THREAT OPS › Threat News
Threat Intelligence News
11830 reports from 110+ open cyber-threat-intelligence sources — APT activity, malware, vulnerabilities and campaigns, newest first.
- [direwolf] DXS International posted to leak siteransomware_live · 2026-08-15
- [NVD] CVE-2026-19906 (LOW 3.7) — A weakness has been identified in pkp pkp-lib 3.3.0/3.4.0/3.5.0. This vulnerability affects the function setData of the file classes/user/form/APIProfileForm.php of the component API Key Generation. Executing a manipulation of the argument apiKey can lead to insufficient entropy.nvd · 2026-08-15
- [NVD] CVE-2026-19905 (HIGH 7.3) — A weakness has been identified in Jinher OA 1.0. Impacted is an unknown function of the file /C6/JHSoft.Web.HrmAttendance/attendance_out_approve.aspx. This manipulation of the argument httpOID causes sql injection. It is possible to initiate the attack remotely. The exploit has bnvd · 2026-08-15
- [NVD] CVE-2026-18855 (CRITICAL 9.1) — The Link Library plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the ll_delete_link_fields function in all versions up to, and including, 7.9.4 This makes it possible for unauthenticated attackers to delete arbitrary filesnvd · 2026-08-15
- [ms13089] servmarmg.cl posted to leak siteransomware_live · 2026-08-15
- [NVD] CVE-2026-19904 (LOW 2.4) — A vulnerability was found in SourceCodester Online Book Store System 1.0. This vulnerability affects unknown code of the file /admin/index.php?page=site_settings of the component System Settings Module. The manipulation results in cross site scripting. The attack can be executed nvd · 2026-08-15
- [NVD] CVE-2026-19903 (MEDIUM 5.3) — A vulnerability has been found in SourceCodester Online Clothing Store 1.0. This affects an unknown part of the file /db/shopping.sql of the component SQL Database Backup. The manipulation leads to files or directories accessible. Remote exploitation of the attack is possible. Thnvd · 2026-08-15
- [NVD] CVE-2026-19901 (HIGH 8.1) — A security flaw has been discovered in LB-LINK X-PRO 1.0.22-20231206. This affects an unknown function of the file /etc/config/easycwmp. The manipulation results in hard-coded credentials. It is possible to launch the attack remotely. Attacks of this nature are highly complex. Thnvd · 2026-08-15
- [NVD] CVE-2026-19598 (CRITICAL 9.8) — The Pods – Custom Content Types and Fields plugin for WordPress is vulnerable to Privilege Escalation via Authorization Bypass in all versions up to, and including, 3.3.9. The vulnerability exists because the pods_admin AJAX router funnels every access check — including the methonvd · 2026-08-15
- [NVD] CVE-2026-19900 (HIGH 8.1) — A vulnerability was identified in LB-LINK X-PRO 1.0.22-20231206. The impacted element is an unknown function of the file /etc/shadow. The manipulation leads to hard-coded credentials. It is possible to initiate the attack remotely. A high degree of complexity is needed for the atnvd · 2026-08-15
- [NVD] CVE-2026-19899 (HIGH 7.3) — A vulnerability was determined in SourceCodester Class and Exam Timetabling System 1.0. The affected element is an unknown function of the file /edit_teacher.php. Executing a manipulation of the argument ID can lead to sql injection. The attack may be performed from remote. The envd · 2026-08-15
- [NVD] CVE-2026-19898 (LOW 3.7) — A vulnerability was found in VictoriaMetrics up to 1.146.0. Impacted is the function requestHandler of the file app/vmauth/main.go of the component VMAuth Authentication Endpoint. Performing a manipulation results in improper restriction of excessive authentication attempts. The nvd · 2026-08-15
- [NVD] CVE-2026-19897 (LOW 3.7) — A vulnerability has been found in mangroup dtale up to 3.22.0. This issue affects the function Login of the file dtale/auth.py of the component Login Endpoint. Such manipulation leads to improper restriction of excessive authentication attempts. The attack can be executed remotelnvd · 2026-08-15
