Skip to content
Threat Feed

July 2026 (30)

medium advisory

CVE-2026-47241: Net::IMAP Denial of Service Vulnerability

A Denial of Service vulnerability, identified as CVE-2026-47241, exists in the Net::IMAP library due to incomplete raw argument validation, potentially allowing an attacker to cause an application crash or unresponsiveness.

Net::IMAP denial-of-service vulnerability imap
1c
medium advisory

Divi Form Builder Missing Authorization Vulnerability (CVE-2026-5523) Leads to Account Takeover

The Divi Form Builder plugin for WordPress versions up to 5.1.8 is vulnerable to Missing Authorization, allowing authenticated attackers with subscriber-level access to change the email and password of any user, including administrators, by exploiting improper authorization checks in the update_user() and handle_register_submission() functions, enabling complete account takeover.

Divi Form Builder plugin <= 5.1.8 wordpress plugin vulnerability web-application account-takeover missing-authorization
3t 1c
high advisory

Claude Code Sandbox Escape via Symlink Following

A sandbox escape vulnerability in Claude Code allowed writing arbitrary files outside the workspace by creating symlinks from within the sandbox that were followed by unsandboxed processes, potentially leading to code execution outside the sandbox.

PoC Claude Code +8 sandbox-escape symlink arbitrary-file-write
2r 2t 1c updated
high advisory

Vite Dev Server `server.fs.deny` Bypass on Windows (CVE-2026-53571)

A high-severity vulnerability (CVE-2026-53571) in the Vite development server on Windows allows threat actors to bypass `server.fs.deny` restrictions, leading to information disclosure of sensitive files like `.env` or `tls.pem` via crafted HTTP requests utilizing NTFS Alternate Data Streams or 8.3 short names, impacting applications that expose the dev server to the network.

PoC Vite +4 information-disclosure bypass web-vulnerability windows development-server
2r 1t 1c 3i updated
high threat

CVE-2026-15137: Remote SQL Injection in code-projects Interview Management System

A critical SQL injection vulnerability (CVE-2026-15137) has been identified in code-projects Interview Management System version 1.0, allowing remote unauthenticated attackers to manipulate the 'ID' argument in the '/inc/classes/View.php' file, leading to arbitrary SQL query execution and potential data compromise; a public exploit is available.

exploited Interview Management System 1.0 sql-injection webserver vulnerability cve code-projects interview-management-system
1r 2t 1c 6i
high threat

CVE-2026-15135 - SQL Injection in code-projects Online Food Order System

A high-severity SQL injection vulnerability, CVE-2026-15135, exists in code-projects Online Food Order System 1.0 affecting the `/edit_food_items.php` file's 'update' argument, allowing remote attackers to perform unauthorized data disclosure or manipulation, with a public exploit available.

exploited Online Food Order System 1.0 web-exploitation sql-injection cve data-exfiltration data-manipulation
1r 3t 1c 7i
high advisory

CVE-2026-15134: SQL Injection in CodeAstro Simple Online Leave Management System

A high-severity SQL injection vulnerability (CVE-2026-15134) in CodeAstro Simple Online Leave Management System 1.0, specifically within the '/SimpleOnlineLeave/index.php' file, allows a remote unauthenticated attacker to execute arbitrary SQL commands by manipulating the 'email' argument, leading to unauthorized database access and data compromise, with a public exploit available.

Simple Online Leave Management System 1.0 sql-injection web-application cve remote-code-execution data-exfiltration
1r 2t 1c
medium advisory

Detection of Failed WMI Event Log Clear Attempts

This brief details the detection of failed attempts by an adversary to clear Windows event logs using the WMI `ClearEventLog` method, indicating an unsuccessful defense impairment action due to insufficient privileges or other issues.

defense-evasion host-activity windows
1r 1t
low advisory

macOS Local System Accounts Discovery

Adversaries leverage various built-in macOS utilities and commands, such as `dscl`, `dscacheutil`, `cat /etc/passwd`, `id`, `lsof`, `who`, `w`, `users`, `last`, `ls /Users`, `defaults`, and `plutil`, to enumerate local system accounts, facilitating lateral movement or privilege escalation within a compromised macOS environment.

macOS discovery reconnaissance
1r 1t
high advisory

AWS Bedrock API Key Phantom User Activity Outside Bedrock

An Amazon Bedrock API key phantom user (IAM user starting with 'BedrockAPIKey-*') performing non-Bedrock API calls, such as to IAM, STS, EC2, VPC, or KMS, indicates credential misuse and realized privilege escalation by an attacker using added standard IAM access keys for reconnaissance or lateral movement beyond the intended Bedrock authentication boundary.

AWS Bedrock +5 cloud-security privilege-escalation aws bedrock iam
1r 1t
high advisory

CVE-2026-60105: Monsta FTP SSRF Vulnerability Leading to Credential Disclosure

An unauthenticated attacker can exploit CVE-2026-60105, a Server-Side Request Forgery vulnerability in Monsta FTP before 2.14.5, by leveraging an incomplete IP blocklist check with IPv4-mapped IPv6 addresses to force the server to issue HTTP requests to internal services and write responses to an attacker-controlled FTP destination, potentially enabling retrieval of cloud instance metadata credentials.

