Skip to content
Threat Feed

August 2026 (30)

high advisory

Critical RCE and Information Disclosure Vulnerability in Gitea

Gitea contains a critical vulnerability allowing remote, unauthenticated attackers to execute arbitrary code and gain unauthorized access to sensitive information.

Gitea vulnerability remote-code-execution web-application
1t
high advisory

Multiple Vulnerabilities in pgAdmin

Multiple vulnerabilities in pgAdmin enable unauthenticated or authenticated remote attackers to execute arbitrary code, conduct SQL injection, bypass security controls, and perform unauthorized data access.

pgAdmin
2t
low advisory

Detection of Background Utility Usage for Process Execution on Linux

Adversaries leverage Linux background utilities such as setsid, nohup, and disown to execute processes in new sessions, enabling them to ignore termination signals and decouple malicious tasks from parent process trees.

linux execution defense-evasion process-decoupling
1r 2t
low advisory

Detection of External IP Discovery via Curl on macOS

Threat actors utilize curl or nscurl on macOS to query public IP geolocation services for reconnaissance, enabling them to assess network context and stage follow-on malicious activity.

macos discovery reconnaissance
1r 1t 1i
high advisory

Apple Security Updates — August 2026

Roundup of Apple security advisories published in August 2026.

macOS roundup
medium advisory

Suspicious Cross-User Process Spawning Behavior

Detection of common user-space applications being spawned under different user contexts, which often indicates privilege escalation testing or sacrificial process execution.

privilege-escalation stealth windows process-creation
1r 2t
medium advisory

Detection of Suspicious Offline Registry Library Usage

Detection of unauthorized processes loading offreg.dll to perform direct registry hive modification, potentially bypassing standard Windows Registry auditing.

defense-impairment persistence windows telemetry-bypass
1r 1t
high advisory

Suspicious Staging of Windows Registry Hive Files

Detection of registry hive files created outside of standard user profile directories, a common indicator of unauthorized hive manipulation for credential access or persistence.

persistence privilege-escalation credential-access
1r 2t
medium advisory

Detection of Suspicious Explicit Credential Local Logon

Detection logic for monitoring Windows Event ID 4648 to identify potential privilege escalation through unauthorized explicit credential usage.

windows security-auditing privilege-escalation
1r 1t
high advisory

Suspicious Microsoft Office Child Process Activity

Microsoft Office applications are frequently abused to spawn system processes to execute malicious code, download payloads, or facilitate privilege escalation.

Microsoft Office
1r 3t 1c
medium advisory

Incorrect Default Permissions in Synology Assistant

Synology Assistant versions prior to 7.0.7-50095 contain a vulnerability allowing local users to perform arbitrary file operations and trigger denial-of-service during the installation process.

Synology Assistant
1c
critical advisory

Stack-based Buffer Overflow in Wavlink WL-NU516U1 nas.cgi

A stack-based buffer overflow vulnerability in the nas.cgi file of Wavlink WL-NU516U1 routers allows remote, unauthenticated attackers to execute arbitrary code via a malicious CONTENT_LENGTH argument.

WL-NU516U1 +1 cve-2026-18589 buffer-overflow router rce
4t 1c
high advisory

Diffusers TOCTOU Vulnerability Leads to Remote Code Execution

A Time-of-Check Time-of-Use (TOCTOU) vulnerability in the `diffusers` package allows arbitrary code execution via a race condition when loading pipelines from the Hugging Face Hub, bypassing trust checks.

diffusers toctou rce huggingface
2r 1t 3c updated
high advisory

WordPress Redsys Payment Gateway Plugin Vulnerable to Payment Forgery (CVE-2026-5050)

The Payment Gateway for Redsys & WooCommerce Lite plugin for WordPress is vulnerable to cryptographic signature forgery, allowing unauthenticated attackers to mark pending orders as paid by forging payment callback data in versions up to 7.0.0.

PoC LDAP authentication services wordpress woocommerce redsys payment-gateway vulnerability
2r 1t 1c 1i updated
critical advisory

Critical Unauthenticated RCE in Realtyna WPL Real Estate Plugin

A critical unauthenticated remote code execution vulnerability, CVE-2026-13714, in Realtyna WPL Real Estate and Organic IDX plugins allows attackers to upload arbitrary PHP shells via the I/O API.

WPL Real Estate +1 wordpress rce vulnerability
1r 2t 1c 1i
critical advisory

SQL Injection in PyAthena DefaultParameterFormatter

Unauthenticated attackers can achieve arbitrary SQL execution in PyAthena versions prior to 3.35.4 by exploiting improper quote-escaping within the DefaultParameterFormatter.format() function.

