1w ago
2026-09-03 19:17Z
CRIT

CVE-2026-82526 — R2R: through 3.6.6 contains a stacked SQL injection vulnerability that allows unauthenticated attackers to

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-82526

R2R through 3.6.6 contains a stacked SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL statements by manipulating the index name parameter in the vector index creation endpoint. The index name is interpolated directly into a CREATE INDEX statement via string formatting without identifier quoting or allowlist validation, enabling arbitrary DDL and DML execution through semicolon-separated statements under the PostgreSQL superuser accoun CVSSv3.1 9.8 (CRITICAL)

CWECWE 89VNDR2rTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
1w ago
2026-09-03 19:17Z
HIGH

CVE-2026-82302 — Incorrect: Authorization (CWE-863) in Kibana can lead to unauthorized configuration modification via Exploiting Incorrectly

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-82302

Incorrect Authorization (CWE-863) in Kibana can lead to unauthorized configuration modification via Exploiting Incorrectly Configured Access Control Security Levels (CAPEC-180). CVSSv3.1 8.1 (HIGH)

CWECWE 863TYPVulnerability
8.1
CVSS v3.1
91
Edit Score
1w ago
2026-09-03 19:17Z
HIGH

CVE-2026-78583 — Incorrect: Authorization (CWE-863) in Kibana can lead to privilege escalation via Input Data Manipulation

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-78583

Incorrect Authorization (CWE-863) in Kibana can lead to privilege escalation via Input Data Manipulation (CAPEC-153). Elasticsearch cluster privilege declarations originating from integration packages were not validated before being used to mint credentials for enrolled Elastic Agents. A user holding Fleet management privileges could therefore cause every Elastic Agent on a targeted policy to receive a credential carrying arbitrarily elevated Elasticsearch cluster privileges, CVSSv3.1 8.1 (HIGH)

CWECWE 863TYPVulnerability
8.1
CVSS v3.1
91
Edit Score
1w ago
2026-09-03 18:17Z
HIGH

CVE-2026-85012 — Improper neutralization of special elements used in an OS command (CWE-78) in the blueprint

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-85012

Improper neutralization of special elements used in an OS command (CWE-78) in the blueprint resynthesis framework in Amazon Web Services codecatalyst-blueprints before 0.3.156 might allow a user with permission to commit to a repository in the project to execute arbitrary commands in the blueprint resynthesis environment via shell metacharacters in the owner field of a [local] merge strategy entry in a crafted .ownership-file. Version 0.3.156 removes shell interpretation o CVSSv3.1 8.0 (HIGH)

CWECWE 78TYPVulnerability
8.0
CVSS v3.1
90
Edit Score
1w ago
2026-09-03 18:17Z
HIGH

CVE-2026-63219 — GeoNetwork: Prior to versions 4.4.12 and 4.2.17, the API endpoint for creating a new formatter

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-63219

GeoNetwork is a catalog application to manage spatially referenced resources. Prior to versions 4.4.12 and 4.2.17, the API endpoint for creating a new formatter via file upload is unprotected and allows the upload of external uncontrolled files. An unauthenticated attacker can upload arbitrary `.xsl` or `.zip` formatter files to the server. An unauthenticated attacker can write arbitrary files into the GeoNetwork formatter directory. On its own this constitutes unauthorized CVSSv3.1 8.6 (HIGH)

CWECWE 862VNDGeonetworkTYPVulnerability
8.6
CVSS v3.1
93
Edit Score
1w ago
2026-09-03 18:17Z
CRIT

CVE-2026-58400 — GeoNetwork: Any stylesheet loaded by GeoNetwork can therefore invoke `java.lang.Runtime.exec()` or `java.lang.ProcessBuilder` directly, achieving arbitrary

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-58400

GeoNetwork is a catalog application to manage spatially referenced resources. Prior to versions 4.4.12 and 4.2.17, the Saxon XSLT processor used to render formatters is configured without secure processing (`FEATURE_SECURE_PROCESSING`) and without disabling Java extension functions (`ALLOW_EXTERNAL_FUNCTIONS`). Any stylesheet loaded by GeoNetwork can therefore invoke `java.lang.Runtime.exec()` or `java.lang.ProcessBuilder` directly, achieving arbitrary command execution as th CVSSv3.1 9.1 (CRITICAL)

CWECWE 94CWECWE 470VNDGeonetworkTYPVulnerability
9.1
CVSS v3.1
96
Edit Score
1w ago
2026-09-03 17:17Z
CRIT

CVE-2026-84834 — PHP: Unauthenticated PHP Object Injection in JobSearch <= 3.2.0 versions.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-84834

Unauthenticated PHP Object Injection in JobSearch <= 3.2.0 versions. CVSSv3.1 9.8 (CRITICAL)

CWECWE 502TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
728 × 90 / responsive · programmatic ad slot
1w ago
2026-09-03 17:17Z
CRIT

