Skip to content
Threat Feed

May 2026 (30)

medium advisory

CVE-2026-34651 - Adobe Commerce Uncontrolled Resource Consumption Vulnerability

Adobe Commerce versions 2.4.9-beta1 and earlier are vulnerable to uncontrolled resource consumption, potentially leading to application denial-of-service due to an attacker's ability to exhaust system resources without user interaction.

Commerce dos cve-2026-34651 adobe commerce
2r 1t 1c
medium advisory

Adobe Commerce Uncontrolled Resource Consumption Vulnerability (CVE-2026-34650)

Adobe Commerce versions 2.4.9-beta1, 2.4.8-p4, 2.4.7-p9, 2.4.6-p14, 2.4.5-p16, 2.4.4-p17 and earlier are susceptible to an uncontrolled resource consumption vulnerability (CVE-2026-34650) that allows an unauthenticated attacker to cause a denial-of-service condition by exhausting system resources.

Commerce versions 2.4.9-beta1 +5 dos resource-exhaustion cve
2r 1t 1c
medium advisory

CVE-2026-34649: Adobe Commerce Uncontrolled Resource Consumption Vulnerability

Adobe Commerce versions 2.4.9-beta1 and earlier are susceptible to an uncontrolled resource consumption vulnerability (CVE-2026-34649), allowing an unauthenticated attacker to trigger a denial-of-service condition by exhausting system resources.

Commerce cve-2026-34649 dos resource-consumption
2r 1t 1c
medium advisory

Adobe Commerce SSRF Vulnerability (CVE-2026-34647)

Adobe Commerce versions 2.4.9-beta1 and earlier are vulnerable to Server-Side Request Forgery (SSRF) via a maliciously crafted URL, potentially leading to security feature bypass and unauthorized read access.

Commerce ssrf security-bypass cve-2026-34647 adobe-commerce
2r 1t 1c
high advisory

Adobe Commerce Incorrect Authorization Vulnerability (CVE-2026-34646)

Adobe Commerce versions 2.4.9-beta1 and earlier are vulnerable to an Incorrect Authorization issue (CVE-2026-34646) that allows attackers to bypass security features and gain unauthorized write access without user interaction.

Commerce incorrect authorization security feature bypass ecommerce
2r 2t 1c
high threat

Adobe Commerce Incorrect Authorization Vulnerability (CVE-2026-34645)

Adobe Commerce versions 2.4.9-beta1, 2.4.8-p4, 2.4.7-p9, 2.4.6-p14, 2.4.5-p16, 2.4.4-p17 and earlier are affected by an Incorrect Authorization vulnerability (CVE-2026-34645) that could allow an attacker to bypass security measures and gain unauthorized write access without user interaction.

Commerce <= 2.4.9-beta1 +5 cve security-bypass web-application
2r 1t 1c
critical threat

Multiple Vulnerabilities in Fortinet Products Could Allow for Remote Code Execution

Multiple vulnerabilities in Fortinet's FortiAuthenticator and FortiSandbox products could lead to remote code execution, potentially allowing attackers to install programs, modify data, or create new accounts.

FortiAuthenticator +1 vulnerability rce fortinet
2r 1t
medium advisory

LSASS Process Access via Windows API

This rule identifies access attempts to the LSASS handle, which may indicate an attempt to dump credentials from LSASS memory by detecting specific API calls (OpenProcess, OpenThread, ReadProcessMemory) targeting the 'lsass.exe' process.

Microsoft Defender XDR +1 credential-access windows lsass
2r 2t
high advisory

SPIP RCE Vulnerability in Nginx Configurations (CVE-2026-8430)

SPIP versions prior to 4.4.14 contain a remote code execution vulnerability exploitable in certain Nginx configurations, allowing attackers to execute arbitrary code within the web server's context.

SPIP +1 vulnerability rce webserver
2r 1t 1c
critical threat

CVE-2026-8429: SPIP Remote Code Execution Vulnerability

SPIP versions prior to 4.4.14 contain a remote code execution vulnerability (CVE-2026-8429) in the private space, allowing attackers to execute arbitrary code in the context of the web server, bypassing SPIP security screen protections.

SPIP cve-2026-8429 rce
2r 1t 1c
high advisory

CVE-2026-34682: Adobe Substance3D Designer Out-of-Bounds Write Vulnerability

Adobe Substance3D Designer versions 15.1.0 and earlier are susceptible to an out-of-bounds write vulnerability (CVE-2026-34682) that can lead to arbitrary code execution if a user opens a specially crafted malicious file.

Substance3D Designer cve adobe out-of-bounds write code execution user interaction
2r 1t 1c
high advisory

CVE-2026-34681 - Adobe Substance3D Designer Out-of-Bounds Write Vulnerability

Adobe Substance3D Designer versions 15.1.0 and earlier are vulnerable to an out-of-bounds write, potentially leading to arbitrary code execution if a user opens a malicious file.

Substance3D Designer cve-2026-34681 out-of-bounds write code execution user interaction
2r 1t 1c
critical advisory

Adobe Connect Incorrect Authorization Vulnerability (CVE-2026-34660)

Adobe Connect versions 2025.9.15, 2025.8.157 and earlier are affected by an Incorrect Authorization vulnerability (CVE-2026-34660) that could lead to arbitrary code execution through malicious script injection, requiring user interaction.

Connect cve authorization code execution adobe connect
2r 1t 1c
high threat

Adobe Connect Deserialization of Untrusted Data Vulnerability (CVE-2026-34659)

Adobe Connect versions 2025.9.15, 2025.8.157 and earlier are vulnerable to deserialization of untrusted data, potentially leading to arbitrary code execution if a user interacts with a malicious URL or compromised webpage.

