2026-06-16
2026-06-16 13:16Z
CRIT

CVE-2026-12304 — Same: Same-origin policy bypass in the Networking: Cookies component.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-12304

Same-origin policy bypass in the Networking: Cookies component. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Thunderbird 152, and Thunderbird 140.12. CVSSv3.1 9.1 (CRITICAL)

CWECWE 346TYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2026-06-16
2026-06-16 13:16Z
CRIT

CVE-2026-12297 — Mozilla Firefox: Sandbox escape due to incorrect boundary conditions in the Networking component.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-12297

Sandbox escape due to incorrect boundary conditions in the Networking component. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Firefox ESR 115.37, Thunderbird 152, and Thunderbird 140.12. CVSSv3.1 9.6 (CRITICAL) · EPSS 5th percentile

CWECWE 119VNDMozillaTYPVulnerability
9.6
CVSS v3.1
98
Edit Score
2026-06-16
2026-06-16 13:16Z
CRIT

CVE-2026-12296 — Mozilla Firefox: Sandbox escape in the Security: Process Sandboxing component.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-12296

Sandbox escape in the Security: Process Sandboxing component. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Thunderbird 152, and Thunderbird 140.12. CVSSv3.1 9.6 (CRITICAL) · EPSS 5th percentile

CWECWE 693VNDMozillaTYPVulnerability
9.6
CVSS v3.1
98
Edit Score
2026-06-16
2026-06-16 13:16Z
CRIT

CVE-2026-12295 — Mozilla Firefox: Sandbox escape in the DOM: Navigation component.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-12295

Sandbox escape in the DOM: Navigation component. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Firefox ESR 115.37, Thunderbird 152, and Thunderbird 140.12. CVSSv3.1 9.6 (CRITICAL) · EPSS 5th percentile

CWECWE 693VNDMozillaTYPVulnerability
9.6
CVSS v3.1
98
Edit Score
2026-06-16
2026-06-16 13:16Z
CRIT

CVE-2026-12294 — Mozilla Firefox: Sandbox escape in the DOM: Workers component.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-12294

Sandbox escape in the DOM: Workers component. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Firefox ESR 115.37, Thunderbird 152, and Thunderbird 140.12. CVSSv3.1 9.6 (CRITICAL) · EPSS 5th percentile

CWECWE 693VNDMozillaTYPVulnerability
9.6
CVSS v3.1
98
Edit Score
2026-06-16
2026-06-16 13:16Z
CRIT

CVE-2026-12293 — Mozilla Firefox: Use-after-free in the Graphics: WebGPU component.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-12293

Use-after-free in the Graphics: WebGPU component. This vulnerability was fixed in Firefox 152 and Thunderbird 152. CVSSv3.1 9.8 (CRITICAL)

CWECWE 416VNDMozillaTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-06-16
2026-06-16 13:16Z
HIGH

CVE-2026-12292 — Mozilla Firefox: Incorrect boundary conditions in the Web Audio component.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-12292

Incorrect boundary conditions in the Web Audio component. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Thunderbird 152, and Thunderbird 140.12. CVSSv3.1 8.1 (HIGH) · EPSS 5th percentile

CWECWE 119VNDMozillaTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
728 × 90 / responsive · programmatic ad slot
2026-06-16
2026-06-16 13:16Z
HIGH

CVE-2026-12291 — Mozilla Firefox: Use-after-free in the Networking: HTTP component.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-12291

Use-after-free in the Networking: HTTP component. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Firefox ESR 115.37, Thunderbird 152, and Thunderbird 140.12. CVSSv3.1 8.8 (HIGH) · EPSS 5th percentile

CWECWE 416VNDMozillaTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-06-16
2026-06-16 13:16Z
HIGH

CVE-2026-12290 — Memory: safety bug fixed in Thunderbird 152.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-12290

Memory safety bug fixed in Thunderbird 152. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Firefox ESR 115.37, Thunderbird 152, and Thunderbird 140.12. CVSSv3.1 8.1 (HIGH)

CWECWE 119TYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-06-16
2026-06-16 13:16Z
HIGH

CVE-2026-12289 — Privilege: escalation in the Graphics: WebRender component.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-12289

Privilege escalation in the Graphics: WebRender component. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, and Firefox ESR 115.37. CVSSv3.1 8.8 (HIGH)

CWECWE 269TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-06-16
2026-06-16 13:00Z
HIGH

A Crash, Not a Shell: SolarWinds Serve-U CVE-2026-28318

Bishop Fox Labs·bishopfox.comCVE-2026-28318

Bishop Fox analyzed CVE-2026-28318, an unauthenticated denial-of-service in SolarWinds Serv-U 15.5.4 and earlier triggered by a POST request with Content-Encoding: deflate header. The vulnerability stems from a buffer-management bug in the decompressor that causes an invalid free() and process abort. Despite the underlying heap corruption, the researchers exhaustively tested three potential RCE paths and confirmed the impact is strictly availability denial—no code execution is viable.

