2026-05-19
2026-05-19 04:16Z
HIGH

CVE-2026-24792 — OpenHarmony: in OpenHarmony v6.0 and prior versions allow a remote attacker arbitrary code execution in

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-24792

in OpenHarmony v6.0 and prior versions allow a remote attacker arbitrary code execution in pre-installed apps. CVSSv3.1 8.1 (HIGH)

CWECWE 364VNDOpenharmonyTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-05-19
2026-05-19 00:00Z
HIGH

WantToCry ransomware remotely encrypts files

Sophos X-Ops·news.sophos.comin the wild

Sophos CTU researchers documented WantToCry ransomware campaigns that abuse exposed SMB services for initial access via brute-force attacks, then exfiltrate and remotely encrypt files on attacker infrastructure before rewriting encrypted data back to victims' systems via authenticated SMB sessions. The threat actors use segmented infrastructure across multiple countries and demand modest ransoms ($400–$1,800), with no evidence of double-extortion tactics or post-compromise lateral movement.

TACTA0001SRFNetworkSRFNetwork ApplianceTACTA0007SWWannacryVNDSophosTYPThreat IntelSTGInitial Access
72
Edit Score
2026-05-19
2026-05-19 00:00Z
CRIT

Inside SHADOW-WATER-063’s Banana RAT: From Build Server to Banking Fraud

Trend Micro Research·trendmicro.comin the wild

Trend Micro MDR researchers mapped the complete operational infrastructure of Banana RAT, a Brazilian banking trojan attributed to SHADOW-WATER-063, by recovering both attacker server-side tooling and victim-side telemetry. The malware uses a FastAPI-based polymorphic crypter generating 100–200 unique AES-wrapped builds per delivery folder, fileless PowerShell execution, and modular .NET DLLs to enable screen streaming, keylogging, remote input control, and PIX QR code interception targeting 16 Brazilian financial institutions. The attack chain spans WhatsApp/phishing lures, staged batch-file execution, in-memory payload decryption, scheduled-task persistence, and active C&C communication on port 443.

SRFApplicationTACTA0005TACTA0001TACTA0002TACTA0006TACTA0007SRFWebTACTA0003
88
Edit Score
2026-05-18
2026-05-18 22:00Z
CRIT

How OLTs may have exposed entire ISP networks

Quarkslab·blog.quarkslab.com

Quarkslab disclosed multiple unauthenticated remote code execution vulnerabilities in VSOL GPON OLT devices and their Cloud EMS fleet management platform. The attack chain begins with exploiting pre-auth command injection flaws in OLT traceroute and TACACS+ features, escalates via unauthenticated arbitrary file upload in Cloud EMS (JSP webshell), and enables complete ISP network takeover. Default credentials (admin/Xpon@Olt9417#) hardcoded across firmware binaries compound the risk.

TACTA0001TACTA0002SRFNetworkSRFNetwork ApplianceTACTA0003TACTA0008SWCloud EmsVNDVsol
92
Edit Score
2026-05-18
2026-05-18 21:16Z
HIGH

CVE-2026-8851 — SOGo: 5.12.7 contains a SQL injection vulnerability in the Access Control List management functionality

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-8851

SOGo 5.12.7 contains a SQL injection vulnerability in the Access Control List management functionality that allows authenticated users to extract arbitrary data from the database by injecting SQL subqueries through the uid parameter of the addUserInAcls endpoint. Attackers can inject malicious SQL code to write extracted data into the sogo_acl table and retrieve it through the /acls API, establishing an out-of-band data exfiltration channel. CVSSv3.1 8.1 (HIGH)

CWECWE 89VNDSogoTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-05-18
2026-05-18 21:16Z
CRIT

CVE-2026-8838 — Unsafe: use of Python's eval() on server-received data in the vector_in() function in amazon-redshift-python-driver

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-8838

Unsafe use of Python's eval() on server-received data in the vector_in() function in amazon-redshift-python-driver before 2.1.14 allows a rogue server or man-in-the-middle actor to execute arbitrary code on the client. To remediate this issue, users should upgrade to version 2.1.14. CVSSv3.1 9.8 (CRITICAL)

CWECWE 94VNDUnsafeTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-05-18
2026-05-18 21:16Z
CRIT

CVE-2026-27130 — Dokploy: Versions 0.26.6 and below have OS command injection through the appName parameter.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-27130

Dokploy is a free, self-hostable Platform as a Service (PaaS). Versions 0.26.6 and below have OS command injection through the appName parameter. 3 chained issues cause this problem: inadequate input sanitization, lack of schema validation and direct shell interpolation. User-controlled application names are passed through inadequate sanitization (cleanAppName function only replaces spaces and converts to lowercase) before being interpolated directly into shell commands execu CVSSv3.1 9.9 (CRITICAL)

CWECWE 78VNDDokployTYPVulnerability
9.9
CVSS v3.1
100
Edit Score
728 × 90 / responsive · programmatic ad slot
2026-05-18
2026-05-18 21:16Z
CRIT

CVE-2026-25244 — WebdriverIO: Versions below 9.24.0 contain a command injection vulnerability leading to remote code execution (RCE)

