Skip to content
Threat Feed

September 2026 (30)

high advisory

Insecure Deserialization in Cotonti Comments Plugin

Cotonti version 1.0.0 contains an insecure deserialization vulnerability in the comments plugin allowing authenticated users to trigger object injection and potential remote code execution.

Cotonti web-application deserialization vulnerability
1t 1c
high advisory

Arbitrary File Upload Vulnerability in WP Cloud Plugins for WordPress

Multiple WP Cloud Plugins for WordPress are vulnerable to arbitrary file upload via the download_file_to_uploads function, enabling remote code execution by authenticated attackers.

Use-your-Drive +3 web-application wordpress cve-2026-93031 rce
1r 1t 1c
high advisory

SQL Injection Vulnerability in IBM Platform RTM

IBM Platform RTM contains a SQL injection vulnerability that allows a remote, unauthenticated attacker to execute arbitrary SQL statements against the backend database, leading to potential unauthorized data access, modification, or deletion.

Platform RTM
1t 1c
high advisory

Integer Overflow Vulnerability in IBM MQ Request Processing (CVE-2026-11725)

An integer overflow vulnerability in IBM MQ's processing of MQINQ requests allows an authenticated attacker to trigger a denial of service or potentially execute arbitrary code.

MQ vulnerability remote-code-execution ibm-mq
1c
high threat

Path Traversal Vulnerability in Caucho Resin Documentation Webapp

A path traversal vulnerability (CVE-2017-20284) in the Caucho Resin documentation web application allows unauthenticated remote attackers to read arbitrary files via the inputFile parameter.

exploited Resin path-traversal web-security
1r 1t 1c
critical advisory

Remote Code Execution in LightLLM Config Server via Insecure Deserialization

LightLLM versions 1.2.0 and earlier are vulnerable to unauthenticated remote code execution via the Config Server's /visual_register WebSocket endpoint due to insecure pickle deserialization.

LightLLM
3t 1c updated
critical advisory

Authenticated OS Command Injection in IBM Guardium Data Protection

IBM Guardium Data Protection 12.2 contains an authenticated OS command injection vulnerability in the exportCertificate functionality that allows attackers to execute arbitrary system commands.

1c
high advisory

Unauthenticated SQL Injection in Chanjet CRM (CVE-2021-48008)

Chanjet CRM contains an unauthenticated SQL injection vulnerability in the webservice endpoint, enabling remote attackers to extract sensitive data via the site_id parameter.

CRM web-application-vulnerability sql-injection cve-2021-48008
1r 1t 1c
high threat

Unauthenticated SQL Injection in Weaver E-cology

Weaver E-cology is vulnerable to an unauthenticated SQL injection via the 'userIdentifiers' GET parameter, allowing attackers to extract sensitive database information including administrator credentials.

E-cology web-application-vulnerability sqli remote-execution
1r 2t 1c
high advisory

Prototype Pollution Vulnerability in deepmerge

The deepmerge library up to version 4.3.1 contains a prototype pollution vulnerability in the mergeObject() function, allowing attackers to inject malicious properties into objects.

deepmerge
1c
low advisory

Denial of Service Vulnerability in CSSOM CSSStyleDeclaration.setProperty

The CSSOM library up to version 0.5.0 is vulnerable to a denial of service attack via malicious CSS declarations that trigger excessive memory allocation.

CSSOM
1c
low advisory

Denial of Service via Malicious Source Maps in source-map-js

A vulnerability in source-map-js versions 1.2.1 and earlier allows unauthenticated attackers to trigger synchronous event loop blocking by supplying malformed indexed source maps containing extreme offset line values.

denial-of-service web-application supply-chain
1c
critical threat

SQL Injection in Hongjing e-HR /servlet/codesettree

Hongjing e-HR versions prior to 8.2 are vulnerable to unauthenticated SQL injection via the categories parameter in the /servlet/codesettree endpoint, allowing remote attackers to extract sensitive database content.

exploited e-HR web-application injection vurnerability
1r 1t 1c
high advisory

Cross-Site Scripting Vulnerability in Grafana Geomap MapLibre

Grafana OSS versions 12.x and 13.x contain a cross-site scripting (XSS) vulnerability (CVE-2026-76154) in the Geomap MapLibre component that could allow attackers to execute malicious scripts in a user's session.

Grafana OSS web-application xss security-advisory
1c
high threat

Unauthenticated Administrative Access in Semantic MediaWiki smwtask API

The Semantic MediaWiki smwtask API module fails to enforce authorization, enabling unauthenticated remote attackers to perform sensitive information disclosure, queue administrative maintenance jobs, and manipulate stored semantic data.

exploited Semantic MediaWiki +1 api-security broken-access-control webserver web-security xss cms
1r 1t
medium threat

Capsule Namespace and Service Metadata Enforcement Bypass

A vulnerability in Capsule's metadata validation logic allows tenant owners to bypass configured forbidden labels and annotations, enabling unauthorized configuration changes to Kubernetes resources.

