2d ago
2026-07-28 16:18Z
HIGH

CVE-2026-51269 — ESP32: schreibfaul1 ESP32-audioI2S 3.4.5 has a heap-based buffer overflow vulnerability in the connecttospeech() function.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-51269

schreibfaul1 ESP32-audioI2S 3.4.5 has a heap-based buffer overflow vulnerability in the connecttospeech() function. The application accepts attacker-controlled long speech text input, performs URL encoding, and directly appends the encoded result into a fixed ps_ptr heap buffer when constructing HTTP TTS request headers. Lack of input length validation and boundary checking allows remote attackers to craft oversized input to trigger out-of-bounds heap write, resulting in arbi CVSSv3.1 8.8 (HIGH)

CWECWE 122VNDEsp32TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2d ago
2026-07-28 16:18Z
CRIT

CVE-2026-51267 — ESP32: schreibfaul1 ESP32-audioI2S 3.4.5 has a heap-based buffer overflow vulnerability in the URL path concatenation

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-51267

schreibfaul1 ESP32-audioI2S 3.4.5 has a heap-based buffer overflow vulnerability in the URL path concatenation and encoding module. The application splices untrusted extension path and attacker-controlled query string into a path buffer, then invokes urlencode without validating the final string length. Remote attackers can construct an oversized malicious URL path and query string to trigger out-of-bounds heap write, resulting in arbitrary code execution, information disclos CVSSv3.1 9.8 (CRITICAL)

CWECWE 122VNDEsp32TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2d ago
2026-07-28 16:18Z
CRIT

CVE-2026-51266 — ESP32: schreibfaul1 ESP32-audioI2S 3.4.5 has a heap-based buffer overflow vulnerability in the HTTP request header

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-51266

schreibfaul1 ESP32-audioI2S 3.4.5 has a heap-based buffer overflow vulnerability in the HTTP request header construction logic. The application dynamically splices attacker-controlled host name, path, query string, and multiple HTTP header fields into a fixed ps_ptr heap buffer without proper size limitation and boundary validation. Remote attackers can use an oversized crafted network request parameter to trigger out-of-bounds heap write, leading to arbitrary code execution. CVSSv3.1 9.8 (CRITICAL)

CWECWE 122VNDEsp32TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2d ago
2026-07-28 16:18Z
CRIT

CVE-2026-51263 — ESP32: schreibfaul1 ESP32-audioI2S 3.4.5 is vulnerable to Buffer Overflow.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-51263

schreibfaul1 ESP32-audioI2S 3.4.5 is vulnerable to Buffer Overflow. The Audio::openai_speech function in the Audio library manually constructs JSON request bodies and HTTP request headers by directly concatenating externally controllable input and instructions strings without effective length restriction and boundary validation. An unauthenticated remote attacker can send oversized malicious string data to trigger a heap buffer overflow during string splicing, resulting in me CVSSv3.1 9.8 (CRITICAL)

CWECWE 122VNDEsp32TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2d ago
2026-07-28 16:18Z
HIGH

CVE-2026-47483 — NVIDIA: A successful exploit of this vulnerability might lead to denial of service and information

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-47483

NVIDIA DCGM Exporter for all platforms contains a vulnerability in the /debug/pprof endpoints, where an attacker could cause uncontrolled resource consumption by submitting concurrent unauthenticated profiling requests. A successful exploit of this vulnerability might lead to denial of service and information disclosure. CVSSv3.1 8.2 (HIGH)

CWECWE 770VNDNvidiaTYPVulnerability
8.2
CVSS v3.1
91
Edit Score
2d ago
2026-07-28 16:18Z
HIGH

CVE-2026-45293 — WordPress: From 0.14.1 until 3.4.1, the WordPress.WP.EnqueuedResourceParameters sniff (active in the WordPress and WordPress-Extra rulesets)

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-45293

WordPress Coding Standards is a set of PHP_CodeSniffer rules (sniffs) that enforce WordPress coding conventions. From 0.14.1 until 3.4.1, the WordPress.WP.EnqueuedResourceParameters sniff (active in the WordPress and WordPress-Extra rulesets) reconstructed the $ver argument passed to functions such as wp_enqueue_script() and ran it through eval() inside its is_falsy() method, so a maliciously crafted argument such as 'system'('id') would execute during a scan; as a result, ru CVSSv3.1 8.6 (HIGH)

