Skip to content
Threat Feed

September 2026 (30)

high advisory

Cross-Site Scripting Vulnerability in AVideo YPTSocket Plugin

An unauthenticated XSS vulnerability in the AVideo YPTSocket plugin allows attackers to execute arbitrary JavaScript in victim browsers via crafted websocket callback messages.

AVideo +3 web-application xss injection web-security access-control pii-leak account-takeover authentication-bypass +1
9t 1c updated
critical advisory

Remote Code Execution via Improper Input Validation in rcourtman Pulse

An improper input validation vulnerability in the rcourtman Pulse Quick Security Setup Handler allows remote attackers to perform arbitrary operations via the Username argument.

Pulse
1r 1t 1c
rumour rumour

SparroWock Backdoor Analysis

SparroWock is a backdoor malware that utilizes custom command-and-control communication mechanisms to execute arbitrary commands on compromised Windows systems, establishing persistence to maintain long-term access.

malware backdoor persistence command-and-control
2t
critical threat

Critical Vulnerabilities Patched in Cisco FMC, ISE, and Nexus Dashboard

Cisco has released emergency patches for dozens of critical vulnerabilities across Identity Services Engine (ISE), Secure Firewall Management Center (FMC), and Nexus Dashboard, including several flaws currently exploited in the wild.

exploited Secure Firewall Management Center +4 vulnerability cisco network-security patch-management
2t 3c
medium advisory

Denial of Service Vulnerability in BIND Named Service

A memory management flaw in BIND 9 allows an attacker-controlled authoritative DNS server to trigger a service abort by providing a maliciously crafted 65536-byte negative DNS response.

BIND +10 denial-of-service dns infrastructure
1t 6c updated
high advisory

MovieReaper Multi-Stage Trojan Campaign

MovieReaper is a multi-stage modular Trojan distributed via compromised torrent files on itorrents.org that leverages the Solana blockchain for C2 discovery and achieves persistence via UAC bypass.

Windows trojan modular blockchain torrent malware
1r 3t 4i
medium advisory

Cross-Site Scripting Vulnerability in Drupal Core

A vulnerability in Drupal Core allows an unauthenticated attacker to perform a Cross-Site Scripting (XSS) attack to execute malicious scripts in a user's browser.

Drupal Core
1t
high advisory

Multiple Vulnerabilities in Znuny

Znuny is affected by multiple security vulnerabilities that allow a remote, unauthenticated attacker to conduct SQL injection and perform unauthorized privilege escalation.

Znuny vulnerability web-application sql-injection privilege-escalation
1t
medium advisory

Information Disclosure Vulnerability in Graylog

An authenticated remote attacker can exploit a vulnerability in Graylog to gain unauthorized access to sensitive information within the application.

Graylog vulnerability information-disclosure log-management
1t
medium advisory

Multiple Denial of Service Vulnerabilities in Dovecot

Dovecot is affected by multiple vulnerabilities that can be exploited by a remote attacker to cause a denial-of-service condition on the affected service.

Dovecot denial-of-service vulnerability
1t
low advisory

Information Disclosure and Spoofing Vulnerability in Eclipse Jetty

A vulnerability in Eclipse Jetty, identified as CVE-2024-8184, allows a remote unauthenticated attacker to manipulate displayed information and gain unauthorized access to sensitive data.

Jetty vulnerability webserver cve-2024-8184
1c
low advisory

Remote Code Execution Vulnerability in Nextcloud

A critical vulnerability in Nextcloud Hub, tracked as CVE-2024-28112, allows remote attackers to execute arbitrary code on the underlying application server.

Nextcloud Hub web-application vulnerability rce
2t 1c
medium advisory

Varnish HTTP Cache Denial of Service Vulnerability

A vulnerability in Varnish HTTP Cache allows a remote, unauthenticated attacker to trigger a denial of service condition, potentially causing service instability or resource exhaustion.

Varnish HTTP Cache vulnerability dos webserver
1c
high advisory

Security Advisories for cPanel WHM and ConfigServer Security & Firewall

WebPros has released patches for multiple critical vulnerabilities in cPanel & WebHost Manager and ConfigServer Security & Firewall, including an SQL injection flaw in the EmailTrack component.

PoC cPanel & WebHost Manager +1 vulnerability web-application cpanel sql-injection
3c updated
high advisory

Arbitrary File Upload Vulnerability in Paid Downloads WordPress Plugin

An unauthenticated arbitrary file upload vulnerability in the Paid Downloads plugin (<= 3.15) allows remote attackers to execute code by bypassing file type validation via the admin_request_handler function.

