2026-07-31
2026-07-31 21:17Z
CRIT

CVE-2025-69946 — SourceCodester: Modern Loan Management System 1.0 is vulnerable to SQL Injection in ajaxData.php via

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2025-69946

SourceCodester Modern Loan Management System 1.0 is vulnerable to SQL Injection in ajaxData.php via the parameters district_id , division_id, region_id, and ward_id. CVSSv3.1 9.8 (CRITICAL) · EPSS 6th percentile

CWECWE 89VNDSourcecodesterTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-07-31
2026-07-31 21:13Z
HIGH

CVE-2026-20316 | Cisco Secure Firewall Management Center Static Credential Vulnerability

Horizon3.ai·horizon3.aiCVE-2026-20316in the wild

CVE-2026-20316 is a hard-coded credential vulnerability in Cisco Secure Firewall Management Center allowing unauthenticated remote attackers to authenticate via a static low-privileged account. Cisco assigned CVSS 8.9 and confirmed active exploitation in the wild; the flaw is tracked in CISA's KEV catalog with an August 1, 2026 remediation deadline for federal agencies. Patches are available across all affected software branches (7.0–7.7 and 10.0–10.1).

SRFApplicationTACTA0001SRFNetwork ApplianceSWCisco Secure Firewall Management CenterVNDCiscoTYPVulnerabilityTECT1078.001EXPAuth Bypass
82
Edit Score
2026-07-31
2026-07-31 20:16Z
HIGH

CVE-2026-53510 — Savon: From 0.9.8 until 2.17.2, Savon::Model .all_operations interpolates attacker-controlled WSDL operation names into Ruby source

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-53510

Savon is a Ruby SOAP client. From 0.9.8 until 2.17.2, Savon::Model .all_operations interpolates attacker-controlled WSDL operation names into Ruby source passed to module_eval, allowing Ruby code execution in the application process. This issue is fixed in version 2.17.2. CVSSv3.1 8.1 (HIGH)

CWECWE 94VNDSavonTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-07-31
2026-07-31 20:16Z
CRIT

CVE-2026-38711 — TR1200: v2.4.15, TR3000 v2.4.21, WR300 v2.4.25, WR1200 v2.4.23, WR1300 v2.4.22, WR1500 v2.3.10, WR3000 v2.4.19

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-38711

TR1200 v2.4.15, TR3000 v2.4.21, WR300 v2.4.25, WR1200 v2.4.23, WR1300 v2.4.22, WR1500 v2.3.10, WR3000 v2.4.19, WR3600 v2.3.16, and WR6500 v2.3.15 were discovered to contain a command injection vulnerability in the system.upgrade_check interface. This vulnerability allows attackers to execute arbitrary commands as root via a crafted input. CVSSv3.1 9.8 (CRITICAL) · EPSS 65th percentile

CWECWE 77VNDTr1200TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-07-31
2026-07-31 19:17Z
HIGH

CVE-2026-53501 — Thumbor: This allows crafting URLs where the validated string differs from the actual requested resource

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-53501

Thumbor is an open-source photo thumbnail service by globo.com. Prior to 7.8.0, Thumbor’s HMAC validation can be bypassed due to the use of Python’s .replace() when removing the signature from the URL before validation. Since .replace() removes all occurrences of the substring, an attacker can insert the same signature multiple times in the URL and manipulate the final URL used for validation. This allows crafting URLs where the validated string differs from the actual reques CVSSv3.1 8.2 (HIGH)

CWECWE 347VNDThumborTYPVulnerability
8.2
CVSS v3.1
91
Edit Score
2026-07-31
2026-07-31 19:17Z
HIGH

CVE-2026-53500 — Thumbor: Prior to 7.8.0, the ALLOWED_SOURCES configuration passes plain strings to re.match() without escaping dots

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-53500

Thumbor is an open-source photo thumbnail service by globo.com. Prior to 7.8.0, the ALLOWED_SOURCES configuration passes plain strings to re.match() without escaping dots, so a hostname differing at dot positions can match the allowlist. This issue is fixed in 7.8.0. CVSSv3.1 8.2 (HIGH)

CWECWE 918VNDThumborTYPVulnerability
8.2
CVSS v3.1
91
Edit Score
2026-07-31
2026-07-31 18:17Z
CRIT

