Skip to content
Threat Feed

July 2026 (30)

high advisory

Multiple Vulnerabilities in Foxit PDF Editor and Reader

Multiple critical vulnerabilities, including CVE-2026-13126 and CVE-2026-13127, have been discovered in Foxit PDF Editor and Reader for Windows and macOS, enabling a remote attacker to achieve arbitrary code execution, elevate privileges, and compromise data confidentiality if users open a crafted malicious PDF document.

PDF Editor +3 client-side-exploitation document-exploit pdf rce privilege-escalation data-exfiltration windows macos
3t 5c
high advisory

CVE-2026-12957: Amazon Q VS Code Extension Arbitrary Code Execution

A high-severity vulnerability (CVE-2026-12957) in the Amazon Q Developer Extension for Visual Studio Code allowed attackers to achieve arbitrary code execution and cloud credential theft by automatically loading and executing malicious Model Context Protocol (MCP) server configurations from a `.amazonq/mcp.json` file in a repository without user consent, providing full access to a developer's environment and cloud credentials.

PoC Amazon Q Developer Extension for Visual Studio Code +18 vulnerability code-editor cloud rce vs-code supply-chain
1r 4t 5c 2i updated
high advisory

Krayin CRM v2.2.x Authenticated Remote Code Execution Exploit

A public exploit (EDB-52629) has been released for Krayin CRM v2.2.x, demonstrating an authenticated remote code execution vulnerability that allows an authenticated attacker to execute arbitrary code on the underlying system, significantly increasing the risk for unpatched deployments of the web application.

Krayin CRM v2.2.x webapps rce exploit-db krayin-crm crm
1t
high advisory

Joomla Page Builder CK Arbitrary File Upload (EDB-52626)

A public exploit has been released for an arbitrary file upload vulnerability in Joomla Page Builder CK version 3.5.10, which allows an unauthenticated attacker to upload malicious files to the server, potentially leading to remote code execution and full system compromise.

Joomla Page Builder CK 3.5.10 webapps arbitrary-file-upload joomla remote-code-execution
3t
high advisory

CVE-2026-5356: LatePoint WordPress Plugin Improper Input Validation Leading to Arbitrary Payments

An improper input validation vulnerability (CVE-2026-5356) in the LatePoint - Calendar Booking Plugin for Appointments and Events for WordPress, versions up to and including 5.4.0, allows unauthenticated attackers to exploit its Stripe Connect payment processor by supplying a previously succeeded PaymentIntent ID, resulting in the processing of arbitrary payments.

LatePoint – Calendar Booking Plugin for Appointments and Events wordpress plugin vulnerability webserver cve
2t 1c
critical advisory

Critical SQL Injection in Webbeyaz Web Design Mediküm Web (CVE-2026-8307)

A critical SQL injection vulnerability (CVE-2026-8307) in Webbeyaz Web Design's Mediküm Web product, affecting all versions through 2026-07-08, allows unauthenticated attackers to execute arbitrary SQL commands, potentially leading to full compromise of confidentiality, integrity, and availability, with the vendor stating the product is unsupported.

Mediküm Web sql-injection web-application critical-vulnerability cve
1r 1t 1c
high advisory

CVE-2026-6230: Tainacan WordPress Plugin SQL Injection Vulnerability

An unauthenticated attacker can exploit CVE-2026-6230, a time-based blind SQL Injection vulnerability in the Tainacan plugin for WordPress (versions up to and including 1.0.3) via the 'geoquery' parameter, to append arbitrary SQL queries and exfiltrate sensitive information from the database due to insufficient input validation.

Tainacan plugin wordpress sql-injection webserver vulnerability cve
1r 1t 1c
high advisory

CVE-2026-6854 - WordPress My Calendar Plugin Time-Based Blind SQL Injection

A time-based blind SQL Injection vulnerability exists in the My Calendar - Accessible Event Manager plugin for WordPress, affecting all versions up to and including 3.7.8. This flaw, located in the 'mc_auth' parameter, stems from insufficient input sanitization and improper SQL query preparation, allowing unauthenticated attackers to inject additional SQL queries to extract sensitive information from the underlying database.

My Calendar - Accessible Event Manager plugin <= 3.7.8 wordpress sql-injection vulnerability web-application collection initial-access
1r 2t 1c
high advisory

CVE-2026-6818: VikBooking WordPress Plugin Stored XSS Vulnerability

A stored cross-site scripting vulnerability (CVE-2026-6818) exists in the VikBooking Hotel Booking Engine & PMS plugin for WordPress, affecting versions up to and including 1.8.8, caused by insufficient input sanitization of the 'special_requests' parameter, enabling unauthenticated attackers to inject arbitrary web scripts that execute whenever a user accesses an affected page, potentially leading to unauthorized data access, session hijacking, or defacement.

