Skip to content
Threat Feed

September 2026 (30)

high advisory

Stored Cross-Site Scripting in MotoPress Hotel Booking Plugin

The MotoPress Hotel Booking plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Stripe webhook listener due to missing signature verification and improper output sanitization.

Hotel Booking web-application xss wordpress plugin-vulnerability
1r 1t 1c
low advisory

Denial-of-Service Vulnerability in Hirschmann HiOS Switch Platform

Hirschmann HiOS Switch Platform devices are susceptible to a remote unauthenticated denial-of-service vulnerability due to improper input validation in the integrated web server.

HiOS Switch Platform
1c
critical advisory

Heap-Based Buffer Overflow in Ghostscript JPEG 2000 Output Adapter

Ghostscript versions prior to 10.08.0 are vulnerable to a heap-based buffer overflow in the JPEG 2000 output adapter (CVE-2026-39919), potentially allowing arbitrary code execution via a specially crafted PDF.

Ghostscript
1t 1c
critical advisory

Authentication Bypass in pig via Password Reset Endpoint

An authentication bypass vulnerability in pig versions prior to 4.1.0 allows remote attackers to perform unauthorized account takeovers by exploiting improper password verification in the /register/password endpoint.

PoC pig
1r 2t 1c
critical advisory

Authorization Bypass Vulnerability in Casdoor /api/mcp Endpoint

Casdoor versions through 4.4.0 contain an authorization bypass vulnerability (CVE-2026-91998) in the /api/mcp endpoint, allowing authenticated attackers to perform unauthorized administrative actions across all organizations.

PoC Casdoor
1r 1c
high advisory

Privilege Escalation in Consulting Theme for WordPress via Improper Access Control

The Consulting theme for WordPress in versions 6.7.16 and earlier contains a vulnerability allowing authenticated users to escalate privileges to administrator by manipulating insecure transient-based authentication mechanisms.

PoC Consulting wordpress web-application privilege-escalation
1r 1t 1c
high advisory

Privilege Escalation Vulnerability in OpenBMC phosphor-net-ipmid (CVE-2026-16140)

A logic flaw in OpenBMC's phosphor-net-ipmid implementation allows authenticated remote attackers to hijack existing sessions and perform unauthorized privilege escalation.

phosphor-net-ipmid privilege-escalation ipmi openbmc
1t 1c
high advisory

Unauthenticated Information Disclosure in lamp-cloud via CVE-2026-91996

An authentication bypass vulnerability in lamp-cloud versions 5.10.0 and earlier allows unauthenticated attackers to exfiltrate sensitive JVM system properties via insecurely whitelisted API endpoints.

lamp-cloud vulnerability authentication-bypass information-disclosure
1r 1t 1c
high advisory

SSRF Vulnerability in KubeSphere Git Credential Verification

KubeSphere versions up to 4.1.3 contain a server-side request forgery (SSRF) vulnerability in the git credential verification endpoint, allowing authenticated attackers to exfiltrate Kubernetes Secrets.

KubeSphere
1c
high advisory

Remote Code Execution Vulnerability in WebKitGTK

A memory corruption vulnerability in WebKitGTK allows a remote, unauthenticated attacker to execute arbitrary code or trigger a denial-of-service condition by processing maliciously crafted web content.

WebKitGTK vulnerability rce linux
1t 1c
high advisory

Local Privilege Escalation Vulnerability in Windows 11 Secure Kernel Mode

A vulnerability in the Secure Kernel Mode of Microsoft Windows 11 allows a local attacker to perform privilege escalation on the affected system.

Windows 11 windows privilege-escalation kernel
1t
high advisory

Arbitrary Code Execution Vulnerability in Octopus Deploy Server

A vulnerability in Octopus Deploy Server allows a remote attacker to execute arbitrary code, potentially leading to full system compromise of the application instance.

Octopus Deploy Server vulnerability rce cicd
2t 1c
high advisory

Multiple Vulnerabilities in Langflow

Langflow contains multiple vulnerabilities that enable remote attackers to achieve remote code execution with administrative privileges and bypass existing security controls.

Langflow vulnerability rce
2t
medium advisory

Unauthenticated Arbitrary File Manipulation in Royal Elementor Addons

A vulnerability in the Royal Elementor Addons plugin for WordPress allows an unauthenticated, remote attacker to manipulate files on the server via improper access control.

Royal Elementor Addons
1t 1c
low threat

Cross-Site Scripting Vulnerability in Governikus AusweisApp2

A vulnerability in the Governikus AusweisApp2 software allows a remote, unauthenticated attacker to execute a Cross-Site Scripting (XSS) attack.

exploited AusweisApp2 web-vulnerability xss
1t
high advisory

Heap-Based Buffer Overflow in GIMP PSP File Loader

A heap-based buffer overflow in GIMP's PSP file loader, tracked as CVE-2026-90949, allows attackers to trigger crashes or arbitrary code execution via crafted image files.