CVE-2026-54725 — Kubernetes: vault-secrets-webhook is a Kubernetes mutating webhook that makes direct secret injection into Pods possible.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-54725

vault-secrets-webhook is a Kubernetes mutating webhook that makes direct secret injection into Pods possible. Prior to 1.23.1, parseVaultConfig() in pkg/webhook/config.go accepts the vault.security.banzaicloud.io/vault-addr annotation, MutateConfigMap and MutateSecret call newVaultClient in pkg/webhook/webhook.go, and vault.security.banzaicloud.io/vault-serviceaccount can cause a ServiceAccount JWT to be sent to an attacker-controlled Vault address. This issue is fixed in ver CVSSv3.1 9.6 (CRITICAL)

CWECWE 918VNDKubernetesTYPVulnerability
9.6
CVSS v3.1
98
Edit Score
728 × 90 / responsive · programmatic ad slot
2026-07-31
2026-07-31 18:17Z
CRIT

CVE-2026-21662 — Johnsoncontrols Fms_employee: Unrestricted upload of file with dangerous type vulnerability in Johnson Controls FM Systems Employee

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-21662

Unrestricted upload of file with dangerous type vulnerability in Johnson Controls FM Systems Employee allows Using Malicious Files. This issue affects FM Systems Employee: before 2025.3.1. CVSSv3.1 9.8 (CRITICAL) · EPSS 34th percentile

CWECWE 434VNDJohnsoncontrolsTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-07-31
2026-07-31 17:16Z
CRIT

CVE-2026-67822 — Tenda: W6-S 1.0.0.4(510) contains a stack-based buffer overflow vulnerability in the /goform/wifiSSIDset endpoint.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-67822

Tenda W6-S 1.0.0.4(510) contains a stack-based buffer overflow vulnerability in the /goform/wifiSSIDset endpoint. The function formwrlSSIDset uses sprintf to copy user-controlled 'GO' and 'index' parameters into a 64-byte stack buffer without length restriction, leading to stack overflow. CVSSv3.1 9.8 (CRITICAL)

CWECWE 121VNDTendaTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-07-31
2026-07-31 17:16Z
CRIT

CVE-2026-52855 — Wings: Prior to 1.12.3, {{config.}} placeholders in egg configuration-file templates allow a low-privileged user to

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-52855

Wings is the server control plane for Pterodactyl, a free, open-source game server management panel. Prior to 1.12.3, {{config.}} placeholders in egg configuration-file templates allow a low-privileged user to read {{config.token}}, {{config.token_id}}, and {{config.docker.registries}} from the full daemon configuration. This issue is fixed in version 1.12.3. CVSSv3.1 9.9 (CRITICAL)

CWECWE 200CWECWE 522VNDWingsTYPVulnerability
9.9
CVSS v3.1
100
Edit Score
2026-07-31
2026-07-31 16:17Z
HIGH

CVE-2026-18141 — An unauthenticated remote attacker can bypass mutual Transport Layer Security (mTLS) authentication for event

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-18141

A flaw was found in aap-gateway, a component of Ansible Automation Platform's Event-Driven Ansible (EDA). An unauthenticated remote attacker can bypass mutual Transport Layer Security (mTLS) authentication for event streams. This is achieved by manipulating the event stream URL and forging the HTTP Subject header. The system also inadvertently discloses the expected certificate subject in error messages, which simplifies the attack. This vulnerability allows an attacker to in CVSSv3.1 8.2 (HIGH)

CWECWE 295TYPVulnerability
8.2
CVSS v3.1
91
Edit Score
2026-07-31
2026-07-31 16:17Z
CRIT

CVE-2026-17566 — Data: This is the same class of bug as CVE-2025-12762/CVE-2025-13780 (RCE via psql meta-command/COPY injection

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-17566

pgAdmin 4's Import/Export Data tool builds a psql \copy (...) command line by interpolating a user-supplied SQL query into a Jinja template and passing the rendered line to psql via --command. To stop an attacker from breaking out of the (...) wrapper, create_import_export_job() (route POST /import_export/job/<sid>, gated only by the ordinary, commonly-granted tools_import_export_data permission) validated the query with a hand-written parenthesis-balance checker, _is_query_p CVSSv3.1 9.9 (CRITICAL)

CWECWE 78CWECWE 115TYPVulnerability
9.9
CVSS v3.1
100
Edit Score
2026-07-31
2026-07-31 16:16Z
CRIT

CVE-2026-17351 — CVE: This reintroduces the same write/RCE bypass CVE-2026-12045 was meant to close, reachable via the

