ZeroHour

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2025-40949
+2 in the same advisory: …40947 …40948
A vulnerability has been identified in RUGGEDCOM ROX MX5000 (All versions < V2.17.1), RUGGEDCOM ROX MX5000RE (All versions < V2.17.1), RUGGEDCOM ROX RX1400 (All

A vulnerability has been identified in RUGGEDCOM ROX MX5000 (All versions < V2.17.1), RUGGEDCOM ROX MX5000RE (All versions < V2.17.1), RUGGEDCOM ROX RX1400 (All versions < V2.17.1), RUGGEDCOM ROX RX1500 (All versions < V2.17.1), RUGGEDCOM ROX RX1501 (All versions < V2.17.1), RUGGEDCOM ROX RX1510 (All versions < V2.17.1), RUGGEDCOM ROX RX1511 (All versions < V2.17.1), RUGGEDCOM ROX RX1512 (All versions < V2.17.1), RUGGEDCOM ROX RX1524 (All versions < V2.17.1), RUGGEDCOM ROX RX1536 (All versions < V2.17.1), RUGGEDCOM ROX RX5000 (All versions < V2.17.1). Affected devices do not properly sanitize user-supplied input in the Scheduler functionality of the Web UI, allowing commands to be injected into the task scheduling backend. This could allow an authenticated remote attacker to execute arbitrary commands with root privileges on the underlying operating system.

NVD description · AI analysis pending
8.9
group max
<1%
  • siemens ruggedcom rox mx5000 firmware
  • siemens ruggedcom rox mx5000re firmware
  • siemens ruggedcom rox rx1400 firmware
  • +1 more
CVE-2025-66376
Stored Cross-Site Scripting in Synacor Zimbra Collaboration Suite Classic UI

Zimbra Collaboration Suite (ZCS) 10 before 10.0.18 and 10.1 before 10.1.13 is vulnerable to stored cross-site scripting through its Classic webmail interface. An attacker sends an HTML e-mail containing a Cascading Style Sheets (CSS) @import directive, and when a recipient opens that message in Classic UI, the injected content executes as script in the victim's browser session. Successful exploitation lets an attacker run arbitrary JavaScript in the Zimbra webmail context, potentially hijacking the session, reading mail, or acting as the user, consistent with the cross-scope impact reflected in the 6.1 CVSS score. Only deployments running the affected ZCS 10/10.1 versions with the Classic UI enabled are exposed; organizations on patched releases or not using Classic UI are not impacted. CISA added the flaw to the Known Exploited Vulnerabilities catalog on 2026-03-18, confirming exploitation in the wild, and recent reporting describes Zimbra flaws being used by Russian-aligned espionage actors against Western and Ukrainian targets.

Do: Upgrade ZCS to 10.0.18 or 10.1.13 (or later) following vendor instructions, as required by CISA's BOD 22-01 KEV guidance; federal agencies and critical infrastructure should prioritize this by the catalog deadline. Until patched, filter or sanitize HTML mail containing CSS @import directives and consider restricting or disabling the Classic UI. Check mailboxes and webmail access logs for suspicious HTML messages and unexplained session activity, which may indicate exploitation.

6.120% KEV
  • Synacor Zimbra Collaboration Suite (ZCS) 10 10.x before 10.0.18
  • Synacor Zimbra Collaboration Suite (ZCS) 10.1 10.1.x before 10.1.13
largetens of thousands of internet-exposed Zimbra servers (public internet scans typically surface on the order of 50,000+ Zimbra instances), affecting an estimated…
CVE-2026-10591
Insufficient access control restrictions in the file write tool in Amazon Kiro IDE before version 0.11 might allow remote unauthenticated actors to execute arbi

Insufficient access control restrictions in the file write tool in Amazon Kiro IDE before version 0.11 might allow remote unauthenticated actors to execute arbitrary commands via crafted instructions that cause writes to execution-sensitive paths (such as .vscode/tasks.json), enabling auto-execution on folder open. To remediate this issue, users should upgrade to Kiro IDE version 0.11 or later.

NVD description · AI analysis pending
8.6<1%
  • amazon kiro ide
CVE-2026-12927
CWE-787 Out-of-bounds write vulnerability exists that could cause loss of data or potentially risk arbitrary code execution when a malicious CGF file is importe

CWE-787 Out-of-bounds write vulnerability exists that could cause loss of data or potentially risk arbitrary code execution when a malicious CGF file is imported to IGSS Definition.

NVD description · AI analysis pending
8.4<1%
CVE-2026-14985
The Analog Way Picturall Quad Compact Mark II version 3.5.8, contains a local privilege escalation vulnerability in the core firmware.

The Analog Way Picturall Quad Compact Mark II version 3.5.8, contains a local privilege escalation vulnerability in the core firmware. This is due to improper privilege delegation and insufficient input validation in a maintenance script.

NVD description · AI analysis pending
7.8<1%
CVE-2026-15226
A sandbox confinement bypass vulnerability exists in Canonical snapd within its internal execution environment compiler (snap-confine).

