3d ago
2026-07-27 14:16Z
CRIT

CVE-2026-61511 — vBulletin 5.x through 5.7.5 and 6.x through 6.2.1 contains an eval injection vulnerability in

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-61511

vBulletin 5.x through 5.7.5 and 6.x through 6.2.1 contains an eval injection vulnerability in the vB5_Template_Runtime::runMaths() method within the template runtime that allows unauthenticated remote attackers to execute arbitrary PHP code by supplying crafted input through the pagenav[pagenumber] parameter. Attackers can exploit the insufficiently restrictive regex filter by using phpfuck-style encoding with permitted characters to inject and execute arbitrary PHP code via CVSSv3.1 9.8 (CRITICAL)

CWECWE 95TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
3d ago
2026-07-27 13:18Z
HIGH

CVE-2026-59690 — Authorization: A Missing Authorization vulnerability in Progress Software LoadMaster, ECS Connection Manager, Object Scale Connection

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-59690

A Missing Authorization vulnerability in Progress Software LoadMaster, ECS Connection Manager, Object Scale Connection Manager, MOVEit WAF, and Multi Tenant allows an authenticated attacker with low privileges to perform privileged administrative operations via the REST API that should not be accessible to their permission level, potentially resulting in a system compromise. CVSSv3.1 8.0 (HIGH)

CWECWE 862TYPVulnerability
8.0
CVSS v3.1
90
Edit Score
3d ago
2026-07-27 13:18Z
HIGH

CVE-2026-59689 — Incorrect: An Incorrect Authorization vulnerability in Progress Software LoadMaster, ECS Connection Manager, Object Scale Connection

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-59689

An Incorrect Authorization vulnerability in Progress Software LoadMaster, ECS Connection Manager, Object Scale Connection Manager, and MOVEit WAF allows an authenticated attacker with low privileges to escalate privileges to root on the affected appliance, potentially resulting in full system compromise. CVSSv3.1 8.0 (HIGH)

CWECWE 863TYPVulnerability
8.0
CVSS v3.1
90
Edit Score
3d ago
2026-07-27 13:18Z
HIGH

CVE-2026-59688 — Command: An OS Command Injection vulnerability in Progress Software LoadMaster, ECS Connection Manager, Object Scale

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-59688

An OS Command Injection vulnerability in Progress Software LoadMaster, ECS Connection Manager, Object Scale Connection Manager, and MOVEit WAF allows an authenticated attacker with high privileges to execute arbitrary operating system commands on the affected appliance via the backup restore functionality, potentially resulting in complete system compromise. CVSSv3.1 8.4 (HIGH)

CWECWE 78VNDCommandTYPVulnerability
8.4
CVSS v3.1
92
Edit Score
3d ago
2026-07-27 13:18Z
HIGH

CVE-2026-59687 — Command: An OS Command Injection vulnerability in Progress Software LoadMaster, ECS Connection Manager, Object Scale

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-59687

An OS Command Injection vulnerability in Progress Software LoadMaster, ECS Connection Manager, Object Scale Connection Manager, and MOVEit WAF allows an authenticated attacker with high privileges to execute arbitrary operating system commands on the affected appliance via the Geo Location management interface, potentially resulting in complete system compromise. CVSSv3.1 8.4 (HIGH)

CWECWE 78VNDCommandTYPVulnerability
8.4
CVSS v3.1
92
Edit Score
3d ago
2026-07-27 13:18Z
HIGH

CVE-2026-59686 — Command: An OS Command Injection vulnerability in Progress Software LoadMaster, ECS Connection Manager, Object Scale

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-59686

An OS Command Injection vulnerability in Progress Software LoadMaster, ECS Connection Manager, Object Scale Connection Manager, and MOVEit WAF allows an authenticated attacker with high privileges to execute arbitrary operating system commands on the affected appliance via the management interface, potentially resulting in complete system compromise. CVSSv3.1 8.4 (HIGH)

CWECWE 78VNDCommandTYPVulnerability
8.4
CVSS v3.1
92
Edit Score
3d ago
2026-07-27 12:16Z
CRIT

