2026-07-02
2026-07-02 12:17Z
CRIT

CVE-2026-57624 — Code: Unauthenticated Remote Code Execution (RCE) in Blocksy Companion Pro <= 2.1.46 versions.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-57624

Unauthenticated Remote Code Execution (RCE) in Blocksy Companion Pro <= 2.1.46 versions. CVSSv3.1 10.0 (CRITICAL)

CWECWE 94VNDCodeTYPVulnerability
10.0
CVSS v3.1
100
Edit Score
2026-07-02
2026-07-02 12:17Z
CRIT

CVE-2026-57623 — Arbitrary: Unauthenticated Arbitrary Code Execution in W3 Total Cache <= 2.9.4 versions.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-57623

Unauthenticated Arbitrary Code Execution in W3 Total Cache <= 2.9.4 versions. CVSSv3.1 9.0 (CRITICAL)

CWECWE 1284VNDArbitraryTYPVulnerability
9.0
CVSS v3.1
95
Edit Score
2026-07-02
2026-07-02 12:17Z
CRIT

CVE-2026-57621 — PHP: Unauthenticated PHP Object Injection in Booktics <= 1.0.21 versions.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-57621

Unauthenticated PHP Object Injection in Booktics <= 1.0.21 versions. CVSSv3.1 9.8 (CRITICAL)

CWECWE 502TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-07-02
2026-07-02 12:17Z
HIGH

CVE-2026-56037 — Deserialization: of Untrusted Data vulnerability in Themify Themify Popup allows Object Injection.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-56037

Deserialization of Untrusted Data vulnerability in Themify Themify Popup allows Object Injection. This issue affects Themify Popup: from n/a through 1.4.3. CVSSv3.1 8.8 (HIGH)

CWECWE 502TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-07-02
2026-07-02 12:17Z
HIGH

CVE-2026-42382 — File: Unauthenticated Local File Inclusion in Audrey <= 1.5 versions.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-42382

Unauthenticated Local File Inclusion in Audrey <= 1.5 versions. CVSSv3.1 8.1 (HIGH)

CWECWE 98TYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-07-02
2026-07-02 12:17Z
CRIT

CVE-2026-27436 — Editor: Arbitrary Code Execution in Five Star Business Profile and Schema <= 2.3.19 versions.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-27436

Editor Arbitrary Code Execution in Five Star Business Profile and Schema <= 2.3.19 versions. CVSSv3.1 9.1 (CRITICAL)

CWECWE 94VNDEditorTYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2026-07-02
2026-07-02 12:17Z
CRIT

CVE-2026-27419 — Subscriber: Arbitrary File Upload in Zegen <= 1.1.9 versions.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-27419

Subscriber Arbitrary File Upload in Zegen <= 1.1.9 versions. CVSSv3.1 9.9 (CRITICAL)

CWECWE 434VNDSubscriberTYPVulnerability
9.9
CVSS v3.1
100
Edit Score
728 × 90 / responsive · programmatic ad slot
2026-07-02
2026-07-02 12:17Z
HIGH

CVE-2026-27414 — Contributor: PHP Object Injection in Werkstatt <= 4.8.3 versions.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-27414

Contributor PHP Object Injection in Werkstatt <= 4.8.3 versions. CVSSv3.1 8.8 (HIGH)

CWECWE 502VNDContributorTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-07-02
2026-07-02 12:17Z
HIGH

CVE-2026-27412 — File: Unauthenticated Local File Inclusion in Pearl - Corporate Business <= 3.4.10 versions.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-27412

Unauthenticated Local File Inclusion in Pearl - Corporate Business <= 3.4.10 versions. CVSSv3.1 8.1 (HIGH)

CWECWE 98TYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-07-02
2026-07-02 12:16Z
HIGH

CVE-2026-27060 — Contributor: PHP Object Injection in ARMember Premium <= 7.0 versions.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-27060

Contributor PHP Object Injection in ARMember Premium <= 7.0 versions. CVSSv3.1 8.8 (HIGH)

CWECWE 502VNDContributorTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-07-02
2026-07-02 12:16Z
HIGH

CVE-2025-69094 — Subscriber: SQL Injection in Unicamp <= 2.2.2 versions.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2025-69094

Subscriber SQL Injection in Unicamp <= 2.2.2 versions. CVSSv3.1 8.5 (HIGH)

CWECWE 89VNDSubscriberTYPVulnerability
8.5
CVSS v3.1
93
Edit Score
2026-07-02
2026-07-02 12:16Z
HIGH

CVE-2025-58902 — File: Unauthenticated Local File Inclusion in Lighthouse <= 1.2.12 versions.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2025-58902

Unauthenticated Local File Inclusion in Lighthouse <= 1.2.12 versions. CVSSv3.1 8.1 (HIGH)

CWECWE 98TYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-07-02
2026-07-02 11:00Z
HIGH

Field reports from Patch the Planet

Trail of Bits·blog.trailofbits.com

Trail of Bits reports on Patch the Planet, a collaboration with OpenAI using GPT-5.5-Cyber to proactively discover vulnerabilities in open-source projects before attackers do. The initiative demonstrates that frontier LLMs can autonomously design and execute sophisticated fuzzing campaigns (e.g., building custom harnesses across a dozen zlib entrypoints in a single day), dramatically lowering the expertise barrier for vulnerability discovery and shifting the threat model for security-critical software.

