Vulnerebility JULY H  ECV  KB  KEV |  2026()  2025() |
Vulnerebility Calendar  Top Vulnerebility  List of Attack  CWE   Anti-Debug Tricks


2026  January  February  March  April  May  June  July  August  September  October  November  December


DATE

NAME

INFO

CATEGORY

SUBCATE

31.7.26

CVE-2026-4368 Race Condition in NetScaler ADC and NetScaler Gateway when appliance is configured as Gateway (SSL VPN, ICA Proxy, CVPN, RDP Proxy) or AAA virtual server leading to User Session Mixup VULNEREBILITY VULNEREBILITY

31.7.26

CVE-2026-3055 Insufficient input validation in NetScaler ADC and NetScaler Gateway when configured as a SAML IDP leading to memory overread VULNEREBILITY VULNEREBILITY

31.7.26

CVE-2026-8233 A vulnerability was determined in Dotouch XproUPF 2.0.0-release-088aa7c4. Affected is an unknown function of the component UPF. This manipulation causes improper access controls. A high degree of complexity is needed for the attack. The exploitability is told to be difficult. The vendor was contacted early about this disclosure. VULNEREBILITY VULNEREBILITY

31.7.26

CVE-2026-3545 Insufficient data validation in Navigation in Google Chrome prior to 145.0.7632.159 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High) VULNEREBILITY VULNEREBILITY

30.7.26

CosmosEscape VULNEREBILITY VULNEREBILITY VULNEREBILITY

30.7.26

Certighost Certighost is an Active Directory Certificate Services (AD CS) vulnerability that allowed a low-privileged domain user to impersonate a Domain Controller and achieve domain compromise in the tested AD CS configuration. The issue was addressed in the July 2026 security updates. VULNEREBILITY VULNEREBILITY

30.7.26

CVE-2026-20316 Cisco Secure Firewall Management Center Use of Hard-coded Password Vulnerability VULNEREBILITY VULNEREBILITY

30.7.26

CVE-2026-47876 Vulnerability in Oracle Application Testing Suite. The supported version that is affected is 13.3.0.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via Oracle Net to compromise Oracle Application Testing Suite. VULNEREBILITY VULNEREBILITY

30.7.26

CVE-2026-41703 An unauthenticated remote attacker can cause a Denial of Service by turning off the output of the UPS via Modbus command. VULNEREBILITY VULNEREBILITY

30.7.26

CVE-2026-41709 An unauthenticated remote attacker can perform a command injection via Modbus-TCP or Modbus-RTU to gain read and write access on the affected device. VULNEREBILITY VULNEREBILITY

30.7.26

CVE-2026-66066 [CVE-2026-66066] Possible arbitrary file read and remote code execution in Active Storage variant processing VULNEREBILITY VULNEREBILITY

30.7.26

CVE-2026-59726 Unauthenticated RCE in ruflo MCP bridge default docker-compose deployment VULNEREBILITY VULNEREBILITY

29.7.26

CVE-2026-10702 JIT miscompilation in the JavaScript Engine: JIT component. This vulnerability was fixed in Firefox 151.0.3. VULNEREBILITY VULNEREBILITY

29.7.26

CVE-2025-60004 An Improper Check for Unusual or Exceptional Conditions vulnerability in the routing protocol daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows an unauthenticated, network-based attacker to cause a Denial-Of-Service (DoS). When an affected system receives a specific BGP EVPN update message over an established BGP session, this causes an rpd crash and restart. A BGP EVPN configuration is not necessary to be vulnerable. VULNEREBILITY VULNEREBILITY

28.7.26

CVE-2013-4786 The IPMI 2.0 specification supports RMCP+ Authenticated Key-Exchange Protocol (RAKP) authentication, which allows remote attackers to obtain password hashes and conduct offline password guessing attacks by obtaining the HMAC from a RAKP message 2 response from a BMC. VULNEREBILITY VULNEREBILITY

28.7.26

CVE-2026-62947 ACL bypass and arbitrary root file read via cgi-io cgi-download VULNEREBILITY VULNEREBILITY

28.7.26

CVE-2026-63921 In the Linux kernel, the following vulnerability has been resolved: ip6: vti: Use ip6_tnl.net in vti6_siocdevprivate(). After patch 1/2 in this series, vti6_update() unlinks and relinks the tunnel through t->net. vti6_siocdevprivate() still uses dev_net(dev) for the collision lookup. VULNEREBILITY VULNEREBILITY

28.7.26

CVE-2026-64739 Apple Libnotify/notifyd Stack Overflow (CVE-2026-64739) — Discovered by ThreatBook XGPT VULNEREBILITY VULNEREBILITY

28.7.26

CVE-2026-53264 In the Linux kernel, the following vulnerability has been resolved: net/sched: act_api: use RCU with deferred freeing for action lifecycle When NEWTFILTER and DELFILTER are run concurrently it is possible to create a race with an associated action. VULNEREBILITY VULNEREBILITY

28.7.26

CVE-2026-63077 In JetBrains TeamCity before 2026.1.3, 2025.11.7 unauthenticated remote code execution was possible via the agent polling protocol VULNEREBILITY VULNEREBILITY

28.7.26

CVE-2025-68686 Fortinet FortiOS Exposure of Sensitive Information to an Unauthorized Actor Vulnerability VULNEREBILITY VULNEREBILITY

28.7.26

CVE-2026-16812 Arista VeloCloud Orchestrator On-Prem OS Command Injection Vulnerability VULNEREBILITY VULNEREBILITY