PyAthena
1t 1c
high advisory

Authentication Bypass and Privilege Escalation in Vikunja API

Vikunja versions 0.22.0 through 2.3.0 contain an authentication bypass vulnerability allowing attackers to impersonate users and manage their API tokens via manipulated link-share JWTs.

Vikunja
1t 1c
critical advisory

Heap-based Buffer Overflow in FreeRDP Windows Clipboard Client

A heap-based buffer overflow in FreeRDP versions 3.29.0 and earlier allows a malicious RDP server to execute an out-of-bounds write in the memory of a paste consumer process when handling clipboard file transfers.

FreeRDP vulnerability remote-access windows rdp
1c
high advisory

ArcadeDB Privilege Escalation via JavaScript Triggers

ArcadeDB versions before 26.7.3 insecurely expose the LocalDatabase object to JavaScript triggers, allowing attackers with schema update permissions to perform unauthorized administrative actions.

ArcadeDB +1 information-disclosure privilege-escalation database authentication-bypass database-security cve-2026-68578
1r 3t 1c
high advisory

Insecure Direct Object Reference in better-auth passkey

An Insecure Direct Object Reference (IDOR) vulnerability (CVE-2025-71400) in better-auth passkey versions before 1.4.0 allows authenticated users to delete arbitrary passkeys by enumerating IDs.

passkey idor authentication web-application cve-2025-71400
1r 1t 1c
medium advisory

Better Auth Path Normalization Vulnerability (CVE-2025-71399)

Better Auth versions prior to 1.4.5 contain a path normalization vulnerability in the rou3 library that allows attackers to bypass disabledPaths configurations and rate limits via URL path manipulation.

Better Auth web-application security-bypass cve-2025-71399
1c
high advisory

Local Privilege Escalation in PackageKit via TOCTOU Race Condition

CVE-2026-41651 is a local privilege escalation vulnerability in PackageKit that allows unprivileged users to execute arbitrary packages as root by bypassing PolKit via a TOCTOU race condition.

PackageKit privilege-escalation linux cve-2026-41651
1t 1c
critical advisory

Gitea Actions Fork Pull Request Approval Gate Bypass

A vulnerability in Gitea Actions (versions v1.20.0 and later) allows an unprivileged attacker to permanently bypass the fork pull request approval gate for a repository after a single, initial workflow approval, enabling arbitrary shell command execution on the Gitea Actions runner without further maintainer interaction, leading to source code disclosure and potential system compromise.

PoC Gitea +1 logic-bug ci-cd code-execution privilege-escalation gitea-actions
4t 1c 1i updated
high advisory

Directory Traversal Vulnerability in User Access Manager for WordPress

An unauthenticated directory traversal vulnerability in the User Access Manager WordPress plugin (CVE-2026-18352) allows attackers to read arbitrary files by bypassing access controls via the uamgetfile parameter.

User Access Manager
1r 2t 1c
high advisory

Arbitrary File Read Vulnerability in CubeWP Framework

An unauthenticated directory traversal vulnerability in the CubeWP Framework plugin allows attackers to read arbitrary files by leveraging exposed AJAX nonces.

CubeWP Framework web-application wordpress vulnerability
2t 1c
critical advisory

Authentication Bypass Vulnerability in WooCommerce Social Login Plugin

The WooCommerce - Social Login plugin for WordPress contains an authentication bypass vulnerability (CVE-2026-8457) that allows unauthenticated attackers to log in as any user, including administrators, via forged Apple ID tokens.

WooCommerce - Social Login
2t 1c
high advisory

Autonomous AI Agents Pose New Supply Chain and Data Exfiltration Risks

This content introduces AI Detection and Response (AIDR) as a new cybersecurity category to address emerging threats from autonomous AI agents, including supply chain attacks and unintended data sharing, highlighting their ability to execute with inherited privileges across endpoints, SaaS, and cloud environments.

ClawHub +42 ai agentic-ai aidr supply-chain-attack data-exfiltration cloud-security endpoint-security saas-security
4t 16i updated
critical advisory

Authentication Bypass in Single Sign On For TNG WordPress Plugin

An unauthenticated password reset vulnerability in the Single Sign On For TNG plugin (CVE-2026-15964) allows attackers to perform full site takeover by bypassing AJAX nonce protections.

PoC Single Sign On For TNG +1
1r 1c 1i updated
high advisory

ClickFix Campaign Activity

Tracking brief for the ClickFix campaign; individual sightings are folded in as reported.

PoC open source packages +36 campaign clickfix
16i updated
high advisory

Heap Out-of-Bounds Read in FreeRDP Glyph Caching

FreeRDP versions 3.28.0 and earlier are vulnerable to a heap out-of-bounds read during the processing of malicious RDP server glyph fragments, allowing for potential client-side crashes or information disclosure.

FreeRDP vulnerability memory-safety remote-access tls man-in-the-middle
1t 1c