Tag
UAT-10147 Deploys SPECTRE Cross-Platform Backdoor
2 rules 6 TTPsThe threat actor UAT-10147 is deploying a sophisticated cross-platform backdoor named SPECTRE, featuring kernel-level rootkits, BYOVD defense evasion, and AI-assisted development artifacts to target IIS and Linux infrastructure.
Remote Code Execution in Cost Calculator Builder PRO WordPress Plugin
1 rule 2 TTPs 1 CVEThe Cost Calculator Builder PRO plugin for WordPress, versions up to and including 4.0.3, is vulnerable to unauthenticated Remote Code Execution (RCE) via CVE-2026-14900 due to insufficient sanitization of the `orderDetails[*].originalValue` field, allowing arbitrary code injection into a `PHP eval()` call that can be exploited by unauthenticated attackers.
GoDAM WordPress Plugin Arbitrary File Upload Vulnerability (CVE-2026-14282)
1 rule 2 TTPs 1 CVEAn arbitrary file upload vulnerability exists in the GoDAM WordPress plugin versions up to and including 1.12.2 due to insufficient file type validation in the `save_video_file()` function, allowing unauthenticated attackers to upload arbitrary files to the server and potentially achieve remote code execution.
Grav Remote Code Execution Vulnerability in Blueprint::dynamicData()
2 TTPs 1 CVE 4 IOCsA critical remote code execution vulnerability (CVE-2026-65008) in Grav versions prior to 2.0.7 allows an authenticated attacker with `admin.pages` or `api.pages.write` permissions to embed malicious callable directives in a page's frontmatter, leading to arbitrary code execution as the web-server user when the page is accessed.
Unusual Command Execution via Linux Web Server Processes
1 rule 4 TTPsThis brief details how attackers exploit vulnerable web applications or deploy webshells on Linux systems to achieve persistence by executing unusual shell commands from web server processes, potentially leading to payload downloads, reverse shells, or cron-like task implants.
CVE-2026-56400 open-webui Cross-Origin Resource Sharing Misconfiguration Leads to RCE
3 TTPs 1 CVEA cross-origin resource sharing (CORS) misconfiguration in open-webui versions prior to 0.3.14 allows remote attackers to achieve arbitrary code execution by crafting malicious cross-site requests that an authenticated administrator user visits.
CVE-2026-15489: SQL Injection in RafyMrX TOKO-ONLINE-ROTI login.php
2 rules 4 TTPs 1 CVEA critical SQL injection vulnerability (CVE-2026-15489) exists in RafyMrX TOKO-ONLINE-ROTI, allowing remote attackers to bypass authentication and potentially exfiltrate sensitive data by manipulating the 'Username' argument in the 'proses/login.php' file, with a public exploit available.
CVE-2026-61428: PraisonAI AgentMail Webhook Signature Bypass
3 TTPs 1 CVEPraisonAI AgentMail versions before 4.6.78 are vulnerable to CVE-2026-61428, an authentication bypass flaw in webhook mode that allows unauthenticated attackers to inject messages with spoofed sender addresses, enabling them to trigger replies to attacker-controlled addresses and bypass email filtering.
Unauthenticated PHP Object Injection in PrestaShop ps_facetedsearch Leads to RCE
1 rule 3 TTPsAn unauthenticated PHP Object Injection vulnerability, tracked as CVE-2026-54159, affects the PrestaShop ps_facetedsearch module versions 3.0.0 through 4.0.3, allowing attackers to craft malicious serialized PHP objects in URL parameters that, upon deserialization, result in arbitrary file writes and remote code execution on the server.
CVE-2026-15070: WordPress Salon Booking Plugin CSRF to RCE
1 rule 3 TTPsThe Salon Booking System - Free Version plugin for WordPress (versions up to and including 10.30.32) is susceptible to a Cross-Site Request Forgery (CSRF) vulnerability stemming from a lack of nonce validation in the setCustomText function, allowing unauthenticated attackers to inject arbitrary PHP code into the web-accessible translate-constants.php file, which can lead to remote code execution (RCE) on the server if an administrator is tricked into clicking a crafted link.
Critical RCE Vulnerability in Hermes WebUI (CVE-2026-58123)
1 rule 2 TTPs 1 CVEAn unauthenticated remote code execution vulnerability, CVE-2026-58123, exists in Hermes WebUI versions prior to 0.51.788, allowing remote attackers to execute arbitrary shell commands by accessing exposed terminal API endpoints without credentials, leading to full command execution as the server process user.
