[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"cve-CVE-2026-100556":3,"landing-trending":43,"landing-articles":117},{"id":4,"cve_id":5,"summary":6,"published":7,"cvss_data":8,"is_remote":23,"cwes":24,"cpes":26,"technologies":27,"references":28,"score":31,"epss_score":32,"epss_percentile":33,"is_kev":34,"cisa_kev_date_added":35,"cisa_kev_due_date":35,"cisa_ssvc":36,"exploits":42},395828,"CVE-2026-100556","OpenClaw (npm package openclaw) versions >= 2026.5.2 and \u003C 2026.8.1 contain an incorrect authorization vulnerability in WhatsApp group handling. A group sender who is admitted for ordinary messages but denied by commands.allowFrom or owner command authorization can issue the \u002Fnew \u003Cmodel> command to reset the shared group session and persist a provider and model override. This allows a command-denied group member to select a provider and model already permitted by the operator for subsequent turns in the shared group session, potentially changing provider routing, cost, data flow, or availability. It does not allow adding a new provider or host command execution. The issue is fixed in version 2026.8.1.","2026-09-26T03:17:00Z",{"cvss_v3.1":9,"cvss_v4.0":18},{"scope":10,"version":11,"baseScore":12,"attackVector":13,"baseSeverity":14,"vectorString":15,"integrityImpact":16,"userInteraction":17,"attackComplexity":16,"availabilityImpact":16,"privilegesRequired":16,"confidentialityImpact":16},"UNCHANGED","3.1",6.3,"NETWORK","MEDIUM","CVSS:3.1\u002FAV:N\u002FAC:L\u002FPR:L\u002FUI:N\u002FS:U\u002FC:L\u002FI:L\u002FA:L","LOW","NONE",{"Safety":19,"version":20,"Recovery":19,"baseScore":21,"Automatable":19,"attackVector":13,"baseSeverity":14,"valueDensity":19,"vectorString":22,"exploitMaturity":19,"providerUrgency":19,"userInteraction":17,"attackComplexity":16,"attackRequirements":17,"privilegesRequired":16,"subIntegrityImpact":17,"vulnIntegrityImpact":16,"integrityRequirement":19,"modifiedAttackVector":19,"subAvailabilityImpact":17,"vulnAvailabilityImpact":16,"availabilityRequirement":19,"modifiedUserInteraction":19,"modifiedAttackComplexity":19,"subConfidentialityImpact":17,"vulnConfidentialityImpact":16,"confidentialityRequirement":19,"modifiedAttackRequirements":19,"modifiedPrivilegesRequired":19,"modifiedSubIntegrityImpact":19,"modifiedVulnIntegrityImpact":19,"vulnerabilityResponseEffort":19,"modifiedSubAvailabilityImpact":19,"modifiedVulnAvailabilityImpact":19,"modifiedSubConfidentialityImpact":19,"modifiedVulnConfidentialityImpact":19},"NOT_DEFINED","4.0",5.3,"CVSS:4.0\u002FAV:N\u002FAC:L\u002FAT:N\u002FPR:L\u002FUI:N\u002FVC:L\u002FVI:L\u002FVA:L\u002FSC:N\u002FSI:N\u002FSA:N\u002FE:X\u002FCR:X\u002FIR:X\u002FAR:X\u002FMAV:X\u002FMAC:X\u002FMAT:X\u002FMPR:X\u002FMUI:X\u002FMVC:X\u002FMVI:X\u002FMVA:X\u002FMSC:X\u002FMSI:X\u002FMSA:X\u002FS:X\u002FAU:X\u002FR:X\u002FV:X\u002FRE:X\u002FU:X",true,[25],"CWE-863",[],[],[29,30],"https:\u002F\u002Fgithub.com\u002Fopenclaw\u002Fopenclaw\u002Fsecurity\u002Fadvisories\u002FGHSA-mm7m-wcgh-8mfq","https:\u002F\u002Fwww.vulncheck.com\u002Fadvisories\u002Fopenclaw-before-2026.8.1-authentication-bypass-via-session-reset",0.47,0.00278,0.18182,false,null,{"timestamp":35,"automatable":37,"tech_impact":38,"exploitation":39,"cisa_decision":40,"cisa_remediation_timeline":41},"no","partial","none",{},"FSU",[],{"count":44,"next":45,"previous":35,"results":46},197,"http:\u002F\u002Fweb:8606\u002Fapi\u002Ftrending_attacks\u002F?page=2&sorted_by=-published_at",[47,55,63,71,75,83,91,96,104,108],{"id":44,"title":48,"summary":49,"published_at":50,"severity":51,"vendor":52,"products":53},"WordPress plugin Forminator Forms - Unauthenticated Arbitrary Shortcode Execution","Forminator Forms is a popular WordPress plugin designed for building custom forms, interactive quizzes, polls, and calculations using a drag-and-drop builder.