Subscribe, build a custom feed, or pitch a sponsorship at hello@acadenix.com
Latest intel// live feed
CVE-2026-33823 — Microsoft: Improper authorization in Microsoft Teams allows an authorized attacker to disclose information over a
Improper authorization in Microsoft Teams allows an authorized attacker to disclose information over a network. CVSSv3.1 9.6 (CRITICAL)
CVE-2026-33109 — Azure: Improper access control in Azure Managed Instance for Apache Cassandra allows an authorized attacker
Improper access control in Azure Managed Instance for Apache Cassandra allows an authorized attacker to execute code over a network. CVSSv3.1 9.9 (CRITICAL)
CVE-2026-32207 — Improper neutralization of input during web page generation ('cross-site scripting') in Azure Machine Learning
Improper neutralization of input during web page generation ('cross-site scripting') in Azure Machine Learning allows an unauthorized attacker to perform spoofing over a network. CVSSv3.1 8.8 (HIGH)
CVE-2026-42449 — MCP: Response bodies are returned to the caller (non-blind SSRF), and the n8nApiKey is forwarded
n8n-MCP is an MCP server that provides AI assistants access to n8n node documentation, properties, and operations. In versions 2.47.4 through 2.47.13, the SDK embedder path (N8NDocumentationMCPServer constructor, getN8nApiClient(), and validateInstanceContext()), the synchronous URL validator in SSRFProtection.validateUrlSync() had no IPv6 checks. IPv4-mapped IPv6 addresses such as http://[::ffff:169.254.169.254] bypassed the cloud-metadata, localhost, and private-IP range ch CVSSv3.1 8.5 (HIGH)
CVE-2026-42047 — Inngest: Versions 3.22.0 through 3.53.1 contain a vulnerability that allows unauthenticated remote attackers to exfiltrate
Inngest is a platform for running event-driven and scheduled background functions with queueing, retries, and step orchestration. Versions 3.22.0 through 3.53.1 contain a vulnerability that allows unauthenticated remote attackers to exfiltrate environment variables from the host process via the serve() HTTP handler. The serve() handler implements GET, POST, and PUT methods. Requests using PATCH, OPTIONS, or DELETE fall through to a generic handler that returns diagnostic info CVSSv3.1 8.6 (HIGH)
CVE-2026-42239 — Budibase: This means every XSS becomes a full account takeover — the attacker steals the
Budibase is an open-source low-code platform. Prior to version 3.35.10, the budibase:auth cookie containing the JWT session token is set with httpOnly: false at packages/backend-core/src/utils/utils.ts:218. JavaScript can read this cookie via document.cookie. This means every XSS becomes a full account takeover — the attacker steals the JWT and has persistent access to the victim's account. The cookie also lacks secure: true (sent over plaintext HTTP) and sameSite attribute. CVSSv3.1 8.1 (HIGH)
v3.4.0.58
Mythic v3.4.0.58 released with a bug fix for lazyQuery on the single task view page. This is a minor patch release addressing UI/UX functionality in the command & control framework.
CVE-2026-42284 — GitPython: Prior to version 3.1.47, _clone() validates multi_options as the original list, then executes shlex.split("
GitPython is a python library used to interact with Git repositories. Prior to version 3.1.47, _clone() validates multi_options as the original list, then executes shlex.split(" ".join(multi_options)). A string like "--branch main --config core.hooksPath=/x" passes validation (starts with --branch), but after split becomes ["--branch", "main", "--config", "core.hooksPath=/x"]. Git applies the config and executes attacker hooks during clone. This issue has been patched in vers CVSSv3.1 8.1 (HIGH)
CVE-2026-42215 — GitPython: From version 3.1.30 to before version 3.1.47, GitPython blocks dangerous Git options such as
GitPython is a python library used to interact with Git repositories. From version 3.1.30 to before version 3.1.47, GitPython blocks dangerous Git options such as --upload-pack and --receive-pack by default, but the equivalent Python kwargs upload_pack and receive_pack bypass that check. If an application passes attacker-controlled kwargs into Repo.clone_from(), Remote.fetch(), Remote.pull(), or Remote.push(), this leads to arbitrary command execution even when allow_unsafe_o CVSSv3.1 8.8 (HIGH)
CVE-2026-41902 — FreeScout: Combined with realistic hash-leakage scenarios (forwarded invite emails, HTTP referrer to external CDNs on
FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Prior to version 1.8.217, the /user-setup/{hash} endpoint accepts a 60-character random invite_hash to set a new user's password. The endpoint performs no expiration check — the hash remains valid indefinitely until consumed. Combined with realistic hash-leakage scenarios (forwarded invite emails, HTTP referrer to external CDNs on the setup page, server-side log exposure, abandoned invite email CVSSv3.1 9.1 (CRITICAL)
CVE-2022-0847-Container-Escape — CVE-2022-0847 used to achieve container escape 利用CVE-2022-0847 (Dirty Pipe) 实现容器逃逸
A GitHub repository demonstrates a practical container escape exploit leveraging CVE-2022-0847 (Dirty Pipe) combined with the CAP_DAC_READ_SEARCH capability to overwrite arbitrary read-only files on the host filesystem from within a container. The exploit uses splice() and open_by_handle_at() syscalls to bypass file permission checks and modify host files, with a working proof-of-concept in C.
