/2026-07-pypi-cve-2026-55615.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-pypi-cve-2026-55615.html</guid>
      <pubDate>Mon, 06 Jul 2026 00:00:00 +0000</pubDate>
      <description>Langroid: Neo4jChatAgent executes LLM-generated Cypher without validation (prompt-to-Cypher injection; config-conditional RCE), mirroring the SQLChatAgent bug fixed in CVE-2026-25879</description>
    </item>
    <item>
      <title>flyto-core has Unauthenticated Command Execution via HTTP MCP `execute_module`</title>
      <link>https://www.patchbrief.org/items/2026-07-pypi-cve-2026-55786.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-pypi-cve-2026-55786.html</guid>
      <pubDate>Mon, 06 Jul 2026 00:00:00 +0000</pubDate>
      <description>flyto-core has Unauthenticated Command Execution via HTTP MCP `execute_module`</description>
    </item>
    <item>
      <title>flyto-core has SSRF guard bypass via IPv6 transition addresses (IPv4-mapped / 6to4 / NAT64) in validate_url_ssrf</title>
      <link>https://www.patchbrief.org/items/2026-07-pypi-cve-2026-55787.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-pypi-cve-2026-55787.html</guid>
      <pubDate>Mon, 06 Jul 2026 00:00:00 +0000</pubDate>
      <description>flyto-core has SSRF guard bypass via IPv6 transition addresses (IPv4-mapped / 6to4 / NAT64) in validate_url_ssrf</description>
    </item>
    <item>
      <title>chmod: --preserve-root bypassed by any path that resolves to root (e.g. /../)</title>
      <link>https://www.patchbrief.org/items/2026-07-rust-cve-2026-35338.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-rust-cve-2026-35338.html</guid>
      <pubDate>Mon, 06 Jul 2026 00:00:00 +0000</pubDate>
      <description>chmod: --preserve-root bypassed by any path that resolves to root (e.g. /../)</description>
    </item>
    <item>
      <title>mkfifo: permissions of an existing file are changed after FIFO creation fails</title>
      <link>https://www.patchbrief.org/items/2026-07-rust-cve-2026-35341.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-rust-cve-2026-35341.html</guid>
      <pubDate>Mon, 06 Jul 2026 00:00:00 +0000</pubDate>
      <description>mkfifo: permissions of an existing file are changed after FIFO creation fails</description>
    </item>
    <item>
      <title>Zebra: Missing copy constraint in halo2_gadgets variable-base scalar multiplication allows under-constrained base, br...</title>
      <link>https://www.patchbrief.org/items/2026-07-rust-cve-2026-54496.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-rust-cve-2026-54496.html</guid>
      <pubDate>Mon, 06 Jul 2026 00:00:00 +0000</pubDate>
      <description>Zebra: Missing copy constraint in halo2_gadgets variable-base scalar multiplication allows under-constrained base, breaking Orchard Action circuit soundness</description>
    </item>
    <item>
      <title>VU#213560: Tenda firmware (multiple versions) contains hidden authentication backdoor</title>
      <link>https://www.patchbrief.org/items/2026-07-tenda-vu-213560.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-tenda-vu-213560.html</guid>
      <pubDate>Mon, 06 Jul 2026 00:00:00 +0000</pubDate>
      <description>Overview Several versions of Tenda firmware contain an undocumented authentication backdoor that grants administrative access to the devices' web management interfaces. An attacker can expoit this vulnerability, tracked as CVE-2026-11405, to bypass the password verification process and obtain full administrative control without valid credentials. Affected Versions: * US_FH1201V1.0BR_V1.2.0.14(408)_EN_TD * US_W15EV1.0br_V15.11.0.5(1068_1567_841)_EN_TDE * US_AC10V1.0re_V15.03.06.46_multi_TDE01 * US_AC5V1.0RTL_V15.03.06.48_multi_TDE01 * US_AC6V2.0RTL_V15.03.06.51_multi_T Description Tenda is a supplier of home and business network devices such as routers, switches, wireless access points, and video surveillance equipment. Most of these devices include web-based interfaces that allow users to perform configuration and management operations... Related CVEs: CVE-2026-11405.</description>
    </item>
    <item>
      <title>Traefik Traefik — CVE-2026-54763 (Critical)</title>
      <link>https://www.patchbrief.org/items/2026-07-traefik-cve-2026-54763.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-traefik-cve-2026-54763.html</guid>
      <pubDate>Mon, 06 Jul 2026 00:00:00 +0000</pubDate>
      <description>Traefik is an HTTP reverse proxy and load balancer. Prior to v2.11.51, v3.6.22, and v3.7.6, Traefik's BasicAuth, DigestAuth, and ForwardAuth middlewares strip canonical-cased spoofed identity headers before writing Traefik's own value, but do not account for underscore-variant header names, which many backends normalize identically to dashed forms. An attacker able to reach a protected route can inject an underscore-variant header that survives Traefik's stripping and reaches the backend alongside, or on the unauthenticated ForwardAuth authResponseHeaders path instead of, the value Traefik int</description>
    </item>
    <item>
      <title>Apereo CAS 7.3.0 — CVE-2026-59099 (Critical)</title>
      <link>https://www.patchbrief.org/items/2026-07-apereo-cve-2026-59099.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-apereo-cve-2026-59099.html</guid>
      <pubDate>Thu, 02 Jul 2026 00:00:00 +0000</pubDate>
      <description>Apereo CAS 7.3.0 before 8.0.0-RC6 contains a cryptographic vulnerability that allows remote unauthenticated attackers to recover plaintext conversation state by exploiting AES-GCM initialization vector reuse across the server lifetime. Attackers can collect multiple client-side webflow execution tokens from the unauthenticated login page and perform known-plaintext analysis to decrypt the webflow conversation state due to keystream reuse caused by a fixed all-zero IV paired with the same encryption key.</description>
    </item>
    <item>
      <title>SimpleSAMLphp HTTP-Artifact TLS validator confusion allows cross-IdP authentication bypass</title>
      <link>https://www.patchbrief.org/items/2026-07-composer-cve-2026-49283.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-composer-cve-2026-49283.html</guid>
      <pubDate>Thu, 02 Jul 2026 00:00:00 +0000</pubDate>
      <description>SimpleSAMLphp HTTP-Artifact TLS validator confusion allows cross-IdP authentication bypass</description>
    </item>
    <item>
      <title>SimpleSAMLphp SP accepts a response from an unexpected IdP when unsigned `Response/InResponseTo` is combined with a s...</title>
      <link>https://www.patchbrief.org/items/2026-07-composer-cve-2026-49284.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-composer-cve-2026-49284.html</guid>
      <pubDate>Thu, 02 Jul 2026 00:00:00 +0000</pubDate>
      <description>SimpleSAMLphp SP accepts a response from an unexpected IdP when unsigned `Response/InResponseTo` is combined with a signed assertion lacking `SubjectConfirmationData/InResponseTo`</description>
    </item>
    <item>
      <title>SimpleSAMLphp has Possible DoS via XPath Transform</title>
      <link>https://www.patchbrief.org/items/2026-07-composer-cve-2026-49289.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-composer-cve-2026-49289.html</guid>
      <pubDate>Thu, 02 Jul 2026 00:00:00 +0000</pubDate>
      <description>SimpleSAMLphp has Possible DoS via XPath Transform</description>
    </item>
    <item>
      <title>Craft CMS's mass assignment via id in newAttributes during bulk duplicate overwrites existing elements</title>
      <link>https://www.patchbrief.org/items/2026-07-composer-cve-2026-50281.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-composer-cve-2026-50281.html</guid>
      <pubDate>Thu, 02 Jul 2026 00:00:00 +0000</pubDate>
      <description>Craft CMS's mass assignment via id in newAttributes during bulk duplicate overwrites existing elements</description>
    </item>
    <item>
      <title>Craft CMS Vulnerable to Unauthorized Deletion of Destination Folders During Forced Moves</title>
      <link>https://www.patchbrief.org/items/2026-07-composer-cve-2026-50282.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-composer-cve-2026-50282.html</guid>
      <pubDate>Thu, 02 Jul 2026 00:00:00 +0000</pubDate>
      <description>Craft CMS Vulnerable to Unauthorized Deletion of Destination Folders During Forced Moves</description>
    </item>
    <item>
      <title>Mautic has Server-Side Template Injection (SSTI) in Theme Templates</title>
      <link>https://www.patchbrief.org/items/2026-07-composer-cve-2026-9558.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-composer-cve-2026-9558.html</guid>
      <pubDate>Thu, 02 Jul 2026 00:00:00 +0000</pubDate>
      <description>Mautic has Server-Side Template Injection (SSTI) in Theme Templates</description>
    </item>
    <item>
      <title>Mautic vulnerable to Path Traversal via Campaign Import</title>
      <link>https://www.patchbrief.org/items/2026-07-composer-cve-2026-9559.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-composer-cve-2026-9559.html</guid>
      <pubDate>Thu, 02 Jul 2026 00:00:00 +0000</pubDate>
      <description>Mautic vulnerable to Path Traversal via Campaign Import</description>
    </item>
    <item>
      <title>Mautic has an Authorization Bypass in API v2 Endpoints</title>
      <link>https://www.patchbrief.org/items/2026-07-composer-cve-2026-9808.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-composer-cve-2026-9808.html</guid>
      <pubDate>Thu, 02 Jul 2026 00:00:00 +0000</pubDate>
      <description>Mautic has an Authorization Bypass in API v2 Endpoints</description>
    </item>
    <item>
      <title>Mautic has Stored Cross-Site Scripting (XSS) in Projects Component</title>
      <link>https://www.patchbrief.org/items/2026-07-composer-cve-2026-9809.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-composer-cve-2026-9809.html</guid>
      <pubDate>Thu, 02 Jul 2026 00:00:00 +0000</pubDate>
      <description>Mautic has Stored Cross-Site Scripting (XSS) in Projects Component</description>
    </item>
    <item>
      <title>golang.org/x/image/tiff has excessive resource consumption in PackBits decompression</title>
      <link>https://www.patchbrief.org/items/2026-07-go-cve-2026-46599.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-go-cve-2026-46599.html</guid>
      <pubDate>Thu, 02 Jul 2026 00:00:00 +0000</pubDate>
      <description>golang.org/x/image/tiff has excessive resource consumption in PackBits decompression</description>
    </item>
    <item>
      <title>Algernon vulnerable to server-side script source disclosure on Windows via NTFS filename</title>
      <link>https://www.patchbrief.org/items/2026-07-go-cve-2026-52792.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-go-cve-2026-52792.html</guid>
      <pubDate>Thu, 02 Jul 2026 00:00:00 +0000</pubDate>
      <description>Algernon vulnerable to server-side script source disclosure on Windows via NTFS filename</description>
    </item>
    <item>
      <title>VU#639124: Multiple local privilege escalation vulnerabilities in Little Orbits GameFirst Anti-Cheat</title>
      <link>https://www.patchbrief.org/items/2026-07-little-vu-639124.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-little-vu-639124.html</guid>
      <pubDate>Thu, 02 Jul 2026 00:00:00 +0000</pubDate>
      <description>Overview The GamersFirst Anti-Cheat (GFAC) driver GFAC.sys contains multiple local privilege escalations and denial-of-service vulnerabilities stemming from insecure handling of user-controlled input through a minifilter communication port. A local attacker can abuse these flaws to perform arbitrary kernel memory writes, obtain privilege escalation to SYSTEM, or trigger a system crash. Description GFAC is a proprietary anti-cheat software developed by video game publisher Little Orbit. GFAC includes a kernel-mode driver, GFAC_Sys_x64.sys , that exposes privileged functionality to user-mode applications through a minifilter communication port. Although these low-level interfaces are necessary for the software's operation, vulnerabilities can arise if user-mode access is not properly restricted and validated. CVE-2026-12166... Related CVEs: CVE-2026-12166, CVE-2026-12167, CVE-2026-12168.</description>
    </item>
    <item>
      <title>Keycloak: Unauthorized access via improper validation of encrypted SAML assertions</title>
      <link>https://www.patchbrief.org/items/2026-07-maven-cve-2026-2092.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-maven-cve-2026-2092.html</guid>
      <pubDate>Thu, 02 Jul 2026 00:00:00 +0000</pubDate>
      <description>Keycloak: Unauthorized access via improper validation of encrypted SAML assertions</description>
    </item>
    <item>
      <title>LaunchServer FileServerHandler has an unauthenticated path traversal issue</title>
      <link>https://www.patchbrief.org/items/2026-07-maven-cve-2026-54617.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-maven-cve-2026-54617.html</guid>
      <pubDate>Thu, 02 Jul 2026 00:00:00 +0000</pubDate>
      <description>LaunchServer FileServerHandler has an unauthenticated path traversal issue</description>
    </item>
    <item>
      <title>Microsoft Azure Synapse Elevation of Privilege Vulnerability</title>
      <link>https://www.patchbrief.org/items/2026-07-microsoft-cve-2026-26145.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-microsoft-cve-2026-26145.html</guid>
      <pubDate>Thu, 02 Jul 2026 00:00:00 +0000</pubDate>
      <description>Improper access control in Azure Synapse allows an authorized attacker to elevate privileges over a network. Published in July 2026 Early Security Updates. MSRC exploitability: Publicly Disclosed:No;Exploited:No;Latest Software Release:N/A.</description>
    </item>
    <item>
      <title>Microsoft 365 Copilot Elevation of Privilege Vulnerability</title>
      <link>https://www.patchbrief.org/items/2026-07-microsoft-cve-2026-41106.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-microsoft-cve-2026-41106.html</guid>
      <pubDate>Thu, 02 Jul 2026 00:00:00 +0000</pubDate>
      <description>Url redirection to untrusted site ('open redirect') in M365 Copilot allows an unauthorized attacker to elevate privileges over a network. Published in July 2026 Early Security Updates. MSRC exploitability: Publicly Disclosed:No;Exploited:No;Latest Software Release:N/A.</description>
    </item>
    <item>
      <title>Azure OpenAI Elevation of Privilege Vulnerability</title>
      <link>https://www.patchbrief.org/items/2026-07-microsoft-cve-2026-45499.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-microsoft-cve-2026-45499.html</guid>
      <pubDate>Thu, 02 Jul 2026 00:00:00 +0000</pubDate>
      <description>Server-side request forgery (ssrf) in Azure OpenAI allows an authorized attacker to elevate privileges over a network. Published in July 2026 Early Security Updates. MSRC exploitability: Publicly Disclosed:No;Exploited:No;Latest Software Release:N/A.</description>
    </item>
    <item>
      <title>Microsoft Exchange Online Elevation of Privilege Vulnerability</title>
      <link>https://www.patchbrief.org/items/2026-07-microsoft-cve-2026-54998.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-microsoft-cve-2026-54998.html</guid>
      <pubDate>Thu, 02 Jul 2026 00:00:00 +0000</pubDate>
      <description>Incorrect authorization in Microsoft Exchange Online allows an authorized attacker to elevate privileges over a network. Published in July 2026 Early Security Updates. MSRC exploitability: Publicly Disclosed:No;Exploited:No;Latest Software Release:N/A.</description>
    </item>
    <item>
      <title>Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability</title>
      <link>https://www.patchbrief.org/items/2026-07-microsoft-cve-2026-56645.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-microsoft-cve-2026-56645.html</guid>
      <pubDate>Thu, 02 Jul 2026 00:00:00 +0000</pubDate>
      <description>Heap-based buffer overflow in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network. Published in July 2026 Early Security Updates. MSRC exploitability: Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation Less Likely.</description>
    </item>
    <item>
      <title>Microsoft Entra Provisioning Service Elevation of Privilege Vulnerability</title>
      <link>https://www.patchbrief.org/items/2026-07-microsoft-cve-2026-57100.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-microsoft-cve-2026-57100.html</guid>
      <pubDate>Thu, 02 Jul 2026 00:00:00 +0000</pubDate>
      <description>Server-side request forgery (ssrf) in Microsoft Entra Provisioning Service (SyncFabric) allows an authorized attacker to elevate privileges over a network. Published in July 2026 Early Security Updates. MSRC exploitability: Publicly Disclosed:No;Exploited:No;Latest Software Release:N/A.</description>
    </item>
    <item>
      <title>Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability</title>
      <link>https://www.patchbrief.org/items/2026-07-microsoft-cve-2026-57974.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-microsoft-cve-2026-57974.html</guid>
      <pubDate>Thu, 02 Jul 2026 00:00:00 +0000</pubDate>
      <description>Integer overflow or wraparound in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network. Published in July 2026 Early Security Updates. MSRC exploitability: Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation Unlikely.</description>
    </item>
    <item>
      <title>Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability</title>
      <link>https://www.patchbrief.org/items/2026-07-microsoft-cve-2026-57981.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-microsoft-cve-2026-57981.html</guid>
      <pubDate>Thu, 02 Jul 2026 00:00:00 +0000</pubDate>
      <description>Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network. Published in July 2026 Early Security Updates. MSRC exploitability: Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation Unlikely.</description>
    </item>
    <item>
      <title>Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability</title>
      <link>https://www.patchbrief.org/items/2026-07-microsoft-cve-2026-58289.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-microsoft-cve-2026-58289.html</guid>
      <pubDate>Thu, 02 Jul 2026 00:00:00 +0000</pubDate>
      <description>Access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network. Published in July 2026 Early Security Updates. MSRC exploitability: Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation Unlikely.</description>
    </item>
    <item>
      <title>9router's Hardcoded Default fallback JWT Secret  Allows Authentication Bypass</title>
      <link>https://www.patchbrief.org/items/2026-07-npm-cve-2026-49352.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-npm-cve-2026-49352.html</guid>
      <pubDate>Thu, 02 Jul 2026 00:00:00 +0000</pubDate>
      <description>9router's Hardcoded Default fallback JWT Secret Allows Authentication Bypass</description>
    </item>
    <item>
      <title>9router has an Incomplete Fix: Local-Only Access Gate Bypass in 9router via Host Header SpoofING</title>
      <link>https://www.patchbrief.org/items/2026-07-npm-cve-2026-49353.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-npm-cve-2026-49353.html</guid>
      <pubDate>Thu, 02 Jul 2026 00:00:00 +0000</pubDate>
      <description>9router has an Incomplete Fix: Local-Only Access Gate Bypass in 9router via Host Header SpoofING</description>
    </item>
    <item>
      <title>jsonata: Malicious inputs to "$toMillis" function can cause resource exhaustion</title>
      <link>https://www.patchbrief.org/items/2026-07-npm-cve-2026-52746.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-npm-cve-2026-52746.html</guid>
      <pubDate>Thu, 02 Jul 2026 00:00:00 +0000</pubDate>
      <description>jsonata: Malicious inputs to "$toMillis" function can cause resource exhaustion</description>
    </item>
    <item>
      <title>@asymmetric-effort/nogginlessdom's Path Traversal in matchFileSnapshot allows arbitrary file write</title>
      <link>https://www.patchbrief.org/items/2026-07-npm-ghsa-322x-v876-g883.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-npm-ghsa-322x-v876-g883.html</guid>
      <pubDate>Thu, 02 Jul 2026 00:00:00 +0000</pubDate>
      <description>@asymmetric-effort/nogginlessdom's Path Traversal in matchFileSnapshot allows arbitrary file write</description>
    </item>
    <item>
      <title>9router: Missing Authorization and OS Command Injection</title>
      <link>https://www.patchbrief.org/items/2026-07-npm-ghsa-g6g7-pvmx-m74p.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-npm-ghsa-g6g7-pvmx-m74p.html</guid>
      <pubDate>Thu, 02 Jul 2026 00:00:00 +0000</pubDate>
      <description>9router: Missing Authorization and OS Command Injection</description>
    </item>
    <item>
      <title>OpenClaw: QQBot admin commands could skip DM-only and allowFrom policy</title>
      <link>https://www.patchbrief.org/items/2026-07-npm-ghsa-w4v6-g3wm-w36c.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-npm-ghsa-w4v6-g3wm-w36c.html</guid>
      <pubDate>Thu, 02 Jul 2026 00:00:00 +0000</pubDate>
      <description>OpenClaw: QQBot admin commands could skip DM-only and allowFrom policy</description>
    </item>
    <item>
      <title>Steeltoe vulnerable to management-port isolation bypass via spoofed Host header</title>
      <link>https://www.patchbrief.org/items/2026-07-nuget-cve-2026-50194.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-nuget-cve-2026-50194.html</guid>
      <pubDate>Thu, 02 Jul 2026 00:00:00 +0000</pubDate>
      <description>Steeltoe vulnerable to management-port isolation bypass via spoofed Host header</description>
    </item>
    <item>
      <title>Steeltoe.Discovery.Eureka: Unrecognized DataCenterInfo.Name poisons entire registry fetch</title>
      <link>https://www.patchbrief.org/items/2026-07-nuget-cve-2026-50196.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-nuget-cve-2026-50196.html</guid>
      <pubDate>Thu, 02 Jul 2026 00:00:00 +0000</pubDate>
      <description>Steeltoe.Discovery.Eureka: Unrecognized DataCenterInfo.Name poisons entire registry fetch</description>
    </item>
    <item>
      <title>Steeltoe's env sanitizer misses connection strings — leaks embedded DB passwords</title>
      <link>https://www.patchbrief.org/items/2026-07-nuget-cve-2026-50200.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-nuget-cve-2026-50200.html</guid>
      <pubDate>Thu, 02 Jul 2026 00:00:00 +0000</pubDate>
      <description>Steeltoe's env sanitizer misses connection strings — leaks embedded DB passwords</description>
    </item>
    <item>
      <title>Recce server has unauthenticated SQL execution that allows local file read/write through DuckDB</title>
      <link>https://www.patchbrief.org/items/2026-07-pypi-cve-2026-49360.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-pypi-cve-2026-49360.html</guid>
      <pubDate>Thu, 02 Jul 2026 00:00:00 +0000</pubDate>
      <description>Recce server has unauthenticated SQL execution that allows local file read/write through DuckDB</description>
    </item>
    <item>
      <title>mcp-memory-service: Missing Authentication on Document API Endpoints Allows Unauthenticated Memory Read/Write/Delete</title>
      <link>https://www.patchbrief.org/items/2026-07-pypi-cve-2026-50027.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-pypi-cve-2026-50027.html</guid>
      <pubDate>Thu, 02 Jul 2026 00:00:00 +0000</pubDate>
      <description>mcp-memory-service: Missing Authentication on Document API Endpoints Allows Unauthenticated Memory Read/Write/Delete</description>
    </item>
    <item>
      <title>Linuxfabrik Monitoring Plugins: Sudoers may be able to obtain privilege escalation via /usr/bin/apt-get arguments</title>
      <link>https://www.patchbrief.org/items/2026-07-pypi-cve-2026-52817.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-pypi-cve-2026-52817.html</guid>
      <pubDate>Thu, 02 Jul 2026 00:00:00 +0000</pubDate>
      <description>Linuxfabrik Monitoring Plugins: Sudoers may be able to obtain privilege escalation via /usr/bin/apt-get arguments</description>
    </item>
    <item>
      <title>fast-mcp-telegram: Bearer token path traversal bypasses reserved Telegram session protection</title>
      <link>https://www.patchbrief.org/items/2026-07-pypi-cve-2026-52830.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-pypi-cve-2026-52830.html</guid>
      <pubDate>Thu, 02 Jul 2026 00:00:00 +0000</pubDate>
      <description>fast-mcp-telegram: Bearer token path traversal bypasses reserved Telegram session protection</description>
    </item>
    <item>
      <title>zebrad has consensus divergence via P2SH sigop undercount in pure-Rust disabled-opcode parser</title>
      <link>https://www.patchbrief.org/items/2026-07-rust-cve-2026-52735.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-rust-cve-2026-52735.html</guid>
      <pubDate>Thu, 02 Jul 2026 00:00:00 +0000</pubDate>
      <description>zebrad has consensus divergence via P2SH sigop undercount in pure-Rust disabled-opcode parser</description>
    </item>
    <item>
      <title>Zebra has block suppression via NU5 same-header body poisoning of sent-hash cache</title>
      <link>https://www.patchbrief.org/items/2026-07-rust-cve-2026-52736.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-rust-cve-2026-52736.html</guid>
      <pubDate>Thu, 02 Jul 2026 00:00:00 +0000</pubDate>
      <description>Zebra has block suppression via NU5 same-header body poisoning of sent-hash cache</description>
    </item>
    <item>
      <title>Zebra Address Book Aborted by IPv4-Mapped Mempool Misbehavior Update</title>
      <link>https://www.patchbrief.org/items/2026-07-rust-cve-2026-52829.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-rust-cve-2026-52829.html</guid>
      <pubDate>Thu, 02 Jul 2026 00:00:00 +0000</pubDate>
      <description>Zebra Address Book Aborted by IPv4-Mapped Mempool Misbehavior Update</description>
    </item>
    <item>
      <title>jxl-grid on 32-bit platforms has an out-of-bounds writes due to integer overflow</title>
      <link>https://www.patchbrief.org/items/2026-07-rust-cve-2026-52834.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-rust-cve-2026-52834.html</guid>
      <pubDate>Thu, 02 Jul 2026 00:00:00 +0000</pubDate>
      <description>jxl-grid on 32-bit platforms has an out-of-bounds writes due to integer overflow</description>
    </item>
    <item>
      <title>Twig: Sandbox filter, tag and function allow-list bypass when sandbox state changes between renders for a cached `Tem...</title>
      <link>https://www.patchbrief.org/items/2026-07-composer-cve-2026-49981.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-composer-cve-2026-49981.html</guid>
      <pubDate>Wed, 01 Jul 2026 00:00:00 +0000</pubDate>
      <description>Twig: Sandbox filter, tag and function allow-list bypass when sandbox state changes between renders for a cached `Template`</description>
    </item>
    <item>
      <title>QUIC has Broken TLS verification</title>
      <link>https://www.patchbrief.org/items/2026-07-erlang-cve-2026-49457.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-erlang-cve-2026-49457.html</guid>
      <pubDate>Wed, 01 Jul 2026 00:00:00 +0000</pubDate>
      <description>QUIC has Broken TLS verification</description>
    </item>
    <item>
      <title>Rancher has Privilege Escalation from Project Owner to Host</title>
      <link>https://www.patchbrief.org/items/2026-07-go-cve-2026-41052.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-go-cve-2026-41052.html</guid>
      <pubDate>Wed, 01 Jul 2026 00:00:00 +0000</pubDate>
