2026-06-12
2026-06-12 15:16Z
CRIT

CVE-2026-47140 — This allows sandboxed code to bypass the intended builtin restrictions and execute code in

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-47140

vm2 is an open source vm/sandbox for Node.js. Prior to version 3.11.4, NodeVM blocks several dangerous Node.js builtins such as module, worker_threads, cluster, vm, repl, and inspector. However, the denylist misses process and inspector/promises. Both can be used from sandboxed code to reach host-side execution primitives. This allows sandboxed code to bypass the intended builtin restrictions and execute code in the host process. This issue has been patched in version 3.11.4. CVSSv3.1 10.0 (CRITICAL)

CWECWE 693TYPVulnerability
10.0
CVSS v3.1
100
Edit Score
2026-06-12
2026-06-12 15:16Z
HIGH

CVE-2026-47139 — vm2 is an open source vm/sandbox for Node.js.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-47139

vm2 is an open source vm/sandbox for Node.js. Prior to version 3.11.4, NodeVM supports excluding public network builtins from the wildcard builtin option. With this configuration direct access to http, https, http2, net, dgram, tls, dns, and dns/promises is blocked. However, Node.js also exposes underscored internal HTTP builtins such as _http_client and _http_server. These are not blocked when the public modules are excluded. Sandboxed code can use these internal builtins to CVSSv3.1 8.6 (HIGH)

CWECWE 693TYPVulnerability
8.6
CVSS v3.1
93
Edit Score
2026-06-12
2026-06-12 15:16Z
CRIT

CVE-2026-47137 — vm2 is an open source vm/sandbox for Node.js.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-47137

vm2 is an open source vm/sandbox for Node.js. Prior to version 3.11.4, the fix for GHSA-8hg8-63c5-gwmx (CVE-2023-37903) introduced a check in nodevm.js line 263 that blocks the combination nesting: true + require: false. However, the check uses strict equality (options.require === false), which is trivially bypassed by omitting the require option entirely. When require is not specified, options.require is undefined, not false. The strict equality check fails, so the security CVSSv3.1 10.0 (CRITICAL)

CWECWE 913TYPVulnerability
10.0
CVSS v3.1
100
Edit Score
2026-06-12
2026-06-12 15:16Z
HIGH

CVE-2026-47135 — vm2 is an open source vm/sandbox for Node.js.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-47135

vm2 is an open source vm/sandbox for Node.js. Prior to version 3.11.4, Symbol.for override in setup-sandbox.js only intercepts 2 of 9 dangerous Node.js cross-realm symbols. Combined with the bridge's set/defineProperty/deleteProperty traps having no isDangerousCrossRealmSymbol key check, sandbox code can obtain real cross-realm symbols, write them to host objects, and control host-side behavior — verified with a full util.promisify hijack chain. This issue has been patched in CVSSv3.1 8.7 (HIGH)

CWECWE 693TYPVulnerability
8.7
CVSS v3.1
94
Edit Score
2026-06-12
2026-06-12 15:16Z
CRIT

CVE-2026-47131 — Prior to version 3.11.4, by combining Buffer.call.call({}.__lookupGetter__, Buffer, "__proto__"), Buffer.call.call({}.__lookupSetter__, Buffer, "__proto__"), and Node.js's

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-47131

vm2 is an open source vm/sandbox for Node.js. Prior to version 3.11.4, by combining Buffer.call.call({}.__lookupGetter__, Buffer, "__proto__"), Buffer.call.call({}.__lookupSetter__, Buffer, "__proto__"), and Node.js's ERR_INVALID_ARG_TYPE Error, the host's TypeError constructor can be obtained, which allows the escape from the sandbox. This allows attackers to run arbitrary code. This issue has been patched in version 3.11.4. CVSSv3.1 10.0 (CRITICAL)

CWECWE 913TYPVulnerability
10.0
CVSS v3.1
100
Edit Score
2026-06-12
2026-06-12 15:16Z
HIGH

CVE-2026-45674 — Netty: Prior to versions 4.1.135.Final and 4.2.15.Final, Netty's DnsResolveContext fails to validate the origin (bailiwick)