- [spacebears] SEARS (Grupo Sanborns) posted to leak siteransomware_live · 2026-08-15
- [NVD] CVE-2026-19896 (LOW 3.7) — A flaw has been found in mangroup dtale up to 3.22.0. This vulnerability affects the function build_secret_key of the file dtale/app.py of the component Flask Session Cookie. This manipulation causes insufficiently random values. Remote exploitation of the attack is possible. Thenvd · 2026-08-15
- [securotrop] Lepi Enterprises posted to leak siteransomware_live · 2026-08-15
- [NVD] CVE-2026-19895 (LOW 3.7) — A vulnerability was detected in opensourcepos Open Source Point of Sale up to 3.4.2. This affects the function Login::index of the file app/Config/Filters.php of the component Login Endpoint. The manipulation results in improper restriction of excessive authentication attempts. Tnvd · 2026-08-15
- [NVD] CVE-2026-19474 (HIGH 7.5) — @fastify/multipart is a multipart form-data parser for Fastify. In versions from 3.0.0 up to but not including 10.1.1, request.saveRequestFiles() can leave completed temporary files on disk when a client disconnects while the parser is advancing between multipart parts. The iteranvd · 2026-08-15
- [NVD] CVE-2026-18549 (HIGH 7.5) — @fastify/multipart is a multipart form-data parser for Fastify. In versions from 5.3.0 up to but not including 10.1.1, when the busboy fileSize limit truncates a file part, the plugin clears its internal current-file reference while the underlying stream is still open. If the clinvd · 2026-08-15
- [NVD] CVE-2026-18500 (HIGH 8.1) — @fastify/jwt is a JSON Web Token plugin for Fastify. In versions before 10.2.2, a per-request verification key passed to request.jwtVerify({ key }) is silently overridden by the plugin's globally configured secret, because the option merge applies the global key last. Applicationnvd · 2026-08-15
- [NVD] CVE-2026-18165 (MEDIUM 4.2) — @fastify/oauth2 is an OAuth 2.0 plugin for Fastify. In versions from 7.2.0 up to but not including 8.3.0, the plugin validates the OAuth state, and with PKCE the code verifier, by comparing the callback query parameter against an unprefixed, predictable cookie, with no server-sidnvd · 2026-08-15
- [NVD] CVE-2026-15689 — Dancer2::Plugin::Auth::Extensible versions through 0.713 for Perl allow password reset link poisoning via the request Host header in _default_email_password_reset and _default_welcome_send. Both default emails emit a link of the form `$base/login/$code`, whose authority comes frnvd · 2026-08-15
- CVE-2026-73194: DBI versions before 1.652 for Perl allow a heap out-of-bounds write via an unvalidated numeric placeholder that sets the binder counter in preparseoss_sec · 2026-08-15
- [NVD] CVE-2026-74474 (CRITICAL 9.8) — In the Linux kernel, the following vulnerability has been resolved: vxlan: use pskb_network_may_pull() for transmit path header pulls In vxlan_xmit(), arp_reduce(), and vxlan_mdb_entry_skb_get(), pskb_may_pull() was being called to verify the availability of network layer headenvd · 2026-08-15
- CVE-2026-73193: DBI versions before 1.652 for Perl allow a heap out-of-bounds write on 32-bit perl via an integer wraparound in the output buffer size computed by preparseoss_sec · 2026-08-15
- [Barracuda] VR Advogados posted to leak siteransomware_live · 2026-08-15
- [blackwater] www.amca.org.ar posted to leak siteransomware_live · 2026-08-15
- [blackwater] www.shalina.com posted to leak siteransomware_live · 2026-08-15
- Apple macOS Screen Sharing Flaw Exploited on Internet-Exposed Macs to Install Monero Minerthehackernews · 2026-08-15
- [NVD] CVE-2026-74407 (HIGH 8.8) — In the Linux kernel, the following vulnerability has been resolved: wifi: ath11k: cancel SSR work items during PCI shutdown A reboot can crash the kernel if it overlaps with WLAN firmware crash recovery (SSR). The crash is a NULL pointer dereference in the MHI teardown path whinvd · 2026-08-15
