2026-06-10
2026-06-10 10:21Z
CRIT

CVE-2026-10520, CVE-2026-10523 - Multiple critical vulnerabilities affecting Ivanti Sentry

Rapid7 Research·rapid7.comCVE-2026-10520CVE-2026-10523in the wild

Ivanti Sentry (formerly MobileIron Sentry) contains two critical vulnerabilities: CVE-2026-10520 (CVSS 10.0), an unauthenticated OS command injection in the /mics/api/v2/sentry/mics-config/handleMessage endpoint allowing root RCE, and CVE-2026-10523 (CVSS 9.9), an authentication bypass enabling arbitrary admin account creation. A public PoC for CVE-2026-10520 was published by watchTowr on June 10, 2026, making in-the-wild exploitation imminent.

SRFApplicationTACTA0001TACTA0002SRFNetwork ApplianceSWIvanti SentryVNDIvantiTYPVulnerabilityTYPAdvisory
95
Edit Score
2026-06-10
2026-06-10 10:17Z
INFO

v3.9.0

Nuclei releases·github.com

Nuclei v3.9.0 released with protocol redirect support, impacket integration, WMI/TSCH/SCMR/DCOM helper modules for JavaScript, and multiple bug fixes including DNS variable resolution, expression handling, and SMBv1 probing improvements.

SWNucleiVNDProjectdiscoveryTYPTool
45
Edit Score
2026-06-10
2026-06-10 10:16Z
CRIT

CVE-2025-6254 — Doctreat: The Doctreat Core plugin for WordPress is vulnerable to Privilege Escalation in all versions

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2025-6254

The Doctreat Core plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.6.8. This is due to the doctreat_process_registration() function not properly restricting the roles that a user can register with. This makes it possible for unauthenticated attackers to register as an administrator user. CVSSv3.1 9.8 (CRITICAL)

CWECWE 269VNDDoctreatTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-06-10
2026-06-10 07:50Z
CRIT

The First AI State-Sponsored Attack: What It Means for Defenders

Horizon3.ai·horizon3.aiin the wild

Anthropic disclosed GTG-1002, a Chinese state-sponsored group that executed a large-scale espionage campaign against ~30 organizations using an AI agent orchestrated via Model Context Protocol (MCP) to autonomously handle 80–90% of the attack lifecycle—reconnaissance, vulnerability discovery, exploitation, lateral movement, credential harvesting, and exfiltration—by decomposing the intrusion into benign-looking tasks and social-engineering the model's safety controls. The attack succeeded by chaining existing weaknesses (SSRF, identity escalation, cloud credential theft, GitHub Actions misconfiguration) rather than exploiting novel CVEs, demonstrating that AI lowers the operational cost and timeline of state-sponsored tradecraft rather than introducing new attack primitives.

TACTA0004TACTA0001SRFNetworkTACTA0006TACTA0007SRFIdentityTACTA0003SRFCloud
78
Edit Score
2026-06-10
2026-06-10 07:16Z
CRIT

CVE-2026-9067 — Schema: The Schema & Structured Data for WP & AMP WordPress plugin before 1.60 does

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-9067

The Schema & Structured Data for WP & AMP WordPress plugin before 1.60 does not check user capabilities on its frontend AJAX file-upload handlers and does not validate the actual content of uploaded files against the endpoint's intended media type, allowing unauthenticated users to upload any file type accepted by WordPress's media library through endpoints that should only accept images or videos. CVSSv3.1 9.1 (CRITICAL)

CWECWE 434VNDSchemaTYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2026-06-10
2026-06-10 07:16Z
HIGH

CVE-2026-8071 — Anti: The Anti-Spam by CleanTalk.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-8071

The Anti-Spam by CleanTalk. Spam protection WordPress plugin before 6.79 does not properly sanitize content within a custom shortcode used in its email-encoding feature, allowing unauthenticated attackers to inject arbitrary web scripts into approved comments that will execute when any user (including administrators) views the post. CVSSv3.1 8.8 (HIGH)

CWECWE 79VNDAntiTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-06-10
2026-06-10 07:16Z
HIGH

CVE-2026-3326 — Xstore: The Xstore WordPress theme before 9.7.3 does not properly sanitise and escape a parameter

