A time-to-check-time-of-use in polkit authentication of qSnapper before version 1.3.3 allowed a local attacker to bypass qSnappers authentication mechanism and operate e.g. as root user.
CVSSv3.1 8.1 (HIGH)
CWECWE 367TYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-06-22
2026-06-22 16:16Z
HIGH
CVE-2026-12628 — IBM: Storage Protect Client 8.1.0.0 through 8.2.1.0 and IBM Storage Protect Snapshot For Windows
IBM Storage Protect Client 8.1.0.0 through 8.2.1.0 and IBM Storage Protect Snapshot For Windows 8.1.0.0 through 8.2.1.0 could allow a remote attacker to bypass authentication due to the use of a hardcoded credential in the FlashCopy Manager (FCM) authentication mechanism. The application contains a static credential embedded in multiple authentication code paths, and does not properly validate authentication responses, which may allow an unauthenticated attacker to establish
CVSSv3.1 8.1 (HIGH)
CWECWE 798VNDIbmTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-06-22
2026-06-22 15:59Z
CRIT
Out of Shift: How a Shared State Bug in V8’s AsmJS Parser Broke the Ubercage
A shared state bug in V8's AsmJS parser allows an attacker to corrupt the WebAssembly opcode stream by exploiting recursive ShiftExpression() calls that overwrite the heap_access_shift_position_ member variable. The corrupted stream causes immediate values to be misinterpreted as opcodes, enabling arbitrary read/write primitives that break out of the Ubercage sandbox. The vulnerability was patched in Chrome on March 3, 2026.
Sekoia's TDR team published a comprehensive two-decade retrospective of APT28 (GRU Unit 26165) tradecraft evolution, from signature X-Agent/X-Tunnel implants through disposable modular malware to LLM-integrated infostealers. The analysis documents major operational shifts including the 2019 Mueller Report-induced five-year public blind spot, weaponization of zero-click Outlook CVE-2023-23397 for NTLMv2 harvesting, systematic migration to compromised edge-device infrastructure (MooBot, FrostArmada DNS hijacking), and the 2025 emergence of LameHug—the first APT28 malware delegating command logic to Qwen 2.5 LLM via Hugging Face API.
ADINT: From Ad-Based Geolocation Tracking to Intrusion Vector
Sekoia.io·sekoia.ioin the wild
Sekoia's TDR team documents ADINT (Advertising-based Intelligence), the weaponization of legitimate AdTech mechanisms—real-time bidding (RTB) and third-party SDKs—into a surveillance apparatus spanning passive geolocation profiling, active near-real-time tracking, and offensive zero-click spyware deployment via malicious ads. The research categorizes three escalating threat levels: passive ADINT for group profiling via RTB data leakage; active ADINT for targeted individual tracking using Mobile Advertising IDs; and offensive ADINT exploiting ad delivery to remotely install spyware on mobile devices, exemplified by Intellexa's Aladdin and Insanet's Sherlock.
Use After Free in libxml2's xmlParseInternalSubset from GNOME libxml2 version 2.9.11 to 2.11.0 allows a remote attacker to cause a denial-of-service via maliciously crafted XML input with improper entity resolution handling.
CVSSv3.1 9.8 (CRITICAL) · EPSS 21th percentile
CWECWE 416CWECWE 611VNDXmlsoftTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-06-22
2026-06-22 14:17Z
HIGH
CVE-2026-56425 — Misp-project Misp: The Azure Active Directory (AAD) authentication implementation contained multiple weaknesses in its OAuth 2.0
The Azure Active Directory (AAD) authentication implementation contained multiple weaknesses in its OAuth 2.0 authorization flow that could allow attackers to bypass important security guarantees provided by the protocol.
The application used the PHP session identifier (session_id()) as the OAuth state parameter. Because session identifiers are long-lived authentication credentials, exposing them in OAuth redirect URLs could leak valid session tokens through browser history
CVSSv3.1 8.8 (HIGH) · EPSS 22th percentile
CWECWE 384VNDAzureVNDMisp ProjectTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
728 × 90 / responsive · programmatic ad slot
2026-06-22
2026-06-22 14:17Z
HIGH
CVE-2026-54100 — A flaw was found in the Windows Machine Config Operator (WMCO) for Red Hat
A flaw was found in the Windows Machine Config Operator (WMCO) for Red Hat OpenShift Container Platform. WMCO establishes SSH connections to Windows worker nodes without verifying the remote server host key. An adjacent-network attacker who can intercept or redirect WMCO's SSH session can capture WICD and kubelet bootstrap credentials transferred during node configuration, enabling compromise of Windows node identities in the cluster.
