Overview of incoming advisories.
1553 results found
A critical unauthenticated privilege escalation vulnerability has been identified in the Digits WordPress plugin affecting versions up to and including 9.2. The vulnerability allows unauthenticated attackers to escalate their privileges, potentially gaining administrative access to affected WordPress installations. The flaw is tracked as CVE-2026-28165 and has been documented by both the NVD and Patchstack. No authentication is required to exploit this vulnerability, making it particularly dangerous. WordPress site administrators using the Digits plugin should update to a patched version immediately. The vulnerability was reported via Patchstack's WordPress vulnerability database. The high severity rating reflects the risk of complete site compromise without any prior authentication.
View original advisory →CVE-2026-76072 affects the Continue CLI, which uses an incomplete denylist as its sole barrier against destructive shell commands in headless and auto (unattended) modes. The default policy grants the Bash tool broad 'allow' permissions, with blocking only occurring when the terminal-security evaluator returns a 'disabled' verdict. The dangerous-path check covers only a limited set of paths, leaving /home, /root, /var, /opt, and /srv unprotected from recursive forced deletion. Shell variable expansion via shell-quote parsing causes $HOME to resolve to an empty token, bypassing the dangerous-path check. Dangerous commands such as shred, wipefs, truncate, and pkexec are entirely unhandled, and find with -delete is merely rated high risk rather than blocked. Because the agent autonomously processes external content including web pages, repository files, and issue text, an indirect prompt injection attack can trigger unattended data destruction. This vulnerability enables an attacker to cause complete data loss for the invoking user through crafted malicious content.
View original advisory →CVE-2026-76835 describes a critical authentication bypass vulnerability in OAuth2 Proxy affecting its default reverse-proxy configuration. The flaw exists because the proxy trusts client-supplied X-Forwarded-Uri headers when evaluating skip-auth rules, while the guard introduced for CVE-2026-40575 is ineffective in this default setup. The root cause is that buildTrustedProxyNetSet defaults to 0.0.0.0/0 and ::/0 when trusted_proxy_ip is not explicitly configured, effectively trusting every client as a proxy. An unauthenticated attacker can set X-Forwarded-Uri to a value matching an allow-listed route, causing the skip-auth decision to be made against the spoofed path while the actual protected upstream path is forwarded unchanged. This allows complete bypass of authentication controls without any credentials. The vulnerability impacts installations running in reverse-proxy mode without explicit trusted_proxy_ip configuration, which is the default state. Affected code spans pkg/requests/util/util.go, oauthproxy.go, and pkg/apis/middleware/scope.go.
View original advisory →A vulnerability has been identified in EFM ipTIME T16000M firmware version 14.20.2. The flaw resides in the function httpcon_check_session_url within the Session Validation Handler component. The vulnerability leads to improper authentication, allowing remote attackers to bypass session validation. Exploitation is possible remotely without physical access to the device. A public exploit has already been released, increasing the risk of active attacks. The vulnerability was responsibly disclosed to the vendor, but no response was received. The public availability of the exploit significantly raises the threat level for affected devices. Network devices like routers are critical infrastructure components, making this a high-priority issue. Organizations using the affected firmware version should apply mitigations or monitor for exploitation attempts.
View original advisory →A SQL injection vulnerability has been identified in Shenzhen Gongji Technology's XBROTHER Dynamic Environment Monitoring System, affecting versions up to 300R004C00B300. The vulnerability resides in the PlanController.getImmediatePlans function within the /xbreport/api/v1/plamange/plansImmediate endpoint. Attackers can manipulate the 'order' or 'sort' arguments to perform SQL injection attacks remotely. The exploit has been publicly disclosed, increasing the risk of active exploitation. This affects monitoring infrastructure systems commonly used in data center and facility management environments. No authentication details are specified, suggesting potential unauthenticated access. The public disclosure and remote exploitability make this a high-severity issue requiring prompt patching.
View original advisory →CVE-2026-59564 describes an authentication bypass vulnerability in communications between affected versions of the Zscaler Client Connector and the Zscaler Client Connector Portal. The flaw could allow an attacker to bypass authentication mechanisms in the communication channel between these components. Zscaler Client Connector is a widely deployed enterprise security agent used for zero-trust network access. An authentication bypass in this component could have significant security implications for organizations relying on Zscaler for network security enforcement. The vulnerability is documented on the NVD and has an associated release summary from Zscaler detailing affected versions. The current criticality is rated High, suggesting meaningful risk to affected deployments. Users of affected versions should consult the Zscaler release summary to identify fixed versions and apply patches promptly.
