24h | 7d | 30d

Overview

  • Microsoft
  • Microsoft Malware Protection Engine

20 May 2026
Published
22 May 2026
Updated

CVSS v3.1
HIGH (7.8)
EPSS
5.22%

Description

Improper link resolution before file access ('link following') in Microsoft Defender allows an authorized attacker to elevate privileges locally.

Statistics

  • 1 Post

Last activity: 15 hours ago

Fediverse

Profile picture fallback

Your antivirus is now the exploit. Defender's own remediation engine writes SYSTEM-level files to attacker-chosen paths via a symlink race. Check MPE version 1.1.26040.8 manually. Auto-update is a faith-based control.
decryptiondigest.com/blog/cve-

  • 0
  • 0
  • 0
  • 15h ago

Overview

  • Google Cloud
  • Internal Integration Platform APIs

15 May 2026
Published
15 May 2026
Updated

CVSS v4.0
CRITICAL (10.0)
EPSS
0.42%

KEV

Description

An Improper Access Control vulnerability in several internal API endpoints for Google Cloud Application Integration prior to 2026-01-23 allows a remote, unauthenticated attacker to disclose sensitive internal information and execute arbitrary code using specially crafted HTTP requests to inadvertently exposed internal API endpoints.

Statistics

  • 2 Posts

Last activity: 15 hours ago

Fediverse

Profile picture fallback

$148,337 paid by Google to a researcher (@brutecat) who found debug endpoints on Google Cloud allowing to configure privileged workflows leading to full in Google Cloud production (CVE-2026-2031)

👇
brutecat.com/articles/google-c

  • 0
  • 0
  • 1
  • 15h ago

Overview

  • prefecthq
  • prefecthq/prefect

24 May 2026
Published
24 May 2026
Updated

CVSS v3.0
HIGH (8.5)
EPSS
Pending

KEV

Description

A vulnerability in the `GitHubRepository` block of the `prefect-github` integration in Prefect version 3.6.18 allows an attacker to inject arbitrary git command-line options via the `reference` field. The `reference` field is concatenated directly into a `git clone` command string without proper sanitization, and then parsed by `shlex.split()`. This enables injection of options such as `-c`, leading to potential Server-Side Request Forgery (SSRF), credential theft, or remote code execution (RCE). The vulnerability affects both the `aget_directory()` and `get_directory()` methods in `src/integrations/prefect-github/prefect_github/repository.py`. This issue does not affect the GitLab and BitBucket integrations, which use a safer list-based command construction approach.

Statistics

  • 1 Post

Last activity: 20 hours ago

Fediverse

Profile picture fallback

🚨 HIGH severity: CVE-2026-3515 in Prefect's GitHub integration (v3.6.18) lets attackers inject git options via 'reference' field, risking SSRF, credential theft, or RCE. No patch yet — avoid untrusted input! radar.offseq.com/threat/cve-20

  • 0
  • 0
  • 0
  • 20h ago
Showing 11 to 13 of 13 CVEs