THREAT OPS › Threat News
Threat Intelligence News
12109 reports from 110+ open cyber-threat-intelligence sources — APT activity, malware, vulnerabilities and campaigns, newest first.
- [NVD] CVE-2026-60154 (MEDIUM 5.4) — Vulnerability in the Oracle Application Object Library product of Oracle E-Business Suite (component: Core). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oraclenvd · 2026-07-21
- [NVD] CVE-2026-56816 (HIGH 7.5) — Netty is a network application framework for development of protocol servers and clients. Prior to 4.2.16.Final, Netty's `Http3FrameCodec` buffers incoming data for HTTP/3 reserved frame types up to the wire-specified payload length without limits; `decodeFrame` trusts `payLoadLenvd · 2026-07-21
- [NVD] CVE-2026-47058 (HIGH 7.4) — Vulnerability in Oracle Java SE (component: Scripting). Supported versions that are affected are Oracle Java SE: 8u491, 8u491-perf and 11.0.31. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Javnvd · 2026-07-21
- [NVD] CVE-2026-47026 (HIGH 7.4) — Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: OpenSearch Dashboards). Supported versions that are affected are 8.61 and 8.62. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compronvd · 2026-07-21
- [NVD] CVE-2026-47021 (MEDIUM 5.3) — Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: 2D). Supported versions that are affected are Oracle Java SE: 8u491, 8u491-perf, 11.0.31, 17.0.19, 21.0.11, 25.0.3, 26.0.1; Oracle GraalVM for JDKnvd · 2026-07-21
- [NVD] CVE-2026-47019 (HIGH 8.1) — Vulnerability in the Oracle Product Hub product of Oracle E-Business Suite (component: Item Catalog). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Producnvd · 2026-07-21
- [NVD] CVE-2026-47015 (HIGH 7.1) — Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: PIA Core Technology). The supported version that is affected is 8.62. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Peopnvd · 2026-07-21
- [NVD] CVE-2026-47014 (HIGH 8.1) — Vulnerability in the Oracle Product Workbench product of Oracle E-Business Suite (component: Security). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Prodnvd · 2026-07-21
- [NVD] CVE-2026-47013 (MEDIUM 5.3) — Vulnerability in Oracle Java SE (component: JavaFX). The supported version that is affected is Oracle Java SE: 8u491. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE. Successful attacks ofnvd · 2026-07-21
- [NVD] CVE-2026-47010 (LOW 3.7) — Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: ImageIO). Supported versions that are affected are Oracle Java SE: 8u491, 8u491-perf, 11.0.31, 17.0.19, 21.0.11, 25.0.3, 26.0.1; Oracle GraalVM fonvd · 2026-07-21
- [NVD] CVE-2026-47009 (MEDIUM 6.5) — Vulnerability in the Oracle Agile PLM product of Oracle Supply Chain (component: Folders, Files & Attachments). The supported version that is affected is 9.3.6. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Agnvd · 2026-07-21
- [NVD] CVE-2026-47007 (HIGH 7.3) — Vulnerability in the Oracle Communications Pricing Design Center product of Oracle Communications (component: On-premise Deployment). Supported versions that are affected are 15.0.0.0.0, 15.0.1.0.0, 15.1.0.0.0 and 15.2.0.0.0. Easily exploitable vulnerability allows low privilegnvd · 2026-07-21
- [NVD] CVE-2026-46999 (HIGH 7.0) — Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Discovery Framework). Supported versions that are affected are 13.5 and 24.1. Difficult to exploit vulnerability allows unauthenticated attacker with network access vianvd · 2026-07-21
- [NVD] CVE-2026-46997 (MEDIUM 6.5) — Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Metadata Plugin). Supported versions that are affected are 13.5 and 24.1. Easily exploitable vulnerability allows low privileged attacker with network access via HTTPS nvd · 2026-07-21
