2026-08-13
2026-08-13 17:17Z
HIGH

CVE-2026-59109 — SQL: injection in the Zalktis accounting application via trading-partner-controlled text fields in received electronic

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-59109

SQL injection in the Zalktis accounting application via trading-partner-controlled text fields in received electronic invoices. When importing a received e-invoice (UBL/PEPPOL) or an e-commerce export, Zalktis concatenates partner-controlled values directly into SQL statement text using string concatenation, with neither parameterised queries nor escaping. The application's own escaping helper, Dazadi.sql_txt(), is not invoked on these code paths, so a party that sends an inv CVSSv3.1 8.8 (HIGH)

CWECWE 89CWECWE 20TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-08-13
2026-08-13 17:17Z
CRIT

CVE-2026-58508 — Two: SSRF vulnerabilities in Gitea migration/mirror (DNS rebinding + missing re-validation)

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-58508

Two SSRF vulnerabilities in Gitea migration/mirror (DNS rebinding + missing re-validation) CVSSv3.1 9.1 (CRITICAL)

CWECWE 284VNDTwoTYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2026-08-13
2026-08-13 17:17Z
CRIT

CVE-2026-58443 — Public: Public-only repository tokens can update private PR head branches

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-58443

Public-only repository tokens can update private PR head branches CVSSv3.1 9.1 (CRITICAL)

CWECWE 863TYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2026-08-13
2026-08-13 17:17Z
HIGH

CVE-2026-58439 — Branch: Protection Bypass via PR Retargeting Preserves Stale `official` Approval Flag

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-58439

Branch Protection Bypass via PR Retargeting Preserves Stale `official` Approval Flag CVSSv3.1 8.1 (HIGH)

CWECWE 284VNDBranchTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-08-13
2026-08-13 17:17Z
CRIT

CVE-2026-58433 — Team: Team-repository linking endpoint bypasses the RepoAdminChangeTeamAccess organization setting

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-58433

Team-repository linking endpoint bypasses the RepoAdminChangeTeamAccess organization setting CVSSv3.1 9.1 (CRITICAL)

CWECWE 862VNDTeamTYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2026-08-13
2026-08-13 17:17Z
HIGH

CVE-2026-57894 — Repository: Migration Follows Git HTTP Redirects After URL Allow/Block Validation, Enabling Internal Git Repository

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-57894

Repository Migration Follows Git HTTP Redirects After URL Allow/Block Validation, Enabling Internal Git Repository Exfiltration CVSSv3.1 8.5 (HIGH)

CWECWE 918VNDRepositoryTYPVulnerability
8.5
CVSS v3.1
93
Edit Score
2026-08-13
2026-08-13 17:17Z
CRIT

CVE-2026-56750 — Gitea: Remember-Me Token Theft Not Invalidating Attacker Session

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-56750

Gitea Remember-Me Token Theft Not Invalidating Attacker Session CVSSv3.1 9.1 (CRITICAL)

CWECWE 284VNDGiteaTYPVulnerability
9.1
CVSS v3.1
96
Edit Score
728 × 90 / responsive · programmatic ad slot
2026-08-13
2026-08-13 17:17Z
CRIT

CVE-2026-56654 — Privilege: Escalation via Access Token Scope Escalation in API

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-56654

Privilege Escalation via Access Token Scope Escalation in API CVSSv3.1 9.8 (CRITICAL)

CWECWE 284TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-08-13
2026-08-13 17:17Z
CRIT

CVE-2026-56443 — Token: public-only scope bypassed on Limited-visibility owners (Repository + Package categories) — residual after

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-56443

Token public-only scope bypassed on Limited-visibility owners (Repository + Package categories) — residual after CVE-2026-25714 / PR #37118 CVSSv3.1 9.6 (CRITICAL)

CWECWE 863TYPVulnerability
9.6
CVSS v3.1
98
Edit Score
2026-08-13
2026-08-13 17:17Z
HIGH

CVE-2026-55987 — OAuth2: sign-in reactivates an administrator-deactivated account on auth sources without refresh tokens (incomplete fix

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-55987

OAuth2 sign-in reactivates an administrator-deactivated account on auth sources without refresh tokens (incomplete fix of #38009) CVSSv3.1 8.1 (HIGH)

CWECWE 863VNDOauth2TYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-08-13
2026-08-13 17:17Z
CRIT

CVE-2026-55982 — OIDC: userinfo Endpoint Returns Identity Claims Without Enforcing API Token Scopes

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-55982

OIDC userinfo Endpoint Returns Identity Claims Without Enforcing API Token Scopes CVSSv3.1 9.1 (CRITICAL)

CWECWE 200VNDOidcTYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2026-08-13
2026-08-13 17:17Z
HIGH

CVE-2026-24791 — Public: Public-only tokens bypass private-resource restrictions on `/api/v1/user` self routes

