{
  "summary": {
    "source": "kev",
    "catalogVersion": "2026.07.21",
    "catalogReleased": "2026-07-21T15:12:01.557Z",
    "windowDays": 30,
    "total": 28,
    "vendors": 18,
    "ransomware": 0,
    "withPoc": 15,
    "multiSource": 25,
    "builtAt": "2026-07-22T06:02:14.705Z",
    "unenriched": 26,
    "onTelegram": 18
  },
  "cves": [
    {
      "cve": "CVE-2026-60137",
      "title": "WordPress Core SQL Injection Vulnerability",
      "category": "WordPress",
      "vendor": "WordPress",
      "product": "Core",
      "exploited": true,
      "publiclyDisclosed": false,
      "faq": "WordPress Core contains a SQL injection vulnerability when a plugin or theme passes untrusted input to the parameter. This vulnerability can be chained with CVE-2026-63030 to allow an unauthenticated attacker to gain remote code execution on default WordPress installations.",
      "cvss": 5.9,
      "cvssVector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N",
      "severity": "MEDIUM",
      "impact": null,
      "products": [
        "Core"
      ],
      "productCount": 1,
      "mitreUrl": "https://nvd.nist.gov/vuln/detail/CVE-2026-60137",
      "source": "kev",
      "kev": {
        "dateAdded": "2026-07-21",
        "dueDate": "2026-08-04",
        "requiredAction": "Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.",
        "ransomware": false,
        "cwes": [
          "CWE-89"
        ],
        "references": [
          "https://wordpress.org/news/2026/07/wordpress-7-0-2-release/",
          "https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk",
          "https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk",
          "https://nvd.nist.gov/vuln/detail/CVE-2026-60137"
        ]
      },
      "epss": 0.04026,
      "epssPercentile": 0.89474,
      "pocCount": 3,
      "pocTopStars": 8,
      "pocConfidence": "confirmed",
      "pocRepos": [
        {
          "url": "https://github.com/codeb0ssx/Ultimate-wp2shell",
          "stars": 8,
          "desc": "wp2shell — Pre-authentication RCE in WordPress Core (CVE-2026-60137 + CVE-2026-63030). Chains an SQL injection in author__not_in with batch-route confusion for ",
          "createdAt": "2026-07-18",
          "hasCode": true
        },
        {
          "url": "https://github.com/h4cd0c/wp2shell",
          "stars": 0,
          "desc": "wp2shell — Pre-authentication RCE in WordPress Core (CVE-2026-60137 + CVE-2026-63030). Chains an SQL injection in author__not_in with batch-route confusion for ",
          "createdAt": "2026-07-18",
          "hasCode": true
        },
        {
          "url": "https://github.com/yoerivegt/wp2shell-poc",
          "stars": 0,
          "desc": "wp2shell (CVE-2026-60137 / CVE-2026-63030)",
          "createdAt": "2026-07-18",
          "hasCode": true
        }
      ],
      "published": "2026-07-17T20:17:27.790",
      "corroboration": {
        "poc": true,
        "xOrigin": false,
        "independent": [
          "poc"
        ],
        "level": "multi-source"
      },
      "research": [
        {
          "url": "https://github.com/Icex0/wp2shell-poc",
          "type": "poc",
          "source": "GitHub / Icex0",
          "note": "Full RCE chain PoC; most widely referenced",
          "hasCode": true
        },
        {
          "url": "https://github.com/0xsha/wp2shell",
          "type": "poc",
          "source": "GitHub / 0xsha",
          "note": "Unified stdlib-only PoC merging 6 public chains",
          "hasCode": true
        },
        {
          "url": "https://slcyber.io/research-center/wp2shell-pre-authentication-rce-in-wordpress-core",
          "type": "writeup",
          "source": "Searchlight Cyber / Adam Kues",
          "note": "Original discoverer advisory; no full technicals yet"
        },
        {
          "url": "https://github.com/ZephrFish/wp2shell-scanner",
          "type": "module",
          "source": "GitHub / ZephrFish",
          "note": "Scanner + Nuclei YAML: wp2shell-exposure.yaml",
          "hasCode": false
        },
        {
          "url": "https://labs.eye.security/wp2shell-defenders-guide/",
          "type": "writeup",
          "source": "Eye Security Research",
          "note": "Defender guide; verified Icex0 PoC end-to-end"
        },
        {
          "url": "https://www.vulncheck.com/blog/wp2shell",
          "type": "writeup",
          "source": "VulnCheck",
          "note": "Technical chain breakdown; 24+ PoCs confirmed"
        },
        {
          "url": "https://blog.zsec.uk/wp2shell-code-trace-deep-dive/",
          "type": "writeup",
          "source": "ZephrFish / ZephrSec",
          "note": "Deep-dive code trace; linked from scanner repo"
        },
        {
          "url": "https://wp2shell.com/",
          "type": "detection",
          "source": "Searchlight Cyber (wp2shell.com)",
          "note": "Official exposure checker; no exploit payload sent"
        }
      ],
      "aliases": [
        "WP2Shell",
        "wp2shell"
      ],
      "researchers": [
        "TF1T",
        "dtro",
        "haongo",
        "adamkues"
      ],
      "x": {
        "mentions": 102,
        "aliases": [
          "WP2Shell",
          "wp2shell"
        ],
        "posts": [
          {
            "handle": "elhackernet",
            "followers": 140895,
            "likes": 10,
            "createdAt": "2026-07-20",
            "url": "https://x.com/elhackernet/status/2079297919677857809",
            "github": [],
            "origin": true
          },
          {
            "handle": "connect24h",
            "followers": 4416,
            "likes": 8,
            "createdAt": "2026-07-20",
            "url": "https://x.com/connect24h/status/2079284178823344328",
            "github": [],
            "origin": true
          },
          {
            "handle": "Racer_Kamira",
            "followers": 11440,
            "likes": 5,
            "createdAt": "2026-07-20",
            "url": "https://x.com/Racer_Kamira/status/2079298320045056275",
            "github": [],
            "origin": true
          },
          {
            "handle": "siennawebdesign",
            "followers": 292,
            "likes": 3,
            "createdAt": "2026-07-20",
            "url": "https://x.com/siennawebdesign/status/2079342484493156445",
            "github": [],
            "origin": true
          },
          {
            "handle": "snyff",
            "followers": 20667,
            "likes": 2,
            "createdAt": "2026-07-20",
            "url": "https://x.com/snyff/status/2079336372310249667",
            "github": [],
            "origin": true
          },
          {
            "handle": "__kokumoto",
            "followers": 7585,
            "likes": 2,
            "createdAt": "2026-07-20",
            "url": "https://x.com/__kokumoto/status/2079345020709265478",
            "github": [],
            "origin": true
          },
          {
            "handle": "Horizon3ai",
            "followers": 2894,
            "likes": 2,
            "createdAt": "2026-07-20",
            "url": "https://x.com/Horizon3ai/status/2079336182480257029",
            "github": [],
            "origin": true
          },
          {
            "handle": "eSecurityPlanet",
            "followers": 6841,
            "likes": 0,
            "createdAt": "2026-07-20",
            "url": "https://x.com/eSecurityPlanet/status/2079268552884772897",
            "github": [],
            "origin": true
          }
        ]
      },
      "bsky": {
        "mentions": 44,
        "posts": [
          {
            "handle": "infosec.skyfleet.blue",
            "displayName": "InfoSec",
            "likes": 1,
            "reposts": 0,
            "replies": 0,
            "createdAt": "2026-07-18",
            "url": "https://bsky.app/profile/infosec.skyfleet.blue/post/3mqwsmwum3c22",
            "origin": true,
            "authority": true,
            "github": []
          },
          {
            "handle": "raptor.infosec.exchange.ap.brid.gy",
            "displayName": "raptor",
            "likes": 1,
            "reposts": 1,
            "replies": 1,
            "createdAt": "2026-07-18",
            "url": "https://bsky.app/profile/raptor.infosec.exchange.ap.brid.gy/post/3mqvtnm45ddy2",
            "origin": true,
            "authority": false,
            "github": [
              {
                "url": "https://github.com/Icex0/wp2shell-poc",
                "hasCode": true
              }
            ]
          },
          {
            "handle": "r-blueteamsec.bsky.social",
            "displayName": "r/blueteamsec bot",
            "likes": 0,
            "reposts": 0,
            "replies": 0,
            "createdAt": "2026-07-18",
            "url": "https://bsky.app/profile/r-blueteamsec.bsky.social/post/3mqw7fxlakd2e",
            "origin": true,
            "authority": false,
            "github": [
              {
                "url": "https://github.com/Icex0/wp2shell-poc",
                "hasCode": true
              }
            ]
          },
          {
            "handle": "goodtech.info",
            "displayName": "Goodtech - L'actu open source 🇫🇷🐧🇪🇺",
            "likes": 2,
            "reposts": 2,
            "replies": 0,
            "createdAt": "2026-07-20",
            "url": "https://bsky.app/profile/goodtech.info/post/3mr24wwys63ec",
            "origin": true,
            "authority": false,
            "github": []
          },
          {
            "handle": "ninjaowl.ai",
            "displayName": "Ninja Owl",
            "likes": 3,
            "reposts": 0,
            "replies": 0,
            "createdAt": "2026-07-19",
            "url": "https://bsky.app/profile/ninjaowl.ai/post/3mqxim6htkn2o",
            "origin": true,
            "authority": false,
            "github": []
          },
          {
            "handle": "r-netsec.bsky.social",
            "displayName": "r/netsec bot",
            "likes": 2,
            "reposts": 0,
            "replies": 0,
            "createdAt": "2026-07-18",
            "url": "https://bsky.app/profile/r-netsec.bsky.social/post/3mqxa34s4rl2o",
            "origin": true,
            "authority": false,
            "github": []
          }
        ]
      },
      "telegram": {
        "mentions": 8,
        "reach": 40169,
        "posts": [
          {
            "channel": "thehackernews",
            "channelTitle": "The Hacker News",
            "tier": "news",
            "date": "2026-07-18",
            "views": 9527,
            "forwards": 78,
            "url": "https://t.me/thehackernews/9544",
            "text": "⚡ UPDATE: #wp2shell now has two CVEs, and a working proof-of-concept is public. > CVE-2026-63030 breaks REST batch routing > CVE-2026-60137 injects SQL Chained, they give an anonymous attacker code execution on affected WordPress sites. How the exploit path works: https://thehackernews.com/2026/07/new-wp2shell-wordpress-core-flaw-lets.html",
            "github": [],
            "origin": false
          }
        ]
      }
    },
    {
      "cve": "CVE-2026-63030",
      "title": "WordPress Core Interpretation Conflict Vulnerability",
      "category": "WordPress",
      "vendor": "WordPress",
      "product": "Core",
      "exploited": true,
      "publiclyDisclosed": false,
      "faq": "WordPress Core contains an interpretation conflict vulnerability that could allow an attacker to perform SQL Injection and achieve Remote Code Execution. This vulnerability can be chained with CVE-2026-60137.",
      "cvss": 9.8,
      "cvssVector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "severity": "CRITICAL",
      "impact": null,
      "products": [
        "Core"
      ],
      "productCount": 1,
      "mitreUrl": "https://nvd.nist.gov/vuln/detail/CVE-2026-63030",
      "source": "kev",
      "kev": {
        "dateAdded": "2026-07-21",
        "dueDate": "2026-07-24",
        "requiredAction": "Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.",
        "ransomware": false,
        "cwes": [
          "CWE-436"
        ],
        "references": [
          "https://wordpress.org/news/2026/07/wordpress-7-0-2-release/",
          "https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk",
          "https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk",
          "https://nvd.nist.gov/vuln/detail/CVE-2026-63030"
        ]
      },
      "epss": 0.08946,
      "epssPercentile": 0.94679,
      "pocCount": 8,
      "pocTopStars": 460,
      "pocConfidence": "confirmed",
      "pocRepos": [
        {
          "url": "https://github.com/Icex0/wp2shell-poc",
          "stars": 460,
          "desc": "wp2shell (CVE-2026-63030 & CVE-2026-60137) - full RCE chain",
          "createdAt": "2026-07-17",
          "hasCode": true
        },
        {
          "url": "https://github.com/0xsha/wp2shell",
          "stars": 58,
          "desc": "CVE-2026-63030 + CVE-2026-60137 - “wp2shell”: unauthenticated RCE in WordPress core",
          "createdAt": "2026-07-18",
          "hasCode": true
        },
        {
          "url": "https://github.com/dinosn/wp2shell-lab",
          "stars": 35,
          "desc": "Non-destructive detector + Docker lab for wp2shell (CVE-2026-63030 REST /batch/v1 route confusion + CVE-2026-60137 author__not_in SQLi) in WordPress core 6.9.0-",
          "createdAt": "2026-07-18",
          "hasCode": true
        },
        {
          "url": "https://github.com/47Cid/wp2shell-lab",
          "stars": 12,
          "desc": "Educational PoC + lab for CVE-2026-63030 + CVE-2026-60137: pre-auth SQLi in WordPress core via REST batch-route confusion",
          "createdAt": "2026-07-18",
          "hasCode": true
        },
        {
          "url": "https://github.com/NULL200OK/WP2Shell",
          "stars": 9,
          "desc": "WP2Shell - CVE-2026-63030 / CVE-2026-60137 This tool exploits a critical SQL injection vulnerability in the WordPress REST API `/wp-json/batch/v1` endpoint, all",
          "createdAt": "2026-07-18",
          "hasCode": true
        },
        {
          "url": "https://github.com/4minx/CVE-2026-63030",
          "stars": 8,
          "desc": "CVE-2026-63030 (wp2shell) POC.",
          "createdAt": "2026-07-18",
          "hasCode": true
        }
      ],
      "published": "2026-07-17T20:17:28.490",
      "corroboration": {
        "poc": true,
        "xOrigin": false,
        "independent": [
          "poc"
        ],
        "level": "multi-source"
      },
      "research": [
        {
          "url": "https://github.com/Icex0/wp2shell-poc",
          "type": "poc",
          "source": "Icex0 / GitHub",
          "note": "Full RCE chain: SQLi→admin forge→webshell plugin",
          "hasCode": true
        },
        {
          "url": "https://github.com/0xsha/wp2shell",
          "type": "poc",
          "source": "0xsha / GitHub",
          "note": "Unified stdlib-only RCE; credits Icex0/sergiointel techniques",
          "hasCode": true
        },
        {
          "url": "https://github.com/sergiointel/wp2shell-poc",
          "type": "poc",
          "source": "sergiointel / GitHub",
          "note": "Crack-free pre-auth admin creation via oEmbed/customizer",
          "hasCode": true
        },
        {
          "url": "https://slcyber.io/research-center/wp2shell-pre-authentication-rce-in-wordpress-core/",
          "type": "writeup",
          "source": "Adam Kues / Searchlight Cyber (Assetnote)",
          "note": "Original discoverer writeup; authoritative disclosure"
        },
        {
          "url": "https://labs.eye.security/wp2shell-defenders-guide/",
          "type": "writeup",
          "source": "Eye Security Research",
          "note": "Deep defender guide; verified end-to-end chain independently"
        },
        {
          "url": "https://www.rapid7.com/blog/post/etr-cve-2026-63030-wp2shell-a-critical-remote-code-execution-vulnerability-in-wordpress-core/",
          "type": "writeup",
          "source": "Rapid7 ETR",
          "note": "ETR with CVSS analysis; InsightVM/Nexpose coverage noted"
        },
        {
          "url": "https://github.com/projectdiscovery/nuclei-templates/pull/16595",
          "type": "module",
          "source": "mielverkerken / ProjectDiscovery nuclei-templates",
          "note": "Official Nuclei detection template PR; merged 2026-07-17",
          "hasCode": true
        },
        {
          "url": "https://github.com/Senanfurkan/wordpress-cve-2026-63030",
          "type": "detection",
          "source": "Senanfurkan / GitHub",
          "note": "Safe detection-only PoC: route confusion + time-based SQLi",
          "hasCode": true
        }
      ],
      "aliases": [
        "wp2shell"
      ],
      "researchers": [
        "adamkues",
        "Icex0",
        "0xsha",
        "sergiointel",
        "attackercan"
      ],
      "x": {
        "mentions": 133,
        "aliases": [
          "wp2shell"
        ],
        "posts": [
          {
            "handle": "elhackernet",
            "followers": 140895,
            "likes": 10,
            "createdAt": "2026-07-20",
            "url": "https://x.com/elhackernet/status/2079297919677857809",
            "github": [],
            "origin": true
          },
          {
            "handle": "connect24h",
            "followers": 4416,
            "likes": 8,
            "createdAt": "2026-07-20",
            "url": "https://x.com/connect24h/status/2079284178823344328",
            "github": [],
            "origin": true
          },
          {
            "handle": "Racer_Kamira",
            "followers": 11440,
            "likes": 5,
            "createdAt": "2026-07-20",
            "url": "https://x.com/Racer_Kamira/status/2079298320045056275",
            "github": [],
            "origin": true
          },
          {
            "handle": "siennawebdesign",
            "followers": 292,
            "likes": 3,
            "createdAt": "2026-07-20",
            "url": "https://x.com/siennawebdesign/status/2079342484493156445",
            "github": [],
            "origin": true
          },
          {
            "handle": "snyff",
            "followers": 20667,
            "likes": 2,
            "createdAt": "2026-07-20",
            "url": "https://x.com/snyff/status/2079336372310249667",
            "github": [],
            "origin": true
          },
          {
            "handle": "__kokumoto",
            "followers": 7585,
            "likes": 2,
            "createdAt": "2026-07-20",
            "url": "https://x.com/__kokumoto/status/2079345020709265478",
            "github": [],
            "origin": true
          },
          {
            "handle": "Horizon3ai",
            "followers": 2894,
            "likes": 2,
            "createdAt": "2026-07-20",
            "url": "https://x.com/Horizon3ai/status/2079336182480257029",
            "github": [],
            "origin": true
          },
          {
            "handle": "__su888",
            "followers": 853,
            "likes": 2,
            "createdAt": "2026-07-20",
            "url": "https://x.com/__su888/status/2079325728181518491",
            "github": [],
            "origin": true
          }
        ]
      },
      "bsky": {
        "mentions": 35,
        "posts": [
          {
            "handle": "infosec.skyfleet.blue",
            "displayName": "InfoSec",
            "likes": 1,
            "reposts": 0,
            "replies": 0,
            "createdAt": "2026-07-18",
            "url": "https://bsky.app/profile/infosec.skyfleet.blue/post/3mqwsmwum3c22",
            "origin": true,
            "authority": true,
            "github": []
          },
          {
            "handle": "raptor.infosec.exchange.ap.brid.gy",
            "displayName": "raptor",
            "likes": 1,
            "reposts": 1,
            "replies": 1,
            "createdAt": "2026-07-18",
            "url": "https://bsky.app/profile/raptor.infosec.exchange.ap.brid.gy/post/3mqvtnm45ddy2",
            "origin": true,
            "authority": false,
            "github": [
              {
                "url": "https://github.com/Icex0/wp2shell-poc",
                "hasCode": true
              }
            ]
          },
          {
            "handle": "r-blueteamsec.bsky.social",
            "displayName": "r/blueteamsec bot",
            "likes": 0,
            "reposts": 0,
            "replies": 0,
            "createdAt": "2026-07-18",
            "url": "https://bsky.app/profile/r-blueteamsec.bsky.social/post/3mqw7fxlakd2e",
            "origin": true,
            "authority": false,
            "github": [
              {
                "url": "https://github.com/Icex0/wp2shell-poc",
                "hasCode": true
              }
            ]
          },
          {
            "handle": "goodtech.info",
            "displayName": "Goodtech - L'actu open source 🇫🇷🐧🇪🇺",
            "likes": 2,
            "reposts": 2,
            "replies": 0,
            "createdAt": "2026-07-20",
            "url": "https://bsky.app/profile/goodtech.info/post/3mr24wwys63ec",
            "origin": true,
            "authority": false,
            "github": []
          },
          {
            "handle": "ninjaowl.ai",
            "displayName": "Ninja Owl",
            "likes": 3,
            "reposts": 0,
            "replies": 0,
            "createdAt": "2026-07-19",
            "url": "https://bsky.app/profile/ninjaowl.ai/post/3mqxim6htkn2o",
            "origin": true,
            "authority": false,
            "github": []
          },
          {
            "handle": "lobsters-feed.bsky.social",
            "displayName": "The Lobste.rs RSS feed",
            "likes": 1,
            "reposts": 0,
            "replies": 0,
            "createdAt": "2026-07-18",
            "url": "https://bsky.app/profile/lobsters-feed.bsky.social/post/3mqwvioehke2o",
            "origin": true,
            "authority": false,
            "github": []
          }
        ]
      },
      "telegram": {
        "mentions": 12,
        "reach": 50074,
        "posts": [
          {
            "channel": "thehackernews",
            "channelTitle": "The Hacker News",
            "tier": "news",
            "date": "2026-07-18",
            "views": 9529,
            "forwards": 78,
            "url": "https://t.me/thehackernews/9544",
            "text": "⚡ UPDATE: #wp2shell now has two CVEs, and a working proof-of-concept is public. > CVE-2026-63030 breaks REST batch routing > CVE-2026-60137 injects SQL Chained, they give an anonymous attacker code execution on affected WordPress sites. How the exploit path works: https://thehackernews.com/2026/07/new-wp2shell-wordpress-core-flaw-lets.html",
            "github": [],
            "origin": false
          }
        ]
      }
    },
    {
      "cve": "CVE-2026-0770",
      "title": "Langflow Inclusion of Functionality from Untrusted Control Sphere Vulnerability",
      "category": "Langflow",
      "vendor": "Langflow",
      "product": "Langflow",
      "exploited": true,
      "publiclyDisclosed": false,
      "faq": "Langflow contains an inclusion of functionality from untrusted control sphere vulnerability that allows remote attackers to execute arbitrary code on affected installations. ",
      "cvss": 9.8,
      "cvssVector": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "severity": "CRITICAL",
      "impact": null,
      "products": [
        "Langflow"
      ],
      "productCount": 1,
      "mitreUrl": "https://nvd.nist.gov/vuln/detail/CVE-2026-0770",
      "source": "kev",
      "kev": {
        "dateAdded": "2026-07-21",
        "dueDate": "2026-07-24",
        "requiredAction": "Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.",
        "ransomware": false,
        "cwes": [
          "CWE-829"
        ],
        "references": [
          "https://github.com/langflow-ai/langflow/releases/tag/v1.9.0",
          "https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk",
          "https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk",
          "https://nvd.nist.gov/vuln/detail/CVE-2026-0770"
        ]
      },
      "epss": 0.10371,
      "epssPercentile": 0.95225,
      "pocCount": 2,
      "pocTopStars": 0,
      "pocConfidence": "confirmed",
      "pocRepos": [
        {
          "url": "https://github.com/Ez4rd1x1/CVE-2026-0770",
          "stars": 0,
          "desc": "LangFlow RCE | CVE-2026-0770 | Proof-Of-Concept",
          "createdAt": "2026-05-15",
          "hasCode": true
        },
        {
          "url": "https://github.com/diamorphine666/CVE-2026-0770",
          "stars": 0,
          "desc": "Langflow remote code execution exploit",
          "createdAt": "2026-05-23",
          "hasCode": true
        }
      ],
      "published": "2026-01-23T04:16:04.063",
      "corroboration": {
        "poc": true,
        "xOrigin": false,
        "independent": [
          "poc"
        ],
        "level": "multi-source"
      },
      "research": [
        {
          "url": "https://github.com/langflow-ai/langflow/security/advisories/GHSA-vwmf-pq79-vjvx",
          "type": "writeup",
          "source": "langflow GHSA",
          "note": "Unauth RCE via public flow build endpoint",
          "hasCode": true
        },
        {
          "url": "https://www.exploit-db.com/exploits/52597",
          "type": "poc",
          "source": "Exploit-DB",
          "note": "Langflow 1.3.0 RCE exploit"
        },
        {
          "url": "https://github.com/affix/CVE-2026-0770-PoC",
          "type": "poc",
          "source": "affix",
          "note": "PoC for Langflow RCE via validate_code",
          "hasCode": true
        },
        {
          "url": "https://github.com/0xgh057r3c0n/CVE-2026-0770",
          "type": "poc",
          "source": "0xgh057r3c0n",
          "note": "RCE PoC exec_globals exec()",
          "hasCode": true
        }
      ],
      "aliases": [],
      "researchers": [
        "affix",
        "0xgh057r3c0n"
      ],
      "x": {
        "mentions": 4,
        "posts": [
          {
            "handle": "pdnuclei_bot",
            "followers": 949,
            "likes": 5,
            "createdAt": "2026-02-22",
            "url": "https://x.com/pdnuclei_bot/status/2025707211205517544",
            "origin": false,
            "github": []
          },
          {
            "handle": "transilienceai",
            "followers": 332,
            "likes": 0,
            "createdAt": "2026-02-22",
            "url": "https://x.com/transilienceai/status/2025413138925908276",
            "origin": false,
            "github": []
          },
          {
            "handle": "CVEnew",
            "followers": 57565,
            "likes": 0,
            "createdAt": "2026-01-23",
            "url": "https://x.com/CVEnew/status/2014576951957315822",
            "origin": false,
            "github": []
          },
          {
            "handle": "CveFindCom",
            "followers": 620,
            "likes": 0,
            "createdAt": "2026-01-23",
            "url": "https://x.com/CveFindCom/status/2014558758748270784",
            "origin": false,
            "github": []
          }
        ],
        "aliases": []
      },
      "bsky": {
        "mentions": 6,
        "posts": [
          {
            "handle": "beikokucyber.bsky.social",
            "displayName": "Beikoku Cybersecurity",
            "likes": 0,
            "reposts": 0,
            "replies": 0,
            "createdAt": "2026-02-23",
            "url": "https://bsky.app/profile/beikokucyber.bsky.social/post/3mfkkg736ie2h",
            "origin": false,
            "authority": false,
            "github": []
          },
          {
            "handle": "thehackerwire.bsky.social",
            "displayName": "TheHackerWire",
            "likes": 0,
            "reposts": 0,
            "replies": 0,
            "createdAt": "2026-01-23",
            "url": "https://bsky.app/profile/thehackerwire.bsky.social/post/3md2zecuky22h",
            "origin": false,
            "authority": false,
            "github": []
          },
          {
            "handle": "cve.skyfleet.blue",
            "displayName": "CVE Alerts ",
            "likes": 0,
            "reposts": 0,
            "replies": 0,
            "createdAt": "2026-01-23",
            "url": "https://bsky.app/profile/cve.skyfleet.blue/post/3md3bcrstqg2c",
            "origin": false,
            "authority": false,
            "github": []
          }
        ]
      },
      "telegram": {
        "mentions": 0,
        "posts": []
      }
    },
    {
      "cve": "CVE-2021-27137",
      "title": "DD-WRT Stack-Based Buffer Overflow Vulnerability",
      "category": "DD-WRT",
      "vendor": "DD-WRT",
      "product": "DD-WRT",
      "exploited": true,
      "publiclyDisclosed": false,
      "faq": "DD-WRT contains a stack-based buffer overflow vulnerability that could allow an unauthenticated attacker to overflow an internal buffer used by UPnP and trigger a code execution vulnerability.",
      "cvss": 8.1,
      "cvssVector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "severity": "HIGH",
      "impact": null,
      "products": [
        "DD-WRT"
      ],
      "productCount": 1,
      "mitreUrl": "https://nvd.nist.gov/vuln/detail/CVE-2021-27137",
      "source": "kev",
      "kev": {
        "dateAdded": "2026-07-21",
        "dueDate": "2026-07-24",
        "requiredAction": "Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.",
        "ransomware": false,
        "cwes": [
          "CWE-121"
        ],
        "references": [
          "https://svn.dd-wrt.com/changeset/45724",
          "https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk",
          "https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk",
          "https://nvd.nist.gov/vuln/detail/CVE-2021-27137"
        ]
      },
      "epss": 0.05447,
      "epssPercentile": 0.91861,
      "pocCount": 0,
      "pocTopStars": 0,
      "pocConfidence": "none",
      "pocRepos": [],
      "published": "2026-07-16T18:16:39.113",
      "corroboration": {
        "poc": false,
        "xOrigin": false,
        "independent": [],
        "level": "cisa-attributed"
      },
      "research": [
        {
          "url": "https://ssd-disclosure.com/ssd-advisory-dd-wrt-upnp-buffer-overflow/",
