2026-07-08
2026-07-08 21:16Z
HIGH

CVE-2026-60105 — Monsta: An unauthenticated attacker can obtain a CSRF token from the public getSystemVars endpoint and

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-60105

Monsta FTP before 2.14.5 contains a server-side request forgery vulnerability in the fetchRemoteFile action caused by an incomplete IP blocklist check in the isBlockedIP() function, which fails to detect embedded IPv4 addresses within IPv4-mapped IPv6 addresses. An unauthenticated attacker can obtain a CSRF token from the public getSystemVars endpoint and submit a fetchRemoteFile request with a source URL resolving to an IPv4-mapped address, causing the server to issue HTTP r CVSSv3.1 8.6 (HIGH)

CWECWE 918VNDMonstaTYPVulnerability
8.6
CVSS v3.1
93
Edit Score
2026-07-08
2026-07-08 21:16Z
HIGH

CVE-2026-58525 — Microsoft: Improper access control in Microsoft Edge (Chromium-based) allows an unauthorized attacker to bypass a

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-58525

Improper access control in Microsoft Edge (Chromium-based) allows an unauthorized attacker to bypass a security feature over a network. CVSSv3.1 8.2 (HIGH)

CWECWE 284VNDMicrosoftTYPVulnerability
8.2
CVSS v3.1
91
Edit Score
2026-07-08
2026-07-08 21:16Z
HIGH

CVE-2026-58192 — Appium: Prior to 1.1.6, the Appium storage plugin exposes POST /storage/delete, whose handler passes the

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-58192

Appium is a cross-platform automation framework for all kinds of apps, built on top of the W3C WebDriver protocol. Prior to 1.1.6, the Appium storage plugin exposes POST /storage/delete, whose handler passes the user-supplied name value directly into path.join(storageRoot, name) and fs.rimraf() without path sanitization, allowing an unauthenticated remote client to escape the storage root with ../ sequences and recursively delete arbitrary writable files or directories. This CVSSv3.1 8.6 (HIGH)

CWECWE 22CWECWE 73VNDAppiumTYPVulnerability
8.6
CVSS v3.1
93
Edit Score
2026-07-08
2026-07-08 21:16Z
HIGH

CVE-2026-55596 — Plate: From 53.0.0 until 53.1.4, the media embed renderer trusts serialized provider or sourceUrl metadata

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-55596

Plate is a rich-text editor with AI and shadcn/ui. From 53.0.0 until 53.1.4, the media embed renderer trusts serialized provider or sourceUrl metadata in useMediaState and skips parseMediaUrl protocol validation, allowing a crafted Plate document to set a known video provider while keeping url as a javascript: iframe source that the registry MediaEmbedElement renders directly as an iframe src when a victim opens the document. This issue is fixed in version 53.1.4. CVSSv3.1 8.7 (HIGH)

CWECWE 79VNDPlateTYPVulnerability
8.7
CVSS v3.1
94
Edit Score
2026-07-08
2026-07-08 21:16Z
HIGH

CVE-2026-54591 — AsyncSSH: Prior to 2.23.1, a malicious SSH server can write arbitrary files on the asyncssh

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-54591

AsyncSSH is a Python package which provides an asynchronous client and server implementation of the SSHv2 protocol on top of the Python asyncio framework. Prior to 2.23.1, a malicious SSH server can write arbitrary files on the asyncssh SCP client's filesystem by sending filenames containing ../ traversal sequences because _parse_cd_args in scp.py returns server-provided names verbatim and _recv_files joins them to the destination path without enforcing the target directory b CVSSv3.1 8.1 (HIGH)

CWECWE 22VNDAsyncsshTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-07-08
2026-07-08 21:16Z
CRIT

CVE-2026-54527 — Jupyter Jupyterlab-git: From 0.30.0b3 before 0.54.0, the PlainTextDiff.ts createHeader() method passes Git filenames directly to innerHTML

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-54527

JupyterLab Git is a Git extension for JupyterLab. From 0.30.0b3 before 0.54.0, the PlainTextDiff.ts createHeader() method passes Git filenames directly to innerHTML when rendering renamed files in commit history, allowing a crafted filename to execute JavaScript when a victim views the rename diff in the Git History tab. This issue is fixed in version 0.54.0. CVSSv3.1 9.0 (CRITICAL) · EPSS 20th percentile

CWECWE 79VNDJupyterVNDJupyterlabTYPVulnerability
9.0
CVSS v3.1
95
Edit Score
2026-07-08
2026-07-08 20:17Z
HIGH