A sandbox confinement bypass vulnerability exists in Canonical snapd within its internal execution environment compiler (snap-confine). The default seccomp security templates generated by the engine to restrict system calls do not filter or reject process operations capable of creating or manipulating file execution flags with set-user-ID attributes. Consequently, an application running within a strictly confined snap environment can successfully compile or drop binaries and apply setuid properties to them. If a compromised or malicious process inside the snap sandbox executes these generated setuid binaries, it can potentially circumvent architectural sandboxing assumptions, drop intended restriction policies, or execute privileged actions inside the container namespace that should otherwise be strictly blocked. The vulnerability has been resolved by hardening the seccomp template engine to block the execution and creation of setuid executables by sandboxed snap processes.

NVD description · AI analysis pending
8.4<1%
CVE-2026-15342
Plane contains a multi‑tenant authorization flaw in its asset‑management API that allows authenticated users from one workspace to access, delete, or duplicate

Plane contains a multi‑tenant authorization flaw in its asset‑management API that allows authenticated users from one workspace to access, delete, or duplicate assets belonging to another workspace by providing only the victim workspace slug and asset ID. The affected endpoints return presigned file URLs and enable destructive or duplicative actions without verifying that the requester is a member of the targeted workspace. This enables cross‑tenant data exposure, data deletion, and persistent exfiltration of files into an attacker‑controlled workspace.

NVD description · AI analysis pending
6.5<1%
CVE-2026-15611
Logto allows unverified email-based SSO account linking, enabling an attacker to register an identity at a permissive IdP using a victim’s email and gain unauth

Logto allows unverified email-based SSO account linking, enabling an attacker to register an identity at a permissive IdP using a victim’s email and gain unauthorized access to the victim’s account.

NVD description · AI analysis pending
9.1<1%
CVE-2026-15617
Logto performs principal lookup without normalizing email and identifier strings, enabling principal collision and unauthorized account access via case- or Unic

Logto performs principal lookup without normalizing email and identifier strings, enabling principal collision and unauthorized account access via case- or Unicode-different identities.

NVD description · AI analysis pending
9.1<1%
CVE-2026-15901
+2 in the same advisory: …15900 …15899
Use after free in Network in Google Chrome prior to 150.0.7871.128 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

Use after free in Network in Google Chrome prior to 150.0.7871.128 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Critical)

NVD description · AI analysis pending
9.6<1%
  • google chrome
CVE-2026-16157
Duplicati v2.3.0.1 backup software gives Authenticated Users MODIFY permissions that propagate to all subdirectories.

Duplicati v2.3.0.1 backup software gives Authenticated Users MODIFY permissions that propagate to all subdirectories. Installing the software outside of the Program Files directory, or on a custom path, creates a LocalSystem service running from a directory that any standard local user can write to. A standard local user can overwrite any DLL in the service directory. On service restart, the OS loads the attacker's DLL before any managed code runs, executing arbitrary code as SYSTEM.

NVD description · AI analysis pending
7.8<1%
CVE-2026-16232
Authentication Bypass in Check Point SmartConsole Grants Full Admin Access

Check Point SmartConsole, the administrative client used to manage Quantum Security Management and Multi-Domain Security Management, contains an authentication bypass (CWE-287) in its login process that allows an unauthenticated remote attacker to obtain an application login token and authenticate with full administrative privileges. Exploitation is possible when the Management Server IP address is reachable from the internet and the configuration does not restrict Trusted Clients. A successful attacker can modify security policies and security configurations, effectively taking control of firewall management. Any organization running an internet-exposed Check Point management server without Trusted Client restrictions is affected, though Check Point reports exploitation has impacted only a very small number of customers. The flaw was added to CISA's KEV on 2026-07-22, is actively exploited, and press reports indicate public proof-of-concept code has been released.

Do: Apply the fix released in Check Point's advisory for CVE-2026-16232 by updating SmartConsole and the associated Quantum/MDS management software; no fixed version numbers were provided in this data, so confirm them against the vendor bulletin. As an interim mitigation, restrict internet access to the Management Server IP address and configure Trusted Clients so SmartConsole connections are accepted only from known administrator addresses. Review management logs for unexpected logins, unauthenticated token issuance, or unfamiliar administrator sessions, and complete remediation per CISA BOD 26-04 given the KEV listing.

9.372% KEV
  • Check Point SmartConsole
  • Check Point Quantum Security Management
  • Check Point Multi-Domain Security Management
largeplausibly tens of thousands of Check Point management deployments, though the vulnerable subset is only those with an internet-exposed Management Server and no…
CVE-2026-16412
+2 in the same advisory: …16411 …16360
Memory safety bugs present in Firefox ESR 140.12 and Firefox 152.

Memory safety bugs present in Firefox ESR 140.12 and Firefox 152. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 153, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13.

NVD description · AI analysis pending
9.8<1%
  • mozilla firefox
CVE-2026-16723
A remote code execution (RCE) vulnerability exists in fastjson 1.2.68 through 1.2.83.

A remote code execution (RCE) vulnerability exists in fastjson 1.2.68 through 1.2.83. This vulnerability is exploitable under fastjson's stock default configuration — no AutoType enablement required, no classpath gadget required.

