THREAT OPS › Threat News
Threat Intelligence News
12109 reports from 110+ open cyber-threat-intelligence sources — APT activity, malware, vulnerabilities and campaigns, newest first.
- How to Find Which ISP is Slowing Down Your Userszscaler_threatlabz · 2026-07-22
- CVE-2026-60167, CVE-2026-60168, CVE-2026-60169 & CVE-2026-60170 | Oracle Hospitality Simphony Multiple Vulnerabilitieshorizon3 · 2026-07-22
- Drupal security advisory (AV26-738)cccs_ca · 2026-07-22
- Exim security advisory (AV26-737)cccs_ca · 2026-07-22
- Progress security advisory (AV26-736)cccs_ca · 2026-07-22
- Mitel security advisory (AV26-734)cccs_ca · 2026-07-22
- n8n security advisory (AV26-733)cccs_ca · 2026-07-22
- OpenSSF Community Day North America (NA) First-time Experienceopenssf_blog · 2026-07-22
- Risk Prioritization: How Security Teams Focus on What Mattersorca_security · 2026-07-22
- Security Visibility: Best Practices for Cloud Security Teamsorca_security · 2026-07-22
- ISC BIND security advisory (AV26-732)cccs_ca · 2026-07-22
- The Hugging Face Incident Changes the Vulnerability Equationsonatype · 2026-07-22
- Sol Searching | Can Frontier Models Tackle Autonomous Long-Horizon Malware Analysis?sentinelone · 2026-07-22
- RefluXFS: A Linux Kernel Local Privilege Escalation to Root in XFS (CVE-2026-64600)qualys · 2026-07-22
- Real world incident response: Microsoft and AXA XL strengthen cyber resiliencemsstic · 2026-07-22
- Next chapter: Restructuring GitHub’s bug bounty programgithub_security_lab · 2026-07-22
- Atlassian security advisory (AV26-731)cccs_ca · 2026-07-22
- Google Chrome security advisory (AV26-730)cccs_ca · 2026-07-22
- Ransom & Dark Web Issues Week 4, July 2026ahnlab · 2026-07-22
- Oracle security advisory – July 2026 quarterly rollup (AV26-729)cccs_ca · 2026-07-22
- WordPress Core Pre-Auth RCE Chain Exploited in the Wildorca_security · 2026-07-22
- AI on Both Sides: Key Takeaways From Cloud Security LIVE 2026orca_security · 2026-07-22
- Oracle Critical Patch Update, July 2026 Security Update Reviewqualys · 2026-07-22
- What’s New in Rapid7 Products and Services: Q2 2026 in Reviewrapid7 · 2026-07-22
- Dolphin X Stealer Targets 300+ Apps and Profiles Users with AIvaronis_blog · 2026-07-22
- Inside a TrickBot Variant Using DNS Tunneling for C2fortinet_research · 2026-07-22
- Chick-fil-A loyalty accounts hijacked using stolen passwordsmalwarebytes_blog · 2026-07-22
- SolarWinds security advisory (AV26-728)cccs_ca · 2026-07-22
- CISA Adds Two Known Exploited Vulnerabilities to Catalogcisa_advisories · 2026-07-22
- First-Person Identity Theft Storyschneier · 2026-07-22
- Risky Bulletin: Rogue OpenAI models were behind the Hugging Face breachriskybiz_news · 2026-07-22
- Mozilla Products Multiple Vulnerabilitieshkcert · 2026-07-22
- Google Chrome Multiple Vulnerabilitieshkcert · 2026-07-22
- LG to Ban Residential Proxies from Smart TV Appskrebs · 2026-07-22
- Oracle Products Multiple Vulnerabilitieshkcert · 2026-07-22
- [CISA KEV] CVE-2026-50522 — Microsoft SharePoint: Microsoft SharePoint Deserialization of Untrusted Data Vulnerability cisa_kev · 2026-07-22
- Modern Attack Vectors | Recorded Futurerecordedfuture · 2026-07-22
- [CISA KEV] CVE-2026-16232 — Check Point SmartConsole: Check Point SmartConsole Improper Authentication Vulnerabilitycisa_kev · 2026-07-22
- [NVD] CVE-2026-16517 (LOW 2.9) — A signed integer overflow vulnerability was found in libarchive's ZIP writer. In the archive_write_zip_header function in archive_write_set_format_zip.c, when ZIP encryption is enabled and the entry file size is close to INT64_MAX, the addition of the encryption overhead to the envd · 2026-07-21
- [NVD] CVE-2026-62574 (HIGH 7.8) — Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Install). Supported versions that are affected are Oracle Java SE: 8u491, 11.0.31, 17.0.19, 21.0.11, 25.0.3, 26.0.1; Oracle GraalVM for JDK: 17.0.nvd · 2026-07-21
- [NVD] CVE-2026-61312 (HIGH 8.5) — Vulnerability in the Oracle Product Hub product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracnvd · 2026-07-21
- [NVD] CVE-2026-61311 (HIGH 8.8) — Vulnerability in the Oracle Product Hub product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oraclenvd · 2026-07-21
- [NVD] CVE-2026-61310 (HIGH 8.1) — Vulnerability in the Oracle Product Hub product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oraclenvd · 2026-07-21
- [NVD] CVE-2026-61197 (CRITICAL 9.1) — Vulnerability in the Oracle Identity Manager product of Oracle Fusion Middleware (component: OIM Legacy UI). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compnvd · 2026-07-21