CVSSv3.1 8.3 (HIGH)
CWECWE 295TYPVulnerability
8.3
CVSS v3.1
92
Edit Score
2026-06-22
2026-06-22 14:17Z
HIGH
CVE-2026-54099 — A flaw was found in the Windows Machine Config Operator (WMCO) for Red Hat
A flaw was found in the Windows Machine Config Operator (WMCO) for Red Hat OpenShift Container Platform. The WICD CSR auto-approver validates that a Certificate Signing Request contains the organization system:wicd-nodes but does not reject additional organization values such as system:masters. A compromised Windows worker node that holds WICD credentials can submit a CSR that is auto-approved and signed by the cluster, yielding a client certificate that grants cluster-admini
CVSSv3.1 8.8 (HIGH)
CWECWE 269TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-06-22
2026-06-22 14:16Z
CRIT
CVE-2026-28381 — Snowflake: The Snowflake datasource allows for GET/PUT commands, which can allow any user with access
The Snowflake datasource allows for GET/PUT commands, which can allow any user with access to run queries against the data source to read/write files between the local grafana server and the connected Snowflake host.
CVSSv3.1 9.6 (CRITICAL)
VNDSnowflakeTYPVulnerability
9.6
CVSS v3.1
98
Edit Score
2026-06-22
2026-06-22 14:16Z
CRIT
CVE-2026-10561 — IBM: Langflow OSS 1.0.0 through 1.9.3 has an vulnerability due to an improper isolation
IBM Langflow OSS 1.0.0 through 1.9.3 has an vulnerability due to an improper isolation of Python execution combined with an authentication bypass that allows an unauthenticated attacker to execute arbitrary code on the host system, resulting in complete compromise
CVSSv3.1 10.0 (CRITICAL)
CWECWE 94VNDIbmTYPVulnerability
10.0
CVSS v3.1
100
Edit Score
2026-06-22
2026-06-22 13:25Z
HIGH
ErrTraffic: A Growing ClickFix Malware Distribution Framework
Sekoia.io·sekoia.ioin the wild
Sekoia's TDR team published an in-depth analysis of ErrTraffic, a JavaScript-based ClickFix malware distribution framework sold as Malware-as-a-Service (MaaS) on cybercrime forums. The framework is injected into compromised WordPress sites to deliver social-engineering lures and distribute infostealers (Vidar, Stealc, Remus, Salat) and RATs, using blockchain-based dead-drop resolvers (EtherHiding on Polygon) to rotate C2 infrastructure. Two distinct operational clusters (Analytics and Beer) were identified, with the Beer cluster supporting multiple affiliate campaigns under a subscription model ranging $300–$4,500 monthly, demonstrating a mature and profitable cybercrime ecosystem.
Net::Statsite::Client versions through 1.1.0 for Perl allow metric injections.
Net::Statsite::Client is a client for the statsite protocol, which is a variant of statsd.
Newlines are not removed from metric names, allowing metric injections.
Values are not sanitised for newlines or other protocol control characters such as colons or pipes, allowing metric injections.
CVSSv3.1 9.1 (CRITICAL)
CWECWE 93CWECWE 150TYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2026-06-22
2026-06-22 10:16Z
HIGH
CVE-2023-45796 — A stored cross-site scripting vulnerability in the Runtime component of Pilz PASvisu before 1.14.1
A stored cross-site scripting vulnerability in the Runtime component of Pilz PASvisu before 1.14.1 and PMI v8xx up to and including 2.0.33992 allows a low-privileged remote unauthenticated attacker to manipulate process data with potential impact on integrity and/or availability.
CVSSv3.1 8.1 (HIGH)
CWECWE 79TYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-06-22
2026-06-22 10:00Z
HIGH
A VBScript campaign distributed through WhatsApp deploying RMM software
Kaspersky Securelist·securelist.com
Kaspersky discovered an active WhatsApp-based malware campaign distributing malicious VBScript attachments that deploy ManageEngine Endpoint Central RMM software. The attack chain uses compromised WhatsApp accounts to send financially-themed VBS files to contacts, which execute a three-stage infection process: initial downloader, UAC bypass attempt, and silent RMM installation. The campaign has affected users across 11+ countries with 80% of victims in Malaysia, and infrastructure overlaps suggest possible Chinese-speaking threat actors.
Apache Doris MCP Server contains a SQL injection vulnerability in a metadata query path. A user-controlled database name is directly interpolated into a SQL query, and the query is executed without passing the caller's authorization context. This may allow an authenticated attacker, or an anonymous attacker if authentication is disabled, to bypass SQL security validation and access metadata outside the intended database scope.
