2026-05-22
2026-05-22 21:16Z
HIGH

CVE-2026-3294 — Tp-link Re305_firmware: An authentication logic vulnerability in multiple TP-Link range extenders allows an unauthenticated attacker on

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-3294

An authentication logic vulnerability in multiple TP-Link range extenders allows an unauthenticated attacker on an adjacent network to manipulate a login parameter and reset the administrator password due to insufficient validation. Successful exploitation allows an attacker to obtain full administrative control of the affected device, potentially impacting on confidentiality, integrity, and availability. CVSSv3.1 8.8 (HIGH)

CWECWE 862CWECWE 20VNDTp LinkTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-05-22
2026-05-22 20:16Z
HIGH

CVE-2026-5843 — Docker Docker_desktop: The MLX backend runs without sandboxing, resulting in arbitrary code execution on the Docker

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-5843

The MLX inference backend in Docker Model Runner on macOS uses the MLX-LM library, which unconditionally imports and executes arbitrary Python files from model directories via the model_file configuration field in config.json. When a model's config.json specifies a model_file pointing to a Python file, MLX-LM uses importlib to load and execute it with no trust_remote_code gate or equivalent safety check. The MLX backend runs without sandboxing, resulting in arbitrary code exe CVSSv3.1 8.2 (HIGH)

CWECWE 829VNDDockerVNDMlxTYPVulnerability
8.2
CVSS v3.1
91
Edit Score
2026-05-22
2026-05-22 20:16Z
HIGH

CVE-2026-5817 — Docker Docker_desktop: This causes transformers.AutoTokenizer.from_pretrained() to import and execute arbitrary Python files included in any model

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-5817

The vllm-metal inference backend in Docker Model Runner on macOS unconditionally sets trust_remote_code=True when loading model tokenizers, and runs without sandboxing. This causes transformers.AutoTokenizer.from_pretrained() to import and execute arbitrary Python files included in any model pulled from an OCI registry, resulting in arbitrary code execution on the Docker host as the Docker Desktop user when inference is triggered. Any container on the Docker network can trig CVSSv3.1 8.2 (HIGH)

CWECWE 829VNDDockerTYPVulnerability
8.2
CVSS v3.1
91
Edit Score
2026-05-22
2026-05-22 19:17Z
HIGH

CVE-2026-6406 — Docker Docker_desktop: The Docker CLI --use-api-socket flag bypasses Enhanced Container Isolation (ECI) restrictions in Docker Desktop.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-6406

The Docker CLI --use-api-socket flag bypasses Enhanced Container Isolation (ECI) restrictions in Docker Desktop. When ECI is enabled, Docker socket mounts from containers are denied unless explicitly allowed via the admin-settings configuration. However, the --use-api-socket flag adds the Docker socket mount via the HostConfig.Mounts field rather than the HostConfig.Binds field. The ECI enforcement in the Docker Desktop API proxy only inspected Binds, allowing the mount to pa CVSSv3.1 8.8 (HIGH)

CWECWE 863VNDDockerTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-05-22
2026-05-22 19:17Z
HIGH

CVE-2026-40172 — In versions prior to 2025.12.5 and 2026.2.0-rc1 through 2026.2.2, the PATCH /api/v3/core/users/{pk}/ API allows

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-40172

authentik is an open-source identity provider. In versions prior to 2025.12.5 and 2026.2.0-rc1 through 2026.2.2, the PATCH /api/v3/core/users/{pk}/ API allows a caller with change_user on a target user to assign arbitrary groups through UserSerializer, including groups with is_superuser=True, without requiring enable_group_superuser, leading to privilege escalation. This bypasses the stricter permission model enforced in group-management paths and enables delegated user-manag CVSSv3.1 8.1 (HIGH) · EPSS 42th percentile

CWECWE 269TYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-05-22
2026-05-22 19:10Z
HIGH

Metasploit Wrap Up 22/05/2026

Metasploit Framework 6.4.134 release adds five new modules covering authentication bypasses and RCE vulnerabilities: Cisco SD-WAN vHub auth bypass (CVE-2026-20182), HUSTOJ zip-slip RCE (CVE-2026-24479), Barracuda ESG Excel eval injection (CVE-2023-7102), cPanel/WHM CRLF injection auth bypass to root (CVE-2026-41940), and Tenable Security Center credential extraction. Also includes six enhancements and four bug fixes.