28.7.26

CVE-2025-9528 A vulnerability was determined in Linksys E1700 1.0.0.4.003. This vulnerability affects the function systemCommand of the file /goform/systemCommand. Executing manipulation of the argument command can lead to os command injection. The attack may be launched remotely. The exploit has been publicly disclosed and may be utilized. VULNEREBILITY VULNEREBILITY

28.7.26

CVE-2026-61511 vBulletin 5.x through 5.7.5 and 6.x through 6.2.1 contains an eval injection vulnerability in the vB5_Template_Runtime::runMaths() method within the template runtime that allows unauthenticated remote attackers to execute arbitrary PHP code by supplying crafted input through the pagenav[pagenumber] parameter. VULNEREBILITY VULNEREBILITY

27.7.26

Bypassing n8n's CVE-2026-27577 Breaking the Sandbox Again: Bypassing n8n's CVE-2026-27577 Patch VULNEREBILITY VULNEREBILITY

26.7.26

CVE-2026-12569 A critical remote code execution (RCE) vulnerability has been reported in PTC Windchill PDMlink and PTC FlexPLM. The vulnerability may be exploited through the deserialization of untrusted data. * This advisory also applies to all CPS versions * The identified vulnerability also impacts Windchill and FlexPLM releases prior to 11.0 M030 VULNEREBILITY VULNEREBILITY

26.726

CVE-2025-56383 Notepad++ v8.8.3 has a DLL hijacking vulnerability, which can replace the original DLL file to execute malicious code. NOTE: this is disputed by multiple parties because the behavior only occurs when a user installs the product into a directory tree that allows write access by arbitrary unprivileged users. VULNEREBILITY VULNEREBILITY

26.7.26

CVE-2026-12569 A critical remote code execution (RCE) vulnerability has been reported in PTC Windchill PDMlink and PTC FlexPLM. The vulnerability may be exploited through the deserialization of untrusted data. * This advisory also applies to all CPS versions * The identified vulnerability also impacts Windchill and FlexPLM releases prior to 11.0 M030 VULNEREBILITY VULNEREBILITY

26.726

CVE-2025-56383 Notepad++ v8.8.3 has a DLL hijacking vulnerability, which can replace the original DLL file to execute malicious code. NOTE: this is disputed by multiple parties because the behavior only occurs when a user installs the product into a directory tree that allows write access by arbitrary unprivileged users. VULNEREBILITY VULNEREBILITY

25.7.26

FastJson 1.2.83 Remote Code Execution Everyone used to treat fastjson 1.2.83 as the safe one. It's the last release of the 1.x line, it ships with AutoType turned off by default, and for years the advice has been "just move to 1.2.83 and you are good." Not anymore! VULNEREBILITY VULNEREBILITY

25.7.26

CVE-2026-16723 A remote code execution (RCE) vulnerability exists in fastjson 1.2.68 through 1.2.83. This vulnerability is exploitable under fastjson's stock default configuration — no AutoType enablement required, no classpath gadget required. VULNEREBILITY VULNEREBILITY

24.7.26

CVE-2026-54121 Active Directory Certificate Services Elevation of Privilege Vulnerability VULNEREBILITY VULNEREBILITY

24.7.26

CVE-2026-21536 Microsoft Devices Pricing Program Remote Code Execution Vulnerability VULNEREBILITY VULNEREBILITY

24.7.26

CVE-2026-32194 filed as command injection under CWE-77, is the public "Search by Image" upload, with the SVG going in base64 as the imageBin field to /images/kblob. VULNEREBILITY VULNEREBILITY

24.7.26

CVE-2026-32191 filed as OS command injection under CWE-78, is the crawler route: host the SVG anywhere, hand its URL to the search through the imgurl parameter, and bingbot/2.0 fetches it into the same pipeline. Neither needs authentication, cookies, session state or a click. VULNEREBILITY VULNEREBILITY

24.7.26

CVE-2025-27915 An issue was discovered in Zimbra Collaboration (ZCS) 9.0 and 10.0 and 10.1. A stored cross-site scripting (XSS) vulnerability exists in the Classic Web Client due to insufficient sanitization of HTML content in ICS files. VULNEREBILITY VULNEREBILITY

24.7.26

0day .ICS attack in the wild Earlier in 2025, an apparent sender from 193.29.58.37 spoofed the Libyan Navy’s Office of Protocol to send a then-zero-day exploit in Zimbra’s Collaboration Suite, CVE-2025-27915, targeting Brazil’s military. VULNEREBILITY ICS

24.7.26

CVE-2026-58593 NodeBB does not bind the claimed author of an inbound ActivityPub object to the authenticated remote actor. The inbound middleware verifies the HTTP-signature actor and checks the origin of object.id, but never validates that attributedTo corresponds to the sender. VULNEREBILITY VULNEREBILITY

24.7.26

CVE-2026-25589 RedisBloom is a probabilistic data structures module for Redis. In all versions of RedisBloom before 2.8.20, the module does not properly validate serialized values processed through the Redis RESTORE command. VULNEREBILITY VULNEREBILITY

24.7.26

CVE-2026-25243 Redis is an in-memory data structure store. In versions of redis-server up to 8.6.3, the RESTORE command does not properly validate serialized values. An authenticated attacker with permission to execute RESTORE can supply a crafted serialized payload that triggers invalid memory access and may lead to remote code execution. VULNEREBILITY VULNEREBILITY

24.7.26

CVE-2026-8496 A cross-site scripting (XSS) vulnerability exists in Alinto SOGo, version 5.12.7. A maliciously crafted ICS calendar invitation files allows arbitrary JavaScript execution within the authenticated SOGo webmail session. VULNEREBILITY VULNEREBILITY