NVD description · AI analysis pending
9.016%
CVE-2026-23794
+1 in the same advisory: …23795
Reflected XSS in Apache Syncope's Enduser Login page.

Reflected XSS in Apache Syncope's Enduser Login page. An attacker that tricks a legitimate user into clicking a malicious link and logging in to Syncope Enduser could steal that user's credentials. This issue affects Apache Syncope: from 3.0 through 3.0.15, from 4.0 through 4.0.3. Users are recommended to upgrade to version 3.0.16 / 4.0.4, which fix this issue.

NVD description · AI analysis pending
6.8
group max
<1%
  • apache syncope
CVE-2026-32194
+1 in the same advisory: …32191
Improper neutralization of special elements used in a command ('command injection') in Microsoft Bing Images allows an unauthorized attacker to execute code ove

Improper neutralization of special elements used in a command ('command injection') in Microsoft Bing Images allows an unauthorized attacker to execute code over a network.

NVD description · AI analysis pending
9.81%
  • microsoft bing images
CVE-2026-42953
The application contains an out-of-bounds write vulnerability that can be exploited by an attacker to cause the program to write data past the end of an allocat

The application contains an out-of-bounds write vulnerability that can be exploited by an attacker to cause the program to write data past the end of an allocated memory buffer. This can lead to arbitrary code execution.

NVD description · AI analysis pending
8.4<1%
CVE-2026-42958
The application contains a use-after-free vulnerability that can be exploited to cause memory corruption while parsing specially crafted files.

The application contains a use-after-free vulnerability that can be exploited to cause memory corruption while parsing specially crafted files. This could allow an attacker to execute arbitrary code in the context of the current process.

NVD description · AI analysis pending
8.4<1%
CVE-2026-47056
Vulnerability in the Oracle Data Integrator product of Oracle Fusion Middleware (component:

Vulnerability in the Oracle Data Integrator product of Oracle Fusion Middleware (component: Rest Service). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Data Integrator. While the vulnerability is in Oracle Data Integrator, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Data Integrator. CVSS 3.1 Base Score 10.0 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H).

NVD description · AI analysis pending
10.0<1%
  • oracle data integrator
CVE-2026-48294
Adobe Acrobat PDF Extension (Chrome) versions 26.5.2.2 and earlier are affected by a UXSS-class cross-origin data disclosure vulnerability.

Adobe Acrobat PDF Extension (Chrome) versions 26.5.2.2 and earlier are affected by a UXSS-class cross-origin data disclosure vulnerability. An attacker could exploit this vulnerability to gain access to data regarding the victim's session. Exploitation of this issue requires user interaction in that a victim must visit a maliciously crafted URL or interact with a compromised web page. Scope is changed.

NVD description · AI analysis pending
7.42%
  • adobe acrobat
CVE-2026-49033
The application contains a stack-based buffer overflow vulnerability that can be exploited by an attacker to execute arbitrary code.

The application contains a stack-based buffer overflow vulnerability that can be exploited by an attacker to execute arbitrary code.

NVD description · AI analysis pending
8.4<1%
CVE-2026-54052
n8n-MCP is an MCP server that provides AI assistants access to n8n node documentation, properties, and operations.

n8n-MCP is an MCP server that provides AI assistants access to n8n node documentation, properties, and operations. Prior to 2.56.1, in HTTP mode with multi-tenancy enabled through ENABLE_MULTI_TENANT=true, n8n-mcp's local workflow version history backups were not isolated per tenant, allowing an authenticated tenant to read workflow version snapshots belonging to other tenants and delete or destroy other tenants' stored backups, including full node definitions, credential references, and authorization headers. This issue is fixed in version 2.56.1.

NVD description · AI analysis pending
9.9<1%
  • n8n-mcp n8n-mcp
CVE-2026-54121
Improper authorization in Active Directory Certificate Services (AD CS) allows an authorized attacker to elevate privileges over a network.

Improper authorization in Active Directory Certificate Services (AD CS) allows an authorized attacker to elevate privileges over a network.

NVD description · AI analysis pending
8.82% PoC ×2
  • microsoft windows 10 1607
  • microsoft windows 10 1809
  • microsoft windows server 2012
  • +1 more
CVE-2026-57239
The user-controllable executable files will be directly executed by high-privilege processes, allowing low-privilege users to have the opportunity to elevate th

The user-controllable executable files will be directly executed by high-privilege processes, allowing low-privilege users to have the opportunity to elevate their privileges to NT AUTHORITY\SYSTEM.

NVD description · AI analysis pending
7.8<1%
  • foxit pdf editor
  • foxit pdf reader
CVE-2026-57308
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Syncope.

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Syncope. An administrator with adequate entitlements can achieve execution of arbitrary SQL via stacked queries, leveraging unsanitized sort parameters. This issue affects Apache Syncope: from 3.0.0-M0 through 3.0.16, from 4.0.0-M0 Through 4.0.6, from 4.1.0-M0 through 4.1.1. Users are recommended to upgrade to version 4.0.7 / 4.1.2, which fix this issue.

