2026-07-06
2026-07-06 20:16Z
HIGH

CVE-2026-14536 — Devolutions Devolutions_server: Improper enforcement of a mandatory multi-factor authentication policy in Devolutions Server 2026.2.9.0 allows an

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-14536

Improper enforcement of a mandatory multi-factor authentication policy in Devolutions Server 2026.2.9.0 allows an attacker with valid user credentials to bypass the MFA Required policy and authenticate without completing multi-factor authentication. The problem occurs when DVLS encounters an invalid default MFA value. CVSSv3.1 8.8 (HIGH) · EPSS 8th percentile

CWECWE 863VNDDevolutionsTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-07-06
2026-07-06 20:16Z
CRIT

CVE-2026-11405 — The web server binary /bin/httpd contains a hidden backdoor authentication mechanism in the login()

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-11405

The web server binary /bin/httpd contains a hidden backdoor authentication mechanism in the login() function at 004c88b8. - The function contains a normal authentication path using MD5/hash-based password verification (prod_encode64/PasswordToMd5/check_rand_key). - After normal authentication fails, it calls GetValue("sys.rzadmin.password") to read a backdoor password from the device configuration. - It performs a direct strcmp() comparison (plaintext, not hashed) betwee CVSSv3.1 9.8 (CRITICAL)

TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-07-06
2026-07-06 19:17Z
CRIT

CVE-2026-9182 — Esri Arcgis_server: Successful exploitation could allow arbitrary file upload.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-9182

ArcGIS Server contains an unrestricted file upload vulnerability. An unauthenticated attacker could exploit this issue by uploading a crafted file to the affected endpoint. Successful exploitation could allow arbitrary file upload. CVSSv3.1 9.8 (CRITICAL)

CWECWE 434VNDEsriVNDArcgisTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-07-06
2026-07-06 19:17Z
CRIT

CVE-2026-9181 — ArcGIS: Server contains a directory traversal vulnerability.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-9181

ArcGIS Server contains a directory traversal vulnerability. An unauthenticated attacker could exploit this issue by sending crafted path parameters. Successful exploitation could allow access to sensitive files on the system. This issue impacts all versions of ArcGIS Server 12.0 and prior. CVSSv3.1 9.8 (CRITICAL)

CWECWE 22VNDArcgisTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-07-06
2026-07-06 18:16Z
CRIT

CVE-2026-48614 — An improper authorization vulnerability in the Plesk XML API allows an authenticated user to

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-48614

An improper authorization vulnerability in the Plesk XML API allows an authenticated user to inject arbitrary configuration directives, resulting in arbitrary file write as root and full privilege escalation on the underlying server. CVSSv3.1 9.9 (CRITICAL)

CWECWE 94TYPVulnerability
9.9
CVSS v3.1
100
Edit Score
2026-07-06
2026-07-06 17:16Z
CRIT

CVE-2026-48316 — ColdFusion: versions 2025.9, 2023.20 and earlier are affected by an Improper Input Validation vulnerability

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-48316

ColdFusion versions 2025.9, 2023.20 and earlier are affected by an Improper Input Validation vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue does not require user interaction. Scope is changed. CVSSv3.1 10.0 (CRITICAL)

CWECWE 20VNDColdfusionTYPVulnerability
10.0
CVSS v3.1
100
Edit Score
2026-07-06
2026-07-06 17:16Z
CRIT

CVE-2026-40141 — Beyondtrust Privileged_remote_access: Insufficient validation of user-supplied input may allow an authenticated attacker with limited privileges to

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-40141

A high-severity vulnerability exists in a web application component of BeyondTrust Remote Support and Privileged Remote Access related to the processing of certain input parameters. Insufficient validation of user-supplied input may allow an authenticated attacker with limited privileges to access unintended resources or data beyond their authorization scope. Exploitation is restricted to accounts with specific permissions. CVSSv3.1 9.9 (CRITICAL)

CWECWE 943VNDBeyondtrustTYPVulnerability
9.9
CVSS v3.1
100
Edit Score
728 × 90 / responsive · programmatic ad slot
2026-07-06
2026-07-06 17:16Z
CRIT

CVE-2026-40139 — Beyondtrust Privileged_remote_access: Improper processing of authentication requests may allow an unauthenticated remote attacker to bypass access

