1d ago
2026-07-28 21:17Z
CRIT

CVE-2026-14512 — IBM: WebSphere Application Server 9.0, and 8.5 traditional is vulnerable to pre-authentication unsafe deserialization

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-14512

IBM WebSphere Application Server 9.0, and 8.5 traditional is vulnerable to pre-authentication unsafe deserialization which could allow a remote attacker to bypass authentication or execute arbitrary code. CVSSv3.1 9.8 (CRITICAL)

CWECWE 502VNDIbmTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
1d ago
2026-07-28 21:17Z
CRIT

CVE-2026-14446 — IBM: WebSphere Application Server 9.0, and 8.5 is vulnerable to broken access control/privilege escalation

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-14446

IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to broken access control/privilege escalation in the administrative console. CVSSv3.1 9.8 (CRITICAL)

CWECWE 306VNDIbmTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
1d ago
2026-07-28 20:17Z
HIGH

CVE-2026-57510 — SuperPlane: before 0.27.0 contains a broken object-level authorization vulnerability in the CanvasService gRPC handlers

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-57510

SuperPlane before 0.27.0 contains a broken object-level authorization vulnerability in the CanvasService gRPC handlers that allows authenticated users with viewer-level access to one organization to access resources belonging to other organizations by supplying arbitrary canvas or queue UUIDs without organization scoping. Attackers can read cross-tenant execution history and event payloads containing sensitive secrets, write queue items and canvas events into victim organizat CVSSv3.1 8.8 (HIGH)

CWECWE 639VNDSuperplaneTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
1d ago
2026-07-28 20:17Z
HIGH

CVE-2026-48060 — Litestar: Prior to version 2.20.0, Litestar instances which use a template engine in conjunction with

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-48060

Litestar is an Asynchronous Server Gateway Interface (ASGI) framework. Prior to version 2.20.0, Litestar instances which use a template engine in conjunction with CSRF protection are vulnerable to HTML Injection which can be escalated to Cross Site Scripting due to the contents of the CSRF cookie being excluded from automatic escaping by the template engine when configured inline with documentation recommendations. This issue has been patched in version 2.20.0. CVSSv3.1 8.1 (HIGH)

CWECWE 79VNDLitestarTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
1d ago
2026-07-28 20:17Z
HIGH

CVE-2026-16347 — MikroTik: This deficiency increases the risk that an attacker could eventually obtain valid credentials and

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-16347

MikroTik RouterOS contains a weakness in its API authentication handling that lacks effective safeguards against excessive login attempts. The system does not enforce meaningful rate-limiting, account lockout, or source-based restrictions, allowing repeated authentication failures to proceed without defensive response. In some versions, a fixed per-connection delay is present, but it can be bypassed through concurrent sessions, resulting in continued high-volume attempts. Thi CVSSv3.1 8.8 (HIGH)

CWECWE 307VNDMikrotikTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
1d ago
2026-07-28 19:17Z
HIGH

CVE-2026-7769 — IBM: Sterling B2B Integrator 6.2.0.0 through 6.2.0.5_2, 6.2.1.0 through 6.2.1.1_2, and 6.2.2.0 through 6.2.2.0_1

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-7769

IBM Sterling B2B Integrator 6.2.0.0 through 6.2.0.5_2, 6.2.1.0 through 6.2.1.1_2, and 6.2.2.0 through 6.2.2.0_1 and IBM Sterling File Gateway 6.2.0.0 through 6.2.0.5_2, 6.2.1.0 through 6.2.1.1_2, and 6.2.2.0 through 6.2.2.0_1 is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attacker to view, add, modify, or delete information in the back-end database. CVSSv3.1 8.1 (HIGH)

CWECWE 89VNDIbmTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
1d ago
2026-07-28 19:17Z
HIGH

CVE-2026-49258 — Nebula: In versions 0.3.5 and below, the web UI (/ui/*) does not apply the per-operator

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-49258

Nebula Mesh is a self-hosted control plane for the Slack Nebula mesh VPN. In versions 0.3.5 and below, the web UI (/ui/*) does not apply the per-operator CA scoping employed by the JSON API. This was partially addressed by GHSA-598g-h2vc-h5vg, but the changes were not implemented in the web read/mutation surface. Any authenticated non-admin operator (for example, one created via self-registration or OIDC) can access resources belonging to other operators. The host create/edit CVSSv3.1 8.8 (HIGH)

