Skip to content
Threat Feed

May 2026 (30)

medium advisory

CVE-2026-46099: IPv6 NOREF DST Use Vulnerability in seg6 and rpl lwtunnels

CVE-2026-46099 describes a vulnerability in the IPv6 network stack related to NOREF dst use in seg6 and rpl lwtunnels, requiring a security update to address potential exploitation.

ipv6 network denial-of-service information-disclosure
2r 1c
medium advisory

CVE-2026-46072 ntfs3 Buffer Boundary Check Vulnerability

CVE-2026-46072 is a buffer boundary check vulnerability in ntfs3 affecting an unspecified Microsoft product, requiring further investigation upon patch application to understand exploitation vectors and develop detections.

vulnerability ntfs3 buffer-overflow
2r 1c
medium threat

CVE-2026-45842: Unspecified Vulnerability in Microsoft Products

CVE-2026-45842 is an unspecified vulnerability affecting Microsoft products, requiring further investigation to determine the specific attack vector, impact, and affected systems.

Unspecified Microsoft Product vulnerability microsoft
2r 1t 1c
medium threat

CVE-2026-44899 Mistune Image Directive CSS Injection Vulnerability

CVE-2026-44899 is a CSS Injection vulnerability in the Mistune Image Directive, potentially allowing for malicious CSS injection if user-supplied content is not properly sanitized.

Mistune Image Directive css-injection vulnerability mistune
2r 1c
medium threat

CVE-2025-71305 Published - Insufficient DP MST VCPI Protection

Microsoft published CVE-2025-71305, addressing a vulnerability related to insufficient protection against zero VCPI values in DisplayPort Multi-Stream Transport (MST), although specifics on exploitation and impact are not detailed in the provided source.

cve vulnerability displayport
2r 1c
medium threat

CVE-2026-45843 slip: bound decode() vulnerability

CVE-2026-45843 is a Microsoft vulnerability with unspecified details at the time of this brief.

cve vulnerability microsoft
1r 1c
high advisory

CVE-2026-45571 go-git Crafted Repositories Modify .git Directories

CVE-2026-45571 is a vulnerability in go-git that allows crafted repositories to modify main and submodule .git directories, potentially leading to arbitrary code execution or information disclosure.

go-git cve git directory modification code execution
2r 1c
medium advisory

CVE-2026-44844 eml_parser Recursion Denial-of-Service

CVE-2026-44844 is a denial-of-service vulnerability in Microsoft's eml_parser due to recursion in nested message/rfc822 attachments, potentially causing a service outage.

eml_parser dos vulnerability
2r 1t 1c
medium advisory

CVE-2026-45932 bpf: Fix tcx/netkit Detach Permissions

CVE-2026-45932 is a vulnerability affecting the bpf component, related to tcx/netkit detach permissions when the prog fd isn't given, requiring a security update from Microsoft.

cve bpf permissions microsoft
2r 1c
medium advisory

CVE-2026-45991 UDF Partition Descriptor Append Bookkeeping Vulnerability

CVE-2026-45991 is a security vulnerability affecting a Microsoft product, related to UDF partition descriptor append bookkeeping.

udf vulnerability msft
2r 1c
medium advisory

CVE-2026-46084 RDMA/mana_ib: Disable RX steering on RSS QP destroy

CVE-2026-46084 is a vulnerability related to RDMA/mana_ib that requires disabling RX steering on RSS QP destroy, potentially leading to denial of service or privilege escalation.

rdma mana_ib rss_qp rx_steering cve-2026-46084
2r 1c
critical advisory

Crawlomatic Multipage Scraper Post Generator Plugin RCE (CVE-2026-9009)

The Crawlomatic Multipage Scraper Post Generator plugin for WordPress is vulnerable to remote code execution (RCE) via the 'callback_raw' shortcode attribute, allowing authenticated attackers with author-level access or higher to execute arbitrary code on the server.

