Deep Analysis

Threat Articles

Long-form security analysis and prioritization guidance. 88 records found.

articleCRITICAL 9.3

Critical Unauthenticated SQL Injection Vulnerability in MapSVG Plugin

A critical SQL injection vulnerability (CVE-2026-59527) has been discovered in the MapSVG plugin, affecting versions up to 8.14.0. This unauthenticated vulnerability has a CVSS score of 9.3, indicating a high severity threat. Successful exploitation could lead to unauthorized access to sensitive data. Immediate patching to version 8.14.1 or later is strongly recommended.

1 source
articleCRITICAL 9.1

Critical Vulnerability in Masteriyo LMS WordPress Plugin Allows Unauthenticated Session Termination (CVE-2026-13332)

A critical vulnerability (CVE-2026-13332, CVSS 9.1) exists in the Masteriyo LMS WordPress plugin prior to version 2.3.1. This flaw allows unauthenticated attackers to terminate the active sessions of any user, including administrators, via an unauthenticated AJAX action. Immediate patching is recommended to prevent potential exploitation.

1 source
articleMEDIUM 6.5

Linux Kernel Vulnerability: CVE-2024-14040 - Insufficient Weight Representation in Nexthop Group Members

A vulnerability in the Linux kernel's nexthop group member configuration allows for potential issues with weight representation, affecting the ability to configure certain network deployments. The vulnerability has been resolved by increasing the weight representation from u8 to u16. This change impacts the Linux kernel's networking functionality, specifically in CLOS networks where ECMP weights are adjusted. Affected systems should apply patches to ensure proper weight configuration and prevent potential network instability.

1 source
articleCRITICAL 9.0

Critical Shell Command Injection Vulnerability in Catalyst::View::Wkhtmltopdf

A critical vulnerability (CVE-2026-16766) has been discovered in Catalyst::View::Wkhtmltopdf versions before 0.6.1, allowing for shell command injection via PDF render options. This vulnerability is particularly severe as it enables remote code execution (RCE) without authentication. The affected package is no longer actively developed, and users are urged to migrate to alternative solutions. Immediate patching or migration is strongly recommended to prevent potential exploitation.

1 source
articleCRITICAL 10.0

Critical Vulnerability in Microsoft Azure Kubernetes Service Allows Privilege Escalation

A critical vulnerability, CVE-2026-56163, with a CVSS score of 10, was discovered in Microsoft Azure Kubernetes Service. This vulnerability allows an unauthorized attacker to elevate privileges over a network due to missing authentication for a critical function. The vulnerability has not been actively exploited but poses a significant risk due to its high severity and potential impact. Immediate patching or mitigation is recommended.

1 source
articleCRITICAL 9.1

Auth.js Configuration Error Leads to Silent Fail-Open in Existence-Based Auth Checks

A critical vulnerability in Auth.js (next-auth) version 5 allows misconfigured applications to fail open, granting unauthorized access to all users when the auth layer encounters a server-side error. This issue arises from existence-based auth checks evaluating to true for every request, including unauthenticated ones, when the auth object is populated with an error. The vulnerability has a CVSS score of 9.1 and is classified under CWE-636 (Not Failing Securely) and CWE-285 (Improper Authorization).

1 source
articleCRITICAL 9.8

Critical Vulnerability in GoDAM WordPress Plugin Allows Arbitrary File Uploads and Potential RCE

The GoDAM – Organize WordPress Media Library & File Manager plugin for WordPress is vulnerable to arbitrary file uploads in versions up to and including 1.12.2. This critical vulnerability, with a CVSS score of 9.8, allows unauthenticated attackers to upload arbitrary files on the affected site's server, potentially leading to remote code execution. Immediate patching is recommended.

1 source
articleCRITICAL 9.1

Critical Authentication Bypass Vulnerability in Check Point SmartConsole (CVE-2026-16232)

A critical authentication bypass vulnerability (CVE-2026-16232) has been discovered in Check Point SmartConsole, allowing unauthenticated remote attackers to obtain application login tokens and gain full administrative privileges. This vulnerability has a CVSS score of 9.1 and is actively being exploited. Affected products include various versions of Check Point Quantum Security Management and Multi-Domain Security Management. Immediate patching or mitigation is strongly recommended.

