2026-07-14
2026-07-14 09:16Z
CRIT

CVE-2026-59083 — Handling: Improper Handling of URL Encoding (Hex Encoding) vulnerability in Apache Tomcat's rewrite valve allowed

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-59083

Improper Handling of URL Encoding (Hex Encoding) vulnerability in Apache Tomcat's rewrite valve allowed security constraint bypass for some configurations. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.23, from 10.1.0-M1 through 10.1.56, from 9.0.0.M1 through 9.0.119, from 8.5.0 through 8.5.100. Other versions that have reached end of support may also be affected. Users are recommended to upgrade to version 11.0.24, 10.1.57 or 9.0.120, which fix the issue. CVSSv3.1 9.1 (CRITICAL)

CWECWE 177VNDHandlingTYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2026-07-14
2026-07-14 09:16Z
CRIT

CVE-2026-57898 — Eclipse: In Eclipse BaSyx Java Server SDK versions 2.0.0-milestone-05 to 2.0.0-milestone-12, deployments using the MongoDB

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-57898

In Eclipse BaSyx Java Server SDK versions 2.0.0-milestone-05 to 2.0.0-milestone-12, deployments using the MongoDB backend are vulnerable to an unauthenticated arbitrary file write through the AAS thumbnail API. The AAS thumbnail upload path accepted a client-controlled fileName request parameter and passed it through repository file handling as both a repository key and, during thumbnail retrieval, a local filesystem path. With the MongoDB file repository, the supplied fi CVSSv3.1 9.0 (CRITICAL)

CWECWE 22CWECWE 73VNDEclipseTYPVulnerability
9.0
CVSS v3.1
95
Edit Score
2026-07-14
2026-07-14 09:16Z
HIGH

CVE-2026-15416 — Argo: A flaw was identified in Argo CD, the GitOps engine used by Red Hat

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-15416

A flaw was identified in Argo CD, the GitOps engine used by Red Hat OpenShift GitOps, that could allow an unauthenticated attacker with network access to the Argo CD repo-server to achieve remote code execution. Under certain conditions, the attacker may then manipulate cached data to deploy malicious Kubernetes resources to managed clusters, potentially resulting in complete cluster compromise. CVSSv3.1 8.9 (HIGH)

CWECWE 306VNDArgoTYPVulnerability
8.9
CVSS v3.1
95
Edit Score
2026-07-14
2026-07-14 06:17Z
HIGH

CVE-2026-12583 — Newsletters: The Newsletters WordPress plugin before 4.15 does not prevent deserialization of untrusted input that

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-12583

The Newsletters WordPress plugin before 4.15 does not prevent deserialization of untrusted input that is stored through a public form, allowing unauthenticated attackers to inject a PHP object and, via a property-oriented gadget chain bundled with the Newsletters WordPress plugin before 4.15, write arbitrary files and execute code on the server. CVSSv3.1 8.1 (HIGH)

CWECWE 502VNDNewslettersTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-07-14
2026-07-14 06:17Z
HIGH

CVE-2026-12511 — Engine: The AI Engine WordPress plugin before 3.5.5 does not sanitize a user-supplied filename before

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-12511

The AI Engine WordPress plugin before 3.5.5 does not sanitize a user-supplied filename before using it to write a downloaded file, allowing authenticated users with editor-level access to write attacker-controlled bytes to an arbitrary location on the server via path traversal. CVSSv3.1 8.1 (HIGH)

VNDEngineTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-07-14
2026-07-14 06:16Z
CRIT

CVE-2026-11563 — Word: The Word Count and Social Shares WordPress plugin through 1.0 does not validate a

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-11563

The Word Count and Social Shares WordPress plugin through 1.0 does not validate a user-supplied file path before deletion, nor does it have proper authorization or CSRF checks, allowing any authenticated user, such as a Subscriber, to delete arbitrary files on the server, which can lead to a full site takeover (e.g. by deleting wp-config.php). CVSSv3.1 9.6 (CRITICAL)

VNDWordTYPVulnerability
9.6
CVSS v3.1
98
Edit Score
2026-07-14
2026-07-14 01:16Z
CRIT

CVE-2026-44761 — SAP: Successful exploitation results in high impact on confidentiality and integrity, with no impact on

