2026-07-16
2026-07-16 14:16Z
HIGH

CVE-2026-5674 — PipeWire: This vulnerability allows an attacker to escape sandboxed applications, such as Flatpak, by exploiting

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-5674

A flaw was found in PipeWire, a multimedia server. This vulnerability allows an attacker to escape sandboxed applications, such as Flatpak, by exploiting PipeWire's PulseAudio compatibility layer. An attacker with minimal permissions within a sandboxed environment can load a malicious library, leading to arbitrary code execution outside the sandbox and potential compromise of the user's system. CVSSv3.1 8.8 (HIGH)

CWECWE 427VNDPipewireTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-07-16
2026-07-16 13:16Z
HIGH

CVE-2026-63306 — stoatchat before 0.13.5 contains an unauthenticated server-side request forgery vulnerability in the /proxy and

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-63306

stoatchat before 0.13.5 contains an unauthenticated server-side request forgery vulnerability in the /proxy and /embed endpoints that accept arbitrary URLs without DNS resolution filtering or private IP range validation. Attackers can enumerate internal services, fingerprint applications, and reach instance metadata endpoints by supplying malicious URLs or leveraging redirect chains to access internal infrastructure. CVSSv3.1 8.6 (HIGH)

CWECWE 918TYPVulnerability
8.6
CVSS v3.1
93
Edit Score
2026-07-16
2026-07-16 13:16Z
HIGH

CVE-2026-63305 — AVideo: through 29.0 contains an OS command injection vulnerability in the ffmpeg.json.php endpoint where

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-63305

AVideo through 29.0 contains an OS command injection vulnerability in the ffmpeg.json.php endpoint where notifyCode and callback parameters are concatenated into a shell command without escaping. Attackers who can craft a valid encrypted payload can inject arbitrary shell metacharacters into these fields to execute OS commands as the web-server user. CVSSv3.1 8.1 (HIGH)

CWECWE 78VNDAvideoTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-07-16
2026-07-16 13:16Z
HIGH

CVE-2026-63304 — AVideo: through 29.0 contains an OS command injection vulnerability in plugin/API/standAlone/functions.php where the listFFmpegProcesses()

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-63304

AVideo through 29.0 contains an OS command injection vulnerability in plugin/API/standAlone/functions.php where the listFFmpegProcesses() function interpolates unsanitized keyword parameters inside single quotes without escaping. Attackers who can craft a valid encrypted codeToExec payload can break out of the single-quoted grep context and execute arbitrary OS commands as the web-server user. CVSSv3.1 8.1 (HIGH)

CWECWE 78VNDAvideoTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-07-16
2026-07-16 13:16Z
CRIT

CVE-2026-11386 — An input validation and injection vulnerability exists in Canonical ubuntu-pro-client (formerly ubuntu-advantage-tools).

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-11386

An input validation and injection vulnerability exists in Canonical ubuntu-pro-client (formerly ubuntu-advantage-tools). The client constructs APT source files (such as /etc/apt/sources.list.d/ubuntu-.list or their DEB822 equivalents) using data received directly from the contract server response via the directives.suites[] and directives.aptURL fields. Because the client utilizes Python's str.format() to write these files without performing escaping, validation, or newline c CVSSv3.1 9.0 (CRITICAL)

CWECWE 20TYPVulnerability
9.0
CVSS v3.1
95
Edit Score
2026-07-16
2026-07-16 13:05Z
CRIT

HelloNet campaign — new malicious modules launched through the ViPNet update system

Kaspersky Securelist·securelist.comin the wild

Kaspersky discovered the HelloNet APT campaign, active since May 2026, targeting Russian government, energy, transport, education, and logistics sectors via malicious modules injected through the ViPNet secure network software's update system. The attack chain uses DLL sideloading (wtsapi32.dll) to achieve persistence, followed by deployment of HelloInjector (loader), HelloProxy (traffic interception/C2 proxy), HelloExecutor (reconnaissance), HelloCleaner (log deletion), and HelloBackdoor (Rust-based file operations backdoor). Attribution points with low confidence to a Chinese-speaking APT group based on Sina.com references and Chinese mirror usage in compilation artifacts.

