2026-07-28
2026-07-28 16:00Z
HIGH

Disrupting supply chain attacks on npm and GitHub Actions

GitHub Security·github.blog

GitHub and npm announced a coordinated set of supply-chain hardening measures deployed over the past year to disrupt common attack patterns targeting open-source maintainers and CI/CD pipelines. Changes include account protection delays for high-impact npm accounts, safer pull_request_target defaults in GitHub Actions, staged publishing, disabled install scripts by default in npm v12, Dependabot version cooldowns, and credential revocation tooling for incident response.

TACTA0001TACTA0006SRFSupply ChainSWGithub ActionsVNDGithubTYPAdvisorySTGInitial AccessSTGCred Access
72
Edit Score
2026-07-28
2026-07-28 15:17Z
CRIT

CVE-2026-66713 — Deserialization: of Untrusted Data (CWE-502) in the Tribes-based clustering component in Apache Software Foundation

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-66713

Deserialization of Untrusted Data (CWE-502) in the Tribes-based clustering component  in Apache Software Foundation Apache Axis2/Java through 2.0.0 on Apache Tomcat  (only when Tribes clustering is enabled, which is off by default) allows an  unauthenticated remote attacker with network access to the clustering port to  execute arbitrary code via a crafted serialized Java object delivered to the cluster  channel and deserialized in  org.apache.axis2.clustering.tri CVSSv3.1 9.8 (CRITICAL)

CWECWE 502TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-07-28
2026-07-28 15:17Z
HIGH

CVE-2026-63727 — Anchore: Enterprise versions from 5.11.0 to 5.27.1 and 6.0.0 contain an improper privilege escalation

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-63727

Anchore Enterprise versions from 5.11.0 to 5.27.1 and 6.0.0 contain an improper privilege escalation vulnerability in the user management API. An authenticated attacker who is able to access the Anchore Enterprise API could issue an API call capable of modifying user permissions to gain access to additional resources and operations. It is not possible to grant the system-admin role, but a read only user could be granted write access. This issue is fixed in Anchore Enterprise CVSSv3.1 8.8 (HIGH)

CWECWE 648VNDAnchoreTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-07-28
2026-07-28 15:17Z
CRIT

CVE-2026-51261 — AudioBuffer: Missing mutex synchronization in AudioBuffer::freeSpace() in schreibfaul1 ESP32-audioI2S 3.4.5 creates a race condition between

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-51261

Missing mutex synchronization in AudioBuffer::freeSpace() in schreibfaul1 ESP32-audioI2S 3.4.5 creates a race condition between concurrent tasks. The function calculates available buffer space without protecting shared read/write pointers, returning an incorrectly large value. Trusting this value leads to heap out-of-bounds write, memory corruption, device crash, and arbitrary code execution. CVSSv3.1 9.8 (CRITICAL)

CWECWE 362VNDAudiobufferTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-07-28
2026-07-28 15:17Z
CRIT

CVE-2026-51260 — Unsafe: fixed-size memcpy operation in AudioBuffer::writeSpace() of schreibfaul1 ESP32-audioI2S 3.4.5 allows remote heap buffer

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-51260

Unsafe fixed-size memcpy operation in AudioBuffer::writeSpace() of schreibfaul1 ESP32-audioI2S 3.4.5 allows remote heap buffer overflow. The code copies a full UINT16_MAX bytes without validating destination available space, causing out-of-bounds memory write. CVSSv3.1 9.4 (CRITICAL)

CWECWE 122VNDUnsafeTYPVulnerability
9.4
CVSS v3.1
97
Edit Score
2026-07-28
2026-07-28 15:17Z
CRIT

CVE-2026-51259 — Unchecked: unsigned integer overflow in buffer size calculation in schreibfaul1 ESP32-audioI2S 3.4.5 leads to

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-51259

Unchecked unsigned integer overflow in buffer size calculation in schreibfaul1 ESP32-audioI2S 3.4.5 leads to undersized PSRAM buffer allocation. Subsequent normal audio buffer read and write operations cause heap out-of-bounds access, memory corruption, denial of service, and potential code execution. CVSSv3.1 9.8 (CRITICAL)

CWECWE 122VNDUncheckedTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-07-28
2026-07-28 15:17Z
CRIT

CVE-2026-51252 — ESP32: schreibfaul1 ESP32-audioI2S 3.4.5 has a buffer overflow vulnerability in the MP3Decoder::UnpackSFMPEG1 function due to

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-51252

schreibfaul1 ESP32-audioI2S 3.4.5 has a buffer overflow vulnerability in the MP3Decoder::UnpackSFMPEG1 function due to missing input validation on attacker-controlled MP3 metadata. CVSSv3.1 9.8 (CRITICAL)

CWECWE 120VNDEsp32TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
728 × 90 / responsive · programmatic ad slot
2026-07-28
2026-07-28 15:05Z
INFO

BloodHound CE v9.5.0

BloodHound releases·github.comCVE-2026-16221

BloodHound CE v9.5.0 released with 50+ commits including data quality improvements, API enhancements, webhook functionality, and a vulnerability fix (CVE-2026-16221). Changes span backend refactoring, UI improvements, permission controls, and OpenGraph entity support.

