2026-06-11
2026-06-11 19:16Z
HIGH

CVE-2026-45178 — Paloaltonetworks Idira_secrets_manager: A remote, authenticated attacker possessing standard node-level credentials could leverage these endpoints to potentially

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-45178

Idira Secrets Manager Self-Hosted versions 13.8.0 and lower exhibit improper access control within internal cluster endpoints. A remote, authenticated attacker possessing standard node-level credentials could leverage these endpoints to potentially retrieve unauthorized secrets or cause a denial of service (DoS). CyberArk Security Bulletin: CA26-20 CVSSv3.1 8.1 (HIGH) · EPSS 24th percentile

CWECWE 284VNDPaloaltonetworksVNDIdiraTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-06-11
2026-06-11 19:16Z
CRIT

CVE-2026-45177 — Paloaltonetworks Idira_secrets_manager_edge: Under specific circumstances, this could allow the attacker to manipulate internal validation mechanisms, potentially

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-45177

Idira Secrets Manager SaaS Edge versions prior to 1.8 exhibit improper access control within its internal authentication components. A remote, unauthenticated attacker could exploit this by submitting a specially crafted request. Under specific circumstances, this could allow the attacker to manipulate internal validation mechanisms, potentially leading to a bypass of identity verification and the unauthorized acquisition of an access token. CyberArk Security Bulletin: CA26-2 CVSSv3.1 9.1 (CRITICAL) · EPSS 42th percentile

CWECWE 284VNDPaloaltonetworksVNDIdiraTYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2026-06-11
2026-06-11 19:16Z
HIGH

CVE-2025-24284 — This issue was addressed with improved checks to prevent unauthorized actions.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2025-24284

This issue was addressed with improved checks to prevent unauthorized actions. This issue is fixed in macOS Sequoia 15.4. An app may be able to break out of its sandbox. CVSSv3.1 8.8 (HIGH)

CWECWE 693TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-06-11
2026-06-11 18:30Z
INFO

v9.3.0-rc3

BloodHound releases·github.com

BloodHound v9.3.0-rc3 release candidate published with a single bug fix addressing OG Extension Deletion Dialogue (BED-8570). This is a routine pre-release update in the v9.3.0 release cycle.

SWBloodhoundTYPTool
15
Edit Score
2026-06-11
2026-06-11 18:16Z
CRIT

CVE-2026-49261 — MariaDB: server is a community developed fork of MySQL server.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-49261

MariaDB server is a community developed fork of MySQL server. Versions 10.6.1 through 10.6.26, 10.11.1 through 10.11.17, 11.4.1 through 11.4.11, 11.8.1 through 11.8.7, and 12.3.1 with `wsrep_notify_cmd` enabled would execute shell commands embedded in the name of the joiner node. This is fixed in 10.6.27, 10.11.18, 11.4.12, 11.8.8, and 12.3.2. As a workaround, anyone who cannot upgrade now should disable `wsrep_notify_cmd`. CVSSv3.1 10.0 (CRITICAL)

CWECWE 78VNDMariadbTYPVulnerability
10.0
CVSS v3.1
100
Edit Score
2026-06-11
2026-06-11 17:16Z
HIGH

CVE-2026-49982 — tmp is a temporary file and directory creator for node.js.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-49982

tmp is a temporary file and directory creator for node.js. In version 0.2.6, the _assertPath guard added to tmp rejects only string values that contain the substring ... It is bypassed when prefix, postfix, or template is supplied as a non-string value (Array, Buffer, or any object) whose includes('..') returns falsy but whose stringification still contains ../. The value flows through Array.prototype.join/String coercion inside _generateTmpName and path.join(tmpDir, opts.dir CVSSv3.1 8.2 (HIGH)

CWECWE 22CWECWE 20TYPVulnerability
8.2
CVSS v3.1
91
Edit Score
2026-06-11
2026-06-11 17:16Z
HIGH

CVE-2026-44705 — Raszi Tmp: Prior to 0.2.6, the tmp npm package contains a path traversal vulnerability that allows

