Entities
2463 CVEs, products, actors, campaigns, incidents, tools, advisories, and reports tracked across briefs. The ×N marker counts entries referencing an entity · multi-entry entities are the "stories that unfolded".
Total entities
2463
10 types
Recent (30 d)
612
entities with new coverage in window
Distinct sources
608
hosts cited at least once
Total appearances
2591
brief-section attributions
Co-occurrence links
9199
entity ↔ entity in same item
By type
- cve1144 (46%)
- product537 (22%)
- incident199 (8%)
- actor140 (6%)
- campaign138 (6%)
- tool109 (4%)
- malware80 (3%)
- trend42 (2%)
- report41 (2%)
- policy33 (1%)
Recent coverage
Aggregate mentions per ISO week, last 21 weeks.
By year
- policy EU Cyber Resilience Act×4
- policy EU NIS2 Directive×2
- policy Austria NISG 2026
- tool Hermes AI agent×5
- tool Strix
- tool Cairn
- policy Canton Bern Gesetz über Informations- und Cybersicherheit (ICSG) and IDSV ordinance×2
- product Arista VeloCloud Orchestrator On-Prem×2
- product Check Point Log Server×2
- product Check Point Multi-Domain Log Server×2
- product Check Point Multi-Domain Security Management Server×4
- product Check Point Security Management Server×5
- product Check Point SmartEvent
- product F5 BIG-IP Access Policy Manager (APM)
- product Google Account
- product Magento
- product Softaculous Virtualizor
- product WordPress×5
- cve Softaculous Virtualizor: unauthenticated OS command injection to root via billing-module hook
- cve Softaculous Virtualizor: unauthenticated PHP object injection in billing-module hook
- cve Softaculous Virtualizor: unauthenticated cross-tenant balance write via billing-module hook
- cve MikroTik RouterOS SSH signature-verification bypass (MikroTrick component); CERT Polska confirms active exploitation
- cve MikroTik RouterOS SSH pre-auth rekey exec request, unauthenticated managed-file-namespace write
- cve Check Point Quantum Security Gateway/Spark Firewall, improper certificate validation, unauthenticated RCE in VPN negotiation (CVSS 9.8)
- cve Check Point Security Management: pre-auth path traversal to arbitrary script execution, exploited as a zero-day since July
- cve Arista VeloCloud Orchestrator: actively exploited, two release trains still have no fix
- cve F5 BIG-IP APM: unauthenticated heap overflow in OAuth-profile processing reaches RCE
- product Anthropic Claude Code×4
- product GitHub Copilot
- product Google Gemini CLI×2
- product Microsoft Windows×22
- product OpenAI Codex×3
- product Synology DiskStation Manager (DSM)
- product Zyxel GS1900 Series Switches
- actor Red Heron×2
- cve Synology DSM, unauthenticated insufficient login-logic entropy, arbitrary file read/write and DoS
- cve Synology DSM, authenticated LDAP API permission flaw, arbitrary file read/write and DoS
- cve Synology DSM, unauthenticated SCGI output-encoding bug, arbitrary file read/write and DoS
- cve Windows Install Service "Dark Elevator" privesc, incomplete fix later closed by CVE-2026-66804
- cve Synology DSM, authenticated Upload API path-control flaw, arbitrary file write and DoS
- cve Windows Cross Device Service, dangling COM registration reaches SYSTEM privesc (Google Project Zero)
- cve Zyxel GS1900 Series Switches stack-based buffer overflow, exploited at scale by an actor GreyNoise assesses overlaps Red Heron, CISA KEV
- actor MuddyWater×4
- actor Qilin×14
- actor The Gentlemen×9
- tool macOS.Gaslight×2
- campaign Contagious Interview×8
- actor Cybernox×4
- actor Jade Sleet×2
- product GLPI×2
- product Google Chrome×7
- product Google Docs / Apps Script
- product macOS×2
- product Microsoft Edge×4
- product Microsoft Exchange Server×4
- product NetSupport Manager
- product SAP NetWeaver AS ABAP
- product SentinelOne SentinelMemoryScanner.exe
- product Terraform
- actor NightEagle
- malware GhostContainer
- actor REF9334
- malware KREMLIN
- actor xMetah×2
- incident AFPA third-party accommodation-tool data extraction (September 2026)
- cve BlueKeep, Windows RDP pre-auth RCE (2019), exploited by NightEagle/APT-Q-95 for local-account creation and by BlueMoon-adjacent chains historically
- cve Microsoft Exchange Server post-auth RCE via ViewState (2020), exploit component bundled into NightEagle/APT-Q-95's GhostContainer Exchange backdoor
- cve ZeroLogon, Netlogon privilege escalation; chained by Cl0p in South Staffordshire Water 2020-2022 intrusion (cited in ICO 2026-05-11 enforcement)
- cve GLPI unauthenticated SQL injection via the inventory endpoint, exploited by an operator associated with The Gentlemen RaaS for initial access
- product Oracle Access Manager
- product Oracle Forms
- product Oracle Fusion Middleware×3
- product Oracle Hyperion Financial Management×2
- product Oracle Internet Directory×2
- product Oracle Platform Security for Java
- product Oracle WebLogic Server×3
- cve Oracle Access Manager (Authentication Engine), unauthenticated flaw over HTTP, CVSS 10.0, September 2026 CSPU
- cve Oracle Platform Security for Java (centralized third-party jars), unauthenticated flaw over HTTP, CVSS 10.0, September 2026 CSPU
- cve Oracle WebLogic Server (Web Container), unauthenticated flaw over HTTP, CVSS 10.0, September 2026 CSPU
- cve Oracle Internet Directory (OID LDAP Server), unauthenticated flaw over LDAP, CVSS 10.0, September 2026 CSPU
- cve Oracle Forms (Forms Services), unauthenticated flaw over HTTP, CVSS 10.0, September 2026 CSPU
- cve Oracle Hyperion Financial Management (Security), unauthenticated flaw over HTTP, CVSS 10.0, September 2026 CSPU
- tool OTTERCOOKIE×3
- actor PurpleDelta×7
- product Linux kernel×4
- product Microsoft Visual Studio Code
- product NLnet Labs Unbound
- malware BeaverTail×2
- malware InvisibleFerret
- malware OtterCandy
- malware StoatWaffle
- cve Linux Kernel kTLS receive-path zero-length record logic error, CISA KEV 2026-09-18, network-reachable with kernel TLS receive offload
- cve Linux Kernel AF_ALG crypto-socket concurrent-write race condition, CISA KEV 2026-09-18, local
- cve Linux Kernel netfilter bridge ebtables SNAT ARP-rewrite out-of-bounds write, CISA KEV 2026-09-18, local
- cve NLnet Labs Unbound DNSSEC-validator self-referencing compression-pointer heap overflow, RCE possible (CVSS4.0 9.1)
- cve NLnet Labs Unbound CNAME-synthesis heap corruption during upstream response processing, RCE possible under specific builds (CVSS4.0 8.4)
- product Acronis Backup extension for Plesk (Linux)
- product Acronis Backup plugin for cPanel & WHM (Linux)
- product Brevo
- product Gyazo
- report NTC Cybersecurity of Photovoltaic Systems (2026)
- actor FamousSparrow×4
- malware SparroWocky
- malware MovieReaper
- incident Gyazo (Helpfeel) data breach (September 2026)
- incident Brevo Cloudflare Worker / ClickFix supply-chain compromise (September 2026)
- cve Cisco Identity Services Engine CWE-class-grouped bundle CVE from the Sept 2026 hardening release (CVSS 10.0), not reported exploited
- cve Cisco Identity Services Engine CWE-class-grouped bundle CVE from the Sept 2026 hardening release (CVSS 10.0), not reported exploited
- cve Cisco Secure Firewall Management Center Java deserialization RCE via External Database Access allowlist (CVSS 9.8), not reported exploited
- cve Cisco Secure Firewall Management Center sftunnel arbitrary file write to root (CVSS 9.9), requires existing low-privilege device credentials, not reported exploited
- cve Cisco Identity Services Engine sibling unauthenticated API authentication bypass (CVSS 10.0), not yet confirmed exploited
- cve Cisco Identity Services Engine unauthenticated API authentication bypass to root (CVSS 10.0), confirmed exploited, found via a TAC support case
- cve Acronis Backup plugin for cPanel & WHM/Plesk local privilege escalation via insecure default permissions (CVSS 7.8), CISA KEV-listed 2026-09-16, exploitation basis is a single customer report
- cve Check Point Security Management/Multi-Domain Security Management/Log Server unauthenticated stack overflow in login process to root RCE (CVSS 9.8), no confirmed exploitation, LivePatch fix
- actor Kairos×5
- incident Ayuntamiento de Velilla de San Antonio Kairos extortion claim (2026-08)×2
- tool DDRop
- malware PhantomRaven
- report Mandiant AI Risk and Resilience Report 2026
- actor DARK CASTLE×2
- policy AEPD guidance on AI-agent-executed attacks
- incident Ville de Libercourt ransomware/data-theft incident (2026-08)
- product AMD SEV-SNP
- product CircleCI
- product Cisco Identity Services Engine
- product Cisco ISE Passive Identity Connector
- product GitHub Actions×3
- product GitLab CI
- product Google Pixel
- product Intel Scalable SGX
- product Intel TDX
- product Jenkins
- product npm (Node Package Manager)
- cve Google Pixel cellular-modem zero-click privilege escalation, exploited in limited targeted attacks, CISA KEV 2026-09-16
- malware PlugX×6
- malware CHOSEN BRICK
- malware BambooToken
- cve GitLab CE/EE unauthenticated path traversal in repository commits API, arbitrary file read, CVSS 10.0
- cve GitLab EE insecure GraphQL-subscription deserialization, Advanced Search config/credential exposure via Duo Chat (CVSS 9.9), same 19.3.2 release as CVE-2026-85706
- incident Salt Mobile SA peripheral-system access-misuse data incident (September 2026)
- incident Swiss Bitcoin Pay internal-systems breach (September 2026)
- product Cisco Secure Email and Web Manager
- product Cisco Secure Email Gateway
- cve Cisco Secure Email Gateway / Secure Email and Web Manager, uncontrolled resource consumption grouping, September 2026 hardening release, not reported exploited
- cve Cisco Secure Email Gateway / Secure Email and Web Manager, path-traversal grouping, September 2026 hardening release, not reported exploited
- cve Cisco Secure Email Gateway / Secure Email and Web Manager, improper access control grouping, September 2026 hardening release, not reported exploited
- cve Cisco Secure Email Gateway / Secure Email and Web Manager, input-validation grouping, September 2026 hardening release, not reported exploited
- cve Cisco Secure Email Gateway / Secure Email and Web Manager, second injection-class grouping, September 2026 hardening release, distinct from the exploited CVE-2026-76461
- cve Cisco Secure Email Gateway, unauthenticated SQL injection in email parsing reaches root command execution, exploited, CISA KEV (3-day deadline)
- cve JFrog Artifactory auth-bypass, CVSS 9.8, now confirmed under active exploitation (watchTowr, NCSC-CH); attackers minting admin tokens via a default 'phantom' join key
- actor GTG-20006×2
- actor GTG-27005
- actor Midnight Blizzard×7
- actor Storm-2945×3
- campaign CaptiveCrunch×3
- incident Revolut fake-government-request KYC data breach (September 2026)
- cve CVE-2026-20079, Cisco Secure Firewall Management Center web interface: unauthenticated authentication bypass to root via a boot-time csm_processes session (CVSS 10.0, CWE-288); disclosed 2026-03-04 with no fix, per-train hot fixes added to the advisory 2026-07-31; Cisco reports no known malicious use, VulnCheck built a working exploit
- cve CVE-2026-20316; Cisco Secure Firewall Management Center ships a static low-privilege account in its web interface, and Cisco confirms exploitation has been ongoing
- cve Google Chrome V8 type confusion, actively exploited via a crafted HTML page×2
- cve Windows ALPC heap-based buffer overflow EoP / AppContainer sandbox escape to SYSTEM (CVSS 7.8), actively exploited zero-day, CISA KEV 2026-09-08, legacy line (Windows 10, Server 2012-2022)×2
- cve Google Chrome V8 out-of-bounds write, exploited in the wild, patched in Chrome 153 (seventh exploited Chrome zero-day of 2026)×2
- cve GitLab EE, buffer overflow in Advanced Search Unicode-conversion wrapper reachable via crafted Git project import (CVSS 8.5)
- incident Japan Digital Agency GSS unauthorized-access incident (2026-09)
- product ConnectWise ScreenConnect×2
- product GitLab×2
- product JFrog Artifactory×4
- cve SonicWall SMA1000 Work Place unauthenticated SSRF (CVSS 10.0, actively exploited)
- cve JFrog Artifactory token scope-validation flaw chained with CVE-2026-42018 into admin takeover, confirmed exploited
- cve JFrog Artifactory anonymous-user token exposure chained with CVE-2026-42016 into admin takeover, confirmed exploited
- cve ConnectWise ScreenConnect client file-transfer authorization flaw, worm-like exploitation from 20 August 2026, patched 26.6.5
- product Apereo CAS
- product Ivanti Endpoint Manager Mobile (EPMM)
- product Ivanti Neurons for ITSM
- product Ivanti Sentry
- cve Ivanti Neurons for ITSM, authenticated missing-authorization escalation to RCE (CVSS 9.9)
- cve Ivanti Neurons for ITSM, authenticated missing-authorization escalation to RCE (CVSS 9.9)
- cve Ivanti Neurons for ITSM, authenticated missing-authorization escalation to RCE (CVSS 9.9)
- cve Ivanti Neurons for ITSM, authenticated deserialization RCE (CVSS 8.8)
- cve Ivanti Neurons for ITSM, authenticated deserialization RCE (CVSS 9.9)
- cve Ivanti Neurons for ITSM, authenticated deserialization RCE (CVSS 8.8)
- cve Ivanti Neurons for ITSM, unauthenticated deserialization RCE (CVSS 9.8), September 2026 security update
- cve Ivanti Neurons for ITSM, unauthenticated deserialization RCE (CVSS 9.8), September 2026 security update
- cve Ivanti Endpoint Manager Mobile (EPMM), authenticated missing-authorization escalation to admin (CVSS 8.8)
- cve MikroTik RouterOS bandwidth-test unauthenticated memory disclosure / DoS
- cve Ivanti Sentry, unauthenticated authentication bypass to admin access (CVSS 8.1)
- malware PivotC2
- actor APT31
- actor UNK_LateNight
- actor UNK_DoubleCheck
- actor UNK_QuietRacket
- tool BlueMoon
- tool GemStone
- tool GhostChrome-X
- malware ShadowPad×4
- actor UTA0560
- malware GRIMWEDGE
- tool SUPERSTOMP
- tool LONGTALE
- product Check Point Security Gateway
- product Check Point Spark Firewall
- product Fortinet FortiOS×4
- product Fortinet FortiSASE
- product Fortinet FortiSwitchManager
- product SAP ABAP Platform×2
- product SAP BW/4HANA
- product SAP Enterprise Portal
- product SAP ERP / Business Suite (ECC)
- product SAP Kernel
- product SAP NetWeaver Application Server ABAP×3
- product SAP NetWeaver Message Server
- product SAP PI/PO
- product SAP S/4HANA
- product SAP Solution Manager
- product SAP Web Dispatcher
- cve RECON, SAP NetWeaver AS Java LM Configuration Wizard unauthenticated admin-account creation (2020); cited by Onapsis as historical precedent for 72-hour SAP patch reverse-engineering
- cve noPac, Active Directory sAMAccountName spoofing (2021); cited by GreyNoise as one of three domain-admin escalation paths in the PaperCut AI-orchestrated campaign
- cve noPac, Active Directory KDC ticket forging companion flaw (2021); cited by GreyNoise as one of three domain-admin escalation paths in the PaperCut AI-orchestrated campaign
- cve Fortinet FortiOS/FortiSwitchManager CAPWAP heap overflow, CISA KEV 2026-09-09, actively exploited since July 2026 via the PivotC2 RAT
- cve SAP NetWeaver Visual Composer unauthenticated file upload (2025), Mandiant's named most-exploited CVE of 2025; cited by Onapsis as historical precedent for OVERPASS/S4GET's severity
- cve Citrix NetScaler ADC/Gateway, memory overflow leading to unpredictable behaviour or denial of service; requires SIP ALG enabled on a Large Scale NAT group. CVSS 8.8.
- cve Citrix NetScaler ADC/Gateway, authentication bypass using an alternate path on Gateway (SSL VPN, ICA Proxy, CVPN, RDP Proxy) or AAA virtual servers; CVSS v4.0 9.3, no exploitation observed as of 2026-08-19.
- cve SAP OVERPASS, unauthenticated memory-corruption RCE in shared SAP kernel Extended Passport processing (CVSS 10.0), September 2026 Patch Day
- cve SAP S4GET, unauthenticated Message Server trust-bypass RCE (CVSS 9.8), September 2026 Patch Day
- cve PaperCut NG/MF, authentication bypass in the web management interface (Tapestry request-routing confusion), chained to CVE-2026-82078 for pre-auth RCE, exploited before a patch existed
- cve PaperCut NG/MF, unsafe dynamic class loading in the database connector, reached via CVE-2026-81578's config rewrite to achieve arbitrary Java bytecode execution
- cve Check Point Quantum Security Gateway/Management Server, unauthenticated heap overflow in VPN certificate ASN.1 decoding (CVSS 9.8)
- tool WeWorm
- product Microsoft Windows Server×4
- product Tencent WeChat
- cve Windows Update Stack link-following EoP to SYSTEM (CVSS 7.8), actively exploited zero-day, CISA KEV 2026-09-08, newest builds (Server 2025, Windows 11)
- actor Kimsuky×5
- actor ScarCruft×3
- trend StyleSmuggler
- actor TEMP.Hermit
- actor Citrine Sleet×2
- actor CryptoCore
- actor Moonstone Sleet
- actor Andariel
- trend 2026 wave of French public-administration data breaches
- incident Ministère de la Transition écologique data-exposure claim (France, 2026-09)
- tool BigBear 2.0
- product Adobe Commerce×2
- product Adobe Commerce B2B×2
- product Magento Open Source×2
- product Microsoft 365×12
- product Microsoft Entra ID×12
- product OISO (Outil Informatique de Surveillance des Organismes)
- cve StyleSmuggler, unauthenticated CVSS 10.0 RCE in Magento/Adobe Commerce via template-engine injection, exploited before Adobe's hotfix existed
- campaign StrikeShark×2
- actor Storm-1175×3
- actor SHADOW-EARTH-053
- malware StormEncryptor×2
- malware ted backdoor
- tool curlRAT
- malware Medusa×4
- report Recorded Future H1 2026 Malware and Vulnerability Trends
- actor ChimeraZ×2
- incident OnRecrute.EnAveyron.fr (Département de l'Aveyron employment platform) breach, September 2026
- product Apache Shiro
- product Cisco IOS XE×3
- product F5 BIG-IP
- product GeoServer×2
- product HAProxy
- product Microsoft SharePoint×8
- product N-able N-central×2
- product Odoo
- cve N-able N-central, internal API access-control gap (part of the September 2026 auth-bypass chain)
- cve N-able N-central, authentication bypass by primary weakness reaching internal APIs
- cve N-able N-central, pre-authentication RCE zero-day, confirmed exploited in the wild
- actor Nightmare Eclipse×10
- actor UNC6671×7
- incident Hugging Face autonomous AI agent breach×5
- trend MikroTrick (MikroTik RouterOS unauthenticated SSH takeover chain)
- incident OpenAI DSEwiki agent-collusion incident×2
- incident IDScan.net / Nexus 153M+ driver's-license dark-web marketplace
- incident Association des maires de France (AMF) SQL-injection breach
- incident JetBrains Cadence breach via unpatched TeamCity (CVE-2026-63077)
- tool HardBreacher
- tool PrettyPrague
- tool FalconFlank
- tool GreenSection
- product Association des maires de France membership portal (amf.asso.fr)
- product Avast Antivirus
- product CrowdStrike Falcon
- product Dell Secure Connect Gateway
- product IDScan.net identity-verification / document-scanning platform
- product JetBrains Cadence
- product JetBrains TeamCity On-Premises×2
- product Kaspersky Endpoint Security for Windows
- product MikroTik RouterOS
- cve Dell Secure Connect Gateway 5.0, flaw reported alongside CVE-2026-61410 and CVE-2026-61409 (DSA-2026-382)
- cve Dell Secure Connect Gateway 5.0, OS command injection reported alongside CVE-2026-61410 (DSA-2026-382)
- cve Dell Secure Connect Gateway 5.0, missing authorization allowing unauthenticated remote command execution via a single crafted request (DSA-2026-382)
- cve JetBrains TeamCity On-Premises, unauthenticated deserialization RCE via the agent-polling protocol (CVSS 9.8); added to the CISA KEV catalog 2026-08-05 on evidence of active exploitation, reversing the vendor's no-known-exploitation position at disclosure×2
- cve MikroTik RouterOS X.509 malformed-signature acceptance enabling TLS impersonation
- cve MikroTik RouterOS WebFig /jsproxy unauthenticated file read via stale session pointer
- cve Dell Secure Connect Gateway 5.0, insufficient verification of data authenticity; an unauthenticated attacker replays a captured request indefinitely to mint ADMIN access and refresh tokens (DSA-2026-382)
- cve Dell Secure Connect Gateway 5.0, execution with unnecessary privileges; exposed Docker socket yields host root from a low-privileged SSH operator and an orchestrator-container escape (DSA-2026-382)
- cve MikroTik RouterOS SSH crafted-username privilege escalation (MikroTrick component); CERT Polska confirms active exploitation
- incident Thomson Reuters C-Track court records breach
- product GeoNetwork opensource
- product Thomson Reuters C-Track
- cve Dirty Frag, Linux kernel xfrm-ESP page-cache write primitive, LPE (ITW, PoC public)
- cve Dirty Frag, Linux kernel RxRPC page-cache write primitive, LPE chain (ITW, patch pending)
- cve Fragnesia, Linux kernel xfrm ESP-in-TCP LPE (PoC public)
- cve GeoNetwork opensource: Saxon XSLT processor configured without secure processing, reachable via formatter upload chain to unauthenticated RCE
- cve GeoNetwork opensource: unauthenticated formatter-upload endpoint chained to unauthenticated RCE via unsafe Saxon XSLT processing
- incident Hôpital privé de la Loire (Ramsay Santé) DPI breach and 2026 CNIL sanction
- campaign ASCII-smuggling finance-lure phishing campaign (ActiveCampaign-relayed)
- actor CL-CRI-1131
- actor CL-CRI-1163
- actor BREEZE COMET
- incident Coder module-registry Cloudflare infrastructure compromise
- product Cisco Nexus 9000 Series Switches
- product Coder
- product Coder module registry (registry.coder.com)
- product HPE Aruba Networking AOS-CX
- product HPE Networking Fabric Composer
- cve HPE Networking Fabric Composer adjacent-network auth bypass (CVSS 9.6)
- cve Cisco Nexus 9000 Series Silicon One S1HAL unauthenticated root RCE (CVSS 9.8)
- cve HPE Networking Fabric Composer authenticated stored XSS (CVSS 9.0)
- cve HPE Networking Fabric Composer unauthenticated privileged RCE (CVSS 9.0)
- cve HPE ArubaOS-CX unauthenticated buffer-overflow RCE (CVSS 9.8)
- cve HPE ArubaOS-CX unauthenticated adjacent-network arbitrary file write (CVSS 8.8)
- cve HPE ArubaOS-CX predictable factory-default admin password (CVSS 8.1)
- cve HPE ArubaOS-CX authenticated stored XSS, named in BleepingComputer's account of HPE's bulletin but absent from NCSC-NL's structured mirror of the same bulletin; referenced only as an example of the source-count discrepancy, not independently confirmed
- cve HPE ArubaOS-CX unauthenticated format-string CLI flaw (CVSS 8.1)
- cve HPE Networking Fabric Composer API auth-bypass to admin (CVSS 10.0)
- cve HPE Networking Fabric Composer SSH daemon unauthenticated RCE (CVSS 10.0)
- cve Google Chrome DevTools use-after-free, High severity, no reported exploitation
- cve Google Chrome Network incomplete cleanup, High severity, no reported exploitation
- cve Google Chrome Mobile use-of-released-resource, Medium severity, no reported exploitation
- cve Google Chrome V8 race condition, High severity, no reported exploitation
- cve Google Chrome Transactions Platform improper input validation, Medium severity, no reported exploitation
- cve Google Chrome Compositing use-after-free, High severity, no reported exploitation
- cve Google Chrome Skia use-after-free, High severity, no reported exploitation
- cve Google Chrome WebGL out-of-bounds write, High severity, no reported exploitation
- cve Google Chrome Compositing type confusion, High severity, no reported exploitation
- cve Google Chrome CrashReporting out-of-bounds read, High severity, no reported exploitation
- cve Google Chrome CacheStorage improper resource exposure, High severity, no reported exploitation
- actor UTA0533×2
- malware EtherRAT×4
- malware SynkLoader×3
- actor Earth Berberoka
- tool oRAT
- tool AlphaAgent
- tool DownPro
- tool GitSpawn
- malware MoiClient
- product Alibaba Qwen Code
- product Apache HTTP Server
- product BerriAI LiteLLM×2
- product Block Goose
- product Cursor×2
- product Langflow×6
- product Lenovo PC Manager
- product Microsoft Teams×4
- product Nous Research Hermes Agent
- product Sangoma Switchvox
- product SonicWall SMA 1000×2
- product Windows Remote Management
- product xAI Grok Build
- cve Langflow, code-parameter code injection RCE in the validate endpoint, renewed mass exploitation since August 2026
- cve OpenAI Codex CLI, GitSpawn class, core.fsmonitor-adjacent helper mechanism running outside the command sandbox without user approval
- cve BerriAI LiteLLM, MCP OAuth2-passthrough fallback auth bypass, CISA KEV 2026-09-02
- cve Hermes Agent (Nous Research), GitSpawn class, git-config-triggered command execution; VulnCheck-assigned, unpublished in NVD/MITRE/CIRCL as of 2026-09-03
- cve Goose (AI coding agent), GitSpawn class, core.fsmonitor git-config command execution via `goose review`
- cve SonicWall SMA1000; pre-auth SSRF in Work Place interface, actively exploited
- cve SonicWall SMA1000, post-auth OS command injection in Appliance Management Console, actively exploited
- cve Sangoma Switchvox, unauthenticated SQL injection to RCE via PostgreSQL COPY TO PROGRAM, CISA KEV 2026-09-02
- actor Screening Serpens×4
- tool NodeRabbit
- tool PollCat
- incident Dropbox account takeover via Lenovo-ID SSO trust gap (2026-08)
- policy Swiss E-ID trust infrastructure
- product Dropbox
- cve WatchGuard Fireware OS, third pre-auth stack overflow in iked (IKE_AUTH/EAP-MSCHAPv2); requires IKE payload diagnostic logging enabled; CVSS 9.3, no exploitation reported
- cve WatchGuard Dimension, session hijack via unredacted session tokens in web UI diagnostic log; low-privileged Administrator can extract a Super Administrator's session; CVSS 9.3, no exploitation reported
- campaign Claude session-hijacking infostealer campaign
- actor Silver Fox×2
- malware ValleyRAT×4
- product Anthropic Claude
- cve BerriAI LiteLLM MCP test endpoints command injection to host RCE (CVSS 8.7), CISA KEV, actively exploited; unauthenticated when chained with CVE-2026-48710×2
- cve Microsoft Exchange Server MRSProxy, missing channel-binding check, authentication bypass by capture-replay; public exploit code published 27 August 2026
- actor Rhysida×5
- incident French Éducation nationale agent-training system breach (July 2026)×3
- incident DGFiP tax-authority intrusion (France, 2026)×2
- actor ZeroBytes×2
- incident Zéro Logement Vacant data breach (France, 2026)×2
- campaign France SDIS (fire and rescue) data-leak campaign 2026
- actor AplaGroup
- campaign TerminalFix×2
- incident Norway Digdir / ID-porten DDoS (August 2026)
- malware LoremIpsumLoader×2
- product Kestra
- product Metabase×2
- product RAGFlow
- product WatchGuard Dimension
- product WatchGuard Firebox
- product WatchGuard Fireware OS
- cve WatchGuard Fireware OS Mobile Security epm service - pre-auth stack overflow yielding root RCE
- cve WatchGuard Fireware OS iked - pre-auth heap buffer overflow yielding RCE, patched 2026-08-27
- cve WatchGuard Fireware OS iked - pre-auth type confusion via duplicated EAP payload in IKE_AUTH, yielding RCE
- cve Starlette/FastAPI host-header auth bypass (BadHost)×3
- cve Kestra workflow orchestrator - critical pre-auth login-bypass vulnerability, exploited to reach worker-side shell execution
- cve WatchGuard Fireware OS iked - heap-based buffer overflow yielding denial of service (BSI CERT-Bund WID-SEC-2026-3068, same advisory family as CVE-2026-19313/19315/13086, not itemised in WatchGuard's own blog roundup)
- malware SNOWLIGHT×3
- actor UNC5174×2
- actor UNC6586×2
- incident Berlin Landesnetz compromise (August 2026)
- product Gitea×2
- product Oracle HTTP Server
- product Oracle WebLogic Server Proxy Plug-in
