2026-07-18
2026-07-18 09:17Z
HIGH

CVE-2026-47867 — VMware: Avi Load Balancer contains a remote code execution vulnerability.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-47867

VMware Avi Load Balancer contains a remote code execution vulnerability. A malicious user with network access may be able to access the Avi Control plane and execute code remotely. Affected versions: 32.1.1 (fixed in 32.1.2) 31.1.1 through 31.2.2 (fixed in 31.2.2-2p3) 30.1.1 through 30.2.6 (fixed in 30.2.7) 22.1.1 through 22.1.7 (fixed in 30.2.7) CVSSv3.1 8.7 (HIGH)

CWECWE 94VNDVmwareTYPVulnerability
8.7
CVSS v3.1
94
Edit Score
2026-07-18
2026-07-18 09:17Z
HIGH

CVE-2026-47866 — VMware: Avi Load Balancer contains an authorization bypass vulnerability.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-47866

VMware Avi Load Balancer contains an authorization bypass vulnerability. A malicious actor on the network can access a limited subset of the Avi Control Plane without proper authorization. Affected versions: 32.1.1 (fixed in 32.1.2) 31.1.1 through 31.2.2 (fixed in 31.2.2-2p3) 30.1.1 through 30.2.6 (fixed in 30.2.7) 22.1.1 through 22.1.7 (fixed in 30.2.7) CVSSv3.1 8.3 (HIGH)

CWECWE 863VNDVmwareTYPVulnerability
8.3
CVSS v3.1
92
Edit Score
2026-07-18
2026-07-18 09:17Z
CRIT

CVE-2026-47865 — VMware: Avi Load Balancer contains an authentication bypass vulnerability.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-47865

VMware Avi Load Balancer contains an authentication bypass vulnerability. A malicious user with network access may be able to access the Avi Control plane by bypassing the authentication mechanism. Affected versions: 31.1.1 through 31.2.2 (fixed in 31.2.2-2p3) 30.1.1 through 30.2.6 (fixed in 30.2.7) 22.1.1 through 22.1.7 (fixed in 30.2.7) CVSSv3.1 9.8 (CRITICAL)

CWECWE 287VNDVmwareTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-07-18
2026-07-18 00:00Z
CRIT

New North Korean campaign uses fake coding interviews to steal developer credentials

Elastic Security Labs·elastic.coin the wild

Elastic Security Labs discovered a new DPRK-aligned campaign (REF9403) using fake coding interview challenges to distribute OTTERCOOKIE malware hidden via steganography in SVG flag images. The trojanized repositories contain a four-stage payload delivering browser credential/crypto wallet theft, file exfiltration, Socket.IO-based RAT, and clipboard stealing, with zero antivirus detections at time of discovery. The campaign specifically targets developers as initial access vectors for supply-chain compromise.

SRFApplicationTACTA0004TACTA0005TACTA0001TACTA0002TACTA0006TACTA0007TACTA0003
92
Edit Score
2026-07-18
2026-07-18 00:00Z
CRIT

New North Korean campaign uses fake coding interviews to steal developer credentials

Elastic Security Labs·elastic.coin the wild

Elastic Security Labs discovered a new North Korean Contagious Interview campaign (REF9403) targeting developers with fake job postings and trojanized coding challenges. The malware uses SVG steganography to hide a four-stage OTTERCOOKIE payload (browser/wallet stealer, file stealer, Socket.IO RAT, clipboard stealer) and achieved zero antivirus detections across seven samples. The campaign demonstrates sophisticated supply-chain attack methodology with direct targeting of developer credentials and cryptocurrency wallets.

SRFApplicationTACTA0005TACTA0001TACTA0002TACTA0006TACTA0007TACTA0003TACTA0009
92
Edit Score
2026-07-17
2026-07-17 22:23Z
CRIT

CVE-2026-63030: wp2shell a Critical Remote Code Execution Vulnerability in WordPress Core

Rapid7 Research·rapid7.comCVE-2026-63030

CVE-2026-63030 is a critical unauthenticated remote code execution vulnerability in WordPress Core affecting versions 6.9.0–6.9.4 and 7.0.0–7.0.1, exploitable via the REST API batch endpoint without authentication or user interaction. The vulnerability is fixed in WordPress 6.9.5, 7.0.2, and 7.1 Beta 2. Rapid7 assesses that public PoC code is likely imminent given the open-source nature of WordPress and AI code analysis capabilities.