      <description>Rancher has Privilege Escalation from Project Owner to Host</description>
    </item>
    <item>
      <title>Rancher has over-inclusive team membership expansion in GitHub App authentication provider</title>
      <link>https://www.patchbrief.org/items/2026-07-go-cve-2026-41053.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-go-cve-2026-41053.html</guid>
      <pubDate>Wed, 01 Jul 2026 00:00:00 +0000</pubDate>
      <description>Rancher has over-inclusive team membership expansion in GitHub App authentication provider</description>
    </item>
    <item>
      <title>Rancher Fleet vulnerable to cross namespace secret disclosure via unvalidated `valuesFrom` references in Helm Deployer</title>
      <link>https://www.patchbrief.org/items/2026-07-go-cve-2026-44935.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-go-cve-2026-44935.html</guid>
      <pubDate>Wed, 01 Jul 2026 00:00:00 +0000</pubDate>
      <description>Rancher Fleet vulnerable to cross namespace secret disclosure via unvalidated `valuesFrom` references in Helm Deployer</description>
    </item>
    <item>
      <title>Rancher Fleet has Unauthenticated Webhook: Regex Injection via Unsanitized Repository URL Components</title>
      <link>https://www.patchbrief.org/items/2026-07-go-cve-2026-44937.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-go-cve-2026-44937.html</guid>
      <pubDate>Wed, 01 Jul 2026 00:00:00 +0000</pubDate>
      <description>Rancher Fleet has Unauthenticated Webhook: Regex Injection via Unsanitized Repository URL Components</description>
    </item>
    <item>
      <title>Fleet has PSS Bypass through addLabelsFromOptions in Fleet Agent</title>
      <link>https://www.patchbrief.org/items/2026-07-go-cve-2026-44938.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-go-cve-2026-44938.html</guid>
      <pubDate>Wed, 01 Jul 2026 00:00:00 +0000</pubDate>
      <description>Fleet has PSS Bypass through addLabelsFromOptions in Fleet Agent</description>
    </item>
    <item>
      <title>Rancher vulnerable to command injection through unsanitized YAML parameter</title>
      <link>https://www.patchbrief.org/items/2026-07-go-cve-2026-44939.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-go-cve-2026-44939.html</guid>
      <pubDate>Wed, 01 Jul 2026 00:00:00 +0000</pubDate>
      <description>Rancher vulnerable to command injection through unsanitized YAML parameter</description>
    </item>
    <item>
      <title>Centrifugo's dynamic JWKS key cache keyed only by `kid` allows cross-issuer JWT authentication bypass</title>
      <link>https://www.patchbrief.org/items/2026-07-go-cve-2026-49998.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-go-cve-2026-49998.html</guid>
      <pubDate>Wed, 01 Jul 2026 00:00:00 +0000</pubDate>
      <description>Centrifugo's dynamic JWKS key cache keyed only by `kid` allows cross-issuer JWT authentication bypass</description>
    </item>
    <item>
      <title>goshs: WebDAV listener ignores --read-only, --upload-only, and --no-delete mode flags</title>
      <link>https://www.patchbrief.org/items/2026-07-go-cve-2026-50138.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-go-cve-2026-50138.html</guid>
      <pubDate>Wed, 01 Jul 2026 00:00:00 +0000</pubDate>
      <description>goshs: WebDAV listener ignores --read-only, --upload-only, and --no-delete mode flags</description>
    </item>
    <item>
      <title>oras-go blob upload vulnerable to credential forwarding via unvalidated Location header</title>
      <link>https://www.patchbrief.org/items/2026-07-go-cve-2026-50151.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-go-cve-2026-50151.html</guid>
      <pubDate>Wed, 01 Jul 2026 00:00:00 +0000</pubDate>
      <description>oras-go blob upload vulnerable to credential forwarding via unvalidated Location header</description>
    </item>
    <item>
      <title>`oras-go` tar extraction: Hardlink entry with relative Linkname escapes extract dir via process CWD resolution</title>
      <link>https://www.patchbrief.org/items/2026-07-go-cve-2026-50163.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-go-cve-2026-50163.html</guid>
      <pubDate>Wed, 01 Jul 2026 00:00:00 +0000</pubDate>
      <description>`oras-go` tar extraction: Hardlink entry with relative Linkname escapes extract dir via process CWD resolution</description>
    </item>
    <item>
      <title>Linuxfoundation Containerd — CVE-2026-50195 (Critical)</title>
      <link>https://www.patchbrief.org/items/2026-07-linuxfoundation-cve-2026-50195.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-linuxfoundation-cve-2026-50195.html</guid>
      <pubDate>Wed, 01 Jul 2026 00:00:00 +0000</pubDate>
      <description>containerd is an open-source container runtime. Versions prior to 2.3.2, 2.2.5 and 2.1.9 contain a vulnerability in the CRI checkpoint import process where it fails to validate the image references specified within a checkpoint image's configuration. An attacker with permissions to create pods can use a crafted checkpoint image to force containerd to pull a malicious image and assign it an arbitrary local tag, thereby poisoning the node's local image cache. Subsequently, if other pods on the same node attempt to use the poisoned tag with an IfNotPresent (or Never) pull policy, they will unknow</description>
    </item>
    <item>
      <title>Linuxfoundation Containerd — CVE-2026-53492 (Critical)</title>
      <link>https://www.patchbrief.org/items/2026-07-linuxfoundation-cve-2026-53492.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-linuxfoundation-cve-2026-53492.html</guid>
      <pubDate>Wed, 01 Jul 2026 00:00:00 +0000</pubDate>
      <description>containerd is an open-source container runtime. In Versions prior to 2.3.2, 2.2.5 and 2.1.9, the CRI implementation improperly trusts Container Device Interface (CDI) annotations found within untrusted checkpoint image metadata during container restoration. When restoring a container from a checkpoint, containerd preserves CDI-related annotations from the checkpoint archive rather than relying solely on the pod's create-time specification. This allows a user with pod creation permissions to bypass standard Kubernetes resource allocation and device plugin enforcement, injecting arbitrary CDI ed</description>
    </item>
    <item>
      <title>OnGres SCRAM silent channel-binding authentication downgrade via unsupported certificate algorithms</title>
      <link>https://www.patchbrief.org/items/2026-07-maven-cve-2026-53712.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-maven-cve-2026-53712.html</guid>
      <pubDate>Wed, 01 Jul 2026 00:00:00 +0000</pubDate>
      <description>OnGres SCRAM silent channel-binding authentication downgrade via unsupported certificate algorithms</description>
    </item>
    <item>
      <title>Keycloak has privilege escalation via improper scope mapping enforcement</title>
      <link>https://www.patchbrief.org/items/2026-07-maven-cve-2026-9795.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-maven-cve-2026-9795.html</guid>
      <pubDate>Wed, 01 Jul 2026 00:00:00 +0000</pubDate>
      <description>Keycloak has privilege escalation via improper scope mapping enforcement</description>
    </item>
    <item>
      <title>Microsoft SharePoint Server Deserialization of Untrusted Data Vulnerability</title>
      <link>https://www.patchbrief.org/items/2026-07-microsoft-cve-2026-45659.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-microsoft-cve-2026-45659.html</guid>
      <pubDate>Wed, 01 Jul 2026 00:00:00 +0000</pubDate>
      <description>Microsoft SharePoint Server contains a deserialization of untrusted data vulnerability which allows an authorized attacker to execute code over a network.</description>
    </item>
    <item>
      <title>sigstore's `certificateOIDs` verification constraints are silently dropped and never enforced</title>
      <link>https://www.patchbrief.org/items/2026-07-npm-cve-2026-48815.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-npm-cve-2026-48815.html</guid>
      <pubDate>Wed, 01 Jul 2026 00:00:00 +0000</pubDate>
      <description>sigstore's `certificateOIDs` verification constraints are silently dropped and never enforced</description>
    </item>
    <item>
      <title>auth-fetch-mcp has SSRF Protection Bypass via IPv4-mapped IPv6 Loopback</title>
      <link>https://www.patchbrief.org/items/2026-07-npm-cve-2026-49857.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-npm-cve-2026-49857.html</guid>
      <pubDate>Wed, 01 Jul 2026 00:00:00 +0000</pubDate>
      <description>auth-fetch-mcp has SSRF Protection Bypass via IPv4-mapped IPv6 Loopback</description>
    </item>
    <item>
      <title>wetty vulnerable to DOM XSS via file-download filename</title>
      <link>https://www.patchbrief.org/items/2026-07-npm-cve-2026-49864.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-npm-cve-2026-49864.html</guid>
      <pubDate>Wed, 01 Jul 2026 00:00:00 +0000</pubDate>
      <description>wetty vulnerable to DOM XSS via file-download filename</description>
    </item>
    <item>
      <title>repomix Vulnerable to Command Injection (RCE) via `--remote-branch` Argument Injection</title>
      <link>https://www.patchbrief.org/items/2026-07-npm-cve-2026-49987.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-npm-cve-2026-49987.html</guid>
      <pubDate>Wed, 01 Jul 2026 00:00:00 +0000</pubDate>
      <description>repomix Vulnerable to Command Injection (RCE) via `--remote-branch` Argument Injection</description>
    </item>
    <item>
      <title>Apify Model Context Protocol (MCP) server: Actor MCP path authority injection leaks Apify token</title>
      <link>https://www.patchbrief.org/items/2026-07-npm-cve-2026-50143.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-npm-cve-2026-50143.html</guid>
      <pubDate>Wed, 01 Jul 2026 00:00:00 +0000</pubDate>
      <description>Apify Model Context Protocol (MCP) server: Actor MCP path authority injection leaks Apify token</description>
    </item>
    <item>
      <title>Ghost: Cache-poisoning XSS in Ghost frontend via x-ghost-preview header</title>
      <link>https://www.patchbrief.org/items/2026-07-npm-cve-2026-53943.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-npm-cve-2026-53943.html</guid>
      <pubDate>Wed, 01 Jul 2026 00:00:00 +0000</pubDate>
      <description>Ghost: Cache-poisoning XSS in Ghost frontend via x-ghost-preview header</description>
    </item>
    <item>
      <title>Cortex has Untrusted Project Bootstrap Code Execution via `CLAUDE_PROJECT_DIR`</title>
      <link>https://www.patchbrief.org/items/2026-07-pypi-cve-2026-49986.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-pypi-cve-2026-49986.html</guid>
      <pubDate>Wed, 01 Jul 2026 00:00:00 +0000</pubDate>
      <description>Cortex has Untrusted Project Bootstrap Code Execution via `CLAUDE_PROJECT_DIR`</description>
    </item>
    <item>
      <title>pay-rails/pay: non-constant-time HMAC comparison in Paddle Billing webhook signature verifier</title>
      <link>https://www.patchbrief.org/items/2026-07-rubygems-ghsa-mjgf-xj26-9qf9.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-rubygems-ghsa-mjgf-xj26-9qf9.html</guid>
      <pubDate>Wed, 01 Jul 2026 00:00:00 +0000</pubDate>
      <description>pay-rails/pay: non-constant-time HMAC comparison in Paddle Billing webhook signature verifier</description>
    </item>
    <item>
      <title>SurrealDB: HTTP RPC Session Race Condition Allows Privilege Escalation</title>
      <link>https://www.patchbrief.org/items/2026-07-rust-ghsa-4vgr-h27g-cf9p.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-rust-ghsa-4vgr-h27g-cf9p.html</guid>
      <pubDate>Wed, 01 Jul 2026 00:00:00 +0000</pubDate>
      <description>SurrealDB: HTTP RPC Session Race Condition Allows Privilege Escalation</description>
    </item>
    <item>
      <title>SurrealDB: HTTP /rpc `sessions` method leaks attached session UUIDs, enabling full session hijack by anonymous callers</title>
      <link>https://www.patchbrief.org/items/2026-07-rust-ghsa-5qfp-32cf-69jh.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-rust-ghsa-5qfp-32cf-69jh.html</guid>
      <pubDate>Wed, 01 Jul 2026 00:00:00 +0000</pubDate>
      <description>SurrealDB: HTTP /rpc `sessions` method leaks attached session UUIDs, enabling full session hijack by anonymous callers</description>
    </item>
    <item>
      <title>SurrealDB has Denial of Service in JSON parser due to nested objects</title>
      <link>https://www.patchbrief.org/items/2026-07-rust-ghsa-q729-696q-g9pq.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-rust-ghsa-q729-696q-g9pq.html</guid>
      <pubDate>Wed, 01 Jul 2026 00:00:00 +0000</pubDate>
      <description>SurrealDB has Denial of Service in JSON parser due to nested objects</description>
    </item>
    <item>
      <title>SurrealDB has unauthenticated remote DoS via malformed RPC `use` call</title>
      <link>https://www.patchbrief.org/items/2026-07-rust-ghsa-wjjj-24cx-f28g.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-rust-ghsa-wjjj-24cx-f28g.html</guid>
      <pubDate>Wed, 01 Jul 2026 00:00:00 +0000</pubDate>
      <description>SurrealDB has unauthenticated remote DoS via malformed RPC `use` call</description>
    </item>
    <item>
      <title>Shenzhen Aitemi M300 Wi-Fi Repeater (hardware model MT02) — CVE-2026-58457 (Critical)</title>
      <link>https://www.patchbrief.org/items/2026-07-shenzhen-cve-2026-58457.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-07-shenzhen-cve-2026-58457.html</guid>
      <pubDate>Wed, 01 Jul 2026 00:00:00 +0000</pubDate>
      <description>Shenzhen Aitemi M300 Wi-Fi Repeater (hardware model MT02) contains an unauthenticated OS command injection vulnerability that allows network-adjacent attackers to execute arbitrary shell commands by injecting unsanitized input through the smacfilter_conf handler in the commuos web backend. Attackers can append semicolon-delimited payloads to the name, enable, or mac GET parameters, which are passed without sanitization into sprintf() to build uci shell commands executed via doSystemCmdComlib(), granting full root-level control of the device.</description>
    </item>
    <item>
      <title>Adobe Campaign Classic (ACC) — CVE-2026-48286 (Critical)</title>
      <link>https://www.patchbrief.org/items/2026-06-adobe-cve-2026-48286.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-06-adobe-cve-2026-48286.html</guid>
      <pubDate>Tue, 30 Jun 2026 00:00:00 +0000</pubDate>
      <description>Adobe Campaign Classic (ACC) versions 7.4.3 build 9396 and earlier are affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue does not require user interaction. Scope is changed.</description>
    </item>
    <item>
      <title>Citrix Netscaler Application Delivery Controller — CVE-2026-8452 (Critical)</title>
      <link>https://www.patchbrief.org/items/2026-06-citrix-cve-2026-8452.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-06-citrix-cve-2026-8452.html</guid>
      <pubDate>Tue, 30 Jun 2026 00:00:00 +0000</pubDate>
      <description>Memory overflow vulnerability NetScaler ADC and NetScaler Gateway leading to unpredictable or erroneous behavior and Denial of Service if the appliance is configured as a Gateway (SSL VPN, ICA Proxy, CVPN, RDP Proxy) or AAA virtual server</description>
    </item>
    <item>
      <title>Citrix Netscaler Application Delivery Controller — CVE-2026-8655 (Critical)</title>
      <link>https://www.patchbrief.org/items/2026-06-citrix-cve-2026-8655.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-06-citrix-cve-2026-8655.html</guid>
      <pubDate>Tue, 30 Jun 2026 00:00:00 +0000</pubDate>
      <description>Multiple Memory overflow vulnerabilities in NetScaler ADC and NetScaler Gateway leading to unpredictable or erroneous behavior and Denial of Service if NetScaler ADC is configured as an LB of type Oracle OR NetScaler ADC is configured as a DNS Proxy OR NetScaler ADC is configured as a DNS recursive resolver deployment</description>
    </item>
    <item>
      <title>Paymenter has URL parameter injection that bypasses paid plan limits at checkout</title>
      <link>https://www.patchbrief.org/items/2026-06-composer-cve-2026-47198.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-06-composer-cve-2026-47198.html</guid>
      <pubDate>Tue, 30 Jun 2026 00:00:00 +0000</pubDate>
      <description>Paymenter has URL parameter injection that bypasses paid plan limits at checkout</description>
    </item>
    <item>
      <title>Gnome Glib — CVE-2026-58016 (Critical)</title>
      <link>https://www.patchbrief.org/items/2026-06-gnome-cve-2026-58016.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-06-gnome-cve-2026-58016.html</guid>
      <pubDate>Tue, 30 Jun 2026 00:00:00 +0000</pubDate>
      <description>A flaw was found in GLib. A state confusion issue exists in g_dbus_node_info_new_for_xml() in the gio/gdbusintrospection.c file when processing malformed D-Bus introspection XML, specifically with a &lt;node&gt; element nested within other elements like &lt;method&gt;, &lt;signal&gt;, &lt;property&gt; or &lt;arg&gt;. This issue can cause an unsigned integer overflow and lead to an out-of-bounds read, resulting in a denial of service.</description>
    </item>
    <item>
      <title>Fulcio has OIDC Discovery Redirect Following Allows SSRF and JWKS Substitution for Meta-Issuer Paths, with Kubernetes...</title>
      <link>https://www.patchbrief.org/items/2026-06-go-cve-2026-49478.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-06-go-cve-2026-49478.html</guid>
      <pubDate>Tue, 30 Jun 2026 00:00:00 +0000</pubDate>
      <description>Fulcio has OIDC Discovery Redirect Following Allows SSRF and JWKS Substitution for Meta-Issuer Paths, with Kubernetes Service-Account Token Leakage</description>
    </item>
    <item>
      <title>Fission: Cross-namespace Environment reference in Package allows build-time command execution and SA token exfiltration</title>
      <link>https://www.patchbrief.org/items/2026-06-go-cve-2026-49821.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-06-go-cve-2026-49821.html</guid>
      <pubDate>Tue, 30 Jun 2026 00:00:00 +0000</pubDate>
      <description>Fission: Cross-namespace Environment reference in Package allows build-time command execution and SA token exfiltration</description>
    </item>
    <item>
      <title>Fission: Cross-namespace event leakage via KubernetesWatchTrigger allows persistent tenant surveillance</title>
      <link>https://www.patchbrief.org/items/2026-06-go-cve-2026-49822.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-06-go-cve-2026-49822.html</guid>
      <pubDate>Tue, 30 Jun 2026 00:00:00 +0000</pubDate>
      <description>Fission: Cross-namespace event leakage via KubernetesWatchTrigger allows persistent tenant surveillance</description>
    </item>
    <item>
      <title>Fission: Cross-namespace Package read via unvalidated PackageRef in Function admission webhook</title>
      <link>https://www.patchbrief.org/items/2026-06-go-cve-2026-49823.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-06-go-cve-2026-49823.html</guid>
      <pubDate>Tue, 30 Jun 2026 00:00:00 +0000</pubDate>
      <description>Fission: Cross-namespace Package read via unvalidated PackageRef in Function admission webhook</description>
    </item>
    <item>
      <title>Fission: Cross-namespace Environment reference via unvalidated EnvironmentRef in Function admission webhook</title>
      <link>https://www.patchbrief.org/items/2026-06-go-cve-2026-49824.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-06-go-cve-2026-49824.html</guid>
      <pubDate>Tue, 30 Jun 2026 00:00:00 +0000</pubDate>
      <description>Fission: Cross-namespace Environment reference via unvalidated EnvironmentRef in Function admission webhook</description>
    </item>
    <item>
      <title>Fission Environment CRD PodSpec Injection Leading to Node Escape and Cluster Takeover</title>
      <link>https://www.patchbrief.org/items/2026-06-go-cve-2026-50545.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-06-go-cve-2026-50545.html</guid>
      <pubDate>Tue, 30 Jun 2026 00:00:00 +0000</pubDate>
      <description>Fission Environment CRD PodSpec Injection Leading to Node Escape and Cluster Takeover</description>
    </item>
    <item>
      <title>Fission Container Executor Function PodSpec Injection Leading to Node Escape</title>
      <link>https://www.patchbrief.org/items/2026-06-go-cve-2026-50563.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-06-go-cve-2026-50563.html</guid>
      <pubDate>Tue, 30 Jun 2026 00:00:00 +0000</pubDate>
      <description>Fission Container Executor Function PodSpec Injection Leading to Node Escape</description>
    </item>
    <item>
      <title>Fission Environment CRD podspec passthrough enables hostPID/hostNetwork/privileged pods, node escape</title>
      <link>https://www.patchbrief.org/items/2026-06-go-cve-2026-50564.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-06-go-cve-2026-50564.html</guid>
      <pubDate>Tue, 30 Jun 2026 00:00:00 +0000</pubDate>
      <description>Fission Environment CRD podspec passthrough enables hostPID/hostNetwork/privileged pods, node escape</description>
    </item>
    <item>
      <title>Fission: Environment Runtime.Container and Builder.Container SecurityContext bypass allows privileged pod creation</title>
      <link>https://www.patchbrief.org/items/2026-06-go-cve-2026-50566.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-06-go-cve-2026-50566.html</guid>
      <pubDate>Tue, 30 Jun 2026 00:00:00 +0000</pubDate>
      <description>Fission: Environment Runtime.Container and Builder.Container SecurityContext bypass allows privileged pod creation</description>
    </item>
    <item>
      <title>Kahi has privilege-drop and socket/log permission issues</title>
      <link>https://www.patchbrief.org/items/2026-06-go-ghsa-55f6-4pr5-c7m5.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-06-go-ghsa-55f6-4pr5-c7m5.html</guid>
      <pubDate>Tue, 30 Jun 2026 00:00:00 +0000</pubDate>
      <description>Kahi has privilege-drop and socket/log permission issues</description>
    </item>
    <item>
      <title>Fission: MessageQueueTrigger scaler manager materializes Secret values into Deployment envvars and accepts arbitrary ...</title>
      <link>https://www.patchbrief.org/items/2026-06-go-ghsa-7m8x-qg2j-4m3v.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-06-go-ghsa-7m8x-qg2j-4m3v.html</guid>
      <pubDate>Tue, 30 Jun 2026 00:00:00 +0000</pubDate>
      <description>Fission: MessageQueueTrigger scaler manager materializes Secret values into Deployment envvars and accepts arbitrary user PodSpec</description>
    </item>
    <item>
      <title>Google Chrome — CVE-2026-13775 (Critical)</title>
      <link>https://www.patchbrief.org/items/2026-06-google-cve-2026-13775.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-06-google-cve-2026-13775.html</guid>
      <pubDate>Tue, 30 Jun 2026 00:00:00 +0000</pubDate>
      <description>Use after free in GPU in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)</description>
    </item>
    <item>
      <title>Google Chrome — CVE-2026-13776 (Critical)</title>
      <link>https://www.patchbrief.org/items/2026-06-google-cve-2026-13776.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-06-google-cve-2026-13776.html</guid>
      <pubDate>Tue, 30 Jun 2026 00:00:00 +0000</pubDate>
      <description>Type Confusion in Dawn in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)</description>
    </item>
    <item>
      <title>Google Chrome — CVE-2026-13780 (Critical)</title>
      <link>https://www.patchbrief.org/items/2026-06-google-cve-2026-13780.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-06-google-cve-2026-13780.html</guid>
      <pubDate>Tue, 30 Jun 2026 00:00:00 +0000</pubDate>
      <description>Insufficient validation of untrusted input in ANGLE in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)</description>
    </item>
    <item>
      <title>Google Chrome — CVE-2026-13781 (Critical)</title>
      <link>https://www.patchbrief.org/items/2026-06-google-cve-2026-13781.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-06-google-cve-2026-13781.html</guid>
      <pubDate>Tue, 30 Jun 2026 00:00:00 +0000</pubDate>
      <description>Insufficient validation of untrusted input in Skia in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)</description>
    </item>
    <item>
      <title>Google Chrome — CVE-2026-13782 (Critical)</title>
      <link>https://www.patchbrief.org/items/2026-06-google-cve-2026-13782.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-06-google-cve-2026-13782.html</guid>
      <pubDate>Tue, 30 Jun 2026 00:00:00 +0000</pubDate>
      <description>Use after free in Browser in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)</description>
    </item>
    <item>
      <title>Google Chrome — CVE-2026-13785 (Critical)</title>
      <link>https://www.patchbrief.org/items/2026-06-google-cve-2026-13785.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-06-google-cve-2026-13785.html</guid>
      <pubDate>Tue, 30 Jun 2026 00:00:00 +0000</pubDate>
      <description>Use after free in Bluetooth in Google Chrome on Mac prior to 150.0.7871.47 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)</description>
    </item>
    <item>
      <title>Google Chrome — CVE-2026-14101 (Critical)</title>
      <link>https://www.patchbrief.org/items/2026-06-google-cve-2026-14101.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-06-google-cve-2026-14101.html</guid>
      <pubDate>Tue, 30 Jun 2026 00:00:00 +0000</pubDate>
      <description>Insufficient policy enforcement in Sandbox in Google Chrome on Mac prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Low)</description>
    </item>
    <item>
      <title>Google Chrome — CVE-2026-14104 (Critical)</title>
      <link>https://www.patchbrief.org/items/2026-06-google-cve-2026-14104.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-06-google-cve-2026-14104.html</guid>
      <pubDate>Tue, 30 Jun 2026 00:00:00 +0000</pubDate>
      <description>Insufficient validation of untrusted input in WebAppInstalls in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Low)</description>
    </item>
    <item>
      <title>Grav CMS — CVE-2026-56700 (Critical)</title>
      <link>https://www.patchbrief.org/items/2026-06-grav-cve-2026-56700.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-06-grav-cve-2026-56700.html</guid>
      <pubDate>Tue, 30 Jun 2026 00:00:00 +0000</pubDate>
      <description>Grav CMS before 2.0.0-beta.2 contains multiple code-execution vulnerabilities. Three unsafe unserialize() calls - in Scheduler\JobQueue, Framework\Cache\Adapter\FileCache, and Session - deserialize untrusted data without restricting allowed classes, enabling PHP object injection and, via a gadget chain, arbitrary code execution where an attacker controls the serialized input. Additionally, InstallCommand's git clone operation passes the branch, url, and path parameters into a shell command without escaping, allowing OS command injection via plugin/theme installation (which requires admin acces</description>
    </item>
    <item>
      <title>IBM Langflow OSS 1.0.0 — CVE-2026-10140 (Critical)</title>
      <link>https://www.patchbrief.org/items/2026-06-ibm-cve-2026-10140.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-06-ibm-cve-2026-10140.html</guid>
      <pubDate>Tue, 30 Jun 2026 00:00:00 +0000</pubDate>
      <description>IBM Langflow OSS 1.0.0 through 1.10.0 voice mode contains improper shared-state handling that allows reuse of API clients across tenant boundaries. An authenticated attacker can manipulate cache state to cause requests from other users to be processed using incorrect upstream API credentials, leading to cross-tenant billing and accountability misattribution.</description>