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-40139

A critical pre-authentication vulnerability exists in the authentication subsystem of BeyondTrust Remote Support. Improper processing of authentication requests may allow an unauthenticated remote attacker to bypass access controls and gain unauthorized access to the appliance, including accounts with elevated privileges. Exploitation requires a specific authentication configuration to be enabled. CVSSv3.1 9.8 (CRITICAL)

CWECWE 287VNDBeyondtrustTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-07-06
2026-07-06 17:16Z
HIGH

CVE-2026-40138 — Beyondtrust Privileged_remote_access: Improper validation of authentication data may allow a network-positioned attacker to bypass access controls

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-40138

A critical pre-authentication vulnerability exists in the authentication subsystem of BeyondTrust Remote Support and Privileged Remote Access. Improper validation of authentication data may allow a network-positioned attacker to bypass access controls and gain unauthorized access to the appliance, including accounts with elevated privileges. Exploitation requires a specific authentication configuration to be enabled CVSSv3.1 8.1 (HIGH)

CWECWE 287VNDBeyondtrustTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-07-06
2026-07-06 17:16Z
HIGH

CVE-2025-53831 — DrawIO: In DrawIO for ownCloud prior to version 1.0.2, which corresponds to ownCloud 10 prior

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2025-53831

DrawIO for ownCloud is an application for using DrawIO with the file storage, synchronization, and sharing application ownCloud Classic. In DrawIO for ownCloud prior to version 1.0.2, which corresponds to ownCloud 10 prior to version 10.15.3, attackers with access to the DrawIO app can leverage improper neutralization of input during web page generation to achieve stored XSS. Upgrade ownCloud 10 to version 10.15.3 or later or upgrade DrawIO for ownCloud 10 to version 1.0.2 or CVSSv3.1 8.2 (HIGH)

CWECWE 79VNDDrawioTYPVulnerability
8.2
CVSS v3.1
91
Edit Score
2026-07-06
2026-07-06 16:16Z
CRIT

CVE-2026-5268 — An authentication bypass vulnerability exists in the default SFTP server component utilized across the

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-5268

An authentication bypass vulnerability exists in the default SFTP server component utilized across the Ciena products listed. This vulnerability allows a remote, unauthenticated attacker to bypass security controls and gain unauthorized access to the underlying filesystem. Successful exploitation could allow an attacker to read or modify system files. CVSSv3.1 9.1 (CRITICAL)

CWECWE 288TYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2026-07-06
2026-07-06 16:16Z
HIGH

CVE-2026-59195 — pnpm is a package manager.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-59195

pnpm is a package manager. Prior to 10.34.4 and 11.8.0, pnpm accepts package names from the env lockfile configDependencies section and uses those names directly when creating config dependency symlinks under node_modules/.pnpm-config. A malicious repository can commit a crafted pnpm-lock.yaml whose env-lockfile document contains a traversal-shaped config dependency name. During pnpm install, pnpm installs the config dependency and creates a symlink at a path derived from tha CVSSv3.1 8.2 (HIGH)

CWECWE 22TYPVulnerability
8.2
CVSS v3.1
91
Edit Score
2026-07-06
2026-07-06 16:16Z
CRIT

CVE-2025-53830 — Anti: Versions of Anti-Virus for ownCloud before 1.2.3 are vulnerable to Server-Side Request Forgery (SSRF).

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2025-53830

Anti-Virus for ownCloud is an anti-virus application for file storage, synchronization, and sharing application ownCloud. Versions of Anti-Virus for ownCloud before 1.2.3 are vulnerable to Server-Side Request Forgery (SSRF). This corresponds to versions of ownCloud 10 prior to 10.15.3. Upgrade ownCloud 10 to version 10.15.3 or later or upgrade Anti-Virus for ownCloud 10 to version 1.2.3 or later to receive a fix. CVSSv3.1 9.1 (CRITICAL)

CWECWE 918VNDAntiTYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2026-07-06
2026-07-06 16:16Z
HIGH

CVE-2025-53829 — In ownCloud 10 prior to version 10.15.3, an attacker with administrative privileges can exploit

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2025-53829

ownCloud is a file storage, synchronization, and sharing application. In ownCloud 10 prior to version 10.15.3, an attacker with administrative privileges can exploit a path traversal vulnerability in the system to execute arbitrary code. Upgrade ownCloud 10 to version 10.15.3 or later to receive a patch. CVSSv3.1 8.0 (HIGH)

