2026-06-01
2026-06-01 13:00Z
CRIT

CVE-2026-0826: How an Old Bug Can Feed AI-Powered Impersonation

Rapid7 Research·rapid7.comCVE-2026-0826

CVE-2026-0826 is a critical unauthenticated stack-based buffer overflow in HP Poly VVX and Trio VoIP phones that allows remote code execution without authentication. The vulnerability bypasses modern memory protections and can be exploited to gain root access on trusted office devices. The research highlights the emerging threat of compromised VoIP phones as collection points for high-quality audio data to feed AI-powered impersonation and social engineering attacks.

TACTA0001TACTA0002SRFNetwork ApplianceSWPoly TrioSWPoly VvxVNDHpTYPVulnerabilitySTGInitial Access
78
Edit Score
2026-06-01
2026-06-01 13:00Z
CRIT

CVE-2026-0826: Critical unauthenticated stack buffer overflow in HP Poly VVX and Trio VoIP Phones (FIXED)

Rapid7 Research·rapid7.comCVE-2026-0826

Rapid7 discovered a critical unauthenticated stack-based buffer overflow (CVE-2026-0826, CVSS 9.2) in HP Poly VVX and Trio VoIP phones affecting all VVX models and three Trio models. The vulnerability exists in the parsing of SDP ICE candidate attributes and allows remote code execution with root privileges when ICE is enabled. Patches are available: VVX UCS 6.4.8, Trio 8300 UCS 8.1.7, Trio 8500/8800 UCS 7.2.8.

TACTA0001SRFNetwork ApplianceSWPoly TrioSWPoly VvxVNDHpTYPExploitTYPVulnerabilitySTGExecution
92
Edit Score
2026-06-01
2026-06-01 10:00Z
CRIT

Containers on fire: from container escapes to supply chain attacks

Kaspersky Securelist·securelist.comCVE-2019-5736CVE-2022-0492CVE-2024-21626

Kaspersky's comprehensive analysis of container attack vectors covering exploitation of host vulnerabilities (runC, cgroups), malicious activity within containers, container escape techniques via Linux capability misconfigurations (CAP_SYS_ADMIN, CAP_SYS_MODULE, CAP_SYS_PTRACE, CAP_NET_ADMIN), orchestration API abuse, and supply chain attacks including Docker Hub poisoning. The article details real-world APT campaigns like TeamPCP's Checkmarx KICS compromise and provides technical walkthroughs of escape primitives including kernel module injection and ptrace-based process hijacking.

SRFOsTACTA0004SRFCloudTACTA0008SWKubernetesSWDockerSWRuncVNDKaspersky
82
Edit Score
2026-06-01
2026-06-01 09:16Z
HIGH

CVE-2026-9024 — Stored: A Stored Cross-site Scripting (XSS) vulnerability affecting Process Experience Studio in DELMIA Service Process

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-9024

A Stored Cross-site Scripting (XSS) vulnerability affecting Process Experience Studio in DELMIA Service Process Engineer from Release 3DEXPERIENCE R2024x through Release 3DEXPERIENCE R2026x could allow an attacker to execute arbitrary script code in user's browser session. CVSSv3.1 8.7 (HIGH)

CWECWE 79VNDStoredTYPVulnerability
8.7
CVSS v3.1
94
Edit Score
2026-06-01
2026-06-01 09:16Z
CRIT

CVE-2026-7858 — Deserialization: A Deserialization of Untrusted Data vulnerability affecting Teamwork Cloud from No Magic Release 2022x

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-7858

A Deserialization of Untrusted Data vulnerability affecting Teamwork Cloud from No Magic Release 2022x through No Magic Release 2026x and Magic Collaboration Studio from CATIA Magic Release 2022x through CATIA Magic Release 2026x could lead to an unauthenticated remote code execution. CVSSv3.1 9.8 (CRITICAL)

CWECWE 502TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-06-01
2026-06-01 09:16Z
HIGH

CVE-2026-49298 — Apache: A bug in Apache Airflow's KubernetesExecutor caused JWT tokens used by worker pods to

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-49298

A bug in Apache Airflow's KubernetesExecutor caused JWT tokens used by worker pods to authenticate against the Execution API to be passed to the worker container as command-line arguments visible in the pod spec. An authenticated UI/API user with Kubernetes read-only access to the cluster (e.g. `pods/get` in the Airflow namespace) could harvest the JWT from `kubectl describe pod` output and then call state-mutating Execution API endpoints — triggering Dag runs, clearing runs, CVSSv3.1 8.8 (HIGH)

