SEC536: Adversarial AI - Penetration Testing AI Systems


Experience SANS training through course previews.
Learn MoreLet us help.
Contact usBecome a member for instant access to our free resources.
Sign UpWe're here to help.
Contact UsISC provides a free analysis and warning service to thousands of Internet users and organizations, and is actively working with Internet Service Providers to fight back against the most malicious attackers. https://isc.sans.edu/about.html
My Stack Simulator
Published: 2026-07-08
Last Updated: 2026-07-08 08:09:03 UTC
by Xavier Mertens (Version: 1)
The stack is a memory region where a program stores temporary data - like local variables and return addresses. Think of the stack as a pile of plates in your kitchen: you can only add a new plate to the top, and you can only take one away from the top too. Programs use this same "last in, first out" principle to keep track of what they're doing. Every time a function is called, the program pushes a new plate onto the stack containing things like local variables and the address to return to once the function finishes. When the function is done, that plate is popped off the top, and execution resumes exactly where it left off. This simple mechanism is what allows programs to call functions within functions within functions, and always find their way back - but it's also precisely why a stack that grows too large, or gets overwritten with unexpected data, becomes a favorite target for attackers looking to hijack a program's execution flow.
In the SANS class FOR610[1] (malware analysis), there is an introduction to assembly and, when students learn how functions work, they have to understand how the stack also works. If you’ve no prior experience, it could be a bit challenging. To help students to vizualise how the stack works, I created a “stack simulator” that allows to “see” what’s happening when code is executed ...
Read the full entry: https://isc.sans.edu/diary/My+Stack+Simulator/33138/
RCS and DNS: The NAPTR Record
Published: 2026-07-06
Last Updated: 2026-07-06 13:35:58 UTC
by Johannes Ullrich (Version: 1)
Over the last year, with recent updates to iOS and Android, RCS (Rich Communication Services) has become an increasingly used protocol. RCS is supposed to eventually replace SMS, and in addition to richer formatting, provides added (but optional) security. RCS messages may be end-to-end encrypted and digitally signed. Unlike SMS, which was "bolted on" to existing voice-focused phone standards. The SMS standard was based on old-fashioned pagers and allowed for limited clear-text communications. RCS is built from the ground up around modern IP-based network infrastructure and behaves more like IP chat services (think iMessage, WhatsApp...). RCS defines the message format, while protocols like SIP are used to establish connections and transport messages.
"Do as you say", I do from time to time take a look at odd DNS traffic on my network. An activity I recommend when teaching SEC503. Recently, I noticed more "NAPTR" queries, a record type I had not seen before. The record type is defined in RFC 2915, which was ratified in 2000. It is not a new record. But so far, at least in my network, it has not really shown up before.
The description of the record sounds rather ominous ...
Read the full entry: https://isc.sans.edu/diary/RCS+and+DNS+The+NAPTR+Record/33124/
More Odd DNS Records: NIMLOC
Published: 2026-07-07
Last Updated: 2026-07-07 18:09:04 UTC
by Johannes Ullrich (Version: 1)
Yesterday, I talked about NAPTR records and how they are related to RCS. But there is another "odd" record that shows up in my DNS logs. This one isn't new, but I don't think I ever covered it: NIMLOC. At least that is what Zeek calls it. But let's see what it is all about.
At first, it looks like NIMLOC records are no longer used. Google's AI overview explains: "A NIMLOC (Nimrod Locator) DNS record is an obsolete resource record type (Type 32) originally designed for the Nimrod routing architecture to map names to network locators. Because Nimrod was an experimental protocol, NIMLOC records are considered historic and are not used in modern, standard network operations."
While I do have one or the other odd IOT device in my network, I doubt any of them speak "Nimrod". On the other hand, the queries originate from my macOS systems. This turns out to be an older standard, replaced by a newer (but still old) standard, with the newer standard becoming obsolete before the even older standard is phased out.
DNS defines several resource record types. The official list is maintained by IANA and I am including a sample below ...
