July 2026 (30)
CVE-2026-29008: U-Boot Integer Underflow Leads to Bootloader Crash
1 TTP 1 CVEAn integer underflow vulnerability (CVE-2026-29008) in U-Boot's `tcp_rx_state_machine()` function allows a network-adjacent attacker to crash the bootloader by sending a crafted TCP SYN+ACK packet, potentially preventing device boot and leading to memory corruption.
Detecting Hostile Prompt Sentiment in AWS Bedrock Claude
1 ruleThis brief outlines the detection of hostile or aggressive prompt sentiment sent to AWS Bedrock Claude large language models, indicating potential abuse, harassment, or attempts at model manipulation, requiring the configuration of Bedrock model invocation logging and Splunk ingestion.
CVE-2026-3144 - IBM API Connect Default Credentials Vulnerability
1 TTP 1 CVEIBM API Connect versions 12.1.0.0 through 12.1.0.3 are vulnerable to unauthorized access due to the use of default credentials, allowing an attacker to gain initial access to the application before the system enforces a credential update.
Unauthenticated SQL Injection in IBM API Connect (CVE-2026-9074)
1 rule 3 TTPs 1 CVEIBM API Connect versions 10.0.8.0 through 10.0.8.9 and 12.1.0.0 through 12.1.0.3 are vulnerable to an unauthenticated SQL injection (CVE-2026-9074) in the password reset functionality, potentially leading to unauthorized data access or authentication bypass.
CVE-2026-59702: repomix Server-Side Request Forgery
1 rule 4 TTPs 1 CVEAn unauthenticated server-side request forgery (SSRF) vulnerability, CVE-2026-59702, in repomix's POST /api/pack endpoint allows attackers to make arbitrary outbound requests, potentially leading to internal network reconnaissance, access to cloud metadata services, and local filesystem path enumeration.
CVE-2026-0284 PAN-OS: XML Injection Vulnerability in Large Scale VPN (LSVPN)
3 TTPsAn XML injection vulnerability (CVE-2026-0284) in the Large Scale VPN (LSVPN) functionality of Palo Alto Networks PAN-OS software allows an unauthenticated attacker with network access to inject malicious XML content, potentially leading to information disclosure or corruption of internal LSVPN satellite data.
CVE-2026-0286 PAN-OS: Authenticated Command Injection in CLI
3 TTPsA command injection vulnerability, CVE-2026-0286, in the management plane of Palo Alto Networks PAN-OS software allows an authenticated administrator to execute arbitrary OS commands as root on PA-Series and VM-Series firewalls and Panorama (virtual and M-Series) devices, potentially leading to high system compromise.
CVE-2026-0280 PAN-OS: IPv6 Firewall Policy Bypass
1 TTPAn unauthenticated attacker can exploit CVE-2026-0280, an IPv6 packet processing vulnerability in the dataplane of Palo Alto Networks PAN-OS software, to bypass firewall security policy enforcement, allowing network traffic that should be blocked to reach protected services.
CVE-2026-0285 PAN-OS: Server-Side Request Forgery Vulnerability in Management Web Interface
3 TTPsA server-side request forgery (SSRF) vulnerability, tracked as CVE-2026-0285, exists in the management web interface of Palo Alto Networks PAN-OS software, allowing an authenticated administrator with network access to make unauthorized requests from the firewall to internal services, potentially leading to information disclosure or further network compromise.
CVE-2026-0276: Palo Alto Networks Cortex XDR Broker VM Privilege Escalation
1 TTPA local privilege escalation vulnerability, CVE-2026-0276, in Palo Alto Networks Cortex XDR Broker VM allows a locally authenticated low-privileged user to gain root access, potentially leading to compromise of the security solution itself.
CVE-2026-0288 PAN-OS: Buffer Overflow Vulnerabilities in User-ID Terminal Server Agent
3 TTPsPalo Alto Networks has disclosed multiple buffer overflow vulnerabilities (CVE-2026-0288) in their PAN-OS User-ID Terminal Server Agent (TSA) component, which an unauthenticated attacker with network access can exploit by sending specially crafted network traffic to cause a denial of service (DoS) or potentially achieve arbitrary code execution, affecting various versions of PAN-OS, Cloud NGFW, and Prisma Access if the TSA is exposed to untrusted networks.