SRFApplicationSRFNetworkTACTA0007TACTA0003TACTA0008TACTA0009OSWindowsSWVipnet
82
Edit Score
2026-07-16
2026-07-16 12:17Z
HIGH

CVE-2026-35149 — HCL: DFXServer is affected by an Authentication Bypass vulnerability via server response manipulation.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-35149

HCL DFXServer is affected by an Authentication Bypass vulnerability via server response manipulation. An unauthorized user without valid credentials can exploit this flaw by intercepting and altering the server's authentication responses, allowing them to gain unauthorized access to the application without verification. CVSSv3.1 8.2 (HIGH)

CWECWE 294VNDHclTYPVulnerability
8.2
CVSS v3.1
91
Edit Score
728 × 90 / responsive · programmatic ad slot
2026-07-16
2026-07-16 12:17Z
HIGH

CVE-2026-35147 — HCL: The application fails to verify the user's authentication status when accessing specific API endpoints

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-35147

HCL DFXServer is affected by a Broken Authentication vulnerability via direct API access. The application fails to verify the user's authentication status when accessing specific API endpoints, allowing an unauthenticated attacker to interact with the APIs and perform unauthorized actions without valid credentials. CVSSv3.1 8.2 (HIGH)

CWECWE 639VNDHclTYPVulnerability
8.2
CVSS v3.1
91
Edit Score
2026-07-16
2026-07-16 12:00Z
CRIT

GoSerpent: a persistent threat evolves with sophisticated data collection and exfiltration

Kaspersky Securelist·securelist.comin the wild

Kaspersky disclosed GoSerpent, a sophisticated Go-based RAT backdoor active since at least 2021 targeting government and diplomatic entities in Southeast Asia. The threat actor deploys a multi-stage toolchain including GoSerpent/McMx RATs, ThumbcacheService for file collection, credential dumping tools (Mimikatz, QuarksDumpLocalHash), and a second-stage Stowaway RAT with TmcLoader/TmcPayload for data exfiltration via network shares. The campaign demonstrates advanced operational planning with encrypted C2 communications, SOCKS5 proxy capabilities, and deliberate tool integration for long-term intelligence gathering.

SRFOsTACTA0004TACTA0005TACTA0001TACTA0002SRFNetworkTACTA0006TACTA0007
82
Edit Score
2026-07-16
2026-07-16 11:16Z
CRIT

CVE-2023-49900 — An unauthenticated remote attacker is able to perform remote code execution due to incorrectly

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2023-49900

An unauthenticated remote attacker is able to perform remote code execution due to incorrectly sanitized user input in the SetParameter command. CVSSv3.1 9.8 (CRITICAL)

CWECWE 78TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-07-16
2026-07-16 11:16Z
CRIT

CVE-2023-49899 — An unauthenticated remote attacker can execute any command on the affected device due to

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2023-49899

An unauthenticated remote attacker can execute any command on the affected device due to not correctly verifying the origin of a communication channel. CVSSv3.1 9.8 (CRITICAL)

CWECWE 346TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-07-16
2026-07-16 10:16Z
CRIT

CVE-2026-22752 — Authentication: bypass by primary weakness vulnerability in Spring Security Spring Authorization Server.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-22752

Authentication bypass by primary weakness vulnerability in Spring Security Spring Authorization Server. This issue affects Spring Authorization Server: from 7.0.0 through 7.0.4, from 1.5.0 through 1.5.6, from 1.4.0 through 1.4.9, from 1.3.0 through 1.3.10. CVSSv3.1 9.6 (CRITICAL)

TYPVulnerability
9.6
CVSS v3.1
98
Edit Score
2026-07-16
2026-07-16 09:16Z
HIGH

CVE-2026-15103 — WPFunnels: The WPFunnels – Funnel Builder for WooCommerce with Checkout & One Click Upsell plugin

