THREAT OPS › Threat News
Threat Intelligence News
11884 reports from 110+ open cyber-threat-intelligence sources — APT activity, malware, vulnerabilities and campaigns, newest first.
- [NVD] CVE-2026-70377 (HIGH 7.5) — imagecli's pipeline operation (Scale::apply in src/image_ops.rs) computes output width/height as (dimension as f32 * ratio) as u32 with no upper-bound validation on the CLI-supplied ratio, which is parsed via nom::number::complete::float with no range check. Any application embednvd · 2026-08-05
- [NVD] CVE-2026-70376 (CRITICAL 9.6) — Pluck CMS's admin panel relies solely on a Referer-header comparison (requestedByTheSameDomain in data/inc/functions.admin.php, gating every admin.php action) for CSRF protection, with no per-request anti-CSRF token anywhere in the admin area.nvd · 2026-08-05
- [NVD] CVE-2026-64581 (HIGH 7.8) — In the Linux kernel, the following vulnerability has been resolved: xfrm: fix sk_dst_cache double-free in xfrm_user_policy() xfrm_user_policy() clears the socket dst cache with __sk_dst_reset(), i.e. the non-atomic __sk_dst_set(sk, NULL): it reads sk_dst_cache with rcu_dereferenvd · 2026-08-05
- [NVD] CVE-2026-64580 (HIGH 7.8) — In the Linux kernel, the following vulnerability has been resolved: xfrm6: clear dst.dev on error to avoid double netdev_put in xfrm6_fill_dst() On the error path where in6_dev_get(dev) returns NULL, xfrm6_fill_dst() releases the device reference with netdev_put() but leaves xdnvd · 2026-08-05
- [NVD] CVE-2026-64578 (HIGH 8.2) — In the Linux kernel, the following vulnerability has been resolved: ksmbd: validate compound request size before reading StructureSize2 When ksmbd validates a compound (chained) SMB2 request, ksmbd_smb2_check_message() reads pdu->StructureSize2 without first checking that the cnvd · 2026-08-05
- [NVD] CVE-2026-64577 (HIGH 7.5) — In the Linux kernel, the following vulnerability has been resolved: gtp: check skb_pull_data() return in gtp1u_send_echo_resp() gtp1u_send_echo_resp() ignores skb_pull_data()'s return value. Its caller gtp1u_udp_encap_recv() only guarantees 16 bytes (udphdr + gtp1_header), but nvd · 2026-08-05
- [NVD] CVE-2026-64576 (HIGH 7.1) — In the Linux kernel, the following vulnerability has been resolved: nexthop: initialize extack in nh_res_bucket_migrate() nh_res_bucket_migrate() passes an uninitialized netlink_ext_ack to call_nexthop_res_bucket_notifiers(). When nh_notifier_res_bucket_info_init() fails (e.g. nvd · 2026-08-05
- [NVD] CVE-2026-64575 (HIGH 7.8) — In the Linux kernel, the following vulnerability has been resolved: bpf: tcp: fix double sock release on batch realloc bpf_iter_tcp_batch() releases the current batch via bpf_iter_tcp_put_batch(), which drops the socket refs and rewrites each slot with the socket cookie, then gnvd · 2026-08-05
- [NVD] CVE-2026-64574 (HIGH 7.8) — In the Linux kernel, the following vulnerability has been resolved: wifi: mac80211: tear down new links on vif update error path When ieee80211_vif_update_links() adds new links it allocates a link container for each and calls ieee80211_link_init() (which registers the per-linknvd · 2026-08-05
- [NVD] CVE-2026-64570 (HIGH 7.8) — In the Linux kernel, the following vulnerability has been resolved: wifi: mac80211: fix fils_discovery double free on alloc failure ieee80211_set_fils_discovery() calls kfree_rcu() on the old template before allocating the replacement. If the kzalloc() then fails, it returns -Envd · 2026-08-05
- [NVD] CVE-2026-64568 (HIGH 7.8) — In the Linux kernel, the following vulnerability has been resolved: wifi: mac80211: fix unsol_bcast_probe_resp double free on alloc failure ieee80211_set_unsol_bcast_probe_resp() calls kfree_rcu() on the old template before allocating the replacement. If the kzalloc() then failnvd · 2026-08-05
- [NVD] CVE-2026-64567 (HIGH 7.8) — In the Linux kernel, the following vulnerability has been resolved: btrfs: reject free space cache with more entries than pages When loading a v1 free space cache, __load_free_space_cache() takes num_entries and num_bitmaps straight from the on-disk btrfs_free_space_header. Thanvd · 2026-08-05