SRFApplicationSRFNetwork ApplianceSRFWebSWMetasploitSWHustojVNDBarracudaVNDCiscoVNDCpanel
72
Edit Score
2026-05-22
2026-05-22 18:16Z
HIGH

CVE-2026-46727 — Ruby-lang Ruby: A race condition leading to a use-after-free in the pthread-based getaddrinfo timeout handler (rb_getaddrinfo

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-46727

An issue was discovered in Ruby 4 before 4.0.5. A race condition leading to a use-after-free in the pthread-based getaddrinfo timeout handler (rb_getaddrinfo in ext/socket/raddrinfo.c) allows a remote attacker who can delay DNS responses near the user-specified timeout to crash a Ruby process that calls Addrinfo.getaddrinfo(..., timeout:) or Socket.tcp(..., resolv_timeout:). Memory-corruption-based exploitation is theoretically possible. The attack could, for example, be carr CVSSv3.1 8.1 (HIGH)

CWECWE 362VNDRuby LangTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
728 × 90 / responsive · programmatic ad slot
2026-05-22
2026-05-22 17:16Z
CRIT

CVE-2026-33712 — Typebot: In versions 3.15.2 and prior, the preview chat endpoint (POST /api/v1/typebots/{typebotId}/preview/startChat) allows unauthenticated users

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-33712

Typebot is a chatbot builder tool. In versions 3.15.2 and prior, the preview chat endpoint (POST /api/v1/typebots/{typebotId}/preview/startChat) allows unauthenticated users to achieve Server-Side Request Forgery (SSRF) by supplying a custom typebot definition with server-side code blocks. The fetch function exposed inside the isolated-vm sandbox calls Node.js native fetch without the SSRF validation (validateHttpReqUrl) that protects the HTTP Request block. This bypasses all CVSSv3.1 10.0 (CRITICAL) · EPSS 27th percentile

CWECWE 862CWECWE 918VNDTypebotTYPVulnerability
10.0
CVSS v3.1
100
Edit Score
2026-05-22
2026-05-22 17:16Z
CRIT

CVE-2026-32253 — Lizardbyte Sunshine: This can allow an untrusted certificate to pass authentication and access protected HTTPS endpoints.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-32253

Sunshine is a self-hosted game stream host for Moonlight. In versions prior to 2026.516.143833, the client-certificate authentication can be bypassed because of how OpenSSL verification results are handled. In src/crypto.cpp, the custom verify callback treats X509_V_ERR_UNABLE_TO_GET_ISSUER_CERT_LOCALLY, X509_V_ERR_CERT_NOT_YET_VALID, and X509_V_ERR_CERT_HAS_EXPIRED as success. This can allow an untrusted certificate to pass authentication and access protected HTTPS endpoints CVSSv3.1 9.8 (CRITICAL)

CWECWE 287CWECWE 295VNDLizardbyteVNDSunshineTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-05-22
2026-05-22 17:16Z
HIGH

CVE-2026-28445 — Typebot: This allows session hijacking and privilege escalation within the builder application.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-28445

Typebot is a chatbot builder tool. In versions 3.15.2 and prior, the RatingButton component in the embed package renders the user-controlled customIcon.svg field directly via Solid's innerHTML directive without any sanitization, even though DOMPurify is already a dependency and is used elsewhere in the codebase (e.g., StreamingBubble.tsx). Because rating blocks are not flagged as isUnsafe by the import sanitizer and the builder preview renders bots inline on the builder's own CVSSv3.1 8.7 (HIGH) · EPSS 17th percentile

CWECWE 79VNDTypebotTYPVulnerability
8.7
CVSS v3.1
94
Edit Score
2026-05-22
2026-05-22 16:16Z
CRIT

CVE-2026-39821 — ToASCII: This behavior can lead to privilege escalation in programs using the idna package.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-39821

The ToASCII and ToUnicode functions incorrectly accept Punycode-encoded labels that decode to an ASCII-only label. For example, ToUnicode("xn--example-.com") incorrectly returns the name "example.com" rather than an error. This behavior can lead to privilege escalation in programs using the idna package. For example, a program which performs privilege checks on the ASCII hostname may reject "example.com" but permit "xn--example-.com". If that program subsequently converts the CVSSv3.1 9.6 (CRITICAL)

CWECWE 1289VNDToasciiTYPVulnerability
9.6
CVSS v3.1
98
Edit Score
2026-05-22
2026-05-22 15:16Z
HIGH

CVE-2026-9256 — F5 Nginx_open_source: This may cause a heap buffer overflow in the NGINX worker process leading to

