Skip to content
Threat Feed

May 2026 (30)

high threat

Ransomware-as-a-Service (RaaS) Ecosystem: Affiliate Tradecraft and Initial Access Vectors

Ransomware-as-a-service (RaaS) attacks leverage affiliates for initial access, persistence, and exfiltration, using varied techniques like compromised RDP, vulnerable VPNs, and rogue RMM tools, impacting multiple organizations in a single campaign.

Remote Desktop Protocol +7 ransomware raas initial-access persistence
2r 1t
medium advisory

Taiko AG1000-01A SMS Alert Gateway Stored XSS (CVE-2026-9144)

Taiko AG1000-01A SMS Alert Gateway Rev 7.3 and Rev 8 is vulnerable to stored cross-site scripting (CVE-2026-9144) in the web configuration interface, allowing authenticated attackers to execute persistent JavaScript by fragmenting malicious payloads across multiple administrative form fields for persistent code execution.

AG1000-01A SMS Alert Gateway xss stored_xss CVE-2026-9144 web_application
2r 1t 1c
critical advisory

Taiko AG1000-01A SMS Alert Gateway Authentication Bypass (CVE-2026-9141)

Taiko AG1000-01A SMS Alert Gateway Rev 7.3 and Rev 8 contains an authentication bypass vulnerability (CVE-2026-9141) in the embedded web configuration interface, allowing unauthenticated attackers to access internal application pages, modify alarm routing, and disrupt monitoring and control functions.

AG1000-01A SMS Alert Gateway authentication-bypass web-application critical
2r 1t 1c
critical threat

Taiko AG1000-01A SMS Alert Gateway Hardcoded Credentials Vulnerability (CVE-2026-9139)

Taiko AG1000-01A SMS Alert Gateway Rev 7.3 and Rev 8 contains a hard-coded credential vulnerability (CVE-2026-9139) in the embedded web configuration interface, allowing unauthenticated attackers with network access to recover administrative credentials directly from client-side JavaScript and gain full administrative access to the device.

AG1000-01A SMS Alert Gateway cve hardcoded-credentials network-device
2r 1t 1c
high threat

Actively Exploited Integer Overflow in PgBouncer (CVE-2026-6664)

PgBouncer versions prior to 1.25.2 are vulnerable to an integer overflow (CVE-2026-6664), enabling unauthenticated remote attackers to trigger a denial-of-service via a crafted SCRAM authentication packet, with active exploitation reported.

exploited PgBouncer < 1.25.2 integer overflow denial of service CVE-2026-6664
1r 1t 1c
medium advisory

Splunk Releases Security Advisory Addressing Multiple Products

Splunk released security advisories on May 20, 2026, addressing vulnerabilities in Splunk User Behavior Analytics, AppDynamics Agents, Universal Forwarder, Enterprise, Cloud Platform, and AI Toolkit, prompting users to apply necessary updates.

Splunk User Behavior Analytics +12 vulnerability splunk
2r
critical advisory

Cisco Secure Workload Unauthorized API Access Vulnerability

Cisco Secure Workload versions 3.9 and prior, versions prior to 3.10.8.3, and versions prior to 4.0.3.17 are vulnerable to unauthorized API access, requiring an urgent update.

Secure Workload cisco vulnerability api
1r
medium advisory

Splunk Enterprise and Cloud Platform Information Disclosure Vulnerability (CVE-2026-20239)

Splunk Enterprise and Cloud Platform versions prior to 10.2.2 and 10.0.5, and Splunk Cloud Platform versions below 10.3.2512.8, 10.2.2510.11, 10.1.2507.21, and 10.0.2503.13 are vulnerable to information disclosure (CVE-2026-20239), allowing users with access to the `_internal` index to view sensitive data.

Splunk Enterprise +1 information-disclosure splunk cloud
2r 2t 1c
medium advisory

Microsoft Defender Denial of Service Vulnerability (CVE-2026-45498)

CVE-2026-45498 is a denial-of-service vulnerability in Microsoft Defender that could disrupt endpoint protection capabilities, requiring timely mitigation per vendor instructions.

