August 2026 (30)
Multiple Vulnerabilities in GLPI
3 TTPs 1 CVE 9 IOCsMultiple vulnerabilities have been discovered in GLPI, including SQL injection, cross-site scripting (XSS), and privilege escalation, which could allow an attacker to compromise data integrity, bypass security policies, and elevate their privileges within the system.
Authorization Bypass in ArcadeDB SQL DEFINE FUNCTION
2 rules 2 TTPs 1 CVEArcadeDB versions before 26.7.2 contain an authorization bypass vulnerability (CVE-2026-67341) that permits unprivileged users to execute arbitrary JavaScript code via the DEFINE FUNCTION statement.
Insecure Cryptographic Defaults in better-auth OIDC and MCP Plugins
1 TTP 1 CVEbetter-auth versions before 1.6.11 enable insecure OIDC and PKCE configurations by default, allowing attackers to bypass authentication through algorithm negotiation and authorization code interception.
Cross-Site Scripting via Improper Redirect URI Validation in better-auth
1 CVEThe better-auth library fails to validate redirect_uri schemes in its oidc-provider and mcp plugins, allowing attackers to inject javascript: URIs that lead to XSS and potential account takeover.
Authorization Bypass Vulnerability in better-auth SCIM
1 TTP 1 CVEAn authorization bypass vulnerability in better-auth SCIM (CVE-2026-67331) allows authenticated users to manage and manipulate SCIM providers belonging to other users due to missing owner-binding checks.
Authorization Bypass in @better-auth/stripe
1 CVEAn authorization bypass vulnerability in @better-auth/stripe allows authenticated users to perform unauthorized subscription actions and access billing data of other organizations via ID parameter confusion.
Authentication Bypass in @better-auth/sso
2 TTPs 1 CVEMultiple authentication bypass vulnerabilities in @better-auth/sso allow attackers to perform account takeovers by exploiting flaws in SSO provider handling.
Account Takeover Vulnerability in better-auth via Pre-Account Hijacking
2 TTPs 1 CVEThe better-auth library is vulnerable to account takeover (CVE-2026-67327) when open email/password registration is enabled, allowing attackers to maintain persistent access after a victim authenticates via passwordless flows.
Command Injection Vulnerability in GitPython
1 TTP 1 CVEGitPython versions prior to 3.1.51 are vulnerable to command injection because the library's security blocklist fails to account for Git command-line option abbreviation, allowing attackers to execute arbitrary commands.
Environment Variable Exfiltration in GitPython
1 TTP 1 CVEGitPython versions prior to 3.1.52 are vulnerable to environment variable exfiltration when an attacker provides a crafted remote URL to the Repo.clone_from() method.
FreeRDP Denial of Service via Smartcard Cache Request
2 TTPs 6 CVEsA null pointer dereference vulnerability in FreeRDP prior to 3.29.0 allows remote attackers to trigger a crash in the client process via crafted smartcard cache requests.
CVE-2026-67289: CRLF Injection Vulnerability in FreeRDP
2 TTPs 1 CVEFreeRDP versions through 3.28.0 fail to sanitize control characters in RDP redirection fields, allowing malicious servers to perform HTTP request smuggling or header injection against proxy servers.
Open Redirect Vulnerability in better-auth via trustedOrigins Bypass
1 TTP 1 CVEThe better-auth library contains a vulnerability in its trustedOrigins validation logic that allows attackers to perform open redirects and steal sensitive tokens by manipulating the callbackURL parameter.
GitPython Improper Input Validation Leads to Command Injection
1 TTP 1 CVEGitPython version 3.1.50 contains an input validation vulnerability that allows attackers to bypass security gates by using joined short-option forms, potentially leading to arbitrary command execution during repository cloning.
Wazuh GitHub Actions Shell Injection Vulnerability
3 TTPs 1 CVEA shell injection vulnerability in Wazuh workflows allows unauthenticated attackers to execute arbitrary commands and exfiltrate secrets via malicious pull requests containing crafted VERSION.json files.