- [NVD] CVE-2026-46992 (HIGH 8.8) — Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Enterprise Config Management). Supported versions that are affected are 13.5 and 24.1. Easily exploitable vulnerability allows low privileged attacker with network accenvd · 2026-07-21
- [NVD] CVE-2026-46983 (CRITICAL 9.8) — Vulnerability in the Oracle Retail Integration Bus product of Oracle Retail Applications (component: RIB Kernal). The supported version that is affected is 16.0.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oraclenvd · 2026-07-21
- [NVD] CVE-2026-46982 (CRITICAL 9.8) — Vulnerability in the Oracle Retail Integration Bus product of Oracle Retail Applications (component: RIB Kernal). The supported version that is affected is 14.1.3.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracnvd · 2026-07-21
- [NVD] CVE-2026-46968 (MEDIUM 5.9) — Vulnerability in Oracle Java SE (component: JSSE). Supported versions that are affected are Oracle Java SE: 8u491, 8u491-perf, 11.0.31, 17.0.19, 21.0.11, 25.0.3, 26.0.1; Oracle GraalVM for JDK: 17.0.19 and 21.0.11; Oracle GraalVM Enterprise Edition: 21.3.18. Difficult to exploinvd · 2026-07-21
- [NVD] CVE-2026-46943 (HIGH 7.4) — Vulnerability in the Oracle Retail EFTLink product of Oracle Retail Applications (component: Core/Plugin). Supported versions that are affected are 21.0.0-25.0.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oraclnvd · 2026-07-21
- [NVD] CVE-2026-34316 (MEDIUM 6.1) — Vulnerability in the Oracle Commerce Service Center product of Oracle Commerce (component: Commerce Service Center). The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oranvd · 2026-07-21
- [NVD] CVE-2026-21954 (MEDIUM 4.3) — Vulnerability in the Oracle Retail Xstore Point of Service product of Oracle Retail Applications (component: Xstore Mobile). The supported version that is affected is 21.0.3. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromnvd · 2026-07-21
- [NVD] CVE-2026-21953 (LOW 3.3) — Vulnerability in the Oracle Retail Xstore Point of Service product of Oracle Retail Applications (component: Xstore Mobile). The supported version that is affected is 21.0.3. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where nvd · 2026-07-21
- [NVD] CVE-2026-63140 (MEDIUM 6.5) — Reachable Assertion (CWE-617) in Elasticsearch can lead to denial of service via Input Data Manipulation (CAPEC-153). A specially crafted search request containing a null value in a specific query clause causes an internal assertion to be raised during query parsing. Because Elasnvd · 2026-07-21
- [NVD] CVE-2026-63136 (MEDIUM 6.5) — Uncontrolled Resource Consumption (CWE-400) in Elasticsearch can lead to denial of service via Excessive Allocation (CAPEC-130). A user with search privileges can submit a specially crafted search request that causes a data node to exhaust available heap memory, resulting in nodenvd · 2026-07-21
- [NVD] CVE-2026-47689 (MEDIUM 4.6) — FOG is a free open-source cloning/imaging/rescue suite/inventory management system. Prior to versions 1.5.10.1832 and 1.6.0-beta.2313, the `buildRow()` method in `fogpage.class.php` substitutes data values into HTML table cell templates using `str_replace()` without any HTML escanvd · 2026-07-21
- [NVD] CVE-2026-47688 (HIGH 8.2) — FOG is a free open-source cloning/imaging/rescue suite/inventory management system. Prior to versions 1.5.10.1832 and 1.6.0-beta.2313, the `clearAES` and `clearPMTasks` methods in `FOGPage` can be invoked by an unauthenticated attacker via a single HTTP GET request through the punvd · 2026-07-21
- [NVD] CVE-2026-47687 (HIGH 7.3) — FOG is a free open-source cloning/imaging/rescue suite/inventory management system. Prior to versions 1.5.10.1832 and 1.6.0-beta.2313, the `selectForm()` helper in `fogpage.class.php` renders `<option>` labels using raw, unescaped user input. An unauthenticated attacker who knowsnvd · 2026-07-21
