2026-06-18
2026-06-18 16:16Z
HIGH

CVE-2026-44688 — Eclipse Theia: An attacker could craft a malicious repository with adversarial directory or file names that

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-44688

In Eclipse Theia versions prior to 1.71.0, the AI chat agent processed workspace file and directory names as part of its prompt context without distinguishing them from system instructions. An attacker could craft a malicious repository with adversarial directory or file names that, when analyzed by the AI agent, would cause the agent to follow attacker-controlled instructions (indirect prompt injection). Combined with other AI chat features available in untrusted workspaces, CVSSv3.1 8.8 (HIGH)

CWECWE 829VNDEclipseTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-06-18
2026-06-18 14:17Z
CRIT

CVE-2026-9158 — Eclipse 4diac_forte: In Eclipse 4diac FORTE versions 3.0.0 to 3.1.0, a specially crafted DELETE connection command

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-9158

In Eclipse 4diac FORTE versions 3.0.0 to 3.1.0, a specially crafted DELETE connection command to the management interface can lead to a dangling pointer. This allows subsequent commands to access freed memory (use-after-free). CVSSv3.1 9.8 (CRITICAL) · EPSS 5th percentile

CWECWE 416VNDEclipseTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-06-18
2026-06-18 14:17Z
HIGH

CVE-2026-8461 — An out-of-bounds write vulnerability in FFmpeg's libavcodec library, specifically in the MagicYUV decoder, allows

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-8461

An out-of-bounds write vulnerability in FFmpeg's libavcodec library, specifically in the MagicYUV decoder, allows denial-of-service and, in some cases, can be exploited for remote code execution. This vulnerability is associated with the file libavcodec/magicyuv.C. This issue affects FFmpeg before version 8.1.2. CVSSv3.1 8.8 (HIGH)

CWECWE 787TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-06-18
2026-06-18 14:17Z
CRIT

CVE-2026-8024 — A remote, unauthenticated attacker may exploit a deserialization of untrusted data vulnerability in ibaPDA

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-8024

A remote, unauthenticated attacker may exploit a deserialization of untrusted data vulnerability in ibaPDA or ibaDatCoordinator to gain full access to the affected systems. CVSSv3.1 9.8 (CRITICAL)

CWECWE 502TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-06-18
2026-06-18 14:17Z
HIGH

CVE-2026-56012 — Neutralization: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-56012

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in David Lingren Media LIbrary Assistant allows Blind SQL Injection. This issue affects Media LIbrary Assistant: from n/a through 3.35. CVSSv3.1 8.5 (HIGH)

CWECWE 89TYPVulnerability
8.5
CVSS v3.1
93
Edit Score
2026-06-18
2026-06-18 14:17Z
CRIT

CVE-2026-54419 — PIAF: claudiopizzillo PIAF-HMS (PBX-In-A-Flash Hotel Management System; no released versions, latest commit 389d2633441b65ced1c104212cd62be2bfca21e5) contains multiple

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-54419

claudiopizzillo PIAF-HMS (PBX-In-A-Flash Hotel Management System; no released versions, latest commit 389d2633441b65ced1c104212cd62be2bfca21e5) contains multiple unauthenticated SQL injection vulnerabilities. The application has no authentication mechanism and passes user-supplied HTTP parameters directly into deprecated mysql_query() calls via string concatenation, without sanitization, escaping, or parameterization. Affected sinks include rooms.php (DELETE FROM Rooms WHERE CVSSv3.1 9.8 (CRITICAL)

CWECWE 89VNDPiafTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-06-18
2026-06-18 14:17Z
HIGH

CVE-2026-42488 — This causes a mismatch between the loaded page-tables and the mapcache metadata which can

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-42488

Some shadow paging errors paths will switch the page-tables without updating the currently running vCPU reference. This causes a mismatch between the loaded page-tables and the mapcache metadata which can lead to corruption of the mapcache. CVSSv3.1 8.1 (HIGH)

CWECWE 119TYPVulnerability
8.1
CVSS v3.1
91
Edit Score
728 × 90 / responsive · programmatic ad slot
2026-06-18
2026-06-18 14:17Z
HIGH

CVE-2026-11719 — Google Mcp_toolbox_for_databases: An authenticated authorization bypass vulnerability exists in MCP Toolbox for Databases due to missing

