2026-06-08
2026-06-08 17:05Z
CRIT

Critical Check Point VPN Zero-Day Exploited in the Wild (CVE-2026-50751)

Rapid7 Research·rapid7.comCVE-2026-50751CVE-2026-50752in the wild0day

Check Point disclosed CVE-2026-50751, a critical authentication bypass (CVSS 9.3) in Remote Access VPN, Mobile Access, and Spark Firewall products affecting IKEv1 deployments without machine certificate requirements. The vulnerability is actively exploited in the wild since May 7, 2026, with confirmed ties to Qilin ransomware affiliates across several dozen organizations. A related MITM vulnerability (CVE-2026-50752, CVSS 7.4) was also identified but remains unexploited.

TACTA0001SRFNetworkSRFNetwork ApplianceSWCheck Point Mobile AccessSWCheck Point Remote Access VpnSWCheck Point Spark FirewallVNDCheckpointTYPVulnerability
92
Edit Score
2026-06-08
2026-06-08 16:36Z
INFO

v2.12.2-rc1

AzureHound releases·github.com

AzureHound v2.12.2-rc1 release candidate published with minor maintenance updates: semver compliance fix for rolling build version string, GitHub Actions workflow updates, removal of unnecessary credentials from build process, and migration to Node.js 24 for DigiCert signing.

SWAzurehoundVNDSpecteropsTYPTool
15
Edit Score
2026-06-08
2026-06-08 16:16Z
HIGH

CVE-2026-49975 — Apache Http_server: Memory Allocation with Excessive Size Value vulnerability in Apache HTTP Server's mod_http leads to

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-49975

Memory Allocation with Excessive Size Value vulnerability in Apache HTTP Server's mod_http leads to denial of service via malicious HTTP requests. This issue affects Apache HTTP Server: from 2.4.17 through 2.4.67. CVSSv3.1 7.5 (HIGH) · EPSS 95th percentile

CWECWE 789VNDApacheTYPVulnerability
7.5
CVSS v3.1
91
Edit Score
2026-06-08
2026-06-08 16:16Z
HIGH

CVE-2026-46656 — Bludit: This "Ghost Session" allows revoked users to maintain full unauthorized access to the system.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-46656

Bludit is a content management system. Versions prior to 3.22.0 have a Broken Access Control flaw where active sessions remain valid even after the corresponding user account has been physically deleted from the database. This "Ghost Session" allows revoked users to maintain full unauthorized access to the system. Version 3.22.0 fixes the issue. CVSSv3.1 8.8 (HIGH)

CWECWE 285CWECWE 613VNDBluditTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-06-08
2026-06-08 16:16Z
HIGH

CVE-2026-46480 — Flowiseai Flowise: Prior to version 3.1.2, evaluator create and update mass-assignment allows cross-workspace evaluator takeover.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-46480

Flowise is a drag & drop user interface to build a customized large language model flow. Prior to version 3.1.2, evaluator create and update mass-assignment allows cross-workspace evaluator takeover. This issue has been patched in version 3.1.2. CVSSv3.1 8.8 (HIGH)

CWECWE 915VNDFlowiseaiVNDFlowiseTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-06-08
2026-06-08 16:16Z
HIGH

CVE-2026-46479 — Flowiseai Flowise: Prior to version 3.1.2, evaluation create and update mass-assignment allows cross-workspace evaluation takeover.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-46479

Flowise is a drag & drop user interface to build a customized large language model flow. Prior to version 3.1.2, evaluation create and update mass-assignment allows cross-workspace evaluation takeover. This issue has been patched in version 3.1.2. CVSSv3.1 8.8 (HIGH) · EPSS 19th percentile

CWECWE 915VNDFlowiseaiVNDFlowiseTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-06-08
2026-06-08 16:16Z
HIGH

CVE-2026-46478 — Flowiseai Flowise: Prior to version 3.1.2, DatasetRow create and update mass-assignment allows cross-workspace row takeover.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-46478

