2026-06-16
2026-06-16 05:00Z
HIGH

Unveiling ErrTraffic: inside a growing ClickFix malware distribution framework

Sekoia.io·sekoia.ioin the wild

Sekoia TDR published a comprehensive analysis of ErrTraffic, a JavaScript-based ClickFix malware distribution framework operating as a Malware-as-a-Service (MaaS) on Exploit.IN since December 2025. The framework uses EtherHiding (blockchain-based Dead Drop Resolver) to conceal C2 infrastructure, integrates a Traffic Distribution System (TDS), and has evolved through multiple versions with pricing ranging from $300–$4,500/month. The report documents two distinct operational clusters ("Analytics" and "Beer"), identifies 11 alleged affiliates, and provides forensic analysis of WordPress compromise chains involving credential stuffing, harvested credentials, and persistent PHP backdoors.

SRFApplicationTACTA0004TACTA0005TACTA0001TACTA0006SRFWebTACTA0003TYPResearch
78
Edit Score
2026-06-16
2026-06-16 03:16Z
HIGH

CVE-2026-7273 — A stack-based buffer overflow vulnerability in the CGI program of Zyxel GS1900-48HPv2 firmware versions

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-7273

A stack-based buffer overflow vulnerability in the CGI program of Zyxel GS1900-48HPv2 firmware versions through 2.90(ABTQ.1)C0 could allow a LAN-based, unauthenticated attacker to exploit the flaw and potentially execute OS commands via a crafted HTTP request. CVSSv3.1 8.8 (HIGH)

CWECWE 121TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-06-16
2026-06-16 01:16Z
HIGH

CVE-2026-12161 — SSH: Improper input validation in the SSH Elevate Shell feature in Devolutions Remote Desktop Manager

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-12161

Improper input validation in the SSH Elevate Shell feature in Devolutions Remote Desktop Manager 2026.2.7 allows an authenticated user with permission to create or modify a shared SSH entry to execute arbitrary commands on a remote SSH host using stored elevation credentials via a crafted alternate username and user interaction with the Elevate Shell action. CVSSv3.1 8.8 (HIGH)

CWECWE 78VNDSshTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-06-15
2026-06-15 23:16Z
CRIT

CVE-2026-12205 — Crypt: Crypt::DSA versions before 1.21 for Perl reused the nonce across signatures, leading to private-key

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-12205

Crypt::DSA versions before 1.21 for Perl reused the nonce across signatures, leading to private-key recovery. Crypt::DSA::sign caches the per-signature nonce material in the Key object without ever clearing it. The first sign() on a Key object picks a nonce, and every later sign() on that same object reuses it, producing an identical "r". Keys used to sign more than once with an affected version should be considered compromised. CVSSv3.1 9.1 (CRITICAL)

CWECWE 323VNDCryptTYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2026-06-15
2026-06-15 22:16Z
CRIT

CVE-2026-48714 — i18next-http-middleware is a middleware to be used with Node.js web frameworks like express or

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-48714

i18next-http-middleware is a middleware to be used with Node.js web frameworks like express or Fastify and also for Deno. In versions prior to 3.9.7, the missingKeyHandler blocked the literal request-body keys __proto__, constructor, and prototype (added in 3.9.3, see GHSA-5fgg-jcpf-8jjw), but did not reject dotted variants such as "__proto__.polluted". Downstream backends that split the missing-key string on a configured keySeparator (notably i18next-fs-backend ≤ 2.6.5) hand CVSSv3.1 9.1 (CRITICAL)

CWECWE 1321TYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2026-06-15
2026-06-15 22:16Z
CRIT

CVE-2026-48713 — Versions prior to 2.6.6 are vulnerable to prototype pollution via crafted missing-key strings when

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-48713

Versions prior to 2.6.6 are vulnerable to prototype pollution via crafted missing-key strings when used to persist missing translation keys (e.g. via i18next-http-middleware's missingKeyHandler exposed to untrusted input). Backend.writeFile() splits each queued missing-key string on the configured keySeparator (default .) before calling the internal setPath() walker. The walker (getLastOfPath in lib/utils.js) did not guard against unsafe segments, so a key like "__proto__.pol CVSSv3.1 9.1 (CRITICAL)

CWECWE 1321TYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2026-06-15
2026-06-15 22:16Z
HIGH