CVE-2026-0283: Authentication Bypass in Palo Alto Networks PAN-OS Large Scale VPN (LSVPN)
1 TTPAn authentication bypass vulnerability, CVE-2026-0283, in Palo Alto Networks PAN-OS software allows an unauthenticated attacker with network access to establish an unauthorized site-to-site VPN connection when LSVPN functionality with configured satellites is enabled, leading to potential access to internal network resources.
CVE-2026-0279 PAN-OS: Multiple Cross-Site Scripting (XSS) Vulnerabilities
2 TTPsPalo Alto Networks has disclosed multiple low-severity cross-site scripting (XSS) vulnerabilities, CVE-2026-0279, in PAN-OS software affecting the User-ID Authentication Portal, GlobalProtect gateway/portal features, and Clientless VPN, which could allow a malicious unauthenticated user to inject and execute JavaScript in a victim's browser.
CVE-2026-0278 Prisma Access Agent: Multiple DLP Policy Bypass Vulnerabilities on Windows
1 TTPCVE-2026-0278 describes multiple protection mechanism failures in the Prisma Access Agent's Data Loss Prevention (DLP) component for Windows, allowing a local user to bypass DLP policy enforcement controls and exfiltrate sensitive data on affected versions prior to 26.2.1.
CVE-2026-0281 PAN-OS: Information Disclosure Vulnerability in Management Web Interface
2 TTPsAn information disclosure vulnerability (CVE-2026-0281) in Palo Alto Networks PAN-OS software allows an unauthenticated attacker to obtain web session tokens via user interaction with a malicious link, potentially leading to unauthorized access to the management interface.
CVE-2026-0277 Prisma Access Agent: Improper Certificate Validation on iOS
1 TTPAn improper certificate validation vulnerability (CVE-2026-0277) in the Prisma Access Agent for iOS, affecting versions prior to 26.2.1, enables an attacker to perform a man-in-the-middle (MitM) attack to intercept VPN traffic, leading to potential compromise of data confidentiality and integrity.
CVE-2026-0287 PAN-OS: Denial of Service Vulnerabilities in Network Traffic Processing
1 TTPMultiple denial of service vulnerabilities, tracked as CVE-2026-0287, in Palo Alto Networks PAN-OS software allow an unauthenticated attacker to cause a DoS condition by sending specially crafted network traffic, potentially forcing the firewall into maintenance mode.
CVE-2026-0282 PAN-OS: Unauthenticated File Deletion Vulnerability
An unauthenticated attacker with network access to the management web interface of Palo Alto Networks PAN-OS software can exploit CVE-2026-0282, a file deletion vulnerability, to delete files from a temporary directory, impacting PA-Series and VM-Series firewalls, and Panorama appliances.
HAProxy CVE-2021-40346 Integer Overflow Leading to HTTP Request Smuggling and ACL Bypass
2 TTPs 1 CVEA critical integer overflow vulnerability, CVE-2021-40346, in HAProxy's `htx_add_header()` function allows unauthenticated attackers to bypass access control rules by crafting HTTP requests with specific header name lengths, leading to HTTP request smuggling and unauthorized access to backend paths, for which a public exploit is available.
CVE-2026-59703: repomix Local File Inclusion Vulnerability
1 rule 2 TTPs 1 CVErepomix contains a local file inclusion vulnerability (CVE-2026-59703) in its git clone endpoint, allowing unauthenticated attackers to read arbitrary local git repositories and server filesystem contents by bypassing validation with crafted file:// URLs.
Multiple Critical Vulnerabilities in Ubiquiti UniFi OS
2 rules 1 TTP 5 CVEs 1 IOCUbiquiti has addressed multiple critical vulnerabilities including CVE-2026-34908, CVE-2026-34909, CVE-2026-34910, and CVE-2026-33000 in UniFi OS, which could allow remote attackers to make unauthorized system changes, access sensitive files, disclose information, or execute arbitrary commands on vulnerable systems.