Read the full entry: https://isc.sans.edu/diary/More+Odd+DNS+Records+NIMLOC/33128/
Why Ask Credentials If There Are Secret Codes? (2026.07.01)
https://isc.sans.edu/diary/Why+Ask+Credentials+If+There+Are+Secret+Codes/33118/
June 2026 Apple Updates (2026.06.30)
https://isc.sans.edu/diary/June+2026+Apple+Updates/33114/
Adding some Automation to the favicon.ico method of Host Recon (2026.06.29)
https://isc.sans.edu/diary/Adding+some+Automation+to+the+faviconico+method+of+Host+Recon/33110/
YARA-X 1.18.0 and 1.19.0 Release (2026.06.28)
https://isc.sans.edu/diary/YARAX+1180+and+1190+Release/33106/
What do Ports Hear When Nobody's Listening? An Assessment of Automated Cybercrime [Guest Diary] (2026.06.24)
The list is assembled by pulling recent vulnerabilities from NIST NVD, Microsoft, Twitter mentions of vulnerabilities, ISC Diaries and Podcast, and the CISA list of known exploited vulnerabilities. There are also some unscored, but significant, vulnerabilities at the end. This includes vulnerabilities that have not been added to the NVD yet.
CVE-2026-48282 (KEV), CVE-2026-48276, CVE-2026-48277, CVE-2026-48281, CVE-2026-48283, CVE-2026-48313, CVE-2026-48315, CVE-2026-48316 - Multiple vulnerabilities in Adobe ColdFusion.
Product: Adobe Coldfusion
CVSS Scores: 9.3 - 10.0
** KEV since 2026-07-07 **
NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-48282 (path traversal)
NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-48276 (unrestricted file upload)
NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-48277 (improper input validation)
NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-48281 (improper input validation)
NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-48283 (unrestricted file upload)
NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-48313 (path traversal)
NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-48315 (malicious file interaction)
NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-48316 (improper input validation)
NVD References:
- https://helpx.adobe.com/security/products/coldfusion/apsb26-68.html
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-48282
CVE-2026-48286 - Adobe Campaign Classic (ACC) versions 7.4.3 build 9396 and earlier have an Incorrect Authorization vulnerability allowing arbitrary code execution without user interaction.
Product: Adobe Campaign
CVSS Score: 10.0
NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-48286
NVD References: https://helpx.adobe.com/security/products/campaign/apsb26-69.html
CVE-2026-56290 - Page Builder CK for Joomla is vulnerable to unauthenticated arbitrary file uploads, potentially resulting in remote code execution.
Product: Joomla Page Builder CK
CVSS Score: 0
** KEV since 2026-07-07 **
NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-56290
NVD References: https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-56290
CVE-2026-40139 - BeyondTrust Remote Support is vulnerable to unauthorized access by remote attackers due to a critical pre-authentication flaw in its authentication subsystem.
Product: BeyondTrust Remote Support
CVSS Score: 9.8
NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-40139
ISC Podcast: https://isc.sans.edu/podcastdetail/9996
NVD References: https://www.beyondtrust.com/trust-center/security-advisories/bt26-03
CVE-2026-40138 - BeyondTrust Remote Support and Privileged Remote Access has a critical pre-authentication vulnerability that can be exploited by a network-positioned attacker to bypass access controls and gain unauthorized access to the appliance.
Product: BeyondTrust
CVSS Score: 8.1
NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-40138
ISC Podcast: https://isc.sans.edu/podcastdetail/9996
NVD References: https://www.beyondtrust.com/trust-center/security-advisories/bt26-03
CVE-2026-40141 - BeyondTrust Remote Support and Privileged Remote Access is vulnerable to unauthorized access of resources by authenticated attackers with limited privileges due to insufficient validation of user-supplied input parameters.
