2026-05-28
2026-05-28 17:16Z
HIGH

CVE-2026-44543 — Path: This can result in a privileged pod running on the target node with the

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-44543

Local Path Provisioner provides a way for the Kubernetes users to utilize the local storage in each node. Prior to 0.0.36, a malicious user with permission to edit the local-path-config ConfigMap in the local-path-storage namespace can manipulate the helperPod.yaml template used by rancher/local-path-provisioner. The helperPod.yaml template is loaded by the provisioner and used to create HelperPods during PVC provisioning and cleanup operations. However, the template is not s CVSSv3.1 8.7 (HIGH)

CWECWE 269TYPVulnerability
8.7
CVSS v3.1
94
Edit Score
2026-05-28
2026-05-28 17:16Z
CRIT

CVE-2026-44477 — Linuxfoundation Cloudnativepg: Prior to 1.29.1 and 1.28.3, the CloudNativePG metrics exporter opens its PostgreSQL connection as

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-44477

CloudNativePG is a platform designed to manage PostgreSQL databases within Kubernetes environments. Prior to 1.29.1 and 1.28.3, the CloudNativePG metrics exporter opens its PostgreSQL connection as the postgres superuser via the pod-local Unix socket, then demotes the session with SET ROLE pg_monitor. SET ROLE changes only current_user; session_user remains postgres. Any SQL expression evaluated inside the scrape session can invoke RESET ROLE to recover real superuser privile CVSSv3.1 9.9 (CRITICAL)

CWECWE 426CWECWE 250CWECWE 271VNDLinuxfoundationVNDCloudnativepgTYPVulnerability
9.9
CVSS v3.1
100
Edit Score
2026-05-28
2026-05-28 17:16Z
HIGH

CVE-2026-44466 — Zed: Prior to 0.229.0, Zed's terminal tool permission system can be bypassed via bash arithmetic

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-44466

Zed is a code editor. Prior to 0.229.0, Zed's terminal tool permission system can be bypassed via bash arithmetic expansion $((...)), allowing execution of arbitrary commands nested inside an allowlisted command like echo. This vulnerability is fixed in 0.229.0. CVSSv3.1 8.6 (HIGH)

CWECWE 78VNDZedTYPVulnerability
8.6
CVSS v3.1
93
Edit Score
2026-05-28
2026-05-28 17:16Z
HIGH

CVE-2026-44465 — Zed: This allows an attacker to achieve Remote Code Execution (RCE) when a victim open

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-44465

Zed is a code editor. Prior to 0.227.1, Zed IDE executes arbitrary commands when opening a folder with a malicious .git/config file that abuses the core.fsmonitor Git configuration option. This allows an attacker to achieve Remote Code Execution (RCE) when a victim open a folder in untrusted mode. This vulnerability is fixed in 0.227.1. CVSSv3.1 8.6 (HIGH)

CWECWE 78VNDZedTYPVulnerability
8.6
CVSS v3.1
93
Edit Score
2026-05-28
2026-05-28 17:16Z
HIGH

CVE-2026-44463 — Zed: Prior to 0.229.0, Zed's terminal tool permission system can be bypassed by prepending environment

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-44463

Zed is a code editor. Prior to 0.229.0, Zed's terminal tool permission system can be bypassed by prepending environment variable assignments to allowlisted commands, hijacking program behavior (e.g., PAGER) to execute arbitrary code. This vulnerability is fixed in 0.229.0. CVSSv3.1 8.6 (HIGH)

CWECWE 78CWECWE 184VNDZedTYPVulnerability
8.6
CVSS v3.1
93
Edit Score
2026-05-28
2026-05-28 17:16Z
HIGH

CVE-2026-44461 — Zed: This can lead to arbitrary command execution on the remote host under the victim

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-44461

Zed is a code editor. Prior to 0.227.1, Zed builds SSH/WSL remote commands as a shell command string that starts with exec env ..., but environment variable keys are inserted without shell quoting or validation. If an attacker can control an environment variable key (for example via project terminal settings), shell expansions in the key (such as $(...)) are evaluated by the remote shell when a terminal is opened. This can lead to arbitrary command execution on the remote hos CVSSv3.1 8.6 (HIGH)

CWECWE 78VNDZedTYPVulnerability
8.6
CVSS v3.1
93
Edit Score
2026-05-28
2026-05-28 17:16Z
CRIT