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-24791

Public-only tokens bypass private-resource restrictions on `/api/v1/user` self routes CVSSv3.1 8.1 (HIGH)

CWECWE 863TYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-08-13
2026-08-13 17:17Z
CRIT

CVE-2026-13051 — Form: Form::Processor::Field::HtmlArea versions from 0.06 through 1.162360 for Perl allow attacker selected method dispatch and

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-13051

Form::Processor::Field::HtmlArea versions from 0.06 through 1.162360 for Perl allow attacker selected method dispatch and resource exhaustion via an HTML::Tidy diagnostic that validate passes to add_error as a Locale::Maketext template. validate runs HTML::Tidy over the submitted markup and passes each resulting message to add_error as its first argument, which add_error hands to the language handle as the Locale::Maketext message key. The default handle's lexicon sets `_AUT CVSSv3.1 9.1 (CRITICAL)

CWECWE 1336CWECWE 470VNDFormTYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2026-08-13
2026-08-13 17:17Z
HIGH

CVE-2026-13048 — Data: Data::MuForm::Localizer versions through 0.05 for Perl execute Perl from a message catalog header, reached

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-13048

Data::MuForm::Localizer versions through 0.05 for Perl execute Perl from a message catalog header, reached at an arbitrary path because load_lexicon interpolates the language attribute into the catalog filename. load_lexicon builds the catalog path by appending `Messages/$lang.po` to the directory holding Localizer.pm, where $lang is the language attribute, with no check that it names a bare locale tag. A value holding `../` segments walks out of the message directory, so an CVSSv3.1 8.2 (HIGH)

CWECWE 22CWECWE 95TYPVulnerability
8.2
CVSS v3.1
91
Edit Score
2026-08-13
2026-08-13 17:17Z
CRIT

CVE-2022-4993 — HTML: HTML::FormHandler versions through 0.40068 for Perl allow attacker selected method dispatch and resource exhaustion

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2022-4993

HTML::FormHandler versions through 0.40068 for Perl allow attacker selected method dispatch and resource exhaustion because _apply_actions and add_error use error message text built from request data as a Locale::Maketext bracket notation template. add_error hands its first argument to the language handle as the Locale::Maketext message key, and the default handle's lexicon sets `_AUTO`, so a string that is not a lexicon entry is compiled as a bracket notation template inste CVSSv3.1 9.1 (CRITICAL)

CWECWE 1336CWECWE 470TYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2026-08-13
2026-08-13 16:19Z
HIGH

CVE-2026-73570 — A remote code execution vulnerability exists in Zimbra Collaboration (ZCS) before 10.1.20 when the

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-73570

A remote code execution vulnerability exists in Zimbra Collaboration (ZCS) before 10.1.20 when the optional zimbra-snmp package is installed and SNMP notifications are enabled. Due to improper sanitization of untrusted input during SNMP notification processing, an unauthenticated attacker can send specially crafted SMTP requests that may result in execution of arbitrary operating system commands as the Zimbra user. CVSSv3.1 8.9 (HIGH)

CWECWE 78TYPVulnerability
8.9
CVSS v3.1
95
Edit Score
2026-08-13
2026-08-13 16:19Z
CRIT

CVE-2026-73533 — Ninja: Tables Pro 5.2.11 contains an embedded malicious code vulnerability introduced via a tampered

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-73533

Ninja Tables Pro 5.2.11 contains an embedded malicious code vulnerability introduced via a tampered plugin build served through a decommissioned update server. The tampered build introduced a rogue PHP file (app/Library/updater/NinjaTableDataSync.php) that established a backdoor REST API endpoint, dropped persistent PHP files in mu-plugins and uploads directories, installed a passwordless administrator account, and registered scheduled tasks that survived plugin removal. CVSSv3.1 9.8 (CRITICAL)

CWECWE 506VNDNinjaTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-08-13
2026-08-13 16:19Z
CRIT

CVE-2026-73532 — Fluent: Forms Pro 6.2.7 contains an embedded malicious code vulnerability introduced via a tampered

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-73532

Fluent Forms Pro 6.2.7 contains an embedded malicious code vulnerability introduced via a tampered plugin build served through a decommissioned update server. The tampered build introduced a rogue PHP file (libs/class-license-sync.php), loaded via a require_once directive added to fluentformpro.php, that established a backdoor REST API endpoint, dropped persistent PHP files in mu-plugins and uploads directories, installed a passwordless administrator account, and registered s CVSSv3.1 9.8 (CRITICAL)

CWECWE 506VNDFluentTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-08-13
2026-08-13 16:19Z
HIGH

CVE-2026-73515 — PostGIS: before 3.7.0beta2 contains an out-of-bounds read vulnerability that allows attackers to cause memory

