THREAT OPS › Threat News
Threat Intelligence News
11791 reports from 110+ open cyber-threat-intelligence sources — APT activity, malware, vulnerabilities and campaigns, newest first.
- [NVD] CVE-2026-60841 (HIGH 8.5) — Vulnerability in the Oracle Unified Directory product of Oracle Fusion Middleware (component: OUD Core). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Difficult to exploit vulnerability allows low privileged attacker with network access via LDAP to compromnvd · 2026-08-18
- [NVD] CVE-2026-60830 (MEDIUM 6.5) — Vulnerability in the Oracle Workflow product of Oracle E-Business Suite (component: Worklist). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Workflow. Sunvd · 2026-08-18
- [NVD] CVE-2026-60822 (HIGH 7.8) — Vulnerability in the Oracle Enterprise Manager for Systems Infrastructure product of Oracle Enterprise Manager (component: Agent). Supported versions that are affected are 13.5 and 24.1. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastrunvd · 2026-08-18
- [NVD] CVE-2026-60808 (HIGH 7.5) — Vulnerability in the Siebel Apps - Marketing product of Oracle Siebel CRM (component: Email Marketing). Supported versions that are affected are 17.0-26.6. Difficult to exploit vulnerability allows low privileged attacker with logon to the infrastructure where Siebel Apps - Marknvd · 2026-08-18
- [NVD] CVE-2026-60803 (HIGH 7.4) — Vulnerability in the Siebel Apps - Marketing product of Oracle Siebel CRM (component: Marketing). Supported versions that are affected are 17.0-26.6. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Siebel Apps - Markenvd · 2026-08-18
- [NVD] CVE-2026-60769 (HIGH 7.5) — Vulnerability in the Oracle General Ledger product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Onvd · 2026-08-18
- [NVD] CVE-2026-60753 (HIGH 7.8) — Vulnerability in the Siebel CRM Deployment product of Oracle Siebel CRM (component: Installation). Supported versions that are affected are 17.0-26.6. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Siebel CRM Deployment exenvd · 2026-08-18
- [NVD] CVE-2026-60720 (CRITICAL 9.9) — Vulnerability in the Oracle Identity Manager product of Oracle Fusion Middleware (component: OIM Legacy UI). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to comprnvd · 2026-08-18
- [NVD] CVE-2026-60707 (HIGH 8.7) — Vulnerability in the Oracle Identity Manager product of Oracle Fusion Middleware (component: Security). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromisnvd · 2026-08-18
- [NVD] CVE-2026-60682 (MEDIUM 6.5) — Vulnerability in the Oracle Hyperion Financial Reporting product of Oracle Hyperion (component: Repository). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracnvd · 2026-08-18
- [NVD] CVE-2026-60414 (HIGH 7.8) — Vulnerability in the Oracle Outside In Technology product of Oracle Fusion Middleware (component: Outside In Core). The supported version that is affected is 8.5.8. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle Ounvd · 2026-08-18
- [NVD] CVE-2026-60413 (HIGH 7.8) — Vulnerability in the Oracle Outside In Technology product of Oracle Fusion Middleware (component: Outside In Core). The supported version that is affected is 8.5.8. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle Ounvd · 2026-08-18
- [NVD] CVE-2026-60412 (HIGH 7.8) — Vulnerability in the Oracle Outside In Technology product of Oracle Fusion Middleware (component: Outside In Core). The supported version that is affected is 8.5.8. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle Ounvd · 2026-08-18
- [NVD] CVE-2026-60392 (HIGH 7.8) — Vulnerability in the Oracle Outside In Technology product of Oracle Fusion Middleware (component: Outside In PDF Export SDK). The supported version that is affected is 8.5.8. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure wherenvd · 2026-08-18