Flowise is a drag & drop user interface to build a customized large language model flow. Prior to version 3.1.2, DatasetRow create and update mass-assignment allows cross-workspace row takeover. This issue has been patched in version 3.1.2. CVSSv3.1 8.8 (HIGH) · EPSS 19th percentile

CWECWE 915VNDFlowiseaiVNDFlowiseTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
728 × 90 / responsive · programmatic ad slot
2026-06-08
2026-06-08 16:16Z
HIGH

CVE-2026-46477 — Flowiseai Flowise: Prior to version 3.1.2, dataset create and update mass-assignment allows cross-workspace dataset takeover.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-46477

Flowise is a drag & drop user interface to build a customized large language model flow. Prior to version 3.1.2, dataset create and update mass-assignment allows cross-workspace dataset takeover. This issue has been patched in version 3.1.2. CVSSv3.1 8.8 (HIGH) · EPSS 19th percentile

CWECWE 915VNDFlowiseaiVNDFlowiseTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-06-08
2026-06-08 16:16Z
HIGH

CVE-2026-46476 — Flowiseai Flowise: Prior to version 3.1.2, CustomTemplate create and update mass-assignment allows cross-workspace template takeover.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-46476

Flowise is a drag & drop user interface to build a customized large language model flow. Prior to version 3.1.2, CustomTemplate create and update mass-assignment allows cross-workspace template takeover. This issue has been patched in version 3.1.2. CVSSv3.1 8.8 (HIGH) · EPSS 19th percentile

CWECWE 915VNDFlowiseaiVNDFlowiseTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-06-08
2026-06-08 16:16Z
HIGH

CVE-2026-46475 — Flowiseai Flowise: Prior to version 3.1.2, assistant create and update mass-assignment allows cross-workspace assistant takeover.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-46475

Flowise is a drag & drop user interface to build a customized large language model flow. Prior to version 3.1.2, assistant create and update mass-assignment allows cross-workspace assistant takeover. This issue has been patched in version 3.1.2. CVSSv3.1 8.8 (HIGH) · EPSS 17th percentile

CWECWE 915VNDFlowiseaiVNDFlowiseTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-06-08
2026-06-08 16:16Z
HIGH

CVE-2026-46444 — Flowiseai Flowise: Prior to version 3.1.2, all CRUD endpoints for OpenAI Assistants Vector Store have no

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-46444

Flowise is a drag & drop user interface to build a customized large language model flow. Prior to version 3.1.2, all CRUD endpoints for OpenAI Assistants Vector Store have no authentication middleware and the route path /api/v1/openai-assistants-vector-store is not in WHITELIST_URLS. However, it is also not protected by the main auth middleware when accessed via API key — the route requires API key auth (not whitelisted), but no permission checks exist on any operation. This CVSSv3.1 8.8 (HIGH) · EPSS 24th percentile

CWECWE 862VNDFlowiseaiVNDFlowiseTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-06-08
2026-06-08 16:16Z
CRIT

CVE-2026-46442 — Flowiseai Flowise: The result is authenticated remote code execution on the Flowise server host.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-46442

Flowise is a drag & drop user interface to build a customized large language model flow. Prior to version 3.1.2, POST /api/v1/node-custom-function lacks route-level authorization, allowing any authenticated user or API key to submit arbitrary JavaScript to the Custom JS Function node. When E2B_APIKEY is not configured — the common deployment case — Flowise executes this code inside a NodeVM sandbox. This sandbox can be escaped, allowing an attacker to reach the host process o CVSSv3.1 9.9 (CRITICAL) · EPSS 57th percentile

CWECWE 94VNDFlowiseaiVNDFlowiseTYPVulnerability
9.9
CVSS v3.1
100
Edit Score
2026-06-08
2026-06-08 16:16Z
CRIT

CVE-2026-46441 — Flowiseai Flowise: The endpoint allows authenticated users to modify server-controlled properties such as workspaceId, createdDate, and

