2026-07-08
2026-07-08 01:16Z
CRIT

CVE-2026-56843 — Incorrect: authorization in the XML-RPC API of WebPros Plesk before 18.0.78.4 allows a low-privileged

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-56843

Incorrect authorization in the XML-RPC API of WebPros Plesk before 18.0.78.4 allows a low-privileged authenticated customer to look up domains they do not own, because ownership is enforced only for certain lookup filters and schema validation is bypassed for legacy protocol versions. This results in cross-tenant disclosure of other tenants' FTP credentials stored in cleartext, which can be leveraged to execute code as another tenant's system user. CVSSv3.1 9.9 (CRITICAL)

CWECWE 522TYPVulnerability
9.9
CVSS v3.1
100
Edit Score
2026-07-08
2026-07-08 00:16Z
HIGH

CVE-2026-55429 — Coder: allows organizations to provision remote development environments via Terraform.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-55429

Coder allows organizations to provision remote development environments via Terraform. Prior to versions 2.29.7, 2.32.7, 2.33.8, and 2.34.2, `UpsertWorkspaceApp` overwrites an existing app's `agent_id` on a primary-key conflict and `insertAgentApp` accepts the app ID from the provisioner's `CompleteJob` payload without verifying it belongs to the workspace being built. `CompleteJob` runs under `dbauthz.AsProvisionerd` so the authorization layer does not block the cross-worksp CVSSv3.1 8.7 (HIGH)

CWECWE 639VNDCoderTYPVulnerability
8.7
CVSS v3.1
94
Edit Score
2026-07-08
2026-07-08 00:16Z
HIGH

CVE-2026-55428 — Coder: allows organizations to provision remote development environments via Terraform.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-55428

Coder allows organizations to provision remote development environments via Terraform. Prior to versions 2.29.7, 2.32.7, 2.33.8, and 2.34.2, the tailnet coordinator validates that an agent's `Addresses` derive from its authenticated UUID but applies no equivalent check to `AllowedIPs`. The coordinator forwards agent-supplied `AllowedIPs` verbatim to tunnel peers which install them into the WireGuard peer configuration. The fix in versions 2.29.7, 2.32.7, 2.33.8, and 2.34.2 va CVSSv3.1 8.2 (HIGH)

CWECWE 285CWECWE 863VNDCoderTYPVulnerability
8.2
CVSS v3.1
91
Edit Score
2026-07-08
2026-07-08 00:16Z
HIGH

CVE-2026-55427 — Coder: allows organizations to provision remote development environments via Terraform.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-55427

Coder allows organizations to provision remote development environments via Terraform. Prior to versions 2.29.7, 2.32.7, 2.33.8, and 2.34.2, `coder config-ssh` wrote server-supplied SSH settings (`HostnameSuffix`, `SSHConfigOptions`) into the user's `~/.ssh/config` without sanitizing embedded newlines or restricting directives so a malicious or compromised Coder server could inject arbitrary SSH configuration. Practical exploitation requires control of the server-supplied val CVSSv3.1 8.3 (HIGH)

CWECWE 74CWECWE 78VNDCoderTYPVulnerability
8.3
CVSS v3.1
92
Edit Score
2026-07-08
2026-07-08 00:00Z
CRIT

ClickFix to Cash-Out: Anatomy of a Mexican Banking-Fraud Toolkit

Elastic Security Labs·elastic.coin the wild

Elastic Security Labs disclosed REF6045, an active operator-assisted banking fraud campaign targeting Mexican financial institutions using SCMBANKER, a PowerShell toolkit delivered via ClickFix fake-CAPTCHA pages. The malware provides operators with banking-session monitoring, vishing overlays, clipboard hijacking, phishing redirects, and silent Remote Utilities RAT installation, with evidence of AI-assisted code generation and multiple OPSEC failures exposing the full operation's infrastructure and targeting logic.

SRFApplicationTACTA0005TACTA0001TACTA0002TACTA0006TACTA0007SRFWebTACTA0003
92
Edit Score
2026-07-08
2026-07-08 00:00Z
CRIT

ClickFix to Cash-Out: Anatomy of a Mexican Banking-Fraud Toolkit

Elastic Security Labs·elastic.coin the wild

Elastic Security Labs disclosed REF6045, an active operator-assisted banking fraud campaign targeting Mexican financial institutions using a ClickFix-delivered PowerShell toolkit called SCMBANKER. The malware chains fake CAPTCHA pages, UAC consent fatigue, mouse-locking, and clipboard hijacking to enable vishing overlays, phishing redirects, and silent Remote Utilities RAT installation. Operator OPSEC failures exposed the full web root, revealing targeting logic, C2 infrastructure, and AI-generated code artifacts dating back to October 2025.