Capsule Individual Tenant kubernetes misconfiguration privilege-escalation validation-bypass
1t
high advisory

zot Registry Unauthorized Deletion via Bearer Token Scope Mismatch

A logic flaw in zot registry's bearer authentication handler causes HTTP DELETE requests to be incorrectly mapped to the 'push' scope, allowing unauthorized deletion of image manifests and blobs by push-only clients.

1c
high threat

ToolHive Containerized MCP Servers Vulnerable to Host Pivot and Lateral Movement

ToolHive versions prior to 0.30.1 enable insecure container network defaults that allow MCP servers to reach host services via host.docker.internal, enabling unauthenticated lateral movement and host API exploitation.

exploited ToolHive container-security mcp lateral-movement cve-2026-58197
3t 1c
high advisory

Cross-Tenant IDOR in Convoy API Exposes Broker Credentials

Convoy versions up to and including 26.6.2 contain an Insecure Direct Object Reference (IDOR) vulnerability that allows authenticated users to leak plaintext message broker credentials from other tenants.

convoy idor credential-leak api-security
2t 1c
low advisory

Denial of Service via Uncontrolled Memory Allocation in adm-zip

The adm-zip library is vulnerable to a denial of service (DoS) attack where a maliciously crafted ZIP archive forces excessive memory allocation by misrepresenting uncompressed file sizes.

1c
high advisory

SSRF Vulnerability in Obot via Remote MCP Server URLs

Obot versions 0.22.1 and earlier are vulnerable to server-side request forgery (SSRF) allowing authenticated privileged users to probe internal network resources and cloud instance metadata services.

Obot +1 ssrf cloud-security vulnerability oauth authentication-bypass token-theft mcp
5t
critical advisory

Eval Injection in XWiki Rendering XML

An evaluation injection vulnerability in xwiki-rendering-xml allows authenticated users to achieve remote code execution by injecting script macros into HTML macro output.

xwiki-rendering-xml injection rce web-vulnerability
2t 1c
critical advisory

Authentication Bypass and Privilege Escalation in kcp Front-Proxy

The kcp front-proxy fails to sanitize inbound X-Remote-* identity headers, allowing authenticated attackers to perform privilege escalation to system:masters and bypass multi-tenant authorization.

kcp
1t 1c
critical advisory

Mnemosyne Sync Server Authentication Bypass via JWT Signature Verification Failure

A flaw in the Mnemosyne sync server's JWT implementation fails to verify HMAC-SHA256 signatures, allowing unauthenticated attackers to forge tokens and access or modify arbitrary user data.

1c
high advisory

Microsoft Dataverse Privilege Escalation Vulnerability

A vulnerability in Microsoft Dataverse identified as CVE-2024-38064 allows a remote, unauthenticated attacker to escalate privileges and potentially gain administrative access to the service.

Dataverse privilege-escalation cloud-security vulnerability high-confidence-source
1t 1c
high threat

TraderTraitor Campaign Targeting DevOps Engineers via Weaponized Terraform Repositories

North Korean threat actor TraderTraitor is using fake job interview lures on GitHub containing weaponized Terraform lock files to deliver macOS backdoors to DevOps engineers, facilitating cloud credential theft.

Terraform TraderTraitor macos supply-chain social-engineering cloud-security devops
4t 5i
critical advisory

Chamilo LMS CStudio Unauthenticated Remote Code Execution

An unauthenticated remote code execution vulnerability in the Chamilo LMS CStudio upload flow allows attackers to gain server-level access by exploiting improper file handling (CVE-2026-45140).

PoC Chamilo LMS remote-code-execution web-application critical-vulnerability
1r 2t 1c updated
medium advisory

Remote Denial of Service Vulnerability in Moxa TN-4500B Series

A critical out-of-bounds write vulnerability (CVE-2026-15579) in Moxa TN-4500B Series switches allows remote, unauthenticated attackers to cause a denial-of-service condition.

TN-4500B Series vulnerability industrial-control-systems denial-of-service network-device
1t 1c
low advisory

AWS STS AssumeRole with New MFA Device

Adversaries may register new MFA devices for compromised AWS IAM roles to maintain persistence, escalate privileges, or facilitate lateral movement by assuming roles via the AWS Security Token Service (STS).

AWS Security Token Service +1 cloud aws persistence identity-audit
3t
high advisory

Suspicious Script Injection in AWS SageMaker Lifecycle Configurations

Threat actors are targeting AWS SageMaker notebook lifecycle configurations to achieve persistent, root-level code execution by injecting malicious scripts that trigger automatically upon instance startup.

SageMaker cloud aws persistence execution
2t