- [NVD] CVE-2026-53759 — linuxfabrik-lib provides Python modules for database access, caching, shell execution, and API integrations. Prior to version 4.2.0, db_sqlite.py created SQLite databases at predictable paths in the shared /tmp directory and followed attacker-created symbolic links at those pathsnvd · 2026-08-18
- [NVD] CVE-2026-53454 — Blueprint Studio is a VS Code-like file editor for Home Assistant configuration files. Prior to 2.5.2, Blueprint Studio configured Git's credential.helper store when saving Git credentials, causing Git credential-store to persist usernames and access tokens in plaintext in the .gnvd · 2026-08-18
- [NVD] CVE-2026-41921 (MEDIUM 5.4) — Koha before 26.05.02, 25.11.07, and 25.05.13 contains a stored cross-site scripting vulnerability in the purchase suggestion handler that allows authenticated staff users to inject malicious scripts by submitting unsanitized input through the suggestion save operation. Attackers nvd · 2026-08-18
- [GHSA] GHSA-pxmc-2ffp-8j67 (high) — Lemur: Any user can revoke arbitrary certificates at the CA by uploading a duplicate record and revoking itgithub_advisories · 2026-08-18
- [GHSA] GHSA-4h97-p9wq-chqj (medium) — Lemur: Missing authorization check on POST /certificates/<id>/export for plugins with requires_key = Falsegithub_advisories · 2026-08-18
- [GHSA] GHSA-g7p5-89mh-248h (medium) — Lemur: Sub-CA creation never checks `AuthorityPermission` on the parent authoritygithub_advisories · 2026-08-18
- [GHSA] GHSA-cfh6-pv5c-38jv (high) — Lemur: Unchecked `replaces[]` lets any user silence notifications and hijack auto-rotation for arbitrary certificatesgithub_advisories · 2026-08-18
- [GHSA] GHSA-6c8m-q6g9-vrw3 (high) — Lemur: Authenticated low-privilege users can read plaintext destination credentials (SFTP password / private-key passphrase) via the destinations APIgithub_advisories · 2026-08-18
- [GHSA] GHSA-v5rc-cpwc-cfpr (high) — Lemur: Incomplete fix for GHSA-v2wp-frmc-5q3v -- ACME authority update endpoint allows non-admin to replace `acme_url` with internal IP, bypassing allowlistgithub_advisories · 2026-08-18
- [GHSA] GHSA-f3qq-49m6-rw8f (medium) — Lemur: SSRF protection in certificate revocation checking bypassable via HTTP redirects and DNS rebinding (incomplete fix for GHSA-54vg-pfh7-jq95)github_advisories · 2026-08-18
- [GHSA] GHSA-xpmj-wjcp-6pww (high) — Lemur: Server-Side Request Forgery via the ACME client following server-controlled URLsgithub_advisories · 2026-08-18
- [GHSA] GHSA-7788-ghfq-c6mh (critical) — Froxlor: Credential and 2FA secret disclosure via Froxlor API endpointsgithub_advisories · 2026-08-18
- [GHSA] GHSA-xpr4-8vp6-c87j (medium) — Froxlor has CSRF Vulnerability in AJAX Endpoint — Missing Cross-Site Request Forgery Protectiongithub_advisories · 2026-08-18
- [GHSA] GHSA-5rw4-4665-cvwf (medium) — Froxlor DomainZones.add allows DNS zone-file RR injection via record/type fieldsgithub_advisories · 2026-08-18
- [GHSA] GHSA-w27m-rmmf-g5w4 (high) — Froxlor: Second-Order SQL Injection via `Admins.add` `ipaddress` Parameter Allows Full Database Exfiltrationgithub_advisories · 2026-08-18
- [GHSA] GHSA-43gm-9rr3-cx7g (high) — Froxlor: Stored XSS in DNS TXT Record Content Allows Customer-to-Admin Account Takeovergithub_advisories · 2026-08-18
- [GHSA] GHSA-m5pq-69xg-vcq3 (medium) — devpi-server may leak database contentsgithub_advisories · 2026-08-18
- [GHSA] GHSA-59xm-4m8c-g3xj (high) — MineAdmin Vulnerable to Path Traversal via Unsanitized identifier in Plugin Install/Uninstallgithub_advisories · 2026-08-18
- [GHSA] GHSA-wg9g-w2j2-8pgr (high) — MONAI: Unsafe deserialization in NumpyReader allows arbitrary code execution via malicious .npy filesgithub_advisories · 2026-08-18
- [GHSA] GHSA-rghg-q7wp-9767 (high) — MONAI vulnerable to OS command injectiongithub_advisories · 2026-08-18
- [GHSA] GHSA-qxq5-qhx6-94qw (high) — Incomplete Fix in MONAI: algo_from_pickle() pickle.loads() RCE still present in v1.5.2 despite GHSA-89gg-p5r5-q6r4 claiming patchgithub_advisories · 2026-08-18