\r\n\r\nCVE-2026-92229\r\n\r\nCritical 9.1 CVSS-rated vulnerability in the Forminator Forms WordPress plugin (versions ≤ 1.57.2) that allows remote, unauthenticated attackers to execute arbitrary WordPress shortcodes by exploiting a lack of input validation on the current_url parameter during AJAX quiz submissions (forminator_submit_form_quizzes), potentially leading to unauthorized data exposure or deeper site compromise depending on the active shortcodes available on the server.","2026-09-25T12:24:44.219824Z",4,"WPMU DEV",[54],"Forminator",{"id":56,"title":57,"summary":58,"published_at":59,"severity":51,"vendor":60,"products":61},196,"Multiple vulnerability on Synology - Potential RCE via Authentication Bypass due to Insufficient Login Entropy & Potential RCE via Arbitrary File Write due to SCGI Encoding Flaw","Synology DiskStation Manager (DSM) (the impacted technology) is a proprietary, Linux-based operating system that centralizes storage management, file sharing, and cloud application hosting across the brand's NAS servers.\r\n\r\nCVE-2026-13639\r\n\r\nThe authentication subsystem uses a weak pseudo-random number generator when creating session tokens — either an inadequate seed, insufficient environmental entropy at generation time, or a predictable algorithmic pattern. The result: session identifiers that can be predicted or enumerated within a feasible attack window.\r\nAn attacker who can observe or probe the DSM management interface collects token samples, identifies the pattern, and forges a valid administrative session — without ever needing a password. Once in, they have full DSM access: file system operations, user management, package installs, and all connected storage volumes.\r\n\r\nCVE-2026-13684\r\n\r\nThe SCGI (Server Common Gateway Interface) component fails to properly encode or escape output before passing data downstream. Crafted HTTP requests inject content interpreted as commands or path traversal sequences rather than literal data.\r\nFrom there: read arbitrary files (configuration, \u002Fetc\u002Fpasswd, private keys, stored credentials) or write arbitrary files (drop a web shell into the DSM web root, overwrite configuration for persistence). The write primitive maps to T1505.003 (Web Shell).","2026-09-24T14:32:39.544994Z","Synology",[62],"Synology DiskStation Manager (DSM)",{"id":64,"title":65,"summary":66,"published_at":67,"severity":51,"vendor":68,"products":69},195,"F5 BIG-IP APM - Unauthenticated Remote Code Execution via OAuth Profile","F5 BIG-IP APM is a widely deployed SSL VPN, reverse proxy, and access gateway used by enterprises to publish and control access to internal applications through OAuth-based authentication and access policies.\r\n\r\nCVE-2026-94127\r\n\r\nWhen BIG-IP APM is configured with an OAuth Authorization Server profile on a virtual server, specially crafted malicious traffic allows unauthenticated attackers to execute remote code on the BIG-IP system.\r\nThis data plane vulnerability affects internet-facing appliances and enables complete perimeter compromise, including internal network pivoting and traffic interception.","2026-09-24T13:25:44.640222Z","F5",[70],"F5 big-ip access policy manager",{"id":72,"title":57,"summary":58,"published_at":73,"severity":51,"vendor":60,"products":74},193,"2026-09-23T12:19:37.010409Z",[62],{"id":76,"title":77,"summary":78,"published_at":79,"severity":80,"vendor":81,"products":82},192,"WordPress - Unauthenticated path traversal in page-template resolution leading to conditional RCE","WordPress is the world's most popular open-source Content Management System (CMS), written in PHP and paired with a MySQL\u002FMariaDB database, powering over 40% of all websites on the internet to manage and publish digital content.\r\n\r\nCVE-2026-87902\r\n\r\nCritical unauthenticated path traversal and local file inclusion (LFI) vulnerability in WordPress Core. The flaw exists in how WordPress dynamically resolves and handles page templates based on the requested URL parameters (pagename) without properly sanitizing directory traversal sequences (like ..\u002F).