          "type": "writeup",
          "source": "SSD Secure Disclosure / Selim Enes Karaduman",
          "note": "Original advisory; vuln analysis + PoC trigger"
        },
        {
          "url": "https://github.com/tzwlhack/Vulnerability/blob/main/DD-WRT%20%E7%BC%93%E5%86%B2%E5%8C%BA%E6%BA%A2%E5%87%BA%E6%BC%8F%E6%B4%9E%EF%BC%88CVE-2021-27137%EF%BC%89.md",
          "type": "poc",
          "source": "GitHub / tzwlhack",
          "note": "Python UDP M-SEARCH PoC; 164-byte ST:uuid overflow",
          "hasCode": false
        },
        {
          "url": "https://github.com/JianrongXiao-Linksys/miscellaneous",
          "type": "poc",
          "source": "GitHub / JianrongXiao-Linksys",
          "note": "miniupnpd exploit test tool for CVE-2021-27137",
          "hasCode": true
        },
        {
          "url": "https://www.fortinet.com/blog/threat-research/inside-cross-platform-propagation-of-new-gafgyt-variant-c0xmo",
          "type": "writeup",
          "source": "FortiGuard Labs / Fortinet",
          "note": "C0XMO botnet; deep analysis of CVE-2021-27137 exploitation"
        },
        {
          "url": "https://www.onekey.com/resource/broadcom-sdk-vulnerabilities-bug-reports",
          "type": "writeup",
          "source": "ONEKEY Research",
          "note": "Broadcom SDK supply-chain context; CVE-2021-27137 noted"
        },
        {
          "url": "https://www.fortiguard.com/encyclopedia/ips/56117",
          "type": "detection",
          "source": "Fortinet FortiGuard IPS",
          "note": "IPS signature: DD-WRT.UPNP.CVE-2021-27137.uuid.Buffer.Overflow"
        },
        {
          "url": "https://www.cisa.gov/news-events/alerts/2026/07/21/cisa-adds-four-known-exploited-vulnerabilities-catalog",
          "type": "detection",
          "source": "CISA KEV Catalog",
          "note": "Added to KEV 2026-07-21; active exploitation confirmed"
        },
        {
          "url": "https://svn.dd-wrt.com/changeset/45724",
          "type": "detection",
          "source": "DD-WRT SVN / vendor patch",
          "note": "Official vendor fix; changeset 45724 patches ssdp.c strcpy"
        }
      ],
      "aliases": [],
      "researchers": [
        "Enesdex"
      ],
      "x": {
        "mentions": 15,
        "engagement": 6,
        "aliases": [],
        "posts": [
          {
            "handle": "__kokumoto",
            "followers": 7584,
            "likes": 3,
            "reposts": 0,
            "quotes": 0,
            "impressions": 571,
            "createdAt": "2026-07-21",
            "url": "https://x.com/__kokumoto/status/2079701986791100440",
            "github": [],
            "origin": false
          },
          {
            "handle": "FR13ND0x7F",
            "followers": 448,
            "likes": 1,
            "reposts": 0,
            "quotes": 0,
            "impressions": 332,
            "createdAt": "2026-07-10",
            "url": "https://x.com/FR13ND0x7F/status/2075698831061307495",
            "github": [],
            "origin": false
          },
          {
            "handle": "r0otk3r",
            "followers": 43,
            "likes": 1,
            "reposts": 0,
            "quotes": 0,
            "impressions": 68,
            "createdAt": "2026-07-12",
            "url": "https://x.com/r0otk3r/status/2076270600591495492",
            "github": [],
            "origin": false
          },
          {
            "handle": "AseemShrey",
            "followers": 8793,
            "likes": 0,
            "reposts": 0,
            "quotes": 0,
            "impressions": 94,
            "createdAt": "2026-07-15",
            "url": "https://x.com/AseemShrey/status/2077224685767630991",
            "github": [],
            "origin": false
          },
          {
            "handle": "SecAlertsCo",
            "followers": 858,
            "likes": 0,
            "reposts": 0,
            "quotes": 0,
            "impressions": 73,
            "createdAt": "2026-07-21",
            "url": "https://x.com/SecAlertsCo/status/2079607270300598376",
            "github": [],
            "origin": false
          },
          {
            "handle": "lexs17",
            "followers": 187,
            "likes": 0,
            "reposts": 0,
            "quotes": 0,
            "impressions": 185,
            "createdAt": "2026-07-13",
            "url": "https://x.com/lexs17/status/2076597065199636958",
            "github": [],
            "origin": false
          },
          {
            "handle": "VistemSolutions",
            "followers": 79,
            "likes": 0,
            "reposts": 0,
            "quotes": 0,
            "impressions": 15,
            "createdAt": "2026-07-21",
            "url": "https://x.com/VistemSolutions/status/2079705493149307216",
            "github": [],
            "origin": false
          },
          {
            "handle": "0xMetaLabs",
            "followers": 67,
            "likes": 0,
            "reposts": 0,
            "quotes": 0,
            "impressions": 27,
            "createdAt": "2026-07-15",
            "url": "https://x.com/0xMetaLabs/status/2077397923068067971",
            "github": [],
            "origin": false
          }
        ]
      },
      "bsky": {
        "mentions": 11,
        "engagement": 0,
        "posts": [
          {
            "handle": "thecybermind.co",
            "displayName": "mikeransier.bsky.social",
            "likes": 0,
            "reposts": 0,
            "replies": 0,
            "createdAt": "2026-07-22",
            "url": "https://bsky.app/profile/thecybermind.co/post/3mr7giaghtj24",
            "origin": false,
            "authority": true,
            "github": []
          },
          {
            "handle": "cyberhub.blog",
            "displayName": "CyberHub",
            "likes": 0,
            "reposts": 0,
            "replies": 0,
            "createdAt": "2026-07-22",
            "url": "https://bsky.app/profile/cyberhub.blog/post/3mr7agdtno72s",
            "origin": false,
            "authority": false,
            "github": []
          },
          {
            "handle": "termsofsurrender.bsky.social",
            "displayName": "AfterShock Index",
            "likes": 0,
            "reposts": 0,
            "replies": 0,
            "createdAt": "2026-07-22",
            "url": "https://bsky.app/profile/termsofsurrender.bsky.social/post/3mr7joxowrf2g",
            "origin": false,
            "authority": false,
            "github": []
          },
          {
            "handle": "cvesentinel.bsky.social",
            "displayName": "CVESentinel",
            "likes": 0,
            "reposts": 0,
            "replies": 0,
            "createdAt": "2026-07-21",
            "url": "https://bsky.app/profile/cvesentinel.bsky.social/post/3mr62lvr2v72h",
            "origin": false,
            "authority": false,
            "github": []
          },
          {
            "handle": "happeningnow.news",
            "displayName": "HappeningNow",
            "likes": 0,
            "reposts": 0,
            "replies": 0,
            "createdAt": "2026-07-21",
            "url": "https://bsky.app/profile/happeningnow.news/post/3mr6akwgum72q",
            "origin": false,
            "authority": false,
            "github": []
          },
          {
            "handle": "cve.skyfleet.blue",
            "displayName": "CVE Alerts ",
            "likes": 0,
            "reposts": 0,
            "replies": 0,
            "createdAt": "2026-07-16",
            "url": "https://bsky.app/profile/cve.skyfleet.blue/post/3mqrwzmanf62c",
            "origin": false,
            "authority": false,
            "github": []
          }
        ]
      },
      "telegram": {
        "mentions": 1,
        "reach": 127,
        "posts": [
          {
            "channel": "VulnerabilityNews",
            "channelTitle": "Vulnerability News",
            "tier": "news",
            "date": "2026-07-21",
            "views": 126,
            "forwards": 1,
            "url": "https://t.me/VulnerabilityNews/43589",
            "text": "CISA Adds Four Known Exploited Vulnerabilities to Catalog CISA has added four new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation. CVE-2021-27137 DD-WRT Stack-Based Buffer Overflow Vulnerability CVE-2026-0770 Langflow Inclusion of Functionality from Untrusted Control Sphere Vulnerability CVE-2026-63030 WordPress Core Interpretation Con",
            "github": [],
            "origin": false
          }
        ]
      }
    },
    {
      "cve": "CVE-2026-58644",
      "title": "Microsoft SharePoint Deserialization of Untrusted Data Vulnerability",
      "category": "Microsoft",
      "vendor": "Microsoft",
      "product": "SharePoint",
      "exploited": true,
      "publiclyDisclosed": false,
      "faq": "Microsoft SharePoint contains a deserialization of untrusted data vulnerability that allows an unauthorized attacker to execute code over a network.",
      "cvss": 9.8,
      "cvssVector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "severity": "CRITICAL",
      "impact": null,
      "products": [
        "SharePoint"
      ],
      "productCount": 1,
      "mitreUrl": "https://nvd.nist.gov/vuln/detail/CVE-2026-58644",
      "source": "kev",
      "kev": {
        "dateAdded": "2026-07-16",
        "dueDate": "2026-07-19",
        "requiredAction": "Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.",
        "ransomware": false,
        "cwes": [
          "CWE-502"
        ],
        "references": [
          "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-58644",
          "https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk",
          "https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk",
          "https://nvd.nist.gov/vuln/detail/CVE-2026-58644"
        ]
      },
      "epss": 0.01465,
      "epssPercentile": 0.70792,
      "pocCount": 0,
      "pocTopStars": 0,
      "pocConfidence": "none",
      "pocRepos": [],
      "published": "2026-07-14T17:17:14.257",
      "research": [
        {
          "url": "https://www.zerodayinitiative.com/blog/2026/7/14/the-july-2026-security-update-review",
          "type": "writeup",
          "source": "Zero Day Initiative (ZDI)",
          "note": "ZDI review; CVE-2026-50522 sibling demoed at Pwn2Own Berlin"
        },
        {
          "url": "https://www.rapid7.com/blog/post/etr-cve-2026-58644-microsoft-sharepoint-server-unauthenticated-remote-code-execution-vulnerability-exploited-in-the-wild/",
          "type": "writeup",
          "source": "Rapid7",
          "note": "ETR: unauthenticated RCE, KEV-listed, CVSS 9.8"
        },
        {
          "url": "https://hivesecurity.gitlab.io/blog/cve-2026-58644-sharepoint-rce-incident-response/",
          "type": "writeup",
          "source": "Hive Security",
          "note": "IR-focused writeup; CWE-502, patch + compromise assessment"
        },
        {
          "url": "https://www.penligent.ai/hackinglabs/cve-2026-58644/",
          "type": "writeup",
          "source": "Penligent",
          "note": "Technical deserialization deep-dive + detection guidance"
        },
        {
          "url": "https://www.cisa.gov/news-events/alerts/2026/07/14/cisa-urges-sharepoint-hardening-after-new-exploitations",
          "type": "detection",
          "source": "CISA",
          "note": "Official hardening alert; KEV added Jul 16, 2026"
        },
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-58644",
          "type": "detection",
          "source": "Microsoft MSRC",
          "note": "Vendor advisory; patches KB5002653/54/55 per version"
        },
        {
          "url": "https://cvefeed.io/vuln/detail/CVE-2026-58644",
          "type": "detection",
          "source": "CVEfeed.io",
          "note": "Aggregator; lists 7 GitHub PoCs (tab-gated, no direct URLs)"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-58644",
          "type": "detection",
          "source": "NIST NVD",
          "note": "Official NVD entry; CWE-502, CVSS 9.8 Critical"
        }
      ],
      "x": {
        "mentions": 1,
        "aliases": [],
        "posts": [
          {
            "handle": "MalwareBibleJP",
            "followers": 7678,
            "likes": 2,
            "createdAt": "2026-07-19",
            "url": "https://x.com/MalwareBibleJP/status/2078884829123445001",
            "github": [],
            "origin": false
          }
        ]
      },
      "bsky": {
        "mentions": 21,
        "posts": [
          {
            "handle": "thecybermind.co",
            "displayName": "mikeransier.bsky.social",
            "likes": 0,
            "reposts": 0,
            "replies": 0,
            "createdAt": "2026-07-20",
            "url": "https://bsky.app/profile/thecybermind.co/post/3mr37da5yae2y",
            "origin": false,
            "authority": true,
            "github": []
          },
          {
            "handle": "infosec.skyfleet.blue",
            "displayName": "InfoSec",
            "likes": 0,
            "reposts": 0,
            "replies": 0,
            "createdAt": "2026-07-17",
            "url": "https://bsky.app/profile/infosec.skyfleet.blue/post/3mqtcaanzzb2m",
            "origin": false,
            "authority": true,
            "github": []
          },
          {
            "handle": "kotosecurity.bsky.social",
            "displayName": null,
            "likes": 0,
            "reposts": 0,
            "replies": 1,
            "createdAt": "2026-07-18",
            "url": "https://bsky.app/profile/kotosecurity.bsky.social/post/3mqx5yozm2c2o",
            "origin": false,
            "authority": false,
            "github": []
          },
          {
            "handle": "vulnsea.com",
            "displayName": "VulnSea",
            "likes": 1,
            "reposts": 0,
            "replies": 0,
            "createdAt": "2026-07-17",
            "url": "https://bsky.app/profile/vulnsea.com/post/3mqun3imxcw2r",
            "origin": false,
            "authority": false,
            "github": []
          },
          {
            "handle": "cyberhub.blog",
            "displayName": "CyberHub",
            "likes": 1,
            "reposts": 0,
            "replies": 0,
            "createdAt": "2026-07-16",
            "url": "https://bsky.app/profile/cyberhub.blog/post/3mqqay4r2mv2t",
            "origin": false,
            "authority": false,
            "github": []
          },
          {
            "handle": "aegisbot.bsky.social",
            "displayName": "AEGIS // Threat Intel",
            "likes": 0,
            "reposts": 0,
            "replies": 0,
            "createdAt": "2026-07-20",
            "url": "https://bsky.app/profile/aegisbot.bsky.social/post/3mr3aoxg4hh2o",
            "origin": false,
            "authority": false,
            "github": []
          }
        ]
      },
      "corroboration": {
        "poc": false,
        "xOrigin": false,
        "independent": [
          "x-mention"
        ],
        "level": "multi-source"
      },
      "aliases": [],
      "researchers": [],
      "telegram": {
        "mentions": 1,
        "reach": 6625,
        "posts": [
          {
            "channel": "thehackernews",
            "channelTitle": "The Hacker News",
            "tier": "news",
            "date": "2026-07-17",
            "views": 6598,
            "forwards": 27,
            "url": "https://t.me/thehackernews/9531",
            "text": "Microsoft patched a SharePoint flaw after attackers had already exploited it as a zero-day. CVE-2026-58644 affects every supported on-premises SharePoint version and can lead to remote code execution. CISA has now added it to KEV. Here's what SharePoint admins need to check: https://thehackernews.com/2026/07/cisa-adds-exploited-sharepoint-rce-zero.html",
            "github": [],
            "origin": false
          }
        ]
      }
    },
    {
      "cve": "CVE-2026-25089",
      "title": "Fortinet FortiSandbox OS Command Injection Vulnerability",
      "category": "Fortinet",
      "vendor": "Fortinet",
      "product": "FortiSandbox",
      "exploited": true,
      "publiclyDisclosed": false,
      "faq": "Fortinet FortiSandbox, FortiSandbox Cloud, and FortiSandbox PaaS contain an OS command injection vulnerability that allows an unauthenticated attacker to execute unauthorized commands via specifically crafted HTTP requests.",
      "cvss": 9.8,
      "cvssVector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "severity": "CRITICAL",
      "impact": null,
      "products": [
        "FortiSandbox"
      ],
      "productCount": 1,
      "mitreUrl": "https://nvd.nist.gov/vuln/detail/CVE-2026-25089",
      "source": "kev",
      "kev": {
        "dateAdded": "2026-07-16",
        "dueDate": "2026-07-19",
        "requiredAction": "Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.",
        "ransomware": false,
        "cwes": [
          "CWE-78"
        ],
        "references": [
          "https://fortiguard.fortinet.com/psirt/FG-IR-26-141",
          "https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk",
          "https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk",
          "https://nvd.nist.gov/vuln/detail/CVE-2026-25089"
        ]
      },
      "epss": 0.36135,
      "epssPercentile": 0.98311,
      "pocCount": 2,
      "pocTopStars": 6,
      "pocConfidence": "confirmed",
      "pocRepos": [
        {
          "url": "https://github.com/HORKimhab/CVE-2026-25089",
          "stars": 6,
          "desc": "CVE-2026-25089 - Fortinet FortiSandbox",
          "createdAt": "2026-06-10",
          "hasCode": true
        },
        {
          "url": "https://github.com/0xBlackash/CVE-2026-25089",
          "stars": 2,
          "desc": "CVE-2026-25089",
          "createdAt": "2026-06-12",
          "hasCode": true
        }
      ],
      "published": "2026-06-09T16:16:39.943",
      "research": [
        {
          "url": "https://www.fortiguard.com/psirt/FG-IR-26-141",
          "type": "writeup",
          "source": "Fortinet PSIRT (official advisory)",
          "note": "Official vendor advisory; second-order OS cmd injection"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-25089",
          "type": "detection",
          "source": "NVD / NIST",
          "note": "NVD entry; CVSS 9.8 critical, CWE-78 confirmed"
        },
        {
          "url": "https://www.tenable.com/cve/CVE-2026-25089",
          "type": "detection",
          "source": "Tenable Research",
          "note": "Tenable Vulnerability Watch classification entry"
        },
        {
          "url": "https://cybersecuritynews.com/fortinet-fortisandbox-vulnerability-exploited/",
          "type": "writeup",
          "source": "CyberSecurityNews",
          "note": "Technical breakdown; reporter: Adham El Karn (Fortinet)"
        },
        {
          "url": "https://thehackernews.com/2026/06/ivanti-fortinet-and-sap-release-patches.html",
          "type": "writeup",
          "source": "The Hacker News",
          "note": "Patch context; FortiSandbox Web UI unauthenticated RCE"
        },
        {
          "url": "https://securityaffairs.com/193509/security/fortinet-patched-a-new-critical-fortisandbox-flaw.html",
          "type": "writeup",
          "source": "Security Affairs / Pierluigi Paganini",
          "note": "Summary writeup; no in-the-wild exploitation reported"
        },
        {
          "url": "https://github.com/nomi-sec/PoC-in-GitHub/blob/master/2026/CVE-2026-25089.json",
          "type": "poc",
          "source": "nomi-sec/PoC-in-GitHub (aggregator)",
          "note": "GitHub PoC tracker entry; underlying repo unresolved",
          "hasCode": false
        },
        {
          "url": "https://www.csa.gov.sg/alerts-and-advisories/alerts/al-2026-073/",
          "type": "detection",
          "source": "Cyber Security Agency of Singapore (CSA)",
          "note": "Government alert urging immediate patch application"
        }
      ],
      "x": {
        "mentions": 3,
        "aliases": [],
        "posts": [
          {
            "handle": "ptdbugs",
            "followers": 1502,
            "likes": 61,
            "createdAt": "2026-06-11",
            "url": "https://x.com/ptdbugs/status/2065015711924142538",
            "github": [],
            "origin": false
          },
          {
            "handle": "CCBalert",
            "followers": 7212,
            "likes": 0,
            "createdAt": "2026-06-11",
            "url": "https://x.com/CCBalert/status/2065075395901194533",
            "github": [],
            "origin": false
          },
          {
            "handle": "YogSoth0",
            "followers": 671,
            "likes": 0,
            "createdAt": "2026-06-10",
            "url": "https://x.com/YogSoth0/status/2064838632352239892",
            "github": [],
            "origin": false
          }
        ]
      },
      "bsky": {
        "mentions": 18,
        "posts": [
          {
            "handle": "iberianm.bsky.social",
            "displayName": "Citizen X",
            "likes": 0,
            "reposts": 1,
            "replies": 1,
            "createdAt": "2026-06-13",
            "url": "https://bsky.app/profile/iberianm.bsky.social/post/3mo67fgsf7n2r",
            "origin": false,
            "authority": false,
            "github": []
          },
          {
            "handle": "o2cloud.bsky.social",
            "displayName": "CVE by o2Cloud",
            "likes": 0,
            "reposts": 1,
            "replies": 1,
            "createdAt": "2026-06-10",
            "url": "https://bsky.app/profile/o2cloud.bsky.social/post/3mnws6ecbbi2y",
            "origin": false,
            "authority": false,
            "github": []
          },
          {
            "handle": "blackhatnews.tokyo",
            "displayName": "blackhatnews.tokyo",
            "likes": 0,
            "reposts": 1,
            "replies": 0,
            "createdAt": "2026-06-17",
            "url": "https://bsky.app/profile/blackhatnews.tokyo/post/3mohquqzh6a2d",
            "origin": false,
            "authority": false,
            "github": []
          },
          {
            "handle": "securitycyberuk.bsky.social",
            "displayName": "Security Cyber",
            "likes": 0,
            "reposts": 1,
            "replies": 0,
            "createdAt": "2026-06-10",
            "url": "https://bsky.app/profile/securitycyberuk.bsky.social/post/3mnx3gfta3s2d",
            "origin": false,
            "authority": false,
            "github": []
          },
          {
            "handle": "postac001.bsky.social",
            "displayName": "tec_acc",
            "likes": 0,
            "reposts": 1,
            "replies": 0,
            "createdAt": "2026-06-10",
            "url": "https://bsky.app/profile/postac001.bsky.social/post/3mnxbqhtuxe2r",
            "origin": false,
            "authority": false,
            "github": []
          },
          {
            "handle": "technoholic.bsky.social",
            "displayName": "Technoholic.me",
            "likes": 0,
            "reposts": 0,
            "replies": 0,
            "createdAt": "2026-06-19",
            "url": "https://bsky.app/profile/technoholic.bsky.social/post/3moo3csgxk42f",
            "origin": false,
            "authority": false,
            "github": []
          }
        ]
      },
      "corroboration": {
        "poc": true,
        "xOrigin": false,
        "independent": [
          "poc",
          "x-mention"
        ],
        "level": "multi-source"
      },
      "aliases": [],
      "researchers": [],
      "telegram": {
        "mentions": 0,
        "posts": []
      }
    },
    {
      "cve": "CVE-2026-39808",
      "title": "Fortinet FortiSandbox OS Command Injection Vulnerability",
      "category": "Fortinet",
      "vendor": "Fortinet",
      "product": "FortiSandbox",
      "exploited": true,
      "publiclyDisclosed": false,
      "faq": "Fortinet FortiSandbox contains an OS command injection vulnerability that could allow an unauthenticated attacker to execute unauthorized code or commands via crafted HTTP requests.",
      "cvss": 9.8,
      "cvssVector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "severity": "CRITICAL",
      "impact": null,
      "products": [
        "FortiSandbox"
      ],
      "productCount": 1,
      "mitreUrl": "https://nvd.nist.gov/vuln/detail/CVE-2026-39808",
      "source": "kev",
      "kev": {
        "dateAdded": "2026-07-16",
        "dueDate": "2026-07-19",
        "requiredAction": "Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.",
        "ransomware": false,
        "cwes": [
          "CWE-78"
        ],
        "references": [
          "https://fortiguard.fortinet.com/psirt/FG-IR-26-100",
          "https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk",
          "https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk",
          "https://nvd.nist.gov/vuln/detail/CVE-2026-39808"
        ]
      },
      "epss": 0.84158,
      "epssPercentile": 0.99668,
      "pocCount": 1,
      "pocTopStars": 0,
      "pocConfidence": "confirmed",
      "pocRepos": [
        {
          "url": "https://github.com/error-inside/CVE-2026-39808",
          "stars": 0,
          "desc": "Fortinet FortiSandbox 4.4.0-4.4.8 - OS Command Injection via tracer-behavior Endpoint",
          "createdAt": "2026-06-18",
          "hasCode": true
        },
        {
          "url": "https://github.com/HORKimhab/CVE-2026-39808",
          "stars": 0,
          "desc": "CVE-2026-39808 - Fortinet Sandbox - Draft",
          "createdAt": "2026-06-17",
          "hasCode": false
        }
      ],
      "published": "2026-04-14T16:16:44.860",
      "research": [
        {
          "url": "https://github.com/samu-delucas/CVE-2026-39808",
          "type": "poc",
          "source": "GitHub / samu-delucas",
          "note": "Primary PoC; unauthenticated RCE as root via jid param",
          "hasCode": false
        },
        {
          "url": "https://github.com/ynsmroztas/FortiSandbox-RCE-Exploit-CVE-2026-39808",
          "type": "poc",
          "source": "GitHub / ynsmroztas (mitsec)",
          "note": "Python RCE scanner; canary verify + Shodan dorks",
          "hasCode": true
        },
        {
          "url": "https://github.com/error-inside/CVE-2026-39808",
          "type": "poc",
          "source": "GitHub / error-inside",
          "note": "Two-step inject+verify PoC, tracer-behavior endpoint",
          "hasCode": true
        },
        {
          "url": "https://github.com/0xBlackash/CVE-2026-39808",
          "type": "poc",
          "source": "GitHub / 0xBlackash",
          "note": "Documented PoC; sandbox escape to root (uid=0)",
          "hasCode": true
        },
        {
          "url": "https://github.com/projectdiscovery/nuclei-templates/releases",
          "type": "module",
          "source": "ProjectDiscovery / dhiyaneshdk",
          "note": "Nuclei template [CVE-2026-39808] critical, April 2026",
          "hasCode": true
        },
        {
          "url": "https://fortiguard.fortinet.com/psirt/FG-IR-26-100",
          "type": "writeup",
          "source": "Fortinet PSIRT",
          "note": "Official advisory FG-IR-26-100; affected versions+patch"
        },
        {
          "url": "https://www.crowdsec.net/vulntracking-report/cve-2026-39808-fortinet-fortisandbox-command-injection",
          "type": "detection",
          "source": "CrowdSec",
          "note": "Detection rule + 49 IPs tracked; early exploitation report"
        },
        {
          "url": "https://projectdiscovery.io/blog/nuclei-templates-april-2026",
          "type": "writeup",
          "source": "ProjectDiscovery Blog",
          "note": "April 2026 Nuclei templates release; CVE-2026-39808 listed"
        }
      ],
      "x": {
        "mentions": 79,
        "aliases": [],
        "posts": [
          {
            "handle": "MalwareObserver",
            "followers": 11,
            "likes": 0,
            "createdAt": "2026-07-20",
            "url": "https://x.com/MalwareObserver/status/2079280525265514912",
            "github": [
              {
                "url": "https://github.com/chamilo/chamilo-lms/security/advisories/GHSA-gcjp-f7jm-rrrg",
                "hasCode": true
              },
              {
                "url": "https://github.com/chamilo/chamilo-lms/security/advisories/GHSA-gcjp-f7jm-rrrg",
                "hasCode": true
              }
            ],
            "origin": false
          },
          {
            "handle": "geovexintel",
            "followers": 999,
            "likes": 17,
            "createdAt": "2026-07-20",
            "url": "https://x.com/geovexintel/status/2079263366049063306",
            "github": [],
            "origin": false
          },
          {
            "handle": "0x0SojalSec",
            "followers": 47743,
            "likes": 12,
            "createdAt": "2026-07-20",
            "url": "https://x.com/0x0SojalSec/status/2079262255892603372",
            "github": [],
            "origin": false
          },
          {
            "handle": "NetSPI",
            "followers": 4074,
            "likes": 11,
            "createdAt": "2026-07-20",
            "url": "https://x.com/NetSPI/status/2079265470633381982",
            "github": [],
            "origin": false
          },
          {
            "handle": "MalwareBibleJP",
            "followers": 7678,
            "likes": 6,
            "createdAt": "2026-07-20",
            "url": "https://x.com/MalwareBibleJP/status/2079323720771088529",
            "github": [],
            "origin": false
          },
          {
            "handle": "ptdbugs",
            "followers": 2491,
            "likes": 5,
            "createdAt": "2026-07-20",
            "url": "https://x.com/ptdbugs/status/2079264509483515990",
            "github": [],
            "origin": false
          },
          {
            "handle": "LupovisDefence",
            "followers": 575,
            "likes": 5,
            "createdAt": "2026-07-20",
            "url": "https://x.com/LupovisDefence/status/2079290355443269739",
            "github": [],
            "origin": false
          },
