2026-07-06
2026-07-06 09:16Z
CRIT

CVE-2026-48203 — Neutralization: Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection'), Improper

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-48203

Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection'), Improper Input Validation, Server-Side Request Forgery (SSRF) vulnerability in Apache Camel Solr component. The camel-solr producer copies Exchange message headers whose names begin with the SolrParam. prefix into the parameters of the Solr request, and headers whose names begin with the SolrField. prefix into the fields of the indexed Solr document. The prefix constants (Solr CVSSv3.1 9.1 (CRITICAL)

CWECWE 74CWECWE 918CWECWE 20TYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2026-07-06
2026-07-06 09:16Z
HIGH

CVE-2026-46591 — Neutralization: CVE-2025-66169 addressed Cypher injection through the property values by binding them as query parameters

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-46591

Improper Neutralization of Special Elements in Data Query Logic vulnerability in Apache Camel Neo4J component. The camel-neo4j producer builds the Cypher WHERE clause for its match/retrieve and delete operations from the CamelNeo4jMatchProperties map. CVE-2025-66169 addressed Cypher injection through the property values by binding them as query parameters ($paramN), but the property names (the JSON keys of that map) were still concatenated into the query string verbatim in N CVSSv3.1 8.2 (HIGH)

CWECWE 943TYPVulnerability
8.2
CVSS v3.1
91
Edit Score
2026-07-06
2026-07-06 09:16Z
HIGH

CVE-2026-46590 — Deserialization: of Untrusted Data vulnerability in Apache Camel PQC component.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-46590

Deserialization of Untrusted Data vulnerability in Apache Camel PQC component. The camel-pqc component persists post-quantum key metadata (KeyMetadata) through pluggable KeyLifecycleManager implementations. HashicorpVaultKeyLifecycleManager and AwsSecretsManagerKeyLifecycleManager read that metadata back from the configured secret backend by deserializing a Base64-wrapped value with a raw java.io.ObjectInputStream.readObject() and no ObjectInputFilter or class allow-list; th CVSSv3.1 8.8 (HIGH)

CWECWE 502TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-07-06
2026-07-06 09:16Z
CRIT

CVE-2026-46456 — Input: Improper Input Validation vulnerability in Apache Camel AWS2-SQS Component.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-46456

Improper Input Validation vulnerability in Apache Camel AWS2-SQS Component. The camel-aws2-sqs component map inbound message attributes into the Camel Exchange through a component-specific HeaderFilterStrategy. Sqs2HeaderFilterStrategy configured only an outbound filter (setOutFilterPattern, which blocks Camel*, breadcrumbId and org.apache.camel.* headers being written to the broker) but did not configure an inbound filter. As a result, when Sqs2Consumer copies each SQS Mes CVSSv3.1 9.8 (CRITICAL)

CWECWE 20VNDInputTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-07-06
2026-07-06 09:16Z
CRIT

CVE-2026-46455 — Session: Insufficient Session Expiration vulnerability in Apache Camel Keycloak Component.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-46455

Insufficient Session Expiration vulnerability in Apache Camel Keycloak Component. The camel-keycloak security helper KeycloakSecurityHelper.parseAndVerifyAccessToken builds a Keycloak TokenVerifier using withChecks(...) with only the subject-exists check and the realm-URL (issuer) check. Keycloak's TokenVerifier.withChecks(...) appends to an initially empty check list - the upstream default checks are installed only when withDefaultChecks() is called - so the built-in IS_ACT CVSSv3.1 9.8 (CRITICAL)

CWECWE 613TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-07-06
2026-07-06 09:16Z
CRIT

CVE-2026-46454 — Input: Improper Input Validation vulnerability in Apache Camel Cometd Component.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-46454

Improper Input Validation vulnerability in Apache Camel Cometd Component. The camel-cometd component maps inbound Bayeux (CometD) message headers into the Camel Exchange without applying a HeaderFilterStrategy. CometdBinding.populateExchangeFromMessage copies the entire ext.CamelHeaders map supplied by the CometD client directly onto the Camel message (message.setHeaders), so any header name - including Camel-internal control headers such as CamelHttpUri, CamelFileName or Ca CVSSv3.1 9.8 (CRITICAL)

