2026-08-11
2026-08-11 12:17Z
HIGH

CVE-2026-72533 — Portainer: An authentication bypass vulnerability in Portainer CE through 2.44.0 allows authenticated low-privileged users to

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-72533

An authentication bypass vulnerability in Portainer CE through 2.44.0 allows authenticated low-privileged users to bypass Docker proxy authorization checks via non-canonical URL normalization, defeating all authorization middleware. The proxy endpoint fails to normalize request paths before applying access controls, allowing crafted requests to be interpreted differently by the proxy and the authorization layer. Successful exploitation grants the attacker root-level access to CVSSv3.1 8.8 (HIGH)

CWECWE 287VNDPortainerTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-08-11
2026-08-11 12:17Z
CRIT

CVE-2026-13739 — Commvault Commvault: A legacy endpoint in Command Center contained an unauthenticated server-side request forgery (SSRF) vulnerability

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-13739

A legacy endpoint in Command Center contained an unauthenticated server-side request forgery (SSRF) vulnerability related to the handling of arbitrary target URLs. Software customers upgrade to resolved maintenance release. Update Command Center. CVSSv3.1 9.8 (CRITICAL) · EPSS 27th percentile

CWECWE 918VNDCommvaultVNDCommandTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-08-11
2026-08-11 12:17Z
CRIT

CVE-2026-13738 — Commvault Commvault: CommServe contained an authorization bypass vulnerability affecting a limited set of command execution operations.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-13738

CommServe contained an authorization bypass vulnerability affecting a limited set of command execution operations. Software customers upgrade to resolved maintenance release. Update all Commvault installations, including Commserve, Webserver, Command Center, Media Agents, Clients and HyperScale X. CVSSv3.1 9.8 (CRITICAL) · EPSS 44th percentile

CWECWE 863VNDCommvaultVNDCommserveTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-08-11
2026-08-11 12:17Z
CRIT

CVE-2026-13737 — Commvault Commvault: CommServe contained an allowlist bypass vulnerability affecting command execution authorization.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-13737

CommServe contained an allowlist bypass vulnerability affecting command execution authorization. Software customers upgrade to resolved maintenance release. Update all Commvault installations, including Commserve, Webserver, Command Center, Media Agents, Clients and HyperScale X. CVSSv3.1 9.8 (CRITICAL) · EPSS 38th percentile

CWECWE 863VNDCommvaultVNDCommserveTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-08-11
2026-08-11 12:00Z
CRIT

Head Mare APT is exploiting vulnerabilities in an unpatched TrueConf server to deliver PhantomCore and PhantomGraph to video conference participants

Kaspersky Securelist·securelist.comin the wild

Kaspersky disclosed a sophisticated attack by Head Mare APT exploiting two zero-day vulnerabilities (KLCERT-26-057 and KLCERT-26-058) in TrueConf video conferencing servers (versions 5.3.x–5.5.5) to achieve unauthenticated remote code execution with SYSTEM privileges. The attackers replaced legitimate TrueConf client installers with malicious versions delivering PhantomCore and PhantomGraph backdoors to conference participants, establishing persistence via Windows services and using Microsoft OneDrive as a C2 channel. Patches were released June 18, 2026 (versions 5.3.9, 5.4.9, 5.5.5).

SRFApplicationTACTA0004TACTA0005TACTA0001TACTA0006TACTA0007SRFWebTACTA0003
92
Edit Score
2026-08-11
2026-08-11 11:43Z
CRIT

bad_garbage — CVE-2026-53361 AF_UNIX GC vs MSG_PEEK use-after-free container escape

GitHub · container escape·github.comGITHUB POCCVE-2026-53361CVE-2021-0920CVE-2026-23394

CVE-2026-53361 is a use-after-free vulnerability in the Linux kernel's AF_UNIX socket garbage collector triggered by a race condition between concurrent MSG_PEEK operations and the GC's census mechanism. The vulnerability allows unprivileged attackers to escape containers and achieve arbitrary code execution. A public proof-of-concept exploit targeting kernel versions 6.8–6.17 (including Ubuntu 24.04 HWE, Debian trixie, RHEL 10, and CentOS Stream 10) is now available on GitHub.

