Skip to content
Threat Feed

July 2026 (30)

high threat

CVE-2026-14996: IBM Aspera Faspex 5 Session Management Vulnerability

CVE-2026-14996 details a high-severity vulnerability (CVSS v3.1 8.2, CWE-613) in IBM Aspera Faspex 5 versions 5.0.0 through 5.0.15.4 that allows unauthenticated, remote attackers to exploit insufficient session management, leading to high confidentiality impact and low integrity impact.

exploited Aspera Faspex 5 +1 vulnerability session-management IBM cve
1t 1c
medium advisory

IBM WebSphere Application Server Liberty Denial of Service Vulnerability (CVE-2026-16192)

A denial of service vulnerability, CVE-2026-16192, affects IBM WebSphere Application Server - Liberty versions 17.0.0.3 through 26.0.0.8 when the `restConnector-2.0` feature is enabled, allowing an unauthenticated attacker to cause service unavailability.

WebSphere Application Server - Liberty +1 denial-of-service vulnerability websphere
2c
high advisory

IBM WebSphere Application Server Unsafe Deserialization Vulnerability

A critical unsafe deserialization vulnerability, CVE-2026-14974, in IBM WebSphere Application Server versions 8.5 and 9.0 traditional, allows a remote attacker to execute arbitrary code by processing specially crafted untrusted data, potentially leading to full system compromise.

WebSphere Application Server 8.5 +1 vulnerability deserialization rce websphere cve
2t 1c
high advisory

IBM Instana Node.js Tracer Vulnerable to Prototype Pollution (CVE-2026-14893)

A high-severity prototype pollution vulnerability, CVE-2026-14893, exists in the IBM Instana Node.js tracer component (@instana/core version 6.2.1) affecting IBM Observability with Instana Agent builds 1.0.303 through 1.0.320, allowing an attacker to modify critical application behavior through the configuration normalization API.

IBM Observability with Instana +1 vulnerability prototype-pollution nodejs instana
1c 2i
high threat

IBM Langflow OSS Vulnerability Allows FAISS Namespace Reuse and Information Disclosure (CVE-2026-13442)

A critical vulnerability, CVE-2026-13442, in IBM Langflow OSS versions 1.0.0 through 1.10.1 enables an authenticated attacker to reuse other users' FAISS namespaces, leading to cross-user information disclosure of owner-only vector content and potential limited integrity impact via persistent poisoning of query results.

exploited Langflow OSS 1.0.0 +1 information-disclosure software-vulnerability access-control-bypass
5t 1c
critical advisory

IBM Aspera Desktop App Path Traversal Vulnerability (CVE-2026-14973)

The IBM Aspera Desktop App (versions 1.0.5 through 1.0.19) is affected by a path traversal vulnerability (CWE-22) which allows files to be written outside of the user's selected download destination, leading to high integrity and confidentiality impacts through arbitrary file write operations, and requires user interaction to exploit.

Aspera Desktop App +1 vulnerability path-traversal ibm aspera cve critical-vulnerability
1t 1c
critical advisory

CVE-2026-14959: IBM Aspera Faspex 5 Remote Code Execution via Shell Command Injection

A critical vulnerability, CVE-2026-14959, in IBM Aspera Faspex 5 (versions 5.0.0 through 5.0.15.4) allows a remote authenticated attacker to execute arbitrary code due to a shell command injection flaw, potentially leading to full system compromise and significant data loss or service disruption.

Aspera Faspex 5 vulnerability command-injection rce remote-code-execution ibm
2t 1c
critical advisory

IBM Aspera Faspex 5 Remote Code Execution Vulnerability (CVE-2026-14958)

A critical remote code execution vulnerability (CVE-2026-14958) in IBM Aspera Faspex 5, affecting versions 5.0.0 through 5.0.15.4, allows a remote authenticated attacker to execute arbitrary code due to unquoted shell interpolation, posing a significant risk of system compromise.

Aspera Faspex 5 remote-code-execution vulnerability os-command-injection web-application
1r 2t 1c
high advisory

SuperPlane Broken Object-Level Authorization Vulnerability (CVE-2026-57510)

A critical broken object-level authorization vulnerability in SuperPlane's CanvasService gRPC handlers, tracked as CVE-2026-57510, allows authenticated users with viewer-level access to bypass organization scoping and access resources across tenant boundaries, leading to data collection and system impact.