CVE-2026-48017 — DbGate: is cross-platform database manager.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-48017

DbGate is cross-platform database manager. In versions 7.1.8 and prior, the POST /runners/load-reader endpoint in DbGate accepts a functionName parameter that is directly interpolated into a JavaScript code template without any sanitization or validation. An authenticated user (with basic access, no special permissions required) can inject arbitrary JavaScript code that executes on the server with full process privileges, bypassing the require=null sandbox restriction. An aut CVSSv3.1 8.8 (HIGH)

CWECWE 94VNDDbgateTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
728 × 90 / responsive · programmatic ad slot
2026-06-15
2026-06-15 22:16Z
CRIT

CVE-2026-12087 — Socket: versions before 2.041 for Perl have an out-of-bounds heap read.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-12087

Socket versions before 2.041 for Perl have an out-of-bounds heap read. In Socket.xs, pack_ip_mreq_source() checks the length of its source argument before the argument is read, so the check tests the byte length carried over from the preceding multiaddr argument instead. Both addresses occupy a 4-byte field, so a valid multiaddr lets a source of any length pass the check, and the source is then copied into the 4-byte imr_sourceaddr field with a fixed-size copy. A source shor CVSSv3.1 9.1 (CRITICAL)

CWECWE 125CWECWE 805VNDSocketTYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2026-06-15
2026-06-15 22:16Z
CRIT

CVE-2026-11832 — Dancer2: Dancer2::Plugin::Auth::OAuth versions before 0.22 for Perl default to a predictable nonce.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-11832

Dancer2::Plugin::Auth::OAuth versions before 0.22 for Perl default to a predictable nonce. The default nonce was generated using an MD5 hash of the epoch time, which is predictable. CVSSv3.1 9.1 (CRITICAL)

CWECWE 338VNDDancer2TYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2026-06-15
2026-06-15 21:17Z
CRIT

CVE-2026-9691 — PHP: Unauthenticated PHP Object Injection in Integration for ActiveCampaign and Contact Form 7, WPForms, Elementor

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-9691

Unauthenticated PHP Object Injection in Integration for ActiveCampaign and Contact Form 7, WPForms, Elementor, Ninja Forms <= 1.1.1 versions. CVSSv3.1 9.8 (CRITICAL)

CWECWE 502TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-06-15
2026-06-15 21:17Z
CRIT

CVE-2026-52703 — Path: Unauthenticated Path Traversal in FastDup <= 2.7.2 versions.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-52703

Unauthenticated Path Traversal in FastDup <= 2.7.2 versions. CVSSv3.1 9.6 (CRITICAL)

CWECWE 35TYPVulnerability
9.6
CVSS v3.1
98
Edit Score
2026-06-15
2026-06-15 21:17Z
HIGH

CVE-2026-52700 — Subscriber: SQL Injection in WCMultiShipping <= 3.0.2 versions.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-52700

Subscriber SQL Injection in WCMultiShipping <= 3.0.2 versions. CVSSv3.1 8.5 (HIGH)

CWECWE 89VNDSubscriberTYPVulnerability
8.5
CVSS v3.1
93
Edit Score
2026-06-15
2026-06-15 21:17Z
HIGH

CVE-2026-52697 — Subscriber: SQL Injection in Taskbuilder <= 5.0.7 versions.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-52697

Subscriber SQL Injection in Taskbuilder <= 5.0.7 versions. CVSSv3.1 8.5 (HIGH)

CWECWE 89VNDSubscriberTYPVulnerability
8.5
CVSS v3.1
93
Edit Score
2026-06-15
2026-06-15 21:17Z
CRIT

CVE-2026-52693 — SQL: Unauthenticated SQL Injection in eCommerce Product Catalog <= 3.5.5 versions.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-52693

Unauthenticated SQL Injection in eCommerce Product Catalog <= 3.5.5 versions. CVSSv3.1 9.3 (CRITICAL)

CWECWE 89TYPVulnerability
9.3
CVSS v3.1
97
Edit Score
2026-06-15
2026-06-15 21:17Z
CRIT

CVE-2026-49781 — PHP: Unauthenticated PHP Object Injection in OttoKit <= 1.1.27 versions.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-49781

Unauthenticated PHP Object Injection in OttoKit <= 1.1.27 versions. CVSSv3.1 9.8 (CRITICAL)

