24h | 7d | 30d

Overview

  • Drupal
  • Drupal core

10 Jul 2026
Published
13 Jul 2026
Updated

CVSS
Pending
EPSS
0.22%

KEV

Description

Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Drupal Drupal core allows Object Injection. This issue affects Drupal core versions: from 0.0.0 to 10.5.12, from 10.6.0 to 10.6.11, from 11.2.0 to 11.2.14, from 11.3.0 to 11.3.12, from 0.0.0 to 11.0.*, from 0.0.0 to 11.1.*.

Statistics

  • 1 Post

Last activity: 23 hours ago

Bluesky

Profile picture fallback
@mandiant.com Google details its Agentic Vulnerability Discovery Harness (AVDH) for rapid AI-driven source code analysis. - IOCs: CVE-2026-13242, CVE-2026-55803 - #AI #ThreatIntel #VulnMgmt
  • 0
  • 0
  • 0
  • 23h ago

Overview

  • mlflow
  • mlflow

17 Aug 2026
Published
19 Aug 2026
Updated

CVSS v3.1
CRITICAL (9.3)
EPSS
1.11%

KEV

Description

MLflow is an open source AI engineering platform for agents, large language models, and machine learning models. Prior to 3.15.0, the unauthenticated POST /api/2.0/mlflow/webhooks/{id}/test endpoint calls _validate_webhook_url() in mlflow/utils/validation.py only for the original URL while mlflow/webhooks/delivery.py follows redirects and re-resolves the hostname without pinning the validated address, allowing attackers to reach internal or cloud metadata services and receive response_status and response_body. This issue is fixed in version 3.15.0.

Statistics

  • 1 Post

Last activity: 18 hours ago

Bluesky

Profile picture fallback
Two critical vulnerabilities in MLflow (CVE-2026-64849, CVSS 9.3) and FUXA (CVE-2026-25895, CVSS 9.5) are under active exploitation. Attackers are exploiting […]
  • 0
  • 0
  • 0
  • 18h ago

Overview

  • VMware
  • Cloud Foundation

30 Jul 2026
Published
19 Aug 2026
Updated

CVSS v3.1
CRITICAL (9.8)
EPSS
2.40%

Description

VMware vCenter contains a directory traversal vulnerability in the Syslog server. A malicious actor with network access to vCenter may exploit this issue to execute arbitrary code.

Statistics

  • 1 Post

Last activity: 20 hours ago

Bluesky

Profile picture fallback
~Cisa~ CISA added four actively exploited vulnerabilities to its KEV Catalog, including flaws in Microsoft and VMware products. - IOCs: CVE-2026-33824, CVE-2026-55040, CVE-2026-59310 - #CISA #KEV #ThreatIntel
  • 0
  • 0
  • 0
  • 20h ago

Overview

  • cisagov
  • Malcolm

11 Aug 2026
Published
13 Aug 2026
Updated

CVSS v3.1
MEDIUM (5.4)
EPSS
0.25%

KEV

Description

Malcolm is a network traffic analysis tool suite. Prior to version 26.07.0, `safe-extract.py` protects file extraction with libarchive's secure flags, but creates directory entries with a raw `os.makedirs(os.path.join(dest, entry.pathname))` that has no traversal protection. An uploaded malicious archive containing a directory entry with a `../` sequence or an absolute path causes the filebeat processing container to create directories outside the intended extraction directory. Version 26.07.0 fixes the issue.

Statistics

  • 1 Post

Last activity: 20 hours ago

Bluesky

Profile picture fallback
~Cisa~ CISA Malcolm network traffic analysis tool has multiple vulnerabilities allowing DoS and arbitrary code execution. - IOCs: CVE-2026-55676, CVE-2026-63133, CVE-2026-63134 - #CISA #CVE #Malcolm #ThreatIntel
  • 0
  • 0
  • 0
  • 20h ago

Overview

  • cisagov
  • Malcolm

11 Aug 2026
Published
12 Aug 2026
Updated

CVSS v3.1
HIGH (8.8)
EPSS
0.30%

KEV

Description

Malcolm is a network traffic analysis tool suite. The file-upload component (FilePond PHP backend) accepts uploads at `POST /server/php/submit.php` and stores them in a directory served by the same nginx and php-fpm instance. The allow-list that should restrict accepted file types is an empty array by default (`file-upload/php/config.php:16`), so the type check is a no-op and every extension is accepted. The filename sanitizer keeps the `.php` extension intact. Committed files land in `/var/www/upload/server/php/files` (`file-upload/php/config.php:7`), and the component's nginx routes any URL ending in `.php` to php-fpm. An authenticated `GET /server/php/files/<name>.php` then executes the uploaded code as `www-data`. Prior to version 26.06.1, in RBAC mode, the upload endpoint is reachable by the granular `ROLE_UPLOAD` role (`nginx/lua/nginx_auth_helpers.lua:71`), a role intended only for submitting capture files. As a result, a user holding the upload-only role runs arbitrary PHP as `www-data` inside the file-upload container. Version 26.06.1 fixes the issue.

Statistics

  • 1 Post

Last activity: 20 hours ago

Bluesky

Profile picture fallback
~Cisa~ CISA Malcolm network traffic analysis tool has multiple vulnerabilities allowing DoS and arbitrary code execution. - IOCs: CVE-2026-55676, CVE-2026-63133, CVE-2026-63134 - #CISA #CVE #Malcolm #ThreatIntel
  • 0
  • 0
  • 0
  • 20h ago

Overview

  • cisagov
  • Malcolm

11 Aug 2026
Published
12 Aug 2026
Updated

CVSS v3.1
MEDIUM (6.5)
EPSS
0.25%

KEV

Description

Malcolm is a network traffic analysis tool suite. Prior to version 26.07.0, `safe-extract.py` extracts uploaded archives with no limit on entry count, directory depth, total entries, or output size. A small malicious archive containing a large number of directory or file entries causes the filebeat processing container to create an unbounded number of filesystem objects, exhausting inodes or filesystem metadata and denying service to the processing pipeline and any service sharing the same mount. Version 26.07.0 fixes the issue.

Statistics

  • 1 Post

Last activity: 20 hours ago

Bluesky

Profile picture fallback
~Cisa~ CISA Malcolm network traffic analysis tool has multiple vulnerabilities allowing DoS and arbitrary code execution. - IOCs: CVE-2026-55676, CVE-2026-63133, CVE-2026-63134 - #CISA #CVE #Malcolm #ThreatIntel
  • 0
  • 0
  • 0
  • 20h ago
Showing 51 to 56 of 56 CVEs