Skip to content
Threat Feed

July 2026 (30)

medium advisory

Credential Exfiltration via koku-metrics-operator SSRF

An SSRF vulnerability in the koku-metrics-operator allows an authenticated user to exfiltrate the cluster-global Red Hat pull-secret token by specifying an arbitrary destination URL within the CostManagementMetricsConfig resource.

Cost Management Metrics Operator
1t
high advisory

Authorization Bypass in Subscriptions for WooCommerce Plugin

An authorization flaw in the Subscriptions for WooCommerce WordPress plugin allows authenticated users with shop manager privileges to remotely install and activate arbitrary plugins.

Subscriptions for WooCommerce wordpress plugin web-application-vulnerability cve-2026-15397
1r 2t 1c
critical advisory

Authentication Bypass and RCE in CentreStack via Hardcoded Cryptographic Key

CentreStack versions prior to 17.5 contain a hardcoded cryptographic key vulnerability, allowing unauthenticated attackers to forge authentication tokens and execute arbitrary code.

CentreStack authentication-bypass remote-code-execution hardcoded-key
1t 1c
critical advisory

Critical Vulnerabilities in VMware vCenter and ESX Products

Multiple critical vulnerabilities, including CVE-2026-59309 and CVE-2026-59310 with CVSS 9.8, affect VMware vCenter and ESX/ESXi products, enabling unauthorized access without credentials, arbitrary code execution, virtualization escape, information disclosure, and defense evasion, which could lead to full system compromise and data breaches.

PoC VMware vCenter +13 virtualization critical-vulnerability rce unauthorized-access privilege-escalation defense-evasion esxi vcenter
5t 4c updated
high advisory

OctLurk and SilkLurk Memory-Resident Backdoors Targeting Central Asia

OctLurk and SilkLurk are sophisticated, memory-resident backdoors targeting government and research entities in Central Asia since January 2025, utilizing machine-specific key derivation for payload decryption and modular plugin injection.

Windows backdoor cyber-espionage memory-resident central-asia chinese-speaking
1r 4t 6i
critical threat

Microsoft Addresses Two Actively Exploited Zero-Day Vulnerabilities in July 2026 Patch Tuesday

Microsoft's July 2026 Patch Tuesday addressed 622 vulnerabilities, including two actively exploited zero-day elevation of privilege flaws, CVE-2026-56155 in Active Directory Federation Services and CVE-2026-56164 in SharePoint, allowing local and remote attackers to gain administrative control.

exploited PoC Active Directory Federation Services +23 patch-tuesday zero-day vulnerability microsoft windows sharepoint active-directory-federation-services bitlocker +2
8t 4c 8i updated
critical threat

Critical RCE Vulnerability in Langflow AI Pipelines (CVE-2026-33017)

A critical remote code execution vulnerability, CVE-2026-33017, exists in Langflow AI pipelines prior to version 1.9.0 that allows an unauthenticated remote attacker to execute code with full server process privileges, impacting availability, integrity, and confidentiality.

Siyuan +6 langflow rce cve-2026-33017 ai-pipeline
2r 2t 1i updated
medium advisory

IBM WebSphere Application Server Security Bypass Vulnerability

IBM WebSphere Application Server and Liberty are vulnerable to a security bypass flaw that permits remote, unauthenticated attackers to circumvent established security controls.

WebSphere Application Server +1 vulnerability websphere middleware
1t
low advisory

Denial of Service Vulnerabilities in RHEL perl-Archive-Tar and httplib2

Multiple vulnerabilities in Red Hat Enterprise Linux packages perl-Archive-Tar and httplib2 can be exploited by a remote, anonymous attacker to cause a Denial of Service condition.

Enterprise Linux +2 vulnerability denial-of-service linux
1t 2c
high advisory

Remote Code Execution Vulnerability in KDE Konsole

A vulnerability in the KDE Konsole application allows a remote, unauthenticated attacker to execute arbitrary code, potentially leading to full system compromise.

Konsole
1t
high advisory

Suspicious Windows Public IP Address Discovery via DNS

Adversaries frequently use public IP lookup services to perform network reconnaissance and verify egress connectivity prior to establishing C2 channels, a behavior detectable via DNS query analysis from suspicious processes.

discovery c2 windows reconnaissance
1r 1t 33i
medium advisory

Detection of Unauthorized AWS NACL Modification by New Identities

Adversaries may modify AWS Network Access Control Lists (NACLs) to allow all traffic, effectively disabling network-layer defenses to facilitate lateral movement or data exfiltration, a behavior this detection identifies when performed by previously unseen identities.

AWS EC2 aws cloud defense-evasion
1t
medium advisory

AWS S3 Bucket ACL Modification to Public Access by New Identity

Detection of unauthorized S3 bucket ACL modifications to public-read or public-read-write by previously unseen identities, potentially indicating credential compromise for data exfiltration.

AWS S3 cloud aws collection s3
1r 1t
critical advisory

Unauthenticated Remote Access to Phoenix Contact CHARX SEC MQTT Broker

A critical vulnerability (CVE-2026-44090) in Phoenix Contact CHARX SEC controllers allows unauthenticated remote attackers to gain full device control by bypassing authentication on the MQTT broker.