1 source
articleHIGH 8.3

Next.js Server-Side Request Forgery Vulnerability in Rewrites via Attacker-Controlled Destination Hostname

A critical vulnerability (CVE-2026-64645) has been discovered in Next.js, a popular React-based framework for building server-rendered, statically generated, and performance-optimized web applications. This vulnerability allows for Server-Side Request Forgery (SSRF) in rewrites via attacker-controlled destination hostnames, with a CVSS score of 8.3. The vulnerability affects Next.js versions >= 12.0.0 and < 15.5.21, as well as versions >= 16.0.0 and < 16.2.11. Immediate patching or workarounds are recommended to prevent potential SSRF attacks.

1 source
articleCRITICAL 9.3

CVE-2026-65048: Critical Unauthenticated Stored XSS in Ninja Forms WordPress Plugin

A critical vulnerability (CVE-2026-65048, CVSS 9.3) exists in the Ninja Forms plugin for WordPress versions 3.10.4 through 3.14.9, allowing unauthenticated stored cross-site scripting (XSS) attacks via the Repeatable Fieldset feature. An attacker can submit a crafted form with malicious script payloads, which execute in an administrator's browser when viewing submissions, enabling session-cookie theft, creation of administrator accounts, and arbitrary modification of site content. Immediate patching is recommended.

1 source
articleHIGH 7.0

Inheritance of High-Severity Vulnerabilities in libvips: CVE-2026-33327, CVE-2026-33328, CVE-2026-35590, CVE-2026-35591

Multiple high-severity vulnerabilities have been discovered in the libvips dependency used by the sharp library. These vulnerabilities, with a CVSS score of 7, affect versions of sharp prior to 0.35.0. The vulnerabilities have been patched in sharp version 0.35.3, which includes libvips 8.18.3. Immediate upgrade is recommended to prevent potential exploitation.

1 source
articleCRITICAL 9.0

Critical Path Traversal Vulnerability in Red Hat Ansible Automation Platform and Satellite (CVE-2026-12701)

A high-severity path traversal vulnerability (CVE-2026-12701, CVSS 9) was discovered in pulpcore, affecting Red Hat Ansible Automation Platform and Satellite. An authenticated administrator can exploit this flaw to write arbitrary files to any location writable by the Pulp service user, potentially leading to service compromise or further system exploitation. Immediate patching is recommended.

1 source
articleHIGH 7.1

CVE-2026-9833: Unauthenticated XSS in Tag Groups WordPress Plugin

The CVE-2026-9833 vulnerability is a high-severity (CVSS 7.1) unauthenticated stored cross-site scripting (XSS) flaw in the Tag Groups WordPress plugin prior to version 2.2.0. An attacker can exploit this vulnerability by crafting a link that, when followed by a logged-in user with 'edit_pages' capability (Editor or higher), allows the execution of arbitrary JavaScript in the user's browser. This could lead to unauthorized actions within the WordPress dashboard. Immediate action is recommended to upgrade to version 2.2.0 or later.

1 source
articleHIGH 7.5

CVE-2026-16221: fast-uri Vulnerability Allows URL Parsing Discrepancies and Potential SSRF Attacks

A high-severity vulnerability (CVE-2026-16221, CVSS 7.5) exists in fast-uri versions 2.3.1 through 4.1.0, which can lead to URL parsing discrepancies when used with Node's native WHATWG URL parser. This discrepancy can be exploited to bypass host-based security policies, potentially allowing SSRF attacks or steering to unintended destinations, including cloud metadata endpoints or internal hosts. Affected applications should upgrade to fast-uri 4.1.1, 3.1.4, or 2.4.3 immediately.

1 source
articleMEDIUM 6.5

CVE-2026-16215: Missing Authorization in geex-arts django-jet OAuth Credential Revoke Handler

A security flaw has been discovered in geex-arts django-jet up to 1.0.8, impacting the OAuth Credential Revoke Handler. The vulnerability results in missing authorization, allowing remote attacks. The exploit has been released publicly, and while there is no active exploitation, the severity is rated at 6.5 (CVSS 3.1). Affected versions include 1.0.0 to 1.0.8, and the recommended action is to upgrade to a patched version once available.

