Skip to content
Threat Feed

July 2026 (30)

high advisory

CVE-2026-65898: DOMPurify Vulnerability Leads to Stored Cross-Site Scripting

A vulnerability in DOMPurify before version 3.4.11 allows attackers to achieve stored Cross-Site Scripting (XSS) by manipulating the `ALLOWED_ATTR` allowlist through an `uponSanitizeAttribute` hook, leading to client-side code execution.

DOMPurify xss javascript web-vulnerability client-side
2t 1c 2i
high advisory

Bold Reports Standalone Report Designer Path Traversal to RCE Vulnerability

A missing filepath validation vulnerability (CVE-2026-65690) in Bold Reports Standalone Report Designer before version 14.1.12 allows authenticated attackers to perform path traversal via crafted filenames during file upload, leading to arbitrary command execution with high privileges.

Standalone Report Designer vulnerability path-traversal rce web-application
1r 1t 1c 2i
critical advisory

CVE-2026-65689: Bold Reports Standalone Report Designer Path Traversal Vulnerability

A missing filepath validation vulnerability (CVE-2026-65689) in Bold Reports Standalone Report Designer before version 14.1.12 allows unauthenticated attackers to perform path traversal by sending a crafted request to the database download feature, enabling them to read arbitrary sensitive server files, including authentication credentials, and potentially gain full unauthorized access to the application.

Standalone Report Designer path-traversal vulnerability web-application arbitrary-file-read cve
1r 1t 1c
critical advisory

Bold Reports Standalone Report Designer Path Traversal Vulnerability (CVE-2026-65687)

CVE-2026-65687 describes a path traversal vulnerability in Bold Reports Standalone Report Designer prior to version 14.1.12, allowing an unauthenticated attacker to read arbitrary files from the server filesystem by exploiting a missing filepath validation flaw in the SVG processing feature, potentially leading to full unauthorized access via disclosure of sensitive server files like authentication credentials.

Bold Reports Standalone Report Designer +1 path-traversal arbitrary-file-read web-vulnerability critical-vulnerability
1r 2t 2c
high threat

FrostyNeighbor Targets Ukraine with Updated PicassoLoader Chain

The FrostyNeighbor threat actor is targeting Ukrainian governmental organizations with spearphishing emails containing malicious PDFs that deliver a JavaScript dropper (PicassoLoader) and ultimately a Cobalt Strike beacon.

PoC Cobalt Strike +8 FrostyNeighbor cyberespionage cobaltstrike picassoloader ukraine
2r 3t 5c 16i updated
high advisory

Grav API Plugin Privilege Escalation via Invitation Group Manipulation (CVE-2026-65897)

An authenticated attacker can exploit CVE-2026-65897 in Grav API Plugin versions prior to 1.0.10 by manipulating the 'groups' field during invitation creation, allowing invited accounts to gain super-admin API access, leading to privilege escalation.

Grav API Plugin privilege-escalation vulnerability
1t 1c 4i
high advisory

Grav API Plugin Path Traversal Vulnerability (CVE-2026-65896)

An authenticated API caller with 'api.pages.write' permission in Grav API Plugin (Composer package getgrav/grav-plugin-api) before version 1.0.10 can exploit a path traversal vulnerability (CVE-2026-65896). The 'POST /pages/{route}/move' endpoint's 'slug' field is not properly sanitized, allowing attackers to use path traversal sequences (e.g., '01.home/../../../pwned'). This enables them to move an entire page directory, including content and media, to an arbitrary writable location outside the intended 'user/pages/' directory, potentially leading to unauthorized file manipulation or system compromise.

Grav API Plugin path-traversal web-application vulnerability
3t 1c
high advisory

Grav API Plugin Missing Authorization Allows Security Settings Modification

Grav API Plugin versions prior to 1.0.10 contain a missing authorization vulnerability (CVE-2026-65895) allowing authenticated users with the 'api.config.write' privilege to modify critical security settings, including disabling site-wide rate limiting to enable credential brute-forcing attacks and reconfiguring CORS policies to include attacker-controlled origins with credentials enabled, potentially leading to unauthorized data access.

Grav API Plugin grav-cms api-plugin vulnerability access-control cwe-862
1t 1c
critical advisory

CVE-2026-65606 - SiYuan XSS to RCE Vulnerability

A critical cross-site scripting (XSS) vulnerability, CVE-2026-65606, exists in SiYuan desktop application versions prior to 3.7.2's `siyuan://` protocol handler, allowing an attacker to inject an unescaped `<img>` element into the tab header, leading to arbitrary JavaScript execution and ultimately operating system command execution due to `nodeIntegration:true`.

