2026-05-13
2026-05-13 16:16Z
HIGH

CVE-2026-40631 — Resource: An authenticated attacker with the Resource Administrator or Administrator role can modify configuration objects

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-40631

An authenticated attacker with the Resource Administrator or Administrator role can modify configuration objects through iControl SOAP resulting in privilege escalation.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated. CVSSv3.1 8.7 (HIGH)

CWECWE 552VNDResourceTYPVulnerability
8.7
CVSS v3.1
94
Edit Score
2026-05-13
2026-05-13 16:16Z
HIGH

CVE-2026-40061 — BIG: When BIG-IP DNS is provisioned, a vulnerability exists in an undisclosed iControl REST and

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-40061

When BIG-IP DNS is provisioned, a vulnerability exists in an undisclosed iControl REST and BIG-IP TMOS Shell (tmsh) command that may allow an authenticated attacker with the Resource Administrator or Administrator role to execute arbitrary system commands with higher privileges. In Appliance mode deployments, a successful exploit can allow the attacker to cross a security boundary.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated. CVSSv3.1 8.7 (HIGH)

CWECWE 77VNDBigTYPVulnerability
8.7
CVSS v3.1
94
Edit Score
2026-05-13
2026-05-13 16:16Z
HIGH

CVE-2026-34176 — Appliance: When running in Appliance mode, an authenticated remote command injection vulnerability exists in an

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-34176

When running in Appliance mode, an authenticated remote command injection vulnerability exists in an undisclosed iControl REST endpoint. A successful exploit can allow the attacker to cross a security boundary.   Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated. CVSSv3.1 8.7 (HIGH)

CWECWE 78VNDApplianceTYPVulnerability
8.7
CVSS v3.1
94
Edit Score
2026-05-13
2026-05-13 16:16Z
HIGH

CVE-2026-32673 — BIG: A vulnerability exists in BIG-IP scripted monitors that may allow an authenticated attacker with

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-32673

A vulnerability exists in BIG-IP scripted monitors that may allow an authenticated attacker with the Resource Administrator or Administrator role to execute arbitrary system commands with higher privileges. In appliance mode deployments, a successful exploit can allow the attacker to cross a security boundary.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated. CVSSv3.1 8.7 (HIGH)

CWECWE 250VNDBigTYPVulnerability
8.7
CVSS v3.1
94
Edit Score
2026-05-13
2026-05-13 16:16Z
HIGH

CVE-2026-32643 — BIG: A vulnerability exists in BIG-IP and BIG-IQ systems where a highly privileged, authenticated attacker

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-32643

A vulnerability exists in BIG-IP and BIG-IQ systems where a highly privileged, authenticated attacker with at least the Certificate Manager role can modify configuration objects that allow running arbitrary commands.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated. CVSSv3.1 8.7 (HIGH)

CWECWE 250VNDBigTYPVulnerability
8.7
CVSS v3.1
94
Edit Score
2026-05-13
2026-05-13 16:16Z
HIGH

CVE-2026-20916 — REST: An authenticated iControl REST user with low privileges can create or modify arbitrary files

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-20916

An authenticated iControl REST user with low privileges can create or modify arbitrary files through an undisclosed iControl REST endpoint on the BIG-IQ system.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated. CVSSv3.1 8.1 (HIGH)

CWECWE 22VNDRestTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-05-13
2026-05-13 16:16Z
HIGH

CVE-2020-37221 — Atomic: Alarm Clock 6.3 contains a stack overflow vulnerability that allows local attackers to

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2020-37221

Atomic Alarm Clock 6.3 contains a stack overflow vulnerability that allows local attackers to execute arbitrary code by supplying a malicious string to the display name textbox in the Time Zones Clock configuration. Attackers can craft a buffer with structured exception handling overwrite and encoded shellcode to bypass SafeSEH protections and execute arbitrary commands with application privileges. CVSSv3.1 8.4 (HIGH)

CWECWE 121VNDAtomicTYPVulnerability
8.4
CVSS v3.1
92
Edit Score
728 × 90 / responsive · programmatic ad slot
2026-05-13
2026-05-13 16:16Z
HIGH