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-25244

WebdriverIO is a test automation framework for unit, e2e and component testing using WebDriver, WebDriver BiDi and Appium. Versions below 9.24.0 contain a command injection vulnerability leading to remote code execution (RCE) in test orchestration. Git permits branch names containing shell metacharacters, and getGitMetadataForAISelection() interpolates these names directly into execSync() calls without sanitization. An attacker can exploit this by supplying a malicious reposi CVSSv3.1 9.8 (CRITICAL)

CWECWE 78VNDWebdriverioTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-05-18
2026-05-18 21:16Z
HIGH

CVE-2026-22810 — Joplin: Versions prior to 3.5.7 contain a path traversal vulnerability in the importer which allows

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-22810

Joplin is an open source note-taking and to-do application that organises notes and lists into notebooks. Versions prior to 3.5.7 contain a path traversal vulnerability in the importer which allows overwriting arbitrary files on disk. The OneNote converter does not sanitize the names of embedded files before writing them to disk. As a result, it's possible for an attacker to create a malicious .one file that includes file names containing ../../, that are then interpreted as CVSSv3.1 8.2 (HIGH)

CWECWE 24VNDJoplinTYPVulnerability
8.2
CVSS v3.1
91
Edit Score
2026-05-18
2026-05-18 19:16Z
CRIT

CVE-2026-8836 — Performing a manipulation of the argument msgAuthenticationParameters results in stack-based buffer overflow.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-8836

A vulnerability was found in lwIP up to 2.2.1. Affected is the function snmp_parse_inbound_frame of the file src/apps/snmp/snmp_msg.c of the component snmpv3 USM Handler. Performing a manipulation of the argument msgAuthenticationParameters results in stack-based buffer overflow. The attack may be initiated remotely. The patch is named 0c957ec03054eb6c8205e9c9d1d05d90ada3898c. It is suggested to install a patch to address this issue. CVSSv3.1 9.8 (CRITICAL)

CWECWE 121CWECWE 119TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-05-18
2026-05-18 18:17Z
HIGH

CVE-2026-45495 — Microsoft: Edge (Chromium-based) Remote Code Execution Vulnerability

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-45495

Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability CVSSv3.1 8.8 (HIGH)

CWECWE 94CWECWE 20CWECWE 119VNDMicrosoftTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-05-18
2026-05-18 18:17Z
CRIT

CVE-2026-45230 — DumbAssets: through 1.0.11 contains a path traversal vulnerability in the POST /api/delete-file endpoint and

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-45230

DumbAssets through 1.0.11 contains a path traversal vulnerability in the POST /api/delete-file endpoint and filesToDelete array parameters that allows unauthenticated attackers to delete arbitrary files by supplying ../ sequences that bypass directory boundary validation. Attackers can exploit the optional and disabled-by-default authentication control to traverse outside the intended application directory and delete critical files such as server.js or package.json, causing c CVSSv3.1 9.1 (CRITICAL)

CWECWE 22VNDDumbassetsTYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2026-05-18
2026-05-18 18:17Z
CRIT

CVE-2026-42822 — Azure: Improper authentication in Azure Local Disconnected Operations allows an unauthorized attacker to elevate privileges

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-42822

Improper authentication in Azure Local Disconnected Operations allows an unauthorized attacker to elevate privileges over a network. CVSSv3.1 10.0 (CRITICAL)

CWECWE 287VNDAzureTYPVulnerability
10.0
CVSS v3.1
100
Edit Score
2026-05-18
2026-05-18 18:17Z
CRIT

CVE-2023-24215 — Incorrect: access control in the /uci/get/ endpoint of NOVUS AirGate 4G firmware v1.1.16 allows

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2023-24215

Incorrect access control in the /uci/get/ endpoint of NOVUS AirGate 4G firmware v1.1.16 allows unauthenticated attackers to obtain administrator credentials via a crafted POST request. CVSSv3.1 9.1 (CRITICAL)

CWECWE 284TYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2026-05-18
2026-05-18 17:58Z
INFO

v9.2.0-rc1

BloodHound releases·github.comCVE-2026-6321

BloodHound v9.2.0-rc1 release candidate published with 50+ commits including bug fixes, UI/UX improvements, API enhancements, and a fix for CVE-2026-6321 in the fast-uri dependency. Changes span graph schema refactoring, Cypher query fixes, new filtering endpoints, Prometheus metrics exposure, and permission tightening.

SWBloodhoundVNDSpecteropsTYPTool
35
Edit Score
2026-05-18
2026-05-18 17:33Z
INFO

v9.2.0

BloodHound releases·github.comCVE-2026-6321

BloodHound v9.2.0 released with 50+ commits including bug fixes, UI improvements, and new features. Notable changes include Prometheus metrics exposure, findings endpoint, graph schema refactoring, and a fix for CVE-2026-6321 in the fast-uri dependency.