Monsta FTP < 2.14.5 server-side-request-forgery vulnerability web-application credential-access
1r 2t 1c
high advisory

NL Portal IDOR Vulnerability Allows Tampering and Data Leakage of Other Users' Tasks (CVE-2026-49464)

An Insecure Direct Object Reference (IDOR) vulnerability, CVE-2026-49464, in NL Portal's Taak V2 implementation (versions 1.5.0 through 3.0.0) allows authenticated attackers to mark other users' tasks as complete, overwrite submitted data, and leak personal information by exploiting an authorization bypass in the `submitTaakV2` GraphQL endpoint.

NL Portal Taak idor graphql data-tampering data-leakage authentication-bypass cve
2t
high advisory

Serena Agent Unauthenticated RCE via DNS Rebinding (CVE-2026-49471)

An unspecified attacker can achieve remote code execution in Serena agent versions prior to 1.5.2 by leveraging an unauthenticated Flask dashboard, DNS rebinding, and memory poisoning, enabling persistent attacker-controlled command execution.

serena-agent remote-code-execution dns-rebinding persistence command-and-control python flask agent
1r 6t 1c 1i
critical advisory

Joro: Unauthenticated Cross-Origin Plugin Upload Leads to RCE

Joro's default proxy mode (versions ≤ v1.1.0) is vulnerable to unauthenticated remote code execution (CVE-2026-53649) via a local API on `127.0.0.1:9090` that allows cross-origin JavaScript to upload a malicious native plugin and trigger a system restart, leading to RCE as the operator's user from a single page visit.

Joro rce web-exploitation vulnerability javascript cross-origin cors
2r 5t 1i
high advisory

DSpace RCE via Velocity Templates (CVE-2026-49832)

DSpace versions 8.0 through 8.3, 9.0 through 9.2, and 10.0-rc1 are vulnerable to Remote Code Execution (RCE) via Velocity Templates used for COAR Notify/LDN messages, allowing an attacker with DSpace administrator credentials to execute direct Java code using reflection, a high-impact vulnerability that can be chained with a related path traversal attack (GHSA-9qm4-rh6w-pq5x).

DSpace +7 rce web-application vulnerability
1t
high advisory

`lxml_html_clean` `javascript:` URL Bypass via `xlink:href` (CVE-2026-49825)

The `lxml_html_clean.Cleaner` Python library, and the `lxml.html.clean` module in `lxml`, fails to strip `javascript:`, `vbscript:`, and `data:` URLs from namespaced attributes like `xlink:href` when configured with `safe_attrs_only=False`. This vulnerability, identified as CVE-2026-49825, is a form of stored Cross-Site Scripting (XSS) that allows malicious JavaScript to bypass sanitization, enabling client-side code execution if an application processes and renders untrusted HTML containing such payloads.

lxml <= 6.1.0 +2 xss vulnerability python web-application html-sanitization
2t
high advisory

Zalando Skipper OPA Policy Bypass via Chunked Encoding

A critical vulnerability in `zalando/skipper`'s OpenPolicyAgent integration, tracked as GHSA-659f-rgp5-w4wf, allows attackers to bypass `opaAuthorizeRequestWithBody` policies using HTTP/1.1 `Transfer-Encoding: chunked` or HTTP/2 requests lacking a `content-length` pseudo-header, leading to unauthorized access to upstream services with uninspected payloads.

skipper vulnerability api-gateway security-bypass opa network
1r 1t
critical advisory

Nuclio Controller Vulnerability Leads to Persistent Kubernetes RCE (GHSA-v5px-423j-pf7p)

The Nuclio controller improperly sanitizes user-controlled input (cron trigger event headers and body) before injecting it into `curl` commands executed by Kubernetes CronJobs, allowing remote attackers to perform command injection and achieve remote code execution (RCE) by breaking quoting contexts in header keys or utilizing shell command substitution in event bodies, leading to arbitrary command execution with root privileges and potential persistence within the Kubernetes cluster.

Nuclio <= 1.15.27 remote-code-execution kubernetes cloud-native command-injection persistence critical-vulnerability ghsa
2r 3t 2i
high advisory

CVE-2026-60104 - Bitwarden Server Vault Key Disclosure and Account Takeover

A low-privileged Bitwarden organization member can exploit CVE-2026-60104 in Bitwarden Server versions prior to 2026.6.0, which allows an attacker to obtain another user's vault key and access token by creating a Trusted Device Encryption authentication request bound to an attacker-controlled public key, leading to account takeover.

Bitwarden Server < 2026.6.0 vulnerability cve account-takeover credential-access data-disclosure bitwarden
7t 1c
high advisory

Gradio Open Redirect and Server-Side Request Forgery (SSRF) Vulnerability (CVE-2026-59806)

Gradio versions before 6.20.0 contain an open redirect and server-side request forgery (SSRF) vulnerability, CVE-2026-59806, allowing attackers to redirect users or perform client-side SSRF by supplying unvalidated HTTP/HTTPS URLs to the `/gradio_api/file=` endpoint, potentially leading to the retrieval of sensitive credentials, such as EC2 IAM role credentials.

