Daily Updates

Cyber News

Short, concise cybersecurity updates. 146 records found.

newsHIGH 7.0

Snipe-IT Improper Privilege Management Vulnerability (CVE-2026-55843)

A vulnerability in Snipe-IT, a popular IT asset management system, allows attackers to exploit improper privilege management, potentially leading to privilege escalation and administrative access loss. The issue affects versions prior to 8.6.0 and has been patched. Users should update to version 8.6.0 or later to mitigate this vulnerability.

1 source
newsHIGH 8.2

CVE-2026-47877: Spring Security Authorization Server Vulnerability

A vulnerability in Spring Security Authorization Server's default consent page allows an attacker to inject user-controlled values without HTML entity encoding, potentially leading to XSS attacks. Affected versions include Spring Security 7.1.0 and 7.0.0-7.0.6. The CVSS score is 8.2, indicating a high severity vulnerability.

1 source
newsHIGH 7.5

Linux Kernel Vulnerability: CVE-2026-74741 - NULL Pointer Dereference in Non-MSI-X Interrupt Enabling

A vulnerability in the Linux kernel, specifically in the ngbe driver, allows for a NULL pointer dereference in non-MSI-X interrupt enabling. This issue has a CVSS score of 7.5 and can lead to a denial of service (DoS) attack. Affected systems include Linux versions prior to specific commits and version 6.16.

1 source
newsHIGH 8.1

CVE-2026-80192: @better-auth/sso Domain-Ownership Flaws Allow Organization Takeover and Account Linking

A vulnerability in @better-auth/sso (CVE-2026-80192, CVSS 8.1) allows attackers to exploit domain-ownership flaws, potentially leading to organization takeover and account linking. Affected versions include those before 1.6.27, 1.4.8, and 1.7.0-rc.5. Immediate action is required to update to a patched version.

1 source
newsCRITICAL 9.8

Critical Vulnerability in QWED-MCP: Arbitrary Code Execution via SymPy's parse_expr() Function

A critical vulnerability (CVE-2026-55546, CVSS score: 9.8) was discovered in QWED-MCP, a deterministic verification gateway for MCP, which allows an attacker to execute arbitrary operating-system commands, read or modify accessible data, exfiltrate process secrets, or reach internal services. The vulnerability exists in the verify_math_expression() function in src/qwed_mcp/engines/math_engine.py, which passes attacker-controlled input to SymPy's parse_expr() function without proper validation. Affected versions are prior to 0.2.1.

1 source
newsCRITICAL 9.2

gRPC Erlang Package Vulnerable to Remote Code Execution

The gRPC Erlang package is vulnerable to remote code execution with attacker-controlled gRPC payloads. Any unauthenticated peer that can reach a gRPC endpoint with `Content-Type: application/grpc+erlpack` can crash the entire BEAM node or achieve remote code execution inside the server process. Affected versions include `grpc` ≥ 0.4.0.

1 source
newsCRITICAL 9.1

CVE-2026-67602: phpIPAM REST API Authentication Bypass Vulnerability

A critical vulnerability (CVE-2026-67602, CVSS 9.1) in phpIPAM before 1.8.2 allows unauthenticated attackers to bypass authentication and gain full API access, enabling them to read, write, and delete IP address management records. This vulnerability is due to an insecure object cache keying mechanism in the REST API.

1 source
newsHIGH 8.9

Critical Vulnerability in Velociraptor: CVE-2026-19200

A critical vulnerability (CVE-2026-19200, CVSS 8.9) in Velociraptor allows attackers with NOTEBOOK_EDIT permission to overwrite existing artifacts without required permissions, potentially leading to high impact on confidentiality and integrity. Affected versions are Velociraptor < 0.77.2 on Linux and Windows. Immediate mitigation is required.

1 source
newsMEDIUM 6.1

CVE-2026-5751: justhtml Parser-Differential Cross-Site Scripting Vulnerability

A parser-differential cross-site scripting (mXSS) vulnerability exists in justhtml versions 1.13.0 and earlier. The flaw allows for markup injection when using a custom SanitizationPolicy that preserves foreign namespaces. Update to version 1.14.0 or later to mitigate.

1 source
newsHIGH 7.5

CVE-2026-62388: NLTK Insecure Default Configuration in pathsec.py Allows Path Traversal and Pickle Deserialization Bypass

A vulnerability in NLTK versions before 3.10.0 allows attackers to bypass path traversal and pickle deserialization protections due to insecure default configuration. The vulnerability has a CVSS score of 7.5 and is classified as HIGH severity. Affected users should update NLTK to version 3.10.0 or later.

