Skip to content
Threat Feed

July 2026 (30)

high advisory

Google Security Updates — July 2026

Roundup of Google security advisories published in July 2026.

golang.org/x/crypto/ssh +74 roundup
5c 41i updated
high advisory

Microsoft Security Updates — July 2026

Roundup of Microsoft security advisories published in July 2026.

PoC PowerShell +511 roundup
11c 354i updated
medium advisory

Redis Authenticated Remote Code Execution Vulnerability

A vulnerability in Redis allows a remote, authenticated attacker to achieve arbitrary code execution on the target server.

Redis vulnerability rce database
1t
high advisory

Multiple Vulnerabilities in Progress MOVEit Transfer

Multiple vulnerabilities, including remote XSS and security policy bypass, have been identified in Progress MOVEit Transfer versions prior to 2026.0.3, enabling potential unauthorized access and session-based script execution.

MOVEit Transfer vulnerability web-application moveit
1t 4c
high advisory

Apple Security Updates — July 2026

Roundup of Apple security advisories published in July 2026.

PoC macOS LaunchAgents +46 roundup
4c 10i updated
medium advisory

Detection of Malicious AMQP Multi-Queue Message Purging

Adversaries may perform rapid multi-queue purges in AMQP-based messaging systems, such as RabbitMQ, to facilitate data destruction or cause widespread application disruption following credential compromise.

RabbitMQ
1t
medium threat

Denial of Service in gnome-remote-desktop via Connection Throttling Bypass

A vulnerability in gnome-remote-desktop allows an unauthenticated remote attacker to exhaust system resources by bypassing connection throttling when RDP is enabled in system mode on Red Hat Enterprise Linux.

exploited Red Hat Enterprise Linux denial-of-service linux rdp cve-2026-18358
1t 1c
critical advisory

Unauthenticated Remote Code Injection in Logsign SIEM

Logsign SIEM versions prior to 6.4.108 are vulnerable to a critical code injection flaw (CVE-2026-17561) that enables unauthenticated remote attackers to achieve arbitrary code execution.

Logsign SIEM code-injection rce siem vulnerability
1c
critical threat

Citrix NetScaler ADC and Gateway CVE-2026-3055 Exploitation

Threat actors are actively exploiting CVE-2026-3055, a critical memory overread vulnerability in Citrix NetScaler ADC and NetScaler Gateway appliances configured as a SAML identity provider (IDP), to extract sensitive information, including authenticated administrative session IDs, potentially leading to full system takeover.

PoC Langflow +4 citrix netscaler cve-2026-3055 memory-overread information-disclosure
2r 3t 5c 1i updated
high advisory

Red Hat Advanced Cluster Security Policy Bypass via Deployment Label Manipulation

A vulnerability in Red Hat Advanced Cluster Security for Kubernetes (RHACS) allows an authenticated user to bypass security policy enforcement by setting the 'openshift.io/encoded-deployment-config' label to 'null'.

Advanced Cluster Security for Kubernetes kubernetes cloud-security defense-evasion cve-2026-10079
1t 1c
high advisory

SolarWinds Web Help Desk Security Bypass Vulnerability

A vulnerability in SolarWinds Web Help Desk, identified as CVE-2024-28986, allows remote unauthenticated attackers to bypass security measures, potentially leading to unauthorized access.

Web Help Desk web-application security-bypass vulnerability-management
1c
medium advisory

Multiple Vulnerabilities in Red Hat Enterprise Linux ABRT

Multiple vulnerabilities in the Automatic Bug Reporting Tool (abrt) within Red Hat Enterprise Linux allow a local attacker to perform privilege escalation, manipulate data, or trigger a denial-of-service condition.

Enterprise Linux +1
1t
high advisory

AWS SageMaker Execution Role Privilege Escalation via PassRole

An adversary with SageMaker resource-creation rights and broad iam:PassRole permissions can escalate privileges by passing highly privileged IAM roles to SageMaker notebook instances, training, processing, or pipeline jobs.

AWS SageMaker cloud aws privilege-escalation sagemaker
1t
medium advisory

Detection of Unusual AWS IAM Guardrail Policy Deletion

This threat brief identifies a detection strategy for attackers attempting defense evasion or persistence by deleting sensitive AWS IAM managed policies using previously unseen identities.

AWS IAM cloud defense-evasion persistence aws iam
1r 2t
medium advisory

Unusual AWS Batch Job Container Command Override Detection

This detection targets the abuse of AWS Batch 'containerOverrides.command' parameters by infrequent users to inject malicious commands or data exfiltration logic into production compute environments.