SRFApplicationTACTA0001SRFWebSWWordpressVNDWordpressTYPVulnerabilitySTGExecutionSTGInitial Access
82
Edit Score
2026-07-17
2026-07-17 21:17Z
CRIT

CVE-2026-55518 — Avo: An authenticated low-privileged Avo user can bypass hidden or disabled attach controls and directly

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-55518

Avo is a framework to create admin panels for Ruby on Rails apps. Prior to 3.32.1 and 4.0.0.beta.51, Avo's association attach workflow checks attach_<association>? in the UI and GET /resources/:resource/:id/:related/new path, but the actual write endpoint, POST /resources/:resource/:id/:related, does not run the same authorization check before mutating the association through Avo::AssociationsController#create. An authenticated low-privileged Avo user can bypass hidden or dis CVSSv3.1 9.6 (CRITICAL)

CWECWE 862CWECWE 639CWECWE 863VNDAvoTYPVulnerability
9.6
CVSS v3.1
98
Edit Score
728 × 90 / responsive · programmatic ad slot
2026-07-17
2026-07-17 21:17Z
HIGH

CVE-2026-54498 — From 4.0.0 until 4.12.0, ViewComponent::Base#around_render can return HTML-unsafe strings that bypass the escaping behavior

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-54498

view_component is a framework for building reusable, testable, and encapsulated view components in Ruby on Rails. From 4.0.0 until 4.12.0, ViewComponent::Base#around_render can return HTML-unsafe strings that bypass the escaping behavior applied to normal #call return values. This creates an XSS risk when downstream applications use around_render to wrap, replace, instrument, or conditionally return content that includes user-controlled data, and ViewComponent::Collection#ren CVSSv3.1 8.7 (HIGH)

CWECWE 79TYPVulnerability
8.7
CVSS v3.1
94
Edit Score
2026-07-17
2026-07-17 21:17Z
CRIT

CVE-2026-54159 — PrestaShop: ps_facetedsearch is a module that adds layered navigation filters.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-54159

PrestaShop ps_facetedsearch is a module that adds layered navigation filters. From 3.0.0 until 4.0.4, the ps_facetedsearch module rebuilds selected search filters from the request URL, and the value of a slider filter, price or weight, is taken from the URL without sufficient validation and stored in an internal filter-block cache where it is serialized and later read back with a raw native unserialize() in src/Filters/Block.php. By crafting that value, an unauthenticated att CVSSv3.1 10.0 (CRITICAL)

CWECWE 74VNDPrestashopTYPVulnerability
10.0
CVSS v3.1
100
Edit Score
2026-07-17
2026-07-17 21:17Z
CRIT

CVE-2026-52348 — cool-admin-java 8.0.0 has a SQL injection vulnerability in the order() method of CrudOption.java.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-52348

cool-admin-java 8.0.0 has a SQL injection vulnerability in the order() method of CrudOption.java. CVSSv3.1 9.8 (CRITICAL) · EPSS 4th percentile

CWECWE 89TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-07-17
2026-07-17 21:17Z
CRIT

CVE-2026-48062 — CodeIgniter: Applications are impacted if they accept user-controlled uploads, rely on ext_in to validate the

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-48062

CodeIgniter is a PHP full-stack web framework. Prior to 4.7.3, the ext_in upload validation rule in system/Validation/StrictRules/FileRules.php checked the MIME-derived guessed extension instead of the client-provided filename extension. As a result, an uploaded file named shell.php containing GIF-like content could pass validation such as uploaded[avatar]|is_image[avatar]|mime_in[avatar,image/gif]|ext_in[avatar,gif] because the detected MIME type maps to gif, even though the CVSSv3.1 9.8 (CRITICAL)

CWECWE 434VNDCodeigniterTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-07-17
2026-07-17 21:17Z
CRIT

CVE-2026-13446 — IBM: Langflow OSS 1.0.0 through 1.10.1 contains hard-coded credentials, such as a password or

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-13446

IBM Langflow OSS 1.0.0 through 1.10.1 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to external components, or encryption of internal data. CVSSv3.1 9.8 (CRITICAL)

CWECWE 798VNDIbmTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-07-17
2026-07-17 21:17Z
HIGH