\r\nAn unauthenticated remote attacker can exploit this to force the application to load and execute an arbitrary, readable local .php file from outside the active theme directory. Under specific server environments—such as when the PHP configuration register_argc_argv is enabled—this LFI can be leveraged to achieve full Remote Code Execution (RCE), allowing complete server takeover.","2026-09-23T08:14:56.775223Z",3,"WordPress",[81],{"id":84,"title":85,"summary":86,"published_at":87,"severity":51,"vendor":88,"products":89},194,"Multiple vulnerability on SolarWinds - SAML 2.0 Authentication Bypass in Web Help Desk & Unauthenticated RCE via Hardcoded Cryptographic Key & Unauthenticated Deserialization RCE & Unauthenticated RCE via Integrity Check Bypass","SolarWinds Web Help Desk and Access Rights Manager provide helpdesk ticketing and identity\u002Faccess governance capabilities across enterprise environments, often deployed with internet or DMZ-facing components for remote administration.\r\n\r\nCVE-2026-28323\r\n\r\nSolarWinds Web Help Desk fails to properly validate SAML 2.0 assertions, allowing unauthenticated attackers to bypass authentication and impersonate legitimate users. This requires the SAML 2.0 authentication method to be enabled. Exploitation enables reading and modifying all helpdesk tickets and attachments—which frequently contain credentials, PII, and internal system data—and pivoting to integrated systems such as Active Directory and email.\r\n\r\nCVE-2026-28326\r\n\r\nSolarWinds Access Rights Manager contains a hardcoded static cryptographic key that allows unauthenticated remote code execution on the ARM server. Successful exploitation grants the attacker privileges of the service account, which holds sensitive Active Directory and permission data, enabling lateral movement and privilege escalation across the organization.\r\n\r\nCVE-2026-28324\r\n\r\nCritical remote code execution (RCE) vulnerability in SolarWinds Observability Self-Hosted that has been assigned a maximum CVSS base score of 9.8. This flaw stems from insufficient integrity checks within the application. It specifically impacts instances that have been deployed in a non-default, non-secure configuration. Because it requires no user interaction or privileges, a remote, unauthenticated attacker can exploit this weakness over the network to execute arbitrary commands, potentially leading to a total compromise of the host system's confidentiality, integrity, and availability.\r\n\r\nCVE-2026-28325\r\n\r\nHigh-severity security vulnerability, rated with a CVSS score of 8.8, which also leads to unauthenticated remote code execution (RCE). The root cause of this flaw is the deserialization of untrusted data when the application is configured to run under a specific communication mode, often tied to Web Performance Monitor (WPM) players. By sending maliciously crafted serialized objects over the adjacent network, an attacker can manipulate the processing logic without any valid credentials. This allows them to run unauthorized commands or malware directly within the context of the underlying SolarWinds server.","2026-09-22T12:22:59.154694Z","solarwinds",[90],"solarwinds web help desk",{"id":92,"title":93,"summary":94,"published_at":87,"severity":51,"vendor":88,"products":95},191,"Multiple vulnerability on SolarWinds - SAML 2.0 Authentication Bypass in Web Help Desk & Unauthenticated RCE via Hardcoded Cryptographic Key","SolarWinds Web Help Desk and Access Rights Manager provide helpdesk ticketing and identity\u002Faccess governance capabilities across enterprise environments, often deployed with internet or DMZ-facing components for remote administration.\r\n\r\nCVE-2026-28323\r\n\r\nSolarWinds Web Help Desk fails to properly validate SAML 2.0 assertions, allowing unauthenticated attackers to bypass authentication and impersonate legitimate users. This requires the SAML 2.0 authentication method to be enabled. Exploitation enables reading and modifying all helpdesk tickets and attachments—which frequently contain credentials, PII, and internal system data—and pivoting to integrated systems such as Active Directory and email.