1 source
articleCRITICAL 9.8

Critical Authentication Bypass Vulnerability in VMware Avi Load Balancer (CVE-2026-47865)

A critical authentication bypass vulnerability (CVE-2026-47865) has been discovered in VMware Avi Load Balancer, with a CVSS score of 9.8. The vulnerability allows a malicious user with network access to bypass the authentication mechanism and access the Avi Control plane. Affected versions include 31.1.1 through 31.2.2, 30.1.1 through 30.2.6, and 22.1.1 through 22.1.7. Immediate patching is recommended to prevent potential exploitation.

1 source
articleCRITICAL 9.8

Critical XXE Vulnerability in libpvestorage-perl and libpve-storage-perl

A critical XML External Entity (XXE) vulnerability, CVE-2026-51080, has been discovered in libpvestorage-perl v9.1.1 and libpve-storage-perl v8.3.7. This vulnerability has a CVSS score of 9.8, indicating a high severity. Although it is not currently being actively exploited, its potential for remote, unauthenticated attacks with high impact makes it a significant threat. Immediate patching or mitigation is recommended.

1 source
articleCRITICAL 9.1

Critical Vulnerability in Clawvet Self-Hosted API Server: CVE-2026-62241

A critical vulnerability (CVE-2026-62241, CVSS 9.1) exists in the Clawvet self-hosted API server (apps/api) before version 0.7.5. The vulnerability allows a remote unauthenticated attacker to harvest user IDs, forge a valid session cookie, and obtain sensitive user information. The vulnerability has not been actively exploited but poses a significant risk due to its severity and the potential for exploitation. Immediate patching to version 0.7.5 or later is strongly recommended.

1 source
articleHIGH 7.6

MCP Python SDK Vulnerability: Experimental Task Handlers Allow Unauthorized Access to Tasks

A high-severity vulnerability (CVE-2026-52870) exists in the MCP Python SDK, specifically in the experimental tasks feature. When enabled, default request handlers do not check session ownership, allowing any client to access and cancel other clients' tasks. Affected versions are from 1.23.0 to 1.27.1. The vulnerability has a CVSS v3 score of 7.6 and is classified under CWE-862 (Missing Authorization).

1 source
articleHIGH 8.7

Critical Vulnerability in ArcadeDB: Unauthorized JavaScript Execution via SQL Injection

A critical vulnerability (GHSA-vwjc-v7x7-cm6g) has been discovered in ArcadeDB, a popular database management system. This vulnerability allows any user authorized for the database, including those with read-only roles, to bypass scripting authorization gates and execute arbitrary JavaScript code. The vulnerability has a CVSS score of 8.7 and can lead to severe impacts including SSRF, remote JavaScript inclusion, and unbounded CPU/memory DoS. Immediate patching to version 26.7.2 or later is highly recommended.

1 source
articleCRITICAL 9.2

Critical WebSocket Message Corruption Vulnerability in websocket-driver (CVE-2026-54466)

A critical vulnerability (CVE-2026-54466, CVSS 9.2) exists in the websocket-driver library, allowing for message corruption via abuse of protocol length headers. This issue affects versions < 0.7.5 and has been patched in version 0.7.5. Successful exploitation requires no authentication or user interaction and can lead to incorrect parsing of subsequent payloads. Immediate upgrade to version 0.7.5 is recommended.

1 source
articleHIGH 8.6

Critical Confused-Deputy Flaw in Grafana MCP Server Enables Token Exfiltration and SSRF

A high-severity vulnerability (CVE-2026-15583, CVSS 8.6) in Grafana MCP Server allows unauthenticated remote attackers to exfiltrate environment-configured Grafana service-account tokens and conduct SSRF attacks against internal services. The flaw has not been actively exploited but poses a significant risk due to its potential impact. Organizations using Grafana MCP Server version 0.17.1 or earlier are advised to upgrade immediately.

