2026-08-05
2026-08-05 17:16Z
HIGH

CVE-2026-20270 — The vulnerabilities tracked by CVE-2026-20270 are related to incorrect calculation issues that are grouped

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-20270

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XE Software engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered vulnerabilities. The vulnerabilities tracked by CVE-2026-20270 are related to incorrect calculation issues that are grouped under the Common Weakness Enumeration (CWE) Pillar CWE-682. CVSSv3.1 8.6 (HIGH)

CWECWE 682TYPVulnerability
8.6
CVSS v3.1
93
Edit Score
2026-08-05
2026-08-05 17:16Z
HIGH

CVE-2026-20269 — As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-20269

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XE Software engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered vulnerabilities. The vulnerabilities tracked by CVE-2026-20269 are related to issues with improper control of a resource through its lifetime that are grouped under the Common Weakness Enumeration (CWE CVSSv3.1 8.6 (HIGH)

CWECWE 664TYPVulnerability
8.6
CVSS v3.1
93
Edit Score
2026-08-05
2026-08-05 17:16Z
HIGH

CVE-2026-20268 — As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-20268

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XE Software engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered vulnerabilities. The vulnerabilities tracked by CVE-2026-20268 are related to issues with improper restriction of operations within the bounds of a memory buffer that are grouped under the Common Weakn CVSSv3.1 8.6 (HIGH)

CWECWE 119TYPVulnerability
8.6
CVSS v3.1
93
Edit Score
2026-08-05
2026-08-05 17:16Z
CRIT

CVE-2026-20267 — As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-20267

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XE Software engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered vulnerabilities. The vulnerabilities tracked by CVE-2026-20267 are related to improper access control issues that are grouped under the Common Weakness Enumeration (CWE) Pillar CWE-284. CVSSv3.1 9.0 (CRITICAL)

CWECWE 284TYPVulnerability
9.0
CVSS v3.1
95
Edit Score
2026-08-05
2026-08-05 17:16Z
HIGH

CVE-2026-20263 — Blocks: A vulnerability in the Blocks Extensible Exchange Protocol (BEEP) feature of Cisco IOS XE

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-20263

A vulnerability in the Blocks Extensible Exchange Protocol (BEEP) feature of Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to improper handling when parsing a specific BEEP SOAP request. An attacker could exploit this vulnerability by sending a specific BEEP SOAP request to an affected device. A successful exploit could allow the attacker to cause the devic CVSSv3.1 8.6 (HIGH)

CWECWE 388VNDBlocksTYPVulnerability
8.6
CVSS v3.1
93
Edit Score
2026-08-05
2026-08-05 17:16Z
HIGH

CVE-2026-20200 — A vulnerability in the web-based management interface of Cisco IMC could allow an authenticated

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-20200

A vulnerability in the web-based management interface of Cisco IMC could allow an authenticated, remote attacker with low privileges to execute arbitrary commands on the underlying operating system of an affected system and elevate privileges to root.  This vulnerability is due to improper validation of user-supplied input. An attacker could exploit this vulnerability by entering crafted inputs to the web-based management interface of the affected software. A successf CVSSv3.1 8.8 (HIGH)

CWECWE 141TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-08-05
2026-08-05 17:16Z
HIGH

CVE-2026-17626 — IBM: Langflow OSS 1.0.0 through 1.10.3 Langflow could allow an authenticated attacker to read

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-17626

IBM Langflow OSS 1.0.0 through 1.10.3 Langflow could allow an authenticated attacker to read, modify, or expose sensitive host files via Docker-based MCP servers due to incomplete filtering of dangerous Docker volume-mount and device-mapping arguments. CVSSv3.1 8.8 (HIGH)

CWECWE 266VNDIbmTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
728 × 90 / responsive · programmatic ad slot
2026-08-05
2026-08-05 17:16Z
HIGH

CVE-2026-17623 — IBM: Langflow OSS 1.0.0 through 1.10.3 could allow a remote authenticated attacker to execute

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-17623

IBM Langflow OSS 1.0.0 through 1.10.3 could allow a remote authenticated attacker to execute arbitrary commands due to improper validation of the command field in MCP server configurations. CVSSv3.1 8.8 (HIGH)

CWECWE 78VNDIbmTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-08-05
2026-08-05 17:16Z
HIGH

CVE-2026-17617 — IBM: Application Gateway Operator 22.2 through 26.06 is vulnerable to Server-Side Request Forgery (SSRF)

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-17617

IBM Application Gateway Operator 22.2 through 26.06 is vulnerable to Server-Side Request Forgery (SSRF) due to insufficient validation of URLs specified in custom resources. CVSSv3.1 8.5 (HIGH)

CWECWE 918VNDIbmTYPVulnerability
8.5
CVSS v3.1
93
Edit Score
2026-08-05
2026-08-05 17:15Z
CRIT

Turning Enterprise Update Servers Into Backdoor Factories (0_o) – Part 1

SpecterOps·specterops.io

SpecterOps researcher David Beyviel demonstrates a novel attack chain against Windows Server Update Services (WSUS) that leverages NTLM coercion and relay to compromise the WSUS database, then uses SQL stored procedures to inject malicious updates targeting specific computers. Part 1 details the reconnaissance, authentication relay to the MSSQL backend, and the mechanics of crafting custom updates via spImportUpdate and spSaveXMLFragment stored procedures.

