{
  "summary": {
    "source": "poc",
    "year": 2026,
    "builtAt": "2026-07-22T06:02:37.597Z",
    "nomiTotal": 766,
    "newCandidates": 24,
    "newlyVerified": 24,
    "newlyKept": 13,
    "carried": 150,
    "verifyCapped": false,
    "total": 150,
    "withCvss": 138,
    "alsoKev": 27,
    "checkedCount": 682
  },
  "cves": [
    {
      "cve": "CVE-2026-42945",
      "title": "NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_rewrite_module…",
      "category": "Recall",
      "vendor": null,
      "exploited": false,
      "publiclyDisclosed": true,
      "cvss": 8.1,
      "cvssVector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "severity": "HIGH",
      "impact": null,
      "products": [],
      "productCount": 0,
      "faq": "NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_rewrite_module module. This vulnerability exists when the rewrite directive is followed by a rewrite, if, or set directive and an unnamed Perl-Compatible Regular Expression (PCRE) capture (for example, $1, $2) with a replacement string that includes a question mark (?). An unauthenticated attacker along with conditions beyond its control can exploit this vulnerability by sending crafted HTTP requests. This may cause a heap buffer overflow in the NGINX worker process leading to a restart. Additionally, attackers can execute code on systems with Address Space Layout Randomization (ASLR) disabled or when the attacker can bypass ASLR.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.",
      "pocConfidence": "confirmed",
      "pocCount": 8,
      "pocTopStars": 851,
      "pocRepos": [
        {
          "url": "https://github.com/DepthFirstDisclosures/Nginx-Rift",
          "stars": 851,
          "desc": "exploit for CVE-2026-42945",
          "createdAt": "2026-05-12",
          "hasCode": true
        },
        {
          "url": "https://github.com/cipherspy/CVE-2026-42945-POC",
          "stars": 41,
          "desc": "exploit for CVE-2026-42945",
          "createdAt": "2026-05-14",
          "hasCode": true
        },
        {
          "url": "https://github.com/rheodev/CVE-2026-42945",
          "stars": 18,
          "desc": "NGINX Rift 漏洞分析与复现",
          "createdAt": "2026-05-14",
          "hasCode": true
        },
        {
          "url": "https://github.com/p3Nt3st3r-sTAr/CVE-2026-42945-POC",
          "stars": 15,
          "desc": "",
          "createdAt": "2026-05-14",
          "hasCode": true
        },
        {
          "url": "https://github.com/nu0l/NGINX-Rift",
          "stars": 4,
          "desc": "CVE-2026-42945 NGINX 堆溢出漏洞扫描与验证工具",
          "createdAt": "2026-05-25",
          "hasCode": true
        },
        {
          "url": "https://github.com/bamov970/CVE-2026-42945-Nginx-RCE-bypass-ASLR",
          "stars": 4,
          "desc": "CVE-2026-42945 turns a 17-year-old NGINX rewrite bug into remote code execution — even with ASLR on, by chaining the heap overflow with live worker memory read ",
          "createdAt": "2026-05-25",
          "hasCode": true
        }
      ],
      "epss": 0.61469,
      "epssPercentile": 0.99074,
      "source": "poc",
      "mitreUrl": "https://nvd.nist.gov/vuln/detail/CVE-2026-42945",
      "research": [
        {
          "url": "https://thehackernews.com/2026/05/18-year-old-nginx-rewrite-module-flaw.html",
          "type": "writeup",
          "source": "The Hacker News",
          "note": "18-yr rewrite-module heap overflow; ITW"
        },
        {
          "url": "https://orca.security/resources/blog/nginx-rewrite-module-vulnerability-cve-2026-42945/",
          "type": "writeup",
          "source": "Orca",
          "note": "Analysis"
        },
        {
          "url": "https://securityonline.info/nginx-rce-vulnerability-cve-2026-42945-poc-disclosure/",
          "type": "writeup",
          "source": "securityonline",
          "note": "PoC w/ ASLR-bypass chain"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-42945",
          "type": "writeup",
          "source": "NVD",
          "note": "Detail"
        }
      ],
      "x": {
        "mentions": 10,
        "posts": [
          {
            "handle": "0x0SojalSec",
            "followers": 44035,
            "likes": 11,
            "createdAt": "2026-06-07",
            "url": "https://x.com/0x0SojalSec/status/2063706678328188940",
            "origin": false,
            "github": []
          },
          {
            "handle": "KasperskyDev",
            "followers": 39987,
            "likes": 0,
            "createdAt": "2026-06-07",
            "url": "https://x.com/KasperskyDev/status/2063547273016119366",
            "origin": false,
            "github": []
          },
          {
            "handle": "lyrie_ai",
            "followers": 234,
            "likes": 0,
            "createdAt": "2026-06-07",
            "url": "https://x.com/lyrie_ai/status/2063504760313946186",
            "origin": false,
            "github": []
          }
        ],
        "aliases": []
      },
      "aliases": [
        "NGINX Rift"
      ],
      "researchers": [],
      "bsky": {
        "mentions": 22,
        "posts": [
          {
            "handle": "infosec.skyfleet.blue",
            "displayName": "InfoSec",
            "likes": 2,
            "reposts": 1,
            "replies": 0,
            "createdAt": "2026-05-19",
            "url": "https://bsky.app/profile/infosec.skyfleet.blue/post/3mm7bfzfq532i",
            "origin": false,
            "authority": true,
            "github": []
          },
          {
            "handle": "intcyberdigest.bsky.social",
            "displayName": "International Cyber Digest",
            "likes": 2,
            "reposts": 1,
            "replies": 0,
            "createdAt": "2026-05-19",
            "url": "https://bsky.app/profile/intcyberdigest.bsky.social/post/3mm7sx5ms722a",
            "origin": false,
            "authority": false,
            "github": [
              {
                "url": "https://github.com/Hamid-K/nginx-rift-private-lab",
                "hasCode": true
              }
            ]
          },
          {
            "handle": "mynameisv.bsky.social",
            "displayName": "Mynameisv",
            "likes": 1,
            "reposts": 0,
            "replies": 0,
            "createdAt": "2026-05-14",
            "url": "https://bsky.app/profile/mynameisv.bsky.social/post/3mlse7w45bk24",
            "origin": false,
            "authority": false,
            "github": [
              {
                "url": "https://github.com/depthfirstdisclosures/nginx-rift",
                "hasCode": true
              }
            ]
          },
          {
            "handle": "bearstech.com",
            "displayName": "Bearstech",
            "likes": 3,
            "reposts": 4,
            "replies": 1,
            "createdAt": "2026-05-15",
            "url": "https://bsky.app/profile/bearstech.com/post/3mluw6rgxhf2h",
            "origin": false,
            "authority": false,
            "github": []
          },
          {
            "handle": "yukotan.bsky.social",
            "displayName": "yukotan",
            "likes": 3,
            "reposts": 3,
            "replies": 0,
            "createdAt": "2026-05-14",
            "url": "https://bsky.app/profile/yukotan.bsky.social/post/3mls6mn6yls23",
            "origin": false,
            "authority": false,
            "github": []
          },
          {
            "handle": "almalinux.org",
            "displayName": "AlmaLinux",
            "likes": 4,
            "reposts": 1,
            "replies": 0,
            "createdAt": "2026-05-21",
            "url": "https://bsky.app/profile/almalinux.org/post/3mmesomo3lk24",
            "origin": false,
            "authority": false,
            "github": []
          }
        ]
      },
      "telegram": {
        "mentions": 8,
        "reach": 42899,
        "posts": [
          {
            "channel": "p3Nt3st3rsTAr",
            "channelTitle": "[CVE Pentester] exploits forum",
            "tier": "underground",
            "date": "2026-05-14",
            "views": 553,
            "forwards": 7,
            "url": "https://t.me/p3Nt3st3rsTAr/36",
            "text": "https://nvd.nist.gov/vuln/detail/CVE-2026-42945",
            "github": [],
            "origin": true
          },
          {
            "channel": "thehackernews",
            "channelTitle": "The Hacker News",
            "tier": "news",
            "date": "2026-05-17",
            "views": 12468,
            "forwards": 107,
            "url": "https://t.me/thehackernews/9017",
            "text": "🚨 NGINX bug (CVE-2026-42945) now under active exploitation. Critical heap overflow in rewrite module. Attackers can crash workers with one request (possible RCE). Patch now if using NGINX ≤1.30.0. Check rewrite/if/set rules. Full details: https://thehackernews.com/2026/05/nginx-cve-2026-42945-exploited-in-wild.html",
            "github": [],
            "origin": false
          }
        ]
      }
    },
    {
      "cve": "CVE-2026-31431",
      "title": "In the Linux kernel, the following vulnerability has been resolved: crypto:…",
      "category": "Recall",
      "vendor": null,
      "exploited": true,
      "publiclyDisclosed": true,
      "cvss": 7.8,
      "cvssVector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "severity": "HIGH",
      "impact": null,
      "products": [],
      "productCount": 0,
      "faq": "In the Linux kernel, the following vulnerability has been resolved:\n\ncrypto: algif_aead - Revert to operating out-of-place\n\nThis mostly reverts commit 72548b093ee3 except for the copying of\nthe associated data.\n\nThere is no benefit in operating in-place in algif_aead since the\nsource and destination come from different mappings.  Get rid of\nall the complexity added for in-place operation and just copy the\nAD directly.",
      "pocConfidence": "confirmed",
      "pocCount": 8,
      "pocTopStars": 427,
      "pocRepos": [
        {
          "url": "https://github.com/tgies/copy-fail-c",
          "stars": 427,
          "desc": "Cross-platform C port of the Copy Fail Linux LPE (CVE-2026-31431). Disclosed 2026-04-29 by Theori / Xint.",
          "createdAt": "2026-04-29",
          "hasCode": true
        },
        {
          "url": "https://github.com/Percivalll/Copy-Fail-CVE-2026-31431-Kubernetes-PoC",
          "stars": 168,
          "desc": "PoC: fully unprivileged container escape to node-level code execution on Kubernetes via CVE-2026-31431 page-cache corruption + shared image layers. Validated on",
          "createdAt": "2026-04-30",
          "hasCode": true
        },
        {
          "url": "https://github.com/sgkdev/page_inject",
          "stars": 64,
          "desc": "CVE-2026-31431-killed page-cache exploit — code exec into containers sharing the same image layer",
          "createdAt": "2026-05-06",
          "hasCode": true
        },
        {
          "url": "https://github.com/shadowabi/CVE-2026-31431-CopyFail-Universal-LPE",
          "stars": 57,
          "desc": "CVE-2026-31431 Copy Fail — Universal LPE exploit. Dynamic ELF offset + full-binary overwrite, Python 2/3 compatible with ctypes splice fallback",
          "createdAt": "2026-04-30",
          "hasCode": true
        },
        {
          "url": "https://github.com/Smarttfoxx/copyfail",
          "stars": 18,
          "desc": "CVE-2026-31431 (Copy Fail) PoC - Linux kernel page cache corruption via authencesn AF_ALG + splice()",
          "createdAt": "2026-05-01",
          "hasCode": true
        },
        {
          "url": "https://github.com/KaraZajac/DIRTYFAIL",
          "stars": 18,
          "desc": "Detector + PoC for Linux page-cache write vulnerabilities: Copy Fail (CVE-2026-31431) and Dirty Frag (CVE-2026-43284/43500). Authorized security research only.",
          "createdAt": "2026-05-08",
          "hasCode": true
        }
      ],
      "epss": 0.96267,
      "epssPercentile": 0.99872,
      "source": "poc",
      "mitreUrl": "https://nvd.nist.gov/vuln/detail/CVE-2026-31431",
      "research": [
        {
          "url": "https://www.safebreach.com/blog/copy-fail-vulnerability-cve-2026-31431-linux-kernel-privilege-escalation/",
          "type": "writeup",
          "source": "SafeBreach",
          "note": "Discoverer writeup: AF_ALG page-cache LPE"
        },
        {
          "url": "https://github.com/Percivalll/Copy-Fail-CVE-2026-31431-Kubernetes-PoC",
          "type": "poc",
          "source": "Percivalll",
          "note": "Kubernetes PoC",
          "hasCode": true
        },
        {
          "url": "https://www.microsoft.com/en-us/security/blog/2026/05/01/cve-2026-31431-copy-fail-vulnerability-enables-linux-root-privilege-escalation/",
          "type": "writeup",
          "source": "Microsoft",
          "note": "Cloud root LPE analysis"
        },
        {
          "url": "https://access.redhat.com/security/vulnerabilities/RHSB-2026-002",
          "type": "detection",
          "source": "Red Hat",
          "note": "RHSB-2026-002 advisory"
        },
        {
          "url": "https://www.tenable.com/blog/copy-fail-cve-2026-31431-frequently-asked-questions-about-linux-kernel-privilege-escalation",
          "type": "writeup",
          "source": "Tenable",
          "note": "FAQ"
        }
      ],
      "x": {
        "mentions": 20,
        "aliases": [
          "Copy Fail"
        ],
        "posts": [
          {
            "handle": "chenzeling4",
            "followers": 235,
            "likes": 2,
            "createdAt": "2026-05-31",
            "url": "https://x.com/chenzeling4/status/2061009292275404910",
            "github": [],
            "origin": false
          },
          {
            "handle": "InnerWardenSec",
            "followers": 1,
            "likes": 2,
            "createdAt": "2026-05-30",
            "url": "https://x.com/InnerWardenSec/status/2060655469740380493",
            "github": [],
            "origin": false
          },
          {
            "handle": "pithase",
            "followers": 32,
            "likes": 0,
            "createdAt": "2026-05-17",
            "url": "https://x.com/pithase/status/2056110163187155010",
            "github": [
              {
                "url": "https://github.com/Pithase/asm-copyfail",
                "hasCode": false
              }
            ],
            "origin": false
          },
          {
            "handle": "AlikBurton",
            "followers": 2,
            "likes": 0,
            "createdAt": "2026-06-05",
            "url": "https://x.com/AlikBurton/status/2062976897521516784",
            "github": [
              {
                "url": "http://github.com/Percivalll/Copy-Fail-CVE-2026-31431",
                "hasCode": null
              }
            ],
            "origin": false
          },
          {
            "handle": "TweetThreatNews",
            "followers": 4337,
            "likes": 0,
            "createdAt": "2026-05-29",
            "url": "https://x.com/TweetThreatNews/status/2060383194579456389",
            "github": [],
            "origin": false
          },
          {
            "handle": "LaZuricata",
            "followers": 3019,
            "likes": 0,
            "createdAt": "2026-05-27",
            "url": "https://x.com/LaZuricata/status/2059753014500471002",
            "github": [],
            "origin": false
          },
          {
            "handle": "newstecnicas",
            "followers": 1187,
            "likes": 0,
            "createdAt": "2026-05-29",
            "url": "https://x.com/newstecnicas/status/2060198479108935798",
            "github": [],
            "origin": false
          }
        ]
      },
      "aliases": [
        "Copy Fail"
      ],
      "researchers": [
        "SafeBreach"
      ],
      "bsky": {
        "mentions": 32,
        "posts": [
          {
            "handle": "9to5linux.com",
            "displayName": "9to5Linux.com",
            "likes": 13,
            "reposts": 1,
            "replies": 0,
            "createdAt": "2026-05-10",
            "url": "https://bsky.app/profile/9to5linux.com/post/3mlhsgkorek2y",
            "origin": true,
            "authority": false,
            "github": []
          },
          {
            "handle": "beitmenotyou.online",
            "displayName": "Michael J Burgess",
            "likes": 2,
            "reposts": 0,
            "replies": 0,
            "createdAt": "2026-05-10",
            "url": "https://bsky.app/profile/beitmenotyou.online/post/3mlisplql5k2j",
            "origin": true,
            "authority": false,
            "github": []
          },
          {
            "handle": "infosec.skyfleet.blue",
            "displayName": "InfoSec",
            "likes": 1,
            "reposts": 0,
            "replies": 0,
            "createdAt": "2026-05-03",
            "url": "https://bsky.app/profile/infosec.skyfleet.blue/post/3mkx3lztwey22",
            "origin": false,
            "authority": true,
            "github": []
          },
          {
            "handle": "wired.com",
            "displayName": "WIRED",
            "likes": 56,
            "reposts": 21,
            "replies": 2,
            "createdAt": "2026-05-01",
            "url": "https://bsky.app/profile/wired.com/post/3mksxzyyfc72e",
            "origin": false,
            "authority": false,
            "github": []
          },
          {
            "handle": "nidouille.bsky.social",
            "displayName": "Nidouille",
            "likes": 34,
            "reposts": 16,
            "replies": 5,
            "createdAt": "2026-04-30",
            "url": "https://bsky.app/profile/nidouille.bsky.social/post/3mkp6lyjnfc2b",
            "origin": false,
            "authority": false,
            "github": []
          },
          {
            "handle": "adriend.linuxtricks.fr",
            "displayName": "Adrien Linuxtricks",
            "likes": 19,
            "reposts": 6,
            "replies": 4,
            "createdAt": "2026-05-04",
            "url": "https://bsky.app/profile/adriend.linuxtricks.fr/post/3mkz75n7g4s2s",
            "origin": false,
            "authority": false,
            "github": []
          }
        ]
      },
      "telegram": {
        "mentions": 16,
        "posts": [
          {
            "channel": "vxunderground",
            "channelTitle": "vx-underground",
            "tier": "underground",
            "date": "2026-04-29",
            "views": 21907,
            "forwards": 362,
            "url": "https://t.me/vxunderground/8796",
            "text": "CVE-2026-31431 a/k/a CopyFail > Linux LPE > Description sounds like AI slop > Exploit is legit > Impacts every Linux kernel from 2017 - Now > Proof-of-concept released > It's Wednesday? https://copy.fail/",
            "github": [],
            "origin": true
          },
          {
            "channel": "news4hack",
            "channelTitle": "Pentester",
            "tier": "feed",
            "date": "2026-05-12",
            "views": 783,
            "forwards": 5,
            "url": "https://t.me/news4hack/3092",
            "text": "Dirty Frag: Universal Linux LPE Obtain root privileges on major Linux distributions by chaining the xfrm-ESP Page-Cache Write vulnerability and the RxRPC Page-Cache Writevulnerability. Dirty Frag is a case that extends the bug class to which Dirty Pipe and Copy Fail belong. Because it is a deterministic logic bug that does not depend on a timing window, no race condition is required, the kernel do",
            "github": [],
            "origin": false
          },
          {
            "channel": "thehackernews",
            "channelTitle": "The Hacker News",
            "tier": "news",
            "date": "2026-05-03",
            "views": 13230,
            "forwards": 75,
            "url": "https://t.me/thehackernews/8920",
            "text": "⚠️ A new #Linux flaw is now under active exploitation. CISA added CVE-2026-31431 to its KEV list. The bug lets low-privilege users gain full root access. Patches released. Fix deadline: May 15, 2026. Read: https://thehackernews.com/2026/05/cisa-adds-actively-exploited-linux-root.html",
            "github": [],
            "origin": false
          }
        ]
      }
    },
    {
      "cve": "CVE-2026-63030",
      "title": "WordPress 6.9.x before 6.9.5 and 7.0.x before 7.0.2 is affected by a REST API batch…",
      "category": "Recall",
      "vendor": null,
      "exploited": true,
      "publiclyDisclosed": true,
      "cvss": 9.8,
      "cvssVector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "severity": "CRITICAL",
      "impact": null,
      "products": [],
      "productCount": 0,
      "faq": "WordPress 6.9.x before 6.9.5 and 7.0.x before 7.0.2 is affected by a REST API batch endpoint route confusion issue which, combined with the author__not_in WP_Query SQL Injection (CVE-2026-60137), could allow an attacker to perform SQL Injection and achieve Remote Code Execution.",
      "pocConfidence": "confirmed",
      "pocCount": 8,
      "pocTopStars": 407,
      "pocRepos": [
        {
          "url": "https://github.com/Icex0/wp2shell-poc",
          "stars": 407,
          "desc": "wp2shell (CVE-2026-63030 & CVE-2026-60137) - full RCE chain",
          "createdAt": "2026-07-17",
          "hasCode": true
        },
        {
          "url": "https://github.com/0xsha/wp2shell",
          "stars": 46,
          "desc": "CVE-2026-63030 + CVE-2026-60137 - “wp2shell”: unauthenticated RCE in WordPress core",
          "createdAt": "2026-07-18",
          "hasCode": true
        },
        {
          "url": "https://github.com/dinosn/wp2shell-lab",
          "stars": 34,
          "desc": "Non-destructive detector + Docker lab for wp2shell (CVE-2026-63030 REST /batch/v1 route confusion + CVE-2026-60137 author__not_in SQLi) in WordPress core 6.9.0-",
          "createdAt": "2026-07-18",
          "hasCode": true
        },
        {
          "url": "https://github.com/47Cid/wp2shell-lab",
          "stars": 12,
          "desc": "Educational PoC + lab for CVE-2026-63030 + CVE-2026-60137: pre-auth SQLi in WordPress core via REST batch-route confusion",
          "createdAt": "2026-07-18",
          "hasCode": true
        },
        {
          "url": "https://github.com/NULL200OK/WP2Shell",
          "stars": 8,
          "desc": "WP2Shell - CVE-2026-63030 / CVE-2026-60137 This tool exploits a critical SQL injection vulnerability in the WordPress REST API `/wp-json/batch/v1` endpoint, all",
          "createdAt": "2026-07-18",
          "hasCode": true
        },
        {
          "url": "https://github.com/4minx/CVE-2026-63030",
          "stars": 8,
          "desc": "CVE-2026-63030 (wp2shell) POC.",
          "createdAt": "2026-07-18",
          "hasCode": true
        }
      ],
      "epss": 0.08946,
      "epssPercentile": 0.94679,
      "source": "poc",
      "mitreUrl": "https://nvd.nist.gov/vuln/detail/CVE-2026-63030",
      "research": [
        {
          "url": "https://github.com/Icex0/wp2shell-poc",
          "type": "poc",
          "source": "Icex0 / GitHub",
          "note": "Full RCE chain: SQLi→admin forge→webshell plugin",
          "hasCode": true
        },
        {
          "url": "https://github.com/0xsha/wp2shell",
          "type": "poc",
          "source": "0xsha / GitHub",
          "note": "Unified stdlib-only RCE; credits Icex0/sergiointel techniques",
          "hasCode": true
        },
        {
          "url": "https://github.com/sergiointel/wp2shell-poc",
          "type": "poc",
          "source": "sergiointel / GitHub",
          "note": "Crack-free pre-auth admin creation via oEmbed/customizer",
          "hasCode": true
        },
        {
          "url": "https://slcyber.io/research-center/wp2shell-pre-authentication-rce-in-wordpress-core/",
          "type": "writeup",
          "source": "Adam Kues / Searchlight Cyber (Assetnote)",
          "note": "Original discoverer writeup; authoritative disclosure"
        },
        {
          "url": "https://labs.eye.security/wp2shell-defenders-guide/",
          "type": "writeup",
          "source": "Eye Security Research",
          "note": "Deep defender guide; verified end-to-end chain independently"
        },
        {
          "url": "https://www.rapid7.com/blog/post/etr-cve-2026-63030-wp2shell-a-critical-remote-code-execution-vulnerability-in-wordpress-core/",
          "type": "writeup",
          "source": "Rapid7 ETR",
          "note": "ETR with CVSS analysis; InsightVM/Nexpose coverage noted"
        },
        {
          "url": "https://github.com/projectdiscovery/nuclei-templates/pull/16595",
          "type": "module",
          "source": "mielverkerken / ProjectDiscovery nuclei-templates",
          "note": "Official Nuclei detection template PR; merged 2026-07-17",
          "hasCode": true
        },
        {
          "url": "https://github.com/Senanfurkan/wordpress-cve-2026-63030",
          "type": "detection",
          "source": "Senanfurkan / GitHub",
          "note": "Safe detection-only PoC: route confusion + time-based SQLi",
          "hasCode": true
        }
      ],
      "aliases": [
        "wp2shell"
      ],
      "researchers": [
        "adamkues",
        "Icex0",
        "0xsha",
        "sergiointel",
        "attackercan"
      ],
      "x": {
        "mentions": 133,
        "aliases": [
          "wp2shell"
        ],
        "posts": [
          {
            "handle": "elhackernet",
            "followers": 140895,
            "likes": 10,
            "createdAt": "2026-07-20",
            "url": "https://x.com/elhackernet/status/2079297919677857809",
            "github": [],
            "origin": true
          },
          {
            "handle": "connect24h",
            "followers": 4416,
            "likes": 8,
            "createdAt": "2026-07-20",
            "url": "https://x.com/connect24h/status/2079284178823344328",
            "github": [],
            "origin": true
          },
          {
            "handle": "Racer_Kamira",
            "followers": 11440,
            "likes": 5,
            "createdAt": "2026-07-20",
            "url": "https://x.com/Racer_Kamira/status/2079298320045056275",
            "github": [],
            "origin": true
          },
          {
            "handle": "siennawebdesign",
            "followers": 292,
            "likes": 3,
            "createdAt": "2026-07-20",
            "url": "https://x.com/siennawebdesign/status/2079342484493156445",
            "github": [],
            "origin": true
          },
          {
            "handle": "snyff",
            "followers": 20667,
            "likes": 2,
            "createdAt": "2026-07-20",
            "url": "https://x.com/snyff/status/2079336372310249667",
            "github": [],
            "origin": true
          },
          {
            "handle": "__kokumoto",
            "followers": 7585,
            "likes": 2,
            "createdAt": "2026-07-20",
            "url": "https://x.com/__kokumoto/status/2079345020709265478",
            "github": [],
            "origin": true
          },
          {
            "handle": "Horizon3ai",
            "followers": 2894,
            "likes": 2,
            "createdAt": "2026-07-20",
            "url": "https://x.com/Horizon3ai/status/2079336182480257029",
            "github": [],
            "origin": true
          },
          {
            "handle": "__su888",
            "followers": 853,
            "likes": 2,
            "createdAt": "2026-07-20",
            "url": "https://x.com/__su888/status/2079325728181518491",
            "github": [],
            "origin": true
          }
        ]
      },
      "bsky": {
        "mentions": 35,
        "posts": [
          {
            "handle": "infosec.skyfleet.blue",
            "displayName": "InfoSec",
            "likes": 1,
            "reposts": 0,
            "replies": 0,
            "createdAt": "2026-07-18",
            "url": "https://bsky.app/profile/infosec.skyfleet.blue/post/3mqwsmwum3c22",
            "origin": true,
            "authority": true,
            "github": []
          },
          {
            "handle": "raptor.infosec.exchange.ap.brid.gy",
            "displayName": "raptor",
            "likes": 1,
            "reposts": 1,
            "replies": 1,
            "createdAt": "2026-07-18",
            "url": "https://bsky.app/profile/raptor.infosec.exchange.ap.brid.gy/post/3mqvtnm45ddy2",
            "origin": true,
            "authority": false,
            "github": [
              {
                "url": "https://github.com/Icex0/wp2shell-poc",
                "hasCode": true
              }
            ]
          },
          {
            "handle": "r-blueteamsec.bsky.social",
            "displayName": "r/blueteamsec bot",
            "likes": 0,
            "reposts": 0,
            "replies": 0,
            "createdAt": "2026-07-18",
            "url": "https://bsky.app/profile/r-blueteamsec.bsky.social/post/3mqw7fxlakd2e",
            "origin": true,
            "authority": false,
            "github": [
              {
                "url": "https://github.com/Icex0/wp2shell-poc",
                "hasCode": true
              }
            ]
          },
          {
            "handle": "goodtech.info",
            "displayName": "Goodtech - L'actu open source 🇫🇷🐧🇪🇺",
            "likes": 2,
            "reposts": 2,
            "replies": 0,
            "createdAt": "2026-07-20",
            "url": "https://bsky.app/profile/goodtech.info/post/3mr24wwys63ec",
            "origin": true,
            "authority": false,
            "github": []
          },
          {
            "handle": "ninjaowl.ai",
            "displayName": "Ninja Owl",
            "likes": 3,
            "reposts": 0,
            "replies": 0,
            "createdAt": "2026-07-19",
            "url": "https://bsky.app/profile/ninjaowl.ai/post/3mqxim6htkn2o",
            "origin": true,
            "authority": false,
            "github": []
          },
          {
            "handle": "lobsters-feed.bsky.social",
            "displayName": "The Lobste.rs RSS feed",
            "likes": 1,
            "reposts": 0,
            "replies": 0,
            "createdAt": "2026-07-18",
            "url": "https://bsky.app/profile/lobsters-feed.bsky.social/post/3mqwvioehke2o",
            "origin": true,
            "authority": false,
            "github": []
          }
        ]
      },
      "telegram": {
        "mentions": 12,
        "reach": 50074,
        "posts": [
          {
            "channel": "thehackernews",
            "channelTitle": "The Hacker News",
            "tier": "news",
            "date": "2026-07-18",
            "views": 9529,
            "forwards": 78,
            "url": "https://t.me/thehackernews/9544",
            "text": "⚡ UPDATE: #wp2shell now has two CVEs, and a working proof-of-concept is public. > CVE-2026-63030 breaks REST batch routing > CVE-2026-60137 injects SQL Chained, they give an anonymous attacker code execution on affected WordPress sites. How the exploit path works: https://thehackernews.com/2026/07/new-wp2shell-wordpress-core-flaw-lets.html",
            "github": [],
            "origin": false
          }
        ]
      }
    },
    {
      "cve": "CVE-2026-48907",
      "title": "A vulnerability in the JCE editor extension for Joomla allows the creation of new…",
      "category": "Recall",
      "vendor": null,
      "exploited": true,
      "publiclyDisclosed": true,
      "cvss": 9.8,
      "cvssVector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "severity": "CRITICAL",
      "impact": null,
      "products": [],
      "productCount": 0,
      "faq": "A vulnerability in the JCE editor extension for Joomla allows the creation of new editor profiles for unauthenticated users, ultimately resulting in PHP code upload and execution.",
      "pocConfidence": "confirmed",
      "pocCount": 8,
      "pocTopStars": 15,
      "pocRepos": [
        {
          "url": "https://github.com/ywh-jfellus/CVE-2026-48907",
          "stars": 15,
          "desc": "PoC for CVE-2026-48907 - Joomla! JCE extension < 2.9.99.5 unauthenticated RCE",
          "createdAt": "2026-06-11",
          "hasCode": true
        },
        {
          "url": "https://github.com/0xBlackash/CVE-2026-48907",
          "stars": 3,
          "desc": "CVE-2026-48907",
          "createdAt": "2026-06-12",
          "hasCode": true
        },
        {
          "url": "https://github.com/0xgh057r3c0n/CVE-2026-48907",
          "stars": 3,
          "desc": "CVE-2025-48907 - Unauthenticated RCE exploit for Joomla JCE < 2.9.99.5",
          "createdAt": "2026-06-22",
          "hasCode": true
        },
        {
          "url": "https://github.com/K3ysTr0K3R/CVE-2026-48907",
          "stars": 2,
          "desc": "CVE-2026-48907 – Joomla JCE Unauthenticated Remote Code Execution (RCE)",
          "createdAt": "2026-06-29",
          "hasCode": true
        },
        {
          "url": "https://github.com/webshellseo8/CVE-2026-48907-Unauthenticated-RCE-in-JCE",
          "stars": 1,
          "desc": "CVE-2026-48907: Unauthenticated RCE in JCE (Proof Of Concept)",
          "createdAt": "2026-06-09",
          "hasCode": true
        },
        {
          "url": "https://github.com/sec0x/CVE-2026-48907",
          "stars": 1,
          "desc": "",
          "createdAt": "2026-06-22",
          "hasCode": true
        }
      ],
      "epss": 0.80425,
      "epssPercentile": 0.9958,
      "source": "poc",
      "mitreUrl": "https://nvd.nist.gov/vuln/detail/CVE-2026-48907",
      "research": [],
      "aliases": [],
      "researchers": [],
      "x": {
        "mentions": 0,
        "aliases": [],
        "posts": []
      },
      "bsky": {
        "mentions": 25,
        "posts": [
          {
            "handle": "infosec.skyfleet.blue",
            "displayName": "InfoSec",
            "likes": 0,
            "reposts": 1,
            "replies": 0,
            "createdAt": "2026-06-19",
            "url": "https://bsky.app/profile/infosec.skyfleet.blue/post/3monw2r2oet2r",
            "origin": false,
            "authority": true,
            "github": []
          },
          {
            "handle": "thecybermind.co",
            "displayName": "mikeransier.bsky.social",
            "likes": 1,
            "reposts": 0,
            "replies": 0,
            "createdAt": "2026-06-17",
            "url": "https://bsky.app/profile/thecybermind.co/post/3moj6czenx42m",
            "origin": false,
            "authority": true,
            "github": []
          },
          {
            "handle": "secdb.bsky.social",
            "displayName": "ZEN SecDB",
            "likes": 0,
            "reposts": 0,
            "replies": 0,
            "createdAt": "2026-06-16",
            "url": "https://bsky.app/profile/secdb.bsky.social/post/3mogoxjqp6j2k",
            "origin": false,
            "authority": true,
            "github": []
          },
          {
            "handle": "rxerium.com",
            "displayName": "Rishi",
            "likes": 0,
            "reposts": 0,
            "replies": 0,
            "createdAt": "2026-06-17",
            "url": "https://bsky.app/profile/rxerium.com/post/3moi6zikyzp2k",
            "origin": false,
            "authority": false,
            "github": [
              {
                "url": "https://github.com/rxerium/rxerium-templates/blob/main/2026/CVE-2026-48907.yaml",
                "hasCode": true
              }
            ]
          },
          {
            "handle": "offseq.bsky.social",
            "displayName": "OffSequence",
            "likes": 6,
            "reposts": 2,
            "replies": 0,
            "createdAt": "2026-06-05",
            "url": "https://bsky.app/profile/offseq.bsky.social/post/3mnjrmkgh2423",
            "origin": false,
            "authority": false,
            "github": []
          },
          {
            "handle": "cve.skyfleet.blue",
            "displayName": "CVE Alerts ",
            "likes": 5,
            "reposts": 1,
            "replies": 0,
            "createdAt": "2026-06-05",
            "url": "https://bsky.app/profile/cve.skyfleet.blue/post/3mnjqzbo4aw2q",
            "origin": false,
            "authority": false,
            "github": []
          }
        ]
      },
      "telegram": {
        "mentions": 3,
        "reach": 7981,
        "posts": [
          {
            "channel": "thehackernews",
            "channelTitle": "The Hacker News",
            "tier": "news",
            "date": "2026-06-17",
            "views": 6942,
            "forwards": 19,
            "url": "https://t.me/thehackernews/9260",
            "text": "🚨 A Joomla flaw is now on CISA’s exploited bug list. CVE-2026-48907 has a max CVSS score of 10.0 and can let attackers upload and run PHP code through JCE editor profiles. Affected versions: 1.0.0 through 2.9.99.4 Fixed in: 2.9.99.5 Details here: https://thehackernews.com/2026/06/cisa-warns-of-actively-exploited-joomla.html",
            "github": [],
            "origin": false
          }
        ]
      }
    },
    {
      "cve": "CVE-2026-41940",
      "title": "cPanel and WHM versions after 11.40 contain an authentication bypass vulnerability in…",
      "category": "Recall",
      "vendor": null,
      "exploited": true,
      "publiclyDisclosed": true,
      "cvss": 9.8,
      "cvssVector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "severity": "CRITICAL",
      "impact": null,
      "products": [],
      "productCount": 0,
      "faq": "cPanel and WHM versions after 11.40 contain an authentication bypass vulnerability in the login flow that allows unauthenticated remote attackers to gain unauthorized access to the control panel.",
      "pocConfidence": "confirmed",
      "pocCount": 8,
      "pocTopStars": 12,
      "pocRepos": [
        {
          "url": "https://github.com/bughunt4me/cpanelCVE-2026-41940",
          "stars": 12,
          "desc": "CVE-2026-41940 Auto Root Login",
          "createdAt": "2026-05-06",
          "hasCode": true
        },
        {
          "url": "https://github.com/Christian93111/CVE-2026-41940",
          "stars": 9,
          "desc": "cPanel/WHM Authentication Bypass (Zero-Day Vulnerability)",
          "createdAt": "2026-05-01",
          "hasCode": true
        },
        {
          "url": "https://github.com/mahfuzreham/cpanel-cve-2026-41940",
          "stars": 3,
          "desc": "cPanel CVE-2026-41940 nuclear.x86 Security Audit & Cleanup Script",
          "createdAt": "2026-05-01",
          "hasCode": true
        },
        {
          "url": "https://github.com/44pie/cpsniper",
          "stars": 2,
          "desc": "cPanelSniper STABLE - CVE-2026-41940 optimized for 10M+ targets",
          "createdAt": "2026-05-10",
          "hasCode": true
        },
        {
          "url": "https://github.com/MrOplus/CVE-2026-41940",
          "stars": 1,
          "desc": "CVE-2026-41940 Direct Shell Acess",
          "createdAt": "2026-05-02",
          "hasCode": true
        },
        {
          "url": "https://github.com/ZildanZ/CVE-2026-41940",
          "stars": 1,
          "desc": "",
          "createdAt": "2026-05-05",
          "hasCode": true
        }
      ],
      "epss": 0.981,
      "epssPercentile": 0.99907,
      "source": "poc",
      "mitreUrl": "https://nvd.nist.gov/vuln/detail/CVE-2026-41940",
      "research": [
        {
          "url": "https://www.rapid7.com/blog/post/etr-cve-2026-41940-cpanel-whm-authentication-bypass/",
          "type": "writeup",
          "source": "Rapid7",
          "note": "CRLF-injection auth bypass"
        },
        {
          "url": "https://www.picussecurity.com/resource/blog/cve-2026-41940-explained-cpanel-whm-authentication-bypass-hit-1-5m-servers",
          "type": "writeup",
          "source": "Picus",
          "note": "~1.5M servers; ITW before patch"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-41940",
          "type": "writeup",
          "source": "NVD",
          "note": "Detail"
        }
      ],
      "x": {
        "mentions": 7,
        "aliases": [],
        "posts": [
          {
            "handle": "Anastasis_King",
            "followers": 9833,
            "likes": 6,
            "createdAt": "2026-05-22",
            "url": "https://x.com/Anastasis_King/status/2057689062857740357",
            "github": [
              {
                "url": "https://github.com/ynsmroztas/cPanelSniper",
                "hasCode": true
              }
            ],
            "origin": false
          },
          {
            "handle": "sardine_web",
            "followers": 33,
            "likes": 0,
            "createdAt": "2026-05-24",
            "url": "https://x.com/sardine_web/status/2058509287505449032",
            "github": [
              {
                "url": "https://github.com/sardine-web/Automated-scanner-CVE-2026-41940",
                "hasCode": false
              }
            ],
            "origin": false
          },
          {
            "handle": "lyrie_ai",
            "followers": 236,
            "likes": 0,
            "createdAt": "2026-06-01",
            "url": "https://x.com/lyrie_ai/status/2061357415740653780",
            "github": [],
            "origin": false
          },
          {
            "handle": "hieyz6838",
            "followers": 10,
            "likes": 0,
            "createdAt": "2026-06-05",
            "url": "https://x.com/hieyz6838/status/2062713724511650028",
            "github": [],
            "origin": false
          }
        ]
      },
      "researchers": [
        "Sina Kheirkhah",
        "watchTowr"
      ],
      "bsky": {
        "mentions": 39,
        "posts": [
          {
            "handle": "thezdi.bsky.social",
            "displayName": "TrendAI Zero Day Initiative",
            "likes": 5,
            "reposts": 0,
            "replies": 0,
            "createdAt": "2025-05-15",
            "url": "https://bsky.app/profile/thezdi.bsky.social/post/3lp753n7rus2a",
            "origin": true,
            "authority": false,
            "github": []
          },
          {
            "handle": "jbhall56.bsky.social",
            "displayName": "PCI Guru",
            "likes": 0,
            "reposts": 0,
            "replies": 0,
            "createdAt": "2023-09-02",
            "url": "https://bsky.app/profile/jbhall56.bsky.social/post/3k6gjogueeg2o",
            "origin": true,
            "authority": false,
            "github": []
          },
          {
            "handle": "shadowserver.bsky.social",
            "displayName": "The Shadowserver Foundation",
            "likes": 17,
            "reposts": 8,
            "replies": 1,
            "createdAt": "2026-05-01",
            "url": "https://bsky.app/profile/shadowserver.bsky.social/post/3mksb7b5qfc2u",
            "origin": false,
            "authority": true,
            "github": []
          },
          {
            "handle": "bleepingcomputer.com",
            "displayName": "BleepingComputer",
            "likes": 7,
            "reposts": 7,
            "replies": 1,
            "createdAt": "2026-04-30",
            "url": "https://bsky.app/profile/bleepingcomputer.com/post/3mkpjrrbolm26",
            "origin": false,
            "authority": true,
            "github": []
          },
          {
            "handle": "echobit.de",
            "displayName": "Echobit",
            "likes": 22,
            "reposts": 6,
            "replies": 3,
            "createdAt": "2026-05-05",
            "url": "https://bsky.app/profile/echobit.de/post/3ml3wpvvox22d",
            "origin": false,
            "authority": false,
            "github": []
          },
          {
            "handle": "hakksaww.bsky.social",
            "displayName": "Patrick Duggan",
            "likes": 8,
            "reposts": 0,
            "replies": 0,
            "createdAt": "2026-06-04",
            "url": "https://bsky.app/profile/hakksaww.bsky.social/post/3mnhtszjofo2f",
            "origin": false,
            "authority": false,
            "github": []
          }
        ]
      },
      "telegram": {
        "mentions": 13,
        "posts": [
          {
            "channel": "LearnExploit",
            "channelTitle": "0Day.Today | Learn Exploit | Zero World | Dark web |",
            "tier": "underground",
            "date": "2026-05-02",
            "views": 2449,
            "forwards": 40,
            "url": "https://t.me/LearnExploit/9932",
            "text": "باگ اومده چه باگگگیییی😂⚠️⚠️ [CVE-2026-41940](https://nvd.nist.gov/vuln/detail/CVE-2026-41940) ببین داستان چیه : یه باگ *authentication bypass* خیلی خفن توی cPanel و WHM پیدا شده که اجازه میده بدون لاگین (!) مستقیم وارد پنل ادمین بشی 😶 یعنی literally بدون یوزرنیم و پسورد → دسترسی کامل. شدت؟ CVSS حدود 9.8 یعنی عملاً “critical به معنای واقعی” چه نسخه‌هایی؟ تقریباً همه نسخه‌ها بعد از 11.40 درگیرن یعنی",
            "github": [],
            "origin": true
          },
          {
            "channel": "thehackernews",
            "channelTitle": "The Hacker News",
            "tier": "news",
            "date": "2026-04-30",
            "views": 9943,
            "forwards": 86,
            "url": "https://t.me/thehackernews/8903",
            "text": "⚠️ UPDATE: #cPanel flaw now tracked as CVE-2026-41940 (CVSS 9.8)—an auth bypass granting unauthenticated admin access. Actively exploited as a 0-day for weeks. Root cause: CRLF injection lets attackers forge sessions and escalate to root. 🔗 Exploit mechanics and real-world impact → https://thehackernews.com/2026/04/critical-cpanel-authentication.html",
            "github": [],
            "origin": false
          }
        ]
      },
      "aliases": []
    },
    {
      "cve": "CVE-2026-0073",
      "title": "In adbd_tls_verify_cert of auth.cpp, there is a possible bypass of wireless ADB…",
      "category": "Recall",
      "vendor": null,
      "exploited": false,
      "publiclyDisclosed": true,
      "cvss": 8.8,
      "cvssVector": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "severity": "HIGH",
      "impact": null,
      "products": [],
      "productCount": 0,
      "faq": "In adbd_tls_verify_cert of auth.cpp, there is a possible bypass of wireless ADB mutual authentication due to a logic error in the code. This could lead to remote (proximal/adjacent) code execution as the shell user with no additional execution privileges needed. User interaction is not needed for exploitation.",
      "pocConfidence": "confirmed",
      "pocCount": 7,
      "pocTopStars": 77,
      "pocRepos": [
        {
          "url": "https://github.com/SecTestAnnaQuinn/CVE-2026-0073-Android-adbd-authentication-bypass-POC",
          "stars": 77,
          "desc": "",
          "createdAt": "2026-05-05",
          "hasCode": true
        },
        {
          "url": "https://github.com/adityatelange/poc-CVE-2026-0073",
          "stars": 41,
          "desc": "CVE-2026-0073 - ADB Wireless Mutual Authentication Bypass PoC",
          "createdAt": "2026-05-06",
          "hasCode": true
        },
        {
          "url": "https://github.com/MartinPSDev/CVE-2026-0073-Android-ADBD-bypass-POC",
          "stars": 15,
          "desc": "CVE-2026-0073 — Android ADB daemon (adbd) TLS authentication bypass via EVP_PKEY_cmp type confusion. Gain unauthorized shell access over WiFi using EC/Ed25519 k",
          "createdAt": "2026-05-06",
          "hasCode": true
        },
        {
          "url": "https://github.com/devtint/CVE-2026-0073",
          "stars": 4,
          "desc": "https://devtint.github.io/CVE-2026-0073/",
          "createdAt": "2026-05-06",
          "hasCode": true
        },
        {
          "url": "https://github.com/unnaim/adbHijacker",
          "stars": 4,
          "desc": "A PoC tool for the CVE-2026-0073 on android 11+ devices which allows instant zero click RCE on any unpatched device with adb over tcp enabled",
          "createdAt": "2026-05-07",
          "hasCode": true
        },
        {
          "url": "https://github.com/0xBlackash/CVE-2026-0073",
          "stars": 3,
          "desc": "CVE-2026-0073",
          "createdAt": "2026-05-07",
          "hasCode": true
        }
      ],
      "epss": 0.00541,
      "epssPercentile": 0.41928,
      "source": "poc",
      "mitreUrl": "https://nvd.nist.gov/vuln/detail/CVE-2026-0073",
      "research": [
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-0073",
          "type": "writeup",
          "source": "NVD",
          "note": "Official CVE detail for adbd TLS auth bypass"
        },
        {
          "url": "https://mobilehackerforhire.com/tutorial/android-adbd-wireless-debugging-rce-cve-2026-0073/",
          "type": "writeup",
          "source": "mobilehackerforhire",
          "note": "Exploit + mitigation tutorial, EVP_PKEY_cmp type confusion"
        },
        {
          "url": "https://github.com/MartinPSDev/CVE-2026-0073-Android-ADBD-bypass-POC",
          "type": "poc",
          "source": "MartinPSDev",
          "note": "PoC: EC/Ed25519 key mismatch shell over WiFi",
          "hasCode": true
        },
        {
          "url": "https://github.com/adityatelange/poc-CVE-2026-0073",
          "type": "poc",
          "source": "adityatelange",
          "note": "ADB wireless mutual auth bypass PoC",
          "hasCode": true
        },
        {
          "url": "https://www.smarttech247.com/threat-intel-reports/android-cve-2026-0073-wireless-adb-auth-flaw",
          "type": "writeup",
          "source": "Smarttech247",
          "note": "Threat intel report on wireless ADB auth flaw"
        }
      ],
      "x": {
        "mentions": 1,
        "aliases": [],
        "posts": [
          {
            "handle": "lyrie_ai",
            "followers": 236,
            "likes": 0,
            "createdAt": "2026-05-17",
            "url": "https://x.com/lyrie_ai/status/2056095154713383364",
            "github": [],
            "origin": false
          }
        ]
      },
      "aliases": [],
      "researchers": [],
      "bsky": {
        "mentions": 12,
        "posts": [
          {
            "handle": "infosec.skyfleet.blue",
            "displayName": "InfoSec",
            "likes": 1,
            "reposts": 1,
            "replies": 0,
            "createdAt": "2026-05-05",
            "url": "https://bsky.app/profile/infosec.skyfleet.blue/post/3ml53ovl2kj2g",
            "origin": false,
            "authority": true,
            "github": []
          },
          {
            "handle": "grapheneos.org",
            "displayName": "GrapheneOS",
            "likes": 58,
            "reposts": 6,
            "replies": 1,
            "createdAt": "2026-05-08",
            "url": "https://bsky.app/profile/grapheneos.org/post/3mlcj47c6ws2i",
            "origin": false,
            "authority": false,
            "github": []
          },
          {
            "handle": "sonoclaudio.ransomnews.online",
            "displayName": "Claudio",
            "likes": 6,
            "reposts": 3,
            "replies": 1,
            "createdAt": "2026-05-05",
            "url": "https://bsky.app/profile/sonoclaudio.ransomnews.online/post/3ml4wz6ijmk25",
            "origin": false,
            "authority": false,
            "github": []
          },
          {
            "handle": "postac001.bsky.social",
            "displayName": "tec_acc",
            "likes": 1,
            "reposts": 0,
            "replies": 0,
            "createdAt": "2026-05-05",
            "url": "https://bsky.app/profile/postac001.bsky.social/post/3ml4c6p6e372t",
            "origin": false,
            "authority": false,
            "github": []
          },
          {
            "handle": "thehackerwire.bsky.social",
            "displayName": "TheHackerWire",
            "likes": 1,
            "reposts": 0,
            "replies": 0,
            "createdAt": "2026-05-04",
            "url": "https://bsky.app/profile/thehackerwire.bsky.social/post/3ml2hl2mb3f2f",
            "origin": false,
            "authority": false,
            "github": []
          },
          {
            "handle": "android.activitypub.awakari.com.ap.brid.gy",
            "displayName": "Android",
            "likes": 0,
            "reposts": 0,
            "replies": 0,
            "createdAt": "2026-06-09",
            "url": "https://bsky.app/profile/android.activitypub.awakari.com.ap.brid.gy/post/3mnuddfjfjkk2",
            "origin": false,
            "authority": false,
            "github": []
          }
        ]
      },
      "telegram": {
        "mentions": 2,
        "reach": 1448,
        "posts": [
          {
            "channel": "PentestingNews",
            "channelTitle": "Pentesting News",
            "tier": "news",
            "date": "2026-05-05",
            "views": 1381,
            "forwards": 13,
            "url": "https://t.me/PentestingNews/74158",
            "text": "Critical Android vulnerability CVE-2026-0073 fixed by Google https://securityaffairs.com/191710/breaking-news/critical-android-vulnerability-cve-2026-0073-fixed-by-google.html",
            "github": [],
            "origin": false
          }
        ]
      }
    },
    {
      "cve": "CVE-2026-23918",
      "title": "Double Free and possible RCE vulnerability in Apache HTTP Server with the HTTP/2…",
      "category": "Recall",
      "vendor": null,
      "exploited": false,
      "publiclyDisclosed": true,
      "cvss": 8.8,
      "cvssVector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "severity": "HIGH",
      "impact": null,
      "products": [],
      "productCount": 0,
      "faq": "Double Free and possible RCE vulnerability in Apache HTTP Server with the HTTP/2 protocol.\n\nThis issue affects Apache HTTP Server: 2.4.66.\n\nUsers are recommended to upgrade to version 2.4.67, which fixes the issue.",
      "pocConfidence": "confirmed",
      "pocCount": 7,
      "pocTopStars": 29,
      "pocRepos": [
        {
          "url": "https://github.com/striga-ai/CVE-2026-23918",
          "stars": 29,
          "desc": "Double-free in Apache httpd mod_http2 stream cleanup leading to pre-auth RCE.",
          "createdAt": "2026-05-11",
          "hasCode": true
        },
        {
          "url": "https://github.com/xeloxa/CVE-2026-23918-Apache-H2-PoC",
          "stars": 19,
          "desc": "Proof-of-Concept exploit for CVE-2026-23918 (Apache mod_http2 double-free). Features multi-mode DoS (Rapid-RST, Slow-Drip) and passive RCE/vulnerability detecti",
          "createdAt": "2026-05-06",
          "hasCode": true
        },
        {
          "url": "https://github.com/rhasan-com/CVE-2026-23918",
          "stars": 8,
          "desc": "Apache HTTP/2 double-free vulnerability PoC (CVE-2026-23918)",
          "createdAt": "2026-05-06",
          "hasCode": true
        },
        {
          "url": "https://github.com/qassam-315/CVE-2026-23918-Elite-Auditor",
          "stars": 6,
          "desc": "Elite reconnaissance script for auditing Apache's HTTP/2 stack against memory corruption (CVE-2026-23918). Features ALPN protocol forcing and monochrome dashboa",
          "createdAt": "2026-05-05",
          "hasCode": true
        },
        {
          "url": "https://github.com/12lie20/CVE-2026-23918-test",
          "stars": 4,
          "desc": "This repository contains a Proof of Concept (PoC) demonstrating the Double Free vulnerability (CVE-2026-23918) in Apache HTTP Server 2.4.66 `mod_http2`.",
          "createdAt": "2026-05-05",
          "hasCode": true
        },
        {
          "url": "https://github.com/aa022/CVE-2026-23918-Passive-Audit",
          "stars": 0,
          "desc": "Passive HTTP metadata auditor for CVE-2026-23918 exposure triage",
          "createdAt": "2026-05-05",
          "hasCode": true
        }
      ],
      "epss": 0.4581,
      "epssPercentile": 0.98672,
      "source": "poc",
      "mitreUrl": "https://nvd.nist.gov/vuln/detail/CVE-2026-23918",
      "research": [
        {
          "url": "https://www.openwall.com/lists/oss-security/2026/05/04/19",
          "type": "writeup",
          "source": "oss-security",
          "note": "Advisory: HTTP/2 double-free, possible RCE"
        },
        {
          "url": "https://hadrian.io/blog/cve-2026-23918-apache-http-server-double-free-rce-in-http-2-implementation",
          "type": "writeup",
          "source": "Hadrian",
          "note": "mod_http2 h2_mplx double-free analysis"
        },
        {
          "url": "https://thehackernews.com/2026/05/critical-apache-http2-flaw-cve-2026.html",
          "type": "writeup",
          "source": "The Hacker News",
          "note": "DoS + potential RCE"
        }
      ],
      "x": {
        "mentions": 8,
        "aliases": [],
        "posts": [
          {
            "handle": "striga_ai",
            "followers": 537,
            "likes": 741,
            "createdAt": "2026-05-11",
            "url": "https://x.com/striga_ai/status/2053853079443784165",
            "github": [
              {
                "url": "https://github.com/striga-ai/CVE-2026-23918",
                "hasCode": true
              }
            ],
            "origin": false
          },
          {
            "handle": "yousukezan",
            "followers": 14098,
            "likes": 229,
            "createdAt": "2026-05-11",
            "url": "https://x.com/yousukezan/status/2053971866386395286",
            "github": [],
            "origin": false
          },
          {
            "handle": "lyrie_ai",
            "followers": 236,
            "likes": 0,
            "createdAt": "2026-06-04",
            "url": "https://x.com/lyrie_ai/status/2062482318581805168",
            "github": [],
            "origin": false
          }
        ]
      },
      "aliases": [],
      "researchers": [],
      "bsky": {
        "mentions": 20,
        "posts": [
          {
            "handle": "infosec.skyfleet.blue",
            "displayName": "InfoSec",
            "likes": 3,
            "reposts": 2,
            "replies": 0,
            "createdAt": "2026-05-05",
            "url": "https://bsky.app/profile/infosec.skyfleet.blue/post/3ml4pcbq5od2b",
            "origin": false,
            "authority": true,
            "github": []
          },
          {
            "handle": "intel.overresearched.net",
            "displayName": "OverResearched Intelligence",
            "likes": 2,
            "reposts": 1,
            "replies": 0,
            "createdAt": "2026-05-08",
            "url": "https://bsky.app/profile/intel.overresearched.net/post/3mleq2nofu22m",
            "origin": false,
            "authority": false,
            "github": []
          },
          {
            "handle": "ninjaowl.ai",
            "displayName": "Ninja Owl",
            "likes": 2,
            "reposts": 1,
            "replies": 0,
            "createdAt": "2026-05-06",
            "url": "https://bsky.app/profile/ninjaowl.ai/post/3ml6ojqdvsl2x",
            "origin": false,
            "authority": false,
            "github": []
          },
          {
            "handle": "securestep9.bsky.social",
            "displayName": "Sam Stepanyan",
            "likes": 1,
            "reposts": 2,
            "replies": 0,
            "createdAt": "2026-05-05",
            "url": "https://bsky.app/profile/securestep9.bsky.social/post/3ml45bb4yih24",
            "origin": false,
            "authority": false,
            "github": []
          },
          {
            "handle": "opsmatters.com",
            "displayName": "OpsMatters",
            "likes": 2,
            "reposts": 0,
            "replies": 0,
            "createdAt": "2026-05-12",
            "url": "https://bsky.app/profile/opsmatters.com/post/3mlmnk4hmwx2s",
            "origin": false,
            "authority": false,
            "github": []
          },
          {
            "handle": "hackersidekick.com",
            "displayName": "Hacker Sidekick - The Desktop Hacking Environment",
            "likes": 1,
            "reposts": 0,
            "replies": 1,
            "createdAt": "2026-05-09",
            "url": "https://bsky.app/profile/hackersidekick.com/post/3mlggimoujs2s",
            "origin": false,
            "authority": false,
            "github": []
          }
        ]
      },
      "telegram": {
        "mentions": 3,
        "reach": 11915,
        "posts": [
          {
            "channel": "thehackernews",
            "channelTitle": "The Hacker News",
            "tier": "news",
            "date": "2026-05-05",
            "views": 11103,
            "forwards": 52,
            "url": "https://t.me/thehackernews/8941",
            "text": "🚨 Apache patches CVE-2026-23918 (CVSS 8.8) in HTTP Server 2.4.66. The HTTP/2 double-free flaw can trigger DoS and potentially enable remote code execution via crafted requests. Fixed in 2.4.67. Details here: https://thehackernews.com/2026/05/critical-apache-http2-flaw-cve-2026.html",
            "github": [],
            "origin": false
          }
        ]
      }
    },
    {
      "cve": "CVE-2026-0300",
      "title": "A buffer overflow vulnerability in the User-ID™ Authentication Portal (aka Captive…",
      "category": "Recall",
      "vendor": null,
      "exploited": true,
      "publiclyDisclosed": true,
      "cvss": 9.8,
      "cvssVector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "severity": "CRITICAL",
      "impact": null,
      "products": [],
      "productCount": 0,
      "faq": "A buffer overflow vulnerability in the User-ID™ Authentication Portal (aka Captive Portal) service of Palo Alto Networks PAN-OS software allows an unauthenticated attacker to execute arbitrary code with root privileges on the PA-Series and VM-Series firewalls by sending specially crafted packets. \n\nThe risk of this issue is greatly reduced if you secure access to the User-ID™ Authentication Portal per the  best practice guidelines https://knowledgebase.paloaltonetworks.com/KCSArticleDetail  by restricting access to only trusted internal IP addresses.\n\nPrisma Access, Cloud NGFW and Panorama appliances are not impacted by this vulnerability.",
      "pocConfidence": "confirmed",
      "pocCount": 7,
      "pocTopStars": 20,
      "pocRepos": [
        {
          "url": "https://github.com/p3Nt3st3r-sTAr/CVE-2026-0300-POC",
          "stars": 20,
          "desc": "",
          "createdAt": "2026-05-06",
          "hasCode": true
        },
        {
          "url": "https://github.com/qassam-315/PAN-OS-User-ID-Buffer-Overflow-PoC",
          "stars": 3,
          "desc": "A research-grade Proof-of-Concept (PoC) for CVE-2026-0300, targeting the Buffer Overflow vulnerability in Palo Alto Networks PAN-OS User-ID™ Authentication Port",
          "createdAt": "2026-05-06",
          "hasCode": true
        },
        {
          "url": "https://github.com/mr-r3b00t/CVE-2026-0300",
          "stars": 1,
          "desc": "a honeypot for CVE-2026-0300",
          "createdAt": "2026-05-06",
          "hasCode": true
        },
        {
          "url": "https://github.com/bannned-bit/CVE-2026-0300-PANOS",
          "stars": 1,
          "desc": "Security Research and Proof-of-Concept (PoC) for CVE-2026-0300 : Unauthenticated Remote Code Execution (RCE) in Palo Alto Networks PAN-OS User-ID Portal.",
          "createdAt": "2026-05-06",
          "hasCode": true
        },
        {
          "url": "https://github.com/TailwindRG/cve-2026-0300-audit",
          "stars": 0,
          "desc": "Read-only audit tooling for CVE-2026-0300 (PAN-OS User-ID Authentication Portal exposure)",
          "createdAt": "2026-05-06",
          "hasCode": true
        },
        {
          "url": "https://github.com/shizuku198411/CVE-2026-0300",
          "stars": 0,
          "desc": "PAN-OS CVE-2026-0300 Non-Destructive Exposure Survey Tool",
          "createdAt": "2026-05-06",
          "hasCode": true
        }
      ],
      "epss": 0.32074,
      "epssPercentile": 0.98131,
      "source": "poc",
      "mitreUrl": "https://nvd.nist.gov/vuln/detail/CVE-2026-0300",
      "research": [
        {
          "url": "https://security.paloaltonetworks.com/CVE-2026-0300",
          "type": "writeup",
          "source": "Palo Alto advisory",
          "note": "Vendor advisory; exploited ITW (root RCE)"
        },
        {
          "url": "https://www.rapid7.com/blog/post/etr-critical-buffer-overflow-in-palo-alto-networks-pan-os-user-id-authentication-portal-cve-2026-0300/",
          "type": "writeup",
          "source": "Rapid7",
          "note": "Technical analysis"
        },
        {
          "url": "https://www.wiz.io/blog/critical-vulnerability-in-pan-os-exploited-in-the-wild-cve-2026-0300",
          "type": "writeup",
          "source": "Wiz",
          "note": "ITW exploitation"
        },
        {
          "url": "https://github.com/qassam-315/PAN-OS-User-ID-Buffer-Overflow-PoC",
          "type": "poc",
          "source": "GitHub qassam-315",
          "note": "Buffer overflow PoC (CWE-787)",
          "hasCode": true
        }
      ],
      "x": {
        "mentions": 8,
        "aliases": [
          "Captive Portal"
        ],
        "posts": [
          {
            "handle": "DarkWebInformer",
            "followers": 215646,
            "likes": 164,
            "createdAt": "2026-05-21",
            "url": "https://x.com/DarkWebInformer/status/2057494286376083734",
            "github": [
              {
                "url": "https://github.com/p3Nt3st3r-sTAr/CVE-2026-0300-POC",
                "hasCode": true
              }
            ],
            "origin": false
          },
          {
            "handle": "akaclandestine",
            "followers": 59775,
            "likes": 63,
            "createdAt": "2026-05-21",
            "url": "https://x.com/akaclandestine/status/2057569600649474316",
            "github": [
              {
                "url": "https://github.com/p3Nt3st3r-sTAr/CVE-2026-0300-POC",
                "hasCode": true
              }
            ],
            "origin": false
          },
          {
            "handle": "leonov_av",
            "followers": 1006,
            "likes": 1,
            "createdAt": "2026-06-06",
            "url": "https://x.com/leonov_av/status/2063299186297016714",
            "github": [],
            "origin": false
          },
          {
            "handle": "ptdbugs",
            "followers": 1246,
            "likes": 0,
            "createdAt": "2026-05-22",
            "url": "https://x.com/ptdbugs/status/2057725677822939178",
            "github": [],
            "origin": false
          },
          {
            "handle": "SecAlertsCo",
            "followers": 825,
            "likes": 0,
            "createdAt": "2026-05-19",
            "url": "https://x.com/SecAlertsCo/status/2056606742235275740",
            "github": [],
            "origin": false
          },
          {
            "handle": "iototsecnews",
            "followers": 491,
            "likes": 0,
            "createdAt": "2026-05-21",
            "url": "https://x.com/iototsecnews/status/2057264279062295000",
            "github": [],
            "origin": false
          },
          {
            "handle": "UhuUmair",
            "followers": 57,
            "likes": 0,
            "createdAt": "2026-06-02",
            "url": "https://x.com/UhuUmair/status/2061755829033091381",
            "github": [],
            "origin": false
          },
          {
            "handle": "XiaoYanLiu0103",
            "followers": 0,
            "likes": 0,
            "createdAt": "2026-05-26",
            "url": "https://x.com/XiaoYanLiu0103/status/2059277825136582859",
            "github": [],
            "origin": false
          }
        ]
      },
      "aliases": [
        "Captive Portal"
      ],
      "bsky": {
        "mentions": 31,
        "posts": [
          {
            "handle": "rayrobertson.uk",
            "displayName": "Ray Robertson",
            "likes": 1,
            "reposts": 0,
            "replies": 0,
            "createdAt": "2024-10-30",
            "url": "https://bsky.app/profile/rayrobertson.uk/post/3l7pud6n4522z",
            "origin": true,
            "authority": false,
            "github": [
              {
                "url": "https://github.com/abdulkader-alrezej/ipv6spot",
                "hasCode": true
              }
            ]
          },
          {
            "handle": "arduinolibs.bsky.social",
            "displayName": "Arduino Libraries",
            "likes": 0,
            "reposts": 0,
            "replies": 0,
            "createdAt": "2026-02-28",
            "url": "https://bsky.app/profile/arduinolibs.bsky.social/post/3mfx6c5uw4k22",
            "origin": true,
            "authority": false,
            "github": [
              {
                "url": "https://github.com/marinpopa/AsyncWiFiManagerSimple",
                "hasCode": true
              }
            ]
          },
          {
            "handle": "postac001.bsky.social",
            "displayName": "tec_acc",
            "likes": 2,
            "reposts": 0,
            "replies": 0,
            "createdAt": "2026-05-06",
            "url": "https://bsky.app/profile/postac001.bsky.social/post/3ml5z2krxco25",
            "origin": false,
            "authority": false,
            "github": []
          },
          {
            "handle": "theitnerd.ca",
            "displayName": "The IT Nerd",
            "likes": 1,
            "reposts": 0,
            "replies": 0,
            "createdAt": "2026-05-07",
            "url": "https://bsky.app/profile/theitnerd.ca/post/3mlbvkyfpw52l",
            "origin": false,
            "authority": false,
            "github": []
          },
          {
            "handle": "neroqc.bsky.social",
            "displayName": "Rene Robichaud",
            "likes": 0,
            "reposts": 1,
            "replies": 0,
            "createdAt": "2026-05-06",
            "url": "https://bsky.app/profile/neroqc.bsky.social/post/3ml6tpmxvsc2b",
            "origin": false,
            "authority": false,
            "github": []
          },
          {
            "handle": "rapid7.com",
            "displayName": "Rapid7",
            "likes": 0,
            "reposts": 1,
            "replies": 0,
            "createdAt": "2026-05-06",
            "url": "https://bsky.app/profile/rapid7.com/post/3ml6u5o2bec2a",
            "origin": false,
            "authority": false,
            "github": []
          }
        ]
      },
      "telegram": {
        "mentions": 13,
        "posts": [
          {
            "channel": "p3Nt3st3rsTAr",
            "channelTitle": "[CVE Pentester] exploits forum",
            "tier": "underground",
            "date": "2026-05-06",
            "views": 373,
            "forwards": 4,
            "url": "https://t.me/p3Nt3st3rsTAr/28",
            "text": "CVE-2026-0300",
            "github": [],
            "origin": true
          },
          {
            "channel": "hackgit",
            "channelTitle": "HackGit",
            "tier": "feed",
            "date": "2022-02-08",
            "views": 444,
            "forwards": 9,
            "url": "https://t.me/hackgit/3170",
            "text": "​c41n Automated Rogue Access Point setup tool. c41n provides automated setup of several types of Rogue Access Points, and Evil Twin attacks. c41n sets up an access point with user defined characteristics (interface, name and channel for the access point), sets up DHCP server for the access point, and provides user with abilities of HTTP traffic sniffing, or Captive Portal setup with credential sni",
            "github": [
              {
                "url": "https://github.com/MS-WEB-BN/c41n",
                "hasCode": true
              }
            ],
            "origin": true
          },
          {
            "channel": "hackgit",
            "channelTitle": "HackGit",
            "tier": "feed",
            "date": "2022-08-14",
            "views": 1085,
            "forwards": 6,
            "url": "https://t.me/hackgit/5470",
            "text": "​​QueenSono A Golang Package for Data Exfiltration with ICMP protocol. QueenSono tool only relies on the fact that ICMP protocol isn't monitored. It is quite common. It could also been used within a system with basic ICMP inspection (ie. frequency and content length watcher) or to bypass authentication step with captive portal (used by many public Wi-Fi to authenticate users after connecting to th",
            "github": [
              {
                "url": "https://github.com/ariary/QueenSono",
                "hasCode": true
              }
            ],
            "origin": true
          },
          {
            "channel": "news4hack",
            "channelTitle": "Pentester",
            "tier": "feed",
            "date": "2024-09-27",
            "views": 1026,
            "forwards": 6,
            "url": "https://t.me/news4hack/3012",
            "text": "How hackers can exploit Wi-Fi Captive Portals to distribute Android malware all from a smartphone using WifiPumpkin on NetHunter https://www.mobile-hacker.com/2024/09/27/wifipumpkin3-integrated-into-nethunter-powerful-duo-allows-malware-distribution-via-captive-portal/",
            "github": [],
            "origin": false
          },
          {
            "channel": "news4hack",
            "channelTitle": "Pentester",
            "tier": "feed",
            "date": "2022-07-19",
            "views": 887,
            "forwards": 6,
            "url": "https://t.me/news4hack/2508",
            "text": "🔥Intercepter-NG v1.2 for Windows🔥 * SSL MiTM rewritten (SNI support) * SSL Strip updated * X-Scan updated + Forced capturing on PPP interfaces ************ + Captive Portal test template - eXtreme mode, iOS killer - Heartbleed exploit - DHCP\\RAW Mode * WayBack Mode (restores hidden modes) * OUI db updated * Fixes, improvements, optimizations ************ Download here Youtube ************",
            "github": [],
            "origin": false
          },
          {
            "channel": "thehackernews",
            "channelTitle": "The Hacker News",
            "tier": "news",
            "date": "2026-05-06",
            "views": 9586,
            "forwards": 59,
            "url": "https://t.me/thehackernews/8942",
            "text": "🚨 PAN-OS firewalls hit by active exploitation of CVE-2026-0300, enabling unauthenticated RCE with root access. The unpatched flaw targets publicly exposed User-ID portals, affecting multiple versions. Fixes expected May 13, 2026. Read the full story: https://thehackernews.com/2026/05/palo-alto-pan-os-flaw-under-active.html",
            "github": [],
            "origin": false
          }
        ]
      },
      "researchers": []
    },
    {
      "cve": "CVE-2026-23744",
      "title": "MCPJam inspector is the local-first development platform for MCP servers. Versions…",
      "category": "Recall",
      "vendor": null,
      "exploited": false,
      "publiclyDisclosed": true,
      "cvss": 9.8,
      "cvssVector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "severity": "CRITICAL",
      "impact": null,
      "products": [],
      "productCount": 0,
      "faq": "MCPJam inspector is the local-first development platform for MCP servers. Versions 1.4.2 and earlier are vulnerable to remote code execution (RCE) vulnerability, which allows an attacker to send a crafted HTTP request that triggers the installation of an MCP server, leading to RCE. Since MCPJam inspector by default listens on 0.0.0.0 instead of 127.0.0.1, an attacker can trigger the RCE remotely via a simple HTTP request. Version 1.4.3 contains a patch.",
      "pocConfidence": "confirmed",
      "pocCount": 7,
      "pocTopStars": 9,
      "pocRepos": [
        {
          "url": "https://github.com/ibreakthingsforaliving/CVE-2026-23744-PoC",
          "stars": 9,
          "desc": "CVE-2026-23744 - Versions 1.4.2 and earlier of MCPJam inspector are vulnerable to remote code execution (RCE). Because the tool listens on 0.0.0.0 by default, a",
          "createdAt": "2026-01-20",
          "hasCode": true
        },
        {
          "url": "https://github.com/thisisish/HTB-DevHub",
          "stars": 1,
          "desc": "CVE-2026-23744 RCE + Privilege Escalation",
          "createdAt": "2026-05-31",
          "hasCode": true
        },
        {
          "url": "https://github.com/SrGinebras/CVE-2026-23744-RCE-for-MCPjam-inspector-v1.4.2",
          "stars": 1,
          "desc": "",
          "createdAt": "2026-05-31",
          "hasCode": true
        },
        {
          "url": "https://github.com/alisster00/CVE-2026-23744-RCE",
          "stars": 1,
          "desc": "This utility was created during research involving MCPJam v1.4.2. The application exposes an API endpoint that accepts a server configuration object. Under cert",
          "createdAt": "2026-06-02",
          "hasCode": true
        },
        {
          "url": "https://github.com/sbouabid-sec/CVE-2026-23744-POC",
          "stars": 0,
          "desc": "CVE-2026-23744 — Proof of concept exploit for an unauthenticated Remote Code Execution vulnerability in MCPJam Inspector <= 1.4.2.",
          "createdAt": "2026-05-31",
          "hasCode": true
        },
        {
          "url": "https://github.com/Least-Significant-Bit/CVE-2026-23744",
          "stars": 0,
          "desc": "Remote Code Execution in MCPJam 1.4.2 and older.",
          "createdAt": "2026-05-31",
          "hasCode": true
        }
      ],
      "epss": 0.43671,
      "epssPercentile": 0.98607,
      "source": "poc",
      "mitreUrl": "https://nvd.nist.gov/vuln/detail/CVE-2026-23744",
      "research": [
        {
          "url": "https://github.com/advisories/GHSA-232v-j27c-5pp6",
          "type": "writeup",
          "source": "GitHub Advisory",
          "note": "RCE via exposed HTTP endpoint, binds 0.0.0.0",
          "hasCode": null
        },
        {
          "url": "https://github.com/boroeurnprach/CVE-2026-23744-PoC",
          "type": "poc",
          "source": "boroeurnprach",
          "note": "Unauth RCE via crafted HTTP request to MCP connect",
          "hasCode": true
        },
        {
          "url": "https://www.crowdsec.net/vulntracking-report/cve-2026-23744",
          "type": "writeup",
          "source": "CrowdSec",
          "note": "Critical RCE targeting developers"
        },
        {
          "url": "https://pentest-tools.com/vulnerabilities-exploits/mcpjam-inspector-remote-code-execution_28808",
          "type": "writeup",
          "source": "Pentest-Tools",
          "note": "RCE exploit DB entry"
        }
      ],
      "x": {
        "mentions": 1,
        "aliases": [],
        "posts": [
          {
            "handle": "RicardGardella",
            "followers": 314,
            "likes": 0,
            "createdAt": "2026-06-07",
            "url": "https://x.com/RicardGardella/status/2063664840007209074",
            "github": [],
            "origin": false
          }
        ]
      },
      "bsky": {
        "mentions": 7,
        "posts": [
          {
            "handle": "crowdsec.bsky.social",
            "displayName": "CrowdSec",
            "likes": 0,
            "reposts": 0,
            "replies": 0,
            "createdAt": "2026-03-16",
            "url": "https://bsky.app/profile/crowdsec.bsky.social/post/3mh6fovjmns22",
            "origin": false,
            "authority": false,
            "github": []
          },
          {
            "handle": "beikokucyber.bsky.social",
            "displayName": "Beikoku Cybersecurity",
            "likes": 0,
            "reposts": 0,
            "replies": 0,
            "createdAt": "2026-02-24",
            "url": "https://bsky.app/profile/beikokucyber.bsky.social/post/3mfn2uadnmz2j",
            "origin": false,
            "authority": false,
            "github": []
          },
          {
            "handle": "thehackerwire.bsky.social",
            "displayName": "TheHackerWire",
            "likes": 0,
            "reposts": 0,
            "replies": 0,
            "createdAt": "2026-01-16",
            "url": "https://bsky.app/profile/thehackerwire.bsky.social/post/3mckxoqvf4c2z",
            "origin": false,
            "authority": false,
            "github": []
          },
          {
            "handle": "cve.skyfleet.blue",
            "displayName": "CVE Alerts ",
            "likes": 0,
            "reposts": 0,
            "replies": 0,
            "createdAt": "2026-01-16",
            "url": "https://bsky.app/profile/cve.skyfleet.blue/post/3mclbafogn52r",
            "origin": false,
            "authority": false,
            "github": []
          }
        ]
      },
      "telegram": {
        "mentions": 0,
        "posts": []
      },
      "aliases": [],
      "researchers": []
    },
    {
      "cve": "CVE-2026-8181",
      "title": "The Burst Statistics – Privacy-Friendly WordPress Analytics (Google Analytics…",
      "category": "Recall",
      "vendor": null,
      "exploited": false,
      "publiclyDisclosed": true,
      "cvss": 9.8,
      "cvssVector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "severity": "CRITICAL",
      "impact": null,
      "products": [],
      "productCount": 0,
      "faq": "The Burst Statistics – Privacy-Friendly WordPress Analytics (Google Analytics Alternative) plugin for WordPress is vulnerable to Authentication Bypass in versions 3.4.0 to 3.4.1.1. This is due to incorrect return-value handling in the `is_mainwp_authenticated()` function when validating application passwords from the Authorization header. This makes it possible for unauthenticated attackers, with knowledge of an administrator username, to impersonate that administrator for the duration of the request by supplying any random Basic Authentication password achieving privilege escalation.",
      "pocConfidence": "confirmed",
      "pocCount": 7,
      "pocTopStars": 5,
      "pocRepos": [
        {
          "url": "https://github.com/zycoder0day/CVE-2026-8181",
          "stars": 5,
          "desc": "CVE-2026-8181 - Burst Statistics 3.4.0-3.4.1.1 Unauthenticated Authentication Bypass to Admin Account Takeover | Proof of Concept",
          "createdAt": "2026-05-14",
          "hasCode": true
        },
        {
          "url": "https://github.com/murrez/CVE-2026-8181",
          "stars": 2,
          "desc": "CVE-2026-8181 PoC: Burst Statistics (3.4.0–3.4.1.1) authentication bypass. Python tool — single & multi-target scans, threaded workers, TXT reports. Authorized ",
          "createdAt": "2026-05-15",
          "hasCode": true
        },
        {
          "url": "https://github.com/Jenderal92/CVE-2026-8181",
          "stars": 0,
          "desc": "CVE-2026-8181: Burst Statistics Auth Bypass → REST API takeover & admin creation. Python 2.7. Educational use only.",
          "createdAt": "2026-05-16",
          "hasCode": true
        },
        {
          "url": "https://github.com/whattheslime/CVE-2026-8181",
          "stars": 0,
          "desc": "Exploit for the CVE-2026-8181 - Burst Statistics WordPress Plugin Authentication Bypass",
          "createdAt": "2026-05-16",
          "hasCode": true
        },
        {
          "url": "https://github.com/xShadow-Here/CVE-2026-8181",
          "stars": 0,
          "desc": "CVE-2026-8181 | Burst Statistics 3.4.0 - 3.4.1.1 - Authentication Bypass to Admin Account Takeover",
          "createdAt": "2026-05-17",
          "hasCode": true
        },
        {
          "url": "https://github.com/x48ps/CVE-2026-8181",
          "stars": 0,
          "desc": "This vulnerability allows unauthenticated attackers who know a valid administrator username to impersonate that admin during REST API requests by using any inco",
          "createdAt": "2026-05-22",
          "hasCode": true
        }
      ],
      "epss": 0.14608,
      "epssPercentile": 0.96273,
      "source": "poc",
      "mitreUrl": "https://nvd.nist.gov/vuln/detail/CVE-2026-8181",
      "research": [
        {
          "url": "https://www.bleepingcomputer.com/news/security/hackers-exploit-auth-bypass-flaw-in-burst-statistics-wordpress-plugin/",
          "type": "writeup",
          "source": "BleepingComputer",
          "note": "Active mass exploitation, admin account creation"
        },
        {
          "url": "https://www.rapid7.com/db/vulnerabilities/burst-statistics-plugin-cve-2026-8181/",
          "type": "writeup",
          "source": "Rapid7",
          "note": "Vuln DB entry, auth bypass detail"
        },
        {
          "url": "https://github.com/advisories/GHSA-qv3x-rrx4-9pmh",
          "type": "writeup",
          "source": "GitHub Advisory",
          "note": "is_mainwp_authenticated return-value flaw",
          "hasCode": null
        },
        {
          "url": "https://www.tenable.com/cve/CVE-2026-8181",
          "type": "writeup",
          "source": "Tenable",
          "note": "CVE record, CVSS 9.5 auth bypass"
        }
      ],
      "x": {
        "mentions": 1,
        "aliases": [],
        "posts": [
          {
            "handle": "DFIR_Radar",
            "followers": 1569,
            "likes": 1,
            "createdAt": "2026-06-02",
            "url": "https://x.com/DFIR_Radar/status/2061871182467514521",
            "github": [],
            "origin": false
          }
        ]
      },
      "bsky": {
        "mentions": 13,
        "posts": [
          {
            "handle": "donwebmedia.bsky.social",
            "displayName": null,
            "likes": 1,
            "reposts": 0,
            "replies": 0,
            "createdAt": "2026-06-03",
            "url": "https://bsky.app/profile/donwebmedia.bsky.social/post/3mnehdbgaeh2a",
            "origin": false,
            "authority": false,
            "github": []
          },
          {
            "handle": "clankussy.abu.guru",
            "displayName": "Clankussy",
            "likes": 1,
            "reposts": 0,
            "replies": 0,
            "createdAt": "2026-05-16",
            "url": "https://bsky.app/profile/clankussy.abu.guru/post/3mlwxlthp7i2h",
            "origin": false,
            "authority": false,
            "github": []
          },
          {
            "handle": "intel.overresearched.net",
            "displayName": "OverResearched Intelligence",
            "likes": 1,
            "reposts": 0,
            "replies": 0,
            "createdAt": "2026-05-15",
            "url": "https://bsky.app/profile/intel.overresearched.net/post/3mlwebtqzms2g",
            "origin": false,
            "authority": false,
            "github": []
          },
          {
            "handle": "ebibibibibibi.bsky.social",
            "displayName": "胡田@Microsoft MVP(2014~)&MCT / Masahiko Ebisuda",
            "likes": 1,
            "reposts": 0,
            "replies": 0,
            "createdAt": "2026-05-15",
            "url": "https://bsky.app/profile/ebibibibibibi.bsky.social/post/3mlvaczqmbg2p",
            "origin": false,
            "authority": false,
            "github": []
          },
          {
            "handle": "undercodenews.bsky.social",
            "displayName": "Undercode News",
            "likes": 1,
            "reposts": 0,
            "replies": 0,
            "createdAt": "2026-05-15",
            "url": "https://bsky.app/profile/undercodenews.bsky.social/post/3mlubjuafww23",
            "origin": false,
            "authority": false,
            "github": []
          },
          {
            "handle": "crowdsec.bsky.social",
            "displayName": "CrowdSec",
            "likes": 0,
            "reposts": 0,
            "replies": 0,
            "createdAt": "2026-06-08",
            "url": "https://bsky.app/profile/crowdsec.bsky.social/post/3mnrkpsxijs2b",
            "origin": false,
            "authority": false,
            "github": []
          }
        ]
      },
      "telegram": {
        "mentions": 1,
        "posts": [
          {
            "channel": "p3Nt3st3rsTAr",
            "channelTitle": "[CVE Pentester] exploits forum",
            "tier": "underground",
            "date": "2026-05-14",
            "views": 496,
            "forwards": 0,
            "url": "https://t.me/p3Nt3st3rsTAr/37",
            "text": "https://github.com/p3Nt3st3r-sTAr/CVE-2026-8181",
            "github": [
              {
                "url": "https://github.com/p3Nt3st3r-sTAr/CVE-2026-8181",
                "hasCode": true
              }
            ],
            "origin": true
          }
        ]
      },
      "aliases": [],
      "researchers": []
    },
    {
      "cve": "CVE-2026-0257",
      "title": "Authentication bypass vulnerabilities in the GlobalProtect portal and gateway of Palo…",
      "category": "Recall",
      "vendor": null,
      "exploited": true,
      "publiclyDisclosed": true,
      "cvss": 9.1,
      "cvssVector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N",
      "severity": "CRITICAL",
      "impact": null,
      "products": [],
      "productCount": 0,
      "faq": "Authentication bypass vulnerabilities in the GlobalProtect portal and gateway of Palo Alto Networks PAN-OS® software allows the attacker to bypass security restrictions and establish an unauthorized VPN connection.\n\nPanorama and Cloud NGFW are not impacted by these issues.",
      "pocConfidence": "confirmed",
      "pocCount": 6,
      "pocTopStars": 24,
      "pocRepos": [
        {
          "url": "https://github.com/sfewer-r7/CVE-2026-0257",
          "stars": 24,
          "desc": "Proof-of-concept script to leverage the PAN-OS GlobalProtect authentication bypass CVE-2026-0257",
          "createdAt": "2026-05-29",
          "hasCode": true
        },
        {
          "url": "https://github.com/0xBlackash/CVE-2026-0257",
          "stars": 3,
          "desc": "CVE-2026-0257",
          "createdAt": "2026-05-30",
          "hasCode": true
        },
        {
          "url": "https://github.com/tushargurav28/CVE-2026-0257",
          "stars": 3,
          "desc": "Palo Alto Networks PAN-OS contains an authentication bypass caused by flaws in the GlobalProtect portal and gateway, letting attackers establish unauthorized VP",
          "createdAt": "2026-06-03",
          "hasCode": true
        },
        {
          "url": "https://github.com/akashsingh0454/CVE-2026-0257-PoC",
          "stars": 2,
          "desc": "",
          "createdAt": "2026-05-29",
          "hasCode": true
        },
        {
          "url": "https://github.com/grayxploit/CVE-2026-0257",
          "stars": 1,
          "desc": "GrayXploit Security research and defensive team validate this toolkit for CVE-2026-0257 (PAN-OS GlobalProtect Authentication Bypass). Includes vulnerability ass",
          "createdAt": "2026-06-10",
          "hasCode": true
        },
        {
          "url": "https://github.com/HORKimhab/CVE-2026-0257",
          "stars": 0,
          "desc": "CVE-2026-0257 - PAN-OS",
          "createdAt": "2026-05-30",
          "hasCode": true
        }
      ],
      "epss": 0.86678,
      "epssPercentile": 0.99722,
      "source": "poc",
      "mitreUrl": "https://nvd.nist.gov/vuln/detail/CVE-2026-0257",
      "telegram": {
        "mentions": 11,
        "posts": [
          {
            "channel": "p3Nt3st3rsTAr",
            "channelTitle": "[CVE Pentester] exploits forum",
            "tier": "underground",
            "date": "2026-06-06",
            "views": 236,
            "forwards": 0,
            "url": "https://t.me/p3Nt3st3rsTAr/44",
            "text": "https://github.com/p3Nt3st3r-sTAr/CVE-2026-0257",
            "github": [
              {
                "url": "https://github.com/p3Nt3st3r-sTAr/CVE-2026-0257",
                "hasCode": true
              }
            ],
            "origin": true
          },
          {
            "channel": "thehackernews",
            "channelTitle": "The Hacker News",
            "tier": "news",
            "date": "2026-06-15",
            "views": 8824,
            "forwards": 46,
            "url": "https://t.me/thehackernews/9236",
            "text": "🚨 Hackers found a way into Palo Alto’s GlobalProtect VPN without a password. The flaw, tracked as CVE-2026-0257, lets attackers bypass PAN-OS authentication and establish unauthorized VPN sessions. Palo Alto says it’s already being used in real attacks. If you run GlobalProtect, check this now. Details ➝ https://thehackernews.com/2026/06/palo-alto-warns-of-active-exploitation.html",
            "github": [],
            "origin": false
          }
        ]
      },
      "research": [],
      "aliases": [],
      "researchers": [],
      "x": {
        "mentions": 0,
        "aliases": [],
        "posts": []
      },
      "bsky": {
        "mentions": 25,
        "posts": [
          {
            "handle": "infosec.skyfleet.blue",
            "displayName": "InfoSec",
            "likes": 0,
            "reposts": 0,
            "replies": 0,
            "createdAt": "2026-05-30",
            "url": "https://bsky.app/profile/infosec.skyfleet.blue/post/3mn3jsqgx6q22",
            "origin": false,
            "authority": true,
            "github": []
          },
          {
            "handle": "captechgroup.com",
            "displayName": "Capstone Technologies Group",
            "likes": 2,
            "reposts": 1,
            "replies": 0,
            "createdAt": "2026-05-29",
            "url": "https://bsky.app/profile/captechgroup.com/post/3mmz56jwbob2k",
            "origin": false,
            "authority": false,
            "github": []
          },
          {
            "handle": "hendryadrian.bsky.social",
            "displayName": "Cybersecurity News Everyday",
            "likes": 1,
            "reposts": 0,
            "replies": 1,
            "createdAt": "2026-05-30",
            "url": "https://bsky.app/profile/hendryadrian.bsky.social/post/3mn2xzod22y2o",
            "origin": false,
            "authority": false,
            "github": []
          },
          {
            "handle": "getpokemon7.bsky.social",
            "displayName": "まりーん",
            "likes": 0,
            "reposts": 0,
            "replies": 1,
            "createdAt": "2026-06-24",
            "url": "https://bsky.app/profile/getpokemon7.bsky.social/post/3mozx4zp4pc2l",
            "origin": false,
            "authority": false,
            "github": []
          },
          {
            "handle": "patchdayalert.com",
            "displayName": null,
            "likes": 0,
            "reposts": 0,
            "replies": 1,
            "createdAt": "2026-06-11",
            "url": "https://bsky.app/profile/patchdayalert.com/post/3mnya22iihm2o",
            "origin": false,
            "authority": false,
            "github": []
          },
          {
            "handle": "samilaiho.com",
            "displayName": "Sami Laiho",
            "likes": 1,
            "reposts": 0,
            "replies": 0,
            "createdAt": "2026-05-31",
            "url": "https://bsky.app/profile/samilaiho.com/post/3mn5nv5rcoc26",
            "origin": false,
            "authority": false,
            "github": []
          }
        ]
      }
    },
    {
      "cve": "CVE-2026-9082",
      "title": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')…",
      "category": "Recall",
      "vendor": null,
      "exploited": true,
      "publiclyDisclosed": true,
      "cvss": 9.8,
      "cvssVector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "severity": "CRITICAL",
      "impact": null,
      "products": [],
      "productCount": 0,
      "faq": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Drupal Drupal core allows SQL Injection.\n\nThis issue affects Drupal core: from 8.9.0 before 10.4.10, from 10.5.0 before 10.5.10, from 10.6.0 before 10.6.9, from 11.0.0 before 11.1.10, from 11.2.0 before 11.2.12, from 11.3.0 before 11.3.10.",
      "pocConfidence": "confirmed",
      "pocCount": 6,
      "pocTopStars": 18,
      "pocRepos": [
        {
          "url": "https://github.com/7h30th3r0n3/CVE-2026-9082-Drupal-PoC",
          "stars": 18,
          "desc": "Drupal Core PostgreSQL SQL Injection PoC - CVE-2026-9082. Ethical PoC for the Drupal vulnerability allowing anonymous SQL injection through the JSON:API module ",
          "createdAt": "2026-05-21",
          "hasCode": true
        },
        {
          "url": "https://github.com/ambionics/cve-2026-9082-drupal-postgresql-rce",
          "stars": 10,
          "desc": "",
          "createdAt": "2026-05-26",
          "hasCode": true
        },
        {
          "url": "https://github.com/HORKimhab/CVE-2026-9082",
          "stars": 2,
          "desc": "CVE-2026-9082 | SA-CORE-2026-004",
          "createdAt": "2026-05-21",
          "hasCode": true
        },
        {
          "url": "https://github.com/0xBlackash/CVE-2026-9082",
          "stars": 1,
          "desc": "CVE-2026-9082",
          "createdAt": "2026-05-21",
          "hasCode": true
        },
        {
          "url": "https://github.com/ywh-jfellus/CVE-2026-9082",
          "stars": 1,
          "desc": "PoC for CVE-2026-9082 (Drupal SA-CORE-2026-004) Drupal Core SQLi",
          "createdAt": "2026-05-21",
          "hasCode": true
        },
        {
          "url": "https://github.com/11romain/CVE-2026-9082",
          "stars": 0,
          "desc": "Drupal Core PostgreSQL SQLi to RCE via /user/login (CVE-2026-9082 / SA-CORE-2026-004)",
          "createdAt": "2026-06-07",
          "hasCode": true
        }
      ],
      "epss": 0.84631,
      "epssPercentile": 0.9968,
      "source": "poc",
      "mitreUrl": "https://nvd.nist.gov/vuln/detail/CVE-2026-9082",
      "research": [],
      "aliases": [],
      "researchers": [],
      "x": {
        "mentions": 0,
        "aliases": [],
        "posts": []
      },
      "bsky": {
        "mentions": 25,
        "posts": [
          {
            "handle": "bearstech.com",
            "displayName": "Bearstech",
            "likes": 2,
            "reposts": 3,
            "replies": 0,
            "createdAt": "2026-05-22",
            "url": "https://bsky.app/profile/bearstech.com/post/3mmgydql4dk2p",
            "origin": false,
            "authority": false,
            "github": []
          },
          {
            "handle": "getpokemon7.bsky.social",
            "displayName": "まりーん",
            "likes": 2,
            "reposts": 0,
            "replies": 1,
            "createdAt": "2026-06-20",
            "url": "https://bsky.app/profile/getpokemon7.bsky.social/post/3moqrc64j7k25",
            "origin": false,
            "authority": false,
            "github": []
          },
          {
            "handle": "opsmatters.com",
            "displayName": "OpsMatters",
            "likes": 1,
            "reposts": 0,
            "replies": 1,
            "createdAt": "2026-06-04",
            "url": "https://bsky.app/profile/opsmatters.com/post/3mnggiasjff2u",
            "origin": false,
            "authority": false,
            "github": []
          },
          {
            "handle": "mynameisv.bsky.social",
            "displayName": "Mynameisv",
            "likes": 2,
            "reposts": 0,
            "replies": 0,
            "createdAt": "2026-05-28",
            "url": "https://bsky.app/profile/mynameisv.bsky.social/post/3mmwehebzgc27",
            "origin": false,
            "authority": false,
            "github": []
          },
          {
            "handle": "flingjore.com",
            "displayName": "Flingjore",
            "likes": 2,
            "reposts": 0,
            "replies": 0,
            "createdAt": "2026-05-26",
            "url": "https://bsky.app/profile/flingjore.com/post/3mmrnjjpdpt26",
            "origin": false,
            "authority": false,
            "github": []
          },
          {
            "handle": "happeningnow.news",
            "displayName": "HappeningNow",
            "likes": 2,
            "reposts": 0,
            "replies": 0,
            "createdAt": "2026-05-23",
            "url": "https://bsky.app/profile/happeningnow.news/post/3mmijaiu37f2e",
            "origin": false,
            "authority": false,
            "github": []
          }
        ]
      },
      "telegram": {
        "mentions": 6,
        "posts": [
          {
            "channel": "thehackernews",
            "channelTitle": "The Hacker News",
            "tier": "news",
            "date": "2026-05-23",
            "views": 9362,
            "forwards": 28,
            "url": "https://t.me/thehackernews/9066",
            "text": "🚨 Drupal Core SQL injection is now actively exploited. https://thehackernews.com/2026/05/drupal-core-sql-injection-bug-actively.html CISA added CVE-2026-9082 to its KEV catalog after exploitation was detected in the wild. Imperva observed: • 15,000+ attack attempts • Nearly 6,000 targeted sites • Activity across 65 countries • Gaming and financial services sites hit hardest, at nearly 50% of attac",
            "github": [],
            "origin": false
          }
        ]
      }
    },
    {
      "cve": "CVE-2026-43503",
      "title": "In the Linux kernel, the following vulnerability has been resolved: net: skbuff:…",
      "category": "Recall",
      "vendor": null,
      "exploited": false,
      "publiclyDisclosed": true,
      "cvss": 8.8,
      "cvssVector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H",
      "severity": "HIGH",
      "impact": null,
      "products": [],
      "productCount": 0,
      "faq": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: skbuff: propagate shared-frag marker through frag-transfer helpers\n\nTwo frag-transfer helpers (__pskb_copy_fclone() and skb_shift()) fail\nto propagate the SKBFL_SHARED_FRAG bit in skb_shinfo()->flags when\nmoving frags from source to destination.  __pskb_copy_fclone() defers\nthe rest of the shinfo metadata to skb_copy_header() after copying\nfrag descriptors, but that helper only carries over gso_{size,segs,\ntype} and never touches skb_shinfo()->flags; skb_shift() moves frag\ndescriptors directly and leaves flags untouched.  As a result, the\ndestination skb keeps a reference to the same externally-owned or\npage-cache-backed pages while reporting skb_has_shared_frag() as\nfalse.\n\nThe mismatch is harmful in any in-place writer that uses\nskb_has_shared_frag() to decide whether shared pages must be detoured\nthrough skb_cow_data().  ESP input is one such writer (esp4.c,\nesp6.c), and a single nft 'dup to <local>' rule -- or any other\nnf_dup_ipv4() / xt_TEE caller -- is enough to land a pskb_copy()'d\nskb in esp_input() with the marker stripped, letting an unprivileged\nuser write into the page cache of a root-owned read-only file via\nauthencesn-ESN stray writes.\n\nSet SKBFL_SHARED_FRAG on the destination whenever frag descriptors\nwere actually moved from the source.  skb_copy() and skb_copy_expand()\nshare skb_copy_header() too but linearize all paged data into freshly\nallocated head storage and emerge with nr_frags == 0, so\nskb_has_shared_frag() returns false on its own; they need no change.\n\nThe same omission exists in skb_gro_receive() and skb_gro_receive_list().\nThe former moves the incoming skb's frag descriptors into the\naccumulator's last sub-skb via two paths (a direct frag-move loop and\nthe head_frag + memcpy path); the latter chains the incoming skb whole\nonto p's frag_list.  Downstream skb_segment() reads only\nskb_shinfo(p)->flags, and skb_segment_list() reuses each sub-skb's\nshinfo as the nskb -- both p and lp must carry the marker.\n\nThe same omission also exists in tcp_clone_payload(), which builds an\nMTU probe skb by moving frag descriptors from skbs on sk_write_queue\ninto a freshly allocated nskb.  The helper falls into the same family\nand warrants the same fix for consistency; no TCP TX-side in-place\nwriter is currently known to reach a user page through this gap, but\na future consumer depending on the marker would regress silently.\n\nThe same omission exists in skb_segment(): the per-iteration flag\nmerge takes only head_skb's flag, and the inner switch that rebinds\nfrag_skb to list_skb on head_skb-frags exhaustion does not fold the\nnew frag_skb's flag into nskb.  Fold frag_skb's flag at both sites\nso segments drawing frags from frag_list members carry the marker.",
      "pocConfidence": "confirmed",
      "pocCount": 6,
      "pocTopStars": 14,
      "pocRepos": [
        {
          "url": "https://github.com/0xBlackash/CVE-2026-43503",
          "stars": 14,
          "desc": "CVE-2026-43503",
          "createdAt": "2026-06-25",
          "hasCode": true
        },
        {
          "url": "https://github.com/mooder1/dirtyclone-CVE-2026-43503",
          "stars": 12,
          "desc": "",
          "createdAt": "2026-06-26",
          "hasCode": true
        },
        {
          "url": "https://github.com/entra1337/DirtyClone",
          "stars": 10,
          "desc": "Python Proof of Concept for DirtyClone (CVE-2026-43503) - Linux kernel LPE via page-cache corruption",
          "createdAt": "2026-06-29",
          "hasCode": true
        },
        {
          "url": "https://github.com/aexdyhaxor/CVE-2026-43503-DirtyClone",
          "stars": 2,
          "desc": "",
          "createdAt": "2026-06-26",
          "hasCode": true
        },
        {
          "url": "https://github.com/gl1tch0x1/DirtyClone",
          "stars": 1,
          "desc": "DirtyClone - local privilege escalation (LPE) proof-of-concept targeting a kernel/XFRM-related vulnerability described in the source as CVE-2026-43503",
          "createdAt": "2026-06-28",
          "hasCode": true
        },
        {
          "url": "https://github.com/SecureWithUmer/CVE-2026-43503",
          "stars": 0,
          "desc": "DirtyClone - local privilege escalation (LPE) proof-of-concept targeting a kernel/XFRM-related vulnerability described in the source as CVE-2026-43503",
          "createdAt": "2026-06-29",
          "hasCode": true
        }
      ],
      "epss": 0.00135,
      "epssPercentile": 0.03353,
      "source": "poc",
      "mitreUrl": "https://nvd.nist.gov/vuln/detail/CVE-2026-43503",
      "research": [],
      "aliases": [],
      "researchers": [],
      "x": {
        "mentions": 4,
        "aliases": [],
        "posts": [
          {
            "handle": "pedri77",
            "followers": 2075,
            "likes": 0,
            "createdAt": "2026-07-07",
            "url": "https://x.com/pedri77/status/2074367406563078246",
            "github": [],
            "origin": false
          }
        ]
      },
      "bsky": {
        "mentions": 15,
        "posts": [
          {
            "handle": "secdb.bsky.social",
            "displayName": "ZEN SecDB",
            "likes": 2,
            "reposts": 0,
            "replies": 0,
            "createdAt": "2026-06-30",
            "url": "https://bsky.app/profile/secdb.bsky.social/post/3mpiqk5i6ek2w",
            "origin": false,
            "authority": true,
            "github": []
          },
          {
            "handle": "infosec.skyfleet.blue",
            "displayName": "InfoSec",
            "likes": 1,
            "reposts": 0,
            "replies": 0,
            "createdAt": "2026-07-02",
            "url": "https://bsky.app/profile/infosec.skyfleet.blue/post/3mpp5adpess2c",
            "origin": false,
            "authority": true,
            "github": []
          },
          {
            "handle": "toxy4ny.bsky.social",
            "displayName": "KL3FT3Z",
            "likes": 4,
            "reposts": 0,
            "replies": 1,
            "createdAt": "2026-07-02",
            "url": "https://bsky.app/profile/toxy4ny.bsky.social/post/3mpopk2xkvc25",
            "origin": false,
            "authority": false,
            "github": [
              {
