2026-07-17
2026-07-17 20:17Z
HIGH

CVE-2026-50289 — Systeminformation Systeminformation: Prior to 5.31.7, networkInterfaces() on Linux is vulnerable to OS command injection through the

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-50289

systeminformation is a System and OS information library for node.js. Prior to 5.31.7, networkInterfaces() on Linux is vulnerable to OS command injection through the Debian/Ubuntu interfaces(5) source directive because lib/network.js checkLinuxDCHPInterfaces() reads /etc/network/interfaces, extracts a source <path> token from file content, and interpolates it unquoted into cat ${file} 2> /dev/null | grep 'iface\|source' executed by execSync(cmd, util.execOptsLinux), allowing CVSSv3.1 8.8 (HIGH) · EPSS 63th percentile

CWECWE 78VNDSysteminformationTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-07-17
2026-07-17 20:17Z
HIGH

CVE-2026-45260 — Pimcore: Prior to 11.5.17 (LTS) and 12.3.7, Pimcore's WebDAV asset endpoint exposes a MOVE operation

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-45260

Pimcore is an Open Source Data & Experience Management Platform. Prior to 11.5.17 (LTS) and 12.3.7, Pimcore's WebDAV asset endpoint exposes a MOVE operation through /asset/webdav{path} without an authentication plugin in bundles/CoreBundle/src/Controller/WebDavController.php, and models/Asset/WebDAV/Tree.php performs asset mutation and deletion through models/Asset.php before checking a current Pimcore user or the rename, delete, create, or publish permissions, allowing unaut CVSSv3.1 8.1 (HIGH)

CWECWE 862VNDPimcoreTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-07-17
2026-07-17 20:17Z
HIGH

CVE-2026-44739 — Pimcore: Prior to 11.5.17 (LTS) and 12.3.6, the columnConfigAction endpoint in bundles/CustomReportsBundle/src/Controller/Reports/CustomReportController.php passes malicious SQL

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-44739

Pimcore is an Open Source Data & Experience Management Platform. Prior to 11.5.17 (LTS) and 12.3.6, the columnConfigAction endpoint in bundles/CustomReportsBundle/src/Controller/Reports/CustomReportController.php passes malicious SQL configuration through CustomReportController:columnConfigAction, SqlAdapter::getColumns, SqlAdapter::buildQueryString, and Db::fetchAssociative(), allowing an attacker with the reports_config permission to use arbitrary SELECT queries, UNION stat CVSSv3.1 8.7 (HIGH)

CWECWE 89VNDPimcoreTYPVulnerability
8.7
CVSS v3.1
94
Edit Score
2026-07-17
2026-07-17 20:17Z
CRIT

CVE-2026-42168 — django-pyas2 through 1.2.3 is vulnerable to OS command injection via the cmd_receive and cmd_send

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-42168

django-pyas2 through 1.2.3 is vulnerable to OS command injection via the cmd_receive and cmd_send fields on the Partner model. These fields are passed directly to os.system() in pyas2/utils.py without sanitization, allowing an authenticated admin user to execute arbitrary commands on the server when an AS2 message is received or sent. CVSSv3.1 9.1 (CRITICAL) · EPSS 47th percentile

CWECWE 78TYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2026-07-17
2026-07-17 20:17Z
CRIT

CVE-2026-36669 — An unauthenticated arbitrary file upload vulnerability in ck_upload_handler.php in Feng Office 3.11.13.11 allows remote

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-36669

An unauthenticated arbitrary file upload vulnerability in ck_upload_handler.php in Feng Office 3.11.13.11 allows remote attackers to upload malicious files (such as .html) to the web-accessible /tmp/ directory. CVSSv3.1 9.8 (CRITICAL) · EPSS 37th percentile

CWECWE 434TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-07-17
2026-07-17 20:17Z
CRIT

CVE-2026-15091 — IBM: Engineering AI Hub 1.0.0, 1.1.0, and 1.2.0 could allow a remote attacker to

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-15091

IBM Engineering AI Hub 1.0.0, 1.1.0, and 1.2.0 could allow a remote attacker to execute arbitrary scripts due to improper neutralization of input during web page generation. CVSSv3.1 9.3 (CRITICAL)