Product: BeyondTrust
CVSS Score: 9.9
NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-40141
NVD References: https://www.beyondtrust.com/trust-center/security-advisories/bt26-03
CVE-2026-58289 - Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
Product: Microsoft Edge Chromium
CVSS Score: 9.0
NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-58289
MSFT Details: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-58289
CVE-2026-10536, CVE-2026-8924, CVE-2026-8926, CVE-2026-9547, CVE-2026-11564 - Multiple vulnerabilities in Libcurl
Product: Libcurl
CVSS Score: 9.8
NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-10536 (HTTP/2 stream-dependency tree UAF)
NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-8924 (trailing dot domain super cookie)
NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-8926 (password leak with netrc and user in URL)
NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-9547 (SSH improper host validation)
NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-11564 (improper certificate validation)
NVD References:
- https://curl.se/docs/CVE-2026-10536.html
- https://curl.se/docs/CVE-2026-8924.html
- https://curl.se/docs/CVE-2026-8926.html
- https://curl.se/docs/CVE-2026-9547.html
- https://curl.se/docs/CVE-2026-11564.html
CVE-2026-34037, CVE-2026-34038, CVE-2026-34047, CVE-2026-34048 - Multiple vulnerabilities in Coolify.
Product: Coolify
CVSS Score: 9.9
NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-34037 (authorization bypass)
NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-34038 (OS command injection)
NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-34047 (incorrect authorization)
NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-34048 (improper authoriztion)
NVD References:
- https://github.com/coollabsio/coolify/security/advisories/GHSA-ggrr-wrvr-x83v
- https://github.com/coollabsio/coolify/security/advisories/GHSA-qqrq-r9h4-x6wp
- https://github.com/coollabsio/coolify/security/advisories/GHSA-652w-qv22-2r7c
- https://github.com/coollabsio/coolify/security/advisories/GHSA-mw6q-2hmg-mhxv
CVE-2026-56700 - Grav CMS before 2.0.0-beta.2 contains multiple code-execution vulnerabilities, including unsafe unserialize() calls and OS command injection via plugin/theme installation, fixed in 2.0.0-beta.2.
Product: Grav CMS Scheduler, JobQueue, Framework, Cache, Adapter, FileCache, Session, InstallCommand
CVSS Score: 9.8
NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-56700
CVE-2026-58116 - LLaMA-Factory through 0.9.5 is vulnerable to remote code execution through WebUI access when malicious model paths are supplied in the Chat or Training interfaces.
Product: Hiyouga LLaMA-Factory
CVSS Score: 9.8
NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-58116
CVE-2026-58166 - OpenBMB ChatDev through 2.2.0 allows unauthenticated remote attackers to write or delete arbitrary files by exploiting a path traversal vulnerability in the file upload endpoint.
Product: OpenBMB ChatDev through 2.2.0
CVSS Score: 9.1
NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-58166
CVE-2026-58138 - Orkes Conductor 3.21.21 before 3.30.2 is vulnerable to unauthenticated remote code execution through malicious JavaScript or Python expressions submitted to the workflow API endpoint.
Product: Orkes Conductor
CVSS Score: 9.8
NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-58138
CVE-2026-10109 - IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.4 allows remote code execution through insecure DRDA handshake handling.
Product: IBM Db2
CVSS Score: 9.8
NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-10109
NVD References: https://www.ibm.com/support/pages/node/7277424
CVE-2026-58449 - txtai through 9.10.0 exposes an API /reindex endpoint that allows remote code execution in certain deployment conditions.
Product: txtai through 9.10.0
CVSS Score: 9.8
NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-58449
CVE-2026-7840 - UltraVNC repeater through 1.8.2.2 contains a global buffer overflow in its embedded HTTP administration server, allowing for arbitrary code execution by unauthenticated attackers.
Product: UltraVNC repeater
CVSS Score: 9.8
NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-7840
CVE-2026-23537 - The Feast Feature Server's `/save-document` endpoint allows unauthenticated remote attackers to write arbitrary JSON files to the server's filesystem, potentially leading to unauthorized system modifications, denial of service, or remote code execution.
Product: Feast Feature Server /save-document endpoint
CVSS Score: 9.1
NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-23537
CVE-2026-24270 - NVIDIA AIStore framework is vulnerable to authentication bypass, potentially resulting in denial of service, privilege escalation, information disclosure, and data tampering.