- [NVD] CVE-2026-74378 (HIGH 7.8) — In the Linux kernel, the following vulnerability has been resolved: RDMA/rxe: Fix TOCTOU heap overflow in get_srq_wqe get_srq_wqe() reads wqe->dma.num_sge from the shared receive queue buffer, which is mapped into userspace. It validates num_sge against max_sge, but then re-reanvd · 2026-08-15
- [NVD] CVE-2026-74371 (HIGH 7.8) — In the Linux kernel, the following vulnerability has been resolved: bpf: fix BPF_PROG_QUERY OOB write and cgroup backward compat BPF_PROG_QUERY writes back the 'query.revision' field unconditionally to userspace. If userspace passes a smaller 'bpf_attr' structure (e.g. 40 bytesnvd · 2026-08-15
- [NVD] CVE-2026-74347 (HIGH 7.8) — In the Linux kernel, the following vulnerability has been resolved: netfilter: cttimeout: detach dataplane timeout policy and repurpose refcount Add a refcount for struct nf_ct_timeout which is used by ct extension to set the custom ct timeout policy, this tells us that the ct nvd · 2026-08-15
- [NVD] CVE-2026-74334 (HIGH 7.8) — In the Linux kernel, the following vulnerability has been resolved: RDMA/nldev: Fix locking when accessing mr->pd Sashiko points out that, due to rereg_mr, the PD is actually variable and all the touches in nldev are racy. Use mr->device instead of mr->pd->device. Getting thenvd · 2026-08-15
- [NVD] CVE-2026-74294 (HIGH 7.3) — In the Linux kernel, the following vulnerability has been resolved: ASoC: meson: aiu: Validate written enum values The AIU HDMI and internal codec mux put callbacks use the written enum value with snd_soc_enum_item_to_val() before checking whether the value is valid for the enunvd · 2026-08-15
- [NVD] CVE-2026-74291 — In the Linux kernel, the following vulnerability has been resolved: ASoC: topology: Check PCM and DAI name strings before use Topology objects store several PCM and DAI names in fixed-size UAPI arrays. Other topology parser paths validate these fields with bounded strnlen() chenvd · 2026-08-15
- [NVD] CVE-2026-74289 (HIGH 7.8) — In the Linux kernel, the following vulnerability has been resolved: ipv4: fib: Don't dump dying fib_info in fib_leaf_notify(). syzbot reported use-after-free in nsim_fib4_prepare_event(). [0] The problem is that the following functions call fib_info_hold() / refcount_inc() whinvd · 2026-08-15
- [NVD] CVE-2026-74269 (CRITICAL 9.8) — In the Linux kernel, the following vulnerability has been resolved: bnxt: fix head underflow on XDP head-grow The xdp.py test test_xdp_native_adjst_head_grow_data crashes when run on a bnxt machine (and also crashes in NIPA). It seems that the bug is an underflow in bnxt_rx_munvd · 2026-08-15
- [NVD] CVE-2026-74268 (CRITICAL 9.8) — In the Linux kernel, the following vulnerability has been resolved: tcp: clear sock_ops cb flags before force-closing a child socket A child socket inherits the listener's bpf_sock_ops_cb_flags via sk_clone_lock(). If its setup fails in tcp_v4_syn_recv_sock() / tcp_v6_syn_recv_nvd · 2026-08-15
- [NVD] CVE-2026-74258 (HIGH 7.8) — In the Linux kernel, the following vulnerability has been resolved: bpf: Guard __get_user acesss with access_ok for uprobe_multi data As reported by sashiko [1] we need to use access_ok to check the user space data bounds before we use __get-user to get it. [1] https://lore.kenvd · 2026-08-15
- [NVD] CVE-2026-72496 (CRITICAL 9.2) — In the Linux kernel, the following vulnerability has been resolved: RDMA/bnxt_re: Proper rollback if the ioremap fails bnxt_qplib_alloc_dpi returns success even if ioremap fails. Add the proper rollback when the ioremap fails and return -ENOMEM status.nvd · 2026-08-15
- [NVD] CVE-2026-72494 (CRITICAL 9.8) — In the Linux kernel, the following vulnerability has been resolved: RDMA/irdma: Replace waitqueue and flag with completion The driver previously used a waitqueue along with an explicit request_done flag, but without proper barriers around request_done. An earlier patch by Gui-nvd · 2026-08-15
