Threat Reports

21 AI-generated reports, human-reviewed.

INFOthreat

WordPress Core SQL Injection (CVE-2026-60137) Chained for RCE

A SQL injection vulnerability in WordPress Core’s `WP_Query` `author__not_in` parameter (CVE-2026-60137) allows attackers to inject malicious SQL. This vulnerability can be chained with CVE-2026-63030 to achieve unauthenticated remote code execution on default WordPress installations, and is currently being actively exploited in the wild.

Read report →
INFOthreat

CVE-2026-50522: Critical SharePoint RCE via Deserialization of Untrusted Data

CVE-2026-50522 is a critical deserialization vulnerability in Microsoft SharePoint Server, allowing unauthorized remote code execution. Actively exploited, this flaw enables attackers to compromise SharePoint instances, potentially leading to machine key theft and broader network compromise. Immediate patching is required.

Read report →
INFOthreat

CVE-2026-63030: WordPress REST API RCE via Chained SQL Injection

A critical vulnerability, CVE-2026-63030, in WordPress Core’s REST API batch endpoint, when chained with CVE-2026-60137 (SQL Injection), allows unauthenticated attackers to achieve Remote Code Execution. This flaw affects WordPress versions 6.9.x before 6.9.5 and 7.0.x before 7.0.2 and is actively exploited in the wild.

Read report →
INFOthreat

CVE-2026-16232: Check Point SmartConsole Authentication Bypass Vulnerability

A critical authentication bypass vulnerability (CVE-2026-16232) in Check Point SmartConsole allows unauthenticated remote attackers to gain full administrative privileges. This flaw enables attackers to modify security policies and configurations on affected Check Point Management Servers. Check Point has confirmed active exploitation of this vulnerability.

Read report →
INFOthreat

CVE-2026-46817: Oracle E-Business Suite Payments Takeover Vulnerability

A critical improper privilege management vulnerability (CVE-2026-46817) in Oracle E-Business Suite’s Payments product allows unauthenticated attackers to achieve full takeover of Oracle Payments via network access. This vulnerability affects versions 12.2.3 through 12.2.15 and has a CVSS 3.1 score of 9.8.

Read report →
INFOthreat

CVE-2026-58644: Microsoft SharePoint Deserialization RCE

A critical deserialization of untrusted data vulnerability (CVE-2026-58644) in Microsoft SharePoint allows unauthenticated, remote code execution. This flaw, with a CVSSv3.1 score of 9.8, enables attackers to compromise affected SharePoint servers without prior authentication. Immediate patching is advised to prevent exploitation.

Read report →
INFOthreat

CVE-2026-39808: Fortinet FortiSandbox OS Command Injection Vulnerability

A critical OS command injection vulnerability (CVE-2026-39808) exists in Fortinet FortiSandbox versions 4.4.0 through 4.4.9. This flaw allows an unauthenticated attacker to execute arbitrary code or commands via crafted HTTP requests. The vulnerability has a CVSSv3.1 score of 9.8 (CRITICAL) and is listed in CISA’s Known Exploited Vulnerabilities Catalog, indicating active exploitation.

Read report →
INFOthreat

CVE-2026-25089: Fortinet FortiSandbox OS Command Injection Vulnerability

Fortinet FortiSandbox products are vulnerable to an unauthenticated OS command injection (CVE-2026-25089). This critical flaw allows remote attackers to execute arbitrary commands via crafted HTTP requests. Active exploitation has been observed, making immediate patching crucial for affected organizations.

Read report →
INFOthreat

CVE-2026-41091: Microsoft Defender Link Following Vulnerability

CVE-2026-41091 is a high-severity local privilege escalation vulnerability in Microsoft Defender, rated 7.8 CVSSv3.1. It stems from improper link resolution, allowing an authorized local attacker to gain elevated privileges. This vulnerability is listed in CISA’s KEV catalog, indicating active exploitation.

Read report →
INFOthreat

Lucifer DaaS: Scaling Crypto Wallet Theft via Malicious Transaction Approvals

The Lucifer DaaS (Drainer-as-a-Service) platform facilitates large-scale cryptocurrency wallet theft by tricking users into approving malicious blockchain transactions. Unlike traditional wallet hacks, these attacks leverage sophisticated phishing and social engineering to gain explicit user consent, leading to the irreversible draining of funds. Defenders should focus on user education and transaction scrutiny.

Read report →
INFOthreat

CVE-2026-41091: Microsoft Defender Link Following Vulnerability

CVE-2026-41091 is a high-severity local privilege escalation vulnerability affecting Microsoft Defender. An authorized attacker can exploit improper link resolution to gain elevated privileges on a compromised system. This vulnerability poses a significant risk to endpoint security, allowing attackers to bypass security controls and achieve SYSTEM-level access.

