2026-06-24
2026-06-24 16:16Z
CRIT

CVE-2026-56121 — Feast: before 0.63.0 contains an unsafe deserialization vulnerability that allows unauthenticated or unauthorized attackers

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-56121

Feast before 0.63.0 contains an unsafe deserialization vulnerability that allows unauthenticated or unauthorized attackers to achieve remote code execution by sending a crafted gRPC request to the registry server. The user_defined_function.body field of an OnDemandFeatureView spec is decoded from base64 and passed to dill.loads() before any authorization check is performed, enabling attackers to embed a malicious serialized Python object with an arbitrary __reduce__ method to CVSSv3.1 9.8 (CRITICAL)

CWECWE 502VNDFeastTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-06-24
2026-06-24 16:16Z
CRIT

CVE-2026-56111 — Marlin: Firmware through 2.1.2.7, fixed in commit 1f255d1, when built with MESH_BED_LEVELING enabled, contains

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-56111

Marlin Firmware through 2.1.2.7, fixed in commit 1f255d1, when built with MESH_BED_LEVELING enabled, contains an out-of-bounds write vulnerability in the M421 G-code handler that allows attackers to corrupt firmware memory by supplying out-of-range X and Y grid indices. Attackers can send a single crafted G-code command via USB serial, network interface, or malicious gcode file to write an attacker-controlled 32-bit float value past the z_values array bounds, corrupting adjac CVSSv3.1 9.1 (CRITICAL)

CWECWE 129VNDMarlinTYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2026-06-24
2026-06-24 16:16Z
HIGH

CVE-2026-49269 — Apple: M1 GPUs retain register file data between compute shader dispatches from different processes.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-49269

Apple M1 GPUs retain register file data between compute shader dispatches from different processes. A sandboxed Metal attacker app can run a GPU reader shader that reads stale register values left by a separate sandboxed victim app. In the proof of concept, GPUVictim.app generates a fresh random 128-bit secret using SecRandomCopyBytes and loads it into GPU registers. GPUAttacker.app, a separate sandboxed app, recovers the exact secret from stale GPU register state. NOTE: The CVSSv3.1 8.6 (HIGH) · EPSS 22th percentile

CWECWE 200VNDAppleTYPVulnerability
8.6
CVSS v3.1
93
Edit Score
2026-06-24
2026-06-24 15:49Z
HIGH

CVE-2026-47729 | Squid Heap Buffer Overread Vulnerability

Horizon3.ai·horizon3.aiCVE-2026-47729

CVE-2026-47729 (Squidbleed) is a heap buffer overread in Squid's FTP gateway parser that leaks adjacent memory contents—credentials, cookies, API keys, session tokens—when processing malformed FTP directory listings from attacker-controlled servers. The vulnerability requires an attacker-controlled FTP server reachable through the proxy and is most impactful in shared proxy environments. Squid 7.7+ contains the fix; no confirmed in-the-wild exploitation has been reported.

SRFNetwork ApplianceTACTA0006SWSquidTYPVulnerabilitySTGCollectionTECT1005EXPHeap OverflowSTApatched
72
Edit Score
2026-06-24
2026-06-24 14:17Z
HIGH

CVE-2026-57301 — Jenkins: OWASP ZAP Plugin 1.0.7 and earlier performs build operations on the Jenkins controller

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-57301

Jenkins OWASP ZAP Plugin 1.0.7 and earlier performs build operations on the Jenkins controller rather than the assigned agent, allowing attackers with Item/Configure permission to execute arbitrary code on the Jenkins controller. CVSSv3.1 8.8 (HIGH)

CWECWE 610VNDJenkinsTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-06-24
2026-06-24 14:17Z
HIGH

CVE-2026-57296 — Jenkins: External Workspace Manager Plugin 1.3.2 and earlier does not reject path traversal sequences

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-57296

Jenkins External Workspace Manager Plugin 1.3.2 and earlier does not reject path traversal sequences in the custom workspace path provided to the exwsAllocate Pipeline step, allowing attackers with Item/Configure permission to read arbitrary files on the Jenkins controller file system, which can lead to remote code execution. CVSSv3.1 8.8 (HIGH)

CWECWE 22VNDJenkinsTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-06-24
2026-06-24 14:17Z
HIGH

CVE-2026-57280 — Jenkins: Script Security Plugin 1402.v94c9ce464861 and earlier does not intercept the implicit type casts

