September 2026 (30)
Insecure Deserialization in Cotonti Comments Plugin
1 TTP 1 CVECotonti version 1.0.0 contains an insecure deserialization vulnerability in the comments plugin allowing authenticated users to trigger object injection and potential remote code execution.
Arbitrary File Upload Vulnerability in WP Cloud Plugins for WordPress
1 rule 1 TTP 1 CVEMultiple WP Cloud Plugins for WordPress are vulnerable to arbitrary file upload via the download_file_to_uploads function, enabling remote code execution by authenticated attackers.
SQL Injection Vulnerability in IBM Platform RTM
1 TTP 1 CVEIBM Platform RTM contains a SQL injection vulnerability that allows a remote, unauthenticated attacker to execute arbitrary SQL statements against the backend database, leading to potential unauthorized data access, modification, or deletion.
Integer Overflow Vulnerability in IBM MQ Request Processing (CVE-2026-11725)
1 CVEAn integer overflow vulnerability in IBM MQ's processing of MQINQ requests allows an authenticated attacker to trigger a denial of service or potentially execute arbitrary code.
Path Traversal Vulnerability in Caucho Resin Documentation Webapp
1 rule 1 TTP 1 CVEA path traversal vulnerability (CVE-2017-20284) in the Caucho Resin documentation web application allows unauthenticated remote attackers to read arbitrary files via the inputFile parameter.
Remote Code Execution in LightLLM Config Server via Insecure Deserialization
3 TTPs 1 CVELightLLM versions 1.2.0 and earlier are vulnerable to unauthenticated remote code execution via the Config Server's /visual_register WebSocket endpoint due to insecure pickle deserialization.
Authenticated OS Command Injection in IBM Guardium Data Protection
1 CVEIBM Guardium Data Protection 12.2 contains an authenticated OS command injection vulnerability in the exportCertificate functionality that allows attackers to execute arbitrary system commands.
Unauthenticated SQL Injection in Chanjet CRM (CVE-2021-48008)
1 rule 1 TTP 1 CVEChanjet CRM contains an unauthenticated SQL injection vulnerability in the webservice endpoint, enabling remote attackers to extract sensitive data via the site_id parameter.
Unauthenticated SQL Injection in Weaver E-cology
1 rule 2 TTPs 1 CVEWeaver E-cology is vulnerable to an unauthenticated SQL injection via the 'userIdentifiers' GET parameter, allowing attackers to extract sensitive database information including administrator credentials.
Prototype Pollution Vulnerability in deepmerge
1 CVEThe deepmerge library up to version 4.3.1 contains a prototype pollution vulnerability in the mergeObject() function, allowing attackers to inject malicious properties into objects.
Denial of Service Vulnerability in CSSOM CSSStyleDeclaration.setProperty
1 CVEThe CSSOM library up to version 0.5.0 is vulnerable to a denial of service attack via malicious CSS declarations that trigger excessive memory allocation.
Denial of Service via Malicious Source Maps in source-map-js
1 CVEA vulnerability in source-map-js versions 1.2.1 and earlier allows unauthenticated attackers to trigger synchronous event loop blocking by supplying malformed indexed source maps containing extreme offset line values.
SQL Injection in Hongjing e-HR /servlet/codesettree
1 rule 1 TTP 1 CVEHongjing e-HR versions prior to 8.2 are vulnerable to unauthenticated SQL injection via the categories parameter in the /servlet/codesettree endpoint, allowing remote attackers to extract sensitive database content.
Cross-Site Scripting Vulnerability in Grafana Geomap MapLibre
1 CVEGrafana OSS versions 12.x and 13.x contain a cross-site scripting (XSS) vulnerability (CVE-2026-76154) in the Geomap MapLibre component that could allow attackers to execute malicious scripts in a user's session.
Unauthenticated Administrative Access in Semantic MediaWiki smwtask API
1 rule 1 TTPThe Semantic MediaWiki smwtask API module fails to enforce authorization, enabling unauthenticated remote attackers to perform sensitive information disclosure, queue administrative maintenance jobs, and manipulate stored semantic data.
