2026-05-13
2026-05-13 06:16Z
CRIT

CVE-2026-32661 — Stack: Stack-based buffer overflow vulnerability exists in GUARDIANWALL MailSuite and GUARDIANWALL Mail Security Cloud (SaaS

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-32661

Stack-based buffer overflow vulnerability exists in GUARDIANWALL MailSuite and GUARDIANWALL Mail Security Cloud (SaaS version). If a remote attacker sends a specially crafted request to the product's web service, arbitrary code may be executed when the product is configured to run pop3wallpasswd with grdnwww user privilege. CVSSv3.1 9.8 (CRITICAL)

CWECWE 121VNDStackTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-05-13
2026-05-13 06:16Z
CRIT

CVE-2025-11159 — Hitachi: Vantara Pentaho Data Integration & Analytics of all versions contain a JDBC driver

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2025-11159

Hitachi Vantara Pentaho Data Integration & Analytics of all versions contain a JDBC driver for H2 databases which is vulnerable to external script execution when a new connection is created by a data source administrator. CVSSv3.1 9.1 (CRITICAL)

VNDHitachiTYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2026-05-13
2026-05-13 05:16Z
HIGH

CVE-2026-7635 — Activity: The coreActivity: Activity Logging for WordPress plugin for WordPress is vulnerable to PHP Object

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-7635

The coreActivity: Activity Logging for WordPress plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 3.0. This is due to the plugin failing to validate or strip PHP serialization syntax from the User-Agent HTTP header before storing it in the logmeta table, and subsequently calling `maybe_unserialize()` on every retrieved `meta_value` in `query_metas()` without verifying the data was originally serialized by the application. This m CVSSv3.1 8.1 (HIGH)

CWECWE 502VNDActivityTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-05-13
2026-05-13 04:17Z
HIGH

CVE-2026-8053 — MongoDB: An issue in MongoDB Server's time-series collection implementation allows an authenticated user with database

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-8053

An issue in MongoDB Server's time-series collection implementation allows an authenticated user with database write privileges to trigger an out-of-bounds memory write in the mongod process. The issue results from an inconsistency in the internal field-name-to-index mapping within the time-series bucket catalog. Under certain conditions this can result in arbitrary code execution. This issue impacts MongoDB Server v5.0 versions prior to 5.0.33, v6.0 versions prior to 6.0.28, CVSSv3.1 8.8 (HIGH)

CWECWE 787VNDMongodbTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-05-13
2026-05-13 00:22Z
CRIT

Patch Tuesday - May 2026

Microsoft's May 2026 Patch Tuesday addresses 137 vulnerabilities, including three critical RCEs: CVE-2026-41089 (Netlogon stack buffer overflow, CVSS 9.8, SYSTEM-level execution on domain controllers), CVE-2026-41096 (DNS client RCE, CVSS 9.8), and CVE-2026-41103 (Entra ID auth plugin EoP in self-hosted JIRA/Confluence, CVSS 9.1). Additionally, 133 browser vulnerabilities were patched separately. No active exploitation reported for any vulnerability.

SRFApplicationSRFOsSRFCloudOSWindowsSWAzureSWChromiumSWConfluenceSWEdge
78
Edit Score
2026-05-13
2026-05-13 00:00Z
CRIT

May’s Patch Tuesday hauls out 132 CVEs

Microsoft's May 2026 Patch Tuesday addresses 132 CVEs across 20 product families, including 29 Critical-severity issues and 43 with CVSS scores of 8.0 or higher. Notably, 14 CVEs were pre-patched before Patch Tuesday with no public disclosure or known active exploitation. Key vulnerabilities include authentication bypass in Microsoft SSO plugins for Jira/Confluence (CVE-2026-41103), Windows Netlogon and DNS Client RCEs (CVE-2026-41089, CVE-2026-41096), and six Office/Word RCEs exploitable via Preview Pane.

