2026-05-07
2026-05-07 06:16Z
CRIT

CVE-2026-41586 — Hyperledger Fabric: This is a classic Java deserialization RCE pattern.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-41586

Hyperledger Fabric is an enterprise-grade permissioned distributed ledger framework for developing solutions and applications. From versions 1.0.0 to 2.2.26, Channel.java implements readObject() and exposes deSerializeChannel() which call ObjectInputStream.readObject() on untrusted byte arrays without configuring an ObjectInputFilter. This is a classic Java deserialization RCE pattern. At time of publication, there are no publicly available patches. CVSSv3.1 9.8 (CRITICAL) · EPSS 34th percentile

CWECWE 502VNDHyperledgerTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-05-07
2026-05-07 06:16Z
HIGH

CVE-2026-41143 — YesWiki: Prior to version 4.6.1, YesWiki bazar module contains a SQL injection vulnerability in tools/bazar/services/EntryManager.php

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-41143

YesWiki is a wiki system written in PHP. Prior to version 4.6.1, YesWiki bazar module contains a SQL injection vulnerability in tools/bazar/services/EntryManager.php at line 704. The $data['id_fiche'] value (sourced from $_POST['id_fiche']) is concatenated directly into a raw SQL query without any sanitization or parameterization. This issue has been patched in version 4.6.1. CVSSv3.1 8.8 (HIGH)

CWECWE 89VNDYeswikiTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-05-07
2026-05-07 06:16Z
HIGH

CVE-2026-41139 — Math: From version 13.1.0 to before version 15.2.0, arbitrary JavaScript can be executed via the

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-41139

Math.js is an extensive math library for JavaScript and Node.js. From version 13.1.0 to before version 15.2.0, arbitrary JavaScript can be executed via the expression parser of mathjs. This issue has been patched in version 15.2.0. CVSSv3.1 8.8 (HIGH)

CWECWE 915VNDMathTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-05-07
2026-05-07 04:16Z
CRIT

CVE-2026-42217 — Openexr Openexr: provides the specification and reference implementation of the EXR file format, an image

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-42217

OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the motion picture industry. From versions 3.0.0 to before 3.2.9, 3.3.0 to before 3.3.11, and 3.4.0 to before 3.4.11, readVariableLengthInteger() decodes a variable-length integer from untrusted EXR input without bounding the shift count. After enough continuation bytes, the code executes a left shift by 70 on a 64-bit value, which is undefined behavior. This is CVSSv3.1 9.8 (CRITICAL)

CWECWE 190VNDOpenexrTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-05-07
2026-05-07 04:16Z
CRIT

CVE-2026-42216 — Openexr Openexr: provides the specification and reference implementation of the EXR file format, an image

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-42216

OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the motion picture industry. From versions 3.0.0 to before 3.2.9, 3.3.0 to before 3.3.11, and 3.4.0 to before 3.4.11, IDManifest::init() reconstructs strings from a prefix-compressed representation. If the previous string is longer than 255 bytes, the next string is expected to begin with a 2-byte prefix length. The code reads stringList[i][0] and stringList[i][ CVSSv3.1 9.1 (CRITICAL)

CWECWE 125VNDOpenexrTYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2026-05-07
2026-05-07 04:16Z
HIGH

CVE-2026-41670 — Admidio: Prior to version 5.0.9, the SAML IdP implementation in Admidio's SSO module uses the

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-41670

Admidio is an open-source user management solution. Prior to version 5.0.9, the SAML IdP implementation in Admidio's SSO module uses the AssertionConsumerServiceURL value directly from incoming SAML AuthnRequest messages as the destination for the SAML response, without validating it against the registered ACS URL (smc_acs_url) stored in the database for the corresponding service provider client. An attacker who knows the Entity ID of a registered SP client can craft a SAML A CVSSv3.1 8.2 (HIGH)

CWECWE 20CWECWE 601VNDAdmidioTYPVulnerability
8.2
CVSS v3.1
91
Edit Score
2026-05-07
2026-05-07 04:16Z
HIGH

CVE-2026-41669 — Admidio: Prior to version 5.0.9, the Admidio SAML Identity Provider implementation discards the return value