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-45674

Netty is a network application framework for development of protocol servers and clients. Prior to versions 4.1.135.Final and 4.2.15.Final, Netty's DnsResolveContext fails to validate the origin (bailiwick) of CNAME records in DNS responses. Versions 4.1.135.Final and 4.2.15.Final patch the issue. CVSSv3.1 8.7 (HIGH)

CWECWE 345VNDNettyTYPVulnerability
8.7
CVSS v3.1
94
Edit Score
2026-06-12
2026-06-12 15:16Z
CRIT

CVE-2026-10557 — Yarbo: The Yarbo Android and iOS applications contain hard-coded MQTT broker credentials that are identical

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-10557

The Yarbo Android and iOS applications contain hard-coded MQTT broker credentials that are identical for all users and all devices. These credentials are embedded in the application binary and are readily extractable via APK decompilation. The credentials provide access to cloud MQTT brokers carrying real-time telemetry for the entire global Yarbo robot fleet. They allow both wildcard subscription to all robot telemetry topics and publishing to any robot's command topic using CVSSv3.1 9.8 (CRITICAL)

CWECWE 798VNDYarboTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
728 × 90 / responsive · programmatic ad slot
2026-06-12
2026-06-12 13:43Z
CRIT

Active Exploitation of Oracle PeopleSoft Zero-Day (CVE-2026-35273)

Rapid7 Research·rapid7.comCVE-2026-35273in the wild0day

Oracle PeopleSoft PeopleTools versions 8.61 and 8.62 contain a critical SSRF vulnerability (CVE-2026-35273, CVSS 9.8) in the Environment Management Hub that enables unauthenticated remote code execution. The vulnerability was actively exploited in the wild by UNC6240 (ShinyHunters) from May 27 to June 9, 2026—two weeks before Oracle's June 10 advisory—with 68% of targeted organizations in higher education. Post-exploitation activity included MeshCentral RAT deployment, lateral movement, and data exfiltration via zstd compression.

SRFApplicationTACTA0004TACTA0001TACTA0002TACTA0007SRFWebTACTA0003TACTA0011
92
Edit Score
2026-06-12
2026-06-12 11:16Z
CRIT

CVE-2026-11849 — IEI: The iRM-IEI Remote Management developed by IEI Integration Corp has a Hardcoded Credentials vulnerability

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-11849

The  iRM-IEI Remote Management developed by IEI Integration Corp has a Hardcoded Credentials vulnerability, allowing unauthenticated remote attackers to exploit hard-coded credentials to gain administrative privileges on the database. CVSSv3.1 9.8 (CRITICAL)

CWECWE 798VNDIeiTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-06-12
2026-06-12 11:00Z
HIGH

Factoring "short-sleeve" RSA keys with polynomials

Trail of Bits·blog.trailofbits.comin the wild

Trail of Bits and Hanno Böck discovered hundreds of real-world RSA and DSA keys with biased bit patterns ("short-sleeve" keys) that can be rapidly factored using polynomial-based cryptanalysis. The vulnerability was traced to a type mismatch bug in CompleteFTP versions 10.0.0–12.0.0 (RSA) and 10.0.0–23.0.4 (DSA) where RNG output was incorrectly cast to big-integer limbs, creating predictable zero-bit blocks. EnterpriseDT released patched versions (26.1.0+) with automated detection tools; 603 RSA and 74 DSA private keys were recovered from internet scans.

SRFApplicationSRFNetwork ApplianceSWCompleteftpVNDEnterprisedtTYPResearchTYPVulnerabilitySTGDiscoveryTECT1040
88
Edit Score
2026-06-12
2026-06-12 10:16Z
CRIT

CVE-2026-50633 — JNDI: A JNDI Injection vulnerability has been discovered in Apache CXF's JCA integration module, which

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-50633

A JNDI Injection vulnerability has been discovered in Apache CXF's JCA integration module, which can allow for code execution, if an attacker is able to manipulate the JCA deployment descriptor (ra.xml) or runtime activation parameters. Users are recommended to upgrade to versions 4.2.2 or 4.1.7, which fixes this issue. CVSSv3.1 9.8 (CRITICAL)

CWECWE 20VNDJndiTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-06-12
2026-06-12 10:16Z
CRIT

CVE-2026-50632 — A further incomplete fix for a previous advisory CVE-2026-44417 (Untrusted JMS configuration can lead

