Skip to content
Threat Feed

Briefs

← Newer Older →

August 2026 (30)

medium advisory

Vulnerabilities in MISP cti-transmute

The MISP project has patched multiple security vulnerabilities in the cti-transmute tool, including arbitrary file/network access and improper authorization controls for user management.

cti-transmute vulnerability misp patch-management
3i
critical advisory

Flowise Unauthenticated RCE via Environment Variable Bypass

Flowise v3.1.2 and earlier are vulnerable to unauthenticated remote code execution because the CVE-2025-8943 patch relies on an incomplete environment variable blocklist, allowing attackers to inject configuration variables that force arbitrary package installation.

Flowise +4 rce injection cve-2026-69263 python-injection authentication-bypass oauth cve-2026-70478 web-vulnerability +7
6r 11t 2c
critical advisory

Denying the Worm: Detecting SANDWORM_MODE and AI Toolchain Supply Chain Attacks

The SANDWORM_MODE campaign is a multi-stage npm supply chain worm that targets AI-augmented development workflows by exploiting runtime behaviors of AI coding assistants and CI/CD pipelines, leading to credential theft, supply chain poisoning, and persistence through obfuscated loaders, credential harvesting, and malicious Git hooks.

npm +16 supply-chain-attack git ai-toolchain development-workflow code-injection credential-theft persistence evasion
3r 14t 8i updated
critical advisory

IBM Langflow OSS Unauthenticated Remote Code Execution via Chained API Endpoints (CVE-2026-9198)

Unauthenticated attackers can achieve Remote Code Execution (RCE) on default IBM Langflow OSS deployments, versions 1.0.0 through 1.10.0, by chaining access to the `/api/v1/auto_login` endpoint, which mints SUPERUSER tokens, with the `/api/v1/validate/code` endpoint, which executes user-supplied code via `exec()`.

PoC Langflow OSS +3 remote-code-execution api-exploitation unauthenticated-access code-injection web-vulnerability ai-llm
1r 3t 3c 2i updated
high advisory

Unrestricted File Upload Vulnerability in ResponsiveFilemanager

A publicly disclosed, unpatched unrestricted file upload vulnerability in Trippo ResponsiveFilemanager up to version 9.14.0 allows remote attackers to execute arbitrary code.

ResponsiveFilemanager
1r 1t 1c
critical threat

Improper Access Control in Atlas-Livre Admin Controllers

An unauthenticated access control flaw in Atlas-Livre allows attackers to bypass authentication and execute privileged database operations due to a failure to terminate script execution following HTTP redirects.

exploited Atlas-Livre vulnerability web-application cve-2026-69703
1r 2t 1c
high advisory

Security Updates for cPanel and WP Squared

WebPros has issued a security advisory addressing HTTP request smuggling and database privilege escalation vulnerabilities in cPanel and WP Squared products.

WP Squared +1 web-application-vulnerability vulnerability-management
2c
high advisory

Critical Remote Code Execution in Check Point Security Management

Check Point security management products are vulnerable to remote code execution and security policy bypass via CVE-2026-18574, affecting multiple current and legacy versions.

Multi-Domain Security Management +3
2t 1c
high advisory

Command Injection Vulnerability in GL.iNet AX1800 RPC Endpoint

An authenticated remote command injection vulnerability in the RPC component of GL.iNet AX1800 routers (firmware <= 4.8.3) allows attackers to execute arbitrary system commands via the 'remove_rule' function.

AX1800
1t 1c
critical advisory

Unauthenticated Remote Code Execution in kotaemon

An insecure deserialization vulnerability (CVE-2026-69098) in the kotaemon check_connection endpoint allows unauthenticated attackers to achieve remote code execution by injecting malicious __type__ fields.

kotaemon
1r 2t 1c
high advisory

Flowise Broken Access Control in /api/v1/files

A broken access control vulnerability in Flowise versions 3.1.2 and earlier allows authenticated users with low-privileged API keys to list and delete files across different workspaces within the same organization.

Flowise
1r 1t 1c
high advisory

Flowise Sandbox Escape to Remote Code Execution

Authenticated attackers can exploit an insecure JavaScript sandbox configuration in FlowiseAI to execute arbitrary system commands via a chained injection and path traversal payload.

Flowise +1
2t 1c
critical advisory

FlowiseAI Flowise CSV Agent Prompt Injection RCE Vulnerability

A remote code execution vulnerability exists in FlowiseAI Flowise version 3.0.13 due to insufficient sandboxing when evaluating LLM-generated Python scripts, allowing unauthenticated attackers to inject malicious code via prompts processed by the CSV Agent node, bypassing input validation, to execute arbitrary OS commands.

Flowise +1 rce prompt-injection
2r 1t 4c updated
critical threat

Qilin Ransomware Claims New Victim in Agriculture and Food Production Sector

The Qilin ransomware group, active since July 2022 and utilizing Golang, has claimed a new victim, Danone (International Delights) in the US Agriculture and Food Production sector, employing double extortion tactics involving data encryption and threatened data release.

www.acosol.es +42 Qilin +1 ransomware double-extortion golang agriculture food-production
2r 13t 156i updated
high advisory

Hard-Coded Cryptographic Key in Acrisure KARR BT and DR-100

A hard-coded cryptographic key vulnerability (CVE-2026-18411) in Acrisure KARR BT and DR-100 automotive anti-theft systems allows nearby attackers to issue unauthorized commands to vehicles.