CVE-2026-58662 — Apache Thrift: Improper Validation of Specified Quantity in Input, Out-of-bounds Read vulnerability in Apache Thrift C++

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-58662

Improper Validation of Specified Quantity in Input, Out-of-bounds Read vulnerability in Apache Thrift C++ bindings. This issue affects Apache Thrift: before 0.24.0. Users are recommended to upgrade to version 0.24.0, which fixes the issue. CVSSv3.1 9.1 (CRITICAL)

CWECWE 125CWECWE 1284VNDApacheTYPVulnerability
9.1
CVSS v3.1
96
Edit Score
728 × 90 / responsive · programmatic ad slot
3d ago
2026-07-27 12:16Z
CRIT

CVE-2026-58023 — Apache Thrift: Out-of-bounds Read vulnerability in Apache Thrift c_glib bindings.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-58023

Out-of-bounds Read vulnerability in Apache Thrift c_glib bindings. This issue affects Apache Thrift: before 0.24.0. Users are recommended to upgrade to version 0.24.0, which fixes the issue. CVSSv3.1 9.1 (CRITICAL)

CWECWE 125VNDApacheTYPVulnerability
9.1
CVSS v3.1
96
Edit Score
3d ago
2026-07-27 12:16Z
CRIT

CVE-2026-55971 — Apache Thrift: Heap-based Buffer Overflow vulnerability in Apache Thrift C++ bindings.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-55971

Heap-based Buffer Overflow vulnerability in Apache Thrift C++ bindings. This issue affects Apache Thrift: before 0.24.0. Users are recommended to upgrade to version 0.24.0, which fixes the issue. CVSSv3.1 9.8 (CRITICAL)

CWECWE 122VNDApacheVNDHeapTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
3d ago
2026-07-27 12:16Z
CRIT

CVE-2026-48144 — Apache Thrift: Improper Validation of Certificate with Host Mismatch vulnerability in Apache Thrift c_glib bindings.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-48144

Improper Validation of Certificate with Host Mismatch vulnerability in Apache Thrift c_glib bindings. This issue affects Apache Thrift: before 0.24.0. Users are recommended to upgrade to version 0.24.0, which fixes the issue. CVSSv3.1 9.1 (CRITICAL)

CWECWE 297VNDApacheTYPVulnerability
9.1
CVSS v3.1
96
Edit Score
3d ago
2026-07-27 08:16Z
HIGH

CVE-2026-64536 — Linux: In the Linux kernel, the following vulnerability has been resolved: staging: rtl8723bs: fix OOB

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-64536

In the Linux kernel, the following vulnerability has been resolved: staging: rtl8723bs: fix OOB reads in is_ap_in_tkip() IE loop The loop in is_ap_in_tkip() iterates over IEs without verifying that enough bytes remain before dereferencing the IE header or its payload: - pIE->element_id and pIE->length are read without checking that i + sizeof(*pIE) <= ie_length, so a truncated IE at the end of the buffer causes an OOB read. - For WLAN_EID_VENDOR_SPECIFIC the code comp CVSSv3.1 8.1 (HIGH)

TYPVulnerability
8.1
CVSS v3.1
91
Edit Score
3d ago
2026-07-27 08:16Z
CRIT

CVE-2026-64535 — Linux: In the Linux kernel, the following vulnerability has been resolved: nvmet-tcp: Fix potential UAF

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-64535

In the Linux kernel, the following vulnerability has been resolved: nvmet-tcp: Fix potential UAF when ddgst mismatch Shivam Kumar found via vulnerability testing: When data digest is enabled on an NVMe/TCP connection and a digest mismatch occurs on a non-final H2C_DATA PDU during an R2T-based data transfer, the digest error handler in nvmet_tcp_try_recv_ddgst() calls nvmet_req_uninit() — which performs percpu_ref_put() on the submission queue — but does NOT mark the command CVSSv3.1 9.8 (CRITICAL)

TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
3d ago
2026-07-27 08:16Z
CRIT

CVE-2026-64534 — Linux: The unconditional percpu_ref_put() inside nvmet_req_uninit() then causes a refcount underflow, leading to a WARNING