CWECWE 79VNDIbmTYPVulnerability
9.3
CVSS v3.1
97
Edit Score
2026-07-17
2026-07-17 20:17Z
HIGH

CVE-2026-14499 — IBM: Langflow OSS 1.0.0 through 1.10.1 Langflow could allow an authenticated user to execute

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-14499

IBM Langflow OSS 1.0.0 through 1.10.1 Langflow could allow an authenticated user to execute arbitrary commands with elevated privileges on the system due to improper validation of user supplied input in the Python Interpreter component. CVSSv3.1 8.8 (HIGH)

CWECWE 78VNDIbmTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
728 × 90 / responsive · programmatic ad slot
2026-07-17
2026-07-17 20:17Z
HIGH

CVE-2026-13473 — IBM: Storage Protect Client 8.1.0.0 through 8.1.27.0, 8.1.27.1, and 8.2.0.0 through 8.2.1.0 IBM Storage

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-13473

IBM Storage Protect Client 8.1.0.0 through 8.1.27.0, 8.1.27.1, and 8.2.0.0 through 8.2.1.0 IBM Storage Protect is vulnerable to a heap-based buffer overflow, caused by improper bounds checking. A remote attacker could overflow a buffer and execute arbitrary code on the system or cause the server to crash. CVSSv3.1 8.1 (HIGH)

VNDIbmTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-07-17
2026-07-17 20:17Z
HIGH

CVE-2026-13448 — IBM: Langflow OSS 1.0.0 through 1.10.1 Lanflow OSS contains an unauthenticated remote code execution

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-13448

IBM Langflow OSS 1.0.0 through 1.10.1 Lanflow OSS contains an unauthenticated remote code execution vulnerability in the public flow build endpoint ( /api/v1/build_public_tmp/{flow_id}/flow ). The vulnerability stems from an incomplete denylist in the validate_public_flow_no_code_execution() function that fails to block several code-execution agent components including OpenDsStarAgent, CodeActAgentSmolagents, and CSVAgent. CVSSv3.1 8.1 (HIGH)

VNDIbmTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-07-17
2026-07-17 20:17Z
CRIT

CVE-2025-51677 — An output mismatch between the RTL and the netlist of the or1200 cpu output

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2025-51677

An issue was discovered in openRISC OR1200 commit 83ac6b. An output mismatch between the RTL and the netlist of the or1200 cpu output port can lead to unexpected behavior. CVSSv3.1 9.1 (CRITICAL) · EPSS 6th percentile

CWECWE 116TYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2026-07-17
2026-07-17 19:50Z
INFO

v4.0.0rc3

Mythic releases·github.com

Mythic v4.0.0rc3 release candidate published on GitHub with adjustments to the payloads table buttons. This is a routine version bump in the Mythic command and control framework development cycle.

SWMythicTYPTool
25
Edit Score
2026-07-17
2026-07-17 19:30Z
INFO

Metasploit Wrap Up: An HTTP to SMB relay plus Payload Improvements

Rapid7 Research·rapid7.com

Metasploit Framework v6.4.144 release includes Linux Fetch Multi payloads for automatic architecture detection across ARM, MIPS, and RISC-V targets, a new HTTP-to-SMB relay auxiliary module for NTLM relay attacks, and expanded RISC-V payload support with XOR encoders. The Fetch Multi feature eliminates the need to pre-select target architecture when delivering staged payloads via HTTP/HTTPS.

SRFOsTACTA0008TACTA0009SWMetasploitVNDRapid7TYPToolSTGExecutionSTGLat Movement
68
Edit Score
2026-07-17
2026-07-17 19:17Z
CRIT

CVE-2026-9135 — IBM: Langflow OSS 1.0.0 through 1.10.0 Langflow versions up to 1.9.2 (commit 94981c443d4918517b9e8163d70fc598dc33a32d) contain

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-9135

IBM Langflow OSS 1.0.0 through 1.10.0 Langflow versions up to 1.9.2 (commit 94981c443d4918517b9e8163d70fc598dc33a32d) contain a code injection vulnerability in the Policies component's ToolGuard integration that bypasses the allow_custom_components=false security control. The vulnerability exists because the validation mechanism only checks the main component source code in node_template["code"]["value"] but fails to validate dynamic CodeInput fields that store generated Tool CVSSv3.1 9.9 (CRITICAL)