Connect deserialization rce cve-2026-34659
2r 2t 1c
high advisory

Windows Service Installed via an Unusual Client for Privilege Escalation

Identifies the creation of a Windows service by an unusual client process, which can be leveraged to escalate privileges from administrator to SYSTEM by exploiting misconfigurations or vulnerabilities in the service creation process.

VeeamVssSupport +6 privilege-escalation windows-service windows
2r 1t
high advisory

Process Created with an Elevated Token via Token Theft

This rule detects the creation of a process running as SYSTEM while impersonating the token context of a Windows core binary, which adversaries may leverage to escalate privileges and bypass access controls through token theft.

privilege-escalation token-theft windows
2r 1t
high advisory

Privilege Escalation via Rogue Named Pipe Impersonation

An adversary may attempt privilege escalation by masquerading as a known named pipe and manipulating a privileged process to connect to it on Windows systems.

privilege-escalation named-pipe windows
2r 1t
high advisory

Privilege Elevation via Parent Process PID Spoofing

This rule detects parent process spoofing used to create an elevated child process, specifically targeting privilege escalation to SYSTEM, where adversaries may spoof the parent process identifier (PPID) of a new process to evade process-monitoring defenses or to elevate privileges on Windows systems.

Elastic Endpoint +2 privilege-escalation windows ppid-spoofing
2r 1t
high advisory

UAC Bypass Attempt via Windows Directory Masquerading

Detects attempts to bypass User Account Control (UAC) by masquerading as a trusted Microsoft Windows directory, abusing a trailing-space in the path to execute code with elevated privileges.

Elastic Endpoint +4 privilege-escalation uac-bypass windows
2r 1t
high advisory

UAC Bypass via Event Viewer

Detects User Account Control (UAC) bypass attempts using eventvwr.exe to execute code with elevated permissions by identifying child processes of eventvwr.exe, excluding mmc.exe and WerFault.exe, which may indicate unauthorized privilege escalation.

Microsoft Defender XDR +3 privilege-escalation uac-bypass windows
2r 1t
high advisory

UAC Bypass via ICMLuaUtil Elevated COM Interface

Detects User Account Control (UAC) bypass attempts via the ICMLuaUtil Elevated COM interface, where attackers may attempt to stealthily execute code with elevated permissions, potentially leading to privilege escalation.

Elastic Defend +2 privilege-escalation uac-bypass windows
2r 1t
high advisory

Potential Privileged Escalation via SamAccountName Spoofing (CVE-2021-42278)

This rule detects potential privilege escalation attempts by exploiting CVE-2021-42278, which involves spoofing the samAccountName attribute to impersonate a domain controller and elevate privileges from a standard domain user to a domain administrator by identifying suspicious computer account name rename events where a machine account name is renamed to a user-like account name.

Active Directory privilege-escalation windows active-directory cve-2021-42278
2r 1t 1c
high advisory

Privilege Escalation via Rogue Windir Environment Variable

A privilege escalation attempt is detected through modification of the Windows directory (Windir) environment variable, a technique often combined with other vulnerabilities to elevate privileges by redirecting system processes.

Elastic Defend +3 privilege-escalation registry-modification windows
2r 1t
high advisory

Privilege Escalation via Named Pipe Impersonation

Adversaries may escalate privileges by abusing named pipe impersonation, a technique often used with tools like Metasploit's meterpreter getsystem command, where a process writes to a named pipe to facilitate a SYSTEM-token handoff.

Microsoft Defender XDR +4 privilege-escalation named-pipe windows
2r 1t
high advisory

Fortinet Patches Multiple Vulnerabilities in FortiAuthenticator, FortiOS, and FortiSandbox

Fortinet released security advisories on May 12, 2026, addressing critical vulnerabilities including improper access control, incorrect global authorization, and out-of-bounds access across FortiAuthenticator, FortiOS, and FortiSandbox product lines, urging users to apply necessary updates.

FortiAuthenticator +20 fortinet vulnerability patch
2r
high advisory

Service Creation via Local Kerberos Authentication Leading to Privilege Escalation

The rule detects a local successful logon event with Kerberos authentication from localhost, followed by service creation from the same LogonId, indicating a potential Kerberos relay attack for local privilege escalation to LocalSystem.

kerberos relay privilege-escalation windows service-creation
3r 1t
high advisory

Potential Privilege Escalation via InstallerFileTakeOver (CVE-2021-41379)

This rule detects potential exploitation of the InstallerTakeOver vulnerability (CVE-2021-41379), where successful exploitation allows an unprivileged user to escalate privileges to SYSTEM.

Edge privilege-escalation cve-2021-41379 windows
2r 1t 1c
high advisory

Group Policy Abuse for Privilege Addition

Detects modifications to Group Policy Object Attributes that grant privileges to user accounts or add users as local administrators, indicating potential privilege escalation attempts.

Active Directory +1 group-policy privilege-escalation windows
2r 1t
high advisory

Unusual dMSA Account Creation for Privilege Escalation

Detects the creation of a delegated Managed Service Account (dMSA) by an unusual subject account, potentially indicating an attempt to abuse weak permissions for privilege escalation in Active Directory.

winlogbeat-* +2 privilege-escalation windows
3r 1t
high advisory

Unusual Modification of Delegated Managed Service Account Attribute

Detection of modifications to the msDS-ManagedAccountPrecededByLink attribute of a delegated managed service account (dMSA) by an unusual subject account, which attackers can abuse to inherit permissions and elevate privileges in Active Directory.

Active Directory privilege-escalation active-directory windows
3r 1t