SRFApplicationSRFOsTACTA0004TACTA0002SRFCloudTACTA0008SWAzureSWOffice
72
Edit Score
2026-05-13
2026-05-13 00:00Z
CRIT

Analyzing TeamPCP’s Supply Chain Attacks: Checkmarx KICS and elementary-data in CI/CD Credential Theft

Trend Micro Research·trendmicro.comin the wild

Trend Micro Research documents TeamPCP, a financially motivated threat actor cluster, conducting a coordinated supply-chain campaign from March–April 2026 targeting seven confirmed waves across multiple package registries (PyPI, Docker Hub, npm, GHCR, VS Code/OpenVSX). The two primary case studies—Checkmarx KICS (April 22) and elementary-data (April 24)—demonstrate multichannel CI/CD poisoning and GitHub Actions script injection respectively, both designed to harvest developer credentials, cloud keys, SSH material, and CI tokens at scale. The elementary-data attack notably required no maintainer credential compromise; a single unsanitized pull-request comment injected into a GitHub Actions workflow was sufficient to forge a signed release and publish malicious packages.

TACTA0001TACTA0002TACTA0006TACTA0007SRFCloudSRFSupply ChainSWBitwardenSWElementary Data
92
Edit Score
728 × 90 / responsive · programmatic ad slot
2026-05-12
2026-05-12 23:16Z
HIGH

CVE-2026-44548 — ChurchCRM: Prior to 7.3.2, top-level cross-site GET navigation from an attacker-controlled page to FundRaiserDelete.php, PropertyTypeDelete.php

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-44548

ChurchCRM is an open-source church management system. Prior to 7.3.2, top-level cross-site GET navigation from an attacker-controlled page to FundRaiserDelete.php, PropertyTypeDelete.php, or NoteDelete.php causes a logged-in ChurchCRM user with the relevant role to silently delete records, including cascaded property and record-to-property assignments. This vulnerability is fixed in 7.3.2. CVSSv3.1 8.1 (HIGH)

CWECWE 352CWECWE 650VNDChurchcrmTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-05-12
2026-05-12 23:16Z
CRIT

CVE-2026-44547 — ChurchCRM: From 7.2.0 to 7.2.2, The fix for CVE-2026-4058 is incomplete.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-44547

ChurchCRM is an open-source church management system. From 7.2.0 to 7.2.2, The fix for CVE-2026-4058 is incomplete. The hardening commit was merged and then silently stripped from src/api/routes/public/public-user.php by an unrelated PR before any 7.2.x tag was cut. Every shipped 7.2.x release therefore remains exploitable by the PoC published with the original advisory. This vulnerability is fixed in 7.3.1. CVSSv3.1 9.6 (CRITICAL)

CWECWE 287CWECWE 304VNDChurchcrmTYPVulnerability
9.6
CVSS v3.1
98
Edit Score
2026-05-12
2026-05-12 23:16Z
HIGH

CVE-2026-42289 — ChurchCRM: Prior to 7.3.2, UserEditor.php processes user account creation and permission updates entirely through $_POST

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-42289

ChurchCRM is an open-source church management system. Prior to 7.3.2, UserEditor.php processes user account creation and permission updates entirely through $_POST parameters with no CSRF token validation. An unauthenticated attacker can craft a malicious HTML page that, when visited by an authenticated administrator, silently elevates any low-privilege user to full administrator or creates a new admin backdoor account without the victim's knowledge This vulnerability is fixe CVSSv3.1 8.8 (HIGH)

CWECWE 352CWECWE 269CWECWE 306VNDChurchcrmTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-05-12
2026-05-12 23:16Z
CRIT

CVE-2026-42288 — ChurchCRM: The pre-authentication remote code execution vulnerability in ChurchCRM's setup wizard via unsanitized DB_PASSWORD remains

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-42288

ChurchCRM is an open-source church management system. Prior to 7.3.2, The fix for CVE-2026-39337 is incomplete. The pre-authentication remote code execution vulnerability in ChurchCRM's setup wizard via unsanitized DB_PASSWORD remains fully exploitable This vulnerability is fixed in 7.3.2. CVSSv3.1 10.0 (CRITICAL)

CWECWE 94VNDChurchcrmTYPVulnerability
10.0
CVSS v3.1
100
Edit Score
2026-05-12
2026-05-12 23:16Z
CRIT

CVE-2026-41901 — Thymeleaf: Prior to 3.1.5.RELEASE, a security bypass vulnerability exists in the expression execution mechanisms of

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-41901

Thymeleaf is a server-side Java template engine for web and standalone environments. Prior to 3.1.5.RELEASE, a security bypass vulnerability exists in the expression execution mechanisms of Thymeleaf. Although the library provides mechanisms to avoid the execution of potentially dangerous expressions in some specific sandboxed (restricted) contexts, it fails to properly neutralize specific constructs that allow this kind of expressions to be executed. If an application develo CVSSv3.1 9.0 (CRITICAL)