Read report →
INFOthreat

CVE-2026-45498: Microsoft Defender Denial of Service Vulnerability

CVE-2026-45498 describes an unspecified denial of service vulnerability in Microsoft Defender. This vulnerability has been added to CISA’s Known Exploited Vulnerabilities (KEV) catalog, indicating a significant risk that requires prompt attention. Exploitation could lead to the disruption of endpoint protection services.

Read report →
INFOthreat

Grafana GitHub Breach: Stolen Token Led to Codebase Theft

Grafana Labs disclosed a security incident where a stolen GitHub access token was used to breach their GitHub environment. Attackers downloaded private source code repositories, prompting immediate token revocation and security enhancements. No customer data or production environments were affected.

Read report →
INFOthreat

Leaked Shai-Hulud Malware Fuels New npm Infostealer Campaign

The recently leaked Shai-Hulud infostealer malware is now being actively used in new campaigns targeting the Node Package Manager (npm) ecosystem. Threat actors are distributing malicious npm packages to compromise developer systems and exfiltrate sensitive data, posing a significant supply chain risk.

Read report →
INFOthreat

New Malware Libraries Drive Signature Updates and Evasion Challenges

The continuous development of new malware libraries and obfuscation techniques necessitates constant updates to security product signatures. Defenders must ensure their detection mechanisms are current to identify evolving threats that leverage these new components, challenging traditional static signature-based defenses. This ongoing evolution highlights the importance of behavioral analysis alongside signature updates.

Read report →
INFOthreat

Pwn2Own Berlin Day 2: Zero-Days Demonstrated in Microsoft Exchange, Windows 11, and RHEL

During Pwn2Own Berlin 2026 Day 2, researchers successfully exploited 15 unique zero-day vulnerabilities across multiple products. Key targets included Microsoft Exchange, Windows 11, and Red Hat Enterprise Linux for Workstations, demonstrating critical security flaws in these widely deployed systems.

Read report →
INFOthreat

CVE-2026-42897: Microsoft Exchange Server Cross-Site Scripting Vulnerability

A high-severity cross-site scripting (XSS) vulnerability, CVE-2026-42897, has been identified in Microsoft Exchange Server, including versions 2016 and 2019. This flaw allows an unauthenticated attacker to execute arbitrary JavaScript in a user’s browser context via Outlook Web Access when certain interaction conditions are met, leading to high impact on confidentiality and integrity. CISA has added this CVE to its Known Exploited Vulnerabilities Catalog.

Read report →
INFOthreat

CVE-2026-42208: Critical SQL Injection in BerriAI LiteLLM AI Gateway

A critical SQL injection vulnerability (CVE-2026-42208) affects BerriAI LiteLLM versions 1.81.16 to before 1.83.7. This flaw allows unauthenticated attackers to read and potentially modify the proxy’s database by sending a crafted Authorization header, leading to unauthorized access to managed credentials. The vulnerability is actively exploited and listed in CISA’s KEV catalog.

Read report →
INFOthreat

CVE-2026-6973: Remote Code Execution in Ivanti EPMM

CVE-2026-6973 is an improper input validation vulnerability in Ivanti Endpoint Manager Mobile (EPMM) that allows a remotely authenticated administrative user to achieve remote code execution. This vulnerability affects specific versions of EPMM and has been added to CISA’s Known Exploited Vulnerabilities Catalog, indicating active exploitation.

Read report →
INFOthreat

WordPress Funnel Builder Plugin Vulnerability Actively Exploited for Credit Card Theft

A critical vulnerability in the Funnel Builder WordPress plugin is under active exploitation. Attackers are leveraging this flaw to inject malicious JavaScript into WooCommerce checkout pages, aiming to steal sensitive credit card details from customers. This poses a significant risk to e-commerce platforms utilizing the vulnerable plugin.

Read report →
INFOthreat

CVE-2026-0300: PAN-OS User-ID Authentication Portal RCE Vulnerability

A critical out-of-bounds write vulnerability (CVE-2026-0300) in Palo Alto Networks PAN-OS User-ID Authentication Portal allows unauthenticated attackers to achieve root-level arbitrary code execution. This affects PA-Series and VM-Series firewalls, posing a significant risk if the portal is publicly exposed. The vulnerability has a CVSS 3.1 score of 9.8 (CRITICAL) and is listed in CISA’s KEV catalog, indicating active exploitation.

Read report →