CVE-2026-37709 — Permissions: Insecure Permissions vulnerability in grokability snipe-it v.8.4.0 and before and fixed after 2026-03-10 commit
Insecure Permissions vulnerability in grokability snipe-it v.8.4.0 and before and fixed after 2026-03-10 commit 676a9958 allows a remote attacker to execute arbitrary code via the app/Http/Controllers/Api/UploadedFilesController.php component CVSSv3.1 9.8 (CRITICAL)
CVE-2026-7415 — MQTT: The MQTT broker embedded in Yarbo firmware v2.3.9 is configured to allow anonymous connections
The MQTT broker embedded in Yarbo firmware v2.3.9 is configured to allow anonymous connections with no topic-level read or write ACLs. Any host on the same network can subscribe to sensitive telemetry topics or publish control messages directly to the robot without authentication or authorization of any kind. CVSSv3.1 9.8 (CRITICAL)
CVE-2026-7414 — Yarbo: These credentials are identical across all devices running this firmware and cannot be changed
Yarbo firmware v2.3.9 contains hardcoded administrative credentials embedded in the firmware image. These credentials are identical across all devices running this firmware and cannot be changed or removed by end users, enabling trivial unauthorized access to device management interfaces by anyone who knows them. CVSSv3.1 9.8 (CRITICAL)
CVE-2026-6973 — Ivanti Endpoint_manager_mobile: A configuration control vulnerability in the Ivanti Endpoint Manager Mobile before 12.9.0.1, 12.8.0.3 and
A configuration control vulnerability in the Ivanti Endpoint Manager Mobile before 12.9.0.1, 12.8.0.3 and 12.7.0.2 versions allows a remote authenticated attacker to inject arbitrary Apache directives, leading to remote code execution. CVSSv3.1 7.2 (HIGH) · EPSS 90th percentile
CVE-2026-5787 — Certificate: An Improper Certificate Validation in Ivanti EPMM before versions 12.6.1.1, 12.7.0.1, and 12.8.0.1 allows
An Improper Certificate Validation in Ivanti EPMM before versions 12.6.1.1, 12.7.0.1, and 12.8.0.1 allows a remote unauthenticated attacker to impersonate registered Sentry hosts and obtain valid CA-signed client certificates. CVSSv3.1 8.9 (HIGH)
CVE-2026-5786 — Access: An Improper Access Control vulnerability in Ivanti EPMM before versions 12.6.1.1, 12.7.0.1, and 12.8.0.1
An Improper Access Control vulnerability in Ivanti EPMM before versions 12.6.1.1, 12.7.0.1, and 12.8.0.1 allows a remote authenticated attacker to gain administrative access. CVSSv3.1 8.8 (HIGH)
CVE-2025-63704 — NPM: package query-parser-string 1.0.0 is vulnerable to Prototype Pollution.
NPM package query-parser-string 1.0.0 is vulnerable to Prototype Pollution. The package does not properly sanitize user supplied query parameters and merges them to the newly created object. CVSSv3.1 9.8 (CRITICAL)
CVE-2025-63703 — npm package parse-ini v1.0.6 is vulnerable to Prototype Pollution in index.js().
npm package parse-ini v1.0.6 is vulnerable to Prototype Pollution in index.js(). CVSSv3.1 9.8 (CRITICAL)
Shift Happens – Uncovering Two Built-in Command Injections in Windows Context Menus
SpecterOps researcher Remi Gascou disclosed two command injection vulnerabilities in Windows Explorer's built-in "Open PowerShell window here" context menu. By crafting folder names with special characters (e.g., "folder; calc"), attackers can achieve arbitrary PowerShell command execution when users Shift+Right-Click and select the menu option. One variant affects Windows 11 Canary builds; the other existed since Windows 10 1703 (2017) and was fixed after responsible disclosure to MSRC.
CVE-2026-41654 — Weblate Weblate: http://127.0.0.1:9999/) or using a non-allow-listed scheme (e.g.
Weblate is a web based localization tool. Prior to version 5.17.1, an authenticated user with project.add permission (default on hosted Weblate SaaS and for any user holding an active billing/trial plan) can import a crafted project backup ZIP whose components/<name>.json contains an attacker-chosen repo URL pointing at a private address (e.g. http://127.0.0.1:9999/) or using a non-allow-listed scheme (e.g. file://, git://). Weblate persists the component via Component.object CVSSv3.1 8.1 (HIGH)
CVE-2026-41505 — RELATE: Prior to commit 2f68e16, RELATE is vulnerable to predictable token generation in auth.py's make_sign_in_key()
RELATE is a web-based courseware package. Prior to commit 2f68e16, RELATE is vulnerable to predictable token generation in auth.py's make_sign_in_key() function and exam.py's gen_ticket_code() function. This issue has been patched via commit 2f68e16. CVSSv3.1 8.7 (HIGH)
CVE-2026-41422 — Daptin: Prior to version 0.11.4, the /aggregate/:typename endpoint accepted column and group query parameters that
Daptin is a GraphQL/JSON-API headless CMS. Prior to version 0.11.4, the /aggregate/:typename endpoint accepted column and group query parameters that were passed verbatim to goqu.L() — a raw SQL literal expression builder — without any validation. This bypassed all parameterization and allowed authenticated users with any valid session to inject arbitrary SQL expressions. This issue has been patched in version 0.11.4. CVSSv3.1 8.3 (HIGH)
CVE-2026-36458 — ChestnutCMS: v1.5.10 has a SQL injection vulnerability.
ChestnutCMS v1.5.10 has a SQL injection vulnerability. The content parameter of the cms_content tag can be manipulated in the admin backend and injected into a SQL query when the template is rendered. CVSSv3.1 9.8 (CRITICAL)
CVE-2025-63706 — NPM: package next-npm-version1.0.1 is vulnerable to Command injection.
NPM package next-npm-version1.0.1 is vulnerable to Command injection. CVSSv3.1 9.8 (CRITICAL)