2026-07-21
2026-07-21 18:16Z
CRIT

CVE-2026-16439 — Eclipse Openj9: In Eclipse OpenJ9 versions up to 0.60, using -Xtrace to trace method arguments can

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-16439

In Eclipse OpenJ9 versions up to 0.60, using -Xtrace to trace method arguments can lead to buffer underflow. CVSSv3.1 9.1 (CRITICAL) · EPSS 11th percentile

CWECWE 124VNDEclipseTYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2026-07-21
2026-07-21 17:47Z
HIGH

Why Exposure Management Is Replacing Vulnerability Management

Horizon3.ai·horizon3.ai

Horizon3.ai argues that traditional vulnerability management—focused on identifying and patching individual CVEs—is insufficient for modern threat landscapes. The article advocates for Exposure Management and Gartner's CTEM framework, which evaluate how weaknesses chain together across identities, permissions, and systems to create exploitable attack paths rather than treating vulnerabilities in isolation.

SRFApplicationTACTA0004TACTA0005TACTA0001SRFIdentityTACTA0003SRFCloudTYPResearch
62
Edit Score
2026-07-21
2026-07-21 17:17Z
CRIT

CVE-2026-47410 — PraisonAI: Versions prior to 0.1.4 have an insecure default cryptographic key.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-47410

PraisonAI Platform is the platform layer for the PraisonAI multi-agent teams system. Versions prior to 0.1.4 have an insecure default cryptographic key. The JWT signing secret defaults to the hardcoded literal `"dev-secret-change-me"` when `PLATFORM_JWT_SECRET` is unset. A safety check exists but only fires when `PLATFORM_ENV != "dev"`; the default value of `PLATFORM_ENV` is `"dev"`, so the check is silently bypassed in any deployment that does not explicitly opt out. The att CVSSv3.1 9.8 (CRITICAL)

CWECWE 798CWECWE 321VNDPraisonaiTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-07-21
2026-07-21 17:17Z
HIGH

CVE-2026-47409 — PraisonAI: Versions prior to 0.1.4 have an authorization bypass enabling owner lockout.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-47409

PraisonAI Platform is the platform layer for the PraisonAI multi-agent teams system. Versions prior to 0.1.4 have an authorization bypass enabling owner lockout. The `DELETE /workspaces/{workspace_id}/members/{user_id}` endpoint is gated only by `require_workspace_member(workspace_id)` (default `min_role="member"`). Any member can remove any other member, including the workspace owner, using a single DELETE. There is no caller-role check, no target-role check, no "cannot remo CVSSv3.1 8.1 (HIGH)

CWECWE 862CWECWE 269VNDPraisonaiTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-07-21
2026-07-21 17:17Z
HIGH

CVE-2026-47406 — PraisonAI: Versions prior to 0.1.4 have an Insecure Direct Object Reference.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-47406

PraisonAI Platform is the platform layer for the PraisonAI multi-agent teams system. Versions prior to 0.1.4 have an Insecure Direct Object Reference. The dependency endpoints (`POST/GET /workspaces/{workspace_id}/issues/{issue_id}/dependencies` and `DELETE .../dependencies/{dep_id}`) gate access on `require_workspace_member(workspace_id)` only, then dispatch to `DependencyService` calls that take URL/body-supplied issue and dependency IDs without verifying any of them belong CVSSv3.1 8.1 (HIGH)

CWECWE 639VNDPraisonaiTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-07-21
2026-07-21 17:17Z
HIGH

CVE-2026-47405 — PraisonAI: Versions prior to 0.1.4 have a broken workspace authorization check that allows any authenticated

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-47405

PraisonAI Platform is the platform layer for the PraisonAI multi-agent teams system. Versions prior to 0.1.4 have a broken workspace authorization check that allows any authenticated low-privilege workspace member to escalate their own role to `owner`. The issue is caused by privileged workspace-management routes using the shared dependency `require_workspace_member(...)` without requiring `admin` or `owner`. The dependency defaults to `min_role="member"`, so routes that shou CVSSv3.1 8.8 (HIGH)

CWECWE 862CWECWE 284VNDPraisonaiTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-07-21
2026-07-21 17:17Z
HIGH

