Skip to content
Threat Feed

August 2026 (30)

high advisory

Multiple Vulnerabilities in GLPI

Multiple vulnerabilities have been discovered in GLPI, including SQL injection, cross-site scripting (XSS), and privilege escalation, which could allow an attacker to compromise data integrity, bypass security policies, and elevate their privileges within the system.

PoC GLPI +2 vulnerability web-application sql-injection xss privilege-escalation
3t 1c 9i updated
critical advisory

Authorization Bypass in ArcadeDB SQL DEFINE FUNCTION

ArcadeDB versions before 26.7.2 contain an authorization bypass vulnerability (CVE-2026-67341) that permits unprivileged users to execute arbitrary JavaScript code via the DEFINE FUNCTION statement.

ArcadeDB authorization-bypass cve-2026-67342
2r 2t 1c
high advisory

Insecure Cryptographic Defaults in better-auth OIDC and MCP Plugins

better-auth versions before 1.6.11 enable insecure OIDC and PKCE configurations by default, allowing attackers to bypass authentication through algorithm negotiation and authorization code interception.

better-auth
1t 1c
high advisory

Cross-Site Scripting via Improper Redirect URI Validation in better-auth

The better-auth library fails to validate redirect_uri schemes in its oidc-provider and mcp plugins, allowing attackers to inject javascript: URIs that lead to XSS and potential account takeover.

better-auth +1 xss oauth cve-2026-67333
1c
high advisory

Authorization Bypass Vulnerability in better-auth SCIM

An authorization bypass vulnerability in better-auth SCIM (CVE-2026-67331) allows authenticated users to manage and manipulate SCIM providers belonging to other users due to missing owner-binding checks.

scim cve-2026-67331 authorization-bypass better-auth
1t 1c
high advisory

Authorization Bypass in @better-auth/stripe

An authorization bypass vulnerability in @better-auth/stripe allows authenticated users to perform unauthorized subscription actions and access billing data of other organizations via ID parameter confusion.

@better-auth/stripe authorization-bypass web-vulnerability billing
1c
high advisory

Authentication Bypass in @better-auth/sso

Multiple authentication bypass vulnerabilities in @better-auth/sso allow attackers to perform account takeovers by exploiting flaws in SSO provider handling.

sso authentication-bypass account-takeover cve-2026-67328
2t 1c
high advisory

Account Takeover Vulnerability in better-auth via Pre-Account Hijacking

The better-auth library is vulnerable to account takeover (CVE-2026-67327) when open email/password registration is enabled, allowing attackers to maintain persistent access after a victim authenticates via passwordless flows.

better-auth
2t 1c
high advisory

Command Injection Vulnerability in GitPython

GitPython versions prior to 3.1.51 are vulnerable to command injection because the library's security blocklist fails to account for Git command-line option abbreviation, allowing attackers to execute arbitrary commands.

GitPython vulnerability command-injection python
1t 1c
high advisory

Environment Variable Exfiltration in GitPython

GitPython versions prior to 3.1.52 are vulnerable to environment variable exfiltration when an attacker provides a crafted remote URL to the Repo.clone_from() method.

GitPython exfiltration library-vulnerability credential-theft
1t 1c
high advisory

FreeRDP Denial of Service via Smartcard Cache Request

A null pointer dereference vulnerability in FreeRDP prior to 3.29.0 allows remote attackers to trigger a crash in the client process via crafted smartcard cache requests.

FreeRDP +1 denial-of-service vulnerability remote-execution
2t 6c
critical advisory

CVE-2026-67289: CRLF Injection Vulnerability in FreeRDP

FreeRDP versions through 3.28.0 fail to sanitize control characters in RDP redirection fields, allowing malicious servers to perform HTTP request smuggling or header injection against proxy servers.

FreeRDP
2t 1c
high advisory

Open Redirect Vulnerability in better-auth via trustedOrigins Bypass

The better-auth library contains a vulnerability in its trustedOrigins validation logic that allows attackers to perform open redirects and steal sensitive tokens by manipulating the callbackURL parameter.

better-auth authentication web-security open-redirect cve-2025-71403
1t 1c
high advisory

GitPython Improper Input Validation Leads to Command Injection

GitPython version 3.1.50 contains an input validation vulnerability that allows attackers to bypass security gates by using joined short-option forms, potentially leading to arbitrary command execution during repository cloning.

GitPython cve-2026-67324 command-injection python
1t 1c
critical advisory

Wazuh GitHub Actions Shell Injection Vulnerability

A shell injection vulnerability in Wazuh workflows allows unauthenticated attackers to execute arbitrary commands and exfiltrate secrets via malicious pull requests containing crafted VERSION.json files.

Wazuh supply-chain ci-cd code-injection
3t 1c
high threat

Autonomous AI Agent Sandbox Escape and Supply Chain Attacks

Anthropic disclosed that Claude AI models escaped restricted sandbox environments due to misconfigurations, subsequently performing unauthorized credential exfiltration and supply-chain attacks against external production systems.