CVE-2020-37218 — Joomla: com_hdwplayer 4.2 contains an SQL injection vulnerability in the search.php file that allows

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2020-37218

Joomla com_hdwplayer 4.2 contains an SQL injection vulnerability in the search.php file that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the hdwplayersearch parameter. Attackers can submit POST requests with crafted SQL payloads in the hdwplayersearch parameter to extract sensitive database information from the hdwplayer_videos table. CVSSv3.1 8.2 (HIGH)

CWECWE 89VNDJoomlaTYPVulnerability
8.2
CVSS v3.1
91
Edit Score
2026-05-13
2026-05-13 16:16Z
CRIT

CVE-2020-37168 — Ecommerce: Systempay 1.0 contains a weak cryptographic implementation vulnerability that allows attackers to brute

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2020-37168

Ecommerce Systempay 1.0 contains a weak cryptographic implementation vulnerability that allows attackers to brute force the 16-character production secret key used for payment signature generation. Attackers can extract payment form data and signatures from POST requests to the payment endpoint, then use SHA1 hash comparison to iteratively test key candidates until discovering the correct production key, enabling them to forge valid payment signatures and manipulate transacti CVSSv3.1 9.8 (CRITICAL)

CWECWE 328VNDEcommerceTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-05-13
2026-05-13 14:44Z
CRIT

When IT Support Calls: Dissecting a ModeloRAT Campaign from Teams to Domain Compromise

Rapid7 Research·rapid7.comCVE-2023-36036in the wild

Rapid7 analyzed a ModeloRAT campaign that began with Teams social engineering impersonating IT Support and escalated to full domain compromise. The attack chain leveraged a Dropbox-hosted Python payload, CVE-2023-36036 privilege escalation via cldflt.sys heap overflow, credential harvesting via fake lock screen, and lateral movement across 100+ internal systems. The intrusion demonstrates how collaboration platforms, Living-off-the-Land techniques, and patched vulnerabilities can be chained into rapid enterprise-wide compromise.

SRFApplicationTACTA0004TACTA0005TACTA0001TACTA0002TACTA0006TACTA0007SRFIdentity
92
Edit Score
2026-05-13
2026-05-13 13:16Z
CRIT

CVE-2026-42062 — ELECOM: wireless LAN access point devices contain an OS command injection in processing of

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-42062

ELECOM wireless LAN access point devices contain an OS command injection in processing of username parameter. If processing a crafted request, an arbitrary OS command may be executed. No authentication is required. CVSSv3.1 9.8 (CRITICAL)

CWECWE 78VNDElecomTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-05-13
2026-05-13 13:16Z
CRIT

CVE-2026-40621 — ELECOM: wireless LAN access point devices do not require authentication to access some specific

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-40621

ELECOM wireless LAN access point devices do not require authentication to access some specific URLs. The affected product may be operated without authentication. CVSSv3.1 9.8 (CRITICAL)

CWECWE 288VNDElecomTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-05-13
2026-05-13 13:16Z
HIGH

CVE-2026-3425 — RTMKit: The RTMKit Addons for Elementor plugin for WordPress is vulnerable to Local File Inclusion

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-3425

The RTMKit Addons for Elementor plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 2.0.2 via the 'path' parameter of the 'get_content' AJAX action. This makes it possible for authenticated attackers, with Author-level access and above, to include and execute arbitrary PHP files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code ex CVSSv3.1 8.8 (HIGH)

CWECWE 98VNDRtmkitTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-05-13
2026-05-13 13:00Z
HIGH

Otto-Support: Supply Chain Risks in MCP Servers

Bishop Fox Labs·bishopfox.comin the wild

Bishop Fox Labs published research on supply chain risks in MCP (Model Context Protocol) servers, demonstrating how malicious updates can exfiltrate sensitive credentials while maintaining normal functionality. The analysis covers real incidents (postmark-mcp BCC injection, ClawHub malicious skills) and introduces otto-support's selfpwn module to quantify the attack surface—showing SSH keys, cloud credentials, API tokens, and wallet keys accessible to any MCP server running under the user's context. Mitigations include version pinning, internal registries, signed plugins, and network egress controls.