CWECWE 1336CWECWE 917VNDThymeleafTYPVulnerability
9.0
CVSS v3.1
95
Edit Score
2026-05-12
2026-05-12 22:16Z
HIGH

CVE-2026-8449 — Linux: ksmbd contains a remote memory corruption vulnerability in the ACL inheritance path that

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-8449

Linux ksmbd contains a remote memory corruption vulnerability in the ACL inheritance path that allows remote clients with directory creation permissions to trigger a heap out-of-bounds read and subsequent heap corruption by setting a crafted DACL with a malformed SID containing an inflated num_subauth field. Attackers can exploit this vulnerability by creating a directory, setting the malicious DACL via SMB2_SET_INFO, and creating child entries to cause kernel instability, de CVSSv3.1 8.8 (HIGH)

CWECWE 125TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-05-12
2026-05-12 22:16Z
HIGH

CVE-2026-45227 — Heym: before 0.0.21 contains a sandbox escape vulnerability in the custom Python tool executor

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-45227

Heym before 0.0.21 contains a sandbox escape vulnerability in the custom Python tool executor that allows authenticated workflow authors to bypass sandbox restrictions by using object-graph introspection primitives. Attackers can use Python introspection techniques to recover the unrestricted __import__ function, import blocked modules such as os and subprocess, and access inherited backend environment variables containing database credentials and encryption keys to execute a CVSSv3.1 8.8 (HIGH)

CWECWE 693VNDHeymTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-05-12
2026-05-12 22:16Z
HIGH

CVE-2026-44304 — Lemur: manages TLS certificate creation.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-44304

Lemur manages TLS certificate creation. Prior to 1.9.0, Lemur's LDAP authentication module (lemur/auth/ldap.py) constructs LDAP search filters using unsanitized user input via Python string interpolation. An authenticated LDAP user can inject LDAP filter metacharacters through the username field to manipulate group membership queries and escalate their privileges to administrator. This vulnerability is fixed in 1.9.0. CVSSv3.1 8.1 (HIGH)

CWECWE 90VNDLemurTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-05-12
2026-05-12 22:16Z
HIGH

CVE-2026-44301 — Gohugo Hugo: As a result, executing hugo against an untrusted site could allow code running through

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-44301

Hugo is a static site generator. From 0.43 to before 0.161.0, when building a Hugo site that uses Node-based asset pipelines (PostCSS, Babel, TailwindCSS), Hugo invoked the configured Node tools without restrictions on file system access. As a result, executing hugo against an untrusted site could allow code running through these tools to read or write files outside the project's working directory. Users who do not use PostCSS, Babel, or TailwindCSS, or who only build trusted CVSSv3.1 8.1 (HIGH)

CWECWE 22VNDGohugoVNDHugoTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-05-12
2026-05-12 22:16Z
CRIT

CVE-2026-44262 — Scramble: generates API documentation for Laravel project.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-44262

Scramble generates API documentation for Laravel project. From 0.13.2 to before 0.13.22, when documentation endpoints are publicly accessible and validation rules reference user-controlled input, request supplied data may be evaluated during documentation generation, leading to execution of arbitrary PHP code in the application context. This vulnerability is fixed in 0.13.22. CVSSv3.1 9.4 (CRITICAL)

CWECWE 94VNDScrambleTYPVulnerability
9.4
CVSS v3.1
97
Edit Score
2026-05-12
2026-05-12 22:16Z
HIGH

CVE-2026-44260 — Enterprise: efw4.X is an Enterprise Framework for Web.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-44260

efw4.X is an Enterprise Framework for Web. Prior to 4.08.010, the readonly flag set on the <efw:elFinder> JSP tag is intended to prevent file modifications. When protected=true, elfinder_checkRisk enforces that the client sends readonly=true (matching the session value), but no event handler checks the readonly value before performing write operations. The flag only controls client-side UI elements (disabling buttons) and response metadata (write: 0, locked: 1). An attacker w CVSSv3.1 8.1 (HIGH)

CWECWE 863VNDEnterpriseTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-05-12
2026-05-12 22:16Z
HIGH

CVE-2026-44015 — Nginx: In 2.3.4 and earlier, an authenticated user can perform Server-Side Request Forgery (SSRF) by

