Skip to content
Threat Feed

May 2026 (30)

high advisory

Bludit CMS 3.18.4 Remote Code Execution Vulnerability

A remote code execution vulnerability exists in Bludit CMS 3.18.4, for which a public exploit has been published, increasing the risk to unpatched systems.

Bludit CMS 3.18.4 webapps rce bludit
2r 1t
high advisory

Microsoft Partner Center Spoofing Vulnerability (CVE-2026-34327)

CVE-2026-34327 is a spoofing vulnerability in Microsoft Partner Center that allows unauthorized attackers to perform spoofing over a network by using externally controlled references to resources in another sphere.

Partner Center spoofing cve-2026-34327 web-application
2r 1t 1c
high advisory

Ech0 'Never Expire' Access Tokens Cannot Be Revoked

Ech0's access tokens with the 'never expire' option cannot be revoked through logout or deletion, leading to persistent access until the JWT secret is rotated instance-wide.

Ech0 credential-access token-revocation web-application
2r 1t
high threat

code-projects Feedback System 1.0 SQL Injection Vulnerability (CVE-2026-8098)

A SQL injection vulnerability exists in code-projects Feedback System 1.0 via manipulation of the email parameter in /admin/checklogin.php, potentially allowing remote attackers to execute arbitrary SQL commands.

Feedback System 1.0 cve sql-injection web-application
2r 1t 1c
critical advisory

Zebra Consensus Divergence in Transparent Sighash Hash-Type Handling (CVE-2026-44497)

Zebra versions prior to 4.4.0 exhibit a consensus divergence vulnerability (CVE-2026-44497) due to insufficient error handling of invalid sighash types during sighash computation, potentially leading to network partitioning and double-spend attacks.

zebrad +1 consensus-failure vulnerability network-partition
2r
medium advisory

Zebra Block Validator Sigops Undercount Vulnerability

Zebra's block validator undercounts signature operations, allowing it to accept invalid blocks, leading to a network split between Zebra and zcashd nodes.

zebra blockchain consensus-failure zcash
2r
high advisory

SourceCodester Pharmacy Sales and Inventory System SQL Injection Vulnerability

A remote SQL injection vulnerability exists in SourceCodester Pharmacy Sales and Inventory System 1.0 via manipulation of the ID argument in the /ajax.php?action=save_user file, potentially allowing attackers to execute arbitrary SQL queries.

Pharmacy Sales and Inventory System 1.0 sql-injection web-application cve-2026-8083
2r 1t 1c
high advisory

Cinny Access Token Disclosure via Malicious Emoji Pack

A remote authenticated attacker who shares a room with a victim can steal their Matrix access token by injecting a malicious emote pack, exploiting improper URL validation and service worker behavior in Cinny versions prior to 4.10.3.

cinny credential-access web-application token-theft
3r 1t
high threat

Broadcom Patches Multiple Vulnerabilities in Tanzu Products

Broadcom released security advisories on May 7, 2026, addressing vulnerabilities in several Tanzu products, requiring users and administrators to apply necessary updates to mitigate potential risks.

Tanzu Greenplum Command Center +7 vulnerability patch broadcom tanzu
2r 1t
critical threat

Ivanti EPMM Authenticated Remote Code Execution Vulnerability Exploited

CVE-2026-6973, an authenticated remote code execution vulnerability in Ivanti Endpoint Manager Mobile (EPMM), is being actively exploited, potentially leading to data breaches and system compromise.

exploited Endpoint Manager Mobile ivanti eppm rce vulnerability exploitation
2r 4t 1c
critical advisory

Claude Code OAuth Token Theft via MCP Hijacking

Attackers can silently redirect Claude Code MCP traffic to intercept OAuth tokens, enabling persistent access to connected SaaS platforms by modifying the ~/.claude.json file in a man-in-the-middle attack.

Claude Code oauth man-in-the-middle credential access
3r 2t
critical advisory

AxonFlow Platform Multi-Tenant Isolation and Access Control Vulnerabilities

Multiple vulnerabilities in AxonFlow platform versions prior to 7.5.0, including multi-tenant isolation issues and SQL injection, could lead to unauthorized access, information disclosure, denial of service, and other security impacts; AxonFlow v7.5.0 resolves these issues.

axonflow platform +2 multi-tenancy access-control SQL injection denial of service vulnerability
2r 5t
high advisory

Chromium CVE-2026-7906 Use-After-Free in SVG

CVE-2026-7906 is a use-after-free vulnerability in the SVG component of Chromium, also affecting Microsoft Edge.

Chrome +1 chromium use-after-free svg cve-2026-7906
2r 1c
high advisory

Chromium Type Confusion Vulnerability in Accessibility (CVE-2026-7914)

CVE-2026-7914 is a type confusion vulnerability in the Accessibility component of Chromium, also affecting Microsoft Edge.

Chrome +1 cve-2026-7914 type confusion chromium
2r 2t 1c
medium advisory

CVE-2026-26164 M365 Copilot Information Disclosure Vulnerability

CVE-2026-26164 is an information disclosure vulnerability in M365 Copilot due to improper neutralization of special elements, allowing unauthorized information disclosure over a network.

