ZeroHour

Search: “vulnerability-database”

28 stories

Smart search ranks by meaning as well as keywords (one row per story, last 45 days).

Artifactory flaws chained in attacks deploying backdoor malware

Attackers chain JFrog Artifactory flaws CVE-2026-42018 and CVE-2026-42016 to gain admin tokens and deploy a Rust backdoor on self-hosted servers.

Wiz observed multiple threat actors chaining CVE-2026-42018 and CVE-2026-42016 against self-hosted JFrog Artifactory instances between August 15 and September 8, 2026, in some cases obtaining admin access in under five minutes. The critical authentication bypass CVE-2026-82329 was also exploited this month to mint administrator tokens. Attackers installed malicious Groovy plugins, dropped a Rust backdoor with C2 capabilities, uploaded webshells, stole configuration data and cluster join keys, and added SSH keys to new accounts. Wiz estimates 49-62% of internet-reachable Artifactory instances are vulnerable to at least one of the three flaws, and patched releases from 7.111.21 through 7.161.20 are available.

BleepingComputerupdated · 2d agofirst · 5d agoExploit / PoC in the wild 7 sourcesCVE-2026-42018CVE-2026-42016CVE-2026-823291

NIST wants to overhaul its vulnerability database for the AI age

NIST issued a Federal Register RFI seeking public input on overhauling the National Vulnerability Database for AI-scale, machine-consumable security data.

NIST published a request for information arguing the National Vulnerability Database must adapt as LLMs increasingly find and exploit vulnerabilities at machine scale. The RFI seeks input on integrating automation into vulnerability reporting, faster dissemination to defenders, and transparency and auditability in AI-driven decisions. It follows the White House-backed Gold Eagle clearinghouse at Treasury and the VINCE program with Carnegie Mellon's Software Engineering Institute for AI-discovered vulnerability reports.

CyberScoop · Aug 11, 2026Policy & legal

Towards Scalable and Cost-Efficient Vulnerability Detection: A Study on Automatic Query Generation

A study finds LLM-synthesized CodeQL queries improve average F1-score by 82% over baseline queries, offering scalable vulnerability detection versus direct LLM scanning.

Researchers conducted an empirical study evaluating whether LLMs can synthesize executable CodeQL queries from National Vulnerability Database vulnerability data. LLM-generated queries significantly enhanced baseline CodeQL suites, yielding an 82% improvement in average F1-score across a diverse set of real-world vulnerabilities. A cost-benefit analysis shows direct LLM-based scanning of entire repositories is often computationally and financially prohibitive, while LLM query synthesis offers a scalable and cost-effective alternative for large-scale vulnerability detection.

arXiv cs.CR · 7d agoResearch1

[hardware] Fullhan FH8626V100 - Multiple Vulnerabilities

Multiple vulnerabilities in the Fullhan FH8626V100 hardware chip have been disclosed alongside public proof-of-concept exploits.

Exploit-DB lists an entry covering multiple vulnerabilities in the Fullhan FH8626V100, a hardware component. The listing provides no CVE ids, vulnerability classes, or evidence of in-the-wild exploitation. Impact is likely limited to devices embedding the affected chip.

Exploit-DB · 15d agoExploit / PoC

USN-8765-1: python-sql vulnerability

Ubuntu patches python-sql SQL injection flaw where values passed to unary operators are incorrectly escaped.

Ubuntu Security Notice USN-8765-1 fixes a vulnerability in python-sql discovered by Cedric Krier. The library incorrectly escaped values passed to unary operators, allowing an attacker to potentially perform SQL injection attacks against applications using the library.

Ubuntu Security Notices · 1d agoAdvisory

Inside the Metabase SQLi: Exploited in the Wild

Wiz reverse engineers Metabase SQLi CVE-2026-72898, exploited in the wild, using AI to speed defenses.

Wiz published an analysis of Metabase CVE-2026-72898, a SQL injection vulnerability that is being exploited in the wild. The write-up reverse engineers the flaw and applies AI to accelerate defensive guidance for responders. Organizations running Metabase should treat the flaw as actively targeted.

Wiz Blog · Aug 10, 2026Exploit / PoC in the wildCVE-2026-72898

CISA Warns of Microsoft SQL Server RCE Vulnerability Exploited in Attacks

CISA warns attackers are exploiting CVE-2019-1068, a remote code execution vulnerability in Microsoft SQL Server, to run malicious commands on database servers.

