Skip to content
Threat Feed

July 2026 (30)

high advisory

WordPress WPZOOM Portfolio Plugin XSS Vulnerability (CVE-2026-49069)

A critical reflected cross-site scripting (XSS) vulnerability, CVE-2026-49069, affects the WPZOOM Portfolio plugin (version 1.4.21 and earlier) for WordPress, enabling unauthenticated attackers to inject malicious JavaScript into web pages via the `wpzoom_load_more_items` AJAX action, leading to client-side script execution in victims' browsers.

WordPress Plugin WPZOOM Portfolio <= 1.4.21 +1 xss wordpress webapps cve
1r 2t 1c 2i
critical advisory

Windows Defender Race Condition (EDB-52612) Leads to Local Privilege Escalation and AV Bypass

A critical local race condition (EDB-52612) exists in Microsoft Windows Defender's MsMpEng.exe, specifically between its cleanup routine (`MpCleanCallbackFunction`) and Volume Shadow Copy creation, allowing Local Privilege Escalation (LPE) to NT AUTHORITY\SYSTEM and temporary disabling of antivirus protection through a use-after-free vulnerability, with a public exploit demonstrating the risk.

Windows Defender Antivirus local-privilege-escalation race-condition windows-defender exploit-db vulnerability endpoint
1t 3i
high advisory

Proof-of-Concept Exploit Released for Linux 'Bad Epoll' Root Access Vulnerability (CVE-2026-46242)

A publicly available proof-of-concept exploit for CVE-2026-46242, a race-condition use-after-free vulnerability dubbed 'Bad Epoll' in the Linux kernel's `epoll` facility, enables unprivileged processes to gain root privileges on affected Linux and Android systems.

Linux kernel +1 linux privilege-escalation vulnerability poc
1t 1c
high advisory

Multiple Vulnerabilities in Apache Camel Lead to Arbitrary Code Execution

Multiple vulnerabilities exist in Apache Camel that an attacker can exploit to bypass security controls and execute arbitrary program code, potentially leading to system compromise and unauthorized operations.

Apache Camel vulnerability apache camel code-execution security-bypass
1t
high advisory

Rundll32 Remote Thread Injection by Malware

This brief details the use of rundll32.exe to create remote threads into other processes, a technique observed with malware like IcedID, enabling defense evasion, arbitrary code execution, privilege escalation, and data theft on Windows endpoints.

rundll32 remote-thread-injection icedid defense-evasion code-injection windows endpoint
1r 1t
medium advisory

dhcpcd Denial of Service Vulnerability

A vulnerability in the dhcpcd DHCP client daemon allows an attacker from an adjacent network to execute a Denial of Service attack, potentially disrupting network connectivity on affected Linux systems.

dhcpcd denial-of-service linux impact
1t
high advisory

OpenVPN: Multiple Vulnerabilities

A local attacker can exploit multiple vulnerabilities in OpenVPN to achieve arbitrary code execution, manipulate data, or cause a denial of service.

OpenVPN vulnerability rce dos
3t
medium advisory

Kubernetes Secret Access by Node or Pod Service Account

Attackers who have compromised a Kubernetes pod or node are observed attempting to `get` or `list` Kubernetes Secret objects via the API, a common post-compromise technique by various threat actors to achieve credential access and gather sensitive information such as tokens, registry credentials, TLS keys, or application configurations.

Kubernetes credential-access cloud-security container-security threat-detection
1r 1t
medium advisory

CVE-2026-9165 - Red Hat Advanced Cluster Security for Kubernetes Central Component Denial of Service

An authenticated denial of service vulnerability (CVE-2026-9165) exists in the Red Hat Advanced Cluster Security for Kubernetes (RHACS) Central component, allowing attackers with a valid API token to send deeply nested GraphQL queries that cause excessive resource consumption and render the management plane unavailable.

Red Hat Advanced Cluster Security for Kubernetes +1 kubernetes red-hat dos vulnerability graphql
1t 1c
high advisory

CVE-2026-14809: Unauthenticated SQL Injection in Prog Management System

A SQL Injection vulnerability, identified as CVE-2026-14809, exists in the Prog Management System developed by PROG MIS, allowing unauthenticated remote attackers to inject arbitrary SQL commands to read database contents.

Prog Management System sql-injection vulnerability web cve high-severity
1r 2t 1c
medium advisory

Potential DNS Exfiltration via Excessive Chunked Queries

This brief details the technique of DNS exfiltration where threat actors use chunked DNS queries with subdomain labels following an 'index-payload.base_domain' pattern to exfiltrate data from compromised Windows hosts, allowing them to bypass volume-based detection and extract sensitive information.

exfiltration dns-tunneling data-exfiltration windows endpoint command-and-control
1r 2t
critical advisory

CVE-2026-14808 — Prog Management System Sensitive Information Exposure

A critical vulnerability, CVE-2026-14808, in the Prog Management System developed by PROG MIS allows unauthenticated remote attackers to view a specific web page and obtain sensitive database account credentials, including the username and password, with high impact on confidentiality, integrity, and availability.

