2026-08-05
2026-08-05 04:17Z
HIGH

CVE-2026-18898 — The manipulation of the argument timestart results in stack-based buffer overflow.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-18898

A security flaw has been discovered in UTT HiPER 1200GW up to v2.5.3-170306. This affects the function strcpy of the file /goform/ConfigAdvideo. The manipulation of the argument timestart results in stack-based buffer overflow. The attack can be launched remotely. The exploit has been released to the public and may be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way. CVSSv3.1 8.8 (HIGH)

CWECWE 121CWECWE 119TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-08-05
2026-08-05 02:16Z
HIGH

CVE-2026-18897 — UTT: The manipulation of the argument tempName leads to stack-based buffer overflow.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-18897

A vulnerability was identified in UTT HiPER 1250GW up to v3.2.7-210907-180535. The impacted element is the function strcpy of the file /goform/getOneApConfTempEntry. The manipulation of the argument tempName leads to stack-based buffer overflow. The attack can be initiated remotely. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way. CVSSv3.1 8.8 (HIGH)

CWECWE 121CWECWE 119VNDUttTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-08-05
2026-08-05 02:16Z
HIGH

CVE-2026-18895 — UTT: Performing a manipulation of the argument cipher results in stack-based buffer overflow.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-18895

A vulnerability was found in UTT HiPER 1250GW up to 3.2.7-210907-180535. Impacted is the function strcpy of the file /goform/APSecurity_5g. Performing a manipulation of the argument cipher results in stack-based buffer overflow. It is possible to initiate the attack remotely. The exploit has been made public and could be used. The vendor was contacted early about this disclosure but did not respond in any way. CVSSv3.1 8.8 (HIGH)

CWECWE 121CWECWE 119VNDUttTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-08-04
2026-08-04 23:16Z
CRIT

CVE-2026-45537 — OpenSIPS: In versions prior to 3.6.6 and 4.0.0-rc1, the construct_uri() function concatenates multiple URI components

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-45537

OpenSIPS is a Session Initiation Protocol (SIP) server implementation. In versions prior to 3.6.6 and 4.0.0-rc1, the construct_uri() function concatenates multiple URI components (protocol, username, domain, port, params) into a fixed 1024-byte global BSS buffer without any bounds checking. When a routing script calls construct_uri() with an attacker-controlled username, a combined component length exceeding 1024 bytes overflows the buffer, corrupting adjacent global data wit CVSSv3.1 9.1 (CRITICAL)

CWECWE 120VNDOpensipsTYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2026-08-04
2026-08-04 22:17Z
HIGH

CVE-2026-70619 — Odysseus: before commit bf325f6 contains a missing authorization vulnerability that allows authenticated non-admin users

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-70619

Odysseus before commit bf325f6 contains a missing authorization vulnerability that allows authenticated non-admin users to manage server-wide embedding backend configuration by invoking endpoint management routes that verify session authentication but omit the admin authorization guard. Attackers can supply an attacker-controlled URL to overwrite the embedding backend persisted in the endpoint configuration file and process environment, causing all subsequent embedding operat CVSSv3.1 8.8 (HIGH)

CWECWE 862VNDOdysseusTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-08-04
2026-08-04 22:17Z
CRIT

CVE-2026-45100 — OpenSIPS: Versions 3.4.0-beta through 3.6.5 and 4.0.0-beta contain a buffer overflow in the {s.b64encode} string

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-45100

OpenSIPS is a Session Initiation Protocol (SIP) server implementation. Versions 3.4.0-beta through 3.6.5 and 4.0.0-beta contain a buffer overflow in the {s.b64encode} string transformation. The size check for {s.b64encode} only verifies that the input fits within the 64 KB transformation buffer, but base64 encoding expands the data by roughly a third, so an input between about 49,153 and 65,535 bytes produces more output than the buffer can hold and overflows it by up to 21,8 CVSSv3.1 9.1 (CRITICAL)

CWECWE 120VNDOpensipsTYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2026-08-04
2026-08-04 21:59Z
INFO

Benchmarking the Agentic SOC: How we evaluate LLMs for security workflows

Elastic Security Labs·elastic.co

Elastic Security Labs published a benchmarking framework for evaluating LLMs in SOC workflows, moving beyond generic leaderboards to grade models on actual tool execution, parameter correctness, and grounded decision-making. The framework tests seven security capabilities (alert analysis, entity analytics, threat hunting, detection rules, workflow authoring, triggering workflows, multi-step response) using a synthetic Chrysalis backdoor intrusion scenario, capturing full execution traces and blind-judging results to identify failure modes like fabricated verdicts and unexecuted tool calls.

