Skip to content
Threat Feed

August 2026 (30)

critical advisory

Unauthenticated Remote Code Execution in Pix for WooCommerce

A critical vulnerability (CVE-2026-3891) in the Pix for WooCommerce WordPress plugin allows unauthenticated attackers to upload and execute arbitrary PHP files via vulnerable AJAX handlers.

Pix for WooCommerce wordpress rce cve-2026-3891
1r 2t 1c
critical advisory

Critical Prototype Pollution Vulnerability in Apollo Federation

CVE-2026-32621 is a critical prototype pollution vulnerability in Apollo Federation that allows unauthenticated attackers to manipulate application objects via malicious GraphQL queries.

Apollo Federation
1t 1c 1i
high advisory

Blind SQL Injection in Krayin CRM leads DataGrid

Krayin CRM versions prior to 2.2.4 contain a blind SQL injection vulnerability in the leads DataGrid, allowing authenticated attackers to exfiltrate database contents via the rotten_lead[in] query parameter.

Krayin CRM sqli vulnerability web-application
1r 1t 1c
high advisory

Arbitrary Code Execution in Ghidra Swift Demangler

An arbitrary code execution vulnerability in the Ghidra Swift demangler analyzer allows attackers to execute arbitrary binaries by manipulating the Swift tool directory path within a project file.

Ghidra
1t 1c
high advisory

Remote Stack-Based Buffer Overflow in Wavlink Networking Devices

Multiple Wavlink networking devices are vulnerable to a remote stack-based buffer overflow in the lighttpd component due to insecure use of strcpy in the upload.cgi script via the HTTP_COOKIE header.

WN572 +10 vulnerability rce network-infrastructure
1t 1c 1i
high advisory

Privilege Escalation in Razer RzUpdateService

A local privilege escalation vulnerability in Razer RzUpdateService version 1.10.14.0 allows local attackers to manipulate the Named Pipe Handler to gain unauthorized privileges.

RzUpdateService privilege-escalation windows vulnerability
1t 1c
high advisory

Local Privilege Escalation in CheckMAL AppCheck Pro via Kernel Driver

A local privilege escalation vulnerability in the AppCheckD.sys driver of CheckMAL AppCheck Pro version 3.1.43.10 allows attackers to perform uncontrolled search path manipulation.

AppCheck Pro privilege-escalation windows kernel-driver
1t 1c
critical advisory

Krayin CRM Installer Authentication Bypass Vulnerability

Krayin CRM 2.2.4 contains a missing authentication vulnerability in the installer middleware, allowing unauthenticated remote attackers to overwrite the administrator account via crafted HTTP POST requests.

Krayin CRM vulnerability crm authentication-bypass
1r 1t 1c
high advisory

Cross-Site Scripting Vulnerability in Angular Server-Side Rendering

A Cross-Site Scripting (XSS) vulnerability in @angular/platform-server (CVE-2026-69149) allows script injection via improper serialization of fallback raw-content elements during server-side rendering.

platform-server +3 xss web-vulnerability angular
1t 1c
medium advisory

Multiple Vulnerabilities in PaperCut NG/MF

Multiple vulnerabilities, including CVE-2026-8793 and CVE-2026-8794, affect PaperCut NG/MF versions prior to 26.0.3, potentially allowing for data confidentiality breaches and security policy bypass.

PaperCut NG +1
2c
low advisory

Detection of Unusual File Creation by Web Server Processes on Linux

This brief details a behavioral detection strategy for identifying potential web shell deployment and persistence mechanisms by monitoring anomalous file creation activities originating from common web server processes on Linux.

nginx +44 persistence web-shell linux behavioral-detection
1r 4t updated
medium advisory

Detection of Destructive NFS File Operations

Detection logic identifies ransomware-like activity on NFS shares by flagging high-frequency bursts of successful WRITE, REMOVE, and RENAME operations from a single client within a one-minute window.

impact nfs ransomware network-security detection-engineering
2t
low advisory

Detection of SSH Reverse Port Forwarding on Windows

Adversaries are abusing native Windows OpenSSH and Plink binaries to establish unauthorized reverse SSH tunnels, bypassing inbound connectivity controls for C2 and lateral movement.

OpenSSH +1 command-and-control lateral-movement proxy tunneling windows
1r 3t
low advisory

Detection of Suspicious Base64 Decoding Activity on Linux

This detection brief monitors Linux hosts for the use of standard system utilities and scripting interpreters to decode Base64 data, a common technique employed by adversaries to obfuscate malicious payloads and command-and-control traffic.

Elastic Defend defense-evasion execution linux detection
2t
high advisory

OS Command Injection in Telenia Software TVox

Telenia Software TVox contains an OS command injection vulnerability in action_audio.php that allows authenticated attackers to execute arbitrary system commands as the apache user.