- malware JITTERLY
- malware SIXZUT
- cve Oracle HTTP Server / WebLogic Server Proxy Plug-in - unauthenticated access-control bypass, CVSS 10.0; CISA KEV 2026-08-24, exploited since January 2026
- cve Gitea diffpatch endpoint - Git-hook code injection, command execution as the service account, CVSS 9.8; CISA KEV 2026-08-25, fixed in 1.27.1
- incident Pwn2Own Berlin 2026×4
- tool RedC2×2
- incident Swiss cantons eAutoIndex/ecari vehicle-registry data-harvesting incident
- product eAutoIndex (Viacar AG)
- product ecari
- product PaperCut MF
- product PaperCut NG
- product ServiceNow AI Platform×2
- product ServiceNow Now Platform
- cve PaperCut NG/MF, 2023 authentication-bypass RCE mass-exploited by ransomware operators; cited as historical background by Rapid7's 2026-08-28 analysis of the unrelated CVE-2026-81578/82078 chain
- cve ServiceNow AI Platform, unauthenticated GraphQL Composite Data API code injection (CVSS4.0 10.0)
- cve ServiceNow Now Platform, unauthenticated access-control bypass in the system-configuration image-upload processor (CVSS4.0 10.0)
- cve ServiceNow Now Platform, sandbox escape, same vulnerability class as CVE-2026-6875 (CVSS4.0 8.7)
- cve ServiceNow AI Platform, unauthenticated dynamic-schema SQL injection (CVSS4.0 10.0)
- actor JADEPUFFER×2
- actor ShinyHunters×24
- actor TA4922×4
- actor TeamPCP×16
- actor The Syndicate×2
- trend Joomla extension file-upload RCE wave×9
- tool NightLedger×2
- tool BridgeHead×2
- tool ArcBridge×2
- actor knaithe / KnYuan×2
- malware Troy×3
- actor UAT-10147×3
- campaign SilkParasite×2
- actor QTFY
- tool QScan
- tool QTRouter
- incident Manchester Airports Group data breach
- incident Martigny-Combe municipal email compromise (Valais, Switzerland, 2026-08)
- incident La Protection Civile eProtec platform data breach (France, 2026)
- incident SUEZ Eau France technical-supplier data breach (France, 2026-08)
- incident Winnipeg Health Sciences Centre ransomware (BMS impact)
- malware CNCMachineRMS
- actor Bismarck
- tool Wiz Red Agent
- incident Taiwan near-autonomous AI government intrusion (July 2026)
- tool Agentic Vulnerability Discovery Harness (AVDH)
- actor Dark Caracal
- malware GoCaracal
- tool TWOSTROKE(-like) backdoor
- tool Nimbus Manticore reverse SSH tunneler
- tool PackClient
- actor FulcrumSec×2
- product Activepieces
- product Adobe Campaign Classic×3
- product Adobe ColdFusion
- product Budibase
- product Copeland XWEB300D PRO
- product Copeland XWEB500B PRO
- product Copeland XWEB500D PRO
- product Danfoss AK-SM 800A
- product Directus
- product Elementor Pro (WordPress plugin)
- product IBM SPSS Statistics
- product iCagenda (mod_icagenda_calendar) for Joomla
- product isolated-vm (npm package)
- product Johnson Controls C-CURE 9000
- product Johnson Controls victor
- product Johnson Controls victor Application Server
- product Johnson Controls victor Web
- product Kaltura HTML5 Player Library (mwEmbed / html5lib)
- product Kaltura Server
- product Keycloak×2
- product LiteSpeed Cache (WordPress plugin)
- product Mastra AI
- product miniOrange OAuth Client for Joomla
- product miniOrange SAML 2.0 Single Sign On (WordPress)
- product miniOrange SAML SSO for Joomla
- product n8n×3
- product OAuth 2.0 / OpenID Connect discovery endpoints
- product ownCloud core (owncloud/core)
- product Rocket.Chat
- product Sim.ai
- product snowflake-connector-net
- product Sourcerer for Joomla (plg_system_sourcerer, plg_editors-xtd_sourcerer)
- product Splunk Enterprise
- product Splunk Secure Gateway
- product Ubiquiti UniFi Access
- product Ubiquiti UniFi Connect
- product Ubiquiti UniFi Enterprise Audio/Video Bridge
- product Ubiquiti UniFi Network
- product Ubiquiti UniFi OS Server
- product Ubiquiti UniFi Protect
- product Ubiquiti UniFi Talk
- product Unisoc T612
- product YOOtheme Pro for Joomla
- product YOOtheme ZOO (com_zoo)
- product Zalktis accounting software
- cve A 2023 ownCloud auth-bypass CVE re-enters CISA KEV because Hunt.io caught a suspected Chinese-speaking operator's open staging server using it to steal nuclear-research and naval-contractor data from two Philippine organisations
- cve A 2023 ownCloud auth-bypass CVE re-enters CISA KEV because Hunt.io caught a suspected Chinese-speaking operator's open staging server using it to steal nuclear-research and naval-contractor data from two Philippine organisations
- cve Claroty Team82: Danfoss AK-SM 800A refrigeration system managers, undocumented 'code-of-the-day' authentication bypass and post-authentication command-injection RCE across roughly 2,765 internet-exposed devices
- cve Claroty Team82: Danfoss AK-SM 800A refrigeration system managers, undocumented 'code-of-the-day' authentication bypass and post-authentication command-injection RCE across roughly 2,765 internet-exposed devices
- cve Claroty Team82: Danfoss AK-SM 800A refrigeration system managers, undocumented 'code-of-the-day' authentication bypass and post-authentication command-injection RCE across roughly 2,765 internet-exposed devices
- cve Roundcube Crypt_GPG_Engine PHP deserialization RCE - chained by UNK_MassTraction after CVE-2024-42009 XSS (Proofpoint)×2
- cve Google Gemini CLI GitHub Actions harness, trust-boundary bypass; fixed gemini-cli 0.39.1 / run-gemini-cli 0.1.22, published 2026-04-24
- cve miniOrange's SAML2Core library ships the same openssl_verify() tri-state authentication bypass across both its WordPress and Joomla SAML SSO products, one vendor code defect, two ecosystems, exploitation already attempted against the WordPress line
- cve Kaltura mwEmbed/html5lib video player: unauthenticated RCE and arbitrary file read via an undocumented ServiceUrl parameter, no vendor response, no patch, 630+ exposed instances found by the discoverer
- cve Kaltura mwEmbed/html5lib video player: unauthenticated RCE and arbitrary file read via an undocumented ServiceUrl parameter, no vendor response, no patch, 630+ exposed instances found by the discoverer
- cve Copeland XWEB Pro refrigeration controller, OS command injection (Claroty Team82 disclosure)
- cve Copeland XWEB Pro refrigeration controller, OS command injection (Claroty Team82 disclosure)
- cve Copeland XWEB Pro refrigeration controller, OS command injection (Claroty Team82 disclosure)
- cve Copeland XWEB Pro refrigeration controller, OS command injection (Claroty Team82 disclosure)
- cve Adobe ColdFusion 2025/2023, privilege escalation via input validation (APSB26-90)
- cve Copeland XWEB Pro refrigeration controller, OS command injection (Claroty Team82 disclosure)
- cve Johnson Controls C-CURE 9000 / victor: unauthenticated adjacent-network deserialization RCE on physical access-control application servers reaches connected security-workstation clients too (CVE-2026-21655, CVSS 9.6)
- cve Johnson Controls C-CURE 9000 / victor: unauthenticated adjacent-network deserialization RCE on physical access-control application servers reaches connected security-workstation clients too (CVE-2026-21655, CVSS 9.6)
- cve Claroty Team82: 23 vulnerabilities in Copeland XWEB Pro supervisory refrigeration controllers chain to unauthenticated root RCE; a deterministic admin password derived from the device's own MAC address is one of two independent pre-auth paths
- cve Copeland XWEB Pro refrigeration controller, OS command injection (Claroty Team82 disclosure)
- cve Copeland XWEB Pro refrigeration controller, OS command injection (Claroty Team82 disclosure)
- cve Copeland XWEB Pro refrigeration controller, OS command injection (Claroty Team82 disclosure)
- cve Copeland XWEB Pro refrigeration controller, OS command injection (Claroty Team82 disclosure)
- cve Copeland XWEB Pro refrigeration controller, OS command injection (Claroty Team82 disclosure)
- cve Copeland XWEB Pro refrigeration controller, OS command injection (Claroty Team82 disclosure)
- cve Copeland XWEB Pro refrigeration controller, OS command injection (Claroty Team82 disclosure)
- cve Claroty Team82: 23 vulnerabilities in Copeland XWEB Pro supervisory refrigeration controllers chain to unauthenticated root RCE; a deterministic admin password derived from the device's own MAC address is one of two independent pre-auth paths
- cve Copeland XWEB Pro refrigeration controller, OS command injection (Claroty Team82 disclosure)
- cve Copeland XWEB Pro refrigeration controller, OS command injection (Claroty Team82 disclosure)
- cve Copeland XWEB Pro refrigeration controller, OS command injection (Claroty Team82 disclosure)
- cve Copeland XWEB Pro refrigeration controller, OS command injection (Claroty Team82 disclosure)
- cve Copeland XWEB Pro refrigeration controller, OS command injection (Claroty Team82 disclosure)
- cve Copeland XWEB Pro refrigeration controller, OS command injection (Claroty Team82 disclosure)
- cve Adobe August 2026 Patch Day: ColdFusion ships a CVSS 10.0 unauthenticated OS command injection, and Campaign Classic ships two more unauthenticated CVSS 10.0 flaws in the same release
- cve Elementor Pro (WordPress, ~6M installs): unauthenticated arbitrary file upload to RCE via a validator/mover desynchronization in the Forms File Upload field (CVE-2026-32475, CVSS 9.0)
- cve SAP NetWeaver Application Server ABAP / ABAP Platform kernel, logical errors in DIAG protocol parsing allow an unauthenticated attacker to generate memory corruptions, CVSS 9.8, SAP Security Note 3714806.
- cve Johnson Controls C-CURE 9000 / victor: unauthenticated adjacent-network deserialization RCE on physical access-control application servers reaches connected security-workstation clients too (CVE-2026-21655, CVSS 9.6)
- cve NGINX ngx_http_rewrite_module heap buffer overflow (earlier of two May 2026 disclosures); exploitation attempts per NCSC-NL; § 7 drop (primary 2026-05-18 out-of-window)×3
- cve SAP Manufacturing Integration and Intelligence code injection reaching arbitrary OS command execution with a higher privilege requirement, CVSS 9.1, SAP Security Note 3758900.
- cve SAP Manufacturing Integration and Intelligence code injection reaching arbitrary OS command execution, CVSS 9.9, SAP Security Note 3765948; the patch removes the vulnerable servlet component.
- cve Adobe August 2026 Patch Day: ColdFusion ships a CVSS 10.0 unauthenticated OS command injection, and Campaign Classic ships two more unauthenticated CVSS 10.0 flaws in the same release
- cve Adobe August 2026 Patch Day: ColdFusion ships a CVSS 10.0 unauthenticated OS command injection, and Campaign Classic ships two more unauthenticated CVSS 10.0 flaws in the same release
- cve Adobe August 2026 Patch Day: ColdFusion ships a CVSS 10.0 unauthenticated OS command injection, and Campaign Classic ships two more unauthenticated CVSS 10.0 flaws in the same release
- cve Adobe ColdFusion 2025/2023, heap-based buffer overflow (APSB26-90)
- cve Linux kernel IPv6 UDP fraggap accounting bug (CVE-2026-53362) added to CISA KEV, an unprivileged local heap overflow via MSG_SPLICE_PAGES, no exploitation narrative published
- cve Anthropic Claude Code Action, CI command-validation bypass (quote-stripping before inspection; read-only allowlist exempt from path checks); fixed claude-code 2.1.163, published 2026-06-13
- cve SAP Commerce Cloud Data Hub Adapter, unauthenticated improper-authorization flaw reaching arbitrary code execution (CVSS 10.0), fixed in SAP Security Note 3771065 and requiring a rebuild and redeploy. Exploitation attempts against honeypot sensors recorded by Defused on 2026-08-14, three days after patch day, with no public proof-of-concept; NCSC-NL advisory NCSC-2026-0302 (2026-08-15) records active scanning for vulnerable systems.
- cve SAP ABAP Development Tools SQL Console; host expressions in SQL statements let a low-privileged authenticated user run unauthorized database operations, CVSS 8.8, SAP Security Note 3772411.
- cve Zalktis (Latvian accounting software): unauthenticated SQL injection reachable by any PEPPOL/UBL e-invoice sender, no account, no network position, just a routine bookkeeping import (CVE-2026-59109)
- cve VMSA-2026-0006, VMware vCenter Syslog directory traversal to remote code execution; confirmed actively exploited from 2026-08-03, 361 victim IP addresses across 47 countries
- cve miniOrange's SAML2Core library ships the same openssl_verify() tri-state authentication bypass across both its WordPress and Joomla SAML SSO products, one vendor code defect, two ecosystems, exploitation already attempted against the WordPress line
- cve Sourcerer for Joomla: unauthenticated RCE exploited in the wild since before a working fix existed; the vendor's first two patches did not close it, and the CVE was re-scoped in place to widen the affected range
- cve Hugging Face intrusion update; the sandbox escape was a chain of previously unknown JFrog Artifactory flaws, now patched, and the models also used publicly exposed credentials on four third-party services
- cve Hugging Face intrusion update; the sandbox escape was a chain of previously unknown JFrog Artifactory flaws, now patched, and the models also used publicly exposed credentials on four third-party services
- cve Hugging Face intrusion update; the sandbox escape was a chain of previously unknown JFrog Artifactory flaws, now patched, and the models also used publicly exposed credentials on four third-party services
- cve Hugging Face intrusion update; the sandbox escape was a chain of previously unknown JFrog Artifactory flaws, now patched, and the models also used publicly exposed credentials on four third-party services
- cve Hugging Face intrusion update; the sandbox escape was a chain of previously unknown JFrog Artifactory flaws, now patched, and the models also used publicly exposed credentials on four third-party services
- cve Hugging Face intrusion update; the sandbox escape was a chain of previously unknown JFrog Artifactory flaws, now patched, and the models also used publicly exposed credentials on four third-party services
- cve Hugging Face intrusion update; the sandbox escape was a chain of previously unknown JFrog Artifactory flaws, now patched, and the models also used publicly exposed credentials on four third-party services
- cve Hugging Face intrusion update; the sandbox escape was a chain of previously unknown JFrog Artifactory flaws, now patched, and the models also used publicly exposed credentials on four third-party services
- cve Hugging Face intrusion update; the sandbox escape was a chain of previously unknown JFrog Artifactory flaws, now patched, and the models also used publicly exposed credentials on four third-party services
- cve JFrog Artifactory: authenticated Docker-cache path traversal (CVE-2026-66384) added to CISA KEV, a CI/CD artifact-store write primitive with no published exploitation narrative
- cve iCagenda Calendar module for Joomla: unauthenticated SQL injection via com_ajax needs no session, token or account (CVE-2026-67365, CVSS 9.2), and the vulnerable module's own version number does not track the package version
- cve Microsoft Windows Ancillary Function Driver for WinSock (afd.sys) use-after-free race condition, exploited as a zero-day by the Lazarus-affiliated Operation Dream Job campaign to reach SYSTEM and load the FudModule v3.1 kernel rootkit; patched 2026-08-11, CISA KEV the same day.
- cve Adobe August 2026 Patch Day: ColdFusion ships a CVSS 10.0 unauthenticated OS command injection, and Campaign Classic ships two more unauthenticated CVSS 10.0 flaws in the same release
- cve Adobe ColdFusion 2025/2023, cross-site scripting escalating to code execution (APSB26-90)
- cve Adobe August 2026 Patch Day: ColdFusion ships a CVSS 10.0 unauthenticated OS command injection, and Campaign Classic ships two more unauthenticated CVSS 10.0 flaws in the same release
- cve Sourcerer for Joomla: unauthenticated RCE exploited in the wild since before a working fix existed; the vendor's first two patches did not close it, and the CVE was re-scoped in place to widen the affected range
- cve YOOtheme ZOO for Joomla: unauthenticated file-upload RCE (CVSS 10.0) plus a precondition-free SQL injection reachable with no submission form at all, three releases in three days, and the 3.x line has no fix
- cve YOOtheme ZOO for Joomla: unauthenticated file-upload RCE (CVSS 10.0) plus a precondition-free SQL injection reachable with no submission form at all, three releases in three days, and the 3.x line has no fix
- cve YOOtheme ZOO (Joomla), open redirect in Twitter comment callback
- cve Splunk Enterprise, privilege escalation via scheduled-search alert-action configuration, reaches the full credential store (SVD-2026-0801)
- cve Splunk Enterprise August 2026 hardening release (SVD-2026-0801): three unauthenticated CVSS 9.4 flaws let anyone holding an embedded-report token hijack the report owner's session, admins included
- cve Splunk Enterprise August 2026 hardening release (SVD-2026-0801): three unauthenticated CVSS 9.4 flaws let anyone holding an embedded-report token hijack the report owner's session, admins included
- cve Splunk Enterprise August 2026 hardening release (SVD-2026-0801): three unauthenticated CVSS 9.4 flaws let anyone holding an embedded-report token hijack the report owner's session, admins included
- cve Splunk Enterprise August 2026 hardening release (SVD-2026-0801): three unauthenticated CVSS 9.4 flaws let anyone holding an embedded-report token hijack the report owner's session, admins included
- cve Splunk Enterprise August 2026 hardening release (SVD-2026-0801): three unauthenticated CVSS 9.4 flaws let anyone holding an embedded-report token hijack the report owner's session, admins included
- cve YOOtheme ZOO for Joomla: unauthenticated file-upload RCE (CVSS 10.0) plus a precondition-free SQL injection reachable with no submission form at all, three releases in three days, and the 3.x line has no fix
- cve YOOtheme ZOO for Joomla: unauthenticated file-upload RCE (CVSS 10.0) plus a precondition-free SQL injection reachable with no submission form at all, three releases in three days, and the 3.x line has no fix
- cve Ubiquiti UniFi ecosystem: 22 CVEs in one bulletin, three at CVSS 10.0, unauthenticated CRLF-injection auth bypass, and unauthenticated command injection in UniFi Protect and UniFi Talk
- cve Ubiquiti UniFi ecosystem: 22 CVEs in one bulletin, three at CVSS 10.0, unauthenticated CRLF-injection auth bypass, and unauthenticated command injection in UniFi Protect and UniFi Talk
- cve Ubiquiti UniFi ecosystem: 22 CVEs in one bulletin, three at CVSS 10.0, unauthenticated CRLF-injection auth bypass, and unauthenticated command injection in UniFi Protect and UniFi Talk
- cve miniOrange's SAML2Core library ships the same openssl_verify() tri-state authentication bypass across both its WordPress and Joomla SAML SSO products, one vendor code defect, two ecosystems, exploitation already attempted against the WordPress line
- cve miniOrange's SAML2Core library ships the same openssl_verify() tri-state authentication bypass across both its WordPress and Joomla SAML SSO products, one vendor code defect, two ecosystems, exploitation already attempted against the WordPress line
- cve Citrix NetScaler ADC/Gateway, pre-auth SAML IdP memory overread leaking process memory in the NSC_TASS cookie; carried by NCSC-CH as actively exploited with a public PoC since 2026-07-03. Fixed in 14.1-72.61 / 13.1-63.18
- cve Citrix NetScaler ADC/Gateway, heap overflow during SAML SignedInfo canonicalization; CVE record describes only Denial of Service, but watchTowr published a pre-authentication chain to root (identifier is watchTowr's inference). Fixed in 14.1-72.61 / 13.1-63.18
- actor Static Tundra×2
- incident Poland energy-sector destructive attack (29 December 2025)×3
- campaign Operation Dream Job×2
- report BACS Halbjahresbericht 2026/I (Swiss cyber threat landscape, January–June 2026)
- report Rapid7 Labs Quarterly Threat Landscape Report, Q2 2026
- incident ReliaQuest social-engineering attempt (August 2026)
- malware DriveSilkRAT
- malware CookiETagRAT
- malware NomadRAT
- malware GoginRAT
- malware NodeEdgeRAT
- product Amazon Web Services
- cve Red Hat build of Keycloak (keycloak-services), reset-credentials flow bypass letting an unauthenticated attacker complete a password reset without the email-verification click and set new credentials, reaching full account takeover including administrators (CVSS 9.1, Red Hat as CNA; root cause improper state validation). Fixed 2026-08-18 in RHBK 26.4.15 (RHSA-2026:56520) and 26.6.6 (RHSA-2026:56523) plus the matching image and operator errata. Product-state correction (2026-08-24 audit): Red Hat records only two products under package_state, both "Not affected", the JBoss EAP Expansion Pack and Red Hat Single Sign-On 7; no Red Hat product is affected and unfixed.
- cve GitLab CE/EE, code injection via a GraphQL directive allowing an unauthenticated user to remotely modify or delete public projects and user data (CVSS 9.4, vendor-assigned). Fixed out of band on 2026-08-17 in 18.11.11 / 19.0.8 / 19.1.6 / 19.2.4. Actively exploited: WatchTowr honeypots caught in-the-wild attempts ~2 days after the patch (SecurityWeek 2026-08-20); NCSC-CH amended its advisory 2026-08-21; covered by entries/2026-08-22/cve-2026-19478-gitlab-honeypot-exploitation-confirmed. Not on CISA KEV as of 2026-08-24.
- cve Windows NAT (Hyper-V, upstream-spoofing configuration), NatJack primitive; the August 2026 update adds ISN randomisation, shipped disabled by default and enabled only via a registry key
- cve GeoServer / GeoTools jsonArrayContains unauthenticated SQL injection, exploited; fixed 2026-08-14 in GeoServer 3.0.1 / 2.28.5 / 2.27.6 (GeoTools 35.1 / 34.5 / 33.6); identifier assigned 2026-08-21
- cve SPIP before 4.4.20, unconditional pre-authentication RCE reported anonymously via ANSSI; the vendor's bulletin states exploitation attempts were already observed in the wild (August 2026). A second, distinct unconditional pre-auth RCE affects 4.4.20 itself and is fixed only in 4.4.21, that one is CVE-2026-77806. No mechanism is described by any citable vendor or CERT source.
- cve SPIP before 4.4.21, second unconditional pre-auth RCE, affecting 4.4.20 itself; exploited in the wild August 2026; identifier added to CERT-FR's advisory 2026-08-24
- campaign Mastra easy-day-js backdoor
- actor Sapphire Sleet×5
- actor Head Mare
- malware PhantomCore
- malware PhantomGraph
- malware PhantomHook
- malware PhantomReact
- campaign arrayref crates.io compile-time backdoor
- malware SPECTRE×2
- tool PentestGPT
- tool DeepAudit
- tool BTR.sys weaponisation (BTR Reforged)
- tool GraphSpy
- malware Phexia×2
- malware CastleRAT
- actor UNC6293
- actor UNC5976
- malware HEADRUSH
- actor Payload×3
- incident HWZ service-provider data breach (Switzerland, 2026-08)
- product Alibaba Nacos
- product append-only-vec (Rust crate)
- product arrayref (Rust crate)
- product Google Workspace
- product internment (Rust crate)
- product Microsoft Defender Antivirus×4
- product Microsoft Internet Information Services×2
- product MISP misp-stix
- product Progress Telerik UI for ASP.NET AJAX
- product TrueConf Server
- product WhatsApp
- product Zimbra Collaboration×6
- cve MSI Afterburner RTCore64.sys driver flaw, long patched, recorded only as one of the two vulnerable drivers Cisco Talos observed the SPECTRE implant loading to obtain a kernel read/write primitive for unlinking EDR notification callbacks. Not a new or in-window disclosure.
- cve Historical, long-patched CVE referenced only as background by a 2026-08-23 entry; not an in-window disclosure and not this run's finding. Telerik UI for ASP.NET AJAX deserialization flaw named by Cisco Talos among UAT-10147's mass-exploitation set.
- cve Dell DBUtil_2_3.sys driver flaw, long patched, recorded only as the second vulnerable driver Cisco Talos observed the SPECTRE implant loading as its kernel read/write primitive. Not a new or in-window disclosure.
- cve Historical, long-patched CVE referenced only as background by a 2026-08-23 entry; not an in-window disclosure and not this run's finding. AjaxPro deserialization flaw named by Cisco Talos among UAT-10147's mass-exploitation set.
- cve Historical, long-patched CVE referenced only as background by a 2026-08-23 entry; not an in-window disclosure and not this run's finding. Local privilege-escalation flaw in the same Windows Defender BTR.sys driver file, disclosed by SentinelLabs and patched by Microsoft in February 2021; referenced as historical background by the BTR Reforged deep dive and unrelated to that technique.
- cve Historical, long-patched CVE referenced only as background by a 2026-08-23 entry; not an in-window disclosure and not this run's finding. Nacos missing-authentication flaw on the Derby management endpoint, named by Cisco Talos among UAT-10147's mass-exploitation set and chained toward script-engine code execution.
- cve Historical, long-patched CVE referenced only as background by a 2026-08-23 entry; not an in-window disclosure and not this run's finding. Zimbra Collaboration Suite flaw Cisco Talos names among the long-public vulnerabilities UAT-10147 mass-exploits for initial access; historically reached unauthenticated code execution when chained with CVE-2022-37042.
- cve Historical, long-patched CVE referenced only as background by a 2026-08-23 entry; not an in-window disclosure and not this run's finding. Zimbra authentication-bypass flaw that historically completed the unauthenticated path alongside CVE-2022-27925; recorded for the chaining nuance the Talos shorthand omits.
- cve Cisco Crosswork applications, SQL injection, CVSS 3.1 10.0; patched, exploitation status unknown (relayed by NCSC-CH 2026-08-21)
- cve Cisco Secure Workload, command/OS injection, CVSS 3.1 9.9; patched, exploitation status unknown (relayed by NCSC-CH 2026-08-21)
- cve Cisco Secure Workload, improper access control, CVSS 3.1 10.0; patched, exploitation status unknown (relayed by NCSC-CH 2026-08-21)
- cve Cisco Secure Workload, improper authentication, CVSS 3.1 10.0; patched, exploitation status unknown (relayed by NCSC-CH 2026-08-21)
- cve Cisco Secure Workload, path traversal, CVSS 3.1 9.6; patched, exploitation status unknown (relayed by NCSC-CH 2026-08-21)
- cve Cisco Crosswork, missing authentication for a critical function, CVSS 3.1 10.0; patched, exploitation status unknown (relayed by NCSC-CH 2026-08-21)
- cve Cisco Crosswork, external control of the file system, CVSS 3.1 10.0; patched, exploitation status unknown (relayed by NCSC-CH 2026-08-21)
- cve Cisco Crosswork, insufficiently protected credentials, CVSS 3.1 9.9; patched, exploitation status unknown (relayed by NCSC-CH 2026-08-21)
- cve Microsoft Entra ID deserialization of untrusted data (CWE-502), CVSS 3.1 base 10.0, a cloud-service CVE already mitigated by Microsoft with no tenant action available. Recorded here for the exploitation-status contradiction: MSRC revision 1.1 of 2026-08-21 corrected the record to not-exploited, while ENISA's EU Vulnerability Database still carried it on the exploited feed when checked on 2026-08-22.
- cve TrueConf Server missing authentication for a critical function on port 4307/TCP; an unauthenticated caller invokes an undocumented function to run a script inside the server's isolated environment. CISA KEV and ENISA EUVD both record exploitation since 2026-08-20; chained with CVE-2026-72530 by Head Mare to reach SYSTEM. Fixed 2026-06-18 in 5.3.9/5.4.9/5.5.5.
