Skip to content
Threat Feed

July 2026 (30)

critical advisory

Ninja Forms Plugin Vulnerability Allows Network-Wide Data Deletion in WordPress Multisite

A critical privilege escalation vulnerability, CVE-2026-65049, in the Ninja Forms plugin (version 3.14.8 and prior) for WordPress Multisite allows a subsite Administrator to trigger network-wide deletion of all Ninja Forms data by exploiting an incorrect authorization check combined with unsafe multisite migration defaults, leading to severe data loss.

Ninja Forms plugin +1 wordpress plugin privilege-escalation data-deletion webserver cve
1r 2t 1c
critical advisory

Critical Unauthenticated Stored XSS in Ninja Forms WordPress Plugin (CVE-2026-65048)

A critical unauthenticated stored cross-site scripting (XSS) vulnerability (CVE-2026-65048) in the Ninja Forms plugin for WordPress allows attackers to inject malicious script payloads via crafted form submissions, leading to session-cookie theft, administrator account creation, and arbitrary content modification when an administrator views the submission.

Ninja Forms plugin 3.10.4-3.14.9 wordpress xss plugin web-application cve
1r 6t 1c
high advisory

CVE-2026-16327: D-Link DNS-320 Unrestricted File Upload Vulnerability

A high-severity unrestricted file upload vulnerability (CVE-2026-16327) in D-Link DNS-320 firmware version 1.0.2 allows remote attackers to upload arbitrary files, potentially leading to remote code execution and full device compromise, with exploit code publicly disclosed.

DNS-320 1.0.2 web-vulnerability remote-code-execution file-upload d-link unrestricted-file-upload nas vulnerability unrestricted-upload +2
4r 4t 2i updated
high advisory

CVE-2026-16445: Dracut Command Injection via Malicious DHCP Options

A command injection vulnerability exists in dracut's NetworkManager-based initrd network module that allows a remote attacker on an adjacent network to achieve root code execution within the initramfs during system boot by providing specially crafted DHCP options without proper escaping.

dracut command-injection initramfs dhcp linux cve
1t 1c
high advisory

Midyear Assessment of Iran-Linked Cyber Threat Landscape

SentinelOne Labs' midyear assessment highlights that Iran-linked cyber operations, involving groups like MuddyWater/Seedworm, Screening Serpens, APT42, and persona groups such as Handala, focus on persistent access, espionage, and selective disruption, often leveraging social engineering, compromised service providers, and RMM abuse, with increasing risk to operational technology environments.

iran espionage destructive-malware social-engineering operational-technology rmm supply-chain threat-assessment +1
12t
critical advisory

AI Agent Frameworks Vulnerable to RCE via Prompt Injection

AI agents using frameworks like Microsoft's Semantic Kernel are vulnerable to remote code execution (RCE) via prompt injection by manipulating plugin parameters due to unsafe data handling.

PoC Semantic Kernel +7 ai prompt-injection rce semantic-kernel
2r 1t 2c 2i updated
critical advisory

Grav API Plugin Authorization Bypass Leads to Account Takeover (CVE-2026-65007)

The Grav api plugin (grav-plugin-api) versions prior to 1.0.8 contain an authorization bypass vulnerability where the plugin intercepts API key generation and revocation tasks before proper ACL checks, allowing any user with the baseline admin.login permission to generate or revoke API keys for any account, enabling impersonation, privilege escalation, and potential account takeover.

grav-plugin-api authorization-bypass privilege-escalation account-takeover cms
3t 1c
critical advisory

Critical SQL Injection Vulnerability in Turkhotspot 5651 Loglama (CVE-2026-1617)

A critical SQL injection vulnerability (CVE-2026-1617) exists in Turkmesh Communication Services Inc. Turkhotspot 5651 Loglama software, affecting versions from 5.1.2 before 5.1.3. This flaw, rated with a CVSS v3.1 Base Score of 9.8, allows attackers to execute arbitrary SQL commands due to improper neutralization of special elements in an SQL query.

Turkhotspot 5651 Loglama sql-injection vulnerability web-application
1r 1t 1c
high advisory

Multiple Vulnerabilities in Synacor Zimbra

An attacker can exploit multiple vulnerabilities in Synacor Zimbra to execute arbitrary code, perform cross-site scripting attacks, bypass security measures, disclose confidential information, and carry out unauthorized actions.