CVE-2026-47399 — PraisonAI: Prior to version 0.1.4, the workspace-scoped REST routes contain a systemic object-level authorization flaw

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-47399

PraisonAI Platform is the platform layer for the PraisonAI multi-agent teams system. Prior to version 0.1.4, the workspace-scoped REST routes contain a systemic object-level authorization flaw that allows an authenticated user from one workspace to access, modify, and delete objects belonging to another workspace by supplying the victim object's global UUID. The affected pattern appears in workspace-scoped routes such as agents, projects, issues, and comments. The route layer CVSSv3.1 8.8 (HIGH)

CWECWE 639CWECWE 284VNDPraisonaiTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
728 × 90 / responsive · programmatic ad slot
2026-07-21
2026-07-21 17:17Z
HIGH

CVE-2026-47398 — PraisonAI: The v4.6.32 chokepoint refactor (which patched CVE-2026-44334 / GHSA-xcmw-grxf-wjhj) added the PRAISONAI_ALLOW_LOCAL_TOOLS env-var gate

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-47398

PraisonAI is a multi-agent teams system. The v4.6.32 chokepoint refactor (which patched CVE-2026-44334 / GHSA-xcmw-grxf-wjhj) added the PRAISONAI_ALLOW_LOCAL_TOOLS env-var gate to the tool_override.py sinks. However, two additional spec.loader.exec_module call sites in praisonai/agents_generator.py were missed and remain completely unguarded in versions prior to 4.6.40. Both functions accept a module_path parameter sourced from YAML configuration and execute it without valida CVSSv3.1 8.1 (HIGH)

CWECWE 94CWECWE 829VNDPraisonaiTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-07-21
2026-07-21 17:17Z
HIGH

CVE-2026-15829 — Google Mcp_toolbox_for_databases: A SQL injection (CWE-89) and security boundary bypass (CWE-863) vulnerability exists in the prebuilt

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-15829

A SQL injection (CWE-89) and security boundary bypass (CWE-863) vulnerability exists in the prebuilt BigQuery forecasting tool (bigquery-forecast) of googleapis/mcp-toolbox. The tool accepts client-controlled parameters (data_col, timestamp_col, and id_cols) as plain strings and interpolates them unescaped via fmt.Sprintf directly into a generated AI.FORECAST table-valued SELECT statement. While MCP Toolbox utilizes an allowedDatasets mechanism to restrict queries, this defe CVSSv3.1 8.1 (HIGH) · EPSS 9th percentile

CWECWE 89CWECWE 863VNDGoogleTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-07-21
2026-07-21 17:17Z
HIGH

CVE-2026-15724 — Progress: In Progress ShareFile Storage Zones Controller versions prior to 5.12.5 and 6.0.2, an authenticated

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-15724

In Progress ShareFile Storage Zones Controller versions prior to 5.12.5 and 6.0.2, an authenticated administrative user can exploit a path traversal vulnerability to read arbitrary files from the server filesystem, write files to arbitrary directories, or determine whether specific files exist on the server. CVSSv3.1 8.7 (HIGH)

CWECWE 22CWECWE 73CWECWE 20VNDProgressTYPVulnerability
8.7
CVSS v3.1
94
Edit Score
2026-07-21
2026-07-21 16:17Z
CRIT

CVE-2026-64825 — Home: Assistant Core before 2026.6.0 contains a path traversal vulnerability that allows unauthenticated attackers

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-64825

Home Assistant Core before 2026.6.0 contains a path traversal vulnerability that allows unauthenticated attackers to write arbitrary files to any directory on the host filesystem by uploading a crafted backup archive during the initial onboarding window. Attackers can manipulate the 'name' field inside the uploaded archive's backup.json to supply an absolute path, causing pathlib.Path.__truediv__ to discard the configured backup directory prefix and write attacker-controlled CVSSv3.1 9.3 (CRITICAL)

CWECWE 22VNDHomeTYPVulnerability
9.3
CVSS v3.1
97
Edit Score
2026-07-21
2026-07-21 16:17Z
HIGH

CVE-2026-64824 — Home: Assistant Core before 2026.6.0 contains a path traversal vulnerability in the backup-restore function

