2026-08-03
2026-08-03 13:17Z
HIGH

CVE-2026-18599 — This manipulation of the argument record_size causes command injection.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-18599

A flaw has been found in GL.iNet GL-MT3000 up to 4.4.5. The impacted element is the function logread.set_config of the file /usr/lib/oui-httpd/rpc/logread of the component Logread Lua RPC Plugin. This manipulation of the argument record_size causes command injection. The exploit has been published and may be used. The vendor was contacted early about this disclosure and confirmed the existence of the vulnerability. CVSSv3.1 8.0 (HIGH)

CWECWE 74CWECWE 77TYPVulnerability
8.0
CVSS v3.1
90
Edit Score
2026-08-03
2026-08-03 13:17Z
HIGH

CVE-2026-18598 — The manipulation of the argument module results in command injection.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-18598

A vulnerability was detected in GL.iNet GL-MT3000 up to 4.4.5. The affected element is the function logread.get_system_log of the file /usr/lib/oui-httpd/rpc/logread of the component Logread Lua RPC plugin. The manipulation of the argument module results in command injection. The attack can be launched remotely. The exploit is now public and may be used. The vendor was contacted early about this disclosure and confirmed the existence of the vulnerability. CVSSv3.1 8.8 (HIGH)

CWECWE 74CWECWE 77TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-08-03
2026-08-03 13:00Z
HIGH

An analysis of incidents at Brazilian educational institutions

Kaspersky Securelist·securelist.comin the wild

Kaspersky's incident response analysis of 18 months of attacks (Jan 2025–Jun 2026) against Brazilian educational institutions reveals a pattern of ransomware (DragonForce, LockBit 3) and insider threats exploiting weak credential hygiene, unpatched legacy systems (Windows 10 EOL, Server 2016), and exposed remote access tools. Three detailed case studies demonstrate abuse of valid accounts, PsExec lateral movement, AnyDesk remote access deployment, and a Python keylogger used by an insider to harvest passwords from shared workstations.

SRFApplicationTACTA0005TACTA0001TACTA0002SRFNetworkTACTA0003TACTA0040TYPResearch
72
Edit Score
2026-08-03
2026-08-03 07:27Z
CRIT

Nuclei Templates v10.4.7 - Release Notes

Nuclei Templates v10.4.7 release adds 122 new templates covering 49 CVEs, including 16 critical vulnerabilities across WordPress, Gitea, Joomla, ServiceNow, Apache Solr, and other enterprise software. The release includes significant bug fixes for false positives/negatives, template validation improvements, and enhancements to detection accuracy for existing checks.

SWNucleiVNDProjectdiscoveryTYPTool
78
Edit Score
2026-08-03
2026-08-03 07:16Z
CRIT

CVE-2026-18589 — Wavlink: The manipulation of the argument User1Passwd results in stack-based buffer overflow.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-18589

A vulnerability was found in Wavlink WL-NU516U1 708c073-mt7628. This impacts the function change_password of the file nas.cgi. The manipulation of the argument User1Passwd results in stack-based buffer overflow. The attack can be executed remotely. The exploit has been made public and could be used. The affected component should be upgraded. The vendor was contacted early, responded in a very professional manner and quickly released a fixed version of the affected product. CVSSv3.1 9.8 (CRITICAL)

CWECWE 121CWECWE 119VNDWavlinkTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-08-03
2026-08-03 07:16Z
CRIT

CVE-2026-18588 — The manipulation of the argument CONTENT_LENGTH leads to stack-based buffer overflow.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-18588

A vulnerability has been found in Wavlink WL-NU516U1 708c073-mt7628. This affects the function fgets of the file nas.cgi. The manipulation of the argument CONTENT_LENGTH leads to stack-based buffer overflow. Remote exploitation of the attack is possible. You should upgrade the affected component. The vendor was contacted early, responded in a very professional manner and quickly released a fixed version of the affected product. CVSSv3.1 9.8 (CRITICAL)

CWECWE 121CWECWE 119TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-08-03
2026-08-03 07:16Z
HIGH

CVE-2026-16572 — LogMyTrip: The LogMyTrip WordPress plugin through 1.9 does not sanitize and escape a value taken

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-16572

The LogMyTrip WordPress plugin through 1.9 does not sanitize and escape a value taken from a cookie before using it in a SQL query, allowing unauthenticated users to perform SQL injection attacks on any page that renders one of the LogMyTrip WordPress plugin through 1.9's shortcodes. CVSSv3.1 8.6 (HIGH)

CWECWE 89VNDLogmytripTYPVulnerability
8.6
CVSS v3.1
93
Edit Score
728 × 90 / responsive · programmatic ad slot
2026-08-03
2026-08-03 07:16Z
HIGH

CVE-2026-16539 — WordPress: The sm page duplicator WordPress plugin through 1.0.0 does not sanitise and escape a

