Skip to content
Threat Feed

July 2026 (30)

high advisory

UsersWP Plugin Arbitrary File Deletion (CVE-2026-13492)

The UsersWP plugin for WordPress contains an Arbitrary File Deletion vulnerability, CVE-2026-13492, in versions up to and including 1.2.65, allowing an authenticated attacker with Subscriber-level access or higher to exploit insufficient validation in file-field values combined with an AJAX handler that lacks proper path canonicalization to delete arbitrary files on the server, including critical files like `wp-config.php`, leading to system impact.

UsersWP plugin <= 1.2.65 +1 wordpress plugin vulnerability web file-deletion remote-code-execution
1r 3t 1c
high advisory

FreePBX API and Backup Modules Vulnerabilities Allowing Authenticated RCE and SSH Key Injection

FreePBX has released security advisories to address critical vulnerabilities in its API and Backup modules, affecting FreePBX API (versions prior to 17.0.9) and FreePBX Backup (versions prior to 17.0.11), which include authenticated command injection and arbitrary SSH key injection leading to remote code execution and unauthorized access.

FreePBX API +1 freepbx vulnerability command-injection rce ssh-key-injection voip pbx linux
2t
high threat

UAT-7810 Expands ORB Networks with New Malware; ARToken Phishing-as-a-Service and Device Vulnerabilities Highlighted

The China-nexus threat actor UAT-7810 is expanding its Operational Relay Box (ORB) networks by exploiting known vulnerabilities in unpatched Ruckus and ASUS routers to deploy custom backdoors like LONGLEASH and DOGLEASH, while other threats include the ARToken Phishing-as-a-Service platform targeting Microsoft 365, critical flaws in AirDrop/Quick Share, and a backdoor in Tenda router firmware.

Ruckus routers +5 UAT-7810 China-nexus APT router-exploitation ORB-network backdoor phishing-as-a-service credential-theft data-exfiltration +3
10t 8i
high advisory

CVE-2026-58459 - gpsd gpsprof Command Injection

A command injection vulnerability, CVE-2026-58459, exists in the gpsprof utility of gpsd through version 3.27.5, allowing an attacker to exploit this by controlling the GPS device subtype value and embedding backtick payloads within the gnuplot plot title, which leads to arbitrary shell command execution as the user running gnuplot when a victim renders a generated plot via the gpsprof and gnuplot workflow due to improper escaping.

gpsd command-injection vulnerability execution linux macos
2r 1t 1c
high advisory

CVE-2026-15190: SQL Injection in SourceCodester Simple and Nice Shopping Cart Script

A critical SQL injection vulnerability (CVE-2026-15190) exists in SourceCodester Simple and Nice Shopping Cart Script version 1.0, allowing unauthenticated remote attackers to bypass authentication and potentially exfiltrate sensitive data by manipulating the 'Username' argument on the `/login.php` page, with a public exploit now available.

Simple and Nice Shopping Cart Script sql-injection web-application vulnerability cve
1r 3t 1c 3i
critical advisory

CVE-2026-9181: Unauthenticated Directory Traversal in ArcGIS Server

An unauthenticated attacker can exploit CVE-2026-9181, a critical directory traversal vulnerability in ArcGIS Server versions 12.0 and prior, by sending crafted path parameters to access sensitive files, leading to unauthorized information disclosure.

ArcGIS Server +17 directory-traversal web-vulnerability esri cve
2t 1i updated
high advisory

CVE-2026-11404: Cesanta Mongoose TLS Out-of-Bounds Read Leading to Denial of Service

Cesanta Mongoose before version 7.22 contains an out-of-bounds read vulnerability (CVE-2026-11404) in its built-in TLS server function, `mg_tls_server_recv_hello()`, allowing a remote, unauthenticated attacker to send a specially crafted TLS ClientHello message with an oversized session ID length, leading to a service crash and denial of service for HTTPS, MQTTS, or WSS services.