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-64534

In the Linux kernel, the following vulnerability has been resolved: nvmet-tcp: check INIT_FAILED before nvmet_req_uninit in digest error path In nvmet_tcp_try_recv_ddgst(), when a data digest mismatch is detected, nvmet_req_uninit() is called unconditionally. However, if the command arrived via the nvmet_tcp_handle_req_failure() path, nvmet_req_init() had returned false and percpu_ref_tryget_live() was never executed. The unconditional percpu_ref_put() inside nvmet_req_unin CVSSv3.1 9.8 (CRITICAL)

TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
3d ago
2026-07-27 07:16Z
HIGH

CVE-2026-9830 — WordPress: The bookingpress-appointment-booking-pro WordPress plugin before 5.7.3 does not correctly invoke its REST permission callback

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-9830

The bookingpress-appointment-booking-pro WordPress plugin before 5.7.3 does not correctly invoke its REST permission callback, leaving every route in one of its API namespaces reachable without authentication and allowing unauthenticated attackers to read customer booking data and modify other users' bookings. CVSSv3.1 8.2 (HIGH)

CWECWE 287VNDWordpressTYPVulnerability
8.2
CVSS v3.1
91
Edit Score
3d ago
2026-07-27 07:16Z
CRIT

CVE-2026-14289 — FacturaONE: The FacturaONE para WooCommerce con VeriFactu WordPress plugin before 5.37 does not authenticate one

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-14289

The FacturaONE para WooCommerce con VeriFactu WordPress plugin before 5.37 does not authenticate one of its request handlers, whose only protection is derived from a cryptographic key that is empty in the default, unconfigured state, allowing unauthenticated attackers to write an arbitrary file into a web-accessible directory and achieve remote code execution. CVSSv3.1 9.0 (CRITICAL)

CWECWE 94VNDFacturaoneTYPVulnerability
9.0
CVSS v3.1
95
Edit Score
3d ago
2026-07-27 07:16Z
CRIT

CVE-2026-13714 — Realtyna: This makes it possible for unauthenticated attackers to upload arbitrary PHP files and achieve

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-13714

The Realtyna Organic IDX plugin + WPL Real Estate WordPress plugin before 5.3.0 does not validate the type of uploaded files, and its file upload functionality is gated only by an API that is enabled by default and authenticated with hardcoded credentials shipped identically across all installations. This makes it possible for unauthenticated attackers to upload arbitrary PHP files and achieve remote code execution. CVSSv3.1 9.8 (CRITICAL)

CWECWE 434VNDRealtynaTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
3d ago
2026-07-27 07:16Z
CRIT

CVE-2026-13597 — WordPress: This allows an unauthenticated attacker to forge a login event for any existing username

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-13597

The 微信二维码登陆 WordPress plugin through 1.3 does not properly validate WeChat webhook requests, as its signature check always passes, and it discloses the generated login code in the webhook response. This allows an unauthenticated attacker to forge a login event for any existing username, read the login code, and redeem it through an unauthenticated AJAX action to log in as that user, including an administrator, without a password. CVSSv3.1 9.1 (CRITICAL)

CWECWE 287VNDWordpressTYPVulnerability
9.1
CVSS v3.1
96
Edit Score
3d ago
2026-07-27 07:16Z
CRIT

CVE-2026-13332 — Masteriyo: The Masteriyo LMS WordPress plugin before 2.3.1 does not correctly verify authorization on an

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-13332

The Masteriyo LMS WordPress plugin before 2.3.1 does not correctly verify authorization on an unauthenticated AJAX action used to clear user sessions, allowing unauthenticated attackers to terminate the active sessions (force-logout) of any user on the site, including administrators. CVSSv3.1 9.1 (CRITICAL)

CWECWE 287VNDMasteriyoTYPVulnerability
9.1
CVSS v3.1
96
Edit Score
3d ago
2026-07-27 07:16Z
HIGH

CVE-2026-13152 — Custom: The Custom Fields Account Registration For Woocommerce WordPress plugin before 1.4 does not prevent