Defender denial-of-service vulnerability microsoft-defender
2r 1t 1c
high advisory

CVE-2026-41091 - Microsoft Defender Link Following Vulnerability

CVE-2026-41091 is a link following vulnerability in Microsoft Defender that allows an authorized attacker to escalate privileges locally.

Defender privilege-escalation cve
2r 1t 1c
critical advisory

CVE-2010-0806 Microsoft Internet Explorer Use-After-Free Vulnerability

CVE-2010-0806 is a use-after-free vulnerability in Microsoft Internet Explorer that allows remote attackers to execute arbitrary code by accessing an invalid pointer after object deletion; mitigations should be applied or product utilization discontinued.

Internet Explorer use-after-free iexplorer cve-2010-0806
2r 1t 1c
critical advisory

Adobe Acrobat and Reader Heap-Based Buffer Overflow Vulnerability (CVE-2009-3459)

Adobe Acrobat and Reader contain a heap-based buffer overflow vulnerability, tracked as CVE-2009-3459, that could allow remote attackers to execute arbitrary code via a crafted PDF file.

Acrobat +1 cve-2009-3459 adobe heap overflow remote code execution
2r 1t 1c
critical advisory

CVE-2009-1537 - Microsoft DirectX NULL Byte Overwrite Vulnerability

Microsoft DirectX contains a NULL byte overwrite vulnerability in the QuickTime Movie Parser Filter (quartz.dll) in DirectShow, potentially allowing remote attackers to execute arbitrary code via a crafted QuickTime media file.

DirectX CVE-2009-1537 null-byte-overwrite code-execution
2r 1t 1c
critical advisory

CVE-2008-4250 - Windows Server Service Buffer Overflow Vulnerability

CVE-2008-4250 is a buffer overflow vulnerability in the Microsoft Windows Server Service that allows remote attackers to execute arbitrary code via a crafted RPC request during path canonicalization.

Windows cve buffer-overflow rpc smbv1
2r 1t 1c
critical advisory

CVE-2010-0249: Microsoft Internet Explorer Use-After-Free Vulnerability

Microsoft Internet Explorer is vulnerable to a use-after-free vulnerability (CVE-2010-0249) that allows remote attackers to execute arbitrary code by accessing a pointer associated with a deleted object.

Internet Explorer cve use-after-free remote-code-execution
2r 1t 1c
medium advisory

CVE-2026-7613: Cost of Goods by PixelYourSite WordPress Plugin Stored XSS

The Cost of Goods by PixelYourSite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'csvdata[0][cost_of_goods_value]' parameter in versions up to, and including, 1.2.12 due to insufficient input sanitization and output escaping, allowing unauthenticated attackers to inject arbitrary web scripts that execute when a user accesses an injected page.

Cost of Goods by PixelYourSite plugin for WordPress xss wordpress CVE-2026-7613
2r 1c
medium advisory

CVE-2026-5783: CityPLus Reflected XSS Vulnerability

CVE-2026-5783 is a reflected cross-site scripting (XSS) vulnerability in Beyaz Computer Software Design Industry and Trade Ltd. Co. CityPLus before version V24.29750.1.0, allowing attackers to inject malicious scripts into web pages viewed by users.

CityPLus cve xss reflected-xss web-application
2r 1t 1c
medium advisory

Cisco ThousandEyes Enterprise Agent BrowserBot Command Injection Vulnerability

CVE-2026-20206 describes a command injection vulnerability in the BrowserBot component of Cisco ThousandEyes Enterprise Agent where an authenticated remote attacker with transaction test management privileges could execute arbitrary commands within the BrowserBot container as the node user.

ThousandEyes Enterprise Agent +1 command-injection cve cisco
2r 1t
medium threat

Cisco ThousandEyes Virtual Appliance Authenticated Remote Code Execution Vulnerability

CVE-2026-20199 - A vulnerability in the SSL certificate handling of Cisco ThousandEyes Virtual Appliance could allow an authenticated, remote attacker to execute commands on the underlying operating system as the root user.

ThousandEyes Virtual Appliance cve-2026-20199 rce cisco thousandeyes ssl
2r 1t
critical advisory

Cisco Secure Workload Unauthorized API Access Vulnerability

CVE-2026-20223: An unauthenticated, remote attacker can access Cisco Secure Workload site resources with Site Admin privileges by sending a crafted API request, due to insufficient validation and authentication of REST API endpoints.