- cve TrueConf Server sandbox escape, a flaw in the isolated environment's code-generation logic lets an attacker who already has script execution there run arbitrary OS commands as NT AUTHORITY\SYSTEM. CISA KEV and ENISA EUVD both record exploitation since 2026-08-20. Fixed 2026-06-18 in 5.3.9/5.4.9/5.5.5.
- cve misp-stix STIX-import trust-boundary flaw (CVSS 4.0 6.9); the importer decided whether a document was a trusted internal MISP export from markers the producer controls, then copied a whole attribute dictionary onto imported attributes, letting a crafted bundle set distribution, sharing_group_id and tags. Last affected 2026.7.8; fixed by commits only, no tagged release.
- cve misp-stix denial of service (CVSS 4.0 8.7), parse failures called sys.exit(), raising SystemExit past callers' exception handlers, so one malformed STIX document terminates a long-running importer; no size limit was applied before parsing. Last affected 2026.7.8; fixed by commits only.
- cve misp-stix cross-document parser state contamination (CVSS 4.0 6.3), reused parser instances retained galaxy data, references, titles and timestamps across conversions, so one document's content can appear in the event generated from the next. Last affected 2026.7.8; fixed by commits only.
- malware E4del
- malware PINHOLE
- product PTC FlexPLM×2
- product PTC Windchill×2
- product PTC Windchill PDMLink
- product PTC Windchill Risk and Reliability
- product SPIP
- product TP-Link Omada Gateway DR3150
- product TP-Link Omada Gateway DR3220v-4G
- product TP-Link Omada Gateway DR3650v
- product TP-Link Omada Gateway DR3650v-4G
- product TP-Link Omada Gateway ER603WP-4G-Outdoor
- product TP-Link Omada Gateway ER605
- product TP-Link Omada Gateway ER605W
- product TP-Link Omada Gateway ER701-5G-Outdoor
- product TP-Link Omada Gateway ER703WP-4G-Outdoor
- product TP-Link Omada Gateway ER706W
- product TP-Link Omada Gateway ER706W-4G
- product TP-Link Omada Gateway ER706WP-4G
- product TP-Link Omada Gateway ER707-M2
- product TP-Link Omada Gateway ER7206
- product TP-Link Omada Gateway ER7212PC
- product TP-Link Omada Gateway ER7406
- product TP-Link Omada Gateway ER7412-M2
- product TP-Link Omada Gateway ER8411
- product Zoom Meeting SDK
- product Zoom Rooms
- product Zoom Video SDK
- product Zoom Workplace
- product Zoom Workplace VDI Client for Windows
- cve TP-Link Omada gateways, pre-authentication OS command injection in the OpenVPN server; fixed per hardware revision in the vendor firmware table
- cve TP-Link Omada gateways, second flaw in the August 2026 Omada advisory
- cve Cisco Crosswork / Secure Workload, the ninth CVE of the August 2026 hardening set, absent from the W34 weekly rollup enumeration
- cve Zoom, one of three August 2026 client flaws; lower patch floor than CVE-2026-53415
- cve Zoom, one of three August 2026 client flaws; lower patch floor than CVE-2026-53415
- cve Zoom, requires a HIGHER fixed version than its two siblings; patching to the obvious floor leaves it open
- cve PTC Windchill, one of three new August 2026 CVEs, all PR:N, no obtainable fixed version for two of them
- cve PTC Windchill, one of three new August 2026 CVEs, all PR:N
- cve PTC Windchill PDMLink, one of three new August 2026 CVEs, all PR:N
- cve TP-Link Omada gateways, third flaw in the August 2026 Omada advisory
- product ATutor
- cve Thirteen CVEs in ATutor, none of which will ever be fixed, including an unauthenticated auto-login token forgery that authenticates as any account, a
- cve Thirteen CVEs in ATutor, none of which will ever be fixed, including an unauthenticated auto-login token forgery that authenticates as any account, a
- cve Thirteen CVEs in ATutor, none of which will ever be fixed, including an unauthenticated auto-login token forgery that authenticates as any account, a
- cve Thirteen CVEs in ATutor, none of which will ever be fixed, including an unauthenticated auto-login token forgery that authenticates as any account, a
- cve Thirteen CVEs in ATutor, none of which will ever be fixed, including an unauthenticated auto-login token forgery that authenticates as any account, a
- cve Thirteen CVEs in ATutor, none of which will ever be fixed, including an unauthenticated auto-login token forgery that authenticates as any account, a
- cve Thirteen CVEs in ATutor, none of which will ever be fixed, including an unauthenticated auto-login token forgery that authenticates as any account, a
- cve Thirteen CVEs in ATutor, none of which will ever be fixed, including an unauthenticated auto-login token forgery that authenticates as any account, a
- cve Thirteen CVEs in ATutor, none of which will ever be fixed, including an unauthenticated auto-login token forgery that authenticates as any account, a
- cve Thirteen CVEs in ATutor, none of which will ever be fixed, including an unauthenticated auto-login token forgery that authenticates as any account, a
- cve Thirteen CVEs in ATutor, none of which will ever be fixed, including an unauthenticated auto-login token forgery that authenticates as any account, a
- cve Thirteen CVEs in ATutor, none of which will ever be fixed, including an unauthenticated auto-login token forgery that authenticates as any account, a
- cve Thirteen CVEs in ATutor, none of which will ever be fixed, including an unauthenticated auto-login token forgery that authenticates as any account, a
- cve Microsoft Defender / Malware Protection Engine elevation of privilege, publicly referred to as ShieldBreak, Microsoft's identifier for the proof-of-concept claiming a bypass of the July fix for CVE-2026-50656. Important, CVSS 3.1 base 7.8, publicly disclosed, exploitation not detected, assessed 'Exploitation More Likely'; no update available at publication.
- actor DragonForce×4
- actor Mabna Institute
- actor Panzer
- actor Ransom Busters
- actor Settra
- actor Anubis (ransomware-as-a-service)
- malware Grandoreiro×2
- incident Latvia CSDD payment-receipt data breach (2026)
- incident Castilla-La Mancha regional government cyberattack (2026)
- product Citrix NetScaler×4
- product MLflow
- product Oracle E-Business Suite×2
- product Oracle Hyperion Data Relationship Management
- product Siemens SIMATIC S7-1200×3
- product Siemens SIMATIC S7-1500×2
- product Siemens SIMATIC S7-200
- product Siemens SIMATIC S7-300×2
- product Siemens SIMATIC S7-400
- cve Oracle WebLogic Server (Core), unauthenticated flaw over T3 and IIOP, CVSS 9.8; August 2026 Critical Security Patch Update.
- cve Oracle E-Business Suite, Oracle Payments (File Transmission), unauthenticated flaw over HTTP, CVSS 9.8, EBS 12.2.3-12.2.15; August 2026 Critical Security Patch Update.
- cve Oracle Internet Directory (OID LDAP Server), unauthenticated flaw over LDAP, CVSS 3.1 base 10.0, scope changed; August 2026 Critical Security Patch Update.
- cve MLflow, unauthenticated full-read SSRF in webhook delivery; the URL guard validates the resolved address but never pins it, and delivery follows redirects unvalidated. CISA KEV 2026-08-19; fixed in 3.15.0.
- cve Oracle Hyperion Data Relationship Management (Access and security), unauthenticated flaw over TCP, CVSS 3.1 base 10.0; August 2026 Critical Security Patch Update.
- cve Oracle Hyperion Financial Management (Security), unauthenticated flaw over TLS, CVSS 3.1 base 10.0; August 2026 Critical Security Patch Update.
- cve Oracle E-Business Suite, Oracle Workflow (Workflow Notification Mailer), unauthenticated flaw over SMTP, CVSS 9.8, EBS 12.2.3-12.2.15; August 2026 Critical Security Patch Update.
- cve Zimbra Collaboration, pre-authentication command injection in SNMP notification processing reaching OS command execution as the Zimbra user; fixed in 10.1.20 (21 July 2026), CVE published 13 August, ENISA records exploitation from 2026-08-18.
- campaign StopAndProtect
- malware SilentEncryptor
- product Cozmoslabs User Profile Builder
- product Red Hat Build of Keycloak×2
- product Red Hat JBoss Enterprise Application Platform Expansion Pack
- product WPMU DEV Forminator Forms
- cve Accellion FTA SQL injection, referenced by the 2026-08-19 Cl0p Windchill implant entry solely as campaign lineage: the flaw Cl0p exploited before deploying its DEWMODE web shell. Long patched; recorded for provenance of that historical reference, not as in-window coverage.
- cve Progress MOVEit Transfer SQL injection, referenced by the 2026-08-19 Cl0p Windchill implant entry solely as campaign lineage: the flaw Cl0p exploited before deploying its LEMURLOOT web shell. Long patched; recorded for provenance of that historical reference, not as in-window coverage.
- cve PTC Windchill / FlexPLM, pre-auth deserialization RCE, CISA KEV-listed, now driving a Cl0p-attributed mass data-theft extortion campaign
- cve Keycloak, FGAP v2 role groups endpoint discloses hidden group metadata without group view permission. Named here only as one of the five flaws closed by RHSA-2026:56523 (Red Hat build of Keycloak 26.6.6, 2026-08-18) alongside CVE-2026-18963; recorded so the 26.4 and 26.6 upgrade decisions are comparable, and not otherwise assessed by this store.
- cve Keycloak, predictable account-linking hash enables account takeover via a malicious OIDC client. Closed by RHSA-2026:56523 (Red Hat build of Keycloak 26.6.6, 2026-08-18); Red Hat records a public date of 2026-08-18. A second account-takeover path on the same identity surface as CVE-2026-18963 and one reason the 26.6.6 upgrade is not equivalent to 26.4.15.
- cve WPMU DEV Forminator Forms (WordPress, 600,000+ installs), unauthenticated arbitrary file upload to remote code execution in handle_file_upload: the dangerous-extension blocklist matches MIME-type keys exactly and is bypassed by a pipe-alternative key, while a forged Select-field value overrides the upload field's own type configuration. CVSS 9.8, Wordfence as CNA. Exploitable only on forms carrying both a File Upload and a Select field. Fixed in 1.56.2 (2026-07-31); root-cause write-up published 2026-08-17, relayed by NCSC-CH 2026-08-18. No exploitation reported.
- cve Cozmoslabs User Profile Builder (WordPress, 40,000+ installs), unauthenticated authentication bypass via type confusion: wppb_log_in_user() calls absint() on the return value of wp_insert_user() before the is_wp_error() check, so a 61-70 character username makes core return a WP_Error that coerces to the integer 1 and the plugin issues an autologin bound to user ID 1. CVSS 9.8, Wordfence as CNA. Exploitable only where the plugin's Automatically Log In setting is enabled. Fixed in 3.16.5 (2026-07-16); write-up 2026-08-14, relayed by NCSC-CH 2026-08-18. No exploitation reported.
- cve Keycloak, vault-resolved rotated client secrets leaked via the Admin REST API. Closed by RHSA-2026:56523 (Red Hat build of Keycloak 26.6.6, 2026-08-18); a credential-disclosure flaw on the component that fronts single sign-on, recorded alongside CVE-2026-18963 for upgrade comparability.
- cve GitLab CE/EE, cross-site request forgery in the GraphQL multiplex query handler allowing mutations to be executed via GET requests through improper request validation (CVSS 7.1, vendor-assigned). Fixed in the same 2026-08-17 out-of-band release as CVE-2026-19478.
- cve Windows IKE Extensions (IKE VPN), Unit 42 records reverse-shell callbacks from three endpoints in the autonomous-AI intrusion campaign
- cve Microsoft SharePoint Server security-feature bypass (CWE-1390 weak authentication), CVSS 9.1, four-weakness JWT forgery chain published with proof-of-concept; exploitation attempts observed against honeypots 2026-08-12
- cve Metabase unauthenticated SQL injection via the /api/session/reset_password endpoint reaching administrator access, CVSS 10.0; the identifier assigned in GHSA-vwf4-m7j8-wcjf for the zero-day Metabase confirmed was already being exploited, CISA KEV 2026-08-11.
- cve Keycloak, privilege escalation via a time-of-check-to-time-of-use race. Closed by RHSA-2026:56523 (Red Hat build of Keycloak 26.6.6, 2026-08-18); recorded as one of the five flaws in that erratum, not otherwise assessed by this store.
- incident Zurich District Court LockerGoga / MegaCortex / Nefilim ransomware trial (2026)
- malware LockerGoga
- malware MegaCortex
- malware Nefilim
- incident Arbeiterkammer Oberösterreich cyberattack (2026)
- product Ray
- cve GeoTools/GeoServer OGC filter SQL injection fixed in 2023. Referenced by the 2026-08-18 GeoServer entry as the flaw the jsonArrayContains injection regresses: GeoTools states the mitigation published for this CVE (enabling prepared statements and disabling encode functions) is not effective against the 2026 variant, so operators who applied it are not protected.
- cve Ray dashboard code injection, unauthenticated job-submission endpoints guarded only by a User-Agent string check, bypassable from Firefox and Safari via fetch() combined with DNS rebinding, reaching code execution on the host running Ray. Fixed in Ray 2.52.0; CISA KEV-listed 2026-08-17.
- actor Akira×14
- actor APT36×2
- malware PATCHCORD
- malware SHEETCORD
- malware HACKERAI C2 Agent
- product SonicWall SSL VPN
- actor Jewelbug
- tool XG-Web
- malware Antino
- malware PDF Viewer (Jewelbug browser extension)
- malware ClientKing
- tool Evooo1Bot
- product Alcatel-Lucent OmniPCX Enterprise Communication Server
- product Atlassian Confluence
- product D-Link DIR-823X
- product Hikvision IP cameras
- product Kubernetes ingress-nginx Controller
- product Mitsubishi Electric ME-RTU
- product Mozilla Firefox×3
- product NETGEAR routers
- product Tenda AC10
- product TP-Link Archer AX21
- product WSO2 products
- product Zyxel firewalls
- cve UPDATE, water-sector PLC lockout status: an OT vendor's decade retrospective attributes the Minnesota controller intrusions to a CVE whose own record
- cve Atlassian Confluence Server and Data Center OGNL injection reaching unauthenticated remote code execution, fixed by Atlassian in June 2022. Referenced by the 2026-08-16 Evooo1Bot entry as one of three enterprise-class exploit modules carried by that Mirai-derived botnet; the flaw itself is long patched; the delta is that it is now in commodity automated scanning.
- cve WSO2 API Manager, Identity Server and Enterprise Integrator unrestricted file upload reaching remote code execution via the /fileupload endpoint, fixed by WSO2 in April 2022. Referenced by the 2026-08-16 Evooo1Bot entry as an enterprise exploit module in that botnet's arsenal.
- cve PHP-CGI argument injection on Windows deployments. Referenced by the 2026-08-16 Evooo1Bot entry as an exploit module carried by that botnet.
- cve Kubernetes ingress-nginx admission-controller remote code execution, disclosed March 2025 and fixed in ingress-nginx 1.12.1 and 1.11.5. Referenced by the 2026-08-16 Evooo1Bot entry as the most recent of three enterprise-class exploit modules in that botnet's arsenal.
- cve Haiwell IoT Cloud HMI Gateway, unauthenticated OS command injection as root via the Net Check cmdPing diagnostic (CVSS 10.0); fixed in Scada-v3.50.1.19
- cve Cisco Secure Firewall ASA/FTD Remote Access SSL VPN, insufficient error checking on HTTP request processing lets an unauthenticated attacker reload the device (denial of service), CVSS 8.6, no workaround; Cisco PSIRT confirmed active exploitation and CISA KEV-listed it 2026-08-11 with a 14 August due date.
- cve UPDATE; the fourth passkey attack thread this pipeline could not source last week is now documented, and it closed: Windows cached YubiKey assertions
- cve Microsoft SharePoint Server CWE-502 deserialization RCE, authenticated Site Member (PR:L); CISA KEV since 2026-07-01 and flagged for known ransomware campaign use as of catalog version 2026.08.11
- cve Microsoft Defender Malware Protection Engine 'RoguePlanet' link-following LPE to SYSTEM - now fixed (engine >=1.1.26060.3008); NCSC-CH Nightmare Eclipse tracker×3
- cve Siemens SIMATIC IoT2050 Advanced, unauthenticated Node-RED HTTP interface allows remote code execution with maximum privileges (CVSS 10.0), fixed in V4.3.4.1
- cve Apple macOS Screen Sharing (screensharingd) pre-authentication improper authentication, CVSS 7.1, fixed in macOS Tahoe 26.6.1, Sequoia 15.7.9 and Sonoma 14.8.9. NCSC-NL advisory NCSC-2026-0280 revision 1.0.1 (2026-08-12) records active abuse observed on multiple systems with port 5900 reachable from the internet, root access obtained in all of them and a Monero cryptocurrency miner planted.
- cve Adobe Commerce / Adobe Commerce B2B / Magento Open Source, incorrect authorization (CWE-863), CVSS 3.1 9.1, unauthenticated customer account takeover by switching a customer session to another customer's account; no authentication, no admin privileges and no user interaction required. Fixed in the -2026-aug isolated patch files of APSB26-92 (2026-08-11). Adobe states it is not aware of exploits in the wild; Sansec reports its Shield WAF already blocking exploitation attempts.
- campaign Outsider PhaaS×2
- actor Gunra×2
- incident NHS Blood and Transplant unencrypted pager exposure
- incident Threema / Nine DDoS campaign (August 2026)
- actor Mustang Panda×3
- malware CoolClient
- malware ToneShell
- tool JWR
- incident Bloctel telemarketing opt-out registry breach (France, 2026)
- malware Claimloader
- malware Havencode
- actor Epsilon
- malware WaveStealer
- product Aqua Security Trivy
- product Fortinet FortiClient
- product Fortinet FortiManager
- product Fortinet FortiManager Cloud
- product Fortinet FortiWeb
- product GeoTools
- product Haiwell IoT Cloud HMI Gateway
- product LiteLLM×3
- product Threema
- cve Fortinet FortiWeb, improper authentication lets an unauthenticated attacker log into the GUI/CLI with any username and password when the non-default RADIUS admin Wildcard option is enabled
- cve Fortinet FortiClient for Windows, buffer copy without size check lets an unauthenticated attacker able to alter or craft DNS responses execute arbitrary code (CVSS 8.1); fixed in 7.4.4 / 7.2.12
- cve Fortinet FortiWeb, incomplete list of disallowed inputs allows an unauthenticated attacker to bypass WAF policies; fixed in 8.0.3 / 7.6.6, with no fixed build for the 7.4 and 7.2 branches
- cve Fortinet FortiManager / FortiManager Cloud, FGFM authentication bypass letting a holder of a valid certificate impersonate any managed FortiGate when fgfm-peercert-withoutsn is set
- cve Flowise before 3.1.3, regex-based Python code-validator bypass in CSV and Airtable Agent nodes reachable by prompt injection through the unauthenticated prediction API
- incident MyDr electronic health record platform breach (Poland, 2026)
- incident ACRO Criminal Records Office website and CMS compromise (2022-2023)
- malware WindRelay
- malware SpyNote
- product Siemens SIMATIC IoT2050 Advanced
- trend RoguePlanet×5
- trend LegacyHive×2
- actor Lazarus Group×4
- tool FudModule
- malware MISTPEN
- malware ForestTiger
- tool RelayShell
- trend ShieldBreak
- incident Stiftung Brandenburgische Gedenkstätten ransomware attack (August 2026)
- product Cisco Secure Firewall Adaptive Security Appliance (ASA)
- product Cisco Secure Firewall Threat Defense (FTD)
- product Microsoft Malware Protection Engine
- product Roundcube Webmail×3
- product SAP ABAP Developer Tools
- product SAP Commerce Cloud×2
- product SAP Manufacturing Integration and Intelligence
- cve Windows Ancillary Function Driver for WinSock use-after-free, patched August 2024 and reported at the time as exploited by FudModule. Referenced as prior-art context by the 2026-08-12 Lazarus entry: the same driver family has now yielded a second FudModule privilege-escalation zero-day.
- cve Use-after-free in the Windows AFD.sys driver fixed in November 2025 and not linked to any particular threat actor. Referenced by the 2026-08-12 Lazarus entry: Check Point states the 2026 exploit initially resembled it but testing on a fully patched system confirmed a distinct, previously undocumented vulnerability.
- cve N-able N-central, authentication bypass using an alternate path or channel (CWE-288), affects through 2026.1, fixed in 2026.2 (CVSS 8.2) | CISA KEV 2026-08-04.
- cve N-able N-central, incomplete patch for CVE-2026-18556; unauthenticated admin auth bypass exploited in the wild, superseded by Hotfix 2 build 2026.3.1.10 of 2026-08-06, which the vendor requires even where 2026.3.1.7 was applied (CVSS 8.2)
- cve Windows User Profile Service improper link resolution before file access, local elevation of privilege, CVSS 7.8, publicly disclosed before the fix and rated Exploitation More Likely; patched 2026-08-11. Rapid7 assesses the advisory is a solid match for the LegacyHive proof-of-concept.
- cve Microsoft SharePoint Server remote code execution (CWE-20 improper input validation), CVSS 8.1, patched 2026-08-11. Rapid7, which discovered it, states it is the second of a pair that chain into a critical unauthenticated RCE against a vulnerable SharePoint server.
- incident CEVA Logistics European fulfilment-systems breach (August 2026)
- product Fortinet FortiProxy
- product Nitro Software Belgium Connective Signing Extension
- cve Fortinet FortiOS / FortiProxy authentication bypass (CWE-288), named by joint advisory AA26-222A as a primary Gunra ransomware initial-access vector, abused to create a persistent super-user account on the appliance
- cve Fortinet FortiOS / FortiProxy authentication bypass (CWE-288), named by joint advisory AA26-222A as a primary Gunra ransomware initial-access vector, abused to create a persistent super-user account on the appliance
- trend claude-code-action bot-actor bypass
- actor Scattered Spider×4
- actor Interlock×2
- malware NodeSnake
- campaign PAM-impersonation Monero-mining campaign
- report Intrinsec AI Agents X Digital Forensics series
- actor UNC5537
- actor Cameron Wagenius
- incident Zabka supplier-account ticketing-system intrusion
- trend NatJack
- trend Coding-agent CI harness trust-boundary failures
- incident Retelit / Qilin extortion attack
- product FreeBSD
- product Linux kernel netfilter
- product Microsoft Hyper-V
- product Microsoft Windows NAT
- product OpenAI Codex CLI×2
- product OpenCode
- product TrueNAS Enterprise
- product VMware ESXi×4
- product Wazuh
- product Wazuh manager
- cve Rockwell Automation Allen-Bradley MicroLogix 1400 Series B/C firmware 21.002 and earlier; stack-based buffer overflow that may allow remote code execution. Referenced as a firmware-currency signal on internet-exposed controllers in already-attacked water-utility cities; Forescout states exploitation would require Modbus TCP enabled, which was not confirmed, and that no CVE is confirmed as exploited in that campaign.
- cve Wazuh cluster protocol privilege escalation to root via file write, fixed in 4.14.3 by the _ALLOWED_PREFIXES hardening. Referenced as the earlier fix that CVE-2026-49441 and CVE-2026-48024 both bypass through sibling code paths.