CWECWE 20VNDInputTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-07-06
2026-07-06 09:16Z
CRIT

CVE-2026-43867 — Deserialization: of Untrusted Data vulnerability in Apache Camel PQC Component.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-43867

Deserialization of Untrusted Data vulnerability in Apache Camel PQC Component. The camel-pqc component persists post-quantum key metadata (KeyMetadata) through pluggable KeyLifecycleManager implementations. AwsSecretsManagerKeyLifecycleManager.deserializeMetadata() reads that metadata back from the configured AWS Secrets Manager secret by Base64-decoding the stored value and deserializing it with a raw java.io.ObjectInputStream.readObject() and no ObjectInputFilter or class CVSSv3.1 9.8 (CRITICAL)

CWECWE 502TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
728 × 90 / responsive · programmatic ad slot
2026-07-06
2026-07-06 09:16Z
HIGH

CVE-2026-43865 — Deserialization: of Untrusted Data vulnerability in Apache Camel Hazelcast component.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-43865

Deserialization of Untrusted Data vulnerability in Apache Camel Hazelcast component. The camel-hazelcast component creates and manages Hazelcast instances using a default configuration that applies no Java deserialization filter. When Camel builds the Hazelcast Config itself - that is, when no user-supplied HazelcastInstance, hazelcastConfigUri, or referenced Config bean is provided - neither Hazelcast's JavaSerializationFilterConfig nor a Camel-side ObjectInputFilter is con CVSSv3.1 8.1 (HIGH)

CWECWE 502TYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-07-06
2026-07-06 09:16Z
HIGH

CVE-2026-42527 — Deserialization: of Untrusted Data vulnerability in Apache Camel.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-42527

Deserialization of Untrusted Data vulnerability in Apache Camel. The default ObjectInputFilter pattern shipped with several Apache Camel components for defense-in-depth deserialization filtering ('java.**;javax.**;org.apache.camel.**;!*', or the no-'javax.**' variant in the aggregation-repository components) uses a recursive 'java.**' glob that admits classes whose hashCode/equals/readObject methods perform network I/O, notably java.net.URL and java.net.InetAddress. When an CVSSv3.1 8.1 (HIGH)

CWECWE 502TYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-07-06
2026-07-06 09:16Z
HIGH

CVE-2026-40859 — Deserialization: of Untrusted Data vulnerability in Apache Camel.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-40859

Deserialization of Untrusted Data vulnerability in Apache Camel. The camel-vertx-http component deserializes HTTP response bodies carrying the Content-Type application/x-java-serialized-object using a raw java.io.ObjectInputStream, without applying any ObjectInputFilter (VertxHttpHelper.deserializeJavaObjectFromStream) This deserialization path is reached only when the producer endpoint is configured with transferException=true (or the component-level allowJavaSerializedObje CVSSv3.1 8.1 (HIGH)

CWECWE 502TYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-07-06
2026-07-06 09:16Z
CRIT

CVE-2026-40047 — Neutralization: Improper Neutralization of Argument Delimiters in a Command ('Argument Injection') vulnerability in Apache Camel

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-40047

Improper Neutralization of Argument Delimiters in a Command ('Argument Injection') vulnerability in Apache Camel Docling component. The camel-docling component invokes the external `docling` command-line tool by assembling an argument list in DoclingProducer and executing it through java.lang.ProcessBuilder. Custom CLI arguments supplied through the `CamelDoclingCustomArguments` exchange header (a List<String>) were appended to that argument list with insufficient validation CVSSv3.1 9.1 (CRITICAL)

CWECWE 88TYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2026-07-06
2026-07-06 09:16Z
CRIT

CVE-2026-24014 — Apache: If the internal DataNode RPC port is exposed to an untrusted network, an attacker

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-24014

Apache IoTDB DataNode’s internal RPC interface for creating Trigger instances uses the uploaded Trigger JAR name to build a file path without sufficient validation. If the internal DataNode RPC port is exposed to an untrusted network, an attacker may use path traversal sequences in the JAR name to write files outside the intended Trigger installation directory. This could allow arbitrary file write with the permissions of the IoTDB process. This issue affects Apache IoTDB: f CVSSv3.1 9.8 (CRITICAL)

