2026-04-28
2026-04-28 19:37Z
CRIT

CVE-2026-3893 — Carlson: The Carlson VASCO-B GNSS Receiver lacks an authentication mechanism, allowing an attacker with network

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-3893

The Carlson VASCO-B GNSS Receiver lacks an authentication mechanism, allowing an attacker with network access to directly access and modify its configuration and operational functions without needing credentials. CVSSv3.1 9.4 (CRITICAL)

CWECWE 306VNDCarlsonTYPVulnerability
9.4
CVSS v3.1
97
Edit Score
2026-04-28
2026-04-28 19:37Z
HIGH

CVE-2026-38949 — Site: Cross-Site Scripting (XSS) vulnerability exists in HTMLy version 3.1.1 in the content creation functionality

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-38949

Cross-Site Scripting (XSS) vulnerability exists in HTMLy version 3.1.1 in the content creation functionality at the /add/content?type=image endpoint. The application fails to properly sanitize user input, allowing injection of arbitrary code CVSSv3.1 8.9 (HIGH) · EPSS 6th percentile

CWECWE 79TYPVulnerability
8.9
CVSS v3.1
95
Edit Score
2026-04-28
2026-04-28 19:36Z
HIGH

CVE-2026-24222 — NVIDIA: A successful exploit of this vulnerability might lead to information disclosure.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-24222

NVIDIA NeMoClaw contains a vulnerability in the sandbox environment initialization component, where a remote attacker could cause improper access control by sending prompt-injected content that causes the agent to read and exfiltrate host environment variables not properly restricted during sandbox creation. A successful exploit of this vulnerability might lead to information disclosure. CVSSv3.1 8.6 (HIGH)

CWECWE 497VNDNvidiaTYPVulnerability
8.6
CVSS v3.1
93
Edit Score
2026-04-28
2026-04-28 19:36Z
HIGH

CVE-2026-24186 — NVIDIA: FLARE SDK contains a vulnerability in FOBS, where an attacker may cause deserialization

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-24186

NVIDIA FLARE SDK contains a vulnerability in FOBS, where an attacker may cause deserialization of untrusted data by sending a malicious FOBS- encoded message. A successful exploit of this vulnerability might lead to code execution. CVSSv3.1 8.8 (HIGH)

CWECWE 502VNDNvidiaTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-04-28
2026-04-28 19:36Z
CRIT

CVE-2026-24178 — NVIDIA: NVFlare Dashboard contains a vulnerability in the user management and authentication system where

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-24178

NVIDIA NVFlare Dashboard contains a vulnerability in the user management and authentication system where an unauthenticated attacker may cause authorization bypass through user-controlled key. A successful exploit of this vulnerability may lead to privilege escalation, data tampering, information disclosure, code execution, and denial of service. CVSSv3.1 9.8 (CRITICAL)

CWECWE 639VNDNvidiaTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-04-28
2026-04-28 17:35Z
INFO

v9.1.0-rc1

BloodHound releases·github.com

BloodHound v9.1.0-rc1 released with incremental UI/UX improvements, bug fixes, and backend refactoring. Changes include PDF attack paths table, OpenGraph extension permissions, improved component library (Doodle UI), database pooling enhancements for IAM RDS auth, and various post-processing migrations to DCA.

SWBloodhoundTYPTool
35
Edit Score
2026-04-28
2026-04-28 16:16Z
CRIT

CVE-2026-41873 — Apache Pony_mail: ** UNSUPPORTED WHEN ASSIGNED ** Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') vulnerability

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-41873

** UNSUPPORTED WHEN ASSIGNED ** Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') vulnerability in Pony Mail leading to admin account takeover. This issue affects all versions of the Lua implementation of Pony Mail. There is a Python implementation under development under the name "Pony Mail Foal" that is not affected by this issue, but hasn't been released yet. As the Lua implementation of this project is retired, we do not plan to release a CVSSv3.1 9.8 (CRITICAL)

CWECWE 444VNDApacheVNDUnsupportedTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
728 × 90 / responsive · programmatic ad slot
2026-04-28
2026-04-28 16:16Z
HIGH

CVE-2026-38651 — Authentication: Bypass vulnerability exists in Netmaker versions prior to 1.5.0.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-38651

Authentication Bypass vulnerability exists in Netmaker versions prior to 1.5.0. The VerifyHostToken function in logic/jwts.go fails to validate the JWT signature when verifying host tokens. An attacker can forge a JWT signed with any arbitrary key and use it to impersonate any host in the network, gaining access to sensitive information CVSSv3.1 8.2 (HIGH)

CWECWE 347TYPVulnerability
8.2
CVSS v3.1
91
Edit Score
2026-04-28
2026-04-28 16:16Z
CRIT

CVE-2025-60889 — Insecure deserialization of untrusted input in StellarGroup HPX 1.11.0 under certain conditions may allow

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2025-60889

Insecure deserialization of untrusted input in StellarGroup HPX 1.11.0 under certain conditions may allow attackers to execute arbitrary code or other unspecified impacts. CVSSv3.1 9.8 (CRITICAL)

CWECWE 502TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-04-28
2026-04-28 15:30Z
CRIT

Securing the git push pipeline: Responding to a critical remote code execution vulnerability

GitHub Security·github.blogCVE-2026-38540day

GitHub disclosed CVE-2026-3854, a critical remote code execution vulnerability in the git push pipeline affecting github.com and GitHub Enterprise Server. The vulnerability allowed authenticated users with push access to inject unsanitized git push options into internal metadata, bypassing sandboxing and achieving arbitrary command execution on GitHub servers. GitHub patched github.com within 2 hours of validation, found no evidence of exploitation, and released patches for all supported GHES versions.

