May 2026 (30)
Fake Claude AI Site Spreads Beagle Backdoor via DLL Sideloading
2 rules 2 TTPs 3 IOCsA malicious website impersonating Anthropic's Claude AI platform delivers the Beagle backdoor through a DLL sideloading attack, leveraging a compromised G DATA antivirus updater to execute malicious code.
Ghost CMS 6.19.0 SQL Injection Vulnerability
2 rules 1 TTPA SQL injection vulnerability exists in Ghost CMS 6.19.0, and a public exploit (EDB-52555) is available, increasing the risk to unpatched systems.
LuaJIT 2.1.1774638290 Arbitrary Code Execution Vulnerability
2 rules 1 TTPA public exploit has been published for LuaJIT version 2.1.1774638290, enabling arbitrary code execution on vulnerable web applications.
NocoBase 2.0.27 VM Sandbox Escape Vulnerability
2 rulesA local exploit has been published for NocoBase 2.0.27, detailing a VM Sandbox Escape vulnerability, increasing the risk to unpatched systems.
rmcp Streamable HTTP Server Transport DNS Rebinding Vulnerability
2 rules 1 TTPThe `rmcp` crate before v1.4.0 is vulnerable to DNS rebinding attacks via the Streamable HTTP server transport due to missing Host header validation, potentially allowing arbitrary code execution on a victim's machine if they visit a malicious website.
ThingsBoard IoT Platform 4.2.0 Server-Side Request Forgery Vulnerability
1 rule 1 TTPA public exploit is available for a Server-Side Request Forgery (SSRF) vulnerability in ThingsBoard IoT Platform 4.2.0, increasing the risk for unpatched systems.
ldap3_proto LDAP Filter Stack Exhaustion Vulnerability
2 rules 1 TTPThe ldap3_proto package is vulnerable to LDAP Filter stack exhaustion due to unbounded query depth, potentially causing a denial of service in applications processing LDAP queries, affecting versions before 0.7.1.
Kanidm SCIM Filter Stack Exhaustion Vulnerability
2 rules 3 TTPsAn unauthenticated GET request with deeply nested parentheses in the SCIM filter parameter can cause stack exhaustion and process termination in Kanidm, leading to denial of service.
Netty epoll Transport Denial of Service via RST on Half-Closed TCP Connection
2 rules 1 TTPNetty's epoll transport fails to properly close TCP connections that receive a RST after a half-close, leading to resource exhaustion and potential CPU busy-loops, impacting service availability.
Daptin SQL Injection Vulnerability via Fuzzy Search
2 rules 4 TTPsDaptin versions up to 0.11.4 are vulnerable to SQL injection, where an authenticated user can inject unvalidated column names into raw SQL via the `processFuzzySearch` function, allowing them to read the entire database.
PraisonAI SSRF Vulnerability via URL Parsing Discrepancy
2 rules 1 TTPPraisonAI versions 1.6.31 and earlier contain a Server-Side Request Forgery (SSRF) vulnerability due to inconsistent URL parsing between the application's validation logic and the underlying requests library, allowing attackers to bypass intended security checks and access internal resources.
Grav CMS API Blueprint Upload Privilege Escalation
2 rules 1 TTPA low-privileged authenticated API user with `api.media.write` can abuse `/api/v1/blueprint-upload` in Grav CMS to write an arbitrary YAML file into `user/accounts/`, enabling creation of a super-admin account and leading to full administrative compromise of the Grav API.
Snappier SnappyStream Decompression Infinite Loop Vulnerability
2 rules 1 TTPSnappier versions 1.3.0 and earlier are vulnerable to a denial-of-service condition where a malformed Snappy stream input to `SnappyStream` decompression causes an infinite loop, consuming a thread until the process is terminated.
phpMyFAQ SQL Injection via Unescaped OAuth Token
2 rules 1 TTPphpMyFAQ is vulnerable to SQL injection due to the `setTokenData` function failing to sanitize OAuth token fields from Azure AD JWT claims, potentially allowing attackers to execute arbitrary SQL commands via crafted Azure AD display names or custom claims.
OpenClaw Heredoc Shell Expansion Bypass (CVE-2026-44115)
2 rules 1 TTP 1 CVEOpenClaw before 2026.4.22 is vulnerable to shell expansion in unquoted heredoc bodies, allowing attackers to bypass exec allowlist validation and execute unauthorized commands.
OpenClaw Improper Environment Variable Handling Vulnerability
2 rules 1 TTP 1 CVEOpenClaw before 2026.4.20 is vulnerable to improper environment variable namespace reservation, allowing attackers to override critical runtime variables via workspace dotenv files.