Crawlomatic Multipage Scraper Post Generator plugin <= 2.7.2 CVE-2026-9009 rce wordpress plugin crawlomatic
2r 1t 1c
high advisory

FUXA Unauthenticated Project Data Disclosure Vulnerability

FUXA v1.3.0-2773 is vulnerable to unauthenticated project data disclosure (CVE-2026-47717) via the /api/project endpoint, exposing sensitive configuration data like scripts and device settings, even with security enabled.

FUXA v1.3.0-2773 cve unauthenticated-access data-disclosure ics scada
2r 1t
critical threat

Yamcs Authenticated Remote Code Execution via Jython Algorithm Code Injection

Yamcs is vulnerable to authenticated remote code execution (CVE-2026-46621) where an authenticated user with the ChangeMissionDatabase privilege can inject malicious Jython code into existing Python algorithms, leading to arbitrary command execution on the underlying host operating system.

yamcs-core rce code-injection yamcs
2r 1t 1i
medium advisory

Pimcore CustomReports Share Bypass Vulnerability

Pimcore's CustomReports feature has a share bypass vulnerability due to inconsistent authorization checks between the report listing endpoint and the report detail endpoint, allowing low-privileged users to access report configurations without explicit sharing permissions.

Pimcore CustomReports privilege-escalation defense-evasion web-application
1r 2t
high threat

Cyber Extortion Economy Shifting Towards Data Theft

Cyber extortion is increasingly relying on data theft rather than ransomware encryption, with threat actors like Bling Libra and TGR-CRI-1135 leveraging techniques like vishing and software supply chain compromise, fueled by regulatory compliance pressures and the impending weaponization of frontier AI models.

EBS +1 Bling Libra cyber-extortion data-theft ransomware
2r 4t
high advisory

Automad Unauthenticated Exposure of Administrator Password Hashes and TOTP Secrets

Automad versions 2.0.0-alpha.1 through 2.0.0-beta.27 are vulnerable to CVE-2026-45332, a Broken Access Control vulnerability that allows an unauthenticated attacker to retrieve bcrypt password hashes of administrator accounts using a single POST request to the `/_api/user-collection/create-first-user` endpoint, potentially leading to credential compromise and information disclosure.

Automad broken-access-control credential-access cve-2026-45332
2r 2t
high advisory

GPU Mining Malware Spreads via SEO Poisoning and AI Chatbots

A cryptojacking campaign targets systems with high-performance GPUs using SEO poisoning and manipulated AI chatbot recommendations, distributing malware disguised as legitimate software utilities to establish persistence and evade detection before deploying GPU mining programs.

Microsoft Defender +8 cryptojacking seo-poisoning process-hollowing persistence defense-evasion gpu-mining windows
3r 6t 1i
high threat

Symfony Email Header / SMTP Command Injection via CRLF Characters

Symfony's Mime Address component is susceptible to email header and SMTP command injection due to accepting CRLF characters within email addresses, leading to potential header manipulation or unauthorized SMTP commands in symfony/mime and symfony/symfony versions prior to 5.4.52, versions 6.0.0 to before 6.4.40, versions 7.0.0 to before 7.4.12 and versions 8.0.0 to before 8.0.12.

symfony/mime +1 crlf-injection email-injection symfony CVE-2026-45067
2r 1t
high advisory

CrowdSec AppSec WAF Bypass via Chunked/HTTP-2 Requests

CrowdSec AppSec component fails to read the HTTP request body for chunked/HTTP-2 requests, leading to a bypass of WAF rules targeting `REQUEST_BODY`, `BODY_ARGS`, `ARGS_POST`, `JSON`, or `XML`, enabling unauthenticated remote attackers to evade body-inspection pipelines.

