Daily Updates
Cyber News
Short, concise cybersecurity updates. 89 records found.
CVE-2026-59533: Unauthenticated SQL Injection in Relevanssi Light Plugin
A critical vulnerability (CVE-2026-59533, CVSS 9.3) was discovered in the Relevanssi Light plugin (versions <= 1.2.2) for WordPress, allowing unauthenticated SQL injection. This vulnerability is not currently being exploited, but it poses a significant risk to WordPress sites using the affected plugin versions. Immediate action is required to update to a patched version.
Critical Vulnerability in 微信二维码登陆 WordPress Plugin Allows Unauthenticated Login
A critical vulnerability (CVE-2026-13597, CVSS 9.1) in the 微信二维码登陆 WordPress plugin (version 1.3 and earlier) allows unauthenticated attackers to forge login events, read login codes, and log in as any user, including administrators, without a password. Immediate action is required to prevent exploitation.
Linux Kernel Vulnerability: CVE-2026-64530 - Use-After-Free in net/sched/cls_api.c
A use-after-free vulnerability was discovered in the Linux kernel's net/sched/cls_api.c, specifically in the tcf_qevent_handle function. This vulnerability can be exploited by an attacker to potentially execute arbitrary code or cause a denial-of-service (DoS) condition. Linux kernel versions 5.15.148, 6.1.75, 6.6.14, and 6.7.2 are affected.
Linux Kernel Vulnerability: CVE-2026-64257 - Reject Overlapping Data Areas in SMB2 Responses
A vulnerability in the Linux kernel's SMB2 response handling can allow an attacker to trigger an invalid response that appears to have no data area, potentially leading to security issues. This vulnerability affects various Linux kernel versions. Users should update to the latest version to mitigate the risk.
Critical Server-Side Request Forgery Vulnerability in Microsoft Purview Data Governance (CVE-2026-57106)
A critical server-side request forgery (SSRF) vulnerability, CVE-2026-57106, with a CVSS score of 10, has been identified in Microsoft Purview Data Governance. This vulnerability allows an unauthorized attacker to elevate privileges over a network. Immediate action is required to mitigate this critical vulnerability.
Auth.js Vulnerability: Homoglyph @ Bypass in Email Normalizer
A critical vulnerability in Auth.js allows an attacker to bypass email validation, potentially leading to account takeover. The flaw affects versions of `next-auth` and `@auth/core` when using the email/magic-link sign-in flow with the default identifier normalizer. Immediate action is required to prevent exploitation.
Critical Code Injection Vulnerability in Customer Support Ticket System & Helpdesk Plugin for WordPress (CVE-2026-15011)
A critical vulnerability (CVE-2026-15011, CVSS score: 9.8) exists in the Customer Support Ticket System & Helpdesk plugin for WordPress, allowing unauthenticated attackers to inject arbitrary PHP code. This vulnerability affects all versions up to and including 6.0.5. Immediate action is required to prevent potential site disruption and data exposure.
LiteLLM MCP Authentication Bypass via OAuth2 Passthrough Fallback (CVE-2026-59822)
LiteLLM's MCP Streamable HTTP endpoint is vulnerable to an authentication bypass attack via OAuth2 passthrough fallback, allowing an unauthenticated attacker to establish an authenticated MCP session using an arbitrary Bearer token. This issue is fixed in version 1.84.0. A CVSS score of 8.8 indicates high severity.
Next.js Denial of Service Vulnerability in App Router using Server Actions
A denial of service vulnerability exists in Next.js applications using App Router with at least one Server Action. Crafted requests can lead to excessive CPU usage, blocking further requests. Affected versions include Next.js 13.0.0 to 15.5.20 and 16.0.0 to 16.2.10.
CVE-2026-65049: Critical Vulnerability in Ninja Forms Plugin for WordPress Multisite
A critical vulnerability (CVE-2026-65049, CVSS 9.3) exists in the Ninja Forms plugin (version 3.14.8 and prior) for WordPress Multisite. This incorrect authorization vulnerability allows a subsite Administrator to trigger network-wide deletion of all Ninja Forms data without requiring super-admin or network-admin privileges. Immediate action is required to update to version 3.14.9 or later.