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-73515

PostGIS before 3.7.0beta2 contains an out-of-bounds read vulnerability that allows attackers to cause memory disclosure or a server crash by supplying a malformed FlatGeobuf buffer. The FlatGeobuf property metadata decoder verifies that a string length field is present but fails to verify that the subsequent string body is contained within the supplied buffer before materializing it into a SQL-visible value, enabling memory disclosure or denial of service. CVSSv3.1 8.1 (HIGH)

CWECWE 125VNDPostgisTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-08-13
2026-08-13 16:19Z
HIGH

CVE-2026-73514 — PostGIS: The address_standardizer extension for PostGIS through 3.7.0, fixed in commit 423570b, contains an out-of-bounds

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-73514

The address_standardizer extension for PostGIS through 3.7.0, fixed in commit 423570b, contains an out-of-bounds write vulnerability that allows a database user with the ability to supply caller-controlled relation names to standardize_address() to trigger memory corruption by providing a rules table with a classification Type value exceeding the fixed class range. Attackers can craft a malicious rules table entry with an oversized rule type value that is used without bounds CVSSv3.1 8.8 (HIGH)

CWECWE 787VNDPostgisTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-08-13
2026-08-13 16:00Z
HIGH

Return of the Cookie Monster

SpecterOps·specterops.io

SpecterOps published research on enabling Chrome DevTools Protocol (CDP) inside running Chromium browser processes to bypass cookie protections and perform post-exploitation activities including cookie theft, password extraction, and browser takeover. The technique leverages a Beacon Object File (CDP-Enable-BOF) to inject a remote debugging stub into chrome.exe or msedge.exe without requiring process restart or suspicious launch arguments, paired with CDP-Toolkit for automated browser enumeration and credential harvesting.

SRFApplicationTACTA0006TACTA0007SRFBrowserOSWindowsTYPResearchTYPToolSTGExecution
82
Edit Score
2026-08-13
2026-08-13 16:00Z
HIGH

Attack of The Extensions

SpecterOps·specterops.io

SpecterOps researchers released SilentChrome-BOF, a Beacon object file that silently installs Chromium extensions by modifying the Secure Preferences file, bypassing user interaction. The technique leverages a new Mythic C2 agent called Ditto that runs as a browser extension with optional Isolated Web Application (IWA) and Native Messaging Host sidecars to enable cookie theft, tab enumeration, page capture, browser history queries, SOCKS proxying, and Windows OS interaction. The attack chain defeats extension allow-lists through public-key reuse and persists across browser restarts without user awareness.

SRFApplicationTACTA0005TACTA0003SRFBrowserSWMythicSWChromiumSWEdgeSWChrome
82
Edit Score
2026-08-13
2026-08-13 15:20Z
HIGH

CVE-2026-70463 — rsync 3.1.0 before 3.5.0 contains an authorization bypass in auth users directive parsing.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-70463

rsync 3.1.0 before 3.5.0 contains an authorization bypass in auth users directive parsing. The auth users parser uses comma-only tokenization when splitting the user list, which fails to correctly handle entries of the form @Group Name where the group name contains a space. The space within the group name causes the parser to split the entry at the space boundary, discarding the deny rule associated with the group. An authenticated user whose username or group membership woul CVSSv3.1 8.1 (HIGH)

CWECWE 863TYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-08-13
2026-08-13 15:20Z
HIGH

CVE-2026-70461 — rsync 3.2.5 before 3.5.0 contains a heap out-of-bounds write vulnerability that allows remote unauthenticated

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-70461

rsync 3.2.5 before 3.5.0 contains a heap out-of-bounds write vulnerability that allows remote unauthenticated attackers to write one attacker-controlled byte past the end of a heap allocation by supplying a crafted files-from entry. Attackers can trigger the vulnerability against a read-only rsync daemon module by providing a files-from entry containing both an interior and trailing backslash, causing the add_implied_include() function to under-count the trailing backslash wh CVSSv3.1 8.2 (HIGH)

CWECWE 787TYPVulnerability
8.2
CVSS v3.1
91
Edit Score
2026-08-13
2026-08-13 15:19Z
HIGH

CVE-2026-70460 — rsync 2.3.3 before 3.5.0 contains a path traversal vulnerability that allows a malicious sender

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-70460

rsync 2.3.3 before 3.5.0 contains a path traversal vulnerability that allows a malicious sender to escape the module root by exploiting symlinks within the module file tree when using --partial-dir or --backup-dir options. Attackers with write access to place a symlink under the module root, or who can exploit a pre-existing trusted symlink, can direct file writes to locations outside the intended module root, achieving arbitrary file write relative to the module root parent. CVSSv3.1 8.1 (HIGH)

CWECWE 22CWECWE 59TYPVulnerability
8.1
CVSS v3.1
91
Edit Score