September 2026 (30)
Cross-Site Scripting Vulnerability in AVideo YPTSocket Plugin
9 TTPs 1 CVEAn unauthenticated XSS vulnerability in the AVideo YPTSocket plugin allows attackers to execute arbitrary JavaScript in victim browsers via crafted websocket callback messages.
Remote Code Execution via Improper Input Validation in rcourtman Pulse
1 rule 1 TTP 1 CVEAn improper input validation vulnerability in the rcourtman Pulse Quick Security Setup Handler allows remote attackers to perform arbitrary operations via the Username argument.
SparroWock Backdoor Analysis
2 TTPsSparroWock is a backdoor malware that utilizes custom command-and-control communication mechanisms to execute arbitrary commands on compromised Windows systems, establishing persistence to maintain long-term access.
Critical Vulnerabilities Patched in Cisco FMC, ISE, and Nexus Dashboard
2 TTPs 3 CVEsCisco has released emergency patches for dozens of critical vulnerabilities across Identity Services Engine (ISE), Secure Firewall Management Center (FMC), and Nexus Dashboard, including several flaws currently exploited in the wild.
Denial of Service Vulnerability in BIND Named Service
1 TTP 6 CVEsA memory management flaw in BIND 9 allows an attacker-controlled authoritative DNS server to trigger a service abort by providing a maliciously crafted 65536-byte negative DNS response.
MovieReaper Multi-Stage Trojan Campaign
1 rule 3 TTPs 4 IOCsMovieReaper is a multi-stage modular Trojan distributed via compromised torrent files on itorrents.org that leverages the Solana blockchain for C2 discovery and achieves persistence via UAC bypass.
Cross-Site Scripting Vulnerability in Drupal Core
1 TTPA vulnerability in Drupal Core allows an unauthenticated attacker to perform a Cross-Site Scripting (XSS) attack to execute malicious scripts in a user's browser.
Multiple Vulnerabilities in Znuny
1 TTPZnuny is affected by multiple security vulnerabilities that allow a remote, unauthenticated attacker to conduct SQL injection and perform unauthorized privilege escalation.
Information Disclosure Vulnerability in Graylog
1 TTPAn authenticated remote attacker can exploit a vulnerability in Graylog to gain unauthorized access to sensitive information within the application.
Multiple Denial of Service Vulnerabilities in Dovecot
1 TTPDovecot is affected by multiple vulnerabilities that can be exploited by a remote attacker to cause a denial-of-service condition on the affected service.
Information Disclosure and Spoofing Vulnerability in Eclipse Jetty
1 CVEA vulnerability in Eclipse Jetty, identified as CVE-2024-8184, allows a remote unauthenticated attacker to manipulate displayed information and gain unauthorized access to sensitive data.
Remote Code Execution Vulnerability in Nextcloud
2 TTPs 1 CVEA critical vulnerability in Nextcloud Hub, tracked as CVE-2024-28112, allows remote attackers to execute arbitrary code on the underlying application server.
Varnish HTTP Cache Denial of Service Vulnerability
1 CVEA vulnerability in Varnish HTTP Cache allows a remote, unauthenticated attacker to trigger a denial of service condition, potentially causing service instability or resource exhaustion.
Security Advisories for cPanel WHM and ConfigServer Security & Firewall
3 CVEsWebPros has released patches for multiple critical vulnerabilities in cPanel & WebHost Manager and ConfigServer Security & Firewall, including an SQL injection flaw in the EmailTrack component.
Arbitrary File Upload Vulnerability in Paid Downloads WordPress Plugin
1 rule 1 TTP 1 CVEAn unauthenticated arbitrary file upload vulnerability in the Paid Downloads plugin (<= 3.15) allows remote attackers to execute code by bypassing file type validation via the admin_request_handler function.