CWECWE 94VNDIbmTYPVulnerability
9.9
CVSS v3.1
100
Edit Score
2026-07-17
2026-07-17 19:17Z
CRIT

CVE-2026-9103 — IBM: Langflow OSS 1.0.0 through 1.10.0 could allow a remote attacker to gain unauthorized

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-9103

IBM Langflow OSS 1.0.0 through 1.10.0 could allow a remote attacker to gain unauthorized access due to improper authentication in the /api/v1/login/auto_login endpoint. The endpoint issues long-lived superuser bearer tokens without requiring authentication when the AUTO_LOGIN configuration is enabled (enabled by default), which may allow an unauthenticated network attacker to obtain full administrative access. Additionally, permissive cross-origin resource sharing (CORS) sett CVSSv3.1 9.8 (CRITICAL)

CWECWE 306VNDIbmTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-07-17
2026-07-17 19:17Z
HIGH

CVE-2026-58195 — Agentic: Prior to 2.0.14, agentic-flow MCP server tools in src/mcp/standalone-stdio.ts, src/mcp/fastmcp/servers/claude-flow-sdk.ts, src/mcp/fastmcp/servers/stdio-full.ts, src/mcp/fast

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-58195

Agentic-Flow is an AI agent orchestration platform. Prior to 2.0.14, agentic-flow MCP server tools in src/mcp/standalone-stdio.ts, src/mcp/fastmcp/servers/claude-flow-sdk.ts, src/mcp/fastmcp/servers/stdio-full.ts, src/mcp/fastmcp/servers/http-streaming-updated.ts, src/mcp/fastmcp/servers/http-sse.ts, src/mcp/fastmcp/servers/poc-stdio.ts, src/mcp/fastmcp/tools/agent/{execute,list,parallel}.ts, src/mcp/fastmcp/tools/swarm/orchestrate.ts, and src/mcp/fastmcp/tools/hooks/pretrain CVSSv3.1 8.8 (HIGH)

CWECWE 78VNDAgenticTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-07-17
2026-07-17 19:17Z
HIGH

CVE-2026-45162 — Pimcore: Prior to 11.5.17 (LTS) and 12.3.7, multiple Pimcore locations call PHP's unserialize() on data

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-45162

Pimcore is an Open Source Data & Experience Management Platform. Prior to 11.5.17 (LTS) and 12.3.7, multiple Pimcore locations call PHP's unserialize() on data from database columns and filesystem files without the allowed_classes restriction, including lib/Tool/Authentication.php, models/Site/Dao.php, models/DataObject/ClassDefinition/CustomLayout/Dao.php, models/Tool/TmpStore/Dao.php, models/Asset/WebDAV/Service.php, and admin-ui-classic-bundle/src/Helper/Dashboard.php, ena CVSSv3.1 8.0 (HIGH)

CWECWE 502VNDPimcoreTYPVulnerability
8.0
CVSS v3.1
90
Edit Score
2026-07-17
2026-07-17 18:18Z
CRIT

CVE-2026-58644: Microsoft SharePoint Server Unauthenticated Remote Code Execution Vulnerability Exploited in the Wild

Rapid7 Research·rapid7.comCVE-2026-58644in the wild

Microsoft SharePoint Server on-premises deployments are vulnerable to unauthenticated remote code execution via deserialization of untrusted data (CVE-2026-58644, CVSS 9.8). Active exploitation in the wild has been confirmed and the vulnerability was added to CISA's KEV catalog; Microsoft released patches on July 14, 2026, with detection signatures available via AMSI and Microsoft Defender.

SRFApplicationTACTA0001SRFWebSWSharepointVNDMicrosoftTYPVulnerabilityTYPAdvisorySTGExecution
92
Edit Score
2026-07-17
2026-07-17 18:17Z
CRIT

CVE-2026-9202 — IBM: Langflow OSS 1.0.0 through 1.10.0 allows unauthenticated attackers to create unlimited user accounts

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-9202

IBM Langflow OSS 1.0.0 through 1.10.0 allows unauthenticated attackers to create unlimited user accounts on any Langflow instance; when NEW_USER_IS_ACTIVE=true (documented deployment option), newly created accounts are immediately active and can authenticate to reach RCE endpoints, bypassing the need for AUTO_LOGIN. CVSSv3.1 9.8 (CRITICAL)

