2026-07-15
2026-07-15 16:16Z
CRIT

CVE-2026-44986 — Penpot: Prior to 2.14.5, Penpot exposed teams_invitations.clj invitation tokens from create-team-invitations, embedded an existing profile

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-44986

Penpot is an open-source design tool for design and code collaboration. Prior to 2.14.5, Penpot exposed teams_invitations.clj invitation tokens from create-team-invitations, embedded an existing profile id in auth.clj prepare-register-profile, and had auth.clj register-profile issue a session based on the invitation email match without password verification, allowing a registered user to take over any non-blocked profile. This issue is fixed in version 2.14.5. CVSSv3.1 9.9 (CRITICAL)

CWECWE 287CWECWE 639VNDPenpotTYPVulnerability
9.9
CVSS v3.1
100
Edit Score
2026-07-15
2026-07-15 16:00Z
HIGH

There and Back Again: An Operators Guide on NTLM Relaying Egress

SpecterOps·specterops.io

SpecterOps publishes a comprehensive operational guide on NTLM relay tradecraft for egress scenarios where traditional layer-2 relay attacks are unavailable. The technique, termed "There and Back Again," coerces outbound NTLM authentication to an internet-facing cloud VM, tunnels it back to red team infrastructure, and relays it against internal services (LDAP, ADCS) to achieve privilege escalation and domain compromise. The post covers infrastructure setup, WebDAV/EFSRPC coercion chains, shadow credentials abuse, and S4U2Self delegation workflows, with defensive mitigations including NTLM signing, channel binding, EPA enforcement, and egress filtering.

TACTA0004SRFNetworkTACTA0006SRFIdentityTACTA0008SWImpacketSWCertipySWKrbrelayx
78
Edit Score
2026-07-15
2026-07-15 15:16Z
HIGH

CVE-2026-61836 — Directus: Prior to 12.0.0, when response caching is enabled, the cache-key derivation in api/src/utils/get-cache-key.ts includes

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-61836

Directus is a real-time API and App dashboard for managing SQL database content. Prior to 12.0.0, when response caching is enabled, the cache-key derivation in api/src/utils/get-cache-key.ts includes version, path, query, and accountability.user but omits authorization context such as share, role, roles, admin, app, and policies. Directus share tokens and anonymous requests can both reduce to user null, so different shares or anonymous clients requesting the same URL and quer CVSSv3.1 8.6 (HIGH)

CWECWE 639CWECWE 524VNDDirectusTYPVulnerability
8.6
CVSS v3.1
93
Edit Score
2026-07-15
2026-07-15 15:16Z
CRIT

CVE-2026-61736 — LightRAG: provides simple and fast retrieval-augmented generation.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-61736

LightRAG provides simple and fast retrieval-augmented generation. Prior to 1.5.4, the server defaults to CORS_ORIGINS=* combined with allow_credentials=True in lightrag/api/lightrag_server.py, causing Starlette CORSMiddleware to effectively whitelist every origin for credentialed cross-origin requests. Any malicious website visited by an authenticated LightRAG user can silently make authenticated API requests, exfiltrating documents and knowledge graph data or performing dest CVSSv3.1 9.3 (CRITICAL)

CWECWE 942VNDLightragTYPVulnerability
9.3
CVSS v3.1
97
Edit Score
2026-07-15
2026-07-15 15:16Z
HIGH

CVE-2026-55723 — NGINX: When NGINX Ingress Controller is configured with Custom Resource Definitions (CRDs) or Ingress annotations

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-55723

When NGINX Ingress Controller is configured with Custom Resource Definitions (CRDs) or Ingress annotations, an injection vulnerability exists in the configuration generator of NGINX Ingress Controller. Multiple user-controllable fields are written into the generated NGINX configuration without sanitization. An authenticated attacker with permission to create or modify these CRDs or annotations may craft values that inject arbitrary NGINX configuration directives. Impact: An CVSSv3.1 8.3 (HIGH)

CWECWE 76VNDNginxTYPVulnerability
8.3
CVSS v3.1
92
Edit Score
2026-07-15
2026-07-15 15:16Z
HIGH

CVE-2026-42533 — NGINX: This may cause a heap buffer overflow in the NGINX worker process leading to

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-42533

A vulnerability exists in NGINX Plus and NGINX Open Source when a map directive uses regex matching and a string expression references the map's regex capture variables before referencing the map output variable. Alternatively, the same result could be achieved by using a non-cacheable variable in a string expression under certain conditions. An unauthenticated attacker along with conditions beyond their control can exploit this vulnerability by sending crafted HTTP requests. CVSSv3.1 8.1 (HIGH)

