Skip to content
Threat Feed

July 2026 (30)

high advisory

OpenWrt luci-app-samba4 Vulnerability Allows Remote Command Execution

A vulnerability in OpenWrt's luci-app-samba4, identified as CVE-2026-59260, allows authenticated delegated users to achieve remote command execution on the Samba daemon by leveraging improper ACLs that grant `file.exec` permission on `/usr/sbin/smbd`.

luci-app-samba4 openwrt samba cve rce network linux
1r 2t 1c
high advisory

Capgo Email Change Vulnerability Bypasses Authentication (CVE-2026-56308)

A vulnerability (CVE-2026-56308) in Capgo before version 12.128.2 allows an attacker with an authenticated session to change a user's email address without re-authentication or verification of the existing email, leading to account takeover through recovery mechanisms and multi-factor authentication bypass.

Capgo vulnerability authentication-bypass account-takeover web-application
2t 1c 2i
high advisory

Crawl4AI Credential Exfiltration and Authentication Bypass Vulnerabilities

A critical vulnerability, CVE-2026-56259, in Crawl4AI versions prior to 0.8.8 allows attackers to exploit unauthenticated Docker API server endpoints by manipulating the `base_url` and `api_token` parameters, leading to credential exfiltration and authentication bypass.

Crawl4AI before 0.8.8 vulnerability credential-access defense-evasion exfiltration cloud
1r 4t 1c
high advisory

Capgo Privilege Escalation via Retained Super_Admin Privileges (CVE-2026-56241)

A privilege escalation vulnerability, CVE-2026-56241, in Capgo versions prior to 12.128.2 allows demoted super_admin users to retain access to critical RPCs, enabling them to indefinitely enumerate and bulk delete non-compliant bundles across an organization.

Capgo privilege-escalation vulnerability cloud
1t 1c
high advisory

CVE-2026-56238 - Capgo Supabase PostgREST Information Disclosure

An information disclosure vulnerability (CVE-2026-56238) in Capgo before 12.128.2's Supabase PostgREST global_stats endpoint allows unauthenticated attackers to retrieve sensitive financial and operational metrics using a public API key.

Capgo < 12.128.2 +1 information-disclosure web-application vulnerability supabase
1r 2t 1c
high advisory

SQL Injection Vulnerability in sergomanov SmartHomeAdatum Login Component (CVE-2026-15498)

A SQL injection vulnerability, identified as CVE-2026-15498, exists in the Login component of sergomanov SmartHomeAdatum, affecting versions up to commit cf495353d81b680675eb8d9aa14a318aa45ce12c. This flaw allows remote attackers to perform SQL injection by manipulating the 'Login' argument in the 'users.php' file.

SmartHomeAdatum sql-injection web-application vulnerability cve
1r 2t 1c
high advisory

SonicCloudOrg Sonic-Agent Code Injection Vulnerability (CVE-2026-15497)

A critical vulnerability (CVE-2026-15497) exists in SonicCloudOrg's sonic-agent, affecting versions up to 2.7.2. The flaw resides within an unknown function in the `ExchangeController.java` file, specifically within the JWT Authentication Filter component of the `sonic-server-controller`. This vulnerability allows for remote code injection, and public exploits are available. The vendor was notified but has not responded, and the affected products are no longer supported.

sonic-agent <= 2.7.2 vulnerability rce code-injection
1r 2t 1c
critical advisory

Flowise Authentication Bypass via Hardcoded JWT Secrets (CVE-2026-56271)

Flowise versions 3.0.13 and earlier are vulnerable due to hardcoded default JWT secrets ('auth_token', 'refresh_token') and default audience/issuer values ('AUDIENCE', 'ISSUER'), allowing an attacker to forge valid JWTs and impersonate any user, including administrators, leading to an authentication bypass if environment variables are not explicitly set.

Flowise authentication-bypass jwt hardcoded-credentials web-application critical-vulnerability
2t 1c
critical advisory

Crawl4AI Arbitrary File Write via Docker API Server Endpoints (CVE-2026-56260)

Crawl4AI versions prior to 0.8.7 are vulnerable to CVE-2026-56260, an arbitrary file write vulnerability in its Docker API server's /screenshot and /pdf endpoints, allowing unauthenticated attackers to supply path traversal or absolute file paths via the output_path parameter to overwrite server files, leading to denial of service or impaired defenses.

Crawl4AI < 0.8.7 vulnerability web-application path-traversal arbitrary-file-write denial-of-service
1r 3t 1c
high advisory

CVE-2026-15489: SQL Injection in RafyMrX TOKO-ONLINE-ROTI login.php

A critical SQL injection vulnerability (CVE-2026-15489) exists in RafyMrX TOKO-ONLINE-ROTI, allowing remote attackers to bypass authentication and potentially exfiltrate sensitive data by manipulating the 'Username' argument in the 'proses/login.php' file, with a public exploit available.