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-41669

Admidio is an open-source user management solution. Prior to version 5.0.9, the Admidio SAML Identity Provider implementation discards the return value of its validateSignature() method at both call sites (handleSSORequest() line 418 and handleSLORequest() line 613). The method returns error strings on failure rather than throwing exceptions, but the developer believed it would throw (per comments on lines 416 and 611). This means the smc_require_auth_signed configuration opt CVSSv3.1 8.2 (HIGH)

CWECWE 347VNDAdmidioTYPVulnerability
8.2
CVSS v3.1
91
Edit Score
728 × 90 / responsive · programmatic ad slot
2026-05-07
2026-05-07 04:16Z
CRIT

CVE-2026-41201 — CI4MS: In version 0.31.4.0, an attacker can achieve Full Account Takeover & Privilege Escalation via

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-41201

CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorization and theme support. In version 0.31.4.0, an attacker can achieve Full Account Takeover & Privilege Escalation via Stored DOM XSS in backup module filename field manipulated via a sql file that tampers with the file name field to contain hidden XSS payload. This issue has been patched in version 0.31.5.0. CVSSv3.1 9.1 (CRITICAL)

CWECWE 79VNDCi4msTYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2026-05-07
2026-05-07 04:16Z
HIGH

CVE-2026-41142 — OpenEXR: From versions 3.0.0 to before 3.2.9, 3.3.0 to before 3.3.11, and 3.4.0 to before

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-41142

OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the motion picture industry. From versions 3.0.0 to before 3.2.9, 3.3.0 to before 3.3.11, and 3.4.0 to before 3.4.11, there is an integer overflow in ImageChannel::resize that leads to heap OOB write via OpenEXRUtil public API. This issue has been patched in versions 3.2.9, 3.3.11, and 3.4.11. CVSSv3.1 8.8 (HIGH)

CWECWE 190VNDOpenexrTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-05-07
2026-05-07 04:16Z
CRIT

CVE-2026-40982 — Spring: Cloud Config allows applications to serve arbitrary text and binary files through the

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-40982

Spring Cloud Config allows applications to serve arbitrary text and binary files through the spring-cloud-config-server module. A malicious user, or attacker, can send a request using a specially crafted URL that can lead to a directory traversal attack. Spring Cloud Config 3.1.x: affected from 3.1.0 through 3.1.13 (inclusive); upgrade to 3.1.14 or greater (Enterprise Support Only). Spring Cloud Config 4.1.x: affected from 4.1.0 through 4.1.9 (inclusive); upgrade to 4.1.10 or CVSSv3.1 9.1 (CRITICAL)

CWECWE 22VNDSpringTYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2026-05-07
2026-05-07 00:00Z
CRIT

TCLBANKER: Brazilian Banking Trojan Spreading via WhatsApp and Outlook

Elastic Security Labs·elastic.coin the wild

Elastic Security Labs disclosed TCLBANKER, a Brazilian banking trojan distributed via trojanized Logitech MSI installers (DLL sideloading attack). The malware features environment-gated payload decryption, comprehensive anti-analysis watchdog, WPF-based full-screen overlay framework for credential harvesting and social engineering, and self-propagating WhatsApp/Outlook worm modules. The campaign (REF3076) targets 59 Brazilian banking, fintech, and cryptocurrency domains via browser URL monitoring and WebSocket C2, with infrastructure hosted on Cloudflare Workers.

SRFApplicationTACTA0005TACTA0001TACTA0002TACTA0006TACTA0007SRFWebTACTA0003
88
Edit Score
2026-05-07
2026-05-07 00:00Z
HIGH

Donuts and Beagles: Fake Claude site spreads backdoor

Sophos X-Ops·news.sophos.comin the wild

Sophos X-Ops discovered a malvertising campaign distributing a fake Claude AI website (claude-pro[.]com) that delivers a previously undocumented backdoor dubbed 'Beagle' via DLL sideloading. The attack chain uses a legitimate G DATA signed executable (NOVupdate.exe) to load a malicious avk.dll, which decrypts and executes DonutLoader shellcode that ultimately deploys the Beagle backdoor. The campaign shows signs of active exploitation with multiple samples from February–April 2026 using similar infection chains but varying payloads, including AdaptixC2 variants, suggesting either threat actor retooling or TTP imitation.