CVE-2026-13445 — IBM: Langflow OSS 1.0.0 through 1.10.1 can allow an authenticated attacker to exploit the

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-13445

IBM Langflow OSS 1.0.0 through 1.10.1 can allow an authenticated attacker to exploit the SaveToFile component to read and modify another user's uploaded files by specifying absolute paths pointing to victim storage locations. In append mode, the attacker's workflow reads victim file contents, appends attacker-controlled data, and uploads a copy containing victim data to the attacker's namespace (confidentiality breach). In overwrite mode, the attacker can replace victim file CVSSv3.1 8.1 (HIGH)

CWECWE 639VNDIbmTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-07-17
2026-07-17 20:25Z
CRIT

CVE-2026-15409 / CVE-2026-15410 | SonicWall SMA1000 Server-Side Request Forgery and Code Injection Vulnerabilities

Horizon3.ai·horizon3.aiCVE-2026-15409CVE-2026-15410in the wild

SonicWall SMA1000 appliances are affected by two actively exploited vulnerabilities: CVE-2026-15409 (CVSS 10.0), a pre-authentication SSRF in the Workplace interface, and CVE-2026-15410 (CVSS 7.2), a post-authentication code injection in the Management Console. Attackers chain these vulnerabilities to achieve unauthenticated RCE and full device compromise. SonicWall released patches on July 14, 2026, and CISA added both to its Known Exploited Vulnerabilities Catalog with a federal remediation deadline of July 17, 2026.

TACTA0001TACTA0002SRFNetwork ApplianceSWSonicwall Sma1000VNDSonicwallTYPVulnerabilityTYPAdvisorySTGExecution
92
Edit Score
2026-07-17
2026-07-17 20:17Z
CRIT

CVE-2026-8859 — IBM: Langflow OSS 1.0.0 through 1.10.0 Langflow could allow an attacker to write arbitrary

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-8859

IBM Langflow OSS 1.0.0 through 1.10.0 Langflow could allow an attacker to write arbitrary files to unintended locations due to improper input validation in the APIRequest component. A path traversal vulnerability exists when the "Save to File" feature is enabled, where filenames extracted from HTTP response Content-Disposition headers are not sanitized before being joined to the temporary directory path. An attacker controlling an external HTTP server can supply crafted filen CVSSv3.1 9.9 (CRITICAL)

CWECWE 22VNDIbmTYPVulnerability
9.9
CVSS v3.1
100
Edit Score
2026-07-17
2026-07-17 20:17Z
CRIT

CVE-2026-8635 — IBM: Langflow OSS 1.0.0 through 1.10.0 allows authenticated users to escalate privileges to superuser

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-8635

IBM Langflow OSS 1.0.0 through 1.10.0 allows authenticated users to escalate privileges to superuser by directly manipulating the database, execute arbitrary system commands, and achieve full system compromise with Langflow service permissions. CVSSv3.1 9.9 (CRITICAL)

CWECWE 94VNDIbmTYPVulnerability
9.9
CVSS v3.1
100
Edit Score
2026-07-17
2026-07-17 20:17Z
CRIT

CVE-2026-8505 — IBM: Langflow OSS 1.0.0 through 1.10.0 has a vulnerability in Langflow's webhook authentication logic

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-8505

IBM Langflow OSS 1.0.0 through 1.10.0 has a vulnerability in Langflow's webhook authentication logic allows unauthenticated users to trigger the execution of any flow. The system incorrectly bypasses API key validation when the WEBHOOK_AUTH_ENABLE configuration is set to False (which is the default setting). This allows a remote attacker who knows a flow's UUID to execute it as if they were the owner, potentially leading to Remote Code Execution (RCE). CVSSv3.1 9.8 (CRITICAL)

VNDIbmTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-07-17
2026-07-17 20:17Z
CRIT

CVE-2026-8481 — IBM: Langflow OSS 1.0.0 through 1.10.0 contain a critical remote code execution vulnerability in

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-8481

IBM Langflow OSS 1.0.0 through 1.10.0 contain a critical remote code execution vulnerability in the code validation API endpoint. The POST /api/v1/validate/code endpoint accepts user-supplied Python code and executes it directly using Python's built-in exec() function without sandboxing, input validation, or privilege restrictions, enabling any authenticated user to execute arbitrary system commands with the full privileges of the Langflow server process. CVSSv3.1 9.9 (CRITICAL)

