2026-06-10
2026-06-10 16:17Z
HIGH

CVE-2026-49759 — Erlang Erlang\/otp: Stack-based Buffer Overflow vulnerability in Erlang OTP erts (inet_drv) allows an unauthenticated remote attacker

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-49759

Stack-based Buffer Overflow vulnerability in Erlang OTP erts (inet_drv) allows an unauthenticated remote attacker to crash the BEAM VM by sending a crafted SCTP ERROR chunk. The sctp_parse_error_chunk function in erts/emulator/drivers/common/inet_drv.c parses SCTP ERROR chunks and writes cause codes into a fixed-size stack-allocated ErlDrvTermData spec[] array without checking bounds. A remote attacker who has established an SCTP association to a listening port can send a si CVSSv3.1 8.2 (HIGH) · EPSS 27th percentile

CWECWE 121VNDErlangVNDStackTYPVulnerability
8.2
CVSS v3.1
91
Edit Score
2026-06-10
2026-06-10 16:17Z
HIGH

CVE-2026-46558 — Plane: Prior to version 1.3.1, there is a cross-workspace asset authorization bypass lets any authenticated

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-46558

Plane is an open-source project management tool. Prior to version 1.3.1, there is a cross-workspace asset authorization bypass lets any authenticated user read, copy, delete, and overwrite assets in other Plane workspaces. This issue has been patched in version 1.3.1. CVSSv3.1 8.3 (HIGH)

CWECWE 862CWECWE 639VNDPlaneTYPVulnerability
8.3
CVSS v3.1
92
Edit Score
2026-06-10
2026-06-10 16:17Z
HIGH

CVE-2026-45569 — Roxy: In versions 8.2.6.4 and prior, ommit d4d10006 ("Expand validation to block ..

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-45569

Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. In versions 8.2.6.4 and prior, ommit d4d10006 ("Expand validation to block .. in config_file_name and configver for improved security") added a line in app/modules/config/config.py:462. This is tuple-membership, not substring containment — '..' in (a, b, c) evaluates to True only if any of a, b, c is equal to the literal string '..'. For any realistic path-traversal payload (../../etc/passw CVSSv3.1 8.1 (HIGH)

CWECWE 22CWECWE 697VNDRoxyTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-06-10
2026-06-10 16:17Z
HIGH

CVE-2026-45567 — Roxy: In versions 8.2.6.4 and prior, there is an authentication bypass vulnerability via 'api' substring

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-45567

Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. In versions 8.2.6.4 and prior, there is an authentication bypass vulnerability via 'api' substring in URL + unauthenticated /api/gpt. At time of publication, there are no publicly available patches. CVSSv3.1 8.3 (HIGH)

CWECWE 306CWECWE 287CWECWE 697VNDRoxyTYPVulnerability
8.3
CVSS v3.1
92
Edit Score
2026-06-10
2026-06-10 16:17Z
HIGH

CVE-2026-45565 — Roxy: In versions 8.2.6.4 and prior, EscapedString (app/modules/roxywi/class_models.py:16-30) is the centralised Pydantic validator used on

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-45565

Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. In versions 8.2.6.4 and prior, EscapedString (app/modules/roxywi/class_models.py:16-30) is the centralised Pydantic validator used on dozens of fields including SSH credential name, username, description, etc. Its if/elif/elif/else flow returns the metacharacter-stripped value without also enforcing the .. block. An attacker who appends a single ;, &, |, $, or backtick to a .. payload route CVSSv3.1 8.1 (HIGH)

CWECWE 22CWECWE 20CWECWE 117VNDRoxyTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-06-10
2026-06-10 16:00Z
HIGH

Oops, I Weaponized the Database: Abusing AI Features in SQL Server 2025

SpecterOps·specterops.io

SpecterOps research demonstrates weaponization of native AI features in SQL Server 2025 (sp_invoke_external_rest_endpoint, CREATE EXTERNAL MODEL, AI_GENERATE_EMBEDDINGS) for data exfiltration, NTLM coercion, and C2 transport. The research includes proof-of-concept implementations ranging from simple database dumping to a production-grade CLR-based agent that disguises command-and-control traffic as embedding API calls, all executable from within the database engine with sysadmin privileges.