- [NVD] CVE-2026-64566 (CRITICAL 9.8) — In the Linux kernel, the following vulnerability has been resolved: xfrm: iptfs: propagate SKBFL_SHARED_FRAG in iptfs_skb_add_frags() When iptfs_skb_add_frags() copies frag references from the source frag walk into a new SKB, it increments the page reference count via __skb_franvd · 2026-08-05
- [NVD] CVE-2026-55747 (MEDIUM 6.8) — The pocketflow-coding-agent cookbook example in The-Pocket/PocketFlow implements a helper as a thin os.path.join(workdir, p) wrapper with no canonicalization or containment check, used unguarded by the ReadFile, ListFiles, PatchRead, and PatchApply file-access tools. Severity refnvd · 2026-08-05
- [NVD] CVE-2026-55739 (HIGH 8.3) — Crater isolates data per company_id, and its Invoice/Estimate/Payment/Expense policies enforce both a Bouncer ability check and ->hasCompany(->company_id). CustomerPolicy's view/update/delete methods omit the company-ownership check entirely, checking only the blanket ability. Ronvd · 2026-08-05
- [NVD] CVE-2026-54418 (HIGH 8.1) — Leantime through 3.6.2 exposes the JSON-RPC methods leantime.rpc.TwoFA.TwoFA.getSetupData, saveSecret, verifyAndEnable, and disable2FA, which act on a caller-supplied userId parameter with no ownership check, session pinning, or permission-attribute gate (unlike other RPC-exposednvd · 2026-08-05
- [NVD] CVE-2026-54416 (HIGH 7.2) — Pluck CMS through 4.7.21 restricts dangerous file uploads in its admin file-management feature using a fixed blacklist in data/inc/files.php ('.php','php3','php4','php5','php6','php7','phtml','.phtm','.pht','.ph3','.ph4','.ph5','.asp','.cgi','.phar'), checked against the last 4-5nvd · 2026-08-05
- [spacebears] PontoBR Sistemas posted to leak siteransomware_live · 2026-08-05
- Claude Mythos 5 Tried to Backdoor a Real Open-Source Project in Testing, Then Vouched for Itselfthehackernews · 2026-08-05
- CISA Flags Langflow RCE, Tomcat, and N-central Flaws as Actively Exploitedthehackernews · 2026-08-05
- [gunra] PT All Cosmos Biotek posted to leak siteransomware_live · 2026-08-05
- [Orova] FixIT Tek posted to leak siteransomware_live · 2026-08-05
- Formula 1 Phishing Campaign & Kit Analysissocradar_blog · 2026-08-05
- [NVD] CVE-2026-70375 (HIGH 8.8) — HashBrown CMS through 1.4.6 contains an OS Command Injection vulnerability (CWE-78) in the Git deployer component. GitDeployer.pullRepo in src/Server/Entity/Deployer/GitDeployer.js executes AppService.exec, interpolating the configured branch value directly into a shell command wnvd · 2026-08-05
- [NVD] CVE-2026-70374 (HIGH 8.8) — HashBrown CMS through 1.4.6 contains an OS Command Injection vulnerability (CWE-78) in the media upload thumbnail generation routine. Media.generateThumbnail in src/Server/Entity/Resource/Media.js builds a temporary file path as 'thumbnail' + Path.extname(filename) and passes it,nvd · 2026-08-05
- Risky Bulletin: Hacker breaches Hungary's State Treasuryriskybiz_news · 2026-08-05
- Mozilla Firefox Information Disclosure Vulnerabilityhkcert · 2026-08-05
- Apache Tomcat Multiple Vulnerabilitieshkcert · 2026-08-05
- TP-Link Omada Products Multiple Vulnerabilitieshkcert · 2026-08-05
- FW: X.Org Security Advisory: multiple security issues in libXfont2oss_sec · 2026-08-05
- [incransom] lantisnet.com posted to leak siteransomware_live · 2026-08-05
- Hype vs. Reality: What the Hugging Face Incident Means for AI Safetyrecordedfuture · 2026-08-05
- [CISA KEV] CVE-2026-63077 — JetBrains TeamCity: JetBrains TeamCity Deserialization of Untrusted Data Vulnerabilitycisa_kev · 2026-08-05
- [incransom] Loyalist College posted to leak siteransomware_live · 2026-08-04
- ChainDrop supply chain compromise: Anatomy of a self-propagating wormmsstic · 2026-08-04
- [GHSA] GHSA-xm43-3m56-w3wf (medium) — Ghost: Paid gift memberships obtainable at minimal cost via the donations featuregithub_advisories · 2026-08-04
