2d ago
2026-09-11 04:18Z
CRIT

CVE-2026-8778 — MIPL: plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-8778

The MIPL Grouped Checkout Fields for WooCommerce – Customize & Organize Checkout Fields. plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the `mipl_wc_upload_file` function in all versions up to, and including, 1.2.1. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code execution possible. CVSSv3.1 9.8 (CRITICAL)

CWECWE 434VNDMiplTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2d ago
2026-09-11 04:17Z
HIGH

CVE-2026-19991 — UsersWP: The UsersWP plugin for WordPress is vulnerable to Arbitrary File Deletion in versions up

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-19991

The UsersWP plugin for WordPress is vulnerable to Arbitrary File Deletion in versions up to, and including, 1.2.70 via the upload_file_remove() AJAX handler. The plugin stores the value of an account 'file' form field taken directly from $_POST when no real $_FILES upload is provided (process_account() calls uwp_validate_fields() and array_merges the result with the empty output of UsersWP_Files::validate_uploads()). At storage time the value is only checked with validate_fil CVSSv3.1 8.1 (HIGH)

CWECWE 22VNDUserswpTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
3d ago
2026-09-11 00:00Z
HIGH

Linux Detection Engineering - Local Privilege Escalation

Elastic Security Labs·elastic.co

Elastic Security Labs published a comprehensive Linux privilege escalation detection framework covering 13 recent CVEs, noting that 7 share a copy-on-write bug class (Copy Fail, DirtyFrag, Fragnesia, DirtyDecrypt, DirtyClone, pedit COW, RefluXFS). The post details layered detection rules keyed on behavioral outcomes (unprivileged process becoming root) and technique-specific patterns, with emphasis on SUID/SGID abuse, writable-path execution, and uid_change sequences.

SRFOsTACTA0004OSLinuxSWElastic DefendVNDElasticTYPResearchSTGPrivescTECT1548.001
78
Edit Score
3d ago
2026-09-11 00:00Z
CRIT

“Eye” spy: Cyclops Blink returns with extended capabilities

Sophos X-Ops·news.sophos.comin the wild

Sophos CTU researchers documented an upgraded variant of Cyclops Blink malware targeting Cisco Firewall Management Center (FMC) devices, attributed to Russia-based IRON VIKING (Sandworm). The 2026 x86-64 Linux variant expands beyond the 2022 WatchGuard-focused samples with modular capabilities including host reconnaissance, network discovery, packet surveillance, file transfer, payload execution, and SysV-based persistence. The implant operates as a parent controller managing five worker modules via IPC, communicates via TLS to hardcoded C2 infrastructure, and can serve as a platform for internal reconnaissance and lateral movement from compromised network-edge appliances.

SRFApplicationTACTA0001SRFNetwork ApplianceTACTA0007TACTA0003TACTA0011OSLinuxSWCyclops Blink
92
Edit Score
3d ago
2026-09-10 22:17Z
HIGH

CVE-2026-87958 — IBM: Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.5 is vulnerable to a denial

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-87958

IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.5 is vulnerable to a denial of service where a specific functionality on a Db2 server can be disabled by a privileged user under certain conditions. CVSSv3.1 8.1 (HIGH)

CWECWE 269VNDIbmTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
3d ago
2026-09-10 22:17Z
HIGH

CVE-2026-84889 — IBM: Langflow OSS 1.0.0 through 1.10.3 could allow a remote authenticated attacker to execute

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-84889

IBM Langflow OSS 1.0.0 through 1.10.3 could allow a remote authenticated attacker to execute arbitrary code due to improper limitation of a pathname to a restricted directory. CVSSv3.1 8.8 (HIGH)

CWECWE 22VNDIbmTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
3d ago
2026-09-10 22:17Z
CRIT

CVE-2026-82107 — IBM: DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-82107

IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to obtain sensitive information and bypass security restrictions due to improper authentication. CVSSv3.1 9.6 (CRITICAL)

CWECWE 287VNDIbmTYPVulnerability
9.6
CVSS v3.1
98
Edit Score
728 × 90 / responsive · programmatic ad slot
3d ago
2026-09-10 22:17Z
CRIT

CVE-2026-82100 — IBM: DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-82100

IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to cause a denial of service due to a path traversal vulnerability. CVSSv3.1 9.6 (CRITICAL)

CWECWE 22VNDIbmTYPVulnerability
9.6
CVSS v3.1
98
Edit Score
3d ago
2026-09-10 22:17Z
HIGH

CVE-2026-82099 — IBM: DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-82099

IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to execute arbitrary code due to improper neutralization of special elements used in an OS command. CVSSv3.1 8.8 (HIGH)

CWECWE 78VNDIbmTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
3d ago
2026-09-10 22:17Z
HIGH

CVE-2026-82098 — IBM: DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-82098

IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to execute arbitrary commands due to improper neutralization of special elements used in an OS command. CVSSv3.1 8.8 (HIGH)

CWECWE 78VNDIbmTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
3d ago
2026-09-10 22:17Z
HIGH

CVE-2026-82097 — IBM: DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-82097

IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to execute arbitrary code due to a Server-Side Request Forgery (SSRF) vulnerability. CVSSv3.1 8.8 (HIGH)

CWECWE 918VNDIbmTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
3d ago
2026-09-10 22:17Z
HIGH

CVE-2026-82095 — IBM: DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-82095

IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to execute arbitrary code due to improper neutralization of special elements used in an OS command. CVSSv3.1 8.8 (HIGH)

