Skip to content
Threat Feed

July 2026 (30)

critical advisory

CVE-2026-16462: SQL Injection Vulnerability in PROCON-WEB SCADA

CVE-2026-16462 describes a critical SQL Injection vulnerability in Weidmueller Interface's PROCON-WEB SCADA, where a remote unauthenticated attacker can execute arbitrary SQL commands via the 'GetGridData' endpoint due to improper input sanitization, potentially leading to full system compromise.

PROCON-WEB SCADA <= 6.11.2 sql-injection vulnerability scada critical-vulnerability
1r 2t 1c
medium advisory

Netty: Vulnerability Enables Denial of Service

A denial of service vulnerability exists in Netty, which an unauthenticated, remote attacker can exploit, allowing the attacker to disrupt the availability of affected systems or services.

Netty denial-of-service vulnerability
1t
critical advisory

Erlang/OTP: Multiple Vulnerabilities

Multiple vulnerabilities in Erlang/OTP allow a remote, anonymous attacker to perform a Denial of Service attack, execute arbitrary code, bypass security measures, and manipulate or disclose data.

Erlang/OTP vulnerability erlang otp rce dos data-exfiltration defense-evasion
2t
high advisory

Multiple Vulnerabilities in Linux Kernel Allow Local Privilege Escalation and DoS

Multiple vulnerabilities in the Linux Kernel can be exploited by a local attacker to corrupt memory, disclose sensitive information, manipulate data, or cause a denial-of-service condition, often leading to privilege escalation.

Linux Kernel privilege-escalation dos information-disclosure linux-kernel
4t
high advisory

Generic SQL Injection Vulnerability in WordPress Web Directory Free Plugin (CVE-2026-14785)

The Web Directory Free plugin for WordPress, in all versions up to and including 1.7.13, is vulnerable to generic SQL Injection through the 'levels' parameter. This flaw, caused by insufficient input escaping and lack of query preparation, enables unauthenticated attackers to append arbitrary SQL queries to existing ones, allowing them to extract sensitive information directly from the database.

Web Directory Free sql-injection wordpress plugin web cve
1r 2t 1c
high advisory

Privilege Escalation in Eazy Plugin Manager for WordPress (CVE-2026-14328)

The Eazy Plugin Manager - Powerful Plugin Management Solution for WordPress plugin for WordPress (versions up to and including 4.4.1) is vulnerable to privilege escalation (CVE-2026-14328), allowing authenticated attackers with Subscriber-level access to read sensitive WordPress options, compute an authentication key, and obtain Administrator authentication cookies, leading to full site takeover if the plugin's remote connection feature is configured.

Eazy Plugin Manager – Powerful Plugin Management Solution for WordPress <= 4.4.1 wordpress web privilege-escalation cve-2026-14328
2r 1t 1c
high advisory

WordPress PickPlugins Question Answer Plugin SQL Injection Vulnerability (CVE-2026-10207)

An unauthenticated SQL injection vulnerability, tracked as CVE-2026-10207, exists in the PickPlugins Question Answer plugin for WordPress versions up to and including 1.2.73, allowing attackers to extract sensitive database information due to insufficient input sanitization of the 'id' GET parameter and improper SQL query construction.

Question Answer plugin <= 1.2.73 wordpress sql-injection vulnerability web-application
1r 2t 1c
high advisory

CVE-2026-14516 - Bookly WordPress Plugin Time-Based SQL Injection

Unauthenticated attackers can exploit a time-based SQL Injection vulnerability (CVE-2026-14516) in the Bookly WordPress plugin, affecting versions up to and including 27.5, via the 'staff_ids' parameter, chaining requests to `bookly_get_form_id` and `bookly_render_time` to extract sensitive database information due to insufficient input escaping and lack of CSRF protection.

Bookly plugin for WordPress <= 27.5 web sql-injection wordpress plugin vulnerability cve exfiltration
1r 2t 1c
medium advisory

CVE-2026-14169: Ads-tec DVG-IRF Series Vulnerability Allows Remote Admin Lockout

A low-privileged remote attacker can exploit an incorrect behavior order vulnerability (CVE-2026-14169, CWE-696) in multiple ads-tec Industrial IT DVG-IRF series devices (versions prior to 2.3.0) by sending crafted input, leading to inconsistent account states and password overwrites, resulting in complete administrative unavailability of the device.

DVG-IRF1401 +5 vulnerability denial-of-service industrial-control-systems network-device
1t 1c
high advisory

CVE-2026-14168: ads-tec Industrial IT DVG-IRF Privilege Escalation

A high-severity missing authorization vulnerability, CVE-2026-14168, allows a low-privileged remote attacker to escalate privileges to administrator level by exploiting the insert path of the configuration table in ads-tec Industrial IT DVG-IRF series products, ultimately granting full system access.

