2026-07-14
2026-07-14 20:17Z
HIGH

CVE-2026-47992 — Adobe Commerce: is affected by an Improper Neutralization of Special Elements used in an

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-47992

Adobe Commerce is affected by an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability that could result in arbitrary code execution in the context of the current user. A high-privileged attacker could exploit this vulnerability to execute malicious SQL commands, potentially gaining elevated access or control over the victim's account or session. Exploitation of this issue does not require user interaction. CVSSv3.1 7.2 (HIGH) · EPSS 97th percentile

CWECWE 89VNDAdobeTYPVulnerability
7.2
CVSS v3.1
92
Edit Score
2026-07-14
2026-07-14 20:17Z
HIGH

CVE-2026-47988 — Adobe: Commerce is affected by an Incorrect Authorization vulnerability that could result in a

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-47988

Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass security measures and gain unauthorized read and write access. Exploitation of this issue does not require user interaction. CVSSv3.1 8.6 (HIGH)

CWECWE 863VNDAdobeTYPVulnerability
8.6
CVSS v3.1
93
Edit Score
2026-07-14
2026-07-14 20:17Z
HIGH

CVE-2026-47984 — Adobe: Commerce is affected by an Incorrect Authorization vulnerability that could result in a

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-47984

Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass security measures and gain unauthorized read and write access. Exploitation of this issue does not require user interaction. CVSSv3.1 8.2 (HIGH)

CWECWE 863VNDAdobeTYPVulnerability
8.2
CVSS v3.1
91
Edit Score
2026-07-14
2026-07-14 20:17Z
CRIT

CVE-2026-47429 — Vitest: Prior to 3.2.5 and 4.1.0, the Vitest UI/API server on Windows used isFileServingAllowed incorrectly

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-47429

Vitest is a testing framework powered by Vite. Prior to 3.2.5 and 4.1.0, the Vitest UI/API server on Windows used isFileServingAllowed incorrectly for /__vitest_attachment__, allowing \\?\\..\\ path traversal to read files outside the project; exposed API write and rerun features such as saveTestFile and rerun could also allow arbitrary script execution. This issue is fixed in versions 3.2.5 and 4.1.0. CVSSv3.1 9.8 (CRITICAL)

CWECWE 22VNDVitestTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-07-14
2026-07-14 20:17Z
CRIT

CVE-2026-47428 — Vitest: From 4.0.17 until 4.1.6 and 5.0.0-beta.3, Vitest Browser Mode served /__vitest_test__/ with the otelCarrier

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-47428

Vitest is a testing framework powered by Vite. From 4.0.17 until 4.1.6 and 5.0.0-beta.3, Vitest Browser Mode served /__vitest_test__/ with the otelCarrier query parameter inserted directly into an inline module script, allowing a crafted browser-runner URL to execute arbitrary JavaScript in the Vitest server origin and recover VITEST_API_TOKEN for authenticated API calls. This issue is fixed in versions 4.1.6 and 5.0.0-beta.3. CVSSv3.1 9.6 (CRITICAL)

CWECWE 79VNDVitestTYPVulnerability
9.6
CVSS v3.1
98
Edit Score
2026-07-14
2026-07-14 20:17Z
HIGH

CVE-2026-47423 — DOMPurify: In 3.4.4, DOMPurify allowed selectedcontent by default, allowing browsers to re-clone an XSS payload

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-47423

DOMPurify is a DOM-only cross-site scripting sanitizer for HTML, MathML, and SVG. In 3.4.4, DOMPurify allowed selectedcontent by default, allowing browsers to re-clone an XSS payload after sanitization so that unsanitized markup inside <selectedcontent> is returned. This issue is fixed in version 3.4.5. CVSSv3.1 8.2 (HIGH)

CWECWE 79VNDDompurifyTYPVulnerability
8.2
CVSS v3.1
91
Edit Score
2026-07-14
2026-07-14 20:16Z
HIGH

CVE-2026-15410 — Post: Post-authentication improper control of generation of code ('Code Injection') vulnerability has been identified in

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-15410in the wild

Post-authentication improper control of generation of code ('Code Injection') vulnerability has been identified in the SMA1000 Appliance Management Console (AMC) which in specific conditions could potentially enable a remote authenticated attacker as administrator to execute arbitrary OS commands. CVSSv3.1 7.2 (HIGH)

CWECWE 94VNDPostTYPVulnerabilitySTAitw exploited
7.2
CVSS v3.1
86
Edit Score
728 × 90 / responsive · programmatic ad slot
2026-07-14
2026-07-14 20:16Z
CRIT

CVE-2026-15409 — Server: A Server-side request forgery (SSRF) vulnerability has been identified in the SMA1000 Appliance Work