24.7.26

CVE-2025-66376 Zimbra Collaboration (ZCS) 10 before 10.0.18 and 10.1 before 10.1.13 allows Classic UI stored XSS via Cascading Style Sheets (CSS) @import directives in an HTML e-mail message. VULNEREBILITY VULNEREBILITY

23.7.26

Cookie Crumbles Cookie Crumbles: How Exploitation of CVE-2026-0257 Leads to Qilin Ransomware VULNEREBILITY VULNEREBILITY

23.7.26

CVE-2026-0257 Authentication bypass vulnerabilities in the GlobalProtect portal and gateway of Palo Alto Networks PAN-OS® software allows the attacker to bypass security restrictions and establish an unauthorized VPN connection. Panorama and Cloud NGFW are not impacted by these issues. VULNEREBILITY VULNEREBILITY

23.7.26

SharedRoot SharedRoot; Escaping the Claude Cowork sandbox VULNEREBILITY VULNEREBILITY

23.7.26

RefluXFS RefluXFS: A Linux Kernel Local Privilege Escalation to Root in XFS (CVE-2026-64600) VULNEREBILITY VULNEREBILITY

23.7.26

CVE-2026-64600 In the Linux kernel, the following vulnerability has been resolved: net: hsr: fix potential OOB access in supervision frame handling Ensure the entire TLV header is linearized before access by adding sizeof(struct hsr_sup_tlv) to the pskb_may_pull() calls. Without this, a truncated frame could cause an out-of-bounds access. VULNEREBILITY VULNEREBILITY

23.7.26

CVE-2026-16232 Authentication bypass with SmartConsole login process using application token VULNEREBILITY VULNEREBILITY

23.7.26

Hermeticreader The Vulnerability That Turned Adobe's 300M-Install Extension Into a Full WhatsApp Takeover VULNEREBILITY VULNEREBILITY

23.7.26

CVE-2026-8933 CVE-2026-8933: Local Privilege Escalation in Set-Capabilities snap-confine VULNEREBILITY VULNEREBILITY

23.7.26

CVE-2026-48294 Adobe Acrobat PDF Extension (Chrome) versions 26.5.2.2 and earlier are affected by a UXSS-class cross-origin data disclosure vulnerability. An attacker could exploit this vulnerability to gain access to data regarding the victim's session. VULNEREBILITY VULNEREBILITY

23.7.26

CVE-2026-29059 Windmill is an open-source developer platform for internal code: APIs, background jobs, workflows and UIs. Prior to version 1.603.3, an unauthenticated path traversal vulnerability exists in Windmill's get_log_file endpoint "(/api/w/{workspace}/jobs_u/get_log_file/{filename})". VULNEREBILITY VULNEREBILITY

21.7.26

CVE-2026-10591 CVE-2026-10591 - Kiro IDE Insufficient File Write Restrictions to Execution-Sensitive Paths VULNEREBILITY VULNEREBILITY

21.7.26

CVE-2026-50522 Microsoft SharePoint Remote Code Execution Vulnerability VULNEREBILITY VULNEREBILITY

21.7.26

CVE-2026-0257 Authentication bypass vulnerabilities in the GlobalProtect portal and gateway of Palo Alto Networks PAN-OS® software allows the attacker to bypass security restrictions and establish an unauthorized VPN connection. Panorama and Cloud NGFW are not impacted by these issues. VULNEREBILITY VULNEREBILITY

21.7.26

LegacyHive Free micropatches available for "LegacyHive" 0day VULNEREBILITY VULNEREBILITY

21.7.26

CVE-2026-63030 WordPress < 7.0.2 - REST API batch-route confusion and SQL injection issue leading to Remote Code Execution VULNEREBILITY VULNEREBILITY

21.7.26

CVE-2025-3248 Langflow versions prior to 1.3.0 are susceptible to code injection in the /api/v1/validate/code endpoint. A remote and unauthenticated attacker can send crafted HTTP requests to execute arbitrary code. VULNEREBILITY VULNEREBILITY

21.7.26

CVE-2026-6875 ServiceNow has addressed a remote code execution vulnerability that was identified in the ServiceNow AI platform. This vulnerability could enable an unauthenticated user, in certain circumstances, to execute code within the ServiceNow platform. VULNEREBILITY VULNEREBILITY

20.7.26

CVE-2025-33053 External control of file name or path in Internet Shortcut Files allows an unauthorized attacker to execute code over a network. VULNEREBILITY VULNEREBILITY

20.7.26

CVE-2026-14266 7-Zip XZ Decompression Heap-based Buffer Overflow Remote Code Execution Vulnerability VULNEREBILITY VULNEREBILITY

20.7.26

CVE-2026-42533 A vulnerability exists in NGINX Plus and NGINX Open Source when a map directive uses regex matching and a string expression references the map's regex capture variables before referencing the map output variable VULNEREBILITY VULNEREBILITY

19.7.26

OpenSSL HollowByte OpenSSL HollowByte: A DoS Hiding in 11 Bytes VULNEREBILITY VULNEREBILITY

18.7.26

CVE-2026-53410 high-severity TOCTOU (time-of-check to time-of-use) race condition affecting Zoom Workplace for Windows before 7.0.5, Zoom Workplace VDI Client and VDI Plugin before 6.5.17/6.6.14, Zoom Rooms for Windows before 7.0.5, and Remote Control for Zoom Contact Center before 7.0.0. VULNEREBILITY VULNEREBILITY