CWECWE 23TYPVulnerability
8.0
CVSS v3.1
90
Edit Score
2026-07-06
2026-07-06 16:16Z
HIGH

CVE-2025-53828 — SharePoint: In SharePoint for ownCloud prior to version 0.4.1, which corresponds to ownCloud 10 prior

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2025-53828

SharePoint for ownCloud is an application for using SharePoint with the file storage, synchronization, and sharing application ownCloud Classic. In SharePoint for ownCloud prior to version 0.4.1, which corresponds to ownCloud 10 prior to 10.15.3, an attacker with administrative privileges can use a SSRF vulnerability in the SharePoint app to execute arbitrary code on the system. Upgrade ownCloud 10 to version 10.15.3 or later to receive SharePoint for ownCloud 0.4.1, the fixe CVSSv3.1 8.5 (HIGH)

CWECWE 918VNDSharepointTYPVulnerability
8.5
CVSS v3.1
93
Edit Score
2026-07-06
2026-07-06 16:16Z
CRIT

CVE-2025-53827 — Core: Attackers with administrative privileges may leverage functionality to execute arbitrary code.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2025-53827

ownCloud Core is the server-side component of the file storage, synchronization, and sharing application ownCloud Classic. In versions prior to 10.15.3, the Updater on ownCloud 10 before 10.15.3 has an exposed dangerous method or function. Attackers with administrative privileges may leverage functionality to execute arbitrary code. This issue has been fixed in version 10.15.3. CVSSv3.1 9.1 (CRITICAL)

CWECWE 749VNDCoreTYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2026-07-06
2026-07-06 15:32Z
HIGH

Microsoft Windows Installer Folder Delete Privilege Escalation

Exodus Intel·blog.exodusintel.comCVE-2025-27727

A logic vulnerability in the Windows Installer COM interface (msi.dll) allows low-privileged users to cause the MSI service (running as SYSTEM) to delete arbitrary folders by injecting paths into the TempPackages registry key via the SetEEUIDirectoryAndFilter() method. The vulnerability chains three COM methods—MsiBeginTransactionW(), SetEEUIDirectoryAndFilter(), and CleanupTempPackages()—to achieve arbitrary folder deletion as SYSTEM, which can be leveraged to plant malicious rollback scripts in C:\Config.Msi for code execution. The flaw was patched in April 2025 (CVE-2025-27727).

SRFOsTACTA0004OSWindowsSWWindows InstallerVNDMicrosoftTYPResearchTYPVulnerabilitySTGPrivesc
78
Edit Score
2026-07-06
2026-07-06 15:00Z
HIGH

KYC : Bypass age verification using generative video models

Synacktiv·synacktiv.com

Synacktiv researchers demonstrate practical bypass techniques for KYC (Know Your Customer) age verification systems using generative AI video models. The research establishes a state-of-the-art overview of identity verification frameworks (PVID, eIDAS), catalogs existing anti-injection and liveness detection mechanisms, and provides a concrete proof-of-concept bypassing AWS Rekognition-based age verification on an adult website using deepfake video injection.

TACTA0005TACTA0001SRFIdentitySRFWebTYPResearchSTGDefense EvasionSTGInitial AccessTECT1598
76
Edit Score
2026-07-06
2026-07-06 11:16Z
HIGH

CVE-2026-4249 — This allows an unauthenticated remote attacker to inject malicious JSON data that can lead

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-4249

The throttling event handling mechanism in multiple WSO2 products accepts user-supplied JSON payloads without sufficient validation of their structure and content. This allows an unauthenticated remote attacker to inject malicious JSON data that can lead to a persistent denial of service condition. Successful exploitation of this vulnerability can disrupt the API Gateway, preventing legitimate API traffic from being processed and impacting complete service availability. The CVSSv3.1 8.6 (HIGH)

CWECWE 707TYPVulnerability
8.6
CVSS v3.1
93
Edit Score
2026-07-06
2026-07-06 11:16Z
HIGH

CVE-2026-49297 — Apache: Airflow's Google provider operators `GCSToSFTPOperator` and `GCSTimeSpanFileTransformOperator` joined GCS object names returned by