- [NVD] CVE-2026-61196 (CRITICAL 9.8) — Vulnerability in the Oracle Identity Manager product of Oracle Fusion Middleware (component: OIM Legacy UI). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compnvd · 2026-07-21
- [NVD] CVE-2026-61188 (HIGH 7.5) — Vulnerability in the Oracle Agile Product Lifecycle Management for Process product of Oracle Supply Chain (component: Installation). The supported version that is affected is 6.2.4. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP tnvd · 2026-07-21
- [NVD] CVE-2026-61185 (HIGH 7.4) — Vulnerability in the Oracle Agile Product Lifecycle Management for Process product of Oracle Supply Chain (component: Installation). The supported version that is affected is 6.2.4. Easily exploitable vulnerability allows unauthenticated attacker with access to the physical comnvd · 2026-07-21
- [NVD] CVE-2026-61184 (CRITICAL 9.1) — Vulnerability in the Oracle Agile Product Lifecycle Management for Process product of Oracle Supply Chain (component: Product Quality Management). The supported version that is affected is 6.2.4. Easily exploitable vulnerability allows unauthenticated attacker with network accenvd · 2026-07-21
- [NVD] CVE-2026-61183 (CRITICAL 9.8) — Vulnerability in the Oracle Agile Product Lifecycle Management for Process product of Oracle Supply Chain (component: Reporting). The supported version that is affected is 6.2.4. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to convd · 2026-07-21
- [NVD] CVE-2026-61182 (MEDIUM 6.7) — Vulnerability in the Oracle Agile Product Lifecycle Management for Process product of Oracle Supply Chain (component: Data Import). The supported version that is affected is 6.2.4. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructurenvd · 2026-07-21
- [NVD] CVE-2026-61181 (HIGH 7.6) — Vulnerability in the Oracle Agile Product Lifecycle Management for Process product of Oracle Supply Chain (component: Product Quality Management). The supported version that is affected is 6.2.4. Easily exploitable vulnerability allows low privileged attacker with network accesnvd · 2026-07-21
- [NVD] CVE-2026-61180 (HIGH 8.8) — Vulnerability in the Oracle Agile Product Lifecycle Management for Process product of Oracle Supply Chain (component: Product Quality Management). The supported version that is affected is 6.2.4. Easily exploitable vulnerability allows low privileged attacker with network accesnvd · 2026-07-21
- [NVD] CVE-2026-61179 (HIGH 8.8) — Vulnerability in the Oracle Agile Product Lifecycle Management for Process product of Oracle Supply Chain (component: Product Quality Management). The supported version that is affected is 6.2.4. Easily exploitable vulnerability allows low privileged attacker with network accesnvd · 2026-07-21
- [NVD] CVE-2026-61140 (CRITICAL 9.8) — Vulnerability in the Oracle WebCenter Sites product of Oracle Fusion Middleware (component: WebCenter Sites). The supported version that is affected is 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oraclenvd · 2026-07-21
- [NVD] CVE-2026-61116 (HIGH 7.5) — Vulnerability in the Oracle Application Object Library product of Oracle E-Business Suite (component: Core). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oraclnvd · 2026-07-21
- [NVD] CVE-2026-61114 (HIGH 7.5) — Vulnerability in the Oracle Application Object Library product of Oracle E-Business Suite (component: DB Privileges). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compronvd · 2026-07-21
- [NVD] CVE-2026-61113 (HIGH 7.4) — Vulnerability in the Oracle Application Object Library product of Oracle E-Business Suite (component: Core). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oranvd · 2026-07-21
- [NVD] CVE-2026-61111 (MEDIUM 6.5) — Vulnerability in the Oracle Application Object Library product of Oracle E-Business Suite (component: Core). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Appnvd · 2026-07-21
- [NVD] CVE-2026-61110 (HIGH 8.8) — Vulnerability in the Oracle Applications DBA product of Oracle E-Business Suite (component: ADPatch). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Applicnvd · 2026-07-21
- [NVD] CVE-2026-61107 (HIGH 7.2) — Vulnerability in the Oracle Applications DBA product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise nvd · 2026-07-21
- [NVD] CVE-2026-61082 (MEDIUM 6.5) — Vulnerability in the MySQL Connectors product of Oracle MySQL (component: Connector/J). Supported versions that are affected are 9.7.0-9.7.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise MySQL Connectornvd · 2026-07-21