SiYuan xss rce desktop-application vulnerability cve
2t 1c
critical advisory

CVE-2026-63766: Unauthenticated OS Command Injection in GPT-SoVITS webui.py

An unauthenticated OS command injection vulnerability (CVE-2026-63766) in GPT-SoVITS through version 20250606v2pro's webui.py allows attackers to execute arbitrary operating system commands via shell metacharacters in Gradio textbox inputs, leading to remote code execution.

PoC GPT-SoVITS through 20250606v2pro +1 command-injection rce web-vulnerability ai/ml-model cve
1r 2t 1c 2i updated
medium advisory

Exim: Multiple Vulnerabilities Allow Local Command Execution and Privilege Escalation

Multiple vulnerabilities in Exim allow a local attacker to execute arbitrary commands and escalate privileges on the affected system, enabling a local adversary to gain higher control over the mail transfer agent and potentially the underlying operating system.

Exim vulnerability privilege-escalation command-execution
2t
high advisory

Multiple Vulnerabilities in Mitel Products Allow Remote Code Execution and XSS

Multiple vulnerabilities have been discovered in Mitel MiCollab and Openscape UC products, enabling a remote attacker to achieve arbitrary code execution and conduct indirect remote code injection (XSS), posing significant risks to affected organizations.

MiCollab versions 10.2.x antérieures à 10.2 SP1 FP2 +4 vulnerability rce xss mitel
3t 2i
low advisory

CVE-2026-64611: libcupsfilters Denial of Service via Malformed Printer Advertisement

A high-severity denial of service vulnerability, CVE-2026-64611, exists in the `cfIEEE1284NormalizeMakeModel()` function of libcupsfilters, allowing a network-adjacent attacker to cause sustained CPU consumption and system unresponsiveness by broadcasting a specially crafted printer advertisement with an empty model field in the IEEE-1284 device ID.

libcupsfilters +5 vulnerability denial-of-service linux printer-vulnerability
1t 1c
high advisory

CVE-2026-16745: Authentication Bypass in Red Hat OpenShift AI odh-dashboard

A critical vulnerability, CVE-2026-16745, exists in the odh-dashboard web console component of Red Hat OpenShift AI (RHOAI), allowing a malicious actor within the cluster to bypass authentication by providing an arbitrary access token, leading to user impersonation and unauthorized access to the Kubernetes API, potentially resulting in arbitrary code execution, privilege escalation, and information disclosure.

odh-dashboard +1 cloud-security kubernetes authentication-bypass privilege-escalation arbitrary-code-execution red-hat
4t 1c
high threat

Multiple Vulnerabilities in n8n Workflow Automation Platform

An attacker can exploit multiple vulnerabilities in the n8n workflow automation platform to bypass security measures, perform a Denial of Service attack, disclose sensitive information, manipulate files, conduct SQL injection, and execute arbitrary code.

n8n vulnerability rce sql-injection denial-of-service data-exfiltration defense-evasion
5t
critical advisory

Mitel MiCollab Vulnerability Allows Remote Code Execution

A critical vulnerability in Mitel MiCollab allows a remote, unauthenticated attacker to execute arbitrary code, which could lead to full system compromise or further network penetration.

MiCollab vulnerability rce network
1t
high threat

Multiple Vulnerabilities Affect MongoDB

Multiple vulnerabilities in MongoDB allow an attacker to execute arbitrary code, bypass security measures, disclose confidential information, manipulate data, cause memory corruption, or trigger a denial-of-service condition.

exploited MongoDB vulnerability code-execution data-exfiltration denial-of-service data-manipulation
5t
high threat

Mitel OpenScape Cross-Site Scripting Vulnerability

A remote, authenticated attacker can exploit a Cross-Site Scripting (XSS) vulnerability in Mitel OpenScape, allowing the execution of malicious scripts in the victim's browser, potentially leading to session hijacking, data theft, or redirection to malicious websites.

OpenScape Authenticated Attacker cross-site-scripting vulnerability web-application
1r 1t
medium advisory

Internet Systems Consortium BIND: Multiple Vulnerabilities

Multiple vulnerabilities in Internet Systems Consortium BIND allow an anonymous, remote attacker to bypass security measures, manipulate data, disclose confidential information, or trigger a Denial-of-Service condition, potentially leading to compromise of data integrity, confidentiality, and availability of the DNS service.

BIND dns vulnerability denial-of-service data-manipulation information-disclosure network-infrastructure
3t
high advisory

WordPress MDJM Event Management Plugin Privilege Escalation (CVE-2026-15017)

An unauthenticated privilege escalation vulnerability (CVE-2026-15017) in the MDJM Event Management plugin for WordPress, affecting all versions up to 1.7.8.4, allows attackers to grant arbitrary MDJM capabilities to any registered WordPress role due to missing capability checks and nonce verification, ultimately enabling a low-privilege user to escalate to Administrator.