CWECWE 95VNDWordpressTYPVulnerability
8.6
CVSS v3.1
93
Edit Score
2d ago
2026-07-28 16:18Z
HIGH

CVE-2026-43910 — Appium: Java Client is the Java language binding for writing Appium tests that conform

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-43910

Appium Java Client is the Java language binding for writing Appium tests that conform to the W3C WebDriver protocol. From 8.2.1 until 10.1.1, when directConnect(true) is enabled, AppiumCommandExecutor.setDirectConnect() reads the directConnectHost, directConnectPort, and directConnectPath fields from the server's NEW_SESSION response and rebuilds the client's server URL from them, validating only that the protocol is https, with no host allowlist or IP validation; a rogue or CVSSv3.1 8.2 (HIGH)

CWECWE 918CWECWE 441VNDAppiumTYPVulnerability
8.2
CVSS v3.1
91
Edit Score
728 × 90 / responsive · programmatic ad slot
2d ago
2026-07-28 16:12Z
CRIT

ColdFusion Under Fire: Breaking Down CVE-2026-48283 and CVE-2026-48313

Horizon3.ai·horizon3.aiCVE-2026-48283CVE-2026-48313in the wild

Adobe ColdFusion 2025 (Update 9 and earlier) and 2023 (Update 20 and earlier) contain two critical unauthenticated vulnerabilities: CVE-2026-48283 (CVSS 10.0) allows arbitrary file upload via the CKEditor filemanager connector, enabling RCE as NT AUTHORITY\SYSTEM; CVE-2026-48313 (CVSS 9.3) is a path traversal flaw in the same connector permitting read/write access to files outside intended scope. Horizon3.ai's NodeZero achieved host compromise in 87 seconds via CVE-2026-48283, and both vulnerabilities are patchable via ColdFusion 2025 Update 10 and 2023 Update 21.

SRFApplicationTACTA0001TACTA0007SRFWebSWColdfusionVNDAdobeTYPResearchTYPVulnerability
82
Edit Score
2d ago
2026-07-28 16:00Z
HIGH

Disrupting supply chain attacks on npm and GitHub Actions

GitHub Security·github.blog

GitHub and npm announced a coordinated set of supply-chain hardening measures deployed over the past year to disrupt common attack patterns targeting open-source maintainers and CI/CD pipelines. Changes include account protection delays for high-impact npm accounts, safer pull_request_target defaults in GitHub Actions, staged publishing, disabled install scripts by default in npm v12, Dependabot version cooldowns, and credential revocation tooling for incident response.

TACTA0001TACTA0006SRFSupply ChainSWGithub ActionsVNDGithubTYPAdvisorySTGInitial AccessSTGCred Access
72
Edit Score
2d ago
2026-07-28 15:17Z
CRIT

CVE-2026-66713 — Deserialization: of Untrusted Data (CWE-502) in the Tribes-based clustering component in Apache Software Foundation

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-66713

Deserialization of Untrusted Data (CWE-502) in the Tribes-based clustering component  in Apache Software Foundation Apache Axis2/Java through 2.0.0 on Apache Tomcat  (only when Tribes clustering is enabled, which is off by default) allows an  unauthenticated remote attacker with network access to the clustering port to  execute arbitrary code via a crafted serialized Java object delivered to the cluster  channel and deserialized in  org.apache.axis2.clustering.tri CVSSv3.1 9.8 (CRITICAL)

CWECWE 502TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2d ago
2026-07-28 15:17Z
HIGH

CVE-2026-63727 — Anchore: Enterprise versions from 5.11.0 to 5.27.1 and 6.0.0 contain an improper privilege escalation

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-63727

Anchore Enterprise versions from 5.11.0 to 5.27.1 and 6.0.0 contain an improper privilege escalation vulnerability in the user management API. An authenticated attacker who is able to access the Anchore Enterprise API could issue an API call capable of modifying user permissions to gain access to additional resources and operations. It is not possible to grant the system-admin role, but a read only user could be granted write access. This issue is fixed in Anchore Enterprise CVSSv3.1 8.8 (HIGH)

CWECWE 648VNDAnchoreTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2d ago
2026-07-28 15:17Z
CRIT