- cve Copy Fail, Linux kernel algif_aead local privilege escalation (ITW, KEV)
- cve Wazuh distributed API, deserialization RCE as root via unallowlisted builtin resolution when a request fans out across two or more nodes (CVSS 8.4); fixed 4.14.6
- cve Wazuh wazuh-authd, pre-authentication stack buffer overflow reachable on TCP/1515 under the shipped anonymous-SSL default (CVSS 7.5); fixed 4.14.6
- cve Wazuh cluster protocol, sibling arbitrary-file-write-to-root path via peer-controlled merged-file header traversal (CVSS 9.1); fixed 4.14.6
- cve Wazuh cluster protocol, arbitrary file write to root RCE on the master file-receive path, bypassing the CVE-2026-25770 fix (CVSS 9.1); fixed 4.14.6
- cve NatJack, Windows NAT origin-validation error allowing downstream-spoofing TCP session hijack, affecting Hyper-V; fixed in the July 2026 security update
- cve NatJack; Linux netfilter TCP conntrack state machine forced to CLOSE by an RST with an invalid sequence number, enabling downstream-spoofing TCP session hijack; fixed in 7.1 and stable/LTS backports
- cve WordPress Core XSS2Shell, pre-auth login-screen reflected XSS chaining via DOM clobbering and a JSONP callback to Application-Password minting and plugin upload (CVSS 4.0 8.9); fixed 7.0.3 with backports to 4.7.34
- cve Ruby on Rails Active Storage variant processing on libvips, unauthenticated arbitrary file read (and possible RCE via exposed application secrets) from an untrusted image upload; CVSS 4.0 9.5 assigned by GitHub Security Advisories as the Rails CNA; fixed in activestorage 7.2.3.2 / 8.0.5.1 / 8.1.3.1 and requires libvips >= 8.13 to be effective
- incident Metabase unauthenticated SQL-injection zero-day exploitation (August 2026)
- product crypto-js
- product Fortinet FortiGate
- product Metabase Cloud
- product Teltonika RUTX50
- product Tobit Laboratories AG TeamDavid
- product WAGO PFC200
- product WALLIX Access Manager
- product WALLIX Bastion
- cve Tobit TeamDavid Webbox, authenticated arbitrary file deletion via @@COMMENTFILE
- cve Tobit TeamDavid Webbox, open redirect via URL-encoded manipulation of the 302 redirect domain
- cve Thermo Fisher Applied Biosystems genetic analyzers, result files written without integrity checking; CORRECTED 2026-08-09: patched software exists for five product lines (4.0.3 / 5.0.3 / 1.2.6 / 1.2.1 / 1.7.4), three EoL lines unfixed
- cve KerberLoss, Active Directory Domain Services SPN uniqueness bypass via unfilterable Unicode, enabling Kerberos ticket mis-encryption and NTLM downgrade
- cve Progress ShareFile Storage Zone Controller, pre-auth authentication bypass, exploited in the wild from 2026-07-10 (Shadowserver); NEVER CISA KEV-listed (verified against catalogVersion 2026.08.07)
- cve Progress ShareFile Storage Zone Controller, chained storage-repointing RCE, exploited alongside CVE-2026-2699; NEVER CISA KEV-listed (verified against catalogVersion 2026.08.07)
- cve ResetNightmare, Windows Kerberos password-change flow accepts a UPN-borrowed identity, taking a low-privileged user to Domain Admin
- cve Tobit TeamDavid Webbox, HTTP header injection in the link-storing function via request body
- cve Tobit TeamDavid Webbox, authenticated local file inclusion via @@attach with NTFS ADS filter bypass
- cve Tobit TeamDavid Webbox, error log files served without authentication or authorisation
- cve Tobit TeamDavid Webbox, authenticated path traversal in archive creation
- cve Tobit TeamDavid Webbox, unauthenticated uninitialised-heap disclosure via /.well-known/mta-sts. leaking stored credentials
- cve Tobit TeamDavid Webbox, unauthenticated SSRF via UNC path in the search pathnameroot parameter
- cve Tobit TeamDavid Webbox, authenticated SSRF via UNC path in the link-storing pathname parameter
- cve Tobit TeamDavid Webbox, authenticated SSRF via UNC path in the @@INCLUDE messaging command
- cve Tobit TeamDavid Webbox, authenticated SSRF via UNC path in the !ArcEntryMove archive-move function
- cve Tobit TeamDavid Webbox, unauthenticated arbitrary file write reaching stored XSS
- cve Tobit TeamDavid Webbox, unauthenticated buffer overflow via (editini) arbitrary-path read into a fixed stack buffer
- cve Tobit TeamDavid Webbox, unauthenticated buffer overflow via overlong upload filename
- cve Tobit TeamDavid Webbox, authenticated buffer overflow in serverClient_close.html form parameters
- cve Tobit TeamDavid Webbox, unauthenticated buffer overflow via crafted API request body
- cve Tobit TeamDavid Webbox, unauthenticated single-request denial of service via /internalRestart
- cve Tobit TeamDavid Webbox, HTTP header injection via the cType parameter (Content-Type control)
- cve Tobit TeamDavid Webbox, open redirect via the replyUrl parameter
- cve Tobit TeamDavid Webbox, reflected cross-site scripting via !templateName/EntryInfo
- cve Tobit TeamDavid Webbox, stored cross-site scripting via email content
- cve Tobit TeamDavid Webbox, reversible (XOR-obfuscated) storage of user passwords in access.ini
- cve crypto-js < 4.0.0, CryptoJS.lib.WordArray.random() is not a CSPRNG; ~2^39/2^47 effective entropy, actively exploited to drain wallets (Coinspect 'Ill Bloom')
- actor JINX-0163
- report Wiz Cloud Threat Highlights: H1 2026
- campaign ScreenConnect app-store-themed fake-update distribution campaign
- incident Beacon CRM access-key breach affecting around 1,500 UK charities
- incident Digitaal Vlaanderen compromise disclosed in the Stykas North Korea victim-set research
- product Apple macOS×5
- product ATN-B1 CPDLC (Advisory Circular 90-117 Data Link Communications)
- product Beacon CRM
- product Cloudflare Code Mode
- product Cloudflare Workers
- product Dify
- product Flowise
- product FlowiseAI Flowise
- product Ollama
- product workerd
- cve CPDLC over ATN-B1, missing authentication for VHF Data Link messages allows rogue ground stations to inject clearances (CVSS 7.1); no mitigation available
- cve CPDLC over ATN-B1, Unnumbered Disconnect and malformed link-control frames terminate CPDLC sessions (CVSS 5.3); no mitigation available
- cve CPDLC over ATN-B1, broadcast control frames disconnect multiple aircraft simultaneously (CVSS 5.3); no mitigation available
- cve CPDLC over ATN-B1, injection of false emergency or status messages (CVSS 7.1); no mitigation available
- cve CPDLC over ATN-B1, malformed or out-of-sequence X.25-layer frames cause repeated resets (CVSS 5.3); no mitigation available
- cve Cisco IOS XE August 2026 hardening release, improper access control CWE grouping (CVSS 9.0); fixed 17.9.10/17.12.8/17.15.6/17.18.4/26.1.2
- cve Cisco IOS XE August 2026 hardening release, memory-buffer bounds CWE grouping (CVSS 8.6)
- cve Cisco IOS XE August 2026 hardening release, resource lifetime CWE grouping (CVSS 8.6)
- cve Cisco IOS XE August 2026 hardening release, incorrect calculation CWE grouping (CVSS 8.6)
- cve Cisco IOS XE August 2026 hardening release, control-flow management CWE grouping (CVSS 8.6)
- cve Cisco IOS XE August 2026 hardening release, command/OS/argument injection CWE grouping (CVSS 9.8), highest of the batch; no workaround
- cve Cisco IOS XE August 2026 hardening release, input validation / path traversal CWE grouping (CVSS 8.6)
- cve Flowise, earlier authentication bypass on the OAuth2 credential-refresh route; the fix was incomplete and is bypassed by CVE-2026-70636
- cve Linux KVM/x86 'Januscape' shadow-MMU use-after-free, guest-to-host VM escape on Intel and AMD (public PoC host-DoS; RCE withheld); fixed 6.1.177/6.6.144/6.12.95/6.18.38/7.1.3
- cve WordPress core WP_Query author__not_in SQL injection (WP2Shell chain component)
- cve WP2Shell: WordPress core REST batch route confusion to pre-auth RCE chain
- cve Linux KVM/x86 'Zapscape'; use-after-free in the recursive shadow-MMU zap path gives guest-root-to-host escape (CVSS 8.8); needs nested virtualization, and on Intel EPT page-walk lengths 4 and 5 exposed to L1; fixed upstream 2abd5287f083
- cve Flowise ≤3.1.4, missing authorization on document-store mutation endpoints lets a view-only member drive ingestion (CVSS 4.0 7.2, CWE-862); no fix, vendor sunsetting
- cve Flowise ≤3.1.4; IDOR in the OpenAI Assistants integration gives cross-workspace credential access (CVSS 4.0 8.5, CWE-639); no fix, vendor sunsetting
- cve Flowise ≤3.1.4, unauthenticated OAuth2 credential-refresh endpoint reachable via prefix-whitelist bypass (CVSS 4.0 8.7, CWE-862); bypass of CVE-2026-41273; no fix, vendor sunsetting
- cve Progress Kemp LoadMaster pre-auth command injection, added to CISA KEV 2026-08-07 on evidence of active exploitation; fixed GA 7.2.63.2 / LTSF 7.2.54.18
- campaign ClickFix macOS expansion
- campaign Flooding Dropper
- campaign UNK_DeadDrop×2
- incident Meta AI cybersecurity-evaluation containment breach (August 2026)×2
- trend Adobe ColdFusion/Campaign APSB26-68/69×2
- actor Helix×2
- tool Overlord×2
- malware MacSync×2
- product npm×3
- product Okta×2
- cve Keycloak; Dynamic Client Registration 'Allowed Protocol Mapper Types' policy does not re-validate mapper type on update, allowing a type-swap to an admin-role-hardcoding mapper and full realm admin; CVSS 8.8, fixed in 26.4.14 / 26.6.5 / 26.7.1
- cve Keycloak; Authorization Services PathMatcher does not normalize URIs, so a trailing slash or matrix parameter selects a less restrictive policy and an authenticated user reaches restricted paths; CVSS 8.1, fixed in 26.4.14 / 26.6.5 / 26.7.1
- cve Keycloak, LDAP entry-DN user search escapes the configured users-DN boundary, disclosing and importing directory entries from outside the intended scope; CVSS 5.4, fixed in 26.4.14 / 26.6.5 / 26.7.1
- cve Keycloak, user-event metrics record request-controlled error text as Prometheus labels, giving an authenticated user an unbounded-cardinality memory-exhaustion DoS; CVSS 6.5, fixed in 26.4.14 / 26.6.5 / 26.7.1
- cve Keycloak, default Dynamic Client Registration policy mis-validates the claim path for User Property mappers, letting a standard account with a limited Initial Access Token forge administrative roles and reach full realm control; CVSS 8.1, fixed in 26.4.14 / 26.6.5 / 26.7.1
- cve Keycloak; SAML IdP-initiated SSO endpoint does not check the link-only restriction, so an attacker controlling a linked upstream identity gains full access to the local account; CVSS 7.4, fixed in 26.4.14 / 26.6.5 / 26.7.1
- cve Keycloak / Red Hat Build of Keycloak, SAML broker metadata import without key-usage attributes disables response signature validation, letting an unauthenticated attacker forge a SAML response and log in as any user whose external identifier is known; CVSS 7.4, fixed in 26.4.14 / 26.6.5 / 26.7.1
- cve Adobe Campaign Classic (on-premise), authenticated eval injection (CWE-95) reaching arbitrary code execution, CVSS 9.6; APSB26-120, fixed in ACC v7 7.4.3 build 9399
- cve Adobe Campaign Classic (on-premise), unauthenticated template-engine injection (CWE-1336) reaching arbitrary code execution, CVSS 10.0, scope changed; APSB26-120, fixed in ACC v7 7.4.3 build 9399
- cve Adobe Campaign Classic (on-premise), authenticated SQL injection (CWE-89) reaching arbitrary code execution, CVSS 9.9; APSB26-120, fixed in ACC v7 7.4.3 build 9399
- cve Adobe Campaign Classic (on-premise), unauthenticated SQL injection (CWE-89) reaching arbitrary code execution, CVSS 10.0, scope changed; APSB26-120, fixed in ACC v7 7.4.3 build 9399
- cve Adobe Campaign Classic (on-premise), unauthenticated SSRF (CWE-918) reaching arbitrary code execution, CVSS 10.0, scope changed; APSB26-120, fixed in ACC v7 7.4.3 build 9399
- cve Adobe Campaign Classic (on-premise), unauthenticated incorrect authorization (CWE-863) giving privilege escalation, CVSS 9.8; APSB26-120, fixed in ACC v7 7.4.3 build 9399
- cve Adobe Campaign Classic (on-premise), violation of secure design principles (CWE-657) giving a security-feature bypass, CVSS 7.5; APSB26-120, fixed in ACC v7 7.4.3 build 9399
- incident BIT/FOITT SharePoint Server breach (Switzerland, 2026-07)×3
- incident Canton Graubünden SharePoint Server breach (Switzerland, 2026-08)×2
- campaign Shai-Hulud CHAINDROP wave
- tool ENDLESSDOORS
- tool DARKLANTERN
- tool SPEAKINGSTONE
- product ALLNET ALL-WR1200AC-WRT (ZBT WG2626 OEM, rebrand lineage match, implant presence unconfirmed)
- product cPanel & WHM
- product Digineo AC1200 Pro (ZBT WG3526 OEM, rebrand lineage match, implant presence unconfirmed)
- product HPE Aruba Networking SD-WAN Orchestrator
- product OneX RV WIFI Route (ZBT-WE826 rebrand lineage match, implant presence unconfirmed)
- product Veeam ONE
- product Veeam Service Provider Console
- product WiFlyer WG3526 (ZBT WG3526 OEM)
- product WP Squared
- product ZBT-WE826-T2 and rebrands (Deep Orange)
- product Zbtlink CPE2801
- product Zbtlink WE1026-5G-WD
- product Zbtlink WE1326
- product Zbtlink WE2007
- product Zbtlink WE2008-DSIM
- product Zbtlink WE2416
- product Zbtlink WE3326
- product Zbtlink WE5927
- product Zbtlink WE5931
- product Zbtlink WE5931AC
- product Zbtlink WE826-T3-DSIM
- product Zbtlink WG108
- product Zbtlink WG1602
- product Zbtlink WG1608-DSIM
- product Zbtlink WG209
- product Zbtlink WG2105
- product Zbtlink WG2107
- product Zbtlink WG259
- product Zbtlink WG3526
- product Zbtlink Z8102AX-2DSIM
- cve cPanel & WHM, HTTP request smuggling in cpsrvd allowing an unauthenticated attacker to manipulate responses delivered to other users on the same server (CVSS v4.0 5.6); interim mitigation disables cpsrvd backend connection reuse
- cve cPanel & WHM, SQL mode not preserved when renaming a database, so an authenticated account holder with the MySQL/MariaDB feature executes SQL in root context (CVSS v4.0 9.4, HackerOne CNA); fixed across the 11.110–11.136 build lines and WP Squared 138.1.6
- cve Veeam Service Provider Console, unauthenticated host-memory exhaustion denial of service (CVSS v4.0 8.7); fixed in 9.3.0.35057
- cve Veeam Service Provider Console, unauthenticated access to the proxied appliance API as Portal Administrator during a window after an admin session begins (CVSS v4.0 8.2); fixed in 9.3.0.35057
- cve Veeam Service Provider Console, arbitrary file write on the management server leading to remote code execution (CVSS v4.0 9.0); fixed in 9.3.0.35057
- cve Veeam Service Provider Console, unauthenticated attacker impersonates a managed agent and obtains its credentials (CVSS v4.0 9.5, high attack complexity); fixed in SPC 9.3.0.35057
- cve Veeam ONE, arbitrary code execution on the server by a high-privileged user (CVSS v4.0 8.6); fixed in 13.1.0.7034
- cve Veeam ONE, unauthenticated arbitrary file read from the host, leveragable to local privilege escalation (CVSS v4.0 8.7); fixed in 13.1.0.7034
- cve HPE Aruba Networking SD-WAN Orchestrator, REST API authentication bypass via spoofed HTTP headers (CVSS v3.1 9.8), 9.6.x branch only; fixed in 9.6.2.40210 / 9.6.3.40140 / 9.7.0.43264
- cve HPE Aruba Networking SD-WAN Orchestrator, second REST API authentication bypass via spoofed HTTP headers (CVSS v3.1 9.8), 9.6.x branch only; fixed in 9.6.2.40210 / 9.6.3.40140 / 9.7.0.43264
- cve Veeam ONE; low-privileged retrieval of report data outside a shared link's scope (CVSS v4.0 5.3); fixed in 13.1.0.7034
- cve Veeam ONE, SQL injection by a low-privileged user extracting database contents (CVSS v4.0 8.6); fixed in 13.1.0.7034
- cve Veeam ONE, unauthenticated remote code execution on the agent host (CVSS v4.0 10.0); fixed in Veeam ONE 13.1.0.7034
- cve Veeam ONE, local privilege escalation into the Reporter service context (CVSS v4.0 8.4); fixed in 13.1.0.7034
- cve Zbtlink routers/CPE, ENDLESSDOORS, a factory-installed unauthenticated root-command backdoor started by the vendor's own init script across 20+ models; no fix, VulnCheck advises device replacement
- actor ByteToBreach×2
- incident ANCPI Romania cadastre cyberattack×2
- incident Anthropic cybersecurity-evaluation environment escape (July 2026)×3
- incident Hungarian State Treasury (MVH) breach
- incident RUAG LLC Akira ransomware incident and VBS ownership review
- incident UK AISI cyber-range unsanctioned agent actions×2
- tool Ultraviolet
- product Apache Tomcat×2
- product Applied Biosystems GeneMapper ID-X
- product Applied Biosystems SeqStudio Genetic Analyzer
- product Cloudflare Pages
- product GitHub Pages
- product Netlify
- product Thermo Fisher Applied Biosystems 3500 Series Data Collection Software
- product Thermo Fisher Applied Biosystems 3730 Series Data Collection Software
- product Thermo Fisher Applied Biosystems GeneMapper ID-X Software
- product Thermo Fisher Applied Biosystems Genetic Analyzers
- product Thermo Fisher Applied Biosystems SeqStudio Flex Series Instrument Software
- product Thermo Fisher Applied Biosystems SeqStudio Genetic Analyzer Data Collection Software
- product Traefik Proxy
- product Vercel
- cve Check Point Security Management / Multi-Domain Security Management, unauthenticated bypass of management authentication to arbitrary command execution; fixed in Jumbo HFA R81.20 Take 161 / R82 Take 122 / R82.10 Take 40, no fix for the R80.x / R81 / R81.10 end-of-support trains
- cve Apache Tomcat; EncryptInterceptor defaulted to CBC and was exploitable as a padding oracle; its fix introduced the fail-open regression tracked as CVE-2026-34486
- cve Apache Tomcat Tribes/EncryptInterceptor fail-open; the fix for CVE-2026-29146 let messages that fail decryption reach the Java deserialization path; CISA KEV 2026-08-04 (previously recorded only as reverse-shell attempts observed by Unit 42); fixed in 9.0.117 / 10.1.54 / 11.0.21
- cve IBM Langflow, unauthenticated auto_login endpoint mints a superuser token, chained with the code-validation endpoint for pre-auth code execution (CVSS 9.8); CISA KEV 2026-08-04; affects Langflow OSS 1.0.0-1.10.0
- actor Sandworm×5
- incident Liechtenstein VwbP beneficial-ownership register breach (July 2026)
- trend LLM-fabricated CVE advisory wave (programmervuln/cveadvisory-)
- report CrowdStrike 2026 Threat Hunting Report
- actor VAULT PANDA
- actor GENESIS PANDA
- actor UMBRAL BISON
- actor ALTERED SPIDER
- trend Passkey / WebAuthn attack-surface disclosure convergence (2026-08)
- actor UAT-12197
- actor UAT-11823
- actor UAT-11988
- malware Cyclops Blink
- product Cisco Secure Firewall Management Center×2
- product Cisco Security Cloud Control Firewall Management
- product GitHub Advisory Database
- product Google Password Manager
- product NIST National Vulnerability Database
- product SQLite
- cve SonicWall SMA1000 AMC post-auth code injection (actively exploited)
- cve FABRICATED / NOT A REAL VULNERABILITY, a use-after-free claim against SQLite 3.41 from the LLM-generated advisory batch published via the programmervuln/cveadvisory- GitHub repository. NOT among the six ids JFrog Security Research reproduction-tested; JFrog assessed 54 of the 55 advisories from that account as completely fabricated, and SQLite's maintainer reported the wave independently on 2026-07-29. Still live as an unreviewed record in the GitHub Advisory Database (GHSA-4r76-5xh9-qj36) on 2026-08-04, after BSI CERT-Bund and NCSC-NL had withdrawn their SQLite advisories. Recorded here so a scanner or triage lookup resolves to the retraction; do NOT open remediation work from this id.
- cve FABRICATED / NOT A REAL VULNERABILITY, one of the LLM-generated SQLite advisories published via the programmervuln/cveadvisory- GitHub repository. JFrog Security Research reproduction-tested it under AddressSanitizer against the claimed SQLite release and it did not reproduce; it cited lines 3555 and 3575 of src/json.c in a file that is 2706 lines long in the claimed version 3.41.0. NCSC-NL withdrew NCSC-2026-0268 on 2026-08-03 stating the CVE was hallucinated by an LLM, and BSI CERT-Bund withdrew WID-SEC-2026-2581 and WID-SEC-2026-2604 the same day. Recorded here so a scanner or triage lookup resolves to the retraction; do NOT open remediation work from this id.
- cve FABRICATED / NOT A REAL VULNERABILITY, one of the LLM-generated SQLite advisories published via the programmervuln/cveadvisory- GitHub repository. JFrog Security Research reproduction-tested it under AddressSanitizer against the claimed SQLite release and it did not reproduce; it referenced jsonBlobEdit(), a function absent from the claimed version 3.41.0. NCSC-NL withdrew NCSC-2026-0268 on 2026-08-03 stating the CVE was hallucinated by an LLM, and BSI CERT-Bund withdrew WID-SEC-2026-2581 and WID-SEC-2026-2604 the same day. Recorded here so a scanner or triage lookup resolves to the retraction; do NOT open remediation work from this id.
- cve FABRICATED / NOT A REAL VULNERABILITY, one of the LLM-generated SQLite advisories published via the programmervuln/cveadvisory- GitHub repository. JFrog Security Research reproduction-tested it under AddressSanitizer against the claimed SQLite release and it did not reproduce; the cited line numbers are a comment and a memory allocation, unrelated to the deletion logic it describes. NCSC-NL withdrew NCSC-2026-0268 on 2026-08-03 stating the CVE was hallucinated by an LLM, and BSI CERT-Bund withdrew WID-SEC-2026-2581 and WID-SEC-2026-2604 the same day. Recorded here so a scanner or triage lookup resolves to the retraction; do NOT open remediation work from this id.
- cve FABRICATED / NOT A REAL VULNERABILITY, one of the LLM-generated SQLite advisories published via the programmervuln/cveadvisory- GitHub repository. JFrog Security Research reproduction-tested it under AddressSanitizer against the claimed SQLite release and it did not reproduce; the named function exprComputeOperands() did not exist in SQLite 3.41 and sqlite3ReleaseTempReg() performs no heap deallocation, making the claimed bug class impossible; Red Hat initially scored it 10.0 before downgrading to 7.6. NCSC-NL withdrew NCSC-2026-0268 on 2026-08-03 stating the CVE was hallucinated by an LLM, and BSI CERT-Bund withdrew WID-SEC-2026-2581 and WID-SEC-2026-2604 the same day. Recorded here so a scanner or triage lookup resolves to the retraction; do NOT open remediation work from this id.
- cve FABRICATED / NOT A REAL VULNERABILITY, one of the LLM-generated SQLite advisories published via the programmervuln/cveadvisory- GitHub repository. JFrog Security Research reproduction-tested it under AddressSanitizer against the claimed SQLite release and it did not reproduce; it claimed a fix in 3.51.3 although a 3.51.2-to-3.51.3 diff shows no changes to src/expr.c at all. NCSC-NL withdrew NCSC-2026-0268 on 2026-08-03 stating the CVE was hallucinated by an LLM, and BSI CERT-Bund withdrew WID-SEC-2026-2581 and WID-SEC-2026-2604 the same day. Recorded here so a scanner or triage lookup resolves to the retraction; do NOT open remediation work from this id.
- cve FABRICATED / NOT A REAL VULNERABILITY, one of the LLM-generated SQLite advisories published via the programmervuln/cveadvisory- GitHub repository. JFrog Security Research reproduction-tested it under AddressSanitizer against the claimed SQLite release and it did not reproduce; it gave a single-argument signature for a function that requires a database-handle argument. NCSC-NL withdrew NCSC-2026-0268 on 2026-08-03 stating the CVE was hallucinated by an LLM, and BSI CERT-Bund withdrew WID-SEC-2026-2581 and WID-SEC-2026-2604 the same day. Recorded here so a scanner or triage lookup resolves to the retraction; do NOT open remediation work from this id.
- tool PhantomKiller
- product Bouncy Castle FIPS Java API
- product Bouncy Castle for Java
- product Gladinet CentreStack
- cve Gladinet CentreStack and Triofox, files or directories accessible to external parties; added to the CISA Known Exploited Vulnerabilities catalog 2025-11-04. Referenced as historical exploitation context by the 2026-08-03 CentreStack entry.
- cve Gladinet CentreStack and Triofox, hard-coded cryptographic key vulnerability; added to the CISA Known Exploited Vulnerabilities catalog 2025-12-15. Referenced as historical exploitation context by the 2026-08-03 CentreStack entry.
- cve Gladinet CentreStack, use of a hard-coded cryptographic key; added to the CISA Known Exploited Vulnerabilities catalog 2025-04-08. Referenced as historical exploitation context by the 2026-08-03 CentreStack entry.