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-11719

An authenticated authorization bypass vulnerability exists in MCP Toolbox for Databases due to missing scope enforcement across older protocol handlers. While the 2025-11-25 protocol version handler correctly enforces per-tool restrictions defined by scopesRequired, older supported protocol versions (2025-06-18, 2025-03-26, and 2024-11-05) omit this check. An authenticated client with low-privilege tokens (e.g., read) can bypass the intended per-tool scope restrictions and e CVSSv3.1 8.1 (HIGH) · EPSS 5th percentile

CWECWE 862VNDGoogleTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-06-18
2026-06-18 14:17Z
CRIT

CVE-2026-11718 — Google Mcp_toolbox_for_databases: An authentication bypass vulnerability exists in the generic opaque token validation path (validateOpaqueToken) of

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-11718

An authentication bypass vulnerability exists in the generic opaque token validation path (validateOpaqueToken) of googleapis/mcp-toolbox. When the toolbox validates an opaque token via an OAuth 2.0 introspection endpoint (RFC 7662), it decodes the response into an introspectResp struct. However, the subsequent claim-checking logic (validateClaims) evaluates the issuer condition as if a.issuer != "" && iss != "". If the external OAuth provider's introspection response omits CVSSv3.1 9.1 (CRITICAL) · EPSS 11th percentile

CWECWE 287VNDGoogleTYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2026-06-18
2026-06-18 14:17Z
CRIT

CVE-2026-11717 — Google Mcp_toolbox_for_databases: An authentication bypass vulnerability exists in the generic opaque token validation path (validateOpaqueToken) of

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-11717

An authentication bypass vulnerability exists in the generic opaque token validation path (validateOpaqueToken) of googleapis/mcp-toolbox. When verifying an unparsed opaque token via an OAuth 2.0 introspection endpoint (RFC 7662), the toolbox decodes the response into an introspectResp struct where the Active field is declared as a pointer to a boolean (*bool). The code only explicitly rejects a token if the response contains a populated active field set to false (if introsp CVSSv3.1 9.1 (CRITICAL) · EPSS 10th percentile

CWECWE 287VNDGoogleTYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2026-06-18
2026-06-18 13:00Z
CRIT

Shynet | VERSION 0.13.1

Bishop Fox Labs·bishopfox.comCVE-2026-35508CVE-2026-35507

Bishop Fox disclosed two vulnerabilities in Shynet 0.13.1: an unauthenticated stored XSS in analytics tracking fields (location/referrer) that allows injection of malicious JavaScript into all tracked applications, and a password reset poisoning vulnerability via Host header spoofing that enables account takeover. Both vulnerabilities were patched in version 0.14.0 released March 15, 2026.

SRFApplicationTACTA0001TACTA0006SRFWebSWShynetVNDMilesmccTYPVulnerabilitySTGInitial Access
78
Edit Score
2026-06-18
2026-06-18 08:16Z
HIGH

CVE-2026-55744 — Cotonti: 1.0.0 (master branch, commit f43f1fc3) is vulnerable to Cross-Site Request Forgery in the

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-55744

Cotonti 1.0.0 (master branch, commit f43f1fc3) is vulnerable to Cross-Site Request Forgery in the Personal File Storage (PFS) module. In modules/pfs/inc/pfs.main.php, the file upload action ('a=upload') processes uploaded files without calling cot_check_xg() to validate the anti-CSRF token, even though sibling actions such as 'delete' (line 272) do. A remote attacker who lures an authenticated user into visiting a malicious page can force the browser to submit a forged multip CVSSv3.1 8.1 (HIGH)

CWECWE 352VNDCotontiTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-06-18
2026-06-18 08:16Z
CRIT

CVE-2026-55742 — Cotonti: 1.0.0 (master branch, commit f43f1fc3) is vulnerable to Cross-Site Request Forgery in the

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-55742

Cotonti 1.0.0 (master branch, commit f43f1fc3) is vulnerable to Cross-Site Request Forgery in the administration rights handler. In system/admin/admin.rights.php, the rights update action ('a=update') modifies group access rights (including via cot_auth_add_group) without calling cot_check_xg() to validate the anti-CSRF token. A remote attacker who lures an authenticated administrator into visiting a malicious page can force the browser to submit a forged request that grants CVSSv3.1 9.6 (CRITICAL)

CWECWE 352VNDCotontiTYPVulnerability
9.6
CVSS v3.1
98
Edit Score
2026-06-18
2026-06-18 08:16Z
HIGH

CVE-2026-55741 — Cotonti: 1.0.0 (master branch, commit f43f1fc3) is vulnerable to Cross-Site Request Forgery in the