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-16539

The sm page duplicator WordPress plugin through 1.0.0 does not sanitise and escape a stored value before using it in a SQL statement when duplicating a page, allowing users with the Editor role and above to perform SQL Injection attacks. CVSSv3.1 8.1 (HIGH)

CWECWE 89VNDWordpressTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-08-03
2026-08-03 07:16Z
CRIT

CVE-2026-16534 — Import: The Import and export users and customers WordPress plugin before 2.4.2 does not enforce

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-16534

The Import and export users and customers WordPress plugin before 2.4.2 does not enforce WordPress's role-assignment and per-user edit permissions during CSV import, allowing a user holding only the user-creation capability to create an administrator account and to overwrite an existing administrator's password or email. CVSSv3.1 9.1 (CRITICAL)

CWECWE 269VNDImportTYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2026-08-03
2026-08-03 07:16Z
CRIT

CVE-2026-16532 — Link: The Link Library WordPress plugin before 7.9.3 does not properly sanitise and escape a

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-16532

The Link Library WordPress plugin before 7.9.3 does not properly sanitise and escape a user-supplied value before using it in a SQL query, allowing unauthenticated users to perform SQL injection attacks. CVSSv3.1 9.1 (CRITICAL)

CWECWE 89VNDLinkTYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2026-08-03
2026-08-03 07:16Z
CRIT

CVE-2026-16300 — ChamaWP: The ChamaWP WordPress plugin before 1.0.13 does not properly validate a password reset request

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-16300

The ChamaWP WordPress plugin before 1.0.13 does not properly validate a password reset request, allowing unauthenticated attackers to reset the password of arbitrary users, including administrators, which could lead to a full site takeover. CVSSv3.1 9.8 (CRITICAL)

CWECWE 862VNDChamawpTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-08-03
2026-08-03 07:16Z
CRIT

CVE-2026-16250 — Personal: The Personal QR Message WordPress plugin through 1.0 does not restrict the file types

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-16250

The Personal QR Message WordPress plugin through 1.0 does not restrict the file types that can be uploaded through an unauthenticated handler, allowing unauthenticated users to upload arbitrary executable PHP files that are directly reachable, leading to remote code execution. CVSSv3.1 9.8 (CRITICAL) · EPSS 13th percentile

CWECWE 434VNDPersonalTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-08-03
2026-08-03 07:16Z
CRIT

CVE-2026-16060 — Insert: The Insert or Embed Articulate Content into WordPress plugin through 4.3000000027 does not correctly

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-16060

The Insert or Embed Articulate Content into WordPress plugin through 4.3000000027 does not correctly validate the contents of an uploaded archive, relying on a bypassable check that lets an Editor-level user upload a server-executable file into a public directory, resulting in remote code execution on servers configured to execute it. CVSSv3.1 9.8 (CRITICAL) · EPSS 11th percentile

CWECWE 434VNDInsertTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-08-03
2026-08-03 07:16Z
CRIT

CVE-2026-15930 — Simple: The Simple Membership WordPress plugin before 4.7.8 does not verify whether user creation failed

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-15930

The Simple Membership WordPress plugin before 4.7.8 does not verify whether user creation failed during registration before using the returned value as a user ID to update an account, allowing unauthenticated attackers to overwrite the primary administrator's account data (including the email address) and take over that account through the password reset flow. CVSSv3.1 9.4 (CRITICAL)

CWECWE 862VNDSimpleTYPVulnerability
9.4
CVSS v3.1
97
Edit Score
2026-08-03
2026-08-03 07:16Z
CRIT

CVE-2026-14557 — SoftMarket: The SoftMarket — Digital Marketplace WordPress plugin through 1.0.0 does not properly validate an

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-14557

The SoftMarket — Digital Marketplace WordPress plugin through 1.0.0 does not properly validate an authentication token in one branch of its email-verification flow, allowing unauthenticated attackers to obtain a valid session as any verified user by supplying only that user's ID. CVSSv3.1 9.1 (CRITICAL) · EPSS 9th percentile

CWECWE 287VNDSoftmarketTYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2026-08-03
2026-08-03 07:16Z
CRIT

CVE-2026-12965 — Super: The Super Store Finder WordPress plugin through 7.8 does not sanitize a parameter of

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-12965

The Super Store Finder WordPress plugin through 7.8 does not sanitize a parameter of an unauthenticated AJAX action before using it in a SQL query, allowing unauthenticated attackers to perform SQL injection and extract data from the database. CVSSv3.1 9.1 (CRITICAL)

CWECWE 89VNDSuperTYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2026-08-03
2026-08-03 07:16Z
CRIT

CVE-2026-12872 — Webinfos: The Webinfos WordPress plugin through 1.2 does not validate the type or name of

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-12872

The Webinfos WordPress plugin through 1.2 does not validate the type or name of uploaded files, nor restrict the upload action with any authentication, capability, or nonce check, allowing unauthenticated attackers to upload arbitrary files (including PHP) to a web-accessible directory, leading to remote code execution on servers that execute PHP from the uploads path. CVSSv3.1 9.8 (CRITICAL) · EPSS 20th percentile