DVG-IRF1401 +5 privilege-escalation missing-authorization industrial-control-system embedded-device
1t 1c
high advisory

CVE-2026-14167: ads-tec Industrial IT DVG-IRF Series Privilege Escalation Vulnerability

A low-privileged remote attacker can exploit CVE-2026-14167, an incorrect authorization vulnerability in multiple ads-tec Industrial IT DVG-IRF series products, to perform privileged configuration changes, including permission management, leading to privilege escalation.

DVG-IRF1401 +5 vulnerability privilege-escalation authorization-bypass ICS OT
1t 1c
high advisory

TrueBooker WordPress Plugin SQL Injection Vulnerability (CVE-2026-13161)

An unauthenticated attacker can exploit CVE-2026-13161, a generic SQL Injection vulnerability in the TrueBooker - Appointment Booking and Scheduler System plugin for WordPress affecting versions up to and including 1.2.2, by manipulating the 'alldata[truebooker_user]' parameter in POST requests, allowing the extraction of sensitive database information.

TrueBooker – Appointment Booking and Scheduler System plugin +1 wordpress sqli plugin web-vulnerability cve
1r 2t 1c
high advisory

WordPress Premium Packages Plugin SQL Injection Vulnerability (CVE-2026-12800)

The Premium Packages - Sell Digital Products Securely plugin for WordPress, in versions up to and including 6.2.0, is vulnerable to SQL Injection via the 'code' parameter of the POST /wp-json/wpdmpp/v1/cart/coupon REST API endpoint, allowing unauthenticated attackers to append additional SQL queries to extract sensitive database information.

Premium Packages – Sell Digital Products Securely wordpress sql-injection web-application unauthenticated
1r 3t 1c
high threat

Adversarial Indirect Prompt Injection Tools Emerge in Underground Forums

Malicious actors are actively developing and advertising tools for Indirect Prompt Injection (IDPI) on underground forums, leveraging hidden prompts within various mediums like emails, PDFs, calendar invites, and malvertising to manipulate Large Language Models (LLMs) and AI agents, potentially leading to unintended behaviors such as data exfiltration or bypassing content moderation systems.

exploited Large Language Models +4 prompt-injection ai-security llm malvertising phishing
4t
medium advisory

Credential Manager Access By Uncommon Applications

A SigmaHQ detection rule identifies suspicious processes accessing Windows credential manager and vault files, potentially indicating credential theft by tools like Mimikatz, enabling lateral movement and data exfiltration.

credential-theft mimikatz dpapi windows post-exploitation
1r 1t
high threat

System File Execution Location Anomaly

This brief describes the detection of Windows system binaries executing from uncommon locations, a defense evasion and stealth technique employed by various threat actors including Lazarus Group and Sidewinder APT, indicating potential malicious activity on an endpoint.

Windows Lazarus Group +5 defense-evasion stealth execution process-anomaly
1r 4t updated
medium advisory

Msiexec Quiet Installation for Proxy Execution

Adversaries leverage the Windows Installer utility msiexec.exe to proxy the quiet execution of malicious payloads, bypassing traditional security controls by masquerading as legitimate installation processes.

living-off-the-land proxy-execution persistence execution
1r 1t
medium advisory

Suspicious WSMAN Provider Image Loads

A detection engineering rule targets suspicious loading of Windows Management (WSMAN) provider DLLs by unusual processes, indicating potential local or remote execution and lateral movement through Windows Remote Management (WinRM) by threat actors.

lateral-movement remote-execution windows-management winrm
1r 2t
medium advisory

PowerShell Core DLL Loaded By Non PowerShell Process

This threat brief details a detection for the suspicious loading of PowerShell Core DLLs by non-PowerShell processes, a technique often employed by attackers to execute PowerShell code stealthily and evade security monitoring.

defense-evasion scripting powershell
1r 1t
low advisory

Uncommon Process Loading RstrtMgr.DLL for Malicious Purposes

Attackers, including ransomware families like Conti and Cactus, and wipers such as BiBi, abuse the legitimate Windows `RstrtMgr.dll` (Restart Manager) by loading it into uncommon processes to terminate applications, including security software and those holding locks on files, facilitating data encryption or destruction.