CISA warned that CVE-2019-1068, a remote code execution vulnerability in Microsoft SQL Server, is being exploited in active attacks. Successful exploitation allows an attacker to execute malicious commands on a vulnerable database server, with access limited to the privileges of the SQL Server service account. The warning signals active exploitation of a long-known flaw and makes patching a priority for organizations running affected SQL Server deployments.

CISA Adds Three Known Exploited Vulnerabilities to Catalog

CISA added three actively exploited vulnerabilities — two JFrog Artifactory and one ConnectWise ScreenConnect — to its KEV Catalog.

CISA added CVE-2026-42016 (JFrog Artifactory incorrect authorization), CVE-2026-42018 (JFrog Artifactory improper authentication), and CVE-2026-84869 (ConnectWise ScreenConnect improper privilege management and missing authorization) to the Known Exploited Vulnerabilities Catalog based on evidence of active exploitation. BOD 26-04 requires Federal Civilian Executive Branch agencies to prioritize rapid remediation of such high-risk vulnerabilities on publicly exposed assets and to check for prior compromise. CISA urges all organizations to adopt risk-based vulnerability management and prioritize KEV remediation.

Critical Langflow Vulnerability Exploited as Attacks on AI Platform Rise

Attacks exploiting CVE-2026-0768, a critical vulnerability in the Langflow low-code AI platform, are rising amid growing adversary attention this year.

CVE-2026-0768 is a critical vulnerability in Langflow, a low-code AI development platform, with exploitation attacks now rising. Dark Reading notes the platform has drawn increasing adversary attention in 2026. Organizations running exposed Langflow instances face elevated risk and should patch promptly and review instances for compromise.

Dark Reading · 15d agoExploit / PoC in the wildCVE-2026-07681

SEMA-GUARD: Semantic and Graph-Based Vulnerability Detection in Assembly Code

SEMA-GUARD uses semantic analysis and graph neural networks to detect vulnerabilities in assembly code, achieving 85.1% accuracy on a Juliet-derived benchmark.

SEMA-GUARD is a framework that detects vulnerabilities in compiled programs when source code is unavailable, targeting malware, firmware, and embedded systems analysis. It enriches control flow graphs with low-level execution semantics including stack manipulations, memory accesses, and data flow. Evaluated on a Juliet Test Suite set compiled to assembly and split into function-level chunks, it achieves 85.1% accuracy and an F1 score of 0.801, outperforming purely statistical or structural approaches.

arXiv cs.CR · 1d agoResearch1

[webapps] EasyAppointments 1.5.1 - Blind SQL Injection

A proof-of-concept exploit for a blind SQL injection vulnerability in EasyAppointments 1.5.1 has been published on Exploit-DB.

Exploit-DB lists a public proof-of-concept exploit for a blind SQL injection flaw in EasyAppointments 1.5.1. The listing falls under the webapps category and enables reproduction of the injection. No in-the-wild exploitation or CVE identifier is stated in the listing.

Exploit-DB · 16d agoExploit / PoC1

[webapps] Payload CMS 3.72.0 - Blind SQL Injection

A proof-of-concept exploit for a blind SQL injection vulnerability in Payload CMS 3.72.0 has been published on Exploit-DB.

Exploit-DB lists a public proof-of-concept exploit for a blind SQL injection flaw in Payload CMS 3.72.0. The listing falls under the webapps category and allows reproduction of the injection. No in-the-wild exploitation or CVE identifier is stated in the listing.

Exploit-DB · 16d agoExploit / PoC1

Cisco Unified Intelligence Center SQL Injection Vulnerability

Cisco patched a blind SQL injection in Unified Intelligence Center's web interface allowing authenticated local attackers to read the internal database.

Cisco disclosed a blind SQL injection vulnerability in the web-based management interface of Unified Intelligence Center, caused by insufficient validation of user-supplied input. An authenticated local attacker can send crafted requests and read the contents of the device's internal database. Exploitation requires valid user credentials, and Cisco has released software updates.

Cisco Security Advisories · 28d agoAdvisory

Can your coding style predict whether your code is vulnerable?

University of Massachusetts Dartmouth researchers present VulStyle, a stylometry-based vulnerability detector that also exposes benchmark reliability problems.

VulStyle combines stylometric features with syntax-tree structure and source tokens, pre-trained on about 4.9 million functions across seven programming languages and fine-tuned on five vulnerability detection datasets. It beat token-only detectors on some benchmarks but its F1 drops sharply on DiverseVul, which the authors link to noisy labels inflating reported performance across popular datasets. The authors argue style-aware detection should be harder to evade but did not test this empirically, and they note that uniform LLM-generated code may strip away the individual developer style the model depends on.