CWECWE 862CWECWE 639VNDNebulaTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
728 × 90 / responsive · programmatic ad slot
1d ago
2026-07-28 19:17Z
HIGH

CVE-2026-48396 — Bridge: is affected by an Incorrect Authorization vulnerability that could result in arbitrary code

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-48396

Bridge is affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code. Exploitation of this issue requires user interaction in that a victim must open a malicious file. Scope is changed. CVSSv3.1 8.6 (HIGH)

CWECWE 863VNDBridgeTYPVulnerability
8.6
CVSS v3.1
93
Edit Score
1d ago
2026-07-28 19:17Z
HIGH

CVE-2026-48395 — Bridge: is affected by an Untrusted Search Path vulnerability that could result in arbitrary

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-48395

Bridge is affected by an Untrusted Search Path vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code. Exploitation of this issue requires user interaction in that a victim must open a malicious file. Scope is changed. CVSSv3.1 8.6 (HIGH)

CWECWE 426VNDBridgeTYPVulnerability
8.6
CVSS v3.1
93
Edit Score
1d ago
2026-07-28 19:17Z
HIGH

CVE-2026-48391 — Bridge: is affected by an Untrusted Search Path vulnerability that could result in arbitrary

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-48391

Bridge is affected by an Untrusted Search Path vulnerability that could result in arbitrary code execution in the context of the current user. A low-privileged attacker could exploit this vulnerability to execute arbitrary code. Exploitation of this issue requires user interaction in that a victim must open a malicious file. Scope is changed. CVSSv3.1 8.2 (HIGH)

CWECWE 426VNDBridgeTYPVulnerability
8.2
CVSS v3.1
91
Edit Score
1d ago
2026-07-28 19:17Z
HIGH

CVE-2026-48390 — Bridge: is affected by an Incorrect Authorization vulnerability that could result in privilege escalation.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-48390

Bridge is affected by an Incorrect Authorization vulnerability that could result in privilege escalation. An attacker could leverage this vulnerability to gain unauthorized read and write access. Exploitation of this issue requires user interaction in that a victim must open a malicious file. Scope is changed. CVSSv3.1 8.2 (HIGH)

CWECWE 863VNDBridgeTYPVulnerability
8.2
CVSS v3.1
91
Edit Score
1d ago
2026-07-28 19:17Z
HIGH

CVE-2026-16771 — This allows unauthenticated attackers on the LAN to read sensitive configuration data, modify persistent

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-16771

In firmware versions 2.7.7 and earlier, the Arris BGW210‑700 gateway fails to enforce any server‑side authentication on its /cgi-bin/*.ha management endpoints, relying solely on client‑side CSS/JavaScript gating that can be bypassed by any HTTP client. This allows unauthenticated attackers on the LAN to read sensitive configuration data, modify persistent device settings, or trigger backend diagnostic operations. The issue appears systemic across the CGI handler chain. CVSSv3.1 8.8 (HIGH)

CWECWE 306TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
1d ago
2026-07-28 19:17Z
CRIT

CVE-2026-16498 — The terraform-mcp-server before version 1.1.0 is vulnerable to a cross-tenant credential reuse issue in

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-16498

The terraform-mcp-server before version 1.1.0 is vulnerable to a cross-tenant credential reuse issue in the streamable-HTTP stateless transport mode that may allow one user's Terraform token to be used to execute tool calls on behalf of subsequent users. This vulnerability, CVE-2026-16498, is fixed in terraform-mcp-server 1.1.0. CVSSv3.1 10.0 (CRITICAL)

CWECWE 488TYPVulnerability
10.0
CVSS v3.1
100
Edit Score
1d ago
2026-07-28 19:17Z
HIGH

CVE-2026-16496 — The terraform-mcp-server before version 1.1.0 is vulnerable to an authorization bypass in the streamable-HTTP

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-16496

The terraform-mcp-server before version 1.1.0 is vulnerable to an authorization bypass in the streamable-HTTP stateful transport mode that may allow a user who obtains another user's MCP session ID to have their tool calls executed using that user's Terraform credentials. This vulnerability, CVE-2026-16496, is fixed in terraform-mcp-server 1.1.0. CVSSv3.1 8.9 (HIGH)