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-9256

NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_rewrite_module module. This vulnerability exists when a rewrite directive uses a regex pattern with distinct, overlapping Perl-Compatible Regular Expression (PCRE) captures (for example, ^/((.*))$) and a replacement string that references multiple such captures (for example, $1$2) in a redirect or arguments context. An unauthenticated attacker along with conditions beyond their control can exploit this vuln CVSSv3.1 8.1 (HIGH) · EPSS 55th percentile

CWECWE 122VNDF5VNDNginxTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-05-22
2026-05-22 15:16Z
HIGH

CVE-2026-8992 — Ivanti Secure_access_client: An improper certificate validation vulnerability in Ivanti Secure Access Client before 22.8R6 allows a

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-8992

An improper certificate validation vulnerability in Ivanti Secure Access Client before 22.8R6 allows a remote unauthenticated attacker to execute arbitrary code. CVSSv3.1 8.8 (HIGH) · EPSS 43th percentile

CWECWE 295VNDIvantiTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-05-22
2026-05-22 14:16Z
HIGH

CVE-2026-9277 — shell-quote's `quote()` function did not validate object-token inputs against the operator model used by

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-9277

shell-quote's `quote()` function did not validate object-token inputs against the operator model used by `parse()`. The `.op` field was backslash-escaped character by character using `/(.)/g`, which in JavaScript does not match line terminators (\n, \r, U+2028, U+2029). A line terminator in `.op` therefore passed through unescaped into the output; POSIX shells treat a literal newline as a command separator, so any content after it would execute as a second command. The vulner CVSSv3.1 8.1 (HIGH) · EPSS 53th percentile

CWECWE 77CWECWE 78TYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-05-22
2026-05-22 14:16Z
CRIT

CVE-2026-8670 — Avantra Avantra: Insufficient session expiration vulnerability in syslink software AG Avantra on Linux, Windows allows Reusing

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-8670

Insufficient session expiration vulnerability in syslink software AG Avantra on Linux, Windows allows Reusing Session IDs (aka Session Replay). This issue affects Avantra: before 25.3.1. CVSSv3.1 9.6 (CRITICAL)

CWECWE 613VNDAvantraTYPVulnerability
9.6
CVSS v3.1
98
Edit Score
2026-05-22
2026-05-22 13:16Z
CRIT

CVE-2026-44930 — Apache Cxf: An LDAP injection vulnerability in the LDAP Certificate repository of the XKMS server in

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-44930

An LDAP injection vulnerability in the LDAP Certificate repository of the XKMS server in Apache CXF may allow an attacker to retrieve arbitrary certificates from the repository.  Users are recommended to upgrade to versions 4.2.1, 4.1.6 or 3.6.11, which fix this issue. CVSSv3.1 9.8 (CRITICAL) · EPSS 48th percentile

CWECWE 90VNDApacheVNDLdapTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-05-22
2026-05-22 13:00Z
HIGH

Detecting CVE-2026-0265 at Scale: PAN-OS CAS Authentication Bypass

Bishop Fox Labs·bishopfox.comCVE-2026-0265in the wild

CVE-2026-0265 is a pre-authentication JWT signature-verification bypass in PAN-OS and Panorama when Cloud Authentication Service (CAS) is attached to an authentication profile. Bishop Fox published a detection script that identifies vulnerable instances via a single anonymous HTTP request to the GlobalProtect prelogin endpoint, extracting both the CAS configuration state and the authoritative PAN-OS version from embedded JWT claims. Patches are available (10.2.18+, 11.1.15+, 11.2.12+, 12.1.7+); workaround is to detach CAS and use SAML, RADIUS, LDAP, or local authentication instead.

TACTA0001SRFNetwork ApplianceTACTA0006SRFWebSWPan OsSWPanoramaVNDPaloaltonetworksTYPResearch
82
Edit Score
2026-05-22
2026-05-22 11:00Z
HIGH

We hardened zizmor's GitHub Actions static analyzer

Trail of Bits·blog.trailofbits.comCVE-2026-33634

Trail of Bits collaborated with zizmor maintainers to harden the GitHub Actions static analyzer against YAML anchor misconfigurations and edge cases. The work involved analyzing 41,253 real-world workflows from 6,612 high-value open-source repositories, fixing 20 bugs (15 merged PRs) including anchor parsing crashes, deserialization issues, and expression evaluator misalignments. This effort directly addresses the attack surface exploited in the March 2026 Trivy supply-chain compromise.