SRFApplicationTACTA0007SRFAiSWElastic SecurityVNDElasticTYPResearch
72
Edit Score
728 × 90 / responsive · programmatic ad slot
2026-08-04
2026-08-04 21:16Z
CRIT

CVE-2026-70554 — MaxSite: CMS contains a PHP object injection vulnerability that allows unauthenticated attackers to execute

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-70554

MaxSite CMS contains a PHP object injection vulnerability that allows unauthenticated attackers to execute arbitrary code by passing attacker-controlled serialized data in the maxsite_comuser cookie directly to unserialize() without validation or class allowlisting. Attackers can craft a malicious serialized PHP object payload delivered in a single HTTP request to trigger magic methods during object graph reconstruction, enabling property-oriented programming attacks or remot CVSSv3.1 9.8 (CRITICAL)

CWECWE 502VNDMaxsiteTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-08-04
2026-08-04 21:16Z
HIGH

CVE-2026-70494 — Open: From 0.10.0 until 0.11.0, the DELETE /api/v1/folders/{id} handler in backend/open_webui/routers/folders.py allowed a user granted

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-70494

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.10.0 until 0.11.0, the DELETE /api/v1/folders/{id} handler in backend/open_webui/routers/folders.py allowed a user granted write access to a shared chat folder to permanently delete chats and messages belonging to the folder owner. The cascade following the authorization check is bound to the folder owner's id, but the subfolder check accepted any inherited write grant instead of requ CVSSv3.1 8.1 (HIGH)

CWECWE 862CWECWE 863TYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-08-04
2026-08-04 21:16Z
HIGH

CVE-2026-70492 — Open: From 0.10.0 until 0.11.0, src/lib/components/chat/Messages/Markdown/KatexRenderer.svelte could store and render a chat message whose math

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-70492

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.10.0 until 0.11.0, src/lib/components/chat/Messages/Markdown/KatexRenderer.svelte could store and render a chat message whose math block makes KaTeX fail with a stack overflow instead of a parse error. The catch branch fell back to inserting the original math source into the page as HTML through {@html} rather than as text, so script in the message runs in the browser of whoever views CVSSv3.1 8.7 (HIGH)

CWECWE 79TYPVulnerability
8.7
CVSS v3.1
94
Edit Score
2026-08-04
2026-08-04 21:16Z
CRIT

CVE-2026-67979 — Incorrect: access control in the Executive Services dynamic application start path component of NASA

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-67979

Incorrect access control in the Executive Services dynamic application start path component of NASA cFS v7.0.1 allows attackers to execute arbitrary code via placing a shared object on target storage. CVSSv3.1 9.1 (CRITICAL)

CWECWE 284TYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2026-08-04
2026-08-04 21:16Z
CRIT

CVE-2026-66902 — Google: Google::Auth versions before 0.06 for Perl run a command named in an external_account credentials

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-66902

Google::Auth versions before 0.06 for Perl run a command named in an external_account credentials JSON via an ungated system call. The Pluggable subclass reads credential_source.executable.command from the credentials JSON and runs it as `system($command)`, a single argument call that passes the whole string to /bin/sh -c. The executable's environment_variables map from the same JSON is copied into %ENV first. No opt-in gate guards the call. make_creds selects the Pluggable CVSSv3.1 9.8 (CRITICAL)

CWECWE 829CWECWE 78VNDGoogleTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-08-04
2026-08-04 21:16Z
HIGH

CVE-2026-51400 — Vim: An issue in Vim Project v9.2.0389 and earlier allows a local attacker to execute

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-51400

An issue in Vim Project v9.2.0389 and earlier allows a local attacker to execute arbitrary code via the vms_fixfilename() function within file vim/src/os_vms.c CVSSv3.1 8.4 (HIGH)

CWECWE 401VNDVimTYPVulnerability
8.4
CVSS v3.1
92
Edit Score
2026-08-04
2026-08-04 21:16Z
CRIT