CWECWE 122VNDNginxTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-07-15
2026-07-15 14:18Z
CRIT

CVE-2026-43637 — Cornac: before 2.6.0 contains a path traversal (Tar Slip) vulnerability that allows attackers to

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-43637

Cornac before 2.6.0 contains a path traversal (Tar Slip) vulnerability that allows attackers to write arbitrary files outside the intended cache directory by supplying a crafted TAR archive containing ../ sequences, absolute paths, or symlink/hardlink entries to the _extract_archive() function in cornac/utils/download.py. Attackers can trigger this vulnerability through the built-in dataset loaders, which automatically download and extract archives, causing archive.extractall CVSSv3.1 9.1 (CRITICAL)

CWECWE 22VNDCornacTYPVulnerability
9.1
CVSS v3.1
96
Edit Score
728 × 90 / responsive · programmatic ad slot
2026-07-15
2026-07-15 13:00Z
HIGH

Investigating Persistence Mechanisms in AWS

Rapid7 Research·rapid7.com

Rapid7 Labs publishes a comprehensive guide to detecting and investigating four major AWS persistence mechanisms: IAM user creation/modification, assume-role policy backdooring, Lambda function abuse, and federated session creation. The article provides concrete CloudTrail detection queries (LEQL), attack examples with code samples, and step-by-step investigation workflows for incident responders using Rapid7 Incident Command.

TACTA0004SRFIdentityTACTA0003SRFCloudSWAwsVNDAmazonTYPResearchSTGDiscovery
72
Edit Score
2026-07-15
2026-07-15 12:18Z
HIGH

CVE-2026-61873 — Grav: before 9.1.8 contains an arbitrary file write vulnerability in the Form plugin's process.save.filename

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-61873

Grav before 9.1.8 contains an arbitrary file write vulnerability in the Form plugin's process.save.filename parameter, which is validated against path traversal before Twig processing but never re-validated after rendering. Attackers can submit form data containing path traversal sequences that are processed through Twig templates, allowing them to write arbitrary files including PHP webshells to the web root or other sensitive directories. CVSSv3.1 8.1 (HIGH)

CWECWE 73VNDGravTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-07-15
2026-07-15 12:18Z
HIGH

CVE-2026-61457 — Grav: The Grav API plugin (getgrav/grav-plugin-api) before 1.0.3 contains a file upload extension bypass in

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-61457

The Grav API plugin (getgrav/grav-plugin-api) before 1.0.3 contains a file upload extension bypass in the API media controller. HandlesMediaUploads::validateFileExtension() inspects only the final file extension via pathinfo($filename, PATHINFO_EXTENSION), so a user with api.media.write permission can upload a file with a double extension such as shell.php.jpg to bypass the dangerous extensions blocklist. The web server may then execute the file as PHP, resulting in remote co CVSSv3.1 8.8 (HIGH)

CWECWE 434VNDGravTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-07-15
2026-07-15 12:18Z
CRIT

CVE-2026-61451 — Grav: The Grav API plugin (grav-plugin-api) before 1.0.4 does not validate the origin of the

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-61451

The Grav API plugin (grav-plugin-api) before 1.0.4 does not validate the origin of the client-supplied admin_base_url field in the POST /api/v1/auth/forgot-password endpoint. The sanitizeHttpUrl() function only checks that the URL scheme is http/https and never verifies the host against the server's own origin, so an attacker can supply an arbitrary host. As a result, an unauthenticated attacker can cause the password reset email sent to a victim to contain a reset link point CVSSv3.1 9.6 (CRITICAL)

CWECWE 601VNDGravTYPVulnerability
9.6
CVSS v3.1
98
Edit Score
2026-07-15
2026-07-15 12:18Z
HIGH

CVE-2026-61446 — PraisonAI: (praisonaiagents) before 1.6.78 contains a remote code execution vulnerability in the plugin manager

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-61446

PraisonAI (praisonaiagents) before 1.6.78 contains a remote code execution vulnerability in the plugin manager, which loads and executes arbitrary Python (.py) files from project-level and user-home .praisonai/plugins/ directories using importlib spec_from_file_location() and exec_module() without code signing, integrity verification, or sandboxing. An attacker who can write a malicious .py file to a plugin directory (for example via path traversal, a supply chain attack, or CVSSv3.1 8.4 (HIGH)

CWECWE 94VNDPraisonaiTYPVulnerability
8.4
CVSS v3.1
92
Edit Score
2026-07-15
2026-07-15 12:18Z
HIGH