NVD description · AI analysis pending
9.8<1%
  • apache syncope
CVE-2026-60217
Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component:

Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via TCP to compromise Oracle Coherence. While the vulnerability is in Oracle Coherence, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Coherence. CVSS 3.1 Base Score 10.0 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H).

NVD description · AI analysis pending
10.0<1%
  • oracle coherence
CVE-2026-60358
Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component:

Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Authentication Engine). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Access Manager. While the vulnerability is in Oracle Access Manager, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Access Manager. CVSS 3.1 Base Score 10.0 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H).

NVD description · AI analysis pending
10.0<1%
  • oracle access manager
CVE-2026-60360
Vulnerability in the Oracle Unified Directory product of Oracle Fusion Middleware (component:

Vulnerability in the Oracle Unified Directory product of Oracle Fusion Middleware (component: OUD Core). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via LDAP to compromise Oracle Unified Directory. While the vulnerability is in Oracle Unified Directory, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Unified Directory. CVSS 3.1 Base Score 10.0 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H).

NVD description · AI analysis pending
10.0<1%
  • oracle unified directory
CVE-2026-60365
Vulnerability in the Oracle Weblogic Server Proxy Plug-in product of Oracle Fusion Middleware (component:

Vulnerability in the Oracle Weblogic Server Proxy Plug-in product of Oracle Fusion Middleware (component: WebLogic Server Proxy Plug-In for Third-Party Web Servers). The supported version that is affected is 15.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Weblogic Server Proxy Plug-in. While the vulnerability is in Oracle Weblogic Server Proxy Plug-in, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Weblogic Server Proxy Plug-in accessible data as well as unauthorized access to critical data or complete access to all Oracle Weblogic Server Proxy Plug-in accessible data. CVSS 3.1 Base Score 10.0 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N).

NVD description · AI analysis pending
10.0<1%
  • oracle http server
  • oracle weblogic server proxy plug-in
CVE-2026-60366
Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component:

Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Platform Security for Java. While the vulnerability is in Oracle Platform Security for Java, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Platform Security for Java. CVSS 3.1 Base Score 10.0 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H).

NVD description · AI analysis pending
10.0<1%
  • oracle platform security for java
CVE-2026-60379
+1 in the same advisory: …60389
Vulnerability in the Service Delivery Platform product of Oracle Fusion Middleware (component:

Vulnerability in the Service Delivery Platform product of Oracle Fusion Middleware (component: Messaging Enabler). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via SOAP to compromise Service Delivery Platform. While the vulnerability is in Service Delivery Platform, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Service Delivery Platform. CVSS 3.1 Base Score 10.0 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H).

NVD description · AI analysis pending
10.0<1%
  • oracle service delivery platform
CVE-2026-60402
Vulnerability in the TimesTen In-Memory Database product of Oracle TimesTen In-Memory Database (component:

Vulnerability in the TimesTen In-Memory Database product of Oracle TimesTen In-Memory Database (component: Kubernetes Operator). The supported version that is affected is 26.1.1.1.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTPS to compromise TimesTen In-Memory Database. While the vulnerability is in TimesTen In-Memory Database, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of TimesTen In-Memory Database. CVSS 3.1 Base Score 9.9 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H).

NVD description · AI analysis pending
9.9<1%
  • oracle timesten in-memory database
CVE-2026-60644
Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component:

Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Web Content Management). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Content. While the vulnerability is in Oracle WebCenter Content, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle WebCenter Content. CVSS 3.1 Base Score 10.0 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H).

NVD description · AI analysis pending
10.0<1%
  • oracle webcenter content
CVE-2026-61146
Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component:

Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Content Acquisition System). The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Commerce Guided Search / Oracle Commerce Experience Manager. While the vulnerability is in Oracle Commerce Guided Search / Oracle Commerce Experience Manager, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Commerce Guided Search / Oracle Commerce Experience Manager. CVSS 3.1 Base Score 9.9 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H).

NVD description · AI analysis pending
9.9<1%
  • oracle commerce experience manager
  • oracle commerce guided search
CVE-2026-61211
Vulnerability in the RDBMS component of Oracle Database Server.

Vulnerability in the RDBMS component of Oracle Database Server. Supported versions that are affected are 19.3-19.31 and 23.4.0-23.26.2. Easily exploitable vulnerability allows low privileged attacker having Execute DBMS_CLOUD privilege with network access via Oracle Net to compromise RDBMS. While the vulnerability is in RDBMS, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of RDBMS. CVSS 3.1 Base Score 9.9 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H).

NVD description · AI analysis pending
9.9<1%
  • oracle database server
CVE-2026-62144
Authentication Bypass in Check Point Security and Multi-Domain Security Management

CVE-2026-62144 is an authentication bypass (CWE-287) in Check Point Security Management and Multi-Domain Security Management that lets an unauthenticated remote attacker execute administrative commands on the Management Server. It is triggered when an attacker can reach the Management Server over the network without firewall protection, or when the management configuration does not restrict Trusted Clients. Successful exploitation gives the attacker full administrative command execution on the management server and may also allow command execution on the managed Security Gateways behind it. Any organization running these Check Point management products where the management interface is reachable without Trusted Clients restriction is affected. As of now there is no public proof-of-concept, it is not in CISA KEV, and no confirmed in-the-wild exploitation is known, although its EPSS of 20.8% (97th percentile) indicates an elevated likelihood of exploitation within 30 days.