SRFApplicationTACTA0001SRFSupply ChainSWOpenaiSWZlibTYPResearchTYPToolSTGDiscovery
82
Edit Score
2026-07-02
2026-07-02 10:16Z
HIGH

CVE-2026-14336 — OIDC: PIA's OIDC issuer allowlist for Jenkins tokens uses a bare string-prefix check (issuer.startswith(' https://ci.eclipse.org

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-14336

PIA's OIDC issuer allowlist for Jenkins tokens uses a bare string-prefix check (issuer.startswith(' https://ci.eclipse.org ') in is_issuer_known, pia/models.py:139) instead of validating the issuer as a properly host-bounded URL. An attacker can craft an issuer such as https://ci.eclipse.org@evil.host (userinfo trick) or https://ci.eclipse.org.evil.host (suffix trick) that satisfies the prefix check while pointing the OIDC discovery and JWKS fetches at a server the attack CVSSv3.1 8.2 (HIGH)

CWECWE 918VNDOidcTYPVulnerability
8.2
CVSS v3.1
91
Edit Score
2026-07-02
2026-07-02 10:00Z
HIGH

Exploring cross-domain & cross-forest RBCD: part 2

Synacktiv·synacktiv.com

Synacktiv extends Resource-Based Constrained Delegation (RBCD) attacks to multi-domain and cross-forest scenarios, demonstrating recursive S4U2Self+U2U and S4U2Proxy implementations that enable impersonation of any user within a forest to access resources across domain and forest boundaries. The research includes practical exploitation of SPN-less RBCD in complex trust chains and provides updated Impacket implementations with branch-aware algorithm variants.

TACTA0006SRFIdentityTACTA0008TYPResearchSTGCred AccessSTGLat MovementTECT1187TECT1558
82
Edit Score
2026-07-02
2026-07-02 09:16Z
HIGH

CVE-2026-8147 — MLflow: This allows any authenticated user to bypass experiment-level authorization controls on all trace operations

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-8147

In MLflow versions prior to 3.14.0, when running with authentication enabled, the trace API endpoints lack proper authorization validators. This allows any authenticated user to bypass experiment-level authorization controls on all trace operations, including reading, deleting, and modifying traces on experiments they do not have permission to access. The issue arises from the `_before_request` handler, which does not register authorization validators for trace endpoints, res CVSSv3.1 8.1 (HIGH)

CWECWE 284VNDMlflowTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-07-02
2026-07-02 09:00Z
HIGH

Missed incidents, persistent threats, and response gaps: Insights from compromise assessment projects

Kaspersky Securelist·securelist.comCVE-2017-0144

Kaspersky's 2025 Compromise Assessment report reveals systemic detection gaps across enterprise networks: 60% of incidents were missed due to absent high-confidence alerts, 52% of high-severity compromises went undetected for 90+ days, and 40% of web shells persisted in backups post-remediation. Key findings include a four-year-old crypto-mining infection on domain controllers exploiting EternalBlue, persistent use of LoLBins and remote management tools across all compromised environments, and communication failures during incident response that compounded detection blindness.

SRFApplicationSRFNetworkTACTA0007TACTA0003TACTA0008VNDKasperskyTYPResearchTYPThreat Intel
78
Edit Score
2026-07-02
2026-07-02 06:16Z
HIGH

CVE-2026-5821 — Image: The Image Optimizer plugin for WordPress is vulnerable to arbitrary file deletion in versions

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-5821

The Image Optimizer plugin for WordPress is vulnerable to arbitrary file deletion in versions up to and including 1.7.4. This is due to insufficient path validation in the Image_Backup::remove() function where backup file paths stored in post meta are used directly in file deletion operations without verifying they are within the uploads directory. The plugin stores backup file paths in the image_optimizer_metadata post meta field and trusts these paths completely when deleti CVSSv3.1 8.1 (HIGH)

CWECWE 73VNDImageTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-07-02
2026-07-02 04:17Z
HIGH

CVE-2026-57278 — GeoWebPlayer: #### Buffer Overflow in ip field

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-57278

GeoWebPlayer (also called "Web Plugin" in the GV-VMS documentation and "WS Player" for VMS-Cloud) is an addon that can be installed with various GeoVision software (GV-VMS, GV-Cloud, ...). It creates a websocket server that expands the capabilities of the various web-interfaces provided by the GeoVision software and may be necessary for them to function properly. The Websocket server can accept various commands coming from localhost. One of them, `connectionInfo` is meant to CVSSv3.1 8.3 (HIGH)

