Modification of assumed-immutable data (maid) in Azure Active Directory allows an authorized attacker to elevate privileges over a network.
CVSSv3.1 9.9 (CRITICAL)
CWECWE 471VNDModificationTYPVulnerability
9.9
CVSS v3.1
100
Edit Score
2026-08-07
2026-08-07 00:16Z
HIGH
CVE-2026-49163 — Improper limitation of a pathname to a restricted directory ('path traversal') in Application Insights
Improper limitation of a pathname to a restricted directory ('path traversal') in Application Insights Profiler allows an authorized attacker to elevate privileges over a network.
CVSSv3.1 8.8 (HIGH)
CWECWE 22TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-08-07
2026-08-07 00:00Z
MED
The security signal log tailing can't see: tracking npm cooldown removals with Elastic Agent
Elastic Security Labs·elastic.co
Elastic Security Labs published a technical deep-dive on detecting npm cooldown (min-release-age) removals from developer workstations using Elastic Agent's CEL integration. The post documents a ~40-line CEL snapshot-based approach that polls .npmrc files every 6 hours to detect when the min-release-age setting is deleted, contrasting it with failed filestream-based attempts and explaining the architectural trade-offs between state monitoring and log tailing.
The security signal log tailing can't see: tracking npm cooldown removals with Elastic Agent
Elastic Security Labs·elastic.co
Elastic Security Labs published a technical deep-dive on detecting npm cooldown (min-release-age) removals from developer workstations using Elastic Agent's CEL input with 6-hour snapshot semantics. The post documents three iterations of monitoring approaches (filestream, CEL emit-on-change, CEL heartbeat), explains why filestream fails for config-file state monitoring, and provides production-ready CEL integration code with agent-side token filtering and ingest pipelines for macOS, Linux, and Windows.
Living off the coding agent: Two tales of tunnels and LaunchAgents
Elastic Security Labs·elastic.co
Elastic Security Labs documents a multi-stage attack chain on a macOS developer endpoint where Claude Code and Cursor coding agents were abused to establish reverse tunnels (localhost.run, Cloudflare Quick Tunnels, ngrok), exfiltrate credentials over HTTP, and install LaunchAgent persistence mechanisms. The activity spanned July 20–23, 2026, and demonstrates how trusted, vendor-signed AI coding agents can be weaponized to bypass traditional endpoint controls while maintaining plausible deniability as legitimate developer tooling.
CVE-2026-71327 — Traefik Traefik: From 3.0.0 until 3.6.25 and 3.7.10, Traefik's Kubernetes Gateway API provider in pkg/provider/kubernetes/gateway/httproute.go, grpcroute.go
Traefik is an open source HTTP reverse proxy and load balancer. From 3.0.0 until 3.6.25 and 3.7.10, Traefik's Kubernetes Gateway API provider in pkg/provider/kubernetes/gateway/httproute.go, grpcroute.go, tcproute.go, and tlsroute.go builds HTTPRoute, GRPCRoute, TCPRoute, and TLSRoute router and service identities by hyphen-concatenating namespace, route name, Gateway identity, entry point, and rule index, allowing colliding Routes to overwrite another namespace's backend. Th
CVSSv3.1 8.1 (HIGH) · EPSS 30th percentile
CWECWE 694VNDTraefikTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
728 × 90 / responsive · programmatic ad slot
2026-08-06
2026-08-06 22:18Z
CRIT
CVE-2026-71324 — Traefik Traefik: Prior to 2.11.53, 3.6.24, and 3.7.9, Traefik's default HTTP reverse proxy forwards a plain
Traefik is an open source HTTP reverse proxy and load balancer. Prior to 2.11.53, 3.6.24, and 3.7.9, Traefik's default HTTP reverse proxy forwards a plain HTTP/2 or HTTP/3 CONNECT request and its body to an HTTP/1.1 upstream through a shared net/http.Transport. When the upstream answers the CONNECT with a keep-alive non-2xx response and does not drain the body, Traefik returns the desynchronized backend socket to its shared pool and reuses it for other clients. An unauthentic
CVSSv3.1 9.1 (CRITICAL) · EPSS 44th percentile
CWECWE 444VNDTraefikTYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2026-08-06
2026-08-06 22:18Z
HIGH
CVE-2026-70634 — TimescaleDB: through 2.29.1, fixed in commit 517c13e, contains an out-of-bounds read in the Dictionary
TimescaleDB through 2.29.1, fixed in commit 517c13e, contains an out-of-bounds read in the Dictionary compression reverse row iterator (tsl/src/compression/algorithms/dictionary.c). The forward path validates the decoded index; the reverse path uses an assertion compiled out of release builds, leaving the 64-bit Simple8b index unvalidated and the read offset attacker-controlled. Attackers with DML access to a physical compressed relation can store a crafted datum and run a re
CVSSv3.1 8.1 (HIGH)
Dinky's POST /download/uploadFromRsByLocal handler passes the caller-supplied path parameter directly to new File(path) and file.transferTo(dest) with no path validation. The route is marked @SaIgnore and /download/** is excluded from the Sa-Token interceptor, so the only guard is a header equality check against a dinkyToken value whose default (efda1551-7958-4e0f-80a8-dfd107df3e38) is hardcoded in source and shipped to every deployment. Anyone who can reach Dinky's HTTP port
CVSSv3.1 9.8 (CRITICAL)
CWECWE 434VNDPostTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-08-06
2026-08-06 22:18Z
CRIT
CVE-2026-67689 — SQL: Injection vulnerability in FineAdmin V1.0 allows a remote attacker to execute arbitrary code
SQL Injection vulnerability in FineAdmin V1.0 allows a remote attacker to execute arbitrary code via the `field` and `order` parameters in paginated list endpoints
CVSSv3.1 9.8 (CRITICAL)
CWECWE 89TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-08-06
2026-08-06 22:18Z
CRIT
CVE-2026-67688 — ICS: This allows a remote attacker to execute arbitrary code.