          {
            "handle": "thingwhere",
            "followers": 8,
            "likes": 4,
            "createdAt": "2026-07-20",
            "url": "https://x.com/thingwhere/status/2079330106921607615",
            "github": [],
            "origin": false
          }
        ]
      },
      "bsky": {
        "mentions": 18,
        "posts": [
          {
            "handle": "infosec.skyfleet.blue",
            "displayName": "InfoSec",
            "likes": 1,
            "reposts": 1,
            "replies": 0,
            "createdAt": "2026-04-16",
            "url": "https://bsky.app/profile/infosec.skyfleet.blue/post/3mjmw4zfxor22",
            "origin": false,
            "authority": true,
            "github": []
          },
          {
            "handle": "thecybermind.co",
            "displayName": "mikeransier.bsky.social",
            "likes": 0,
            "reposts": 0,
            "replies": 0,
            "createdAt": "2026-07-20",
            "url": "https://bsky.app/profile/thecybermind.co/post/3mr3cpqhc7y2v",
            "origin": false,
            "authority": true,
            "github": []
          },
          {
            "handle": "kotosecurity.bsky.social",
            "displayName": null,
            "likes": 0,
            "reposts": 0,
            "replies": 1,
            "createdAt": "2026-07-19",
            "url": "https://bsky.app/profile/kotosecurity.bsky.social/post/3mqzogcxreb2x",
            "origin": false,
            "authority": false,
            "github": []
          },
          {
            "handle": "alphahunt.io",
            "displayName": "AlphaHunt Converge",
            "likes": 0,
            "reposts": 0,
            "replies": 1,
            "createdAt": "2026-07-18",
            "url": "https://bsky.app/profile/alphahunt.io/post/3mqwjqujt422d",
            "origin": false,
            "authority": false,
            "github": []
          },
          {
            "handle": "vulnsea.com",
            "displayName": "VulnSea",
            "likes": 1,
            "reposts": 0,
            "replies": 0,
            "createdAt": "2026-07-16",
            "url": "https://bsky.app/profile/vulnsea.com/post/3mqrz3g3qbh26",
            "origin": false,
            "authority": false,
            "github": []
          },
          {
            "handle": "securityrss.bsky.social",
            "displayName": "securityrss.ai",
            "likes": 0,
            "reposts": 0,
            "replies": 0,
            "createdAt": "2026-07-18",
            "url": "https://bsky.app/profile/securityrss.bsky.social/post/3mqwbroccqx27",
            "origin": false,
            "authority": false,
            "github": []
          }
        ]
      },
      "researchers": [
        "samu-delucas",
        "error-inside",
        "0xBlackash",
        "ynsmroztas",
        "dhiyaneshdk"
      ],
      "corroboration": {
        "poc": true,
        "xOrigin": false,
        "independent": [
          "poc",
          "x-mention"
        ],
        "level": "multi-source"
      },
      "aliases": [],
      "telegram": {
        "mentions": 1,
        "reach": 361,
        "posts": [
          {
            "channel": "p3Nt3st3rsTAr",
            "channelTitle": "[CVE Pentester] exploits forum",
            "tier": "underground",
            "date": "2026-04-22",
            "views": 361,
            "forwards": 0,
            "url": "https://t.me/p3Nt3st3rsTAr/24",
            "text": "https://github.com/p3Nt3st3r-sTAr/FortiSandbox-RCE-Exploit-CVE-2026-39808",
            "github": [
              {
                "url": "https://github.com/p3Nt3st3r-sTAr/FortiSandbox-RCE-Exploit-CVE-2026-39808",
                "hasCode": true
              }
            ],
            "origin": true
          }
        ]
      }
    },
    {
      "cve": "CVE-2026-46817",
      "title": "Oracle E-Business Suite Improper Privilege Management Vulnerability",
      "category": "Oracle",
      "vendor": "Oracle",
      "product": "E-Business Suite",
      "exploited": true,
      "publiclyDisclosed": false,
      "faq": "Oracle E-Business Suite contains an improper privilege management vulnerability that allows an unauthenticated attacker with network access via HTTP to compromise Oracle Payments. Successful attacks of this vulnerability can result in takeover of Oracle Payments.",
      "cvss": 9.8,
      "cvssVector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "severity": "CRITICAL",
      "impact": null,
      "products": [
        "E-Business Suite"
      ],
      "productCount": 1,
      "mitreUrl": "https://nvd.nist.gov/vuln/detail/CVE-2026-46817",
      "source": "kev",
      "kev": {
        "dateAdded": "2026-07-15",
        "dueDate": "2026-07-18",
        "requiredAction": "Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.",
        "ransomware": false,
        "cwes": [
          "CWE-269",
          "CWE-287",
          "CWE-306"
        ],
        "references": [
          "https://www.oracle.com/security-alerts/cspumay2026.html",
          "https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk",
          "https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk",
          "https://nvd.nist.gov/vuln/detail/CVE-2026-46817"
        ]
      },
      "epss": 0.01045,
      "epssPercentile": 0.60378,
      "pocCount": 1,
      "pocTopStars": 1,
      "pocConfidence": "confirmed",
      "pocRepos": [
        {
          "url": "https://github.com/0xBlackash/CVE-2026-46817",
          "stars": 1,
          "desc": "CVE-2026-46817",
          "createdAt": "2026-06-29",
          "hasCode": true
        }
      ],
      "published": "2026-05-28T21:16:31.503",
      "research": [
        {
          "url": "https://defusedcyber.com/exploited/cve-2026-46817-oracle-e-business-suite",
          "type": "writeup",
          "source": "Defused Cyber",
          "note": "Honeypot telemetry; first ITW exploit captured Jun 27"
        },
        {
          "url": "https://www.cisa.gov/news-events/alerts/2026/07/15/cisa-adds-two-known-exploited-vulnerabilities-catalog",
          "type": "detection",
          "source": "CISA KEV",
          "note": "Official KEV entry added Jul 15 2026; patch mandate"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-46817",
          "type": "detection",
          "source": "NIST NVD",
          "note": "Official NVD entry; CVSS 9.8, CWE-269/287/306"
        },
        {
          "url": "https://www.oracle.com/security-alerts/cspumay2026.html",
          "type": "detection",
          "source": "Oracle",
          "note": "Vendor advisory; May 2026 CSPU patch source"
        },
        {
          "url": "https://www.helpnetsecurity.com/2026/06/30/oracle-payments-cve-2026-46817-exploitation/",
          "type": "writeup",
          "source": "Help Net Security",
          "note": "Technical detail: ibytransmit XML payload, /etc/passwd"
        },
        {
          "url": "https://rewterz.com/threat-advisory/oracle-e-business-suite-flaw-under-active-exploitation",
          "type": "detection",
          "source": "Rewterz",
          "note": "IOCs: attacker IP, UA string, CODEX_PULL_* scheme"
        },
        {
          "url": "https://dailysecurityreview.com/cyber-security/attackers-hit-oracle-ebs-cve-2026-46817-days-after-patch/",
          "type": "writeup",
          "source": "Daily Security Review",
          "note": "XML DeliveryRequest payload structure described"
        },
        {
          "url": "https://socradar.io/blog/cve-2026-46817-oracle-payments-takeover/",
          "type": "writeup",
          "source": "SOCRadar",
          "note": "Threat intel overview; detection & mitigation guidance"
        }
      ],
      "x": {
        "mentions": 4,
        "aliases": [],
        "posts": [
          {
            "handle": "lyrie_ai",
            "followers": 317,
            "likes": 0,
            "createdAt": "2026-07-19",
            "url": "https://x.com/lyrie_ai/status/2078767126614077730",
            "github": [],
            "origin": false
          }
        ]
      },
      "bsky": {
        "mentions": 22,
        "posts": [
          {
            "handle": "bleepingcomputer.com",
            "displayName": "BleepingComputer",
            "likes": 3,
            "reposts": 5,
            "replies": 0,
            "createdAt": "2026-06-29",
            "url": "https://bsky.app/profile/bleepingcomputer.com/post/3mpgmrwrd2525",
            "origin": false,
            "authority": true,
            "github": []
          },
          {
            "handle": "shadowserver.bsky.social",
            "displayName": "The Shadowserver Foundation",
            "likes": 4,
            "reposts": 2,
            "replies": 1,
            "createdAt": "2026-07-01",
            "url": "https://bsky.app/profile/shadowserver.bsky.social/post/3mpldeactwk2n",
            "origin": false,
            "authority": true,
            "github": []
          },
          {
            "handle": "thecybermind.co",
            "displayName": "mikeransier.bsky.social",
            "likes": 0,
            "reposts": 0,
            "replies": 0,
            "createdAt": "2026-07-19",
            "url": "https://bsky.app/profile/thecybermind.co/post/3mqybdbjmzb2p",
            "origin": false,
            "authority": true,
            "github": []
          },
          {
            "handle": "hacker.at.thenote.app",
            "displayName": "Hacker & Security News",
            "likes": 3,
            "reposts": 1,
            "replies": 0,
            "createdAt": "2026-06-30",
            "url": "https://bsky.app/profile/hacker.at.thenote.app/post/3mpiz6ray5c2a",
            "origin": false,
            "authority": false,
            "github": []
          },
          {
            "handle": "kotosecurity.bsky.social",
            "displayName": null,
            "likes": 0,
            "reposts": 1,
            "replies": 1,
            "createdAt": "2026-07-16",
            "url": "https://bsky.app/profile/kotosecurity.bsky.social/post/3mqrszjfqby23",
            "origin": false,
            "authority": false,
            "github": []
          },
          {
            "handle": "netsecio.bsky.social",
            "displayName": "CyberNetSecIO",
            "likes": 1,
            "reposts": 0,
            "replies": 0,
            "createdAt": "2026-07-17",
            "url": "https://bsky.app/profile/netsecio.bsky.social/post/3mqu6ksj3cd2q",
            "origin": false,
            "authority": false,
            "github": []
          }
        ]
      },
      "corroboration": {
        "poc": true,
        "xOrigin": false,
        "independent": [
          "poc",
          "x-mention"
        ],
        "level": "multi-source"
      },
      "aliases": [],
      "researchers": [],
      "telegram": {
        "mentions": 4,
        "reach": 8816,
        "posts": [
          {
            "channel": "thehackernews",
            "channelTitle": "The Hacker News",
            "tier": "news",
            "date": "2026-06-30",
            "views": 7997,
            "forwards": 19,
            "url": "https://t.me/thehackernews/9362",
            "text": "🚨 Oracle E-Business Suite has a new active exploitation problem. CVE-2026-46817 is a CVSS 9.8 flaw in Oracle Payments that can allow unauthenticated HTTP takeover. No public PoC. Attribution unknown. Read the full report: https://thehackernews.com/2026/06/oracle-e-business-suite-flaw-cve-2026.html",
            "github": [],
            "origin": false
          }
        ]
      }
    },
    {
      "cve": "CVE-2023-4346",
      "title": "KNX Association KNX Protocol Connection Authorization Option 1 Overly Restrictive Account Lockout Mechanism Vulnerability",
      "category": "KNX Association",
      "vendor": "KNX Association",
      "product": "KNX Protocol Connection Authorization Option 1",
      "exploited": true,
      "publiclyDisclosed": false,
      "faq": "KNX Association KNX Protocol Connection Authorization Option 1 contains an overly restrictive account lockout mechanism vulnerability that could allow an attacker to purge all devices without additional security options enabled and set a BCU key to lock the device. ",
      "cvss": 7.5,
      "cvssVector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
      "severity": "HIGH",
      "impact": null,
      "products": [
        "KNX Protocol Connection Authorization Option 1"
      ],
      "productCount": 1,
      "mitreUrl": "https://nvd.nist.gov/vuln/detail/CVE-2023-4346",
      "source": "kev",
      "kev": {
        "dateAdded": "2026-07-15",
        "dueDate": "2026-07-29",
        "requiredAction": "Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.",
        "ransomware": false,
        "cwes": [
          "CWE-645"
        ],
        "references": [
          "https://www.cisa.gov/news-events/ics-advisories/icsa-23-236-01",
          "https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk",
          "https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk",
          "https://nvd.nist.gov/vuln/detail/CVE-2023-4346"
        ]
      },
      "epss": 0.00855,
      "epssPercentile": 0.54365,
      "pocCount": 0,
      "pocTopStars": 0,
      "pocConfidence": "none",
      "pocRepos": [],
      "published": "2023-08-29T20:15:10.300",
      "research": [
        {
          "url": "https://github.com/f0rw4rd/knxunlocker",
          "type": "poc",
          "source": "Felix Eberstaller / Limes Security (GitHub: f0rw4rd)",
          "note": "C# BCU key bruteforcer; dict+full keyspace modes",
          "hasCode": true
        },
        {
          "url": "https://limessecurity.com/en/knxlock/",
          "type": "writeup",
          "source": "Limes Security",
          "note": "Original KNXlock campaign technical advisory (2021/2023)"
        },
        {
          "url": "https://limessecurity.com/en/a-new-twist-in-the-knxlock-attack-campaign/",
          "type": "writeup",
          "source": "Limes Security",
          "note": "2024 update: readable-key variant, KNXunlocker release"
        },
        {
          "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-23-236-01",
          "type": "writeup",
          "source": "CISA ICS-CERT (ICSA-23-236-01)",
          "note": "Official ICS advisory; CVE assigned Aug 2023"
        },
        {
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2023-4346",
          "type": "detection",
          "source": "CISA KEV Catalog",
          "note": "Added to KEV Jul 15 2026; BOD 26-04 deadline Jul 29"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-4346",
          "type": "detection",
          "source": "NIST NVD",
          "note": "NVD entry; CVSS 7.5 HIGH, CWE-645"
        },
        {
          "url": "https://github.com/advisories/GHSA-qccg-qqvh-pq7q",
          "type": "detection",
          "source": "GitHub Advisory Database",
          "note": "GHSA advisory; published Aug 29 2023",
          "hasCode": null
        },
        {
          "url": "https://ccb.belgium.be/advisories/warning-cisa-added-actively-exploited-vulnerability-cve-2023-4346-knx-protocol-its-kev",
          "type": "detection",
          "source": "CCB Belgium (Centre for Cybersecurity Belgium)",
          "note": "Defensive advisory; mitigation steps for operators"
        }
      ],
      "x": {
        "mentions": 31,
        "aliases": [
          "KNXlock"
        ],
        "posts": [
          {
            "handle": "CCBalert",
            "followers": 7218,
            "likes": 2,
            "createdAt": "2026-07-16",
            "url": "https://x.com/CCBalert/status/2077778019649736779",
            "github": [],
            "origin": true
          },
          {
            "handle": "8kSec",
            "followers": 3574,
            "likes": 46,
            "createdAt": "2026-07-13",
            "url": "https://x.com/8kSec/status/2076645610120233345",
            "github": [],
            "origin": false
          },
          {
            "handle": "hackyboiz2",
            "followers": 204,
            "likes": 43,
            "createdAt": "2026-07-19",
            "url": "https://x.com/hackyboiz2/status/2078829209955533194",
            "github": [],
            "origin": false
          },
          {
            "handle": "TheHackersNews",
            "followers": 1851846,
            "likes": 34,
            "createdAt": "2026-07-14",
            "url": "https://x.com/TheHackersNews/status/2077055767832883239",
            "github": [],
            "origin": false
          },
          {
            "handle": "ptdbugs",
            "followers": 2491,
            "likes": 31,
            "createdAt": "2026-07-16",
            "url": "https://x.com/ptdbugs/status/2077629794737344696",
            "github": [],
            "origin": false
          },
          {
            "handle": "CISACyber",
            "followers": 299806,
            "likes": 24,
            "createdAt": "2026-07-16",
            "url": "https://x.com/CISACyber/status/2077740069805273518",
            "github": [],
            "origin": false
          },
          {
            "handle": "piyokango",
            "followers": 43826,
            "likes": 15,
            "createdAt": "2026-07-16",
            "url": "https://x.com/piyokango/status/2077888676730958170",
            "github": [],
            "origin": false
          },
          {
            "handle": "MalwareBibleJP",
            "followers": 7678,
            "likes": 14,
            "createdAt": "2026-07-15",
            "url": "https://x.com/MalwareBibleJP/status/2077254587300667443",
            "github": [],
            "origin": false
          }
        ]
      },
      "bsky": {
        "mentions": 8,
        "posts": [
          {
            "handle": "kotosecurity.bsky.social",
            "displayName": null,
            "likes": 1,
            "reposts": 0,
            "replies": 1,
            "createdAt": "2026-07-19",
            "url": "https://bsky.app/profile/kotosecurity.bsky.social/post/3mqzognw3sz2k",
            "origin": true,
            "authority": false,
            "github": []
          },
          {
            "handle": "thecybermind.co",
            "displayName": "mikeransier.bsky.social",
            "likes": 0,
            "reposts": 0,
            "replies": 0,
            "createdAt": "2026-07-16",
            "url": "https://bsky.app/profile/thecybermind.co/post/3mqsf2ua55a2l",
            "origin": false,
            "authority": true,
            "github": []
          },
          {
            "handle": "securityonline.bsky.social",
            "displayName": "Daily CyberSecurity",
            "likes": 0,
            "reposts": 0,
            "replies": 0,
            "createdAt": "2026-07-16",
            "url": "https://bsky.app/profile/securityonline.bsky.social/post/3mqq6zevtsw24",
            "origin": false,
            "authority": false,
            "github": []
          },
          {
            "handle": "kitafox.bsky.social",
            "displayName": "キタきつね",
            "likes": 0,
            "reposts": 0,
            "replies": 0,
            "createdAt": "2026-07-16",
            "url": "https://bsky.app/profile/kitafox.bsky.social/post/3mqqm4d4fsy2g",
            "origin": false,
            "authority": false,
            "github": []
          },
          {
            "handle": "cvesentinel.bsky.social",
            "displayName": "CVESentinel",
            "likes": 0,
            "reposts": 0,
            "replies": 0,
            "createdAt": "2026-07-15",
            "url": "https://bsky.app/profile/cvesentinel.bsky.social/post/3mqp7ytwxk72f",
            "origin": false,
            "authority": false,
            "github": []
          },
          {
            "handle": "thecircuitry.to",
            "displayName": "The Circuitry",
            "likes": 0,
            "reposts": 0,
            "replies": 0,
            "createdAt": "2026-07-15",
            "url": "https://bsky.app/profile/thecircuitry.to/post/3mqpc3rakth2x",
            "origin": false,
            "authority": false,
            "github": []
          }
        ]
      },
      "aliases": [
        "KNXlock"
      ],
      "researchers": [
        "f0rw4rd"
      ],
      "corroboration": {
        "poc": false,
        "xOrigin": true,
        "independent": [
          "x"
        ],
        "level": "multi-source"
      },
      "telegram": {
        "mentions": 1,
        "reach": 148,
        "posts": [
          {
            "channel": "VulnerabilityNews",
            "channelTitle": "Vulnerability News",
            "tier": "news",
            "date": "2026-07-15",
            "views": 147,
            "forwards": 1,
            "url": "https://t.me/VulnerabilityNews/43501",
            "text": "CISA Adds Two Known Exploited Vulnerabilities to Catalog CISA has added two new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation. CVE-2023-4346 KNX Association KNX Protocol Connection Authorization Option 1 Overly Restrictive Account Lockout Mechanism Vulnerability CVE-2026-46817 Oracle E-Business Suite Improper Privilege Management Vul",
            "github": [],
            "origin": false
          }
        ]
      }
    },
    {
      "cve": "CVE-2026-56155",
      "title": "Microsoft Active Directory Federation Services Insufficient Granularity of Access Control Vulnerability ",
      "category": "Microsoft",
      "vendor": "Microsoft",
      "product": "Active Directory Federation Services",
      "exploited": true,
      "publiclyDisclosed": false,
      "faq": "Microsoft Active Directory Federation Services contains an insufficient granularity of access control vulnerability that allows an authorized attacker to elevate privileges locally.",
      "cvss": 7.8,
      "cvssVector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "severity": "HIGH",
      "impact": null,
      "products": [
        "Active Directory Federation Services"
      ],
      "productCount": 1,
      "mitreUrl": "https://nvd.nist.gov/vuln/detail/CVE-2026-56155",
      "source": "kev",
      "kev": {
        "dateAdded": "2026-07-14",
        "dueDate": "2026-07-28",
        "requiredAction": "Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.",
        "ransomware": false,
        "cwes": [
          "CWE-1220"
        ],
        "references": [
          "https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2026-56155",
          "https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk",
          "https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk",
          "https://nvd.nist.gov/vuln/detail/CVE-2026-56155",
          "https://learn.microsoft.com/en-us/windows-server/identity/ad-fs/decommission/adfs-decommission-guide"
        ]
      },
      "epss": 0.00379,
      "epssPercentile": 0.30287,
      "pocCount": 0,
      "pocTopStars": 0,
      "pocConfidence": "none",
      "pocRepos": [],
      "published": "2026-07-14T17:17:09.763",
      "research": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-56155",
          "type": "detection",
          "source": "Microsoft MSRC",
          "note": "Official advisory; patch + Event ID 1132 detection"
        },
        {
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "type": "detection",
          "source": "CISA KEV",
          "note": "KEV-listed 2026-07-14; due date 2026-07-28"
        },
        {
          "url": "https://windowsnews.ai/article/patch-now-cisa-adds-two-microsoft-zero-days-and-two-sonicwall-flaws-to-must-fix-list.438204",
          "type": "writeup",
          "source": "Windows News",
          "note": "DKM ACL root cause; token-key theft impact"
        },
        {
          "url": "https://www.zerodayinitiative.com/blog/2026/7/14/the-july-2026-security-update-review",
          "type": "writeup",
          "source": "ZDI / Trend Micro",
          "note": "ZDI July 2026 review; RCE-chain pivot risk"
        },
        {
          "url": "https://www.bleepingcomputer.com/news/microsoft/microsoft-july-2026-patch-tuesday-fixes-massive-570-flaws-3-zero-days/",
          "type": "writeup",
          "source": "BleepingComputer",
          "note": "Credits DART's Kingston & Clark; zero-day context"
        },
        {
          "url": "https://www.tenable.com/blog/microsofts-july-2026-patch-tuesday-addresses-569-cves-cve-2026-56155-cve-2026-56164",
          "type": "writeup",
          "source": "Tenable Research",
          "note": "CVSSv3 7.8; DART credit; admin privesc impact"
        },
        {
          "url": "https://blog.talosintelligence.com/microsoft-patch-tuesday-july-2026/",
          "type": "writeup",
          "source": "Cisco Talos",
          "note": "Talos Patch Tuesday; insufficient ACL analysis"
        },
        {
          "url": "https://vulnerability.circl.lu/vuln/CVE-2026-56155",
          "type": "detection",
          "source": "CIRCL Vulnerability-Lookup",
          "note": "Aggregated refs: NVD, MSRC, CISA KEV, GHSA"
        }
      ],
      "x": {
        "mentions": 0,
        "aliases": [],
        "posts": []
      },
      "bsky": {
        "mentions": 4,
        "posts": [
          {
            "handle": "cvesentinel.bsky.social",
            "displayName": "CVESentinel",
            "likes": 0,
            "reposts": 1,
            "replies": 0,
            "createdAt": "2026-07-14",
            "url": "https://bsky.app/profile/cvesentinel.bsky.social/post/3mqmt3ncdul23",
            "origin": false,
            "authority": false,
            "github": []
          },
          {
            "handle": "blackhatnews.tokyo",
            "displayName": "blackhatnews.tokyo",
            "likes": 0,
            "reposts": 1,
            "replies": 0,
            "createdAt": "2026-07-14",
            "url": "https://bsky.app/profile/blackhatnews.tokyo/post/3mqmv7wcsti26",
            "origin": false,
            "authority": false,
            "github": []
          },
          {
            "handle": "securityrss.bsky.social",
            "displayName": "securityrss.ai",
            "likes": 0,
            "reposts": 0,
            "replies": 0,
            "createdAt": "2026-07-14",
            "url": "https://bsky.app/profile/securityrss.bsky.social/post/3mqn4kn2xsr2i",
            "origin": false,
            "authority": false,
            "github": []
          },
          {
            "handle": "securityonline.bsky.social",
            "displayName": "Daily CyberSecurity",
            "likes": 0,
            "reposts": 0,
            "replies": 0,
            "createdAt": "2026-07-14",
            "url": "https://bsky.app/profile/securityonline.bsky.social/post/3mqnc5xk42a23",
            "origin": false,
            "authority": false,
            "github": []
          }
        ]
      },
      "telegram": {
        "mentions": 0,
        "posts": []
      },
      "corroboration": {
        "poc": false,
        "xOrigin": false,
        "independent": [],
        "level": "cisa-attributed"
      },
      "aliases": [],
      "researchers": []
    },
    {
      "cve": "CVE-2026-56164",
      "title": "Microsoft SharePoint Server Missing Authentication for Critical Function Vulnerability",
      "category": "Microsoft",
      "vendor": "Microsoft",
      "product": "SharePoint Server",
      "exploited": true,
      "publiclyDisclosed": false,
      "faq": "Microsoft SharePoint contains a missing authentication for critical function vulnerability that allows an unauthorized attacker to elevate privileges over a network.",
      "cvss": 5.3,
      "cvssVector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N",
      "severity": "MEDIUM",
      "impact": null,
      "products": [
        "SharePoint Server"
      ],
      "productCount": 1,
      "mitreUrl": "https://nvd.nist.gov/vuln/detail/CVE-2026-56164",
      "source": "kev",
      "kev": {
        "dateAdded": "2026-07-14",
        "dueDate": "2026-07-17",
        "requiredAction": "Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.",
        "ransomware": false,
        "cwes": [
          "CWE-306"
        ],
        "references": [
          "https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2026-56164",
          "https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk",
          "https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk",
          "https://nvd.nist.gov/vuln/detail/CVE-2026-56164"
        ]
      },
      "epss": 0.05601,
      "epssPercentile": 0.92056,
      "pocCount": 0,
      "pocTopStars": 15,
      "pocConfidence": "reported",
      "pocRepos": [
        {
          "url": "https://github.com/sentinel-aidefense/CVE-2026-56164-EXP",
          "stars": 15,
          "desc": "CVE-2026-56164 EOP Exploit",
          "createdAt": "2026-07-15",
          "hasCode": false
        }
      ],
      "published": "2026-07-14T17:17:09.907",
      "research": [
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-56164",
          "type": "writeup",
          "source": "Microsoft MSRC",
          "note": "Official vendor advisory; patch + AMSI mitigation details"
        },
        {
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "type": "detection",
          "source": "CISA KEV Catalog",
          "note": "KEV entry added 2026-07-14; due date 2026-07-17"
        },
        {
          "url": "https://www.cisa.gov/news-events/alerts/2026/07/14/cisa-urges-sharepoint-hardening-after-new-exploitations",
          "type": "detection",
          "source": "CISA Alert AA26-195A",
          "note": "Active exploitation alert; hardening/triage guidance"
        },
        {
          "url": "https://www.zerodayinitiative.com/blog/2026/7/14/the-july-2026-security-update-review",
          "type": "writeup",
          "source": "Zero Day Initiative (ZDI)",
          "note": "ZDI July 2026 review; CWE-306, unauthenticated EoP analysis"
        },
        {
          "url": "https://www.bleepingcomputer.com/news/microsoft/microsoft-july-2026-patch-tuesday-fixes-massive-570-flaws-3-zero-days/",
          "type": "writeup",
          "source": "BleepingComputer",
          "note": "Credits Frost/Mandiant & Jiang/FLARE; no exploit details public"
        },
        {
          "url": "https://thehackernews.com/2026/07/microsoft-patches-record-622-flaws.html",