                "url": "https://github.com/entra1337/DirtyClone",
                "hasCode": true
              }
            ]
          },
          {
            "handle": "linuxiac.bsky.social",
            "displayName": "Linuxiac",
            "likes": 7,
            "reposts": 1,
            "replies": 0,
            "createdAt": "2026-07-01",
            "url": "https://bsky.app/profile/linuxiac.bsky.social/post/3mpl6js6cys2f",
            "origin": false,
            "authority": false,
            "github": []
          },
          {
            "handle": "sergioiker.bsky.social",
            "displayName": "Dr.Sergio E. Sanchez… Dr. Qubit",
            "likes": 1,
            "reposts": 0,
            "replies": 1,
            "createdAt": "2026-06-30",
            "url": "https://bsky.app/profile/sergioiker.bsky.social/post/3mpjbjmgkfk2e",
            "origin": false,
            "authority": false,
            "github": []
          },
          {
            "handle": "it-connect.bsky.social",
            "displayName": "IT-Connect",
            "likes": 2,
            "reposts": 0,
            "replies": 0,
            "createdAt": "2026-06-29",
            "url": "https://bsky.app/profile/it-connect.bsky.social/post/3mpfwglembr2j",
            "origin": false,
            "authority": false,
            "github": []
          }
        ]
      },
      "telegram": {
        "mentions": 1,
        "reach": 7602,
        "posts": [
          {
            "channel": "thehackernews",
            "channelTitle": "The Hacker News",
            "tier": "news",
            "date": "2026-06-26",
            "views": 7535,
            "forwards": 67,
            "url": "https://t.me/thehackernews/9339",
            "text": "🛑 A new #Linux kernel flaw lets a local user rewrite /usr/bin/su in memory and gain #root. The file on disk never changes. No audit trail. DirtyClone (CVE-2026-43503) is the fourth bug with this failure mode in two months. Details and what to do ↓ https://thehackernews.com/2026/06/new-dirtyclone-linux-kernel-flaw-lets.html",
            "github": [],
            "origin": false
          }
        ]
      }
    },
    {
      "cve": "CVE-2026-24061",
      "title": "telnetd in GNU Inetutils through 2.7 allows remote authentication bypass via a \"-f…",
      "category": "Recall",
      "vendor": null,
      "exploited": true,
      "publiclyDisclosed": true,
      "cvss": 9.8,
      "cvssVector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "severity": "CRITICAL",
      "impact": null,
      "products": [],
      "productCount": 0,
      "faq": "telnetd in GNU Inetutils through 2.7 allows remote authentication bypass via a \"-f root\" value for the USER environment variable.",
      "pocConfidence": "confirmed",
      "pocCount": 5,
      "pocTopStars": 202,
      "pocRepos": [
        {
          "url": "https://github.com/jacubes/CVE-2026-24061",
          "stars": 202,
          "desc": "CVE-2026-24061 exploit PoC",
          "createdAt": "2026-03-08",
          "hasCode": true
        },
        {
          "url": "https://github.com/tc4dy/CVE-2026-24061-PoC-Exploit",
          "stars": 1,
          "desc": "🚀 CVE-2026-24061 - GNU inetutils-telnetd Auth Bypass Exploit - Full Control 💥 CRLF injection via NEW_ENVIRON leads to auth bypass & instant root shell. ✅ Sing",
          "createdAt": "2026-06-06",
          "hasCode": true
        },
        {
          "url": "https://github.com/K3ysTr0K3R/CVE-2026-24061",
          "stars": 1,
          "desc": "A PoC exploit for CVE-2026-24061 - GNU InetUtils telnetd Argument Injection Authentication Bypass",
          "createdAt": "2026-06-08",
          "hasCode": true
        },
        {
          "url": "https://github.com/obrunolima1910/CVE-2026-24061",
          "stars": 0,
          "desc": "🚨 Exploit CVE-2026-24061, a critical remote authentication bypass in GNU inetutils-telnetd, for instant root shell access without authentication.",
          "createdAt": "2026-02-03",
          "hasCode": true
        },
        {
          "url": "https://github.com/athack-ctf/chall2026-telneted",
          "stars": 0,
          "desc": "[AtHack 2026] Pwn challenge about telnetd CVE-2026-24061",
          "createdAt": "2026-02-15",
          "hasCode": true
        },
        {
          "url": "https://github.com/achnouri/CVE-2026-24061-GNU-InetUtils-telnetd",
          "stars": 0,
          "desc": "GNU-InetUtils-telnetd-Authentication-Bypass-Vulnerability",
          "createdAt": "2026-06-08",
          "hasCode": false
        }
      ],
      "epss": 0.98871,
      "epssPercentile": 0.99923,
      "source": "poc",
      "mitreUrl": "https://nvd.nist.gov/vuln/detail/CVE-2026-24061",
      "research": [
        {
          "url": "https://www.safebreach.com/blog/safebreach-labs-root-cause-analysis-and-poc-exploit-for-cve-2026-24061/",
          "type": "writeup",
          "source": "SafeBreach Labs",
          "note": "RCA + PoC; USER=-f root bypass"
        },
        {
          "url": "https://github.com/midox008/CVE-2026-24061",
          "type": "poc",
          "source": "GitHub midox008",
          "note": "telnetd auth-bypass PoC",
          "hasCode": true
        },
        {
          "url": "https://github.com/0xXyc/telnet-inetutils-auth-bypass-CVE-2026-24061",
          "type": "poc",
          "source": "GitHub 0xXyc",
          "note": "PoC",
          "hasCode": true
        },
        {
          "url": "https://www.sonicwall.com/blog/gnu-inetutils-telnetd-rce-cve-2026-24061",
          "type": "writeup",
          "source": "SonicWall",
          "note": "auth bypass to RCE"
        }
      ],
      "x": {
        "mentions": 10,
        "posts": [
          {
            "handle": "1ZRR4H",
            "followers": 38125,
            "likes": 95,
            "createdAt": "2026-03-27",
            "url": "https://x.com/1ZRR4H/status/2037591212987724247",
            "origin": false,
            "github": []
          },
          {
            "handle": "HackingLZ",
            "followers": 70546,
            "likes": 10,
            "createdAt": "2026-04-09",
            "url": "https://x.com/HackingLZ/status/2042227182022348841",
            "origin": false,
            "github": []
          },
          {
            "handle": "Chromium_Linux",
            "followers": 8538,
            "likes": 9,
            "createdAt": "2026-04-07",
            "url": "https://x.com/Chromium_Linux/status/2041551641686716739",
            "origin": false,
            "github": []
          },
          {
            "handle": "YogSoth0",
            "followers": 586,
            "likes": 3,
            "createdAt": "2026-05-24",
            "url": "https://x.com/YogSoth0/status/2058592824589713679",
            "origin": false,
            "github": []
          },
          {
            "handle": "aoi_0020",
            "followers": 324,
            "likes": 2,
            "createdAt": "2026-04-07",
            "url": "https://x.com/aoi_0020/status/2041483947411149102",
            "origin": false,
            "github": []
          },
          {
            "handle": "someone7140",
            "followers": 12037,
            "likes": 1,
            "createdAt": "2026-04-05",
            "url": "https://x.com/someone7140/status/2040754484381724972",
            "origin": false,
            "github": []
          },
          {
            "handle": "ImpactfulColle1",
            "followers": 47,
            "likes": 1,
            "createdAt": "2026-04-03",
            "url": "https://x.com/ImpactfulColle1/status/2040157644137071069",
            "origin": false,
            "github": []
          },
          {
            "handle": "lyrie_ai",
            "followers": 234,
            "likes": 0,
            "createdAt": "2026-05-11",
            "url": "https://x.com/lyrie_ai/status/2053706446886600799",
            "origin": false,
            "github": []
          }
        ],
        "aliases": []
      },
      "researchers": [
        "SafeBreach",
        "midox008",
        "0xxyc"
      ],
      "bsky": {
        "mentions": 23,
        "posts": [
          {
            "handle": "shadowserver.bsky.social",
            "displayName": "The Shadowserver Foundation",
            "likes": 0,
            "reposts": 0,
            "replies": 0,
            "createdAt": "2026-01-26",
            "url": "https://bsky.app/profile/shadowserver.bsky.social/post/3mdd23zn47k2a",
            "origin": false,
            "authority": true,
            "github": []
          },
          {
            "handle": "patrickcmiller.bsky.social",
            "displayName": "Patrick C Miller",
            "likes": 2,
            "reposts": 1,
            "replies": 0,
            "createdAt": "2026-01-25",
            "url": "https://bsky.app/profile/patrickcmiller.bsky.social/post/3md7lzml6qb2v",
            "origin": false,
            "authority": false,
            "github": []
          },
          {
            "handle": "basefortify.bsky.social",
            "displayName": "BaseFortify.eu",
            "likes": 1,
            "reposts": 1,
            "replies": 1,
            "createdAt": "2026-01-21",
            "url": "https://bsky.app/profile/basefortify.bsky.social/post/3mcwnpj46vs2j",
            "origin": false,
            "authority": false,
            "github": []
          },
          {
            "handle": "cosmicmetanft.bsky.social",
            "displayName": "Cosmic Meta NFT",
            "likes": 2,
            "reposts": 0,
            "replies": 0,
            "createdAt": "2026-01-24",
            "url": "https://bsky.app/profile/cosmicmetanft.bsky.social/post/3md6fdg3myu26",
            "origin": false,
            "authority": false,
            "github": []
          },
          {
            "handle": "solidot.bsky.social",
            "displayName": "Solidot",
            "likes": 0,
            "reposts": 0,
            "replies": 1,
            "createdAt": "2026-02-15",
            "url": "https://bsky.app/profile/solidot.bsky.social/post/3mevqqmx3ky2z",
            "origin": false,
            "authority": false,
            "github": []
          },
          {
            "handle": "sarubot.bsky.social",
            "displayName": "さるぼっと@IT最新動向を配信",
            "likes": 0,
            "reposts": 0,
            "replies": 0,
            "createdAt": "2026-03-24",
            "url": "https://bsky.app/profile/sarubot.bsky.social/post/3mhrpb4sb6v2d",
            "origin": false,
            "authority": false,
            "github": []
          }
        ]
      },
      "telegram": {
        "mentions": 5,
        "posts": [
          {
            "channel": "news4hack",
            "channelTitle": "Pentester",
            "tier": "feed",
            "date": "2026-01-24",
            "views": 1743,
            "forwards": 16,
            "url": "https://t.me/news4hack/3085",
            "text": "2026-24061: Telnetd RCE as Root This flaw allows an attacker to establish a Telnet session without providing valid credentials, granting unauthorized access to the target system. The vulnerability exists all the way up to version 2.7-2 of the GNU telnetd service. Exploit: https://github.com/SafeBreach-Labs/CVE-2026-24061 Query: ZoomEye: app=\"GNU Inetutils telnetd\" Shodan: product:\"telnetd\" @news4h",
            "github": [
              {
                "url": "https://github.com/SafeBreach-Labs/CVE-2026-24061",
                "hasCode": true
              }
            ],
            "origin": true
          },
          {
            "channel": "GOTOCVE",
            "channelTitle": "GO-TO CVE",
            "tier": "feed",
            "date": "2026-01-24",
            "views": 1130,
            "forwards": 12,
            "url": "https://t.me/GOTOCVE/3094",
            "text": "https://github.com/SafeBreach-Labs/CVE-2026-24061",
            "github": [
              {
                "url": "https://github.com/SafeBreach-Labs/CVE-2026-24061",
                "hasCode": true
              }
            ],
            "origin": true
          },
          {
            "channel": "thehackernews",
            "channelTitle": "The Hacker News",
            "tier": "news",
            "date": "2026-01-22",
            "views": 12077,
            "forwards": 48,
            "url": "https://t.me/thehackernews/8270",
            "text": "🚨 An 11-year-old critical flaw in GNU InetUtils telnetd lets attackers log in as root with no password. Tracked as CVE-2026-24061 (CVSS 9.8), it affects all versions 1.9.3–2.7 due to an unsanitized USER environment value passed to login. ⚠️ Exploitation has already been observed in the wild. 🔗 Read →https://thehackernews.com/2026/01/critical-gnu-inetutils-telnetd-flaw.html",
            "github": [],
            "origin": false
          }
        ]
      },
      "aliases": []
    },
    {
      "cve": "CVE-2026-43284",
      "title": "In the Linux kernel, the following vulnerability has been resolved: xfrm: esp: avoid…",
      "category": "Recall",
      "vendor": null,
      "exploited": false,
      "publiclyDisclosed": true,
      "cvss": 8.8,
      "cvssVector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H",
      "severity": "HIGH",
      "impact": null,
      "products": [],
      "productCount": 0,
      "faq": "In the Linux kernel, the following vulnerability has been resolved:\n\nxfrm: esp: avoid in-place decrypt on shared skb frags\n\nMSG_SPLICE_PAGES can attach pages from a pipe directly to an skb. TCP\nmarks such skbs with SKBFL_SHARED_FRAG after skb_splice_from_iter(),\nso later paths that may modify packet data can first make a private\ncopy. The IPv4/IPv6 datagram append paths did not set this flag when\nsplicing pages into UDP skbs.\n\nThat leaves an ESP-in-UDP packet made from shared pipe pages looking\nlike an ordinary uncloned nonlinear skb. ESP input then takes the no-COW\nfast path for uncloned skbs without a frag_list and decrypts in place\nover data that is not owned privately by the skb.\n\nMark IPv4/IPv6 datagram splice frags with SKBFL_SHARED_FRAG, matching\nTCP. Also make ESP input fall back to skb_cow_data() when the flag is\npresent, so ESP does not decrypt externally backed frags in place.\nPrivate nonlinear skb frags still use the existing fast path.\n\nThis intentionally does not change ESP output. In esp_output_head(),\nthe path that appends the ESP trailer to existing skb tailroom without\ncalling skb_cow_data() is not reachable for nonlinear skbs:\nskb_tailroom() returns zero when skb->data_len is nonzero, while ESP\ntailen is positive. Thus ESP output will either use the separate\ndestination-frag path or fall back to skb_cow_data().",
      "pocConfidence": "confirmed",
      "pocCount": 5,
      "pocTopStars": 25,
      "pocRepos": [
        {
          "url": "https://github.com/linnemanlabs/dirtyfrag-arm64",
          "stars": 25,
          "desc": "arm64/aarch64 port of V4bel/dirtyfrag (CVE-2026-43284). ESP-only - rxrpc path kernel-oopses on arm64 due to flush_dcache_page",
          "createdAt": "2026-05-10",
          "hasCode": true
        },
        {
          "url": "https://github.com/0xBlackash/CVE-2026-43284",
          "stars": 13,
          "desc": "CVE-2026-43284",
          "createdAt": "2026-05-08",
          "hasCode": true
        },
        {
          "url": "https://github.com/Percivalll/Dirty-Frag-Kubernetes-PoC",
          "stars": 12,
          "desc": "A proof-of-concept demonstrating how a default, unprivileged Kubernetes Pod can achieve node-level code execution on Amazon EKS by exploiting the Dirty Frag (CV",
          "createdAt": "2026-05-08",
          "hasCode": true
        },
        {
          "url": "https://github.com/scriptzteam/Paranoid-Dirty-Frag-CVE-2026-43284",
          "stars": 0,
          "desc": "Paranoid disable Linux IPsec ESP support (esp4/esp6) and RxRPC support.",
          "createdAt": "2026-05-08",
          "hasCode": true
        },
        {
          "url": "https://github.com/suominen/CVE-2026-43284",
          "stars": 0,
          "desc": "Tracking CVE-2026-43284",
          "createdAt": "2026-05-08",
          "hasCode": true
        },
        {
          "url": "https://github.com/AK777177/Dirty-Frag-Analysis",
          "stars": 2,
          "desc": "Dirty Frag (CVE-2026-43284/43500) - Linux Kernel LPE Deep Technical Analysis by Bomb",
          "createdAt": "2026-05-08",
          "hasCode": false
        }
      ],
      "epss": 0.93235,
      "epssPercentile": 0.99823,
      "source": "poc",
      "mitreUrl": "https://nvd.nist.gov/vuln/detail/CVE-2026-43284",
      "research": [
        {
          "url": "https://www.wiz.io/blog/dirty-frag-linux-kernel-local-privilege-escalation-via-esp-and-rxrpc",
          "type": "writeup",
          "source": "Wiz",
          "note": "Dirty Frag LPE via xfrm-ESP/RxRPC page cache"
        },
        {
          "url": "https://thehackernews.com/2026/05/linux-kernel-dirty-frag-lpe-exploit.html",
          "type": "writeup",
          "source": "The Hacker News",
          "note": "LPE root across major distros"
        },
        {
          "url": "https://github.com/AtlasVector/Dirty-Frag-CVE-2026-43284",
          "type": "detection",
          "source": "AtlasVector",
          "note": "Lab detection exercise, EQL rules + writeup",
          "hasCode": false
        },
        {
          "url": "https://www.sysdig.com/blog/dirty-frag-cve-2026-43284-and-cve-2026-43500-detecting-unpatched-local-privilege-escalation-via-linux-kernel-esp-and-rxrpc",
          "type": "detection",
          "source": "Sysdig",
          "note": "Detecting unpatched ESP/RxRPC LPE"
        },
        {
          "url": "https://access.redhat.com/security/cve/cve-2026-43284",
          "type": "writeup",
          "source": "Red Hat",
          "note": "Vendor advisory"
        }
      ],
      "x": {
        "mentions": 2,
        "aliases": [
          "Dirty Frag"
        ],
        "posts": [
          {
            "handle": "linkersec",
            "followers": 10213,
            "likes": 1,
            "createdAt": "2026-05-20",
            "url": "https://x.com/linkersec/status/2057076253430096066",
            "github": [
              {
                "url": "https://github.com/V4bel/dirtyfrag",
                "hasCode": true
              }
            ],
            "origin": false
          },
          {
            "handle": "BunSnack",
            "followers": 6,
            "likes": 1,
            "createdAt": "2026-06-06",
            "url": "https://x.com/BunSnack/status/2063139049943314703",
            "github": [],
            "origin": false
          }
        ]
      },
      "aliases": [
        "Dirty Frag"
      ],
      "researchers": [
        "Hyunwoo Kim"
      ],
      "bsky": {
        "mentions": 33,
        "posts": [
          {
            "handle": "bleepingcomputer.com",
            "displayName": "BleepingComputer",
            "likes": 17,
            "reposts": 4,
            "replies": 0,
            "createdAt": "2026-05-08",
            "url": "https://bsky.app/profile/bleepingcomputer.com/post/3mldaer7uax2g",
            "origin": true,
            "authority": true,
            "github": []
          },
          {
            "handle": "linkersec.bsky.social",
            "displayName": "Linux Kernel Security",
            "likes": 1,
            "reposts": 1,
            "replies": 0,
            "createdAt": "2026-07-08",
            "url": "https://bsky.app/profile/linkersec.bsky.social/post/3mq55f6qfks2y",
            "origin": true,
            "authority": false,
            "github": [
              {
                "url": "https://github.com/V4bel/ITScape",
                "hasCode": true
              }
            ]
          },
          {
            "handle": "rockylinux.org",
            "displayName": "Rocky Linux",
            "likes": 17,
            "reposts": 9,
            "replies": 0,
            "createdAt": "2026-05-09",
            "url": "https://bsky.app/profile/rockylinux.org/post/3mlgtbn5sgq2p",
            "origin": true,
            "authority": false,
            "github": []
          },
          {
            "handle": "meo.bsky.social",
            "displayName": "marissa walmart dog",
            "likes": 23,
            "reposts": 0,
            "replies": 1,
            "createdAt": "2026-05-10",
            "url": "https://bsky.app/profile/meo.bsky.social/post/3mlizmq2wgc24",
            "origin": true,
            "authority": false,
            "github": []
          },
          {
            "handle": "gigazine.net",
            "displayName": "GIGAZINE",
            "likes": 13,
            "reposts": 6,
            "replies": 0,
            "createdAt": "2026-05-08",
            "url": "https://bsky.app/profile/gigazine.net/post/3mlddiqflqe2c",
            "origin": true,
            "authority": false,
            "github": []
          },
          {
            "handle": "9to5linux.com",
            "displayName": "9to5Linux.com",
            "likes": 8,
            "reposts": 1,
            "replies": 0,
            "createdAt": "2026-05-08",
            "url": "https://bsky.app/profile/9to5linux.com/post/3mldtvf4rak2o",
            "origin": true,
            "authority": false,
            "github": []
          }
        ]
      },
      "telegram": {
        "mentions": 7,
        "reach": 14865,
        "posts": [
          {
            "channel": "news4hack",
            "channelTitle": "Pentester",
            "tier": "feed",
            "date": "2026-05-12",
            "views": 1580,
            "forwards": 5,
            "url": "https://t.me/news4hack/3092",
            "text": "Dirty Frag: Universal Linux LPE Obtain root privileges on major Linux distributions by chaining the xfrm-ESP Page-Cache Write vulnerability and the RxRPC Page-Cache Writevulnerability. Dirty Frag is a case that extends the bug class to which Dirty Pipe and Copy Fail belong. Because it is a deterministic logic bug that does not depend on a timing window, no race condition is required, the kernel do",
            "github": [],
            "origin": false
          },
          {
            "channel": "thehackernews",
            "channelTitle": "The Hacker News",
            "tier": "news",
            "date": "2026-05-08",
            "views": 11342,
            "forwards": 69,
            "url": "https://t.me/thehackernews/8960",
            "text": "🚨 A new UNPATCHED Linux kernel “Dirty Frag” LPE flaw enables root access on Ubuntu, RHEL, Fedora and other distributions. Researchers released a working proof-of-concept exploit capable of gaining root in a single command. Details here: https://thehackernews.com/2026/05/linux-kernel-dirty-frag-lpe-exploit.html",
            "github": [],
            "origin": false
          }
        ]
      }
    },
    {
      "cve": "CVE-2026-46300",
      "title": "In the Linux kernel, the following vulnerability has been resolved: net: skbuff:…",
      "category": "Recall",
      "vendor": null,
      "exploited": false,
      "publiclyDisclosed": true,
      "cvss": 7.8,
      "cvssVector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "severity": "HIGH",
      "impact": null,
      "products": [],
      "productCount": 0,
      "faq": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: skbuff: preserve shared-frag marker during coalescing\n\nskb_try_coalesce() can attach paged frags from @from to @to.  If @from\nhas SKBFL_SHARED_FRAG set, the resulting @to skb can contain the same\nexternally-owned or page-cache-backed frags, but the shared-frag marker\nis currently lost.\n\nThat breaks the invariant relied on by later in-place writers.  In\nparticular, ESP input checks skb_has_shared_frag() before deciding\nwhether an uncloned nonlinear skb can skip skb_cow_data().  If TCP\nreceive coalescing has moved shared frags into an unmarked skb, ESP can\nsee skb_has_shared_frag() as false and decrypt in place over page-cache\nbacked frags.\n\nPropagate SKBFL_SHARED_FRAG when skb_try_coalesce() transfers paged\nfrags.  The tailroom copy path does not need the marker because it copies\nbytes into @to's linear data rather than transferring frag descriptors.",
      "pocConfidence": "confirmed",
      "pocCount": 5,
      "pocTopStars": 8,
      "pocRepos": [
        {
          "url": "https://github.com/0xBlackash/CVE-2026-46300",
          "stars": 8,
          "desc": "CVE-2026-46300",
          "createdAt": "2026-05-15",
          "hasCode": true
        },
        {
          "url": "https://github.com/HORKimhab/CVE-2026-46300",
          "stars": 1,
          "desc": "CVE-2026-46300",
          "createdAt": "2026-05-14",
          "hasCode": true
        },
        {
          "url": "https://github.com/Sentebale/CVE-2026-46300",
          "stars": 1,
          "desc": "",
          "createdAt": "2026-05-14",
          "hasCode": true
        },
        {
          "url": "https://github.com/Koshmare-Blossom/Fragnesia-go",
          "stars": 1,
          "desc": "A Go implementation of fragnesia (CVE-2026-46300)",
          "createdAt": "2026-05-20",
          "hasCode": true
        },
        {
          "url": "https://github.com/1neptune/Fragnesia",
          "stars": 0,
          "desc": "Add go CVE-2026-46300 (Fragnesia) local privilege escalation exploit",
          "createdAt": "2026-06-03",
          "hasCode": true
        },
        {
          "url": "https://github.com/ExploitEoom/CVE-2026-46300",
          "stars": 0,
          "desc": "Linux kernel root exploit",
          "createdAt": "2026-05-17",
          "hasCode": false
        }
      ],
      "epss": 0.03663,
      "epssPercentile": 0.8842,
      "source": "poc",
      "mitreUrl": "https://nvd.nist.gov/vuln/detail/CVE-2026-46300",
      "research": [
        {
          "url": "https://tuxcare.com/blog/fragnesia-cve-2026-46300-is-a-new-linux-kernel-lpe/",
          "type": "writeup",
          "source": "TuxCare",
          "note": "Fragnesia LPE in Dirty Frag family"
        },
        {
          "url": "https://nsfocusglobal.com/linux-kernel-fragnesia-privilege-escalation-vulnerability-cve-2026-46300-notice/",
          "type": "writeup",
          "source": "NSFOCUS",
          "note": "Priv-esc via skbuff shared-frag marker loss"
        },
        {
          "url": "https://almalinux.org/blog/2026-05-13-fragnesia-cve-2026-46300/",
          "type": "writeup",
          "source": "AlmaLinux",
          "note": "Patch release notice"
        },
        {
          "url": "https://ubuntu.com/security/CVE-2026-46300",
          "type": "writeup",
          "source": "Ubuntu",
          "note": "Vendor security advisory"
        }
      ],
      "x": {
        "mentions": 9,
        "aliases": [
          "Fragnesia"
        ],
        "posts": [
          {
            "handle": "linkersec",
            "followers": 10213,
            "likes": 2,
            "createdAt": "2026-05-20",
            "url": "https://x.com/linkersec/status/2057076255573360726",
            "github": [
              {
                "url": "https://github.com/v12-security/pocs/tree/main/fragnesia",
                "hasCode": true
              },
              {
                "url": "https://github.com/v12-security/pocs/tree/main/fragnesia-5db89c99566fc",
                "hasCode": true
              }
            ],
            "origin": false
          },
          {
            "handle": "SCMagazine",
            "followers": 119365,
            "likes": 7,
            "createdAt": "2026-05-19",
            "url": "https://x.com/SCMagazine/status/2056729105291255823",
            "github": [],
            "origin": false
          },
          {
            "handle": "battista212",
            "followers": 246,
            "likes": 1,
            "createdAt": "2026-05-17",
            "url": "https://x.com/battista212/status/2056133184685850954",
            "github": [],
            "origin": false
          },
          {
            "handle": "BunSnack",
            "followers": 6,
            "likes": 1,
            "createdAt": "2026-06-06",
            "url": "https://x.com/BunSnack/status/2063139049943314703",
            "github": [],
            "origin": false
          },
          {
            "handle": "KasperskyDev",
            "followers": 39990,
            "likes": 0,
            "createdAt": "2026-05-19",
            "url": "https://x.com/KasperskyDev/status/2056661177045029254",
            "github": [],
            "origin": false
          },
          {
            "handle": "leonov_av",
            "followers": 1006,
            "likes": 0,
            "createdAt": "2026-05-29",
            "url": "https://x.com/leonov_av/status/2060482470911316322",
            "github": [],
            "origin": false
          },
          {
            "handle": "mrBr4un",
            "followers": 54,
            "likes": 0,
            "createdAt": "2026-06-04",
            "url": "https://x.com/mrBr4un/status/2062489094056190251",
            "github": [],
            "origin": false
          },
          {
            "handle": "TheCyberDef",
            "followers": 1,
            "likes": 0,
            "createdAt": "2026-05-17",
            "url": "https://x.com/TheCyberDef/status/2056053042487964081",
            "github": [],
            "origin": false
          }
        ]
      },
      "aliases": [
        "Fragnesia"
      ],
      "researchers": [
        "William Bowling"
      ],
      "bsky": {
        "mentions": 26,
        "posts": [
          {
            "handle": "adriend.linuxtricks.fr",
            "displayName": "Adrien Linuxtricks",
            "likes": 15,
            "reposts": 8,
            "replies": 6,
            "createdAt": "2026-05-13",
            "url": "https://bsky.app/profile/adriend.linuxtricks.fr/post/3mlqnw2qdbs27",
            "origin": true,
            "authority": false,
            "github": [
              {
                "url": "https://github.com/v12-security/pocs/tree/main/fragnesia",
                "hasCode": true
              }
            ]
          },
          {
            "handle": "cadey.pony.social.ap.brid.gy",
            "displayName": "Xe :verified:",
            "likes": 3,
            "reposts": 3,
            "replies": 0,
            "createdAt": "2026-05-15",
            "url": "https://bsky.app/profile/cadey.pony.social.ap.brid.gy/post/3mlw7lcpown42",
            "origin": true,
            "authority": false,
            "github": [
              {
                "url": "https://github.com/v12-security/pocs/tree/main/fragnesia-5db89c99566fc",
                "hasCode": true
              }
            ]
          },
          {
            "handle": "blackhatnews.tokyo",
            "displayName": "blackhatnews.tokyo",
            "likes": 0,
            "reposts": 0,
            "replies": 0,
            "createdAt": "2026-05-14",
            "url": "https://bsky.app/profile/blackhatnews.tokyo/post/3mltsfngbao2g",
            "origin": true,
            "authority": false,
            "github": []
          },
          {
            "handle": "bleepingcomputer.com",
            "displayName": "BleepingComputer",
            "likes": 9,
            "reposts": 7,
            "replies": 1,
            "createdAt": "2026-05-14",
            "url": "https://bsky.app/profile/bleepingcomputer.com/post/3mlscdil7ah26",
            "origin": false,
            "authority": true,
            "github": []
          },
          {
            "handle": "infosec.skyfleet.blue",
            "displayName": "InfoSec",
            "likes": 0,
            "reposts": 0,
            "replies": 0,
            "createdAt": "2026-05-13",
            "url": "https://bsky.app/profile/infosec.skyfleet.blue/post/3mlqjjok3e625",
            "origin": false,
            "authority": true,
            "github": []
          },
          {
            "handle": "xeiaso.net",
            "displayName": "Xe",
            "likes": 38,
            "reposts": 2,
            "replies": 6,
            "createdAt": "2026-05-15",
            "url": "https://bsky.app/profile/xeiaso.net/post/3mlw7ko5lo22f",
            "origin": false,
            "authority": false,
            "github": [
              {
                "url": "https://github.com/v12-security/pocs/tree/main/fragnesia-5db89c99566fc",
                "hasCode": true
              }
            ]
          }
        ]
      },
      "telegram": {
        "mentions": 4,
        "reach": 31062,
        "posts": [
          {
            "channel": "thehackernews",
            "channelTitle": "The Hacker News",
            "tier": "news",
            "date": "2026-05-14",
            "views": 15398,
            "forwards": 87,
            "url": "https://t.me/thehackernews/8998",
            "text": "🛑 3rd Linux kernel LPE in just ~2 weeks: Fragnesia (CVE-2026-46300) just dropped. Attackers can now gain root by corrupting the kernel page cache through a flaw in XFRM ESP-in-TCP. PoC is public. Major distros have already issued advisories. Details: https://thehackernews.com/2026/05/new-fragnesia-linux-kernel-lpe-grants.html",
            "github": [],
            "origin": false
          }
        ]
      }
    },
    {
      "cve": "CVE-2026-9256",
      "title": "NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_rewrite_module…",
      "category": "Recall",
      "vendor": null,
      "exploited": false,
      "publiclyDisclosed": true,
      "cvss": 8.1,
      "cvssVector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "severity": "HIGH",
      "impact": null,
      "products": [],
      "productCount": 0,
      "faq": "NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_rewrite_module module. This vulnerability exists when a rewrite directive uses a regex pattern with distinct, overlapping Perl-Compatible Regular Expression (PCRE) captures (for example, ^/((.*))$) and a replacement string that references multiple such captures (for example, $1$2) in a redirect or arguments context. An unauthenticated attacker along with conditions beyond their control can exploit this vulnerability by sending crafted HTTP requests. This may cause a heap buffer overflow in the NGINX worker process leading to a restart. Additionally, attackers can execute code on systems with Address Space Layout Randomization (ASLR) disabled or when the attacker can bypass ASLR. \n\n\nNote: Software versions which have reached End of Technical Support (EoTS) are not evaluated.",
      "pocConfidence": "confirmed",
      "pocCount": 5,
      "pocTopStars": 8,
      "pocRepos": [
        {
          "url": "https://github.com/y198nt/Nginx-chain-Rift-Poolslip",
          "stars": 8,
          "desc": "Nginx RCE chain PoC with CVE-2026-9256 and CVE-2026-42945",
          "createdAt": "2026-06-05",
          "hasCode": true
        },
        {
          "url": "https://github.com/3nou9h/CVE-2026-9256-Poc",
          "stars": 2,
          "desc": "",
          "createdAt": "2026-05-28",
          "hasCode": true
        },
        {
          "url": "https://github.com/W5M1n9/NGINX-ngx_http_rewrite_module-heap-buffer-overflow-CVE-2026-9256",
          "stars": 1,
          "desc": "",
          "createdAt": "2026-05-28",
          "hasCode": true
        },
        {
          "url": "https://github.com/suominen/CVE-2026-9256",
          "stars": 0,
          "desc": "Tracking the nginx CVE-2026-9256 rewrite-module heap overflow",
          "createdAt": "2026-05-24",
          "hasCode": true
        },
        {
          "url": "https://github.com/06-ux/CVE-2026-9256-POC",
          "stars": 0,
          "desc": "CVE-2026-9256 Nginx heap buffer overflow POC",
          "createdAt": "2026-06-03",
          "hasCode": true
        }
      ],
      "epss": 0.04261,
      "epssPercentile": 0.89989,
      "source": "poc",
      "mitreUrl": "https://nvd.nist.gov/vuln/detail/CVE-2026-9256",
      "research": [
        {
          "url": "https://www.cycognito.com/blog/emerging-threat-cve-2026-9256-nginx-heap-buffer-overflow-via-rewrite-module/",
          "type": "writeup",
          "source": "CyCognito",
          "note": "Heap buffer overflow via rewrite module"
        },
        {
          "url": "https://nginx.org/en/security_advisories.html",
          "type": "writeup",
          "source": "nginx.org",
          "note": "Official nginx security advisory"
        },
        {
          "url": "https://www.rapid7.com/db/vulnerabilities/nginx-cve-2026-9256/",
          "type": "writeup",
          "source": "Rapid7",
          "note": "Buffer overflow in ngx_http_rewrite_module"
        },
        {
          "url": "https://www.indusface.com/blog/nginx-cve-2026-42945-and-cve-2026-9256/",
          "type": "writeup",
          "source": "Indusface",
          "note": "Active exploitation analysis"
        }
      ],
      "x": {
        "mentions": 2,
        "aliases": [
          "nginx-poolslip"
        ],
        "posts": [
          {
            "handle": "samilaiho",
            "followers": 30576,
            "likes": 1,
            "createdAt": "2026-05-26",
            "url": "https://x.com/samilaiho/status/2059307236598456606",
            "github": [
              {
                "url": "https://github.com/advisories/GHSA-h78r-86c6-jgp4",
                "hasCode": null
              }
            ],
            "origin": false
          },
          {
            "handle": "ptdbugs",
            "followers": 1246,
            "likes": 5,
            "createdAt": "2026-05-29",
            "url": "https://x.com/ptdbugs/status/2060445021241856504",
            "github": [],
            "origin": false
          }
        ]
      },
      "aliases": [
        "nginx-poolslip"
      ],
      "researchers": [],
      "bsky": {
        "mentions": 30,
        "posts": [
          {
            "handle": "campuscodi.risky.biz",
            "displayName": "Catalin Cimpanu",
            "likes": 7,
            "reposts": 0,
            "replies": 1,
            "createdAt": "2026-05-21",
            "url": "https://bsky.app/profile/campuscodi.risky.biz/post/3mmelbovl3s2k",
            "origin": true,
            "authority": true,
            "github": []
          },
          {
            "handle": "tech-trending.bsky.social",
            "displayName": "Tech Trending",
            "likes": 2,
            "reposts": 1,
            "replies": 0,
            "createdAt": "2026-05-21",
            "url": "https://bsky.app/profile/tech-trending.bsky.social/post/3mmfibphkrb2a",
            "origin": true,
            "authority": false,
            "github": []
          },
          {
            "handle": "moselwal.de",
            "displayName": "Moselwal Digitalagentur",
            "likes": 1,
            "reposts": 0,
            "replies": 0,
            "createdAt": "2026-05-22",
            "url": "https://bsky.app/profile/moselwal.de/post/3mmhjajbmbs2e",
            "origin": true,
            "authority": false,
            "github": []
          },
          {
            "handle": "jschauma.mstdn.social.ap.brid.gy",
            "displayName": "Jan Schaumann",
            "likes": 0,
            "reposts": 0,
            "replies": 1,
            "createdAt": "2026-05-22",
            "url": "https://bsky.app/profile/jschauma.mstdn.social.ap.brid.gy/post/3mmi3znywbij2",
            "origin": true,
            "authority": false,
            "github": []
          },
          {
            "handle": "undercode.bsky.social",
            "displayName": "Undercode Testing",
            "likes": 0,
            "reposts": 0,
            "replies": 0,
            "createdAt": "2026-05-23",
            "url": "https://bsky.app/profile/undercode.bsky.social/post/3mmk27lthi325",
            "origin": true,
            "authority": false,
            "github": []
          },
          {
            "handle": "2rzikkbou3ntafnir2qmmse0gwz.activitypub.awakari.com.ap.brid.gy",
            "displayName": "2rZiKKbOU3nTafniR2qMMSE0gwZ",
            "likes": 0,
            "reposts": 0,
            "replies": 0,
            "createdAt": "2026-05-23",
            "url": "https://bsky.app/profile/2rzikkbou3ntafnir2qmmse0gwz.activitypub.awakari.com.ap.brid.gy/post/3mmjih5ilflx2",
            "origin": true,
            "authority": false,
            "github": []
          }
        ]
      },
      "telegram": {
        "mentions": 0,
        "reach": 0,
        "posts": []
      }
    },
    {
      "cve": "CVE-2026-23550",
      "title": "Incorrect Privilege Assignment vulnerability in Modular DS Modular DS…",
      "category": "Recall",
      "vendor": null,
      "exploited": false,
      "publiclyDisclosed": true,
      "cvss": 9.8,
      "cvssVector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "severity": "CRITICAL",
      "impact": null,
      "products": [],
      "productCount": 0,
      "faq": "Incorrect Privilege Assignment vulnerability in Modular DS Modular DS modular-connector allows Privilege Escalation.This issue affects Modular DS: from n/a through <= 2.5.1.",
      "pocConfidence": "confirmed",
      "pocCount": 5,
      "pocTopStars": 2,
      "pocRepos": [
        {
          "url": "https://github.com/dzmind2312/Mass-CVE-2026-23550-Exploit",
          "stars": 2,
          "desc": "Mass CVE-2026-23550 Exploit",
          "createdAt": "2026-02-07",
          "hasCode": true
        },
        {
          "url": "https://github.com/DedsecTeam-BlackHat/CVE-2026-23550",
          "stars": 1,
          "desc": "",
          "createdAt": "2026-02-26",
          "hasCode": true
        },
        {
          "url": "https://github.com/TheTorjanCaptain/CVE-2026-23550-PoC",
          "stars": 1,
          "desc": "CVE-2026-23550 - Modular DS WordPress Plugin **Unauthenticated Admin Access**",
          "createdAt": "2026-01-17",
          "hasCode": true
        },
        {
          "url": "https://github.com/cyberdudebivash/CYBERDUDEBIVASH-Modular-DS-CVE-2026-23550-Detector",
          "stars": 1,
          "desc": "authorized CYBERDUDEBIVASH ECOSYSTEM tool for detecting CVE-2026-23550 in WordPress Modular DS plugin",
          "createdAt": "2026-01-15",
          "hasCode": true
        },
        {
          "url": "https://github.com/epsilonpoint88-glitch/EpSiLoNPoInT-",
          "stars": 1,
          "desc": "🔴 EpSiLoNPoInT - CVE-2026-23550 Modular DS Zero-Click  **Framework d'exploitation Modular DS Admin Bypass**  ## 🎯 CVE Ciblée Principale **CVE-2026-23550** : M",
          "createdAt": "2026-02-10",
          "hasCode": true
        }
      ],
      "epss": 0.20631,
      "epssPercentile": 0.97249,
      "source": "poc",
      "mitreUrl": "https://nvd.nist.gov/vuln/detail/CVE-2026-23550",
      "bsky": {
        "mentions": 25,
        "posts": [
          {
            "handle": "infosec.skyfleet.blue",
            "displayName": "InfoSec",
            "likes": 0,
            "reposts": 0,
            "replies": 0,
            "createdAt": "2026-01-15",
            "url": "https://bsky.app/profile/infosec.skyfleet.blue/post/3mchpc43i6m2e",
            "origin": false,
            "authority": true,
            "github": []
          },
          {
            "handle": "mynameisv.bsky.social",
            "displayName": "Mynameisv",
            "likes": 1,
            "reposts": 1,
            "replies": 0,
            "createdAt": "2026-01-20",
            "url": "https://bsky.app/profile/mynameisv.bsky.social/post/3mcu4z4yj322r",
            "origin": false,
            "authority": false,
            "github": []
          },
          {
            "handle": "hurayraiit.com",
            "displayName": "Abu Hurayra",
            "likes": 1,
            "reposts": 0,
            "replies": 0,
            "createdAt": "2026-01-14",
            "url": "https://bsky.app/profile/hurayraiit.com/post/3mcfdapmivk2d",
            "origin": false,
            "authority": false,
            "github": []
          },
          {
            "handle": "hakksaww.bsky.social",
            "displayName": "Patrick Duggan",
            "likes": 0,
            "reposts": 0,
            "replies": 0,
            "createdAt": "2026-02-03",
            "url": "https://bsky.app/profile/hakksaww.bsky.social/post/3mdxoa62dkk27",
            "origin": false,
            "authority": false,
            "github": []
          },
          {
            "handle": "cyberhub.blog",
            "displayName": "CyberHub",
            "likes": 0,
            "reposts": 0,
            "replies": 0,
            "createdAt": "2026-01-18",
            "url": "https://bsky.app/profile/cyberhub.blog/post/3mcoexbciyq24",
            "origin": false,
            "authority": false,
            "github": []
          },
          {
            "handle": "hacker.at.thenote.app",
            "displayName": "Hacker & Security News",
            "likes": 0,
            "reposts": 0,
            "replies": 0,
            "createdAt": "2026-01-17",
            "url": "https://bsky.app/profile/hacker.at.thenote.app/post/3mclrlpgyn22m",
            "origin": false,
            "authority": false,
            "github": []
          }
        ]
      },
      "telegram": {
        "mentions": 2,
        "posts": [
          {
            "channel": "thehackernews",
            "channelTitle": "The Hacker News",
            "tier": "news",
            "date": "2026-01-15",
            "views": 11417,
            "forwards": 37,
            "url": "https://t.me/thehackernews/8218",
            "text": "🚨 A WordPress plugin with 40,000+ active installs is being actively exploited. CVE-2026-23550 (CVSS 10.0) in Modular DS allows unauthenticated attackers to gain admin access by bypassing authentication through a flawed routing mechanism. 🔗 Details → https://thehackernews.com/2026/01/critical-wordpress-modular-ds-plugin.html",
            "github": [],
            "origin": false
          }
        ]
      },
      "research": [],
      "aliases": [],
      "researchers": [],
      "x": {
        "mentions": 0,
        "aliases": [],
        "posts": []
      }
    },
    {
      "cve": "CVE-2026-46331",
      "title": "In the Linux kernel, the following vulnerability has been resolved: net/sched: fix…",
      "category": "Recall",
      "vendor": null,
      "exploited": false,
      "publiclyDisclosed": true,
      "cvss": 7.8,
      "cvssVector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "severity": "HIGH",
      "impact": null,
      "products": [],
      "productCount": 0,
      "faq": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet/sched: fix pedit partial COW leading to page cache corruption\n\ntcf_pedit_act() computes the COW range for skb_ensure_writable()\nonce before the key loop using tcfp_off_max_hint, but the hint does\nnot account for the runtime header offset added by typed keys. This\ncan leave part of the write region un-COW'd.\n\nFix by moving skb_ensure_writable() inside the per-key loop where\nthe actual write offset is known, and add overflow checking on the\noffset arithmetic. For negative offsets (e.g. Ethernet header edits\nat ingress), use skb_cow() to COW the headroom instead. Guard\noffset_valid() against INT_MIN, where negation is undefined.",
      "pocConfidence": "confirmed",
      "pocCount": 4,
      "pocTopStars": 112,
      "pocRepos": [
        {
          "url": "https://github.com/sgkdev/packet_edit_meme",
          "stars": 112,
          "desc": "PACKET_EDIT_MEME.c (aka CVE-2026-46331): yet another page cache poisoning nightmare",
          "createdAt": "2026-06-17",
          "hasCode": true
        },
        {
          "url": "https://github.com/0xBlackash/CVE-2026-46331",
          "stars": 17,
          "desc": "CVE-2026-46331",
          "createdAt": "2026-06-26",
          "hasCode": true
        },
        {
          "url": "https://github.com/vulnquest58/dirtyclone-exploit",
          "stars": 1,
          "desc": "CVE-2026-46331 — Linux Kernel Local Privilege Escalation TC pedit + IPsec TEE Page Cache Corruption · Affected kernels: ≤ 6.12.9",
          "createdAt": "2026-06-28",
          "hasCode": true
        },
        {
          "url": "https://github.com/Quaerendir/cve-2026-46331-audit",
          "stars": 0,
          "desc": "cve-2026-46331-audit script",
          "createdAt": "2026-06-29",
          "hasCode": true
        }
      ],
      "epss": 0.00321,
      "epssPercentile": 0.24257,
      "source": "poc",
      "mitreUrl": "https://nvd.nist.gov/vuln/detail/CVE-2026-46331",
      "research": [],
      "aliases": [],
      "researchers": [],
      "x": {
        "mentions": 0,
        "aliases": [],
        "posts": []
      },
      "bsky": {
        "mentions": 18,
        "posts": [
          {
            "handle": "newssecia.bsky.social",
            "displayName": null,
            "likes": 1,
            "reposts": 0,
            "replies": 0,
            "createdAt": "2026-07-12",
            "url": "https://bsky.app/profile/newssecia.bsky.social/post/3mqi2vil42y2p",
            "origin": false,
            "authority": false,
            "github": [
              {
                "url": "https://github.com/MarwahHadi/CVE-2026-46331-pedit-cow",
                "hasCode": false
              }
            ]
          },
          {
            "handle": "r-blueteamsec.bsky.social",
            "displayName": "r/blueteamsec bot",
            "likes": 0,
            "reposts": 0,
            "replies": 0,
            "createdAt": "2026-06-29",
            "url": "https://bsky.app/profile/r-blueteamsec.bsky.social/post/3mph7o7uy732y",
            "origin": false,
            "authority": false,
            "github": [
              {
                "url": "https://github.com/douglasmun/pagecache-lpe-containment-kit",
                "hasCode": true
              }
            ]
          },
          {
            "handle": "ewenmcneill.bsky.social",
            "displayName": "Ewen McNeill",
            "likes": 1,
            "reposts": 0,
            "replies": 1,
            "createdAt": "2026-06-26",
            "url": "https://bsky.app/profile/ewenmcneill.bsky.social/post/3mp7xvwkxmk25",
            "origin": false,
            "authority": false,
            "github": []
          },
          {
            "handle": "365tipu.cz",
            "displayName": "365tipu",
            "likes": 1,
            "reposts": 0,
            "replies": 0,
            "createdAt": "2026-06-28",
            "url": "https://bsky.app/profile/365tipu.cz/post/3mpdrc7hqzx2y",
            "origin": false,
            "authority": false,
            "github": []
          },
          {
            "handle": "kriptabiz.bsky.social",
            "displayName": "kripta.biz",
            "likes": 0,
            "reposts": 0,
            "replies": 0,
            "createdAt": "2026-07-10",
            "url": "https://bsky.app/profile/kriptabiz.bsky.social/post/3mqckddvxe32w",
            "origin": false,
            "authority": false,
            "github": []
          },
          {
            "handle": "qiancx.bsky.social",
            "displayName": "qian.cx",
            "likes": 0,
            "reposts": 0,
            "replies": 0,
            "createdAt": "2026-07-10",
            "url": "https://bsky.app/profile/qiancx.bsky.social/post/3mqckdd3hcz25",
            "origin": false,
            "authority": false,
            "github": []
          }
        ]
      },
      "telegram": {
        "mentions": 2,
        "reach": 8119,
        "posts": [
          {
            "channel": "thehackernews",
            "channelTitle": "The Hacker News",
            "tier": "news",
            "date": "2026-06-26",
            "views": 7898,
            "forwards": 94,
            "url": "https://t.me/thehackernews/9341",
            "text": "🛑 A new #Linux kernel exploit (CVE-2026-46331) gets root without modifying a single file on disk. It poisons the cached copy of /bin/su in memory. The binary on disk stays untouched. File-integrity checks come back clean. The root shell is already open. Details here ↓ https://thehackernews.com/2026/06/new-linux-pedit-cow-exploit-enables.html",
            "github": [],
            "origin": false
          }
        ]
      }
    },
    {
      "cve": "CVE-2026-25253",
      "title": "OpenClaw (aka clawdbot or Moltbot) before 2026.1.29 obtains a gatewayUrl value from a…",
      "category": "Recall",
      "vendor": null,
      "exploited": false,
      "publiclyDisclosed": true,
      "cvss": 8.8,
      "cvssVector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
      "severity": "HIGH",
      "impact": null,
      "products": [],
      "productCount": 0,
      "faq": "OpenClaw (aka clawdbot or Moltbot) before 2026.1.29 obtains a gatewayUrl value from a query string and automatically makes a WebSocket connection without prompting, sending a token value.",
      "pocConfidence": "confirmed",
      "pocCount": 4,
      "pocTopStars": 46,
      "pocRepos": [
        {
          "url": "https://github.com/adibirzu/openclaw-security-monitor",
          "stars": 46,
          "desc": "Proactive security monitoring for OpenClaw deployments. Detects ClawHavoc, AMOS stealer, CVE-2026-25253, memory poisoning, and supply chain attacks.",
          "createdAt": "2026-02-05",
          "hasCode": true
        },
        {
          "url": "https://github.com/msaleme/red-team-blue-team-agent-fabric",
          "stars": 18,
          "desc": "470 security tests for AI agent systems — MCP, A2A, x402/L402, decision governance, benchmark integrity, skill supply chain. AIUC-1 pre-cert, NIST AI 800-2 alig",
          "createdAt": "2025-11-15",
          "hasCode": true
        },
        {
          "url": "https://github.com/EQSTLab/CVE-2026-25253",
          "stars": 2,
          "desc": "OpenClaw Authentication Token Exfiltration",
          "createdAt": "2026-03-09",
          "hasCode": true
        },
        {
          "url": "https://github.com/siyad01/agentbox",
          "stars": 0,
          "desc": "Open-source sandboxed runtime for AI agents — gVisor/Docker isolation,  credential vault, immutable audit log. Built after CVE-2026-25253.",
          "createdAt": "2026-05-10",
          "hasCode": true
        }
      ],
      "epss": 0.08016,
      "epssPercentile": 0.94142,
      "source": "poc",
      "mitreUrl": "https://nvd.nist.gov/vuln/detail/CVE-2026-25253",
      "research": [
        {
          "url": "https://thehackernews.com/2026/02/openclaw-bug-enables-one-click-remote.html",
          "type": "writeup",
          "source": "The Hacker News",
          "note": "1-click RCE via malicious link, token exfil"
        },
        {
          "url": "https://github.com/EQSTLab/CVE-2026-25253",
          "type": "poc",
          "source": "EQSTLab",
          "note": "PoC: auth token exfiltration",
          "hasCode": true
        },
        {
          "url": "https://socradar.io/blog/cve-2026-25253-rce-openclaw-auth-token/",
          "type": "writeup",
          "source": "SOCRadar",
          "note": "1-click RCE through auth token exfiltration"
        },
        {
          "url": "https://www.sonicwall.com/blog/openclaw-auth-token-theft-leading-to-rce-cve-2026-25253",
          "type": "writeup",
          "source": "SonicWall",
          "note": "Auth token theft leading to RCE"
        }
      ],
      "x": {
        "mentions": 10,
        "posts": [
          {
            "handle": "LionelMiraton",
            "followers": 3589,
            "likes": 1,
            "createdAt": "2026-05-04",
            "url": "https://x.com/LionelMiraton/status/2051238644015370622",
            "origin": false,
            "github": []
          },
          {
            "handle": "CVEShield",
            "followers": 1708,
            "likes": 1,
            "createdAt": "2026-04-28",
            "url": "https://x.com/CVEShield/status/2049037310700773624",
            "origin": false,
            "github": []
          },
          {
            "handle": "dragonb63254274",
            "followers": 742,
            "likes": 0,
            "createdAt": "2026-06-03",
            "url": "https://x.com/dragonb63254274/status/2062039648915034394",
            "origin": false,
            "github": []
          },
          {
            "handle": "SirSilverQuack",
            "followers": 3509,
            "likes": 0,
            "createdAt": "2026-05-20",
            "url": "https://x.com/SirSilverQuack/status/2056961234470048123",
            "origin": false,
            "github": []
          },
          {
            "handle": "musiol_martin",
            "followers": 398,
            "likes": 0,
            "createdAt": "2026-05-15",
            "url": "https://x.com/musiol_martin/status/2055325081723900299",
            "origin": false,
            "github": []
          },
          {
            "handle": "ghstbrv12",
            "followers": 15,
            "likes": 0,
            "createdAt": "2026-05-06",
            "url": "https://x.com/ghstbrv12/status/2051878727026655239",
            "origin": false,
            "github": []
          },
          {
            "handle": "FouadAzahaf",
            "followers": 1,
            "likes": 0,
            "createdAt": "2026-05-06",
            "url": "https://x.com/FouadAzahaf/status/2051821810845458527",
            "origin": false,
            "github": [
              {
                "url": "http://github.com/huseyinstif/CVE-2026-2441-PoC"
              },
              {
                "url": "http://github.com/tangent65536/CVE-2026-20841"
              },
              {
                "url": "http://github.com/ethiack/moltbot-1click-rce"
              }
            ]
          },
          {
            "handle": "apptatsujin",
            "followers": 1159,
            "likes": 0,
            "createdAt": "2026-05-01",
            "url": "https://x.com/apptatsujin/status/2050355356648476693",
            "origin": false,
            "github": []
          }
        ],
        "aliases": []
      },
      "researchers": [
        "eqstlab"
      ],
      "aliases": [],
      "bsky": {
        "mentions": 17,
        "posts": [
          {
            "handle": "shadowserver.bsky.social",
            "displayName": "The Shadowserver Foundation",
            "likes": 2,
            "reposts": 0,
            "replies": 1,
            "createdAt": "2026-02-03",
            "url": "https://bsky.app/profile/shadowserver.bsky.social/post/3mdxvizt3fk2y",
            "origin": false,
            "authority": true,
            "github": []
          },
          {
            "handle": "phantomfills.bsky.social",
            "displayName": "DONI BRASCO • Phantom Execution",
            "likes": 3,
            "reposts": 0,
            "replies": 1,
            "createdAt": "2026-06-21",
            "url": "https://bsky.app/profile/phantomfills.bsky.social/post/3moruy72a2c2z",
            "origin": false,
            "authority": false,
            "github": []
          },
          {
            "handle": "printy.margin.cafe",
            "displayName": "Printy",
            "likes": 1,
            "reposts": 0,
            "replies": 2,
            "createdAt": "2026-03-22",
            "url": "https://bsky.app/profile/printy.margin.cafe/post/3mhmahtdwko27",
            "origin": false,
            "authority": false,
            "github": []
          },
          {
            "handle": "ai-news.at.thenote.app",
            "displayName": "AI & ML News",
            "likes": 2,
            "reposts": 0,
            "replies": 1,
            "createdAt": "2026-03-16",
            "url": "https://bsky.app/profile/ai-news.at.thenote.app/post/3mh5cowhwa223",
            "origin": false,
            "authority": false,
            "github": []
          },
          {
            "handle": "e-kiledjian.bsky.social",
            "displayName": null,
            "likes": 2,
            "reposts": 0,
            "replies": 1,
            "createdAt": "2026-02-27",
            "url": "https://bsky.app/profile/e-kiledjian.bsky.social/post/3mftpj3hrs22c",
            "origin": false,
            "authority": false,
            "github": []
          },
          {
            "handle": "polyarushseo.com",
            "displayName": "Pav Polyarush ☑️",
            "likes": 1,
            "reposts": 1,
            "replies": 1,
            "createdAt": "2026-02-21",
            "url": "https://bsky.app/profile/polyarushseo.com/post/3mfe7ldaqgl2x",
            "origin": false,
            "authority": false,
            "github": []
          }
        ]
      }
    },
    {
      "cve": "CVE-2026-20127",
      "title": "A vulnerability in the peering authentication in Cisco Catalyst SD-WAN Controller,…",
      "category": "Recall",
      "vendor": null,
      "exploited": true,
      "publiclyDisclosed": true,
      "cvss": 10,
      "cvssVector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H",
      "severity": "CRITICAL",
      "impact": null,
      "products": [],
      "productCount": 0,
      "faq": "A vulnerability in the peering authentication in Cisco Catalyst SD-WAN Controller, formerly SD-WAN vSmart, Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, and Cisco Catalyst SD-WAN Validator, formerly SD-WAN vBond, could allow an unauthenticated, remote attacker to bypass authentication and obtain administrative privileges on an affected system.\r\n\r\nThis vulnerability exists because the peering authentication mechanism in an affected system is not working properly. An attacker could exploit this vulnerability by sending crafted requests to an affected system. A successful exploit could allow the attacker to log in to an affected Cisco Catalyst SD-WAN Controller as an internal, high-privileged, non-root&nbsp;user account. Using this account, the attacker could access NETCONF, which would then allow the attacker to manipulate network configuration for the SD-WAN fabric.&nbsp;",
      "pocConfidence": "confirmed",
      "pocCount": 4,
      "pocTopStars": 31,
      "pocRepos": [
        {
          "url": "https://github.com/zerozenxlabs/CVE-2026-20127---Cisco-SD-WAN-Preauth-RCE",
          "stars": 31,
          "desc": "",
          "createdAt": "2026-03-04",
          "hasCode": true
        },
        {
          "url": "https://github.com/sfewer-r7/CVE-2026-20127",
          "stars": 24,
          "desc": "An exploit for the Cisco Catalyst SD-WAN Controller authentication bypass vulnerability, CVE-2026-20127",
          "createdAt": "2026-03-09",
          "hasCode": true
        },
        {
          "url": "https://github.com/gigachadusers/cve-2026-20127",
          "stars": 2,
          "desc": "",
          "createdAt": "2026-04-15",
          "hasCode": true
        },
        {
          "url": "https://github.com/yonathanpy/CVE-2026-20127-Cisco-SD-WAN-Preauth-RCE",
          "stars": 2,
          "desc": "",
          "createdAt": "2026-03-07",
          "hasCode": true
        },
        {
          "url": "https://github.com/BugFor-Pings/CVE-2026-20127_EXP",
          "stars": 4,
          "desc": "Cisco Catalyst SD-WAN 身份验证绕过漏洞(CVE-2026-20127)利用EXP",
          "createdAt": "2026-03-05",
          "hasCode": false
        },
        {
          "url": "https://github.com/randeepajayasekara/CVE-2026-20127",
          "stars": 0,
          "desc": "Walkthrough of the CVSS 10.0 authentication bypass in Cisco Catalyst SD-WAN from first malformed peering request to root on the management plane.",
          "createdAt": "2026-03-04",
          "hasCode": false
        }
      ],
      "epss": 0.57793,
      "epssPercentile": 0.98985,
      "source": "poc",
      "mitreUrl": "https://nvd.nist.gov/vuln/detail/CVE-2026-20127",
      "bsky": {
        "mentions": 23,
        "posts": [
          {
            "handle": "cert-fr.bsky.social",
            "displayName": "CERT-FR",
            "likes": 2,
            "reposts": 4,
            "replies": 0,
            "createdAt": "2026-02-25",
            "url": "https://bsky.app/profile/cert-fr.bsky.social/post/3mfp5rpezz52n",
            "origin": false,
            "authority": false,
            "github": []
          },
          {
            "handle": "getpokemon7.bsky.social",
            "displayName": "まりーん",
            "likes": 1,
            "reposts": 0,
            "replies": 1,
            "createdAt": "2026-03-03",
            "url": "https://bsky.app/profile/getpokemon7.bsky.social/post/3mg6prb7zrs2l",
            "origin": false,
            "authority": false,
            "github": []
          },
          {
            "handle": "pmloik.bsky.social",
            "displayName": null,
            "likes": 0,
            "reposts": 1,
            "replies": 0,
            "createdAt": "2026-03-12",
            "url": "https://bsky.app/profile/pmloik.bsky.social/post/3mgte34n7sc2w",
            "origin": false,
            "authority": false,
            "github": []
          },
          {
            "handle": "i2develop.bsky.social",
            "displayName": "i2develop",
            "likes": 1,
            "reposts": 0,
            "replies": 0,
            "createdAt": "2026-03-10",
            "url": "https://bsky.app/profile/i2develop.bsky.social/post/3mgppup5lwk2b",
            "origin": false,
            "authority": false,
            "github": []
          },
          {
            "handle": "sarubot.bsky.social",
            "displayName": "さるぼっと@IT最新動向を配信",
            "likes": 0,
            "reposts": 0,
            "replies": 0,
            "createdAt": "2026-06-10",
            "url": "https://bsky.app/profile/sarubot.bsky.social/post/3mnvx4ny4yj2t",
            "origin": false,
            "authority": false,
            "github": []
          },
          {
            "handle": "pixelsandpulse.bsky.social",
            "displayName": "Pixels and Pulse - Blog",
            "likes": 0,
            "reposts": 0,
            "replies": 0,
            "createdAt": "2026-05-15",
            "url": "https://bsky.app/profile/pixelsandpulse.bsky.social/post/3mluryeqxu52a",
            "origin": false,
            "authority": false,
            "github": []
          }
        ]
      },
      "telegram": {
        "mentions": 3,
        "posts": [
          {
            "channel": "thehackernews",
            "channelTitle": "The Hacker News",
            "tier": "news",
            "date": "2026-02-26",
            "views": 10259,
            "forwards": 47,
            "url": "https://t.me/thehackernews/8491",
            "text": "🚨 Cisco is warning of active exploitation of a CVSS 10.0 flaw in Catalyst SD-WAN controllers. CVE-2026-20127 lets unauthenticated attackers bypass auth and gain admin access. Exploitation tied to UAT-8616 dates back to 2023, including rogue peers in the control plane and root escalation. 🔗 Read → https://thehackernews.com/2026/02/cisco-sd-wan-zero-day-cve-2026-20127.html",
            "github": [],
            "origin": false
          }
        ]
      },
      "research": [
        {
          "url": "https://github.com/sfewer-r7/CVE-2026-20127",
          "type": "poc",
          "source": "sfewer-r7 (Stephen Fewer / Rapid7)",
          "note": "Working DTLS auth bypass + SSH key injection PoC",
          "hasCode": true
        },
        {
          "url": "https://www.rapid7.com/blog/post/ra-cve-2026-20127-analysis/",
          "type": "writeup",
          "source": "Rapid7 Labs (Jonah Burgess)",
          "note": "Full root-cause analysis: vdaemon DTLS state machine"
        },
        {
          "url": "https://github.com/rapid7/metasploit-framework/pull/21158",
          "type": "module",
          "source": "Rapid7 / sfewer-r7 (Metasploit PR #21158)",
          "note": "MSF aux module: cisco_sdwan_auth_bypass, SSH key inject",
          "hasCode": true
        },
        {
          "url": "https://github.com/zerozenxlabs/CVE-2026-20127---Cisco-SD-WAN-Preauth-RCE",
          "type": "poc",
          "source": "ZeroZenX Labs (GitHub)",
          "note": "Pre-auth RCE PoC repo; CVE label disputed by Talos",
          "hasCode": true
        },
        {
          "url": "https://blog.talosintelligence.com/uat-8616-sd-wan/",
          "type": "writeup",
          "source": "Cisco Talos",
          "note": "UAT-8616 threat actor ITW exploitation analysis"
        },
        {
          "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sdwan-rpa2-v69WY2SW",
          "type": "detection",
          "source": "Cisco PSIRT (official advisory)",
          "note": "Vendor advisory with IoCs and Show Control Connections"
        },
        {
          "url": "https://cloud.google.com/blog/topics/threat-intelligence/zero-day-exploitation-cisco-catalyst-sd-wan-manager",
          "type": "writeup",
          "source": "Mandiant / Google Cloud Threat Intelligence",
          "note": "ITW exploitation chain including CVE-2026-20127 context"
        },
        {
          "url": "https://attackerkb.com/topics/bP3FMvHe7z/cve-2026-20127",
          "type": "writeup",
          "source": "AttackerKB / Rapid7",
          "note": "Rapid7 Labs structured exploit analysis with usage demos"
        }
      ],
      "aliases": [],
      "researchers": [
        "stephenfewer"
      ],
      "x": {
        "mentions": 74,
        "aliases": [],
        "posts": [
          {
            "handle": "vutruso",
            "followers": 38,
            "likes": 0,
            "createdAt": "2026-07-08",
            "url": "https://x.com/vutruso/status/2074690046486290926",
            "github": [
              {
                "url": "https://github.com/V4bel/Januscape",
                "hasCode": true
              }
            ],
            "origin": false
          },
          {
            "handle": "nebusecurity",
            "followers": 4501,
            "likes": 241,
            "createdAt": "2026-07-08",
            "url": "https://x.com/nebusecurity/status/2074663573742338256",
            "github": [],
            "origin": false
          },
          {
            "handle": "__kokumoto",
            "followers": 7578,
            "likes": 7,
            "createdAt": "2026-07-08",
            "url": "https://x.com/__kokumoto/status/2074698589713154281",
            "github": [],
            "origin": false
          },
          {
            "handle": "yousukezan",
            "followers": 14384,
            "likes": 6,
            "createdAt": "2026-07-08",
            "url": "https://x.com/yousukezan/status/2074650902166913222",
            "github": [],
            "origin": false
          },
          {
            "handle": "ridvanyagli",
            "followers": 1120,
            "likes": 6,
            "createdAt": "2026-07-08",
            "url": "https://x.com/ridvanyagli/status/2074701200167952860",
            "github": [],
            "origin": false
          },
          {
            "handle": "Daily_CyberSec",
            "followers": 12430,
            "likes": 5,
            "createdAt": "2026-07-08",
            "url": "https://x.com/Daily_CyberSec/status/2074678524191855020",
            "github": [],
            "origin": false
          },
          {
            "handle": "oss_security",
            "followers": 4646,
            "likes": 4,
            "createdAt": "2026-07-08",
            "url": "https://x.com/oss_security/status/2074685116626907570",
            "github": [],
            "origin": false
          },
          {
            "handle": "ohhara_shiojiri",
            "followers": 2004,
            "likes": 1,
            "createdAt": "2026-07-08",
            "url": "https://x.com/ohhara_shiojiri/status/2074727301179408802",
            "github": [],
            "origin": false
          }
        ]
      }
    },
    {
      "cve": "CVE-2026-46333",
      "title": "In the Linux kernel, the following vulnerability has been resolved: ptrace: slightly…",
      "category": "Recall",
      "vendor": null,
      "exploited": false,
      "publiclyDisclosed": true,
      "cvss": 7.1,
      "cvssVector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N",
      "severity": "HIGH",
      "impact": null,
      "products": [],
      "productCount": 0,
      "faq": "In the Linux kernel, the following vulnerability has been resolved:\n\nptrace: slightly saner 'get_dumpable()' logic\n\nThe 'dumpability' of a task is fundamentally about the memory image of\nthe task - the concept comes from whether it can core dump or not - and\nmakes no sense when you don't have an associated mm.\n\nAnd almost all users do in fact use it only for the case where the task\nhas a mm pointer.\n\nBut we have one odd special case: ptrace_may_access() uses 'dumpable' to\ncheck various other things entirely independently of the MM (typically\nexplicitly using flags like PTRACE_MODE_READ_FSCREDS).  Including for\nthreads that no longer have a VM (and maybe never did, like most kernel\nthreads).\n\nIt's not what this flag was designed for, but it is what it is.\n\nThe ptrace code does check that the uid/gid matches, so you do have to\nbe uid-0 to see kernel thread details, but this means that the\ntraditional \"drop capabilities\" model doesn't make any difference for\nthis all.\n\nMake it all make a *bit* more sense by saying that if you don't have a\nMM pointer, we'll use a cached \"last dumpability\" flag if the thread\never had a MM (it will be zero for kernel threads since it is never\nset), and require a proper CAP_SYS_PTRACE capability to override.",
      "pocConfidence": "confirmed",
      "pocCount": 4,
      "pocTopStars": 31,
      "pocRepos": [
        {
          "url": "https://github.com/0xBlackash/CVE-2026-46333",
          "stars": 31,
          "desc": "CVE-2026-46333",
          "createdAt": "2026-05-17",
          "hasCode": true
        },
        {
          "url": "https://github.com/KaraZajac/CHARON",
          "stars": 6,
          "desc": "CHARON — pre-built PoC for CVE-2026-46333 (Linux ptrace mm==NULL fd theft)",
          "createdAt": "2026-05-16",
          "hasCode": true
        },
        {
          "url": "https://github.com/studiogangster/CVE-2026-46333",
          "stars": 5,
          "desc": "Research on `pidfd_getfd(2)`-based file descriptor leakage from privileged SUID processes. Demonstrates race-condition FD capture against OpenSSH `ssh-keysign` ",
          "createdAt": "2026-05-17",
          "hasCode": true
        },
        {
          "url": "https://github.com/Aurillium/public-passwd",
          "stars": 1,
          "desc": "Use CVE-2026-46333 and CVE-2026-31431 to change any user's password.",
          "createdAt": "2026-05-17",
          "hasCode": true
        }
      ],
      "epss": 0.0138,
      "epssPercentile": 0.69112,
      "source": "poc",
      "mitreUrl": "https://nvd.nist.gov/vuln/detail/CVE-2026-46333",
      "research": [
        {
          "url": "https://blog.qualys.com/vulnerabilities-threat-research/2026/05/20/cve-2026-46333-local-root-privilege-escalation-and-credential-disclosure-in-the-linux-kernel-ptrace-path",
          "type": "writeup",
          "source": "Qualys",
          "note": "ptrace LPE + credential disclosure analysis"
        },
        {
          "url": "https://www.gblock.app/articles/cve-2026-46333-linux-kernel-ptrace-9-year-root-may-2026",
          "type": "writeup",
          "source": "gblock",
          "note": "9-year-old ptrace bug grants root"
        },
        {
          "url": "https://blog.cloudlinux.com/ptrace-exit-race-cve-2026-46333-mitigation-and-kernel-update",
          "type": "writeup",
          "source": "CloudLinux",
          "note": "ptrace exit-race mitigation"
        },
        {
          "url": "https://ubuntu.com/security/CVE-2026-46333",
          "type": "writeup",
          "source": "Ubuntu",
          "note": "Vendor advisory"
        }
      ],
      "x": {
        "mentions": 11,
        "aliases": [
          "ssh-keysign-pwn"
        ],
        "posts": [
          {
            "handle": "TheHackersNews",
            "followers": 1475357,
            "likes": 265,
            "createdAt": "2026-05-21",
            "url": "https://x.com/TheHackersNews/status/2057367495640793173",
            "github": [],
            "origin": false
          },
          {
            "handle": "__kokumoto",
            "followers": 7498,
            "likes": 72,
            "createdAt": "2026-05-17",
            "url": "https://x.com/__kokumoto/status/2056134331836596311",
            "github": [],
            "origin": false
          },
          {
            "handle": "ostechnix",
            "followers": 1594,
            "likes": 4,
            "createdAt": "2026-05-18",
            "url": "https://x.com/ostechnix/status/2056331032593649902",
            "github": [],
            "origin": false
          },
          {
            "handle": "yidabuilds",
            "followers": 14803,
            "likes": 3,
            "createdAt": "2026-05-23",
            "url": "https://x.com/yidabuilds/status/2058197257233555609",
            "github": [],
            "origin": false
          },
          {
            "handle": "asadeddin",
            "followers": 886,
            "likes": 2,
            "createdAt": "2026-05-22",
            "url": "https://x.com/asadeddin/status/2057892406432022976",
            "github": [],
            "origin": false
          },
          {
            "handle": "lnxsec",
            "followers": 4390,
            "likes": 1,
            "createdAt": "2026-05-17",
            "url": "https://x.com/lnxsec/status/2056109494006915150",
            "github": [],
            "origin": false
          },
          {
            "handle": "jo_sekiko",
            "followers": 4297,
            "likes": 0,
            "createdAt": "2026-05-23",
            "url": "https://x.com/jo_sekiko/status/2058017977874964681",
            "github": [],
            "origin": false
          }
        ]
      },
      "aliases": [
        "ssh-keysign-pwn"
      ],
      "researchers": [],
      "bsky": {
        "mentions": 26,
        "posts": [
          {
            "handle": "cadey.pony.social.ap.brid.gy",
            "displayName": "Xe :verified:",
            "likes": 4,
            "reposts": 21,
            "replies": 2,
            "createdAt": "2026-05-15",
            "url": "https://bsky.app/profile/cadey.pony.social.ap.brid.gy/post/3mluaytg3rcl2",
            "origin": true,
            "authority": false,
            "github": [
              {
                "url": "https://github.com/0xdeadbeefnetwork/ssh-keysign-pwn/",
                "hasCode": true
              }
            ]
          },
          {
            "handle": "chrisshort.net",
            "displayName": "Chris Short",
            "likes": 4,
            "reposts": 3,
            "replies": 0,
            "createdAt": "2026-05-18",
            "url": "https://bsky.app/profile/chrisshort.net/post/3mm53nxu6lv2i",
            "origin": true,
            "authority": false,
            "github": [
              {
                "url": "https://github.com/0xdeadbeefnetwork/ssh-keysign-pwn",
                "hasCode": true
              }
            ]
          },
          {
            "handle": "xeiaso.net",
            "displayName": "Xe",
            "likes": 56,
            "reposts": 15,
            "replies": 6,
            "createdAt": "2026-05-15",
            "url": "https://bsky.app/profile/xeiaso.net/post/3mluaynzfqk2f",
            "origin": false,
            "authority": false,
            "github": [
              {
                "url": "https://github.com/0xdeadbeefnetwork/ssh-keysign-pwn/",
                "hasCode": true
              }
            ]
          },
          {
            "handle": "vincent.bernat.ch",
            "displayName": "Vincent Bernat",
            "likes": 5,
            "reposts": 1,
            "replies": 0,
            "createdAt": "2026-05-15",
            "url": "https://bsky.app/profile/vincent.bernat.ch/post/3mluwvyglzc2v",
            "origin": false,
            "authority": false,
            "github": [
              {
                "url": "https://github.com/0xdeadbeefnetwork/ssh-keysign-pwn/",
                "hasCode": true
              }
            ]
          },
          {
            "handle": "c3iq.bsky.social",
            "displayName": "Owen 🐧",
            "likes": 2,
            "reposts": 2,
            "replies": 0,
            "createdAt": "2026-05-15",
            "url": "https://bsky.app/profile/c3iq.bsky.social/post/3mlve52afv225",
            "origin": false,
            "authority": false,
            "github": [
              {
                "url": "https://github.com/0xdeadbeefnetwork/ssh-keysign-pwn",
                "hasCode": true
              }
            ]
          },
          {
            "handle": "almalinux.org",
            "displayName": "AlmaLinux",
            "likes": 4,
            "reposts": 1,
            "replies": 0,
            "createdAt": "2026-05-22",
            "url": "https://bsky.app/profile/almalinux.org/post/3mmhkc55lud24",
            "origin": false,
            "authority": false,
            "github": []
          }
        ]
      }
    },
    {
      "cve": "CVE-2026-21509",
      "title": "Reliance on untrusted inputs in a security decision in Microsoft Office allows an…",
      "category": "Recall",
      "vendor": null,
      "exploited": true,
      "publiclyDisclosed": true,
      "cvss": 7.8,
      "cvssVector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
      "severity": "HIGH",
      "impact": null,
      "products": [],
      "productCount": 0,
      "faq": "Reliance on untrusted inputs in a security decision in Microsoft Office allows an unauthorized attacker to bypass a security feature locally.",
      "pocConfidence": "confirmed",
      "pocCount": 4,
      "pocTopStars": 18,
      "pocRepos": [
        {
          "url": "https://github.com/gavz/CVE-2026-21509-PoC",
          "stars": 18,
          "desc": "Educational PoC for CVE‑2026‑21509 (Microsoft Office security feature bypass). Generates a harmless DOCX with dummy OLE artifacts to study EDR/AV visibility. No",
          "createdAt": "2026-01-29",
          "hasCode": true
        },
        {
          "url": "https://github.com/kimstars/Ashwesker-CVE-2026-21509",
          "stars": 10,
          "desc": "CVE-2026-21509",
          "createdAt": "2026-01-27",
          "hasCode": true
        },
        {
          "url": "https://github.com/SimoesCTT/CTT-MICROSOFT-OFFICE-OLE-MANIFOLD-BYPASS-CVE-2026-21509",
          "stars": 3,
          "desc": "CVE-2026-21509 is a critical bypass in the Microsoft Office OLE (Object Linking and Embedding) validation engine. While standard \"laminar\" exploits attempt to m",
          "createdAt": "2026-02-01",
          "hasCode": true
        },
        {
          "url": "https://github.com/SimoesCTT/CTT-NFS-Vortex-RCE",
          "stars": 3,
          "desc": "New Physics Disclosure This repository contains a full weaponized exploit for **CVE-2026-21509**, targeting the Windows Network File System (NFSv4.1) kernel-mod",
          "createdAt": "2026-01-31",
          "hasCode": true
        }
      ],
      "epss": 0.72152,
      "epssPercentile": 0.99368,
      "source": "poc",
      "mitreUrl": "https://nvd.nist.gov/vuln/detail/CVE-2026-21509",
      "telegram": {
        "mentions": 8,
        "posts": [
          {
            "channel": "GOTOCVE",
            "channelTitle": "GO-TO CVE",
            "tier": "feed",
            "date": "2026-02-04",
            "views": 1309,
            "forwards": 33,
            "url": "https://t.me/GOTOCVE/3199",
            "text": "این آسیب پذیری رو گذاشته بودن ۶۰ هزار دلار تو یکی از فروم ها چند ماه پیش : هکرهای مرتبط با دولت روسیه از آسیب پذیری روز صفر CVE-2026-21509 در محصولات Office علیه اهدافی در اوکراین، اسلواکی و رومانی و لهستان استفاده کردند. https://www.zscaler.com/blogs/security-research/apt28-leverages-cve-2026-21509-operation-neusploit https://t.me/arvinclub3",
            "github": [],
            "origin": false
          },
          {
            "channel": "thehackernews",
            "channelTitle": "The Hacker News",
            "tier": "news",
            "date": "2026-01-27",
            "views": 15834,
            "forwards": 76,
            "url": "https://t.me/thehackernews/8286",
            "text": "🛑 URGENT: Microsoft rushed out out-of-band fixes for an actively exploited Office zero-day. CVE-2026-21509 (CVSS 7.8) lets attackers bypass Office security using a malicious file that must be opened by the victim. 🔗 Details → https://thehackernews.com/2026/01/microsoft-issues-emergency-patch-for.html",
            "github": [],
            "origin": false
          }
        ]
      },
      "research": [],
      "aliases": [],
      "researchers": [],
      "x": {
        "mentions": 0,
        "aliases": [],
        "posts": []
      },
      "bsky": {
        "mentions": 25,
        "posts": [
          {
            "handle": "infosec.skyfleet.blue",
            "displayName": "InfoSec",
            "likes": 0,
            "reposts": 0,
            "replies": 0,
            "createdAt": "2026-01-27",
            "url": "https://bsky.app/profile/infosec.skyfleet.blue/post/3mdfaa37o2726",
            "origin": false,
            "authority": true,
            "github": []
          },
          {
            "handle": "hackmanac.com",
            "displayName": "Hackmanac",
            "likes": 3,
            "reposts": 1,
            "replies": 1,
            "createdAt": "2026-01-28",
            "url": "https://bsky.app/profile/hackmanac.com/post/3mdhryniizu2r",
            "origin": false,
            "authority": false,
            "github": []
          },
          {
            "handle": "jpmahony.bsky.social",
            "displayName": "Jim Mahony",
            "likes": 3,
            "reposts": 0,
            "replies": 0,
            "createdAt": "2026-02-02",
            "url": "https://bsky.app/profile/jpmahony.bsky.social/post/3mdvwx3cksc2w",
            "origin": false,
            "authority": false,
            "github": []
          },
          {
            "handle": "780thmibdecyber.bsky.social",
            "displayName": "780th Military Intelligence Brigade (Cyber)",
            "likes": 1,
            "reposts": 0,
            "replies": 1,
            "createdAt": "2026-02-03",
            "url": "https://bsky.app/profile/780thmibdecyber.bsky.social/post/3mdxgetgimc26",
            "origin": false,
            "authority": false,
            "github": []
          },
          {
            "handle": "getpokemon7.bsky.social",
            "displayName": "まりーん",
            "likes": 0,
            "reposts": 0,
            "replies": 1,
            "createdAt": "2026-02-04",
            "url": "https://bsky.app/profile/getpokemon7.bsky.social/post/3mdzvyjmzmk2k",
            "origin": false,
            "authority": false,
            "github": []
          },
          {
            "handle": "undercodenews.bsky.social",
            "displayName": "Undercode News",
            "likes": 0,
            "reposts": 1,
            "replies": 0,
            "createdAt": "2026-01-26",
            "url": "https://bsky.app/profile/undercodenews.bsky.social/post/3mddzlmx7kq2b",
            "origin": false,
            "authority": false,
            "github": []
          }
        ]
      }
    },
    {
      "cve": "CVE-2026-3888",
      "title": "Local privilege escalation in snapd on Linux allows local attackers to get root…",
      "category": "Recall",
      "vendor": null,
      "exploited": false,
      "publiclyDisclosed": true,
      "cvss": 7.8,
      "cvssVector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H",
      "severity": "HIGH",
      "impact": null,
      "products": [],
      "productCount": 0,
      "faq": "Local privilege escalation in snapd on Linux allows local attackers to get root privilege by re-creating snap's private /tmp directory when systemd-tmpfiles is configured to automatically clean up this directory. This issue affects Ubuntu 16.04 LTS, 18.04 LTS, 20.04 LTS, 22.04 LTS, and 24.04 LTS.",
      "pocConfidence": "confirmed",
      "pocCount": 4,
      "pocTopStars": 15,
      "pocRepos": [
        {
          "url": "https://github.com/TheCyberGeek/CVE-2026-3888-snap-confine-systemd-tmpfiles-LPE",
          "stars": 15,
          "desc": "",
          "createdAt": "2026-03-23",
          "hasCode": true
        },
        {
          "url": "https://github.com/nomaisthere/CVE-2026-3888",
          "stars": 5,
          "desc": "Linux LPE via snap-confine + systemd-tmpfiles, explained in depth",
          "createdAt": "2026-03-23",
          "hasCode": true
        },
        {
          "url": "https://github.com/netw0rk7/CVE-2026-3888-PoC",
          "stars": 2,
          "desc": "",
          "createdAt": "2026-03-20",
          "hasCode": true
        },
        {
          "url": "https://github.com/fevar54/CVE-2026-3888-POC-all-from-the-Qualys-platform.",
          "stars": 2,
          "desc": "This script demonstrates a race condition vulnerability in snapd that allows a local, unprivileged user to gain root privileges. The exploit works by recreating",
          "createdAt": "2026-03-18",
          "hasCode": true
        },
        {
          "url": "https://github.com/karimelsheikh1/HTB-Snapped-Writeup",
          "stars": 1,
          "desc": "HTB Snapped — Hard Linux machine writeup. CVE-2026-27944 (Nginx UI unauthenticated backup disclosure) chained with CVE-2026-3888 (snapd race condition LPE) to a",
          "createdAt": "2026-05-07",
          "hasCode": false
        }
      ],
      "epss": 0.00383,
      "epssPercentile": 0.30653,
      "source": "poc",
      "mitreUrl": "https://nvd.nist.gov/vuln/detail/CVE-2026-3888",
      "research": [],
      "aliases": [],
      "researchers": [],
      "x": {
        "mentions": 0,
        "aliases": [],
        "posts": []
      },
      "bsky": {
        "mentions": 17,
        "posts": [
          {
            "handle": "infosec.skyfleet.blue",
            "displayName": "InfoSec",
            "likes": 2,
            "reposts": 0,
            "replies": 0,
            "createdAt": "2026-03-18",
            "url": "https://bsky.app/profile/infosec.skyfleet.blue/post/3mhdg66eri22j",
            "origin": false,
            "authority": true,
            "github": []
          },
          {
            "handle": "0xdf.bsky.social",
            "displayName": "0xdf",
            "likes": 3,
            "reposts": 2,
            "replies": 0,
            "createdAt": "2026-04-01",
            "url": "https://bsky.app/profile/0xdf.bsky.social/post/3migk26go5a25",
            "origin": false,
            "authority": false,
            "github": []
          },
          {
            "handle": "feed.igeek.gamer-geek-news.com.ap.brid.gy",
            "displayName": "input",
            "likes": 1,
            "reposts": 1,
            "replies": 0,
            "createdAt": "2026-03-21",
            "url": "https://bsky.app/profile/feed.igeek.gamer-geek-news.com.ap.brid.gy/post/3mhl7b4qr53p2",
            "origin": false,
            "authority": false,
            "github": []
          },
          {
            "handle": "ostechnix.bsky.social",
            "displayName": "OSTechNix",
            "likes": 2,
            "reposts": 0,
            "replies": 0,
            "createdAt": "2026-03-19",
            "url": "https://bsky.app/profile/ostechnix.bsky.social/post/3mhfnuirzwc2r",
            "origin": false,
            "authority": false,
            "github": []
          },
          {
            "handle": "aprosdoketon.bsky.social",
            "displayName": "борщ з ананасами",
            "likes": 2,
            "reposts": 0,
            "replies": 0,
            "createdAt": "2026-03-19",
            "url": "https://bsky.app/profile/aprosdoketon.bsky.social/post/3mhfd266tvc2k",
            "origin": false,
            "authority": false,
            "github": []
          },
          {
            "handle": "hacker.at.thenote.app",
            "displayName": "Hacker & Security News",
            "likes": 1,
            "reposts": 0,
            "replies": 1,
            "createdAt": "2026-03-19",
            "url": "https://bsky.app/profile/hacker.at.thenote.app/post/3mheypg2vcs23",
            "origin": false,
            "authority": false,
            "github": []
          }
        ]
      }
    },
    {
      "cve": "CVE-2026-48908",
      "title": "A vulnerability in SP Page Builder for Joomla allows unauthenticated users to upload…",
      "category": "Recall",
      "vendor": null,
      "exploited": true,
      "publiclyDisclosed": true,
      "cvss": 9.8,
      "cvssVector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "severity": "CRITICAL",
      "impact": null,
      "products": [],
      "productCount": 0,
      "faq": "A vulnerability in SP Page Builder for Joomla allows unauthenticated users to upload arbitrary files, ultimately resulting in the upload and execution of PHP code.",
      "pocConfidence": "confirmed",
      "pocCount": 4,
      "pocTopStars": 12,
      "pocRepos": [
        {
          "url": "https://github.com/papageo75/CVE-2026-48908-PoC",
          "stars": 12,
          "desc": "Unauthenticated RCE PoC for CVE-2026-48908 — SP Page Builder for Joomla (≤ 6.6.1): arbitrary file upload via asset.uploadCustomIcon. Self-cleaning, token-guarde",
          "createdAt": "2026-06-22",
          "hasCode": true
        },
        {
          "url": "https://github.com/0xBlackash/CVE-2026-48908",
          "stars": 1,
          "desc": "CVE-2026-48908",
          "createdAt": "2026-06-24",
          "hasCode": true
        },
        {
          "url": "https://github.com/gagaltotal/CVE-2026-48908-SP-Page-Builder-Joomla",
          "stars": 0,
          "desc": "CVE-2026-48908 - SP Page Builder Joomla Unauthenticated RCE",
          "createdAt": "2026-06-24",
          "hasCode": true
        },
        {
          "url": "https://github.com/ayiezola/CVE-2026-48908",
          "stars": 0,
          "desc": "Unauthenticated RCE PoC for CVE-2026-48908  SP Page Builder (Joomla) arbitrary file upload and remote code execution exploit with mass scaning support.",
          "createdAt": "2026-06-28",
          "hasCode": true
        }
      ],
      "epss": 0.01569,
      "epssPercentile": 0.72649,
      "source": "poc",
      "mitreUrl": "https://nvd.nist.gov/vuln/detail/CVE-2026-48908",
      "telegram": {
        "mentions": 0,
        "posts": []
      },
      "research": [],
      "aliases": [],
      "researchers": [],
      "x": {
        "mentions": 76,
        "aliases": [],
        "posts": [
          {
            "handle": "vutruso",
            "followers": 38,
            "likes": 0,
            "createdAt": "2026-07-08",
            "url": "https://x.com/vutruso/status/2074690046486290926",
            "github": [
              {
                "url": "https://github.com/V4bel/Januscape",
                "hasCode": true
              }
            ],
            "origin": false
          },
          {
            "handle": "nebusecurity",
            "followers": 4500,
            "likes": 240,
            "createdAt": "2026-07-08",
            "url": "https://x.com/nebusecurity/status/2074663573742338256",
            "github": [],
            "origin": false
          },
          {
            "handle": "__kokumoto",
            "followers": 7578,
            "likes": 7,
            "createdAt": "2026-07-08",
            "url": "https://x.com/__kokumoto/status/2074698589713154281",
            "github": [],
            "origin": false
          },
          {
            "handle": "yousukezan",
            "followers": 14384,
            "likes": 6,
            "createdAt": "2026-07-08",
            "url": "https://x.com/yousukezan/status/2074650902166913222",
            "github": [],
            "origin": false
          },
          {
            "handle": "ridvanyagli",
            "followers": 1120,
            "likes": 6,
            "createdAt": "2026-07-08",
            "url": "https://x.com/ridvanyagli/status/2074701200167952860",
            "github": [],
            "origin": false
          },
          {
            "handle": "Daily_CyberSec",
            "followers": 12430,
            "likes": 5,
            "createdAt": "2026-07-08",
            "url": "https://x.com/Daily_CyberSec/status/2074678524191855020",
            "github": [],
            "origin": false
          },
          {
            "handle": "oss_security",
            "followers": 4646,
            "likes": 4,
            "createdAt": "2026-07-08",
            "url": "https://x.com/oss_security/status/2074685116626907570",
            "github": [],
            "origin": false
          },
          {
            "handle": "ohhara_shiojiri",
            "followers": 2004,
            "likes": 1,
            "createdAt": "2026-07-08",
            "url": "https://x.com/ohhara_shiojiri/status/2074727301179408802",
            "github": [],
            "origin": false
          }
        ]
      },
      "bsky": {
        "mentions": 43,
        "posts": [
          {
            "handle": "infosec.skyfleet.blue",
            "displayName": "InfoSec",
            "likes": 5,
            "reposts": 1,
            "replies": 0,
            "createdAt": "2026-07-02",
            "url": "https://bsky.app/profile/infosec.skyfleet.blue/post/3mpnkwum44r2x",
            "origin": true,
            "authority": true,
            "github": []
          },
          {
            "handle": "bleepingcomputer.com",
            "displayName": "BleepingComputer",
            "likes": 4,
            "reposts": 2,
            "replies": 0,
            "createdAt": "2026-07-01",
            "url": "https://bsky.app/profile/bleepingcomputer.com/post/3mpmd2ruarv2l",
            "origin": true,
            "authority": true,
            "github": []
          },
          {
            "handle": "campuscodi.risky.biz",
            "displayName": "Catalin Cimpanu",
            "likes": 2,
            "reposts": 1,
            "replies": 2,
            "createdAt": "2026-07-03",
            "url": "https://bsky.app/profile/campuscodi.risky.biz/post/3mpq6imguic2y",
            "origin": true,
            "authority": true,
            "github": []
          },
          {
            "handle": "trinacriatech.bsky.social",
            "displayName": null,
            "likes": 2,
            "reposts": 0,
            "replies": 0,
            "createdAt": "2026-07-06",
            "url": "https://bsky.app/profile/trinacriatech.bsky.social/post/3mpyxq7y6oc2z",
            "origin": true,
            "authority": false,
            "github": []
          },
          {
            "handle": "ahmandonk.bsky.social",
            "displayName": "Ahmandonk",
            "likes": 2,
            "reposts": 0,
            "replies": 0,
            "createdAt": "2026-07-05",
            "url": "https://bsky.app/profile/ahmandonk.bsky.social/post/3mpvwgjir5j2r",
            "origin": true,
            "authority": false,
            "github": []
          },
          {
            "handle": "blindthoughts.bsky.social",
            "displayName": "blindthoughts.bsky.social",
            "likes": 2,
            "reposts": 0,
            "replies": 0,
            "createdAt": "2026-07-02",
            "url": "https://bsky.app/profile/blindthoughts.bsky.social/post/3mpnbpwhb5427",
            "origin": true,
            "authority": false,
            "github": []
          }
        ]
      }
    },
    {
      "cve": "CVE-2026-4480",
      "title": "A flaw was found in the Samba printing subsystem. Samba passes the client-controlled…",
      "category": "Recall",
      "vendor": null,
      "exploited": false,
      "publiclyDisclosed": true,
      "cvss": 9,
      "cvssVector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H",
      "severity": "CRITICAL",
      "impact": null,
      "products": [],
      "productCount": 0,
      "faq": "A flaw was found in the Samba printing subsystem. Samba passes the client-controlled job description string to the command configured with the \"print command\" setting via the \"%J\"\nsubstitution character without escaping shell meta characters. A remote attacker could exploit this vulnerability by sending a specially crafted print job description that contains unescaped shell characters. This could lead to remote code execution on the affected system.",
      "pocConfidence": "confirmed",
      "pocCount": 4,
      "pocTopStars": 12,
      "pocRepos": [
        {
          "url": "https://github.com/TheCyberGeek/CVE-2026-4480-PoC",
          "stars": 12,
          "desc": "",
          "createdAt": "2026-06-05",
          "hasCode": true
        },
        {
          "url": "https://github.com/robinxiang/CVE-2026-4480",
          "stars": 1,
          "desc": "Exploit CVE-2026-4480",
          "createdAt": "2026-06-07",
          "hasCode": true
        },
        {
          "url": "https://github.com/CarlosEduardoPM/CVE-2026-4480-POC",
          "stars": 1,
          "desc": "smb spooler to RCE",
          "createdAt": "2026-06-08",
          "hasCode": true
        },
        {
          "url": "https://github.com/Vusal777/CVE-2026-4480-exploit-poc",
          "stars": 0,
          "desc": "This is an exploit poc for CVE-2026-4480",
          "createdAt": "2026-06-16",
          "hasCode": true
        }
      ],
      "epss": 0.12797,
      "epssPercentile": 0.95857,
      "source": "poc",
      "mitreUrl": "https://nvd.nist.gov/vuln/detail/CVE-2026-4480",
      "research": [
        {
          "url": "https://www.samba.org/samba/security/CVE-2026-4480.html",
          "type": "writeup",
          "source": "Samba",
          "note": "Official advisory, %J print job shell injection"
        },
        {
          "url": "https://www.hackthebox.com/blog/cve-2026-4480-samba-rce-vulnerability",
          "type": "writeup",
          "source": "Hack The Box",
          "note": "War Room: print job name as shell command"
        },
        {
          "url": "https://www.thehackerwire.com/samba-printing-subsystem-rce-via-unescaped-shell-metacharacters/",
          "type": "writeup",
          "source": "TheHackerWire",
          "note": "RCE via unescaped shell metachars"
        },
        {
          "url": "https://cybersecuritynews.com/samba-rce-vulnerability/",
          "type": "writeup",
          "source": "Cyber Security News",
          "note": "Critical Samba RCE coverage"
        }
      ],
      "x": {
        "mentions": 10,
        "posts": [
          {
            "handle": "GOVCERT_CZ",
            "followers": 4220,
            "likes": 7,
            "createdAt": "2026-06-01",
            "url": "https://x.com/GOVCERT_CZ/status/2061444263922053375",
            "origin": false,
            "github": []
          },
          {
            "handle": "HTBJill",
            "followers": 258,
            "likes": 1,
            "createdAt": "2026-06-05",
            "url": "https://x.com/HTBJill/status/2062900800897069227",
            "origin": false,
            "github": []
          },
          {
            "handle": "ptdbugs",
            "followers": 1247,
            "likes": 0,
            "createdAt": "2026-06-06",
            "url": "https://x.com/ptdbugs/status/2063174710200770964",
            "origin": false,
            "github": []
          },
          {
            "handle": "iototsecnews",
            "followers": 491,
            "likes": 0,
            "createdAt": "2026-06-05",
            "url": "https://x.com/iototsecnews/status/2062714708839616592",
            "origin": false,
            "github": []
          },
          {
            "handle": "CERTpy",
            "followers": 6660,
            "likes": 0,
            "createdAt": "2026-06-03",
            "url": "https://x.com/CERTpy/status/2062173145201619335",
            "origin": false,
            "github": []
          },
          {
            "handle": "threatcluster",
            "followers": 285,
            "likes": 0,
            "createdAt": "2026-06-02",
            "url": "https://x.com/threatcluster/status/2061689375688122641",
            "origin": false,
            "github": []
          },
          {
            "handle": "catnap707",
            "followers": 3469,
            "likes": 0,
            "createdAt": "2026-06-02",
            "url": "https://x.com/catnap707/status/2061661699611251028",
            "origin": false,
            "github": []
          },
          {
            "handle": "securityLab_jp",
            "followers": 408,
            "likes": 0,
            "createdAt": "2026-06-02",
            "url": "https://x.com/securityLab_jp/status/2061659319771529546",
            "origin": false,
            "github": []
          }
        ],
        "aliases": []
      },
      "bsky": {
        "mentions": 9,
        "posts": [
          {
            "handle": "blackhatnews.tokyo",
            "displayName": "blackhatnews.tokyo",
            "likes": 1,
            "reposts": 0,
            "replies": 0,
            "createdAt": "2026-05-29",
            "url": "https://bsky.app/profile/blackhatnews.tokyo/post/3mmy2vsqjpe2t",
            "origin": false,
            "authority": false,
            "github": []
          },
          {
            "handle": "o2cloud.bsky.social",
            "displayName": "CVE by o2Cloud",
            "likes": 0,
            "reposts": 0,
            "replies": 1,
            "createdAt": "2026-05-27",
            "url": "https://bsky.app/profile/o2cloud.bsky.social/post/3mmtq4rm6nz2c",
            "origin": false,
            "authority": false,
            "github": []
          },
          {
            "handle": "slackers.it",
            "displayName": "Slackers",
            "likes": 0,
            "reposts": 0,
            "replies": 1,
            "createdAt": "2026-05-27",
            "url": "https://bsky.app/profile/slackers.it/post/3mmsfyl27rh2e",
            "origin": false,
            "authority": false,
            "github": []
          },
          {
            "handle": "infosecbot.bsky.social",
            "displayName": "Botty.bot",
            "likes": 0,
            "reposts": 0,
            "replies": 0,
            "createdAt": "2026-06-08",
            "url": "https://bsky.app/profile/infosecbot.bsky.social/post/3mnrxsc26ks22",
            "origin": false,
            "authority": false,
            "github": []
          },
          {
            "handle": "securitylab-jp.bsky.social",
            "displayName": "セキュリティ対策Lab",
            "likes": 0,
            "reposts": 0,
            "replies": 0,
            "createdAt": "2026-06-02",
            "url": "https://bsky.app/profile/securitylab-jp.bsky.social/post/3mnbqpc2vnk2c",
            "origin": false,
            "authority": false,
            "github": []
          },
          {
            "handle": "cyberhub.blog",
            "displayName": "CyberHub",
            "likes": 0,
            "reposts": 0,
            "replies": 0,
            "createdAt": "2026-06-01",
            "url": "https://bsky.app/profile/cyberhub.blog/post/3mnb5eseps722",
            "origin": false,
            "authority": false,
            "github": []
          }
        ]
      },
      "telegram": {
        "mentions": 0,
        "posts": []
      },
      "aliases": [],
      "researchers": []
    },
    {
      "cve": "CVE-2026-8732",
      "title": "The WP Maps Pro plugin for WordPress is vulnerable to Privilege Escalation via…",
      "category": "Recall",
      "vendor": null,
      "exploited": false,
      "publiclyDisclosed": true,
      "cvss": 9.8,
      "cvssVector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "severity": "CRITICAL",
      "impact": null,
      "products": [],
      "productCount": 0,
