2026-07-01
2026-07-01 16:16Z
CRIT

CVE-2026-58025 — Mediawiki Mediawiki: Deserialization of untrusted data vulnerability in Wikimedia Foundation MediaWiki.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-58025

Deserialization of untrusted data vulnerability in Wikimedia Foundation MediaWiki. This vulnerability is associated with program files includes/Import/WikiImporter.Php, includes/Import/WikiRevision.Php, includes/Logging/LogEntryBase.Php. This issue affects MediaWiki: from * before 1.46.0, 1.45.4, 1.44.6, 1.43.9. CVSSv3.1 9.8 (CRITICAL) · EPSS 26th percentile

CWECWE 94CWECWE 502VNDMediawikiTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-07-01
2026-07-01 16:16Z
CRIT

CVE-2026-57517 — Control: Web Panel before 0.9.8.1225 contains a blind SQL injection vulnerability that allows unauthenticated

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-57517

Control Web Panel before 0.9.8.1225 contains a blind SQL injection vulnerability that allows unauthenticated remote attackers to execute arbitrary SQL queries by submitting unsanitized input through the userRes POST parameter at the user endpoint. Attackers can exploit MySQL root privileges obtained via the injection to write arbitrary files using INTO DUMPFILE, enabling deployment of a PHP webshell to the web-accessible roundcube logs directory and achieving remote code exec CVSSv3.1 9.8 (CRITICAL)

CWECWE 89TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-07-01
2026-07-01 16:16Z
CRIT

CVE-2026-24270 — NVIDIA: AIStore framework contains a vulnerability where an attacker could bypass authentication.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-24270

NVIDIA AIStore framework contains a vulnerability where an attacker could bypass authentication. A successful exploit of this vulnerability might lead to denial of service, escalation of privileges, information disclosure, and data tampering. CVSSv3.1 9.8 (CRITICAL)

CWECWE 290VNDNvidiaTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-07-01
2026-07-01 16:16Z
HIGH

CVE-2026-24260 — NVIDIA: Container Toolkit for Linux contains a vulnerability where an attacker could cause a

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-24260

NVIDIA Container Toolkit for Linux contains a vulnerability where an attacker could cause a time-of-check time-of-use race condition. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, and data tampering. CVSSv3.1 8.5 (HIGH)

CWECWE 367VNDNvidiaTYPVulnerability
8.5
CVSS v3.1
93
Edit Score
2026-07-01
2026-07-01 16:16Z
HIGH

CVE-2026-13706 — Mediawiki Mediawiki: Improper input validation vulnerability in Wikimedia Foundation UrlShortener.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-13706

Improper input validation vulnerability in Wikimedia Foundation UrlShortener. This vulnerability is associated with program files includes/UrlShortenerUtils.Php. CVSSv3.1 8.8 (HIGH) · EPSS 20th percentile

CWECWE 20VNDMediawikiVNDWikimediaTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-07-01
2026-07-01 16:16Z
CRIT

CVE-2025-23351 — NVIDIA: ConnectX and BlueField contain a vulnerability in the command interface where a local

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2025-23351

NVIDIA ConnectX and BlueField contain a vulnerability in the command interface where a local user with virtual function (VF) access may cause a write out of bounds by crafted input. A successful exploit of this vulnerability may lead to arbitrary code execution on the device. CVSSv3.1 9.0 (CRITICAL)

CWECWE 787VNDNvidiaTYPVulnerability
9.0
CVSS v3.1
95
Edit Score
2026-07-01
2026-07-01 16:16Z
CRIT

CVE-2025-23350 — NVIDIA: ConnectX and BlueField contain a vulnerability in the command interface where a local

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2025-23350

NVIDIA ConnectX and BlueField contain a vulnerability in the command interface where a local user with virtual function (VF) access may cause a write out of bounds by crafted input. A successful exploit of this vulnerability may lead to arbitrary code execution on the device. CVSSv3.1 9.0 (CRITICAL)