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-44015

Nginx UI is a web user interface for the Nginx web server. In 2.3.4 and earlier, an authenticated user can perform Server-Side Request Forgery (SSRF) by creating a cluster node pointing to an arbitrary internal URL and then sending API requests with the X-Node-ID header. The Proxy middleware forwards these requests to the attacker-specified internal address, bypassing network segmentation and enabling access to services bound to localhost or internal networks. CVSSv3.1 8.5 (HIGH)

CWECWE 918VNDNginxTYPVulnerability
8.5
CVSS v3.1
93
Edit Score
2026-05-12
2026-05-12 22:16Z
CRIT

CVE-2026-43948 — wger is a free, open-source workout and fitness manager.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-43948

wger is a free, open-source workout and fitness manager. Prior to 2.6, the reset_user_password and gym_permissions_user_edit views in wger perform a gym-scope authorization check using Python object comparison (!=) that evaluates None != None as False, silently bypassing the guard when both the attacker and victim have no gym assignment (gym=None). A user with gym.manage_gym permission and gym=None can reset the password of any other gym=None user; the new plaintext password CVSSv3.1 9.9 (CRITICAL)

CWECWE 863TYPVulnerability
9.9
CVSS v3.1
100
Edit Score
2026-05-12
2026-05-12 22:16Z
CRIT

CVE-2026-42854 — Arduino: Sending a boundary string longer than ~8000 characters overflows the 8192-byte task stack of

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-42854

arduino-esp32 is an Arduino core for the ESP32, ESP32-S2, ESP32-S3, ESP32-C3, ESP32-C6 and ESP32-H2 microcontrollers. Prior to 3.3.8, the WebServer multipart form parser in arduino-esp32 allocates a Variable Length Array (VLA) on the stack whose size is derived from an attacker-controlled HTTP header field (Content-Type: multipart/form-data; boundary=...) without enforcing any length limit. Sending a boundary string longer than ~8000 characters overflows the 8192-byte task st CVSSv3.1 9.8 (CRITICAL)

CWECWE 121VNDArduinoTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-05-12
2026-05-12 22:16Z
HIGH

CVE-2026-42844 — Getgrav Grav: This results in full administrative compromise of the Grav API.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-42844

Grav is a file-based Web platform. In Grav 2.0.0-beta.2, a low-privileged authenticated API user with api.media.write can abuse /api/v1/blueprint-upload to write an arbitrary YAML file into user/accounts/, then log in as the newly created account with api.super privileges. This results in full administrative compromise of the Grav API. This vulnerability is fixed in API 1.0.0-beta.17. CVSSv3.1 8.8 (HIGH)

CWECWE 434CWECWE 269VNDGravVNDGetgravTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-05-12
2026-05-12 22:16Z
HIGH

CVE-2026-26289 — PowerSYSTEM: Center REST API endpoint for device account export allows an authenticated user with

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-26289

PowerSYSTEM Center REST API endpoint for device account export allows an authenticated user with limited permissions to expose sensitive information normally restricted to administrative permissions only. CVSSv3.1 8.2 (HIGH)

CWECWE 863VNDPowersystemTYPVulnerability
8.2
CVSS v3.1
91
Edit Score
2026-05-12
2026-05-12 21:16Z
HIGH

CVE-2026-44224 — Requarks Wiki.js: Prior to 2.5.313, the users.update GraphQL mutation accepts an arbitrary groups array and applies

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-44224

Wiki.js is an open source wiki app built on Node.js. Prior to 2.5.313, the users.update GraphQL mutation accepts an arbitrary groups array and applies it directly to the database with no validation of the group IDs supplied. The resolver passes the caller's arguments straight to the model without any ownership check or restriction on which groups can be assigned. A user with manage:users — a permission typically delegated to wiki moderators for account management — can set gr CVSSv3.1 8.8 (HIGH)

CWECWE 269VNDRequarksVNDWikiTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-05-12
2026-05-12 20:16Z
HIGH

CVE-2026-7474 — HashiCorp: Nomad and Nomad Enterprise prior to 2.0.1 are vulnerable to code execution on

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-7474

HashiCorp Nomad and Nomad Enterprise prior to 2.0.1 are vulnerable to code execution on the client host through a path traversal attack. This vulnerability (CVE-2026-7474) is fixed in Nomad 2.0.1, 1.11.5 and 1.10.11. CVSSv3.1 8.8 (HIGH)

CWECWE 22VNDHashicorpTYPVulnerability
8.8
CVSS v3.1
94
Edit Score