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-15409

A Server-side request forgery (SSRF) vulnerability has been identified in the SMA1000 Appliance Work Place interface. A remote unauthenticated attacker could potentially cause the appliance to make requests to unintended location. CVSSv3.1 10.0 (CRITICAL)

CWECWE 918TYPVulnerability
10.0
CVSS v3.1
100
Edit Score
2026-07-14
2026-07-14 20:16Z
CRIT

CVE-2026-13001 — Podlove: The Podlove Podcast Publisher plugin for WordPress is vulnerable to arbitrary file uploads due

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-13001

The Podlove Podcast Publisher plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'podlove_handle_cache_files' function in all versions up to, and including, 4.5.1. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code execution possible. CVSSv3.1 9.8 (CRITICAL)

CWECWE 20VNDPodloveTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-07-14
2026-07-14 19:52Z
HIGH

Hacking the Hackers: Can You Still Deceive an AI Attacker?

Horizon3.ai·horizon3.ai

Horizon3.ai conducted a controlled study testing 21 AI models across 10 providers against cyber deception techniques (honeypots, honeytokens, decoys), analyzing 10,962 attacker decisions. AI models fell for deception at 2x the rate of human red-teamers, but exhibited a 'recognition-action gap' where they identified traps in their own reasoning yet attacked anyway. The research challenges foundational assumptions about deception effectiveness and recommends shifting defensive strategies from misdirection to detection for AI-driven adversaries.

TACTA0001SRFAiVNDHorizon3TYPResearchSTGDefense Evasion
78
Edit Score
2026-07-14
2026-07-14 19:17Z
CRIT

CVE-2026-47767 — Sensiolabs Symfony: From 5.4.46 until 5.4.52, 6.4.40, 7.4.12, and 8.0.12, the CVE-2024-50340 fix gated runtime argv

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-47767

Symfony is a PHP framework for web and console applications and a set of reusable PHP components. From 5.4.46 until 5.4.52, 6.4.40, 7.4.12, and 8.0.12, the CVE-2024-50340 fix gated runtime argv parsing on empty($_GET), but parse_str() and the web SAPI can disagree, allowing a crafted query string to leave $_GET empty while $_SERVER['argv'] still carries attacker-controlled --env or --no-debug flags that change APP_ENV or APP_DEBUG. This issue is fixed in versions 5.4.52, 6.4. CVSSv3.1 9.8 (CRITICAL)

CWECWE 436VNDSensiolabsVNDSymfonyTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-07-14
2026-07-14 19:17Z
HIGH

CVE-2026-47304 — Improper verification of cryptographic signature in .NET allows an unauthorized attacker to bypass a

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-47304

Improper verification of cryptographic signature in .NET allows an unauthorized attacker to bypass a security feature over a network. CVSSv3.1 8.1 (HIGH)

CWECWE 345CWECWE 347TYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-07-14
2026-07-14 19:17Z
HIGH

CVE-2026-47303 — Authentication: bypass by assumed-immutable data in ASP.NET Core allows an authorized attacker to elevate

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-47303

Authentication bypass by assumed-immutable data in ASP.NET Core allows an authorized attacker to elevate privileges over a network. CVSSv3.1 8.8 (HIGH)

CWECWE 863CWECWE 90CWECWE 302TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-07-14
2026-07-14 19:17Z
HIGH

CVE-2026-47301 — Microsoft: Improper access control in Microsoft Configuration Manager allows an authorized attacker to elevate privileges

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-47301

Improper access control in Microsoft Configuration Manager allows an authorized attacker to elevate privileges over a network. CVSSv3.1 8.8 (HIGH)

CWECWE 284VNDMicrosoftTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-07-14
2026-07-14 19:17Z
HIGH

CVE-2026-47300 — Incorrect: implementation of authentication algorithm in ASP.NET Core allows an authorized attacker to elevate

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-47300

Incorrect implementation of authentication algorithm in ASP.NET Core allows an authorized attacker to elevate privileges over a network. CVSSv3.1 8.8 (HIGH)

CWECWE 303TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-07-14
2026-07-14 19:17Z
HIGH

CVE-2026-45075 — Sensiolabs Symfony: Prior to 7.4.12 and 8.0.12, method-scoped #[IsGranted], #[IsSignatureValid], and #[IsCsrfTokenValid] attributes can be configured

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-45075

Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 7.4.12 and 8.0.12, method-scoped #[IsGranted], #[IsSignatureValid], and #[IsCsrfTokenValid] attributes can be configured for GET only, but Symfony routes HEAD requests to the GET handler while the attribute check is skipped, allowing protected controllers to execute and leak headers or perform side effects. This issue is fixed in versions 7.4.12 and 8.0.12. CVSSv3.1 8.2 (HIGH)