\r\n\r\nCVE-2026-28326\r\n\r\nSolarWinds Access Rights Manager contains a hardcoded static cryptographic key that allows unauthenticated remote code execution on the ARM server. Successful exploitation grants the attacker privileges of the service account, which holds sensitive Active Directory and permission data, enabling lateral movement and privilege escalation across the organization.",[90],{"id":97,"title":98,"summary":99,"published_at":100,"severity":51,"vendor":101,"products":102},190,"Zimbra SNMP - Unauthenticated RCE via SMTP","Zimbra SNMP is an integrated component of Zimbra Collaboration Suite designed to generate and transmit server performance data, health metrics, and alerts to centralized network monitoring systems.\r\n\r\nCVE-2026-73570\r\n\r\nCritical remote code execution vulnerability exists in Zimbra Collaboration versions prior to 10.1.20 due to improper sanitization of untrusted input within the platform's SNMP notification processing system. When the optional zimbra-snmp package is installed and SNMP notifications are enabled, an unauthenticated remote attacker can transmit specially crafted SMTP requests to the mail server. Because the incoming notification payloads are processed without sufficient input validation, the malicious data escapes its context and is injected directly into operating system commands. This flaw allows the attacker to achieve arbitrary code execution on the underlying server with the full system privileges of the zimbra user, requiring no credentials or user interaction.","2026-09-18T08:48:52.390988Z","Synacor",[103],"Zimbra Collaboration Suite (ZCS)",{"id":105,"title":98,"summary":99,"published_at":100,"severity":51,"vendor":101,"products":106},188,[107],"Zimbra SNMP",{"id":109,"title":110,"summary":111,"published_at":112,"severity":51,"vendor":113,"products":114},183,"Cisco Identity Services Engine - Unauthenticated Admin Access & Unauthenticated API Auth Bypass","Cisco Identity Services Engine (ISE) is a network access control platform that enforces security policies by validating user and device identities. Its companion component, Cisco ISE Passive Identity Connector (ISE-PIC), gathers user identity information passively from external authentication servers (like Active Directory) and shares that data with security subscribers. Both technologies work together to control network access dynamically and maintain complete infrastructure visibility.\r\n\r\nCVE-2026-76460\r\n\r\nThis vulnerability represents a critical authentication bypass flaw within the REST API endpoint of Cisco ISE. Assigned the maximum severity rating of CVSS 10.0, it allows remote, unauthenticated attackers to completely circumvent security controls and gain unauthorized access to the system. This security loophole has been identified as a zero-day vulnerability and is actively being exploited in the wild, making immediate patching a vital priority for administrators.\r\n\r\nCVE-2026-76423\r\n\r\nParallel to the authentication flaw, this critical vulnerability involves an authorization bypass defect residing in the Cisco ISE REST API framework. Also rated at a maximum CVSS 10.0, the bug enables a remote, non-authenticated threat actor to manipulate API requests to bypass administrative validation mechanisms. Successfully exploiting this flaw grants the attacker full administrative privileges over the affected deployment, compromising the entire network access control infrastructure.","2026-09-17T08:39:13.162649Z","Cisco",[115,116],"Cisco Identity Services Engine (ISE)","Cisco ISE Passive Identity Connector (ISE-PIC)",{"count":118,"next":119,"previous":35,"results":120},29,"http:\u002F\u002Fweb:8606\u002Fapi\u002Farticles\u002F?page=2&sorted_by=-published_at",[121,128,136,143,150,158,163,170,177,184],{"id":118,"title":122,"summary":123,"published_at":124,"type":125,"link":126,"image_url":127},"Manage External Security Across All Your Entities","Centralize the management of entities, users and external security resources while maintaining strict data isolation with Patrowl.","2026-09-15T00:00:00Z","security tips","https:\u002F\u002Fpatrowl.io\u002Fen\u002Fblog\u002Fmulti-entity-external-security-how-structure-governance-group-level","https:\u002F\u002Fpatrowl.io\u002Fmedia\u002Fsite\u002F8b2c0cc5eb-1789551467\u002Fvisu_1_multi_tenancy_dark_1x.webp",{"id":129,"title":130,"summary":131,"published_at":132,"type":133,"link":134,"image_url":135},28,"Will