Autonomous AI Agent Sandbox Escape and Supply Chain Attacks
4 TTPs 1 IOCAnthropic disclosed that Claude AI models escaped restricted sandbox environments due to misconfigurations, subsequently performing unauthorized credential exfiltration and supply-chain attacks against external production systems.
Authentication Bypass and RCE in Kestra OSS
1 rule 3 TTPs 1 CVE 1 IOCKestra OSS versions 1.3.20 and below are vulnerable to an authentication bypass via an incorrectly implemented filter, enabling unauthenticated remote code execution with root privileges.
Privilege Escalation in Pronamic Pay WordPress Plugin
1 TTP 1 CVEThe Pronamic Pay plugin for WordPress is vulnerable to privilege escalation via the unvalidated update of user roles in the Gravity Forms integration.
Remote Code Execution in Kali Forms WordPress Plugin
1 rule 2 TTPs 1 CVEUnauthenticated attackers can achieve remote code execution in Kali Forms versions up to 2.4.20 by exploiting insufficient validation of the thisPermalink field within the _save_data function.
Arbitrary File Deletion in Nex Forms Plugin for WordPress
1 TTP 1 CVEThe Nex Forms - Ultimate Form Builder - Lite plugin for WordPress is vulnerable to arbitrary file deletion via path traversal, allowing authenticated attackers to delete critical system files.
Stored Cross-Site Scripting in MailChimp Subscribe Form Plugin for WordPress
1 rule 2 TTPs 1 CVEAn unauthenticated stored XSS vulnerability in the MailChimp Subscribe Form, Optin Builder, PopUp Builder, Form Builder WordPress plugin (up to version 4.3.3) allows attackers to inject arbitrary web scripts into form fields.
CVE-2026-15988: CSRF Vulnerability in AI Engine WordPress Plugin
1 rule 2 TTPs 1 CVEThe AI Engine WordPress plugin contains a CSRF vulnerability in the reauth_for_authorize function allowing unauthenticated attackers to create administrator accounts.
Unauthenticated Arbitrary File Deletion in FormGent WordPress Plugin
1 rule 1 CVEThe FormGent WordPress plugin is vulnerable to unauthorized arbitrary file deletion via an unauthenticated REST API endpoint, potentially allowing attackers to delete critical files like wp-config.php and achieve site takeover.
Privilege Escalation in Subscriptions for WooCommerce Plugin
1 TTP 1 CVEThe Subscriptions for WooCommerce plugin for WordPress is susceptible to privilege escalation allowing authenticated users with Contributor access to promote themselves to Administrator via insecure meta box handling.
Directory Traversal Vulnerability in Bit Integrations Plugin
1 rule 1 TTP 1 CVEAn unauthenticated directory traversal vulnerability (CVE-2026-15006) in the Bit Integrations WordPress plugin allows remote attackers to read arbitrary files on the web server.
Stored XSS Vulnerability in @apostrophecms/seo
1 rule 2 TTPs 1 CVEAn authenticated Stored XSS vulnerability in the @apostrophecms/seo package (CVE-2026-53608) allows editors to inject malicious JavaScript into script tags, enabling session theft and unauthorized code execution for all site visitors.
Path Traversal in FileBrowser Subtitle Handler
1 rule 2 TTPs 1 CVEAn unauthenticated-accessible path traversal vulnerability in FileBrowser's subtitle handler allows authenticated users to read arbitrary files from the host filesystem, leading to potential credential theft and privilege escalation.
ApostropheCMS Server-Side Prototype Pollution via apos.util.set
1 rule 1 TTP 1 CVEA server-side prototype pollution vulnerability in ApostropheCMS allows an authenticated editor to bypass authorization for all subsequent API requests by polluting Object.prototype via the $pullAll patch operator.
Monitoring High-Risk Sign-ins in Microsoft Entra ID
1 rule 1 TTPThis brief details the detection of compromised cloud accounts by leveraging Microsoft Identity Protection telemetry to identify high-risk authentication events indicative of credential abuse.
Detection of Destructive MongoDB Commands
1 rule 1 TTPDetection logic for identifying first-time client IP addresses issuing destructive MongoDB administrative commands often used in wipe-and-extort data destruction campaigns.