CVE-2026-38707 — A command injection vulnerability exists in the IPSec VPN feature of InHand Networks IR302

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-38707

A command injection vulnerability exists in the IPSec VPN feature of InHand Networks IR302 firmware V3.5.108, IR305 firmware V1.0.118, IR315 firmware V1.0.118, IR615 firmware V1.0.118, and earlier versions. Attackers can exploit this vulnerability to obtain ROOT privileges on remote target devices. CVSSv3.1 9.8 (CRITICAL)

CWECWE 77TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
728 × 90 / responsive · programmatic ad slot
2026-05-28
2026-05-28 17:16Z
CRIT

CVE-2026-38704 — A command injection vulnerability exists in the WireGuard VPN feature of InHand Networks IR302

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-38704

A command injection vulnerability exists in the WireGuard VPN feature of InHand Networks IR302 firmware V3.5.108, IR305 firmware V1.0.118, IR315 firmware V1.0.118, IR615 firmware V1.0.118, and earlier versions. Attackers can exploit this vulnerability to obtain ROOT privileges on remote target devices. CVSSv3.1 9.8 (CRITICAL)

CWECWE 77TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-05-28
2026-05-28 17:16Z
CRIT

CVE-2026-38703 — A command injection vulnerability exists in the ZeroTier VPN feature of InHand Networks IR302

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-38703

A command injection vulnerability exists in the ZeroTier VPN feature of InHand Networks IR302 firmware V3.5.108, IR305 firmware V1.0.118, IR315 firmware V1.0.118, IR615 firmware V1.0.118, and earlier versions. Attackers can exploit this vulnerability to obtain ROOT privileges on remote target devices. CVSSv3.1 9.8 (CRITICAL)

CWECWE 77TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-05-28
2026-05-28 17:16Z
CRIT

CVE-2026-38702 — A command injection vulnerability exists in the Admin Access feature of InHand Networks IR302

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-38702

A command injection vulnerability exists in the Admin Access feature of InHand Networks IR302 firmware V3.5.108, IR305 firmware V1.0.118, IR315 firmware V1.0.118, IR615 firmware V1.0.118, and earlier versions. Attackers can exploit this vulnerability to obtain ROOT privileges on remote target devices. CVSSv3.1 9.8 (CRITICAL)

CWECWE 77TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-05-28
2026-05-28 17:16Z
CRIT

CVE-2026-24444 — SDMC: NE6037 cable modem routers running firmware 7.1.6.0.25 and 7.1.6.1.9_B9 contain a hardcoded password

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-24444

SDMC NE6037 cable modem routers running firmware 7.1.6.0.25 and 7.1.6.1.9_B9 contain a hardcoded password vulnerability in the web management interface recovery endpoints (mgmt.php, npcmd.php) that allows unauthenticated attackers to gain root access by submitting the hardcoded credential to the recovery endpoint via HTTP. Attackers can leverage this hardcoded password to enable filtered SSH and Telnet services on the device, resulting in unauthenticated root-level remote acc CVSSv3.1 9.8 (CRITICAL)

CWECWE 798VNDSdmcTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-05-28
2026-05-28 16:16Z
HIGH

CVE-2026-47762 — TinyMCE: Prior to 5.11.1, 7.9.3, and 8.5.1, there is a stored XSS vulnerability via forged

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-47762

TinyMCE is an open source rich text editor. Prior to 5.11.1, 7.9.3, and 8.5.1, there is a stored XSS vulnerability via forged mce:protected comments. Allows attackers to bypass sanitization and inject scripts that execute when content is restored. Impacts users who utilize the protect option. This vulnerability is fixed in 5.11.1, 7.9.3, and 8.5.1. CVSSv3.1 8.7 (HIGH)

CWECWE 79VNDTinymceTYPVulnerability
8.7
CVSS v3.1
94
Edit Score
2026-05-28
2026-05-28 16:16Z
HIGH

CVE-2026-47761 — TinyMCE: Prior to 5.11.1, 7.9.3, and 8.5.1, there is a stored XSS vulnerability in the

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-47761

TinyMCE is an open source rich text editor. Prior to 5.11.1, 7.9.3, and 8.5.1, there is a stored XSS vulnerability in the media plugin. Attackers can inject malicious scripts via crafted data-mce-* attributes, which are executed when content is rendered. Impacts users of TinyMCE with the media plugin enabled. This vulnerability is fixed in 5.11.1, 7.9.3, and 8.5.1. CVSSv3.1 8.7 (HIGH)