CVE-2026-84814 — Subscriber: Privilege Escalation in Bricksforge <= 3.1.8.8 versions.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-84814

Subscriber Privilege Escalation in Bricksforge <= 3.1.8.8 versions. CVSSv3.1 9.8 (CRITICAL)

CWECWE 266VNDSubscriberTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
1w ago
2026-09-03 17:17Z
CRIT

CVE-2026-84813 — SQL: Unauthenticated SQL Injection in GeoDirectory <= 2.8.174 versions.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-84813

Unauthenticated SQL Injection in GeoDirectory <= 2.8.174 versions. CVSSv3.1 9.3 (CRITICAL)

CWECWE 89TYPVulnerability
9.3
CVSS v3.1
97
Edit Score
1w ago
2026-09-03 17:17Z
HIGH

CVE-2026-84779 — Subscriber: Broken Access Control in Agentimus – AI SEO, llms.txt &amp; MCP for AI

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-84779

Subscriber Broken Access Control in Agentimus – AI SEO, llms.txt &amp; MCP for AI Agents <= 1.51.0 versions. CVSSv3.1 8.1 (HIGH)

CWECWE 862VNDSubscriberTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
1w ago
2026-09-03 17:17Z
CRIT

CVE-2026-84768 — SQL: Unauthenticated SQL Injection in VikAppointments Services Booking Calendar <= 1.2.20 versions.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-84768

Unauthenticated SQL Injection in VikAppointments Services Booking Calendar <= 1.2.20 versions. CVSSv3.1 9.3 (CRITICAL)

CWECWE 89TYPVulnerability
9.3
CVSS v3.1
97
Edit Score
1w ago
2026-09-03 17:17Z
HIGH

CVE-2026-84757 — Settings: Unauthenticated Settings Change in WP Compress <= 7.21.28 versions.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-84757

Unauthenticated Settings Change in WP Compress <= 7.21.28 versions. CVSSv3.1 8.2 (HIGH)

CWECWE 862VNDSettingsTYPVulnerability
8.2
CVSS v3.1
91
Edit Score
1w ago
2026-09-03 17:17Z
CRIT

CVE-2026-84753 — PHP: Unauthenticated PHP Object Injection in Mail Mint <= 1.31.0 versions.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-84753

Unauthenticated PHP Object Injection in Mail Mint <= 1.31.0 versions. CVSSv3.1 9.8 (CRITICAL)

CWECWE 502TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
1w ago
2026-09-03 17:17Z
HIGH

CVE-2026-84752 — Contributor: PHP Object Injection in RTMKit <= 2.1.5 versions.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-84752

Contributor PHP Object Injection in RTMKit <= 2.1.5 versions. CVSSv3.1 8.8 (HIGH)

CWECWE 502VNDContributorTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
1w ago
2026-09-03 17:17Z
CRIT

CVE-2026-84238 — Broken: Unauthenticated Broken Access Control in YITH Request a Quote for WooCommerce Premium < 4.46.0

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-84238

Unauthenticated Broken Access Control in YITH Request a Quote for WooCommerce Premium < 4.46.0 versions. CVSSv3.1 9.8 (CRITICAL)

CWECWE 862VNDBrokenTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
1w ago
2026-09-03 16:18Z
HIGH

CVE-2026-85237 — Misp-project Misp: This significantly increased the feasibility of guessing the OTP and bypassing the additional authentication

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-85237

A vulnerability in MISP's email-based one-time password (OTP) authentication flow allowed an attacker to perform an unrestricted number of OTP verification attempts. The email_otp() endpoint did not apply brute-force protection when validating submitted OTP values. An attacker who had reached the OTP verification stage, for example after successfully providing a user's primary authentication credentials, could repeatedly submit candidate OTP values while the same OTP remain CVSSv3.1 8.1 (HIGH) · EPSS 22th percentile

CWECWE 307VNDMisp ProjectTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
1w ago
2026-09-03 16:18Z
HIGH

CVE-2026-85236 — Misp-project Misp: A cross-site request forgery (CSRF) vulnerability existed in the cullEmptyEvents action of MISP.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-85236

A cross-site request forgery (CSRF) vulnerability existed in the cullEmptyEvents action of MISP. The endpoint performed a state-changing and irreversible operation while accepting HTTP GET requests. Because bodyless GET requests are not subject to CakePHP's CSRF validation, an attacker could cause an authenticated MISP user with sufficient privileges to invoke the endpoint simply by causing their browser to load a crafted URL, for example through an embedded image or other CVSSv3.1 8.8 (HIGH) · EPSS 10th percentile

CWECWE 352VNDCsrfVNDMisp ProjectTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
1w ago
2026-09-03 16:18Z
HIGH

CVE-2026-71963 — Hermes: Agent 0.18.2 through 0.21.0, fixed in commit f6234d0, contains a remote code execution

