Skip to content
Threat Feed

July 2026 (30)

critical advisory

Unauthenticated Remote Code Execution in IBM Langflow OSS

IBM Langflow OSS versions 1.0.0 through 1.10.1 are susceptible to unauthenticated remote code execution due to improper sanitization of environment variables in the MCP stdio launcher.

Langflow OSS remote-code-execution cve-2026-12940 ibm langflow code-injection vulnerability rce
3t 1c
critical advisory

Critical OS Command Injection in IBM Hardware Management Console

A critical unauthenticated command injection vulnerability (CVE-2026-12943) in IBM HMC and Novalink allows remote attackers to execute arbitrary commands with elevated privileges.

HMC V10.3 +2 vulnerability rce ibm-power critical
1c
critical advisory

Critical Deserialization Vulnerability in IBM webMethods Integration

IBM webMethods Integration (on-premises) versions 10.11 and 10.15 contain a critical deserialization vulnerability (CVE-2026-12118) that enables unauthenticated remote code execution.

webMethods Integration remote-code-execution deserialization ibm cve-2026-12118
1t 1c
high advisory

Authorization Bypass Vulnerability in IBM Langflow OSS

IBM Langflow OSS versions 1.0.0 through 1.10.1 contain an authorization bypass vulnerability (CVE-2026-12945) allowing authenticated users to access and manipulate build jobs of other users.

Langflow OSS cve-2026-12945 authorization-bypass cwe-639
1t 1c
high advisory

IBM PowerVM Hypervisor Memory Integrity Vulnerability

A buffer overflow vulnerability in IBM PowerVM Hypervisor allows a local attacker with low privileges to trigger system crashes or compromise OS memory integrity via crafted hypervisor calls.

PowerVM Hypervisor +2 vulnerability hypervisor buffer-overflow
1c
critical advisory

SolarWinds Web Help Desk SAML Authentication Bypass

SolarWinds Web Help Desk versions 2026.1 and prior are vulnerable to a critical authentication bypass via the SAML 2.0 implementation, allowing unauthenticated remote access.

Web Help Desk authentication-bypass saml vulnerability cve-2026-28323
1t 1c
high advisory

Authentication Bypass and Credential Exposure in OpenCost

OpenCost versions before 1.121.0 contain authentication bypass vulnerabilities allowing unauthenticated credential exfiltration via GET /helmValues and unauthorized service key modification via POST /serviceKey.

OpenCost
1r 2t 1c
high advisory

Insecure Direct Object Reference Vulnerability in Julep

An insecure direct object reference (IDOR) vulnerability in Julep allows authenticated tenants to bypass authorization checks and access the execution data of other tenants via the get_execution_details endpoint.

julep
1r 1t 1c
high advisory

SSRF Vulnerability in Swarms library

The Swarms library contains a server-side request forgery (SSRF) vulnerability in the _is_safe_url function that allows attackers to bypass blocklists and access restricted internal services.

Swarms
1t 1c
medium advisory

Insufficient Redirect URI Validation in MaxKey

MaxKey versions through 4.1.12 are vulnerable to OAuth 2.0 authorization code hijacking due to improper host boundary checks in the DefaultRedirectResolver component.

MaxKey oauth identity-management cve-2026-67345
2t 1c
low advisory

Denial of Service Vulnerability in IBM Enterprise Build of Quarkus

A resource exhaustion vulnerability (CVE-2026-16308) in IBM Enterprise Build of Quarkus allows remote, unauthenticated attackers to cause a denial of service via unbounded accumulation of multipart MIME headers.

Enterprise Build of Quarkus
1t 1c
high advisory

Denial of Service Vulnerability in IBM WebSphere Application Server - Liberty

A remote unauthenticated denial-of-service vulnerability in IBM WebSphere Application Server - Liberty allows attackers to cause excessive memory consumption via crafted requests.

WebSphere Application Server - Liberty denial-of-service vulnerability web-server web-application csrf ssrf privilege-escalation
1c
high advisory

Arbitrary Code Execution in IBM Aspera Desktop App via DLL Hijacking

IBM Aspera Desktop App versions 1.0.5 through 1.0.19 are susceptible to arbitrary code execution through a DLL hijacking vulnerability during application start-up.

Aspera Desktop App
1t 1c
high advisory

Authentication Context Confusion in Serendipity

Serendipity versions prior to 2.6.1 are vulnerable to an authentication context confusion flaw allowing an authenticated Editor to escalate privileges to Administrator via username collision.

Serendipity
1t 1c
high advisory

Authentication Bypass in FTC E-Commerce Management Panel

A missing authentication vulnerability in FTC E-Commerce Management Panel versions prior to 1.0.2 allows unauthenticated remote attackers to bypass security controls and gain unauthorized access.

FTC E-Commerce Management Panel authentication-bypass cve-2026-12722 web-vulnerability
1c
critical advisory

Critical Path Traversal Vulnerability in IBM App Connect Enterprise (CVE-2026-15435)

IBM App Connect Enterprise contains a critical path traversal vulnerability (CVE-2026-15435) allowing remote, unauthenticated attackers to write arbitrary files to the system via crafted HTTP requests.

