September 2026 (30)
BIND 9 Denial of Service via Malformed DNS64 Response
1 TTP 1 CVEA vulnerability in BIND 9 resolvers configured with DNS64 allows an authoritative server to cause a process crash through malformed responses, resulting in a denial of service.
Authentication Bypass in Kubero Notifications API
1 TTP 1 CVEKubero versions 3.1.1 and earlier contain an authentication bypass vulnerability in the notifications API, allowing unauthenticated attackers to exfiltrate webhook secrets and manipulate pipeline alerting configurations.
CVE-2026-92717 Authentication Bypass in Covenant
1 TTP 1 CVECovenant versions 0.6 and earlier contain an authentication bypass vulnerability allowing unauthenticated remote actors to gain full operator API access via the CovenantHub SignalR hub.
Cross-Tenant Privilege Escalation in Shuffle
1 TTP 1 CVEShuffle through version 2.2.1 is vulnerable to a cross-tenant privilege escalation flaw in the HandleApiGeneration endpoint that allows an authenticated administrator to reset and steal API keys from other tenants.
Untrusted Search Path Vulnerability in OpenTelemetry.Resources.Host on macOS
1 TTP 1 CVEThe OpenTelemetry.Resources.Host NuGet package is vulnerable to arbitrary code execution on macOS due to the use of bare paths for system command execution, allowing PATH hijacking.
Cross-Site Request Forgery Vulnerability in djust SSE Transport
1 rule 1 CVEThe djust library before version 1.0.7 is vulnerable to CSRF via its SSE transport, allowing cross-origin requests to execute state-changing event handlers as an authenticated victim.
Resource Exhaustion in node-opcua via TCP Socket Leak
1 CVEA vulnerability in node-opcua (CVE-2026-68904) causes TCP socket exhaustion and process crashes when clock skew triggers continuous reconnection cycles.
SSRF Vulnerability in mcp-gitlab Enables GitLab Credential Theft
1 rule 6 TTPs 1 CVEThe mcp-gitlab server is vulnerable to Server-Side Request Forgery (SSRF) when ENABLE_DYNAMIC_API_URL is enabled, allowing attackers to force the server to forward victim GitLab tokens to an arbitrary host.
Remote Code Execution in LMDeploy via Insecure Pickle Deserialization
2 TTPs 1 CVE 1 IOCLMDeploy versions 0.9.1 through 0.10.1 are vulnerable to remote code execution due to insecure pickle deserialization within the AsyncRPCServer component, allowing attackers to execute arbitrary system commands.
Multiple Vulnerabilities in Google Chrome and Microsoft Edge
1 TTP 2 CVEsMultiple vulnerabilities in Google Chrome and Microsoft Edge allow remote, unauthenticated attackers to achieve arbitrary code execution, bypass sandbox protections, and perform information disclosure.
Hard-Coded JWT Key in Issabel Framework Enabling RCE
2 TTPs 1 CVEA hard-coded HS256 signing key in the Issabel Framework allows unauthenticated attackers to forge JWTs and execute arbitrary commands via the Asterisk manager originate endpoint.
SilkParasite Campaign Infrastructure Analysis
1 TTPAnalysis of the SilkParasite campaign reveals a 13-server command-and-control cluster facilitating the deployment of SpiceRAT against targets in Central Asia.
Chamilo LMS OS Command Injection Vulnerability (CVE-2026-35196)
2 rules 1 TTP 1 CVEChamilo LMS versions prior to 2.0.0-RC.3 are vulnerable to OS Command Injection via the _cid session variable in the export_all_certificates action, potentially leading to arbitrary command execution.
Arbitrary File Upload and RCE in Pluck CMS via CVE-2023-50564
1 rule 2 TTPs 1 CVEAn authenticated arbitrary file upload vulnerability in Pluck CMS v4.7.18 allows remote attackers to achieve code execution by uploading a malicious ZIP archive via the module installation interface.
Authenticated Blind SQL Injection in ScadaLTS
1 rule 2 TTPs 1 CVEScadaLTS 2.8.1-rc is vulnerable to an authenticated blind SQL injection via the sortBy parameter in the /api/events/search endpoint, allowing low-privileged users to exfiltrate database contents.