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-17351

The fix for CVE-2026-12045 in pgAdmin 4 9.16 required the LLM-supplied query passed to the AI Assistant's execute_sql_query tool to parse, via sqlparse, as exactly one non-transaction-control statement before running it inside a BEGIN TRANSACTION READ ONLY wrapper. sqlparse's string-literal lexing can disagree with PostgreSQL's own parser: under standard_conforming_strings = on (PostgreSQL's default since 9.1), a backslash immediately before a quote is an ordinary character t CVSSv3.1 9.0 (CRITICAL)

CWECWE 89CWECWE 115VNDCveTYPVulnerability
9.0
CVSS v3.1
95
Edit Score
2026-07-31
2026-07-31 16:16Z
CRIT

CVE-2026-17349 — Workspaces: /misc/workspace/adhoc_connect_server, part of the Workspaces feature introduced in pgAdmin 4 9.0, when passed the

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-17349

/misc/workspace/adhoc_connect_server, part of the Workspaces feature introduced in pgAdmin 4 9.0, when passed the id of an existing server, clones that server via Server.clone(), which copies every column from the source row, including user_id, shared, shared_username, and the stored credential fields password, save_password, and tunnel_password. When a non-owner triggered an adhoc connect against another user's (in practice, typically an administrator's) shared server, the c CVSSv3.1 9.6 (CRITICAL)

CWECWE 639CWECWE 522VNDWorkspacesTYPVulnerability
9.6
CVSS v3.1
98
Edit Score
2026-07-31
2026-07-31 16:16Z
HIGH

CVE-2026-17346 — CVE: The fix for CVE-2026-12044 in pgAdmin 4 9.16 hardened qtLiteral and switched sixteen COMMENT

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-17346

The fix for CVE-2026-12044 in pgAdmin 4 9.16 hardened qtLiteral and switched sixteen COMMENT ON / pgstattuple / pgstatindex templates to it, but missed several sinks that had been placed in test_sql_string_literal_lint.py's ALLOWLIST on the incorrect assumption that schema, table, publication, and subscription names sourced from pg_catalog via the browser tree could never contain an apostrophe. PostgreSQL permits arbitrary characters in quoted identifiers, so a low-privileged CVSSv3.1 8.8 (HIGH)

CWECWE 89VNDCveTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-07-31
2026-07-31 16:16Z
CRIT

CVE-2026-16504 — Deployment: of the VPS.org one-click Zulip template deploys a hardcoded application signing key, a

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-16504

Deployment of the VPS.org one-click Zulip template deploys a hardcoded application signing key, a default database password ("zulip"), and DISABLE_HTTPS=True. CVSSv3.1 9.8 (CRITICAL) · EPSS 3th percentile

CWECWE 1188CWECWE 1393CWECWE 321VNDDeploymentTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-07-31
2026-07-31 16:16Z
CRIT

CVE-2026-16503 — Deployment: of the VPS.org one-click Supabase template deploys a PostgreSQL instance that is published

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-16503

Deployment of the VPS.org one-click Supabase template deploys a PostgreSQL instance that is published on all interfaces (0.0.0.0:5432) with a default database password set to "postgres". Because Docker installs its own iptables rules, this exposure bypasses a standard host UFW configuration. CVSSv3.1 9.1 (CRITICAL) · EPSS 4th percentile

CWECWE 1188CWECWE 1393CWECWE 1327VNDDeploymentTYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2026-07-31
2026-07-31 13:17Z
CRIT

CVE-2026-17561 — Control: Improper Control of Generation of Code ('Code Injection') vulnerability in Innotim Software, Telecommunications and

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-17561

Improper Control of Generation of Code ('Code Injection') vulnerability in Innotim Software, Telecommunications and Consulting Trade Ltd. Co. Logsign SIEM allows Code Injection. This issue affects Logsign SIEM: before 6.4.108. CVSSv3.1 9.8 (CRITICAL)

CWECWE 94TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-07-31
2026-07-31 13:00Z
HIGH

What Security Leaders Think About Frontier AI Models: Firsthand of Mythos

Bishop Fox Labs·bishopfox.com

Bishop Fox executives discuss frontier AI models (specifically Anthropic's Claude Mythos) and their impact on offensive and defensive security. The consensus: Mythos raises the ceiling for skilled attackers (enabling nation-state velocity) while lowering the bar for novices, but the model itself is not the differentiator—the harness and expertise matter more. Defenders face a 24-month disadvantage window; traditional patching won't scale, and operational resilience becomes critical.

