2026-07-30
2026-07-30 13:16Z
HIGH

CVE-2026-54368 — CentreStack: before 17.4 contains a SQL injection vulnerability in GladDBFiles.SearchEx() and SearchExUnder() that allows

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-54368

CentreStack before 17.4 contains a SQL injection vulnerability in GladDBFiles.SearchEx() and SearchExUnder() that allows authenticated attackers to execute arbitrary SQL statements by supplying a crafted x-glad-filter request header through the jsondir API endpoint. Attackers can exploit unsanitized interpolation of the Field parameter directly into SQL query strings to write arbitrary files to the server filesystem via PostgreSQL lo_from_bytea() and lo_export() functions, en CVSSv3.1 8.8 (HIGH)

CWECWE 89VNDCentrestackTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-07-30
2026-07-30 13:16Z
HIGH

CVE-2026-54367 — CentreStack: before 17.2 contains an authentication bypass vulnerability that allows unauthenticated attackers to read

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-54367

CentreStack before 17.2 contains an authentication bypass vulnerability that allows unauthenticated attackers to read, write, or delete arbitrary account settings by exploiting exposed API endpoints that lack authorization checks. Attackers can generate valid encrypted EntAcctId values using the static shared encryption key to forge identifiers for any user GUID, including the system-wide cluster settings account, enabling enumeration of hosted tenant domains and administrato CVSSv3.1 8.6 (HIGH)

CWECWE 306VNDCentrestackTYPVulnerability
8.6
CVSS v3.1
93
Edit Score
2026-07-30
2026-07-30 13:16Z
CRIT

CVE-2026-54363 — CentreStack: before 17.5 contains a hardcoded cryptographic key vulnerability that allows unauthenticated attackers to

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-54363

CentreStack before 17.5 contains a hardcoded cryptographic key vulnerability that allows unauthenticated attackers to forge arbitrary encrypted tokens by exploiting a static SysNumber value used as entropy for AccessTicket.Encrypt() and AccessTicket.Decrypt() across all installations. Attackers can use the hardcoded key to craft valid x-glad-auth headers and call privileged API endpoints such as acquiretenantbackuptoken to obtain a domain administrator IdentityTicket, enablin CVSSv3.1 9.1 (CRITICAL)

CWECWE 321VNDCentrestackTYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2026-07-30
2026-07-30 13:16Z
CRIT

CVE-2026-47876 — VMware: ESX contains an out-of-bounds write vulnerability in the VMXNET3 virtual network adapter.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-47876

VMware ESX contains an out-of-bounds write vulnerability in the VMXNET3 virtual network adapter. A malicious actor with local administrative privileges on a virtual machine with VMXNET3 virtual network adapter may exploit this issue to execute code on the host. Non VMXNET3 virtual adapters are not affected by this issue. CVSSv3.1 9.3 (CRITICAL)

CWECWE 787VNDVmwareTYPVulnerability
9.3
CVSS v3.1
97
Edit Score
2026-07-30
2026-07-30 12:17Z
CRIT

CVE-2026-17544 — Php Php: Attacker-provided inputs to bccomp() could lead to an out-of-bounds write with stack and heap

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-17544

Attacker-provided inputs to bccomp() could lead to an out-of-bounds write with stack and heap corruption in PHP versions from 8.4.* before 8.4.24 and from 8.5.* before 8.5.9. CVSSv3.1 9.8 (CRITICAL) · EPSS 35th percentile

CWECWE 787VNDAttackerTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-07-30
2026-07-30 12:17Z
CRIT

CVE-2026-17543 — Php Php: Improper escaping of backslashes in attacker-provided parameters would allow for trivial SQL injection in

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-17543

Improper escaping of backslashes in attacker-provided parameters would allow for trivial SQL injection in PHP versions from 8.2.* before 8.2.33, from 8.3.* before 8.3.33, from 8.4.* before 8.4.24, and from 8.5.* before 8.5.9. CVSSv3.1 9.8 (CRITICAL) · EPSS 31th percentile

CWECWE 89TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-07-30
2026-07-30 11:16Z
HIGH

CVE-2026-22622 — Improper input validation in one of the session management interface of Eaton's Tripp Lite

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-22622

Improper input validation in one of the session management interface of Eaton's Tripp Lite series PADM firmware could allow an authenticated user to elevate privileges resulting in unrestricted access to the device. CVSSv3.1 8.8 (HIGH)

CWECWE 78TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
728 × 90 / responsive · programmatic ad slot
2026-07-30
2026-07-30 11:16Z
HIGH

CVE-2026-22621 — Improper input validation in one of the session management interface of Eaton's Tripp Lite

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-22621

Improper input validation in one of the session management interface of Eaton's Tripp Lite Series PADM firmware could allow an authenticated administrator to execute arbitrary commands within a restricted environment. CVSSv3.1 8.3 (HIGH)

CWECWE 78TYPVulnerability
8.3
CVSS v3.1
92
Edit Score
2026-07-30
2026-07-30 11:16Z
HIGH