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-46441

Flowise is a drag & drop user interface to build a customized large language model flow. Prior to version 3.1.2, a mass assignment vulnerability exists in the assistant update endpoint of FlowiseAI. The endpoint allows authenticated users to modify server-controlled properties such as workspaceId, createdDate, and updatedDate when updating an assistant resource. Due to missing server-side validation and authorization checks, an attacker can manipulate the workspaceId field an CVSSv3.1 9.6 (CRITICAL) · EPSS 15th percentile

CWECWE 639CWECWE 284CWECWE 915VNDFlowiseaiVNDFlowiseTYPVulnerability
9.6
CVSS v3.1
98
Edit Score
2026-06-08
2026-06-08 16:16Z
CRIT

CVE-2026-46440 — Flowiseai Flowise: Prior to version 3.1.2, the checkBasicAuth endpoint validates credentials in plaintext without rate limiting

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-46440

Flowise is a drag & drop user interface to build a customized large language model flow. Prior to version 3.1.2, the checkBasicAuth endpoint validates credentials in plaintext without rate limiting and with direct comparison. This issue has been patched in version 3.1.2. CVSSv3.1 9.1 (CRITICAL) · EPSS 13th percentile

CWECWE 522VNDFlowiseaiVNDFlowiseTYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2026-06-08
2026-06-08 16:16Z
CRIT

CVE-2026-44631 — Buffer: Underwrite vulnerability in Apache HTTP Server on crafted regular expressions in the configuration.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-44631

Buffer Underwrite vulnerability in Apache HTTP Server on crafted regular expressions in the configuration. This issue affects Apache HTTP Server: from 2.4.0 through 2.4.67. Users are recommended to upgrade to version 2.4.68, which fixes the issue. CVSSv3.1 9.8 (CRITICAL)

CWECWE 124VNDBufferTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-06-08
2026-06-08 16:16Z
HIGH

CVE-2026-42863 — Flowiseai Flowise: The endpoint allows clients to modify server-controlled properties such as deployed, isPublic, workspaceId, createdDate

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-42863

Flowise is a drag & drop user interface to build a customized large language model flow. Prior to version 3.1.2, a mass assignment vulnerability exists in the chatflow update endpoint of FlowiseAI. The endpoint allows clients to modify server-controlled properties such as deployed, isPublic, workspaceId, createdDate, and updatedDate when updating a chatflow object. Due to missing server-side validation and authorization checks, an authenticated user can manipulate internal at CVSSv3.1 8.1 (HIGH) · EPSS 16th percentile

CWECWE 639CWECWE 284CWECWE 915VNDFlowiseaiVNDFlowiseTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-06-08
2026-06-08 16:16Z
CRIT

CVE-2026-42861 — Flowiseai Flowise: The endpoint allows authenticated users to modify server-controlled properties such as workspaceId, createdDate, and

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-42861

Flowise is a drag & drop user interface to build a customized large language model flow. Prior to version 3.1.2, a mass assignment vulnerability exists in the variable update endpoint of FlowiseAI. The endpoint allows authenticated users to modify server-controlled properties such as workspaceId, createdDate, and updatedDate when updating a variable resource. Due to missing server-side validation and authorization checks, an attacker can manipulate the workspaceId field and r CVSSv3.1 9.6 (CRITICAL) · EPSS 16th percentile

CWECWE 639CWECWE 284CWECWE 915VNDFlowiseaiVNDFlowiseTYPVulnerability
9.6
CVSS v3.1
98
Edit Score
2026-06-08
2026-06-08 16:16Z
CRIT

CVE-2026-42535 — A path handling issue in mod_dav_fs in Apache 2.4.67 and earlier allows a WebDAV

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-42535

A path handling issue in mod_dav_fs in Apache 2.4.67 and earlier allows a WebDAV content author to directly manipulate trusted DAV property databases, potentially causing child process crashes. Users are recommended to upgrade to version 2.4.68, which fixes this issue. CVSSv3.1 9.1 (CRITICAL)

CWECWE 668TYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2026-06-08
2026-06-08 16:16Z
CRIT

