[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"cve-CVE-2026-17524":3,"landing-trending":43,"landing-articles":121},{"id":4,"cve_id":5,"summary":6,"published":7,"cvss_data":8,"is_remote":23,"cwes":24,"cpes":26,"technologies":27,"references":28,"score":32,"epss_score":33,"epss_percentile":33,"is_kev":34,"cisa_kev_date_added":35,"cisa_kev_due_date":35,"cisa_ssvc":36,"exploits":42},369877,"CVE-2026-17524","Versions of the package zip-lib before 1.1.0 are vulnerable to Directory Traversal via the caching mechanism for path validation during the extraction process. An attacker can bypass security checks designed to prevent directory traversal. The intended security function, isOutsideTargetFolder, only checks and caches the path status when the initial directory symlink is created during the first extraction.","2026-07-28T06:16:00Z",{"cvss_v3.1":9,"cvss_v4.0":18},{"scope":10,"version":11,"baseScore":12,"attackVector":13,"baseSeverity":14,"vectorString":15,"integrityImpact":16,"userInteraction":16,"attackComplexity":17,"availabilityImpact":16,"privilegesRequired":16,"confidentialityImpact":14},"UNCHANGED","3.1",7.5,"NETWORK","HIGH","CVSS:3.1\u002FAV:N\u002FAC:L\u002FPR:N\u002FUI:N\u002FS:U\u002FC:H\u002FI:N\u002FA:N","NONE","LOW",{"Safety":19,"version":20,"Recovery":19,"baseScore":21,"Automatable":19,"attackVector":13,"baseSeverity":14,"valueDensity":19,"vectorString":22,"exploitMaturity":19,"providerUrgency":19,"userInteraction":16,"attackComplexity":17,"attackRequirements":16,"privilegesRequired":16,"subIntegrityImpact":16,"vulnIntegrityImpact":16,"integrityRequirement":19,"modifiedAttackVector":19,"subAvailabilityImpact":16,"vulnAvailabilityImpact":16,"availabilityRequirement":19,"modifiedUserInteraction":19,"modifiedAttackComplexity":19,"subConfidentialityImpact":16,"vulnConfidentialityImpact":14,"confidentialityRequirement":19,"modifiedAttackRequirements":19,"modifiedPrivilegesRequired":19,"modifiedSubIntegrityImpact":19,"modifiedVulnIntegrityImpact":19,"vulnerabilityResponseEffort":19,"modifiedSubAvailabilityImpact":19,"modifiedVulnAvailabilityImpact":19,"modifiedSubConfidentialityImpact":19,"modifiedVulnConfidentialityImpact":19},"NOT_DEFINED","4.0",8.7,"CVSS:4.0\u002FAV:N\u002FAC:L\u002FAT:N\u002FPR:N\u002FUI:N\u002FVC:H\u002FVI:N\u002FVA:N\u002FSC:N\u002FSI:N\u002FSA:N\u002FE:X\u002FCR:X\u002FIR:X\u002FAR:X\u002FMAV:X\u002FMAC:X\u002FMAT:X\u002FMPR:X\u002FMUI:X\u002FMVC:X\u002FMVI:X\u002FMVA:X\u002FMSC:X\u002FMSI:X\u002FMSA:X\u002FS:X\u002FAU:X\u002FR:X\u002FV:X\u002FRE:X\u002FU:X",true,[25],"CWE-22",[],[],[29,30,31],"https:\u002F\u002Fgithub.com\u002Ffpsqdb\u002Fzip-lib\u002Fcommit\u002F0c29b1e17050f2611f4f37e6aaa92a60b3cb89d5","https:\u002F\u002Fgithub.com\u002Ffpsqdb\u002Fzip-lib\u002Fissues\u002F14","https:\u002F\u002Fsecurity.snyk.io\u002Fvuln\u002FSNYK-JS-ZIPLIB-13834403",0.64,0,false,null,{"timestamp":35,"automatable":37,"tech_impact":38,"exploitation":39,"cisa_decision":40,"cisa_remediation_timeline":41},"no","partial","none",{},"FSU",[],{"count":44,"next":45,"previous":35,"results":46},133,"http:\u002F\u002Fweb:8606\u002Fapi\u002Ftrending_attacks\u002F?page=2&sorted_by=-published_at",[47,55,59,66,75,83,90,98,105,114],{"id":44,"title":48,"summary":49,"published_at":50,"severity":51,"vendor":52,"products":53},"CVE-2025-48828 and CVE-2026-61511 in vBulletin allow attackers to execute arbitrary PHP code through unauthenticated Remote Code Execution (RCE).","vBulletin is a commercial, self-hosted forum platform written in PHP and 2 CVE impact it.