AWS Batch cloud aws batch cloudtrail execution
1r 1t
high advisory

Arbitrary File Upload Vulnerability in Realtyna Organic IDX Plugin

The Realtyna Organic IDX plugin for WordPress contains an arbitrary file upload vulnerability (CVE-2026-16236) due to improper validation and authentication, allowing remote attackers to achieve remote code execution.

Organic IDX
2t 1c
critical advisory

Critical Hard-coded Credential Vulnerability in Rich Source DMS+ (Non-Mobile)

Rich Source DMS+ (Non-Mobile) versions 5.63 and earlier contain a hard-coded API key allowing unauthenticated remote attackers to gain full administrative control over affected devices.

DMS+
1t 1c
high advisory

Argument Injection Vulnerability in yggdrasil-worker-package-manager

An argument injection vulnerability in the APT backend of yggdrasil-worker-package-manager allows local attackers to manipulate apt-get command-line arguments to achieve root-level code execution.

yggdrasil-worker-package-manager privilege-escalation linux cve-2026-18157
1t 1c
high advisory

MeshCentral WebSocket Hijacking Vulnerability

CVE-2026-66420 is a high-severity vulnerability in MeshCentral 1.1.21 allowing unauthenticated attackers to hijack administrator sessions via a cross-site WebSocket hijacking protection bypass.

MeshCentral
1c
critical advisory

Stored XSS Vulnerability in OpenClaw Dashboard

An unauthenticated stored XSS vulnerability in the OpenClaw Dashboard allows remote attackers to execute arbitrary JavaScript in administrative sessions via the sessions API.

OpenClaw Dashboard web-application-security xss cve-2026-66421
1t 1c
high advisory

Siemens Security Updates — July 2026

Roundup of Siemens security advisories published in July 2026.

PoC CPCI85 Central Processing/Communication < V26.20 +27 roundup
5c 2i updated
high advisory

Authenticated Remote Code Execution in Wolf CMS

Wolf CMS versions up to 0.8.3.1 contain a remote code execution vulnerability in the FileManagerController allowing authenticated users with specific permissions to upload and execute arbitrary PHP files.

Wolf CMS remote-code-execution web-application-vulnerability
1r 3t
high advisory

Authentication Bypass Vulnerability in IBM WebSphere Application Server

A critical authentication bypass vulnerability (CVE-2026-10842) allows remote, unauthenticated attackers to circumvent security constraints in IBM WebSphere Application Server and Liberty versions.

WebSphere Application Server +2
2c
critical advisory

Critical Authentication Bypass in Spikster API

A missing authentication vulnerability in Spikster allows unauthenticated remote attackers to access approximately 50 API endpoints, leading to full system compromise.

Spikster authentication-bypass cve-2026-67594 rce
1c
critical advisory

Remote Code Execution via Exposed H2 Database in Juggle Through

An unauthenticated remote code execution vulnerability in Juggle Through 1.6.0 allows attackers to leverage default credentials on the H2 database console to execute system-level commands.

Juggle Through remote-code-execution vulnerability cve-2026-67208
2t 1c
high advisory

SSRF Protection Bypass in dssrf Library via URL Normalization

The dssrf library version 1.0.3 contains an SSRF bypass vulnerability in the is_url_safe function caused by improper character removal before URL parsing, allowing attackers to access restricted internal resources.

dssrf ssrf validation-bypass cve-2026-54722
1t 1c
critical advisory

Arbitrary Code Execution in AWS Amplify Studio via Input Validation Flaw

The amplify-codegen-ui package is vulnerable to arbitrary code execution due to insufficient input validation during the component expression-binding process, allowing authenticated users to inject malicious JavaScript.

amplify-codegen-ui +1 supply-chain rce amplify
1t 1c
high advisory

Leantime Authenticated LFI and SSRF via Blueprints

Leantime 3.6.2 contains a vulnerability in the Blueprints::import method allowing authenticated attackers to perform SSRF and LFI via the JSON-RPC API.

Leantime lfi ssrf cve-2026-66415 web-vulnerability csrf cve-2026-66416
1t 1c
high advisory

Path Traversal Vulnerability in IBM Langflow OSS

IBM Langflow OSS versions 1.0.0 through 1.10.1 are vulnerable to a path traversal flaw (CVE-2026-12942) that allows unauthenticated remote attackers to read arbitrary files from the hosting system.

Langflow OSS
1r 1c
high advisory

Stack-based Buffer Overflow in IBM Db2 setgid Helper

IBM Db2 versions 11.5.0 through 11.5.9 and 12.1.0 through 12.1.4 contain a buffer overflow vulnerability in the db2flacc setgid helper that allows local attackers to escalate privileges.

Db2 11.5 +1 privilege-escalation buffer-overflow ibm-db2
1r 1t 1c