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-50632

A further incomplete fix for a previous advisory CVE-2026-44417 (Untrusted JMS configuration can lead to RCE) for Apache CXF has been identified, which can allow code execution capabilities, if untrusted users are allowed to configure JMS for Apache CXF. Users are recommended to upgrade to versions 4.2.2 or 4.1.7, which fixes this issue. CVSSv3.1 9.8 (CRITICAL)

CWECWE 20TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-06-12
2026-06-12 10:16Z
HIGH

CVE-2026-50629 — HTTP: This allows an attacker to inject arbitrary content, including fake log entries, into the

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-50629

The 'clientId' parameter from incoming HTTP requests is directly concatenated into OAuth2 server log warning messages without sanitizing control characters. This allows an attacker to inject arbitrary content, including fake log entries, into the server's log files. Users are recommended to upgrade to versions 4.2.2 or 4.1.7, which fixes this issue. CVSSv3.1 8.2 (HIGH)

CWECWE 93VNDHttpTYPVulnerability
8.2
CVSS v3.1
91
Edit Score
2026-06-12
2026-06-12 10:16Z
CRIT

CVE-2026-50628 — Apache Cxf: A logic error in OAuthRequestFilter rejects legitimate requests originating from the bound IP address

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-50628

A logic error in OAuthRequestFilter rejects legitimate requests originating from the bound IP address, while blindly allowing requests from any other IP address. Enabling this security feature inadvertently creates an inverse security check. Users are recommended to upgrade to versions 4.2.2 or 4.1.7, which fixes this issue. CVSSv3.1 9.8 (CRITICAL) · EPSS 11th percentile

CWECWE 20VNDApacheVNDOauthrequestfilterTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-06-12
2026-06-12 10:16Z
CRIT

CVE-2026-50627 — Apache Cxf: This allows a JWT issued for one Resource Server to be successfully replayed against

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-50627

The JwtAccessTokenValidator class in Apache CXF fails to validate the 'aud' (Audience) claims of incoming JWT access tokens. This allows a JWT issued for one Resource Server to be successfully replayed against a completely different Resource Server, leading to Token Confusion/Routing attacks. Users are recommended to upgrade to versions 4.2.2 or 4.1.7, which fixes this issue. CVSSv3.1 9.1 (CRITICAL) · EPSS 4th percentile

CWECWE 289VNDApacheVNDJwtaccesstokenvalidatorTYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2026-06-12
2026-06-12 10:16Z
CRIT

CVE-2026-49875 — Apache Cxf: CXF's EndpointReferenceUtils and W3CMultiSchemaFactory classes construct a SAXParserFactory without the necessary JAXP hardening

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-49875

Apache CXF's EndpointReferenceUtils and W3CMultiSchemaFactory classes construct a SAXParserFactory without the necessary JAXP hardening configurations, enabling out-of-band (OOB) external entity resolution. Users are recommended to upgrade to versions 4.2.2 or 4.1.7, which fix this issue. CVSSv3.1 9.8 (CRITICAL) · EPSS 4th percentile

CWECWE 611VNDApacheTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-06-12
2026-06-12 10:16Z
HIGH

CVE-2026-11846 — IEI: The iVEC-IEI Virtualization Edge Computer developed by IEI Integration Corp has an Arbitrary File

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-11846

The  iVEC-IEI Virtualization Edge Computer developed by IEI Integration Corp has an Arbitrary File Deletion vulnerability, allowing authenticated remote attackers to exploit this vulnerability to delete arbitrary system files or directories,  resulting in data destruction or service disruption. CVSSv3.1 8.1 (HIGH)

CWECWE 22VNDIeiTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-06-12
2026-06-12 08:39Z
HIGH

AI-Powered Exploit Generation: Speed, Scale & Cyber Risk

Horizon3.ai·horizon3.ai

Horizon3.ai analyzes how AI-powered exploit generation fundamentally accelerates attack timelines and lowers the skill barrier for sophisticated cyberattacks. The article argues that AI systems can compress exploit development from days/weeks to hours through parallel hypothesis testing and continuous iteration, enabling smaller threat actors to conduct nation-state-level campaigns. It benchmarks NodeZero's autonomous penetration testing achieving full Active Directory compromise in 14 minutes versus 12-16 hours for human testers, and contends that defenders must deploy autonomous defense operating at machine speed to match machine-speed offense.