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-64824

Home Assistant Core before 2026.6.0 contains a path traversal vulnerability in the backup-restore function that allows attackers to write files to arbitrary absolute filesystem paths by supplying a crafted tar archive with a SYMTYPE entry containing a benign member name paired with an absolute linkname pointing outside the extraction directory. Because the official Docker image runs the Home Assistant process as root and the subsequent regular-file entry is written through th CVSSv3.1 8.4 (HIGH)

CWECWE 22VNDHomeTYPVulnerability
8.4
CVSS v3.1
92
Edit Score
2026-07-21
2026-07-21 16:17Z
CRIT

CVE-2026-47396 — PraisonAI: Since every sensitive agent-control endpoint depends on this helper, starting the call server without

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-47396

PraisonAI is a multi-agent teams system. Prior to version 4.6.40, PraisonAI's call server exposes a network-facing agent control API without authentication when `CALL_SERVER_TOKEN` is not configured. The affected component is the `praisonai.api.agent_invoke` router as mounted by `praisonai.api.call`. The authentication helper `verify_token()` fails open when `CALL_SERVER_TOKEN` is unset. Since every sensitive agent-control endpoint depends on this helper, starting the call se CVSSv3.1 9.8 (CRITICAL)

CWECWE 306CWECWE 284VNDPraisonaiTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-07-21
2026-07-21 16:17Z
CRIT

CVE-2026-47393 — PraisonAI: CVE-2026-44338 (GHSA-6rmh-7xcm-cpxj) documents that PraisonAI ships a code-generator (`praisonai.deploy.api.generate_api_server_code`) that emits a Flask API

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-47393

PraisonAI is a multi-agent teams system. CVE-2026-44338 (GHSA-6rmh-7xcm-cpxj) documents that PraisonAI ships a code-generator (`praisonai.deploy.api.generate_api_server_code`) that emits a Flask API server with authentication disabled by default. Users who follow the documented quickstart (`praisonai deploy --type api`) get a server that binds to `0.0.0.0` per the recommended sample YAML, exposes `/chat` and `/agents` endpoints, runs `praisonai.run()` on user-supplied JSON in CVSSv3.1 9.8 (CRITICAL)

CWECWE 306CWECWE 1188VNDPraisonaiTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-07-21
2026-07-21 16:17Z
CRIT

CVE-2026-47392 — PraisonAI: This is a novel bypass that survives all patches for CVE-2026-39888 (frame traversal), CVE-2026-34938

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-47392

PraisonAI is a multi-agent teams system. Prior to version 4.6.40 of PraisonAI, corresponding to version 1.6.40 of praisonaiagents, `execute_code()` in `praisonaiagents/tools/python_tools.py` (v1.6.37, subprocess sandbox mode) can be fully bypassed using `print.__self__` to retrieve the real Python `builtins` module, from which `__import__` can be extracted via `vars()` and runtime string construction. This achieves arbitrary OS command execution on the host, completely defeat CVSSv3.1 9.9 (CRITICAL)

CWECWE 693CWECWE 184VNDPraisonaiTYPVulnerability
9.9
CVSS v3.1
100
Edit Score
2026-07-21
2026-07-21 16:17Z
CRIT

CVE-2026-47391 — PraisonAI: Prior to version 4.6.40, PraisonAI's first-party A2A server example exposes an unauthenticated A2A JSON-RPC

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-47391

PraisonAI is a multi-agent teams system. Prior to version 4.6.40, PraisonAI's first-party A2A server example exposes an unauthenticated A2A JSON-RPC endpoint and registers a `calculate(expression)` tool implemented with Python `eval()`. The example also binds to `0.0.0.0`. A remote unauthenticated attacker can send `message/send` to `/a2a`; the request reaches `agent.chat()`, and a real LLM can invoke the registered `calculate` tool. In testing with `gemini/gemini-2.5-flash-l CVSSv3.1 9.8 (CRITICAL)

CWECWE 306CWECWE 95VNDPraisonaiTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-07-21
2026-07-21 16:17Z
CRIT

CVE-2026-28321 — SolarWinds: Serv-U is affected by a broken access control vulnerability that could allow arbitrary