SWBloodhoundVNDSpecteropsTYPTool
42
Edit Score
2026-05-18
2026-05-18 17:16Z
CRIT

CVE-2026-45829 — A pre-authentication, code injection vulnerability in version 1.0.0 or later of the ChromaDB Python

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-45829

A pre-authentication, code injection vulnerability in version 1.0.0 or later of the ChromaDB Python project allows an unauthenticated attacker to run arbitrary code on the server by sending a malicious model repository and trust_remote_code set to true in the /api/v2/tenants/{tenant}/databases/{db}/collections endpoint. CVSSv3.1 10.0 (CRITICAL) · EPSS 95th percentile

CWECWE 94CWECWE 502TYPVulnerability
10.0
CVSS v3.1
100
Edit Score
2026-05-18
2026-05-18 17:16Z
HIGH

CVE-2026-41085 — Thermo: Fisher Scientific Torrent Suite Dx through 5.14.2 has a privilege escalation vulnerability that

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-41085

Thermo Fisher Scientific Torrent Suite Dx through 5.14.2 has a privilege escalation vulnerability that may allow an authenticated user with limited access privileges to gain unauthorized administrator-level privileges through exploitation of specific system interfaces. CVSSv3.1 8.8 (HIGH)

CWECWE 269VNDThermoTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-05-18
2026-05-18 16:16Z
HIGH

CVE-2025-57282 — ngrok v4.3.3 and 5.0.0-beta.2 is vulnerable to Command Injection.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2025-57282

ngrok v4.3.3 and 5.0.0-beta.2 is vulnerable to Command Injection. CVSSv3.1 8.8 (HIGH)

CWECWE 77TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-05-18
2026-05-18 15:16Z
CRIT

CVE-2026-41948 — Dify Dify: version 1.14.1 and prior contain a path traversal vulnerability that allows authenticated users

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-41948

Dify version 1.14.1 and prior contain a path traversal vulnerability that allows authenticated users to manipulate requests forwarded to the Plugin Daemon's internal REST API by exploiting insufficient URL path sanitization. Attackers can traverse out of their authorized tenant path using unencoded dot sequences in task identifiers or manipulated filename parameters to access internal endpoints such as debug interfaces, requiring only knowledge of the victim tenant's UUID. NO CVSSv3.1 9.4 (CRITICAL)

CWECWE 23VNDDifyTYPVulnerability
9.4
CVSS v3.1
97
Edit Score
2026-05-18
2026-05-18 15:16Z
CRIT

CVE-2026-41947 — Dify Dify: before version 1.14.2 contains an authorization bypass vulnerability that allows authenticated editor users

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-41947

Dify before version 1.14.2 contains an authorization bypass vulnerability that allows authenticated editor users to set and enable trace configurations for any application regardless of tenant ownership. Attackers can exploit missing tenant ownership checks in the trace configuration endpoints to redirect all messages and responses from victim applications to attacker-controlled LLM trace providers. NOTE: Dify Cloud allows unauthenticated free self-registration, making accoun CVSSv3.1 9.1 (CRITICAL)

CWECWE 639VNDDifyTYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2026-05-18
2026-05-18 12:16Z
CRIT

CVE-2026-7304 — SGLangs: multimodal generation runtime is vulnerable to unauthenticated remote code execution when the --enable-custom-logit-processor

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-7304

SGLangs multimodal generation runtime is vulnerable to unauthenticated remote code execution when the --enable-custom-logit-processor option is enabled, as Python objects loaded via dill.loads() will be deserialized without validation. CVSSv3.1 9.8 (CRITICAL)

CWECWE 502VNDSglangsTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-05-18
2026-05-18 12:16Z
CRIT

CVE-2026-7302 — SGLangs: multimodal generation runtime is vulnerable to an unauthenticated path traversal vulnerability, allowing an

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-7302

SGLangs multimodal generation runtime is vulnerable to an unauthenticated path traversal vulnerability, allowing an attacker to write arbitrary files anywhere the server process has write access, by including ../ sequences in the upload filename when sent to specific endpoints. CVSSv3.1 9.1 (CRITICAL)

CWECWE 35VNDSglangsTYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2026-05-18
2026-05-18 12:16Z
CRIT

CVE-2026-7301 — SGLangs: multimodal generation runtime scheduler's ROUTER socket binds to 0.0.0.0 by default and contains

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-7301

SGLangs multimodal generation runtime scheduler's ROUTER socket binds to 0.0.0.0 by default and contains a sink that calls pickle.loads() on incoming messages, enabling RCE when exposed to the internet. CVSSv3.1 9.8 (CRITICAL)

CWECWE 502VNDSglangsTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-05-18
2026-05-18 12:00Z
HIGH

IT threat evolution in Q1 2026. Mobile statistics

Kaspersky Securelist·securelist.com

Kaspersky's Q1 2026 mobile threat report documents 2.67M prevented attacks, with Trojan-Banker malware accounting for 10.86% of detections and 162,275 malicious banking packages discovered. Key findings include the rise of Mamont banking Trojan variants (73.5% of banker detections), pre-installed Triada backdoors across device ranges, and discovery of SparkCat crypto stealer variants on Google Play and App Store using custom Dalvik-like VMs and Apple Vision framework for OCR.

SRFMobileOSAndroidOSIosSWApp StoreSWGoogle PlayVNDKasperskyTYPThreat Intel
72
Edit Score