Do: Upgrade Security Management and Multi-Domain Security Management to the patched release per Check Point's official advisory. As interim mitigation, restrict Trusted Clients on the management server and firewall network access to management interfaces, and audit existing configurations for missing Trusted Clients restrictions. Separately, ensure the actively exploited SmartConsole authentication bypass (CVE-2026-16232) is also patched, since it affects the same management ecosystem.

9.121%
  • Check Point Security Management
  • Check Point Multi-Domain Security Management
largetens of thousands of management server deployments, of which only the subset with management interfaces reachable without Trusted Clients restriction are…
CVE-2026-62145
A vulnerability in Check Point Gaia Portal allows an authenticated attacker with read-only Gaia Portal privileges to execute commands with root privileges.

A vulnerability in Check Point Gaia Portal allows an authenticated attacker with read-only Gaia Portal privileges to execute commands with root privileges.

NVD description · AI analysis pending
7.58%
CVE-2026-64600
In the Linux kernel, the following vulnerability has been resolved:

In the Linux kernel, the following vulnerability has been resolved: xfs: resample the data fork mapping after cycling ILOCK xfs_reflink_fill_{cow_hole,delalloc} are both presented with an inode, a data fork mapping, and a cow fork mapping. Unfortunately, these two helpers cycle the ILOCK to grab a transaction, which means that the mappings are stale as soon as we reacquire the ILOCK. Currently we refresh the cow fork mapping by re-calling xfs_find_trim_cow_extent, but we don't refresh the data fork mapping beforehand, which means that the xfs_bmap_trim_cow in that function queries the refcount btree about the wrong physical blocks and returns an inaccurate value in *shared. If *shared is now false, the directio write proceeds with a stale data fork mapping. Fix this by querying the data fork mapping if the sequence counter changes across the ILOCK cycle.

NVD description · AI analysis pending
7.8<1% PoC ×2
  • linux linux kernel
CVE-2026-64813
+1 in the same advisory: …64812
In JetBrains IntelliJ IDEA before 2026.2 unauthorized settings modification was possible in a Remote Development session

In JetBrains IntelliJ IDEA before 2026.2 unauthorized settings modification was possible in a Remote Development session

NVD description · AI analysis pending
10.0<1%
  • jetbrains intellij idea
CVE-2026-65906
In JetBrains TeamCity before 2026.1.2, 2025.11.6 сode execution via Kotlin DSL sandbox escape was possible

In JetBrains TeamCity before 2026.1.2, 2025.11.6 сode execution via Kotlin DSL sandbox escape was possible

NVD description · AI analysis pending
10.0<1%
  • jetbrains teamcity
CVE-2026-8085
+3 in the same advisory: …8312 …8313 …8314
A security issue exists within Arena® Simulation due to a memory corruption vulnerability in the model.exe (Siman) component.

A security issue exists within Arena® Simulation due to a memory corruption vulnerability in the model.exe (Siman) component. The vulnerability stems from improper validation of user-supplied data, which can result in an out-of-bounds write. An attacker could leverage this vulnerability to execute arbitrary code in the context of the current process by convincing a user to open a malicious file.

NVD description · AI analysis pending
7.0<1%
  • rockwellautomation arena
CVE-2026-8933
A local privilege escalation vulnerability exists in snap-confine, a set-capabilities core component used internally by Canonical snapd to construct the secure

A local privilege escalation vulnerability exists in snap-confine, a set-capabilities core component used internally by Canonical snapd to construct the secure execution environment for snap applications. This vulnerability uniquely affects versions of snap-confine configured with set-capabilities (rather than standard set-uid-root installations). Due to a flaw in how privilege boundaries or security sandboxes are initialized when the binary runs under limited ambient capabilities, a local, unprivileged attacker can exploit this behavior to bypass intended restrictions and execute arbitrary code. Successful exploitation allows the local user to elevate their privileges to full root authority.

NVD description · AI analysis pending
7.8<1%

Indicators of compromiseAll →

TypeIndicatorContext
domainhunt.iol prompts for commands that could be considered dangerous," Hunt.io said. "Purpose-built scripts target MOF Hadoop infrastructu
Full article2,480 words · extracted from thehackernews.com · click to collapse

Ravie LakshmananJul 27, 2026Cybersecurity / Hacking

Monday starts with the usual promise that everything is under control. Then the logs wake up.

This week, trusted tools crossed lines, old flaws found new work, exposed systems stayed exposed, and attackers kept hiding inside normal-looking services. Nothing looked strange at first. That helped.

That is the mood. Here is the full recap.

