SEC536: Adversarial AI - Penetration Testing AI Systems


Experience SANS training through course previews.
Learn MoreLet us help.
Contact usBecome a member for instant access to our free resources.
Sign UpWe're here to help.
Contact UsISC provides a free analysis and warning service to thousands of Internet users and organizations, and is actively working with Internet Service Providers to fight back against the most malicious attackers. https://isc.sans.edu/about.html
Atomic MacOS (AMOS) stealer infection
Published: 2026-08-02
Last Updated: 2026-08-02 04:05:08 UTC
by Brad Duncan (Version: 1)
Introduction
This diary provides indicators from an Atomic MacOS (AMOS) stealer infection that I generated in my lab on July 31st, 2026. This was distributed through a web page from getmacouscloud[.]com with instructions to paste text into a macOS Terminal window, supposedly for "macOS toolkit," but instead the text is a command to retrieve and install AMOS stealer malware.
Of note, I ran the text in the Terminal window twice, because I wanted to make sure I retrieved copies of files in the host's /tmp directory before entering the user account password. This is why the initial infection traffic is repeated, and also likely why there are two different directories with the AMOS stealer malware persistent on my infected lab host.
Images from the Infection ...
Read the full entry: https://isc.sans.edu/diary/Atomic+MacOS+AMOS+stealer+infection/33208/
Phishing Campaigns Targeting AI Solutions Providers
Published: 2026-08-01
Last Updated: 2026-08-01 07:22:32 UTC
by Xavier Mertens (Version: 1)
Most phishing campaigns rely on the fact that the victim is afraid to loose "something": money, access to information, ... Many brands have been impersonated by campaigns but I spotted some phishing emails that focus on AI services like ChatGPT.
Yesterday, I found this email that was properly designed but also sent with a very good timing: the end of the month when your classic billing process is restarted ...
Read the full entry: https://isc.sans.edu/diary/Phishing+Campaigns+Targeting+AI+Solutions+Providers/33206/
Botnet Hunting for Vulnerabilities in Diagnostic Tools
Published: 2026-08-04
Last Updated: 2026-08-04 12:46:19 UTC
by Johannes Ullrich (Version: 1)
This morning, I noticed specific sources "hunting" for vulnerabilities in URLs that I haven't noticed before. All of these URLs appear to be associated with diagnostic tools ...
The naming of these URLs points to diagnostic tools. I was unable to find any specific vulnerabilities associated with many of the URLs, but the table above reflects those I found. But diagnostic tools often suffer from file inclusion and code execution vulnerabilities.
These tools will often call operating system commands directly, without properly separating user-provided arguments. Here is a sample vulnerability in a ping utility ...
Read the full entry: https://isc.sans.edu/diary/Botnet+Hunting+for+Vulnerabilities+in+Diagnostic+Tools/33214/
zipdump.py: Metadata Encoding (2026.07.31)
https://isc.sans.edu/diary/zipdumppy+Metadata+Encoding/33202/
Reconnaissance First: An SSH Bot That Sizes Up Your Hardware Before Deploying a Miner [Guest Diary] (2026.07.30)
The list is assembled by pulling recent vulnerabilities from NIST NVD, Microsoft, Twitter mentions of vulnerabilities, ISC Diaries and Podcast, and the CISA list of known exploited vulnerabilities. There are also some unscored, but significant, vulnerabilities at the end. This includes vulnerabilities that have not been added to the NVD yet.
CVE-2024-12856 - The Four-Faith router models F3x24 and F3x36 are vulnerable to OS command injection via apply.cgi due to default credentials in firmware version 2.0.
Product: Four-Faith router models
CVSS Score: 0
NVD: https://nvd.nist.gov/vuln/detail/CVE-2024-12856
ISC Diary: https://isc.sans.edu/diary/33214
CVE-2026-20316 - Cisco Secure Firewall Management Center Use of Hard-coded Password Vulnerability
Product: Cisco Secure Firewall Management Center
CVSS Score: 5.3
** KEV since 2026-07-29 **
NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-20316
ISC Podcast: https://isc.sans.edu/podcastdetail/10032
NVD References:
- https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-fmc-static-cred-BET3Cjh
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-20316
CVE-2026-18577 - An incomplete patch for CVE-2026-18556 allows for authentication bypass and account takeover in N-central Versions through 2026.3.1
Product: N-Able N-Central
CVSS Score: 8.1
** KEV since 2026-08-03 **
NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-18577
NVD References:
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-18577
- https://www.n-able.com/blog/n-central-security-update-august-2-2026
CVE-2026-18556 - N-able N-central is vulnerable to authentication bypass via an alternate path or channel, allowing unauthorized access without proper authentication through version 2026.1.
