SEC536: Adversarial AI - Penetration Testing AI Systems


Experience SANS training through course previews.
Learn MoreLet us help.
Contact usBecome a member for instant access to our free resources.
Sign UpWe're here to help.
Contact UsISC provides a free analysis and warning service to thousands of Internet users and organizations, and is actively working with Internet Service Providers to fight back against the most malicious attackers. https://isc.sans.edu/about.html
WordPress Exploitation Underway (CVE-2026-63030)
Published: 2026-07-20
Last Updated: 2026-07-20 18:41:24 UTC
by Johannes Ullrich (Version: 1)
Last week, Searchlight Cyber released details about a vulnerability they are calling "wp2shell". The vulnerability was initially announced without a CVE number. But now has been assigned CVE-2026-63030. Many WordPress plugin vulnerabilities are never assigned CVE numbers. But wp2shell is different. It is a SQL injection vulnerability in WordPress Core, not a plugin, and can lead to unauthenticated remote code execution. Shortly after being announced, the vulnerability started to be exploited.
If you are running WordPress, stop reading now. Check if you are vulnerable at https://wp2shell.com. Assume compromise if you are vulnerable.
The exploit attempts hitting our honeypots are designed to detect the vulnerability, and do not deliver a functional exploit. But one of our readers submitted a complete exploit request captured by SecurityOnion ...
Read the full entry: https://isc.sans.edu/diary/WordPress+Exploitation+Underway+CVE202663030/33168/
Scans for Hikvision Intelligent Security API
Published: 2026-07-19
Last Updated: 2026-07-19 15:00:38 UTC
by Johannes Ullrich (Version: 1)
We have been following issues with Hikvision cameras for a long, long time. Like many similar products, Hikvision cameras have a long history of vulnerabilities and are often targeted by internet-wide scans that our honeypot network detects.
This weekend, I noticed a new type of recon scans against the newer OPEN Intelligent Security API (ISAPI) provided by Hikvision cameras. This REST-based API does provide access to a wide range of features. Despite using the word "Intelligent" in its name, the API is not limited to some of the AI/facial recognition functions, but can be used to fully control the camera settings and manage the camera. The API is intended for integration with various third-party products and is well-documented by Hikvision. The ISAPI has been around since at least 2018, but I have only now noticed scans for /ISAPI/System/status, an endpoint that is an obvious choice to profile ISAPI devices. Messages can use XML or JSON. Most examples I have seen use XML.
ISAPI requests are authenticated using Basic or Digest authentication. The cameras support HTTPS, but of course, like for many similar IoT devices, it must first be configured with appropriate keys and certificates. Messages may also be encrypted with AES 128 or 256 in CBC mode. The encryption key is derived from the password, and the iv is exposed in the URL. As a result, the encryption does not provide any additional security if Basic authentication is used and the password is sent in the clear. HTTPS should provide more comprehensive protection ...
Read the full entry: https://isc.sans.edu/diary/Scans+for+Hikvision+Intelligent+Security+API/33164/
Captive Portal Detection (2026.07.21)
https://isc.sans.edu/diary/Captive+Portal+Detection/33172/
Microsoft Patch Tuesday July 2026 - The AI Apocalypse is Here (2026.07.14)
https://isc.sans.edu/diary/Microsoft+Patch+Tuesday+July+2026+The+AI+Acopolypse+is+Here/33154/
The list is assembled by pulling recent vulnerabilities from NIST NVD, Microsoft, Twitter mentions of vulnerabilities, ISC Diaries and Podcast, and the CISA list of known exploited vulnerabilities. There are also some unscored, but significant, vulnerabilities at the end. This includes vulnerabilities that have not been added to the NVD yet.