CVE-2026-22620 — Improper input validation in the authentication component of Eaton's Tripp Lite series PADM firmware

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-22620

Improper input validation in the authentication component of Eaton's Tripp Lite series PADM firmware could allow an unauthenticated remote attacker to bypass authentication and gain a privileged user access to the device. CVSSv3.1 8.6 (HIGH)

CWECWE 89TYPVulnerability
8.6
CVSS v3.1
93
Edit Score
2026-07-30
2026-07-30 11:00Z
HIGH

OctLurk and SilkLurk: newly identified tailored backdoors in cyber-espionage campaign in Central Asia

Kaspersky Securelist·securelist.com

Kaspersky identified two new tailored backdoors, OctLurk and SilkLurk, deployed in a coordinated cyber-espionage campaign targeting government organizations across Central Asia (Afghanistan, Kyrgyzstan, Tajikistan, Uzbekistan, Kazakhstan, Syria) since January 2025. Both backdoors feature custom loaders using victim-machine fingerprinting for payload decryption, plugin-based architecture for command shells, file management, keylogging, credential harvesting, and remote access. The campaign demonstrates sophisticated post-compromise activity including event log exfiltration, Impacket secretsdump deployment for domain controller credential theft, and browser password extraction.

SRFOsTACTA0004TACTA0001SRFNetworkTACTA0007TACTA0003TACTA0008TACTA0009
78
Edit Score
2026-07-30
2026-07-30 11:00Z
HIGH

Building secure Uniswap v4 hooks

Trail of Bits·blog.trailofbits.com

Trail of Bits published a comprehensive security guide for Uniswap v4 hooks, identifying seven recurring failure patterns in hook and application code that have led to $20M+ in losses (Cork ~$12M, Bunni ~$8.4M). The analysis covers missing caller checks, pool validation gaps, accounting bugs, callback timing issues, permission-bit mismatches, denial-of-service vectors, and state-mutation risks during callback sequences.

SRFApplicationTACTA0005SRFWebSWUniswapTYPResearchSTGExecutionSTGImpactEXPAuth Bypass
78
Edit Score
2026-07-30
2026-07-30 10:35Z
CRIT

Critical VMware vCenter Vulnerabilities Allow Authentication Bypass and Remote Code Execution (CVE-2026-59309, CVE-2026-59310)

Rapid7 Research·rapid7.comCVE-2026-59309CVE-2026-59310

Broadcom published VMSA-2026-0006 disclosing two critical unauthenticated vulnerabilities in VMware vCenter Server: CVE-2026-59309 (authentication bypass in Directory Service, CVSS 9.8) and CVE-2026-59310 (directory traversal in Syslog server enabling RCE, CVSS 9.8). Both require only network access and no prior authentication; patches are available across vCenter 8.0, 9.0, and 9.1 versions. No public PoC or in-the-wild exploitation reported at publication, but vCenter has a history of rapid weaponization.

SRFApplicationTACTA0001TACTA0002SRFCloudSWVcenterSWVsphereVNDVmwareVNDBroadcom
92
Edit Score
2026-07-30
2026-07-30 08:00Z
CRIT

Toy Ghouls’ new toy: the GenieLocker ransomware

Kaspersky Securelist·securelist.comin the wild

Kaspersky disclosed GenieLocker, a custom-built ransomware family deployed by the Toy Ghouls threat group since March 2026 against Russian manufacturing and construction sectors. The malware runs natively on Windows, Linux, and ESXi, uses XChaCha20-Poly1305 for file encryption with Curve25519-XSalsa20-Poly1305 for key wrapping, and includes anti-debugging, process termination, and service shutdown capabilities. The group has transitioned from using third-party ransomware (RedAlert, LockBit, Babuk) to this proprietary variant, reducing operational dependency and unifying their encryption stack across platforms.

SRFApplicationSRFOsTACTA0001TACTA0007TACTA0008TACTA0009OSLinuxOSWindows
78
Edit Score
2026-07-30
2026-07-30 07:16Z
CRIT

CVE-2026-7849 — Due to improper neutralization of special elements, an unauthenticated remote attacker is able to

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-7849

Due to improper neutralization of special elements, an unauthenticated remote attacker is able to inject a command into the system configuration which is subsequently executed as root. CVSSv3.1 9.8 (CRITICAL)

CWECWE 77TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-07-30
2026-07-30 07:16Z
CRIT

CVE-2026-44108 — Due to a flaw in the execution order of scripts during shutdown, the firewall

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-44108

Due to a flaw in the execution order of scripts during shutdown, the firewall is terminated prematurely during system shutdown. This creates a temporary window in which internal services may become externally accessible, potentially allowing an unauthenticated remote attacker to connect to these services, resulting in full system compromise. CVSSv3.1 9.8 (CRITICAL)

CWECWE 696TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-07-30
2026-07-30 07:16Z
CRIT

CVE-2026-44104 — This allows an unauthenticated remote attacker to install a modified firmware, resulting in full

