Subscribe, build a custom feed, or pitch a sponsorship at hello@acadenix.com
Latest intel// live feed
CVE-2026-39553 — Control: Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion')
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Select-Themes WaveRide allows PHP Local File Inclusion. This issue affects WaveRide: from n/a through 1.4. CVSSv3.1 8.1 (HIGH)
CVE-2026-39552 — Control: Blueprint allows PHP Local File Inclusion.
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Code Supply Co. Blueprint allows PHP Local File Inclusion. This issue affects Blueprint: from n/a before 1.1.5. CVSSv3.1 8.1 (HIGH)
CVE-2026-10622 — Authentication: Improper Authentication in REST API in Collibra Agent, allows a remote unauthenticated attacker to
Improper Authentication in REST API in Collibra Agent, allows a remote unauthenticated attacker to access privileged functionality via exposed '/rest/* endpoints. CVSSv3.1 8.2 (HIGH)
CVE-2025-69369 — Control: Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion')
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Axiomthemes Racquet allows PHP Local File Inclusion. This issue affects Racquet: from n/a through 1.12.0. CVSSv3.1 8.1 (HIGH)
CVE-2025-68886 — Control: Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion')
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in androThemes Cookiteer allows PHP Local File Inclusion. This issue affects Cookiteer: from n/a through 1.4.8. CVSSv3.1 8.1 (HIGH)
CVE-2025-58897 — Control: Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion')
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Axiomthemes Fermentio allows PHP Local File Inclusion. This issue affects Fermentio: from n/a through 1.5.0. CVSSv3.1 8.1 (HIGH)
CVE-2025-58707 — Control: Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion')
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Axiomthemes Spin allows PHP Local File Inclusion. This issue affects Spin: from n/a through 1.8. CVSSv3.1 8.1 (HIGH)
CVE-2019-25719 — Infinity: Dräger Infinity Acute Care System and Standalone Infinity M540 patient monitors running software versions
Dräger Infinity Acute Care System and Standalone Infinity M540 patient monitors running software versions VG4.1.1, VG4.0.3, and lower contain network message handling vulnerabilities that allow network-adjacent attackers to spoof or tamper with data and cause denial-of-service conditions. Attackers with access to an enabled Infinity network port or physical proximity to a wireless access point can modify device settings such as alarm states or alarm limits, and overwhelm the CVSSv3.1 8.6 (HIGH)
CVE-2026-42684 — Neutralization: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Ahmad WP Job Portal allows Blind SQL Injection. This issue affects WP Job Portal: from n/a through 2.5.1. CVSSv3.1 9.3 (CRITICAL)
CVE-2026-39551 — Deserialization: of Untrusted Data vulnerability in Elated-Themes Töbel allows Object Injection.
Deserialization of Untrusted Data vulnerability in Elated-Themes Töbel allows Object Injection. This issue affects Töbel: from n/a through 1.8.1. CVSSv3.1 8.1 (HIGH)
CVE-2026-39550 — Deserialization: of Untrusted Data vulnerability in Elated-Themes Aperitif allows Object Injection.
Deserialization of Untrusted Data vulnerability in Elated-Themes Aperitif allows Object Injection. This issue affects Aperitif: from n/a through 1.6. CVSSv3.1 8.1 (HIGH)
CVE-2025-58705 — Control: Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion')
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Axiomthemes Crafti allows PHP Local File Inclusion. This issue affects Crafti: from n/a through 1.12. CVSSv3.1 8.1 (HIGH)
CVE-2025-53440 — Control: Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion')
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Axiomthemes Confidant allows PHP Local File Inclusion. This issue affects Confidant: from n/a through 1.4. CVSSv3.1 8.1 (HIGH)
CVE-2026-5422 — Jupyter Jupyter_server: A path traversal vulnerability exists in jupyter-server version 2.17.0 due to an incorrect root
A path traversal vulnerability exists in jupyter-server version 2.17.0 due to an incorrect root directory boundary check in the _get_os_path() function within jupyter_server/services/contents/fileio.py. The check uses startswith(root) without appending a trailing path separator, allowing sibling directories with names starting with the same prefix as root_dir to bypass the check. Additionally, the to_os_path() function in utils.py does not strip ".." from path parts, enabling CVSSv3.1 8.1 (HIGH)
CVE-2025-53345 — Authorization: Missing Authorization vulnerability leading to code execution after installing malicious vulnerable plugin in ThimPress
Missing Authorization vulnerability leading to code execution after installing malicious vulnerable plugin in ThimPress Thim Core. This issue affects Thim Core: from n/a through 2.3.3. CVSSv3.1 8.8 (HIGH)
CVE-2025-53209 — Incorrect: Privilege Assignment vulnerability in Themeisle Masteriyo LMS PRO allows Privilege Escalation.
