2026-07-02
2026-07-02 15:17Z
HIGH

CVE-2026-53358 — Linux: In the Linux kernel, the following vulnerability has been resolved: Bluetooth: L2CAP: use chan

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-53358

In the Linux kernel, the following vulnerability has been resolved: Bluetooth: L2CAP: use chan timer to close channels in cleanup_listen() l2cap_chan_close() removes the channel from conn->chan_l, which must be done under conn->lock. cleanup_listen() runs under the parent sk_lock, so acquiring conn->lock would invert the established conn->lock -> chan->lock -> sk_lock order. Instead of calling l2cap_chan_close() directly, schedule l2cap_chan_timeout with delay 0 to close CVSSv3.1 8.8 (HIGH) · EPSS 6th percentile

TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-07-02
2026-07-02 15:17Z
HIGH

CVE-2026-53357 — Linux: A concurrent HCI disconnect drives hci_rx_work -> l2cap_conn_del() which runs l2cap_chan_del() + l2cap_sock_kill() and

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-53357

In the Linux kernel, the following vulnerability has been resolved: Bluetooth: fix UAF in l2cap_sock_cleanup_listen() vs l2cap_conn_del() bt_accept_dequeue() unlinks a not-yet-accepted child from the parent accept queue and release_sock()s it before returning, so the returned sk has no caller reference and is unlocked. l2cap_sock_cleanup_listen() walks these children on listening-socket close. A concurrent HCI disconnect drives hci_rx_work -> l2cap_conn_del() which runs l CVSSv3.1 8.0 (HIGH) · EPSS 6th percentile

TYPVulnerability
8.0
CVSS v3.1
90
Edit Score
2026-07-02
2026-07-02 15:17Z
CRIT

CVE-2026-50748 — A malicious actor with access to the network and low privileges could exploit an

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-50748

A malicious actor with access to the network and low privileges could exploit an Improper Input Validation vulnerability found in UniFi Access Application to execute a Command Injection on the host device. CVSSv3.1 9.9 (CRITICAL)

CWECWE 20TYPVulnerability
9.9
CVSS v3.1
100
Edit Score
2026-07-02
2026-07-02 15:17Z
CRIT

CVE-2026-50747 — A malicious actor with access to the network and low privileges could exploit a

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-50747

A malicious actor with access to the network and low privileges could exploit a series of authenticated SQL Injection vulnerabilities found in UniFi Talk Application to escalate privileges on the host device. CVSSv3.1 9.9 (CRITICAL)

CWECWE 89TYPVulnerability
9.9
CVSS v3.1
100
Edit Score
2026-07-02
2026-07-02 15:17Z
CRIT

CVE-2026-50746 — A malicious actor with access to the network could exploit an Improper Access Control

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-50746

A malicious actor with access to the network could exploit an Improper Access Control vulnerability found in UniFi Connect Application to execute a Command Injection on the host device. CVSSv3.1 10.0 (CRITICAL)

CWECWE 284TYPVulnerability
10.0
CVSS v3.1
100
Edit Score
2026-07-02
2026-07-02 14:47Z
INFO

v9.4.0-rc3

BloodHound releases·github.com

BloodHound v9.4.0-rc3 release candidate published on GitHub. This is a pre-release version containing GraphDB updates and code review preparation changes.

SWBloodhoundTYPTool
15
Edit Score
2026-07-02
2026-07-02 14:16Z
CRIT

CVE-2026-4767 — Missing authentication for critical function vulnerability in TR7 Cyber ​​Defense Inc.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-4767

Missing authentication for critical function vulnerability in TR7 Cyber ​​Defense Inc. WAF-ASP allows Authentication Abuse. This issue affects WAF-ASP: from v1.0.324.900 before v1.4.0.117. CVSSv3.1 9.8 (CRITICAL)

CWECWE 306TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
728 × 90 / responsive · programmatic ad slot
2026-07-02
2026-07-02 13:32Z
INFO

Formalizing Red Teaming Offensive Methodology as a Multi-Agent AI Architecture

Rapid7 Research·rapid7.com

Rapid7 formalized its red team methodology into a multi-agent AI architecture using Claude Mythos, decomposing penetration testing into specialist agents (enumeration, code review, dynamic testing, reporting) coordinated by an orchestrator. The system prioritizes human judgment at critical decision points, implements tiered safety guardrails including scope enforcement and human-in-the-loop approval for destructive actions, and uses deterministic scripts to reduce token consumption. The research also informed Rapid7's defensive AI security posture through direct architectural insights into prompt injection, trust boundary failures, and guardrail bypasses.