M365 Copilot information disclosure cloud vulnerability
2r 1t
medium advisory

CVE-2026-32207 Azure Machine Learning Notebook Spoofing Vulnerability

CVE-2026-32207 is a cross-site scripting vulnerability in Azure Machine Learning, allowing an unauthorized attacker to perform spoofing over a network.

Azure Machine Learning xss spoofing azure
2r 1t
critical advisory

CVE-2026-33109 Azure Managed Instance for Apache Cassandra Remote Code Execution Vulnerability

CVE-2026-33109 is a remote code execution vulnerability in Microsoft's Azure Managed Instance for Apache Cassandra due to improper access control, allowing an authorized attacker to execute code over a network.

Azure Managed Instance for Apache Cassandra cve rce azure cassandra
2r 1t
medium advisory

CVE-2026-33111 Copilot Chat (Microsoft Edge) Information Disclosure Vulnerability

CVE-2026-33111 is a command injection vulnerability in Microsoft Edge's Copilot Chat feature that allows an unauthorized attacker to disclose information over a network.

Copilot Chat cve-2026-33111 command injection information disclosure
2r 1t
medium advisory

CVE-2026-33823 Microsoft Teams Information Disclosure Vulnerability

CVE-2026-33823 is an information disclosure vulnerability in Microsoft Teams that allows an authorized attacker to disclose sensitive information over a network due to improper authorization.

Teams information-disclosure cloud microsoft-teams
1r 1t
critical advisory

CVE-2026-33844 Azure Managed Instance for Apache Cassandra Remote Code Execution Vulnerability

CVE-2026-33844 is a remote code execution vulnerability in Azure Managed Instance for Apache Cassandra due to improper input validation, allowing an authorized network attacker to execute code.

Azure Managed Instance for Apache Cassandra rce vulnerability azure
2r 1t
medium advisory

CVE-2026-35428 Azure Cloud Shell Spoofing Vulnerability

CVE-2026-35428 is a command injection vulnerability in Azure Cloud Shell that allows an unauthorized attacker to perform spoofing over a network.

Azure Cloud Shell command-injection spoofing cloud
1r 1t
high advisory

CVE-2026-35435 Azure AI Foundry Elevation of Privilege Vulnerability

CVE-2026-35435 is an elevation of privilege vulnerability in Azure AI Foundry M365 that allows an unauthorized attacker to elevate privileges over a network due to improper access control in published agents.

Azure AI Foundry azure privilege-escalation cloud
2r 1t
medium advisory

CVE-2026-40379 Microsoft Enterprise Security Token Service (ESTS) Spoofing Vulnerability

CVE-2026-40379 is a spoofing vulnerability in Microsoft Enterprise Security Token Service (ESTS) where exposure of sensitive information in Azure Entra ID allows an unauthorized attacker to perform spoofing over a network.

Enterprise Security Token Service +1 entra_id spoofing cloud
2r 1t
high advisory

CVE-2026-41105 Azure Monitor Action Group Notification System Elevation of Privilege Vulnerability

A server-side request forgery vulnerability in Azure Notification Service allows an authorized attacker to elevate privileges over a network, leading to privilege escalation.

Azure Monitor Action Group Notification System ssrf privilege-escalation azure
2r 1t
medium advisory

CVE-2026-42826 Azure DevOps Information Disclosure Vulnerability

CVE-2026-42826 is an information disclosure vulnerability in Azure DevOps that allows unauthorized disclosure of sensitive information over a network.

Azure DevOps information disclosure cloud
2r 1t
high advisory

CVE-2026-7925 Use-After-Free Vulnerability in Chromium Chromoting

CVE-2026-7925 is a use-after-free vulnerability in the Chromoting component of Google Chrome, also affecting Microsoft Edge.

Chrome +1 use-after-free vulnerability chromoting
2r 1c
high advisory

CVE-2026-7928 Use-After-Free Vulnerability in WebRTC

CVE-2026-7928 is a use-after-free vulnerability in the WebRTC component of Chromium, affecting Google Chrome and Microsoft Edge (Chromium-based) and potentially allowing for arbitrary code execution.

Edge +1 use-after-free webrtc chromium cve remote-code-execution
2r 4t 1c
critical advisory

PAN-OS Authentication Portal Remote Code Execution Vulnerability

An unauthenticated remote code execution vulnerability exists in the PAN-OS Authentication Portal (Captive Portal) service, potentially allowing attackers to execute arbitrary code with root privileges on PA-Series and VM-Series firewalls by sending crafted network packets.

PAN-OS +2 vulnerability rce network
2r 1t
high advisory

Manipulation of Vision-Language Models via Imperceptible Image Perturbations

Cisco researchers discovered that attackers can manipulate vision-language models (VLMs) by using pixel-level perturbations in images to embed malicious instructions, which are unreadable by humans but interpreted by AI, leading to potential data exfiltration or other unauthorized actions.

GPT-4o +5 ai vlm perturbation defense-evasion ai-security
2r 1t
medium advisory

DivvyDrive Stored XSS Vulnerability

DivvyDrive versions 4.8.2.9 before 4.8.3.2 are susceptible to stored cross-site scripting (XSS) due to improper neutralization of user-supplied input during web page generation, potentially allowing attackers to execute arbitrary JavaScript in a user's browser.

DivvyDrive xss stored-xss web-application
2r 1t 1c