Entities
1019 CVEs, actors, campaigns, incidents, tools, advisories, and reports tracked across briefs. The ×N marker counts entries referencing an entity · multi-entry entities are the "stories that unfolded".
Total entities
1019
9 types
Recent (30 d)
381
entities with new coverage in window
Distinct sources
390
hosts cited at least once
Total appearances
1373
brief-section attributions
Co-occurrence links
1324
entity ↔ entity in same item
By type
- cve590 (58%)
- incident127 (12%)
- campaign123 (12%)
- actor52 (5%)
- tool47 (5%)
- trend32 (3%)
- report29 (3%)
- policy17 (2%)
- malware2 (0%)
Recent coverage
Aggregate mentions per ISO week, last 11 weeks.
By year
- actor ShinyHunters×64
- actor The Gentlemen×24
- actor UTA0533
- tool KNUCKLEBALL / ORANGETAIL SonicWall SMA toolset
- campaign Contagious Interview×4
- tool OTTERCOOKIE
- malware GoSerpent
- actor TetrisPhantom
- cve Siemens RUGGEDCOM ROX II feature-key gpgv command injection to root (CVSS 7.5); Unit 42 chain
- cve Siemens RUGGEDCOM ROX II arbitrary file disclosure via root-privileged xz misuse (CVSS 6.8); Unit 42 chain
- cve Siemens RUGGEDCOM ROX II task-scheduler command injection, persistent root (CVSS 9.1); Siemens SSA-081142
- cve SonicWall SMA1000 Work Place unauthenticated SSRF (CVSS 10.0, actively exploited)×2
- cve SonicWall SMA1000 AMC post-auth code injection (actively exploited)×2
- cve VMware Avi Load Balancer control-plane unauthenticated authentication bypass (CVSS 9.8), VMSA-2026-0005
- cve VMware Avi Load Balancer authorization bypass (CVSS 8.3), VMSA-2026-0005
- cve VMware Avi Load Balancer high-privilege RCE (CVSS 8.7), VMSA-2026-0005
- cve VMware Avi Load Balancer local privilege escalation to root (CVSS 7.8), VMSA-2026-0005
- cve VMware Avi Load Balancer authenticated RCE (CVSS 8.7), VMSA-2026-0005
- cve VMware Avi Load Balancer privilege escalation (CVSS 7.1), VMSA-2026-0005
- cve VMware Avi Load Balancer authenticated directory traversal (CVSS 8.8), VMSA-2026-0005
- cve Moodle local_o365 plugin JWT-signature-not-verified SSO auth bypass
- cve WordPress core WP_Query author__not_in SQL injection (WP2Shell chain component)
- cve WP2Shell: WordPress core REST batch route confusion to pre-auth RCE chain
- incident Transport for London 2024 intrusion
- tool Amatera
- actor Scattered Spider×7
- actor UAT-11795
- tool Starland RAT
- tool WLDR
- tool CastleStealer
- campaign HelloNet
- tool HelloNet toolkit
- tool ACR Stealer×4
- incident Wind Tre vishing + API-enumeration breach (2025)
- cve Mozilla Firefox WebAssembly engine invalid-pointer memory-safety flaw (public exploit code, no confirmed ITW); fixed 152.0.6
- cve Mozilla Firefox DOM Navigation site-isolation bypass (public exploit code, no confirmed ITW); fixed 152.0.6
- cve Microsoft SharePoint Server on-prem RCE — part of the actively-exploited SharePoint cluster (CISA KEV 2026-04-14), referenced as context in the CVE-2026-58644 exploitation update
- cve CVE-2026-58644 — Microsoft SharePoint Server deserialization RCE (CVSS 9.8); confirmed exploited + CISA KEV 2026-07-16×2
- actor The Syndicate×3
- actor World Leaks×2
- campaign Miasma×14
- incident Nayax cloud-account incident×3
- incident AsyncAPI npm supply-chain compromise via GitHub Actions (M-RED-TEAM)×2
- tool M-RED-TEAM×2
- incident Industrielle Werke Basel (IWB) third-party service-provider data breach (July 2026)
- tool TELEPUZ
- incident Kudankulam nuclear-plant contractor (Reliance Group) third-party-hosting data breach (July 2026)
- cve KNX Connection Authorization Option 1 overly-restrictive account-lockout DoS (CVSS 7.5, CWE-645); CISA KEV 2026-07-15, no software patch (procedural mitigation)
- cve Oracle E-Business Suite / Oracle Payments File Transmission unauthenticated RCE/takeover (CVSS 9.8); CISA KEV 2026-07-15, exploited ITW since 2026-06-27; fixed Oracle May 2026 CPU (12.2.3-12.2.15)×3
- incident Pwn2Own Berlin 2026×3
- actor UNK_pyreq2323
- actor UNK_OutFlareAZ
- cve CVE-2025-13162 — ABB 800xA for Advant Master / Control Builder A: DLL search-path element (CVSS 4.4)
- cve CVE-2025-14771 — ABB T-MAC Plus: authenticated file disclosure (CVSS 9.9)
- cve CVE-2025-14772 — ABB T-MAC Plus: broken access control / authz bypass (CVSS 8.8)
- cve CVE-2025-14773 — ABB T-MAC Plus: stored XSS (CVSS 8.0)
- cve CVE-2025-14774 — ABB T-MAC Plus: Card Reader service DoS (CVSS 7.4)
- cve CVE-2026-10577 — Rockwell 1715-AENTR EtherNet/IP Adapter: unauthenticated debug-port takeover (CVSS 10.0)
- cve CVE-2026-50522 — Microsoft SharePoint Server: Site-Owner deserialization RCE (CVSS 9.8)
- cve CVE-2026-55040 — Microsoft SharePoint Server: JWT authentication bypass, Pwn2Own chain (CVSS 9.1)
- cve CVE-2026-55944 — Microsoft Dynamics NAV / Dynamics 365 Business Central (On-Prem): pre-auth deserialization RCE (CVSS 9.8)
- actor DragonForce×8
- actor TeamPCP×31
- incident Operation Saffron×3
- report Check Point Annual AI Security Report 2026
- tool CrashStealer
- incident Progress ShareFile Storage Zone Controller emergency shutdown×3
- campaign prt-scan
- incident IFAGE Geneva — DragonForce leak-site claim (850 GB)
- actor bandcampro
- campaign Patriot Bait
- actor Storm-3138
- cve GRUB 2 Secure Boot bypass (historical) — cited by ESET/CERT/CC as an old bug reopened by pre-15.3 UEFI shims lacking SBAT (context in CVE-2026-8863/10797 entry)
- cve Forgotten pre-0.9 UEFI shim signature-length validation mismatch (revocation-check vs signature-verification size divergence) — Secure Boot bypass; revoked via Microsoft dbx 2026-06-09 (ESET Research)
- cve Progress ShareFile Storage Zone Controller pre-auth authentication bypass (CVSS 9.8) — Shadowserver confirmed active in-the-wild exploitation 2026-07-10; fixed 5.12.4×2
- cve SAP Approuter unauthenticated HTTP request smuggling (CVSS 9.1)
- cve SAP NetWeaver AS ABAP kernel memory corruption (CVSS 9.9)
- cve SAP Commerce Cloud hardcoded sample OAuth2 credential (CVSS 9.1)
- cve Microsoft AD FS local elevation of privilege (exploited zero-day)
- cve Microsoft SharePoint Server unauthenticated elevation of privilege (exploited zero-day)
- cve Forgotten pre-0.9 UEFI shim trust-validation weakness (Secure Boot bypass on machines trusting the Microsoft third-party UEFI CA); revoked via Microsoft dbx 2026-06-09 (ESET Research)
- actor Secret Blizzard×7
- actor Sandworm×6
- actor Static Tundra×2
- incident Poland energy-sector destructive attack (29 December 2025)
- incident France/EU formal attribution of Turla (FSB Centre 16) espionage against France
- campaign Russian hijacking of IP cameras along NATO military-supply routes (2026-07)
- cve Cisco IOS (end-of-life devices) — named by the 2026-07-13 FSB Centre 16 joint advisory as an exploited legacy CVE; no patch (EOL)
- cve Cisco IOS/IOS XE Smart Install pre-auth RCE — actively exploited by FSB Centre 16 / Static Tundra
- cve Progress ShareFile Storage Zone Controller — storage-repository web-shell RCE chained from CVE-2026-2699
- cve WAGO I/O System Field — undocumented early-boot diagnostic interface, unauthenticated full compromise (CWE-912)
- cve Rejetto HFS < 3.2.1 predictable session-signing PRNG (Math.random) enables pre-auth admin session forgery to RCE via server_code (CVSS 9.3); fixed 3.2.1
- cve Rejetto HFS 3.0.0–3.2.0 stored XSS in admin log via crafted failed-login username; fixed 3.2.1
- cve Rejetto HFS 3.0.0–3.2.0 state-changing admin actions accepted over GET with no anti-CSRF check; fixed 3.2.1
- cve Rejetto HFS 3.0.0–3.2.0 unauthenticated username enumeration (incl. default admin) via login-endpoint response differences; fixed 3.2.1
- cve Rejetto HFS 3.0.0–3.2.0 stored XSS via unescaped filenames in fallback 'basic' listing; fixed 3.2.1
- cve Rejetto HFS 3.0.0–3.2.0 path traversal via lang query parameter (limited JSON file read); fixed 3.2.1
- cve ServiceNow AI Platform sandbox escape — unauthenticated code execution within the platform (CVSS 9.5); hosted fixed server-side, self-hosted/partner patch listed family releases
- actor 888×2
- actor Akira×21
- actor Bitter×2
- actor Cavern Manticore×2
- actor Qilin×22
- actor UAT-7810×2
- actor Unsafe×2
- campaign FrostyNeighbor March–May 2026 campaign×13
- campaign LSHIY Azure CLI ROPC token-spray×2
- campaign Railway device-code phishing×2
- campaign STAC3725 CitrixBleed 2-to-DragonForce IAB chain×2
- incident CERT.LV LVM/Olpha ransomware intrusion (2026)×2
- incident FortiBleed×12
- incident Groupe 3R ransomware breach×4
- incident KDDI email-platform breach×2
- incident Nextcloud GmbH corporate Elasticsearch data exposure (2026)×2
- incident Odido (Netherlands telecom) ShinyHunters breach×2
- incident PDAG email-account compromise×3
- policy EU Cyber Resilience Act×19
- report ESET Threat Report H1 2026×2
- tool 'Ghost in the Database' ADFS key recovery×2
- tool Cavern×2
- tool LONGLEASH / SHORTLEASH ORB malware suite×2
- trend Adobe ColdFusion/Campaign APSB26-68/69×2
- trend Joomla extension file-upload RCE wave×4
- actor UNK_MassTraction×2
- actor Helix×2
- incident @injectivelabs/sdk-ts npm supply-chain compromise (2026)×2
- tool Forg365×2
- campaign Friendly Fire (AI Now Institute exploit)×2
- actor Armored Likho×3
- malware BusySnake Stealer×3
- incident jscrambler npm supply-chain compromise (2026-07)
- tool GhostApproval×2
- tool GigaWiper
- tool Crucio
- tool FlockWiper
- actor Hyadina
- tool PoisonX
- cve Progress MOVEit Transfer Custom Reports table-scope bypass, admin-privileged (CVSS 7.2; CERT-FR AVI-0856)
- cve Progress MOVEit Transfer SFTP-service memory-leak pre-auth denial of service (CVSS 7.5; CERT-FR AVI-0856)
- cve Progress MOVEit Transfer Ad Hoc module stored XSS, low-priv authenticated (CVSS 8.0; CERT-FR AVI-0856)
- cve Windows HTTP.sys pre-auth kernel RCE (CVSS 9.8); ZDI published full exploitation mechanics + detection signature 2026-07-10×2
- cve Joomla RSFiles! (com_rsfiles) unauthenticated file-upload RCE (CVSS 4.0 10.0); part of the mySites.guru Joomla-extension CWE-434 wave
- cve Joomla Phoca Download (com_phocadownload) authenticated file-upload RCE via member-upload allow-list bypass (CVSS 4.0 9.0)
- cve PraisonAI PGVector/Cassandra knowledge store — SQL/CQL injection via unvalidated vector dimension (CVSS 9.3)
- cve PraisonAI AICoder — arbitrary file write / command execution via LLM tool calls (CVSS 9.4)