CWECWE 787VNDNvidiaTYPVulnerability
9.0
CVSS v3.1
95
Edit Score
728 × 90 / responsive · programmatic ad slot
2026-07-01
2026-07-01 16:16Z
CRIT

CVE-2025-15646 — HTML: HTML::Gumbo versions before 0.19 for Perl disclose heap memory via type confusion.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2025-15646

HTML::Gumbo versions before 0.19 for Perl disclose heap memory via type confusion. Support for the <template> element was added to libgumbo 0.10.0 in 2015, but the walk_tree function in lib/HTML/Gumbo.xs was not updated to support it. The element was treated as a text-node, where strlen() over-reads the heap block that the pointer addresses. Any caller that runs parse() with the default format => 'string', or with format => 'tree', on input containing a <template> element s CVSSv3.1 9.8 (CRITICAL)

CWECWE 125CWECWE 843TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-07-01
2026-07-01 15:45Z
LOW

v3.4.0.61

Mythic releases·github.com

Mythic v3.4.0.61 released with a bug fix for process browser filtering. This is a minor patch release addressing a UI/functionality issue in the command & control framework.

SWMythicTYPTool
25
Edit Score
2026-07-01
2026-07-01 15:17Z
CRIT

CVE-2026-23537 — A vulnerability has been identified in the Feast Feature Server’s `/save-document` endpoint that allows

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-23537

A vulnerability has been identified in the Feast Feature Server’s `/save-document` endpoint that allows an unauthenticated remote attacker to write arbitrary JSON files to the server's filesystem. Although the system attempts to restrict file locations, these protections can be bypassed, enabling an attacker to overwrite vital application configurations or startup scripts. Because this flaw requires no credentials or special privileges, any attacker with network access to the CVSSv3.1 9.1 (CRITICAL)

CWECWE 862TYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2026-07-01
2026-07-01 15:03Z
CRIT

The June 2026 Apple Security Update Review

Apple released 37 CVEs in June 2026 across iOS 26.5.2, iPadOS 26.5.2, macOS Tahoe 26.5.2, and Safari 26.5.2. The release includes two critical kernel memory write/corruption bugs (CVE-2026-43724, CVE-2026-39868) credited to elite researchers, plus two WebKit sandbox escapes (CVE-2026-43725, CVE-2026-43701) that bridge remote code execution to kernel exploitation. The majority of the 37 CVEs are WebKit/WebRTC DoS bugs, but the kernel and sandbox-escape primitives represent weaponizable, full-chain exploitation paths.

SRFOsSRFBrowserOSMacosOSIosSWSafariSWWebkitVNDAppleTYPAdvisory
78
Edit Score
2026-07-01
2026-07-01 15:00Z
CRIT

Caught in the Octopus Trap: Unauthenticated RCE in Argo CD with CodeQL

Synacktiv·synacktiv.com

Synacktiv discovered an unauthenticated remote code execution vulnerability in Argo CD's repo-server component via an exposed gRPC endpoint. The vulnerability chains command injection through kustomize's --helm-command parameter with attacker-controlled Git repositories to achieve arbitrary code execution on the Kubernetes cluster. The researchers used CodeQL with custom model packs to identify the vulnerability and released a proof-of-concept exploit tool.

SRFApplicationTACTA0002TACTA0003SRFCloudSWArgo CdVNDArgoprojTYPResearchTYPVulnerability
92
Edit Score
2026-07-01
2026-07-01 14:16Z
HIGH

CVE-2026-5136 — Foreman: This allows an authenticated user with usergroup management permissions to attach arbitrary roles, including

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-5136

A flaw was found in Foreman. The Usergroup model in Foreman does not properly validate role assignments against the calling user's permissions. This allows an authenticated user with usergroup management permissions to attach arbitrary roles, including administrative roles, to a user group and then add themselves as a member. Successful exploitation of this vulnerability leads to full privilege escalation, granting the attacker administrator-level access. CVSSv3.1 8.8 (HIGH)

CWECWE 266VNDForemanTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-07-01
2026-07-01 14:16Z
CRIT