Product: N-Able N-Central
CVSS Score: 7.4
** KEV since 2026-08-04 **
NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-18556
NVD References:
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-18556
- https://www.n-able.com/blog/n-central-security-update-august-2-2026
CVE-2026-16812 - Arista VeloCloud Orchestrator On-Prem OS Command Injection Vulnerability
Product: Arista Velocloud_Orchestrator 7.0.0
CVSS Score: 0
** KEV since 2026-07-27 **
NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-16812
CVE-2026-42533 - NGINX Map directive and Regex matching vulnerability
Product: NGINX Plus and NGINX Open Source
CVSS Score: 8.1
NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-42533
ISC Podcast: https://isc.sans.edu/podcastdetail/10028
MSFT Details: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-42533
CVE-2026-42530 - NGINX Open Source is vulnerable to a remote unauthenticated attacker exploiting the ngx_http_v3_module to cause a Use-after-Free in the worker process leading to a restart when configured to use the HTTP/3 QUIC module.
Product: NGINX Open Source
CVSS Score: 0
NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-42530
ISC Podcast: https://isc.sans.edu/podcastdetail/10028
CVE-2026-66803 - Azure Cosmos DB Remote Code Execution Vulnerability
Product: Microsoft Azure Cosmos Db
CVSS Score: 10.0
NO CUSTOMER ACTION REQUIRED
NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-66803
MSFT Details: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-66803
CVE-2026-53384 - serial: 8250_dw: unregister 8250 port if clk_notifier_register() fails
Product: Linux kernel
CVSS Score: 9.8
NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-53384
CVE-2026-18601, CVE-2026-18602, CVE-2026-18612 through CVE-2026-18616, CVE-2026-18684, CVE-2026-18685, CVE-2026-18686 - Multiple vulnerabilities in GL.iNet GL-MT3000
Product: GL.iNet GL-MT3000
CVSS Score: 9.8
NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-18601
NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-18602
NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-18612
NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-18613
NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-18614
NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-18615
NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-18616
NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-18684
NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-18685
NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-18686
CVE-2026-66713 - Apache Axis2/Java through 2.0.0 on Apache Tomcat is vulnerable to remote code execution through deserialization of untrusted data in the Tribes-based clustering component when enabled, requiring users to upgrade to version 2.0.1 to fix this issue.
Product: Apache Axis2/Java
CVSS Score: 9.8
References: https://lists.apache.org/thread/fgggbv3sjjqw7p6q0j88gspt9b2rb728
CVE-2026-33267, CVE-2026-41920, CVE-2026-57834, CVE-2026-58150, CVE-2026-58155, CVE-2026-58162 - Multiple vulnerabilities in Apache Traffic Server.
Product: Apache Traffic Server
CVSS Scores: 9.3 - 10.0
Reference: https://lists.apache.org/thread/5prl9glcm9g2swnq9hqxvnokylm1gr6d
CVE-2026-52680 - Apache Kyuubi allows a remote attacker to perform path traversal exploits through client-supplied filenames in REST batch uploads before version 1.12.0.
Product: Apache Kyuubi
CVSS Score: 9.8
NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-52680
Reference: https://lists.apache.org/thread/b0qx2v8k5v4rrqsh53pb146t7so0lmrk
CVE-2026-59243 - The FAB auth manager's Azure AD OAuth login had a vulnerability where an attacker could bypass authentication and log in as an arbitrary user by presenting a forged or unsigned ID token.
Product: Apache Airflow FAB provider
CVSS Score: 9.8
Reference: https://lists.apache.org/thread/x4784l7z00tl3gw4tv2dmvoon77rxgpl
CVE-2026-28812 - Apache JSPWiki UserManager lack of checks allows impersonation, enabling privilege escalation in versions up to 2.12.3.