CVE-2026-61443 — PraisonAI: before 1.6.78 contains a remote code execution vulnerability in SkillTools.run_skill_script() that executes scripts

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-61443

PraisonAI before 1.6.78 contains a remote code execution vulnerability in SkillTools.run_skill_script() that executes scripts without path containment validation. Attackers can supply absolute file paths to execute arbitrary scripts from any filesystem location, including those outside the intended working directory. CVSSv3.1 8.1 (HIGH)

CWECWE 22VNDPraisonaiTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-07-15
2026-07-15 12:18Z
HIGH

CVE-2026-61436 — PraisonAI: before 4.6.78 fails to verify Svix webhook signatures in AgentMail webhook mode, allowing

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-61436

PraisonAI before 4.6.78 fails to verify Svix webhook signatures in AgentMail webhook mode, allowing unauthenticated attackers to forge message.received events. Attackers can send crafted JSON payloads to the webhook endpoint to invoke configured agents with arbitrary sender addresses and message content. CVSSv3.1 8.6 (HIGH)

CWECWE 287VNDPraisonaiTYPVulnerability
8.6
CVSS v3.1
93
Edit Score
2026-07-15
2026-07-15 12:18Z
HIGH

CVE-2026-61435 — PraisonAI: before 4.6.78 contains an authentication bypass in the Call API agent invocation endpoints

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-61435

PraisonAI before 4.6.78 contains an authentication bypass in the Call API agent invocation endpoints (src/praisonai/praisonai/api/agent_invoke.py) when PRAISONAI_CALL_AUTH=disabled is configured. The safeguard intended to restrict the disabled-auth opt-out to localhost binding derives the bind host from request.url.hostname, which is taken from the client-controlled HTTP Host header. A remote, unauthenticated attacker who can reach the service over the network can send a spoo CVSSv3.1 8.2 (HIGH)

CWECWE 287VNDPraisonaiTYPVulnerability
8.2
CVSS v3.1
91
Edit Score
2026-07-15
2026-07-15 12:18Z
HIGH

CVE-2026-61430 — PraisonAI: Attackers can use DNS rebinding to bypass SSRF protection and retrieve internal HTTP response

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-61430

PraisonAI before 1.6.78 contains a server-side request forgery vulnerability in the web_crawl tool that validates hostnames at check time but re-resolves them at connection time without IP pinning. Attackers can use DNS rebinding to bypass SSRF protection and retrieve internal HTTP response bodies from private or loopback services. CVSSv3.1 8.5 (HIGH)

CWECWE 918VNDPraisonaiTYPVulnerability
8.5
CVSS v3.1
93
Edit Score
2026-07-15
2026-07-15 12:18Z
HIGH

CVE-2026-58655 — Grav: The bundled Grav Flex Objects plugin (getgrav/grav-plugin-flex-objects) before 1.4.0 contains a stored server-side template

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-58655

The bundled Grav Flex Objects plugin (getgrav/grav-plugin-flex-objects) before 1.4.0 contains a stored server-side template injection vulnerability. When rendering dynamic collection or object titles, the plugin passes user-controlled frontmatter values (page.header.flex.collection.title or page.header.flex.object.title) to Twig's template_from_string(), causing them to be evaluated as Twig code rather than treated as text. This path bypasses Grav's Security::cleanDangerousTw CVSSv3.1 8.8 (HIGH)

CWECWE 94VNDGravTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-07-15
2026-07-15 12:18Z
HIGH

CVE-2026-57996 — phpMyFAQ before 4.1.5 contains a privilege escalation vulnerability in the user/add API endpoint that

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-57996

phpMyFAQ before 4.1.5 contains a privilege escalation vulnerability in the user/add API endpoint that allows non-SuperAdmin administrators to create SuperAdmin accounts. A delegated administrator with USER_ADD/EDIT/DELETE permissions can call POST /admin/api/user/add with isSuperAdmin: true and attacker-chosen credentials to create a SuperAdmin account, then authenticate as that account to achieve full instance takeover. CVSSv3.1 8.8 (HIGH)

CWECWE 269TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-07-15
2026-07-15 12:18Z
CRIT

CVE-2026-56699 — Wazuh: Manager before 5.0.0-beta3 fails to escape the DataValue.index field when constructing OpenSearch bulk