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-55741

Cotonti 1.0.0 (master branch, commit f43f1fc3) is vulnerable to Cross-Site Request Forgery in the administration configuration handler. In system/admin/admin.config.php, the configuration update action ('a=update') processes POST data via cot_config_update_options() without calling cot_check_xg() to validate the anti-CSRF token (the 'x' parameter), unlike other admin handlers (e.g. admin.structure.php, admin.cache.php). A remote attacker who lures an authenticated administrat CVSSv3.1 8.8 (HIGH)

CWECWE 352VNDCotontiTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-06-18
2026-06-18 06:16Z
HIGH

CVE-2026-9860 — Offload: The Offload, AI & Optimize with Cloudflare Images plugin for WordPress is vulnerable to

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-9860

The Offload, AI & Optimize with Cloudflare Images plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 1.10.2 via the 'account-id' parameter parameter. This is due to insufficient privilege enforcement on the cf_images_do_setup AJAX handler, which requires only the upload_files capability (Author+) rather than manage_options before writing to wp-config.php, combined with the absence of single-quote escaping — sanitize_text_field() CVSSv3.1 8.8 (HIGH)

CWECWE 434VNDOffloadTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-06-18
2026-06-18 06:16Z
CRIT

CVE-2026-55740 — Nur: Nur-Alam39 bus-ticket (no released versions; latest commit 459cabdbeb99c00225b26e46e3c2c30ae1de7bad) contains an unauthenticated SQL injection vulnerability

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-55740

Nur-Alam39 bus-ticket (no released versions; latest commit 459cabdbeb99c00225b26e46e3c2c30ae1de7bad) contains an unauthenticated SQL injection vulnerability in bus_info.php. The busid parameter received via HTTP POST is concatenated directly into a MySQL query (select * from bus_info where id=$busid) without sanitization, escaping, or parameterization, and in a numeric (unquoted) context. A remote, unauthenticated attacker can inject arbitrary SQL — for example a UNION-based CVSSv3.1 9.8 (CRITICAL)

CWECWE 89VNDNurTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-06-18
2026-06-18 04:16Z
HIGH

CVE-2026-12407 — E2Pdf: The E2Pdf – Export Pdf Tool for WordPress plugin for WordPress is vulnerable to

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-12407

The E2Pdf – Export Pdf Tool for WordPress plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 1.32.26. This is due to the screen_action() function lacking a dedicated capability check and nonce verification — when invoked via the ?action=screen routing path the controller's index_action() nonce gate is bypassed entirely — while reading an attacker-controlled option name and value from $_POST['wp_screen_options'] and passing them direc CVSSv3.1 8.8 (HIGH)

CWECWE 862VNDE2pdfTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-06-18
2026-06-18 01:18Z
CRIT

CVE-2026-12569 — Ptc Flexplm: A critical remote code execution (RCE) vulnerability has been reported in PTC Windchill PDMlink

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-12569in the wild

A critical remote code execution (RCE) vulnerability has been reported in PTC Windchill PDMlink and PTC FlexPLM. The vulnerability may be exploited through the deserialization of untrusted data.  * This advisory also applies to all CPS versions * The identified vulnerability also impacts Windchill and FlexPLM releases prior to 11.0 M030 CVSSv3.1 9.8 (CRITICAL) · EPSS 39th percentile

CWECWE 502CWECWE 20VNDRceVNDPtcTYPVulnerabilitySTAitw exploited
9.8
CVSS v3.1
99
Edit Score
2026-06-18
2026-06-18 00:24Z
HIGH

The Smash-and-Grab Era

Bishop Fox Labs·bishopfox.com

Bishop Fox's strategic analysis argues that cyberattacks have evolved through three eras: low-and-slow espionage (pre-2016), loud ransomware extortion (2016-2020), and now 'smash-and-grab' operations enabled by LLMs. LLM-driven attackers can parallelize reconnaissance and movement across multiple paths simultaneously, removing the traditional bottlenecks of human comprehension and sequential movement, leaving only inference speed as a constraint and overwhelming defender detection-and-response models.