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-28321

SolarWinds Serv-U is affected by a broken access control vulnerability that could allow arbitrary file read and write, which can then be used to escalate privileges and execute code as root. A domain administrator access is required, and the impact is lower in Windows installations. CVSSv3.1 9.1 (CRITICAL)

CWECWE 284VNDSolarwindsTYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2026-07-21
2026-07-21 16:17Z
CRIT

CVE-2026-28317 — SolarWinds: Serv-U is affected by an insecure direct object reference (IDOR) vulnerability that can

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-28317

SolarWinds Serv-U is affected by an insecure direct object reference (IDOR) vulnerability that can lead to privilege escalation. This issue requires domain administrator access. The impact is lower in Windows deployments. CVSSv3.1 9.1 (CRITICAL)

CWECWE 639VNDSolarwindsTYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2026-07-21
2026-07-21 16:17Z
CRIT

CVE-2026-28316 — SolarWinds: Serv-U is affected by an insecure direct object reference (IDOR) vulnerability that can

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-28316

SolarWinds Serv-U is affected by an insecure direct object reference (IDOR) vulnerability that can lead to privilege escalation to a system administrator with the ability to execute commands as the root user. This issue requires a domain account with administrator access. The impact is lower in Windows deployments. CVSSv3.1 9.1 (CRITICAL)

CWECWE 639VNDSolarwindsTYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2026-07-21
2026-07-21 16:17Z
CRIT

CVE-2026-28314 — SolarWinds: Serv-U is affected by an insecure direct object reference vulnerability that leads to

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-28314

SolarWinds Serv-U is affected by an insecure direct object reference vulnerability that leads to an account takeover. User authentication is required. The impact is lower in Windows deployments. CVSSv3.1 9.1 (CRITICAL)

CWECWE 639VNDSolarwindsTYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2026-07-21
2026-07-21 16:17Z
CRIT

CVE-2026-28313 — SolarWinds: Serv-U is affected by an insecure direct object reference (IDOR) vulnerability that can

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-28313

SolarWinds Serv-U is affected by an insecure direct object reference (IDOR) vulnerability that can lead to SMTP hijacking leading to arbitrary account takeover. The impact is lower in Windows deployments. CVSSv3.1 9.1 (CRITICAL)

CWECWE 639VNDSolarwindsTYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2026-07-21
2026-07-21 16:17Z
CRIT

CVE-2026-28312 — SolarWinds: Serv-U is affected by a privilege escalation vulnerability.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-28312

SolarWinds Serv-U is affected by a privilege escalation vulnerability. This would elevate a group’s access to system administrator and allow code execution as root. The impact is lower in Windows deployments. CVSSv3.1 9.1 (CRITICAL)

CWECWE 285VNDSolarwindsTYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2026-07-21
2026-07-21 16:17Z
CRIT

CVE-2026-28310 — SolarWinds: Serv-U is affected by a privilege escalation vulnerability that allows a domain administrator

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-28310

SolarWinds Serv-U is affected by a privilege escalation vulnerability that allows a domain administrator to escalate their user type to that of a system administrator. The impact is lower in Windows deployments. CVSSv3.1 9.1 (CRITICAL)

CWECWE 862VNDSolarwindsTYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2026-07-21
2026-07-21 16:17Z
CRIT

CVE-2026-28309 — SolarWinds: Serv-U is affected by a broken access control vulnerability that allows a domain

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-28309

SolarWinds Serv-U is affected by a broken access control vulnerability that allows a domain administrator to create system administrator accounts. The impact is lower in Windows deployments. CVSSv3.1 9.1 (CRITICAL)

CWECWE 862VNDSolarwindsTYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2026-07-21
2026-07-21 16:17Z
CRIT

CVE-2026-28308 — SolarWinds: Serv-U is affected by an insecure direct object reference (IDOR) vulnerability that can

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-28308

SolarWinds Serv-U is affected by an insecure direct object reference (IDOR) vulnerability that can lead to remote code execution. Domain administrator access is required. The impact is lower in Windows deployments. CVSSv3.1 9.1 (CRITICAL)

CWECWE 639VNDSolarwindsTYPVulnerability
9.1
CVSS v3.1
96
Edit Score