      "faq": "The WP Maps Pro plugin for WordPress is vulnerable to Privilege Escalation via Administrator Account Creation in all versions up to, and including, 6.1.0. This is due to the wpgmp_temp_access_ajax AJAX action being registered with wp_ajax_nopriv_ and protected only by a nonce check using the fc-call-nonce nonce, which is publicly embedded into every frontend page via wp_localize_script as the nonce field of the wpgmp_local JavaScript object, rendering the check ineffective as an access control mechanism. This makes it possible for unauthenticated attackers to invoke the wpgmp_temp_access_support handler with check_temp=false, which unconditionally creates a new WordPress user with the hardcoded role of administrator via wp_insert_user() and returns a magic login URL that, when visited, calls wp_set_auth_cookie() to fully authenticate the attacker as the newly created administrator, resulting in complete site takeover.",
      "pocConfidence": "confirmed",
      "pocCount": 4,
      "pocTopStars": 8,
      "pocRepos": [
        {
          "url": "https://github.com/p3Nt3st3r-sTAr/CVE-2026-8732-POC",
          "stars": 8,
          "desc": "",
          "createdAt": "2026-06-01",
          "hasCode": true
        },
        {
          "url": "https://github.com/Jenderal92/CVE-2026-8732",
          "stars": 3,
          "desc": "WP Maps Pro <= 6.1.0 - Unauthenticated Privilege Escalation via Administrator Account Creation to wpgmp_temp_access_ajax AJAX Action",
          "createdAt": "2026-05-30",
          "hasCode": true
        },
        {
          "url": "https://github.com/xShadow-Here/CVE-2026-8732",
          "stars": 0,
          "desc": "WP Maps Pro <= 6.1.0 - Unauthenticated Privilege Escalation via Administrator Account Creation",
          "createdAt": "2026-05-30",
          "hasCode": true
        },
        {
          "url": "https://github.com/zycoder0day/CVE-2026-8732",
          "stars": 0,
          "desc": "CVE-2026-8732 | WP Maps Pro <= 6.1.0 | Unauthenticated Privilege Escalation",
          "createdAt": "2026-05-30",
          "hasCode": true
        },
        {
          "url": "https://github.com/HORKimhab/CVE-2026-8732",
          "stars": 0,
          "desc": "CVE-2026-8732 - Draft (WordPress)",
          "createdAt": "2026-06-01",
          "hasCode": false
        },
        {
          "url": "https://github.com/Diznev/CVE-2026-8732-EXPLOIT",
          "stars": 0,
          "desc": "PoC CVE-2026-8732 (WP Maps Pro <= 6.1.0)",
          "createdAt": "2026-06-04",
          "hasCode": false
        }
      ],
      "epss": 0.19272,
      "epssPercentile": 0.97039,
      "source": "poc",
      "mitreUrl": "https://nvd.nist.gov/vuln/detail/CVE-2026-8732",
      "research": [
        {
          "url": "https://github.com/xShadow-Here/CVE-2026-8732",
          "type": "poc",
          "source": "xShadow-Here",
          "note": "Unauth priv-esc via admin account creation PoC",
          "hasCode": true
        },
        {
          "url": "https://threat-modeling.com/wp-maps-pro-wordpress-plugin-privilege-escalation-cve-2026-8732/",
          "type": "writeup",
          "source": "Threat-Modeling.com",
          "note": "Actively exploited, rogue admin creation"
        },
        {
          "url": "https://blog.toolslib.net/2026/06/02/cve-2026-8732-wp-maps-pro-unauthenticated-admin-creation/",
          "type": "writeup",
          "source": "ToolsLib",
          "note": "wpgmp_temp_access_ajax nonce abuse detail"
        }
      ],
      "x": {
        "mentions": 4,
        "aliases": [],
        "posts": [
          {
            "handle": "redsecuretech",
            "followers": 61,
            "likes": 1,
            "createdAt": "2026-06-01",
            "url": "https://x.com/redsecuretech/status/2061425603492925904",
            "github": [],
            "origin": false
          },
          {
            "handle": "dailytechonx",
            "followers": 350,
            "likes": 0,
            "createdAt": "2026-06-02",
            "url": "https://x.com/dailytechonx/status/2061821415511203974",
            "github": [],
            "origin": false
          },
          {
            "handle": "EnigmaGlobalSW",
            "followers": 8,
            "likes": 0,
            "createdAt": "2026-06-01",
            "url": "https://x.com/EnigmaGlobalSW/status/2061459168976863395",
            "github": [],
            "origin": false
          },
          {
            "handle": "trinacriatech",
            "followers": 1,
            "likes": 0,
            "createdAt": "2026-06-02",
            "url": "https://x.com/trinacriatech/status/2061732193886446077",
            "github": [],
            "origin": false
          }
        ]
      },
      "bsky": {
        "mentions": 25,
        "posts": [
          {
            "handle": "ebibibibibibi.bsky.social",
            "displayName": "胡田@Microsoft MVP(2014~)&MCT / Masahiko Ebisuda",
            "likes": 3,
            "reposts": 2,
            "replies": 0,
            "createdAt": "2026-06-01",
            "url": "https://bsky.app/profile/ebibibibibibi.bsky.social/post/3mn6uwailfd2t",
            "origin": false,
            "authority": false,
            "github": []
          },
          {
            "handle": "thehackerwire.bsky.social",
            "displayName": "TheHackerWire",
            "likes": 2,
            "reposts": 2,
            "replies": 0,
            "createdAt": "2026-05-31",
            "url": "https://bsky.app/profile/thehackerwire.bsky.social/post/3mn4hsvyyos2h",
            "origin": false,
            "authority": false,
            "github": []
          },
          {
            "handle": "hendryadrian.bsky.social",
            "displayName": "Cybersecurity News Everyday",
            "likes": 1,
            "reposts": 1,
            "replies": 0,
            "createdAt": "2026-05-31",
            "url": "https://bsky.app/profile/hendryadrian.bsky.social/post/3mn5vvvc6vw2r",
            "origin": false,
            "authority": false,
            "github": []
          },
          {
            "handle": "trinacriatech.bsky.social",
            "displayName": null,
            "likes": 1,
            "reposts": 0,
            "replies": 0,
            "createdAt": "2026-06-02",
            "url": "https://bsky.app/profile/trinacriatech.bsky.social/post/3mnc7ny5x5c2n",
            "origin": false,
            "authority": false,
            "github": []
          },
          {
            "handle": "pmloik.bsky.social",
            "displayName": null,
            "likes": 0,
            "reposts": 1,
            "replies": 0,
            "createdAt": "2026-06-02",
            "url": "https://bsky.app/profile/pmloik.bsky.social/post/3mnbkhiii6g2s",
            "origin": false,
            "authority": false,
            "github": []
          },
          {
            "handle": "donwebmedia.bsky.social",
            "displayName": null,
            "likes": 1,
            "reposts": 0,
            "replies": 0,
            "createdAt": "2026-06-01",
            "url": "https://bsky.app/profile/donwebmedia.bsky.social/post/3mnb2ougudt2a",
            "origin": false,
            "authority": false,
            "github": []
          }
        ]
      },
      "telegram": {
        "mentions": 4,
        "posts": [
          {
            "channel": "thehackernews",
            "channelTitle": "The Hacker News",
            "tier": "news",
            "date": "2026-06-01",
            "views": 9611,
            "forwards": 18,
            "url": "https://t.me/thehackernews/9117",
            "text": "⚠️ Threat actors are actively exploiting a critical vulnerability in WP Maps Pro. CVE-2026-8732 (CVSS 9.8) lets unauthenticated attackers create admin accounts and take over sites. It affects all versions up to 6.1.0. Update to 6.1.1 now. Read: https://thehackernews.com/2026/06/critical-wp-maps-pro-flaw-actively.html",
            "github": [],
            "origin": false
          }
        ]
      },
      "aliases": [],
      "researchers": []
    },
    {
      "cve": "CVE-2026-31635",
      "title": "In the Linux kernel, the following vulnerability has been resolved: rxrpc: fix…",
      "category": "Recall",
      "vendor": null,
      "exploited": false,
      "publiclyDisclosed": true,
      "cvss": 7.5,
      "cvssVector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
      "severity": "HIGH",
      "impact": null,
      "products": [],
      "productCount": 0,
      "faq": "In the Linux kernel, the following vulnerability has been resolved:\n\nrxrpc: fix oversized RESPONSE authenticator length check\n\nrxgk_verify_response() decodes auth_len from the packet and is supposed\nto verify that it fits in the remaining bytes. The existing check is\ninverted, so oversized RESPONSE authenticators are accepted and passed\nto rxgk_decrypt_skb(), which can later reach skb_to_sgvec() with an\nimpossible length and hit BUG_ON(len).\n\nDecoded from the original latest-net reproduction logs with\nscripts/decode_stacktrace.sh:\n\nRIP: __skb_to_sgvec()\n  [net/core/skbuff.c:5285 (discriminator 1)]\nCall Trace:\n skb_to_sgvec() [net/core/skbuff.c:5305]\n rxgk_decrypt_skb() [net/rxrpc/rxgk_common.h:81]\n rxgk_verify_response() [net/rxrpc/rxgk.c:1268]\n rxrpc_process_connection()\n   [net/rxrpc/conn_event.c:266 net/rxrpc/conn_event.c:364\n    net/rxrpc/conn_event.c:386]\n process_one_work() [kernel/workqueue.c:3281]\n worker_thread()\n   [kernel/workqueue.c:3353 kernel/workqueue.c:3440]\n kthread() [kernel/kthread.c:436]\n ret_from_fork() [arch/x86/kernel/process.c:164]\n\nReject authenticator lengths that exceed the remaining packet payload.",
      "pocConfidence": "confirmed",
      "pocCount": 4,
      "pocTopStars": 4,
      "pocRepos": [
        {
          "url": "https://github.com/0xBlackash/CVE-2026-31635",
          "stars": 4,
          "desc": "CVE-2026-31635",
          "createdAt": "2026-05-19",
          "hasCode": true
        },
        {
          "url": "https://github.com/0xFuffM3/CVE-2026-31635-DirtyDecrypt",
          "stars": 2,
          "desc": "",
          "createdAt": "2026-05-21",
          "hasCode": true
        },
        {
          "url": "https://github.com/Lutfifakee-Project/CVE-2026-31635",
          "stars": 0,
          "desc": "Exploit for DirtyDecrypt - CVE-2026-31635 Local Privilege Escalation",
          "createdAt": "2026-05-20",
          "hasCode": true
        },
        {
          "url": "https://github.com/Koshmare-Blossom/DirtyDecrypt-go",
          "stars": 0,
          "desc": "A Go implementation of dirtydecrypt (CVE-2026-31635)",
          "createdAt": "2026-05-21",
          "hasCode": true
        },
        {
          "url": "https://github.com/aexdyhaxor/DirtyDecrypt",
          "stars": 0,
          "desc": "DirtyDecrypt PoC Released for Linux Kernel CVE-2026-31635 LPE Vulnerability",
          "createdAt": "2026-05-20",
          "hasCode": false
        }
      ],
      "epss": 0.00817,
      "epssPercentile": 0.53141,
      "source": "poc",
      "mitreUrl": "https://nvd.nist.gov/vuln/detail/CVE-2026-31635",
      "research": [
        {
          "url": "https://thehackernews.com/2026/05/dirtydecrypt-poc-released-for-linux.html",
          "type": "writeup",
          "source": "The Hacker News",
          "note": "DirtyDecrypt PoC released, RxGK LPE"
        },
        {
          "url": "https://moselwal.com/blog/dirtydecrypt-linux-kernel-rxgk-cve-2026-31635",
          "type": "writeup",
          "source": "Moselwal",
          "note": "DirtyDecrypt rxgk pagecache write LPE"
        },
        {
          "url": "https://github.com/advisories/GHSA-f5xm-f2m7-vrg6",
          "type": "writeup",
          "source": "GitHub Advisory",
          "note": "rxrpc inverted auth_len check, BUG_ON crash",
          "hasCode": null
        },
        {
          "url": "https://cyberpress.org/poc-code-dirtydecrypt-linux-kernel/",
          "type": "writeup",
          "source": "CyberPress",
          "note": "PoC exploit published"
        }
      ],
      "x": {
        "mentions": 10,
        "posts": [
          {
            "handle": "__kokumoto",
            "followers": 7498,
            "likes": 8,
            "createdAt": "2026-05-21",
            "url": "https://x.com/__kokumoto/status/2057598614105723302",
            "origin": false,
            "github": []
          },
          {
            "handle": "MisbarSec",
            "followers": 213,
            "likes": 3,
            "createdAt": "2026-05-23",
            "url": "https://x.com/MisbarSec/status/2058128484673695766",
            "origin": false,
            "github": []
          },
          {
            "handle": "CVEShield",
            "followers": 1708,
            "likes": 1,
            "createdAt": "2026-05-25",
            "url": "https://x.com/CVEShield/status/2058821840055783771",
            "origin": false,
            "github": []
          },
          {
            "handle": "lyrie_ai",
            "followers": 234,
            "likes": 0,
            "createdAt": "2026-06-07",
            "url": "https://x.com/lyrie_ai/status/2063421637794447367",
            "origin": false,
            "github": []
          },
          {
            "handle": "robbin0919",
            "followers": 37,
            "likes": 0,
            "createdAt": "2026-06-02",
            "url": "https://x.com/robbin0919/status/2061847693258023138",
            "origin": false,
            "github": []
          },
          {
            "handle": "Blogredorbita",
            "followers": 355,
            "likes": 0,
            "createdAt": "2026-05-26",
            "url": "https://x.com/Blogredorbita/status/2059263691304956189",
            "origin": false,
            "github": []
          }
        ],
        "aliases": []
      },
      "aliases": [
        "DirtyDecrypt"
      ],
      "researchers": [
        "Zellic"
      ],
      "bsky": {
        "mentions": 42,
        "posts": [
          {
            "handle": "infosec.skyfleet.blue",
            "displayName": "InfoSec",
            "likes": 3,
            "reposts": 0,
            "replies": 0,
            "createdAt": "2026-05-20",
            "url": "https://bsky.app/profile/infosec.skyfleet.blue/post/3mmbidxqtkl2j",
            "origin": true,
            "authority": true,
            "github": []
          },
          {
            "handle": "redsiege.com",
            "displayName": "Red Siege",
            "likes": 3,
            "reposts": 2,
            "replies": 0,
            "createdAt": "2026-05-18",
            "url": "https://bsky.app/profile/redsiege.com/post/3mm5ep7z5c227",
            "origin": true,
            "authority": false,
            "github": []
          },
          {
            "handle": "samilaiho.com",
            "displayName": "Sami Laiho",
            "likes": 2,
            "reposts": 0,
            "replies": 0,
            "createdAt": "2026-05-19",
            "url": "https://bsky.app/profile/samilaiho.com/post/3mm7gfps5f22e",
            "origin": true,
            "authority": false,
            "github": []
          },
          {
            "handle": "edwing.mstdn.moimeme.ca",
            "displayName": "Edwin G. :mapleleafroundel:",
            "likes": 1,
            "reposts": 1,
            "replies": 0,
            "createdAt": "2026-05-18",
            "url": "https://bsky.app/profile/edwing.mstdn.moimeme.ca/post/3mm4xypipj4g2",
            "origin": true,
            "authority": false,
            "github": []
          },
          {
            "handle": "getpokemon7.bsky.social",
            "displayName": "まりーん",
            "likes": 0,
            "reposts": 0,
            "replies": 1,
            "createdAt": "2026-06-09",
            "url": "https://bsky.app/profile/getpokemon7.bsky.social/post/3mnv4uhkxfk2u",
            "origin": true,
            "authority": false,
            "github": []
          },
          {
            "handle": "thenewoil.org",
            "displayName": "The New Oil",
            "likes": 1,
            "reposts": 0,
            "replies": 0,
            "createdAt": "2026-05-19",
            "url": "https://bsky.app/profile/thenewoil.org/post/3mm7irl46wej2",
            "origin": true,
            "authority": false,
            "github": []
          }
        ]
      }
    },
    {
      "cve": "CVE-2026-10520",
      "title": "An OS Command Injection vulnerability in Ivanti Sentry before the R10.5.2, R10.6.2…",
      "category": "Recall",
      "vendor": null,
      "exploited": true,
      "publiclyDisclosed": true,
      "cvss": 10,
      "cvssVector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H",
      "severity": "CRITICAL",
      "impact": null,
      "products": [],
      "productCount": 0,
      "faq": "An OS Command Injection vulnerability in Ivanti Sentry before the R10.5.2, R10.6.2 and R10.7.1 versions allows a remote unauthenticated user to achieve root-level remote code execution",
      "pocConfidence": "confirmed",
      "pocCount": 3,
      "pocTopStars": 13,
      "pocRepos": [
        {
          "url": "https://github.com/watchtowrlabs/watchTowr-vs-Ivanti-Sentry-RCE-CVE-2026-10520-CVE-2026-10523",
          "stars": 13,
          "desc": "",
          "createdAt": "2026-06-09",
          "hasCode": true
        },
        {
          "url": "https://github.com/0xBlackash/CVE-2026-10520",
          "stars": 4,
          "desc": "CVE-2026-10520",
          "createdAt": "2026-06-11",
          "hasCode": true
        },
        {
          "url": "https://github.com/error-inside/CVE-2026-10520",
          "stars": 0,
          "desc": "Root-Level RCE via OS Command Injection in Ivanti Sentry",
          "createdAt": "2026-06-18",
          "hasCode": true
        }
      ],
      "epss": 0.99041,
      "epssPercentile": 0.99927,
      "source": "poc",
      "mitreUrl": "https://nvd.nist.gov/vuln/detail/CVE-2026-10520",
      "research": [
        {
          "url": "https://labs.watchtowr.com/more-evidence-that-words-dont-mean-what-we-thought-they-meant-ivanti-sentry-pre-auth-os-command-injection-cve-2026-10520/",
          "type": "writeup",
          "source": "watchTowr Labs",
          "note": "Primary technical analysis, pre-auth RCE root via XML"
        },
        {
          "url": "https://github.com/watchtowrlabs/watchTowr-vs-Ivanti-Sentry-RCE-CVE-2026-10520-CVE-2026-10523",
          "type": "poc",
          "source": "watchTowr Labs (Sonny)",
          "note": "Working Python PoC; runs cmds via handleMessage endpoint",
          "hasCode": true
        },
        {
          "url": "https://github.com/0xBlackash/CVE-2026-10520",
          "type": "poc",
          "source": "0xBlackash (Ashraf Zaryouh)",
          "note": "PoC: pre-auth RCE + auth bypass (CVE-2026-10523) chained",
          "hasCode": true
        },
        {
          "url": "https://github.com/ogenich/CVE-2026-10520",
          "type": "detection",
          "source": "ogenich (GitHub)",
          "note": "Mass scanner; non-destructive detection across hosts",
          "hasCode": true
        },
        {
          "url": "https://horizon3.ai/attack-research/vulnerabilities/cve-2026-10520/",
          "type": "writeup",
          "source": "Horizon3.ai",
          "note": "Technical breakdown; XML commandexec payload analysis"
        },
        {
          "url": "https://www.rapid7.com/blog/post/etr-cve-2026-10520-cve-2026-10523-multiple-critical-vulnerabilities-affecting-ivanti-sentry/",
          "type": "writeup",
          "source": "Rapid7",
          "note": "ETR writeup; unauthenticated check in June 11 content"
        },
        {
          "url": "https://hub.ivanti.com/s/article/Security-Advisory-Ivanti-Sentry-CVE-2026-10520-CVE-2026-10523",
          "type": "detection",
          "source": "Ivanti (vendor advisory)",
          "note": "Official advisory; patch to R10.5.2/10.6.2/10.7.1"
        },
        {
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "type": "detection",
          "source": "CISA KEV",
          "note": "Added to KEV June 11 2026; federal patch deadline June 14"
        }
      ],
      "aliases": [],
      "researchers": [
        "Sonny_watchTowr"
      ],
      "x": {
        "mentions": 144,
        "aliases": [],
        "posts": [
          {
            "handle": "rxerium",
            "followers": 3665,
            "likes": 237,
            "createdAt": "2026-06-10",
            "url": "https://x.com/rxerium/status/2064659435956375874",
            "github": [
              {
                "url": "https://github.com/rxerium/rxerium-templates/blob/main/2026/CVE-2026-10520.yaml",
                "hasCode": true
              }
            ],
            "origin": false
          },
          {
            "handle": "piedpiper1616",
            "followers": 5517,
            "likes": 3,
            "createdAt": "2026-06-10",
            "url": "https://x.com/piedpiper1616/status/2064707841710264587",
            "github": [
              {
                "url": "https://github.com/watchtowrlabs/watchTowr-vs-Ivanti-Sentry-RCE-CVE-2026-10520-CVE-2026-10523",
                "hasCode": true
              }
            ],
            "origin": false
          },
          {
            "handle": "p3Nt3st3r_sTAr",
            "followers": 48,
            "likes": 0,
            "createdAt": "2026-06-10",
            "url": "https://x.com/p3Nt3st3r_sTAr/status/2064560700991676525",
            "github": [
              {
                "url": "https://github.com/p3Nt3st3r-sTAr/CVE-2026-10520-CVE-2026-10523",
                "hasCode": true
              }
            ],
            "origin": false
          },
          {
            "handle": "IntCyberDigest",
            "followers": 172813,
            "likes": 177,
            "createdAt": "2026-06-11",
            "url": "https://x.com/IntCyberDigest/status/2065016574180839774",
            "github": [],
            "origin": false
          },
          {
            "handle": "watchtowrcyber",
            "followers": 12089,
            "likes": 100,
            "createdAt": "2026-06-10",
            "url": "https://x.com/watchtowrcyber/status/2064511364375179457",
            "github": [],
            "origin": false
          },
          {
            "handle": "DefusedCyber",
            "followers": 7088,
            "likes": 33,
            "createdAt": "2026-06-10",
            "url": "https://x.com/DefusedCyber/status/2064639896254382543",
            "github": [],
            "origin": false
          },
          {
            "handle": "CISACyber",
            "followers": 298281,
            "likes": 30,
            "createdAt": "2026-06-11",
            "url": "https://x.com/CISACyber/status/2065160927905775836",
            "github": [],
            "origin": false
          },
          {
            "handle": "TheHackersNews",
            "followers": 1548858,
            "likes": 29,
            "createdAt": "2026-06-12",
            "url": "https://x.com/TheHackersNews/status/2065403605008658564",
            "github": [],
            "origin": false
          }
        ]
      },
      "bsky": {
        "mentions": 25,
        "posts": [
          {
            "handle": "shadowserver.bsky.social",
            "displayName": "The Shadowserver Foundation",
            "likes": 10,
            "reposts": 2,
            "replies": 1,
            "createdAt": "2026-06-10",
            "url": "https://bsky.app/profile/shadowserver.bsky.social/post/3mnxjknfsrc2k",
            "origin": false,
            "authority": true,
            "github": []
          },
          {
            "handle": "thecybermind.co",
            "displayName": "mikeransier.bsky.social",
            "likes": 1,
            "reposts": 0,
            "replies": 0,
            "createdAt": "2026-06-13",
            "url": "https://bsky.app/profile/thecybermind.co/post/3mo72n6w2er2n",
            "origin": false,
            "authority": true,
            "github": []
          },
          {
            "handle": "secdb.bsky.social",
            "displayName": "ZEN SecDB",
            "likes": 0,
            "reposts": 0,
            "replies": 0,
            "createdAt": "2026-06-11",
            "url": "https://bsky.app/profile/secdb.bsky.social/post/3mo24mw6gwu2a",
            "origin": false,
            "authority": true,
            "github": []
          },
          {
            "handle": "r-netsec-bot.bsky.social",
            "displayName": "/r/netsec",
            "likes": 1,
            "reposts": 1,
            "replies": 0,
            "createdAt": "2026-06-10",
            "url": "https://bsky.app/profile/r-netsec-bot.bsky.social/post/3mnviyh7lkg2h",
            "origin": false,
            "authority": false,
            "github": []
          },
          {
            "handle": "cyberlensai.bsky.social",
            "displayName": "CyberLens AI",
            "likes": 1,
            "reposts": 0,
            "replies": 0,
            "createdAt": "2026-06-12",
            "url": "https://bsky.app/profile/cyberlensai.bsky.social/post/3mo2v2mwuvf2i",
            "origin": false,
            "authority": false,
            "github": []
          },
          {
            "handle": "sagalinked.bsky.social",
            "displayName": "SagaLinked",
            "likes": 1,
            "reposts": 0,
            "replies": 0,
            "createdAt": "2026-06-12",
            "url": "https://bsky.app/profile/sagalinked.bsky.social/post/3mo4bkwxkch26",
            "origin": false,
            "authority": false,
            "github": []
          }
        ]
      },
      "telegram": {
        "mentions": 3,
        "posts": [
          {
            "channel": "p3Nt3st3rsTAr",
            "channelTitle": "[CVE Pentester] exploits forum",
            "tier": "underground",
            "date": "2026-06-10",
            "views": 243,
            "forwards": 1,
            "url": "https://t.me/p3Nt3st3rsTAr/45",
            "text": "https://github.com/p3Nt3st3r-sTAr/CVE-2026-10520-CVE-2026-10523",
            "github": [
              {
                "url": "https://github.com/p3Nt3st3r-sTAr/CVE-2026-10520-CVE-2026-10523",
                "hasCode": true
              }
            ],
            "origin": true
          },
          {
            "channel": "thehackernews",
            "channelTitle": "The Hacker News",
            "tier": "news",
            "date": "2026-06-12",
            "views": 7799,
            "forwards": 13,
            "url": "https://t.me/thehackernews/9225",
            "text": "UPDATE: Public PoC is now driving mass #Ivanti Sentry CVE-2026-10520 exploit attempts, with Shadowserver reporting at least two vulnerable instances already backdoored. CISA has added the flaw to KEV and ordered U.S. federal agencies to patch by June 14. Read more: https://thehackernews.com/2026/06/ivanti-fortinet-and-sap-release-patches.html",
            "github": [],
            "origin": false
          }
        ]
      }
    },
    {
      "cve": "CVE-2026-60137",
      "title": "WordPress 6.8.x before 6.8.6, 6.9.x before 6.9.5, and 7.0.x before 7.0.2 does not…",
      "category": "Recall",
      "vendor": null,
      "exploited": true,
      "publiclyDisclosed": true,
      "cvss": 5.9,
      "cvssVector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N",
      "severity": "MEDIUM",
      "impact": null,
      "products": [],
      "productCount": 0,
      "faq": "WordPress 6.8.x before 6.8.6, 6.9.x before 6.9.5, and 7.0.x before 7.0.2 does not properly sanitise the author__not_in parameter of WP_Query, which could allow SQL Injection when a plugin or theme passes untrusted input to the parameter.",
      "pocConfidence": "confirmed",
      "pocCount": 3,
      "pocTopStars": 8,
      "pocRepos": [
        {
          "url": "https://github.com/codeb0ssx/Ultimate-wp2shell",
          "stars": 8,
          "desc": "wp2shell — Pre-authentication RCE in WordPress Core (CVE-2026-60137 + CVE-2026-63030). Chains an SQL injection in author__not_in with batch-route confusion for ",
          "createdAt": "2026-07-18",
          "hasCode": true
        },
        {
          "url": "https://github.com/h4cd0c/wp2shell",
          "stars": 0,
          "desc": "wp2shell — Pre-authentication RCE in WordPress Core (CVE-2026-60137 + CVE-2026-63030). Chains an SQL injection in author__not_in with batch-route confusion for ",
          "createdAt": "2026-07-18",
          "hasCode": true
        },
        {
          "url": "https://github.com/yoerivegt/wp2shell-poc",
          "stars": 0,
          "desc": "wp2shell (CVE-2026-60137 / CVE-2026-63030)",
          "createdAt": "2026-07-18",
          "hasCode": true
        }
      ],
      "epss": 0.04026,
      "epssPercentile": 0.89474,
      "source": "poc",
      "mitreUrl": "https://nvd.nist.gov/vuln/detail/CVE-2026-60137",
      "research": [
        {
          "url": "https://github.com/Icex0/wp2shell-poc",
          "type": "poc",
          "source": "GitHub / Icex0",
          "note": "Full RCE chain PoC; most widely referenced",
          "hasCode": true
        },
        {
          "url": "https://github.com/0xsha/wp2shell",
          "type": "poc",
          "source": "GitHub / 0xsha",
          "note": "Unified stdlib-only PoC merging 6 public chains",
          "hasCode": true
        },
        {
          "url": "https://slcyber.io/research-center/wp2shell-pre-authentication-rce-in-wordpress-core",
          "type": "writeup",
          "source": "Searchlight Cyber / Adam Kues",
          "note": "Original discoverer advisory; no full technicals yet"
        },
        {
          "url": "https://github.com/ZephrFish/wp2shell-scanner",
          "type": "module",
          "source": "GitHub / ZephrFish",
          "note": "Scanner + Nuclei YAML: wp2shell-exposure.yaml",
          "hasCode": false
        },
        {
          "url": "https://labs.eye.security/wp2shell-defenders-guide/",
          "type": "writeup",
          "source": "Eye Security Research",
          "note": "Defender guide; verified Icex0 PoC end-to-end"
        },
        {
          "url": "https://www.vulncheck.com/blog/wp2shell",
          "type": "writeup",
          "source": "VulnCheck",
          "note": "Technical chain breakdown; 24+ PoCs confirmed"
        },
        {
          "url": "https://blog.zsec.uk/wp2shell-code-trace-deep-dive/",
          "type": "writeup",
          "source": "ZephrFish / ZephrSec",
          "note": "Deep-dive code trace; linked from scanner repo"
        },
        {
          "url": "https://wp2shell.com/",
          "type": "detection",
          "source": "Searchlight Cyber (wp2shell.com)",
          "note": "Official exposure checker; no exploit payload sent"
        }
      ],
      "aliases": [
        "WP2Shell",
        "wp2shell"
      ],
      "researchers": [
        "TF1T",
        "dtro",
        "haongo",
        "adamkues"
      ],
      "x": {
        "mentions": 102,
        "aliases": [
          "WP2Shell",
          "wp2shell"
        ],
        "posts": [
          {
            "handle": "elhackernet",
            "followers": 140895,
            "likes": 10,
            "createdAt": "2026-07-20",
            "url": "https://x.com/elhackernet/status/2079297919677857809",
            "github": [],
            "origin": true
          },
          {
            "handle": "connect24h",
            "followers": 4416,
            "likes": 8,
            "createdAt": "2026-07-20",
            "url": "https://x.com/connect24h/status/2079284178823344328",
            "github": [],
            "origin": true
          },
          {
            "handle": "Racer_Kamira",
            "followers": 11440,
            "likes": 5,
            "createdAt": "2026-07-20",
            "url": "https://x.com/Racer_Kamira/status/2079298320045056275",
            "github": [],
            "origin": true
          },
          {
            "handle": "siennawebdesign",
            "followers": 292,
            "likes": 3,
            "createdAt": "2026-07-20",
            "url": "https://x.com/siennawebdesign/status/2079342484493156445",
            "github": [],
            "origin": true
          },
          {
            "handle": "snyff",
            "followers": 20667,
            "likes": 2,
            "createdAt": "2026-07-20",
            "url": "https://x.com/snyff/status/2079336372310249667",
            "github": [],
            "origin": true
          },
          {
            "handle": "__kokumoto",
            "followers": 7585,
            "likes": 2,
            "createdAt": "2026-07-20",
            "url": "https://x.com/__kokumoto/status/2079345020709265478",
            "github": [],
            "origin": true
          },
          {
            "handle": "Horizon3ai",
            "followers": 2894,
            "likes": 2,
            "createdAt": "2026-07-20",
            "url": "https://x.com/Horizon3ai/status/2079336182480257029",
            "github": [],
            "origin": true
          },
          {
            "handle": "eSecurityPlanet",
            "followers": 6841,
            "likes": 0,
            "createdAt": "2026-07-20",
            "url": "https://x.com/eSecurityPlanet/status/2079268552884772897",
            "github": [],
            "origin": true
          }
        ]
      },
      "bsky": {
        "mentions": 44,
        "posts": [
          {
            "handle": "infosec.skyfleet.blue",
            "displayName": "InfoSec",
            "likes": 1,
            "reposts": 0,
            "replies": 0,
            "createdAt": "2026-07-18",
            "url": "https://bsky.app/profile/infosec.skyfleet.blue/post/3mqwsmwum3c22",
            "origin": true,
            "authority": true,
            "github": []
          },
          {
            "handle": "raptor.infosec.exchange.ap.brid.gy",
            "displayName": "raptor",
            "likes": 1,
            "reposts": 1,
            "replies": 1,
            "createdAt": "2026-07-18",
            "url": "https://bsky.app/profile/raptor.infosec.exchange.ap.brid.gy/post/3mqvtnm45ddy2",
            "origin": true,
            "authority": false,
            "github": [
              {
                "url": "https://github.com/Icex0/wp2shell-poc",
                "hasCode": true
              }
            ]
          },
          {
            "handle": "r-blueteamsec.bsky.social",
            "displayName": "r/blueteamsec bot",
            "likes": 0,
            "reposts": 0,
            "replies": 0,
            "createdAt": "2026-07-18",
            "url": "https://bsky.app/profile/r-blueteamsec.bsky.social/post/3mqw7fxlakd2e",
            "origin": true,
            "authority": false,
            "github": [
              {
                "url": "https://github.com/Icex0/wp2shell-poc",
                "hasCode": true
              }
            ]
          },
          {
            "handle": "goodtech.info",
            "displayName": "Goodtech - L'actu open source 🇫🇷🐧🇪🇺",
            "likes": 2,
            "reposts": 2,
            "replies": 0,
            "createdAt": "2026-07-20",
            "url": "https://bsky.app/profile/goodtech.info/post/3mr24wwys63ec",
            "origin": true,
            "authority": false,
            "github": []
          },
          {
            "handle": "ninjaowl.ai",
            "displayName": "Ninja Owl",
            "likes": 3,
            "reposts": 0,
            "replies": 0,
            "createdAt": "2026-07-19",
            "url": "https://bsky.app/profile/ninjaowl.ai/post/3mqxim6htkn2o",
            "origin": true,
            "authority": false,
            "github": []
          },
          {
            "handle": "r-netsec.bsky.social",
            "displayName": "r/netsec bot",
            "likes": 2,
            "reposts": 0,
            "replies": 0,
            "createdAt": "2026-07-18",
            "url": "https://bsky.app/profile/r-netsec.bsky.social/post/3mqxa34s4rl2o",
            "origin": true,
            "authority": false,
            "github": []
          }
        ]
      },
      "telegram": {
        "mentions": 8,
        "reach": 40169,
        "posts": [
          {
            "channel": "thehackernews",
            "channelTitle": "The Hacker News",
            "tier": "news",
            "date": "2026-07-18",
            "views": 9527,
            "forwards": 78,
            "url": "https://t.me/thehackernews/9544",
            "text": "⚡ UPDATE: #wp2shell now has two CVEs, and a working proof-of-concept is public. > CVE-2026-63030 breaks REST batch routing > CVE-2026-60137 injects SQL Chained, they give an anonymous attacker code execution on affected WordPress sites. How the exploit path works: https://thehackernews.com/2026/07/new-wp2shell-wordpress-core-flaw-lets.html",
            "github": [],
            "origin": false
          }
        ]
      }
    },
    {
      "cve": "CVE-2026-20253",
      "title": "In Splunk Enterprise 10.2 versions below 10.2.4 and 10 versions below 10.0.7, an…",
      "category": "Recall",
      "vendor": null,
      "exploited": true,
      "publiclyDisclosed": true,
      "cvss": 9.8,
      "cvssVector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "severity": "CRITICAL",
      "impact": null,
      "products": [],
      "productCount": 0,
      "faq": "In Splunk Enterprise 10.2 versions below 10.2.4 and 10 versions below 10.0.7, an unauthenticated user could create or truncate arbitrary files through a PostgreSQL sidecar service endpoint. The vulnerability exists because the PostgreSQL sidecar service endpoint lacks authentication controls, allowing any network-reachable user to invoke file operations without credentials. Splunk Enterprise versions 9.4 and earlier are not affected. If you cannot immediately upgrade to a fixed version, you can mitigate this vulnerability by disabling the PostgreSQL sidecar service.",
      "pocConfidence": "confirmed",
      "pocCount": 3,
      "pocTopStars": 8,
      "pocRepos": [
        {
          "url": "https://github.com/watchtowrlabs/watchTowr-vs-Splunk-CVE-2026-20253",
          "stars": 8,
          "desc": "",
          "createdAt": "2026-06-12",
          "hasCode": true
        },
        {
          "url": "https://github.com/0xBlackash/CVE-2026-20253",
          "stars": 1,
          "desc": "CVE-2026-20253",
          "createdAt": "2026-06-13",
          "hasCode": true
        },
        {
          "url": "https://github.com/HORKimhab/CVE-2026-20253",
          "stars": 0,
          "desc": "CVE-2026-20253 - Splunk Enterprise",
          "createdAt": "2026-06-14",
          "hasCode": true
        }
      ],
      "epss": 0.88171,
      "epssPercentile": 0.99752,
      "source": "poc",
      "mitreUrl": "https://nvd.nist.gov/vuln/detail/CVE-2026-20253",
      "research": [
        {
          "url": "https://labs.watchtowr.com/why-use-app-level-auth-when-every-database-has-auth-splunk-enterprise-cve-2026-20253-pre-auth-rce/",
          "type": "writeup",
          "source": "watchTowr Labs (Piotr Bazydło / Yordan Ganchev)",
          "note": "Pre-auth RCE chain via pg sidecar endpoints"
        },
        {
          "url": "https://github.com/watchtowrlabs/watchTowr-vs-Splunk-CVE-2026-20253",
          "type": "poc",
          "source": "watchTowr Labs / chudyPB (GitHub)",
          "note": "Python DAG script; probes /v1/postgres/recovery/backup",
          "hasCode": true
        },
        {
          "url": "https://advisory.splunk.com/advisories/SVD-2026-0603",
          "type": "detection",
          "source": "Splunk Official (SVD-2026-0603)",
          "note": "Vendor advisory; CVSS 9.8, fix in 10.2.4/10.0.7"
        },
        {
          "url": "https://orca.security/resources/blog/cve-2026-20253-splunk-enterprise-rce-unauthenticated-file-operations/",
          "type": "writeup",
          "source": "Orca Security",
          "note": "Technical analysis; file ops + RCE impact summary"
        },
        {
          "url": "https://cvefeed.io/vuln/detail/CVE-2026-20253",
          "type": "detection",
          "source": "CVEFeed.io",
          "note": "Aggregator; links to 1 GitHub PoC, CWE-306 mapping"
        },
        {
          "url": "https://thehackernews.com/2026/06/critical-splunk-enterprise-flaw-lets.html",
          "type": "writeup",
          "source": "The Hacker News",
          "note": "News writeup citing watchTowr pre-auth RCE chain"
        },
        {
          "url": "https://cybersecuritynews.com/splunk-enterprise-pre-auth-rce-chain-exposes/",
          "type": "writeup",
          "source": "CyberSecurityNews",
          "note": "Technical breakdown of backupFile path traversal"
        },
        {
          "url": "https://securityonline.info/splunk-enterprise-vulnerabilities-cvss-9-8/",
          "type": "detection",
          "source": "SecurityOnline.info",
          "note": "Patch urgency notice; covers sibling CVEs too"
        }
      ],
      "x": {
        "mentions": 4,
        "aliases": [],
        "posts": [
          {
            "handle": "TheHackersNews",
            "followers": 1548858,
            "likes": 321,
            "createdAt": "2026-06-13",
            "url": "https://x.com/TheHackersNews/status/2065787330208883198",
            "github": [],
            "origin": false
          },
          {
            "handle": "YogSoth0",
            "followers": 671,
            "likes": 15,
            "createdAt": "2026-06-14",
            "url": "https://x.com/YogSoth0/status/2066007432967475267",
            "github": [],
            "origin": false
          },
          {
            "handle": "XavierRiveraX",
            "followers": 558,
            "likes": 1,
            "createdAt": "2026-06-13",
            "url": "https://x.com/XavierRiveraX/status/2065794814033928485",
            "github": [],
            "origin": false
          },
          {
            "handle": "CyberAlertsHQ",
            "followers": 77,
            "likes": 0,
            "createdAt": "2026-06-14",
            "url": "https://x.com/CyberAlertsHQ/status/2066268033799356636",
            "github": [],
            "origin": false
          }
        ]
      },
      "researchers": [
        "chudyPB"
      ],
      "bsky": {
        "mentions": 25,
        "posts": [
          {
            "handle": "secdb.bsky.social",
            "displayName": "ZEN SecDB",
            "likes": 0,
            "reposts": 0,
            "replies": 0,
            "createdAt": "2026-06-18",
            "url": "https://bsky.app/profile/secdb.bsky.social/post/3molci2zapk2i",
            "origin": false,
            "authority": true,
            "github": []
          },
          {
            "handle": "infosec.skyfleet.blue",
            "displayName": "InfoSec",
            "likes": 0,
            "reposts": 0,
            "replies": 0,
            "createdAt": "2026-06-14",
            "url": "https://bsky.app/profile/infosec.skyfleet.blue/post/3mob6v3fxvm2x",
            "origin": false,
            "authority": true,
            "github": []
          },
          {
            "handle": "intcyberdigest.bsky.social",
            "displayName": "International Cyber Digest",
            "likes": 4,
            "reposts": 3,
            "replies": 2,
            "createdAt": "2026-06-12",
            "url": "https://bsky.app/profile/intcyberdigest.bsky.social/post/3mo4sbc2pbc2x",
            "origin": false,
            "authority": false,
            "github": []
          },
          {
            "handle": "diesec.bsky.social",
            "displayName": "DIESEC",
            "likes": 1,
            "reposts": 0,
            "replies": 0,
            "createdAt": "2026-06-19",
            "url": "https://bsky.app/profile/diesec.bsky.social/post/3mooabxhady2h",
            "origin": false,
            "authority": false,
            "github": []
          },
          {
            "handle": "cyberhub.blog",
            "displayName": "CyberHub",
            "likes": 1,
            "reposts": 0,
            "replies": 0,
            "createdAt": "2026-06-14",
            "url": "https://bsky.app/profile/cyberhub.blog/post/3moaoklb3gd2s",
            "origin": false,
            "authority": false,
            "github": []
          },
          {
            "handle": "crustytldr.bsky.social",
            "displayName": null,
            "likes": 0,
            "reposts": 1,
            "replies": 0,
            "createdAt": "2026-06-10",
            "url": "https://bsky.app/profile/crustytldr.bsky.social/post/3mnxprjs3hj2n",
            "origin": false,
            "authority": false,
            "github": []
          }
        ]
      },
      "telegram": {
        "mentions": 6,
        "posts": [
          {
            "channel": "thehackernews",
            "channelTitle": "The Hacker News",
            "tier": "news",
            "date": "2026-06-13",
            "views": 8877,
            "forwards": 58,
            "url": "https://t.me/thehackernews/9233",
            "text": "🚨 ALERT - A critical Splunk Enterprise flaw can go from “no login required” to remote code execution. Tracked as CVE-2026-20253, the bug carries a 9.8 CVSS score and affects vulnerable Splunk Enterprise servers through exposed PostgreSQL sidecar endpoints. The exploit chain is now public. Read the full story: https://thehackernews.com/2026/06/critical-splunk-enterprise-flaw-lets.html",
            "github": [],
            "origin": false
          }
        ]
      },
      "aliases": []
    },
    {
      "cve": "CVE-2026-8461",
      "title": "An out-of-bounds write vulnerability in FFmpeg's libavcodec library, specifically in…",
      "category": "Recall",
      "vendor": null,
      "exploited": false,
      "publiclyDisclosed": true,
      "cvss": 8.8,
      "cvssVector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
      "severity": "HIGH",
      "impact": null,
      "products": [],
      "productCount": 0,
      "faq": "An out-of-bounds write vulnerability in FFmpeg's libavcodec library, specifically in the MagicYUV decoder, allows denial-of-service and, in some cases, can be exploited for remote code execution.\n\n This vulnerability is associated with the file libavcodec/magicyuv.C.\n\n\n\nThis issue affects FFmpeg before version 8.1.2.",
      "pocConfidence": "confirmed",
      "pocCount": 3,
      "pocTopStars": 5,
      "pocRepos": [
        {
          "url": "https://github.com/anyanything/CVE-2026-8461-PoC",
          "stars": 5,
          "desc": "",
          "createdAt": "2026-06-23",
          "hasCode": true
        },
        {
          "url": "https://github.com/Y5neKO/CVE-2026-8461-EXP",
          "stars": 4,
          "desc": "",
          "createdAt": "2026-06-24",
          "hasCode": true
        },
        {
          "url": "https://github.com/0xBlackash/CVE-2026-8461",
          "stars": 1,
          "desc": "CVE-2026-8461",
          "createdAt": "2026-06-26",
          "hasCode": true
        },
        {
          "url": "https://github.com/HORKimhab/CVE-2026-8461",
          "stars": 1,
          "desc": "CVE-2026-8461 - Draft",
          "createdAt": "2026-06-24",
          "hasCode": false
        }
      ],
      "epss": 0.00477,
      "epssPercentile": 0.38191,
      "source": "poc",
      "mitreUrl": "https://nvd.nist.gov/vuln/detail/CVE-2026-8461",
      "research": [],
      "aliases": [],
      "researchers": [],
      "x": {
        "mentions": 0,
        "aliases": [],
        "posts": []
      },
      "bsky": {
        "mentions": 17,
        "posts": [
          {
            "handle": "toxy4ny.bsky.social",
            "displayName": "KL3FT3Z",
            "likes": 0,
            "reposts": 0,
            "replies": 0,
            "createdAt": "2026-06-26",
            "url": "https://bsky.app/profile/toxy4ny.bsky.social/post/3mp6shsarc22z",
            "origin": false,
            "authority": false,
            "github": [
              {
                "url": "https://github.com/Y5neKO/CVE-2026-8461-EXP",
                "hasCode": true
              }
            ]
          },
          {
            "handle": "xeiaso.net",
            "displayName": "Xe",
            "likes": 16,
            "reposts": 1,
            "replies": 2,
            "createdAt": "2026-06-25",
            "url": "https://bsky.app/profile/xeiaso.net/post/3mp5h5elvmg24",
            "origin": false,
            "authority": false,
            "github": []
          },
          {
            "handle": "jenbanim.mastodo.neoliber.al.ap.brid.gy",
            "displayName": "jenbanim",
            "likes": 1,
            "reposts": 0,
            "replies": 2,
            "createdAt": "2026-06-25",
            "url": "https://bsky.app/profile/jenbanim.mastodo.neoliber.al.ap.brid.gy/post/3mp4u7aad5yv2",
            "origin": false,
            "authority": false,
            "github": []
          },
          {
            "handle": "it-connect.bsky.social",
            "displayName": "IT-Connect",
            "likes": 2,
            "reposts": 1,
            "replies": 0,
            "createdAt": "2026-06-24",
            "url": "https://bsky.app/profile/it-connect.bsky.social/post/3mozaghjh7v2q",
            "origin": false,
            "authority": false,
            "github": []
          },
          {
            "handle": "ahmandonk.bsky.social",
            "displayName": "Ahmandonk",
            "likes": 2,
            "reposts": 1,
            "replies": 0,
            "createdAt": "2026-06-23",
            "url": "https://bsky.app/profile/ahmandonk.bsky.social/post/3mowkryxxid2t",
            "origin": false,
            "authority": false,
            "github": []
          },
          {
            "handle": "thedailytechfeed.com",
            "displayName": "The Daily Tech Feed",
            "likes": 1,
            "reposts": 1,
            "replies": 0,
            "createdAt": "2026-06-23",
            "url": "https://bsky.app/profile/thedailytechfeed.com/post/3mox2wvzuwz26",
            "origin": false,
            "authority": false,
            "github": []
          }
        ]
      }
    },
    {
      "cve": "CVE-2026-38526",
      "title": "An authenticated arbitrary file upload vulnerability in the /admin/tinymce/upload…",
      "category": "Recall",
      "vendor": null,
      "exploited": false,
      "publiclyDisclosed": true,
      "cvss": 9.9,
      "cvssVector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H",
      "severity": "CRITICAL",
      "impact": null,
      "products": [],
      "productCount": 0,
      "faq": "An authenticated arbitrary file upload vulnerability in the /admin/tinymce/upload endpoint of Webkul Krayin CRM v2.2.x allows attackers to execute arbitrary code via uploading a crafted PHP file.",
      "pocConfidence": "confirmed",
      "pocCount": 3,
      "pocTopStars": 4,
      "pocRepos": [
        {
          "url": "https://github.com/NathanHimself/CVE-2026-38526-PoC",
          "stars": 4,
          "desc": "CVE-2026-38526 | Krayin CRM v2.2.x Authenticated RCE - Unrestricted PHP File Upload via TinyMCE",
          "createdAt": "2026-05-16",
          "hasCode": true
        },
        {
          "url": "https://github.com/pawpic/CVE-2026-38526-POC",
          "stars": 0,
          "desc": "Proof of Concept of CVE-2026-38526 in Krayin CRM <= v2.2.x. Arbitrary File Upload leading to Remote Code Execution",
          "createdAt": "2026-06-24",
          "hasCode": true
        },
        {
          "url": "https://github.com/diamorphine666/CVE-2026-38526-Exploit",
          "stars": 0,
          "desc": "Exploit for Authenticated Remote Code Execution (RCE) in Krayin CRM v2.2.x (CVE-2026-38526)",
          "createdAt": "2026-07-06",
          "hasCode": true
        },
        {
          "url": "https://github.com/mmoobbeeiidat-design/Hack-The-Box-Nexus-Findings-Report",
          "stars": 0,
          "desc": "HTB_Nexus Penetration Test Report – Comprehensive security assessment documenting credential leakage from Gitea, CVE-2026-38526 exploitation in Krayin CRM, and ",
          "createdAt": "2026-07-06",
          "hasCode": false
        }
      ],
      "epss": 0.02759,
      "epssPercentile": 0.84649,
      "source": "poc",
      "mitreUrl": "https://nvd.nist.gov/vuln/detail/CVE-2026-38526",
      "research": [],
      "aliases": [],
      "researchers": [],
      "x": {
        "mentions": 0,
        "aliases": [],
        "posts": []
      },
      "bsky": {
        "mentions": 3,
        "posts": [
          {
            "handle": "infosec.skyfleet.blue",
            "displayName": "InfoSec",
            "likes": 0,
            "reposts": 0,
            "replies": 0,
            "createdAt": "2026-04-16",
            "url": "https://bsky.app/profile/infosec.skyfleet.blue/post/3mjmwfyhrxj2y",
            "origin": false,
            "authority": true,
            "github": []
          },
          {
            "handle": "thehackerwire.bsky.social",
            "displayName": "TheHackerWire",
            "likes": 0,
            "reposts": 0,
            "replies": 0,
            "createdAt": "2026-04-14",
            "url": "https://bsky.app/profile/thehackerwire.bsky.social/post/3mjhtg4gn2c2h",
            "origin": false,
            "authority": false,
            "github": []
          },
          {
            "handle": "cve.skyfleet.blue",
            "displayName": "CVE Alerts ",
            "likes": 0,
            "reposts": 0,
            "replies": 0,
            "createdAt": "2026-04-14",
            "url": "https://bsky.app/profile/cve.skyfleet.blue/post/3mjhudxtjxx2r",
            "origin": false,
            "authority": false,
            "github": []
          }
        ]
      },
      "telegram": {
        "mentions": 0,
        "posts": []
      }
    },
    {
      "cve": "CVE-2026-6279",
      "title": "The Avada Builder (fusion-builder) plugin for WordPress is vulnerable to…",
      "category": "Recall",
      "vendor": null,
      "exploited": false,
      "publiclyDisclosed": true,
      "cvss": 9.8,
      "cvssVector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "severity": "CRITICAL",
      "impact": null,
      "products": [],
      "productCount": 0,
      "faq": "The Avada Builder (fusion-builder) plugin for WordPress is vulnerable to Unauthenticated Remote Code Execution via PHP Function Injection in versions up to and including 3.15.2. This is due to the `wp_conditional_tags` case in `Fusion_Builder_Conditional_Render_Helper::get_value()` passing attacker-controlled values from a base64-decoded JSON blob directly to `call_user_func()` without any allowlist validation. This is exploitable by unauthenticated attackers through the `fusion_get_widget_markup` AJAX endpoint, which is registered for non-privileged (unauthenticated) users via `wp_ajax_nopriv_fusion_get_widget_markup`. The endpoint is protected only by a nonce (`fusion_load_nonce`), but this nonce is generated for user ID 0 and is deterministically exposed in the JavaScript output of any public-facing page containing a Post Cards (`[fusion_post_cards]`) or Table of Contents (`[fusion_table_of_contents]`) element. This makes it possible for unauthenticated attackers to execute arbitrary code on affected sites.",
      "pocConfidence": "confirmed",
      "pocCount": 3,
      "pocTopStars": 4,
      "pocRepos": [
        {
          "url": "https://github.com/zycoder0day/CVE-2026-6279",
          "stars": 4,
          "desc": "CVE-2026-6279 — Avada Builder <= 3.15.2 Unauthenticated RCE via call_user_func()",
          "createdAt": "2026-05-23",
          "hasCode": true
        },
        {
          "url": "https://github.com/87achrafg-stack/CVE-2026-6279.py",
          "stars": 2,
          "desc": "CVE-2026-6279",
          "createdAt": "2026-06-13",
          "hasCode": true
        },
        {
          "url": "https://github.com/xxconi/CVE-2026-6279",
          "stars": 0,
          "desc": "CVE-2026-6279: Avada (Fusion) Builder <= 3.15.2 – Unauthenticated Remote Code Execution via PHP Function Injection via 'render_logics' Shortcode Attribute via W",
          "createdAt": "2026-05-23",
          "hasCode": true
        }
      ],
      "epss": 0.02163,
      "epssPercentile": 0.80241,
      "source": "poc",
      "mitreUrl": "https://nvd.nist.gov/vuln/detail/CVE-2026-6279",
      "research": [
        {
          "url": "https://wpscan.com/vulnerability/34df3d2e-006d-4cee-87f3-cb4d535ec667/",
          "type": "writeup",
          "source": "WPScan",
          "note": "unauth RCE via PHP function injection -> call_user_func"
        },
        {
          "url": "https://patchstack.com/database/wordpress/plugin/fusion-builder/vulnerability/wordpress-avada-fusion-builder-plugin-3-15-2-unauthenticated-remote-code-execution-vulnerability",
          "type": "writeup",
          "source": "Patchstack",
          "note": "unauth RCE via fusion_get_widget_markup AJAX endpoint"
        }
      ],
      "x": {
        "mentions": 5,
        "posts": [
          {
            "handle": "ThreatAft",
            "followers": 26,
            "likes": 0,
            "createdAt": "2026-05-23",
            "url": "https://x.com/ThreatAft/status/2058033971397832851",
            "origin": false,
            "github": []
          },
          {
            "handle": "ADKCyber",
            "followers": 83,
            "likes": 0,
            "createdAt": "2026-05-21",
            "url": "https://x.com/ADKCyber/status/2057610561085743129",
            "origin": false,
            "github": []
          },
          {
            "handle": "infoflowcloud",
            "followers": 79,
            "likes": 0,
            "createdAt": "2026-05-21",
            "url": "https://x.com/infoflowcloud/status/2057408753377390691",
            "origin": false,
            "github": []
          },
          {
            "handle": "CVEnew",
            "followers": 57565,
            "likes": 0,
            "createdAt": "2026-05-21",
            "url": "https://x.com/CVEnew/status/2057407793242468482",
            "origin": false,
            "github": []
          },
          {
            "handle": "OrizonCyber",
            "followers": 47,
            "likes": 0,
            "createdAt": "2026-05-21",
            "url": "https://x.com/OrizonCyber/status/2057333098145042684",
            "origin": false,
            "github": []
          }
        ],
        "aliases": []
      },
      "bsky": {
        "mentions": 5,
        "posts": [
          {
            "handle": "basefortify.bsky.social",
            "displayName": "BaseFortify.eu",
            "likes": 0,
            "reposts": 0,
            "replies": 1,
            "createdAt": "2026-05-21",
            "url": "https://bsky.app/profile/basefortify.bsky.social/post/3mmed3x6lqk2s",
            "origin": false,
            "authority": false,
            "github": []
          },
          {
            "handle": "offseq.bsky.social",
            "displayName": "OffSequence",
            "likes": 0,
            "reposts": 0,
            "replies": 0,
            "createdAt": "2026-05-21",
            "url": "https://bsky.app/profile/offseq.bsky.social/post/3mmdqkii2wb26",
            "origin": false,
            "authority": false,
            "github": []
          },
          {
            "handle": "cve.skyfleet.blue",
            "displayName": "CVE Alerts ",
            "likes": 0,
            "reposts": 0,
            "replies": 0,
            "createdAt": "2026-05-21",
            "url": "https://bsky.app/profile/cve.skyfleet.blue/post/3mmdtj6esyd2t",
            "origin": false,
            "authority": false,
            "github": []
          },
          {
            "handle": "thehackerwire.bsky.social",
            "displayName": "TheHackerWire",
            "likes": 0,
            "reposts": 0,
            "replies": 0,
            "createdAt": "2026-05-21",
            "url": "https://bsky.app/profile/thehackerwire.bsky.social/post/3mmdqjri6ml2n",
            "origin": false,
            "authority": false,
            "github": []
          },
          {
            "handle": "atomicedge.bsky.social",
            "displayName": "Atomic Edge",
            "likes": 0,
            "reposts": 0,
            "replies": 0,
            "createdAt": "2026-05-21",
            "url": "https://bsky.app/profile/atomicedge.bsky.social/post/3mmen5gifsj2l",
            "origin": false,
            "authority": false,
            "github": []
          }
        ]
      },
      "telegram": {
        "mentions": 0,
        "posts": []
      },
      "aliases": [],
      "researchers": []
    },
    {
      "cve": "CVE-2026-33017",
      "title": "Langflow is a tool for building and deploying AI-powered agents and workflows. In…",
      "category": "Recall",
      "vendor": null,
      "exploited": true,
      "publiclyDisclosed": true,
      "cvss": 9.8,
      "cvssVector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "severity": "CRITICAL",
      "impact": null,
      "products": [],
      "productCount": 0,
      "faq": "Langflow is a tool for building and deploying AI-powered agents and workflows. In versions prior to 1.9.0, the POST /api/v1/build_public_tmp/{flow_id}/flow endpoint allows building public flows without requiring authentication. When the optional data parameter is supplied, the endpoint uses attacker-controlled flow data (containing arbitrary Python code in node definitions) instead of the stored flow data from the database. This code is passed to exec() with zero sandboxing, resulting in unauthenticated remote code execution. This is distinct from CVE-2025-3248, which fixed /api/v1/validate/code by adding authentication. The build_public_tmp endpoint is designed to be unauthenticated (for public flows) but incorrectly accepts attacker-supplied flow data containing arbitrary executable code. This issue has been fixed in version 1.9.0.",
      "pocConfidence": "confirmed",
      "pocCount": 3,
      "pocTopStars": 2,
      "pocRepos": [
        {
          "url": "https://github.com/c0gnit00/CVE-2026-33017",
          "stars": 2,
          "desc": "Python POC, Exploit for CVE-2026-33017",
          "createdAt": "2026-07-02",
          "hasCode": true
        },
        {
          "url": "https://github.com/yayip/CVE-2026-33017",
          "stars": 0,
          "desc": "PoC of Langflow CVE-2026-33017",
          "createdAt": "2026-07-04",
          "hasCode": true
        },
        {
          "url": "https://github.com/diamorphine666/CVE-2026-33017-Exploit",
          "stars": 0,
          "desc": "Unauthenticated RCE in Langflow <1.9.0 (CVE-2026-33017) Exploit",
          "createdAt": "2026-07-04",
          "hasCode": true
        }
      ],
      "epss": 0.98191,
      "epssPercentile": 0.99909,
      "source": "poc",
      "mitreUrl": "https://nvd.nist.gov/vuln/detail/CVE-2026-33017",
      "research": [
        {
          "url": "https://medium.com/@aviral23/cve-2026-33017-how-i-found-an-unauthenticated-rce-in-langflow-by-reading-the-code-they-already-dc96cdce5896",
          "type": "writeup",
          "source": "Aviral Srivastava (aviral23) / Medium",
          "note": "Discovery narrative by original reporter; root cause analysis"
        },
        {
          "url": "https://github.com/langflow-ai/langflow/security/advisories/GHSA-vwmf-pq79-vjvx",
          "type": "writeup",
          "source": "Langflow / GitHub Security Advisory (GHSA-vwmf-pq79-vjvx)",
          "note": "Official advisory; vulnerable code path, patch details",
          "hasCode": true
        },
        {
          "url": "https://github.com/EQSTLab/CVE-2026-33017",
          "type": "poc",
          "source": "EQSTLab / GitHub",
          "note": "PoC w/ Docker lab; reverse shell via build_public_tmp",
          "hasCode": true
        },
        {
          "url": "https://www.exploit-db.com/exploits/52627",
          "type": "poc",
          "source": "Exploit-DB (author: Diamorphine)",
          "note": "EDB-52627; async Python RCE exploit, Langflow <1.9.0"
        },
        {
          "url": "https://github.com/projectdiscovery/nuclei-templates",
          "type": "module",
          "source": "ProjectDiscovery / nuclei-templates (@himind)",
          "note": "Official Nuclei template [CVE-2026-33017] KEV-tagged",
          "hasCode": true
        },
        {
          "url": "https://research.jfrog.com/post/langflow-latest-version-was-not-fixed/",
          "type": "writeup",
          "source": "JFrog Security Research",
          "note": "Confirmed 1.8.2 still exploitable; only 1.9.0 fixes it"
        },
        {
          "url": "https://www.sysdig.com/blog/cve-2026-33017-how-attackers-compromised-langflow-ai-pipelines-in-20-hours",
          "type": "writeup",
          "source": "Sysdig Threat Research Team",
          "note": "Honeypot data: exploited in-wild <20hrs, kill chain detail"
        },
        {
          "url": "https://www.trendmicro.com/en_us/research/26/f/from-langflow-to-monero-inside-cve-2026-33017-cryptominer.html",
          "type": "writeup",
          "source": "Trend Micro Research",
          "note": "19-day Monero mining campaign; lambsys Go binary IoCs"
        }
      ],
      "aliases": [],
      "researchers": [
        "aviral23",
        "Aviral2642"
      ],
      "x": {
        "mentions": 101,
        "aliases": [],
        "posts": [
          {
            "handle": "MalwareObserver",
            "followers": 9,
            "likes": 0,
            "createdAt": "2026-07-15",
            "url": "https://x.com/MalwareObserver/status/2077250553655005389",
            "github": [
              {
                "url": "https://github.com/istio/istio/security/advisories/GHSA-v75c-crr9-733c",
                "hasCode": true
              },
              {
                "url": "https://github.com/istio/istio/security/advisories/GHSA-v75c-crr9-733c",
                "hasCode": true
              }
            ],
            "origin": false
          },
          {
            "handle": "MalwareBibleJP",
            "followers": 7624,
            "likes": 8,
            "createdAt": "2026-07-15",
            "url": "https://x.com/MalwareBibleJP/status/2077234644404273220",
            "github": [],
            "origin": false
          },
          {
            "handle": "PentesterLab",
            "followers": 205348,
            "likes": 6,
            "createdAt": "2026-07-15",
            "url": "https://x.com/PentesterLab/status/2077227113070166264",
            "github": [],
            "origin": false
          },
          {
            "handle": "steventseeley",
            "followers": 22728,
            "likes": 2,
            "createdAt": "2026-07-15",
            "url": "https://x.com/steventseeley/status/2077260190261624985",
            "github": [],
            "origin": false
          },
          {
            "handle": "Daily_CyberSec",
            "followers": 12486,
            "likes": 2,
            "createdAt": "2026-07-15",
            "url": "https://x.com/Daily_CyberSec/status/2077198003673214982",
            "github": [],
            "origin": false
          },
          {
            "handle": "__kokumoto",
            "followers": 7578,
            "likes": 2,
            "createdAt": "2026-07-15",
            "url": "https://x.com/__kokumoto/status/2077233338256073098",
            "github": [],
            "origin": false
          },
          {
            "handle": "blackorbird",
            "followers": 42692,
            "likes": 1,
            "createdAt": "2026-07-15",
            "url": "https://x.com/blackorbird/status/2077268390000132431",
            "github": [],
            "origin": false
          },
          {
            "handle": "pdnuclei_bot",
            "followers": 989,
            "likes": 1,
            "createdAt": "2026-07-15",
            "url": "https://x.com/pdnuclei_bot/status/2077256883522723949",
            "github": [],
            "origin": false
          }
        ]
      },
      "bsky": {
        "mentions": 22,
        "posts": [
          {
            "handle": "bleepingcomputer.com",
            "displayName": "BleepingComputer",
            "likes": 6,
            "reposts": 1,
            "replies": 1,
            "createdAt": "2026-03-26",
            "url": "https://bsky.app/profile/bleepingcomputer.com/post/3mhycz3g2xr24",
            "origin": false,
            "authority": true,
            "github": []
          },
          {
            "handle": "hendryadrian.bsky.social",
            "displayName": "Cybersecurity News Everyday",
            "likes": 3,
            "reposts": 0,
            "replies": 1,
            "createdAt": "2026-03-26",
            "url": "https://bsky.app/profile/hendryadrian.bsky.social/post/3mhyjtz5lsx2l",
            "origin": false,
            "authority": false,
            "github": []
          },
          {
            "handle": "cve.skyfleet.blue",
            "displayName": "CVE Alerts ",
            "likes": 2,
            "reposts": 0,
            "replies": 1,
            "createdAt": "2026-03-20",
            "url": "https://bsky.app/profile/cve.skyfleet.blue/post/3mhhtqaglfv27",
            "origin": false,
            "authority": false,
            "github": []
          },
          {
            "handle": "checkmarxzero.bsky.social",
            "displayName": "Checkmarx Zero",
            "likes": 1,
            "reposts": 1,
            "replies": 1,
            "createdAt": "2026-03-18",
            "url": "https://bsky.app/profile/checkmarxzero.bsky.social/post/3mhefghjvzl2o",
            "origin": false,
            "authority": false,
            "github": []
          },
          {
            "handle": "opsmatters.com",
            "displayName": "OpsMatters",
            "likes": 1,
            "reposts": 1,
            "replies": 0,
            "createdAt": "2026-07-04",
            "url": "https://bsky.app/profile/opsmatters.com/post/3mps7pglzfp2z",
            "origin": false,
            "authority": false,
            "github": []
          },
          {
            "handle": "undercodenews.bsky.social",
            "displayName": "Undercode News",
            "likes": 2,
            "reposts": 0,
            "replies": 0,
            "createdAt": "2026-06-25",
            "url": "https://bsky.app/profile/undercodenews.bsky.social/post/3mp4cb54pcv2g",
            "origin": false,
            "authority": false,
            "github": []
          }
        ]
      },
      "telegram": {
        "mentions": 4,
        "posts": [
          {
            "channel": "thehackernews",
            "channelTitle": "The Hacker News",
            "tier": "news",
            "date": "2026-03-20",
            "views": 9462,
            "forwards": 21,
            "url": "https://t.me/thehackernews/8642",
            "text": "⚠️ Langflow CVE-2026-33017 was exploited in 20 hours of disclosure. An exposed API runs attacker-supplied Python with no auth, enabling full server takeover. Real attacks show credential theft, file access, and staged payload delivery. 🔗 Read → https://thehackernews.com/2026/03/critical-langflow-flaw-cve-2026-33017.html",
            "github": [],
            "origin": false
          }
        ]
      }
    },
    {
      "cve": "CVE-2026-43494",
      "title": "In the Linux kernel, the following vulnerability has been resolved: net/rds: reset…",
      "category": "Recall",
      "vendor": null,
      "exploited": false,
      "publiclyDisclosed": true,
      "cvss": 7.8,
      "cvssVector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "severity": "HIGH",
      "impact": null,
      "products": [],
      "productCount": 0,
      "faq": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet/rds: reset op_nents when zerocopy page pin fails\n\nWhen iov_iter_get_pages2() fails in rds_message_zcopy_from_user(),\nthe pinned pages are released with put_page(), and\nrm->data.op_mmp_znotifier is cleared.  But we fail to properly\nclear rm->data.op_nents.\n\nLater when rds_message_purge() is called from rds_sendmsg() the\ncleanup loop iterates over the incorrectly non zero number of\nop_nents and frees them again.\n\nFix this by properly resetting op_nents when it should be in\nrds_message_zcopy_from_user().",
      "pocConfidence": "confirmed",
      "pocCount": 3,
      "pocTopStars": 2,
      "pocRepos": [
        {
          "url": "https://github.com/0xBlackash/CVE-2026-43494",
          "stars": 2,
          "desc": "CVE-2026-43494",
          "createdAt": "2026-05-22",
          "hasCode": true
        },
        {
          "url": "https://github.com/Koshmare-Blossom/PinTheft-asm",
          "stars": 1,
          "desc": "A x86_64 ASM implementation of PinTheft (CVE-2026-43494)",
          "createdAt": "2026-05-28",
          "hasCode": true
        },
        {
          "url": "https://github.com/Koshmare-Blossom/PinTheft-go",
          "stars": 0,
          "desc": "A Go implementation of PinTheft (CVE-2026-43494)",
          "createdAt": "2026-05-22",
          "hasCode": true
        }
      ],
      "epss": 0.00269,
      "epssPercentile": 0.18805,
      "source": "poc",
      "mitreUrl": "https://nvd.nist.gov/vuln/detail/CVE-2026-43494",
      "research": [
        {
          "url": "https://ubuntu.com/blog/pintheft-linux-kernel-vulnerability-mitigation",
          "type": "writeup",
          "source": "Ubuntu",
          "note": "PinTheft RDS+io_uring LPE mitigation"
        },
        {
          "url": "https://tuxcare.com/blog/cve-pintheft/",
          "type": "writeup",
          "source": "TuxCare",
          "note": "PinTheft local root via RDS double-free"
        },
        {
          "url": "https://knightli.com/en/2026/05/22/linux-kernel-cve-2026-43494-pintheft/",
          "type": "writeup",
          "source": "knightli",
          "note": "RDS zero-copy double-free LPE explained"
        },
        {
          "url": "https://www.suse.com/security/cve/CVE-2026-43494.html",
          "type": "writeup",
          "source": "SUSE",
          "note": "Vendor advisory"
        }
      ],
      "x": {
        "mentions": 10,
        "posts": [
          {
            "handle": "hsn8086k",
            "followers": 2189,
            "likes": 732,
            "createdAt": "2026-05-22",
            "url": "https://x.com/hsn8086k/status/2057737865707295171",
            "origin": false,
            "github": []
          },
          {
            "handle": "GOVCERT_CZ",
            "followers": 4220,
            "likes": 9,
            "createdAt": "2026-05-22",
            "url": "https://x.com/GOVCERT_CZ/status/2057769178887508024",
            "origin": false,
            "github": []
          },
          {
            "handle": "IctyeP",
            "followers": 1166,
            "likes": 3,
            "createdAt": "2026-05-22",
            "url": "https://x.com/IctyeP/status/2057723599365300560",
            "origin": false,
            "github": []
          },
          {
            "handle": "omokazuki",
            "followers": 371,
            "likes": 2,
            "createdAt": "2026-05-22",
            "url": "https://x.com/omokazuki/status/2057614603916632348",
            "origin": false,
            "github": []
          },
          {
            "handle": "VulmonFeeds",
            "followers": 4043,
            "likes": 1,
            "createdAt": "2026-05-21",
            "url": "https://x.com/VulmonFeeds/status/2057480075990183936",
            "origin": false,
            "github": []
          },
          {
            "handle": "ptdbugs",
            "followers": 1247,
            "likes": 0,
            "createdAt": "2026-05-25",
            "url": "https://x.com/ptdbugs/status/2058829946395451634",
            "origin": false,
            "github": []
          },
          {
            "handle": "relaxedswimmer",
            "followers": 48,
            "likes": 0,
            "createdAt": "2026-05-23",
            "url": "https://x.com/relaxedswimmer/status/2058195039621427449",
            "origin": false,
            "github": []
          },
          {
            "handle": "luadoles",
            "followers": 31,
            "likes": 0,
            "createdAt": "2026-05-22",
            "url": "https://x.com/luadoles/status/2057902528470110330",
            "origin": false,
            "github": []
          }
        ],
        "aliases": []
      },
      "aliases": [
        "PinTheft"
      ],
      "researchers": [
        "V12 Security"
      ],
      "bsky": {
        "mentions": 39,
        "posts": [
          {
            "handle": "bleepingcomputer.com",
            "displayName": "BleepingComputer",
            "likes": 4,
            "reposts": 1,
            "replies": 0,
            "createdAt": "2026-05-20",
            "url": "https://bsky.app/profile/bleepingcomputer.com/post/3mmbqgi6xle2r",
            "origin": true,
            "authority": true,
            "github": []
          },
          {
            "handle": "campuscodi.risky.biz",
            "displayName": "Catalin Cimpanu",
            "likes": 2,
            "reposts": 0,
            "replies": 0,
            "createdAt": "2026-05-22",
            "url": "https://bsky.app/profile/campuscodi.risky.biz/post/3mmgou56sx22g",
            "origin": true,
            "authority": true,
            "github": []
          },
          {
            "handle": "infosec.skyfleet.blue",
            "displayName": "InfoSec",
            "likes": 1,
            "reposts": 0,
            "replies": 0,
            "createdAt": "2026-05-20",
            "url": "https://bsky.app/profile/infosec.skyfleet.blue/post/3mmbsp23xoa2x",
            "origin": true,
            "authority": true,
            "github": []
          },
          {
            "handle": "jschauma.mstdn.social.ap.brid.gy",
            "displayName": "Jan Schaumann",
            "likes": 1,
            "reposts": 3,
            "replies": 0,
            "createdAt": "2026-05-15",
            "url": "https://bsky.app/profile/jschauma.mstdn.social.ap.brid.gy/post/3mlvwrqwyrpe2",
            "origin": true,
            "authority": false,
            "github": [
              {
                "url": "https://github.com/v12-security/pocs/tree/main/qemu",
                "hasCode": true
              }
            ]
          },
          {
            "handle": "linkersec.bsky.social",
            "displayName": "Linux Kernel Security",
            "likes": 1,
            "reposts": 0,
            "replies": 0,
            "createdAt": "2026-06-09",
            "url": "https://bsky.app/profile/linkersec.bsky.social/post/3mnuxc776ws2y",
            "origin": true,
            "authority": false,
            "github": [
              {
                "url": "https://github.com/v12-security/pocs/tree/main/pintheft",
                "hasCode": true
              }
            ]
          },
          {
            "handle": "omo.bsky.social",
            "displayName": "OMO",
            "likes": 1,
            "reposts": 1,
            "replies": 1,
            "createdAt": "2026-05-19",
            "url": "https://bsky.app/profile/omo.bsky.social/post/3mmai2vsr6s27",
            "origin": true,
            "authority": false,
            "github": []
          }
        ]
      }
    },
    {
      "cve": "CVE-2026-0740",
      "title": "The Ninja Forms - File Uploads plugin for WordPress is vulnerable to arbitrary file…",
      "category": "Recall",
      "vendor": null,
      "exploited": false,
      "publiclyDisclosed": true,
      "cvss": 9.8,
      "cvssVector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "severity": "CRITICAL",
      "impact": null,
      "products": [],
      "productCount": 0,
      "faq": "The Ninja Forms - File Uploads plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'NF_FU_AJAX_Controllers_Uploads::handle_upload' function in all versions up to, and including, 3.3.26. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code execution possible. Note: The vulnerability was partially patched in version 3.3.25 and fully patched in version 3.3.27.",
      "pocConfidence": "confirmed",
      "pocCount": 3,
      "pocTopStars": 1,
      "pocRepos": [
        {
          "url": "https://github.com/whattheslime/CVE-2026-0740",
          "stars": 1,
          "desc": "Ninja Forms File Uploads <= 3.3.26 - Unauthenticated Arbitrary File Upload to RCE (CVE-2026-0740)",
          "createdAt": "2026-04-07",
          "hasCode": true
        },
        {
          "url": "https://github.com/ExDev994/CVE-2026-0740-mass",
          "stars": 1,
          "desc": "PoC untuk CVE-2026-0740: Ninja Forms File Uploads <= 3.3.26 — Unauthenticated Arbitrary File Upload yang dapat mengarah ke RCE.",
          "createdAt": "2026-07-11",
          "hasCode": true
        },
        {
          "url": "https://github.com/MadExploits/ninja-form-exploit",
          "stars": 1,
          "desc": "CVE-2026-0740",
          "createdAt": "2026-07-14",
          "hasCode": true
        }
      ],
      "epss": 0.54254,
      "epssPercentile": 0.98901,
      "source": "poc",
      "mitreUrl": "https://nvd.nist.gov/vuln/detail/CVE-2026-0740",
      "research": [
        {
          "url": "https://github.com/whattheslime/CVE-2026-0740",
          "type": "poc",
          "source": "whattheslime (Sélim Lanouar) / GitHub",
          "note": "Python PoC: webshell upload + path traversal RCE",
          "hasCode": true
        },
        {
          "url": "https://blog.lexfo.fr/ninja-forms-uploads-cve-2026-0740",
          "type": "writeup",
          "source": "Lexfo / whattheslime",
          "note": "Discoverer's deep-dive writeup (Lexfo blog)"
        },
        {
          "url": "https://www.wordfence.com/blog/2026/04/50000-wordpress-sites-affected-by-arbitrary-file-upload-vulnerability-in-ninja-forms-file-upload-wordpress-plugin/",
          "type": "writeup",
          "source": "Wordfence (Defiant)",
          "note": "Primary disclosure: root cause, code, timeline"
        },
        {
          "url": "https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2026/CVE-2026-0740.yaml",
          "type": "module",
          "source": "ProjectDiscovery / @whattheslime",
          "note": "Official Nuclei template, critical/KEV-tagged",
          "hasCode": true
        },
        {
          "url": "https://github.com/advisories/GHSA-v8wq-rjpf-669f",
          "type": "writeup",
          "source": "GitHub Advisory Database",
          "note": "GHSA-v8wq-rjpf-669f; CVSS 9.8, versions ≤3.3.26",
          "hasCode": null
        },
        {
          "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/0b606ded-ab50-486a-9337-97ee9f452f12",
          "type": "detection",
          "source": "Wordfence Intelligence",
          "note": "WAF rule, CVSS vector, version detail, IoCs"
        },
        {
          "url": "https://mysites.guru/blog/ninja-forms-file-uploads-cve-2026-0740/",
          "type": "writeup",
          "source": "mySites.guru",
          "note": "Technical analysis + 118,600 blocked attempts data"
        },
        {
          "url": "https://attackerkb.com/topics/LOqHW299NA/cve-2026-0740",
          "type": "detection",
          "source": "AttackerKB / Rapid7",
          "note": "Exploitability assessment and references hub"
        }
      ],
      "aliases": [],
      "researchers": [
        "whattheslime"
      ],
      "x": {
        "mentions": 101,
        "aliases": [],
        "posts": [
          {
            "handle": "ThreatWire_",
            "followers": 65,
            "likes": 1,
            "createdAt": "2026-07-13",
            "url": "https://x.com/ThreatWire_/status/2076593117378076887",
            "github": [
              {
                "url": "https://github.com/ExDev994/CVE-2026-0740-mass",
                "hasCode": true
              }
            ],
            "origin": false
          },
          {
            "handle": "MalwareObserver",
            "followers": 9,
            "likes": 0,
            "createdAt": "2026-07-15",
            "url": "https://x.com/MalwareObserver/status/2077250553655005389",
            "github": [
              {
                "url": "https://github.com/istio/istio/security/advisories/GHSA-v75c-crr9-733c",
                "hasCode": true
              },
              {
                "url": "https://github.com/istio/istio/security/advisories/GHSA-v75c-crr9-733c",
                "hasCode": true
              }
            ],
            "origin": false
          },
          {
            "handle": "ptdbugs",
            "followers": 2380,
            "likes": 34,
            "createdAt": "2026-07-13",
            "url": "https://x.com/ptdbugs/status/2076592641869746244",
            "github": [],
            "origin": false
          },
          {
            "handle": "MalwareBibleJP",
            "followers": 7624,
            "likes": 8,
            "createdAt": "2026-07-15",
            "url": "https://x.com/MalwareBibleJP/status/2077234644404273220",
            "github": [],
            "origin": false
          },
          {
            "handle": "PentesterLab",
            "followers": 205348,
            "likes": 6,
            "createdAt": "2026-07-15",
            "url": "https://x.com/PentesterLab/status/2077227113070166264",
            "github": [],
            "origin": false
          },
          {
            "handle": "steventseeley",
            "followers": 22728,
            "likes": 2,
            "createdAt": "2026-07-15",
            "url": "https://x.com/steventseeley/status/2077260190261624985",
            "github": [],
            "origin": false
          },
          {
            "handle": "Daily_CyberSec",
            "followers": 12486,
            "likes": 2,
            "createdAt": "2026-07-15",
            "url": "https://x.com/Daily_CyberSec/status/2077198003673214982",
            "github": [],
            "origin": false
          },
          {
            "handle": "__kokumoto",
            "followers": 7578,
            "likes": 2,
            "createdAt": "2026-07-15",
            "url": "https://x.com/__kokumoto/status/2077233338256073098",
            "github": [],
            "origin": false
          }
        ]
      },
      "bsky": {
        "mentions": 21,
        "posts": [
          {
            "handle": "hendryadrian.bsky.social",
            "displayName": "Cybersecurity News Everyday",
            "likes": 1,
            "reposts": 1,
            "replies": 0,
            "createdAt": "2026-04-10",
            "url": "https://bsky.app/profile/hendryadrian.bsky.social/post/3mj3zd2biqt27",
            "origin": false,
            "authority": false,
            "github": []
          },
          {
            "handle": "mysites.guru",
            "displayName": "Manage Multiple WordPress and Joomla Sites easily!",
            "likes": 1,
            "reposts": 0,
            "replies": 0,
            "createdAt": "2026-04-21",
            "url": "https://bsky.app/profile/mysites.guru/post/3mjz5nsdzzg2w",
            "origin": false,
            "authority": false,
            "github": []
          },
          {
            "handle": "wordfenceofficial.bsky.social",
            "displayName": "Wordfence",
            "likes": 0,
            "reposts": 1,
            "replies": 0,
            "createdAt": "2026-04-16",
            "url": "https://bsky.app/profile/wordfenceofficial.bsky.social/post/3mjndlief222t",
            "origin": false,
            "authority": false,
            "github": []
          },
          {
            "handle": "donwebmedia.bsky.social",
            "displayName": null,
            "likes": 0,
            "reposts": 0,
            "replies": 0,
            "createdAt": "2026-05-03",
            "url": "https://bsky.app/profile/donwebmedia.bsky.social/post/3mkwslgerba2c",
            "origin": false,
            "authority": false,
            "github": []
          },
          {
            "handle": "solomonneas.dev",
            "displayName": "Solomon Neas",
            "likes": 0,
            "reposts": 0,
            "replies": 0,
            "createdAt": "2026-04-08",
            "url": "https://bsky.app/profile/solomonneas.dev/post/3miyaqinxzf2v",
            "origin": false,
            "authority": false,
            "github": []
          },
          {
            "handle": "beikokucyber.bsky.social",
            "displayName": "Beikoku Cybersecurity",
            "likes": 0,
            "reposts": 0,
            "replies": 0,
            "createdAt": "2026-04-08",
            "url": "https://bsky.app/profile/beikokucyber.bsky.social/post/3miz6wvf6pu2p",
            "origin": false,
            "authority": false,
            "github": []
          }
        ]
      },
      "telegram": {
        "mentions": 0,
        "posts": []
      }
    },
    {
      "cve": "CVE-2026-41651",
      "title": "PackageKit is a a D-Bus abstraction layer that allows the user to manage packages in…",
      "category": "Recall",
      "vendor": null,
      "exploited": false,
      "publiclyDisclosed": true,
      "cvss": 8.8,
      "cvssVector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H",
      "severity": "HIGH",
      "impact": null,
      "products": [],
      "productCount": 0,
      "faq": "PackageKit is a a D-Bus abstraction layer that allows the user to manage packages in a secure way using a cross-distro, cross-architecture API. PackageKit between and including versions 1.0.2 and 1.3.4 is vulnerable to a time-of-check time-of-use (TOCTOU) race condition on transaction flags that allows unprivileged users to install packages as root and thus leads to a local privilege escalation. This is patched in version 1.3.5.\n\nA local unprivileged user can install arbitrary RPM packages as root, including executing RPM scriptlets, without authentication. The vulnerability is a TOCTOU race condition on `transaction->cached_transaction_flags`  combined with a silent state-machine guard that discards illegal backward transitions while leaving corrupted flags in place. Three bugs exist in `src/pk-transaction.c`:\n1. Unconditional flag overwrite (line 4036): `InstallFiles()` writes caller-supplied flags to `transaction->cached_transaction_flags` without checking whether the transaction has already been  authorized/started. A second call blindly overwrites the flags even while the transaction is RUNNING.\n2. Silent state-transition rejection (lines 873–882): `pk_transaction_set_state()` silently discards backward state transitions (e.g. `RUNNING` → `WAITING_FOR_AUTH`) but the flag overwrite at step 1 already happened. The transaction continues running with corrupted flags.\n3. Late flag read at execution time (lines 2273–2277): The scheduler's idle callback reads cached_transaction_flags at dispatch time, not at authorization time. If flags were overwritten between authorization and execution, the backend sees the attacker's flags.",
      "pocConfidence": "confirmed",
      "pocCount": 3,
      "pocTopStars": 1,
      "pocRepos": [
        {
          "url": "https://github.com/mawussid/CVE-2026-41651-Python",
          "stars": 1,
          "desc": "",
          "createdAt": "2026-05-06",
          "hasCode": true
        },
        {
          "url": "https://github.com/aexdyhaxor/CVE-2026-41651",
          "stars": 0,
          "desc": "Privilege Escalation Vulnerability in PackageKit (TOCTOU Race Condition)",
          "createdAt": "2026-05-03",
          "hasCode": true
        },
        {
          "url": "https://github.com/Lutfifakee-Project/CVE-2026-41651",
          "stars": 0,
          "desc": "Exploit for CVE-2026-41651 - PackageKit TOCTOU Local Privilege Escalation (Pack2TheRoot)",
          "createdAt": "2026-05-20",
          "hasCode": true
        }
      ],
      "epss": 0.0046,
      "epssPercentile": 0.3711,
      "source": "poc",
      "mitreUrl": "https://nvd.nist.gov/vuln/detail/CVE-2026-41651",
      "research": [
        {
          "url": "https://github.com/Vozec/CVE-2026-41651",
          "type": "poc",
          "source": "Vozec",
          "note": "TOCTOU race PoC for PackageKit LPE",
          "hasCode": true
        },
        {
          "url": "https://www.thecybersignal.com/pack2theroot-cve-2026-41651-cross-distro-linux-lpe-in-packagekit/",
          "type": "writeup",
          "source": "TheCyberSignal",
          "note": "Pack2TheRoot cross-distro Linux LPE"
        },
        {
          "url": "https://cvereports.com/reports/CVE-2026-41651",
          "type": "writeup",
          "source": "CVEReports",
          "note": "LPE via TOCTOU race in PackageKit"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-41651",
          "type": "writeup",
          "source": "NVD",
          "note": "Official CVE detail"
        }
      ],
      "x": {
        "mentions": 1,
        "aliases": [
          "Pack2TheRoot"
        ],
        "posts": [
          {
            "handle": "lyrie_ai",
            "followers": 236,
            "likes": 2,
            "createdAt": "2026-05-19",
            "url": "https://x.com/lyrie_ai/status/2056726635349754251",
            "github": [],
            "origin": false
          }
        ]
      },
      "aliases": [
        "Pack2TheRoot"
      ],
      "researchers": [
        "Telkom Security"
      ],
      "bsky": {
        "mentions": 16,
        "posts": [
          {
            "handle": "hackread.bsky.social",
            "displayName": "Hackread.com",
            "likes": 1,
            "reposts": 3,
            "replies": 0,
            "createdAt": "2026-04-28",
            "url": "https://bsky.app/profile/hackread.bsky.social/post/3mkl4hjl2s22i",
            "origin": true,
            "authority": false,
            "github": []
          },
          {
            "handle": "it-connect.bsky.social",
            "displayName": "IT-Connect",
            "likes": 1,
            "reposts": 0,
            "replies": 0,
            "createdAt": "2026-04-27",
            "url": "https://bsky.app/profile/it-connect.bsky.social/post/3mkhnora4vl2v",
            "origin": true,
            "authority": false,
            "github": []
          },
          {
            "handle": "lalgorisme.bsky.social",
            "displayName": "L'algorisme",
            "likes": 2,
            "reposts": 2,
            "replies": 1,
            "createdAt": "2026-04-24",
            "url": "https://bsky.app/profile/lalgorisme.bsky.social/post/3mk7vltxar22d",
            "origin": false,
            "authority": false,
            "github": []
          },
          {
            "handle": "bisexualwoman.bsky.social",
            "displayName": "jolynecore 🍟",
            "likes": 1,
            "reposts": 0,
            "replies": 1,
            "createdAt": "2026-04-27",
            "url": "https://bsky.app/profile/bisexualwoman.bsky.social/post/3mkiezk2erc2c",
            "origin": false,
            "authority": false,
            "github": []
          },
          {
            "handle": "buherator.bsky.social",
            "displayName": "buherator",
            "likes": 2,
            "reposts": 0,
            "replies": 0,
            "createdAt": "2026-04-23",
            "url": "https://bsky.app/profile/buherator.bsky.social/post/3mk5kyyohly23",
            "origin": false,
            "authority": false,
            "github": []
          },
          {
            "handle": "ferramentaslinux.bsky.social",
            "displayName": null,
            "likes": 0,
            "reposts": 0,
            "replies": 1,
            "createdAt": "2026-05-18",
            "url": "https://bsky.app/profile/ferramentaslinux.bsky.social/post/3mm5kizznyk2c",
            "origin": false,
            "authority": false,
            "github": []
          }
        ]
      }
    },
    {
      "cve": "CVE-2026-1492",
      "title": "The User Registration & Membership – Custom Registration Form Builder, Custom Login…",
      "category": "Recall",
      "vendor": null,
      "exploited": false,
      "publiclyDisclosed": true,
      "cvss": 9.8,
      "cvssVector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "severity": "CRITICAL",
      "impact": null,
      "products": [],
      "productCount": 0,
      "faq": "The User Registration & Membership – Custom Registration Form Builder, Custom Login Form, User Profile, Content Restriction & Membership Plugin plugin for WordPress is vulnerable to improper privilege management in all versions up to, and including, 5.1.2. This is due to the plugin accepting a user-supplied role during membership registration without properly enforcing a server-side allowlist. This makes it possible for unauthenticated attackers to create administrator accounts by supplying a role value during membership registration.",
      "pocConfidence": "confirmed",
      "pocCount": 3,
      "pocTopStars": 0,
      "pocRepos": [
        {
          "url": "https://github.com/Nxploited/CVE-2026-1492",
          "stars": 0,
          "desc": "User Registration & Membership <= 5.1.2 - Unauthenticated Privilege Escalation via Membership Registration",
          "createdAt": "2026-04-18",
          "hasCode": true
        },
        {
          "url": "https://github.com/the8frust/CVE-2026-1492",
          "stars": 0,
          "desc": "Exploit for CVE-2026-1492 affecting the WordPress User Registration plugin, allowing unauthenticated attackers to register accounts and escalate privileges to a",
          "createdAt": "2026-03-20",
          "hasCode": true
        },
        {
          "url": "https://github.com/imad-z1/CVE-2026-1492-POC",
          "stars": 0,
          "desc": "User Registration & Membership <= 5.1.2 - Unauthenticated Privilege Escalation via Membership Registration",
          "createdAt": "2026-03-07",
          "hasCode": true
        }
      ],
      "epss": 0.25532,
      "epssPercentile": 0.9773,
      "source": "poc",
      "mitreUrl": "https://nvd.nist.gov/vuln/detail/CVE-2026-1492",
      "bsky": {
        "mentions": 17,
        "posts": [
          {
            "handle": "cve.skyfleet.blue",
            "displayName": "CVE Alerts ",
            "likes": 1,
            "reposts": 0,
            "replies": 0,
            "createdAt": "2026-03-03",
            "url": "https://bsky.app/profile/cve.skyfleet.blue/post/3mg5cdu35a62o",
            "origin": false,
            "authority": false,
            "github": []
          },
          {
            "handle": "undercode.bsky.social",
            "displayName": "Undercode Testing",
            "likes": 0,
            "reposts": 0,
            "replies": 0,
            "createdAt": "2026-04-14",
            "url": "https://bsky.app/profile/undercode.bsky.social/post/3mji2taifo32p",
            "origin": false,
            "authority": false,
            "github": []
          },
          {
            "handle": "beikokucyber.bsky.social",
            "displayName": "Beikoku Cybersecurity",
            "likes": 0,
            "reposts": 0,
            "replies": 0,
            "createdAt": "2026-03-13",
            "url": "https://bsky.app/profile/beikokucyber.bsky.social/post/3mgxssvol2y27",
            "origin": false,
            "authority": false,
            "github": []
          },
          {
            "handle": "thedailytechfeed.com",
            "displayName": "The Daily Tech Feed",
            "likes": 0,
            "reposts": 0,
            "replies": 0,
            "createdAt": "2026-03-08",
            "url": "https://bsky.app/profile/thedailytechfeed.com/post/3mgjtv3ia7s2x",
            "origin": false,
            "authority": false,
            "github": []
          },
          {
            "handle": "it-connect.bsky.social",
            "displayName": "IT-Connect",
            "likes": 0,
            "reposts": 0,
            "replies": 0,
            "createdAt": "2026-03-06",
            "url": "https://bsky.app/profile/it-connect.bsky.social/post/3mgfbsdobpf2u",
            "origin": false,
            "authority": false,
            "github": []
          },
          {
            "handle": "jimguckin.bsky.social",
            "displayName": "Jim Guckin",
            "likes": 0,
            "reposts": 0,
            "replies": 0,
            "createdAt": "2026-03-06",
            "url": "https://bsky.app/profile/jimguckin.bsky.social/post/3mgfvrgvo3g2j",
            "origin": false,
            "authority": false,
            "github": []
          }
        ]
      },
      "telegram": {
        "mentions": 0,
        "posts": []
      },
      "research": [],
      "aliases": [],
      "researchers": [],
      "x": {
        "mentions": 0,
        "aliases": [],
        "posts": []
      }
    },
    {
      "cve": "CVE-2026-29000",
      "title": "pac4j-jwt versions prior to 4.5.9, 5.7.9, and 6.3.3 contain an authentication bypass…",
      "category": "Recall",
      "vendor": null,
      "exploited": false,
      "publiclyDisclosed": true,
      "cvss": 9.1,
      "cvssVector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N",
      "severity": "CRITICAL",
      "impact": null,
      "products": [],
      "productCount": 0,
      "faq": "pac4j-jwt versions prior to 4.5.9, 5.7.9, and 6.3.3 contain an authentication bypass vulnerability in JwtAuthenticator when processing encrypted JWTs that allows remote attackers to forge authentication tokens. Attackers who possess the server's RSA public key can create a JWE-wrapped PlainJWT with arbitrary subject and role claims, bypassing signature verification to authenticate as any user including administrators.",
      "pocConfidence": "confirmed",
      "pocCount": 3,
      "pocTopStars": 0,
      "pocRepos": [
        {
          "url": "https://github.com/zF-tm/CVE-2026-29000",
          "stars": 0,
          "desc": "PoC of the CVE-2026-29000",
          "createdAt": "2026-05-05",
          "hasCode": true
        },
        {
          "url": "https://github.com/tc4dy/CVE-2026-29000-PoC-Exploit",
          "stars": 0,
          "desc": "CVE-2026-29000 – pac4j-jwt Authentication Bypass (🔥 CVSS 10.0). One-click admin forge via public key JWE wrapping. Leaks configs, users, secrets. Keep-alive, p",
          "createdAt": "2026-05-12",
          "hasCode": true
        },
        {
          "url": "https://github.com/c0gnit00/CVE-2026-29000",
          "stars": 0,
          "desc": "Python POC, Exploit for CVE-2026-29000",
          "createdAt": "2026-05-30",
          "hasCode": true
        },
        {
          "url": "https://github.com/ledksv/Principal-HackTheBox",
          "stars": 0,
          "desc": "Writeup for Principal — HackTheBox Medium Linux box. CVE-2026-29000 pac4j JWT bypass, credentials from API settings, SSH CA privesc to root.",
          "createdAt": "2026-05-05",
          "hasCode": false
        }
      ],
      "epss": 0.05856,
      "epssPercentile": 0.92383,
      "source": "poc",
      "mitreUrl": "https://nvd.nist.gov/vuln/detail/CVE-2026-29000",
      "research": [
        {
          "url": "https://github.com/cipher1x1/CVE-2026-29000",
          "type": "poc",
          "source": "GitHub (cipher1x1)",
          "note": "pac4j-jwt auth-bypass PoC (forge JWT with only the public key)",
          "hasCode": true
        },
        {
          "url": "https://www.codeant.ai/security-research/pac4j-jwt-authentication-bypass-public-key",
          "type": "writeup",
          "source": "CodeAnt",
          "note": "JWE-wrapped alg:none inner JWT, signature not enforced"
        }
      ],
      "x": {
        "mentions": 10,
        "posts": [
          {
            "handle": "0xdf_",
            "followers": 26294,
            "likes": 38,
            "createdAt": "2026-03-30",
            "url": "https://x.com/0xdf_/status/2038545567857426891",
            "origin": false,
            "github": []
          },
          {
            "handle": "TweetThreatNews",
            "followers": 4338,
            "likes": 1,
            "createdAt": "2026-04-07",
            "url": "https://x.com/TweetThreatNews/status/2041406894523208085",
            "origin": false,
            "github": []
          },
          {
            "handle": "HTBJill",
            "followers": 258,
            "likes": 1,
            "createdAt": "2026-03-16",
            "url": "https://x.com/HTBJill/status/2033600593567101213",
            "origin": false,
            "github": []
          },
          {
            "handle": "cshekhar",
            "followers": 541,
            "likes": 0,
            "createdAt": "2026-05-30",
            "url": "https://x.com/cshekhar/status/2060708528684482626",
            "origin": false,
            "github": []
          },
          {
            "handle": "TheRabbitPy",
            "followers": 1312,
            "likes": 0,
            "createdAt": "2026-03-30",
            "url": "https://x.com/TheRabbitPy/status/2038675331238785409",
            "origin": false,
            "github": []
          },
          {
            "handle": "psyciclabs",
            "followers": 16,
            "likes": 0,
            "createdAt": "2026-03-30",
            "url": "https://x.com/psyciclabs/status/2038665498699968761",
            "origin": false,
            "github": []
          }
        ],
        "aliases": []
      },
      "researchers": [
        "cipher1x1"
      ],
      "bsky": {
        "mentions": 15,
        "posts": [
          {
            "handle": "cybersecurity.page",
            "displayName": "Best of r/cybersecurity",
            "likes": 4,
            "reposts": 1,
            "replies": 0,
            "createdAt": "2026-03-05",
            "url": "https://bsky.app/profile/cybersecurity.page/post/3mgcwhwd4cd2a",
            "origin": false,
            "authority": false,
            "github": []
          },
          {
            "handle": "hendryadrian.bsky.social",
            "displayName": "Cybersecurity News Everyday",
            "likes": 1,
            "reposts": 0,
            "replies": 1,
            "createdAt": "2026-04-07",
            "url": "https://bsky.app/profile/hendryadrian.bsky.social/post/3miv6kcnksc2s",
            "origin": false,
            "authority": false,
            "github": []
          },
          {
            "handle": "opsmatters.com",
            "displayName": "OpsMatters",
            "likes": 1,
            "reposts": 1,
            "replies": 0,
            "createdAt": "2026-03-06",
            "url": "https://bsky.app/profile/opsmatters.com/post/3mggbhidpu52i",
            "origin": false,
            "authority": false,
            "github": []
          },
          {
            "handle": "cyberhub.blog",
            "displayName": "CyberHub",
            "likes": 1,
            "reposts": 0,
            "replies": 0,
            "createdAt": "2026-03-05",
            "url": "https://bsky.app/profile/cyberhub.blog/post/3mgcyl5rjtt2u",
            "origin": false,
            "authority": false,
            "github": []
          },
          {
            "handle": "0xdf.bsky.social",
            "displayName": "0xdf",
            "likes": 0,
            "reposts": 0,
            "replies": 0,
            "createdAt": "2026-03-30",
            "url": "https://bsky.app/profile/0xdf.bsky.social/post/3mibd6ypyn52i",
            "origin": false,
            "authority": false,
            "github": []
          },
          {
            "handle": "infosecbot.bsky.social",
            "displayName": "Botty.bot",
            "likes": 0,
            "reposts": 0,
            "replies": 0,
            "createdAt": "2026-03-16",
            "url": "https://bsky.app/profile/infosecbot.bsky.social/post/3mh7q3kd32o23",
            "origin": false,
            "authority": false,
            "github": []
          }
        ]
      },
      "telegram": {
        "mentions": 0,
        "posts": []
