20h ago
2026-07-29 17:16Z
CRIT

CVE-2026-51992 — SQL: Injection vulnerability in ClickHouse Server Versions <= 26.3.9.8 allows a remote attacker to

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-51992

SQL Injection vulnerability in ClickHouse Server Versions <= 26.3.9.8 allows a remote attacker to execute arbitrary code via the create dictionaries function. CVSSv3.1 9.1 (CRITICAL)

CWECWE 89TYPVulnerability
9.1
CVSS v3.1
96
Edit Score
20h ago
2026-07-29 17:16Z
MED

CVE-2026-20316 — Cisco Secure_firewall_management_center: A vulnerability in the web interface of Cisco Secure Firewall Management Center (FMC) Software

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-20316in the wild

A vulnerability in the web interface of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated, remote attacker to log in to an affected device using a low-privileged account to access sensitive data within the impacted systems. This vulnerability is due to the presence of static user credentials for a low-privileged&nbsp;account. An attacker could exploit this vulnerability by using the account to log in to an affected system. A successful e CVSSv3.1 5.3 (MEDIUM)

CWECWE 259VNDCiscoTYPVulnerabilitySTAitw exploited
5.3
CVSS v3.1
77
Edit Score
21h ago
2026-07-29 16:17Z
HIGH

CVE-2026-67192 — Xlight: FTP Server before 3.9.5 contains a pre-authentication stack buffer overflow vulnerability that allows

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-67192

Xlight FTP Server before 3.9.5 contains a pre-authentication stack buffer overflow vulnerability that allows unauthenticated attackers to corrupt stack memory by sending malformed SSH packets when a GCM cipher is negotiated. Attackers can craft packets with an unvalidated length field passed directly to the GCM decrypt function, overwriting the stack cookie and return address to potentially achieve remote code execution before any authentication occurs. CVSSv3.1 8.1 (HIGH)

CWECWE 121VNDXlightTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
21h ago
2026-07-29 16:17Z
CRIT

CVE-2026-67191 — Xlight: FTP Server before 3.9.5 contains a pre-authentication heap buffer overflow vulnerability that allows

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-67191

Xlight FTP Server before 3.9.5 contains a pre-authentication heap buffer overflow vulnerability that allows remote unauthenticated attackers to write past the end of a heap buffer by sending a malformed SSH client identification string. A logic error in the recv loop's termination condition uses an incorrect OR operator where an AND operator is required, enabling exploitation on any SSH or SFTP connection before authentication occurs. CVSSv3.1 9.8 (CRITICAL)

CWECWE 122VNDXlightTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
21h ago
2026-07-29 16:17Z
CRIT

CVE-2026-60113 — AMMOS: Instrument Toolkit (AIT) Deep Space Network (DSN) Interface before 2.2.2 contains a missing

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-60113

AMMOS Instrument Toolkit (AIT) Deep Space Network (DSN) Interface before 2.2.2 contains a missing authentication vulnerability in the Space Link Extension (SLE) interface manager that allows unauthenticated network attackers to access seven unprotected API routes by sending direct HTTP requests with no credentials. Attackers can reach the exposed SLE endpoints to start or stop Deep Space Network communication sessions, retrieve telemetry frame data, and inject arbitrary frame CVSSv3.1 9.8 (CRITICAL)

CWECWE 306VNDAmmosTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
21h ago
2026-07-29 16:17Z
CRIT

CVE-2026-60112 — AMMOS: Instrument Toolkit (AIT) GUI before 2.5.1 contains a missing authentication vulnerability that allows

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-60112

AMMOS Instrument Toolkit (AIT) GUI before 2.5.1 contains a missing authentication vulnerability that allows any unauthenticated network attacker to obtain a valid session and issue arbitrary spacecraft commands by calling Sessions.create() without any credential check. Attackers can exploit the unauthenticated session issuance in Sessions.create() and subsequently invoke handle_cmd() to forward arbitrary commands directly to the AIT command bus without any authentication gate CVSSv3.1 9.8 (CRITICAL)

CWECWE 306VNDAmmosTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
21h ago
2026-07-29 16:17Z
CRIT