18.7.26

CVE-2026-53409 high-severity improper privilege management flaw affecting Zoom Rooms for Windows before version 7.1.0 that could allow an authenticated user with local access to escalate privileges. VULNEREBILITY VULNEREBILITY

18.7.26

CVE-2026-53411 high-severity improper input validation flaw affecting the Zoom Workplace VDI Plugin for Windows before version 6.6.14 that could allow an authenticated user with local access to escalate privileges. VULNEREBILITY VULNEREBILITY

18.7.26

CVE-2026-60137 WordPress 6.8.x before 6.8.6, 6.9.x before 6.9.5, and 7.0.x before 7.0.2 does not properly sanitise the author__not_in parameter of WP_Query, which could allow SQL Injection when a plugin or theme passes untrusted input to the parameter. VULNEREBILITY VULNEREBILITY

18.7.26

CVE-2026-44761 SAP Commerce Cloud could retain a sample OAuth2 client with publicly documented sample credentials originating from sample configuration provided in SAP Help Portal documentation. If left unchanged, an unauthenticated attacker could use these well-known credentials to obtain a valid access token and invoke certain APIs to read and modify data. Successful exploitation results in high impact on confidentiality and integrity, with no impact on availability. VULNEREBILITY VULNEREBILITY

18.7.26

CVE-2026-44747 SAP NetWeaver Application Server ABAP allows an authenticated attacker to leverage logical errors in memory management to cause a memory corruption that could lead to unauthorized data access, modification, or system unavailability. This has high impact on confidentiality, integrity, and availability of the application. VULNEREBILITY VULNEREBILITY

18.7.26

CVE-2025-40948 An attacker leverages an insecure configuration of the xz utility, which executes with root privileges, to read any file on the switch’s file system. This vulnerability enables initial reconnaissance that could reveal critical information such as sensitive configuration files, password hashes and private cryptographic keys. VULNEREBILITY VULNEREBILITY

18.7.26

CVE-2025-40947 This critical flaw resides in the feature key validation function. The function fails to sanitize an attacker-controlled payload before inserting it directly into a command executed with root privileges. Exploiting this allows for direct command injection and full root access. VULNEREBILITY VULNEREBILITY