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-57280

Jenkins Script Security Plugin 1402.v94c9ce464861 and earlier does not intercept the implicit type casts applied to the elements of typed for-each loops in sandboxed Groovy scripts, allowing attackers able to provide such scripts to invoke arbitrary constructors and bypass the sandbox protection. CVSSv3.1 8.8 (HIGH)

CWECWE 693VNDJenkinsTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
728 × 90 / responsive · programmatic ad slot
2026-06-24
2026-06-24 14:17Z
HIGH

CVE-2026-35025 — ProFTPD: through 1.3.9b and 1.3.10rc2 contains an access control bypass vulnerability that allows authenticated

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-35025

ProFTPD through 1.3.9b and 1.3.10rc2 contains an access control bypass vulnerability that allows authenticated FTP users to circumvent Directory ACL restrictions by prefixing paths with /proc/self/root in the RNFR command handler. Attackers can exploit the unresolved symlink components in dir_canonical_path() to cause dir_check() to perform lexical path comparisons that match no configured Directory block, enabling rename operations on files in DenyAll-protected directories a CVSSv3.1 8.1 (HIGH)

CWECWE 59VNDProftpdTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-06-24
2026-06-24 13:16Z
HIGH

CVE-2026-56351 — n8n before version 2.4.0 contains a sql injection vulnerability in MySQL, PostgreSQL, and Microsoft

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-56351

n8n before version 2.4.0 contains a sql injection vulnerability in MySQL, PostgreSQL, and Microsoft SQL nodes that allows authenticated users to inject arbitrary SQL through unescaped identifier values in node configuration parameters. Attackers with workflow creation permissions can supply specially crafted table or column names to execute unauthorized database commands and compromise data integrity. CVSSv3.1 8.2 (HIGH)

CWECWE 89TYPVulnerability
8.2
CVSS v3.1
91
Edit Score
2026-06-24
2026-06-24 13:16Z
HIGH

CVE-2026-56245 — Supabase: Capgo before 12.128.2 contains an authorization bypass vulnerability in the SECURITY DEFINER record_build_time

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-56245

Supabase Capgo before 12.128.2 contains an authorization bypass vulnerability in the SECURITY DEFINER record_build_time RPC function that allows unauthenticated attackers to insert arbitrary build-time records. Attackers can exploit this by calling POST /rest/v1/rpc/record_build_time with a public API key to poison billing and quota data for any organization, enabling resource exhaustion and cross-tenant billing manipulation. CVSSv3.1 8.2 (HIGH)

CWECWE 269VNDSupabaseTYPVulnerability
8.2
CVSS v3.1
91
Edit Score
2026-06-24
2026-06-24 13:16Z
CRIT

CVE-2026-56237 — Capgo: An attacker can tamper with the API key parameter in the generation request and

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-56237

Capgo before 12.128.2 contains a broken authentication vulnerability in its API key generation mechanism. API keys are exposed in frontend requests, and the backend fails to validate that keys are securely generated and bound to the authenticated user. An attacker can tamper with the API key parameter in the generation request and supply arbitrary values, generating custom API keys without proper authorization, which can lead to unauthorized access to protected endpoints. CVSSv3.1 9.1 (CRITICAL)

CWECWE 287VNDCapgoTYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2026-06-24
2026-06-24 13:16Z
HIGH

CVE-2026-56232 — Capgo: Attackers can bypass subkey scope restrictions by referencing their own subkeys, causing all downstream

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-56232

Capgo before 12.128.2 fails to enforce limited_to_orgs and limited_to_apps constraints on subkeys provided via x-limited-key-id header in middlewareKey function. Attackers can bypass subkey scope restrictions by referencing their own subkeys, causing all downstream route handlers to use the unrestricted parent key instead of the scoped subkey. CVSSv3.1 8.8 (HIGH)

CWECWE 863VNDCapgoTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-06-24
2026-06-24 13:16Z
HIGH

CVE-2026-56223 — Capgo: before 12.128.2 contains a cross-domain SSO account takeover vulnerability in the provision-user endpoint

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-56223

Capgo before 12.128.2 contains a cross-domain SSO account takeover vulnerability in the provision-user endpoint that allows attackers to merge arbitrary victim accounts based on email match without validating SSO provider domain authorization. An attacker with enterprise org admin access and a malicious IdP can forge SAML assertions containing victim email addresses to trigger account merge and gain full access to victim accounts, organizations, and data. CVSSv3.1 8.7 (HIGH)