          "type": "writeup",
          "source": "The Hacker News",
          "note": "Covers zero-day context; Mandiant/FLARE discovery attribution"
        },
        {
          "url": "https://www.securityweek.com/microsoft-patches-record-622-vulnerabilities-including-two-exploited-zero-days/",
          "type": "writeup",
          "source": "SecurityWeek",
          "note": "Zero-day roundup; unauthenticated network EoP confirmed"
        },
        {
          "url": "https://zecurit.com/endpoint-management/patch-tuesday/",
          "type": "detection",
          "source": "Zecurit",
          "note": "Patch Tuesday analysis; AMSI Full mode interim mitigation"
        }
      ],
      "x": {
        "mentions": 106,
        "aliases": [],
        "posts": [
          {
            "handle": "MalwareObserver",
            "followers": 9,
            "likes": 0,
            "createdAt": "2026-07-15",
            "url": "https://x.com/MalwareObserver/status/2077250553655005389",
            "github": [
              {
                "url": "https://github.com/istio/istio/security/advisories/GHSA-v75c-crr9-733c",
                "hasCode": true
              },
              {
                "url": "https://github.com/istio/istio/security/advisories/GHSA-v75c-crr9-733c",
                "hasCode": true
              }
            ],
            "origin": false
          },
          {
            "handle": "MalwareBibleJP",
            "followers": 7624,
            "likes": 8,
            "createdAt": "2026-07-15",
            "url": "https://x.com/MalwareBibleJP/status/2077234644404273220",
            "github": [],
            "origin": false
          },
          {
            "handle": "PentesterLab",
            "followers": 205348,
            "likes": 6,
            "createdAt": "2026-07-15",
            "url": "https://x.com/PentesterLab/status/2077227113070166264",
            "github": [],
            "origin": false
          },
          {
            "handle": "steventseeley",
            "followers": 22728,
            "likes": 2,
            "createdAt": "2026-07-15",
            "url": "https://x.com/steventseeley/status/2077260190261624985",
            "github": [],
            "origin": false
          },
          {
            "handle": "Daily_CyberSec",
            "followers": 12486,
            "likes": 2,
            "createdAt": "2026-07-15",
            "url": "https://x.com/Daily_CyberSec/status/2077198003673214982",
            "github": [],
            "origin": false
          },
          {
            "handle": "__kokumoto",
            "followers": 7578,
            "likes": 2,
            "createdAt": "2026-07-15",
            "url": "https://x.com/__kokumoto/status/2077233338256073098",
            "github": [],
            "origin": false
          },
          {
            "handle": "blackorbird",
            "followers": 42692,
            "likes": 1,
            "createdAt": "2026-07-15",
            "url": "https://x.com/blackorbird/status/2077268390000132431",
            "github": [],
            "origin": false
          },
          {
            "handle": "pdnuclei_bot",
            "followers": 989,
            "likes": 1,
            "createdAt": "2026-07-15",
            "url": "https://x.com/pdnuclei_bot/status/2077256883522723949",
            "github": [],
            "origin": false
          }
        ]
      },
      "bsky": {
        "mentions": 5,
        "posts": [
          {
            "handle": "cvesentinel.bsky.social",
            "displayName": "CVESentinel",
            "likes": 0,
            "reposts": 1,
            "replies": 0,
            "createdAt": "2026-07-14",
            "url": "https://bsky.app/profile/cvesentinel.bsky.social/post/3mqmt3pfil62x",
            "origin": false,
            "authority": false,
            "github": []
          },
          {
            "handle": "securityonline.bsky.social",
            "displayName": "Daily CyberSecurity",
            "likes": 0,
            "reposts": 0,
            "replies": 0,
            "createdAt": "2026-07-15",
            "url": "https://bsky.app/profile/securityonline.bsky.social/post/3mqnjrcevrj2b",
            "origin": false,
            "authority": false,
            "github": []
          },
          {
            "handle": "stackflag.bsky.social",
            "displayName": "STACKFLAG",
            "likes": 0,
            "reposts": 0,
            "replies": 0,
            "createdAt": "2026-07-14",
            "url": "https://bsky.app/profile/stackflag.bsky.social/post/3mqn7ovdxyj2q",
            "origin": false,
            "authority": false,
            "github": []
          },
          {
            "handle": "securityrss.bsky.social",
            "displayName": "securityrss.ai",
            "likes": 0,
            "reposts": 0,
            "replies": 0,
            "createdAt": "2026-07-14",
            "url": "https://bsky.app/profile/securityrss.bsky.social/post/3mqn4kn2xsr2i",
            "origin": false,
            "authority": false,
            "github": []
          }
        ]
      },
      "telegram": {
        "mentions": 0,
        "posts": []
      },
      "researchers": [
        "JaysonFrost_IR",
        "GenWeiJiang"
      ],
      "corroboration": {
        "poc": false,
        "xOrigin": false,
        "independent": [
          "x-mention"
        ],
        "level": "multi-source"
      },
      "aliases": []
    },
    {
      "cve": "CVE-2026-15409",
      "title": "SonicWall SMA1000 Appliances Server-Side Request Forgery Vulnerability",
      "category": "SonicWall",
      "vendor": "SonicWall",
      "product": "SMA1000 Appliances",
      "exploited": true,
      "publiclyDisclosed": false,
      "faq": "SonicWall SMA1000 Appliances contain a server-side request forgery vulnerability that could allow a remote unauthenticated attacker to potentially cause the appliance to make requests to unintended location.",
      "cvss": 10,
      "cvssVector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H",
      "severity": "CRITICAL",
      "impact": null,
      "products": [
        "SMA1000 Appliances"
      ],
      "productCount": 1,
      "mitreUrl": "https://nvd.nist.gov/vuln/detail/CVE-2026-15409",
      "source": "kev",
      "kev": {
        "dateAdded": "2026-07-14",
        "dueDate": "2026-07-17",
        "requiredAction": "Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.",
        "ransomware": false,
        "cwes": [
          "CWE-918"
        ],
        "references": [
          "https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2026-0008",
          "https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk",
          "https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk",
          "https://nvd.nist.gov/vuln/detail/CVE-2026-15409"
        ]
      },
      "epss": 0.01266,
      "epssPercentile": 0.66544,
      "pocCount": 2,
      "pocTopStars": 26,
      "pocConfidence": "confirmed",
      "pocRepos": [
        {
          "url": "https://github.com/remmons-r7/rapid7-CVE-2026-15409",
          "stars": 26,
          "desc": "This repo contains a proof-of-concept exploit for CVE-2026-15409. It establishes non-root remote code execution on SonicWall SMA 1000 by implementing the Erlang",
          "createdAt": "2026-07-15",
          "hasCode": true
        },
        {
          "url": "https://github.com/0xBlackash/CVE-2026-15409",
          "stars": 1,
          "desc": "CVE-2026-15409",
          "createdAt": "2026-07-15",
          "hasCode": true
        },
        {
          "url": "https://github.com/HORKimhab/CVE-2026-15409",
          "stars": 0,
          "desc": "CVE-2026-15409 - Dectect",
          "createdAt": "2026-07-15",
          "hasCode": false
        }
      ],
      "published": "2026-07-14T20:16:56.783",
      "research": [
        {
          "url": "https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2026-0008",
          "type": "detection",
          "source": "SonicWall PSIRT",
          "note": "Official vendor advisory; patch + IOC guidance"
        },
        {
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "type": "detection",
          "source": "CISA KEV",
          "note": "KEV listing; BOD 26-04 deadline 2026-07-17"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-15409",
          "type": "detection",
          "source": "NIST NVD",
          "note": "CVSS 10.0 CRITICAL; full CVSSv3.1 metadata"
        },
        {
          "url": "https://vulnerability.circl.lu/vuln/CVE-2026-15409",
          "type": "detection",
          "source": "CIRCL Vulnerability-Lookup",
          "note": "Aggregated vuln data; SSVC active/automatable"
        },
        {
          "url": "https://www.bleepingcomputer.com/news/security/sonicwall-warns-of-sma1000-flaws-exploited-in-zero-day-attacks-patch-now/",
          "type": "writeup",
          "source": "BleepingComputer",
          "note": "Zero-day coverage; chain w/ CVE-2026-15410"
        },
        {
          "url": "https://www.helpnetsecurity.com/2026/07/14/sonicwall-sma-attacks-via-cve-2026-15409-cve-2026-15410/",
          "type": "writeup",
          "source": "Help Net Security",
          "note": "Active exploitation confirmed; tandem exploit chain"
        }
      ],
      "x": {
        "mentions": 1,
        "aliases": [],
        "posts": [
          {
            "handle": "OffensiveLab",
            "followers": 79,
            "likes": 0,
            "createdAt": "2026-07-15",
            "url": "https://x.com/OffensiveLab/status/2077267480154935347",
            "github": [],
            "origin": false
          }
        ]
      },
      "bsky": {
        "mentions": 13,
        "posts": [
          {
            "handle": "bleepingcomputer.com",
            "displayName": "BleepingComputer",
            "likes": 2,
            "reposts": 0,
            "replies": 0,
            "createdAt": "2026-07-14",
            "url": "https://bsky.app/profile/bleepingcomputer.com/post/3mqn5d4tfmq27",
            "origin": false,
            "authority": true,
            "github": []
          },
          {
            "handle": "securityonline.bsky.social",
            "displayName": "Daily CyberSecurity",
            "likes": 1,
            "reposts": 0,
            "replies": 0,
            "createdAt": "2026-07-15",
            "url": "https://bsky.app/profile/securityonline.bsky.social/post/3mqng6u6m3s2a",
            "origin": false,
            "authority": false,
            "github": []
          },
          {
            "handle": "cybernewsroom.bsky.social",
            "displayName": "Cyber Newsroom",
            "likes": 0,
            "reposts": 0,
            "replies": 0,
            "createdAt": "2026-07-15",
            "url": "https://bsky.app/profile/cybernewsroom.bsky.social/post/3mqnztgbmgi2p",
            "origin": false,
            "authority": false,
            "github": []
          },
          {
            "handle": "hapsis.bsky.social",
            "displayName": "Tomas Ström",
            "likes": 0,
            "reposts": 0,
            "replies": 0,
            "createdAt": "2026-07-14",
            "url": "https://bsky.app/profile/hapsis.bsky.social/post/3mqmvbuce4c2u",
            "origin": false,
            "authority": false,
            "github": []
          },
          {
            "handle": "cvesentinel.bsky.social",
            "displayName": "CVESentinel",
            "likes": 0,
            "reposts": 0,
            "replies": 0,
            "createdAt": "2026-07-14",
            "url": "https://bsky.app/profile/cvesentinel.bsky.social/post/3mqmzrvb4nk22",
            "origin": false,
            "authority": false,
            "github": []
          },
          {
            "handle": "blackhatnews.tokyo",
            "displayName": "blackhatnews.tokyo",
            "likes": 0,
            "reposts": 0,
            "replies": 0,
            "createdAt": "2026-07-14",
            "url": "https://bsky.app/profile/blackhatnews.tokyo/post/3mqmrct2poa2b",
            "origin": false,
            "authority": false,
            "github": []
          }
        ]
      },
      "telegram": {
        "mentions": 2,
        "posts": [
          {
            "channel": "VulnerabilityNews",
            "channelTitle": "Vulnerability News",
            "tier": "news",
            "date": "2026-07-14",
            "views": 73,
            "forwards": 1,
            "url": "https://t.me/VulnerabilityNews/43452",
            "text": "SonicWall warns of SMA1000 flaws exploited in zero-day attacks, patch now SonicWall warns that threat actors have been exploiting two SMA1000 vulnerabilities, tracked as CVE-2026-15409 and CVE-2026-15410, in zero-day attacks and urges customers to install the newly released security updates. [...] https://www.bleepingcomputer.com/news/security/sonicwall-warns-of-sma1000-flaws-exploited-in-zero-day",
            "github": [],
            "origin": false
          }
        ]
      },
      "corroboration": {
        "poc": true,
        "xOrigin": false,
        "independent": [
          "poc",
          "x-mention"
        ],
        "level": "multi-source"
      },
      "aliases": [],
      "researchers": []
    },
    {
      "cve": "CVE-2026-15410",
      "title": "SonicWall SMA1000 Appliances Code Injection Vulnerability",
      "category": "SonicWall",
      "vendor": "SonicWall",
      "product": "SMA1000 Appliances",
      "exploited": true,
      "publiclyDisclosed": false,
      "faq": "SonicWall SMA1000 Appliances contain a code injection vulnerability which in specific conditions could potentially enable a remote authenticated attacker as administrator to execute arbitrary OS commands.",
      "cvss": 7.2,
      "cvssVector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H",
      "severity": "HIGH",
      "impact": null,
      "products": [
        "SMA1000 Appliances"
      ],
      "productCount": 1,
      "mitreUrl": "https://nvd.nist.gov/vuln/detail/CVE-2026-15410",
      "source": "kev",
      "kev": {
        "dateAdded": "2026-07-14",
        "dueDate": "2026-07-17",
        "requiredAction": "Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.",
        "ransomware": false,
        "cwes": [
          "CWE-94"
        ],
        "references": [
          "https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2026-0008",
          "https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk",
          "https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk",
          "https://nvd.nist.gov/vuln/detail/CVE-2026-15410"
        ]
      },
      "epss": 0.01486,
      "epssPercentile": 0.71201,
      "pocCount": 1,
      "pocTopStars": 0,
      "pocConfidence": "confirmed",
      "pocRepos": [
        {
          "url": "https://github.com/HORKimhab/CVE-2026-15410",
          "stars": 0,
          "desc": "CVE-2026-15410 - More: https://github.com/HORKimhab/poc-cve-collection",
          "createdAt": "2026-07-15",
          "hasCode": true
        }
      ],
      "published": "2026-07-14T20:16:56.903",
      "research": [
        {
          "url": "https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2026-0008",
          "type": "detection",
          "source": "SonicWall PSIRT (SNWLID-2026-0008)",
          "note": "Official vendor advisory; patch & IoC guidance"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-15410",
          "type": "detection",
          "source": "NIST NVD",
          "note": "NVD entry; CVSS 7.2 HIGH, CWE-94, active exploit"
        },
        {
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "type": "detection",
          "source": "CISA KEV Catalog",
          "note": "KEV listed 2026-07-14; BOD 26-04 patch deadline"
        },
        {
          "url": "https://vulnerability.circl.lu/vuln/CVE-2026-15410",
          "type": "detection",
          "source": "CIRCL Vulnerability-Lookup",
          "note": "Aggregated vuln data; CWE-94 code injection detail"
        },
        {
          "url": "https://www.bleepingcomputer.com/news/security/sonicwall-warns-of-sma1000-flaws-exploited-in-zero-day-attacks-patch-now/",
          "type": "writeup",
          "source": "BleepingComputer",
          "note": "Zero-day chaining w/ CVE-2026-15409 confirmed ITW"
        },
        {
          "url": "https://www.helpnetsecurity.com/2026/07/14/sonicwall-sma-attacks-via-cve-2026-15409-cve-2026-15410/",
          "type": "writeup",
          "source": "Help Net Security",
          "note": "Tandem exploit confirmed; discoverer Adam Babis/PSIRT"
        },
        {
          "url": "https://www.csa.gov.sg/alerts-and-advisories/alerts/al-2026-033/",
          "type": "detection",
          "source": "CSA Singapore (AL-2026-033)",
          "note": "Govt advisory; immediate patch recommended"
        },
        {
          "url": "https://hackread.com/sonicwall-sma-appliances-exploited-zero-day-attacks/",
          "type": "writeup",
          "source": "HackRead",
          "note": "AMC attack surface & mitigation steps covered"
        }
      ],
      "x": {
        "mentions": 0,
        "aliases": [],
        "posts": []
      },
      "bsky": {
        "mentions": 10,
        "posts": [
          {
            "handle": "bleepingcomputer.com",
            "displayName": "BleepingComputer",
            "likes": 2,
            "reposts": 0,
            "replies": 0,
            "createdAt": "2026-07-14",
            "url": "https://bsky.app/profile/bleepingcomputer.com/post/3mqn5d4tfmq27",
            "origin": false,
            "authority": true,
            "github": []
          },
          {
            "handle": "cybernewsroom.bsky.social",
            "displayName": "Cyber Newsroom",
            "likes": 0,
            "reposts": 0,
            "replies": 0,
            "createdAt": "2026-07-15",
            "url": "https://bsky.app/profile/cybernewsroom.bsky.social/post/3mqnztgbmgi2p",
            "origin": false,
            "authority": false,
            "github": []
          },
          {
            "handle": "blackhatnews.tokyo",
            "displayName": "blackhatnews.tokyo",
            "likes": 0,
            "reposts": 0,
            "replies": 0,
            "createdAt": "2026-07-15",
            "url": "https://bsky.app/profile/blackhatnews.tokyo/post/3mqny4xcime2x",
            "origin": false,
            "authority": false,
            "github": []
          },
          {
            "handle": "hapsis.bsky.social",
            "displayName": "Tomas Ström",
            "likes": 0,
            "reposts": 0,
            "replies": 0,
            "createdAt": "2026-07-14",
            "url": "https://bsky.app/profile/hapsis.bsky.social/post/3mqmvbuce4c2u",
            "origin": false,
            "authority": false,
            "github": []
          },
          {
            "handle": "cvesentinel.bsky.social",
            "displayName": "CVESentinel",
            "likes": 0,
            "reposts": 0,
            "replies": 0,
            "createdAt": "2026-07-14",
            "url": "https://bsky.app/profile/cvesentinel.bsky.social/post/3mqmzrxebkp2p",
            "origin": false,
            "authority": false,
            "github": []
          },
          {
            "handle": "hendryadrian.bsky.social",
            "displayName": "Cybersecurity News Everyday",
            "likes": 0,
            "reposts": 0,
            "replies": 0,
            "createdAt": "2026-07-14",
            "url": "https://bsky.app/profile/hendryadrian.bsky.social/post/3mqnefpclnf2a",
            "origin": false,
            "authority": false,
            "github": []
          }
        ]
      },
      "telegram": {
        "mentions": 2,
        "posts": [
          {
            "channel": "VulnerabilityNews",
            "channelTitle": "Vulnerability News",
            "tier": "news",
            "date": "2026-07-14",
            "views": 73,
            "forwards": 1,
            "url": "https://t.me/VulnerabilityNews/43452",
            "text": "SonicWall warns of SMA1000 flaws exploited in zero-day attacks, patch now SonicWall warns that threat actors have been exploiting two SMA1000 vulnerabilities, tracked as CVE-2026-15409 and CVE-2026-15410, in zero-day attacks and urges customers to install the newly released security updates. [...] https://www.bleepingcomputer.com/news/security/sonicwall-warns-of-sma1000-flaws-exploited-in-zero-day",
            "github": [],
            "origin": false
          }
        ]
      },
      "corroboration": {
        "poc": true,
        "xOrigin": false,
        "independent": [
          "poc"
        ],
        "level": "multi-source"
      },
      "aliases": [],
      "researchers": []
    },
    {
      "cve": "CVE-2008-4128",
      "title": "Cisco IOS Cross-Site Request Forgery Vulnerability",
      "category": "Cisco",
      "vendor": "Cisco",
      "product": "IOS",
      "exploited": true,
      "publiclyDisclosed": false,
      "faq": "Cisco IOS 12.4 contains multiple cross-site forgery vulnerabilities that allows remote attackers to execute arbitrary commands via (1) a certain \"show privilege\" command to the /level/15/exec/- URI, and (2) a certain \"alias exec\" command to the /level/15/exec/-/configure/http URI.",
      "cvss": 4.3,
      "cvssVector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N",
      "severity": "MEDIUM",
      "impact": null,
      "products": [
        "IOS"
      ],
      "productCount": 1,
      "mitreUrl": "https://nvd.nist.gov/vuln/detail/CVE-2008-4128",
      "source": "kev",
      "kev": {
        "dateAdded": "2026-07-13",
        "dueDate": "2026-07-16",
        "requiredAction": "Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.",
        "ransomware": false,
        "cwes": [
          "CWE-352"
        ],
        "references": [
          "https://www.cisco.com/c/en/us/obsolete/ios-nx-os-software/cisco-ios-software-releases-12-4-mainline.html",
          "https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk",
          "https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk",
          "https://nvd.nist.gov/vuln/detail/CVE-2008-4128"
        ]
      },
      "epss": 0.23857,
      "epssPercentile": 0.97582,
      "pocCount": 0,
      "pocTopStars": 0,
      "pocConfidence": "none",
      "pocRepos": [],
      "published": "2008-09-18T20:00:00.530",
      "research": [
        {
          "url": "https://www.exploit-db.com/exploits/6476",
          "type": "poc",
          "source": "Exploit-DB (EDB-ID 6476)",
          "note": "CSRF PoC #1: show privilege via /level/15/exec/-"
        },
        {
          "url": "https://www.exploit-db.com/exploits/6477",
          "type": "poc",
          "source": "Exploit-DB (EDB-ID 6477)",
          "note": "CSRF PoC #2: alias exec via /level/15/exec/-/configure/http"
        },
        {
          "url": "http://jbrownsec.blogspot.com/2008/09/cisco-0day-released.html",
          "type": "writeup",
          "source": "jbrownsec (original discloser blog)",
          "note": "Original 0day disclosure blog post, Sept 2008"
        },
        {
          "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/45226",
          "type": "writeup",
          "source": "IBM X-Force (cisco-router-csrf/45226)",
          "note": "IBM X-Force VDB entry: cisco-router-csrf(45226)"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2008-4128",
          "type": "writeup",
          "source": "NIST NVD",
          "note": "Official NVD advisory with references & scoring"
        },
        {
          "url": "https://www.cisa.gov/news-events/alerts/2026/07/13/cisa-adds-one-known-exploited-vulnerability-catalog",
          "type": "detection",
          "source": "CISA KEV Catalog",
          "note": "Added to KEV 2026-07-13; active exploitation confirmed"
        },
        {
          "url": "https://www.cisco.com/c/en/us/obsolete/ios-nx-os-software/cisco-ios-software-releases-12-4-mainline.html",
          "type": "detection",
          "source": "Cisco (vendor mitigation)",
          "note": "Cisco IOS 12.4 EOL/obsolete page; official mitigation"
        },
        {
          "url": "https://media.defense.gov/2026/Jul/09/2003959498/-1/-1/1/CSA_IMPROVE_ROUTER_HYGIENE.PDF",
          "type": "detection",
          "source": "NSA/DoD (CSA_IMPROVE_ROUTER_HYGIENE)",
          "note": "NSA/DoD CSA: router hygiene guidance referencing CVE"
        }
      ],
      "x": {
        "mentions": 23,
        "aliases": [],
        "posts": [
          {
            "handle": "MalwareBibleJP",
            "followers": 7624,
            "likes": 89,
            "createdAt": "2026-07-02",
            "url": "https://x.com/MalwareBibleJP/status/2072532472366252391",
            "github": [],
            "origin": false
          },
          {
            "handle": "piyokango",
            "followers": 43666,
            "likes": 17,
            "createdAt": "2026-07-14",
            "url": "https://x.com/piyokango/status/2076873110486405486",
            "github": [],
            "origin": false
          },
          {
            "handle": "CISACyber",
            "followers": 299586,
            "likes": 14,
            "createdAt": "2026-07-14",
            "url": "https://x.com/CISACyber/status/2077088886715469846",
            "github": [],
            "origin": false
          },
          {
            "handle": "__kokumoto",
            "followers": 7578,
            "likes": 2,
            "createdAt": "2026-07-13",
            "url": "https://x.com/__kokumoto/status/2076803357294117350",
            "github": [],
            "origin": false
          },
          {
            "handle": "rahmid3mir",
            "followers": 346,
            "likes": 2,
            "createdAt": "2026-07-14",
            "url": "https://x.com/rahmid3mir/status/2076960536235761956",
            "github": [],
            "origin": false
          },
          {
            "handle": "f1tym1",
            "followers": 999,
            "likes": 1,
            "createdAt": "2026-07-13",
            "url": "https://x.com/f1tym1/status/2076768504838054216",
            "github": [],
            "origin": false
          },
          {
            "handle": "DC3DCISE",
            "followers": 728,
            "likes": 1,
            "createdAt": "2026-07-03",
            "url": "https://x.com/DC3DCISE/status/2073060948286263696",
            "github": [],
            "origin": false
          },
          {
            "handle": "PCMedicalist",
            "followers": 116,
            "likes": 1,
            "createdAt": "2026-07-14",
            "url": "https://x.com/PCMedicalist/status/2077121529259688085",
            "github": [],
            "origin": false
          }
        ]
      },
      "bsky": {
        "mentions": 7,
        "posts": [
          {
            "handle": "secdb.bsky.social",
            "displayName": "ZEN SecDB",
            "likes": 0,
            "reposts": 0,
            "replies": 0,
            "createdAt": "2026-07-13",
            "url": "https://bsky.app/profile/secdb.bsky.social/post/3mqketpxyi62r",
            "origin": false,
            "authority": true,
            "github": []
          },
          {
            "handle": "suriq.io",
            "displayName": "Suriq - Always on Watch",
            "likes": 0,
            "reposts": 0,
            "replies": 0,
            "createdAt": "2026-07-14",
            "url": "https://bsky.app/profile/suriq.io/post/3mqlit67few22",
            "origin": false,
            "authority": false,
            "github": []
          },
          {
            "handle": "blackhatnews.tokyo",
            "displayName": "blackhatnews.tokyo",
            "likes": 0,
            "reposts": 0,
            "replies": 0,
            "createdAt": "2026-07-14",
            "url": "https://bsky.app/profile/blackhatnews.tokyo/post/3mqlvy3ls3e25",
            "origin": false,
            "authority": false,
            "github": []
          },
          {
            "handle": "cvesentinel.bsky.social",
            "displayName": "CVESentinel",
            "likes": 0,
            "reposts": 0,
            "replies": 0,
            "createdAt": "2026-07-13",
            "url": "https://bsky.app/profile/cvesentinel.bsky.social/post/3mqk7rgvkgi27",
            "origin": false,
            "authority": false,
            "github": []
          },
          {
            "handle": "qiancx.bsky.social",
            "displayName": "qian.cx",
            "likes": 0,
            "reposts": 0,
            "replies": 0,
            "createdAt": "2026-07-13",
            "url": "https://bsky.app/profile/qiancx.bsky.social/post/3mqk7ydvawh23",
            "origin": false,
            "authority": false,
            "github": []
          },
          {
            "handle": "happeningnow.news",
            "displayName": "HappeningNow",
            "likes": 0,
            "reposts": 0,
            "replies": 0,
            "createdAt": "2026-07-13",
            "url": "https://bsky.app/profile/happeningnow.news/post/3mqkf7zlzh32k",
            "origin": false,
            "authority": false,
            "github": []
          }
        ]
      },
      "telegram": {
        "mentions": 0,
        "posts": []
      },
      "researchers": [
        "jbrownsec"
      ],
      "corroboration": {
        "poc": false,
        "xOrigin": false,
        "independent": [
          "x-mention"
        ],
        "level": "multi-source"
      },
      "aliases": []
    },
    {
      "cve": "CVE-2026-56291",
      "title": "Balbooa Forms Unrestricted Upload of File with Dangerous Type Vulnerability",
      "category": "Balbooa",
      "vendor": "Balbooa",
      "product": "Forms",
      "exploited": true,
      "publiclyDisclosed": false,
      "faq": "Balbooa Forms contains an unrestricted upload of file with dangerous type vulnerability that allows an unauthenticated arbitrary file upload which could allow uploading of executable files leading to full RCE.",
      "cvss": 9.8,
      "cvssVector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "severity": "CRITICAL",
      "impact": null,
      "products": [
        "Forms"
      ],
      "productCount": 1,
      "mitreUrl": "https://nvd.nist.gov/vuln/detail/CVE-2026-56291",
      "source": "kev",
