1w ago
2026-09-04 15:17Z
HIGH

CVE-2026-85607 — Blinko: 1.8.7 contains an authorization bypass (IDOR) vulnerability in multiple tRPC procedures (message.list, message.update

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-85607

Blinko 1.8.7 contains an authorization bypass (IDOR) vulnerability in multiple tRPC procedures (message.list, message.update, message.delete, message.clearAfter in server/routerTrpc/message.ts and conversation.clearMessages in server/routerTrpc/conversation.ts). Although these procedures require authentication, they query the database by caller-supplied conversation or message ID without verifying that the resource belongs to the requesting account. Any authenticated user can CVSSv3.1 8.8 (HIGH)

CWECWE 639VNDBlinkoTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
1w ago
2026-09-04 14:17Z
HIGH

CVE-2026-52691 — UNSUPPORTED: ** UNSUPPORTED WHEN ASSIGNED ** Improper Neutralization of Special Elements used in an SQL

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-52691

** UNSUPPORTED WHEN ASSIGNED ** Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Griffin Hive Metastore Module.  This issue affects Apache Griffin Hive Metastore Module: all versions. As this project is retired, we do not plan to release a version that fixes this issue. Users are recommended to find an alternative or restrict access to the instance to trusted users. NOTE: This vulnerability only affects prod CVSSv3.1 8.8 (HIGH) · EPSS 7th percentile

CWECWE 89VNDUnsupportedTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
1w ago
2026-09-04 13:18Z
HIGH

CVE-2026-18198 — Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-18198

Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in TAC Information Services Internal and External Trade Inc. GOLDENHORN ONEIT allows Blind SQL Injection. This issue affects GOLDENHORN ONEIT: before Göbeklitepe. CVSSv3.1 8.8 (HIGH)

CWECWE 89TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
1w ago
2026-09-04 12:17Z
HIGH

CVE-2026-85617 — snipe-it versions before 8.6.3 contain an authorization bypass vulnerability in the bulk delete functionality

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-85617

snipe-it versions before 8.6.3 contain an authorization bypass vulnerability in the bulk delete functionality that allows restricted users to soft-delete users outside their authorized scope. Attackers can include unauthorized user IDs in bulk delete requests to bypass instance-level restrictions and modify or disable accounts they should not access. CVSSv3.1 8.8 (HIGH)

CWECWE 639TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
1w ago
2026-09-04 12:17Z
HIGH

CVE-2026-85616 — Snipe: Snipe-IT versions before 8.6.2 contain an authorization bypass vulnerability in checkout-acceptance report actions when

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-85616

Snipe-IT versions before 8.6.2 contain an authorization bypass vulnerability in checkout-acceptance report actions when Full Multiple Company Support is enabled. Authenticated users with reports.view permission can enumerate sequential acceptance IDs and soft-delete or trigger reminder emails for acceptances belonging to other companies by exploiting a null check on the legacy users.company_id column. CVSSv3.1 8.5 (HIGH)

CWECWE 639VNDSnipeTYPVulnerability
8.5
CVSS v3.1
93
Edit Score
1w ago
2026-09-04 12:17Z
HIGH

CVE-2026-85614 — OpenPanel: before 2.3.0 contains an unauthenticated server-side request forgery vulnerability in the GET /tools/site-checker

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-85614

OpenPanel before 2.3.0 contains an unauthenticated server-side request forgery vulnerability in the GET /tools/site-checker endpoint that accepts a fully client-controlled URL parameter with no private IP filtering or DNS-rebinding protection. Attackers can make the OpenPanel server issue requests to internal services, localhost, and cloud metadata endpoints, reading internal HTTP response titles, headers, status codes, and SSL certificate information. CVSSv3.1 8.6 (HIGH)

CWECWE 918VNDOpenpanelTYPVulnerability
8.6
CVSS v3.1
93
Edit Score
1w ago
2026-09-04 12:17Z
HIGH

CVE-2026-85613 — OpenPanel: before 2.3.0 contains a cross-site scripting vulnerability in the unauthenticated favicon proxy endpoint

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-85613

OpenPanel before 2.3.0 contains a cross-site scripting vulnerability in the unauthenticated favicon proxy endpoint GET /misc/favicon that allows remote attackers to execute scripts by supplying an SVG file URL. Attackers can host malicious SVG files with embedded scripts that execute in the victim's browser on the API origin, enabling same-origin credentialed requests to authenticated endpoints. CVSSv3.1 8.2 (HIGH)

CWECWE 79VNDOpenpanelTYPVulnerability
8.2
CVSS v3.1
91
Edit Score
728 × 90 / responsive · programmatic ad slot
1w ago
2026-09-04 12:17Z
HIGH

CVE-2026-85610 — OpenPanel: before 2.3.0 fails to properly validate chart formula expressions, allowing authenticated project members

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-85610

OpenPanel before 2.3.0 fails to properly validate chart formula expressions, allowing authenticated project members with read access to execute arbitrary code by recovering the native JavaScript Function constructor through mathjs matrix objects. Attackers can use the recovered constructor to load Node.js built-ins and execute operating system commands with the privileges of the API process, bypassing organization authorization boundaries. CVSSv3.1 8.8 (HIGH)