- [GHSA] GHSA-vjf8-9fx6-mv6x (medium) — Triton VM Soundness Vulnerability due to Missing Constraintgithub_advisories · 2026-08-18
- [NVD] CVE-2026-73529 (MEDIUM 5.3) — Plainpad through 1.1.1, fixed in commit d3823fc, contains a missing rate limiting vulnerability that allows unauthenticated attackers to send unbounded login requests to the POST /v1/sessions endpoint due to dead code in App\Http\Kernel.php that is never instantiated under the Lanvd · 2026-08-18
- [NVD] CVE-2026-67443 — FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. In 1.3.2 and earlier, the allowDashboard authorization gate in server/integrations/node-red/index.js calls authJwt.verify for /nodered without inspecting the decoded identity. When nodeRedEnabled is true, snvd · 2026-08-18
- [NVD] CVE-2026-47719 (HIGH 8.2) — FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. Prior to 1.3.2, the DEVICE_WEBAPI_REQUEST and DEVICE_PROPERTY Socket.IO handlers in server/runtime/index.js omit isSocketWriteAuthorized and accept attacker-controlled property.address or endpoint connectionvd · 2026-08-18
- [GHSA] GHSA-pcw8-m77r-2528 (critical) — jmespath.php has CompilerRuntime code injection via unescaped function namesgithub_advisories · 2026-08-18
- [GHSA] GHSA-43hj-fxwj-49qw (medium) — membrane_mp4_plugin has an unauthenticated denial-of-service via BEAM atom table exhaustiongithub_advisories · 2026-08-18
- [GHSA] GHSA-rcr2-hggw-43wm (critical) — surfio has an out-of-bounds readgithub_advisories · 2026-08-18
- [GHSA] GHSA-pr85-w493-9w3x (critical) — resdata has Classic Buffer Overflow, Improper Validation of Array Index, NULL Pointer Dereference and Out-of-bounds Readgithub_advisories · 2026-08-18
- [GHSA] GHSA-7pwq-q9jf-539h (critical) — kobako Sandbox Escape: guest eval reaches host RCE via method_missing → public_send (any bound Service)github_advisories · 2026-08-18
- [GHSA] GHSA-c7hr-448w-65px (high) — MeshCentral has unsanitized data fieldsgithub_advisories · 2026-08-18
- [securotrop] ADL Embedded Solutions posted to leak siteransomware_live · 2026-08-18
- [SilentRansomGroup] T... P... L... posted to leak siteransomware_live · 2026-08-18
- [NVD] CVE-2026-67846 (HIGH 7.8) — Berkeley Out-of-Order Machine (BOOM) commit 5223e44cfeb26f41380057a2eb4d651197475f69 contains a potential incorrect privilege assignment issue in the v3 and v4 NBDTLB implementations. The raw mstatus.SUM value participates in the read and write permission logic without an explicinvd · 2026-08-18
- [NVD] CVE-2026-66780 (MEDIUM 6.5) — A flaw was found in the submariner-operator component. The `submariner-k8s-broker-cluster` Role, which is assigned to joined clusters, possesses excessive permissions. This allows a compromised cluster to alter network configurations, specifically by overwriting other clusters' envd · 2026-08-18
- [NVD] CVE-2026-48508 (HIGH 8.8) — Lemur manages TLS certificate creation. Prior to 1.9.1, StrictRolePermission and AuthorityCreatorPermission in lemur/auth/permissions.py call flask_principal.Permission.__init__() with zero Need objects when ADMIN_ONLY_AUTHORITY_CREATION and LEMUR_STRICT_ROLE_ENFORCEMENT are unsenvd · 2026-08-18
- [NVD] CVE-2021-43717 (CRITICAL 9.8) — An issue exists in pson EH-TW5350 Epson iProjection.apk v3.2.6. If you identify a projector equipped with an iProjection function, you can access the projector using hard-coded authentication information and control the projector maliciously.nvd · 2026-08-18
- CVE-2026-68820 is in KEV. Here Is What CISA BOD 26-04 Actually Requires Nowqualys · 2026-08-18
- More than 200 victims of Medusa ransomware identified over the last year, CISA saysthe_record · 2026-08-18
- [GHSA] GHSA-8j49-mmcx-4mp5 (medium) — MobSF Vulnerable to Arbitrary File Read via Path Traversal in ZIP Uploadsgithub_advisories · 2026-08-18