SRFOsTACTA0004TACTA0005OSLinuxTYPExploitTYPVulnerabilitySTGPrivescSTGExecution
92
Edit Score
2026-08-11
2026-08-11 11:17Z
CRIT

CVE-2026-58231 — SAP: Commerce Cloud allows an unauthenticated attacker to abuse a default authentication client and

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-58231

SAP Commerce Cloud allows an unauthenticated attacker to abuse a default authentication client and submit specially crafted input to certain functions lacking sufficient validation. Successful exploitation could enable arbitrary code execution and compromise internal components, resulting in high impact on confidentiality, integrity, and availability of the application. CVSSv3.1 10.0 (CRITICAL)

CWECWE 94VNDSapTYPVulnerability
10.0
CVSS v3.1
100
Edit Score
728 × 90 / responsive · programmatic ad slot
2026-08-11
2026-08-11 10:00Z
HIGH

Project CAV3RN continues: Google Apps Script as C2 relay and DNS-based C2 channel selection

Kaspersky Securelist·securelist.com

Kaspersky's GReAT team documented Project CAV3RN, a modular espionage framework targeting Israel, revealing a sophisticated multi-transport C2 architecture that leverages Google Apps Script as a relay and DNS A-record responses to dynamically select between direct HTTPS and Google-proxied channels. The framework uses DNS queries to validate and rotate Google Apps Script deployment IDs, includes a local DLL broker for component orchestration, and employs XOR-obfuscation and Base64 encoding to evade detection. Infrastructure analysis shows the threat actor re-registered an expired Israeli domain (studiotikva.com) in May 2026 and hosted both authoritative DNS and direct C2 endpoints.

SRFNetworkSRFCloudTACTA0011TACTA0010VNDMicrosoftVNDGoogleTYPResearchTYPThreat Intel
82
Edit Score
2026-08-11
2026-08-11 09:17Z
HIGH

CVE-2026-15560 — EAP: when EAP runs with -secmgr, the openjdk-orb's JDKBridge honours attacker-supplied CDR codebase URLs during

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-15560

when EAP runs with -secmgr, the openjdk-orb's JDKBridge honours attacker-supplied CDR codebase URLs during object unmarshalling on :3528, allowing an unauthenticated attacker to load and instantiate arbitrary classes from a remote URL in the server JVM before EJB security interceptors run. CVSSv3.1 8.1 (HIGH)

CWECWE 829VNDEapTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-08-11
2026-08-11 09:17Z
HIGH

CVE-2026-15556 — A flaw was found in Picketlink's SP signature validation; a SAML response containing zero

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-15556

A flaw was found in Picketlink's SP signature validation; a SAML response containing zero assertion elements matching the signature check can allow an attacker to forge a SAML response and auth as any principal with any roles on the protected application. CVSSv3.1 8.1 (HIGH)

CWECWE 347TYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-08-11
2026-08-11 09:17Z
HIGH

CVE-2026-15555 — JBoss: The Infinispan session replication path deserializes replicated session data via the JBoss Marshalling River

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-15555

A flaw was found in JBoss marshalling. The Infinispan session replication path deserializes replicated session data via the JBoss Marshalling River unmarshaller with no class filtering — enabling RCE via deserialization gadget chains on every cluster node. CVSSv3.1 8.8 (HIGH)

CWECWE 502VNDJbossTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-08-11
2026-08-11 09:17Z
CRIT

CVE-2026-10579 — Picketlink: This could lead to information disclosure, access to restricted operations, or other flaws.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-10579

A flaw was found in Picketlink Federation SAML; the unsolcited response handler would accept forged assertions with no verification or validation, permitting an unauthed attacker to authenticate as any principal in any role. This could lead to information disclosure, access to restricted operations, or other flaws. CVSSv3.1 9.8 (CRITICAL)

VNDPicketlinkTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-08-11
2026-08-11 07:17Z
HIGH

CVE-2026-16053 — Zohocorp: ManageEngine M365 Manager Plus and M365 Security Plus versions below 4820 are affected

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-16053

Zohocorp ManageEngine M365 Manager Plus and M365 Security Plus versions below 4820 are affected to Authenticated Path Traversal vulnerability in Exchange Online backup module. CVSSv3.1 8.5 (HIGH)

