Skip to content
Threat Feed

May 2026 (30)

medium advisory

Multiple Vulnerabilities in ImageMagick Allow for DoS and Potential Data Exposure

A local attacker can exploit multiple vulnerabilities in ImageMagick to perform a denial of service attack or affect confidentiality, availability, and integrity.

ImageMagick vulnerability dos local-access
2r 2t
medium advisory

JetBrains TeamCity On-Premises Privilege Escalation Vulnerability

A remote, authenticated attacker can exploit a vulnerability in JetBrains TeamCity On-Premises to escalate privileges.

TeamCity On-Premises privilege-escalation teamcity webserver
2r 1t
high advisory

Multiple Vulnerabilities in Apple macOS

Multiple vulnerabilities in Apple macOS allow an attacker to bypass security measures, conduct denial of service attacks, disclose information, manipulate files, and escalate privileges.

macOS vulnerability
2r 4t
medium advisory

CVE-2026-6690: LifePress WordPress Plugin Stored XSS Vulnerability

The LifePress plugin for WordPress is vulnerable to stored cross-site scripting (XSS) due to insufficient input sanitization and output escaping within the `lp_update_mds` AJAX action, allowing unauthenticated attackers to inject arbitrary web scripts via the 'n' parameter that execute when a user accesses the injected page; this affects versions up to and including 2.2.2.

LifePress plugin <= 2.2.2 wordpress xss cve-2026-6690 lifepress stored-xss plugin
2r 1t 1c
high threat

AIWU WordPress Plugin Vulnerable to SQL Injection (CVE-2026-2993)

The AI Chatbot & Workflow Automation by AIWU plugin for WordPress is vulnerable to SQL Injection (CVE-2026-2993) in versions up to 1.4.17, allowing unauthenticated attackers to extract sensitive information from the database.

AI Chatbot & Workflow Automation by AIWU plugin for WordPress cve sqli wordpress injection
2r 1t 1c
high advisory

Poppler Vulnerability Allows Code Execution

A local attacker can exploit a vulnerability in poppler to execute arbitrary program code on a vulnerable system.

poppler vulnerability code-execution
2r 1t
high advisory

cPanel & WHM Multiple Vulnerabilities Leading to Privilege Escalation

Multiple vulnerabilities in cPanel & WHM and WP Squared allow authenticated users to escalate privileges, execute arbitrary code, and cause denial-of-service conditions by exploiting improper input validation and unsafe symlink handling.

cPanel & WHM +1 cpanel privilege-escalation code-execution
3r 3t 3c
medium advisory

Kubernetes Service Account Token Created via TokenRequest API by Non-System Identity

The rule detects the creation of Kubernetes service account tokens through the TokenRequest API by non-system identities, which can be abused to escalate privileges, pivot to cloud resources, or generate persistent tokens, bypassing file system-based detection.

kubernetes credential-access tokenrequest cloud
2r 1t
medium advisory

Sonatype Nexus Repository Manager Security Bypass Vulnerability

An authenticated remote attacker can exploit a vulnerability in Sonatype Nexus Repository Manager to bypass security precautions.

Nexus Repository Manager security-bypass vulnerability nexus
2r 1t
medium advisory

Linux Kernel: Local Privilege Escalation Vulnerabilities

A local attacker can exploit multiple vulnerabilities in the Linux Kernel to escalate privileges or manipulate files.

linux kernel privilege-escalation linux kernel
2r 1t
critical advisory

IBM DB2 Big SQL Multiple Vulnerabilities

Multiple vulnerabilities in IBM DB2 Big SQL could allow an attacker to perform a denial of service attack and execute arbitrary code.

DB2 Big SQL db2 bigsql denial-of-service code-execution
2r 2t
critical advisory

Red Hat Enterprise Linux Multiple Vulnerabilities Leading to RCE/DoS

A remote, anonymous attacker can exploit multiple vulnerabilities in Red Hat Enterprise Linux to execute arbitrary code or cause a denial-of-service condition.

Enterprise Linux vulnerability rhel remote-code-execution denial-of-service linux
2r 2t
critical advisory

Multiple Vulnerabilities in Red Hat Build of Keycloak

Multiple vulnerabilities in Red Hat Build of Keycloak could allow an attacker to bypass authentication, gain elevated privileges, disclose sensitive information, cause a denial of service condition, execute arbitrary code, or manipulate data.

Build of Keycloak keycloak vulnerability authentication-bypass
2r 5t
medium advisory

Multiple Vulnerabilities in 7-Zip Allow File Manipulation and Information Disclosure

An anonymous remote attacker can exploit multiple vulnerabilities in 7-Zip to manipulate files or disclose sensitive information on Windows systems.

7-Zip vulnerability file-manipulation information-disclosure windows
2r 2t
high threat

Mini Shai-Hulud Campaign Compromises npm Packages

The Mini Shai-Hulud supply chain campaign, attributed to TeamPCP, has compromised several npm packages, including those within the @tanstack, @uipath, and @mistralai namespaces, leading to credential theft and potential further compromise.

@tanstack/react-router +2 TeamPCP supply-chain npm malware
3r 6t 8i
medium advisory

CVE-2026-7287 - Zyxel NWA1100-N Buffer Overflow Vulnerability

A buffer overflow vulnerability in Zyxel NWA1100-N firmware allows a remote attacker to cause a denial-of-service by sending a crafted HTTP request to the webs binary.

NWA1100-N customized firmware dos buffer overflow cve-2026-7287
2r 2t 1c
high advisory

Zyxel WRE6505 v2 Command Injection Vulnerability (CVE-2026-7256)

A command injection vulnerability (CVE-2026-7256) in Zyxel WRE6505 v2 firmware allows an adjacent attacker on the LAN to execute arbitrary OS commands by sending a crafted HTTP request.