SRFApplicationSRFNetworkTACTA0040SWServ UVNDSolarwindsTYPResearchTYPVulnerabilitySTGImpact
78
Edit Score
2026-06-16
2026-06-16 13:00Z
HIGH

A Crash, Not a Shell: SolarWinds Serv-U CVE-2026-28318

Bishop Fox Labs·bishopfox.comCVE-2026-28318

Bishop Fox analyzed CVE-2026-28318, an unauthenticated denial-of-service in SolarWinds Serv-U 15.5.4 and earlier triggered by a POST request with Content-Encoding: deflate header. The vulnerability stems from a buffer-management bug in the decompressor that causes an invalid free() and process abort. Despite the underlying heap corruption, Bishop Fox's reverse engineering and exploitation attempts across three RCE vectors conclusively determined the impact is denial-of-service only; the vendor's CVSS 7.5 rating is accurate.

SRFApplicationTACTA0001SRFNetworkSWServ UVNDSolarwindsTYPResearchTYPVulnerabilitySTGInitial Access
78
Edit Score
2026-06-16
2026-06-16 12:16Z
CRIT

CVE-2026-40750 — Upload: Unrestricted Upload of File with Dangerous Type vulnerability in themagnifico52 Kids Online Store allows

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-40750

Unrestricted Upload of File with Dangerous Type vulnerability in themagnifico52 Kids Online Store allows Upload a Web Shell to a Web Server. This issue affects Kids Online Store: from n/a through 0.8.9. CVSSv3.1 9.9 (CRITICAL)

CWECWE 434TYPVulnerability
9.9
CVSS v3.1
100
Edit Score
2026-06-16
2026-06-16 10:16Z
HIGH

CVE-2026-8442 — Review: The WP Review Slider Pro plugin for WordPress is vulnerable to Arbitrary File Deletion

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-8442

The WP Review Slider Pro plugin for WordPress is vulnerable to Arbitrary File Deletion in versions up to and including 12.6.8. This is due to missing authorization checks on the wpfb_hide_review and wprp_save_review_admin AJAX handlers combined with insufficient path validation in the wpfb_hidereview_ajax() function, which uses strpos() to check that a stored media URL starts with the expected prefix but fails to sanitize path traversal sequences in the remaining relative pat CVSSv3.1 8.1 (HIGH)

CWECWE 22VNDReviewTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-06-16
2026-06-16 10:16Z
HIGH

CVE-2026-5416 — Due to the improper neutralization of special elements used in a name parameter a

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-5416

Due to the improper neutralization of special elements used in a name parameter a low privileged remote attacker can exploit a command injection vulnerability in the Managed Ethernet Switch, resulting in full system compromise. CVSSv3.1 8.8 (HIGH)

CWECWE 78TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-06-16
2026-06-16 10:16Z
CRIT

CVE-2026-52715 — SQL: Unauthenticated SQL Injection in GEO my WordPress <= 4.5.5 versions.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-52715

Unauthenticated SQL Injection in GEO my WordPress <= 4.5.5 versions. CVSSv3.1 9.3 (CRITICAL)

CWECWE 89TYPVulnerability
9.3
CVSS v3.1
97
Edit Score
2026-06-16
2026-06-16 10:16Z
CRIT

CVE-2026-49774 — Control: Improper Control of Generation of Code ('Code Injection') vulnerability in Filipe Nasc RD Station

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-49774

Improper Control of Generation of Code ('Code Injection') vulnerability in Filipe Nasc RD Station allows Remote Code Inclusion. This issue affects RD Station: from n/a through 5.6.0. CVSSv3.1 9.9 (CRITICAL)

CWECWE 94TYPVulnerability
9.9
CVSS v3.1
100
Edit Score
2026-06-16
2026-06-16 10:16Z
CRIT

CVE-2026-49772 — Neutralization: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-49772

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Liquid Web / StellarWP The Events Calendar allows Blind SQL Injection. This issue affects The Events Calendar: from 6.15.12 through 6.16.2. CVSSv3.1 9.3 (CRITICAL)

CWECWE 89TYPVulnerability
9.3
CVSS v3.1
97
Edit Score
2026-06-16
2026-06-16 10:16Z
HIGH

CVE-2026-39581 — Subscriber: SQL Injection in WP Sessions Time Monitoring Full Automatic <= 1.1.4 versions.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-39581