CWECWE 78VNDIbmTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
3d ago
2026-09-10 22:17Z
HIGH

CVE-2026-82092 — IBM: DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-82092

IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to obtain sensitive information due to an absolute-path traversal vulnerability. CVSSv3.1 8.8 (HIGH)

CWECWE 36VNDIbmTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
3d ago
2026-09-10 22:17Z
HIGH

CVE-2026-81941 — IBM: Langflow OSS 1.0.0 through 1.11.5 allows an authenticated non-administrative user could execute arbitrary

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-81941

IBM Langflow OSS 1.0.0 through 1.11.5 allows an authenticated non-administrative user could execute arbitrary operating system commands on the server at the privilege level of the application process by constructing a flow with an MCP Tools component configured to use a local stdio subprocess transport. This bypasses both the LANGFLOW_CUSTOM_COMPONENT_ADMIN_ONLY and LANGFLOW_BLOCK_CODE_INTERPRETER_COMPONENTS server-side controls intended to prevent exactly this class of acces CVSSv3.1 8.8 (HIGH)

CWECWE 284VNDIbmTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
3d ago
2026-09-10 22:17Z
HIGH

CVE-2026-81940 — IBM: Langflow OSS 1.0.0 through 1.11.5 could allow a remote authenticated attacker to execute

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-81940

IBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote authenticated attacker to execute arbitrary code due to improper neutralization of special characters in flow display names. CVSSv3.1 8.8 (HIGH)

CWECWE 94VNDIbmTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
3d ago
2026-09-10 22:17Z
HIGH

CVE-2026-81554 — IBM: DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-81554

IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to obtain sensitive information due to an absolute-path traversal vulnerability. CVSSv3.1 8.8 (HIGH)

CWECWE 22VNDIbmTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
3d ago
2026-09-10 22:17Z
HIGH

CVE-2026-81551 — IBM: DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-81551

IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to arbitrarily write to or delete files on shared storage due to a path traversal vulnerability. CVSSv3.1 8.8 (HIGH)

CWECWE 22VNDIbmTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
3d ago
2026-09-10 22:17Z
HIGH

CVE-2026-81550 — IBM: DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-81550

IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to execute arbitrary code due to improper neutralization of special elements used in an OS command. CVSSv3.1 8.8 (HIGH)

CWECWE 78VNDIbmTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
3d ago
2026-09-10 22:17Z
HIGH

CVE-2026-81540 — IBM: DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-81540

IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to overwrite ruleset files belonging to other tenants due to a path traversal vulnerability. CVSSv3.1 8.5 (HIGH)

CWECWE 22VNDIbmTYPVulnerability
8.5
CVSS v3.1
93
Edit Score
3d ago
2026-09-10 22:17Z
HIGH

CVE-2026-81268 — IBM: Langflow OSS 1.0.0 through 1.11.5 could allow a remote authenticated attacker to execute

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-81268

IBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote authenticated attacker to execute flows and obtain sensitive information due to insufficient session expiration of API keys after user deactivation. CVSSv3.1 8.1 (HIGH)

CWECWE 613VNDIbmTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
3d ago
2026-09-10 22:17Z
HIGH

CVE-2026-81213 — IBM: Langflow OSS 1.0.0 through 1.11.5 could allow a remote attacker to obtain sensitive

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-81213

IBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote attacker to obtain sensitive information from internal network resources due to improper validation of user-supplied URLs. CVSSv3.1 8.6 (HIGH)

CWECWE 918VNDIbmTYPVulnerability
8.6
CVSS v3.1
93
Edit Score
3d ago
2026-09-10 22:17Z
HIGH

CVE-2026-81211 — IBM: Langflow OSS 1.0.0 through 1.11.5 could allow a remote authenticated attacker to execute

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-81211

IBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote authenticated attacker to execute arbitrary Python code due to improper authorization of custom components in stored flows. CVSSv3.1 8.8 (HIGH)

CWECWE 862VNDIbmTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
3d ago
2026-09-10 22:17Z
HIGH

CVE-2026-81207 — IBM: DataStage on Cloud Pak for Data 5.4.0.0 allows any authenticated tenant — with

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-81207

IBM DataStage on Cloud Pak for Data 5.4.0.0 allows any authenticated tenant — with no project membership or role — fully controls scheme/host/port/path of an outbound fetch originating from a shared-infrastructure pod, and the WSDL body is reflected verbatim to the caller. The ds-canvas pod sits on the OpenShift overlay with reach to co-tenant services, in-cluster CP4D APIs, and link-local addresses. Scope is Changed, confidentiality High (response-reflecting), integrity Low CVSSv3.1 8.5 (HIGH)

CWECWE 918VNDIbmTYPVulnerability
8.5
CVSS v3.1
93
Edit Score
3d ago
2026-09-10 22:17Z
CRIT

CVE-2026-81204 — IBM: Langflow OSS 1.0.0 through 1.11.5 could allow a remote attacker to execute arbitrary

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-81204

IBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote attacker to execute arbitrary code due to code injection during graph construction. CVSSv3.1 9.8 (CRITICAL)

CWECWE 94VNDIbmTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
3d ago
2026-09-10 22:17Z
HIGH

CVE-2026-80436 — IBM: DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-80436

IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to cause a denial of service by deleting arbitrary RabbitMQ queues or exchanges due to improper authorization. CVSSv3.1 8.5 (HIGH)

CWECWE 285VNDIbmTYPVulnerability
8.5
CVSS v3.1
93
Edit Score