CVE-2026-13439: Unauthenticated Privilege Escalation in Easy Form Builder by WhiteStudio WordPress Plugin
The Easy Form Builder by WhiteStudio plugin for WordPress is vulnerable to unauthenticated privilege escalation to administrator in versions up to 4.0.11. This vulnerability allows unauthenticated attackers to reset the password of any WordPress user, including administrators, and gain full administrator access. A CVSS score of 9.8 indicates critical severity.
CVE-2026-35198: Critical Stored XSS Vulnerability in HeyForm
A critical stored cross-site scripting (XSS) vulnerability exists in HeyForm, an open-source form builder, prior to version 3.0.0-rc.7. A low-privileged team member can inject malicious JavaScript, leading to account takeover through privilege escalation when a team owner views the form. Update to version 3.0.0-rc.7 or later to mitigate.
CVE-2026-12898: Unauthenticated Log File Creation/Append Vulnerability in All-in-One WP Migration and Backup Plugin
A vulnerability in the All-in-One WP Migration and Backup WordPress plugin before version 7.106 allows unauthenticated attackers to create or append log files in arbitrary locations. The vulnerability has a CVSS score of 6.5 and is classified as MEDIUM severity. Affected versions are prior to 7.106.
Mythos Exposure Window: A Security Program Risk
The recent reveal of Anthropic's Mythos has raised concerns about the potential security risks it poses. While the industry has focused on the volume of new CVEs and the speed of exploitation, the real issue may be the exposure window that Mythos creates. Security teams need to assess and mitigate this risk.
CVE-2026-16204: Remote Code Injection in zevorn rt-claw
A code injection vulnerability has been discovered in zevorn rt-claw up to 0.2.0, affecting the Telegram-to-AI Tool Execution Flow. The vulnerability has a CVSS score of 6.3 and can be exploited remotely. Affected versions include 0.1 and 0.2.0.
VMware Avi Load Balancer Directory Traversal Vulnerability (CVE-2026-47871)
A directory traversal vulnerability in VMware Avi Load Balancer allows authenticated network users to perform directory traversal attacks. Multiple versions are affected, with CVSS score of 8.8. Update to fixed versions to mitigate.
Critical Unverified Password Change Vulnerability in Vimesoft Inc. Enterprise Video Platform (CVE-2026-12692)
A critical unverified password change vulnerability (CVE-2026-12692) with a CVSS score of 9.8 affects Vimesoft Inc.'s Enterprise Video Platform versions 3.11.0.0 to 3.24.0. This vulnerability allows for authentication bypass and could lead to severe impacts including high confidentiality, integrity, and availability risks. Immediate action is required to update to version 3.25.0 or later.
Inc Ransomware Exploits SonicWall SMA Zero-Days
Inc ransomware threat actors are actively exploiting two zero-day vulnerabilities in SonicWall's mobile access appliances, allowing them to gain root-level capabilities. This exploitation enables the threat actors to compromise the appliances and potentially gain unauthorized access to sensitive data. Security teams should immediately investigate and patch affected systems.
MCP Python SDK Vulnerability: WebSocket Server Transport Lacks Host/Origin Validation (CVE-2026-59950)
A vulnerability in the deprecated WebSocket server transport of the MCP Python SDK allows unauthenticated attackers to connect and issue JSON-RPC requests. Affected servers are those that expose `mcp.server.websocket.websocket_server` and lack proper authentication or origin validation. The vulnerability has a CVSS score of 7.6.
Critical Remote Code Execution Vulnerability in Metabase
A critical vulnerability (CVE-2026-50148) with a CVSS score of 10 has been discovered in Metabase, an open-source business intelligence tool. This vulnerability allows a Metabase user with permission to add or edit a database connection to achieve remote code execution on the Metabase server. All users of affected Metabase versions must update to patched versions immediately.