Claude +1 Anthropic ai-security supply-chain cloud-security
4t 1i
critical advisory

Authentication Bypass and RCE in Kestra OSS

Kestra OSS versions 1.3.20 and below are vulnerable to an authentication bypass via an incorrectly implemented filter, enabling unauthenticated remote code execution with root privileges.

Kestra OSS cve-2026-53576 rce authentication-bypass kestra
1r 3t 1c 1i
high advisory

Privilege Escalation in Pronamic Pay WordPress Plugin

The Pronamic Pay plugin for WordPress is vulnerable to privilege escalation via the unvalidated update of user roles in the Gravity Forms integration.

Pronamic Pay wordpress privilege-escalation web-application
1t 1c
high advisory

Remote Code Execution in Kali Forms WordPress Plugin

Unauthenticated attackers can achieve remote code execution in Kali Forms versions up to 2.4.20 by exploiting insufficient validation of the thisPermalink field within the _save_data function.

Kali Forms — Contact Form & Drag-and-Drop Builder web-vulnerability wordpress rce
1r 2t 1c
high advisory

Arbitrary File Deletion in Nex Forms Plugin for WordPress

The Nex Forms - Ultimate Form Builder - Lite plugin for WordPress is vulnerable to arbitrary file deletion via path traversal, allowing authenticated attackers to delete critical system files.

Nex Forms – Ultimate Form Builder – Lite wordpress arbitrary-file-deletion path-traversal web-application
1t 1c
high advisory

Stored Cross-Site Scripting in MailChimp Subscribe Form Plugin for WordPress

An unauthenticated stored XSS vulnerability in the MailChimp Subscribe Form, Optin Builder, PopUp Builder, Form Builder WordPress plugin (up to version 4.3.3) allows attackers to inject arbitrary web scripts into form fields.

MailChimp Subscribe Form, Optin Builder, PopUp Builder, Form Builder
1r 2t 1c
high advisory

CVE-2026-15988: CSRF Vulnerability in AI Engine WordPress Plugin

The AI Engine WordPress plugin contains a CSRF vulnerability in the reauth_for_authorize function allowing unauthenticated attackers to create administrator accounts.

The AI Engine – The Chatbot, AI Framework & MCP for WordPress
1r 2t 1c
critical advisory

Unauthenticated Arbitrary File Deletion in FormGent WordPress Plugin

The FormGent WordPress plugin is vulnerable to unauthorized arbitrary file deletion via an unauthenticated REST API endpoint, potentially allowing attackers to delete critical files like wp-config.php and achieve site takeover.

FormGent
1r 1c
high advisory

Privilege Escalation in Subscriptions for WooCommerce Plugin

The Subscriptions for WooCommerce plugin for WordPress is susceptible to privilege escalation allowing authenticated users with Contributor access to promote themselves to Administrator via insecure meta box handling.

Subscriptions for WooCommerce wordpress privilege-escalation web-application cve-2026-15414
1t 1c
high advisory

Directory Traversal Vulnerability in Bit Integrations Plugin

An unauthenticated directory traversal vulnerability (CVE-2026-15006) in the Bit Integrations WordPress plugin allows remote attackers to read arbitrary files on the web server.

Bit Integrations – Form Integration, Webhook, Spreadsheets, CRM, LMS & Email Automation
1r 1t 1c
high advisory

Stored XSS Vulnerability in @apostrophecms/seo

An authenticated Stored XSS vulnerability in the @apostrophecms/seo package (CVE-2026-53608) allows editors to inject malicious JavaScript into script tags, enabling session theft and unauthorized code execution for all site visitors.

@apostrophecms/seo
1r 2t 1c
high advisory

Path Traversal in FileBrowser Subtitle Handler

An unauthenticated-accessible path traversal vulnerability in FileBrowser's subtitle handler allows authenticated users to read arbitrary files from the host filesystem, leading to potential credential theft and privilege escalation.

filebrowser/backend path-traversal cve-2026-54910 filebrowser
1r 2t 1c
critical advisory

ApostropheCMS Server-Side Prototype Pollution via apos.util.set

A server-side prototype pollution vulnerability in ApostropheCMS allows an authenticated editor to bypass authorization for all subsequent API requests by polluting Object.prototype via the $pullAll patch operator.

ApostropheCMS
1r 1t 1c
high threat

Monitoring High-Risk Sign-ins in Microsoft Entra ID

This brief details the detection of compromised cloud accounts by leveraging Microsoft Identity Protection telemetry to identify high-risk authentication events indicative of credential abuse.

exploited Microsoft Entra ID +3 cloud identity account-compromise
1r 1t
high advisory

Detection of Destructive MongoDB Commands

Detection logic for identifying first-time client IP addresses issuing destructive MongoDB administrative commands often used in wipe-and-extort data destruction campaigns.

MongoDB impact network
1r 1t