- cve Bouncy Castle for Java (< 1.85), BKS/UBER keystore allocates from untrusted lengths before integrity check (CVSS 7.1)
- cve Bouncy Castle for Java (< 1.85); CMS AuthEnvelopedData fails to enforce tag-length on decryption (CVSS 8.7)
- cve Bouncy Castle for Java (< 1.85); KCCMBlockCipher MAC does not bind nonce when AAD is absent (cross-nonce AEAD forgery) (CVSS 8.7)
- cve Bouncy Castle for Java (< 1.85), IESEngine stream-mode MAC forgery via length-dependent KDF split (CVSS 8.7)
- cve Bouncy Castle for Java (< 1.85), OpenPGP AEAD decryption skips final tag on chunk-aligned data (CVSS 8.7)
- cve Bouncy Castle for Java (< 1.85), MLS wire decoder allocates attacker-declared opaque length before bounds check (CVSS 8.7)
- cve Bouncy Castle for Java (< 1.85), RSA PKCS#1 verification skips last two hash bytes in NULL-omitted path (CVSS 8.7)
- cve Bouncy Castle for Java (< 1.85), Lazy ASN.1 sequence forcing resets nesting-depth guard (CVSS 8.7)
- cve Bouncy Castle for Java (< 1.85), PKCS#12 MAC and bag-decryption KDF iteration-count bound (DoS) (CVSS 5.3)
- cve Bouncy Castle for Java (< 1.85), Possible OOM from unbounded up-front allocation on a definite-length read (CVSS 8.7)
- cve Bouncy Castle for Java (< 1.85), PKCS#8 / PBES2 decryptors honour unbounded KDF cost from input (CVSS 5.3)
- cve Gladinet CentreStack < 17.5, hardcoded cryptographic key (static SysNumber) forges AccessTickets and x-glad-auth headers, reaching a domain-administrator IdentityTicket and unauthenticated RCE (CVSS 9.3)
- cve Gladinet CentreStack < 17.4, session-variable injection at SelectProvider.aspx bypasses the IsValidRSession check (CVSS 6.9)
- cve Gladinet CentreStack < 17.3, unauthenticated deserialization in GSNamespace.dll reaches NetUserAdd, creating arbitrary local OS accounts (CVSS 8.7)
- cve Gladinet CentreStack < 17.4, XXE at the unauthenticated SharePoint StorageConfig endpoint exfiltrates files including Web.config (CVSS 8.7)
- cve Gladinet CentreStack < 17.2, unauthenticated authorization bypass via forged EntAcctId values reaches any account's settings (CVSS 8.8)
- cve Gladinet CentreStack < 17.4, authenticated SQL injection via the x-glad-filter header writes files through PostgreSQL large-object functions (CVSS 8.7)
- cve Bouncy Castle for Java (< 1.85), Quadratic-time escaping when stringifying X.500 distinguished names (CVSS 8.7)
- cve Bouncy Castle for Java (< 1.85), HSS public-key level count unbounded, enabling huge allocation on verify (CVSS 8.7)
- cve Bouncy Castle for Java (< 1.85), CCM-family modes write plaintext to caller buffer before tag check (CVSS 8.7)
- cve Bouncy Castle for Java (< 1.85), Stapled OCSP response accepted without binding to the checked certificate (CVSS 9.3)
- cve Bouncy Castle for Java (< 1.85), BCFKS keystore load honours unbounded KDF cost from untrusted file (CVSS 5.3)
- cve Bouncy Castle for Java (< 1.85), JSSE hostname verifier CN-fallback enabled by default despite documented opt-in (CVSS 9.3)
- cve Bouncy Castle for Java (< 1.85), CMS verifySignatures returns true for SignedData with zero signers (CVSS 8.7)
- cve Bouncy Castle for Java (< 1.85), OpenPGP CFB quick-check oracle active on symmetric/session-key paths (CVSS 8.7)
- cve Bouncy Castle for Java (< 1.85), S/MIME validator trusts signer-asserted signingTime for path validation (CVSS 8.7)
- cve Bouncy Castle for Java (< 1.85), CMS AuthenticatedData content not bound to MAC when authAttrs present (CVSS 8.7)
- cve Bouncy Castle for Java (< 1.85), OpenPGP inline-signature policy failures silently ignored (CVSS 8.7)
- cve Bouncy Castle for Java (< 1.85), MLS hash-ratchet honours arbitrary 32-bit generation counter from sender (CVSS 8.7)
- cve Bouncy Castle for Java (< 1.85), OER parser recurses without depth limit on self-referential IEEE 1609.2 schema (CVSS 8.7)
- cve Bouncy Castle for Java (< 1.85), DTLS handshake reassembler allocates buffer from unchecked 24-bit length (CVSS 8.7)
- cve Bouncy Castle for Java (< 1.85), CRMF/CMP password-MAC honours unbounded iteration count (CVSS 6.9)
- cve Bouncy Castle for Java (< 1.85), OpenPGP Argon2 S2K honours attacker-chosen memory and passes (CVSS 6.9)
- cve Bouncy Castle for Java (< 1.85), OpenPGP user-attribute subpacket length bounded only by JVM max memory (CVSS 8.7)
- cve Bouncy Castle for Java (< 1.85), MTI/A0 DH agreement exponentiates unvalidated peer value (CVSS 9.3)
- cve Bouncy Castle for Java (< 1.85), BKS keystore accepts legacy version with 16-bit integrity MAC key (CVSS 7.1)
- cve Bouncy Castle for Java (< 1.85), LDAP filter injection in legacy jdk1.4 LDAPStoreHelper (CVSS 6.9)
- cve Bouncy Castle for Java (< 1.85), Name Constraints bypass via trailing dot in rfc822Name and URI (CVSS 9.3)
- incident Adform trackpoint-async.js supply-chain crypto-clipper compromise (July 2026)
- incident CCI Nice Côte d'Azur eDRH administrator-account export breach (July 2026)
- incident COLDCARD hardware-RNG fallback wallet-seed theft (2026)
- product Adform trackpoint-async.js
- product Coinkite COLDCARD Mk2
- product Coinkite COLDCARD Mk3
- product Coinkite COLDCARD Mk4
- product Coinkite COLDCARD Mk5
- product Coinkite COLDCARD Q
- product JoomShaper SP Page Builder
- product Phoenix Contact CHARX SEC-3000
- product Phoenix Contact CHARX SEC-3050
- product Phoenix Contact CHARX SEC-3100
- product Phoenix Contact CHARX SEC-3150
- cve CVE-2013-4786, 24,650 internet-exposed BMCs hand a crackable password hash to any unauthenticated caller, and Lava found ransom notes on live management interfaces
- cve OpenSSL CMS AuthEnvelopedData parsing stack buffer overflow (CVSS 9.8 per Siemens ProductCERT; OpenSSL rates it High), pre-auth, fires before AEAD tag verification; vendored in Siemens Desigo CC, where family V7 has no fix available, V8 is fixed by patch V8.0 QU2.0021 and V9 by 9.0.1; public command-execution PoC
- cve FortiOS SSL-VPN symlink-persistence patch bypass (exploited, KEV)
- cve Langflow eval_custom_component_code eval injection (CVSS 9.8, CWE-95), unauthenticated RCE, published by ZDI as a 0-day advisory with no fixed version documented anywhere and "restrict interaction with the product" as the only stated mitigation; VulnCheck reports observed exploitation for credential harvesting, cryptomining and lateral movement; NOT in CISA KEV (distinct from the KEV-listed CVE-2026-0770)
- cve IBM WebSphere Application Server traditional, missing authentication for critical function in the administrative console (CWE-306), CVSS 9.8; interim fix APAR DT496500, Fix Pack targeted 3Q2026
- cve IBM WebSphere Application Server traditional, pre-authentication unsafe deserialization (CWE-502), CVSS 9.8; interim fix APAR PH72166, Fix Pack targeted 3Q2026
- cve Check Point SmartConsole authentication bypass to full admin (exploited)
- cve Alibaba fastjson 1.2.68–1.2.83, remote code execution under stock defaults in Spring Boot fat-JAR deployments; no patched 1.x release, exploited in the wild
- cve Arista VeloCloud Orchestrator on-prem unauthenticated OS command injection (exploited, KEV)
- cve SolarWinds Web Help Desk, unauthenticated SAML 2.0 authentication bypass, CVSS 9.8; fixed in 2026.2.1
- cve Citrix NetScaler ADC/Gateway out-of-bounds memory read when configured as a SAML Identity Provider (CWE-125, CVSS 9.8), CISA KEV-listed and exploited by multiple unrelated clusters, including manual exfiltration of appliance memory searched for session cookies (Unit 42, 2026-07-30); fixed in 13.1-62.24 / 14.1-66.60 / 13.1-FIPS-NDcPP 13.1-37.263
- cve marimo notebook, pre-auth RCE via the unauthenticated /terminal/ws endpoint (CWE-306), CVSS 4.0 9.3, fixed in 0.23.0, CISA KEV-listed; Unit 42 records command execution confirmed on 11 endpoints during the 2026-07 autonomous-agent campaign
- cve Microsoft Exchange Server Outlook Web Access stored XSS (CWE-79, CVSS 3.1 8.1, Microsoft CNA), exploited in the wild by TA488/LAUNDRY BEAR to deliver the OWAReaper browser implant; CISA KEV 2026-05-15; permanent fix is the July 2026 Exchange SU (SE RTM; 2019 CU14/CU15 and 2016 CU23 via ESU Period 2), which does not remove earlier mitigations×4
- cve Phoenix Contact CHARX SEC-3xxx, MQTT broker reachable without authentication, protected from external access only by the device firewall (CWE-306); CVSS 3.1 9.8
- cve Phoenix Contact CHARX SEC-3xxx, missing authentication on the CHARX OCPP Agent lets a remote attacker reconfigure the backend connection (CWE-306); CVSS 3.1 9.8
- cve Phoenix Contact CHARX SEC-3xxx, basemodule firmware update validates only a CRC32 checksum with no cryptographic signature verification (CWE-347), allowing unauthenticated installation of modified firmware; CVSS 3.1 9.8
- cve Phoenix Contact CHARX SEC-3xxx, firewall terminates prematurely during shutdown because of script execution order (CWE-696), exposing internal services in the window; CVSS 3.1 9.8
- cve Adobe Campaign Classic, unauthenticated SQL injection giving arbitrary file-system read; CVSS 3.1 8.6, fixed in ACC v7 7.4.3 build 9398 (APSB26-114)
- cve Adobe Campaign Classic, Incorrect Authorization (CWE-863) giving unauthenticated arbitrary code execution; CVSS 3.1 10.0, on-premise and hybrid on-premise components only, fixed in ACC v7 7.4.3 build 9398 (APSB26-114)
- cve Apache Airflow FAB provider, Azure AD OAuth login decoded ID tokens with verify_signature defaulted to False, allowing login as any user incl. Admin; no CVSS published by any party; fixed in apache-airflow-providers-fab 3.7.3
- cve CVE-2026-59726 (RufRoot), Ruflo's MCP bridge took unauthenticated tool calls on all interfaces, and the memory it poisons is not cleaned up by the patch (CVSS 10.0)
- cve vBulletin {vb:math} runMaths eval injection, unauthenticated RCE (public exploit)
- cve JoomShaper SP Page Builder for Joomla, pre-authentication SQL injection in the Dynamic Content endpoint's ORDER BY clause, guarded only by a CSRF token Joomla issues to anonymous visitors; Joomla CNA CVSS 4.0 9.2 (discloser self-scored 8.7), fixed in 6.7.1
- cve JoomShaper SP Page Builder for Joomla, unauthenticated SQL injection through the catid parameter of the loadMoreArticles endpoint; Joomla CNA CVSS 4.0 9.2, fixed in 6.7.1. Not among the four flaws mySites.guru reported and not tested by it
- cve JoomShaper SP Page Builder for Joomla, authenticated SQL injection in the media manager's search and date filters, reachable by a low-privilege author; Joomla CNA CVSS 4.0 8.2, fixed in 6.7.1
- cve JoomShaper SP Page Builder for Joomla, authenticated arbitrary file delete via an unguarded request-supplied path in the media-delete action; Joomla CNA CVSS 4.0 8.3, fixed in 6.7.1
- cve JoomShaper SP Page Builder for Joomla, unauthenticated mail relay via a shared secret hardcoded identically into every shipped copy (CWE-798); the Joomla CNA assigned no metrics, so the 9.8 is a CISA-ADP CVSS 3.1 score and is not on the CVSS 4.0 scale its siblings use. Fixed in 6.7.1
- cve Aimy Captcha-Less Form Guard (Joomla plugin), unauthenticated PHP object injection to RCE, CVSS 9.8; fixed in 20.1
- cve Balbooa Gridbox for Joomla; registration handler adds caller-supplied usergroup IDs, letting an unauthenticated visitor register an account directly into an administrator group; CVSS 4.0 10.0 (CWE-284, Joomla CNA), exploit maturity Attacked; affected 1.0.0-2.20.1, fixed 2.20.2
- cve Balbooa Gridbox for Joomla, authenticated arbitrary file upload; becomes unauthenticated RCE chained with CVE-2026-65884 because the attacker can create the required account; CVSS 4.0 9.4 (CWE-434, Joomla CNA), exploit maturity Attacked; affected 1.0.0-2.20.1, fixed 2.20.2
- cve Phoenix Contact CHARX SEC-3xxx EV charging controllers, unauthenticated command injection into the system configuration executed as root (CWE-77); CVSS 3.1 9.8, firmware below 1.9.1, fix unreleased at disclosure (CERT@VDE VDE-2026-008)
- malware CornFlake
- tool ChocoShell
- malware XCSSET
- product Aimy Captcha-Less Form Guard
- product Apple Xcode
- product IBM WebSphere Application Server
- product SolarWinds Web Help Desk
- cve IBM WebSphere Application Server traditional, sensitive information written to log files (CWE-532), CVSS 7.4
- cve SolarWinds Web Help Desk, denial of service, server crash due to insufficient memory; 8.2 High per the vendor's 2026.2.1 release-notes CVE table; fixed in 2026.2.1
- malware OctLurk×2
- malware SilkLurk
- tool LurkProxy
- actor Toy Ghouls
- malware GenieLocker
- actor ExfilSquad
- incident UK Department for Education portal and Police National Legal Database breach (July 2026)
- tool mqtt-bird-agent
- tool matrix-bird-agent
- product libvips
- product Marimo
- product Marimo Notebook
- product Microsoft Dataverse
- product Microsoft Dynamics 365
- product Microsoft Power Apps
- product Microsoft Power Apps Portals
- product Microsoft Power Pages
- product Palo Alto Networks PAN-OS
- product Python Package Index (PyPI)
- product Ruby on Rails
- product Ruby on Rails Active Storage
- product ruby-vips
- product HashiCorp Terraform MCP Server
- product HPE iLO
- product Ruflo
- product SonicWall SonicOS
- product Supermicro BMC (IPMI)
- product VMware Cloud Foundation
- product VMware Fusion
- product VMware Telco Cloud Infrastructure
- product VMware Telco Cloud Platform
- product VMware vCenter Server×2
- product VMware vSphere Foundation
- product VMware Workstation
- cve HCSEC-2026-23, HashiCorp Terraform MCP Server leaks its own bearer token to an attacker-supplied address, and its credential cache crosses sessions and tenants (CVE-2026-14869, CVE-2026-16496, CVE-2026-16498)
- cve HCSEC-2026-23, HashiCorp Terraform MCP Server leaks its own bearer token to an attacker-supplied address, and its credential cache crosses sessions and tenants (CVE-2026-14869, CVE-2026-16496, CVE-2026-16498)
- cve HCSEC-2026-23, HashiCorp Terraform MCP Server leaks its own bearer token to an attacker-supplied address, and its credential cache crosses sessions and tenants (CVE-2026-14869, CVE-2026-16496, CVE-2026-16498)
- cve VMSA-2026-0006, VMware vCenter: unauthenticated Directory Service auth bypass and Syslog traversal RCE (both CVSS 9.8), plus a VMXNET3 guest-to-host escape
- cve VMSA-2026-0006, VMware vCenter: unauthenticated Directory Service auth bypass and Syslog traversal RCE (both CVSS 9.8), plus a VMXNET3 guest-to-host escape
- cve VMSA-2026-0006, VMware vCenter: unauthenticated Directory Service auth bypass and Syslog traversal RCE (both CVSS 9.8), plus a VMXNET3 guest-to-host escape
- cve VMSA-2026-0006, VMware vCenter: unauthenticated Directory Service auth bypass and Syslog traversal RCE (both CVSS 9.8), plus a VMXNET3 guest-to-host escape
- tool ARToken×2
- actor Chaos (ransomware-as-a-service)×2
- actor STAC4749
- actor Sinobi
- actor Warlock
- actor UAT-11764
- report Cisco Talos IR Trends Q2 2026
- incident Minnesota coordinated water-utility OT cyberattack (July 2026)
- incident UVVG Arad cyberattack (July 2026)
- product AnyDesk
- product Apache Airflow FAB provider
- product DWAgent
- product MeshCentral MeshAgent
- product Microsoft Quick Assist
- product RemSupp
- product Rockwell Automation MicroLogix
- product Siemens Desigo CC
- product Siemens Mendix Runtime
- product Zoho Assist
- cve Siemens Mendix Runtime (all versions, CVSS 9.1), platform-enforced access rules on the System.User entity cannot be overridden by access rules on a specialization, so the anonymous role commonly reaches all stored user records; no code fix, mitigation is App Security role-management reconfiguration
- tool Dysphoria
- tool MedusaHVNC
- product vBulletin
- product Alibaba fastjson
- campaign FakeAgent
- malware SectopRAT
- malware TELESHIM
- tool MIXEDKEY
- malware BINDCLOAK
- product Balbooa Gridbox
- product Balbooa Gridbox for Joomla
- product GitLab CE
- product GitLab EE
- product Joomla Events Booking
- product Joomla Membership Pro
- product JoomShaper EasyStore
- product Oracle Coherence
- product Oracle Data Integrator
- product Oracle Database Server
- cve Windows shortcut working-directory resolution flaw abused for remote WebDAV execution
- cve CVE-2026-0770, Langflow: unauthenticated exec_globals RCE (actively exploited, CISA KEV 2026-07-21)
- cve IBM Langflow OSS Python Interpreter authenticated command injection (CVSS 8.8), fixed in 1.10.2, not 1.10.1
- cve Oracle Data Integrator REST Service, unauthenticated takeover (CVSS 10.0, July 2026 CPU)
- cve Oracle Coherence Core, unauthenticated takeover over TCP (CVSS 10.0, July 2026 CPU)
- cve Oracle Fusion Middleware CVSS 10.0 unauthenticated flaw, listed twice in Oracle's July 2026 risk matrix (Oracle HTTP Server and WebLogic Server Proxy Plug-in), which is why the ten-row / nine-CVE counts diverge
- cve Oracle Database Server, DBMS_CLOUD privilege abuse to full server control (CVSS 9.9)
- cve Balbooa Gridbox for Joomla, unauthenticated cookie-forgery authentication bypass to Super User
- cve Membership Pro for Joomla, unauthenticated file upload (CVSS 9.1, Joomla CNA); fixed in 4.6.2
- cve Events Booking for Joomla, unauthenticated invoice IDOR exposing personal and financial data
- cve JoomShaper EasyStore for Joomla, unauthenticated order/payment forgery on the repayment endpoint (CVSS 4.0 8.7, Joomla CNA)
- cve JoomShaper EasyStore for Joomla, cross-customer order/invoice IDOR reachable by any logged-in customer (CVSS 4.0 9.2, Joomla CNA)
- cve JoomShaper EasyStore for Joomla, unauthenticated SQL injection, full site-database read (CVSS 4.0 9.3, Joomla CNA)
- actor INC Ransom×3
- actor LAUNDRY BEAR×3
- actor TA458×2
- malware SpyPress
- tool Hades×3
- incident Thailand Ministry of Finance, Hermes AI-agent-automated intrusion (2026-07)
- report Microsoft Email Threat Landscape Q2 2026
- product Apache Ambari
- product Apache Hive
- product Eclipse GlassFish
- product Kerio Connect
- product MDaemon Email Server
- product Microsoft Defender for Office 365
- product SOGo
- cve Roundcube webmail persistent XSS (n-day exploited by TA458/Operation RoundPress)
- cve Zimbra Collaboration half-click webmail flaw (TA458/Operation RoundPress)
- cve mDaemon webmail half-click flaw (TA458/Operation RoundPress)
- cve Certighost, Windows Server AD CS elevation of privilege (DC impersonation to DCSync)
- cve Check Point Security Management / MDS unauthenticated command execution
- cve Check Point Gaia Portal read-only to root command execution
- cve SOGo webmail half-click XSS zero-day (Operation RoundPress / TA458)
- actor CyberAv3ngers
- tool Ulej / Flowerbed×2
- actor BravoX
- incident BravoX breach of a Yverdon-les-Bains fiduciary, Vaud municipalities data exposure
- malware msaRAT
- tool Kratos (phishing-as-a-service)
- product Mitel MiCollab
- product MZ Automation lib60870
- product MZ Automation libIEC61850
- product Rockwell Automation CompactLogix
- product Rockwell Automation Micro850
- product Schneider Electric Modicon M340
- product Siemens S7-1200
- cve Zimbra Collaboration Suite Classic Web Client stored XSS (view-based/zero-click) exploited by Russian actor LAUNDRY BEAR; CVSS 7.2 (MITRE)/6.1 (NVD); CISA KEV; patched ZCS 10.0.18/10.1.13
- cve MZ Automation lib60870 out-of-bounds read parser-crash DoS (IEC 60870-5-104); lib60870 <= 2.4.0 (CVSS 3.1 8.2 / 4.0 8.8)
- cve MZ Automation libIEC61850 unauthenticated heap-overflow RCE via crafted MMS Initiate request (CVSS 3.1 8.1 / 4.0 9.2); libIEC61850 1.0.0-1.6.1
- cve MZ Automation libIEC61850 NULL-pointer dereference DoS in MMS Write Named Variable List handler (CVSS 3.1 7.5 / 4.0 8.7)
- cve MZ Automation libIEC61850 stack-based buffer overflow via crafted ReadRequest (CVSS 3.1 7.5 / 4.0 8.7)
- cve MZ Automation libIEC61850 NULL-pointer dereference DoS in L2 GOOSE/R-GOOSE parser via malformed TLV (CVSS 3.1 6.5 / 4.0 7.1)
- malware SANDWORM_MODE
- actor Cl0p×5
- product Check Point Gaia Portal
- product Check Point SmartConsole
- product Claude Desktop
- product Model Context Protocol (MCP)
- product SolarWinds Serv-U
- product Visual Studio Code
- product Windsurf
- cve SolarWinds Serv-U 2026.3 IDOR/broken-access-control (priv-esc to root RCE)
- cve SolarWinds Serv-U 2026.3 IDOR/broken-access-control (priv-esc to root RCE)
- cve SolarWinds Serv-U 2026.3 IDOR/broken-access-control (priv-esc to root RCE)
- cve SolarWinds Serv-U 2026.3 IDOR/broken-access-control (priv-esc to root RCE)
- cve SolarWinds Serv-U 2026.3 IDOR/broken-access-control (priv-esc to root RCE)
- cve SolarWinds Serv-U 2026.3 IDOR/broken-access-control (priv-esc to root RCE)
- cve SolarWinds Serv-U 2026.3 IDOR/broken-access-control (priv-esc to root RCE)
- cve SolarWinds Serv-U 2026.3 IDOR/broken-access-control (priv-esc to root RCE)
- cve SolarWinds Serv-U 2026.3 IDOR/broken-access-control (priv-esc to root RCE)
- cve SolarWinds Serv-U 2026.3 IDOR/broken-access-control (priv-esc to root RCE)
- cve SolarWinds Serv-U 2026.3 IDOR/broken-access-control (priv-esc to root RCE)
- cve SolarWinds Serv-U 2026.3 IDOR/broken-access-control (priv-esc to root RCE)
- cve SolarWinds Serv-U 2026.3 IDOR/broken-access-control (priv-esc to root RCE)
- cve SolarWinds Serv-U 2026.3 IDOR/broken-access-control (priv-esc to root RCE)
- cve SolarWinds Serv-U 2026.3 IDOR/broken-access-control (priv-esc to root RCE)
- cve SolarWinds Serv-U 2026.3 IDOR/broken-access-control (priv-esc to root RCE)
- cve GLPI 11.0.8/10.0.26 security release (critical RCE via form import; MFA bypass)
- cve GLPI 11.0.8/10.0.26 security release (critical RCE via form import; MFA bypass)
- cve GLPI 11.0.8/10.0.26 security release (critical RCE via form import; MFA bypass)
- cve GLPI 11.0.8/10.0.26 security release (critical RCE via form import; MFA bypass)
- cve GLPI 11.0.8/10.0.26 security release (critical RCE via form import; MFA bypass)
- cve GLPI 11.0.8/10.0.26 security release (critical RCE via form import; MFA bypass)
- cve GLPI 11.0.8/10.0.26 security release (critical RCE via form import; MFA bypass)
- cve GLPI 11.0.8/10.0.26 security release (critical RCE via form import; MFA bypass)
- cve GLPI 11.0.8/10.0.26 security release (critical RCE via form import; MFA bypass)
- cve GLPI 11.0.8/10.0.26 security release (critical RCE via form import; MFA bypass)
- actor Everest×4
- actor XEntry Team
- incident Stadler Rail supplier-platform breach
- incident KNDA diplomatic-academy zero-day breach
- product IBM Langflow
- product IBM Langflow OSS
- product Langflow Desktop
- product Langflow OSS
- product ManageEngine Endpoint Central
- product Microsoft SQL Server
- product Microsoft Windows BitLocker
- product Tactical RMM
- cve CVE-2026-10631, Zimbra: EWS extension access-control issue (fixed 10.1.20; RESERVED on NVD)
- cve CVE-2026-50054, Zimbra: mailbox delegation authorization flaw (fixed 10.1.20; RESERVED on NVD)
- cve CVE-2026-50055, Zimbra: mail-forwarding restriction bypass (fixed 10.1.20; RESERVED on NVD)
- cve CVE-2026-50522, Microsoft SharePoint Server: Site-Owner deserialization RCE (CVSS 9.8)
- cve CVE-2026-7754, Langflow OSS: SSRF from insecure default configuration (fixed 1.10.1)
- cve CVE-2026-7755, Langflow OSS: RCE via insufficient validation of MCP server config files (fixed 1.10.1)
- cve CVE-2026-8476, Langflow OSS: unsafe deserialization in AsyncDiskCache via apply_tweaks() (fixed 1.10.1)
- cve CVE-2026-8859, Langflow OSS: path-traversal arbitrary file write (fixed 1.10.1)
- cve CVE-2026-9135, Langflow OSS: code injection in Policies/ToolGuard component (fixed 1.10.1)
- cve CVE-2026-9202, Langflow OSS: unauthenticated account creation reaching RCE (fixed 1.10.1)
- actor Cavern Manticore×2
- actor OilRig×2
- tool Cavern×2
- tool Cruciferra
- tool HOLLOWGRAPH
- product dnsmasq
- product Hugging Face Hub
- product Microsoft Graph
- product Microsoft Outlook
- cve dnsmasq really_insert() DNS-cache heap buffer overflow (RCE per Exodus; NVD frames as DoS/cache-poisoning)
- cve ServiceNow AI Platform sandbox escape, unauthenticated code execution within the platform (CVSS 9.5); hosted fixed server-side, self-hosted/partner patch listed family releases
- actor UAC-0145
- product F5 NGINX Open Source
- product F5 NGINX Plus
- cve nginx / NGINX Plus PCRE capture-clobber pre-auth heap overflow (CVSS 9.2); F5 out-of-band patch 2026-07-15/16, credited researcher demonstrates RCE beyond F5's DoS-only framing (no public PoC, no ITW as of 2026-07-20); fixed nginx 1.30.4/1.31.3, NGINX Plus R36 P7/37.0.3.1
- tool ClickLock Stealer
- incident Ernst & Young third-party ITSM breach
- malware GoSerpent
- actor TetrisPhantom
- incident Brinks Home breach (July 2026)
- product Moodle local_o365 plugin (Microsoft Office 365 Integration for Moodle)
- product PHP
- product Salesforce×2
- product ServiceNow
- product Siemens RUGGEDCOM ROX II
- product VMware Avi Load Balancer
- product VMware NSX Advanced Load Balancer
- product WordPress Core
- cve Siemens RUGGEDCOM ROX II feature-key gpgv command injection to root (CVSS 7.5); Unit 42 chain
- cve Siemens RUGGEDCOM ROX II arbitrary file disclosure via root-privileged xz misuse (CVSS 6.8); Unit 42 chain
- cve Siemens RUGGEDCOM ROX II task-scheduler command injection, persistent root (CVSS 9.1); Siemens SSA-081142
- cve VMware Avi Load Balancer control-plane unauthenticated authentication bypass (CVSS 9.8), VMSA-2026-0005
- cve VMware Avi Load Balancer authorization bypass (CVSS 8.3), VMSA-2026-0005
- cve VMware Avi Load Balancer high-privilege RCE (CVSS 8.7), VMSA-2026-0005
- cve VMware Avi Load Balancer local privilege escalation to root (CVSS 7.8), VMSA-2026-0005
- cve VMware Avi Load Balancer authenticated RCE (CVSS 8.7), VMSA-2026-0005
- cve VMware Avi Load Balancer privilege escalation (CVSS 7.1), VMSA-2026-0005
- cve VMware Avi Load Balancer authenticated directory traversal (CVSS 8.8), VMSA-2026-0005
- cve Moodle local_o365 plugin JWT-signature-not-verified SSO auth bypass
- tool Amatera
- actor UAT-11795
- tool Starland RAT
- tool WLDR
- tool CastleStealer
- campaign HelloNet
- tool HelloNet toolkit
- tool ACR Stealer×3
- incident Wind Tre vishing + API-enumeration breach (2025)
- product Abacus AbaClik
- product Abacus AbaClik.ai
- product Abacus ERP
- product InfoTeCS ViPNet
- cve Mozilla Firefox WebAssembly engine invalid-pointer memory-safety flaw (public exploit code, no confirmed ITW); fixed 152.0.6