- [NVD] CVE-2026-72485 (HIGH 7.8) — In the Linux kernel, the following vulnerability has been resolved: coresight: platform: defer connection counter increment until alloc succeeds coresight_add_out_conn() increments nr_outconns before calling devm_krealloc_array() and again before devm_kmalloc(). If either allocnvd · 2026-08-15
- [NVD] CVE-2026-72438 (HIGH 7.5) — In the Linux kernel, the following vulnerability has been resolved: md/raid10: fix writes_pending and barrier reference leaks on discard failures raid10_make_request() acquires a writes_pending reference with md_write_start() before calling raid10_handle_discard(). Several failnvd · 2026-08-15
- [NVD] CVE-2026-72413 — In the Linux kernel, the following vulnerability has been resolved: sctp: fix err_chunk memory leaks in INIT handling When sctp_verify_init() encounters unrecognized parameters, it allocates an err_chunk to report them. However, this chunk is leaked in several code paths: 1. Invd · 2026-08-15
- [NVD] CVE-2026-72402 — In the Linux kernel, the following vulnerability has been resolved: bpf: Mask pseudo pointer values in verifier logs print_bpf_insn() masks ldimm64 immediates for pointer-bearing pseudo sources when pointer leaks are not allowed, but the mask only covers BPF_PSEUDO_MAP_FD and Bnvd · 2026-08-15
- [NVD] CVE-2026-72355 (CRITICAL 9.8) — In the Linux kernel, the following vulnerability has been resolved: netfs: Fix barriering when walking subrequest list Fix the barriering used when walking the subrequest list in retry as there's a possibility of seeing a subreq that's just been added by the application thread.nvd · 2026-08-15
- [NVD] CVE-2026-72334 (HIGH 8.8) — In the Linux kernel, the following vulnerability has been resolved: Bluetooth: ISO: fix malformed ISO_END/CONT handling Core specification (Part C vol 4 sec 5.4.5) does not exclude empty ISO_CONT, ISO_END packets. We currently reject them if they are last. If controller sendsnvd · 2026-08-15
- [NVD] CVE-2026-72255 (HIGH 7.8) — In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_queue: pin bridge device while NFQUEUE holds fake dst The br_netfilter fake rtable is embedded in struct net_bridge and is attached to bridged packets with skb_dst_set_noref(). If such a packet isnvd · 2026-08-15
- [NVD] CVE-2026-72131 — In the Linux kernel, the following vulnerability has been resolved: nvme-apple: Prevent shared tags across queues on Apple A11 On Apple A11, tags of pending commands must be unique across the admin and IO queues, else the firmware crashes with "duplicate tag error for tag N", wnvd · 2026-08-15
- [anubis] Interim HealthCare posted to leak siteransomware_live · 2026-08-15
- The Agentic AI threat cluster: Seven incidents, three actors, and what they mean for your exposuretenable · 2026-08-15
- The Illusion of a Lock – How AI is changing the speed and scale of hands-on WordPress vulnerability research.sucuri_blog · 2026-08-15
- [Panzer] Alpine Electronics Europe posted to leak siteransomware_live · 2026-08-15
- [Breach] Oz Hair and Beauty — 1,988,331 accounts exposedhibp_breaches · 2026-08-15
- [GHSA] GHSA-9q54-f358-3fqf (medium) — s2n-quic has excessive memory allocationgithub_advisories · 2026-08-14
- [GHSA] GHSA-76pc-mqxp-3rq5 (medium) — Token Optimizer MCP: Unauthenticated Path Traversal in Dashboard Session Log API Endpointsgithub_advisories · 2026-08-14
- [GHSA] GHSA-49mq-fc6q-3h46 (high) — Token Optimizer MCP: OS command injection in smart_user via username in get-user-infogithub_advisories · 2026-08-14
- Metasploit Wrap Up: Lot of summer shells and fit http profilesrapid7 · 2026-08-14
- Friday Squid Blogging: Searching for the Colossal Squidschneier · 2026-08-14
- CVE Request: BlueZ AVRCP Out-of-Bounds Read (CWE-125)oss_sec · 2026-08-14
- [qilin] FERRARI MANGIMI SRL posted to leak siteransomware_live · 2026-08-14
- [GHSA] GHSA-9hgc-g3w5-67cm (medium) — ContextForge: DNS TOCTOU race condition causes SSRF protection bypass (`/admin/gateways/test`)github_advisories · 2026-08-14