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-44705

tmp is a temporary file and directory creator for node.js. Prior to 0.2.6, the tmp npm package contains a path traversal vulnerability that allows escaping the intended temporary directory when untrusted data flows into the prefix, postfix, or dir options. By embedding traversal sequences (e.g., ../) or path separators in these parameters, attackers can cause files to be created outside the configured temporary base directory at attacker-controlled locations with the privileg CVSSv3.1 8.2 (HIGH) · EPSS 20th percentile

CWECWE 22VNDRasziTYPVulnerability
8.2
CVSS v3.1
91
Edit Score
728 × 90 / responsive · programmatic ad slot
2026-06-11
2026-06-11 17:16Z
HIGH

CVE-2026-44494 — Axios: From 1.0.0 to before 1.16.0, the Axios library is vulnerable to a Prototype Pollution

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-44494

Axios is a promise based HTTP client for the browser and Node.js. From 1.0.0 to before 1.16.0, the Axios library is vulnerable to a Prototype Pollution "Gadget" attack that allows any Object.prototype pollution in the application's dependency tree to be escalated into a full Man-in-the-Middle (MITM) attack — intercepting, reading, and modifying all HTTP traffic including authentication credentials. The HTTP adapter at lib/adapters/http.js:670 reads config.proxy via standard p CVSSv3.1 8.7 (HIGH)

CWECWE 441CWECWE 1321VNDAxiosTYPVulnerability
8.7
CVSS v3.1
94
Edit Score
2026-06-11
2026-06-11 17:16Z
HIGH

CVE-2026-44492 — Axios: Prior to 0.32.0 and 1.16.0, Axios does not normalise IPv4-mapped IPv6 addresses.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-44492

Axios is a promise based HTTP client for the browser and Node.js. Prior to 0.32.0 and 1.16.0, Axios does not normalise IPv4-mapped IPv6 addresses. When NO_PROXY lists an IPv4 address such as 127.0.0.1 or 169.254.169.254, a request URL using the IPv4-mapped IPv6 form (::ffff:7f00:1, ::ffff:a9fe:a9fe) still routes through the configured proxy. Node.js resolves these addresses to the underlying IPv4 host, so the request reaches the internal service via the proxy rather than bein CVSSv3.1 8.6 (HIGH)

CWECWE 918VNDAxiosTYPVulnerability
8.6
CVSS v3.1
93
Edit Score
2026-06-11
2026-06-11 16:16Z
CRIT

CVE-2026-9648 — Haskell: This oversight enables an attacker who compromises a name-constrained sub-CA to impersonate domains beyond

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-9648

The crypton-x509-validation Haskell library fails to enforce X.509 NameConstraints, allowing TLS clients to accept certificates whose Subject Alternative Names fall outside the issuing CA’s permitted subtrees. This oversight enables an attacker who compromises a name-constrained sub-CA to impersonate domains beyond its intended scope. CVSSv3.1 9.1 (CRITICAL)

VNDHaskellTYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2026-06-11
2026-06-11 16:16Z
HIGH

CVE-2026-7870 — IBM: i 7.6, 7.5, 7.4, and 7.3 could allow a user to gain elevated

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-7870

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a user to gain elevated privileges due to an unqualified library call. A malicious actor could cause user-controlled code to run with administrator privilege. CVSSv3.1 8.8 (HIGH)

CWECWE 427VNDIbmTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-06-11
2026-06-11 16:16Z
HIGH

CVE-2026-53777 — Perry: before 0.5.1159 contains a path traversal vulnerability that allows a malicious build server

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-53777

Perry before 0.5.1159 contains a path traversal vulnerability that allows a malicious build server to write arbitrary content to any location writable by the running process by supplying unsanitized path components in the artifact_name field of ArtifactReady WebSocket messages. Attackers controlling the server URL can deliver traversal payloads through the artifact_name or download_path fields, causing the client to overwrite sensitive files or expose arbitrary local files to CVSSv3.1 8.1 (HIGH)

CWECWE 22VNDPerryTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-06-11
2026-06-11 16:16Z
CRIT