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-71963

Hermes Agent 0.18.2 through 0.21.0, fixed in commit f6234d0, contains a remote code execution vulnerability that allows attackers to execute arbitrary OS commands by supplying a malicious repository with a crafted .git/config that sets core.fsmonitor to an attacker-controlled command. When a user opens the malicious repository and sends any message, the agent triggers a git status index refresh which executes the injected command in the user's process context, exposing the fu CVSSv3.1 8.8 (HIGH)

CWECWE 78VNDHermesTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
1w ago
2026-09-03 15:34Z
HIGH

AuthStrike — AuthStrike is an identity and authentication security testing tool for controlled simulations, security research, and ed

GitHub · Azure / Entra tools·github.comGITHUB POC

AuthStrike is a new open-source identity and authentication security testing tool designed for authorized assessments of Microsoft Entra attack paths. It simulates device-code authentication flows, token handling, device registration, and Microsoft Graph/Outlook access to help red teams and security researchers evaluate Entra defenses in controlled lab environments.

TACTA0006TACTA0007SRFIdentitySRFCloudSWAuthstrikeVNDMicrosoftTYPToolSTGDiscovery
78
Edit Score
1w ago
2026-09-03 15:33Z
INFO

v3.1.1-rc2

AzureHound releases·github.com

AzureHound v3.1.1-rc2 released with bug fixes including removal of deprecated organization URLs, GHCR credential handling, and license error handling when pulling users.

SRFIdentitySRFCloudSWAzurehoundVNDSpecteropsTYPTool
28
Edit Score
1w ago
2026-09-03 15:19Z
HIGH

How to correlate Kubernetes audit logs with container runtime data

Elastic Security Labs·elastic.co

Elastic Security Labs demonstrates practical correlation techniques between Kubernetes audit logs and container runtime data (Defend for Containers) to detect multi-plane attacks. The research shows how attackers using compromised service accounts can perform discovery, secret theft, privileged pod creation, and container escape attempts—with critical evasion gaps where escape tools like nsenter and chroot appear only in audit logs but not runtime process telemetry.

TACTA0007SRFCloudSWKubernetesSWElasticTYPResearchTECT1552TECT1059TECT1611
72
Edit Score
1w ago
2026-09-03 15:17Z
CRIT

CVE-2026-85221 — Misp-project Misp: Successful exploitation could allow an attacker to observe sensitive information transmitted by MISP, including

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-85221

MISP contains an improper TLS certificate validation vulnerability in CurlClient. The CurlClient::$verifyPeer property was not explicitly initialized and therefore defaulted to null. When passed to cURL, this value effectively disabled TLS peer verification unless the calling code explicitly enabled it. As a result, HTTPS connections made through affected CurlClient instances could accept certificates that were not issued by a trusted certificate authority. An attacker capa CVSSv3.1 9.1 (CRITICAL) · EPSS 0th percentile

CWECWE 295VNDMispVNDMisp ProjectTYPVulnerability
9.1
CVSS v3.1
96
Edit Score
1w ago
2026-09-03 15:17Z
CRIT

CVE-2026-85216 — Misp-project Misp: contains an authentication bypass vulnerability in its LDAP and LinOTP authentication components due

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-85216

MISP contains an authentication bypass vulnerability in its LDAP and LinOTP authentication components due to insufficient validation of user-supplied credentials. The custom LdapAuthenticate and LinOTPAuthenticate components replace CakePHP's FormAuthenticate implementation but did not replicate its credential validation checks. As a result, empty or non-string values could reach the underlying authentication mechanisms. In the LDAP authentication path, an attacker able to CVSSv3.1 9.8 (CRITICAL) · EPSS 40th percentile

CWECWE 521VNDMispVNDMisp ProjectTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
1w ago
2026-09-03 15:17Z
HIGH

CVE-2026-85214 — Attackers can overwrite other users' names, addresses, and disable accounts including administrators to cause

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-85214

vhr fails to validate user authorization in the PUT /hr/info endpoint, allowing authenticated users to modify arbitrary HR profiles by supplying any profile ID in the request body. Attackers can overwrite other users' names, addresses, and disable accounts including administrators to cause denial of service. CVSSv3.1 8.1 (HIGH)

CWECWE 639TYPVulnerability
8.1
CVSS v3.1
91
Edit Score
1w ago
2026-09-03 15:17Z
HIGH

CVE-2026-85212 — CRMEB: contains an authentication bypass vulnerability in the verifyAuth() method of SystemRoleServices.php that returns

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-85212

CRMEB contains an authentication bypass vulnerability in the verifyAuth() method of SystemRoleServices.php that returns true from both conditional branches. Sub-administrators and accounts with no roles can access restricted admin endpoints by exploiting the inert role check that always permits requests. CVSSv3.1 8.3 (HIGH)

CWECWE 862VNDCrmebTYPVulnerability
8.3
CVSS v3.1
92
Edit Score