2026-06-29
2026-06-29 14:16Z
HIGH

CVE-2026-40524 — FrontAccounting: before 2.4.20 contains a SQL injection vulnerability in the get_gl_transactions() function where the

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-40524

FrontAccounting before 2.4.20 contains a SQL injection vulnerability in the get_gl_transactions() function where the filter_type parameter is concatenated directly into a SQL IN() clause without parameterization. Attackers with SA_GLANALYTIC permission can inject arbitrary SQL by supplying a closing parenthesis followed by malicious conditions to extract sensitive journal entry data through boolean-based blind SQL injection with reliable response size differentials. CVSSv3.1 8.1 (HIGH)

CWECWE 89VNDFrontaccountingTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-06-29
2026-06-29 14:16Z
HIGH

CVE-2026-40523 — FrontAccounting: before 2.4.20 contains a SQL injection vulnerability in the Audit Trail report handler

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-40523

FrontAccounting before 2.4.20 contains a SQL injection vulnerability in the Audit Trail report handler that allows authenticated attackers with SA_GLANALYTIC permission to execute arbitrary SQL queries by injecting malicious code into the PARAM_2 and PARAM_3 POST parameters. Attackers can exploit time-based blind SQL injection through SLEEP() functions that are amplified across JOIN result sets to cause denial of service by exhausting database connections, or extract arbitrar CVSSv3.1 8.1 (HIGH)

CWECWE 89VNDFrontaccountingTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-06-29
2026-06-29 14:16Z
HIGH

CVE-2026-40521 — FrontAccounting: before 2.4.20 contains a path traversal vulnerability in the attachment upload handler that

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-40521

FrontAccounting before 2.4.20 contains a path traversal vulnerability in the attachment upload handler that allows authenticated attackers to execute arbitrary code by uploading files with traversal sequences in the unique_name parameter. Attackers can supply path traversal sequences ../../../shell.php to write files outside the intended attachments directory into the web root, and by uploading PHP files without extension validation, achieve remote code execution as the web s CVSSv3.1 8.8 (HIGH)

CWECWE 22VNDFrontaccountingTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-06-29
2026-06-29 14:16Z
HIGH

CVE-2026-12856 — If a user clicks a specially crafted link within a JavaDoc hover popup, an

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-12856

A flaw was found in the vscode-java extension, which provides Java language support for Visual Studio Code. The extension incorrectly trusts all Markdown content in JavaDoc hovers, allowing a malicious Java file to include hidden commands. If a user clicks a specially crafted link within a JavaDoc hover popup, an attacker can execute arbitrary VS Code commands, which can lead to full system compromise in trusted workspaces. CVSSv3.1 8.8 (HIGH)

CWECWE 88TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-06-29
2026-06-29 14:00Z
HIGH

Charting your way in: Helm template injection

Synacktiv·synacktiv.com

Synacktiv published an in-depth technical analysis of YAML template injection vulnerabilities in Helm charts, particularly when values are rendered without escaping or validation. The research demonstrates how attackers with repository push access can inject arbitrary YAML—including new Kubernetes objects, privilege escalation payloads, and cluster-scoped resources—through multi-line value syntax (| and |-). The article covers exploitation techniques, differences between Helm v3 and v4 (where server-side apply mitigates some attacks), and defensive strategies including JSON schema validation, Helm escaping functions, and ArgoCD resource whitelisting.

SRFApplicationTACTA0004TACTA0002SRFCloudSWKubernetesSWArgocdSWHelmTYPResearch
78
Edit Score
2026-06-29
2026-06-29 12:16Z
HIGH

CVE-2026-13564 — Edimax: Performing a manipulation of the argument pppUserName results in stack-based buffer overflow.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-13564

A vulnerability was found in Edimax EW-7478APC 1.04. Affected is the function formPPPoESetup of the file /goform/formPPPoESetup of the component POST Request Handler. Performing a manipulation of the argument pppUserName results in stack-based buffer overflow. The attack can be initiated remotely. The exploit has been made public and could be used. The vendor was contacted early about this disclosure but did not respond in any way. CVSSv3.1 8.8 (HIGH)

CWECWE 121CWECWE 119VNDEdimaxTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-06-29
2026-06-29 12:16Z
HIGH