Windows defense-evasion impact ransomware wiper
1r 2t
medium advisory

PSScriptPolicyTest Creation By Uncommon Process

This brief describes a detection opportunity for the stealthy creation of the 'PSScriptPolicyTest' PowerShell script by processes other than standard PowerShell executables or legitimate Windows components, a behavior potentially indicative of advanced adversaries attempting to bypass PowerShell logging and security policies.

stealth detection powershell
1r 1t
medium advisory

Suspicious System Process Names in Unusual File Locations

This brief detects an attacker's attempt to evade detection and maintain persistence by creating executable files with names identical to legitimate Windows system processes in non-standard directories, a tactic associated with stealth and defense evasion.

stealth defense-evasion persistence windows file-event
1r 1t
medium advisory

Suspicious Access to Windows DPAPI Master Keys by Uncommon Applications

Adversaries can access Windows Data Protection API (DPAPI) master keys using uncommon applications like Mimikatz to decrypt user credentials and sensitive data, indicating credential theft activities.

dpapi credential-theft mimikatz windows credential-access
1r 1t
high advisory

CVE-2026-12741: Unauthenticated SQL Injection in WP Fast Total Search WordPress Plugin

An SQL injection vulnerability (CVE-2026-12741) exists in the WP Fast Total Search - The Power of Indexed Search plugin for WordPress, affecting all versions up to and including 1.80.280. The flaw, located in the 'form_data[s]' parameter, is due to insufficient input escaping and poor SQL query preparation, allowing unauthenticated attackers to inject malicious SQL queries and extract sensitive information from the underlying database.

WP Fast Total Search – The Power of Indexed Search wordpress plugin sql-injection web-vulnerability data-exfiltration
1r 2t 1c
critical advisory

Authentication Bypass in WordPress SMS Alert Plugin Leads to Account Takeover (CVE-2026-15014)

An authentication bypass vulnerability (CVE-2026-15014) in the 'SMS Alert - SMS & OTP for WooCommerce, Order Notifications & Abandoned Cart Recovery' WordPress plugin allows unauthenticated attackers to achieve account takeover by exploiting a flaw in the `processRegistration()` function's OTP verification, enabling authentication as any existing WordPress user with a known phone number.

SMS Alert – SMS & OTP for WooCommerce, Order Notifications & Abandoned Cart Recovery plugin +1 wordpress authentication-bypass account-takeover web-application cve
1r 2t 1c
high threat

Mirage Kitten Targets Middle East and Africa with New Malware

Mirage Kitten, an advanced persistent threat (APT) group, is deploying new Windows backdoor (NightLedger) and WebSocket tunnelers (ArcBridge, BridgeHead) via spear-phishing campaigns to conduct cyber-espionage and data exfiltration against aerospace, aviation, defense, and telecommunications sectors in the Middle East and Europe.

Windows Mirage Kitten cyber-espionage apt malware backdoor tunneler dll-hijacking websocket spear-phishing
4r 13t 3i
high advisory

CVE-2026-50107: NGINX Gateway Fabric Configuration Injection Vulnerability

An injection vulnerability, CVE-2026-50107, exists in the NGINX configuration generator component of NGINX Gateway Fabric when configured with NGINX Plus or NGINX Open Source as the data plane, allowing authenticated attackers with CRD modification permissions to inject arbitrary NGINX configuration directives via unsanitized user-supplied string values in the access log format setting, leading to control plane compromise and potential defense evasion or system impact.

PoC NGINX Plus +10 config-injection nginx kubernetes cloud-native web-vulnerability cve
2r 1t 5c 2i updated
high advisory

Arbitrary File Deletion Vulnerability in WordPress Better Messages Plugin

A path traversal vulnerability, CVE-2026-16585, in the Better Messages - Chat Rooms, Group Chat, Private Messages & AI Chat Bots plugin for WordPress allows authenticated administrators to delete arbitrary files on the server by bypassing file path validation, potentially leading to remote code execution.

Better Messages – Chat Rooms, Group Chat, Private Messages & AI Chat Bots < 2.15.19 wordpress web-vulnerability path-traversal rce file-deletion
1r 2t 1c
medium advisory

The Demi WordPress Plugin Vulnerable to Arbitrary Directory Deletion (CVE-2026-14490)

Unauthenticated attackers can exploit CVE-2026-14490 in The Demi - One Click Demo Import, WP Backup & Site Migration WordPress plugin (versions up to and including 0.0.7) to achieve arbitrary directory deletion by retrieving a publicly exposed HMAC signing key and forging valid requests to a vulnerable AJAX handler.

The Demi – One Click Demo Import, WP Backup & Site Migration plugin <= 0.0.7 wordpress plugin-vulnerability arbitrary-deletion web-vulnerability
2t 1c
high advisory

Svchost LOLBAS Execution Process Spawn

This brief details the detection of `svchost.exe` spawning Living Off The Land Binaries and Scripts (LOLBAS) processes, indicating potential malicious code execution, privilege escalation, or persistence attempts by adversaries within a Windows environment.

Windows lolbas execution persistence lateral-movement system-binary-proxy-execution
1r 2t