SWBloodhoundVNDSpecteropsTYPTool
42
Edit Score
2026-07-28
2026-07-28 13:19Z
HIGH

CVE-2026-7187 — Missing authentication for critical function vulnerability in Universal Software Inc.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-7187

Missing authentication for critical function vulnerability in Universal Software Inc. UKBS allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects UKBS: through 28072026. NOTE: The vendor was contacted and it was learned that the product is not supported. CVSSv3.1 8.8 (HIGH)

CWECWE 306TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-07-28
2026-07-28 13:19Z
HIGH

CVE-2026-62427 — CNA: [This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-62427

[This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] To manage the system, sysctl and platform operations are used by the control domain or a possible Xenstore domain. Some of these operations may not be executed in parallel, so a system-wide lock each is used. The way those locks are acquired is, however, not providing any fairness. Furthermore, with XSM/Flask in use, the lock acquire will, for som CVSSv3.1 8.8 (HIGH)

CWECWE 284CWECWE 305VNDCnaTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-07-28
2026-07-28 13:19Z
HIGH

CVE-2026-62426 — CNA: [This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-62426

[This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] To manage the system, sysctl and platform operations are used by the control domain or a possible Xenstore domain. Some of these operations may not be executed in parallel, so a system-wide lock each is used. The way those locks are acquired is, however, not providing any fairness. Furthermore, with XSM/Flask in use, the lock acquire will, for som CVSSv3.1 8.8 (HIGH)

CWECWE 667CWECWE 412VNDCnaTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-07-28
2026-07-28 13:18Z
HIGH

CVE-2026-49332 — A flaw was found in openshift/oauth-proxy.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-49332

A flaw was found in openshift/oauth-proxy. The proxy sets authenticated identity headers using only dash-variant keys (X-Forwarded-User) but does not strip underscore-variant keys (X_Forwarded_User) from incoming requests. WSGI and PHP frameworks normalize both variants to the same variable, allowing an authenticated low-privilege user to smuggle a forged identity that may override the legitimate authenticated identity in the upstream application. CVSSv3.1 8.5 (HIGH)

CWECWE 436TYPVulnerability
8.5
CVSS v3.1
93
Edit Score
2026-07-28
2026-07-28 11:56Z
HIGH

Introducing Attack Path Management for Entra Agents in BloodHound Enterprise

SpecterOps·specterops.io

SpecterOps released Attack Path Management for Entra Agents in BloodHound Enterprise, extending the attack graph to model AI agent identities, execution contexts, and trust relationships across Microsoft's agent ecosystem (Entra Agent ID, Copilot Studio, Power Automate, Azure AI Foundry). The extension identifies attack paths where low-privileged users can invoke agents that act with higher-privileged identities, public agents bridge anonymous callers to authenticated resources, and agent identity blueprints expose multiple child identities.

TACTA0004TACTA0001SRFIdentityTACTA0003SRFCloudSWBloodhoundSWEntraSWAzure Ai Foundry
78
Edit Score
2026-07-28
2026-07-28 11:50Z
INFO

Designing an MCP Server for AI Agents: Why Wrapping Your API Is the Wrong Abstraction

SpecterOps·specterops.io

SpecterOps published a technical design essay on building Model Context Protocol (MCP) servers for AI agents, using BloodHound Hunter as a case study. The post argues that MCP servers should be designed around agent intent and workflow rather than wrapping existing REST APIs, emphasizing interface design principles like reducing cognitive load and hiding implementation complexity.

SRFApplicationTACTA0007SWBloodhoundVNDSpecteropsTYPResearchTECT1087
62
Edit Score
2026-07-28
2026-07-28 11:50Z
INFO

Attack Path Management Comes to AWS

SpecterOps·specterops.io

SpecterOps announced AWS IAM attack path management capabilities in BloodHound Enterprise, extending the platform's identity graph analysis to AWS environments. The release models IAM, Organizations, STS, S3, KMS, Lambda, EC2, CloudFormation, EKS, and SSM resources to visualize privilege escalation chains, cross-account trust relationships, and lateral movement paths across AWS organizations.

TACTA0006SRFIdentitySRFCloudTACTA0008SWBloodhoundSWAwsVNDAmazonTYPTool
72
Edit Score
2026-07-28
2026-07-28 11:50Z
HIGH

Expanding attack path management to the AI frontier

SpecterOps·specterops.io

SpecterOps announced new BloodHound Enterprise features for AWS attack path management and Entra Agent ID support, enabling defenders to visualize privilege escalation and lateral movement chains across hybrid cloud, SaaS, and AI agent identities. The update models 20+ AWS resource types and 150+ relationships (IAM, Lambda, S3, KMS, cross-account trust, PassRole abuse) and introduces BloodHound Hunter, an MCP interface that connects approved AI agents to attack path findings for automated remediation prioritization.