CVE-2026-13563 — Such manipulation of the argument L2TPUserName leads to stack-based buffer overflow.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-13563

A vulnerability has been found in Edimax EW-7478APC 1.04. This impacts the function formL2TPSetup of the file /goform/formL2TPSetup of the component POST Request Handler. Such manipulation of the argument L2TPUserName leads to stack-based buffer overflow. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way. CVSSv3.1 8.8 (HIGH)

CWECWE 121CWECWE 119TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
728 × 90 / responsive · programmatic ad slot
2026-06-29
2026-06-29 12:16Z
HIGH

CVE-2026-13562 — This manipulation of the argument selSSID causes buffer overflow.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-13562

A flaw has been found in Edimax EW-7478APC 1.04. This affects the function formiNICSiteSurvey of the file /goform/formiNICSiteSurvey of the component POST Request Handler. This manipulation of the argument selSSID causes buffer overflow. It is possible to initiate the attack remotely. The exploit has been published and may be used. The vendor was contacted early about this disclosure but did not respond in any way. CVSSv3.1 8.8 (HIGH)

CWECWE 120CWECWE 119TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-06-29
2026-06-29 10:16Z
HIGH

CVE-2026-25707 — A relative path traversal bug problem when processing repository metadata in libzypp before 17.38.10

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-25707

A relative path traversal bug problem when processing repository metadata in libzypp before 17.38.10 could be used by remote attackers supplying repositories to overwrite files on the system, leading to denial of service or privilege escalation. CVSSv3.1 8.8 (HIGH)

CWECWE 23TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-06-29
2026-06-29 10:00Z
CRIT

The Gentlemen are knocking: сustom backdoors and evolving tactics

Kaspersky Securelist·securelist.comin the wild

Kaspersky documents The Gentlemen RaaS group's operations, a top-10 ransomware actor in 2026 using custom Go and C-based malware. The group employs multi-stage attacks combining stolen credentials, VPN/firewall exploitation, custom backdoors, BYOVD driver abuse, GPO-based lateral movement, and hybrid encryption (Curve25519/XChaCha20). Novel TTPs include network sniffing via netsh, SharpADWS for AD enumeration, custom Go obfuscator, and coordinated ransomware deployment across enterprise networks.

SRFApplicationSRFOsTACTA0004TACTA0005TACTA0001SRFNetworkTACTA0007TACTA0003
82
Edit Score
2026-06-29
2026-06-29 09:16Z
HIGH

CVE-2026-13545 — Such manipulation of the argument UID leads to os command injection.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-13545

A vulnerability has been found in D-Link DCS-935L 1.10.01. This affects the function sub_400E40 of the file setconf.cgi of the component POST Parameter Handler. Such manipulation of the argument UID leads to os command injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. CVSSv3.1 8.8 (HIGH)

CWECWE 77CWECWE 78TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-06-29
2026-06-29 07:16Z
HIGH

CVE-2026-13539 — Wavlink: Such manipulation of the argument Guest_ssid leads to stack-based buffer overflow.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-13539

A vulnerability was identified in Wavlink WL-NU516U1-A M16U1_V240425. The impacted element is the function sub_407504 of the file /cgi-bin/wireless.cgi of the component POST Parameter Handler. Such manipulation of the argument Guest_ssid leads to stack-based buffer overflow. The attack can be executed remotely. The exploit is publicly available and might be used. It is suggested to upgrade the affected component. The vendor was contacted early, responded in a very professiona CVSSv3.1 8.8 (HIGH)

CWECWE 121CWECWE 119VNDWavlinkTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-06-29
2026-06-29 07:16Z
HIGH

CVE-2025-2902 — Authorization: Improper Authorization Vulnerability of Maintenance Utility in Hitachi Virtual Storage Platform.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2025-2902

Improper Authorization Vulnerability of Maintenance Utility in Hitachi Virtual Storage Platform. This issue affects Hitachi Virtual Storage Platform E390, E590, E790, E990, E1090, E390H, E590H, E790H, E1090H: before DKCMAIN Ver. 93-07-26-xx/00, GUM Ver. 93-07-26/00; Hitachi Virtual Storage Platform 5100, 5500, 5100H, 5500H, 5200, 5600, 5200H, 5600H: before DKCMAIN Ver. 90-09-27-00/00, GUM Ver. 90-09-27/00; Hitachi Virtual Storage Platform G130, G150, G350, G370, G700, G900, CVSSv3.1 8.3 (HIGH)