- [NVD] CVE-2026-47685 (HIGH 7.3) — FOG is a free open-source cloning/imaging/rescue suite/inventory management system. Prior to versions 1.5.10.1832 and 1.6.0-beta.2313, the unauthenticated inventory service endpoint (`/service/inventory.php`) persists client-supplied values without sanitization, and the Host Mananvd · 2026-07-21
- Oracle July 2026 Critical Patch Update Addresses 1235 CVEstenable · 2026-07-21
- [NVD] CVE-2026-56145 (MEDIUM 6.5) — Uncontrolled Resource Consumption (CWE-400) in Elasticsearch can lead to denial of service via Excessive Allocation (CAPEC-130). A low-privileged authenticated user with permission to execute EQL sequence queries against an index they control can send a specially crafted query thnvd · 2026-07-21
- [NVD] CVE-2026-56144 (MEDIUM 5.3) — Incorrect Authorization (CWE-863) in Elasticsearch can allow an authenticated user with limited index privileges to exploit insufficient authorization controls in the ingest simulation feature. By targeting indices they are not authorized to access directly, the user can cause thnvd · 2026-07-21
- HPE security advisory (AV26-727)cccs_ca · 2026-07-21
- [NVD] CVE-2026-16493 (HIGH 7.8) — A flaw was found in ansible-core. The _extract_collection_from_git() function in ansible-core's concrete_artifact_manager.py constructs git clone commands without a '--' (end-of-options) separator before user-supplied URLs when installing collections from git sources. An attackernvd · 2026-07-21
- Why Exposure Management Is Replacing Vulnerability Managementhorizon3 · 2026-07-21
- Representing OpenSSF at AfricaCyberFestopenssf_blog · 2026-07-21
- Understanding Illicit Ecosystems: Inside Rehub’s Rise as a Primary Ransomware Marketplaceflashpoint · 2026-07-21
- Pwn2Own Ireland 2026 – New Targets and Categorieszdi_blog · 2026-07-21
- [NVD] CVE-2026-15829 (HIGH 8.1) — A SQL injection (CWE-89) and security boundary bypass (CWE-863) vulnerability exists in the prebuilt BigQuery forecasting tool (bigquery-forecast) of googleapis/mcp-toolbox. The tool accepts client-controlled parameters (data_col, timestamp_col, and id_cols) as plain strings andnvd · 2026-07-21
- [NVD] CVE-2026-15724 (HIGH 8.7) — In Progress ShareFile Storage Zones Controller versions prior to 5.12.5 and 6.0.2, an authenticated administrative user can exploit a path traversal vulnerability to read arbitrary files from the server filesystem, write files to arbitrary directories, or determine whether specifnvd · 2026-07-21
- [NVD] CVE-2026-15432 (MEDIUM 5.9) — When verifying a mac with a ChunkedMacVerification object, Tink compares the resulting tag with non constant time comparison. This potentially allows an attacker to use timinig information as a side channel in order to get information how many bytes of a given tag match the correnvd · 2026-07-21
- Cisco Catalyst SD-WAN Controller, Catalyst SD-WAN Manager, and Catalyst SD-WAN Validator Authenticated Privilege Escalation Vulnerabilitycisco_psirt · 2026-07-21
- WordPress security advisory (AV26-723) - Update 1cccs_ca · 2026-07-21
- [NVD] CVE-2026-59849 (LOW 3.1) — A flaw was found in libssh. Logic errors in automatic certificate-based public key authentication can cause libssh clients to loop indefinitely when configured certificates are missing or repeatedly rejected by a server, leading to denial of service.nvd · 2026-07-21
- Manual Patching Can’t Outrun AI. Automated Remediation Can.qualys · 2026-07-21
- CVE-2026-8933: Local Privilege Escalation in Set-Capabilities snap-confinequalys · 2026-07-21
- Critical SharePoint Bug Under Attackduo_decipher · 2026-07-21
- Mozilla security advisory (AV26-726)cccs_ca · 2026-07-21
- Zyxel security advisory (AV26-725)cccs_ca · 2026-07-21
- Tenable security advisory (AV26-724)cccs_ca · 2026-07-21
- [NVD] CVE-2026-16445 (HIGH 7.5) — A flaw was found in dracut. A remote attacker on the adjacent network can exploit this vulnerability by providing specially crafted DHCP options, such as a malicious root-path, next-server, or bootfile name, to a system using dracut's NetworkManager-based initrd network module. Tnvd · 2026-07-21