SRFNetworkTACTA0008SWWsusVNDMicrosoftTYPResearchSTGInitial AccessSTGLat MovementTECT1570
92
Edit Score
2026-08-05
2026-08-05 17:15Z
CRIT

Turning Enterprise Update Servers Into Backdoor Factories (0_o) – Part 2

SpecterOps·specterops.io

SpecterOps researcher Beyviel David demonstrates a complete attack chain for weaponizing Windows Server Update Services (WSUS) to deploy arbitrary malicious payloads. The attack exploits a signature verification bypass in Microsoft.UpdateServices.ContentSyncAgent.dll by appending .txt or .esd file extensions, allowing unsigned executables to bypass digital signature checks. The technique achieves code execution and persistence across enterprise networks when combined with automatic update group policies, with accompanying tools (NotWSUSpicious, ludus_wsus) released for automation.

SRFOsTACTA0005TACTA0001SRFNetworkTACTA0003OSWindowsSWWsusSWBits
92
Edit Score
2026-08-05
2026-08-05 17:15Z
HIGH

Of Course We Built a WSUS Ludus Lab

SpecterOps·specterops.io

SpecterOps released a Ludus lab automation collection for deploying Windows Server Update Services (WSUS) infrastructure in virtual environments. The lab supports testing WSUS takeover and custom payload deployment for lateral movement, with Ansible roles for WSUS server, SQL backend, GPO configuration, and client management. This is part of a broader research series on weaponizing enterprise update servers.

SRFApplicationTACTA0008OSWindowsSWLudusSWWsusTYPToolSTGExecutionSTGLat Movement
72
Edit Score
2026-08-05
2026-08-05 17:15Z
CRIT

Weaponizing Windows Updates with NotWSUSpicious

SpecterOps·specterops.io

SpecterOps released NotWSUSpicious, a toolset for weaponizing Windows Server Update Services (WSUS) after gaining database access. The tool automates SQL query generation to inject malicious updates into WSUS, enabling arbitrary code execution on managed endpoints via the legitimate update mechanism. This follows a multi-part research series on WSUS database takeover via NTLM relay attacks against external MSSQL servers.

TACTA0001TACTA0002SRFNetworkSWWsusVNDMicrosoftTYPToolSTGExecutionSTGInitial Access
82
Edit Score
2026-08-05
2026-08-05 16:17Z
HIGH

CVE-2026-9203 — A server-side request forgery vulnerability in Progress MarkLogic Server before 11.3.6 and 12.0.3 allows

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-9203

A server-side request forgery vulnerability in Progress MarkLogic Server before 11.3.6 and 12.0.3 allows an authenticated user with low-privileged roles to bypass protections for cloud instance metadata endpoints. Successful exploitation can disclose cloud credentials and compromise cloud resources accessible to the host instance. CVSSv3.1 8.5 (HIGH)

CWECWE 918TYPVulnerability
8.5
CVSS v3.1
93
Edit Score
2026-08-05
2026-08-05 16:17Z
CRIT

CVE-2026-9195 — A cross-site scripting vulnerability in the Query Console of Progress MarkLogic Server before 11.3.6

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-9195

A cross-site scripting vulnerability in the Query Console of Progress MarkLogic Server before 11.3.6 and 12.0.3 allows a remote attacker who lures an authenticated administrator to a crafted URL to execute arbitrary JavaScript in the administrator's browser session, capture credentials, and perform privileged actions on the administrator's behalf. CVSSv3.1 9.3 (CRITICAL)

CWECWE 22CWECWE 79TYPVulnerability
9.3
CVSS v3.1
97
Edit Score
2026-08-05
2026-08-05 16:17Z
CRIT

CVE-2026-9193 — An improper privilege management vulnerability in the Hadoop integration of Progress MarkLogic Server before

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-9193

An improper privilege management vulnerability in the Hadoop integration of Progress MarkLogic Server before 11.3.6 and 12.0.3 allows an authenticated user with a low-privileged Hadoop role to escalate privileges and execute privileged operations against the Security database. CVSSv3.1 9.9 (CRITICAL)

CWECWE 269TYPVulnerability
9.9
CVSS v3.1
100
Edit Score
2026-08-05
2026-08-05 16:17Z
CRIT

CVE-2026-9192 — An authentication bypass vulnerability in the ODBC App Server of Progress MarkLogic Server before

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-9192

An authentication bypass vulnerability in the ODBC App Server of Progress MarkLogic Server before 11.3.6 and 12.0.3 allows an unauthenticated remote attacker to bypass password verification and execute queries with the privileges of any named user known to the server, including administrators. CVSSv3.1 9.8 (CRITICAL)

