Skip to content
Threat Feed

May 2026 (30)

medium advisory

CVE-2026-0244 Prisma SD-WAN ION Improper Certificate Validation Vulnerability

CVE-2026-0244 is an improper certificate validation vulnerability in Palo Alto Networks Prisma SD-WAN ION that allows a man-in-the-middle (MitM) attacker to impersonate the controller.

Prisma SD-WAN ION vulnerability mitm certificate validation
2r 1t
medium advisory

CVE-2026-0261 PAN-OS Authenticated Admin Command Injection Vulnerability

CVE-2026-0261 describes multiple command injection vulnerabilities in Palo Alto Networks PAN-OS software that allow an authenticated administrator to bypass system restrictions and execute arbitrary commands as root.

PAN-OS cve command injection palo alto networks
2r 1t
medium threat

CVE-2026-0242: Trust Protection Foundation SQL Injection Vulnerability

A SQL injection vulnerability in Trust Protection Foundation allows an authenticated attacker to execute arbitrary SQL commands against the product database, potentially leading to sensitive data exposure, data modification, and privilege escalation.

exploited Trust Protection Foundation cve sql-injection palo alto networks
2r 1t
medium threat

CVE-2026-0241: Trust Protection Foundation Authorization Bypass Vulnerabilities

CVE-2026-0241 describes multiple incorrect authorization vulnerabilities in Palo Alto Networks Trust Protection Foundation that allow attackers to bypass access controls and perform unauthorized actions on restricted resources.

exploited Trust Protection Foundation cve authorization bypass palo alto networks
2r 1t
medium advisory

CVE-2026-0258 PAN-OS SSRF vulnerability in IKEv2 certificate URL fetching

CVE-2026-0258 is a medium severity server-side request forgery (SSRF) vulnerability in Palo Alto Networks PAN-OS that allows an unauthenticated attacker to cause the firewall to send network requests to unintended destinations, potentially leading to a denial of service (DoS).

PAN-OS ssrf cve-2026-0258 network palo alto networks
2r 1t
medium advisory

CVE-2026-0250 Palo Alto Networks GlobalProtect App Buffer Overflow Vulnerability

CVE-2026-0250 is a medium severity buffer overflow vulnerability in Palo Alto Networks GlobalProtect App that could allow a man-in-the-middle attacker to disrupt system processes and potentially execute arbitrary code with SYSTEM privileges by intercepting and manipulating requests and responses between the Portal and Gateway.

GlobalProtect App +1 cve-2026-0250 buffer-overflow man-in-the-middle
2r 1t
medium advisory

CVE-2026-0240 Trust Protection Foundation Sensitive Information Disclosure Vulnerability

CVE-2026-0240 is a medium severity information disclosure vulnerability in Palo Alto Networks Trust Protection Foundation, allowing an authenticated attacker to obtain sensitive information from the server's vault, potentially leading to user impersonation and arbitrary modification of configuration settings.

Trust Protection Foundation information-disclosure cve-2026-0240 palo alto networks
2r 2t
medium advisory

CVE-2026-0262 PAN-OS: Denial of Service Vulnerabilities in Network Traffic Parsing

Unauthenticated attackers can cause a denial of service (DoS) condition on Palo Alto Networks PAN-OS firewalls by sending specially crafted network traffic, as described in CVE-2026-0262.

PAN-OS +1 dos denial of service CVE-2026-0262
2r 2t
medium advisory

CVE-2026-0246 Prisma Access Agent Local Privilege Escalation Vulnerability

A local privilege escalation vulnerability exists in Palo Alto Networks Prisma Access Agent versions prior to 26.2.1 on Linux, macOS, and Windows, allowing a locally authenticated non-administrative user to gain root or NT AUTHORITY\SYSTEM privileges and execute arbitrary code.

Prisma Access Agent privilege-escalation cve
2r 1t
medium advisory

CVE-2026-0251: Palo Alto Networks GlobalProtect App Local Privilege Escalation

Multiple local privilege escalation vulnerabilities exist in Palo Alto Networks GlobalProtect App, allowing a local user to escalate privileges to NT AUTHORITY\SYSTEM on Windows and root on macOS and Linux, enabling arbitrary command execution with administrative privileges.