CVE-2026-63030 - WordPress Core Interpretation Conflict Vulnerability
Product: WordPress Core
CVSS Score: 9.8
** KEV since 2026-07-21 **
NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-63030
ISC Diary: https://isc.sans.edu/diary/33168
ISC Podcast: https://isc.sans.edu/podcastdetail/10016
NVD References:
- https://github.com/WordPress/wordpress-develop/security/advisories/GHSA-ff9f-jf42-662q
- https://wordpress.org/news/2026/07/wordpress-7-0-2-release/
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-63030
CVE-2026-60137 - WordPress Core SQL Injection Vulnerability
Product: WordPress Core
CVSS Score: 5.9
** KEV since 2026-07-21 **
NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-60137
NVD References:
- https://github.com/WordPress/wordpress-develop/security/advisories/GHSA-fpp7-x2x2-2mjf
- https://wordpress.org/news/2026/07/wordpress-7-0-2-release/
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-60137
CVE-2026-58644 - Microsoft SharePoint Remote Code Execution Vulnerability
Product: Microsoft SharePoint Server
CVSS Score: 9.8
** KEV since 2026-07-16 **
NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-58644
MSFT Details: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-58644
NVD References: https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-58644
CVE-2026-56164 - Microsoft SharePoint Server Elevation of Privilege Vulnerability
Product: Microsoft SharePoint Server
CVSS Score: 5.3
** KEV since 2026-07-14 **
NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-56164
MSFT Details: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-56164
NVD References: https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-56164
CVE-2026-50522 - Microsoft SharePoint Remote Code Execution Vulnerability
Product: Microsoft Sharepoint Server
CVSS Score: 9.8
NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-50522
MSFT Details: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50522
CVE-2026-55040 - Microsoft SharePoint Server Security Feature Bypass Vulnerability
Product: Microsoft SharePoint Server
CVSS Score: 9.1
NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-55040
MSFT Details: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-55040
CVE-2026-15409 - SonicWall SMA1000 Appliances Server-Side Request Forgery Vulnerability
Product: SonicWall SMA1000 series
CVSS Score: 10.0
** KEV since 2026-07-14 **
NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-15409
NVD References:
- https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2026-0008
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-15409
CVE-2026-15410 - SonicWall SMA1000 Appliances Code Injection Vulnerability
Product: SonicWall SMA1000 series
CVSS Score: 7.2
** KEV since 2026-07-14 **
NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-15410
NVD References:
- https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2026-0008
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-15410
CVE-2026-56155 - Active Directory Federation Services Elevation of Privilege Vulnerability
Product: Microsoft Windows
CVSS Score: 7.8
** KEV since 2026-07-14 **
NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-56155
MSFT Details: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-56155
NVD References: https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-56155
CVE-2021-27137 - DD-WRT Stack-Based Buffer Overflow Vulnerability
Product: DD-WRT
CVSS Score: 8.1
** KEV since 2026-07-21 **
NVD: https://nvd.nist.gov/vuln/detail/CVE-2021-27137
NVD References:
- https://securityaffairs.com/193290/uncategorized/iot-botnet-c0xmo-adds-competitor-killing-capability.html
- https://ssd-disclosure.com/ssd-advisory-dd-wrt-upnp-buffer-overflow/
- https://svn.dd-wrt.com/changeset/45724
- https://www.bleepingcomputer.com/news/security/c0xmo-botnet-spreads-via-dd-wrt-router-flaw-kills-rival-malware/
- https://www.fortinet.com/blog/threat-research/inside-cross-platform-propagation-of-new-gafgyt-variant-c0xmo
- https://ssd-disclosure.com/ssd-advisory-dd-wrt-upnp-buffer-overflow/
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2021-27137
CVE-2023-4346 - KNX Association KNX Protocol Connection Authorization Option 1 Overly Restrictive Account Lockout Mechanism Vulnerability
Product: KNX Protocol
CVSS Score: 0
** KEV since 2026-07-15 **
NVD: https://nvd.nist.gov/vuln/detail/CVE-2023-4346
NVD References: https://www.cisa.gov/news-events/ics-advisories/icsa-23-236-01
CVE-2026-48356 - Adobe Commerce is susceptible to an Unrestricted Upload of File with Dangerous Type flaw that could lead to arbitrary code execution, enabling attackers to gain elevated access or control over the victim's account or session with user interaction required for exploitation.