Product: Apache JSPWiki
CVSS Score: 9.8
Reference: https://lists.apache.org/thread/n3m666d6t6871dldvz3ct49ooqkbgw2p
CVE-2026-14446, CVE-2026-14512, CVE-2026-14529 - Vulnerabilities in IBM WebSphere Application Server 9.0 and 8.5.
Product: IBM WebSphere Application Server
CVSS Scores: 9.4 - 9.8
References:
- https://www.ibm.com/support/pages/node/7281649
- https://www.ibm.com/support/pages/node/7281631
- https://www.ibm.com/support/pages/node/7281721
CVE-2026-14958, CVE-2026-14959 - Multiple vulnerabilities in IBM Aspera Faspex
Product: IBM Aspera Faspex 5
CVSS Score: 9.1
Reference: https://www.ibm.com/support/pages/node/7280530
CVE-2026-14973 - IBM Aspera Desktop App versions 1.0.5 through 1.0.19 may allow files to be written outside of the user's chosen download location.
Product: IBM Aspera Desktop App
CVSS Score: 9.3
Reference: https://www.ibm.com/support/pages/node/7280939
CVE-2026-15435 - IBM App Connect Enterprise versions 13.0.1.0 through 13.0.7.2, and 12.0.1.0 through 12.0.12.27 are vulnerable to directory traversal, allowing a remote attacker to write arbitrary files on the system through specially crafted URL requests.
Product: IBM App Connect Enterprise
CVSS Score: 9.8
Reference: https://www.ibm.com/support/pages/node/7281896
CVE-2026-12943 - IBM HMC V10.3.1050.0 through 10.3.1064.0 and IBM HMC V11.1.1110.0 through 11.1.1112.0 Management systems in IBM Power environments are vulnerable to unauthorized users executing arbitrary commands with elevated privileges.
Product: IBM HMC
CVSS Score: 9.8
Reference: https://www.ibm.com/support/pages/node/7278667
CVE-2026-11707 - IBM Tivoli System Automation Application Manager 4.1 and IBM WebSphere Application Server is vulnerable to cross-site scripting on the administrative console login page.
Product: IBM Tivoli System Automation Application Manager
CVSS Score: 9.3
Reference: https://www.ibm.com/support/pages/node/7281073
CVE-2026-12940, CVE-2026-12946, CVE-2026-13435 - Vulnerabilities in IBM Langflow OSS versions 1.0.0 through 1.10.1.
Product: IBM Langflow OSS
CVSS Score: 9.8 - 9.9
References:
- https://www.ibm.com/support/pages/node/7279995
- https://www.ibm.com/support/pages/node/7278928
- https://www.ibm.com/support/pages/node/7279987
CVE-2026-12118 - IBM webMethods Integration (on prem) 10.15, 10.11 is vulnerable to unauthenticated remote code execution via deserialization of untrusted data.
Product: IBM webMethods Integration On Prem
CVSS Score: 9.8
Reference: https://www.ibm.com/support/pages/node/7278857
CVE-2026-48317, CVE-2026-48323, CVE-2026-48326, CVE-2026-48330, CVE-2026-48331, CVE-2026-48333, CVE-2026-48449 - Multiple vulnerabilities in Adobe Campaign Classic (ACC)
Product: Adobe Campaign Classic
CVSS Scores: 9.6 - 10.0
References:
- https://helpx.adobe.com/security/products/campaign/apsb26-120.html
- https://helpx.adobe.com/security/products/campaign/apsb26-114.html
CVE-2026-59309, CVE-2026-59310 - Vulnerabilities in VMware vCenter is vulnerable to an authentication bypass in its VMware Directory Service, potentially allowing unauthorized access by a malicious actor with network access.
Product: VMware vCenter
CVSS Score: 9.8
Reference: https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/38017
CVE-2026-47876 - VMware ESX is vulnerable to an out-of-bounds write flaw in the VMXNET3 virtual network adapter, allowing local administrators to run code on the host.