MDJM Event Management plugin <= 1.7.8.4 +1 wordpress plugin privilege-escalation cve web-application
2t 1c
critical advisory

MountDev AI MCP Connector WordPress Plugin Vulnerability Allows Unauthenticated Admin Access (CVE-2026-15015)

An authorization bypass vulnerability, CVE-2026-15015, in all versions up to 1.6.1 of the MountDev AI MCP Connector for WordPress plugin allows unauthenticated attackers to obtain an administrator-bound OAuth Bearer token by exploiting publicly accessible client registration and an unprotected authorization endpoint, granting full administrator-equivalent access to the plugin's tool surface and WordPress content.

MountDev AI MCP Connector for WordPress plugin <= 1.6.1 +1 wordpress authorization-bypass cve webserver privilege-escalation
1r 2t 1c
critical advisory

Critical Code Injection Vulnerability in WordPress Customer Support Ticket System & Helpdesk Plugin (CVE-2026-15011)

A critical code injection vulnerability, CVE-2026-15011, affects the Customer Support Ticket System & Helpdesk plugin for WordPress versions up to and including 6.0.5, allowing unauthenticated attackers to invoke arbitrary parameterless PHP functions via the 'path' parameter, potentially disrupting site functionality or exposing sensitive information without prior authentication.

Customer Support Ticket System & Helpdesk plugin for WordPress <= 6.0.5 code-injection wordpress web-application plugin-vulnerability php
1t 1c
critical advisory

GoDAM WordPress Plugin Arbitrary File Upload Vulnerability (CVE-2026-14282)

An arbitrary file upload vulnerability exists in the GoDAM WordPress plugin versions up to and including 1.12.2 due to insufficient file type validation in the `save_video_file()` function, allowing unauthenticated attackers to upload arbitrary files to the server and potentially achieve remote code execution.

GoDAM - Organize WordPress Media Library & File Manager with Unlimited Folders for Images, Vid... <= 1.12.2 wordpress arbitrary-file-upload remote-code-execution web-exploitation
1r 2t 1c
medium threat

Intel Ethernet Products: Multiple Vulnerabilities

Multiple vulnerabilities exist in various Intel Ethernet products, which an attacker can exploit to trigger a denial-of-service condition and expose confidential information.

exploited Intel Ethernet Products vulnerability intel network-device dos information-disclosure
2t
high threat

OS Command Injection Vulnerability in Pardus-Update (CVE-2026-16287)

A high-severity OS command injection vulnerability, tracked as CVE-2026-16287, has been identified in the TUBITAK BILGEM Software Technologies Research Institute's pardus-update software, affecting versions from 0.6.6 before 0.7.0, enabling attackers to execute arbitrary operating system commands due to improper neutralization of special elements.

exploited pardus-update os-command-injection vulnerability linux
1t 1c 1i
high advisory

CVE-2026-9713: Lumise Product Designer for WooCommerce Plugin SQL Injection

The Lumise Product Designer for WooCommerce plugin for WordPress, in versions up to and including 2.1.1, is vulnerable to SQL Injection via the 'id' and 'table' parameters within an uploaded cart JSON file processed by the checkout AJAX action, allowing unauthenticated attackers to extract sensitive database information.

Lumise Product Designer for WooCommerce wordpress woocommerce sql-injection web-vulnerability cve
1r 2t 1c
high advisory

ARforms WordPress Plugin Vulnerable to Stored Cross-Site Scripting via 'password' Field (CVE-2026-12421)

An insufficient input sanitization and output escaping vulnerability (CVE-2026-12421) in the ARforms plugin for WordPress, affecting versions up to and including 7.2.1, allows unauthenticated attackers to inject arbitrary web scripts via the 'password' field, leading to Stored Cross-Site Scripting (XSS) when a user accesses an injected page.

ARforms wordpress xss plugin web-application vulnerability
2t 1c
critical threat

Check Point SmartConsole Authentication Bypass (CVE-2026-16232) Actively Exploited

Check Point released a critical security advisory to address CVE-2026-16232, an authentication bypass vulnerability in SmartConsole, which is actively being exploited in the wild and affects Security Management, Multi-Domain Management, Firewall, and Multi-Domain Log Server products.

exploited PoC SmartConsole +9 cve vulnerability authentication-bypass checkpoint
1t 4c 6i updated
low advisory

CoreDNS CVE-2026-62994 Denial of Service Vulnerability

A vulnerability in CoreDNS, specifically within the `k8s_external` plugin, allows for a denial of service when performing a headless AXFR, as the `k8s_external` plugin can emit an empty transfer batch, which subsequently causes the `transfer` plugin to panic.

CoreDNS denial-of-service kubernetes cve
1c
medium advisory

Excon Redirection Vulnerability (CVE-2026-54171)

A vulnerability, CVE-2026-54171, has been identified in the Excon library concerning the redaction of sensitive or risky headers when following redirects, which could potentially expose confidential information if not properly addressed.

Excon vulnerability information-disclosure library
1c