187.26

CVE-2025-40949 Following privilege escalation, the final vulnerability is exploited in the switch’s web management task scheduler. Improper input sanitization allows an authenticated attacker to inject malicious commands into the system’s root cron table. This establishes persistent code execution, surviving system reboots and maintaining full control. VULNEREBILITY VULNEREBILITY
177.26 CVE-2026-58644 Microsoft SharePoint Remote Code Execution Vulnerability VULNEREBILITY VULNEREBILITY
16.7.26 CVE-2026-59208 n8n is an open source workflow automation platform. Prior to 2.27.4 and from 2.28.0 prior to 2.28.1, n8n instances configured with more than one trusted token-exchange issuer resolved external identities to local accounts using only the JWT sub claim and ignored the iss claim, allowing an attacker with a valid token from one trusted issuer and a sub matching a victim under another issuer to authenticate as that victim. This issue is fixed in versions 2.27.4 and 2.28.1. VULNEREBILITY VULNEREBILITY
16.7.26 CVE-2026-55040 Microsoft SharePoint Server Security Feature Bypass Vulnerability VULNEREBILITY VULNEREBILITY
16.7.26 CVE-2026-45659 Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. VULNEREBILITY VULNEREBILITY
16.7.26 CVE-2026-32201 Improper input validation in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network. VULNEREBILITY VULNEREBILITY
16.7.26 CVE-2026-53411 (CVSS score: 7.8) - An improper input validation vulnerability in the Zoom Workplace VDI Plugin for Windows before version 6.6.14 that may allow an authenticated user to conduct an escalation of privilege via local access. VULNEREBILITY VULNEREBILITY
16.7.26 CVE-2026-53410 (CVSS score: 7.0) - A time-of-check to time-of-use (TOCTOU) race condition vulnerability in the installation and uninstallation process of certain Zoom Clients for Windows that could allow an authenticated local user to escalate privileges. VULNEREBILITY VULNEREBILITY
16.7.26 CVE-2026-53409 (CVSS score: 7.8) - An improper privilege management vulnerability in Zoom Rooms for Windows before version 7.1.0 that may allow an authenticated user to conduct an escalation of privilege via local access. VULNEREBILITY VULNEREBILITY
16.7.26 CVE-2026-15765 Use after free in Ozone in Google Chrome prior to 150.0.7871.125 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Critical) VULNEREBILITY VULNEREBILITY
16.7.26 CVE-2026-15764 Use after free in Ozone in Google Chrome on Linux prior to 150.0.7871.125 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Critical) VULNEREBILITY VULNEREBILITY
16.7.26 CVE-2026-15718 We are aware that exploit code for this is public however we are not aware of any attacks in the wild abusing this flaw. This vulnerability was fixed in Firefox 152.0.6. VULNEREBILITY VULNEREBILITY
16.7.26 CVE-2026-15719 We are aware that exploit code for this is public however we are not aware of any attacks in the wild abusing this flaw. This vulnerability was fixed in Firefox 152.0.6. VULNEREBILITY VULNEREBILITY
15.7.26 CVE-2026-56164 Microsoft SharePoint Server Elevation of Privilege Vulnerability VULNEREBILITY VULNEREBILITY
15.7.26 CVE-2026-56155 Active Directory Federation Services Elevation of Privilege Vulnerability VULNEREBILITY VULNEREBILITY
15.7.26 CVE-2026-15409 (CVSS score: 10.0) - A Server-side request forgery (SSRF) vulnerability that a remote unauthenticated attacker could exploit to potentially cause the appliance to make requests to an unintended location. VULNEREBILITY VULNEREBILITY
15.7.26 CVE-2026-15410 (CVSS score: 7.2) - A post-authentication code injection vulnerability rooted in the Appliance Management Console (AMC) that a remote authenticated attacker could exploit to execute arbitrary operating system commands as administrator under certain conditions. VULNEREBILITY VULNEREBILITY
14.7.26 CVE-2026-44747 SAP NetWeaver Application Server ABAP allows an authenticated attacker to leverage logical errors in memory management to cause a memory corruption that could lead to unauthorized data access, modification, or system unavailability. VULNEREBILITY VULNEREBILITY
14.7.26 CVE-2026-27690 (CVSS score: 9.1) - An HTTP request/response smuggling flaw in SAP Approuter deployments in non-Cloud Foundry environments that allows an unauthenticated attacker to send a specially crafted HTTP request that leads to request-response desynchronization and results in the exposure of user responses and triggers denial-of-service (DoS) attacks. VULNEREBILITY VULNEREBILITY
14.7.26 CVE-2026-44761 (CVSS score: 9.1) - A use of default credentials flaw in SAP Commerce Cloud that could retain a sample OAuth 2.0 client with publicly documented sample credentials originating from a sample configuration provided in SAP Help Portal documentation. VULNEREBILITY VULNEREBILITY
14.7.26 CVE-2026-44747 SAP NetWeaver Application Server ABAP allows an authenticated attacker to leverage logical errors in memory management to cause a memory corruption that could lead to unauthorized data access, modification, or system unavailability. VULNEREBILITY VULNEREBILITY
14.7.26 CVE-2026-27690 (CVSS score: 9.1) - An HTTP request/response smuggling flaw in SAP Approuter deployments in non-Cloud Foundry environments that allows an unauthenticated attacker to send a specially crafted HTTP request that leads to request-response desynchronization and results in the exposure of user responses and triggers denial-of-service (DoS) attacks. VULNEREBILITY VULNEREBILITY
14.7.26 CVE-2026-44761 (CVSS score: 9.1) - A use of default credentials flaw in SAP Commerce Cloud that could retain a sample OAuth 2.0 client with publicly documented sample credentials originating from a sample configuration provided in SAP Help Portal documentation. VULNEREBILITY VULNEREBILITY
14.7.26 Forgotten UEFI shims undermining Secure Boot ESET researchers discovered 11 vulnerable UEFI shim bootloaders signed by Microsoft that allow attackers to bypass UEFI Secure Boot by exploiting decade-old vulnerabilities VULNEREBILITY VULNEREBILITY