View original advisory →A SQL injection vulnerability has been identified in the Shenzhen Gongji Technology XBROTHER Dynamic Environment Monitoring System, affecting versions up to 300R004C00B300. The vulnerability exists in the PlanController.getImmediatePlans function within the /xbreport/api/v1/plamange/plansImmediate endpoint. Attackers can manipulate the 'order' or 'sort' arguments to perform SQL injection attacks remotely. The exploit has been publicly disclosed, increasing the risk of active exploitation. No authentication barrier details are specified, suggesting potential unauthenticated remote access. The vulnerability poses a significant risk to organizations using this environmental monitoring system. Public disclosure of the exploit raises the urgency for patching or mitigating the affected systems.
View original advisory →A vulnerability was discovered in rpmbuild where processing a crafted tarball in tarball mode can lead to macro injection via specially designed tar member names. This flaw allows a remote attacker to execute arbitrary code on the affected system. The attack vector requires social engineering, convincing a user to build a malicious tarball. The vulnerability is tracked as CVE-2026-78367 and has been reported to Red Hat's security team. References include Red Hat's security advisory, a Bugzilla bug report, and a GitHub issue in the rpm-software-management repository. The issue affects the RPM build toolchain, which is widely used in Linux distributions such as Red Hat Enterprise Linux and Fedora. Given its potential for remote code execution, this vulnerability is considered high severity.
View original advisory →A vulnerability has been identified in Open5GS version 2.8.0 affecting the function pcrf_rx_aar_cb in the file src/pcrf/pcrf-rx-path.c within the Rx AA-Request Handler component. The vulnerability allows an out-of-bounds read condition to be triggered through manipulation of the affected function. The attack can be initiated remotely, increasing its potential impact. A patch has been developed and identified by commit hash c18dc6938bf63cc7374315d3dca303d92066e746. Affected users are strongly recommended to apply the patch immediately. The vulnerability is tracked under CVE-2026-78157 and has been referenced in both the NVD and VulDB databases. Open5GS is an open-source implementation of 5G and LTE core network components, making this vulnerability relevant to telecommunications infrastructure.
View original advisory →A critical unauthenticated privilege escalation vulnerability has been identified in the Jawn WordPress theme affecting versions 1.4.2 and below. The vulnerability allows unauthenticated users to escalate their privileges, potentially gaining administrative access to affected WordPress installations. This type of vulnerability poses a significant risk as it requires no prior authentication to exploit. The issue is tracked as CVE-2026-66648 and has been documented by both the NVD and Patchstack. Users of the Jawn theme are advised to update to a patched version as soon as one becomes available. The vulnerability was disclosed through Patchstack's WordPress vulnerability database. No additional technical details about the exploitation method are provided in the current disclosure.
View original advisory →A SQL injection vulnerability has been identified in itsourcecode Sales and Inventory System version 1.0. The vulnerability exists in the file /pages/processlogin.php, where manipulation of the 'User' argument allows an attacker to perform SQL injection. The attack can be initiated remotely without requiring physical access to the system. The exploit has been publicly disclosed and is available for use, increasing the risk of exploitation. This vulnerability poses a significant risk to organizations using this software, as it could allow attackers to access, modify, or delete database contents. The affected product is a sales and inventory management system commonly used by small businesses. No patch or mitigation details are mentioned in the article. The vulnerability has been catalogued in VulDB and NVD databases.
View original advisory →CVE-2026-32558 describes an unauthenticated privilege escalation vulnerability affecting the Affiliate Pro - Affiliate Program for WooCommerce & WordPress plugin in versions up to and including 8.9.1. The vulnerability allows unauthenticated attackers to escalate their privileges, posing a significant security risk to WordPress and WooCommerce installations using this plugin. The flaw has been documented by both the NVD (National Vulnerability Database) and Patchstack. No authentication is required to exploit this vulnerability, making it particularly dangerous for affected sites. Users are advised to update the plugin beyond version 8.9.1 to remediate the issue. The vulnerability is classified as high severity given the unauthenticated nature of the exploit and the potential for full privilege escalation.
View original advisory →CVE-2026-59568 describes multiple vulnerabilities affecting Zscaler Client Connector (ZCC) that enable remote code execution. The flaws allow an unauthenticated, unprivileged remote user to execute arbitrary code within the ZCC context. The vulnerabilities are present in affected versions of the Zscaler Client Connector software. No authentication or special privileges are required to exploit these vulnerabilities, making them particularly severe. The issue is documented on the NVD and Zscaler's own release summary page. Zscaler has published a Client Connector App Release Summary for 2026 that likely contains patched versions. The criticality is rated High due to the unauthenticated RCE nature of the vulnerability. Organizations using affected versions of Zscaler Client Connector should update immediately.