SRFApplicationTACTA0002TACTA0011SWSql ServerVNDMicrosoftTYPResearchSTGExecutionSTGExfil
88
Edit Score
2026-06-10
2026-06-10 15:16Z
CRIT

CVE-2026-53476 — An unauthenticated attacker, located on the same local area network (LAN), can exploit a

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-53476

A flaw was found in assisted-migration-agent. An unauthenticated attacker, located on the same local area network (LAN), can exploit a path traversal vulnerability. By crafting a specially designed gzipped tarball, the attacker can bypass security checks and write arbitrary files to the system. This could ultimately lead to the execution of unauthorized code on the appliance. CVSSv3.1 9.6 (CRITICAL)

CWECWE 59TYPVulnerability
9.6
CVSS v3.1
98
Edit Score
728 × 90 / responsive · programmatic ad slot
2026-06-10
2026-06-10 15:16Z
CRIT

CVE-2026-53475 — This vulnerability allows a Man-in-the-Middle (MITM) attacker to intercept and harvest vCenter administrator credentials.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-53475

A flaw was found in assisted-migration-agent. The application hardcodes insecure Transport Layer Security (TLS) connections when communicating with vCenter. This vulnerability allows a Man-in-the-Middle (MITM) attacker to intercept and harvest vCenter administrator credentials. This can lead to unauthorized access to vCenter. CVSSv3.1 9.3 (CRITICAL)

CWECWE 295TYPVulnerability
9.3
CVSS v3.1
97
Edit Score
2026-06-10
2026-06-10 15:16Z
CRIT

CVE-2026-53474 — This SQL Injection allows for arbitrary file reading on the system, potentially exposing sensitive

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-53474

A flaw was found in migration-planner. A remote authenticated attacker could exploit this vulnerability by uploading a specially crafted RVTools .xlsx file. Due to improper input sanitization, malicious SQL embedded within a spreadsheet cell is executed when cluster names are processed. This SQL Injection allows for arbitrary file reading on the system, potentially exposing sensitive information such as Kubernetes service account tokens and other credentials, which could lead CVSSv3.1 9.6 (CRITICAL)

CWECWE 89TYPVulnerability
9.6
CVSS v3.1
98
Edit Score
2026-06-10
2026-06-10 15:16Z
CRIT

CVE-2026-53471 — This oversight allows an authenticated attacker with a valid agent token to manipulate data

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-53471

A flaw was found in migration-planner. The agent-API middleware processes JSON Web Tokens (JWTs) for authentication, but its UpdateSourceInventory and UpdateAgentStatus handlers fail to validate the source_id claim within these tokens against the requested source ID. This oversight allows an authenticated attacker with a valid agent token to manipulate data across different tenants, leading to a complete collapse of tenant isolation. This could result in unauthorized overwrit CVSSv3.1 9.6 (CRITICAL)

CWECWE 639TYPVulnerability
9.6
CVSS v3.1
98
Edit Score
2026-06-10
2026-06-10 15:16Z
CRIT

CVE-2026-53470 — This flaw allows the attacker to bypass an ownership check and obtain presigned S3

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-53470

A flaw was found in migration-planner. An authenticated attacker could exploit an improper access control vulnerability in the `/api/v1/sources/{id}/image-url` endpoint. This flaw allows the attacker to bypass an ownership check and obtain presigned S3 URLs for Open Virtual Appliance (OVA) images belonging to other users. Consequently, the attacker can download OVA images containing sensitive information, such as long-lived agent JSON Web Tokens (JWTs) and source configuratio CVSSv3.1 9.6 (CRITICAL)

CWECWE 639TYPVulnerability
9.6
CVSS v3.1
98
Edit Score
2026-06-10
2026-06-10 15:16Z
CRIT

CVE-2026-53469 — This allows for the destruction of all customer data, including sources, agents, and assessments

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-53469

A flaw was found in migration-planner. An authenticated user can exploit this vulnerability by sending a DELETE request to the /api/v1/sources route, which lacks proper authorization and filtering. This allows for the destruction of all customer data, including sources, agents, and assessments, leading to a critical loss of availability and integrity across the entire SaaS platform. CVSSv3.1 9.1 (CRITICAL)

CWECWE 306TYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2026-06-10
2026-06-10 15:16Z
HIGH

CVE-2026-45564 — Roxy: An authenticated user with role <= 3 ("user") therefore reaches a bin/sh -c command-injection

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-45564

Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. In versions 8.2.6.4 and prior, POST /config/versions/<service>/<server_ip>/<configver>/save interpolates the URL-path configver parameter directly into a config-version path that ends up at os.system(f"dos2unix -q {cfg}"). configver is not run through EscapedString (Pydantic doesn't validate path segments declared as str) and the surrounding .. block is the broken tuple-membership patch fro CVSSv3.1 8.8 (HIGH)