Product: Adobe Commerce
CVSS Score: 9.3
NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-48356
NVD References: https://helpx.adobe.com/security/products/magento/apsb26-73.html
CVE-2026-50518, CVE-2026-56159 - Windows DHCP Server Remote Code Execution Vulnerabilities
Product: Microsoft Windows DHCP Server
CVSS Score: 9.8
NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-50518
NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-56159
MSFT Details:
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50518
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-56159
CVE-2026-49798 - Windows Kernel Elevation of Privilege Vulnerability
Product: Microsoft Windows Kernel
CVSS Score: 9.3
NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-49798
MSFT Details: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-49798
CVE-2026-42990 - SQL Server ODBC driver Elevation of Privilege Vulnerability
Product: Microsoft Windows
CVSS Score: 9.8
NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-42990
MSFT Details: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-42990
CVE-2026-48561 - Microsoft Copilot Remote Code Execution Vulnerability
Product: Microsoft Copilot
CVSS Score: 9.6
NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-48561
MSFT Details: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-48561
CVE-2026-49172 - Windows FTP Service Remote Code Execution Vulnerability
Product: Microsoft Windows
CVSS Score: 9.8
NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-49172
MSFT Details: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-49172
CVE-2026-54990 - Remote Desktop Client Remote Code Execution Vulnerability
Product: Microsoft Windows
CVSS Score: 9.8
NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-54990
MSFT Details: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-54990
CVE-2026-56190 - Remote Desktop Protocol Remote Code Execution Vulnerability
Product: Microsoft Windows RDP
CVSS Score: 9.8
NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-56190
MSFT Details: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-56190
CVE-2026-55008 - Microsoft Exchange Server Spoofing Vulnerability
Product: Microsoft Exchange Server
CVSS Score: 9.6
NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-55008
MSFT Details: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-55008
CVE-2026-50380 - Windows GDI+ Remote Code Execution Vulnerability
Product: Microsoft Windows
CVSS Score: 9.6
NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-50380
MSFT Details: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50380
CVE-2026-50447 - Windows Message Queuing Service (MSMQ) Remote Code Execution Vulnerability
Product: Microsoft Windows
CVSS Score: 9.8
NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-50447
MSFT Details: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50447
CVE-2026-55010 - Minecraft Bedrock Dedicated Server Remote Code Execution Vulnerability
Product: Mojang Minecraft Bedrock Dedicated Server
CVSS Score: 9.8
NO CUSTOMER ACTION REQUIRED
NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-55010
MSFT Details: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-55010
CVE-2026-55944 - Microsoft Dynamics NAV and Microsoft Dynamics 365 Business Central (On Premises) Remote Code Execution Vulnerability
Product: Microsoft Dynamics NAV and Microsoft Dynamics 365 Business Central (On Premises)
CVSS Score: 9.8
NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-55944
MSFT Details: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-55944
CVE-2026-56188 - Windows Server Network driver Remote Code Execution Vulnerability
Product: Microsoft Windows Server Network driver
CVSS Score: 9.8
NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-56188
MSFT Details: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-56188
CVE-2026-57092 - Microsoft Windows VMSwitch Elevation of Privilege Vulnerability
Product: Microsoft Windows
CVSS Score: 9.9
NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-57092
MSFT Details: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-57092
CVE-2026-57433 - Storable versions before 3.41 for Perl have a signed integer overflow when deserializing a crafted SX_HOOK record
Product: Storable
CVSS Score: 9.8
NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-57433
CVE-2026-48284, CVE-2026-48318, CVE-2026-48319, CVE-2026-48321, CVE-2026-48324, CVE-2026-48322, CVE-2026-48325, CVE-2026-48327 - Multiple vulnerabilities in Adobe ColdFusion.
Product: Adobe ColdFusion
CVSS Score: 9.1 - 9.8
NVD References:
- https://helpx.adobe.com/security/products/coldfusion/apsb26-82.html (CVE-2026-48284: improper input validation)
- https://helpx.adobe.com/security/products/coldfusion/apsb26-82.html (CVE-2026-48318: path traversal)
- https://helpx.adobe.com/security/products/coldfusion/apsb26-82.html (CVE-2026-48319: path traversal)
- https://helpx.adobe.com/security/products/coldfusion/apsb26-82.html (CVE-2026-48321: incorrect authorization)
- https://helpx.adobe.com/security/products/coldfusion/apsb26-82.html (CVE-2026-48324: SQL injection)
- https://helpx.adobe.com/security/products/coldfusion/apsb26-82.html (CVE-2026-48322: code injection)
- https://helpx.adobe.com/security/products/coldfusion/apsb26-82.html (CVE-2026-48325: missing authentication for critical function)
- https://helpx.adobe.com/security/products/coldfusion/apsb26-82.html (CVE-2026-48327: incorrect authorization)
CVE-2026-48358, CVE-2026-47992 - Vulnerabilities in Adobe Commerce is vulnerable to an arbitrary code execution flaw due to improper encoding, allowing attackers with high privileges to exploit it without user interaction.
Product: Adobe Commerce
CVSS Scores: 7.2 - 9.1
NVD References:
- https://helpx.adobe.com/security/products/magento/apsb26-73.html (CVE-2026-48358: arbitrary code execution)
- https://helpx.adobe.com/security/products/magento/apsb26-73.html (CVE-2026-47992: SQL injection)
CVE-2026-48259, CVE-2026-48359 - Vulnerabilities in Adobe Experience Manager is vulnerable to XXE, allowing low-privileged attackers to execute arbitrary code and potentially gain elevated access without user interaction.