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-44761

SAP Commerce Cloud could retain a sample OAuth2 client with publicly documented sample credentials originating from sample configuration provided in SAP Help Portal documentation. If left unchanged, an unauthenticated attacker could use these well-known credentials to obtain a valid access token and invoke certain APIs to read and modify data. Successful exploitation results in high impact on confidentiality and integrity, with no impact on availability. CVSSv3.1 9.1 (CRITICAL)

CWECWE 1392VNDSapTYPVulnerability
9.1
CVSS v3.1
96
Edit Score
728 × 90 / responsive · programmatic ad slot
2026-07-14
2026-07-14 01:16Z
HIGH

CVE-2026-44752 — SAP: NetWeaver Application Server Java allows an unauthenticated attacker to inject malicious JavaScript through

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-44752

SAP NetWeaver Application Server Java allows an unauthenticated attacker to inject malicious JavaScript through crafted URLs. When a victim accesses such a URL, the script executes in the user's browser, allowing the attacker to access sensitive session information and modify non-sensitive data displayed in the client�s browser. This results in a high impact on confidentiality, low impact on integrity with no impact on availability of the application. CVSSv3.1 8.2 (HIGH)

CWECWE 79VNDSapTYPVulnerability
8.2
CVSS v3.1
91
Edit Score
2026-07-14
2026-07-14 01:16Z
CRIT

CVE-2026-44747 — SAP: NetWeaver Application Server ABAP allows an authenticated attacker to leverage logical errors in

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-44747

SAP NetWeaver Application Server ABAP allows an authenticated attacker to leverage logical errors in memory management to cause a memory corruption that could lead to unauthorized data access, modification, or system unavailability. This has high impact on confidentiality, integrity, and availability of the application. CVSSv3.1 9.9 (CRITICAL)

CWECWE 787VNDSapTYPVulnerability
9.9
CVSS v3.1
100
Edit Score
2026-07-14
2026-07-14 01:16Z
HIGH

CVE-2026-44745 — SAP: This allows an unauthenticated remote attacker to craft a malicious link which, when clicked

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-44745

SAP Approuter does not properly validate incoming request headers during the OAuth2 login flow under certain configurations. This allows an unauthenticated remote attacker to craft a malicious link which, when clicked by a victim, could lead to unauthorized access. Successful exploitation results in a high impact to the confidentiality and integrity with no impact on the availability of the application. CVSSv3.1 8.1 (HIGH)

CWECWE 601VNDSapTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-07-14
2026-07-14 01:16Z
CRIT

CVE-2026-27690 — HTTP: Due to an HTTP Request Smuggling vulnerability in SAP Approuter, an unauthenticated attacker could

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-27690

Due to an HTTP Request Smuggling vulnerability in SAP Approuter, an unauthenticated attacker could send a specially crafted HTTP request that leads to request-response desynchronization. This could result in the exposure of user responses and cause the system to become unavailable. This leads to a high impact on confidentiality and availability. CVSSv3.1 9.1 (CRITICAL)

CWECWE 444VNDHttpTYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2026-07-14
2026-07-14 01:16Z
HIGH

CVE-2026-0487 — SAProuter: on Microsoft Windows allows an unauthenticated attacker to load library (DLL) files from

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-0487

SAProuter on Microsoft Windows allows an unauthenticated attacker to load library (DLL) files from an untrusted location, allowing them to execute malicious code on the system. This could enable the attacker to hijack the DLL loading process and achieve arbitrary code execution. This has high impact on confidentiality, integrity and availability of the system. CVSSv3.1 8.4 (HIGH)

CWECWE 427VNDSaprouterTYPVulnerability
8.4
CVSS v3.1
92
Edit Score
2026-07-14
2026-07-14 00:00Z
CRIT

Six Minutes to Compromise: How ‘Patriot Bait’ Actor Used AI to Build and Deploy a C&C Botnet

Trend Micro Research·trendmicro.comin the wild

Trend Micro Research analyzed 200 Gemini CLI session logs from a Russian-speaking threat actor ('bandcampro') who used Google's AI to build, deploy, and operate a live C&C botnet in six minutes, with the actor contributing only 11% of the work while AI handled architecture, coding, deployment, and debugging. The entire operation is encoded in three portable plain-text files (~5KB), making it trivially replicable and shareable; the actor also leveraged AI for password cracking, WordPress compromise, and cryptocurrency fraud planning. The research demonstrates how AI-assisted infrastructure becomes disposable and operator-replaceable, fundamentally shifting the threat landscape by lowering barriers to entry for malicious C&C operations.

