July 2026 (30)
Unauthenticated Remote Code Execution in IBM Langflow OSS
3 TTPs 1 CVEIBM Langflow OSS versions 1.0.0 through 1.10.1 are susceptible to unauthenticated remote code execution due to improper sanitization of environment variables in the MCP stdio launcher.
Critical OS Command Injection in IBM Hardware Management Console
1 CVEA critical unauthenticated command injection vulnerability (CVE-2026-12943) in IBM HMC and Novalink allows remote attackers to execute arbitrary commands with elevated privileges.
Critical Deserialization Vulnerability in IBM webMethods Integration
1 TTP 1 CVEIBM webMethods Integration (on-premises) versions 10.11 and 10.15 contain a critical deserialization vulnerability (CVE-2026-12118) that enables unauthenticated remote code execution.
Authorization Bypass Vulnerability in IBM Langflow OSS
1 TTP 1 CVEIBM Langflow OSS versions 1.0.0 through 1.10.1 contain an authorization bypass vulnerability (CVE-2026-12945) allowing authenticated users to access and manipulate build jobs of other users.
IBM PowerVM Hypervisor Memory Integrity Vulnerability
1 CVEA buffer overflow vulnerability in IBM PowerVM Hypervisor allows a local attacker with low privileges to trigger system crashes or compromise OS memory integrity via crafted hypervisor calls.
SolarWinds Web Help Desk SAML Authentication Bypass
1 TTP 1 CVESolarWinds Web Help Desk versions 2026.1 and prior are vulnerable to a critical authentication bypass via the SAML 2.0 implementation, allowing unauthenticated remote access.
Authentication Bypass and Credential Exposure in OpenCost
1 rule 2 TTPs 1 CVEOpenCost versions before 1.121.0 contain authentication bypass vulnerabilities allowing unauthenticated credential exfiltration via GET /helmValues and unauthorized service key modification via POST /serviceKey.
Insecure Direct Object Reference Vulnerability in Julep
1 rule 1 TTP 1 CVEAn insecure direct object reference (IDOR) vulnerability in Julep allows authenticated tenants to bypass authorization checks and access the execution data of other tenants via the get_execution_details endpoint.
SSRF Vulnerability in Swarms library
1 TTP 1 CVEThe Swarms library contains a server-side request forgery (SSRF) vulnerability in the _is_safe_url function that allows attackers to bypass blocklists and access restricted internal services.
Insufficient Redirect URI Validation in MaxKey
2 TTPs 1 CVEMaxKey versions through 4.1.12 are vulnerable to OAuth 2.0 authorization code hijacking due to improper host boundary checks in the DefaultRedirectResolver component.
Denial of Service Vulnerability in IBM Enterprise Build of Quarkus
1 TTP 1 CVEA resource exhaustion vulnerability (CVE-2026-16308) in IBM Enterprise Build of Quarkus allows remote, unauthenticated attackers to cause a denial of service via unbounded accumulation of multipart MIME headers.
Denial of Service Vulnerability in IBM WebSphere Application Server - Liberty
1 CVEA remote unauthenticated denial-of-service vulnerability in IBM WebSphere Application Server - Liberty allows attackers to cause excessive memory consumption via crafted requests.
Arbitrary Code Execution in IBM Aspera Desktop App via DLL Hijacking
1 TTP 1 CVEIBM Aspera Desktop App versions 1.0.5 through 1.0.19 are susceptible to arbitrary code execution through a DLL hijacking vulnerability during application start-up.
Authentication Context Confusion in Serendipity
1 TTP 1 CVESerendipity versions prior to 2.6.1 are vulnerable to an authentication context confusion flaw allowing an authenticated Editor to escalate privileges to Administrator via username collision.
Authentication Bypass in FTC E-Commerce Management Panel
1 CVEA missing authentication vulnerability in FTC E-Commerce Management Panel versions prior to 1.0.2 allows unauthenticated remote attackers to bypass security controls and gain unauthorized access.