App Connect Enterprise +1
1r 1c
high advisory

Reflected XSS in IBM Tivoli System Automation and WebSphere Application Server

IBM Tivoli System Automation Application Manager 4.1 and WebSphere Application Server are affected by a reflected cross-site scripting vulnerability in the administrative console login page that allows unauthenticated attackers to execute arbitrary JavaScript.

Tivoli System Automation Application Manager +1 xss web-vulnerability cve-2026-11707
1r 1c
high advisory

Critical Vulnerabilities in Spring Tools IDE Extensions

Multiple vulnerabilities in Spring Tools for Eclipse and VSCode/Cursor/Theia allow for remote code execution, unauthorized service access, credential exposure, and cross-site scripting.

Spring Tools for Eclipse +3 vulnerability ide rce spring-framework
5c
high advisory

Blind SQL Injection Vulnerability in Plesk XML-RPC API

A blind SQL injection vulnerability, tracked as CVE-2026-58046, affects the Plesk XML-RPC API, potentially allowing unauthenticated attackers to execute arbitrary database queries.

Plesk web-application sql-injection vulnerability
1r 1t 1c
low advisory

OliveTin Unauthenticated OAuth2 Memory Exhaustion

An unauthenticated attacker can trigger a denial-of-service in OliveTin by flooding the OAuth2 login endpoint, causing unbounded memory growth due to the lack of expiration for stored login states.

OliveTin
1r 1t 1c
low advisory

Uncontrolled Memory Allocation in MCP Ruby SDK

An unauthenticated remote attacker can cause a denial-of-service in MCP Ruby SDK servers by sending oversized JSON-RPC requests that trigger unbounded memory allocation.

mcp
1t 1c
high advisory

Session Poisoning Vulnerability in Ruby MCP SDK

The Ruby SDK for the Model Context Protocol (MCP) lacks session ownership validation, allowing attackers to perform unauthorized tool executions within a victim's active session.

Ruby SDK cve-2026-67431 mcp session-hijacking ruby sse
1c
high advisory

Credential Exfiltration via Unrestricted Base URL in Flyto-core

Flyto-core versions prior to 2.26.7 allow unauthenticated callers to exfiltrate API provider keys by supplying a malicious 'base_url' parameter, which forces the library to append operator-configured secrets to requests sent to attacker-controlled infrastructure.

flyto-core credential-theft vulnerability cloud-security cve-2026-67425 cve-2026-67427 exfiltration flyto variable-interpolation
2t 1c
high advisory

Flyto2 Core SSRF via Insecure Redirect Handling

Flyto2 Core HTTP modules perform insufficient SSRF revalidation on HTTP redirects, allowing attackers to reach internal resources and cloud metadata services.

Flyto2 Core
1t 1c
critical threat

Unauthenticated SSRF and Secret Exfiltration in Flyto Core

An unauthenticated SSRF vulnerability in the Flyto Core /run endpoint allows attackers to exfiltrate the internal FLYTO_RUNNER_SECRET and perform unauthorized requests against internal infrastructure.

Flyto Core ssrf credential-theft vulnerability cve-2026-67426 path-traversal arbitrary-file-write rce framework
1r 4t 1c
low advisory

Multiple Vulnerabilities in GitLab

Multiple security vulnerabilities identified in GitLab CE and EE versions 19.x can result in remote denial of service, data confidentiality breaches, and reflected cross-site scripting.

GitLab Community Edition +1 vulnerability gitlab patch-management
5c
high threat

Astaroth Botnet Deploys New WhatsApp Web Spambot Component

Operators of the Astaroth (aka Guildma) botnet, which targets Brazil-based users, introduced a new spambot component in Q4 2025 that leverages WhatsApp Web in headless browser mode for malware distribution, exhibiting evasion techniques like payload encryption and WebDriver automation indicator stripping.

Windows +5 Astaroth botnet malware spambot latin-america
1r 9t 8i updated
high advisory

CVE-2026-54366 CentreStack XXE Injection

CentreStack versions prior to 17.4 are vulnerable to an unauthenticated XXE injection via the SharePoint storage configuration handler, allowing attackers to exfiltrate sensitive server-side files.

CentreStack xxe vulnerability web-application
1r 2t 1c
high advisory

Authentication Bypass Vulnerability in CentreStack

CentreStack versions prior to 17.2 are vulnerable to an authentication bypass that allows unauthenticated attackers to manipulate account settings and enumerate system data via exposed API endpoints.

CentreStack authentication-bypass cve-2026-54367 api-security
1t 1c
high advisory

Unauthenticated Deserialization Vulnerability in CentreStack

An unauthenticated deserialization vulnerability in CentreStack allows remote attackers to create unauthorized local user accounts by sending crafted XML payloads to specific API endpoints.

CentreStack vulnerability deserialization remote-code-execution
2t