SRFApplicationSRFNetworkTACTA0006TACTA0007TACTA0003TACTA0011VNDGoogleVNDTrend Micro
92
Edit Score
2026-07-13
2026-07-13 23:16Z
CRIT

CVE-2026-58102 — Crypt: Crypt::OpenSSL::X509 versions before 2.1.3 for Perl allow a heap out-of-bounds read via a long

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-58102

Crypt::OpenSSL::X509 versions before 2.1.3 for Perl allow a heap out-of-bounds read via a long certificate extension OID in hv_exts. When building the extension hash (via extensions(), extensions_by_long_name(), extensions_by_oid(), or has_extension_oid()), the code passes OBJ_obj2txt()'s return value as the hash-key length; because that value is the OID's full text length rather than the bytes written to the fixed-size buffer (129 bytes), an OID whose text is longer than th CVSSv3.1 9.1 (CRITICAL)

CWECWE 125VNDCryptTYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2026-07-13
2026-07-13 23:16Z
HIGH

CVE-2026-57856 — Cockpit: CMS contains a path traversal vulnerability in the Bucket file storage API (/system/buckets/api).

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-57856

Cockpit CMS contains a path traversal vulnerability in the Bucket file storage API (/system/buckets/api). The api() method in modules/System/Controller/Buckets.php sanitizes the bucket name with preg_replace('/[^a-zA-Z0-9-_\\.]/','', $bucket), which permits '..' and '../' sequences. The sanitized value is interpolated into a Flysystem path as uploads://buckets/{bucket}. Flysystem's WhitespacePathNormalizer resolves 'buckets/..' to the empty string (the uploads storage root) w CVSSv3.1 8.8 (HIGH)

CWECWE 22VNDCockpitTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-07-13
2026-07-13 23:16Z
HIGH

CVE-2026-57855 — Cockpit: CMS contains a missing authorization vulnerability in the Bucket file storage API (/system/buckets/api).

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-57855

Cockpit CMS contains a missing authorization vulnerability in the Bucket file storage API (/system/buckets/api). The api() method in modules/System/Controller/Buckets.php executes bucket commands (ls, upload, removefiles, rename, createfolder) without performing any ACL or role check. Any authenticated user, regardless of role, can perform all bucket operations on any named bucket, including buckets intended for admin use only. CVSSv3.1 8.8 (HIGH)

CWECWE 284VNDCockpitTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-07-13
2026-07-13 22:16Z
CRIT

CVE-2026-62327 — 9Router through version 0.4.41 contain an unauthenticated information disclosure vulnerability that allows remote attackers

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-62327

9Router through version 0.4.41 contain an unauthenticated information disclosure vulnerability that allows remote attackers to retrieve plaintext API keys for all connected AI provider accounts by sending a single unauthenticated request to the /api/usage/stats endpoint. Attackers can exploit the missing authentication middleware on the Next.js API route to obtain full API key strings alongside token counts, cost breakdowns, and request metadata, enabling unauthorized use of CVSSv3.1 9.1 (CRITICAL)

CWECWE 306CWECWE 522TYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2026-07-13
2026-07-13 22:16Z
HIGH

CVE-2026-62242 — Spring: Boot Admin Server before 4.1.2 contains a server-side request forgery vulnerability that allows

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-62242

Spring Boot Admin Server before 4.1.2 contains a server-side request forgery vulnerability that allows unauthenticated attackers to register instances with attacker-controlled healthUrl and managementUrl parameters without validation against private IP ranges or metadata endpoints. Attackers can force the server to make HTTP requests to arbitrary internal addresses and retrieve response bodies via the actuator proxy to exfiltrate cloud credentials. CVSSv3.1 8.6 (HIGH)

CWECWE 918VNDSpringTYPVulnerability
8.6
CVSS v3.1
93
Edit Score
2026-07-13
2026-07-13 22:16Z
HIGH