14.7.26 CVE-2026-57219 (CVSS score: 8.7) - An obsolete HTTP API endpoint ("GET /api/auth") that reveals client secret on RabbitMQ installations that had OAuth 2 configured to use the management.oauth_client_secret configuration key, allowing an attacker to exchange it for an administrator token and obtain full control of every message, queue, user, and broker setting. VULNEREBILITY VULNEREBILITY
14.7.26 CVE-2026-57221 (CVSS score: 5.3) - A missing authorization that allows any authenticated user who can connect to a virtual host to enumerate all queue and exchange names in that virtual host and read queue message counts and consumer counts, regardless of their actual permissions. VULNEREBILITY VULNEREBILITY
14.7.26 CVE-2026-8863 UEFI Secure Boot Security Feature Bypass Vulnerability VULNEREBILITY VULNEREBILITY
9.7.26 CVE-2026-50656 Microsoft Defender Elevation of Privilege Vulnerability VULNEREBILITY VULNEREBILITY
9.7.26 CVE-2026-39861 Claude Code is an agentic coding tool. Prior to version 2.1.64, Claude Code's sandbox did not prevent sandboxed processes from creating symlinks pointing to locations outside the workspace. VULNEREBILITY VULNEREBILITY
8.7.26 CVE-2026-55116 A malicious actor with access to the network and under certain network configurations could exploit an Improper Access Control vulnerability found in certain devices running UniFi OS to make unauthorized changes to such UniFi OS devices. VULNEREBILITY VULNEREBILITY
8.7.26 CVE-2026-54402 A malicious actor with access to the network and low privileges could exploit an Improper Input Validation vulnerability found in UniFi OS to execute a Command Injection on the host device. VULNEREBILITY VULNEREBILITY
8.7.26 CVE-2026-55115 A malicious actor with access to the network and low privileges could exploit a Server-Side Request Forgery (SSRF) in UniFi Protect Application to escalate privileges on the host device. VULNEREBILITY VULNEREBILITY
8.7.26 CVE-2026-54400 A malicious actor with access to the network and high privileges could exploit an Improper Access Control vulnerability found in UniFi Access Application to escalate privileges on the host device. VULNEREBILITY VULNEREBILITY
8.7.26 CVE-2026-50748 A malicious actor with access to the network and low privileges could exploit an Improper Input Validation vulnerability found in UniFi Access Application to execute a Command Injection on the host device. VULNEREBILITY VULNEREBILITY
8.7.26 CVE-2026-50747 A malicious actor with access to the network and low privileges could exploit a series of authenticated SQL Injection vulnerabilities found in UniFi Talk Application to escalate privileges on the host device. VULNEREBILITY VULNEREBILITY
8.7.26 CVE-2026-50746 A malicious actor with access to the network could exploit an Improper Access Control vulnerability found in UniFi Connect Application to execute a Command Injection on the host device. VULNEREBILITY VULNEREBILITY
8.7.26 SCMBANKER ClickFix to Cash-Out: Anatomy of a Mexican Banking-Fraud Toolkit VULNEREBILITY VULNEREBILITY
8.7.26 CVE-2025-2492 An improper authentication control vulnerability exists in AiCloud. This vulnerability can be triggered by a crafted request, potentially leading to unauthorized execution of functions. Refer to the 'ASUS Router AiCloud vulnerability' section on the ASUS Security Advisory for more information. VULNEREBILITY VULNEREBILITY
8.7.26 CVE-2023-25717 Ruckus Wireless Admin through 10.4 allows Remote Code Execution via an unauthenticated HTTP GET Request, as demonstrated by a /forms/doLogin?login_username=admin&password=password$(curl substring. VULNEREBILITY VULNEREBILITY
8.7.26 CVE-2020-22658 In Ruckus R310 10.5.1.0.199, Ruckus R500 10.5.1.0.199, Ruckus R600 10.5.1.0.199, Ruckus T300 10.5.1.0.199, Ruckus T301n 10.5.1.0.199, Ruckus T301s 10.5.1.0.199, SmartCell Gateway 200 (SCG200) before 3.6.2.0.795, SmartZone 100 (SZ-100) before 3.6.2.0.795, SmartZone 300 (SZ300) before 3.6.2.0.795, Virtual SmartZone (vSZ) before 3.6.2.0.795, ZoneDirector 1100 9.10.2.0.130, ZoneDirector 1200 10.2.1.0.218, ZoneDirector 3000 10.2.1.0.218, ZoneDirector 5000 10.0.1.0.151, a vulnerability allows attackers to switch completely to unauthorized image to be Boot as primary verified image. VULNEREBILITY VULNEREBILITY
8.7.26 CVE-2020-22653 In Ruckus R310 10.5.1.0.199, Ruckus R500 10.5.1.0.199, Ruckus R600 10.5.1.0.199, Ruckus T300 10.5.1.0.199, Ruckus T301n 10.5.1.0.199, Ruckus T301s 10.5.1.0.199, SmartCell Gateway 200 (SCG200) before 3.6.2.0.795, SmartZone 100 (SZ-100) before 3.6.2.0.795, SmartZone 300 (SZ300) before 3.6.2.0.795, Virtual SmartZone (vSZ) before 3.6.2.0.795, ZoneDirector 1100 9.10.2.0.130, ZoneDirector 1200 10.2.1.0.218, ZoneDirector 3000 10.2.1.0.218, ZoneDirector 5000 10.0.1.0.151, a vulnerability allows attackers to exploit the official image signature to force injection unauthorized image signature. VULNEREBILITY VULNEREBILITY
8.7.26 WriteOut WriteOut: Abusing the Sandbox for a Critical Cross-Tenant Vulnerability in Writer AI VULNEREBILITY VULNEREBILITY
8.7.26 GitLost GitLost: How We Tricked GitHub’s AI Agent into Leaking Private Repos VULNEREBILITY VULNEREBILITY
8.7.26 CVE-2026-26030 Semantic Kernel, Microsoft's semantic kernel Python SDK, has a remote code execution vulnerability in versions prior to 1.39.4, specifically within the `InMemoryVectorStore` filter functionality. VULNEREBILITY VULNEREBILITY
8.7.26 CVE-2026-25592 Semantic Kernel is an SDK used to build, orchestrate, and deploy AI agents and multi-agent systems. Prior to 1.71.0, an Arbitrary File Write vulnerability has been identified in Microsoft's Semantic Kernel .NET SDK, specifically within the SessionsPythonPlugin. VULNEREBILITY VULNEREBILITY
8.7.26 CVE-2026-48282 (CVSS score: 10.0) - A path traversal vulnerability in Adobe ColdFusion that could lead to arbitrary code execution in the context of the current user. VULNEREBILITY VULNEREBILITY
