July 2026 (30)
libTIFF Vulnerability Enables Arbitrary Code Execution and Denial of Service
1 TTPA local attacker can exploit a vulnerability in libTIFF to execute arbitrary code and perform a denial of service attack against the system where the library is used.
CVE-2026-15557: Improper Authentication Vulnerability in waooAI waoowaoo
1 rule 2 TTPs 1 CVEA high-severity improper authentication vulnerability, CVE-2026-15557, exists in waooAI waoowaoo up to version 0.4.1, allowing remote attackers to bypass authentication and gain unauthorized access by manipulating the 'x-internal-user-id' request argument in the Internal Task Header Handler component, with a public exploit available.
Shibby Tomato Router Firmware Stack-Based Buffer Overflow (CVE-2026-15548)
2 TTPs 1 CVEA critical stack-based buffer overflow vulnerability (CVE-2026-15548) exists in Shibby Tomato router firmware versions up to 1.28.0000, specifically in the `sub_407220` function of the `/usr/sbin/httpd` component related to DNS List Rendering, allowing remote attackers to achieve high impact on confidentiality, integrity, and availability.
Multiple Vulnerabilities in Grafana Could Lead to DoS and XSS
2 TTPsAttackers can exploit multiple vulnerabilities in Grafana to conduct Denial of Service attacks or Cross-Site Scripting attacks, potentially leading to service disruption or client-side code execution.
Multiple Vulnerabilities in JetBrains TeamCity
2 TTPsMultiple vulnerabilities in JetBrains TeamCity could allow an attacker to execute arbitrary code, manipulate data, or perform Cross-Site Scripting (XSS) attacks, potentially leading to system compromise or client-side attacks.
Contao Information Disclosure Vulnerability
1 TTPAn authenticated remote attacker can exploit a vulnerability in Contao to disclose sensitive information, gaining unauthorized access to data within the system.
JetBrains IntelliJ IDEA Vulnerability Allows Code Execution
2 TTPsA remote, anonymous attacker can exploit an unspecified vulnerability in JetBrains IntelliJ IDEA to achieve arbitrary code execution, enabling them to execute arbitrary program code on the affected system.
Linux Kernel Vulnerability (xfrm: iptfs) Allows Local DoS and Data Manipulation
2 TTPsA local attacker can exploit a vulnerability in the Linux Kernel's xfrm: iptfs component to potentially trigger a denial-of-service condition or manipulate data on affected systems.
Targeting and Compromise of French Entities Using the Turla Intrusion Set
The Turla intrusion set, operated by the 16th Centre of the Federal Security Service (FSB) of Russia, has been targeting French entities and other strategic organizations globally since at least 2004 for intelligence-gathering purposes, with victims in France including ministries and entities within the diplomatic, defence, justice, and technology sectors.
Shibby Tomato Firmware Vulnerability CVE-2026-15545 Leads to Remote Out-of-Bounds Write
2 TTPs 1 CVEA critical out-of-bounds write vulnerability (CVE-2026-15545) exists in Shibby Tomato firmware up to version 1.28.0000, specifically within the `main` function of the `www/apcupsd/tomatodata.cgi` file in the `apcupsd` component, which can be exploited remotely with a publicly available exploit, posing a significant risk to affected network devices.
Wget Vulnerability Allows Security Bypass and Server-Side Request Forgery
1 TTPA local attacker can exploit a vulnerability in wget to bypass existing security measures and perform a Server-Side Request Forgery (SSRF) attack, enabling requests to internal or restricted resources from the local system.
GraphicsMagick PCD Decoder Vulnerability Allows Code Execution
2 TTPsA remote, anonymous attacker can exploit a vulnerability in the GraphicsMagick PCD decoder to potentially execute arbitrary code, corrupt memory, or cause a denial-of-service condition. This flaw could lead to compromise of the system running the affected software or disruption of its availability.
Shibby Tomato Firmware Vulnerability CVE-2026-15544 Enables Remote Code Execution
2 TTPs 1 CVEA stack-based buffer overflow vulnerability, identified as CVE-2026-15544, exists in the `getupsvar` function within the `www/apcupsd/tomatodata.cgi` file of the `apcupsd` component in Shibby Tomato firmware versions up to and including 1.28.0000, allowing a remote attacker to achieve arbitrary code execution by manipulating the `Field` argument.
CVE-2026-4769: Unauthenticated Remote Access in WAGO System I/O Field Series
2 TTPs 1 CVEA critical vulnerability, CVE-2026-4769, in certain WAGO System I/O Field series devices allows an unauthenticated remote attacker to gain full system compromise by accessing an undocumented internal diagnostic capability during the initial startup sequence.
Critical Buffer Overflow in Tenda CH22 Leads to Remote Code Execution (CVE-2026-15543)
1 TTP 1 CVEA critical buffer overflow vulnerability, CVE-2026-15543, exists in the Tenda CH22 1.0.0.1 firmware's `formCertListInfo` function, allowing unauthenticated remote attackers to achieve arbitrary code execution by manipulating the 'Name' argument, with a public exploit available.
CVE-2026-15541: Missing Authorization in will-moss Isaiah Master Websocket Handler
2 TTPs 1 CVEA critical missing authorization vulnerability (CVE-2026-15541) exists in the `Server.Handle` function of the `Master Websocket Handler` component within `will-moss Isaiah` versions up to 1.36.9, allowing a remote attacker to bypass authorization controls by manipulating the `Agent` argument, potentially leading to unauthorized access or privilege escalation.