    </item>
    <item>
      <title>Ibm Websphere Application Server — CVE-2026-11541 (Critical)</title>
      <link>https://www.patchbrief.org/items/2026-06-ibm-cve-2026-11541.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-06-ibm-cve-2026-11541.html</guid>
      <pubDate>Tue, 30 Jun 2026 00:00:00 +0000</pubDate>
      <description>IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.6 are affected by an HTTP request smuggling vulnerability.</description>
    </item>
    <item>
      <title>Ibm Websphere Application Server — CVE-2026-11546 (Critical)</title>
      <link>https://www.patchbrief.org/items/2026-06-ibm-cve-2026-11546.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-06-ibm-cve-2026-11546.html</guid>
      <pubDate>Tue, 30 Jun 2026 00:00:00 +0000</pubDate>
      <description>IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.7 is affected by a server-side request forgery vulnerability with the adminCenter-1.0 feature enabled.</description>
    </item>
    <item>
      <title>Ibm Websphere Application Server — CVE-2026-11714 (Critical)</title>
      <link>https://www.patchbrief.org/items/2026-06-ibm-cve-2026-11714.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-06-ibm-cve-2026-11714.html</guid>
      <pubDate>Tue, 30 Jun 2026 00:00:00 +0000</pubDate>
      <description>IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.7 is affected by a server-side request forgery vulnerability with the apiDiscovery-1.0 feature enabled.</description>
    </item>
    <item>
      <title>Ibm Business Automation Manager — CVE-2026-13449 (Critical)</title>
      <link>https://www.patchbrief.org/items/2026-06-ibm-cve-2026-13449.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-06-ibm-cve-2026-13449.html</guid>
      <pubDate>Tue, 30 Jun 2026 00:00:00 +0000</pubDate>
      <description>IBM Business Automation Manager Open Editions 9.0.0 through 9.4.2 is vulnerable to an XML external entity injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources.</description>
    </item>
    <item>
      <title>Ibm Websphere Extreme Scale — CVE-2026-13772 (Critical)</title>
      <link>https://www.patchbrief.org/items/2026-06-ibm-cve-2026-13772.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-06-ibm-cve-2026-13772.html</guid>
      <pubDate>Tue, 30 Jun 2026 00:00:00 +0000</pubDate>
      <description>IBM WebSphere Extreme Scale 8.6.1.0 through 8.6.1.6 's Object Query Language engine resolves attacker-supplied class names via Class.forName() and invokes their constructors with no allow-list at three distinct sinks (SELECT NEW, enum literals, and reflection-based comparators); an authenticated remote attacker who can influence an application-built OQL query string can execute arbitrary constructors on the WAS JVM, and a SELECT DISTINCT variant using planted grid values fires the same gadget post-readObject in a manner that survives JEP-290 serialization filters across grid node boundaries</description>
    </item>
    <item>
      <title>Ibm Websphere Extreme Scale — CVE-2026-13773 (Critical)</title>
      <link>https://www.patchbrief.org/items/2026-06-ibm-cve-2026-13773.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-06-ibm-cve-2026-13773.html</guid>
      <pubDate>Tue, 30 Jun 2026 00:00:00 +0000</pubDate>
      <description>IBM WebSphere Extreme Scale 8.6.1.0 through 8.6.1.6 Approximately 50 generated CORBA stub classes in WebSphere eXtreme Scale's ogclient.jar call ORB.string_to_object() on an attacker-controlled IOR string during Java deserialization, turning any unfiltered ObjectInputStream sink in WAS into outbound IIOP SSRF to an attacker-chosen host; when chained with the IBM ORB's getUserException class-instantiation flaw (WAS-26), this SSRF escalates to remote code execution on the calling JVM.</description>
    </item>
    <item>
      <title>Langflow Langflow — CVE-2026-10560 (Critical)</title>
      <link>https://www.patchbrief.org/items/2026-06-langflow-cve-2026-10560.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-06-langflow-cve-2026-10560.html</guid>
      <pubDate>Tue, 30 Jun 2026 00:00:00 +0000</pubDate>
      <description>IBM Langflow OSS 1.0.0 through 1.9.6 contains a missing authentication vulnerability in /api/v1/build_public_tmp/ endpoints that allows an unauthenticated attacker to read build event data or cancel jobs using a valid job identifier, resulting in information disclosure and denial of service.</description>
    </item>
    <item>
      <title>Langflow Langflow — CVE-2026-7663 (Critical)</title>
      <link>https://www.patchbrief.org/items/2026-06-langflow-cve-2026-7663.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-06-langflow-cve-2026-7663.html</guid>
      <pubDate>Tue, 30 Jun 2026 00:00:00 +0000</pubDate>
      <description>IBM Langflow OSS 1.0.0 through 1.9.6 could allow unauthenticated attackers to access protected MCP project resources and execute MCP operations due to improper authorization enforcement in the Streamable MCP transport endpoint.</description>
    </item>
    <item>
      <title>Mozilla Firefox — CVE-2026-14241 (Critical)</title>
      <link>https://www.patchbrief.org/items/2026-06-mozilla-cve-2026-14241.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-06-mozilla-cve-2026-14241.html</guid>
      <pubDate>Tue, 30 Jun 2026 00:00:00 +0000</pubDate>
      <description>Memory safety bugs present in Firefox 152.0.3. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 152.0.4.</description>
    </item>
    <item>
      <title>@adonisjs/bodyparser has an incomplete fix for CVE-2026-25754</title>
      <link>https://www.patchbrief.org/items/2026-06-npm-cve-2026-48795.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-06-npm-cve-2026-48795.html</guid>
      <pubDate>Tue, 30 Jun 2026 00:00:00 +0000</pubDate>
      <description>@adonisjs/bodyparser has an incomplete fix for CVE-2026-25754</description>
    </item>
    <item>
      <title>@cedar-policy/authorization-for-expressjs has an authorization bypass via query string manipulation</title>
      <link>https://www.patchbrief.org/items/2026-06-npm-cve-2026-49473.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-06-npm-cve-2026-49473.html</guid>
      <pubDate>Tue, 30 Jun 2026 00:00:00 +0000</pubDate>
      <description>@cedar-policy/authorization-for-expressjs has an authorization bypass via query string manipulation</description>
    </item>
    <item>
      <title>Microsoft.OpenAPI: Circular schema references may terminate OpenAPI parsing</title>
      <link>https://www.patchbrief.org/items/2026-06-nuget-cve-2026-49451.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-06-nuget-cve-2026-49451.html</guid>
      <pubDate>Tue, 30 Jun 2026 00:00:00 +0000</pubDate>
      <description>Microsoft.OpenAPI: Circular schema references may terminate OpenAPI parsing</description>
    </item>
    <item>
      <title>Orkes Conductor 3.21.21 — CVE-2026-58138 (Critical)</title>
      <link>https://www.patchbrief.org/items/2026-06-orkes-cve-2026-58138.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-06-orkes-cve-2026-58138.html</guid>
      <pubDate>Tue, 30 Jun 2026 00:00:00 +0000</pubDate>
      <description>Orkes Conductor 3.21.21 before 3.30.2 contains an unauthenticated remote code execution vulnerability that allows remote attackers to execute arbitrary OS commands by submitting inline workflow definitions containing malicious JavaScript or Python expressions to the workflow API endpoint prior to authentication. Attackers can exploit unsandboxed GraalVM evaluators configured with HostAccess.ALL or allowAllAccess(true) through INLINE, LAMBDA, DO_WHILE, and SWITCH task types to invoke arbitrary system commands via Java reflection or direct subprocess calls.</description>
    </item>
    <item>
      <title>Open Babel has heap buffer overflow in SMILES OBSmilesParser::ParseSmiles</title>
      <link>https://www.patchbrief.org/items/2026-06-pypi-cve-2025-10996.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-06-pypi-cve-2025-10996.html</guid>
      <pubDate>Tue, 30 Jun 2026 00:00:00 +0000</pubDate>
      <description>Open Babel has heap buffer overflow in SMILES OBSmilesParser::ParseSmiles</description>
    </item>
    <item>
      <title>Dgraph Vulnerable to DQL Injection via checkUserPassword GraphQL Query</title>
      <link>https://www.patchbrief.org/items/2026-06-go-cve-2026-44840.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-06-go-cve-2026-44840.html</guid>
      <pubDate>Mon, 29 Jun 2026 00:00:00 +0000</pubDate>
      <description>Dgraph Vulnerable to DQL Injection via checkUserPassword GraphQL Query</description>
    </item>
    <item>
      <title>Google Mcp Toolbox For Databases — CVE-2026-11720 (Critical)</title>
      <link>https://www.patchbrief.org/items/2026-06-google-cve-2026-11720.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-06-google-cve-2026-11720.html</guid>
      <pubDate>Mon, 29 Jun 2026 00:00:00 +0000</pubDate>
      <description>A path traversal vulnerability exists in the HTTP tool URL builder of googleapis/mcp-toolbox. When constructing downstream API requests, the URL builder substitutes user-controlled pathParams into the configured tool path and parses the resulting string as a relative URL. While it checks that the input does not alter the scheme, host, or user info, it relies on ResolveReference for the final URL resolution. Because dot segments (../) are normalized during this resolution step, an attacker can supply path parameters containing directory traversal sequences to escape the operator-configured pat</description>
    </item>
    <item>
      <title>OpenAM Authenticated RCE via Groovy Sandbox Escape</title>
      <link>https://www.patchbrief.org/items/2026-06-maven-cve-2026-47424.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-06-maven-cve-2026-47424.html</guid>
      <pubDate>Mon, 29 Jun 2026 00:00:00 +0000</pubDate>
      <description>OpenAM Authenticated RCE via Groovy Sandbox Escape</description>
    </item>
    <item>
      <title>OpenAM OAuth Client Impersonation via JWKS Resolver Cache</title>
      <link>https://www.patchbrief.org/items/2026-06-maven-cve-2026-47426.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-06-maven-cve-2026-47426.html</guid>
      <pubDate>Mon, 29 Jun 2026 00:00:00 +0000</pubDate>
      <description>OpenAM OAuth Client Impersonation via JWKS Resolver Cache</description>
    </item>
    <item>
      <title>SimpleHelp Authentication Bypass Vulnerability</title>
      <link>https://www.patchbrief.org/items/2026-06-simplehelp-cve-2026-48558.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-06-simplehelp-cve-2026-48558.html</guid>
      <pubDate>Mon, 29 Jun 2026 00:00:00 +0000</pubDate>
      <description>SimpleHelp contains an authentication bypass vulnerability in the OIDC authentication flow. When OIDC authentication is configured, identity tokens submitted during login are accepted without verifying their cryptographic signature. In a vulnerable configuration, a remote, unauthenticated attacker can submit a forged token containing arbitrary identity claims to obtain a fully authenticated technician session. In some configurations, this may also allow bypass of multi-factor authentication.</description>
    </item>
    <item>
      <title>Snowflake Snowflake Cli — CVE-2026-13751 (Critical)</title>
      <link>https://www.patchbrief.org/items/2026-06-snowflake-cve-2026-13751.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-06-snowflake-cve-2026-13751.html</guid>
      <pubDate>Mon, 29 Jun 2026 00:00:00 +0000</pubDate>
      <description>Improper handling of untrusted remote references in Snowflake CLI versions prior to 3.19 allowed server-side request forgery. The SQL statement reader's !source/!load directives could reference remote URLs that were retrieved at runtime without sufficient restriction on the request destination. By supplying crafted SQL content processed through a vulnerable command path, an attacker could cause the victim's environment to issue unintended outbound requests to internal or otherwise non-public network locations, and could cause remote SQL content to be retrieved and executed in the context of th</description>
    </item>
    <item>
      <title>pnpm: `patch-remove` could delete project-selected files outside the patches directory</title>
      <link>https://www.patchbrief.org/items/2026-06-npm-ghsa-72r4-9c5j-mj57.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-06-npm-ghsa-72r4-9c5j-mj57.html</guid>
      <pubDate>Sat, 27 Jun 2026 00:00:00 +0000</pubDate>
      <description>pnpm: `patch-remove` could delete project-selected files outside the patches directory</description>
    </item>
    <item>
      <title>pnpm: Hoisted install imports lockfile alias outside node_modules</title>
      <link>https://www.patchbrief.org/items/2026-06-npm-ghsa-fr4h-3cph-29xv.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-06-npm-ghsa-fr4h-3cph-29xv.html</guid>
      <pubDate>Sat, 27 Jun 2026 00:00:00 +0000</pubDate>
      <description>pnpm: Hoisted install imports lockfile alias outside node_modules</description>
    </item>
    <item>
      <title>pnpm: Path traversal in configDependencies env lockfile allows symlink creation outside node_modules/.pnpm-config</title>
      <link>https://www.patchbrief.org/items/2026-06-npm-ghsa-qrv3-253h-g69c.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-06-npm-ghsa-qrv3-253h-g69c.html</guid>
      <pubDate>Sat, 27 Jun 2026 00:00:00 +0000</pubDate>
      <description>pnpm: Path traversal in configDependencies env lockfile allows symlink creation outside node_modules/.pnpm-config</description>
    </item>
    <item>
      <title>Dokku Dokku — CVE-2026-54636 (Critical)</title>
      <link>https://www.patchbrief.org/items/2026-06-dokku-cve-2026-54636.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-06-dokku-cve-2026-54636.html</guid>
      <pubDate>Fri, 26 Jun 2026 00:00:00 +0000</pubDate>
      <description>Dokku is a docker-powered PaaS. Prior to 0.38.7, the cron plugin utilizes commands in the app.json file to manage system cron running as the Dokku user. An app.json cron command utilizing special shell characters - including, but not limited to, &gt; or ; - can break out of the Docker container and execute commands on the host as the Dokku user. This vulnerability is fixed in 0.38.7.</description>
    </item>
    <item>
      <title>Relyra SAML SignatureValue not cryptographically verified -&gt; authentication bypass</title>
      <link>https://www.patchbrief.org/items/2026-06-erlang-cve-2026-49454.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-06-erlang-cve-2026-49454.html</guid>
      <pubDate>Fri, 26 Jun 2026 00:00:00 +0000</pubDate>
      <description>Relyra SAML SignatureValue not cryptographically verified -&gt; authentication bypass</description>
    </item>
    <item>
      <title>ex_aws_sns: Trusted-attacker `SigningCertURL` permits complete SNS signature bypass</title>
      <link>https://www.patchbrief.org/items/2026-06-erlang-ghsa-8jgf-23q5-x7xx.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-06-erlang-ghsa-8jgf-23q5-x7xx.html</guid>
      <pubDate>Fri, 26 Jun 2026 00:00:00 +0000</pubDate>
      <description>ex_aws_sns: Trusted-attacker `SigningCertURL` permits complete SNS signature bypass</description>
    </item>
    <item>
      <title>Incus has an arbitrary file read+write on host via rootfs/ symlink in malicious image</title>
      <link>https://www.patchbrief.org/items/2026-06-go-cve-2026-48749.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-06-go-cve-2026-48749.html</guid>
      <pubDate>Fri, 26 Jun 2026 00:00:00 +0000</pubDate>
      <description>Incus has an arbitrary file read+write on host via rootfs/ symlink in malicious image</description>
    </item>
    <item>
      <title>Incus has an arbitrary file write on host via `exec-output` symlink in crafted image</title>
      <link>https://www.patchbrief.org/items/2026-06-go-cve-2026-48750.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-06-go-cve-2026-48750.html</guid>
      <pubDate>Fri, 26 Jun 2026 00:00:00 +0000</pubDate>
      <description>Incus has an arbitrary file write on host via `exec-output` symlink in crafted image</description>
    </item>
    <item>
      <title>Incus has a restricted project bypass leading to arbitrary command execution</title>
      <link>https://www.patchbrief.org/items/2026-06-go-cve-2026-48751.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-06-go-cve-2026-48751.html</guid>
      <pubDate>Fri, 26 Jun 2026 00:00:00 +0000</pubDate>
      <description>Incus has a restricted project bypass leading to arbitrary command execution</description>
    </item>
    <item>
      <title>Incus has arbitrary file read+write on host via templates/ symlink in malicious image</title>
      <link>https://www.patchbrief.org/items/2026-06-go-cve-2026-48752.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-06-go-cve-2026-48752.html</guid>
      <pubDate>Fri, 26 Jun 2026 00:00:00 +0000</pubDate>
      <description>Incus has arbitrary file read+write on host via templates/ symlink in malicious image</description>
    </item>
    <item>
      <title>Incus has an arbitrary file write via path traversal in S3 multipart upload</title>
      <link>https://www.patchbrief.org/items/2026-06-go-cve-2026-48753.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-06-go-cve-2026-48753.html</guid>
      <pubDate>Fri, 26 Jun 2026 00:00:00 +0000</pubDate>
      <description>Incus has an arbitrary file write via path traversal in S3 multipart upload</description>
    </item>
    <item>
      <title>Incus has an argument injection in backup compression algorithm leading to AFW and ACE</title>
      <link>https://www.patchbrief.org/items/2026-06-go-cve-2026-48755.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-06-go-cve-2026-48755.html</guid>
      <pubDate>Fri, 26 Jun 2026 00:00:00 +0000</pubDate>
      <description>Incus has an argument injection in backup compression algorithm leading to AFW and ACE</description>
    </item>
    <item>
      <title>Incus has an arbitrary file write on its client due to trusted image hash</title>
      <link>https://www.patchbrief.org/items/2026-06-go-cve-2026-48769.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-06-go-cve-2026-48769.html</guid>
      <pubDate>Fri, 26 Jun 2026 00:00:00 +0000</pubDate>
      <description>Incus has an arbitrary file write on its client due to trusted image hash</description>
    </item>
    <item>
      <title>Subsonic API: any authenticated user can delete or read any other user's playlist (IDOR)</title>
      <link>https://www.patchbrief.org/items/2026-06-go-cve-2026-49338.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-06-go-cve-2026-49338.html</guid>
      <pubDate>Fri, 26 Jun 2026 00:00:00 +0000</pubDate>
      <description>Subsonic API: any authenticated user can delete or read any other user's playlist (IDOR)</description>
    </item>
    <item>
      <title>gonic: Path Traversal in playlist `id` bypasses ownership check, enabling any user to read/delete other users' playlists</title>
      <link>https://www.patchbrief.org/items/2026-06-go-cve-2026-49339.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-06-go-cve-2026-49339.html</guid>
      <pubDate>Fri, 26 Jun 2026 00:00:00 +0000</pubDate>
      <description>gonic: Path Traversal in playlist `id` bypasses ownership check, enabling any user to read/delete other users' playlists</description>
    </item>
    <item>
      <title>gonic has arbitrary file write in createPlaylist: any authenticated user can write playlist M3U content to attacker-c...</title>
      <link>https://www.patchbrief.org/items/2026-06-go-cve-2026-49340.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-06-go-cve-2026-49340.html</guid>
      <pubDate>Fri, 26 Jun 2026 00:00:00 +0000</pubDate>
      <description>gonic has arbitrary file write in createPlaylist: any authenticated user can write playlist M3U content to attacker-controlled path on the host</description>
    </item>
    <item>
      <title>Nezha Monitoring: Pre-auth path traversal via /dashboard.. prefix confusion leaks jwt_secret_key</title>
      <link>https://www.patchbrief.org/items/2026-06-go-cve-2026-53519.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-06-go-cve-2026-53519.html</guid>
      <pubDate>Fri, 26 Jun 2026 00:00:00 +0000</pubDate>
      <description>Nezha Monitoring: Pre-auth path traversal via /dashboard.. prefix confusion leaks jwt_secret_key</description>
    </item>
    <item>
      <title>Nezha vulnerable to cross-tenant terminal/file-manager session hijack via WebSocket stream UUID without ownership check</title>
      <link>https://www.patchbrief.org/items/2026-06-go-ghsa-q6xx-5vr8-p898.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-06-go-ghsa-q6xx-5vr8-p898.html</guid>
      <pubDate>Fri, 26 Jun 2026 00:00:00 +0000</pubDate>
      <description>Nezha vulnerable to cross-tenant terminal/file-manager session hijack via WebSocket stream UUID without ownership check</description>
    </item>
    <item>
      <title>Blnk has an API key authorization bypass in owner and scope enforcement</title>
      <link>https://www.patchbrief.org/items/2026-06-go-ghsa-wcr3-9x4c-f5gj.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-06-go-ghsa-wcr3-9x4c-f5gj.html</guid>
      <pubDate>Fri, 26 Jun 2026 00:00:00 +0000</pubDate>
      <description>Blnk has an API key authorization bypass in owner and scope enforcement</description>
    </item>
    <item>
      <title>Jetbrains Kotlin — CVE-2026-53914 (Critical)</title>
      <link>https://www.patchbrief.org/items/2026-06-jetbrains-cve-2026-53914.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-06-jetbrains-cve-2026-53914.html</guid>
      <pubDate>Fri, 26 Jun 2026 00:00:00 +0000</pubDate>
      <description>In JetBrains Kotlin before 2.4.20 code execution was possible via unsafe deserialization in the build cache metadata</description>
    </item>
    <item>
      <title>Jetbrains Youtrack — CVE-2026-57926 (Critical)</title>
      <link>https://www.patchbrief.org/items/2026-06-jetbrains-cve-2026-57926.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-06-jetbrains-cve-2026-57926.html</guid>
      <pubDate>Fri, 26 Jun 2026 00:00:00 +0000</pubDate>
      <description>In JetBrains YouTrack before 2026.2.16593 the websandbox bridge was vulnerable to a prototype pollution attack</description>
    </item>
    <item>
      <title>Nodejs Node.Js — CVE-2026-48930 (Critical)</title>
      <link>https://www.patchbrief.org/items/2026-06-nodejs-cve-2026-48930.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-06-nodejs-cve-2026-48930.html</guid>
      <pubDate>Fri, 26 Jun 2026 00:00:00 +0000</pubDate>
      <description>A flaw in Node.js TLS hostname handling can cause Embedded-nul hostnames can lead to silent authority rebinding due to c-string truncation in resolver bindings. This vulnerability affects all supported release lines: **Node.js 22**, **Node.js 24**, and **Node.js 26**.</description>
    </item>
    <item>
      <title>deepstream is vulnerable to prototype pollution</title>
      <link>https://www.patchbrief.org/items/2026-06-npm-cve-2026-49252.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-06-npm-cve-2026-49252.html</guid>
      <pubDate>Fri, 26 Jun 2026 00:00:00 +0000</pubDate>
      <description>deepstream is vulnerable to prototype pollution</description>
    </item>
    <item>
      <title>js-toml vulnerable to CPU exhaustion via O(n^2) BigInt construction on radix-prefixed integer literals</title>
      <link>https://www.patchbrief.org/items/2026-06-npm-cve-2026-49293.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-06-npm-cve-2026-49293.html</guid>
      <pubDate>Fri, 26 Jun 2026 00:00:00 +0000</pubDate>
      <description>js-toml vulnerable to CPU exhaustion via O(n^2) BigInt construction on radix-prefixed integer literals</description>
    </item>
    <item>
      <title>pnpm Vulnerable to Arbitrary File Write/Delete via Malicious Patch File (Path Traversal)</title>
      <link>https://www.patchbrief.org/items/2026-06-npm-cve-2026-50015.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-06-npm-cve-2026-50015.html</guid>
      <pubDate>Fri, 26 Jun 2026 00:00:00 +0000</pubDate>
      <description>pnpm Vulnerable to Arbitrary File Write/Delete via Malicious Patch File (Path Traversal)</description>
    </item>
    <item>
      <title>pnpm: Transitive dependency alias path traversal allows project path override via symlink replacement</title>
      <link>https://www.patchbrief.org/items/2026-06-npm-cve-2026-50016.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-06-npm-cve-2026-50016.html</guid>
      <pubDate>Fri, 26 Jun 2026 00:00:00 +0000</pubDate>
      <description>pnpm: Transitive dependency alias path traversal allows project path override via symlink replacement</description>
    </item>
    <item>
      <title>pnpm: Manifest identity spoof satisfies allowBuilds and runs attacker lifecycle</title>
      <link>https://www.patchbrief.org/items/2026-06-npm-cve-2026-55487.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-06-npm-cve-2026-55487.html</guid>
      <pubDate>Fri, 26 Jun 2026 00:00:00 +0000</pubDate>
      <description>pnpm: Manifest identity spoof satisfies allowBuilds and runs attacker lifecycle</description>
    </item>
    <item>
      <title>pnpm: Repository-controlled configDependencies can select a pacquet native install engine</title>
      <link>https://www.patchbrief.org/items/2026-06-npm-cve-2026-55697.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-06-npm-cve-2026-55697.html</guid>
      <pubDate>Fri, 26 Jun 2026 00:00:00 +0000</pubDate>
      <description>pnpm: Repository-controlled configDependencies can select a pacquet native install engine</description>
    </item>
    <item>
      <title>pnpm: Project env lockfile can short-circuit package-manager resolution and execute lockfile-selected pnpm bytes</title>
      <link>https://www.patchbrief.org/items/2026-06-npm-cve-2026-55698.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-06-npm-cve-2026-55698.html</guid>
      <pubDate>Fri, 26 Jun 2026 00:00:00 +0000</pubDate>
      <description>pnpm: Project env lockfile can short-circuit package-manager resolution and execute lockfile-selected pnpm bytes</description>
    </item>
    <item>
      <title>pnpm: `stage download` writes outside its destination directory via manifest name/version traversal</title>
      <link>https://www.patchbrief.org/items/2026-06-npm-cve-2026-55700.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-06-npm-cve-2026-55700.html</guid>
      <pubDate>Fri, 26 Jun 2026 00:00:00 +0000</pubDate>
      <description>pnpm: `stage download` writes outside its destination directory via manifest name/version traversal</description>
    </item>
    <item>
      <title>Backpropagate: backprop ui --auth and backprop ui --share do not enforce authentication</title>
      <link>https://www.patchbrief.org/items/2026-06-pypi-cve-2026-48797.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-06-pypi-cve-2026-48797.html</guid>
      <pubDate>Fri, 26 Jun 2026 00:00:00 +0000</pubDate>
      <description>Backpropagate: backprop ui --auth and backprop ui --share do not enforce authentication</description>
    </item>
    <item>
      <title>mcp-pinot: Unauthenticated tool invocation via default oauth_enabled=False + host 0.0.0.0 bind</title>
      <link>https://www.patchbrief.org/items/2026-06-pypi-cve-2026-49257.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-06-pypi-cve-2026-49257.html</guid>