CWECWE 434CWECWE 284VNDApacheTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-07-06
2026-07-06 09:16Z
CRIT

CVE-2026-24013 — Authentication: Bypass by Spoofing vulnerability in Apache IoTDB.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-24013

Authentication Bypass by Spoofing vulnerability in Apache IoTDB. Certain Thrift RPC query handlers lack strict validation of the sessionId parameter. An attacker can construct requests with a forged sessionId and, without performing openSession authentication, receive valid query results. This allows authentication bypass and unauthorized reading of time-series data. This issue affects Apache IoTDB: from 1.3.3 before 2.0.8. Users are recommended to upgrade to version 2.0.8 CVSSv3.1 9.1 (CRITICAL)

CWECWE 290TYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2026-07-06
2026-07-06 09:00Z
HIGH

When checking the URL isn’t enough: a Device Code Phishing attack via a Microsoft website

Kaspersky Securelist·securelist.comCVE-2026-41134

Kaspersky researchers documented a sophisticated phishing campaign exploiting Microsoft's Device Authorization Grant (OAuth 2.0 Device Code Flow) to harvest authentication tokens without requiring credential theft. Attackers crafted phishing emails with password-protected PDFs containing links that redirected through legitimate Microsoft and third-party domains (Cacoo.com) to malicious landing pages, where victims were tricked into entering device codes that granted attackers persistent access to email, OneDrive, and Teams via stolen refresh tokens. The campaign, active April–May 2026 with geographic variants targeting Brazil, demonstrates how legitimate authentication mechanisms can be weaponized to bypass traditional phishing defenses.

TACTA0001TACTA0006SRFIdentitySRFWebVNDMicrosoftTYPResearchSTGInitial AccessSTGCred Access
82
Edit Score
2026-07-06
2026-07-06 08:16Z
CRIT

CVE-2026-6382 — FileOrganizer: The FileOrganizer WordPress plugin before 1.1.9, Advanced File Manager WordPress plugin before 5.4.12, File

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-6382

The FileOrganizer WordPress plugin before 1.1.9, Advanced File Manager WordPress plugin before 5.4.12, File Manager Pro WordPress plugin before 2.1.1, File Manager WordPress plugin before 8.0.4 do not properly escape a parameter before passing it to a shell command when processing image operations, allowing authenticated users to perform OS Command Injection. This requires the server to have the ImageMagick convert CLI available without either the PHP imagick or GD extensi CVSSv3.1 9.1 (CRITICAL)

VNDFileorganizerTYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2026-07-06
2026-07-06 08:16Z
CRIT

CVE-2026-14808 — Prog: Management System developed by PROG MIS has a Exposure of Sensitive Information vulnerability

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-14808

Prog Management System developed by PROG MIS has a Exposure of Sensitive Information vulnerability, allowing unauthenticated remote attackers to view a specific page and obtain the database account and password. CVSSv3.1 9.8 (CRITICAL)

CWECWE 497VNDProgTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-07-06
2026-07-06 08:16Z
CRIT

CVE-2026-14807 — ERP: App developed by PROG MIS has a Use of Hard-coded Credentials vulnerability, allowing

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-14807

ERP App developed by PROG MIS has a Use of Hard-coded Credentials vulnerability, allowing unauthenticated remote attackers to log in to view application code and obtain the database account and password. CVSSv3.1 9.8 (CRITICAL)

CWECWE 798VNDErpTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-07-06
2026-07-06 08:16Z
HIGH

CVE-2026-12083 — Admin: The Admin and Site Enhancements (ASE) WordPress plugin before 8.8.4, admin-site-enhancements-pro WordPress plugin before

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-12083

The Admin and Site Enhancements (ASE) WordPress plugin before 8.8.4, admin-site-enhancements-pro WordPress plugin before 8.8.4 does not perform authentication, authorization, or nonce checks on a role-restoration request handler, allowing unauthenticated attackers to restore a previously demoted administrator account back to the administrator role. This is an incomplete fix of CVE-2024-43333 / CVE-2025-24648, which closed the issue for only one of the demotion paths the WordP CVSSv3.1 8.1 (HIGH)

TYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-07-06
2026-07-06 08:16Z
HIGH

CVE-2026-11962 — FileOrganizer: The FileOrganizer WordPress plugin before 1.2.0 does not validate the file type on several

