September 2026 (30)
Stored Cross-Site Scripting in MotoPress Hotel Booking Plugin
1 rule 1 TTP 1 CVEThe MotoPress Hotel Booking plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Stripe webhook listener due to missing signature verification and improper output sanitization.
Denial-of-Service Vulnerability in Hirschmann HiOS Switch Platform
1 CVEHirschmann HiOS Switch Platform devices are susceptible to a remote unauthenticated denial-of-service vulnerability due to improper input validation in the integrated web server.
Heap-Based Buffer Overflow in Ghostscript JPEG 2000 Output Adapter
1 TTP 1 CVEGhostscript versions prior to 10.08.0 are vulnerable to a heap-based buffer overflow in the JPEG 2000 output adapter (CVE-2026-39919), potentially allowing arbitrary code execution via a specially crafted PDF.
Authentication Bypass in pig via Password Reset Endpoint
1 rule 2 TTPs 1 CVEAn authentication bypass vulnerability in pig versions prior to 4.1.0 allows remote attackers to perform unauthorized account takeovers by exploiting improper password verification in the /register/password endpoint.
Authorization Bypass Vulnerability in Casdoor /api/mcp Endpoint
1 rule 1 CVECasdoor versions through 4.4.0 contain an authorization bypass vulnerability (CVE-2026-91998) in the /api/mcp endpoint, allowing authenticated attackers to perform unauthorized administrative actions across all organizations.
Privilege Escalation in Consulting Theme for WordPress via Improper Access Control
1 rule 1 TTP 1 CVEThe Consulting theme for WordPress in versions 6.7.16 and earlier contains a vulnerability allowing authenticated users to escalate privileges to administrator by manipulating insecure transient-based authentication mechanisms.
Privilege Escalation Vulnerability in OpenBMC phosphor-net-ipmid (CVE-2026-16140)
1 TTP 1 CVEA logic flaw in OpenBMC's phosphor-net-ipmid implementation allows authenticated remote attackers to hijack existing sessions and perform unauthorized privilege escalation.
Unauthenticated Information Disclosure in lamp-cloud via CVE-2026-91996
1 rule 1 TTP 1 CVEAn authentication bypass vulnerability in lamp-cloud versions 5.10.0 and earlier allows unauthenticated attackers to exfiltrate sensitive JVM system properties via insecurely whitelisted API endpoints.
SSRF Vulnerability in KubeSphere Git Credential Verification
1 CVEKubeSphere versions up to 4.1.3 contain a server-side request forgery (SSRF) vulnerability in the git credential verification endpoint, allowing authenticated attackers to exfiltrate Kubernetes Secrets.
Remote Code Execution Vulnerability in WebKitGTK
1 TTP 1 CVEA memory corruption vulnerability in WebKitGTK allows a remote, unauthenticated attacker to execute arbitrary code or trigger a denial-of-service condition by processing maliciously crafted web content.
Local Privilege Escalation Vulnerability in Windows 11 Secure Kernel Mode
1 TTPA vulnerability in the Secure Kernel Mode of Microsoft Windows 11 allows a local attacker to perform privilege escalation on the affected system.
Arbitrary Code Execution Vulnerability in Octopus Deploy Server
2 TTPs 1 CVEA vulnerability in Octopus Deploy Server allows a remote attacker to execute arbitrary code, potentially leading to full system compromise of the application instance.
Multiple Vulnerabilities in Langflow
2 TTPsLangflow contains multiple vulnerabilities that enable remote attackers to achieve remote code execution with administrative privileges and bypass existing security controls.
Unauthenticated Arbitrary File Manipulation in Royal Elementor Addons
1 TTP 1 CVEA vulnerability in the Royal Elementor Addons plugin for WordPress allows an unauthenticated, remote attacker to manipulate files on the server via improper access control.
Cross-Site Scripting Vulnerability in Governikus AusweisApp2
1 TTPA vulnerability in the Governikus AusweisApp2 software allows a remote, unauthenticated attacker to execute a Cross-Site Scripting (XSS) attack.