CVE-2026-54735 — Prebid: Prior to version 4.4.0, certain bidder adapters in Prebid Server interpolate user-supplied parameters into

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-54735

Prebid Server is an open-source solution for running real-time advertising auctions in the cloud. Prior to version 4.4.0, certain bidder adapters in Prebid Server interpolate user-supplied parameters into outbound request URLs without properly validating host and subdomain values, allowing crafted bid request parameters to cause server-side requests to unintended destinations and potentially expose internal network services or sensitive server endpoints. This issue is fixed i CVSSv3.1 10.0 (CRITICAL)

CWECWE 918VNDPrebidTYPVulnerability
10.0
CVSS v3.1
100
Edit Score
728 × 90 / responsive · programmatic ad slot
21h ago
2026-07-29 16:16Z
CRIT

CVE-2026-63077: Critical unauthenticated remote code execution in JetBrains TeamCity

Rapid7 Research·rapid7.comCVE-2026-63077

JetBrains disclosed CVE-2026-63077, a critical unauthenticated remote code execution vulnerability in TeamCity On-Premises affecting all versions. The flaw exploits deserialization of untrusted data in the agent polling protocol, allowing unauthenticated attackers to execute arbitrary OS commands with TeamCity server privileges and compromise CI/CD pipeline integrity. Fixed versions (2025.11.7, 2026.1.3) and a security patch plugin are available; TeamCity Cloud is unaffected.

SRFApplicationTACTA0001SWTeamcityVNDJetbrainsTYPVulnerabilitySTGInitial AccessTECT1190EXPRce
92
Edit Score
22h ago
2026-07-29 16:00Z
HIGH

Clustered Points of Failure

SpecterOps·specterops.io

SpecterOps researcher Garrett Foster presents novel attack techniques against Windows Server Failover Clusters (WSFC), demonstrating how cluster nodes share credentials and Kerberos keys stored in the cluster database, enabling complete cluster compromise through resource-based constrained delegation (RBCD) abuse. The research reveals that cluster Name Objects (CNO) and Virtual Cluster Objects (VCO) maintain synchronized passwords across all nodes, allowing forged Kerberos service tickets to be decrypted by any cluster member regardless of the intended target service.

SRFOsTACTA0004TACTA0008OSWindowsVNDMicrosoftTYPResearchSTGPrivescSTGInitial Access
88
Edit Score
22h ago
2026-07-29 15:48Z
INFO

v9.5.1-rc1

BloodHound releases·github.com

BloodHound v9.5.1-rc1 release candidate published with a single fix for data quality batching behind a new feature flag (BED-9078). This is a pre-release version addressing internal data handling improvements.

SWBloodhoundTYPTool
28
Edit Score
22h ago
2026-07-29 15:16Z
HIGH

CVE-2026-54666 — API: swagger-typescript-api generates API clients for Fetch or Axios from an OpenAPI Specification.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-54666

swagger-typescript-api generates API clients for Fetch or Axios from an OpenAPI Specification. Prior to 13.12.2, src/schema-routes/schema-routes.ts passes OpenAPI path keys through parseRouteName to templates/default/procedure-call.ejs and templates/modular/procedure-call.ejs without escaping JavaScript template literal interpolation, allowing an attacker-controlled path containing ${...} to execute when the generated method is called. This issue is fixed in version 13.12.2. CVSSv3.1 8.3 (HIGH)

CWECWE 94CWECWE 74CWECWE 1336VNDApiTYPVulnerability
8.3
CVSS v3.1
92
Edit Score
22h ago
2026-07-29 15:16Z
HIGH

CVE-2026-54664 — API: swagger-typescript-api generates API clients for Fetch or Axios from an OpenAPI Specification.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-54664

swagger-typescript-api generates API clients for Fetch or Axios from an OpenAPI Specification. Prior to 13.12.2, src/schema-parser/base-schema-parsers/enum.ts passes components.schemas.*.enum[i] values to Ts.StringValue in src/configuration.ts without escaping before templates/base/enum-data-contract.ejs renders TypeScript enum declarations, allowing an attacker-controlled OpenAPI spec to inject code that executes when the generated module is imported. This issue is fixed in CVSSv3.1 8.3 (HIGH)