CVE-2026-60104 — Bitwarden: Server before 2026.6.0 does not verify that the email in a POST /auth-requests/admin-request

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-60104

Bitwarden Server before 2026.6.0 does not verify that the email in a POST /auth-requests/admin-request body belongs to the authenticated caller, allowing a low-privileged organization member to obtain another user's vault key and a victim-scoped access token by creating a Trusted Device Encryption authentication request, bound to an attacker-controlled public key, that is readable from an unauthenticated endpoint once approved resulting in disclosure of the victim's vault key CVSSv3.1 8.7 (HIGH)

CWECWE 639VNDBitwardenTYPVulnerability
8.7
CVSS v3.1
94
Edit Score
728 × 90 / responsive · programmatic ad slot
2026-07-08
2026-07-08 20:16Z
HIGH

CVE-2026-59822 — Litellm Litellm: Prior to 1.84.0, LiteLLM's MCP Streamable HTTP endpoint allowed an unauthenticated attacker to use

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-59822

LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. Prior to 1.84.0, LiteLLM's MCP Streamable HTTP endpoint allowed an unauthenticated attacker to use a fabricated Authorization header to trigger an OAuth2 passthrough fallback path that replaced failed LiteLLM key validation with an empty UserAPIKeyAuth() object, allowing requests to reach MCP tooling without a valid LiteLLM key. This issue is fixed in version 1.84.0. CVSSv3.1 8.2 (HIGH) · EPSS 20th percentile

CWECWE 306CWECWE 287VNDLitellmTYPVulnerability
8.2
CVSS v3.1
91
Edit Score
2026-07-08
2026-07-08 20:16Z
HIGH

CVE-2026-59802 — PasswordPusher: before 2.8.1 accepts data URI schemes in URL push payloads due to insufficient

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-59802

PasswordPusher before 2.8.1 accepts data URI schemes in URL push payloads due to insufficient validation in the valid_url function. Attackers can create malicious pushes containing data:text/html URIs that execute arbitrary JavaScript in victims' browsers when clicked, enabling phishing and credential theft under the trusted PasswordPusher domain. CVSSv3.1 8.2 (HIGH)

CWECWE 183VNDPasswordpusherTYPVulnerability
8.2
CVSS v3.1
91
Edit Score
2026-07-08
2026-07-08 20:16Z
HIGH

CVE-2026-58253 — NATS: Prior to 2.14.0, 2.12.7, and 2.11.16, when no_auth_user was configured, a parser fast path

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-58253

NATS Server is a high-performance server for NATS.io, the cloud and edge native messaging system. Prior to 2.14.0, 2.12.7, and 2.11.16, when no_auth_user was configured, a parser fast path intended for ordinary client connections could also apply to route or leafnode listeners, allowing an unauthenticated peer to bypass inter-server CONNECT authentication and operate with the privileges associated with that connection type. This issue is fixed in versions 2.14.0, 2.12.7, and CVSSv3.1 8.8 (HIGH)

CWECWE 287VNDNatsTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-07-08
2026-07-08 20:16Z
HIGH

CVE-2026-14891 — HashiCorp: Nomad and Nomad Enterprise are vulnerable to a sandbox escape in the Docker

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-14891

HashiCorp Nomad and Nomad Enterprise are vulnerable to a sandbox escape in the Docker task driver that may allow a job submitter to bind-mount a host path into a container even when volume bind mounts are disabled, potentially leading to reading and writing files on the host. This vulnerability, CVE-2026-14891, is fixed in Nomad Community Edition 2.0.4 and Nomad Enterprise 2.0.4, 1.11.8, and 1.10.14. CVSSv3.1 8.7 (HIGH)

CWECWE 59VNDHashicorpTYPVulnerability
8.7
CVSS v3.1
94
Edit Score
2026-07-08
2026-07-08 17:17Z
HIGH

CVE-2026-60102 — Horde: Virtual File System (VFS) API before 3.0.1 contains an OS command injection vulnerability

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-60102

Horde Virtual File System (VFS) API before 3.0.1 contains an OS command injection vulnerability in the Horde_Vfs_Smb driver where the _escapeShellCommand() method fails to sanitize command substitution sequences, allowing authenticated attackers to inject arbitrary shell commands through user-controlled filenames. Attackers can supply malicious filenames containing unescaped command substitution payloads through operations such as file upload, folder creation, rename, or dele CVSSv3.1 8.8 (HIGH)