- cve PraisonAI CodeAgent — unsandboxed LLM-generated Python execution with full env-secret leak (CVSS 10.0)
- actor UNC6671×6
- actor WP-SHELLSTORM
- cve Apache Nacos authentication bypass (Nacos-Server User-Agent header) abused by WP-SHELLSTORM for Java-stack credential theft
- cve CitrixBleed 2 (NetScaler ADC/Gateway pre-auth memory over-read) — weaponised in the STAC3725 IAB-to-DragonForce kill chain (Huntress)
- cve Open WebUI /api/tasks/stop/ IDOR — unauthorized task cancellation (unpatched)
- cve Open WebUI Direct Connections XSS chained to unsandboxed Python exec() → RCE
- cve WordPress ThemeREX Addons plugin vulnerability weaponized by the WP-SHELLSTORM crew
- cve Gitea Docker reverse-proxy trust-all auth bypass (X-WEBAUTH-USER impersonation) — NCSC-CH escalated status to actively-exploited 2026-07-10×2
- cve WordPress Breeze Cache Cleaner plugin flaw — highest-yield exploit in the WP-SHELLSTORM webshell-brokerage campaign
- cve Open WebUI /api/openai/responses proxy reaches any model without per-model authz
- cve Open WebUI incomplete collection allowlist exposes knowledge-base metadata to any user
- cve Open WebUI Socket.IO ydoc:document:update checks room membership not write permission
- cve iCagenda for Joomla — unauthenticated file-upload-to-RCE, exploited zero-day, CISA KEV
- cve Open WebUI prompt version-history IDOR (caller-supplied history-ID unauthorized)
- cve Siemens SICAM 8 HTTP-reachable debug interface → authenticated DoS
- cve Siemens SICAM 8 firmware-update signature-validation bypass → persistent malicious firmware
- cve Siemens SICAM 8 ships with OPC UA security disabled by default
- cve Siemens SICAM 8 web-API admin-account credential-validation bypass → privilege escalation
- actor MuddyWater×5
- actor Nightmare Eclipse×15
- campaign Nightmare Eclipse Windows zero-day series×11
- tool Apex2×5
- tool c2c / meow
- tool RedHook
- trend RoguePlanet×8
- tool IceCube
- cve Roundcube XSS — exploited by FrostyNeighbor / Ghostwriter (UNC1151) for Polish-targeting credential harvesting
- cve Roundcube Crypt_GPG_Engine PHP deserialization RCE - chained by UNK_MassTraction after CVE-2024-42009 XSS (Proofpoint)
- cve GeoVision GV-I/O Box 4E unauthenticated OS command injection (Talos, CVSS 9.1)
- cve AWS Language Servers / Amazon Q Developer symlink trust-boundary write outside workspace (GhostApproval, CWE-61); fixed language-servers 1.69.0 / @aws/lsp-codewhisperer 0.0.117
- cve GeoVision GeoWebPlayer unauthenticated localhost WebSocket screen-capture (Talos, CVSS 8.8)
- cve OpenPLC v3 Runtime authenticated arbitrary file-write to native RCE (CVSS 9.9; CISA ICSA-26-190-01, no fix)
- cve VTK-DICOM heap overflow on crafted DICOM file (Talos, CVSS 8.1)
- cve Plesk XML API code injection (CWE-94) — authenticated low-priv to arbitrary root file write / LPE (CVSS 9.9); CCB Belgium; affected <18.0.30, fixed 18.0.30-18.0.78.4 (18.0.79+ unaffected)
- cve Cursor IDE sandbox escape via symlink + failed path canonicalization (GhostApproval); fixed Cursor 3.0
- cve Microsoft Defender Malware Protection Engine 'RoguePlanet' link-following LPE to SYSTEM - now fixed (engine >=1.1.26060.3008); NCSC-CH Nightmare Eclipse tracker×3
- cve wolfSSL registeredID SAN name-constraint bypass (Talos, CVSS 7.4)
- cve Linux KVM/x86 'Januscape' shadow-MMU use-after-free — guest-to-host VM escape on Intel and AMD (public PoC host-DoS; RCE withheld); fixed 6.1.177/6.6.144/6.12.95/6.18.38/7.1.3
- cve Balbooa Forms for Joomla (com_baforms) unauthenticated file-upload RCE (CWE-434, CVSS 4.0 10.0) — zero-day exploited pre-patch; 3rd Joomla-extension file-upload RCE in the 2026-06/07 wave
- cve wolfSSL PKCS#7 OtherRecipientInfo integer underflow -> heap overflow (Talos, CVSS 7.5)
- cve wolfSSL iPAddress SAN name-constraint bypass (Talos coordinated disclosure, CVSS 9.1)
- actor UAT-5918
- tool CrySome RAT
- tool Factory-v3
- cve Ruckus wireless router flaw exploited by UAT-7810 for ORB initial access (context; Cisco Talos)
- cve Ruckus wireless router flaw exploited by UAT-7810 for ORB initial access (context; Cisco Talos)
- cve Ruckus wireless router flaw exploited by UAT-7810 for ORB initial access (context; Cisco Talos)
- cve ASUS AiCloud router flaw exploited by UAT-7810 for ORB initial access (context; Cisco Talos)
- cve Hydro-Quebec EV-charging OCPP WebSocket unauthenticated access -> privilege escalation (CVSS 9.8), CISA ICSA-26-188-01
- cve Langflow unauthenticated RCE (build_public_tmp), CISA KEV, exploited in the Langflow IDOR chain
- cve BeyondTrust RS/PRA pre-auth authentication bypass (CVSS4 9.2), NCSC-CH BT26-03
- cve BeyondTrust RS/PRA pre-auth authentication bypass (CVSS4 9.2), NCSC-CH BT26-03
- cve BeyondTrust RS/PRA unauthenticated DoS (network-communication subsystem), BT26-03
- cve BeyondTrust RS/PRA authenticated broken-access-control (resource access beyond scope), BT26-03
- cve Hydro-Quebec EV-charging: no auth-attempt throttling -> DoS (CVSS 7.5), ICSA-26-188-01
- cve GhostLock — Linux kernel rtmutex use-after-free LPE + container escape, public exploit
- cve Hydro-Quebec EV-charging: duplicate concurrent sessions per charge-point ID -> DoS (CVSS 7.5), ICSA-26-188-01
- cve Adobe ColdFusion CWE-22 path-traversal RCE (CVSS 10.0), APSB26-68 — actively exploited, CISA KEV 2026-07-07×2
- cve JoomShaper SP Page Builder unauth file-upload RCE (CVSS 10.0), CISA KEV zero-day
- cve Ubiquiti UniFi Connect unauthenticated command-injection RCE (CVSS 10.0), SAB-066
- cve Ubiquiti UniFi Talk authenticated SQL injection (CVSS 9.9), SAB-066
- cve Ubiquiti UniFi Access command injection (CVSS 9.9), SAB-066
- cve Ubiquiti UniFi OS command injection (CVSS 9.9), SAB-066
- cve Ubiquiti UniFi OS path-traversal auth-bypass (CVSS 8.6), chainable, SAB-066
- cve Ubiquiti UniFi Protect SSRF privilege escalation (CVSS 9.9), SAB-066
- cve Langflow cross-tenant IDOR (CWE-639), actively exploited, CISA KEV — chained with RCE CVE-2026-33017
- cve Joomlack Page Builder CK unauth file-upload RCE (CVSS 10.0), CISA KEV zero-day
- actor INC Ransom×6
- actor JADEPUFFER×2
- actor Kairos×6
- campaign 0DIN coding-agent prompt-injection chain×2
- campaign Mustang Panda ZOHOMURK
- campaign Popa residential-proxy botnet×3
- campaign StegoAd×2
- campaign Phantom Squatting×2
- incident DHS HSIN breach
- incident Pegasus infection of PEGA-Committee MEP Stelios Kouloglou×2
- tool Avalon×2
- tool PamStealer×2
- tool ARToken×2
- tool Umbrij×2
- cve cve-search unauthenticated /fetch_cve_data parameter manipulation exposes admin credential hashes
- cve Langflow /api/v1/validate/code missing-auth RCE — initial access for the JADEPUFFER agentic ransomware operation
- incident Medtronic breach×4
- cve WatchGuard Fireware OS iked pre-auth use-after-free RCE (IKEv2/LDAP path, CVSS 9.2)
- cve Cisco Catalyst Center unauthenticated path-traversal arbitrary file read (CVSS 7.5; dropped from §2, awareness only)
- cve Coolify authenticated OS command injection to RCE + secrets exfil (CVSS 9.9)
- cve Control Web Panel pre-auth blind SQLi to web-shell RCE via INTO DUMPFILE (CVSS 9.8)
- campaign Trojanised ScreenConnect AsyncRAT campaign
- trend Argo CD repo-server unauthenticated RCE
- cve Altium Enterprise Server / Altium 365 Git Service CWE-22 path-traversal to RCE (CVSS 9.4)
- cve Microsoft SharePoint Server CWE-502 deserialization RCE — authenticated Site Member (PR:L) can execute code over network; CVSS 8.8; NCSC.ch flagged 2026-05-26; § 7 drop (did not clear § 2 gates)
- cve Adobe ColdFusion CWE-434 unrestricted file-upload RCE (CVSS 10.0), APSB26-68
- cve Adobe ColdFusion CWE-20 improper-input-validation RCE (CVSS 10.0), APSB26-68
- cve Adobe ColdFusion CWE-20 improper-input-validation RCE (CVSS 10.0), APSB26-68
- cve Adobe ColdFusion CWE-434 unrestricted file-upload RCE (CVSS 10.0), APSB26-68
- cve Adobe Campaign Classic CWE-863 incorrect-authorization code execution (CVSS 10.0), APSB26-69
- cve Adobe ColdFusion CWE-20 improper-input-validation RCE (CVSS 10.0), APSB26-68
- cve Progress Kemp LoadMaster pre-auth RCE — uninitialized malloc heap corruption in escape_quotes()/ /accessv2 to root (CVSS 9.8); fixed 7.2.63.2×2
- cve Citrix NetScaler ADC/Gateway 'CitrixBleed' session-token memory overread — cited as CVE-2026-8451 lineage context
- cve Citrix NetScaler ADC/Gateway memory-leak (CitrixBleed variant) — cited as CVE-2026-8451 lineage context
- cve Citrix NetScaler ADC/Gateway — Management Interface unauthenticated arbitrary file read (CTX696604)
- cve Citrix NetScaler ADC/Gateway — memory overread when TCP TimeStamp enabled on LB/CS/VPN vserver (CTX696604)
- cve Citrix NetScaler ADC/Gateway — CTX696604 companion CVE
- cve Citrix NetScaler ADC/Gateway pre-auth SAML-parser out-of-bounds read (March 2026, confirmed exploited) — cited as CVE-2026-8451 lineage context
- cve Oracle PeopleSoft PeopleTools PSEMHUB pre-auth RCE (CVSS 9.8), zero-day exploited by UNC6240/ShinyHunters×5
- cve Citrix NetScaler ADC/Gateway — pre-auth SAML AuthnRequest XML-parser memory overread (CitrixBleed lineage, CVSS 8.8), public PoC
- cve Citrix NetScaler ADC/Gateway — memory-management flaw (Gateway/DNS-proxy/AAA vserver), DoS/undefined control flow (CTX696604)
- cve Citrix NetScaler ADC/Gateway — memory-management flaw (Gateway/DNS-proxy/AAA vserver), DoS/undefined control flow (CTX696604)
- incident Bumblebee → AdaptixC2 → Akira intrusion
- cve SzafirHost (KIR e-signature client) JAR parser confusion (JarFile vs JarInputStream, CWE-434) → native-library RCE past signature check; fixed v1.2.2
- cve Progress Kemp LoadMaster — OWASP CRS whitespace-padding file-upload extension-check bypass (high); same bulletin as CVE-2026-8037
- cve Linux kernel 'DirtyClone' LPE — SKBFL_SHARED_FRAG drop in __pskb_copy_fclone() + IPsec in-place decrypt; JFrog working exploit on Debian/Ubuntu/Fedora (CVSS 8.8)×3
- cve SimpleHelp RMM OIDC SSO auth bypass — forged-token full Technician session + MFA bypass; now actively exploited (CISA KEV 2026-06-29), Djinn infostealer via TaskWeaver loader (CVSS 10.0)×2
- cve n8n Dynamic Credentials EE — missing ownership/scope checks enable cross-tenant OAuth credential hijack/revoke (CVSS 8.9, GHSA-2j5h-858j-5mpf); NCSC-2026-0212
- cve n8n public API — editor-level users read other users' credentials in shared instances (CVSS 8.5); NCSC-2026-0212