\r\n\r\nCVE-2025-48828: Template Conditional Bypass RCE\r\n\r\nIt is a Remote Code Execution vulnerability in vBulletin's template engine. Attackers can execute arbitrary PHP code by abusing Template Conditionals through alternative PHP function invocation syntax—specifically using the \"var_dump\"(\"test\") style notation rather than standard syntax. This crafted template code bypasses security checks designed to prevent unauthorized function calls, allowing complete server compromise without any authentication. The vulnerability exploits CWE-424 (Improper Protection of Alternate Path), meaning the security filters don't account for all possible code execution paths. This flaw was confirmed as exploited in the wild in May 2025, with scanning and exploitation attempts detected starting May 25, 2025.\r\n\r\nCVE-2026-61511: Eval Injection in Template Runtime\r\n\r\nIt is a Critical unauthenticated Remote Code Execution vulnerability affecting vBulletin 5.x and 6.x versions. The flaw exists in the vB5_Template_Runtime::runMaths() method, which applies an insufficiently restrictive regex filter before passing user input to PHP's dangerous eval() function. Attackers exploit this by sending specially crafted requests to the publicly accessible ajax\u002Frender AJAX endpoint with malicious input in the pagenav[pagenumber] parameter. Using phpfuck-style encoding—a technique that constructs arbitrary PHP expressions using only characters that pass the regex filter—attackers completely bypass the whitelist and execute arbitrary PHP code. This is exploitable with zero authentication, zero user interaction, and low attack complexity, making it extremely dangerous. A public Proof-of-Concept was released on July 27, 2026.","2026-07-28T07:47:00.746340Z",4,"Jelsoft Enterprises",[54],"vBulletin",{"id":56,"title":57,"summary":49,"published_at":50,"severity":51,"vendor":52,"products":58},132,"CVE-2025-48828 - CVE-2026-61511 - allow attackers to execute arbitrary PHP code and an Unauthenticated RCE",[54],{"id":60,"title":61,"summary":62,"published_at":63,"severity":51,"vendor":64,"products":65},131,"Multiple vulnerability on n8n : Credential Authorization Bypass, Account Takeover, Arbitrary File Read & SSRF via Nodemailer, Sandbox Escape to RCE, Arbitrary File Write","n8n is an open-source workflow automation platform frequently self-hosted on internet-facing infrastructure, enabling developers and enterprises to build, deploy, and manage automation workflows without extensive coding.\r\n\r\nGHSA-6qc9-mqvw-jg7x — HTTP Request Node Credential Authorization Bypass\r\n\r\nAn authenticated user with workflow editing permissions can reference another user's credentials in an HTTP Request node by specifying the credential type via an expression. Pre-execution permission checks compared the unresolved expression instead of the actual credential type, bypassing ownership validation. The credential is then loaded at runtime, allowing unauthorized access or exfiltration of credentials belonging to other users, provided the attacker knows the target credential ID.\r\n\r\nGHSA-8342-988q-86cr — Embed Login Account Takeover via Unverified Email Claims\r\n\r\nOn instances with Embed Login enabled and at least one trusted key source configured, the service failed to verify that the trusted key had appropriate role ceiling coverage for the target account and that email claims were verified. Any attacker with a token accepted by a trusted key source could authenticate as any existing user, gaining complete account control without needing valid credentials.\r\n\r\nGHSA-2x35-3fw4-9jr4 — Send Email Node Arbitrary File Read & SSRF via Nodemailer\r\n\r\nThe Send Email node did not enforce string-type constraints on message fields. Malicious non-string values derived from workflow expressions could be processed by the underlying mail library as file paths or URLs, enabling local file disclosure and SSRF attacks. Exploitation required a webhook-triggered workflow with valid SMTP credentials and unsanitized input mapped directly to message body fields.