CWECWE 502TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-06-15
2026-06-15 21:17Z
HIGH

CVE-2026-49780 — Customer: Privilege Escalation in Dokan <= 5.0.2 versions.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-49780

Customer Privilege Escalation in Dokan <= 5.0.2 versions. CVSSv3.1 8.8 (HIGH)

CWECWE 266VNDCustomerTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-06-15
2026-06-15 21:17Z
CRIT

CVE-2026-49776 — SQL: Unauthenticated SQL Injection in GPTranslate – Multilingual AI Translation for WordPress: Automatically Translate Websites

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-49776

Unauthenticated SQL Injection in GPTranslate – Multilingual AI Translation for WordPress: Automatically Translate Websites <= 2.32.6 versions. CVSSv3.1 9.3 (CRITICAL)

CWECWE 89TYPVulnerability
9.3
CVSS v3.1
97
Edit Score
2026-06-15
2026-06-15 21:17Z
CRIT

CVE-2026-49770 — PHP: Unauthenticated PHP Object Injection in WP Travel Engine <= 6.7.12 versions.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-49770

Unauthenticated PHP Object Injection in WP Travel Engine <= 6.7.12 versions. CVSSv3.1 9.8 (CRITICAL)

CWECWE 502TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-06-15
2026-06-15 21:17Z
CRIT

CVE-2026-49769 — PHP: Unauthenticated PHP Object Injection in wpForo Forum <= 3.1.0 versions.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-49769

Unauthenticated PHP Object Injection in wpForo Forum <= 3.1.0 versions. CVSSv3.1 9.8 (CRITICAL)

CWECWE 502TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-06-15
2026-06-15 21:17Z
CRIT

CVE-2026-49768 — PHP: Unauthenticated PHP Object Injection in Happyforms <= 1.26.13 versions.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-49768

Unauthenticated PHP Object Injection in Happyforms <= 1.26.13 versions. CVSSv3.1 9.8 (CRITICAL)

CWECWE 502TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-06-15
2026-06-15 21:17Z
CRIT

CVE-2026-49766 — Subscriber: Arbitrary File Deletion in WP User Manager <= 2.9.16 versions.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-49766

Subscriber Arbitrary File Deletion in WP User Manager <= 2.9.16 versions. CVSSv3.1 9.9 (CRITICAL)

CWECWE 22VNDSubscriberTYPVulnerability
9.9
CVSS v3.1
100
Edit Score
2026-06-15
2026-06-15 21:17Z
CRIT

CVE-2026-49765 — PHP: Unauthenticated PHP Object Injection in Integration for Mailchimp and Contact Form 7, WPForms, Elementor

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-49765

Unauthenticated PHP Object Injection in Integration for Mailchimp and Contact Form 7, WPForms, Elementor, Ninja Forms <= 1.1.8 versions. CVSSv3.1 9.8 (CRITICAL)

CWECWE 502TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-06-15
2026-06-15 21:17Z
CRIT

CVE-2026-49764 — Broken: Unauthenticated Broken Authentication in RegistrationMagic <= 6.0.8.6 versions.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-49764

Unauthenticated Broken Authentication in RegistrationMagic <= 6.0.8.6 versions. CVSSv3.1 9.8 (CRITICAL)

CWECWE 288VNDBrokenTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-06-15
2026-06-15 21:17Z
CRIT

CVE-2026-49763 — PHP: Unauthenticated PHP Object Injection in Integration for Contact Form 7 HubSpot <= 1.3.7 versions.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-49763

Unauthenticated PHP Object Injection in Integration for Contact Form 7 HubSpot <= 1.3.7 versions. CVSSv3.1 9.8 (CRITICAL)

CWECWE 502TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-06-15
2026-06-15 21:17Z
CRIT

CVE-2026-49109 — PHP: Unauthenticated PHP Object Injection in Integration for Salesforce and Contact Form 7, WPForms, Elementor

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-49109

Unauthenticated PHP Object Injection in Integration for Salesforce and Contact Form 7, WPForms, Elementor, Formidable, Ninja Forms <= 1.4.3 versions. CVSSv3.1 9.8 (CRITICAL)

CWECWE 502TYPVulnerability
9.8
CVSS v3.1
99
Edit Score