CVE-2026-29167 — Use: After Free vulnerability in Apache HTTP Server with mod_ldap in per-directory configuration This

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-29167

Use After Free vulnerability in Apache HTTP Server with mod_ldap in per-directory configuration This issue affects Apache HTTP Server: from 2.4.0 through 2.4.67. Users are recommended to upgrade to version 2.4.68, which fixes the issue. CVSSv3.1 9.8 (CRITICAL)

CWECWE 416TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-06-08
2026-06-08 16:16Z
HIGH

CVE-2026-11528 — Tenda: The manipulation of the argument callback results in stack-based buffer overflow.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-11528

A vulnerability was found in Tenda AC18 15.03.05.05. The affected element is the function sub_45304 of the file /goform/getRebootStatus of the component Web Management Interface. The manipulation of the argument callback results in stack-based buffer overflow. The attack may be launched remotely. The exploit has been made public and could be used. CVSSv3.1 8.8 (HIGH)

CWECWE 121CWECWE 119VNDTendaTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-06-08
2026-06-08 16:16Z
HIGH

CVE-2026-11524 — The manipulation of the argument wifiFilterListRemark leads to stack-based buffer overflow.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-11524

A vulnerability has been found in Tenda W20E 15.11.0.6. Impacted is the function modifyWifiFilterRules of the file /goform/modifyWifiFilterRules of the component Web Management Interface. The manipulation of the argument wifiFilterListRemark leads to stack-based buffer overflow. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. CVSSv3.1 8.8 (HIGH)

CWECWE 121CWECWE 119TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-06-08
2026-06-08 16:16Z
HIGH

CVE-2026-11523 — Executing a manipulation of the argument gotoUrl can lead to stack-based buffer overflow.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-11523

A flaw has been found in Tenda W20E 15.11.0.6. This issue affects the function formPortalAuth of the file /goform/PortalAuth of the component Web Management Interface. Executing a manipulation of the argument gotoUrl can lead to stack-based buffer overflow. The attack can be launched remotely. The exploit has been published and may be used. CVSSv3.1 8.8 (HIGH)

CWECWE 121CWECWE 119TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-06-08
2026-06-08 16:16Z
HIGH

CVE-2026-11522 — Tenda: Performing a manipulation of the argument portMirrorMirroredPorts results in stack-based buffer overflow.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-11522

A vulnerability was detected in Tenda W20E 15.11.0.6. This vulnerability affects the function formSetPortMirror of the file /goform/setPortMirror. Performing a manipulation of the argument portMirrorMirroredPorts results in stack-based buffer overflow. The attack can be initiated remotely. The exploit is now public and may be used. CVSSv3.1 8.8 (HIGH)

CWECWE 121CWECWE 119VNDTendaTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-06-08
2026-06-08 16:00Z
INFO

Keeping a Short Leash: New AzureHound Least-Privilege Documentation

SpecterOps·specterops.io

SpecterOps published comprehensive least-privilege permission documentation for AzureHound, the BloodHound data collector for Microsoft Entra ID and Azure Resource Manager. The research maps 17 Microsoft Graph endpoints to 8 granular application permissions and 17 ARM endpoints to specific RBAC actions, replacing the previous broad Directory.Read.All and Reader role assignments. The work includes validation methodology, permission matrices, and updated deployment scripts shipping with the narrower permission set by default.

TACTA0007SRFIdentitySRFCloudSWBloodhoundSWAzurehoundVNDMicrosoftTYPToolTECT1526
68
Edit Score
2026-06-08
2026-06-08 15:19Z
INFO

v9.3.0-rc1

BloodHound releases·github.comCVE-2026-46625CVE-2026-44705

BloodHound v9.3.0-rc1 release candidate published with numerous feature additions, bug fixes, and dependency updates. Changes include new privilege zone metrics, alerts framework enhancements, ADCS post-processing optimizations, and accessibility improvements across the UI.

SWBloodhoundVNDSpecteropsTYPTool
42
Edit Score