SRFApplicationTACTA0001TACTA0002TACTA0003SRFCloudVNDRapid7TYPResearchTECT1589
72
Edit Score
2026-07-02
2026-07-02 13:17Z
CRIT

CVE-2026-5524 — Divi: The Divi Form Builder plugin for WordPress is vulnerable to Arbitrary File Upload leading

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-5524

The Divi Form Builder plugin for WordPress is vulnerable to Arbitrary File Upload leading to Remote Code Execution in all versions up to and including 5.1.8. This is due to insufficient file extension validation in the do_image_upload() function where user-supplied input from the acceptFileTypes POST parameter is directly interpolated into a regular expression used to validate uploaded files. Attackers can specify PHP-executable extensions such as .phtml, .phar, .php5, or .ph CVSSv3.1 9.8 (CRITICAL)

CWECWE 434VNDDiviTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-07-02
2026-07-02 13:00Z
INFO

On Favicons: From Browser Icons to Attack Surface Intelligence

Bishop Fox Labs·bishopfox.com

Bishop Fox published a comprehensive research article on favicon fingerprinting as an attack surface intelligence technique. The work describes an AI-assisted pipeline to hash, correlate, and enrich favicon signatures at scale, demonstrating practical applications including honeypot detection, trend tracking of vulnerable software, and infrastructure attribution via passive Shodan pivots.

SRFWebTACTA0043TYPResearchTYPToolSTGReconTECT1592
72
Edit Score
2026-07-02
2026-07-02 12:17Z
HIGH

CVE-2026-57766 — Site: Unauthenticated Cross Site Request Forgery (CSRF) in WPIDE – File Manager & Code Editor

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-57766

Unauthenticated Cross Site Request Forgery (CSRF) in WPIDE – File Manager & Code Editor <= 3.5.6 versions. CVSSv3.1 8.8 (HIGH)

CWECWE 352TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-07-02
2026-07-02 12:17Z
HIGH

CVE-2026-57765 — Contributor: SQL Injection in WP EasyCart <= 5.9.0 versions.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-57765

Contributor SQL Injection in WP EasyCart <= 5.9.0 versions. CVSSv3.1 8.5 (HIGH)

CWECWE 89VNDContributorTYPVulnerability
8.5
CVSS v3.1
93
Edit Score
2026-07-02
2026-07-02 12:17Z
HIGH

CVE-2026-57759 — Site: Unauthenticated Cross Site Request Forgery (CSRF) in ProfileGrid <= 5.9.9.7 versions.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-57759

Unauthenticated Cross Site Request Forgery (CSRF) in ProfileGrid <= 5.9.9.7 versions. CVSSv3.1 8.8 (HIGH)

CWECWE 352TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-07-02
2026-07-02 12:17Z
HIGH

CVE-2026-57756 — Contributor: SQL Injection in nicen-localize-image <= 1.4.9 versions.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-57756

Contributor SQL Injection in nicen-localize-image <= 1.4.9 versions. CVSSv3.1 8.5 (HIGH)

CWECWE 89VNDContributorTYPVulnerability
8.5
CVSS v3.1
93
Edit Score
2026-07-02
2026-07-02 12:17Z
HIGH

CVE-2026-57752 — Contributor: SQL Injection in iNET Webkit 1.2.4 versions.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-57752

Contributor SQL Injection in iNET Webkit 1.2.4 versions. CVSSv3.1 8.5 (HIGH)

CWECWE 89VNDContributorTYPVulnerability
8.5
CVSS v3.1
93
Edit Score
2026-07-02
2026-07-02 12:17Z
HIGH

CVE-2026-57751 — Site: Unauthenticated Cross Site Request Forgery (CSRF) in Heateor Social Login <= 1.1.39 versions.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-57751