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-13152

The Custom Fields Account Registration For Woocommerce WordPress plugin before 1.4 does not prevent its custom registration fields from writing to the user capabilities meta key on sites that use a non-default database table prefix, so an unauthenticated user who registers an account can be granted the administrator role when a correspondingly named field has been configured. CVSSv3.1 8.1 (HIGH)

CWECWE 269VNDCustomTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
3d ago
2026-07-27 07:16Z
CRIT

CVE-2026-12394 — MemberGlut: The MemberGlut WordPress plugin before 1.1.5 does not validate the role chosen during front-end

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-12394

The MemberGlut WordPress plugin before 1.1.5 does not validate the role chosen during front-end registration, allowing unauthenticated users to register an account with an arbitrary role, including administrator, leading to full site compromise. CVSSv3.1 9.8 (CRITICAL)

CWECWE 269VNDMemberglutTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
3d ago
2026-07-27 07:16Z
HIGH

CVE-2026-12255 — MainWP: The MainWP Child WordPress plugin before 6.1.2 does not verify the requester's identity in

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-12255

The MainWP Child WordPress plugin before 6.1.2 does not verify the requester's identity in its site-registration request handler when password authentication has been disabled for the targeted account, allowing an unauthenticated attacker to obtain a valid authentication session as that account, including an administrator, by naming its login in a single registration request. CVSSv3.1 8.1 (HIGH)

CWECWE 287VNDMainwpTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
3d ago
2026-07-27 07:16Z
HIGH

CVE-2025-15662 — Printcart: The Printcart Web to Print Product Designer for WooCommerce WordPress plugin before 2.5.3 does

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2025-15662

The Printcart Web to Print Product Designer for WooCommerce WordPress plugin before 2.5.3 does not restrict a user-supplied URL before fetching it server-side and does not enforce a valid authorization check, allowing unauthenticated attackers to read arbitrary local files (including configuration files containing database credentials and secret keys) and to make server-side requests to internal resources. CVSSv3.1 8.6 (HIGH)

CWECWE 918VNDPrintcartTYPVulnerability
8.6
CVSS v3.1
93
Edit Score
4d ago
2026-07-27 00:00Z
INFO

2607-secai

Sophos X-Ops·news.sophos.com

Sophos CISO Ross McKerchar outlines the company's internal AI governance framework, including their AI Safety Board decision-making process, risk philosophy (good vs. bad risks mapped on upside/downside axes), and operational patterns for deploying agentic AI safely. The post acknowledges that security patterns for AI agent monitoring, incident response, and prompt-injection defense are still forming, and emphasizes blast-radius reduction as the practical discipline until mature patterns emerge.

TACTA0005SRFAiVNDSophosTYPResearchSTGDefense Evasion
62
Edit Score
4d ago
2026-07-26 15:16Z
HIGH

CVE-2026-17497 — NoteGen: before 0.32.0 grants the Tauri shell plugin shell:allow-execute capability for bash, python, and

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-17497

NoteGen before 0.32.0 grants the Tauri shell plugin shell:allow-execute capability for bash, python, and python3 with arbitrary arguments in the default desktop capabilities. JavaScript running in the application webview can therefore invoke plugin:shell|execute to run attacker-controlled operating system commands with the privileges of the NoteGen process. In combination with script execution in the webview (for example via chat XSS), this enables full remote code execution CVSSv3.1 8.3 (HIGH)

CWECWE 78CWECWE 276CWECWE 1249VNDNotegenTYPVulnerability
8.3
CVSS v3.1
92
Edit Score
4d ago
2026-07-26 15:16Z
HIGH

CVE-2026-17496 — NoteGen: When the user views the chat response, that markup runs as JavaScript in the

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-17496

NoteGen before 0.32.0 renders AI chat responses with markdown-it configured with html:true and injects the result into the DOM via dangerouslySetInnerHTML in chat-preview, without HTML sanitization and with CSP set to null. Attacker-controlled content that reaches the model prompt (for example a malicious skill REFERENCE.md that instructs the model to emit HTML) can cause the model response to include executable markup such as an img onerror handler. When the user views the c CVSSv3.1 8.1 (HIGH)

CWECWE 79VNDNotegenTYPVulnerability
8.1
CVSS v3.1
91
Edit Score