Capsule Namespace and Service Metadata Enforcement Bypass
1 TTPA vulnerability in Capsule's metadata validation logic allows tenant owners to bypass configured forbidden labels and annotations, enabling unauthorized configuration changes to Kubernetes resources.
zot Registry Unauthorized Deletion via Bearer Token Scope Mismatch
1 CVEA logic flaw in zot registry's bearer authentication handler causes HTTP DELETE requests to be incorrectly mapped to the 'push' scope, allowing unauthorized deletion of image manifests and blobs by push-only clients.
ToolHive Containerized MCP Servers Vulnerable to Host Pivot and Lateral Movement
3 TTPs 1 CVEToolHive versions prior to 0.30.1 enable insecure container network defaults that allow MCP servers to reach host services via host.docker.internal, enabling unauthenticated lateral movement and host API exploitation.
Cross-Tenant IDOR in Convoy API Exposes Broker Credentials
2 TTPs 1 CVEConvoy versions up to and including 26.6.2 contain an Insecure Direct Object Reference (IDOR) vulnerability that allows authenticated users to leak plaintext message broker credentials from other tenants.
Denial of Service via Uncontrolled Memory Allocation in adm-zip
1 CVEThe adm-zip library is vulnerable to a denial of service (DoS) attack where a maliciously crafted ZIP archive forces excessive memory allocation by misrepresenting uncompressed file sizes.
SSRF Vulnerability in Obot via Remote MCP Server URLs
5 TTPsObot versions 0.22.1 and earlier are vulnerable to server-side request forgery (SSRF) allowing authenticated privileged users to probe internal network resources and cloud instance metadata services.
Eval Injection in XWiki Rendering XML
2 TTPs 1 CVEAn evaluation injection vulnerability in xwiki-rendering-xml allows authenticated users to achieve remote code execution by injecting script macros into HTML macro output.
Authentication Bypass and Privilege Escalation in kcp Front-Proxy
1 TTP 1 CVEThe kcp front-proxy fails to sanitize inbound X-Remote-* identity headers, allowing authenticated attackers to perform privilege escalation to system:masters and bypass multi-tenant authorization.
Mnemosyne Sync Server Authentication Bypass via JWT Signature Verification Failure
1 CVEA flaw in the Mnemosyne sync server's JWT implementation fails to verify HMAC-SHA256 signatures, allowing unauthenticated attackers to forge tokens and access or modify arbitrary user data.
Microsoft Dataverse Privilege Escalation Vulnerability
1 TTP 1 CVEA vulnerability in Microsoft Dataverse identified as CVE-2024-38064 allows a remote, unauthenticated attacker to escalate privileges and potentially gain administrative access to the service.
TraderTraitor Campaign Targeting DevOps Engineers via Weaponized Terraform Repositories
4 TTPs 5 IOCsNorth Korean threat actor TraderTraitor is using fake job interview lures on GitHub containing weaponized Terraform lock files to deliver macOS backdoors to DevOps engineers, facilitating cloud credential theft.
Chamilo LMS CStudio Unauthenticated Remote Code Execution
1 rule 2 TTPs 1 CVEAn unauthenticated remote code execution vulnerability in the Chamilo LMS CStudio upload flow allows attackers to gain server-level access by exploiting improper file handling (CVE-2026-45140).
Remote Denial of Service Vulnerability in Moxa TN-4500B Series
1 TTP 1 CVEA critical out-of-bounds write vulnerability (CVE-2026-15579) in Moxa TN-4500B Series switches allows remote, unauthenticated attackers to cause a denial-of-service condition.
AWS STS AssumeRole with New MFA Device
3 TTPsAdversaries may register new MFA devices for compromised AWS IAM roles to maintain persistence, escalate privileges, or facilitate lateral movement by assuming roles via the AWS Security Token Service (STS).
Suspicious Script Injection in AWS SageMaker Lifecycle Configurations
2 TTPsThreat actors are targeting AWS SageMaker notebook lifecycle configurations to achieve persistent, root-level code execution by injecting malicious scripts that trigger automatically upon instance startup.