CWECWE 79VNDTinymceTYPVulnerability
8.7
CVSS v3.1
94
Edit Score
2026-05-28
2026-05-28 16:16Z
HIGH

CVE-2026-47760 — TinyMCE: From 6.8.0 to before 7.1.0, TinyMCE contains an XSS vulnerability caused by improper SVG

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-47760

TinyMCE is an open source rich text editor. From 6.8.0 to before 7.1.0, TinyMCE contains an XSS vulnerability caused by improper SVG namespace scope handling in the sanitizer. A crafted payload using nested elements can bypass attribute sanitization and execute arbitrary JavaScript. This vulnerability is fixed in 7.1.0. CVSSv3.1 8.7 (HIGH)

CWECWE 79VNDTinymceTYPVulnerability
8.7
CVSS v3.1
94
Edit Score
2026-05-28
2026-05-28 16:16Z
HIGH

CVE-2026-47759 — TinyMCE: Prior to 5.11.1, 7.9.3, and 8.5.1, there is a stored XSS vulnerability via unsanitized

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-47759

TinyMCE is an open source rich text editor. Prior to 5.11.1, 7.9.3, and 8.5.1, there is a stored XSS vulnerability via unsanitized data-mce-* attributes (data-mce-href, data-mce-src, data-mce-style). Allows attackers to inject malicious values that override safe attributes during serialization, bypassing validation. This vulnerability is fixed in 5.11.1, 7.9.3, and 8.5.1. CVSSv3.1 8.7 (HIGH)

CWECWE 79VNDTinymceTYPVulnerability
8.7
CVSS v3.1
94
Edit Score
2026-05-28
2026-05-28 16:16Z
HIGH

CVE-2026-44358 — Espressif: Shared GitHub DangerJS is a reusable GitHub Action CI DangerJS workflow for Espressif

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-44358

Espressif Shared GitHub DangerJS is a reusable GitHub Action CI DangerJS workflow for Espressif GitHub projects. Prior to 1.0.1, the action's entrypoint.sh invoked DangerJS from the caller's workspace after copying the fork's checkout into it, creating an untrusted search path for both binary resolution and Node.js module resolution. A fork pull request processed by a pull_request_target workflow could therefore cause fork-supplied code to execute inside the action container CVSSv3.1 8.2 (HIGH)

CWECWE 829CWECWE 427VNDEspressifTYPVulnerability
8.2
CVSS v3.1
91
Edit Score
2026-05-28
2026-05-28 16:16Z
HIGH

CVE-2026-35676 — phpMyFAQ before 4.1.3 contains an unauthenticated password reset vulnerability in the user password update

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-35676

phpMyFAQ before 4.1.3 contains an unauthenticated password reset vulnerability in the user password update API endpoint that allows attackers to change account passwords without token validation. Attackers can enumerate valid username and email pairs and force immediate password changes by sending PUT requests to the /api/index.php/user/password/update endpoint, causing account disruption and invalidating legitimate user credentials. CVSSv3.1 8.2 (HIGH)

CWECWE 640TYPVulnerability
8.2
CVSS v3.1
91
Edit Score
2026-05-28
2026-05-28 16:16Z
HIGH

CVE-2026-35675 — phpMyFAQ before 4.1.3 contains an authentication bypass vulnerability in the password reset endpoint that

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-35675

phpMyFAQ before 4.1.3 contains an authentication bypass vulnerability in the password reset endpoint that allows unauthenticated attackers to reset any user account password without token verification or email confirmation. Attackers can enumerate valid usernames, obtain plaintext passwords via email, and achieve complete account takeover including administrative access. CVSSv3.1 8.2 (HIGH)

CWECWE 307TYPVulnerability
8.2
CVSS v3.1
91
Edit Score
2026-05-28
2026-05-28 16:16Z
HIGH

CVE-2026-35671 — phpMyFAQ before 4.1.3 contains an insecure direct object reference vulnerability in the admin API

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-35671

phpMyFAQ before 4.1.3 contains an insecure direct object reference vulnerability in the admin API user password endpoint that allows authenticated administrators to change any user's password without authorization verification. An attacker with low-privilege admin credentials can escalate to SuperAdmin by modifying the userId parameter in the overwrite-password API request. CVSSv3.1 8.8 (HIGH)

