Skip to content
Threat Feed

May 2026 (30)

medium advisory

ABB B&R Automation Runtime Denial-of-Service Vulnerability

A denial-of-service vulnerability (CVE-2025-11044) exists in ABB B&R Automation Runtime versions prior to 6.5 and R4.93, where an unauthenticated attacker can exploit a race condition to cause permanent denial-of-service.

ABB B&R Automation Runtime dos ics cve-2025-11044
2r 1t 1c
medium advisory

ABB B&R Automation Studio Improper Certificate Validation Vulnerability

ABB B&R Automation Studio versions before 6.5 are vulnerable to improper certificate validation (CVE-2025-11043), potentially allowing an unauthenticated attacker to intercept and interfere with data exchanges, necessitating patching and secure network configurations.

B&R Automation Studio <6.5 ics certificate validation man-in-the-middle
2r 2t 1c
high advisory

Johnson Controls CEM AC2000 Privilege Escalation via DLL Hijacking

A vulnerability exists in Johnson Controls CEM AC2000 versions 12.0, 11.0, and 10.6 due to an uncontrolled search path element that could allow a standard user to escalate privileges on the host machine via DLL hijacking.

CEM AC2000 privilege-escalation dll-hijacking cem-ac2000
2r 1t
critical threat

Weaver E-cology Unauthenticated RCE Exploitation

A critical unauthenticated remote code execution vulnerability (CVE-2026-22679) in Weaver E-cology office automation software is being actively exploited to execute system commands and reconnaissance activities on affected servers.

exploited E-cology 10.0 +1 rce weaver-ecology cve-2026-22679 exploitation
2r 2t 1c
high advisory

OpenCTI Vulnerability Allows Privilege Escalation to Administrator

A remote, authenticated attacker can exploit a vulnerability in OpenCTI to gain administrator privileges, potentially leading to unauthorized access and control over the platform.

OpenCTI privilege-escalation cloud
2r 1t
high advisory

Dell Computer Vulnerability Allows Local Code Execution

A local attacker can exploit a vulnerability in Dell computers to execute arbitrary code.

Dell Computer local-code-execution vulnerability dell
2r 1t
critical advisory

BusyBox Vulnerability Allows Remote Code Execution or Denial-of-Service

A vulnerability in BusyBox allows a remote attacker on an adjacent network to execute arbitrary code or cause a denial-of-service condition.

BusyBox rce dos linux
2r 2t
high advisory

CloudZ RAT Abuses Microsoft Phone Link to Steal SMS and OTPs

A new version of the CloudZ RAT utilizes the Pheno plugin to hijack Microsoft Phone Link connections, enabling the theft of SMS messages and one-time passwords (OTPs) from victims' mobile devices.

Phone Link +2 cloudz malware rat microsoft-phone-link credential-theft otp sms
2r 1t
high advisory

CloudZ RAT Abusing Windows Phone Link to Steal OTPs

An unknown attacker is using the CloudZ RAT and its Pheno plugin to hijack the Microsoft Phone Link application and intercept SMS and OTP messages from connected mobile devices, active since at least January 2026.

Windows 10 +2 cloudz rat pheno phone-link otp credential-theft
2r 6t
medium advisory

Potential Protocol Tunneling via Cloudflared

Adversaries may abuse Cloudflare Tunnel (cloudflared) on Windows systems to proxy command and control traffic or exfiltrate data through Cloudflare's edge, evading direct connection blocking.

M365 Defender +1 cloudflare tunneling command and control proxy
2r 2t 1i
critical advisory

NetBox Vulnerability Allows Remote Code Execution

A remote, authenticated attacker can exploit a vulnerability in NetBox to execute arbitrary program code.

NetBox code-execution web-application
2r 1t
critical threat

Multiple Vulnerabilities in Apache HTTP Server

Multiple vulnerabilities in Apache HTTP Server can be exploited by an attacker to gain elevated privileges, execute arbitrary code, bypass security measures, disclose sensitive information, or cause a denial-of-service condition.

HTTP Server apache vulnerability privilege-escalation execution defense-evasion information-disclosure denial-of-service
2r 6t
critical threat

Red Hat Enterprise Linux freeipmi Vulnerability Allows Code Execution

A remote, anonymous attacker can exploit a vulnerability in Red Hat Enterprise Linux freeipmi to cause a denial of service condition or memory corruption, potentially allowing arbitrary code execution.

Enterprise Linux rhel freeipmi vulnerability code-execution dos
2r 4t
high threat

ScarCruft (APT37) Deploying BirdCall Android Backdoor via Compromised Game Platform

The APT37 group (ScarCruft) is distributing an Android version of the BirdCall backdoor via a supply-chain attack targeting a Chinese video game platform, sqgame[.]net, to collect sensitive information from users.

Google Play +2 ScarCruft android malware spyware apt37 supply-chain
2r 5t 1i
critical threat

Red Hat Enterprise Linux Vulnerability Allows Privilege Escalation and Code Execution

A remote, anonymous attacker can exploit a vulnerability in Red Hat Enterprise Linux (python-wheel) to escalate privileges or execute arbitrary code.