CWECWE 78VNDRoxyTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-06-10
2026-06-10 15:16Z
CRIT

CVE-2026-45558 — Roxy: Because Roxy-WI then pushes the generated config to the load balancer and runs systemctl

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-45558

Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. In versions 8.2.6.4 and prior, the HAProxy section-save endpoints (POST /api/service/haproxy/<server_id>/section/<section_type> and the PUT / global / defaults variants) accept a JSON option field that is not validated, not escaped, and is rendered verbatim into the generated HAProxy configuration via the section.j2, global.j2, and defaults.j2 Ansible templates. Because Roxy-WI then pushes CVSSv3.1 9.9 (CRITICAL)

CWECWE 94CWECWE 77CWECWE 20CWECWE 78VNDRoxyTYPVulnerability
9.9
CVSS v3.1
100
Edit Score
2026-06-10
2026-06-10 15:16Z
CRIT

CVE-2026-45556 — Roxy: The validation chain (_replace_config_path_to_correct → check_is_conf) only requires the path to contain a hard-coded

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-45556

Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. In versions 8.2.6.4 and prior, POST /waf/<service>/<server_ip>/rule/<rule_id>/save accepts a config_file_name form field that is passed straight through to config_mod.master_slave_upload_and_restart(...) as the destination path. The validation chain (_replace_config_path_to_correct → check_is_conf) only requires the path to contain a hard-coded service substring (nginx/haproxy/apache2/httpd CVSSv3.1 9.9 (CRITICAL)

CWECWE 22CWECWE 73CWECWE 20CWECWE 78VNDRoxyTYPVulnerability
9.9
CVSS v3.1
100
Edit Score
2026-06-10
2026-06-10 15:16Z
CRIT

CVE-2026-45552 — Roxy: In versions 8.2.6.4 and prior, the install blueprint declares only bp.before_request → @jwt_required() (app/routes/install/routes.py:36-39).

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-45552

Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. In versions 8.2.6.4 and prior, the install blueprint declares only bp.before_request → @jwt_required() (app/routes/install/routes.py:36-39). The individual endpoints install_exporter, install_waf, install_geoip, check_geoip, get_exporter_version, and get_task_status are not wrapped in page_for_admin and do not call roxywi_common.is_user_has_access_to_its_group(server_ip) or check_is_server_ CVSSv3.1 9.9 (CRITICAL)

CWECWE 862CWECWE 639CWECWE 863VNDRoxyTYPVulnerability
9.9
CVSS v3.1
100
Edit Score
2026-06-10
2026-06-10 15:16Z
CRIT

CVE-2026-45550 — Roxy: In versions 8.2.6.4 and prior, PUT /smon/check (app/routes/smon/routes.py:117-138) gates only on roxywi_common.check_user_group_for_flask() — which

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-45550

Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. In versions 8.2.6.4 and prior, PUT /smon/check (app/routes/smon/routes.py:117-138) gates only on roxywi_common.check_user_group_for_flask() — which validates that the caller has some group, not that the target check_id belongs to it. The downstream SQL update functions update_smon, update_smonHttp, update_smonTcp, update_smonPing, update_smonDns (app/modules/db/smon.py:515-562) all execute CVSSv3.1 9.1 (CRITICAL)

CWECWE 862CWECWE 639CWECWE 863VNDRoxyTYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2026-06-10
2026-06-10 15:16Z
HIGH

CVE-2026-45549 — Roxy: In versions 8.2.6.4 and prior, agent_action (app/routes/smon/agent_routes.py:166-179) has decorators @bp.post('/agent/action/<action>') and @jwt_required() only —

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-45549

Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. In versions 8.2.6.4 and prior, agent_action (app/routes/smon/agent_routes.py:166-179) has decorators @bp.post('/agent/action/<action>') and @jwt_required() only — no role check, no group ownership check on the server_ip form field. Any authenticated user, including role 4 (guest), can start, stop, or restart the roxy-wi-smon-agent systemd unit on any server they can name. Roxy-WI executes t CVSSv3.1 8.5 (HIGH)

CWECWE 862CWECWE 863VNDRoxyTYPVulnerability
8.5
CVSS v3.1
93
Edit Score
2026-06-10
2026-06-10 14:16Z
HIGH

CVE-2026-53435 — Jenkins: In Jenkins 2.567 and earlier, LTS 2.555.2 and earlier, it is possible for attackers