- [GHSA] GHSA-chgm-3698-jm42 (medium) — Ghost: Member existence leak via magic link sign-in responsegithub_advisories · 2026-08-04
- [GHSA] GHSA-xpp7-93x6-v29m (high) — XSS in Ghost's ActivityPub clientgithub_advisories · 2026-08-04
- [GHSA] GHSA-7mpp-r37j-x5wh (medium) — Ghost: Session Fixation in Ghost Admingithub_advisories · 2026-08-04
- [GHSA] GHSA-cjc9-q5gf-327p (medium) — Ghost: Theme Upload Path Traversalgithub_advisories · 2026-08-04
- [GHSA] GHSA-cj62-hvv2-2q5h (medium) — Ghost: Database Backup Path Traversalgithub_advisories · 2026-08-04
- [GHSA] GHSA-gcvv-72q8-9v76 (medium) — Ghost: Server-Side Request Forgery in Image Fetchinggithub_advisories · 2026-08-04
- [GHSA] GHSA-jm22-3w23-5q7w (medium) — Ghost: Blind Password Hash Disclosure in Ghost Admin APIgithub_advisories · 2026-08-04
- [GHSA] GHSA-g366-23fw-ggp6 (medium) — Ghost: Mobiledoc image-size fetch SSRFgithub_advisories · 2026-08-04
- [GHSA] GHSA-ch52-px8q-f22j (medium) — Ghost: Server-side request forgery via DNS rebinding in external request handlinggithub_advisories · 2026-08-04
- [NVD] CVE-2026-70494 (HIGH 8.1) — Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.10.0 until 0.11.0, the DELETE /api/v1/folders/{id} handler in backend/open_webui/routers/folders.py allowed a user granted write access to a shared chat folder to permanently delete chatsnvd · 2026-08-04
- [NVD] CVE-2026-70493 (MEDIUM 6.5) — Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.9.6 until 0.11.0, the built-in knowledge search path in backend/open_webui/tools/knowledge_fs.py and backend/open_webui/tools/builtin.py let a chat participant choose a pattern used to grnvd · 2026-08-04
- [NVD] CVE-2026-70492 (HIGH 8.7) — Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.10.0 until 0.11.0, src/lib/components/chat/Messages/Markdown/KatexRenderer.svelte could store and render a chat message whose math block makes KaTeX fail with a stack overflow instead of nvd · 2026-08-04
- [NVD] CVE-2026-70491 (MEDIUM 6.5) — Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. In 0.10.2 and earlier, the GET /api/v1/tools/, GET /api/v1/tools/list, and GET /api/v1/tools/id/{id} endpoints in backend/open_webui/routers/tools.py returned full Python tool source to authentinvd · 2026-08-04
- [NVD] CVE-2026-70490 (MEDIUM 6.3) — Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.8.8 until 0.11.0, the terminal WebSocket route in backend/open_webui/routers/terminals.py authenticated its own first-message JWT and never applied the verified-user role gate that get_venvd · 2026-08-04
- [NVD] CVE-2026-70489 (MEDIUM 6.5) — Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.9.0 until 0.11.0, automation recurrence parsing in backend/open_webui/utils/automations.py anchored minutely and hourly rules at a fixed date of 2000-01-01 and then walked forward one intnvd · 2026-08-04
- [NVD] CVE-2026-70488 (MEDIUM 4.3) — Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.9.6 until 0.11.0, the sync cleanup endpoint authorized write access to the knowledge base in the URL but then acted on directory and file ids supplied in the request body without checkingnvd · 2026-08-04
- [NVD] CVE-2026-70487 (MEDIUM 5.3) — Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.8.8 until 0.11.0, inline direct model metadata accepted client-supplied knowledge attachments without filtering them against the caller's read access. Any authenticated user who knew anotnvd · 2026-08-04
- [NVD] CVE-2026-54020 (MEDIUM 6.3) — Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. Prior to 0.11.0, Open WebUI resolved a hostname during URL validation and rejected private, loopback, and link-local addresses, but the HTTP clients resolved the hostname again at connection timnvd · 2026-08-04
- [GHSA] GHSA-wvp2-4qqp-4h3r (medium) — Ghost: Private IP filtering bypass to make server-side requests to internal servicesgithub_advisories · 2026-08-04
- [GHSA] GHSA-4wx2-7gvj-qfq3 (medium) — Ghost: Archived Offers can be Redeemedgithub_advisories · 2026-08-04
