Skip to content
Threat Feed

September 2026 (30)

low advisory

BIND 9 Denial of Service via Malformed DNS64 Response

A vulnerability in BIND 9 resolvers configured with DNS64 allows an authoritative server to cause a process crash through malformed responses, resulting in a denial of service.

BIND +5 denial-of-service network-infrastructure vulnerability dns infrastructure
1t 1c
critical advisory

Authentication Bypass in Kubero Notifications API

Kubero versions 3.1.1 and earlier contain an authentication bypass vulnerability in the notifications API, allowing unauthenticated attackers to exfiltrate webhook secrets and manipulate pipeline alerting configurations.

Kubero
1t 1c
critical advisory

CVE-2026-92717 Authentication Bypass in Covenant

Covenant versions 0.6 and earlier contain an authentication bypass vulnerability allowing unauthenticated remote actors to gain full operator API access via the CovenantHub SignalR hub.

Covenant authentication-bypass c2-infrastructure cve-2026-92717
1t 1c
critical advisory

Cross-Tenant Privilege Escalation in Shuffle

Shuffle through version 2.2.1 is vulnerable to a cross-tenant privilege escalation flaw in the HandleApiGeneration endpoint that allows an authenticated administrator to reset and steal API keys from other tenants.

Shuffle through
1t 1c
high advisory

Untrusted Search Path Vulnerability in OpenTelemetry.Resources.Host on macOS

The OpenTelemetry.Resources.Host NuGet package is vulnerable to arbitrary code execution on macOS due to the use of bare paths for system command execution, allowing PATH hijacking.

OpenTelemetry.Resources.Host
1t 1c
medium advisory

Cross-Site Request Forgery Vulnerability in djust SSE Transport

The djust library before version 1.0.7 is vulnerable to CSRF via its SSE transport, allowing cross-origin requests to execute state-changing event handlers as an authenticated victim.

djust web-application-security csrf sse vulnerability
1r 1c
medium advisory

Resource Exhaustion in node-opcua via TCP Socket Leak

A vulnerability in node-opcua (CVE-2026-68904) causes TCP socket exhaustion and process crashes when clock skew triggers continuous reconnection cycles.

node-opcua +2 denial-of-service nodejs opcua resource-exhaustion
1c
critical advisory

SSRF Vulnerability in mcp-gitlab Enables GitLab Credential Theft

The mcp-gitlab server is vulnerable to Server-Side Request Forgery (SSRF) when ENABLE_DYNAMIC_API_URL is enabled, allowing attackers to force the server to forward victim GitLab tokens to an arbitrary host.

mcp-gitlab +2 dns-rebinding mcp gitlab cve-2026-61568 vulnerability rce exfiltration
1r 6t 1c updated
critical advisory

Remote Code Execution in LMDeploy via Insecure Pickle Deserialization

LMDeploy versions 0.9.1 through 0.10.1 are vulnerable to remote code execution due to insecure pickle deserialization within the AsyncRPCServer component, allowing attackers to execute arbitrary system commands.

lmdeploy
2t 1c 1i
critical advisory

Multiple Vulnerabilities in Google Chrome and Microsoft Edge

Multiple vulnerabilities in Google Chrome and Microsoft Edge allow remote, unauthenticated attackers to achieve arbitrary code execution, bypass sandbox protections, and perform information disclosure.

Chrome +9 vulnerability browser-security patch-management
1t 2c updated
critical threat

Hard-Coded JWT Key in Issabel Framework Enabling RCE

A hard-coded HS256 signing key in the Issabel Framework allows unauthenticated attackers to forge JWTs and execute arbitrary commands via the Asterisk manager originate endpoint.

PoC Issabel Framework +2 remote-code-execution pbx cve-2026-89026
2t 1c updated
rumour rumour

SilkParasite Campaign Infrastructure Analysis

Analysis of the SilkParasite campaign reveals a 13-server command-and-control cluster facilitating the deployment of SpiceRAT against targets in Central Asia.

spicerat silkparasite command-and-control central-asia network-security threat-intelligence
1t
critical advisory

Chamilo LMS OS Command Injection Vulnerability (CVE-2026-35196)

Chamilo LMS versions prior to 2.0.0-RC.3 are vulnerable to OS Command Injection via the _cid session variable in the export_all_certificates action, potentially leading to arbitrary command execution.

PoC cve-2026-35196 os command injection chamilo lms web application
2r 1t 1c updated
high advisory

Arbitrary File Upload and RCE in Pluck CMS via CVE-2023-50564

An authenticated arbitrary file upload vulnerability in Pluck CMS v4.7.18 allows remote attackers to achieve code execution by uploading a malicious ZIP archive via the module installation interface.

Pluck web-vulnerability rce file-upload pluck-cms
1r 2t 1c
low advisory

Authenticated Blind SQL Injection in ScadaLTS

ScadaLTS 2.8.1-rc is vulnerable to an authenticated blind SQL injection via the sortBy parameter in the /api/events/search endpoint, allowing low-privileged users to exfiltrate database contents.