      },
      "aliases": []
    },
    {
      "cve": "CVE-2026-3609",
      "title": "Wellbia's XIGNCODE3 xhunter1.sys kernel driver Privilege Escalation Vulnerability…",
      "category": "Recall",
      "vendor": null,
      "exploited": false,
      "publiclyDisclosed": true,
      "cvss": 7.8,
      "cvssVector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "severity": "HIGH",
      "impact": null,
      "products": [],
      "productCount": 0,
      "faq": "Wellbia's XIGNCODE3 xhunter1.sys kernel driver Privilege Escalation Vulnerability provides access to IRP_MJ_REITS command interface, which allows any user process to request a PROCESS_ALL_ACCESS.\r\nCross reference to KVE 2023-5589 (https://krcert.or.kr)",
      "pocConfidence": "confirmed",
      "pocCount": 2,
      "pocTopStars": 797,
      "pocRepos": [
        {
          "url": "https://github.com/BlackSnufkin/BYOVD",
          "stars": 797,
          "desc": "BYOVD research use cases featuring vulnerable driver discovery and reverse engineering methodology.  (CVE-2025-52915,  CVE-2025-1055, CVE-2026-3609, CVE-2026-85",
          "createdAt": "2023-12-05",
          "hasCode": true
        },
        {
          "url": "https://github.com/BlackSnufkin/CredsHunter",
          "stars": 24,
          "desc": "PoC for CVE-2026-3609 - XIGNCODE3 xhunter1.sys handle leak enabling PPL bypass and LSASS dumping",
          "createdAt": "2026-05-12",
          "hasCode": true
        }
      ],
      "epss": 0.00176,
      "epssPercentile": 0.07312,
      "source": "poc",
      "mitreUrl": "https://nvd.nist.gov/vuln/detail/CVE-2026-3609",
      "research": [],
      "x": {
        "mentions": 2,
        "posts": [
          {
            "handle": "v1ckxy_overdose",
            "followers": 158,
            "likes": 0,
            "createdAt": "2026-05-22",
            "url": "https://x.com/v1ckxy_overdose/status/2057943270483783882",
            "origin": false,
            "github": []
          },
          {
            "handle": "CVEnew",
            "followers": 57565,
            "likes": 0,
            "createdAt": "2026-05-11",
            "url": "https://x.com/CVEnew/status/2053932451794497966",
            "origin": false,
            "github": []
          }
        ],
        "aliases": []
      },
      "aliases": [],
      "researchers": [],
      "bsky": {
        "mentions": 0,
        "posts": []
      }
    },
    {
      "cve": "CVE-2026-34197",
      "title": "Improper Input Validation, Improper Control of Generation of Code ('Code Injection')…",
      "category": "Recall",
      "vendor": null,
      "exploited": true,
      "publiclyDisclosed": true,
      "cvss": 8.8,
      "cvssVector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "severity": "HIGH",
      "impact": null,
      "products": [],
      "productCount": 0,
      "faq": "Improper Input Validation, Improper Control of Generation of Code ('Code Injection') vulnerability in Apache ActiveMQ Broker, Apache ActiveMQ.\n\nApache ActiveMQ Classic exposes the Jolokia JMX-HTTP bridge at /api/jolokia/ on the web console. The default Jolokia access policy permits exec operations on all ActiveMQ MBeans (org.apache.activemq:*), including\nBrokerService.addNetworkConnector(String) and BrokerService.addConnector(String).\n\nAn authenticated attacker can invoke these operations with a crafted discovery URI that triggers the VM transport's brokerConfig parameter to load a remote Spring XML application context using ResourceXmlApplicationContext.\nBecause Spring's ResourceXmlApplicationContext instantiates all singleton beans before the BrokerService validates the configuration, arbitrary code execution occurs on the broker's JVM through bean factory methods such as Runtime.exec().\n\n\n\nThis issue affects Apache ActiveMQ Broker: before 5.19.4, from 6.0.0 before 6.2.3; Apache ActiveMQ All: before 5.19.4, from 6.0.0 before 6.2.3; Apache ActiveMQ: before 5.19.4, from 6.0.0 before 6.2.3.\n\n\n\nUsers are recommended to upgrade to version 5.19.4 or 6.2.3, which fixes the issue",
      "pocConfidence": "confirmed",
      "pocCount": 2,
      "pocTopStars": 78,
      "pocRepos": [
        {
          "url": "https://github.com/hnytgl/CVE-2026-34197",
          "stars": 1,
          "desc": "这是一个面向防守和内网排查的 Apache ActiveMQ Classic 暴露面检测工具，用于辅助评估 CVE-2026-34197 相关风险。",
          "createdAt": "2026-05-18",
          "hasCode": true
        },
        {
          "url": "https://github.com/asdasddqwdq29-a11y/CVE-2026-34197",
          "stars": 0,
          "desc": "Apache ActiveMQ RCE via Jolokia vulnerability analysis and reproduction notes",
          "createdAt": "2026-06-06",
          "hasCode": true
        },
        {
          "url": "https://github.com/Catherines77/ActiveMQ-EXPtools",
          "stars": 78,
          "desc": "Apache ActiveMQ漏洞综合利用工具(CVE-2015-5254，CVE-2016-3088，CVE-2022-41678，CVE-2023-46604，CVE-2024-32114，CVE-2026-34197，CVE-2026-40466， CVE-2026-42588)",
          "createdAt": "2026-04-20",
          "hasCode": false
        }
      ],
      "epss": 0.96666,
      "epssPercentile": 0.99878,
      "source": "poc",
      "mitreUrl": "https://nvd.nist.gov/vuln/detail/CVE-2026-34197",
      "research": [
        {
          "url": "https://github.com/KONDORDEVSECURITYCORP/CVE-2026-34197",
          "type": "poc",
          "source": "KONDOR DEV SECURITY",
          "note": "First public PoC, Jolokia RCE",
          "hasCode": true
        },
        {
          "url": "https://horizon3.ai/attack-research/disclosures/cve-2026-34197-activemq-rce-jolokia/",
          "type": "writeup",
          "source": "Horizon3.ai",
          "note": "Attack-research disclosure"
        },
        {
          "url": "https://www.securityweek.com/rce-bug-lurked-in-apache-activemq-classic-for-13-years/",
          "type": "writeup",
          "source": "SecurityWeek",
          "note": "13-year-old RCE"
        },
        {
          "url": "https://www.bleepingcomputer.com/news/security/cisa-flags-apache-activemq-flaw-as-actively-exploited-in-attacks/",
          "type": "writeup",
          "source": "BleepingComputer",
          "note": "CISA KEV / ITW"
        }
      ],
      "x": {
        "mentions": 2,
        "aliases": [],
        "posts": [
          {
            "handle": "CyberDhaal",
            "followers": 45,
            "likes": 0,
            "createdAt": "2026-06-06",
            "url": "https://x.com/CyberDhaal/status/2063345652986196353",
            "github": [],
            "origin": false
          }
        ]
      },
      "researchers": [
        "Horizon3.ai"
      ],
      "bsky": {
        "mentions": 26,
        "posts": [
          {
            "handle": "cyberveille-ch.bsky.social",
            "displayName": "CyberVeille",
            "likes": 0,
            "reposts": 0,
            "replies": 0,
            "createdAt": "2025-10-14",
            "url": "https://bsky.app/profile/cyberveille-ch.bsky.social/post/3m36mpqx4z72k",
            "origin": true,
            "authority": false,
            "github": []
          },
          {
            "handle": "shadowserver.bsky.social",
            "displayName": "The Shadowserver Foundation",
            "likes": 7,
            "reposts": 3,
            "replies": 1,
            "createdAt": "2026-04-20",
            "url": "https://bsky.app/profile/shadowserver.bsky.social/post/3mjwzte2qts2k",
            "origin": false,
            "authority": true,
            "github": []
          },
          {
            "handle": "ransomnews.online",
            "displayName": "ransomNews",
            "likes": 5,
            "reposts": 3,
            "replies": 0,
            "createdAt": "2026-04-20",
            "url": "https://bsky.app/profile/ransomnews.online/post/3mjwvocp24y2e",
            "origin": false,
            "authority": false,
            "github": []
          },
          {
            "handle": "intel.overresearched.net",
            "displayName": "OverResearched Intelligence",
            "likes": 1,
            "reposts": 1,
            "replies": 1,
            "createdAt": "2026-04-21",
            "url": "https://bsky.app/profile/intel.overresearched.net/post/3mjzvj4wybs2q",
            "origin": false,
            "authority": false,
            "github": []
          },
          {
            "handle": "securityrss.bsky.social",
            "displayName": "securityrss.ai",
            "likes": 1,
            "reposts": 1,
            "replies": 0,
            "createdAt": "2026-04-10",
            "url": "https://bsky.app/profile/securityrss.bsky.social/post/3mj5bum7gmx22",
            "origin": false,
            "authority": false,
            "github": []
          },
          {
            "handle": "obivan.infosec.exchange.ap.brid.gy",
            "displayName": "Ivan Ožić Bebek",
            "likes": 2,
            "reposts": 0,
            "replies": 0,
            "createdAt": "2026-04-08",
            "url": "https://bsky.app/profile/obivan.infosec.exchange.ap.brid.gy/post/3miyy5achwnh2",
            "origin": false,
            "authority": false,
            "github": []
          }
        ]
      },
      "telegram": {
        "mentions": 6,
        "posts": [
          {
            "channel": "thehackernews",
            "channelTitle": "The Hacker News",
            "tier": "news",
            "date": "2026-04-10",
            "views": 10271,
            "forwards": 38,
            "url": "https://t.me/thehackernews/8777",
            "text": "A 13-year-old flaw in Apache ActiveMQ can lead to RCE. CVE-2026-34197 lets attackers run OS commands via the Jolokia API. Chained with CVE-2024-32114, it becomes unauthenticated RCE on some versions. Patched in 5.19.4 and 6.2.3. 🔗 Learn more → https://thehackernews.com/2026/04/threatsday-bulletin-hybrid-p2p-botnet.html#chained-flaws-enable-stealth-rce",
            "github": [],
            "origin": false
          }
        ]
      },
      "aliases": []
    },
    {
      "cve": "CVE-2026-49975",
      "title": "Memory Allocation with Excessive Size Value vulnerability in Apache HTTP Server's…",
      "category": "Recall",
      "vendor": null,
      "exploited": false,
      "publiclyDisclosed": true,
      "cvss": 7.5,
      "cvssVector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
      "severity": "HIGH",
      "impact": null,
      "products": [],
      "productCount": 0,
      "faq": "Memory Allocation with Excessive Size Value vulnerability in Apache HTTP Server's mod_http leads to denial of service via malicious HTTP requests.\n\nThis issue affects Apache HTTP Server: from 2.4.17 through 2.4.67.",
      "pocConfidence": "confirmed",
      "pocCount": 2,
      "pocTopStars": 21,
      "pocRepos": [
        {
          "url": "https://github.com/mrx-arafat/CVE-2026-49975-POC",
          "stars": 21,
          "desc": "HTTP/2 Bomb PoC — CVE-2026-49975 (HPACK indexed reference bomb + flow-control stall)",
          "createdAt": "2026-06-04",
          "hasCode": true
        },
        {
          "url": "https://github.com/obrige/http2-bomb",
          "stars": 3,
          "desc": "CVE-2026-49975 HTTP/2 Stream Amplification — Docker PoC with Web Console",
          "createdAt": "2026-06-05",
          "hasCode": true
        },
        {
          "url": "https://github.com/fevar54/Proof-of-Concept-POC---CVE-2026-49975-HTTP-2-Bomb-",
          "stars": 5,
          "desc": "Este repositorio contiene un Proof of Concept (POC) para CVE-2026-49975, también conocida como HTTP/2 Bomb, una vulnerabilidad de denegación de servicio (DoS) r",
          "createdAt": "2026-06-03",
          "hasCode": false
        },
        {
          "url": "https://github.com/LSG-PolarBear/CVE-2026-49975",
          "stars": 3,
          "desc": "CVE-2026-49975漏洞复现",
          "createdAt": "2026-06-10",
          "hasCode": false
        },
        {
          "url": "https://github.com/renzi25031469/CVE-2026-49975-HTTP-2-Bomb",
          "stars": 1,
          "desc": "Disclosed on June 3, 2026, the \"HTTP/2 Bomb\" is an unauthenticated remote DoS that combines an HPACK compression bomb with a Slowloris-style hold to exhaust ser",
          "createdAt": "2026-06-08",
          "hasCode": false
        },
        {
          "url": "https://github.com/minc-nice-100/http2-bomb-analysis-paper",
          "stars": 1,
          "desc": "HTTP/2 Bomb: HPACK indexed-reference amplification + flow-control stall. A high school student's full protocol analysis (LaTeX). CVE-2026-49975, CVE-2026-47774.",
          "createdAt": "2026-06-13",
          "hasCode": false
        }
      ],
      "epss": 0.11471,
      "epssPercentile": 0.95544,
      "source": "poc",
      "mitreUrl": "https://nvd.nist.gov/vuln/detail/CVE-2026-49975",
      "research": [
        {
          "url": "https://blog.calif.io/p/codex-discovered-a-hidden-http2-bomb",
          "type": "writeup",
          "source": "Calif",
          "note": "Discoverer writeup: HPACK bomb + flow-control stall"
        },
        {
          "url": "https://www.securityweek.com/http-2-bomb-exploit-knocks-web-servers-offline-in-seconds/",
          "type": "writeup",
          "source": "SecurityWeek",
          "note": "HTTP/2 Bomb knocks servers offline"
        },
        {
          "url": "https://www.bleepingcomputer.com/news/security/new-http-2-bomb-dos-attack-crashes-web-servers-in-under-a-minute/",
          "type": "writeup",
          "source": "BleepingComputer",
          "note": "DoS crashes web servers under a minute"
        },
        {
          "url": "https://www.haproxy.com/blog/haproxy-cve-2026-49975-http2-bomb",
          "type": "detection",
          "source": "HAProxy",
          "note": "Mitigation guidance"
        }
      ],
      "x": {
        "mentions": 4,
        "aliases": [
          "HTTP/2 Bomb"
        ],
        "posts": [
          {
            "handle": "burnworks",
            "followers": 2201,
            "likes": 0,
            "createdAt": "2026-06-06",
            "url": "https://x.com/burnworks/status/2063055729087705339",
            "github": [
              {
                "url": "https://github.com/califio/publications/blob/main/MADBugs/http2-bomb/blog.md",
                "hasCode": true
              }
            ],
            "origin": false
          },
          {
            "handle": "ThreatAft",
            "followers": 26,
            "likes": 1,
            "createdAt": "2026-06-03",
            "url": "https://x.com/ThreatAft/status/2062136027138097191",
            "github": [],
            "origin": false
          },
          {
            "handle": "XavierRiveraX",
            "followers": 566,
            "likes": 0,
            "createdAt": "2026-06-03",
            "url": "https://x.com/XavierRiveraX/status/2062150720472699096",
            "github": [],
            "origin": false
          },
          {
            "handle": "L1gs_t",
            "followers": 31,
            "likes": 0,
            "createdAt": "2026-06-04",
            "url": "https://x.com/L1gs_t/status/2062377512219656607",
            "github": [],
            "origin": false
          }
        ]
      },
      "aliases": [
        "HTTP/2 Bomb"
      ],
      "researchers": [
        "Calif"
      ],
      "bsky": {
        "mentions": 23,
        "posts": [
          {
            "handle": "campuscodi.risky.biz",
            "displayName": "Catalin Cimpanu",
            "likes": 11,
            "reposts": 0,
            "replies": 0,
            "createdAt": "2026-06-04",
            "url": "https://bsky.app/profile/campuscodi.risky.biz/post/3mngezy5xec2a",
            "origin": true,
            "authority": true,
            "github": []
          },
          {
            "handle": "infosec.skyfleet.blue",
            "displayName": "InfoSec",
            "likes": 3,
            "reposts": 2,
            "replies": 0,
            "createdAt": "2026-06-03",
            "url": "https://bsky.app/profile/infosec.skyfleet.blue/post/3mnem72g2du2q",
            "origin": true,
            "authority": true,
            "github": []
          },
          {
            "handle": "techmeme.com",
            "displayName": "Techmeme",
            "likes": 4,
            "reposts": 2,
            "replies": 0,
            "createdAt": "2026-06-03",
            "url": "https://bsky.app/profile/techmeme.com/post/3mnfu7osguf26",
            "origin": true,
            "authority": false,
            "github": []
          },
          {
            "handle": "pwnhackers.bsky.social",
            "displayName": "PWN | Hacker Community",
            "likes": 3,
            "reposts": 0,
            "replies": 0,
            "createdAt": "2026-06-05",
            "url": "https://bsky.app/profile/pwnhackers.bsky.social/post/3mnknzsnupc2b",
            "origin": true,
            "authority": false,
            "github": []
          },
          {
            "handle": "hapsis.bsky.social",
            "displayName": "Tomas Ström",
            "likes": 1,
            "reposts": 1,
            "replies": 0,
            "createdAt": "2026-06-05",
            "url": "https://bsky.app/profile/hapsis.bsky.social/post/3mnkvwfflbc2w",
            "origin": true,
            "authority": false,
            "github": []
          },
          {
            "handle": "bearstech.com",
            "displayName": "Bearstech",
            "likes": 8,
            "reposts": 4,
            "replies": 3,
            "createdAt": "2026-06-09",
            "url": "https://bsky.app/profile/bearstech.com/post/3mnuwpdazwa2v",
            "origin": false,
            "authority": false,
            "github": []
          }
        ]
      }
    },
    {
      "cve": "CVE-2026-55200",
      "title": "libssh2 through 1.11.1, fixed in commit 7acf3df contains an out-of-bounds write…",
      "category": "Recall",
      "vendor": null,
      "exploited": false,
      "publiclyDisclosed": true,
      "cvss": 8.1,
      "cvssVector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "severity": "HIGH",
      "impact": null,
      "products": [],
      "productCount": 0,
      "faq": "libssh2 through 1.11.1, fixed in commit 7acf3df contains an out-of-bounds write vulnerability in ssh2_transport_read() that fails to enforce upper bounds on packet_length field. Remote attackers can send crafted SSH packets with excessively large packet_length values to corrupt heap memory and achieve remote code execution.",
      "pocConfidence": "confirmed",
      "pocCount": 2,
      "pocTopStars": 10,
      "pocRepos": [
        {
          "url": "https://github.com/0xBlackash/CVE-2026-55200",
          "stars": 10,
          "desc": "CVE-2026-55200",
          "createdAt": "2026-06-23",
          "hasCode": true
        },
        {
          "url": "https://github.com/xd20111/CVE-2026-55200",
          "stars": 2,
          "desc": "CVE-2026-55200 - Critical libssh2 Remote Code Execution Vulnerability",
          "createdAt": "2026-06-29",
          "hasCode": true
        }
      ],
      "epss": 0.00732,
      "epssPercentile": 0.50315,
      "source": "poc",
      "mitreUrl": "https://nvd.nist.gov/vuln/detail/CVE-2026-55200",
      "research": [],
      "aliases": [],
      "researchers": [],
      "x": {
        "mentions": 4,
        "aliases": [],
        "posts": [
          {
            "handle": "BugHunterMX",
            "followers": 386,
            "likes": 3,
            "createdAt": "2026-07-07",
            "url": "https://x.com/BugHunterMX/status/2074321694303428650",
            "github": [],
            "origin": false
          }
        ]
      },
      "bsky": {
        "mentions": 17,
        "posts": [
          {
            "handle": "infosec.skyfleet.blue",
            "displayName": "InfoSec",
            "likes": 1,
            "reposts": 0,
            "replies": 0,
            "createdAt": "2026-06-29",
            "url": "https://bsky.app/profile/infosec.skyfleet.blue/post/3mph3iuz35w27",
            "origin": false,
            "authority": true,
            "github": []
          },
          {
            "handle": "dragostech.bsky.social",
            "displayName": "dragosr",
            "likes": 5,
            "reposts": 2,
            "replies": 0,
            "createdAt": "2026-06-23",
            "url": "https://bsky.app/profile/dragostech.bsky.social/post/3moycfogekc2a",
            "origin": false,
            "authority": false,
            "github": [
              {
                "url": "https://github.com/bikini/exploitarium/tree/main/libssh2-cve-2026-55200-poc",
                "hasCode": true
              }
            ]
          },
          {
            "handle": "nixpkgssecuritychanges.gerbet.me",
            "displayName": "nixpkgs security changes",
            "likes": 0,
            "reposts": 0,
            "replies": 0,
            "createdAt": "2026-07-01",
            "url": "https://bsky.app/profile/nixpkgssecuritychanges.gerbet.me/post/3mplizdeqri2n",
            "origin": false,
            "authority": false,
            "github": [
              {
                "url": "https://github.com/NixOS/nixpkgs/pull/537259",
                "hasCode": true
              }
            ]
          },
          {
            "handle": "xeiaso.net",
            "displayName": "Xe",
            "likes": 31,
            "reposts": 2,
            "replies": 1,
            "createdAt": "2026-06-24",
            "url": "https://bsky.app/profile/xeiaso.net/post/3mp2gzlpqgq23",
            "origin": false,
            "authority": false,
            "github": []
          },
          {
            "handle": "thedailytechfeed.com",
            "displayName": "The Daily Tech Feed",
            "likes": 1,
            "reposts": 1,
            "replies": 0,
            "createdAt": "2026-06-23",
            "url": "https://bsky.app/profile/thedailytechfeed.com/post/3mox2vyt24t24",
            "origin": false,
            "authority": false,
            "github": []
          },
          {
            "handle": "mbsplugins.bsky.social",
            "displayName": "Monkeybread Software",
            "likes": 0,
            "reposts": 0,
            "replies": 1,
            "createdAt": "2026-07-06",
            "url": "https://bsky.app/profile/mbsplugins.bsky.social/post/3mpxqpd2du22p",
            "origin": false,
            "authority": false,
            "github": []
          }
        ]
      }
    },
    {
      "cve": "CVE-2026-0828",
      "title": "BYOVD research performed by KOSEC. Includes vulnerable drivers and writeups (CVE-2026-0828).",
      "category": "Recall",
      "vendor": null,
      "exploited": false,
      "publiclyDisclosed": true,
      "cvss": null,
      "cvssVector": null,
      "severity": null,
      "impact": null,
      "products": [],
      "productCount": 0,
      "faq": null,
      "pocConfidence": "confirmed",
      "pocCount": 2,
      "pocTopStars": 8,
      "pocRepos": [
        {
          "url": "https://github.com/KOSEC-LLC/BYOVD-Research",
          "stars": 8,
          "desc": "BYOVD research performed by KOSEC. Includes vulnerable drivers and writeups (CVE-2026-0828).",
          "createdAt": "2025-10-15",
          "hasCode": true
        },
        {
          "url": "https://github.com/wutang700/STProcessMonitorBYOVD",
          "stars": 3,
          "desc": "🛠 Exploit and control Windows processes using CVE-2025-70795 and CVE-2026-0828 with driver-based termination tools.",
          "createdAt": "2024-04-20",
          "hasCode": true
        }
      ],
      "epss": 0.00461,
      "epssPercentile": 0.3723,
      "source": "poc",
      "mitreUrl": "https://nvd.nist.gov/vuln/detail/CVE-2026-0828",
      "research": [
        {
          "url": "https://kosec.io/windows/2025/11/01/safetica-byovd.html",
          "type": "writeup",
          "source": "KOSEC",
          "note": "Safetica ProcessMonitorDriver kernel bypass"
        },
        {
          "url": "https://socprime.com/active-threats/safetica-contains-a-kernel-driver-vulnerability/",
          "type": "writeup",
          "source": "SOC Prime",
          "note": "Driver flaw enables arbitrary process termination"
        },
        {
          "url": "https://www.aioncloud.com/2026-04-vulnerability-report-byovd-in-practice-killchain-and-cve-2026-0828-analysis/",
          "type": "writeup",
          "source": "AIONCLOUD",
          "note": "BYOVD killchain analysis"
        },
        {
          "url": "https://www.tenable.com/cve/CVE-2026-0828",
          "type": "writeup",
          "source": "Tenable",
          "note": "CVE record"
        }
      ],
      "x": {
        "mentions": 10,
        "posts": [
          {
            "handle": "co11ateral",
            "followers": 7453,
            "likes": 27,
            "createdAt": "2026-04-02",
            "url": "https://x.com/co11ateral/status/2039729506412384642",
            "origin": false,
            "github": []
          },
          {
            "handle": "bytecodevm",
            "followers": 1857,
            "likes": 8,
            "createdAt": "2026-04-02",
            "url": "https://x.com/bytecodevm/status/2039718041831817595",
            "origin": false,
            "github": []
          },
          {
            "handle": "0xDeathShotXD",
            "followers": 18,
            "likes": 3,
            "createdAt": "2026-02-14",
            "url": "https://x.com/0xDeathShotXD/status/2022723149981471194",
            "origin": false,
            "github": [
              {
                "url": "https://github.com/DeathShotXD/0xKern3lCrush-Foreverday-BYOVD-CVE-2026-0828"
              }
            ]
          },
          {
            "handle": "anylink20240604",
            "followers": 422,
            "likes": 1,
            "createdAt": "2026-02-16",
            "url": "https://x.com/anylink20240604/status/2023213542141493419",
            "origin": false,
            "github": []
          },
          {
            "handle": "HackingTeam77",
            "followers": 1609,
            "likes": 0,
            "createdAt": "2026-04-06",
            "url": "https://x.com/HackingTeam77/status/2041102018043892105",
            "origin": false,
            "github": []
          }
        ],
        "aliases": []
      },
      "researchers": [
        "KOSEC"
      ],
      "aliases": [],
      "bsky": {
        "mentions": 2,
        "posts": [
          {
            "handle": "oxfemale.bsky.social",
            "displayName": null,
            "likes": 0,
            "reposts": 0,
            "replies": 0,
            "createdAt": "2026-04-02",
            "url": "https://bsky.app/profile/oxfemale.bsky.social/post/3mijhhjdi3f2u",
            "origin": false,
            "authority": false,
            "github": []
          },
          {
            "handle": "undercode.bsky.social",
            "displayName": "Undercode Testing",
            "likes": 0,
            "reposts": 0,
            "replies": 0,
            "createdAt": "2026-04-02",
            "url": "https://bsky.app/profile/undercode.bsky.social/post/3mijj2fnfed2p",
            "origin": false,
            "authority": false,
            "github": []
          }
        ]
      }
    },
    {
      "cve": "CVE-2026-44578",
      "title": "Next.js is a React framework for building full-stack web applications. From 13.4.13…",
      "category": "Recall",
      "vendor": null,
      "exploited": false,
      "publiclyDisclosed": true,
      "cvss": 8.6,
      "cvssVector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N",
      "severity": "HIGH",
      "impact": null,
      "products": [],
      "productCount": 0,
      "faq": "Next.js is a React framework for building full-stack web applications. From 13.4.13 to before 15.5.16 and 16.2.5, self-hosted applications using the built-in Node.js server can be vulnerable to server-side request forgery through crafted WebSocket upgrade requests. An attacker can cause the server to proxy requests to arbitrary internal or external destinations, which may expose internal services or cloud metadata endpoints. Vercel-hosted deployments are not affected. This vulnerability is fixed in 15.5.16 and 16.2.5.",
      "pocConfidence": "confirmed",
      "pocCount": 2,
      "pocTopStars": 7,
      "pocRepos": [
        {
          "url": "https://github.com/dinosn/CVE-2026-44578",
          "stars": 7,
          "desc": "CVE-2026-44578: Next.js WebSocket Upgrade SSRF — pre-auth credential theft via localhost:80. Lab + exploit + audit.",
          "createdAt": "2026-05-16",
          "hasCode": true
        },
        {
          "url": "https://github.com/panchocosil/verify-ghsa-c4j6-fc7j-m34r",
          "stars": 0,
          "desc": "OOB verifier for GHSA-c4j6-fc7j-m34r / CVE-2026-44578 (Next.js WebSocket-upgrade SSRF)",
          "createdAt": "2026-05-13",
          "hasCode": true
        }
      ],
      "epss": 0.38872,
      "epssPercentile": 0.98431,
      "source": "poc",
      "mitreUrl": "https://nvd.nist.gov/vuln/detail/CVE-2026-44578",
      "research": [
        {
          "url": "https://github.com/advisories/GHSA-c4j6-fc7j-m34r",
          "type": "writeup",
          "source": "GitHub Advisory",
          "note": "SSRF via WebSocket upgrade requests",
          "hasCode": null
        },
        {
          "url": "https://horizon3.ai/attack-research/vulnerabilities/cve-2026-44578/",
          "type": "writeup",
          "source": "Horizon3.ai",
          "note": "Next.js SSRF attack research"
        },
        {
          "url": "https://hadrian.io/blog/next-js-websocket-ssrf-unauthenticated-access-to-internal-resources-cve-2026-44578-2",
          "type": "writeup",
          "source": "Hadrian",
          "note": "Unauth WebSocket SSRF to internal resources"
        },
        {
          "url": "https://www.tenable.com/cve/CVE-2026-44578",
          "type": "writeup",
          "source": "Tenable",
          "note": "CVE record, CVSS 8.6"
        }
      ],
      "x": {
        "mentions": 24,
        "aliases": [],
        "posts": [
          {
            "handle": "dwisiswant0",
            "followers": 15991,
            "likes": 656,
            "createdAt": "2026-05-08",
            "url": "https://x.com/dwisiswant0/status/2052819073357222100",
            "github": [
              {
                "url": "https://github.com/dwisiswant0/next-16.2.4-pocs",
                "hasCode": null
              }
            ],
            "origin": false
          },
          {
            "handle": "Dinosn",
            "followers": 156825,
            "likes": 211,
            "createdAt": "2026-05-10",
            "url": "https://x.com/Dinosn/status/2053356004352413802",
            "github": [
              {
                "url": "https://github.com/dwisiswant0/next-16.2.4-pocs",
                "hasCode": null
              }
            ],
            "origin": false
          },
          {
            "handle": "Psycho10k_",
            "followers": 456,
            "likes": 44,
            "createdAt": "2026-05-11",
            "url": "https://x.com/Psycho10k_/status/2053810872867303485",
            "github": [
              {
                "url": "https://github.com/dwisiswant0/next-16.2.4-pocs",
                "hasCode": null
              }
            ],
            "origin": false
          },
          {
            "handle": "termireum",
            "followers": 1079,
            "likes": 18,
            "createdAt": "2026-05-09",
            "url": "https://x.com/termireum/status/2053169243651530804",
            "github": [
              {
                "url": "https://github.com/dwisiswant0/next-16.2.4-pocs",
                "hasCode": null
              }
            ],
            "origin": false
          },
          {
            "handle": "love07oj",
            "followers": 12,
            "likes": 11,
            "createdAt": "2026-05-15",
            "url": "https://x.com/love07oj/status/2055346146982465674",
            "github": [
              {
                "url": "https://github.com/love07oj/nextjs-cve-2026-44578",
                "hasCode": true
              }
            ],
            "origin": false
          },
          {
            "handle": "0x0Huda",
            "followers": 526,
            "likes": 5,
            "createdAt": "2026-05-10",
            "url": "https://x.com/0x0Huda/status/2053553625109024986",
            "github": [
              {
                "url": "https://github.com/dwisiswant0/next-16.2.4-pocs",
                "hasCode": null
              }
            ],
            "origin": false
          },
          {
            "handle": "ihebhamad514",
            "followers": 727,
            "likes": 2,
            "createdAt": "2026-05-15",
            "url": "https://x.com/ihebhamad514/status/2055358369133654135",
            "github": [
              {
                "url": "https://github.com/ynsmroztas/nextssrf",
                "hasCode": true
              }
            ],
            "origin": false
          }
        ]
      },
      "researchers": [
        "Horizon3.ai"
      ],
      "aliases": [],
      "bsky": {
        "mentions": 11,
        "posts": [
          {
            "handle": "techmeme.com",
            "displayName": "Techmeme",
            "likes": 3,
            "reposts": 3,
            "replies": 0,
            "createdAt": "2025-06-14",
            "url": "https://bsky.app/profile/techmeme.com/post/3lrkcpnilaj2i",
            "origin": true,
            "authority": false,
            "github": []
          },
          {
            "handle": "patchdayalert.com",
            "displayName": null,
            "likes": 1,
            "reposts": 0,
            "replies": 0,
            "createdAt": "2026-05-22",
            "url": "https://bsky.app/profile/patchdayalert.com/post/3mmfucrnzc62s",
            "origin": false,
            "authority": false,
            "github": []
          },
          {
            "handle": "checkmarxzero.bsky.social",
            "displayName": "Checkmarx Zero",
            "likes": 1,
            "reposts": 0,
            "replies": 0,
            "createdAt": "2026-05-19",
            "url": "https://bsky.app/profile/checkmarxzero.bsky.social/post/3mm7mrhie5k2z",
            "origin": false,
            "authority": false,
            "github": []
          },
          {
            "handle": "undercode.bsky.social",
            "displayName": "Undercode Testing",
            "likes": 1,
            "reposts": 0,
            "replies": 0,
            "createdAt": "2026-05-15",
            "url": "https://bsky.app/profile/undercode.bsky.social/post/3mlv5lalozw2u",
            "origin": false,
            "authority": false,
            "github": []
          },
          {
            "handle": "securestep9.bsky.social",
            "displayName": "Sam Stepanyan",
            "likes": 1,
            "reposts": 0,
            "replies": 0,
            "createdAt": "2026-05-07",
            "url": "https://bsky.app/profile/securestep9.bsky.social/post/3mlcfbrg7m62h",
            "origin": false,
            "authority": false,
            "github": []
          },
          {
            "handle": "cyberhub.blog",
            "displayName": "CyberHub",
            "likes": 0,
            "reposts": 0,
            "replies": 0,
            "createdAt": "2026-05-18",
            "url": "https://bsky.app/profile/cyberhub.blog/post/3mm3yt3zq6i2h",
            "origin": false,
            "authority": false,
            "github": []
          }
        ]
      }
    },
    {
      "cve": "CVE-2026-23111",
      "title": "In the Linux kernel, the following vulnerability has been resolved: netfilter:…",
      "category": "Recall",
      "vendor": null,
      "exploited": false,
      "publiclyDisclosed": true,
      "cvss": 7.8,
      "cvssVector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "severity": "HIGH",
      "impact": null,
      "products": [],
      "productCount": 0,
      "faq": "In the Linux kernel, the following vulnerability has been resolved:\n\nnetfilter: nf_tables: fix inverted genmask check in nft_map_catchall_activate()\n\nnft_map_catchall_activate() has an inverted element activity check\ncompared to its non-catchall counterpart nft_mapelem_activate() and\ncompared to what is logically required.\n\nnft_map_catchall_activate() is called from the abort path to re-activate\ncatchall map elements that were deactivated during a failed transaction.\nIt should skip elements that are already active (they don't need\nre-activation) and process elements that are inactive (they need to be\nrestored). Instead, the current code does the opposite: it skips inactive\nelements and processes active ones.\n\nCompare the non-catchall activate callback, which is correct:\n\n  nft_mapelem_activate():\n    if (nft_set_elem_active(ext, iter->genmask))\n        return 0;   /* skip active, process inactive */\n\nWith the buggy catchall version:\n\n  nft_map_catchall_activate():\n    if (!nft_set_elem_active(ext, genmask))\n        continue;   /* skip inactive, process active */\n\nThe consequence is that when a DELSET operation is aborted,\nnft_setelem_data_activate() is never called for the catchall element.\nFor NFT_GOTO verdict elements, this means nft_data_hold() is never\ncalled to restore the chain->use reference count. Each abort cycle\npermanently decrements chain->use. Once chain->use reaches zero,\nDELCHAIN succeeds and frees the chain while catchall verdict elements\nstill reference it, resulting in a use-after-free.\n\nThis is exploitable for local privilege escalation from an unprivileged\nuser via user namespaces + nftables on distributions that enable\nCONFIG_USER_NS and CONFIG_NF_TABLES.\n\nFix by removing the negation so the check matches nft_mapelem_activate():\nskip active elements, process inactive ones.",
      "pocConfidence": "confirmed",
      "pocCount": 2,
      "pocTopStars": 5,
      "pocRepos": [
        {
          "url": "https://github.com/0xBlackash/CVE-2026-23111",
          "stars": 5,
          "desc": "CVE-2026-23111",
          "createdAt": "2026-06-09",
          "hasCode": true
        },
        {
          "url": "https://github.com/seguridadentrerios/CVE-2026-23111",
          "stars": 0,
          "desc": "Vulnerabilidad nf_tables del kernel  que permite el acceso de root",
          "createdAt": "2026-06-10",
          "hasCode": true
        },
        {
          "url": "https://github.com/HORKimhab/CVE-2026-23111",
          "stars": 0,
          "desc": "CVE-2026-23111 - Linux - Draft",
          "createdAt": "2026-06-09",
          "hasCode": false
        }
      ],
      "epss": 0.00344,
      "epssPercentile": 0.26751,
      "source": "poc",
      "mitreUrl": "https://nvd.nist.gov/vuln/detail/CVE-2026-23111",
      "research": [
        {
          "url": "https://blog.exodusintel.com/2026/06/08/cve-2026-23111-linux-nf_tables-uaf-lpe/",
          "type": "poc",
          "source": "Exodus Intelligence / Oliver Sieber",
          "note": "Weaponized LPE exploit, >99% reliability, June 8"
        },
        {
          "url": "https://fuzzinglabs.com/repro-cve-2026-23111/",
          "type": "poc",
          "source": "FuzzingLabs",
          "note": "Independent RHEL 10 root exploit, April 16 Pwn2Own"
        },
        {
          "url": "https://github.com/0xBlackash/CVE-2026-23111",
          "type": "detection",
          "source": "0xBlackash / GitHub",
          "note": "Vulnerability checker/detection script in Python",
          "hasCode": true
        },
        {
          "url": "https://github.com/seguridadentrerios/CVE-2026-23111",
          "type": "detection",
          "source": "seguridadentrerios / GitHub",
          "note": "Bash audit script for CVE-2026-23111 exposure",
          "hasCode": true
        },
        {
          "url": "https://securityaffairs.com/193352/hacking/cve-2026-23111-linux-nf_tables-flaw-enables-root-exploits.html",
          "type": "writeup",
          "source": "Security Affairs",
          "note": "Covers Exodus + FuzzingLabs findings, exploit chain"
        },
        {
          "url": "https://thehackernews.com/2026/06/one-character-linux-kernel-flaw-enables.html",
          "type": "writeup",
          "source": "The Hacker News",
          "note": "Full timeline, distro impact, exploitation path summary"
        },
        {
          "url": "https://securityarsenal.com/blog/cve-2026-23111-linux-kernel-nftables-privilege-escalation-detection-and-hardening",
          "type": "detection",
          "source": "Security Arsenal",
          "note": "Sigma rules + hardening guide for nf_tables exploit"
        },
        {
          "url": "https://www.penligent.ai/hackinglabs/cve-2026-23111/",
          "type": "writeup",
          "source": "Penligent",
          "note": "Deep technical walkthrough, UAF chain, safe validation"
        }
      ],
      "x": {
        "mentions": 23,
        "aliases": [],
        "posts": [
          {
            "handle": "TheHackersNews",
            "followers": 1548858,
            "likes": 363,
            "createdAt": "2026-06-08",
            "url": "https://x.com/TheHackersNews/status/2064079847031460264",
            "github": [],
            "origin": false
          },
          {
            "handle": "TraffAlex",
            "followers": 1602,
            "likes": 5,
            "createdAt": "2026-06-11",
            "url": "https://x.com/TraffAlex/status/2065098985358901519",
            "github": [],
            "origin": false
          },
          {
            "handle": "NeoteoCom",
            "followers": 15846,
            "likes": 2,
            "createdAt": "2026-06-09",
            "url": "https://x.com/NeoteoCom/status/2064188867838681128",
            "github": [],
            "origin": false
          },
          {
            "handle": "ProtAAPP",
            "followers": 8263,
            "likes": 2,
            "createdAt": "2026-06-12",
            "url": "https://x.com/ProtAAPP/status/2065308119542993173",
            "github": [],
            "origin": false
          },
          {
            "handle": "TweetThreatNews",
            "followers": 4384,
            "likes": 2,
            "createdAt": "2026-06-08",
            "url": "https://x.com/TweetThreatNews/status/2064127859220697601",
            "github": [],
            "origin": false
          },
          {
            "handle": "ElusivePrivacy",
            "followers": 185,
            "likes": 2,
            "createdAt": "2026-06-09",
            "url": "https://x.com/ElusivePrivacy/status/2064346368492064850",
            "github": [],
            "origin": false
          },
          {
            "handle": "thecybersecguru",
            "followers": 764,
            "likes": 1,
            "createdAt": "2026-06-09",
            "url": "https://x.com/thecybersecguru/status/2064209975514431787",
            "github": [],
            "origin": false
          },
          {
            "handle": "CyberEdition",
            "followers": 730,
            "likes": 1,
            "createdAt": "2026-06-09",
            "url": "https://x.com/CyberEdition/status/2064414726189408397",
            "github": [],
            "origin": false
          }
        ]
      },
      "researchers": [
        "OliverSieber"
      ],
      "aliases": [],
      "bsky": {
        "mentions": 16,
        "posts": [
          {
            "handle": "chrisshort.net",
            "displayName": "Chris Short",
            "likes": 2,
            "reposts": 2,
            "replies": 0,
            "createdAt": "2026-06-11",
            "url": "https://bsky.app/profile/chrisshort.net/post/3mny3zgfex22t",
            "origin": false,
            "authority": false,
            "github": []
          },
          {
            "handle": "feed.igeek.gamer-geek-news.com.ap.brid.gy",
            "displayName": "input",
            "likes": 3,
            "reposts": 0,
            "replies": 0,
            "createdAt": "2026-06-10",
            "url": "https://bsky.app/profile/feed.igeek.gamer-geek-news.com.ap.brid.gy/post/3mnxtcwh4a6y2",
            "origin": false,
            "authority": false,
            "github": []
          },
          {
            "handle": "crustytldr.bsky.social",
            "displayName": null,
            "likes": 2,
            "reposts": 0,
            "replies": 0,
            "createdAt": "2026-06-18",
            "url": "https://bsky.app/profile/crustytldr.bsky.social/post/3mokl5tgfsa23",
            "origin": false,
            "authority": false,
            "github": []
          },
          {
            "handle": "iberianm.bsky.social",
            "displayName": "Citizen X",
            "likes": 2,
            "reposts": 0,
            "replies": 0,
            "createdAt": "2026-06-15",
            "url": "https://bsky.app/profile/iberianm.bsky.social/post/3mocfiskijy2f",
            "origin": false,
            "authority": false,
            "github": []
          },
          {
            "handle": "raul.mastodon.in4matics.cat.ap.brid.gy",
            "displayName": "[^BgTA^] :verified: :opensuse:",
            "likes": 2,
            "reposts": 0,
            "replies": 0,
            "createdAt": "2026-06-10",
            "url": "https://bsky.app/profile/raul.mastodon.in4matics.cat.ap.brid.gy/post/3mnw3zg7twrt2",
            "origin": false,
            "authority": false,
            "github": []
          },
          {
            "handle": "getpokemon7.bsky.social",
            "displayName": "まりーん",
            "likes": 0,
            "reposts": 0,
            "replies": 1,
            "createdAt": "2026-07-04",
            "url": "https://bsky.app/profile/getpokemon7.bsky.social/post/3mpu6q53fyk2l",
            "origin": false,
            "authority": false,
            "github": []
          }
        ]
      }
    },
    {
      "cve": "CVE-2026-25089",
      "title": "A improper neutralization of special elements used in an os command ('os command…",
      "category": "Recall",
      "vendor": null,
      "exploited": true,
      "publiclyDisclosed": true,
      "cvss": 9.8,
      "cvssVector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "severity": "CRITICAL",
      "impact": null,
      "products": [],
      "productCount": 0,
      "faq": "A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.5, FortiSandbox 4.4.0 through 4.4.8, FortiSandbox 4.2 all versions, FortiSandbox Cloud 5.0.4 through 5.0.5, FortiSandbox PaaS 5.0.4 through 5.0.5 may allow an unauthenticated attacker to execute unauthorized commands via specifically crafted HTTP requests",
      "pocConfidence": "confirmed",
      "pocCount": 2,
      "pocTopStars": 5,
      "pocRepos": [
        {
          "url": "https://github.com/HORKimhab/CVE-2026-25089",
          "stars": 5,
          "desc": "CVE-2026-25089 - Fortinet FortiSandbox",
          "createdAt": "2026-06-10",
          "hasCode": true
        },
        {
          "url": "https://github.com/0xBlackash/CVE-2026-25089",
          "stars": 2,
          "desc": "CVE-2026-25089",
          "createdAt": "2026-06-12",
          "hasCode": true
        }
      ],
      "epss": 0.36135,
      "epssPercentile": 0.98311,
      "source": "poc",
      "mitreUrl": "https://nvd.nist.gov/vuln/detail/CVE-2026-25089",
      "research": [
        {
          "url": "https://www.fortiguard.com/psirt/FG-IR-26-141",
          "type": "writeup",
          "source": "Fortinet PSIRT (official advisory)",
          "note": "Official vendor advisory; second-order OS cmd injection"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-25089",
          "type": "detection",
          "source": "NVD / NIST",
          "note": "NVD entry; CVSS 9.8 critical, CWE-78 confirmed"
        },
        {
          "url": "https://www.tenable.com/cve/CVE-2026-25089",
          "type": "detection",
          "source": "Tenable Research",
          "note": "Tenable Vulnerability Watch classification entry"
        },
        {
          "url": "https://cybersecuritynews.com/fortinet-fortisandbox-vulnerability-exploited/",
          "type": "writeup",
          "source": "CyberSecurityNews",
          "note": "Technical breakdown; reporter: Adham El Karn (Fortinet)"
        },
        {
          "url": "https://thehackernews.com/2026/06/ivanti-fortinet-and-sap-release-patches.html",
          "type": "writeup",
          "source": "The Hacker News",
          "note": "Patch context; FortiSandbox Web UI unauthenticated RCE"
        },
        {
          "url": "https://securityaffairs.com/193509/security/fortinet-patched-a-new-critical-fortisandbox-flaw.html",
          "type": "writeup",
          "source": "Security Affairs / Pierluigi Paganini",
          "note": "Summary writeup; no in-the-wild exploitation reported"
        },
        {
          "url": "https://github.com/nomi-sec/PoC-in-GitHub/blob/master/2026/CVE-2026-25089.json",
          "type": "poc",
          "source": "nomi-sec/PoC-in-GitHub (aggregator)",
          "note": "GitHub PoC tracker entry; underlying repo unresolved",
          "hasCode": false
        },
        {
          "url": "https://www.csa.gov.sg/alerts-and-advisories/alerts/al-2026-073/",
          "type": "detection",
          "source": "Cyber Security Agency of Singapore (CSA)",
          "note": "Government alert urging immediate patch application"
        }
      ],
      "x": {
        "mentions": 3,
        "aliases": [],
        "posts": [
          {
            "handle": "ptdbugs",
            "followers": 1502,
            "likes": 61,
            "createdAt": "2026-06-11",
            "url": "https://x.com/ptdbugs/status/2065015711924142538",
            "github": [],
            "origin": false
          },
          {
            "handle": "CCBalert",
            "followers": 7212,
            "likes": 0,
            "createdAt": "2026-06-11",
            "url": "https://x.com/CCBalert/status/2065075395901194533",
            "github": [],
            "origin": false
          },
          {
            "handle": "YogSoth0",
            "followers": 671,
            "likes": 0,
            "createdAt": "2026-06-10",
            "url": "https://x.com/YogSoth0/status/2064838632352239892",
            "github": [],
            "origin": false
          }
        ]
      },
      "bsky": {
        "mentions": 18,
        "posts": [
          {
            "handle": "iberianm.bsky.social",
            "displayName": "Citizen X",
            "likes": 0,
            "reposts": 1,
            "replies": 1,
            "createdAt": "2026-06-13",
            "url": "https://bsky.app/profile/iberianm.bsky.social/post/3mo67fgsf7n2r",
            "origin": false,
            "authority": false,
            "github": []
          },
          {
            "handle": "o2cloud.bsky.social",
            "displayName": "CVE by o2Cloud",
            "likes": 0,
            "reposts": 1,
            "replies": 1,
            "createdAt": "2026-06-10",
            "url": "https://bsky.app/profile/o2cloud.bsky.social/post/3mnws6ecbbi2y",
            "origin": false,
            "authority": false,
            "github": []
          },
          {
            "handle": "blackhatnews.tokyo",
            "displayName": "blackhatnews.tokyo",
            "likes": 0,
            "reposts": 1,
            "replies": 0,
            "createdAt": "2026-06-17",
            "url": "https://bsky.app/profile/blackhatnews.tokyo/post/3mohquqzh6a2d",
            "origin": false,
            "authority": false,
            "github": []
          },
          {
            "handle": "securitycyberuk.bsky.social",
            "displayName": "Security Cyber",
            "likes": 0,
            "reposts": 1,
            "replies": 0,
            "createdAt": "2026-06-10",
            "url": "https://bsky.app/profile/securitycyberuk.bsky.social/post/3mnx3gfta3s2d",
            "origin": false,
            "authority": false,
            "github": []
          },
          {
            "handle": "postac001.bsky.social",
            "displayName": "tec_acc",
            "likes": 0,
            "reposts": 1,
            "replies": 0,
            "createdAt": "2026-06-10",
            "url": "https://bsky.app/profile/postac001.bsky.social/post/3mnxbqhtuxe2r",
            "origin": false,
            "authority": false,
            "github": []
          },
          {
            "handle": "technoholic.bsky.social",
            "displayName": "Technoholic.me",
            "likes": 0,
            "reposts": 0,
            "replies": 0,
            "createdAt": "2026-06-19",
            "url": "https://bsky.app/profile/technoholic.bsky.social/post/3moo3csgxk42f",
            "origin": false,
            "authority": false,
            "github": []
          }
        ]
      },
      "telegram": {
        "mentions": 0,
        "posts": []
      },
      "aliases": [],
      "researchers": []
    },
    {
      "cve": "CVE-2026-5118",
      "title": "The Divi Form Builder plugin for WordPress is vulnerable to privilege escalation in…",
      "category": "Recall",
      "vendor": null,
      "exploited": false,
      "publiclyDisclosed": true,
      "cvss": 9.8,
      "cvssVector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "severity": "CRITICAL",
      "impact": null,
      "products": [],
      "productCount": 0,
      "faq": "The Divi Form Builder plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 5.1.2. This is due to the plugin accepting a user-controlled 'role' parameter from POST data during user registration without validating it against the form's configured default_user_role setting. This makes it possible for unauthenticated attackers to create administrator accounts by tampering with the role parameter during registration.",
      "pocConfidence": "confirmed",
      "pocCount": 2,
      "pocTopStars": 5,
      "pocRepos": [
        {
          "url": "https://github.com/puj790201-lab/CVE-2026-5118",
          "stars": 0,
          "desc": "CVE-2026-5118-exp_wordpress_Divi Form Builder",
          "createdAt": "2026-05-21",
          "hasCode": true
        },
        {
          "url": "https://github.com/Yucaerin/CVE-2026-5118",
          "stars": 0,
          "desc": "Divi Form Builder <= 5.1.2 — Unauthenticated Privilege Escalation via Role Injection",
          "createdAt": "2026-05-22",
          "hasCode": true
        },
        {
          "url": "https://github.com/zycoder0day/CVE-2026-5118",
          "stars": 5,
          "desc": "CVE-2026-5118 | Divi Form Builder <= 5.1.2 | Unauthenticated Privilege Escalation via Role Injection",
          "createdAt": "2026-05-21",
          "hasCode": false
        }
      ],
      "epss": 0.00487,
      "epssPercentile": 0.38849,
      "source": "poc",
      "mitreUrl": "https://nvd.nist.gov/vuln/detail/CVE-2026-5118",
      "research": [
        {
          "url": "https://www.tenable.com/cve/CVE-2026-5118",
          "type": "writeup",
          "source": "Tenable",
          "note": "Priv-esc via role param tampering, CVSS 9.8"
        },
        {
          "url": "https://patchstack.com/database/wordpress/plugin/forms-for-divi",
          "type": "writeup",
          "source": "Patchstack",
          "note": "Divi Form Builder vuln database entry"
        }
      ],
      "x": {
        "mentions": 2,
        "posts": [
          {
            "handle": "ThreatAft",
            "followers": 26,
            "likes": 0,
            "createdAt": "2026-05-23",
            "url": "https://x.com/ThreatAft/status/2058033971397832851",
            "origin": false,
            "github": []
          },
          {
            "handle": "OrizonCyber",
            "followers": 47,
            "likes": 0,
            "createdAt": "2026-05-21",
            "url": "https://x.com/OrizonCyber/status/2057453896667201919",
            "origin": false,
            "github": []
          }
        ],
        "aliases": []
      },
      "bsky": {
        "mentions": 6,
        "posts": [
          {
            "handle": "thehackerwire.bsky.social",
            "displayName": "TheHackerWire",
            "likes": 2,
            "reposts": 1,
            "replies": 0,
            "createdAt": "2026-05-22",
            "url": "https://bsky.app/profile/thehackerwire.bsky.social/post/3mmftmy6dkw2r",
            "origin": false,
            "authority": false,
            "github": []
          },
          {
            "handle": "offseq.bsky.social",
            "displayName": "OffSequence",
            "likes": 0,
            "reposts": 1,
            "replies": 0,
            "createdAt": "2026-05-21",
            "url": "https://bsky.app/profile/offseq.bsky.social/post/3mmetqmwmbv2l",
            "origin": false,
            "authority": false,
            "github": []
          },
          {
            "handle": "cve.skyfleet.blue",
            "displayName": "CVE Alerts ",
            "likes": 0,
            "reposts": 1,
            "replies": 0,
            "createdAt": "2026-05-21",
            "url": "https://bsky.app/profile/cve.skyfleet.blue/post/3mmestnmsnq2h",
            "origin": false,
            "authority": false,
            "github": []
          },
          {
            "handle": "atomicedge.bsky.social",
            "displayName": "Atomic Edge",
            "likes": 0,
            "reposts": 1,
            "replies": 0,
            "createdAt": "2026-05-21",
            "url": "https://bsky.app/profile/atomicedge.bsky.social/post/3mmejs5dpod2l",
            "origin": false,
            "authority": false,
            "github": []
          }
        ]
      },
      "telegram": {
        "mentions": 0,
        "posts": []
      },
      "aliases": [],
      "researchers": []
    },
    {
      "cve": "CVE-2026-20245",
      "title": "A vulnerability in the CLI of Cisco Catalyst SD-WAN Controller, formerly SD-WAN…",
      "category": "Recall",
      "vendor": null,
      "exploited": true,
      "publiclyDisclosed": true,
      "cvss": 7.8,
      "cvssVector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "severity": "HIGH",
      "impact": null,
      "products": [],
      "productCount": 0,
      "faq": "A vulnerability in the CLI of Cisco Catalyst SD-WAN Controller, formerly SD-WAN vSmart, Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, and Cisco Catalyst SD-WAN Validator, formerly SD-WAN vBond, could allow an authenticated, local attacker to execute arbitrary commands as root by supplying a crafted file to the affected system.\r\n\r\nThis vulnerability is due to insufficient validation of user-supplied input. An attacker could exploit this vulnerability by uploading a crafted file to the affected system. A successful exploit could allow the attacker to perform command injection attacks on an affected system and elevate their privileges as the root user.&nbsp;\r\nTo exploit this vulnerability, the attacker must have netadmin privileges on the affected system. This would require valid credentials or exploitation of  or . Cisco is not aware of successful exploitation by other methods. Cisco has observed limited cases where the exploitation of this bug resulted in a configuration change pushed to edge devices.\r\nCisco recommends that customers upgrade to the fixed software that is documented in the  that was published on May 14, 2026, and verify the configuration of the edge devices.",
      "pocConfidence": "confirmed",
      "pocCount": 2,
      "pocTopStars": 4,
      "pocRepos": [
        {
          "url": "https://github.com/0xBlackash/CVE-2026-20245",
          "stars": 4,
          "desc": "CVE-2026-20245",
          "createdAt": "2026-06-14",
          "hasCode": true
        },
        {
          "url": "https://github.com/fevar54/CVE-2026-20245---Cisco-SD-WAN-Privilege-Escalation-Exploit",
          "stars": 0,
          "desc": "**Este código es SOLO para fines educativos y pruebas de seguridad autorizadas.**",
          "createdAt": "2026-06-10",
          "hasCode": true
        },
        {
          "url": "https://github.com/HORKimhab/CVE-2026-20245",
          "stars": 0,
          "desc": "CVE-2026-20245 - Cisco SD-WAN - Draft",
          "createdAt": "2026-06-06",
          "hasCode": false
        }
      ],
      "epss": 0.25323,
      "epssPercentile": 0.97712,
      "source": "poc",
      "mitreUrl": "https://nvd.nist.gov/vuln/detail/CVE-2026-20245",
      "research": [
        {
          "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sdwan-privesc-4uxFrdzx",
          "type": "writeup",
          "source": "Cisco PSIRT",
          "note": "Official advisory; Bug ID CSCwu18563, CWE-116"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-20245",
          "type": "detection",
          "source": "NIST NVD",
          "note": "CVSS 7.8 High; canonical CVE record"
        },
        {
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "type": "detection",
          "source": "CISA KEV",
          "note": "Added KEV 2026-06-09; due date 2026-06-23"
        },
        {
          "url": "https://www.helpnetsecurity.com/2026/06/05/cisco-sd-wan-cve-2026-20245-0-day-exploited/",
          "type": "writeup",
          "source": "Help Net Security",
          "note": "Zero-day coverage; CLI file-upload cmd injection"
        },
        {
          "url": "https://thehackernews.com/2026/06/cisco-catalyst-sd-wan-manager-cve-2026.html",
          "type": "writeup",
          "source": "The Hacker News",
          "note": "Active exploitation; Mandiant discovery credited"
        },
        {
          "url": "https://socprime.com/blog/cve-2026-20245-analysis/",
          "type": "writeup",
          "source": "SOC Prime",
          "note": "Technical analysis + detection guidance"
        },
        {
          "url": "https://cyberpress.org/cisco-sd-wan-flaw-exploited/",
          "type": "writeup",
          "source": "CyberPress",
          "note": "Chain: CVE-2026-20127/20182 → CVE-2026-20245"
        },
        {
          "url": "https://www.rescana.com/post/active-exploitation-alert-cisco-catalyst-sd-wan-manager-cve-2026-20245-zero-day-under-attack-with-no-patch-available",
          "type": "detection",
          "source": "Rescana",
          "note": "IOCs, log paths, mitigation steps; no patch yet"
        }
      ],
      "aliases": [],
      "researchers": [],
      "x": {
        "mentions": 6,
        "aliases": [],
        "posts": [
          {
            "handle": "helpnetsecurity",
            "followers": 60131,
            "likes": 3,
            "createdAt": "2026-06-05",
            "url": "https://x.com/helpnetsecurity/status/2062818906922725652",
            "github": [],
            "origin": false
          },
          {
            "handle": "the_yellow_fall",
            "followers": 12202,
            "likes": 2,
            "createdAt": "2026-06-07",
            "url": "https://x.com/the_yellow_fall/status/2063462709279289545",
            "github": [],
            "origin": false
          },
          {
            "handle": "cloudsa",
            "followers": 18739,
            "likes": 1,
            "createdAt": "2026-06-05",
            "url": "https://x.com/cloudsa/status/2062905108015489314",
            "github": [],
            "origin": false
          },
          {
            "handle": "ElusivePrivacy",
            "followers": 185,
            "likes": 1,
            "createdAt": "2026-06-06",
            "url": "https://x.com/ElusivePrivacy/status/2063201618607104024",
            "github": [],
            "origin": false
          },
          {
            "handle": "Deepcyber_io",
            "followers": 7,
            "likes": 1,
            "createdAt": "2026-06-05",
            "url": "https://x.com/Deepcyber_io/status/2062935393893302606",
            "github": [],
            "origin": false
          },
          {
            "handle": "shah_sheikh",
            "followers": 2271,
            "likes": 0,
            "createdAt": "2026-06-05",
            "url": "https://x.com/shah_sheikh/status/2062818865663606953",
            "github": [],
            "origin": false
          }
        ]
      },
      "bsky": {
        "mentions": 25,
        "posts": [
          {
            "handle": "bleepingcomputer.com",
            "displayName": "BleepingComputer",
            "likes": 2,
            "reposts": 3,
            "replies": 0,
            "createdAt": "2026-06-05",
            "url": "https://bsky.app/profile/bleepingcomputer.com/post/3mnjivnnxth2s",
            "origin": false,
            "authority": true,
            "github": []
          },
          {
            "handle": "cybersecurity0001.bsky.social",
            "displayName": "CyberSecurity",
            "likes": 1,
            "reposts": 1,
            "replies": 0,
            "createdAt": "2026-06-06",
            "url": "https://bsky.app/profile/cybersecurity0001.bsky.social/post/3mnlytc4ypz2q",
            "origin": false,
            "authority": false,
            "github": []
          },
          {
            "handle": "hacker.at.thenote.app",
            "displayName": "Hacker & Security News",
            "likes": 1,
            "reposts": 0,
            "replies": 0,
            "createdAt": "2026-06-07",
            "url": "https://bsky.app/profile/hacker.at.thenote.app/post/3mnpaeu2xz22h",
            "origin": false,
            "authority": false,
            "github": []
          },
          {
            "handle": "cyberlensai.bsky.social",
            "displayName": "CyberLens AI",
            "likes": 1,
            "reposts": 0,
            "replies": 0,
            "createdAt": "2026-06-06",
            "url": "https://bsky.app/profile/cyberlensai.bsky.social/post/3mnmgo47ke42l",
            "origin": false,
            "authority": false,
            "github": []
          },
          {
            "handle": "o2cloud.bsky.social",
            "displayName": "CVE by o2Cloud",
            "likes": 0,
            "reposts": 0,
            "replies": 1,
            "createdAt": "2026-06-05",
            "url": "https://bsky.app/profile/o2cloud.bsky.social/post/3mnkaof3vso2f",
            "origin": false,
            "authority": false,
            "github": []
          },
          {
            "handle": "shortinfo.bsky.social",
            "displayName": "SHORT INFO",
            "likes": 0,
            "reposts": 0,
            "replies": 0,
            "createdAt": "2026-06-20",
            "url": "https://bsky.app/profile/shortinfo.bsky.social/post/3moornlotvc2j",
            "origin": false,
            "authority": false,
            "github": []
          }
        ]
      },
      "telegram": {
        "mentions": 9,
        "posts": [
          {
            "channel": "thehackernews",
            "channelTitle": "The Hacker News",
            "tier": "news",
            "date": "2026-06-06",
            "views": 8572,
            "forwards": 19,
            "url": "https://t.me/thehackernews/9165",
            "text": "🚨 New Cisco SD-WAN vulnerability under active exploitation. CVE-2026-20245 lets authenticated netadmin attackers run commands as root via crafted file uploads. No patches or mitigations are available. Check /var/log/scripts.log for IoCs. Read: https://thehackernews.com/2026/06/cisco-catalyst-sd-wan-manager-cve-2026.html",
            "github": [],
            "origin": false
          }
        ]
      }
    },
    {
      "cve": "CVE-2026-35273",
      "title": "Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft…",
      "category": "Recall",
      "vendor": null,
      "exploited": true,
      "publiclyDisclosed": true,
      "cvss": 9.8,
      "cvssVector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "severity": "CRITICAL",
      "impact": null,
      "products": [],
      "productCount": 0,
      "faq": "Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Updates Environment Management). Supported versions that are affected are 8.61 and 8.62. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools. Successful attacks of this vulnerability can result in takeover of PeopleSoft Enterprise PeopleTools. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
      "pocConfidence": "confirmed",
      "pocCount": 2,
      "pocTopStars": 4,
      "pocRepos": [
        {
          "url": "https://github.com/HORKimhab/CVE-2026-35273",
          "stars": 4,
          "desc": "CVE-2026-35273",
          "createdAt": "2026-06-12",
          "hasCode": true
        },
        {
          "url": "https://github.com/0xBlackash/CVE-2026-35273",
          "stars": 1,
          "desc": "CVE-2026-35273",
          "createdAt": "2026-06-12",
          "hasCode": true
        }
      ],
      "epss": 0.9233,
      "epssPercentile": 0.99812,
      "source": "poc",
      "mitreUrl": "https://nvd.nist.gov/vuln/detail/CVE-2026-35273",
      "research": [
        {
          "url": "https://www.oracle.com/security-alerts/alert-cve-2026-35273.html",
          "type": "detection",
          "source": "Oracle",
          "note": "Official out-of-band advisory; patch/mitigation guidance"
        },
        {
          "url": "https://cloud.google.com/blog/topics/threat-intelligence/shinyhunters-targets-education-sector-oracle-exploit",
          "type": "writeup",
          "source": "Mandiant / Google Cloud (GTIG)",
          "note": "Primary threat-intel writeup; TTPs, IOCs, UNC6240 campaign"
        },
        {
          "url": "https://www.rapid7.com/blog/post/etr-active-exploitation-of-oracle-peoplesoft-zero-day-cve-2026-35273/",
          "type": "writeup",
          "source": "Rapid7",
          "note": "ETR: SSRF-to-RCE chain, endpoints, NetNTLM hash capture"
        },
        {
          "url": "https://www.bleepingcomputer.com/news/security/oracle-mitigates-peoplesoft-zero-day-exploited-in-data-theft-attacks/",
          "type": "writeup",
          "source": "BleepingComputer",
          "note": "ShinyHunters campaign coverage; 100+ orgs breached"
        },
        {
          "url": "https://thehackernews.com/2026/06/shinyhunters-exploits-oracle-peoplesoft.html",
          "type": "writeup",
          "source": "The Hacker News",
          "note": "Attack chain: /PSEMHUB/hub + /PSIGW/ endpoints detail"
        },
        {
          "url": "https://socradar.io/blog/cve-2026-35273-oracle-peoplesoft-peopletools/",
          "type": "detection",
          "source": "SOCRadar",
          "note": "Exposure analysis; no public PoC confirmed in advisory"
        },
        {
          "url": "https://app.opencve.io/cve/CVE-2026-35273",
          "type": "detection",
          "source": "OpenCVE / NVD",
          "note": "CWE-306 classification; KEV listed; CVSS 9.8"
        },
        {
          "url": "https://www.helpnetsecurity.com/2026/06/11/oracle-peoplesoft-under-attack-cve-2026-35273/",
          "type": "writeup",
          "source": "Help Net Security",
          "note": "Carmakal (Mandiant CTO) warning; TrendAI ZDI credit noted"
        }
      ],
      "aliases": [],
      "researchers": [],
      "x": {
        "mentions": 12,
        "aliases": [],
        "posts": [
          {
            "handle": "TuringCyberObs",
            "followers": 51,
            "likes": 8,
            "createdAt": "2026-06-12",
            "url": "https://x.com/TuringCyberObs/status/2065379684402037151",
            "github": [
              {
                "url": "https://github.com/alan-turing-institute/cyber-threat-observatory/blob/main/reports/2026-06-11/TIER_1_CVE-2026-35273.md",
                "hasCode": false
              }
            ],
            "origin": false
          },
          {
            "handle": "Mandiant",
            "followers": 129003,
            "likes": 107,
            "createdAt": "2026-06-11",
            "url": "https://x.com/Mandiant/status/2065169704566624707",
            "github": [],
            "origin": false
          },
          {
            "handle": "AustinLarsen_",
            "followers": 2135,
            "likes": 33,
            "createdAt": "2026-06-11",
            "url": "https://x.com/AustinLarsen_/status/2065213752522240417",
            "github": [],
            "origin": false
          },
          {
            "handle": "Unit42_Intel",
            "followers": 69082,
            "likes": 30,
            "createdAt": "2026-06-12",
            "url": "https://x.com/Unit42_Intel/status/2065512743466078245",
            "github": [],
            "origin": false
          },
          {
            "handle": "blackorbird",
            "followers": 42221,
            "likes": 25,
            "createdAt": "2026-06-12",
            "url": "https://x.com/blackorbird/status/2065244044184432775",
            "github": [],
            "origin": false
          },
          {
            "handle": "the_yellow_fall",
            "followers": 12202,
            "likes": 10,
            "createdAt": "2026-06-11",
            "url": "https://x.com/the_yellow_fall/status/2064931093544108310",
            "github": [],
            "origin": false
          },
          {
            "handle": "YogSoth0",
            "followers": 671,
            "likes": 9,
            "createdAt": "2026-06-13",
            "url": "https://x.com/YogSoth0/status/2065927509623865393",
            "github": [],
            "origin": false
          },
          {
            "handle": "Cyber_O51NT",
            "followers": 22236,
            "likes": 5,
            "createdAt": "2026-06-12",
            "url": "https://x.com/Cyber_O51NT/status/2065237355519160379",
            "github": [],
            "origin": false
          }
        ]
      },
      "bsky": {
        "mentions": 25,
        "posts": [
          {
            "handle": "campuscodi.risky.biz",
            "displayName": "Catalin Cimpanu",
            "likes": 9,
            "reposts": 5,
            "replies": 0,
            "createdAt": "2026-06-11",
            "url": "https://bsky.app/profile/campuscodi.risky.biz/post/3mnzawhiwdc2l",
            "origin": false,
            "authority": true,
            "github": []
          },
          {
            "handle": "bleepingcomputer.com",
            "displayName": "BleepingComputer",
            "likes": 2,
            "reposts": 3,
            "replies": 0,
            "createdAt": "2026-06-11",
            "url": "https://bsky.app/profile/bleepingcomputer.com/post/3mnzy5mtduv2r",
            "origin": false,
            "authority": true,
            "github": []
          },
          {
            "handle": "thecybermind.co",
            "displayName": "mikeransier.bsky.social",
            "likes": 1,
            "reposts": 0,
            "replies": 0,
            "createdAt": "2026-06-13",
            "url": "https://bsky.app/profile/thecybermind.co/post/3mo72n6w2er2n",
            "origin": false,
            "authority": true,
            "github": []
          },
          {
            "handle": "secdb.bsky.social",
            "displayName": "ZEN SecDB",
            "likes": 0,
            "reposts": 0,
            "replies": 1,
            "createdAt": "2026-06-12",
            "url": "https://bsky.app/profile/secdb.bsky.social/post/3mo4gf5ibxu2b",
            "origin": false,
            "authority": true,
            "github": []
          },
          {
            "handle": "hermes71.bsky.social",
            "displayName": "Some Hermes agent",
            "likes": 1,
            "reposts": 0,
            "replies": 1,
            "createdAt": "2026-06-18",
            "url": "https://bsky.app/profile/hermes71.bsky.social/post/3mok45vo3jo2d",
            "origin": false,
            "authority": false,
            "github": []
          },
          {
            "handle": "ninjaowl.ai",
            "displayName": "Ninja Owl",
            "likes": 1,
            "reposts": 0,
            "replies": 1,
            "createdAt": "2026-06-12",
            "url": "https://bsky.app/profile/ninjaowl.ai/post/3mo45nt7vwd25",
            "origin": false,
            "authority": false,
            "github": []
          }
        ]
      },
      "telegram": {
        "mentions": 4,
        "posts": [
          {
            "channel": "VulnerabilityNews",
            "channelTitle": "Vulnerability News",
            "tier": "news",
            "date": "2026-06-12",
            "views": 137,
            "forwards": 1,
            "url": "https://t.me/VulnerabilityNews/42978",
            "text": "CISA Adds One Known Exploited Vulnerability to Catalog CISA has added one new vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation. CVE-2026-35273 Oracle PeopleSoft Enterprise PeopleTools Missing Authentication for Critical Function Vulnerability This type of vulnerability is a frequent attack vector for malicious cyber actors and poses signi",
            "github": [],
            "origin": false
          }
        ]
      }
    },
    {
      "cve": "CVE-2026-21858",
      "title": "n8n is an open source workflow automation platform. Versions starting with 1.65.0 and…",
      "category": "Recall",
      "vendor": null,
      "exploited": false,
      "publiclyDisclosed": true,
      "cvss": 10,
      "cvssVector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N",
      "severity": "CRITICAL",
      "impact": null,
      "products": [],
      "productCount": 0,
      "faq": "n8n is an open source workflow automation platform. Versions starting with 1.65.0 and below 1.121.0 enable an attacker to access files on the underlying server through execution of certain form-based workflows. A vulnerable workflow could grant access to an unauthenticated remote attacker, resulting in exposure of sensitive information stored on the system and may enable further compromise depending on deployment configuration and workflow usage. This issue is fixed in version 1.121.0.",
      "pocConfidence": "confirmed",
      "pocCount": 2,
      "pocTopStars": 3,
      "pocRepos": [
        {
          "url": "https://github.com/sh4den/CVE-2026-21858",
          "stars": 3,
          "desc": "Proof of Concept: CVE-2026-21858 is vulnerability on n8n where unauthenticated remote attackers can access sensitive files.",
          "createdAt": "2026-01-20",
          "hasCode": true
        },
        {
          "url": "https://github.com/EQSTLab/CVE-2026-21858",
          "stars": 1,
          "desc": "Ni8mare, n8n RCE",
          "createdAt": "2026-02-11",
          "hasCode": true
        }
      ],
      "epss": 0.71647,
      "epssPercentile": 0.99354,
      "source": "poc",
      "mitreUrl": "https://nvd.nist.gov/vuln/detail/CVE-2026-21858",
      "research": [
        {
          "url": "https://github.com/Chocapikk/CVE-2026-21858",
          "type": "poc",
          "source": "GitHub / Chocapikk (Valentin Lobstein)",
          "note": "Full AFR→JWT forge→RCE chain, Python exploit",
          "hasCode": true
        },
        {
          "url": "https://github.com/EQSTLab/CVE-2026-21858",
          "type": "poc",
          "source": "GitHub / EQSTLab (SK Shieldus)",
          "note": "Interactive n8n-shell PoC, extracts key+admin",
          "hasCode": true
        },
        {
          "url": "https://github.com/Fomovet/cve-2026-21858",
          "type": "poc",
          "source": "GitHub / Fomovet",
          "note": "Independent PoC, mirrors Chocapikk chain",
          "hasCode": true
        },
        {
          "url": "https://www.cyera.com/research/ni8mare-unauthenticated-remote-code-execution-in-n8n-cve-2026-21858",
          "type": "writeup",
          "source": "Cyera Research Labs / Dor Attias",
          "note": "Original discoverer writeup, names Ni8mare"
        },
        {
          "url": "https://horizon3.ai/attack-research/attack-blogs/the-ni8mare-test-n8n-rce-under-the-microscope-cve-2026-21858/",
          "type": "writeup",
          "source": "Horizon3.ai Attack Team",
          "note": "Blast-radius analysis; real-world exposure audit"
        },
        {
          "url": "https://www.rapid7.com/blog/post/etr-ni8mare-n8scape-flaws-multiple-critical-vulnerabilities-affecting-n8n/",
          "type": "writeup",
          "source": "Rapid7 / ETR",
          "note": "Multi-CVE chain analysis incl. Ni8mare+N8scape"
        },
        {
          "url": "https://github.com/projectdiscovery/nuclei-templates",
          "type": "module",
          "source": "ProjectDiscovery / rxerium",
          "note": "Nuclei template: CVE-2026-21858 RCE [vKEV]",
          "hasCode": true
        },
        {
          "url": "https://www.cyber.gc.ca/en/alerts-advisories/al26-001-vulnerabilities-affecting-n8n-cve-2026-21858-cve-2026-21877-cve-2025-68613",
          "type": "detection",
          "source": "Canadian Centre for Cyber Security (AL26-001)",
          "note": "Govt advisory; patch + detection guidance"
        }
      ],
      "aliases": [
        "Ni8mare"
      ],
      "researchers": [
        "Chocapikk",
        "rxerium"
      ],
      "x": {
        "mentions": 101,
        "aliases": [
          "Ni8mare"
        ],
        "posts": [
          {
            "handle": "MalwareObserver",
            "followers": 9,
            "likes": 0,
            "createdAt": "2026-07-15",
            "url": "https://x.com/MalwareObserver/status/2077250553655005389",
            "github": [
              {
                "url": "https://github.com/istio/istio/security/advisories/GHSA-v75c-crr9-733c",
                "hasCode": true
              },
              {
                "url": "https://github.com/istio/istio/security/advisories/GHSA-v75c-crr9-733c",
                "hasCode": true
              }
            ],
            "origin": false
          },
          {
            "handle": "MalwareBibleJP",
            "followers": 7624,
            "likes": 8,
            "createdAt": "2026-07-15",
            "url": "https://x.com/MalwareBibleJP/status/2077234644404273220",
            "github": [],
            "origin": false
          },
          {
            "handle": "PentesterLab",
            "followers": 205348,
            "likes": 6,
            "createdAt": "2026-07-15",
            "url": "https://x.com/PentesterLab/status/2077227113070166264",
            "github": [],
            "origin": false
          },
          {
            "handle": "steventseeley",
            "followers": 22728,
            "likes": 2,
            "createdAt": "2026-07-15",
            "url": "https://x.com/steventseeley/status/2077260190261624985",
            "github": [],
            "origin": false
          },
          {
            "handle": "Daily_CyberSec",
            "followers": 12486,
            "likes": 2,
            "createdAt": "2026-07-15",
            "url": "https://x.com/Daily_CyberSec/status/2077198003673214982",
            "github": [],
            "origin": false
          },
          {
            "handle": "__kokumoto",
            "followers": 7578,
            "likes": 2,
            "createdAt": "2026-07-15",
            "url": "https://x.com/__kokumoto/status/2077233338256073098",
            "github": [],
            "origin": false
          },
          {
            "handle": "blackorbird",
            "followers": 42692,
            "likes": 1,
            "createdAt": "2026-07-15",
            "url": "https://x.com/blackorbird/status/2077268390000132431",
            "github": [],
            "origin": false
          },
          {
            "handle": "pdnuclei_bot",
            "followers": 989,
            "likes": 1,
            "createdAt": "2026-07-15",
            "url": "https://x.com/pdnuclei_bot/status/2077256883522723949",
            "github": [],
            "origin": false
          }
        ]
      },
      "bsky": {
        "mentions": 30,
        "posts": [
          {
            "handle": "infosec.skyfleet.blue",
            "displayName": "InfoSec",
            "likes": 1,
            "reposts": 0,
            "replies": 0,
            "createdAt": "2026-01-10",
            "url": "https://bsky.app/profile/infosec.skyfleet.blue/post/3mc2f4hq4xb2g",
            "origin": true,
            "authority": true,
            "github": []
          },
          {
            "handle": "techmeme.com",
            "displayName": "Techmeme",
            "likes": 3,
            "reposts": 0,
            "replies": 0,
            "createdAt": "2026-01-08",
            "url": "https://bsky.app/profile/techmeme.com/post/3mbuuunwruh2g",
            "origin": true,
            "authority": false,
            "github": []
          },
          {
            "handle": "kaiakuroshi.bsky.social",
            "displayName": "Kaia Kuroshi",
            "likes": 1,
            "reposts": 0,
            "replies": 1,
            "createdAt": "2026-02-13",
            "url": "https://bsky.app/profile/kaiakuroshi.bsky.social/post/3merf6thdpx2j",
            "origin": true,
            "authority": false,
            "github": []
          },
          {
            "handle": "marcel-more.de",
            "displayName": "Marcel Moré",
            "likes": 2,
            "reposts": 0,
            "replies": 0,
            "createdAt": "2026-01-08",
            "url": "https://bsky.app/profile/marcel-more.de/post/3mbx2xwvmis2f",
            "origin": true,
            "authority": false,
            "github": []
          },
          {
            "handle": "percepticon.bsky.social",
            "displayName": "Matthias Schulze",
            "likes": 1,
            "reposts": 0,
            "replies": 0,
            "createdAt": "2026-01-12",
            "url": "https://bsky.app/profile/percepticon.bsky.social/post/3mca24n53uk24",
            "origin": true,
            "authority": false,
            "github": []
          },
          {
            "handle": "shadowserver.bsky.social",
            "displayName": "The Shadowserver Foundation",
            "likes": 3,
            "reposts": 0,
            "replies": 1,
            "createdAt": "2026-01-10",
            "url": "https://bsky.app/profile/shadowserver.bsky.social/post/3mc3tfgjqk22o",
            "origin": false,
            "authority": true,
            "github": []
          }
        ]
      },
      "telegram": {
        "mentions": 6,
        "posts": [
          {
            "channel": "news4hack",
            "channelTitle": "Pentester",
            "tier": "feed",
            "date": "2026-01-08",
            "views": 1369,
            "forwards": 12,
            "url": "https://t.me/news4hack/3081",
            "text": "CVE-2026-21858 + CVE-2025-68613: n8n Ni8mare - Full Chain Exploit (CVSS 10.0) Unauthenticated to Root RCE: - LFI via Content-Type confusion - Read /proc/self/environ to find HOME - Steal encryption key + database - Forge admin JWT token - Expression injection sandbox bypass - RCE as root Query: FOFA: app=\"n8n\" HUNTER : product.name=\"N8n\" ZoomEye: app=\"n8n\"",
            "github": [],
            "origin": false
          },
          {
            "channel": "thehackernews",
            "channelTitle": "The Hacker News",
            "tier": "news",
            "date": "2026-01-07",
            "views": 11967,
            "forwards": 76,
            "url": "https://t.me/thehackernews/8166",
            "text": "🚨 Another CVSS 10.0 n8n vulnerability disclosed. Researchers found another critical flaw (CVE-2026-21858) in n8n that lets remote attackers take full control with no authentication required. The bug abuses Content-Type handling in form webhooks to read local files, steal secrets, forge admin sessions, and achieve RCE. 🔗 Details here → https://thehackernews.com/2026/01/critical-n8n-vulnerability-cv",
            "github": [],
            "origin": false
          }
        ]
      }
    },
    {
      "cve": "CVE-2026-20131",
      "title": "A vulnerability in the web-based management interface of Cisco Secure Firewall…",
      "category": "Recall",
      "vendor": null,
      "exploited": true,
      "publiclyDisclosed": true,
      "cvss": 10,
      "cvssVector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H",
      "severity": "CRITICAL",
      "impact": null,
      "products": [],
      "productCount": 0,
      "faq": "A vulnerability in the web-based management interface of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated, remote attacker to execute arbitrary Java code as root&nbsp;on an affected device.\r\n\r\nThis vulnerability is due to insecure deserialization of a user-supplied Java byte stream. An attacker could exploit this vulnerability by sending a crafted serialized Java object to the web-based management interface of an affected device. A successful exploit could allow the attacker to execute arbitrary code on the device and elevate privileges to root.\r\nNote: If the FMC management interface does not have public internet access, the attack surface that is associated with this vulnerability is reduced.",
      "pocConfidence": "confirmed",
      "pocCount": 2,
      "pocTopStars": 3,
      "pocRepos": [
        {
          "url": "https://github.com/sak110/CVE-2026-20131",
          "stars": 3,
          "desc": "",
          "createdAt": "2026-03-11",
          "hasCode": true
        },
        {
          "url": "https://github.com/Hassan-Pouladi/Cisco-FMC-honeypot",
          "stars": 1,
          "desc": "Originally a Honeypot for CVE-2026-20131",
          "createdAt": "2026-04-07",
          "hasCode": true
        }
      ],
      "epss": 0.27551,
      "epssPercentile": 0.97865,
      "source": "poc",
      "mitreUrl": "https://nvd.nist.gov/vuln/detail/CVE-2026-20131",
      "bsky": {
        "mentions": 22,
        "posts": [
          {
            "handle": "taggart-tech.com",
            "displayName": "Taggart",
            "likes": 1,
            "reposts": 0,
            "replies": 2,
            "createdAt": "2026-03-04",
            "url": "https://bsky.app/profile/taggart-tech.com/post/3mgaut62z722w",
            "origin": false,
            "authority": false,
            "github": []
          },
          {
            "handle": "hakksaww.bsky.social",
            "displayName": "Patrick Duggan",
            "likes": 1,
            "reposts": 0,
            "replies": 1,
            "createdAt": "2026-03-23",
            "url": "https://bsky.app/profile/hakksaww.bsky.social/post/3mhq5vp2nfr2n",
            "origin": false,
            "authority": false,
            "github": []
          },
          {
            "handle": "getpokemon7.bsky.social",
            "displayName": "まりーん",
            "likes": 0,
            "reposts": 0,
            "replies": 1,
            "createdAt": "2026-03-24",
            "url": "https://bsky.app/profile/getpokemon7.bsky.social/post/3mhsow7bvzc2d",
            "origin": false,
            "authority": false,
            "github": []
          },
          {
            "handle": "firstpasslab.bsky.social",
            "displayName": "FirstPassLab",
            "likes": 1,
            "reposts": 0,
            "replies": 0,
            "createdAt": "2026-03-21",
            "url": "https://bsky.app/profile/firstpasslab.bsky.social/post/3mhkjpajhaf2q",
            "origin": false,
            "authority": false,
            "github": []
          },
          {
            "handle": "infosecbriefly.bsky.social",
            "displayName": "Information Security Briefly",
            "likes": 1,
            "reposts": 0,
            "replies": 0,
            "createdAt": "2026-03-18",
            "url": "https://bsky.app/profile/infosecbriefly.bsky.social/post/3mhe2loq7lu2f",
            "origin": false,
            "authority": false,
            "github": []
          },
          {
            "handle": "theitnerd.ca",
            "displayName": "The IT Nerd",
            "likes": 1,
            "reposts": 0,
            "replies": 0,
            "createdAt": "2026-03-04",
            "url": "https://bsky.app/profile/theitnerd.ca/post/3mgbao3oioi2u",
            "origin": false,
            "authority": false,
            "github": []
          }
        ]
      },
      "telegram": {
        "mentions": 4,
        "posts": [
          {
            "channel": "p3Nt3st3rsTAr",
            "channelTitle": "[CVE Pentester] exploits forum",
            "tier": "underground",
            "date": "2026-03-06",
            "views": 387,
            "forwards": 3,
            "url": "https://t.me/p3Nt3st3rsTAr/9",
            "text": "https://nvd.nist.gov/vuln/detail/CVE-2026-20131",
            "github": [],
            "origin": true
          },
          {
            "channel": "PentestingNews",
            "channelTitle": "Pentesting News",
            "tier": "news",
            "date": "2026-03-19",
            "views": 426,
            "forwards": 0,
            "url": "https://t.me/PentestingNews/73539",
            "text": "Interlock Ransomware Leveraged Cisco FMC Zero-Day 36 Days Before Patch https://thecyberexpress.com/interlock-fmc-cve-2026-20131/",
            "github": [],
            "origin": false
          }
        ]
      },
      "research": [
        {
          "url": "https://github.com/sak110/CVE-2026-20131",
          "type": "poc",
          "source": "GitHub / sak110",
          "note": "ysoserial-based RCE poc.py + detection probe",
          "hasCode": true
        },
        {
          "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-fmc-rce-NKhnULJh",
          "type": "writeup",
          "source": "Cisco PSIRT",
          "note": "Official advisory; insecure Java deser, CVSS 10"
        },
        {
          "url": "https://www.zscaler.com/blogs/security-research/critical-remote-code-execution-vulnerability-cisco-secure-firewall",
          "type": "writeup",
          "source": "Zscaler ThreatLabz",
          "note": "Attack chain analysis; ITW exploit payloads observed"
        },
        {
          "url": "https://horizon3.ai/attack-research/vulnerabilities/cve-2026-20131/",
          "type": "writeup",
          "source": "Horizon3.ai",
          "note": "Technical breakdown + NodeZero rapid-response test"
        },
        {
          "url": "https://threatprotect.qualys.com/2026/03/05/cisco-patches-secure-firewall-management-center-software-vulnerabilities-cve-2026-20079-cve-2026-20131/",
          "type": "writeup",
          "source": "Qualys ThreatPROTECT",
          "note": "Patch guidance; QVS 100, CISA KEV coverage"
        },
        {
          "url": "https://hivepro.com/threat-advisory/cve-2026-20131-interlock-ransomware-exploits-critical-cisco-secure-fmc-flaw/",
          "type": "writeup",
          "source": "HivePro",
          "note": "Interlock ransomware zero-day timeline & TTPs"
        },
        {
          "url": "https://cvefeed.io/vuln/detail/CVE-2026-20131",
          "type": "detection",
          "source": "cvefeed.io",
          "note": "9 public PoC repos indexed; EPSS/KEV tracking"
        },
        {
          "url": "https://www.penligent.ai/hackinglabs/cve-2026-20131-when-the-firewall-management-plane-becomes-the-breach-point/",
          "type": "writeup",
          "source": "Penligent / HackingLabs",
          "note": "Deep-dive: mgmt-plane blast radius, patch matrix"
        }
      ],
      "aliases": [],
      "researchers": [],
      "x": {
        "mentions": 0,
        "aliases": [],
        "posts": []
      }
    },
    {
      "cve": "CVE-2026-20182",
      "title": "May 2026: This security advisory provides the details and fix information for a…",
      "category": "Recall",
      "vendor": null,
      "exploited": true,
      "publiclyDisclosed": true,
      "cvss": 10,
      "cvssVector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H",
      "severity": "CRITICAL",
      "impact": null,
      "products": [],
      "productCount": 0,
      "faq": "May 2026: This security advisory provides the details and fix information for a vulnerability that was discovered and fixed after the  was disclosed in February 2026. This new advisory is for a new vulnerability in the control connection handshaking. The  section of this advisory includes Show Control Connections guidance to help with system checks.&nbsp;\r\n\r\nA vulnerability in the peering authentication in Cisco Catalyst SD-WAN Controller, formerly SD-WAN vSmart, Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, and Cisco Catalyst SD-WAN Validator, formerly SD-WAN vBond, could allow an unauthenticated, remote attacker to bypass authentication and obtain administrative privileges on an affected system.\r\nThis vulnerability exists because the peering authentication mechanism in an affected system is not working properly. An attacker could exploit this vulnerability by sending crafted requests to the affected system. A successful exploit could allow the attacker to log in to an affected Cisco Catalyst SD-WAN Controller as an internal, high-privileged, non-root user account. Using this account, the attacker could access NETCONF, which would then allow the attacker to manipulate network configuration for the SD-WAN fabric.",
      "pocConfidence": "confirmed",
      "pocCount": 2,
      "pocTopStars": 3,
      "pocRepos": [
        {
          "url": "https://github.com/portbuster1337/CVE-2026-20182",
          "stars": 3,
          "desc": "CVE-2026-20182 PoC - Cisco Catalyst SD-WAN Controller / Manager Authentication Bypass (CVSS 10.0)",
          "createdAt": "2026-05-22",
          "hasCode": true
        },
        {
          "url": "https://github.com/Nxploited/CVE-2026-20182",
          "stars": 1,
          "desc": "Cisco Catalyst SD-WAN Peering Authentication Bypass",
          "createdAt": "2026-05-26",
          "hasCode": true
        }
      ],
      "epss": 0.88496,
      "epssPercentile": 0.99757,
      "source": "poc",
      "mitreUrl": "https://nvd.nist.gov/vuln/detail/CVE-2026-20182",
      "research": [
        {
          "url": "https://blog.talosintelligence.com/sd-wan-ongoing-exploitation/",
          "type": "writeup",
          "source": "Cisco Talos",
          "note": "Active exploitation; cluster UAT-8616"
        },
        {
          "url": "https://www.rapid7.com/blog/post/ve-cve-2026-20182-critical-authentication-bypass-cisco-catalyst-sd-wan-controller-fixed/",
          "type": "module",
          "source": "Rapid7",
          "note": "Metasploit module + discovery writeup"
        },
        {
          "url": "https://github.com/portbuster1337/CVE-2026-20182",
          "type": "poc",
          "source": "GitHub portbuster1337",
          "note": "vdaemon DTLS auth-bypass PoC",
          "hasCode": true
        },
        {
          "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sdwan-rpa2-v69WY2SW",
          "type": "writeup",
          "source": "Cisco advisory",
          "note": "Vendor advisory"
        }
      ],
      "x": {
        "mentions": 100,
        "aliases": [],
        "posts": [
          {
            "handle": "bytecodevm",
            "followers": 1854,
            "likes": 2,
            "createdAt": "2026-05-30",
            "url": "https://x.com/bytecodevm/status/2060696972147773689",
            "github": [],
            "origin": true
          },
          {
            "handle": "0xor0ne",
            "followers": 90961,
            "likes": 65,
            "createdAt": "2026-05-28",
            "url": "https://x.com/0xor0ne/status/2059892640863146090",
            "github": [],
            "origin": false
          },
          {
            "handle": "nekono_naha",
            "followers": 6061,
            "likes": 31,
            "createdAt": "2026-05-18",
            "url": "https://x.com/nekono_naha/status/2056518208602222765",
            "github": [],
            "origin": false
          },
          {
            "handle": "co11ateral",
            "followers": 7441,
            "likes": 20,
            "createdAt": "2026-05-22",
            "url": "https://x.com/co11ateral/status/2057803468824322464",
            "github": [
              {
                "url": "https://github.com/rapid7/metasploit-framework/pull/21463",
                "hasCode": true
              }
            ],
            "origin": false
          },
          {
            "handle": "Dinosn",
            "followers": 156779,
            "likes": 16,
            "createdAt": "2026-05-19",
            "url": "https://x.com/Dinosn/status/2056578429743435853",
            "github": [],
            "origin": false
          },
          {
            "handle": "Nxploited",
            "followers": 107,
            "likes": 1,
            "createdAt": "2026-05-26",
            "url": "https://x.com/Nxploited/status/2059339983425548395",
            "github": [
              {
                "url": "https://github.com/Nxploited/CVE-2026-20182",
                "hasCode": true
              }
            ],
            "origin": false
          },
          {
            "handle": "portbuster1337",
            "followers": 32,
            "likes": 0,
            "createdAt": "2026-05-25",
            "url": "https://x.com/portbuster1337/status/2058956037189697979",
            "github": [
              {
                "url": "https://github.com/portbuster1337/CVE-2026-20182",
                "hasCode": true
              }
            ],
            "origin": false
          }
        ]
      },
      "researchers": [
        "Stephen Fewer",
        "Jonah Burgess"
      ],
      "bsky": {
        "mentions": 36,
        "posts": [
          {
            "handle": "catc0n.bsky.social",
            "displayName": "Caitlin Condon",
            "likes": 3,
            "reposts": 2,
            "replies": 0,
            "createdAt": "2023-06-12",
            "url": "https://bsky.app/profile/catc0n.bsky.social/post/3jxymi4zqzc2u",
            "origin": true,
            "authority": false,
            "github": []
          },
          {
            "handle": "thezdi.bsky.social",
            "displayName": "TrendAI Zero Day Initiative",
            "likes": 1,
            "reposts": 0,
            "replies": 0,
            "createdAt": "2026-05-15",
            "url": "https://bsky.app/profile/thezdi.bsky.social/post/3mluymei5lk2i",
            "origin": true,
            "authority": false,
            "github": []
          },
          {
            "handle": "blackhatnews.tokyo",
            "displayName": "blackhatnews.tokyo",
            "likes": 0,
            "reposts": 0,
            "replies": 0,
            "createdAt": "2026-05-29",
            "url": "https://bsky.app/profile/blackhatnews.tokyo/post/3mmxripomxa2m",
            "origin": true,
            "authority": false,
            "github": []
          },
          {
            "handle": "rcinghio.bsky.social",
            "displayName": "Giorgio di Grazia",
            "likes": 0,
            "reposts": 0,
            "replies": 0,
            "createdAt": "2026-05-16",
            "url": "https://bsky.app/profile/rcinghio.bsky.social/post/3mlxqubade22d",
            "origin": true,
            "authority": false,
            "github": []
          },
          {
            "handle": "jbhall56.bsky.social",
            "displayName": "PCI Guru",
            "likes": 0,
            "reposts": 0,
            "replies": 0,
            "createdAt": "2025-02-15",
            "url": "https://bsky.app/profile/jbhall56.bsky.social/post/3li7x575itk25",
            "origin": true,
            "authority": false,
            "github": []
          },
          {
            "handle": "infosec.skyfleet.blue",
            "displayName": "InfoSec",
            "likes": 1,
            "reposts": 0,
            "replies": 0,
            "createdAt": "2026-05-15",
            "url": "https://bsky.app/profile/infosec.skyfleet.blue/post/3mlucdqka5r25",
            "origin": false,
            "authority": true,
            "github": []
          }
        ]
      },
      "telegram": {
        "mentions": 5,
        "posts": [
          {
            "channel": "thehackernews",
            "channelTitle": "The Hacker News",
            "tier": "news",
            "date": "2026-05-14",
            "views": 11654,
            "forwards": 43,
            "url": "https://t.me/thehackernews/9007",
            "text": "🚨 Limited attacks are exploiting CVE-2026-20182, a CVSS 10.0 auth bypass in Cisco Catalyst SD-WAN Controller. Unauthenticated remote attackers can gain admin privileges and manipulate SD-WAN configurations. Affected: on-prem, cloud, government deployments. Full details and mitigation steps: https://thehackernews.com/2026/05/cisco-catalyst-sd-wan-controller-auth.html",
            "github": [],
            "origin": false
          }
        ]
      },
      "aliases": []
    },
    {
      "cve": "CVE-2026-26980",
      "title": "Ghost is a Node.js content management system. Versions 3.24.0 through 6.19.0 allow…",
      "category": "Recall",
      "vendor": null,
      "exploited": false,
      "publiclyDisclosed": true,
      "cvss": 9.4,
      "cvssVector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L",
      "severity": "CRITICAL",
      "impact": null,
      "products": [],
      "productCount": 0,
      "faq": "Ghost is a Node.js content management system. Versions 3.24.0 through 6.19.0 allow unauthenticated attackers to perform arbitrary reads from the database. This issue has been fixed in version 6.19.1.",
      "pocConfidence": "confirmed",
      "pocCount": 2,
      "pocTopStars": 3,
      "pocRepos": [
        {
          "url": "https://github.com/EQSTLab/CVE-2026-26980",
          "stars": 3,
          "desc": "Ghost Content API SQL Injection",
          "createdAt": "2026-05-27",
          "hasCode": true
        },
        {
          "url": "https://github.com/Kulik-Labs-Development/Ghost-CMS-Code-Injection-Audit-CVE-2026-26980",
          "stars": 0,
          "desc": "Outdated Ghost CMS websites that have fallen become compromised from CVE-2026-26980 can suffer from spam code injection to pages. Use this to mass clear and edi",
          "createdAt": "2026-05-20",
          "hasCode": true
        }
      ],
      "epss": 0.69996,
      "epssPercentile": 0.99303,
      "source": "poc",
      "mitreUrl": "https://nvd.nist.gov/vuln/detail/CVE-2026-26980",
      "research": [
        {
          "url": "https://thehackernews.com/2026/05/ghost-cms-cve-2026-26980-exploited-to.html",
          "type": "writeup",
          "source": "The Hacker News",
          "note": "Exploited to hijack 700+ sites, ClickFix"
        },
        {
          "url": "https://www.sonicwall.com/blog/ghost-cms-content-api-blind-sql-injection",
          "type": "writeup",
          "source": "SonicWall",
          "note": "Content API blind SQLi via ORDER BY"
        },
        {
          "url": "https://pentest-tools.com/vulnerabilities-exploits/ghost-cms-content-api-sql-injection_29129",
          "type": "writeup",
          "source": "Pentest-Tools",
          "note": "Content API SQLi exploit DB entry"
        },
        {
          "url": "https://www.securityweek.com/ghost-cms-vulnerability-exploited-to-hack-over-700-websites/",
          "type": "writeup",
          "source": "SecurityWeek",
          "note": "Exploited to hack 700+ websites"
        }
      ],
      "x": {
        "mentions": 12,
        "aliases": [],
        "posts": [
          {
            "handle": "akaclandestine",
            "followers": 59775,
            "likes": 42,
            "createdAt": "2026-05-26",
            "url": "https://x.com/akaclandestine/status/2059242236311662622",
            "github": [
              {
                "url": "https://github.com/vognik/CVE-2026-26980",
                "hasCode": true
              }
            ],
            "origin": false
          },
          {
            "handle": "CCBalert",
            "followers": 7199,
            "likes": 0,
            "createdAt": "2026-05-22",
            "url": "https://x.com/CCBalert/status/2057847395308786031",
            "github": [
              {
                "url": "https://github.com/TryGhost/Ghost/security/advisories/GHSA-w52v-v783-gw97",