- cve libssh2 pre-auth heap OOB write in ssh2_transport_read() (CVSS 9.2) — public PoC released 2026-06-29; no fixed release tagged yet×3
- actor Embargo×4
- actor Gamaredon×7
- campaign Bluekit PhaaS×2
- campaign Cordyceps×2
- campaign Icarus Salesforce OAuth extortion×3
- campaign BadBlocker×3
- campaign Mini Shai-Hulud×25
- campaign Operation Endgame — Amadey/StealC takedown×6
- campaign StrikeShark×2
- tool macOS.Gaslight×2
- trend Gogs argument-injection RCE×4
- cve Lantronix EDS5000 OS command injection to root (BRIDGE:BREAK; CISA KEV 2026-06-23)×2
- cve ShapedPlugin WordPress Pro supply-chain backdoor (build/EDD pipeline compromise)×2
- cve Keycloak JWT algorithm confusion -> federated-user impersonation (CVSS 8.1)×2
- cve PTC Windchill / FlexPLM — unauthenticated Java deserialization RCE (CVSS 10.0), actively exploited×4
- cve Cisco Unified Communications Manager WebDialer unauthenticated SSRF → OS-root file write (SIR Critical); fix 14SU6 / Release 15 COP×3
- cve Cisco Catalyst SD-WAN Manager command-injection to root — Mandiant confirms pre-disclosure zero-day exploitation; patched (chains CVE-2026-20127/-20182)×6
- cve Ubiquiti UniFi OS improper access control (chain step 1 to unauth root; CISA KEV 2026-06-23)×2
- cve Ubiquiti UniFi OS path traversal (chain step 2 to unauth root; CISA KEV 2026-06-23)×2
- cve Ubiquiti UniFi OS improper input validation/command injection to root (CISA KEV 2026-06-23, actively exploited)×2
- cve Linux kernel 'pedit COW' LPE — tc act_pedit out-of-bounds write poisons setuid-binary page cache; public weaponised PoC×2
- cve Gogs argument-injection RCE (CVE-2026-52806); now actively exploited in K8s cryptojacking campaign (Wiz)×2
- cve libssh2 infinite-loop pre-auth DoS via crafted SSH_MSG_EXT_INFO (CVSS 8.2)×2
- cve Gitea act_runner Docker container-hardening bypass to host escape (CVSS 9.4, public PoC)×2
- cve Keycloak policy-enforcer authorization bypass via access-denied-page path (CVSS 8.1)×2
- cve WinRAR path-traversal (referenced as initial-access exploit in Gamaredon GammaPhish/GammaWorm campaign, Sekoia 2026-06-01)×4
- cve ILIAS 11.0 SQL injection in ilTrQuery learning-progress subsystem (no patch, PoC public)
- cve Cisco Catalyst SD-WAN Manager web UI authenticated path traversal — arbitrary file write to root RCE; CISA KEV 2026-06-15×3
- cve Keycloak group-admin to realm-admin privilege escalation
- cve Microsoft Exchange Server SSRF (ProxyLogon) — cited in 2026-05-16 § 5 deep dive Background as precedent for on-prem Exchange exploitation pattern
- cve Openfire admin-console path-traversal auth bypass — StrikeShark/SharkLoader initial-access vector
- cve F5 BIG-IP TMUI unauthenticated RCE — StrikeShark/SharkLoader initial-access vector
- cve Fortinet FortiOS SSL-VPN out-of-bounds write RCE — StrikeShark/SharkLoader initial-access vector
- cve OSGeo GeoServer OGC-filter RCE — StrikeShark/SharkLoader initial-access vector
- cve GitLab Web IDE workbench stored XSS (CVSS 8.0) — patched 19.1.1/19.0.3/18.11.6; assessed, did not clear §2 gate
- cve Amazon Q Developer (VS Code) auto-loads workspace .amazonq/mcp.json without consent — repo-planted code execution + AWS credential theft
- cve Cisco Catalyst SD-WAN Manager pre-auth RCE (UAT-8616 prior exploitation, Feb 2026)×2
- cve Cisco Catalyst SD-WAN Controller/Manager pre-auth authentication bypass (CVSS 10.0, actively exploited by UAT-8616)×5
- cve Dirty Frag — Linux kernel xfrm-ESP page-cache write primitive, LPE (ITW, PoC public)×4
- cve Dirty Frag — Linux kernel RxRPC page-cache write primitive, LPE chain (ITW, patch pending)×4
- cve Fragnesia — Linux kernel xfrm ESP-in-TCP LPE (PoC public)×2
- cve Check Point Security Gateway IKEv1 Remote Access/Mobile Access certificate-validation authentication bypass (CVSS 9.3) — actively exploited by Qilin affiliate since 2026-05-07, CISA KEV×4
- cve GitLab EE Analytics Dashboard stored XSS (CVSS 8.7) — patched 19.1.1/19.0.3/18.11.6; assessed, did not clear §2 gate
- cve GitLab repository-mirroring SSRF (CVSS 3.1) — patched 19.1.1/19.0.3/18.11.6; low severity, did not clear §2 gate
- cve FFmpeg MagicYUV decoder heap OOB write (PixelSmash, CVSS 8.8) — fixed FFmpeg 8.1.2; out-of-window this run
- tool Edgecution
- tool Mistic
- cve Cacti <1.2.31 — pre-auth SQLi in graph_view.php (rfilter); evaluated, dropped to § 7 (out-of-window, single GHSA)
- cve MISP <2.5.42 — broken access control
- cve MISP <2.5.42 — cross-org IDOR overwrite
- cve MISP <2.5.42 — broken access control, cross-org hard-delete
- cve MISP <2.5.42 — Azure-AD OAuth state-reuse session hijack
- cve MISP <2.5.42 — NDJSON log-injection PHP RCE (site-admin)
- cve MISP <2.5.42 — rdkafka plugin-load RCE (site-admin)
- cve Arista EOS tunnel-decapsulation logic flaw (CWE-1023) bypasses VXLAN segmentation; CISA KEV, exploited
- campaign Cloud-bucket hijacking via namespace reuse
- cve SonicWall SonicOS improper access control (mgmt + SSLVPN, Gen 5/6/7) — Akira/Fog ransomware on-ramp
- cve FortiGate credential-reuse vector referenced in FortiBleed campaign
- cve FortiGate credential-reuse vector referenced in FortiBleed campaign
- cve Gitea TOTP 2FA bypass (web TOCTOU + X-Gitea-OTP replay)
- cve Gitea SSRF in webhook / repo-migration subsystems
- cve FortiGate credential-reuse vector referenced in FortiBleed campaign
- cve Gitea protected-branch enforcement race (single-push batch)
- cve DifyTap — Dify AI platform cross-tenant authorization bypass (evaluated, dropped § 7: authenticated, no ITW, aggregator-only primary)
- cve Microsoft 365 Copilot Business Chat open redirect (BSI WID-SEC-2026-2020; server-side mitigated, dropped § 7)
- cve Squidbleed — 29-year-old heap over-read in Squid FTP gateway leaks cross-user HTTP credentials
- cve ShapedPlugin supply-chain backdoor — duplicate CVE submission for CVE-2026-10735 (noted § 7)
- cve Microsoft 365 Copilot missing-authentication info disclosure (BSI WID-SEC-2026-2020; server-side mitigated, dropped § 7)
- actor Webworm×6
- campaign AryStinger
- campaign ErrTraffic×3
- campaign ShinyHunters PeopleSoft campaign×4
- campaign Cybercrime-underground AI adoption×2
- incident Kyushu Electric SSD loss
- tool usbliter8×2
- trend AutoJack×2
- cve Linksys/D-Link RTL819X command-injection RCE — initial-access vector for the AryStinger botnet
- cve D-Link DIR-850L HTTP-service stack buffer overflow RCE — AryStinger botnet access vector
- cve QNAP Malware Remover code injection (fixed 6.6.8.20251023) — AryStinger NAS access vector
- cve Rockwell FactoryTalk Historian Site Edition — authentication bypass (CVSS 7.7)×2
- cve PAN-OS GlobalProtect pre-auth authentication bypass×6
- cve Rockwell 1794-AENTR/AENTRXT FLEX I/O — CIP-handling denial-of-service (CVSS 7.5)×2
- cve Rockwell 1794-AENTR/AENTRXT FLEX I/O — unauthenticated web-interface password reset (CVSS 9.4)×2
- cve Rockwell CompactLogix/ControlLogix 5370/5570 — CIP message major non-recoverable fault DoS (CVSS 7.5)×2
- cve Cisco ISE / ISE-PIC — authenticated path-traversal OS command execution to root (CVSS 9.1)×3
- cve Cisco ISE / ISE-PIC — unauthenticated read of sensitive data incl. hashed admin credentials (CVSS 7.5)×3
- cve Splunk Enterprise pre-auth RCE via unauthenticated PostgreSQL sidecar REST API proxied by web tier, CVSS 9.8×5
- cve FortiSandbox unauthenticated OS command injection in VNC handler (CVSS 9.8); dropped from brief - no inclusion gate cleared×3
- cve Oracle PeopleSoft PeopleTools 8.61/8.62 Performance Monitor — missing-auth RCE (CVSS 9.8)×2
- cve Fortinet FortiSandbox — JRPC API OS command injection (CVSS 9.8); actively exploited×2
- cve Fortinet FortiSandbox — JRPC API path traversal / auth bypass (CVSS 9.1); actively exploited×2
- cve Gravity SMTP WordPress plugin unauthenticated info-disclosure (email-connector credential dump), mass-exploited×2
- cve Oracle Solaris 11.4 Remote Administration Daemon — unauthenticated flaw (CVSS 10.0), Oracle June 2026 CSPU×2
- cve Widget Factory Joomla Content Editor (JCE) <2.9.99.5 — unauthenticated profile-import to PHP RCE (CVSS v4 10.0); CISA KEV×2
- cve LiteSpeed cPanel/WHM plugin symlink-following on CloudLinux/CageFS shared hosting; exploited ITW May 2026; CISA KEV×2
- cve Drupal core — JSON:API PHP object injection (SA-CORE-2026-005, critical)×2
- cve Drupal core — deserialization gadget chain (SA-CORE-2026-006)×2
- campaign Prinz Eugen
- cve Windows Boot Manager Secure Boot bypass (BlackLotus-class) — possible FishMonger SprySOCKS UEFI component (unconfirmed)
- cve UpdraftPlus WordPress plugin unauthenticated auth-bypass to RCE (all-zero AES key on failed RSA decrypt), CVSS 8.1; actively exploited
- cve pgAdmin 4 — unauthenticated pickle.loads RCE primitive in SQL Editor (server mode, CVSS v4 9.5)
- cve Google Cloud Vertex AI SDK — predictable staging-bucket cross-tenant pickle RCE ('Pickle in the Middle'); patched 1.148.0
- cve AVer PTC500S/PTC115/PTC500+/PTC115+ cameras — unauthenticated RCE via management web interface (CVSS 9.8), CISA ICSA-26-169-01
- cve NGINX — heap overflow in ngx_http_proxy_v2_module/ngx_http_grpc_module (CVSS v4 9.2)
- cve NGINX — HTTP/3 QUIC use-after-free in ngx_http_v3_module (CVSS v4 9.2)
- cve Microsoft 365 Copilot Enterprise Search 'SearchLeak' command-injection/info-disclosure; one-click exfil; patched server-side
- cve phpBB OAuth improper-authentication account hijack (admin) even when OAuth disabled; CVSS 9.8; fixed 3.3.17
- incident Kodak breach
- campaign CryptoBandits
- incident Operation Endgame — SocGholish expansion
- cve pgAdmin 4 — AI Assistant read-only-transaction bypass to RCE via COPY TO PROGRAM (CVSS v4 9.4)
- cve pgAdmin 4 — stored XSS via unsanitised PostgreSQL error/EXPLAIN content (CVSS v4 9.3)
- cve Drupal core — rebuild.php trusted-host bypass (SA-CORE-2026-007)
- cve Drupal core — Media module oEmbed SSRF (SA-CORE-2026-008)
- cve Drupal core — JSON:API/REST image-upload MIME-validation gap (SA-CORE-2026-009)
- actor ScarCruft
- actor TA4922×3
- trend Zammad 7.1 security release
- campaign DragonForce Backdoor.Turn intrusion
- campaign Rokarolla
- cve WP File Manager pre-auth RCE — used as fallback vector in the ErrTraffic ClickFix framework
- cve Topaz Antifraud wsftprm.sys vulnerable kernel driver — DragonForce BYOVD chain