CWECWE 384TYPVulnerability
8.9
CVSS v3.1
95
Edit Score
1d ago
2026-07-28 19:17Z
HIGH

CVE-2026-15992 — Password: The WP Password Policy plugin for WordPress is vulnerable to Privilege Escalation in all

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-15992

The WP Password Policy plugin for WordPress is vulnerable to Privilege Escalation in all versions up to and including 3.7.1. This is due to missing authorization checks and nonce verification in the `get_user()` function of the `Module_Password_Hint` class, which unconditionally calls `WP_User::set_role()` with the attacker-supplied `role` parameter on any account resolved via `$_POST['user_login']`, without confirming the requesting user holds the capability to assign roles. CVSSv3.1 8.8 (HIGH)

CWECWE 269TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
1d ago
2026-07-28 19:17Z
HIGH

CVE-2026-14869 — The terraform-mcp-server before version 1.1.0 is vulnerable to a server-side request forgery issue in

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-14869

The terraform-mcp-server before version 1.1.0 is vulnerable to a server-side request forgery issue in the streamable-HTTP transport that may allow an unauthenticated remote client to redirect the server's Terraform API requests, and the server-side authorization token, to an attacker-controlled endpoint. This vulnerability, CVE-2026-14869, is fixed in terraform-mcp-server 1.1.0. CVSSv3.1 8.6 (HIGH)

CWECWE 918TYPVulnerability
8.6
CVSS v3.1
93
Edit Score
2d ago
2026-07-28 18:32Z
CRIT

Check Point SmartConsole Authentication Bypass Technical Analysis (CVE-2026-16232)

Rapid7 Research·rapid7.comCVE-2026-16232in the wild

Rapid7 published a detailed technical analysis of CVE-2026-16232, a critical authentication bypass in Check Point SmartConsole affecting R81.20 and R82.10. The vulnerability stems from a broken trust boundary where the application accepts an attacker-supplied SIC distinguished name instead of validating it against the authenticated peer certificate, allowing unauthenticated attackers to obtain admin tokens and full SmartConsole access. The analysis includes a working proof-of-concept exploit, root-cause code comparison, and confirmation that vendor patches successfully remediate the flaw.

SRFApplicationTACTA0001TACTA0002SRFNetworkSWSmartconsoleVNDCheckpointTYPResearchTYPVulnerability
92
Edit Score
2d ago
2026-07-28 18:17Z
HIGH

CVE-2026-48388 — Adobe: Photoshop Installer was affected by an Uncontrolled Search Path Element vulnerability that could

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-48388

Adobe Photoshop Installer was affected by an Uncontrolled Search Path Element vulnerability that could have resulted in arbitrary code execution in the context of the current user. An attacker could have exploited this vulnerability by placing a malicious library in a directory searched by the installer. Exploitation of this issue required user interaction in that a victim must have been running the installer. Scope is changed. CVSSv3.1 8.6 (HIGH)

CWECWE 427VNDAdobeTYPVulnerability
8.6
CVSS v3.1
93
Edit Score
2d ago
2026-07-28 17:16Z
HIGH

CVE-2026-54609 — QTI: In version 1.0.0, the relay's handleReconnectRequest forwards RECONNECT_REQUEST packets to the host without bounding

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-54609

QTI Neon is a minimal, game-agnostic, relay-based UDP multiplayer protocol library. In version 1.0.0, the relay's handleReconnectRequest forwards RECONNECT_REQUEST packets to the host without bounding them, so an unauthenticated client can drive relay-to-host amplification and cause a denial of service on the host. No fixed version is available as of this review. CVSSv3.1 8.6 (HIGH)

CWECWE 770CWECWE 400CWECWE 406VNDQtiTYPVulnerability
8.6
CVSS v3.1
93
Edit Score
2d ago
2026-07-28 17:16Z
HIGH

CVE-2026-54603 — OAuth2: From 0.4.0 to 2.0.21, a protocol-relative redirect Location returned to OAuth2::Client#request overrides the request