TOKO-ONLINE-ROTI web-vulnerability sql-injection initial-access public-exploit web-exploitation cve remote-code-execution
2r 4t 1c
high advisory

Unrestricted File Upload Vulnerability in hcr707305003 shiroiAdmin

A remote unrestricted file upload vulnerability (CVE-2026-15488) exists in hcr707305003 shiroiAdmin versions 1.1 and 1.3, allowing attackers to upload arbitrary files by manipulating the 'File' argument in FileController::upload, potentially leading to remote code execution.

shiroiAdmin < 1.4 vulnerability web file-upload remote-code-execution
1r 3t 1c
critical advisory

Cockpit Remote Login Command Injection (CVE-2026-4631)

CVE-2026-4631 allows remote attackers to execute arbitrary code on a Cockpit host by injecting malicious SSH options via a crafted HTTP request to the login endpoint due to insufficient input validation of user-supplied hostnames and usernames.

PoC Cockpit rce command-injection CVE-2026-4631 linux
2r 1t 1c 2i updated
high advisory

Remote Buffer Overflow Vulnerability in TRENDnet TEW-821DAP Access Point

A critical buffer overflow vulnerability (CVE-2026-15484) exists in the `sub_41EC14` function within the `/goform/tools_nslookup` component of the TRENDnet TEW-821DAP 1.12B01 wireless access point, which can be exploited remotely due to improper handling of the ssi element, potentially leading to arbitrary code execution on an End-of-Life device.

TEW-821DAP buffer-overflow vulnerability network-device remote-code-execution
1c
high advisory

SQL Injection Vulnerability in Aster Telecom Azcall (CVE-2026-15482)

A critical SQL injection vulnerability, tracked as CVE-2026-15482, exists in Aster Telecom Azcall 10/11 within the HTTP Handler component, where manipulating the 'nome/perfil/status' argument when accessing '/azcall/adm/gestao_loja/sis.php?t=consultar' can lead to remote SQL injection, with a publicly available exploit allowing unauthenticated attackers to potentially access or modify sensitive data.

Azcall 10/11 sql-injection web-vulnerability cve exploit-available
1r 1t 1c
medium advisory

CPython Denial-of-Service Vulnerability

A remote denial-of-service vulnerability, CVE-2026-15308, has been discovered in CPython, allowing an attacker to cause service disruption to affected systems not running the latest security patch.

CPython +1 denial-of-service vulnerability python
1t 1c 1i updated
high advisory

Remote Command Injection in Trendnet TEW-635BRM Routers (CVE-2026-15481)

A critical remote command injection vulnerability (CVE-2026-15481) has been discovered in Trendnet TEW-635BRM routers up to version 1.00.03, allowing attackers to execute arbitrary commands by manipulating the 'ipoa_ipaddr' argument in the 'ipoa_test' function, with public exploits available for this End-of-Life product.

TEW-635BRM command-injection remote-code-execution network-device EOL-product
1t 1c
high advisory

Trendnet TEW-635BRM Web Service Stack-based Buffer Overflow Vulnerability

CVE-2026-15480 describes a stack-based buffer overflow vulnerability in the Trendnet TEW-635BRM router firmware, specifically in the start_httpd function within the /sbin/rc component's Web Service, which can be exploited remotely by manipulating the 'device_name' argument, potentially leading to arbitrary code execution; an exploit is publicly available, but the product is End-of-Life (EOL) since 2011, and the vendor advises users to switch devices.

TEW-635BRM network vulnerability router buffer-overflow rce eol
2t 1c
high threat

H3C NX15 Weak Password Recovery Vulnerability (CVE-2026-15479)

A critical vulnerability, CVE-2026-15479, in H3C NX15 V100R017 allows remote attackers to perform weak password recovery by manipulating the 'newPass' argument in the '/api/login/modify' endpoint, leading to unauthorized administrator access.

exploited NX15 V100R017 vulnerability api-exploitation password-reset network-device remote-access
2t 1c 5i
critical advisory

Cisco Catalyst SD-WAN Controller Authentication Bypass Vulnerability

A vulnerability in the peering authentication of Cisco Catalyst SD-WAN Controller and Manager (CVE-2026-20182) could allow a remote, unauthenticated attacker to bypass authentication and obtain administrative privileges by sending crafted requests.

PoC Catalyst SD-WAN Controller +7 authentication bypass privilege escalation cisco sd-wan
2r 2t 2c 5i updated
high advisory

Multi-Group Espionage Targets Pakistani Law Enforcement via Weaponized Police Portal

Suspected China- and India-aligned threat actors conducted sustained cyber espionage campaigns between February 2024 and April 2026, compromising Pakistani law enforcement organizations' web applications, network appliances, and email gateways, including the Balochistan Police's Complaint Management System to deploy malware like PlugX, ShadowPad, Cobalt Strike, Remcos RAT, a Rust stager (cms_plugin.exe), and AsyncRAT.