TACTA0001SRFNetworkTACTA0007TYPResearchSTGDiscoverySTGInitial AccessSTGLat MovementTECT1087
78
Edit Score
2026-06-18
2026-06-18 00:16Z
CRIT

CVE-2026-48768 — TypeBot: As a result, any anonymous visitor to a published bot with a file input

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-48768

TypeBot is a chatbot builder tool. In versions 3.16.1 and earlier, POST /api/blocks/file-input/v3/generate-upload-url is unauthenticated and uses unsanitized fileName input to construct public/ S3 object keys, while issuing presigned PUT URLs that do not bind Content-Type. As a result, any anonymous visitor to a published bot with a file input can upload attacker-controlled HTML, SVG, or JS to attacker-chosen subpaths, including other tenants’ publicly served result paths, en CVSSv3.1 9.3 (CRITICAL)

CWECWE 22CWECWE 79VNDTypebotTYPVulnerability
9.3
CVSS v3.1
97
Edit Score
2026-06-18
2026-06-18 00:16Z
HIGH

CVE-2026-48764 — TypeBot: In versions prior to 3.17.2, SSRF validation is implemented by resolving a hostname once

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-48764

TypeBot is a chatbot builder tool. In versions prior to 3.17.2, SSRF validation is implemented by resolving a hostname once and checking whether the resolved IP belongs to a forbidden range allowing for DNS rebinding bypass. The root cause is a time-of-check to time-of-use gap in the SSRF guard. The validator resolves the hostname and approves it, but the later request path performs a fresh resolution and connects to whatever IP the hostname maps to at that moment. The actual CVSSv3.1 8.2 (HIGH)

CWECWE 918VNDTypebotTYPVulnerability
8.2
CVSS v3.1
91
Edit Score
2026-06-18
2026-06-18 00:00Z
CRIT

PeopleSoft PeopleTools Pre-Authentication RCE: A PSIGW SSRF Chain That Executes Inside the JVM

Trend Micro Research·trendmicro.comCVE-2026-35273in the wild

Oracle PeopleSoft PeopleTools 8.61 and 8.62 contain a pre-authentication RCE chain (CVE-2026-35273, CVSS 9.8) that exploits an SSRF in the PSIGW gateway to reach the internal PSEMHUB servlet, plants malicious XML via XMLDecoder deserialization, and executes code in-process on web-tier restart. The vulnerability was exploited in the wild by SHADOW-AETHER-015 (ShinyHunters) from May 27–June 9, 2026, targeting over 100 organizations before Oracle's June 10 out-of-band patch.

SRFApplicationTACTA0005TACTA0001SRFWebTACTA0003SWPeoplesoftSWWeblogicVNDOracle
92
Edit Score
2026-06-17
2026-06-17 22:16Z
HIGH

CVE-2026-50194 — Steeltoe: When Steeltoe management endpoints versions 3.2.2 through 3.3.0 and 4.1.0 are configured to listen

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-50194

Steeltoe is an open source project that provides a collection of libraries that helps users build cloud-native applications. When Steeltoe management endpoints versions 3.2.2 through 3.3.0 and 4.1.0 are configured to listen on an alternate port (`Management:Endpoints:Port` is configured), the middleware responsible for restricting access to the endpoints uses the `Host` HTTP header rather than the actual network socket port. Versions 3.4.0 and 4.2.0 patch the issue. If an imm CVSSv3.1 8.2 (HIGH)

CWECWE 288CWECWE 639VNDSteeltoeTYPVulnerability
8.2
CVSS v3.1
91
Edit Score
2026-06-17
2026-06-17 22:00Z
HIGH

Black Box Probing: a Security Analysis of Xiaomi's MJA1 Secure Chip

Quarkslab·blog.quarkslab.com

Quarkslab published a comprehensive black-box security analysis of Xiaomi's MJA1 secure chip used in their cameras. Researchers reverse-engineered the proprietary chip's I2C protocol, dumped firmware from two device variants, identified 18 documented commands and 2 undocumented commands (including an Update command for writing to data zones), and recovered the CRC-16/X-25 implementation protecting frame integrity. The analysis reveals the chip enforces a trust boundary by keeping private keys isolated while exposing public certificates and cryptographic operations.

SRFFirmwareSRFHardwareSWMiio ClientVNDXiaomiTYPResearchSTGDiscoverySTGReconTECT1040
76
Edit Score
2026-06-17
2026-06-17 20:17Z
HIGH

CVE-2026-55202 — Tinyproxy: through 1.11.3, fixed in commit 09312a1, fails to properly validate the Host header

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-55202

Tinyproxy through 1.11.3, fixed in commit 09312a1, fails to properly validate the Host header during stathost detection, allowing unauthenticated attackers to access the stats page by injecting a matching Host header or bypass detection via port manipulation. Remote attackers can trigger unauthorized access to internal proxy statistics or misroute requests as transparent proxy connections to circumvent access controls. CVSSv3.1 8.2 (HIGH)

CWECWE 290VNDTinyproxyTYPVulnerability
8.2
CVSS v3.1
91
Edit Score