      "kev": {
        "dateAdded": "2026-07-10",
        "dueDate": "2026-07-13",
        "requiredAction": "Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.",
        "ransomware": false,
        "cwes": [
          "CWE-434"
        ],
        "references": [
          "https://www.balbooa.com/joomla-forms",
          "https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk",
          "https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk",
          "https://nvd.nist.gov/vuln/detail/CVE-2026-56291"
        ]
      },
      "epss": 0.08635,
      "epssPercentile": 0.94515,
      "pocCount": 3,
      "pocTopStars": 1,
      "pocConfidence": "confirmed",
      "pocRepos": [
        {
          "url": "https://github.com/shinthink/CVE-2026-56291",
          "stars": 1,
          "desc": "Balbooa Forms (com_baforms) < 2.4.1 — Unauthenticated File Upload to RCE via form.uploadAttachmentFile | CVSS 9.8 | CISA KEV",
          "createdAt": "2026-07-11",
          "hasCode": true
        },
        {
          "url": "https://github.com/rimbadirgantara/CVE-2026-56291.yaml",
          "stars": 0,
          "desc": "nuclei template for CVE-2026-56291",
          "createdAt": "2026-07-13",
          "hasCode": true
        },
        {
          "url": "https://github.com/ChiefYoru/CVE-2026-56291_PoC",
          "stars": 0,
          "desc": "The Joomla extension Balbooa Forms is vulnerable to an unauthenticated arbitrary file upload that allows uploading executable files and leads to full RCE.",
          "createdAt": "2026-07-18",
          "hasCode": true
        }
      ],
      "published": "2026-07-09T11:16:40.990",
      "research": [
        {
          "url": "https://mysites.guru/blog/balbooa-forms-unauthenticated-file-upload-flaw/",
          "type": "writeup",
          "source": "mySites.guru / Phil Taylor (discoverer)",
          "note": "Original disclosure; no PoC released by author"
        },
        {
          "url": "https://www.cisa.gov/news-events/alerts/2026/07/10/cisa-adds-two-known-exploited-vulnerabilities-catalog",
          "type": "detection",
          "source": "CISA KEV Catalog (official)",
          "note": "KEV listing; active exploitation confirmed Jul 10 2026"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56291",
          "type": "detection",
          "source": "NVD / NIST",
          "note": "Official CVE record; CVSS 4.0 score 10.0"
        },
        {
          "url": "https://www.cycognito.com/blog/emerging-threat-cve-2026-56291-balbooa-forms-remote-code-execution-via-unauthenticated-file-upload/",
          "type": "writeup",
          "source": "CyCognito",
          "note": "Threat advisory; detection & remediation guidance"
        },
        {
          "url": "https://thehackernews.com/2026/07/icagenda-and-balbooa-forms-joomla-flaws.html",
          "type": "writeup",
          "source": "The Hacker News",
          "note": "News writeup; zero-day + KEV context"
        },
        {
          "url": "https://htprotect.org/en/balbooa-forms",
          "type": "detection",
          "source": "HTProtect.org",
          "note": "Defensive update guide; IoC checklist included"
        },
        {
          "url": "https://cve.threatint.eu/CVE/CVE-2026-56291",
          "type": "detection",
          "source": "THREATINT",
          "note": "CVE aggregator; CVSS 4.0 vector + KEV status"
        },
        {
          "url": "https://www.securityweek.com/organizations-warned-of-exploited-joomla-extension-vulnerabilities/",
          "type": "writeup",
          "source": "SecurityWeek",
          "note": "Coverage of zero-day exploitation in the wild"
        }
      ],
      "x": {
        "mentions": 101,
        "aliases": [],
        "posts": [
          {
            "handle": "MalwareObserver",
            "followers": 9,
            "likes": 0,
            "createdAt": "2026-07-15",
            "url": "https://x.com/MalwareObserver/status/2077250553655005389",
            "github": [
              {
                "url": "https://github.com/istio/istio/security/advisories/GHSA-v75c-crr9-733c",
                "hasCode": true
              },
              {
                "url": "https://github.com/istio/istio/security/advisories/GHSA-v75c-crr9-733c",
                "hasCode": true
              }
            ],
            "origin": false
          },
          {
            "handle": "ptdbugs",
            "followers": 2380,
            "likes": 13,
            "createdAt": "2026-07-14",
            "url": "https://x.com/ptdbugs/status/2076934981381693826",
            "github": [],
            "origin": false
          },
          {
            "handle": "MalwareBibleJP",
            "followers": 7624,
            "likes": 8,
            "createdAt": "2026-07-15",
            "url": "https://x.com/MalwareBibleJP/status/2077234644404273220",
            "github": [],
            "origin": false
          },
          {
            "handle": "PentesterLab",
            "followers": 205348,
            "likes": 6,
            "createdAt": "2026-07-15",
            "url": "https://x.com/PentesterLab/status/2077227113070166264",
            "github": [],
            "origin": false
          },
          {
            "handle": "steventseeley",
            "followers": 22728,
            "likes": 2,
            "createdAt": "2026-07-15",
            "url": "https://x.com/steventseeley/status/2077260190261624985",
            "github": [],
            "origin": false
          },
          {
            "handle": "Daily_CyberSec",
            "followers": 12486,
            "likes": 2,
            "createdAt": "2026-07-15",
            "url": "https://x.com/Daily_CyberSec/status/2077198003673214982",
            "github": [],
            "origin": false
          },
          {
            "handle": "__kokumoto",
            "followers": 7578,
            "likes": 2,
            "createdAt": "2026-07-15",
            "url": "https://x.com/__kokumoto/status/2077233338256073098",
            "github": [],
            "origin": false
          },
          {
            "handle": "blackorbird",
            "followers": 42692,
            "likes": 1,
            "createdAt": "2026-07-15",
            "url": "https://x.com/blackorbird/status/2077268390000132431",
            "github": [],
            "origin": false
          }
        ]
      },
      "bsky": {
        "mentions": 21,
        "posts": [
          {
            "handle": "vulnsea.com",
            "displayName": "VulnSea",
            "likes": 3,
            "reposts": 0,
            "replies": 0,
            "createdAt": "2026-07-11",
            "url": "https://bsky.app/profile/vulnsea.com/post/3mqfjy535kc2p",
            "origin": false,
            "authority": false,
            "github": []
          },
          {
            "handle": "eyalestrin.bsky.social",
            "displayName": "Eyal Estrin ☁️",
            "likes": 2,
            "reposts": 0,
            "replies": 0,
            "createdAt": "2026-07-14",
            "url": "https://bsky.app/profile/eyalestrin.bsky.social/post/3mqli7q37zh2a",
            "origin": false,
            "authority": false,
            "github": []
          },
          {
            "handle": "ahmandonk.bsky.social",
            "displayName": "Ahmandonk",
            "likes": 1,
            "reposts": 0,
            "replies": 0,
            "createdAt": "2026-07-14",
            "url": "https://bsky.app/profile/ahmandonk.bsky.social/post/3mqloi5uyei22",
            "origin": false,
            "authority": false,
            "github": []
          },
          {
            "handle": "cybernewsroom.bsky.social",
            "displayName": "Cyber Newsroom",
            "likes": 1,
            "reposts": 0,
            "replies": 0,
            "createdAt": "2026-07-13",
            "url": "https://bsky.app/profile/cybernewsroom.bsky.social/post/3mqjfm3n2vp2f",
            "origin": false,
            "authority": false,
            "github": []
          },
          {
            "handle": "toxy4ny.bsky.social",
            "displayName": "KL3FT3Z",
            "likes": 1,
            "reposts": 0,
            "replies": 0,
            "createdAt": "2026-07-13",
            "url": "https://bsky.app/profile/toxy4ny.bsky.social/post/3mqkmnbpmtc2n",
            "origin": false,
            "authority": false,
            "github": []
          },
          {
            "handle": "newssecia.bsky.social",
            "displayName": null,
            "likes": 1,
            "reposts": 0,
            "replies": 0,
            "createdAt": "2026-07-13",
            "url": "https://bsky.app/profile/newssecia.bsky.social/post/3mqj5wg6v462s",
            "origin": false,
            "authority": false,
            "github": []
          }
        ]
      },
      "telegram": {
        "mentions": 2,
        "posts": [
          {
            "channel": "PentestingNews",
            "channelTitle": "Pentesting News",
            "tier": "news",
            "date": "2026-07-13",
            "views": 440,
            "forwards": 2,
            "url": "https://t.me/PentestingNews/75097",
            "text": "CISA Warns of Actively Exploited Joomla Zero-Day Vulnerabilities https://thecyberexpress.com/cisa-cve-2026-48939-cve-2026-56291/",
            "github": [],
            "origin": false
          }
        ]
      },
      "researchers": [
        "philtaylor_mysitesguru"
      ],
      "corroboration": {
        "poc": true,
        "xOrigin": false,
        "independent": [
          "poc",
          "x-mention"
        ],
        "level": "multi-source"
      },
      "aliases": []
    },
    {
      "cve": "CVE-2026-48939",
      "title": "iCagenda Unrestricted Upload of File with Dangerous Type Vulnerability",
      "category": "iCagenda",
      "vendor": "iCagenda",
      "product": "iCagenda",
      "exploited": true,
      "publiclyDisclosed": false,
      "faq": "iCagenda contains an unrestricted upload of file with dangerous type vulnerability that allows the upload of arbitrary files in the file attachment feature, ultimately resulting in PHP code upload and execution.",
      "cvss": 9.8,
      "cvssVector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "severity": "CRITICAL",
      "impact": null,
      "products": [
        "iCagenda"
      ],
      "productCount": 1,
      "mitreUrl": "https://nvd.nist.gov/vuln/detail/CVE-2026-48939",
      "source": "kev",
      "kev": {
        "dateAdded": "2026-07-10",
        "dueDate": "2026-07-13",
        "requiredAction": "Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.",
        "ransomware": false,
        "cwes": [
          "CWE-434"
        ],
        "references": [
          "https://www.icagenda.com/#download",
          "https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk",
          "https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk",
          "https://nvd.nist.gov/vuln/detail/CVE-2026-48939"
        ]
      },
      "epss": 0.01505,
      "epssPercentile": 0.71553,
      "pocCount": 2,
      "pocTopStars": 2,
      "pocConfidence": "confirmed",
      "pocRepos": [
        {
          "url": "https://github.com/shinthink/CVE-2026-48939",
          "stars": 2,
          "desc": "Pre-auth arbitrary file upload RCE exploit for iCagenda Joomla extension < 4.0.8 (CVSS 10.0)",
          "createdAt": "2026-07-05",
          "hasCode": true
        },
        {
          "url": "https://github.com/ChiefYoru/CVE-2026-48939_PoC",
          "stars": 0,
          "desc": "iCagenda extension for Joomla allows the upload of arbitrary files in the file attachment feature, ultimately resulting in PHP code upload and execution.",
          "createdAt": "2026-07-18",
          "hasCode": true
        },
        {
          "url": "https://github.com/Polosss/By-Poloss..-..CVE-2026-48939",
          "stars": 1,
          "desc": "iCagenda Unauthenticated File Upload to RCE",
          "createdAt": "2026-06-29",
          "hasCode": false
        }
      ],
      "published": "2026-06-20T13:16:42.433",
      "research": [
        {
          "url": "https://github.com/shinthink/CVE-2026-48939",
          "type": "poc",
          "source": "GitHub / shinthink",
          "note": "Python mass-exploit: upload shell.php → RCE, CVSS 10",
          "hasCode": true
        },
        {
          "url": "https://github.com/Polosss/By-Poloss..-..CVE-2026-48939",
          "type": "poc",
          "source": "GitHub / Polosss (CISA-ADP tagged exploit)",
          "note": "Bash/curl PoC; tagged exploit in official CVE record",
          "hasCode": false
        },
        {
          "url": "https://mysites.guru/blog/icagenda-zero-day-file-upload-rce/",
          "type": "writeup",
          "source": "mySites.guru / Phil Taylor (finder)",
          "note": "Original discovery writeup; code-review + end-to-end repro"
        },
        {
          "url": "https://www.ionix.io/threat-center/cve-2026-48939/",
          "type": "writeup",
          "source": "IONIX Research",
          "note": "Root-cause analysis, IOCs, CVSS vector breakdown"
        },
        {
          "url": "https://www.sentinelone.com/vulnerability-database/cve-2026-48939/",
          "type": "writeup",
          "source": "SentinelOne Vulnerability Database",
          "note": "Technical flow: POST upload → GET shell execution path"
        },
        {
          "url": "https://www.cisa.gov/news-events/alerts/2026/07/10/cisa-adds-two-known-exploited-vulnerabilities-catalog",
          "type": "detection",
          "source": "CISA KEV Catalog",
          "note": "KEV listing; BOD 26-04 mandate; patch deadline Jul 13 2026"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-48939",
          "type": "detection",
          "source": "NIST NVD",
          "note": "Official CVE record; CVSS 4.0=10.0; CWE-284"
        },
        {
          "url": "https://app.opencve.io/cve/CVE-2026-48939",
          "type": "detection",
          "source": "OpenCVE / CISA-ADP Vulnrichment",
          "note": "Structured CVE record; credits Phil Taylor as finder"
        }
      ],
      "x": {
        "mentions": 104,
        "aliases": [],
        "posts": [
          {
            "handle": "MalwareObserver",
            "followers": 9,
            "likes": 0,
            "createdAt": "2026-07-15",
            "url": "https://x.com/MalwareObserver/status/2077250553655005389",
            "github": [
              {
                "url": "https://github.com/istio/istio/security/advisories/GHSA-v75c-crr9-733c",
                "hasCode": true
              },
              {
                "url": "https://github.com/istio/istio/security/advisories/GHSA-v75c-crr9-733c",
                "hasCode": true
              }
            ],
            "origin": false
          },
          {
            "handle": "MalwareBibleJP",
            "followers": 7624,
            "likes": 8,
            "createdAt": "2026-07-15",
            "url": "https://x.com/MalwareBibleJP/status/2077234644404273220",
            "github": [],
            "origin": false
          },
          {
            "handle": "PentesterLab",
            "followers": 205348,
            "likes": 6,
            "createdAt": "2026-07-15",
            "url": "https://x.com/PentesterLab/status/2077227113070166264",
            "github": [],
            "origin": false
          },
          {
            "handle": "piyokango",
            "followers": 43666,
            "likes": 6,
            "createdAt": "2026-07-13",
            "url": "https://x.com/piyokango/status/2076502207483232651",
            "github": [],
            "origin": false
          },
          {
            "handle": "steventseeley",
            "followers": 22728,
            "likes": 2,
            "createdAt": "2026-07-15",
            "url": "https://x.com/steventseeley/status/2077260190261624985",
            "github": [],
            "origin": false
          },
          {
            "handle": "Daily_CyberSec",
            "followers": 12486,
            "likes": 2,
            "createdAt": "2026-07-15",
            "url": "https://x.com/Daily_CyberSec/status/2077198003673214982",
            "github": [],
            "origin": false
          },
          {
            "handle": "__kokumoto",
            "followers": 7578,
            "likes": 2,
            "createdAt": "2026-07-15",
            "url": "https://x.com/__kokumoto/status/2077233338256073098",
            "github": [],
            "origin": false
          },
          {
            "handle": "PCMedicalist",
            "followers": 116,
            "likes": 2,
            "createdAt": "2026-07-13",
            "url": "https://x.com/PCMedicalist/status/2076727231766790414",
            "github": [],
            "origin": false
          }
        ]
      },
      "bsky": {
        "mentions": 22,
        "posts": [
          {
            "handle": "eyalestrin.bsky.social",
            "displayName": "Eyal Estrin ☁️",
            "likes": 2,
            "reposts": 0,
            "replies": 0,
            "createdAt": "2026-07-14",
            "url": "https://bsky.app/profile/eyalestrin.bsky.social/post/3mqli7q37zh2a",
            "origin": false,
            "authority": false,
            "github": []
          },
          {
            "handle": "ahmandonk.bsky.social",
            "displayName": "Ahmandonk",
            "likes": 1,
            "reposts": 0,
            "replies": 0,
            "createdAt": "2026-07-14",
            "url": "https://bsky.app/profile/ahmandonk.bsky.social/post/3mqloi5uyei22",
            "origin": false,
            "authority": false,
            "github": []
          },
          {
            "handle": "cybernewsroom.bsky.social",
            "displayName": "Cyber Newsroom",
            "likes": 1,
            "reposts": 0,
            "replies": 0,
            "createdAt": "2026-07-13",
            "url": "https://bsky.app/profile/cybernewsroom.bsky.social/post/3mqjfhxw7if2k",
            "origin": false,
            "authority": false,
            "github": []
          },
          {
            "handle": "toxy4ny.bsky.social",
            "displayName": "KL3FT3Z",
            "likes": 1,
            "reposts": 0,
            "replies": 0,
            "createdAt": "2026-07-13",
            "url": "https://bsky.app/profile/toxy4ny.bsky.social/post/3mqkmnbpmtc2n",
            "origin": false,
            "authority": false,
            "github": []
          },
          {
            "handle": "newssecia.bsky.social",
            "displayName": null,
            "likes": 1,
            "reposts": 0,
            "replies": 0,
            "createdAt": "2026-07-13",
            "url": "https://bsky.app/profile/newssecia.bsky.social/post/3mqj5wg6v462s",
            "origin": false,
            "authority": false,
            "github": []
          },
          {
            "handle": "securityrss.bsky.social",
            "displayName": "securityrss.ai",
            "likes": 0,
            "reposts": 1,
            "replies": 0,
            "createdAt": "2026-07-13",
            "url": "https://bsky.app/profile/securityrss.bsky.social/post/3mqjplozg4p2v",
            "origin": false,
            "authority": false,
            "github": []
          }
        ]
      },
      "telegram": {
        "mentions": 2,
        "posts": [
          {
            "channel": "PentestingNews",
            "channelTitle": "Pentesting News",
            "tier": "news",
            "date": "2026-07-13",
            "views": 440,
            "forwards": 2,
            "url": "https://t.me/PentestingNews/75097",
            "text": "CISA Warns of Actively Exploited Joomla Zero-Day Vulnerabilities https://thecyberexpress.com/cisa-cve-2026-48939-cve-2026-56291/",
            "github": [],
            "origin": false
          }
        ]
      },
      "researchers": [
        "Polosss"
      ],
      "corroboration": {
        "poc": true,
        "xOrigin": false,
        "independent": [
          "poc",
          "x-mention"
        ],
        "level": "multi-source"
      },
      "aliases": []
    },
    {
      "cve": "CVE-2026-48908",
      "title": "JoomShaper SP Page Builder Unrestricted Upload of File with Dangerous Type Vulnerability",
      "category": "JoomShaper",
      "vendor": "JoomShaper",
      "product": "SP Page Builder",
      "exploited": true,
      "publiclyDisclosed": false,
      "faq": "JoomShaper SP Page Builder contains an unrestricted upload of file with dangerous type vulnerability that allows unauthenticated users to upload arbitrary files, ultimately resulting in the upload and execution of PHP code.",
      "cvss": 9.8,
      "cvssVector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "severity": "CRITICAL",
      "impact": null,
      "products": [
        "SP Page Builder"
      ],
      "productCount": 1,
      "mitreUrl": "https://nvd.nist.gov/vuln/detail/CVE-2026-48908",
      "source": "kev",
      "kev": {
        "dateAdded": "2026-07-07",
        "dueDate": "2026-07-10",
        "requiredAction": "Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.",
        "ransomware": false,
        "cwes": [
          "CWE-434"
        ],
        "references": [
          "https://extensions.joomla.org/extension/sp-page-builder/",
          "https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk",
          "https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk",
          "https://nvd.nist.gov/vuln/detail/CVE-2026-48908"
        ]
      },
      "epss": 0.01569,
      "epssPercentile": 0.72649,
      "pocCount": 5,
      "pocTopStars": 14,
      "pocConfidence": "confirmed",
      "pocRepos": [
        {
          "url": "https://github.com/papageo75/CVE-2026-48908-PoC",
          "stars": 14,
          "desc": "Unauthenticated RCE PoC for CVE-2026-48908 — SP Page Builder for Joomla (≤ 6.6.1): arbitrary file upload via asset.uploadCustomIcon. Self-cleaning, token-guarde",
          "createdAt": "2026-06-22",
          "hasCode": true
        },
        {
          "url": "https://github.com/Jenderal92/CVE-2026-48908",
          "stars": 2,
          "desc": "CVE-2026-48908 — PoC exploit for unauthenticated RCE in SP Page Builder (Joomla) via arbitrary file upload. Multi‑threaded, case‑bypass, shell verification. For",
          "createdAt": "2026-07-07",
          "hasCode": true
        },
        {
          "url": "https://github.com/0xBlackash/CVE-2026-48908",
          "stars": 1,
          "desc": "CVE-2026-48908",
          "createdAt": "2026-06-24",
          "hasCode": true
        },
        {
          "url": "https://github.com/gagaltotal/CVE-2026-48908-SP-Page-Builder-Joomla",
          "stars": 0,
          "desc": "CVE-2026-48908 - SP Page Builder Joomla Unauthenticated RCE",
          "createdAt": "2026-06-24",
          "hasCode": true
        },
        {
          "url": "https://github.com/ayiezola/CVE-2026-48908",
          "stars": 0,
          "desc": "Unauthenticated RCE PoC for CVE-2026-48908  SP Page Builder (Joomla) arbitrary file upload and remote code execution exploit with mass scaning support.",
          "createdAt": "2026-06-28",
          "hasCode": true
        }
      ],
      "published": "2026-06-20T13:16:42.080",
      "research": [],
      "x": {
        "mentions": 76,
        "aliases": [],
        "posts": [
          {
            "handle": "vutruso",
            "followers": 38,
            "likes": 0,
            "createdAt": "2026-07-08",
            "url": "https://x.com/vutruso/status/2074690046486290926",
            "github": [
              {
                "url": "https://github.com/V4bel/Januscape",
                "hasCode": true
              }
            ],
            "origin": false
          },
          {
            "handle": "nebusecurity",
            "followers": 4500,
            "likes": 240,
            "createdAt": "2026-07-08",
            "url": "https://x.com/nebusecurity/status/2074663573742338256",
            "github": [],
            "origin": false
          },
          {
            "handle": "__kokumoto",
            "followers": 7578,
            "likes": 7,
            "createdAt": "2026-07-08",
            "url": "https://x.com/__kokumoto/status/2074698589713154281",
            "github": [],
            "origin": false
          },
          {
            "handle": "yousukezan",
            "followers": 14384,
            "likes": 6,
            "createdAt": "2026-07-08",
            "url": "https://x.com/yousukezan/status/2074650902166913222",
            "github": [],
            "origin": false
          },
          {
            "handle": "ridvanyagli",
            "followers": 1120,
            "likes": 6,
            "createdAt": "2026-07-08",
            "url": "https://x.com/ridvanyagli/status/2074701200167952860",
            "github": [],
            "origin": false
          },
          {
            "handle": "Daily_CyberSec",
            "followers": 12430,
            "likes": 5,
            "createdAt": "2026-07-08",
            "url": "https://x.com/Daily_CyberSec/status/2074678524191855020",
            "github": [],
            "origin": false
          },
          {
            "handle": "oss_security",
            "followers": 4646,
            "likes": 4,
            "createdAt": "2026-07-08",
            "url": "https://x.com/oss_security/status/2074685116626907570",
            "github": [],
            "origin": false
          },
          {
            "handle": "ohhara_shiojiri",
            "followers": 2004,
            "likes": 1,
            "createdAt": "2026-07-08",
            "url": "https://x.com/ohhara_shiojiri/status/2074727301179408802",
            "github": [],
            "origin": false
          }
        ]
      },
      "bsky": {
        "mentions": 43,
        "posts": [
          {
            "handle": "infosec.skyfleet.blue",
            "displayName": "InfoSec",
            "likes": 5,
            "reposts": 1,
            "replies": 0,
            "createdAt": "2026-07-02",
            "url": "https://bsky.app/profile/infosec.skyfleet.blue/post/3mpnkwum44r2x",
            "origin": true,
            "authority": true,
            "github": []
          },
          {
            "handle": "bleepingcomputer.com",
            "displayName": "BleepingComputer",
            "likes": 4,
            "reposts": 2,
            "replies": 0,
            "createdAt": "2026-07-01",
            "url": "https://bsky.app/profile/bleepingcomputer.com/post/3mpmd2ruarv2l",
            "origin": true,
            "authority": true,
            "github": []
          },
          {
            "handle": "campuscodi.risky.biz",
            "displayName": "Catalin Cimpanu",
            "likes": 2,
            "reposts": 1,
            "replies": 2,
            "createdAt": "2026-07-03",
            "url": "https://bsky.app/profile/campuscodi.risky.biz/post/3mpq6imguic2y",
            "origin": true,
            "authority": true,
            "github": []
          },
          {
            "handle": "trinacriatech.bsky.social",
            "displayName": null,
            "likes": 2,
            "reposts": 0,
            "replies": 0,
            "createdAt": "2026-07-06",
            "url": "https://bsky.app/profile/trinacriatech.bsky.social/post/3mpyxq7y6oc2z",
            "origin": true,
            "authority": false,
            "github": []
          },
          {
            "handle": "ahmandonk.bsky.social",
            "displayName": "Ahmandonk",
            "likes": 2,
            "reposts": 0,
            "replies": 0,
            "createdAt": "2026-07-05",
            "url": "https://bsky.app/profile/ahmandonk.bsky.social/post/3mpvwgjir5j2r",
            "origin": true,
            "authority": false,
            "github": []
          },
          {
            "handle": "blindthoughts.bsky.social",
            "displayName": "blindthoughts.bsky.social",
            "likes": 2,
            "reposts": 0,
            "replies": 0,
            "createdAt": "2026-07-02",
            "url": "https://bsky.app/profile/blindthoughts.bsky.social/post/3mpnbpwhb5427",
            "origin": true,
            "authority": false,
            "github": []
          }
        ]
      },
      "telegram": {
        "mentions": 0,
        "posts": []
      },
      "corroboration": {
        "poc": true,
        "xOrigin": false,
        "independent": [
          "poc",
          "x-mention"
        ],
        "level": "multi-source"
      },
      "aliases": [],
      "researchers": []
    },
    {
      "cve": "CVE-2026-55255",
      "title": "Langflow Authorization Bypass Through User-Controlled Key Vulnerability",
      "category": "Langflow",
      "vendor": "Langflow",
      "product": "Langflow",
      "exploited": true,
      "publiclyDisclosed": false,
      "faq": "Langflow contains an authorization bypass through user-controlled key vulnerability which allows an authenticated attacker to execute any flow belonging to another user by specifying the victim's flow ID in the request.",
      "cvss": 8.4,
      "cvssVector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:L",
      "severity": "HIGH",
      "impact": null,
      "products": [
        "Langflow"
      ],
      "productCount": 1,
      "mitreUrl": "https://nvd.nist.gov/vuln/detail/CVE-2026-55255",
      "source": "kev",
      "kev": {
        "dateAdded": "2026-07-07",
        "dueDate": "2026-07-10",
        "requiredAction": "Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.",
        "ransomware": false,
        "cwes": [
          "CWE-639"
        ],
        "references": [
          "https://github.com/langflow-ai/langflow/security/advisories/GHSA-qrpv-q767-xqq2",
          "https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk",
          "https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk",
          "https://nvd.nist.gov/vuln/detail/CVE-2026-55255"
        ]
      },
      "epss": 0.0056,
      "epssPercentile": 0.42931,
      "pocCount": 0,
      "pocTopStars": 0,
      "pocConfidence": "none",
      "pocRepos": [],
      "published": "2026-06-23T17:17:08.050",
      "research": [],
      "x": {
        "mentions": 0,
        "aliases": [],
        "posts": []
      },
      "bsky": {