Help Net Security · 23d agoResearch1

CISA Adds One Known Exploited Vulnerability to Catalog

CISA added CVE-2026-76461, an actively exploited SQL injection in Cisco Secure Email Gateway, to the KEV catalog.

CISA added CVE-2026-76461, a SQL injection vulnerability in Cisco Secure Email Gateway, to its Known Exploited Vulnerabilities (KEV) Catalog based on evidence of active exploitation. BOD 26-04 requires Federal Civilian Executive Branch agencies to prioritize rapid remediation of KEV vulnerabilities on publicly exposed assets and to check whether systems were compromised before patching. CISA encourages all organizations to adopt risk-based vulnerability management and prioritize KEV remediation.

CISA Advisoriesupdated · 13h agofirst · 2d agoExploit / PoC in the wild 17 sourcesCVE-2026-76461

Exploits and vulnerabilities in Q2 2026

Kaspersky's Q2 2026 report tallies vulnerability, exploit, and C2 framework statistics, adding first-ever data on open-source AI framework flaws.

Kaspersky Securelist released its quarterly report on vulnerabilities, exploits, and C2 frameworks for Q2 2026. The report aggregates statistics on vulnerability disclosures and exploit activity for the quarter. For the first time, it also aggregates data on vulnerabilities in open-source AI agents and AI frameworks, extending coverage into the AI software supply chain.

Kaspersky Securelist · 21d agoResearch

Building a risk-based vulnerability management program that scales

Asimily CEO Shankar Somasundaram outlines a risk-based vulnerability management approach using inventory, attack paths, KEV and EPSS data.

In a Help Net Security video, Asimily CEO Shankar Somasundaram argues patching everything is infeasible as AI-driven attacks inflate vulnerability counts, with one customer finding a thousand unknowns for each known one. He recommends building a full inventory of devices, applications, and data flows, mapping attack paths for reachability, and prioritizing with KEV, EPSS, and business impact. Mitigations include patching, virtual patching via NACs and firewalls, segmentation, and configuration snapshots to detect drift.

Help Net Security · 23d agoIndustry

Exploitation of Sangoma Switchvox flaw is underway (CVE-2026-9586)

Attackers actively exploit SQL injection flaw CVE-2026-9586 in unauthenticated Sangoma Switchvox endpoints, dropping reverse shells and second-stage cryptominer malware.

CVE-2026-9586, an unauthenticated SQL injection in Sangoma Switchvox SMB Edition 8.3, lets crafted HTTP POST requests execute arbitrary SQL against the backend PostgreSQL database. Horizon3 honeypots first saw exploitation on August 30, 2026 from IP 176.65.148.184, and dozens of additional source IPs have since joined with scanning payloads and second-stage malware that appears to be a cryptominer. The flaw was patched in Switchvox 8.4.0.2 on July 14, 2026; roughly 4,000 exposed instances exist, mostly in the United States, and exploitation is likely against most of them.

Help Net Security · 15d agoExploit / PoC in the wildCVE-2026-9586

Ubiquiti security advisory (AV26-850)

Canada's Cyber Centre reports critical vulnerabilities across Ubiquiti UniFi products including UniFi OS Server, Network, Protect, and Access; updates required.

The Canadian Centre for Cyber Security (AV26-850) reports critical vulnerabilities affecting numerous Ubiquiti products, including UniFi OS Server (<=5.1.21), UniFi Network Application (<=10.4.57), UniFi Protect Application (<=7.1.87), and UniFi Access Application (<=4.3.3). Other affected products include UniFi Connect, UID Enterprise Agent, UniFi Talk, UniFi Protect AI Key, Connect Display Cast Pro, and Enterprise Audio/Video Bridge. Administrators should update affected applications and devices; the advisory lists no CVE ids or exploitation details.

Canadian Centre for Cyber Security · 21d agoAdvisory

An Empirical Analysis of CodeQL False Positives and Query Refinements for Java Vulnerabilities

Study of 167 Java CVE instances finds CodeQL false positives follow recurring patterns; query refinements remove 81.8% of reviewed ones.