CWECWE 78VNDHordeTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-07-08
2026-07-08 17:17Z
HIGH

CVE-2026-59731 — Astro: Version 6.4.7 performs authorization decisions on a partially decoded pathname after reaching the iterative

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-59731

Astro is a web framework for content-driven websites. Version 6.4.7 performs authorization decisions on a partially decoded pathname after reaching the iterative URL decoder limit, while later rewrite route matching performs an additional decodeURI() operation and can resolve the request to a protected route. This issue is fixed in version 6.4.8. CVSSv3.1 8.2 (HIGH)

CWECWE 647VNDAstroTYPVulnerability
8.2
CVSS v3.1
91
Edit Score
2026-07-08
2026-07-08 17:17Z
HIGH

CVE-2026-29009 — Boot: U-Boot through 2026.04-rc3 contains a buffer overflow vulnerability in nfs_readlink_reply() (net/nfs-common.c) when CONFIG_CMD_NFS is

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-29009

U-Boot through 2026.04-rc3 contains a buffer overflow vulnerability in nfs_readlink_reply() (net/nfs-common.c) when CONFIG_CMD_NFS is enabled, allowing a malicious or compromised NFS server to overflow the 2048-byte nfs_path_buff buffer by returning multiple relative symlink targets that are appended without cumulative length validation. Attackers can send two or more READLINK responses containing relative symlink targets of approximately 1100 bytes each to corrupt adjacent B CVSSv3.1 8.2 (HIGH)

CWECWE 120VNDBootTYPVulnerability
8.2
CVSS v3.1
91
Edit Score
2026-07-08
2026-07-08 17:00Z
CRIT

CVE-2026-9181 | Esri ArcGIS Server Pre-Authentication Path Traversal Vulnerability

Horizon3.ai·horizon3.aiCVE-2026-9181

CVE-2026-9181 is a critical pre-authentication path traversal vulnerability in Esri ArcGIS Server 12.0 and prior, affecting the REST Uploads resource. An unauthenticated attacker can craft malicious itemName parameters to traverse directory boundaries and access sensitive files. Esri released a patch (ArcGIS Server Security 2026 Update 2) on May 27, 2026, with a CVSS 9.8 base score.

SRFWebSWArcgisVNDEsriTYPVulnerabilityEXPPath TraversalSTApatched
78
Edit Score
2026-07-08
2026-07-08 16:16Z
CRIT

CVE-2026-9074 — IBM: API Connect 10.0.8.0 through 10.0.8.9 and 12.1.0.0 through 12.1.0.3 contains an unauthenticated SQL

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-9074

IBM API Connect 10.0.8.0 through 10.0.8.9 and 12.1.0.0 through 12.1.0.3 contains an unauthenticated SQL injection vulnerability in the password reset functionality. CVSSv3.1 9.1 (CRITICAL)

CWECWE 89VNDIbmTYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2026-07-08
2026-07-08 16:16Z
CRIT

CVE-2026-59702 — repomix contains a server-side request forgery vulnerability in the POST /api/pack endpoint that allows

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-59702

repomix contains a server-side request forgery vulnerability in the POST /api/pack endpoint that allows unauthenticated attackers to make arbitrary outbound requests. The endpoint fails to properly validate http://, https://, and file:// URLs before passing them to git clone, enabling attackers to access private network addresses, GCP metadata services, or local filesystem paths. CVSSv3.1 9.3 (CRITICAL)

CWECWE 918TYPVulnerability
9.3
CVSS v3.1
97
Edit Score
2026-07-08
2026-07-08 16:16Z
HIGH

CVE-2026-3144 — IBM: API Connect 12.1.0.0 through 12.1.0.3 uses default credentials which could allow an attacker

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-3144

IBM API Connect 12.1.0.0 through 12.1.0.3 uses default credentials which could allow an attacker to gain unauthorized access to the application before the system enforces a credential update. CVSSv3.1 8.1 (HIGH)

CWECWE 1392VNDIbmTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-07-08
2026-07-08 16:00Z
INFO

Building a Mental Model for Kubernetes Security Research

SpecterOps·specterops.io

SpecterOps researcher Hector Riestra presents a mental model and framework for analyzing Kubernetes and Azure Kubernetes Service (AKS) security posture by decomposing cluster architecture into nine analytical lenses: cluster control, credential retrieval, authentication, authorization, admission, workload management, data/storage, computing, and networking. The framework uses YAML specifications and Terraform to deliberately construct and study cluster scenarios, enabling systematic exploration of how identity, access, and control mechanisms interact in production environments.