- cve K7 Security K7RKScan.sys vulnerable kernel driver — DragonForce BYOVD chain
- cve React/Next.js Server Actions deserialisation ("React2Shell") — weaponised by PCPJack worm
- cve Tower of Fantasy GameDriverx64.sys vulnerable kernel driver — DragonForce BYOVD chain
- actor UAT-8616×5
- campaign UNK_DeadDrop
- cve Splunk Secure Gateway jsonpickle deserialization RCE (CVSS 8.8) — assessed, no §2 gate (no ITW, post-auth); NCSC-NL advisory
- cve LiteLLM Custom Code Guardrails sandbox escape to RCE via exec()/bytecode; CVSS 8.8; fixed v1.83.14
- cve LiteLLM authorization bypass via unvalidated allowed_routes in key-generation; CVSS 8.8; fixed v1.83.14
- cve LiteLLM privilege escalation — self-promote to proxy_admin via /user/update; CVSS 8.8; fixed v1.83.14
- cve phpBB OAuth improper state verification + CSRF session hijack; CVSS 8.0; fixed 3.3.17
- campaign Outsider PhaaS
- cve GitLab EE Analytics Dashboard stored XSS (CVSS 8.7) — assessed, no §2 gate
- cve OpenSSL CMS AuthEnvelopedData integrity bypass (moderate) — assessed, out-of-window, not promoted
- cve Traefik v3.x security-policy bypass (GHSA-3g6v-2r68-prfc) — assessed, no §2 gate, out-of-window
- cve Adobe ColdFusion unauthenticated no-interaction RCE (CVSS 9.6, APSB26-64; scope change S:C; fixed 2023 Update 20 / 2025 Update 9)
- cve Adobe ColdFusion path-traversal security-feature bypass (CVSS 8.8, APSB26-64) — co-disclosed; assessed, not promoted
- cve GitLab CE/EE Grape API unauthenticated DoS (CVSS 7.5) — assessed, no §2 gate
- cve GitLab CE/EE Gitaly repository-import SSRF (CVSS 5.3) — assessed, no §2 gate
- actor VerdantBamboo×9
- campaign Atomic Arch×4
- campaign IronWorm×5
- campaign Velvet Ant Operation Highland×2
- incident Conti developer Lytvynenko guilty plea
- incident Cyber Europe 2026×2
- incident Tchap messenger breach
- policy NIS2 CJEU referral (France, Spain)
- report CrowdStrike 2026 Technology Threat Landscape Report×2
- trend GreatXML×3
- cve Windows Cloud Filter driver cldflt.sys privilege escalation (MiniPlasma PoC)×3
- cve Windows Print Spooler privilege escalation weaponised by APT28 GooseEgg (cited as historical context in Sekoia APT28 retrospective)
- cve LangGraph SQLite checkpointer SQL injection in get_state_history() (CVSS 7.3; fixed langgraph-checkpoint-sqlite 3.0.1)
- cve Ivanti Sentry pre-auth OS command injection to root (MICS handleMessage), CVSS 10.0; public PoC by watchTowr×2
- cve Ivanti Sentry authentication bypass (CWE-288), companion to CVE-2026-10520
- cve Google Chrome V8 out-of-bounds read/write, exploited ITW, CISA KEV; fixed 149.0.7827.103
- cve BUK TS-G gas-station automation unauthenticated admin bypass, CVSS 9.8 (dropped from brief — aggregator-only sourcing)
- cve Linux kernel nf_tables use-after-free in nft_map_catchall_activate() (single-character genmask inversion) — local-root + container escape, working public exploit (Exodus Intelligence), patched upstream 2026-02-05, CVSS 7.8
- cve LangGraph unsafe msgpack deserialization on checkpoint load, chains with SQLi to RCE (CVSS 6.8; fixed langgraph 1.0.10)
- cve Everest Forms Pro (WordPress) Calculation Addon unauthenticated eval() PHP code injection (CVSS 9.8); mass exploitation since 2026-04-13 creating rogue admin accounts; patched v1.9.13 (2026-03-18)×2
- cve Windows Netlogon stack buffer overflow — unauthenticated remote RCE to SYSTEM on domain controllers (CVSS 9.8, May 2026 Patch Tuesday); active ITW exploitation confirmed by CCB Belgium 2026-06-01×4
- cve BerriAI LiteLLM MCP test endpoints command injection to host RCE (CVSS 8.8) — CISA KEV, actively exploited; unauthenticated when chained with CVE-2026-48710
- cve SAP NetWeaver AS ABAP SAML XML Signature Wrapping (CVSS 9.9), SAP_BASIS 702-919×2
- cve Veeam Backup & Replication 12.x authenticated domain-user deserialization RCE (CVSS 9.4); fixed 12.3.2.4854
- cve Windows YellowKey BitLocker bypass via WinRE×3
- cve Windows CTFMON elevation of privilege (June 2026 Patch Tuesday); referenced in § 7 GreenPlasma cross-source discrepancy note
- cve Windows kernel TCP/IP use-after-free network RCE to SYSTEM (CVSS 9.8)
- cve vm2 Node.js sandbox escape via WebAssembly JSPI Promise-species bypass, CVSS 9.8 (dropped from brief — out-of-window, no ITW)
- cve TYPO3 Core June 2026 (TYPO3-CORE-SA-2026-006) — XSS bypassing the HTML Sanitizer; lead CVE of the 13-advisory batch
- cve strongSwan libstrongswan identity-clone double-free, unauth RCE over EAP; fixed 6.0.7
- cve Acer Wave-7 mesh router broken access control — unauthenticated cleartext credential log acer_cgi.log exposure (CVSS 10.0, no patch until ~end-June 2026)
- cve Acer Wave-7 mesh router hardcoded AES key in upload.cgi backup handler — persistent backdoor injection (CVSS 10.0, no patch until ~end-June 2026)
- cve MariaDB Server Galera wsrep_notify_cmd OS command injection (CVSS 10.0)×2
- cve Langflow path traversal (POST /api/v2/files) -> arbitrary file write, pre-auth via default auto-login, exploited ITW
- campaign Agentjacking
- cve LangGraph Redis checkpointer RediSearch query injection (CVSS 6.5; fixed @langchain/langgraph-checkpoint-redis 1.0.1)
- cve OpenSSL PKCS7_verify heap use-after-free on empty SignedData.digestAlgorithms (High; fixed 4.0.1/3.6.3/3.5.7/3.4.6/3.0.21) — out-of-window drop this run
- cve GitLab EE Group SAML identity API improper authorization, Group Owner account takeover (CVSS 8.7; fixed 19.0.2/18.11.5/18.10.8) — did not clear daily section-2 gate
- actor OceanLotus
- campaign OpenClaw agent-phishing disclosures
- cve Nuance PowerScribe unauthenticated deserialization RCE (CVSS 9.8)
- cve Azure Stack Edge external file path control RCE (CVSS 9.8)
- cve MariaDB Galera wsrep parameter-injection (companion fix to CVE-2026-49261)
- cve MariaDB Galera wsrep parameter-injection (companion fix to CVE-2026-49261)
- cve Exchange Online improper-authorisation information disclosure (CVSS 9.1, service-side fix)
- campaign JDY botnet
- cve Fortinet FortiClient EMS 7.4.5/7.4.6 — improper-access-control on X-SSL-CLIENT-VERIFY header lets unauth attacker spoof mTLS state and reach management API; ITW exploited to push EKZ Infostealer per Arctic Wolf 2026-05-27×3
- cve Windows BitLocker physical-access bypass, publicly disclosed, June 2026 Patch Tuesday
- campaign Ghost-Sender
- campaign Job-seeker targeting wave (CH)
- campaign Security-tool impersonation TDS campaign
- report Dragos Q1 2026 Industrial Ransomware Analysis
- trend Entra Agent ID OBO abuse×3
- cve SAP Commerce Cloud / Data Hub missing HTTP security headers via Spring Security (CVSS 9.1)
- cve SAP NetWeaver/ABAP RFC kernel memory corruption, unauthenticated (CVSS 9.8)
- cve SAP NetWeaver AS Java Web Container path traversal (CVSS 9.0)
- cve Windows DHCP Client Service RCE (CVSS 9.8), June 2026 Patch Tuesday
- cve Visual Studio Code EoP to SYSTEM via malicious .code-workspace (CVSS 9.6)
- cve Windows HTTP.sys HTTP/2 compression-bomb DoS (IIS analogue of CVE-2026-49975); MaxHeadersCount mitigation
- cve HTTP/2 Bomb — HPACK dynamic-table amplification + Slowloris stream-hold memory-exhaustion DoS vs nginx/Apache/IIS/Envoy/Pingora; nginx 1.29.8 & Apache mod_http2 2.0.41 patched, IIS/Envoy/Pingora unpatched at disclosure×2
- actor Fox Tempest×3
- cve Starlette/FastAPI host-header auth bypass (BadHost)×3
- cve Check Point IKEv1 site-to-site VPN MitM via certificate validation weakness (CVSS 7.4) — no observed exploitation
- campaign C0XMO
- campaign FIFA World Cup 2026 pre-event threat cluster
- cve DD-WRT UPnP/SSDP parser stack buffer overflow — FortiGuard-attributed propagation vector for C0XMO/Gafgyt botnet; DOES NOT RESOLVE ON NVD/MITRE (flagged 2026-06-08, vendor-attributed/unverified)
- cve Google Chrome ANGLE graphics engine out-of-bounds read/write → sandbox escape (CVSS 9.6); Chrome 149 record 429-patch release
- cve Keycloak CORS ACAO reflected from unverified JWT azp claim on UMA endpoint (fixed 26.6.3)
- cve FFmpeg parser/demuxer heap or stack overflow (depthfirst AI-agent discovery; PoC public, fixed upstream)
- cve FFmpeg parser/demuxer heap or stack overflow (depthfirst AI-agent discovery; PoC public, fixed upstream)
- cve FFmpeg parser/demuxer heap or stack overflow (depthfirst AI-agent discovery; PoC public, fixed upstream)
- cve FFmpeg parser/demuxer heap or stack overflow (depthfirst AI-agent discovery; PoC public, fixed upstream)
- cve FFmpeg parser/demuxer heap or stack overflow (depthfirst AI-agent discovery; PoC public, fixed upstream)
- cve FFmpeg parser/demuxer heap or stack overflow (depthfirst AI-agent discovery; PoC public, fixed upstream)
- cve FFmpeg parser/demuxer heap or stack overflow (depthfirst AI-agent discovery; PoC public, fixed upstream)
- cve FFmpeg parser/demuxer heap or stack overflow (depthfirst AI-agent discovery; PoC public, fixed upstream)
- cve FFmpeg parser/demuxer heap or stack overflow (depthfirst AI-agent discovery; PoC public, fixed upstream)
- cve Keycloak SSRF via OIDC token endpoint manipulation (fixed 26.6.3)×2
- cve Keycloak missing server-side WebAuthn credential-registration validation (fixed 26.6.3)
- cve Keycloak token-exchange privilege escalation via silent subject_token removal (fixed 26.6.3)×2
- cve Keycloak ROPC grant bypass of client-policy enforcement (fixed 26.6.3)
- cve Keycloak refresh-token replay window after server restart resets startupTime (fixed 26.6.3)
- actor OP-512×2
- campaign Silent Ransom Group physical USB intrusions×5
- cve MISP access-control bypass exposing private galaxy metadata to non-admin org users (CVSS 5.3)
- cve MISP mass-assignment account-takeover in UsersController::edit() (CVSS 9.0, patched 2026-06-04)×2
- cve SolarWinds Serv-U uncontrolled resource consumption — unauthenticated DoS via Content-Encoding: deflate (CISA KEV 2026-06-05)
- campaign Operation FlutterBridge
- incident DentaQuest×3
- cve Redis use-after-free in unblockClientOnKey() → GOT-overwrite RCE (post-auth; default-passwordless)
- cve Simple SA Wirtualna Uczelnia unauthenticated SSTI → RCE (redirectToUrl)
- cve Simple SA Wirtualna Uczelnia reflected XSS (locale parameter)
- cve OpenStack Mistral policy-enforcement bypass → authenticated arbitrary code execution (OSSA-2026-020; evaluated and dropped — see brief §7)
- campaign DesckVB RAT malspam
- campaign Stock-exchange mailbox espionage