CWECWE 23VNDZohocorpTYPVulnerability
8.5
CVSS v3.1
93
Edit Score
2026-08-11
2026-08-11 07:00Z
CRIT

Critical SQL Injection in Metabase via Password Reset: CVE-2026-72898

Bishop Fox Labs·bishopfox.comCVE-2026-72898in the wild

A critical unauthenticated SQL injection vulnerability (CVSS 10.0) exists in Metabase's password reset endpoint (/api/session/reset_password) that allows attackers to execute arbitrary SQL against the application database and gain full administrative access. The flaw stems from insufficient input validation on undeclared request fields, and Metabase has confirmed active exploitation in the wild. Patches are available for Metabase 58.24+, 59.21+, 60.17+, 61.11+, 62.9+, and 63.5+.

SRFApplicationTACTA0001TACTA0006SRFWebSWMetabaseTYPVulnerabilitySTGInitial AccessSTGCred Access
92
Edit Score
2026-08-11
2026-08-11 06:17Z
CRIT

CVE-2026-19516 — Grafana: A caller-supplied X-Grafana-URL request header controls the destination of mcp-grafana's outbound requests, and the

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-19516

A caller-supplied X-Grafana-URL request header controls the destination of mcp-grafana's outbound requests, and the grafana_api_request tool lets the caller also choose the HTTP method, path, and body. Because the destination is not restricted to the configured Grafana instance, a caller can direct requests at internal, loopback, and link-local network services (including metadata endpoints) and read the responses, resulting in server-side request forgery. The fix for CVE-202 CVSSv3.1 9.1 (CRITICAL)

CWECWE 918VNDGrafanaTYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2026-08-11
2026-08-11 06:17Z
CRIT

CVE-2026-13716 — Path: traversal in server import and admin file upload in Crafty Controller.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-13716

Path traversal in server import and admin file upload in Crafty Controller. Allows a remote, authenticated attacker to upload files to arbitrary paths permitted to the Crafty Controller application and perform remote code execution. CVSSv3.1 9.1 (CRITICAL)

CWECWE 35TYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2026-08-11
2026-08-11 05:17Z
CRIT

CVE-2026-19425 — Travel: Agency Management System developed by Win Men Intermational has a SQL Injection vulnerability.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-19425

Travel Agency Management System developed by Win Men Intermational has a SQL Injection vulnerability. Unauthenticated remote attackers can inject arbitrary SQL commands to read, modify, and delete database contents. CVSSv3.1 9.8 (CRITICAL)

CWECWE 89VNDTravelTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-08-11
2026-08-11 01:17Z
HIGH

CVE-2026-58243 — SAP: ABAP Development Tools does not perform necessary authorization checks for certain functionality, allowing

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-58243

SAP ABAP Development Tools does not perform necessary authorization checks for certain functionality, allowing an attacker with low privileges to execute unauthorized database operations against SAP NetWeaver AS ABAP. Successful exploitation could allow the attacker to read sensitive data, modify application data, and disrupt access for legitimate users, resulting in high impact on confidentiality, integrity, and availability. CVSSv3.1 8.8 (HIGH)

CWECWE 862VNDSapTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-08-11
2026-08-11 01:17Z
CRIT

CVE-2026-44758 — SAP: Manufacturing Integration and Intelligence (MII) allows an attacker with high privileges to submit

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-44758

SAP Manufacturing Integration and Intelligence (MII) allows an attacker with high privileges to submit specially crafted input to certain affected functionality, which is processed without sufficient validation. Successful exploitation could allow the attacker to execute arbitrary commands on the underlying operating system, resulting in high impact on confidentiality, integrity, and availability of the application. CVSSv3.1 9.1 (CRITICAL)

CWECWE 94VNDSapTYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2026-08-11
2026-08-11 01:17Z
CRIT

CVE-2026-34265 — SAP: NetWeaver Application Server ABAP allows an unauthenticated attacker to exploit logical errors in

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-34265

SAP NetWeaver Application Server ABAP allows an unauthenticated attacker to exploit logical errors in DIAG protocol parsing, resulting in memory corruption. This vulnerability could potentially disclose sensitive system information or crash the system, leading to a high impact on the confidentiality, integrity, and availability of the application. CVSSv3.1 9.8 (CRITICAL)