      <pubDate>Fri, 26 Jun 2026 00:00:00 +0000</pubDate>
      <description>mcp-pinot: Unauthenticated tool invocation via default oauth_enabled=False + host 0.0.0.0 bind</description>
    </item>
    <item>
      <title>semantic-router exposed to compromised litellm wheel (CVE-2026-42208) via unbounded transitive pin</title>
      <link>https://www.patchbrief.org/items/2026-06-pypi-ghsa-98x5-vq43-vc5p.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-06-pypi-ghsa-98x5-vq43-vc5p.html</guid>
      <pubDate>Fri, 26 Jun 2026 00:00:00 +0000</pubDate>
      <description>semantic-router exposed to compromised litellm wheel (CVE-2026-42208) via unbounded transitive pin</description>
    </item>
    <item>
      <title>Fluentd is Vulnerable to Remote Code Execution (RCE) via Arbitrary File Write in `${tag}` Placeholder</title>
      <link>https://www.patchbrief.org/items/2026-06-rubygems-cve-2026-44024.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-06-rubygems-cve-2026-44024.html</guid>
      <pubDate>Fri, 26 Jun 2026 00:00:00 +0000</pubDate>
      <description>Fluentd is Vulnerable to Remote Code Execution (RCE) via Arbitrary File Write in `${tag}` Placeholder</description>
    </item>
    <item>
      <title>Wso2 Api Manager — CVE-2026-2053 (Critical)</title>
      <link>https://www.patchbrief.org/items/2026-06-wso2-cve-2026-2053.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-06-wso2-cve-2026-2053.html</guid>
      <pubDate>Fri, 26 Jun 2026 00:00:00 +0000</pubDate>
      <description>The WSO2 API Manager's message flow component, when processing WS-Addressing headers, does not sufficiently validate or restrict user-controlled input within these headers. This omission allows an attacker to manipulate WS-Addressing headers to specify arbitrary destinations for server-initiated requests. Successful exploitation allows an unauthenticated attacker to control the destination of server-initiated requests originating from the WSO2 API Manager. This direct control can enable unauthorized access to internal network resources or services that would typically be inaccessible from ext</description>
    </item>
    <item>
      <title>Anysphere Cursor — CVE-2026-50548 (Critical)</title>
      <link>https://www.patchbrief.org/items/2026-06-anysphere-cve-2026-50548.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-06-anysphere-cve-2026-50548.html</guid>
      <pubDate>Thu, 25 Jun 2026 00:00:00 +0000</pubDate>
      <description>Cursor is a code editor built for programming with AI. Prior to 3.0, Cursor runs agent terminal commands in a sandbox by default, and the sandbox grants write access to the command's working directory. A flaw was identified in how the agent could modify the working_directory parameter, which could cause the sandbox to include writable paths outside the intended workspace. A malicious agent could set working_directory to a sensitive location and write arbitrary files outside the workspace under the user's privileges. This enables non-sandboxed Remote Code Execution — for example by overwriting</description>
    </item>
    <item>
      <title>Anysphere Cursor — CVE-2026-50549 (Critical)</title>
      <link>https://www.patchbrief.org/items/2026-06-anysphere-cve-2026-50549.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-06-anysphere-cve-2026-50549.html</guid>
      <pubDate>Thu, 25 Jun 2026 00:00:00 +0000</pubDate>
      <description>Cursor is a code editor built for programming with AI. Prior to 3.0, Cursor runs agent terminal commands in a sandbox by default. Before a Write, the agent canonicalizes the target path to confirm it stays inside the workspace, but when canonicalization fails it falls back to the original path and writes without approval. A malicious agent can create an in-workspace symlink that points outside the workspace and force canonicalization to fail — either because the target does not exist or because read permission is removed from the path — so the agent writes through the symlink to an arbitrary l</description>
    </item>
    <item>
      <title>Cacti Cacti — CVE-2026-40079 (Critical)</title>
      <link>https://www.patchbrief.org/items/2026-06-cacti-cve-2026-40079.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-06-cacti-cve-2026-40079.html</guid>
      <pubDate>Thu, 25 Jun 2026 00:00:00 +0000</pubDate>
      <description>Cacti is an open source performance and fault management framework. Versions 1.2.30 and prior are vulnerable to Command Injection due to lack of sanitization in the escape_command() function. The escape_command() function at lib/rrd.php is a no-op: it returns $command unchanged. The command line built by rrdtool_function_graph() is passed through this function and then to shell_exec($full_commandline). The risk is in __rrd_execute() where text_format values from graph templates (which may contain host variable substitutions) reach shell_exec without adequate escaping. This issue has been addre</description>
    </item>
    <item>
      <title>Cisco Unified Communications Manager Server-Side Request Forgery (SSRF) Vulnerability</title>
      <link>https://www.patchbrief.org/items/2026-06-cisco-cve-2026-20230.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-06-cisco-cve-2026-20230.html</guid>
      <pubDate>Thu, 25 Jun 2026 00:00:00 +0000</pubDate>
      <description>Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communications Manager Session Management Edition (Unified CM SME) contain a server-side request forgery (SSRF) Vulnerability that could allow an unauthenticated, remote attacker to write files to the underlying operating system that could be used later to elevate to root.</description>
    </item>
    <item>
      <title>Filament: Multi-factor authentication (app) recovery codes can still be used multiple times via concurrent submission</title>
      <link>https://www.patchbrief.org/items/2026-06-composer-cve-2026-48505.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-06-composer-cve-2026-48505.html</guid>
      <pubDate>Thu, 25 Jun 2026 00:00:00 +0000</pubDate>
      <description>Filament: Multi-factor authentication (app) recovery codes can still be used multiple times via concurrent submission</description>
    </item>
    <item>
      <title>Dest Unreach Socat — CVE-2026-56123 (Critical)</title>
      <link>https://www.patchbrief.org/items/2026-06-dest-unreach-cve-2026-56123.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-06-dest-unreach-cve-2026-56123.html</guid>
      <pubDate>Thu, 25 Jun 2026 00:00:00 +0000</pubDate>
      <description>socat versions 1.8.0.0 through 1.8.1.1 contain a heap-based buffer overflow vulnerability that allows a malicious SOCKS5 proxy server to overwrite adjacent heap memory by exploiting a sign-extension flaw in the DOMAINNAME reply parser. During connection setup, the domain name length byte is read through a signed char field causing a negative bytes_to_read value that is implicitly converted to size_t, resulting in an unbounded heap write into the 262-byte reply buffer with attacker-controlled size and content.</description>
    </item>
    <item>
      <title>golang.org/x/crypto/ssh: Invoking pathological RSA/DSA parameters may cause DoS</title>
      <link>https://www.patchbrief.org/items/2026-06-go-cve-2026-39829.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-06-go-cve-2026-39829.html</guid>
      <pubDate>Thu, 25 Jun 2026 00:00:00 +0000</pubDate>
      <description>golang.org/x/crypto/ssh: Invoking pathological RSA/DSA parameters may cause DoS</description>
    </item>
    <item>
      <title>golang.org/x/crypto/ssh: Invoking client can cause server deadlock on unexpected responses</title>
      <link>https://www.patchbrief.org/items/2026-06-go-cve-2026-39830.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-06-go-cve-2026-39830.html</guid>
      <pubDate>Thu, 25 Jun 2026 00:00:00 +0000</pubDate>
      <description>golang.org/x/crypto/ssh: Invoking client can cause server deadlock on unexpected responses</description>
    </item>
    <item>
      <title>golang.org/x/crypto/ssh: FIDO/U2F security key physical presence check can be bypassed</title>
      <link>https://www.patchbrief.org/items/2026-06-go-cve-2026-39831.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-06-go-cve-2026-39831.html</guid>
      <pubDate>Thu, 25 Jun 2026 00:00:00 +0000</pubDate>
      <description>golang.org/x/crypto/ssh: FIDO/U2F security key physical presence check can be bypassed</description>
    </item>
    <item>
      <title>golang.org/x/crypto/ssh/agent doesn't drop invoking agent constraints when forwarding keys</title>
      <link>https://www.patchbrief.org/items/2026-06-go-cve-2026-39832.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-06-go-cve-2026-39832.html</guid>
      <pubDate>Thu, 25 Jun 2026 00:00:00 +0000</pubDate>
      <description>golang.org/x/crypto/ssh/agent doesn't drop invoking agent constraints when forwarding keys</description>
    </item>
    <item>
      <title>golang.org/x/crypto/ssh/agent doesn't enforce invoking key constraints</title>
      <link>https://www.patchbrief.org/items/2026-06-go-cve-2026-39833.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-06-go-cve-2026-39833.html</guid>
      <pubDate>Thu, 25 Jun 2026 00:00:00 +0000</pubDate>
      <description>golang.org/x/crypto/ssh/agent doesn't enforce invoking key constraints</description>
    </item>
    <item>
      <title>golang.org/x/crypto/ssh vulnerable to infinite loop on large channel writes</title>
      <link>https://www.patchbrief.org/items/2026-06-go-cve-2026-39834.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-06-go-cve-2026-39834.html</guid>
      <pubDate>Thu, 25 Jun 2026 00:00:00 +0000</pubDate>
      <description>golang.org/x/crypto/ssh vulnerable to infinite loop on large channel writes</description>
    </item>
    <item>
      <title>golang.org/x/crypto/ssh/knownhosts vulnerable to auth bypass via unenforced @revoked status</title>
      <link>https://www.patchbrief.org/items/2026-06-go-cve-2026-42508.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-06-go-cve-2026-42508.html</guid>
      <pubDate>Thu, 25 Jun 2026 00:00:00 +0000</pubDate>
      <description>golang.org/x/crypto/ssh/knownhosts vulnerable to auth bypass via unenforced @revoked status</description>
    </item>
    <item>
      <title>golang.org/x/crypto/ssh: Invoking VerifiedPublicKeyCallback permissions skip enforcement</title>
      <link>https://www.patchbrief.org/items/2026-06-go-cve-2026-46595.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-06-go-cve-2026-46595.html</guid>
      <pubDate>Thu, 25 Jun 2026 00:00:00 +0000</pubDate>
      <description>golang.org/x/crypto/ssh: Invoking VerifiedPublicKeyCallback permissions skip enforcement</description>
    </item>
    <item>
      <title>golang.org/x/crypto/ssh: Invoking byte arithmetic causes underflow and panic</title>
      <link>https://www.patchbrief.org/items/2026-06-go-cve-2026-46597.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-06-go-cve-2026-46597.html</guid>
      <pubDate>Thu, 25 Jun 2026 00:00:00 +0000</pubDate>
      <description>golang.org/x/crypto/ssh: Invoking byte arithmetic causes underflow and panic</description>
    </item>
    <item>
      <title>Rekor has an OOM Condition due to Unbounded gzip Decompression in Alpine APK Parsing Logic</title>
      <link>https://www.patchbrief.org/items/2026-06-go-cve-2026-48702.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-06-go-cve-2026-48702.html</guid>
      <pubDate>Thu, 25 Jun 2026 00:00:00 +0000</pubDate>
      <description>Rekor has an OOM Condition due to Unbounded gzip Decompression in Alpine APK Parsing Logic</description>
    </item>
    <item>
      <title>chi's RealIP Middleware allows IP spoofing via unvalidated X-Forwarded-For header</title>
      <link>https://www.patchbrief.org/items/2026-06-go-ghsa-rjr7-jggh-pgcp.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-06-go-ghsa-rjr7-jggh-pgcp.html</guid>
      <pubDate>Thu, 25 Jun 2026 00:00:00 +0000</pubDate>
      <description>chi's RealIP Middleware allows IP spoofing via unvalidated X-Forwarded-For header</description>
    </item>
    <item>
      <title>i18next-fs-backend vulnerable to prototype pollution via crafted missing-key string</title>
      <link>https://www.patchbrief.org/items/2026-06-npm-cve-2026-48713.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-06-npm-cve-2026-48713.html</guid>
      <pubDate>Thu, 25 Jun 2026 00:00:00 +0000</pubDate>
      <description>i18next-fs-backend vulnerable to prototype pollution via crafted missing-key string</description>
    </item>
    <item>
      <title>i18next-http-middleware: MissingKeyHandler does not reject keys whose segments contain prototype-polluting names</title>
      <link>https://www.patchbrief.org/items/2026-06-npm-cve-2026-48714.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-06-npm-cve-2026-48714.html</guid>
      <pubDate>Thu, 25 Jun 2026 00:00:00 +0000</pubDate>
      <description>i18next-http-middleware: MissingKeyHandler does not reject keys whose segments contain prototype-polluting names</description>
    </item>
    <item>
      <title>MessagePack-CSharp: Denial of service vulnerabilities can swamp the CPU or crash the process with stack and heap over...</title>
      <link>https://www.patchbrief.org/items/2026-06-nuget-cve-2026-48502.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-06-nuget-cve-2026-48502.html</guid>
      <pubDate>Thu, 25 Jun 2026 00:00:00 +0000</pubDate>
      <description>MessagePack-CSharp: Denial of service vulnerabilities can swamp the CPU or crash the process with stack and heap overflows</description>
    </item>
    <item>
      <title>MessagePack-CSharp: MessagePackReader.Skip can recurse without enforcing maximum object graph depth</title>
      <link>https://www.patchbrief.org/items/2026-06-nuget-cve-2026-48506.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-06-nuget-cve-2026-48506.html</guid>
      <pubDate>Thu, 25 Jun 2026 00:00:00 +0000</pubDate>
      <description>MessagePack-CSharp: MessagePackReader.Skip can recurse without enforcing maximum object graph depth</description>
    </item>
    <item>
      <title>ImageMagick: Policy Bypass in DCM decoder could result in image with invalid dimensions</title>
      <link>https://www.patchbrief.org/items/2026-06-nuget-cve-2026-49218.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-06-nuget-cve-2026-49218.html</guid>
      <pubDate>Thu, 25 Jun 2026 00:00:00 +0000</pubDate>
      <description>ImageMagick: Policy Bypass in DCM decoder could result in image with invalid dimensions</description>
    </item>
    <item>
      <title>ImageMagick: Policy Bypass can Trigger an Out-of-Memory condition</title>
      <link>https://www.patchbrief.org/items/2026-06-nuget-cve-2026-53460.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-06-nuget-cve-2026-53460.html</guid>
      <pubDate>Thu, 25 Jun 2026 00:00:00 +0000</pubDate>
      <description>ImageMagick: Policy Bypass can Trigger an Out-of-Memory condition</description>
    </item>
    <item>
      <title>ImageMagick has out-of-bounds write in ICON decoder due to incorrect loop</title>
      <link>https://www.patchbrief.org/items/2026-06-nuget-cve-2026-53461.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-06-nuget-cve-2026-53461.html</guid>
      <pubDate>Thu, 25 Jun 2026 00:00:00 +0000</pubDate>
      <description>ImageMagick has out-of-bounds write in ICON decoder due to incorrect loop</description>
    </item>
    <item>
      <title>PTC Windchill and FlexPLM Improper Input Validation Vulnerability</title>
      <link>https://www.patchbrief.org/items/2026-06-ptc-cve-2026-12569.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-06-ptc-cve-2026-12569.html</guid>
      <pubDate>Thu, 25 Jun 2026 00:00:00 +0000</pubDate>
      <description>PTC Windchill and FlexPLM contains an improper input validation vulnerability allowing an unauthenticated, remote attacker to execute arbitrary code by sending a malicious request to the network.</description>
    </item>
    <item>
      <title>Lemur has an authorization bypass in StrictRolePermission / AuthorityCreatorPermission</title>
      <link>https://www.patchbrief.org/items/2026-06-pypi-cve-2026-48508.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-06-pypi-cve-2026-48508.html</guid>
      <pubDate>Thu, 25 Jun 2026 00:00:00 +0000</pubDate>
      <description>Lemur has an authorization bypass in StrictRolePermission / AuthorityCreatorPermission</description>
    </item>
    <item>
      <title>Lemur: ACME SSRF + creator-equality IDOR lead to AWS IAM/PKI compromise</title>
      <link>https://www.patchbrief.org/items/2026-06-pypi-cve-2026-55166.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-06-pypi-cve-2026-55166.html</guid>
      <pubDate>Thu, 25 Jun 2026 00:00:00 +0000</pubDate>
      <description>Lemur: ACME SSRF + creator-equality IDOR lead to AWS IAM/PKI compromise</description>
    </item>
    <item>
      <title>amazon-braket-sdk vulnerable to Insecure Deserialization via pickle.loads()</title>
      <link>https://www.patchbrief.org/items/2026-06-pypi-cve-2026-9291.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-06-pypi-cve-2026-9291.html</guid>
      <pubDate>Thu, 25 Jun 2026 00:00:00 +0000</pubDate>
      <description>amazon-braket-sdk vulnerable to Insecure Deserialization via pickle.loads()</description>
    </item>
    <item>
      <title>Rtklib Rtklib — CVE-2026-56786 (Critical)</title>
      <link>https://www.patchbrief.org/items/2026-06-rtklib-cve-2026-56786.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-06-rtklib-cve-2026-56786.html</guid>
      <pubDate>Thu, 25 Jun 2026 00:00:00 +0000</pubDate>
      <description>RTKLIB through 2.4.3 contains an out-of-bounds write vulnerability in decode_type1033 function that fails to clamp length counters to destination buffer size, allowing up to 191-byte overflow into fixed 64-byte descriptor fields. An attacker controlling an NTRIP or serial RTCM3 correction stream can craft a valid CRC-bearing type-1033 message to corrupt adjacent rtcm_t object members, potentially achieving arbitrary code execution or denial of service.</description>
    </item>
    <item>
      <title>Wolfssl Wolfssl — CVE-2026-6094 (Critical)</title>
      <link>https://www.patchbrief.org/items/2026-06-wolfssl-cve-2026-6094.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-06-wolfssl-cve-2026-6094.html</guid>
      <pubDate>Thu, 25 Jun 2026 00:00:00 +0000</pubDate>
      <description>Heap buffer overread in wc_PKCS7_DecodeEnvelopedData when parsing crafted PKCS7 EnvelopedData. This could theoretically be triggered by attacker-supplied data delivered via S/MIME or CMS.</description>
    </item>
    <item>
      <title>Wolfssl Wolfssl — CVE-2026-7531 (Critical)</title>
      <link>https://www.patchbrief.org/items/2026-06-wolfssl-cve-2026-7531.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-06-wolfssl-cve-2026-7531.html</guid>
      <pubDate>Thu, 25 Jun 2026 00:00:00 +0000</pubDate>
      <description>Use-after-free in PQC hybrid key-share handling. This is an incomplete-fix follow-up to CVE-2026-5460 (released in 5.9.1): a malicious TLS 1.3 server sending a truncated PQC hybrid KeyShare can still trigger the error cleanup path to operate on freed memory.</description>
    </item>
    <item>
      <title>Appsmith Appsmith — CVE-2026-55455 (Critical)</title>
      <link>https://www.patchbrief.org/items/2026-06-appsmith-cve-2026-55455.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-06-appsmith-cve-2026-55455.html</guid>
      <pubDate>Wed, 24 Jun 2026 00:00:00 +0000</pubDate>
      <description>Appsmith is a platform to build admin panels, internal tools, and dashboards. Prior to 2.1, the outbound HTTP host filter applied by WebClientUtils (used by the REST API and GraphQL datasource plugins) validates hosts against an exact-match string denylist. The comprehensive address-class check (loopback, any-local, link-local, fc00::/7) exists only on a separate code path used by SMTP, not by the HTTP plugin path. As a result, an authenticated user can craft outbound requests that reach loopback-bound services inside the container. This vulnerability is fixed in 2.1.</description>
    </item>
    <item>
      <title>Cacti Cacti — CVE-2026-39948 (Critical)</title>
      <link>https://www.patchbrief.org/items/2026-06-cacti-cve-2026-39948.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-06-cacti-cve-2026-39948.html</guid>
      <pubDate>Wed, 24 Jun 2026 00:00:00 +0000</pubDate>
      <description>Cacti is an open source performance and fault management framework. In versions 1.2.30 and prior, the rfilter request parameter is retrieved via the raw accessor grv() (rather than gfrv() with FILTER_VALIDATE_IS_REGEX validation) and concatenated directly into RLIKE SQL clauses in lib/html_graph.php and lib/html_tree.php, which are reachable pre-authentication through graph_view.php on installations with guest graph viewing enabled. Because the unbalanced-quote payload bypasses the regex validation that would otherwise reject it, an unauthenticated attacker can inject arbitrary SQL to compromi</description>
    </item>
    <item>
      <title>OliveTin has a Concurrent Template Parsing Race Condition which Leads to Cross-Request Command Contamination</title>
      <link>https://www.patchbrief.org/items/2026-06-go-cve-2026-48708.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-06-go-cve-2026-48708.html</guid>
      <pubDate>Wed, 24 Jun 2026 00:00:00 +0000</pubDate>
      <description>OliveTin has a Concurrent Template Parsing Race Condition which Leads to Cross-Request Command Contamination</description>
    </item>
    <item>
      <title>OpenAM: Pre-auth RCE via Java Deserialization in WebAuthn Authenticator Storage</title>
      <link>https://www.patchbrief.org/items/2026-06-maven-cve-2026-45051.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-06-maven-cve-2026-45051.html</guid>
      <pubDate>Wed, 24 Jun 2026 00:00:00 +0000</pubDate>
      <description>OpenAM: Pre-auth RCE via Java Deserialization in WebAuthn Authenticator Storage</description>
    </item>
    <item>
      <title>OpenAM Pre-auth User Profile Tampering via Anonymous SOAP Authn in Liberty IDPP/Discovery Endpoints</title>
      <link>https://www.patchbrief.org/items/2026-06-maven-cve-2026-45052.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-06-maven-cve-2026-45052.html</guid>
      <pubDate>Wed, 24 Jun 2026 00:00:00 +0000</pubDate>
      <description>OpenAM Pre-auth User Profile Tampering via Anonymous SOAP Authn in Liberty IDPP/Discovery Endpoints</description>
    </item>
    <item>
      <title>N8N N8N — CVE-2026-56351 (Critical)</title>
      <link>https://www.patchbrief.org/items/2026-06-n8n-cve-2026-56351.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-06-n8n-cve-2026-56351.html</guid>
      <pubDate>Wed, 24 Jun 2026 00:00:00 +0000</pubDate>
      <description>n8n before version 2.4.0 contains a sql injection vulnerability in MySQL, PostgreSQL, and Microsoft SQL nodes that allows authenticated users to inject arbitrary SQL through unescaped identifier values in node configuration parameters. Attackers with workflow creation permissions can supply specially crafted table or column names to execute unauthorized database commands and compromise data integrity.</description>
    </item>
    <item>
      <title>Rubyconcurrency Concurrent Ruby — CVE-2026-54906 (Critical)</title>
      <link>https://www.patchbrief.org/items/2026-06-rubyconcurrency-cve-2026-54906.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-06-rubyconcurrency-cve-2026-54906.html</guid>
      <pubDate>Wed, 24 Jun 2026 00:00:00 +0000</pubDate>
      <description>concurrent-ruby is a modern concurrency tools for Ruby. Prior to 1.3.7, Concurrent::ReadWriteLock#release_write_lock does not verify that the calling thread acquired the write lock. Any thread with access to the lock object can release an active write lock held by another thread. A second writer can then enter its critical section while the first writer is still running. Concurrent::ReadWriteLock#release_read_lock also decrements the shared counter even when no read lock is held. Calling it on a fresh lock changes the counter from 0 to -1, after which normal read acquisition raises Concurrent:</description>
    </item>
    <item>
      <title>Snipe-IT: Bulk editing users allowed `ldap_import` and `activated_in` bulk editing users</title>
      <link>https://www.patchbrief.org/items/2026-06-composer-cve-2026-48507.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-06-composer-cve-2026-48507.html</guid>
      <pubDate>Tue, 23 Jun 2026 00:00:00 +0000</pubDate>
      <description>Snipe-IT: Bulk editing users allowed `ldap_import` and `activated_in` bulk editing users</description>
    </item>
    <item>
      <title>Snipe-IT API Vulnerable to Cross-Tenant Accessory Injection</title>
      <link>https://www.patchbrief.org/items/2026-06-composer-cve-2026-54329.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-06-composer-cve-2026-54329.html</guid>
      <pubDate>Tue, 23 Jun 2026 00:00:00 +0000</pubDate>
      <description>Snipe-IT API Vulnerable to Cross-Tenant Accessory Injection</description>
    </item>
    <item>
      <title>AVideo has an incomplete fix of CVE-2026-33482: sanitizeFFmpegCommand still allows a single '&amp;' (background operator)...</title>
      <link>https://www.patchbrief.org/items/2026-06-composer-cve-2026-55173.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-06-composer-cve-2026-55173.html</guid>
      <pubDate>Tue, 23 Jun 2026 00:00:00 +0000</pubDate>
      <description>AVideo has an incomplete fix of CVE-2026-33482: sanitizeFFmpegCommand still allows a single '&amp;' (background operator), giving OS command execution at the same execAsync sh -c sink</description>
    </item>
    <item>
      <title>Algernon: Host header path traversal in --domain mode reads files and runs Lua from parent dir</title>
      <link>https://www.patchbrief.org/items/2026-06-go-cve-2026-48126.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-06-go-cve-2026-48126.html</guid>
      <pubDate>Tue, 23 Jun 2026 00:00:00 +0000</pubDate>
      <description>Algernon: Host header path traversal in --domain mode reads files and runs Lua from parent dir</description>
    </item>
    <item>
      <title>Gogs vulnerable to RCE via git rebase --exec argument injection in pull request merge</title>
      <link>https://www.patchbrief.org/items/2026-06-go-cve-2026-52806.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-06-go-cve-2026-52806.html</guid>
      <pubDate>Tue, 23 Jun 2026 00:00:00 +0000</pubDate>
      <description>Gogs vulnerable to RCE via git rebase --exec argument injection in pull request merge</description>
    </item>
    <item>
      <title>Gogs has DOM-based XSS via Milestone Name on New Issue Page</title>
      <link>https://www.patchbrief.org/items/2026-06-go-cve-2026-52807.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-06-go-cve-2026-52807.html</guid>
      <pubDate>Tue, 23 Jun 2026 00:00:00 +0000</pubDate>
      <description>Gogs has DOM-based XSS via Milestone Name on New Issue Page</description>
    </item>
    <item>
      <title>Gogs's write-level collaborators can mutate admin-only repository settings via API</title>
      <link>https://www.patchbrief.org/items/2026-06-go-cve-2026-52808.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-06-go-cve-2026-52808.html</guid>
      <pubDate>Tue, 23 Jun 2026 00:00:00 +0000</pubDate>
      <description>Gogs's write-level collaborators can mutate admin-only repository settings via API</description>
    </item>
    <item>