SQL Injection in SourceCodester Inventory and Monitoring System
1 rule 1 TTP 1 CVESourceCodester Inventory and Monitoring System 1.0 is vulnerable to remote SQL injection via the Username argument in index.php, allowing unauthenticated attackers to execute arbitrary database commands.
Improper Authentication Vulnerability in ChangeWeDer CRM
1 TTP 1 CVEAn unauthenticated remote code execution vulnerability in the LoginUserUtil.releaseUserIdFromCookie function of ChangeWeDer CRM allows attackers to bypass authentication through cookie manipulation.
Cryptographic Vulnerability in sequoia-openpgp
1 CVEA vulnerability in the sequoia-openpgp library allows attackers to bypass back-signature checks and forge subkey bindings due to incorrect key flag inference.
Remote Command Injection in Ruijie RG-EW3000GX
1 rule 2 TTPs 1 CVEA critical remote OS command injection vulnerability in the Ruijie RG-EW3000GX router allows unauthenticated attackers to execute arbitrary commands via the configChange component.
Privilege Escalation in JetFormBuilder Plugin for WordPress
1 TTP 1 CVEAn unauthenticated privilege escalation vulnerability (CVE-2026-12793) in the JetFormBuilder plugin allows attackers to register arbitrary administrator accounts via improper server-side validation.
Active Exploitation of Google Pixel Improper Authorization Vulnerability
1 CVECISA has added CVE-2026-58704, an improper authorization vulnerability in Google Pixel devices, to its Known Exploited Vulnerabilities (KEV) Catalog due to evidence of active exploitation.
DataGear Server-Side Request Forgery in /dataSet/preview/Http
1 rule 1 TTP 1 CVEDataGear versions up to 6.0.0 contain an unauthenticated server-side request forgery vulnerability allowing attackers to perform arbitrary internal HTTP requests and exfiltrate response bodies.
SQL Injection Vulnerability in WuzhiCMS
2 rules 1 TTP 1 CVEWuzhiCMS versions up to 4.1.0 contain a SQL injection vulnerability in the article::getDataOfJson function, allowing remote attackers to execute arbitrary SQL commands via the title or master_table parameters.
SQL Injection in code-projects Matrimonial System
1 rule 1 TTP 1 CVEMatrimonial System 1.0 contains a remote SQL injection vulnerability in the search.php script, allowing unauthenticated attackers to manipulate search arguments to execute arbitrary database commands.
Denial of Service Vulnerability in Keycloak Theme Localization
1 rule 1 TTP 1 CVEAn unauthenticated denial-of-service vulnerability in Keycloak (CVE-2026-79651) allows attackers to exhaust server memory by injecting arbitrary locale tags into an unbounded cache.
CVE-2026-18212 Keycloak Denial of Service via SAML Redirect Binding
1 TTP 1 CVEAn unauthenticated attacker can trigger a denial of service in Keycloak by sending repeated malformed SAML requests that cause native memory exhaustion due to improper zlib memory management.
Authorization Bypass in zlt2000 microservices-platform
1 TTP 1 CVEA default configuration vulnerability in zlt2000 microservices-platform through 6.0.0 disables URL permission checks, allowing authenticated users to perform unauthorized administrative actions.
Authorization Bypass in yshop-crm CrmCustomerController
1 rule 2 TTPs 1 CVEAn authorization bypass vulnerability in yshop-crm versions 2.1.3 and earlier allows authenticated users to manipulate Redis-based customer policies, leading to service disruption and data loss.
Illicit OpenAI Agent Activity on Hugging Face
4 TTPsAI agents utilizing the WebCache tool exploited compromised Hugging Face credentials to host unauthorized proxy relays, perform SSRF probing, and stage automated ChatGPT account registration services.
NightEagle APT Targets Russian Organizations with GhostContainer Backdoor
3 TTPs 1 CVEThe NightEagle APT group is actively targeting organizations by exploiting compromised VPN credentials, deploying the memory-resident GhostContainer backdoor on Exchange servers, and utilizing legitimate tunneling tools for lateral movement.