                "hasCode": true
              }
            ],
            "origin": false
          },
          {
            "handle": "InfosecDotWatch",
            "followers": 35,
            "likes": 0,
            "createdAt": "2026-06-03",
            "url": "https://x.com/InfosecDotWatch/status/2062300864732151985",
            "github": [
              {
                "url": "https://github.com/TryGhost/Ghost/security/advisories/GHSA-w52v-v783-gw97",
                "hasCode": true
              }
            ],
            "origin": false
          },
          {
            "handle": "Anavem_",
            "followers": 159,
            "likes": 6,
            "createdAt": "2026-05-24",
            "url": "https://x.com/Anavem_/status/2058678235332784563",
            "github": [],
            "origin": false
          },
          {
            "handle": "AndreGironda",
            "followers": 3783,
            "likes": 1,
            "createdAt": "2026-05-09",
            "url": "https://x.com/AndreGironda/status/2053199725856481591",
            "github": [],
            "origin": false
          },
          {
            "handle": "blackstormsecbr",
            "followers": 2000,
            "likes": 0,
            "createdAt": "2026-05-29",
            "url": "https://x.com/blackstormsecbr/status/2060149712724852865",
            "github": [],
            "origin": false
          },
          {
            "handle": "f1tym1",
            "followers": 985,
            "likes": 0,
            "createdAt": "2026-05-26",
            "url": "https://x.com/f1tym1/status/2059266847325782263",
            "github": [],
            "origin": false
          },
          {
            "handle": "R4yt3d",
            "followers": 720,
            "likes": 0,
            "createdAt": "2026-05-26",
            "url": "https://x.com/R4yt3d/status/2059280835648344435",
            "github": [],
            "origin": false
          }
        ]
      },
      "bsky": {
        "mentions": 25,
        "posts": [
          {
            "handle": "bleepingcomputer.com",
            "displayName": "BleepingComputer",
            "likes": 3,
            "reposts": 1,
            "replies": 0,
            "createdAt": "2026-05-24",
            "url": "https://bsky.app/profile/bleepingcomputer.com/post/3mmm5lzxgji2r",
            "origin": false,
            "authority": true,
            "github": []
          },
          {
            "handle": "ebibibibibibi.bsky.social",
            "displayName": "胡田@Microsoft MVP(2014~)&MCT / Masahiko Ebisuda",
            "likes": 3,
            "reposts": 0,
            "replies": 0,
            "createdAt": "2026-05-24",
            "url": "https://bsky.app/profile/ebibibibibibi.bsky.social/post/3mmn4zexmo32d",
            "origin": false,
            "authority": false,
            "github": []
          },
          {
            "handle": "ninjaowl.ai",
            "displayName": "Ninja Owl",
            "likes": 1,
            "reposts": 1,
            "replies": 0,
            "createdAt": "2026-05-25",
            "url": "https://bsky.app/profile/ninjaowl.ai/post/3mmpaz3ltdc2w",
            "origin": false,
            "authority": false,
            "github": []
          },
          {
            "handle": "geeknewsbot.bsky.social",
            "displayName": "GeekNews 봇",
            "likes": 0,
            "reposts": 1,
            "replies": 0,
            "createdAt": "2026-05-27",
            "url": "https://bsky.app/profile/geeknewsbot.bsky.social/post/3mmsjbj3m5v26",
            "origin": false,
            "authority": false,
            "github": []
          },
          {
            "handle": "hendryadrian.bsky.social",
            "displayName": "Cybersecurity News Everyday",
            "likes": 1,
            "reposts": 0,
            "replies": 0,
            "createdAt": "2026-05-25",
            "url": "https://bsky.app/profile/hendryadrian.bsky.social/post/3mmot4246vl2o",
            "origin": false,
            "authority": false,
            "github": []
          },
          {
            "handle": "virusbtn.bsky.social",
            "displayName": "Virus Bulletin",
            "likes": 0,
            "reposts": 1,
            "replies": 0,
            "createdAt": "2026-05-22",
            "url": "https://bsky.app/profile/virusbtn.bsky.social/post/3mmglkgivsk2y",
            "origin": false,
            "authority": false,
            "github": []
          }
        ]
      },
      "telegram": {
        "mentions": 4,
        "posts": [
          {
            "channel": "thehackernews",
            "channelTitle": "The Hacker News",
            "tier": "news",
            "date": "2026-05-25",
            "views": 8563,
            "forwards": 27,
            "url": "https://t.me/thehackernews/9074",
            "text": "🚨 Hackers breached 700+ Ghost CMS websites to serve ClickFix malware attacks. Read 🠒 https://thehackernews.com/2026/05/ghost-cms-cve-2026-26980-exploited-to.html The attackers exploited critical flaw CVE-2026-26980 to steal admin API keys and inject malicious JavaScript into legitimate sites, including university, AI, blockchain, and fintech platforms. Visitors were shown fake CAPTCHA pages that t",
            "github": [],
            "origin": false
          }
        ]
      },
      "aliases": [],
      "researchers": []
    },
    {
      "cve": "CVE-2026-7482",
      "title": "Ollama before 0.17.1 contains a heap out-of-bounds read vulnerability in the GGUF…",
      "category": "Recall",
      "vendor": null,
      "exploited": false,
      "publiclyDisclosed": true,
      "cvss": 9.1,
      "cvssVector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H",
      "severity": "CRITICAL",
      "impact": null,
      "products": [],
      "productCount": 0,
      "faq": "Ollama before 0.17.1 contains a heap out-of-bounds read vulnerability in the GGUF model loader. The /api/create endpoint accepts an attacker-supplied GGUF file in which the declared tensor offset and size exceed the file's actual length; during quantization in fs/ggml/gguf.go and server/quantization.go (WriteTo()), the server reads past the allocated heap buffer. The leaked memory contents may include environment variables, API keys, system prompts, and concurrent users' conversation data, and can be exfiltrated by uploading the resulting model artifact through the /api/push endpoint to an attacker-controlled registry. The /api/create and /api/push endpoints have no authentication in the upstream distribution. Default deployments bind to 127.0.0.1, but the documented OLLAMA_HOST=0.0.0.0 configuration is widely used in practice (large public-internet exposure observed).",
      "pocConfidence": "confirmed",
      "pocCount": 2,
      "pocTopStars": 3,
      "pocRepos": [
        {
          "url": "https://github.com/0x0OZ/CVE-2026-7482-PoC",
          "stars": 3,
          "desc": "1day vuln research I guess",
          "createdAt": "2026-05-05",
          "hasCode": true
        },
        {
          "url": "https://github.com/szybnev/CVE-2026-7482",
          "stars": 0,
          "desc": "Ollama CVE-2026-7482 Heap OOB read reproduction and black-box impact notes",
          "createdAt": "2026-05-07",
          "hasCode": true
        }
      ],
      "epss": 0.01001,
      "epssPercentile": 0.59039,
      "source": "poc",
      "mitreUrl": "https://nvd.nist.gov/vuln/detail/CVE-2026-7482",
      "research": [
        {
          "url": "https://thehackernews.com/2026/05/ollama-out-of-bounds-read-vulnerability.html",
          "type": "writeup",
          "source": "The Hacker News",
          "note": "Bleeding Llama: unauth GGUF OOB read leaks server memory"
        },
        {
          "url": "https://integsec.com/blog/cve-2026-7482-ollama-heap-out-of-bounds-read-in-gguf-model-loader-what-it-means-for-your-business-and-how-to-respond",
          "type": "writeup",
          "source": "IntegSec",
          "note": "GGUF model-loader OOB read attack chain"
        }
      ],
      "x": {
        "mentions": 7,
        "aliases": [],
        "posts": [
          {
            "handle": "DanKornas",
            "followers": 92132,
            "likes": 10,
            "createdAt": "2026-05-10",
            "url": "https://x.com/DanKornas/status/2053559439937184185",
            "github": [],
            "origin": false
          },
          {
            "handle": "qualys",
            "followers": 34248,
            "likes": 4,
            "createdAt": "2026-05-12",
            "url": "https://x.com/qualys/status/2054062318883922227",
            "github": [],
            "origin": false
          },
          {
            "handle": "Trish_DIntel",
            "followers": 34,
            "likes": 1,
            "createdAt": "2026-05-12",
            "url": "https://x.com/Trish_DIntel/status/2054294440681054392",
            "github": [],
            "origin": false
          },
          {
            "handle": "FosoTweets",
            "followers": 333,
            "likes": 0,
            "createdAt": "2026-05-18",
            "url": "https://x.com/FosoTweets/status/2056473340450148544",
            "github": [],
            "origin": false
          },
          {
            "handle": "AISGateway",
            "followers": 39,
            "likes": 0,
            "createdAt": "2026-05-11",
            "url": "https://x.com/AISGateway/status/2053953824847798539",
            "github": [],
            "origin": false
          },
          {
            "handle": "ayudle_aisec",
            "followers": 0,
            "likes": 0,
            "createdAt": "2026-05-11",
            "url": "https://x.com/ayudle_aisec/status/2053811304880582781",
            "github": [],
            "origin": false
          }
        ]
      },
      "bsky": {
        "mentions": 21,
        "posts": [
          {
            "handle": "lalgorisme.bsky.social",
            "displayName": "L'algorisme",
            "likes": 2,
            "reposts": 3,
            "replies": 0,
            "createdAt": "2026-05-07",
            "url": "https://bsky.app/profile/lalgorisme.bsky.social/post/3mlatqjeszc2e",
            "origin": false,
            "authority": false,
            "github": []
          },
          {
            "handle": "opsmatters.com",
            "displayName": "OpsMatters",
            "likes": 1,
            "reposts": 0,
            "replies": 1,
            "createdAt": "2026-05-13",
            "url": "https://bsky.app/profile/opsmatters.com/post/3mlphjah4sn2x",
            "origin": false,
            "authority": false,
            "github": []
          },
          {
            "handle": "icsda.bsky.social",
            "displayName": "ICSDA",
            "likes": 1,
            "reposts": 0,
            "replies": 1,
            "createdAt": "2026-05-07",
            "url": "https://bsky.app/profile/icsda.bsky.social/post/3mlcdw4dx4s26",
            "origin": false,
            "authority": false,
            "github": []
          },
          {
            "handle": "hatena-bookmark.bsky.social",
            "displayName": "はてなブックマーク 人気エントリー",
            "likes": 1,
            "reposts": 0,
            "replies": 0,
            "createdAt": "2026-05-26",
            "url": "https://bsky.app/profile/hatena-bookmark.bsky.social/post/3mmrfjcfbou2z",
            "origin": false,
            "authority": false,
            "github": []
          },
          {
            "handle": "kubernetes.activitypub.awakari.com.ap.brid.gy",
            "displayName": "Kubernetes",
            "likes": 1,
            "reposts": 0,
            "replies": 0,
            "createdAt": "2026-05-12",
            "url": "https://bsky.app/profile/kubernetes.activitypub.awakari.com.ap.brid.gy/post/3mlnivxjq2zh2",
            "origin": false,
            "authority": false,
            "github": []
          },
          {
            "handle": "2rzikkbou3ntafnir2qmmse0gwz.activitypub.awakari.com.ap.brid.gy",
            "displayName": "2rZiKKbOU3nTafniR2qMMSE0gwZ",
            "likes": 1,
            "reposts": 0,
            "replies": 0,
            "createdAt": "2026-05-10",
            "url": "https://bsky.app/profile/2rzikkbou3ntafnir2qmmse0gwz.activitypub.awakari.com.ap.brid.gy/post/3mlizr4n4u3a2",
            "origin": false,
            "authority": false,
            "github": []
          }
        ]
      },
      "telegram": {
        "mentions": 2,
        "posts": [
          {
            "channel": "thehackernews",
            "channelTitle": "The Hacker News",
            "tier": "news",
            "date": "2026-05-10",
            "views": 13077,
            "forwards": 76,
            "url": "https://t.me/thehackernews/8968",
            "text": "🚨 CVE-2026-7482 in Ollama could let remote attackers leak process memory from more than 300,000 exposed servers using crafted GGUF files. Separate unpatched Windows flaws enable persistent code execution through Ollama’s update mechanism. Full details and mitigations: https://thehackernews.com/2026/05/ollama-out-of-bounds-read-vulnerability.html",
            "github": [],
            "origin": false
          }
        ]
      },
      "aliases": [],
      "researchers": []
    },
    {
      "cve": "CVE-2026-8206",
      "title": "The Kirki – Freeform Page Builder, Website Builder & Customizer plugin for WordPress…",
      "category": "Recall",
      "vendor": null,
      "exploited": false,
      "publiclyDisclosed": true,
      "cvss": 9.8,
      "cvssVector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "severity": "CRITICAL",
      "impact": null,
      "products": [],
      "productCount": 0,
      "faq": "The Kirki – Freeform Page Builder, Website Builder & Customizer plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions 6.0.0 to 6.0.6. This is due to the plugin accepting an arbitrary email address when a username is used in the password reset request. This makes it possible for unauthenticated attackers to send a password reset link for any user registered on the site to their own email address.",
      "pocConfidence": "confirmed",
      "pocCount": 2,
      "pocTopStars": 2,
      "pocRepos": [
        {
          "url": "https://github.com/Jenderal92/CVE-2026-8206",
          "stars": 2,
          "desc": "Mass exploitation tool for CVE-2026-8206 – Unauthenticated Privilege Escalation via 'handle_forgot_password' in Kirki WordPress plugin (≤6.0.6).",
          "createdAt": "2026-06-02",
          "hasCode": true
        },
        {
          "url": "https://github.com/izxci/CVE-2026-8206",
          "stars": 0,
          "desc": "CVE-2026-8206 Kirki Plugin Unauthenticated Account Takeover Exploit",
          "createdAt": "2026-06-17",
          "hasCode": true
        }
      ],
      "epss": 0.0126,
      "epssPercentile": 0.66378,
      "source": "poc",
      "mitreUrl": "https://nvd.nist.gov/vuln/detail/CVE-2026-8206",
      "research": [
        {
          "url": "https://github.com/Jenderal92/CVE-2026-8206",
          "type": "poc",
          "source": "GitHub / Jenderal92",
          "note": "Mass exploit tool; REST endpoint + user enum",
          "hasCode": true
        },
        {
          "url": "https://github.com/izxci/CVE-2026-8206",
          "type": "poc",
          "source": "GitHub / izxci",
          "note": "Unauthenticated account takeover exploit",
          "hasCode": true
        },
        {
          "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/3b5630bd-5bce-4226-959f-5e81ae69b799?source=cve",
          "type": "writeup",
          "source": "Wordfence / Defiant (CVE assigner)",
          "note": "Official advisory; handle_forgot_password() root cause"
        },
        {
          "url": "https://orca.security/resources/blog/kirki-wordpress-plugin-vulnerability-cve-2026-8206/",
          "type": "writeup",
          "source": "Orca Security",
          "note": "Technical deep-dive; REST API flow analysis"
        },
        {
          "url": "https://www.bleepingcomputer.com/news/security/critical-kirki-flaw-exploited-to-hijack-wordpress-admin-accounts/",
          "type": "writeup",
          "source": "BleepingComputer",
          "note": "Active exploitation; 222+ blocked attempts reported"
        },
        {
          "url": "https://www.rapid7.com/db/vulnerabilities/kirki-plugin-cve-2026-8206/",
          "type": "writeup",
          "source": "Rapid7 / AttackerKB",
          "note": "Rapid7 vuln DB entry with AttackerKB link"
        },
        {
          "url": "https://github.com/advisories/GHSA-gr32-6rr4-7px2",
          "type": "detection",
          "source": "GitHub Advisory Database",
          "note": "GHSA entry; patch changeset refs included",
          "hasCode": null
        },
        {
          "url": "https://plugins.trac.wordpress.org/changeset/3530843/kirki",
          "type": "detection",
          "source": "WordPress.org Trac",
          "note": "Official patch diff for 6.0.7 fix"
        }
      ],
      "aliases": [],
      "researchers": [
        "CHOIGYEONGMIN"
      ],
      "x": {
        "mentions": 61,
        "aliases": [],
        "posts": [
          {
            "handle": "MalwareObserver",
            "followers": 11,
            "likes": 0,
            "createdAt": "2026-07-20",
            "url": "https://x.com/MalwareObserver/status/2079280525265514912",
            "github": [
              {
                "url": "https://github.com/chamilo/chamilo-lms/security/advisories/GHSA-gcjp-f7jm-rrrg",
                "hasCode": true
              },
              {
                "url": "https://github.com/chamilo/chamilo-lms/security/advisories/GHSA-gcjp-f7jm-rrrg",
                "hasCode": true
              }
            ],
            "origin": false
          },
          {
            "handle": "MalwareBibleJP",
            "followers": 7683,
            "likes": 9,
            "createdAt": "2026-07-20",
            "url": "https://x.com/MalwareBibleJP/status/2079323720771088529",
            "github": [],
            "origin": false
          },
          {
            "handle": "LupovisDefence",
            "followers": 575,
            "likes": 5,
            "createdAt": "2026-07-20",
            "url": "https://x.com/LupovisDefence/status/2079290355443269739",
            "github": [],
            "origin": false
          },
          {
            "handle": "yousukezan",
            "followers": 14471,
            "likes": 4,
            "createdAt": "2026-07-20",
            "url": "https://x.com/yousukezan/status/2079344854665187623",
            "github": [],
            "origin": false
          },
          {
            "handle": "thingwhere",
            "followers": 8,
            "likes": 4,
            "createdAt": "2026-07-20",
            "url": "https://x.com/thingwhere/status/2079330106921607615",
            "github": [],
            "origin": false
          },
          {
            "handle": "Horizon3ai",
            "followers": 2894,
            "likes": 2,
            "createdAt": "2026-07-20",
            "url": "https://x.com/Horizon3ai/status/2079336182480257029",
            "github": [],
            "origin": false
          },
          {
            "handle": "__su888",
            "followers": 853,
            "likes": 2,
            "createdAt": "2026-07-20",
            "url": "https://x.com/__su888/status/2079325728181518491",
            "github": [],
            "origin": false
          },
          {
            "handle": "orcasec",
            "followers": 4829,
            "likes": 1,
            "createdAt": "2026-07-20",
            "url": "https://x.com/orcasec/status/2079287728030798288",
            "github": [],
            "origin": false
          }
        ]
      },
      "bsky": {
        "mentions": 15,
        "posts": [
          {
            "handle": "bleepingcomputer.com",
            "displayName": "BleepingComputer",
            "likes": 3,
            "reposts": 1,
            "replies": 0,
            "createdAt": "2026-06-02",
            "url": "https://bsky.app/profile/bleepingcomputer.com/post/3mndmizugrm2q",
            "origin": false,
            "authority": true,
            "github": []
          },
          {
            "handle": "thehackerwire.bsky.social",
            "displayName": "TheHackerWire",
            "likes": 1,
            "reposts": 1,
            "replies": 0,
            "createdAt": "2026-06-02",
            "url": "https://bsky.app/profile/thehackerwire.bsky.social/post/3mnbsrflkei27",
            "origin": false,
            "authority": false,
            "github": []
          },
          {
            "handle": "cwealthsentinel.bsky.social",
            "displayName": "Commonwealth Sentinel Cyber Security",
            "likes": 0,
            "reposts": 0,
            "replies": 1,
            "createdAt": "2026-06-05",
            "url": "https://bsky.app/profile/cwealthsentinel.bsky.social/post/3mnitm35b7o2x",
            "origin": false,
            "authority": false,
            "github": []
          },
          {
            "handle": "ahmandonk.bsky.social",
            "displayName": "Ahmandonk",
            "likes": 1,
            "reposts": 0,
            "replies": 0,
            "createdAt": "2026-06-03",
            "url": "https://bsky.app/profile/ahmandonk.bsky.social/post/3mne5kpxqtj2l",
            "origin": false,
            "authority": false,
            "github": []
          },
          {
            "handle": "atomicedge.bsky.social",
            "displayName": "Atomic Edge",
            "likes": 0,
            "reposts": 0,
            "replies": 0,
            "createdAt": "2026-06-12",
            "url": "https://bsky.app/profile/atomicedge.bsky.social/post/3mo4ny3b3ob2f",
            "origin": false,
            "authority": false,
            "github": []
          },
          {
            "handle": "securityrss.bsky.social",
            "displayName": "securityrss.ai",
            "likes": 0,
            "reposts": 0,
            "replies": 0,
            "createdAt": "2026-06-08",
            "url": "https://bsky.app/profile/securityrss.bsky.social/post/3mnrvn345pz2g",
            "origin": false,
            "authority": false,
            "github": []
          }
        ]
      }
    },
    {
      "cve": "CVE-2026-13001",
      "title": "The Podlove Podcast Publisher plugin for WordPress is vulnerable to arbitrary file…",
      "category": "Recall",
      "vendor": null,
      "exploited": false,
      "publiclyDisclosed": true,
      "cvss": 9.8,
      "cvssVector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "severity": "CRITICAL",
      "impact": null,
      "products": [],
      "productCount": 0,
      "faq": "The Podlove Podcast Publisher plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'podlove_handle_cache_files' function in all versions up to, and including, 4.5.1. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code execution possible.",
      "pocConfidence": "confirmed",
      "pocCount": 2,
      "pocTopStars": 2,
      "pocRepos": [
        {
          "url": "https://github.com/Raimu0x19/CVE-2026-13001",
          "stars": 2,
          "desc": "",
          "createdAt": "2026-07-15",
          "hasCode": true
        },
        {
          "url": "https://github.com/shinthink/CVE-2026-13001",
          "stars": 0,
          "desc": "Podlove Podcast Publisher Unauthenticated File Upload RCE via is_image() vs extract_file_extension() Mismatch | CVSS 9.8",
          "createdAt": "2026-07-15",
          "hasCode": true
        }
      ],
      "epss": 0.01079,
      "epssPercentile": 0.61396,
      "source": "poc",
      "mitreUrl": "https://nvd.nist.gov/vuln/detail/CVE-2026-13001",
      "research": [
        {
          "url": "https://github.com/Raimu0x19/CVE-2026-13001",
          "type": "poc",
          "source": "Raimu0x19 (GitHub)",
          "note": "Origin researcher PoC; GIF89a polyglot uploader",
          "hasCode": true
        },
        {
          "url": "https://github.com/shinthink/CVE-2026-13001",
          "type": "poc",
          "source": "shinthink (GitHub)",
          "note": "Python RCE tool; mass-scan & single-target modes",
          "hasCode": true
        },
        {
          "url": "https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/podlove-podcasting-plugin-for-wordpress",
          "type": "writeup",
          "source": "Wordfence / Talal Nasraddeen",
          "note": "Official advisory; discovered via Wordfence Jul 2026"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-13001",
          "type": "writeup",
          "source": "NVD / NIST",
          "note": "Official NVD entry; CVSS 9.8 Critical"
        },
        {
          "url": "https://www.ionix.io/threat-center/cve-2026-13001/",
          "type": "writeup",
          "source": "IONIX Threat Center",
          "note": "Deep-dive: root cause, attack chain, patch diff"
        },
        {
          "url": "https://wordpress.org/plugins/podlove-podcasting-plugin-for-wordpress/",
          "type": "detection",
          "source": "WordPress.org / Podlove",
          "note": "Vendor changelog; fix in v4.5.2"
        },
        {
          "url": "https://wpscan.com/plugin/podlove-podcasting-plugin-for-wordpress/",
          "type": "detection",
          "source": "WPScan",
          "note": "WPScan DB entry; unauth file upload < 4.5.2"
        },
        {
          "url": "https://github.com/topscoder/nuclei-wordfence-cve",
          "type": "module",
          "source": "topscoder / nuclei-wordfence-cve",
          "note": "Daily-updated Nuclei templates from Wordfence intel",
          "hasCode": true
        }
      ],
      "aliases": [],
      "researchers": [
        "Raimu0x19",
        "TalalNasraddeen"
      ],
      "x": {
        "mentions": 78,
        "aliases": [],
        "posts": [
          {
            "handle": "MalwareObserver",
            "followers": 11,
            "likes": 0,
            "createdAt": "2026-07-20",
            "url": "https://x.com/MalwareObserver/status/2079280525265514912",
            "github": [
              {
                "url": "https://github.com/chamilo/chamilo-lms/security/advisories/GHSA-gcjp-f7jm-rrrg",
                "hasCode": true
              },
              {
                "url": "https://github.com/chamilo/chamilo-lms/security/advisories/GHSA-gcjp-f7jm-rrrg",
                "hasCode": true
              }
            ],
            "origin": false
          },
          {
            "handle": "geovexintel",
            "followers": 999,
            "likes": 17,
            "createdAt": "2026-07-20",
            "url": "https://x.com/geovexintel/status/2079263366049063306",
            "github": [],
            "origin": false
          },
          {
            "handle": "0x0SojalSec",
            "followers": 47743,
            "likes": 12,
            "createdAt": "2026-07-20",
            "url": "https://x.com/0x0SojalSec/status/2079262255892603372",
            "github": [],
            "origin": false
          },
          {
            "handle": "NetSPI",
            "followers": 4074,
            "likes": 11,
            "createdAt": "2026-07-20",
            "url": "https://x.com/NetSPI/status/2079265470633381982",
            "github": [],
            "origin": false
          },
          {
            "handle": "MalwareBibleJP",
            "followers": 7678,
            "likes": 6,
            "createdAt": "2026-07-20",
            "url": "https://x.com/MalwareBibleJP/status/2079323720771088529",
            "github": [],
            "origin": false
          },
          {
            "handle": "ptdbugs",
            "followers": 2491,
            "likes": 5,
            "createdAt": "2026-07-20",
            "url": "https://x.com/ptdbugs/status/2079264509483515990",
            "github": [],
            "origin": false
          },
          {
            "handle": "LupovisDefence",
            "followers": 575,
            "likes": 5,
            "createdAt": "2026-07-20",
            "url": "https://x.com/LupovisDefence/status/2079290355443269739",
            "github": [],
            "origin": false
          },
          {
            "handle": "thingwhere",
            "followers": 8,
            "likes": 4,
            "createdAt": "2026-07-20",
            "url": "https://x.com/thingwhere/status/2079330106921607615",
            "github": [],
            "origin": false
          }
        ]
      },
      "bsky": {
        "mentions": 5,
        "posts": [
          {
            "handle": "rpunkt.bsky.social",
            "displayName": "Rpunkt",
            "likes": 2,
            "reposts": 1,
            "replies": 0,
            "createdAt": "2026-07-15",
            "url": "https://bsky.app/profile/rpunkt.bsky.social/post/3mqo3pzfdlc2l",
            "origin": false,
            "authority": false,
            "github": []
          },
          {
            "handle": "johnspurlock.com",
            "displayName": "John Spurlock",
            "likes": 1,
            "reposts": 0,
            "replies": 0,
            "createdAt": "2026-07-15",
            "url": "https://bsky.app/profile/johnspurlock.com/post/3mqowbwzmjs23",
            "origin": false,
            "authority": false,
            "github": []
          },
          {
            "handle": "dlamorski.social.tchncs.de.ap.brid.gy",
            "displayName": "David Lamorski",
            "likes": 0,
            "reposts": 0,
            "replies": 0,
            "createdAt": "2026-07-20",
            "url": "https://bsky.app/profile/dlamorski.social.tchncs.de.ap.brid.gy/post/3mr45bxkhf3q2",
            "origin": false,
            "authority": false,
            "github": []
          },
          {
            "handle": "pulse-wp.com",
            "displayName": "Pulse WP",
            "likes": 0,
            "reposts": 0,
            "replies": 0,
            "createdAt": "2026-07-15",
            "url": "https://bsky.app/profile/pulse-wp.com/post/3mqng36zng626",
            "origin": false,
            "authority": false,
            "github": []
          },
          {
            "handle": "stackflag.bsky.social",
            "displayName": "STACKFLAG",
            "likes": 0,
            "reposts": 0,
            "replies": 0,
            "createdAt": "2026-07-14",
            "url": "https://bsky.app/profile/stackflag.bsky.social/post/3mqnd5rawin2v",
            "origin": false,
            "authority": false,
            "github": []
          }
        ]
      }
    },
    {
      "cve": "CVE-2026-40047",
      "title": "Improper Neutralization of Argument Delimiters in a Command ('Argument Injection')…",
      "category": "Recall",
      "vendor": null,
      "exploited": false,
      "publiclyDisclosed": true,
      "cvss": 9.1,
      "cvssVector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N",
      "severity": "CRITICAL",
      "impact": null,
      "products": [],
      "productCount": 0,
      "faq": "Improper Neutralization of Argument Delimiters in a Command ('Argument Injection') vulnerability in Apache Camel Docling component.\n\nThe camel-docling component invokes the external `docling` command-line tool by assembling an argument list in DoclingProducer and executing it through java.lang.ProcessBuilder. Custom CLI arguments supplied through the `CamelDoclingCustomArguments` exchange header (a List<String>) were appended to that argument list with insufficient validation: the original implementation relied on a denylist of disallowed flags and only rejected path values that contained a literal `../` sequence. As a result, a Camel route that forwards externally-influenced data into the `CamelDoclingCustomArguments` header (or into the path-bearing headers used to build the invocation) could cause the producer to pass unrecognized or unintended `docling` CLI flags to the subprocess, and could supply path-like argument values that resolved outside the intended directory through traversal sequences not caught by the literal `../` check. Because Camel itself builds the `docling` invocation from these values, the component is responsible for constraining them, and the weak validation allowed CLI-argument injection and directory traversal in the arguments passed to the external tool. The invocation uses the list-based form of ProcessBuilder, so a shell does not interpret the argument values; OS command injection through shell metacharacters was not possible, and the metacharacter rejection added by the fix is defense-in-depth.\nThis issue affects Apache Camel: from 4.15.0 before 4.18.3.\n\nUsers are recommended to upgrade to a release that contains the CAMEL-23212 fix. On the mainline the fix is included from Apache Camel 4.19.0 (and later releases such as 4.20.0). For users on the 4.18.x LTS releases stream, upgrade to 4.18.3. The fix replaces the denylist with a strict allowlist of recognized `docling` CLI flags (rejecting any unrecognized flag, and rejecting producer-managed flags such as the output-directory flags), defensively rejects shell metacharacters in argument values, and normalizes path-like values with Path.normalize() before validating them so that traversal sequences which bypass a literal `../` check are detected. As defence in depth, route authors should avoid mapping untrusted message content into the `CamelDoclingCustomArguments` header and the path-bearing headers, and should strip Camel-internal headers from messages that arrive from untrusted producers.",
      "pocConfidence": "confirmed",
      "pocCount": 2,
      "pocTopStars": 2,
      "pocRepos": [
        {
          "url": "https://github.com/oscerd/CVE-2026-40047",
          "stars": 2,
          "desc": "Reproducer for CVE-2026-40047: Apache Camel camel-docling CLI argument injection / path traversal",
          "createdAt": "2026-07-08",
          "hasCode": true
        },
        {
          "url": "https://github.com/amnsecurity/CVE-2026-40047-Apache-Camel-Docling-Injection",
          "stars": 1,
          "desc": "CVE-2026-40047 - Apache Camel Docling CLI Argument Injection - PoC & Analysis | CVSS 9.1 CRITICAL | AMN SECURITY",
          "createdAt": "2026-07-13",
          "hasCode": true
        }
      ],
      "epss": 0.01569,
      "epssPercentile": 0.72645,
      "source": "poc",
      "mitreUrl": "https://nvd.nist.gov/vuln/detail/CVE-2026-40047",
      "research": [
        {
          "url": "https://www.openwall.com/lists/oss-security/2026/07/05/2",
          "type": "writeup",
          "source": "oss-security / Andrea Cosentino (Apache)",
          "note": "Official public disclosure on oss-security list"
        },
        {
          "url": "https://cve.threatint.eu/CVE/CVE-2026-40047",
          "type": "writeup",
          "source": "ThreatInt CVE database",
          "note": "Full technical description of arg injection flaw"
        },
        {
          "url": "https://www.cvedetails.com/cve/CVE-2026-40047/",
          "type": "writeup",
          "source": "CVEdetails",
          "note": "CVE detail page incl. affected versions & fix"
        },
        {
          "url": "https://camel.apache.org/security/",
          "type": "detection",
          "source": "Apache Camel / ASF",
          "note": "Official security advisory index; fix: 4.18.3/4.19.0"
        },
        {
          "url": "https://issues.apache.org/jira/browse/CAMEL-23212",
          "type": "detection",
          "source": "Apache JIRA",
          "note": "Patch tracker: allowlist replaces denylist fix"
        }
      ],
      "aliases": [],
      "researchers": [],
      "x": {
        "mentions": 0,
        "aliases": [],
        "posts": []
      },
      "bsky": {
        "mentions": 5,
        "posts": [
          {
            "handle": "infosec.skyfleet.blue",
            "displayName": "InfoSec",
            "likes": 0,
            "reposts": 0,
            "replies": 0,
            "createdAt": "2026-07-05",
            "url": "https://bsky.app/profile/infosec.skyfleet.blue/post/3mpwchziqm62z",
            "origin": false,
            "authority": true,
            "github": []
          },
          {
            "handle": "cyberhub.blog",
            "displayName": "CyberHub",
            "likes": 0,
            "reposts": 0,
            "replies": 0,
            "createdAt": "2026-07-09",
            "url": "https://bsky.app/profile/cyberhub.blog/post/3mq7a5qlicz2m",
            "origin": false,
            "authority": false,
            "github": []
          },
          {
            "handle": "kriptabiz.bsky.social",
            "displayName": "kripta.biz",
            "likes": 0,
            "reposts": 0,
            "replies": 0,
            "createdAt": "2026-07-09",
            "url": "https://bsky.app/profile/kriptabiz.bsky.social/post/3mq6pahgiuq2e",
            "origin": false,
            "authority": false,
            "github": []
          },
          {
            "handle": "qiancx.bsky.social",
            "displayName": "qian.cx",
            "likes": 0,
            "reposts": 0,
            "replies": 0,
            "createdAt": "2026-07-09",
            "url": "https://bsky.app/profile/qiancx.bsky.social/post/3mq6pahf75u2k",
            "origin": false,
            "authority": false,
            "github": []
          },
          {
            "handle": "stackflag.bsky.social",
            "displayName": "STACKFLAG",
            "likes": 0,
            "reposts": 0,
            "replies": 0,
            "createdAt": "2026-07-06",
            "url": "https://bsky.app/profile/stackflag.bsky.social/post/3mpyszg4wcn2y",
            "origin": false,
            "authority": false,
            "github": []
          }
        ]
      },
      "telegram": {
        "mentions": 0,
        "posts": []
      }
    },
    {
      "cve": "CVE-2026-20896",
      "title": "Gitea Docker image versions up to and including 1.26.2 use…",
      "category": "Recall",
      "vendor": null,
      "exploited": false,
      "publiclyDisclosed": true,
      "cvss": 9.8,
      "cvssVector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "severity": "CRITICAL",
      "impact": null,
      "products": [],
      "productCount": 0,
      "faq": "Gitea Docker image versions up to and including 1.26.2 use REVERSE_PROXY_TRUSTED_PROXIES=* by default, allowing any source IP to impersonate a user when reverse-proxy authentication headers such as X-WEBAUTH-USER are enabled.",
      "pocConfidence": "confirmed",
      "pocCount": 2,
      "pocTopStars": 2,
      "pocRepos": [
        {
          "url": "https://github.com/rz1027/CVE-2026-20896",
          "stars": 2,
          "desc": "Public PoC and detector for CVE-2026-20896 (\"Gitea Docker: One Header, Any User\")",
          "createdAt": "2026-07-05",
          "hasCode": true
        },
        {
          "url": "https://github.com/kaleth4/CVE-2026-20896",
          "stars": 1,
          "desc": "",
          "createdAt": "2026-07-02",
          "hasCode": true
        }
      ],
      "epss": 0.00783,
      "epssPercentile": 0.52029,
      "source": "poc",
      "mitreUrl": "https://nvd.nist.gov/vuln/detail/CVE-2026-20896",
      "research": [],
      "aliases": [],
      "researchers": [],
      "x": {
        "mentions": 15,
        "aliases": [],
        "posts": [
          {
            "handle": "DarkWebInformer",
            "followers": 222189,
            "likes": 34,
            "createdAt": "2026-07-07",
            "url": "https://x.com/DarkWebInformer/status/2074548580585517397",
            "github": [],
            "origin": false
          },
          {
            "handle": "ai_dev_official",
            "followers": 1511,
            "likes": 7,
            "createdAt": "2026-07-06",
            "url": "https://x.com/ai_dev_official/status/2074180805791007214",
            "github": [],
            "origin": false
          },
          {
            "handle": "shah_sheikh",
            "followers": 2284,
            "likes": 0,
            "createdAt": "2026-07-06",
            "url": "https://x.com/shah_sheikh/status/2074179904590258415",
            "github": [],
            "origin": false
          },
          {
            "handle": "mergenewsapp",
            "followers": 21,
            "likes": 0,
            "createdAt": "2026-07-07",
            "url": "https://x.com/mergenewsapp/status/2074526945799229685",
            "github": [],
            "origin": false
          }
        ]
      },
      "bsky": {
        "mentions": 24,
        "posts": [
          {
            "handle": "infosec.skyfleet.blue",
            "displayName": "InfoSec",
            "likes": 0,
            "reposts": 0,
            "replies": 0,
            "createdAt": "2026-07-06",
            "url": "https://bsky.app/profile/infosec.skyfleet.blue/post/3mpyowhw5i32x",
            "origin": false,
            "authority": true,
            "github": []
          },
          {
            "handle": "poxek.bsky.social",
            "displayName": "Sergey Zybnev (Poxek AI)",
            "likes": 0,
            "reposts": 0,
            "replies": 0,
            "createdAt": "2026-07-07",
            "url": "https://bsky.app/profile/poxek.bsky.social/post/3mq3imox2uw2x",
            "origin": false,
            "authority": false,
            "github": [
              {
                "url": "https://github.com/szybnev/cve-2026-20896-gitea-poc",
                "hasCode": true
              }
            ]
          },
          {
            "handle": "technology-news.bsky.social",
            "displayName": "Tech-News",
            "likes": 1,
            "reposts": 0,
            "replies": 0,
            "createdAt": "2026-07-08",
            "url": "https://bsky.app/profile/technology-news.bsky.social/post/3mq474jhpg62i",
            "origin": false,
            "authority": false,
            "github": []
          },
          {
            "handle": "cybersecurity0001.bsky.social",
            "displayName": "CyberSecurity",
            "likes": 1,
            "reposts": 0,
            "replies": 0,
            "createdAt": "2026-07-06",
            "url": "https://bsky.app/profile/cybersecurity0001.bsky.social/post/3mpynoifcex2v",
            "origin": false,
            "authority": false,
            "github": []
          },
          {
            "handle": "thehackerwire.bsky.social",
            "displayName": "TheHackerWire",
            "likes": 1,
            "reposts": 0,
            "replies": 0,
            "createdAt": "2026-07-05",
            "url": "https://bsky.app/profile/thehackerwire.bsky.social/post/3mpwhtesstw2e",
            "origin": false,
            "authority": false,
            "github": []
          },
          {
            "handle": "cybernewsroom.bsky.social",
            "displayName": "Cyber Newsroom",
            "likes": 0,
            "reposts": 0,
            "replies": 0,
            "createdAt": "2026-07-07",
            "url": "https://bsky.app/profile/cybernewsroom.bsky.social/post/3mq3qfqngqi2f",
            "origin": false,
            "authority": false,
            "github": []
          }
        ]
      },
      "telegram": {
        "mentions": 3,
        "posts": [
          {
            "channel": "thehackernews",
            "channelTitle": "The Hacker News",
            "tier": "news",
            "date": "2026-07-06",
            "views": 6450,
            "forwards": 17,
            "url": "https://t.me/thehackernews/9422",
            "text": "🚨 CVE-2026-20896 saw its first in-the-wild attempt 13 days after disclosure. The Gitea Docker flaw lets reachable containers trust spoofed X-WEBAUTH-USER headers when reverse proxy auth is enabled. See which setups are exposed and where the probe stopped: https://thehackernews.com/2026/07/threat-actors-probe-gitea-docker-flaw.html",
            "github": [],
            "origin": false
          }
        ]
      }
    },
    {
      "cve": "CVE-2026-35204",
      "title": "Helm is a package manager for Charts for Kubernetes. From 4.0.0 to 4.1.3, a specially…",
      "category": "Recall",
      "vendor": null,
      "exploited": false,
      "publiclyDisclosed": true,
      "cvss": 8.6,
      "cvssVector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H",
      "severity": "HIGH",
      "impact": null,
      "products": [],
      "productCount": 0,
      "faq": "Helm is a package manager for Charts for Kubernetes. From 4.0.0 to 4.1.3, a specially crafted Helm plugin, when installed or updated, will cause Helm to write the contents of the plugin to an arbitrary filesystem location. To prevent this, validate that the plugin.yaml of the Helm plugin does not include a version: field containing POSIX dot-dot path separators ie. \"/../\". This vulnerability is fixed in 4.1.4.",
      "pocConfidence": "confirmed",
      "pocCount": 2,
      "pocTopStars": 1,
      "pocRepos": [
        {
          "url": "https://github.com/h3ck13r/CVE-2026-35204",
          "stars": 1,
          "desc": "CVE-2026-35204 PoC",
          "createdAt": "2026-07-08",
          "hasCode": true
        },
        {
          "url": "https://github.com/amnsecurity/CVE-2026-35204-Helm-Plugin-Traversal",
          "stars": 1,
          "desc": "CVE-2026-35204 - Helm Plugin Path Traversal Arbitrary File Write - PoC & Analysis | CVSS 8.6 HIGH | AMN SECURITY",
          "createdAt": "2026-07-13",
          "hasCode": true
        }
      ],
      "epss": 0.00158,
      "epssPercentile": 0.05439,
      "source": "poc",
      "mitreUrl": "https://nvd.nist.gov/vuln/detail/CVE-2026-35204",
      "research": [
        {
          "url": "https://github.com/helm/helm/security/advisories/GHSA-vmx8-mqv2-9gmg",
          "type": "writeup",
          "source": "helm/helm (GitHub Security Advisory)",
          "note": "Official advisory: plugin.yaml version path traversal",
          "hasCode": true
        },
        {
          "url": "https://github.com/helm/helm/commit/36c8539e99bc42d7aef9b87d136254662d04f027",
          "type": "writeup",
          "source": "helm/helm (GitHub)",
          "note": "Upstream patch commit fixing arbitrary file write",
          "hasCode": true
        },
        {
          "url": "https://www.herodevs.com/vulnerability-directory/cve-2026-35204",
          "type": "writeup",
          "source": "HeroDevs",
          "note": "Technical analysis: plugin path traversal, impact chain"
        },
        {
          "url": "https://www.herodevs.com/vulnerability-directory/cve-2026-35205",
          "type": "writeup",
          "source": "HeroDevs",
          "note": "Chain: 35204 + 35205 = arbitrary write + sig bypass"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-35204",
          "type": "detection",
          "source": "NIST NVD",
          "note": "Official NVD entry, CVSS 8.4 HIGH (CWE-22)"
        },
        {
          "url": "https://access.redhat.com/security/cve/CVE-2026-35204",
          "type": "detection",
          "source": "Red Hat (RHSA-2026:26441)",
          "note": "Red Hat advisory; fixed in Helm CLI 4.1 packages"
        },
        {
          "url": "https://www.sentinelone.com/vulnerability-database/cve-2026-35206/",
          "type": "detection",
          "source": "SentinelOne Vulnerability DB",
          "note": "Lists CVE-2026-35204 as related; mitigation guidance"
        },
        {
          "url": "https://github.com/helm/helm/releases/tag/v4.1.4",
          "type": "detection",
          "source": "helm/helm (GitHub Releases)",
          "note": "Fixed release v4.1.4; patch for 35204 + 35205",
          "hasCode": true
        }
      ],
      "aliases": [],
      "researchers": [],
      "x": {
        "mentions": 0,
        "aliases": [],
        "posts": []
      },
      "bsky": {
        "mentions": 1,
        "posts": [
          {
            "handle": "cve.skyfleet.blue",
            "displayName": "CVE Alerts ",
            "likes": 0,
            "reposts": 0,
            "replies": 0,
            "createdAt": "2026-04-09",
            "url": "https://bsky.app/profile/cve.skyfleet.blue/post/3mj3ez4ayie2i",
            "origin": false,
            "authority": false,
            "github": []
          }
        ]
      }
    },
    {
      "cve": "CVE-2026-48172",
      "title": "LiteSpeed User-End cPanel Plugin before 2.4.5 allows privilege escalation (possibly…",
      "category": "Recall",
      "vendor": null,
      "exploited": true,
      "publiclyDisclosed": true,
      "cvss": 9.8,
      "cvssVector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "severity": "CRITICAL",
      "impact": null,
      "products": [],
      "productCount": 0,
      "faq": "LiteSpeed User-End cPanel Plugin before 2.4.5 allows privilege escalation (possibly to root), as exploited in the wild in May 2026. Detection is best done via a command line of grep -rE \"cpanel_jsonapi_func=redisAble\" /var/cpanel/logs /usr/local/cpanel/logs/ 2>/dev/null in Bash. If you get no output, you have not been hit with exploitation of the vulnerability. If there is output, we recommend you examine the IP addresses in the list, determine if they are valid IP addresses, and if not, block them. To determine damage done, examine the system logs for use by the detected IP addresses. The issue is related to mishandling of Redis enable/disable features. The recommended minimum version is 2.4.7.",
      "pocConfidence": "confirmed",
      "pocCount": 2,
      "pocTopStars": 1,
      "pocRepos": [
        {
          "url": "https://github.com/HORKimhab/CVE-2026-48172",
          "stars": 1,
          "desc": "CVE-2026-48172",
          "createdAt": "2026-05-23",
          "hasCode": true
        },
        {
          "url": "https://github.com/fevar54/CVE-2026-48172---LiteSpeed-cPanel-Plugin-Version-Auditor",
          "stars": 0,
          "desc": "This script safely checks the local version of the LiteSpeed cPanel plugin to determine if the system is running a version vulnerable to CVE-2026-48172. It does",
          "createdAt": "2026-05-28",
          "hasCode": true
        },
        {
          "url": "https://github.com/retmakarunia/CVE-2026-48172",
          "stars": 0,
          "desc": "cPanel user run arbitrary scripts as root",
          "createdAt": "2026-05-23",
          "hasCode": false
        }
      ],
      "epss": 0.18914,
      "epssPercentile": 0.96987,
      "source": "poc",
      "mitreUrl": "https://nvd.nist.gov/vuln/detail/CVE-2026-48172",
      "telegram": {
        "mentions": 3,
        "posts": [
          {
            "channel": "thehackernews",
            "channelTitle": "The Hacker News",
            "tier": "news",
            "date": "2026-05-23",
            "views": 9867,
            "forwards": 36,
            "url": "https://t.me/thehackernews/9067",
            "text": "🚨 Active exploit: LiteSpeed cPanel root flaw. https://thehackernews.com/2026/05/litespeed-cpanel-plugin-cve-2026-48172.html CVE-2026-48172 is a CVSS 10.0 vulnerability in LiteSpeed User-End cPanel Plugin that lets any cPanel user run arbitrary scripts as root. 🔸 Affected: v2.3–2.4.4 🔸 Not affected: WHM plugin 🔸 Fix: upgrade to WHM Plugin 5.3.1.0 with cPanel plugin v2.4.7+ 🔸 IOC: cpanel_jsonapi_fun",
            "github": [],
            "origin": false
          }
        ]
      },
      "research": [],
      "aliases": [],
      "researchers": [],
      "x": {
        "mentions": 0,
        "aliases": [],
        "posts": []
      },
      "bsky": {
        "mentions": 24,
        "posts": [
          {
            "handle": "infosec.skyfleet.blue",
            "displayName": "InfoSec",
            "likes": 1,
            "reposts": 0,
            "replies": 0,
            "createdAt": "2026-05-28",
            "url": "https://bsky.app/profile/infosec.skyfleet.blue/post/3mmva2n3yyv2z",
            "origin": false,
            "authority": true,
            "github": []
          },
          {
            "handle": "hapsis.bsky.social",
            "displayName": "Tomas Ström",
            "likes": 2,
            "reposts": 0,
            "replies": 0,
            "createdAt": "2026-05-31",
            "url": "https://bsky.app/profile/hapsis.bsky.social/post/3mn57tiswik2y",
            "origin": false,
            "authority": false,
            "github": []
          },
          {
            "handle": "getpokemon7.bsky.social",
            "displayName": "まりーん",
            "likes": 0,
            "reposts": 0,
            "replies": 1,
            "createdAt": "2026-06-22",
            "url": "https://bsky.app/profile/getpokemon7.bsky.social/post/3movob4qkzk2u",
            "origin": false,
            "authority": false,
            "github": []
          },
          {
            "handle": "ahmandonk.bsky.social",
            "displayName": "Ahmandonk",
            "likes": 0,
            "reposts": 1,
            "replies": 0,
            "createdAt": "2026-06-16",
            "url": "https://bsky.app/profile/ahmandonk.bsky.social/post/3mofqovg7e62n",
            "origin": false,
            "authority": false,
            "github": []
          },
          {
            "handle": "offseq.bsky.social",
            "displayName": "OffSequence",
            "likes": 1,
            "reposts": 0,
            "replies": 0,
            "createdAt": "2026-05-27",
            "url": "https://bsky.app/profile/offseq.bsky.social/post/3mmtcgzadie2d",
            "origin": false,
            "authority": false,
            "github": []
          },
          {
            "handle": "securitycyberuk.bsky.social",
            "displayName": "Security Cyber",
            "likes": 0,
            "reposts": 0,
            "replies": 0,
            "createdAt": "2026-06-22",
            "url": "https://bsky.app/profile/securitycyberuk.bsky.social/post/3motsyggsdb27",
            "origin": false,
            "authority": false,
            "github": []
          }
        ]
      }
    },
    {
      "cve": "CVE-2026-22557",
      "title": "A malicious actor with access to the network could exploit a Path Traversal…",
      "category": "Recall",
      "vendor": null,
      "exploited": false,
      "publiclyDisclosed": true,
      "cvss": 10,
      "cvssVector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H",
      "severity": "CRITICAL",
      "impact": null,
      "products": [],
      "productCount": 0,
      "faq": "A malicious actor with access to the network could exploit a Path Traversal vulnerability found in the UniFi Network Application to access files on the underlying system that could be manipulated to access an underlying account.",
      "pocConfidence": "confirmed",
      "pocCount": 2,
      "pocTopStars": 1,
      "pocRepos": [
        {
          "url": "https://github.com/0xBlackash/CVE-2026-22557",
          "stars": 1,
          "desc": "CVE-2026-22557",
          "createdAt": "2026-04-05",
          "hasCode": true
        },
        {
          "url": "https://github.com/ThePotatoOfDoom/CVE-2026-22557-PoC",
          "stars": 0,
          "desc": "PoC for UniFi Network Application Pre-Auth Path Traversal (CVE-2026-22557)",
          "createdAt": "2026-04-11",
          "hasCode": true
        }
      ],
      "epss": 0.15601,
      "epssPercentile": 0.96476,
      "source": "poc",
      "mitreUrl": "https://nvd.nist.gov/vuln/detail/CVE-2026-22557",
      "bsky": {
        "mentions": 22,
        "posts": [
          {
            "handle": "etguenni.bsky.social",
            "displayName": "etguenni (Günter Born) borncity.com",
            "likes": 1,
            "reposts": 2,
            "replies": 0,
            "createdAt": "2026-03-19",
            "url": "https://bsky.app/profile/etguenni.bsky.social/post/3mheq66qwwc2l",
            "origin": false,
            "authority": false,
            "github": []
          },
          {
            "handle": "intcyberdigest.bsky.social",
            "displayName": "International Cyber Digest",
            "likes": 0,
            "reposts": 2,
            "replies": 1,
            "createdAt": "2026-03-18",
            "url": "https://bsky.app/profile/intcyberdigest.bsky.social/post/3mhejkrgswx2r",
            "origin": false,
            "authority": false,
            "github": []
          },
          {
            "handle": "yinlang-nikki.bsky.social",
            "displayName": "Nikki Meir 🍉",
            "likes": 0,
            "reposts": 1,
            "replies": 1,
            "createdAt": "2026-03-23",
            "url": "https://bsky.app/profile/yinlang-nikki.bsky.social/post/3mhotawprxs2r",
            "origin": false,
            "authority": false,
            "github": []
          },
          {
            "handle": "opsmatters.com",
            "displayName": "OpsMatters",
            "likes": 1,
            "reposts": 0,
            "replies": 0,
            "createdAt": "2026-03-27",
            "url": "https://bsky.app/profile/opsmatters.com/post/3mhyukett5e2d",
            "origin": false,
            "authority": false,
            "github": []
          },
          {
            "handle": "theitnerd.ca",
            "displayName": "The IT Nerd",
            "likes": 1,
            "reposts": 0,
            "replies": 0,
            "createdAt": "2026-03-23",
            "url": "https://bsky.app/profile/theitnerd.ca/post/3mhqit6viks27",
            "origin": false,
            "authority": false,
            "github": []
          },
          {
            "handle": "firstpasslab.bsky.social",
            "displayName": "FirstPassLab",
            "likes": 1,
            "reposts": 0,
            "replies": 0,
            "createdAt": "2026-03-21",
            "url": "https://bsky.app/profile/firstpasslab.bsky.social/post/3mhkkj4smms2z",
            "origin": false,
            "authority": false,
            "github": []
          }
        ]
      },
      "telegram": {
        "mentions": 0,
        "posts": []
      },
      "research": [],
      "aliases": [],
      "researchers": [],
      "x": {
        "mentions": 0,
        "aliases": [],
        "posts": []
      }
    },
    {
      "cve": "CVE-2026-27886",
      "title": "Strapi is an open source headless content management system. Strapi versions starting…",
      "category": "Recall",
      "vendor": null,
      "exploited": false,
      "publiclyDisclosed": true,
      "cvss": 7.5,
      "cvssVector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
      "severity": "HIGH",
      "impact": null,
      "products": [],
      "productCount": 0,
      "faq": "Strapi is an open source headless content management system. Strapi versions starting in 4.0.0 and prior to 5.37.0 did not sufficiently sanitize query parameters when filtering content via relational fields. An unauthenticated attacker could use the `where` query parameter on any publicly-accessible content-type with an `updatedBy` (or other admin-relation) field to perform a boolean-oracle attack against private fields on the joined `admin_users` table, including the `resetPasswordToken` field. Extracting an admin reset token via this oracle made full administrative account takeover possible without authentication. When a filter such as `where[updatedBy][resetPasswordToken][$startsWith]=a` was applied to a public Content API endpoint, the underlying query generation performed a `LEFT JOIN` against the `admin_users` table and emitted a `WHERE` clause referencing the joined column. The query parameter sanitization layer did not block operator chains that traversed into relational target schemas the caller had no read permission on, allowing the response count to be used as a one-bit oracle on any admin-table field. The patch in version 5.37.0 introduces explicit query-parameter sanitization at the controller and service boundary via three new primitives: `strictParam`, `addQueryParams`, and `addBodyParams`. Operator chains that traverse into restricted relational targets are now rejected before reaching the database.",
      "pocConfidence": "confirmed",
      "pocCount": 2,
      "pocTopStars": 1,
      "pocRepos": [
        {
          "url": "https://github.com/thesw0rd/CVE-2026-27886-PoC-Account-Takeover",
          "stars": 1,
          "desc": "Account takeover full PoC for CVE-2026-27886 in Strapi CMS",
          "createdAt": "2026-06-08",
          "hasCode": true
        },
        {
          "url": "https://github.com/EvtDanya/CVE-2026-27886",
          "stars": 0,
          "desc": "Strapi CVE-2026-27886. Leaking sensitive data via relational filtering due to lack of query sanitization",
          "createdAt": "2026-06-01",
          "hasCode": true
        }
      ],
      "epss": 0.00612,
      "epssPercentile": 0.454,
      "source": "poc",
      "mitreUrl": "https://nvd.nist.gov/vuln/detail/CVE-2026-27886",
      "research": [
        {
          "url": "https://bishopfox.com/blog/cve-2026-27886-unauthenticated-boolean-oracle-exfiltration-of-administrator-secrets-in-strapi",
          "type": "writeup",
          "source": "Bishop Fox",
          "note": "Unauth boolean-oracle exfil of admin secrets"
        },
        {
          "url": "https://strapi.io/blog/security-disclosure-of-vulnerabilities-cve-2025-64526-cve-2026-22599-cve-2026-22706-cve-2026-22707-and-cve-2026-27886",
          "type": "writeup",
          "source": "Strapi",
          "note": "Official security disclosure"
        },
        {
          "url": "https://github.com/advisories/GHSA-rjg2-95x7-8qmx",
          "type": "writeup",
          "source": "GitHub Advisory",
          "note": "Data leak via relational filtering",
          "hasCode": null
        }
      ],
      "x": {
        "mentions": 1,
        "aliases": [],
        "posts": [
          {
            "handle": "NateRobb",
            "followers": 198,
            "likes": 1,
            "createdAt": "2026-05-27",
            "url": "https://x.com/NateRobb/status/2059771504758530470",
            "github": [
              {
                "url": "https://github.com/BishopFox/CVE-2026-27886-check",
                "hasCode": false
              }
            ],
            "origin": false
          }
        ]
      },
      "researchers": [
        "Bishop Fox"
      ],
      "aliases": [],
      "bsky": {
        "mentions": 2,
        "posts": [
          {
            "handle": "packetstorm.bsky.social",
            "displayName": "Packet Storm News",
            "likes": 0,
            "reposts": 0,
            "replies": 0,
            "createdAt": "2026-05-25",
            "url": "https://bsky.app/profile/packetstorm.bsky.social/post/3mmp76mk5ju2w",
            "origin": false,
            "authority": false,
            "github": []
          },
          {
            "handle": "thehackerwire.bsky.social",
            "displayName": "TheHackerWire",
            "likes": 0,
            "reposts": 0,
            "replies": 0,
            "createdAt": "2026-05-17",
            "url": "https://bsky.app/profile/thehackerwire.bsky.social/post/3mm2g4qor3e2n",
            "origin": false,
            "authority": false,
            "github": []
          }
        ]
      }
    },
    {
      "cve": "CVE-2026-4885",
      "title": "The Piotnet Addons for Elementor Pro plugin for WordPress is vulnerable to arbitrary…",
      "category": "Recall",
      "vendor": null,
      "exploited": false,
      "publiclyDisclosed": true,
      "cvss": 9.8,
      "cvssVector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "severity": "CRITICAL",
      "impact": null,
      "products": [],
      "productCount": 0,
      "faq": "The Piotnet Addons for Elementor Pro plugin for WordPress is vulnerable to arbitrary file upload due to missing file type validation in the 'pafe_ajax_form_builder' function in all versions up to, and including, 7.1.70. The plugin uses an incomplete extension blacklist that only blocks php, phpt, php5, php7, and exe extensions, while allowing dangerous extensions such as .phar or .phtml to be uploaded. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code execution possible. Note: The exploit can only be exploited if a file field is added to the form.",
      "pocConfidence": "confirmed",
      "pocCount": 2,
      "pocTopStars": 1,
      "pocRepos": [
        {
          "url": "https://github.com/xShadow-Here/CVE-2026-4885",
          "stars": 1,
          "desc": "Piotnet Addons for Elementor Pro <= 7.1.70 - Unauthenticated Arbitrary File Upload → RCE",
          "createdAt": "2026-05-21",
          "hasCode": true
        },
        {
          "url": "https://github.com/Jenderal92/CVE-2026-4885",
          "stars": 0,
          "desc": "Piotnet Addons for Elementor Pro <= 7.1.70 - Unauthenticated Arbitrary File Upload via Form File Upload",
          "createdAt": "2026-05-23",
          "hasCode": true
        }
      ],
      "epss": 0.00953,
      "epssPercentile": 0.57487,
      "source": "poc",
      "mitreUrl": "https://nvd.nist.gov/vuln/detail/CVE-2026-4885",
      "research": [
        {
          "url": "https://cve.halosecurity.com/cve-advisory/cve-2026-4885-piotnet-addons-for-elementor-pro-file-upload-vulnerability",
          "type": "writeup",
          "source": "Halo Security",
          "note": "unauth arbitrary file upload (pafe_ajax_form_builder) -> RCE/webshell"
        },
        {
          "url": "https://managed-wp.com/blogs/securing-piotnet-addons-against-arbitrary-uploads-cve20264885-2026-05-21",
          "type": "writeup",
          "source": "Managed-WP",
          "note": "missing file-type validation, unauth upload"
        }
      ],
      "x": {
        "mentions": 3,
        "posts": [
          {
            "handle": "ADKCyber",
            "followers": 83,
            "likes": 0,
            "createdAt": "2026-05-19",
            "url": "https://x.com/ADKCyber/status/2056843490399506466",
            "origin": false,
            "github": []
          },
          {
            "handle": "CVEnew",
            "followers": 57565,
            "likes": 0,
            "createdAt": "2026-05-19",
            "url": "https://x.com/CVEnew/status/2056670076162761166",
            "origin": false,
            "github": []
          },
          {
            "handle": "OrizonCyber",
            "followers": 47,
            "likes": 0,
            "createdAt": "2026-05-19",
            "url": "https://x.com/OrizonCyber/status/2056653640165667136",
            "origin": false,
            "github": []
          }
        ],
        "aliases": []
      },
      "bsky": {
        "mentions": 4,
        "posts": [
          {
            "handle": "atomicedge.bsky.social",
            "displayName": "Atomic Edge",
            "likes": 1,
            "reposts": 0,
            "replies": 0,
            "createdAt": "2026-05-19",
            "url": "https://bsky.app/profile/atomicedge.bsky.social/post/3mmakf6zijh2a",
            "origin": false,
            "authority": false,
            "github": []
          },
          {
            "handle": "keiwork35.bsky.social",
            "displayName": "ケイ | 副業Webライター📖",
            "likes": 0,
            "reposts": 0,
            "replies": 0,
            "createdAt": "2026-05-31",
            "url": "https://bsky.app/profile/keiwork35.bsky.social/post/3mn5g2skrze2d",
            "origin": false,
            "authority": false,
            "github": []
          },
          {
            "handle": "cve.skyfleet.blue",
            "displayName": "CVE Alerts ",
            "likes": 0,
            "reposts": 0,
            "replies": 0,
            "createdAt": "2026-05-19",
            "url": "https://bsky.app/profile/cve.skyfleet.blue/post/3mm6yawlzhu2i",
            "origin": false,
            "authority": false,
            "github": []
          },
          {
            "handle": "offseq.bsky.social",
            "displayName": "OffSequence",
            "likes": 0,
            "reposts": 0,
            "replies": 0,
            "createdAt": "2026-05-19",
            "url": "https://bsky.app/profile/offseq.bsky.social/post/3mm6zote6yl2c",
            "origin": false,
            "authority": false,
            "github": []
          }
        ]
      },
      "telegram": {
        "mentions": 0,
        "posts": []
      },
      "aliases": [],
      "researchers": []
    },
    {
      "cve": "CVE-2026-5718",
      "title": "The Drag and Drop Multiple File Upload for Contact Form 7 plugin for WordPress is…",
      "category": "Recall",
      "vendor": null,
      "exploited": false,
      "publiclyDisclosed": true,
      "cvss": 8.1,
      "cvssVector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "severity": "HIGH",
      "impact": null,
      "products": [],
      "productCount": 0,
      "faq": "The Drag and Drop Multiple File Upload for Contact Form 7 plugin for WordPress is vulnerable to arbitrary file upload in versions up to, and including, 1.3.9.7. This is due to insufficient file type validation that occurs when custom blacklist types are configured, which replaces the default dangerous extension denylist instead of merging with it, and the wpcf7_antiscript_file_name() sanitization function being bypassed for filenames containing non-ASCII characters. This makes it possible for unauthenticated attackers to upload arbitrary files, such as PHP files, to the server, which can be leveraged to achieve remote code execution. The vulnerability was originally reported by Leonid Semenenko (lsemenenko) and partially patched in version 1.3.9.7. A bypass for the patch was separately discovered and reported by Nguyen Hung (Mitchell).",
      "pocConfidence": "confirmed",
      "pocCount": 2,
      "pocTopStars": 1,
      "pocRepos": [
        {
          "url": "https://github.com/kyukazamiqq/cve-2026-5718",
          "stars": 1,
          "desc": "",
          "createdAt": "2026-05-08",
          "hasCode": true
        },
        {
          "url": "https://github.com/xxconi/CVE-2026-5718",
          "stars": 0,
          "desc": "CVE-2026-5718: Unauthenticated File Upload To RCE in DnD Upload CF7 Plugin",
          "createdAt": "2026-05-26",
          "hasCode": true
        },
        {
          "url": "https://github.com/xxconi/CVE-2026-5718-PR-V-EXPLO-T",
          "stars": 0,
          "desc": "WORDPRESS",
          "createdAt": "2026-06-10",
          "hasCode": false
        }
      ],
      "epss": 0.04175,
      "epssPercentile": 0.8981,
      "source": "poc",
      "mitreUrl": "https://nvd.nist.gov/vuln/detail/CVE-2026-5718",
      "research": [
        {
          "url": "https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/drag-and-drop-multiple-file-upload-contact-form-7",
          "type": "writeup",
          "source": "Wordfence",
          "note": "Arbitrary file upload, non-ASCII filename bypass"
        },
        {
          "url": "https://www.tenable.com/cve/CVE-2026-5718",
          "type": "writeup",
          "source": "Tenable",
          "note": "CVE record, CVSS 8.1 file upload"
        },
        {
          "url": "https://wpscan.com/plugin/drag-and-drop-multiple-file-upload-contact-form-7/",
          "type": "writeup",
          "source": "WPScan",
          "note": "Plugin vuln listing"
        }
      ],
      "x": {
        "mentions": 4,
        "posts": [
          {
            "handle": "ctiwatchcloud",
            "followers": 5581,
            "likes": 0,
            "createdAt": "2026-04-23",
            "url": "https://x.com/ctiwatchcloud/status/2047163560745222601",
            "origin": false,
            "github": []
          },
          {
            "handle": "CVEnew",
            "followers": 57565,
            "likes": 0,
            "createdAt": "2026-04-19",
            "url": "https://x.com/CVEnew/status/2045889722463994137",
            "origin": false,
            "github": []
          },
          {
            "handle": "VulmonFeeds",
            "followers": 4043,
            "likes": 0,
            "createdAt": "2026-04-17",
            "url": "https://x.com/VulmonFeeds/status/2045227307313275046",
            "origin": false,
            "github": []
          },
          {
            "handle": "KaitanSecurity",
            "followers": 86,
            "likes": 0,
            "createdAt": "2026-04-17",
            "url": "https://x.com/KaitanSecurity/status/2045208176874717634",
            "origin": false,
            "github": []
          }
        ],
        "aliases": []
      },
      "aliases": [],
      "researchers": [],
      "bsky": {
        "mentions": 4,
        "posts": [
          {
            "handle": "beikokucyber.bsky.social",
            "displayName": "Beikoku Cybersecurity",
            "likes": 0,
            "reposts": 0,
            "replies": 0,
            "createdAt": "2026-04-23",
            "url": "https://bsky.app/profile/beikokucyber.bsky.social/post/3mk6vwwbewr2c",
            "origin": false,
            "authority": false,
            "github": []
          },
          {
            "handle": "thehackerwire.bsky.social",
            "displayName": "TheHackerWire",
            "likes": 0,
            "reposts": 0,
            "replies": 0,
            "createdAt": "2026-04-17",
            "url": "https://bsky.app/profile/thehackerwire.bsky.social/post/3mjpk3gndxu2o",
            "origin": false,
            "authority": false,
            "github": []
          },
          {
            "handle": "cve.skyfleet.blue",
            "displayName": "CVE Alerts ",
            "likes": 0,
            "reposts": 0,
            "replies": 0,
            "createdAt": "2026-04-17",
            "url": "https://bsky.app/profile/cve.skyfleet.blue/post/3mjpmmmc3zg2d",
            "origin": false,
            "authority": false,
            "github": []
          }
        ]
      }
    },
    {
      "cve": "CVE-2026-42271",
      "title": "LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format.…",
      "category": "Recall",
      "vendor": null,
      "exploited": true,
      "publiclyDisclosed": true,
      "cvss": 8.8,
      "cvssVector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "severity": "HIGH",
      "impact": null,
      "products": [],
      "productCount": 0,
      "faq": "LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. From version 1.74.2 to before version 1.83.7, two endpoints used to preview an MCP server before saving it — POST /mcp-rest/test/connection and POST /mcp-rest/test/tools/list — accepted a full server configuration in the request body, including the command, args, and env fields used by the stdio transport. When called with a stdio configuration, the endpoints attempted to connect, which spawned the supplied command as a subprocess on the proxy host with the privileges of the proxy process. The endpoints were gated only by a valid proxy API key, with no role check. Any authenticated user — including holders of low-privilege internal-user keys — could therefore run arbitrary commands on the host. This issue has been patched in version 1.83.7.",
      "pocConfidence": "confirmed",
      "pocCount": 2,
      "pocTopStars": 0,
      "pocRepos": [
        {
          "url": "https://github.com/learner202649/CVE-2026-42271-PoC",
          "stars": 0,
          "desc": "The code for personally reproducing the corresponding vulnerability",
          "createdAt": "2026-05-20",
          "hasCode": true
        },
        {
          "url": "https://github.com/amnsecurity/CVE-2026-42271-LiteLLM-RCE",
          "stars": 0,
          "desc": "CVE-2026-42271 - LiteLLM AI Gateway MCP Command Injection RCE - PoC & Analysis | CVSS 8.8 | AMN SECURITY",
          "createdAt": "2026-07-07",
          "hasCode": true
        }
      ],
      "epss": 0.80188,
      "epssPercentile": 0.99576,
      "source": "poc",
      "mitreUrl": "https://nvd.nist.gov/vuln/detail/CVE-2026-42271",
      "research": [
        {
          "url": "https://github.com/BerriAI/litellm/security/advisories/GHSA-v4p8-mg3p-g94g",
          "type": "writeup",
          "source": "BerriAI/jaydns — GitHub Security Advisory",
          "note": "Vendor advisory; full vuln description by discoverer",
          "hasCode": true
        },
        {
          "url": "https://horizon3.ai/attack-research/vulnerabilities/cve-2026-42271-chained-with-cve-2026-48710/",
          "type": "poc",
          "source": "Horizon3.ai",
          "note": "PoC: chains with BadHost for unauth RCE (CVSS 10)"
        },
        {
          "url": "https://github.com/advisories/GHSA-v4p8-mg3p-g94g",
          "type": "writeup",
          "source": "GitHub Advisory Database",
          "note": "Official GitHub advisory DB entry for CVE-2026-42271",
          "hasCode": null
        },
        {
          "url": "https://www.sentinelone.com/vulnerability-database/cve-2026-42271/",
          "type": "writeup",
          "source": "SentinelOne Vulnerability Database",
          "note": "Early technical documentation; May 8 first writeup"
        },
        {
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-42271",
          "type": "detection",
          "source": "CISA KEV Catalog",
          "note": "KEV listing; June 8 2026; BOD 22-01 deadline June 22"
        },
        {
          "url": "https://cybelangel.com/blog/itellm-vulnerability-cve-2026-42271/",
          "type": "writeup",
          "source": "CybelAngel",
          "note": "7-point analysis; credential multiplier risk highlighted"
        },
        {
          "url": "https://vulert.com/blog/litellm-cve-2026-42271-rce/",
          "type": "writeup",
          "source": "Vulert",
          "note": "Technical writeup; chain with CVE-2026-48710 explained"
        },
        {
          "url": "https://www.helpnetsecurity.com/2026/06/09/litellm-vulnerability-under-active-attack-cisa-warns-cve-2026-42271/",
          "type": "detection",
          "source": "Help Net Security",
          "note": "IoC list, mitigation steps, active exploitation confirmed"
        }
      ],
      "aliases": [],
      "researchers": [
        "jaydns"
      ],
      "x": {
        "mentions": 92,
        "aliases": [],
        "posts": [
          {
            "handle": "RitikChaddha",
            "followers": 437,
            "likes": 9,
            "createdAt": "2026-06-02",
            "url": "https://x.com/RitikChaddha/status/2061906441901048173",
            "github": [
              {
                "url": "https://github.com/projectdiscovery/nuclei-templates/pull/16325/changes",
                "hasCode": true
              },
              {
                "url": "https://github.com/projectdiscovery/nuclei-templates/pull/16324/changes",
                "hasCode": true
              }
            ],
            "origin": false
          },
          {
            "handle": "456c6f727269",
            "followers": 100,
            "likes": 0,
            "createdAt": "2026-06-11",
            "url": "https://x.com/456c6f727269/status/2064961185447891237",
            "github": [
              {
                "url": "http://github.com/advisories/GHSA-v4p8-mg3p-g94g",
                "hasCode": null
              }
            ],
            "origin": false
          },
          {
            "handle": "TheHackersNews",
            "followers": 1548859,
            "likes": 159,
            "createdAt": "2026-06-09",
            "url": "https://x.com/TheHackersNews/status/2064233564334698774",
            "github": [],
            "origin": false
          },
          {
            "handle": "CISACyber",
            "followers": 298281,
            "likes": 26,
            "createdAt": "2026-06-08",
            "url": "https://x.com/CISACyber/status/2064074591308227072",
            "github": [],
            "origin": false
          },
          {
            "handle": "MalwareBibleJP",
            "followers": 6724,
            "likes": 17,
            "createdAt": "2026-06-09",
            "url": "https://x.com/MalwareBibleJP/status/2064309445702897692",
            "github": [],
            "origin": false
          },
          {
            "handle": "__kokumoto",
            "followers": 7539,
            "likes": 11,
            "createdAt": "2026-06-08",
            "url": "https://x.com/__kokumoto/status/2064114605757202493",
            "github": [],
            "origin": false
          },
          {
            "handle": "modat_magnify",
            "followers": 1687,
            "likes": 8,
            "createdAt": "2026-06-09",
            "url": "https://x.com/modat_magnify/status/2064359667183034478",
            "github": [],
            "origin": false
          },
          {
            "handle": "Dinosn",
            "followers": 156928,
            "likes": 4,
            "createdAt": "2026-06-09",
            "url": "https://x.com/Dinosn/status/2064248049988223425",
            "github": [],
            "origin": false
          }
        ]
      },
      "bsky": {
        "mentions": 25,
        "posts": [
          {
            "handle": "infosec.skyfleet.blue",
            "displayName": "InfoSec",
            "likes": 3,
            "reposts": 0,
            "replies": 0,
            "createdAt": "2026-06-09",
            "url": "https://bsky.app/profile/infosec.skyfleet.blue/post/3mntlyw6gat2q",
            "origin": false,
            "authority": true,
            "github": []
          },
          {
            "handle": "helpnetsecurity.com",
            "displayName": "Help Net Security",
            "likes": 3,
            "reposts": 0,
            "replies": 0,
            "createdAt": "2026-06-09",
            "url": "https://bsky.app/profile/helpnetsecurity.com/post/3mnu4mdbhss2o",
            "origin": false,
            "authority": false,
            "github": []
          },
          {
            "handle": "ins-aisolutions.bsky.social",
            "displayName": "INS AI Solutions",
            "likes": 1,
            "reposts": 0,
            "replies": 1,
            "createdAt": "2026-06-11",
            "url": "https://bsky.app/profile/ins-aisolutions.bsky.social/post/3mnzcx5k6pe2f",
            "origin": false,
            "authority": false,
            "github": []
          },
          {
            "handle": "hacker.at.thenote.app",
            "displayName": "Hacker & Security News",
            "likes": 1,
            "reposts": 0,
            "replies": 0,
            "createdAt": "2026-06-10",
            "url": "https://bsky.app/profile/hacker.at.thenote.app/post/3mnvqkbrpj22h",
            "origin": false,
            "authority": false,
            "github": []
          },
          {
            "handle": "crustytldr.bsky.social",
            "displayName": null,
            "likes": 0,
            "reposts": 0,
            "replies": 1,
            "createdAt": "2026-06-09",
            "url": "https://bsky.app/profile/crustytldr.bsky.social/post/3mntwx7jrr42z",
            "origin": false,
            "authority": false,
            "github": []
          },
          {
            "handle": "packetstorm.bsky.social",
            "displayName": "Packet Storm News",
            "likes": 0,
            "reposts": 1,
            "replies": 0,
            "createdAt": "2026-06-09",
            "url": "https://bsky.app/profile/packetstorm.bsky.social/post/3mnutyxds3r2s",
            "origin": false,
            "authority": false,
            "github": []
          }
        ]
      },
      "telegram": {
        "mentions": 1,
        "posts": [
          {
            "channel": "thehackernews",
            "channelTitle": "The Hacker News",
            "tier": "news",
            "date": "2026-06-09",
            "views": 8218,
            "forwards": 32,
            "url": "https://t.me/thehackernews/9184",
            "text": "🚨 Hackers are already exploiting a flaw in LiteLLM, a widely used open-source AI gateway. One bug (CVE-2026-42271) lets any logged-in user run commands on the server. Chain it with a second bug, and attackers get in with no login at all. At risk: API keys, stored secrets, and everything connected to it. 🔗 Details: https://thehackernews.com/2026/06/litellm-flaw-cve-2026-42271-exploited.html",
            "github": [],
            "origin": false
          }
        ]
      }
    },
    {
      "cve": "CVE-2026-5513",
      "title": "The Online Scheduling and Appointment Booking System – Bookly plugin for WordPress is…",
      "category": "Recall",
      "vendor": null,
      "exploited": false,
      "publiclyDisclosed": true,
      "cvss": 7.2,
      "cvssVector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N",
      "severity": "HIGH",
      "impact": null,
      "products": [],
      "productCount": 0,
      "faq": "The Online Scheduling and Appointment Booking System – Bookly plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'bookly-customer-full-name' cookie in versions up to, and including, 27.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. Exploitation requires 'Remember personal information in cookies' setting to be enabled (disabled by default).",
      "pocConfidence": "confirmed",
      "pocCount": 2,
      "pocTopStars": 0,
      "pocRepos": [
        {
          "url": "https://github.com/Xaanziu/CVE-2026-5513",
          "stars": 0,
          "desc": "CVE-2026-5513: Bookly <= 27.2 Stored XSS via Cookie (Unauthenticated)",
          "createdAt": "2026-06-14",
          "hasCode": true
        },
        {
          "url": "https://github.com/87achrafg-stack/CVE-2026-5513",
          "stars": 0,
          "desc": "CVE-2026-5513 — Bookly ≤ 27.2 Stored XSS via Cookie",
          "createdAt": "2026-06-14",
          "hasCode": true
        }
      ],
      "epss": 0.00312,
      "epssPercentile": 0.23316,
      "source": "poc",
      "mitreUrl": "https://nvd.nist.gov/vuln/detail/CVE-2026-5513",
      "research": [],
      "aliases": [],
      "researchers": [],
      "x": {
        "mentions": 0,
        "aliases": [],
        "posts": []
      },
      "bsky": {
        "mentions": 8,
        "posts": [
          {
            "handle": "cybersecinsight.bsky.social",
            "displayName": "CyberSec Insight",
            "likes": 1,
            "reposts": 1,
            "replies": 1,
            "createdAt": "2026-06-14",
            "url": "https://bsky.app/profile/cybersecinsight.bsky.social/post/3moaop5bw442b",
            "origin": false,
            "authority": false,
            "github": []
          },
          {
            "handle": "cve.skyfleet.blue",
            "displayName": "CVE Alerts ",
            "likes": 1,
            "reposts": 1,
            "replies": 0,
            "createdAt": "2026-06-13",
            "url": "https://bsky.app/profile/cve.skyfleet.blue/post/3mo6m3c34xg2r",
            "origin": false,
            "authority": false,
            "github": []
          },
          {
            "handle": "hermes71.bsky.social",
            "displayName": "Some Hermes agent",
            "likes": 0,
            "reposts": 0,
            "replies": 1,
            "createdAt": "2026-06-15",
            "url": "https://bsky.app/profile/hermes71.bsky.social/post/3mod2dzmmsy2y",
            "origin": false,
            "authority": false,
            "github": []
          },
          {
            "handle": "offseq.bsky.social",
            "displayName": "OffSequence",
            "likes": 0,
            "reposts": 1,
            "replies": 0,
            "createdAt": "2026-06-14",
            "url": "https://bsky.app/profile/offseq.bsky.social/post/3moa3qky2ho2l",
            "origin": false,
            "authority": false,
            "github": []
          },
          {
            "handle": "postac001.bsky.social",
            "displayName": "tec_acc",
            "likes": 0,
            "reposts": 1,
            "replies": 0,
            "createdAt": "2026-06-13",
            "url": "https://bsky.app/profile/postac001.bsky.social/post/3mo6fbiwasm22",
            "origin": false,
            "authority": false,
            "github": []
          },
          {
            "handle": "pulse-wp.com",
            "displayName": "Pulse WP",
            "likes": 0,
            "reposts": 1,
            "replies": 0,
            "createdAt": "2026-06-13",
            "url": "https://bsky.app/profile/pulse-wp.com/post/3mo6tilwrx22o",
            "origin": false,
            "authority": false,
            "github": []
          }
        ]
      }
    },
    {
      "cve": "CVE-2026-0770",
      "title": "Langflow exec_globals Inclusion of Functionality from Untrusted Control Sphere Remote…",
      "category": "Recall",
      "vendor": null,
      "exploited": true,
      "publiclyDisclosed": true,
      "cvss": 9.8,
      "cvssVector": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "severity": "CRITICAL",
      "impact": null,
      "products": [],
      "productCount": 0,
      "faq": "Langflow exec_globals Inclusion of Functionality from Untrusted Control Sphere Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Langflow. Authentication is not required to exploit this vulnerability.\n\nThe specific flaw exists within the handling of the exec_globals parameter provided to the validate endpoint. The issue results from the inclusion of a resource from an untrusted control sphere. An attacker can leverage this vulnerability to execute code in the context of root. Was ZDI-CAN-27325.",
      "pocConfidence": "confirmed",
      "pocCount": 2,
      "pocTopStars": 0,
      "pocRepos": [
        {
          "url": "https://github.com/Ez4rd1x1/CVE-2026-0770",
          "stars": 0,
          "desc": "LangFlow RCE | CVE-2026-0770 | Proof-Of-Concept",
          "createdAt": "2026-05-15",
          "hasCode": true
        },
        {
          "url": "https://github.com/diamorphine666/CVE-2026-0770",
          "stars": 0,
          "desc": "Langflow remote code execution exploit",
          "createdAt": "2026-05-23",
          "hasCode": true
        }
      ],
      "epss": 0.10371,
      "epssPercentile": 0.95225,
      "source": "poc",
      "mitreUrl": "https://nvd.nist.gov/vuln/detail/CVE-2026-0770",
      "research": [
        {
          "url": "https://github.com/langflow-ai/langflow/security/advisories/GHSA-vwmf-pq79-vjvx",
          "type": "writeup",
          "source": "langflow GHSA",
          "note": "Unauth RCE via public flow build endpoint",
          "hasCode": true
        },
        {
          "url": "https://www.exploit-db.com/exploits/52597",
          "type": "poc",
          "source": "Exploit-DB",
          "note": "Langflow 1.3.0 RCE exploit"
        },
        {
          "url": "https://github.com/affix/CVE-2026-0770-PoC",
          "type": "poc",
          "source": "affix",
          "note": "PoC for Langflow RCE via validate_code",
          "hasCode": true
        },
        {
          "url": "https://github.com/0xgh057r3c0n/CVE-2026-0770",
          "type": "poc",
          "source": "0xgh057r3c0n",
          "note": "RCE PoC exec_globals exec()",
          "hasCode": true
        }
      ],
      "x": {
        "mentions": 4,
        "posts": [
          {
            "handle": "pdnuclei_bot",
            "followers": 949,
            "likes": 5,
            "createdAt": "2026-02-22",
            "url": "https://x.com/pdnuclei_bot/status/2025707211205517544",
            "origin": false,
            "github": []
          },
          {
            "handle": "transilienceai",
            "followers": 332,
            "likes": 0,
            "createdAt": "2026-02-22",
            "url": "https://x.com/transilienceai/status/2025413138925908276",
            "origin": false,
            "github": []
          },
          {
            "handle": "CVEnew",
            "followers": 57565,
            "likes": 0,
            "createdAt": "2026-01-23",
            "url": "https://x.com/CVEnew/status/2014576951957315822",
            "origin": false,
            "github": []
          },
          {
            "handle": "CveFindCom",
            "followers": 620,
            "likes": 0,
            "createdAt": "2026-01-23",
            "url": "https://x.com/CveFindCom/status/2014558758748270784",
            "origin": false,
            "github": []
          }
        ],
        "aliases": []
      },
      "researchers": [
        "affix",
        "0xgh057r3c0n"
      ],
      "bsky": {
        "mentions": 6,
        "posts": [
          {
            "handle": "beikokucyber.bsky.social",
            "displayName": "Beikoku Cybersecurity",
            "likes": 0,
            "reposts": 0,
            "replies": 0,
            "createdAt": "2026-02-23",
            "url": "https://bsky.app/profile/beikokucyber.bsky.social/post/3mfkkg736ie2h",
            "origin": false,
            "authority": false,
            "github": []
          },
          {
            "handle": "thehackerwire.bsky.social",
            "displayName": "TheHackerWire",
            "likes": 0,
            "reposts": 0,
            "replies": 0,
            "createdAt": "2026-01-23",
            "url": "https://bsky.app/profile/thehackerwire.bsky.social/post/3md2zecuky22h",
            "origin": false,
            "authority": false,
            "github": []
          },
          {
            "handle": "cve.skyfleet.blue",
            "displayName": "CVE Alerts ",
            "likes": 0,
            "reposts": 0,
            "replies": 0,
            "createdAt": "2026-01-23",
            "url": "https://bsky.app/profile/cve.skyfleet.blue/post/3md3bcrstqg2c",
            "origin": false,
            "authority": false,
            "github": []
          }
        ]
      },
      "telegram": {
        "mentions": 0,
        "posts": []
      },
      "aliases": []
    },
    {
      "cve": "CVE-2026-10795",
      "title": "The UpdraftPlus: WP Backup & Migration Plugin plugin for WordPress is vulnerable to…",
      "category": "Recall",
      "vendor": null,
      "exploited": false,
      "publiclyDisclosed": true,
      "cvss": 8.1,
      "cvssVector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "severity": "HIGH",
      "impact": null,
      "products": [],
      "productCount": 0,
      "faq": "The UpdraftPlus: WP Backup & Migration Plugin plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 1.26.4 via the UpdraftPlus_Remote_Communications_V2::wp_loaded function. This is due to insufficient validation of the remote communications message format, where signature verification can be bypassed and unchecked decryption return values collapse to a predictable all-zero encryption key. This makes it possible for unauthenticated attackers to forge arbitrary RPC commands and run them as the connected administrator, such as uploading and activating a malicious plugin, which ultimately leads to remote code execution.",
      "pocConfidence": "confirmed",
      "pocCount": 2,
      "pocTopStars": 0,
      "pocRepos": [
        {
          "url": "https://github.com/izxci/CVE-2026-10795",
          "stars": 0,
          "desc": "CVE-2026-10795 – UpdraftPlus Authentication Bypass",
          "createdAt": "2026-06-11",
          "hasCode": true
        },
        {
          "url": "https://github.com/webshellseo8/CVE-2026-10795-POC",
          "stars": 0,
          "desc": "CVE-2026-10795 The UpdraftPlus POC",
          "createdAt": "2026-06-11",
          "hasCode": true
        }
      ],
      "epss": 0.03578,
      "epssPercentile": 0.88129,
      "source": "poc",
      "mitreUrl": "https://nvd.nist.gov/vuln/detail/CVE-2026-10795",
      "research": [
        {
          "url": "https://github.com/izxci/CVE-2026-10795",
          "type": "poc",
          "source": "GitHub / izxci",
          "note": "Python PoC: forges RPC, uploads webshell ZIP",
          "hasCode": true
        },
        {
          "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/e901c2a0-2477-4b9a-8483-6002419e0a2f?source=cve",
          "type": "writeup",
          "source": "Wordfence Threat Intelligence",
          "note": "Official advisory; discoverer vtim, $5200 bounty"
        },
        {
          "url": "https://www.wordfence.com/blog/2026/06/critical-unauthenticated-authentication-bypass-vulnerability-patched-in-updraftplus-wordpress-plugin/",
          "type": "writeup",
          "source": "Wordfence Blog",
          "note": "Deep-dive: crypto bypass, all-zero AES key root cause"
        },
        {
          "url": "https://plugins.trac.wordpress.org/changeset/3561938/updraftplus/trunk/vendor/team-updraft/common-libs/src/updraft-rpc/class-udrpc2.php",
          "type": "writeup",
          "source": "WordPress.org Trac (vendor patch diff)",
          "note": "Official patch diff for class-udrpc2.php"
        },
        {
          "url": "https://plugins.svn.wordpress.org/updraftplus/tags/1.26.4/vendor/team-updraft/common-libs/src/updraft-rpc/class-udrpc2.php",
          "type": "writeup",
          "source": "WordPress SVN (vuln source)",
          "note": "Vulnerable udrpc2.php source for diff analysis"
        },
        {
          "url": "https://github.com/topscoder/nuclei-wordfence-cve",
          "type": "module",
          "source": "GitHub / topscoder (nuclei-wordfence-cve)",
          "note": "70k+ WP Nuclei templates; CVE-2026-10795 auto-included",
          "hasCode": true
        },
        {
          "url": "https://vuldb.com/cve/CVE-2026-10795",
          "type": "writeup",
          "source": "VulDB",
          "note": "Enriched CVE entry; crypto bypass mechanic detail"
        },
        {
          "url": "https://www.tenable.com/cve/CVE-2026-10795",
          "type": "detection",
          "source": "Tenable",
          "note": "Tenable plugin/detection entry; patch references"
        }
      ],
      "x": {
        "mentions": 2,
        "aliases": [],
        "posts": [
          {
            "handle": "AndreGironda",
            "followers": 3793,
            "likes": 0,
            "createdAt": "2026-06-11",
            "url": "https://x.com/AndreGironda/status/2065094293728170004",
            "github": [
              {
                "url": "https://github.com/izxci/CVE-2026-10795",
                "hasCode": true
              }
            ],
            "origin": false
          },
          {
            "handle": "the_yellow_fall",
            "followers": 12202,
            "likes": 5,
            "createdAt": "2026-06-10",
            "url": "https://x.com/the_yellow_fall/status/2064856167910916252",
            "github": [],
            "origin": false
          }
        ]
      },
      "researchers": [
        "vtim"
      ],
      "aliases": [],
      "bsky": {
        "mentions": 10,
        "posts": [
          {
            "handle": "responsive-uk.bsky.social",
            "displayName": "Responsive UK",
            "likes": 0,
            "reposts": 1,
            "replies": 1,
            "createdAt": "2026-06-10",
            "url": "https://bsky.app/profile/responsive-uk.bsky.social/post/3mnxf3bkwjk23",
            "origin": false,
            "authority": false,
            "github": []
          },
          {
            "handle": "atomicedge.bsky.social",
            "displayName": "Atomic Edge",
            "likes": 1,
            "reposts": 0,
            "replies": 0,
            "createdAt": "2026-06-12",
            "url": "https://bsky.app/profile/atomicedge.bsky.social/post/3mo2hl2aa5v26",
            "origin": false,
            "authority": false,
            "github": []
          },
          {
            "handle": "thehackerwire.bsky.social",
            "displayName": "TheHackerWire",
            "likes": 0,
            "reposts": 1,
            "replies": 0,
            "createdAt": "2026-06-11",
            "url": "https://bsky.app/profile/thehackerwire.bsky.social/post/3mnz35knkmi2n",
            "origin": false,
            "authority": false,
            "github": []
          },
          {
            "handle": "donwebmedia.bsky.social",
            "displayName": null,
            "likes": 0,
            "reposts": 1,
            "replies": 0,
            "createdAt": "2026-06-11",
            "url": "https://bsky.app/profile/donwebmedia.bsky.social/post/3mnys6ewjgy2w",
            "origin": false,
            "authority": false,
            "github": []
          },
          {
            "handle": "postac001.bsky.social",
            "displayName": "tec_acc",
            "likes": 0,
            "reposts": 1,
            "replies": 0,
            "createdAt": "2026-06-11",
            "url": "https://bsky.app/profile/postac001.bsky.social/post/3mnypcydait2v",
            "origin": false,
            "authority": false,
            "github": []
          },
          {
            "handle": "pulse-wp.com",
            "displayName": "Pulse WP",
            "likes": 0,
            "reposts": 1,
            "replies": 0,
            "createdAt": "2026-06-11",
            "url": "https://bsky.app/profile/pulse-wp.com/post/3mnz6hbl2ed2n",
            "origin": false,
            "authority": false,
            "github": []
          }
        ]
      }
    },
    {
      "cve": "CVE-2026-49009",
      "title": "Northern.tech Mender Server v4.1.0, v4.0.1 and below, and fixed in v4.1.1 and v4.0.2…",
      "category": "Recall",
      "vendor": null,
      "exploited": false,
      "publiclyDisclosed": true,
      "cvss": 3.1,
      "cvssVector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N",
      "severity": "LOW",
      "impact": null,
      "products": [],
      "productCount": 0,
      "faq": "Northern.tech Mender Server v4.1.0, v4.0.1 and below, and fixed in v4.1.1 and v4.0.2 allows Directory Traversal.",
      "pocConfidence": "confirmed",
      "pocCount": 2,
      "pocTopStars": 0,
      "pocRepos": [
        {
          "url": "https://github.com/j0xh-sec/CVE-2026-49009",
          "stars": 0,
          "desc": "POC for CVE-2026-49009, an authenticated path traversal to RCE issue in Mender Server.",
          "createdAt": "2026-05-28",
          "hasCode": true
        },
        {
          "url": "https://github.com/INTELEON404/CVE-2026-49009",
          "stars": 0,
          "desc": "Mender Server - Authenticated Path Traversal to RCE",
          "createdAt": "2026-06-02",
          "hasCode": true
        }
      ],
      "epss": 0.0052,
      "epssPercentile": 0.40808,
      "source": "poc",
      "mitreUrl": "https://nvd.nist.gov/vuln/detail/CVE-2026-49009",
      "research": [
        {
          "url": "https://mender.io/blog/cve-2026-49009-cve-2026-33552-input-sanitization-and-access-control-issues-in-mender-server",
          "type": "writeup",
          "source": "Mender",
          "note": "Path traversal in artifact creation endpoint"
        },
        {
          "url": "https://bitninja.com/blog/server-security-alert-cve-2026-49009-vulnerability/",
          "type": "writeup",
          "source": "BitNinja",
          "note": "Server security alert analysis"
        }
      ],
      "x": {
        "mentions": 0,
        "posts": [],
        "aliases": []
      },
      "researchers": [
        "j0xh-sec"
      ],
      "aliases": [],
      "bsky": {
        "mentions": 0,
        "posts": []
      }
    },
    {
      "cve": "CVE-2026-20817",
      "title": "Improper handling of insufficient permissions or privileges in Windows Error…",
      "category": "Recall",
      "vendor": null,
      "exploited": false,
      "publiclyDisclosed": true,
      "cvss": 7.8,
      "cvssVector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "severity": "HIGH",
      "impact": null,
      "products": [],
      "productCount": 0,
      "faq": "Improper handling of insufficient permissions or privileges in Windows Error Reporting allows an authorized attacker to elevate privileges locally.",
      "pocConfidence": "confirmed",
      "pocCount": 1,
      "pocTopStars": 126,
      "pocRepos": [
        {
          "url": "https://github.com/oxfemale/CVE-2026-20817",
          "stars": 126,
          "desc": "Windows Error Reporting ALPC Elevation of Privilege (CVE-2026-20817) - Proof-of-Concept exploit demonstrating local privilege escalation via WER service.",
          "createdAt": "2026-02-18",
          "hasCode": true
        }
      ],
      "epss": 0.05333,
      "epssPercentile": 0.91733,
      "source": "poc",
      "mitreUrl": "https://nvd.nist.gov/vuln/detail/CVE-2026-20817",
      "research": [],
      "aliases": [],
      "researchers": [],
      "x": {
        "mentions": 0,
        "aliases": [],
        "posts": []
      },
      "bsky": {
        "mentions": 16,
        "posts": [
          {
            "handle": "infosec.skyfleet.blue",
            "displayName": "InfoSec",
            "likes": 0,
            "reposts": 0,
            "replies": 0,
            "createdAt": "2026-04-18",
            "url": "https://bsky.app/profile/infosec.skyfleet.blue/post/3mjqk2ct6hd24",
            "origin": false,
            "authority": true,
            "github": []
          },
          {
            "handle": "oxfemale.bsky.social",
            "displayName": null,
            "likes": 1,
            "reposts": 0,
            "replies": 0,
            "createdAt": "2026-02-18",
            "url": "https://bsky.app/profile/oxfemale.bsky.social/post/3mf5bbnqepu2c",
            "origin": false,
            "authority": false,
            "github": [
              {
                "url": "https://github.com/oxfemale/CVE-2026-20817",
                "hasCode": true
              }
            ]
          },
          {
            "handle": "co11ateral.bsky.social",
            "displayName": "co11ateral",
            "likes": 0,
            "reposts": 0,
            "replies": 0,
            "createdAt": "2026-02-21",
            "url": "https://bsky.app/profile/co11ateral.bsky.social/post/3mfepziijds2s",
            "origin": false,
            "authority": false,
            "github": [
              {
                "url": "https://github.com/oxfemale/CVE-2026-20817",
                "hasCode": true
              }
            ]
          },
          {
            "handle": "undercode.bsky.social",
            "displayName": "Undercode Testing",
            "likes": 1,
            "reposts": 0,
            "replies": 0,
            "createdAt": "2026-03-27",
            "url": "https://bsky.app/profile/undercode.bsky.social/post/3mhzrb6ipwo2d",
            "origin": false,
            "authority": false,
            "github": []
          },
          {
            "handle": "securitylab-jp.bsky.social",
            "displayName": "セキュリティ対策Lab",
            "likes": 0,
            "reposts": 0,
            "replies": 0,
            "createdAt": "2026-03-31",
            "url": "https://bsky.app/profile/securitylab-jp.bsky.social/post/3micuxxje7k2m",
            "origin": false,
            "authority": false,
            "github": []
          },
          {
            "handle": "thedailytechfeed.com",
            "displayName": "The Daily Tech Feed",
            "likes": 0,
            "reposts": 0,
            "replies": 0,
            "createdAt": "2026-03-28",
            "url": "https://bsky.app/profile/thedailytechfeed.com/post/3mi4x3qpjcs2p",
            "origin": false,
            "authority": false,
            "github": []
          }
        ]
      }
    },
    {
      "cve": "CVE-2026-34486",
      "title": "Missing Encryption of Sensitive Data vulnerability in Apache Tomcat due to the fix…",
      "category": "Recall",
      "vendor": null,
      "exploited": false,
      "publiclyDisclosed": true,
      "cvss": 7.5,
      "cvssVector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
      "severity": "HIGH",
      "impact": null,
      "products": [],
      "productCount": 0,
      "faq": "Missing Encryption of Sensitive Data vulnerability in Apache Tomcat due to the fix for CVE-2026-29146 allowing the bypass of the EncryptInterceptor.\n\nThis issue affects Apache Tomcat: 11.0.20, 10.1.53, 9.0.116.\n\nUsers are recommended to upgrade to version 11.0.21, 10.1.54 or 9.0.117, which fix the issue.",
      "pocConfidence": "confirmed",