KARR BT +1 ics transportation-security bluetooth vulnerability
1t
medium advisory

Integrity Vulnerability in Thermo Fisher Genetic Analyzer Software

Thermo Fisher Applied Biosystems Genetic Analyzer software lacks integrity checks for output data files, enabling local users to modify DNA analysis results (CVE-2026-17583).

Applied Biosystems 3500/3500xL Series Data Collection Software +7
high advisory

Unauthenticated Remote Code Execution in Perspective 5.0.0

Perspective version 5.0.0 is vulnerable to unauthenticated remote code execution via unsafe Python eval() calls within the PolarsVirtualServer backend triggered by crafted protobuf messages.

Perspective remote-code-execution cve-2026-67195 denial-of-service vulnerability CVE-2026-67198
3t 3c
high advisory

Missing Authorization Vulnerability in HAVELSAN Liman MYS

A missing authorization vulnerability (CVE-2026-18650) in HAVELSAN Liman MYS versions 2.2.3 through 2.3.0 allows authenticated users to escalate privileges.

Liman MYS vulnerability privilege-escalation havelsan
1c
high advisory

Authorization Bypass in HAVELSAN Liman MYS

A missing authorization vulnerability in HAVELSAN Liman MYS (versions 2.2.3 through 2.3.0) allows low-privileged users to access restricted system functions.

Liman MYS
1t 1c
critical advisory

Authentication Bypass in Puwell IP Camera Firmware

Puwell IP Camera firmware versions 2.x through 4.x contain an authentication bypass vulnerability (CVE-2026-61514) allowing unauthenticated attackers to control device functions via TCP port 23456.

IP Camera +1
2t 2c 1i
high advisory

Microsoft Security Updates - August 2026

Roundup of five Microsoft security advisories affecting Microsoft Office Excel and Microsoft Edge, with CVSS scores from 7.4 to 8.8.

Microsoft Office 2019 +6 roundup
5c updated
critical advisory

Critical Vulnerabilities in HUMANIST Digital Human Resources

Multiple critical vulnerabilities in Bilin Software and Informatics Consultancy Inc. HUMANIST Digital Human Resources version 26.0 allow unauthorized access, web shell upload, session hijacking, and remote code execution. Upgrade to version 26.1 immediately.

HUMANIST Digital Human Resources sql-injection vulnerability webserver remote-code-execution web-application cve-2026-14175 session-hijacking credential-access
1r 3t 4c
critical advisory

Remote Command Injection in GL.iNet GL-MT3000

Multiple unauthenticated remote command injection vulnerabilities in the GL.iNet GL-MT3000 router allow arbitrary code execution via the /cgi-bin/glc component. Public exploit code is available; patch firmware immediately.

exploited GL-MT3000 cve rce iot router cve-2026-18686 command-injection
1r 3t 2c 2i updated
high advisory

Stack-based Buffer Overflow in Autodesk FBX SDK

A stack-based buffer overflow vulnerability (CVE-2026-10709) in the Autodesk FBX SDK allows arbitrary code execution via maliciously crafted FBX files.

FBX SDK +1 vulnerability rce sdk
1t 2c
high advisory

QuickFox Supply Chain Attack and FDMTP Implant Deployment

Threat actors compromised QuickFox software supply chain to distribute trojanized Windows installers, resulting in the installation of a custom FDMTP implant for persistent access.

supply-chain-attack implant windows fortiguard
1t
high advisory

N-able N-central Authentication Bypass Exploitation

Threat actors are actively exploiting a patch bypass vulnerability (CVE-2026-18577) in N-able N-central to gain administrative control and establish persistent remote access via Cloudflare tunnels.

PoC N-central +3 supply-chain rmm cve-2026-18577 exploitation
3t 2c 6i updated
critical advisory

Unauthenticated Arbitrary File Write in Apache Kyuubi REST API

An unauthenticated path-traversal vulnerability in the Apache Kyuubi REST API (CVE-2026-52680) allows remote attackers to write arbitrary files to the filesystem, leading to remote code execution.

Apache Kyuubi
1r 2t
high advisory

Multiple Vulnerabilities in PHP Language

Multiple vulnerabilities, including CVE-2026-17543, CVE-2026-17544, CVE-2026-7260, and CVE-2026-9672, have been identified in PHP, potentially enabling SQL injection and denial-of-service attacks.

PoC PHP 8.2 +4
3c 1i updated
critical advisory

Remote Code Execution in ArcadeDB via Script Triggers

An authenticated remote code execution vulnerability (CVE-2026-67340) in ArcadeDB engine versions before 26.7.2 allows attackers to escape script sandboxing and execute arbitrary OS commands.

PoC arcadedb-engine +1 cve-2026-67340 rce database arcadedb
1t 1c 1i updated
critical advisory

Unauthenticated Remote Code Execution in Realtyna Organic IDX and WPL Real Estate WordPress Plugins

The Realtyna Organic IDX and WPL Real Estate plugins contain an arbitrary file upload vulnerability (CVE-2026-14483) allowing unauthenticated remote code execution via static, default API credentials.

PoC Organic IDX plugin +2 wordpress rce file-upload cve-2026-14483
1r 1c 1i updated