CWECWE 287VNDCapgoTYPVulnerability
8.7
CVSS v3.1
94
Edit Score
2026-06-24
2026-06-24 13:16Z
HIGH

CVE-2026-12242 — AdRotate: The AdRotate Banner Manager plugin for WordPress is vulnerable to PHP Code Injection in

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-12242

The AdRotate Banner Manager plugin for WordPress is vulnerable to PHP Code Injection in all versions up to, and including, 5.17.7 via the 'banner' attribute of the adrotate shortcode. This is due to insufficient input validation and sanitization of the banner shortcode attribute before concatenation into a PHP code string wrapped in W3 Total Cache mfunc or Borlabs Cache fragment markers. This makes it possible for authenticated attackers, with Contributor-level access and abo CVSSv3.1 8.8 (HIGH)

CWECWE 94VNDAdrotateTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-06-24
2026-06-24 13:16Z
HIGH

CVE-2025-71361 — picklescan before 0.0.29 fails to detect malicious idlelib.calltip.Calltip.fetch_tip calls in pickle files, allowing remote

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2025-71361

picklescan before 0.0.29 fails to detect malicious idlelib.calltip.Calltip.fetch_tip calls in pickle files, allowing remote code execution. Attackers can embed undetected payloads in pickle files that execute arbitrary code when loaded via pickle.load(). CVSSv3.1 8.1 (HIGH)

CWECWE 95TYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-06-24
2026-06-24 13:16Z
HIGH

CVE-2025-71354 — picklescan before 0.0.29 fails to detect malicious pickle files that exploit idlelib.debugobj.ObjectTreeItem.SetText function in

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2025-71354

picklescan before 0.0.29 fails to detect malicious pickle files that exploit idlelib.debugobj.ObjectTreeItem.SetText function in reduce methods. Attackers can craft pickle files with embedded code that bypasses picklescan detection and executes arbitrary commands when pickle.load() is called. CVSSv3.1 8.1 (HIGH)

CWECWE 502TYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-06-24
2026-06-24 13:00Z
HIGH

AI Finds Vulnerabilities. Security Experts Find Impact.

Bishop Fox Labs·bishopfox.com

Bishop Fox security consultant documents a real web application assessment where AI-assisted code review identified vulnerability patterns but required human expertise to determine actual impact. Two case studies illustrate the gap: a phone-verification bypass that became account-creation at scale only after discovering reusable invitation codes, and an SSRF that appeared blind until fuzzing revealed data-extraction via mime-type manipulation. The post argues AI excels at pattern detection but fails at impact assessment and confidence calibration.

SRFApplicationTACTA0006SRFWebVNDBishop FoxTYPResearchTYPWriteupSTGDiscoverySTGCred Access
72
Edit Score
2026-06-24
2026-06-24 10:00Z
HIGH

StrikeShark: investigating a new campaign delivering Cobalt Strike through SharkLoader

Kaspersky disclosed StrikeShark, a previously undocumented campaign deploying SharkLoader—a custom malware loader that delivers Cobalt Strike Beacon. The threat actor gains initial access via exploitation of internet-facing applications (Exchange, SharePoint, Openfire, GeoServer, F5 BIG-IP, Fortinet FortiOS, Cisco IOS XE) and dropper-based distribution, targeting diplomatic, government, and software development entities across Indonesia, Taiwan, Hong Kong, Lebanon, Syria, Colombia, and other regions. SharkLoader employs sophisticated evasion techniques including DLL sideloading, Perfect DLL Hijacking to bypass Windows loader locks, Blowfish and AES encryption for payload obfuscation, reflective PE loading, and Vectored Exception Handlers for API hooking.

SRFApplicationTACTA0005TACTA0001SRFNetwork ApplianceSRFWebTACTA0003SWCobalt StrikeVNDMicrosoft
78
Edit Score
2026-06-24
2026-06-24 08:16Z
HIGH

CVE-2026-7761 — Ultimate: The Ultimate Member plugin for WordPress is vulnerable to Account Takeover via Password Reset

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-7761

The Ultimate Member plugin for WordPress is vulnerable to Account Takeover via Password Reset Link Disclosure in all versions up to and including 2.11.4. This is due to a chain of three logic bugs: (1) an MD5 hash fallback in get_directory_by_hash() that allows any post to be used as a member directory by computing SUBSTRING(MD5(post_id), 11, 5), (2) a strstr() parsing logic flaw in post_data() that allows bypassing WordPress's protected meta key restrictions by placing '_um_ CVSSv3.1 8.8 (HIGH)