TACTA0001TACTA0002SRFAiSWMythosVNDAnthropicTYPNewsSTGDiscoverySTGRecon
72
Edit Score
2026-07-31
2026-07-31 11:17Z
HIGH

CVE-2026-62391 — CVE: Any client who can access to Apache Kyuubi Server via Kyuubi frontend protocols can

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-62391

The security fix for CVE-2025-66518 is incomplete. Any client who can access to Apache Kyuubi Server via Kyuubi frontend protocols can bypass server-side config kyuubi.session.local.dir.allowlist via unprefixed Spark config aliases. This issue affects Apache Kyuubi: from 1.6.0 before 1.12.0. Users are recommended to upgrade to version 1.12.0, which fixes the issue. CVSSv3.1 8.1 (HIGH)

CWECWE 22CWECWE 27VNDCveTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-07-31
2026-07-31 10:16Z
HIGH

CVE-2026-10079 — Red: A flaw was found in Red Hat Advanced Cluster Security for Kubernetes (RHACS).

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-10079

A flaw was found in Red Hat Advanced Cluster Security for Kubernetes (RHACS). When processing Kubernetes Deployments, ACS replaces deployment identity metadata based on the openshift.io/encoded-deployment-config label. A user with permission to create Deployments can set this label to "null", causing ACS to treat the workload as having empty UID, name and labels and namespace "default". This bypasses deploy-time policy detection and enforcement visibility, prevents correct pe CVSSv3.1 8.5 (HIGH)

CWECWE 345VNDRedTYPVulnerability
8.5
CVSS v3.1
93
Edit Score
2026-07-31
2026-07-31 10:00Z
HIGH

Network Anomaly Detection in KATA

Kaspersky Securelist·securelist.com

Kaspersky's KATA platform implements Network Anomaly Detection (NAD) rules to identify Kerberoasting and DNS tunneling attacks by analyzing deviations from baseline network behavior rather than relying on signature-based detection. The article details how NAD correlates indirect indicators—anomalous request sources, SPN request surges, and abnormal data volumes—to detect attacks that blend seamlessly with legitimate traffic, and provides practical examples of SQL-based detection rules with configurable thresholds and exclusions.

SRFNetworkTACTA0007TACTA0010SWKataVNDKasperskyTYPResearchSTGDiscoverySTGExfil
68
Edit Score
2026-07-31
2026-07-31 09:16Z
HIGH

CVE-2026-65313 — A provisioning script used when installing HIPASE-250 (formerly 250 SCALA) engineering workstations sets a

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-65313

A provisioning script used when installing HIPASE-250 (formerly 250 SCALA) engineering workstations sets a fixed, hard-coded x11vnc password. Because the same credential is applied to every workstation provisioned this way, an attacker with adjacent-network access who knows the password can gain VNC access to affected workstations. CVSSv3.1 8.1 (HIGH)

CWECWE 798CWECWE 1392TYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-07-31
2026-07-31 07:16Z
CRIT

CVE-2026-18452 — Non: DMS+ (Non-Mobile) developed by Rich Source has a Use of Hard-coded Credentials vulnerability.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-18452

DMS+ (Non-Mobile) developed by Rich Source has a Use of Hard-coded Credentials vulnerability. Unauthenticated remote attackers can exploit a fixed API key to gain control over all installed DMS+ devices. CVSSv3.1 10.0 (CRITICAL)

CWECWE 798VNDNonTYPVulnerability
10.0
CVSS v3.1
100
Edit Score
2026-07-31
2026-07-31 07:16Z
HIGH

CVE-2026-16236 — Realtyna: The Realtyna Organic IDX plugin for WordPress is vulnerable to Arbitrary File Upload in

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-16236

The Realtyna Organic IDX plugin for WordPress is vulnerable to Arbitrary File Upload in versions up to, and including, 5.3.0. This is due to missing file extension and content validation in the saveLiveImages() function combined with an insufficient authorization check on the get_keys() AJAX handler and a missing authentication check on the REST API import endpoint. This makes it possible for authenticated attackers, with subscriber-level access and above, to upload arbitrary CVSSv3.1 8.8 (HIGH)

CWECWE 434VNDRealtynaTYPVulnerability
8.8
CVSS v3.1
94
Edit Score