CWECWE 787VNDSapTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-08-11
2026-08-11 00:00Z
HIGH

deno-case-studies

Sophos X-Ops·news.sophos.comin the wild

Sophos MDR documented a coordinated threat campaign in early 2026 leveraging Deno (a legitimate JavaScript/TypeScript runtime) as a fileless execution engine for C2 payloads. The attack chain combines ClickFix social engineering, trojanized MSI installers, VBS/PowerShell loaders, and LOLBin abuse (msiexec, wscript, curl, tar) to deploy Deno and execute obfuscated in-memory JavaScript. The threat actors use a repeatable framework with consistent staging mechanisms, NATO phonetic alphabet naming conventions, and hardcoded C2 infrastructure with JWT-based authentication.

SRFApplicationSRFOsTACTA0005TACTA0001TACTA0002TACTA0007TACTA0003OSWindows
78
Edit Score
2026-08-11
2026-08-11 00:00Z
HIGH

ClickFix campaign abuses Deno runtime for infostealer delivery

Sophos X-Ops·news.sophos.comin the wild

Sophos CTU identified a June 2026 ClickFix campaign leveraging the Deno JavaScript runtime as a core execution mechanism for infostealer delivery. Threat actors injected malicious JavaScript into 500+ compromised WordPress sites, serving Cloudflare-themed lures that tricked users into executing PowerShell commands. The chain installed Deno via winget, executed remote JavaScript payloads, and deployed a Python-based infostealer capable of harvesting credentials, browser data, and keystrokes.

SRFApplicationTACTA0005TACTA0001TACTA0006SRFWebTACTA0003SWWordpressSWDeno
72
Edit Score
2026-08-11
2026-08-11 00:00Z
HIGH

13 million tool calls: auditing every AI coding agent action with Elastic Agent

Elastic Security Labs·elastic.co

Elastic Security Labs published a comprehensive guide on auditing AI coding agent (Cursor) activity at scale using Cursor hooks and Elastic Agent. The approach captures 13+ million tool-call events across 1,100+ machines, logging shell commands, file reads, MCP server calls, and sub-agent spawns as structured JSONL events shipped to Elasticsearch for threat hunting and governance. The post includes a 280-line bash collector script, deployment patterns for MDM and non-MDM environments, ES|QL hunting queries, and privacy/access controls applied during rollout.

SRFApplicationSRFOsTACTA0007SWElasticsearchSWCursorSWElastic AgentVNDElasticTYPResearch
78
Edit Score
2026-08-11
2026-08-11 00:00Z
MED

13 million tool calls: auditing every AI coding agent action with Elastic Agent

Elastic Security Labs·elastic.co

Elastic Security Labs published a comprehensive guide on auditing AI coding agent activity (Cursor) using Cursor's hook system and Elastic Agent. The approach captures 13M+ tool-call events across 1,100+ machines via a 280-line bash collector script that logs shell commands, file reads, MCP server calls, and agent lifecycle events as structured JSONL, shipped to Elasticsearch for ES|QL hunting. The post includes deployment patterns, privacy controls, and threat-hunting queries for detecting credential access and suspicious download-execute patterns.

SRFApplicationTACTA0007TYPResearchTYPToolSTGCollectionTECT1105TECT1552.001
72
Edit Score
2026-08-10
2026-08-10 23:16Z
HIGH

CVE-2026-8718 — In CONFIG_USERSPACE builds the getsockopt syscall verifier (z_vrfy_zsock_getsockopt) bounce-buffers the user's optval into a

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-8718

tls_opt_dtls_peer_connection_id_value_get() in subsys/net/lib/sockets/sockets_tls.c, which handles getsockopt(SOL_TLS, TLS_DTLS_PEER_CID_VALUE), passed the caller-supplied optval directly to mbedtls_ssl_get_peer_cid() without verifying the buffer was at least MBEDTLS_SSL_CID_OUT_LEN_MAX (default 32) bytes. mbedtls_ssl_get_peer_cid() copies the peer-negotiated DTLS Connection ID (length 1..MBEDTLS_SSL_CID_OUT_LEN_MAX) into that buffer without a destination-size parameter, so a CVSSv3.1 8.4 (HIGH)

CWECWE 787TYPVulnerability
8.4
CVSS v3.1
92
Edit Score