- [GHSA] GHSA-3p54-567p-2wpr (medium) — MobSF's CSRF checks not enforced after Django migrationgithub_advisories · 2026-08-18
- [GHSA] GHSA-95px-34x5-p37h (low) — MobSF has SSRF port restriction bypass in assetlinks_checkgithub_advisories · 2026-08-18
- [GHSA] GHSA-x768-8642-mmq9 (medium) — MobSF Vulnerable to Zip Bomb Denial of Service via Per-File Size Limit Bypass in ZIP/APK Extractiongithub_advisories · 2026-08-18
- [GHSA] GHSA-q4gh-4ffp-5cg8 (medium) — MagicMirror socket payload secret placeholder expansion can disclose SECRET_* environment variablesgithub_advisories · 2026-08-18
- [GHSA] GHSA-p23g-mvhj-jh3j (high) — GeoLens: Cross-dataset authorization bypass discloses private dataset metadata, schema, sample values, table rows, and raster/vector tile datagithub_advisories · 2026-08-18
- [GHSA] GHSA-c9fv-cgmm-2wg7 (high) — LibreNMS Vulnerable to Remote Code Execution by Signal Alert Transportation modulegithub_advisories · 2026-08-18
- [dragonforce] R & D Machine and Engineering posted to leak siteransomware_live · 2026-08-18
- Microsoft Copilot Personal Flaws Could Let One Click Exfiltrate Data From Connected Appsthehackernews · 2026-08-18
- Attackers Exploit MLflow SSRF Flaw to Steal Cloud Credentials and Secretsthehackernews · 2026-08-18
- [play] Coltrane Systems posted to leak siteransomware_live · 2026-08-18
- [GHSA] GHSA-w6x9-28jw-hq7j (medium) — MagicMirror: ssrf calendar .jsgithub_advisories · 2026-08-18
- [GHSA] GHSA-998g-7v5w-cr7g (medium) — MagicMirror newsfeed Socket.IO notification allows blind server-side request forgerygithub_advisories · 2026-08-18
- [GHSA] GHSA-w26r-fwg8-rcp3 (low) — MagicMirror Socket.IO module namespaces bypass configured IP whitelist and allow unauthenticated server-side actionsgithub_advisories · 2026-08-18
- [NVD] CVE-2026-70415 (HIGH 8.1) — Dell PowerStore SDNAS contains a Buffer Copy without Checking Size of Input vulnerability in NFS/RPC. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to command execution and denial of service.nvd · 2026-08-18
- [NVD] CVE-2026-67271 (CRITICAL 9.8) — Dell PowerStore SDNAS, contains an Out-of-bounds Write vulnerability in SMB/CIFS. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to denial of service and remote execution. This is a Critical vulnerability as a remote user coulnvd · 2026-08-18
- What’s in the SOSS? Podcast #69 – S3E21 Watering the Community Garden: Navigating the EU CRA for Open Source with Roman Zhukovopenssf_blog · 2026-08-18
- Hunting MacSync Stealer infrastructure through behavioral pivotsmsstic · 2026-08-18
- Ransom Busters Claims It Hacked Ransomware Servers, Asks Victims for Up to $60,000thehackernews · 2026-08-18
- [GHSA] GHSA-5xwg-cfvj-gff5 (low) — RabbitMQ Java client accepts broker frames larger than the negotiated AMQP frame_maxgithub_advisories · 2026-08-18
- [GHSA] GHSA-5m9f-rphj-c435 (medium) — RabbitMQ Java client: TrustEverythingTrustManager used by default in useSslProtocol() enables MITMgithub_advisories · 2026-08-18
- [GHSA] GHSA-qx7j-jv8m-fppr (medium) — RabbitMQ Java client malformed body frame triggers raw command assembler exceptiongithub_advisories · 2026-08-18
- [GHSA] GHSA-6g32-pxv4-2wfj (high) — RabbitMQ Java client: Unvalidated Class.forName in JSON-RPC ProcedureDescription enables arbitrary class loadinggithub_advisories · 2026-08-18
- [GHSA] GHSA-68mj-5wr7-6fgg (high) — RabbitMQ Java client ValueReader: Oversized LongString/bytes length triggers OOM via unchecked allocationgithub_advisories · 2026-08-18
- [GHSA] GHSA-93j5-89vc-pph4 (high) — RabbitMQ Java client ValueReader: Unbounded recursive table/array nesting causes StackOverflowError DoSgithub_advisories · 2026-08-18
- [GHSA] GHSA-8rc5-4fr6-64pw (medium) — Trivy Plugin Manager has Path Traversal that Allows Arbitrary File Writegithub_advisories · 2026-08-18
- [GHSA] GHSA-34pm-923j-7wf8 (high) — Kestra vulnerable to stored XSS via custom Markdown [[link]] attribute injectiongithub_advisories · 2026-08-18