CWECWE 94CWECWE 74CWECWE 1336VNDApiTYPVulnerability
8.3
CVSS v3.1
92
Edit Score
22h ago
2026-07-29 15:16Z
HIGH

CVE-2026-54662 — API: swagger-typescript-api generates API clients for Fetch or Axios from OpenAPI specifications.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-54662

swagger-typescript-api generates API clients for Fetch or Axios from OpenAPI specifications. Prior to 13.12.2, src/code-gen-process.ts createApiConfig copies servers[0].url into apiConfig.baseUrl, and templates/base/http-clients/fetch-http-client.ejs interpolates apiConfig.baseUrl into the generated HttpClient baseUrl field without escaping, allowing an attacker-controlled OpenAPI spec to inject TypeScript static field code that executes when the generated fetch client module CVSSv3.1 8.3 (HIGH)

CWECWE 94CWECWE 74CWECWE 1336VNDApiTYPVulnerability
8.3
CVSS v3.1
92
Edit Score
22h ago
2026-07-29 15:16Z
HIGH

CVE-2026-54661 — API: swagger-typescript-api generates API clients for Fetch or Axios from an OpenAPI Specification.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-54661

swagger-typescript-api generates API clients for Fetch or Axios from an OpenAPI Specification. Prior to 13.12.2, templates/base/http-clients/axios-http-client.ejs interpolates servers[0].url from src/code-gen-process.ts into the HttpClient constructor without escaping, allowing an attacker-controlled OpenAPI spec to inject code that executes when new HttpClient() or new Api() is constructed. This issue is fixed in version 13.12.2. CVSSv3.1 8.3 (HIGH)

CWECWE 94CWECWE 74CWECWE 1336VNDApiTYPVulnerability
8.3
CVSS v3.1
92
Edit Score
22h ago
2026-07-29 15:16Z
HIGH

CVE-2026-12703 — TeamViewer: Full Client and Host for macOS before version 15.80 contain a business logic

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-12703

TeamViewer Full Client and Host for macOS before version 15.80 contain a business logic error that can allow an authenticated attacker to bypass a configured 2FA for Connections approval flow via Unattended Access and establish a remote connection to an affected macOS host. CVSSv3.1 8.0 (HIGH)

CWECWE 288VNDTeamviewerTYPVulnerability
8.0
CVSS v3.1
90
Edit Score
1d ago
2026-07-29 12:16Z
HIGH

CVE-2026-14270 — Extra: The Extra Checkout Options (addon for Extra Product Options & Add-Ons for WooCommerce) plugin

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-14270

The Extra Checkout Options (addon for Extra Product Options & Add-Ons for WooCommerce) plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 2.3.2. This is due to missing authorization and nonce validation in the eco_save_settings() function, which allows low-privileged authenticated users to modify the tc_eco_custom_file_types upload allowlist setting, combined with insufficient authorization on the wc_eco_upload_file AJAX action. CVSSv3.1 8.8 (HIGH)

CWECWE 434VNDExtraTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
1d ago
2026-07-29 11:16Z
CRIT

CVE-2026-14900 — Cost: The Cost Calculator Builder PRO plugin for WordPress is vulnerable to Remote Code Execution

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-14900

The Cost Calculator Builder PRO plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 4.0.3 via the js_to_php function. This is due to insufficient sanitization of the orderDetails[*].originalValue field, which is injected verbatim into a calculator formula string passed to PHP eval() inside js_to_php(), with the regex allow-list in evaluateFormula() only filtering alphanumeric tokens and leaving non-word punctuation characters inta CVSSv3.1 9.8 (CRITICAL)

CWECWE 94VNDCostTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
1d ago
2026-07-29 11:16Z
CRIT

CVE-2026-14488 — Meta: The Meta Box AIO plugin for WordPress is vulnerable to Missing Authorization via the

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-14488

The Meta Box AIO plugin for WordPress is vulnerable to Missing Authorization via the template_redirect dispatcher in the MB Frontend Submission extension in versions up to, and including, 3.8.0. This is due to the handle_request() function routing the mbfs_delete action without any capability or ownership check, and the nonce verification in check_ajax() being gated behind is_ajax() which is false for template_redirect requests, making it bypassable. This makes it possible fo CVSSv3.1 9.1 (CRITICAL)