SRFApplicationTACTA0002SRFWebSWGitVNDGithubTYPVulnerabilityTYPAdvisorySTGExecution
92
Edit Score
2026-04-28
2026-04-28 15:16Z
CRIT

CVE-2026-7321 — Sandbox: escape due to incorrect boundary conditions in the WebRTC: Networking component.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-7321

Sandbox escape due to incorrect boundary conditions in the WebRTC: Networking component. This vulnerability was fixed in Firefox ESR 140.10.1. CVSSv3.1 9.6 (CRITICAL)

CWECWE 120TYPVulnerability
9.6
CVSS v3.1
98
Edit Score
2026-04-28
2026-04-28 15:16Z
HIGH

CVE-2026-7289 — The manipulation of the argument submit-url results in buffer overflow.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-7289

A vulnerability was found in D-Link DIR-825M 1.1.12. This issue affects the function sub_414BA8 of the file /boafrm/formWanConfigSetup. The manipulation of the argument submit-url results in buffer overflow. The attack can be executed remotely. The exploit has been made public and could be used. CVSSv3.1 8.8 (HIGH)

CWECWE 120CWECWE 119TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-04-28
2026-04-28 15:16Z
HIGH

CVE-2026-7288 — The manipulation of the argument submit-url leads to buffer overflow.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-7288

A vulnerability has been found in D-Link DIR-825M 1.1.12. This vulnerability affects the function sub_4151FC of the file /boafrm/formVpnConfigSetup. The manipulation of the argument submit-url leads to buffer overflow. Remote exploitation of the attack is possible. The exploit has been disclosed to the public and may be used. CVSSv3.1 8.8 (HIGH)

CWECWE 120CWECWE 119TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-04-28
2026-04-28 15:16Z
HIGH

CVE-2026-27760 — OpenCATS: prior to commit 3002a29 contains a PHP code injection vulnerability in the installer

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-27760

OpenCATS prior to commit 3002a29 contains a PHP code injection vulnerability in the installer AJAX endpoint that allows unauthenticated attackers to execute arbitrary code by injecting PHP statements into the databaseConnectivity action parameter. Attackers can break out of the define() string context in config.php using a single quote and statement separator to inject malicious PHP code that persists and executes on every subsequent page load when the installation wizard rem CVSSv3.1 8.1 (HIGH)

CWECWE 94VNDOpencatsTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-04-28
2026-04-28 14:16Z
HIGH

CVE-2026-5944 — While the API primarily supports read-only operations, it also allows certain cluster maintenance workflows

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-5944

An improper access control vulnerability exists in the Cisco Intersight Device Connector for Nutanix Prism Central. The service exposes an API passthrough endpoint on TCP port 7373 that is accessible within the network scope of the deployment environment without authentication. An unauthenticated attacker with network access can exploit this vulnerability by sending crafted requests to the exposed endpoint to enumerate cluster metadata, including virtual machine informatio CVSSv3.1 8.2 (HIGH)

CWECWE 862CWECWE 306TYPVulnerability
8.2
CVSS v3.1
91
Edit Score
2026-04-28
2026-04-28 13:19Z
HIGH

CVE-2026-5781 — Agilonhealth Minerva: An authorization vulnerability in MphRx's Minerva V3.6.0, specifically in the '/minerva/moUser/update' endpoint, could allow

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-5781

An authorization vulnerability in MphRx's Minerva V3.6.0, specifically in the '/minerva/moUser/update' endpoint, could allow an authenticated user with user modification privileges to escalate their privileges by sending an HTTP request with a manipulated 'identifier' field. Successful exploitation of this vulnerability could allow an authenticated user to obtain administrator privileges. It is not possible to escalate privileges through the graphical user interface. CVSSv3.1 8.8 (HIGH) · EPSS 13th percentile

CWECWE 285VNDAgilonhealthVNDMinervaTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-04-28
2026-04-28 13:19Z
HIGH

CVE-2026-5780 — Agilonhealth Minerva: This allows an attacker to obtain a list of users.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-5780

An insecure direct object reference (IDOR) vulnerability in MphRx's Minerva V3.6.0, specifically in the endpoint '/minerva/moUser/show/'. If this vulnerability is successfully exploited, an authenticated user can access the data of other registered users simply by modifying the ID. This allows an attacker to obtain a list of users. CVSSv3.1 8.1 (HIGH) · EPSS 13th percentile