Incorrect Privilege Assignment vulnerability in Themeisle Masteriyo LMS PRO allows Privilege Escalation. This issue affects Masteriyo LMS PRO: from n/a through 2.20.0. CVSSv3.1 9.8 (CRITICAL)
CVE-2026-1784 — Route: The Route OpenShift resource allows to define routes to make pods reachable at a
The Route OpenShift resource allows to define routes to make pods reachable at a subdomain through HAProxy. It was found that the checks performed on the spec.path YAML stanza in a Route document was insufficient and could allow a controlled injection of the HAProxy configuration. CVSSv3.1 8.8 (HIGH)
CVE-2026-8206 — Kirki: The Kirki – Freeform Page Builder, Website Builder & Customizer plugin for WordPress is
The Kirki – Freeform Page Builder, Website Builder & Customizer plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions 6.0.0 to 6.0.6. This is due to the plugin accepting an arbitrary email address when a username is used in the password reset request. This makes it possible for unauthenticated attackers to send a password reset link for any user registered on the site to their own email address. CVSSv3.1 9.8 (CRITICAL)
Pointing a Cursor at evading detection
Sophos X-Ops identified a threat actor using AI-accelerated tools (Cursor IDE, Claude Opus agents) to develop and iteratively test EDR evasion techniques against Sophos, CrowdStrike, and Windows Defender. The attacker built a modular payload generator with ~80 modules testing 70+ evasion techniques, integrated Cobalt Strike profiles, Telegram-based C2, and Sliver post-exploitation framework within a virtualized red-team lab environment. The activity was linked to known ransomware deployment and data theft operations.
CVE-2026-25879 — Langroid: Prior to version 0.63.0, SQLChatAgent executes SQL produced by an LLM, which is influenceable
Langroid is a framework for building large-language-model-powered applications. Prior to version 0.63.0, SQLChatAgent executes SQL produced by an LLM, which is influenceable by prompt injection. When configured with a database role that has privileges enabling code execution or filesystem access (e.g., PostgreSQL pg_execute_server_program, MySQL FILE, MSSQL xp_cmdshell), an attacker who can shape the agent's input — including indirectly via data returned to the LLM — can coer CVSSv3.1 9.8 (CRITICAL)
CVE-2026-25277 — Memory: corruption while using Strongbox due to buffer overflow.
Memory corruption while using Strongbox due to buffer overflow. CVSSv3.1 8.8 (HIGH)
CVE-2026-25276 — Memory: corruption while using Strongbox due to missing bounds check.
Memory corruption while using Strongbox due to missing bounds check. CVSSv3.1 8.8 (HIGH)
CVE-2026-24752 — Kiteworks: Prior to version 9.3.0, a reflected XSS vulnerability in Kiteworks Secure Data Forms could
Kiteworks is a private data network (PDN). Prior to version 9.3.0, a reflected XSS vulnerability in Kiteworks Secure Data Forms could allow an external attacker to trick a user into executing arbitrary JavaScript code. Upgrade Kiteworks to version 9.3.0 or later to receive a patch. CVSSv3.1 8.2 (HIGH)
CVE-2026-24088 — Cryptographic: Issue while processing a specific partition which allows unauthorized write access to load
Cryptographic Issue while processing a specific partition which allows unauthorized write access to load a customized bootloader. CVSSv3.1 8.2 (HIGH)
CVE-2019-25718 — Infinity: Dräger Infinity Explorer C700 contains a privilege escalation vulnerability that allows attackers to break
Dräger Infinity Explorer C700 contains a privilege escalation vulnerability that allows attackers to break out of kiosk mode and access the underlying operating system through a specific dialog interaction. Attackers can exploit this kiosk escape to take control of the operating system and cause the device to display incorrect or no information from the connected Delta Family patient monitor. CVSSv3.1 8.4 (HIGH)