CWECWE 94VNDIbmTYPVulnerability
9.9
CVSS v3.1
100
Edit Score
2026-07-17
2026-07-17 20:17Z
CRIT

CVE-2026-8476 — IBM: Langflow OSS 1.0.0 through 1.10.0 contain a critical remote code execution vulnerability in

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-8476

IBM Langflow OSS 1.0.0 through 1.10.0 contain a critical remote code execution vulnerability in the disk-based caching mechanism. The AsyncDiskCache class uses Python's unsafe pickle.loads() function to deserialize cached objects from disk without validation, integrity verification, or authentication, enabling arbitrary code execution when malicious pickle payloads are processed. Attackers who can influence cached data through file system access, malicious workflow inputs, cu CVSSv3.1 9.9 (CRITICAL)

CWECWE 502VNDIbmTYPVulnerability
9.9
CVSS v3.1
100
Edit Score
2026-07-17
2026-07-17 20:17Z
HIGH

CVE-2026-8056 — IBM: Langflow OSS 1.0.0 through 1.10.0 allows authenticated users to override component parameters at

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-8056

IBM Langflow OSS 1.0.0 through 1.10.0 allows authenticated users to override component parameters at runtime via the API. A critical security flaw exists in the parameter filtering mechanism within the `apply_tweaks()` function. CVSSv3.1 8.8 (HIGH)

CWECWE 94VNDIbmTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-07-17
2026-07-17 20:17Z
HIGH

CVE-2026-7755 — IBM: Langflow OSS 1.0.0 through 1.10.0 Langflow could allow remote code execution due to

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-7755

IBM Langflow OSS 1.0.0 through 1.10.0 Langflow could allow remote code execution due to incomplete validation enforcement on MCP server configuration files. CVSSv3.1 8.8 (HIGH)

VNDIbmTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-07-17
2026-07-17 20:17Z
HIGH

CVE-2026-7667 — IBM: Langflow OSS 1.0.0 through 1.10.0 allows an authenticated attacker to create a malicious

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-7667

IBM Langflow OSS 1.0.0 through 1.10.0 allows an authenticated attacker to create a malicious flow pointing to an attacker-controlled URL that returns a specially crafted Content-Disposition header (e.g., filename="../../../target/path" ), enabling arbitrary file write operations with attacker-controlled content to any path accessible by the Langflow process. CVSSv3.1 8.8 (HIGH)

CWECWE 22VNDIbmTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-07-17
2026-07-17 20:17Z
CRIT

CVE-2026-63030 — WordPress: 6.9.x before 6.9.5 and 7.0.x before 7.0.2 is affected by a REST API

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-63030

WordPress 6.9.x before 6.9.5 and 7.0.x before 7.0.2 is affected by a REST API batch endpoint route confusion issue which, combined with the author__not_in WP_Query SQL Injection (CVE-2026-60137), could allow an attacker to perform SQL Injection and achieve Remote Code Execution. CVSSv3.1 9.8 (CRITICAL)

CWECWE 436VNDWordpressTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-07-17
2026-07-17 20:17Z
CRIT

CVE-2026-60137 — WordPress: 6.8.x before 6.8.6, 6.9.x before 6.9.5, and 7.0.x before 7.0.2 does not properly

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-60137

WordPress 6.8.x before 6.8.6, 6.9.x before 6.9.5, and 7.0.x before 7.0.2 does not properly sanitise the author__not_in parameter of WP_Query, which could allow SQL Injection when a plugin or theme passes untrusted input to the parameter. CVSSv3.1 9.1 (CRITICAL)

CWECWE 89VNDWordpressTYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2026-07-17
2026-07-17 20:17Z
CRIT

CVE-2026-52199 — Generic: An issue in Generic OEM UZ801_v2.1 4G LTE Router V3.4.3 allows a remote attacker

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-52199

An issue in Generic OEM UZ801_v2.1 4G LTE Router V3.4.3 allows a remote attacker to execute arbitrary code via the sbin/adbd component CVSSv3.1 9.1 (CRITICAL) · EPSS 27th percentile

CWECWE 94CWECWE 77VNDGenericTYPVulnerability
9.1
CVSS v3.1
96
Edit Score