FortiMail +2 cyber-espionage nation-state malware rat windows
3r 5t 5i
high advisory

CVE-2026-61442: PraisonAI Platform Authorization Bypass

PraisonAI Platform versions before 0.1.9 are vulnerable to an authorization bypass on PATCH routes for projects, issues, and agents, allowing an attacker with a workspace-member role to modify owner-created records, reassign the lead_id to their own user ID, and subsequently delete owner-created projects, bypassing standard permission checks and leading to unauthorized data manipulation and deletion.

PraisonAI Platform < 0.1.9 authorization-bypass vulnerability web-application cve
2t 1c
high advisory

PraisonAI Prompt Injection Defense Bypass Vulnerability (CVE-2026-61439)

A prompt injection defense misconfiguration in PraisonAI versions before 4.6.78 allows high-severity threats to bypass blocking mechanisms due to a default block threshold set to CRITICAL severity, enabling attackers to submit instruction overrides or financial manipulation for system prompt extraction and unauthorized tool invocations.

PraisonAI prompt-injection ai-security vulnerability defense-bypass
3t 1c
high advisory

PraisonAI Server-Side Request Forgery via DNS Rebinding and Redirects (CVE-2026-61429)

PraisonAI versions prior to 1.6.78 are vulnerable to server-side request forgery (SSRF) due to an issue in the Crawl4AI/Chromium backend, allowing attackers to bypass existing SSRF validation by employing DNS rebinding and HTTP redirects to access and exfiltrate sensitive internal responses, including canary values.

PraisonAI ssrf vulnerability dns-rebinding web-application
4t 1c
high advisory

CVE-2026-61428: PraisonAI AgentMail Webhook Signature Bypass

PraisonAI AgentMail versions before 4.6.78 are vulnerable to CVE-2026-61428, an authentication bypass flaw in webhook mode that allows unauthenticated attackers to inject messages with spoofed sender addresses, enabling them to trigger replies to attacker-controlled addresses and bypass email filtering.

PraisonAI AgentMail authentication-bypass web-exploitation message-injection email-spoofing cve
3t 1c
high advisory

Insecure Default Configuration in PraisonAI Allows Unauthenticated Access

An insecure default configuration in PraisonAI before version 1.7.3 allows unauthenticated attackers to exploit CVE-2026-61426 by reading sensitive agent instructions and system prompts via the `/api/agents` endpoint and invoking agents without authentication through the `/api/chat` endpoint, leading to unauthorized information disclosure and potential control over AI functionalities.

PraisonAI vulnerability web-application insecure-configuration cve
2r 3t 1c
high advisory

Capgo API Key Information Disclosure Vulnerability (CVE-2026-56303)

An information disclosure vulnerability (CVE-2026-56303) in Capgo versions before 12.128.2 allows unauthenticated attackers to retrieve sensitive API key metadata, including user ID, mode, organization scoping, and expiration details, by exploiting a misconfigured PostgreSQL function via the `/rest/v1/rpc/find_apikey_by_value` endpoint.

Capgo information-disclosure vulnerability api-security web-application
1r 1t 1c
critical advisory

CVE-2026-61447 PraisonAI Remote Code Execution Vulnerability via Prompt Injection

Attackers can exploit CVE-2026-61447, a critical remote code execution vulnerability in PraisonAI versions before 1.6.78, by using prompt injection to manipulate LLM-generated Python code, leading to arbitrary code execution and exfiltration of environment secrets on the host system.

PraisonAI remote-code-execution prompt-injection llm ai vulnerability
1t 1c
critical advisory

PraisonAI SQL/CQL Injection via Unvalidated PGVector/Cassandra Dimension (CVE-2026-60090)

PraisonAI versions before 4.6.78 are vulnerable to SQL/CQL injection, allowing an attacker to inject malicious SQL/CQL tokens into generated CREATE TABLE DDL statements by influencing the unvalidated 'dimension' argument in PGVector and Cassandra knowledge-store backends, potentially leading to arbitrary database command execution and data manipulation or destruction.

PraisonAI before 4.6.78 sql-injection cql-injection data-destruction praisonai database-vulnerability
2t 1c
critical advisory

WordPress Super Forms Plugin Arbitrary File Upload (CVE-2026-14894)

An unauthenticated arbitrary file upload vulnerability (CVE-2026-14894) exists in the Super Forms - Drag & Drop Form Builder plugin for WordPress, affecting all versions up to and including 6.3.313, allowing unauthenticated attackers to upload executable files via the `submit_form` AJAX handler, leading to remote code execution after trivial nonce bypass.

PoC Super Forms – Drag & Drop Form Builder <= 6.3.313 +1 wordpress plugin arbitrary-file-upload rce web-exploit
1r 2t 1c 1i updated
critical advisory

CVE-2026-15282: WordPress Instant Appointment Plugin Arbitrary File Upload to RCE

An unauthenticated attacker can exploit CVE-2026-15282, an arbitrary file upload vulnerability due to missing file type validation in the `insapp_upload_image_as_attachment` function of the WordPress Instant Appointment plugin up to version 1.2, to upload malicious files and achieve remote code execution on the affected server.

PoC Instant Appointment Plugin <= 1.2 wordpress plugin vulnerability rce file-upload webserver
1r 2t 1c updated