Mongoose denial-of-service vulnerability tls webserver firmware
1t 1c
medium advisory

Schneider Electric Easergy MiCOM Px40 Series Information Disclosure via Hard-coded Credentials (CVE-2026-4832)

Schneider Electric Easergy MiCOM Px40 Series products are vulnerable to CVE-2026-4832, a hard-coded credentials flaw (CWE-798) that allows unauthenticated attackers to interrogate the SNMP port and expose basic device identification information from critical manufacturing, energy, and transportation systems assets globally.

Easergy MiCOM P14x +25 ics ot scada vulnerability schneider-electric snmp cve-2026-4832 information-disclosure
2t 1c
critical advisory

OpenPLC v3 Arbitrary File Write Leads to Native Code Execution (CVE-2026-14480)

An authenticated arbitrary file write vulnerability (CVE-2026-14480) in OpenPLC v3's legacy web UI program-upload workflow allows attackers to write arbitrary files, escalating to arbitrary native code execution as the OpenPLC runtime user when an operator triggers program compilation.

OpenPLC v3 ics scada vulnerability rce authenticated-rce file-write cwe-73
3t
high threat

Multiple Vulnerabilities in Schneider Electric PowerChute Serial Shutdown

Multiple vulnerabilities, including CVE-2026-2399, CVE-2026-2404, CVE-2026-2405, CVE-2026-2403, CVE-2026-2400, and CVE-2026-2401, in Schneider Electric PowerChute Serial Shutdown versions 1.4 and prior could allow attackers with adjacent network access and high privileges to overwrite critical system files via path traversal, forge or inject malicious log data, gain unauthorized account access through excessive authentication attempts, trigger denial-of-service conditions, or expose sensitive information.

exploited PowerChute Serial Shutdown ics ot vulnerability path-traversal crlf-injection dos log-tampering critical-infrastructure
5t 5c
critical advisory

GigaWiper: Multi-Payload Destructive Backdoor

GigaWiper is a sophisticated, Golang-based destructive backdoor observed since October 2025 by Microsoft Threat Intelligence, that combines robust command-and-control (C2) capabilities with multiple destructive payloads, including physical disk wiping, ransomware-like encryption derived from Crucio, and multi-pass secure wiping reimplemented from FlockWiper.

Windows wiper destructive backdoor ransomware golang
3r 6t 2i
medium advisory

CVE-2026-60109 - Zeek Kerberos Protocol Analyzer Null Pointer Dereference

A null pointer dereference vulnerability (CVE-2026-60109) exists in Zeek's Kerberos protocol analyzer before version 8.0.9, allowing unauthenticated remote attackers to crash a Zeek sensor by sending a specially crafted KRB_ERROR message with error-code 25 and specific PA-DATA elements, leading to a denial-of-service condition.

Zeek vulnerability network dos kerberos
1t 1c
medium advisory

CVE-2026-60108 - Zeek FTP Analyzer Uncontrolled Memory Consumption leading to DoS

An uncontrolled memory consumption vulnerability in the Zeek FTP analyzer, versions prior to 8.0.9, allows unauthenticated remote attackers to cause process termination and denial of service of the Zeek sensor. This occurs when a crafted FTP control session with AUTH GSSAPI and a large ADAT control line exploits the NVT_Analyzer component's lack of a maximum line length check, leading to an unbounded internal buffer during base64 decoding.

Zeek cve dos network-protocol vulnerability
1t 1c
high advisory

Multiple Vulnerabilities Discovered in GitLab CE/EE

Multiple vulnerabilities have been discovered in GitLab Community Edition (CE) and Enterprise Edition (EE) across versions 19.0.x, 19.1.x, and 18.11.x, allowing an attacker to compromise data confidentiality, inject remote code via Cross-Site Scripting (XSS) (CVE-2026-11827), and bypass security policies (CVE-2026-13320).

GitLab Community Edition +5 web-application vulnerability gitlab xss data-leak
1t 5c
high advisory

Multiple Vulnerabilities Discovered in Wireshark Leading to DoS and Data Confidentiality Compromise

Multiple vulnerabilities (CVE-2026-15163 through CVE-2026-15174) have been discovered in Wireshark, impacting versions 4.6.x prior to 4.6.7 and versions prior to 4.4.17, which could allow a remote attacker to cause a denial of service and compromise data confidentiality.

