Skip to content
Threat Feed

May 2026 (30)

high advisory

Multiple Vulnerabilities in Red Hat Enterprise Linux

An unauthenticated or authenticated remote attacker can exploit vulnerabilities in Red Hat Enterprise Linux to perform cross-site scripting, cause denial of service, or disclose sensitive information.

Red Hat Enterprise Linux vulnerability xss dos redhat
2r 3t
medium advisory

Red Hat OpenShift Service Mesh Multiple Vulnerabilities

An anonymous remote attacker can exploit multiple vulnerabilities in Red Hat OpenShift Service Mesh to manipulate files, disclose information, or cause a denial-of-service condition.

OpenShift Service Mesh openshift servicemesh vulnerability dos
2r 4t
medium advisory

CallPhantom Android Apps Falsely Promise Call History for Payment

ESET researchers discovered 28 fraudulent Android apps, named CallPhantom, on Google Play that falsely claim to provide call logs for any phone number in exchange for payment, generating random data or requesting email addresses and amassing over 7.3 million downloads before being removed.

Google Play android scam callphantom fraud
2r
medium advisory

Microsoft CVE-2026-25833 Vulnerability Published

Microsoft published CVE-2026-25833, a security vulnerability for which details are currently unavailable, impacting systems and requiring further investigation upon release of additional information.

vulnerability microsoft cve-2026-25833
1c
medium advisory

Microsoft Published Information Regarding CVE-2025-66442

Microsoft has published information regarding the vulnerability CVE-2025-66442; details are currently unavailable, limiting specific analysis and detection strategies.

cve vulnerability microsoft
2r 1t 1c
medium advisory

Microsoft Published Information Regarding CVE-2026-25835

Microsoft has published information regarding the vulnerability CVE-2026-25835, but details about the vulnerability, affected products, and exploitation are currently unavailable.

cve vulnerability microsoft
2r 1c
high advisory

macOS SIP Bypass via Sandboxing Abuse

A macOS vulnerability enables bypassing System Integrity Protection (SIP) by abusing sandboxing mechanisms to load an untrusted library into a SIP-entitled process.

defense-evasion privilege-escalation macos sip-bypass
2r 2t
medium advisory

Threat Actors Use Claude AI to Target Water Utility OT Assets

An unidentified threat actor used Claude AI to identify and target a vNode SCADA/IIoT management interface at a Mexican water utility between December 2025 and February 2026, ultimately failing to gain access.

AI OT SCADA password-spraying reconnaissance
2r 2t
high threat

Adware Doctor Steals and Exfiltrates Browser History from Mac App Store Users

Adware Doctor, a popular app available on the Mac App Store, surreptitiously steals user's browsing history from Safari and Chrome, compresses the data into a password-protected zip archive, and exfiltrates it to a remote server.

Adware Doctor +1 adware exfiltration macos
2r 2t 9i
medium advisory

Mac Adware Injecting Malicious JavaScript via Obfuscated Python Script

A Mac adware, likely a component of OSX.Pirrit, uses multiple layers of obfuscation, including base64 encoding, zlib compression, and variable renaming, to evade detection and inject malicious JavaScript from hxxps://1049434604.rsc.cdn77.org/ij1.min.js.

CleanMyMac X +1 adware macos python javascript_injection
2r 2t 1i
medium advisory

OSX.Dummy Malware Targeting Cryptocurrency Community

OSX.Dummy is a new macOS malware targeting the cryptocurrency community, as reported by Objective-See.

OSX.Dummy malware cryptocurrency macos
2r
high threat

WINDSHIFT APT Abuses Custom URL Schemes for macOS Infection

The WINDSHIFT APT group is infecting Macs by abusing custom URL schemes, where advertising support for a custom URL scheme in an application's Info.plist causes the application to be automatically launched when a URL with that scheme is opened, allowing attackers to remotely compromise systems with minimal user interaction and creating an initial access vector.

macOS WINDSHIFT APT url-scheme apt
2r 1t
high advisory

BetterDocs Pro Plugin SQL Injection Vulnerability

The BetterDocs Pro plugin for WordPress is vulnerable to SQL Injection via the `get_current_letter_docs` and `docs_sort_by_letter` AJAX actions, allowing unauthenticated attackers to extract sensitive information from the database.

BetterDocs Pro plugin sqli wordpress plugin cve-2026-4348
2r 1t 1c
critical advisory

WordPress Slider Revolution Plugin Arbitrary File Upload Vulnerability

The Slider Revolution plugin for WordPress is vulnerable to arbitrary file upload due to insufficient file type validation, allowing authenticated attackers with subscriber-level access or higher to upload executable files, potentially leading to remote code execution.

Slider Revolution plugin wordpress file-upload rce plugin
2r 1t 1c
high advisory

vm2 Sandbox Escape via Buffer.alloc Memory Exhaustion

A vulnerability exists in the vm2 npm package (<= 3.10.5) where sandboxed code can bypass the timeout protection by calling Buffer.alloc() with an arbitrary size, leading to memory exhaustion on the host system.

vm2 sandbox-escape dos memory-exhaustion
3r 2t
high advisory

Bandit WebSocket permessage-deflate unbounded inflate leads to DoS

Bandit versions 0.5.8 before 1.11.0 are vulnerable to denial of service when permessage-deflate is enabled, allowing an unauthenticated client to exhaust the BEAM's memory with a single, small, compressed WebSocket frame due to unbounded decompression.

bandit websocket denial-of-service erlang
3r 6t
critical advisory

FileBrowser Public Share DELETE API Path Traversal Allows Arbitrary File Deletion