\r\n\r\nGHSA-gv7g-jm28-cr3m — Expression Sandbox Escape to Remote Code Execution\r\n\r\nAn authenticated user with workflow creation or modification permissions could craft expressions using arrow functions to bypass the expression sandbox and trigger unintended system command execution on the n8n host. The sandbox normally blocks .constructor access, but using with() statements and arrow functions, attackers could resolve constructor to the global Function constructor at runtime, achieving arbitrary code execution.\r\n\r\nGHSA-xmc9-4f2h-jf9c — Edit Image Node Format Injection to Arbitrary File Write\r\n\r\nThe Edit Image node passed its output format parameter to the underlying image library without validation. A crafted format value could write arbitrary bytes outside the node's working directory. Any authenticated user capable of executing workflows could exploit this to write arbitrary files to the n8n instance, potentially enabling persistence or privilege escalation.","2026-07-23T09:16:53.806844Z","n8n",[64],{"id":67,"title":68,"summary":69,"published_at":70,"severity":71,"vendor":72,"products":73},130,"CVE-2026-10816 - Arbitrary File Read (Unauthenticated) in NetScaler ADC and NetScaler Gateway","Citrix NetScaler is an application delivery controller (ADC) and load balancing platform that optimizes application performance, distributes traffic across servers, and manages user sessions in enterprise networks.\r\n\r\nCVE-2026-10816 is a critical unauthenticated arbitrary file read vulnerability affecting NetScaler ADC and Gateway. Attackers with adjacent network access to the management interface (NSIP, Cluster Management IP, or SNIP) can read arbitrary files without authentication, exposing sensitive data like configuration files, encryption keys, and session tokens. The vulnerability has a CVSS score of 7.5 (HIGH) and requires no user interaction or credentials to exploit.","2026-07-22T07:56:14.549887Z",3,"Citrix Systems",[74],"NetScaler",{"id":76,"title":77,"summary":78,"published_at":79,"severity":51,"vendor":80,"products":81},129,"Joomla Page Builder CK — CVE-2026-56290 : Unauthenticated Arbitrary File Upload to RCE","CVE-2026-56290 is a critical unauthenticated arbitrary file upload vulnerability affecting the Joomlack Page Builder CK extension for Joomla. It allows remote attackers without authentication to upload executable files directly to the server, resulting in complete remote code execution (RCE). The vulnerability stems from a lack of access control and upload restrictions — only a public CSRF token is required — enabling the placement of PHP web shells in any directory. It has a CVSS score of 10.0 (Critical) and is actively exploited since July 2026. Versions up to 3.5.10 are vulnerable; upgrading to version 3.6.0 (June 27, 2026) is imperative to fix authentication and authorization on the upload endpoint.","2026-07-21T13:10:44.290283Z","",[82],"Joomla",{"id":84,"title":85,"summary":86,"published_at":87,"severity":51,"vendor":88,"products":89},128,"CVE-2025-20309: Hardcoded SSH Root Credentials in Cisco Unified Communications Manager","Cisco Unified Communications Manager (UCM) and Cisco Unified Communications Manager Session Management Edition (SME) versions 15.0.1.13010-1 through 15.0.1.13017-1 contain hardcoded SSH root credentials that cannot be modified or removed by administrators. This vulnerability allows unauthenticated remote attackers to gain unauthorized administrative access to the system and execute arbitrary commands with root privileges.\r\nKey Details\r\n\r\nAn attacker with network access to the SSH port (22) of an affected Cisco Unified CM instance can authenticate using the embedded root credentials, bypassing all authentication mechanisms. Once authenticated, the attacker gains complete control of the system, enabling them to intercept communications, modify configurations, steal sensitive data, install persistent backdoors, and disrupt critical unified communications services.