CWECWE 538VNDApacheTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-06-01
2026-06-01 09:16Z
HIGH

CVE-2026-49157 — Incorrect: Default Permissions vulnerability in Apache ActiveMQ.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-49157

Incorrect Default Permissions vulnerability in Apache ActiveMQ. This issue affects Apache ActiveMQ: before 5.19.7, from 6.0.0 before 6.2.6. The default Jolokia authorization settings granted non-admin (low-privilege) web-login accounts access to Jolokia operations which allowed executing broker management operations meant for admins such as addQueue and removeQueue. Users are recommended to upgrade to version 6.2.6 or 5.19.7, which fixes the issue. CVSSv3.1 8.8 (HIGH)

CWECWE 276TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
728 × 90 / responsive · programmatic ad slot
2026-06-01
2026-06-01 09:16Z
HIGH

CVE-2026-45505 — Input: Improper Input Validation, Improper Control of Generation of Code ('Code Injection') vulnerability in Apache

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-45505

Improper Input Validation, Improper Control of Generation of Code ('Code Injection') vulnerability in Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ. Non-parenthesized discovery wrappers such as `masterslave:vm://...,...` and `static:vm://...` incorrectly pass validation allowing bypass of fix in CVE-2026-34197.  Original description from CVE-2026-34197. Apache ActiveMQ exposes the Jolokia JMX-HTTP bridge at /api/jolokia/ on the web console. The default Jolo CVSSv3.1 8.8 (HIGH)

CWECWE 94CWECWE 20VNDInputTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-06-01
2026-06-01 09:16Z
HIGH

CVE-2026-44825 — Hardcoded: credentials in the Basic Authentication setup tool (bin/solr auth enable) in Apache Solr

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-44825

Hardcoded credentials in the Basic Authentication setup tool (bin/solr auth enable) in Apache Solr versions 9.4.0 through 9.10.1 and 10.0.0 allows a remote attacker to gain full administrative access to the cluster via publicly known default credentials installed silently alongside the user-specified account. As an immediate workaround without upgrading, delete the template users (superadmin, admin, search, index) from security.json or change their passwords. The future, no CVSSv3.1 8.1 (HIGH)

CWECWE 1188CWECWE 798VNDHardcodedTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-06-01
2026-06-01 09:16Z
HIGH

CVE-2026-42588 — Input: Improper Input Validation, Improper Control of Generation of Code ('Code Injection') vulnerability in Apache

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-42588

Improper Input Validation, Improper Control of Generation of Code ('Code Injection') vulnerability in Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ. Apache ActiveMQ Classic exposes the Jolokia JMX-HTTP bridge at /api/jolokia/ on the web console. The default Jolokia access policy permits exec operations on all ActiveMQ MBeans (org.apache.activemq:*), including BrokerService.addNetworkConnector(String). An authenticated attacker can invoke these operations with CVSSv3.1 8.1 (HIGH)

CWECWE 94CWECWE 20VNDInputTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-06-01
2026-06-01 09:16Z
HIGH

CVE-2026-42359 — Apache: The endpoint also accepted serialized payload shapes the triggerer's deserializer treats as code; combined

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-42359

A bug in Apache Airflow's XCom PATCH endpoint `PATCH /api/v2/xcomEntries/{key}` allowed an authenticated UI/API user with XCom write permission on a Dag to set XCom entries under reserved key names (e.g. `return_value`) that the matching POST endpoint already validated against `FORBIDDEN_XCOM_KEYS`. The endpoint also accepted serialized payload shapes the triggerer's deserializer treats as code; combined, this allowed RCE on the triggerer when the affected task next deferred. CVSSv3.1 8.8 (HIGH)

CWECWE 502VNDApacheTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-06-01
2026-06-01 09:16Z
CRIT

CVE-2026-42252 — Apache: Dag authors who copied the pattern verbatim into deployments where users had `Dag.can_trigger` permission

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-42252

Apache Airflow's official documentation at `core-concepts/dag-run.html` ("Passing Parameters when triggering Dags") showed a verbatim `BashOperator(bash_command="echo value: {{ dag_run.conf['conf1'] }}")` example without any quoting / sanitization warning. Dag authors who copied the pattern verbatim into deployments where users had `Dag.can_trigger` permission on the affected Dag (typical multi-team deployments, hosted offerings exposing a trigger API) could be exposed to she CVSSv3.1 9.1 (CRITICAL)

CWECWE 1336VNDApacheTYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2026-06-01
2026-06-01 08:16Z
HIGH