TACTA0001SRFSupply ChainSWGithub ActionsSWZizmorTYPResearchSTGReconTECT1199
78
Edit Score
2026-05-22
2026-05-22 09:12Z
HIGH

Cloud Atlas activity in the second half of 2025 and early 2026: new tools and a new payload

Kaspersky Securelist·securelist.comCVE-2018-0802

Kaspersky reports sustained Cloud Atlas APT activity targeting Russian and Belarusian government and diplomatic entities in H2 2025 and early 2026. The group deployed new tools (PowerCloud, PowerShower, VBCloud backdoors) alongside established techniques including LNK-based phishing, reverse SSH/SOCKS tunneling, Tor exfiltration, and multi-user RDP via termsrv.dll patching. Comprehensive IOCs provided including file hashes, C2 domains, and file paths.

SRFOsTACTA0004TACTA0005TACTA0001TACTA0002SRFNetworkTACTA0006TACTA0007
78
Edit Score
2026-05-22
2026-05-22 07:00Z
CRIT

CVE-2026-27886: Unauthenticated Boolean-Oracle Exfiltration of Administrator Secrets in Strapi

Bishop Fox Labs·bishopfox.comCVE-2026-27886in the wild

CVE-2026-27886 is a critical unauthenticated sanitization bypass in Strapi 4.0.0–5.36.1 that allows attackers to extract administrator secrets via a boolean-oracle attack on the Content API. By crafting malformed `where` clauses that bypass the query sanitizer, an attacker can leak password-reset tokens character-by-character through pagination metadata, then pivot to full Super Admin account takeover using Strapi's legitimate password-recovery endpoints. The vulnerability affects over 20,000 internet-facing instances and was patched in version 5.37.0 on February 26, 2026.

SRFApplicationTACTA0001TACTA0006SRFWebSWStrapiVNDStrapiTYPResearchTYPVulnerability
92
Edit Score
2026-05-22
2026-05-22 05:16Z
HIGH

CVE-2026-9018 — Easy: The Easy Elements for Elementor – Addons & Website Templates plugin for WordPress is

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-9018

The Easy Elements for Elementor – Addons & Website Templates plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.4.5 via the `easyel_handle_register()` function. This is due to the `wp_ajax_nopriv_eel_register` AJAX handler iterating the attacker-controlled `custom_meta` POST array and writing every supplied key-value pair to the newly created user's meta via `update_user_meta()` without any key whitelist or blocklist, allowing t CVSSv3.1 8.8 (HIGH)

CWECWE 269VNDEasyTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-05-22
2026-05-22 04:16Z
CRIT

CVE-2026-46595 — Golang Crypto: Previously, CVE-2024-45337 fixed an authorization bypass for misused ssh server configurations; if any other

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-46595

Previously, CVE-2024-45337 fixed an authorization bypass for misused ssh server configurations; if any other type of callback is passed other than public key, then the source-address validation would be skipped. CVSSv3.1 10.0 (CRITICAL) · EPSS 35th percentile

CWECWE 863CWECWE 303VNDPreviouslyTYPVulnerability
10.0
CVSS v3.1
100
Edit Score
2026-05-22
2026-05-22 04:16Z
CRIT

CVE-2026-42508 — Golang Crypto: Previously, a revoked 'SignatureKey' belonging to a CA was not correctly checked for revocation.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-42508

Previously, a revoked 'SignatureKey' belonging to a CA was not correctly checked for revocation. Now, both the 'key' and 'key.SignatureKey' are checked for @revoked. CVSSv3.1 9.1 (CRITICAL) · EPSS 36th percentile

CWECWE 295VNDPreviouslyTYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2026-05-22
2026-05-22 04:16Z
CRIT

CVE-2026-39834 — Golang Crypto: When writing data larger than 4GB in a single Write call on an SSH

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-39834

When writing data larger than 4GB in a single Write call on an SSH channel, an integer overflow in the internal payload size calculation caused the write loop to spin indefinitely, sending empty packets without making progress. The size comparison now uses int64 to prevent truncation. CVSSv3.1 9.1 (CRITICAL)

CWECWE 190TYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2026-05-22
2026-05-22 04:16Z
CRIT

CVE-2026-39833 — Golang Crypto: The in-memory keyring returned by NewKeyring() silently accepted keys with the ConfirmBeforeUse constraint but

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-39833

The in-memory keyring returned by NewKeyring() silently accepted keys with the ConfirmBeforeUse constraint but never enforced it. The key would sign without any confirmation prompt, with no indication to the caller that the constraint was not in effect. NewKeyring() now returns an error when unsupported constraints are requested. CVSSv3.1 9.1 (CRITICAL)

CWECWE 862TYPVulnerability
9.1
CVSS v3.1
96
Edit Score