VikBooking Hotel Booking Engine & PMS plugin < 1.8.9 wordpress plugin xss web-vulnerability cms
1r 5t 1c
high advisory

CVE-2026-3688: WordPress WCFM Membership Plugin Insecure Direct Object Reference

Authenticated attackers with vendor-level access can exploit an Insecure Direct Object Reference (IDOR) vulnerability (CVE-2026-3688) in the WCFM Membership - WooCommerce Memberships for Multivendor Marketplace plugin for WordPress to change any user's role to 'wcfm_vendor' by manipulating membership plans, leading to unauthorized privilege escalation.

WCFM Membership – WooCommerce Memberships for Multivendor Marketplace < 2.11.10 wordpress web vulnerability idor privilege-escalation
2t 1c
high advisory

Multiple Vulnerabilities in IBM Operational Decision Manager

Multiple vulnerabilities in IBM Operational Decision Manager can be exploited by a remote, unauthenticated attacker, allowing them to bypass security restrictions, achieve remote code execution, and cause a denial of service condition.

IBM Operational Decision Manager vulnerability rce dos ibm security-bypass
4t
high threat

Red Hat Enterprise Linux (389-ds-base): Multiple Vulnerabilities Allow Code Execution and DoS

Multiple vulnerabilities in Red Hat Enterprise Linux and the 389-ds-base component allow a remote, authenticated attacker to execute arbitrary code or cause a Denial-of-Service condition.

exploited Red Hat Enterprise Linux +1 linux vulnerability code-execution denial-of-service red-hat
2t
high advisory

X.Org X11 and Xwayland Multiple Vulnerabilities Allowing Code Execution and DoS

Multiple vulnerabilities in X.Org X11 and Xwayland allow an attacker to cause a denial of service or potentially execute arbitrary program code, posing a significant risk to systems utilizing these display server implementations, potentially leading to system instability or full compromise.

X.Org X11 +1 vulnerability linux x.org x11 xwayland denial-of-service code-execution
2t
high threat

UAT-7810 Expands ORB Networks with New Custom Malware: LONGLEASH, DOGLEASH, and JARLEASH

China-nexus APT actor UAT-7810 is actively expanding its LapDogs Operational Relay Box (ORB) network by exploiting N-day vulnerabilities in Ruckus and ASUS routers to deploy new custom malware families including LONGLEASH, DOGLEASH, and JARLEASH, enabling advanced command and control capabilities for secondary threat actors.

exploited PoC Ruckus Wireless Routers +1 UAT-7810 apt malware backdoor orb-network router-exploitation china-nexus linux embedded
1r 7t 4c 4i updated
high advisory

Multiple Vulnerabilities in ESRI ArcGIS Allow Privilege Escalation and Security Bypass

Multiple unpatched vulnerabilities in ESRI ArcGIS allow a remote, anonymous attacker to bypass security measures or gain elevated user rights, potentially leading to unauthorized access and privilege escalation within affected systems.

ArcGIS vulnerability esri privilege-escalation defense-evasion
3t
high advisory

IBM WebSphere Application Server: Authenticated Remote Action Execution Vulnerability

A vulnerability in IBM WebSphere Application Server allows a remote, authenticated attacker to execute arbitrary actions on the server, potentially leading to a compromise of the host system.

WebSphere Application Server websphere vulnerability rce ibm server authenticated-access
1t
high advisory

dpkg: Vulnerability Enables Information Disclosure

A remote, unauthenticated attacker can exploit a vulnerability in the dpkg package management system to disclose information from the affected system, potentially exposing sensitive data or system details to unauthorized parties.

dpkg information-disclosure linux package-manager vulnerability
1t
high advisory

ILIAS: Multiple Vulnerabilities Identified by BSI

An attacker can leverage several vulnerabilities within the ILIAS e-learning platform to bypass security controls, disclose sensitive information, and execute Cross-Site Scripting (XSS) attacks, potentially leading to unauthorized access, data compromise, and client-side code execution.

ILIAS web-application vulnerability xss information-disclosure
2t
low threat

GStreamer (webrtcbin): Vulnerability Allows Circumvention of Security Measures

A remote, unauthenticated attacker can exploit a low-severity vulnerability within the GStreamer webrtcbin component to bypass existing security measures, potentially allowing for the circumvention of protective mechanisms without further details on specific impact.

exploited GStreamer vulnerability security-bypass webrtc
1t
medium advisory

Red Hat JBoss Enterprise Application Platform Cross-Site Scripting Vulnerability

A remote, unauthenticated attacker can exploit a Cross-Site Scripting (XSS) vulnerability in the 'io.undertow.jastow' component of Red Hat JBoss Enterprise Application Platform, allowing injection of malicious scripts into web pages which can lead to session hijacking, data theft, or defacement.

JBoss Enterprise Application Platform xss web-application jboss vulnerability red-hat
1t
medium advisory

New Abuse of ClickOnce Technology: Understanding Internals

CrowdStrike details the internal mechanisms of Microsoft's ClickOnce technology, a legitimate software deployment method that offers minimal user interaction and no administrative privilege requirements, making it a double-edged sword with significant potential for threat actor abuse in malware distribution and persistence.