1 source
newsHIGH 7.5

Authorization Bypass Vulnerability in WWBN AVideo (CVE-2026-59256)

A vulnerability in WWBN AVideo allows attackers to bypass authorization checks by retrieving a token from the Gallery endpoint, affecting video content access. The vulnerability has a CVSS score of 7.5 and is classified as HIGH severity. AVideo users should update to a fixed version to mitigate this risk.

1 source
newsCRITICAL 9.9

Critical Vulnerability in Incus: Arbitrary File Write Leads to Root Command Execution

A critical vulnerability (CVE-2026-48769, CVSS 9.9) exists in Incus versions prior to 7.2.0, allowing an attacker to write arbitrary files and execute commands as root on the server. This is triggered by a malicious image server returning a crafted 'Incus-Image-Hash' header. Affected users must update to version 7.2.0 or later immediately.

1 source
newsHIGH 8.0

Android Car Malware Spreads Through Built-In Updaters for Ad Fraud, Proxy Botnet

A new malware family targeting Android-based vehicle head unit firmware developed by DoFun has been discovered. The malware spreads through built-in updaters and enables ad fraud and creation of a proxy botnet. Security professionals should investigate and mitigate this threat to prevent potential attacks.

1 source
newsCRITICAL 9.0

Active Threat to Siemens S7 Series PLCs: AI-Generated Exploitation Scripts

Unattributed threat actors are actively targeting exposed Siemens S7 Series PLCs across critical infrastructure sectors using AI-generated exploitation scripts. The threat actors are leveraging AI to build and refine exploit scripts faster than manual development would allow, lowering the technical bar for ICS attacks. There is no single patch, and mitigation depends on removing Siemens S7 Series PLCs from direct internet exposure, segmenting OT from IT networks, and hardening access controls.

1 source
newsCRITICAL 9.8

CVE-2026-14950: Critical Session Fixation Vulnerability in Frauscher Sensortechnik FDS 102

A critical vulnerability (CVE-2026-14950, CVSS 9.8) exists in Frauscher Sensortechnik's FDS 102, allowing an unauthenticated remote attacker to continue using a valid session after it has expired. This could enable unauthorized access to the FDS web interface. Affected versions are 2.1.0 to 2.13.3; users should update to version 2.13.4 or later.

1 source
newsHIGH 8.8

Copier Trust-Prefix Bypass via Path Traversal (CVE-2026-53951)

A vulnerability in Copier (CVE-2026-53951) allows an attacker to bypass the trust prefix check via path traversal, leading to arbitrary command execution. Affected versions are Copier >= 9.5.0 and <= 9.15.1. Users should update to a patched version to mitigate this high-severity vulnerability.

1 source
newsHIGH 8.6

Critical Cross-Site Scripting Vulnerability in SiYuan Note-taking App

A critical cross-site scripting (XSS) vulnerability, CVE-2026-74902, has been discovered in SiYuan, a popular note-taking application, affecting versions prior to 3.7.4. This vulnerability allows attackers to craft malicious filenames that can execute with full OS command access when a user interacts with the file. Immediate action is required to update to a patched version.

1 source
newsHIGH 8.1

CVE-2026-75044: JetBrains YouTrack Authorization Bypass Vulnerability

A vulnerability in JetBrains YouTrack before versions 2025.3.156085, 2026.1.13914, and 2026.2.18095 allows an authenticated user to delete arbitrary entities via the mailbox endpoint due to missing authorization. This vulnerability has a CVSS score of 8.1, indicating high severity. Affected organizations should update to a patched version immediately.

1 source
newsHIGH 8.7

vm2 Buffer Alloc Limit Bypass via Buffer.concat and Buffer.from

A vulnerability in vm2 allows untrusted sandbox code to bypass the bufferAllocLimit cap, leading to a potential DoS attack. The vulnerability has a CVSS score of 8.7 and is identified as CVE-2026-47683.

1 source
newsCRITICAL 9.0

Medplum Vulnerability: Improper Validation of Redirect URI in External Auth Callback (CVE-2026-53728)

A critical vulnerability in Medplum's external auth callback allows an attacker to leak authorization codes by manipulating the redirect URI. This affects users of Medplum's external identity provider flow, potentially leading to full account takeover and exposure of sensitive healthcare data. Immediate action is required to mitigate this vulnerability.