SRFApplicationTACTA0005TACTA0001TACTA0002TACTA0006TACTA0007SRFWebTACTA0003
92
Edit Score
2026-07-07
2026-07-07 23:16Z
CRIT

CVE-2026-59705 — mem0's openmemory/api component contains an unauthenticated access vulnerability that allows unauthenticated attackers to read

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-59705

mem0's openmemory/api component contains an unauthenticated access vulnerability that allows unauthenticated attackers to read, write, and delete arbitrary user memories by accessing API routers registered without authentication middleware. Attackers can supply arbitrary user_id parameters or directly access memory retrieval endpoints to expose private memory content, or invoke pause endpoints with global_pause=true to cause denial-of-service across all users. CVSSv3.1 9.8 (CRITICAL)

CWECWE 306TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
728 × 90 / responsive · programmatic ad slot
2026-07-07
2026-07-07 23:16Z
CRIT

CVE-2026-37271 — Fire: Fire-Boltt Smartwatch FB BGS001 Firmware: MOY-JS14-2.0.4 is vulnerable to Improper Authentication, The device accepts

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-37271

Fire-Boltt Smartwatch FB BGS001 Firmware: MOY-JS14-2.0.4 is vulnerable to Improper Authentication, The device accepts GATT Write Request commands without sufficient authentication or strong session validation. Under specific conditions, previously captured BLE packets can be replayed from a nearby device to trigger functionality on the smartwatch. CVSSv3.1 9.8 (CRITICAL)

CWECWE 287VNDFireTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-07-07
2026-07-07 23:16Z
CRIT

CVE-2026-37270 — Trueview: Security camera T18161- AF v4.9.60.0 contains an authentication bypass vulnerability caused by improper

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-37270

Trueview Security camera T18161- AF v4.9.60.0 contains an authentication bypass vulnerability caused by improper password validation and the presence of hard-coded credentials in the firmware. CVSSv3.1 9.8 (CRITICAL)

CWECWE 287CWECWE 798VNDTrueviewTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-07-07
2026-07-07 23:16Z
CRIT

CVE-2026-14740 — DBI: versions before 1.650 for Perl read one byte out-of-bounds in preparse when deleting

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-14740

DBI versions before 1.650 for Perl read one byte out-of-bounds in preparse when deleting an initial SQL comment. The preparse method normalises SQL and removes comments. When the SQL starts with a comment line, the deletion of that line during normalisation led to an out-of-bounds read by one byte. The result is a fault on memory-hardened builds and nondeterministic newline retention on normal builds. CVSSv3.1 9.1 (CRITICAL)

CWECWE 125VNDDbiTYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2026-07-07
2026-07-07 23:16Z
CRIT

CVE-2026-14739 — DBI: versions before 1.650 for Perl have a heap overflow when preparsing SQL statements

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-14739

DBI versions before 1.650 for Perl have a heap overflow when preparsing SQL statements with an extreme number of placeholders. The fix for CVE-2026-10879 did not allocate enough memory to handle approximately 1.2-million placeholders. DBI version 1.650 sets a hard limit of 99,999 placeholders. CVSSv3.1 9.8 (CRITICAL)

CWECWE 787VNDDbiTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-07-07
2026-07-07 23:16Z
HIGH

CVE-2026-14380 — DBI: versions before 1.650 for Perl are vulnerable to code injection via caller-influenced Profile.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-14380

DBI versions before 1.650 for Perl are vulnerable to code injection via caller-influenced Profile. When a string is assigned to a DBI handle's Profile attribute, DBI splits it into path, package and arguments, and interpolates the package part in a string eval with no validation of the package name. Any caller-influenced value that reaches the Profile attribute is therefore arbitrary Perl code execution, including calls to run system commands. The Profile attribute can be CVSSv3.1 8.8 (HIGH) · EPSS 15th percentile

CWECWE 95VNDDbiTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-07-07
2026-07-07 22:16Z
CRIT