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-11962

The FileOrganizer WordPress plugin before 1.2.0 does not validate the file type on several of its file-management operations, allowing authenticated users who have been granted file-manager access — which its premium add-on can extend to sub-administrator roles — to upload arbitrary PHP files and achieve remote code execution. This is an incomplete fix of CVE-2024-7985, which only added file-type validation to the upload operation. CVSSv3.1 8.8 (HIGH)

VNDFileorganizerTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-07-06
2026-07-06 08:16Z
HIGH

CVE-2026-11855 — Simple: The Simple Membership WordPress plugin before 4.7.5 does not verify the authenticity of Stripe

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-11855

The Simple Membership WordPress plugin before 4.7.5 does not verify the authenticity of Stripe webhook requests when no signing secret is configured, nor escape a value taken from them before outputting it in an administrator notice, allowing unauthenticated attackers to inject arbitrary web scripts that execute in the context of a logged-in administrator. CVSSv3.1 8.8 (HIGH)

VNDSimpleTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-07-06
2026-07-06 08:16Z
HIGH

CVE-2026-11766 — Ultimate: The Ultimate Member WordPress plugin before 2.12.0 does not properly sanitise and escape the

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-11766

The Ultimate Member WordPress plugin before 2.12.0 does not properly sanitise and escape the value of custom textarea profile fields before outputting it on user profiles, allowing authenticated users with Subscriber-level access and above to store JavaScript that executes when any user, including an administrator, views the affected profile. CVSSv3.1 8.0 (HIGH)

VNDUltimateTYPVulnerability
8.0
CVSS v3.1
90
Edit Score
2026-07-06
2026-07-06 08:16Z
HIGH

CVE-2026-10830 — AllCoach: The AllCoach WordPress plugin before 1.0.2 does not verify that an email address submitted

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-10830

The AllCoach WordPress plugin before 1.0.2 does not verify that an email address submitted to a public account-registration endpoint is not already associated with an existing user before overwriting that user's password, allowing unauthenticated attackers to reset the password of arbitrary accounts, including administrators, and take over the site. CVSSv3.1 8.8 (HIGH)

VNDAllcoachTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-07-06
2026-07-06 07:00Z
INFO

v3.11.0

Nuclei releases·github.com

Nuclei v3.11.0 introduces a breaking change requiring digital signatures for custom templates using the JavaScript protocol, continuing security hardening from v3.10.0. Official templates remain pre-signed and unaffected; users with custom JavaScript templates must sign them before use. The release also includes dependency updates (x/crypto, go-pkcs12) and general maintenance.

SRFApplicationTACTA0005SWNucleiVNDProjectdiscoveryTYPTool
45
Edit Score
2026-07-05
2026-07-05 22:00Z
MED

Cortex Security Audit

Quarkslab·blog.quarkslab.com

Quarkslab completed a security audit of Cortex, an open-source multi-tenant time-series data store for Prometheus, identifying 7 vulnerabilities across tenant isolation and data segregation mechanisms. Key findings include tenant impersonation via PushStream gRPC (V01), stored XSS (V02), sensitive credential leakage via /config endpoint (V03), unbound gzip decompression (V04), uncontrolled protobuf histogram memory allocation (V05), unbounded gossip reads (V06), and unenforced gossip packet integrity (V07). All vulnerabilities have been patched by the Cortex maintainers.

SRFApplicationTACTA0001TACTA0006SRFCloudSWCortexTYPResearchTYPVulnerabilitySTGDefense Evasion
68
Edit Score
2026-07-05
2026-07-05 15:16Z
HIGH

CVE-2026-9085 — Incorrect: Permission Assignment for Critical Resource, Improper Access Control vulnerability in TUBITAK BILGEM Software

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-9085

Incorrect Permission Assignment for Critical Resource, Improper Access Control vulnerability in TUBITAK BILGEM Software Technologies Research Institute Pardus-Parental-Control allows DNS Spoofing. This issue affects Pardus-Parental-Control: from <=0.5.1 before 0.7.0. CVSSv3.1 8.8 (HIGH)

CWECWE 284CWECWE 732TYPVulnerability
8.8
CVSS v3.1
94
Edit Score