Paid Downloads web-vulnerability wordpress remote-code-execution
1r 1t 1c
high advisory

Memory Corruption in Linux Kernel I2C Subsystem (CVE-2026-25278)

A race condition vulnerability in the Linux kernel I2C subsystem allows local attackers to trigger memory corruption, potentially leading to system crashes or privilege escalation.

Linux Kernel linux kernel vulnerability privilege-escalation
1t 1c
high advisory

Access Token Theft in rmcp via OAuth Metadata Spoofing

The rmcp library fails to validate the resource parameter during OAuth metadata discovery per RFC 9728, allowing attackers to spoof metadata and steal access tokens for legitimate MCP servers.

rmcp
2t 1c
high advisory

Cross-Site Scripting Vulnerability in @nuxtjs/mdc

The @nuxtjs/mdc package contains an XSS vulnerability (CVE-2026-63671) due to improper sanitization of SVG xlink:href attributes and iframe data:text/html sources during markdown parsing.

@nuxtjs/mdc xss web-vulnerability nuxtjs
1t 1c
high advisory

Privilege Escalation Vulnerability in Acronis Backup for cPanel and Plesk

Acronis Backup for cPanel and WHM and the extension for Plesk contain an incorrect default permissions vulnerability (CVE-2026-87886) that enables privilege escalation.

Backup +1 vulnerability privilege-escalation server-security
1t
high advisory

Remote Code Execution in Craft CMS via HMAC Signature Misuse

Craft CMS versions 4.8.0 through 4.18.5 and 5.0.0 through 5.10.12 contain a critical vulnerability allowing authenticated users to achieve remote code execution by injecting malicious payloads into improperly validated redirect parameters.

Craft CMS +1 cve authorization graphql web-vulnerability
3t 1c
high advisory

Remote Argument Injection in HKUDS nanobot

HKUDS nanobot versions up to 0.2.1 contain an argument injection vulnerability in the ExecTool component that allows remote attackers to execute arbitrary commands.

nanobot +1 vulnerability rce command-injection ssrf cloud-security
3t 1c updated
high advisory

Supply Chain Vulnerability in quay-builder-qemu via Mutable GitHub Action

A supply chain vulnerability in quay-builder-qemu allows for remote code execution and credential theft due to the use of a mutable GitHub Action dependency.

quay-builder-qemu supply-chain ci-cd vulnerability
2t 1c
high advisory

Manticore Search Multi-Statement Authorization Bypass

Manticore Search versions 27.0.0 through 28.4.3 contain an authorization vulnerability that allows authenticated read-only users to execute unauthorized SQL statements by appending malicious queries to multi-statement requests.

Manticore Search vulnerability sql-injection manticore
1t 1c
high advisory

Authentication Bypass in OpenSign getDocument Function

OpenSign versions through 2.41.3 contain an authentication bypass vulnerability allowing unauthenticated attackers to retrieve sensitive document data and download tokens when OTP verification is disabled.

OpenSign authentication-bypass cloud-security information-disclosure
2t 1c
high advisory

Access Control Bypass in Wiki.js via Path Prefix Confusion

Wiki.js versions 2.5.314 and earlier contain an access control vulnerability where insufficient path validation allows authenticated users to access unauthorized pages sharing a common prefix.

Wiki.js access-control web-application privilege-escalation
1t 1c
high advisory

Privilege Escalation in WebVirtCloud via UserInstance Grant Validation

WebVirtCloud suffers from a privilege escalation vulnerability (CVE-2026-92761) where the get_instance gate fails to validate permission flags, enabling read-only users to perform administrative actions.

WebVirtCloud privilege-escalation web-application virtualization
1c
medium advisory

CVE-2026-92751: CSRF Vulnerability in CMAK Allows Unauthenticated State Changes

CMAK versions up to 3.0.0.6 are vulnerable to Cross-Site Request Forgery (CSRF) due to missing request filters, enabling attackers to execute unauthorized actions like cluster deletion or configuration changes.

CMAK
1t 1c
high advisory

Path Traversal in ComfyUI Dataset Save Nodes

ComfyUI versions prior to 0.30.0 are vulnerable to path traversal via unsanitized input in dataset save nodes, allowing attackers to write arbitrary files and potentially achieve code execution.

ComfyUI web-vulnerability path-traversal cve-2026-92816
2t 1c
high advisory

SSRF Vulnerability in changedetection.io

changedetection.io versions 0.60.6 and earlier contain a Server-Side Request Forgery (SSRF) vulnerability allowing unauthenticated attackers to access internal network resources.

changedetection.io web-vulnerability ssrf
2t 1c
high advisory

CSRF Vulnerability in phpList Mass Subscriber Removal

phpList versions prior to 3.6.17 are vulnerable to CSRF, allowing an attacker to force an authenticated administrator to delete or blacklist subscribers without authorization.

phpList web-vulnerability csrf patch-management
1t 1c