Product: NVIDIA AIStore framework
CVSS Score: 9.8
NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-24270
CVE-2026-57517 - Control Web Panel before 0.9.8.1225 is susceptible to a blind SQL injection vulnerability that enables unauthenticated remote attackers to execute arbitrary SQL queries and achieve remote code execution.
Product: Control Web Panel
CVSS Score: 9.8
NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-57517
CVE-2026-58126 - PACSgear PACS Scan 5.2.1 is vulnerable to unauthenticated remote code execution via an exposed .NET Remoting TCP service on port 22222, allowing attackers to read and write arbitrary files without authentication, potentially leading to remote code execution as NT Authority\SYSTEM upon service restart.
Product: PACSgear PACS Scan
CVSS Score: 9.8
NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-58126
CVE-2026-58127 - PACSgear MediaWriter 5.2.1 is vulnerable to an unauthenticated remote attack allowing an attacker to read and write arbitrary files on the host filesystem, potentially leading to remote code execution as SYSTEM.
Product: PACSgear MediaWriter 5.2.1
CVSS Score: 9.8
NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-58127
CVE-2026-50160 - Hoppscotch's unauthenticated POST /v1/onboarding/config endpoint is vulnerable to mass assignment, allowing an attacker to overwrite critical values like JWT_SECRET and SESSION_SECRET and gain full control of the server in versions 2026.4.1 and earlier.
Product: Hoppscotch
CVSS Score: 10.0
NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-50160
CVE-2026-51947 - Pivotal CRM 6.6.4.08 and systems utilizing patch-ghi-15381-cwe-502-20251225.zip allow remote attackers to execute arbitrary code via Pivotal.Engine.Client.Services.Conversion.dll, with incomplete fix for CVE-2026-39253.
Product: Pivotal CRM
CVSS Score: 9.8
NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-51947
CVE-2026-50746 - Command injection vuonerabilities in UniFi Connect Application, Access Application, and OS
Product: UniFi Connect Application, Access Application, and OS
CVSS Scores: 9.9 - 10.0
NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-50746 (Connect Application)
NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-50748 (Access Application)
NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-54402 (OS)
NVD References: https://community.ui.com/releases/Security-Advisory-Bulletin-066-066/984eceb3-49c8-4227-942d-671c289b3afc
CVE-2026-44935 - SUSE Rancher Fleet 0.15 before 0.15.2, 0.14 before 0.14.6, 0.13 before 0.13.11 and 0.12 before 0.12.15 is vulnerable to unauthorized access of fleet credentials through missing validation in Helm Deployer.
Product: SUSE Rancher Fleet
CVSS Score: 9.9
NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-44935
CVE-2026-58466 - AutoBangumi before 3.2.8 is vulnerable to hard-coded default credentials that allow unauthenticated attackers to gain full control of the application.
Product: AutoBangumi
CVSS Score: 9.8
NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-58466
CVE-2026-14544 - HPLIP is susceptible to a remote attacker exploiting an incomplete fix for CVE-2026-8631, potentially leading to privilege escalation or arbitrary code execution due to an integer overflow in the hpcups processing path.
Product: HPLIP (HP Linux Imaging and Printing Software)
CVSS Score: 9.8
NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-14544
CVE-2026-24013, CVE-2026-24014 - Vulnerabilities in Apache IoTDB.
Product: Apache IoTDB
CVSS Scores: 9.1 - 9.8
NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-24013 (authentication bypass by spoofing)
NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-24014 (path traversal)
NVD References:
- https://lists.apache.org/thread/6pwkgnqhbm56mvn309f87snm84s0b75y
- https://lists.apache.org/thread/38298f803gb5j9nlhf0l9zkf34o90h3m
CVE-2026-40047, CVE-2026-43867, CVE-2026-46454, CVE-2026-46455, CVE-2026-46456, CVE-2026-48203, CVE-2026-48204, CVE-2026-48205, CVE-2026-53913, CVE-2026-56140 - Vulnerabilities in multiple Apache Camel components.