\r\n\r\nThe vulnerability affects only specific Engineering Special (ES) versions of Cisco Unified CM 15.0.1. Versions 12.5, 14.x, and 15SU3 (released July 2025 onwards) are not affected. The issue was publicly disclosed on July 2, 2025, with a critical CVSS score of 10.0 and no known public exploits at the time of publication, though exploitation is expected to be trivial given the straightforward attack vector.","2026-07-20T15:38:00.501391Z","Cisco",[88],{"id":91,"title":92,"summary":93,"published_at":94,"severity":51,"vendor":95,"products":96},127,"DifyTap: Authorization Bypass and Plugin Daemon Path Traversal in Dify AI Platform (CVE-2026-41947 & CVE-2026-41948)","CVE-2026-41947 (CVSS 9.1) — Authorization Bypass in Tracing Configuration\r\nAn authorization bypass vulnerability allows authenticated editor users to set and enable trace configurations for any application, regardless of tenant ownership. Because the tracing configuration endpoints fail to validate the requester's tenant, an attacker with a standard console account (freely obtainable through self-registration on Dify Cloud) can locate a public-facing application, obtain its internal App ID, and register their own tracing backend. This establishes a persistent exfiltration channel that redirects all messages and responses from the victim application to an attacker-controlled endpoint, effectively enabling \"wiretapping\" of private AI chat traffic.\r\n\r\nCVE-2026-41948 (CVSS 9.4) — Path Traversal in the Plugin Daemon\r\nA path traversal vulnerability in the Plugin Daemon (the component responsible for managing and running Dify plugins) allows authenticated users to manipulate requests forwarded to the daemon's internal REST API. By exploiting insufficient URL path sanitization, an attacker can traverse to and reach internal, private endpoints that should not be accessible from unauthenticated or external contexts.","2026-07-20T14:33:19.525819Z","LangGenius",[97],"Dify",{"id":99,"title":100,"summary":101,"published_at":102,"severity":71,"vendor":103,"products":104},126,"Arbitrary File Read (Unauthenticated) in NetScaler ADC and NetScaler Gateway","The vulnerability allows an attacker with adjacent or network access to the NetScaler management interfaces—specifically the NSIP (NetScaler IP), Cluster Management IP, or SNIP (Subnet IP) with management access enabled—to read arbitrary files from the appliance without requiring any authentication.","2026-07-20T12:46:29.390880Z","Citrix",[74],{"id":106,"title":107,"summary":108,"published_at":109,"severity":110,"vendor":111,"products":112},124,"Multiple vulnerability on Zimbra : Stored XSS via Calendar, crafted email and CSS @import","CVE-2024-27443\r\n\r\nThis is a cross-site scripting vulnerability affecting Zimbra Collaboration (ZCS) versions 9.0 and 10.0, specifically affecting the CalendarInvite feature in the Zimbra webmail classic user interface. The vulnerability stems from improper input validation in the handling of calendar headers within the CalendarInvite feature. The CVSS v3.1 base score is 6.1 (Medium), with the vector string CVSS:3.1\u002FAV:N\u002FAC:L\u002FPR:N\u002FUI:R\u002FS:C\u002FC:L\u002FI:L\u002FA:N, indicating network accessibility, low attack complexity, no privileges required, and user interaction required. When exploited, an attacker can execute arbitrary JavaScript in the context of the victim's session, triggered when the victim views a crafted email in the classic interface. It was added to CISA's Known Exploited Vulnerabilities (KEV) catalog on May 19, 2025. \r\nWiz + 3\r\n\r\nCVE-2025-48700\r\n\r\nThis is a cross-site scripting vulnerability in the Zimbra Classic UI affecting Zimbra Collaboration (ZCS) 8.8.15, 9.0, 10.0 and 10.1, allowing attackers to execute arbitrary JavaScript within a user's session, potentially leading to unauthorized access to sensitive information. This issue arises from insufficient sanitization of HTML content, specifically involving crafted tag structures and attribute values that include an @import directive and other script injection vectors. The vulnerability is triggered when a user views a crafted e-mail message in the Classic UI. It carries a CVSS 3.1 base score of 6.1 (Medium), vector CVSS:3.1\u002FAV:N\u002FAC:L\u002FPR:N\u002FUI:R\u002FS:C\u002FC:L\u002FI:L\u002FA:N. Synacor released security patches in June 2025, and CISA later added it to its Known Exploited Vulnerabilities catalog. \r\nGitHub + 2\r\n\r\nCVE-2025-66376\r\n\r\nThis is a stored cross-site scripting vulnerability affecting Zimbra Collaboration (ZCS) 10 before 10.0.18 and 10.1 before 10.1.13, allowing Classic UI stored XSS via Cascading Style Sheets (CSS) @import directives in an HTML email message. When a user opens the crafted email in the Classic UI, the injected script executes in the context of their browser session. It is rated high-severity with a CVSS score of 7.2 (vector CVSS:3.1\u002FAV:N\u002FAC:L\u002FPR:N\u002FUI:N\u002FS:C\u002FC:L\u002FI:L\u002FA:N per one vendor advisory). Synacor addressed the flaw with the release of Zimbra versions 10.1.13 and 10.0.18. It was added to CISA's KEV catalog in March 2026. \r\nCVE Details + 2\r\n\r\nA common thread across all three is that they are XSS flaws in Zimbra's Classic Web Client, exploited by sending specially crafted emails, and each has been associated with active exploitation in reporting. The general remediation guidance in each case is to update to the latest patched version.","2026-07-20T09:42:23.894156Z",2,"Synacor",[113],"Zimbra",{"id":115,"title":116,"summary":117,"published_at":118,"severity":71,"vendor":119,"products":120},125,"Authentication bypass in Traefik","Traefik is an HTTP reverse proxy and load balancer. Prior to versions 2.11.43, 3.6.14, and 3.7.0-rc.2, there is a high severity authentication bypass vulnerability in Traefik's StripPrefixRegex middleware when used in combination with ForwardAuth, BasicAuth, or DigestAuth. The middleware matches the regex against the decoded URL path but uses the resulting byte length to slice the percent-encoded raw path. When a dot (or multiple dots) appears in the prefix portion of the URL, the raw path after stripping becomes a dot-segment (e.g. \u002F.\u002Fadmin\u002Fsecret). ForwardAuth receives this dot-segment path in X-Forwarded-Uri, which does not match the protected path patterns and therefore allows the request through. The backend then normalizes the dot-segment to the real path per RFC 3986 and serves the protected content An unauthenticated attacker can exploit this against any backend that performs dot-segment normalization. This issue has been patched in versions 2.11.43, 3.6.14, and 3.7.0-rc.2.","2026-07-20T09:15:02.620009Z","Traefik",[119],{"count":122,"next":123,"previous":35,"results":124},20,"http:\u002F\u002Fweb:8606\u002Fapi\u002Farticles\u002F?page=2&sorted_by=-published_at",[125,133,137,140,148,155,163,170,177,182],{"id":126,"title":127,"summary":128,"published_at":129,"type":130,"link":131,"image_url":132},19,"Wp2shell: WordPress Security Flaws","Deep dive into wp2shell vulnerabilities (CVE-2026-63030 & CVE-2026-60137) in WordPress. Detection guide and fixes to secure your sites.","2026-07-20T00:00:00Z","cve","https:\u002F\u002Fpatrowl.io\u002Fen\u002Fblog\u002Fwp2shell-critical-wordpress-vulnerabilities-copier","https:\u002F\u002Fpatrowl.io\u002Fmedia\u002Fsite\u002F97aa11e60b-1784565821\u002Fminiature-wp2shell.png",{"id":134,"title":127,"summary":135,"published_at":129,"type":130,"link":136,"image_url":132},18,"Deep