Unauthenticated Cross Site Request Forgery (CSRF) in Heateor Social Login <= 1.1.39 versions. CVSSv3.1 8.1 (HIGH)

CWECWE 352TYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-07-02
2026-07-02 12:17Z
HIGH

CVE-2026-57688 — Broken: Unauthenticated Broken Access Control in POS Entegratör <= 3.7.103 versions.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-57688

Unauthenticated Broken Access Control in POS Entegratör <= 3.7.103 versions. CVSSv3.1 8.2 (HIGH)

CWECWE 862VNDBrokenTYPVulnerability
8.2
CVSS v3.1
91
Edit Score
2026-07-02
2026-07-02 12:17Z
HIGH

CVE-2026-57687 — Contributor: SQL Injection in Custom Field Template <= 2.7.8 versions.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-57687

Contributor SQL Injection in Custom Field Template <= 2.7.8 versions. CVSSv3.1 8.5 (HIGH)

CWECWE 89VNDContributorTYPVulnerability
8.5
CVSS v3.1
93
Edit Score
2026-07-02
2026-07-02 12:17Z
CRIT

CVE-2026-57683 — SQL: Unauthenticated SQL Injection in WP Fast Total Search <= 1.80.280 versions.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-57683

Unauthenticated SQL Injection in WP Fast Total Search <= 1.80.280 versions. CVSSv3.1 9.3 (CRITICAL)

CWECWE 89TYPVulnerability
9.3
CVSS v3.1
97
Edit Score
2026-07-02
2026-07-02 12:17Z
CRIT

CVE-2026-57679 — SQL: Unauthenticated SQL Injection in GeekyBot <= 1.2.5 versions.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-57679

Unauthenticated SQL Injection in GeekyBot <= 1.2.5 versions. CVSSv3.1 9.3 (CRITICAL)

CWECWE 89TYPVulnerability
9.3
CVSS v3.1
97
Edit Score
2026-07-02
2026-07-02 12:17Z
CRIT

CVE-2026-57677 — PHP: Unauthenticated PHP Object Injection in Novalnet Payment Gateway for WooCommerce <= 12.10.3 versions.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-57677

Unauthenticated PHP Object Injection in Novalnet Payment Gateway for WooCommerce <= 12.10.3 versions. CVSSv3.1 9.8 (CRITICAL)

CWECWE 502TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-07-02
2026-07-02 12:17Z
CRIT

CVE-2026-57625 — Site: Unauthenticated Cross Site Scripting (XSS) in Admin and Site Enhancements (ASE) Pro <= 8.8.5

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-57625

Unauthenticated Cross Site Scripting (XSS) in Admin and Site Enhancements (ASE) Pro <= 8.8.5 versions. CVSSv3.1 9.6 (CRITICAL)

CWECWE 79TYPVulnerability
9.6
CVSS v3.1
98
Edit Score
2026-07-02
2026-07-02 12:17Z
CRIT

CVE-2026-57624 — Code: Unauthenticated Remote Code Execution (RCE) in Blocksy Companion Pro <= 2.1.46 versions.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-57624

Unauthenticated Remote Code Execution (RCE) in Blocksy Companion Pro <= 2.1.46 versions. CVSSv3.1 10.0 (CRITICAL)

CWECWE 94VNDCodeTYPVulnerability
10.0
CVSS v3.1
100
Edit Score
2026-07-02
2026-07-02 12:17Z
CRIT

CVE-2026-57623 — Arbitrary: Unauthenticated Arbitrary Code Execution in W3 Total Cache <= 2.9.4 versions.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-57623

Unauthenticated Arbitrary Code Execution in W3 Total Cache <= 2.9.4 versions. CVSSv3.1 9.0 (CRITICAL)

CWECWE 1284VNDArbitraryTYPVulnerability
9.0
CVSS v3.1
95
Edit Score
2026-07-02
2026-07-02 12:17Z
CRIT

CVE-2026-57621 — PHP: Unauthenticated PHP Object Injection in Booktics <= 1.0.21 versions.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-57621

Unauthenticated PHP Object Injection in Booktics <= 1.0.21 versions. CVSSv3.1 9.8 (CRITICAL)

CWECWE 502TYPVulnerability
9.8
CVSS v3.1
99
Edit Score