CVE-2026-15537: SQL Injection Vulnerability in SourceCodester Online Book Store System 1.0
1 TTP 1 CVEA remote SQL injection vulnerability (CVE-2026-15537) has been identified in SourceCodester Online Book Store System 1.0. The flaw is located in the `admin/login.php` file, specifically impacting the 'Username' argument, and allows for authentication bypass. This vulnerability can be exploited remotely, and a public exploit is available.
Drupal AlternativeCommerce (Basket) Module Vulnerability Allows Code Execution
2 TTPsA critical vulnerability in the Drupal 'AlternativeCommerce' (Basket) module allows a remote, unauthenticated attacker to execute arbitrary program code. This can lead to full compromise of the affected web application.
Multiple Vulnerabilities in SaltStack Salt
2 TTPsMultiple vulnerabilities in SaltStack Salt allow an attacker to execute arbitrary program code on affected systems and bypass security measures, potentially leading to unauthorized access and control over managed infrastructure.
Django, Debian, and Ubuntu Vulnerability Allows Remote Denial of Service
1 TTPA remote, unauthenticated attacker can exploit a vulnerability in Django, Debian Linux, and Ubuntu Linux to initiate a Denial of Service attack, potentially disrupting services and making them unavailable to legitimate users.
Django Vulnerability Enables Denial of Service
1 TTPA remote, unauthenticated attacker can exploit an unspecified vulnerability in Django to conduct a Denial of Service attack, which could disrupt the availability of services running on the affected Django application.
CPython Vulnerability Enables Remote Denial of Service
1 TTPA remote, unauthenticated attacker can exploit an unspecified vulnerability within CPython to launch a Denial of Service attack, affecting the CPython interpreter across various operating systems.
CVE-2026-9492 - Improper Access Control in Gigabyte Control Center MBStorage Module
1 TTP 1 CVEAn Improper Access Control vulnerability (CVE-2026-9492) in the MBStorage DRAM lighting control module of Gigabyte Control Center (GCC) allows authenticated local attackers to achieve kernel-level privileges by sending specific IOCTL commands to the `MyPortIO_x64.sys` driver, enabling arbitrary physical memory read/write.
Remote SQL Injection Vulnerability in Jinher OA 1.0 (CVE-2026-15517)
1 rule 2 TTPs 1 CVE 5 IOCsA remote SQL injection vulnerability, CVE-2026-15517, has been discovered in Jinher OA 1.0, allowing unauthenticated attackers to execute arbitrary SQL commands by manipulating the `httpOID` argument in the `/C6/JHSoft.Web.PlanSummarize/PlanGiveOut.aspx` file, with a public exploit available.
Tencent PC Manager QMUDisk Driver Uncontrolled Search Path Vulnerability (CVE-2026-15515)
1 CVEA high-severity uncontrolled search path vulnerability (CVE-2026-15515) in the `qmudisk64.sys` component of Tencent PC Manager 18.1.30242.301 allows a local attacker to execute arbitrary code with elevated privileges, despite high complexity and difficult exploitability, due to public exploit disclosure.
Metasoft MetaCRM SQL Injection Vulnerability (CVE-2026-15514)
1 rule 1 TTP 1 CVEA critical SQL injection vulnerability (CVE-2026-15514) in Metasoft MetaCRM up to version 6.4.0 Beta06 allows remote attackers to exploit the RPCService.query function via the phprpc_args argument in /customizemt/xkq/rpc.jsp, leading to unauthorized database access and manipulation, with a public exploit available.
Comfast Router CVE-2026-15511: Remote OS Command Injection
1 rule 2 TTPs 1 CVEA critical remote OS command injection vulnerability, CVE-2026-15511, affects Comfast CF-WR631AX V3 WiFi routers, allowing unauthenticated remote attackers to execute arbitrary operating system commands by manipulating the 'filename' argument in the FastCGI Backend's file upload function, leading to full device compromise.
CVE-2026-15506: SecureAge CatchPulse Local Privilege Escalation via Heap-based Buffer Overflow
1 TTP 1 CVEA heap-based buffer overflow vulnerability, CVE-2026-15506, in the `saappctl.sys` driver of SecureAge CatchPulse versions up to 10.9.3 allows a local attacker to achieve privilege escalation, and an exploit has been publicly disclosed.
LuCI DHCPv6 Lease Hostname Stored Cross-Site Scripting Vulnerability (CVE-2026-61876)
1 TTP 1 CVELuCI versions are vulnerable to CVE-2026-61876, a stored Cross-Site Scripting (XSS) flaw in their DHCPv6 lease hostname rendering logic, allowing an adjacent network attacker to inject malicious HTML markup that executes in an administrator's browser when viewing DHCP lease status pages.
CVE-2026-61875: Stored Cross-Site Scripting in OpenWrt luci-app-upnp
2 TTPs 1 CVECVE-2026-61875 details a stored cross-site scripting vulnerability in OpenWrt's luci-app-upnp that allows unauthenticated LAN clients to inject malicious JavaScript into UPnP IGD AddPortMapping SOAP requests, leading to client-side code execution in an administrator's browser when viewing specific web interface pages.