Wireshark 4.6.x +1 vulnerability wireshark dos info-disclosure product-vulnerability
2t 5c
high advisory

Multiple Security Policy Bypass Vulnerabilities in Traefik Edge Router

Multiple vulnerabilities have been discovered in Traefik, affecting versions 3.6.x prior to 3.6.23, 3.7.x prior to 3.7.7, and versions prior to 2.11.52, which allow an attacker to bypass security policies, potentially leading to unauthorized access or actions.

Traefik < 3.6.23 +2 vulnerability policy-bypass Traefik edge-router
3i
high advisory

CVE-2026-4256 - PEAKUP PassGate LDAP Injection Vulnerability

A high-severity LDAP injection vulnerability, CVE-2026-4256, exists in PEAKUP Technology Inc.'s PassGate product through version 30042026, allowing an unauthenticated attacker to manipulate LDAP queries, potentially leading to high confidentiality impact and low integrity impact.

PassGate ldap-injection vulnerability web-application
4t 1c
medium advisory

AppLocker Audit Events Indicate Potential Policy Violations

This brief describes the detection of Windows AppLocker audit events (Event IDs 8003, 8006, 8021, 8024) that indicate applications, DLLs, scripts, MSIs, or packaged apps would have been blocked by an active AppLocker policy, providing insight into unauthorized software execution attempts or policy violations in audit mode.

AppLocker audit windows-security application-control
1r 6t
medium advisory

Ruby CSS Parser Vulnerable to SSRF and Local File Disclosure via `read_remote_file`

The `css_parser` library, specifically in versions up to and including 2.2.0, is vulnerable to Server-Side Request Forgery (SSRF) and local file disclosure through improper URI validation in the `CssParser::Parser#read_remote_file` method, allowing attackers to access internal network resources or read local files when processing attacker-controlled CSS.

css_parser <= 2.2.0 ssrf lfi supply-chain ruby vulnerability web-application
4t
high advisory

Craft CMS RCE via Missing cleanseConfig in FieldsController

An authenticated administrator in Craft CMS (versions 5.5.0 to 5.9.13) is vulnerable to Remote Code Execution (RCE) via a missing input sanitization vulnerability in the `actionRenderCardPreview()` method of `FieldsController`, allowing Yii2 event handler injection through specially crafted `fieldLayoutConfig` POST parameters, which enables arbitrary PHP code execution and sensitive information disclosure.

Craft CMS rce web-application cms craft-cms php
1r 1t
high advisory

Note Mark Path Traversal Vulnerability (CVE-2026-50553)

A low-privilege authenticated user can exploit CVE-2026-50553, a path traversal vulnerability in Note Mark versions up to v0.19.4, by crafting a malicious 'slug' parameter in API requests, leading to arbitrary file write outside the intended export directory when an administrator runs the 'migrate export' command, potentially allowing root-level privilege escalation and code execution.

Note Mark <= v0.19.4 path-traversal privilege-escalation web-application rce go linux
1r 4t
medium advisory

Soup Sieve Memory Exhaustion via Large Comma-Separated Selector Lists (CVE-2026-49476)

A memory exhaustion vulnerability (CVE-2026-49476) in the soupsieve CSS selector parser, an indirect dependency of Beautiful Soup 4, allows an unauthenticated attacker to cause a denial of service by supplying a crafted, large comma-separated CSS selector string to applications using `soupsieve.compile()` or Beautiful Soup's `.select()`/`.select_one()`, leading to unbounded memory allocation and system resource exhaustion.

soupsieve <= 2.8.3 +1 denial-of-service memory-exhaustion python supply-chain
1t
high advisory

Rival Espionage Actors Converge on Pakistani Law Enforcement

Suspected China- and India-nexus threat actors conducted separate cyberespionage operations against several Pakistani law enforcement organizations, including Balochistan Police, from February 2024 to April 2026, compromising web applications and network appliances with tools like PlugX, ShadowPad, Cobalt Strike, and Remcos to exfiltrate sensitive criminal and biometric data.