Zimbra vulnerability rce xss data-exfiltration defense-evasion
5t
medium threat

OPNsense: Multiple Vulnerabilities

An attacker can exploit multiple vulnerabilities in OPNsense to bypass security controls, disclose information, perform Cross-Site Scripting (XSS) attacks, and execute Denial of Service (DoS) attacks.

exploited OPNsense vulnerability firewall network-device
4t
low advisory

Drupal OpenAI Provider Module Vulnerable to Server-Side Request Forgery and Local File Read (CVE-2026-13233)

A moderately critical Server-Side Request Forgery (SSRF) vulnerability, CVE-2026-13233, in the Drupal OpenAI Provider (`ai_provider_openai`) module allows attackers to achieve local file reads or access internal network services by manipulating the upstream AI API response, with a public exploit now available.

OpenAI Provider +1 SSRF file-read Drupal CVE web-application
2r 3t 1c 5i
high advisory

ProFTPD: Multiple Vulnerabilities Leading to RCE and Information Disclosure

A remote, authenticated attacker can exploit multiple vulnerabilities in ProFTPD to achieve arbitrary code execution and disclose confidential information, leading to system compromise and data theft.

ProFTPD vulnerability rce information-disclosure linux
3t
high advisory

MapSVG WordPress Plugin Vulnerability Allows Arbitrary File Uploads (CVE-2026-1771)

An authenticated attacker with Administrator-level access can exploit CVE-2026-1771 in the MapSVG WordPress plugin, affecting versions up to 8.14.0, due to missing file type validation, enabling arbitrary file uploads and potentially leading to remote code execution on the server.

MapSVG – Vector maps, Image maps, Google Maps <= 8.14.0 wordpress plugin arbitrary-file-upload rce web-application
1r 3t 1c
medium advisory

CUPS (libcupsfilters, cups-filters) Denial of Service Vulnerability

A vulnerability in CUPS, specifically affecting libcupsfilters and cups-filters, allows a remote, unauthenticated attacker to exploit the system, leading to a denial-of-service condition that disrupts the availability of the printing system.

CUPS +2 denial-of-service vulnerability linux
1t
high advisory

rsyslog Vulnerability Allows Denial of Service and Potential Code Execution

A remote, unauthenticated attacker can exploit a vulnerability in rsyslog to perform a Denial of Service attack and potentially execute arbitrary code.

rsyslog vulnerability denial-of-service code-execution linux
2t
high threat

Red Hat Enterprise Linux Vulnerabilities Allow Privilege Escalation and DoS

Multiple vulnerabilities in Red Hat Enterprise Linux, affecting components such as sssd, glib, and c-ares, can be exploited by an attacker to gain administrator privileges, bypass security measures, manipulate data, and trigger a denial-of-service condition.

exploited Red Hat Enterprise Linux red-hat linux vulnerability privilege-escalation defense-evasion denial-of-service
4t
low advisory

BusyBox AWK Vulnerability Leads to Denial of Service

A stack overflow vulnerability, identified as CVE-2026-38752, exists in the evaluate() function within the AWK editor (editors/awk.c) of BusyBox commit 371fe9, which allows attackers to trigger a Denial of Service (DoS) condition by providing a specially crafted AWK script.

BusyBox denial-of-service vulnerability linux
1t 1c
high advisory

CVE-2026-38754: Busybox Heap Overflow Leads to Denial of Service

A heap overflow vulnerability (CVE-2026-38754) exists in the ifsbreakup() function (shell/ash.c) of Busybox v1.38.0. This flaw allows attackers to trigger a Denial of Service (DoS) by providing a specially crafted input, leading to application instability or unavailability.

Busybox v1.38.0 vulnerability denial-of-service heap-overflow linux
1t 3c
medium advisory

ethtool RSS Resource Leak on get_rxfh Failure

A vulnerability, CVE-2026-63999, has been identified in the `ethtool` utility on Linux systems, involving a resource leak of `indir_table` and `hkey` when the `get_rxfh` function related to Receive Side Scaling (RSS) functionality fails, which could lead to system instability or resource exhaustion.

ethtool linux vulnerability resource-leak
1c
high threat

Linux Kernel USB Type-C Wcove Driver Buffer Overflow Vulnerability

A buffer overflow vulnerability, identified as CVE-2026-63960, exists in the `wcove_read_rx_buffer()` function within the USB Type-C `wcove` driver in the Linux kernel, potentially leading to memory corruption or system instability upon exploitation.

exploited Linux Kernel linux kernel vulnerability buffer-overflow cve
1c
medium threat

CVE-2026-64117 Vulnerability in Linux Kernel mac80211 Wi-Fi Subsystem

A vulnerability, CVE-2026-64117, has been disclosed in the Linux kernel's mac80211 Wi-Fi subsystem, potentially leading to unexpected behavior or information exposure due to incorrect handling of fast-RX rates and `skb->cb` buffer reuse in mesh networking contexts.