Enterprise Linux privilege-escalation execution linux
2r 2t
critical advisory

Multiple Vulnerabilities in vm2 Sandbox

Multiple vulnerabilities in vm2 allow attackers to execute arbitrary code, perform denial of service, disclose information, and bypass security measures.

vm2 sandbox-escape code-execution denial-of-service
2r 3t
high threat

Multiple Vulnerabilities in Prometheus Allow for DoS, Information Disclosure, and XSS

Multiple vulnerabilities in Prometheus could allow an attacker to perform a Denial of Service attack, disclose sensitive information, or execute Cross-Site Scripting attacks.

Prometheus vulnerability denial-of-service information-disclosure cross-site-scripting
2r 2t
medium advisory

Microsoft Product Vulnerability CVE-2026-37457

CVE-2026-37457 is a vulnerability affecting a Microsoft product, for which details are currently unavailable.

vulnerability microsoft
2r 1c
high advisory

Forminator Forms Plugin Path Traversal Vulnerability

The Forminator Forms WordPress plugin is vulnerable to an unauthenticated path traversal that allows reading arbitrary files on the server when specific features are enabled.

Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin path-traversal wordpress plugin
2r 1t 1c
high advisory

54yyyu code-mcp Command Injection Vulnerability (CVE-2026-7812)

A command injection vulnerability (CVE-2026-7812) exists in the git_operation function of 54yyyu code-mcp's MCP Tool, allowing remote attackers to execute arbitrary commands by manipulating the operation argument.

code-mcp command-injection web-application cve-2026-7812
2r 1t 1c
high advisory

Path Traversal Vulnerability in UsamaK98 python-notebook-mcp

A path traversal vulnerability exists in the create_notebook/read_notebook/edit_cell/add_cell functions of server.py in UsamaK98's python-notebook-mcp, allowing remote attackers to access arbitrary files.

python-notebook-mcp path traversal vulnerability
3r 1t 1c
high advisory

AWP Classifieds WordPress Plugin SQL Injection Vulnerability

The AWP Classifieds plugin for WordPress is vulnerable to SQL Injection via the 'regions' parameter array keys in versions up to, and including, 4.4.5, potentially allowing unauthenticated attackers to extract sensitive information from the database.

AWP Classifieds plugin for WordPress sql-injection wordpress plugin
2r 1t 1c
critical advisory

WordPress Mentoring Plugin Privilege Escalation Vulnerability

The Mentoring plugin for WordPress is vulnerable to privilege escalation, allowing unauthenticated attackers to register with administrator-level user accounts due to improper role restriction in the mentoring_process_registration() function.

Mentoring plugin for WordPress privilege-escalation wordpress plugin
2r 1t 1c
high advisory

Axle-Bucamp MCP-Docusaurus Path Traversal Vulnerability

A path traversal vulnerability exists in Axle-Bucamp MCP-Docusaurus versions up to commit 404bc028e15ec304c9a045528560f4b5f27a17e0, allowing remote attackers to access sensitive files by manipulating the DOCS_DIR/path argument in specific functions.

MCP-Docusaurus path-traversal vulnerability web-application
2r 1t 1c
critical threat

A-G-U-P-T-A wireshark-mcp OS Command Injection Vulnerability

A-G-U-P-T-A wireshark-mcp is vulnerable to remote OS command injection (CVE-2026-7785) via manipulation of the `quick_capture` function in `pyshark_mcp.py`, potentially allowing attackers to execute arbitrary commands on the system.

exploited wireshark-mcp command-injection web-application rolling-release
2r 1t 1c
medium advisory

RTGS2017 NagaAgent Path Traversal Vulnerability

RTGS2017 NagaAgent up to version 5.1.0 is vulnerable to path traversal via manipulation of the 'Name' argument in the Skills Endpoint, potentially leading to unauthorized file access.

NagaAgent path-traversal web-application cve-2026-7784
2r 2t 1c
critical advisory

Google Android Remote Code Execution Vulnerability

A vulnerability in Google Android allows a remote attacker to execute arbitrary code, affecting versions prior to 14, 15, 16 and 16-qpr2 before the May 4, 2026 patch.

Android rce vulnerability
2r 1t 1c
critical advisory

Multiple Vulnerabilities in Apache HTTP Server Allow Remote Code Execution, Privilege Escalation, and Denial of Service

Multiple vulnerabilities in Apache HTTP Server versions prior to 2.4.67 can allow remote attackers to execute arbitrary code, escalate privileges, or cause a denial of service.

HTTP Server apache http vulnerability rce privilege-escalation dos
3r 3t 5c
high advisory

Multiple Vulnerabilities in PaperCut Allow Data Confidentiality Breach and Security Policy Bypass

Multiple vulnerabilities in PaperCut Embedded App versions prior to 2.2.0 on Ricoh devices and PaperCut NG/MF versions prior to 25.0.11 allow attackers to compromise data confidentiality and bypass security policies, potentially leading to unauthorized access and control.

PaperCut Embedded App +1 vulnerability papercut data-breach security-bypass
2r 2t 3c
high advisory

Traefik Data Confidentiality Vulnerability

A vulnerability in Traefik allows an attacker to compromise the confidentiality of data, affecting versions v2.11.x prior to v2.11.44, v3.6.x prior to v3.6.15, and v3.7.0-rc.x prior to v3.7.0-rc.3.

Traefik vulnerability data-disclosure
2r 1t