SRFApplicationTACTA0001TACTA0002SRFWebTACTA0011SWDonutloaderVNDAnthropicTYPVulnerability
76
Edit Score
2026-05-07
2026-05-07 00:00Z
CRIT

TCLBANKER: Brazilian Banking Trojan Spreading via WhatsApp and Outlook

Elastic Security Labs·elastic.coin the wild

Elastic Security Labs disclosed TCLBANKER, a Brazilian banking trojan distributed via trojanized Logitech MSI installers (DLL sideloading of LogiAiPromptBuilder.exe). The malware features environment-gated payload decryption, comprehensive anti-analysis watchdog, WPF-based full-screen overlay framework for social engineering, and self-propagating WhatsApp/Outlook worm modules targeting 59 Brazilian banking and fintech domains. Infrastructure hosted on Cloudflare Workers with developer artifacts suggesting early-stage operations.

SRFApplicationTACTA0005TACTA0001TACTA0002TACTA0006TACTA0007SRFWebTACTA0003
88
Edit Score
2026-05-06
2026-05-06 21:16Z
CRIT

CVE-2026-40281 — Gotenberg: A newline character in a metadata value splits the ExifTool stdin line into two

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-40281

Gotenberg is a Docker-powered stateless API for PDF files. In versions 8.30.1 and earlier, the metadata write endpoint validates metadata keys for control characters but leaves metadata values unsanitized. A newline character in a metadata value splits the ExifTool stdin line into two separate arguments, allowing injection of arbitrary ExifTool pseudo-tags such as -FileName, -Directory, -SymLink, and -HardLink. This is a bypass of the incomplete key-sanitization fix introduce CVSSv3.1 10.0 (CRITICAL)

CWECWE 88VNDGotenbergTYPVulnerability
10.0
CVSS v3.1
100
Edit Score
2026-05-06
2026-05-06 20:16Z
HIGH

CVE-2026-44116 — OpenClaw: before 2026.4.22 contains a server-side request forgery vulnerability in the Zalo plugin's sendPhoto

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-44116

OpenClaw before 2026.4.22 contains a server-side request forgery vulnerability in the Zalo plugin's sendPhoto function that fails to validate outbound photo URLs through the SSRF guard. Attackers can bypass SSRF protection by providing malicious photo URLs to the Zalo Bot API, enabling unauthorized access to internal resources. CVSSv3.1 8.6 (HIGH)

CWECWE 918VNDOpenclawTYPVulnerability
8.6
CVSS v3.1
93
Edit Score
2026-05-06
2026-05-06 20:16Z
HIGH

CVE-2026-44115 — OpenClaw: Attackers can bypass allowlist validation by embedding shell expansion tokens in heredoc bodies to

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-44115

OpenClaw before 2026.4.22 contains an exec allowlist analysis vulnerability allowing shell expansion hiding in unquoted heredoc bodies. Attackers can bypass allowlist validation by embedding shell expansion tokens in heredoc bodies to execute unapproved commands at runtime. CVSSv3.1 8.8 (HIGH)

CWECWE 184VNDOpenclawTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-05-06
2026-05-06 20:16Z
CRIT

CVE-2026-44112 — Openclaw Openclaw: before 2026.4.22 contains a time-of-check/time-of-use race condition in OpenShell sandbox filesystem writes that

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-44112

OpenClaw before 2026.4.22 contains a time-of-check/time-of-use race condition in OpenShell sandbox filesystem writes that allows attackers to redirect writes outside the intended mount root. Attackers can exploit symlink swaps during filesystem operations to bypass sandbox restrictions and write files outside the local mount root. CVSSv3.1 9.6 (CRITICAL)

CWECWE 367VNDOpenclawTYPVulnerability
9.6
CVSS v3.1
98
Edit Score
2026-05-06
2026-05-06 20:16Z
HIGH

CVE-2026-44110 — OpenClaw: before 2026.4.15 contains an authorization bypass vulnerability in Matrix room control-command authorization that

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-44110

OpenClaw before 2026.4.15 contains an authorization bypass vulnerability in Matrix room control-command authorization that trusts DM pairing-store entries. Attackers with DM-paired sender IDs can execute room control commands without being in configured allowlists by posting in bot rooms, potentially enabling privileged OpenClaw behavior. CVSSv3.1 8.8 (HIGH)

CWECWE 863VNDOpenclawTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-05-06
2026-05-06 20:16Z
CRIT

CVE-2026-44109 — OpenClaw: before 2026.4.15 contains an authentication bypass vulnerability in Feishu webhook and card-action validation