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-44104

The firmware update process for the basemodule of the charging controller only validates the CRC32 checksum without cryptographic signature verification. This allows an unauthenticated remote attacker to install a modified firmware, resulting in full system compromise. CVSSv3.1 9.8 (CRITICAL)

CWECWE 347TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-07-30
2026-07-30 07:16Z
CRIT

CVE-2026-44101 — CHARX: Due to missing authentication the CHARX OCPP Agent service allows an unauthenticated remote attacker

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-44101

Due to missing authentication the CHARX OCPP Agent service allows an unauthenticated remote attacker to reconfigure the backend connection. This can lead to Denial-of-Service and confidential data being disclosed to the attacker. CVSSv3.1 9.8 (CRITICAL)

CWECWE 306VNDCharxTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-07-30
2026-07-30 07:16Z
CRIT

CVE-2026-44100 — CHARX: The CHARX JupiCore service allows an unauthenticated remote attacker to reconfigure charging points.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-44100

The CHARX JupiCore service allows an unauthenticated remote attacker to reconfigure charging points. This can lead to disclosure of charging point UIDs, Denial-of-Service and files tampering. CVSSv3.1 9.4 (CRITICAL)

CWECWE 306VNDCharxTYPVulnerability
9.4
CVSS v3.1
97
Edit Score
2026-07-30
2026-07-30 07:16Z
HIGH

CVE-2026-44098 — This vulnerability allows an unauthenticated remote attacker with control over the OCPP backend via

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-44098

This vulnerability allows an unauthenticated remote attacker with control over the OCPP backend via firewall-bypass to perform an OS command injection, resulting in the execution of arbitrary commands as the limited user charx-oa. Charging could be interrupted. CVSSv3.1 8.6 (HIGH)

CWECWE 78TYPVulnerability
8.6
CVSS v3.1
93
Edit Score
2026-07-30
2026-07-30 07:16Z
HIGH

CVE-2026-44094 — This could allow the attacker to gain SSH access to the system as an

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-44094

An unauthenticated remote attacker can enforce the system to fall back to a firmware partition with an insecure configuration including default credentials. This could allow the attacker to gain SSH access to the system as an unprivileged user "user-app". Charging could be interrupted. CVSSv3.1 8.6 (HIGH)

CWECWE 636TYPVulnerability
8.6
CVSS v3.1
93
Edit Score
2026-07-30
2026-07-30 07:16Z
CRIT

CVE-2026-44092 — This may lead to integrity and availability loss.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-44092

An unauthenticated remote attacker can inject malicious input into the ModbusServer application because it does not validate the input it fetches from MQTT. This may lead to integrity and availability loss. CVSSv3.1 9.1 (CRITICAL)

CWECWE 93TYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2026-07-30
2026-07-30 07:16Z
CRIT

CVE-2026-44091 — An unauthenticated remote attacker can post a malicious ID to the MQTT Broker results

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-44091

An unauthenticated remote attacker can post a malicious ID to the MQTT Broker results in the creation of a new configuration entry in the system configuration. This may lead to integrity and availability loss. CVSSv3.1 9.1 (CRITICAL)

CWECWE 501TYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2026-07-30
2026-07-30 07:16Z
CRIT

CVE-2026-44090 — Due to missing authentication, an unauthenticated remote attacker may access the MQTT broker, which

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-44090

Due to missing authentication, an unauthenticated remote attacker may access the MQTT broker, which is only protected from external access by a firewall. This may lead to the device being fully compromised. CVSSv3.1 9.8 (CRITICAL)

CWECWE 306TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-07-30
2026-07-30 06:25Z
CRIT

CVE-2026-58066 — Rocket: Rocket.Chat's SAML SSO before versions 8.7.0, 8.6.1, 8.5.2, 8.4.5, 8.3.7, 8.2.7, 8.1.7, 8.0.8, and

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-58066

Rocket.Chat's SAML SSO before versions 8.7.0, 8.6.1, 8.5.2, 8.4.5, 8.3.7, 8.2.7, 8.1.7, 8.0.8, and 7.10.14 verified XML signatures but did not bind the validated signature to samlp:Response / saml:Assertion. An attacker could submit a wrapped document carrying forged identity attributes alongside any valid signature made by the trusted IdP certificate, and log in as an arbitrary user. CVSSv3.1 9.8 (CRITICAL)

CWECWE 287VNDRocketTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-07-30
2026-07-30 06:25Z
CRIT

CVE-2026-58046 — Plesk: Improper neutralization in the Plesk XML-RPC API allows a remote authenticated low-privileged user to

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-58046

Improper neutralization in the Plesk XML-RPC API allows a remote authenticated low-privileged user to perform SQL injection and read arbitrary data from the Plesk database, leading to full compromise of the panel. CVSSv3.1 9.9 (CRITICAL)

CWECWE 89VNDPleskTYPVulnerability
9.9
CVSS v3.1
100
Edit Score