Prog Management System sensitive-data-exposure web-vulnerability critical-vulnerability cwe-497 database-credentials
2t 1c 2i
critical advisory

CVE-2026-14807: PROG MIS ERP App Hard-coded Credentials Vulnerability

An unauthenticated remote attacker can exploit a Use of Hard-coded Credentials vulnerability (CWE-798) in the ERP App developed by PROG MIS, allowing the attacker to log in to view application code and obtain database account and password information, leading to high impact on confidentiality, integrity, and availability.

ERP App hard-coded-credentials erp web-application vulnerability
3t 1c
high advisory

Gitea: Multiple Vulnerabilities Leading to XSS, Info Disclosure, and File Manipulation

An attacker can exploit multiple unpatched vulnerabilities in Gitea to bypass security measures, disclose sensitive information, perform Cross-Site Scripting (XSS) attacks, and manipulate files, posing a high risk to self-hosted Git instances.

Gitea web-exploitation vulnerability
4t
high advisory

CVE-2026-14802: Remote OS Command Injection in React Create React App

A high-severity OS command injection vulnerability (CVE-2026-14802) exists in `react create-react-app` up to version 5.0.1, specifically within the `startBrowserProcess` function of the `openBrowser.js` file in the `react-dev-utils` component, allowing for remote exploitation and arbitrary OS command execution on affected macOS development environments.

create-react-app <= 5.0.1 +1 vulnerability command-injection macos web-application
2t 1c 6i
high advisory

Red Hat JBoss Enterprise Application Platform: Multiple Vulnerabilities

Multiple vulnerabilities in Red Hat JBoss Enterprise Application Platform allow a remote, unauthenticated attacker to execute arbitrary code, perform cross-site scripting (XSS) attacks, disclose sensitive information, cause a denial of service, or bypass security mechanisms, posing a significant risk of system compromise and data exposure.

JBoss Enterprise Application Platform vulnerability rce xss dos information-disclosure red-hat jboss enterprise-application-platform +1
5t
high advisory

Eclipse Jetty: Multiple Vulnerabilities Including Arbitrary Code Execution

An authenticated remote attacker can exploit multiple vulnerabilities in Eclipse Jetty to achieve arbitrary code execution, bypass security measures, or perform an HTTP cache poisoning attack, necessitating immediate patching and enhanced monitoring of Jetty instances.

Jetty vulnerability webserver RCE authentication-bypass cache-poisoning eclipse-jetty
2t
high advisory

CVE-2026-14778: Improper Authorization in SourceCodester Onlne Examination & Learning Management System

A high-severity improper authorization vulnerability (CVE-2026-14778) exists in SourceCodester Onlne Examination & Learning Management System version 1.0, allowing remote attackers to bypass authorization checks by manipulating the `student_id`, `schedule_id`, or `action` arguments in `/ajax_enroll.php`, potentially leading to unauthorized access or actions.

Onlne Examination & Learning Management System 1.0 web-vulnerability improper-authorization cve
1c
high advisory

CVE-2026-14771: SourceCodester Class and Exam Timetabling System SQL Injection Vulnerability

A critical SQL injection vulnerability (CVE-2026-14771) has been discovered in SourceCodester Class and Exam Timetabling System version 1.0, allowing remote unauthenticated attackers to manipulate the 'ID' argument in `/edit_exam1.php`, leading to arbitrary SQL command execution and potential data compromise.

Class and Exam Timetabling System 1.0 sql-injection web-application vulnerability remote-code-execution data-exfiltration
1r 1t 1c 6i
high advisory

CVE-2026-14770: SourceCodester Class and Exam Timetabling System SQL Injection Vulnerability

A high-severity SQL injection vulnerability, CVE-2026-14770, exists in SourceCodester Class and Exam Timetabling System version 1.0 within the `/edit_room.php` file, allowing remote, unauthenticated attackers to manipulate the 'ID' argument with public exploits, leading to data exposure and potential database compromise.

Class and Exam Timetabling System 1.0 sql-injection vulnerability web-application cve
1r 1t 1c
high advisory

CVE-2026-14769 — SQL Injection in code-projects Real State Services 1.0

A critical security vulnerability, CVE-2026-14769, allows for remote SQL Injection in code-projects Real State Services 1.0 via the 'Bankname' argument in the '/pay.php' file, with a publicly disclosed exploit enabling information disclosure and potential data manipulation.