- A new extortion cocktail: office printers, small ransoms, and BitLockersecurelist · 2026-07-21
- Iran War Cyber Threat Landscape | A Midyear Assessment on What Matterssentinelone · 2026-07-21
- Introducing the SpecterOps Tradecraft Academyspecterops · 2026-07-21
- Your AI agent’s config is now the payload: How attackers are targeting the developer agent harnesstenable · 2026-07-21
- [NVD] CVE-2026-59842 (LOW 3.7) — A flaw was found in libssh. During server-side GSSAPI key exchange, a client-supplied Curve25519 public key shorter than the expected length is copied without proper length validation, leading to an out-of-bounds heap read. This could allow a remote unauthenticated attacker to dinvd · 2026-07-21
- CISA Adds Four Known Exploited Vulnerabilities to Catalogcisa_advisories · 2026-07-21
- Tycon Systems TPDIN-Monitor-WEB2cisa_ics · 2026-07-21
- Rockwell Automation 1718-AENTR/1719-AENTRcisa_advisories · 2026-07-21
- Siemens SIDIS Secured SmartPlugcisa_advisories · 2026-07-21
- Siemens IAM Clientcisa_advisories · 2026-07-21
- Siemens RUGGEDCOM APE1808 with Palo Alto Networks Virtual NGFWcisa_advisories · 2026-07-21
- Rockwell Automation 1734 POINT I/Ocisa_advisories · 2026-07-21
- Rockwell Automation FactoryTalk Services Platformcisa_advisories · 2026-07-21
- Rockwell Automation Studio 5000 Logix Designercisa_advisories · 2026-07-21
- Siemens CADRAcisa_advisories · 2026-07-21
- Siemens Opcenter Xcisa_advisories · 2026-07-21
- MIT to Become Hotbed of AI Video Surveillanceschneier · 2026-07-21
- [NVD] CVE-2026-15370 (MEDIUM 6.7) — A flaw was found in libssh. During SFTP server directory listing, the longname field is constructed with unsafe concatenation into a fixed-size stack buffer. When a client causes the server to list attacker-controlled filenames, sufficiently long names can overflow that stack bufnvd · 2026-07-21
- New Project CAV3RN module abuses Outlook calendar events for C2 and DNS AAAA records for configuration recoverysecurelist · 2026-07-21
- [NVD] CVE-2026-15927 (MEDIUM 6.8) — A flaw was found in Red Hat Quay's repository-level mirror configuration feature. The POST and PUT handlers in endpoints/api/mirror.py accept an external_reference parameter without SSRF validation, unlike the organization-level mirror handlers which apply validate_external_regisnvd · 2026-07-21
- ASUS bsitf.sys (CVE-2026-13585): Arbitrary Physical Memory Mapping in ASUS Business/Software Manager kernel driverfulldisclosure · 2026-07-21
- New Release: UFONet v2.0 - "R3DST4R!"...fulldisclosure · 2026-07-21
- XSSer v.1.9 - "Bl4ck Swarm!" releasedfulldisclosure · 2026-07-21
- NotCVE registry index — public records of vulnerabilities that shipped without a CVEfulldisclosure · 2026-07-21
- [CISA KEV] CVE-2026-0770 — Langflow Langflow: Langflow Inclusion of Functionality from Untrusted Control Sphere Vulnerabilitycisa_kev · 2026-07-21
- [CISA KEV] CVE-2021-27137 — DD-WRT DD-WRT: DD-WRT Stack-Based Buffer Overflow Vulnerabilitycisa_kev · 2026-07-21
- [Breach] SplitVPN — 865,336 accounts exposedhibp_breaches · 2026-07-21
- [CISA KEV] CVE-2026-60137 — WordPress Core: WordPress Core SQL Injection Vulnerabilitycisa_kev · 2026-07-21
- wp2shell Aftermath: The First Critical Unauthenticated WordPress Core RCE in Nearly a Decadewordfence · 2026-07-20
- [NVD] CVE-2026-44231 (CRITICAL 9.1) — RT is an open source, enterprise-grade issue and ticket tracking system. Versions prior to 5.0.10, 6.0.0 and above, prior to 6.0.3 contain an information disclosure and privilege escalation vulnerability in the REST 2.0 API. A privileged (non-administrative) user can obtain authenvd · 2026-07-20
- [NVD] CVE-2026-44230 (MEDIUM 6.1) — RT is an open source, enterprise-grade issue and ticket tracking system. Versions 5.0.4 up to (but not including) 5.0.10, and 6.0.0 up to (but not including) 6.0.3 contain a reflected Cross-Site Scripting (XSS) vulnerability where an attacker who can induce an authenticated RT usnvd · 2026-07-20