CVE-2026-45538 — OpenSIPS: In versions 4.0.0 and prior, processing a SIP message with a header name longer

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-45538

OpenSIPS is a Session Initiation Protocol (SIP) server implementation. In versions 4.0.0 and prior, processing a SIP message with a header name longer than 255 bytes causes a stack buffer overflow when sip_to_json() is called in the routing script. Function sip_to_json() (modules/sipmsgops/sipmsgops.c) copies SIP header names into a fixed 255-byte stack buffer without bounds checking, performing a memcpy of the full header-name length even though the SIP parser imposes no suc CVSSv3.1 9.8 (CRITICAL)

CWECWE 121VNDOpensipsTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-08-04
2026-08-04 20:16Z
CRIT

CVE-2026-70553 — MaxSite: CMS contains a remote code execution vulnerability that allows unauthenticated attackers to inject

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-70553

MaxSite CMS contains a remote code execution vulnerability that allows unauthenticated attackers to inject arbitrary PHP code into the application configuration file by submitting crafted POST requests to the install endpoint after installation is complete. Attackers can supply a malicious db_dbprefix value containing a single quote to break out of a PHP string literal in application/config/database.php, appending attacker-controlled PHP statements that are executed by the we CVSSv3.1 9.8 (CRITICAL)

CWECWE 94VNDMaxsiteTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-08-04
2026-08-04 20:16Z
CRIT

CVE-2026-70552 — MaxSite: CMS 109.5 and earlier contains an authentication bypass vulnerability in the AJAX dispatcher

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-70552

MaxSite CMS 109.5 and earlier contains an authentication bypass vulnerability in the AJAX dispatcher that allows unauthenticated attackers to access admin-gated endpoints by supplying any X-Requested-With header and requesting a base64-encoded path resolving to any *-ajax.php file in the codebase. Attackers can exploit this dispatcher bypass to reach privileged plugin endpoints without credentials, enabling actions such as manipulating poll states and vote counts, and amplify CVSSv3.1 9.8 (CRITICAL)

CWECWE 306VNDMaxsiteTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-08-04
2026-08-04 20:16Z
HIGH

CVE-2026-70486 — Open: From 0.9.0 until 0.11.0, the terminal file-preview serveUrl iframe branch always granted allow-same-origin together

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-70486

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.9.0 until 0.11.0, the terminal file-preview serveUrl iframe branch always granted allow-same-origin together with allow-scripts for HTML files served from the application origin. Any authenticated user with access to a configured terminal server could cause script in a previewed file to run in the Open WebUI origin, read the victim's session token from localStorage, and take over the CVSSv3.1 8.2 (HIGH)

CWECWE 79CWECWE 1021TYPVulnerability
8.2
CVSS v3.1
91
Edit Score
2026-08-04
2026-08-04 20:16Z
HIGH

CVE-2026-70482 — Open: From 0.8.0 until 0.11.0, when ENABLE_OAUTH_TOKEN_EXCHANGE=True, /oauth/{provider}/token/exchange accepts a raw provider access token and

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-70482

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.8.0 until 0.11.0, when ENABLE_OAUTH_TOKEN_EXCHANGE=True, /oauth/{provider}/token/exchange accepts a raw provider access token and validates it by calling the provider userinfo endpoint without confirming which OAuth client the token was issued to. Anyone holding an access token minted for any client registered with the same provider could exchange it for an Open WebUI session as that CVSSv3.1 8.1 (HIGH)

CWECWE 287TYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-08-04
2026-08-04 20:16Z
CRIT

CVE-2026-70478 — Flowiseai Flowise: Prior to 3.1.3, the POST /api/v1/oauth2-credential/refresh/:credentialId endpoint is included in WHITELIST_URLS and requires no

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-70478

Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, the POST /api/v1/oauth2-credential/refresh/:credentialId endpoint is included in WHITELIST_URLS and requires no authentication. The endpoint decrypts the stored credential, sends a refresh request to the configured OAuth provider with the client secret and refresh token, and returns the refreshed access_token in the response body. An attacker with a credential ID can use t CVSSv3.1 10.0 (CRITICAL) · EPSS 31th percentile