CVE-2026-59706 — API: mem0 contains unauthenticated config API endpoints that expose LLM API keys in plaintext and

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-59706

mem0 contains unauthenticated config API endpoints that expose LLM API keys in plaintext and allow server-side request forgery via attacker-controlled ollama_base_url parameter. Unauthenticated attackers can retrieve stored secrets like OpenAI API keys via GET /api/v1/config/ or trigger SSRF attacks by setting ollama_base_url to internal addresses like cloud IMDS via PUT /api/v1/config/mem0/llm endpoint. CVSSv3.1 9.3 (CRITICAL)

CWECWE 306VNDApiTYPVulnerability
9.3
CVSS v3.1
97
Edit Score
2026-07-07
2026-07-07 22:16Z
HIGH

CVE-2026-55418 — FastGPT: Prior to v4.15.0-beta5, two FastGPT file handlers authorize an unrelated resource and then sign

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-55418

FastGPT is an open source AI knowledge base platform. Prior to v4.15.0-beta5, two FastGPT file handlers authorize an unrelated resource and then sign or read an S3 object using a key taken directly from the request, without checking that the key belongs to the caller's team. Because S3 object keys are global within the bucket and carry the tenant id only as a path segment, an attacker can supply another team's key and obtain its file contents through the chat-file presign end CVSSv3.1 8.6 (HIGH)

CWECWE 639VNDFastgptTYPVulnerability
8.6
CVSS v3.1
93
Edit Score
2026-07-07
2026-07-07 22:16Z
HIGH

CVE-2026-49229 — Actual: Prior to 26.6.0, in OpenID multi-user mode, disabling a user only blocks future OpenID

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-49229

Actual is a local-first personal finance app. Prior to 26.6.0, in OpenID multi-user mode, disabling a user only blocks future OpenID login for that identity, while existing Actual session tokens for the disabled user remain valid. The shared session validation path accepts any existing token row that has not expired without checking whether the associated user is still enabled, allowing a disabled user to continue calling authenticated server endpoints. This issue is fixed in CVSSv3.1 8.3 (HIGH)

CWECWE 613VNDActualTYPVulnerability
8.3
CVSS v3.1
92
Edit Score
2026-07-07
2026-07-07 22:16Z
CRIT

CVE-2026-46354 — Coder: allows organizations to provision remote development environments via Terraform.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-46354

Coder allows organizations to provision remote development environments via Terraform. In versions prior tp 2.24.5, 2.29.13, 2.30.8, 2.31.12, 2.32.2, and 2.33.3, `azureidentity.Validate()` verifies that the PKCS#7 signer certificate chains to a trusted Azure CA but never verifies the PKCS#7 signature itself. An attacker can embed a legitimate Azure certificate alongside arbitrary content e.g. `{"vmId":"<target>"}` and the forged `vmId` will be accepted returning the victim wo CVSSv3.1 9.1 (CRITICAL)

CWECWE 347VNDCoderTYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2026-07-07
2026-07-07 21:17Z
HIGH

CVE-2026-59707 — LocalAI: contains an unauthenticated server-side request forgery vulnerability in the POST /models/apply endpoint that

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-59707

LocalAI contains an unauthenticated server-side request forgery vulnerability in the POST /models/apply endpoint that allows attackers to fetch arbitrary internal URLs. The endpoint passes unsanitized gallery URL fields directly to gallery.GetGalleryConfigFromURLWithContext without proper validation, enabling attackers to force the server to issue HTTP GET requests to private and loopback ranges with partial response content leaked through error messages. CVSSv3.1 8.6 (HIGH)

CWECWE 918VNDLocalaiTYPVulnerability
8.6
CVSS v3.1
93
Edit Score
2026-07-07
2026-07-07 21:17Z
CRIT

CVE-2026-58473 — Cognee: before 1.2.0 contains an improper access control vulnerability that allows unauthenticated attackers to

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-58473

Cognee before 1.2.0 contains an improper access control vulnerability that allows unauthenticated attackers to overwrite the global LLM provider configuration by self-registering an account and calling the settings endpoint, which performs no admin or superuser check. Attackers can redirect all LLM operations instance-wide to an attacker-controlled endpoint by exploiting the process-wide singleton configuration cache, enabling exfiltration of prompts, uploaded documents, extr CVSSv3.1 9.1 (CRITICAL)