- incident Booking.com-fed hotel phishing (CH)×2
- cve MISP OTP bypass — session established in beforeFilter before OTP when LdapAuth.mixedAuth+require_otp both on; fix commit 39b3cb15 / >=2.5.37
- cve Windows Snipping Tool ms-screensketch: URI handler NTLM hash leak — patched April 2026; cited as structural predecessor of unpatched search: URI variant
- cve Microsoft 365 Copilot for Android OAuth-token theft via production debug flag (CVSS 4.4); patched 2026-05-12
- cve Microsoft Word for Android OAuth-token theft via production debug flag (CVSS 7.1); patched 2026-05-12
- cve Microsoft PowerPoint for Android OAuth-token theft via production debug flag (CVSS 7.1); patched 2026-05-12
- cve Microsoft Excel for Android OAuth-token theft via setIsDebugMode(true) debug flag left in production (CVSS 7.7); patched 2026-05-12
- cve Mirasvit Full Page Cache Warmer (Magento 2) unauthenticated PHP object-injection RCE via CacheWarmer cookie; CISA KEV 2026-06-03, ITW from 2026-04-24; fix v1.11.12
- cve Progress Sitefinity CMS web-services improper input validation (CWE-20); BSI WID-SEC-2026-1783
- cve Progress Sitefinity CMS OData improper input validation (CVSS 9.8, CWE-20), affects 15.4.8623-15.4.8629; BSI WID-SEC-2026-1783
- cve Progress Sitefinity CMS ServiceStack web-services credential exposure (CVSS 8.8, CWE-522); BSI WID-SEC-2026-1783
- cve Progress Sitefinity CMS — CWE-522 Insufficiently Protected Credentials (Sitefinity Insight credential disclosure, gated on Insight integration/non-default config); CVSS 10.0 per NVD; BSI WID-SEC-2026-1783; evaluated 2026-06-04, dropped to §7 (no fetchable vendor primary, no ITW)
- cve Progress Sitefinity CMS legacy-branch flaw (CVSS 8.7), affects v8.0-13.3; BSI WID-SEC-2026-1783
- cve Devolutions Server LDAP coercion exposing PAM credentials (DEVO-2026-0013, CVSS 7.1); evaluated 2026-06-04, dropped to §7 (no ITW, below §2 gate)
- cve Burst Statistics WordPress 3.4.0-3.4.1.1 unauthenticated REST auth-bypass (is_mainwp_authenticated) → admin impersonation/rogue admin; actively exploited; fix v3.4.2
- cve Kirki WordPress Freeform Page Builder 6.0.0-6.0.6 unauthenticated password-reset hijack → admin account takeover; actively exploited; fix v6.0.7
- cve Devolutions Server MFA bypass via improper factor-key state handling (DEVO-2026-0013, CVSS 7.5); evaluated 2026-06-04, dropped to §7 (no ITW, below §2 gate)
- campaign Operation XENOFISCAL
- report Sophos 2026 Active Adversary Report×2
- cve ZeroLogon — Netlogon privilege escalation; chained by Cl0p in South Staffordshire Water 2020-2022 intrusion (cited in ICO 2026-05-11 enforcement)
- cve Linux kernel cgroup v1 release_agent container escape (missing CAP_SYS_ADMIN check); CISA KEV 2026-06-02
- cve Oracle WebLogic Server unauth T3/IIOP data access (CVSS 7.5); CISA KEV 2026-06-01 on active exploitation
- cve Android Framework integer-overflow LPE (no-interaction), limited targeted exploitation; June 2026 bulletin
- cve Trend Micro Apex One On-Premise relative path traversal fleet-wide code injection
- cve Windows Hyper-V UAF guest-to-host escape (May 2026 Patch Tuesday); evaluated 2026-06-03, not covered (out-of-window)
- cve Windows DNS Client (dnsapi.dll) heap buffer overflow — RCE via malicious DNS response (CVSS 9.8, May 2026 Patch Tuesday)
- cve Digital Knowledge KnowledgeDeliver LMS — pre-shared ASP.NET machineKey ViewState deserialization RCE; exploited as zero-day pre-2026-02-24×2
- campaign Operation Dragon Weave
- cve KAMSOFT KS-SOMED healthcare software — hardcoded FTP credentials in update client allow malicious-update injection / supply-chain (CVSS 4.0 8.7, CERT-PL)
- cve Apache Solr 9.4.0-9.10.1/10.0.0 — hardcoded BasicAuth template credentials allow unauthenticated remote admin (CVSS 8.1, BSI WID-SEC-2026-1740); no patch yet, manual workaround
- cve CIFSwitch — Linux kernel CIFS/SMB-client LPE to root via forged cifs.spnego key requests (19-year-old bug; RHEL9/SLES15/Mint/Kali); dropped from 2026-06-02 brief as out-of-window + no Section 2 gate
- cve WP Maps Pro WordPress plugin <=6.1.0 — unauthenticated admin-account creation via disclosed nonce + wp_ajax_nopriv_ handler; actively exploited (CVSS 9.8); fixed 6.1.1
- cve Disig Web Signer 2.0.3-2.5.3 — unauthenticated RCE in Slovak eIDAS qualified-signature client (CVSS 4.0 9.4, SK-CERT); fixed 2.5.5
- campaign Ghost Stadium PhaaS×2
- campaign Italian low-cost commercial spyware
- campaign SmartApeSG ClickFix campaign
- campaign TrapDoor×5
- incident Dutch/Belgian/Irish booking-SaaS breach
- policy EU 20th Russia sanctions package×2
- report ENISA NIS360 2026×2
- cve Oracle E-Business Suite — May 2026 CPU critical (referenced in §7, dropped)
- cve Oracle E-Business Suite — May 2026 CPU critical (referenced in §7, dropped)
- cve Oracle E-Business Suite — May 2026 CPU critical (referenced in §7, dropped)
- cve Oracle E-Business Suite — May 2026 CPU critical (referenced in §7, dropped)
- cve Delta Electronics DIAView SCADA — unauthenticated remote database access (predecessor to CVE-2026-9642 mitigation bypass)
- cve Ghost CMS Content API unauthenticated SQLi (CVSS 9.4); ITW-exploited in ClickFix campaign; fixed 6.19.1×3
- cve Veeam Agent for Microsoft Windows — local privilege escalation enabling arbitrary command execution / lateral movement (CVSS 7.3)
- cve Veeam Software Appliance (Linux) — authenticated Backup Administrator can write arbitrary files (CVSS 8.6)
- cve QuickCMS (OpenSolution) session fixation — CERT-PL; dropped (niche, CVSS 4.8)
- cve QuickCMS (OpenSolution) MITM-XSS via HTTP plugin fetch — CERT-PL; dropped (niche, CVSS 2.3)
- cve Slican PBX administrative protocol authentication bypass — attacker bypasses login by executing a specific command; CVSS 4.0: 9.3; CERT Polska disclosure 2026-05-27
- cve Slican PBX deterministic secure-key generation from publicly-obtainable system properties — admin credentials recoverable without auth; CVSS 4.0: 8.7; CERT Polska
- cve Slican PBX remote management modem interface — hardcoded caller-ID bypasses admin auth and temporarily re-enables remote access when configured off; CVSS 4.0: 9.3; CERT Polska
- cve Marimo notebook pre-auth RCE
- cve SUSE Rancher — project-owner role can flip namespace PSA labels to privileged, enabling container-to-host escape (CVSS 8.4)
- cve SUSE Rancher GitHub App auth — group principals granted for every team in GitHub org to any team-belonging user (CVSS 8.8)
- cve Samba SAMR RPC server — unauthenticated shell injection via %u substitution in check password script (CVSS 10.0)×2
- cve Samba print-command subsystem — unauthenticated shell injection via %J substitution; raw/classic printing only (CVSS 10.0)×2
- cve Portainer CE — Docker plugin endpoints not registered in proxy authorization handler; non-admin can install/enable plugins → root host execution (CVSS 9.4)
- cve Portainer CE Docker Swarm service API — EndpointSecuritySettings restrictions not enforced; non-admin escapes to host via privileged containers (CVSS 9.4)
- cve SUSE Rancher cluster-import endpoint — command injection via URL-encoded newline in authImage YAML field; control-plane node RCE (CVSS 9.6)
- cve Mautic API contact-filtering SQL injection (post-auth)
- cve LiteSpeed User-End cPanel plugin lsws.redisAble priv-esc to root (CVSS 10.0, ITW)×2
- cve GitLab CE/EE Duo AI integration — improper user identity resolution allows authenticated user to impersonate another user when triggering Duo AI workflows (CVSS 8.2)
- cve Roundcube Webmail pre-auth SQL injection in virtuser_query plugin via preg_replace backslash escape bypass; CVSS 8.1; patched in 1.6.16 LTS / 1.7.1×2
- cve Ivanti Secure Access Client local privilege escalation
- cve Szafir SDK (KIR) improper certificate verification / auth bypass — Polish qualified e-signature SDK; fixed v463
- cve IBM HTTP Server / WebSphere Application Server — pre-auth RCE via improper input validation in HTTP request parser (CVSS 9.8); NCSC.ch flagged 2026-05-28×2
- cve GitHub Enterprise Server < 3.22 — unauthenticated SSRF via upload-endpoint path traversal exposes internal services and credentials (CVSS 4.0 = 9.2; GHSA-fwfp-h68w-2hcr)
- cve Mautic Focus component SSRF (post-auth; reaches internal/cloud-metadata)
- cve Mautic stored XSS (post-auth)
- cve Mautic stored XSS / JS injection (post-auth)
- cve Delta Electronics DIAView SCADA — incomplete fix / mitigation bypass of CVE-2025-62582 unauthenticated remote database access (CVSS 3.1 = 9.8; Tenable TRA-2026-44)
- cve Mautic file inclusion / path traversal (post-auth)
- cve Mautic path traversal / file manipulation (post-auth)
- cve Mautic JavaScript code injection (post-auth)
- actor GREYVIBE×2
- actor Kimsuky×2
- campaign ChatGPhish×2
- campaign LLMShare×2
- report ESET APT Activity Report Q4 2025 – Q1 2026×2
- campaign Asocks residential-proxy takedown
- campaign JINX-0164
- cve Gogs prior argument-injection variant (referenced in Rapid7 2026-05-29 disclosure as same-class predecessor)
- cve GitLab CE/EE — Wiki DoS via insufficient validation of malformed markup (CVSS 6.5)
- cve GitLab EE — Developer-role users can access deployment data (pipeline environment variables, deployment keys) via missing authorization checks (CVSS 4.3)
- cve Gogs argument-injection RCE (CVE id claimed by S3 sub-agent — unverified against authoritative NVD entry; Rapid7 publication states no CVE assigned at disclosure; deferred to next-run verification)
- cve GitLab CE/EE — seventh CVE in 19.0.1 / 18.11.4 / 18.10.7 patch release (defender-relevance not enumerated; left to vendor page)
- cve GitLab EE — Developer-role users can bypass group-level flow restrictions when foundational flows enabled (CVSS 4.3)
- cve GitLab CE/EE — unauthenticated enumeration of private project paths via API (CVSS 5.3)
- cve GitLab CE/EE — Authenticated users can access CI data from unintended reference types via incorrect reference resolution (CVSS 4.3)
- cve IBM HTTP Server Administration Server — heap-based buffer overflow (CVSS 8.0)
- cve IBM HTTP Server mod_ibm_upload — DoS via NULL pointer dereference (CVSS 7.5)
- cve IBM HTTP Server mod_mem_cache — DoS via expired pointer dereference (CVSS 7.5)
- cve IBM HTTP Server — RCE in TLS mutual-authentication configurations (CVSS 8.1)
- cve IBM HTTP Server — DoS via uncontrolled resource consumption (CVSS 7.7)