Affected users are recommended to upgrade to Dor
CVSSv3.1 8.1 (HIGH)
CWECWE 89VNDApacheTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-06-22
2026-06-22 06:16Z
HIGH
CVE-2026-8157 — Vitepos: The Vitepos WordPress plugin before 3.4.2 does not properly restrict the roles that can
The Vitepos WordPress plugin before 3.4.2 does not properly restrict the roles that can be assigned when creating new users via one of its REST API endpoints, allowing authenticated users with a custom Vitepos WordPress plugin before 3.4.2 role to escalate privileges to administrator.
CVSSv3.1 8.8 (HIGH)
CWECWE 269VNDViteposTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-06-21
2026-06-21 20:16Z
HIGH
CVE-2026-12806 — The manipulation of the argument selSSID leads to buffer overflow.
A vulnerability has been found in Edimax BR-6478AC V2 1.23. The impacted element is the function formWlSiteSurvey of the file /goform/formWlSiteSurvey of the component POST Request Handler. The manipulation of the argument selSSID leads to buffer overflow. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
CVSSv3.1 8.8 (HIGH)
CWECWE 120CWECWE 119TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-06-21
2026-06-21 19:38Z
HIGH
CloudSec — Master the art of cloud exploitation. A specialized resource for offensive security researchers and red teamers focused
GitHub · Azure / Entra tools·github.comGITHUB POC
CloudSec is a GitHub repository offering a curated toolkit for offensive cloud security research, containing weaponized exploits, attack simulations, and evasion techniques targeting Azure, Entra ID, AWS, and Microsoft 365. The repository organizes resources across offensive operations, vulnerability research, threat intelligence, anti-forensics, and custom tooling, with explicit focus on identity theft, token compromise, infrastructure exploitation, and SIEM/XDR evasion.
Mythic v3.4.0.60 released on GitHub. The release page contains minimal substantive information—only a version bump tag with no changelog, commit details, or feature/fix descriptions provided.
SWMythicTYPTool
15
Edit Score
2026-06-21
2026-06-21 14:16Z
CRIT
CVE-2026-56397 — SiYuan: Attackers can achieve remote code execution on any user browsing the Bazaar by embedding
SiYuan before v3.6.1 fails to sanitize package metadata and README content in the Bazaar marketplace, allowing malicious package authors to inject arbitrary HTML and JavaScript. Attackers can achieve remote code execution on any user browsing the Bazaar by embedding XSS payloads in package displayName, description, or README fields, exploiting Electron's nodeIntegration setting to execute OS commands.
CVSSv3.1 9.6 (CRITICAL)
CWECWE 79VNDSiyuanTYPVulnerability
9.6
CVSS v3.1
98
Edit Score
2026-06-21
2026-06-21 14:16Z
HIGH
CVE-2026-56396 — phpMyFAQ before 4.1.4 contains missing authorization vulnerabilities in editUser() and updateUserRights() endpoints that allow
phpMyFAQ before 4.1.4 contains missing authorization vulnerabilities in editUser() and updateUserRights() endpoints that allow authenticated administrators to escalate privileges. Non-SuperAdmin users with edit_user permission can set is_superadmin flag or grant arbitrary rights to escalate to SuperAdmin access.
CVSSv3.1 8.8 (HIGH)
CWECWE 862TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-06-21
2026-06-21 14:16Z
CRIT
CVE-2026-56395 — SiYuan: Attackers can achieve remote code execution on any user browsing the Bazaar by embedding
SiYuan before v3.6.1 fails to sanitize package metadata and README content in the Bazaar marketplace, allowing malicious package authors to inject arbitrary HTML and JavaScript. Attackers can achieve remote code execution on any user browsing the Bazaar by embedding XSS payloads in package displayName, description, or README fields, exploiting Electron's nodeIntegration setting to execute OS commands.
CVSSv3.1 9.6 (CRITICAL)
CWECWE 79VNDSiyuanTYPVulnerability
9.6
CVSS v3.1
98
Edit Score
2026-06-21
2026-06-21 14:16Z
CRIT
CVE-2026-56265 — Crawl4AI: before 0.8.7 contains an authentication bypass vulnerability due to a hardcoded default JWT
Crawl4AI before 0.8.7 contains an authentication bypass vulnerability due to a hardcoded default JWT signing key in the Docker API server. Attackers who know the default key can forge valid authentication tokens for any user, bypassing authentication and gaining full access to protected functionality.
CVSSv3.1 9.8 (CRITICAL)
CWECWE 798VNDCrawl4aiTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-06-21
2026-06-21 14:16Z
HIGH
CVE-2025-71378 — picklescan before 0.0.30 fails to detect cProfile.runctx function calls in pickle file reduce methods
picklescan before 0.0.30 fails to detect cProfile.runctx function calls in pickle file reduce methods, allowing attackers to execute arbitrary code. Malicious pickle files bypass picklescan detection and execute remote code when loaded via pickle.load().
CVSSv3.1 8.1 (HIGH)