Product: Adobe Experience Manager
CVSS Score: 9.6
NVD References:
- https://helpx.adobe.com/security/products/experience-manager/apsb26-74.html (CVE-2026-48259: server-side request rorgery (SSRF))
- https://helpx.adobe.com/security/products/experience-manager/apsb26-74.html (CVE-2026-48359: improper restriction of XML external entity reference)
CVE-2026-48334 - Adobe Illustrator is vulnerable to an Improper Input Validation flaw which could allow an attacker to execute arbitrary code by tricking the user into opening a malicious file, potentially gaining unauthorized access.
Product: Adobe Illustrator
CVSS Score: 9.3
NVD References: https://helpx.adobe.com/security/products/illustrator/apsb26-79.html
CVE-2026-58479 - Sustainable Irrigation Platform (SIP) version 5.2.16 has a command injection vulnerability in the cli_control plugin, allowing attackers to execute operating-system commands via the plugin's HTTP endpoint.
Product: Sustainable Irrigation Platform
CVSS Score: 9.8
NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-58479
NVD References:
- https://www.vulncheck.com/advisories/sustainable-irrigation-platform-rce-via-cli-control-plugin-command-injection
- https://www.zeroscience.mk/#/advisories/ZSL-2026-5999
CVE-2026-62390, CVE-2026-62392 - Vulnerabilities in Apache Kylin.
Product: Apache Kylin
CVSS Score: 9.8
NVD References:
- https://lists.apache.org/thread/zdrj93txvdjj07f88s43d2pcg2gomvjc (CVE-2026-62390: SQL injection)
- https://lists.apache.org/thread/9hof8lxo3mzshsh5r77mskzqlkns09gn (CVE-2026-62392: OS command injection)
CVE-2026-27690 - SAP Approuter is vulnerable to HTTP Request Smuggling, allowing unauthenticated attackers to desynchronize requests, potentially exposing user responses and causing system downtime.
Product: SAP Approuter
CVSS Score: 9.1
NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-27690
CVE-2026-44747 - SAP NetWeaver Application Server ABAP is susceptible to memory corruption through logical errors, enabling an attacker to potentially access, modify, or disrupt the system, compromising confidentiality, integrity, and availability.
Product: SAP NetWeaver Application Server ABAP
CVSS Score: 9.9
NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-44747
CVE-2026-44761 - SAP Commerce Cloud has a vulnerability where publicly available sample OAuth2 client credentials can be used by an attacker to access and manipulate data.
Product: SAP Commerce Cloud
CVSS Score: 9.1
NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-44761
CVE-2026-3014 - XProtect® has a security vulnerability in Management Server API that allows users with edit permissions to execute arbitrary code.
Product: Milestone XProtect®
CVSS Score: 9.1
NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-3014
NVD References:
- https://doc.milestonesys.com/en-US/bundle/sec1504_latest/page/milestone_security_advisory_CVE-2026-3014_potential_remote_code_execution_by_admin_user_on_Management_Server.html
- https://support.milestonesys.com/article/CVE-2026-3014-potential-remote-code-execution-by-admin-user-on-Management-Server
CVE-2026-47428, CVE-2026-47429, CVE-2026-53633 - Multiple vulnerabilities in Vitest.
Product: Vitest
CVSS Scores: 9.6 - 9.8
NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-47428 (cross-site scripting)
NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-47429 (path traversal)
NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-53633 (exposed dangerous method or function / missing authorization)
NVD References:
- https://github.com/vitest-dev/vitest/security/advisories/GHSA-2h32-95rg-cppp
- https://github.com/vitest-dev/vitest/security/advisories/GHSA-5xrq-8626-4rwp
- https://github.com/vitest-dev/vitest/security/advisories/GHSA-g8mr-85jm-7xhm
CVE-2026-53486 - The decompress package for Node.js has a vulnerability that allows crafted archives to read or write files outside of the target directory prior to versions 10.2.1 and 11.1.3.