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-15103

The WPFunnels – Funnel Builder for WooCommerce with Checkout & One Click Upsell plugin for WordPress is vulnerable to Privilege Escalation via arbitrary option update in all versions up to, and including, 3.12.8. This is due to the `update_settings()` REST callback failing to validate the `group_id` path parameter against an allowlist of permitted option names before passing it directly to `get_option()` and `update_option()`, allowing the built-in `wp_user_roles` option — wh CVSSv3.1 8.8 (HIGH)

CWECWE 269VNDWpfunnelsTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-07-16
2026-07-16 09:16Z
HIGH

CVE-2026-15008 — Uncanny: The Uncanny Automator – Easy Automation, Integration, Webhooks & Workflow Builder Plugin plugin for

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-15008

The Uncanny Automator – Easy Automation, Integration, Webhooks & Workflow Builder Plugin plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the fr_token function in all versions up to, and including, 7.3.1.4. This makes it possible for unauthenticated attackers to delete arbitrary files on the server, which can easily lead to remote code execution when the right file is deleted (such as wp-config.php). Exploitation requir CVSSv3.1 8.1 (HIGH)

CWECWE 502VNDUncannyTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-07-16
2026-07-16 09:16Z
HIGH

CVE-2026-15005 — Loco: The Loco Translate plugin for WordPress is vulnerable to Cross-Site Request Forgery in all

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-15005

The Loco Translate plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.8.5. This is due to missing or incorrect nonce validation on the execTemplate function. This makes it possible for unauthenticated attackers to execute arbitrary PHP code on the server by supplying a php://filter stream wrapper URI as the 'template' parameter, which bypasses path validation and is passed directly to the include sink in execTemplate() via CVSSv3.1 8.8 (HIGH)

CWECWE 352VNDLocoTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-07-16
2026-07-16 09:16Z
HIGH

CVE-2026-13741 — Digits: The Digits: WordPress Mobile Number Signup and Login plugin for WordPress is vulnerable to

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-13741

The Digits: WordPress Mobile Number Signup and Login plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 9.1.0.5. This is due to missing authorization and role validation in the `dig_update_wpwc_custom_fields()` function. This makes it possible for authenticated attackers, with Subscriber-level access and above, to escalate their privileges to Administrator by submitting a forged `digits_reg_userrole` value during profile update, g CVSSv3.1 8.8 (HIGH)

CWECWE 269VNDDigitsTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-07-16
2026-07-16 07:16Z
HIGH

CVE-2026-12585 — Abandoned: The Abandoned Cart Lite for WooCommerce WordPress plugin before 6.8.2 does not protect the

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-12585

The Abandoned Cart Lite for WooCommerce WordPress plugin before 6.8.2 does not protect the integrity of its cart-recovery tokens or bind them to the requesting account, allowing unauthenticated attackers to forge a recovery link that logs them in as another user when the automatic-login option is enabled. CVSSv3.1 8.1 (HIGH)

CWECWE 287VNDAbandonedTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-07-16
2026-07-16 07:16Z
HIGH

CVE-2026-12525 — Redux: The Redux Framework WordPress plugin before 4.5.13 does not restrict which user meta keys

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-12525

The Redux Framework WordPress plugin before 4.5.13 does not restrict which user meta keys can be written when saving custom profile fields, allowing users with at least the Subscriber role to escalate their privileges to Administrator by submitting a crafted value while updating their own profile, on sites where the Redux Framework WordPress plugin before 4.5.13's user-profile (Users extension) feature is enabled. CVSSv3.1 8.8 (HIGH)

CWECWE 269VNDReduxTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-07-16
2026-07-16 07:16Z
CRIT

CVE-2026-12492 — Happy: The Happy Coders OTP Login for WooCommerce WordPress plugin before 2.8 does not verify

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-12492

The Happy Coders OTP Login for WooCommerce WordPress plugin before 2.8 does not verify that a one-time password was actually validated before authenticating a user based on a supplied identifier, allowing unauthenticated attackers to log in as any existing user, including administrators, as well as to create new accounts. CVSSv3.1 9.8 (CRITICAL)

CWECWE 287VNDHappyTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-07-16
2026-07-16 05:16Z
CRIT