TVox +1 privilege-escalation linux cve-2026-67609
1r 3t 1c
high advisory

CVE-2026-69096: OS Command Injection in OpenWrt luci-app-dockerman

An authenticated OS command injection vulnerability in the docker_rpc.uc backend of luci-app-dockerman allows attackers with read-only ACLs to execute arbitrary commands as root via the /ubus RPC endpoint.

luci-app-dockerman
2t 1c
high advisory

Authentication Bypass Vulnerability in Admidio Forum Module

Admidio versions prior to 5.0.11 contain an authentication bypass vulnerability in the forum module, allowing unauthenticated remote attackers to access sensitive forum content.

Admidio
1r 1t 1c
high advisory

Path Traversal Vulnerability in Grav CMS ImageMedium Class

Grav CMS 2.0.10 is vulnerable to path traversal in the ImageMedium::watermark() method, allowing unauthenticated attackers to disclose arbitrary image files by traversing outside the media sandbox.

Grav CMS
1r 1t 1c
high advisory

Arbitrary Static Method Execution in Grav CMS

Grav CMS versions 2.0.7 through 2.0.10 allow authenticated users with page-editing permissions to trigger arbitrary public static method calls via malicious blueprint directives, leading to unauthorized file read and write operations.

Grav CMS cms rce file-read web-application
2t 1c
critical advisory

SQL Injection in SiYuan fullTextSearchAssetContent Endpoint

SiYuan versions before 3.7.3 contain a critical SQL injection vulnerability in the fullTextSearchAssetContent endpoint, allowing unauthenticated attackers to execute arbitrary SQL commands on the backend asset-content database.

SiYuan sql-injection web-vulnerability path-traversal cve-2026-69086 web-application
3r 2t 1c
high advisory

Authentication Bypass Vulnerability in SiYuan Publish Mode

SiYuan versions before 3.7.3 contain an authentication bypass vulnerability allowing unauthenticated attackers to retrieve content from password-protected documents.

SiYuan
2t 1c
high advisory

Deserialization Vulnerability in eta-otp-lock

An insecure deserialization vulnerability in TUBITAK BILGEM eta-otp-lock (CVE-2026-18642) allows unauthenticated attackers to perform object injection, potentially leading to remote code execution.

eta-otp-lock
1t 1c
high advisory

Remote Code Execution and Arbitrary File Read in Ruby on Rails Active Storage

A vulnerability (CVE-2026-66066) in Ruby on Rails Active Storage allows unauthenticated attackers to achieve arbitrary file read and remote code execution during the variant processing phase.

PoC Active Storage +10
1c 1i updated
critical advisory

Critical Pre-Authentication RCE in Gitea and Forgejo

CVE-2026-60004 is a critical pre-authentication RCE vulnerability in Gitea and Forgejo platforms caused by an unsafe bare clone design in the diffpatch API endpoint, enabling arbitrary command execution via injected Git hooks.

Gitea +1 remote-code-execution git vulnerability forgejo
1r 3t
high advisory

Linux Kernel posix-cpu-timers Use-After-Free Vulnerability

A use-after-free vulnerability in the Linux kernel posix-cpu-timers subsystem, identified as CVE-2026-64560, allows attackers to trigger kernel memory corruption via a race condition during non-leader thread exec() calls.

Linux Kernel +1 vulnerability linux-kernel cve uaf
1t 1c 1i
critical advisory

Authorization Bypass Vulnerability in Menulux Mobile App

CVE-2026-2346 is a critical authorization bypass vulnerability (CWE-639) in the Menulux Mobile App allowing unauthenticated attackers to manipulate user-controlled keys and compromise software integrity.

Mobile App
1t 1c
medium advisory

Apache HttpComponents Denial of Service Vulnerability

A vulnerability in Apache HttpComponents allows a remote, unauthenticated attacker to trigger a Denial of Service condition on targeted applications.

HttpComponents
1t
medium threat

Denial of Service Vulnerability in Red Hat Multicluster Engine for Kubernetes

A vulnerability in Red Hat Multicluster Engine for Kubernetes allows an unauthenticated remote attacker to trigger a denial of service condition by exploiting a software flaw.

exploited multicluster engine for Kubernetes denial-of-service kubernetes cloud-native vulnerability
1t
high advisory

Multiple Vulnerabilities in Red Hat Ansible Automation Platform

Multiple vulnerabilities in Red Hat Ansible Automation Platform allow a remote, unauthenticated attacker to achieve remote code execution or manipulate information displayed by the platform.

Ansible Automation Platform vulnerability remote-code-execution enterprise-automation
2t
high advisory

Multiple Vulnerabilities in cPanel/WHM

Multiple vulnerabilities in cPanel/WHM allow remote attackers to manipulate files and escalate privileges, potentially leading to arbitrary code execution with administrative rights.

cPanel/WHM vulnerability cpanel web-hosting
2t