- actor Ababil of Minab×2
- campaign GlassWorm takedown
- campaign AI-chatbot search-poisoning cryptojacking
- campaign Akira kill-chain reconstruction (SANS ISC)
- incident AFC Ajax fan-data breach
- trend ILIAS LMS May 2026 fixes×2
- cve Gitea container registry access-control failure — private repo container images unauthenticatedly pullable across all versions < 1.26.2 (4-year exposure window); Forgejo confirmed affected; § 7 drop 2026-05-28
- cve NGINX ngx_http_rewrite_module heap buffer overflow (earlier of two May 2026 disclosures); exploitation attempts per NCSC-NL; § 7 drop (primary 2026-05-18 out-of-window)×2
- cve TanStack Router npm credential-stealing payload — exfiltrated Nx contributor GitHub CLI OAuth token (precursor to CVE-2026-48027 Nx Console compromise); CISA KEV 2026-05-27
- cve Nx Console v18.95.0 VS Code extension supply-chain compromise — credential-stealing payload harvested 1Password, Claude Code config, npm, GitHub, AWS creds; CISA KEV 2026-05-27
- cve Roundcube Webmail CSS sanitisation failure via SVG animate attributeName=style — info disclosure / SSRF in HTML email rendering; patched in 1.6.16 LTS / 1.7.1
- cve Roundcube Webmail code injection via LDAP autovalues option — arbitrary PHP code evaluation when option is configured; patched in 1.6.16 LTS / 1.7.1
- cve Roundcube Webmail HTML sanitisation bypass via SVG document permitting CSS injection; patched in 1.6.16 LTS / 1.7.1
- cve DAEMON Tools Lite signed-build trojanisation (12.5.0.2421–12.5.0.2434) via Disc Soft Limited build infrastructure; CISA KEV 2026-05-27
- cve NGINX ngx_http_rewrite_module heap buffer overflow — out-of-bounds write in worker process memory pool via overlapping regex capture groups; CVSS v3.1 8.1 / v4.0 9.2; exploitation attempts per NCSC-NL; § 7 drop (primary 2026-05-22 out-of-window)
- actor Screening Serpens×3
- cve yoda-digital mcp-gitlab-server < 0.6.0 — no-auth SSE RPC endpoint bound to 0.0.0.0 with wildcard CORS exposes operator GitLab PAT (CVSS 4.0 = 9.2; GHSA-8jr5-6gvj-rfpf); noted in § 7 (niche package)
- tool RemotePE
- trend Underminr
- cve SonicWall Gen6 SSL-VPN MFA bypass via UPN vs SAM account-name split; Akira-linked actors exploited Feb-Mar 2026; firmware update insufficient without 6-step LDAP reconfiguration×2
- cve FortiOS / FortiProxy authentication bypass — weaponised by 'The Gentlemen' RaaS initial access
- cve Erlang SSH RCE (Cisco context) — confirmed by Check Point Research as initial-access CVE for The Gentlemen RaaS
- cve Langflow CORS misconfiguration + SameSite=None refresh token theft
- cve Palo Alto PAN-OS Captive Portal unauthenticated root RCE (CVSS 9.3, ITW, KEV deadline 2026-05-09)×6
- cve Cisco Secure Workload internal REST API zero-auth Site Admin CVSS 10.0×2
- cve SEPPmail Secure E-Mail Gateway — pre-auth path traversal in LFT /v1/file.app → arbitrary file write as nobody → RCE via /etc/syslog.conf overwrite
- cve Linux kernel RxGK rxgk_decrypt_skb() page-cache write (missing COW guard) — DirtyDecrypt LPE; affects Fedora / Arch / openSUSE Tumbleweed (CONFIG_RXGK=y)
- cve Microsoft Defender Malware Protection Engine — link-following EoP to SYSTEM (CWE-59); Engine ≤ 1.1.26030.3008; actively exploited×3
- cve Sparx Pro Cloud Server — authenticated SQL injection via database API endpoint; PCS ≤ 6.1×2
- cve Sparx Pro Cloud Server — pre-auth bypass via model-parameter omission in POST binary blob → unauthenticated SQL query execution; CVSS4 9.3×2
- cve Sparx Enterprise Architect ≤ 17.1 — client-side RBAC bypass via EA client binary patch (CWE-603); CVSS4 8.7×2
- cve Sparx Pro Cloud Server WebEA — race condition in /data_api/dl_internal_artifact.php → RCE in web-server context (CWE-362); CVSS4 7.7×2
- cve Sparx Pro Cloud Server — malformed SQL crash (DoS); CWE-835×2
- cve n8n self-hosted automation — xml2js prototype pollution (CWE-1321), root of authenticated-to-RCE chain via Git node SSH×2
- cve Microsoft Azure Local Disconnected Operations (ALDO) — CVSS 10.0 unauthenticated network elevation-of-privilege; MSRC Exploitation More Likely×2
- cve vm2 Node.js sandbox — host-object access via BaseHandler.getPrototypeOf trap; sandbox escape to host context; CVSS 10.0; patched 3.11.0
- cve Microsoft Defender Antivirus local DoS — exploited alongside CVE-2026-41091 in combined out-of-band engine update 4.18.26040.7×2
- cve Microsoft Defender Malware Protection Engine — heap-based buffer overflow over network → unauthenticated RCE in Defender process context; CVSS 8.1
- cve ChromaDB Python FastAPI server pre-auth RCE via embedding-function model loading before auth check (CVSS 4.0 = 10.0; v1.5.9 unpatched at disclosure)×2
- cve Keycloak OIDC login flow session fixation enabling account takeover (Keycloak 26.6.2; BSI WID-SEC-2026-1612 HIGH)×2
- cve Drupal core highly-critical pre-auth SQL injection in database abstraction API on PostgreSQL backends; CISA KEV-listed 2026-05-22 (SA-CORE-2026-004)×4
- campaign Megalodon×6
- campaign Packagist Laravel-Lang supply-chain wave
- trend Software-exposed BYOVD hardware-gate bypass
- cve Stormshield SNS remote DoS (CERTFR-2026-AVI-0631); dropped from §2, mentioned in §7
- cve NLnet Labs Unbound DNSSEC validator UAF (CVSS 9.8), fixed 1.25.1
- cve ISC BIND 9 DoH use-after-free (CVSS 7.4), fixed 9.20.23
- cve Keycloak OIDC token introspection endpoint does not enforce audience restriction; lightweight access tokens leak claims cross-client (Keycloak 26.6.2)×2
- cve Keycloak execute-actions token replay enabling unauthorised WebAuthn / FIDO2 credential enrollment on victim account (Keycloak 26.6.2)×2
- cve Microsoft Exchange Server 2016/2019/SE — OWA stored XSS (CISA KEV 2026-05-15, actively exploited, no permanent patch — EEMS Mitigation M2 only)×5
- cve NLnet Labs Unbound heap overflow, default-config (CVSS 8.6), fixed 1.25.1
- cve Keycloak Authorization Services Protection API cross-realm IDOR allowing realm-A authenticated attacker to access realm-B resources (Keycloak 26.6.2)×2
- cve ssh-keysign-pwn — 9-year ptrace race in Linux kernel __ptrace_may_access() reaches root + SSH host-key exfiltration; four public Qualys exploits on default major distros
- cve ISC BIND 9 non-Internet CLASS DoS (CVSS 7.5), fixed 9.18.49/9.20.23
- incident Kimwolf DDoS-for-hire arrest
- report Check Point AI Threat Landscape Digest (Mar–Apr 2026)
- report Rapid7 Q1 2026 Threat Landscape Report×2
- trend SPIP 2026 RCE wave×3
- cve Linux kernel ptrace credential-window LPE (Jann Horn, 2019) — historical predecessor cited as background in 2026-05-23 CVE-2026-46333 deep dive
- cve PwnKit — polkit pkexec local root (Qualys, 2022) — historical reference cited in 2026-05-23 CVE-2026-46333 deep dive as functional-equivalent outcome
- cve Looney Tunables — glibc ld.so local privilege escalation (Qualys, 2023) — historical reference cited in 2026-05-23 CVE-2026-46333 deep dive as disclosure-pattern precedent
- campaign Calypso telco espionage campaign×4
- cve Microsoft Azure CVSS 10.0 cluster — server-side mitigated, no customer action required (MSRC May 2026)
- cve Microsoft Azure CVSS 10.0 cluster — server-side mitigated, no customer action required (MSRC May 2026)
- cve Microsoft Azure CVSS 10.0 cluster — server-side mitigated, no customer action required (MSRC May 2026)
- cve Microsoft Entra ID / Azure CVSS 10.0 cluster — server-side mitigated, no customer action required (MSRC May 2026)
- cve Microsoft Entra ID / Azure CVSS 10.0 cluster — server-side mitigated, no customer action required (MSRC May 2026)
- report Verizon 2026 DBIR×2
- trend PinTheft
- cve SquirrelMail post-auth RCE — used by Webworm against Serbian government targets per ESET 2026-05-20 (initial-access probe after credential theft)
- cve Keycloak admin evaluate-scopes endpoint cross-role PII leakage bypassing user-view permissions (Keycloak 26.6.2)
- cve Keycloak WebAuthn packed self-attestation acceptable-AAGUID policy bypass enabling enrolment of hardware tokens outside policy (Keycloak 26.6.2)
- actor Storm-2949
- campaign Storm-2949 SSPR-to-Key-Vault kill chain
- incident actions-cool/issues-helper compromise
- trend Sparx Enterprise Architect five-CVE chain×2
- cve Fortinet FortiSandbox unauthenticated RCE in Web UI (CWE-862, CVSS 9.1 vendor / 9.8 NVD) — pre-auth, patch in 4.4.9 / 5.0.2 / Cloud 5.0.6; Cloud 23/24 require migration×2
- cve vm2 Node.js sandbox — symbol-to-string coercion TypeError sandbox bypass; patched 3.10.5
- cve Copy Fail — Linux kernel algif_aead local privilege escalation (ITW, KEV)
- cve vm2 NodeVM allow-list bypass — Module._load() reachable when child_process is explicitly permitted → OS command execution; CVSS 9.9
- cve vm2 prototype pollution via attacker-controlled JS; CVSS 10.0; affects 3.9.6 – 3.10.5; patched 3.11.0
- cve vm2 code injection via BaseHandler.getPrototypeOf; CVSS 10.0; patched 3.11.0
- cve vm2 null-proto exception exploitation; CVSS 9.8; affects ≤ 3.11.1; patched 3.11.2
- cve vm2 neutralizeArraySpeciesBatch() bypass via null-proto exception; CVSS 9.8; affects ≤ 3.11.1; patched 3.11.2
- cve SEPPmail Secure Email Gateway — unauthenticated RCE via exposed GINAv2 test endpoints (CVSS 9.3)×3
- cve Fortinet FortiAuthenticator unauthenticated RCE in management interface (CWE-284, CVSS 9.8) — pre-auth, patch in 6.5.7 / 6.6.9 / 8.0.3×2
- cve Exim 4.97–4.99.2 GnuTLS builds — BDAT/CHUNKING use-after-free (Dead.Letter), pre-auth RCE (CVSS 9.8, ENISA EUVD critical); fixed in Exim 4.99.3
- campaign Fast16
- campaign INTERPOL Operation Ramz×2
- campaign Living Off the Pipeline×3
- incident ARWINI data exfiltration
- incident Grafana Labs CoinbaseCartel breach
- tool PCPJack×5
- trend BigBlueButton bbb-web CVE trio
- cve VMware Fusion 25H2 (macOS) — TOCTOU SETUID race condition LPE (CVSS 7.8); dropped from § 2 in 2026-05-19 brief (did not clear inclusion gates)
- cve n8n HTTP Request Node injection — companion amplifier to CVE-2026-42231 prototype-pollution chain×2
- cve n8n XML Node injection — companion amplifier to CVE-2026-42231 prototype-pollution chain×2
- cve n8n Git node SSH chain — terminal sink of CVE-2026-42231 prototype-pollution to RCE×2
- cve n8n XML Node injection — companion amplifier to CVE-2026-42231 prototype-pollution chain×2
- cve BigBlueButton bbb-web < 3.0.21 — insecure sessionToken generation (CWE-330) enables session hijack