- [GHSA] GHSA-8rw6-p7m8-63jp (medium) — SurrealDB: Array element-level (field.*) SELECT permissions leak denied elements to record usersgithub_advisories · 2026-08-14
- [GHSA] GHSA-h84g-69h7-mw6v (high) — mchange-commons-java contains elements susceptible to abuse via JNDI injection and "deserialization gadgets"github_advisories · 2026-08-14
- [GHSA] GHSA-fpmh-vx4h-xc33 (high) — OpenAM Insecure SSO Cookie Initializationgithub_advisories · 2026-08-14
- [GHSA] GHSA-xghw-p77p-3r7x (medium) — Fabric CA Developer's Guide: LDAP Injection via Unescaped Username in GetUser Filtergithub_advisories · 2026-08-14
- [GHSA] GHSA-2j9v-p4xj-cjw2 (high) — Lima: An arbitrary user in a QEMU VM could gain the root privilege in the VM via the guest agent socketgithub_advisories · 2026-08-14
- [GHSA] GHSA-4x9g-vw65-vvf9 (high) — Grav: Unauthenticated denial of service via unbounded image derivative dimensionsgithub_advisories · 2026-08-14
- [GHSA] GHSA-5fpj-28rv-84r7 (high) — Budibase: SSRF in Automation Steps - Webhook, Zapier, N8N, Slack, Discord Bypass IP Blacklistgithub_advisories · 2026-08-14
- [NVD] CVE-2026-50029 (MEDIUM 5.3) — js-toml is a TOML parser for JavaScript, Prior to version 1.1.2, the interpreter checks whether a key already exists in a parser-built container with `if (object[key])` instead of `if (key in object)`. When the prior value is a falsy primitive — `false`, `0`, `0n`, `0.0`, `-0`, onvd · 2026-08-14
- [NVD] CVE-2026-50027 (CRITICAL 9.8) — mcp-memory-service is a semantic memory layer for AI applications. Prior to 10.67.1, all HTTP routes under /api/documents/* in mcp-memory-service are served without any authentication dependency, even when the server is configured with an API key (MCP_API_KEY) or OAuth. An unauthnvd · 2026-08-14
- [NVD] CVE-2026-49457 (CRITICAL 9.1) — erlang_quic is a pure Erlang QUIC implementation. Prior to version 1.4.4, the QUIC client did not authenticate the server during the TLS 1.3 handshake. The CertificateVerify signature was not checked, the certificate chain was not validated, and the hostname was not compared againvd · 2026-08-14
- [NVD] CVE-2026-45699 (HIGH 7.5) — Netatalk is a Free and Open Source file server suite for Unix-like operating systems. In versions 3.1.19 through 4.4.2, a stack-based buffer overflow exists in the copydir() function of Netatalk's afpd daemon due to an integer underflow in the calculation of the remaining buffernvd · 2026-08-14
- Hackers Spend Nearly $7 Million on Expired Domains to Redirect Traffic to Scams and Malwarethehackernews · 2026-08-14
- 40,000 WordPress Sites affected by Authentication Bypass Vulnerability in User Profile Builder WordPress Pluginwordfence · 2026-08-14
- [NVD] CVE-2026-73849 (CRITICAL 9.8) — Emlog is an open source website building system. In 2.6.26 and earlier, install.php accepts action=reinstall without authentication and deliberately skips the already-installed check because the guard runs only when $act != 'reinstall'. A remote attacker can submit hostname, dbusnvd · 2026-08-14
- [NVD] CVE-2026-73847 (MEDIUM 6.8) — Emlog is an open source website building system. In 2.6.26 and earlier, missing CSRF protection on the AI Assistant execute_tool action in admin/ai.php lets a remote unauthenticated attacker submit a forged cross-site request from an attacker-controlled page to a recently logged-nvd · 2026-08-14
- [NVD] CVE-2026-48528 (CRITICAL 9.8) — Metacat is data repository software that helps researchers preserve, share, and discover data. Metacat versions 2.0.0 through 3.4.0 contain an unauthenticated SQL injection vulnerability in the `/cn/v1/object` and `/cn/v2/object` REST API endpoints due to unsanitized user input tnvd · 2026-08-14
- SOC Automation: AI-Driven Tools and Best Practicesorca_security · 2026-08-14
- Agentic AI Security: Risks, Controls & Frameworkorca_security · 2026-08-14
- AI Agents Security: Risks and Protection Strategiesorca_security · 2026-08-14
- [safepay] granjarinya.com posted to leak siteransomware_live · 2026-08-14