      <title>Gogs allows users to write to readonly repositories using receive-pack + service=git-upload-pack confusion</title>
      <link>https://www.patchbrief.org/items/2026-06-go-cve-2026-52810.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-06-go-cve-2026-52810.html</guid>
      <pubDate>Tue, 23 Jun 2026 00:00:00 +0000</pubDate>
      <description>Gogs allows users to write to readonly repositories using receive-pack + service=git-upload-pack confusion</description>
    </item>
    <item>
      <title>Gogs: UploadRepoFiles writes outside repo working tree via committed parent sym</title>
      <link>https://www.patchbrief.org/items/2026-06-go-cve-2026-52811.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-06-go-cve-2026-52811.html</guid>
      <pubDate>Tue, 23 Jun 2026 00:00:00 +0000</pubDate>
      <description>Gogs: UploadRepoFiles writes outside repo working tree via committed parent sym</description>
    </item>
    <item>
      <title>Gogs: LFS dedupe path leaks private repo content across tenants</title>
      <link>https://www.patchbrief.org/items/2026-06-go-cve-2026-52812.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-06-go-cve-2026-52812.html</guid>
      <pubDate>Tue, 23 Jun 2026 00:00:00 +0000</pubDate>
      <description>Gogs: LFS dedupe path leaks private repo content across tenants</description>
    </item>
    <item>
      <title>Gogs has Path Traversal in organization name that results in RCE through Git hooks</title>
      <link>https://www.patchbrief.org/items/2026-06-go-cve-2026-52813.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-06-go-cve-2026-52813.html</guid>
      <pubDate>Tue, 23 Jun 2026 00:00:00 +0000</pubDate>
      <description>Gogs has Path Traversal in organization name that results in RCE through Git hooks</description>
    </item>
    <item>
      <title>Lantronix EDS5000 Code Injection Vulnerability</title>
      <link>https://www.patchbrief.org/items/2026-06-lantronix-cve-2025-67038.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-06-lantronix-cve-2025-67038.html</guid>
      <pubDate>Tue, 23 Jun 2026 00:00:00 +0000</pubDate>
      <description>Lantronix EDS5000 contains a code injection vulnerability that could allow attackers to inject arbitrary OS commands into the username parameter. Injected commands are executed with root privileges.</description>
    </item>
    <item>
      <title>OpenAM Authenticated Privilege Escalation via Raw Token Disclosure Session RPC</title>
      <link>https://www.patchbrief.org/items/2026-06-maven-cve-2026-45048.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-06-maven-cve-2026-45048.html</guid>
      <pubDate>Tue, 23 Jun 2026 00:00:00 +0000</pubDate>
      <description>OpenAM Authenticated Privilege Escalation via Raw Token Disclosure Session RPC</description>
    </item>
    <item>
      <title>OpenAM Unauthenticated Session Hijacking via Information Exposure in CDCServlet</title>
      <link>https://www.patchbrief.org/items/2026-06-maven-cve-2026-45049.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-06-maven-cve-2026-45049.html</guid>
      <pubDate>Tue, 23 Jun 2026 00:00:00 +0000</pubDate>
      <description>OpenAM Unauthenticated Session Hijacking via Information Exposure in CDCServlet</description>
    </item>
    <item>
      <title>jackson-databind has a PolymorphicTypeValidator bypass via generic type parameters that allows arbitrary class instan...</title>
      <link>https://www.patchbrief.org/items/2026-06-maven-cve-2026-54512.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-06-maven-cve-2026-54512.html</guid>
      <pubDate>Tue, 23 Jun 2026 00:00:00 +0000</pubDate>
      <description>jackson-databind has a PolymorphicTypeValidator bypass via generic type parameters that allows arbitrary class instantiation</description>
    </item>
    <item>
      <title>jackson-databind has an array subtype allowlist bypass in BasicPolymorphicTypeValidator (allowIfSubTypeIsArray)</title>
      <link>https://www.patchbrief.org/items/2026-06-maven-cve-2026-54513.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-06-maven-cve-2026-54513.html</guid>
      <pubDate>Tue, 23 Jun 2026 00:00:00 +0000</pubDate>
      <description>jackson-databind has an array subtype allowlist bypass in BasicPolymorphicTypeValidator (allowIfSubTypeIsArray)</description>
    </item>
    <item>
      <title>N8N N8N — CVE-2026-44789 (Critical)</title>
      <link>https://www.patchbrief.org/items/2026-06-n8n-cve-2026-44789.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-06-n8n-cve-2026-44789.html</guid>
      <pubDate>Tue, 23 Jun 2026 00:00:00 +0000</pubDate>
      <description>n8n is an open source workflow automation platform. Prior to 1.123.43, 2.22.1, and 2.20.7, an authenticated user with permission to create or modify workflows could achieve global prototype pollution via an unvalidated pagination parameter in the HTTP Request node. Combined with other techniques this could lead to RCE on the instance. This vulnerability is fixed in 1.123.43, 2.22.1, and 2.20.7.</description>
    </item>
    <item>
      <title>N8N N8N — CVE-2026-44791 (Critical)</title>
      <link>https://www.patchbrief.org/items/2026-06-n8n-cve-2026-44791.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-06-n8n-cve-2026-44791.html</guid>
      <pubDate>Tue, 23 Jun 2026 00:00:00 +0000</pubDate>
      <description>n8n is an open source workflow automation platform. Prior to 1.123.43, 2.22.1, and 2.20.7, an authenticated user with permission to create or modify workflows could bypass the patch for CVE-2026-42232 in the XML node. When combined with other nodes, this could lead to RCE on the n8n host. This vulnerability is fixed in 1.123.43, 2.22.1, and 2.20.7.</description>
    </item>
    <item>
      <title>N8N N8N — CVE-2026-44792 (Critical)</title>
      <link>https://www.patchbrief.org/items/2026-06-n8n-cve-2026-44792.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-06-n8n-cve-2026-44792.html</guid>
      <pubDate>Tue, 23 Jun 2026 00:00:00 +0000</pubDate>
      <description>n8n is an open source workflow automation platform. Prior to 1.123.43, 2.22.1, and 2.20.7, an attacker with write access to the git repository connected to an n8n Source Control configuration could commit a malicious Data Table JSON file containing a crafted column name. When an administrator performed a Source Control Pull, n8n imported the file and could lead to SQL injection on the internal PostgreSQL instance. Exploitation requires the n8n instance uses PostgreSQL as its database backend, the Source Control feature is enabled and connected to a repository the attacker can write to, and an</description>
    </item>
    <item>
      <title>N8N N8N — CVE-2026-54305 (Critical)</title>
      <link>https://www.patchbrief.org/items/2026-06-n8n-cve-2026-54305.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-06-n8n-cve-2026-54305.html</guid>
      <pubDate>Tue, 23 Jun 2026 00:00:00 +0000</pubDate>
      <description>n8n is an open source workflow automation platform. Prior to 1.123.55, 2.25.7, and 2.26.2, three EE endpoints used by the Dynamic Credentials feature accepted any authenticated n8n session without performing per-resource ownership or scope checks on the target workflow or credential. An authenticated user with no project membership or credential sharing relationship could enumerate credential identifiers, names, and types referenced by any private workflow in the instance, initiate an OAuth authorization flow against another user's credential to overwrite its stored tokens with tokens bound to</description>
    </item>
    <item>
      <title>N8N N8N — CVE-2026-54307 (Critical)</title>
      <link>https://www.patchbrief.org/items/2026-06-n8n-cve-2026-54307.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-06-n8n-cve-2026-54307.html</guid>
      <pubDate>Tue, 23 Jun 2026 00:00:00 +0000</pubDate>
      <description>n8n is an open source workflow automation platform. Prior to 1.123.55, 2.25.7, and 2.26.2, a member-level user with editor access to a shared workflow could reference credentials they do not own via specific public API endpoints. Credential ownership checks were only enforced partially leading to cross-user credential access. This issue affects instances where workflow sharing is enabled and at least one workflow has been shared with a member-level user as an Editor. This vulnerability is fixed in 1.123.55, 2.25.7, and 2.26.2.</description>
    </item>
    <item>
      <title>N8N N8N — CVE-2026-54309 (Critical)</title>
      <link>https://www.patchbrief.org/items/2026-06-n8n-cve-2026-54309.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-06-n8n-cve-2026-54309.html</guid>
      <pubDate>Tue, 23 Jun 2026 00:00:00 +0000</pubDate>
      <description>n8n is an open source workflow automation platform. Prior to 2.25.7 and 2.26.2, when @n8n/mcp-browser is run in HTTP transport mode, the MCP endpoint accepts session initialization and tool invocation requests without any authentication. Any network-reachable client, or any website visited by the user, can establish an MCP session and invoke browser-control tools. Where the n8n AI Browser Bridge extension is installed and a browser connection is active, an unauthenticated caller can access browser-control capabilities including navigation, JavaScript evaluation, and cookie and storage access a</description>
    </item>
    <item>
      <title>N8N N8N — CVE-2026-54310 (Critical)</title>
      <link>https://www.patchbrief.org/items/2026-06-n8n-cve-2026-54310.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-06-n8n-cve-2026-54310.html</guid>
      <pubDate>Tue, 23 Jun 2026 00:00:00 +0000</pubDate>
      <description>n8n is an open source workflow automation platform. Prior to 2.25.7 and 2.26.2, an authenticated user with permission to create or modify workflows could supply a crafted parameters to the TimescaleDB and/or legacy Postgres v1 node's allowing arbitrary SQL to be injected and executed against the connected database within the privileges of the configured database account. This vulnerability is fixed in 2.25.7 and 2.26.2.</description>
    </item>
    <item>
      <title>Budibase has nonymous NoSQL operator injection via published-app query templates</title>
      <link>https://www.patchbrief.org/items/2026-06-npm-cve-2026-54350.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-06-npm-cve-2026-54350.html</guid>
      <pubDate>Tue, 23 Jun 2026 00:00:00 +0000</pubDate>
      <description>Budibase has nonymous NoSQL operator injection via published-app query templates</description>
    </item>
    <item>
      <title>Glances has arbitrary file write and command execution via `secure_popen` redirection and chaining operators in AMP c...</title>
      <link>https://www.patchbrief.org/items/2026-06-pypi-cve-2026-53925.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-06-pypi-cve-2026-53925.html</guid>
      <pubDate>Tue, 23 Jun 2026 00:00:00 +0000</pubDate>
      <description>Glances has arbitrary file write and command execution via `secure_popen` redirection and chaining operators in AMP command configuration</description>
    </item>
    <item>
      <title>OctoPrint has possible file exfiltration via query parameters on upload endpoints</title>
      <link>https://www.patchbrief.org/items/2026-06-pypi-cve-2026-54134.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-06-pypi-cve-2026-54134.html</guid>
      <pubDate>Tue, 23 Jun 2026 00:00:00 +0000</pubDate>
      <description>OctoPrint has possible file exfiltration via query parameters on upload endpoints</description>
    </item>
    <item>
      <title>motionEye's Absolute Path Traversal in Media File Handlers Allows Arbitrary File Read</title>
      <link>https://www.patchbrief.org/items/2026-06-pypi-cve-2026-55488.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-06-pypi-cve-2026-55488.html</guid>
      <pubDate>Tue, 23 Jun 2026 00:00:00 +0000</pubDate>
      <description>motionEye's Absolute Path Traversal in Media File Handlers Allows Arbitrary File Read</description>
    </item>
    <item>
      <title>motionEye Partial Authentication Bypass: Unauthenticated Admin Credential Theft via Path Traversal</title>
      <link>https://www.patchbrief.org/items/2026-06-pypi-ghsa-phv5-334h-mxcw.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-06-pypi-ghsa-phv5-334h-mxcw.html</guid>
      <pubDate>Tue, 23 Jun 2026 00:00:00 +0000</pubDate>
      <description>motionEye Partial Authentication Bypass: Unauthenticated Admin Credential Theft via Path Traversal</description>
    </item>
    <item>
      <title>motionEye: LFI → pass‑the‑hash admin → unsafe restore → unauth action exec (RCE)</title>
      <link>https://www.patchbrief.org/items/2026-06-pypi-ghsa-qxvg-h7q2-hcxh.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-06-pypi-ghsa-qxvg-h7q2-hcxh.html</guid>
      <pubDate>Tue, 23 Jun 2026 00:00:00 +0000</pubDate>
      <description>motionEye: LFI → pass‑the‑hash admin → unsafe restore → unauth action exec (RCE)</description>
    </item>
    <item>
      <title>Mise vulnerable to arbitrary command execution via task-include files in an untrusted, config-less repository</title>
      <link>https://www.patchbrief.org/items/2026-06-rust-cve-2026-55441.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-06-rust-cve-2026-55441.html</guid>
      <pubDate>Tue, 23 Jun 2026 00:00:00 +0000</pubDate>
      <description>Mise vulnerable to arbitrary command execution via task-include files in an untrusted, config-less repository</description>
    </item>
    <item>
      <title>Ubiquiti UniFi OS Improper Access Control Vulnerability</title>
      <link>https://www.patchbrief.org/items/2026-06-ubiquiti-cve-2026-34908.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-06-ubiquiti-cve-2026-34908.html</guid>
      <pubDate>Tue, 23 Jun 2026 00:00:00 +0000</pubDate>
      <description>Ubiquiti UniFi OS contains an improper access control vulnerability which could allow a malicious actor with access to the network to make unauthorized changes to the system.</description>
    </item>
    <item>
      <title>Ubiquiti UniFi OS Path Traversal Vulnerability</title>
      <link>https://www.patchbrief.org/items/2026-06-ubiquiti-cve-2026-34909.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-06-ubiquiti-cve-2026-34909.html</guid>
      <pubDate>Tue, 23 Jun 2026 00:00:00 +0000</pubDate>
      <description>Ubiquiti UniFi OS contains a path traversal vulnerability which could allow a malicious actor with access to the network to access files on the underlying system that could be manipulated to access an underlying account.</description>
    </item>
    <item>
      <title>Ubiquiti UniFi OS Improper Input Validation Vulnerability</title>
      <link>https://www.patchbrief.org/items/2026-06-ubiquiti-cve-2026-34910.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-06-ubiquiti-cve-2026-34910.html</guid>
      <pubDate>Tue, 23 Jun 2026 00:00:00 +0000</pubDate>
      <description>Ubiquiti UniFi OS contains an improper input validation vulnerability which could allow a malicious actor with access to the network to conduct command injection.</description>
    </item>
    <item>
      <title>Paymenter vulnerable to Remote Code Execution via public file uploads</title>
      <link>https://www.patchbrief.org/items/2026-06-composer-cve-2025-58048.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-06-composer-cve-2025-58048.html</guid>
      <pubDate>Mon, 22 Jun 2026 00:00:00 +0000</pubDate>
      <description>Paymenter vulnerable to Remote Code Execution via public file uploads</description>
    </item>
    <item>
      <title>VU#936962: Multiple file parsing vulnerabilities in FastStone Image Viewer 8.3.0.0</title>
      <link>https://www.patchbrief.org/items/2026-06-faststone-vu-936962.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-06-faststone-vu-936962.html</guid>
      <pubDate>Mon, 22 Jun 2026 00:00:00 +0000</pubDate>
      <description>Overview Two vulnerabilities have been identified in FastStone Image Viewer 8.3 that may allow remote code execution or control-flow corruption when processing specially crafted image files. The affected components include the JPEG 2000 (JP2) parser and the PSD file parser. An attacker can exploit these vulnerabilities by causing the application to automatically or interactively process malicious image files. Description FastStone Image Viewer is a software tool for browsing, editing, and managing images, offering features like full‑screen viewing, batch processing, red‑eye removal, and a wide range of editing effects. It supports virtually all major image and RAW formats and includes conveniences like slideshows, comparison tools, scanner support, and screen capture. CVE-2026-30040 A critical heap-based buffer overflow vulnerability... Related CVEs: CVE-2026-30040, CVE-2026-30041.</description>
    </item>
    <item>
      <title>Ibm Websphere Application Server — CVE-2026-8646 (Critical)</title>
      <link>https://www.patchbrief.org/items/2026-06-ibm-cve-2026-8646.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-06-ibm-cve-2026-8646.html</guid>
      <pubDate>Mon, 22 Jun 2026 00:00:00 +0000</pubDate>
      <description>IBM WebSphere Application Server 9.0 and 8.5 and IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.6 are vulnerable to HTTP request smuggling. A remote attacker could smuggle a specially crafted request to the application server thereby allowing the attacker to bypass security controls, spoof identity, escalate privilege, and expose sensitive information.</description>
    </item>
    <item>
      <title>Ibm Websphere Application Server — CVE-2026-9006 (Critical)</title>
      <link>https://www.patchbrief.org/items/2026-06-ibm-cve-2026-9006.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-06-ibm-cve-2026-9006.html</guid>
      <pubDate>Mon, 22 Jun 2026 00:00:00 +0000</pubDate>
      <description>IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to server-side request forgery (SSRF) with the Ajax Proxy configured. This may allow an attacker to send unauthorized requests from the system, resulting in a security bypass or information disclosure.</description>
    </item>
    <item>
      <title>Ibm I — CVE-2026-9072 (Critical)</title>
      <link>https://www.patchbrief.org/items/2026-06-ibm-cve-2026-9072.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-06-ibm-cve-2026-9072.html</guid>
      <pubDate>Mon, 22 Jun 2026 00:00:00 +0000</pubDate>
      <description>IBM i 7.6, 7.5, 7.4, and 7.3, IBM WebSphere Application Server, and IBM WebSphere Application Server Liberty - when using Intelligent Management with the WebSphere WebServer Plug-in component - are vulnerable to remote code execution and denial of service. This vulnerability can be exploited when an attacker impersonates backend servers and sends crafted responses to the plug-in.</description>
    </item>
    <item>
      <title>Litellm Litellm — CVE-2026-49468 (Critical)</title>
      <link>https://www.patchbrief.org/items/2026-06-litellm-cve-2026-49468.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-06-litellm-cve-2026-49468.html</guid>
      <pubDate>Mon, 22 Jun 2026 00:00:00 +0000</pubDate>
      <description>LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. Prior to 1.84.0, This vulnerability is fixed in 1.84.0.</description>
    </item>
    <item>
      <title>xwiki-pro-macros has remote code execution from page title and content via excerpt-include macro</title>
      <link>https://www.patchbrief.org/items/2026-06-maven-cve-2026-44179.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-06-maven-cve-2026-44179.html</guid>
      <pubDate>Mon, 22 Jun 2026 00:00:00 +0000</pubDate>
      <description>xwiki-pro-macros has remote code execution from page title and content via excerpt-include macro</description>
    </item>
    <item>
      <title>OpenAM has pre-auth Reflected XSS in OAuth2 / OIDC response_mode=form_post via state parameter (FormPostResponse.ftl)</title>
      <link>https://www.patchbrief.org/items/2026-06-maven-cve-2026-44203.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-06-maven-cve-2026-44203.html</guid>
      <pubDate>Mon, 22 Jun 2026 00:00:00 +0000</pubDate>
      <description>OpenAM has pre-auth Reflected XSS in OAuth2 / OIDC response_mode=form_post via state parameter (FormPostResponse.ftl)</description>
    </item>
    <item>
      <title>OpenDJ Pre-Auth RCE via Java Deserialization in JMX RMI</title>
      <link>https://www.patchbrief.org/items/2026-06-maven-cve-2026-46495.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-06-maven-cve-2026-46495.html</guid>
      <pubDate>Mon, 22 Jun 2026 00:00:00 +0000</pubDate>
      <description>OpenDJ Pre-Auth RCE via Java Deserialization in JMX RMI</description>
    </item>
    <item>
      <title>Messagepack Messagepack — CVE-2026-48509 (Critical)</title>
      <link>https://www.patchbrief.org/items/2026-06-messagepack-cve-2026-48509.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-06-messagepack-cve-2026-48509.html</guid>
      <pubDate>Mon, 22 Jun 2026 00:00:00 +0000</pubDate>
      <description>MessagePack for C# is a MessagePack serializer for C#. Prior to 2.5.301 and 3.1.7, the parameterless MessagePackInputFormatter() constructor uses default serializer options, which resolve to MessagePackSerializerOptions.Standard with MessagePackSecurity.TrustedData. The formatter is designed for ASP.NET Core MVC request bodies, which commonly cross an HTTP trust boundary. This insecure default can expose applications to denial-of-service attacks that MessagePackSecurity.UntrustedData is intended to mitigate, such as hash-collision attacks against dictionary-like model properties. This vulnerab</description>
    </item>
    <item>
      <title>VU#226679: Microsoft WinRE allows for bypass of UEFI/BIOS password enforcement</title>
      <link>https://www.patchbrief.org/items/2026-06-microsoft-vu-226679.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-06-microsoft-vu-226679.html</guid>
      <pubDate>Mon, 22 Jun 2026 00:00:00 +0000</pubDate>
      <description>Overview Microsoft Windows Recovery Environment (WinRE) provides a mechanism for recovering and repairing Windows systems using an alternate boot environment. Under certain platform implementations, access to WinRE may allow an attacker to bypass firmware security controls, including administrator-configured UEFI/BIOS passwords. An attacker with physical or administrative access to a device may be able to leverage WinRE-related boot mechanisms to circumvent firmware protections and gain unauthorized access to system resources. Description Microsoft Windows versions 10 and 11 include the WinRE capability, a recovery platform that supports features such as the F11 recovery menu and the Reset this PC functionalities. WinRE is commonly used for system recovery, troubleshooting, and remote support scenarios. When WinRE is invoked, the system...</description>
    </item>
    <item>
      <title>N8N N8N — CVE-2026-56348 (Critical)</title>
      <link>https://www.patchbrief.org/items/2026-06-n8n-cve-2026-56348.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-06-n8n-cve-2026-56348.html</guid>
      <pubDate>Mon, 22 Jun 2026 00:00:00 +0000</pubDate>
      <description>n8n before 2.20.0 contains a credential exfiltration vulnerability in the POST /rest/dynamic-node-parameters/options endpoint that allows authenticated users to bypass Allowed HTTP Request Domains restrictions. Attackers with credential access can cause the n8n server to issue HTTP requests with credentials to unauthorized hosts, exfiltrating sensitive authentication data.</description>
    </item>
    <item>
      <title>scimPatch vulnerable to prototype pollution via unfiltered keys in patch</title>
      <link>https://www.patchbrief.org/items/2026-06-npm-cve-2026-48170.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-06-npm-cve-2026-48170.html</guid>
      <pubDate>Mon, 22 Jun 2026 00:00:00 +0000</pubDate>
      <description>scimPatch vulnerable to prototype pollution via unfiltered keys in patch</description>
    </item>
    <item>
      <title>Budibase has arbitrary file read by workspace-builder via PWA-zip symlink upload</title>
      <link>https://www.patchbrief.org/items/2026-06-npm-cve-2026-54352.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-06-npm-cve-2026-54352.html</guid>
      <pubDate>Mon, 22 Jun 2026 00:00:00 +0000</pubDate>
      <description>Budibase has arbitrary file read by workspace-builder via PWA-zip symlink upload</description>
    </item>
    <item>
      <title>motionEye: Authentication possible via password hash</title>
      <link>https://www.patchbrief.org/items/2026-06-pypi-cve-2026-46488.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-06-pypi-cve-2026-46488.html</guid>
      <pubDate>Mon, 22 Jun 2026 00:00:00 +0000</pubDate>
      <description>motionEye: Authentication possible via password hash</description>
    </item>
    <item>
      <title>Mise Vulnerable to Arbitrary Code Execution via Tera Templates in .tool-versions Files (Trust Bypass)</title>
      <link>https://www.patchbrief.org/items/2026-06-rust-cve-2026-33646.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-06-rust-cve-2026-33646.html</guid>
      <pubDate>Mon, 22 Jun 2026 00:00:00 +0000</pubDate>
      <description>Mise Vulnerable to Arbitrary Code Execution via Tera Templates in .tool-versions Files (Trust Bypass)</description>
    </item>
    <item>
      <title>VU#457458: Vendor-signed UEFI applications found vulnerable to Secure Boot bypass</title>
      <link>https://www.patchbrief.org/items/2026-06-multiple-vendors-vu-457458.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-06-multiple-vendors-vu-457458.html</guid>
      <pubDate>Thu, 18 Jun 2026 00:00:00 +0000</pubDate>
      <description>Overview Multiple vendor-signed UEFI applications are vulnerable to Secure Boot bypass via a "Bring Your Own Vulnerable Driver" (BYOVD)-style attack. If a target system trusts the affected vendor’s certificate, an attacker can exploit these applications to execute arbitrary code during the early pre-boot phase before the operating system initializes. To mitigate this risk, system administrators should apply updates to the UEFI Forbidden Signature Database (DBX) that revoke trust in the affected vendor-signed binaries, preventing these vulnerable applications from executing during the boot process. Description The Unified Extensible Firmware Interface ( UEFI ) standard defines the modern firmware architecture used to initialize hardware and transfer control to the operating system during system startup. On systems with Secure Boot...</description>
    </item>
    <item>
      <title>Splunk Enterprise Missing Authentication for Critical Function Vulnerability</title>
      <link>https://www.patchbrief.org/items/2026-06-splunk-cve-2026-20253.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-06-splunk-cve-2026-20253.html</guid>
      <pubDate>Thu, 18 Jun 2026 00:00:00 +0000</pubDate>
      <description>Splunk Enterprise contains a missing authentication for critical function vulnerability which could allow an unauthenticated user to create or truncate arbitrary files through a PostgreSQL sidecar service endpoint.</description>
    </item>
    <item>
      <title>Apache Dolphinscheduler — CVE-2026-32966 (Critical)</title>
      <link>https://www.patchbrief.org/items/2026-06-apache-cve-2026-32966.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-06-apache-cve-2026-32966.html</guid>
      <pubDate>Wed, 17 Jun 2026 00:00:00 +0000</pubDate>
      <description>DataSource API Missing Authorization Check Leads to Arbitrary Data Source Metadata Disclosure in Apache DolphinScheduler.