Product: VMware ESX
CVSS Score: 9.3
Reference: https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/38017
CVE-2026-28323 - SolarWinds Web Help Desk has a SAML authentication bypass vulnerability when using SAML 2.0 authentication.
Product: SolarWinds Web Help Desk
CVSS Score: 9.8
Reference: https://www.solarwinds.com/trust-center/security-advisories/CVE-2026-28323
CVE-2026-16498 - The terraform-mcp-server is vulnerable to cross-tenant credential reuse, allowing one user's token to be used by others, fixed in version 1.1.0.
Product: terraform-mcp-server
CVSS Score: 10.0
Reference: https://discuss.hashicorp.com/t/hcsec-2026-23-multiple-vulnerabilities-impacting-hashicorp-terraform-mcp-server/77606
CVE-2026-44090, CVE-2026-44091, CVE-2026-44092 - Multiple vulnerabilities in the firmware of CHARX SEC3xxx charging controllers: MQTT broker vulnerability allows unauthenticated remote attackers to access the device, potentially leading to full compromise; MQTT Broker allows unauthenticated remote attackers to create new configuration entries through posting a malicious ID, posing potential integrity and availability risks; ModbusServer is vulnerable to remote attackers injecting malicious input from MQTT, potentially causing integrity and availability issues.
Product: CHARX SEC3xxx charging controllers firmware
CVSS Scores: 9.1 - 9.8
NVD Reference: https://www.certvde.com/en/advisories/VDE-2026-008/
CVE-2026-15969 - SGLang is vulnerable to unauthenticated remote code execution via crafted base64-encoded pickle payloads.
Product: SGLang
CVSS Score: 9.8
NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-15969
NVD Reference: https://thoughts.apoorvdayal.com/posts/sglang-disclosures/
CVE-2026-18245 - Amazon @aws-amplify/codegen-ui-react before 2.20.6 may allow remote authenticated users to execute arbitrary code via crafted Studio component or theme schema values, necessitating an upgrade to version 2.20.6 for remediation.
Product: Amazon @aws-amplify/codegen-ui-react
CVSS Score: 9.0
Reference: https://github.com/aws-amplify/amplify-codegen-ui/security/advisories/GHSA-74xx-rjgf-m69j
CVE-2026-68502 - LazyOwn RedTeam/APT Framework allows unauthenticated remote code execution in the C2 process prior to version 0.2.154.
Product: LazyOwn RedTeam/APT Framework
CVSS Score: 9.8
Reference: https://github.com/grisuno/LazyOwn/security/advisories/GHSA-fr84-8cfg-59w4
CVE-2026-68770 - Sentence-transformers contains a security control bypass vulnerability, allowing attackers to achieve arbitrary code execution by exploiting a logic flaw in the import_module_class helper within sentence_transformers/util/misc.py.
Product: Sentence-transformers
CVSS Score: 9.8
Reference: https://www.vulncheck.com/advisories/sentence-transformers-arbitrary-code-execution-on-local-model-load-despite-trust-remote-code-false
CVE-2026-68771 - ComfyUI v0.23.0 has an unsafe deserialization vulnerability that enables unauthenticated remote attackers to execute arbitrary Python code by uploading a crafted pickle file to the LoadTrainingDataset node.
Product: ComfyUI
CVSS Score: 9.8
Reference: https://www.vulncheck.com/advisories/comfyui-unauthenticated-rce-via-loadtrainingdataset-pickle-deserialization
CVE-2026-67340, CVE-2026-67341, CVE-2026-67341 - Multiple vulnerabilities in ArcadeDB before version 26.7.2
Product: ArcadeDB
CVSS Score: 9.8
References:
- https://github.com/ArcadeData/arcadedb/security/advisories/GHSA-x9f9-r4m8-9xc2
- https://github.com/ArcadeData/arcadedb/security/advisories/GHSA-vwjc-v7x7-cm6g
- https://github.com/ArcadeData/arcadedb/security/advisories/GHSA-x8mg-6r4p-87pf
- https://www.vulncheck.com/advisories/arcadedb-before-remote-code-execution-via-trigger-scripts
- https://www.vulncheck.com/advisories/arcadedb-before-authorization-bypass-via-sql-define-function
- https://www.vulncheck.com/advisories/arcadedb-before-authorization-bypass-via-database-handlers
CVE-2026-18588, CVE-2026-18589 - Stack-based buffer overflow vulnerabilities in Wavlink WL-NU516U1
Product: Wavlink WL-NU516U1
CVSS Score: 9.8
NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-18588
NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-18589
CVE-2026-39932 - OpenEMR through 8.2.0 has a remote code execution vulnerability in the document category tree component (library/classes/Tree.class.php) that allows authenticated administrators to inject PHP payloads into the categories database table and execute arbitrary operating system commands.