TACTA0006SRFIdentitySRFCloudTACTA0008SWBloodhoundSWEntraSWGithubSWAws
72
Edit Score
2026-07-28
2026-07-28 11:00Z
INFO

How we use /goal to find bugs in Patch the Planet

Trail of Bits·blog.trailofbits.com

Trail of Bits describes their methodology for using Codex's /goal feature (goal-based prompting) to systematically discover bugs in widely-audited open-source projects including Rust, curl, and zlib as part of the Patch the Planet initiative. The post details three core techniques: leveraging Codex to write its own goal prompts, defining outcomes rather than prescribing paths, and assigning one outcome per agent to avoid optimization conflicts. They report finding critical vulnerabilities including a Rust soundness hole, 11 variant CVE hits via Semgrep rules, and high-severity privilege-escalation bugs in Keycloak's SAML component.

SRFApplicationTACTA0043TYPResearchTYPToolSTGDiscoveryTECT1592
72
Edit Score
2026-07-28
2026-07-28 10:16Z
CRIT

CVE-2026-16462 — PROCON: This allows a remote unauthenticated attacker to execute arbitrary SQL commands.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-16462

In PROCON-WEB SCADA the endpoint 'GetGridData' is not properly sanitized. This allows a remote unauthenticated attacker to execute arbitrary SQL commands. CVSSv3.1 9.8 (CRITICAL)

CWECWE 89VNDProconTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-07-28
2026-07-28 10:16Z
HIGH

CVE-2026-14328 — Eazy: The Eazy Plugin Manager – Powerful Plugin Management Solution for WordPress plugin for WordPress

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-14328

The Eazy Plugin Manager – Powerful Plugin Management Solution for WordPress plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 4.4.1. This is due to insufficient authorization on the `wp_ajax_pos_get_option` AJAX handler, which verifies only a nonce that is localized to every logged-in admin-area user via `admin_enqueue_scripts` — without any capability check — before returning the value of any arbitrary WordPress option via `get_ CVSSv3.1 8.8 (HIGH)

CWECWE 269VNDEazyTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-07-28
2026-07-28 10:16Z
CRIT

CVE-2026-11841 — Additionally, exposure of the custom application directory may allow execution of arbitrary Lua code

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-11841

An attacker may perform unauthenticated read and write operations on sensitive filesystem areas via the AppEngine Fileaccess over HTTP due to improper access restrictions. A critical filesystem directory was unintentionally exposed through the HTTP-based file access feature, allowing access without authentication. This includes device parameter files, enabling an attacker to read and modify application settings, including customer-defined passwords. Additionally, exposure of CVSSv3.1 9.4 (CRITICAL)

CWECWE 552TYPVulnerability
9.4
CVSS v3.1
97
Edit Score
2026-07-28
2026-07-28 09:16Z
HIGH

CVE-2026-14169 — Due to incorrect behavior order a low privileged remote attacker could trigger account inconsistent

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-14169

Due to incorrect behavior order a low privileged remote attacker could trigger account inconsistent state via crafted input and overwrites existing user passwords which could result in complete administrative unavailability of the device. CVSSv3.1 8.1 (HIGH)

CWECWE 696TYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-07-28
2026-07-28 09:16Z
HIGH

CVE-2026-14168 — A low privileged remote attacker can gain administrator privileges due to missing authorization at

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-14168

A low privileged remote attacker can gain administrator privileges due to missing authorization at the insert path of the configuration table resulting in gaining full system access. CVSSv3.1 8.8 (HIGH)

CWECWE 862TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-07-28
2026-07-28 09:16Z
HIGH

CVE-2026-14167 — A low privileged remote attacker can perform privileged configuration changes reserved for the administrator

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-14167

A low privileged remote attacker can perform privileged configuration changes reserved for the administrator level including permission management due to incorrect authorization. CVSSv3.1 8.8 (HIGH)

CWECWE 863TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-07-28
2026-07-28 08:17Z
CRIT

CVE-2026-15014 — SMS: The SMS Alert – SMS & OTP for WooCommerce, Order Notifications & Abandoned Cart

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-15014

The SMS Alert – SMS & OTP for WooCommerce, Order Notifications & Abandoned Cart Recovery plugin for WordPress is vulnerable to Authentication Bypass leading to Account Takeover in all versions up to, and including, 3.9.7 via the `billing_phone` parameter. This is due to the `processRegistration()` function using a phone-unbound `$_SESSION['sa_mobile_verified']` boolean flag as the sole gate before issuing an authentication cookie — the flag is set to `true` after any successf CVSSv3.1 9.8 (CRITICAL)

CWECWE 288VNDSmsTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-07-28
2026-07-28 08:17Z
CRIT

CVE-2026-11756 — Deserialization: A Deserialization of Untrusted Data vulnerability affecting Station Launcher App in 3DEXPERIENCE platform from

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-11756

A Deserialization of Untrusted Data vulnerability affecting Station Launcher App in 3DEXPERIENCE platform from Release 3DEXPERIENCE R2023x through Release 3DEXPERIENCE R2026x could lead to an unauthenticated remote code execution. CVSSv3.1 10.0 (CRITICAL)

CWECWE 502TYPVulnerability
10.0
CVSS v3.1
100
Edit Score