CVE-2026-62200 — OpenClaw: versions before 2026.6.1 contain a flaw in host exec environment filtering that could

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-62200

OpenClaw versions before 2026.6.1 contain a flaw in host exec environment filtering that could allow Git ext transport to be abused. When the affected feature is enabled and reachable, a lower-trust caller or configured input path could execute or persist actions beyond the caller's intended authorization. CVSSv3.1 8.8 (HIGH)

CWECWE 184VNDOpenclawTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-07-13
2026-07-13 22:16Z
HIGH

CVE-2026-62199 — OpenClaw: versions before 2026.6.6 contain a flaw in host exec environment filtering that can

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-62199

OpenClaw versions before 2026.6.6 contain a flaw in host exec environment filtering that can miss interpreter startup variables. When the affected feature is enabled and reachable, a lower-trust caller or configured input path can supply crafted environment variables to execute or persist actions beyond the caller's intended authorization. CVSSv3.1 8.8 (HIGH)

CWECWE 184VNDOpenclawTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-07-13
2026-07-13 22:16Z
HIGH

CVE-2026-62197 — OpenClaw: before 2026.6.6 contains a policy bypass vulnerability in browser CDP discovery that accepts

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-62197

OpenClaw before 2026.6.6 contains a policy bypass vulnerability in browser CDP discovery that accepts blocked WebSocket URLs. Attackers with lower-trust access can reach network destinations that should have been blocked by OpenClaw policy when the affected feature is enabled. CVSSv3.1 8.5 (HIGH)

CWECWE 918VNDOpenclawTYPVulnerability
8.5
CVSS v3.1
93
Edit Score
2026-07-13
2026-07-13 22:16Z
HIGH

CVE-2026-62196 — OpenClaw: versions 2026.3.22 before 2026.6.6 contain an authorization bypass vulnerability where WhatsApp group IDs

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-62196

OpenClaw versions 2026.3.22 before 2026.6.6 contain an authorization bypass vulnerability where WhatsApp group IDs can satisfy elevated sender allowlists. Attackers with lower-trust access can perform actions requiring stronger authorization by leveraging group ID validation in the affected feature. CVSSv3.1 8.3 (HIGH)

CWECWE 863VNDOpenclawTYPVulnerability
8.3
CVSS v3.1
92
Edit Score
2026-07-13
2026-07-13 22:16Z
HIGH

CVE-2026-62195 — OpenClaw: versions 2026.5.20 before 2026.6.6 contain an authorization bypass vulnerability in the MCP loopback

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-62195

OpenClaw versions 2026.5.20 before 2026.6.6 contain an authorization bypass vulnerability in the MCP loopback feature that allows lower-trust callers to execute owner-only tools. Attackers can bypass authorization checks through configured input paths to execute or persist actions beyond their intended permissions. CVSSv3.1 8.3 (HIGH)

CWECWE 732VNDOpenclawTYPVulnerability
8.3
CVSS v3.1
92
Edit Score
2026-07-13
2026-07-13 22:16Z
HIGH

CVE-2026-62194 — OpenClaw: versions 2026.5.20 before 2026.6.9 contain a privilege escalation vulnerability in plugin install commands

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-62194

OpenClaw versions 2026.5.20 before 2026.6.9 contain a privilege escalation vulnerability in plugin install commands that allows lower-trust callers to execute or persist actions beyond their intended authorization. Attackers can exploit misconfigured input paths or enabled features to escalate privileges and perform unauthorized actions when the feature is reachable. CVSSv3.1 8.8 (HIGH)

CWECWE 862CWECWE 732VNDOpenclawTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-07-13
2026-07-13 22:16Z
HIGH

CVE-2026-62192 — OpenClaw: versions 2026.6.6 before 2026.6.9 contain an authorization bypass vulnerability in Discord guild actions

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-62192

OpenClaw versions 2026.6.6 before 2026.6.9 contain an authorization bypass vulnerability in Discord guild actions that allows lower-trust callers to perform actions requiring stronger authorization checks. Attackers can exploit misconfigured input paths to skip cross-provider requester authorization and execute restricted operations. CVSSv3.1 8.1 (HIGH)

CWECWE 863VNDOpenclawTYPVulnerability
8.1
CVSS v3.1
91
Edit Score