Real State Services 1.0 sql-injection web-vulnerability cve data-exfiltration
1r 3t 1c 6i
high advisory

CVE-2026-14768: Remote SQL Injection in code-projects Real State Services 1.0

A remote SQL injection vulnerability (CVE-2026-14768) has been identified in code-projects Real State Services 1.0, allowing attackers to exploit the 'loc' argument in '/builderHome.php' for arbitrary SQL command execution, with a public exploit available.

Real State Services 1.0 web-vulnerability sql-injection php cve
1r 1t 1c
high threat

CVE-2026-14764: SQL Injection in code-projects Hotel and Tourism Reservation

An unauthenticated attacker can remotely exploit CVE-2026-14764, an SQL injection vulnerability in code-projects Hotel and Tourism Reservation 1.0's `/admin/add_event.php` component via the `fdetails` argument, to manipulate database queries and compromise sensitive data, with public exploit disclosure increasing the risk of active exploitation.

exploited Hotel and Tourism Reservation 1.0 web-vulnerability sql-injection cve data-compromise webserver
1r 3t 1c
high threat

CVE-2026-14763: SQL Injection in code-projects Hotel and Tourism Reservation

A SQL injection vulnerability, tracked as CVE-2026-14763, has been discovered in code-projects Hotel and Tourism Reservation version 1.0. The flaw affects an unknown function within the '/admin/tour_reserves.php' file, specifically in the 'Tour Reservations Page' component, due to improper handling of the 'tour' argument, allowing for remote SQL injection attacks, and a public exploit is available, increasing the risk of compromise.

exploited Hotel and Tourism Reservation 1.0 sql-injection web-application cve data-exfiltration
1r 2t 1c 6i
high advisory

CVE-2026-14762: Remote SQL Injection in code-projects Hotel and Tourism Reservation

A critical SQL injection vulnerability (CVE-2026-14762) exists in code-projects Hotel and Tourism Reservation version 1.0, located in the `/admin/rooms.php` file's Room Management Page, allowing remote attackers to manipulate the `delete` argument for data compromise, with a public exploit now available.

Hotel and Tourism Reservation 1.0 sql-injection web-application cve php
1r 1t 1c
high advisory

CVE-2026-9085: Incorrect Permissions Allow DNS Spoofing in Pardus-Parental-Control

An Improper Access Control and Incorrect Permission Assignment vulnerability (CVE-2026-9085) in TUBITAK BILGEM's Pardus-Parental-Control software, affecting versions up to 0.5.1 and all versions before 0.7.0, allows a local attacker to perform DNS Spoofing.

Pardus-Parental-Control dns-spoofing access-control linux vulnerability
1c
high threat

CVE-2026-6509 — Missing Authorization Vulnerability in Pardus Update Allows Privilege Escalation

A Missing Authorization vulnerability (CVE-2026-6509) in TUBITAK BILGEM Software Technologies Research Institute's Pardus Update software allows a local, low-privileged attacker to escalate privileges on affected Pardus Linux systems by bypassing authorization checks in versions up to and including 0.6.3.

exploited Pardus Update privilege-escalation linux vulnerability cve
1t 1c
high threat

CVE-2026-14756: SQL Injection in code-projects Hotel and Tourism Reservation

A remote SQL injection vulnerability (CVE-2026-14756) exists in code-projects Hotel and Tourism Reservation version 1.0, allowing unauthenticated attackers to exploit improper input sanitization in the `delete_image` parameter of `/admin/add_tour.php` to bypass authentication, extract sensitive data, or manipulate database records, with a public exploit available.

exploited Hotel and Tourism Reservation 1.0 sql-injection web-application cve code-projects
1r 3t 1c 6i
high advisory

CVE-2026-14755: Remote SQL Injection in code-projects Hotel and Tourism Reservation

A critical remote unauthenticated SQL injection vulnerability (CVE-2026-14755) in code-projects Hotel and Tourism Reservation version 1.0, specifically within the '/admin/reservations.php' file's 'delete' argument, allows attackers to manipulate backend database queries, leading to data exposure and manipulation with a publicly disclosed exploit.

Hotel and Tourism Reservation 1.0 sql-injection web-vulnerability cve remote-code-execution data-exfiltration
1r 2t 1c 2i
high advisory

CVE-2026-12250: Pardus Domain Joiner Vulnerability Exposes Sensitive Information

A high-severity vulnerability, CVE-2026-12250, in TUBITAK BILGEM Software Technologies Research Institute's Pardus Domain Joiner (versions 0.5.2 before 0.5.4) allows local attackers to excavate sensitive information by observing process invocations that expose credentials or other confidential data.

Pardus Domain Joiner 0.5.2 +1 vulnerability linux data-exposure pardus
1c