Product: Apache Camel
CVSS Scores: 9.1 - 9.8
NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-40047 (argument injection)
NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-43867 (deserialization of untrusted data)
NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-46454 (improper input validation)
NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-46455 (insufficient session expiration)
NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-46456 (improper input validation)
NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-48203 (injection, input validation, and SSRF)
NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-48204 (improper input validation)
NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-48205 (improper input validation)
NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-53913 (improper authentication)
NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-56140 (improper input validation)
NVD References:
- https://camel.apache.org/security/CVE-2026-40047.html
- https://camel.apache.org/security/CVE-2026-43867.html
- https://camel.apache.org/security/CVE-2026-46454.html
- https://camel.apache.org/security/CVE-2026-46455.html
- https://camel.apache.org/security/CVE-2026-46456.html
- https://camel.apache.org/security/CVE-2026-48203.html
- https://camel.apache.org/security/CVE-2026-48204.html
- https://camel.apache.org/security/CVE-2026-48205.html
- https://camel.apache.org/security/CVE-2026-53913.html
- https://camel.apache.org/security/CVE-2026-56140.html
CVE-2026-33264 - Apache Airflow had a vulnerability in `BaseSerialization.deserialize()` that allowed malicious triggers to gain remote code execution, fixed in version 3.3.0 with a mitigation for restricted DAG-author trust.
Product: Apache Airflow
CVSS Score: 9.8
NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-33264
CVE-2026-9181 - ArcGIS Server is vulnerable to directory traversal which allows unauthenticated attackers to access sensitive files by sending crafted path parameters, affecting all versions up to 12.0.
Product: ArcGIS Server
CVSS Score: 9.8
NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-9181
NVD References: https://www.esri.com/arcgis-blog/products/arcgis-enterprise/administration/may-2026-arcgis-security-bulletin
CVE-2026-57572 - Crawl4AI's Docker API server prior to version 0.9.0 allowed for arbitrary command execution via request-supplied Chromium switches.
Product: Kidocode Crawl4Ai
CVSS Score: 10.0
NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-57572
CVE-2026-6556 - @fastify/express versions 4.0.6 and earlier have a vulnerability where middleware mount paths are not properly handled for non-string paths, potentially allowing bypass of path-scoped middleware for authentication, authorization, rate limiting, or auditing.
Product: Fastify\\/Express
CVSS Score: 9.1
NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-6556
CVE-2026-14198 - The vulnerability in @fastify/middie versions 9.1.0 through 9.3.2 allows attackers to bypass security measures on parameterized paths by sending crafted URLs with encoded slashes, requiring an upgrade to version 9.3.3 or alternative security measures to mitigate the risk.
Product: Fastify Fastify\/Middie
CVSS Score: 9.1
NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-14198
CVE-2026-8452, CVE-2026-8655 - Memory overflow vulnerabilities in NetScaler ADC and NetScaler Gateway
Product: Citrix NetScaler ADC and NetScaler Gateway
CVSS Score: 9.8
NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-8452
NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-8655
NVD References: https://support.citrix.com/support-home/kbsearch/article?articleNumber=CTX696604
CVE-2026-14241 - Firefox 152.0.3 is vulnerable to memory safety bugs that could have been exploited to run arbitrary code, but this issue has been resolved in Firefox 152.0.4.
Product: Mozilla Firefox 152.0.3
CVSS Score: 9.8
NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-14241
CVE-2026-58172 - Ocelot up to version 24.1.0 allows denied clients to bypass IP-based access restrictions through WebSocket upgrade requests due to a security control bypass vulnerability.