- [NVD] CVE-2026-60812 (MEDIUM 6.5) — Vulnerability in the Oracle Supply Chain Trading Connector product of Oracle E-Business Suite (component: Collaboration History). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTPnvd · 2026-07-21
- [NVD] CVE-2026-60811 (MEDIUM 6.3) — Vulnerability in the Oracle Supply Chain Trading Connector product of Oracle E-Business Suite (component: Collaboration History). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTPnvd · 2026-07-21
- [NVD] CVE-2026-60810 (HIGH 8.2) — Vulnerability in the Oracle Supply Chain Trading Connector product of Oracle E-Business Suite (component: Collaboration History). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTnvd · 2026-07-21
- [NVD] CVE-2026-60804 (LOW 2.0) — Vulnerability in the Oracle E-Business Intelligence product of Oracle E-Business Suite (component: Definition). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows high privileged attacker with network access via HTTP to compromise nvd · 2026-07-21
- [NVD] CVE-2026-60802 (MEDIUM 6.1) — Vulnerability in the Oracle E-Business Intelligence product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compnvd · 2026-07-21
- [NVD] CVE-2026-60801 (MEDIUM 5.9) — Vulnerability in the Oracle E-Business Intelligence product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows high privileged attacker with network access via HTTP to convd · 2026-07-21
- [NVD] CVE-2026-60800 (HIGH 7.1) — Vulnerability in the Oracle Compensation Workbench product of Oracle E-Business Suite (component: Compensation Workbench). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to comnvd · 2026-07-21
- [NVD] CVE-2026-60799 (HIGH 7.1) — Vulnerability in the Oracle Compensation Workbench product of Oracle E-Business Suite (component: Compensation Workbench). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to comnvd · 2026-07-21
- [NVD] CVE-2026-60776 (MEDIUM 6.7) — Vulnerability in the Oracle Application Object Library product of Oracle E-Business Suite (component: AOL Generic Loader). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure wnvd · 2026-07-21
- [NVD] CVE-2026-60773 (CRITICAL 9.6) — Vulnerability in the Oracle Application Object Library product of Oracle E-Business Suite (component: Core). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTPS to compromise Oraclnvd · 2026-07-21
- [NVD] CVE-2026-60772 (HIGH 7.1) — Vulnerability in the Oracle Financials Common Modules product of Oracle E-Business Suite (component: Common Components). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to comprnvd · 2026-07-21
- [NVD] CVE-2026-60771 (HIGH 8.1) — Vulnerability in the Oracle Complex Maintenance, Repair and Overhaul product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access nvd · 2026-07-21
- [NVD] CVE-2026-60764 (HIGH 8.1) — Vulnerability in the Oracle Financials Common Modules product of Oracle E-Business Suite (component: Common Components). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to comprnvd · 2026-07-21
- [NVD] CVE-2026-60761 (MEDIUM 6.5) — Vulnerability in the Oracle Applications DBA product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oraclnvd · 2026-07-21
- [NVD] CVE-2026-60736 (HIGH 8.1) — Vulnerability in the Oracle E-Business Intelligence product of Oracle E-Business Suite (component: Definition). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oranvd · 2026-07-21
- [NVD] CVE-2026-60708 (HIGH 8.1) — Vulnerability in the Oracle Process Manufacturing Financials product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTPnvd · 2026-07-21
- [NVD] CVE-2026-60703 (HIGH 7.1) — Vulnerability in the Oracle Interaction Blending product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Onvd · 2026-07-21
- [NVD] CVE-2026-60685 (MEDIUM 6.1) — Vulnerability in the Oracle iSupport product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle invd · 2026-07-21
- [NVD] CVE-2026-60684 (MEDIUM 4.6) — Vulnerability in the Oracle Applications Framework product of Oracle E-Business Suite (component: Upload Attachments). Supported versions that are affected are 12.2.8-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromnvd · 2026-07-21
- [NVD] CVE-2026-60683 (HIGH 7.7) — Vulnerability in the Oracle Process Manufacturing Regulatory Management product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network accenvd · 2026-07-21