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-49297

Apache Airflow's Google provider operators `GCSToSFTPOperator` and `GCSTimeSpanFileTransformOperator` joined GCS object names returned by the bucket listing API directly to a destination filesystem path without normalisation or containment check. A user with write access to the source GCS bucket (typically a different trust principal than the DAG author — partner uploads, ingest-only service accounts, public-data buckets) could create an object whose name contains `..` segmen CVSSv3.1 8.1 (HIGH)

CWECWE 22VNDApacheTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-07-06
2026-07-06 11:16Z
HIGH

CVE-2026-44937 — Suse Rancher_fleet: Potential forgery of webhook requests when using a unauthenticated webhook in SUSE Rancher Fleet

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-44937

Potential forgery of webhook requests when using a unauthenticated webhook in SUSE Rancher Fleet 0.15 before 0.15.2, 0.14 before 0.14.6, 0.13 before 0.13.11 and 0.12 before 0.12.5 could be used by remote attackers to cause a denial of service or a downgrade attack on other repositories on the system. CVSSv3.1 8.2 (HIGH) · EPSS 8th percentile

CWECWE 918VNDPotentialTYPVulnerability
8.2
CVSS v3.1
91
Edit Score
2026-07-06
2026-07-06 09:16Z
CRIT

CVE-2026-56140 — Input: Improper Input Validation vulnerability in Apache Camel AWS SNS component.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-56140

Improper Input Validation vulnerability in Apache Camel AWS SNS component. The camel-aws2-sns component filters Camel headers through a component-specific HeaderFilterStrategy, Sns2HeaderFilterStrategy. Like the sibling Sqs2HeaderFilterStrategy, it originally configured only an outbound filter (setOutFilterPattern, which blocks Camel*, breadcrumbId and org.apache.camel.* headers from being written out) and did not configure an inbound filter rule. For the related camel-aws2 CVSSv3.1 9.8 (CRITICAL)

CWECWE 20VNDInputTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-07-06
2026-07-06 09:16Z
CRIT

CVE-2026-53913 — Authentication: Improper Authentication, Missing Authentication for Critical Function, Not Failing Securely ('Failing Open') vulnerability in

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-53913

Improper Authentication, Missing Authentication for Critical Function, Not Failing Securely ('Failing Open') vulnerability in Apache Camel Keycloak Component. The KeycloakSecurityPolicy of camel-keycloak guards a route by running KeycloakSecurityProcessor.beforeProcess(), which performs three checks in sequence: it rejects a request that carries no access token, then - only if requiredRoles is non-empty - validates the roles, and - only if requiredPermissions is non-empty - CVSSv3.1 9.8 (CRITICAL) · EPSS 21th percentile

CWECWE 306CWECWE 287CWECWE 636TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-07-06
2026-07-06 09:16Z
CRIT

CVE-2026-48205 — Input: Improper Input Validation, Server-Side Request Forgery (SSRF) vulnerability in Apache Camel DNS component.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-48205

Improper Input Validation, Server-Side Request Forgery (SSRF) vulnerability in Apache Camel DNS component. The camel-dns producers read DNS operation parameters - the resolver to query, the name or domain to look up, the record type and class, and the search term - from Exchange message headers whose constant values (DnsConstants.DNS_SERVER, DNS_NAME, DNS_DOMAIN, DNS_TYPE, DNS_CLASS, TERM) were the plain strings dns.server, dns.name, dns.domain, dns.type, dns.class and term. CVSSv3.1 9.1 (CRITICAL)

CWECWE 918CWECWE 20VNDInputTYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2026-07-06
2026-07-06 09:16Z
CRIT

CVE-2026-48204 — Input: In a route that bridges an HTTP consumer (for example platform-http) into a mongodb-gridfs

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-48204

Improper Input Validation, Improper Access Control vulnerability in Apache Camel in Camel Mongodb Gridfs component. The camel-mongodb-gridfs producer selects the GridFS operation to perform from the gridfs.operation Exchange header when the endpoint's operation parameter is not set - which is the default. The control-header constants (GridFsConstants.GRIDFS_OPERATION, GRIDFS_OBJECT_ID, GRIDFS_METADATA, GRIDFS_CHUNKSIZE, GRIDFS_FILE_ID_PRODUCED) were the plain strings gridfs. CVSSv3.1 9.8 (CRITICAL)

CWECWE 284CWECWE 20VNDInputTYPVulnerability
9.8
CVSS v3.1
99
Edit Score