CWECWE 94VNDOpenpanelTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
1w ago
2026-09-04 12:17Z
HIGH

CVE-2026-85604 — Grav: before 2.0.19 (affected versions <= 2.0.17) contains a remote code execution vulnerability in

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-85604

Grav before 2.0.19 (affected versions <= 2.0.17) contains a remote code execution vulnerability in the Twig sort filter. The sortFunc wrapper in GravExtension.php hardcodes Twig's isSandboxed argument to false, so unlike |map/|filter/|reduce, |sort accepts a plain function name inside the sandbox; the remaining denylist misses spl_autoload, which performs a PHP include. An authenticated user with only page-write rights (admin.pages or api.pages.write) can supply a crafted pay CVSSv3.1 8.8 (HIGH)

CWECWE 94VNDGravTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
1w ago
2026-09-04 12:00Z
CRIT

DPRK APTs: Ted backdoor and curlRAT target South Korean media and automotive sectors

Rapid7 Research·rapid7.comin the wild

Rapid7 Labs disclosed a sophisticated Linux toolkit attributed to DPRK APTs targeting South Korean media and automotive sectors since early 2025. The campaign leverages a custom HAProxy 2.8.12 backdoor (ted) compiled with malicious filter plugins, trojanized system daemons (crond, sshd, agetty, atd, polkitd), and a curl-based RAT (curlRAT) for persistent command execution, credential harvesting, traffic interception, and watering-hole attacks. Initial access likely exploited RCE vulnerabilities in externally exposed groupware portals or mail servers, with the toolkit enabling long-term espionage through deep OS integration and sophisticated log erasure.

SRFApplicationTACTA0005SRFNetwork ApplianceTACTA0006TACTA0007TACTA0003TACTA0011OSLinux
92
Edit Score
1w ago
2026-09-04 10:17Z
HIGH

CVE-2026-85540 — DreamMaker: developed by Interinfo has a SQL Injection vulnerability.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-85540

DreamMaker developed by Interinfo has a SQL Injection vulnerability. Authenticated remote attackers can inject arbitrary SQL commands to read, modify, and delete database contents. CVSSv3.1 8.8 (HIGH)

CWECWE 89VNDDreammakerTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
1w ago
2026-09-04 10:17Z
CRIT

CVE-2026-85184 — An unauthenticated network attacker can use this to bypass path-based access controls in a

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-85184

@fastify/middie versions >= 9.1.0 and before 9.3.4 decide whether to run path-scoped middleware by matching against the raw request target, while the Fastify router resolves an absolute-form request target to its path before dispatching. Because the two layers evaluate different strings, a request using an absolute-form target reaches the route handler while the path-scoped middleware, such as authentication or authorization, is skipped. An unauthenticated network attacker ca CVSSv3.1 9.1 (CRITICAL)

CWECWE 436TYPVulnerability
9.1
CVSS v3.1
96
Edit Score
1w ago
2026-09-04 10:17Z
HIGH

CVE-2026-84504 — An authenticated low-privilege caller can use this to make nested data replace the validated

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-84504

fastify versions before 5.12.2 treat the object resolved by a successful Ajv async validator as the value result protocol used by custom validator compilers. If a request that passes its route schema contains a property named value at the root, fastify replaces the entire request body with that property's value before the handler runs, so the handler receives a different object than the one that satisfied the schema. An authenticated low-privilege caller can use this to make CVSSv3.1 8.1 (HIGH)

CWECWE 20TYPVulnerability
8.1
CVSS v3.1
91
Edit Score
1w ago
2026-09-04 10:17Z
CRIT

CVE-2026-82923 — Website: On a host that serves PHP from the uploads directory, that file write is

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-82923

The AI Website Builder WordPress plugin (GitHub build) 1.0.0 does not perform any authorisation or nonce check on its REST API routes, allowing unauthenticated attackers to install and activate plugins and themes, import content from a URL under their control, write a file of their choosing into the uploads directory, and delete site content and media. On a host that serves PHP from the uploads directory, that file write is remote code execution. CVSSv3.1 9.8 (CRITICAL)

TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
1w ago
2026-09-04 10:00Z
HIGH

Angry Birds: Toy Ghouls’ new toys

Kaspersky Securelist·securelist.comin the wild

Kaspersky researchers discovered two new custom backdoors deployed by the Toy Ghouls APT group targeting Russian organizations since July 2026. The backdoors—mqtt-bird-agent and matrix-bird-agent—use unconventional C2 channels (HiveMQ MQTT broker and Element/Matrix messenger) and are delivered via WinRM, establishing persistence as Windows services with full command execution capabilities via PowerShell.