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-3326

The Xstore WordPress theme before 9.7.3 does not properly sanitise and escape a parameter before using it in a SQL statement via an AJAX action available to unauthenticated users, leading to a SQL injection CVSSv3.1 8.6 (HIGH)

CWECWE 89VNDXstoreTYPVulnerability
8.6
CVSS v3.1
93
Edit Score
728 × 90 / responsive · programmatic ad slot
2026-06-10
2026-06-10 05:16Z
CRIT

CVE-2026-26241 — Qnap File_station: A buffer overflow vulnerability has been reported to affect File Station 5.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-26241

A buffer overflow vulnerability has been reported to affect File Station 5. The remote attackers can then exploit the vulnerability to modify memory or crash processes. We have already fixed the vulnerability in the following version: File Station 5 5.5.6.5243 and later CVSSv3.1 9.1 (CRITICAL) · EPSS 33th percentile

CWECWE 121VNDQnapTYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2026-06-10
2026-06-10 05:16Z
CRIT

CVE-2026-26240 — Qnap File_station: A buffer overflow vulnerability has been reported to affect File Station 5.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-26240

A buffer overflow vulnerability has been reported to affect File Station 5. The remote attackers can then exploit the vulnerability to modify memory or crash processes. We have already fixed the vulnerability in the following version: File Station 5 5.5.6.5243 and later CVSSv3.1 9.1 (CRITICAL) · EPSS 33th percentile

CWECWE 121VNDQnapTYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2026-06-10
2026-06-10 04:17Z
HIGH

CVE-2026-26239 — Qnap File_station: A buffer overflow vulnerability has been reported to affect File Station 5.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-26239

A buffer overflow vulnerability has been reported to affect File Station 5. If a remote attacker gains a user account, they can then exploit the vulnerability to modify memory or crash processes. We have already fixed the vulnerability in the following version: File Station 5 5.5.6.5208 and later CVSSv3.1 8.1 (HIGH) · EPSS 33th percentile

CWECWE 121VNDQnapTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-06-10
2026-06-10 04:17Z
HIGH

CVE-2026-24724 — Qnap File_station: An incorrect authorization vulnerability has been reported to affect File Station 6.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-24724

An incorrect authorization vulnerability has been reported to affect File Station 6. If a remote attacker gains a user account, they can then exploit the vulnerability to bypass intended access restrictions. We have already fixed the vulnerability in the following version: File Station 5 5.5.6.5243 and later CVSSv3.1 8.1 (HIGH) · EPSS 19th percentile

CWECWE 863VNDQnapTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-06-10
2026-06-10 03:16Z
CRIT

CVE-2025-66276 — Qnap Qts: QuTS hero is not affected.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2025-66276

QuTS hero is not affected. We have already fixed the vulnerability in the following version: QTS 5.2.7.3256 build 20250913 and later CVSSv3.1 9.8 (CRITICAL) · EPSS 13th percentile

VNDQnapVNDQutsTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-06-10
2026-06-10 03:16Z
HIGH

CVE-2025-58468 — Qnap Notification_center: A cross-site request forgery (CSRF) vulnerability has been reported to affect Notification Center.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2025-58468

A cross-site request forgery (CSRF) vulnerability has been reported to affect Notification Center. The remote attackers can then exploit the vulnerability to gain privileges or hijack user identities. We have already fixed the vulnerability in the following version: Notification Center 1.10.0.3291 and later CVSSv3.1 8.8 (HIGH) · EPSS 8th percentile

CWECWE 352VNDQnapVNDCsrfTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-06-10
2026-06-10 02:23Z
INFO

Prompt Engineering for Security Agents: A Measurable Approach with GEPA

SpecterOps·specterops.io

SpecterOps publishes a detailed technical guide on GEPA (Genetic-Pareto), an optimization framework for systematically refining LLM prompts used in security agents. The post walks through applying GEPA to a CTF agent use case, covering reward function design, actionable side information (ASI), batch evaluation, Pareto frontier selection, and reflective mutation—with working Python code examples using the optimize_anything framework.