⚡ Threat of the Week

OpenAI Says Its AI Agent Went Rogue and Targeted Hugging Face - OpenAI disclosed that it lost control of two AI models during a security evaluation that ended in a breach of Hugging Face. The AI company said its AI models broke out of a sealed testing environment and broke into Hugging Face's production system to find solutions for the ExploitGym benchmark. "The incident also makes clear that advanced models can discover and exploit novel attack paths in real-world systems without source-code access," OpenAI said. "It highlights that advanced cyber capabilities must be developed alongside stronger safeguards and defensive tools." The development is the latest sign that capable AI models can pose serious cybersecurity risks even when they're being tested for defensive or research purposes. The incident also demonstrates that frontier models are becoming more capable of carrying out complex, multistep cyber operations, particularly when guardrails designed to restrict that activity are removed. OpenAI did not say what data was accessed.

🔔 Top News

  • Check Point Patches Exploited SmartConsole Flaw - Check Point has released security updates to address multiple vulnerabilities impacting Security Management and Multi-Domain Management (MDSM) products, including a critical flaw that has come under active exploitation in the wild. The security flaw, tracked as CVE-2026-16232 (CVSS score: 9.3), is an authentication bypass affecting the Check Point SmartConsole login process that allows an unauthenticated remote attacker to obtain an application login token and use it to authenticate with full administrative privileges. Lotem Finkelstein, vice president of research at Check Point, said the company is aware of a handful of customers being targeted by this flaw, and that it has already notified them. It did not disclose the nature of the attacks or when they were discovered.
  • China-Nexus Operation Uses TriBack Loader - A threat actor with ties to China has been observed using DLL side-loading techniques to deliver TriBack Loader, which is used to deliver AdaptixC2 and Beagle. Targets of the campaign include a Vietnamese public hospital's medical imaging system, the Malaysian Ministry of Foreign Affairs, and multiple Hong Kong educational institutions. The activity has been codenamed JadeProx by Group-IB. The threat actor exploits internet-facing systems in Southeast Asia to drop web shells for persistent access. Against end-user targets in Latin America, spear-phishing ZIP archives or MSI installers are used to deliver TriBack Loader. "JadeProx operates by conducting phishing campaigns delivering Windows loaders for initial access, tunnelling tools maintaining persistence across compromised networks, and custom Go-based relay infrastructure keeping the operator's traffic hidden behind Alibaba and Cloudflare," Group-IB said.
  • Hacker Runs Hermes AI Agent to Target Thai Finance Ministry - An unknown threat actor leveraged Hermes, an autonomous AI agent using "YOLO" mode, to target Thailand's Ministry of Finance (MOF), an analysis of three simultaneous open directories hosted on AS132883 (TOPIDC) has revealed. "Hermes output logs show the operator ran the agent in unattended or YOLO mode, bypassing approval prompts for commands that could be considered dangerous," Hunt.io said. "Purpose-built scripts target MOF Hadoop infrastructure with a HiveServer2 client using hardcoded credentials and a malicious Hive UDF issuing commands and returning output over WebHDFS."
  • Russian Espionage Group Exploited Zimbra Zero-Day to Steal Mail and 2FA Codes - A Russian state-supported espionage group codenamed Laundry Bear exploited a then-zero-day in Zimbra (CVE-2025-66376) to access Western mailboxes. The issue was fixed by Zimbra in November 2025, but not before it was weaponized in attacks targeting government and commercial organizations since July 2025. The attacks are designed to deliver a JavaScript payload called ZimReaper that captures the victim's credentials and 2FA codes and sends them to actor-controlled infrastructure. The flaw affects Zimbra Collaboration Suite version 10.0 before 10.0.18 and 10.1 before 10.1.13.
  • Certighost Exploit Allows Privilege Escalation - A proof-of-concept (PoC) exploit has been released for CVE-2026-54121 (aka Certighost), a critical privilege elevation vulnerability in Active Directory Certificate Services (AD CS) that lets any authenticated domain user perform privileged Active Directory operations. Microsoft patched the flaw earlier this month. "The exploit lets any low-privileged, authenticated domain user with no requirement for admin rights or user interaction required to obtain a valid certificate impersonating a Domain Controller and use it to run DCSync and extract the krbtgt secret, a precursor to Golden Ticket-level domain compromise," Dataminr said.

‎️🔥 Trending CVEs

Bugs drop weekly, and the gap between a patch and an exploit is shrinking fast. These are the heavy hitters for the week: high-severity, widely used, or already being poked at in the wild.