web applications +2 cyberespionage nation-state data-exfiltration web-application command-and-control malware
1r 7t 13i
high advisory

CVE-2026-9253: WordPress E&P Forms Plugin Stored Cross-Site Scripting

An unauthenticated attacker can inject arbitrary web scripts into WordPress sites running the 'WP Cost Estimation & Payment Forms Builder' plugin version 10.5.97 and earlier by exploiting CVE-2026-9253, a Stored Cross-Site Scripting vulnerability via the 'customerInfos' parameter, leading to script execution in users' browsers and potential session hijacking or data theft.

WP Cost Estimation & Payment Forms Builder wordpress xss web-vulnerability plugin
2t 1c
medium advisory

CVE-2026-59692: GStreamer DTLS Plugin Stack Buffer Overflow Leading to DoS

A stack buffer overflow vulnerability, CVE-2026-59692, exists in GStreamer's DTLS plugin, allowing a remote unauthenticated attacker to cause a denial of service by sending a crafted certificate with an oversized Subject Distinguished Name during a DTLS handshake, which the plugin prints into a fixed-size stack buffer without bounds checking, leading to a process crash.

DTLS plugin +2 denial-of-service buffer-overflow vulnerability dtls gstreamer linux high_confidence_source watchlist_match
2t 1c
high advisory

CVE-2026-59691: GStreamer rfbsrc Heap Buffer Overflow Leads to DoS

A heap buffer overflow vulnerability (CVE-2026-59691) exists in GStreamer's rfbsrc plugin, allowing a malicious RFB/VNC server to trigger an out-of-bounds heap write in connecting clients, leading to denial of service and potential memory corruption.

GStreamer rfbsrc plugin +2 vulnerability heap-overflow denial-of-service gstreamer linux red-hat cve
1t 1c
high advisory

CVE-2026-4275 - The Divi Torque Lite - Divi Theme, Divi Builder & Extra Theme plugin for WordPress is vulnerable to CSRF

The Divi Torque Lite plugin for WordPress, in versions up to 4.2.3, is vulnerable to Cross-Site Request Forgery (CVE-2026-4275), allowing an unauthenticated attacker to exploit inadequate nonce verification on the /install_plugin and /activate_plugin REST API endpoints to install arbitrary WordPress plugins, potentially leading to remote code execution or further system compromise.

Divi Torque Lite plugin for WordPress web vulnerability wordpress csrf cve
1r 1t 1c
high advisory

CVE-2026-14372 - The Bit Form WordPress Plugin Arbitrary File Deletion

The Bit Form WordPress plugin (versions up to 3.1.1) is vulnerable to arbitrary file deletion due to insufficient file path validation, allowing authenticated attackers with subscriber-level access to delete critical server files like wp-config.php, potentially leading to remote code execution.

The Bit Form – Contact Form, Payment Forms, Multi Step Forms, Calculator & Custom Form Builder plugin for WordPress wordpress plugin vulnerability web rce file-deletion
3t 1c
high advisory

EventPrime WordPress Plugin Stored XSS (CVE-2026-13441)

A critical stored Cross-Site Scripting (XSS) vulnerability, CVE-2026-13441, exists in all versions up to 4.3.4.2 of the EventPrime - Events Calendar, Bookings and Tickets plugin for WordPress, allowing authenticated attackers with custom-level access (or unauthenticated attackers if 'Guest Submissions' is enabled) to inject malicious web scripts via the new_event_type_background_color parameter that execute whenever a user accesses an affected page, potentially leading to session hijacking, defacement, or further compromise.

EventPrime – Events Calendar, Bookings and Tickets plugin web-vulnerability wordpress xss plugin
1r 2t 1c
high advisory

rclone: Multiple Vulnerabilities

A remote, authenticated attacker can exploit multiple vulnerabilities in rclone to gain unauthorized capabilities, allowing them to read and write arbitrary files on the system, disclose sensitive information, and bypass existing security mechanisms, potentially leading to data compromise or system integrity issues.

rclone vulnerability data-exfiltration impact
5t