CVE-2026-35563 — Apache Directory_ldap_api: While the underlying code validates the certificate chain against a trusted authority, the absence

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-35563

It was identified that the LDAP client implementation in version 2.1.7 does not verify if the server certificate matches the intended LDAP hostname. While the underlying code validates the certificate chain against a trusted authority, the absence of endpoint identification allows a valid certificate issued for an entirely unrelated host to be improperly accepted. This oversight leaves the connection highly vulnerable to server impersonation and complete connection compr CVSSv3.1 8.5 (HIGH)

CWECWE 297VNDApacheVNDLdapTYPVulnerability
8.5
CVSS v3.1
93
Edit Score
2026-06-01
2026-06-01 06:42Z
HIGH

OpenClaw: risks for agent users and how to mitigate them

Kaspersky Securelist·securelist.comin the wild

Kaspersky researchers document widespread security risks in OpenClaw, an AI agent platform, identifying ~530 vulnerabilities and 1,100+ malicious skill accounts distributing over 600 malicious skills via ClawHub. The attack surface centers on command injection through natural-language skill definitions, privilege escalation via stored credentials, and supply-chain compromise through the unvetted skill marketplace.

SRFApplicationTACTA0001TACTA0002SRFAiSWOpenclawTYPResearchTYPThreat IntelSTGExecution
72
Edit Score
2026-06-01
2026-06-01 06:30Z
CRIT

FSB’s matryoshka #1/3 – Gamaredon’s gifts that keeps unpacking – GammaPhish and GammaWorm

Sekoia.io·sekoia.ioCVE-2025-8088CVE-2018-20250in the wild

Sekoia's TDR team reconstructed a complete Gamaredon (FSB-linked) infection chain deployed in January 2026 targeting Ukrainian government and military entities. The campaign chains spearphishing with weaponized xHTML/RAR files exploiting CVE-2025-8088 to deploy a modular malware ecosystem (GammaPhish, GammaLoad, GammaWorm, GammaSteel) that establishes persistence, propagates via USB/network shares, and exfiltrates documents to cloud storage. The report establishes a unified taxonomy across a decade of fragmented Gamaredon nomenclature and documents novel evasion techniques including NTFS Alternate Data Streams, Dead Drop Resolvers, and redundant backdoor capabilities at every infection stage.

SRFApplicationSRFOsTACTA0004TACTA0005TACTA0001TACTA0002TACTA0007TACTA0003
92
Edit Score
2026-06-01
2026-06-01 04:16Z
CRIT

CVE-2026-48188 — Input: An improper Input Validation vulnerability in OTRS or ((OTRS)) Community Edition database layer module

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-48188

An improper Input Validation vulnerability in OTRS or ((OTRS)) Community Edition database layer module allows an unauthenticated SQL injection which can lead to an authentication bypass. This issue only affects the system if the MySQL/MariaDB server is configured with the NO_BACKSLASH_ESCAPES SQL mode. This issue affects OTRS: * 7.0.X * 8.0.X * 2023.X * 2024.X * 2025.X * 2026.X before 2026.4.X * (OTRS)) Community Edition: 6.0.x Products based on the ( CVSSv3.1 9.1 (CRITICAL)

CWECWE 20VNDInputTYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2026-06-01
2026-06-01 04:16Z
HIGH

CVE-2026-20452 — In wlan AP driver, there is a possible memory corruption due to a heap

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-20452

In wlan AP driver, there is a possible memory corruption due to a heap buffer overflow. This could lead to remote (proximal/adjacent) code execution with User execution privileges needed. User interaction is not needed for exploitation. Patch ID: WCNCR00480138; Issue ID: MSV-6295. CVSSv3.1 8.0 (HIGH)

CWECWE 122TYPVulnerability
8.0
CVSS v3.1
90
Edit Score
2026-06-01
2026-06-01 01:16Z
HIGH

CVE-2026-10206 — Performing a manipulation of the argument str results in stack-based buffer overflow.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-10206

A vulnerability was detected in D-Link DI-8400 up to 16.07.26A1. This affects an unknown function of the file /dbsrv.asp. Performing a manipulation of the argument str results in stack-based buffer overflow. Remote exploitation of the attack is possible. The exploit is now public and may be used. The initial researcher advisory mentions contradicting parameter names to be affected. CVSSv3.1 8.8 (HIGH)

CWECWE 121CWECWE 119TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-06-01
2026-06-01 00:00Z
CRIT