ICS-Park Smart Park Management System v2.0 contains an unrestricted file upload vulnerability in the file upload module. This allows a remote attacker to execute arbitrary code.
CVSSv3.1 9.8 (CRITICAL)
CWECWE 434VNDIcsTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-08-06
2026-08-06 22:18Z
HIGH
CVE-2026-67687 — Permissions: Insecure Permissions vulnerability in ics-park v.2.0 allows a remote attacker to escalate privileges via
Insecure Permissions vulnerability in ics-park v.2.0 allows a remote attacker to escalate privileges via the /system/role/save endpoint in RoleController.java and system/user/update endpoint in UserController.java
CVSSv3.1 8.8 (HIGH)
CWECWE 284TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-08-06
2026-08-06 22:18Z
CRIT
CVE-2026-67622 — Flowise: through 3.1.4 contains an insecure direct object reference vulnerability in the OpenAI Assistants
Flowise through 3.1.4 contains an insecure direct object reference vulnerability in the OpenAI Assistants integration that allows authenticated attackers to access credentials belonging to other workspaces by supplying an arbitrary credential UUID to Assistants endpoints without workspace ownership verification. Attackers can enumerate cross-workspace assistant metadata, retrieve file and vector store listings, and upload files into victim workspaces by exploiting the missing
CVSSv3.1 9.9 (CRITICAL)
CWECWE 639VNDFlowiseTYPVulnerability
9.9
CVSS v3.1
100
Edit Score
2026-08-06
2026-08-06 22:18Z
CRIT
CVE-2026-65400 — Apple Macos: An authentication issue was addressed with improved state management.
An authentication issue was addressed with improved state management. This issue is fixed in macOS Sequoia 15.7.9, macOS Sonoma 14.8.9, macOS Tahoe 26.6.1. An attacker on the network may be able to authenticate to Screen Sharing without valid credentials.
CVSSv3.1 9.8 (CRITICAL) · EPSS 40th percentile
CWECWE 287VNDAppleTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-08-06
2026-08-06 22:18Z
HIGH
CVE-2026-64665 — Statamic: Prior to 5.74.1 and 6.24.0, when OAuth login was enabled with a provider that
Statamic is a Laravel and Git powered content management system (CMS). Prior to 5.74.1 and 6.24.0, when OAuth login was enabled with a provider that does not guarantee verified email addresses, an unauthenticated attacker could sign in as an existing user, potentially including a super admin, without knowing that user's password, because the application matched OAuth identities to accounts by email address alone. Exploitation requires OAuth to be explicitly enabled with such
CVSSv3.1 8.1 (HIGH)
CWECWE 287CWECWE 290VNDStatamicTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-08-06
2026-08-06 22:18Z
HIGH
CVE-2026-63637 — Dgraph: Prior to 25.3.8, maybeQuoteArg in graphql/resolve/query_rewriter.go passes regexp filter strings into generated DQL without
Dgraph is an open source distributed GraphQL database. Prior to 25.3.8, maybeQuoteArg in graphql/resolve/query_rewriter.go passes regexp filter strings into generated DQL without quoting or validating the /pattern/flags form, allowing crafted GraphQL query or mutation filters to inject DQL operators, disclose unintended nodes, or expand modification and deletion targets. This issue is fixed in version 25.3.8.