SuperPlane < 0.27.0 authorization-bypass api-security saas cloud multi-tenancy grpc cve
3t 1c
high advisory

Fission Zip Slip Vulnerability in pkg/utils/zip.go Unarchive Function

The Unarchive function in Fission's pkg/utils/zip.go was vulnerable to a Zip Slip path traversal. An attacker controlling a malicious zip archive's URL could leverage this to write files outside the intended destination directory, potentially leading to overwriting sensitive files, accessing secrets from mounted volumes, or tampering with the fetcher's own binaries, impacting other tenants in a multi-tenant containerized environment. This vulnerability affects Fission versions up to and including v1.24.0 and was fixed in v1.25.0.

Fission <= 1.24.0 zip-slip path-traversal vulnerability cloud linux
3t 1c
high advisory

SQL Injection Vulnerability in IBM Sterling B2B Integrator and File Gateway (CVE-2026-7769)

A remote attacker can exploit CVE-2026-7769, an SQL injection vulnerability in IBM Sterling B2B Integrator and IBM Sterling File Gateway, to send specially crafted SQL statements, allowing them to view, add, modify, or delete information in the backend database.

Sterling B2B Integrator +5 sql-injection vulnerability data-manipulation enterprise-software
3t 1c
high advisory

Artica Proxy Session Fixation Vulnerability CVE-2026-66745

A session fixation vulnerability, CVE-2026-66745, in Artica Proxy before version 4.50.000000 Service Pack 7 allows unauthenticated attackers to hijack administrative sessions by pre-setting a PHPSESSID on a victim's browser, leading to full administrative control upon victim authentication.

Artica Proxy vulnerability session-fixation web-application proxy
1t 1c 1i
high threat

Adobe Bridge Untrusted Search Path Vulnerability Allows Arbitrary Code Execution (CVE-2026-48395)

An Untrusted Search Path vulnerability (CVE-2026-48395) in Adobe Bridge, affecting versions up to 16.0.5 and 15.1.6, can be exploited by an attacker to achieve arbitrary code execution in the context of the current user when a victim opens a specially crafted malicious file.

exploited Adobe Bridge +1 vulnerability code-execution user-interaction adobe
2t 1c 1i
high advisory

CVE-2026-48393: Out-of-Bounds Write Vulnerability in Adobe Bridge Leads to Arbitrary Code Execution

An out-of-bounds write vulnerability (CVE-2026-48393, CWE-787) in Adobe Bridge allows for arbitrary code execution in the context of the current user, requiring user interaction by opening a specially crafted malicious file.

Adobe Bridge +1 arbitrary-code-execution out-of-bounds-write user-interaction adobe
2t 1c
high advisory

CVE-2026-48390: Adobe Bridge Privilege Escalation via Incorrect Authorization

A critical privilege escalation vulnerability, CVE-2026-48390, in Adobe Bridge allows an attacker to gain unauthorized read and write access if a victim opens a specially crafted malicious file, leading to potential system compromise.

Adobe Bridge +1 privilege-escalation incorrect-authorization adobe cve user-interaction
2t 1c
high advisory

CRIU Restartable Sequences Vulnerability Allows Container Privilege Escalation

A flaw, CVE-2026-18107, in CRIU's handling of restartable sequences (rseq) during checkpoint/restore allows a malicious process inside a container to hijack CRIU's parasite code injection, enabling the spoofing of process credentials in the checkpoint image and leading to elevated capabilities and zeroed UIDs/GIDs upon restore.

CRIU +3 container-security privilege-escalation linux cloud-native
1t 1c
critical advisory

WP Password Policy Plugin Privilege Escalation via Crafted POST Request (CVE-2026-15992)

The WP Password Policy plugin for WordPress, in versions up to and including 3.7.1, is vulnerable to privilege escalation, allowing authenticated attackers with subscriber-level access to escalate their privileges to Administrator by sending a crafted POST request to the password-reset form endpoint, leveraging missing authorization checks and nonce verification.

WP Password Policy wordpress privilege-escalation web-vulnerability php
1r 1t 1c
high advisory

Detection of Common Ransomware File Extension Modifications

This analytic identifies ransomware activity by detecting file creation or modification events on endpoint filesystems where the resulting file extensions match known ransomware patterns, potentially leading to significant data loss and operational disruption.

ransomware endpoint-detection file-modification impact Rhysida Ransomware Prestige Ransomware LockBit Ransomware Medusa Ransomware +7
1r 1t
medium advisory

Progress Software Security Advisory Addresses Multiple Vulnerabilities

Progress Software has issued a security advisory (AV26-755) addressing multiple vulnerabilities, identified by CVEs CVE-2026-59686 through CVE-2026-59690, across several of its products including ECS Connection Manager, LoadMaster, MOVEit WAF, Multi Tenant, and Object Scale Connection Manager, with specific versions prior to various patch levels being vulnerable, urging administrators to apply necessary updates to secure their systems.