This issue affects Apache DolphinScheduler: before 3.4.2.

Users are recommended to upgrade to version 3.4.2, which fixes the issue.</description>
    </item>
    <item>
      <title>Apache Dolphinscheduler — CVE-2026-32967 (Critical)</title>
      <link>https://www.patchbrief.org/items/2026-06-apache-cve-2026-32967.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-06-apache-cve-2026-32967.html</guid>
      <pubDate>Wed, 17 Jun 2026 00:00:00 +0000</pubDate>
      <description>Incorrect Authorization vulnerability of `/v2` experimental interface in Apache DolphinScheduler.

This issue affects Apache DolphinScheduler: before 3.4.2.

Users are recommended to upgrade to version 3.4.2, which fixes the issue.</description>
    </item>
    <item>
      <title>Apache Shiro — CVE-2026-49268 (Critical)</title>
      <link>https://www.patchbrief.org/items/2026-06-apache-cve-2026-49268.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-06-apache-cve-2026-49268.html</guid>
      <pubDate>Wed, 17 Jun 2026 00:00:00 +0000</pubDate>
      <description>A remote attacker can inject LDAP special characters into the Distinguished Name (DN) construction in DefaultLdapRealm class. User-supplied username input is directly concatenated into the LDAP DN template without any escaping of RFC 2253 special characters. This allows an attacker to manipulate the DN structure used for LDAP bind authentication, potentially bypassing authentication or impersonating other users.

This issue affects all Apache Shiro versions through 2.2.0, and 3.0.0-alpha-1 when using DefaultLdapRealm
Upgrade to Apache Shiro 2.2.1 or 3.0.0-alpha-2 or later, which fixes the issu</description>
    </item>
    <item>
      <title>VU#380058: SignalRGB kernel driver contains improper access control and IOCTL vulnerabilities</title>
      <link>https://www.patchbrief.org/items/2026-06-signalrgb-vu-380058.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-06-signalrgb-vu-380058.html</guid>
      <pubDate>Wed, 17 Jun 2026 00:00:00 +0000</pubDate>
      <description>Overview The SignalRGB kernel driver, SignalIo.sys , contains two vulnerabilities involving improper access control and unsafe memory handling. The device object is created with an overly permissive Discretionary Access Control List (DACL) that allows user-mode processes to access privileged hardware operations through input/output control (IOCTL) commands. Additionally, several IOCTL handlers are susceptible to NULL pointer dereference conditions, which further enables low-privilege users to trigger kernel crashes and cause Denial of Service (DoS). Version 1.3.7.0 of the SignalRGB driver remediates these vulnerabilities. Description SignalRGB is a Windows application used for RGB lighting control and hardware monitoring. Its kernel component, SignalIo.sys , provides the low-level interfaces required to access and interact with hardware... Related CVEs: CVE-2026-8049, CVE-2026-8050.</description>
    </item>
    <item>
      <title>Widget Factory Joomla Content Editor Improper Access Control Vulnerability</title>
      <link>https://www.patchbrief.org/items/2026-06-widget-factory-cve-2026-48907.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-06-widget-factory-cve-2026-48907.html</guid>
      <pubDate>Tue, 16 Jun 2026 00:00:00 +0000</pubDate>
      <description>Widget Factory Joomla Content Editor contains an improper access control vulnerability which could allow for upload and execution of PHP code via the creation of new editor profiles for unauthenticated users.</description>
    </item>
    <item>
      <title>Cisco Catalyst SD-WAN Manager Directory or Path Traversal Vulnerability</title>
      <link>https://www.patchbrief.org/items/2026-06-cisco-cve-2026-20262.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-06-cisco-cve-2026-20262.html</guid>
      <pubDate>Mon, 15 Jun 2026 00:00:00 +0000</pubDate>
      <description>Cisco Catalyst SD-WAN Manager contains a directory or path traversal vulnerability that could allow an authenticated, remote attacker to create a file or overwrite any file on the filesystem of an affected system.</description>
    </item>
    <item>
      <title>LiteSpeed cPanel Plugin UNIX Symbolic Link (Symlink) Following Vulnerability</title>
      <link>https://www.patchbrief.org/items/2026-06-litespeed-cve-2026-54420.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-06-litespeed-cve-2026-54420.html</guid>
      <pubDate>Mon, 15 Jun 2026 00:00:00 +0000</pubDate>
      <description>LiteSpeed cPanel plugin contains a UNIX symbolic link (Symlink) following vulnerability that could allow a user with FTP or web shell access on a shared hosting server running CloudLinux/CageFS.</description>
    </item>
    <item>
      <title>Oracle PeopleSoft Enterprise PeopleTools Missing Authentication for Critical Function Vulnerability</title>
      <link>https://www.patchbrief.org/items/2026-06-oracle-cve-2026-35273.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-06-oracle-cve-2026-35273.html</guid>
      <pubDate>Fri, 12 Jun 2026 00:00:00 +0000</pubDate>
      <description>Oracle PeopleSoft Enterprise PeopleTools contains a missing authentication for critical function vulnerability which could allow an unauthenticated attacker to obtain takeover of PeopleSoft Enterprise PeopleTools.</description>
    </item>
    <item>
      <title>Ivanti Sentry OS Command Injection Vulnerability</title>
      <link>https://www.patchbrief.org/items/2026-06-ivanti-cve-2026-10520.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-06-ivanti-cve-2026-10520.html</guid>
      <pubDate>Thu, 11 Jun 2026 00:00:00 +0000</pubDate>
      <description>Ivanti Sentry (formerly known as MobileIron Sentry) contains an OS command injection vulnerability which could allow a remote unauthenticated user to achieve root-level remote code execution. This vulnerability can be successfully exploited in cases where the Sentry appliance is in an unmanaged state with its endpoints externally reachable. The use of mTLS with EPMM or restricted HTTPS access through Neurons for MDM makes interfaces inaccessible to external actors.</description>
    </item>
    <item>
      <title>VU#862559: crypton-x509-validation Haskell libraries do not enforce X.509 NameConstraints</title>
      <link>https://www.patchbrief.org/items/2026-06-multiple-vendors-vu-862559.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-06-multiple-vendors-vu-862559.html</guid>
      <pubDate>Thu, 11 Jun 2026 00:00:00 +0000</pubDate>
      <description>Overview A vulnerability has been discovered in the Haskell TLS software stack, commonly used by applications built in the Haskell programming language to securely connect to servers over the internet. Specifically, the libraries "crypton-x509-validation" fail to enforce a key security feature called NameConstraints, a standard defined in RFC 5280 that helps organizations control which domains a certificate authority (CA) is allowed to issue certificates for. This vulnerability allows an attacker with access to the sub-CA to create certificates that will validate successfully with any Haskell TLS connection, allowing the attacker access to full session visibility. Version 1.91 for crypton-x509-validation have been released to address the vulnerability, tracked as CVE-2026-9648. Description Haskell is a programming language often used in... Related CVEs: CVE-2026-9648.</description>
    </item>
    <item>
      <title>Arista Extensible Operating System Incomplete Comparison with Missing Factors Vulnerability</title>
      <link>https://www.patchbrief.org/items/2026-06-arista-cve-2026-7473.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-06-arista-cve-2026-7473.html</guid>
      <pubDate>Tue, 09 Jun 2026 00:00:00 +0000</pubDate>
      <description>Arista Extensible Operating System (EOS) contains an incomplete comparison with missing factors vulnerability when the switch incorrectly decapsulate and forwards other unexpected tunneled packet with a destination IP matching its configured decapsulation IP.</description>
    </item>
    <item>
      <title>Cisco Catalyst SD-WAN Manager Improper Encoding or Escaping of Output Vulnerability</title>
      <link>https://www.patchbrief.org/items/2026-06-cisco-cve-2026-20245.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-06-cisco-cve-2026-20245.html</guid>
      <pubDate>Tue, 09 Jun 2026 00:00:00 +0000</pubDate>
      <description>Cisco Catalyst SD-WAN Manager formerly SD-WAN vManage contains an improper encoding or escaping of output vulnerability. This vulnerability could allow an authenticated, local attacker to execute arbitrary commands as root by supplying a crafted file to the affected system.</description>
    </item>
    <item>
      <title>Google Chromium V8 Out-of-Bounds Read and Write Vulnerability</title>
      <link>https://www.patchbrief.org/items/2026-06-google-cve-2026-11645.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-06-google-cve-2026-11645.html</guid>
      <pubDate>Tue, 09 Jun 2026 00:00:00 +0000</pubDate>
      <description>Google Chromium V8 out-of-bounds read and write vulnerability that could allow a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.</description>
    </item>
    <item>
      <title>Azure Bot Service Elevation of Privilege Vulnerability</title>
      <link>https://www.patchbrief.org/items/2026-06-microsoft-cve-2026-32174.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-06-microsoft-cve-2026-32174.html</guid>
      <pubDate>Tue, 09 Jun 2026 00:00:00 +0000</pubDate>
      <description>Improper authentication in Azure Bot Service allows an authorized attacker to elevate privileges over a network. Published in June 2026 Security Updates. MSRC exploitability: Publicly Disclosed:No;Exploited:No.</description>
    </item>
    <item>
      <title>Microsoft Edge (Chromium-based) Spoofing Vulnerability</title>
      <link>https://www.patchbrief.org/items/2026-06-microsoft-cve-2026-32208.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-06-microsoft-cve-2026-32208.html</guid>
      <pubDate>Tue, 09 Jun 2026 00:00:00 +0000</pubDate>
      <description>Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Edge (Chromium-based) allows an authorized attacker to perform spoofing over a network. Published in June 2026 Security Updates. MSRC exploitability: Publicly Disclosed:No;Exploited:No;Latest Software Release:N/A.</description>
    </item>
    <item>
      <title>Microsoft Copilot Tampering Vulnerability</title>
      <link>https://www.patchbrief.org/items/2026-06-microsoft-cve-2026-42895.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-06-microsoft-cve-2026-42895.html</guid>
      <pubDate>Tue, 09 Jun 2026 00:00:00 +0000</pubDate>
      <description>Improper neutralization of special elements used in a command ('command injection') in Microsoft Copilot allows an unauthorized attacker to perform tampering over a network. Published in June 2026 Security Updates. MSRC exploitability: Publicly Disclosed:No;Exploited:No;Latest Software Release:N/A.</description>
    </item>
    <item>
      <title>Microsoft Office Remote Code Execution Vulnerability</title>
      <link>https://www.patchbrief.org/items/2026-06-microsoft-cve-2026-45472.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-06-microsoft-cve-2026-45472.html</guid>
      <pubDate>Tue, 09 Jun 2026 00:00:00 +0000</pubDate>
      <description>Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally. Published in June 2026 Security Updates. MSRC exploitability: Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation Less Likely.</description>
    </item>
    <item>
      <title>Microsoft Office Remote Code Execution Vulnerability</title>
      <link>https://www.patchbrief.org/items/2026-06-microsoft-cve-2026-45474.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-06-microsoft-cve-2026-45474.html</guid>
      <pubDate>Tue, 09 Jun 2026 00:00:00 +0000</pubDate>
      <description>Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally. Published in June 2026 Security Updates. MSRC exploitability: Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation Less Likely.</description>
    </item>
    <item>
      <title>Azure Active Directory Elevation of Privilege Vulnerability</title>
      <link>https://www.patchbrief.org/items/2026-06-microsoft-cve-2026-45480.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-06-microsoft-cve-2026-45480.html</guid>
      <pubDate>Tue, 09 Jun 2026 00:00:00 +0000</pubDate>
      <description>Improper authentication in Azure Active Directory allows an unauthorized attacker to elevate privileges over a network. Published in June 2026 Security Updates. MSRC exploitability: Publicly Disclosed:No;Exploited:No;Latest Software Release:N/A.</description>
    </item>
    <item>
      <title>Microsoft Cost Management Information Disclosure Vulnerability</title>
      <link>https://www.patchbrief.org/items/2026-06-microsoft-cve-2026-47633.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-06-microsoft-cve-2026-47633.html</guid>
      <pubDate>Tue, 09 Jun 2026 00:00:00 +0000</pubDate>
      <description>Exposure of sensitive information to an unauthorized actor in Cost Management Interactive Experiences allows an unauthorized attacker to disclose information over a network. Published in June 2026 Security Updates. MSRC exploitability: Publicly Disclosed:No;Exploited:No;Latest Software Release:N/A.</description>
    </item>
    <item>
      <title>Copilot Chat (Microsoft Edge) Information Disclosure Vulnerability</title>
      <link>https://www.patchbrief.org/items/2026-06-microsoft-cve-2026-47644.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-06-microsoft-cve-2026-47644.html</guid>
      <pubDate>Tue, 09 Jun 2026 00:00:00 +0000</pubDate>
      <description>Improper neutralization of special elements in output used by a downstream component ('injection') in Copilot Chat (Microsoft Edge) allows an unauthorized attacker to disclose information over a network. Published in June 2026 Security Updates. MSRC exploitability: Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation Less Likely.</description>
    </item>
    <item>
      <title>Microsoft Graph Information Disclosure Vulnerability</title>
      <link>https://www.patchbrief.org/items/2026-06-microsoft-cve-2026-47655.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-06-microsoft-cve-2026-47655.html</guid>
      <pubDate>Tue, 09 Jun 2026 00:00:00 +0000</pubDate>
      <description>Exposure of sensitive information to an unauthorized actor in Microsoft Graph allows an authorized attacker to disclose information over a network. Published in June 2026 Security Updates. MSRC exploitability: Publicly Disclosed:No;Exploited:No;Latest Software Release:N/A.</description>
    </item>
    <item>
      <title>M365 Copilot Information Disclosure Vulnerability</title>
      <link>https://www.patchbrief.org/items/2026-06-microsoft-cve-2026-54130.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-06-microsoft-cve-2026-54130.html</guid>
      <pubDate>Tue, 09 Jun 2026 00:00:00 +0000</pubDate>
      <description>Missing authentication for critical function in M365 Copilot allows an unauthorized attacker to disclose information over a network. Published in June 2026 Security Updates. MSRC exploitability: Publicly Disclosed:No;Exploited:No;Latest Software Release:N/A.</description>
    </item>
    <item>
      <title>VU#616257: Microsoft-signed UEFI shim bootloaders vulnerable to Secure Boot bypass</title>
      <link>https://www.patchbrief.org/items/2026-06-uefi-vu-616257.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-06-uefi-vu-616257.html</guid>
      <pubDate>Tue, 09 Jun 2026 00:00:00 +0000</pubDate>
      <description>Overview Microsoft-signed UEFI bootloaders of the open-source shim project, primarily from version 0.9 and earlier, were identified as vulnerable to Secure Boot bypass. To mitigate this risk, the affected bootloaders will be added to the Microsoft UEFI Forbidden Signature Database (DBX). Once the DBX update is applied, these bootloaders will no longer be trusted for execution during the boot process. An attacker could exploit these vulnerable shim bootloaders using a Bring Your Own Vulnerable Driver (BYOVD)-style technique to execute arbitrary code during the early boot phase, prior to operating system initialization, thereby bypassing Secure Boot protections. Description The Unified Extensible Firmware Interface (UEFI) standard defines the modern firmware architecture used to initialize hardware and transfer control to the operating... Related CVEs: CVE-2026-10797, CVE-2026-8863.</description>
    </item>
    <item>
      <title>BerriAI LiteLLM Command Injection Vulnerability</title>
      <link>https://www.patchbrief.org/items/2026-06-berriai-cve-2026-42271.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-06-berriai-cve-2026-42271.html</guid>
      <pubDate>Mon, 08 Jun 2026 00:00:00 +0000</pubDate>
      <description>BerriAI LiteLLM contains a command injection vulnerability that could allow any authenticated user, including holders of low-privilege internal-user keys, to run arbitrary commands on the host.</description>
    </item>
    <item>
      <title>Check Point Security Gateway Improper Authentication Vulnerability</title>
      <link>https://www.patchbrief.org/items/2026-06-check-point-cve-2026-50751.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-06-check-point-cve-2026-50751.html</guid>
      <pubDate>Mon, 08 Jun 2026 00:00:00 +0000</pubDate>
      <description>Check Point Security Gateway contains an improper authentication vulnerability in IKEv1 key exchange that could allow an unauthenticated remote attacker to bypass user authentication and establish a remote access VPN connection without a valid user password.</description>
    </item>
    <item>
      <title>SolarWinds Serv-U Uncontrolled Resource Consumption Vulnerability</title>
      <link>https://www.patchbrief.org/items/2026-06-solarwinds-cve-2026-28318.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-06-solarwinds-cve-2026-28318.html</guid>
      <pubDate>Fri, 05 Jun 2026 00:00:00 +0000</pubDate>
      <description>SolarWinds Serv-U contains an uncontrolled resource consumption vulnerability that allows specially crafted POST requests using the Content-Encoding: deflate header to crash the Serv-U service without authentication.</description>
    </item>
    <item>
      <title>Mirasvit Full Page Cache Warmer Deserialization of Untrusted Data Vulnerability</title>
      <link>https://www.patchbrief.org/items/2026-06-mirasvit-cve-2026-45247.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-06-mirasvit-cve-2026-45247.html</guid>
      <pubDate>Wed, 03 Jun 2026 00:00:00 +0000</pubDate>
      <description>Mirasvit Full Page Cache Warmer contains a deserialization of untrusted data vulnerability that could allow unauthenticated attackers to achieve remote code execution by supplying a crafted serialized PHP object in the CacheWarmer cookie.</description>
    </item>
    <item>
      <title>VU#595768: Securly Chrome Extension contains multiple weak encryption and access control vulnerabilities</title>
      <link>https://www.patchbrief.org/items/2026-06-securly-vu-595768.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-06-securly-vu-595768.html</guid>
      <pubDate>Wed, 03 Jun 2026 00:00:00 +0000</pubDate>
      <description>Overview Version 3.0.7 of the Securly Chrome Extension contains multiple vulnerabilities involving insecure data transmission, weak cryptography, and improper access control. These issues may expose sensitive filtering rules, enable the manipulation of downloaded configuration files, and allow unauthenticated access to protected resources. An attacker could exploit these weakness to steal configuration information, induce a Denial of Service (DoS), or modify content blocking rules for student users. Description The Securly Chrome Extension is a browser add-on commonly used in K–12 school-managed Chromebooks to enforce internet safety policies, filter or block websites, and provide activity monitoring for students. It is an element of the Securly classroom management platform, which helps schools comply with web filtering requirements and... Related CVEs: CVE-2026-8874, CVE-2026-8876, CVE-2026-8878, CVE-2026-8879.</description>
    </item>
    <item>
      <title>Android Framework Integer Overflow Vulnerability</title>
      <link>https://www.patchbrief.org/items/2026-06-android-cve-2025-48595.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-06-android-cve-2025-48595.html</guid>
      <pubDate>Tue, 02 Jun 2026 00:00:00 +0000</pubDate>
      <description>Android Framework contains an integer overflow vulnerability that allows for code execution that could allow for local privilege escalation.</description>
    </item>
    <item>
      <title>VU#265691: Appsmiths SQL Query autocomplete renderer contains a cross site scripting vulnerability</title>
      <link>https://www.patchbrief.org/items/2026-06-appsmiths-vu-265691.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-06-appsmiths-vu-265691.html</guid>
      <pubDate>Tue, 02 Jun 2026 00:00:00 +0000</pubDate>
      <description>Overview A stored cross-site scripting (XSS) vulnerability has been discovered in Appsmith, specifically in the CodeMirror based SQL query editor’s autocomplete renderer. CVE-2026-7299 has been assigned to track the vulnerability. An attacker with developer level access to a shared PostgreSQL datasource can inject arbitrary JavaScript by creating malicious database objects whose names contain XSS payloads. Successful exploitation leads to arbitrary JavaScript execution in the browser of any workspace member who triggers SQL autocomplete, enabling session hijacking, privilege escalation, or credential theft. Version 2.1 of Appsmith fixes CVE-2026-7299. Description Appsmith is an open source, low code platform intended to allow developers to build internal tools, dashboards, and applications using a UI builder, database and API... Related CVEs: CVE-2026-7299.</description>
    </item>
    <item>
      <title>VU#873170: Collibra Agent contains improper authentication and path traversal vulnerabilities</title>
      <link>https://www.patchbrief.org/items/2026-06-collibra-vu-873170.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-06-collibra-vu-873170.html</guid>
      <pubDate>Tue, 02 Jun 2026 00:00:00 +0000</pubDate>
      <description>Overview The Collibra Platform Agent contains vulnerabilities that can be chained by a remote, unauthenticated attacker to achieve remote code execution. An attacker can exploit these issues by uploading a crafted ZIP archive that writes attacker-controlled files to arbitrary locations on the server once extracted, resulting in code execution. Description Collibra Platform (CP) and Collibra Platform Self-Hosted (CPSH), an enterprise grade, cloud-based platform designed to help organizations locate, understand, trust, and manage their data assets. The Collibra Agent of CP and CPSH that is installed on the host system is an independent service that listens on different port than the web interface and have the following vulnerabilities. CVE-2026-10622 Privileged REST endpoints exposed under /rest/* do not properly enforce authentication or... Related CVEs: CVE-2026-10621, CVE-2026-10622.</description>
    </item>
    <item>
      <title>Linux Kernel Improper Authentication Vulnerability</title>
      <link>https://www.patchbrief.org/items/2026-06-linux-cve-2022-0492.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-06-linux-cve-2022-0492.html</guid>
      <pubDate>Tue, 02 Jun 2026 00:00:00 +0000</pubDate>
      <description>Linux Kernel contains an improper authentication vulnerability which could allow for privilege escalation via the cgroups v1 release_agent feature.</description>
    </item>
    <item>
      <title>VU#615987: Missing IPsec Integrity Protection for IMS SIP Signaling in Verizon VoLTE Deployments</title>
      <link>https://www.patchbrief.org/items/2026-06-verizon-vu-615987.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-06-verizon-vu-615987.html</guid>
      <pubDate>Tue, 02 Jun 2026 00:00:00 +0000</pubDate>