CWECWE 120VNDGeowebplayerTYPVulnerability
8.3
CVSS v3.1
92
Edit Score
2026-07-02
2026-07-02 04:17Z
HIGH

CVE-2026-57277 — GeoWebPlayer: #### Buffer Overflow in key field

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-57277

GeoWebPlayer (also called "Web Plugin" in the GV-VMS documentation and "WS Player" for VMS-Cloud) is an addon that can be installed with various GeoVision software (GV-VMS, GV-Cloud, ...). It creates a websocket server that expands the capabilities of the various web-interfaces provided by the GeoVision software and may be necessary for them to function properly. The Websocket server can accept various commands coming from localhost. One of them, `connectionInfo` is meant to CVSSv3.1 8.3 (HIGH)

CWECWE 120VNDGeowebplayerTYPVulnerability
8.3
CVSS v3.1
92
Edit Score
2026-07-02
2026-07-02 04:17Z
HIGH

CVE-2026-57276 — GeoWebPlayer: #### Buffer Overflow in password field (key present)

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-57276

GeoWebPlayer (also called "Web Plugin" in the GV-VMS documentation and "WS Player" for VMS-Cloud) is an addon that can be installed with various GeoVision software (GV-VMS, GV-Cloud, ...). It creates a websocket server that expands the capabilities of the various web-interfaces provided by the GeoVision software and may be necessary for them to function properly. The Websocket server can accept various commands coming from localhost. One of them, `connectionInfo` is meant to CVSSv3.1 8.3 (HIGH)

CWECWE 120VNDGeowebplayerTYPVulnerability
8.3
CVSS v3.1
92
Edit Score
2026-07-02
2026-07-02 04:17Z
HIGH

CVE-2026-57275 — GeoWebPlayer: #### Buffer Overflow in username field (key present)

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-57275

GeoWebPlayer (also called "Web Plugin" in the GV-VMS documentation and "WS Player" for VMS-Cloud) is an addon that can be installed with various GeoVision software (GV-VMS, GV-Cloud, ...). It creates a websocket server that expands the capabilities of the various web-interfaces provided by the GeoVision software and may be necessary for them to function properly. The Websocket server can accept various commands coming from localhost. One of them, `connectionInfo` is meant to CVSSv3.1 8.3 (HIGH)

CWECWE 120VNDGeowebplayerTYPVulnerability
8.3
CVSS v3.1
92
Edit Score
2026-07-02
2026-07-02 04:17Z
HIGH

CVE-2026-57274 — GeoWebPlayer: #### Buffer Overflow in password field (no key present)

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-57274

GeoWebPlayer (also called "Web Plugin" in the GV-VMS documentation and "WS Player" for VMS-Cloud) is an addon that can be installed with various GeoVision software (GV-VMS, GV-Cloud, ...). It creates a websocket server that expands the capabilities of the various web-interfaces provided by the GeoVision software and may be necessary for them to function properly. The Websocket server can accept various commands coming from localhost. One of them, `connectionInfo` is meant to CVSSv3.1 8.3 (HIGH)

CWECWE 120VNDGeowebplayerTYPVulnerability
8.3
CVSS v3.1
92
Edit Score
2026-07-02
2026-07-02 04:17Z
HIGH

CVE-2026-57273 — GeoWebPlayer: #### Buffer Overflow in username field (no key present)

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-57273

GeoWebPlayer (also called "Web Plugin" in the GV-VMS documentation and "WS Player" for VMS-Cloud) is an addon that can be installed with various GeoVision software (GV-VMS, GV-Cloud, ...). It creates a websocket server that expands the capabilities of the various web-interfaces provided by the GeoVision software and may be necessary for them to function properly. The Websocket server can accept various commands coming from localhost. One of them, `connectionInfo` is meant to CVSSv3.1 8.3 (HIGH)

CWECWE 120VNDGeowebplayerTYPVulnerability
8.3
CVSS v3.1
92
Edit Score
2026-07-02
2026-07-02 04:17Z
HIGH

CVE-2026-57272 — GeoWebPlayer: #### byPass command index-out-of-bound

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-57272

GeoWebPlayer (also called "Web Plugin" in the GV-VMS documentation and "WS Player" for VMS-Cloud) is an addon that can be installed with various GeoVision software (GV-VMS, GV-Cloud, ...). It creates a websocket server that expands the capabilities of the various web-interfaces provided by the GeoVision software and may be necessary for them to function properly. The Websocket server can accept various commands coming from localhost. Many of the commands will take an `index` CVSSv3.1 8.3 (HIGH)

CWECWE 129VNDGeowebplayerTYPVulnerability
8.3
CVSS v3.1
92
Edit Score