CWECWE 862TYPVulnerability
8.3
CVSS v3.1
92
Edit Score
2026-06-29
2026-06-29 05:51Z
CRIT

ipv6_frag_escape — Linux LPE - Reliable Jail/Container Escape

GitHub · container escape·github.comGITHUB POC

A proof-of-concept Linux privilege escalation and container escape exploit targeting CentOS/RHEL 10 (kernel 6.12.x). The exploit chains an IPv6 fragmentation bug in __ip6_append_data() (already patched upstream, no CVE assigned) through in-slab overflow, page use-after-free, KASLR defeat, and arbitrary kernel read/write to achieve unprivileged-to-root escape from network-isolated containers. The PoC deliberately omits reliability scaffolding and is scoped to specific kernel configurations.

SRFOsTACTA0004OSLinuxTYPExploitSTGPrivescSTGImpactTECT1548EXPPrivilege Escalation
92
Edit Score
2026-06-29
2026-06-29 02:16Z
HIGH

CVE-2026-13519 — Tenda: The manipulation of the argument page results in stack-based buffer overflow.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-13519

A vulnerability was found in Tenda JD12L 16.03.53.23. This impacts the function fromNatStaticSetting of the file /goform/NatStaticSetting. The manipulation of the argument page results in stack-based buffer overflow. The attack can be executed remotely. The exploit has been made public and could be used. CVSSv3.1 8.8 (HIGH)

CWECWE 121CWECWE 119VNDTendaTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-06-29
2026-06-29 01:16Z
HIGH

CVE-2026-13518 — The manipulation of the argument page leads to stack-based buffer overflow.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-13518

A vulnerability has been found in Tenda JD12L 16.03.53.23. This affects the function fromAddressNat of the file /goform/addressNat. The manipulation of the argument page leads to stack-based buffer overflow. Remote exploitation of the attack is possible. The exploit has been disclosed to the public and may be used. CVSSv3.1 8.8 (HIGH)

CWECWE 121CWECWE 119TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-06-29
2026-06-29 01:16Z
HIGH

CVE-2026-13517 — Executing a manipulation of the argument security_5g can lead to stack-based buffer overflow.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-13517

A flaw has been found in Tenda JD12L 16.03.53.23. The impacted element is the function formWifiBasicSet of the file /goform/WifiBasicSet. Executing a manipulation of the argument security_5g can lead to stack-based buffer overflow. The attack may be launched remotely. The exploit has been published and may be used. CVSSv3.1 8.8 (HIGH)

CWECWE 121CWECWE 119TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-06-29
2026-06-29 00:16Z
HIGH

CVE-2026-13516 — Tenda: Performing a manipulation of the argument shareSpeed results in stack-based buffer overflow.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-13516

A vulnerability was detected in Tenda JD12L 16.03.53.23. The affected element is the function fromSetWifiGusetBasic of the file /goform/WifiGuestSet. Performing a manipulation of the argument shareSpeed results in stack-based buffer overflow. The attack may be initiated remotely. The exploit is now public and may be used. CVSSv3.1 8.8 (HIGH)

CWECWE 121CWECWE 119VNDTendaTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-06-29
2026-06-29 00:16Z
HIGH

CVE-2026-13515 — Such manipulation of the argument startIp leads to stack-based buffer overflow.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-13515

A security vulnerability has been detected in Tenda JD12L 16.03.53.23. Impacted is the function formSetPPTPServer of the file /goform/SetPptpServerCfg. Such manipulation of the argument startIp leads to stack-based buffer overflow. The attack can be launched remotely. The exploit has been disclosed publicly and may be used. CVSSv3.1 8.8 (HIGH)

CWECWE 121CWECWE 119TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-06-29
2026-06-29 00:00Z
HIGH

TONResolver RAT Abuses TON Blockchain to Target Japan's Hotel Industry

Trend Micro Research·trendmicro.comin the wild

Trend Micro disclosed TONResolver, a JavaScript-based RAT targeting Japanese hotel chains via phishing emails impersonating Booking.com complaints. The malware abuses the TON blockchain as a dead-drop resolver for C&C infrastructure, enabling attackers to swap server addresses without recompilation. Infection chains through LNK files, PowerShell obfuscation, and Node.js deployment with VM-based obfuscation and ECDH+AES-256-CBC encryption.