Product: OpenEMR
CVSS Score: 9.1
Reference: https://www.vulncheck.com/advisories/openemr-remote-code-execution-via-categorytree-eval-injection
CVE-2026-41452 - Krayin CRM 2.2.4 is vulnerable to a missing authentication flaw in the installer middleware, allowing unauthenticated attackers to overwrite the primary administrator account and gain full administrative access to CRM data.
Product: Krayin CRM 2.2.4
CVSS Score: 9.8
Reference: https://jivasecurity.com/writeups/krayin-installer-bypass-account-takeover-cve-2026-41452
CVE-2026-11756 - Station Launcher App in 3DEXPERIENCE platform is vulnerable to untrusted data deserialization, allowing for unauthenticated remote code execution.
Product: 3D EXPERIENCE Station Launcher App
CVSS Score: 10.0
NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-11756
CVE-2026-11841 - AppEngine Fileaccess allows unauthenticated read and write access to sensitive filesystem areas, posing a critical security risk.
Product: AppEngine Fileaccess
CVSS Score: 9.4
NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-11841
CVE-2026-60112, CVE-2026-60113 - Missing authentication vulnerabilities in AMMOS Instrument Toolkit (AIT) GUI and Deep Space Network (DSN) Interface
Product: AMMOS Instrument Toolkit (AIT) GUI and Deep Space Network (DSN) Interface
CVSS Score: 9.8
Reference:
- https://www.vulncheck.com/advisories/ait-gui-missing-authentication-via-sessions-create
- https://github.com/NASA-AMMOS/AIT-DSN/security/advisories/GHSA-gj83-67wr-82mv
CVE-2026-54680 - Logging operator prior to version 6.6.0 allows for remote code execution in the Fluentd aggregator via unescaped CRD values.
Product: Elastic Cloud on Kubernetes (ECK)
CVSS Score: 9.9
Reference: https://github.com/kube-logging/logging-operator/security/advisories/GHSA-mjqf-28ph-426h
CVE-2026-58046 - Plesk XML-RPC API vulnerability allows SQL injection by low-privileged users, leading to full panel compromise.
Product: Plesk XML-RPC API
CVSS Score: 9.9
Reference: https://support.plesk.com/hc/en-us/articles/42139500580119-Vulnerability-CVE-2026-58046-Blind-SQL-injection-in-Plesk-s-XML-RPC-API
CVE-2026-15971, CVE-2026-15976 - Vulnerabilities in SGLang.
Product: SGLang
CVSS Score: 9.8
NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-15971
NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-15976
CVE-2026-66418, CVE-2026-66421 - Stored cross-site scripting vulnerabilities in OpenClaw Dashboard
Product: OpenClaw Dashboard v3.0.0
CVSS Score: 9.3
Reference:
- https://www.vulncheck.com/advisories/openclaw-dashboard-stored-xss-via-failed-login-username-field
- https://www.vulncheck.com/advisories/openclaw-dashboard-stored-xss-via-lastmessage-session-field
CVE-2026-68503 - LazyOwn RedTeam/APT Framework prior to version 0.2.154 allows network-reachable attackers to authenticate to the C2 dashboard with operator-level access using default credentials.
Product: LazyOwn RedTeam/APT Framework
CVSS Score: 9.8
Reference: https://github.com/grisuno/LazyOwn/security/advisories/GHSA-38jf-j9x7-jf6f
CVE-2026-63221, CVE-2026-63223 - Vulnerabilities in CodeIgniter
Product: CodeIgniter PHP full-stack web framework
CVSS Scores: 9.4 - 9.8
Reference:
- https://github.com/codeigniter4/CodeIgniter4/security/advisories/GHSA-c9w5-rwh3-7pm9
- https://github.com/codeigniter4/CodeIgniter4/security/advisories/GHSA-mmj4-63m4-r6h5
CVE-2026-18452 - DMS+ (Non-Mobile) by Rich Source is vulnerable to unauthenticated remote attackers exploiting hard-coded credentials to control all installed devices.