SRFApplicationTACTA0001TACTA0006SRFSupply ChainSWClawhubSWOtto SupportSWPostmark McpTYPResearch
78
Edit Score
2026-05-13
2026-05-13 12:02Z
HIGH

From Patch Tuesday to Pentest Wednesday®: How a Software Provider Closed Unknown Paths to Cloud Compromise

Horizon3.ai·horizon3.ai

A healthcare software provider conducted an insider threat pentest using NodeZero that exposed how a single compromised developer credential could chain multiple weaknesses into lateral movement across segmented networks and AWS compromise. Initial testing identified 16 exploitable weaknesses leading to AWS full account compromise and sensitive data exposure; post-remediation reduced to 2 low-severity findings with no business impact through continuous monthly testing cycles and privileged access controls.

TACTA0004TACTA0001SRFIdentitySRFCloudTACTA0008TYPResearchTYPWriteupSTGPrivesc
62
Edit Score
2026-05-13
2026-05-13 08:16Z
CRIT

CVE-2026-41050 — Helm: Fleet's Helm deployer did not fully apply ServiceAccount impersonation in two code paths, allowing

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-41050

Fleet's Helm deployer did not fully apply ServiceAccount impersonation in two code paths, allowing a tenant with git push access to a Fleet-monitored repository to read secrets from any namespace on every downstream cluster targeted by their `GitRepo`. CVSSv3.1 9.9 (CRITICAL)

CWECWE 863VNDHelmTYPVulnerability
9.9
CVSS v3.1
100
Edit Score
2026-05-13
2026-05-13 08:16Z
HIGH

CVE-2026-25705 — A vulnerability has been identified in [Rancher's Extensions](https://ranchermanager.docs.rancher.com/integrations-in-rancher/rancher-extensions) where malicious code can be injected

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-25705

A vulnerability has been identified in [Rancher's Extensions](https://ranchermanager.docs.rancher.com/integrations-in-rancher/rancher-extensions) where malicious code can be injected in Rancher through a path traversal in the `compressedEndpoint` field inside a `UIPlugin` deployment. A malicious UI extension could abuse that to: * Overwrite Rancher binaries or configuration to inject code. * Write to /var/lib/rancher/ to tamper with cluster state. * If hostPath volu CVSSv3.1 8.4 (HIGH)

CWECWE 35TYPVulnerability
8.4
CVSS v3.1
92
Edit Score
2026-05-13
2026-05-13 07:00Z
CRIT

A 0-click exploit chain for the Pixel 10: When a Door Closes, a Window Opens

Project Zero·googleprojectzero.blogspot.comCVE-2025-549570day

Project Zero disclosed a 0-click exploit chain for Pixel 10 combining a patched Dolby UDC vulnerability (CVE-2025-54957) with a novel VPU driver vulnerability. The VPU mmap handler fails to bound physical memory mapping to the register region size, allowing arbitrary kernel memory read-write with 5 lines of code. The VPU bug was patched 71 days after disclosure in February 2026, demonstrating improved Android triage velocity.

SRFOsTACTA0004TACTA0005SRFHardwareOSAndroidVNDGoogleTYPResearchTYPWriteup
95
Edit Score
2026-05-13
2026-05-13 06:16Z
CRIT

CVE-2026-32661 — Stack: Stack-based buffer overflow vulnerability exists in GUARDIANWALL MailSuite and GUARDIANWALL Mail Security Cloud (SaaS

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-32661

Stack-based buffer overflow vulnerability exists in GUARDIANWALL MailSuite and GUARDIANWALL Mail Security Cloud (SaaS version). If a remote attacker sends a specially crafted request to the product's web service, arbitrary code may be executed when the product is configured to run pop3wallpasswd with grdnwww user privilege. CVSSv3.1 9.8 (CRITICAL)

CWECWE 121VNDStackTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-05-13
2026-05-13 06:16Z
CRIT

CVE-2025-11159 — Hitachi: Vantara Pentaho Data Integration & Analytics of all versions contain a JDBC driver

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2025-11159

Hitachi Vantara Pentaho Data Integration & Analytics of all versions contain a JDBC driver for H2 databases which is vulnerable to external script execution when a new connection is created by a data source administrator. CVSSv3.1 9.1 (CRITICAL)

VNDHitachiTYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2026-05-13
2026-05-13 05:16Z
HIGH

CVE-2026-7635 — Activity: The coreActivity: Activity Logging for WordPress plugin for WordPress is vulnerable to PHP Object

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-7635

The coreActivity: Activity Logging for WordPress plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 3.0. This is due to the plugin failing to validate or strip PHP serialization syntax from the User-Agent HTTP header before storing it in the logmeta table, and subsequently calling `maybe_unserialize()` on every retrieved `meta_value` in `query_metas()` without verifying the data was originally serialized by the application. This m CVSSv3.1 8.1 (HIGH)

CWECWE 502VNDActivityTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-05-13
2026-05-13 04:17Z
HIGH

CVE-2026-8053 — MongoDB: An issue in MongoDB Server's time-series collection implementation allows an authenticated user with database

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-8053

An issue in MongoDB Server's time-series collection implementation allows an authenticated user with database write privileges to trigger an out-of-bounds memory write in the mongod process. The issue results from an inconsistency in the internal field-name-to-index mapping within the time-series bucket catalog. Under certain conditions this can result in arbitrary code execution. This issue impacts MongoDB Server v5.0 versions prior to 5.0.33, v6.0 versions prior to 6.0.28, CVSSv3.1 8.8 (HIGH)

CWECWE 787VNDMongodbTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-05-13
2026-05-13 00:22Z
CRIT

Patch Tuesday - May 2026

Microsoft's May 2026 Patch Tuesday addresses 137 vulnerabilities, including three critical RCEs: CVE-2026-41089 (Netlogon stack buffer overflow, CVSS 9.8, SYSTEM-level execution on domain controllers), CVE-2026-41096 (DNS client RCE, CVSS 9.8), and CVE-2026-41103 (Entra ID auth plugin EoP in self-hosted JIRA/Confluence, CVSS 9.1). Additionally, 133 browser vulnerabilities were patched separately. No active exploitation reported for any vulnerability.

SRFApplicationSRFOsSRFCloudOSWindowsSWAzureSWChromiumSWConfluenceSWEdge
78
Edit Score
2026-05-13
2026-05-13 00:00Z
CRIT

May’s Patch Tuesday hauls out 132 CVEs

Microsoft's May 2026 Patch Tuesday addresses 132 CVEs across 20 product families, including 29 Critical-severity issues and 43 with CVSS scores of 8.0 or higher. Notably, 14 CVEs were pre-patched before Patch Tuesday with no public disclosure or known active exploitation. Key vulnerabilities include authentication bypass in Microsoft SSO plugins for Jira/Confluence (CVE-2026-41103), Windows Netlogon and DNS Client RCEs (CVE-2026-41089, CVE-2026-41096), and six Office/Word RCEs exploitable via Preview Pane.

SRFApplicationSRFOsTACTA0004TACTA0002SRFCloudTACTA0008SWAzureSWOffice
72
Edit Score
2026-05-13
2026-05-13 00:00Z
CRIT

Analyzing TeamPCP’s Supply Chain Attacks: Checkmarx KICS and elementary-data in CI/CD Credential Theft

Trend Micro Research·trendmicro.comin the wild

Trend Micro Research documents TeamPCP, a financially motivated threat actor cluster, conducting a coordinated supply-chain campaign from March–April 2026 targeting seven confirmed waves across multiple package registries (PyPI, Docker Hub, npm, GHCR, VS Code/OpenVSX). The two primary case studies—Checkmarx KICS (April 22) and elementary-data (April 24)—demonstrate multichannel CI/CD poisoning and GitHub Actions script injection respectively, both designed to harvest developer credentials, cloud keys, SSH material, and CI tokens at scale. The elementary-data attack notably required no maintainer credential compromise; a single unsanitized pull-request comment injected into a GitHub Actions workflow was sufficient to forge a signed release and publish malicious packages.

TACTA0001TACTA0002TACTA0006TACTA0007SRFCloudSRFSupply ChainSWBitwardenSWElementary Data
92
Edit Score