      "pocCount": 1,
      "pocTopStars": 68,
      "pocRepos": [
        {
          "url": "https://github.com/striga-ai/CVE-2026-34486",
          "stars": 68,
          "desc": "EncryptInterceptor fail-open bypass in Apache Tomcat Tribes clustering leading to unauthenticated RCE via Java deserialization.",
          "createdAt": "2026-05-11",
          "hasCode": true
        }
      ],
      "epss": 0.21691,
      "epssPercentile": 0.9737,
      "source": "poc",
      "mitreUrl": "https://nvd.nist.gov/vuln/detail/CVE-2026-34486",
      "research": [
        {
          "url": "https://tomcat.apache.org/security-11.html",
          "type": "writeup",
          "source": "Apache Tomcat",
          "note": "Official advisory, EncryptInterceptor fail-open"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-34486",
          "type": "writeup",
          "source": "NVD",
          "note": "Missing encryption, bypass of EncryptInterceptor"
        },
        {
          "url": "https://www.acunetix.com/vulnerabilities/web/apache-tomcat-missing-encryption-of-sensitive-data-vulnerability-cve-2026-34486/",
          "type": "writeup",
          "source": "Acunetix",
          "note": "Missing encryption of sensitive data"
        }
      ],
      "x": {
        "mentions": 7,
        "aliases": [],
        "posts": [
          {
            "handle": "striga_ai",
            "followers": 537,
            "likes": 741,
            "createdAt": "2026-05-11",
            "url": "https://x.com/striga_ai/status/2053853079443784165",
            "github": [
              {
                "url": "https://github.com/striga-ai/CVE-2026-34486",
                "hasCode": true
              }
            ],
            "origin": false
          },
          {
            "handle": "yousukezan",
            "followers": 14098,
            "likes": 229,
            "createdAt": "2026-05-11",
            "url": "https://x.com/yousukezan/status/2053971866386395286",
            "github": [],
            "origin": false
          },
          {
            "handle": "darkrelaylabs",
            "followers": 148,
            "likes": 6,
            "createdAt": "2026-05-11",
            "url": "https://x.com/darkrelaylabs/status/2053856404243660957",
            "github": [
              {
                "url": "https://github.com/striga-ai/CVE-2026-34486",
                "hasCode": true
              }
            ],
            "origin": false
          },
          {
            "handle": "threatcluster",
            "followers": 285,
            "likes": 0,
            "createdAt": "2026-05-28",
            "url": "https://x.com/threatcluster/status/2060043845039960455",
            "github": [],
            "origin": false
          },
          {
            "handle": "lyrie_ai",
            "followers": 236,
            "likes": 0,
            "createdAt": "2026-05-12",
            "url": "https://x.com/lyrie_ai/status/2054140798262718677",
            "github": [],
            "origin": false
          }
        ]
      },
      "aliases": [],
      "researchers": [],
      "bsky": {
        "mentions": 7,
        "posts": [
          {
            "handle": "infosec.skyfleet.blue",
            "displayName": "InfoSec",
            "likes": 1,
            "reposts": 0,
            "replies": 0,
            "createdAt": "2026-04-09",
            "url": "https://bsky.app/profile/infosec.skyfleet.blue/post/3mj3xbf5a7m2m",
            "origin": false,
            "authority": true,
            "github": []
          },
          {
            "handle": "o2cloud.bsky.social",
            "displayName": "CVE by o2Cloud",
            "likes": 0,
            "reposts": 0,
            "replies": 1,
            "createdAt": "2026-04-10",
            "url": "https://bsky.app/profile/o2cloud.bsky.social/post/3mj5ediuo5m2z",
            "origin": false,
            "authority": false,
            "github": []
          },
          {
            "handle": "hack0day.bsky.social",
            "displayName": null,
            "likes": 0,
            "reposts": 0,
            "replies": 0,
            "createdAt": "2026-06-07",
            "url": "https://bsky.app/profile/hack0day.bsky.social/post/3mnplvp2nq22x",
            "origin": false,
            "authority": false,
            "github": []
          },
          {
            "handle": "modat-io.bsky.social",
            "displayName": "Modat",
            "likes": 0,
            "reposts": 0,
            "replies": 0,
            "createdAt": "2026-04-14",
            "url": "https://bsky.app/profile/modat-io.bsky.social/post/3mjhaxbrnf22g",
            "origin": false,
            "authority": false,
            "github": []
          },
          {
            "handle": "e-kiledjian.bsky.social",
            "displayName": null,
            "likes": 0,
            "reposts": 0,
            "replies": 0,
            "createdAt": "2026-04-13",
            "url": "https://bsky.app/profile/e-kiledjian.bsky.social/post/3mjfepkuor22c",
            "origin": false,
            "authority": false,
            "github": []
          },
          {
            "handle": "thehackerwire.bsky.social",
            "displayName": "TheHackerWire",
            "likes": 0,
            "reposts": 0,
            "replies": 0,
            "createdAt": "2026-04-12",
            "url": "https://bsky.app/profile/thehackerwire.bsky.social/post/3mjbouv6jrq2w",
            "origin": false,
            "authority": false,
            "github": []
          }
        ]
      }
    },
    {
      "cve": "CVE-2026-3227",
      "title": "A command injection vulnerability was identified in TP-Link TL-WR802N v4, TL-WR841N…",
      "category": "Recall",
      "vendor": null,
      "exploited": false,
      "publiclyDisclosed": true,
      "cvss": 6.8,
      "cvssVector": "CVSS:3.1/AV:A/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H",
      "severity": "MEDIUM",
      "impact": null,
      "products": [],
      "productCount": 0,
      "faq": "A command injection vulnerability was identified in TP-Link TL-WR802N v4, TL-WR841N v14, and TL-WR840N v6 due to improper neutralization of special elements used in an OS command.  In the router configuration import function allows an authenticated attacker to upload a crafted configuration file that results in execution of OS commands with root privileges during port-trigger processing.  \nSuccessful exploitation allows an authenticated attacker to execute system commands with root privileges, leading to full device compromise.",
      "pocConfidence": "confirmed",
      "pocCount": 1,
      "pocTopStars": 40,
      "pocRepos": [
        {
          "url": "https://github.com/do4choo/CVE-2026-3227",
          "stars": 40,
          "desc": "",
          "createdAt": "2026-06-25",
          "hasCode": true
        }
      ],
      "epss": 0.01102,
      "epssPercentile": 0.62107,
      "source": "poc",
      "mitreUrl": "https://nvd.nist.gov/vuln/detail/CVE-2026-3227",
      "research": [],
      "aliases": [],
      "researchers": [],
      "x": {
        "mentions": 0,
        "aliases": [],
        "posts": []
      },
      "bsky": {
        "mentions": 10,
        "posts": [
          {
            "handle": "opsmatters.com",
            "displayName": "OpsMatters",
            "likes": 0,
            "reposts": 1,
            "replies": 0,
            "createdAt": "2026-07-01",
            "url": "https://bsky.app/profile/opsmatters.com/post/3mpkrh364ai2u",
            "origin": false,
            "authority": false,
            "github": []
          },
          {
            "handle": "secqube.com",
            "displayName": "SecQube | Harvey | AI Platform for MS Graph",
            "likes": 0,
            "reposts": 1,
            "replies": 0,
            "createdAt": "2026-04-02",
            "url": "https://bsky.app/profile/secqube.com/post/3mii32lsfcb2s",
            "origin": false,
            "authority": false,
            "github": []
          },
          {
            "handle": "offseq.bsky.social",
            "displayName": "OffSequence",
            "likes": 0,
            "reposts": 1,
            "replies": 0,
            "createdAt": "2026-03-14",
            "url": "https://bsky.app/profile/offseq.bsky.social/post/3mgyvuvnldn2n",
            "origin": false,
            "authority": false,
            "github": []
          },
          {
            "handle": "kriptabiz.bsky.social",
            "displayName": "kripta.biz",
            "likes": 0,
            "reposts": 0,
            "replies": 0,
            "createdAt": "2026-07-02",
            "url": "https://bsky.app/profile/kriptabiz.bsky.social/post/3mpndyeipyr2y",
            "origin": false,
            "authority": false,
            "github": []
          },
          {
            "handle": "qiancx.bsky.social",
            "displayName": "qian.cx",
            "likes": 0,
            "reposts": 0,
            "replies": 0,
            "createdAt": "2026-07-02",
            "url": "https://bsky.app/profile/qiancx.bsky.social/post/3mpndycy3io2a",
            "origin": false,
            "authority": false,
            "github": []
          },
          {
            "handle": "potato.software",
            "displayName": "CyberTaters",
            "likes": 0,
            "reposts": 0,
            "replies": 0,
            "createdAt": "2026-07-01",
            "url": "https://bsky.app/profile/potato.software/post/3mpkscfnxlp2n",
            "origin": false,
            "authority": false,
            "github": []
          }
        ]
      }
    },
    {
      "cve": "CVE-2026-8389",
      "title": "JIT miscompilation in the JavaScript Engine: JIT component. This vulnerability was…",
      "category": "Recall",
      "vendor": null,
      "exploited": false,
      "publiclyDisclosed": true,
      "cvss": 8.8,
      "cvssVector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
      "severity": "HIGH",
      "impact": null,
      "products": [],
      "productCount": 0,
      "faq": "JIT miscompilation in the JavaScript Engine: JIT component. This vulnerability was fixed in Firefox 150.0.3.",
      "pocConfidence": "confirmed",
      "pocCount": 1,
      "pocTopStars": 40,
      "pocRepos": [
        {
          "url": "https://github.com/crixpwn/CVE-2026-8389",
          "stars": 40,
          "desc": "",
          "createdAt": "2026-06-04",
          "hasCode": true
        }
      ],
      "epss": 0.00331,
      "epssPercentile": 0.25346,
      "source": "poc",
      "mitreUrl": "https://nvd.nist.gov/vuln/detail/CVE-2026-8389",
      "research": [
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-8389",
          "type": "writeup",
          "source": "NVD",
          "note": "JIT miscompilation in JS engine, fixed Firefox 150.0.3"
        },
        {
          "url": "https://vulnerability.circl.lu/vuln/cve-2026-8389",
          "type": "writeup",
          "source": "CIRCL",
          "note": "Firefox JS engine JIT miscompilation"
        }
      ],
      "x": {
        "mentions": 4,
        "posts": [
          {
            "handle": "pwning_me",
            "followers": 479,
            "likes": 194,
            "createdAt": "2026-06-04",
            "url": "https://x.com/pwning_me/status/2062567017786531850",
            "origin": false,
            "github": [
              {
                "url": "https://github.com/crixpwn/CVE-2026-8389"
              }
            ]
          },
          {
            "handle": "xvonfers",
            "followers": 4985,
            "likes": 15,
            "createdAt": "2026-05-13",
            "url": "https://x.com/xvonfers/status/2054594270653259927",
            "origin": false,
            "github": []
          },
          {
            "handle": "TheRabbitPy",
            "followers": 1312,
            "likes": 1,
            "createdAt": "2026-05-12",
            "url": "https://x.com/TheRabbitPy/status/2054297768504533303",
            "origin": false,
            "github": []
          },
          {
            "handle": "Cezar_H_Linux",
            "followers": 1518,
            "likes": 0,
            "createdAt": "2026-05-15",
            "url": "https://x.com/Cezar_H_Linux/status/2055391209850290497",
            "origin": false,
            "github": []
          }
        ],
        "aliases": []
      },
      "researchers": [
        "ggwhyp"
      ],
      "aliases": [],
      "bsky": {
        "mentions": 4,
        "posts": [
          {
            "handle": "wdormann.infosec.exchange.ap.brid.gy",
            "displayName": "Will Dormann",
            "likes": 1,
            "reposts": 2,
            "replies": 1,
            "createdAt": "2026-06-05",
            "url": "https://bsky.app/profile/wdormann.infosec.exchange.ap.brid.gy/post/3mnk6yb6nabv2",
            "origin": false,
            "authority": false,
            "github": [
              {
                "url": "https://github.com/crixpwn/CVE-2026-8389",
                "hasCode": true
              }
            ]
          },
          {
            "handle": "ferramentaslinux.bsky.social",
            "displayName": null,
            "likes": 2,
            "reposts": 1,
            "replies": 1,
            "createdAt": "2026-05-15",
            "url": "https://bsky.app/profile/ferramentaslinux.bsky.social/post/3mlw7mpsl4c2i",
            "origin": false,
            "authority": false,
            "github": []
          },
          {
            "handle": "cve.skyfleet.blue",
            "displayName": "CVE Alerts ",
            "likes": 0,
            "reposts": 1,
            "replies": 0,
            "createdAt": "2026-05-12",
            "url": "https://bsky.app/profile/cve.skyfleet.blue/post/3mlo3f3lnww2c",
            "origin": false,
            "authority": false,
            "github": []
          },
          {
            "handle": "getpokemon7.bsky.social",
            "displayName": "まりーん",
            "likes": 0,
            "reposts": 0,
            "replies": 0,
            "createdAt": "2026-05-25",
            "url": "https://bsky.app/profile/getpokemon7.bsky.social/post/3mmpkrtavx224",
            "origin": false,
            "authority": false,
            "github": []
          }
        ]
      }
    },
    {
      "cve": "CVE-2026-23631",
      "title": "Redis is an in-memory data structure store. In all versions of redis-server with Lua…",
      "category": "Recall",
      "vendor": null,
      "exploited": false,
      "publiclyDisclosed": true,
      "cvss": 8.1,
      "cvssVector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H",
      "severity": "HIGH",
      "impact": null,
      "products": [],
      "productCount": 0,
      "faq": "Redis is an in-memory data structure store. In all versions of redis-server with Lua scripting, an authenticated attacker can exploit the master-replica synchronization mechanism to trigger a use-after-free on replicas where replica-read-only is disabled or can be disabled, which may lead to remote code execution. A workaround is to prevent users from executing Lua scripts or avoid using replicas where replica-read-only is disabled. This is patched in version 8.6.3.",
      "pocConfidence": "confirmed",
      "pocCount": 1,
      "pocTopStars": 30,
      "pocRepos": [
        {
          "url": "https://github.com/yoyosh/DarkReplica",
          "stars": 30,
          "desc": "CVE-2026-23631 (DarkReplica) Redis Exploit",
          "createdAt": "2026-05-07",
          "hasCode": true
        }
      ],
      "epss": 0.01782,
      "epssPercentile": 0.75866,
      "source": "poc",
      "mitreUrl": "https://nvd.nist.gov/vuln/detail/CVE-2026-23631",
      "research": [
        {
          "url": "https://redis.io/blog/security-advisory-cve202623479-cve202625243-cve-2026-25588-cve202625589-cve-2026-23631/",
          "type": "writeup",
          "source": "Redis",
          "note": "Official advisory, Lua replica UAF to RCE"
        },
        {
          "url": "https://www.offsec.com/blog/recent-vulnerabilities-in-redis-servers-lua-scripting-engine/",
          "type": "writeup",
          "source": "OffSec",
          "note": "Analysis of Redis Lua scripting flaws"
        },
        {
          "url": "https://cybersecuritynews.com/redis-vulnerabilities-enables-rce/",
          "type": "writeup",
          "source": "Cyber Security News",
          "note": "Redis Lua RCE coverage"
        }
      ],
      "x": {
        "mentions": 1,
        "aliases": [],
        "posts": [
          {
            "handle": "akaclandestine",
            "followers": 59775,
            "likes": 44,
            "createdAt": "2026-06-03",
            "url": "https://x.com/akaclandestine/status/2062110258034626815",
            "github": [
              {
                "url": "https://github.com/yoyosh/DarkReplica",
                "hasCode": true
              }
            ],
            "origin": false
          }
        ]
      },
      "researchers": [
        "Yoni Sherez"
      ],
      "aliases": [],
      "bsky": {
        "mentions": 4,
        "posts": [
          {
            "handle": "undercodenews.bsky.social",
            "displayName": "Undercode News",
            "likes": 1,
            "reposts": 1,
            "replies": 0,
            "createdAt": "2026-06-08",
            "url": "https://bsky.app/profile/undercodenews.bsky.social/post/3mnrjrz2fdi2v",
            "origin": false,
            "authority": false,
            "github": []
          },
          {
            "handle": "o2cloud.bsky.social",
            "displayName": "CVE by o2Cloud",
            "likes": 0,
            "reposts": 0,
            "replies": 1,
            "createdAt": "2026-05-06",
            "url": "https://bsky.app/profile/o2cloud.bsky.social/post/3ml6wd7neux2u",
            "origin": false,
            "authority": false,
            "github": []
          },
          {
            "handle": "blackhatnews.tokyo",
            "displayName": "blackhatnews.tokyo",
            "likes": 0,
            "reposts": 0,
            "replies": 0,
            "createdAt": "2026-06-08",
            "url": "https://bsky.app/profile/blackhatnews.tokyo/post/3mnrbfj44kx2n",
            "origin": false,
            "authority": false,
            "github": []
          },
          {
            "handle": "buherator.bsky.social",
            "displayName": "buherator",
            "likes": 0,
            "reposts": 0,
            "replies": 0,
            "createdAt": "2026-06-04",
            "url": "https://bsky.app/profile/buherator.bsky.social/post/3mnhfe24er72u",
            "origin": false,
            "authority": false,
            "github": []
          }
        ]
      }
    },
    {
      "cve": "CVE-2026-2005",
      "title": "Heap buffer overflow in PostgreSQL pgcrypto allows a ciphertext provider to execute…",
      "category": "Recall",
      "vendor": null,
      "exploited": false,
      "publiclyDisclosed": true,
      "cvss": 8.8,
      "cvssVector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "severity": "HIGH",
      "impact": null,
      "products": [],
      "productCount": 0,
      "faq": "Heap buffer overflow in PostgreSQL pgcrypto allows a ciphertext provider to execute arbitrary code as the operating system user running the database.  Versions before PostgreSQL 18.2, 17.8, 16.12, 15.16, and 14.21 are affected.",
      "pocConfidence": "confirmed",
      "pocCount": 1,
      "pocTopStars": 24,
      "pocRepos": [
        {
          "url": "https://github.com/var77/CVE-2026-2005",
          "stars": 24,
          "desc": "PoC for CVE-2026-2005",
          "createdAt": "2026-05-13",
          "hasCode": true
        }
      ],
      "epss": 0.01208,
      "epssPercentile": 0.65002,
      "source": "poc",
      "mitreUrl": "https://nvd.nist.gov/vuln/detail/CVE-2026-2005",
      "research": [
        {
          "url": "https://www.postgresql.org/support/security/CVE-2026-2005/",
          "type": "writeup",
          "source": "PostgreSQL",
          "note": "Official advisory, pgcrypto heap overflow RCE"
        },
        {
          "url": "https://www.zeroday.cloud/blog/postgres-xint",
          "type": "writeup",
          "source": "ZeroDay.cloud",
          "note": "Discoverer writeup, RCE demo at ZeroDay.Cloud"
        },
        {
          "url": "https://github.com/var77/CVE-2026-2005",
          "type": "poc",
          "source": "var77",
          "note": "pgcrypto heap overflow PoC",
          "hasCode": true
        },
        {
          "url": "https://www.rapid7.com/db/vulnerabilities/postgres-cve-2026-2005/",
          "type": "writeup",
          "source": "Rapid7",
          "note": "Vuln DB entry"
        }
      ],
      "x": {
        "mentions": 8,
        "aliases": [],
        "posts": [
          {
            "handle": "D4RK7ET",
            "followers": 268,
            "likes": 140,
            "createdAt": "2026-05-13",
            "url": "https://x.com/D4RK7ET/status/2054597336467206196",
            "github": [
              {
                "url": "https://github.com/var77/CVE-2026-2005",
                "hasCode": true
              }
            ],
            "origin": false
          },
          {
            "handle": "yousukezan",
            "followers": 14098,
            "likes": 44,
            "createdAt": "2026-05-19",
            "url": "https://x.com/yousukezan/status/2056671688432181612",
            "github": [],
            "origin": false
          },
          {
            "handle": "the_yellow_fall",
            "followers": 12178,
            "likes": 7,
            "createdAt": "2026-05-19",
            "url": "https://x.com/the_yellow_fall/status/2056553349588345260",
            "github": [],
            "origin": false
          },
          {
            "handle": "foxbook",
            "followers": 4840,
            "likes": 1,
            "createdAt": "2026-05-20",
            "url": "https://x.com/foxbook/status/2056948114943029739",
            "github": [],
            "origin": false
          },
          {
            "handle": "moton",
            "followers": 659,
            "likes": 1,
            "createdAt": "2026-05-19",
            "url": "https://x.com/moton/status/2056756069763023071",
            "github": [],
            "origin": false
          },
          {
            "handle": "iototsecnews",
            "followers": 491,
            "likes": 1,
            "createdAt": "2026-05-26",
            "url": "https://x.com/iototsecnews/status/2059071346144100701",
            "github": [],
            "origin": false
          },
          {
            "handle": "threatcluster",
            "followers": 285,
            "likes": 0,
            "createdAt": "2026-05-19",
            "url": "https://x.com/threatcluster/status/2056686473756196954",
            "github": [],
            "origin": false
          },
          {
            "handle": "EthicalSafe",
            "followers": 5,
            "likes": 0,
            "createdAt": "2026-05-19",
            "url": "https://x.com/EthicalSafe/status/2056727288540987548",
            "github": [],
            "origin": false
          }
        ]
      },
      "researchers": [
        "Xint Code"
      ],
      "aliases": [],
      "bsky": {
        "mentions": 20,
        "posts": [
          {
            "handle": "te9-dev.bsky.social",
            "displayName": "https://te9.dev",
            "likes": 0,
            "reposts": 0,
            "replies": 0,
            "createdAt": "2026-07-19",
            "url": "https://bsky.app/profile/te9-dev.bsky.social/post/3mqxwowidwi2n",
            "origin": true,
            "authority": false,
            "github": []
          },
          {
            "handle": "darkrat.chaosfurs.social.ap.brid.gy",
            "displayName": "DarkRat",
            "likes": 10,
            "reposts": 18,
            "replies": 0,
            "createdAt": "2026-04-29",
            "url": "https://bsky.app/profile/darkrat.chaosfurs.social.ap.brid.gy/post/3mkntehiybqy2",
            "origin": false,
            "authority": false,
            "github": []
          },
          {
            "handle": "almalinux.org",
            "displayName": "AlmaLinux",
            "likes": 12,
            "reposts": 11,
            "replies": 0,
            "createdAt": "2026-05-01",
            "url": "https://bsky.app/profile/almalinux.org/post/3mkse3swqeq24",
            "origin": false,
            "authority": false,
            "github": []
          },
          {
            "handle": "o2cloud.bsky.social",
            "displayName": "CVE by o2Cloud",
            "likes": 0,
            "reposts": 0,
            "replies": 1,
            "createdAt": "2026-04-23",
            "url": "https://bsky.app/profile/o2cloud.bsky.social/post/3mk675y6xcq2e",
            "origin": false,
            "authority": false,
            "github": []
          },
          {
            "handle": "ferramentaslinux.bsky.social",
            "displayName": null,
            "likes": 0,
            "reposts": 1,
            "replies": 0,
            "createdAt": "2026-03-06",
            "url": "https://bsky.app/profile/ferramentaslinux.bsky.social/post/3mgf64ee7e227",
            "origin": false,
            "authority": false,
            "github": []
          },
          {
            "handle": "securitylab-jp.bsky.social",
            "displayName": "セキュリティ対策Lab",
            "likes": 0,
            "reposts": 1,
            "replies": 0,
            "createdAt": "2026-02-18",
            "url": "https://bsky.app/profile/securitylab-jp.bsky.social/post/3mf675nhsis2h",
            "origin": false,
            "authority": false,
            "github": []
          }
        ]
      }
    },
    {
      "cve": "CVE-2026-21852",
      "title": "Claude Code is an agentic coding tool. Prior to version 2.0.65, vulnerability in…",
      "category": "Recall",
      "vendor": null,
      "exploited": false,
      "publiclyDisclosed": true,
      "cvss": 7.5,
      "cvssVector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
      "severity": "HIGH",
      "impact": null,
      "products": [],
      "productCount": 0,
      "faq": "Claude Code is an agentic coding tool. Prior to version 2.0.65, vulnerability in Claude Code's project-load flow allowed malicious repositories to exfiltrate data including Anthropic API keys before users confirmed trust. An attacker-controlled repository could include a settings file that sets ANTHROPIC_BASE_URL to an attacker-controlled endpoint and when the repository was opened, Claude Code would read the configuration and immediately issue API requests before showing the trust prompt, potentially leaking the user's API keys. Users on standard Claude Code auto-update have received this fix already. Users performing manual updates are advised to update to version 2.0.65, which contains a patch, or to the latest version.",
      "pocConfidence": "confirmed",
      "pocCount": 1,
      "pocTopStars": 23,
      "pocRepos": [
        {
          "url": "https://github.com/atiilla/CVE-2026-21852-PoC",
          "stars": 23,
          "desc": "",
          "createdAt": "2026-02-27",
          "hasCode": true
        },
        {
          "url": "https://github.com/M0broot/CVE-Archive",
          "stars": 0,
          "desc": "Claude Code Vulnerability [CVE-2026-21852]",
          "createdAt": "2026-02-27",
          "hasCode": null
        }
      ],
      "epss": 0.2297,
      "epssPercentile": 0.97501,
      "source": "poc",
      "mitreUrl": "https://nvd.nist.gov/vuln/detail/CVE-2026-21852",
      "research": [],
      "aliases": [],
      "researchers": [],
      "x": {
        "mentions": 0,
        "aliases": [],
        "posts": []
      },
      "bsky": {
        "mentions": 14,
        "posts": [
          {
            "handle": "undercode.bsky.social",
            "displayName": "Undercode Testing",
            "likes": 2,
            "reposts": 1,
            "replies": 1,
            "createdAt": "2026-02-26",
            "url": "https://bsky.app/profile/undercode.bsky.social/post/3mfs27crvye2p",
            "origin": false,
            "authority": false,
            "github": []
          },
          {
            "handle": "astral100.bsky.social",
            "displayName": "Astral",
            "likes": 2,
            "reposts": 0,
            "replies": 1,
            "createdAt": "2026-05-30",
            "url": "https://bsky.app/profile/astral100.bsky.social/post/3mmzuv4kgmh2l",
            "origin": false,
            "authority": false,
            "github": []
          },
          {
            "handle": "hacker.at.thenote.app",
            "displayName": "Hacker & Security News",
            "likes": 3,
            "reposts": 0,
            "replies": 0,
            "createdAt": "2026-03-17",
            "url": "https://bsky.app/profile/hacker.at.thenote.app/post/3mha5pwl6cs23",
            "origin": false,
            "authority": false,
            "github": []
          },
          {
            "handle": "securityrss.bsky.social",
            "displayName": "securityrss.ai",
            "likes": 1,
            "reposts": 1,
            "replies": 0,
            "createdAt": "2026-02-26",
            "url": "https://bsky.app/profile/securityrss.bsky.social/post/3mfqwy4hc662y",
            "origin": false,
            "authority": false,
            "github": []
          },
          {
            "handle": "cyfar.ca",
            "displayName": "boredchilada",
            "likes": 1,
            "reposts": 0,
            "replies": 0,
            "createdAt": "2026-05-26",
            "url": "https://bsky.app/profile/cyfar.ca/post/3mmqz5tyqou26",
            "origin": false,
            "authority": false,
            "github": []
          },
          {
            "handle": "olivier-coreprose.bsky.social",
            "displayName": "Olivier @ CoreProse",
            "likes": 1,
            "reposts": 0,
            "replies": 0,
            "createdAt": "2026-03-08",
            "url": "https://bsky.app/profile/olivier-coreprose.bsky.social/post/3mgjuxa7hr22j",
            "origin": false,
            "authority": false,
            "github": []
          }
        ]
      }
    },
    {
      "cve": "CVE-2026-48909",
      "title": "SP LMS (com_splms) < 4.1.4 by JoomShaper deserializes user-controlled cookie data…",
      "category": "Recall",
      "vendor": null,
      "exploited": false,
      "publiclyDisclosed": true,
      "cvss": null,
      "cvssVector": null,
      "severity": null,
      "impact": null,
      "products": [],
      "productCount": 0,
      "faq": "SP LMS (com_splms) < 4.1.4 by JoomShaper deserializes user-controlled cookie data without validation, enabling an unauthenticated remote attacker to execute arbitrary code on the server.",
      "pocConfidence": "confirmed",
      "pocCount": 1,
      "pocTopStars": 22,
      "pocRepos": [
        {
          "url": "https://github.com/Is4yev/CVE-2026-48909",
          "stars": 22,
          "desc": "CVE-2026-48909 PoC",
          "createdAt": "2026-06-21",
          "hasCode": true
        }
      ],
      "epss": 0.02726,
      "epssPercentile": 0.8445,
      "source": "poc",
      "mitreUrl": "https://nvd.nist.gov/vuln/detail/CVE-2026-48909",
      "research": [],
      "aliases": [],
      "researchers": [],
      "x": {
        "mentions": 0,
        "aliases": [],
        "posts": []
      },
      "bsky": {
        "mentions": 5,
        "posts": [
          {
            "handle": "toxy4ny.bsky.social",
            "displayName": "KL3FT3Z",
            "likes": 5,
            "reposts": 1,
            "replies": 1,
            "createdAt": "2026-06-23",
            "url": "https://bsky.app/profile/toxy4ny.bsky.social/post/3moyeu62nn22k",
            "origin": false,
            "authority": false,
            "github": [
              {
                "url": "https://github.com/Is4yev/CVE-2026-48909",
                "hasCode": true
              }
            ]
          },
          {
            "handle": "offseq.bsky.social",
            "displayName": "OffSequence",
            "likes": 1,
            "reposts": 1,
            "replies": 0,
            "createdAt": "2026-06-21",
            "url": "https://bsky.app/profile/offseq.bsky.social/post/3morex5l44o2t",
            "origin": false,
            "authority": false,
            "github": []
          },
          {
            "handle": "hermes71.bsky.social",
            "displayName": "Some Hermes agent",
            "likes": 1,
            "reposts": 0,
            "replies": 1,
            "createdAt": "2026-06-21",
            "url": "https://bsky.app/profile/hermes71.bsky.social/post/3morluejtd22v",
            "origin": false,
            "authority": false,
            "github": []
          },
          {
            "handle": "cve.skyfleet.blue",
            "displayName": "CVE Alerts ",
            "likes": 1,
            "reposts": 1,
            "replies": 0,
            "createdAt": "2026-06-20",
            "url": "https://bsky.app/profile/cve.skyfleet.blue/post/3mopyrpawac2a",
            "origin": false,
            "authority": false,
            "github": []
          }
        ]
      }
    },
    {
      "cve": "CVE-2026-45250",
      "title": "The setcred(2) system call is only available to privileged users. However, before the…",
      "category": "Recall",
      "vendor": null,
      "exploited": false,
      "publiclyDisclosed": true,
      "cvss": 7.8,
      "cvssVector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "severity": "HIGH",
      "impact": null,
      "products": [],
      "productCount": 0,
      "faq": "The setcred(2) system call is only available to privileged users.  However, before the privilege level of the caller is checked, the user-supplied list of supplementary groups is copied into a fixed-size kernel stack buffer without first validating its length.  If the supplied list exceeds the capacity of that buffer, a stack buffer overflow occurs.\n\nBecause the bounds check on the supplementary groups list occurs after the kernel stack buffer has already been written, an unprivileged local user may trigger the overflow without holding any special privilege.  Successful exploitation may allow an attacker to execute arbitrary code in the context of the kernel, allowing an unprivileged local user to gain elevated privileges on the affected system.",
      "pocConfidence": "confirmed",
      "pocCount": 1,
      "pocTopStars": 22,
      "pocRepos": [
        {
          "url": "https://github.com/venglin/setcred",
          "stars": 22,
          "desc": "CVE-2026-45250 - FreeBSD 14.x LPE",
          "createdAt": "2026-05-21",
          "hasCode": true
        }
      ],
      "epss": 0.00409,
      "epssPercentile": 0.33243,
      "source": "poc",
      "mitreUrl": "https://nvd.nist.gov/vuln/detail/CVE-2026-45250",
      "research": [
        {
          "url": "https://fatgid.io/",
          "type": "writeup",
          "source": "fatgid.io",
          "note": "FatGid FreeBSD 14.x kernel LPE site"
        },
        {
          "url": "https://bsdsec.net/articles/freebsd-security-advisory-freebsd-sa-26-18-setcred",
          "type": "writeup",
          "source": "bsdsec.net",
          "note": "FreeBSD-SA-26:18.setcred advisory"
        },
        {
          "url": "https://hackaday.com/2026/05/29/this-week-in-security-ubiquiti-fixes-and-freebsd-joins-the-club-you-dont-want-to-join/",
          "type": "writeup",
          "source": "Hackaday",
          "note": "setcred stack overflow LPE coverage"
        }
      ],
      "x": {
        "mentions": 2,
        "aliases": [
          "FatGid"
        ],
        "posts": [
          {
            "handle": "ksg93rd",
            "followers": 3290,
            "likes": 0,
            "createdAt": "2026-05-29",
            "url": "https://x.com/ksg93rd/status/2060419657069130201",
            "github": [
              {
                "url": "https://github.com/califio/publications/tree/main/MADBugs/freebsd/setcred-CVE-2026-45250",
                "hasCode": true
              },
              {
                "url": "https://github.com/califio/publications/tree/main/MADBugs/freebsd",
                "hasCode": true
              }
            ],
            "origin": false
          },
          {
            "handle": "the_yellow_fall",
            "followers": 12178,
            "likes": 5,
            "createdAt": "2026-05-27",
            "url": "https://x.com/the_yellow_fall/status/2059494093051564396",
            "github": [],
            "origin": false
          }
        ]
      },
      "aliases": [
        "FatGid"
      ],
      "researchers": [
        "Olivier Certner"
      ],
      "bsky": {
        "mentions": 31,
        "posts": [
          {
            "handle": "campuscodi.risky.biz",
            "displayName": "Catalin Cimpanu",
            "likes": 7,
            "reposts": 1,
            "replies": 0,
            "createdAt": "2026-05-25",
            "url": "https://bsky.app/profile/campuscodi.risky.biz/post/3mmo7zo4vus2p",
            "origin": true,
            "authority": true,
            "github": []
          },
          {
            "handle": "i0null.infosec.exchange.ap.brid.gy",
            "displayName": "Hacker Memes",
            "likes": 7,
            "reposts": 31,
            "replies": 3,
            "createdAt": "2026-05-21",
            "url": "https://bsky.app/profile/i0null.infosec.exchange.ap.brid.gy/post/3mmev35lyd232",
            "origin": true,
            "authority": false,
            "github": []
          },
          {
            "handle": "alexandreborges.bsky.social",
            "displayName": "Alexandre Borges",
            "likes": 1,
            "reposts": 0,
            "replies": 0,
            "createdAt": "2026-05-21",
            "url": "https://bsky.app/profile/alexandreborges.bsky.social/post/3mmeijh7myk2g",
            "origin": true,
            "authority": false,
            "github": []
          },
          {
            "handle": "r-netsec-bot.bsky.social",
            "displayName": "/r/netsec",
            "likes": 0,
            "reposts": 0,
            "replies": 0,
            "createdAt": "2026-05-22",
            "url": "https://bsky.app/profile/r-netsec-bot.bsky.social/post/3mmh6ach4tl2w",
            "origin": true,
            "authority": false,
            "github": []
          },
          {
            "handle": "lobsters-feed.bsky.social",
            "displayName": "The Lobste.rs RSS feed",
            "likes": 0,
            "reposts": 0,
            "replies": 0,
            "createdAt": "2026-05-21",
            "url": "https://bsky.app/profile/lobsters-feed.bsky.social/post/3mmeks7k4vw24",
            "origin": true,
            "authority": false,
            "github": []
          },
          {
            "handle": "infosec.skyfleet.blue",
            "displayName": "InfoSec",
            "likes": 1,
            "reposts": 0,
            "replies": 0,
            "createdAt": "2026-05-22",
            "url": "https://bsky.app/profile/infosec.skyfleet.blue/post/3mmgbklk6bs2j",
            "origin": false,
            "authority": true,
            "github": []
          }
        ]
      }
    },
    {
      "cve": "CVE-2026-34621",
      "title": "Acrobat Reader versions 24.001.30356, 26.001.21367 and earlier are affected by an…",
      "category": "Recall",
      "vendor": null,
      "exploited": true,
      "publiclyDisclosed": true,
      "cvss": 8.6,
      "cvssVector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H",
      "severity": "HIGH",
      "impact": null,
      "products": [],
      "productCount": 0,
      "faq": "Acrobat Reader versions 24.001.30356, 26.001.21367 and earlier are affected by an Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.",
      "pocConfidence": "confirmed",
      "pocCount": 1,
      "pocTopStars": 21,
      "pocRepos": [
        {
          "url": "https://github.com/azefzafyoussef/CVE-2026-34621",
          "stars": 21,
          "desc": "",
          "createdAt": "2026-05-12",
          "hasCode": true
        }
      ],
      "epss": 0.07086,
      "epssPercentile": 0.93525,
      "source": "poc",
      "mitreUrl": "https://nvd.nist.gov/vuln/detail/CVE-2026-34621",
      "research": [
        {
          "url": "https://www.threatlocker.com/blog/adobe-acrobat-reader-cve-2026-34621-active-exploitation-via-prototype-pollution",
          "type": "writeup",
          "source": "ThreatLocker",
          "note": "Prototype-pollution RCE via PDF JS"
        },
        {
          "url": "https://www.helpnetsecurity.com/2026/04/13/adobe-acrobat-reader-cve-2026-34621-emergency-fix/",
          "type": "writeup",
          "source": "Help Net Security",
          "note": "Emergency fix, ITW"
        },
        {
          "url": "https://thehackernews.com/2026/04/adobe-patches-actively-exploited.html",
          "type": "writeup",
          "source": "The Hacker News",
          "note": "Actively exploited"
        },
        {
          "url": "https://www.tenable.com/cve/CVE-2026-34621",
          "type": "detection",
          "source": "Tenable",
          "note": "CVE detail"
        }
      ],
      "x": {
        "mentions": 3,
        "aliases": [],
        "posts": [
          {
            "handle": "DarkWebInformer",
            "followers": 215646,
            "likes": 259,
            "createdAt": "2026-05-15",
            "url": "https://x.com/DarkWebInformer/status/2055422938862452859",
            "github": [
              {
                "url": "https://github.com/azefzafyoussef/CVE-2026-34621",
                "hasCode": true
              }
            ],
            "origin": false
          },
          {
            "handle": "vuln_tracker",
            "followers": 655,
            "likes": 0,
            "createdAt": "2026-05-16",
            "url": "https://x.com/vuln_tracker/status/2055490216400753145",
            "github": [],
            "origin": false
          },
          {
            "handle": "lyrie_ai",
            "followers": 236,
            "likes": 0,
            "createdAt": "2026-05-15",
            "url": "https://x.com/lyrie_ai/status/2055166601498923245",
            "github": [],
            "origin": false
          }
        ]
      },
      "researchers": [
        "Haifei Li"
      ],
      "bsky": {
        "mentions": 31,
        "posts": [
          {
            "handle": "2rzikkbou3ntafnir2qmmse0gwz.activitypub.awakari.com.ap.brid.gy",
            "displayName": "2rZiKKbOU3nTafniR2qMMSE0gwZ",
            "likes": 2,
            "reposts": 0,
            "replies": 0,
            "createdAt": "2026-04-09",
            "url": "https://bsky.app/profile/2rzikkbou3ntafnir2qmmse0gwz.activitypub.awakari.com.ap.brid.gy/post/3mj2gnxw6koe2",
            "origin": true,
            "authority": false,
            "github": []
          },
          {
            "handle": "getpokemon7.bsky.social",
            "displayName": "まりーん",
            "likes": 0,
            "reposts": 0,
            "replies": 1,
            "createdAt": "2026-04-12",
            "url": "https://bsky.app/profile/getpokemon7.bsky.social/post/3mjbwkkrzm22t",
            "origin": true,
            "authority": false,
            "github": []
          },
          {
            "handle": "hacker.at.thenote.app",
            "displayName": "Hacker & Security News",
            "likes": 1,
            "reposts": 0,
            "replies": 0,
            "createdAt": "2026-04-10",
            "url": "https://bsky.app/profile/hacker.at.thenote.app/post/3mj5wxksbbk2q",
            "origin": true,
            "authority": false,
            "github": []
          },
          {
            "handle": "hackmag.com",
            "displayName": "HackMag — Top-notch cybersecurity magazine",
            "likes": 0,
            "reposts": 0,
            "replies": 0,
            "createdAt": "2026-04-13",
            "url": "https://bsky.app/profile/hackmag.com/post/3mjduqyfxfy2f",
            "origin": true,
            "authority": false,
            "github": []
          },
          {
            "handle": "hendryadrian.bsky.social",
            "displayName": "Cybersecurity News Everyday",
            "likes": 0,
            "reposts": 0,
            "replies": 0,
            "createdAt": "2026-04-09",
            "url": "https://bsky.app/profile/hendryadrian.bsky.social/post/3mj2ugvrhnz27",
            "origin": true,
            "authority": false,
            "github": []
          },
          {
            "handle": "infosec.skyfleet.blue",
            "displayName": "InfoSec",
            "likes": 5,
            "reposts": 0,
            "replies": 0,
            "createdAt": "2026-04-12",
            "url": "https://bsky.app/profile/infosec.skyfleet.blue/post/3mjc7oh2scb2t",
            "origin": false,
            "authority": true,
            "github": []
          }
        ]
      },
      "telegram": {
        "mentions": 9,
        "posts": [
          {
            "channel": "thehackernews",
            "channelTitle": "The Hacker News",
            "tier": "news",
            "date": "2026-04-12",
            "views": 13197,
            "forwards": 63,
            "url": "https://t.me/thehackernews/8783",
            "text": "🛑 Adobe released emergency fixes for a 9.6 CVSS flaw (CVE-2026-34621) in Acrobat/Reader, confirmed under active exploitation. A prototype pollution bug lets malicious PDFs run arbitrary code via JavaScript. Evidence shows attacks may date back to Dec 2025. 🔗 Read → https://thehackernews.com/2026/04/adobe-patches-actively-exploited.html",
            "github": [],
            "origin": false
          }
        ]
      },
      "aliases": []
    },
    {
      "cve": "CVE-2026-27771",
      "title": "CVE-2026-27771 - Gitea/Forgejo Container Registry Auth Bypass Exploit PoC - Pull private container images without authentication",
      "category": "Recall",
      "vendor": null,
      "exploited": false,
      "publiclyDisclosed": true,
      "cvss": null,
      "cvssVector": null,
      "severity": null,
      "impact": null,
      "products": [],
      "productCount": 0,
      "faq": null,
      "pocConfidence": "confirmed",
      "pocCount": 1,
      "pocTopStars": 15,
      "pocRepos": [
        {
          "url": "https://github.com/portbuster1337/CVE-2026-27771",
          "stars": 15,
          "desc": "CVE-2026-27771 - Gitea/Forgejo Container Registry Auth Bypass Exploit PoC - Pull private container images without authentication",
          "createdAt": "2026-05-27",
          "hasCode": true
        }
      ],
      "epss": 0.40738,
      "epssPercentile": 0.98504,
      "source": "poc",
      "mitreUrl": "https://nvd.nist.gov/vuln/detail/CVE-2026-27771",
      "research": [
        {
          "url": "https://horizon3.ai/attack-research/vulnerabilities/cve-2026-27771/",
          "type": "writeup",
          "source": "Horizon3.ai",
          "note": "Gitea registry auth bypass research"
        },
        {
          "url": "https://orca.security/resources/blog/gitea-container-registry-vulnerability/",
          "type": "writeup",
          "source": "Orca Security",
          "note": "Private images exposed to unauth attackers"
        },
        {
          "url": "https://www.noscope.com/blog/gitea-instances-exposing-private-container",
          "type": "writeup",
          "source": "NoScope",
          "note": "Discoverer writeup, private container exposure"
        },
        {
          "url": "https://www.securityweek.com/gitea-vulnerability-exposed-30000-deployments-to-attacks/",
          "type": "writeup",
          "source": "SecurityWeek",
          "note": "30,000 deployments exposed"
        }
      ],
      "x": {
        "mentions": 1,
        "aliases": [],
        "posts": [
          {
            "handle": "AndreGironda",
            "followers": 3783,
            "likes": 3,
            "createdAt": "2026-05-28",
            "url": "https://x.com/AndreGironda/status/2059980894388232505",
            "github": [
              {
                "url": "https://github.com/portbuster1337/CVE-2026-27771",
                "hasCode": true
              }
            ],
            "origin": false
          }
        ]
      },
      "researchers": [
        "NoScope"
      ],
      "aliases": [],
      "bsky": {
        "mentions": 13,
        "posts": [
          {
            "handle": "lalgorisme.bsky.social",
            "displayName": "L'algorisme",
            "likes": 1,
            "reposts": 1,
            "replies": 1,
            "createdAt": "2026-05-28",
            "url": "https://bsky.app/profile/lalgorisme.bsky.social/post/3mmvfhmokq32k",
            "origin": false,
            "authority": false,
            "github": []
          },
          {
            "handle": "thehackerwire.bsky.social",
            "displayName": "TheHackerWire",
            "likes": 1,
            "reposts": 0,
            "replies": 1,
            "createdAt": "2026-07-05",
            "url": "https://bsky.app/profile/thehackerwire.bsky.social/post/3mpw5rjnwws2t",
            "origin": false,
            "authority": false,
            "github": []
          },
          {
            "handle": "blackhatnews.tokyo",
            "displayName": "blackhatnews.tokyo",
            "likes": 1,
            "reposts": 1,
            "replies": 0,
            "createdAt": "2026-05-28",
            "url": "https://bsky.app/profile/blackhatnews.tokyo/post/3mmvqnhrkuj27",
            "origin": false,
            "authority": false,
            "github": []
          },
          {
            "handle": "mathieu.fenniak.net",
            "displayName": "Mathieu Fenniak",
            "likes": 1,
            "reposts": 0,
            "replies": 0,
            "createdAt": "2026-06-10",
            "url": "https://bsky.app/profile/mathieu.fenniak.net/post/3mnwroj6kos2s",
            "origin": false,
            "authority": false,
            "github": []
          },
          {
            "handle": "yoota.it",
            "displayName": null,
            "likes": 0,
            "reposts": 0,
            "replies": 1,
            "createdAt": "2026-06-10",
            "url": "https://bsky.app/profile/yoota.it/post/3mnwb3aunp42p",
            "origin": false,
            "authority": false,
            "github": []
          },
          {
            "handle": "postac001.bsky.social",
            "displayName": "tec_acc",
            "likes": 0,
            "reposts": 1,
            "replies": 0,
            "createdAt": "2026-05-27",
            "url": "https://bsky.app/profile/postac001.bsky.social/post/3mmticw7cvf2a",
            "origin": false,
            "authority": false,
            "github": []
          }
        ]
      }
    },
    {
      "cve": "CVE-2026-32710",
      "title": "MariaDB server is a community developed fork of MySQL server. An authenticated user…",
      "category": "Recall",
      "vendor": null,
      "exploited": false,
      "publiclyDisclosed": true,
      "cvss": 8.5,
      "cvssVector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H",
      "severity": "HIGH",
      "impact": null,
      "products": [],
      "productCount": 0,
      "faq": "MariaDB server is a community developed fork of MySQL server. An authenticated user can crash MariaDB versions 11.4 before 11.4.10 and 11.8 before 11.8.6 via a bug in JSON_SCHEMA_VALID() function. Under certain conditions it might be possible to turn the crash into a remote code execution. These conditions require tight control over memory layout which is generally only attainable in a lab environment. This issue is fixed in MariaDB 11.4.10, MariaDB 11.8.6, and MariaDB 12.2.2.",
      "pocConfidence": "confirmed",
      "pocCount": 1,
      "pocTopStars": 14,
      "pocRepos": [
        {
          "url": "https://github.com/dinosn/CVE-2026-32710",
          "stars": 14,
          "desc": "Heap OOB write in MariaDB JSON_SCHEMA_VALID() → persistent privilege escalation (lab-assisted)",
          "createdAt": "2026-05-06",
          "hasCode": true
        }
      ],
      "epss": 0.00856,
      "epssPercentile": 0.54395,
      "source": "poc",
      "mitreUrl": "https://nvd.nist.gov/vuln/detail/CVE-2026-32710",
      "research": [
        {
          "url": "https://www.zeroday.cloud/blog/mariadb-cve-2026-32710-deep-dive",
          "type": "writeup",
          "source": "ZeroDay.cloud",
          "note": "JSON_SCHEMA_VALID heap overflow to RCE deep dive"
        },
        {
          "url": "https://www.thehackerwire.com/mariadb-json_schema_valid-crash-potential-rce-cve-2026-32710/",
          "type": "writeup",
          "source": "TheHackerWire",
          "note": "JSON_SCHEMA_VALID crash + potential RCE"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-32710",
          "type": "writeup",
          "source": "NVD",
          "note": "Official CVE detail"
        }
      ],
      "x": {
        "mentions": 1,
        "aliases": [],
        "posts": [
          {
            "handle": "fad_777",
            "followers": 68,
            "likes": 0,
            "createdAt": "2026-05-08",
            "url": "https://x.com/fad_777/status/2052715580143112237",
            "github": [
              {
                "url": "https://github.com/dinosn/CVE-2026-32710",
                "hasCode": true
              }
            ],
            "origin": false
          }
        ]
      },
      "researchers": [
        "Xint Code"
      ],
      "aliases": [],
      "bsky": {
        "mentions": 7,
        "posts": [
          {
            "handle": "te9-dev.bsky.social",
            "displayName": "https://te9.dev",
            "likes": 0,
            "reposts": 0,
            "replies": 0,
            "createdAt": "2026-07-19",
            "url": "https://bsky.app/profile/te9-dev.bsky.social/post/3mqxwowidwi2n",
            "origin": true,
            "authority": false,
            "github": []
          },
          {
            "handle": "darkrat.chaosfurs.social.ap.brid.gy",
            "displayName": "DarkRat",
            "likes": 10,
            "reposts": 18,
            "replies": 0,
            "createdAt": "2026-04-29",
            "url": "https://bsky.app/profile/darkrat.chaosfurs.social.ap.brid.gy/post/3mkntehiybqy2",
            "origin": false,
            "authority": false,
            "github": []
          },
          {
            "handle": "almalinux.org",
            "displayName": "AlmaLinux",
            "likes": 12,
            "reposts": 11,
            "replies": 0,
            "createdAt": "2026-05-01",
            "url": "https://bsky.app/profile/almalinux.org/post/3mkse3swqeq24",
            "origin": false,
            "authority": false,
            "github": []
          },
          {
            "handle": "thehackerwire.bsky.social",
            "displayName": "TheHackerWire",
            "likes": 1,
            "reposts": 0,
            "replies": 0,
            "createdAt": "2026-03-20",
            "url": "https://bsky.app/profile/thehackerwire.bsky.social/post/3mhjdpvfhp62c",
            "origin": false,
            "authority": false,
            "github": []
          },
          {
            "handle": "cyberhub.blog",
            "displayName": "CyberHub",
            "likes": 0,
            "reposts": 0,
            "replies": 0,
            "createdAt": "2026-04-01",
            "url": "https://bsky.app/profile/cyberhub.blog/post/3mifhdpoonh2r",
            "origin": false,
            "authority": false,
            "github": []
          },
          {
            "handle": "securitylab-jp.bsky.social",
            "displayName": "セキュリティ対策Lab",
            "likes": 0,
            "reposts": 0,
            "replies": 0,
            "createdAt": "2026-03-27",
            "url": "https://bsky.app/profile/securitylab-jp.bsky.social/post/3mhyvu265oc2l",
            "origin": false,
            "authority": false,
            "github": []
          }
        ]
      }
    },
    {
      "cve": "CVE-2026-40003",
      "title": "ZTE ZX297520V3 BootROM contains a vulnerability that allows arbitrary memory writes…",
      "category": "Recall",
      "vendor": null,
      "exploited": false,
      "publiclyDisclosed": true,
      "cvss": 5.1,
      "cvssVector": "CVSS:3.1/AV:P/AC:H/PR:N/UI:R/S:U/C:L/I:H/A:L",
      "severity": "MEDIUM",
      "impact": null,
      "products": [],
      "productCount": 0,
      "faq": "ZTE ZX297520V3 BootROM contains a vulnerability that allows arbitrary memory writes via USB. Attackers can exploit the lack of target address validation in the USB download mode to write data to any location in BootROM runtime memory, thereby overwriting the stack, hijacking the execution flow, bypassing the Secure Boot signature verification mechanism, and achieving unauthorized code execution.",
      "pocConfidence": "confirmed",
      "pocCount": 1,
      "pocTopStars": 14,
      "pocRepos": [
        {
          "url": "https://github.com/rva3/CVE-2026-40003",
          "stars": 14,
          "desc": "ZXIC/Sanechips BootROM exploit",
          "createdAt": "2026-05-07",
          "hasCode": true
        }
      ],
      "epss": 0.00296,
      "epssPercentile": 0.21642,
      "source": "poc",
      "mitreUrl": "https://nvd.nist.gov/vuln/detail/CVE-2026-40003",
      "research": [
        {
          "url": "https://vulnerability.circl.lu/vuln/cve-2026-40003",
          "type": "writeup",
          "source": "CIRCL",
          "note": "ZTE ZX297520V3 BootROM arbitrary write via USB"
        }
      ],
      "x": {
        "mentions": 4,
        "posts": [
          {
            "handle": "infoflowcloud",
            "followers": 79,
            "likes": 0,
            "createdAt": "2026-05-07",
            "url": "https://x.com/infoflowcloud/status/2052402145668862023",
            "origin": false,
            "github": []
          },
          {
            "handle": "CVEnew",
            "followers": 57565,
            "likes": 0,
            "createdAt": "2026-05-07",
            "url": "https://x.com/CVEnew/status/2052400859854815713",
            "origin": false,
            "github": []
          },
          {
            "handle": "CVEarity",
            "followers": 160,
            "likes": 0,
            "createdAt": "2026-05-07",
            "url": "https://x.com/CVEarity/status/2052340380100907399",
            "origin": false,
            "github": []
          },
          {
            "handle": "VulmonFeeds",
            "followers": 4043,
            "likes": 0,
            "createdAt": "2026-05-07",
            "url": "https://x.com/VulmonFeeds/status/2052222962976076091",
            "origin": false,
            "github": []
          }
        ],
        "aliases": []
      },
      "aliases": [],
      "researchers": [],
      "bsky": {
        "mentions": 0,
        "posts": []
      }
    },
    {
      "cve": "CVE-2026-46242",
      "title": "In the Linux kernel, the following vulnerability has been resolved: eventpoll: fix…",
      "category": "Recall",
      "vendor": null,
      "exploited": false,
      "publiclyDisclosed": true,
      "cvss": 7.8,
      "cvssVector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "severity": "HIGH",
      "impact": null,
      "products": [],
      "productCount": 0,
      "faq": "In the Linux kernel, the following vulnerability has been resolved:\n\neventpoll: fix ep_remove struct eventpoll / struct file UAF\n\nep_remove() (via ep_remove_file()) cleared file->f_ep under\nfile->f_lock but then kept using @file inside the critical section\n(is_file_epoll(), hlist_del_rcu() through the head, spin_unlock).\nA concurrent __fput() taking the eventpoll_release() fastpath in\nthat window observed the transient NULL, skipped\neventpoll_release_file() and ran to f_op->release / file_free().\n\nFor the epoll-watches-epoll case, f_op->release is\nep_eventpoll_release() -> ep_clear_and_put() -> ep_free(), which\nkfree()s the watched struct eventpoll. Its embedded ->refs\nhlist_head is exactly where epi->fllink.pprev points, so the\nsubsequent hlist_del_rcu()'s \"*pprev = next\" scribbles into freed\nkmalloc-192 memory.\n\nIn addition, struct file is SLAB_TYPESAFE_BY_RCU, so the slot\nbacking @file could be recycled by alloc_empty_file() --\nreinitializing f_lock and f_ep -- while ep_remove() is still\nnominally inside that lock. The upshot is an attacker-controllable\nkmem_cache_free() against the wrong slab cache.\n\nPin @file via epi_fget() at the top of ep_remove() and gate the\ncritical section on the pin succeeding. With the pin held @file\ncannot reach refcount zero, which holds __fput() off and\ntransitively keeps the watched struct eventpoll alive across the\nhlist_del_rcu() and the f_lock use, closing both UAFs.\n\nIf the pin fails @file has already reached refcount zero and its\n__fput() is in flight. Because we bailed before clearing f_ep,\nthat path takes the eventpoll_release() slow path into\neventpoll_release_file() and blocks on ep->mtx until the waiter\nside's ep_clear_and_put() drops it. The bailed epi's share of\nep->refcount stays intact, so the trailing ep_refcount_dec_and_test()\nin ep_clear_and_put() cannot free the eventpoll out from under\neventpoll_release_file(); the orphaned epi is then cleaned up\nthere.\n\nA successful pin also proves we are not racing\neventpoll_release_file() on this epi, so drop the now-redundant\nre-check of epi->dying under f_lock. The cheap lockless\nREAD_ONCE(epi->dying) fast-path bailout stays.",
      "pocConfidence": "confirmed",
      "pocCount": 1,
      "pocTopStars": 11,
      "pocRepos": [
        {
          "url": "https://github.com/0xBlackash/CVE-2026-46242",
          "stars": 11,
          "desc": "CVE-2026-46242",
          "createdAt": "2026-07-04",
          "hasCode": true
        }
      ],
      "epss": 0.00125,
      "epssPercentile": 0.02588,
      "source": "poc",
      "mitreUrl": "https://nvd.nist.gov/vuln/detail/CVE-2026-46242",
      "research": [],
      "aliases": [],
      "researchers": [],
      "x": {
        "mentions": 36,
        "aliases": [],
        "posts": [
          {
            "handle": "ptdbugs",
            "followers": 2267,
            "likes": 77,
            "createdAt": "2026-07-06",
            "url": "https://x.com/ptdbugs/status/2074036940857340391",
            "github": [],
            "origin": false
          },
          {
            "handle": "ita_blog",
            "followers": 2788,
            "likes": 1,
            "createdAt": "2026-07-07",
            "url": "https://x.com/ita_blog/status/2074398580907913220",
            "github": [],
            "origin": false
          },
          {
            "handle": "EvanKirstel",
            "followers": 379242,
            "likes": 0,
            "createdAt": "2026-07-06",
            "url": "https://x.com/EvanKirstel/status/2074206752732541264",
            "github": [],
            "origin": false
          },
          {
            "handle": "connect24h",
            "followers": 4222,
            "likes": 0,
            "createdAt": "2026-07-07",
            "url": "https://x.com/connect24h/status/2074330646240166370",
            "github": [],
            "origin": false
          },
          {
            "handle": "herodevs",
            "followers": 2673,
            "likes": 0,
            "createdAt": "2026-07-06",
            "url": "https://x.com/herodevs/status/2074208487626915937",
            "github": [],
            "origin": false
          },
          {
            "handle": "HardwareBusters",
            "followers": 957,
            "likes": 0,
            "createdAt": "2026-07-07",
            "url": "https://x.com/HardwareBusters/status/2074389899977912601",
            "github": [],
            "origin": false
          },
          {
            "handle": "Qpsk1234",
            "followers": 689,
            "likes": 0,
            "createdAt": "2026-07-06",
            "url": "https://x.com/Qpsk1234/status/2074095898569884090",
            "github": [],
            "origin": false
          },
          {
            "handle": "XavierRiveraX",
            "followers": 577,
            "likes": 0,
            "createdAt": "2026-07-06",
            "url": "https://x.com/XavierRiveraX/status/2074135041139994754",
            "github": [],
            "origin": false
          }
        ]
      },
      "bsky": {
        "mentions": 15,
        "posts": [
          {
            "handle": "infosec.skyfleet.blue",
            "displayName": "InfoSec",
            "likes": 1,
            "reposts": 0,
            "replies": 0,
            "createdAt": "2026-07-08",
            "url": "https://bsky.app/profile/infosec.skyfleet.blue/post/3mq6bli65is2h",
            "origin": false,
            "authority": true,
            "github": []
          },
          {
            "handle": "jschauma.mstdn.social.ap.brid.gy",
            "displayName": "Jan Schaumann",
            "likes": 0,
            "reposts": 4,
            "replies": 1,
            "createdAt": "2026-07-08",
            "url": "https://bsky.app/profile/jschauma.mstdn.social.ap.brid.gy/post/3mq5ym2fuptm2",
            "origin": false,
            "authority": false,
            "github": [
              {
                "url": "https://github.com/J-jaeyoung/bad-epoll",
                "hasCode": false
              }
            ]
          },
          {
            "handle": "securityonline.bsky.social",
            "displayName": "Daily CyberSecurity",
            "likes": 0,
            "reposts": 0,
            "replies": 0,
            "createdAt": "2026-07-14",
            "url": "https://bsky.app/profile/securityonline.bsky.social/post/3mqmf2plwqc2d",
            "origin": false,
            "authority": false,
            "github": [
              {
                "url": "https://github.com/J-jaeyoung/bad-epoll",
                "hasCode": false
              }
            ]
          },
          {
            "handle": "kravietz.agora.echelon.pl.ap.brid.gy",
            "displayName": "kravietz 🦇",
            "likes": 1,
            "reposts": 5,
            "replies": 0,
            "createdAt": "2026-07-06",
            "url": "https://bsky.app/profile/kravietz.agora.echelon.pl.ap.brid.gy/post/3mpxw7yhteet2",
            "origin": false,
            "authority": false,
            "github": []
          },
          {
            "handle": "almalinux.org",
            "displayName": "AlmaLinux",
            "likes": 3,
            "reposts": 1,
            "replies": 0,
            "createdAt": "2026-07-07",
            "url": "https://bsky.app/profile/almalinux.org/post/3mpzg5g3tgy2a",
            "origin": false,
            "authority": false,
            "github": []
          },
          {
            "handle": "de-nachrichten.bsky.social",
            "displayName": "Nachrichten",
            "likes": 2,
            "reposts": 0,
            "replies": 0,
            "createdAt": "2026-07-07",
            "url": "https://bsky.app/profile/de-nachrichten.bsky.social/post/3mq2clqlwhl22",
            "origin": false,
            "authority": false,
            "github": []
          }
        ]
      }
    },
    {
      "cve": "CVE-2026-0091",
      "title": "In multiple locations, there is a possible way to execute code in the launcher…",
      "category": "Recall",
      "vendor": null,
      "exploited": false,
      "publiclyDisclosed": true,
      "cvss": 7.8,
      "cvssVector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "severity": "HIGH",
      "impact": null,
      "products": [],
      "productCount": 0,
      "faq": "In multiple locations, there is a possible way to execute code in the launcher process due to an over-privileged shell user. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.",
      "pocConfidence": "confirmed",
      "pocCount": 1,
      "pocTopStars": 10,
      "pocRepos": [
        {
          "url": "https://github.com/canyie/TransitionPlayer",
          "stars": 10,
          "desc": "CVE-2026-0091, play with an issue in android window management to perform arbitrary code execution in Launcher process from adb",
          "createdAt": "2026-05-25",
          "hasCode": true
        }
      ],
      "epss": 0.00067,
      "epssPercentile": 0.00035,
      "source": "poc",
      "mitreUrl": "https://nvd.nist.gov/vuln/detail/CVE-2026-0091",
      "research": [],
      "aliases": [],
      "researchers": [],
      "x": {
        "mentions": 0,
        "aliases": [],
        "posts": []
      },
      "bsky": {
        "mentions": 0,
        "posts": []
      }
    },
    {
      "cve": "CVE-2026-46529",
      "title": "Atril Document Viewer is the default document reader of the MATE desktop environment…",
      "category": "Recall",
      "vendor": null,
      "exploited": false,
      "publiclyDisclosed": true,
      "cvss": null,
      "cvssVector": null,
      "severity": null,
      "impact": null,
      "products": [],
      "productCount": 0,
      "faq": "Atril Document Viewer is the default document reader of the MATE desktop environment for Linux. A single-click remote code execution vulnerability in versions prior to 1.26.3 and 1.28.4 allows an attacker to achieve arbitrary code execution as the user by tricking them into clicking a link inside a malicious PDF document. The PDF can be packaged as a polyglot file that is simultaneously a valid PDF and a valid ELF shared library, making the attack a single-file, single-click, configuration-independent RCE on stock atril installations. The root cause is `shell/ev-application.c:ev_spawn`, which builds a command line from attacker-controlled PDF link-destination fields without applying `g_shell_quote`. The cmdline is then handed to `g_app_info_create_from_commandline`, which shell-parses it back into argv — splitting any embedded `--gtk-module=PATH` into a separate argv element. GTK then `dlopen()`s the path during init, running any `__attribute__((constructor))` it finds. Versions 1.26.3 and 1.28.4 contain a patch for the issue. This is the same defect class as CVE-2023-51698 (CBT `--checkpoint-action` injection in `comics-document.c`, fixed in 1.6.2) but in a different code path (`shell/ev-application.c`) that the original patch did not touch.",
      "pocConfidence": "confirmed",
      "pocCount": 1,
      "pocTopStars": 10,
      "pocRepos": [
        {
          "url": "https://github.com/N1et/CVE-2026-46529",
          "stars": 10,
          "desc": "Evince/xreader/Atril RCE exploit to CVE-2026-46529",
          "createdAt": "2026-05-16",
          "hasCode": true
        }
      ],
      "epss": 0.00529,
      "epssPercentile": 0.41277,
      "source": "poc",
      "mitreUrl": "https://nvd.nist.gov/vuln/detail/CVE-2026-46529",
      "research": [
        {
          "url": "https://blogs.gnome.org/mcatanzaro/2026/05/21/single-click-code-execution-exploit-for-evince-atril-and-xreader/",
          "type": "writeup",
          "source": "Michael Catanzaro/GNOME",
          "note": "Single-click code exec via PDF /GoToR argv inject"
        },
        {
          "url": "https://ubuntu.com/security/CVE-2026-46529",
          "type": "writeup",
          "source": "Ubuntu",
          "note": "Vendor advisory, ev_spawn shell quoting flaw"
        }
      ],
      "x": {
        "mentions": 3,
        "aliases": [],
        "posts": [
          {
            "handle": "luckyhacker43",
            "followers": 138,
            "likes": 19,
            "createdAt": "2026-06-05",
            "url": "https://x.com/luckyhacker43/status/2062830031521370464",
            "github": [
              {
                "url": "https://github.com/mate-desktop/atril/security/advisories/GHSA-vgv2-m826-8f6f",
                "hasCode": true
              },
              {
                "url": "https://github.com/N1et/CVE-2026-46529",
                "hasCode": true
              }
            ],
            "origin": false
          },
          {
            "handle": "N45HTOfficial",
            "followers": 93,
            "likes": 0,
            "createdAt": "2026-05-29",
            "url": "https://x.com/N45HTOfficial/status/2060264343426711887",
            "github": [
              {
                "url": "https://github.com/mate-desktop/atril/security/advisories/GHSA-vgv2-m826-8f6f",
                "hasCode": true
              },
              {
                "url": "https://github.com/N1et/CVE-2026-46529",
                "hasCode": true
              }
            ],
            "origin": false
          },
          {
            "handle": "__kokumoto",
            "followers": 7498,
            "likes": 3,
            "createdAt": "2026-05-28",
            "url": "https://x.com/__kokumoto/status/2059839906713915635",
            "github": [],
            "origin": false
          }
        ]
      },
      "researchers": [
        "João Medeiros"
      ],
      "aliases": [],
      "bsky": {
        "mentions": 8,
        "posts": [
          {
            "handle": "infosec.skyfleet.blue",
            "displayName": "InfoSec",
            "likes": 0,
            "reposts": 0,
            "replies": 0,
            "createdAt": "2026-05-21",
            "url": "https://bsky.app/profile/infosec.skyfleet.blue/post/3mmevpk2prw2g",
            "origin": false,
            "authority": true,
            "github": []
          },
          {
            "handle": "wdormann.infosec.exchange.ap.brid.gy",
            "displayName": "Will Dormann",
            "likes": 2,
            "reposts": 0,
            "replies": 0,
            "createdAt": "2026-05-23",
            "url": "https://bsky.app/profile/wdormann.infosec.exchange.ap.brid.gy/post/3mmkepycm3fd2",
            "origin": false,
            "authority": false,
            "github": [
              {
                "url": "https://github.com/N1et/CVE-2026-46529",
                "hasCode": true
              }
            ]
          },
          {
            "handle": "ferramentaslinux.bsky.social",
            "displayName": null,
            "likes": 0,
            "reposts": 0,
            "replies": 1,
            "createdAt": "2026-06-04",
            "url": "https://bsky.app/profile/ferramentaslinux.bsky.social/post/3mnijpysvqc2y",
            "origin": false,
            "authority": false,
            "github": []
          },
          {
            "handle": "cve.skyfleet.blue",
            "displayName": "CVE Alerts ",
            "likes": 0,
            "reposts": 0,
            "replies": 0,
            "createdAt": "2026-06-11",
            "url": "https://bsky.app/profile/cve.skyfleet.blue/post/3mnxxpa5vn52n",
            "origin": false,
            "authority": false,
            "github": []
          },
          {
            "handle": "news.karthihegde.dev",
            "displayName": "Cartero",
            "likes": 0,
            "reposts": 0,
            "replies": 0,
            "createdAt": "2026-05-22",
            "url": "https://bsky.app/profile/news.karthihegde.dev/post/3mmhxksbk7j2w",
            "origin": false,
            "authority": false,
            "github": []
          },
          {
            "handle": "lobsters-feed.bsky.social",
            "displayName": "The Lobste.rs RSS feed",
            "likes": 0,
            "reposts": 0,
            "replies": 0,
            "createdAt": "2026-05-22",
            "url": "https://bsky.app/profile/lobsters-feed.bsky.social/post/3mmhxr4xxgz2q",
            "origin": false,
            "authority": false,
            "github": []
          }
        ]
      }
    },
    {
      "cve": "CVE-2026-20980",
      "title": "Improper input validation in PACM prior to SMR Feb-2026 Release 1 allows physical…",
      "category": "Recall",
      "vendor": null,
      "exploited": false,
      "publiclyDisclosed": true,
      "cvss": 6.8,
      "cvssVector": "CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "severity": "MEDIUM",
      "impact": null,
      "products": [],
      "productCount": 0,
      "faq": "Improper input validation in PACM prior to SMR Feb-2026 Release 1 allows physical attacker to execute arbitrary commands.",
      "pocConfidence": "confirmed",
      "pocCount": 1,
      "pocTopStars": 9,
      "pocRepos": [
        {
          "url": "https://github.com/Vikramaditya015/samsung-android-lpe",
          "stars": 9,
          "desc": "Poc for CVE-2026-20980, CVE-2026-20981, CVE-2026-20982",
          "createdAt": "2026-06-01",
          "hasCode": true
        }
      ],
      "epss": 0.00227,
      "epssPercentile": 0.13497,
      "source": "poc",
      "mitreUrl": "https://nvd.nist.gov/vuln/detail/CVE-2026-20980",
      "research": [],
      "x": {
        "mentions": 3,
        "posts": [
          {
            "handle": "MarianaLop87830",
            "followers": 0,
            "likes": 0,
            "createdAt": "2026-04-22",
            "url": "https://x.com/MarianaLop87830/status/2047044815871729915",
            "origin": false,
            "github": []
          },
          {
            "handle": "VulmonFeeds",
            "followers": 4043,
            "likes": 0,
            "createdAt": "2026-02-04",
            "url": "https://x.com/VulmonFeeds/status/2018980893960950064",
            "origin": false,
            "github": []
          },
          {
            "handle": "CVEnew",
            "followers": 57565,
            "likes": 0,
            "createdAt": "2026-02-04",
            "url": "https://x.com/CVEnew/status/2018956882661011606",
            "origin": false,
            "github": []
          }
        ],
        "aliases": []
      },
      "aliases": [],
      "researchers": [],
      "bsky": {
        "mentions": 0,
        "posts": []
      }
    },
    {
      "cve": "CVE-2026-23869",
      "title": "A denial of service vulnerability exists in React Server Components, affecting the…",
      "category": "Recall",
      "vendor": null,
      "exploited": false,
      "publiclyDisclosed": true,
      "cvss": 7.5,
      "cvssVector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
      "severity": "HIGH",
      "impact": null,
      "products": [],
      "productCount": 0,
      "faq": "A denial of service vulnerability exists in React Server Components, affecting the following packages: react-server-dom-parcel, react-server-dom-turbopack and react-server-dom-webpack (versions 19.0.0 through 19.0.4, 19.1.0 through 19.1.5, and 19.2.0 through 19.2.4). The vulnerability is triggered by sending specially crafted HTTP requests to Server Function endpoints.The payload of the HTTP request causes excessive CPU usage for up to a minute ending in a thrown error that is catchable.",
      "pocConfidence": "confirmed",
      "pocCount": 1,
      "pocTopStars": 8,
      "pocRepos": [
        {
          "url": "https://github.com/cybertechajju/CVE-2026-23869-Exploit",
          "stars": 8,
          "desc": "",
          "createdAt": "2026-04-11",
          "hasCode": true
        },
        {
          "url": "https://github.com/shaheryar773/mitigate-cve-2026-23869-react-server-component-loops",
          "stars": 0,
          "desc": "Technical troubleshooting repository for fixing infinite rendering vulnerability loops and resource exhaustion threats under CVE-2026-23869 cleanly.",
          "createdAt": "2026-07-04",
          "hasCode": false
        }
      ],
      "epss": 0.01551,
      "epssPercentile": 0.72388,
      "source": "poc",
      "mitreUrl": "https://nvd.nist.gov/vuln/detail/CVE-2026-23869",
      "research": [],
      "aliases": [],
      "researchers": [],
      "x": {
        "mentions": 0,
        "aliases": [],
        "posts": []
      },
      "bsky": {
        "mentions": 9,
        "posts": [
          {
            "handle": "tech-trending.bsky.social",
            "displayName": "Tech Trending",
            "likes": 2,
            "reposts": 0,
            "replies": 0,
            "createdAt": "2026-04-10",
            "url": "https://bsky.app/profile/tech-trending.bsky.social/post/3mj5e6q53ss2y",
            "origin": false,
            "authority": false,
            "github": []
          },
          {
            "handle": "azu.bsky.social",
            "displayName": "azu",
            "likes": 1,
            "reposts": 0,
            "replies": 0,
            "createdAt": "2026-04-09",
            "url": "https://bsky.app/profile/azu.bsky.social/post/3mj3z5tefhm2q",
            "origin": false,
            "authority": false,
            "github": []
          },
          {
            "handle": "opsmatters.com",
            "displayName": "OpsMatters",
            "likes": 0,
            "reposts": 0,
            "replies": 0,
            "createdAt": "2026-04-21",
            "url": "https://bsky.app/profile/opsmatters.com/post/3mjxw2memdo2x",
            "origin": false,
            "authority": false,
            "github": []
          },
          {
            "handle": "securitylab-jp.bsky.social",
            "displayName": "セキュリティ対策Lab",
            "likes": 0,
            "reposts": 0,
            "replies": 0,
            "createdAt": "2026-04-15",
            "url": "https://bsky.app/profile/securitylab-jp.bsky.social/post/3mjj2hhgqgc2e",
            "origin": false,
            "authority": false,
            "github": []
          },
          {
            "handle": "hacker.at.thenote.app",
            "displayName": "Hacker & Security News",
            "likes": 0,
            "reposts": 0,
            "replies": 0,
            "createdAt": "2026-04-10",
            "url": "https://bsky.app/profile/hacker.at.thenote.app/post/3mj5ecnzrok2q",
            "origin": false,
            "authority": false,
            "github": []
          },
          {
            "handle": "undercode.bsky.social",
            "displayName": "Undercode Testing",
            "likes": 0,
            "reposts": 0,
            "replies": 0,
            "createdAt": "2026-04-10",
            "url": "https://bsky.app/profile/undercode.bsky.social/post/3mj5wghlkmr2s",
            "origin": false,
            "authority": false,
            "github": []
          }
        ]
      }
    },
    {
      "cve": "CVE-2026-20700",
      "title": "A memory corruption issue was addressed with improved state management. This issue is…",
      "category": "Recall",
      "vendor": null,
      "exploited": true,
      "publiclyDisclosed": true,
      "cvss": 7.8,
      "cvssVector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "severity": "HIGH",
      "impact": null,
      "products": [],
      "productCount": 0,
      "faq": "A memory corruption issue was addressed with improved state management. This issue is fixed in iOS 26.3 and iPadOS 26.3, macOS Tahoe 26.3, tvOS 26.3, visionOS 26.3, watchOS 26.3. An attacker with memory write capability may be able to execute arbitrary code. Apple is aware of a report that this issue may have been exploited in an extremely sophisticated attack against specific targeted individuals on versions of iOS before iOS 26. CVE-2025-14174 and CVE-2025-43529 were also issued in response to this report.",
      "pocConfidence": "confirmed",
      "pocCount": 1,
      "pocTopStars": 8,
      "pocRepos": [
        {
          "url": "https://github.com/R3n3r0/CVE-2026-20700",
          "stars": 8,
          "desc": "",
          "createdAt": "2026-05-23",
          "hasCode": true
        }
      ],
      "epss": 0.01319,
      "epssPercentile": 0.677,
      "source": "poc",
      "mitreUrl": "https://nvd.nist.gov/vuln/detail/CVE-2026-20700",
      "research": [
        {
          "url": "https://thebreach.news/posts/apple-dyld-zero-day-cve-2026-20700",
          "type": "writeup",
          "source": "The Breach",
          "note": "dyld zero-day deep dive"
        },
        {
          "url": "https://www.penligent.ai/hackinglabs/cve-2026-20700-poc-the-dyld-zero-day-that-turns-memory-write-into-code-execution-across-apples-stack/",
          "type": "writeup",
          "source": "Penligent",
          "note": "Memory-write to RCE analysis"
        },
        {
          "url": "https://socprime.com/blog/cve-2026-20700-vulnerability/",
          "type": "detection",
          "source": "SOC Prime",
          "note": "Detection content"
        },
        {
          "url": "https://www.securityweek.com/apple-patches-ios-zero-day-exploited-in-extremely-sophisticated-attack/",
          "type": "writeup",
          "source": "SecurityWeek",
          "note": "Sophisticated targeted attack (TAG)"
        },
        {
          "url": "https://www.lookout.com/threat-intelligence/article/cve-2026-20700-update",
          "type": "writeup",
          "source": "Lookout",
          "note": "Threat-intel update"
        }
      ],
      "x": {
        "mentions": 7,
        "posts": [
          {
            "handle": "brunotorossi",
            "followers": 1716,
            "likes": 4,
            "createdAt": "2026-05-21",
            "url": "https://x.com/brunotorossi/status/2057497317679448559",
            "origin": false,
            "github": []
          },
          {
            "handle": "MOHAMMEDbaderJ",
            "followers": 1,
            "likes": 2,
            "createdAt": "2026-04-03",
            "url": "https://x.com/MOHAMMEDbaderJ/status/2039863196647932308",
            "origin": false,
            "github": []
          },
          {
            "handle": "lyrie_ai",
            "followers": 234,
            "likes": 0,
            "createdAt": "2026-05-05",
            "url": "https://x.com/lyrie_ai/status/2051684255080583453",
            "origin": false,
            "github": []
          },
          {
            "handle": "3r1k4dl3r",
            "followers": 643,
            "likes": 0,
            "createdAt": "2026-04-12",
            "url": "https://x.com/3r1k4dl3r/status/2043325640292634707",
            "origin": false,
            "github": []
          },
          {
            "handle": "DarkForgeNews",
            "followers": 23,
            "likes": 0,
            "createdAt": "2026-04-01",
            "url": "https://x.com/DarkForgeNews/status/2039161135669129717",
            "origin": false,
            "github": []
          },
          {
            "handle": "webwise_digital",
            "followers": 468,
            "likes": 0,
            "createdAt": "2026-03-30",
            "url": "https://x.com/webwise_digital/status/2038730488416960613",
            "origin": false,
            "github": []
          },
          {
            "handle": "psyciclabs",
            "followers": 16,
            "likes": 0,
            "createdAt": "2026-03-30",
            "url": "https://x.com/psyciclabs/status/2038622924853403790",
            "origin": false,
            "github": []
          }
        ],
        "aliases": []
      },
      "researchers": [
        "Google Threat Analysis Group"
      ],
      "bsky": {
        "mentions": 29,
        "posts": [
          {
            "handle": "termsofsurrender.bsky.social",
            "displayName": "AfterShock Index",
            "likes": 0,
            "reposts": 0,
            "replies": 0,
            "createdAt": "2026-02-01",
            "url": "https://bsky.app/profile/termsofsurrender.bsky.social/post/3mdrq6qskx72g",
            "origin": true,
            "authority": false,
            "github": []
          },
          {
            "handle": "viralpique.bsky.social",
            "displayName": null,
            "likes": 0,
            "reposts": 0,
            "replies": 0,
            "createdAt": "2025-12-13",
            "url": "https://bsky.app/profile/viralpique.bsky.social/post/3m7td5endkd27",
            "origin": true,
            "authority": false,
            "github": []
          },
          {
            "handle": "qualysofficial.bsky.social",
            "displayName": "Qualys",
            "likes": 0,
            "reposts": 0,
            "replies": 0,
            "createdAt": "2025-09-19",
            "url": "https://bsky.app/profile/qualysofficial.bsky.social/post/3lz6yhqff342y",
            "origin": true,
            "authority": false,
            "github": []
          },
          {
            "handle": "infosecindustry.bsky.social",
            "displayName": "InfoSec Industry",
            "likes": 0,
            "reposts": 0,
            "replies": 0,
            "createdAt": "2025-09-18",
            "url": "https://bsky.app/profile/infosecindustry.bsky.social/post/3lz3v2xzblo2q",
            "origin": true,
            "authority": false,
            "github": []
          },
          {
            "handle": "estherschindler.bsky.social",
            "displayName": "Esther Schindler",
            "likes": 0,
            "reposts": 0,
            "replies": 0,
            "createdAt": "2024-10-08",
            "url": "https://bsky.app/profile/estherschindler.bsky.social/post/3l5zdfkc7vl2w",
            "origin": true,
            "authority": false,
            "github": []
          },
          {
            "handle": "r-blueteamsec.bsky.social",
            "displayName": "r/blueteamsec bot",
            "likes": 0,
            "reposts": 0,
            "replies": 0,
            "createdAt": "2026-05-25",
            "url": "https://bsky.app/profile/r-blueteamsec.bsky.social/post/3mmpbuhotqm2n",
            "origin": false,
            "authority": false,
            "github": [
              {
                "url": "https://github.com/R3n3r0/CVE-2026-20700",
                "hasCode": true
              }
            ]
          }
        ]
      },
      "telegram": {
        "mentions": 3,
        "posts": [
          {
            "channel": "thehackernews",
            "channelTitle": "The Hacker News",
            "tier": "news",
            "date": "2026-02-12",
            "views": 10504,
            "forwards": 39,
            "url": "https://t.me/thehackernews/8398",
            "text": "🚨 Apple shipped emergency updates after confirming exploitation of a zero-day in dyld. The bug (CVE-2026-20700) could allow attackers to execute arbitrary code on vulnerable Apple devices. 🔗 Read: https://thehackernews.com/2026/02/apple-fixes-exploited-zero-day.html Fixes extend across iOS, macOS, visionOS, and legacy platforms.",
            "github": [],
            "origin": false
          }
        ]
      },
      "aliases": []
    },
    {
      "cve": "CVE-2026-23416",
      "title": "In the Linux kernel, the following vulnerability has been resolved: mm/mseal: update…",
      "category": "Recall",
      "vendor": null,
      "exploited": false,
      "publiclyDisclosed": true,
      "cvss": 5.5,
      "cvssVector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
      "severity": "MEDIUM",
      "impact": null,
      "products": [],
      "productCount": 0,
      "faq": "In the Linux kernel, the following vulnerability has been resolved:\n\nmm/mseal: update VMA end correctly on merge\n\nPreviously we stored the end of the current VMA in curr_end, and then upon\niterating to the next VMA updated curr_start to curr_end to advance to the\nnext VMA.\n\nHowever, this doesn't take into account the fact that a VMA might be\nupdated due to a merge by vma_modify_flags(), which can result in curr_end\nbeing stale and thus, upon setting curr_start to curr_end, ending up with\nan incorrect curr_start on the next iteration.\n\nResolve the issue by setting curr_end to vma->vm_end unconditionally to\nensure this value remains updated should this occur.\n\nWhile we're here, eliminate this entire class of bug by simply setting\nconst curr_[start/end] to be clamped to the input range and VMAs, which\nalso happens to simplify the logic.",
      "pocConfidence": "confirmed",
      "pocCount": 1,
      "pocTopStars": 8,
      "pocRepos": [
        {
          "url": "https://github.com/bluedragonsecurity/CVE-2026-23416-POC",
          "stars": 8,
          "desc": "POC for CVE-2026-23416 (linux kernel 6.17 – linux kernel 7 rc5) - vulnerability discovered by Antonius",
          "createdAt": "2026-04-02",
          "hasCode": true
        }
      ],
      "epss": 0.00218,
      "epssPercentile": 0.12322,
      "source": "poc",
      "mitreUrl": "https://nvd.nist.gov/vuln/detail/CVE-2026-23416",
      "research": [
        {
          "url": "https://github.com/bluedragonsecurity/CVE-2026-23416-POC",
          "type": "poc",
          "source": "bluedragonsecurity",
          "note": "PoC for mseal VMA stale state bug",
          "hasCode": true
        },
        {
          "url": "https://cve.threatint.eu/CVE/CVE-2026-23416",
          "type": "writeup",
          "source": "THREATINT",
          "note": "mm/mseal logic error detail"
        }
      ],
      "x": {
        "mentions": 4,
        "posts": [
          {
            "handle": "bluedragonsec",
            "followers": 69,
            "likes": 5,
            "createdAt": "2026-04-02",
            "url": "https://x.com/bluedragonsec/status/2039723767631675421",
            "origin": false,
            "github": [
              {
                "url": "https://github.com/bluedragonsecurity/CVE-2026-23416-POC"
              }
            ]
          },
          {
            "handle": "CVEnew",
            "followers": 57565,
            "likes": 0,
            "createdAt": "2026-04-02",
            "url": "https://x.com/CVEnew/status/2039744366344839434",
            "origin": false,
            "github": []
          },
          {
            "handle": "cyberbivash",
            "followers": 248,
            "likes": 0,
            "createdAt": "2026-04-02",
            "url": "https://x.com/cyberbivash/status/2039697491407360315",
            "origin": false,
            "github": []
          }
        ],
        "aliases": []
      },
      "researchers": [
        "Antonius"
      ],
      "aliases": [],
      "bsky": {
        "mentions": 1,
        "posts": [
          {
            "handle": "cve.skyfleet.blue",
            "displayName": "CVE Alerts ",
            "likes": 0,
            "reposts": 0,
            "replies": 0,
            "createdAt": "2026-04-02",
            "url": "https://bsky.app/profile/cve.skyfleet.blue/post/3mijetz6bw62o",
            "origin": false,
            "authority": false,
            "github": []
          }
        ]
      }
    },
    {
      "cve": "CVE-2026-52656",
      "title": "An issue in SJCAM AllWinner Tech products SJ4000-Air V1.4C and before and Whitelabel…",
      "category": "Recall",
      "vendor": null,
      "exploited": false,
      "publiclyDisclosed": true,
      "cvss": null,
      "cvssVector": null,
      "severity": null,
      "impact": null,
      "products": [],
      "productCount": 0,
      "faq": "An issue in SJCAM AllWinner Tech products SJ4000-Air V1.4C and before and Whitelabel based v.1.4C and before allows an attacker to execute arbitrary code via a crafted FEX file",
      "pocConfidence": "confirmed",
      "pocCount": 1,
      "pocTopStars": 7,
      "pocRepos": [
        {
          "url": "https://github.com/keowu/sjcam",
          "stars": 7,
          "desc": "Reverse engineering research and custom firmware for the Allwinner V3-based   SJCAM SJ4000 Air, including firmware parsers, an AVIOCTRL client, security   resea",
          "createdAt": "2025-12-01",
          "hasCode": true
        }
      ],
      "epss": 0.00241,
      "epssPercentile": 0.15267,
      "source": "poc",
      "mitreUrl": "https://nvd.nist.gov/vuln/detail/CVE-2026-52656",
      "research": [],
      "aliases": [],
      "researchers": [],
      "x": {
        "mentions": 0,
        "aliases": [],
        "posts": []
      },
      "bsky": {
        "mentions": 0,
        "posts": []
      }
    },
    {
      "cve": "CVE-2026-52943",
      "title": "In the Linux kernel, the following vulnerability has been resolved: net: skbuff: fix…",
      "category": "Recall",
      "vendor": null,
      "exploited": false,
      "publiclyDisclosed": true,
      "cvss": 7.8,
      "cvssVector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "severity": "HIGH",
      "impact": null,
      "products": [],
      "productCount": 0,
      "faq": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: skbuff: fix missing zerocopy reference in pskb_carve helpers\n\npskb_carve_inside_header() and pskb_carve_inside_nonlinear() both copy\nthe old skb_shared_info header into a new buffer via memcpy(), which\nincludes the destructor_arg pointer (uarg) for MSG_ZEROCOPY skbs.\nNeither function calls net_zcopy_get() for the new shinfo, creating an\nunaccounted holder: every skb_shared_info with destructor_arg set will\ncall skb_zcopy_clear() once when freed, but the corresponding\nnet_zcopy_get() was never called for the new copy. Repeated calls\ndrive uarg->refcnt to zero prematurely, freeing ubuf_info_msgzc while\nTX skbs still hold live destructor_arg pointers.\n\nKASAN reports use-after-free on a freed ubuf_info_msgzc:\n\n  BUG: KASAN: slab-use-after-free in skb_release_data+0x77b/0x810\n  Read of size 8 at addr ffff88801574d3e8 by task poc/220\n\n  Call Trace:\n   skb_release_data+0x77b/0x810\n   kfree_skb_list_reason+0x13e/0x610\n   skb_release_data+0x4cd/0x810\n   sk_skb_reason_drop+0xf3/0x340\n   skb_queue_purge_reason+0x282/0x440\n   rds_tcp_inc_free+0x1e/0x30\n   rds_recvmsg+0x354/0x1780\n   __sys_recvmsg+0xdf/0x180\n\n  Allocated by task 219:\n   msg_zerocopy_realloc+0x157/0x7b0\n   tcp_sendmsg_locked+0x2892/0x3ba0\n\n  Freed by task 219:\n   ip_recv_error+0x74a/0xb10\n   tcp_recvmsg+0x475/0x530\n\nThe skb consuming the late access still referenced the same uarg via\nshinfo->destructor_arg copied by pskb_carve_inside_nonlinear() without\na refcount bump. This has been verified to be reliably exploitable: a\nworking proof-of-concept achieves full root privilege escalation from\nan unprivileged local user on a default kernel configuration.\n\nThe fix follows the pattern of pskb_expand_head() which has the same\nmemcpy/cloned structure. For pskb_carve_inside_header(), net_zcopy_get()\nis placed after skb_orphan_frags() succeeds, so the orphan error path\nneeds no cleanup. For pskb_carve_inside_nonlinear(), net_zcopy_get() is\nplaced after all failure points and just before skb_release_data(), so\nno error path needs cleanup at all -- matching pskb_expand_head() more\nclosely and avoiding the need for a balancing net_zcopy_put().",
      "pocConfidence": "confirmed",
      "pocCount": 1,
      "pocTopStars": 7,
      "pocRepos": [
        {
          "url": "https://github.com/vn-lazyming/CVE-2026-52943",
          "stars": 7,
          "desc": "This is a Linux Kernel Local Privilege Escalation PoC code for CVE-2026-52943 a use-after-free in skbuff.c, my first 0day found by me in linux kernel",
          "createdAt": "2026-06-16",
          "hasCode": true
        }
      ],
      "epss": 0.00238,
      "epssPercentile": 0.14916,
      "source": "poc",
      "mitreUrl": "https://nvd.nist.gov/vuln/detail/CVE-2026-52943",
      "research": [],
      "aliases": [],
      "researchers": [],
      "x": {
        "mentions": 0,
        "aliases": [],
        "posts": []
      },
      "bsky": {
        "mentions": 0,
        "posts": []
      }
    },
    {
      "cve": "CVE-2026-1555",
      "title": "The WebStack theme for WordPress is vulnerable to arbitrary file uploads due to…",
      "category": "Recall",
      "vendor": null,
      "exploited": false,
      "publiclyDisclosed": true,
      "cvss": 9.8,
      "cvssVector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "severity": "CRITICAL",
      "impact": null,
      "products": [],
      "productCount": 0,
      "faq": "The WebStack theme for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the io_img_upload() function in all versions up to, and including, 1.2024. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code execution possible.",
      "pocConfidence": "confirmed",
      "pocCount": 1,
      "pocTopStars": 7,
      "pocRepos": [
        {
          "url": "https://github.com/Nxploited/CVE-2026-1555",
          "stars": 7,
          "desc": "WebStack <= 1.2024 - Unauthenticated Arbitrary File Upload",
          "createdAt": "2026-04-17",
          "hasCode": true
        }
      ],
      "epss": 0.00984,
      "epssPercentile": 0.58467,
      "source": "poc",
      "mitreUrl": "https://nvd.nist.gov/vuln/detail/CVE-2026-1555",
      "bsky": {
        "mentions": 5,
        "posts": [
          {
            "handle": "hermes71.bsky.social",
            "displayName": "Some Hermes agent",
            "likes": 0,
            "reposts": 0,
            "replies": 1,
            "createdAt": "2026-04-15",
            "url": "https://bsky.app/profile/hermes71.bsky.social/post/3mjj4r3xoul2z",
            "origin": false,
            "authority": false,
            "github": []
          },
          {
            "handle": "cve.skyfleet.blue",
            "displayName": "CVE Alerts ",
            "likes": 0,
            "reposts": 0,
            "replies": 0,
            "createdAt": "2026-04-15",
            "url": "https://bsky.app/profile/cve.skyfleet.blue/post/3mjjibnomy52g",
            "origin": false,
            "authority": false,
            "github": []
          },
          {
            "handle": "offseq.bsky.social",
            "displayName": "OffSequence",
            "likes": 0,
            "reposts": 0,
            "replies": 0,
            "createdAt": "2026-04-15",
            "url": "https://bsky.app/profile/offseq.bsky.social/post/3mjj2qkoar62p",
            "origin": false,
            "authority": false,
            "github": []
          },
          {
            "handle": "thehackerwire.bsky.social",
            "displayName": "TheHackerWire",
            "likes": 0,
            "reposts": 0,
            "replies": 0,
            "createdAt": "2026-04-15",
            "url": "https://bsky.app/profile/thehackerwire.bsky.social/post/3mjkgcool622e",
            "origin": false,
            "authority": false,
            "github": []
          }
        ]
      },
      "telegram": {
        "mentions": 0,
        "posts": []
      },
      "research": [],
      "aliases": [],
      "researchers": [],
      "x": {
        "mentions": 0,
        "aliases": [],
        "posts": []
      }
    },
    {
      "cve": "CVE-2026-48778",
      "title": "Notepad++ RCE via config.xml commandLineInterpreter",
      "category": "Recall",
      "vendor": null,
      "exploited": false,
      "publiclyDisclosed": true,
      "cvss": null,
      "cvssVector": null,
      "severity": null,
      "impact": null,
      "products": [],
      "productCount": 0,
      "faq": null,
      "pocConfidence": "confirmed",
      "pocCount": 1,
      "pocTopStars": 7,
      "pocRepos": [
        {
          "url": "https://github.com/XK3NF4/CVE-2026-48778",
          "stars": 7,
          "desc": "Notepad++ RCE via config.xml commandLineInterpreter",
          "createdAt": "2026-05-30",
          "hasCode": true
        }
      ],
      "epss": 0.01314,
      "epssPercentile": 0.67574,
      "source": "poc",
      "mitreUrl": "https://nvd.nist.gov/vuln/detail/CVE-2026-48778",
      "research": [
        {
          "url": "https://github.com/notepad-plus-plus/notepad-plus-plus/security/advisories/GHSA-7hm3-wp5q-ccv9",
          "type": "writeup",
          "source": "notepad-plus-plus GHSA",
          "note": "ACE via commandLineInterpreter in config.xml",
          "hasCode": true
        },
        {
          "url": "https://www.exploit-db.com/exploits/52606",
          "type": "poc",
          "source": "Exploit-DB",
          "note": "Notepad++ 8.9.6 arbitrary code execution"
        },
        {
          "url": "https://threatprotect.qualys.com/2026/05/29/notepad-vulnerabilities-allow-attackers-to-execute-arbitrary-code-cve-2026-48778/",
          "type": "writeup",
          "source": "Qualys",
          "note": "ACE analysis"
        }
      ],
      "x": {
        "mentions": 7,
        "aliases": [],
        "posts": [
          {
            "handle": "piedpiper1616",
            "followers": 5519,
            "likes": 9,
            "createdAt": "2026-05-30",
            "url": "https://x.com/piedpiper1616/status/2060544381585948861",
            "github": [
              {
                "url": "https://github.com/atiilla/Notepad-8.9.6-PoC",
                "hasCode": true
              }
            ],
            "origin": false
          },
          {
            "handle": "hackingspace",
            "followers": 7100,
            "likes": 4,
            "createdAt": "2026-05-29",
            "url": "https://x.com/hackingspace/status/2060149949652668777",
            "github": [
              {
                "url": "https://github.com/intelseclab/poc-archive/tree/master/pocs/binary/2026-05-28_notepad-plus-plus-8-9-6-multi-cve",
                "hasCode": true
              }
            ],
            "origin": false
          },
          {
            "handle": "__kokumoto",
            "followers": 7498,
            "likes": 8,
            "createdAt": "2026-06-01",
            "url": "https://x.com/__kokumoto/status/2061285316934410372",
            "github": [],
            "origin": false
          },
          {
            "handle": "csirt_it",
            "followers": 8946,
            "likes": 2,
            "createdAt": "2026-05-28",
            "url": "https://x.com/csirt_it/status/2060013883708871138",
            "github": [],
            "origin": false
          },
          {
            "handle": "vintcessun",
            "followers": 2266,
            "likes": 1,
            "createdAt": "2026-06-01",
            "url": "https://x.com/vintcessun/status/2061289635142390039",
            "github": [],
            "origin": false
          },
          {
            "handle": "Vulcanux_",
            "followers": 614,
            "likes": 0,
            "createdAt": "2026-05-28",
            "url": "https://x.com/Vulcanux_/status/2060015362951803361",
            "github": [],
            "origin": false
          }
        ]
      },
      "aliases": [],
      "researchers": [],
      "bsky": {
        "mentions": 15,
        "posts": [
          {
            "handle": "notepad-plus-plus.org",
            "displayName": "Notepad++",
            "likes": 22,
            "reposts": 5,
            "replies": 0,
            "createdAt": "2026-05-31",
            "url": "https://bsky.app/profile/notepad-plus-plus.org/post/3mn5rlokl3c2g",
            "origin": false,
            "authority": false,
            "github": []
          },
          {
            "handle": "crustytldr.bsky.social",
            "displayName": null,
            "likes": 1,
            "reposts": 1,
            "replies": 0,
            "createdAt": "2026-05-29",
            "url": "https://bsky.app/profile/crustytldr.bsky.social/post/3mmzk5ms7vf2l",
            "origin": false,
            "authority": false,
            "github": []
          },
          {
            "handle": "pmloik.bsky.social",
            "displayName": null,
            "likes": 0,
            "reposts": 1,
            "replies": 0,
            "createdAt": "2026-06-02",
            "url": "https://bsky.app/profile/pmloik.bsky.social/post/3mnbkhiii6g2s",
            "origin": false,
            "authority": false,
            "github": []
          },
          {
            "handle": "eyalestrin.bsky.social",
            "displayName": "Eyal Estrin ☁️",
            "likes": 0,
            "reposts": 1,
            "replies": 0,
            "createdAt": "2026-05-30",
            "url": "https://bsky.app/profile/eyalestrin.bsky.social/post/3mn32y62gra2x",
            "origin": false,
            "authority": false,
            "github": []
          },
          {
            "handle": "blackhatnews.tokyo",
            "displayName": "blackhatnews.tokyo",
            "likes": 0,
            "reposts": 1,
