Skip to content
Threat Feed

July 2026 (30)

high advisory

Path Traversal Vulnerability in NitroShare Desktop (CVE-2026-66050)

NitroShare Desktop versions up to and including 0.3.4 are vulnerable to a path traversal flaw in their LAN file transfer server, allowing unauthenticated attackers on the same network to craft malicious filenames containing directory traversal sequences within the JSON item header. Exploiting this, attackers can write arbitrary files outside the intended transfer root to any location the current user has write access, including the Windows Startup folder, leading to persistent code execution upon user login.

NitroShare Desktop <= 0.3.4 path-traversal persistence code-execution vulnerability
1r 1t 1c
critical advisory

Grav Remote Code Execution Vulnerability in Blueprint::dynamicData()

A critical remote code execution vulnerability (CVE-2026-65008) in Grav versions prior to 2.0.7 allows an authenticated attacker with `admin.pages` or `api.pages.write` permissions to embed malicious callable directives in a page's frontmatter, leading to arbitrary code execution as the web-server user when the page is accessed.

PoC Grav < 2.0.7 +1 web-exploitation rce php
2t 1c 4i updated
medium advisory

Siemens Teamcenter Vulnerability CVE-2026-33862 - Cross-Site Scripting

Siemens Teamcenter versions V2312 (before V2312.0014), V2406 (before V2406.0012), V2412 (before V2412.0009), V2506 (before V2506.0005), and V2512 are vulnerable to cross-site scripting (XSS) due to improper encoding or filtering of user-supplied data, potentially leading to arbitrary code execution by other users.

PoC Teamcenter V2312 +6 cve xss siemens teamcenter
2r 1t 3c 3i updated
critical advisory

Zabbix Cross-Site Scripting Vulnerability

A critical cross-site scripting (XSS) vulnerability has been identified in Zabbix, which a remote, unauthenticated attacker can exploit to execute malicious scripts within a user's browser session, potentially leading to unauthorized actions or data theft.

Zabbix cross-site-scripting xss web-application vulnerability
1r 1t
high threat

FFmpeg: Multiple Vulnerabilities

Multiple vulnerabilities in ffmpeg allow a remote, anonymous attacker to cause memory corruption, execute arbitrary code, trigger a denial-of-service condition, or disclose confidential information. The attacker does not require authentication to exploit these flaws.

exploited ffmpeg vulnerability rce denial-of-service information-disclosure memory-corruption
2t
high advisory

CVE-2026-17527: Kubernetes CDI Privilege Escalation and Data Exfiltration

A vulnerability in the Containerized Data Importer (CDI) for Kubernetes, identified as CVE-2026-17527, allows privilege escalation and data exfiltration through an improperly configured `cdi.kubevirt.io:view` ClusterRole, enabling attackers with partial access to clone and access data from any PersistentVolumeClaim in the cluster.

Containerized Data Importer containerization kubernetes privilege-escalation data-exfiltration cloud
3t 1c
high advisory

Kernel Local Privilege Escalation Vulnerability CVE-2026-17523

A critical local privilege escalation (LPE) vulnerability, tracked as CVE-2026-17523 and identified as an Expired Pointer Dereference (CWE-825), exists within the kernel, primarily affecting Red Hat Enterprise Linux 8, enabling an unprivileged local user to execute arbitrary code within the kernel, leading to root privileges and full control over the compromised system.

Red Hat Enterprise Linux 8 privilege-escalation kernel-vulnerability linux lpe cve
1t 1c
high advisory

OpenCTI Security Bypass and Information Disclosure Vulnerability

A remote, anonymous attacker can exploit a vulnerability in OpenCTI to bypass security measures and disclose sensitive information, potentially leading to unauthorized access to critical threat intelligence data and circumvention of protective controls within the platform.

OpenCTI vulnerability information-disclosure security-bypass
2t
high threat

Multiple Vulnerabilities in libssh2 Library Discovered

Multiple vulnerabilities in the libssh2 library allow a remote, unauthenticated attacker to potentially disclose sensitive information, cause a denial-of-service condition, or execute arbitrary code.

exploited libssh2 vulnerability library remote-code-execution denial-of-service information-disclosure
2t
high advisory

Improper Signature Verification in Lenze Products (CVE-2026-14837)

A low-privileged local attacker can exploit CVE-2026-14837, an improper signature verification vulnerability, in multiple Lenze products including models c430, c520, c550, i950 GenA, and i950 GenB to bypass the verification of the SSH enable file signature, subsequently enabling SSH access on the affected device, resulting in unauthorized administrative access and complete system compromise.

c430 +4 vulnerability ics ot industrial-control-system ssh signature-bypass
2t 1c
critical advisory

SiYuan Missing Authorization Vulnerability in /mcp Endpoint (CVE-2026-66012)

A critical missing authorization vulnerability, CVE-2026-66012, in SiYuan before version 3.7.2 allows a remote unauthenticated attacker to exploit the POST /mcp kernel endpoint when the Publish server is in anonymous mode, leading to arbitrary file writes, sensitive credential exposure, malicious plugin execution, and ultimately administrator takeover on affected systems.