CVE-2026-57692 — Incorrect: Privilege Assignment vulnerability in LCweb PrivateContent allows Privilege Escalation.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-57692

Incorrect Privilege Assignment vulnerability in LCweb PrivateContent allows Privilege Escalation. This issue affects PrivateContent: from n/a through 9.9.2. CVSSv3.1 9.8 (CRITICAL)

CWECWE 266TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-07-01
2026-07-01 14:16Z
CRIT

CVE-2026-53355 — Linux: In the Linux kernel, the following vulnerability has been resolved: net: rds: clear i_sends

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-53355

In the Linux kernel, the following vulnerability has been resolved: net: rds: clear i_sends on setup unwind The RDS IB connection teardown path is written so it can run during partial startup and on repeated shutdown attempts. It uses NULL pointers to distinguish resources that are still owned from resources that have already been released. When rds_ib_setup_qp() fails after allocating i_sends but before allocating i_recvs, the sends_out path frees i_sends without clearing CVSSv3.1 9.8 (CRITICAL) · EPSS 6th percentile

TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-07-01
2026-07-01 14:16Z
HIGH

CVE-2026-53354 — Linux: Enable this workaround for affected CPUs, and update the silicon errata documentation accordingly.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-53354

In the Linux kernel, the following vulnerability has been resolved: arm64: errata: Mitigate TLBI errata on various Arm CPUs A number of CPUs developed by Arm suffer from errata whereby a broadcast TLBI;DSB sequence may complete before the global observation of writes which are translated by an affected TLB entry. These errata ONLY affect the completion of memory accesses which have been translated by an invalidated TLB entry, and these errata DO NOT affect the actual inval CVSSv3.1 8.8 (HIGH) · EPSS 8th percentile

TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-07-01
2026-07-01 13:17Z
HIGH

CVE-2026-5120 — Race: A Race Condition vulnerability affecting BIOVIA Workbook from Release 2021 through Release 2026 could

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-5120

A Race Condition vulnerability affecting BIOVIA Workbook from Release 2021 through Release 2026 could allow a user to access unauthorized data from another user. CVSSv3.1 8.1 (HIGH)

CWECWE 362VNDRaceTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-07-01
2026-07-01 13:17Z
HIGH

CVE-2026-53906 — Mycomplianceoffice Mycomplianceoffice: MCO is vulnerable to Path Disclosure and Path Traversal in file handling functionality related

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-53906

MCO is vulnerable to Path Disclosure and Path Traversal in file handling functionality related to data export and upload. Improper validation of the filename parameter allows writing files to arbitrary locations as well as indirect disclosure of absolute server paths through error messages. Because vendor contact attempts were unsuccessful, the vulnerability has only been confirmed in version 25.3.3.1 but may also affect other versions. CVSSv3.1 8.2 (HIGH) · EPSS 34th percentile

CWECWE 22CWECWE 209VNDMycomplianceofficeVNDMcoTYPVulnerability
8.2
CVSS v3.1
91
Edit Score
2026-07-01
2026-07-01 13:17Z
HIGH

CVE-2026-53903 — Mycomplianceoffice Mycomplianceoffice: MCO is vulnerable to an Insecure Direct Object Reference (IDOR) vulnerability in the /customer/servlet/mco/webapi/trading-document/fetchPdfState

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-53903

MCO is vulnerable to an Insecure Direct Object Reference (IDOR) vulnerability in the /customer/servlet/mco/webapi/trading-document/fetchPdfStatement endpoint. The application does not properly validate whether an authenticated user is authorized to access a requested document, allowing direct retrieval based on a user-supplied identifier. An attacker can access trading documents belonging to other users by providing a valid document ID. Although exploitation requires guessing CVSSv3.1 8.1 (HIGH) · EPSS 16th percentile

CWECWE 639VNDMycomplianceofficeVNDMcoTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-07-01
2026-07-01 12:16Z
CRIT

CVE-2026-14198 — The bypass is HTTP method agnostic and requires no authentication or special preconditions.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-14198