CWECWE 284VNDAgilonhealthVNDIdorTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-04-28
2026-04-28 13:19Z
HIGH

CVE-2026-5779 — Agilonhealth Minerva: This allows an authenticated user to modify the information of other registered users.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-5779

An insecure direct object reference (IDOR) vulnerability in MphRx's Minerva V3.6.0, specifically in the '/minerva/user/updateUserProfile' endpoint. This allows an authenticated user to modify the information of other registered users. Successful exploitation of this vulnerability allows an authenticated user to modify other users' information, such as their email address, and request a new password via the '/webconnect/#/forgotPassword' endpoint. This could lead to complete a CVSSv3.1 8.8 (HIGH) · EPSS 13th percentile

CWECWE 284VNDAgilonhealthVNDIdorTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-04-28
2026-04-28 11:50Z
HIGH

The State of Assumed Security

Horizon3.ai·horizon3.ai

Horizon3.ai released a research report surveying 750 security leaders, revealing a critical gap between perceived security posture and actual defensive validation. The study found that 93% of CISOs believe they've prevented breaches, yet only 12% have validated EDR effectiveness in 90 days, 26% test SOC detection of real attack techniques, and just 11% confirm remediation of known exploited vulnerabilities within 24 hours. The report argues that patched vulnerabilities and closed tickets do not guarantee eliminated attack paths, and that most organizations measure completion rather than resistance.

SRFApplicationSRFNetworkTYPResearchTYPThreat IntelSTGDiscoverySTGImpactSTGLat Movement
72
Edit Score
2026-04-28
2026-04-28 10:16Z
HIGH

CVE-2026-41604 — Out: Out-of-bounds Read vulnerability in Apache Thrift.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-41604

Out-of-bounds Read vulnerability in Apache Thrift. This issue affects Apache Thrift: before 0.23.0. Users are recommended to upgrade to version 0.23.0, which fixes the issue. CVSSv3.1 8.2 (HIGH)

CWECWE 125TYPVulnerability
8.2
CVSS v3.1
91
Edit Score
2026-04-28
2026-04-28 09:16Z
CRIT

CVE-2026-7248 — The manipulation of the argument fn results in buffer overflow.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-7248

A vulnerability was found in D-Link DI-8100 16.07.26A1. This affects the function tgfile_htm of the file tgfile.htm of the component CGI Endpoint. The manipulation of the argument fn results in buffer overflow. The attack can be executed remotely. The exploit has been made public and could be used. CVSSv3.1 9.8 (CRITICAL)

CWECWE 120CWECWE 119TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-04-28
2026-04-28 09:16Z
CRIT

CVE-2026-7244 — The manipulation of the argument merge results in os command injection.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-7244

A security flaw has been discovered in Totolink A8000RU 7.1cu.643_b20200521. The impacted element is the function setWiFiEasyGuestCfg of the file /cgi-bin/cstecgi.cgi of the component CGI Handler. The manipulation of the argument merge results in os command injection. It is possible to launch the attack remotely. The exploit has been released to the public and may be used for attacks. CVSSv3.1 9.8 (CRITICAL)

CWECWE 77CWECWE 78TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-04-28
2026-04-28 09:16Z
CRIT

CVE-2026-7243 — Totolink: The manipulation of the argument maxRtrAdvInterval leads to os command injection.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-7243

A vulnerability was identified in Totolink A8000RU 7.1cu.643_b20200521. The affected element is the function setRadvdCfg of the file /cgi-bin/cstecgi.cgi of the component CGI Handler. The manipulation of the argument maxRtrAdvInterval leads to os command injection. It is possible to initiate the attack remotely. The exploit is publicly available and might be used. CVSSv3.1 9.8 (CRITICAL)

CWECWE 77CWECWE 78VNDTotolinkTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-04-28
2026-04-28 09:16Z
CRIT

CVE-2026-7242 — Totolink: Executing a manipulation of the argument enabled can lead to os command injection.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-7242

A vulnerability was determined in Totolink A8000RU 7.1cu.643_b20200521. Impacted is the function setOpenVpnClientCfg of the file /cgi-bin/cstecgi.cgi of the component CGI Handler. Executing a manipulation of the argument enabled can lead to os command injection. The attack may be performed from remote. The exploit has been publicly disclosed and may be utilized. CVSSv3.1 9.8 (CRITICAL)

CWECWE 77CWECWE 78VNDTotolinkTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-04-28
2026-04-28 09:16Z
CRIT

CVE-2026-7241 — Totolink: Performing a manipulation of the argument wifiOff results in os command injection.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-7241

A vulnerability was found in Totolink A8000RU 7.1cu.643_b20200521. This issue affects the function setWiFiBasicCfg of the file /cgi-bin/cstecgi.cgi of the component CGI Handler. Performing a manipulation of the argument wifiOff results in os command injection. The attack is possible to be carried out remotely. The exploit has been made public and could be used. CVSSv3.1 9.8 (CRITICAL)

CWECWE 77CWECWE 78VNDTotolinkTYPVulnerability
9.8
CVSS v3.1
99
Edit Score