CVE-2026-11839 — Rotaban allows Upload a Web Shell to a Web Server.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-11839

Unrestricted upload of file with dangerous type vulnerability in Başarsoft Information Technologies Inc. Rotaban allows Upload a Web Shell to a Web Server. This issue affects Rotaban: from V2026.06.002 before V2026.06.003. CVSSv3.1 9.9 (CRITICAL)

CWECWE 434TYPVulnerability
9.9
CVSS v3.1
100
Edit Score
2026-06-11
2026-06-11 16:00Z
HIGH

Building an Indirect Prompt Injection Workflow

SpecterOps·specterops.io

SpecterOps researcher Antero Guy documents a systematic methodology for automating indirect prompt injection attacks against Claude Sonnet models on Amazon Bedrock. The workflow uses OpenAI Codex to iteratively generate, test, and refine payloads that achieve data exfiltration, command execution, and HTTP-based C2 via poisoned knowledge bases. The research identifies key payload components (authority framing, accuracy directives, obfuscation, sequential compliance) that increase exploitation reliability across model versions.

TACTA0001TACTA0002TACTA0009SRFAiTYPResearchSTGExecutionSTGInitial AccessSTGExfil
78
Edit Score
2026-06-11
2026-06-11 16:00Z
MED

Making secret scanning more trustworthy: Reducing false positives at scale

GitHub Security·github.blog

GitHub published research on reducing false positives in secret scanning by applying LLM-based contextual verification to AI-detected secrets. The approach extracts high-signal usage patterns (variable assignment, API calls, auth headers) rather than analyzing full code context, achieving a 75.76% false positive reduction on customer-confirmed alerts while maintaining detection coverage.

SRFApplicationTACTA0006SRFSupply ChainSWGithubVNDMicrosoftVNDGithubTYPResearchTECT1552
62
Edit Score
2026-06-11
2026-06-11 15:35Z
CRIT

CVE-2026-10520 | Ivanti Sentry Pre-Authenticated OS Command Injection Vulnerability |

Horizon3.ai·horizon3.aiCVE-2026-10520in the wild

Ivanti Sentry contains a critical pre-authenticated OS command injection vulnerability (CVE-2026-10520, CVSS 10.0) in the /mics/api/v2/sentry/mics-config/handleMessage endpoint that allows unauthenticated remote attackers to execute arbitrary commands as root. A public proof-of-concept was released June 10, 2026, and patches are available for versions R10.5.2, R10.6.2, and R10.7.1 and later.

TACTA0001SRFNetwork ApplianceSWIvanti SentryVNDIvantiTYPVulnerabilitySTGInitial AccessTECT1190EXPCommand Injection
92
Edit Score
2026-06-11
2026-06-11 14:54Z
INFO

v9.3.0-rc2

BloodHound releases·github.com

BloodHound v9.3.0-rc2 release candidate published with bug fixes and dependency updates. Changes include fixes for current vulnerabilities, DAWGS index regression fix, and bumps to vulnerable Go dependencies (crypto, sys, chi).

SWBloodhoundVNDSpecteropsTYPTool
28
Edit Score
2026-06-11
2026-06-11 14:16Z
CRIT

CVE-2026-38581 — SQL: Injection vulnerability in damasac thaipalliative_lte through version 3.0 allows remote attackers to execute

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-38581

SQL Injection vulnerability in damasac thaipalliative_lte through version 3.0 allows remote attackers to execute arbitrary SQL commands via the idFormMain parameter to /substudy/ezform.php (line 14) and the id parameter (line 49). The parameters are concatenated directly into SQL queries without sanitization or parameterized statements. CVSSv3.1 9.8 (CRITICAL)

CWECWE 89TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-06-11
2026-06-11 14:16Z
HIGH

CVE-2026-11816 — Keras: versions prior to 3.14.0 are vulnerable to a path traversal issue in the

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-11816

Keras versions prior to 3.14.0 are vulnerable to a path traversal issue in the archive extraction utilities located in `keras/src/utils/file_utils.py`. The functions `filter_safe_tarinfos()` and `filter_safe_zipinfos()` validate archive member paths against the process current working directory (CWD) instead of the actual extraction destination. When the process runs with CWD set to `/`, which is common in Docker containers, CI/CD runners, and Jupyter environments, the valida CVSSv3.1 8.1 (HIGH)