SRFApplicationTACTA0004TACTA0005TACTA0001TACTA0002SRFNetworkTACTA0003VNDAnthropic
62
Edit Score
2026-06-12
2026-06-12 07:16Z
HIGH

CVE-2026-12059 — SSH: The SSH service of CelloOS developed by Cellopoint has an Improper Access Control vulnerability

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-12059

The SSH service of CelloOS developed by Cellopoint has an Improper Access Control vulnerability, allowing authenticated remote attackers to bypass the enforced command restrictions and execute operating system commands outside the originally authorized scope. CVSSv3.1 8.8 (HIGH)

CWECWE 1284VNDSshTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-06-12
2026-06-12 05:17Z
CRIT

Marking Your Own Homework (Check Point Remote Access VPN IKEv1 Authentication Bypass CVE-2026-50751)

watchTowr Labs·labs.watchtowr.comCVE-2026-50751in the wild

Check Point Remote Access VPN contains a critical authentication bypass (CVE-2026-50751, CVSS 9.3) in deprecated IKEv1 code affecting R80.20–R82.10. The vulnerability stems from a logic flaw where the gateway allows clients to control certificate validation flags via a Vendor ID payload, enabling attackers to bypass signature verification and machine certificate checks. The flaw has been exploited in the wild since May 2026 by Qilin ransomware affiliates and others, affecting dozens of organizations.

SRFNetworkSRFNetwork ApplianceTACTA0006TACTA0007SWCheck Point Remote Access VpnVNDCheckpointTYPResearchTYPVulnerability
95
Edit Score
2026-06-12
2026-06-12 05:16Z
HIGH

CVE-2026-45169 — Paloaltonetworks Idira_privileged_access_manager_vault: Under specific circumstances and configuration scenarios, processing unexpected input could potentially lead to an

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-45169

Idira Privileged Access Manager (PAM) Self-Hosted Vault versions prior to 15.0.3, 14.6.5, 14.2.7, and 14.0.8 exhibit a validation vulnerability. Under specific circumstances and configuration scenarios, processing unexpected input could potentially lead to an unexpected service termination, resulting in a localized denial of service (DoS). CyberArk Security Bulletin: CA26-17 CVSSv3.1 8.6 (HIGH) · EPSS 22th percentile

CWECWE 400VNDPaloaltonetworksVNDIdiraTYPVulnerability
8.6
CVSS v3.1
93
Edit Score
2026-06-12
2026-06-12 04:17Z
HIGH

CVE-2026-48612 — OAuth: Improper state verification in the OAuth implementation could allow an attacker to manipulate the

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-48612

Improper state verification in the OAuth implementation could allow an attacker to manipulate the authentication flow and cause a victim’s account to be linked to an attacker-controlled account. This can result in unauthorized account linking and potential account takeover. CVSSv3.1 8.0 (HIGH)

CWECWE 352VNDOauthTYPVulnerability
8.0
CVSS v3.1
90
Edit Score
2026-06-12
2026-06-12 04:17Z
CRIT

CVE-2026-48611 — OAuth: Improper authentication checks in the OAuth implementation allow account hijacking even when OAuth is

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-48611

Improper authentication checks in the OAuth implementation allow account hijacking even when OAuth is not configured or enabled leading to unauthorized access in default installations. CVSSv3.1 9.8 (CRITICAL)

CWECWE 287VNDOauthTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-06-12
2026-06-12 04:17Z
HIGH

CVE-2026-48610 — Under certain network configurations, a malicious actor with access to network could exploit an

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-48610

Under certain network configurations, a malicious actor with access to network could exploit an Improper Access Control vulnerability found in certain devices running UniFi OS to make unauthorized changes to such UniFi OS devices. CVSSv3.1 8.1 (HIGH)

CWECWE 284TYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-06-12
2026-06-12 04:17Z
CRIT

CVE-2026-47370 — A malicious actor with access to the network and low privileges could exploit an

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-47370

A malicious actor with access to the network and low privileges could exploit an Improper Input Validation vulnerability found in certain devices running UniFi OS to execute a Command Injection within such UniFi OS devices or instances. CVSSv3.1 9.9 (CRITICAL)

CWECWE 20TYPVulnerability
9.9
CVSS v3.1
100
Edit Score