Skip to content
Threat Feed

May 2026 (30)

high advisory

DivvyDrive Cross-Site Request Forgery Vulnerability (CVE-2026-5791)

DivvyDrive versions 4.8.2.9 through 4.8.3.2 are susceptible to cross-site request forgery (CSRF), allowing an attacker to execute unauthorized actions on behalf of an authenticated user.

DivvyDrive csrf web-application vulnerability
2r 1t 1c
medium advisory

DivvyDrive Cross-Site Scripting (XSS) Vulnerability (CVE-2026-6002)

DivvyDrive versions 4.8.2.9 before 4.8.3.2 are susceptible to cross-site scripting (XSS) due to improper neutralization of script-related HTML tags, potentially allowing an attacker to inject malicious scripts.

DivvyDrive xss cve-2026-6002 web-application
2r 1t 1c
critical advisory

AI Coding Agents Vulnerable to Supply Chain Attacks via Malicious Repositories

AI coding agents like Claude Code, Gemini CLI, Cursor CLI, and GitHub Copilot Agents can be manipulated to introduce malicious code into software supply chains by accessing attacker-controlled repositories, leading to potential remote code execution and supply chain compromises.

Claude Code +3 supply chain ai remote code execution
2r 1t
medium advisory

Proticaret E-Commerce Reflected XSS Vulnerability (CVE-2026-3953)

A reflected cross-site scripting (XSS) vulnerability exists in Gosoft Software Industry and Trade Ltd. Co.'s Proticaret E-Commerce software (versions v5.0.0 before V 6.0.1767.1383) due to improper neutralization of input during web page generation, potentially allowing attackers to execute arbitrary JavaScript in a user's browser.

Proticaret E-Commerce xss cross-site scripting reflected xss web application vulnerability
2r 1t 1c
medium advisory

Broadcom Tanzu Jammy Stemcell Vulnerability (CVE-2026-341431)

A vulnerability in Broadcom's Tanzu Jammy Stemcell versions prior to 1.1193, tracked as CVE-2026-341431, requires patching to prevent potential exploitation.

Tanzu Jammy Stemcell vmware tanzu vulnerability
2r 1t
medium advisory

Cisco Crosswork Network Controller and Network Services Orchestrator Connection Exhaustion Denial of Service

An unauthenticated remote attacker can cause a denial-of-service condition on Cisco Crosswork Network Controller and Network Services Orchestrator by exhausting connection resources via a high volume of connection requests.

Crosswork Network Controller +1 denial-of-service cisco network
2r 1t
medium advisory

Google Chrome Security Update Required

Google released a security advisory addressing vulnerabilities in Chrome for Desktop versions prior to 148.0.7778.96/97 on Windows/Mac and 148.0.7778.96 on Linux, requiring users to update to mitigate potential exploits.

Chrome +1 vulnerability browser
2r
high advisory

JupyterLab Command Execution via Crafted HTML Content

JupyterLab's HTML sanitizer allows execution of arbitrary commands via specially crafted HTML content in notebooks or Markdown files due to improper handling of `data-commandlinker-command` and `data-commandlinker-args` attributes.

jupyterlab +1 command-execution html-injection
2r 1t
medium advisory

MAXHUB Pivot Client Application Vulnerability CVE-2026-6411

A vulnerability exists in MAXHUB Pivot client application versions prior to v1.36.2, where a hardcoded AES key allows attackers to decrypt tenant email addresses and associated metadata, and potentially cause a denial-of-service via unauthorized device enrollment through MQTT.

MAXHUB Pivot client application cve-2026-6411 maxhub pivot broken-crypto dos
2r 1t
high threat

MuddyWater Disguises Cyber-Espionage as Chaos Ransomware Attack

The MuddyWater group is disguising its cyber-espionage operations as Chaos ransomware attacks, using Microsoft Teams social engineering for initial access and establishing persistence, likely to complicate attribution and mask their true objectives.

Microsoft Teams +3 MuddyWater chaos ransomware cyberespionage data theft iranian apt
2r 5t
critical advisory

Nginx-UI Unauthenticated Remote Code Execution via Backup Restore

Nginx-UI is vulnerable to unauthenticated remote code execution (RCE) via the `POST /api/restore` endpoint, allowing attackers to inject arbitrary commands into the configuration.

nginx-ui rce authentication bypass command injection devops
2r 2t
high advisory

OpenTelemetry Collector Azure Auth Extension Authentication Bypass

A server-side authentication bypass vulnerability exists in opentelemetry-collector-contrib's azureauthextension versions 0.124.0 through 0.150.0, allowing attackers with a valid Azure access token to authenticate to any OpenTelemetry receiver that uses `auth: azure_auth` due to improper JWT validation.

opentelemetry-collector-contrib +3 authentication-bypass opentelemetry azure jwt
2r 1t
high advisory

QuantumNous new-api SSRF Bypass via 0.0.0.0

The QuantumNous new-api is vulnerable to SSRF attacks. The SSRF protection implemented in versions v0.9.0.5 (CVE-2025-59146) and v0.9.6 (CVE-2025-62155) can be bypassed by using the address `0.0.0.0`. An attacker with a valid API token can send a request to `/v1/chat/completions`, `/v1/responses`, or `/v1/messages` with `0.0.0.0` as the image/file URL host, which bypasses the private-IP filter and allows the server to issue HTTP requests to localhost, enabling a blind SSRF and possibly a full-read SSRF in specific configurations.

new-api ssrf vulnerability quantumnous
2r 1t 2c 2i
critical advisory

Rucio SQL Injection Vulnerability in DID Search API

A SQL injection vulnerability exists in the Oracle path of `FilterEngine.create_sqla_query` in Rucio, allowing any authenticated user to execute arbitrary SQL against the backend database via the DID search endpoint, potentially leading to full database compromise and data exfiltration.

rucio sql-injection cve-2026-29080 web-application
2r 8t
critical advisory

Valtimo SpEL Injection Vulnerability Allows Remote Code Execution

Valtimo is vulnerable to SpEL injection via StandardEvaluationContext, which allows Remote Code Execution by admin users who can execute arbitrary OS commands and exfiltrate sensitive information.