CWECWE 200VNDFlowiseaiVNDFlowiseTYPVulnerability
10.0
CVSS v3.1
100
Edit Score
2026-08-04
2026-08-04 20:16Z
CRIT

CVE-2026-70477 — Flowiseai Flowise: Prior to 3.1.3, a prompt injection sent to a chatflow using a CSV Agent

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-70477

Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, a prompt injection sent to a chatflow using a CSV Agent node can cause the LLM to respond with a malicious Python script that bypasses the blocklist validator and executes in an unsandboxed Pyodide environment. The specific flaw exists within the run method of the CSV_Agents class, where untrusted data is used to construct an LLM prompt and the resulting pythonCode is vali CVSSv3.1 9.8 (CRITICAL) · EPSS 37th percentile

CWECWE 94VNDFlowiseaiVNDFlowiseTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-08-04
2026-08-04 20:16Z
HIGH

CVE-2026-70476 — Flowiseai Flowise: An authenticated attacker can perform unauthorized Stripe subscription operations on other tenants, including changing

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-70476

Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, several organization billing endpoints in packages/server/src/enterprise/routes/organization.route.ts and packages/server/src/enterprise/controllers/organization.controller.ts accept attacker-controlled Stripe subscriptionId values without verifying that the identifier belongs to the authenticated user's organization. An authenticated attacker can perform unauthorized Stri CVSSv3.1 8.2 (HIGH) · EPSS 21th percentile

CWECWE 639CWECWE 284VNDFlowiseaiVNDFlowiseTYPVulnerability
8.2
CVSS v3.1
91
Edit Score
2026-08-04
2026-08-04 20:16Z
HIGH

CVE-2026-16793 — An improper neutralization of special elements used in an operating system command vulnerability was

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-16793

An improper neutralization of special elements used in an operating system command vulnerability was reported in Lenovo XClarity Orchestrator (LXCO) 2.2.0 that could allow an authenticated attacker to execute arbitrary operating system commands as a privileged user under a specific circumstance. CVSSv3.1 8.8 (HIGH)

CWECWE 20CWECWE 78TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-08-04
2026-08-04 20:09Z
INFO

Mythic 4 Public Beta: More Than a New Coat of Paint

SpecterOps·specterops.io

Mythic 4.0 enters public beta with major feature additions including operation chat, pluggable AI chat containers with scoped API tokens, inline task references for credentials, resumable file transfers, in-browser file editing, and a refreshed UI. The release includes breaking changes requiring updates to agents, C2 profiles, and custom services, with a multi-month beta period for community testing and migration.

SRFApplicationSWMythicVNDSpecteropsTYPTool
72
Edit Score
2026-08-04
2026-08-04 19:16Z
HIGH

CVE-2026-70474 — Flowiseai Flowise: This allows any authenticated user to initiate OAuth2 flows against credentials belonging to other

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-70474

Flowise is a drag-and-drop user interface for building customized large language model (LLM) flows. Prior to 3.1.3, Flowise has three OAuth2 credential endpoints that look up credentials by id alone with no workspaceId filter. The authorize, callback, and refresh handlers query the Credential table by id only; callback and refresh are whitelisted from authentication. This allows any authenticated user to initiate OAuth2 flows against credentials belonging to other workspaces, CVSSv3.1 8.1 (HIGH) · EPSS 23th percentile

CWECWE 863VNDFlowiseaiVNDFlowiseTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-08-04
2026-08-04 19:16Z
HIGH

CVE-2026-70473 — Flowiseai Flowise: The observed behavior indicates missing or insufficient authorization checks, workspace/project/tenant isolation, and pagination or

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-70473

Flowise is a drag-and-drop user interface for building customized large language model (LLM) flows. Prior to 3.1.3, Flowise GET /api/v1/upsert-history returns the entire server-wide upsert history instead of being scoped to the requesting user, tenant, or workspace. The response can exceed 100MB and includes sensitive configuration data, including Vector Store settings such as Qdrant Server URL and collection name. The observed behavior indicates missing or insufficient autho CVSSv3.1 8.5 (HIGH) · EPSS 16th percentile

CWECWE 862CWECWE 200CWECWE 202VNDFlowiseaiVNDFlowiseTYPVulnerability
8.5
CVSS v3.1
93
Edit Score