Researchers ran CodeQL's Java security query suite on 167 CVE instances from 110 projects, manually reviewing 500 sampled false-positive paths and building a five-category taxonomy led by Missed Path Constraint or Sanitization (36.6%), Benign Execution Context (29.4%), and Missing Trust Boundary Modeling (27.6%). Guided by the taxonomy, query-level refinements removed 81.8% of reviewed false positives and 15.8% of reported paths across the selected queries while retaining 7 of 8 true positives. To address generalization, agentic coding tools given the refinement patterns as templates adapted them to new projects successfully in 56% and 62% of tasks, versus 28% without guidance.

arXiv cs.CR · 13d agoResearch1

USN-8679-2: Vim vulnerability

Ubuntu's USN-8679-2 updates Vim for Ubuntu 26.04 LTS, fixing a tags-file handling flaw that could allow arbitrary code execution.

Ubuntu Security Notice USN-8679-2 extends the Vim fix from USN-8679-1 to Ubuntu 26.04 LTS. The vulnerability stems from incorrect handling of certain tags files, which an attacker could exploit to execute arbitrary code. This is a routine distribution security update with no exploitation reported.

Ubuntu Security Notices · 8d agoAdvisory 2 sources

CISA Added JFrog Artifactory Vulnerability to its Known Exploited Vulnerabilities Catalog (CVE-2026-82329)

CISA added the actively exploited JFrog Artifactory flaw CVE-2026-82329 (CVSS 9.8) to its KEV catalog; unauthenticated attackers gain admin access.

CISA added CVE-2026-82329, a critical improper authentication flaw in JFrog Artifactory, to its Known Exploited Vulnerabilities Catalog with a September 5, 2026 patch deadline. The CVSS v3.1 9.8 flaw allows unauthenticated attackers with network access to obtain administrative privileges under the default configuration. WatchTowr honeypot data shows attackers minting administrator tokens, enumerating users, groups, and federated access topologies, and in some cases creating backdoor users for persistence. Users must upgrade to Artifactory 7.161.20 or the applicable fixed release; Qualys detects vulnerable assets via QID 735249.

Qualys ThreatPROTECT · 13d agoExploit / PoC in the wildCVE-2026-82329

Evaluating the NIST Bugs Framework Against CWE as a Successor for Automated Vulnerability Classification

NIST Bugs Framework evaluation shows it is more structured and automation-friendly than CWE for automated vulnerability classification, with gaps in attribute guidance.

The paper evaluates NIST SP 800-231's Bugs Framework (BF) against CWE as a target for automated CVE classification using a systematically screened corpus of CVE-to-CWE research. An inter-rater study with 2 subject-matter experts mapping 13 CVEs showed strong agreement on BF's cause and operation axes but only fair agreement on the attribute axis. Automated classification was tested across two LLM deployments under different budgets, and findings support BF as more structured and automation-friendly than CWE, though gaps include under-specified attribute guidance and missing fix commits for closed-source software.

arXiv cs.CR · 2d agoResearch1

USN-8735-1: HSQLDB vulnerability

Ubuntu released USN-8735-1 fixing an HSQLDB flaw that lets specially crafted database files overwrite arbitrary files.

Ubuntu Security Notice USN-8735-1 addresses a vulnerability in HSQLDB, which incorrectly handled specially crafted database files. An attacker could exploit the flaw to overwrite arbitrary files on affected systems; updated packages are available.

Ubuntu Security Notices · 8d agoAdvisory

CISA Adds Two Known Exploited Vulnerabilities to Catalog

CISA added two actively exploited MikroTik RouterOS vulnerabilities, CVE-2026-67277 and CVE-2026-86060, to its KEV catalog, mandating federal remediation.

CISA added CVE-2026-67277 (missing authentication for a critical function) and CVE-2026-86060 (improper neutralization of argument delimiters in a command), both in MikroTik RouterOS, to the Known Exploited Vulnerabilities Catalog based on evidence of active exploitation. Under BOD 26-04, Federal Civilian Executive Branch agencies must prioritize rapid remediation of these flaws on publicly exposed assets that grant total control post-exploitation. Agencies are also required to check whether systems were compromised before patches were applied.

CISA Advisories · 6d agoExploit / PoC in the wildCVE-2026-67277CVE-2026-86060

Enterprise Applications Carry 4.31x More Critical and High Vulnerabilities

Sonatype reports enterprise applications contain 4.31x more critical and high-severity vulnerabilities as accelerated software creation drives rising vulnerability levels.

Sonatype's analysis found enterprise applications carry 4.31 times more critical and high-severity vulnerabilities. The report links rising vulnerability levels to accelerated enterprise software creation. The findings are part of Sonatype's software supply chain research coverage reported by Infosecurity Magazine.

Infosecurity Magazine · 29d agoIndustry