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-54603

OAuth2 is a Ruby wrapper for the OAuth 2.0 and 2.1 authorization frameworks, including OpenID Connect (OIDC). From 0.4.0 to 2.0.21, a protocol-relative redirect Location returned to OAuth2::Client#request overrides the request authority, so the bearer Authorization header is sent to an attacker-controlled host, leaking the credential. This issue is fixed in version 2.0.22. CVSSv3.1 8.6 (HIGH)

CWECWE 200CWECWE 601VNDOauth2TYPVulnerability
8.6
CVSS v3.1
93
Edit Score
2d ago
2026-07-28 17:16Z
HIGH

CVE-2026-51275 — ESP32: In schreibfaul1 ESP32-audioI2S 3.4.5, a heap-based buffer overflow in the ID3v2 APIC frame parsing

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-51275

In schreibfaul1 ESP32-audioI2S 3.4.5, a heap-based buffer overflow in the ID3v2 APIC frame parsing function in audiolib allows remote attackers to execute arbitrary code or cause a denial of service (crash) via a crafted MP3 file. The vulnerability exists due to missing length validation when processing the APIC frame size field, leading to an out-of-bounds memory write. CVSSv3.1 8.8 (HIGH)

CWECWE 122VNDEsp32TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2d ago
2026-07-28 17:16Z
HIGH

CVE-2026-51274 — ESP32: In schreibfaul1 ESP32-audioI2S 3.4.5, a heap-based buffer overflow in the ID3v2 SYLT synchronized lyrics

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-51274

In schreibfaul1 ESP32-audioI2S 3.4.5, a heap-based buffer overflow in the ID3v2 SYLT synchronized lyrics parser in audiolib allows remote attackers to cause a denial of service (application crash), information disclosure, or potential arbitrary code execution via a crafted MP3 file. The vulnerability occurs due to missing bounds validation on attacker-controlled frame size and improper memory access during lyric parsing. CVSSv3.1 8.8 (HIGH)

CWECWE 122VNDEsp32TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2d ago
2026-07-28 16:20Z
HIGH

CVE-2026-66748 — Camaleon: CMS versions 2.1.1 through 2.9.1 contains an authenticated remote code execution vulnerability that

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-66748

Camaleon CMS versions 2.1.1 through 2.9.1 contains an authenticated remote code execution vulnerability that allows users with custom_fields manage permission to execute arbitrary Ruby code by supplying a malicious expression through the select_eval custom field type. Attackers can store an attacker-controlled Ruby expression in the field options command parameter, which is evaluated via instance_eval within an ERB view whenever a post edit page is rendered, achieving server- CVSSv3.1 8.8 (HIGH)

CWECWE 94VNDCamaleonTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2d ago
2026-07-28 16:19Z
HIGH

CVE-2026-54593 — Pterodactyl: Prior to Panel version 1.12.3 and Wings version 1.12.2, the Wings /upload/file endpoint accepted

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-54593

Pterodactyl is a free, open-source game server management panel. Prior to Panel version 1.12.3 and Wings version 1.12.2, the Wings /upload/file endpoint accepted any valid panel-signed JWT that contained server_uuid, user_uuid, and unique_id claims without checking the token's intended purpose; because the Panel issues JWTs carrying those same claims for lower-privilege operations such as WebSocket authentication and file-download links, an authenticated subuser could reuse o CVSSv3.1 8.1 (HIGH)

CWECWE 1270CWECWE 1259VNDPterodactylTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2d ago
2026-07-28 16:18Z
CRIT

CVE-2026-51271 — ESP32: In schreibfaul1 ESP32-audioI2S 3.4.5, a heap-based buffer overflow vulnerability exists in the WAV header

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-51271

In schreibfaul1 ESP32-audioI2S 3.4.5, a heap-based buffer overflow vulnerability exists in the WAV header parsing function read_WAV_Header(). The function reads untrusted chunk size and bytes-to-skip value directly from malicious WAV files without reasonable range restriction. Abnormally large bts and headerSize values lead to out-of-bounds heap memory read/write during header parsing, which can be exploited to execute arbitrary code, disclose sensitive information, cause den CVSSv3.1 9.6 (CRITICAL)

CWECWE 122VNDEsp32TYPVulnerability
9.6
CVSS v3.1
98
Edit Score