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-56699

Wazuh Manager before 5.0.0-beta3 fails to escape the DataValue.index field when constructing OpenSearch bulk requests, allowing enrolled agents to inject arbitrary NDJSON operations. Attackers can smuggle delete, index, or update operations into bulk requests executed under the manager's admin credentials, enabling document deletion, alert tampering, and cross-agent SIEM state manipulation. CVSSv3.1 10.0 (CRITICAL)

CWECWE 74VNDWazuhTYPVulnerability
10.0
CVSS v3.1
100
Edit Score
2026-07-15
2026-07-15 12:18Z
HIGH

CVE-2026-56400 — Attackers can execute arbitrary code on the openwebui instance by crafting malicious cross-site requests

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-56400

open-webui before 0.3.14 contains a cross-origin resource sharing misconfiguration allowing arbitrary origins with allow_origins=* and authenticated requests to the /api/v1/functions endpoint. Attackers can execute arbitrary code on the openwebui instance by crafting malicious cross-site requests from attacker-controlled websites when an admin user visits them. CVSSv3.1 8.3 (HIGH)

CWECWE 613TYPVulnerability
8.3
CVSS v3.1
92
Edit Score
2026-07-15
2026-07-15 10:16Z
HIGH

CVE-2026-57821 — SQL: A SQL Injection vulnerability exists in Apache Fineract's Office Search API (GET /api/v1/offices) in

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-57821

A SQL Injection vulnerability exists in Apache Fineract's Office Search API (GET /api/v1/offices) in versions up to and including 1.14.0. The orderBy request parameter is concatenated into a SQL query without sufficient validation, allowing an authenticated user with permission to view offices to inject arbitrary SQL via a crafted orderBy value. This is a bypass of the ColumnValidator fix introduced for CVE-2024-32838, which does not detect bare subqueries in the ORDER BY pos CVSSv3.1 8.1 (HIGH)

CWECWE 89TYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-07-15
2026-07-15 10:16Z
HIGH

CVE-2026-56287 — SQL: A boolean-based SQL Injection vulnerability exists in Apache Fineract's Client Search API (GET /api/v1/clients)

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-56287

A boolean-based SQL Injection vulnerability exists in Apache Fineract's Client Search API (GET /api/v1/clients) in versions up to and including 1.14.0. The orderBy and sortOrder request parameters are concatenated into a SQL query without sufficient validation, allowing an authenticated user with permission to view clients to inject arbitrary SQL via a crafted orderBy value. This can be leveraged to perform blind boolean-based data extraction and, on MySQL/MariaDB, to disclos CVSSv3.1 8.1 (HIGH)

CWECWE 89TYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-07-15
2026-07-15 10:16Z
HIGH

CVE-2026-35152 — SQL: A SQL Injection vulnerability exists in Apache Fineract's Report Execution API (runreports endpoint) in

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-35152

A SQL Injection vulnerability exists in Apache Fineract's Report Execution API (runreports endpoint) in versions up to and including 1.14.0. Report parameter values are incorporated into the generated SQL query without sufficient validation, allowing an authenticated user with permission to run reports to inject arbitrary SQL via crafted parameter values. This can be leveraged to perform unauthorized access to data beyond what the report was designed to expose. Users are reco CVSSv3.1 8.8 (HIGH)

CWECWE 89TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-07-15
2026-07-15 10:00Z
CRIT

OkoBot: new sophisticated malware framework targets cryptocurrency users

Kaspersky Securelist·securelist.comin the wild

Kaspersky disclosed OkoBot, a sophisticated modular malware framework actively targeting cryptocurrency users since January 2026. The framework comprises 20+ payloads delivered via TookPS downloader, SSH tunneling, and UAC bypass techniques, with specialized modules for stealing cryptocurrency wallet seed phrases from Ledger/Trezor, browser credential harvesting via malicious extensions, and comprehensive system surveillance. Initial infection vectors include ClickFix attacks and trojanized GitHub repositories masquerading as legitimate software (e.g., fake SSMS packages).

SRFApplicationSRFOsTACTA0005TACTA0001TACTA0002TACTA0006TACTA0007SRFWeb
88
Edit Score
2026-07-15
2026-07-15 08:16Z
HIGH

CVE-2026-15804 — HCM: The HCM developed by MetaGuru has a SQL Injection vulnerability.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-15804

The HCM developed by MetaGuru has a SQL Injection vulnerability. Authenticated remote attackers can inject SQL commands via specific parameters, thereby compromising the confidentiality, integrity, and availability of database data. CVSSv3.1 8.8 (HIGH)

CWECWE 89VNDHcmTYPVulnerability
8.8
CVSS v3.1
94
Edit Score