ScadaLTS sqli vulnerability web-application
1r 2t 1c
high advisory

SQL Injection in SourceCodester Inventory and Monitoring System

SourceCodester Inventory and Monitoring System 1.0 is vulnerable to remote SQL injection via the Username argument in index.php, allowing unauthenticated attackers to execute arbitrary database commands.

Inventory and Monitoring System sql-injection web-vulnerability
1r 1t 1c
high advisory

Improper Authentication Vulnerability in ChangeWeDer CRM

An unauthenticated remote code execution vulnerability in the LoginUserUtil.releaseUserIdFromCookie function of ChangeWeDer CRM allows attackers to bypass authentication through cookie manipulation.

crm web-application authentication-bypass vulnerability
1t 1c
high advisory

Cryptographic Vulnerability in sequoia-openpgp

A vulnerability in the sequoia-openpgp library allows attackers to bypass back-signature checks and forge subkey bindings due to incorrect key flag inference.

sequoia-openpgp
1c
critical advisory

Remote Command Injection in Ruijie RG-EW3000GX

A critical remote OS command injection vulnerability in the Ruijie RG-EW3000GX router allows unauthenticated attackers to execute arbitrary commands via the configChange component.

RG-EW3000GX remote-code-execution cve-2026-92398 command-injection
1r 2t 1c
critical advisory

Privilege Escalation in JetFormBuilder Plugin for WordPress

An unauthenticated privilege escalation vulnerability (CVE-2026-12793) in the JetFormBuilder plugin allows attackers to register arbitrary administrator accounts via improper server-side validation.

PoC Dynamic Blocks Form Builder wordpress plugin privilege-escalation web-application
1t 1c updated
high threat

Active Exploitation of Google Pixel Improper Authorization Vulnerability

CISA has added CVE-2026-58704, an improper authorization vulnerability in Google Pixel devices, to its Known Exploited Vulnerabilities (KEV) Catalog due to evidence of active exploitation.

exploited Pixel vulnerability cisa-kev mobile-security
1c
high advisory

DataGear Server-Side Request Forgery in /dataSet/preview/Http

DataGear versions up to 6.0.0 contain an unauthenticated server-side request forgery vulnerability allowing attackers to perform arbitrary internal HTTP requests and exfiltrate response bodies.

DataGear
1r 1t 1c
high advisory

SQL Injection Vulnerability in WuzhiCMS

WuzhiCMS versions up to 4.1.0 contain a SQL injection vulnerability in the article::getDataOfJson function, allowing remote attackers to execute arbitrary SQL commands via the title or master_table parameters.

WuzhiCMS sql-injection vulnerability web-application ssrf web-vulnerability
2r 1t 1c updated
high advisory

SQL Injection in code-projects Matrimonial System

Matrimonial System 1.0 contains a remote SQL injection vulnerability in the search.php script, allowing unauthenticated attackers to manipulate search arguments to execute arbitrary database commands.

Matrimonial System sqli web-vulnerability
1r 1t 1c
low advisory

Denial of Service Vulnerability in Keycloak Theme Localization

An unauthenticated denial-of-service vulnerability in Keycloak (CVE-2026-79651) allows attackers to exhaust server memory by injecting arbitrary locale tags into an unbounded cache.

Keycloak denial-of-service vulnerability identity-management
1r 1t 1c
low advisory

CVE-2026-18212 Keycloak Denial of Service via SAML Redirect Binding

An unauthenticated attacker can trigger a denial of service in Keycloak by sending repeated malformed SAML requests that cause native memory exhaustion due to improper zlib memory management.

Keycloak denial-of-service vulnerability
1t 1c
high advisory

Authorization Bypass in zlt2000 microservices-platform

A default configuration vulnerability in zlt2000 microservices-platform through 6.0.0 disables URL permission checks, allowing authenticated users to perform unauthorized administrative actions.

microservices-platform vulnerability privilege-escalation web-application
1t 1c
high advisory

Authorization Bypass in yshop-crm CrmCustomerController

An authorization bypass vulnerability in yshop-crm versions 2.1.3 and earlier allows authenticated users to manipulate Redis-based customer policies, leading to service disruption and data loss.

yshop-crm
1r 2t 1c
high advisory

Illicit OpenAI Agent Activity on Hugging Face

AI agents utilizing the WebCache tool exploited compromised Hugging Face credentials to host unauthorized proxy relays, perform SSRF probing, and stage automated ChatGPT account registration services.

WebCache +1 cloud ssrf agent-security supply-chain
4t
high threat

NightEagle APT Targets Russian Organizations with GhostContainer Backdoor

The NightEagle APT group is actively targeting organizations by exploiting compromised VPN credentials, deploying the memory-resident GhostContainer backdoor on Exchange servers, and utilizing legitimate tunneling tools for lateral movement.

Exchange Server NightEagle apt exchange backdoor tunnel
3t 1c