SRFApplicationTACTA0005TACTA0001SRFNetworkTACTA0003TACTA0011OSWindowsSWElement
78
Edit Score
1w ago
2026-09-04 07:17Z
HIGH

CVE-2026-85094 — Canva: The Canva Android App before 2.376.0 did not restrict the headers returned to an

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-85094

The Canva Android App before 2.376.0 did not restrict the headers returned to an external origin running in a privileged WebView. A threat actor with control of the WebView could access a user’s session. CVSSv3.1 8.8 (HIGH)

CWECWE 212VNDCanvaTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
1w ago
2026-09-04 07:17Z
CRIT

CVE-2026-85085 — Canva: The Canva Android App before 2.376.0 allowed an external origin to be loaded in

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-85085

The Canva Android App before 2.376.0 allowed an external origin to be loaded in a privileged WebView. A threat actor who controls the page loaded by the user is able to communicate with Canva using the user’s session. CVSSv3.1 9.6 (CRITICAL)

CWECWE 940VNDCanvaTYPVulnerability
9.6
CVSS v3.1
98
Edit Score
1w ago
2026-09-04 07:17Z
CRIT

CVE-2026-80181 — Apache: Allura's webhooks are vulnerable to Server-Side Request Forgery (SSRF).

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-80181

Apache Allura's webhooks are vulnerable to Server-Side Request Forgery (SSRF). This issue affects Apache Allura: through 1.20.0. Users are recommended to upgrade to version 1.21.0, which fixes the issue. CVSSv3.1 9.1 (CRITICAL) · EPSS 11th percentile

CWECWE 918VNDApacheTYPVulnerability
9.1
CVSS v3.1
96
Edit Score
1w ago
2026-09-04 07:17Z
CRIT

CVE-2026-70403 — XING: CPTrans-ME-X contains a Use of Hard-coded Password (CWE-259).

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-70403

XING CPTrans-ME-X contains a Use of Hard-coded Password (CWE-259). Anyone with the knowledge of the credential may log in to the affected device. CVSSv3.1 9.8 (CRITICAL)

CWECWE 259VNDXingTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
1w ago
2026-09-04 07:17Z
CRIT

CVE-2026-69657 — XING: CPTrans-ME-X contains a Use of Default Password (CWE-1393).

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-69657

XING CPTrans-ME-X contains a Use of Default Password (CWE-1393). Anyone with the knowledge of the credential may log in to the affected device. CVSSv3.1 9.8 (CRITICAL)

CWECWE 1393VNDXingTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
1w ago
2026-09-04 07:17Z
CRIT

CVE-2026-62928 — XING: CPTrans-ME-X contains an OS Command Injection (CWE-78).

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-62928

XING CPTrans-ME-X contains an OS Command Injection (CWE-78). Unauthenticated OS command may be injected. CVSSv3.1 9.8 (CRITICAL)

CWECWE 78VNDXingTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
1w ago
2026-09-04 07:17Z
CRIT

CVE-2026-15354 — ACPT: The ACPT (Premium) plugin for WordPress is vulnerable to Privilege Escalation in all versions

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-15354

The ACPT (Premium) plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 2.0.66. This is due to missing authorization in the `submit()` function, which allows unauthenticated form submissions to control the target user ID before calling `wp_update_user()`. This makes it possible for unauthenticated attackers to overwrite any WordPress user's email address and password, including an administrator's, and take over the account. Successf CVSSv3.1 9.8 (CRITICAL)

CWECWE 269VNDAcptTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
1w ago
2026-09-04 05:17Z
CRIT

CVE-2026-85509 — FreeIPMI: before 1.6.19 has a stack-based buffer overflow in _read_fru_data in libfreeipmi/fru/ipmi-fru.c when a

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-85509

FreeIPMI before 1.6.19 has a stack-based buffer overflow in _read_fru_data in libfreeipmi/fru/ipmi-fru.c when a BMC returns more bytes than requested. CVSSv3.1 9.8 (CRITICAL)

CWECWE 121VNDFreeipmiTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
1w ago
2026-09-04 05:17Z
CRIT

CVE-2026-85508 — FreeIPMI: ipmi-oem in FreeIPMI before 1.6.19 has a stack-based buffer overflow in _output_dell_system_info_cmc_ipv6_info in ipmi-oem/ipmi-oem-dell.c

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-85508

ipmi-oem in FreeIPMI before 1.6.19 has a stack-based buffer overflow in _output_dell_system_info_cmc_ipv6_info in ipmi-oem/ipmi-oem-dell.c (cmc-ipv6-info subcommand to dell get-system-info). CVSSv3.1 9.8 (CRITICAL)

CWECWE 121VNDFreeipmiTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
1w ago
2026-09-04 05:17Z
CRIT

CVE-2026-85507 — FreeIPMI: ipmi-oem in FreeIPMI before 1.6.19 has a stack-based buffer overflow in _output_dell_system_info_cmc_info in ipmi-oem/ipmi-oem-dell.c

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-85507

ipmi-oem in FreeIPMI before 1.6.19 has a stack-based buffer overflow in _output_dell_system_info_cmc_info in ipmi-oem/ipmi-oem-dell.c (cmc-info subcommand to dell get-system-info). CVSSv3.1 9.8 (CRITICAL)

CWECWE 121VNDFreeipmiTYPVulnerability
9.8
CVSS v3.1
99
Edit Score