View original advisory →CVE-2026-32559 describes an Arbitrary File Upload vulnerability affecting the UltimateAI WordPress plugin in versions 3.1.0 and below. The flaw allows subscriber-level authenticated users to upload arbitrary files to the server, which could lead to remote code execution or site compromise. This type of vulnerability is particularly dangerous in WordPress environments as it can allow low-privileged users to gain elevated access. The vulnerability has been documented by both the NVD and Patchstack security database. Users of the UltimateAI plugin are advised to update to a patched version immediately. The issue is rated as high severity given the potential for significant impact on affected WordPress installations.
View original advisory →A critical unauthenticated Local File Inclusion (LFI) vulnerability has been identified in the WP Cafe Pro WordPress plugin affecting versions prior to 3.0.15. The vulnerability allows unauthenticated attackers to include local files on the server, potentially leading to sensitive information disclosure, code execution, or full system compromise. No authentication is required to exploit this vulnerability, significantly increasing its risk. The issue has been assigned CVE-2026-66587 and is documented in both the NVD and Patchstack databases. Users of WP Cafe Pro are strongly advised to update to version 3.0.15 or later to remediate the vulnerability. The unauthenticated nature of the exploit makes it particularly dangerous for sites running outdated versions of the plugin.
View original advisory →CVE-2026-78211 affects 4MOSAn GCB Doctor, a product developed by 4MOSAn Security Technology. The vulnerability is an OS Command Injection flaw that can be exploited by unauthenticated remote attackers. Attackers can inject malicious commands through an unremoved ADOdb test page parameter left in the application. Successful exploitation allows arbitrary system command execution on the affected server. No authentication is required, making this vulnerability particularly dangerous and easily exploitable. The vulnerability was reported via Taiwan's TWCERT/CC advisory system. The issue stems from improper removal of a database library test page exposed in the production environment. This type of leftover debug/test functionality represents a significant security risk. The criticality is rated High due to the unauthenticated remote code execution potential.
View original advisory →A security vulnerability has been identified in EFM ipTIME T24000M firmware versions up to 14.20.0. The flaw exists in the function httpcon_check_session_url within the Session Validation Handler component. Exploitation of this vulnerability leads to improper authentication, potentially allowing unauthorized access. The attack vector is remote, requiring no physical access to the device. A public exploit has already been disclosed and is available for use. The vendor was notified prior to public disclosure but did not respond. This poses a significant risk to network infrastructure relying on this hardware. No patch or mitigation from the vendor has been confirmed.
View original advisory →A SQL injection vulnerability has been identified in SourceCodester Simple Online Food Ordering System version 1.0. The vulnerability exists in the file /fos/admin/ajax.php?action=confirm_order, where manipulation of the 'ID' argument leads to SQL injection. The attack can be executed remotely without requiring physical access. A public exploit has been released, increasing the risk of active exploitation. The vulnerability affects the admin panel's order confirmation functionality. No authentication bypass details are specified, but the remote exploitability and public exploit availability make this a significant threat. Organizations using this software should apply patches or mitigations immediately.
View original advisory →A heap-based buffer overflow vulnerability exists in Konami's Metal Gear Online 3 due to improper validation of the lobby data field 'kick_num'. The function processes kicked player IDs without verifying that 'kick_num' stays within expected bounds, allowing writes beyond a 16-entry buffer sized for the maximum player count. Overflow data spills into adjacent heap memory containing Steam callback handler structures used for lobby data updates and messaging. An attacker can overwrite function pointers and callback argument values within these structures by supplying a crafted oversized 'kick_num' and corresponding 'kicked_id_%i' fields. This enables control-flow hijacking and potentially arbitrary code execution within the game process. The vulnerability is classified as CWE-122 (Heap-based Buffer Overflow) and is referenced by CERT/CC advisory VU#728712. Exploitation requires the ability to supply malicious lobby data to a target player in an online session.
View original advisory →A SQL injection vulnerability has been identified in SourceCodester Simple Online Food Ordering System version 1.0. The flaw exists in the file /fos/admin/ajax.php?action=save_user, where manipulation of the Username argument allows SQL injection attacks. The vulnerability can be exploited remotely without requiring physical access to the target system. A public exploit has already been released, increasing the risk of active exploitation. The vulnerability has been assigned CVE-2026-78197 and is tracked in VulDB as vuln/394574. No patch or mitigation details are currently mentioned in the article. The public availability of the exploit makes this a higher-risk issue for any organization running this software.
View original advisory →