CrowdSec AppSec waf-bypass appsec web-application
2r 1t
high advisory

Deno TLS Plaintext Injection Vulnerability

A vulnerability in Deno's Node.js tls compatibility layer (versions 2.0.0 to 2.7.7) allows a network attacker to intercept and tamper with plaintext application data transmitted over a supposedly TLS-protected connection when `autoSelectFamily` is enabled and the initial connection attempt fails, leading to potential information disclosure and data manipulation.

deno tls plaintext vulnerability
2r 1t
medium advisory

Google Chrome Security Update Released

Google released a security update on May 27, 2026, to address vulnerabilities in Chrome for Desktop versions prior to 0.7778.216/217 for Windows, 148.0.7778.215/216 for Mac, and 148.0.7778.215 for Linux, requiring users to apply the necessary updates to mitigate potential exploitation.

Chrome for Desktop browser vulnerability chrome patch
2r
critical threat

Critical Deserialization Vulnerability in Apache ActiveMQ NMS AMQP Client (CVE-2025-54539)

A critical deserialization of untrusted data vulnerability (CVE-2025-54539) exists in Apache ActiveMQ NMS AMQP Client <= v2.3.0, where an attacker controlling or impersonating an AMQP broker can send malicious serialized data that the client deserializes unsafely, allowing arbitrary code execution on the client system.

ActiveMQ NMS AMQP Client <= v2.3.0 deserialization rce activemq cve-2025-54539 windows
2r 1t 1c
critical advisory

LiquidJS Remote Code Execution Vulnerability

A remote code execution vulnerability exists in LiquidJS versions prior to 10.26.0, where crafted templates can execute arbitrary code by manipulating the `valueOf` filter and leveraging function calls via a comparable gadget.

liquidjs rce template-injection
2r 1t
medium advisory

Threat Actors Spoofing FIFA Websites in Advance of the 2026 World Cup

Cyber threat actors are conducting spoofing attacks against FIFA websites in advance of the 2026 FIFA World Cup to steal personal information and facilitate monetary scams.

fifa.com fifa spoofing phishing typo-squatting
2r 1t 36i
high threat

Kirby CMS Stored XSS Vulnerability in KirbyTags and Image Blocks (CVE-2026-45368)

Kirby CMS is vulnerable to stored cross-site scripting (XSS) due to insufficient sanitization of links within KirbyTags and image blocks, allowing authenticated users with content editing privileges to inject malicious JavaScript that executes when other users interact with the crafted links on the site frontend; patched in versions 4.9.1 and 5.4.1.

cms +1 xss kirbycms cve-2026-45368
2r 1t
critical advisory

Daemon Tools Lite Embedded Malicious Code Vulnerability

Daemon Tools Lite contains an unspecified vulnerability (CVE-2026-8398) that has a high impact on confidentiality, integrity, and availability, requiring immediate mitigation or discontinuation of use.

Daemon Tools Lite cve-2026-8398 vulnerability
2r 1c
high advisory

Nx Console Compromised Extension Harvesting Credentials (CVE-2026-48027)

Nx Console contained an embedded malicious code vulnerability (CVE-2026-48027) which allowed a malicious version of the extension to be published and harvest credentials from disk and memory.

Nx Console supply-chain credential-theft cve
2r 1t 1c
high advisory

Pimcore WebDAV Asset MOVE Missing Authorization Vulnerability

Pimcore's WebDAV asset endpoint exposes a `MOVE` operation without authentication, allowing unauthenticated remote attackers to delete assets if they know two existing asset paths in the same directory; Authenticated low-privileged users may also be able to perform unauthorized asset move or overwrite operations because the move path does not enforce `rename`, `delete`, `create`, or `publish` permissions, leading to data loss, content integrity loss, and service disruption.

pimcore/pimcore webdav asset-management missing-authorization pimcore
2r 2t
high advisory

Pimcore Unsafe PHP Deserialization Vulnerability (CVE-2026-45162)

Pimcore v11 and earlier is vulnerable to unsafe PHP deserialization in multiple locations due to missing `allowed_classes` restrictions when calling `unserialize()` on data from database columns and filesystem files; an attacker with control over serialized data sources (e.g., via SQL injection or file write vulnerabilities) can inject PHP gadget chains, leading to remote code execution.

pimcore/pimcore +1 deserialization remote code execution php
2r 1t