Check the list, patch what you have, and hit the ones marked urgent first - CVE-2026-16723 (Alibaba Fastjson), CVE-2026-32194 CVE-2026-32191 (Microsoft Bing), CVE-2026-10591 (AWS Kiro), CVE-2026-48294 (Adobe Acrobat Chrome extension), CVE-2026-8933 (snap-confine), CVE-2026-16232, CVE-2026-62144, CVE-2026-62145 (Check Point), CVE-2026-64600 (Linux kernel), CVE-2026-15226 (Ubuntu), CVE-2026-15899, CVE-2026-15900, CVE-2026-15901 (Google Chrome), CVE-2026-15342 (Plane), CVE-2026-16411, CVE-2026-16412, CVE-2026-16360 (Mozilla Firefox), CVE-2026-16157 (Duplicati), CVE-2026-14985 (Analog Way Picturall Quad Compact Mark II), CVE-2026-47056, CVE-2026-60217, CVE-2026-60358, CVE-2026-60360, CVE-2026-60365, CVE-2026-60366, CVE-2026-60379, CVE-2026-60389, CVE-2026-60644, CVE-2026-61211, CVE-2026-60402, CVE-2026-61146 (Oracle), from CVE-2026-15611 to CVE-2026-15617 (Logto), CVE-2026-57239 (Foxit PDF Reader), CVE-2026-57308, CVE-2026-23795, CVE-2026-23794 (Apache Syncope), CVE-2026-65906, CVE-2026-64812, CVE-2026-64813 (JetBrains), CVE-2026-8085, CVE-2026-8312, CVE-2026-8313, CVE-2026-8314 (Rockwell Automation), CVE-2026-12927 (Schneider Electric), CVE-2026-42958, CVE-2026-42953, CVE-2026-49033 (Labcenter Proteus PDSPRJ), CVE-2025-40947, CVE-2025-40948, CVE-2025-40949 (Siemens ROX II OT switches), CVE-2026-54052 (n8n), and multiple vulnerabilities in NodeBB, Redis, and Zimbra (no CVEs).

🎥 Cybersecurity Webinars

  • AI Ships Code Faster Than Security Can Review ItAI-assisted development is producing more code than traditional review and CVE-based remediation can keep up with. This webinar gives security leaders a practical framework for controlling the growing attack surface, enforcing secure-by-default development, and scaling delivery without losing control of software risk.
  • AI Attacks Move in Minutes. Can Your Security Team Keep Up? → AI can now find vulnerabilities, build exploits, and chain attacks faster than traditional security operations can respond. This webinar presents a practical framework for expanding attack-surface visibility, speeding up investigations, and building security operations that can contain machine-speed threats.