1 source
articleCRITICAL 9.8

Critical Command Injection Vulnerability in Sustainable Irrigation Platform (SIP)

A critical command injection vulnerability (CVE-2026-58479) has been discovered in the Sustainable Irrigation Platform (SIP) through version 5.2.16. The vulnerability, located in the optional cli_control plugin, allows unauthenticated or cross-site request forgery attackers to execute arbitrary operating-system commands. This can be achieved by storing a malicious payload via the plugin's HTTP endpoint and triggering execution by activating the associated irrigation station, exploiting the absence of passphrase protection or the default passphrase 'opendoor'. The vulnerability has a CVSS score of 9.8 and is considered critical.

1 source
articleHIGH 7.1

Woodpecker CI gRPC Agent ID Spoofing Vulnerability Allows Cross-Tenant Impersonation

A vulnerability in Woodpecker CI's gRPC layer (CVE-2026-50141, CVSS 7.1) allows authenticated agents to impersonate other agents by spoofing the `agent_id` metadata. This issue enables cross-tenant impersonation, potentially leading to unauthorized access and privilege escalation. Affected versions include Woodpecker CI 3.0.0 to 3.14.1. Immediate patching or workarounds are recommended.

1 source
articleHIGH 8.1

Critical Vulnerability in User Registration & Membership WordPress Plugin Allows Unauthorized Role Elevation

A high-severity vulnerability (CVE-2026-11963, CVSS 8.1) exists in the User Registration & Membership WordPress plugin prior to version 5.2.2. This flaw allows any authenticated user, including subscribers, to change another user's WordPress role and membership tier without proper authorization. The vulnerability has not been actively exploited but poses a significant risk due to its ease of exploitation and potential impact.

1 source
articleHIGH 7.8

Critical Use-After-Free Vulnerability in Zephyr's Dynamic Kernel-Object Tracking (CVE-2026-10667)

A critical use-after-free vulnerability (CVE-2026-10667) has been discovered in Zephyr's dynamic kernel-object tracking, affecting SMP systems with userspace enabled. This vulnerability allows a deprivileged user thread to corrupt kernel object-tracking structures, potentially leading to privilege escalation or denial of service. The vulnerability has a CVSS score of 7.8 and affects Zephyr versions from 1.14.0 to 4.4.0. Immediate patching is recommended to prevent potential exploitation.

1 source
articleHIGH 8.8

CVE-2026-15484: Buffer Overflow Vulnerability in TRENDnet TEW-821DAP

A buffer overflow vulnerability (CVE-2026-15484) with a CVSS score of 8.8 affects TRENDnet TEW-821DAP version 1.12B01. The vulnerability is in the /goform/tools_nslookup component and can be exploited remotely. The vendor has confirmed the vulnerability but notes that the product is End-of-Life (EOL) and no longer supported. Immediate patching or mitigation is recommended.

1 source
articleHIGH 8.8

Critical Vulnerability in Swiss Toolkit For WP Plugin: Arbitrary File Upload and Potential RCE

The Swiss Toolkit For WP plugin for WordPress, versions up to and including 1.4.6, is vulnerable to arbitrary file upload due to a flawed file type validation bypass. This allows authenticated attackers with Author-level access to upload arbitrary files, potentially leading to remote code execution if the 'Enhanced Multi-Format Image Support' feature is enabled. The vulnerability has a CVSS score of 8.8, indicating high severity. Immediate patching is recommended.

1 source
articleHIGH 8.7

Unauthenticated Access Vulnerability in Clauster Dashboard

A critical vulnerability in Clauster, a dashboard and API management tool, allows unauthenticated access to its entire dashboard and API when deployed on non-loopback addresses and authentication is not properly enabled. This affects all released versions up to 0.2.1. An attacker with network access can gain full control, enabling remote code execution in project directories. Immediate action is required to set auth.enabled to true or bind to loopback addresses with secure access controls.

1 source
articleHIGH 8.2

Critical Vulnerability in OpenStack Ironic: CVE-2026-54423

A critical vulnerability (CVE-2026-54423) has been discovered in OpenStack Ironic, allowing an authenticated user to send arbitrary IPMI commands to a node, bypassing access control. This vulnerability has a CVSS score of 8.2 and affects multiple versions of OpenStack Ironic. Immediate patching is recommended to prevent potential exploitation.

1 source