1 source
newsHIGH 8.8

CVE-2026-17123: Royal Elementor Addons Plugin for WordPress Server-Side Request Forgery Vulnerability

The Royal Elementor Addons plugin for WordPress is vulnerable to Server-Side Request Forgery (SSRF) in versions up to and including 1.7.1064. An authenticated attacker with Contributor-level access and above can exploit this vulnerability to make web requests to arbitrary locations, potentially querying and modifying information from internal services. The CVSS score for this vulnerability is 8.8, indicating a high severity level.

1 source
newsLOW 2.0

Evaluating the Security Implications of Limited Training Data in Large Language Models

A research project explores the effects of restricting training data to only fifth-grade level material on the capabilities and potential vulnerabilities of large language models (LLMs). There is no evidence of active exploitation. Security professionals should assess the implications of such limitations on LLMs' security and reliability.

1 source
newsHIGH 8.8

CVE-2026-15312: Privilege Escalation in Propovoice: All-in-One Client Management System Plugin

The Propovoice: All-in-One Client Management System plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.7.8. Authenticated attackers with `ndpv_manager`-level access can create a new WordPress user account with the `administrator` role assigned, achieving full vertical privilege escalation. Immediate action is required to update the plugin to a patched version.

1 source
newsHIGH 8.7

Unauthenticated Denial of Service in Grav via Unbounded Image Derivative Dimensions

An unauthenticated visitor can exhaust server memory and CPU by requesting an image with oversized resize dimensions in Grav, potentially taking the host down. This affects any Grav site that serves images with no account, plugin, or non-default config required. The vulnerability has a CVSS score of 8.7.

1 source
newsHIGH 8.8

CVE-2026-19791: Tenda G0 Stack-Based Buffer Overflow Vulnerability

A stack-based buffer overflow vulnerability exists in Tenda G0 up to version 20260625, affecting the httpd web management interface. An attacker can exploit this vulnerability remotely by manipulating the staticRouteNet argument in the addStaticRoute function, potentially leading to arbitrary code execution. The vulnerability has a CVSS score of 8.8 and is considered high severity.

1 source
newsCRITICAL 9.8

Critical Unauthenticated Broken Authentication Vulnerability in OAuth Single Sign On – SSO (OAuth Client) Plugin

A critical vulnerability (CVE-2026-28008, CVSS score: 9.8) was discovered in the OAuth Single Sign On – SSO (OAuth Client) plugin, affecting versions up to 7.0.0. This vulnerability allows unauthenticated attackers to bypass authentication, potentially leading to unauthorized access and control. Immediate action is required to update the plugin to a secure version.

1 source
newsCRITICAL 9.3

Critical Vulnerability in Priority ERP Portal Generator Addon: CVE-2026-59507

A critical vulnerability (CVE-2026-59507, CVSS 9.3) was discovered in the Priority ERP Portal Generator addon, developed by Soft Solutions. This vulnerability affects all versions without Priwall v3 and allows for exposure of sensitive information, improper access control, and use of hard-coded credentials. Security professionals should immediately assess and mitigate this vulnerability to prevent potential exploitation.

1 source
newsCRITICAL 9.0

Lazarus Group Exploits Windows Zero-Day in Operation Dream Job

The North Korean Lazarus Group is actively exploiting a Windows zero-day vulnerability in a new campaign targeting defense professionals with fake Lockheed Martin job offers. This campaign, known as Operation Dream Job, aims to deploy backdoors and evade security controls. Security teams should prioritize patching and implement additional security measures to mitigate this threat.

1 source
newsHIGH 7.3

Ansible FreeBSD Jail Connection Plugin Vulnerability: CVE-2026-55074

A vulnerability in the Ansible FreeBSD Jail Connection Plugin (CVE-2026-55074, CVSS 7.3) allows a party controlling content inside a managed jail to cause an arbitrary root-owned write on the host, outside the jail, leading to a full jail escape. This affects versions up to 1.3.0; upgrade to 2.0.0 or later to mitigate.

1 source
newsCRITICAL 9.0

Lazarus APT Group Exploits Windows Zero-Day Using Post-Quantum Key Exchange

The Lazarus APT group has been actively exploiting a Windows zero-day vulnerability using a novel approach involving post-quantum key exchange to deliver the exploit. This campaign is currently being actively exploited in the wild. Security professionals should prioritize patching and implement enhanced monitoring to detect this threat.

1 source