Product: Node.js
CVSS Score: 9.1
NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-53486
NVD References: https://github.com/XhmikosR/decompress/security/advisories/GHSA-mp2f-45pm-3cg9
CVE-2026-45063, CVE-2026-45069, CVE-2026-47767 - Multiple vulnerabilities in Symfony PHP framework
Product: Symfony PHP framework
CVSS Scorea: 9.1 - 9.8
NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-45063 (authentication bypass by spoofing)
NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-45069 (insufficient verification of data authenticity / improper validation of specified type of input)
NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-47767 (interpretation conflict)
NVD References:
- https://github.com/symfony/symfony/security/advisories/GHSA-ph86-p8f6-f9r2
- https://github.com/symfony/symfony/security/advisories/GHSA-29fc-p6c4-24cg
- https://github.com/symfony/symfony/security/advisories/GHSA-fqc7-9xjw-jrh3
CVE-2026-46633, CVE-2026-46634, CVE-2026-48805, CVE-2026-48806, CVE-2026-48807 - Multiple vulnerabilities in Twig template language for PHP.
Product: Twig
CVSS Scores: 9.1 - 9.8
NVD References:
- https://github.com/twigphp/Twig/security/advisories/GHSA-7p85-w9px-jpjp (CVE-2026-46633: code injection)
- https://github.com/twigphp/Twig/security/advisories/GHSA-24x9-r6q4-q93w (CVE-2026-46634: protection mechanism failure)
- https://github.com/twigphp/Twig/security/advisories/GHSA-p42q-9prx-q5wq (CVE-2026-48805: protection mechanism failure)
- https://github.com/twigphp/Twig/security/advisories/GHSA-5v5v-ww74-355v (CVE-2026-48806: protection mechanism failure / incorrect authorization)
- https://github.com/twigphp/Twig/security/advisories/GHSA-8x9c-rmqh-456c (CVE-2026-48807: protection mechanism failure / incorrect authorization)
CVE-2025-65720 - Open Source GPT Researcher v3.3.7 allows attackers to execute arbitrary commands through user interactions with a malicious HTML page.
Product: Open Source GPT Researcher v3.3.7
CVSS Score: 9.8
NVD: https://nvd.nist.gov/vuln/detail/CVE-2025-65720
NVD References: https://www.ox.security/blog/mcp-supply-chain-advisory-rce-vulnerabilities-across-the-ai-ecosystem/
CVE-2026-30623 - LiteLLM 1.18.10 allows remote code execution via its insecure MCP server creation functionality.
Product: LiteLLM
CVSS Score: 9.8
NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-30623
NVD References: https://www.ox.security/blog/mcp-supply-chain-advisory-rce-vulnerabilities-across-the-ai-ecosystem/
CVE-2026-14890 - SGLang's expert-parallel backup subsystem vulnerability allows unauthenticated remote code execution by exploiting a lack of authentication measures on its ZeroMQ PULL socket.
Product: SGLang
CVSS Score: 9.1
NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-14890
NVD References: https://www.kb.cert.org/vuls/id/326070
CVE-2026-44632, CVE-2026-46562, CVE-2026-46621 - Multiple vulnerabilities in Yamcs mission control framework.
Product: Yamcs mission control framework
CVSS Scores: 9.1 - 9.8
NVD References:
- https://github.com/yamcs/yamcs/security/advisories/GHSA-524g-x36v-9wm6 (CVE-2026-44632: server-side code injection)
- https://github.com/yamcs/yamcs/security/advisories/GHSA-vmwp-vh32-rj75 (CVE-2026-46562: remote code execution)
- https://github.com/yamcs/yamcs/security/advisories/GHSA-2g95-6x5q-xjwj (CVE-2026-46621: authenticated remote code execution)
CVE-2026-53412 - Zoom Desktop Client for Windows, Zoom VDI Client for Windows, and Zoom Meeting SDK for Windows are vulnerable to improper input validation, posing a risk of unauthenticated users potentially conducting an account takeover through network access.
Product: Zoom
CVSS Score: 9.8
NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-53412
NVD References: https://www.zoom.com/en/trust/security-bulletin/zsb-26014
CVE-2026-15091 - IBM Engineering AI Hub versions 1.0.0, 1.1.0, and 1.2.0 are vulnerable to arbitrary script execution by remote attackers.
Product: IBM Engineering AI Hub
CVSS Score: 9.3
NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-15091
NVD References: https://www.ibm.com/support/pages/node/7279964
CVE-2026-36669 - Feng Office 3.11.13.11 is susceptible to an unauthenticated arbitrary file upload vulnerability allowing remote attackers to upload malicious files to the /tmp/ directory.