- [NVD] CVE-2026-60681 (HIGH 8.8) — Vulnerability in the Oracle Process Manufacturing Regulatory Management product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network accenvd · 2026-07-21
- [NVD] CVE-2026-60678 (HIGH 8.8) — Vulnerability in the Oracle General Ledger product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via SOAP to compromise Oranvd · 2026-07-21
- [NVD] CVE-2026-60676 (HIGH 8.8) — Vulnerability in the Oracle Applications Framework product of Oracle E-Business Suite (component: Search Bean). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oranvd · 2026-07-21
- [NVD] CVE-2026-60675 (HIGH 8.8) — Vulnerability in the Oracle Applications Framework product of Oracle E-Business Suite (component: Search Bean). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oranvd · 2026-07-21
- [NVD] CVE-2026-60674 (HIGH 8.2) — Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: BI Platform Security). Supported versions that are affected are 8.2.0.0.0 and 26.01.0.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network nvd · 2026-07-21
- [NVD] CVE-2026-60671 (HIGH 8.6) — Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: BI Platform Security). Supported versions that are affected are 8.2.0.0.0 and 26.01.0.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network nvd · 2026-07-21
- [NVD] CVE-2026-60670 (HIGH 8.1) — Vulnerability in the Oracle Applications Technology Stack product of Oracle E-Business Suite (component: Client System Analyzer). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows unauthenticated attacker with network access via Hnvd · 2026-07-21
- [NVD] CVE-2026-60669 (MEDIUM 5.9) — Vulnerability in the PeopleSoft Enterprise HCM Global Payroll Mexico product of Oracle PeopleSoft (component: Global Payroll for Mexico). The supported version that is affected is 9.2. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTnvd · 2026-07-21
- [NVD] CVE-2026-60668 (HIGH 8.2) — Vulnerability in the PeopleSoft Enterprise HCM Human Resources product of Oracle PeopleSoft (component: French Public Sector Specific). The supported version that is affected is 9.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP tnvd · 2026-07-21
- [NVD] CVE-2026-60667 (HIGH 7.4) — Vulnerability in the PeopleSoft Enterprise HCM Human Resources product of Oracle PeopleSoft (component: Core). The supported version that is affected is 9.2. Difficult to exploit vulnerability allows unauthenticated attacker with network access via TCP to compromise PeopleSoft nvd · 2026-07-21
- [NVD] CVE-2026-60666 (MEDIUM 6.8) — Vulnerability in the PeopleSoft Enterprise HCM Human Resources product of Oracle PeopleSoft (component: Security). The supported version that is affected is 9.2. Difficult to exploit vulnerability allows low privileged attacker with network access via Oracle Net to compromise Pnvd · 2026-07-21
- [NVD] CVE-2026-60665 (HIGH 8.2) — Vulnerability in the PeopleSoft Enterprise HCM Global Payroll Switzerland product of Oracle PeopleSoft (component: Global Payroll for Switzerland). The supported version that is affected is 9.2. Difficult to exploit vulnerability allows low privileged attacker with network accenvd · 2026-07-21
- [NVD] CVE-2026-60661 (HIGH 7.8) — Vulnerability in the Oracle Solaris product of Oracle Systems (component: Filesystems). The supported version that is affected is 11.4. Difficult to exploit vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Solaris executes to compromisenvd · 2026-07-21
- [NVD] CVE-2026-60659 (HIGH 7.1) — Vulnerability in the Oracle Solaris product of Oracle Systems (component: Filesystems). The supported version that is affected is 11.4. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Solaris executes to compromise Onvd · 2026-07-21
- [NVD] CVE-2026-60653 (HIGH 8.1) — Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Web Content Management). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTnvd · 2026-07-21
- [NVD] CVE-2026-60652 (HIGH 8.0) — Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Web Content Management). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTnvd · 2026-07-21
- [NVD] CVE-2026-60651 (HIGH 8.8) — Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Web Content Management). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTnvd · 2026-07-21
- [NVD] CVE-2026-60647 (HIGH 7.1) — Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Web Content Management). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTnvd · 2026-07-21
- [NVD] CVE-2026-60642 (HIGH 7.6) — Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to convd · 2026-07-21