SRFApplicationTACTA0005TACTA0001TACTA0002SRFWebTACTA0003TACTA0011SWTon
78
Edit Score
2026-06-28
2026-06-28 19:16Z
CRIT

CVE-2026-49048 — Joomla: The Joomla extension JoomCCK exposes a front-end controller task, that builds two SQL statements

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-49048

The Joomla extension JoomCCK exposes a front-end controller task, that builds two SQL statements by directly concatenating a user-supplied request parameter into the query string without escaping or parameterisation. CVSSv3.1 9.8 (CRITICAL)

CWECWE 89VNDJoomlaTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-06-28
2026-06-28 02:16Z
CRIT

CVE-2026-58053 — Gitea: act_runner with the Docker backend (through act 0.262.0) passes a workflow's container.options string

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-58053

Gitea act_runner with the Docker backend (through act 0.262.0) passes a workflow's container.options string to the Docker job container's HostConfig and, when configured with privileged: false, forces only the Privileged flag off while merging options such as --pid=host, --cap-add, and --security-opt unchanged. A user who can run a workflow on a Docker-backed runner can create a job container with host namespaces and broad capabilities and escape to the host as root despite p CVSSv3.1 9.9 (CRITICAL)

CWECWE 269VNDGiteaTYPVulnerability
9.9
CVSS v3.1
100
Edit Score
2026-06-28
2026-06-28 02:16Z
HIGH

CVE-2026-58049 — RASC: A crafted media stream using the RASC FourCC, decoded by libavcodec, triggers a bitstream-controlled

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-58049

FFmpeg's RASC video decoder (decode_dlta in libavcodec/rasc.c) performs 32-bit reads and writes at the row cursor before the NEXT_LINE row-boundary check and validates the DLTA region in pixel rather than byte units, so a DLTA run on a PAL8 frame can access several bytes past the row allocation. A crafted media stream using the RASC FourCC, decoded by libavcodec, triggers a bitstream-controlled out-of-bounds heap write and adjacent out-of-bounds read, leading to memory corrup CVSSv3.1 8.6 (HIGH)

CWECWE 787VNDRascTYPVulnerability
8.6
CVSS v3.1
93
Edit Score
2026-06-28
2026-06-28 00:16Z
HIGH

CVE-2026-8095 — Frontend: The Frontend File Manager Plugin plugin for WordPress is vulnerable to Authenticated Arbitrary File

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-8095

The Frontend File Manager Plugin plugin for WordPress is vulnerable to Authenticated Arbitrary File Deletion in versions up to and including 23.6. This is due to a case-sensitive bypass of the wpfm_dir_path parameter sanitization in the wpfm_file_meta_update AJAX handler, where supplying WPFM_DIR_PATH in uppercase evades the unset check and is normalized to wpfm_dir_path by sanitize_key() during update_post_meta(), allowing an attacker to overwrite the stored file path with a CVSSv3.1 8.1 (HIGH)

CWECWE 73VNDFrontendTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-06-28
2026-06-28 00:16Z
HIGH

CVE-2026-10643 — 16-27 bytes for IPv4 IP_PKTINFO on a 64-bit target, where a single element actually

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-10643

Zephyr's IP socket recvmsg() implementation (subsys/net/lib/sockets/sockets_inet.c, insert_pktinfo()) validated the user-supplied ancillary (msg_control) buffer using only the payload length (msg-msg_controllen < pktinfo_len) before writing a full control message consisting of an aligned cmsg header plus the payload. Because the check omitted the cmsg header size, a control buffer whose length falls in the under-checked window (e.g. 16-27 bytes for IPv4 IP_PKTINFO on a 64-bit CVSSv3.1 8.7 (HIGH)

CWECWE 787TYPVulnerability
8.7
CVSS v3.1
94
Edit Score