CWECWE 266TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-05-28
2026-05-28 16:00Z
HIGH

Don’t Jump the Turnstile: Lessons from the Field

SpecterOps·specterops.io

SpecterOps red-teamer Zach Stein documents a phishing engagement where email sandboxes defeated traditional evasion techniques (user-agent spoofing, mouse-movement detection). The solution: weaponizing Cloudflare Turnstile CAPTCHA as a sandbox filter—the CAPTCHA widget validates human interaction before revealing the payload redirect, allowing the phishing page to pass sandbox inspection while remaining invisible to automated crawlers.

TACTA0001SRFWebTYPResearchTYPTechniqueSTGInitial AccessTECT1566.002EXPAuth BypassSTAongoing
76
Edit Score
2026-05-28
2026-05-28 15:23Z
CRIT

Nuclei Templates v10.4.4 - Release Notes

Nuclei Templates v10.4.4 release adds 179 new templates covering 43 CVEs, including critical RCE vulnerabilities in DbGate, TYPO3, Apache Tomcat, Apache Camel, Cisco SD-WAN, Drupal, WordPress plugins, and others. The release includes bug fixes for YAML parsing failures, template ID conflicts, false positives/negatives, and metadata normalization across the template library.

SWNuclei TemplatesVNDProjectdiscoveryTYPTool
78
Edit Score
2026-05-28
2026-05-28 14:16Z
HIGH

CVE-2026-49238 — Canonical: The host-side SFTP server component (sshfs_server), which executes with root privileges on the host

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-49238

An issue was discovered in Canonical Multipass before version 1.16.3. The host-side SFTP server component (sshfs_server), which executes with root privileges on the host, contains a path containment bypass vulnerability within its validate_path function in src/sshfs_mount/sftp_server.cpp. The function performs a plain string prefix comparison on requested paths without path separator validation or dot-dot (..) normalization. A local attacker with root privileges inside a gues CVSSv3.1 8.4 (HIGH)

CWECWE 22VNDCanonicalTYPVulnerability
8.4
CVSS v3.1
92
Edit Score
2026-05-28
2026-05-28 14:16Z
HIGH

CVE-2026-37266 — Responsive: An issue in Responsive File Manager Responsive FileManager Version 9.14.0 allows a remote attacker

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-37266

An issue in Responsive File Manager Responsive FileManager Version 9.14.0 allows a remote attacker to execute arbitrary code via the force_download.php component CVSSv3.1 8.0 (HIGH)

CWECWE 98VNDResponsiveTYPVulnerability
8.0
CVSS v3.1
90
Edit Score
2026-05-28
2026-05-28 12:00Z
CRIT

Authenticated RCE via Argument Injection in Gogs (NOT FIXED)

Rapid7 Research·rapid7.comCVE-2026-261940day

Rapid7 disclosed a critical authenticated argument injection vulnerability (CVSS 9.4) in Gogs that allows any authenticated user to achieve RCE via malicious branch names injected into git rebase operations during pull request merging. The vulnerability affects all versions supporting rebase-before-merge functionality and remains unpatched; exploitation is fully automatable with a Metasploit module provided. On default-configured instances with open registration, unauthenticated attackers can register, create a repository, and exploit the flaw without admin privileges or user interaction.

SRFApplicationTACTA0002SWGogsTYPVulnerabilitySTGExecutionSTGImpactTECT1190EXPRce
95
Edit Score
2026-05-28
2026-05-28 10:16Z
CRIT

CVE-2026-9813 — Flowintel Flowintel: up to version 3.3.0 contains a server-side request forgery (SSRF) vulnerability in the

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-9813

FlowIntel up to version 3.3.0 contains a server-side request forgery (SSRF) vulnerability in the external reference URL probe functionality in app/case/task.py. An attacker who can submit an external reference URL can cause the application server to issue an HTTP HEAD request to an attacker-specified destination. Due to insufficient validation of the URL scheme and resolved destination address, affected versions may allow requests to loopback, link-local, private, reserved, o CVSSv3.1 9.9 (CRITICAL) · EPSS 14th percentile

CWECWE 918VNDFlowintelTYPVulnerability
9.9
CVSS v3.1
100
Edit Score