- [GHSA] GHSA-2mf3-mr2r-r4vf (high) — @rhinostone/swig: arbitrary local file read via include/extends path traversalgithub_advisories · 2026-08-18
- [NVD] CVE-2026-75485 (MEDIUM 5.5) — A flaw was found in the must-gather component of Red Hat Advanced Cluster Management for Kubernetes. The cluster Proxy object is dumped in raw form, bypassing the oc inspect redaction that would normally sanitize sensitive fields. This exposes proxy basic-auth credentials in the nvd · 2026-08-18
- [NVD] CVE-2026-73834 (MEDIUM 5.5) — A flaw was found in the must-gather component of Red Hat Advanced Cluster Management for Kubernetes. Certain ACM wrapper Custom Resources that embed Secret data are collected without redaction. When an administrator runs must-gather, credentials and tokens are captured in cleartenvd · 2026-08-18
- [NVD] CVE-2026-55839 (HIGH 8.7) — Kestra is an open-source, event-driven orchestration platform. Prior to 1.3.24, Kestra's custom Markdown parser in ui/src/utils/markdown_plugins/link.ts allows a user with permission to create or update a Flow description to inject JavaScript event-handler attributes through the nvd · 2026-08-18
- CPython [CVE-2026-15806] urllib.request.HTTPPasswordMgr credentials for one URL scheme sent over another schemeoss_sec · 2026-08-18
- [NVD] CVE-2026-19501 (HIGH 8.8) — CSV export functionality in Brainstorm Force SureForms version, <= 2.12.1, fails to neutralize spreadsheet formula characters in user-controlled form field names before generating CSV exports, which allows a remote attacker to execute spreadsheet formulas on an administrator's wonvd · 2026-08-18
- [NVD] CVE-2026-12564 (CRITICAL 9.6) — A flaw was found in the AAP Controller's HashiCorp Vault credential plugin. The kubernetes_auth() function in awx_plugins/credentials/hashivault.py reads the controller pod's Kubernetes service account token and sends it to an attacker-controlled URL when a HashiCorp Vault Secretnvd · 2026-08-18
- CPython [CVE-2026-17084] StringPrep algorithm considered Unicode codepoint attributes outside Unicode 3.2.0oss_sec · 2026-08-18
- [Security Blog] Why Post-Quantum Cryptography Matters: Preparing Today for Tomorrow’s Security Challengeshkcert · 2026-08-18
- [NVD] CVE-2026-75898 (HIGH 8.5) — RAGFlow before 0.26.3 contains a server-side request forgery vulnerability in the agent workflow "Invoke" component (agent/component/invoke.py). The component builds an outbound request URL from canvas configuration and runtime template variables and passes it to requests.get, renvd · 2026-08-18
- [NVD] CVE-2026-69189 (HIGH 7.6) — Hoppscotch is an open source API development ecosystem. Prior to 2026.6.0, the team, teamMembers.user, RESTHistory, GQLHistory, currentRESTSession, currentGQLSession, environments, globalEnvironments, and settings GraphQL paths expose another workspace member's private User data,nvd · 2026-08-18
- [NVD] CVE-2026-59825 (HIGH 7.4) — Mastodon is a free, open-source social network server based on ActivityPub. Prior to 4.4.19 and from 4.5.0 until 4.5.12, Mastodon's app/models/concerns/user/ldap_authenticable.rb mutates OpenSSL::SSL::SSLContext::DEFAULT_PARAMS when LDAP authentication uses LDAP_TLS_NO_VERIFY=trunvd · 2026-08-18
- [GHSA] GHSA-x5pq-m9p8-f4vx (medium) — Copyparty vulnerable to file/dirkey confusiongithub_advisories · 2026-08-18
- Apple fixes another image-processing flaw that could allow code executionmalwarebytes_blog · 2026-08-18
- [akira] Borchert & LaSpina posted to leak siteransomware_live · 2026-08-18
- Mattermost security advisory (AV26-828)cccs_ca · 2026-08-18
- GitLab security advisory (AV26-827)cccs_ca · 2026-08-18
- Staying Ahead of Adversarial AI Through Agentic Source Code Reviewmandiant_gti · 2026-08-18
- MLflow Bug Actively Exploited to Steal Credentialsduo_decipher · 2026-08-18
- BeyondTrust security advisory (AV26-826)cccs_ca · 2026-08-18