Secure Workload cve cve-2026-20223 privilege-escalation api-attack
2r 1t
medium advisory

Cisco Nexus 3000 and 9000 Series Switches BGP Denial of Service Vulnerability

CVE-2026-20171 describes a vulnerability in the Border Gateway Protocol (BGP) enforce-first-as feature of Cisco Nexus 3000 and 9000 Series Switches that could allow an unauthenticated, remote attacker to trigger BGP peer flaps, resulting in a denial-of-service (DoS) condition.

Nexus 3000 Series Switches +1 bgp dos cisco network
2r 1t
high advisory

phpMyFAQ Authentication Bypass Allows Account Takeover

An authentication bypass vulnerability in phpMyFAQ allows an unauthenticated attacker to reset the password of any user account, including SuperAdmin accounts, by sending a PUT request with a valid username and associated email address to /api/user/password/update, resulting in complete account takeover.

phpmyfaq < 4.1.3 authentication-bypass account-takeover phpmyfaq web-application
2r
medium advisory

Plug Multipart Header Parsing Denial-of-Service Vulnerability (CVE-2026-8468)

Plug versions 1.4.0 to 1.19.1 are vulnerable to denial-of-service (CVE-2026-8468) due to unbounded buffer accumulation in multipart header parsing, allowing an unauthenticated attacker to exhaust server memory by sending a crafted multipart/form-data request.

plug denial-of-service multipart web-application
2r 1t 1c
critical advisory

Compromised @cap-js Packages Lead to Credential Theft and Self-Propagation

Compromised versions of `@cap-js/sqlite@2.2.2`, `@cap-js/postgres@2.2.2`, and `@cap-js/db-service@2.10.1` were published, leading to credential harvesting and attempted self-propagation; upgrade immediately and rotate credentials.

@cap-js/sqlite +2 supply-chain credential-theft npm
2r 2t
medium threat

FreePBX Security Advisories for Security-Reporting Module Vulnerabilities

FreePBX released security advisories addressing authenticated SQL injection and local file inclusion vulnerabilities in the Security-Reporting cdr and dashboard modules for FreePBX 16 and 17.

Security-Reporting cdr +3 freepbx sql_injection lfi vulnerability
2r 1t
high advisory

MediaArea MediaInfoLib Channel Splitting Heap-Based Buffer Overflow (CVE-2026-22554)

MediaArea MediaInfoLib is vulnerable to a heap-based buffer overflow vulnerability when splitting channels, potentially leading to arbitrary code execution.

MediaInfoLib heap-based buffer overflow cve-2026-22554 media processing
2r 1t 1c
high threat

Multiple Vulnerabilities in Mozilla Products Lead to Potential RCE and Privilege Escalation

Multiple vulnerabilities in Mozilla Firefox ESR, Firefox, Firefox for iOS, and Thunderbird products can lead to arbitrary code execution, privilege escalation, and remote denial of service.

Firefox ESR +5 vulnerability rce privilege-escalation dos
2r 3t 4c
high advisory

Multiple Vulnerabilities in Suricata Network Threat Detection Engine

Multiple vulnerabilities in Suricata versions before 8.0.5 and 7.0.16 could allow a remote attacker to execute arbitrary code or cause a denial-of-service condition.

Suricata vulnerability rce dos
2r 2t
medium advisory

Multiple Vulnerabilities in Symfony Framework

Multiple vulnerabilities in Symfony, including CVE-2026-45070, CVE-2026-45077, CVE-2026-45304, CVE-2026-45305, CVE-2026-45753, CVE-2026-45754, CVE-2026-45755, CVE-2026-45756, CVE-2026-46626, and CVE-2026-47212, can lead to remote denial of service, cross-site scripting (XSS), and cross-site request forgery (CSRF) attacks.

symfony/html-sanitizer +10 symfony vulnerability dos xss csrf
3r 1t
critical advisory

Multiple Vulnerabilities in Docker Desktop Allow Remote Code Execution

Multiple vulnerabilities in Docker Desktop versions prior to 4.71.0 allow a remote attacker to execute arbitrary code.

Docker Desktop vulnerability rce docker
2r 1t