- cve BigBlueButton bbb-web < 3.0.21 — presentationUploadExternalUrl API checksum bypass (CWE-284)
- cve BigBlueButton bbb-web < 3.0.23 — SSRF in presentation URL validation (CWE-918)
- incident Rhysida Stuttgart claim
- incident THORChain vault drain
- cve Fireblocks GG18/GG20 Paillier missing-ZK-proof flaw (TSSHOCK class; cited as background-class for THORChain 2026-05-15 GG20 TSS exploit)
- cve AMD-SB-7052 — Zen 2 µop-cache corruption / SoC isolation LPE (CVSS 7.3 CVSS 4.0)
- cve SAP S/4HANA Enterprise Search ABAP — authenticated SQL injection in SAP_BASIS 751–758 / 816 (CVSS 9.6)×2
- cve SAP Commerce Cloud — unauthenticated arbitrary code execution via Spring Security misordering on cloud-config endpoint (CVSS 9.6, SAP Note 3733064)×2
- cve Microsoft SSO Plugin for Jira/Confluence — unauthenticated Entra ID credential forgery (CVSS 9.1, More Likely exploitation)
- cve F5 BIG-IP iControl REST Manager-role authenticated RCE (May 2026 Quarterly Notification, CVSS 9.1)
- cve DHTMLX PDF Export Module — unauthenticated server-side JavaScript injection RCE (CVSS 4.0 score 10.0)
- cve KIR SzafirHost — JAR zip-polyglot signature-verification bypass enabling RCE in Polish qualified e-signature browser helper (CVSS 8.6)×2
- cve OpenClaw / Clawdbot — OpenShell sandbox TOCTOU write escape (CVSS 9.6, Claw Chain)
- cve Nextcloud Server/Enterprise Server 2FA bypass via WebDAV pre-authenticated session token reuse
- cve PHP Composer GitHub Actions token disclosure in error messages (fixed in 2.9.8 / 2.2.28)
- cve DHTMLX Diagram export module — path traversal (CVSS 4.0 score 9.2)
- cve Ivanti Xtraction < 2026.2 external control of file name/path (CWE-73, CVSS 9.6) — arbitrary file read + HTML write to web tree; auth required
- campaign FunnelKit Magecart injection
- cve WinRAR file-extension spoofing arbitrary code execution (cited as veteran exploit by Kaspersky Q1 2026 report)
- cve RelayKing NTLM relay — post-access primitive used by The Gentlemen RaaS
- cve Netgate pfSense Community Edition authenticated root RCE — vendor refuses to fix
- cve Netgate pfSense Community Edition authenticated root RCE companion to CVE-2025-69690 — vendor refuses to fix
- cve Cisco Catalyst SD-WAN companion CVE (exploited since March 2026)
- cve Cisco Catalyst SD-WAN companion CVE (exploited since March 2026)
- cve Cisco Catalyst SD-WAN companion CVE (exploited since March 2026)
- cve Checkmarx Jenkins AST plugin backdoor (TeamPCP/UNC6780 supply-chain compromise, SANDCLOCK credential stealer, CVSS 9.4)
- cve F5 BIG-IP privilege escalation via misconfigured permissions (May 2026 Quarterly, CVSS 8.7)
- cve F5 BIG-IP privilege escalation via misconfigured permissions (May 2026 Quarterly, CVSS 8.7)
- cve F5 BIG-IP privilege escalation via misconfigured permissions (May 2026 Quarterly, CVSS 8.7)
- cve F5 BIG-IP SSH password exposure in iControl REST audit logs (May 2026 Quarterly, CVSS 8.7)
- cve DHTMLX PDF Export Module — path traversal via src attribute (CVSS 4.0 score 9.2)
- cve F5 BIG-IP iControl REST command injection (May 2026 Quarterly, CVSS 8.7)
- cve F5 BIG-IP iControl REST command injection (May 2026 Quarterly, CVSS 8.7)
- cve Microsoft Dynamics 365 On-Premises — authenticated code injection with scope change (CVSS 9.9, May 2026 Patch Tuesday)
- cve F5 BIG-IP iControl REST command injection (May 2026 Quarterly, CVSS 8.7)
- cve F5 BIG-IP iControl REST command injection (May 2026 Quarterly, CVSS 8.7)
- cve OpenClaw / Clawdbot — TOCTOU read escape / file disclosure (CVSS 7.7, Claw Chain)
- cve OpenClaw / Clawdbot — command-parser allowlist bypass (CVSS 8.8, Claw Chain)
- cve OpenClaw / Clawdbot — MCP loopback senderIsOwner privilege escalation (CVSS 7.8, Claw Chain)
- cve Progress MOVEit Automation unauthenticated authentication bypass (CVSS 9.8)
- cve GitLab CE/EE — stored XSS in analytics dashboards (CVSS 8.7); cited as dropped from § 2
- cve PHP SOAP extension UAF in SOAP_GLOBAL(ref_map) (with companions CVE-2026-7261, CVE-2026-7262); patched in PHP 8.4.8 / 8.3.22 / 8.2.30×3
- cve PHP SOAP companion to CVE-2026-6722; patched 2026-05-08×3
- cve PHP SOAP companion to CVE-2026-6722; patched 2026-05-08×3
- cve GitLab CE/EE — stored XSS in container registry virtual registry upstreams (CVSS 8.7); cited as dropped from § 2
- cve GitLab CE/EE — stored XSS in Jira integration (CVSS 8.7); cited as dropped from § 2
- tool Gremlin Stealer
- trend AMD-SB-7052
- cve Microsoft Exchange Server pre-auth RCE (ProxyShell) — cited in 2026-05-16 § 5 deep dive Background
- cve JetBrains TeamCity authentication bypass — cited in 2026-05-16 § 3 SentinelOne CI/CD subversion case study
- cve Cisco SD-WAN local privilege escalation (UAT-8616 version-downgrade re-exploitation technique)
- cve BlueHammer — Windows zero-day by Nightmare Eclipse (confirmed ITW by Huntress, April 2026)
- cve Nextcloud Server SQL injection in column-type parameter (Moderate)
- cve Google Chrome CVE (mentioned in recency-dropped items, 2026-05-12)
- cve Google Chrome CVE (mentioned in recency-dropped items, 2026-05-12)
- campaign CL-STA-1132×11
- campaign FamousSparrow Azerbaijan intrusion
- report Q1 2026 ransomware quarterly synthesis
- tool GemStuffer
- cve Microsoft Exchange Server SSRF (ProxyNotShell) — cited as initial-access vector in 2026-05-14 FamousSparrow deep dive; chained with CVE-2022-41082
- cve Microsoft Exchange Server PowerShell remoting deserialization RCE (ProxyNotShell) — cited as initial-access vector in 2026-05-14 FamousSparrow deep dive; chained with CVE-2022-41040
- cve HPE ArubaOS AOS-10 stored XSS in web management interface (CVSS 8.8) — referenced in 2026-05-14 § 7 drop note (gate not cleared)
- cve Cline kanban npm package cross-origin WebSocket hijack (CVSS 9.6) — referenced in 2026-05-14 § 7 drop note (out-of-window)
- incident Foxconn Nitrogen ransomware
- tool MDASH
- tool TrickMo C
- trend Centreon April 2026 vulnerability cluster
- cve SAP Forecasting & Replenishment — authenticated OS-command injection (CVSS 8.2, SAP May 2026 patch day)
- cve Microsoft Word Preview Pane RCE (CVSS 8.4, More Likely exploitation, May 2026 Patch Tuesday)
- cve Microsoft Word Preview Pane RCE (CVSS 8.4, More Likely exploitation, May 2026 Patch Tuesday)
- cve Microsoft Word Preview Pane RCE (CVSS 8.4, May 2026 Patch Tuesday)
- cve Microsoft Word Preview Pane RCE (CVSS 8.4, May 2026 Patch Tuesday)
- cve Earlier Thymeleaf CVE referenced in § 7 disambiguating the dropped Thymeleaf item; CSO Online article 2026-04-17 covered this CVE rather than CVE-2026-41901
- cve Thymeleaf SSTI sandbox bypass — referenced in § 7 explaining out-of-window drop (GHSA published 2026-04-29)
- incident South Staffordshire Water ICO fine×2
- report CERT-FR agentic-AI risk report (CERTFR-2026-ACT-016)×3
- report GTIG AI Threat Tracker (May 2026)×2
- cve ConnectWise ScreenConnect path traversal — chained with CVE-2024-1709 by Kimsuky/Storm-1175; KEV deadline 2026-05-12 (out-of-window per § 7 of 2026-05-12 brief)
- cve ConnectWise ScreenConnect authentication bypass (CVSS 10.0) — chained with CVE-2024-1708; cited as 2026-05-12 drop
- cve Android adbd wireless ADB authentication bypass (CVSS 8.8, adjacent-network, public PoC 2026-05-11) — § 2 gate not cleared
- cve Ivanti EPMM remote authenticated → administrative-access via improper access control (CVSS 8.8, May 2026 update)×2
- cve Ivanti EPMM on-prem improper certificate validation → pre-auth Sentry impersonation (CVSS 9.1, ITW, KEV chain)×5
- cve Ivanti EPMM unauthenticated arbitrary method invocation (CVSS 7.0, May 2026 update)×2
- cve Ivanti EPMM on-prem admin API improper input validation → RCE (CVSS 7.2, ITW, KEV deadline 2026-05-10)×5
- cve Ivanti EPMM — fourth companion CVE in May 2026 EPMM update (high-severity per BleepingComputer / SecurityWeek)×2
- campaign SMS-blaster smishing (Switzerland)
- policy EDPB Coordinated Enforcement Framework 2026×3
- incident Braintrust AWS breach
- incident DENIC .de DNSSEC outage×3
- incident JDownloader official site compromised×2
- tool Beagle
- cve Microsoft Office Equation Editor RCE (cited as veteran exploit by Kaspersky Q1 2026 exploit report)
- cve Microsoft Office Equation Editor RCE (cited as largest-share detected exploit by Kaspersky Q1 2026 report)
- cve Ivanti EPMM pre-auth API access (2023, exploited by APT29; cited as historical precedent in 2026-05-08 deep dive)
- cve SimpleHelp RMM unauthenticated privilege escalation (ITW)
- cve SimpleHelp RMM path traversal — unauthenticated file download (ITW)
- cve Samsung MagicINFO 9 Server unauthenticated arbitrary file write → RCE (CVSS 8.8, ITW)
- cve Ivanti EPMM critical (January 2025, state-actor exploitation; cited as historical precedent in 2026-05-08 deep dive)
- cve Next.js middleware authorisation bypass via crafted header — weaponised by PCPJack worm
- cve CentOS Web Panel FileManager shell injection — weaponised by PCPJack worm
- cve xrdp pre-authentication stack buffer overflow → RCE
- cve W3 Total Cache PHP injection via mfunc comment processor — weaponised by PCPJack worm
- cve Ivanti EPMM January 2026 critical — historical precedent cited in 2026-05-09 Ivanti UPDATE
- cve Ivanti EPMM January 2026 critical companion — historical precedent cited in 2026-05-09 Ivanti UPDATE
- cve WPVivid Backup unauthenticated file upload — weaponised by PCPJack worm
- cve Cisco Unity Connection authenticated RCE in management API (CVSS 8.8, NATO NCSC discovery; logged § 7 — dropped from § 2, gate not cleared)
- cve Cisco Unity Connection unauthenticated SSRF in default-enabled Web Inbox (CVSS 7.2; logged § 7 — dropped from § 2, gate not cleared)
- cve Windows Shell LNK exploit predecessor — APT28 weaponised against Ukraine and EU; February 2026 patch left CVE-2026-32202 residual
- cve Apache HTTP Server 2.4.66 HTTP/2 double-free — DoS and potential RCE (CVSS 8.8)
- cve Zabbix frontend stored XSS in map element labels (CVSS 6.1)
- cve Zabbix API confidentiality — unprivileged user can read admin host data (CVSS 5.3)
- cve Zabbix frontend reflected XSS in host-group filter (CVSS 6.1)
- cve Microsoft Semantic Kernel .NET SDK — unintended [KernelFunction] on SessionsPythonPlugin Download/UploadFileAsync → arbitrary file write → sandbox escape (CVSS 9.9)×3