Product: Rich Source DMS+ (Non-Mobile)
CVSS Score: 10.0
NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-18452
CVE-2026-17561 - Logsign SIEM allows Code Injection before version 6.4.108.
Product: Logsign SIEM
CVSS Score: 9.8
NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-17561
CVE-2026-16503 - Supabase one-click template deploys PostgreSQL with default password and exposed interfaces, bypassing host UFW configuration due to Docker iptables rules.
Product: Supabase
CVSS Score: 9.1
NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-16503
CVE-2026-16504 - Deployment of the VPS.org one-click Zulip template deploys a hardcoded application signing key, a default database password ("zulip"), and DISABLE_HTTPS=True.
Product: VPS.org Zulip
CVSS Score: 9.8
NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-16504
CVE-2026-17349, CVE-2026-17351, CVE-2026-17566 - Vulnerabilities in pgAdmin 4 allows for unauthorized access to database credentials by cloning shared servers without proper ownership and credential handling.
Product: pgAdmin 4
CVSS Scores: 9.0 - 9.9
NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-17349
NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-17351
NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-17566
CVE-2026-52855 - Pterodactyl's Wings server control plane allowed low-privileged users to read sensitive information from egg configuration-file templates before version 1.12.3.
Product: Pterodactyl Wings
CVSS Score: 9.9
Reference: https://github.com/pterodactyl/wings/security/advisories/GHSA-pfvc-3p5h-x7h6
CVE-2026-54725 - vault-secrets-webhook allows for direct secret injection into Pods through annotations and ServiceAccount JWTs, posing a security risk prior to version 1.23.1.
Product: vault-secrets-webhook
CVSS Score: 9.6
Reference: https://github.com/bank-vaults/vault-secrets-webhook/security/advisories/GHSA-r2v3-8gwf-7ghm
CVE-2026-51785 - Hugo Leisink Hiawatha v.12.1 and earlier is vulnerable to remote code execution through a malicious request.
Product: Hugo Leisink Hiawatha
CVSS Score: 9.8
NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-51785
CVE-2026-52134 - An issue in the parseGoosePayload() function (/goose/goose_receiver.c) of libiec61850 v1.6 allows attackers to bypass authentication via a captured GOOSE frame.
Product: libiec61850 v1.6
CVSS Score: 9.8
NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-52134
CVE-2026-66402, CVE-2026-67289, CVE-2026-68579 - Vulnerabilities in FreeRDP before version 3.29.0.
Product: FreeRDP
CVSS Scores: 9.6 - 9.8
References:
- https://www.vulncheck.com/advisories/freerdp-before-tls-certificate-identity-validation-bypass
- https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-mwwh-mhp9-q7vm
- https://www.vulncheck.com/advisories/freerdp-before-heap-overflow-via-cliprdrstream-read
CVE-2026-67324 - GitPython 3.1.50 allows an attacker to bypass safety checks and execute arbitrary commands during clone by using the -u<value> short option form for --upload-pack.
Product: GitPython
CVSS Score: 9.8
Reference: https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-v396-v7q4-x2qj
CVE-2026-67330 - @better-auth/scim versions >= 1.4.0-beta.27 through <= 1.6.21 and >= 1.7.0-beta.0 through <= 1.7.0-beta.9 contain an authorization bypass allowing account takeover and unauthorized deprovisioning.
Product: @better-auth scim (a better-auth plugin)
CVSS Score: 9.9
Reference: https://www.vulncheck.com/advisories/better-auth-scim-beta-27-through-account-takeover-via-provider-id-collision
CVE-2026-65321 - PyAthena prior to 3.35.4 is vulnerable to a SQL injection attack, allowing unauthenticated attackers to inject arbitrary SQL through improper quote-escaping in DefaultParameterFormatter.format().