exploited mac80211 linux vulnerability kernel wifi
1c
medium threat

CVE-2026-64097: AMD Display Module Vulnerability in Linux Kernel

A vulnerability, CVE-2026-64097, affects the `drm/amd/display` module in the Linux kernel due to insufficient validation of GPIO pin LUT table size, potentially leading to system instability or other security impacts on Linux systems utilizing AMD display drivers.

exploited Linux Kernel vulnerability linux kernel amd denial-of-service
1c
critical advisory

Qemu-kvm HyperV Syndbg Out-of-Bounds Write Vulnerability

A critical vulnerability, CVE-2026-3842, exists in the `hyperv/syndbg` component of Qemu-kvm, allowing an attacker to perform out-of-bounds writes on the host system due to a missing mapped-length guard after a `cpu_physical_memory_map` operation.

Qemu-kvm virtualization hypervisor vulnerability guest-to-host-escape
1c
critical advisory

WordPress Easy Form Builder Plugin Vulnerable to Unauthenticated Administrator Privilege Escalation (CVE-2026-13439)

An unauthenticated privilege escalation vulnerability exists in the Easy Form Builder by WhiteStudio plugin for WordPress, affecting versions up to and including 4.0.11, allowing attackers to exploit a flaw in the password recovery process by using a publicly visible session identifier ('sid') as a reset token, combined with a publicly accessible nonce refresh endpoint, to set an arbitrary new password for any WordPress user, including administrators, to gain full control.

Easy Form Builder by WhiteStudio plugin for WordPress <= 4.0.11 wordpress plugin privilege-escalation web-vulnerability
1r 2t 1c
high advisory

Zyxel AX7501-B1 Firmware Command Injection (CVE-2026-6952)

A post-authentication command injection vulnerability (CVE-2026-6952) in the "LogServer" field of the syslog component in Zyxel AX7501-B1 firmware versions through 5.17(ABPC.7.2)C0 allows an authenticated attacker with administrator privileges to execute arbitrary OS commands on the affected device.

AX7501-B1 firmware command-injection vulnerability router network-device
1t 1c
high advisory

Pillow BdfFontFile Decompression Bomb Bypass Vulnerability

A vulnerability (CVE-2026-55379) in Pillow's BdfFontFile component allows attackers to craft a malicious BDF font file with oversized BBX dimensions and an empty BITMAP section, bypassing documented decompression bomb protection and causing the Image.new() function to silently allocate large amounts of memory in the C-heap, leading to resource exhaustion and denial-of-service for applications processing untrusted BDF fonts.

pillow vulnerability denial-of-service python heap-overflow integer-overflow image-processing python-library cve-2026-59199 +2
4t 1c
high advisory

Axios Node.js HTTP Adapter Vulnerable to Proxy Redirection via Prototype Pollution Bypass

A vulnerability in Axios's Node.js HTTP adapter, affecting versions 1.15.2 and 1.16.0, allows an attacker to bypass prototype pollution hardening, enabling redirection of HTTP requests through an attacker-controlled proxy to achieve sensitive information disclosure.

axios prototype-pollution information-disclosure nodejs
2t
high advisory

AVideo OS Command Injection via Unescaped m3u8 URL (CVE-2026-45578)

AVideo is vulnerable to OS command injection (CVE-2026-45578) in the `on_publish.php` file due to improper sanitization of the m3u8 URL, allowing attackers to execute arbitrary commands by injecting shell metacharacters.

AVideo +1 command injection webserver
2r 1t 2c 3i updated
high advisory

FileBrowser Username Normalization Collision Leads to Authorization Bypass

A critical authorization bypass vulnerability, CVE-2026-62685, in FileBrowser versions <= 2.63.16 enables an attacker to gain full read and write access to other users' files by exploiting a username normalization collision during self-registration, thus bypassing per-user isolation and allowing data tampering or exfiltration.

FileBrowser <= 2.63.16 authorization-bypass web-application filebrowser vulnerability
4t 1c
high advisory

CVE-2026-16324: Metasoft MetaCRM Unrestricted File Upload Vulnerability

A high-severity vulnerability, CVE-2026-16324, exists in Metasoft MetaCRM up to version 6.4.0 Beta06, allowing remote attackers to perform unrestricted file uploads by manipulating the 'File' argument within the `/business/qnaire/upload.jsp` component, which can lead to webshell deployment and remote code execution; a public exploit is available, increasing the risk of attack.

MetaCRM cve rce unrestricted-upload web-vulnerability metasystem
1r 2t 1c