CVE-2026-61436: PraisonAI Webhook Signature Verification Bypass
A vulnerability in PraisonAI before version 4.6.78 allows unauthenticated attackers to forge message.received events by sending crafted JSON payloads to the webhook endpoint, potentially invoking configured agents with arbitrary sender addresses and message content. This vulnerability has a CVSS score of 8.6 and is classified as HIGH severity.
nebula-mesh: CA Private Key Exposure via Unzeroized Memory
A vulnerability in nebula-mesh (CVE-2026-53604, CVSS 8.7) exposes the CA private key in memory due to improper zeroization on error paths in the web UI's mobile-bundle handling. This allows an attacker with process memory access to recover the key and mint arbitrary host certificates. Affected versions are <= 0.3.7; patch to version 0.3.8 or later.
Critical Vulnerability in Siemens Opcenter X Allows Arbitrary JWT Forging
A critical vulnerability (CVE-2026-56451) with a CVSS score of 10 has been identified in Siemens Opcenter X versions prior to V2604. This vulnerability allows an unauthenticated remote attacker to forge arbitrary JSON Web Tokens (JWT), bypass authentication mechanisms, and impersonate any user, including administrative accounts. Immediate action is required to update affected systems.
Integer Overflow Vulnerability in WinFsp (CVE-2026-7162)
A high-severity integer overflow vulnerability (CVE-2026-7162) has been discovered in WinFsp, a software package. Successful exploitation could allow an attacker to achieve system-level access. Affected versions include WinFsp 2.2.26112 and lower.
CVE-2026-15506: SecureAge CatchPulse Heap-Based Buffer Overflow Vulnerability
A heap-based buffer overflow vulnerability has been detected in SecureAge CatchPulse up to version 10.9.3. The vulnerability is located in the library saappctl.sys of the Driver component and requires local access to be exploited. A CVSS score of 7.8 indicates a high severity level.
CVE-2026-61875: Stored Cross-Site Scripting in luci-app-upnp via UPnP IGD AddPortMapping SOAP Requests
A stored cross-site scripting vulnerability exists in luci-app-upnp, allowing unauthenticated LAN clients to inject JavaScript via UPnP IGD AddPortMapping SOAP requests. This vulnerability has a CVSS score of 8.8 and is considered high severity. Affected users should update luci-app-upnp to the latest version.
CVE-2026-15155: Authenticated Account Takeover via Email Header Injection in Essential Addons for Elementor
The Essential Addons for Elementor plugin for WordPress is vulnerable to authenticated account takeover via email header injection. An attacker with Contributor-level access can inject a Bcc header into the administrator's password-reset notification email, potentially leading to full administrator account takeover. The vulnerability has a CVSS score of 8.8 and affects all versions up to 6.6.10.
Critical Path Traversal Vulnerability in JetBrains IntelliJ IDEA
A critical vulnerability (CVE-2026-59792) with a CVSS score of 9.6 was discovered in JetBrains IntelliJ IDEA, allowing for code execution via path traversal in project workspace ID handling. Users of IntelliJ IDEA versions before 2026.1.4 and 2026.2 are affected. Immediate action is required to update to a patched version.
CVE-2026-15293: WP Business Intelligence Lite Plugin Vulnerability
The WP Business Intelligence Lite plugin for WordPress is vulnerable to authorization bypass, allowing authenticated attackers with Subscriber-level access to modify stored SQL queries, potentially leading to privilege escalation. This affects all versions up to and including 3.2.0, with a CVSS score of 8.
Mistune Vulnerability: Potential DoS via Quadratic-Time Parsing in parse_link_text
Mistune is vulnerable to a CPU exhaustion DoS due to superlinear (approximately O(n²)) behavior in parse_link_text. An attacker-controlled Markdown input can trigger excessive CPU usage with a very small payload. Affected applications include web applications, API services, and documentation rendering systems.