- [GHSA] GHSA-944x-pm95-3jpr (medium) — Ghost: File Upload Content-Type Spoofinggithub_advisories · 2026-08-04
- [GHSA] GHSA-2gx6-7gx2-wwcf (medium) — Ghost: Cross-Site Scripting in Universal Importgithub_advisories · 2026-08-04
- CVE-2026-66902: Google::Auth versions before 0.06 for Perl run a command named in an external_account credentials JSON via an ungated system calloss_sec · 2026-08-04
- CVE-2026-66901: Google::Auth versions before 0.09 for Perl allow server side request forgery and credential exfiltration via unvalidated URLs taken from the credentials JSONoss_sec · 2026-08-04
- [GHSA] GHSA-3cg5-48j3-v4gv (high) — Open WebUI: A folder write-collaborator can permanently delete the owner's chats by deleting a shared subfoldergithub_advisories · 2026-08-04
- Products Are Getting Smarter. Enterprise Transformations Are Getting Harder.zscaler_threatlabz · 2026-08-04
- [GHSA] GHSA-2f54-p244-32q6 (medium) — Open WebUI: Any authenticated user can stall a worker via a knowledge-search pattern that backtracks catastrophicallygithub_advisories · 2026-08-04
- [GHSA] GHSA-pwxh-7358-jq2x (high) — Open WebUI: Stored XSS via unescaped KaTeX render-error fallback in rendered messagesgithub_advisories · 2026-08-04
- [GHSA] GHSA-3r7g-q6cg-q2vx (medium) — Open WebUI: Tool source code disclosed to read-only users via the tool list and get endpointsgithub_advisories · 2026-08-04
- [GHSA] GHSA-5gpj-vj23-vhhv (medium) — Open WebUI: Unapproved accounts can open terminal sessions via a WebSocket auth path missing the role checkgithub_advisories · 2026-08-04
- [GHSA] GHSA-73cq-mcgh-379c (medium) — Open WebUI: Instance-wide stall via automation recurrence rules that force multi-second parsinggithub_advisories · 2026-08-04
- [GHSA] GHSA-h6x2-583h-x99r (medium) — DNS Rebinding SSRF Bypassgithub_advisories · 2026-08-04
- Re: Some Changes to GNOME Security Trackingoss_sec · 2026-08-04
- [GHSA] GHSA-6xhv-rxhv-pwm4 (medium) — Open WebUI: Cross-user file content disclosure via request-scoped direct model knowledge metadatagithub_advisories · 2026-08-04
- [GHSA] GHSA-jxc9-xmc4-gr23 (medium) — Open WebUI: Deletion of directories and file embeddings in other knowledge bases via sync cleanupgithub_advisories · 2026-08-04
- Apple battles it out again with the UK over encrypted iCloud accessmalwarebytes_blog · 2026-08-04
- The Director's Cut: When AI Agents Become Liability Riskszscaler_threatlabz · 2026-08-04
- [NVD] CVE-2026-70486 (HIGH 8.2) — Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.9.0 until 0.11.0, the terminal file-preview serveUrl iframe branch always granted allow-same-origin together with allow-scripts for HTML files served from the application origin. Any authnvd · 2026-08-04
- [NVD] CVE-2026-70485 (HIGH 7.1) — Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.9.0 until 0.11.0, Open WebUI checked whether a user-supplied URL destination was globally routable by applying ipaddress.is_global to the literal IPv6 address without examining IPv4 addrenvd · 2026-08-04
- [NVD] CVE-2026-70484 (MEDIUM 4.3) — Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.7.0 until 0.11.0, the legacy chat-completions features block trusted a client-supplied image_generation flag and did not re-check the features.image_generation permission that the direct nvd · 2026-08-04
- [NVD] CVE-2026-70483 (LOW 3.1) — Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.9.6 until 0.11.0, DELETE /api/v1/chats/{id} cancelled a chat's in-flight tasks before checking whether the caller could delete that chat. Any authenticated user who knew another user's chnvd · 2026-08-04
- [NVD] CVE-2026-70482 (HIGH 8.1) — Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.8.0 until 0.11.0, when ENABLE_OAUTH_TOKEN_EXCHANGE=True, /oauth/{provider}/token/exchange accepts a raw provider access token and validates it by calling the provider userinfo endpoint winvd · 2026-08-04