Product: Feng Office
CVSS Score: 9.8
NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-36669
NVD References: https://github.com/firstlax6t/CVE-2026-36669-FengOffice
CVE-2026-52199 - Generic OEM UZ801_v2.1 4G LTE Router V3.4.3 is vulnerable to remote code execution through the sbin/adbd component.
Product: Generic OEM UZ801_v2.1 4G LTE Router V3.4.3
CVSS Score: 9.1
NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-52199
NVD References: https://github.com/lamaper/CVE-2026-52199
CVE-2026-47865 - VMware Avi Load Balancer is vulnerable to authentication bypass, allowing malicious users to access the Avi Control plane without proper authentication in versions 31.1.1 through 31.2.2, 30.1.1 through 30.2.6, and 22.1.1 through 22.1.7.
Product: VMware Avi Load Balancer
CVSS Score: 9.8
NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-47865
NVD References: https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/37926
CVE-2026-57898 - Eclipse BaSyx Java Server SDK versions 2.0.0-milestone-05 to 2.0.0-milestone-12 are vulnerable to an unauthenticated arbitrary file write through the AAS thumbnail API, allowing remote attackers to potentially execute code on the server.
Product: Eclipse BaSyx Java Server SDK
CVSS Score: 9.0
NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-57898
NVD References: https://gitlab.eclipse.org/security/cve-assignment/-/work_items/159
CVE-2026-59083, CVE-2026-59084 - Vulnerabilities in Apache Tomcat
Product: Apache Tomcat
CVSS Score: 9.1
NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-59083 (improper handling of URL encoding)
NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-59084 (insufficient technical documentation)
NVD References:
- https://lists.apache.org/thread/3g63zos2gkjo5vgnrk8kxmosv47w6wbq
- https://lists.apache.org/thread/7w9746ootcxo0gvx26xjpw80l31f1qw7
CVE-2026-58319 - Apache Doris FE HTTP REST administrative APIs were accessible without proper authentication, allowing unauthenticated attackers to potentially disrupt cluster integrity and availability.
Product: Apache Doris
CVSS Score: 9.1
NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-58319
NVD References: https://lists.apache.org/thread/cob5mxkyr1k81o8v91hox2hld6zh25b4
CVE-2026-62422 - JetBrains YouTrack before 2026.1.13757 allowed authentication bypass through direct database access, leading to potential administrative access.
Product: JetBrains YouTrack
CVSS Score: 10.0
NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-62422
NVD References: https://www.jetbrains.com/privacy-security/issues-fixed/
CVE-2026-15265 - Tenable Agent 11.2.0 and 11.1.3 and lower are vulnerable to path traversal, allowing a privileged attacker to write files outside the plugin directory, potentially enabling remote code execution.
Product: Tenable Agent
CVSS Score: 9.1
NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-15265
NVD References: https://www.tenable.com/security/tns-2026-18
CVE-2026-5269, CVE-2026-5270 - Vulnerabilities in Ciena's Navigator Network Control Suite (NCS) and Manage Control Plan (MCP)
Product: Ciena Navigator Network Control Suite (NCS)
VSS Score: 9.8
NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-5269 (default passwords)
NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-5270 (authentication bypass)
NVD References: https://www.ciena.com/product-security
CVE-2026-56699 - Wazuh Manager before 5.0.0-beta3 allows enrolled agents to inject arbitrary NDJSON operations, leading to document deletion, alert tampering, and SIEM state manipulation.
Product: Wazuh Manager
CVSS Score: 10.0
NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-56699
NVD References: https://github.com/wazuh/wazuh/security/advisories/GHSA-ff9g-85jq-r3g3
CVE-2026-50148 - Metabase allows remote code execution due to a flaw in the Snowflake JDBC driver which can be exploited by a user with permission to add or edit a database connection, but this issue is fixed in later versions.
Product: Metabase
CVSS Score: 10.0
NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-50148
NVD References: https://github.com/metabase/metabase/security/advisories/GHSA-r6x2-rchx-q9g9
CVE-2026-53512 - Better Auth versions prior to 1.6.11 allow attackers with a valid refresh token to mint access tokens without verifying the client_secret, fixed in version 1.6.11.
Product: Better Auth
CVSS Score: 9.1
NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-53512
NVD References: https://github.com/better-auth/better-auth/security/advisories/GHSA-pw9m-5jxm-xr6h
CVE-2026-53513 - Better Auth prior to 1.6.11 allows non-blind server-side request forgery and possible account linking via the @better-auth/sso plugin's POST /sso/register and POST /sso/update-provider endpoints.