Valtimo document module +2 spel-injection rce valtimo
2r 1t
critical advisory

wger Cross-Tenant Password Reset and Plaintext Disclosure Vulnerability

A vulnerability in wger version 2.5 and earlier allows an attacker with `gym.manage_gym` permission and `gym=None` to reset the password of any other `gym=None` user, disclosing the new password in plaintext and allowing account takeover.

wger vulnerability account-takeover web-application
2r 1t
high advisory

Checkmk Vulnerability Allows Privilege Escalation and Arbitrary Code Execution

A local attacker can exploit a vulnerability in Checkmk to escalate privileges and execute arbitrary program code with administrator rights.

Checkmk privilege-escalation code-execution
2r 2t
high advisory

VMware Tanzu Spring Cloud Config Multiple Vulnerabilities

Multiple vulnerabilities in VMware Tanzu Spring Cloud Config could allow an attacker to disclose sensitive information or manipulate data.

Tanzu Spring Cloud Config credential-access discovery cloud
2r 2t
critical advisory

Gemini CLI Vulnerability Leads to Potential Supply Chain Attack

A critical vulnerability in Google's Gemini CLI, an open-source AI agent, could have enabled attackers to inject malicious prompts into GitHub issues, leading to code execution and a supply chain compromise.

Gemini CLI +2 supply-chain prompt-injection code-execution
2r 3t
critical threat

Cisco Unity Connection Multiple Vulnerabilities

Multiple vulnerabilities in Cisco Unity Connection allow an attacker to execute arbitrary code with administrator privileges or perform Server-Side Request Forgery (SSRF) attacks.

Unity Connection cisco vulnerability privilege-escalation execution ssrf
2r 2t
high advisory

MongoDB Vulnerability Allows Local Code Execution

A local attacker can exploit a vulnerability in MongoDB to execute arbitrary code, potentially leading to privilege escalation and system compromise.

MongoDB code-execution privilege-escalation
2r 2t
critical threat

Multiple Vulnerabilities in Oracle Java SE

A remote attacker, either anonymous or authenticated, can exploit multiple vulnerabilities in Oracle Java SE to compromise confidentiality, integrity, and availability.

Java SE java vulnerability remote-access
2r 1t
medium advisory

CPython Multiple Vulnerabilities Allow File Manipulation and DoS

A remote, authenticated attacker can exploit multiple vulnerabilities in CPython to manipulate files or cause a denial-of-service condition.

CPython vulnerability dos file_manipulation
2r 2t
high advisory

Multiple Vulnerabilities in IBM SPSS Allow for XSS, DoS, and File Manipulation

Multiple vulnerabilities in IBM SPSS can be exploited by an attacker to perform cross-site scripting (XSS) attacks, denial of service attacks, and to manipulate files.

SPSS xss dos file-manipulation
2r 1t
medium advisory

Erlang/OTP Information Disclosure Vulnerability

A remote, authenticated attacker can exploit an unspecified vulnerability in Erlang/OTP to disclose sensitive information.

Erlang/OTP information-disclosure vulnerability erlang
2r 1t
high advisory

Multiple Vulnerabilities in Red Hat Enterprise Linux

An unauthenticated or authenticated remote attacker can exploit vulnerabilities in Red Hat Enterprise Linux to perform cross-site scripting, cause denial of service, or disclose sensitive information.

Red Hat Enterprise Linux vulnerability xss dos redhat
2r 3t
medium advisory

Red Hat OpenShift Service Mesh Multiple Vulnerabilities

An anonymous remote attacker can exploit multiple vulnerabilities in Red Hat OpenShift Service Mesh to manipulate files, disclose information, or cause a denial-of-service condition.

OpenShift Service Mesh openshift servicemesh vulnerability dos
2r 4t
medium advisory

CallPhantom Android Apps Falsely Promise Call History for Payment

ESET researchers discovered 28 fraudulent Android apps, named CallPhantom, on Google Play that falsely claim to provide call logs for any phone number in exchange for payment, generating random data or requesting email addresses and amassing over 7.3 million downloads before being removed.

Google Play android scam callphantom fraud
2r
medium advisory

Microsoft CVE-2026-25833 Vulnerability Published

Microsoft published CVE-2026-25833, a security vulnerability for which details are currently unavailable, impacting systems and requiring further investigation upon release of additional information.

vulnerability microsoft cve-2026-25833
1c
medium advisory

Microsoft Published Information Regarding CVE-2025-66442

Microsoft has published information regarding the vulnerability CVE-2025-66442; details are currently unavailable, limiting specific analysis and detection strategies.

cve vulnerability microsoft
2r 1t 1c