- [NVD] CVE-2026-70481 (MEDIUM 5.4) — Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.5.0 until 0.11.0, the standard channel message update and delete handlers accepted any caller holding write access on the channel without checking that the caller wrote the message. Becaunvd · 2026-08-04
- [NVD] CVE-2026-70480 (MEDIUM 4.1) — Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.6.34 until 0.11.0, Open WebUI renders vega and vega-lite fenced code blocks in chat content by building a Vega view in the viewer browser without a restricted resource loader. Any user whnvd · 2026-08-04
- [NVD] CVE-2026-70479 (HIGH 7.7) — Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.9.6 until 0.11.0, with WEB_LOADER_ENGINE=playwright, the Playwright web loader validates only the top-level page request and lets sub-resource requests pass unvalidated. A page supplied bnvd · 2026-08-04
- [NVD] CVE-2026-70478 (CRITICAL 10.0) — Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, the POST /api/v1/oauth2-credential/refresh/:credentialId endpoint is included in WHITELIST_URLS and requires no authentication. The endpoint decrypts the stored credential, senvd · 2026-08-04
- [NVD] CVE-2026-70477 (CRITICAL 9.8) — Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, a prompt injection sent to a chatflow using a CSV Agent node can cause the LLM to respond with a malicious Python script that bypasses the blocklist validator and executes in nvd · 2026-08-04
- [NVD] CVE-2026-70476 (HIGH 8.2) — Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, several organization billing endpoints in packages/server/src/enterprise/routes/organization.route.ts and packages/server/src/enterprise/controllers/organization.controller.tsnvd · 2026-08-04
- [NVD] CVE-2026-70475 (MEDIUM 6.5) — Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, the PUT /api/v1/executions/:id endpoint in packages/server/src/routes/executions/index.ts lacks the checkAnyPermission() middleware that protects other execution endpoints. Annvd · 2026-08-04
- Mythic 4 Public Beta: More Than a New Coat of Paintspecterops · 2026-08-04
- Veeam security advisory (AV26-777)cccs_ca · 2026-08-04
- [GHSA] GHSA-3xpf-xq7r-v8c5 (high) — Open WebUI: Same-origin XSS to account takeover via terminal file-preview iframe hardcoding allow-same-origingithub_advisories · 2026-08-04
- [GHSA] GHSA-8x5v-cpv7-8jjp (high) — Open WebUI: Any authenticated user can reach internal services and cloud metadata via NAT64-encoded URLsgithub_advisories · 2026-08-04
- [GHSA] GHSA-g423-grf7-98rv (medium) — Open WebUI: Users denied the image-generation permission can still generate images via chat completionsgithub_advisories · 2026-08-04
- [GHSA] GHSA-rffm-9q57-q649 (medium) — Open WebUI: Client-side SSRF via unrestricted external resource loading in Vega/Vega-Lite chart renderinggithub_advisories · 2026-08-04
- [GHSA] GHSA-3vf6-64vr-3g56 (low) — Open WebUI: Any authenticated user can cancel another user's chat generation via the chat delete endpointgithub_advisories · 2026-08-04
- [GHSA] GHSA-rq84-p6rr-vf89 (high) — Open WebUI: Account takeover via OAuth token exchange accepting tokens issued to any clientgithub_advisories · 2026-08-04
- Adobe security advisory (AV26-776)cccs_ca · 2026-08-04
- [GHSA] GHSA-mj5r-jf49-m3w7 (medium) — Open WebUI: Any member with write access to a standard channel can edit or delete other members' messagesgithub_advisories · 2026-08-04
- [GHSA] GHSA-w2rx-84hp-gg95 (high) — Open WebUI: SSRF into internal services via unvalidated sub-resource requests in the Playwright web loadergithub_advisories · 2026-08-04
- [GHSA] GHSA-qgvm-j2hm-6m38 (critical) — Flowise: Unauthenticated OAuth2 token refresh endpoint returns access tokens — enables token theft for any connected servicegithub_advisories · 2026-08-04
- Re: Some Changes to GNOME Security Trackingoss_sec · 2026-08-04
- CVE-2026-67592: Apache Qpid ProtonJ2: Unable to govern the maximum number of transfer frames per incoming deliveryoss_sec · 2026-08-04
- [GHSA] GHSA-5xvg-pmgg-3mxr (critical) — Flowise: CSV Agent Prompt Injection Remote Code Execution Vulnerabilitygithub_advisories · 2026-08-04