Product: Better Auth
CVSS Score: 9.6
NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-53513
NVD References: https://github.com/better-auth/better-auth/security/advisories/GHSA-5rr4-8452-hf4v
CVE-2026-62948 - OpenWrt prior to version 25.12.5 is vulnerable to newline injection in its odhcpd DHCPv6 client FQDN option handling, allowing for forged lease lines to be displayed in the LuCI admin page.
Product: OpenWrt
CVSS Score: 9.6
NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-62948
NVD References: https://github.com/openwrt/openwrt/security/advisories/GHSA-hhmc-92hw-535f
CVE-2026-49445 - Cilium's L7 functionality prior to versions 1.17.14, 1.18.8, and 1.19.2 allows a local attacker to access Envoy admin endpoints and TLS secrets, potentially disrupting cluster traffic or terminating Envoy.
Product: Cilium
CVSS Score: 9.2
NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-49445
NVD References: https://github.com/cilium/cilium/security/advisories/GHSA-3fcv-jvfp-m4q9
CVE-2026-54052 - n8n-MCP prior to version 2.56.1 allows authenticated tenants to read and delete other tenants' workflow version snapshots and backups.
Product: n8n-MCP
CVSS Score: 9.9
NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-54052
NVD References: https://github.com/czlonkowski/n8n-mcp/security/advisories/GHSA-j6r7-6fhx-77wx
CVE-2026-22752 - Spring Authorization Server is vulnerable to authentication bypass due to a primary weakness in Spring Security.
Product: Spring Authorization Server
CVSS Score: 9.6
NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-22752
NVD References: https://spring.io/security/cve-2026-22752
CVE-2026-11386 - Canonical ubuntu-pro-client is vulnerable to input validation and injection, allowing for arbitrary code execution with root privileges on affected systems.
Product: Canonical ubuntu-pro-client
CVSS Score: 9.0
NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-11386
NVD References: https://ubuntu.com/security/CVE-2026-11386
CVE-2026-45568 - Zrok software's Python SDK ProxyShare Flask proxy route allowed for server-side responses from attacker-chosen URLs in versions prior to 2.0.3.
Product: Zrok
CVSS Score: 9.1
NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-45568
NVD References: https://github.com/openziti/zrok/security/advisories/GHSA-jh67-hwqw-m5r7
CVE-2026-57073 - HTML::Bare through version 0.04 for Perl has an unbounded character lookahead vulnerability that can lead to an out-of-bounds read.
Product: HTML::Bare Perl
CVSS Score: 9.1
NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-57073
CVE-2026-57074 - XML::Bare versions through 0.53 for Perl have an unbounded character lookahead, allowing for out-of-bounds reads triggered by truncated strings.
Product: XML::Bare Perl
CVSS Score: 9.1
NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-57074
CVE-2026-63087 - Grafana OnCall through 1.16.11 is vulnerable to unauthenticated access, allowing remote attackers to exploit hardcoded default values to obtain a valid PluginAuthToken and perform various malicious actions.
Product: Grafana OnCall
CVSS Score: 9.8
NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-63087
CVE-2026-63089 - WireGuard Easy through 15.3.0 contains a cryptographically weak one-time link token generation vulnerability.
Product: WireGuard Easy
CVSS Score: 9.3
NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-63089
NVD References: https://www.vulncheck.com/advisories/wireguard-easy-weak-token-generation-information-disclosure-via-otl-route
CVE-2026-44180 - Jupyter Enterprise Gateway allows for unauthorized remote kernel launches as root, exposing Kubernetes clusters to potential container escapes and compromise.
Product: Jupyter Enterprise Gateway
CVSS Score: 9.8
NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-44180
NVD References: https://github.com/jupyter-server/enterprise_gateway/security/advisories/GHSA-chq7-94j8-cj28
CVE-2026-57075 - YAML::Syck versions before 1.47 for Perl have a vulnerability that allows an out-of-bounds read via a signed-char lookup-table index in syck_base64dec.
Product: Perl YAML::Syck
CVSS Score: 9.1
NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-57075
NVD References: http://www.openwall.com/lists/oss-security/2026/07/17/2
CVE-2026-51080 - libpvestorage-perl v9.1.1 and libpve-storage-perl v8.3.7 were discovered to contain an XML External Entity (XXE) vulnerability.