CWECWE 862VNDUltimateTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-06-24
2026-06-24 08:16Z
HIGH

CVE-2026-52934 — Linux: In the Linux kernel, the following vulnerability has been resolved: batman-adv: tvlv: reject oversized

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-52934

In the Linux kernel, the following vulnerability has been resolved: batman-adv: tvlv: reject oversized TVLV packets batadv_tvlv_container_ogm_append() builds a TVLV packet section from the tvlv.container_list. The total size of this section is computed by batadv_tvlv_container_list_size(), which sums the sizes of all registered containers. The return type and accumulator in batadv_tvlv_container_list_size() were u16. If the accumulated size exceeds U16_MAX, the value wraps CVSSv3.1 8.8 (HIGH) · EPSS 6th percentile

TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-06-24
2026-06-24 08:16Z
CRIT

CVE-2026-52931 — Linux: In the Linux kernel, the following vulnerability has been resolved: batman-adv: tp_meter: avoid use

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-52931

In the Linux kernel, the following vulnerability has been resolved: batman-adv: tp_meter: avoid use of uninit sender vars batadv_tp_recv_ack() and batadv_tp_stop() are only valid for tp_vars in the BATADV_TP_SENDER role. When called with a BATADV_TP_RECEIVER role, it proceeds to read sender-only members that were never initialized, leading to undefined behavior. This can be triggered when a node that is currently acting as a receiver in an ongoing tp_meter session receives CVSSv3.1 9.8 (CRITICAL) · EPSS 6th percentile

TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-06-24
2026-06-24 08:16Z
CRIT

CVE-2026-52924 — Linux: Later, SCTP scheduler dequeue paths (FCFS, RR, PRIO, etc.) rely on stream->out_curr->ext, which can

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-52924

In the Linux kernel, the following vulnerability has been resolved: sctp: purge outqueue on stale COOKIE-ECHO handling sctp_stream_update() is only invoked when the association is moved into COOKIE_WAIT during association setup/reconfiguration. In this path, the outbound stream scheduler state (stream->out_curr) is expected to be clean, since no user data should have been transmitted yet unless the state machine has already partially progressed. However, a corner case exis CVSSv3.1 9.8 (CRITICAL) · EPSS 6th percentile

TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-06-24
2026-06-24 08:16Z
HIGH

CVE-2026-52920 — Linux: In the Linux kernel, the following vulnerability has been resolved: netfilter: xt_policy: fix strict

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-52920

In the Linux kernel, the following vulnerability has been resolved: netfilter: xt_policy: fix strict mode inbound policy matching match_policy_in() walks sec_path entries from the last transform to the first one, but strict policy matching needs to consume info->pol[] in the same forward order as the rule layout. Derive the strict-match policy position from the number of transforms already consumed so that multi-element inbound rules are matched consistently. CVSSv3.1 8.3 (HIGH) · EPSS 6th percentile

TYPVulnerability
8.3
CVSS v3.1
92
Edit Score
2026-06-24
2026-06-24 08:16Z
HIGH

CVE-2026-52918 — Linux: In the Linux kernel, the following vulnerability has been resolved: Bluetooth: serialize accept_q access

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-52918

In the Linux kernel, the following vulnerability has been resolved: Bluetooth: serialize accept_q access bt_sock_poll() walks the accept queue without synchronization, while child teardown can unlink the same socket and drop its last reference. The unsynchronized accept queue walk has existed since the initial Bluetooth import. Protect accept_q with a dedicated lock for queue updates and polling. Also rework bt_accept_dequeue() to take temporary child references under the CVSSv3.1 8.8 (HIGH) · EPSS 7th percentile

TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-06-24
2026-06-24 08:16Z
CRIT

CVE-2026-52914 — Linux: That accounting currently allows the accumulated fragment length to be truncated during updates.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-52914

In the Linux kernel, the following vulnerability has been resolved: batman-adv: fix fragment reassembly length accounting batman-adv keeps a running payload length for queued fragments and uses it to validate a fragment chain before reassembly. That accounting currently allows the accumulated fragment length to be truncated during updates. As a result, malformed fragment chains can bypass the intended validation and drive reassembly with inconsistent length state, leading CVSSv3.1 9.8 (CRITICAL) · EPSS 8th percentile

TYPVulnerability
9.8
CVSS v3.1
99
Edit Score