@fastify/middie versions 9.1.0 through 9.3.2 decode the encoded slash %2F inside path parameter values before matching middleware paths, while Fastify's underlying router preserves the encoding during route lookup. The two layers disagree on the canonical request path, so the middleware fails to match a URL that the route handler does match. When middleware is used for authentication, authorization, rate limiting, or auditing on parameterized paths, an attacker can reach the CVSSv3.1 9.1 (CRITICAL)

CWECWE 436TYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2026-07-01
2026-07-01 11:16Z
HIGH

CVE-2026-13228 — LatePoint: The LatePoint – Calendar Booking Plugin for Appointments and Events plugin for WordPress is

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-13228

The LatePoint – Calendar Booking Plugin for Appointments and Events plugin for WordPress is vulnerable to Privilege Escalation to Administrator in versions up to, and including, 5.6.3 This is due to an Insecure Direct Object Reference (IDOR) in the create_or_update() function of OsOrdersController, which allows an authenticated Agent to supply an arbitrary order[customer_id] and overwrite any LatePoint customer's email field (including one linked to a WordPress Administrator' CVSSv3.1 8.8 (HIGH)

CWECWE 269VNDLatepointTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-07-01
2026-07-01 10:00Z
HIGH

The SOC Files: ScreenConnect masked as freeware. An inside look at a large-scale campaign

Kaspersky Securelist·securelist.comin the wild

Kaspersky MDR uncovered a large-scale campaign distributing ScreenConnect remote access tool disguised as legitimate freeware (OBS Studio, DNS Jumper, DS4Windows, etc.) via typosquatted domains optimized for search engine ranking. The malicious installers use DLL sideloading to deploy ScreenConnect alongside AsyncRAT, establishing persistence via scheduled tasks and disabling Windows Defender. The infrastructure spans 90+ domains across 10 languages, hosted on three IP clusters, with the campaign active from October 2025 through March 2026.

SRFApplicationTACTA0005TACTA0001SRFWebTACTA0003SWAsyncratSWScreenconnectTYPResearch
78
Edit Score
2026-07-01
2026-07-01 08:16Z
HIGH

CVE-2026-12224 — Dokan: The Dokan Pro plugin for WordPress is vulnerable to privilege escalation via update_capabilities REST

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-12224

The Dokan Pro plugin for WordPress is vulnerable to privilege escalation via update_capabilities REST Endpoint in all versions up to, and including, 5.0.4. This is due to the `update_capabilities()` REST handler accepting arbitrary capability strings from the request body and passing them directly to WP_User::add_cap() with no allowlist validation, only verifying that the caller holds the dokandar capability. This makes it possible for authenticated attackers with a self-pro CVSSv3.1 8.8 (HIGH)

CWECWE 269VNDDokanTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-07-01
2026-07-01 08:16Z
HIGH

CVE-2026-12158 — RegistrationMagic: The RegistrationMagic – User Registration Forms Plugin plugin for WordPress is vulnerable to Cross-Site

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-12158

The RegistrationMagic – User Registration Forms Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 6.0.9.1. This is due to missing or incorrect nonce validation on the process_request function. This makes it possible for unauthenticated attackers to escalate the privileges of an arbitrary form submitter to administrator by creating a malicious Chronos automation task that is executed via WordPress cron via a forged re CVSSv3.1 8.8 (HIGH)

CWECWE 352VNDRegistrationmagicTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-07-01
2026-07-01 08:16Z
CRIT

CVE-2026-11387 — SMS: The SMS Alert – SMS & OTP for WooCommerce, Order Notifications & Abandoned Cart

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-11387

The SMS Alert – SMS & OTP for WooCommerce, Order Notifications & Abandoned Cart Recovery plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 3.9.5. This is due to the plugin not properly validating a user's identity prior to updating their details like reset the password of any user account, including administrators, and gain full access to those accounts. This makes it possible for unauthenticated attackers to CVSSv3.1 9.8 (CRITICAL)

CWECWE 287VNDSmsTYPVulnerability
9.8
CVSS v3.1
99
Edit Score