ECS Connection Manager < 7.2.63.3 +4 vulnerability cve security-advisory patch-management
5c
low advisory

Unusual Windows User Privilege Elevation Activity

An Elastic machine learning rule detects atypical user context switching on Windows systems, leveraging tools like 'runas,' which may indicate account takeover or privilege escalation, prompting defenders to investigate user accounts, activity timestamps, and source devices for potential compromise.

endpoint windows threat-detection machine-learning privilege-escalation
2t
low advisory

Detection of Unusual Windows Services via Machine Learning

This threat involves the detection of unusual Windows services, which can indicate unauthorized service execution, malware, or persistence mechanisms, with a machine learning job identifying atypical services by comparing them against known legitimate patterns to aid in early threat detection and response.

machine-learning-detection persistence execution windows endpoint
2t
low advisory

Anomalous Windows Process Creation Detected by Machine Learning

Elastic Security's machine learning rule `v3_windows_anomalous_process_creation_ea` detects unusual parent-child process relationships on Windows systems, indicating potential malware execution or persistence mechanisms and allowing for early detection of new or emerging threats that bypass traditional antivirus.

endpoint windows machine-learning persistence execution anomaly-detection
2t
low advisory

Unusual Process Detection for Windows Hosts via Machine Learning

An Elastic Security machine learning rule detects rare and unusual processes on individual Windows hosts, indicating potential unauthorized services, malware execution, or persistence mechanisms.

endpoint windows machine-learning persistence threat-detection
2t
low advisory

Unusual Process For a Linux Host Detection

An Elastic machine learning rule detects rare processes on Linux hosts, indicating potential persistence mechanisms, unauthorized services, or malware execution by an unknown threat actor, impacting system integrity and security.

persistence linux machine-learning endpoint threat-detection
1t
low advisory

Unusual Process Writing Data to an External Device Detected by Machine Learning

Elastic's Data Exfiltration Detection integration leverages machine learning to identify rare processes writing data to external devices, indicating potential data exfiltration by adversaries using benign-looking processes.

Elastic Defend +15 exfiltration machine-learning elastic-defend endpoint lateral-movement rdp anomaly-detection privilege-escalation +29
22t
low advisory

Potential Data Exfiltration Activity to an Unusual Region

Elastic's machine learning job identifies potential data exfiltration activity to unusual geo-locations by detecting anomalies in network traffic patterns, indicating adversaries leveraging command and control channels to transfer data outside normal organizational patterns.

Elastic Stack +5 exfiltration data-exfiltration machine-learning elastic network-detection command-and-control initial-access persistence
4t
low advisory

Unusual Linux Network Activity Detected by Machine Learning

This Elastic machine learning rule detects anomalous network activity originating from Linux processes that typically do not engage in network communication, signifying potential command-and-control, lateral movement, persistence, or data exfiltration activity, often via process exploitation or injection.

Elastic Defend +2 endpoint linux threat-detection machine-learning detection-rule
3t updated
low advisory

Detection of Rare PowerShell Scripts on Windows Systems

Elastic's machine learning job detects rare PowerShell script executions on Windows hosts, identified by their script block hash, indicating potential malware activity or persistence mechanisms that deviate from an established baseline.

Kibana 9.4.0+ +4 windows machine-learning powershell execution threat-detection
1t updated
low advisory

Suspicious Powershell Script Detected by ML

An Elastic machine learning job detects anomalous PowerShell script behavior, specifically focusing on unusual data characteristics like obfuscation, indicating potential malicious scripts adversaries use for execution and defense evasion on Windows systems.

PowerShell endpoint windows threat-detection machine-learning execution investigation-guide
2t updated
low advisory

Unusual Linux Process Discovery Activity

An Elastic machine learning rule detects unusual Linux process discovery activity from atypical user contexts, indicating a potentially compromised account performing reconnaissance for privilege escalation or persistence on Linux systems.

endpoint linux elastic-defend auditd-manager threat-detection ml machine-learning discovery +1
1t