- cve Microsoft Semantic Kernel Python SDK — prompt-injection-to-RCE via InMemoryVectorStore filter (CVSS 9.9, PoC public)×3
- cve Apache httpd mod_proxy_ajp heap overflow → remote crash / potential RCE (CVSS 7.5)
- cve cPanel/WHM CVE cluster — dropped from § 3 (embargoed, gate not cleared)×2
- cve cPanel/WHM CVE cluster — dropped from § 3 (embargoed, gate not cleared)×2
- cve cPanel/WHM unsafe symlink handling — chmod abuse on arbitrary files (CVSS 8.8, second emergency TSR)×2
- cve Windows Shell protection mechanism failure → NTLM coercion / spoofing (CVSS 4.3, APT28 ITW, KEV deadline 2026-05-12)×2
- cve Traefik proxy mTLS bypass via fragmented TLS ClientHello
- cve GLPI < 10.0.25 / 11.0.7 SSRF (CERTFR-2026-AVI-0551)
- cve Metabase Enterprise Java serialization → authenticated RCE (CVSS 8.8)
- cve GLPI < 10.0.25 / 11.0.7 data integrity compromise (CERTFR-2026-AVI-0551)
- cve Spring Cloud Config Server Google Secrets Manager backend flaw (HIGH)
- cve Spring Cloud Config Server pre-auth directory traversal (CVSS 9.8)
- cve Spring Cloud Config Server companion CVE (HIGH)
- cve Spring Cloud Config Server companion CVE (MEDIUM)
- cve cPanel/WHM authentication bypass via CRLF injection (mass exploitation ongoing, KEV)
- cve LiteLLM Proxy pre-auth SQL injection — all upstream LLM API keys at risk (CVSS 9.3, KEV deadline 2026-05-11)×2
- cve GLPI < 10.0.25 / 11.0.7 XSS (CERTFR-2026-AVI-0551)
- cve GLPI < 10.0.25 / 11.0.7 XSS (CERTFR-2026-AVI-0551)
- cve GLPI < 10.0.25 / 11.0.7 XSS (CERTFR-2026-AVI-0551)
- cve GLPI < 10.0.25 / 11.0.7 XSS (CERTFR-2026-AVI-0551)
- cve SEPPmail GINAv2 — missing authentication in admin REST API (CVSS 9.3)×2
- cve SEPPmail GINAv2 — insecure deserialisation via session cookie → RCE (CVSS 9.2)×2
- cve SEPPmail appliance management — LFI and arbitrary file deletion (CVSS 8.8)×2
- cve SEPPmail GINAv2 — server-side template injection via Freemarker (CVSS 8.3)×2
- cve Progress MOVEit Automation authenticated privilege escalation (CVSS 8.8)
- cve GLPI < 10.0.25 / 11.0.7 security policy bypass / auth bypass (CERTFR-2026-AVI-0551)
- cve Progress Telerik RadAsyncUpload DoS via path traversal (CVSS 7.5)
- cve Progress Telerik RadFilter deserialization → unauthenticated RCE (CVSS 9.8)
- cve SEPPmail appliance management — information disclosure (CVSS 6.9)×2
- incident DAEMON Tools supply-chain compromise
- incident Inditex (Zara) breach×2
- cve Apache CloudStack post-auth authentication token flaw — dropped from § 3 (gate not cleared)
- incident Die Linke ransomware breach×2
- incident Eurail breach
- report Dragos 2025 OT Cybersecurity Year in Review×2
- report Kaspersky Q1 2026 Exploits and Vulnerabilities Report×2
- cve Microsoft Office Protected View bypass — security feature bypass (CVSS 7.8, KEV deadline 2026-02-16 already passed; deferred from §4)
- cve Microsoft Office Protected View chain CVE (deferred from §4; see CVE-2026-21509 series)
- cve Microsoft Office Protected View chain CVE (deferred from §4; see CVE-2026-21509 series)
- actor UAT-8302
- incident DigiCert support-portal compromise
- incident Mediaworks Kft (Hungary)
- incident Trellix source-code breach
- policy ENISA CVE Numbering Authority Root expansion
- policy EU Cybersecurity Package 2026
- policy Poland NIS2 transposition
- report GTIG Europe Data Leak Landscape 2025
- report Europol IOCTA 2026
- report Mandiant M-Trends 2026
- campaign ACR Stealer fake-Claude distribution
- campaign AI-brand impersonation malware delivery
- campaign Amazon SES BEC abuse
- campaign APT28 tradecraft evolution 2026
- campaign B1ack's Stash May 2026 card release
- campaign Chinese-language PhaaS OTP-relay ecosystem
- campaign BadIIS 'demo.pdb' MaaS backdoor campaign
- campaign CL-STA-1062 TinyRCT campaign
- campaign ClickFix macOS expansion
- campaign IPv4-mapped IPv6 eBanking phishing
- campaign Kali365 PhaaS
- campaign FishMonger Windows SprySOCKS campaign
- campaign FortiSandbox triple exploitation
- campaign Gamaredon GammaPhish / GammaWorm
- campaign Grandoreiro 2026 Iberian campaign
- campaign Potemkin / RMMProject ClickFix campaign
- campaign InstallFix
- campaign Malicious JetBrains Marketplace AI plugins
- campaign npm/Go folderOpen-task infostealer campaign
- campaign Kimsuky HelloDoor / PebbleDash C2 evolution
- campaign macOS ClickFix hdiutil campaign
- campaign Stripe-metadata Magecart skimmer
- campaign Fake 'Perplexity AI' Chrome extension
- campaign Mastra easy-day-js backdoor
- campaign MuddyWater Chaos false-flag
- campaign MuddyWater Q1 2026 DLL side-loading campaign
- campaign M365 voicemail-phishing wave (CH)
- campaign npm dependency-confusion wave 2026
- campaign OceanLotus FireAnt supply-chain compromise
- campaign Malicious OpenClaw ClawHub skills
- campaign 'Photo ZIP' hospitality phishing
- campaign PostCSS npm typosquat campaign
- campaign ROADtools weaponisation (Entra ID)
- campaign Rust crypto-clipper VirusTotal abuse
- campaign WeTransfer steganographic JPEG loader
- campaign ScarCruft NarwhalRAT campaign
- campaign ShapedPlugin Pro supply-chain backdoor
- campaign 'Signal Support' recovery-key phishing
- campaign SVG application/ecmascript phishing wave
- campaign Shai-Hulud copycat wave
- campaign Microsoft Teams external-chat phishing
- campaign The Gentlemen self-propagating encryptor
- campaign Turla STOCKSTAY campaign
- campaign Tycoon2FA post-takedown resurgence
- campaign UAC-0226 GIFTEDCROOK WinRAR exploitation
- campaign UNC6508 INFINITERED campaign
- campaign WhatsApp VBScript RMM campaign
- campaign WordPress Steam-profile C2 malware
- incident 7-Eleven Salesforce breach
- incident AdaptHealth contractor session hijack
- incident ADT Inc. cloud environment breach
- incident Aflac Japan subsidiary portal breach
- incident AudiA6 laundering-service takedown
- incident Awesome Motive CDN supply-chain attack
- incident Crimenetwork relaunch takedown
- incident Brazil Cell Broadcast hijack
- incident BWH Hotels reservation breach
- incident California Water Service breach (Handala)
- incident California AG v. 23andMe
- incident Carnival Corporation breach
- incident Cellebrite UFED use on Pivovarov
- incident EFK federal cyber-governance audit
- incident Checkmarx Jenkins plugin backdoor
- incident ChipSoft ransomware breach
- incident CISA/Nightwing GovCloud key exposure
- incident Clinical Diagnostics NMDL ruling
- incident CNIL IQVIA fine
- incident Coupang PIPC record fine
- incident Dashlane TOTP brute-force
- incident Dream Market admin arrest
- incident Drupal core pre-patch warning (PSA-2026-05-18)
- incident Europol shadow-IT disclosure
- incident France ANTS breach
- incident HCRG notification delay
- incident POST Luxembourg outage (Huawei VRP zero-day)
- incident London Clinic insider caution
- incident Markerstudy insider POCA confiscation
- incident RAC insider POCA confiscation
- incident Instructure (Canvas LMS) breach
- incident iRhythm data theft
- incident Jaguar Land Rover 2025 ransomware
- incident Lithuania Centre of Registers breach
- incident Maine breach-portal abuse
- incident Canton Zürich Baudirektion listing
- incident Instagram AI-support account takeovers
- incident Meta v. NSO contempt complaint
- incident Microsoft DCU Fox Tempest disruption
- incident Madison Square Garden breach
- incident Munich LHM-Services breach
- incident NAIC PeopleSoft breach
- incident Navient fourth-party ransomware exposure
- incident NFSP ransomware
- incident Nidec Chaun Choung ransomware
- incident Nintendo TinyPulse breach
- incident Stark Industries hosting arrests
- incident node-ipc backdoor
- incident Novo Nordisk data theft
- incident Nx Console extension compromise
- incident OFAC Nobitex sanctions
- incident One Medical legacy-storage breach
- incident OpenAI supply-chain exposure
- incident Oxford CareerConnect breach
- incident Polish water-treatment OT intrusion
- incident polyfill.io reactivation
- incident PostHog AWS exploit
- incident ServiceNow unauthenticated REST exposure
- incident Charter/Spectrum listing
- incident Silver Fox arrests
- incident Škoda online-shop breach
- incident Spanish doxer arrest
- incident First observed LLM-agent-driven intrusion
- incident Texas Parks & Wildlife vendor breach
- incident The Gentlemen leak-site listings (VSFS, DEVO-Tech)
- incident UK ICO Commissioner resignation
- incident UK visa-portal lookalike exposure
- incident Ukrposhta disruption
- incident Unimed hospital-billing breach
- incident Vimeo breach (Anodot)
- incident West Pharmaceutical ransomware
- incident UN WFP Gaza registration breach
- incident Xsolis breach
- policy LG Berlin II Apobank PSD2 ruling
- policy CISA BOD 26-04
- policy EDPB Art. 33 breach-notification template
- policy ENISA SBOM Adoption State of Play 2026
- policy Europol mandate-expansion pause demand
- policy Germany CRA implementation bill
- policy Germany Cybersicherheitsstärkungsgesetz
- policy Germany KRITIS-Dachgesetz
- policy npm staged publishing GA
- policy npm v12 install-scripts default-off
- report Bauman 'Department No. 4' investigation
- report Elastic AAD Graph detection guidance
- report ESET Gamaredon 2025 annual paper
- report 'Safeguarding Our Secrets' bulletin
- report NCSC-CH G7 Évian pre-event advisory
- report Linux prctl process-masquerading analysis
- report NCSC-CH assessment: AI in vulnerability management
- report NCSC-UK AI-vulnerability checklist
- report Sophos State of Identity Security 2026
- report Swiss Threat Landscape Report (Swiss Post)
- report Windows COM-abuse analysis (Talos)
- tool BirdCall
- tool Datadog Shai-Hulud scanner
- tool PamDOORa
- tool QLNX
- tool AI-orchestrated EDR-evasion lab
- tool ZiChatBot
- trend Adaptive AI worm PoC
- trend Apereo CAS OIDC-provider flaw
- trend claude-code-action bot-actor bypass
- trend Cloud-logging defence-evasion taxonomy
- trend AI-agent FFmpeg zero-day batch
- trend github.dev OAuth-token theft
- trend GCP API-key deletion delay
- trend OpenClaw skills supply-chain surface
- trend LangGraph checkpointer SQLi→RCE chain
- trend M365 Android debug-flag OAuth theft
- trend Mautic 7.1.2/6.0.9 flaw set
- trend Entra Agent ID AddRemoveCreds priv-esc
- trend DICOM/Orthanc heap attack surface
- trend Windows Search URI NTLM leak
- incident xAI Grok Build CLI whole-repository/secrets exfiltration (July 2026)