        "mentions": 8,
        "posts": [
          {
            "handle": "suriq.io",
            "displayName": "Suriq - Always on Watch",
            "likes": 2,
            "reposts": 0,
            "replies": 1,
            "createdAt": "2026-06-19",
            "url": "https://bsky.app/profile/suriq.io/post/3mook75kc3e2d",
            "origin": false,
            "authority": false,
            "github": []
          },
          {
            "handle": "cvesentinel.bsky.social",
            "displayName": "CVESentinel",
            "likes": 1,
            "reposts": 0,
            "replies": 0,
            "createdAt": "2026-07-07",
            "url": "https://bsky.app/profile/cvesentinel.bsky.social/post/3mq36dr4s372w",
            "origin": false,
            "authority": false,
            "github": []
          },
          {
            "handle": "cyberhub.blog",
            "displayName": "CyberHub",
            "likes": 1,
            "reposts": 0,
            "replies": 0,
            "createdAt": "2026-06-25",
            "url": "https://bsky.app/profile/cyberhub.blog/post/3mp3fj5b7sq2n",
            "origin": false,
            "authority": false,
            "github": []
          },
          {
            "handle": "shiojiri.com",
            "displayName": "ohhara",
            "likes": 0,
            "reposts": 0,
            "replies": 0,
            "createdAt": "2026-07-08",
            "url": "https://bsky.app/profile/shiojiri.com/post/3mq4cpumcxcfn",
            "origin": false,
            "authority": false,
            "github": []
          },
          {
            "handle": "stackflag.bsky.social",
            "displayName": "STACKFLAG",
            "likes": 0,
            "reposts": 0,
            "replies": 0,
            "createdAt": "2026-07-07",
            "url": "https://bsky.app/profile/stackflag.bsky.social/post/3mq354ildoj2e",
            "origin": false,
            "authority": false,
            "github": []
          },
          {
            "handle": "csirts.bsky.social",
            "displayName": "CSIRTS.COM",
            "likes": 0,
            "reposts": 0,
            "replies": 0,
            "createdAt": "2026-07-07",
            "url": "https://bsky.app/profile/csirts.bsky.social/post/3mq34zqafiw2q",
            "origin": false,
            "authority": false,
            "github": []
          }
        ]
      },
      "telegram": {
        "mentions": 1,
        "posts": [
          {
            "channel": "VulnerabilityNews",
            "channelTitle": "Vulnerability News",
            "tier": "news",
            "date": "2026-07-07",
            "views": 41,
            "forwards": 1,
            "url": "https://t.me/VulnerabilityNews/43355",
            "text": "CISA Adds Three Known Exploited Vulnerabilities to Catalog CISA has added three new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation. CVE-2026-48908 JoomShaper SP Page Builder Unrestricted Upload of File with Dangerous Type Vulnerability CVE-2026-55255 Langflow Authorization Bypass Through User-Controlled Key Vulnerability CVE-2026-5629",
            "github": [],
            "origin": false
          }
        ]
      },
      "corroboration": {
        "poc": false,
        "xOrigin": false,
        "independent": [],
        "level": "cisa-attributed"
      },
      "aliases": [],
      "researchers": []
    },
    {
      "cve": "CVE-2026-56290",
      "title": "Joomlack Page Builder Improper Access Control Vulnerability",
      "category": "Joomlack",
      "vendor": "Joomlack",
      "product": "Page Builder",
      "exploited": true,
      "publiclyDisclosed": false,
      "faq": "Joomlack Page Builder contains an improper access control vulnerability that could allow for remote code execution via unauthenticated arbitrary file upload.",
      "cvss": 9.8,
      "cvssVector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "severity": "CRITICAL",
      "impact": null,
      "products": [
        "Page Builder"
      ],
      "productCount": 1,
      "mitreUrl": "https://nvd.nist.gov/vuln/detail/CVE-2026-56290",
      "source": "kev",
      "kev": {
        "dateAdded": "2026-07-07",
        "dueDate": "2026-07-10",
        "requiredAction": "Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.",
        "ransomware": false,
        "cwes": [
          "CWE-284"
        ],
        "references": [
          "https://www.joomlack.fr/en/joomla-extensions/page-builder-ck",
          "https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk",
          "https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk",
          "https://nvd.nist.gov/vuln/detail/CVE-2026-56290"
        ]
      },
      "epss": 0.02912,
      "epssPercentile": 0.85485,
      "pocCount": 4,
      "pocTopStars": 3,
      "pocConfidence": "confirmed",
      "pocRepos": [
        {
          "url": "https://github.com/shinthink/pbck-exploit",
          "stars": 3,
          "desc": "📤 Mass exploitation framework for CVE-2026-56290 — Page Builder CK Joomla unauthenticated file upload to RCE",
          "createdAt": "2026-07-04",
          "hasCode": true
        },
        {
          "url": "https://github.com/Jenderal92/CVE-2026-56290",
          "stars": 3,
          "desc": "CVE-2026-56290 - Mass Exploit for Joomla Com_pagebuilderck component (Unrestricted File Upload → RCE). Multi-threaded, automatic CSRF bypass, PHP shell uploader",
          "createdAt": "2026-07-08",
          "hasCode": true
        },
        {
          "url": "https://github.com/sagsooz/PageBuilderCK-CVE-2026-56290-Exploit",
          "stars": 2,
          "desc": "Page Builder CK for Joomla - Unauthenticated SSRF / Remote File Write leading to PHP execution Exploiter",
          "createdAt": "2026-07-03",
          "hasCode": true
        },
        {
          "url": "https://github.com/ChiefYoru/CVE-2026-56290_PoC",
          "stars": 0,
          "desc": "The Joomla extension Page Builder CK is vulnerable to an unauthenticated arbitrary file upload that allows uploading executable files and leads to full RCE.",
          "createdAt": "2026-07-19",
          "hasCode": true
        }
      ],
      "published": "2026-06-29T15:16:42.360",
      "research": [
        {
          "url": "https://github.com/shinthink/pbck-exploit",
          "type": "poc",
          "source": "GitHub / shinthink",
          "note": "Mass exploit framework; unauthenticated file upload→RCE",
          "hasCode": true
        },
        {
          "url": "https://mysites.guru/blog/pagebuilderck-unauthenticated-file-upload-rce/",
          "type": "writeup",
          "source": "mySites.guru / Phil Taylor (finder)",
          "note": "Discoverer writeup; source-diff & live exploitation confirmed"
        },
        {
          "url": "https://www.cisa.gov/news-events/alerts/2026/07/07/cisa-adds-three-known-exploited-vulnerabilities-catalog",
          "type": "detection",
          "source": "CISA KEV",
          "note": "Added to KEV catalog 2026-07-07; patch mandated"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56290",
          "type": "detection",
          "source": "NVD / NIST",
          "note": "Official CVE record; CVSS 10.0, CWE-284/CWE-434"
        },
        {
          "url": "https://www.sentinelone.com/vulnerability-database/cve-2026-56290/",
          "type": "writeup",
          "source": "SentinelOne Vulnerability DB",
          "note": "Technical breakdown; detection IOCs; affected versions"
        },
        {
          "url": "https://www.ionix.io/threat-center/cve-2026-56290/",
          "type": "writeup",
          "source": "IONIX Threat Center",
          "note": "Root cause, attack vector, in-wild exploitation details"
        },
        {
          "url": "https://ccb.belgium.be/advisories/warning-critical-unauthenticated-arbitrary-file-upload-vulnerability-cve-2026-56290",
          "type": "detection",
          "source": "CCB Belgium (national CERT)",
          "note": "Govt advisory; patch & monitoring guidance"
        },
        {
          "url": "https://app.opencve.io/cve/CVE-2026-56290",
          "type": "detection",
          "source": "OpenCVE / CISA ADP Vulnrichment",
          "note": "Structured CVE record with CISA SSVC enrichment"
        }
      ],
      "x": {
        "mentions": 75,
        "aliases": [],
        "posts": [
          {
            "handle": "vutruso",
            "followers": 38,
            "likes": 0,
            "createdAt": "2026-07-08",
            "url": "https://x.com/vutruso/status/2074690046486290926",
            "github": [
              {
                "url": "https://github.com/V4bel/Januscape",
                "hasCode": true
              }
            ],
            "origin": false
          },
          {
            "handle": "nebusecurity",
            "followers": 4500,
            "likes": 240,
            "createdAt": "2026-07-08",
            "url": "https://x.com/nebusecurity/status/2074663573742338256",
            "github": [],
            "origin": false
          },
          {
            "handle": "__kokumoto",
            "followers": 7578,
            "likes": 7,
            "createdAt": "2026-07-08",
            "url": "https://x.com/__kokumoto/status/2074698589713154281",
            "github": [],
            "origin": false
          },
          {
            "handle": "yousukezan",
            "followers": 14384,
            "likes": 6,
            "createdAt": "2026-07-08",
            "url": "https://x.com/yousukezan/status/2074650902166913222",
            "github": [],
            "origin": false
          },
          {
            "handle": "ridvanyagli",
            "followers": 1120,
            "likes": 6,
            "createdAt": "2026-07-08",
            "url": "https://x.com/ridvanyagli/status/2074701200167952860",
            "github": [],
            "origin": false
          },
          {
            "handle": "Daily_CyberSec",
            "followers": 12430,
            "likes": 5,
            "createdAt": "2026-07-08",
            "url": "https://x.com/Daily_CyberSec/status/2074678524191855020",
            "github": [],
            "origin": false
          },
          {
            "handle": "oss_security",
            "followers": 4646,
            "likes": 4,
            "createdAt": "2026-07-08",
            "url": "https://x.com/oss_security/status/2074685116626907570",
            "github": [],
            "origin": false
          },
          {
            "handle": "ohhara_shiojiri",
            "followers": 2004,
            "likes": 1,
            "createdAt": "2026-07-08",
            "url": "https://x.com/ohhara_shiojiri/status/2074727301179408802",
            "github": [],
            "origin": false
          }
        ]
      },
      "bsky": {
        "mentions": 15,
        "posts": [
          {
            "handle": "cyberhub.blog",
            "displayName": "CyberHub",
            "likes": 1,
            "reposts": 0,
            "replies": 0,
            "createdAt": "2026-07-03",
            "url": "https://bsky.app/profile/cyberhub.blog/post/3mppkw5emi42f",
            "origin": false,
            "authority": false,
            "github": []
          },
          {
            "handle": "shiojiri.com",
            "displayName": "ohhara",
            "likes": 0,
            "reposts": 0,
            "replies": 0,
            "createdAt": "2026-07-08",
            "url": "https://bsky.app/profile/shiojiri.com/post/3mq4cpumcxcfn",
            "origin": false,
            "authority": false,
            "github": []
          },
          {
            "handle": "csirts.bsky.social",
            "displayName": "CSIRTS.COM",
            "likes": 0,
            "reposts": 0,
            "replies": 0,
            "createdAt": "2026-07-07",
            "url": "https://bsky.app/profile/csirts.bsky.social/post/3mq34zqoytw2d",
            "origin": false,
            "authority": false,
            "github": []
          },
          {
            "handle": "cvesentinel.bsky.social",
            "displayName": "CVESentinel",
            "likes": 0,
            "reposts": 0,
            "replies": 0,
            "createdAt": "2026-07-07",
            "url": "https://bsky.app/profile/cvesentinel.bsky.social/post/3mq36drvbnv2c",
            "origin": false,
            "authority": false,
            "github": []
          },
          {
            "handle": "stackflag.bsky.social",
            "displayName": "STACKFLAG",
            "likes": 0,
            "reposts": 0,
            "replies": 0,
            "createdAt": "2026-07-07",
            "url": "https://bsky.app/profile/stackflag.bsky.social/post/3mq354jypwd2k",
            "origin": false,
            "authority": false,
            "github": []
          },
          {
            "handle": "qiancx.bsky.social",
            "displayName": "qian.cx",
            "likes": 0,
            "reposts": 0,
            "replies": 0,
            "createdAt": "2026-07-05",
            "url": "https://bsky.app/profile/qiancx.bsky.social/post/3mpweckcrlh2r",
            "origin": false,
            "authority": false,
            "github": []
          }
        ]
      },
      "telegram": {
        "mentions": 0,
        "posts": []
      },
      "researchers": [
        "philtaylor_mysitesguru"
      ],
      "corroboration": {
        "poc": true,
        "xOrigin": false,
        "independent": [
          "poc",
          "x-mention"
        ],
        "level": "multi-source"
      },
      "aliases": []
    },
    {
      "cve": "CVE-2026-48282",
      "title": "Adobe ColdFusion Path Traversal Vulnerability",
      "category": "Adobe",
      "vendor": "Adobe",
      "product": "ColdFusion",
      "exploited": true,
      "publiclyDisclosed": false,
      "faq": "Adobe ColdFusion contains a path traversal vulnerability that could lead to arbitrary code execution in the context of the current user.",
      "cvss": 10,
      "cvssVector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H",
      "severity": "CRITICAL",
      "impact": null,
      "products": [
        "ColdFusion"
      ],
      "productCount": 1,
      "mitreUrl": "https://nvd.nist.gov/vuln/detail/CVE-2026-48282",
      "source": "kev",
      "kev": {
        "dateAdded": "2026-07-07",
        "dueDate": "2026-07-10",
        "requiredAction": "Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.",
        "ransomware": false,
        "cwes": [
          "CWE-22"
        ],
        "references": [
          "https://helpx.adobe.com/security/products/coldfusion/apsb26-68.html",
          "https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk",
          "https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk",
          "https://nvd.nist.gov/vuln/detail/CVE-2026-48282"
        ]
      },
      "epss": 0.28583,
      "epssPercentile": 0.97927,
      "pocCount": 1,
      "pocTopStars": 22,
      "pocConfidence": "confirmed",
      "pocRepos": [
        {
          "url": "https://github.com/imbas007/CVE-2026-48282",
          "stars": 22,
          "desc": "",
          "createdAt": "2026-07-06",
          "hasCode": true
        }
      ],
      "published": "2026-06-30T16:16:54.533",
      "research": [
        {
          "url": "https://labs.watchtowr.com/its-37oc-and-all-we-can-think-about-is-coldfusion-adobe-coldfusion-security-bulletin-apsb26-68-cve-bonanza/",
          "type": "writeup",
          "source": "watchTowr Labs / Sina Kheirkhah",
          "note": "Deep patch-diff; RDS FILEIO arb file write/read analysis"
        },
        {
          "url": "https://github.com/imbas007/CVE-2026-48282",
          "type": "poc",
          "source": "GitHub / imbas007",
          "note": "Python PoC: check, read, write, browse via RDS endpoint",
          "hasCode": true
        },
        {
          "url": "https://www.resecurity.com/blog/article/cve-2026-48282-adobe-coldfusion-rds-path-traversal-leading-to-rce",
          "type": "writeup",
          "source": "Resecurity",
          "note": "Technical breakdown: FILEIO handler, webshell write to RCE"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-48282",
          "type": "detection",
          "source": "NVD / NIST",
          "note": "Official CVE record; CVSS 10.0 path traversal → RCE"
        },
        {
          "url": "https://github.com/projectdiscovery/nuclei-templates/pull/16538",
          "type": "module",
          "source": "ProjectDiscovery / DhiyaneshGeek",
          "note": "Nuclei template PR: ColdFusion RDS arb file write check",
          "hasCode": true
        },
        {
          "url": "https://www.bleepingcomputer.com/news/security/max-severity-adobe-coldfusion-flaw-now-exploited-in-attacks/",
          "type": "detection",
          "source": "BleepingComputer",
          "note": "IOC guidance: /CFIDE/ webshell hunting, KEVIntel ITW data"
        },
        {
          "url": "https://www.helpnetsecurity.com/2026/07/07/adobe-coldfusion-cve-2026-48282-exploitation-detected/",
          "type": "detection",
          "source": "Help Net Security",
          "note": "Exploitation timeline, CCCS advisory AV26-647, IoCs"
        },
        {
          "url": "https://thehackernews.com/2026/07/adobe-patches-7-cvss-100-flaws-in.html",
          "type": "writeup",
          "source": "The Hacker News",
          "note": "Exploit payload sample, watchTowr/KEVIntel attribution"
        }
      ],
      "x": {
        "mentions": 140,
        "aliases": [],
        "posts": [
          {
            "handle": "DarkWebInformer",
            "followers": 222189,
            "likes": 58,
            "createdAt": "2026-07-07",
            "url": "https://x.com/DarkWebInformer/status/2074627080579375543",
            "github": [
              {
                "url": "https://github.com/imbas007/CVE-2026-48282",
                "hasCode": true
              }
            ],
            "origin": false
          },
          {
            "handle": "ridvanyagli",
            "followers": 1120,
            "likes": 1,
            "createdAt": "2026-07-08",
            "url": "https://x.com/ridvanyagli/status/2074661987389190305",
            "github": [
              {
                "url": "https://github.com/imbas007/CVE-2026-48282",
                "hasCode": true
              }
            ],
            "origin": false
          },
          {
            "handle": "vutruso",
            "followers": 38,
            "likes": 0,
            "createdAt": "2026-07-08",
            "url": "https://x.com/vutruso/status/2074690046486290926",
            "github": [
              {
                "url": "https://github.com/V4bel/Januscape",
                "hasCode": true
              }
            ],
            "origin": false
          },
          {
            "handle": "nebusecurity",
            "followers": 4500,
            "likes": 240,
            "createdAt": "2026-07-08",
            "url": "https://x.com/nebusecurity/status/2074663573742338256",
            "github": [],
            "origin": false
          },
          {
            "handle": "__kokumoto",
            "followers": 7578,
            "likes": 7,
            "createdAt": "2026-07-08",
            "url": "https://x.com/__kokumoto/status/2074698589713154281",
            "github": [],
            "origin": false
          },
          {
            "handle": "ptdbugs",
            "followers": 2267,
            "likes": 7,
            "createdAt": "2026-07-07",
            "url": "https://x.com/ptdbugs/status/2074464871832268812",
            "github": [],
            "origin": false
          },
          {
            "handle": "yousukezan",
            "followers": 14384,
            "likes": 6,
            "createdAt": "2026-07-08",
            "url": "https://x.com/yousukezan/status/2074650902166913222",
            "github": [],
            "origin": false
          },
          {
            "handle": "Daily_CyberSec",
            "followers": 12430,
            "likes": 5,
            "createdAt": "2026-07-08",
            "url": "https://x.com/Daily_CyberSec/status/2074678524191855020",
            "github": [],
            "origin": false
          }
        ]
      },
      "bsky": {
        "mentions": 25,
        "posts": [
          {
            "handle": "bleepingcomputer.com",
            "displayName": "BleepingComputer",
            "likes": 4,
            "reposts": 2,
            "replies": 0,
            "createdAt": "2026-07-06",
            "url": "https://bsky.app/profile/bleepingcomputer.com/post/3mpy6ivjebg2g",
            "origin": false,
            "authority": true,
            "github": []
          },
          {
            "handle": "intelnightowl.bsky.social",
            "displayName": "Intel Night OWL 🦉🇺🇸",
            "likes": 1,
            "reposts": 0,
            "replies": 0,
            "createdAt": "2026-07-06",
            "url": "https://bsky.app/profile/intelnightowl.bsky.social/post/3mpyzzusqaa2y",
            "origin": false,
            "authority": true,
            "github": []
          },
          {
            "handle": "infosec.skyfleet.blue",
            "displayName": "InfoSec",
            "likes": 0,
            "reposts": 0,
            "replies": 0,
            "createdAt": "2026-07-07",
            "url": "https://bsky.app/profile/infosec.skyfleet.blue/post/3mpzy3jdskx2r",
            "origin": false,
            "authority": true,
            "github": []
          },
          {
            "handle": "thecircuitry.to",
            "displayName": "The Circuitry",
            "likes": 1,
            "reposts": 0,
            "replies": 0,
            "createdAt": "2026-07-07",
            "url": "https://bsky.app/profile/thecircuitry.to/post/3mpzddyomc72v",
            "origin": false,
            "authority": false,
            "github": []
          },
          {
            "handle": "sergioiker.bsky.social",
            "displayName": "Dr.Sergio E. Sanchez… Dr. Qubit",
            "likes": 0,
            "reposts": 0,
            "replies": 1,
            "createdAt": "2026-07-07",
            "url": "https://bsky.app/profile/sergioiker.bsky.social/post/3mq2qyb6slk2o",
            "origin": false,
            "authority": false,
            "github": []
          },
          {
            "handle": "netsecio.bsky.social",
            "displayName": "CyberNetSecIO",
            "likes": 1,
            "reposts": 0,
            "replies": 0,
            "createdAt": "2026-07-07",
            "url": "https://bsky.app/profile/netsecio.bsky.social/post/3mq333dmrjj2p",
            "origin": false,
            "authority": false,
            "github": []
          }
        ]
      },
      "telegram": {
        "mentions": 4,
        "posts": [
          {
            "channel": "VulnerabilityNews",
            "channelTitle": "Vulnerability News",
            "tier": "news",
            "date": "2026-07-06",
            "views": 43,
            "forwards": 1,
            "url": "https://t.me/VulnerabilityNews/43320",
            "text": "Max severity Adobe ColdFusion flaw now exploited in attacks Attackers are now exploiting a maximum-severity Adobe ColdFusion vulnerability tracked as CVE-2026-48282, according to vulnerability intelligence company KEVIntel. [...] https://www.bleepingcomputer.com/news/security/max-severity-adobe-coldfusion-flaw-now-exploited-in-attacks/",
            "github": [],
            "origin": false
          }
        ]
      },
      "researchers": [
        "SinSinology",
        "ethicalhack3r"
      ],
      "corroboration": {
        "poc": true,
        "xOrigin": false,
        "independent": [
          "poc",
          "x-mention"
        ],
        "level": "multi-source"
      },
      "aliases": []
    },
    {
      "cve": "CVE-2026-45659",
      "title": "Microsoft SharePoint Server Deserialization of Untrusted Data Vulnerability",
      "category": "Microsoft",
      "vendor": "Microsoft",
      "product": "SharePoint Server",
      "exploited": true,
      "publiclyDisclosed": false,
      "faq": "Microsoft SharePoint Server contains a deserialization of untrusted data vulnerability which allows an authorized attacker to execute code over a network.",
      "cvss": 8.8,
      "cvssVector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "severity": "HIGH",
      "impact": null,
      "products": [
        "SharePoint Server"
      ],
      "productCount": 1,
      "mitreUrl": "https://nvd.nist.gov/vuln/detail/CVE-2026-45659",
      "source": "kev",
      "kev": {
        "dateAdded": "2026-07-01",
        "dueDate": "2026-07-04",
        "requiredAction": "Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.",
        "ransomware": false,
        "cwes": [
          "CWE-502"
        ],
        "references": [
          "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45659",
          "https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk",
          "https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk",
          "https://nvd.nist.gov/vuln/detail/CVE-2026-45659"
        ]
      },
      "epss": 0.03219,
      "epssPercentile": 0.86834,
      "pocCount": 0,
      "pocTopStars": 0,
      "pocConfidence": "none",
      "pocRepos": [],
      "published": "2026-05-22T23:16:56.273",
      "research": [],
      "x": {
        "mentions": 9,
        "aliases": [],
        "posts": [
          {
            "handle": "PurpleOps_io",
            "followers": 604,
            "likes": 0,
            "createdAt": "2026-07-06",
            "url": "https://x.com/PurpleOps_io/status/2074059496381460723",
            "github": [],
            "origin": false
          },
          {
            "handle": "alphahunt_io",
            "followers": 141,
            "likes": 0,
            "createdAt": "2026-07-06",
            "url": "https://x.com/alphahunt_io/status/2074115397490458733",
            "github": [],
            "origin": false
          },
          {
            "handle": "ByteDrop453",
            "followers": 22,
            "likes": 0,
            "createdAt": "2026-07-06",
            "url": "https://x.com/ByteDrop453/status/2073997117996020182",
            "github": [],
            "origin": false
          }
        ]
      },
      "bsky": {
        "mentions": 25,
        "posts": [
          {
            "handle": "thecybermind.co",
            "displayName": "mikeransier.bsky.social",
            "likes": 0,
            "reposts": 0,
            "replies": 0,
            "createdAt": "2026-07-02",
            "url": "https://bsky.app/profile/thecybermind.co/post/3mpo26pfdjz25",
            "origin": false,
            "authority": true,
            "github": []
          },
          {
            "handle": "infosec.skyfleet.blue",
            "displayName": "InfoSec",
            "likes": 0,
            "reposts": 0,
            "replies": 0,
            "createdAt": "2026-07-02",
            "url": "https://bsky.app/profile/infosec.skyfleet.blue/post/3mpombjkeyg2p",
            "origin": false,
            "authority": true,
            "github": []
          },
          {
            "handle": "getpokemon7.bsky.social",
            "displayName": "まりーん",
            "likes": 0,
            "reposts": 0,
            "replies": 1,
            "createdAt": "2026-06-22",
            "url": "https://bsky.app/profile/getpokemon7.bsky.social/post/3movog3sfzk2u",
            "origin": false,
            "authority": false,
            "github": []
          },
          {
            "handle": "potato.software",
            "displayName": "CyberTaters",
            "likes": 0,
            "reposts": 0,
            "replies": 0,
            "createdAt": "2026-07-06",
            "url": "https://bsky.app/profile/potato.software/post/3mpx5tborhb2k",
            "origin": false,
            "authority": false,
            "github": []
          },
          {
            "handle": "diesec.bsky.social",
            "displayName": "DIESEC",
            "likes": 0,
            "reposts": 0,
            "replies": 0,
            "createdAt": "2026-07-06",
            "url": "https://bsky.app/profile/diesec.bsky.social/post/3mpxwqll5le2d",
            "origin": false,
            "authority": false,
            "github": []
          },
          {
            "handle": "ahmandonk.bsky.social",
            "displayName": "Ahmandonk",
            "likes": 0,
            "reposts": 0,
            "replies": 0,
            "createdAt": "2026-07-06",
            "url": "https://bsky.app/profile/ahmandonk.bsky.social/post/3mpx5tbcopm2v",
            "origin": false,
            "authority": false,
            "github": []
          }
        ]
      },
      "telegram": {
        "mentions": 3,
        "posts": [
          {
            "channel": "thehackernews",
            "channelTitle": "The Hacker News",
            "tier": "news",
            "date": "2026-05-26",
            "views": 8323,
            "forwards": 31,
            "url": "https://t.me/thehackernews/9083",
            "text": "⚠️ SharePoint RCE Vulnerability. Details → https://thehackernews.com/2026/05/microsoft-patches-sharepoint-rce-flaw.html CVE-2026-45659 allows authenticated attackers with only Site Member permissions to execute code remotely on SharePoint Server. The CVSS 8.8 flaw affects SharePoint Server 2016, 2019, and Subscription Edition.",
            "github": [],
            "origin": false
          }
        ]
      },
      "corroboration": {
        "poc": false,
        "xOrigin": false,
        "independent": [
          "x-mention"
        ],
        "level": "multi-source"
      },
      "aliases": [],
      "researchers": []
    },
    {
      "cve": "CVE-2026-48558",
      "title": "SimpleHelp Authentication Bypass Vulnerability",
      "category": "SimpleHelp ",
      "vendor": "SimpleHelp ",
      "product": "SimpleHelp",
      "exploited": true,
      "publiclyDisclosed": false,
      "faq": "SimpleHelp contains an authentication bypass vulnerability in the OIDC authentication flow. When OIDC authentication is configured, identity tokens submitted during login are accepted without verifying their cryptographic signature. In a vulnerable configuration, a remote, unauthenticated attacker can submit a forged token containing arbitrary identity claims to obtain a fully authenticated technician session. In some configurations, this may also allow bypass of multi-factor authentication.",