- cve Mozilla Firefox DOM Navigation site-isolation bypass (public exploit code, no confirmed ITW); fixed 152.0.6
- cve Microsoft SharePoint Server on-prem RCE, part of the actively-exploited SharePoint cluster (CISA KEV 2026-04-14), referenced as context in the CVE-2026-58644 exploitation update
- cve CVE-2026-58644, Microsoft SharePoint Server deserialization RCE (CVSS 9.8); confirmed exploited + CISA KEV 2026-07-16
- actor World Leaks
- incident Industrielle Werke Basel (IWB) third-party service-provider data breach (July 2026)
- tool TELEPUZ
- incident Kudankulam nuclear-plant contractor (Reliance Group) third-party-hosting data breach (July 2026)
- product KNX Connection Authorization Option 1 devices (no BCU key set)
- product Oracle Payments
- cve KNX Connection Authorization Option 1 overly-restrictive account-lockout DoS (CVSS 7.5, CWE-645); CISA KEV 2026-07-15, no software patch (procedural mitigation)
- cve Oracle E-Business Suite / Oracle Payments File Transmission unauthenticated RCE/takeover (CVSS 9.8); CISA KEV 2026-07-15, exploited ITW since 2026-06-27; fixed Oracle May 2026 CPU (12.2.3-12.2.15)×3
- actor UNK_pyreq2323
- actor UNK_OutFlareAZ
- product ABB 800xA for Advant Master
- product ABB Ability Edgenius
- product ABB T-MAC Plus
- product Rockwell Automation 1715-AENTR
- cve CVE-2025-13162, ABB 800xA for Advant Master / Control Builder A: DLL search-path element (CVSS 4.4)
- cve CVE-2025-14771, ABB T-MAC Plus: authenticated file disclosure (CVSS 9.9)
- cve CVE-2025-14772, ABB T-MAC Plus: broken access control / authz bypass (CVSS 8.8)
- cve CVE-2025-14773, ABB T-MAC Plus: stored XSS (CVSS 8.0)
- cve CVE-2025-14774, ABB T-MAC Plus: Card Reader service DoS (CVSS 7.4)
- cve CVE-2026-10577, Rockwell 1715-AENTR EtherNet/IP Adapter: unauthenticated debug-port takeover (CVSS 10.0)
- cve CVE-2026-55944, Microsoft Dynamics NAV / Dynamics 365 Business Central (On-Prem): pre-auth deserialization RCE (CVSS 9.8)
- campaign Miasma×4
- report Check Point Annual AI Security Report 2026
- tool CrashStealer
- incident AsyncAPI npm supply-chain compromise via GitHub Actions (M-RED-TEAM)
- tool M-RED-TEAM
- campaign prt-scan
- incident IFAGE Geneva, DragonForce leak-site claim (850 GB)
- actor bandcampro
- campaign Patriot Bait
- actor Storm-3138
- tool KNUCKLEBALL / ORANGETAIL SonicWall SMA toolset
- product Abitti
- product @asyncapi/generator
- product @asyncapi/generator-components
- product @asyncapi/generator-helpers
- product @asyncapi/specs
- product Baramundi Management Suite
- product Blancco/WhiteCanyon WipeDrive
- product Gainsight
- product Klue
- product Microsoft Active Directory Federation Services
- product Microsoft Dynamics 365 Business Central (On-Premises)
- product Microsoft Dynamics NAV
- product openSUSE
- product Oracle Linux
- product PC-Doctor Service Center
- product Python (PyPI package ecosystem)
- product Red Hat Enterprise Linux / CentOS
- product ROSA Linux
- product Salesloft Drift
- product SAP Approuter
- product Shim (UEFI bootloader, versions ≤ 0.9)
- product Spyrus WTGCreator
- cve GRUB 2 Secure Boot bypass (historical), cited by ESET/CERT/CC as an old bug reopened by pre-15.3 UEFI shims lacking SBAT (context in CVE-2026-8863/10797 entry)
- cve Forgotten pre-0.9 UEFI shim signature-length validation mismatch (revocation-check vs signature-verification size divergence), Secure Boot bypass; revoked via Microsoft dbx 2026-06-09 (ESET Research)
- cve SAP Approuter unauthenticated HTTP request smuggling (CVSS 9.1)
- cve SAP NetWeaver AS ABAP kernel memory corruption (CVSS 9.9)
- cve SAP Commerce Cloud hardcoded sample OAuth2 credential (CVSS 9.1)
- cve Microsoft AD FS local elevation of privilege (exploited zero-day)
- cve Microsoft SharePoint Server unauthenticated elevation of privilege (exploited zero-day)
- cve Forgotten pre-0.9 UEFI shim trust-validation weakness (Secure Boot bypass on machines trusting the Microsoft third-party UEFI CA); revoked via Microsoft dbx 2026-06-09 (ESET Research)
- actor Secret Blizzard×4
- incident Progress ShareFile Storage Zone Controller emergency shutdown
- incident France/EU formal attribution of Turla (FSB Centre 16) espionage against France
- campaign Russian hijacking of IP cameras along NATO military-supply routes (2026-07)
- product Cisco IOS
- product Progress ShareFile Storage Zone Controller
- product Rejetto HFS
- product WAGO I/O System Field 0765-110x/0100-0000
- product WAGO I/O System Field 0765-120x/0100-0000
- product WAGO I/O System Field 0765-150x/0100-0000
- product WAGO I/O System Field 0765-2101/0100-0000
- product WAGO I/O System Field 0765-2102/0100-0000
- product WAGO I/O System Field 0765-410x/0100-0000
- product WAGO I/O System Field 0765-420x/0100-0000
- product WAGO I/O System Field 0765-450x/0100-0000
- cve Cisco IOS (end-of-life devices), named by the 2026-07-13 FSB Centre 16 joint advisory as an exploited legacy CVE; no patch (EOL)
- cve Cisco IOS/IOS XE Smart Install pre-auth RCE, actively exploited by FSB Centre 16 / Static Tundra
- cve WAGO I/O System Field, undocumented early-boot diagnostic interface, unauthenticated full compromise (CWE-912)
- cve Rejetto HFS < 3.2.1 predictable session-signing PRNG (Math.random) enables pre-auth admin session forgery to RCE via server_code (CVSS 9.3); fixed 3.2.1
- cve Rejetto HFS 3.0.0–3.2.0 stored XSS in admin log via crafted failed-login username; fixed 3.2.1
- cve Rejetto HFS 3.0.0–3.2.0 state-changing admin actions accepted over GET with no anti-CSRF check; fixed 3.2.1
- cve Rejetto HFS 3.0.0–3.2.0 unauthenticated username enumeration (incl. default admin) via login-endpoint response differences; fixed 3.2.1
- cve Rejetto HFS 3.0.0–3.2.0 stored XSS via unescaped filenames in fallback 'basic' listing; fixed 3.2.1
- cve Rejetto HFS 3.0.0–3.2.0 path traversal via lang query parameter (limited JSON file read); fixed 3.2.1
- tool GhostApproval×2
- tool GigaWiper
- tool Crucio
- tool FlockWiper
- actor Hyadina
- tool PoisonX
- campaign Friendly Fire (AI Now Institute exploit)
- actor Armored Likho
- malware BusySnake Stealer
- product Anthropic Claude Code CLI
- product Phoca Download for Joomla
- product PraisonAI
- product Progress MOVEit Transfer
- product RSFiles! for Joomla
- cve Progress MOVEit Transfer Custom Reports table-scope bypass, admin-privileged (CVSS 7.2; CERT-FR AVI-0856)
- cve Progress MOVEit Transfer SFTP-service memory-leak pre-auth denial of service (CVSS 7.5; CERT-FR AVI-0856)
- cve Progress MOVEit Transfer Ad Hoc module stored XSS, low-priv authenticated (CVSS 8.0; CERT-FR AVI-0856)
- cve Windows HTTP.sys pre-auth kernel RCE (CVSS 9.8); ZDI published full exploitation mechanics + detection signature 2026-07-10
- cve Joomla RSFiles! (com_rsfiles) unauthenticated file-upload RCE (CVSS 4.0 10.0); part of the mySites.guru Joomla-extension CWE-434 wave
- cve Joomla Phoca Download (com_phocadownload) authenticated file-upload RCE via member-upload allow-list bypass (CVSS 4.0 9.0)
- cve PraisonAI PGVector/Cassandra knowledge store, SQL/CQL injection via unvalidated vector dimension (CVSS 9.3)
- cve PraisonAI AICoder, arbitrary file write / command execution via LLM tool calls (CVSS 9.4)
- cve PraisonAI CodeAgent, unsandboxed LLM-generated Python execution with full env-secret leak (CVSS 10.0)
- actor Bitter
- campaign LSHIY Azure CLI ROPC token-spray
- campaign Railway device-code phishing
- campaign STAC3725 CitrixBleed 2-to-DragonForce IAB chain
- incident CERT.LV LVM/Olpha ransomware intrusion (2026)
- incident Nextcloud GmbH corporate Elasticsearch data exposure (2026)
- incident Odido (Netherlands telecom) ShinyHunters breach
- incident @injectivelabs/sdk-ts npm supply-chain compromise (2026)
- actor WP-SHELLSTORM
- tool Forg365
- product Apache Nacos
- product Azure CLI
- product Elastic Elasticsearch
- product @injectivelabs/sdk-ts (npm)
- product Joomla
- product JoomliC iCagenda
- product Open WebUI
- product Siemens SICAM A8000 CP-8010/CP-8012 (SICORE firmware)
- product Siemens SICAM A8000 CP-8031/CP-8050 (CPCI85 firmware)
- product Siemens SICAM EGS (CPCI85 firmware)
- product Siemens SICAM S8000 (SICORE firmware)
- product Spring Boot
- product XXL-Job
- cve Apache Nacos authentication bypass (Nacos-Server User-Agent header) abused by WP-SHELLSTORM for Java-stack credential theft
- cve CitrixBleed 2 (NetScaler ADC/Gateway pre-auth memory over-read), weaponised in the STAC3725 IAB-to-DragonForce kill chain (Huntress)
- cve Open WebUI /api/tasks/stop/ IDOR, unauthorized task cancellation (unpatched)
- cve Open WebUI Direct Connections XSS chained to unsandboxed Python exec() → RCE
- cve WordPress ThemeREX Addons plugin vulnerability weaponized by the WP-SHELLSTORM crew
- cve Gitea Docker reverse-proxy trust-all auth bypass (X-WEBAUTH-USER impersonation), NCSC-CH escalated status to actively-exploited 2026-07-10
- cve WordPress Breeze Cache Cleaner plugin flaw, highest-yield exploit in the WP-SHELLSTORM webshell-brokerage campaign
- cve Open WebUI /api/openai/responses proxy reaches any model without per-model authz
- cve Open WebUI incomplete collection allowlist exposes knowledge-base metadata to any user
- cve Open WebUI Socket.IO ydoc:document:update checks room membership not write permission
- cve iCagenda for Joomla, unauthenticated file-upload-to-RCE, exploited zero-day, CISA KEV
- cve Open WebUI prompt version-history IDOR (caller-supplied history-ID unauthorized)
- cve Siemens SICAM 8 HTTP-reachable debug interface → authenticated DoS
- cve Siemens SICAM 8 firmware-update signature-validation bypass → persistent malicious firmware
- cve Siemens SICAM 8 ships with OPC UA security disabled by default
- cve Siemens SICAM 8 web-API admin-account credential-validation bypass → privilege escalation
- actor Unsafe
- campaign FrostyNeighbor March–May 2026 campaign×4
- campaign Nightmare Eclipse Windows zero-day series×6
- incident Nayax cloud-account incident
- incident PDAG email-account compromise
- report ESET Threat Report H1 2026
- tool 'Ghost in the Database' ADFS key recovery
- tool Apex2×3
- tool c2c / meow
- tool RedHook
- actor UNK_MassTraction
- tool IceCube
- product GeoVision GeoWebPlayer
- product GeoVision GV-I/O Box 4E
- product Linux Kernel (KVM/x86)
- product Microsoft Security Essentials
- product Microsoft System Center Endpoint Protection
- product OpenPLC
- product vtk-dicom
- product wolfSSL
- cve Roundcube XSS, exploited by FrostyNeighbor / Ghostwriter (UNC1151) for Polish-targeting credential harvesting
- cve GeoVision GV-I/O Box 4E unauthenticated OS command injection (Talos, CVSS 9.1)
- cve AWS Language Servers / Amazon Q Developer symlink trust-boundary write outside workspace (GhostApproval, CWE-61); fixed language-servers 1.69.0 / @aws/lsp-codewhisperer 0.0.117
- cve GeoVision GeoWebPlayer unauthenticated localhost WebSocket screen-capture (Talos, CVSS 8.8)
- cve OpenPLC v3 Runtime authenticated arbitrary file-write to native RCE (CVSS 9.9; CISA ICSA-26-190-01, no fix)
- cve VTK-DICOM heap overflow on crafted DICOM file (Talos, CVSS 8.1)
- cve Plesk XML API code injection (CWE-94), authenticated low-priv to arbitrary root file write / LPE (CVSS 9.9); CCB Belgium; affected <18.0.30, fixed 18.0.30-18.0.78.4 (18.0.79+ unaffected)
- cve Cursor IDE sandbox escape via symlink + failed path canonicalization (GhostApproval); fixed Cursor 3.0
- cve wolfSSL registeredID SAN name-constraint bypass (Talos, CVSS 7.4)
- cve Balbooa Forms for Joomla (com_baforms) unauthenticated file-upload RCE (CWE-434, CVSS 4.0 10.0), zero-day exploited pre-patch; 3rd Joomla-extension file-upload RCE in the 2026-06/07 wave
- cve wolfSSL PKCS#7 OtherRecipientInfo integer underflow -> heap overflow (Talos, CVSS 7.5)
- cve wolfSSL iPAddress SAN name-constraint bypass (Talos coordinated disclosure, CVSS 9.1)
- actor 888
- actor UAT-5918
- actor UAT-7810
- tool CrySome RAT
- tool Factory-v3
- tool LONGLEASH / SHORTLEASH ORB malware suite
- cve Ruckus wireless router flaw exploited by UAT-7810 for ORB initial access (context; Cisco Talos)
- cve Ruckus wireless router flaw exploited by UAT-7810 for ORB initial access (context; Cisco Talos)
- cve Ruckus wireless router flaw exploited by UAT-7810 for ORB initial access (context; Cisco Talos)
- cve ASUS AiCloud router flaw exploited by UAT-7810 for ORB initial access (context; Cisco Talos)
- cve Hydro-Quebec EV-charging OCPP WebSocket unauthenticated access -> privilege escalation (CVSS 9.8), CISA ICSA-26-188-01
- cve Langflow unauthenticated RCE (build_public_tmp), CISA KEV, exploited in the Langflow IDOR chain
- cve BeyondTrust RS/PRA pre-auth authentication bypass (CVSS4 9.2), NCSC-CH BT26-03
- cve BeyondTrust RS/PRA pre-auth authentication bypass (CVSS4 9.2), NCSC-CH BT26-03
- cve BeyondTrust RS/PRA unauthenticated DoS (network-communication subsystem), BT26-03
- cve BeyondTrust RS/PRA authenticated broken-access-control (resource access beyond scope), BT26-03
- cve Hydro-Quebec EV-charging: no auth-attempt throttling -> DoS (CVSS 7.5), ICSA-26-188-01
- cve GhostLock, Linux kernel rtmutex use-after-free LPE + container escape, public exploit
- cve Hydro-Quebec EV-charging: duplicate concurrent sessions per charge-point ID -> DoS (CVSS 7.5), ICSA-26-188-01
- cve Adobe ColdFusion CWE-22 path-traversal RCE (CVSS 10.0), APSB26-68, actively exploited, CISA KEV 2026-07-07
- cve JoomShaper SP Page Builder unauth file-upload RCE (CVSS 10.0), CISA KEV zero-day
- cve Ubiquiti UniFi Connect unauthenticated command-injection RCE (CVSS 10.0), SAB-066
- cve Ubiquiti UniFi Talk authenticated SQL injection (CVSS 9.9), SAB-066
- cve Ubiquiti UniFi Access command injection (CVSS 9.9), SAB-066
- cve Ubiquiti UniFi OS command injection (CVSS 9.9), SAB-066
- cve Ubiquiti UniFi OS path-traversal auth-bypass (CVSS 8.6), chainable, SAB-066
- cve Ubiquiti UniFi Protect SSRF privilege escalation (CVSS 9.9), SAB-066
- cve Langflow cross-tenant IDOR (CWE-639), actively exploited, CISA KEV, chained with RCE CVE-2026-33017
- cve Joomlack Page Builder CK unauth file-upload RCE (CVSS 10.0), CISA KEV zero-day
- cve cve-search unauthenticated /fetch_cve_data parameter manipulation exposes admin credential hashes
- tool Avalon
- tool PamStealer
- cve Langflow /api/v1/validate/code missing-auth RCE, initial access for the JADEPUFFER agentic ransomware operation
- incident Medtronic breach×2
- incident Pegasus infection of PEGA-Committee MEP Stelios Kouloglou
- cve WatchGuard Fireware OS iked pre-auth use-after-free RCE (IKEv2/LDAP path, CVSS 9.2)
- cve Cisco Catalyst Center unauthenticated path-traversal arbitrary file read (CVSS 7.5; dropped from §2, awareness only)
- cve Coolify authenticated OS command injection to RCE + secrets exfil (CVSS 9.9)
- cve Control Web Panel pre-auth blind SQLi to web-shell RCE via INTO DUMPFILE (CVSS 9.8)
- campaign Trojanised ScreenConnect AsyncRAT campaign
- trend Argo CD repo-server unauthenticated RCE
- cve Altium Enterprise Server / Altium 365 Git Service CWE-22 path-traversal to RCE (CVSS 9.4)
- cve Adobe ColdFusion CWE-434 unrestricted file-upload RCE (CVSS 10.0), APSB26-68
- cve Adobe ColdFusion CWE-20 improper-input-validation RCE (CVSS 10.0), APSB26-68
- cve Adobe ColdFusion CWE-20 improper-input-validation RCE (CVSS 10.0), APSB26-68
- cve Adobe ColdFusion CWE-434 unrestricted file-upload RCE (CVSS 10.0), APSB26-68
- cve Adobe Campaign Classic CWE-863 incorrect-authorization code execution (CVSS 10.0), APSB26-69
- cve Adobe ColdFusion CWE-20 improper-input-validation RCE (CVSS 10.0), APSB26-68
- campaign Phantom Squatting
- tool Umbrij
- cve Citrix NetScaler ADC/Gateway 'CitrixBleed' session-token memory overread, cited as CVE-2026-8451 lineage context
- cve Citrix NetScaler ADC/Gateway memory-leak (CitrixBleed variant), cited as CVE-2026-8451 lineage context
- cve Citrix NetScaler ADC/Gateway, Management Interface unauthenticated arbitrary file read (CTX696604)
- cve Citrix NetScaler ADC/Gateway, memory overread when TCP TimeStamp enabled on LB/CS/VPN vserver (CTX696604)
- cve Citrix NetScaler ADC/Gateway, CTX696604 companion CVE
- cve Oracle PeopleSoft PeopleTools PSEMHUB pre-auth RCE (CVSS 9.8), zero-day exploited by UNC6240/ShinyHunters×2
- cve Citrix NetScaler ADC/Gateway, memory-management flaw (Gateway/DNS-proxy/AAA vserver), DoS/undefined control flow (CTX696604)
- campaign StegoAd
- incident Bumblebee → AdaptixC2 → Akira intrusion
- product Progress Kemp LoadMaster
- cve SzafirHost (KIR e-signature client) JAR parser confusion (JarFile vs JarInputStream, CWE-434) → native-library RCE past signature check; fixed v1.2.2
- cve Progress Kemp LoadMaster, OWASP CRS whitespace-padding file-upload extension-check bypass (high); same bulletin as CVE-2026-8037
- cve Linux kernel 'DirtyClone' LPE, SKBFL_SHARED_FRAG drop in __pskb_copy_fclone() + IPsec in-place decrypt; JFrog working exploit on Debian/Ubuntu/Fedora (CVSS 8.8)
- cve SimpleHelp RMM OIDC SSO auth bypass, forged-token full Technician session + MFA bypass; now actively exploited (CISA KEV 2026-06-29), Djinn infostealer via TaskWeaver loader (CVSS 10.0)×2
- cve n8n Dynamic Credentials EE, missing ownership/scope checks enable cross-tenant OAuth credential hijack/revoke (CVSS 8.9, GHSA-2j5h-858j-5mpf); NCSC-2026-0212
- cve n8n public API, editor-level users read other users' credentials in shared instances (CVSS 8.5); NCSC-2026-0212
- cve libssh2 pre-auth heap OOB write in ssh2_transport_read() (CVSS 9.2), public PoC released 2026-06-29; no fixed release tagged yet
- campaign 0DIN coding-agent prompt-injection chain
- incident KDDI email-platform breach
- cve Gogs argument-injection RCE (CVE-2026-52806); now actively exploited in K8s cryptojacking campaign (Wiz)
- campaign Bluekit PhaaS
- campaign BadBlocker
- cve Lantronix EDS5000 OS command injection to root (BRIDGE:BREAK; CISA KEV 2026-06-23)
- cve WinRAR path-traversal (referenced as initial-access exploit in Gamaredon GammaPhish/GammaWorm campaign, Sekoia 2026-06-01)×3
- cve ShapedPlugin WordPress Pro supply-chain backdoor (build/EDD pipeline compromise)
- cve Keycloak JWT algorithm confusion -> federated-user impersonation (CVSS 8.1)
- cve ILIAS 11.0 SQL injection in ilTrQuery learning-progress subsystem (no patch, PoC public)
- cve Cisco Unified Communications Manager WebDialer unauthenticated SSRF → OS-root file write (SIR Critical); fix 14SU6 / Release 15 COP×2
- cve Cisco Catalyst SD-WAN Manager command-injection to root; Mandiant confirms pre-disclosure zero-day exploitation; patched (chains CVE-2026-20127/-20182)×2
- cve Cisco Catalyst SD-WAN Manager web UI authenticated path traversal, arbitrary file write to root RCE; CISA KEV 2026-06-15×2
- cve Ubiquiti UniFi OS improper access control (chain step 1 to unauth root; CISA KEV 2026-06-23)
- cve Ubiquiti UniFi OS path traversal (chain step 2 to unauth root; CISA KEV 2026-06-23)
- cve Ubiquiti UniFi OS improper input validation/command injection to root (CISA KEV 2026-06-23, actively exploited)
- cve Linux kernel 'pedit COW' LPE, tc act_pedit out-of-bounds write poisons setuid-binary page cache; public weaponised PoC
- cve libssh2 infinite-loop pre-auth DoS via crafted SSH_MSG_EXT_INFO (CVSS 8.2)
- cve Gitea act_runner Docker container-hardening bypass to host escape (CVSS 9.4, public PoC)
- cve Keycloak group-admin to realm-admin privilege escalation
- cve Keycloak policy-enforcer authorization bypass via access-denied-page path (CVSS 8.1)
- cve Microsoft Exchange Server SSRF (ProxyLogon), cited in 2026-05-16 § 5 deep dive Background as precedent for on-prem Exchange exploitation pattern
- cve Openfire admin-console path-traversal auth bypass, StrikeShark/SharkLoader initial-access vector
- cve F5 BIG-IP TMUI unauthenticated RCE, StrikeShark/SharkLoader initial-access vector
- cve Fortinet FortiOS SSL-VPN out-of-bounds write RCE, StrikeShark/SharkLoader initial-access vector
- cve OSGeo GeoServer OGC-filter RCE, StrikeShark/SharkLoader initial-access vector
- cve GitLab Web IDE workbench stored XSS (CVSS 8.0), patched 19.1.1/19.0.3/18.11.6; assessed, did not clear §2 gate
- cve Amazon Q Developer (VS Code) auto-loads workspace .amazonq/mcp.json without consent, repo-planted code execution + AWS credential theft
- cve Cisco Catalyst SD-WAN Manager pre-auth RCE (UAT-8616 prior exploitation, Feb 2026)
- cve Cisco Catalyst SD-WAN Controller/Manager pre-auth authentication bypass (CVSS 10.0, actively exploited by UAT-8616)×3
- cve Check Point Security Gateway IKEv1 Remote Access/Mobile Access certificate-validation authentication bypass (CVSS 9.3), actively exploited by Qilin affiliate since 2026-05-07, CISA KEV×2
- actor Gamaredon×2
- cve GitLab EE Analytics Dashboard stored XSS (CVSS 8.7), patched 19.1.1/19.0.3/18.11.6; assessed, did not clear §2 gate
- cve GitLab repository-mirroring SSRF (CVSS 3.1), patched 19.1.1/19.0.3/18.11.6; low severity, did not clear §2 gate
- cve FFmpeg MagicYUV decoder heap OOB write (PixelSmash, CVSS 8.8), fixed FFmpeg 8.1.2; out-of-window this run
- campaign Cordyceps
- campaign Operation Endgame, Amadey/StealC takedown×2
- tool Edgecution
- tool Mistic
- cve Cacti <1.2.31, pre-auth SQLi in graph_view.php (rfilter); evaluated, dropped to § 7 (out-of-window, single GHSA)
- cve MISP <2.5.42, broken access control
- cve MISP <2.5.42, cross-org IDOR overwrite
- cve MISP <2.5.42, broken access control, cross-org hard-delete
- cve MISP <2.5.42, Azure-AD OAuth state-reuse session hijack
- cve MISP <2.5.42, NDJSON log-injection PHP RCE (site-admin)
- cve MISP <2.5.42, rdkafka plugin-load RCE (site-admin)
- cve Arista EOS tunnel-decapsulation logic flaw (CWE-1023) bypasses VXLAN segmentation; CISA KEV, exploited
- campaign Cloud-bucket hijacking via namespace reuse
- incident Transport for London 2024 intrusion
- cve SonicWall SonicOS improper access control (mgmt + SSLVPN, Gen 5/6/7), Akira/Fog ransomware on-ramp
- cve FortiGate credential-reuse vector referenced in FortiBleed campaign
- cve FortiGate credential-reuse vector referenced in FortiBleed campaign
- cve Gitea TOTP 2FA bypass (web TOCTOU + X-Gitea-OTP replay)
- cve Gitea SSRF in webhook / repo-migration subsystems
- cve FortiGate credential-reuse vector referenced in FortiBleed campaign
- cve Gitea protected-branch enforcement race (single-push batch)
- cve DifyTap, Dify AI platform cross-tenant authorization bypass (evaluated, dropped § 7: authenticated, no ITW, aggregator-only primary)
- cve Microsoft 365 Copilot Business Chat open redirect (BSI WID-SEC-2026-2020; server-side mitigated, dropped § 7)
- cve Squidbleed, 29-year-old heap over-read in Squid FTP gateway leaks cross-user HTTP credentials
- cve ShapedPlugin supply-chain backdoor, duplicate CVE submission for CVE-2026-10735 (noted § 7)
- cve Microsoft 365 Copilot missing-authentication info disclosure (BSI WID-SEC-2026-2020; server-side mitigated, dropped § 7)
- campaign AryStinger
- cve Linksys/D-Link RTL819X command-injection RCE, initial-access vector for the AryStinger botnet
- cve D-Link DIR-850L HTTP-service stack buffer overflow RCE, AryStinger botnet access vector
- cve QNAP Malware Remover code injection (fixed 6.6.8.20251023), AryStinger NAS access vector
- campaign Icarus Salesforce OAuth extortion
- campaign Popa residential-proxy botnet
- campaign Prinz Eugen
- cve Windows Boot Manager Secure Boot bypass (BlackLotus-class), possible FishMonger SprySOCKS UEFI component (unconfirmed)
- cve Rockwell FactoryTalk Historian Site Edition, authentication bypass (CVSS 7.7)
- cve PAN-OS GlobalProtect pre-auth authentication bypass×2
- cve Rockwell 1794-AENTR/AENTRXT FLEX I/O, CIP-handling denial-of-service (CVSS 7.5)
- cve Rockwell 1794-AENTR/AENTRXT FLEX I/O, unauthenticated web-interface password reset (CVSS 9.4)
- cve UpdraftPlus WordPress plugin unauthenticated auth-bypass to RCE (all-zero AES key on failed RSA decrypt), CVSS 8.1; actively exploited
- cve Rockwell CompactLogix/ControlLogix 5370/5570, CIP message major non-recoverable fault DoS (CVSS 7.5)
- cve pgAdmin 4, unauthenticated pickle.loads RCE primitive in SQL Editor (server mode, CVSS v4 9.5)
- cve Cisco ISE / ISE-PIC, authenticated path-traversal OS command execution to root (CVSS 9.1)×2
- cve Cisco ISE / ISE-PIC, unauthenticated read of sensitive data incl. hashed admin credentials (CVSS 7.5)×2
- cve Splunk Enterprise pre-auth RCE via unauthenticated PostgreSQL sidecar REST API proxied by web tier, CVSS 9.8×2
- cve Google Cloud Vertex AI SDK, predictable staging-bucket cross-tenant pickle RCE ('Pickle in the Middle'); patched 1.148.0
- cve FortiSandbox unauthenticated OS command injection in VNC handler (CVSS 9.8); dropped from brief - no inclusion gate cleared
- cve Oracle PeopleSoft PeopleTools 8.61/8.62 Performance Monitor, missing-auth RCE (CVSS 9.8)
- cve Fortinet FortiSandbox, JRPC API OS command injection (CVSS 9.8); actively exploited
- cve Fortinet FortiSandbox, JRPC API path traversal / auth bypass (CVSS 9.1); actively exploited
- cve Gravity SMTP WordPress plugin unauthenticated info-disclosure (email-connector credential dump), mass-exploited
- cve AVer PTC500S/PTC115/PTC500+/PTC115+ cameras, unauthenticated RCE via management web interface (CVSS 9.8), CISA ICSA-26-169-01
- cve NGINX, heap overflow in ngx_http_proxy_v2_module/ngx_http_grpc_module (CVSS v4 9.2)
- cve NGINX, HTTP/3 QUIC use-after-free in ngx_http_v3_module (CVSS v4 9.2)
- cve Microsoft 365 Copilot Enterprise Search 'SearchLeak' command-injection/info-disclosure; one-click exfil; patched server-side
- cve Oracle Solaris 11.4 Remote Administration Daemon, unauthenticated flaw (CVSS 10.0), Oracle June 2026 CSPU
- cve phpBB OAuth improper-authentication account hijack (admin) even when OAuth disabled; CVSS 9.8; fixed 3.3.17
- cve Widget Factory Joomla Content Editor (JCE) <2.9.99.5, unauthenticated profile-import to PHP RCE (CVSS v4 10.0); CISA KEV
- cve LiteSpeed cPanel/WHM plugin symlink-following on CloudLinux/CageFS shared hosting; exploited ITW May 2026; CISA KEV
- cve Drupal core, JSON:API PHP object injection (SA-CORE-2026-005, critical)
- cve Drupal core, deserialization gadget chain (SA-CORE-2026-006)
- incident Kodak breach
- tool usbliter8
- trend AutoJack