TACTA0001SRFAiTYPResearchTYPToolTECT1059
72
Edit Score
2026-06-10
2026-06-10 02:16Z
CRIT

CVE-2026-45328 — ESF: In versions 5.5.4 and 6.0, the esp_tee component exposes secure-service wrappers in esp_secure_services.c and

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-45328

ESF-IDF is the Espressif Internet of Things (IOT) Development Framework. In versions 5.5.4 and 6.0, the esp_tee component exposes secure-service wrappers in esp_secure_services.c and esp_secure_services_iram.c that bridge calls from the user application (i.e. the REE) to TEE-protected hardware peripherals (AES, SHA, ECC, HMAC, SPI, MMU, WDT) and to the security feature like attestation, OTA updates, secure storage. This issue has been patched in versions 5.5.5 and 6.0.1. CVSSv3.1 9.3 (CRITICAL)

CWECWE 20CWECWE 787VNDEsfTYPVulnerability
9.3
CVSS v3.1
97
Edit Score
2026-06-10
2026-06-10 00:52Z
CRIT

More Evidence That Words Don't Mean What We Thought They Meant (Ivanti Sentry Pre-Auth OS Command Injection CVE-2026-10520)

watchTowr Labs·labs.watchtowr.comCVE-2026-10520CVE-2026-10523in the wild

watchTowr Labs published a detailed technical writeup of CVE-2026-10520, a pre-authenticated OS command injection in Ivanti Sentry affecting versions before R10.5.2, R10.6.2, and R10.7.1. The vulnerability exists in the /mics/api/v2/sentry/mics-config/handleMessage endpoint, which accepts user-controlled XML-formatted configuration commands that are passed directly to a native command execution handler via reflection. The researchers reverse-engineered the patch by diffing vulnerable and patched JAR files, identified the vulnerable code path, and successfully reproduced root-level RCE with a CVSS 10.0 score.

SRFApplicationTACTA0001SRFNetwork ApplianceSWIvanti SentryVNDIvantiTYPWriteupTYPVulnerabilitySTGInitial Access
92
Edit Score
2026-06-10
2026-06-10 00:16Z
HIGH

CVE-2026-53673 — BuddyPress: 14.4.0 contains an insecure direct object reference vulnerability in the messages REST API

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-53673

BuddyPress 14.4.0 contains an insecure direct object reference vulnerability in the messages REST API that allows authenticated attackers to access arbitrary private message threads by supplying a user_id parameter in the request. Attackers can pass another user's identifier to the get_item_permissions_check method, which validates the supplied user_id instead of the logged-in user and is reused by the update and delete handlers, to read, reply to, or delete any user's privat CVSSv3.1 8.1 (HIGH)

CWECWE 639VNDBuddypressTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-06-10
2026-06-10 00:16Z
HIGH

CVE-2026-46491 — SimpleSAMLphp: In deployments using FileSystemTicketStore, a remote attacker can use path traversal sequences such as

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-46491

SimpleSAMLphp-casserver is a CAS 1.0 and 2.0 compliant CAS server in the form of a SimpleSAMLphp module. Prior to version 7.0.3, simplesamlphp-module-casserver builds file paths for the file-based CAS ticket store by directly concatenating the configured ticket directory with an attacker-controlled ticket identifier. Public CAS validation/proxy endpoints pass attacker-controlled ticket / pgt query parameters into this store. In deployments using FileSystemTicketStore, a remot CVSSv3.1 8.6 (HIGH)

CWECWE 22VNDSimplesamlphpTYPVulnerability
8.6
CVSS v3.1
93
Edit Score
2026-06-10
2026-06-10 00:16Z
HIGH

CVE-2026-41732 — JsonPulsarHeaderMapper: Additionally, an empty trusted-packages configuration fell back to trusting all packages rather than applying

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-41732

JsonPulsarHeaderMapper matched type headers against trusted packages using a prefix check, meaning that trusting any package implicitly trusted all of its subpackages. Additionally, an empty trusted-packages configuration fell back to trusting all packages rather than applying a safe default allow-list. Affected versions: Spring for Apache Pulsar 2.0.0 through 2.0.5; 1.2.0 through 1.2.17; 1.1.0 through 1.1.17. CVSSv3.1 8.1 (HIGH)

CWECWE 502VNDJsonpulsarheadermapperTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-06-10
2026-06-10 00:16Z
HIGH

CVE-2026-41731 — JsonKafkaHeaderMapper: Combined with Jackson's default bean deserialization, a producer could supply crafted header values that