Gradio < 6.20.0 web-vulnerability ssrf open-redirect credential-access cloud gradio
1r 2t 1c
medium advisory

CVE-2026-59803: rpcx Denial-of-Service Vulnerability

A denial-of-service vulnerability (CVE-2026-59803) in rpcx through version 1.9.3 allows an unauthenticated attacker to trigger out-of-memory conditions and service unavailability by sending a small, compressed message that expands to gigabytes of memory during decompression.

rpcx <= 1.9.3 denial-of-service vulnerability rpcx go-lang
1t 1c
high advisory

CVE-2026-59802 - PasswordPusher Data URI Scheme Vulnerability Leading to Client-Side JavaScript Execution

PasswordPusher versions prior to 2.8.1 contain a client-side vulnerability (CVE-2026-59802) due to insufficient validation of URL push payloads, allowing attackers to embed malicious data URI schemes that execute arbitrary JavaScript in victims' browsers when clicked, enabling phishing and credential theft under the trusted PasswordPusher domain.

PasswordPusher vulnerability web-application client-side javascript credential-theft phishing
3t 1c
high advisory

Progress MOVEit Transfer Critical Security Advisory (AV26-678)

Progress Software has issued a critical security advisory (AV26-678) detailing multiple vulnerabilities, including CVE-2026-10699, CVE-2026-10698, and CVE-2026-11903, affecting various versions of its MOVEit Transfer product, necessitating immediate patching to prevent potential exploitation.

MOVEit Transfer +3 vulnerability cve data-exfiltration critical-vulnerability moveit
3c
critical advisory

Critical SQL Injection Vulnerability in Drupal Location Selector Module (SA-CONTRIB-2026-072)

A critical SQL Injection vulnerability (SA-CONTRIB-2026-072) has been identified in Drupal's Location Selector module, affecting versions prior to 1.3.0, allowing unauthenticated attackers to execute arbitrary SQL commands and potentially leading to unauthorized data access, modification, or deletion.

Location Selector module < 1.3.0 sql-injection web-application drupal
1r 3t
high advisory

Juniper Networks Releases Security Advisories for Multiple Vulnerabilities, Including Heap Buffer Overflow and Memory Leak

Juniper Networks has released security advisories to address multiple vulnerabilities across several products, including Juniper cRPD, CTPView, Network Director, Junos OS, Junos OS Evolved, Junos OS on MX Series with SPC3 and SRX Series, and Junos Space, with key vulnerabilities like a heap buffer overflow (CVE-2020-7450) and a memory leak (CVE-2026-33799) potentially leading to arbitrary code execution or denial of service.

Juniper cRPD +6 vulnerability network-device juniper patch-management
2t 1c
critical advisory

Cisco IOS XE Web UI Implant Access via CVE-2023-20198

Exploitation of the Cisco IOS XE Web UI vulnerability (CVE-2023-20198) through crafted POST requests to obtain unauthorized access and maintain persistence on compromised devices.

PoC IOS XE cisco-ios-xe web-ui cve-2023-20198 implant
2r 1t 1c 4i updated
high advisory

CVE-2026-60102: Horde VFS OS Command Injection Vulnerability

CVE-2026-60102 describes an OS command injection vulnerability in the Horde Virtual File System (VFS) API before version 3.0.1, specifically within the Horde_Vfs_Smb driver, which allows authenticated attackers to inject arbitrary shell commands via user-controlled filenames during file operations, leading to arbitrary command execution on the underlying system.

Horde Virtual File System os-command-injection rce webserver horde cve
1r 1t 1c
high advisory

CVE-2026-59261 - OpenClaw Credential Exposure via Workspace Dotenv Files

A critical vulnerability, CVE-2026-59261, in OpenClaw before version 2026.5.28, allows attackers with lower-trust access to configured input paths to expose sensitive provider credentials by leveraging workspace dotenv files that override legitimate configurations, leading to unauthorized access to sensitive data.

OpenClaw credential-exposure vulnerability configuration-error
1t 1c
high advisory

CVE-2026-29009 - U-Boot Buffer Overflow in nfs_readlink_reply()

A buffer overflow vulnerability exists in the nfs_readlink_reply() function of U-Boot versions up to 2026.04-rc3 when CONFIG_CMD_NFS is enabled, allowing a malicious or compromised NFS server to exploit it by sending multiple relative symlink targets, each approximately 1100 bytes long, to overflow the 2048-byte nfs_path_buff, corrupting adjacent BSS variables and potentially leading to memory corruption and control over the NFS client's state machine.

U-Boot <= 2026.04-rc3 buffer-overflow vulnerability firmware nfs u-boot
1c
high advisory

CVE-2026-29008: U-Boot Integer Underflow Leads to Bootloader Crash

An integer underflow vulnerability (CVE-2026-29008) in U-Boot's `tcp_rx_state_machine()` function allows a network-adjacent attacker to crash the bootloader by sending a crafted TCP SYN+ACK packet, potentially preventing device boot and leading to memory corruption.

U-Boot denial-of-service vulnerability bootloader network embedded-systems
1t 1c