      "cvss": 10,
      "cvssVector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H",
      "severity": "CRITICAL",
      "impact": null,
      "products": [
        "SimpleHelp"
      ],
      "productCount": 1,
      "mitreUrl": "https://nvd.nist.gov/vuln/detail/CVE-2026-48558",
      "source": "kev",
      "kev": {
        "dateAdded": "2026-06-29",
        "dueDate": "2026-07-02",
        "requiredAction": "Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.",
        "ransomware": false,
        "cwes": [
          "CWE-347"
        ],
        "references": [
          "https://simple-help.com/security/simplehelp-security-update-2026-05",
          "https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk",
          "https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk",
          "https://nvd.nist.gov/vuln/detail/CVE-2026-48558"
        ]
      },
      "epss": 0.0116,
      "epssPercentile": 0.63645,
      "pocCount": 1,
      "pocTopStars": 7,
      "pocConfidence": "confirmed",
      "pocRepos": [
        {
          "url": "https://github.com/J4ck3LSyN-Gen2/CVE-2026-48558",
          "stars": 7,
          "desc": "SimpleHelp OIDC Authentication Bypass PoC",
          "createdAt": "2026-07-02",
          "hasCode": true
        }
      ],
      "published": "2026-06-12T18:16:35.317",
      "research": [
        {
          "url": "https://horizon3.ai/attack-research/disclosures/cve-2026-48558-simplehelp-authentication-bypass-iocs/",
          "type": "writeup",
          "source": "Horizon3.ai / Zach Hanley",
          "note": "Discoverer writeup: IoCs, OIDC bypass mechanics, timeline"
        },
        {
          "url": "https://horizon3.ai/attack-research/vulnerabilities/cve-2026-48558/",
          "type": "writeup",
          "source": "Horizon3.ai",
          "note": "Vuln advisory: conditions, affected versions, remediation"
        },
        {
          "url": "https://github.com/J4ck3LSyN-Gen2/CVE-2026-48558",
          "type": "poc",
          "source": "GitHub / J4ck3LSyN-Gen2",
          "note": "Python PoC (poc.py): forges JWT, creates Technician acct",
          "hasCode": true
        },
        {
          "url": "https://dbugs.ptsecurity.com/vulnerability/PT-2026-48947",
          "type": "poc",
          "source": "Positive Technologies / ptdbugs",
          "note": "PT Python exploit, PT ID PT-2026-48947, SYSTEM privs"
        },
        {
          "url": "https://arcticwolf.com/resources/blog/cve-2026-48558-critical-authentication-bypass-vulnerability-in-simplehelp-rmm-exploited-for-credential-theft-and-malware-delivery/",
          "type": "writeup",
          "source": "Arctic Wolf",
          "note": "Active exploitation: Djinn Stealer, credential theft TTPs"
        },
        {
          "url": "https://www.bleepingcomputer.com/news/security/hackers-exploit-critical-simplehelp-flaw-deploy-new-djinn-infostealer-taskweaver-malware/",
          "type": "writeup",
          "source": "BleepingComputer / Blackpoint Cyber",
          "note": "TaskWeaver+Djinn Stealer chain, IoC hashes, infra"
        },
        {
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "type": "detection",
          "source": "CISA KEV",
          "note": "KEV entry, BOD 26-04, July 2 2026 remediation deadline"
        },
        {
          "url": "https://www.sentinelone.com/vulnerability-database/cve-2026-48558/",
          "type": "detection",
          "source": "SentinelOne Vulnerability DB",
          "note": "CWE-347 root cause, detection signals, patch guidance"
        }
      ],
      "x": {
        "mentions": 81,
        "aliases": [
          "Sua Sponte"
        ],
        "posts": [
          {
            "handle": "vutruso",
            "followers": 38,
            "likes": 0,
            "createdAt": "2026-07-08",
            "url": "https://x.com/vutruso/status/2074690046486290926",
            "github": [
              {
                "url": "https://github.com/V4bel/Januscape",
                "hasCode": true
              }
            ],
            "origin": false
          },
          {
            "handle": "nebusecurity",
            "followers": 4500,
            "likes": 240,
            "createdAt": "2026-07-08",
            "url": "https://x.com/nebusecurity/status/2074663573742338256",
            "github": [],
            "origin": false
          },
          {
            "handle": "__kokumoto",
            "followers": 7578,
            "likes": 7,
            "createdAt": "2026-07-08",
            "url": "https://x.com/__kokumoto/status/2074698589713154281",
            "github": [],
            "origin": false
          },
          {
            "handle": "yousukezan",
            "followers": 14384,
            "likes": 6,
            "createdAt": "2026-07-08",
            "url": "https://x.com/yousukezan/status/2074650902166913222",
            "github": [],
            "origin": false
          },
          {
            "handle": "ridvanyagli",
            "followers": 1120,
            "likes": 6,
            "createdAt": "2026-07-08",
            "url": "https://x.com/ridvanyagli/status/2074701200167952860",
            "github": [],
            "origin": false
          },
          {
            "handle": "Daily_CyberSec",
            "followers": 12430,
            "likes": 5,
            "createdAt": "2026-07-08",
            "url": "https://x.com/Daily_CyberSec/status/2074678524191855020",
            "github": [],
            "origin": false
          },
          {
            "handle": "oss_security",
            "followers": 4646,
            "likes": 4,
            "createdAt": "2026-07-08",
            "url": "https://x.com/oss_security/status/2074685116626907570",
            "github": [],
            "origin": false
          },
          {
            "handle": "TheRabbitPy",
            "followers": 1667,
            "likes": 2,
            "createdAt": "2026-07-06",
            "url": "https://x.com/TheRabbitPy/status/2074049134898602483",
            "github": [],
            "origin": false
          }
        ]
      },
      "bsky": {
        "mentions": 25,
        "posts": [
          {
            "handle": "shadowserver.bsky.social",
            "displayName": "The Shadowserver Foundation",
            "likes": 5,
            "reposts": 3,
            "replies": 1,
            "createdAt": "2026-07-02",
            "url": "https://bsky.app/profile/shadowserver.bsky.social/post/3mpnq36omic2t",
            "origin": false,
            "authority": true,
            "github": []
          },
          {
            "handle": "yazoul-alerts.bsky.social",
            "displayName": "Yazoul - Cybersecurity Alerts",
            "likes": 1,
            "reposts": 0,
            "replies": 1,
            "createdAt": "2026-07-02",
            "url": "https://bsky.app/profile/yazoul-alerts.bsky.social/post/3mpns6rekgd2k",
            "origin": false,
            "authority": false,
            "github": []
          },
          {
            "handle": "undercodenews.bsky.social",
            "displayName": "Undercode News",
            "likes": 1,
            "reposts": 0,
            "replies": 1,
            "createdAt": "2026-06-16",
            "url": "https://bsky.app/profile/undercodenews.bsky.social/post/3moepyfm5qu2k",
            "origin": false,
            "authority": false,
            "github": []
          },
          {
            "handle": "securitycyberuk.bsky.social",
            "displayName": "Security Cyber",
            "likes": 1,
            "reposts": 1,
            "replies": 0,
            "createdAt": "2026-06-14",
            "url": "https://bsky.app/profile/securitycyberuk.bsky.social/post/3mobcidnjl72t",
            "origin": false,
            "authority": false,
            "github": []
          },
          {
            "handle": "getpokemon7.bsky.social",
            "displayName": "まりーん",
            "likes": 1,
            "reposts": 0,
            "replies": 0,
            "createdAt": "2026-07-07",
            "url": "https://bsky.app/profile/getpokemon7.bsky.social/post/3mq2m67ypes2b",
            "origin": false,
            "authority": false,
            "github": []
          },
          {
            "handle": "thedailytechfeed.com",
            "displayName": "The Daily Tech Feed",
            "likes": 0,
            "reposts": 1,
            "replies": 0,
            "createdAt": "2026-06-16",
            "url": "https://bsky.app/profile/thedailytechfeed.com/post/3mofz4czfrc24",
            "origin": false,
            "authority": false,
            "github": []
          }
        ]
      },
      "telegram": {
        "mentions": 3,
        "posts": [
          {
            "channel": "thehackernews",
            "channelTitle": "The Hacker News",
            "tier": "news",
            "date": "2026-06-30",
            "views": 5588,
            "forwards": 10,
            "url": "https://t.me/thehackernews/9367",
            "text": "🛑 SimpleHelp RMM CVE-2026-48558 exploited for OIDC authentication bypass. Attackers gain technician sessions to deploy TaskWeaver and Djinn Stealer. Djinn Stealer targets cloud, code, AI tools, browsers, SSH, and wallets. Read the full story: https://thehackernews.com/2026/06/attackers-exploit-simplehelp-cve-2026.html",
            "github": [],
            "origin": false
          }
        ]
      },
      "aliases": [
        "Sua Sponte"
      ],
      "researchers": [
        "zhanley_h3ai"
      ],
      "corroboration": {
        "poc": true,
        "xOrigin": false,
        "independent": [
          "poc",
          "x-mention"
        ],
        "level": "multi-source"
      }
    },
    {
      "cve": "CVE-2026-12569",
      "title": "PTC Windchill and FlexPLM Improper Input Validation Vulnerability",
      "category": "PTC",
      "vendor": "PTC",
      "product": "Windchill and FlexPLM",
      "exploited": true,
      "publiclyDisclosed": false,
      "faq": "PTC Windchill and FlexPLM contains an improper input validation vulnerability allowing an unauthenticated, remote attacker to execute arbitrary code by sending a malicious request to the network.",
      "cvss": 9.8,
      "cvssVector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "severity": "CRITICAL",
      "impact": null,
      "products": [
        "Windchill and FlexPLM"
      ],
      "productCount": 1,
      "mitreUrl": "https://nvd.nist.gov/vuln/detail/CVE-2026-12569",
      "source": "kev",
      "kev": {
        "dateAdded": "2026-06-25",
        "dueDate": "2026-06-28",
        "requiredAction": "Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.",
        "ransomware": false,
        "cwes": [
          "CWE-20",
          "CWE-502"
        ],
        "references": [
          "https://www.ptc.com/en/support/article/CS473270",
          "https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk",
          "https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk",
          "https://nvd.nist.gov/vuln/detail/CVE-2026-12569"
        ]
      },
      "epss": 0.01247,
      "epssPercentile": 0.66054,
      "pocCount": 0,
      "pocTopStars": 0,
      "pocConfidence": "none",
      "pocRepos": [],
      "published": "2026-06-18T01:18:12.040",
      "research": [
        {
          "url": "https://www.ptc.com/en/about/trust-center/advisory-center/active-advisories/windchill-flexplm-rce-vulnerability",
          "type": "detection",
          "source": "PTC Trust Center (vendor)",
          "note": "Official advisory with IOCs, webshell hashes, WAF rules"
        },
        {
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "type": "detection",
          "source": "CISA KEV Catalog",
          "note": "KEV entry added 2026-06-25; patch due 2026-06-28"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-12569",
          "type": "detection",
          "source": "NVD / NIST",
          "note": "CVSS 9.8; CWE-20; active exploitation confirmed"
        },
        {
          "url": "https://www.securityweek.com/first-ever-exploitation-of-ptc-windchill-vulnerability-discovered-in-the-wild/",
          "type": "writeup",
          "source": "SecurityWeek",
          "note": "First confirmed wild exploitation; JSP webshell deployment"
        },
        {
          "url": "https://thehackernews.com/2026/06/cisa-adds-exploited-ptc-windchill-rce.html",
          "type": "writeup",
          "source": "The Hacker News",
          "note": "IOC details, webshell pattern, exploitation timeline"
        },
        {
          "url": "https://www.helpnetsecurity.com/2026/06/29/ptc-windchill-cve-2026-12569-exploited/",
          "type": "writeup",
          "source": "Help Net Security",
          "note": "JSP webshell drops; BSI/BKA German gov warnings"
        },
        {
          "url": "https://www.sentinelone.com/vulnerability-database/cve-2026-12569/",
          "type": "writeup",
          "source": "SentinelOne Vulnerability DB",
          "note": "Java gadget chain deserialization technical breakdown"
        },
        {
          "url": "https://threat-modeling.com/cve-2026-12569-ptc-windchill-flexplm-rce-cisa-kev/",
          "type": "writeup",
          "source": "Threat-Modeling.com",
          "note": "KEV timeline, affected versions, mitigation guidance"
        }
      ],
      "x": {
        "mentions": 9,
        "aliases": [],
        "posts": [
          {
            "handle": "csirt_it",
            "followers": 8984,
            "likes": 3,
            "createdAt": "2026-07-06",
            "url": "https://x.com/csirt_it/status/2074029277868175476",
            "github": [],
            "origin": false
          },
          {
            "handle": "f1tym1",
            "followers": 1008,
            "likes": 0,
            "createdAt": "2026-07-06",
            "url": "https://x.com/f1tym1/status/2074150086217445404",
            "github": [],
            "origin": false
          },
          {
            "handle": "Vulcanux_",
            "followers": 627,
            "likes": 0,
            "createdAt": "2026-07-06",
            "url": "https://x.com/Vulcanux_/status/2074030145828950291",
            "github": [],
            "origin": false
          }
        ]
      },
      "bsky": {
        "mentions": 25,
        "posts": [
          {
            "handle": "thecybermind.co",
            "displayName": "mikeransier.bsky.social",
            "likes": 0,
            "reposts": 0,
            "replies": 0,
            "createdAt": "2026-06-26",
            "url": "https://bsky.app/profile/thecybermind.co/post/3mp6vkw2kgo2r",
            "origin": false,
            "authority": true,
            "github": []
          },
          {
            "handle": "cve.skyfleet.blue",
            "displayName": "CVE Alerts ",
            "likes": 1,
            "reposts": 1,
            "replies": 0,
            "createdAt": "2026-06-18",
            "url": "https://bsky.app/profile/cve.skyfleet.blue/post/3mojqerhu472k",
            "origin": false,
            "authority": false,
            "github": []
          },
          {
            "handle": "offseq.bsky.social",
            "displayName": "OffSequence",
            "likes": 1,
            "reposts": 1,
            "replies": 0,
            "createdAt": "2026-06-18",
            "url": "https://bsky.app/profile/offseq.bsky.social/post/3mojojjvsnz2c",
            "origin": false,
            "authority": false,
            "github": []
          },
          {
            "handle": "hookprobe.com",
            "displayName": "Andrei Toma",
            "likes": 0,
            "reposts": 0,
            "replies": 1,
            "createdAt": "2026-07-06",
            "url": "https://bsky.app/profile/hookprobe.com/post/3mpyhqzyuwg2n",
            "origin": false,
            "authority": false,
            "github": []
          },
          {
            "handle": "etairos-ai.bsky.social",
            "displayName": null,
            "likes": 1,
            "reposts": 0,
            "replies": 0,
            "createdAt": "2026-06-28",
            "url": "https://bsky.app/profile/etairos-ai.bsky.social/post/3mpeo46zkz32m",
            "origin": false,
            "authority": false,
            "github": []
          },
          {
            "handle": "infosecbriefly.bsky.social",
            "displayName": "Information Security Briefly",
            "likes": 0,
            "reposts": 1,
            "replies": 0,
            "createdAt": "2026-06-26",
            "url": "https://bsky.app/profile/infosecbriefly.bsky.social/post/3mp6jugnkkr2w",
            "origin": false,
            "authority": false,
            "github": []
          }
        ]
      },
      "telegram": {
        "mentions": 2,
        "posts": [
          {
            "channel": "thehackernews",
            "channelTitle": "The Hacker News",
            "tier": "news",
            "date": "2026-06-26",
            "views": 6335,
            "forwards": 8,
            "url": "https://t.me/thehackernews/9338",
            "text": "🚨 Attackers are exploiting a critical PTC flaw to drop JSP web shells. CISA added CVE-2026-12569 to its KEV catalog after active exploitation was confirmed. — Affected: PTC Windchill PDMlink and FlexPLM. — Patch now. Hunt for IoCs. Read more: https://thehackernews.com/2026/06/cisa-adds-exploited-ptc-windchill-rce.html",
            "github": [],
            "origin": false
          }
        ]
      },
      "corroboration": {
        "poc": false,
        "xOrigin": false,
        "independent": [
          "x-mention"
        ],
        "level": "multi-source"
      },
      "aliases": [],
      "researchers": []
    },
    {
      "cve": "CVE-2026-20230",
      "title": "Cisco Unified Communications Manager Server-Side Request Forgery (SSRF) Vulnerability",
      "category": "Cisco",
      "vendor": "Cisco",
      "product": "Unified Communications Manager",
      "exploited": true,
      "publiclyDisclosed": false,
      "faq": "Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communications Manager Session Management Edition (Unified CM SME) contain a server-side request forgery (SSRF) Vulnerability that could allow an unauthenticated, remote attacker to write files to the underlying operating system that could be used later to elevate to root.",
      "cvss": 8.6,
      "cvssVector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:N",
      "severity": "HIGH",
      "impact": null,
      "products": [
        "Unified Communications Manager"
      ],
      "productCount": 1,
      "mitreUrl": "https://nvd.nist.gov/vuln/detail/CVE-2026-20230",
      "source": "kev",
      "kev": {
        "dateAdded": "2026-06-25",
        "dueDate": "2026-06-28",
        "requiredAction": "Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.",
        "ransomware": false,
        "cwes": [
          "CWE-918"
        ],
        "references": [
          "https://www.cisco.com/c/en/us/support/docs/csa/cisco-sa-cucm-ssrf-cXPnHcW.html",
          "https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk",
          "https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk",
          "https://nvd.nist.gov/vuln/detail/CVE-2026-20230"
        ]
      },
      "epss": 0.41694,
      "epssPercentile": 0.98537,
      "pocCount": 2,
      "pocTopStars": 1,
      "pocConfidence": "confirmed",
      "pocRepos": [
        {
          "url": "https://github.com/HORKimhab/CVE-2026-20230",
          "stars": 1,
          "desc": "CVE-2026-20230 - Cisco Unified CM",
          "createdAt": "2026-06-05",
          "hasCode": true
        },
        {
          "url": "https://github.com/W5M1n9/Cisco-Unified-Communications-Manager-Server-Side-Forgery-Request-Vulnerability-CVE-2026-20230",
          "stars": 1,
          "desc": "",
          "createdAt": "2026-06-25",
          "hasCode": true
        }
      ],
      "published": "2026-06-03T18:16:20.160",
      "research": [],
      "x": {
        "mentions": 3,
        "aliases": [],
        "posts": [
          {
            "handle": "FirewallCoffee",
            "followers": 0,
            "likes": 0,
            "createdAt": "2026-07-06",
            "url": "https://x.com/FirewallCoffee/status/2074151376112787483",
            "github": [],
            "origin": false
          }
        ]
      },
      "bsky": {
        "mentions": 25,
        "posts": [
          {
            "handle": "ahmandonk.bsky.social",
            "displayName": "Ahmandonk",
            "likes": 1,
            "reposts": 0,
            "replies": 1,
            "createdAt": "2026-07-03",
            "url": "https://bsky.app/profile/ahmandonk.bsky.social/post/3mpqkg2hmgr2k",
            "origin": false,
            "authority": false,
            "github": []
          },
          {
            "handle": "hacker.at.thenote.app",
            "displayName": "Hacker & Security News",
            "likes": 1,
            "reposts": 1,
            "replies": 0,
            "createdAt": "2026-06-24",
            "url": "https://bsky.app/profile/hacker.at.thenote.app/post/3mp2xoge6vk27",
            "origin": false,
            "authority": false,
            "github": []
          },
          {
            "handle": "trinacriatech.bsky.social",
            "displayName": null,
            "likes": 1,
            "reposts": 0,
            "replies": 0,
            "createdAt": "2026-06-29",
            "url": "https://bsky.app/profile/trinacriatech.bsky.social/post/3mpgoavylnc2r",
            "origin": false,
            "authority": false,
            "github": []
          },
          {
            "handle": "kitafox.bsky.social",
            "displayName": "キタきつね",
            "likes": 1,
            "reposts": 0,
            "replies": 0,
            "createdAt": "2026-06-25",
            "url": "https://bsky.app/profile/kitafox.bsky.social/post/3mp36mqeabi2c",
            "origin": false,
            "authority": false,
            "github": []
          },
          {
            "handle": "basefortify.bsky.social",
            "displayName": "BaseFortify.eu",
            "likes": 1,
            "reposts": 0,
            "replies": 0,
            "createdAt": "2026-06-24",
            "url": "https://bsky.app/profile/basefortify.bsky.social/post/3mozwer3bw227",
            "origin": false,
            "authority": false,
            "github": []
          },
          {
            "handle": "hendryadrian.bsky.social",
            "displayName": "Cybersecurity News Everyday",
            "likes": 1,
            "reposts": 0,
            "replies": 0,
            "createdAt": "2026-06-04",
            "url": "https://bsky.app/profile/hendryadrian.bsky.social/post/3mnhfdb677x2l",
            "origin": false,
            "authority": false,
            "github": []
          }
        ]
      },
      "telegram": {
        "mentions": 5,
        "posts": [
          {
            "channel": "thehackernews",
            "channelTitle": "The Hacker News",
            "tier": "news",
            "date": "2026-06-04",
            "views": 8237,
            "forwards": 17,
            "url": "https://t.me/thehackernews/9156",
            "text": "🚨 No auth required ... a crafted web request to Cisco Unified CM can write files to the OS and open a path to root. CVE-2026-20230 patch is out, PoC exploit is public, and no attacks yet. Only bites if WebDialer is ON. Fix: 14SU6 / COP / 15SU5, or kill WebDialer. Read: https://thehackernews.com/2026/06/cisco-patches-cve-2026-20230-in-unified.html",
            "github": [],
            "origin": false
          }
        ]
      },
      "corroboration": {
        "poc": true,
        "xOrigin": false,
        "independent": [
          "poc",
          "x-mention"
        ],
        "level": "multi-source"
      },
      "aliases": [],
      "researchers": []
    },
    {
      "cve": "CVE-2025-67038",
      "title": "Lantronix EDS5000 Code Injection Vulnerability",
      "category": "Lantronix",
      "vendor": "Lantronix",
      "product": "EDS5000",
      "exploited": true,
      "publiclyDisclosed": false,
      "faq": "Lantronix EDS5000 contains a code injection vulnerability that could allow attackers to inject arbitrary OS commands into the username parameter. Injected commands are executed with root privileges.",
      "cvss": 9.8,
      "cvssVector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "severity": "CRITICAL",
      "impact": null,
      "products": [
        "EDS5000"
      ],
      "productCount": 1,
      "mitreUrl": "https://nvd.nist.gov/vuln/detail/CVE-2025-67038",
      "source": "kev",
      "kev": {
        "dateAdded": "2026-06-23",
        "dueDate": "2026-06-26",
        "requiredAction": "Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.",
        "ransomware": false,
        "cwes": [
          "CWE-78",
          "CWE-94"
        ],
        "references": [
          "https://ltrxdev.atlassian.net/wiki/spaces/LTRXTS/pages/2538438657/Latest+Firmware+for+the+EDS5000+series+EDS5008+EDS5016+EDS5032",
          "https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk",
          "https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk",
          "https://nvd.nist.gov/vuln/detail/CVE-2025-67038"
        ]
      },
      "epss": 0.00889,
      "epssPercentile": 0.55389,
      "pocCount": 0,
      "pocTopStars": 0,
      "pocConfidence": "none",
      "pocRepos": [],
      "published": "2026-03-11T17:16:52.010",
      "research": [
        {
          "url": "https://www.forescout.com/research-labs/bridgebreak-vulnerabilities-thrive-in-serial-to-ethernet-converters/",
          "type": "writeup",
          "source": "Forescout Vedere Labs (original disclosers)",
          "note": "BRIDGE:BREAK: 22 vulns incl. CVE-2025-67038 detail"
        },
        {
          "url": "https://www.forescout.com/blog/analyzing-active-exploitation-of-lantronix-and-openwrt-luci/",
          "type": "writeup",
          "source": "Forescout Vedere Labs",
          "note": "ITW exploitation analysis; Chaya_006 cluster IOCs"
        },
        {
          "url": "https://www.cisa.gov/news-events/alerts/2026/06/23/cisa-adds-four-known-exploited-vulnerabilities-catalog",
          "type": "detection",
          "source": "CISA KEV",
          "note": "KEV entry; federal patch deadline June 26 2026"
        },
        {
          "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-069-02",
          "type": "detection",
          "source": "CISA ICS-CERT",
          "note": "ICS advisory ICSA-26-069-02 for EDS5000"
        },
        {
          "url": "https://github.com/advisories/GHSA-55gq-23mv-cw8r",
          "type": "detection",
          "source": "GitHub Advisory Database",
          "note": "Official GitHub security advisory record",
          "hasCode": null
        },
        {
          "url": "https://cvefeed.io/vuln/detail/CVE-2025-67038",
          "type": "detection",
          "source": "cvefeed.io",
          "note": "Aggregator; links to 1 confirmed GitHub PoC"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-67038",
          "type": "detection",
          "source": "NVD / NIST",
          "note": "Authoritative CVE record; CWE-94 code injection"
        },
        {
          "url": "https://www.sentinelone.com/vulnerability-database/cve-2025-67038/",
          "type": "writeup",
          "source": "SentinelOne Vulnerability DB",
          "note": "Technical deep-dive: attack vector & mitigations"
        }
      ],
      "x": {
        "mentions": 22,
        "aliases": [
          "BRIDGE:BREAK"
        ],
        "posts": [
          {
            "handle": "b3ch1r",
            "followers": 160,
            "likes": 2,
            "createdAt": "2026-07-07",
            "url": "https://x.com/b3ch1r/status/2074442101295632758",
            "github": [],
            "origin": false
          },
          {
            "handle": "DFIR_Radar",
            "followers": 1715,
            "likes": 1,
            "createdAt": "2026-07-06",
            "url": "https://x.com/DFIR_Radar/status/2074268069321715846",
            "github": [],
            "origin": false
          },
          {
            "handle": "connect24h",
            "followers": 4222,
            "likes": 0,
            "createdAt": "2026-07-07",
            "url": "https://x.com/connect24h/status/2074413751105925261",
            "github": [],
            "origin": false
          },
          {
            "handle": "SPoint",
            "followers": 2285,
            "likes": 0,
            "createdAt": "2026-07-07",
            "url": "https://x.com/SPoint/status/2074387973013975307",
            "github": [],
            "origin": false
          },
          {
            "handle": "boylahulahu",
            "followers": 2096,
            "likes": 0,
            "createdAt": "2026-07-07",
            "url": "https://x.com/boylahulahu/status/2074392236242952260",
            "github": [],
            "origin": false
          },
          {
            "handle": "iototsecnews",
            "followers": 501,
            "likes": 0,
            "createdAt": "2026-07-08",
            "url": "https://x.com/iototsecnews/status/2074664987705147537",
            "github": [],
            "origin": false
          },
          {
            "handle": "QingQiuGeek",
            "followers": 389,
            "likes": 0,
            "createdAt": "2026-07-08",
            "url": "https://x.com/QingQiuGeek/status/2074710035926843587",
            "github": [],
            "origin": false
          },
          {
            "handle": "DzejBi_JB",
            "followers": 338,
            "likes": 0,
            "createdAt": "2026-07-07",
            "url": "https://x.com/DzejBi_JB/status/2074402828303397353",
            "github": [],
            "origin": false
          }
        ]
      },
      "bsky": {
        "mentions": 28,
        "posts": [
          {
            "handle": "campuscodi.risky.biz",
            "displayName": "Catalin Cimpanu",
            "likes": 2,
            "reposts": 1,
            "replies": 0,
            "createdAt": "2026-04-22",
            "url": "https://bsky.app/profile/campuscodi.risky.biz/post/3mk3avu6km22u",