Product: Ocelot
CVSS Score: 9.1
NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-58172
CVE-2026-10134, CVE-2026-10140, CVE-2026-7663, CVE-2026-7803, CVE-2026-7871, CVE-2026-7873, CVE-2026-7874 - Multiple vulnerabilities in IBM Langflow OSS
Product: IBM Langflow OSS
CVSS Scores: 9.1 - 10.0
NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-10134
NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-10140
NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-7663
NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-7803
NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-7871
NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-7873
NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-7874
NVD References:
- https://www.ibm.com/support/pages/node/7277559
- https://www.ibm.com/support/pages/node/7278209
- https://www.ibm.com/support/pages/node/7277570
- https://www.ibm.com/support/pages/node/7278445
- https://www.ibm.com/support/pages/node/7278443
- https://www.ibm.com/support/pages/node/7278441
- https://www.ibm.com/support/pages/node/7278447
CVE-2026-11708, CVE-2026-11712 - Multiple vulnerabilities in IBM WebSphere Application Server
Product: IBM WebSphere Application Server
CVSS Score: 9.3
NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-11708
NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-11712
NVD References: https://www.ibm.com/support/pages/node/7278590
CVE-2026-56278 - Flowise before 3.1.0 uses a weak hardcoded default secret that can allow attackers to forge valid signed session cookies and impersonate users.
Product: Flowise
CVSS Score: 9.1
NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-56278
CVE-2026-7839 - UltraVNC repeater through 1.8.2.2 has a hardcoded default password in the HTTP administration server, allowing remote attackers to authenticate as administrator and take control of the repeater configuration.
Product: UltraVNC
CVSS Score: 9.1
NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-7839
CVE-2026-10539 - Control-M/Server versions 9.0.20.x to 9.0.21.200 and potentially earlier unsupported versions are vulnerable to unauthorized command execution due to insufficient input filtering.
Product: BMC Software Control-M/Server
CVSS Score: 9.0
NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-10539
CVE-2025-23350, CVE-2025-23351 - Command interface flaws in NVIDIA ConnectX and BlueField are vulnerable to command interface flaws where a local user with virtual function access can trigger a write out of bounds, potentially leading to arbitrary code execution.
Product: NVIDIA ConnectX and BlueField
CVSS Score: 9.0
NVD: https://nvd.nist.gov/vuln/detail/CVE-2025-23350
NVD: https://nvd.nist.gov/vuln/detail/CVE-2025-23351
CVE-2026-58521, CVE-2026-14363 - Mediawiki - Cargo Extension is vulnerable to SQL Injection due to improper neutralization of special elements in SQL commands, affecting versions before 1.43.9, 1.44.6, and 1.45.4.
Product: Mediawiki Cargo
CVSS Score: 9.8
NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-58521
NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-14363
CVE-2026-50195 - Containerd versions prior to 2.3.2, 2.2.5 and 2.1.9 are vulnerable to an attack where an attacker with permissions to create pods can execute arbitrary code under the victim pod's identity by exploiting a flaw in the CRI checkpoint import process.
Product: Linux Foundation Containerd
CVSS Score: 9.9
NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-50195
NVD References: https://github.com/containerd/containerd/security/advisories/GHSA-cvxm-645q-p574
CVE-2026-53492 - Containerd versions prior to 2.3.2, 2.2.5, and 2.1.9 improperly trust CDI annotations, allowing users to bypass resource allocation and inject arbitrary edits during container restoration.
Product: Linux Foundation Containerd
CVSS Score: 9.6
NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-53492
NVD References: https://github.com/containerd/containerd/security/advisories/GHSA-33vj-92qq-66hc
CVE-2026-50747 - UniFi Talk Application allows a malicious actor with network access and low privileges to exploit SQL Injection vulnerabilities for privilege escalation on the host device.
Product: Ubiquiti UniFi Talk Application
CVSS Score: 9.9
NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-50747
NVD References: https://community.ui.com/releases/Security-Advisory-Bulletin-066-066/984eceb3-49c8-4227-942d-671c289b3afc
CVE-2026-54400 - UniFi Access Application is vulnerable to Improper Access Control, allowing a malicious actor to gain high privileges on the network device.
Product: Ubiquiti UniFi Access Application
CVSS Score: 9.1
NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-54400
NVD References: https://community.ui.com/releases/Security-Advisory-Bulletin-066-066/984eceb3-49c8-4227-942d-671c289b3afc
CVE-2026-55115 - UniFi Protect Application is vulnerable to SSRF, allowing a malicious actor with network access to escalate privileges on the host device.