8.7.26 CVE-2026-56290 (CVSS score: 10.0) - An improper access control vulnerability in Joomlack Page Builder that could allow for remote code execution via unauthenticated arbitrary file upload. VULNEREBILITY VULNEREBILITY
8.7.26 CVE-2026-55255 (CVSS score: 6.1) - An authorization bypass through a user-controlled key vulnerability in Langflow that could allow an authenticated attacker to execute any flow belonging to another user by specifying the victim's flow ID in the request. VULNEREBILITY VULNEREBILITY
8.7.26 CVE-2026-48908 (CVSS score: 10.0) - An unrestricted upload of a file with a dangerous type vulnerability in JoomShaper SP Page Builder that allows unauthenticated users to upload arbitrary files, ultimately resulting in the upload and execution of PHP code. VULNEREBILITY VULNEREBILITY
8.7.26 GhostLock 15-Year-Old GhostLock Flaw Enables Root and Container Escape on Most Linux Distros VULNEREBILITY VULNEREBILITY
8.7.26 CVE-2026-43499 In the Linux kernel, the following vulnerability has been resolved: rtmutex: Use waiter::task instead of current in remove_waiter() remove_waiter() is used by the slowlock paths, but it is also used for proxy-lock rollback in rt_mutex_start_proxy_lock() when invoked from futex_requeue(). VULNEREBILITY VULNEREBILITY
7.7.26 CVE-2026-11405 The web server binary /bin/httpd contains a hidden backdoor authentication mechanism in the login() function at 004c88b8. - The function contains a normal authentication path using MD5/hash-based password verification (prod_encode64/PasswordToMd5/check_rand_key). VULNEREBILITY VULNEREBILITY
7.7.26 CVE-2026-40138 A critical pre-authentication vulnerability exists in the authentication subsystem of BeyondTrust Remote Support and Privileged Remote Access. VULNEREBILITY VULNEREBILITY
7.7.26 CVE-2026-40139 A critical pre-authentication vulnerability exists in the authentication subsystem of BeyondTrust Remote Support. VULNEREBILITY VULNEREBILITY
7.7.26 CVE-2026-40140 BeyondTrust Remote Support and Privileged Remote Access contain a high-severity pre-authentication vulnerability in the network communication subsystem. VULNEREBILITY VULNEREBILITY
7.7.26 CVE-2026-40141 A high-severity vulnerability exists in a web application component of BeyondTrust Remote Support and Privileged Remote Access related to the processing of certain input parameters. VULNEREBILITY VULNEREBILITY
7.7.26 CVE-2025-52691 SmarterMail remote code execution vulnerability VULNEREBILITY VULNEREBILITY
7.7.26 CVE-2025-68613 n8n remote code execution vulnerability VULNEREBILITY VULNEREBILITY
7.7.26 CVE-2025-9316 N-Central unauthenticated sessionID generation vulnerability VULNEREBILITY VULNEREBILITY
7.7.26 CVE-2025-34291 Langflow remote code execution vulnerability VULNEREBILITY VULNEREBILITY
7.7.26 CVE-2025-54068 Laravel Livewire remote code execution vulnerability VULNEREBILITY VULNEREBILITY
6.7.26 Januscape Januscape: Guest-to-Host Escape in KVM/x86 VULNEREBILITY VULNEREBILITY
6.7.26 CVE-2026-53359 In the Linux kernel, the following vulnerability has been resolved: KVM: x86: Fix shadow paging use-after-free due to unexpected role Commit 0cb2af2ea66ad ("KVM: x86: Fix shadow paging use-after-free due to unexpected GFN") fixed a shadow paging mismatch between stored and computed GFNs; the bug could be triggered by changing a PDE mapping from outside the guest, and then deleting a memslot. VULNEREBILITY VULNEREBILITY
6.7.26 CVE-2026-20896 Gitea Docker image: `REVERSE_PROXY_TRUSTED_PROXIES = *` default lets any source IP impersonate any user via `X-WEBAUTH-USER` VULNEREBILITY VULNEREBILITY
5.7.26 CVE-2026-20230 A vulnerability in Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communications Manager Session Management Edition (Unified CM SME) could allow an unauthenticated, remote attacker to conduct server-side request forgery (SSRF) attacks through an affected device. VULNEREBILITY VULNEREBILITY
5.7.26 CVE-2026-46817 Vulnerability in the Oracle Payments product of Oracle E-Business Suite (component: File Transmission). Supported versions that are affected are 12.2.3-12.2.15. VULNEREBILITY VULNEREBILITY
5.7.26 CVE-2026-33825 Insufficient granularity of access control in Microsoft Defender allows an authorized attacker to elevate privileges locally. VULNEREBILITY VULNEREBILITY
4.7.26 Bad Epoll In the Linux kernel, the following vulnerability has been resolved: eventpoll: fix ep_remove struct eventpoll / struct file UAF ep_remove() (via ep_remove_file()) cleared file->f_ep under file->f_lock but then kept using @file inside the critical section (is_file_epoll(), hlist_del_rcu() through the head, spin_unlock). A concurrent __fput() taking the eventpoll_release() fastpath in that window observed the transient NULL, skipped eventpoll_release_file() and ran to f_op->release / file_free(). VULNEREBILITY VULNEREBILITY
4.7.26 CVE-2026-46242 In the Linux kernel, the following vulnerability has been resolved: eventpoll: fix ep_remove struct eventpoll / struct file UAF ep_remove() (via ep_remove_file()) cleared file->f_ep under file->f_lock but then kept using @file inside the critical section (is_file_epoll(), hlist_del_rcu() through the head, spin_unlock). A concurrent __fput() taking the eventpoll_release() fastpath in that window observed the transient NULL, skipped eventpoll_release_file() and ran to f_op->release / file_free(). VULNEREBILITY VULNEREBILITY
4.7.26 CVE-2026-31694 In the Linux kernel, the following vulnerability has been resolved: fuse: reject oversized dirents in page cache fuse_add_dirent_to_cache() computes a serialized dirent size from the server-controlled namelen field and copies the dirent into a single page-cache page. VULNEREBILITY VULNEREBILITY
4.7.26 CVE-2026-6684  (CVSS 4.6, Medium) – CVE-2026-6684 covers a GPT entry-count abuse case that can trigger effectively unbounded scanning in older trees. That creates a severe mount-time DoS in affected pre-R0.16 implementations, especially painful in boot paths, but it is ranked last here because upstream R0.16 added protective GPT validation. Now, it's up to implementers to upgrade. VULNEREBILITY VULNEREBILITY