CWECWE 862CWECWE 306VNDCogneeTYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2026-07-07
2026-07-07 21:17Z
HIGH

CVE-2026-49471 — Serena: Prior to v1.5.2, Serena's built-in web dashboard exposes an unauthenticated Flask API on a

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-49471

Serena is a powerful MCP toolkit for coding that provides semantic retrieval and editing capabilities. Prior to v1.5.2, Serena's built-in web dashboard exposes an unauthenticated Flask API on a fixed, predictable port, with no authentication, no CSRF protection, and no Host header validation. A DNS rebinding attack allows a malicious webpage to reach this API from any browser and write arbitrary content to the agent's persistent memory store, which the agent reads and acts on CVSSv3.1 8.3 (HIGH)

CWECWE 352CWECWE 306VNDSerenaTYPVulnerability
8.3
CVSS v3.1
92
Edit Score
2026-07-07
2026-07-07 21:17Z
HIGH

CVE-2026-44454 — Coder: allows organizations to provision remote development environments via Terraform.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-44454

Coder allows organizations to provision remote development environments via Terraform. Prior to versions 2.29.7 and 2.30.2, workspace creation via `mode=auto` deep links silently provisioned workspaces with attacker-controlled parameters, requiring no explicit user confirmation. In versions 2.29.7 and 2.30.2, a consent dialog was added that displays all prefilled `param.*` values and blocks creation until the user explicitly clicks Confirm and Create. CVSSv3.1 8.1 (HIGH)

CWECWE 78VNDCoderTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-07-07
2026-07-07 19:16Z
CRIT

CVE-2026-59800 — 9Router before 0.4.44 contains an OS command injection vulnerability in the unauthenticated POST /api/tunnel/tailscale-install

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-59800

9Router before 0.4.44 contains an OS command injection vulnerability in the unauthenticated POST /api/tunnel/tailscale-install endpoint (this route is not covered by the dashboard middleware matcher, so no authorization check is applied). The sudoPassword field from the request body is written to the stdin of a 'sudo -S sh' child process. When sudo does not prompt for a password (the process runs as root, NOPASSWD is configured, or a recent sudo timestamp cache exists), the s CVSSv3.1 9.8 (CRITICAL)

CWECWE 78TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-07-07
2026-07-07 19:16Z
HIGH

CVE-2026-48958 — Joomla Joomla\!: An improper access check allows unauthorized users to create custom fields via webservices endpoints.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-48958

An improper access check allows unauthorized users to create custom fields via webservices endpoints. CVSSv3.1 8.8 (HIGH) · EPSS 19th percentile

CWECWE 284VNDJoomlaTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-07-07
2026-07-07 19:16Z
HIGH

CVE-2026-48957 — Joomla Joomla\!: An improper access check allows unauthorized users to access com_privacy datasets.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-48957

An improper access check allows unauthorized users to access com_privacy datasets. CVSSv3.1 8.8 (HIGH) · EPSS 16th percentile

CWECWE 284VNDJoomlaTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-07-07
2026-07-07 19:16Z
HIGH

CVE-2026-48948 — Joomla Joomla\!: An improper access check allows user to download vcard exports of com_contact contacts that

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-48948

An improper access check allows user to download vcard exports of com_contact contacts that are inaccessible. CVSSv3.1 8.8 (HIGH) · EPSS 16th percentile

CWECWE 284VNDJoomlaTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-07-07
2026-07-07 17:25Z
CRIT

CVE-2026-48283 / CVE-2026-48313 | Adobe ColdFusion Pre-Authentication Unrestricted File Upload and Path Traversal Vulnerabilities

Horizon3.ai·horizon3.aiCVE-2026-48283CVE-2026-48313

Adobe ColdFusion 2025 Update 9 and earlier, and 2023 Update 20 and earlier, contain two critical pre-authentication vulnerabilities: CVE-2026-48283 (CVSS 10.0) is an unrestricted file upload leading to RCE, and CVE-2026-48313 (CVSS 9.3) is a path traversal in the CKEditor filemanager connector exposing sensitive files. Adobe released patches (2025 Update 10 and 2023 Update 21) on June 30, 2026, with no observed in-the-wild exploitation at publication.

SRFApplicationTACTA0001SRFWebSWColdfusionVNDAdobeTYPVulnerabilitySTGExecutionSTGInitial Access
85
Edit Score