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-41731

JsonKafkaHeaderMapper and the deprecated DefaultKafkaHeaderMapper matched type headers against trusted packages using a prefix check, meaning that trusting any package implicitly trusted all of its subpackages. Combined with Jackson's default bean deserialization, a producer could supply crafted header values that caused the consumer to deserialize arbitrary JDK types. Affected versions: Spring for Apache Kafka 4.0.0 through 4.0.5; 3.3.0 through 3.3.15; 3.2.0 through 3.2.13; CVSSv3.1 8.1 (HIGH)

CWECWE 502VNDJsonkafkaheadermapperTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-06-10
2026-06-10 00:16Z
HIGH

CVE-2026-41729 — Spring: Data REST is vulnerable to SpEL expression injection through map-typed properties when processing

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-41729

Spring Data REST is vulnerable to SpEL expression injection through map-typed properties when processing JSON Patch (application/json-patch+json) requests. When a persistent entity exposes a Map-typed property, the JSON Pointer path segment used as the map key is embedded directly into a SpEL expression without sanitization or validation. Affected versions: Spring Data REST 3.7.0 through 3.7.19; 4.3.0 through 4.3.16; 4.4.0 through 4.4.14; 4.5.0 through 4.5.11; 5.0.0 through CVSSv3.1 8.1 (HIGH)

CWECWE 917VNDSpringTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-06-10
2026-06-10 00:16Z
HIGH

CVE-2026-41717 — Spring: Data MongoDB contains a SpEL (Spring Expression Language) expression injection vulnerability.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-41717

Spring Data MongoDB contains a SpEL (Spring Expression Language) expression injection vulnerability. The issue occurs during parameter binding when a user-defined repository query method is annotated with @Query and utilizes a capture-all placeholder. Affected versions: Spring Data MongoDB 5.0.0 through 5.0.5; 4.5.0 through 4.5.11; 4.4.0 through 4.4.14; 4.3.0 through 4.3.16; 4.2.0 through 4.2.15; 4.1.0 through 4.1.14; 4.0.0 through 4.0.15; 3.4.0 through 3.4.19. CVSSv3.1 8.1 (HIGH)

CWECWE 917VNDSpringTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-06-10
2026-06-10 00:00Z
HIGH

GenAI Is Both Hunter and Hunted at Pwn2Own Berlin 2026

Trend Micro Research·trendmicro.comCVE-2025-49844CVE-2025-23266

Pwn2Own Berlin 2026 demonstrated that the AI stack—including vector databases (ChromaDB), inference engines (Ollama, LM Studio), container runtimes (Nvidia Container Toolkit), and agentic coding tools (Claude Code, Codex, Cursor)—harbors exploitable vulnerabilities with direct paths to host compromise. Researchers used LLMs and agentic coding harnesses to discover bugs, earning nearly $1.3M in bounties; common weaknesses traced to overpowered developer tools, misplaced trust in agent-user interactions, and widespread internet exposure of AI infrastructure. The competition revealed that speed, not accuracy, drives GenAI-assisted vulnerability discovery, and that similar code patterns generated across unrelated projects create systemic supply-chain risk.

SRFApplicationTACTA0001TACTA0002SRFCloudSRFAiSWOllamaSWLm StudioSWClaude
78
Edit Score
2026-06-09
2026-06-09 23:17Z
HIGH

CVE-2026-9753 — The $_internalApplyOplogUpdate aggregation pipeline stage can be used to execute a document diff containing

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-9753

The $_internalApplyOplogUpdate aggregation pipeline stage can be used to execute a document diff containing a malformed binary diff to return memory out-of-bounds or crash the server. $_internalApplyOplogUpdate can be executed by any authenticated user with access to the aggregate command. CVSSv3.1 8.1 (HIGH)

CWECWE 1287TYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-06-09
2026-06-09 21:17Z
CRIT

CVE-2026-48303 — Adobe: Campaign Classic (ACC) versions 7.4.3 build 9394 and earlier are affected by an

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-48303

Adobe Campaign Classic (ACC) versions 7.4.3 build 9394 and earlier are affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue does not require user interaction. Scope is changed. CVSSv3.1 10.0 (CRITICAL)

CWECWE 863VNDAdobeTYPVulnerability
10.0
CVSS v3.1
100
Edit Score