      <description>Overview VoLTE deployments on Verizon’s IMS network have operated without negotiated SIP integrity protection. In observed test conditions, SIP signaling—including registration, call setup, and messaging—traveled without IPsec ESP encapsulation and without SIP Security Agreement headers, exposing it to interception and modification by on-path attackers. Recent carrier configuration updates, including Apple’s iOS 26.5 carrier bundle released on May 11, 2026, include IMS IPsec–related settings. However, such configuration entries do not confirm active deployment, successful negotiation, or functional protection in production. Description CVE-2026-10629 Verizon IMS deployments were observed transmitting SIP signaling without integrity protection. REGISTER exchanges lacked Security-Client, Security-Server, and Security-Verify headers, and no... Related CVEs: CVE-2026-10629.</description>
    </item>
    <item>
      <title>Oracle WebLogic Server Unspecified Vulnerability</title>
      <link>https://www.patchbrief.org/items/2026-06-oracle-cve-2024-21182.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-06-oracle-cve-2024-21182.html</guid>
      <pubDate>Mon, 01 Jun 2026 00:00:00 +0000</pubDate>
      <description>Oracle WebLogic contains an unspecified vulnerability that could allow an unauthenticated attacker with network access via T3, IIOP to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle WebLogic Server accessible data.</description>
    </item>
    <item>
      <title>Palo Alto Networks PAN-OS Authentication Bypass Vulnerability</title>
      <link>https://www.patchbrief.org/items/2026-05-palo-alto-networks-cve-2026-0257.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-05-palo-alto-networks-cve-2026-0257.html</guid>
      <pubDate>Fri, 29 May 2026 00:00:00 +0000</pubDate>
      <description>Palo Alto Networks PAN-OS contains an authentication bypass vulnerability that allows attackers to bypass security restrictions and establish an unauthorized VPN connection.</description>
    </item>
    <item>
      <title>Daemon Tools Lite Embedded Malicious Code Vulnerability</title>
      <link>https://www.patchbrief.org/items/2026-05-daemon-cve-2026-8398.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-05-daemon-cve-2026-8398.html</guid>
      <pubDate>Wed, 27 May 2026 00:00:00 +0000</pubDate>
      <description>Daemon Tools contains an unspecified vulnerability that has a high impact on confidentiality, integrity, and availability.</description>
    </item>
    <item>
      <title>Nx Console Embedded Malicious Code Vulnerability</title>
      <link>https://www.patchbrief.org/items/2026-05-nx-cve-2026-48027.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-05-nx-cve-2026-48027.html</guid>
      <pubDate>Wed, 27 May 2026 00:00:00 +0000</pubDate>
      <description>Nx Console contains an embedded malicious code vulnerability that allowed a malicious version of Nx Console to be published. The compromised extension fetched an obfuscated payload that could harvested credentials from multiple sources on disk and in memory.</description>
    </item>
    <item>
      <title>TanStack Unspecified Vulnerability</title>
      <link>https://www.patchbrief.org/items/2026-05-tanstack-cve-2026-45321.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-05-tanstack-cve-2026-45321.html</guid>
      <pubDate>Wed, 27 May 2026 00:00:00 +0000</pubDate>
      <description>TanStack contains an unspecified vulnerability that allowed malicious versions of the product to be published to the npm registry to publish credential-stealing malware under a trusted identity.</description>
    </item>
    <item>
      <title>LiteSpeed cPanel Plugin Privilege Escalation Vulnerability</title>
      <link>https://www.patchbrief.org/items/2026-05-litespeed-cve-2026-48172.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-05-litespeed-cve-2026-48172.html</guid>
      <pubDate>Tue, 26 May 2026 00:00:00 +0000</pubDate>
      <description>LiteSpeed cPanel Plugin contains privilege escalation vulnerability that is exposed via the user-end cPanel plugin, which can be abused by any cPanel user account to execute arbitrary scripts with root privileges.</description>
    </item>
    <item>
      <title>Drupal Core SQL Injection Vulnerability</title>
      <link>https://www.patchbrief.org/items/2026-05-drupal-cve-2026-9082.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-05-drupal-cve-2026-9082.html</guid>
      <pubDate>Fri, 22 May 2026 00:00:00 +0000</pubDate>
      <description>Drupal Core contains a SQL injection vulnerability that could allow for privilege escalation and remote code execution via specially crafted requests sent with the database abstraction API.</description>
    </item>
    <item>
      <title>Langflow Origin Validation Error Vulnerability</title>
      <link>https://www.patchbrief.org/items/2026-05-langflow-cve-2025-34291.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-05-langflow-cve-2025-34291.html</guid>
      <pubDate>Thu, 21 May 2026 00:00:00 +0000</pubDate>
      <description>Langflow contains an origin validation error vulnerability in which an overly permissive CORS configuration combined with a refresh token cookie configured as SameSite=None allows a malicious webpage to perform cross-origin requests that include credentials and successfully call the refresh endpoint. This could allow the attacker to execute arbitrary code and achieve full system compromise via obtained tokens that permit access to authenticated endpoints.</description>
    </item>
    <item>
      <title>Trend Micro Apex One (On-Premise) Directory Traversal Vulnerability</title>
      <link>https://www.patchbrief.org/items/2026-05-trend-micro-cve-2026-34926.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-05-trend-micro-cve-2026-34926.html</guid>
      <pubDate>Thu, 21 May 2026 00:00:00 +0000</pubDate>
      <description>Trend Micro Apex One (on-premise) contains a directory traversal vulnerability that could allow a pre-authenticated local attacker to modify a key table on the server to inject malicious code to deploy to agents on affected installations.</description>
    </item>
    <item>
      <title>Adobe Acrobat and Reader Heap-Based Buffer Overflow Vulnerability</title>
      <link>https://www.patchbrief.org/items/2026-05-adobe-cve-2009-3459.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-05-adobe-cve-2009-3459.html</guid>
      <pubDate>Wed, 20 May 2026 00:00:00 +0000</pubDate>
      <description>Adobe Acrobat and Reader contain a heap-based buffer overflow vulnerability which could allow remote attackers to execute arbitrary code via a crafted PDF file that triggers memory corruption.</description>
    </item>
    <item>
      <title>Microsoft Windows Buffer Overflow Vulnerability</title>
      <link>https://www.patchbrief.org/items/2026-05-microsoft-cve-2008-4250.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-05-microsoft-cve-2008-4250.html</guid>
      <pubDate>Wed, 20 May 2026 00:00:00 +0000</pubDate>
      <description>Microsoft Windows contains a buffer overflow vulnerability in the Windows Server Service that allows remote attackers to execute arbitrary code via a crafted RPC request that triggers an overflow during path canonicalization.</description>
    </item>
    <item>
      <title>Microsoft DirectX NULL Byte Overwrite Vulnerability</title>
      <link>https://www.patchbrief.org/items/2026-05-microsoft-cve-2009-1537.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-05-microsoft-cve-2009-1537.html</guid>
      <pubDate>Wed, 20 May 2026 00:00:00 +0000</pubDate>
      <description>Microsoft DirectX contains a NULL byte overwrite vulnerability in the QuickTime Movie Parser Filter in quartz.dll in DirectShow which could allow remote attackers to execute arbitrary code via a crafted QuickTime media file.</description>
    </item>
    <item>
      <title>Microsoft Internet Explorer Use-After-Free Vulnerability</title>
      <link>https://www.patchbrief.org/items/2026-05-microsoft-cve-2010-0249.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-05-microsoft-cve-2010-0249.html</guid>
      <pubDate>Wed, 20 May 2026 00:00:00 +0000</pubDate>
      <description>Microsoft Internet Explorer contains an use-after-free vulnerability that could allow remote attackers to execute arbitrary code by accessing a pointer associated with a deleted object. The impacted product could be end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue product utilization.</description>
    </item>
    <item>
      <title>Microsoft Internet Explorer Use-After-Free Vulnerability</title>
      <link>https://www.patchbrief.org/items/2026-05-microsoft-cve-2010-0806.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-05-microsoft-cve-2010-0806.html</guid>
      <pubDate>Wed, 20 May 2026 00:00:00 +0000</pubDate>
      <description>Microsoft Internet Explorer contains an use-after-free vulnerability that could allow remote attackers to execute arbitrary code via vectors involving access to an invalid pointer after the deletion of an object. The impacted product could be end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue product utilization.</description>
    </item>
    <item>
      <title>Microsoft Defender Link Following Vulnerability</title>
      <link>https://www.patchbrief.org/items/2026-05-microsoft-cve-2026-41091.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-05-microsoft-cve-2026-41091.html</guid>
      <pubDate>Wed, 20 May 2026 00:00:00 +0000</pubDate>
      <description>Microsoft Defender contains a link following vulnerability that allows an authorized attacker to elevate privileges locally.</description>
    </item>
    <item>
      <title>Microsoft Defender Denial of Service Vulnerability</title>
      <link>https://www.patchbrief.org/items/2026-05-microsoft-cve-2026-45498.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-05-microsoft-cve-2026-45498.html</guid>
      <pubDate>Wed, 20 May 2026 00:00:00 +0000</pubDate>
      <description>Microsoft Defender contains an unspecified vulnerability that allows for denial of service.</description>
    </item>
    <item>
      <title>Microsoft Exchange Server Cross-Site Scripting Vulnerability</title>
      <link>https://www.patchbrief.org/items/2026-05-microsoft-cve-2026-42897.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-05-microsoft-cve-2026-42897.html</guid>
      <pubDate>Fri, 15 May 2026 00:00:00 +0000</pubDate>
      <description>Microsoft Exchange Server contains a cross-site scripting vulnerability during web page generation in Outlook Web Access and when certain interaction conditions are met, arbitrary JavaScript can be executed in the browser context.</description>
    </item>
    <item>
      <title>Cisco Catalyst SD-WAN Controller Authentication Bypass Vulnerability</title>
      <link>https://www.patchbrief.org/items/2026-05-cisco-cve-2026-20182.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-05-cisco-cve-2026-20182.html</guid>
      <pubDate>Thu, 14 May 2026 00:00:00 +0000</pubDate>
      <description>Cisco Catalyst SD-WAN Controller &amp; Manager contain an authentication bypass vulnerability that allows an unauthenticated, remote attacker to bypass authentication and obtain administrative privileges on an affected system.</description>
    </item>
    <item>
      <title>BerriAI LiteLLM SQL Injection Vulnerability</title>
      <link>https://www.patchbrief.org/items/2026-05-berriai-cve-2026-42208.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-05-berriai-cve-2026-42208.html</guid>
      <pubDate>Fri, 08 May 2026 00:00:00 +0000</pubDate>
      <description>BerriAI LiteLLM contains a SQL injection vulnerability that allows an attacker to read data from the proxy's database and potentially modify it, leading to unauthorized access to the proxy and the credentials it manages.</description>
    </item>
    <item>
      <title>Ivanti Endpoint Manager Mobile (EPMM) Improper Input Validation Vulnerability</title>
      <link>https://www.patchbrief.org/items/2026-05-ivanti-cve-2026-6973.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-05-ivanti-cve-2026-6973.html</guid>
      <pubDate>Thu, 07 May 2026 00:00:00 +0000</pubDate>
      <description>Ivanti Endpoint Manager Mobile (EPMM) contains an improper input validation vulnerability that allows a remotely authenticated user with administrative access to achieve remote code execution.</description>
    </item>
    <item>
      <title>Palo Alto Networks PAN-OS Out-of-bounds Write Vulnerability</title>
      <link>https://www.patchbrief.org/items/2026-05-palo-alto-networks-cve-2026-0300.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-05-palo-alto-networks-cve-2026-0300.html</guid>
      <pubDate>Wed, 06 May 2026 00:00:00 +0000</pubDate>
      <description>Palo Alto Networks PAN-OS contains an out-of-bounds write vulnerability in the User-ID Authentication Portal (aka Captive Portal) service that can allow an unauthenticated attacker to execute arbitrary code with root privileges on the PA-Series and VM-Series firewalls by sending specially crafted packets.</description>
    </item>
    <item>
      <title>Linux Kernel Incorrect Resource Transfer Between Spheres Vulnerability</title>
      <link>https://www.patchbrief.org/items/2026-05-linux-cve-2026-31431.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-05-linux-cve-2026-31431.html</guid>
      <pubDate>Fri, 01 May 2026 00:00:00 +0000</pubDate>
      <description>Linux Kernel contains an incorrect resource transfer between spheres vulnerability that could allow for privilege escalation.</description>
    </item>
    <item>
      <title>WebPros cPanel &amp; WHM and WP2 (WordPress Squared) Missing Authentication for Critical Function Vulnerability</title>
      <link>https://www.patchbrief.org/items/2026-04-webpros-cve-2026-41940.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-04-webpros-cve-2026-41940.html</guid>
      <pubDate>Thu, 30 Apr 2026 00:00:00 +0000</pubDate>
      <description>WebPros cPanel &amp; WHM (WebHost Manager) and WP2 (WordPress Squared) contain an authentication bypass vulnerability in the login flow that allows unauthenticated remote attackers to gain unauthorized access to the control panel.</description>
    </item>
    <item>
      <title>ConnectWise ScreenConnect Path Traversal Vulnerability</title>
      <link>https://www.patchbrief.org/items/2026-04-connectwise-cve-2024-1708.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-04-connectwise-cve-2024-1708.html</guid>
      <pubDate>Tue, 28 Apr 2026 00:00:00 +0000</pubDate>
      <description>ConnectWise ScreenConnect contains a path traversal vulnerability which could allow an attacker to execute remote code or directly impact confidential data and critical systems.</description>
    </item>
    <item>
      <title>Microsoft Windows Protection Mechanism Failure Vulnerability</title>
      <link>https://www.patchbrief.org/items/2026-04-microsoft-cve-2026-32202.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-04-microsoft-cve-2026-32202.html</guid>
      <pubDate>Tue, 28 Apr 2026 00:00:00 +0000</pubDate>
      <description>Microsoft Windows Shell contains a protection mechanism failure vulnerability that allows an unauthorized attacker to perform spoofing over a network.</description>
    </item>
    <item>
      <title>D-Link DIR-823X Command Injection Vulnerability</title>
      <link>https://www.patchbrief.org/items/2026-04-d-link-cve-2025-29635.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-04-d-link-cve-2025-29635.html</guid>
      <pubDate>Fri, 24 Apr 2026 00:00:00 +0000</pubDate>
      <description>D-Link DIR-823X contains a command injection vulnerability that allows an authorized attacker to execute arbitrary commands on remote devices by sending a POST request to /goform/set_prohibiting via the corresponding function. The impacted product could be end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue product utilization.</description>
    </item>
    <item>
      <title>Samsung MagicINFO 9 Server Path Traversal Vulnerability</title>
      <link>https://www.patchbrief.org/items/2026-04-samsung-cve-2024-7399.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-04-samsung-cve-2024-7399.html</guid>
      <pubDate>Fri, 24 Apr 2026 00:00:00 +0000</pubDate>
      <description>Samsung MagicINFO 9 Server contains a path traversal vulnerability that could allow an attacker to write arbitrary files as system authority.</description>
    </item>
    <item>
      <title>SimpleHelp Missing Authorization Vulnerability</title>
      <link>https://www.patchbrief.org/items/2026-04-simplehelp-cve-2024-57726.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-04-simplehelp-cve-2024-57726.html</guid>
      <pubDate>Fri, 24 Apr 2026 00:00:00 +0000</pubDate>
      <description>SimpleHelp contains a missing authorization vulnerability that could allow low-privileged technicians to create API keys with excessive permissions. These API keys can be used to escalate privileges to the server admin role.</description>
    </item>
    <item>
      <title>SimpleHelp Path Traversal Vulnerability</title>
      <link>https://www.patchbrief.org/items/2026-04-simplehelp-cve-2024-57728.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-04-simplehelp-cve-2024-57728.html</guid>
      <pubDate>Fri, 24 Apr 2026 00:00:00 +0000</pubDate>
      <description>SimpleHelp contains a path traversal vulnerability that allows admin users to upload arbitrary files anywhere on the file system by uploading a crafted zip file (i.e. zip slip). This can be exploited to execute arbitrary code on the host in the context of the SimpleHelp server user.</description>
    </item>
    <item>
      <title>Marimo Remote Code Execution Vulnerability</title>
      <link>https://www.patchbrief.org/items/2026-04-marimo-cve-2026-39987.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-04-marimo-cve-2026-39987.html</guid>
      <pubDate>Thu, 23 Apr 2026 00:00:00 +0000</pubDate>
      <description>Marimo contains an pre-authorization remote code execution vulnerability, allowing an unauthenticated attacked to shell access and execute arbitrary system commands.</description>
    </item>
    <item>
      <title>Microsoft Defender Insufficient Granularity of Access Control Vulnerability</title>
      <link>https://www.patchbrief.org/items/2026-04-microsoft-cve-2026-33825.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-04-microsoft-cve-2026-33825.html</guid>
      <pubDate>Wed, 22 Apr 2026 00:00:00 +0000</pubDate>
      <description>Microsoft Defender contains an insufficient granularity of access control vulnerability that could allow an authorized attacker to escalate privileges locally.</description>
    </item>
    <item>
      <title>Cisco Catalyst SD-WAN Manager Incorrect Use of Privileged APIs Vulnerability</title>
      <link>https://www.patchbrief.org/items/2026-04-cisco-cve-2026-20122.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-04-cisco-cve-2026-20122.html</guid>
      <pubDate>Mon, 20 Apr 2026 00:00:00 +0000</pubDate>
      <description>Cisco Catalyst SD-WAN Manager contains an incorrect use of privileged APIs vulnerability due to improper file handling on the API interface of an affected system. An attacker could exploit this vulnerability by uploading a malicious file on the local file system. A successful exploit could allow the attacker to overwrite arbitrary files on the affected system and gain vmanage user privileges.</description>
    </item>
    <item>
      <title>Cisco Catalyst SD-WAN Manager Storing Passwords in a Recoverable Format Vulnerability</title>
      <link>https://www.patchbrief.org/items/2026-04-cisco-cve-2026-20128.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-04-cisco-cve-2026-20128.html</guid>
      <pubDate>Mon, 20 Apr 2026 00:00:00 +0000</pubDate>
      <description>Cisco Catalyst SD-WAN Manager contains a storing passwords in a recoverable format vulnerability that allows an authenticated, local attacker to gain DCA user privileges by accessing a credential file for the DCA user on the filesystem as a low-privileged user.</description>
    </item>
    <item>
      <title>Cisco Catalyst SD-WAN Manager Exposure of Sensitive Information to an Unauthorized Actor Vulnerability</title>
      <link>https://www.patchbrief.org/items/2026-04-cisco-cve-2026-20133.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-04-cisco-cve-2026-20133.html</guid>
      <pubDate>Mon, 20 Apr 2026 00:00:00 +0000</pubDate>
      <description>Cisco Catalyst SD-WAN Manager contains an exposure of sensitive information to an unauthorized actor vulnerability that could allow remote attackers to view sensitive information on affected systems.</description>
    </item>
    <item>
      <title>JetBrains TeamCity Relative Path Traversal Vulnerability</title>
      <link>https://www.patchbrief.org/items/2026-04-jetbrains-cve-2024-27199.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-04-jetbrains-cve-2024-27199.html</guid>
      <pubDate>Mon, 20 Apr 2026 00:00:00 +0000</pubDate>
      <description>JetBrains TeamCity contains a relative path traversal vulnerability that could allow limited admin actions to be performed.</description>
    </item>
    <item>
      <title>Kentico Xperience Path Traversal Vulnerability</title>
      <link>https://www.patchbrief.org/items/2026-04-kentico-cve-2025-2749.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-04-kentico-cve-2025-2749.html</guid>
      <pubDate>Mon, 20 Apr 2026 00:00:00 +0000</pubDate>
      <description>Kentico Xperience contains a path traversal vulnerability that could allow an authenticated user's Staging Sync Server to upload arbitrary data to path relative locations.</description>
    </item>
    <item>
      <title>PaperCut NG/MF Improper Authentication Vulnerability</title>
      <link>https://www.patchbrief.org/items/2026-04-papercut-cve-2023-27351.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-04-papercut-cve-2023-27351.html</guid>
      <pubDate>Mon, 20 Apr 2026 00:00:00 +0000</pubDate>
      <description>PaperCut NG/MF contains an improper authentication vulnerability that could allow remote attackers to bypass authentication on affected installations via the SecurityRequestFilter class.</description>
    </item>
    <item>
      <title>Quest KACE Systems Management Appliance (SMA) Improper Authentication Vulnerability</title>
      <link>https://www.patchbrief.org/items/2026-04-quest-cve-2025-32975.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-04-quest-cve-2025-32975.html</guid>
      <pubDate>Mon, 20 Apr 2026 00:00:00 +0000</pubDate>
      <description>Quest KACE Systems Management Appliance (SMA) contains an improper authentication vulnerability that could allow attackers to impersonate legitimate users without valid credentials.</description>
    </item>
    <item>
      <title>Synacor Zimbra Collaboration Suite (ZCS) Cross-site Scripting Vulnerability</title>
      <link>https://www.patchbrief.org/items/2026-04-synacor-cve-2025-48700.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-04-synacor-cve-2025-48700.html</guid>
      <pubDate>Mon, 20 Apr 2026 00:00:00 +0000</pubDate>
      <description>Synacor Zimbra Collaboration Suite (ZCS) contains a cross-site scripting vulnerability that could allow attackers to execute arbitrary JavaScript within the user's session, potentially leading to unauthorized access to sensitive information.</description>
    </item>
    <item>
      <title>Apache ActiveMQ Improper Input Validation Vulnerability</title>
      <link>https://www.patchbrief.org/items/2026-04-apache-cve-2026-34197.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-04-apache-cve-2026-34197.html</guid>
      <pubDate>Thu, 16 Apr 2026 00:00:00 +0000</pubDate>
      <description>Apache ActiveMQ contains an improper input validation vulnerability that allows for code injection.</description>
    </item>
    <item>
      <title>Microsoft Office Remote Code Execution</title>
      <link>https://www.patchbrief.org/items/2026-04-microsoft-cve-2009-0238.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-04-microsoft-cve-2009-0238.html</guid>
      <pubDate>Tue, 14 Apr 2026 00:00:00 +0000</pubDate>
      <description>Microsoft Office Excel contains a remote code execution vulnerability that could allow an attacker to take complete control of an affected system if a user opens a specially crafted Excel file that includes a malformed object.</description>
    </item>
    <item>
      <title>Microsoft SharePoint Server Improper Input Validation Vulnerability</title>
      <link>https://www.patchbrief.org/items/2026-04-microsoft-cve-2026-32201.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-04-microsoft-cve-2026-32201.html</guid>