Product: libpvestorage-perl
CVSS Score: 9.8
NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-51080
NVD References: https://forum.proxmox.com/threads/proxmox-virtual-environment-security-advisories.149331/post-849970
CVE-2026-8476, CVE-2026-8481, CVE-2026-8505, CVE-2026-8635, CVE-2026-8859, CVE-2026-9103, CVE-2026-9135, CVE-2026-9198, CVE-2026-9202, CVE-2026-13446 - Multiple vulnerabilities in IBM Langflow OSS 1.0.0 through 1.10.0.
Product: IBM Langflow
CVSS Scores: 9.8 - 9.9
NVD References:
- https://www.ibm.com/support/pages/node/7278922 (remote code execution)
- https://www.ibm.com/support/pages/node/7278923 (remote code execution)
- https://www.ibm.com/support/pages/node/7278921 (missing authentication for critical function)
- https://www.ibm.com/support/pages/node/7278925 (arbitrary code execution)
- https://www.ibm.com/support/pages/node/7278924 (path traversal)
- https://www.ibm.com/support/pages/node/7278926 (missing authentication for critical function)
- https://www.ibm.com/support/pages/node/7278920 (code injection)
- https://www.ibm.com/support/pages/node/7278927 (unauthenticated remote code execution)
- https://www.ibm.com/support/pages/node/7278929 (missing authentication for critical function)
- https://www.ibm.com/support/pages/node/7279991 (hard-coded credentials)
CVE-2025-51677 - openRISC OR1200 has an output mismatch vulnerability between its RTL and netlist, potentially causing unexpected behavior.
Product: openRISC OR1200
CVSS Score: 9.1
NVD: https://nvd.nist.gov/vuln/detail/CVE-2025-51677
NVD References: https://www.arxiv.org/abs/2504.18812
CVE-2026-48062 - CodeIgniter version prior to 4.7.3 allows for arbitrary code execution due to a vulnerability in the ext_in upload validation rule.
Product: CodeIgniter PHP full-stack web framework
CVSS Score: 9.8
NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-48062
NVD References: https://github.com/codeigniter4/CodeIgniter4/security/advisories/GHSA-2gr4-ppc7-7mhx
CVE-2026-52348 - cool-admin-java 8.0.0 has a SQL injection vulnerability in the order() method of CrudOption.java.
Product: cool-admin-java
CVSS Score: 9.8
NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-52348
NVD References: https://github.com/cool-team-official/cool-admin-java/issues/19
CVE-2026-55518 - Avo allows authenticated low-privileged users to bypass attach controls and perform unauthorized association mutations in versions prior to 3.32.1 and 4.0.0.beta.51, leading to privilege escalation and cross-tenant data exposure.
Product: Avo
CVSS Score: 9.6
NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-55518
NVD References: https://github.com/avo-hq/avo/security/advisories/GHSA-8fq9-273g-6mrg
CVE-2026-16117 - @fastify/http-proxy versions up to and including 11.5.0 have a vulnerability where the request prefix is not properly rewritten, allowing an attacker to access hidden upstream paths.
Product: fastify @fastify/http-proxy
CVSS Score: 10.0
NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-16117
NVD References:
- https://cna.openjsf.org/security-advisories.html
- https://github.com/fastify/fastify-http-proxy/security/advisories/GHSA-mx7v-qhg9-2mvv
On July 19th and 20th, the Linux kernel project released patches for 432 different vulnerabilities. Many, if not all, of these vulnerabilities were discovered and fixed using AI tools. @Risk will not enumerate these vulnerabilities individually. Linux distributions will include these patches in future kernel updates. The Linux kernel team does not prioritize patches, and takes a quite liberal approach as to what it considers a vulnerability. For more details regarding the Linux kernel’s policy on assigning CVEs see: http://www.kroah.com/log/blog/2026/02/16/linux-cve-assignment-process/
The AI Security Starter Pack - Securing AI apps, Models, and Agents Unlock 7 of the most widely used AI security resources in one place. Apply real-world checklists, templates, and best practices designed to secure AI adoption. Each asset provides practical, implementation-ready resources to secure AI adoption, models, and agents across your environments.
Webinar | Government Forum | Watch now to explore expert-led sessions on AI, OT security, Zero Trust, and cyber resilience.
Webinar | SANS 2026 Cloud Security Exchange | Monday, August 17 | The agenda is now live. Explore expert-led sessions led by AWS, Google & Microsoft. Register to attend live or watch on demand.
Webinar | How to Reduce Connectivity Tickets and Accelerate Application Changes | Wednesday, July 29 | Kevin Garvey & Kyle Wickert