CWECWE 434VNDWebinfosTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-08-03
2026-08-03 07:16Z
HIGH

CVE-2025-15672 — ChamaWP: The ChamaWP WordPress plugin before 1.0.13 does not properly validate user input before passing

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2025-15672

The ChamaWP WordPress plugin before 1.0.13 does not properly validate user input before passing it to a PHP deserialization function, allowing unauthenticated attackers to inject arbitrary PHP objects, which could lead to remote code execution when a suitable gadget chain is present via other installed code. CVSSv3.1 8.1 (HIGH) · EPSS 13th percentile

CWECWE 502VNDChamawpTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-08-03
2026-08-03 04:16Z
HIGH

CVE-2026-12817 — Bouncycastle Bc-java: In Bouncy Castle for Java before 1.85, OpenPGP AEAD decryption skips final tag on

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-12817

In Bouncy Castle for Java before 1.85, OpenPGP AEAD decryption skips final tag on chunk-aligned data. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bcpg-fips 1.0.13 (1.0.X series), 2.0.13 (2.0.X series) and 2.1.13 (2.1.X series). CVSSv3.1 8.6 (HIGH) · EPSS 6th percentile

CWECWE 354VNDBouncycastleVNDBouncyTYPVulnerability
8.6
CVSS v3.1
93
Edit Score
2026-08-03
2026-08-03 03:16Z
CRIT

CVE-2026-58062 — Bouncycastle Bc-java: In Bouncy Castle for Java before 1.85, Stapled OCSP response accepted without binding to

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-58062

In Bouncy Castle for Java before 1.85, Stapled OCSP response accepted without binding to the checked certificate. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bc-fips 2.0.2 (2.0.X series) and 2.1.3 (2.1.X series). CVSSv3.1 9.1 (CRITICAL) · EPSS 12th percentile

CWECWE 295VNDBouncycastleVNDBouncyTYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2026-08-03
2026-08-03 03:16Z
HIGH

CVE-2026-20465 — In wlan AP driver, there is a possible out of bounds write due to

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-20465

In wlan AP driver, there is a possible out of bounds write due to a missing bounds check. This could lead to remote (proximal/adjacent) escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: WCNCR00489200; Issue ID: MSV-7834. CVSSv3.1 8.1 (HIGH)

CWECWE 122TYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-08-03
2026-08-03 01:16Z
CRIT

CVE-2026-8763 — Bouncycastle Bc-java: In Bouncy Castle for Java before 1.85, Name Constraints bypass via trailing dot in

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-8763

In Bouncy Castle for Java before 1.85, Name Constraints bypass via trailing dot in rfc822Name and URI. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bc-fips 1.0.2.7 (1.0.X series), 2.0.2 (2.0.X series) and 2.1.3 (2.1.X series). CVSSv3.1 9.1 (CRITICAL) · EPSS 28th percentile

CWECWE 295VNDBouncycastleVNDBouncyTYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2026-08-03
2026-08-03 01:16Z
CRIT

CVE-2026-59650 — Bouncycastle Bc-java: In Bouncy Castle for Java before 1.85, MTI/A0 DH agreement exponentiates unvalidated peer value.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-59650

In Bouncy Castle for Java before 1.85, MTI/A0 DH agreement exponentiates unvalidated peer value. This issue also affects Bouncy Castle for Java LTS before 2.73.12. CVSSv3.1 9.1 (CRITICAL) · EPSS 20th percentile

CWECWE 20VNDBouncycastleVNDBouncyTYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2026-08-03
2026-08-03 01:16Z
HIGH

CVE-2026-59638 — Bouncycastle Bc-java: In Bouncy Castle for Java before 1.85, JSSE hostname verifier CN-fallback enabled by default

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-59638

In Bouncy Castle for Java before 1.85, JSSE hostname verifier CN-fallback enabled by default despite documented opt-in. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bctls-fips 1.0.24 (1.0.X series), 2.0.24 (2.0.X series) and 2.1.24 (2.1.X series). CVSSv3.1 8.6 (HIGH) · EPSS 20th percentile

CWECWE 297VNDBouncycastleVNDBouncyTYPVulnerability
8.6
CVSS v3.1
93
Edit Score
2026-08-03
2026-08-03 01:16Z
HIGH

CVE-2026-15055 — Bouncycastle Bc-java: In Bouncy Castle for Java before 1.85, PKCS#8 / PBES2 decryptors honour unbounded KDF

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-15055

In Bouncy Castle for Java before 1.85, PKCS#8 / PBES2 decryptors honour unbounded KDF cost from input. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bcpkix-fips 1.0.12 (1.0.X series), 2.0.12 (2.0.X series) and 2.1.12 (2.1.X series). CVSSv3.1 8.2 (HIGH) · EPSS 18th percentile

CWECWE 770VNDBouncycastleVNDBouncyTYPVulnerability
8.2
CVSS v3.1
91
Edit Score