      <pubDate>Tue, 14 Apr 2026 00:00:00 +0000</pubDate>
      <description>Microsoft SharePoint Server contains an improper input validation vulnerability that allows an unauthorized attacker to perform spoofing over a network.</description>
    </item>
    <item>
      <title>Adobe Acrobat Use-After-Free Vulnerability</title>
      <link>https://www.patchbrief.org/items/2026-04-adobe-cve-2020-9715.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-04-adobe-cve-2020-9715.html</guid>
      <pubDate>Mon, 13 Apr 2026 00:00:00 +0000</pubDate>
      <description>Adobe Acrobat contains a use-after-free vulnerability that allows for code execution</description>
    </item>
    <item>
      <title>Adobe Acrobat and Reader Prototype Pollution Vulnerability</title>
      <link>https://www.patchbrief.org/items/2026-04-adobe-cve-2026-34621.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-04-adobe-cve-2026-34621.html</guid>
      <pubDate>Mon, 13 Apr 2026 00:00:00 +0000</pubDate>
      <description>Adobe Acrobat and Reader contain a prototype pollution vulnerability that allows for arbitrary code execution.</description>
    </item>
    <item>
      <title>Fortinet FortiClient EMS SQL Injection Vulnerability</title>
      <link>https://www.patchbrief.org/items/2026-04-fortinet-cve-2026-21643.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-04-fortinet-cve-2026-21643.html</guid>
      <pubDate>Mon, 13 Apr 2026 00:00:00 +0000</pubDate>
      <description>Fortinet FortiClient EMS contains a SQL injection vulnerability that may allow an unauthenticated attacker to execute unauthorized code or commands via specifically crafted HTTP requests.</description>
    </item>
    <item>
      <title>Microsoft Visual Basic for Applications Insecure Library Loading Vulnerability</title>
      <link>https://www.patchbrief.org/items/2026-04-microsoft-cve-2012-1854.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-04-microsoft-cve-2012-1854.html</guid>
      <pubDate>Mon, 13 Apr 2026 00:00:00 +0000</pubDate>
      <description>Microsoft Visual Basic for Applications (VBA) contains an insecure library loading vulnerability that could allow for remote code execution.</description>
    </item>
    <item>
      <title>Microsoft Exchange Server Deserialization of Untrusted Data Vulnerability</title>
      <link>https://www.patchbrief.org/items/2026-04-microsoft-cve-2023-21529.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-04-microsoft-cve-2023-21529.html</guid>
      <pubDate>Mon, 13 Apr 2026 00:00:00 +0000</pubDate>
      <description>Microsoft Exchange Server contains a deserialization of untrusted data that allows an authenticated attacker to achieve remote code execution.</description>
    </item>
    <item>
      <title>Microsoft Windows Out-of-Bounds Read Vulnerability</title>
      <link>https://www.patchbrief.org/items/2026-04-microsoft-cve-2023-36424.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-04-microsoft-cve-2023-36424.html</guid>
      <pubDate>Mon, 13 Apr 2026 00:00:00 +0000</pubDate>
      <description>Microsoft Windows Common Log File System Driver contains an out-of-bounds read vulnerability that could allow a threat actor for privileges escalation</description>
    </item>
    <item>
      <title>Microsoft Windows Link Following Vulnerability</title>
      <link>https://www.patchbrief.org/items/2026-04-microsoft-cve-2025-60710.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-04-microsoft-cve-2025-60710.html</guid>
      <pubDate>Mon, 13 Apr 2026 00:00:00 +0000</pubDate>
      <description>Microsoft Windows contains a link following vulnerability that allows for privilege escalation</description>
    </item>
    <item>
      <title>Ivanti Endpoint Manager Mobile (EPMM) Code Injection Vulnerability</title>
      <link>https://www.patchbrief.org/items/2026-04-ivanti-cve-2026-1340.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-04-ivanti-cve-2026-1340.html</guid>
      <pubDate>Wed, 08 Apr 2026 00:00:00 +0000</pubDate>
      <description>Ivanti Endpoint Manager Mobile (EPMM) contains a code injection vulnerability that could allow attackers to achieve unauthenticated remote code execution.</description>
    </item>
    <item>
      <title>Fortinet FortiClient EMS Improper Access Control Vulnerability</title>
      <link>https://www.patchbrief.org/items/2026-04-fortinet-cve-2026-35616.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-04-fortinet-cve-2026-35616.html</guid>
      <pubDate>Mon, 06 Apr 2026 00:00:00 +0000</pubDate>
      <description>Fortinet FortiClient EMS contains an improper access control vulnerability that may allow an unauthenticated attacker to execute unauthorized code or commands via crafted requests.</description>
    </item>
    <item>
      <title>TrueConf Client Download of Code Without Integrity Check Vulnerability</title>
      <link>https://www.patchbrief.org/items/2026-04-trueconf-cve-2026-3502.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-04-trueconf-cve-2026-3502.html</guid>
      <pubDate>Thu, 02 Apr 2026 00:00:00 +0000</pubDate>
      <description>TrueConf Client contains a download of code without integrity check vulnerability. An attacker who is able to influence the update delivery path can substitute a tampered update payload. If the payload is executed or installed by the updater, this may result in arbitrary code execution in the context of the updating process or user.</description>
    </item>
    <item>
      <title>Google Dawn Use-After-Free Vulnerability</title>
      <link>https://www.patchbrief.org/items/2026-04-google-cve-2026-5281.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-04-google-cve-2026-5281.html</guid>
      <pubDate>Wed, 01 Apr 2026 00:00:00 +0000</pubDate>
      <description>Google Dawn contains an use-after-free vulnerability that could allow a remote attacker who had compromised the renderer process to execute arbitrary code via a crafted HTML page. This vulnerability could affect multiple Chromium-based products including, but not limited to, Google Chrome, Microsoft Edge, and Opera.</description>
    </item>
    <item>
      <title>Citrix NetScaler Out-of-Bounds Read Vulnerability</title>
      <link>https://www.patchbrief.org/items/2026-03-citrix-cve-2026-3055.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-03-citrix-cve-2026-3055.html</guid>
      <pubDate>Mon, 30 Mar 2026 00:00:00 +0000</pubDate>
      <description>Citrix NetScaler ADC (formerly Citrix ADC), NetScaler Gateway (formerly Citrix Gateway) and NetScaler ADC FIPS and NDcPP contain an out-of-bounds reads vulnerability when configured as a SAML IDP leading to memory overread.</description>
    </item>
    <item>
      <title>F5 BIG-IP Stack-Based Buffer Overflow Vulnerability</title>
      <link>https://www.patchbrief.org/items/2026-03-f5-cve-2025-53521.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-03-f5-cve-2025-53521.html</guid>
      <pubDate>Fri, 27 Mar 2026 00:00:00 +0000</pubDate>
      <description>F5 BIG-IP APM contains a stack-based buffer overflow vulnerability that could allow a threat actor to achieve remote code execution.</description>
    </item>
    <item>
      <title>Aquasecurity Trivy Embedded Malicious Code Vulnerability</title>
      <link>https://www.patchbrief.org/items/2026-03-aquasecurity-cve-2026-33634.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-03-aquasecurity-cve-2026-33634.html</guid>
      <pubDate>Thu, 26 Mar 2026 00:00:00 +0000</pubDate>
      <description>Aquasecurity Trivy contains an embedded malicious code vulnerability that could allow an attacker to gain access to everything in the CI/CD environment, including all tokens, SSH keys, cloud credentials, database passwords, and any sensitive configuration in memory.</description>
    </item>
    <item>
      <title>Langflow Code Injection Vulnerability</title>
      <link>https://www.patchbrief.org/items/2026-03-langflow-cve-2026-33017.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-03-langflow-cve-2026-33017.html</guid>
      <pubDate>Wed, 25 Mar 2026 00:00:00 +0000</pubDate>
      <description>Langflow contains a code injection vulnerability that could allow building public flows without requiring authentication.</description>
    </item>
    <item>
      <title>Linuxfoundation Tekton Pipelines — CVE-2026-33211 (Critical)</title>
      <link>https://www.patchbrief.org/items/2026-03-linuxfoundation-cve-2026-33211.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-03-linuxfoundation-cve-2026-33211.html</guid>
      <pubDate>Tue, 24 Mar 2026 00:00:00 +0000</pubDate>
      <description>Tekton Pipelines project provides k8s-style resources for declaring CI/CD-style pipelines. Starting in version 1.0.0 and prior to versions 1.0.1, 1.3.3, 1.6.1, 1.9.2, and 1.10.2, the Tekton Pipelines git resolver is vulnerable to path traversal via the `pathInRepo` parameter. A tenant with permission to create `ResolutionRequests` (e.g. by creating `TaskRuns` or `PipelineRuns` that use the git resolver) can read arbitrary files from the resolver pod's filesystem, including ServiceAccount tokens. The file contents are returned base64-encoded in `resolutionrequest.status.data`. Versions 1.0.1, 1</description>
    </item>
    <item>
      <title>Molotovcherry Android-Imagemagick7 — CVE-2026-33854 (Critical)</title>
      <link>https://www.patchbrief.org/items/2026-03-molotovcherry-cve-2026-33854.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-03-molotovcherry-cve-2026-33854.html</guid>
      <pubDate>Tue, 24 Mar 2026 00:00:00 +0000</pubDate>
      <description>Out-of-bounds Write vulnerability in MolotovCherry Android-ImageMagick7.This issue affects Android-ImageMagick7: before 7.1.2-10.</description>
    </item>
    <item>
      <title>Mozilla Firefox — CVE-2026-4688 (Critical)</title>
      <link>https://www.patchbrief.org/items/2026-03-mozilla-cve-2026-4688.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-03-mozilla-cve-2026-4688.html</guid>
      <pubDate>Tue, 24 Mar 2026 00:00:00 +0000</pubDate>
      <description>Sandbox escape due to use-after-free in the Disability Access APIs component. This vulnerability was fixed in Firefox 149, Firefox ESR 140.9, Thunderbird 149, and Thunderbird 140.9.</description>
    </item>
    <item>
      <title>Mozilla Firefox — CVE-2026-4689 (Critical)</title>
      <link>https://www.patchbrief.org/items/2026-03-mozilla-cve-2026-4689.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-03-mozilla-cve-2026-4689.html</guid>
      <pubDate>Tue, 24 Mar 2026 00:00:00 +0000</pubDate>
      <description>Sandbox escape due to incorrect boundary conditions, integer overflow in the XPCOM component. This vulnerability was fixed in Firefox 149, Firefox ESR 115.34, Firefox ESR 140.9, Thunderbird 149, and Thunderbird 140.9.</description>
    </item>
    <item>
      <title>Mozilla Firefox — CVE-2026-4691 (Critical)</title>
      <link>https://www.patchbrief.org/items/2026-03-mozilla-cve-2026-4691.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-03-mozilla-cve-2026-4691.html</guid>
      <pubDate>Tue, 24 Mar 2026 00:00:00 +0000</pubDate>
      <description>Use-after-free in the CSS Parsing and Computation component. This vulnerability was fixed in Firefox 149, Firefox ESR 115.34, Firefox ESR 140.9, Thunderbird 149, and Thunderbird 140.9.</description>
    </item>
    <item>
      <title>Mozilla Firefox — CVE-2026-4692 (Critical)</title>
      <link>https://www.patchbrief.org/items/2026-03-mozilla-cve-2026-4692.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-03-mozilla-cve-2026-4692.html</guid>
      <pubDate>Tue, 24 Mar 2026 00:00:00 +0000</pubDate>
      <description>Sandbox escape in the Responsive Design Mode component. This vulnerability was fixed in Firefox 149, Firefox ESR 115.34, Firefox ESR 140.9, Thunderbird 149, and Thunderbird 140.9.</description>
    </item>
    <item>
      <title>Mozilla Firefox — CVE-2026-4696 (Critical)</title>
      <link>https://www.patchbrief.org/items/2026-03-mozilla-cve-2026-4696.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-03-mozilla-cve-2026-4696.html</guid>
      <pubDate>Tue, 24 Mar 2026 00:00:00 +0000</pubDate>
      <description>Use-after-free in the Layout: Text and Fonts component. This vulnerability was fixed in Firefox 149, Firefox ESR 115.34, Firefox ESR 140.9, Thunderbird 149, and Thunderbird 140.9.</description>
    </item>
    <item>
      <title>Mozilla Firefox — CVE-2026-4698 (Critical)</title>
      <link>https://www.patchbrief.org/items/2026-03-mozilla-cve-2026-4698.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-03-mozilla-cve-2026-4698.html</guid>
      <pubDate>Tue, 24 Mar 2026 00:00:00 +0000</pubDate>
      <description>JIT miscompilation in the JavaScript Engine: JIT component. This vulnerability was fixed in Firefox 149, Firefox ESR 115.34, Firefox ESR 140.9, Thunderbird 149, and Thunderbird 140.9.</description>
    </item>
    <item>
      <title>Mozilla Firefox — CVE-2026-4700 (Critical)</title>
      <link>https://www.patchbrief.org/items/2026-03-mozilla-cve-2026-4700.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-03-mozilla-cve-2026-4700.html</guid>
      <pubDate>Tue, 24 Mar 2026 00:00:00 +0000</pubDate>
      <description>Mitigation bypass in the Networking: HTTP component. This vulnerability was fixed in Firefox 149, Firefox ESR 140.9, Thunderbird 149, and Thunderbird 140.9.</description>
    </item>
    <item>
      <title>Mozilla Firefox — CVE-2026-4701 (Critical)</title>
      <link>https://www.patchbrief.org/items/2026-03-mozilla-cve-2026-4701.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-03-mozilla-cve-2026-4701.html</guid>
      <pubDate>Tue, 24 Mar 2026 00:00:00 +0000</pubDate>
      <description>Use-after-free in the JavaScript Engine component. This vulnerability was fixed in Firefox 149, Firefox ESR 140.9, Thunderbird 149, and Thunderbird 140.9.</description>
    </item>
    <item>
      <title>Mozilla Firefox — CVE-2026-4702 (Critical)</title>
      <link>https://www.patchbrief.org/items/2026-03-mozilla-cve-2026-4702.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-03-mozilla-cve-2026-4702.html</guid>
      <pubDate>Tue, 24 Mar 2026 00:00:00 +0000</pubDate>
      <description>JIT miscompilation in the JavaScript Engine component. This vulnerability was fixed in Firefox 149, Firefox ESR 140.9, Thunderbird 149, and Thunderbird 140.9.</description>
    </item>
    <item>
      <title>Mozilla Firefox — CVE-2026-4705 (Critical)</title>
      <link>https://www.patchbrief.org/items/2026-03-mozilla-cve-2026-4705.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-03-mozilla-cve-2026-4705.html</guid>
      <pubDate>Tue, 24 Mar 2026 00:00:00 +0000</pubDate>
      <description>Undefined behavior in the WebRTC: Signaling component. This vulnerability was fixed in Firefox 149, Firefox ESR 140.9, Thunderbird 149, and Thunderbird 140.9.</description>
    </item>
    <item>
      <title>Rubyonrails Rails — CVE-2026-33195 (Critical)</title>
      <link>https://www.patchbrief.org/items/2026-03-rubyonrails-cve-2026-33195.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-03-rubyonrails-cve-2026-33195.html</guid>
      <pubDate>Tue, 24 Mar 2026 00:00:00 +0000</pubDate>
      <description>Active Storage allows users to attach cloud and local files in Rails applications. Prior to versions 8.1.2.1, 8.0.4.1, and 7.2.3.1, Active Storage's `DiskService#path_for` does not validate that the resolved filesystem path remains within the storage root directory. If a blob key containing path traversal sequences (e.g. `../`) is used, it could allow reading, writing, or deleting arbitrary files on the server. Blob keys are expected to be trusted strings, but some applications could be passing user input as keys and would be affected. Versions 8.1.2.1, 8.0.4.1, and 7.2.3.1 contain a patch.</description>
    </item>
    <item>
      <title>Rubyonrails Rails — CVE-2026-33202 (Critical)</title>
      <link>https://www.patchbrief.org/items/2026-03-rubyonrails-cve-2026-33202.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-03-rubyonrails-cve-2026-33202.html</guid>
      <pubDate>Tue, 24 Mar 2026 00:00:00 +0000</pubDate>
      <description>Active Storage allows users to attach cloud and local files in Rails applications. Prior to versions 8.1.2.1, 8.0.4.1, and 7.2.3.1, Active Storage's `DiskService#delete_prefixed` passes blob keys directly to `Dir.glob` without escaping glob metacharacters. If a blob key contains attacker-controlled input or custom-generated keys with glob metacharacters, it may be possible to delete unintended files from the storage directory. Versions 8.1.2.1, 8.0.4.1, and 7.2.3.1 contain a patch.</description>
    </item>
    <item>
      <title>Code-Projects Simple Laundry System — CVE-2026-4579 (Critical)</title>
      <link>https://www.patchbrief.org/items/2026-03-code-projects-cve-2026-4579.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-03-code-projects-cve-2026-4579.html</guid>
      <pubDate>Mon, 23 Mar 2026 00:00:00 +0000</pubDate>
      <description>A vulnerability was identified in code-projects Simple Laundry System 1.0. The issue affects /viewdetail.php in the Parameters Handler component. The manipulation of the argument serviceId leads to sql injection. Remote exploitation of the attack is possible. The exploit is publicly available and might be used.</description>
    </item>
    <item>
      <title>Code-Projects Simple Laundry System — CVE-2026-4580 (Critical)</title>
      <link>https://www.patchbrief.org/items/2026-03-code-projects-cve-2026-4580.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-03-code-projects-cve-2026-4580.html</guid>
      <pubDate>Mon, 23 Mar 2026 00:00:00 +0000</pubDate>
      <description>A security flaw has been discovered in code-projects Simple Laundry System 1.0. The issue affects /checkupdatestatus.php in the Parameters Handler component. The manipulation of the argument serviceId results in sql injection. The attack can be executed remotely. The exploit has been released to the public and may be used for attacks.</description>
    </item>
    <item>
      <title>Code-Projects Simple Laundry System — CVE-2026-4581 (Critical)</title>
      <link>https://www.patchbrief.org/items/2026-03-code-projects-cve-2026-4581.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-03-code-projects-cve-2026-4581.html</guid>
      <pubDate>Mon, 23 Mar 2026 00:00:00 +0000</pubDate>
      <description>A weakness has been identified in code-projects Simple Laundry System 1.0. The issue affects /checklogin.php in the Parameters Handler component. This manipulation of the argument Username causes sql injection. The attack is possible to be carried out remotely. The exploit has been made available to the public and could be used for attacks.</description>
    </item>
    <item>
      <title>Jsrsasign Project Jsrsasign — CVE-2026-4600 (Critical)</title>
      <link>https://www.patchbrief.org/items/2026-03-jsrsasign-project-cve-2026-4600.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-03-jsrsasign-project-cve-2026-4600.html</guid>
      <pubDate>Mon, 23 Mar 2026 00:00:00 +0000</pubDate>
      <description>Versions of the package jsrsasign before 11.1.1 are vulnerable to Improper Verification of Cryptographic Signature via the DSA domain-parameter validation in KJUR.crypto.DSA.setPublic (and the related DSA/X509 verification flow in src/dsa-2.0.js). An attacker can forge DSA signatures or X.509 certificates that X509.verifySignature() accepts by supplying malicious domain parameters such as g=1, y=1, and a fixed r=1, which make the verification equation true for any hash.</description>
    </item>
    <item>
      <title>Jsrsasign Project Jsrsasign — CVE-2026-4601 (Critical)</title>
      <link>https://www.patchbrief.org/items/2026-03-jsrsasign-project-cve-2026-4601.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-03-jsrsasign-project-cve-2026-4601.html</guid>
      <pubDate>Mon, 23 Mar 2026 00:00:00 +0000</pubDate>
      <description>Versions of the package jsrsasign before 11.1.1 are vulnerable to Missing Cryptographic Step via the KJUR.crypto.DSA.signWithMessageHash process in the DSA signing implementation. An attacker can recover the private key by forcing r or s to be zero, so the library emits an invalid signature without retrying, and then solves for x from the resulting signature.</description>
    </item>
    <item>
      <title>Mantisbt Mantisbt — CVE-2026-30849 (Critical)</title>
      <link>https://www.patchbrief.org/items/2026-03-mantisbt-cve-2026-30849.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-03-mantisbt-cve-2026-30849.html</guid>
      <pubDate>Mon, 23 Mar 2026 00:00:00 +0000</pubDate>
      <description>Mantis Bug Tracker (MantisBT) is an open source issue tracker. Versions prior to 2.28.1 running on MySQL family databases are affected by an authentication bypass vulnerability in the SOAP API, as a result of an improper type checking on the password parameter. Other database backends are not affected, as they do not perform implicit type conversion from string to integer. Using a crafted SOAP envelope, an attacker knowing the victim's username is able to login to the SOAP API with their account without knowledge of the actual password, and execute any API function they have access to. Version</description>
    </item>
    <item>
      <title>Nexxtsolutions Nebula300Plus Firmware — CVE-2026-31848 (Critical)</title>
      <link>https://www.patchbrief.org/items/2026-03-nexxtsolutions-cve-2026-31848.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-03-nexxtsolutions-cve-2026-31848.html</guid>
      <pubDate>Mon, 23 Mar 2026 00:00:00 +0000</pubDate>
      <description>Nexxt Solutions Nebula 300+ firmware through version 12.01.01.37 uses the ecos_pw cookie for authentication, which contains Base64-encoded credential data combined with a static suffix. Because the encoding is reversible and lacks integrity protection, an attacker can reconstruct or forge a valid cookie value without proper authentication. This allows unauthorized administrative access to protected endpoints.</description>
    </item>
    <item>
      <title>Nexxtsolutions Nebula300Plus Firmware — CVE-2026-31851 (Critical)</title>
      <link>https://www.patchbrief.org/items/2026-03-nexxtsolutions-cve-2026-31851.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-03-nexxtsolutions-cve-2026-31851.html</guid>
      <pubDate>Mon, 23 Mar 2026 00:00:00 +0000</pubDate>
      <description>Nexxt Solutions Nebula 300+ firmware through version 12.01.01.37 does not implement rate limiting or account lockout mechanisms on authentication interfaces. An attacker can perform unlimited authentication attempts against endpoints that rely on credential validation, enabling brute-force attacks to guess administrative credentials without restriction.</description>
    </item>
    <item>
      <title>Openclaw Openclaw — CVE-2026-32913 (Critical)</title>
      <link>https://www.patchbrief.org/items/2026-03-openclaw-cve-2026-32913.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-03-openclaw-cve-2026-32913.html</guid>
      <pubDate>Mon, 23 Mar 2026 00:00:00 +0000</pubDate>
      <description>OpenClaw before 2026.3.7 contains an improper header validation vulnerability in fetchWithSsrFGuard that forwards custom authorization headers across cross-origin redirects. Attackers can trigger redirects to different origins to intercept sensitive headers like X-Api-Key and Private-Token intended for the original destination.</description>
    </item>
    <item>
      <title>Wwbn Avideo — CVE-2026-33297 (Critical)</title>
      <link>https://www.patchbrief.org/items/2026-03-wwbn-cve-2026-33297.html</link>
      <guid isPermaLink="true">https://www.patchbrief.org/items/2026-03-wwbn-cve-2026-33297.html</guid>
      <pubDate>Mon, 23 Mar 2026 00:00:00 +0000</pubDate>
      <description>WWBN AVideo is an open source video platform. Prior to version 26.0, the `setPassword.json.php` endpoint in the CustomizeUser plugin allows administrators to set a channel password for any user. Due to a logic error in how the submitted password value is processed, any password containing non-numeric characters is silently coerced to the integer zero before being stored. This means that regardless of the intended password, the stored channel password becomes 0, which any visitor can trivially guess to bypass channel-level access control. Version 26.0 contains a patch for the issue.</description>
    </item>
  </channel>
</rss>