WRE6505 v2 firmware version V1.00 command injection zyxel cve-2026-7256 network device
2r 1t 1c
high advisory

CVE-2026-34259: SAP Forecasting & Replenishment OS Command Execution

CVE-2026-34259 is an OS Command Execution vulnerability in SAP Forecasting & Replenishment that allows an authenticated attacker with administrative privileges to execute arbitrary OS commands, potentially leading to complete system compromise.

Forecasting & Replenishment cve command injection sap rce vulnerability
2r 3t 1c
critical advisory

SAP Commerce Cloud Unauthenticated Remote Code Execution (CVE-2026-34263)

SAP Commerce Cloud is vulnerable to unauthenticated malicious configuration upload and code injection due to improper Spring Security configuration, resulting in arbitrary server-side code execution.

Commerce cloud CVE-2026-34263 rce sap spring security
2r 1t 1c
high advisory

SAP S/4HANA SQL Injection Vulnerability (CVE-2026-34260)

SAP S/4HANA (SAP Enterprise Search for ABAP) is vulnerable to SQL injection (CVE-2026-34260) via user-controlled input, allowing an authenticated attacker to inject malicious SQL statements, leading to unauthorized data access and potential application crashes.

S/4HANA sql-injection vulnerability sap
2r 2t 1c
critical advisory

Compromised @tanstack/* Packages Exfiltrate Credentials via GitHub Actions Exploit

On 2026-05-11, multiple malicious versions of `@tanstack/*` packages were published to the npm registry due to a chained attack exploiting vulnerabilities in GitHub Actions; the attacker used a compromised GitHub Actions OIDC trusted-publisher binding to publish credential-stealing malware that harvests credentials, exfiltrates data, and propagates the compromise by republishing other packages with the same injection, requiring users who installed affected versions to consider their environment compromised and rotate all credentials.

@tanstack/arktype-adapter +41 supply-chain credential-theft github-actions
2r 4t 6i
high threat

barebox EFI PE Loader Memory-Safety Vulnerabilities (CVE-2026-34963)

barebox versions prior to 2026.04.0 are vulnerable to memory-safety issues in the EFI PE loader (CVE-2026-34963), potentially allowing code execution via malicious EFI PE binaries.

barebox memory-safety heap-overflow bootloader
1r 1t 1c
medium advisory

GhostLock Tool Abuses Windows API to Block File Access

GhostLock is a proof-of-concept tool that abuses the Windows CreateFileW API to block access to files on local and SMB network shares, causing a denial-of-service condition.

Windows +1 denial-of-service file-access
2r 1t
high advisory

Supply Chain Attacks Target Checkmarx and Bitwarden Developer Tools

On April 22, 2026, Checkmarx and Bitwarden suffered supply chain attacks where malicious versions of their developer tools were distributed through official channels, attempting to harvest sensitive information such as GitHub and npm tokens and exfiltrating data to audit.checkmarx[.]cx.

KICS +6 supply-chain credential-theft malware
2r 4t 1i
high advisory

Inkeep Agents Authentication Bypass Vulnerability (CVE-2026-8321)

CVE-2026-8321 is an authentication bypass vulnerability in the createDevContext function of Inkeep Agents 0.58.14, allowing remote attackers to bypass authentication via alternate channels.

agents cve-2026-8321 authentication bypass inkeep
1r 1t 1c
medium advisory

JetBrains TeamCity Vulnerability

A security advisory released by JetBrains on May 11, 2026, addresses a vulnerability in JetBrains TeamCity versions prior to 2026.1 and 2025.11.5, requiring users to apply updates to mitigate potential risks.

TeamCity vulnerability jetbrains
2r
high advisory

Kysely JSON-path Injection Vulnerability

A JSON-path traversal injection vulnerability exists in Kysely versions prior to 0.28.16, allowing attackers to traverse JSON sub-fields outside the intended scope, potentially leading to unauthorized read and write access to sensitive data in MySQL, PostgreSQL, and SQLite databases due to insufficient sanitization of JSON-path metacharacters in the `JSONPathBuilder.key()` and `.at()` functions.

MySQL +3 jsonpath injection kysely cwe-89 cwe-915 cwe-1284
2r 1t 1c
high threat

MantisBT Vulnerable to Stored XSS in File Download

MantisBT is vulnerable to stored cross-site scripting (XSS) via file_download.php by using the `show_inline=1` parameter with a valid CSRF token to upload a crafted XHTML attachment referencing a JavaScript attachment, leading to arbitrary code execution.

mantisbt/mantisbt xss mantisbt github advisory
2r 1t
critical advisory

SandboxJS Function.caller Sandbox Escape Vulnerability (CVE-2026-43898)

SandboxJS is vulnerable to a sandbox escape (CVE-2026-43898); by exploiting the `Function.caller` property, sandboxed code can access the internal `LispType.Call` runtime callback, which allows an attacker to manipulate the context and arguments of the callback, leading to the execution of arbitrary host JavaScript and a complete sandbox escape.

@nyariv/sandboxjs sandbox-escape rce javascript
2r 2t
high advisory

MantisBT Private Bugnote Attachment Content Leak via REST API

MantisBT is vulnerable to a missing authorization check in its file visibility function, allowing authenticated users with REPORTER or higher access to download attachments on private bugnotes they should not be able to access through the REST API and SOAP API, affecting versions 2.23.0 to 2.28.1.

mantisbt credential-access authorization-bypass rest-api
2r 1t