TACTA0001SRFIdentityTACTA0003SRFCloudSWKubernetesSWAzure Kubernetes ServiceVNDMicrosoftTYPResearch
78
Edit Score
2026-07-08
2026-07-08 15:16Z
HIGH

CVE-2026-54652 — Frigate: In version 0.17.1, the GET /api/logs/{service} endpoint allows any authenticated user including the viewer

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-54652

Frigate is an open source network video recorder. In version 0.17.1, the GET /api/logs/{service} endpoint allows any authenticated user including the viewer role to download Frigate and nginx logs, exposing auto-generated admin passwords and camera credentials logged in request query strings and enabling viewer-to-admin privilege escalation. A fixed release has not been identified. CVSSv3.1 8.1 (HIGH)

CWECWE 269CWECWE 863CWECWE 532CWECWE 598VNDFrigateTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-07-08
2026-07-08 15:16Z
HIGH

CVE-2026-24698 — An OS command injection vulnerability exists in the save_syslog_to_file() function of the "httpd" binary

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-24698

An OS command injection vulnerability exists in the save_syslog_to_file() function of the "httpd" binary in Cisco RV130/RV130W with firmware 1.0.3.55 and RV110W routers with firmware 1.2.2.5 / 1.2.2.8. The model_name configuration parameter is not properly sanitized, which could allow an authenticated remote attacker to execute arbitrary OS commands with root privileges. CVSSv3.1 8.8 (HIGH)

CWECWE 78TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-07-08
2026-07-08 15:16Z
HIGH

CVE-2026-15067 — Snowflake: Terraform Provider versions prior to 2.18.0 contain several security vulnerabilities, including SQL injection

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-15067

Snowflake Terraform Provider versions prior to 2.18.0 contain several security vulnerabilities, including SQL injection via an unsanitized data source input could result in arbitrary SQL execution under the provider's privileged Snowflake session, potentially enabling sensitive data exfiltration and minting of long-lived access credentials. Exploitation requires the ability for an attacker to influence a workspace variable in a pipeline where this data source was enabled. Im CVSSv3.1 8.8 (HIGH)

CWECWE 89VNDSnowflakeTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-07-08
2026-07-08 15:16Z
CRIT

CVE-2026-15062 — SQL: injection vulnerabilities in the Snowflake Snowpark Python SDK (snowpark-python) versions prior to 1.53.0

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-15062

SQL injection vulnerabilities in the Snowflake Snowpark Python SDK (snowpark-python) versions prior to 1.53.0 could allow authenticated low-privilege users to execute SQL beyond their authorization scope. An attacker could exploit these vulnerabilities by embedding SQL payloads in source database column names to escalate privileges via the DataFrameReader.dbapi() API by supplying a specially crafted location parameter to DataFrameWriter write methods to redirect a COPY INTO t CVSSv3.1 9.6 (CRITICAL)

CWECWE 89TYPVulnerability
9.6
CVSS v3.1
98
Edit Score
2026-07-08
2026-07-08 15:16Z
HIGH

CVE-2026-11903 — Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Progress MOVEit

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-11903

Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Progress MOVEit Transfer (Ad Hoc module). This issue affects MOVEit Transfer: from 2026.0.0 before 2026.0.1, from 2025.1.0 before 2025.1.4, from 2025.0.0 before 2025.0.8. CVSSv3.1 8.0 (HIGH)

CWECWE 79TYPVulnerability
8.0
CVSS v3.1
90
Edit Score
2026-07-08
2026-07-08 14:17Z
HIGH

CVE-2026-59257 — N8n N8n: before 1.123.61, 2.x before 2.27.4, and 2.28.x before 2.28.1 contains a SQL injection

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-59257

n8n before 1.123.61, 2.x before 2.27.4, and 2.28.x before 2.28.1 contains a SQL injection vulnerability in the legacy MySQL v1 node's executeQuery operation. The operation substitutes evaluated {{ ... }} expression values directly into the raw SQL string without parameterization. When a workflow uses this operation with expression-sourced values and is connected to an externally-reachable trigger (such as a Webhook node), attacker-controlled input reaching those expressions r CVSSv3.1 8.8 (HIGH)

CWECWE 89VNDN8nTYPVulnerability
8.8
CVSS v3.1
94
Edit Score