            "replies": 0,
            "createdAt": "2026-05-28",
            "url": "https://bsky.app/profile/blackhatnews.tokyo/post/3mmvqnt2n5l2c",
            "origin": false,
            "authority": false,
            "github": []
          },
          {
            "handle": "kriptabiz.bsky.social",
            "displayName": "kripta.biz",
            "likes": 0,
            "reposts": 0,
            "replies": 0,
            "createdAt": "2026-06-29",
            "url": "https://bsky.app/profile/kriptabiz.bsky.social/post/3mpgqb7reuw2r",
            "origin": false,
            "authority": false,
            "github": []
          }
        ]
      }
    },
    {
      "cve": "CVE-2026-14382",
      "title": "Insufficient validation of untrusted input in ANGLE in Google Chrome prior to…",
      "category": "Recall",
      "vendor": null,
      "exploited": false,
      "publiclyDisclosed": true,
      "cvss": 9.6,
      "cvssVector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H",
      "severity": "CRITICAL",
      "impact": null,
      "products": [],
      "productCount": 0,
      "faq": "Insufficient validation of untrusted input in ANGLE in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)",
      "pocConfidence": "confirmed",
      "pocCount": 1,
      "pocTopStars": 6,
      "pocRepos": [
        {
          "url": "https://github.com/jaf0rk/CVE-2026-14382",
          "stars": 6,
          "desc": "",
          "createdAt": "2026-07-06",
          "hasCode": true
        }
      ],
      "epss": 0.00276,
      "epssPercentile": 0.196,
      "source": "poc",
      "mitreUrl": "https://nvd.nist.gov/vuln/detail/CVE-2026-14382",
      "research": [
        {
          "url": "https://github.com/advisories/GHSA-7fh8-qj6w-5vcc",
          "type": "detection",
          "source": "GitHub Advisory Database",
          "note": "Official advisory; CVSS 9.6 Critical, no PoC linked",
          "hasCode": null
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-14382",
          "type": "detection",
          "source": "NVD / NIST",
          "note": "NVD entry; sandbox escape via crafted HTML page"
        },
        {
          "url": "https://chromereleases.googleblog.com/2026/06/stable-channel-update-for-desktop_0175352312.html",
          "type": "detection",
          "source": "Google Chrome Releases Blog",
          "note": "Official patch notice for Chrome 150.0.7871.46"
        },
        {
          "url": "https://issues.chromium.org/issues/492218546",
          "type": "detection",
          "source": "Chromium Issue Tracker",
          "note": "Bug report; restricted/non-public as of July 2026"
        },
        {
          "url": "https://www.hkcert.org/security-bulletin/google-chrome-multiple-vulnerabilities_20260702",
          "type": "detection",
          "source": "HKCERT",
          "note": "Security bulletin listing CVE-2026-14382 among others"
        },
        {
          "url": "https://thewindowsupdate.com/2026/07/11/chromium-cve-2026-14382-insufficient-validation-of-untrusted-input-in-angle/",
          "type": "detection",
          "source": "MSRC / TheWindowsUpdate (Edge advisory)",
          "note": "Edge Chromium inherits fix; no technical detail"
        }
      ],
      "aliases": [],
      "researchers": [],
      "x": {
        "mentions": 0,
        "aliases": [],
        "posts": []
      },
      "bsky": {
        "mentions": 1,
        "posts": [
          {
            "handle": "stackflag.bsky.social",
            "displayName": "STACKFLAG",
            "likes": 0,
            "reposts": 0,
            "replies": 0,
            "createdAt": "2026-07-02",
            "url": "https://bsky.app/profile/stackflag.bsky.social/post/3mpoxjm7rci2i",
            "origin": false,
            "authority": false,
            "github": []
          }
        ]
      },
      "telegram": {
        "mentions": 0,
        "posts": []
      }
    },
    {
      "cve": "CVE-2026-43499",
      "title": "In the Linux kernel, the following vulnerability has been resolved: rtmutex: Use…",
      "category": "Recall",
      "vendor": null,
      "exploited": false,
      "publiclyDisclosed": true,
      "cvss": 7.8,
      "cvssVector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "severity": "HIGH",
      "impact": null,
      "products": [],
      "productCount": 0,
      "faq": "In the Linux kernel, the following vulnerability has been resolved:\n\nrtmutex: Use waiter::task instead of current in remove_waiter()\n\nremove_waiter() is used by the slowlock paths, but it is also used for\nproxy-lock rollback in rt_mutex_start_proxy_lock() when invoked from\nfutex_requeue().\n\nIn the latter case waiter::task is not current, but remove_waiter()\noperates on current for the dequeue operation. That results in several\nproblems:\n\n  1) the rbtree dequeue happens without waiter::task::pi_lock being held\n\n  2) the waiter task's pi_blocked_on state is not cleared, which leaves a\n     dangling pointer primed for UAF around.\n\n  3) rt_mutex_adjust_prio_chain() operates on the wrong top priority waiter\n     task\n\nUse waiter::task instead of current in all related operations in\nremove_waiter() to cure those problems.\n\n[ tglx: Fixup rt_mutex_adjust_prio_chain(), add a comment and amend the\n  \tchangelog ]",
      "pocConfidence": "confirmed",
      "pocCount": 1,
      "pocTopStars": 6,
      "pocRepos": [
        {
          "url": "https://github.com/MobiusM/CVE-2026-43499",
          "stars": 6,
          "desc": "CVE-2026-43499 PoC",
          "createdAt": "2026-06-27",
          "hasCode": true
        }
      ],
      "epss": 0.00125,
      "epssPercentile": 0.02588,
      "source": "poc",
      "mitreUrl": "https://nvd.nist.gov/vuln/detail/CVE-2026-43499",
      "research": [],
      "aliases": [],
      "researchers": [],
      "x": {
        "mentions": 28,
        "aliases": [],
        "posts": [
          {
            "handle": "nebusecurity",
            "followers": 4500,
            "likes": 240,
            "createdAt": "2026-07-08",
            "url": "https://x.com/nebusecurity/status/2074663573742338256",
            "github": [],
            "origin": false
          },
          {
            "handle": "__kokumoto",
            "followers": 7578,
            "likes": 7,
            "createdAt": "2026-07-08",
            "url": "https://x.com/__kokumoto/status/2074698589713154281",
            "github": [],
            "origin": false
          },
          {
            "handle": "Daily_CyberSec",
            "followers": 12430,
            "likes": 5,
            "createdAt": "2026-07-08",
            "url": "https://x.com/Daily_CyberSec/status/2074678524191855020",
            "github": [],
            "origin": false
          },
          {
            "handle": "ridvanyagli",
            "followers": 1120,
            "likes": 5,
            "createdAt": "2026-07-08",
            "url": "https://x.com/ridvanyagli/status/2074701200167952860",
            "github": [],
            "origin": false
          },
          {
            "handle": "runtimewire",
            "followers": 146,
            "likes": 1,
            "createdAt": "2026-07-08",
            "url": "https://x.com/runtimewire/status/2074681363207192822",
            "github": [],
            "origin": false
          }
        ]
      },
      "bsky": {
        "mentions": 20,
        "posts": [
          {
            "handle": "linuxiac.bsky.social",
            "displayName": "Linuxiac",
            "likes": 8,
            "reposts": 0,
            "replies": 1,
            "createdAt": "2026-07-09",
            "url": "https://bsky.app/profile/linuxiac.bsky.social/post/3mq7ztecd2s27",
            "origin": false,
            "authority": false,
            "github": []
          },
          {
            "handle": "bearstech.com",
            "displayName": "Bearstech",
            "likes": 3,
            "reposts": 3,
            "replies": 0,
            "createdAt": "2026-07-15",
            "url": "https://bsky.app/profile/bearstech.com/post/3mqplnotvo72h",
            "origin": false,
            "authority": false,
            "github": []
          },
          {
            "handle": "stevensaus.faithcollapsing.com.ap.brid.gy",
            "displayName": "Steven Saus [he/him]",
            "likes": 2,
            "reposts": 0,
            "replies": 0,
            "createdAt": "2026-07-10",
            "url": "https://bsky.app/profile/stevensaus.faithcollapsing.com.ap.brid.gy/post/3mqayt3ktboq2",
            "origin": false,
            "authority": false,
            "github": []
          },
          {
            "handle": "grsecurity.bsky.social",
            "displayName": "grsecurity",
            "likes": 1,
            "reposts": 0,
            "replies": 1,
            "createdAt": "2026-07-08",
            "url": "https://bsky.app/profile/grsecurity.bsky.social/post/3mq5vhkasy22p",
            "origin": false,
            "authority": false,
            "github": []
          },
          {
            "handle": "web.www.haxette.se.ap.brid.gy",
            "displayName": "Haxette",
            "likes": 1,
            "reposts": 0,
            "replies": 0,
            "createdAt": "2026-07-17",
            "url": "https://bsky.app/profile/web.www.haxette.se.ap.brid.gy/post/3mquj4grex2l2",
            "origin": false,
            "authority": false,
            "github": []
          },
          {
            "handle": "cant10.bsky.social",
            "displayName": "Cant10",
            "likes": 0,
            "reposts": 0,
            "replies": 1,
            "createdAt": "2026-07-14",
            "url": "https://bsky.app/profile/cant10.bsky.social/post/3mqmhjjqhos2k",
            "origin": false,
            "authority": false,
            "github": []
          }
        ]
      }
    },
    {
      "cve": "CVE-2026-0023",
      "title": "In createSessionInternal of PackageInstallerService.java, there is a possible way for…",
      "category": "Recall",
      "vendor": null,
      "exploited": false,
      "publiclyDisclosed": true,
      "cvss": 7.8,
      "cvssVector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "severity": "HIGH",
      "impact": null,
      "products": [],
      "productCount": 0,
      "faq": "In createSessionInternal of PackageInstallerService.java, there is a possible way for an app to update its ownership due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.",
      "pocConfidence": "confirmed",
      "pocCount": 1,
      "pocTopStars": 6,
      "pocRepos": [
        {
          "url": "https://github.com/QM4RS/CVE-2026-0023-Update-Ownership-PoC",
          "stars": 6,
          "desc": "",
          "createdAt": "2026-06-10",
          "hasCode": true
        }
      ],
      "epss": 0.00084,
      "epssPercentile": 0.00341,
      "source": "poc",
      "mitreUrl": "https://nvd.nist.gov/vuln/detail/CVE-2026-0023",
      "research": [],
      "x": {
        "mentions": 0,
        "aliases": [],
        "posts": []
      },
      "aliases": [],
      "researchers": [],
      "bsky": {
        "mentions": 2,
        "posts": [
          {
            "handle": "thehackerwire.bsky.social",
            "displayName": "TheHackerWire",
            "likes": 0,
            "reposts": 0,
            "replies": 0,
            "createdAt": "2026-03-03",
            "url": "https://bsky.app/profile/thehackerwire.bsky.social/post/3mg5xk75y6m2c",
            "origin": false,
            "authority": false,
            "github": []
          },
          {
            "handle": "cve.skyfleet.blue",
            "displayName": "CVE Alerts ",
            "likes": 0,
            "reposts": 0,
            "replies": 0,
            "createdAt": "2026-03-02",
            "url": "https://bsky.app/profile/cve.skyfleet.blue/post/3mg42adsg4y2n",
            "origin": false,
            "authority": false,
            "github": []
          }
        ]
      }
    },
    {
      "cve": "CVE-2026-39363",
      "title": "Vite is a frontend tooling framework for JavaScript. From 6.0.0 to before 6.4.2,…",
      "category": "Recall",
      "vendor": null,
      "exploited": false,
      "publiclyDisclosed": true,
      "cvss": 7.5,
      "cvssVector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
      "severity": "HIGH",
      "impact": null,
      "products": [],
      "productCount": 0,
      "faq": "Vite is a frontend tooling framework for JavaScript. From 6.0.0 to before 6.4.2, 7.3.2, and 8.0.5, if it is possible to connect to the Vite dev server’s WebSocket without an Origin header, an attacker can invoke fetchModule via the custom WebSocket event vite:invoke and combine file://... with ?raw (or ?inline) to retrieve the contents of arbitrary files on the server as a JavaScript string (e.g., export default \"...\"). The access control enforced in the HTTP request path (such as server.fs.allow) is not applied to this WebSocket-based execution path. This vulnerability is fixed in 6.4.2, 7.3.2, and 8.0.5.",
      "pocConfidence": "confirmed",
      "pocCount": 1,
      "pocTopStars": 6,
      "pocRepos": [
        {
          "url": "https://github.com/Firebasky/CVE-2026-39363",
          "stars": 6,
          "desc": "CVE-2026-39363 AI  analysis",
          "createdAt": "2026-04-08",
          "hasCode": true
        }
      ],
      "epss": 0.02907,
      "epssPercentile": 0.8546,
      "source": "poc",
      "mitreUrl": "https://nvd.nist.gov/vuln/detail/CVE-2026-39363",
      "research": [],
      "aliases": [],
      "researchers": [],
      "x": {
        "mentions": 0,
        "aliases": [],
        "posts": []
      },
      "bsky": {
        "mentions": 3,
        "posts": [
          {
            "handle": "beikokucyber.bsky.social",
            "displayName": "Beikoku Cybersecurity",
            "likes": 0,
            "reposts": 0,
            "replies": 0,
            "createdAt": "2026-04-19",
            "url": "https://bsky.app/profile/beikokucyber.bsky.social/post/3mjuu2zqxlm2x",
            "origin": false,
            "authority": false,
            "github": []
          },
          {
            "handle": "cve.skyfleet.blue",
            "displayName": "CVE Alerts ",
            "likes": 0,
            "reposts": 0,
            "replies": 0,
            "createdAt": "2026-04-07",
            "url": "https://bsky.app/profile/cve.skyfleet.blue/post/3miwufhlcwy2z",
            "origin": false,
            "authority": false,
            "github": []
          }
        ]
      }
    },
    {
      "cve": "CVE-2026-44706",
      "title": "Chatwoot is a customer engagement suite. From 2.2.0 to before 4.11.2, a SQL injection…",
      "category": "Recall",
      "vendor": null,
      "exploited": false,
      "publiclyDisclosed": true,
      "cvss": 8.5,
      "cvssVector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N",
      "severity": "HIGH",
      "impact": null,
      "products": [],
      "productCount": 0,
      "faq": "Chatwoot is a customer engagement suite. From 2.2.0 to before 4.11.2, a SQL injection vulnerability exists in the conversation and contact filter APIs. When filtering by a custom attribute of type date or number using the is_greater_than or is_less_than operators, user-supplied values in the values field of the filter payload are interpolated directly into the SQL query without parameterization. Any authenticated user with access to an account can exploit this to execute arbitrary SQL via time-based blind injection. This affects /api/v1/accounts/{account_id}/conversations/filter, /api/v1/accounts/{account_id}/contacts/filter, and /api/v1/accounts/{account_id}/custom_attribute_definitions. This vulnerability is fixed in 4.11.2.",
      "pocConfidence": "confirmed",
      "pocCount": 1,
      "pocTopStars": 6,
      "pocRepos": [
        {
          "url": "https://github.com/hakaioffsec/CVE-2026-44706",
          "stars": 6,
          "desc": "Chatwoot SQL injection in FilterService",
          "createdAt": "2026-03-31",
          "hasCode": true
        }
      ],
      "epss": 0.00227,
      "epssPercentile": 0.1345,
      "source": "poc",
      "mitreUrl": "https://nvd.nist.gov/vuln/detail/CVE-2026-44706",
      "research": [
        {
          "url": "https://github.com/chatwoot/chatwoot/security/advisories/GHSA-g8f9-hh83-rcq9",
          "type": "writeup",
          "source": "chatwoot GHSA",
          "note": "Blind SQLi in conversation/contacts filters",
          "hasCode": true
        },
        {
          "url": "https://app.opencve.io/cve/?vendor=chatwoot",
          "type": "writeup",
          "source": "OpenCVE",
          "note": "Chatwoot CVE listing"
        }
      ],
      "x": {
        "mentions": 2,
        "posts": [
          {
            "handle": "HakaiOffsec",
            "followers": 1152,
            "likes": 37,
            "createdAt": "2026-06-05",
            "url": "https://x.com/HakaiOffsec/status/2062990261446119729",
            "origin": false,
            "github": []
          },
          {
            "handle": "CVEnew",
            "followers": 57565,
            "likes": 0,
            "createdAt": "2026-05-26",
            "url": "https://x.com/CVEnew/status/2059337191252255150",
            "origin": false,
            "github": []
          }
        ],
        "aliases": []
      },
      "researchers": [
        "chatwoot"
      ],
      "aliases": [],
      "bsky": {
        "mentions": 0,
        "posts": []
      }
    },
    {
      "cve": "CVE-2026-13585",
      "title": "Allocation of Resources Without Limits and Throttling and Sensitive Information in…",
      "category": "Recall",
      "vendor": null,
      "exploited": false,
      "publiclyDisclosed": true,
      "cvss": null,
      "cvssVector": null,
      "severity": null,
      "impact": null,
      "products": [],
      "productCount": 0,
      "faq": "Allocation of Resources Without Limits and Throttling and Sensitive Information in Resource Not Removed Before Reuse in the ASUS System Control Interface driver and ASUS Business Manager allow a local administrator to disclose sensitive information via crafted IOCTL requests, which, in severe cases, may lead to a Denial of Service (DoS) on the system.\nRefer to the ' \nSecurity Update for ASUS System Control Interface  ' section on the ASUS Security Advisory for more information.",
      "pocConfidence": "confirmed",
      "pocCount": 1,
      "pocTopStars": 5,
      "pocRepos": [
        {
          "url": "https://github.com/416rehman/asus-bsitf-0-day-poc",
          "stars": 5,
          "desc": "PoC for CVE-2026-13585",
          "createdAt": "2026-04-07",
          "hasCode": true
        }
      ],
      "epss": 0.00114,
      "epssPercentile": 0.01737,
      "source": "poc",
      "mitreUrl": "https://nvd.nist.gov/vuln/detail/CVE-2026-13585",
      "research": [
        {
          "url": "https://www.asus.com/security-advisory/",
          "type": "detection",
          "source": "ASUS Security Advisory",
          "note": "Official vendor advisory; patch/mitigation guidance"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-13585",
          "type": "detection",
          "source": "NIST NVD",
          "note": "NVD entry; CVSS 4.0 score 8.2, published Jul 15 2026"
        },
        {
          "url": "https://github.com/advisories/GHSA-jf28-f99p-265w",
          "type": "detection",
          "source": "GitHub Advisory Database",
          "note": "GitHub advisory; no PoC code linked",
          "hasCode": null
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-13585",
          "type": "detection",
          "source": "CVE.org / MITRE",
          "note": "Official CVE record; no exploit references"
        },
        {
          "url": "https://radar.offseq.com/threat/cve-2026-13585-cwe-770-allocation-of-resources-wit-1cd34d6b3abe8958",
          "type": "detection",
          "source": "OffSeq Threat Radar",
          "note": "Threat intel summary; no known exploits in wild"
        },
        {
          "url": "https://secably.com/cve/CVE-2026-13585/",
          "type": "detection",
          "source": "Secably",
          "note": "Vuln tracker; IOCTL abuse vector documented"
        },
        {
          "url": "https://www.thehackerwire.com/vulnerability/CVE-2026-13585/",
          "type": "detection",
          "source": "TheHackerWire",
          "note": "Aggregator page; links to NVD and ASUS advisory"
        }
      ],
      "aliases": [],
      "researchers": [],
      "x": {
        "mentions": 0,
        "aliases": [],
        "posts": []
      },
      "bsky": {
        "mentions": 4,
        "posts": [
          {
            "handle": "r-blueteamsec.bsky.social",
            "displayName": "r/blueteamsec bot",
            "likes": 0,
            "reposts": 1,
            "replies": 0,
            "createdAt": "2026-07-16",
            "url": "https://bsky.app/profile/r-blueteamsec.bsky.social/post/3mqrf5rxb4s2o",
            "origin": false,
            "authority": false,
            "github": [
              {
                "url": "https://github.com/416rehman/asus-bsitf-0-day-poc",
                "hasCode": true
              }
            ]
          },
          {
            "handle": "r-netsec.bsky.social",
            "displayName": "r/netsec bot",
            "likes": 0,
            "reposts": 1,
            "replies": 0,
            "createdAt": "2026-07-16",
            "url": "https://bsky.app/profile/r-netsec.bsky.social/post/3mqr6hadqa42w",
            "origin": false,
            "authority": false,
            "github": []
          },
          {
            "handle": "r-netsec-bot.bsky.social",
            "displayName": "/r/netsec",
            "likes": 0,
            "reposts": 1,
            "replies": 0,
            "createdAt": "2026-07-16",
            "url": "https://bsky.app/profile/r-netsec-bot.bsky.social/post/3mqqm7lisau2t",
            "origin": false,
            "authority": false,
            "github": []
          },
          {
            "handle": "cve.skyfleet.blue",
            "displayName": "CVE Alerts ",
            "likes": 0,
            "reposts": 1,
            "replies": 0,
            "createdAt": "2026-07-15",
            "url": "https://bsky.app/profile/cve.skyfleet.blue/post/3mqnsjokhz42c",
            "origin": false,
            "authority": false,
            "github": []
          }
        ]
      }
    },
    {
      "cve": "CVE-2026-52806",
      "title": "Gogs is an open source self-hosted Git service. Prior to 0.14.3, Gogs allows…",
      "category": "Recall",
      "vendor": null,
      "exploited": false,
      "publiclyDisclosed": true,
      "cvss": 9.9,
      "cvssVector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H",
      "severity": "CRITICAL",
      "impact": null,
      "products": [],
      "productCount": 0,
      "faq": "Gogs is an open source self-hosted Git service. Prior to 0.14.3, Gogs allows authenticated users to achieve Remote Code Execution (RCE) on the server by creating a pull request with a specially crafted branch name that injects the --exec flag into the git rebase command during the \"Rebase before merging\" merge operation. This vulnerability is fixed in 0.14.3.",
      "pocConfidence": "confirmed",
      "pocCount": 1,
      "pocTopStars": 5,
      "pocRepos": [
        {
          "url": "https://github.com/portbuster1337/CVE-2026-52806",
          "stars": 5,
          "desc": "Gogs RCE via argument injection in git rebase (CWE-88) — Python PoC. CVE-2026-52806",
          "createdAt": "2026-05-28",
          "hasCode": true
        }
      ],
      "epss": 0.01029,
      "epssPercentile": 0.59904,
      "source": "poc",
      "mitreUrl": "https://nvd.nist.gov/vuln/detail/CVE-2026-52806",
      "research": [],
      "aliases": [],
      "researchers": [],
      "x": {
        "mentions": 0,
        "aliases": [],
        "posts": []
      },
      "bsky": {
        "mentions": 0,
        "posts": []
      },
      "telegram": {
        "mentions": 0,
        "posts": []
      }
    },
    {
      "cve": "CVE-2026-54806",
      "title": "Unauthenticated PHP Object Injection in WP Activity Log <= 5.6.3.1",
      "category": "Recall",
      "vendor": null,
      "exploited": false,
      "publiclyDisclosed": true,
      "cvss": 9.8,
      "cvssVector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "severity": "CRITICAL",
      "impact": null,
      "products": [],
      "productCount": 0,
      "faq": "Unauthenticated PHP Object Injection in WP Activity Log <= 5.6.3.1 versions.",
      "pocConfidence": "confirmed",
      "pocCount": 1,
      "pocTopStars": 5,
      "pocRepos": [
        {
          "url": "https://github.com/joshuavanderpoll/CVE-2026-54806",
          "stars": 5,
          "desc": "Unauthenticated PHP Object Injection to RCE in WP Activity Log <= 5.6.3.1 (CVE-2026-54806)",
          "createdAt": "2026-06-22",
          "hasCode": true
        }
      ],
      "epss": 0.00661,
      "epssPercentile": 0.47596,
      "source": "poc",
      "mitreUrl": "https://nvd.nist.gov/vuln/detail/CVE-2026-54806",
      "telegram": {
        "mentions": 0,
        "posts": []
      },
      "research": [],
      "aliases": [],
      "researchers": [],
      "x": {
        "mentions": 0,
        "aliases": [],
        "posts": []
      },
      "bsky": {
        "mentions": 1,
        "posts": [
          {
            "handle": "cve.skyfleet.blue",
            "displayName": "CVE Alerts ",
            "likes": 0,
            "reposts": 1,
            "replies": 0,
            "createdAt": "2026-06-17",
            "url": "https://bsky.app/profile/cve.skyfleet.blue/post/3moihfjejpl2g",
            "origin": false,
            "authority": false,
            "github": []
          }
        ]
      }
    },
    {
      "cve": "CVE-2026-27654",
      "title": "NGINX Open Source and NGINX Plus have a vulnerability in the ngx_http_dav_module…",
      "category": "Recall",
      "vendor": null,
      "exploited": false,
      "publiclyDisclosed": true,
      "cvss": 8.2,
      "cvssVector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H",
      "severity": "HIGH",
      "impact": null,
      "products": [],
      "productCount": 0,
      "faq": "NGINX Open Source and NGINX Plus have a vulnerability in the ngx_http_dav_module module that might allow an attacker to trigger a buffer overflow to the NGINX worker process; this vulnerability may result in termination of the NGINX worker process or modification of source or destination file names outside the document root. This issue affects NGINX Open Source and NGINX Plus when the configuration file uses DAV module MOVE or COPY methods, prefix location (nonregular expression location configuration), and alias directives. The integrity impact is constrained because the NGINX worker process user has low privileges and does not have access to the entire system. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.",
      "pocConfidence": "confirmed",
      "pocCount": 1,
      "pocTopStars": 5,
      "pocRepos": [
        {
          "url": "https://github.com/JohannesLks/CVE-2026-27654",
          "stars": 5,
          "desc": "NGINX `ngx_http_dav_module` Heap Buffer Overflow via `size_t` Underflow (Remote DoS / Potential RCE)",
          "createdAt": "2026-04-06",
          "hasCode": true
        }
      ],
      "epss": 0.21621,
      "epssPercentile": 0.97362,
      "source": "poc",
      "mitreUrl": "https://nvd.nist.gov/vuln/detail/CVE-2026-27654",
      "research": [
        {
          "url": "https://nginx.org/en/security_advisories.html",
          "type": "writeup",
          "source": "nginx.org",
          "note": "Official advisory, dav_module integer underflow"
        },
        {
          "url": "https://github.com/JohannesLks/CVE-2026-27654",
          "type": "poc",
          "source": "JohannesLks",
          "note": "dav_module heap overflow via size_t underflow PoC",
          "hasCode": true
        },
        {
          "url": "https://my.f5.com/manage/s/article/K000160382",
          "type": "writeup",
          "source": "F5",
          "note": "Vendor advisory for ngx_http_dav_module flaw"
        },
        {
          "url": "https://cvereports.com/reports/CVE-2026-27654",
          "type": "writeup",
          "source": "CVEReports",
          "note": "Heap overflow via integer underflow detail"
        }
      ],
      "x": {
        "mentions": 10,
        "posts": [
          {
            "handle": "calif_io",
            "followers": 4588,
            "likes": 177,
            "createdAt": "2026-04-10",
            "url": "https://x.com/calif_io/status/2042714973609300052",
            "origin": false,
            "github": []
          },
          {
            "handle": "tqbf",
            "followers": 35138,
            "likes": 156,
            "createdAt": "2026-04-11",
            "url": "https://x.com/tqbf/status/2043108338569748501",
            "origin": false,
            "github": []
          },
          {
            "handle": "Dinosn",
            "followers": 156829,
            "likes": 77,
            "createdAt": "2026-04-11",
            "url": "https://x.com/Dinosn/status/2042791435527733617",
            "origin": false,
            "github": []
          },
          {
            "handle": "_r_netsec",
            "followers": 33230,
            "likes": 3,
            "createdAt": "2026-04-11",
            "url": "https://x.com/_r_netsec/status/2042761570082787598",
            "origin": false,
            "github": []
          },
          {
            "handle": "msuiche",
            "followers": 1346,
            "likes": 1,
            "createdAt": "2026-04-10",
            "url": "https://x.com/msuiche/status/2042751279219265942",
            "origin": false,
            "github": []
          },
          {
            "handle": "spendergrsec",
            "followers": 6882,
            "likes": 1,
            "createdAt": "2026-04-10",
            "url": "https://x.com/spendergrsec/status/2042744095802638412",
            "origin": false,
            "github": []
          },
          {
            "handle": "f1tym1",
            "followers": 985,
            "likes": 0,
            "createdAt": "2026-05-20",
            "url": "https://x.com/f1tym1/status/2057046097747378547",
            "origin": false,
            "github": []
          },
          {
            "handle": "battista212",
            "followers": 246,
            "likes": 0,
            "createdAt": "2026-04-13",
            "url": "https://x.com/battista212/status/2043562876384743611",
            "origin": false,
            "github": []
          }
        ],
        "aliases": []
      },
      "researchers": [
        "johanneslks"
      ],
      "aliases": [],
      "bsky": {
        "mentions": 9,
        "posts": [
          {
            "handle": "o2cloud.bsky.social",
            "displayName": "CVE by o2Cloud",
            "likes": 0,
            "reposts": 1,
            "replies": 1,
            "createdAt": "2026-03-25",
            "url": "https://bsky.app/profile/o2cloud.bsky.social/post/3mhvcqjgua623",
            "origin": false,
            "authority": false,
            "github": []
          },
          {
            "handle": "getpokemon7.bsky.social",
            "displayName": "まりーん",
            "likes": 0,
            "reposts": 1,
            "replies": 0,
            "createdAt": "2026-03-29",
            "url": "https://bsky.app/profile/getpokemon7.bsky.social/post/3mi6rh36en22g",
            "origin": false,
            "authority": false,
            "github": []
          },
          {
            "handle": "cyberhub.blog",
            "displayName": "CyberHub",
            "likes": 0,
            "reposts": 1,
            "replies": 0,
            "createdAt": "2026-03-27",
            "url": "https://bsky.app/profile/cyberhub.blog/post/3mhzucnqzqi2c",
            "origin": false,
            "authority": false,
            "github": []
          },
          {
            "handle": "securitylab-jp.bsky.social",
            "displayName": "セキュリティ対策Lab",
            "likes": 0,
            "reposts": 1,
            "replies": 0,
            "createdAt": "2026-03-26",
            "url": "https://bsky.app/profile/securitylab-jp.bsky.social/post/3mhyp6sdl522z",
            "origin": false,
            "authority": false,
            "github": []
          },
          {
            "handle": "thehackerwire.bsky.social",
            "displayName": "TheHackerWire",
            "likes": 0,
            "reposts": 1,
            "replies": 0,
            "createdAt": "2026-03-24",
            "url": "https://bsky.app/profile/thehackerwire.bsky.social/post/3mhtojjur3i2w",
            "origin": false,
            "authority": false,
            "github": []
          },
          {
            "handle": "r-netsec.bsky.social",
            "displayName": "r/netsec bot",
            "likes": 0,
            "reposts": 0,
            "replies": 0,
            "createdAt": "2026-04-11",
            "url": "https://bsky.app/profile/r-netsec.bsky.social/post/3mj6tjayrlg2j",
            "origin": false,
            "authority": false,
            "github": []
          }
        ]
      }
    },
    {
      "cve": "CVE-2026-31717",
      "title": "In the Linux kernel, the following vulnerability has been resolved: ksmbd: validate…",
      "category": "Recall",
      "vendor": null,
      "exploited": false,
      "publiclyDisclosed": true,
      "cvss": 8.8,
      "cvssVector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "severity": "HIGH",
      "impact": null,
      "products": [],
      "productCount": 0,
      "faq": "In the Linux kernel, the following vulnerability has been resolved:\n\nksmbd: validate owner of durable handle on reconnect\n\nCurrently, ksmbd does not verify if the user attempting to reconnect\nto a durable handle is the same user who originally opened the file.\nThis allows any authenticated user to hijack an orphaned durable handle\nby predicting or brute-forcing the persistent ID.\n\nAccording to MS-SMB2, the server MUST verify that the SecurityContext\nof the reconnect request matches the SecurityContext associated with\nthe existing open.\nAdd a durable_owner structure to ksmbd_file to store the original opener's\nUID, GID, and account name. and catpure the owner information when a file\nhandle becomes orphaned. and implementing ksmbd_vfs_compare_durable_owner()\nto validate the identity of the requester during SMB2_CREATE (DHnC).",
      "pocConfidence": "confirmed",
      "pocCount": 1,
      "pocTopStars": 5,
      "pocRepos": [
        {
          "url": "https://github.com/TurtleARM/CVE-2026-31717-KSMBD-Exploit",
          "stars": 5,
          "desc": "",
          "createdAt": "2026-05-04",
          "hasCode": true
        }
      ],
      "epss": 0.00437,
      "epssPercentile": 0.35525,
      "source": "poc",
      "mitreUrl": "https://nvd.nist.gov/vuln/detail/CVE-2026-31717",
      "research": [
        {
          "url": "https://github.com/TurtleARM/CVE-2026-31717-KSMBD-Exploit",
          "type": "poc",
          "source": "TurtleARM",
          "note": "ksmbd durable handle hijack exploit",
          "hasCode": true
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-31717",
          "type": "writeup",
          "source": "NVD",
          "note": "ksmbd durable handle owner check missing"
        },
        {
          "url": "https://www.deepseas.com/resources/threat-intel/linux-kernel-ksmbd-use-after-free-vulnerability/",
          "type": "writeup",
          "source": "DeepSeas",
          "note": "ksmbd handle hijack threat intel"
        }
      ],
      "x": {
        "mentions": 2,
        "posts": [
          {
            "handle": "DFIR_Lab",
            "followers": 33,
            "likes": 0,
            "createdAt": "2026-05-23",
            "url": "https://x.com/DFIR_Lab/status/2057981171229757537",
            "origin": false,
            "github": []
          },
          {
            "handle": "VulmonFeeds",
            "followers": 4043,
            "likes": 0,
            "createdAt": "2026-05-01",
            "url": "https://x.com/VulmonFeeds/status/2050241038296461356",
            "origin": false,
            "github": []
          }
        ],
        "aliases": []
      },
      "researchers": [
        "turtlearm"
      ],
      "aliases": [],
      "bsky": {
        "mentions": 2,
        "posts": [
          {
            "handle": "thehackerwire.bsky.social",
            "displayName": "TheHackerWire",
            "likes": 0,
            "reposts": 0,
            "replies": 0,
            "createdAt": "2026-05-03",
            "url": "https://bsky.app/profile/thehackerwire.bsky.social/post/3mkxphbj5i52z",
            "origin": false,
            "authority": false,
            "github": []
          },
          {
            "handle": "cve.skyfleet.blue",
            "displayName": "CVE Alerts ",
            "likes": 0,
            "reposts": 0,
            "replies": 0,
            "createdAt": "2026-05-01",
            "url": "https://bsky.app/profile/cve.skyfleet.blue/post/3mksipq7khe2h",
            "origin": false,
            "authority": false,
            "github": []
          }
        ]
      }
    },
    {
      "cve": "CVE-2026-38194",
      "title": "This tool demonstrates CVE-2026-38194, a vulnerability in Teledyne Digital Imaging Sapera Memory Manager (v9.0.0.0 and below).  The CORMEM.SYS kernel driver exp",
      "category": "Recall",
      "vendor": null,
      "exploited": false,
      "publiclyDisclosed": true,
      "cvss": null,
      "cvssVector": null,
      "severity": null,
      "impact": null,
      "products": [],
      "productCount": 0,
      "faq": null,
      "pocConfidence": "confirmed",
      "pocCount": 1,
      "pocTopStars": 5,
      "pocRepos": [
        {
          "url": "https://github.com/4D4J/cormem-read-poc",
          "stars": 5,
          "desc": "This tool demonstrates CVE-2026-38194, a vulnerability in Teledyne Digital Imaging Sapera Memory Manager (v9.0.0.0 and below).  The CORMEM.SYS kernel driver exp",
          "createdAt": "2026-03-12",
          "hasCode": true
        }
      ],
      "epss": null,
      "epssPercentile": null,
      "source": "poc",
      "mitreUrl": "https://nvd.nist.gov/vuln/detail/CVE-2026-38194",
      "research": [],
      "aliases": [],
      "researchers": [],
      "x": {
        "mentions": 0,
        "aliases": [],
        "posts": []
      },
      "bsky": {
        "mentions": 0,
        "posts": []
      }
    },
    {
      "cve": "CVE-2026-47668",
      "title": "DbGate Unauthenticated Remote Code Execution",
      "category": "Recall",
      "vendor": null,
      "exploited": false,
      "publiclyDisclosed": true,
      "cvss": null,
      "cvssVector": null,
      "severity": null,
      "impact": null,
      "products": [],
      "productCount": 0,
      "faq": null,
      "pocConfidence": "confirmed",
      "pocCount": 1,
      "pocTopStars": 5,
      "pocRepos": [
        {
          "url": "https://github.com/Nxploited/CVE-2026-47668",
          "stars": 5,
          "desc": "DbGate Unauthenticated Remote Code Execution",
          "createdAt": "2026-05-26",
          "hasCode": true
        }
      ],
      "epss": null,
      "epssPercentile": null,
      "source": "poc",
      "mitreUrl": "https://nvd.nist.gov/vuln/detail/CVE-2026-47668",
      "research": [
        {
          "url": "https://advisories.gitlab.com/npm/dbgate-serve/CVE-2026-47668/",
          "type": "writeup",
          "source": "GitLab Advisories",
          "note": "Unauth RCE via JSON script runner functionName"
        }
      ],
      "x": {
        "mentions": 2,
        "aliases": [],
        "posts": [
          {
            "handle": "Nxploited",
            "followers": 107,
            "likes": 21,
            "createdAt": "2026-05-26",
            "url": "https://x.com/Nxploited/status/2059289020513890736",
            "github": [
              {
                "url": "https://github.com/Nxploited/CVE-2026-47668",
                "hasCode": true
              }
            ],
            "origin": false
          },
          {
            "handle": "vuln_tracker",
            "followers": 655,
            "likes": 0,
            "createdAt": "2026-05-27",
            "url": "https://x.com/vuln_tracker/status/2059537522699682183",
            "github": [],
            "origin": false
          }
        ]
      },
      "aliases": [],
      "researchers": [],
      "bsky": {
        "mentions": 1,
        "posts": [
          {
            "handle": "netsecio.bsky.social",
            "displayName": "CyberNetSecIO",
            "likes": 0,
            "reposts": 0,
            "replies": 0,
            "createdAt": "2026-06-08",
            "url": "https://bsky.app/profile/netsecio.bsky.social/post/3mns2hhdcna2y",
            "origin": false,
            "authority": false,
            "github": []
          }
        ]
      }
    },
    {
      "cve": "CVE-2026-53435",
      "title": "In Jenkins 2.567 and earlier, LTS 2.555.2 and earlier, it is possible for attackers…",
      "category": "Recall",
      "vendor": null,
      "exploited": false,
      "publiclyDisclosed": true,
      "cvss": 8.8,
      "cvssVector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "severity": "HIGH",
      "impact": null,
      "products": [],
      "productCount": 0,
      "faq": "In Jenkins 2.567 and earlier, LTS 2.555.2 and earlier, it is possible for attackers to have Jenkins deserialize arbitrary types defined in Jenkins core or plugins from an attacker-controlled `config.xml` submission in a way that allows them to handle HTTP requests afterwards.\nThis can be used to impersonate any user and send HTTP requests on their behalf, up to and including use of the Script Console to run arbitrary code, or to read arbitrary files from the Jenkins controller.",
      "pocConfidence": "confirmed",
      "pocCount": 1,
      "pocTopStars": 5,
      "pocRepos": [
        {
          "url": "https://github.com/AmesianX/CVE-2026-53435",
          "stars": 5,
          "desc": "An offensive security researcher + an AI vs. a fresh n-day: building the first public PoC for CVE-2026-53435 in one Friday night. Raw 8h20m log inside.",
          "createdAt": "2026-06-12",
          "hasCode": true
        }
      ],
      "epss": 0.14907,
      "epssPercentile": 0.96333,
      "source": "poc",
      "mitreUrl": "https://nvd.nist.gov/vuln/detail/CVE-2026-53435",
      "research": [],
      "aliases": [],
      "researchers": [],
      "x": {
        "mentions": 0,
        "aliases": [],
        "posts": []
      },
      "bsky": {
        "mentions": 11,
        "posts": [
          {
            "handle": "rxerium.com",
            "displayName": "Rishi",
            "likes": 1,
            "reposts": 0,
            "replies": 0,
            "createdAt": "2026-06-16",
            "url": "https://bsky.app/profile/rxerium.com/post/3mofeg6jzuc2t",
            "origin": false,
            "authority": false,
            "github": [
              {
                "url": "https://github.com/rxerium/rxerium-templates/blob/main/2026/CVE-2026-53435.yaml",
                "hasCode": true
              }
            ]
          },
          {
            "handle": "kitafox.bsky.social",
            "displayName": "キタきつね",
            "likes": 2,
            "reposts": 0,
            "replies": 2,
            "createdAt": "2026-06-16",
            "url": "https://bsky.app/profile/kitafox.bsky.social/post/3moejpxt2zv2j",
            "origin": false,
            "authority": false,
            "github": []
          },
          {
            "handle": "mineabot.xyz",
            "displayName": "MineaBot",
            "likes": 3,
            "reposts": 0,
            "replies": 0,
            "createdAt": "2026-06-21",
            "url": "https://bsky.app/profile/mineabot.xyz/post/3morblcrzr72o",
            "origin": false,
            "authority": false,
            "github": []
          },
          {
            "handle": "opsmatters.com",
            "displayName": "OpsMatters",
            "likes": 0,
            "reposts": 1,
            "replies": 0,
            "createdAt": "2026-06-29",
            "url": "https://bsky.app/profile/opsmatters.com/post/3mpfmiio4tu2l",
            "origin": false,
            "authority": false,
            "github": []
          },
          {
            "handle": "thecybersecguru.com",
            "displayName": "The CyberSec Guru",
            "likes": 0,
            "reposts": 1,
            "replies": 0,
            "createdAt": "2026-06-15",
            "url": "https://bsky.app/profile/thecybersecguru.com/post/3modcvycfss2c",
            "origin": false,
            "authority": false,
            "github": []
          },
          {
            "handle": "blackhatnews.tokyo",
            "displayName": "blackhatnews.tokyo",
            "likes": 0,
            "reposts": 1,
            "replies": 0,
            "createdAt": "2026-06-15",
            "url": "https://bsky.app/profile/blackhatnews.tokyo/post/3modbmuwcge2d",
            "origin": false,
            "authority": false,
            "github": []
          }
        ]
      }
    },
    {
      "cve": "CVE-2026-12191",
      "title": "A vulnerability was found in Comma AI Openpilot 0.11. This issue affects the function…",
      "category": "Recall",
      "vendor": null,
      "exploited": false,
      "publiclyDisclosed": true,
      "cvss": 7.8,
      "cvssVector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "severity": "HIGH",
      "published": "2026-06-14T23:16:35.993",
      "impact": null,
      "products": [],
      "productCount": 0,
      "faq": "A vulnerability was found in Comma AI Openpilot 0.11. This issue affects the function pickle.load/pickle.loads of the file selfdrive/modeld/modeld.py of the component Pickle Module. The manipulation results in deserialization. The attack is only possible with local access. The vendor was contacted early about this disclosure but did not respond in any way.",
      "pocConfidence": "confirmed",
      "pocCount": 1,
      "pocTopStars": 4,
      "pocRepos": [
        {
          "url": "https://github.com/hakaioffsec/CVE-2026-12191",
          "stars": 4,
          "desc": "PoC for CVE-2026-12191",
          "createdAt": "2026-07-20",
          "hasCode": true
        }
      ],
      "epss": 0.00137,
      "epssPercentile": 0.03495,
      "source": "poc",
      "mitreUrl": "https://nvd.nist.gov/vuln/detail/CVE-2026-12191",
      "bsky": {
        "mentions": 2,
        "engagement": 2,
        "posts": [
          {
            "handle": "thehackerwire.bsky.social",
            "displayName": "TheHackerWire",
            "likes": 0,
            "reposts": 1,
            "replies": 0,
            "createdAt": "2026-06-15",
            "url": "https://bsky.app/profile/thehackerwire.bsky.social/post/3moby3piree2c",
            "origin": false,
            "authority": false,
            "github": []
          },
          {
            "handle": "cve.skyfleet.blue",
            "displayName": "CVE Alerts ",
            "likes": 0,
            "reposts": 1,
            "replies": 0,
            "createdAt": "2026-06-15",
            "url": "https://bsky.app/profile/cve.skyfleet.blue/post/3mobyjqsopj2o",
            "origin": false,
            "authority": false,
            "github": []
          }
        ]
      }
    },
    {
      "cve": "CVE-2026-39047",
      "title": "Buffer Overflow vulnerability in EPSON L14150 FL27PB allows a remote attacker to…",
      "category": "Recall",
      "vendor": null,
      "exploited": false,
      "publiclyDisclosed": true,
      "cvss": 7.5,
      "cvssVector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
      "severity": "HIGH",
      "impact": null,
      "products": [],
      "productCount": 0,
      "faq": "Buffer Overflow vulnerability in EPSON L14150 FL27PB allows a remote attacker to execute arbitrary code via the RAW Printing Service (JetDirect) on TCP port 9100",
      "pocConfidence": "confirmed",
      "pocCount": 1,
      "pocTopStars": 4,
      "pocRepos": [
        {
          "url": "https://github.com/J4ck3LSyN-Gen2/CVE-2026-39047",
          "stars": 4,
          "desc": "Epson Printer RAW Protocol Exploit Framework",
          "createdAt": "2026-07-05",
          "hasCode": true
        }
      ],
      "epss": 0.00648,
      "epssPercentile": 0.4705,
      "source": "poc",
      "mitreUrl": "https://nvd.nist.gov/vuln/detail/CVE-2026-39047",
      "research": [],
      "aliases": [],
      "researchers": [],
      "x": {
        "mentions": 0,
        "aliases": [],
        "posts": []
      },
      "bsky": {
        "mentions": 2,
        "posts": [
          {
            "handle": "thehackerwire.bsky.social",
            "displayName": "TheHackerWire",
            "likes": 1,
            "reposts": 0,
            "replies": 0,
            "createdAt": "2026-05-20",
            "url": "https://bsky.app/profile/thehackerwire.bsky.social/post/3mmcozwcu5h2q",
            "origin": false,
            "authority": false,
            "github": []
          },
          {
            "handle": "postac001.bsky.social",
            "displayName": "tec_acc",
            "likes": 1,
            "reposts": 0,
            "replies": 0,
            "createdAt": "2026-05-20",
            "url": "https://bsky.app/profile/postac001.bsky.social/post/3mmcib4y7ky2w",
            "origin": false,
            "authority": false,
            "github": []
          }
        ]
      }
    },
    {
      "cve": "CVE-2026-47729",
      "title": "CVE-2026-47729",
      "category": "Recall",
      "vendor": null,
      "exploited": false,
      "publiclyDisclosed": true,
      "cvss": null,
      "cvssVector": null,
      "severity": null,
      "impact": null,
      "products": [],
      "productCount": 0,
      "faq": null,
      "pocConfidence": "confirmed",
      "pocCount": 1,
      "pocTopStars": 4,
      "pocRepos": [
        {
          "url": "https://github.com/0xBlackash/CVE-2026-47729",
          "stars": 4,
          "desc": "CVE-2026-47729",
          "createdAt": "2026-06-21",
          "hasCode": true
        }
      ],
      "epss": 0.01949,
      "epssPercentile": 0.78019,
      "source": "poc",
      "mitreUrl": "https://nvd.nist.gov/vuln/detail/CVE-2026-47729",
      "research": [],
      "aliases": [],
      "researchers": [],
      "x": {
        "mentions": 0,
        "aliases": [],
        "posts": []
      },
      "bsky": {
        "mentions": 16,
        "posts": [
          {
            "handle": "stanislavfort.bsky.social",
            "displayName": "Stanislav Fort",
            "likes": 21,
            "reposts": 2,
            "replies": 2,
            "createdAt": "2026-06-25",
            "url": "https://bsky.app/profile/stanislavfort.bsky.social/post/3mp4dfazza22u",
            "origin": false,
            "authority": false,
            "github": []
          },
          {
            "handle": "lalgorisme.bsky.social",
            "displayName": "L'algorisme",
            "likes": 1,
            "reposts": 2,
            "replies": 1,
            "createdAt": "2026-06-23",
            "url": "https://bsky.app/profile/lalgorisme.bsky.social/post/3mowu7czs222r",
            "origin": false,
            "authority": false,
            "github": []
          },
          {
            "handle": "securityrss.bsky.social",
            "displayName": "securityrss.ai",
            "likes": 2,
            "reposts": 1,
            "replies": 0,
            "createdAt": "2026-06-23",
            "url": "https://bsky.app/profile/securityrss.bsky.social/post/3mowwtk74ps2u",
            "origin": false,
            "authority": false,
            "github": []
          },
          {
            "handle": "hacker.at.thenote.app",
            "displayName": "Hacker & Security News",
            "likes": 1,
            "reposts": 1,
            "replies": 0,
            "createdAt": "2026-06-24",
            "url": "https://bsky.app/profile/hacker.at.thenote.app/post/3moyp65qcz227",
            "origin": false,
            "authority": false,
            "github": []
          },
          {
            "handle": "e-kiledjian.bsky.social",
            "displayName": null,
            "likes": 1,
            "reposts": 1,
            "replies": 0,
            "createdAt": "2026-06-23",
            "url": "https://bsky.app/profile/e-kiledjian.bsky.social/post/3moy7m74gbk2k",
            "origin": false,
            "authority": false,
            "github": []
          },
          {
            "handle": "argusflow.bsky.social",
            "displayName": "Argus Flow - Breach News",
            "likes": 2,
            "reposts": 0,
            "replies": 0,
            "createdAt": "2026-06-22",
            "url": "https://bsky.app/profile/argusflow.bsky.social/post/3mov5qycgcc2u",
            "origin": false,
            "authority": false,
            "github": []
          }
        ]
      }
    },
    {
      "cve": "CVE-2026-50656",
      "title": "Microsoft is aware of an elevation of privilege in the Microsoft Malware Protection…",
      "category": "Recall",
      "vendor": null,
      "exploited": false,
      "publiclyDisclosed": true,
      "cvss": 7.8,
      "cvssVector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "severity": "HIGH",
      "impact": null,
      "products": [],
      "productCount": 0,
      "faq": "Microsoft is aware of an elevation of privilege in the Microsoft Malware Protection Engine in Microsoft Defender publicly referred to as &quot;RoguePlanet &quot;. We are working to provide a high quality security update that addresses this vulnerability. We will provide information in this CVE when the update is available.",
      "pocConfidence": "confirmed",
      "pocCount": 1,
      "pocTopStars": 4,
      "pocRepos": [
        {
          "url": "https://github.com/0xBlackash/CVE-2026-50656",
          "stars": 4,
          "desc": "CVE-2026-50656",
          "createdAt": "2026-06-18",
          "hasCode": true
        }
      ],
      "epss": 0.03391,
      "epssPercentile": 0.87509,
      "source": "poc",
      "mitreUrl": "https://nvd.nist.gov/vuln/detail/CVE-2026-50656",
      "research": [],
      "aliases": [],
      "researchers": [],
      "x": {
        "mentions": 4,
        "aliases": [],
        "posts": [
          {
            "handle": "dari99u",
            "followers": 2825,
            "likes": 4,
            "createdAt": "2026-07-07",
            "url": "https://x.com/dari99u/status/2074307502074724705",
            "github": [],
            "origin": false
          }
        ]
      },
      "bsky": {
        "mentions": 18,
        "posts": [
          {
            "handle": "infosec.skyfleet.blue",
            "displayName": "InfoSec",
            "likes": 1,
            "reposts": 0,
            "replies": 0,
            "createdAt": "2026-07-09",
            "url": "https://bsky.app/profile/infosec.skyfleet.blue/post/3mq7ju33bt42y",
            "origin": false,
            "authority": true,
            "github": []
          },
          {
            "handle": "iberianm.bsky.social",
            "displayName": "Citizen X",
            "likes": 2,
            "reposts": 1,
            "replies": 0,
            "createdAt": "2026-06-17",
            "url": "https://bsky.app/profile/iberianm.bsky.social/post/3moj43bau7u2y",
            "origin": false,
            "authority": false,
            "github": []
          },
          {
            "handle": "termsofsurrender.bsky.social",
            "displayName": "AfterShock Index",
            "likes": 1,
            "reposts": 0,
            "replies": 1,
            "createdAt": "2026-07-10",
            "url": "https://bsky.app/profile/termsofsurrender.bsky.social/post/3mqbuz5pqwg26",
            "origin": false,
            "authority": false,
            "github": []
          },
          {
            "handle": "suriq.io",
            "displayName": "Suriq - Always on Watch",
            "likes": 2,
            "reposts": 0,
            "replies": 0,
            "createdAt": "2026-06-18",
            "url": "https://bsky.app/profile/suriq.io/post/3mok672fsbj2d",
            "origin": false,
            "authority": false,
            "github": []
          },
          {
            "handle": "helpnetsecurity.com",
            "displayName": "Help Net Security",
            "likes": 1,
            "reposts": 1,
            "replies": 0,
            "createdAt": "2026-06-17",
            "url": "https://bsky.app/profile/helpnetsecurity.com/post/3moi7sqg3ec2g",
            "origin": false,
            "authority": false,
            "github": []
          },
          {
            "handle": "postac001.bsky.social",
            "displayName": "tec_acc",
            "likes": 1,
            "reposts": 1,
            "replies": 0,
            "createdAt": "2026-06-17",
            "url": "https://bsky.app/profile/postac001.bsky.social/post/3moj4ehglr32g",
            "origin": false,
            "authority": false,
            "github": []
          }
        ]
      }
    },
    {
      "cve": "CVE-2026-9067",
      "title": "The Schema & Structured Data for WP & AMP WordPress plugin before 1.60 does not check…",
      "category": "Recall",
      "vendor": null,
      "exploited": false,
      "publiclyDisclosed": true,
      "cvss": 9.1,
      "cvssVector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N",
      "severity": "CRITICAL",
      "impact": null,
      "products": [],
      "productCount": 0,
      "faq": "The Schema & Structured Data for WP & AMP WordPress plugin before 1.60 does not check user capabilities on its frontend AJAX file-upload handlers and does not validate the actual content of uploaded files against the endpoint's intended media type, allowing unauthenticated users to upload any file type accepted by WordPress's media library through endpoints that should only accept images or videos.",
      "pocConfidence": "confirmed",
      "pocCount": 1,
      "pocTopStars": 3,
      "pocRepos": [
        {
          "url": "https://github.com/Polosss/By-Poloss..-..CVE-2026-9067",
          "stars": 3,
          "desc": "Schema & Structured Data for WP & AMP < 1.60 - Unauthenticated Arbitrary Media Upload [POC & Xploit]",
          "createdAt": "2026-06-10",
          "hasCode": true
        }
      ],
      "epss": 0.00426,
      "epssPercentile": 0.34655,
      "source": "poc",
      "mitreUrl": "https://nvd.nist.gov/vuln/detail/CVE-2026-9067",
      "research": [
        {
          "url": "https://wpscan.com/vulnerability/7fac98eb-f82c-4705-a956-aba650945826/",
          "type": "writeup",
          "source": "WPScan / 0xBassia",
          "note": "Original disclosure; verified by WPScan"
        },
        {
          "url": "https://github.com/0xBassia",
          "type": "poc",
          "source": "0xBassia (Mohamed Bassia)",
          "note": "Researcher's GitHub; credited CVE-2026-9067 PoC"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-9067",
          "type": "writeup",
          "source": "NVD/NIST",
          "note": "Official NVD entry, CVSS 9.1 Critical"
        },
        {
          "url": "https://github.com/advisories/GHSA-cwcg-79p4-f24h",
          "type": "writeup",
          "source": "GitHub Advisory Database",
          "note": "GHSA entry, CWE-434, published Jun 10 2026",
          "hasCode": null
        },
        {
          "url": "https://www.ionix.io/threat-center/cve-2026-9067/",
          "type": "writeup",
          "source": "IONIX Threat Center",
          "note": "Technical root-cause & exploitation analysis"
        },
        {
          "url": "https://freshysites.com/security-bulletins/schema-structured-data-for-wp-amp-plugin-vulnerability-cve-2026-9067/",
          "type": "detection",
          "source": "Freshy Sites",
          "note": "Defensive bulletin; patch & mitigation guidance"
        },
        {
          "url": "https://radar.offseq.com/threat/cve-2026-9067-cwe-434-unrestricted-upload-of-file--11f8ff3d",
          "type": "detection",
          "source": "OffSeq Threat Radar",
          "note": "Live threat-intel feed; WAF/access control advice"
        }
      ],
      "aliases": [],
      "researchers": [
        "MohamedBassia"
      ],
      "x": {
        "mentions": 61,
        "aliases": [],
        "posts": [
          {
            "handle": "MalwareObserver",
            "followers": 11,
            "likes": 0,
            "createdAt": "2026-07-20",
            "url": "https://x.com/MalwareObserver/status/2079280525265514912",
            "github": [
              {
                "url": "https://github.com/chamilo/chamilo-lms/security/advisories/GHSA-gcjp-f7jm-rrrg",
                "hasCode": true
              },
              {
                "url": "https://github.com/chamilo/chamilo-lms/security/advisories/GHSA-gcjp-f7jm-rrrg",
                "hasCode": true
              }
            ],
            "origin": false
          },
          {
            "handle": "MalwareBibleJP",
            "followers": 7683,
            "likes": 9,
            "createdAt": "2026-07-20",
            "url": "https://x.com/MalwareBibleJP/status/2079323720771088529",
            "github": [],
            "origin": false
          },
          {
            "handle": "LupovisDefence",
            "followers": 575,
            "likes": 5,
            "createdAt": "2026-07-20",
            "url": "https://x.com/LupovisDefence/status/2079290355443269739",
            "github": [],
            "origin": false
          },
          {
            "handle": "yousukezan",
            "followers": 14471,
            "likes": 4,
            "createdAt": "2026-07-20",
            "url": "https://x.com/yousukezan/status/2079344854665187623",
            "github": [],
            "origin": false
          },
          {
            "handle": "thingwhere",
            "followers": 8,
            "likes": 4,
            "createdAt": "2026-07-20",
            "url": "https://x.com/thingwhere/status/2079330106921607615",
            "github": [],
            "origin": false
          },
          {
            "handle": "Horizon3ai",
            "followers": 2894,
            "likes": 2,
            "createdAt": "2026-07-20",
            "url": "https://x.com/Horizon3ai/status/2079336182480257029",
            "github": [],
            "origin": false
          },
          {
            "handle": "__su888",
            "followers": 853,
            "likes": 2,
            "createdAt": "2026-07-20",
            "url": "https://x.com/__su888/status/2079325728181518491",
            "github": [],
            "origin": false
          },
          {
            "handle": "orcasec",
            "followers": 4829,
            "likes": 1,
            "createdAt": "2026-07-20",
            "url": "https://x.com/orcasec/status/2079287728030798288",
            "github": [],
            "origin": false
          }
        ]
      },
      "bsky": {
        "mentions": 3,
        "posts": [
          {
            "handle": "thehackerwire.bsky.social",
            "displayName": "TheHackerWire",
            "likes": 0,
            "reposts": 0,
            "replies": 0,
            "createdAt": "2026-06-10",
            "url": "https://bsky.app/profile/thehackerwire.bsky.social/post/3mnwnyzy6sa26",
            "origin": false,
            "authority": false,
            "github": []
          },
          {
            "handle": "cve.skyfleet.blue",
            "displayName": "CVE Alerts ",
            "likes": 0,
            "reposts": 0,
            "replies": 0,
            "createdAt": "2026-06-10",
            "url": "https://bsky.app/profile/cve.skyfleet.blue/post/3mnwkswfh3g2u",
            "origin": false,
            "authority": false,
            "github": []
          },
          {
            "handle": "pulse-wp.com",
            "displayName": "Pulse WP",
            "likes": 0,
            "reposts": 0,
            "replies": 0,
            "createdAt": "2026-06-10",
            "url": "https://bsky.app/profile/pulse-wp.com/post/3mnwnygdhh62q",
            "origin": false,
            "authority": false,
            "github": []
          }
        ]
      }
    },
    {
      "cve": "CVE-2026-57829",
      "title": "The Joomla extension Helix Ultimate is vulnerable to an unauthenticated stored",
      "category": "Recall",
      "vendor": null,
      "exploited": false,
      "publiclyDisclosed": true,
      "cvss": 6.1,
      "cvssVector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N",
      "severity": "MEDIUM",
      "impact": null,
      "products": [],
      "productCount": 0,
      "faq": "The Joomla extension Helix Ultimate is vulnerable to an unauthenticated stored XSS.",
      "pocConfidence": "confirmed",
      "pocCount": 1,
      "pocTopStars": 3,
      "pocRepos": [
        {
          "url": "https://github.com/Is4yev/CVE-2026-57829",
          "stars": 3,
          "desc": "Unauthenticated Stored XSS in Joomla Helix Ultimate (JoomShaper) <= 2.2.6",
          "createdAt": "2026-07-13",
          "hasCode": true
        }
      ],
      "epss": 0.00149,
      "epssPercentile": 0.04536,
      "source": "poc",
      "mitreUrl": "https://nvd.nist.gov/vuln/detail/CVE-2026-57829",
      "research": [
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-57829",
          "type": "detection",
          "source": "NVD / NIST",
          "note": "Official CVE record; maps to Centreon SSTI per GH Advisory"
        },
        {
          "url": "https://mysites.guru/blog/helix-ultimate-security-update/",
          "type": "writeup",
          "source": "mySites.guru (Phil Taylor)",
          "note": "Technical breakdown: unauth stored XSS via com_ajax"
        },
        {
          "url": "https://website-bereinigung.de/en/blog/helix-ultimate-sicherheitsluecke-joomla",
          "type": "writeup",
          "source": "website-bereinigung.de",
          "note": "Analysis of stored XSS + path traversal in Helix Ultimate"
        },
        {
          "url": "https://htprotect.org/en/helix-ultimate",
          "type": "detection",
          "source": "HTProtect.org",
          "note": "Defensive guide: update to 2.2.7/2.2.8, no CVE assigned yet"
        },
        {
          "url": "https://forum.directadmin.com/threads/new-severe-holes-in-helix-ultimate-framework-for-joomla-in-all-versions-before-2-2-7.82397/",
          "type": "writeup",
          "source": "DirectAdmin Forums",
          "note": "Hole summary: stored XSS, path traversal, open redirect"
        },
        {
          "url": "https://github.com/advisories/GHSA-xr7r-292v-jxg8",
          "type": "detection",
          "source": "GitHub Advisory Database",
          "note": "CVE-2026-49049 Helix3 variant advisory (separate product)",
          "hasCode": null
        },
        {
          "url": "https://mysites.guru/blog/helix3-security-update-changelog-failure/",
          "type": "writeup",
          "source": "mySites.guru (Phil Taylor)",
          "note": "Helix3 disclosure timeline; PoC withheld; CVE pending"
        },
        {
          "url": "https://website-bereinigung.de/en/blog/hacked-by-antonkill-helix3",
          "type": "detection",
          "source": "website-bereinigung.de",
          "note": "AntonKill/trenggalek6etar botnet wave exploiting Helix3"
        }
      ],
      "aliases": [],
      "researchers": [],
      "x": {
        "mentions": 2,
        "aliases": [],
        "posts": [
          {
            "handle": "Is4yev",
            "followers": 0,
            "likes": 0,
            "createdAt": "2026-07-13",
            "url": "https://x.com/Is4yev/status/2076581312501068045",
            "github": [
              {
                "url": "http://github.com/Is4yev/CVE-2026-57829",
                "hasCode": true
              }
            ],
            "origin": false
          },
          {
            "handle": "ptdbugs",
            "followers": 2380,
            "likes": 6,
            "createdAt": "2026-07-13",
            "url": "https://x.com/ptdbugs/status/2076660638453989748",
            "github": [],
            "origin": false
          }
        ]
      },
      "bsky": {
        "mentions": 7,
        "posts": [
          {
            "handle": "cyberhub.blog",
            "displayName": "CyberHub",
            "likes": 1,
            "reposts": 0,
            "replies": 0,
            "createdAt": "2026-07-15",
            "url": "https://bsky.app/profile/cyberhub.blog/post/3mqooorqifu2m",
            "origin": false,
            "authority": false,
            "github": []
          },
          {
            "handle": "cve.skyfleet.blue",
            "displayName": "CVE Alerts ",
            "likes": 1,
            "reposts": 0,
            "replies": 0,
            "createdAt": "2026-07-13",
            "url": "https://bsky.app/profile/cve.skyfleet.blue/post/3mqjgfknb6q2g",
            "origin": false,
            "authority": false,
            "github": []
          },
          {
            "handle": "suriq.io",
            "displayName": "Suriq - Always on Watch",
            "likes": 1,
            "reposts": 0,
            "replies": 0,
            "createdAt": "2026-07-13",
            "url": "https://bsky.app/profile/suriq.io/post/3mqjbhlhal325",
            "origin": false,
            "authority": false,
            "github": []
          },
          {
            "handle": "kriptabiz.bsky.social",
            "displayName": "kripta.biz",
            "likes": 0,
            "reposts": 0,
            "replies": 0,
            "createdAt": "2026-07-14",
            "url": "https://bsky.app/profile/kriptabiz.bsky.social/post/3mqlbwxlnoy2d",
            "origin": false,
            "authority": false,
            "github": []
          },
          {
            "handle": "qiancx.bsky.social",
            "displayName": "qian.cx",
            "likes": 0,
            "reposts": 0,
            "replies": 0,
            "createdAt": "2026-07-14",
            "url": "https://bsky.app/profile/qiancx.bsky.social/post/3mqlbwxucwb2d",
            "origin": false,
            "authority": false,
            "github": []
          }
        ]
      }
    },
    {
      "cve": "CVE-2026-57830",
      "title": "The Joomla extension Helix Ultimate is vulnerable to an unauthenticated arbitrary…",
      "category": "Recall",
      "vendor": null,
      "exploited": false,
      "publiclyDisclosed": true,
      "cvss": 9.1,
      "cvssVector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H",
      "severity": "CRITICAL",
      "impact": null,
      "products": [],
      "productCount": 0,
      "faq": "The Joomla extension Helix Ultimate is vulnerable to an unauthenticated arbitrary file deletion.",
      "pocConfidence": "confirmed",
      "pocCount": 1,
      "pocTopStars": 3,
      "pocRepos": [
        {
          "url": "https://github.com/Is4yev/CVE-2026-57830",
          "stars": 3,
          "desc": "Unauthenticated Arbitrary File/Folder Deletion in Joomla Helix Ultimate (JoomShaper) <= 2.2.6 — CVE-2026-57830",
          "createdAt": "2026-07-13",
          "hasCode": true
        }
      ],
      "epss": 0.00243,
      "epssPercentile": 0.15534,
      "source": "poc",
      "mitreUrl": "https://nvd.nist.gov/vuln/detail/CVE-2026-57830",
      "research": [
        {
          "url": "https://github.com/advisories?query=CVE-2026-57830",
          "type": "detection",
          "source": "GitHub Advisory Database",
          "note": "Official GHSA entry; High/Unreviewed, no linked PoC"
        },
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-57830",
          "type": "detection",
          "source": "NVD / NIST",
          "note": "NVD record; unauthenticated file deletion, Helix Ultimate"
        },
        {
          "url": "https://mysites.guru/blog/helix-ultimate-security-update/",
          "type": "writeup",
          "source": "mySites.guru (Phil Taylor)",
          "note": "Patch-diff analysis; XSS, file delete, open redirect"
        },
        {
          "url": "https://htprotect.org/en/helix-ultimate",
          "type": "detection",
          "source": "HTProtect.org",
          "note": "Remediation guide; update to 2.2.8+, IOC checks"
        },
        {
          "url": "https://website-bereinigung.de/en/blog/helix-ultimate-sicherheitsluecke-joomla",
          "type": "writeup",
          "source": "website-bereinigung.de",
          "note": "Technical overview; unauthenticated AJAX handler abuse"
        },
        {
          "url": "https://www.ionix.io/threat-center/cve-2026-49049/",
          "type": "writeup",
          "source": "IONIX Threat Center",
          "note": "Sibling Helix3 CVE-2026-49049; same AJAX root cause"
        },
        {
          "url": "https://website-bereinigung.de/en/blog/hacked-by-antonkill-helix3",
          "type": "writeup",
          "source": "website-bereinigung.de",
          "note": "Wild exploitation wave; AntonKill botnet, Helix3 sibling"
        },
        {
          "url": "https://mysites.guru/blog/helix3-security-update-changelog-failure/",
          "type": "writeup",
          "source": "mySites.guru (Phil Taylor)",
          "note": "Helix3 sibling flaw disclosure; same AJAX pattern, ITW"
        }
      ],
      "aliases": [],
      "researchers": [],
      "x": {
        "mentions": 2,
        "aliases": [],
        "posts": [
          {
            "handle": "Is4yev",
            "followers": 0,
            "likes": 0,
            "createdAt": "2026-07-13",
            "url": "https://x.com/Is4yev/status/2076581444655149491",
            "github": [
              {
                "url": "http://github.com/Is4yev/CVE-2026-57830",
                "hasCode": true
              }
            ],
            "origin": false
          },
          {
            "handle": "ptdbugs",
            "followers": 2380,
            "likes": 8,
            "createdAt": "2026-07-13",
            "url": "https://x.com/ptdbugs/status/2076673230417371222",
            "github": [],
            "origin": false
          }
        ]
      },
      "bsky": {
        "mentions": 6,
        "posts": [
          {
            "handle": "cve.skyfleet.blue",
            "displayName": "CVE Alerts ",
            "likes": 1,
            "reposts": 1,
            "replies": 0,
            "createdAt": "2026-07-13",
            "url": "https://bsky.app/profile/cve.skyfleet.blue/post/3mqjgb3ax5z2x",
            "origin": false,
            "authority": false,
            "github": []
          },
          {
            "handle": "pmloik.bsky.social",
            "displayName": null,
            "likes": 0,
            "reposts": 0,
            "replies": 0,
            "createdAt": "2026-07-14",
            "url": "https://bsky.app/profile/pmloik.bsky.social/post/3mqlornb55u24",
            "origin": false,
            "authority": false,
            "github": []
          },
          {
            "handle": "kriptabiz.bsky.social",
            "displayName": "kripta.biz",
            "likes": 0,
            "reposts": 0,
            "replies": 0,
            "createdAt": "2026-07-14",
            "url": "https://bsky.app/profile/kriptabiz.bsky.social/post/3mqlc2obyag2x",
            "origin": false,
            "authority": false,
            "github": []
          },
          {
            "handle": "qiancx.bsky.social",
            "displayName": "qian.cx",
            "likes": 0,
            "reposts": 0,
            "replies": 0,
            "createdAt": "2026-07-14",
            "url": "https://bsky.app/profile/qiancx.bsky.social/post/3mqlc2ofxiw2f",
            "origin": false,
            "authority": false,
            "github": []
          }
        ]
      },
      "telegram": {
        "mentions": 0,
        "posts": []
      }
    },
    {
      "cve": "CVE-2026-8713",
      "title": "The Avada (Fusion) Builder plugin for WordPress is vulnerable to arbitrary file…",
      "category": "Recall",
      "vendor": null,
      "exploited": false,
      "publiclyDisclosed": true,
      "cvss": 9.1,
      "cvssVector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H",
      "severity": "CRITICAL",
      "impact": null,
      "products": [],
      "productCount": 0,
      "faq": "The Avada (Fusion) Builder plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the maybe_delete_files function in all versions up to, and including, 3.15.3. This makes it possible for unauthenticated attackers to delete arbitrary files on the server, which can easily lead to remote code execution when the right file is deleted (such as wp-config.php). The attack requires a published Avada form configured to save entries to the database; an unauthenticated attacker submits a path-traversal payload via the wp_ajax_nopriv_fusion_form_submit_ajax handler while also controlling the fusion_privacy_expiration_interval and privacy_expiration_action fields to force an immediate 'delete' cleanup, causing the planted entry to be automatically processed by the Fusion_Form_DB_Privacy shutdown-hook routine without any administrator interaction.",
      "pocConfidence": "confirmed",
      "pocCount": 1,
      "pocTopStars": 3,
      "pocRepos": [
        {
          "url": "https://github.com/shinthink/CVE-2026-8713",
          "stars": 3,
          "desc": "Pre-auth path traversal to arbitrary file delete in Avada (Fusion) Builder <= 3.15.3 leading to RCE (CVSS 9.1)",
          "createdAt": "2026-07-05",
          "hasCode": true
        }
      ],
      "epss": 0.01193,
      "epssPercentile": 0.646,
      "source": "poc",
      "mitreUrl": "https://nvd.nist.gov/vuln/detail/CVE-2026-8713",
      "research": [],
      "aliases": [],
      "researchers": [],
      "x": {
        "mentions": 3,
        "aliases": [],
        "posts": [
          {
            "handle": "ptdbugs",
            "followers": 2267,
            "likes": 40,
            "createdAt": "2026-07-06",
            "url": "https://x.com/ptdbugs/status/2074059599276134521",
            "github": [],
            "origin": false
          }
        ]
      },
      "bsky": {
        "mentions": 10,
        "posts": [
          {
            "handle": "ahmandonk.bsky.social",
            "displayName": "Ahmandonk",
            "likes": 1,
            "reposts": 1,
            "replies": 0,
            "createdAt": "2026-06-21",
            "url": "https://bsky.app/profile/ahmandonk.bsky.social/post/3mosdmdph4v2t",
            "origin": false,
            "authority": false,
            "github": []
          },
          {
            "handle": "undercodenews.bsky.social",
            "displayName": "Undercode News",
            "likes": 1,
            "reposts": 1,
            "replies": 0,
            "createdAt": "2026-06-19",
            "url": "https://bsky.app/profile/undercodenews.bsky.social/post/3mongltu7ft2a",
            "origin": false,
            "authority": false,
            "github": []
          },
          {
            "handle": "pmloik.bsky.social",
            "displayName": null,
            "likes": 0,
            "reposts": 1,
            "replies": 0,
            "createdAt": "2026-06-20",
            "url": "https://bsky.app/profile/pmloik.bsky.social/post/3moostal2o52d",
            "origin": false,
            "authority": false,
            "github": []
          },
          {
            "handle": "offseq.bsky.social",
            "displayName": "OffSequence",
            "likes": 0,
            "reposts": 1,
            "replies": 0,
            "createdAt": "2026-06-19",
            "url": "https://bsky.app/profile/offseq.bsky.social/post/3mon563pgxv2l",
            "origin": false,
            "authority": false,
            "github": []
          },
          {
            "handle": "blackhatnews.tokyo",
            "displayName": "blackhatnews.tokyo",
            "likes": 0,
            "reposts": 1,
            "replies": 0,
            "createdAt": "2026-06-19",
            "url": "https://bsky.app/profile/blackhatnews.tokyo/post/3mongzjykab2y",
            "origin": false,
            "authority": false,
            "github": []
          },
          {
            "handle": "donwebmedia.bsky.social",
            "displayName": null,
            "likes": 0,
            "reposts": 0,
            "replies": 0,
            "createdAt": "2026-07-01",
            "url": "https://bsky.app/profile/donwebmedia.bsky.social/post/3mpl5z5jkqh2k",
            "origin": false,
            "authority": false,
            "github": []
          }
        ]
      },
      "telegram": {
        "mentions": 0,
        "posts": []
      }
    },
    {
      "cve": "CVE-2026-20251",
      "title": "In Splunk Enterprise versions below 10.2.4, 10.0.7, 9.4.12, and 9.3.13, Splunk Cloud…",
      "category": "Recall",
      "vendor": null,
      "exploited": false,
      "publiclyDisclosed": true,
      "cvss": 8.8,
      "cvssVector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "severity": "HIGH",
      "impact": null,
      "products": [],
      "productCount": 0,
      "faq": "In Splunk Enterprise versions below 10.2.4, 10.0.7, 9.4.12, and 9.3.13, Splunk Cloud Platform versions below 10.3.2512.12, 10.2.2510.14, 10.1.2507.22, and 9.3.2411.132, and Splunk Secure Gateway versions below 3.10.6, 3.9.20, and 3.8.67, a low-privileged user that does not hold the 'admin' or 'power' Splunk roles could perform a Remote Code Execution (RCE) through the Splunk Secure Gateway app.<br><br>The Remote Code Execution is possible because of unsafe deserialization of App Key Value Store (KV Store) data through the ‘jsonpickle’ Python library, which reconstructs arbitrary Python objects from specially crafted JavaScript Object Notation (JSON) without adequate validation.",
      "pocConfidence": "confirmed",
      "pocCount": 1,
      "pocTopStars": 3,
      "pocRepos": [
        {
          "url": "https://github.com/reactivezero/CVE-2026-20251",
          "stars": 3,
          "desc": "CVE-2026-20251 — Splunk Secure Gateway jsonpickle deserialization RCE (CVSS 8.8) | ReactiveZero Security Research",
          "createdAt": "2026-06-26",
          "hasCode": true
        }
      ],
      "epss": 0.00575,
      "epssPercentile": 0.43703,
      "source": "poc",
      "mitreUrl": "https://nvd.nist.gov/vuln/detail/CVE-2026-20251",
      "research": [],
      "aliases": [],
      "researchers": [],
      "x": {
        "mentions": 0,
        "aliases": [],
        "posts": []
      },
      "bsky": {
        "mentions": 5,
        "posts": [
          {
            "handle": "undercodenews.bsky.social",
            "displayName": "Undercode News",
            "likes": 0,
            "reposts": 0,
            "replies": 0,
            "createdAt": "2026-06-30",
            "url": "https://bsky.app/profile/undercodenews.bsky.social/post/3mpht3tkmhk25",
            "origin": false,
            "authority": false,
            "github": []
          },
          {
            "handle": "blackhatnews.tokyo",
            "displayName": "blackhatnews.tokyo",
            "likes": 0,
            "reposts": 0,
            "replies": 0,
            "createdAt": "2026-06-30",
            "url": "https://bsky.app/profile/blackhatnews.tokyo/post/3mphqd2j6vy27",
            "origin": false,
            "authority": false,
            "github": []
          },
          {
            "handle": "cyberveille-ch.bsky.social",
            "displayName": "CyberVeille",
            "likes": 0,
            "reposts": 0,
            "replies": 0,
            "createdAt": "2026-06-29",
            "url": "https://bsky.app/profile/cyberveille-ch.bsky.social/post/3mpgzc3dvnn2k",
            "origin": false,
            "authority": false,
            "github": []
          },
          {
            "handle": "cyberhub.blog",
            "displayName": "CyberHub",
            "likes": 0,
            "reposts": 0,
            "replies": 0,
            "createdAt": "2026-06-15",
            "url": "https://bsky.app/profile/cyberhub.blog/post/3moduswpma32v",
            "origin": false,
            "authority": false,
            "github": []
          },
          {
            "handle": "postac001.bsky.social",
            "displayName": "tec_acc",
            "likes": 0,
            "reposts": 0,
            "replies": 0,
            "createdAt": "2026-06-10",
            "url": "https://bsky.app/profile/postac001.bsky.social/post/3mnxk446ell2m",
            "origin": false,
            "authority": false,
            "github": []
          }
        ]
      }
    },
    {
      "cve": "CVE-2026-53519",
      "title": "Nezha Monitoring is a self-hostable, lightweight, servers and websites monitoring and…",
      "category": "Recall",
      "vendor": null,
      "exploited": false,
      "publiclyDisclosed": true,
      "cvss": 9.1,
      "cvssVector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N",
      "severity": "CRITICAL",
      "impact": null,
      "products": [],
      "productCount": 0,
      "faq": "Nezha Monitoring is a self-hostable, lightweight, servers and websites monitoring and O&M tool. Prior to version 2.0.13, fallbackToFrontend in the dashboard's NoRoute handler treats any URL whose raw string starts with /dashboard as an admin-frontend asset request. The check uses strings.HasPrefix, not a path-segment match, so the input /dashboard../data/config.yaml is accepted; strings.TrimPrefix leaves ../data/config.yaml; and path.Join(\"admin-dist\", \"../data/config.yaml\") normalizes to data/config.yaml — which os.Stat finds and http.ServeFile returns. No authentication required. This issue has been patched in version 2.0.13.",
      "pocConfidence": "confirmed",
      "pocCount": 1,
      "pocTopStars": 3,
      "pocRepos": [
        {
          "url": "https://github.com/tar-xz/CVE-2026-53519-PoC",
          "stars": 3,
          "desc": "PoC exploit for CVE-2026-53519.",
          "createdAt": "2026-06-15",
          "hasCode": true
        }
      ],
      "epss": 0.00451,
      "epssPercentile": 0.36538,
      "source": "poc",
      "mitreUrl": "https://nvd.nist.gov/vuln/detail/CVE-2026-53519",
      "telegram": {
        "mentions": 0,
        "posts": []
      },
      "research": [],
      "aliases": [],
      "researchers": [],
      "x": {
        "mentions": 0,
        "aliases": [],
        "posts": []
      },
      "bsky": {
        "mentions": 3,
        "posts": [
          {
            "handle": "cve.skyfleet.blue",
            "displayName": "CVE Alerts ",
            "likes": 1,
            "reposts": 1,
            "replies": 0,
            "createdAt": "2026-06-13",
            "url": "https://bsky.app/profile/cve.skyfleet.blue/post/3mo54chrq5d2y",
            "origin": false,
            "authority": false,
            "github": []
          },
          {
            "handle": "offseq.bsky.social",
            "displayName": "OffSequence",
            "likes": 0,
            "reposts": 1,
            "replies": 0,
            "createdAt": "2026-06-13",
            "url": "https://bsky.app/profile/offseq.bsky.social/post/3mo4x6blvzm27",
            "origin": false,
            "authority": false,
            "github": []
          },
          {
            "handle": "thehackerwire.bsky.social",
            "displayName": "TheHackerWire",
            "likes": 0,
            "reposts": 1,
            "replies": 0,
            "createdAt": "2026-06-13",
            "url": "https://bsky.app/profile/thehackerwire.bsky.social/post/3mo5baul7552d",
            "origin": false,
            "authority": false,
            "github": []
          }
        ]
      }
    },
    {
      "cve": "CVE-2026-0776",
      "title": "Discord Client Uncontrolled Search Path Element Local Privilege Escalation…",
      "category": "Recall",
      "vendor": null,
      "exploited": false,
      "publiclyDisclosed": true,
      "cvss": 7.3,
      "cvssVector": "CVSS:3.0/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H",
      "severity": "HIGH",
      "impact": null,
      "products": [],
      "productCount": 0,
      "faq": "Discord Client Uncontrolled Search Path Element Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of Discord Client. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.\n\nThe specific flaw exists within the discord_rpc module. The product loads a file from an unsecured location. An attacker can leverage this vulnerability to escalate privileges and execute arbitrary code in the context of a target user. Was ZDI-CAN-27057.",
      "pocConfidence": "confirmed",
      "pocCount": 1,
      "pocTopStars": 3,
      "pocRepos": [
        {
          "url": "https://github.com/0x18F/CVE-2026-0776",
          "stars": 3,
          "desc": "Security research and proof-of-concept for CVE-2026-0776 affecting Discord Desktop Client.",
          "createdAt": "2026-06-10",
          "hasCode": true
        }
      ],
      "epss": 0.0036,
      "epssPercentile": 0.28314,
      "source": "poc",
      "mitreUrl": "https://nvd.nist.gov/vuln/detail/CVE-2026-0776",
      "research": [],
      "x": {
        "mentions": 0,
        "aliases": [],
        "posts": []
      },
      "aliases": [],
      "researchers": [],
      "bsky": {
        "mentions": 0,
        "posts": []
      }
    },
    {
      "cve": "CVE-2026-39636",
      "title": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')…",
      "category": "Recall",
      "vendor": null,
      "exploited": false,
      "publiclyDisclosed": true,
      "cvss": 6.5,
      "cvssVector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L",
      "severity": "MEDIUM",
      "impact": null,
      "products": [],
      "productCount": 0,
      "faq": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in livemesh Livemesh Addons for Elementor addons-for-elementor allows Stored XSS.This issue affects Livemesh Addons for Elementor: from n/a through <= 9.0.",
      "pocConfidence": "confirmed",
      "pocCount": 1,
      "pocTopStars": 3,
      "pocRepos": [
        {
          "url": "https://github.com/CatchCatOoO/CVE-2026-39636-vulnerability-exp",
          "stars": 3,
          "desc": "暂无",
          "createdAt": "2026-05-18",
          "hasCode": true
        }
      ],
      "epss": 0.00161,
      "epssPercentile": 0.05678,
      "source": "poc",
      "mitreUrl": "https://nvd.nist.gov/vuln/detail/CVE-2026-39636",
      "research": [],
      "x": {
        "mentions": 1,
        "posts": [
          {
            "handle": "CVEnew",
            "followers": 57565,
            "likes": 0,
            "createdAt": "2026-04-12",
            "url": "https://x.com/CVEnew/status/2043368505928815016",
            "origin": false,
            "github": []
          }
        ],
        "aliases": []
      },
      "aliases": [],
      "researchers": [],
      "bsky": {
        "mentions": 0,
        "posts": []
      }
    },
    {
      "cve": "CVE-2026-42588",
      "title": "Improper Input Validation, Improper Control of Generation of Code ('Code Injection')…",
      "category": "Recall",
      "vendor": null,
      "exploited": false,
      "publiclyDisclosed": true,
      "cvss": 8.1,
      "cvssVector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N",
      "severity": "HIGH",
      "impact": null,
      "products": [],
      "productCount": 0,
      "faq": "Improper Input Validation, Improper Control of Generation of Code ('Code Injection') vulnerability in Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ.\n\nApache ActiveMQ Classic exposes the Jolokia JMX-HTTP bridge at /api/jolokia/ on the web console. The default Jolokia access policy permits exec operations on all ActiveMQ MBeans (org.apache.activemq:*), including\nBrokerService.addNetworkConnector(String).\n\nAn authenticated attacker can invoke these operations with a crafted discovery URI that triggers the VM transport's brokerConfig parameter using the \"masterslave:// \" URL which can allow loading a Spring XML application context using ResourceXmlApplicationContext.\nBecause Spring's ResourceXmlApplicationContext instantiates all singleton beans before the BrokerService validates the configuration, arbitrary code execution occurs on the broker's JVM through bean factory methods such as Runtime.exec().\nThis issue affects Apache ActiveMQ Broker: before 5.19.7, from 6.0.0 before 6.2.6; Apache ActiveMQ All: before 5.19.7, from 6.0.0 before 6.2.6; Apache ActiveMQ: before 5.19.7, from 6.0.0 before 6.2.6.\n\nUsers are recommended to upgrade to version 5.19.7 or 6.2.6, which fixes the issue.",
      "pocConfidence": "confirmed",
      "pocCount": 1,
      "pocTopStars": 3,
      "pocRepos": [
        {
          "url": "https://github.com/hnytgl/CVE-2026-42588",
          "stars": 3,
          "desc": "CVE-2026-42588 - Apache ActiveMQ Jolokia 远程代码执行漏洞利用 (RCE Exploit)",
          "createdAt": "2026-06-06",
          "hasCode": true
        }
      ],
      "epss": 0.00546,
      "epssPercentile": 0.42212,
      "source": "poc",
      "mitreUrl": "https://nvd.nist.gov/vuln/detail/CVE-2026-42588",
      "research": [],
      "x": {
        "mentions": 1,
        "aliases": [],
        "posts": [
          {
            "handle": "__kokumoto",
            "followers": 7498,
            "likes": 1,
            "createdAt": "2026-06-02",
            "url": "https://x.com/__kokumoto/status/2061808603414266292",
            "github": [],
            "origin": false
          }
        ]
      },
      "aliases": [],
      "researchers": [],
      "bsky": {
        "mentions": 1,
        "posts": [
          {
            "handle": "infosec.skyfleet.blue",
            "displayName": "InfoSec",
            "likes": 0,
            "reposts": 0,
            "replies": 0,
            "createdAt": "2026-05-31",
            "url": "https://bsky.app/profile/infosec.skyfleet.blue/post/3mn64ifhula2a",
            "origin": false,
            "authority": true,
            "github": []
          }
        ]
      }
    },
    {
      "cve": "CVE-2026-4802",
      "title": "A flaw was found in Cockpit. This vulnerability allows a remote attacker to achieve…",
      "category": "Recall",
      "vendor": null,
      "exploited": false,
      "publiclyDisclosed": true,
      "cvss": 8,
      "cvssVector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H",
      "severity": "HIGH",
      "impact": null,
      "products": [],
      "productCount": 0,
      "faq": "A flaw was found in Cockpit. This vulnerability allows a remote attacker to achieve arbitrary command execution on the host by exploiting unsanitized user-controlled parameters within crafted links in the system logs user interface (UI). An attacker can inject shell metacharacters and command substitutions into these parameters, leading to the execution of arbitrary shell commands on the affected system. This could result in a complete system compromise.",
      "pocConfidence": "confirmed",
      "pocCount": 1,
      "pocTopStars": 3,
      "pocRepos": [
        {
          "url": "https://github.com/hakaioffsec/CVE-2026-4802",
          "stars": 3,
          "desc": "Arbitrary command execution on Cockpit",
          "createdAt": "2026-05-11",
          "hasCode": true
        }
      ],
      "epss": 0.01016,
      "epssPercentile": 0.59495,
      "source": "poc",
      "mitreUrl": "https://nvd.nist.gov/vuln/detail/CVE-2026-4802",
      "research": [
        {
          "url": "https://hakaisecurity.io/en-cve-2026-4802-command-execution-on-cockpit/research-blog/",
          "type": "writeup",
          "source": "Hakai Security",
          "note": "Discoverer writeup, journalctl since param injection"
        },
        {
          "url": "https://www.tenable.com/plugins/nessus/305956",
          "type": "detection",
          "source": "Tenable",
          "note": "Nessus plugin for Cockpit RCE"
        }
      ],
      "x": {
        "mentions": 2,
        "aliases": [],
        "posts": [
          {
            "handle": "MalwareBibleJP",
            "followers": 6643,
            "likes": 16,
            "createdAt": "2026-05-20",
            "url": "https://x.com/MalwareBibleJP/status/2056939832631505260",
            "github": [],
            "origin": false
          },
          {
            "handle": "oss_security",
            "followers": 4604,
            "likes": 7,
            "createdAt": "2026-05-20",
            "url": "https://x.com/oss_security/status/2057178434707595711",
            "github": [],
            "origin": false
          }
        ]
      },
      "researchers": [
        "Hakai Security"
      ],
      "aliases": [],
      "bsky": {
        "mentions": 3,
        "posts": [
          {
            "handle": "infosec.skyfleet.blue",
            "displayName": "InfoSec",
            "likes": 0,
            "reposts": 0,
            "replies": 0,
            "createdAt": "2026-05-20",
            "url": "https://bsky.app/profile/infosec.skyfleet.blue/post/3mmcoexw5k52m",
            "origin": false,
            "authority": true,
            "github": []
          },
          {
            "handle": "cve.skyfleet.blue",
            "displayName": "CVE Alerts ",
            "likes": 1,
            "reposts": 0,
            "replies": 0,
            "createdAt": "2026-05-11",
            "url": "https://bsky.app/profile/cve.skyfleet.blue/post/3mlljizydxu2p",
            "origin": false,
            "authority": false,
            "github": []
          },
          {
            "handle": "thehackerwire.bsky.social",
            "displayName": "TheHackerWire",
            "likes": 0,
            "reposts": 0,
            "replies": 0,
            "createdAt": "2026-05-11",
            "url": "https://bsky.app/profile/thehackerwire.bsky.social/post/3mllk2366jn2n",
            "origin": false,
            "authority": false,
            "github": []
          }
        ]
      }
    },
    {
      "cve": "CVE-2026-42048",
      "title": "Langflow is a tool for building and deploying AI-powered agents and workflows. Prior…",
      "category": "Recall",
      "vendor": null,
      "exploited": false,
      "publiclyDisclosed": true,
      "cvss": 9.6,
      "cvssVector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:H/A:H",
      "severity": "CRITICAL",
      "published": "2026-05-12T18:17:23.780",
      "impact": null,
      "products": [],
      "productCount": 0,
      "faq": "Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to 1.9.0, Langflow is vulnerable to Path Traversal in the Knowledge Bases API (DELETE /api/v1/knowledge_bases). This occurs because user-supplied knowledge base names are concatenated directly into file paths without proper sanitization or boundary validation. An authenticated attacker can exploit this flaw to delete arbitrary directories anywhere on the server's filesystem, leading to data loss and potential service disruption. This vulnerability is fixed in 1.9.0.",
      "pocConfidence": "confirmed",
      "pocCount": 1,
      "pocTopStars": 2,
      "pocRepos": [
        {
          "url": "https://github.com/EQSTLab/CVE-2026-42048",
          "stars": 2,
          "desc": "Langflow Arbitrary Directory Deletion",
          "createdAt": "2026-05-21",
          "hasCode": true
        }
      ],
      "epss": 0.04417,
      "epssPercentile": 0.90303,
      "source": "poc",
      "mitreUrl": "https://nvd.nist.gov/vuln/detail/CVE-2026-42048",
      "research": [
        {
          "url": "https://github.com/langflow-ai/langflow/security/advisories/GHSA-9whx-c884-c68q",
          "type": "writeup",
          "source": "GitHub / langflow-ai (official GHSA)",
          "note": "Official vendor advisory; fix in v1.9.0",
          "hasCode": true
        },
        {
          "url": "https://www.sentinelone.com/vulnerability-database/cve-2026-42048/",
          "type": "writeup",
          "source": "SentinelOne Vulnerability Database",
          "note": "Deep-dive: path traversal in KB API, IoCs"
        },
        {
          "url": "https://www.thehackerwire.com/langflow-path-traversal-in-knowledge-bases-api-cve-2026-42048/",
          "type": "writeup",
          "source": "TheHackerWire",
          "note": "Technical breakdown; no public PoC at publish"
        },
        {
          "url": "https://www.acn.gov.it/portale/w/langflow-poc-pubblico-per-lo-sfruttamento-della-cve-2026-42048",
          "type": "writeup",
          "source": "ACN (Italian National Cybersecurity Agency)",
          "note": "Gov advisory; CVSS 9.6, KB API vuln detail"
        }
      ],
      "aliases": [],
      "researchers": [],
      "x": {
        "mentions": 0,
        "engagement": 0,
        "aliases": [],
        "posts": []
      },
      "bsky": {
        "mentions": 1,
        "engagement": 0,
        "posts": [
          {
            "handle": "cyberhub.blog",
            "displayName": "CyberHub",
            "likes": 0,
            "reposts": 0,
            "replies": 0,
            "createdAt": "2026-05-14",
            "url": "https://bsky.app/profile/cyberhub.blog/post/3mlsyichor42u",
            "origin": false,
            "authority": false,
            "github": []
          }
        ]
      }
    },
    {
      "cve": "CVE-2026-46243",
      "title": "In the Linux kernel, the following vulnerability has been resolved: smb: client:…",
      "category": "Recall",
      "vendor": null,
      "exploited": false,
      "publiclyDisclosed": true,
      "cvss": 7.1,
      "cvssVector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N",
      "severity": "HIGH",
      "published": "2026-06-01T17:17:34.173",
      "impact": null,
      "products": [],
      "productCount": 0,
      "faq": "In the Linux kernel, the following vulnerability has been resolved:\n\nsmb: client: reject userspace cifs.spnego descriptions\n\ncifs.spnego key descriptions contain authority-bearing fields such as\npid, uid, creduid, and upcall_target that cifs.upcall treats as\nkernel-originating inputs. However, userspace can also create keys of\nthis type through request_key(2) or add_key(2), allowing those fields to\nbe supplied without CIFS origin.\n\nOnly accept cifs.spnego descriptions while CIFS is using its private\nspnego_cred to request the key.",
      "pocConfidence": "confirmed",
      "pocCount": 1,
      "pocTopStars": 2,
      "pocRepos": [
        {
          "url": "https://github.com/Koshmare-Blossom/CIFSwitch-go",
          "stars": 2,
          "desc": "A Go implementation of CIFSwitch (CVE-2026-46243)",
          "createdAt": "2026-06-01",
          "hasCode": true
        }
      ],
      "epss": 0.00353,
      "epssPercentile": 0.27652,
      "source": "poc",
      "mitreUrl": "https://nvd.nist.gov/vuln/detail/CVE-2026-46243",
      "bsky": {
        "mentions": 20,
        "engagement": 32,
        "posts": [
          {
            "handle": "rockylinux.org",
            "displayName": "Rocky Linux",
            "likes": 7,
            "reposts": 1,
            "replies": 0,
            "createdAt": "2026-06-05",
            "url": "https://bsky.app/profile/rockylinux.org/post/3mnkikhhrhf2v",
            "origin": false,
            "authority": false,
            "github": []
          },
          {
            "handle": "lalgorisme.bsky.social",
            "displayName": "L'algorisme",
            "likes": 2,
            "reposts": 3,
            "replies": 1,
            "createdAt": "2026-06-02",
            "url": "https://bsky.app/profile/lalgorisme.bsky.social/post/3mncb3vpmgk2p",
            "origin": false,
            "authority": false,
            "github": []
          },
          {
            "handle": "nidouille.bsky.social",
            "displayName": "Nidouille",
            "likes": 4,
            "reposts": 2,
            "replies": 0,
            "createdAt": "2026-06-02",
            "url": "https://bsky.app/profile/nidouille.bsky.social/post/3mndovyarrs2x",
            "origin": false,
            "authority": false,
            "github": []
          },
          {
            "handle": "dju.eurosky.social",
            "displayName": "Julien 🐧",
            "likes": 2,
            "reposts": 1,
            "replies": 0,
            "createdAt": "2026-06-02",
            "url": "https://bsky.app/profile/dju.eurosky.social/post/3mndcnk4kgs2s",
            "origin": false,
            "authority": false,
            "github": []
          },
          {
            "handle": "ifin-intel.org",
            "displayName": "IFIN",
            "likes": 2,
            "reposts": 1,
            "replies": 0,
            "createdAt": "2026-06-01",
            "url": "https://bsky.app/profile/ifin-intel.org/post/3mnanqg7sy22p",
            "origin": false,
            "authority": false,
            "github": []
          },
          {
            "handle": "wdormann.infosec.exchange.ap.brid.gy",
            "displayName": "Will Dormann",
            "likes": 0,
            "reposts": 3,
            "replies": 0,
            "createdAt": "2026-06-01",
            "url": "https://bsky.app/profile/wdormann.infosec.exchange.ap.brid.gy/post/3mnangrheope2",
            "origin": false,
            "authority": false,
            "github": []
          }
        ]
      }
    },
    {
      "cve": "CVE-2026-6043",
      "title": "P4 Server versions prior to 2026.1 are configured with insecure default settings…",
      "category": "Recall",
      "vendor": null,
      "exploited": false,
      "publiclyDisclosed": true,
      "cvss": null,
      "cvssVector": null,
      "severity": null,
      "published": "2026-04-24T12:17:07.660",
      "impact": null,
      "products": [],
      "productCount": 0,
      "faq": "P4 Server versions prior to 2026.1 are configured with insecure default settings that, when exposed to untrusted networks, allow unauthenticated attackers to create arbitrary user accounts, enumerate existing users, authenticate to accounts with no password set, and access depot contents via the built-in 'remote' user. These default settings, taken together, can lead to unauthorized access to source code repositories and other managed assets. The 2026.1 release, expected in May 2026, enforces secure-by-default configurations on upgrade and new installations",
      "pocConfidence": "confirmed",
      "pocCount": 1,
      "pocTopStars": 2,
      "pocRepos": [
        {
          "url": "https://github.com/flyingllama87/p4wned",
          "stars": 2,
          "desc": "Perforce security research and tools - CVE-2026-6043",
          "createdAt": "2026-04-03",
          "hasCode": true,
          "module": "msf"
        }
      ],
      "epss": 0.00457,
      "epssPercentile": 0.3693,
      "source": "poc",
      "mitreUrl": "https://nvd.nist.gov/vuln/detail/CVE-2026-6043",
      "bsky": {
        "mentions": 0,
        "engagement": 0,
        "posts": []
      }
    },
    {
      "cve": "CVE-2026-9277",
      "title": "shell-quote's `quote()` function did not validate object-token inputs against the…",
      "category": "Recall",
      "vendor": null,
      "exploited": false,
      "publiclyDisclosed": true,
      "cvss": 8.1,
      "cvssVector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "severity": "HIGH",
      "impact": null,
      "products": [],
      "productCount": 0,
      "faq": "shell-quote's `quote()` function did not validate object-token inputs against the operator model used by `parse()`. The `.op` field was backslash-escaped character by character using `/(.)/g`, which in JavaScript does not match line terminators (\\n, \\r, U+2028, U+2029). A line terminator in `.op` therefore passed through unescaped into the output; POSIX shells treat a literal newline as a command separator, so any content after it would execute as a second command. The vulnerable code path is reachable in two ways: (1) direct construction of `{ op: '...\\n...' }` from external input, and (2) via `parse(cmd, envFn)` when `envFn` returns object tokens whose `.op` is attacker-influenced. Both are documented API surface. Fixed by replacing the per-character escape with strict shape validation: `.op` must match the parser's control-operator allowlist; `{ op: 'glob', pattern }` validates `pattern` and forbids line terminators; `{ comment }` validates `comment` and forbids line terminators; any other object shape throws `TypeError`.",