CWECWE 306VNDIbmTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-07-17
2026-07-17 18:17Z
CRIT

CVE-2026-9198 — IBM: Langflow OSS 1.0.0 through 1.10.0 allows unauthenticated attackers to chain /api/v1/auto_login (mints SUPERUSER

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-9198

IBM Langflow OSS 1.0.0 through 1.10.0 allows unauthenticated attackers to chain /api/v1/auto_login (mints SUPERUSER tokens to any network caller) with /api/v1/validate/code (executes user code via exec()) to achieve full RCE on default Langflow deployments CVSSv3.1 9.8 (CRITICAL)

CWECWE 94VNDIbmTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-07-17
2026-07-17 17:17Z
CRIT

CVE-2026-9586 — Sangoma Switchvox: An unauthenticated SQL injection vulnerability exists in Sangoma Switchvox SMB Edition 8.3 (104997).

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-9586

An unauthenticated SQL injection vulnerability exists in Sangoma Switchvox SMB Edition 8.3 (104997). The /pa endpoint processes XML content beginning with <PolycomIPPhone> and directly concatenates the user-controlled PhoneIP value into PostgreSQL queries without sanitization or parameterization. An unauthenticated remote attacker can execute arbitrary SQL statements against the backend PostgreSQL database using a single crafted request, including database operations and remo CVSSv3.1 9.8 (CRITICAL) · EPSS 50th percentile

CWECWE 89VNDSangomaTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-07-17
2026-07-17 17:17Z
CRIT

CVE-2026-8297 — Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-8297

Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Gis Informatics Engineering Consulting Laboratory R&D and Software Services Inc. GisLab Laboratory Management System allows SQL Injection. This issue affects GisLab Laboratory Management System: from 1.4.03 through 08072026. CVSSv3.1 9.8 (CRITICAL)

CWECWE 89TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-07-17
2026-07-17 17:17Z
CRIT

CVE-2026-54496 — ZEBRA: Prior to zebrad 5.0.0, halo2_gadgets 0.5.0, orchard 0.14.0, zcash_primitives 0.28.0, and zcashd 6.20.0, the

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-54496

ZEBRA is a Zcash node written entirely in Rust. Prior to zebrad 5.0.0, halo2_gadgets 0.5.0, orchard 0.14.0, zcash_primitives 0.28.0, and zcashd 6.20.0, the variable-base scalar multiplication gadget in halo2_gadgets/src/ecc/chip/mul/incomplete.rs used assign_advice() for the base point without a copy constraint tying it to the actual base, allowing a malicious prover to produce a valid proof for an Orchard Action with an under-constrained base point and bypass the diversified CVSSv3.1 9.3 (CRITICAL)

CWECWE 345VNDZebraTYPVulnerability
9.3
CVSS v3.1
97
Edit Score
2026-07-17
2026-07-17 17:17Z
CRIT

CVE-2026-12694 — Authorization: Missing Authorization vulnerability in Vimesoft Inc.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-12694

Missing Authorization vulnerability in Vimesoft Inc. Enterprise Video Platform allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects Enterprise Video Platform: from 3.11.0.0 before 3.25.0. CVSSv3.1 9.1 (CRITICAL)

CWECWE 862TYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2026-07-17
2026-07-17 17:17Z
CRIT

CVE-2026-12693 — Authorization: bypass through User-Controlled key vulnerability in Vimesoft Inc.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-12693

Authorization bypass through User-Controlled key vulnerability in Vimesoft Inc. Enterprise Video Platform allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects Enterprise Video Platform: from 3.11.0.0 before 3.25.0. CVSSv3.1 9.4 (CRITICAL)

CWECWE 639TYPVulnerability
9.4
CVSS v3.1
97
Edit Score
2026-07-17
2026-07-17 17:17Z
CRIT

CVE-2026-12692 — Unverified: Enterprise Video Platform allows Authentication Bypass.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-12692

Unverified password change vulnerability in Vimesoft Inc. Enterprise Video Platform allows Authentication Bypass. This issue affects Enterprise Video Platform: from 3.11.0.0 before 3.25.0. CVSSv3.1 9.8 (CRITICAL)

CWECWE 620VNDUnverifiedTYPVulnerability
9.8
CVSS v3.1
99
Edit Score