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-53435

In Jenkins 2.567 and earlier, LTS 2.555.2 and earlier, it is possible for attackers to have Jenkins deserialize arbitrary types defined in Jenkins core or plugins from an attacker-controlled `config.xml` submission in a way that allows them to handle HTTP requests afterwards. This can be used to impersonate any user and send HTTP requests on their behalf, up to and including use of the Script Console to run arbitrary code, or to read arbitrary files from the Jenkins controlle CVSSv3.1 8.8 (HIGH)

CWECWE 502VNDJenkinsTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-06-10
2026-06-10 14:16Z
HIGH

CVE-2026-52758 — Ghidra: before 12.1 contains a SQL injection vulnerability in BSim filter types that concatenate

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-52758

Ghidra before 12.1 contains a SQL injection vulnerability in BSim filter types that concatenate user-supplied values directly into SQL queries without escaping or parameterization. Remote attackers can inject arbitrary SQL via the BSim network query protocol to read, modify, or delete data in the PostgreSQL database. CVSSv3.1 8.8 (HIGH)

CWECWE 89VNDGhidraTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-06-10
2026-06-10 14:16Z
HIGH

CVE-2026-52754 — Ghidra: before 12.1 contains an authentication bypass vulnerability in PKIAuthenticationModule.authenticate() that allows any user

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-52754

Ghidra before 12.1 contains an authentication bypass vulnerability in PKIAuthenticationModule.authenticate() that allows any user with a valid CA-signed certificate to impersonate other users by presenting their public certificate with a null signature. Attackers can escalate privileges, modify repository access controls, exfiltrate shared reverse engineering databases, and permanently compromise server integrity. CVSSv3.1 8.8 (HIGH)

CWECWE 347VNDGhidraTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-06-10
2026-06-10 14:16Z
HIGH

CVE-2026-52751 — Ghidra: before 12.1 contains an unsafe deserialization vulnerability in client-side Shared-Project RMI connection code

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-52751

Ghidra before 12.1 contains an unsafe deserialization vulnerability in client-side Shared-Project RMI connection code that allows unauthenticated remote code execution. Attackers can craft a malicious project file with a ghidra:// URL that, when opened via File → Open Project, deserializes untrusted objects using a Jython 2.7.4 gadget chain to execute arbitrary commands. CVSSv3.1 8.8 (HIGH)

CWECWE 502VNDGhidraTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-06-10
2026-06-10 14:16Z
HIGH

CVE-2026-49498 — Ghidra: 11.0 before 12.1 contains a SQL injection vulnerability in the changePassword() method of

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-49498

Ghidra 11.0 before 12.1 contains a SQL injection vulnerability in the changePassword() method of PostgresFunctionDatabase that fails to escape double quotes in usernames interpolated into ALTER ROLE statements. Authenticated attackers can inject SQL commands via crafted username parameters in PasswordChange network messages to escalate to PostgreSQL superuser privileges and gain full database control. CVSSv3.1 8.8 (HIGH)

CWECWE 89VNDGhidraTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-06-10
2026-06-10 12:16Z
HIGH

CVE-2026-24067 — Slate: This PID-based client validation is subject to a time-of-check time-of-use race condition because process

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-24067

Slate Digital Connect 1.37.0 for macOS installs a privileged helper tool, com.slatedigital.connect.privileged.helper.tool, which exposes the XPC service com.slatedigital.connect.privileged.helper.tool2. The helper validates connecting XPC clients by obtaining the client's process identifier and using it to retrieve code-signing information for the process. This PID-based client validation is subject to a time-of-check time-of-use race condition because process identifiers can CVSSv3.1 8.4 (HIGH)

CWECWE 367VNDSlateTYPVulnerability
8.4
CVSS v3.1
92
Edit Score
2026-06-10
2026-06-10 12:16Z
HIGH

CVE-2026-24066 — Slate: This allows unauthorized access to privileged helper functionality and may lead to local privilege

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-24066

Slate Digital Connect 1.37.0 for macOS installs a privileged helper tool, com.slatedigital.connect.privileged.helper.tool, which exposes the XPC service com.slatedigital.connect.privileged.helper.tool2. The helper validates connecting XPC clients by checking only the subject.OU value of the client's signing certificate and does not verify that the certificate chains to a trusted code-signing authority. A local attacker can sign a malicious client with a self-signed certificat CVSSv3.1 8.4 (HIGH)

CWECWE 296VNDSlateTYPVulnerability
8.4
CVSS v3.1
92
Edit Score