CVE-2026-51260 — Unsafe: fixed-size memcpy operation in AudioBuffer::writeSpace() of schreibfaul1 ESP32-audioI2S 3.4.5 allows remote heap buffer

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-51260

Unsafe fixed-size memcpy operation in AudioBuffer::writeSpace() of schreibfaul1 ESP32-audioI2S 3.4.5 allows remote heap buffer overflow. The code copies a full UINT16_MAX bytes without validating destination available space, causing out-of-bounds memory write. CVSSv3.1 9.4 (CRITICAL)

CWECWE 122VNDUnsafeTYPVulnerability
9.4
CVSS v3.1
97
Edit Score
2d ago
2026-07-28 15:17Z
CRIT

CVE-2026-51259 — Unchecked: unsigned integer overflow in buffer size calculation in schreibfaul1 ESP32-audioI2S 3.4.5 leads to

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-51259

Unchecked unsigned integer overflow in buffer size calculation in schreibfaul1 ESP32-audioI2S 3.4.5 leads to undersized PSRAM buffer allocation. Subsequent normal audio buffer read and write operations cause heap out-of-bounds access, memory corruption, denial of service, and potential code execution. CVSSv3.1 9.8 (CRITICAL)

CWECWE 122VNDUncheckedTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2d ago
2026-07-28 15:17Z
CRIT

CVE-2026-51252 — ESP32: schreibfaul1 ESP32-audioI2S 3.4.5 has a buffer overflow vulnerability in the MP3Decoder::UnpackSFMPEG1 function due to

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-51252

schreibfaul1 ESP32-audioI2S 3.4.5 has a buffer overflow vulnerability in the MP3Decoder::UnpackSFMPEG1 function due to missing input validation on attacker-controlled MP3 metadata. CVSSv3.1 9.8 (CRITICAL)

CWECWE 120VNDEsp32TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2d ago
2026-07-28 15:05Z
INFO

BloodHound CE v9.5.0

BloodHound releases·github.comCVE-2026-16221

BloodHound CE v9.5.0 released with 50+ commits including data quality improvements, API enhancements, webhook functionality, and a vulnerability fix (CVE-2026-16221). Changes span backend refactoring, UI improvements, permission controls, and OpenGraph entity support.

SWBloodhoundVNDSpecteropsTYPTool
42
Edit Score
2d ago
2026-07-28 13:19Z
HIGH

CVE-2026-7187 — Missing authentication for critical function vulnerability in Universal Software Inc.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-7187

Missing authentication for critical function vulnerability in Universal Software Inc. UKBS allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects UKBS: through 28072026. NOTE: The vendor was contacted and it was learned that the product is not supported. CVSSv3.1 8.8 (HIGH)

CWECWE 306TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2d ago
2026-07-28 13:19Z
HIGH

CVE-2026-62427 — CNA: [This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-62427

[This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] To manage the system, sysctl and platform operations are used by the control domain or a possible Xenstore domain. Some of these operations may not be executed in parallel, so a system-wide lock each is used. The way those locks are acquired is, however, not providing any fairness. Furthermore, with XSM/Flask in use, the lock acquire will, for som CVSSv3.1 8.8 (HIGH)

CWECWE 284CWECWE 305VNDCnaTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2d ago
2026-07-28 13:19Z
HIGH

CVE-2026-62426 — CNA: [This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-62426

[This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] To manage the system, sysctl and platform operations are used by the control domain or a possible Xenstore domain. Some of these operations may not be executed in parallel, so a system-wide lock each is used. The way those locks are acquired is, however, not providing any fairness. Furthermore, with XSM/Flask in use, the lock acquire will, for som CVSSv3.1 8.8 (HIGH)

CWECWE 667CWECWE 412VNDCnaTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2d ago
2026-07-28 13:18Z
HIGH

CVE-2026-49332 — A flaw was found in openshift/oauth-proxy.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-49332

A flaw was found in openshift/oauth-proxy. The proxy sets authenticated identity headers using only dash-variant keys (X-Forwarded-User) but does not strip underscore-variant keys (X_Forwarded_User) from incoming requests. WSGI and PHP frameworks normalize both variants to the same variable, allowing an authenticated low-privilege user to smuggle a forged identity that may override the legitimate authenticated identity in the upstream application. CVSSv3.1 8.5 (HIGH)