- A Look Inside the HuggingFace Breachvaronis_blog · 2026-07-20
- Between Two Nerds: What China gets wrong about Russia's cyber war in Ukraineriskybiz_news · 2026-07-20
- [NVD] CVE-2026-64194 (HIGH 7.5) — Net::DNS versions through 1.55 for Perl allow Denial of Service via deep DNS compression pointer chains. Net::DNS::DomainName::decode follows RFC 1035 compression pointers by recursing into itself with no depth limit. It is possible to construct a name which saturates the call snvd · 2026-07-20
- [NVD] CVE-2026-63770 (HIGH 7.5) — Glance through 0.8.5 contains an IP address spoofing vulnerability in the authentication handler that allows unauthenticated attackers to bypass brute-force lockout protections by supplying arbitrary values in the X-Forwarded-For request header when the server proxied option is envd · 2026-07-20
- [NVD] CVE-2026-64612 (HIGH 7.5) — A flaw was found in libcupsfilters and cups-filters. The PNG image reading function creates a libpng reader without installing an error recovery handler, causing the CUPS image filter process to abort when processing a malformed PNG file. An unauthenticated attacker could exploitnvd · 2026-07-20
- [NVD] CVE-2026-44228 (MEDIUM 5.4) — RT is an open source, enterprise-grade issue and ticket tracking system. Versions 6.0.0 and above, prior to 6.0.3, contain a stored Cross-Site Scripting (XSS) vulnerability, where user-controlled data is rendered without proper HTML escaping. An authenticated user with permissionnvd · 2026-07-20
- [NVD] CVE-2026-44227 (MEDIUM 6.1) — RT is an open source, enterprise-grade issue and ticket tracking system. Versions 6.0.0 and above, prior to 6.0.3 contain a reflected Cross-Site Scripting (XSS) vulnerability. An attacker who can induce an authenticated RT user to visit a crafted URL can execute arbitrary JavaScrnvd · 2026-07-20
- [NVD] CVE-2026-39878 (CRITICAL 9.3) — Chamilo LMS versions 1.11.38 and earlier contain a stored cross-site scripting vulnerability in the user registration form that allows any unauthenticated attacker to execute arbitrary JavaScript in an administrator's browser session, leading to full platform admin account takeovnvd · 2026-07-20
- Email Security Needs Proof, Not Static Detection: Takeaways from SACR's Email Security Reportvaronis_blog · 2026-07-20
- Targeted Attack on Government Entities in the Middle East | Part 1zscaler_threatlabz · 2026-07-20
- [NVD] CVE-2026-64205 — In the Linux kernel, the following vulnerability has been resolved: i2c: i801: fix hardware state machine corruption in error path A severe livelock and subsequent Hung Task panic were observed in the i2c-i801 driver during concurrent Fuzzing. The crash is caused by an unconditnvd · 2026-07-20
- [NVD] CVE-2026-64192 — In the Linux kernel, the following vulnerability has been resolved: bpf: Reject BPF_MAP_TYPE_INODE_STORAGE creation if BPF LSM is uninitialized When CONFIG_BPF_LSM=y is set, BPF inode storage maps (BPF_MAP_TYPE_INODE_STORAGE) are compiled into the kernel. However, if the BPF LSnvd · 2026-07-20
- Is Your Security Program Ready for AI-Speed Application Exploitation?qualys · 2026-07-20
- [NVD] CVE-2026-35198 (CRITICAL 9.0) — HeyForm is an open-source form builder. Prior to version 3.0.0-rc.7, a stored cross-site scripting (XSS) vulnerability in the form builder allows a low-privileged team member to inject malicious JavaScript that executes when a team owner views the form, leading to complete accounnvd · 2026-07-20
- HPE security advisory (AV26-722)cccs_ca · 2026-07-20
- Top Five Compliance Audit Software and Tools: Mastering Modern Regulatory Riskqualys · 2026-07-20
- ServiceNow security advisory (AV26-693) – Update 1cccs_ca · 2026-07-20
- Cisco Identity Services Engine Stored Cross-Site Scripting Vulnerabilitiescisco_psirt · 2026-07-20
- Zimbra security advisory (AV26-721)cccs_ca · 2026-07-20