Armored Likho APT Leverages BusySnake Stealer with AI-Generated Loaders and Phishing
2 rules 10 TTPsThe Armored Likho APT group is conducting a spear-phishing campaign against government and energy sectors in Russia, Kazakhstan, and Brazil, using AI-generated loaders and the Python-based BusySnake Stealer to exfiltrate credentials and sensitive data.
CVE-2026-58656 - Grav API Plugin Cross-Origin Authentication Bypass and Account Takeover
1 rule 3 TTPs 1 CVEA critical vulnerability, CVE-2026-58656, in the Grav API plugin before v1.0.0-rc.16 allows unauthenticated attackers to perform fully authenticated cross-origin API requests by leveraging leaked JWT tokens via the `?token=` URL query parameter and the `Access-Control-Allow-Origin: *` response header, potentially leading to persistent backdoor super-admin accounts and sensitive data exfiltration.
CVE-2026-56776 - n8n Authorization Bypass via Workflow Test Run Endpoint
1 rule 3 TTPs 1 CVEAn authenticated user can exploit CVE-2026-56776, an authorization bypass vulnerability in n8n versions prior to 1.123.55, 2.25.7, and 2.26.2, by sending a POST request to the `/workflows/{workflowId}/test-runs/new` endpoint to trigger unauthorized workflow execution, leading to unintended outbound API calls, data mutations, and other side effects in connected downstream systems.
CVE-2026-56297 - FreeRDP Use-After-Free Vulnerability Leading to RCE/DoS
2 TTPs 1 CVEA use-after-free vulnerability (CVE-2026-56297) in the FreeRDP client before version 3.22.0 allows a malicious RDP server to achieve remote code execution or denial of service on connecting clients by triggering a race condition through concurrent DYNVC_DATA and DYNVC_CLOSE messages.
CVE-2026-56250: Capgo R2 Bundle Object Deletion via Mutable r2_path
2 TTPs 1 CVE 2 IOCsA critical vulnerability, CVE-2026-56250, in Capgo before version 12.128.2 allows an authenticated attacker with upload-scoped API keys to manipulate the app_versions.r2_path field via PostgREST, leading to arbitrary R2 bundle object deletion and denial of service.
CVE-2026-56246 - Capgo Broken Access Control in Organization Management API
3 TTPs 1 CVECapgo versions prior to 12.128.2 contain a broken access control vulnerability (CVE-2026-56246) in their organization management API where a scoped API key inherits the full permissions of its owner-user, allowing an attacker to perform destructive operations against unauthorized organizations, bypassing intended scope and leading to privilege escalation and impact.
CVE-2026-56226 - Capgo Unauthenticated Data Exposure via Supabase PostgREST RPC
1 rule 2 TTPs 1 CVECVE-2026-56226 details a high-severity vulnerability in Capgo versions prior to 12.128.2 that exposes a Supabase PostgREST RPC function, `public.get_orgs_v6`, to unauthenticated attackers, allowing them to retrieve sensitive user organization membership and PII by supplying an arbitrary user UUID.
Multiple Vulnerabilities Discovered in Joomla! CMS
4 TTPs 5 CVEs 24 IOCsMultiple vulnerabilities, including several Cross-Site Scripting (XSS) flaws and incorrect access control issues, have been discovered in Joomla! versions 6.x prior to 6.1.2 and 5.x prior to 5.4.7, which could allow an attacker to bypass security policies, compromise data confidentiality and integrity, and perform remote indirect code injection.
Multiple Vulnerabilities in Foxit PDF Editor and Reader
3 TTPs 5 CVEsMultiple critical vulnerabilities, including CVE-2026-13126 and CVE-2026-13127, have been discovered in Foxit PDF Editor and Reader for Windows and macOS, enabling a remote attacker to achieve arbitrary code execution, elevate privileges, and compromise data confidentiality if users open a crafted malicious PDF document.