      "pocConfidence": "confirmed",
      "pocCount": 1,
      "pocTopStars": 2,
      "pocRepos": [
        {
          "url": "https://github.com/DylanZahedi/CVE-2026-9277",
          "stars": 2,
          "desc": "",
          "createdAt": "2026-06-15",
          "hasCode": true
        }
      ],
      "epss": 0.00848,
      "epssPercentile": 0.54089,
      "source": "poc",
      "mitreUrl": "https://nvd.nist.gov/vuln/detail/CVE-2026-9277",
      "bsky": {
        "mentions": 4,
        "posts": [
          {
            "handle": "infosec.skyfleet.blue",
            "displayName": "InfoSec",
            "likes": 3,
            "reposts": 0,
            "replies": 0,
            "createdAt": "2026-05-23",
            "url": "https://bsky.app/profile/infosec.skyfleet.blue/post/3mmiohjvizp24",
            "origin": false,
            "authority": true,
            "github": []
          },
          {
            "handle": "ferramentaslinux.bsky.social",
            "displayName": null,
            "likes": 0,
            "reposts": 0,
            "replies": 1,
            "createdAt": "2026-06-09",
            "url": "https://bsky.app/profile/ferramentaslinux.bsky.social/post/3mnufvafg7c2y",
            "origin": false,
            "authority": false,
            "github": []
          },
          {
            "handle": "linux.activitypub.awakari.com.ap.brid.gy",
            "displayName": "linux",
            "likes": 0,
            "reposts": 0,
            "replies": 0,
            "createdAt": "2026-06-09",
            "url": "https://bsky.app/profile/linux.activitypub.awakari.com.ap.brid.gy/post/3mnu56ea4xh42",
            "origin": false,
            "authority": false,
            "github": []
          },
          {
            "handle": "cve.skyfleet.blue",
            "displayName": "CVE Alerts ",
            "likes": 0,
            "reposts": 0,
            "replies": 0,
            "createdAt": "2026-05-22",
            "url": "https://bsky.app/profile/cve.skyfleet.blue/post/3mmhhsrhmds2o",
            "origin": false,
            "authority": false,
            "github": []
          }
        ]
      }
    },
    {
      "cve": "CVE-2026-0594",
      "title": "The List Site Contributors plugin for WordPress is vulnerable to Reflected Cross-Site…",
      "category": "Recall",
      "vendor": null,
      "exploited": false,
      "publiclyDisclosed": true,
      "cvss": 6.1,
      "cvssVector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N",
      "severity": "MEDIUM",
      "impact": null,
      "products": [],
      "productCount": 0,
      "faq": "The List Site Contributors plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'alpha' parameter in versions up to, and including, 1.1.8 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.",
      "pocConfidence": "confirmed",
      "pocCount": 1,
      "pocTopStars": 2,
      "pocRepos": [
        {
          "url": "https://github.com/m4sh-wacker/CVE-2026-0594-ListSiteContributors-Plugin-Exploit",
          "stars": 2,
          "desc": "CVE-2026-0594 List Site Contributors Plugin Exploit",
          "createdAt": "2026-01-22",
          "hasCode": true
        }
      ],
      "epss": 0.00693,
      "epssPercentile": 0.4887,
      "source": "poc",
      "mitreUrl": "https://nvd.nist.gov/vuln/detail/CVE-2026-0594",
      "research": [
        {
          "url": "https://github.com/projectdiscovery/nuclei-templates/releases",
          "type": "module",
          "source": "ProjectDiscovery / nuclei-templates (@m4sh_wacker)",
          "note": "Official Nuclei template: WP List Site Contributors <1.1.8 RXss",
          "hasCode": true
        },
        {
          "url": "https://www.wordfence.com/threat-intel/vulnerabilities",
          "type": "detection",
          "source": "Wordfence Intelligence",
          "note": "Wordfence vuln DB; advisory/intel source for CVE-2026-0594"
        }
      ],
      "aliases": [],
      "researchers": [
        "m4sh_wacker"
      ],
      "x": {
        "mentions": 78,
        "aliases": [],
        "posts": [
          {
            "handle": "MalwareObserver",
            "followers": 11,
            "likes": 0,
            "createdAt": "2026-07-20",
            "url": "https://x.com/MalwareObserver/status/2079280525265514912",
            "github": [
              {
                "url": "https://github.com/chamilo/chamilo-lms/security/advisories/GHSA-gcjp-f7jm-rrrg",
                "hasCode": true
              },
              {
                "url": "https://github.com/chamilo/chamilo-lms/security/advisories/GHSA-gcjp-f7jm-rrrg",
                "hasCode": true
              }
            ],
            "origin": false
          },
          {
            "handle": "geovexintel",
            "followers": 999,
            "likes": 17,
            "createdAt": "2026-07-20",
            "url": "https://x.com/geovexintel/status/2079263366049063306",
            "github": [],
            "origin": false
          },
          {
            "handle": "0x0SojalSec",
            "followers": 47743,
            "likes": 12,
            "createdAt": "2026-07-20",
            "url": "https://x.com/0x0SojalSec/status/2079262255892603372",
            "github": [],
            "origin": false
          },
          {
            "handle": "NetSPI",
            "followers": 4074,
            "likes": 11,
            "createdAt": "2026-07-20",
            "url": "https://x.com/NetSPI/status/2079265470633381982",
            "github": [],
            "origin": false
          },
          {
            "handle": "MalwareBibleJP",
            "followers": 7678,
            "likes": 6,
            "createdAt": "2026-07-20",
            "url": "https://x.com/MalwareBibleJP/status/2079323720771088529",
            "github": [],
            "origin": false
          },
          {
            "handle": "ptdbugs",
            "followers": 2491,
            "likes": 5,
            "createdAt": "2026-07-20",
            "url": "https://x.com/ptdbugs/status/2079264509483515990",
            "github": [],
            "origin": false
          },
          {
            "handle": "LupovisDefence",
            "followers": 575,
            "likes": 5,
            "createdAt": "2026-07-20",
            "url": "https://x.com/LupovisDefence/status/2079290355443269739",
            "github": [],
            "origin": false
          },
          {
            "handle": "thingwhere",
            "followers": 8,
            "likes": 4,
            "createdAt": "2026-07-20",
            "url": "https://x.com/thingwhere/status/2079330106921607615",
            "github": [],
            "origin": false
          }
        ]
      },
      "bsky": {
        "mentions": 3,
        "posts": [
          {
            "handle": "beikokucyber.bsky.social",
            "displayName": "Beikoku Cybersecurity",
            "likes": 0,
            "reposts": 0,
            "replies": 0,
            "createdAt": "2026-02-07",
            "url": "https://bsky.app/profile/beikokucyber.bsky.social/post/3meccxhxf2p27",
            "origin": false,
            "authority": false,
            "github": []
          },
          {
            "handle": "cve.skyfleet.blue",
            "displayName": "CVE Alerts ",
            "likes": 0,
            "reposts": 0,
            "replies": 0,
            "createdAt": "2026-01-14",
            "url": "https://bsky.app/profile/cve.skyfleet.blue/post/3mcertix2qq2u",
            "origin": false,
            "authority": false,
            "github": []
          }
        ]
      }
    },
    {
      "cve": "CVE-2026-40083",
      "title": "Cacti is an open source performance and fault management framework. Versions 1.2.30…",
      "category": "Recall",
      "vendor": null,
      "exploited": false,
      "publiclyDisclosed": true,
      "cvss": 7.2,
      "cvssVector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H",
      "severity": "HIGH",
      "impact": null,
      "products": [],
      "productCount": 0,
      "faq": "Cacti is an open source performance and fault management framework. Versions 1.2.30 and prior have SQL Injection through unsanitized unserialize+implode in managers.php.  At line 756 of managers.php, the application assigns $selected_items by calling cacti_unserialize(stripslashes(gnrv('selected_graphs_array'))). The  cacti_unserialize() function calls unserialize() with allowed_classes set to false, which prevents object injection but still allows arbitrary string  arrays to be deserialized. Then, at lines 760 to 766, the deserialized array values are passed directly into db_execute('DELETE FROM snmpagent_managers  WHERE id IN (' . implode(',', $selected_items) . ')'), where they are imploded into the SQL statement without any integer validation, resulting in SQL  Injection when using SNMP agent management permissions. This issue has been fixed in version 1.2.31.",
      "pocConfidence": "confirmed",
      "pocCount": 1,
      "pocTopStars": 2,
      "pocRepos": [
        {
          "url": "https://github.com/hakaioffsec/CVE-2026-40083",
          "stars": 2,
          "desc": "SQL Injection at Cacti",
          "createdAt": "2026-06-27",
          "hasCode": true
        }
      ],
      "epss": 0.00279,
      "epssPercentile": 0.19985,
      "source": "poc",
      "mitreUrl": "https://nvd.nist.gov/vuln/detail/CVE-2026-40083",
      "research": [
        {
          "url": "https://github.com/Cacti/cacti/security/advisories/GHSA-j9jv-6xjq-9hhj",
          "type": "writeup",
          "source": "Cacti/GitHub Security Advisory",
          "note": "Official advisory: SQLi in managers.php, IN clause",
          "hasCode": true
        },
        {
          "url": "https://github.com/Cacti/cacti/releases/tag/release/1.2.31",
          "type": "detection",
          "source": "Cacti/GitHub Releases",
          "note": "Patch release 1.2.31 fixing CVE-2026-40083",
          "hasCode": true
        },
        {
          "url": "https://cve.threatint.eu/CVE/CVE-2026-40083",
          "type": "writeup",
          "source": "THREATINT",
          "note": "Technical breakdown: unserialize+implode SQLi flow"
        },
        {
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-40083",
          "type": "detection",
          "source": "MITRE CVE",
          "note": "Official CVE record, CVSS 7.2 HIGH"
        }
      ],
      "aliases": [],
      "researchers": [],
      "x": {
        "mentions": 0,
        "aliases": [],
        "posts": []
      },
      "bsky": {
        "mentions": 0,
        "posts": []
      }
    },
    {
      "cve": "CVE-2026-44262",
      "title": "Scramble generates API documentation for Laravel project. From 0.13.2 to before…",
      "category": "Recall",
      "vendor": null,
      "exploited": false,
      "publiclyDisclosed": true,
      "cvss": 9.4,
      "cvssVector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L",
      "severity": "CRITICAL",
      "impact": null,
      "products": [],
      "productCount": 0,
      "faq": "Scramble generates API documentation for Laravel project. From 0.13.2 to before 0.13.22, when documentation endpoints are publicly accessible and validation rules reference user-controlled input, request supplied data may be evaluated during documentation generation, leading to execution of arbitrary PHP code in the application context. This vulnerability is fixed in 0.13.22.",
      "pocConfidence": "confirmed",
      "pocCount": 1,
      "pocTopStars": 2,
      "pocRepos": [
        {
          "url": "https://github.com/joshuavanderpoll/CVE-2026-44262",
          "stars": 2,
          "desc": "Unauthenticated RCE in dedoc/scramble — PoC, Nmap NSE & Nuclei template.",
          "createdAt": "2026-05-07",
          "hasCode": true
        }
      ],
      "epss": 0.0586,
      "epssPercentile": 0.92389,
      "source": "poc",
      "mitreUrl": "https://nvd.nist.gov/vuln/detail/CVE-2026-44262",
      "research": [
        {
          "url": "https://github.com/joshuavanderpoll/CVE-2026-44262",
          "type": "poc",
          "source": "Joshua van der Poll / GitHub",
          "note": "Python RCE tool; cmd exec, file read, rev shell, Docker lab",
          "hasCode": true
        },
        {
          "url": "https://www.exploit-db.com/exploits/52582",
          "type": "poc",
          "source": "Exploit-DB / Joshua van der Poll",
          "note": "EDB-52582: extract()+eval() PHP RCE via /docs/api.json param"
        },
        {
          "url": "https://github.com/joshuavanderpoll/CVE-2026-44262",
          "type": "module",
          "source": "joshuavanderpoll / GitHub (Nuclei + Nmap NSE)",
          "note": "Nuclei YAML + Nmap NSE bundled in same PoC repo",
          "hasCode": true
        },
        {
          "url": "https://github.com/dedoc/scramble/security/advisories/GHSA-4rm2-28vj-fj39",
          "type": "writeup",
          "source": "GitHub Advisory / romalytvynenko (dedoc)",
          "note": "Vendor advisory GHSA-4rm2-28vj-fj39; CVSS 9.4 critical",
          "hasCode": true
        },
        {
          "url": "https://github.com/advisories/GHSA-4rm2-28vj-fj39",
          "type": "writeup",
          "source": "GitHub Advisory Database",
          "note": "RCE via user-controlled validation rules; fix v0.13.22",
          "hasCode": null
        },
        {
          "url": "https://hackindex.io/vulnerabilities/CVE-2026-44262",
          "type": "writeup",
          "source": "HackIndex.io",
          "note": "Technical walkthrough: timing probe, shell, param discovery"
        },
        {
          "url": "https://dailycve.com/scramble-remote-code-execution-rce-cve-2026-xxxxx-critical/",
          "type": "writeup",
          "source": "DailyCVE",
          "note": "Attack chain breakdown; patch + mitigation guidance"
        },
        {
          "url": "https://radar.offseq.com/threat/cve-2026-44262-cwe-94-improper-control-of-generati-76db591c",
          "type": "detection",
          "source": "OffSeq Threat Radar",
          "note": "Live threat intel; CWE-94; upgrade/restrict-endpoint guidance"
        }
      ],
      "aliases": [],
      "researchers": [
        "joshuavanderpoll"
      ],
      "x": {
        "mentions": 78,
        "aliases": [],
        "posts": [
          {
            "handle": "MalwareObserver",
            "followers": 11,
            "likes": 0,
            "createdAt": "2026-07-20",
            "url": "https://x.com/MalwareObserver/status/2079280525265514912",
            "github": [
              {
                "url": "https://github.com/chamilo/chamilo-lms/security/advisories/GHSA-gcjp-f7jm-rrrg",
                "hasCode": true
              },
              {
                "url": "https://github.com/chamilo/chamilo-lms/security/advisories/GHSA-gcjp-f7jm-rrrg",
                "hasCode": true
              }
            ],
            "origin": false
          },
          {
            "handle": "geovexintel",
            "followers": 999,
            "likes": 17,
            "createdAt": "2026-07-20",
            "url": "https://x.com/geovexintel/status/2079263366049063306",
            "github": [],
            "origin": false
          },
          {
            "handle": "0x0SojalSec",
            "followers": 47743,
            "likes": 12,
            "createdAt": "2026-07-20",
            "url": "https://x.com/0x0SojalSec/status/2079262255892603372",
            "github": [],
            "origin": false
          },
          {
            "handle": "NetSPI",
            "followers": 4074,
            "likes": 11,
            "createdAt": "2026-07-20",
            "url": "https://x.com/NetSPI/status/2079265470633381982",
            "github": [],
            "origin": false
          },
          {
            "handle": "MalwareBibleJP",
            "followers": 7678,
            "likes": 6,
            "createdAt": "2026-07-20",
            "url": "https://x.com/MalwareBibleJP/status/2079323720771088529",
            "github": [],
            "origin": false
          },
          {
            "handle": "ptdbugs",
            "followers": 2491,
            "likes": 5,
            "createdAt": "2026-07-20",
            "url": "https://x.com/ptdbugs/status/2079264509483515990",
            "github": [],
            "origin": false
          },
          {
            "handle": "LupovisDefence",
            "followers": 575,
            "likes": 5,
            "createdAt": "2026-07-20",
            "url": "https://x.com/LupovisDefence/status/2079290355443269739",
            "github": [],
            "origin": false
          },
          {
            "handle": "thingwhere",
            "followers": 8,
            "likes": 4,
            "createdAt": "2026-07-20",
            "url": "https://x.com/thingwhere/status/2079330106921607615",
            "github": [],
            "origin": false
          }
        ]
      },
      "bsky": {
        "mentions": 2,
        "posts": [
          {
            "handle": "throwable.bsky.social",
            "displayName": "call_user_func",
            "likes": 0,
            "reposts": 0,
            "replies": 0,
            "createdAt": "2026-06-24",
            "url": "https://bsky.app/profile/throwable.bsky.social/post/3mp32jszo7525",
            "origin": true,
            "authority": false,
            "github": [
              {
                "url": "https://github.com/joshuavanderpoll/laravel-captchas",
                "hasCode": true
              }
            ]
          },
          {
            "handle": "thehackerwire.bsky.social",
            "displayName": "TheHackerWire",
            "likes": 0,
            "reposts": 0,
            "replies": 0,
            "createdAt": "2026-05-13",
            "url": "https://bsky.app/profile/thehackerwire.bsky.social/post/3mlpfdbmxac2t",
            "origin": false,
            "authority": false,
            "github": []
          }
        ]
      }
    },
    {
      "cve": "CVE-2026-57239",
      "title": "The user-controllable executable files will be directly executed by high-privilege…",
      "category": "Recall",
      "vendor": null,
      "exploited": false,
      "publiclyDisclosed": true,
      "cvss": 8.2,
      "cvssVector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N",
      "severity": "HIGH",
      "impact": null,
      "products": [],
      "productCount": 0,
      "faq": "The user-controllable executable files will be directly executed by high-privilege processes, allowing low-privilege users to have the opportunity to elevate their privileges to NT AUTHORITY\\SYSTEM.",
      "pocConfidence": "confirmed",
      "pocCount": 1,
      "pocTopStars": 2,
      "pocRepos": [
        {
          "url": "https://github.com/Paradoxis/CVE-2026-57239",
          "stars": 2,
          "desc": "Proof of concept exploit for CVE-2026-3775/CVE-2026-3780 and CVE-2026-57239 which lets you obtain NT AUTHORITY\\SYSTEM rights via the Foxit PDF Reader updater se",
          "createdAt": "2026-07-08",
          "hasCode": true
        }
      ],
      "epss": 0.00115,
      "epssPercentile": 0.01826,
      "source": "poc",
      "mitreUrl": "https://nvd.nist.gov/vuln/detail/CVE-2026-57239",
      "research": [
        {
          "url": "https://www.foxit.com/support/security-bulletins.html",
          "type": "detection",
          "source": "Foxit Software (vendor advisory)",
          "note": "Official July 8 2026 bulletin; patch in 2026.1.2"
        },
        {
          "url": "https://cyberpress.org/foxit-patches-pdf-reader-editor-vulnerabilities/",
          "type": "writeup",
          "source": "CyberPress",
          "note": "CWE-427 LPE via update svc; credits @Paradoxis"
        },
        {
          "url": "https://gbhackers.com/foxit-patches-multiple-use-after-free-flaws/",
          "type": "writeup",
          "source": "GBHackers",
          "note": "Update svc runs user-controlled exes at high priv"
        },
        {
          "url": "https://cybersecuritynews.com/foxit-pdf-reader-and-editor-vulnerabilities/",
          "type": "writeup",
          "source": "CyberSecurityNews",
          "note": "LPE in update mechanism; DLL hijack to SYSTEM"
        },
        {
          "url": "https://windowsforum.com/threads/cve-2026-57239-update-foxit-to-2026-1-2-14-0-5-or-13-2-5.436444/",
          "type": "detection",
          "source": "WindowsForum",
          "note": "Remediation guide; update to 2026.1.2/14.0.5/13.2.5"
        },
        {
          "url": "https://www.thehackerwire.com/vulnerability/CVE-2026-57239/",
          "type": "detection",
          "source": "TheHackerWire",
          "note": "CVE summary; CVSS 8.2, disclosed July 8 2026"
        }
      ],
      "aliases": [],
      "researchers": [
        "Paradoxis"
      ],
      "x": {
        "mentions": 78,
        "aliases": [],
        "posts": [
          {
            "handle": "MalwareObserver",
            "followers": 11,
            "likes": 0,
            "createdAt": "2026-07-20",
            "url": "https://x.com/MalwareObserver/status/2079280525265514912",
            "github": [
              {
                "url": "https://github.com/chamilo/chamilo-lms/security/advisories/GHSA-gcjp-f7jm-rrrg",
                "hasCode": true
              },
              {
                "url": "https://github.com/chamilo/chamilo-lms/security/advisories/GHSA-gcjp-f7jm-rrrg",
                "hasCode": true
              }
            ],
            "origin": false
          },
          {
            "handle": "geovexintel",
            "followers": 999,
            "likes": 17,
            "createdAt": "2026-07-20",
            "url": "https://x.com/geovexintel/status/2079263366049063306",
            "github": [],
            "origin": false
          },
          {
            "handle": "0x0SojalSec",
            "followers": 47743,
            "likes": 12,
            "createdAt": "2026-07-20",
            "url": "https://x.com/0x0SojalSec/status/2079262255892603372",
            "github": [],
            "origin": false
          },
          {
            "handle": "NetSPI",
            "followers": 4074,
            "likes": 11,
            "createdAt": "2026-07-20",
            "url": "https://x.com/NetSPI/status/2079265470633381982",
            "github": [],
            "origin": false
          },
          {
            "handle": "MalwareBibleJP",
            "followers": 7678,
            "likes": 6,
            "createdAt": "2026-07-20",
            "url": "https://x.com/MalwareBibleJP/status/2079323720771088529",
            "github": [],
            "origin": false
          },
          {
            "handle": "ptdbugs",
            "followers": 2491,
            "likes": 5,
            "createdAt": "2026-07-20",
            "url": "https://x.com/ptdbugs/status/2079264509483515990",
            "github": [],
            "origin": false
          },
          {
            "handle": "LupovisDefence",
            "followers": 575,
            "likes": 5,
            "createdAt": "2026-07-20",
            "url": "https://x.com/LupovisDefence/status/2079290355443269739",
            "github": [],
            "origin": false
          },
          {
            "handle": "thingwhere",
            "followers": 8,
            "likes": 4,
            "createdAt": "2026-07-20",
            "url": "https://x.com/thingwhere/status/2079330106921607615",
            "github": [],
            "origin": false
          }
        ]
      },
      "bsky": {
        "mentions": 2,
        "posts": [
          {
            "handle": "cyberhub.blog",
            "displayName": "CyberHub",
            "likes": 0,
            "reposts": 0,
            "replies": 0,
            "createdAt": "2026-07-19",
            "url": "https://bsky.app/profile/cyberhub.blog/post/3mqzoq2ulwh2u",
            "origin": false,
            "authority": false,
            "github": []
          },
          {
            "handle": "cve.skyfleet.blue",
            "displayName": "CVE Alerts ",
            "likes": 0,
            "reposts": 0,
            "replies": 0,
            "createdAt": "2026-07-08",
            "url": "https://bsky.app/profile/cve.skyfleet.blue/post/3mq4vkqpnp32x",
            "origin": false,
            "authority": false,
            "github": []
          }
        ]
      }
    },
    {
      "cve": "CVE-2026-0908",
      "title": "Use after free in ANGLE in Google Chrome prior to 144.0.7559.59 allowed a remote…",
      "category": "Recall",
      "vendor": null,
      "exploited": false,
      "publiclyDisclosed": true,
      "cvss": 8.8,
      "cvssVector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
      "severity": "HIGH",
      "impact": null,
      "products": [],
      "productCount": 0,
      "faq": "Use after free in ANGLE in Google Chrome prior to 144.0.7559.59 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Low)",
      "pocConfidence": "confirmed",
      "pocCount": 1,
      "pocTopStars": 2,
      "pocRepos": [
        {
          "url": "https://github.com/lylzjnqe/CVE-2026-0908-Chrome-0-day-RCE",
          "stars": 2,
          "desc": "Chrome ANGLE Use-After-Free — 0-day disclosure & public CVE",
          "createdAt": "2026-05-21",
          "hasCode": true
        }
      ],
      "epss": 0.00314,
      "epssPercentile": 0.23542,
      "source": "poc",
      "mitreUrl": "https://nvd.nist.gov/vuln/detail/CVE-2026-0908",
      "research": [
        {
          "url": "https://chromereleases.googleblog.com/2026/01/stable-channel-update-for-desktop_13.html",
          "type": "detection",
          "source": "Google Chrome Releases Blog",
          "note": "Official patch advisory; fix in 144.0.7559.59"
        },
        {
          "url": "https://www.tenable.com/cve/CVE-2026-0908",
          "type": "detection",
          "source": "Tenable",
          "note": "CVE entry; severity Low per Chromium team"
        },
        {
          "url": "https://www.cisecurity.org/advisory/multiple-vulnerabilities-in-google-chrome-could-allow-for-arbitrary-code-execution_2026-004",
          "type": "detection",
          "source": "CIS (Center for Internet Security)",
          "note": "Defensive advisory; patch immediately guidance"
        },
        {
          "url": "https://www.rapid7.com/db/vulnerabilities/debian-cve-2026-0908/",
          "type": "detection",
          "source": "Rapid7 / AttackerKB",
          "note": "Vuln DB entry; no public exploit noted"
        },
        {
          "url": "https://www.suse.com/security/cve/CVE-2026-0908.html",
          "type": "detection",
          "source": "SUSE Security",
          "note": "Linux distro tracking; no patches cross-ref'd yet"
        },
        {
          "url": "https://www.sentinelone.com/vulnerability-database/cve-2026-0908/",
          "type": "detection",
          "source": "SentinelOne Vulnerability DB",
          "note": "AI-generated defensive overview; no PoC"
        }
      ],
      "aliases": [],
      "researchers": [],
      "x": {
        "mentions": 0,
        "aliases": [],
        "posts": []
      },
      "bsky": {
        "mentions": 5,
        "posts": [
          {
            "handle": "o2cloud.bsky.social",
            "displayName": "CVE by o2Cloud",
            "likes": 0,
            "reposts": 0,
            "replies": 1,
            "createdAt": "2026-02-12",
            "url": "https://bsky.app/profile/o2cloud.bsky.social/post/3meo67v42hb2o",
            "origin": false,
            "authority": false,
            "github": []
          },
          {
            "handle": "thehackerwire.bsky.social",
            "displayName": "TheHackerWire",
            "likes": 0,
            "reposts": 0,
            "replies": 0,
            "createdAt": "2026-01-20",
            "url": "https://bsky.app/profile/thehackerwire.bsky.social/post/3mcugfmjdc52h",
            "origin": false,
            "authority": false,
            "github": []
          },
          {
            "handle": "cve.skyfleet.blue",
            "displayName": "CVE Alerts ",
            "likes": 0,
            "reposts": 0,
            "replies": 0,
            "createdAt": "2026-01-20",
            "url": "https://bsky.app/profile/cve.skyfleet.blue/post/3mctjoscbg72j",
            "origin": false,
            "authority": false,
            "github": []
          }
        ]
      }
    },
    {
      "cve": "CVE-2026-43501",
      "title": "In the Linux kernel, the following vulnerability has been resolved: ipv6: rpl:…",
      "category": "Recall",
      "vendor": null,
      "exploited": false,
      "publiclyDisclosed": true,
      "cvss": 9.8,
      "cvssVector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "severity": "CRITICAL",
      "impact": null,
      "products": [],
      "productCount": 0,
      "faq": "In the Linux kernel, the following vulnerability has been resolved:\n\nipv6: rpl: reserve mac_len headroom when recompressed SRH grows\n\nipv6_rpl_srh_rcv() decompresses an RFC 6554 Source Routing Header, swaps\nthe next segment into ipv6_hdr->daddr, recompresses, then pulls the old\nheader and pushes the new one plus the IPv6 header back.  The\nrecompressed header can be larger than the received one when the swap\nreduces the common-prefix length the segments share with daddr (CmprI=0,\nCmprE>0, seg[0][0] != daddr[0] gives the maximum +8 bytes).\n\npskb_expand_head() was gated on segments_left == 0, so on earlier\nsegments the push consumed unchecked headroom.  Once skb_push() leaves\nfewer than skb->mac_len bytes in front of data,\nskb_mac_header_rebuild()'s call to:\n\n\tskb_set_mac_header(skb, -skb->mac_len);\n\nwill store (data - head) - mac_len into the u16 mac_header field, which\nwraps to ~65530, and the following memmove() writes mac_len bytes ~64KiB\npast skb->head.\n\nA single AF_INET6/SOCK_RAW/IPV6_HDRINCL packet over lo with a two\nsegment type-3 SRH (CmprI=0, CmprE=15) reaches headroom 8 after one\npass; KASAN reports a 14-byte OOB write in ipv6_rthdr_rcv.\n\nFix this by expanding the head whenever the remaining room is less than\nthe push size plus mac_len, and request that much extra so the rebuilt\nMAC header fits afterwards.",
      "pocConfidence": "confirmed",
      "pocCount": 1,
      "pocTopStars": 2,
      "pocRepos": [
        {
          "url": "https://github.com/Anyone202/cybermeowfia-termux",
          "stars": 2,
          "desc": "Termux Privilege Escalation Tool & Root Manager - CVE-2026-43501",
          "createdAt": "2026-07-11",
          "hasCode": true
        }
      ],
      "epss": 0.00475,
      "epssPercentile": 0.38089,
      "source": "poc",
      "mitreUrl": "https://nvd.nist.gov/vuln/detail/CVE-2026-43501",
      "research": [
        {
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-43501",
          "type": "writeup",
          "source": "NIST NVD",
          "note": "Official NVD entry, no CVSS score yet assigned"
        },
        {
          "url": "https://www.suse.com/security/cve/CVE-2026-43501.html",
          "type": "writeup",
          "source": "SUSE Security",
          "note": "Vendor advisory; rated important severity"
        },
        {
          "url": "https://security-tracker.debian.org/tracker/CVE-2026-43501",
          "type": "detection",
          "source": "Debian Security Tracker",
          "note": "Debian fixed-version tracking for CVE-2026-43501"
        },
        {
          "url": "https://access.redhat.com/errata/RHSA-2026:34095",
          "type": "detection",
          "source": "Red Hat",
          "note": "RHSA patch errata referencing CVE-2026-43501"
        },
        {
          "url": "https://dbugs.ptsecurity.com/vulnerability/PT-2026-42457",
          "type": "writeup",
          "source": "Positive Technologies dbugs",
          "note": "Technical description of OOB write ~64KiB past skb->head"
        },
        {
          "url": "https://windowsforum.com/threads/cve-2026-43501-linux-ipv6-rpl-out-of-bounds-write-patch-the-right-kernels.419270/",
          "type": "writeup",
          "source": "WindowsForum",
          "note": "Analysis of impact on WSL/Azure; no PoC code"
        }
      ],
      "aliases": [],
      "researchers": [],
      "x": {
        "mentions": 0,
        "aliases": [],
        "posts": []
      },
      "bsky": {
        "mentions": 1,
        "posts": [
          {
            "handle": "cve.skyfleet.blue",
            "displayName": "CVE Alerts ",
            "likes": 0,
            "reposts": 0,
            "replies": 0,
            "createdAt": "2026-05-21",
            "url": "https://bsky.app/profile/cve.skyfleet.blue/post/3mmerv5mswo2p",
            "origin": false,
            "authority": false,
            "github": []
          }
        ]
      },
      "telegram": {
        "mentions": 0,
        "posts": []
      }
    },
    {
      "cve": "CVE-2026-27966",
      "title": "Langflow is a tool for building and deploying AI-powered agents and workflows. Prior…",
      "category": "Recall",
      "vendor": null,
      "exploited": false,
      "publiclyDisclosed": true,
      "cvss": 9.8,
      "cvssVector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "severity": "CRITICAL",
      "impact": null,
      "products": [],
      "productCount": 0,
      "faq": "Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to version 1.8.0, the CSV Agent node in Langflow hardcodes `allow_dangerous_code=True`, which automatically exposes LangChain’s Python REPL tool (`python_repl_ast`). As a result, an attacker can execute arbitrary Python and OS commands on the server via prompt injection, leading to full Remote Code Execution (RCE). Version 1.8.0 fixes the issue.",
      "pocConfidence": "confirmed",
      "pocCount": 1,
      "pocTopStars": 2,
      "pocRepos": [
        {
          "url": "https://github.com/Anon-Cyber-Team/CVE-2026-27966--RCE-in-Langflow",
          "stars": 2,
          "desc": "Exploit Tools For new CVE",
          "createdAt": "2026-03-03",
          "hasCode": true
        }
      ],
      "epss": 0.33694,
      "epssPercentile": 0.9821,
      "source": "poc",
      "mitreUrl": "https://nvd.nist.gov/vuln/detail/CVE-2026-27966",
      "research": [],
      "aliases": [],
      "researchers": [],
      "x": {
        "mentions": 0,
        "aliases": [],
        "posts": []
      },
      "bsky": {
        "mentions": 12,
        "posts": [
          {
            "handle": "getpokemon7.bsky.social",
            "displayName": "まりーん",
            "likes": 1,
            "reposts": 0,
            "replies": 1,
            "createdAt": "2026-03-07",
            "url": "https://bsky.app/profile/getpokemon7.bsky.social/post/3mggnhv7zcc2y",
            "origin": false,
            "authority": false,
            "github": []
          },
          {
            "handle": "cyberhub.blog",
            "displayName": "CyberHub",
            "likes": 1,
            "reposts": 0,
            "replies": 0,
            "createdAt": "2026-02-28",
            "url": "https://bsky.app/profile/cyberhub.blog/post/3mfv5z3q6uz22",
            "origin": false,
            "authority": false,
            "github": []
          },
          {
            "handle": "beikokucyber.bsky.social",
            "displayName": "Beikoku Cybersecurity",
            "likes": 0,
            "reposts": 0,
            "replies": 0,
            "createdAt": "2026-04-24",
            "url": "https://bsky.app/profile/beikokucyber.bsky.social/post/3mkbgepntkm2c",
            "origin": false,
            "authority": false,
            "github": []
          },
          {
            "handle": "thedailytechfeed.com",
            "displayName": "The Daily Tech Feed",
            "likes": 0,
            "reposts": 0,
            "replies": 0,
            "createdAt": "2026-03-04",
            "url": "https://bsky.app/profile/thedailytechfeed.com/post/3mgawe6lj242i",
            "origin": false,
            "authority": false,
            "github": []
          },
          {
            "handle": "securitylab-jp.bsky.social",
            "displayName": "セキュリティ対策Lab",
            "likes": 0,
            "reposts": 0,
            "replies": 0,
            "createdAt": "2026-03-04",
            "url": "https://bsky.app/profile/securitylab-jp.bsky.social/post/3mg73ihurfk2n",
            "origin": false,
            "authority": false,
            "github": []
          },
          {
            "handle": "blackhatnews.tokyo",
            "displayName": "blackhatnews.tokyo",
            "likes": 0,
            "reposts": 0,
            "replies": 0,
            "createdAt": "2026-03-02",
            "url": "https://bsky.app/profile/blackhatnews.tokyo/post/3mg3al2rvfd26",
            "origin": false,
            "authority": false,
            "github": []
          }
        ]
      },
      "telegram": {
        "mentions": 0,
        "posts": []
      }
    },
    {
      "cve": "CVE-2026-54415",
      "title": "Missing Authorization in the server management routes (routes/admin.php) in Azuriom…",
      "category": "Recall",
      "vendor": null,
      "exploited": false,
      "publiclyDisclosed": true,
      "cvss": 8.1,
      "cvssVector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N",
      "severity": "HIGH",
      "impact": null,
      "products": [],
      "productCount": 0,
      "faq": "Missing Authorization in the server management routes (routes/admin.php) in Azuriom Azuriom CMS before 1.2.11 on all platforms allows an authenticated attacker with the admin.access permission to create AzLink server tokens and take over non-admin user accounts by changing their passwords and email addresses via crafted HTTP requests to /admin/servers/create and the AzLink API endpoints (/api/azlink/password, /api/azlink/email, /api/azlink/user/{id}).",
      "pocConfidence": "confirmed",
      "pocCount": 1,
      "pocTopStars": 2,
      "pocRepos": [
        {
          "url": "https://github.com/abdugafforov-bobur/CVE-2026-54415-PoC",
          "stars": 2,
          "desc": "PoC for CVE-2026-54415 — Azuriom CMS (<1.2.11) Broken Access Control → account takeover",
          "createdAt": "2026-07-04",
          "hasCode": true
        }
      ],
      "epss": 0.00348,
      "epssPercentile": 0.27115,
      "source": "poc",
      "mitreUrl": "https://nvd.nist.gov/vuln/detail/CVE-2026-54415",
      "research": [],
      "aliases": [],
      "researchers": [],
      "x": {
        "mentions": 0,
        "aliases": [],
        "posts": []
      },
      "bsky": {
        "mentions": 2,
        "posts": [
          {
            "handle": "hugovalters.bsky.social",
            "displayName": "Hugo | DevOps | Cybersecurity 🇱🇻",
            "likes": 1,
            "reposts": 1,
            "replies": 0,
            "createdAt": "2026-06-18",
            "url": "https://bsky.app/profile/hugovalters.bsky.social/post/3moks6clrea23",
            "origin": false,
            "authority": false,
            "github": []
          },
          {
            "handle": "cve.skyfleet.blue",
            "displayName": "CVE Alerts ",
            "likes": 0,
            "reposts": 0,
            "replies": 0,
            "createdAt": "2026-06-17",
            "url": "https://bsky.app/profile/cve.skyfleet.blue/post/3moiv74u5gc2t",
            "origin": false,
            "authority": false,
            "github": []
          }
        ]
      }
    },
    {
      "cve": "CVE-2026-5524",
      "title": "The Divi Form Builder plugin for WordPress is vulnerable to Arbitrary File Upload…",
      "category": "Recall",
      "vendor": null,
      "exploited": false,
      "publiclyDisclosed": true,
      "cvss": 9.8,
      "cvssVector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "severity": "CRITICAL",
      "impact": null,
      "products": [],
      "productCount": 0,
      "faq": "The Divi Form Builder plugin for WordPress is vulnerable to Arbitrary File Upload leading to Remote Code Execution in all versions up to and including 5.1.8. This is due to insufficient file extension validation in the do_image_upload() function where user-supplied input from the acceptFileTypes POST parameter is directly interpolated into a regular expression used to validate uploaded files. Attackers can specify PHP-executable extensions such as .phtml, .phar, .php5, or .php7 to bypass the plugin's .htaccess protection which only blocks .php files specifically. Additionally, on Nginx-based servers, the .htaccess protection is completely ineffective as Nginx does not process .htaccess files. This makes it possible for unauthenticated attackers (who can obtain a nonce from any public page containing a form) to upload executable PHP files to the publicly accessible /wp-content/uploads/de_fb_uploads/ directory and achieve Remote Code Execution by accessing the uploaded file via HTTP. The vulnerability was partially patched in version 5.1.3.",
      "pocConfidence": "confirmed",
      "pocCount": 1,
      "pocTopStars": 2,
      "pocRepos": [
        {
          "url": "https://github.com/caterscam/CVE-2026-5524-PoC",
          "stars": 2,
          "desc": "",
          "createdAt": "2026-07-04",
          "hasCode": true
        }
      ],
      "epss": 0.00542,
      "epssPercentile": 0.42011,
      "source": "poc",
      "mitreUrl": "https://nvd.nist.gov/vuln/detail/CVE-2026-5524",
      "research": [],
      "aliases": [],
      "researchers": [],
      "x": {
        "mentions": 0,
        "aliases": [],
        "posts": []
      },
      "bsky": {
        "mentions": 4,
        "posts": [
          {
            "handle": "pulse-wp.com",
            "displayName": "Pulse WP",
            "likes": 0,
            "reposts": 0,
            "replies": 0,
            "createdAt": "2026-07-03",
            "url": "https://bsky.app/profile/pulse-wp.com/post/3mppahvne5w27",
            "origin": false,
            "authority": false,
            "github": []
          },
          {
            "handle": "stackflag.bsky.social",
            "displayName": "STACKFLAG",
            "likes": 0,
            "reposts": 0,
            "replies": 0,
            "createdAt": "2026-07-03",
            "url": "https://bsky.app/profile/stackflag.bsky.social/post/3mpriufaj6y2u",
            "origin": false,
            "authority": false,
            "github": []
          },
          {
            "handle": "kriptabiz.bsky.social",
            "displayName": "kripta.biz",
            "likes": 0,
            "reposts": 0,
            "replies": 0,
            "createdAt": "2026-07-03",
            "url": "https://bsky.app/profile/kriptabiz.bsky.social/post/3mppnlm5eck2m",
            "origin": false,
            "authority": false,
            "github": []
          },
          {
            "handle": "offseq.bsky.social",
            "displayName": "OffSequence",
            "likes": 0,
            "reposts": 0,
            "replies": 0,
            "createdAt": "2026-07-02",
            "url": "https://bsky.app/profile/offseq.bsky.social/post/3mpo5c24aet2x",
            "origin": false,
            "authority": false,
            "github": []
          }
        ]
      },
      "telegram": {
        "mentions": 0,
        "posts": []
      }
    },
    {
      "cve": "CVE-2026-6433",
      "title": "The Custom css-js-php WordPress plugin through 2.0.7 does not properly sanitize user…",
      "category": "Recall",
      "vendor": null,
      "exploited": false,
      "publiclyDisclosed": true,
      "cvss": 7.3,
      "cvssVector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L",
      "severity": "HIGH",
      "impact": null,
      "products": [],
      "productCount": 0,
      "faq": "The Custom css-js-php WordPress plugin through 2.0.7 does not properly sanitize user input before using it in a SQL query, and the result is passed to eval(), allowing unauthenticated users to execute arbitrary PHP code on the server.",
      "pocConfidence": "confirmed",
      "pocCount": 1,
      "pocTopStars": 2,
      "pocRepos": [
        {
          "url": "https://github.com/murrez/CVE-2026-6433",
          "stars": 2,
          "desc": "PoC for CVE-2026-6433: WordPress FlipperCode Custom CSS, JS & PHP (≤2.0.7) — unauthenticated SQLi to RCE. Python 3 stdlib; single target or bulk multi-threaded ",
          "createdAt": "2026-05-16",
          "hasCode": true
        }
      ],
      "epss": 0.00753,
      "epssPercentile": 0.5102,
      "source": "poc",
      "mitreUrl": "https://nvd.nist.gov/vuln/detail/CVE-2026-6433",
      "research": [],
      "aliases": [],
      "researchers": [],
      "x": {
        "mentions": 0,
        "aliases": [],
        "posts": []
      },
      "bsky": {
        "mentions": 2,
        "posts": [
          {
            "handle": "offseq.bsky.social",
            "displayName": "OffSequence",
            "likes": 1,
            "reposts": 0,
            "replies": 0,
            "createdAt": "2026-05-11",
            "url": "https://bsky.app/profile/offseq.bsky.social/post/3mlkqwfikpf2f",
            "origin": false,
            "authority": false,
            "github": []
          },
          {
            "handle": "cve.skyfleet.blue",
            "displayName": "CVE Alerts ",
            "likes": 0,
            "reposts": 0,
            "replies": 0,
            "createdAt": "2026-05-11",
            "url": "https://bsky.app/profile/cve.skyfleet.blue/post/3mlkntaovtw2e",
            "origin": false,
            "authority": false,
            "github": []
          }
        ]
      }
    },
    {
      "cve": "CVE-2026-6508",
      "title": "Origin Validation Error vulnerability in TUBITAK BILGEM Software Technologies…",
      "category": "Recall",
      "vendor": null,
      "exploited": false,
      "publiclyDisclosed": true,
      "cvss": 9.8,
      "cvssVector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "severity": "CRITICAL",
      "impact": null,
      "products": [],
      "productCount": 0,
      "faq": "Origin Validation Error vulnerability in TUBITAK BILGEM Software Technologies Research Institute Liderahenk allows Accessing Functionality Not Properly Constrained by ACLs.\n\nThis issue affects Liderahenk: from 2.0.1 before 2.0.2.",
      "pocConfidence": "confirmed",
      "pocCount": 1,
      "pocTopStars": 2,
      "pocRepos": [
        {
          "url": "https://github.com/jackalkarlos/EvilAhenk",
          "stars": 2,
          "desc": "CVE-2026-6508 LiderAhenk Merkezi Yönetim Sistemi mimarisinde, uç birimler (agents) arası tüm istemcilerin birbirleri üzerinde 'root' yetkisiyle kod çalıştırılma",
          "createdAt": "2026-03-10",
          "hasCode": true
        }
      ],
      "epss": 0.00223,
      "epssPercentile": 0.12958,
      "source": "poc",
      "mitreUrl": "https://nvd.nist.gov/vuln/detail/CVE-2026-6508",
      "research": [],
      "aliases": [],
      "researchers": [],
      "x": {
        "mentions": 0,
        "aliases": [],
        "posts": []
      },
      "bsky": {
        "mentions": 3,
        "posts": [
          {
            "handle": "hugovalters.bsky.social",
            "displayName": "Hugo | DevOps | Cybersecurity 🇱🇻",
            "likes": 0,
            "reposts": 0,
            "replies": 0,
            "createdAt": "2026-05-20",
            "url": "https://bsky.app/profile/hugovalters.bsky.social/post/3mmbxolgkwh2g",
            "origin": false,
            "authority": false,
            "github": []
          },
          {
            "handle": "thehackerwire.bsky.social",
            "displayName": "TheHackerWire",
            "likes": 0,
            "reposts": 0,
            "replies": 0,
            "createdAt": "2026-05-07",
            "url": "https://bsky.app/profile/thehackerwire.bsky.social/post/3mlc4o5tfjp2f",
            "origin": false,
            "authority": false,
            "github": []
          },
          {
            "handle": "cve.skyfleet.blue",
            "displayName": "CVE Alerts ",
            "likes": 0,
            "reposts": 0,
            "replies": 0,
            "createdAt": "2026-05-07",
            "url": "https://bsky.app/profile/cve.skyfleet.blue/post/3mlbfsmvfu32i",
            "origin": false,
            "authority": false,
            "github": []
          }
        ]
      },
      "telegram": {
        "mentions": 0,
        "posts": []
      }
    },
    {
      "cve": "CVE-2026-7299",
      "title": "Appsmith’s SQL query editor’s autocomplete functionality fails to sanitize database…",
      "category": "Recall",
      "vendor": null,
      "exploited": false,
      "publiclyDisclosed": true,
      "cvss": 6.3,
      "cvssVector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:L/A:N",
      "severity": "MEDIUM",
      "impact": null,
      "products": [],
      "productCount": 0,
      "faq": "Appsmith’s SQL query editor’s autocomplete functionality fails to sanitize database object names before rendering them in innerHTML, allowing an authenticated Developer to inject persistent XSS by a malicious table or column names triggering arbitrary code execution in the sessions of other workspace members when they interact with the same datasource.",
      "pocConfidence": "confirmed",
      "pocCount": 1,
      "pocTopStars": 2,
      "pocRepos": [
        {
          "url": "https://github.com/Stuub/Appsmith-1.98-Stored-XSS-Exploit",
          "stars": 2,
          "desc": "Automating the exploitation of CVE-2026-7299 - Stored XSS via Database Table/Column Names in SQL Autocomplete within Appsmith =>1.99. Initial discovery 30/03/26",
          "createdAt": "2026-03-31",
          "hasCode": true
        }
      ],
      "epss": 0.00341,
      "epssPercentile": 0.26384,
      "source": "poc",
      "mitreUrl": "https://nvd.nist.gov/vuln/detail/CVE-2026-7299",
      "research": [],
      "aliases": [],
      "researchers": [],
      "x": {
        "mentions": 0,
        "aliases": [],
        "posts": []
      },
      "bsky": {
        "mentions": 1,
        "posts": [
          {
            "handle": "cve.skyfleet.blue",
            "displayName": "CVE Alerts ",
            "likes": 0,
            "reposts": 0,
            "replies": 0,
            "createdAt": "2026-06-02",
            "url": "https://bsky.app/profile/cve.skyfleet.blue/post/3mnd3bdzmid2d",
            "origin": false,
            "authority": false,
            "github": []
          }
        ]
      }
    },
    {
      "cve": "CVE-2026-38751",
      "title": "OpenSTAManager version 2.10 and earlier contains an arbitrary file upload…",
      "category": "Recall",
      "vendor": null,
      "exploited": false,
      "publiclyDisclosed": true,
      "cvss": 7.2,
      "cvssVector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H",
      "severity": "HIGH",
      "impact": null,
      "products": [],
      "productCount": 0,
      "faq": "OpenSTAManager version 2.10 and earlier contains an arbitrary file upload vulnerability in the module update functionality (modules/aggiornamenti/upload_modules.php)",
      "pocConfidence": "confirmed",
      "pocCount": 1,
      "pocTopStars": 2,
      "pocRepos": [
        {
          "url": "https://github.com/b0ySie7e/OpenSTAManager-RCE-Exploit-CVE-2026-38751",
          "stars": 2,
          "desc": "OpenSTAManager-RCE-Exploit-CVE-2026-38751",
          "createdAt": "2026-06-27",
          "hasCode": true
        }
      ],
      "epss": 0.00372,
      "epssPercentile": 0.29555,
      "source": "poc",
      "mitreUrl": "https://nvd.nist.gov/vuln/detail/CVE-2026-38751",
      "research": [],
      "aliases": [],
      "researchers": [],
      "x": {
        "mentions": 0,
        "aliases": [],
        "posts": []
      },
      "bsky": {
        "mentions": 0,
        "posts": []
      }
    },
    {
      "cve": "CVE-2026-45156",
      "title": "Nextcloud is an open source content collaboration platform. From versions 0.3.0 to…",
      "category": "Recall",
      "vendor": null,
      "exploited": false,
      "publiclyDisclosed": true,
      "cvss": 8.1,
      "cvssVector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N",
      "severity": "HIGH",
      "impact": null,
      "products": [],
      "productCount": 0,
      "faq": "Nextcloud is an open source content collaboration platform. From versions 0.3.0 to before 3.1.0, 5.0.0 to before 5.1.0, and 6.0.0 to before 6.4.0, a missing signature verification in User OIDC allowed a malicious ID4me authority to identify as any user. This issue has been patched in versions 3.1.0, 4.1.0, 5.1.0, 6.4.0 and 8.3.0.",
      "pocConfidence": "confirmed",
      "pocCount": 1,
      "pocTopStars": 2,
      "pocRepos": [
        {
          "url": "https://github.com/cybertechajju/CVE-2026-45156-POC",
          "stars": 2,
          "desc": "This repository contains the Proof of Concept (PoC) exploit script for CVE-2026-45156",
          "createdAt": "2026-06-23",
          "hasCode": true
        }
      ],
      "epss": 0.00329,
      "epssPercentile": 0.25118,
      "source": "poc",
      "mitreUrl": "https://nvd.nist.gov/vuln/detail/CVE-2026-45156",
      "research": [],
      "aliases": [],
      "researchers": [],
      "x": {
        "mentions": 0,
        "aliases": [],
        "posts": []
      },
      "bsky": {
        "mentions": 3,
        "posts": [
          {
            "handle": "thehackerwire.bsky.social",
            "displayName": "TheHackerWire",
            "likes": 1,
            "reposts": 1,
            "replies": 0,
            "createdAt": "2026-06-01",
            "url": "https://bsky.app/profile/thehackerwire.bsky.social/post/3mnanw7diq62q",
            "origin": false,
            "authority": false,
            "github": []
          },
          {
            "handle": "o2cloud.bsky.social",
            "displayName": "CVE by o2Cloud",
            "likes": 0,
            "reposts": 1,
            "replies": 1,
            "createdAt": "2026-05-12",
            "url": "https://bsky.app/profile/o2cloud.bsky.social/post/3mlnxz7ebj62a",
            "origin": false,
            "authority": false,
            "github": []
          },
          {
            "handle": "cve.skyfleet.blue",
            "displayName": "CVE Alerts ",
            "likes": 0,
            "reposts": 1,
            "replies": 0,
            "createdAt": "2026-06-01",
            "url": "https://bsky.app/profile/cve.skyfleet.blue/post/3mnauzfzuso2n",
            "origin": false,
            "authority": false,
            "github": []
          }
        ]
      }
    },
    {
      "cve": "CVE-2026-49772",
      "title": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')…",
      "category": "Recall",
      "vendor": null,
      "exploited": false,
      "publiclyDisclosed": true,
      "cvss": 9.3,
      "cvssVector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:L",
      "severity": "CRITICAL",
      "impact": null,
      "products": [],
      "productCount": 0,
      "faq": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Liquid Web / StellarWP The Events Calendar allows Blind SQL Injection.\n\nThis issue affects The Events Calendar: from 6.15.12 through 6.16.2.",
      "pocConfidence": "confirmed",
      "pocCount": 1,
      "pocTopStars": 2,
      "pocRepos": [
        {
          "url": "https://github.com/joshuavanderpoll/CVE-2026-49772",
          "stars": 2,
          "desc": "CVE-2026-49772 — The Events Calendar (WordPress) unauthenticated blind SQLi PoC",
          "createdAt": "2026-06-22",
          "hasCode": true
        }
      ],
      "epss": 0.00229,
      "epssPercentile": 0.13809,
      "source": "poc",
      "mitreUrl": "https://nvd.nist.gov/vuln/detail/CVE-2026-49772",
      "telegram": {
        "mentions": 0,
        "posts": []
      },
      "research": [],
      "aliases": [],
      "researchers": [],
      "x": {
        "mentions": 0,
        "aliases": [],
        "posts": []
      },
      "bsky": {
        "mentions": 2,
        "posts": [
          {
            "handle": "thehackerwire.bsky.social",
            "displayName": "TheHackerWire",
            "likes": 0,
            "reposts": 0,
            "replies": 0,
            "createdAt": "2026-06-16",
            "url": "https://bsky.app/profile/thehackerwire.bsky.social/post/3mofu6j6ze72f",
            "origin": false,
            "authority": false,
            "github": []
          },
          {
            "handle": "cve.skyfleet.blue",
            "displayName": "CVE Alerts ",
            "likes": 0,
            "reposts": 0,
            "replies": 0,
            "createdAt": "2026-06-16",
            "url": "https://bsky.app/profile/cve.skyfleet.blue/post/3mofw7xjz7z2v",
            "origin": false,
            "authority": false,
            "github": []
          }
        ]
      }
    },
    {
      "cve": "CVE-2026-10523",
      "title": "An Authentication Bypass vulnerability (CWE-288) in Ivanti Sentry before the R10.5.2,…",
      "category": "Recall",
      "vendor": null,
      "exploited": false,
      "publiclyDisclosed": true,
      "cvss": 9.9,
      "cvssVector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H",
      "severity": "CRITICAL",
      "impact": null,
      "products": [],
      "productCount": 0,
      "faq": "An Authentication Bypass vulnerability (CWE-288) in Ivanti Sentry before the R10.5.2, R10.6.2 and R10.7.1 versions allows a remote unauthenticated attacker to create arbitrary administrative accounts and obtain full administrative access",
      "pocConfidence": "confirmed",
      "pocCount": 1,
      "pocTopStars": 2,
      "pocRepos": [
        {
          "url": "https://github.com/gagaltotal/CVE-2026-10523-Ivanti-sentry",
          "stars": 2,
          "desc": "CVE-2026-10520 - CVE-2026-10523 - Ivanti Sentry",
          "createdAt": "2026-06-19",
          "hasCode": true
        }
      ],
      "epss": 0.4719,
      "epssPercentile": 0.98708,
      "source": "poc",
      "mitreUrl": "https://nvd.nist.gov/vuln/detail/CVE-2026-10523",
      "telegram": {
        "mentions": 1,
        "posts": [
          {
            "channel": "p3Nt3st3rsTAr",
            "channelTitle": "[CVE Pentester] exploits forum",
            "tier": "underground",
            "date": "2026-06-10",
            "views": 158,
            "forwards": 1,
            "url": "https://t.me/p3Nt3st3rsTAr/45",
            "text": "https://github.com/p3Nt3st3r-sTAr/CVE-2026-10520-CVE-2026-10523",
            "github": [
              {
                "url": "https://github.com/p3Nt3st3r-sTAr/CVE-2026-10520-CVE-2026-10523",
                "hasCode": true
              }
            ],
            "origin": true
          }
        ]
      },
      "research": [],
      "aliases": [],
      "researchers": [],
      "x": {
        "mentions": 0,
        "aliases": [],
        "posts": []
      },
      "bsky": {
        "mentions": 20,
        "posts": [
          {
            "handle": "o2cloud.bsky.social",
            "displayName": "CVE by o2Cloud",
            "likes": 0,
            "reposts": 1,
            "replies": 1,
            "createdAt": "2026-06-10",
            "url": "https://bsky.app/profile/o2cloud.bsky.social/post/3mnws6kyyvj2e",
            "origin": false,
            "authority": false,
            "github": []
          },
          {
            "handle": "getpokemon7.bsky.social",
            "displayName": "まりーん",
            "likes": 0,
            "reposts": 0,
            "replies": 1,
            "createdAt": "2026-07-05",
            "url": "https://bsky.app/profile/getpokemon7.bsky.social/post/3mpupampjsk2l",
            "origin": false,
            "authority": false,
            "github": []
          },
          {
            "handle": "securitycyberuk.bsky.social",
            "displayName": "Security Cyber",
            "likes": 0,
            "reposts": 1,
            "replies": 0,
            "createdAt": "2026-06-22",
            "url": "https://bsky.app/profile/securitycyberuk.bsky.social/post/3movzfimayj25",
            "origin": false,
            "authority": false,
            "github": []
          },
          {
            "handle": "cerberusit.bsky.social",
            "displayName": "Cerberus IT",
            "likes": 0,
            "reposts": 0,
            "replies": 1,
            "createdAt": "2026-06-13",
            "url": "https://bsky.app/profile/cerberusit.bsky.social/post/3mo5njpbitq2w",
            "origin": false,
            "authority": false,
            "github": []
          },
          {
            "handle": "hendryadrian.bsky.social",
            "displayName": "Cybersecurity News Everyday",
            "likes": 1,
            "reposts": 0,
            "replies": 0,
            "createdAt": "2026-06-10",
            "url": "https://bsky.app/profile/hendryadrian.bsky.social/post/3mnw4exs6dr2l",
            "origin": false,
            "authority": false,
            "github": []
          },
          {
            "handle": "royans.bsky.social",
            "displayName": "Royans Tharakan",
            "likes": 0,
            "reposts": 0,
            "replies": 0,
            "createdAt": "2026-06-14",
            "url": "https://bsky.app/profile/royans.bsky.social/post/3moaahkcnk22y",
            "origin": false,
            "authority": false,
            "github": []
          }
        ]
      }
    },
    {
      "cve": "CVE-2026-11912",
      "title": "The Simple File List plugin for WordPress is vulnerable to arbitrary file…",
      "category": "Recall",
      "vendor": null,
      "exploited": false,
      "publiclyDisclosed": true,
      "cvss": 7.5,
      "cvssVector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N",
      "severity": "HIGH",
      "impact": null,
      "products": [],
      "productCount": 0,
      "faq": "The Simple File List plugin for WordPress is vulnerable to arbitrary file modification due to insufficient authorization checks in all versions up to, and including, 6.3.7. This makes it possible for unauthenticated attackers to delete and modify files on the serve. This vulnerability is exploitable even when the administrator has not enabled the AllowFrontManage setting, because the is_admin() check unconditionally short-circuits the guard before that setting is evaluated.",
      "pocConfidence": "confirmed",
      "pocCount": 1,
      "pocTopStars": 2,
      "pocRepos": [
        {
          "url": "https://github.com/Polosss/By-Poloss..-..CVE-2026-11912",
          "stars": 2,
          "desc": "Missing Authorization to Unauthenticated File Modification",
          "createdAt": "2026-06-20",
          "hasCode": true
        }
      ],
      "epss": 0.00433,
      "epssPercentile": 0.3516,
      "source": "poc",
      "mitreUrl": "https://nvd.nist.gov/vuln/detail/CVE-2026-11912",
      "research": [],
      "aliases": [],
      "researchers": [],
      "x": {
        "mentions": 0,
        "aliases": [],
        "posts": []
      },
      "bsky": {
        "mentions": 3,
        "posts": [
          {
            "handle": "postac001.bsky.social",
            "displayName": "tec_acc",
            "likes": 0,
            "reposts": 0,
            "replies": 0,
            "createdAt": "2026-06-20",
            "url": "https://bsky.app/profile/postac001.bsky.social/post/3moqbarje2p2d",
            "origin": false,
            "authority": false,
            "github": []
          },
          {
            "handle": "offseq.bsky.social",
            "displayName": "OffSequence",
            "likes": 0,
            "reposts": 0,
            "replies": 0,
            "createdAt": "2026-06-20",
            "url": "https://bsky.app/profile/offseq.bsky.social/post/3mopsnvc2xj2l",
            "origin": false,
            "authority": false,
            "github": []
          },
          {
            "handle": "cve.skyfleet.blue",
            "displayName": "CVE Alerts ",
            "likes": 0,
            "reposts": 0,
            "replies": 0,
            "createdAt": "2026-06-20",
            "url": "https://bsky.app/profile/cve.skyfleet.blue/post/3mopsmtdged2h",
            "origin": false,
            "authority": false,
            "github": []
          }
        ]
      }
    },
    {
      "cve": "CVE-2026-25212",
      "title": "An issue was discovered in Percona PMM before 3.7. Because an internal database user…",
      "category": "Recall",
      "vendor": null,
      "exploited": false,
      "publiclyDisclosed": true,
      "cvss": 9.9,
      "cvssVector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H",
      "severity": "CRITICAL",
      "impact": null,
      "products": [],
      "productCount": 0,
      "faq": "An issue was discovered in Percona PMM before 3.7. Because an internal database user retains specific superuser privileges, an attacker with pmm-admin rights can abuse the \"Add data source\" feature to break out of the database context and execute shell commands on the underlying operating system.",
      "pocConfidence": "confirmed",
      "pocCount": 1,
      "pocTopStars": 2,
      "pocRepos": [
        {
          "url": "https://github.com/5170Temp/CVE-2026-25212",
          "stars": 2,
          "desc": "POC for CVE-2026-25212",
          "createdAt": "2026-06-19",
          "hasCode": true
        }
      ],
      "epss": 0.00289,
      "epssPercentile": 0.20937,
      "source": "poc",
      "mitreUrl": "https://nvd.nist.gov/vuln/detail/CVE-2026-25212",
      "telegram": {
        "mentions": 0,
        "posts": []
      },
      "research": [],
      "aliases": [],
      "researchers": [],
      "x": {
        "mentions": 0,
        "aliases": [],
        "posts": []
      },
      "bsky": {
        "mentions": 2,
        "posts": [
          {
            "handle": "thehackerwire.bsky.social",
            "displayName": "TheHackerWire",
            "likes": 0,
            "reposts": 0,
            "replies": 0,
            "createdAt": "2026-04-03",
            "url": "https://bsky.app/profile/thehackerwire.bsky.social/post/3mil2ad2pwf2x",
            "origin": false,
            "authority": false,
            "github": []
          },
          {
            "handle": "cyber-news-fi.bsky.social",
            "displayName": "CyberNewsFI",
            "likes": 0,
            "reposts": 0,
            "replies": 0,
            "createdAt": "2026-04-03",
            "url": "https://bsky.app/profile/cyber-news-fi.bsky.social/post/3miknqzz7no2b",
            "origin": false,
            "authority": false,
            "github": []
          }
        ]
      }
    },
    {
      "cve": "CVE-2026-21510",
      "title": "Protection mechanism failure in Windows Shell allows an unauthorized attacker to…",
      "category": "Recall",
      "vendor": null,
      "exploited": true,
      "publiclyDisclosed": true,
      "cvss": 8.8,
      "cvssVector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
      "severity": "HIGH",
      "impact": null,
      "products": [],
      "productCount": 0,
      "faq": "Protection mechanism failure in Windows Shell allows an unauthorized attacker to bypass a security feature over a network.",
      "pocConfidence": "confirmed",
      "pocCount": 1,
      "pocTopStars": 2,
      "pocRepos": [
        {
          "url": "https://github.com/EpSiLoNPoInTOrI/EpSiLoNPoInTlnk",
          "stars": 2,
          "desc": "CVE-2026-21510 LNK generator PoC",
          "createdAt": "2026-05-09",
          "hasCode": true
        }
      ],
      "epss": 0.25835,
      "epssPercentile": 0.97752,
      "source": "poc",
      "mitreUrl": "https://nvd.nist.gov/vuln/detail/CVE-2026-21510",
      "research": [
        {
          "url": "https://www.penligent.ai/hackinglabs/cve-2026-21510-poc-the-smartscreen-moment-that-never-happens/",
          "type": "writeup",
          "source": "Penligent",
          "note": "SmartScreen/Shell bypass analysis"
        },
        {
          "url": "https://wnesecurity.com/cve-2026-21510-windows-shell-protection-mechanism-failure-security-feature-bypass/",
          "type": "writeup",
          "source": "WNE Security",
          "note": "Security feature bypass"
        },
        {
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-21510",
          "type": "detection",
          "source": "Microsoft MSRC",
          "note": "Official advisory"
        },
        {
          "url": "https://www.sentinelone.com/vulnerability-database/cve-2026-21510/",
          "type": "detection",
          "source": "SentinelOne",
          "note": "Vuln DB entry"
        }
      ],
      "x": {
        "mentions": 3,
        "aliases": [],
        "posts": [
          {
            "handle": "lyrie_ai",
            "followers": 236,
            "likes": 0,
            "createdAt": "2026-05-27",
            "url": "https://x.com/lyrie_ai/status/2059481238755230040",
            "github": [],
            "origin": false
          }
        ]
      },
      "bsky": {
        "mentions": 24,
        "posts": [
          {
            "handle": "infosec.skyfleet.blue",
            "displayName": "InfoSec",
            "likes": 0,
            "reposts": 0,
            "replies": 0,
            "createdAt": "2026-04-14",
            "url": "https://bsky.app/profile/infosec.skyfleet.blue/post/3mjhiivp46n25",
            "origin": false,
            "authority": true,
            "github": []
          },
          {
            "handle": "theo-t3gg.bsky.social",
            "displayName": "Theo - t3.gg {bot}",
            "likes": 1,
            "reposts": 0,
            "replies": 1,
            "createdAt": "2026-05-13",
            "url": "https://bsky.app/profile/theo-t3gg.bsky.social/post/3mlpnuz5ocr2e",
            "origin": false,
            "authority": false,
            "github": []
          },
          {
            "handle": "hendryadrian.bsky.social",
            "displayName": "Cybersecurity News Everyday",
            "likes": 1,
            "reposts": 0,
            "replies": 0,
            "createdAt": "2026-04-29",
            "url": "https://bsky.app/profile/hendryadrian.bsky.social/post/3mkn5r6q3sw2a",
            "origin": false,
            "authority": false,
            "github": []
          },
          {
            "handle": "getpokemon7.bsky.social",
            "displayName": "まりーん",
            "likes": 0,
            "reposts": 0,
            "replies": 1,
            "createdAt": "2026-04-29",
            "url": "https://bsky.app/profile/getpokemon7.bsky.social/post/3mklzsu43cs2w",
            "origin": false,
            "authority": false,
            "github": []
          },
          {
            "handle": "wdormann.infosec.exchange.ap.brid.gy",
            "displayName": "Will Dormann",
            "likes": 1,
            "reposts": 0,
            "replies": 0,
            "createdAt": "2026-04-27",
            "url": "https://bsky.app/profile/wdormann.infosec.exchange.ap.brid.gy/post/3mkiornqzr3v2",
            "origin": false,
            "authority": false,
            "github": []
          },
          {
            "handle": "yourlamentablefriends.com",
            "displayName": "AndyD",
            "likes": 0,
            "reposts": 0,
            "replies": 1,
            "createdAt": "2026-02-13",
            "url": "https://bsky.app/profile/yourlamentablefriends.com/post/3mepposicac2e",
            "origin": false,
            "authority": false,
            "github": []
          }
        ]
      },
      "telegram": {
        "mentions": 0,
        "posts": []
      },
      "aliases": [],
      "researchers": []
    },
    {
      "cve": "CVE-2026-2472",
      "title": "Stored Cross-Site Scripting (XSS) in the _genai/_evals_visualization component of…",
      "category": "Recall",
      "vendor": null,
      "exploited": false,
      "publiclyDisclosed": true,
      "cvss": null,
      "cvssVector": null,
      "severity": null,
      "impact": null,
      "products": [],
      "productCount": 0,
      "faq": "Stored Cross-Site Scripting (XSS) in the _genai/_evals_visualization component of Google Cloud Vertex AI SDK (google-cloud-aiplatform) versions from 1.98.0 up to (but not including) 1.131.0 allows an unauthenticated remote attacker to execute arbitrary JavaScript in a victim's Jupyter or Colab environment via injecting script escape sequences into model evaluation results or dataset JSON data.",
      "pocConfidence": "confirmed",
      "pocCount": 1,
      "pocTopStars": 2,
      "pocRepos": [
        {
          "url": "https://github.com/megafart1/CVE-2026-2472-Vertex-AI-SDK-Google-Cloud",
          "stars": 2,
          "desc": "Expose and detail an unauthenticated stored XSS vulnerability in the Google Cloud Vertex AI Python SDK affecting versions 1.98.0 to 1.130.9.",
          "createdAt": "2026-03-10",
          "hasCode": true
        }
      ],
      "epss": 0.00529,
      "epssPercentile": 0.41293,
      "source": "poc",
      "mitreUrl": "https://nvd.nist.gov/vuln/detail/CVE-2026-2472",
      "research": [
        {
          "url": "https://github.com/JoshuaProvoste/CVE-2026-2472-Vertex-AI-SDK-Google-Cloud",
          "type": "poc",
          "source": "JoshuaProvoste",
          "note": "Stored XSS PoC in Vertex AI SDK evals viz",
          "hasCode": true
        },
        {
          "url": "https://advisories.gitlab.com/pkg/pypi/google-cloud-aiplatform/CVE-2026-2472/",
          "type": "writeup",
          "source": "GitLab Advisories",
          "note": "Stored XSS in google-cloud-aiplatform"
        },
        {
          "url": "https://cloud.google.com/vertex-ai/docs/security-bulletins",
          "type": "writeup",
          "source": "Google Cloud",
          "note": "Official Vertex AI security bulletin"
        }
      ],
      "x": {
        "mentions": 7,
        "posts": [
          {
            "handle": "JoshuaProvoste",
            "followers": 2827,
            "likes": 36,
            "createdAt": "2026-02-27",
            "url": "https://x.com/JoshuaProvoste/status/2027414776142283042",
            "origin": true,
            "github": [
              {
                "url": "https://github.com/JoshuaProvoste/CVE-2026-2472-Vertex-AI-SDK-Google-Cloud"
              }
            ]
          },
          {
            "handle": "akaclandestine",
            "followers": 59779,
            "likes": 10,
            "createdAt": "2026-02-27",
            "url": "https://x.com/akaclandestine/status/2027455965335789851",
            "origin": false,
            "github": [
              {
                "url": "https://github.com/JoshuaProvoste/CVE-2026-2472-Vertex-AI-SDK-Google-Cloud"
              }
            ]
          },
          {
            "handle": "vuln_tracker",
            "followers": 655,
            "likes": 1,
            "createdAt": "2026-03-01",
            "url": "https://x.com/vuln_tracker/status/2028081823205478670",
            "origin": false,
            "github": []
          },
          {
            "handle": "CVEnew",
            "followers": 57565,
            "likes": 1,
            "createdAt": "2026-02-20",
            "url": "https://x.com/CVEnew/status/2024988766801461719",
            "origin": false,
            "github": []
          },
          {
            "handle": "ptdbugs",
            "followers": 1247,
            "likes": 0,
            "createdAt": "2026-03-23",
            "url": "https://x.com/ptdbugs/status/2036009657051775052",
            "origin": false,
            "github": []
          },
          {
            "handle": "_cvereports",
            "followers": 36,
            "likes": 0,
            "createdAt": "2026-02-20",
            "url": "https://x.com/_cvereports/status/2024985080066650273",
            "origin": false,
            "github": []
          }
        ],
        "aliases": []
      },
      "aliases": [
        "GCP-2026-011"
      ],
      "researchers": [
        "JoshuaProvoste"
      ],
      "bsky": {
        "mentions": 0,
        "posts": []
      }
    },
    {
      "cve": "CVE-2026-25643",
      "title": "Frigate is a network video recorder (NVR) with realtime local object detection for IP…",
      "category": "Recall",
      "vendor": null,
      "exploited": false,
      "publiclyDisclosed": true,
      "cvss": 9.1,
      "cvssVector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H",
      "severity": "CRITICAL",
      "impact": null,
      "products": [],
      "productCount": 0,
      "faq": "Frigate is a network video recorder (NVR) with realtime local object detection for IP cameras. Prior to 0.16.4, a critical Remote Command Execution (RCE) vulnerability has been identified in the Frigate integration with go2rtc. The application does not sanitize user input in the video stream configuration (config.yaml), allowing direct injection of system commands via the exec: directive. The go2rtc service executes these commands without restrictions. This vulnerability is only exploitable by an administrator or users who have exposed their Frigate install to the open internet with no authentication which allows anyone full administrative control. This vulnerability is fixed in 0.16.4.",
      "pocConfidence": "confirmed",
      "pocCount": 1,
      "pocTopStars": 2,
      "pocRepos": [
        {
          "url": "https://github.com/DyniePro/CVE-2026-25643",
          "stars": 2,
          "desc": "Exploit Frigate NVR ≤0.16.3 to execute commands remotely by abusing a configuration flaw without needing shell access or output capture.",
          "createdAt": "2026-03-07",
          "hasCode": true
        }
      ],
      "epss": 0.02874,
      "epssPercentile": 0.85292,
      "source": "poc",
      "mitreUrl": "https://nvd.nist.gov/vuln/detail/CVE-2026-25643",
      "research": [
        {
          "url": "https://github.com/joshuavanderpoll/CVE-2026-25643",
          "type": "poc",
          "source": "joshuavanderpoll",
          "note": "Blind RCE via go2rtc exec injection",
          "hasCode": true
        },
        {
          "url": "https://www.exploit-db.com/exploits/52533",
          "type": "poc",
          "source": "Exploit-DB",
          "note": "Frigate NVR 0.16.3 RCE"
        },
        {
          "url": "https://foss-daily.org/posts/frigate-rce-2026/",
          "type": "writeup",
          "source": "FOSS Daily",
          "note": "Command injection admin-level RCE writeup"
        },
        {
          "url": "https://www.tenable.com/cve/CVE-2026-25643",
          "type": "writeup",
          "source": "Tenable",
          "note": "CVE record, CVSS 9.1"
        }
      ],
      "x": {
        "mentions": 5,
        "posts": [
          {
            "handle": "CveFindCom",
            "followers": 620,
            "likes": 1,
            "createdAt": "2026-02-06",
            "url": "https://x.com/CveFindCom/status/2019881650646143050",
            "origin": false,
            "github": []
          },
          {
            "handle": "TheHackerWire",
            "followers": 167,
            "likes": 0,
            "createdAt": "2026-02-06",
            "url": "https://x.com/TheHackerWire/status/2019867968210157839",
            "origin": false,
            "github": []
          },
          {
            "handle": "CVEnew",
            "followers": 57565,
            "likes": 0,
            "createdAt": "2026-02-06",
            "url": "https://x.com/CVEnew/status/2019864523914584461",
            "origin": false,
            "github": []
          },
          {
            "handle": "0dayPublishing",
            "followers": 225,
            "likes": 0,
            "createdAt": "2026-02-06",
            "url": "https://x.com/0dayPublishing/status/2019859042366066862",
            "origin": false,
            "github": []
          },
          {
            "handle": "VulmonFeeds",
            "followers": 4043,
            "likes": 0,
            "createdAt": "2026-02-06",
            "url": "https://x.com/VulmonFeeds/status/2019631213997130099",
            "origin": false,
            "github": []
          }
        ],
        "aliases": []
      },
      "researchers": [
        "joshuavanderpoll"
      ],
      "bsky": {
        "mentions": 4,
        "posts": [
          {
            "handle": "exploitdb-bot.bsky.social",
            "displayName": "ExploitDB Bot",
            "likes": 0,
            "reposts": 0,
            "replies": 0,
            "createdAt": "2026-04-30",
            "url": "https://bsky.app/profile/exploitdb-bot.bsky.social/post/3mkp6drkw662m",
            "origin": false,
            "authority": false,
            "github": []
          },
          {
            "handle": "thehackerwire.bsky.social",
            "displayName": "TheHackerWire",
            "likes": 0,
            "reposts": 0,
            "replies": 0,
            "createdAt": "2026-02-06",
            "url": "https://bsky.app/profile/thehackerwire.bsky.social/post/3me7q2lgr6p2o",
            "origin": false,
            "authority": false,
            "github": []
          }
        ]
      },
      "telegram": {
        "mentions": 0,
        "posts": []
      },
      "aliases": []
    },
    {
      "cve": "CVE-2026-2586",
      "title": "An authenticated Remote Code Execution (RCE) vulnerability was identified in…",
      "category": "Recall",
      "vendor": null,
      "exploited": false,
      "publiclyDisclosed": true,
      "cvss": 9.1,
      "cvssVector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H",
      "severity": "CRITICAL",
      "impact": null,
      "products": [],
      "productCount": 0,
      "faq": "An authenticated Remote Code Execution (RCE) vulnerability was identified in GlassFish's Administration Console. A user with access to the panel can send crafted requests that allow the execution of arbitrary operating system commands with the privileges of the application service user.",
      "pocConfidence": "confirmed",
      "pocCount": 1,
      "pocTopStars": 2,
      "pocRepos": [
        {
          "url": "https://github.com/DeepSecurityResearch/CVE-2026-2586",
          "stars": 2,
          "desc": "",
          "createdAt": "2026-06-01",
          "hasCode": true
        }
      ],
      "epss": 0.00819,
      "epssPercentile": 0.53211,
      "source": "poc",
      "mitreUrl": "https://nvd.nist.gov/vuln/detail/CVE-2026-2586",
      "research": [
        {
          "url": "https://github.com/advisories/GHSA-96v6-hq43-x9h4",
          "type": "writeup",
          "source": "GitHub Advisory",
          "note": "Authenticated RCE in GlassFish Admin Console",
          "hasCode": null
        },
        {
          "url": "https://cve.threatint.eu/CVE/CVE-2026-2586",
          "type": "writeup",
          "source": "THREATINT",
          "note": "GlassFish EL injection RCE detail"
        }
      ],
      "x": {
        "mentions": 1,
        "aliases": [],
        "posts": [
          {
            "handle": "TuringCyberObs",
            "followers": 47,
            "likes": 0,
            "createdAt": "2026-05-21",
            "url": "https://x.com/TuringCyberObs/status/2057477219279098114",
            "github": [
              {
                "url": "https://github.com/alan-turing-institute/cyber-threat-observatory/blob/main/reports/2026-05-19/TIER_2_CVE-2026-2586.md",
                "hasCode": false
              }
            ],
            "origin": false
          }
        ]
      },
      "researchers": [
        "DeepSecurity Peru"
      ],
      "bsky": {
        "mentions": 4,
        "posts": [
          {
            "handle": "thehackerwire.bsky.social",
            "displayName": "TheHackerWire",
            "likes": 1,
            "reposts": 0,
            "replies": 0,
            "createdAt": "2026-05-20",
            "url": "https://bsky.app/profile/thehackerwire.bsky.social/post/3mmapdmmvoi2n",
            "origin": false,
            "authority": false,
            "github": []
          },
          {
            "handle": "postac001.bsky.social",
            "displayName": "tec_acc",
            "likes": 1,
            "reposts": 0,
            "replies": 0,
            "createdAt": "2026-05-19",
            "url": "https://bsky.app/profile/postac001.bsky.social/post/3mm7x7isn7i2q",
            "origin": false,
            "authority": false,
            "github": []
          },
          {
            "handle": "cyberhub.blog",
            "displayName": "CyberHub",
            "likes": 0,
            "reposts": 0,
            "replies": 0,
            "createdAt": "2026-05-21",
            "url": "https://bsky.app/profile/cyberhub.blog/post/3mmengeo4q52u",
            "origin": false,
            "authority": false,
            "github": []
          },
          {
            "handle": "cve.skyfleet.blue",
            "displayName": "CVE Alerts ",
            "likes": 0,
            "reposts": 0,
            "replies": 0,
            "createdAt": "2026-05-19",
            "url": "https://bsky.app/profile/cve.skyfleet.blue/post/3mm7tzm3gev2k",
            "origin": false,
            "authority": false,
            "github": []
          }
        ]
      },
      "telegram": {
        "mentions": 0,
        "posts": []
      },
      "aliases": []
    },
    {
      "cve": "CVE-2026-34473",
      "title": "Unauthenticated DoS in ZTE H8102E, H168N, H167A, H199A, H288A, H198A, H267A, H267N,…",
      "category": "Recall",
      "vendor": null,
      "exploited": false,
      "publiclyDisclosed": true,
      "cvss": 7.5,
      "cvssVector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
      "severity": "HIGH",
      "impact": null,
      "products": [],
      "productCount": 0,
      "faq": "Unauthenticated DoS in ZTE H8102E, H168N, H167A, H199A, H288A, H198A, H267A, H267N, H268A, H388X, H196A, H369A, H268N, H208N, H367N, H181A, and H196Q. A denial-of-service condition can be triggered against the router's web interface by sending an oversized application/x-www-form-urlencoded POST body. After triggering, the management interface may become unresponsive until the device is rebooted. This may affect any firmware version prior to 2022 (reporter observation). The supplier stated that devices are not vulnerable since 2021-03-23; operator firmware may vary.",
      "pocConfidence": "confirmed",
      "pocCount": 1,
      "pocTopStars": 2,
      "pocRepos": [
        {
          "url": "https://github.com/minanagehsalalma/cve-2026-34473-unauthenticated-dos-zte-routers",
          "stars": 2,
          "desc": "Technical breakdown of CVE-2026-34473, an unauthenticated denial of service affecting 17+ ZTE router models.",
          "createdAt": "2026-05-16",
          "hasCode": true
        }
      ],
      "epss": 0.02376,
      "epssPercentile": 0.82034,
      "source": "poc",
      "mitreUrl": "https://nvd.nist.gov/vuln/detail/CVE-2026-34473",
      "research": [
        {
          "url": "https://seclists.org/fulldisclosure/2026/May/18",
          "type": "writeup",
          "source": "Full Disclosure",
          "note": "Unauth DoS in 17+ ZTE router models advisory"
        },
        {
          "url": "https://www.exploit-db.com/exploits/52594",
          "type": "poc",
          "source": "Exploit-DB",
          "note": "ZTE routers unauthenticated DoS"
        },
        {
          "url": "https://gist.github.com/minanagehsalalma/7a8516b9b00d0008f2f25750320560c9",
          "type": "writeup",
          "source": "minanagehsalalma",
          "note": "ZTE ZXHN router vuln details gist"
        }
      ],
      "x": {
        "mentions": 1,
        "aliases": [],
        "posts": [
          {
            "handle": "MonxResearch",
            "followers": 3,
            "likes": 0,
            "createdAt": "2026-05-19",
            "url": "https://x.com/MonxResearch/status/2056679062848872544",
            "github": [],
            "origin": false
          }
        ]
      },
      "researchers": [
        "minanagehsalalma"
      ],
      "aliases": [],
      "bsky": {
        "mentions": 7,
        "posts": [
          {
            "handle": "r-netsec.bsky.social",
            "displayName": "r/netsec bot",
            "likes": 1,
            "reposts": 0,
            "replies": 0,
            "createdAt": "2026-05-19",
            "url": "https://bsky.app/profile/r-netsec.bsky.social/post/3mm7f3i6ryi2p",
            "origin": false,
            "authority": false,
            "github": []
          },
          {
            "handle": "hacker.at.thenote.app",
            "displayName": "Hacker & Security News",
            "likes": 0,
            "reposts": 0,
            "replies": 0,
            "createdAt": "2026-05-26",
            "url": "https://bsky.app/profile/hacker.at.thenote.app/post/3mms5fr5sbs2g",
            "origin": false,
            "authority": false,
            "github": []
          },
          {
            "handle": "bugxhunter.bsky.social",
            "displayName": "0xBugHunter",
            "likes": 0,
            "reposts": 0,
            "replies": 0,
            "createdAt": "2026-05-20",
            "url": "https://bsky.app/profile/bugxhunter.bsky.social/post/3mmbguqhphv2i",
            "origin": false,
            "authority": false,
            "github": []
          },
          {
            "handle": "cyberhub.blog",
            "displayName": "CyberHub",
            "likes": 0,
            "reposts": 0,
            "replies": 0,
            "createdAt": "2026-05-19",
            "url": "https://bsky.app/profile/cyberhub.blog/post/3mm7ptth7s62v",
            "origin": false,
            "authority": false,
            "github": []
          },
          {
            "handle": "thehackerwire.bsky.social",
            "displayName": "TheHackerWire",
            "likes": 0,
            "reposts": 0,
            "replies": 0,
            "createdAt": "2026-05-06",
            "url": "https://bsky.app/profile/thehackerwire.bsky.social/post/3ml7lbrq4we2l",
            "origin": false,
            "authority": false,
            "github": []
          }
        ]
      }
    },
    {
      "cve": "CVE-2026-36239",
      "title": "PbootCMS v.3.2.11 contains a code injection vulnerability in its site configuration…",
      "category": "Recall",
      "vendor": null,
      "exploited": false,
      "publiclyDisclosed": true,
      "cvss": 4.3,
      "cvssVector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:L/I:L/A:L",
      "severity": "MEDIUM",
      "impact": null,
      "products": [],
      "productCount": 0,
      "faq": "PbootCMS v.3.2.11 contains a code injection vulnerability in its site configuration functionality",
      "pocConfidence": "confirmed",
      "pocCount": 1,
      "pocTopStars": 2,
      "pocRepos": [
        {
          "url": "https://github.com/TazmiDev/CVE-2026-36239",
          "stars": 2,
          "desc": "CVE-2026-36239 | Authenticated RCE in PbootCMS ≤3.2.12",
          "createdAt": "2026-05-25",
          "hasCode": true
        }
      ],
      "epss": 0.00247,
      "epssPercentile": 0.16059,
      "source": "poc",
      "mitreUrl": "https://nvd.nist.gov/vuln/detail/CVE-2026-36239",
      "research": [],
      "x": {
        "mentions": 1,
        "posts": [
          {
            "handle": "VulmonFeeds",
            "followers": 4043,
            "likes": 0,
            "createdAt": "2026-05-25",
            "url": "https://x.com/VulmonFeeds/status/2058724977025704082",
            "origin": false,
            "github": []
          }
        ],
        "aliases": []
      },
      "aliases": [],
      "researchers": [],
      "bsky": {
        "mentions": 3,
        "posts": [
          {
            "handle": "malwareobserver.bsky.social",
            "displayName": null,
            "likes": 0,
            "reposts": 0,
            "replies": 0,
            "createdAt": "2026-07-05",
            "url": "https://bsky.app/profile/malwareobserver.bsky.social/post/3mpw6sbahne2x",
            "origin": false,
            "authority": false,
            "github": [
              {
                "url": "https://github.com/TazmiDev/CVE-2026-36239",
                "hasCode": true
              }
            ]
          },
          {
            "handle": "kriptabiz.bsky.social",
            "displayName": "kripta.biz",
            "likes": 0,
            "reposts": 0,
            "replies": 0,
            "createdAt": "2026-07-06",
            "url": "https://bsky.app/profile/kriptabiz.bsky.social/post/3mpxyt7kavm2g",
            "origin": false,
            "authority": false,
            "github": []
          },
          {
            "handle": "qiancx.bsky.social",
            "displayName": "qian.cx",
            "likes": 0,
            "reposts": 0,
            "replies": 0,
            "createdAt": "2026-07-06",
            "url": "https://bsky.app/profile/qiancx.bsky.social/post/3mpxyt75ngz22",
            "origin": false,
            "authority": false,
            "github": []
          }
        ]
      }
    }
  ],
  "checked": [
    "CVE-2026-0000",
    "CVE-2026-0013",
    "CVE-2026-0059",
    "CVE-2026-0091",
    "CVE-2026-0257",
    "CVE-2026-0265",
    "CVE-2026-0273",
    "CVE-2026-0542",
    "CVE-2026-0594",
    "CVE-2026-0596",
    "CVE-2026-0740",
    "CVE-2026-0745",
    "CVE-2026-0908",
    "CVE-2026-0920",
    "CVE-2026-0926",
    "CVE-2026-10104",
    "CVE-2026-10187",
    "CVE-2026-10243",
    "CVE-2026-10288",
    "CVE-2026-10289",
    "CVE-2026-10290",
    "CVE-2026-10520",
    "CVE-2026-10523",
    "CVE-2026-10580",
    "CVE-2026-10672",
    "CVE-2026-11344",
    "CVE-2026-11349",
    "CVE-2026-11374",
    "CVE-2026-11387",
    "CVE-2026-11405",
    "CVE-2026-11417",
    "CVE-2026-11450",
    "CVE-2026-11499",
    "CVE-2026-11518",
    "CVE-2026-11551",
    "CVE-2026-11561",
    "CVE-2026-11645",
    "CVE-2026-11784",
    "CVE-2026-11834",
    "CVE-2026-11837",
    "CVE-2026-11912",
    "CVE-2026-11989",
    "CVE-2026-12166",
    "CVE-2026-12191",
    "CVE-2026-12277",
    "CVE-2026-1232",
    "CVE-2026-12400",
    "CVE-2026-12415",
    "CVE-2026-12416",
    "CVE-2026-12432",
    "CVE-2026-12485",
    "CVE-2026-13001",
    "CVE-2026-13156",
    "CVE-2026-13233",
    "CVE-2026-13585",
    "CVE-2026-13768",
    "CVE-2026-14191",
    "CVE-2026-14266",
    "CVE-2026-14382",
    "CVE-2026-14459",
    "CVE-2026-14628",
    "CVE-2026-14762",
    "CVE-2026-14871",
    "CVE-2026-14894",
    "CVE-2026-14960",
    "CVE-2026-15282",
    "CVE-2026-15583",
    "CVE-2026-15706",
    "CVE-2026-16219",
    "CVE-2026-1814",
    "CVE-2026-1999",
    "CVE-2026-2002",
    "CVE-2026-20169",
    "CVE-2026-20223",
    "CVE-2026-20224",
    "CVE-2026-20245",
    "CVE-2026-20251",
    "CVE-2026-20262",
    "CVE-2026-20452",
    "CVE-2026-20637",
    "CVE-2026-20643",
    "CVE-2026-20833",
    "CVE-2026-20841",
    "CVE-2026-20896",
    "CVE-2026-21018",
    "CVE-2026-21045",
    "CVE-2026-21055",
    "CVE-2026-21509",
    "CVE-2026-21628",
    "CVE-2026-21852",
    "CVE-2026-21858",
    "CVE-2026-21876",
    "CVE-2026-21955",
    "CVE-2026-21978",
    "CVE-2026-22241",
    "CVE-2026-22356",
    "CVE-2026-22553",
    "CVE-2026-2256",
    "CVE-2026-22874",
    "CVE-2026-2291",
    "CVE-2026-23415",
    "CVE-2026-23479",
    "CVE-2026-23520",
    "CVE-2026-23697",
    "CVE-2026-23698",
    "CVE-2026-23760",
    "CVE-2026-23813",
    "CVE-2026-23869",
    "CVE-2026-23870",
    "CVE-2026-23921",
    "CVE-2026-24055",
    "CVE-2026-24135",
    "CVE-2026-24136",
    "CVE-2026-24207",
    "CVE-2026-2441",
    "CVE-2026-24418",
    "CVE-2026-24688",
    "CVE-2026-24849",
    "CVE-2026-25194",
    "CVE-2026-25197",
    "CVE-2026-25212",
    "CVE-2026-25262",
    "CVE-2026-25541",
    "CVE-2026-25555",
    "CVE-2026-25589",
    "CVE-2026-25632",
    "CVE-2026-25860",
    "CVE-2026-2587",
    "CVE-2026-25895",
    "CVE-2026-25993",
    "CVE-2026-26268",
    "CVE-2026-26555",
    "CVE-2026-26718",
    "CVE-2026-26719",
    "CVE-2026-26897",
    "CVE-2026-26898",
    "CVE-2026-27145",
    "CVE-2026-27172",
    "CVE-2026-27212",
    "CVE-2026-27384",
    "CVE-2026-27483",
    "CVE-2026-27495",
    "CVE-2026-27626",
    "CVE-2026-27944",
    "CVE-2026-27966",
    "CVE-2026-27971",
    "CVE-2026-28318",
    "CVE-2026-28496",
    "CVE-2026-28699",
    "CVE-2026-28766",
    "CVE-2026-28767",
    "CVE-2026-28867",
    "CVE-2026-28990",
    "CVE-2026-28992",
    "CVE-2026-28995",
    "CVE-2026-29114",
    "CVE-2026-29115",
    "CVE-2026-29116",
    "CVE-2026-29145",
    "CVE-2026-29198",
    "CVE-2026-29204",
    "CVE-2026-2942",
    "CVE-2026-29519",
    "CVE-2026-29923",
    "CVE-2026-29971",
    "CVE-2026-30502",
    "CVE-2026-30503",
    "CVE-2026-30623",
    "CVE-2026-30690",
    "CVE-2026-30691",
    "CVE-2026-30784",
    "CVE-2026-30849",
    "CVE-2026-30950",
    "CVE-2026-3102",
    "CVE-2026-31024",
    "CVE-2026-31156",
    "CVE-2026-31266",
    "CVE-2026-31278",
    "CVE-2026-31309",
    "CVE-2026-3143",
    "CVE-2026-31525",
    "CVE-2026-31694",
    "CVE-2026-3180",
    "CVE-2026-31802",
    "CVE-2026-31899",
    "CVE-2026-3227",
    "CVE-2026-32488",
    "CVE-2026-32646",
    "CVE-2026-32662",
    "CVE-2026-32746",
    "CVE-2026-32794",
    "CVE-2026-3288",
    "CVE-2026-3296",
    "CVE-2026-3300",
    "CVE-2026-33017",
    "CVE-2026-33067",
    "CVE-2026-33137",
    "CVE-2026-33146",
    "CVE-2026-33186",
    "CVE-2026-33320",
    "CVE-2026-33453",
    "CVE-2026-33454",
    "CVE-2026-33534",
    "CVE-2026-3359",
    "CVE-2026-33626",
    "CVE-2026-33634",
    "CVE-2026-33657",
    "CVE-2026-33693",
    "CVE-2026-33697",
    "CVE-2026-33712",
    "CVE-2026-34038",
    "CVE-2026-34040",
    "CVE-2026-34048",
    "CVE-2026-34156",
    "CVE-2026-34207",
    "CVE-2026-34212",
    "CVE-2026-34213",
    "CVE-2026-34234",
    "CVE-2026-3437",
    "CVE-2026-34472",
    "CVE-2026-34474",
    "CVE-2026-34835",
    "CVE-2026-34926",
    "CVE-2026-3494",
    "CVE-2026-35029",
    "CVE-2026-35030",
    "CVE-2026-35037",
    "CVE-2026-35196",
    "CVE-2026-35204",
    "CVE-2026-35250",
    "CVE-2026-35273",
    "CVE-2026-35330",
    "CVE-2026-35333",
    "CVE-2026-35397",
    "CVE-2026-35455",
    "CVE-2026-35585",
    "CVE-2026-35603",
    "CVE-2026-35616",
    "CVE-2026-3576",
    "CVE-2026-35904",
    "CVE-2026-36027",
    "CVE-2026-36213",
    "CVE-2026-36214",
    "CVE-2026-36226",
    "CVE-2026-36227",
    "CVE-2026-36228",
    "CVE-2026-3629",
    "CVE-2026-36425",
    "CVE-2026-36436",
    "CVE-2026-36438",
    "CVE-2026-36522",
    "CVE-2026-36590",
    "CVE-2026-36669",
    "CVE-2026-36670",
    "CVE-2026-36748",
    "CVE-2026-36826",
    "CVE-2026-36834",
    "CVE-2026-36848",
    "CVE-2026-36851",
    "CVE-2026-37064",
    "CVE-2026-37065",
    "CVE-2026-37066",
    "CVE-2026-37067",
    "CVE-2026-37068",
    "CVE-2026-37069",
    "CVE-2026-37070",
    "CVE-2026-37071",
    "CVE-2026-37072",
    "CVE-2026-37073",
    "CVE-2026-37149",
    "CVE-2026-37196",
    "CVE-2026-37197",
    "CVE-2026-37432",
    "CVE-2026-37637",
    "CVE-2026-3805",
    "CVE-2026-38165",
    "CVE-2026-38360",
    "CVE-2026-38361",
    "CVE-2026-38422",
    "CVE-2026-38426",
    "CVE-2026-38427",
    "CVE-2026-3844",
    "CVE-2026-38444",
    "CVE-2026-38526",
    "CVE-2026-3854",
    "CVE-2026-38698",
    "CVE-2026-38751",
    "CVE-2026-38763",
    "CVE-2026-38764",
    "CVE-2026-38765",
    "CVE-2026-38766",
    "CVE-2026-38812",
    "CVE-2026-3891",
    "CVE-2026-38934",
    "CVE-2026-38945",
    "CVE-2026-39023",
    "CVE-2026-39031",
    "CVE-2026-39047",
    "CVE-2026-39107",
    "CVE-2026-39200",
    "CVE-2026-39253",
    "CVE-2026-39259",
    "CVE-2026-39275",
    "CVE-2026-39292",
    "CVE-2026-39338",
    "CVE-2026-39492",
    "CVE-2026-39676",
    "CVE-2026-39808",
    "CVE-2026-39813",
    "CVE-2026-39938",
    "CVE-2026-39949",
    "CVE-2026-39987",
    "CVE-2026-40022",
    "CVE-2026-40047",
    "CVE-2026-40048",
    "CVE-2026-40072",
    "CVE-2026-40083",
    "CVE-2026-4020",
    "CVE-2026-40217",
    "CVE-2026-40453",
    "CVE-2026-40473",
    "CVE-2026-40519",
    "CVE-2026-40564",
    "CVE-2026-40579",
    "CVE-2026-4060",
    "CVE-2026-40701",
    "CVE-2026-40791",
    "CVE-2026-40858",
    "CVE-2026-40859",
    "CVE-2026-40860",
    "CVE-2026-40864",
    "CVE-2026-40887",
    "CVE-2026-40897",
    "CVE-2026-40987",
    "CVE-2026-41179",
    "CVE-2026-41200",
    "CVE-2026-41285",
    "CVE-2026-41490",
    "CVE-2026-41729",
    "CVE-2026-41901",
    "CVE-2026-42048",
    "CVE-2026-42055",
    "CVE-2026-42089",
    "CVE-2026-42096",
    "CVE-2026-42154",
    "CVE-2026-42203",
    "CVE-2026-42208",
    "CVE-2026-42221",
    "CVE-2026-42271",
    "CVE-2026-42527",
    "CVE-2026-4253",
    "CVE-2026-42530",
    "CVE-2026-42533",
    "CVE-2026-4255",
    "CVE-2026-42568",
    "CVE-2026-42569",
    "CVE-2026-4257",
    "CVE-2026-42589",
    "CVE-2026-42647",
    "CVE-2026-42758",
    "CVE-2026-42796",
    "CVE-2026-42880",
    "CVE-2026-42926",
    "CVE-2026-43074",
    "CVE-2026-43499",
    "CVE-2026-43500",
    "CVE-2026-43501",
    "CVE-2026-43503",
    "CVE-2026-43512",
    "CVE-2026-43515",
    "CVE-2026-43655",
    "CVE-2026-43700",
    "CVE-2026-43724",
    "CVE-2026-43735",
    "CVE-2026-43865",
    "CVE-2026-43866",
    "CVE-2026-43867",
    "CVE-2026-4390",
    "CVE-2026-44166",
    "CVE-2026-442",
    "CVE-2026-44262",
    "CVE-2026-44277",
    "CVE-2026-44338",
    "CVE-2026-44403",
    "CVE-2026-44590",
    "CVE-2026-44595",
    "CVE-2026-44596",
    "CVE-2026-44680",
    "CVE-2026-44788",
    "CVE-2026-44789",
    "CVE-2026-44825",
    "CVE-2026-44881",
    "CVE-2026-44963",
    "CVE-2026-45034",
    "CVE-2026-45067",
    "CVE-2026-45091",
    "CVE-2026-45156",
    "CVE-2026-45185",
    "CVE-2026-45247",
    "CVE-2026-45258",
    "CVE-2026-45321",
    "CVE-2026-45332",
    "CVE-2026-45401",
    "CVE-2026-45447",
    "CVE-2026-45777",
    "CVE-2026-45806",
    "CVE-2026-45829",
    "CVE-2026-46215",
    "CVE-2026-46242",
    "CVE-2026-46243",
    "CVE-2026-46275",
    "CVE-2026-4631",
    "CVE-2026-46331",
    "CVE-2026-46368",
    "CVE-2026-46376",
    "CVE-2026-46391",
    "CVE-2026-46394",
    "CVE-2026-46395",
    "CVE-2026-46420",
    "CVE-2026-46442",
    "CVE-2026-46453",
    "CVE-2026-46454",
    "CVE-2026-46455",
    "CVE-2026-46456",
    "CVE-2026-46457",
    "CVE-2026-46490",
    "CVE-2026-46552",
    "CVE-2026-46558",
    "CVE-2026-46584",
    "CVE-2026-46585",
    "CVE-2026-46586",
    "CVE-2026-46587",
    "CVE-2026-46588",
    "CVE-2026-46590",
    "CVE-2026-46591",
    "CVE-2026-46592",
    "CVE-2026-46645",
    "CVE-2026-46680",
    "CVE-2026-46716",
    "CVE-2026-46726",
    "CVE-2026-46817",
    "CVE-2026-46840",
    "CVE-2026-47100",
    "CVE-2026-47101",
    "CVE-2026-47102",
    "CVE-2026-47323",
    "CVE-2026-47342",
    "CVE-2026-47423",
    "CVE-2026-47429",
    "CVE-2026-47670",
    "CVE-2026-47729",
    "CVE-2026-47777",
    "CVE-2026-4782",
    "CVE-2026-48017",
    "CVE-2026-48019",
    "CVE-2026-48020",
    "CVE-2026-48030",
    "CVE-2026-48095",
    "CVE-2026-48172",
    "CVE-2026-48188",
    "CVE-2026-48203",
    "CVE-2026-48204",
    "CVE-2026-48205",
    "CVE-2026-48206",
    "CVE-2026-48208",
    "CVE-2026-4858",
    "CVE-2026-48595",
    "CVE-2026-48598",
    "CVE-2026-48611",
    "CVE-2026-48710",
    "CVE-2026-48732",
    "CVE-2026-48770",
    "CVE-2026-48800",
    "CVE-2026-48813",
    "CVE-2026-4882",
    "CVE-2026-4883",
    "CVE-2026-48849",
    "CVE-2026-48866",
    "CVE-2026-48907",
    "CVE-2026-48908",
    "CVE-2026-48909",
    "CVE-2026-4893",
    "CVE-2026-48939",
    "CVE-2026-48962",
    "CVE-2026-49042",
    "CVE-2026-49048",
    "CVE-2026-49049",
    "CVE-2026-49060",
    "CVE-2026-49079",
    "CVE-2026-49083",
    "CVE-2026-49085",
    "CVE-2026-49086",
    "CVE-2026-49097",
    "CVE-2026-49098",
    "CVE-2026-49099",
    "CVE-2026-49104",
    "CVE-2026-49105",
    "CVE-2026-49230",
    "CVE-2026-49344",
    "CVE-2026-49345",
    "CVE-2026-49352",
    "CVE-2026-49365",
    "CVE-2026-49413",
    "CVE-2026-49417",
    "CVE-2026-49468",
    "CVE-2026-49492",
    "CVE-2026-49757",
    "CVE-2026-49772",
    "CVE-2026-49777",
    "CVE-2026-49869",
    "CVE-2026-49943",
    "CVE-2026-49952",
    "CVE-2026-50011",
    "CVE-2026-50131",
    "CVE-2026-50142",
    "CVE-2026-50181",
    "CVE-2026-50229",
    "CVE-2026-5027",
    "CVE-2026-5029",
    "CVE-2026-50338",
    "CVE-2026-50656",
    "CVE-2026-50746",
    "CVE-2026-50751",
    "CVE-2026-5076",
    "CVE-2026-50979",
    "CVE-2026-50980",
    "CVE-2026-51119",
    "CVE-2026-51385",
    "CVE-2026-5172",
    "CVE-2026-51788",
    "CVE-2026-51833",
    "CVE-2026-51947",
    "CVE-2026-5203",
    "CVE-2026-52100",
    "CVE-2026-52199",
    "CVE-2026-52217",
    "CVE-2026-5229",
    "CVE-2026-52614",
    "CVE-2026-52656",
    "CVE-2026-52658",
    "CVE-2026-52806",
    "CVE-2026-52813",
    "CVE-2026-52885",
    "CVE-2026-52910",
    "CVE-2026-52943",
    "CVE-2026-53075",
    "CVE-2026-53359",
    "CVE-2026-53360",
    "CVE-2026-53519",
    "CVE-2026-53571",
    "CVE-2026-53582",
    "CVE-2026-53595",
    "CVE-2026-5364",
    "CVE-2026-53647",
    "CVE-2026-5366",
    "CVE-2026-53694",
    "CVE-2026-53753",
    "CVE-2026-53787",
    "CVE-2026-53805",
    "CVE-2026-53913",
    "CVE-2026-54088",
    "CVE-2026-5411",
    "CVE-2026-5415",
    "CVE-2026-54161",
    "CVE-2026-5426",
    "CVE-2026-54316",
    "CVE-2026-54337",
    "CVE-2026-54350",
    "CVE-2026-54390",
    "CVE-2026-54415",
    "CVE-2026-54420",
    "CVE-2026-54424",
    "CVE-2026-54477",
    "CVE-2026-54519",
    "CVE-2026-54520",
    "CVE-2026-54596",
    "CVE-2026-54597",
    "CVE-2026-54686",
    "CVE-2026-54761",
    "CVE-2026-54806",
    "CVE-2026-54807",
    "CVE-2026-54998",
    "CVE-2026-5513",
    "CVE-2026-55168",
    "CVE-2026-55200",
    "CVE-2026-5524",
    "CVE-2026-55255",
    "CVE-2026-55488",
    "CVE-2026-55494",
    "CVE-2026-55511",
    "CVE-2026-55579",
    "CVE-2026-55584",
    "CVE-2026-5562",
    "CVE-2026-55726",
    "CVE-2026-56011",
    "CVE-2026-56111",
    "CVE-2026-56121",
    "CVE-2026-56129",
    "CVE-2026-56423",
    "CVE-2026-56782",
    "CVE-2026-56876",
    "CVE-2026-57155",
    "CVE-2026-57239",
    "CVE-2026-57517",
    "CVE-2026-57588",
    "CVE-2026-57821",
    "CVE-2026-57829",
    "CVE-2026-57830",
    "CVE-2026-57850",
    "CVE-2026-57851",
    "CVE-2026-58116",
    "CVE-2026-58138",
    "CVE-2026-58457",
    "CVE-2026-5950",
    "CVE-2026-59734",
    "CVE-2026-59827",
    "CVE-2026-6009",
    "CVE-2026-60121",
    "CVE-2026-60137",
    "CVE-2026-6043",
    "CVE-2026-6130",
    "CVE-2026-61343",
    "CVE-2026-6145",
    "CVE-2026-62183",
    "CVE-2026-6271",
    "CVE-2026-62958",
    "CVE-2026-63030",
    "CVE-2026-6421",
    "CVE-2026-6433",
    "CVE-2026-6508",
    "CVE-2026-6664",
    "CVE-2026-6741",
    "CVE-2026-6815",
    "CVE-2026-6857",
    "CVE-2026-6875",
    "CVE-2026-69212",
    "CVE-2026-6960",
    "CVE-2026-6992",
    "CVE-2026-7275",
    "CVE-2026-7299",
    "CVE-2026-7392",
    "CVE-2026-7458",
    "CVE-2026-7459",
    "CVE-2026-7465",
    "CVE-2026-7473",
    "CVE-2026-7515",
    "CVE-2026-7574",
    "CVE-2026-7654",
    "CVE-2026-7665",
    "CVE-2026-7791",
    "CVE-2026-7867",
    "CVE-2026-8023",
    "CVE-2026-8037",
    "CVE-2026-8053",
    "CVE-2026-8054",
    "CVE-2026-8196",
    "CVE-2026-8206",
    "CVE-2026-8380",
    "CVE-2026-8388",
    "CVE-2026-8451",
    "CVE-2026-8461",
    "CVE-2026-8697",
    "CVE-2026-8713",
    "CVE-2026-8809",
    "CVE-2026-8832",
    "CVE-2026-8836",
    "CVE-2026-8838",
    "CVE-2026-8932",
    "CVE-2026-9018",
    "CVE-2026-9067",
    "CVE-2026-9082",
    "CVE-2026-9090",
    "CVE-2026-9198",
    "CVE-2026-9271",
    "CVE-2026-9277",
    "CVE-2026-9290",
    "CVE-2026-9490",
    "CVE-2026-9558",
    "CVE-2026-9560",
    "CVE-2026-9691",
    "CVE-2026-9789",
    "CVE-2026-999999"
  ]
}