GIMP +1 vulnerability memory-corruption
1t 1c updated
medium advisory

Multiple Denial of Service Vulnerabilities in System Security Services Daemon

Local attackers can exploit multiple vulnerabilities in the System Security Services Daemon (SSSD) to trigger a denial of service condition, impacting authentication and identity management services on Linux systems.

System Security Services Daemon denial-of-service sssd linux authentication
1t
medium advisory

Multiple Vulnerabilities in GNU Binutils

The GNU binutils package contains multiple vulnerabilities that allow a local attacker to cause a Denial of Service condition or disclose sensitive information by processing malformed object files.

binutils vulnerability local-exploitation
1t
high advisory

Multiple Vulnerabilities in IBM MQ

IBM MQ is affected by multiple vulnerabilities, including CVE-2024-49033, CVE-2024-49034, and CVE-2024-49035, which could allow a remote attacker to execute arbitrary code, cause a denial of service, disclose sensitive information, or manipulate data.

MQ vulnerability messaging-middleware remote-code-execution
2c
medium advisory

Multiple Vulnerabilities in MikroTik RouterOS

Multiple vulnerabilities in MikroTik RouterOS have been identified that allow a remote, authenticated attacker to trigger a denial of service condition and manipulate arbitrary files on the device.

RouterOS
1t
medium advisory

Detection of Potential Linux Hack Tool Execution

Adversaries leverage common security assessment and exploitation tools on Linux hosts to perform reconnaissance, credential access, and vulnerability exploitation, necessitating a baseline of authorized administrative activities.

linux execution reconnaissance credential-access
1r 2t
medium advisory

Detection of Newly Observed Legitimate Network Scanning Tools

Adversaries frequently utilize legitimate network scanning utilities like SoftPerfect Network Scanner and Advanced IP Scanner for reconnaissance following initial compromise to map internal network topology and identify lateral movement targets.

SoftPerfect Network Scanner +2 discovery reconnaissance windows endpoint-detection
1r 2t updated
high threat

Mass-Scanning Campaign Exploits Vite Flaw to Extract Cloud Credentials

A mass-scanning campaign is actively exploiting CVE-2026-39364 in internet-exposed Vite development servers to bypass security restrictions and exfiltrate sensitive cloud credentials and configuration files.

exploited Vite
1r 3t 1c 2i
high advisory

Remote Code Execution in Polyaxon via Unsandboxed Jinja2 Injection

Authenticated users can execute arbitrary commands on the Polyaxon scheduler process by injecting malicious Jinja2 payloads into operation specification fields.

Polyaxon remote-code-execution jinja2 template-injection
1t 1c
high advisory

Authorization Bypass in pgweb API Connect Endpoint

An authorization bypass vulnerability in pgweb versions up to 0.17.0 allows unauthenticated attackers to supply arbitrary connection strings via the /api/connect endpoint.

pgweb vulnerability web-application authentication-bypass
1r 1t 1c
critical advisory

Critical RCE Vulnerability in Apache Struts (S2-067)

A critical remote code execution vulnerability (CVE-2024-53677) in Apache Struts versions 2.0.0 through 6.3.0.2 allows attackers to leverage path traversal during file uploads to execute arbitrary code.

Struts apache-struts rce file-upload web-application-attack
1r 2t 1c
high advisory

Privilege Escalation in leapp-upgrade-el9toel10

A privilege escalation vulnerability (CVE-2026-75092) in the leapp-upgrade-el9toel10 package allows an attacker with mysql OS identity access to execute arbitrary code as root during RHEL upgrade workflows.

leapp-upgrade-el9toel10 vulnerability privilege-escalation linux rhel
1t 1c
high advisory

Privilege Escalation in Eventin WordPress Plugin

The Eventin WordPress plugin (<= 4.1.23) contains a vulnerability that allows users with ID 1 to bypass capability checks and escalate privileges to administrator level.

Eventin wordpress privilege-escalation plugin-vulnerability
1t 1c
critical advisory

Remote Buffer Overflow Vulnerability in D-Link DI-8300

A critical stack-based buffer overflow vulnerability in the D-Link DI-8300 CGI service enables remote code execution via a manipulated URL parameter.

DI-8300 vulnerability cve network-infrastructure
1t 1c
high advisory

ZITADEL Privilege Escalation via OAuth2 Token Exchange

A vulnerability in ZITADEL's OAuth2 Token Exchange endpoint (CVE-2026-56668) allows authenticated users to exchange low-privilege tokens for highly privileged tokens by bypassing authorization and scope validation checks.

ZITADEL +1 auth-bypass privilege-escalation oauth2
1t 1c