Subscriber SQL Injection in WP Sessions Time Monitoring Full Automatic <= 1.1.4 versions. CVSSv3.1 8.5 (HIGH)

CWECWE 89VNDSubscriberTYPVulnerability
8.5
CVSS v3.1
93
Edit Score
2026-06-16
2026-06-16 10:16Z
CRIT

CVE-2026-39574 — SQL: Unauthenticated SQL Injection in InPost Gallery <= 2.1.4.6 versions.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-39574

Unauthenticated SQL Injection in InPost Gallery <= 2.1.4.6 versions. CVSSv3.1 9.3 (CRITICAL)

CWECWE 89TYPVulnerability
9.3
CVSS v3.1
97
Edit Score
2026-06-16
2026-06-16 09:00Z
HIGH

Dozens of malicious wallpapers found on Steam Workshop: gamers’ accounts at risk

Kaspersky Securelist·securelist.comin the wild

Kaspersky researchers discovered dozens of malicious wallpapers distributed via Steam Workshop's Wallpaper Engine application, targeting gamers primarily in China (89% of attempts) and Russia. The malware exploits the application wallpaper feature—which executes arbitrary code—to deploy backdoors (DarkKomet), infostealers (Lumma, Vidar), crypto miners, and ransomware, with thousands of downloads per malicious package. Valve removed identified wallpapers post-disclosure, but the researchers note new variants continue appearing regularly.

SRFApplicationTACTA0001TACTA0002TACTA0006TACTA0009SRFSupply ChainOSWindowsSWSteam
72
Edit Score
2026-06-16
2026-06-16 08:16Z
HIGH

CVE-2026-8444 — Review: The WP Review Slider Pro plugin for WordPress is vulnerable to SQL Injection via

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-8444

The WP Review Slider Pro plugin for WordPress is vulnerable to SQL Injection via the 'curselrevs[]' parameter of the wpfb_find_reviews AJAX action in versions up to, and including, 12.6.8. This is due to the handler reading $_POST['curselrevs'] raw with no sanitization or type casting, then concatenating each array element directly into a `WHERE id IN ( ... )` clause without quoting and executing via $wpdb->get_results() without $wpdb->prepare(). This makes it possible for au CVSSv3.1 8.8 (HIGH)

CWECWE 89VNDReviewTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-06-16
2026-06-16 06:16Z
HIGH

CVE-2026-8443 — Review: The WP Review Slider Pro plugin for WordPress is vulnerable to SQL Injection via

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-8443

The WP Review Slider Pro plugin for WordPress is vulnerable to SQL Injection via the 'stypes' and 'slocations' parameters of the wppro_get_overall_chart_data AJAX action in versions up to, and including, 12.6.8. This is due to the use of stripslashes() on user-supplied JSON strings prior to json_decode(), which removes the escaping applied by WordPress's wp_magic_quotes; the resulting decoded array values are then concatenated directly into SQL WHERE clauses without parameter CVSSv3.1 8.8 (HIGH)

CWECWE 89VNDReviewTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-06-16
2026-06-16 06:16Z
HIGH

CVE-2026-6933 — Premmerce: The Premmerce Dev Tools plugin for WordPress is vulnerable to Remote Code Execution via

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-6933

The Premmerce Dev Tools plugin for WordPress is vulnerable to Remote Code Execution via missing authorization in versions up to and including 2.0. This is due to the 'generatePluginHandler' function lacking any authorization check before processing user-supplied POST data, combined with the 'createFromStub' function performing unsanitized string substitution of the 'premmerce_plugin_namespace' parameter directly into PHP stub files written to the wp-content/plugins/ directory CVSSv3.1 8.8 (HIGH)

CWECWE 434VNDPremmerceTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-06-16
2026-06-16 05:00Z
HIGH

Unveiling ErrTraffic: inside a growing ClickFix malware distribution framework

Sekoia.io·sekoia.ioin the wild

Sekoia TDR published a comprehensive analysis of ErrTraffic, a JavaScript-based ClickFix malware distribution framework operating as a Malware-as-a-Service (MaaS) on Exploit.IN since December 2025. The framework uses EtherHiding (blockchain-based Dead Drop Resolver) to conceal C2 infrastructure, integrates a Traffic Distribution System (TDS), and has evolved through multiple versions with pricing ranging from $300–$4,500/month. The report documents two distinct operational clusters ("Analytics" and "Beer"), identifies 11 alleged affiliates, and provides forensic analysis of WordPress compromise chains involving credential stuffing, harvested credentials, and persistent PHP backdoors.

SRFApplicationTACTA0004TACTA0005TACTA0001TACTA0006SRFWebTACTA0003TYPResearch
78
Edit Score