A path traversal vulnerability exists in FileBrowser's public share DELETE API allowing unauthenticated attackers with valid share hashes and delete permissions to delete arbitrary files outside the shared directory, leading to unauthorized data loss and potential service disruption.

filebrowser +1 path-traversal file-deletion web-application
2r 1t
medium advisory

Free5GC UDM Information Disclosure via Malformed Request

The free5GC UDM component fails to validate the `supi` path parameter in six GET handlers, allowing an unauthenticated attacker to inject control characters and trigger a `500 Internal Server Error` that exposes internal infrastructure details.

udm information-disclosure input-validation free5GC
2r 2t 1c
critical advisory

ArgoCD ServerSideDiff Secret Extraction Vulnerability

A missing authorization and data-masking gap in Argo CD's ServerSideDiff endpoint allows an attacker with read-only access to extract plaintext Kubernetes Secret data from etcd via the Kubernetes API server's Server-Side Apply dry-run mechanism, affecting versions v3.2.0-v3.2.10 and v3.3.0-v3.3.8.

argo-cd argocd secret-extraction kubernetes credential-access
2r 1t
critical advisory

Rancher Fleet Helm Impersonation Bypass Vulnerability

Fleet's Helm deployer did not fully apply ServiceAccount impersonation in two code paths, allowing a tenant with git push access to a Fleet-monitored repository to read secrets from any namespace on every downstream cluster targeted by their `GitRepo`.

Fleet +5 rancher helm kubernetes impersonation privilege-escalation cve-2026-41050
2r 1t
high advisory

Rancher Extensions Path Traversal Vulnerability

A path traversal vulnerability (CVE-2026-25705) exists in Rancher's Extensions through the `compressedEndpoint` field in a `UIPlugin` deployment, allowing malicious UI extensions to overwrite Rancher binaries, tamper with cluster state, or write to the host filesystem.

Rancher path-traversal kubernetes
2r 1t
high advisory

Amazon ECS Agent for Windows Vulnerable to Command Injection

Amazon ECS Agent for Windows versions 1.47.0 through 1.102.2 are vulnerable to command injection via specially crafted credentials in the FSx Windows File Server volume mounting process, potentially allowing a remote authenticated attacker to execute shell commands with SYSTEM privileges.

ECS Agent for Windows command injection privilege escalation cloud
2r 1t
critical advisory

Gotenberg Unauthenticated SSRF Vulnerability

Gotenberg is vulnerable to Server-Side Request Forgery (SSRF) due to bypassable default deny-lists in the `downloadFrom` and `webhook` features, where case-sensitive regex matching allows attackers to use IPv6 loopback URLs to bypass the deny-list and access internal HTTP services.

Gotenberg ssrf vulnerability
2r 3i
high advisory

Gotenberg SSRF Vulnerability in LibreOffice Conversion Endpoint

Gotenberg is vulnerable to Server-Side Request Forgery (SSRF) due to insufficient hardening in the LibreOffice conversion endpoint, allowing attackers to make outbound HTTP requests by embedding external URLs in uploaded documents, bypassing Gotenberg's SSRF filters, affecting versions up to 8.31.0, and potentially enabling access to internal services, data exfiltration, or port scanning.

Gotenberg +1 ssrf libreoffice vulnerability
2r 1i
high advisory

Gotenberg ExifTool Metadata Write Blocklist Bypass Vulnerability

The ExifTool metadata write blocklist in Gotenberg v8 can be bypassed using ExifTool's group-prefix syntax, enabling arbitrary file rename, move, hardlink, and symlink creation on the server.

Gotenberg exiftool metadata file-manipulation
2r 1t
critical advisory

Compromise of PyTorch Lightning PyPI Package Versions

Compromised PyTorch Lightning PyPI packages versions 2.6.2 and 2.6.3 contain malicious code related to credential harvesting, requiring immediate credential rotation and system rebuilding.

pytorch-lightning +1 supply-chain credential-theft pypi
2r 1t 1i
medium advisory

Netty HttpContentDecompressor Brotli/Zstd/Snappy Decompression Bomb Vulnerability

Netty's HttpContentDecompressor and DelegatingDecompressorFrameListener are vulnerable to a decompression bomb denial-of-service attack because the maxAllocation parameter is not enforced when Content-Encoding is set to br (Brotli), zstd, or snappy, allowing attackers to bypass decompression limits and cause unbounded memory allocation.

netty-codec-http +3 decompression-bomb denial-of-service netty http
3r 1t
medium advisory

Netty Lz4FrameDecoder Resource Exhaustion Vulnerability

Netty's Lz4FrameDecoder is vulnerable to resource exhaustion, where an attacker can cause excessive memory allocation by sending a small, crafted header, leading to a denial-of-service condition; this affects netty-codec-compression versions up to 4.2.12.Final and netty-codec versions up to 4.1.132.Final.

netty-codec-compression +1 resource-exhaustion denial-of-service netty
2r 1t
medium advisory

Netty DNS Codec Input Validation Bypass Vulnerability

Netty's DNS codec fails to enforce RFC 1035 domain name constraints, leading to potential DNS cache poisoning, denial-of-service, and domain validation bypass through null byte injection, overlength labels, silent truncation, and unbounded memory allocation.

Netty 4.2.12.Final netty dns vulnerability cache-poisoning
2r 1t
high advisory

ThingsBoard IoT Platform 4.2.0 Server-Side Request Forgery Vulnerability

A public exploit is available for a Server-Side Request Forgery (SSRF) vulnerability in ThingsBoard IoT Platform 4.2.0, increasing the risk for unpatched systems.

ThingsBoard IoT Platform 4.2.0 ssrf exploit iot
1r 1t