CHARX SEC-3150 +7 industrial-control-systems mqtt cve-2026-44091 ics cve injection authentication-bypass cve-2026-44100 +14
2r 5t 12c
high advisory

Privilege Escalation Vulnerability in Phoenix Contact CHARX Controllers

A local OS command injection vulnerability (CVE-2026-44095) in Phoenix Contact CHARX charging controllers allows low-privileged users to execute arbitrary commands as root.

CHARX SEC-3000 +3 privilege-escalation industrial-control-systems cve command-injection
3t 1c
critical advisory

Command Injection in Phoenix Contact CHARX SEC Controllers

An unauthenticated remote command injection vulnerability in Phoenix Contact CHARX SEC controllers allows attackers to execute arbitrary code as root via malformed system configuration inputs.

CHARX SEC-3150 +3 cve-2026-7849 command-injection industrial-control-system
2t 1c
high threat

Toy Ghouls Deploying Custom GenieLocker Ransomware

The Toy Ghouls threat actor is deploying a custom ransomware family called GenieLocker against manufacturing organizations, utilizing compromised VPN credentials and legitimate system tools for lateral movement and encryption.

Windows +6 Toy Ghouls ransomware extortion manufacturing toy-ghouls
1r 4t 1i
high threat

Fortinet FortiOS CVE-2025-68686 Sensitive Information Exposure Bypass

A remote unauthenticated attacker can exploit CVE-2025-68686 in Fortinet FortiOS to bypass a previously applied patch, allowing sensitive information exposure and enabling persistence post-exploitation, provided the product was already compromised at the filesystem level via another vulnerability.

exploited PoC FortiOS +7 fortinet vulnerability cve exposure persistence
1t 3c 4i updated
high advisory

Privilege Escalation Vulnerability in Performance Co-Pilot linux_sockets Module

A file descriptor leak in the Performance Co-Pilot (PCP) linux_sockets module allows an attacker with initial code execution to escalate privileges to root.

Performance Co-Pilot +8 privilege-escalation linux cve-2026-16526 remote-code-execution cve-2026-16527 monitoring-tool denial-of-service vulnerability +1
1r 1t 1c
high advisory

Command Injection in PCP linux_sockets PMDA

A command injection vulnerability (CVE-2026-16524) in the PCP linux_sockets PMDA allows local attackers to execute arbitrary commands by injecting shell metacharacters into the network.persocket.filter metric.

pcp +5 vulnerability command-injection linux
1t 1c
high advisory

BuddyPress Insecure Deserialization Vulnerability

An insecure deserialization vulnerability in the BuddyPress WordPress plugin allows authenticated attackers to inject arbitrary PHP objects, potentially leading to remote code execution.

BuddyPress wordpress deserialization rce web-vulnerability
1t
high advisory

Authorization Bypass in FleekDash V2 WordPress Plugin

The FleekDash V2 plugin for WordPress contains an authorization bypass vulnerability (CVE-2026-14356) that allows authenticated attackers to overwrite user credentials, including administrative accounts, leading to full site compromise.

FleekDash V2
1r
high advisory

VaahCMS OTP Template Cross-Site Scripting and Code Execution

VaahCMS versions 2.0.0 through 2.3.4 contain a malicious obfuscated JavaScript payload in OTP email templates that executes unauthorized code in victim browsers, enabling credential theft and DOM manipulation.

VaahCMS xss credential-theft web-security
3t 1c
critical advisory

Unauthenticated Remote Code Execution in ASE Pro WordPress Plugin

The ASE Pro WordPress plugin up to version 8.9.0 is vulnerable to unauthenticated remote code execution via insecure input handling in the recursive_html function.

Admin and Site Enhancements
1r 1c
high advisory

Authentication Bypass and Information Disclosure in Senior Rubiweb

Senior Rubiweb versions 6.2.34.28 and 6.2.34.37 contain an authentication bypass vulnerability (CVE-2019-19550) allowing remote, unauthenticated attackers to access administrative functions and sensitive system information via specifically crafted HTTP requests.

Rubiweb +1
1r 1t
high advisory

Cisco Security Updates — July 2026

Roundup of Cisco security advisories published in July 2026.

PoC Cisco devices +54 roundup
5c 55i updated
critical advisory

Unauthenticated Remote Code Execution in RSFiles! Joomla Component

CVE-2026-57827 allows unauthenticated attackers to achieve remote code execution via an unrestricted file upload vulnerability in the RSFiles! Joomla component.

RSFiles! joomla rce file-upload cve-2026-57827
1r 1c
high advisory

SSRF Bypass Vulnerability in V Library

The V library (versions 0.5.2 and below) contains a server-side request forgery (SSRF) bypass vulnerability allowing attackers to circumvent host-based allowlists via URL parsing differentials.

V ssrf vulnerability web-security
1t 1c
critical advisory

SSRF Vulnerability in IBM WebSphere Application Server

IBM WebSphere Application Server and Liberty are vulnerable to unauthenticated Server-Side Request Forgery (SSRF) when the SIP container feature is enabled, allowing attackers to perform unauthorized requests to internal services.

WebSphere Application Server +2 ssrf webserver vulnerability
1c
critical advisory

Hard-coded Credentials in Care Everywhere Gateway WildFly Management Interface

An unauthenticated remote code execution vulnerability exists in Care Everywhere Gateway 14.3.10 due to hard-coded credentials within the bundled WildFly 8.2.0.Final management interface.

Care Everywhere Gateway +1
2t 1c