.NET Framework +1 clickonce windows deployment-technology abuse-of-feature defense-evasion execution
2t
high advisory

CVE-2026-14495: DoLogin Security Plugin Authentication Bypass via Insufficient Randomness

The DoLogin Security plugin for WordPress, in all versions up to and including 4.3, is vulnerable to authentication bypass (CVE-2026-14495) due to insufficient randomness in magic-link token generation, allowing unauthenticated attackers to brute-force and reconstruct valid passwordless login tokens for any user, including administrators, and gain full control.

DoLogin Security plugin <= 4.3 wordpress plugin authentication-bypass web-exploitation cve
2t 1c
high advisory

CVE-2026-14489: WHMCS Bridge Plugin Arbitrary File Upload Leads to RCE

Authenticated attackers with Custom-level access or higher can exploit CVE-2026-14489, a missing file type validation vulnerability (CWE-434) in the `connect()` function of the WHMCS Bridge plugin for WordPress versions up to and including 6.9, to upload arbitrary files, potentially leading to remote code execution.

WHMCS Bridge <= 6.9 wordpress arbitrary-file-upload remote-code-execution web-vulnerability plugin-vulnerability
3t 1c
critical advisory

CVE-2026-12153 — WP Learn Manager Plugin Authorization Bypass

The WP Learn Manager plugin for WordPress, in versions up to and including 1.1.8, is vulnerable to an authorization bypass (CVE-2026-12153) allowing unauthenticated attackers to install and activate arbitrary plugins from the WordPress.org repository, potentially leading to full site compromise.

WP Learn Manager <= 1.1.8 wordpress plugin authorization-bypass cve web-application critical-vulnerability
1r 2t 1c
medium advisory

CrowdStrike Uncovers New Prompt Injection Techniques

CrowdStrike has identified 18 new prompt injection techniques, expanding its taxonomy to over 200 methods, which enable adversaries to manipulate AI systems and agents through hidden context, delayed triggers, semantic constraints, boundary spoofing, and social engineering to bypass security measures, leading to modified behavior, data exfiltration, or malicious command execution in AI-driven applications and agents like chatbots or those running in Kubernetes.

Gemini +2 AI prompt-injection cloud-security threat-intelligence defense-evasion initial-access privilege-escalation
5t
high advisory

CrowdStrike Uncovers New Prompt Injection Techniques

CrowdStrike's AI security research team has identified 18 new prompt injection techniques, expanding its taxonomy to over 200 methods, which adversaries can use to manipulate AI systems and agents through hidden context, delayed triggers, semantic constraints, boundary spoofing, and social engineering, potentially leading to agent hijacking, data exfiltration, or system compromise by causing them to execute unintended commands like shell scripts or SQL queries.

AI systems +5 prompt-injection ai-security llm agentic-ai cloud threat-research
5t 1i
medium advisory

CrowdStrike Uncovers New Prompt Injection Techniques Targeting AI Agents

Adversaries are leveraging sophisticated prompt injection techniques, including hidden rules, token suppression, payload decomposition, and special token injection, against AI agents to manipulate their behavior, bypass safety mechanisms, and achieve objectives such as data exfiltration or arbitrary command execution, posing a critical threat to AI-powered systems.

ai-security prompt-injection adversarial-ai agentic-ai techniques
6t
critical advisory

Better Auth OAuth Refresh Token Replay via Missing Client Authentication (CVE-2026-53512)

The legacy `oidcProvider` and `mcp` plugins in the `better-auth` library versions prior to 1.6.11 are vulnerable to CVE-2026-53512, an OAuth refresh-token replay attack where the plugins fail to verify the `client_secret` of confidential clients during the `refresh_token` grant, allowing an attacker who obtains a valid `refresh_token` and `client_id` to indefinitely mint new access tokens and impersonate the client for unauthorized resource access.

better-auth oauth authentication-bypass vulnerability web
1t
high advisory

CVE-2026-59708: Ghostfolio Unauthenticated Portfolio Data Exposure

An authorization bypass vulnerability (CVE-2026-59708) in Ghostfolio's GET /api/v1/public/:accessId/portfolio endpoint allows unauthenticated attackers with a private access ID to retrieve sensitive financial portfolio data, including holdings and performance metrics, due to missing `granteeUserId` filtering validation.

ghostfolio <= 3.6.0 vulnerability api authorization-bypass data-exposure webserver
3t 1c
critical threat

Critical OS Command Injection in 9Router (CVE-2026-59800)

A critical OS command injection vulnerability (CVE-2026-59800) affects 9Router versions prior to 0.4.44, allowing unauthenticated remote attackers to execute arbitrary OS commands as root via a crafted POST request to the /api/tunnel/tailscale-install endpoint, leading to full system compromise with active exploitation observed.

exploited 9Router < 0.4.44 os-command-injection rce web-vulnerability network-appliance linux
1r 2t 1c