Heap-Based Buffer Overflow in GIMP PSP File Loader
1 TTP 1 CVEA heap-based buffer overflow in GIMP's PSP file loader, tracked as CVE-2026-90949, allows attackers to trigger crashes or arbitrary code execution via crafted image files.
Multiple Denial of Service Vulnerabilities in System Security Services Daemon
1 TTPLocal attackers can exploit multiple vulnerabilities in the System Security Services Daemon (SSSD) to trigger a denial of service condition, impacting authentication and identity management services on Linux systems.
Multiple Vulnerabilities in GNU Binutils
1 TTPThe GNU binutils package contains multiple vulnerabilities that allow a local attacker to cause a Denial of Service condition or disclose sensitive information by processing malformed object files.
Multiple Vulnerabilities in IBM MQ
2 CVEsIBM MQ is affected by multiple vulnerabilities, including CVE-2024-49033, CVE-2024-49034, and CVE-2024-49035, which could allow a remote attacker to execute arbitrary code, cause a denial of service, disclose sensitive information, or manipulate data.
Multiple Vulnerabilities in MikroTik RouterOS
1 TTPMultiple vulnerabilities in MikroTik RouterOS have been identified that allow a remote, authenticated attacker to trigger a denial of service condition and manipulate arbitrary files on the device.
Detection of Potential Linux Hack Tool Execution
1 rule 2 TTPsAdversaries leverage common security assessment and exploitation tools on Linux hosts to perform reconnaissance, credential access, and vulnerability exploitation, necessitating a baseline of authorized administrative activities.
Detection of Newly Observed Legitimate Network Scanning Tools
1 rule 2 TTPsAdversaries frequently utilize legitimate network scanning utilities like SoftPerfect Network Scanner and Advanced IP Scanner for reconnaissance following initial compromise to map internal network topology and identify lateral movement targets.
Mass-Scanning Campaign Exploits Vite Flaw to Extract Cloud Credentials
1 rule 3 TTPs 1 CVE 2 IOCsA mass-scanning campaign is actively exploiting CVE-2026-39364 in internet-exposed Vite development servers to bypass security restrictions and exfiltrate sensitive cloud credentials and configuration files.
Remote Code Execution in Polyaxon via Unsandboxed Jinja2 Injection
1 TTP 1 CVEAuthenticated users can execute arbitrary commands on the Polyaxon scheduler process by injecting malicious Jinja2 payloads into operation specification fields.
Authorization Bypass in pgweb API Connect Endpoint
1 rule 1 TTP 1 CVEAn authorization bypass vulnerability in pgweb versions up to 0.17.0 allows unauthenticated attackers to supply arbitrary connection strings via the /api/connect endpoint.
Critical RCE Vulnerability in Apache Struts (S2-067)
1 rule 2 TTPs 1 CVEA critical remote code execution vulnerability (CVE-2024-53677) in Apache Struts versions 2.0.0 through 6.3.0.2 allows attackers to leverage path traversal during file uploads to execute arbitrary code.
Privilege Escalation in leapp-upgrade-el9toel10
1 TTP 1 CVEA privilege escalation vulnerability (CVE-2026-75092) in the leapp-upgrade-el9toel10 package allows an attacker with mysql OS identity access to execute arbitrary code as root during RHEL upgrade workflows.
Privilege Escalation in Eventin WordPress Plugin
1 TTP 1 CVEThe Eventin WordPress plugin (<= 4.1.23) contains a vulnerability that allows users with ID 1 to bypass capability checks and escalate privileges to administrator level.
Remote Buffer Overflow Vulnerability in D-Link DI-8300
1 TTP 1 CVEA critical stack-based buffer overflow vulnerability in the D-Link DI-8300 CGI service enables remote code execution via a manipulated URL parameter.
ZITADEL Privilege Escalation via OAuth2 Token Exchange
1 TTP 1 CVEA vulnerability in ZITADEL's OAuth2 Token Exchange endpoint (CVE-2026-56668) allows authenticated users to exchange low-privilege tokens for highly privileged tokens by bypassing authorization and scope validation checks.