SiYuan < v3.7.2 vulnerability rce authorization-bypass siyuan cve-2026-66012
5t 2i updated
critical advisory

WordPress SAML Single Sign On Plugin Authentication Bypass (CVE-2026-15981)

A critical authentication bypass vulnerability, CVE-2026-15981, affects the SAML Single Sign On - SSO Login plugin for WordPress (versions up to and including 5.4.4), allowing unauthenticated attackers to log in as any existing user, including administrators, by crafting a malformed SAMLResponse that misleads the plugin's signature validation logic.

PoC SAML Single Sign On – SSO Login plugin +2 authentication-bypass wordpress web-vulnerability cve-2026-15981
2t 1c 2i updated
high advisory

WPForms Pro Plugin Arbitrary File Upload Vulnerability Leading to RCE

The WPForms Pro plugin for WordPress, in versions up to and including 1.10.1.1, is vulnerable to arbitrary file upload via the ajax_chunk_upload_finalize function, allowing unauthenticated attackers to upload executable files due to improper file type validation occurring after file contents are written to disk, which can lead to remote code execution on the affected server.

WPForms Pro plugin for WordPress <= 1.10.1.1 +1 wordpress rce arbitrary-file-upload web-vulnerability
1r 2t 1i updated
critical advisory

Critical RCE Vulnerability in Blocksy Companion Pro WordPress Plugin (CVE-2026-58480)

An unauthenticated arbitrary file upload vulnerability (CVE-2026-58480) in Blocksy Companion Pro plugin for WordPress versions prior to 2.1.47 allows attackers to bypass extension validation via double-extension files, leading to remote code execution by forcing the web server to execute uploaded PHP files.

PoC Blocksy Companion Pro plugin < 2.1.47 +2 wordpress plugin rce file-upload web
1r 3t 2c 1i updated
high advisory

Code Injection Vulnerability in datamodel-code-generator (CVE-2026-63720)

CVE-2026-63720 details a code injection vulnerability in datamodel-code-generator versions prior to 0.70.0, allowing attackers to achieve remote code execution by providing a malicious `customBasePath` value within input schemas that is unsafely embedded into a Python import statement.

datamodel-code-generator < 0.70.0 code-injection rce vulnerability
1t 1c
high advisory

Fluent Forms Pro Add On Pack Vulnerable to PHP Object Injection (CVE-2026-15962)

An authenticated attacker with Subscriber-level access or higher can exploit a PHP Object Injection vulnerability in the Fluent Forms Pro Add On Pack plugin for WordPress, affecting versions up to and including 6.2.6. This deserialization of untrusted input, when combined with a POP chain, allows attackers to change user passwords and potentially achieve administrator account takeover. Exploitation is contingent on user update integration being enabled and a user meta field being mapped.

Fluent Forms Pro Add On Pack plugin <= 6.2.6 wordpress php-object-injection deserialization rce privilege-escalation
3t 1c
high advisory

GNU C Library iconv() Function Assertion Failure (CVE-2026-4046)

A vulnerability in the iconv() function of the GNU C Library (versions 2.43 and earlier) can cause a crash due to an assertion failure when handling IBM1390 or IBM1399 character sets, potentially leading to remote application denial-of-service.

The GNU C Library < 2.44 glibc iconv denial-of-service crash cve-2026-4046
2r 1t 3c updated
high advisory

Microweber CMS Path Traversal Vulnerability (CVE-2026-65694)

An unauthenticated path traversal vulnerability (CVE-2026-65694) in the static file controller of Microweber CMS, affecting versions through 2.0.20, allows remote attackers to read arbitrary files by supplying directory traversal sequences in the 'path' query parameter via a single unauthenticated HTTP GET request, potentially disclosing sensitive information like environment configuration files containing credentials or system files.

PoC Microweber CMS +1 web-vulnerability path-traversal cms webserver
1r 2t 1c 2i updated
high advisory

Multiple Out-of-Bounds Write Vulnerabilities in Rockwell Automation Arena

Multiple out-of-bounds write vulnerabilities (CVE-2026-8085, CVE-2026-8312, CVE-2026-8313, CVE-2026-8314) in Rockwell Automation Arena versions prior to V17.00.01 could allow an attacker to execute arbitrary code by convincing a user to open a malicious file.