CWECWE 287TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-08-05
2026-08-05 16:17Z
CRIT

CVE-2026-9190 — HTTP: An HTTP request smuggling vulnerability in the HTTP App Server of Progress MarkLogic Server

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-9190

An HTTP request smuggling vulnerability in the HTTP App Server of Progress MarkLogic Server before 11.3.6 and 12.0.3 allows a remote attacker to bypass authentication and authorization checks, hijack a legitimate user's session, or capture credentials. The vulnerability occurs when a crafted HTTP request containing both Content-Length and Transfer-Encoding headers causes a reverse proxy and MarkLogic Server to interpret request boundaries differently. CVSSv3.1 9.1 (CRITICAL)

CWECWE 444VNDHttpTYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2026-08-05
2026-08-05 16:17Z
CRIT

CVE-2026-8709 — An improper privilege management vulnerability in the REST API document patch operation of Progress

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-8709

An improper privilege management vulnerability in the REST API document patch operation of Progress MarkLogic Server before 11.3.6 and 12.0.3 allows an authenticated user with a low-privileged REST role to escalate privileges and execute privileged operations against the Security database. CVSSv3.1 9.9 (CRITICAL)

CWECWE 269TYPVulnerability
9.9
CVSS v3.1
100
Edit Score
2026-08-05
2026-08-05 16:17Z
HIGH

CVE-2026-8400 — IBM: WebSphere Application Server 8.5, and 9.0 and IBM WebSphere Application Server - Liberty

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-8400

IBM WebSphere Application Server 8.5, and 9.0 and IBM WebSphere Application Server - Liberty Continuous delivery has a flaw in the ORB component in IBM SDK, Java Technology Edition, may allow a malicious IIOP server to induce loading and instantation of arbitrary classes. CVSSv3.1 8.1 (HIGH)

CWECWE 470VNDIbmTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-08-05
2026-08-05 16:17Z
CRIT

CVE-2026-7557 — An improper verification of cryptographic signature vulnerability in the SAML authentication module of Progress

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-7557

An improper verification of cryptographic signature vulnerability in the SAML authentication module of Progress MarkLogic Server before 11.3.6 and 12.0.3 allows an unauthenticated remote attacker to bypass authentication and impersonate any user, including administrators. This vulnerability affects deployments with SAML single sign-on enabled. CVSSv3.1 9.1 (CRITICAL)

CWECWE 347TYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2026-08-05
2026-08-05 16:17Z
CRIT

CVE-2026-7329 — An improper privilege management vulnerability in the SQL, SPARQL, and Optic REST query interfaces

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-7329

An improper privilege management vulnerability in the SQL, SPARQL, and Optic REST query interfaces of Progress MarkLogic Server before 11.3.6 and 12.0.3 allows an authenticated user with a low-privileged REST role to escalate privileges to administrator. This enables execution of privileged operations and unauthorized data access. CVSSv3.1 9.9 (CRITICAL)

CWECWE 269TYPVulnerability
9.9
CVSS v3.1
100
Edit Score
2026-08-05
2026-08-05 16:17Z
HIGH

CVE-2026-7327 — An improper privilege management vulnerability in the REST API document processing pipeline of Progress

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-7327

An improper privilege management vulnerability in the REST API document processing pipeline of Progress MarkLogic Server before 11.3.6 and 12.0.3 allows an authenticated user with an administrative REST role to escalate privileges. This can result in unauthorized disclosure of sensitive server-side data when it is accessed by a higher-privileged user. CVSSv3.1 8.1 (HIGH)

CWECWE 269TYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-08-05
2026-08-05 16:16Z
CRIT

CVE-2026-60053 — Session: Insufficient Session Expiration vulnerability in Apache Answer.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-60053

Insufficient Session Expiration vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.1. Administrative API keys remained usable after the owning administrator was demoted or the account was marked inactive, suspended, or deleted, allowing continued access until the keys were explicitly removed. Users are recommended to upgrade to version 2.0.2, which fixes the issue. CVSSv3.1 9.1 (CRITICAL)

CWECWE 613TYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2026-08-05
2026-08-05 16:16Z
HIGH

CVE-2026-39923 — Flarum: before 1.8.16 contains a password reset token expiry bypass vulnerability that allows unauthenticated

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-39923

Flarum before 1.8.16 contains a password reset token expiry bypass vulnerability that allows unauthenticated attackers to reuse expired password reset tokens by submitting them directly to the reset processing endpoint. The SavePasswordController::handle() method calls PasswordToken::findOrFail() without performing any expiry validation, allowing attackers to bypass the 24-hour token lifetime enforced only during form rendering and change any account's password to gain an aut CVSSv3.1 8.1 (HIGH)

CWECWE 324VNDFlarumTYPVulnerability
8.1
CVSS v3.1
91
Edit Score