OpenClaw SSRF Vulnerability in Zalo Plugin (CVE-2026-44116)
2 rules 1 TTP 1 CVEOpenClaw before 2026.4.22 is vulnerable to server-side request forgery (SSRF) due to improper validation of outbound photo URLs in the Zalo plugin's sendPhoto function, allowing attackers to potentially access internal resources by providing malicious photo URLs to the Zalo Bot API.
OpenClaw Insufficient Environment Variable Denylist Vulnerability (CVE-2026-43584)
3 rules 3 TTPs 1 CVEOpenClaw before 2026.4.10 is vulnerable to an insufficient environment variable denylist, allowing attackers to manipulate interpreter startup variables to influence execution behavior or network connectivity.
OpenClaw Improper Network Binding Leads to Unauthorized CDP Access (CVE-2026-43581)
2 rules 1 TTP 1 CVEOpenClaw before 2026.4.10 contains an improper network binding vulnerability (CVE-2026-43581) that exposes the Chrome DevTools Protocol (CDP) on 0.0.0.0, allowing attackers to access the DevTools protocol outside intended local sandbox boundaries.
OpenClaw Incomplete Navigation Guard SSRF Bypass (CVE-2026-43580)
2 rules 1 TTP 1 CVEOpenClaw before version 2026.4.10 contains an incomplete navigation guard vulnerability, allowing attackers to trigger navigation without proper SSRF policy enforcement by bypassing post-action security checks via browser interactions like pressKey and type submit flows, potentially leading to unauthorized Server-Side Request Forgery (SSRF).
OpenClaw Privilege Escalation Vulnerability (CVE-2026-43578)
2 rules 1 TTP 1 CVEOpenClaw versions before 2026.4.10 are vulnerable to privilege escalation due to improper handling of background async exec completion events, potentially allowing attackers to execute code with elevated privileges by providing untrusted completion content.
Mezo L1 Bridge Vulnerability Leads to Potential ERC-20 Drain
3 rules 2 TTPsA vulnerability in the Mezo bridge allows for the potential full drain of the L1 bridge without changing the bridged balance on Mezo due to a stale StateDB overwrite, enabling a malicious user to steal ERC-20 tokens locked in the L1 bridge.
Cisco Releases Security Advisories for Multiple Products
3 rules 3 TTPsCisco released security advisories on May 6, 2026, addressing vulnerabilities including remote code execution, server-side request forgery, and denial of service in Crosswork Network Controller, IoT Field Network Director, Network Services Orchestrator, SG350/SG350X Managed Switches, and Unity Connection.
Apache HTTP Server HTTP/2 Protocol Vulnerability Could Allow for Remote Code Execution
2 rules 2 TTPsA vulnerability in Apache HTTP Server's HTTP/2 protocol can lead to denial of service by crashing worker processes, and in specific configurations (APR with mmap), remote code execution.
Vvveb CMS XML External Entity Injection Vulnerability
2 rules 3 TTPs 1 CVEVvveb before 1.0.8.2 is vulnerable to XML external entity (XXE) injection in the admin import feature, allowing authenticated site administrators to read arbitrary files and modify database records, potentially leading to privilege escalation.
Vvveb Hardcoded Credentials Vulnerability in phpMyAdmin Container
2 rules 1 TTP 1 CVEVvveb versions before 1.0.8.2 contain a hardcoded credentials vulnerability in the docker-compose-apache.yaml configuration, allowing unauthenticated attackers to access the phpMyAdmin container and gain unrestricted read and write access to the Vvveb database, leading to account takeover and data manipulation.
dssrf SSRF Protection Bypass via IPv6 Addresses
2 rules 12 IOCsA vulnerability in the dssrf npm package allows attackers to bypass SSRF protections by using specially crafted IPv6 addresses, despite documentation claiming IPv6 is disabled, which can lead to internal resource access or other malicious activities.
Craft CMS Missing Volume Permission Check Allows Information Disclosure
2 rules 1 TTPCraft CMS versions 5.0.0-RC1 before 5.9.18 are vulnerable to information disclosure where an authenticated control panel user with only accessCp permission can discover filenames and the complete folder structure of assets in unauthorized volumes by supplying arbitrary asset IDs to AssetsController::actionShowInFolder(), exposing sensitive volume structures and enabling targeted follow-up attacks.
Craft CMS GraphQL Address Resolver Missing Authorization Allows PII Disclosure
2 rules 1 TTPA missing authorization check in the GraphQL Address element resolver of Craft CMS Pro allows a GraphQL API token scoped to a low-privilege user group to read all addresses in the system, including those belonging to users in groups the token is not authorized to access, exposing personally identifiable information (PII).
Samsung Mobile Devices Multiple Vulnerabilities
2 rulesSamsung released a security update to address multiple vulnerabilities in Samsung mobile devices running versions prior to SMR-MAY-2026 Release 1, potentially allowing attackers to exploit these vulnerabilities for malicious purposes.