GlobalProtect App privilege-escalation cve-2026-0251 palo alto networks globalprotect
3r 1t
low threat

CVE-2026-0238: Palo Alto Networks Broker VM Improper Input Validation

CVE-2026-0238 is an improper input validation vulnerability in Palo Alto Networks Broker VM that allows an authenticated administrator to inject arbitrary content into certain fields, affecting versions 30.0 prior to 30.0.24.

exploited Broker VM vulnerability input validation
2r
medium advisory

CVE-2026-0248 Prisma Access Agent Improper Certificate Validation Vulnerability

CVE-2026-0248 is an improper certificate validation vulnerability in Prisma Access Agent for Android and Chrome OS, enabling a man-in-the-middle (MitM) attack to intercept VPN traffic and capture sensitive device information by presenting a certificate issued by a trusted Certificate Authority.

Prisma Access Agent cve-2026-0248 mitm vpn certificate-validation
2r 2t
medium advisory

CVE-2026-0247 Prisma Access Agent Endpoint DLP: Authorization Bypass Vulnerabilities

Multiple authorization bypass vulnerabilities exist in the Endpoint DLP component of Prisma Access Agent, allowing a local attacker to bypass authentication controls and execute privileged operations on macOS and Windows systems with Endpoint DLP enabled; versions prior to 26.2.1 are affected.

Prisma Access Agent cve-2026-0247 privilege-escalation authorization-bypass endpoint-dlp
2r 1t
high advisory

CVE-2026-4609: ProfileGrid WordPress Plugin Authentication Bypass Vulnerability

The ProfileGrid WordPress plugin versions up to 5.9.8.4 contain an authentication bypass vulnerability (CVE-2026-4609) that allows authenticated users with subscriber-level privileges to add themselves or others to arbitrary groups, including paid groups, without proper authorization, leading to privilege escalation and potential financial impact.

ProfileGrid – User Profiles, Groups and Communities plugin for WordPress <= 5.9.8.4 authentication bypass wordpress plugin privilege escalation cve-2026-4609
1r 1t 1c
medium advisory

CVE-2026-6177 - Custom Twitter Feeds WordPress Plugin Stored XSS

The Custom Twitter Feeds plugin for WordPress is vulnerable to stored cross-site scripting (XSS) in versions up to and including 2.5.4 due to insufficient output escaping, allowing unauthenticated attackers to inject arbitrary web scripts.

Custom Twitter Feeds plugin <= 2.5.4 xss wordpress CVE-2026-6177
2r 1t 1c
high advisory

RTMKit Addons for Elementor WordPress Plugin LFI Vulnerability (CVE-2026-3425)

The RTMKit Addons for Elementor plugin for WordPress is vulnerable to local file inclusion (LFI) via the 'path' parameter in the 'get_content' AJAX action, allowing authenticated attackers with Author-level access or higher to include and execute arbitrary PHP files, leading to potential code execution.

RTMKit Addons for Elementor plugin <= 2.0.2 lfi wordpress plugin cve-2026-3425
1r 2t 1c
high advisory

CVE-2026-4798 - Avada Builder Plugin SQL Injection Vulnerability

The Avada Builder plugin for WordPress is vulnerable to time-based SQL Injection (CVE-2026-4798) via the ‘product_order’ parameter in versions up to 3.15.1, potentially allowing unauthenticated attackers to extract sensitive database information if WooCommerce was previously used and deactivated.

Avada Builder plugin +1 sql-injection wordpress avada-builder cve-2026-4798
2r 1t 1c
high threat

JoomSport WordPress Plugin Vulnerable to Time-Based Blind SQL Injection (CVE-2026-6929)

The JoomSport plugin for WordPress is vulnerable to time-based blind SQL Injection (CVE-2026-6929) via the 'sortf' parameter in versions up to 5.7.7, allowing unauthenticated attackers to extract sensitive information from the database.