CVE-2026-8848: Popup Maker WordPress Plugin Authorization Bypass Leading to RCE
1 rule 2 TTPs 1 CVEAn authorization bypass vulnerability, CVE-2026-8848, exists in the Popup Maker WordPress plugin versions up to and including 1.22.0, allowing authenticated attackers with editor-level access or higher to install and activate arbitrary plugins from a controlled URL, which leads to remote code execution, provided a valid Popup Maker Pro license is active and the Pro version is not yet installed.
CVE-2026-15135 - SQL Injection in code-projects Online Food Order System
1 rule 3 TTPs 1 CVE 7 IOCsA high-severity SQL injection vulnerability, CVE-2026-15135, exists in code-projects Online Food Order System 1.0 affecting the `/edit_food_items.php` file's 'update' argument, allowing remote attackers to perform unauthorized data disclosure or manipulation, with a public exploit available.
Joro: Unauthenticated Cross-Origin Plugin Upload Leads to RCE
2 rules 5 TTPs 1 IOCJoro's default proxy mode (versions ≤ v1.1.0) is vulnerable to unauthenticated remote code execution (CVE-2026-53649) via a local API on `127.0.0.1:9090` that allows cross-origin JavaScript to upload a malicious native plugin and trigger a system restart, leading to RCE as the operator's user from a single page visit.
CVE-2026-14495: DoLogin Security Plugin Authentication Bypass via Insufficient Randomness
2 TTPs 1 CVEThe DoLogin Security plugin for WordPress, in all versions up to and including 4.3, is vulnerable to authentication bypass (CVE-2026-14495) due to insufficient randomness in magic-link token generation, allowing unauthenticated attackers to brute-force and reconstruct valid passwordless login tokens for any user, including administrators, and gain full control.
9routers Database Exposure and Takeover via Insecure API
1 rule 6 TTPs 1 IOCA critical vulnerability (CVE-2026-55500) in 9routers versions <= 0.4.71 allows authenticated attackers with a valid JWT token to export the complete database containing plaintext credentials and secrets, and to import a modified database, leading to full system takeover and credential theft.
Gitea: Multiple Vulnerabilities Leading to XSS, Info Disclosure, and File Manipulation
4 TTPsAn attacker can exploit multiple unpatched vulnerabilities in Gitea to bypass security measures, disclose sensitive information, perform Cross-Site Scripting (XSS) attacks, and manipulate files, posing a high risk to self-hosted Git instances.
CVE-2026-14747: SQL Injection in code-projects Real State Services 1.0
1 rule 1 TTP 1 CVEA high-severity SQL Injection vulnerability, CVE-2026-14747, exists in the /addprojectsale.php file of code-projects Real State Services 1.0, allowing remote unauthenticated attackers to manipulate the 'amen' argument for arbitrary SQL query execution, leading to data compromise or unauthorized access.
CVE-2026-14744: Remote SQL Injection in code-projects Real State Services 1.0
1 rule 4 TTPs 1 CVE 6 IOCsA critical SQL injection vulnerability (CVE-2026-14744) has been found in code-projects Real State Services version 1.0. The flaw resides in an unknown function within the /normalHomeRent.php file, where manipulating the 'loc' argument allows for remote SQL injection, and a public exploit has been released, posing an immediate threat to affected systems.
CVE-2026-14737: Hanwang e-Face General Management Platform SQL Injection
1 rule 1 TTP 1 CVEA remote SQL injection vulnerability (CVE-2026-14737) affects Hanwang e-Face General Management Platform version 6.3.5.4, specifically within the `/sysAuthStr/querySysAuthStr.do` file, triggered by manipulating argument order, allowing remote attackers to potentially gain unauthorized access to or modify database contents with a publicly available exploit.
Web Server Cloud Metadata SSRF Exploitation
1 rule 2 TTPs 7 IOCsAttackers are actively exploiting Server-Side Request Forgery (SSRF) vulnerabilities in public-facing web applications to access cloud instance metadata services, such as those on AWS, GCP, and Azure, to harvest temporary credentials and sensitive instance details.
Steeltoe Host Header Bypass Vulnerability (CVE-2026-50194)
1 rule 2 TTPs 1 CVEAn unauthenticated remote attacker can bypass port isolation in Steeltoe applications configured with `Management:Endpoints:Port` by spoofing the Host HTTP header, allowing access to all actuator endpoints (CVE-2026-50194).