- [NVD] CVE-2026-73846 (MEDIUM 6.5) — CKAN MCP Server is a tool for querying CKAN open data portals. Prior to 0.4.112, canonicalizeParams in src/utils/cache.ts serializes request parameters with unescaped ampersand, equals-sign, and vertical-bar delimiters, allowing different logical parameter sets used by buildCachenvd · 2026-08-14
- [NVD] CVE-2026-73845 (MEDIUM 5.3) — CKAN MCP Server is a tool for querying CKAN open data portals. Prior to 0.4.112, the ckan_get_mqa_quality and ckan_get_mqa_quality_details tools in src/tools/quality.ts use isValidMqaServer to validate the server_url parameter with a prefix-only regular expression for dati.gov.itnvd · 2026-08-14
- [NVD] CVE-2026-73844 (LOW 3.7) — CKAN MCP Server is a tool for querying CKAN open data portals. Prior to 0.4.112, error paths reflect raw upstream response bodies and internal exception messages back to the caller instead of a sanitized, generic message. When the server is pointed at (or redirected/SSRF'd to) a nvd · 2026-08-14
- IAM Compliance Requirements and Best Practicesthehackernews · 2026-08-14
- [NVD] CVE-2026-49989 — CrateDB is a distributed SQL database. Prior to versions 6.2.8 and 6.3.2, any authenticated user can read or delete any blob whose SHA-1 digest they know, and can plant new blobs unconditionally, in any blob table, regardless of `GRANT`s. CrateDB has two ways to access blob storanvd · 2026-08-14
- [NVD] CVE-2026-49986 — The Cortex MCP server (`neuro-cortex-memory`), a cross-platform persistent memory MCP, prior to version 3.17.1 treats the `CLAUDE_PROJECT_DIR` environment variable — automatically set by Claude Code to the currently open project directory — as a trusted Cortex developer checkout.nvd · 2026-08-14
- [NVD] CVE-2026-47766 — crun is an open source OCI Container Runtime fully written in C. Prior to version 1.28, crun's default device setup opens the container rootfs `/dev` directory without `O_NOFOLLOW`. If an OCI bundle contains `rootfs/dev` as a symlink and the bundle configuration does not mount `/nvd · 2026-08-14
- [NVD] CVE-2026-47192 — kas is a setup tool for bitbake based projects. Starting in version 4.8 and prior to version 5.3, kas checks out and processes repositories regarding configuration includes prior to validating signatures of those repositories. This may allow to replace on original repository withnvd · 2026-08-14
- [NVD] CVE-2026-47191 — kas is a setup tool for bitbake based projects. Prior to version 5.3, when relying solely on a git commit ID (SHA-1 or SHA-256) to qualify if a checkout of a repository is equivalent to the state validated while adding its commit ID to a kas configuration, users may be tricked tonvd · 2026-08-14
- [NVD] CVE-2026-46439 (HIGH 7.8) — compliance-trestle is a tooling platform for managing compliance as code. Versions prior to 3.12.2 and 4.0.3 have a Server-Side Template Injection (SSTI) vulnerability exists in the `trestle author jinja` command. The command recursively evaluates rendered templates, allowing an nvd · 2026-08-14
- [NVD] CVE-2026-46380 (MEDIUM 6.7) — compliance-trestle is a tooling platform for managing compliance as code. Prior to versions 3.12.2 and 4.0.3, the HTTPSFetcher._do_fetch() method passes a user-supplied URL directly to requests.get() without validation. This allows an attacker to perform Server-Side Request Forgenvd · 2026-08-14
- [Global Secret Group] Columbia University Information (Dental) posted to leak siteransomware_live · 2026-08-14
- FreePBX security advisory (AV26-818)cccs_ca · 2026-08-14
- Upcoming Speaking Engagementsschneier · 2026-08-14
- HashiCorp security advisory (AV26-817)cccs_ca · 2026-08-14
- [GHSA] GHSA-29rf-f4vv-pvq6 (high) — Authorizer: Zero-click account takeover via OAuth identity linking to unverified email accountsgithub_advisories · 2026-08-14
- croc: Arbitrary File Deletion via received filename, chainable to RCE (fixed in 11.0.3)oss_sec · 2026-08-14