Product: PyAthena
CVSS Score: 9.8
Reference: https://www.vulncheck.com/advisories/pyathena-sql-injection-via-defaultparameterformatter-delete-ctas
CVE-2026-2346 - Menulux Software Inc. Mobile App is vulnerable to an authorization bypass through a User-Controlled key, allowing for a Software Integrity Attack until 12.05.2026.
Product: Menulux Software Inc. Mobile App
CVSS Score: 9.8
NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-2346
CVE-2026-18108 - Net::SAML2 versions before 0.86 for Perl allow authentication bypass due to _verify_encrypted_assertion accepting an EncryptedAssertion without a signature.
Product: Net::SAML2
CVSS Score: 9.8
NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-18108
CVE-2026-64827 - Telenia Software TVox 26.5.3 and prior 26.x versions, and 24.9.21 and prior 24.x versions, are vulnerable to authentication bypass via the set_env.php script, allowing attackers to access PHP scripts under the manager HTML directory without authentication.
Product: Telenia Software TVox
CVSS Score: 9.8
Reference: https://www.vulncheck.com/advisories/telenia-tvox-authentication-bypass-via-set-env-php
CVE-2026-69083, CVE-2026-69084, CVE-2026-69085 - SQL injection vulnerabilities in SiYuan versions before v3.7.3.
Product: SiYuan
CVSS Score: 10.0
Reference:
- https://github.com/siyuan-note/siyuan/security/advisories/GHSA-fph3-ghq9-vw66
- https://github.com/siyuan-note/siyuan/security/advisories/GHSA-vh22-h7hf-www7
- https://github.com/siyuan-note/siyuan/security/advisories/GHSA-33jq-p8c2-q3q4
CVE-2026-9390 - XML::Sig versions before 0.71 for Perl are vulnerable to XPath injection in ID lookup.
Product: Perl XML::Sig
CVSS Score: 9.1
NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-9390
CVE-2026-9487 - XML::Sig versions before 0.71 for Perl allow signature wrapping via duplicate ID.
Product: XML Sig versions before 0.71
CVSS Score: 9.1
NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-9487
CVE-2026-18248 - @fastify/aws-lambda version 6.4.0 allows unauthenticated attackers to forge Lambda proxy events and perform authentication bypasses and privilege escalation.
Product: @fastify/aws-lambda
CVSS Score: 9.1
Reference: https://github.com/fastify/aws-lambda-fastify/security/advisories/GHSA-m93c-jj3f-68ph
CVE-2026-38447 - osTicket 1.18.3 generates predictable API keys using MD5 hashing, making it vulnerable to brute-force attacks.
Product: osTicket
CVSS Score: 9.8
NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-38447
CVE-2026-48031 - go-base prior to 2026-05-18 allows attackers to forge tokens for arbitrary users and bypass authentication by exploiting a hardcoded JWT signing secret set to "random".
Product: go-base
CVSS Score: 9.1
Reference: https://github.com/dhax/go-base/security/advisories/GHSA-mqq6-462x-jxmm
CVE-2026-69240 - Sequelize is vulnerable to SQL injection in Oracle dialect versions prior to 6.37.4 due to a lack of proper escaping in certain scenarios.
Product: Sequelize
CVSS Score: 9.8
Reference: https://github.com/sequelize/sequelize/security/advisories/GHSA-v8fg-2rw7-q452
CVE-2026-18667 - Tenable Sensor Proxy is vulnerable to remote code execution with elevated privileges by coercing an operator to connect the sensor to a malicious host.