JoomSport – for Sports: Team & League, Football, Hockey & more plugin <= 5.7.7 sqli wordpress cve-2026-6929 joomsport injection
2r 1t 1c
medium advisory

coreActivity: Activity Logging for WordPress Plugin Vulnerable to PHP Object Injection (CVE-2026-7635)

The coreActivity: Activity Logging for WordPress plugin for WordPress is vulnerable to PHP Object Injection (CVE-2026-7635), allowing unauthenticated attackers to inject a crafted PHP serialized payload via the User-Agent header, leading to a persistent Denial of Service condition.

coreActivity: Activity Logging for WordPress plugin <= 3.0 cve wordpress php object injection denial of service
2r 1t 1c
high advisory

claude-code-cache-fix Local Code Execution via Python Injection (CVE-2026-45136)

A vulnerability exists in claude-code-cache-fix versions 3.5.0 and 3.5.1 where the `tools/quota-statusline.sh` script interpolates Claude Code's hook stdin payload directly into a Python triple-quoted string literal, allowing local code execution via Python triple-quote injection (CVE-2026-45136).

claude-code-cache-fix code-execution injection linux
2r 1t
high advisory

Anchor Program Validation Bypass Vulnerability

A logic error in anchor-lang versions 1.0.0 to 1.0.1 causes anchor programs to accept any program ID when requiring the system program ID, resulting in false assumptions that could lead to arbitrary CPI in programs invoking system program instructions, potentially leading to validation bypass and unauthorized account control.

anchor-lang anchor solana account-validation cpi-bypass
1r 1t
high advisory

Uniget Command Injection Vulnerability via Malicious Metadata

Uniget is vulnerable to command injection because the `check` field is loaded directly from untrusted JSON metadata without validation, allowing an attacker to execute arbitrary shell commands on the victim's system when performing common uniget operations.

cli command-injection vulnerability linux
2r 1t
medium advisory

Anchor: InterfaceAccount Allows Account Substitution

The `InterfaceAccount` in `anchor-lang` allows an unexpected account type to be passed due to disabled discriminator checking, patched in version 1.0.0-rc.2 and later.

anchor-lang anchor solana interfaceaccount account-substitution
2r
high advisory

SiYuan Publish-Mode Reader Configuration and Index Mutation Vulnerability

SiYuan publish-mode Reader can mutate Conf and SQL index via 8 ungated APIs, leading to configuration changes, denial of service, data corruption, and information disclosure by manipulating cloud sync intervals, graph configurations, SQL block content, and recent-documents lists.

siyuan misconfiguration unauthorized_access data_manipulation
2r 1t
critical advisory

Obot Authorization Bypass in /mcp-connect/{id} Endpoint

Obot version 0.21.0 has an authorization bypass vulnerability in the `/mcp-connect/{id}` endpoint allowing any authenticated user to connect to any registered MCP server, regardless of permissions, leading to unauthorized access and actions on upstream services.

obot authorization bypass privilege escalation mcp cloud
2r 2t
medium advisory

Goobi Viewer Unauthenticated Solr Streaming Expression Proxy Vulnerability

The Goobi viewer REST endpoint accepted an arbitrary Solr streaming expression from unauthenticated network clients, enabling attackers to read, modify, or delete the complete Solr index; this was resolved by removing the affected API endpoint.

Goobi viewer solr proxy unauthenticated CVE-2026-45083 critical
2r 1t
critical threat

SiYuan Bazaar Marketplace Stored XSS Leads to Electron RCE

SiYuan's Bazaar marketplace is vulnerable to stored cross-site scripting (XSS) via unescaped package metadata, leading to arbitrary OS command execution in the desktop Electron client.

github.com/siyuan-note/siyuan/kernel xss rce electron siyuan
2r 1t
high advisory

LangSmith SDK Untrusted Manifest Deserialization Vulnerability

The LangSmith SDK is vulnerable to untrusted manifest deserialization when pulling public prompts via `pull_prompt`, potentially leading to SSRF, prompt injection, or sensitive data exposure; CVE-2026-45134.

langsmith +2 deserialization ssrf prompt-injection
2r 3t
high advisory

Grav CMS Twig Sandbox Vulnerability Allows Plugin Secret Exfiltration

A vulnerability in the Grav CMS Twig sandbox allow-list allows any user with the `admin.pages` role to call `config.toArray()` from within a page body, dumping the entire merged site configuration, including all plugin secrets, into the rendered HTML.

Grav twig rce secret-exfiltration
2r
high advisory

Nautobot Webhook SSRF Vulnerability

Nautobot's Webhook feature is vulnerable to server-side request forgery (SSRF), allowing users with `add` or `change` permissions to make requests to unauthorized hosts, which is fixed in versions 2.4.33 and 3.1.2 by introducing settings to restrict webhook functionality.

Nautobot +1 ssrf cve-2026-44797
2r 1t