CVSSv3.1 8.6 (HIGH)
CWECWE 943VNDDgraphTYPVulnerability
8.6
CVSS v3.1
93
Edit Score
2026-08-06
2026-08-06 22:18Z
HIGH
CVE-2026-5857 — Contiki: Impact ranges from information disclosure and denial of service to remote code execution on
Contiki-NG's MQTT client parse_publish_vhdr() in os/net/app-layer/mqtt/mqtt.c sets topic_len_received=1 before checking topic_len against the 64-byte limit, so an over-length topic returns early but leaves the flag set. On the next TCP segment, tcp_input() re-invokes the parser with topic_received==0, and the persisted topic_len_received==1 skips the length-reading block containing the guard, falling through directly to a memcpy() that uses the unvalidated 16-bit topic_len as
CVSSv3.1 8.1 (HIGH)
CWECWE 787VNDContikiTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-08-06
2026-08-06 22:17Z
CRIT
CVE-2026-53984 — Ground: Station prior to 0.6.0 contains an unauthenticated database-destruction and arbitrary-data-injection vulnerability in the
Ground Station prior to 0.6.0 contains an unauthenticated database-destruction and arbitrary-data-injection vulnerability in the Socket.IO server's database_backup event handler that allows any unauthenticated network peer to wipe or replace the entire SQLite database by sending a single full_restore command with a caller-supplied SQL blob. Attackers can connect to the Socket.IO server on port 7000 without credentials due to disabled authentication enforcement and a wildcard
CVSSv3.1 9.1 (CRITICAL)
CWECWE 306VNDGroundTYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2026-08-06
2026-08-06 22:17Z
HIGH
CVE-2026-53983 — Ground: Station prior to 0.6.0 contains an unauthenticated blind server-side request forgery vulnerability in
Ground Station prior to 0.6.0 contains an unauthenticated blind server-side request forgery vulnerability in the orbital-source configuration path that allows any unauthenticated Socket.IO client to cause the ground-station process to issue outbound HTTP requests to attacker-chosen destinations. Attackers can connect to the Socket.IO server on port 7000 without credentials due to disabled authentication enforcement and a wildcard CORS policy, then submit a data_submission eve
CVSSv3.1 8.6 (HIGH)
CWECWE 918VNDGroundTYPVulnerability
8.6
CVSS v3.1
93
Edit Score
2026-08-06
2026-08-06 22:17Z
CRIT
CVE-2026-48088 — The handler logs an "Unauthorized crypto key storage attempt" warning when neither a session
OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. Prior to version 1.0.4, the route `POST /api/tenants/{tenantId}/staff/{staffId}/crypto` accepts and stores attacker-controlled ML-KEM-768 public keys against any tenant on the platform without authentication. The handler logs an "Unauthorized crypto key storage attempt" warning when neither a session nor a registration cookie is present, then proceeds to insert the row
CVSSv3.1 9.4 (CRITICAL)
CWECWE 862TYPVulnerability
9.4
CVSS v3.1
97
Edit Score
2026-08-06
2026-08-06 22:17Z
CRIT
CVE-2026-48087 — Staff-list endpoints return user IDs to authenticated tenant members per the route signature; live
OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. Prior to version 1.0.2, the registration handler at `POST /api/auth/register/{userId}` validates the relationship between the WebAuthn challenge and the registration cookie's email but never validates that the `userId` in the URL belongs to that email. An unauthenticated attacker requests a challenge for their own email, generates a registration response with their own
CVSSv3.1 9.8 (CRITICAL)
CWECWE 287TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-08-06
2026-08-06 22:17Z
CRIT
CVE-2026-48086 — On a single-tenant self-hosted deployment it is still a privilege escalation because TENANT_ADMIN should
OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. Prior to version 1.0.2, a TENANT_ADMIN promotes themselves to platform-wide GLOBAL_ADMIN through a single PUT request. The role-update handler accepts the `GLOBAL_ADMIN` enum value from any tenant admin updating their own tenant's staff. No policy check enforces that "only an existing GLOBAL_ADMIN may grant GLOBAL_ADMIN", so the schema validation IS the authorization de
CVSSv3.1 9.9 (CRITICAL)
CWECWE 269TYPVulnerability
9.9
CVSS v3.1
100
Edit Score
2026-08-06
2026-08-06 22:17Z
CRIT
CVE-2026-48085 — This is distinct from the deployment race condition already documented on the `Claiming an
OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. Prior to version 1.0.1, a fully provisioned OpenReception instance accepts unauthenticated POST requests to `/setup/create-admin-account` and creates additional GLOBAL_ADMIN accounts without verifying that an admin already exists. Any unauthenticated network attacker who can submit a same-origin form POST gains full platform-level administrative control. The newly creat
CVSSv3.1 9.8 (CRITICAL)
OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. Prior to version 1.0.2, a TENANT_ADMIN can store `javascript:` URLs in the tenant `links` configuration (`website`, `imprint`, `privacyStatement`). These values are returned to the patient-facing landing page via `/api/public`, hydrated into the SvelteKit Button component, and rendered as `<a href="javascript:...">` elements without URL-scheme filtering. A patient who c
CVSSv3.1 8.1 (HIGH)