CWECWE 22VNDKerasTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-06-11
2026-06-11 13:16Z
CRIT

CVE-2026-7852 — LimRAD NAC allows Remote Code Inclusion.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-7852

Unrestricted upload of file with dangerous type vulnerability in Limatek System Inc. LimRAD NAC allows Remote Code Inclusion. This issue affects LimRAD NAC: before 5.5.7.3.9. CVSSv3.1 9.8 (CRITICAL)

CWECWE 434TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-06-11
2026-06-11 13:16Z
CRIT

CVE-2026-11561 — Improper neutralization of special elements used in an expression language statement ('expression language injection')

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-11561

Improper neutralization of special elements used in an expression language statement ('expression language injection') vulnerability in Soagen Informatics Technologies Software and Consulting Inc. Apinizer allows Code Injection. This issue affects Apinizer: from 2026.04.0 before 2026.04.6. CVSSv3.1 9.8 (CRITICAL)

CWECWE 917TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-06-11
2026-06-11 13:00Z
HIGH

Criminal AI-as-a-Service in 2026: How the Underground Market Is Operationalizing Cybercrime

Rapid7 Research·rapid7.com

Rapid7 research documents the operationalization of criminal AI-as-a-Service (AIaaS) in 2026, showing threat actors have moved beyond experimental malicious chatbots to embed AI as a productivity layer across cybercrime workflows. The underground market now offers subscription-based services (FraudGPT, WormGPT, BruteForceAI, Xanthorox) that democratize phishing, social engineering, malware debugging, document forgery, and post-breach data exploitation. Complementary threats include stolen AI account resale and deepfake services for KYC bypass and synthetic identity fraud.

SRFApplicationTACTA0001TACTA0006TACTA0009SRFAiTYPResearchTYPThreat IntelSTGInitial Access
78
Edit Score
2026-06-11
2026-06-11 13:00Z
MED

Enabling Proper PCI Testing with Internal Penetration Tests

Bishop Fox Labs·bishopfox.com

Bishop Fox publishes a detailed methodology for scoping and executing PCI DSS v4.0.1-compliant internal penetration tests, highlighting expanded scope requirements that now explicitly include cloud infrastructure, SaaS applications, and CI/CD pipelines. The article covers scoping documentation requirements, segmentation testing across network and authentication/authorization controls, and deliverable structure aligned with QSA expectations.

SRFApplicationSRFNetworkTACTA0007SRFCloudTACTA0008TYPResearchSTGDiscoverySTGCred Access
62
Edit Score
2026-06-11
2026-06-11 12:16Z
HIGH

CVE-2026-6552 — GitLab: has remediated an issue in GitLab EE affecting all versions from 15.5 before

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-6552

GitLab has remediated an issue in GitLab EE affecting all versions from 15.5 before 18.10.8, 18.11 before 18.11.5, and 19.0 before 19.0.2 that under certain conditions could have allowed an authenticated user with group Owner role to take over another group member's GitLab account due to improper authorization in the Group SAML identity management functionality. CVSSv3.1 8.7 (HIGH)

CWECWE 639VNDGitlabTYPVulnerability
8.7
CVSS v3.1
94
Edit Score
2026-06-11
2026-06-11 12:16Z
HIGH

CVE-2026-10087 — GitLab: has remediated an issue in GitLab EE affecting all versions from 17.1 before

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-10087

GitLab has remediated an issue in GitLab EE affecting all versions from 17.1 before 18.10.8, 18.11 before 18.11.5, and 19.0 before 19.0.2 that under certain conditions could have allowed an authenticated user with developer-role permissions to execute arbitrary client-side code on behalf of a targeted user due to improper input sanitization in the Analytics Dashboard. CVSSv3.1 8.7 (HIGH)

CWECWE 79VNDGitlabTYPVulnerability
8.7
CVSS v3.1
94
Edit Score