Product: Tenable Sensor Proxy
CVSS Score: 9.6
NVD References: https://www.tenable.com/security/tns-2026-21
CVE-2026-62870 - Microsoft Excel Remote Code Execution Vulnerability
Product: Microsoft Office Excel
CVSS Score: 8.8
MSFT Details: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62870
CVE-2026-65802 - Microsoft Edge for Android Information Disclosure Vulnerability
Product: Microsoft Edge for Android
CVSS Score: 7.4
MSFT Details: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-65802
CVE-2026-66310 - Microsoft Edge for Android Information Disclosure Vulnerability
Product: Microsoft Edge for Android
CVSS Score: 7.7
MSFT Details: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-66310
CVE-2026-66315 - Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
Product: Microsoft Edge
CVSS Score: 7.5
MSFT Details: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-66315
CVE-2026-66321 - Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
Product: Microsoft Edge
CVSS Score: 7.4
MSFT Details: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-66321
CVE-2026-66318 - Microsoft Edge (Chromium-based) Information Disclosure Vulnerability
Product: Microsoft Edge (Chromium-based)
CVSS Score: 8.1
MSFT Details: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-66318
CVE-2026-66322 - Microsoft Edge (Chromium-based) Spoofing Vulnerability
Product: Microsoft Edge (Chromium-based)
CVSS Score: 7.1
MSFT Details: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-66322
CVE-2026-56197 - Windows Admin Center (WAC) Remote Code Execution Vulnerability
Product: Windows Admin Center (WAC)
CVSS Score: 8.8
NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-56197
MSFT Details: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-56197
CVE-2026-54128 - Windows DHCP Client Remote Code Execution Vulnerability
Product: Windows DHCP Client
CVSS Score: 8.4
MSFT Details: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-54128
CVE-2026-55129 - Microsoft Office Remote Code Execution Vulnerability
Product: Microsoft Office
CVSS Score: 7.8
MSFT Details: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-55129
CVE-2026-66034 - libssh2 Heap Out-of-Bounds Read via publickey subsystem
Product: libssh2 through 1.11.1
CVSS Score: 7.5
NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-66034
CVE-2026-66035 - libssh2 Heap Buffer Overflow via ETM Cipher Negotiation
Product: libssh2 through 1.11.1
CVSS Score: 7.5
NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-66035
CVE-2026-66033 - libssh2 Integer Underflow DoS via AES-GCM Cipher Negotiation
Product: libssh2 ssh2_cipher_crypt
CVSS Score: 7.5
NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-66033
CVE-2026-50493 - DirectX Graphics Kernel Elevation of Privilege Vulnerability
Product: Microsoft Windows_Server_2025
CVSS Score: 7.8
NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-50493
CVE-2026-38708, CVE-2026-38709, CVE-2026-38711, CVE-2026-38713 - Command injection vulnerabilities in Cudy routers.
Product: Cudy routers
CVSS Score: 9.8
NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-38708
NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-38709
NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-38711
NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-38713
NVD References:
- https://www.cudy.com/pages/security-advisory/cudy-sa-26-7-aihgtk
- https://www.cudy.com/pages/security-advisory/cudy-sa-26-7-jezzy-4
- https://www.cudy.com/pages/security-advisory/cudy-sa-26-7-7-kjw-1-b
- https://www.cudy.com/pages/security-advisory/cudy-sa-26-7-ehixbe
CVE-2026-67822 - Tenda W6-S 1.0.0.4(510) is vulnerable to a stack-based buffer overflow due to unrestricted copying of user-controlled parameters in the /goform/wifiSSIDset endpoint.
Product: Tenda W6-S
CVSS Score: 9.8
Reference: https://github.com/Tristerjh/Tenda/blob/main/Tenda_W6-S_GO_overflow.md
The following vulnerability needs a manual review:
CVE-2026-53921 - Stack buffer overflow in DHCPv6 IA reply serialization. Fixed in OpenWrt version 24.10.8. Product: OpenWrt CVSS Score: 9.8 NVD: N/A References:
- https://github.com/openwrt/odhcpd/security/advisories/GHSA-7fwx-hhrg-3496
- https://thehackernews.com/2026/07/critical-openwrt-dhcpv6-flaw-could-let.html
Webinar | SANS 2026 Cloud Security Exchange | Monday, August 17 | The agenda is now live. Explore expert-led sessions led by AWS, Google & Microsoft. Attend live or watch on demand.
Webinar | How to Reduce Connectivity Tickets and Accelerate Application Changes
Webinar | Cloud Summit Solutions Track 2026 | Tuesday, August 18 | Chaired by Shaun McCullough
Webinar | From Framework to Action: Applying the SANS AI Security Maturity Model | Wednesday, September 16 | Chris Cochran, Diana Kelley, Malcolm Harkins, and Kyriakos "Rock" Lambros