Rockwell Automation Arena <=V17.00.00 +1 vulnerability ics ot memory-corruption out-of-bounds-write arbitrary-code-execution critical-manufacturing
1r 3t 4c updated
low advisory

AWS Smithy-RS HTTP Server Vulnerable to Unauthenticated Slowloris Denial of Service

An unauthenticated Slowloris denial of service vulnerability exists in the default `serve()` path of AWS's `aws-smithy-http-server` framework (versions <= 0.66.4), allowing remote attackers to exhaust server resources by initiating numerous incomplete connections.

aws-smithy-http-server denial-of-service vulnerability webserver rust aws
1t 1c
high advisory

etcd Watch API Authorization Bypass via Open-Ended Range Requests

An authorization bypass vulnerability (GHSA-xg4h-6gfc-h4m8) in etcd's Watch API allows an authenticated user with READ permission on a single key to exploit the `clientv3.WithFromKey()` function, gaining unauthorized access to monitor and receive events for all keys lexicographically greater than or equal to their permitted key in clusters with authentication enabled.

etcd +2 authorization-bypass rbac data-collection
3t
high advisory

AWS Bedrock AgentCore Python SDK Arbitrary Command Execution Vulnerability

An improper neutralization of argument delimiters vulnerability (CVE-2026-16796) in the AWS Bedrock AgentCore Python SDK's `install_packages()` method allows a remote authenticated user to execute arbitrary commands within the Code Interpreter sandbox by crafting malicious package name arguments.

bedrock-agentcore cloud vulnerability rce aws
1t 1c
medium advisory

etcd TLS Listener Denial of Service Vulnerability

A denial-of-service vulnerability in etcd's TLS listener allows a network attacker to exhaust server memory by spawning unbounded goroutines through multiple TCP connections without sending ClientHello messages, leading to loss of availability for etcd clusters and dependent services like Kubernetes.

etcd +2 denial-of-service kubernetes TLS
1t
high advisory

AWS API MCP Server Security Policy Bypass via Startup Initialization Failure (CVE-2026-16584)

The AWS API MCP Server has a high-severity vulnerability, CVE-2026-16584, where a failure to initialize security policy data at server startup leads to a silent bypass of all per-request policy checks, allowing AWS API operations to execute without the intended restrictions, though underlying IAM permissions remain enforced.

AWS API MCP Server vulnerability cloud aws security-bypass
1c
high advisory

Multiple High-Severity Vulnerabilities in OmniFaces Library

Multiple vulnerabilities in OmniFaces versions prior to 1.14.3, 2.7.33, 3.14.23, 4.7.12, and 5.4.2 allow attackers to exploit forged combined-resource IDs leading to server-side request forgery (SSRF)-like behavior or information disclosure, achieve client-side arbitrary code execution via cross-site scripting (XSS) in `o:hashParam`, bypass session authentication for push channels resulting in unauthorized message interception, and cause denial-of-service (DoS) via unbounded caches.

omnifaces +4 web-vulnerability ssrf xss dos java information-disclosure session-hijacking
6t 1c
medium advisory

py-libp2p yamux Connection DoS via Oversized Data Frame

A denial-of-service vulnerability in py-libp2p versions up to 0.6.0 allows an authenticated attacker to send a specially crafted 12-byte DATA or SYN frame with an oversized length field, causing the victim's yamux read loop to block indefinitely and freezing all streams on the affected connection.

py-libp2p denial-of-service vulnerability network python libp2p
1t
medium advisory

Unbounded WebSocket Message Aggregation Leads to Denial of Service in http4s-blaze-server

A vulnerability in `http4s-blaze-server` allows an attacker to cause a denial of service by exploiting unbounded WebSocket message aggregation, enabling an attacker to drive unbounded heap growth in the server's JVM by sending an unterminated fragmented WebSocket message, leading to an `OutOfMemoryError` and server termination, affecting any http4s application serving WebSocket routes over `BlazeServerBuilder` and triggerable by unauthenticated or authenticated clients.

http4s-blaze-server_2.13 +3 denial-of-service webserver jvm websocket
1t
high advisory

OpenList Path Traversal Vulnerability Allows Renaming Files Outside Authorized Paths

An authenticated user with rename permissions in OpenList/v4 is vulnerable to a path traversal flaw (GHSA-95cv-r8x4-vh75) in the `/api/fs/batch_rename` handler, allowing them to rename files outside their authorized base path and source directory by injecting traversal segments in the `src_name` parameter, leading to integrity violations and limited availability impact.

OpenList/v4 <= 4.2.3 path-traversal authenticated-bypass integrity-violation web-application
3t
high advisory

Multiple HTTP/1.1 Request Smuggling Primitives in Blaze Java Parser

Five independent HTTP/1.1 conformance laxities in Blaze's Java parser cause request-boundary disagreement with a stricter intermediary proxy, enabling front-end ACL/authentication bypass, response-queue poisoning on pooled backend connections, and cache poisoning in affected `http4s-blaze-server` and `blaze-http` components.

http4s-blaze-server_2.13 +2 request-smuggling http/1.1 java vulnerability
2t
high advisory

CVE-2025-71408 NLTK Eval Injection Vulnerability

An eval injection vulnerability exists in the nltk.collocations module of NLTK (Natural Language Toolkit) versions prior to 3.9.3, allowing an attacker to exploit this by controlling command-line arguments passed to collocations.py, which are then unsafely passed to eval() enabling remote code execution on the affected system.

NLTK eval-injection remote-code-execution python
1t 1c