CVE-2026-15013 — SAML: The SAML Single Sign On – SSO Login plugin for WordPress is vulnerable to

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-15013

The SAML Single Sign On – SSO Login plugin for WordPress is vulnerable to Authentication Bypass via SAML Signature Algorithm Confusion in all versions up to, and including, 5.4.3. The vulnerability exists because `Mo_SAML_Utilities::mo_saml_cast_key()` reads the `SignatureMethod` Algorithm attribute directly from the attacker-controlled `SAMLResponse` parameter rather than enforcing the locally configured algorithm, causing the plugin to recast the IdP's RSA public key as an CVSSv3.1 9.8 (CRITICAL)

CWECWE 347VNDSamlTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-07-16
2026-07-16 01:16Z
HIGH

CVE-2026-1609 — Keycloak: This allows unauthorized access to sensitive resources.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-1609

A flaw was found in Keycloak. When the JSON Web Token (JWT) authorization grant preview feature is enabled and a user account is disabled, Keycloak fails to validate the user’s disabled status during JWT authorization grant processing. A remote attacker with low privileges can exploit this improper access control vulnerability by presenting a valid assertion token from an external identity provider to obtain a JWT for a disabled user. This allows unauthorized access to sensit CVSSv3.1 8.1 (HIGH)

CWECWE 284VNDKeycloakTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-07-16
2026-07-16 00:00Z
HIGH

TELEPUZ: a modular MaaS malware spreading via CLICKFIX-VIDAR chains

Elastic Security Labs·elastic.coin the wild

Elastic Security Labs reverse-engineered TELEPUZ, a modular malware-as-a-service (MaaS) platform actively spreading via CLICKFIX-VIDAR chains since April 2026. The malware features sophisticated evasion (indirect syscalls, AMSI/ETW patching, NTDLL unhooking), multi-stage infection, UAC bypass techniques, and 36+ C2 commands including stealer, keylogger, and web-injection modules. C2 resilience is achieved through Telegram, Steam, DNS, and Polygon blockchain fallback mechanisms.

SRFOsTACTA0004TACTA0005TACTA0001TACTA0002TACTA0006TACTA0007TACTA0003
82
Edit Score
2026-07-16
2026-07-16 00:00Z
HIGH

TELEPUZ: a modular MaaS malware spreading via CLICKFIX-VIDAR chains

Elastic Security Labs·elastic.coin the wild

Elastic Security Labs discovered TELEPUZ, a modular malware-as-a-service (MaaS) platform actively spreading via CLICKFIX-VIDAR social engineering chains since April 2026. The malware employs sophisticated evasion techniques including indirect syscalls, AMSI/ETW patching, NTDLL unhooking, and UAC bypass via COM elevation and AppInfo ALPC. Command & control infrastructure uses WebSockets with fallback mechanisms via Telegram, Steam profiles, DNS records, and Polygon blockchain smart contracts.

SRFApplicationSRFOsTACTA0005TACTA0001TACTA0003TACTA0011TYPVulnerabilityTYPThreat Intel
82
Edit Score
2026-07-15
2026-07-15 22:53Z
INFO

v4.0.0rc2

Mythic releases·github.com

Mythic v4.0.0rc2 release candidate published on GitHub. No detailed changelog or feature notes are accessible in the provided content due to page load errors.

SWMythicTYPTool
15
Edit Score
2026-07-15
2026-07-15 22:17Z
CRIT

CVE-2026-55652 — Wekan: is open source kanban built with Meteor.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-55652

Wekan is open source kanban built with Meteor. Prior to 9.46, header-login with HEADER_LOGIN_TRUSTED_IPS uses getRequestIp() in server/lib/headerLoginAuth.js to trust the client-supplied X-Forwarded-For header before the real socket address, allowing an unauthenticated attacker to send HEADER_LOGIN_ID for any username and receive a meteor_login_token session, including for admin. This issue is fixed in version 9.46. CVSSv3.1 9.8 (CRITICAL)

CWECWE 287CWECWE 290VNDWekanTYPVulnerability
9.8
CVSS v3.1
99
Edit Score