- trend Gogs argument-injection RCE×2
- campaign Cl0p PTC Windchill / FlexPLM extortion campaign (2026)
- campaign CryptoBandits
- campaign Cybercrime-underground AI adoption
- incident Operation Endgame, SocGholish expansion
- cve pgAdmin 4, AI Assistant read-only-transaction bypass to RCE via COPY TO PROGRAM (CVSS v4 9.4)
- cve pgAdmin 4, stored XSS via unsanitised PostgreSQL error/EXPLAIN content (CVSS v4 9.3)
- cve Drupal core, rebuild.php trusted-host bypass (SA-CORE-2026-007)
- cve Drupal core, Media module oEmbed SSRF (SA-CORE-2026-008)
- cve Drupal core, JSON:API/REST image-upload MIME-validation gap (SA-CORE-2026-009)
- incident FortiBleed
- trend Zammad 7.1 security release
- actor Webworm×2
- campaign DragonForce Backdoor.Turn intrusion
- campaign ErrTraffic
- campaign Rokarolla
- cve WP File Manager pre-auth RCE, used as fallback vector in the ErrTraffic ClickFix framework
- cve Topaz Antifraud wsftprm.sys vulnerable kernel driver, DragonForce BYOVD chain
- cve K7 Security K7RKScan.sys vulnerable kernel driver, DragonForce BYOVD chain
- cve React/Next.js Server Actions deserialisation ("React2Shell"), weaponised by PCPJack worm
- cve Tower of Fantasy GameDriverx64.sys vulnerable kernel driver, DragonForce BYOVD chain
- actor UAT-8616×4
- cve Splunk Secure Gateway jsonpickle deserialization RCE (CVSS 8.8), assessed, no §2 gate (no ITW, post-auth); NCSC-NL advisory
- cve LiteLLM Custom Code Guardrails sandbox escape to RCE via exec()/bytecode; CVSS 8.8; fixed v1.83.14
- cve LiteLLM authorization bypass via unvalidated allowed_routes in key-generation; CVSS 8.8; fixed v1.83.14
- cve LiteLLM privilege escalation, self-promote to proxy_admin via /user/update; CVSS 8.8; fixed v1.83.14
- cve phpBB OAuth improper state verification + CSRF session hijack; CVSS 8.0; fixed 3.3.17
- cve GitLab EE Analytics Dashboard stored XSS (CVSS 8.7), assessed, no §2 gate
- cve OpenSSL CMS AuthEnvelopedData integrity bypass (moderate), assessed, out-of-window, not promoted
- cve Traefik v3.x security-policy bypass (GHSA-3g6v-2r68-prfc), assessed, no §2 gate, out-of-window
- cve Adobe ColdFusion unauthenticated no-interaction RCE (CVSS 9.6, APSB26-64; scope change S:C; fixed 2023 Update 20 / 2025 Update 9)
- cve Adobe ColdFusion path-traversal security-feature bypass (CVSS 8.8, APSB26-64), co-disclosed; assessed, not promoted
- cve GitLab CE/EE Grape API unauthenticated DoS (CVSS 7.5), assessed, no §2 gate
- cve GitLab CE/EE Gitaly repository-import SSRF (CVSS 5.3), assessed, no §2 gate
- incident Conti developer Lytvynenko guilty plea
- incident Cyber Europe 2026
- cve Windows Cloud Filter driver cldflt.sys privilege escalation (MiniPlasma PoC)
- cve Windows Print Spooler privilege escalation weaponised by APT28 GooseEgg (cited as historical context in Sekoia APT28 retrospective)
- cve LangGraph SQLite checkpointer SQL injection in get_state_history() (CVSS 7.3; fixed langgraph-checkpoint-sqlite 3.0.1)
- cve Ivanti Sentry pre-auth OS command injection to root (MICS handleMessage), CVSS 10.0; public PoC by watchTowr
- cve Ivanti Sentry authentication bypass (CWE-288), companion to CVE-2026-10520
- cve Google Chrome V8 out-of-bounds read/write, exploited ITW, CISA KEV; fixed 149.0.7827.103
- cve BUK TS-G gas-station automation unauthenticated admin bypass, CVSS 9.8 (dropped from brief, aggregator-only sourcing)
- cve Linux kernel nf_tables use-after-free in nft_map_catchall_activate() (single-character genmask inversion), local-root + container escape, working public exploit (Exodus Intelligence), patched upstream 2026-02-05, CVSS 7.8
- cve LangGraph unsafe msgpack deserialization on checkpoint load, chains with SQLi to RCE (CVSS 6.8; fixed langgraph 1.0.10)
- cve Everest Forms Pro (WordPress) Calculation Addon unauthenticated eval() PHP code injection (CVSS 9.8); mass exploitation since 2026-04-13 creating rogue admin accounts; patched v1.9.13 (2026-03-18)×2
- cve Windows Netlogon stack buffer overflow, unauthenticated remote RCE to SYSTEM on domain controllers (CVSS 9.8, May 2026 Patch Tuesday); active ITW exploitation confirmed by CCB Belgium 2026-06-01×2
- cve SAP NetWeaver AS ABAP SAML XML Signature Wrapping (CVSS 9.9), SAP_BASIS 702-919
- cve Veeam Backup & Replication 12.x authenticated domain-user deserialization RCE (CVSS 9.4); fixed 12.3.2.4854
- cve Windows YellowKey BitLocker bypass via WinRE×2
- cve Windows CTFMON elevation of privilege (June 2026 Patch Tuesday); referenced in § 7 GreenPlasma cross-source discrepancy note
- cve Windows kernel TCP/IP use-after-free network RCE to SYSTEM (CVSS 9.8)
- cve vm2 Node.js sandbox escape via WebAssembly JSPI Promise-species bypass, CVSS 9.8 (dropped from brief, out-of-window, no ITW)
- cve TYPO3 Core June 2026 (TYPO3-CORE-SA-2026-006), XSS bypassing the HTML Sanitizer; lead CVE of the 13-advisory batch
- cve strongSwan libstrongswan identity-clone double-free, unauth RCE over EAP; fixed 6.0.7
- cve Acer Wave-7 mesh router broken access control, unauthenticated cleartext credential log acer_cgi.log exposure (CVSS 10.0, no patch until ~end-June 2026)
- cve Acer Wave-7 mesh router hardcoded AES key in upload.cgi backup handler, persistent backdoor injection (CVSS 10.0, no patch until ~end-June 2026)
- cve MariaDB Server Galera wsrep_notify_cmd OS command injection (CVSS 10.0)
- cve Langflow path traversal (POST /api/v2/files) -> arbitrary file write, pre-auth via default auto-login, exploited ITW
- campaign Agentjacking
- campaign Atomic Arch
- campaign Velvet Ant Operation Highland
- cve LangGraph Redis checkpointer RediSearch query injection (CVSS 6.5; fixed @langchain/langgraph-checkpoint-redis 1.0.1)
- cve OpenSSL PKCS7_verify heap use-after-free on empty SignedData.digestAlgorithms (High; fixed 4.0.1/3.6.3/3.5.7/3.4.6/3.0.21); out-of-window drop this run
- cve GitLab EE Group SAML identity API improper authorization, Group Owner account takeover (CVSS 8.7; fixed 19.0.2/18.11.5/18.10.8), did not clear daily section-2 gate
- actor OceanLotus
- campaign IronWorm×2
- campaign OpenClaw agent-phishing disclosures
- trend GreatXML
- cve Nuance PowerScribe unauthenticated deserialization RCE (CVSS 9.8)
- cve Azure Stack Edge external file path control RCE (CVSS 9.8)
- cve MariaDB Galera wsrep parameter-injection (companion fix to CVE-2026-49261)
- cve MariaDB Galera wsrep parameter-injection (companion fix to CVE-2026-49261)
- cve Exchange Online improper-authorisation information disclosure (CVSS 9.1, service-side fix)
- actor VerdantBamboo×4
- campaign JDY botnet
- campaign ShinyHunters PeopleSoft campaign
- report CrowdStrike 2026 Technology Threat Landscape Report
- cve Fortinet FortiClient EMS 7.4.5/7.4.6; improper-access-control on X-SSL-CLIENT-VERIFY header lets unauth attacker spoof mTLS state and reach management API; ITW exploited to push EKZ Infostealer per Arctic Wolf 2026-05-27×2
- cve Windows BitLocker physical-access bypass, publicly disclosed, June 2026 Patch Tuesday
- campaign Ghost-Sender
- campaign Job-seeker targeting wave (CH)
- campaign Security-tool impersonation TDS campaign
- report Dragos Q1 2026 Industrial Ransomware Analysis
- trend Entra Agent ID OBO abuse×2
- product Microsoft Windows Server (HTTP.sys/IIS)
- cve SAP Commerce Cloud / Data Hub missing HTTP security headers via Spring Security (CVSS 9.1)
- cve SAP NetWeaver/ABAP RFC kernel memory corruption, unauthenticated (CVSS 9.8)
- cve SAP NetWeaver AS Java Web Container path traversal (CVSS 9.0)
- cve Windows DHCP Client Service RCE (CVSS 9.8), June 2026 Patch Tuesday
- cve Visual Studio Code EoP to SYSTEM via malicious .code-workspace (CVSS 9.6)
- cve Windows HTTP.sys HTTP/2 compression-bomb DoS (IIS analogue of CVE-2026-49975); MaxHeadersCount mitigation
- cve HTTP/2 Bomb, HPACK dynamic-table amplification + Slowloris stream-hold memory-exhaustion DoS vs nginx/Apache/IIS/Envoy/Pingora; nginx 1.29.8 & Apache mod_http2 2.0.41 patched, IIS/Envoy/Pingora unpatched at disclosure
- actor Fox Tempest×2
- campaign Mini Shai-Hulud×8
- cve Check Point IKEv1 site-to-site VPN MitM via certificate validation weakness (CVSS 7.4), no observed exploitation
- campaign C0XMO
- campaign FIFA World Cup 2026 pre-event threat cluster
- cve DD-WRT UPnP/SSDP parser stack buffer overflow, FortiGuard-attributed propagation vector for C0XMO/Gafgyt botnet; DOES NOT RESOLVE ON NVD/MITRE (flagged 2026-06-08, vendor-attributed/unverified)
- cve Google Chrome ANGLE graphics engine out-of-bounds read/write → sandbox escape (CVSS 9.6); Chrome 149 record 429-patch release
- cve Keycloak CORS ACAO reflected from unverified JWT azp claim on UMA endpoint (fixed 26.6.3)
- cve FFmpeg parser/demuxer heap or stack overflow (depthfirst AI-agent discovery; PoC public, fixed upstream)
- cve FFmpeg parser/demuxer heap or stack overflow (depthfirst AI-agent discovery; PoC public, fixed upstream)
- cve FFmpeg parser/demuxer heap or stack overflow (depthfirst AI-agent discovery; PoC public, fixed upstream)
- cve FFmpeg parser/demuxer heap or stack overflow (depthfirst AI-agent discovery; PoC public, fixed upstream)
- cve FFmpeg parser/demuxer heap or stack overflow (depthfirst AI-agent discovery; PoC public, fixed upstream)
- cve FFmpeg parser/demuxer heap or stack overflow (depthfirst AI-agent discovery; PoC public, fixed upstream)
- cve FFmpeg parser/demuxer heap or stack overflow (depthfirst AI-agent discovery; PoC public, fixed upstream)
- cve FFmpeg parser/demuxer heap or stack overflow (depthfirst AI-agent discovery; PoC public, fixed upstream)
- cve FFmpeg parser/demuxer heap or stack overflow (depthfirst AI-agent discovery; PoC public, fixed upstream)
- cve Keycloak SSRF via OIDC token endpoint manipulation (fixed 26.6.3)
- cve Keycloak missing server-side WebAuthn credential-registration validation (fixed 26.6.3)
- cve Keycloak token-exchange privilege escalation via silent subject_token removal (fixed 26.6.3)
- cve Keycloak ROPC grant bypass of client-policy enforcement (fixed 26.6.3)
- cve Keycloak refresh-token replay window after server restart resets startupTime (fixed 26.6.3)
- actor OP-512
- campaign Silent Ransom Group physical USB intrusions×2
- cve MISP access-control bypass exposing private galaxy metadata to non-admin org users (CVSS 5.3)
- cve MISP mass-assignment account-takeover in UsersController::edit() (CVSS 9.0, patched 2026-06-04)
- cve SolarWinds Serv-U uncontrolled resource consumption, unauthenticated DoS via Content-Encoding: deflate (CISA KEV 2026-06-05)
- campaign Operation FlutterBridge
- cve Redis use-after-free in unblockClientOnKey() → GOT-overwrite RCE (post-auth; default-passwordless)
- cve Simple SA Wirtualna Uczelnia unauthenticated SSTI → RCE (redirectToUrl)
- cve Simple SA Wirtualna Uczelnia reflected XSS (locale parameter)
- cve OpenStack Mistral policy-enforcement bypass → authenticated arbitrary code execution (OSSA-2026-020; evaluated and dropped, see brief §7)
- campaign DesckVB RAT malspam
- campaign Stock-exchange mailbox espionage
- incident Booking.com-fed hotel phishing (CH)
- cve MISP OTP bypass, session established in beforeFilter before OTP when LdapAuth.mixedAuth+require_otp both on; fix commit 39b3cb15 / >=2.5.37
- cve Windows Snipping Tool ms-screensketch: URI handler NTLM hash leak, patched April 2026; cited as structural predecessor of unpatched search: URI variant
- cve Microsoft 365 Copilot for Android OAuth-token theft via production debug flag (CVSS 4.4); patched 2026-05-12
- cve Microsoft Word for Android OAuth-token theft via production debug flag (CVSS 7.1); patched 2026-05-12
- cve Microsoft PowerPoint for Android OAuth-token theft via production debug flag (CVSS 7.1); patched 2026-05-12
- cve Microsoft Excel for Android OAuth-token theft via setIsDebugMode(true) debug flag left in production (CVSS 7.7); patched 2026-05-12
- cve Mirasvit Full Page Cache Warmer (Magento 2) unauthenticated PHP object-injection RCE via CacheWarmer cookie; CISA KEV 2026-06-03, ITW from 2026-04-24; fix v1.11.12
- cve Progress Sitefinity CMS web-services improper input validation (CWE-20); BSI WID-SEC-2026-1783
- cve Progress Sitefinity CMS OData improper input validation (CVSS 9.8, CWE-20), affects 15.4.8623-15.4.8629; BSI WID-SEC-2026-1783
- cve Progress Sitefinity CMS ServiceStack web-services credential exposure (CVSS 8.8, CWE-522); BSI WID-SEC-2026-1783
- cve Progress Sitefinity CMS, CWE-522 Insufficiently Protected Credentials (Sitefinity Insight credential disclosure, gated on Insight integration/non-default config); CVSS 10.0 per NVD; BSI WID-SEC-2026-1783; evaluated 2026-06-04, dropped to §7 (no fetchable vendor primary, no ITW)
- cve Progress Sitefinity CMS legacy-branch flaw (CVSS 8.7), affects v8.0-13.3; BSI WID-SEC-2026-1783
- cve Devolutions Server LDAP coercion exposing PAM credentials (DEVO-2026-0013, CVSS 7.1); evaluated 2026-06-04, dropped to §7 (no ITW, below §2 gate)
- cve Burst Statistics WordPress 3.4.0-3.4.1.1 unauthenticated REST auth-bypass (is_mainwp_authenticated) → admin impersonation/rogue admin; actively exploited; fix v3.4.2
- cve Kirki WordPress Freeform Page Builder 6.0.0-6.0.6 unauthenticated password-reset hijack → admin account takeover; actively exploited; fix v6.0.7
- cve Devolutions Server MFA bypass via improper factor-key state handling (DEVO-2026-0013, CVSS 7.5); evaluated 2026-06-04, dropped to §7 (no ITW, below §2 gate)
- campaign Operation XENOFISCAL
- report Sophos 2026 Active Adversary Report
- cve Linux kernel cgroup v1 release_agent container escape (missing CAP_SYS_ADMIN check); CISA KEV 2026-06-02
- cve Oracle WebLogic Server unauth T3/IIOP data access (CVSS 7.5); CISA KEV 2026-06-01 on active exploitation
- cve Android Framework integer-overflow LPE (no-interaction), limited targeted exploitation; June 2026 bulletin
- cve Trend Micro Apex One On-Premise relative path traversal fleet-wide code injection
- cve Windows Hyper-V UAF guest-to-host escape (May 2026 Patch Tuesday); evaluated 2026-06-03, not covered (out-of-window)
- cve Windows DNS Client (dnsapi.dll) heap buffer overflow, RCE via malicious DNS response (CVSS 9.8, May 2026 Patch Tuesday)
- cve Digital Knowledge KnowledgeDeliver LMS, pre-shared ASP.NET machineKey ViewState deserialization RCE; exploited as zero-day pre-2026-02-24
- campaign Operation Dragon Weave
- cve KAMSOFT KS-SOMED healthcare software, hardcoded FTP credentials in update client allow malicious-update injection / supply-chain (CVSS 4.0 8.7, CERT-PL)
- cve Apache Solr 9.4.0-9.10.1/10.0.0, hardcoded BasicAuth template credentials allow unauthenticated remote admin (CVSS 8.1, BSI WID-SEC-2026-1740); no patch yet, manual workaround
- cve CIFSwitch, Linux kernel CIFS/SMB-client LPE to root via forged cifs.spnego key requests (19-year-old bug; RHEL9/SLES15/Mint/Kali); dropped from 2026-06-02 brief as out-of-window + no Section 2 gate
- cve WP Maps Pro WordPress plugin <=6.1.0, unauthenticated admin-account creation via disclosed nonce + wp_ajax_nopriv_ handler; actively exploited (CVSS 9.8); fixed 6.1.1
- cve Disig Web Signer 2.0.3-2.5.3, unauthenticated RCE in Slovak eIDAS qualified-signature client (CVSS 4.0 9.4, SK-CERT); fixed 2.5.5
- campaign Italian low-cost commercial spyware
- campaign SmartApeSG ClickFix campaign
- campaign TrapDoor×3
- cve Oracle E-Business Suite, May 2026 CPU critical (referenced in §7, dropped)
- cve Oracle E-Business Suite, May 2026 CPU critical (referenced in §7, dropped)
- cve Oracle E-Business Suite, May 2026 CPU critical (referenced in §7, dropped)
- cve Oracle E-Business Suite, May 2026 CPU critical (referenced in §7, dropped)
- cve Delta Electronics DIAView SCADA, unauthenticated remote database access (predecessor to CVE-2026-9642 mitigation bypass)
- cve Ghost CMS Content API unauthenticated SQLi (CVSS 9.4); ITW-exploited in ClickFix campaign; fixed 6.19.1×2
- cve Veeam Agent for Microsoft Windows, local privilege escalation enabling arbitrary command execution / lateral movement (CVSS 7.3)
- cve Veeam Software Appliance (Linux); authenticated Backup Administrator can write arbitrary files (CVSS 8.6)
- cve QuickCMS (OpenSolution) session fixation, CERT-PL; dropped (niche, CVSS 4.8)
- cve QuickCMS (OpenSolution) MITM-XSS via HTTP plugin fetch, CERT-PL; dropped (niche, CVSS 2.3)
- cve Slican PBX administrative protocol authentication bypass, attacker bypasses login by executing a specific command; CVSS 4.0: 9.3; CERT Polska disclosure 2026-05-27
- cve Slican PBX deterministic secure-key generation from publicly-obtainable system properties, admin credentials recoverable without auth; CVSS 4.0: 8.7; CERT Polska
- cve Slican PBX remote management modem interface, hardcoded caller-ID bypasses admin auth and temporarily re-enables remote access when configured off; CVSS 4.0: 9.3; CERT Polska
- cve SUSE Rancher; project-owner role can flip namespace PSA labels to privileged, enabling container-to-host escape (CVSS 8.4)
- cve SUSE Rancher GitHub App auth, group principals granted for every team in GitHub org to any team-belonging user (CVSS 8.8)
- cve Samba SAMR RPC server, unauthenticated shell injection via %u substitution in check password script (CVSS 10.0)
- cve Samba print-command subsystem, unauthenticated shell injection via %J substitution; raw/classic printing only (CVSS 10.0)
- cve Portainer CE, Docker plugin endpoints not registered in proxy authorization handler; non-admin can install/enable plugins → root host execution (CVSS 9.4)
- cve Portainer CE Docker Swarm service API, EndpointSecuritySettings restrictions not enforced; non-admin escapes to host via privileged containers (CVSS 9.4)
- cve SUSE Rancher cluster-import endpoint, command injection via URL-encoded newline in authImage YAML field; control-plane node RCE (CVSS 9.6)
- cve Mautic API contact-filtering SQL injection (post-auth)
- cve LiteSpeed User-End cPanel plugin lsws.redisAble priv-esc to root (CVSS 10.0, ITW)
- cve GitLab CE/EE Duo AI integration, improper user identity resolution allows authenticated user to impersonate another user when triggering Duo AI workflows (CVSS 8.2)
- cve Roundcube Webmail pre-auth SQL injection in virtuser_query plugin via preg_replace backslash escape bypass; CVSS 8.1; patched in 1.6.16 LTS / 1.7.1
- cve Ivanti Secure Access Client local privilege escalation
- cve Szafir SDK (KIR) improper certificate verification / auth bypass, Polish qualified e-signature SDK; fixed v463
- cve IBM HTTP Server / WebSphere Application Server, pre-auth RCE via improper input validation in HTTP request parser (CVSS 9.8); NCSC.ch flagged 2026-05-28
- cve GitHub Enterprise Server < 3.22, unauthenticated SSRF via upload-endpoint path traversal exposes internal services and credentials (CVSS 4.0 = 9.2; GHSA-fwfp-h68w-2hcr)
- cve Mautic Focus component SSRF (post-auth; reaches internal/cloud-metadata)
- cve Mautic stored XSS (post-auth)
- cve Mautic stored XSS / JS injection (post-auth)
- cve Delta Electronics DIAView SCADA, incomplete fix / mitigation bypass of CVE-2025-62582 unauthenticated remote database access (CVSS 3.1 = 9.8; Tenable TRA-2026-44)
- cve Mautic file inclusion / path traversal (post-auth)
- cve Mautic path traversal / file manipulation (post-auth)
- cve Mautic JavaScript code injection (post-auth)
- actor GREYVIBE
- campaign ChatGPhish
- campaign Ghost Stadium PhaaS
- campaign LLMShare
- report ESET APT Activity Report Q4 2025 – Q1 2026
- campaign Asocks residential-proxy takedown
- campaign JINX-0164
- cve Gogs prior argument-injection variant (referenced in Rapid7 2026-05-29 disclosure as same-class predecessor)
- cve GitLab CE/EE, Wiki DoS via insufficient validation of malformed markup (CVSS 6.5)
- cve GitLab EE; Developer-role users can access deployment data (pipeline environment variables, deployment keys) via missing authorization checks (CVSS 4.3)
- cve Gogs argument-injection RCE (CVE id claimed by S3 sub-agent, unverified against authoritative NVD entry; Rapid7 publication states no CVE assigned at disclosure; deferred to next-run verification)
- cve GitLab CE/EE, seventh CVE in 19.0.1 / 18.11.4 / 18.10.7 patch release (defender-relevance not enumerated; left to vendor page)
- cve GitLab EE; Developer-role users can bypass group-level flow restrictions when foundational flows enabled (CVSS 4.3)
- cve GitLab CE/EE, unauthenticated enumeration of private project paths via API (CVSS 5.3)
- cve GitLab CE/EE; Authenticated users can access CI data from unintended reference types via incorrect reference resolution (CVSS 4.3)
- cve IBM HTTP Server Administration Server, heap-based buffer overflow (CVSS 8.0)
- cve IBM HTTP Server mod_ibm_upload, DoS via NULL pointer dereference (CVSS 7.5)
- cve IBM HTTP Server mod_mem_cache, DoS via expired pointer dereference (CVSS 7.5)
- cve IBM HTTP Server, RCE in TLS mutual-authentication configurations (CVSS 8.1)
- cve IBM HTTP Server, DoS via uncontrolled resource consumption (CVSS 7.7)
- actor Ababil of Minab
- campaign GlassWorm takedown
- campaign AI-chatbot search-poisoning cryptojacking
- campaign Akira kill-chain reconstruction (SANS ISC)
- incident AFC Ajax fan-data breach
- trend ILIAS LMS May 2026 fixes
- cve Gitea container registry access-control failure, private repo container images unauthenticatedly pullable across all versions < 1.26.2 (4-year exposure window); Forgejo confirmed affected; § 7 drop 2026-05-28
- cve TanStack Router npm credential-stealing payload, exfiltrated Nx contributor GitHub CLI OAuth token (precursor to CVE-2026-48027 Nx Console compromise); CISA KEV 2026-05-27
- cve Nx Console v18.95.0 VS Code extension supply-chain compromise, credential-stealing payload harvested 1Password, Claude Code config, npm, GitHub, AWS creds; CISA KEV 2026-05-27
- cve Roundcube Webmail CSS sanitisation failure via SVG animate attributeName=style, info disclosure / SSRF in HTML email rendering; patched in 1.6.16 LTS / 1.7.1
- cve Roundcube Webmail code injection via LDAP autovalues option; arbitrary PHP code evaluation when option is configured; patched in 1.6.16 LTS / 1.7.1
- cve Roundcube Webmail HTML sanitisation bypass via SVG document permitting CSS injection; patched in 1.6.16 LTS / 1.7.1
- cve DAEMON Tools Lite signed-build trojanisation (12.5.0.2421–12.5.0.2434) via Disc Soft Limited build infrastructure; CISA KEV 2026-05-27
- cve NGINX ngx_http_rewrite_module heap buffer overflow, out-of-bounds write in worker process memory pool via overlapping regex capture groups; CVSS v3.1 8.1 / v4.0 9.2; exploitation attempts per NCSC-NL; § 7 drop (primary 2026-05-22 out-of-window)
- incident DentaQuest
- cve yoda-digital mcp-gitlab-server < 0.6.0, no-auth SSE RPC endpoint bound to 0.0.0.0 with wildcard CORS exposes operator GitLab PAT (CVSS 4.0 = 9.2; GHSA-8jr5-6gvj-rfpf); noted in § 7 (niche package)
- tool RemotePE
- trend Underminr
- cve SonicWall Gen6 SSL-VPN MFA bypass via UPN vs SAM account-name split; Akira-linked actors exploited Feb-Mar 2026; firmware update insufficient without 6-step LDAP reconfiguration
- cve Erlang SSH RCE (Cisco context), confirmed by Check Point Research as initial-access CVE for The Gentlemen RaaS
- cve Langflow CORS misconfiguration + SameSite=None refresh token theft
- cve Palo Alto PAN-OS Captive Portal unauthenticated root RCE (CVSS 9.3, ITW, KEV deadline 2026-05-09)×3
- cve Cisco Secure Workload internal REST API zero-auth Site Admin CVSS 10.0
- cve SEPPmail Secure E-Mail Gateway, pre-auth path traversal in LFT /v1/file.app → arbitrary file write as nobody → RCE via /etc/syslog.conf overwrite
- cve Linux kernel RxGK rxgk_decrypt_skb() page-cache write (missing COW guard), DirtyDecrypt LPE; affects Fedora / Arch / openSUSE Tumbleweed (CONFIG_RXGK=y)
- cve Microsoft Defender Malware Protection Engine, link-following EoP to SYSTEM (CWE-59); Engine ≤ 1.1.26030.3008; actively exploited
- cve Sparx Pro Cloud Server, authenticated SQL injection via database API endpoint; PCS ≤ 6.1
- cve Sparx Pro Cloud Server, pre-auth bypass via model-parameter omission in POST binary blob → unauthenticated SQL query execution; CVSS4 9.3
- cve Sparx Enterprise Architect ≤ 17.1, client-side RBAC bypass via EA client binary patch (CWE-603); CVSS4 8.7
- cve Sparx Pro Cloud Server WebEA, race condition in /data_api/dl_internal_artifact.php → RCE in web-server context (CWE-362); CVSS4 7.7
- cve Sparx Pro Cloud Server, malformed SQL crash (DoS); CWE-835
- cve n8n self-hosted automation, xml2js prototype pollution (CWE-1321), root of authenticated-to-RCE chain via Git node SSH×2
- cve Microsoft Azure Local Disconnected Operations (ALDO), CVSS 10.0 unauthenticated network elevation-of-privilege; MSRC Exploitation More Likely
- cve vm2 Node.js sandbox, host-object access via BaseHandler.getPrototypeOf trap; sandbox escape to host context; CVSS 10.0; patched 3.11.0
- cve Microsoft Defender Antivirus local DoS, exploited alongside CVE-2026-41091 in combined out-of-band engine update 4.18.26040.7
- cve Microsoft Defender Malware Protection Engine, heap-based buffer overflow over network → unauthenticated RCE in Defender process context; CVSS 8.1
- cve ChromaDB Python FastAPI server pre-auth RCE via embedding-function model loading before auth check (CVSS 4.0 = 10.0; v1.5.9 unpatched at disclosure)
- cve Keycloak OIDC login flow session fixation enabling account takeover (Keycloak 26.6.2; BSI WID-SEC-2026-1612 HIGH)
- cve Drupal core highly-critical pre-auth SQL injection in database abstraction API on PostgreSQL backends; CISA KEV-listed 2026-05-22 (SA-CORE-2026-004)
- campaign Megalodon×3
- campaign Packagist Laravel-Lang supply-chain wave
- trend Software-exposed BYOVD hardware-gate bypass
- cve Stormshield SNS remote DoS (CERTFR-2026-AVI-0631); dropped from §2, mentioned in §7
- cve NLnet Labs Unbound DNSSEC validator UAF (CVSS 9.8), fixed 1.25.1
- cve ISC BIND 9 DoH use-after-free (CVSS 7.4), fixed 9.20.23
- cve Keycloak OIDC token introspection endpoint does not enforce audience restriction; lightweight access tokens leak claims cross-client (Keycloak 26.6.2)
- cve Keycloak execute-actions token replay enabling unauthorised WebAuthn / FIDO2 credential enrollment on victim account (Keycloak 26.6.2)
- cve NLnet Labs Unbound heap overflow, default-config (CVSS 8.6), fixed 1.25.1