Pwn2Own Berlin 2026: On the Ground With TrendAI™ ZDI's Biggest AI Showdown Yet

Trend Micro Research·trendmicro.comZDI-CAN-31305ZDI-CAN-31432ZDI-CAN-31263ZDI-CAN-31430ZDI-CAN-31431ZDI-CAN-31482ZDI-CAN-31484ZDI-CAN-31481ZDI-CAN-314900day

Pwn2Own Berlin 2026 disclosed 47 zero-days across AI, enterprise, and virtualization targets, with $1.29M in payouts. AI products dominated the event, with every compromise rooted in 'trust boundary' failures where AI agents unconditionally trust external tools and protocols. Critical findings include Microsoft Exchange SYSTEM RCE, SharePoint pre-auth RCE, Edge sandbox escape, and VMware ESXi guest-to-host escape with cross-tenant implications.

SRFApplicationTACTA0004TACTA0002SRFCloudTACTA0008SRFAiOSLinuxSWLitellm
82
Edit Score
2026-05-31
2026-05-31 22:00Z
MED

Scala Security Audit

Quarkslab·blog.quarkslab.com

Quarkslab conducted a comprehensive security audit of Scala 3 on behalf of OSTIF, identifying 9 vulnerabilities across the compiler, standard library, and tooling. Findings include a deserialization gadget in ProcessBuilderImpl, stored XSS in Scaladoc, command injection in CI/CD workflows, and logic bugs in collection operations and TASTy parsing.

SRFApplicationSWScalaTYPResearchTYPVulnerabilityEXPDeserializationEXPXssEXPCmd InjectionSTApatched
72
Edit Score
2026-05-31
2026-05-31 20:16Z
HIGH

CVE-2026-8796 — Sereal: Sereal::Decoder versions before 5.005 for Perl allow heap out-of-bounds read via crafted input.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-8796

Sereal::Decoder versions before 5.005 for Perl allow heap out-of-bounds read via crafted input. In Perl/Decoder/srl_decoder.c, srl_read_object() and srl_read_hash() process a COPY tag, a back-reference whose target byte the decoder re-decodes as a fresh tag. When that target byte matches the SHORT_BINARY pattern (an inline string whose length is encoded in the low bits of the tag), the resulting read is not bounded to precede the COPY tag's own offset and can run past the en CVSSv3.1 8.1 (HIGH)

CWECWE 125VNDSerealTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-05-31
2026-05-31 17:16Z
HIGH

CVE-2026-10192 — Tenda: Such manipulation of the argument Time leads to stack-based buffer overflow.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-10192

A vulnerability was identified in Tenda W12 3.0.0.7(4763). The affected element is the function set_local_time_0 of the file /bin/httpd. Such manipulation of the argument Time leads to stack-based buffer overflow. The attack can be launched remotely. The exploit is publicly available and might be used. CVSSv3.1 8.8 (HIGH)

CWECWE 121CWECWE 119VNDTendaTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-05-31
2026-05-31 16:16Z
HIGH

CVE-2026-10191 — Tenda: This manipulation of the argument wifiMacFilterSet.macList.mac causes stack-based buffer overflow.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-10191

A vulnerability was determined in Tenda W12 3.0.0.7(4763). Impacted is the function cgiWifiMacFilterSet of the file /bin/httpd. This manipulation of the argument wifiMacFilterSet.macList.mac causes stack-based buffer overflow. The attack can be initiated remotely. The exploit has been publicly disclosed and may be utilized. CVSSv3.1 8.8 (HIGH)

CWECWE 121CWECWE 119VNDTendaTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-05-31
2026-05-31 16:16Z
HIGH

CVE-2026-10189 — The manipulation of the argument sec leads to stack-based buffer overflow.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-10189

A vulnerability has been found in Tenda W12 3.0.0.7(4763). This vulnerability affects the function cgiSysTimeInfoSet of the file /bin/httpd. The manipulation of the argument sec leads to stack-based buffer overflow. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. CVSSv3.1 8.8 (HIGH)

CWECWE 121CWECWE 119TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-05-31
2026-05-31 15:16Z
HIGH

CVE-2026-10188 — Executing a manipulation of the argument staMac can lead to stack-based buffer overflow.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-10188

A flaw has been found in Tenda W12 3.0.0.7(4763). This affects the function cgistaKickOff of the file /bin/httpd. Executing a manipulation of the argument staMac can lead to stack-based buffer overflow. The attack may be performed from remote. The exploit has been published and may be used. CVSSv3.1 8.8 (HIGH)

CWECWE 121CWECWE 119TYPVulnerability
8.8
CVSS v3.1
94
Edit Score