Memory Corruption in Linux Kernel I2C Subsystem (CVE-2026-25278)
1 TTP 1 CVEA race condition vulnerability in the Linux kernel I2C subsystem allows local attackers to trigger memory corruption, potentially leading to system crashes or privilege escalation.
Access Token Theft in rmcp via OAuth Metadata Spoofing
2 TTPs 1 CVEThe rmcp library fails to validate the resource parameter during OAuth metadata discovery per RFC 9728, allowing attackers to spoof metadata and steal access tokens for legitimate MCP servers.
Cross-Site Scripting Vulnerability in @nuxtjs/mdc
1 TTP 1 CVEThe @nuxtjs/mdc package contains an XSS vulnerability (CVE-2026-63671) due to improper sanitization of SVG xlink:href attributes and iframe data:text/html sources during markdown parsing.
Privilege Escalation Vulnerability in Acronis Backup for cPanel and Plesk
1 TTPAcronis Backup for cPanel and WHM and the extension for Plesk contain an incorrect default permissions vulnerability (CVE-2026-87886) that enables privilege escalation.
Remote Code Execution in Craft CMS via HMAC Signature Misuse
3 TTPs 1 CVECraft CMS versions 4.8.0 through 4.18.5 and 5.0.0 through 5.10.12 contain a critical vulnerability allowing authenticated users to achieve remote code execution by injecting malicious payloads into improperly validated redirect parameters.
Remote Argument Injection in HKUDS nanobot
3 TTPs 1 CVEHKUDS nanobot versions up to 0.2.1 contain an argument injection vulnerability in the ExecTool component that allows remote attackers to execute arbitrary commands.
Supply Chain Vulnerability in quay-builder-qemu via Mutable GitHub Action
2 TTPs 1 CVEA supply chain vulnerability in quay-builder-qemu allows for remote code execution and credential theft due to the use of a mutable GitHub Action dependency.
Manticore Search Multi-Statement Authorization Bypass
1 TTP 1 CVEManticore Search versions 27.0.0 through 28.4.3 contain an authorization vulnerability that allows authenticated read-only users to execute unauthorized SQL statements by appending malicious queries to multi-statement requests.
Authentication Bypass in OpenSign getDocument Function
2 TTPs 1 CVEOpenSign versions through 2.41.3 contain an authentication bypass vulnerability allowing unauthenticated attackers to retrieve sensitive document data and download tokens when OTP verification is disabled.
Access Control Bypass in Wiki.js via Path Prefix Confusion
1 TTP 1 CVEWiki.js versions 2.5.314 and earlier contain an access control vulnerability where insufficient path validation allows authenticated users to access unauthorized pages sharing a common prefix.
Privilege Escalation in WebVirtCloud via UserInstance Grant Validation
1 CVEWebVirtCloud suffers from a privilege escalation vulnerability (CVE-2026-92761) where the get_instance gate fails to validate permission flags, enabling read-only users to perform administrative actions.
CVE-2026-92751: CSRF Vulnerability in CMAK Allows Unauthenticated State Changes
1 TTP 1 CVECMAK versions up to 3.0.0.6 are vulnerable to Cross-Site Request Forgery (CSRF) due to missing request filters, enabling attackers to execute unauthorized actions like cluster deletion or configuration changes.
Path Traversal in ComfyUI Dataset Save Nodes
2 TTPs 1 CVEComfyUI versions prior to 0.30.0 are vulnerable to path traversal via unsanitized input in dataset save nodes, allowing attackers to write arbitrary files and potentially achieve code execution.
SSRF Vulnerability in changedetection.io
2 TTPs 1 CVEchangedetection.io versions 0.60.6 and earlier contain a Server-Side Request Forgery (SSRF) vulnerability allowing unauthenticated attackers to access internal network resources.
CSRF Vulnerability in phpList Mass Subscriber Removal
1 TTP 1 CVEphpList versions prior to 3.6.17 are vulnerable to CSRF, allowing an attacker to force an authenticated administrator to delete or blacklist subscribers without authorization.