            "origin": true,
            "authority": true,
            "github": []
          },
          {
            "handle": "shortinfo.bsky.social",
            "displayName": "SHORT INFO",
            "likes": 0,
            "reposts": 0,
            "replies": 0,
            "createdAt": "2026-04-22",
            "url": "https://bsky.app/profile/shortinfo.bsky.social/post/3mk3ofnncok25",
            "origin": true,
            "authority": false,
            "github": []
          },
          {
            "handle": "thecybermind.co",
            "displayName": "mikeransier.bsky.social",
            "likes": 0,
            "reposts": 0,
            "replies": 0,
            "createdAt": "2026-06-24",
            "url": "https://bsky.app/profile/thecybermind.co/post/3mp2ke4vlip2i",
            "origin": false,
            "authority": true,
            "github": []
          },
          {
            "handle": "sergioiker.bsky.social",
            "displayName": "Dr.Sergio E. Sanchez… Dr. Qubit",
            "likes": 0,
            "reposts": 0,
            "replies": 1,
            "createdAt": "2026-06-25",
            "url": "https://bsky.app/profile/sergioiker.bsky.social/post/3mp4jsmgmnk24",
            "origin": false,
            "authority": false,
            "github": []
          },
          {
            "handle": "cvesentinel.bsky.social",
            "displayName": "CVESentinel",
            "likes": 0,
            "reposts": 1,
            "replies": 0,
            "createdAt": "2026-06-23",
            "url": "https://bsky.app/profile/cvesentinel.bsky.social/post/3moxyrhdofq2w",
            "origin": false,
            "authority": false,
            "github": []
          },
          {
            "handle": "csirts.bsky.social",
            "displayName": "CSIRTS.COM",
            "likes": 0,
            "reposts": 0,
            "replies": 0,
            "createdAt": "2026-07-06",
            "url": "https://bsky.app/profile/csirts.bsky.social/post/3mpyvvx2has2f",
            "origin": false,
            "authority": false,
            "github": []
          }
        ]
      },
      "telegram": {
        "mentions": 1,
        "posts": [
          {
            "channel": "VulnerabilityNews",
            "channelTitle": "Vulnerability News",
            "tier": "news",
            "date": "2026-06-24",
            "views": 55,
            "forwards": 1,
            "url": "https://t.me/VulnerabilityNews/43157",
            "text": "CISA Warns Critical Lantronix EDS5000 Flaw Is Being Actively Exploited The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Tuesday warned of active exploitation of a critical security flaw impacting Lantronix EDS5000 Series devices, urging Federal Civilian Executive Branch (FCEB) agencies to apply the fixes by June 26, 2026. The vulnerability in question is CVE-2025-67038 (CVSS sco",
            "github": [],
            "origin": false
          }
        ]
      },
      "aliases": [
        "BRIDGE:BREAK"
      ],
      "researchers": [
        "forescout_vederelab"
      ],
      "corroboration": {
        "poc": false,
        "xOrigin": false,
        "independent": [
          "x-mention"
        ],
        "level": "multi-source"
      }
    },
    {
      "cve": "CVE-2026-34910",
      "title": "Ubiquiti UniFi OS Improper Input Validation Vulnerability",
      "category": "Ubiquiti",
      "vendor": "Ubiquiti",
      "product": "UniFi OS",
      "exploited": true,
      "publiclyDisclosed": false,
      "faq": "Ubiquiti UniFi OS contains an improper input validation vulnerability which could allow a malicious actor with access to the network to conduct command injection.",
      "cvss": 10,
      "cvssVector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H",
      "severity": "CRITICAL",
      "impact": null,
      "products": [
        "UniFi OS"
      ],
      "productCount": 1,
      "mitreUrl": "https://nvd.nist.gov/vuln/detail/CVE-2026-34910",
      "source": "kev",
      "kev": {
        "dateAdded": "2026-06-23",
        "dueDate": "2026-06-26",
        "requiredAction": "Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.",
        "ransomware": false,
        "cwes": [
          "CWE-20"
        ],
        "references": [
          "https://community.ui.com/releases/Security-Advisory-Bulletin-064-064/84811c09-4cf4-42ab-bd61-cc994445963b",
          "https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk",
          "https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk",
          "https://nvd.nist.gov/vuln/detail/CVE-2026-34910"
        ]
      },
      "epss": 0.78555,
      "epssPercentile": 0.99541,
      "pocCount": 0,
      "pocTopStars": 0,
      "pocConfidence": "none",
      "pocRepos": [],
      "published": "2026-05-22T02:16:34.527",
      "research": [
        {
          "url": "https://bishopfox.com/blog/popping-root-on-unifi-os-server-unauthenticated-rce-chain-detection-analysis",
          "type": "writeup",
          "source": "BishopFox",
          "note": "Full chain analysis: auth bypass → cmd injection → root"
        },
        {
          "url": "https://github.com/projectdiscovery/nuclei-templates",
          "type": "module",
          "source": "ProjectDiscovery / @Kazgangap",
          "note": "Nuclei template: UniFi OS cmd injection, KEV-flagged",
          "hasCode": true
        },
        {
          "url": "https://community.ui.com/releases/Security-Advisory-Bulletin-064-064/84811c09-4cf4-42ab-bd61-cc994445963b",
          "type": "detection",
          "source": "Ubiquiti / SAB-064",
          "note": "Vendor advisory; patch to UniFi OS 5.0.8+"
        },
        {
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "type": "detection",
          "source": "CISA KEV",
          "note": "Added KEV June 23 2026; BOD 26-04 3-day mandate"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-34910",
          "type": "detection",
          "source": "NVD / NIST",
          "note": "CVSS 10.0; CWE-20; affects UniFi OS < 5.0.8"
        },
        {
          "url": "https://beazley.security/alerts-advisories/critical-vulnerability-in-ubiquiti-network-application-under-active-exploitation-cve-2026-34908-cve-2026--34909-cve-2026-34910",
          "type": "writeup",
          "source": "Beazley Security",
          "note": "IR-focused writeup; pkg-update sh-c sink, sudo privesc"
        },
        {
          "url": "https://threat-modeling.com/cve-2026-34908-34909-34910-ubiquiti-unifi-os-triple-kev/",
          "type": "writeup",
          "source": "threat-modeling.com",
          "note": "Triple-CVE chain breakdown; CISA KEV context"
        },
        {
          "url": "https://www.securityweek.com/critical-ubiquiti-vulnerabilities-in-attackers-crosshairs/",
          "type": "writeup",
          "source": "SecurityWeek",
          "note": "News analysis citing BishopFox; active exploitation"
        }
      ],
      "x": {
        "mentions": 74,
        "aliases": [],
        "posts": [
          {
            "handle": "vutruso",
            "followers": 38,
            "likes": 0,
            "createdAt": "2026-07-08",
            "url": "https://x.com/vutruso/status/2074690046486290926",
            "github": [
              {
                "url": "https://github.com/V4bel/Januscape",
                "hasCode": true
              }
            ],
            "origin": false
          },
          {
            "handle": "nebusecurity",
            "followers": 4501,
            "likes": 240,
            "createdAt": "2026-07-08",
            "url": "https://x.com/nebusecurity/status/2074663573742338256",
            "github": [],
            "origin": false
          },
          {
            "handle": "__kokumoto",
            "followers": 7578,
            "likes": 7,
            "createdAt": "2026-07-08",
            "url": "https://x.com/__kokumoto/status/2074698589713154281",
            "github": [],
            "origin": false
          },
          {
            "handle": "yousukezan",
            "followers": 14384,
            "likes": 6,
            "createdAt": "2026-07-08",
            "url": "https://x.com/yousukezan/status/2074650902166913222",
            "github": [],
            "origin": false
          },
          {
            "handle": "ridvanyagli",
            "followers": 1120,
            "likes": 6,
            "createdAt": "2026-07-08",
            "url": "https://x.com/ridvanyagli/status/2074701200167952860",
            "github": [],
            "origin": false
          },
          {
            "handle": "Daily_CyberSec",
            "followers": 12430,
            "likes": 5,
            "createdAt": "2026-07-08",
            "url": "https://x.com/Daily_CyberSec/status/2074678524191855020",
            "github": [],
            "origin": false
          },
          {
            "handle": "oss_security",
            "followers": 4646,
            "likes": 4,
            "createdAt": "2026-07-08",
            "url": "https://x.com/oss_security/status/2074685116626907570",
            "github": [],
            "origin": false
          },
          {
            "handle": "ohhara_shiojiri",
            "followers": 2004,
            "likes": 1,
            "createdAt": "2026-07-08",
            "url": "https://x.com/ohhara_shiojiri/status/2074727301179408802",
            "github": [],
            "origin": false
          }
        ]
      },
      "bsky": {
        "mentions": 10,
        "posts": [
          {
            "handle": "alphahunt.io",
            "displayName": "AlphaHunt Converge",
            "likes": 1,
            "reposts": 0,
            "replies": 1,
            "createdAt": "2026-06-25",
            "url": "https://bsky.app/profile/alphahunt.io/post/3mp4gpwmwsl2j",
            "origin": false,
            "authority": false,
            "github": []
          },
          {
            "handle": "cvesentinel.bsky.social",
            "displayName": "CVESentinel",
            "likes": 1,
            "reposts": 0,
            "replies": 1,
            "createdAt": "2026-06-23",
            "url": "https://bsky.app/profile/cvesentinel.bsky.social/post/3moxyrl5akj2u",
            "origin": false,
            "authority": false,
            "github": []
          },
          {
            "handle": "getpokemon7.bsky.social",
            "displayName": "まりーん",
            "likes": 0,
            "reposts": 0,
            "replies": 1,
            "createdAt": "2026-07-03",
            "url": "https://bsky.app/profile/getpokemon7.bsky.social/post/3mprmpjixoc2h",
            "origin": false,
            "authority": false,
            "github": []
          },
          {
            "handle": "csirts.bsky.social",
            "displayName": "CSIRTS.COM",
            "likes": 0,
            "reposts": 0,
            "replies": 0,
            "createdAt": "2026-07-06",
            "url": "https://bsky.app/profile/csirts.bsky.social/post/3mpyvvwmesv2e",
            "origin": false,
            "authority": false,
            "github": []
          },
          {
            "handle": "jbhall56.bsky.social",
            "displayName": "PCI Guru",
            "likes": 0,
            "reposts": 0,
            "replies": 0,
            "createdAt": "2026-06-09",
            "url": "https://bsky.app/profile/jbhall56.bsky.social/post/3mnu4pot3nk2c",
            "origin": false,
            "authority": false,
            "github": []
          },
          {
            "handle": "cve.skyfleet.blue",
            "displayName": "CVE Alerts ",
            "likes": 0,
            "reposts": 0,
            "replies": 0,
            "createdAt": "2026-05-22",
            "url": "https://bsky.app/profile/cve.skyfleet.blue/post/3mmfxwz334o2n",
            "origin": false,
            "authority": false,
            "github": []
          }
        ]
      },
      "telegram": {
        "mentions": 0,
        "posts": []
      },
      "researchers": [
        "Kazgangap"
      ],
      "corroboration": {
        "poc": false,
        "xOrigin": false,
        "independent": [
          "x-mention"
        ],
        "level": "multi-source"
      },
      "aliases": []
    },
    {
      "cve": "CVE-2026-34909",
      "title": "Ubiquiti UniFi OS Path Traversal Vulnerability",
      "category": "Ubiquiti",
      "vendor": "Ubiquiti",
      "product": "UniFi OS",
      "exploited": true,
      "publiclyDisclosed": false,
      "faq": "Ubiquiti UniFi OS contains a path traversal vulnerability which could allow a malicious actor with access to the network to access files on the underlying system that could be manipulated to access an underlying account.",
      "cvss": 10,
      "cvssVector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H",
      "severity": "CRITICAL",
      "impact": null,
      "products": [
        "UniFi OS"
      ],
      "productCount": 1,
      "mitreUrl": "https://nvd.nist.gov/vuln/detail/CVE-2026-34909",
      "source": "kev",
      "kev": {
        "dateAdded": "2026-06-23",
        "dueDate": "2026-06-26",
        "requiredAction": "Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.",
        "ransomware": false,
        "cwes": [
          "CWE-22"
        ],
        "references": [
          "https://community.ui.com/releases/Security-Advisory-Bulletin-064-064/84811c09-4cf4-42ab-bd61-cc994445963b",
          "https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk",
          "https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk",
          "https://nvd.nist.gov/vuln/detail/CVE-2026-34909"
        ]
      },
      "epss": 0.02269,
      "epssPercentile": 0.81139,
      "pocCount": 0,
      "pocTopStars": 0,
      "pocConfidence": "none",
      "pocRepos": [],
      "published": "2026-05-22T02:16:34.390",
      "research": [
        {
          "url": "https://bishopfox.com/blog/popping-root-on-unifi-os-server-unauthenticated-rce-chain-detection-analysis",
          "type": "writeup",
          "source": "BishopFox",
          "note": "Patch-diff analysis; chain CVE-34908+34909→34910 to root"
        },
        {
          "url": "https://github.com/BishopFox/CVE-2026-34908-check",
          "type": "detection",
          "source": "BishopFox / GitHub",
          "note": "Safe exposure-check tool for the auth-bypass+traversal chain",
          "hasCode": true
        },
        {
          "url": "https://community.ui.com/releases/Security-Advisory-Bulletin-064-064/84811c09-4cf4-42ab-bd61-cc994445963b",
          "type": "writeup",
          "source": "Ubiquiti (SAB-064)",
          "note": "Vendor advisory; credits Almadhi for CVE-2026-34909"
        },
        {
          "url": "https://www.cisa.gov/news-events/alerts/2026/06/23/cisa-adds-four-known-exploited-vulnerabilities-catalog",
          "type": "detection",
          "source": "CISA KEV",
          "note": "KEV listing; 3-day patch mandate for federal agencies"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-34909",
          "type": "detection",
          "source": "NVD / NIST",
          "note": "Official CVE record; CVSS 10.0, CWE-22, no-auth network"
        },
        {
          "url": "https://github.com/projectdiscovery/nuclei-templates",
          "type": "module",
          "source": "ProjectDiscovery / @Kazgangap",
          "note": "Nuclei template for CVE-2026-34910 (chained cmd injection)",
          "hasCode": true
        },
        {
          "url": "https://www.securityweek.com/critical-ubiquiti-vulnerabilities-in-attackers-crosshairs/",
          "type": "writeup",
          "source": "SecurityWeek / BishopFox",
          "note": "Coverage of BishopFox live 5.0.6 VM validation findings"
        },
        {
          "url": "https://cybersecuritynews.com/cisa-ubiquiti-unifi-os-vulnerability/",
          "type": "writeup",
          "source": "CybersecurityNews",
          "note": "Active exploitation confirmed; chain with 34908 and 34910"
        }
      ],
      "x": {
        "mentions": 78,
        "aliases": [],
        "posts": [
          {
            "handle": "vutruso",
            "followers": 38,
            "likes": 0,
            "createdAt": "2026-07-08",
            "url": "https://x.com/vutruso/status/2074690046486290926",
            "github": [
              {
                "url": "https://github.com/V4bel/Januscape",
                "hasCode": true
              }
            ],
            "origin": false
          },
          {
            "handle": "nebusecurity",
            "followers": 4501,
            "likes": 240,
            "createdAt": "2026-07-08",
            "url": "https://x.com/nebusecurity/status/2074663573742338256",
            "github": [],
            "origin": false
          },
          {
            "handle": "__kokumoto",
            "followers": 7578,
            "likes": 7,
            "createdAt": "2026-07-08",
            "url": "https://x.com/__kokumoto/status/2074698589713154281",
            "github": [],
            "origin": false
          },
          {
            "handle": "yousukezan",
            "followers": 14384,
            "likes": 6,
            "createdAt": "2026-07-08",
            "url": "https://x.com/yousukezan/status/2074650902166913222",
            "github": [],
            "origin": false
          },
          {
            "handle": "ridvanyagli",
            "followers": 1120,
            "likes": 6,
            "createdAt": "2026-07-08",
            "url": "https://x.com/ridvanyagli/status/2074701200167952860",
            "github": [],
            "origin": false
          },
          {
            "handle": "Daily_CyberSec",
            "followers": 12430,
            "likes": 5,
            "createdAt": "2026-07-08",
            "url": "https://x.com/Daily_CyberSec/status/2074678524191855020",
            "github": [],
            "origin": false
          },
          {
            "handle": "oss_security",
            "followers": 4646,
            "likes": 4,
            "createdAt": "2026-07-08",
            "url": "https://x.com/oss_security/status/2074685116626907570",
            "github": [],
            "origin": false
          },
          {
            "handle": "ohhara_shiojiri",
            "followers": 2004,
            "likes": 1,
            "createdAt": "2026-07-08",
            "url": "https://x.com/ohhara_shiojiri/status/2074727301179408802",
            "github": [],
            "origin": false
          }
        ]
      },
      "bsky": {
        "mentions": 11,
        "posts": [
          {
            "handle": "offseq.bsky.social",
            "displayName": "OffSequence",
            "likes": 5,
            "reposts": 1,
            "replies": 0,
            "createdAt": "2026-05-22",
            "url": "https://bsky.app/profile/offseq.bsky.social/post/3mmgg2g4mix26",
            "origin": false,
            "authority": false,
            "github": []
          },
          {
            "handle": "cve.skyfleet.blue",
            "displayName": "CVE Alerts ",
            "likes": 3,
            "reposts": 1,
            "replies": 0,
            "createdAt": "2026-05-22",
            "url": "https://bsky.app/profile/cve.skyfleet.blue/post/3mmfwt7aoxv2h",
            "origin": false,
            "authority": false,
            "github": []
          },
          {
            "handle": "thehackerwire.bsky.social",
            "displayName": "TheHackerWire",
            "likes": 3,
            "reposts": 1,
            "replies": 0,
            "createdAt": "2026-05-22",
            "url": "https://bsky.app/profile/thehackerwire.bsky.social/post/3mmfwy72mib2w",
            "origin": false,
            "authority": false,
            "github": []
          },
          {
            "handle": "getpokemon7.bsky.social",
            "displayName": "まりーん",
            "likes": 0,
            "reposts": 0,
            "replies": 1,
            "createdAt": "2026-07-03",
            "url": "https://bsky.app/profile/getpokemon7.bsky.social/post/3mprmpjixoc2h",
            "origin": false,
            "authority": false,
            "github": []
          },
          {
            "handle": "csirts.bsky.social",
            "displayName": "CSIRTS.COM",
            "likes": 0,
            "reposts": 0,
            "replies": 0,
            "createdAt": "2026-07-06",
            "url": "https://bsky.app/profile/csirts.bsky.social/post/3mpyvvw2qam2y",
            "origin": false,
            "authority": false,
            "github": []
          },
          {
            "handle": "shiojiri.com",
            "displayName": "ohhara",
            "likes": 0,
            "reposts": 0,
            "replies": 0,
            "createdAt": "2026-06-25",
            "url": "https://bsky.app/profile/shiojiri.com/post/3mp3nmpbhkcj5",
            "origin": false,
            "authority": false,
            "github": []
          }
        ]
      },
      "telegram": {
        "mentions": 0,
        "posts": []
      },
      "researchers": [
        "Abdulaziz Almadhi"
      ],
      "corroboration": {
        "poc": false,
        "xOrigin": false,
        "independent": [
          "x-mention"
        ],
        "level": "multi-source"
      },
      "aliases": []
    },
    {
      "cve": "CVE-2026-34908",
      "title": "Ubiquiti UniFi OS Improper Access Control Vulnerability",
      "category": "Ubiquiti",
      "vendor": "Ubiquiti",
      "product": "UniFi OS",
      "exploited": true,
      "publiclyDisclosed": false,
      "faq": "Ubiquiti UniFi OS contains an improper access control vulnerability which could allow a malicious actor with access to the network to make unauthorized changes to the system.",
      "cvss": 10,
      "cvssVector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H",
      "severity": "CRITICAL",
      "impact": null,
      "products": [
        "UniFi OS"
      ],
      "productCount": 1,
      "mitreUrl": "https://nvd.nist.gov/vuln/detail/CVE-2026-34908",
      "source": "kev",
      "kev": {
        "dateAdded": "2026-06-23",
        "dueDate": "2026-06-26",
        "requiredAction": "Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.",
        "ransomware": false,
        "cwes": [
          "CWE-284"
        ],
        "references": [
          "https://community.ui.com/releases/Security-Advisory-Bulletin-064-064/84811c09-4cf4-42ab-bd61-cc994445963b",
          "https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk",
          "https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk",
          "https://nvd.nist.gov/vuln/detail/CVE-2026-34908"
        ]
      },
      "epss": 0.02452,
      "epssPercentile": 0.8262,
      "pocCount": 0,
      "pocTopStars": 0,
      "pocConfidence": "none",
      "pocRepos": [],
      "published": "2026-05-22T02:16:34.240",
      "research": [
        {
          "url": "https://bishopfox.com/blog/popping-root-on-unifi-os-server-unauthenticated-rce-chain-detection-analysis",
          "type": "writeup",
          "source": "Bishop Fox",
          "note": "Full RCE chain analysis; auth bypass + cmdi to root"
        },
        {
          "url": "https://github.com/BishopFox/CVE-2026-34908-check",
          "type": "detection",
          "source": "BishopFox / GitHub",
          "note": "Safe Python detector; no cmd exec, verdicts vuln/patched",
          "hasCode": true
        },
        {
          "url": "https://community.ui.com/releases/Security-Advisory-Bulletin-064-064/84811c09-4cf4-42ab-bd61-cc994445963b",
          "type": "writeup",
          "source": "Ubiquiti / community.ui.com",
          "note": "Official SAB-064; credits heckintosh_ for CVE-2026-34908"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-34908",
          "type": "detection",
          "source": "NIST NVD",
          "note": "Official NVD record; CVSS 10.0, CWE-284"
        },
        {
          "url": "https://www.cisa.gov/news-events/alerts/2026/06/23/cisa-adds-four-known-exploited-vulnerabilities-catalog",
          "type": "detection",
          "source": "CISA KEV",
          "note": "KEV entry added 2026-06-23; BOD 26-04 3-day mandate"
        },
        {
          "url": "https://www.securityweek.com/critical-ubiquiti-vulnerabilities-in-attackers-crosshairs/",
          "type": "writeup",
          "source": "SecurityWeek",
          "note": "Covers active exploitation; BishopFox chain confirmed on 5.0.6"
        },
        {
          "url": "https://www.bleepingcomputer.com/news/security/critical-unifi-os-bug-lets-hackers-gain-root-without-authentication/",
          "type": "writeup",
          "source": "BleepingComputer",
          "note": "Notes full PoC withheld; sudo privesc to root explained"
        },
        {
          "url": "https://github.com/projectdiscovery/nuclei-templates",
          "type": "module",
          "source": "ProjectDiscovery / nuclei-templates (@Kazgangap)",
          "note": "Nuclei template for CVE-2026-34910 (cmd-inj RCE step in chain)",
          "hasCode": true
        }
      ],
      "x": {
        "mentions": 81,
        "aliases": [],
        "posts": [
          {
            "handle": "vutruso",
            "followers": 38,
            "likes": 0,
            "createdAt": "2026-07-08",
            "url": "https://x.com/vutruso/status/2074690046486290926",
            "github": [
              {
                "url": "https://github.com/V4bel/Januscape",
                "hasCode": true
              }
            ],
            "origin": false
          },
          {
            "handle": "nebusecurity",
            "followers": 4501,
            "likes": 241,
            "createdAt": "2026-07-08",
            "url": "https://x.com/nebusecurity/status/2074663573742338256",
            "github": [],
            "origin": false
          },
          {
            "handle": "__kokumoto",
            "followers": 7578,
            "likes": 7,
            "createdAt": "2026-07-08",
            "url": "https://x.com/__kokumoto/status/2074698589713154281",
            "github": [],
            "origin": false
          },
          {
            "handle": "yousukezan",
            "followers": 14384,
            "likes": 6,
            "createdAt": "2026-07-08",
            "url": "https://x.com/yousukezan/status/2074650902166913222",
            "github": [],
            "origin": false
          },
          {
            "handle": "ridvanyagli",
            "followers": 1120,
            "likes": 6,
            "createdAt": "2026-07-08",
            "url": "https://x.com/ridvanyagli/status/2074701200167952860",
            "github": [],
            "origin": false
          },
          {
            "handle": "Daily_CyberSec",
            "followers": 12430,
            "likes": 5,
            "createdAt": "2026-07-08",
            "url": "https://x.com/Daily_CyberSec/status/2074678524191855020",
            "github": [],
            "origin": false
          },
          {
            "handle": "oss_security",
            "followers": 4646,
            "likes": 4,
            "createdAt": "2026-07-08",
            "url": "https://x.com/oss_security/status/2074685116626907570",
            "github": [],
            "origin": false
          },
          {
            "handle": "ohhara_shiojiri",
            "followers": 2004,
            "likes": 1,
            "createdAt": "2026-07-08",
            "url": "https://x.com/ohhara_shiojiri/status/2074727301179408802",
            "github": [],
            "origin": false
          }
        ]
      },
      "bsky": {
        "mentions": 14,
        "posts": [
          {
            "handle": "getpokemon7.bsky.social",
            "displayName": "まりーん",
            "likes": 0,
            "reposts": 0,
            "replies": 1,
            "createdAt": "2026-07-03",
            "url": "https://bsky.app/profile/getpokemon7.bsky.social/post/3mprmpjixoc2h",
            "origin": false,
            "authority": false,
            "github": []
          },
          {
            "handle": "thehackerwire.bsky.social",
            "displayName": "TheHackerWire",
            "likes": 1,
            "reposts": 0,
            "replies": 0,
            "createdAt": "2026-05-22",
            "url": "https://bsky.app/profile/thehackerwire.bsky.social/post/3mmfwxwkozf2k",
            "origin": false,
            "authority": false,
            "github": []
          },
          {
            "handle": "offseq.bsky.social",
            "displayName": "OffSequence",
            "likes": 0,
            "reposts": 1,
            "replies": 0,
            "createdAt": "2026-05-22",
            "url": "https://bsky.app/profile/offseq.bsky.social/post/3mmgaziuzw62m",
            "origin": false,
            "authority": false,
            "github": []
          },
          {
            "handle": "csirts.bsky.social",
            "displayName": "CSIRTS.COM",
            "likes": 0,
            "reposts": 0,
            "replies": 0,
            "createdAt": "2026-07-06",
            "url": "https://bsky.app/profile/csirts.bsky.social/post/3mpyqmsensp25",
            "origin": false,
            "authority": false,
            "github": []
          },
          {
            "handle": "netsecio.bsky.social",
            "displayName": "CyberNetSecIO",
            "likes": 0,
            "reposts": 0,
            "replies": 0,
            "createdAt": "2026-06-25",
            "url": "https://bsky.app/profile/netsecio.bsky.social/post/3mp4vsuypfp2r",
            "origin": false,
            "authority": false,
            "github": []
          },
          {
            "handle": "infosecbriefly.bsky.social",
            "displayName": "Information Security Briefly",
            "likes": 0,
            "reposts": 0,
            "replies": 0,
            "createdAt": "2026-06-24",
            "url": "https://bsky.app/profile/infosecbriefly.bsky.social/post/3mozwu5rpct2w",
            "origin": false,
            "authority": false,
            "github": []
          }
        ]
      },
      "telegram": {
        "mentions": 0,
        "posts": []
      },
      "researchers": [
        "heckintosh_"
      ],
      "corroboration": {
        "poc": false,
        "xOrigin": false,
        "independent": [
          "x-mention"
        ],
        "level": "multi-source"
      },
      "aliases": []
    }
  ]
}