Product: Ubiquiti Unifi Protect Application
CVSS Score: 9.9
NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-55115
NVD References: https://community.ui.com/releases/Security-Advisory-Bulletin-066-066/984eceb3-49c8-4227-942d-671c289b3afc
CVE-2026-55116 - UniFi OS devices may allow unauthorized changes by a malicious actor with network access due to an Improper Access Control vulnerability.
Product: Ubiquiti UniFi OS
CVSS Score: 9.0
NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-55116
NVD References: https://community.ui.com/releases/Security-Advisory-Bulletin-066-066/984eceb3-49c8-4227-942d-671c289b3afc
CVE-2026-59099 - Apereo CAS 7.3.0 before 8.0.0-RC6 has a vulnerability that enables remote attackers to recover plaintext conversation state by exploiting AES-GCM initialization vector reuse.
Product: Apereo CAS
CVSS Score: 9.1
NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-59099
CVE-2026-38968 - Ntopng through 6.6 is vulnerable to Predictable Session Identifier, allowing for Session Hijacking due to weak time-seeded pseudo-randomness in HTTP session creation.
Product: ntop ntopng
CVSS Score: 9.8
NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-38968
CVE-2026-38971 - ardupilot through Plane-4.6.3 was found to contain an out-of-bounds read issue in libraries/GCS_MAVLink/GCS_serial_control.cpp in GCS_MAVLINK::handle_serial_control().
Product: ardupilot Plane-4.6.3
CVSS Score: 9.1
NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-38971
CVE-2026-5268 - Ciena products are vulnerable to an authentication bypass in the default SFTP server, enabling unauthorized access to the filesystem.
Product: Ciena SFTP server component
CVSS Score: 9.1
NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-5268
NVD References: https://www.ciena.com/product-security
CVE-2026-57571 - Crawl4AI allows for an arbitrary file write vulnerability prior to version 0.9.0, potentially leading to remote code execution.
Product: Kidocode Crawl4AI
CVSS Score: 9.6
NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-57571
NVD References: https://github.com/unclecode/crawl4ai/security/advisories/GHSA-2jq4-q6vv-4cp3
The June 30, 2026 Chrome Stable Channel Update for Desktop includes 433 security fixes, 20 of which are rated critical.
References: https://chromereleases.googleblog.com/2026/06/stable-channel-update-for-desktop_0175352312.html
CVE-2026-41106 - Microsoft 365 Copilot Elevation of Privilege Vulnerability
Product: Microsoft 365 Copilot
CVSS Score: 9.3
NO CUSTOMER ACTION REQUIRED
NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-41106
MSFT Details: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-41106
CVE-2026-45499 - Azure OpenAI Elevation of Privilege Vulnerability
Product: Microsoft Azure OpenAI
CVSS Score: 9.9
NO CUSTOMER ACTION REQUIRED
NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-45499
MSFT Details: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45499
CVE-2026-57100 - Microsoft Entra Provisioning Service Elevation of Privilege Vulnerability
Product: Microsoft Entra Provisioning Service
CVSS Score: 9.9
NO CUSTOMER ACTION REQUIRED
NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-57100
MSFT Details: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-57100
Webinar | The New Face of Fraud in Financial Services | Thursday, July 16 | Kevin Garvey, Mick Leach & Manuel Bernal | Join this session for an unscripted conversation about the state of security in financial services: the methods and sophistication of modern attacks, and what it takes to build an email security program that can move at attacker speed.
SANS AI Survey Insights | Poisoned Wells and Pure Springs: Drawing Security and Compromise from the same AI Source | Wednesday, July 15
Webinar | AI and Network Control: Visibility, Risk Prioritization, and Automation in the Age of Agentic NetOps | Monday, July 20 | Matt Bromiley & Avishai Wool
Webinar | How to Reduce Connectivity Tickets and Accelerate Application Changes | Wednesday, July 29 | Kevin Garvey & Kyle Wickert