CWECWE 862VNDMetaTYPVulnerability
9.1
CVSS v3.1
96
Edit Score
1d ago
2026-07-29 11:00Z
HIGH

Exploiting Titan Quest

Synacktiv·synacktiv.com

Synacktiv published a detailed technical writeup of heap overflow vulnerabilities discovered in Titan Quest Anniversary Edition (v2.10.21415), exploitable through malicious custom map files (.lvl/.map). The vulnerabilities stem from integer overflow in buffer allocation and unchecked array copies in the ImpassableData and EmitterData deserialization methods. The authors demonstrate a complete exploitation chain bypassing ASLR and heap mitigations on Windows 11 32-bit, achieving code execution via ROP and shellcode injection.

SRFApplicationTACTA0002SWTitan QuestVNDThq NordicTYPResearchSTGExecutionTECT1190EXPHeap Overflow
76
Edit Score
1d ago
2026-07-29 10:16Z
CRIT

CVE-2026-59243 — FAB: The FAB auth manager's Azure AD OAuth login defaulted `verify_signature=False` when decoding the ID

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-59243

The FAB auth manager's Azure AD OAuth login defaulted `verify_signature=False` when decoding the ID token, so an attacker able to present a forged or unsigned (`alg:none`) ID token to the OAuth callback could bypass authentication and log in as an arbitrary user, including one holding the Admin role (CWE-347). Deployments running the FAB auth manager with the Azure AD OAuth login path under its default configuration are affected; the Authentik path already defaulted to `True` CVSSv3.1 9.8 (CRITICAL)

CWECWE 347VNDFabTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
1d ago
2026-07-29 10:16Z
HIGH

CVE-2026-58188 — Apache: Several Apache Traffic Server experimental plugins have memory-safety and limit-bypass errors.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-58188

Several Apache Traffic Server experimental plugins have memory-safety and limit-bypass errors. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the issue. CVSSv3.1 8.2 (HIGH)

CWECWE 787VNDApacheTYPVulnerability
8.2
CVSS v3.1
91
Edit Score
1d ago
2026-07-29 10:16Z
HIGH

CVE-2026-58184 — Apache: The Apache Traffic Server header_rewrite plugin can crash or corrupt memory during cookie operations

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-58184

The Apache Traffic Server header_rewrite plugin can crash or corrupt memory during cookie operations and CIDR condition matching. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the issue. CVSSv3.1 8.2 (HIGH)

CWECWE 787VNDApacheTYPVulnerability
8.2
CVSS v3.1
91
Edit Score
1d ago
2026-07-29 10:16Z
HIGH

CVE-2026-58182 — Apache: The Apache Traffic Server ts_lua plugin mishandles initialization, transform context, and per-instance state.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-58182

The Apache Traffic Server ts_lua plugin mishandles initialization, transform context, and per-instance state. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the issue. CVSSv3.1 8.6 (HIGH)

CWECWE 400VNDApacheTYPVulnerability
8.6
CVSS v3.1
93
Edit Score
1d ago
2026-07-29 10:16Z
HIGH

CVE-2026-58179 — Apache: The Apache Traffic Server regex_remap plugin overflows the stack and integers from substitution input.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-58179

The Apache Traffic Server regex_remap plugin overflows the stack and integers from substitution input. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the issue. CVSSv3.1 8.1 (HIGH)

CWECWE 121VNDApacheTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
1d ago
2026-07-29 10:16Z
HIGH

CVE-2026-58177 — Apache: The Apache Traffic Server Cripts framework has out-of-bounds writes, path traversal, and use-after-free errors.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-58177

The Apache Traffic Server Cripts framework has out-of-bounds writes, path traversal, and use-after-free errors. This issue affects Apache Traffic Server: from 10.0.0 through 10.1.3. Users are recommended to upgrade to version 10.1.4, which fix the issue. CVSSv3.1 8.1 (HIGH)

CWECWE 787VNDApacheTYPVulnerability
8.1
CVSS v3.1
91
Edit Score