- cve Keycloak Authorization Services Protection API cross-realm IDOR allowing realm-A authenticated attacker to access realm-B resources (Keycloak 26.6.2)
- cve ssh-keysign-pwn; 9-year ptrace race in Linux kernel __ptrace_may_access() reaches root + SSH host-key exfiltration; four public Qualys exploits on default major distros
- cve ISC BIND 9 non-Internet CLASS DoS (CVSS 7.5), fixed 9.18.49/9.20.23
- incident Kimwolf DDoS-for-hire arrest
- report Check Point AI Threat Landscape Digest (Mar–Apr 2026)
- report Rapid7 Q1 2026 Threat Landscape Report
- trend SPIP 2026 RCE wave×2
- cve Linux kernel ptrace credential-window LPE (Jann Horn, 2019), historical predecessor cited as background in 2026-05-23 CVE-2026-46333 deep dive
- cve PwnKit, polkit pkexec local root (Qualys, 2022), historical reference cited in 2026-05-23 CVE-2026-46333 deep dive as functional-equivalent outcome
- cve Looney Tunables, glibc ld.so local privilege escalation (Qualys, 2023), historical reference cited in 2026-05-23 CVE-2026-46333 deep dive as disclosure-pattern precedent
- campaign Calypso telco espionage campaign×2
- incident Operation Saffron
- cve Microsoft Azure CVSS 10.0 cluster, server-side mitigated, no customer action required (MSRC May 2026)
- cve Microsoft Azure CVSS 10.0 cluster, server-side mitigated, no customer action required (MSRC May 2026)
- cve Microsoft Azure CVSS 10.0 cluster, server-side mitigated, no customer action required (MSRC May 2026)
- cve Microsoft Entra ID / Azure CVSS 10.0 cluster, server-side mitigated, no customer action required (MSRC May 2026)
- cve Microsoft Entra ID / Azure CVSS 10.0 cluster, server-side mitigated, no customer action required (MSRC May 2026)
- report Verizon 2026 DBIR
- trend PinTheft
- cve SquirrelMail post-auth RCE, used by Webworm against Serbian government targets per ESET 2026-05-20 (initial-access probe after credential theft)
- cve Keycloak admin evaluate-scopes endpoint cross-role PII leakage bypassing user-view permissions (Keycloak 26.6.2)
- cve Keycloak WebAuthn packed self-attestation acceptable-AAGUID policy bypass enabling enrolment of hardware tokens outside policy (Keycloak 26.6.2)
- actor Storm-2949
- campaign Storm-2949 SSPR-to-Key-Vault kill chain
- incident actions-cool/issues-helper compromise
- trend Sparx Enterprise Architect five-CVE chain
- cve Fortinet FortiSandbox unauthenticated RCE in Web UI (CWE-862, CVSS 9.1 vendor / 9.8 NVD), pre-auth, patch in 4.4.9 / 5.0.2 / Cloud 5.0.6; Cloud 23/24 require migration
- cve vm2 Node.js sandbox, symbol-to-string coercion TypeError sandbox bypass; patched 3.10.5
- cve vm2 NodeVM allow-list bypass, Module._load() reachable when child_process is explicitly permitted → OS command execution; CVSS 9.9
- cve vm2 prototype pollution via attacker-controlled JS; CVSS 10.0; affects 3.9.6 – 3.10.5; patched 3.11.0
- cve vm2 code injection via BaseHandler.getPrototypeOf; CVSS 10.0; patched 3.11.0
- cve vm2 null-proto exception exploitation; CVSS 9.8; affects ≤ 3.11.1; patched 3.11.2
- cve vm2 neutralizeArraySpeciesBatch() bypass via null-proto exception; CVSS 9.8; affects ≤ 3.11.1; patched 3.11.2
- cve SEPPmail Secure Email Gateway, unauthenticated RCE via exposed GINAv2 test endpoints (CVSS 9.3)
- cve Fortinet FortiAuthenticator unauthenticated RCE in management interface (CWE-284, CVSS 9.8), pre-auth, patch in 6.5.7 / 6.6.9 / 8.0.3
- cve Exim 4.97–4.99.2 GnuTLS builds, BDAT/CHUNKING use-after-free (Dead.Letter), pre-auth RCE (CVSS 9.8, ENISA EUVD critical); fixed in Exim 4.99.3
- campaign Fast16
- campaign INTERPOL Operation Ramz
- campaign Living Off the Pipeline×2
- incident ARWINI data exfiltration
- incident Grafana Labs CoinbaseCartel breach
- trend BigBlueButton bbb-web CVE trio
- cve VMware Fusion 25H2 (macOS), TOCTOU SETUID race condition LPE (CVSS 7.8); dropped from § 2 in 2026-05-19 brief (did not clear inclusion gates)
- cve n8n HTTP Request Node injection, companion amplifier to CVE-2026-42231 prototype-pollution chain×2
- cve n8n XML Node injection, companion amplifier to CVE-2026-42231 prototype-pollution chain×2
- cve n8n Git node SSH chain, terminal sink of CVE-2026-42231 prototype-pollution to RCE×2
- cve n8n XML Node injection, companion amplifier to CVE-2026-42231 prototype-pollution chain×2
- cve BigBlueButton bbb-web < 3.0.21, insecure sessionToken generation (CWE-330) enables session hijack
- cve BigBlueButton bbb-web < 3.0.21, presentationUploadExternalUrl API checksum bypass (CWE-284)
- cve BigBlueButton bbb-web < 3.0.23, SSRF in presentation URL validation (CWE-918)
- incident THORChain vault drain
- tool OWAReaper
- cve Fireblocks GG18/GG20 Paillier missing-ZK-proof flaw (TSSHOCK class; cited as background-class for THORChain 2026-05-15 GG20 TSS exploit)
- cve AMD-SB-7052, Zen 2 µop-cache corruption / SoC isolation LPE (CVSS 7.3 CVSS 4.0)
- cve SAP S/4HANA Enterprise Search ABAP, authenticated SQL injection in SAP_BASIS 751–758 / 816 (CVSS 9.6)
- cve SAP Commerce Cloud, unauthenticated arbitrary code execution via Spring Security misordering on cloud-config endpoint (CVSS 9.6, SAP Note 3733064)
- cve Microsoft SSO Plugin for Jira/Confluence, unauthenticated Entra ID credential forgery (CVSS 9.1, More Likely exploitation)
- cve F5 BIG-IP iControl REST Manager-role authenticated RCE (May 2026 Quarterly Notification, CVSS 9.1)
- cve DHTMLX PDF Export Module, unauthenticated server-side JavaScript injection RCE (CVSS 4.0 score 10.0)
- cve KIR SzafirHost, JAR zip-polyglot signature-verification bypass enabling RCE in Polish qualified e-signature browser helper (CVSS 8.6)
- cve OpenClaw / Clawdbot, OpenShell sandbox TOCTOU write escape (CVSS 9.6, Claw Chain)
- cve Nextcloud Server/Enterprise Server 2FA bypass via WebDAV pre-authenticated session token reuse
- cve PHP Composer GitHub Actions token disclosure in error messages (fixed in 2.9.8 / 2.2.28)
- cve DHTMLX Diagram export module, path traversal (CVSS 4.0 score 9.2)
- cve Ivanti Xtraction < 2026.2 external control of file name/path (CWE-73, CVSS 9.6), arbitrary file read + HTML write to web tree; auth required
- actor Embargo
- campaign FunnelKit Magecart injection
- cve WinRAR file-extension spoofing arbitrary code execution (cited as veteran exploit by Kaspersky Q1 2026 report)
- cve RelayKing NTLM relay, post-access primitive used by The Gentlemen RaaS
- cve Netgate pfSense Community Edition authenticated root RCE, vendor refuses to fix
- cve Netgate pfSense Community Edition authenticated root RCE companion to CVE-2025-69690, vendor refuses to fix
- cve Cisco Catalyst SD-WAN companion CVE (exploited since March 2026)
- cve Cisco Catalyst SD-WAN companion CVE (exploited since March 2026)
- cve Cisco Catalyst SD-WAN companion CVE (exploited since March 2026)
- cve Checkmarx Jenkins AST plugin backdoor (TeamPCP/UNC6780 supply-chain compromise, SANDCLOCK credential stealer, CVSS 9.4)
- cve F5 BIG-IP privilege escalation via misconfigured permissions (May 2026 Quarterly, CVSS 8.7)
- cve F5 BIG-IP privilege escalation via misconfigured permissions (May 2026 Quarterly, CVSS 8.7)
- cve F5 BIG-IP privilege escalation via misconfigured permissions (May 2026 Quarterly, CVSS 8.7)
- cve F5 BIG-IP SSH password exposure in iControl REST audit logs (May 2026 Quarterly, CVSS 8.7)
- cve DHTMLX PDF Export Module, path traversal via src attribute (CVSS 4.0 score 9.2)
- cve F5 BIG-IP iControl REST command injection (May 2026 Quarterly, CVSS 8.7)
- cve F5 BIG-IP iControl REST command injection (May 2026 Quarterly, CVSS 8.7)
- cve Microsoft Dynamics 365 On-Premises, authenticated code injection with scope change (CVSS 9.9, May 2026 Patch Tuesday)
- cve F5 BIG-IP iControl REST command injection (May 2026 Quarterly, CVSS 8.7)
- cve F5 BIG-IP iControl REST command injection (May 2026 Quarterly, CVSS 8.7)
- cve OpenClaw / Clawdbot, TOCTOU read escape / file disclosure (CVSS 7.7, Claw Chain)
- cve OpenClaw / Clawdbot, command-parser allowlist bypass (CVSS 8.8, Claw Chain)
- cve OpenClaw / Clawdbot, MCP loopback senderIsOwner privilege escalation (CVSS 7.8, Claw Chain)
- cve Progress MOVEit Automation unauthenticated authentication bypass (CVSS 9.8)
- cve GitLab CE/EE, stored XSS in analytics dashboards (CVSS 8.7); cited as dropped from § 2
- cve PHP SOAP extension UAF in SOAP_GLOBAL(ref_map) (with companions CVE-2026-7261, CVE-2026-7262); patched in PHP 8.4.8 / 8.3.22 / 8.2.30×2
- cve PHP SOAP companion to CVE-2026-6722; patched 2026-05-08×2
- cve PHP SOAP companion to CVE-2026-6722; patched 2026-05-08×2
- cve GitLab CE/EE, stored XSS in container registry virtual registry upstreams (CVSS 8.7); cited as dropped from § 2
- cve GitLab CE/EE, stored XSS in Jira integration (CVSS 8.7); cited as dropped from § 2
- tool Gremlin Stealer
- trend AMD-SB-7052
- cve Microsoft Exchange Server pre-auth RCE (ProxyShell), cited in 2026-05-16 § 5 deep dive Background
- cve JetBrains TeamCity authentication bypass, cited in 2026-05-16 § 3 SentinelOne CI/CD subversion case study
- trend Dirty Frag / Fragnesia×3
- cve Cisco SD-WAN local privilege escalation (UAT-8616 version-downgrade re-exploitation technique)
- cve BlueHammer, Windows zero-day by Nightmare Eclipse (confirmed ITW by Huntress, April 2026)
- cve Nextcloud Server SQL injection in column-type parameter (Moderate)
- cve Google Chrome CVE (mentioned in recency-dropped items, 2026-05-12)
- cve Google Chrome CVE (mentioned in recency-dropped items, 2026-05-12)
- campaign CL-STA-1132×3
- campaign FamousSparrow Azerbaijan intrusion
- report Q1 2026 ransomware quarterly synthesis
- tool GemStuffer
- product RubyDoc.info
- product RubyGems
- incident OpenAI RubyGems agent attack (May 2026)
- cve Microsoft Exchange Server SSRF (ProxyNotShell), cited as initial-access vector in 2026-05-14 FamousSparrow deep dive; chained with CVE-2022-41082
- cve Microsoft Exchange Server PowerShell remoting deserialization RCE (ProxyNotShell), cited as initial-access vector in 2026-05-14 FamousSparrow deep dive; chained with CVE-2022-41040
- cve HPE ArubaOS AOS-10 stored XSS in web management interface (CVSS 8.8); referenced in 2026-05-14 § 7 drop note (gate not cleared)
- cve Cline kanban npm package cross-origin WebSocket hijack (CVSS 9.6); referenced in 2026-05-14 § 7 drop note (out-of-window)
- incident Foxconn Nitrogen ransomware
- tool MDASH
- tool TrickMo C
- trend Centreon April 2026 vulnerability cluster
- cve SAP Forecasting & Replenishment, authenticated OS-command injection (CVSS 8.2, SAP May 2026 patch day)
- cve Microsoft Word Preview Pane RCE (CVSS 8.4, More Likely exploitation, May 2026 Patch Tuesday)
- cve Microsoft Word Preview Pane RCE (CVSS 8.4, More Likely exploitation, May 2026 Patch Tuesday)
- cve Microsoft Word Preview Pane RCE (CVSS 8.4, May 2026 Patch Tuesday)
- cve Microsoft Word Preview Pane RCE (CVSS 8.4, May 2026 Patch Tuesday)
- cve Earlier Thymeleaf CVE referenced in § 7 disambiguating the dropped Thymeleaf item; CSO Online article 2026-04-17 covered this CVE rather than CVE-2026-41901
- cve Thymeleaf SSTI sandbox bypass, referenced in § 7 explaining out-of-window drop (GHSA published 2026-04-29)
- incident South Staffordshire Water ICO fine
- report CERT-FR agentic-AI risk report (CERTFR-2026-ACT-016)×2
- report GTIG AI Threat Tracker (May 2026)
- tool PCPJack
- cve ConnectWise ScreenConnect path traversal, chained with CVE-2024-1709 by Kimsuky/Storm-1175; KEV deadline 2026-05-12 (out-of-window per § 7 of 2026-05-12 brief)
- cve ConnectWise ScreenConnect authentication bypass (CVSS 10.0), chained with CVE-2024-1708; cited as 2026-05-12 drop
- cve Android adbd wireless ADB authentication bypass (CVSS 8.8, adjacent-network, public PoC 2026-05-11), § 2 gate not cleared
- cve Ivanti EPMM remote authenticated → administrative-access via improper access control (CVSS 8.8, May 2026 update)
- cve Ivanti EPMM on-prem improper certificate validation → pre-auth Sentry impersonation (CVSS 9.1, ITW, KEV chain)×3
- cve Ivanti EPMM unauthenticated arbitrary method invocation (CVSS 7.0, May 2026 update)
- cve Ivanti EPMM on-prem admin API improper input validation → RCE (CVSS 7.2, ITW, KEV deadline 2026-05-10)×3
- cve Ivanti EPMM; fourth companion CVE in May 2026 EPMM update (high-severity per BleepingComputer / SecurityWeek)
- campaign SMS-blaster smishing (Switzerland)
- incident Braintrust AWS breach
- incident Groupe 3R ransomware breach
- incident JDownloader official site compromised
- tool Beagle
- cve Microsoft Office Equation Editor RCE (cited as veteran exploit by Kaspersky Q1 2026 exploit report)
- cve Microsoft Office Equation Editor RCE (cited as largest-share detected exploit by Kaspersky Q1 2026 report)
- cve Ivanti EPMM pre-auth API access (2023, exploited by APT29; cited as historical precedent in 2026-05-08 deep dive)
- cve SimpleHelp RMM unauthenticated privilege escalation (ITW)
- cve SimpleHelp RMM path traversal, unauthenticated file download (ITW)
- cve Samsung MagicINFO 9 Server unauthenticated arbitrary file write → RCE (CVSS 8.8, ITW)
- cve Ivanti EPMM critical (January 2025, state-actor exploitation; cited as historical precedent in 2026-05-08 deep dive)
- cve Next.js middleware authorisation bypass via crafted header, weaponised by PCPJack worm
- cve CentOS Web Panel FileManager shell injection, weaponised by PCPJack worm
- cve xrdp pre-authentication stack buffer overflow → RCE
- cve W3 Total Cache PHP injection via mfunc comment processor, weaponised by PCPJack worm
- cve Ivanti EPMM January 2026 critical, historical precedent cited in 2026-05-09 Ivanti UPDATE
- cve Ivanti EPMM January 2026 critical companion, historical precedent cited in 2026-05-09 Ivanti UPDATE
- cve WPVivid Backup unauthenticated file upload, weaponised by PCPJack worm
- cve Cisco Unity Connection authenticated RCE in management API (CVSS 8.8, NATO NCSC discovery; logged § 7, dropped from § 2, gate not cleared)
- cve Cisco Unity Connection unauthenticated SSRF in default-enabled Web Inbox (CVSS 7.2; logged § 7, dropped from § 2, gate not cleared)
- cve Windows Shell LNK exploit predecessor, APT28 weaponised against Ukraine and EU; February 2026 patch left CVE-2026-32202 residual
- cve Apache HTTP Server 2.4.66 HTTP/2 double-free, DoS and potential RCE (CVSS 8.8)
- cve Zabbix frontend stored XSS in map element labels (CVSS 6.1)
- cve Zabbix API confidentiality; unprivileged user can read admin host data (CVSS 5.3)
- cve Zabbix frontend reflected XSS in host-group filter (CVSS 6.1)
- cve Microsoft Semantic Kernel .NET SDK, unintended [KernelFunction] on SessionsPythonPlugin Download/UploadFileAsync → arbitrary file write → sandbox escape (CVSS 9.9)×2
- cve Microsoft Semantic Kernel Python SDK, prompt-injection-to-RCE via InMemoryVectorStore filter (CVSS 9.9, PoC public)×2
- cve Apache httpd mod_proxy_ajp heap overflow → remote crash / potential RCE (CVSS 7.5)
- cve cPanel/WHM CVE cluster, dropped from § 3 (embargoed, gate not cleared)
- cve cPanel/WHM CVE cluster, dropped from § 3 (embargoed, gate not cleared)
- cve cPanel/WHM unsafe symlink handling, chmod abuse on arbitrary files (CVSS 8.8, second emergency TSR)
- cve Windows Shell protection mechanism failure → NTLM coercion / spoofing (CVSS 4.3, APT28 ITW, KEV deadline 2026-05-12)
- cve Traefik proxy mTLS bypass via fragmented TLS ClientHello
- cve GLPI < 10.0.25 / 11.0.7 SSRF (CERTFR-2026-AVI-0551)
- cve Metabase Enterprise Java serialization → authenticated RCE (CVSS 8.8)
- cve GLPI < 10.0.25 / 11.0.7 data integrity compromise (CERTFR-2026-AVI-0551)
- cve Spring Cloud Config Server Google Secrets Manager backend flaw (HIGH)
- cve Spring Cloud Config Server pre-auth directory traversal (CVSS 9.8)
- cve Spring Cloud Config Server companion CVE (HIGH)
- cve Spring Cloud Config Server companion CVE (MEDIUM)
- cve cPanel/WHM authentication bypass via CRLF injection (mass exploitation ongoing, KEV)
- cve LiteLLM Proxy pre-auth SQL injection, all upstream LLM API keys at risk (CVSS 9.3, KEV deadline 2026-05-11)
- cve GLPI < 10.0.25 / 11.0.7 XSS (CERTFR-2026-AVI-0551)
- cve GLPI < 10.0.25 / 11.0.7 XSS (CERTFR-2026-AVI-0551)
- cve GLPI < 10.0.25 / 11.0.7 XSS (CERTFR-2026-AVI-0551)
- cve GLPI < 10.0.25 / 11.0.7 XSS (CERTFR-2026-AVI-0551)
- cve SEPPmail GINAv2, missing authentication in admin REST API (CVSS 9.3)
- cve SEPPmail GINAv2, insecure deserialisation via session cookie → RCE (CVSS 9.2)
- cve SEPPmail appliance management, LFI and arbitrary file deletion (CVSS 8.8)
- cve SEPPmail GINAv2, server-side template injection via Freemarker (CVSS 8.3)
- cve Progress MOVEit Automation authenticated privilege escalation (CVSS 8.8)
- cve GLPI < 10.0.25 / 11.0.7 security policy bypass / auth bypass (CERTFR-2026-AVI-0551)
- cve Progress Telerik RadAsyncUpload DoS via path traversal (CVSS 7.5)
- cve Progress Telerik RadFilter deserialization → unauthenticated RCE (CVSS 9.8)
- cve SEPPmail appliance management, information disclosure (CVSS 6.9)
- incident DAEMON Tools supply-chain compromise
- incident DENIC .de DNSSEC outage
- incident Inditex (Zara) breach
- cve Apache CloudStack post-auth authentication token flaw, dropped from § 3 (gate not cleared)
- incident Die Linke ransomware breach
- incident Eurail breach
- report Dragos 2025 OT Cybersecurity Year in Review
- report Kaspersky Q1 2026 Exploits and Vulnerabilities Report
- cve Microsoft Office Protected View bypass, security feature bypass (CVSS 7.8, KEV deadline 2026-02-16 already passed; deferred from §4)
- cve Microsoft Office Protected View chain CVE (deferred from §4; see CVE-2026-21509 series)
- cve Microsoft Office Protected View chain CVE (deferred from §4; see CVE-2026-21509 series)
- actor APT42
- actor UAT-8302
- campaign ACR Stealer fake-Claude distribution
- campaign AI-brand impersonation malware delivery
- campaign Amazon SES BEC abuse
- campaign APT28 tradecraft evolution 2026
- campaign B1ack's Stash May 2026 card release
- campaign Chinese-language PhaaS OTP-relay ecosystem
- campaign BadIIS 'demo.pdb' MaaS backdoor campaign
- campaign CL-STA-1062 TinyRCT campaign
- campaign IPv4-mapped IPv6 eBanking phishing
- campaign Kali365 PhaaS
- campaign FishMonger Windows SprySOCKS campaign
- campaign FortiSandbox triple exploitation
- campaign Gamaredon GammaPhish / GammaWorm
- campaign Grandoreiro 2026 Iberian campaign
- campaign Potemkin / RMMProject ClickFix campaign
- campaign InstallFix
- campaign Malicious JetBrains Marketplace AI plugins
- campaign npm/Go folderOpen-task infostealer campaign
- campaign Kimsuky HelloDoor / PebbleDash C2 evolution
- campaign macOS ClickFix hdiutil campaign
- campaign Stripe-metadata Magecart skimmer
- campaign Fake 'Perplexity AI' Chrome extension
- campaign MuddyWater Chaos false-flag
- campaign MuddyWater Q1 2026 DLL side-loading campaign
- campaign Mustang Panda ZOHOMURK
- campaign M365 voicemail-phishing wave (CH)
- campaign npm dependency-confusion wave 2026
- campaign OceanLotus FireAnt supply-chain compromise
- campaign Malicious OpenClaw ClawHub skills
- campaign 'Photo ZIP' hospitality phishing
- campaign PostCSS npm typosquat campaign
- campaign ROADtools weaponisation (Entra ID)
- campaign Rust crypto-clipper VirusTotal abuse
- campaign WeTransfer steganographic JPEG loader
- campaign ScarCruft NarwhalRAT campaign
- campaign ShapedPlugin Pro supply-chain backdoor
- campaign 'Signal Support' recovery-key phishing
- campaign SVG application/ecmascript phishing wave
- campaign Shai-Hulud copycat wave
- campaign Microsoft Teams external-chat phishing
- campaign The Gentlemen self-propagating encryptor
- campaign Turla STOCKSTAY campaign
- campaign Tycoon2FA post-takedown resurgence
- campaign UAC-0226 GIFTEDCROOK WinRAR exploitation
- campaign UNC6508 INFINITERED campaign
- campaign WhatsApp VBScript RMM campaign
- campaign WordPress Steam-profile C2 malware
- incident 7-Eleven Salesforce breach
- incident AdaptHealth contractor session hijack
- incident ADT Inc. cloud environment breach
- incident Aflac Japan subsidiary portal breach
- incident AudiA6 laundering-service takedown
- incident Awesome Motive CDN supply-chain attack
- incident Crimenetwork relaunch takedown
- incident Brazil Cell Broadcast hijack
- incident BWH Hotels reservation breach
- incident California Water Service breach (Handala)
- incident California AG v. 23andMe
- incident Carnival Corporation breach
- incident Cellebrite UFED use on Pivovarov
- incident EFK federal cyber-governance audit
- incident Checkmarx Jenkins plugin backdoor
- incident ChipSoft ransomware breach
- incident CISA/Nightwing GovCloud key exposure
- incident Clinical Diagnostics NMDL ruling
- incident CNIL IQVIA fine
- incident Coupang PIPC record fine
- incident Dashlane TOTP brute-force
- incident DHS HSIN breach
- incident DigiCert support-portal compromise
- incident Dream Market admin arrest
- incident Drupal core pre-patch warning (PSA-2026-05-18)
- incident Dutch/Belgian/Irish booking-SaaS breach
- incident Europol shadow-IT disclosure
- incident France ANTS breach
- incident HCRG notification delay
- incident POST Luxembourg outage (Huawei VRP zero-day)
- incident London Clinic insider caution
- incident Markerstudy insider POCA confiscation
- incident RAC insider POCA confiscation
- incident Instructure (Canvas LMS) breach
- incident iRhythm data theft
- incident Jaguar Land Rover 2025 ransomware
- incident Kyushu Electric SSD loss
- incident Lithuania Centre of Registers breach
- incident Maine breach-portal abuse
- incident Mediaworks Kft (Hungary)
- incident Canton Zürich Baudirektion listing
- incident Instagram AI-support account takeovers
- incident Meta v. NSO contempt complaint
- incident Microsoft DCU Fox Tempest disruption
- incident Madison Square Garden breach
- incident Munich LHM-Services breach
- incident NAIC PeopleSoft breach
- incident Navient fourth-party ransomware exposure
- incident NFSP ransomware
- incident Nidec Chaun Choung ransomware
- incident Nintendo TinyPulse breach
- incident Stark Industries hosting arrests
- incident node-ipc backdoor
- incident Novo Nordisk data theft
- incident Nx Console extension compromise
- incident OFAC Nobitex sanctions
- incident One Medical legacy-storage breach
- incident OpenAI supply-chain exposure
- incident Oxford CareerConnect breach
- incident Polish water-treatment OT intrusion
- incident polyfill.io reactivation
- incident PostHog AWS exploit
- incident Rhysida Stuttgart claim
- incident ServiceNow unauthenticated REST exposure
- incident Charter/Spectrum listing
- incident Silver Fox arrests
- incident Škoda online-shop breach
- incident Spanish doxer arrest
- incident First observed LLM-agent-driven intrusion
- incident Tchap messenger breach
- incident Texas Parks & Wildlife vendor breach
- incident The Gentlemen leak-site listings (VSFS, DEVO-Tech)
- incident Trellix source-code breach
- incident UK ICO Commissioner resignation
- incident UK visa-portal lookalike exposure
- incident Ukrposhta disruption
- incident Unimed hospital-billing breach
- incident Vimeo breach (Anodot)
- incident West Pharmaceutical ransomware
- incident UN WFP Gaza registration breach
- incident Xsolis breach
- policy LG Berlin II Apobank PSD2 ruling
- policy CISA BOD 26-04
- policy EDPB Coordinated Enforcement Framework 2026
- policy EDPB Art. 33 breach-notification template
- policy ENISA CVE Numbering Authority Root expansion
- policy ENISA SBOM Adoption State of Play 2026
- policy EU 20th Russia sanctions package
- policy EU Cybersecurity Package 2026
- policy NIS2 CJEU referral (France, Spain)
- policy Europol mandate-expansion pause demand
- policy Germany CRA implementation bill
- policy Germany Cybersicherheitsstärkungsgesetz
- policy Germany KRITIS-Dachgesetz
- policy npm staged publishing GA
- policy npm v12 install-scripts default-off
- policy Poland NIS2 transposition
- report Bauman 'Department No. 4' investigation
- report Elastic AAD Graph detection guidance
- report ENISA NIS360 2026
- report ESET Gamaredon 2025 annual paper
- report 'Safeguarding Our Secrets' bulletin
- report NCSC-CH G7 Évian pre-event advisory
- report GTIG Europe Data Leak Landscape 2025
- report Europol IOCTA 2026
- report Linux prctl process-masquerading analysis
- report Mandiant M-Trends 2026
- report NCSC-CH assessment: AI in vulnerability management
- report NCSC-UK AI-vulnerability checklist
- report Sophos State of Identity Security 2026
- report Swiss Threat Landscape Report (Swiss Post)
- report Windows COM-abuse analysis (Talos)
- tool BirdCall
- tool Datadog Shai-Hulud scanner
- tool PamDOORa
- tool QLNX
- tool AI-orchestrated EDR-evasion lab
- tool ZiChatBot
- trend Adaptive AI worm PoC
- trend Apereo CAS OIDC-provider flaw
- trend Cloud-logging defence-evasion taxonomy
- trend AI-agent FFmpeg zero-day batch
- trend github.dev OAuth-token theft
- trend GCP API-key deletion delay
- trend OpenClaw skills supply-chain surface
- trend LangGraph checkpointer SQLi→RCE chain
- trend M365 Android debug-flag OAuth theft
- trend Mautic 7.1.2/6.0.9 flaw set
- trend Entra Agent ID AddRemoveCreds priv-esc
- trend DICOM/Orthanc heap attack surface
- trend Windows Search URI NTLM leak
- incident jscrambler npm supply-chain compromise (2026-07)
- incident xAI Grok Build CLI whole-repository/secrets exfiltration (July 2026)
- policy EU Managed Security Services (EUMSS) certification scheme
- policy ENISA Health Action Plan Contribution Agreement
- policy BaFin TeamViewer MAR Article 17 disclosure fine
- policy EU AI Act Digital Omnibus (Regulation (EU) 2026/1744)
- policy CI Fortify, Advice for isolating vital systems
- policy NCSC UK forensic observability for network devices
- policy 2026 Minimum Elements for a Software Bill of Materials
- policy Netherlands Cyberbeveiligingswet (NIS2 transposition)
- policy Germany NIS2 registration deadline and enforcement gap
- policy Swiss ISV Article 51 federal-administration ISMS transition deadline
- actor Krybit
- report Dragos Industrial Ransomware Analysis: Q2 2026
- report Check Point Research: The State of Ransomware Q2 2026
- policy NCSC UK interim guidance on managing the cyber risk of agentic AI (August 2026)
- product Unisoc T606
- product Unisoc T7250
- product Veeam Backup & Replication