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-44109

OpenClaw before 2026.4.15 contains an authentication bypass vulnerability in Feishu webhook and card-action validation that allows unauthenticated requests to reach command dispatch. Missing encryptKey configuration and blank callback tokens fail open instead of rejecting requests, enabling attackers to bypass signature verification and replay protection to execute arbitrary commands. CVSSv3.1 9.8 (CRITICAL)

CWECWE 1188VNDOpenclawTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-05-06
2026-05-06 20:16Z
HIGH

CVE-2026-43585 — OpenClaw: Gateway HTTP and WebSocket handlers fail to re-resolve authentication per-request, enabling attackers to use

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-43585

OpenClaw before 2026.4.15 captures resolved bearer-auth configuration at startup, allowing revoked tokens to remain valid after SecretRef rotation. Gateway HTTP and WebSocket handlers fail to re-resolve authentication per-request, enabling attackers to use rotated-out bearer tokens for unauthorized gateway access. CVSSv3.1 8.1 (HIGH)

CWECWE 672VNDOpenclawTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-05-06
2026-05-06 20:16Z
HIGH

CVE-2026-43584 — OpenClaw: before 2026.4.10 contains an insufficient environment variable denylist vulnerability in its exec environment

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-43584

OpenClaw before 2026.4.10 contains an insufficient environment variable denylist vulnerability in its exec environment policy that allows operator-supplied overrides of high-risk interpreter startup variables including VIMINIT, EXINIT, LUA_INIT, and HOSTALIASES. Attackers can exploit this by manipulating these environment variables to influence downstream execution behavior or network connectivity. CVSSv3.1 8.8 (HIGH)

CWECWE 184VNDOpenclawTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-05-06
2026-05-06 20:16Z
CRIT

CVE-2026-43581 — OpenClaw: before 2026.4.10 contains an improper network binding vulnerability in the sandbox browser CDP

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-43581

OpenClaw before 2026.4.10 contains an improper network binding vulnerability in the sandbox browser CDP relay that exposes Chrome DevTools Protocol on 0.0.0.0. Attackers can access the DevTools protocol outside intended local sandbox boundaries by exploiting the overly broad binding configuration. CVSSv3.1 9.6 (CRITICAL)

CWECWE 1188VNDOpenclawTYPVulnerability
9.6
CVSS v3.1
98
Edit Score
2026-05-06
2026-05-06 20:16Z
CRIT

CVE-2026-43578 — OpenClaw: versions 2026.3.31 before 2026.4.10 contain a privilege escalation vulnerability where heartbeat owner downgrade

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-43578

OpenClaw versions 2026.3.31 before 2026.4.10 contain a privilege escalation vulnerability where heartbeat owner downgrade detection misses local background async exec completion events. Attackers can exploit this by providing untrusted completion content to leave a run in a more privileged context than intended. CVSSv3.1 9.1 (CRITICAL)

CWECWE 184VNDOpenclawTYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2026-05-06
2026-05-06 20:16Z
CRIT

CVE-2026-43575 — OpenClaw: versions 2026.2.21 before 2026.4.10 contain an authentication bypass vulnerability in the sandbox noVNC

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-43575

OpenClaw versions 2026.2.21 before 2026.4.10 contain an authentication bypass vulnerability in the sandbox noVNC helper route that exposes interactive browser session credentials. Attackers can access the noVNC helper route without bridge authentication to gain unauthorized access to the interactive browser session. CVSSv3.1 9.8 (CRITICAL)

CWECWE 862VNDOpenclawTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-05-06
2026-05-06 20:16Z
HIGH

CVE-2026-40076 — Openmrs Openmrs: In versions 2.7.8 and earlier and versions 2.8.0 through 2.8.5, the module upload endpoint

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-40076

OpenMRS Core is an open source electronic medical record system platform. In versions 2.7.8 and earlier and versions 2.8.0 through 2.8.5, the module upload endpoint at POST `/openmrs/ws/rest/v1/module` is vulnerable to a Zip Slip path traversal attack. During automatic extraction of uploaded .omod archives in `WebModuleUtil.startModule()`, ZIP entries under web/module/ are checked only to see whether the full entry path starts with `..,` and the remaining path is then concate CVSSv3.1 8.8 (HIGH)

CWECWE 22VNDOpenmrsTYPVulnerability
8.8
CVSS v3.1
94
Edit Score