4.7.26 CVE-2026-6686 (CVSS 4.6, Medium) – CVE-2026-6686 describes an uninitialized-cluster exposure path where extending files beyond EOF can leak stale data from previously deleted content. It is an information-disclosure bug with real consequences in multi-stage boot/update and shared-media environments. VULNEREBILITY VULNEREBILITY
4.7.26 CVE-2026-6683 (CVSS 4.6, Medium) – CVE-2026-6683 documents a divide-by-zero condition in exFAT sync/write flows that can be triggered by crafted media and produce reliable crash behavior. In update contexts, this can become a practical bricking vector. While generally more "DoS than RCE," it still offers meaningful attacker value against availability, especially given the OTA implications. VULNEREBILITY VULNEREBILITY
4.7.26 CVE-2026-6685 (CVSS 6.1, Medium) – CVE-2026-6685 describes a condition where on fragmented volumes, arithmetic wrap can drive stale dirty-cache behavior and out-of-bounds memory effects in read/write paths. This can manifest as silent corruption, which is exactly the kind of bug operators hate most: hard to detect, easy to misdiagnose, and dangerous in control/data-logging workloads. VULNEREBILITY VULNEREBILITY
4.7.26 CVE-2026-6688 (CVSS 7.6, High) – With LFN enabled, fno.fname can be much larger than many caller buffers expect, as described by CVE-2026-6688. The bug class appears repeatedly in integrations (strcpy, sprintf, fixed-size name/path fields). This one is tricky to fix entirely in FatFs directly (since exploitation depends on wrappers copying long filenames into undersized local buffers), but it could be mitigated by FatFs changes that make filename lengths and truncation/validation outcomes more explicit to callers. VULNEREBILITY VULNEREBILITY
4.7.26 CVE-2026-6687 (CVSS 7.6, High) – CVE-2026-6687 describes a condition where the exFAT label length field is not adequately capped, enabling oversized writes into caller-provided label buffers. This is especially painful where canonical examples and generated code use small stack buffers. It is a clean memory-corruption primitive in a path many firmware projects expose, at least where exFAT has been enabled. VULNEREBILITY VULNEREBILITY
4.7.26 CVE-2026-6682 In FatFS R0.16 and earlier contains a FAT32 integer overflow bug in mount_volume() where fasize *= fs->n_fats can wrap, leading to attacker-controlled file-size metadata and unsafe read lengths in downstream callers. VULNEREBILITY VULNEREBILITY
2.7.26 CVE-2026-45659 Microsoft SharePoint Server Deserialization of Untrusted Data Vulnerability VULNEREBILITY VULNEREBILITY
2.7.26 CVE-2026-42880 Kubernetes Secret Extraction via ArgoCD ServerSideDiff VULNEREBILITY VULNEREBILITY
2.7.26 CVE-2025-55190 Project API Token Exposes Repository Credentials VULNEREBILITY VULNEREBILITY
2.7.26 CVE-2024-31989 Use of Risky or Missing Cryptographic Algorithms in Redis Cache VULNEREBILITY VULNEREBILITY
1.7.26 CVE-2026-50548 abuses a setting. The sandbox permits writes into a command's working folder, and that folder is an optional parameter, working_directory, on Cursor's run_terminal_cmd tool. When the agent sets it to a non-default path, Cursor adds that path to the allowed-write list without question. Injected instructions point it at a system file instead of the project. Overwrite the sandbox helper itself (on macOS, /Applications/Cursor.app/Contents/Resources/app/resources/helpers/cursorsandbox), and later commands run with no sandbox at all. Startup files like ~/.zshrc work as targets too. VULNEREBILITY VULNEREBILITY
1.7.26 CVE-2026-50549 abuses a safety check. Before writing, Cursor resolves shortcuts (symlinks) to confirm the real destination sits inside your project. The bug is the fallback: when that check fails, because the target does not exist or the attacker removes read access from a folder in the path, Cursor gives up and trusts the shortcut's in-project path instead. An attacker creates a shortcut that points outside the project, forces the check to fail, and Cursor writes straight through it to the same sandbox helper. Same escape, different door. VULNEREBILITY VULNEREBILITY
1.7.26 DuneSlide DuneSlide: Two Critical RCE vulnerabilities via Zero-Click Prompt Injection in Cursor IDE VULNEREBILITY VULNEREBILITY
1.7.26 CVE-2026-8451 (CVSS score: 8.8) - An insufficient input validation vulnerability leading to memory overread when NetScaler ADC or NetScaler Gateway is configured as a SAML IDP VULNEREBILITY VULNEREBILITY
1.7.26 CVE-2026-8452 (CVSS score: 8.8) - A memory overflow vulnerability leading to unpredictable or erroneous behavior and denial-of-service when the appliance is configured as a Gateway or an AAA virtual server VULNEREBILITY VULNEREBILITY
1.7.26 CVE-2026-8655 (CVSS score: 8.8) - Multiple memory overflow vulnerabilities leading to unpredictable or erroneous behavior and denial-of-service when NetScaler ADC is configured as an LB of type Oracle, a DNS Proxy, or a DNS recursive resolver deployment VULNEREBILITY VULNEREBILITY
1.7.26 CVE-2026-10816 (CVSS score: 7.7) - An external control of the file name of the path vulnerability leading to unauthenticated, arbitrary file read when access to NSIP, Cluster Management IP, or SNIP with management access is enabled VULNEREBILITY VULNEREBILITY
1.7.26 CVE-2026-10817 (CVSS score: 6.9) - An insufficient input validation vulnerability leading to memory overread when TCP TimeStamp is enabled in TCP Profile and associated with the virtual server (of type LB, CS, VPN) or the service configured on NetScaler VULNEREBILITY VULNEREBILITY
1.7.26 CVE-2026-13474 (CVSS score: 8.7) - A missing release of memory after effective lifetime vulnerability leading to denial-of-service via malformed HTTP/2 requests when HTTP/2 is enabled in the HTTP Profile and associated with the virtual server (of type LB, CS, VPN) or the service configured on NetScaler VULNEREBILITY VULNEREBILITY