📰 Around the Cyber World

  • Meta Announces Facebook Verified - Meta announced Facebook Verified, a free badge designed to confirm that a Facebook profile belongs to a real person rather than an AI-generated fake. "Facebook Verified uses a simple selfie-based process," Meta explained. "You record a short video selfie, which we check against your existing profile photos to confirm a match. The process is free and typically takes just a few minutes. Accounts must meet our trust and safety standards to qualify for verification."
  • New Kali365 Ringer Phishing Attack Uses Google Sites Voicemail Wrapper - ZeroBEC said it detected a Kali365 device-code phishing attack targeting an unnamed financial, regulated customer. "The lure used a missed-call notification and a trusted Google Sites wrapper before redirecting through Google redirector, OCI API Gateway, and a Cloudflare-protected Kali365 host," ZeroBEC said. "The campaign targeted multiple organizations on the same day, including financial and insurance services customers, using the same Google Sites landing page, sender subdomain, subject pattern, and fake internal reference ID. The user was instructed to authorize an attacker-controlled device-code session through Microsoft rather than submit a password to a fake login page." The voicemail-themed attack has been codenamed Kali365 Ringer.
  • 53 Slopsquatting Targets Across 5 Frontier LLMs - A new piece of research has found frontier models, including across Claude Sonnet 4.6, Claude Haiku 4.5, GPT-5.4-mini, Gemini 2.5 Pro, and DeepSeek V3.2, are hallucinating non-existing package names, posing software supply chain risks. Of the 127 names initially identified, 53 of them, 41 on PyPI and 12 on npm, were still available for registration as of April 2026. "An attacker could publish malware under one of these names and wait for an AI coding tool to recommend it to a developer," Socket said. This technique, known as slopsquatting, exploits package names that AI models repeatedly invent. Because every model in the study generated the same names, one malicious registration could potentially target users across several model providers."
  • How SVGs Carry Malicious Scripts - A new analysis from ReversingLabs has detailed how the abuse of SVG files in cyber attacks can complicate detection. "Threat actors use this functionality to craft SVG files that can act maliciously," ReversingLabs said. "Malicious SVGs can take the form of fake login pages, data exfiltrators, or malicious downloaders, amongst other things. SVGs are frequently overlooked, as they are assumed to be benign images, leaving a gap in security architecture. SVGs are difficult to detect, can easily be snuck into emails or webpages, and are able to perform malicious and legitimate actions simultaneously. Many security solutions do not account for malicious SVGs, seeing them only as images."
  • From ClickFix to ClaudeFix - A new campaign has been observed using shareable Claude chats to host ClickFix instructions, leading to the deployment of malware. "As AI platforms have grown in popularity, threat actors have increasingly abused legitimate features such as shareable chats to lend credibility to malicious content," Zscaler said. "Malvertising was a key part of this campaign. Attackers used paid ads to lure Mac users searching for Claude into shared Claude chats that instructed them to run ClickFix commands leading to the download of MacSync Stealer."
  • Microsoft Bolsters Windows Enterprise Activation Security - Microsoft is making Trusted Platform Module (TPM)-backed attestation a requirement for Windows Key Management Service (KMS) to activate Windows devices at scale. "As attackers have exploited fake or cloned KMS servers, organizations face increased compliance and licensing risk," the tech giant said. "Microsoft is now further strengthening defenses with KMS Hardware-Secured, which uses Trusted Platform Module (TPM)-based attestation to help verify that a KMS host is running on trusted hardware before it can activate Windows devices. Starting with upcoming Windows Server releases, KMS hosts must prove they are running on verified, uncompromised hardware before activating clients. This is achieved through TPM - a hardware root of trust that provides cryptographic proof of integrity."
  • Abusing Trusted Business Workflows to Deliver Phantom Stealer - A new phishing campaign is disguising itself as routine business communications to lend it a veneer of trust and deliver Phantom Stealer. The phishing lures distribute malicious JavaScript files packaged within compressed archive attachments. "Although the emails impersonate different trusted entities, including a global logistics provider and a government tax authority, they ultimately lead to an identical multi-stage infection chain," Seqrite Labs said. "Once executed, the JavaScript downloader launches an obfuscated PowerShell script that performs the entire malicious workflow in memory, significantly reducing its on-disk footprint and making detection more challenging. The infection chain ultimately deploys Phantom Stealer v3.5.0, which harvests sensitive information from the compromised system and exfiltrates the collected data via SMTP using encoded content."
  • What's in the INC Ransomware Panel? - An analysis of the INC Ransomware's negotiation panel has found it to be developed using React 18, with react-timer-hook utilized for countdown timers, react-viewer for image gallery, React-Toastify for notifications, and Socket.io for real-time chat. The panel has been active since 2024. The panel also supports file upload for test decryption, ransom tracking, and leak management.
  • Origin Energy Confirms Data Breach - Australian energy giant Origin Energy Limited confirmed there was an "unauthorized access and disclosure of some customers' data," and that it's "working to understand the total number of impacted customers." Impacted information may include name, address, date of birth, contact phone number, and account information, as well as the last four digits of a credit card, or the last three digits of a bank account. An investigation was launched on July 22, 2026.
  • NULLZEREPTOOL, a Telegram-Controlled DDoS and Multi-Function Attack Framework - Flare.io disclosed details of a Telegram-controlled attack framework called NULLZEREPTOOL that supports a DDoS engine and a "growing list of wireless attack, credential-theft, and botnet features that exist only in code, never observed in use." Two versions have been observed: an earlier variant with a focused DDoS and proxy management feature set, and a later variant that retains all previous functionality while adding WiFi/Bluetooth attack modules, credential extraction, and a hierarchical botnet tasking structure. The disclosure comes as the cybersecurity company also highlighted Mycelium, a botnet framework which has been advertised as an AI-as-a-Service platform. "Rather than describing a simple malware implant, the framework advertises a modular enterprise-grade architecture: production-grade C++ platform built around modular plugins supporting exploitation, persistence, browser forensics, distributed computing, reconnaissance, AI services, and autonomous operations," security researcher Assaf Morag said.
  • North Korea's ClickFake Interview Campaign - North Korean threat actors with ties to the Contagious Interview campaign are leveraging ClickFix-like lures to target cryptocurrency and Web3 professionals with fake job interviews to deliver PylangGhost RAT on Windows and the GolangGhost RAT on macOS as part of a bogus skill assessment. "For ClickFake Interview, the actors are creating fraudulent companies or impersonating known ones in the crypto industry, and reach out to targets on social media (e.g., LinkedIn), inviting them to ClickFix-empowered fake skill assessments," SOCRadar said. "Their ClickFix panels incorporate gating, tailored questions based on advertised roles, psychological pressure to act fast, video recording, and social engineering that pushes targets to run malicious commands through fake camera errors."

🔧 Cybersecurity Tools

  • Beetle → It is an open-source, offline-first platform for analysing Android and iOS apps, including Flutter and React Native builds. It combines static analysis, evidence-backed findings, attack-chain correlation, source navigation, OWASP MASVS mapping, and reporting in one local workspace, with optional AI assistance for investigating results.
  • ndrstnd → It turns a coding agent's branch changes into a clear, evidence-linked story. Instead of reading thousands of lines file by file, you can see what changed, why it matters, where the risk is, and which exact diff hunks support each claim. It runs locally and works with Codex and Claude Code.

Disclaimer: This is strictly for research and learning. It hasn't been through a formal security audit, so don't just blindly drop it into production. Read the code, break it in a sandbox first, and make sure whatever you're doing stays on the right side of the law.

Conclusion

The lesson this week is simple: attackers do not need everything to fail. One trusted tool, one old bug, one exposed service, or one careless setting can be enough.

The best defence is still the boring work. Patch early. Remove access nobody needs. Watch the tools that act on your behalf. Treat anything public as something people will eventually test.

That is the week's warning. Small gaps rarely stay small for long.

Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.

Text extracted automatically; images, tables and formatting may be missing. Original: https://thehackernews.com/2026/07/weekly-recap-rogue-ai-agents-check.html