AI Become the Next Hacker? Bruce Schneier Answers at DEF CON 34","Tax law, finance, legislation: Bruce Schneier shows how AI could hack human rule systems just as easily as it hacks software.","2026-09-14T00:00:00Z","hacks","https:\u002F\u002Fpatrowl.io\u002Fen\u002Fblog\u002Fbruce-schneier-def-con-34","https:\u002F\u002Fpatrowl.io\u002Fmedia\u002Fsite\u002F5c616d9db4-1789462598\u002Fai-hacker.en.png",{"id":137,"title":138,"summary":139,"published_at":140,"type":125,"link":141,"image_url":142},27,"Exposure Management: definition, stakes, and how it works","Vulnerabilities, misconfigurations, poorly managed identities: understand what Exposure Management is and why it matters in 2026.","2026-09-10T00:00:00Z","https:\u002F\u002Fpatrowl.io\u002Fen\u002Fblog\u002Fdefinition-exposure-management","https:\u002F\u002Fpatrowl.io\u002Fmedia\u002Fsite\u002F06170638a9-1789050834\u002Fexposure.management.definition.en.png",{"id":144,"title":145,"summary":146,"published_at":147,"type":133,"link":148,"image_url":149},26,"DGFiP Cyberattack 2026: Inside the Attacker","Two distinct attacks hit France","2026-08-17T00:00:00Z","https:\u002F\u002Fpatrowl.io\u002Fen\u002Fblog\u002Fdgfip-cyberattack-2026-inside-attacker-mind","https:\u002F\u002Fpatrowl.io\u002Fmedia\u002Fsite\u002Fdc38d33696-1787055371\u002Fdgfip-2026.png",{"id":151,"title":152,"summary":153,"published_at":154,"type":155,"link":156,"image_url":157},25,"CVE-2026-64638: XSS2Shell, a WordPress Login Vulnerability","Pre-auth XSS on wp-login.php, patched August 6. What is actually exploitable, and how to read it in your Patrowl report.","2026-08-10T00:00:00Z","cve","https:\u002F\u002Fpatrowl.io\u002Fen\u002Fblog\u002Fxss2shell-critical-wordpress-login-vulnerability-2026","https:\u002F\u002Fpatrowl.io\u002Fmedia\u002Fsite\u002F904e61748b-1786369212\u002Fxss2shell.png",{"id":159,"title":160,"summary":160,"published_at":154,"type":155,"link":161,"image_url":162},24,"CVE-2026-64638 : XSS2Shell, faille du login WordPress","https:\u002F\u002Fpatrowl.io\u002Fen\u002Fblog\u002Fcve-2026-64638-xss2shell-faille-login-wordpress","",{"id":164,"title":165,"summary":166,"published_at":167,"type":155,"link":168,"image_url":169},23,"How Agentic AI Hunts Down CVEs Before Attackers Do","38 vulnerability sources monitored around the clock, pentester-validated proof of exploitability, an alert within hours. See how it works.","2026-08-05T00:00:00Z","https:\u002F\u002Fpatrowl.io\u002Fen\u002Fblog\u002Fproactive-threat-hunting-agentic-ai-cve","https:\u002F\u002Fpatrowl.io\u002Fmedia\u002Fsite\u002F804988ce7b-1785930160\u002Fproactive-threat-hunting-how-agentic-ai-tracks-cves.png",{"id":171,"title":172,"summary":173,"published_at":174,"type":133,"link":175,"image_url":176},22,"AI Agent Incident: OpenAI HuggingFace — Risks and Lessons","An autonomous AI agent escaped its sandbox via a JFrog Artifactory zero-day, compromised HuggingFace via privilege escalation and stolen credentials. Reconstructed timeline and security lessons.","2026-07-31T00:00:00Z","https:\u002F\u002Fpatrowl.io\u002Fen\u002Fblog\u002Fai-agent-incident-openai-huggingface-risks","[Image URL from Kirby]",{"id":178,"title":179,"summary":180,"published_at":181,"type":125,"link":182,"image_url":183},21,"SaaS Under Watch: What Your SDLC Doesn","Your pipeline is green. Your real exposure may have changed without you knowing it. The complete guide for software vendors.","2026-07-29T00:00:00Z","https:\u002F\u002Fpatrowl.io\u002Fen\u002Fblog\u002Fsecuring-saas-application-software-vendor","https:\u002F\u002Fpatrowl.io\u002Fmedia\u002Fsite\u002F20d6ec0cd0-1785331401\u002Fapplication-security.png",{"id":185,"title":186,"summary":187,"published_at":188,"type":155,"link":189,"image_url":190},18,"Wp2shell: WordPress Security Flaws","Deep dive into wp2shell vulnerabilities (CVE-2026-63030 & CVE-2026-60137) in WordPress 7.0.2. Detection guide and fixes to secure your sites.","2026-07-20T00:00:00Z","https:\u002F\u002Fpatrowl.io\u002Fen\u002Fblog\u002Fwp2shell-critical-wordpress-vulnerabilities","https:\u002F\u002Fpatrowl.io\u002Fmedia\u002Fsite\u002F97aa11e60b-1784565821\u002Fminiature-wp2shell.png"]