Critical Path Traversal Vulnerability in IBM App Connect Enterprise (CVE-2026-15435)
1 rule 1 CVEIBM App Connect Enterprise contains a critical path traversal vulnerability (CVE-2026-15435) allowing remote, unauthenticated attackers to write arbitrary files to the system via crafted HTTP requests.
Reflected XSS in IBM Tivoli System Automation and WebSphere Application Server
1 rule 1 CVEIBM Tivoli System Automation Application Manager 4.1 and WebSphere Application Server are affected by a reflected cross-site scripting vulnerability in the administrative console login page that allows unauthenticated attackers to execute arbitrary JavaScript.
Critical Vulnerabilities in Spring Tools IDE Extensions
5 CVEsMultiple vulnerabilities in Spring Tools for Eclipse and VSCode/Cursor/Theia allow for remote code execution, unauthorized service access, credential exposure, and cross-site scripting.
Blind SQL Injection Vulnerability in Plesk XML-RPC API
1 rule 1 TTP 1 CVEA blind SQL injection vulnerability, tracked as CVE-2026-58046, affects the Plesk XML-RPC API, potentially allowing unauthenticated attackers to execute arbitrary database queries.
OliveTin Unauthenticated OAuth2 Memory Exhaustion
1 rule 1 TTP 1 CVEAn unauthenticated attacker can trigger a denial-of-service in OliveTin by flooding the OAuth2 login endpoint, causing unbounded memory growth due to the lack of expiration for stored login states.
Uncontrolled Memory Allocation in MCP Ruby SDK
1 TTP 1 CVEAn unauthenticated remote attacker can cause a denial-of-service in MCP Ruby SDK servers by sending oversized JSON-RPC requests that trigger unbounded memory allocation.
Session Poisoning Vulnerability in Ruby MCP SDK
1 CVEThe Ruby SDK for the Model Context Protocol (MCP) lacks session ownership validation, allowing attackers to perform unauthorized tool executions within a victim's active session.
Credential Exfiltration via Unrestricted Base URL in Flyto-core
2 TTPs 1 CVEFlyto-core versions prior to 2.26.7 allow unauthenticated callers to exfiltrate API provider keys by supplying a malicious 'base_url' parameter, which forces the library to append operator-configured secrets to requests sent to attacker-controlled infrastructure.
Flyto2 Core SSRF via Insecure Redirect Handling
1 TTP 1 CVEFlyto2 Core HTTP modules perform insufficient SSRF revalidation on HTTP redirects, allowing attackers to reach internal resources and cloud metadata services.
Unauthenticated SSRF and Secret Exfiltration in Flyto Core
1 rule 4 TTPs 1 CVEAn unauthenticated SSRF vulnerability in the Flyto Core /run endpoint allows attackers to exfiltrate the internal FLYTO_RUNNER_SECRET and perform unauthorized requests against internal infrastructure.
Multiple Vulnerabilities in GitLab
5 CVEsMultiple security vulnerabilities identified in GitLab CE and EE versions 19.x can result in remote denial of service, data confidentiality breaches, and reflected cross-site scripting.
Astaroth Botnet Deploys New WhatsApp Web Spambot Component
1 rule 9 TTPs 8 IOCsOperators of the Astaroth (aka Guildma) botnet, which targets Brazil-based users, introduced a new spambot component in Q4 2025 that leverages WhatsApp Web in headless browser mode for malware distribution, exhibiting evasion techniques like payload encryption and WebDriver automation indicator stripping.
CVE-2026-54366 CentreStack XXE Injection
1 rule 2 TTPs 1 CVECentreStack versions prior to 17.4 are vulnerable to an unauthenticated XXE injection via the SharePoint storage configuration handler, allowing attackers to exfiltrate sensitive server-side files.
Authentication Bypass Vulnerability in CentreStack
1 TTP 1 CVECentreStack versions prior to 17.2 are vulnerable to an authentication bypass that allows unauthenticated attackers to manipulate account settings and enumerate system data via exposed API endpoints.
Unauthenticated Deserialization Vulnerability in CentreStack
2 TTPsAn unauthenticated deserialization vulnerability in CentreStack allows remote attackers to create unauthorized local user accounts by sending crafted XML payloads to specific API endpoints.