CWECWE 863VNDSensiolabsVNDSymfonyTYPVulnerability
8.2
CVSS v3.1
91
Edit Score
2026-07-14
2026-07-14 19:17Z
CRIT

CVE-2026-45069 — Sensiolabs Symfony: Prior to 6.4.40, 7.4.12, and 8.0.12, OidcTokenHandler::verifyClaims() registered audience (aud), issuer (iss), and expiry

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-45069

Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 6.4.40, 7.4.12, and 8.0.12, OidcTokenHandler::verifyClaims() registered audience (aud), issuer (iss), and expiry (exp) checkers but did not pass the mandatory claims list to ClaimCheckerManager::check(), so a validly signed JWT that omitted those claims could pass verification. This issue is fixed in versions 6.4.40, 7.4.12, and 8.0.12. CVSSv3.1 9.1 (CRITICAL)

CWECWE 345CWECWE 1287VNDSensiolabsVNDSymfonyTYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2026-07-14
2026-07-14 19:17Z
CRIT

CVE-2026-45063 — Sensiolabs Symfony: Prior to 5.4.52, 6.4.40, 7.4.12, and 8.0.12, X509Authenticator extracts the user identifier from $_SERVER['SSL_CLIENT_S_DN']

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-45063

Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 5.4.52, 6.4.40, 7.4.12, and 8.0.12, X509Authenticator extracts the user identifier from $_SERVER['SSL_CLIENT_S_DN'] with an unanchored regex that matches emailAddress= anywhere in the distinguished name, allowing an attacker with a trusted certificate containing emailAddress=victim inside another RDN value such as CN to authenticate as the victim. This issue is fixed in CVSSv3.1 9.1 (CRITICAL)

CWECWE 290VNDSensiolabsVNDSymfonyTYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2026-07-14
2026-07-14 19:16Z
HIGH

CVE-2026-15720 — Open5GS: In Open5GS through version 2.7.7 a pre-authentication heap out-of-bounds read in the AMF NAS

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-15720

In Open5GS through version 2.7.7 a pre-authentication heap out-of-bounds read in the AMF NAS 5GS mobile-identity handler may result in subscriber-wide denial of service. CVSSv3.1 8.6 (HIGH)

CWECWE 125VNDOpen5gsTYPVulnerability
8.6
CVSS v3.1
93
Edit Score
2026-07-14
2026-07-14 18:18Z
HIGH

CVE-2026-58626 — Use: after free in Windows Remote Desktop Services allows an authorized attacker to execute

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-58626

Use after free in Windows Remote Desktop Services allows an authorized attacker to execute code over a network. CVSSv3.1 8.8 (HIGH)

CWECWE 416TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-07-14
2026-07-14 18:18Z
HIGH

CVE-2026-58617 — Microsoft: Improper access control in Microsoft 365 Copilot for iOS allows an unauthorized attacker to

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-58617

Improper access control in Microsoft 365 Copilot for iOS allows an unauthorized attacker to elevate privileges over a network. CVSSv3.1 8.1 (HIGH)

CWECWE 284VNDMicrosoftTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-07-14
2026-07-14 18:18Z
HIGH

CVE-2026-58594 — Integer: overflow or wraparound in Windows RDP allows an unauthorized attacker to execute code

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-58594

Integer overflow or wraparound in Windows RDP allows an unauthorized attacker to execute code over a network. CVSSv3.1 8.8 (HIGH)

CWECWE 190TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-07-14
2026-07-14 18:18Z
HIGH

CVE-2026-58534 — Heap: Heap-based buffer overflow in Microsoft Input Method Editor (IME) allows an authorized attacker to

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-58534

Heap-based buffer overflow in Microsoft Input Method Editor (IME) allows an authorized attacker to elevate privileges locally. CVSSv3.1 8.8 (HIGH)

CWECWE 122VNDHeapTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-07-14
2026-07-14 18:18Z
HIGH

CVE-2026-58277 — Microsoft: Improper authorization in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-58277

Improper authorization in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a network. CVSSv3.1 8.8 (HIGH)

CWECWE 285VNDMicrosoftTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-07-14
2026-07-14 18:18Z
HIGH

CVE-2026-57102 — Inclusion: of functionality from untrusted control sphere in Visual Studio Code allows an unauthorized

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-57102

Inclusion of functionality from untrusted control sphere in Visual Studio Code allows an unauthorized attacker to bypass a security feature over a network. CVSSv3.1 8.8 (HIGH)

CWECWE 200CWECWE 829VNDInclusionTYPVulnerability
8.8
CVSS v3.1
94
Edit Score