CWECWE 436TYPVulnerability
8.5
CVSS v3.1
93
Edit Score
2d ago
2026-07-28 11:56Z
HIGH

Introducing Attack Path Management for Entra Agents in BloodHound Enterprise

SpecterOps·specterops.io

SpecterOps released Attack Path Management for Entra Agents in BloodHound Enterprise, extending the attack graph to model AI agent identities, execution contexts, and trust relationships across Microsoft's agent ecosystem (Entra Agent ID, Copilot Studio, Power Automate, Azure AI Foundry). The extension identifies attack paths where low-privileged users can invoke agents that act with higher-privileged identities, public agents bridge anonymous callers to authenticated resources, and agent identity blueprints expose multiple child identities.

TACTA0004TACTA0001SRFIdentityTACTA0003SRFCloudSWBloodhoundSWEntraSWAzure Ai Foundry
78
Edit Score
2d ago
2026-07-28 11:50Z
INFO

Designing an MCP Server for AI Agents: Why Wrapping Your API Is the Wrong Abstraction

SpecterOps·specterops.io

SpecterOps published a technical design essay on building Model Context Protocol (MCP) servers for AI agents, using BloodHound Hunter as a case study. The post argues that MCP servers should be designed around agent intent and workflow rather than wrapping existing REST APIs, emphasizing interface design principles like reducing cognitive load and hiding implementation complexity.

SRFApplicationTACTA0007SWBloodhoundVNDSpecteropsTYPResearchTECT1087
62
Edit Score
2d ago
2026-07-28 11:50Z
INFO

Attack Path Management Comes to AWS

SpecterOps·specterops.io

SpecterOps announced AWS IAM attack path management capabilities in BloodHound Enterprise, extending the platform's identity graph analysis to AWS environments. The release models IAM, Organizations, STS, S3, KMS, Lambda, EC2, CloudFormation, EKS, and SSM resources to visualize privilege escalation chains, cross-account trust relationships, and lateral movement paths across AWS organizations.

TACTA0006SRFIdentitySRFCloudTACTA0008SWBloodhoundSWAwsVNDAmazonTYPTool
72
Edit Score
2d ago
2026-07-28 11:50Z
HIGH

Expanding attack path management to the AI frontier

SpecterOps·specterops.io

SpecterOps announced new BloodHound Enterprise features for AWS attack path management and Entra Agent ID support, enabling defenders to visualize privilege escalation and lateral movement chains across hybrid cloud, SaaS, and AI agent identities. The update models 20+ AWS resource types and 150+ relationships (IAM, Lambda, S3, KMS, cross-account trust, PassRole abuse) and introduces BloodHound Hunter, an MCP interface that connects approved AI agents to attack path findings for automated remediation prioritization.

TACTA0006SRFIdentitySRFCloudTACTA0008SWBloodhoundSWEntraSWGithubSWAws
72
Edit Score
2d ago
2026-07-28 11:00Z
INFO

How we use /goal to find bugs in Patch the Planet

Trail of Bits·blog.trailofbits.com

Trail of Bits describes their methodology for using Codex's /goal feature (goal-based prompting) to systematically discover bugs in widely-audited open-source projects including Rust, curl, and zlib as part of the Patch the Planet initiative. The post details three core techniques: leveraging Codex to write its own goal prompts, defining outcomes rather than prescribing paths, and assigning one outcome per agent to avoid optimization conflicts. They report finding critical vulnerabilities including a Rust soundness hole, 11 variant CVE hits via Semgrep rules, and high-severity privilege-escalation bugs in Keycloak's SAML component.

SRFApplicationTACTA0043TYPResearchTYPToolSTGDiscoveryTECT1592
72
Edit Score
2d ago
2026-07-28 10:16Z
CRIT

CVE-2026-16462 — PROCON: This allows a remote unauthenticated attacker to execute arbitrary SQL commands.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-16462

In PROCON-WEB SCADA the endpoint 'GetGridData' is not properly sanitized. This allows a remote unauthenticated attacker to execute arbitrary SQL commands. CVSSv3.1 9.8 (CRITICAL)

CWECWE 89VNDProconTYPVulnerability
9.8
CVSS v3.1
99
Edit Score