dive into wp2shell vulnerabilities (CVE-2026-63030 & CVE-2026-60137) in WordPress 7.0.2. Detection guide and fixes to secure your sites.","https:\u002F\u002Fpatrowl.io\u002Fen\u002Fblog\u002Fwp2shell-critical-wordpress-vulnerabilities",{"id":122,"title":127,"summary":128,"published_at":129,"type":130,"link":138,"image_url":139},"https:\u002F\u002Fpatrowl.io\u002Fen\u002Fblog\u002Fwp2shell-critical-wordpress-vulnerabilities-2026","https:\u002F\u002Fpatrowl.io\u002Fmedia\u002Fsite\u002F97aa11e60b-1784567602\u002Fminiature-wp2shell.png",{"id":141,"title":142,"summary":143,"published_at":144,"type":145,"link":146,"image_url":147},17,"SAST vs DAST vs IAST vs RASP: Which One Do You Need?","Four methods, four moments in the application risk cycle. Compare SAST, DAST, IAST and RASP — and see which one fits your stack, your team and your code access.","2026-07-13T00:00:00Z","security tips","https:\u002F\u002Fpatrowl.io\u002Fen\u002Fblog\u002Fsast-vs-dast-vs-iast-vs-rasp","https:\u002F\u002Fpatrowl.io\u002Fmedia\u002Fsite\u002F1d32e651a8-1784299758\u002Fsast-dast-iast-rasp.png",{"id":149,"title":150,"summary":151,"published_at":152,"type":145,"link":153,"image_url":154},16,"NIS2 transposition delays: why waiting is a trap","The substance of NIS2 is fixed by Directive (EU) 2022\u002F2555 and ENISA","2026-07-10T00:00:00Z","https:\u002F\u002Fpatrowl.io\u002Fen\u002Fblog\u002Fnis2-transposition-delay","https:\u002F\u002Fpatrowl.io\u002Fmedia\u002Fsite\u002F33c9b48a9c-1783691971\u002Fnis2-update.png",{"id":156,"title":157,"summary":158,"published_at":159,"type":160,"link":161,"image_url":162},15,"Claude Mythos & curl: AI Is Driving an Explosion in Vulnerability Reports","As curl is overwhelmed by AI-generated reports, Claude Mythos is accelerating the discovery of real vulnerabilities. For security teams, the challenge is validating and prioritizing what truly matters.","2026-07-08T00:00:00Z","hacks","https:\u002F\u002Fpatrowl.io\u002Fen\u002Fblog\u002Fclaude-mythos-ia-vulnerabilities","https:\u002F\u002Fpatrowl.io\u002Fmedia\u002Fsite\u002F0bcbb9b93f-1783584347\u002Fclaude-mythos-miniature.png",{"id":164,"title":165,"summary":166,"published_at":167,"type":145,"link":168,"image_url":169},14,"Cyber security frameworks: technical vs compliance, and what automation changes.","OWASP, NIS Regulations, FCA resilience, UK GDPR… two families of framework, two uses. How to choose by context, and how far automation can take you.","2026-06-30T00:00:00Z","https:\u002F\u002Fpatrowl.io\u002Fen\u002Fblog\u002Fcyber-security-frameworks-technical-vs-compliance-2026","https:\u002F\u002Fpatrowl.io\u002Fmedia\u002Fsite\u002Ffd2bcdb500-1782814993\u002Fcyber-security-framework-2026-og.png",{"id":171,"title":172,"summary":173,"published_at":174,"type":145,"link":175,"image_url":176},13,"OWASP Top 10 2025: the ranking, the changes and the 2026 data","Two new categories, SSRF absorbed, security misconfiguration now at #2. The new OWASP ranking explained, with the 2026 supply-chain data that matters.","2026-06-29T00:00:00Z","https:\u002F\u002Fpatrowl.io\u002Fen\u002Fblog\u002Fowasp-top-10-2025-what-s-changed-and-the-2026-data","https:\u002F\u002Fpatrowl.io\u002Fmedia\u002Fsite\u002Fa617128d05-1782741441\u002Fowasp-top-10-2025-open-graph-uk.png",{"id":178,"title":179,"summary":179,"published_at":174,"type":180,"link":181,"image_url":80},12,"OWASP Top 10 2025 : nouveautés, classement et données 2026","astuces","https:\u002F\u002Fpatrowl.io\u002Fen\u002Fblog\u002Fowasp-top-10-2025-nouveautes-classement-et-donnees-2026",{"id":183,"title":184,"summary":185,"published_at":186,"type":145,"link":187,"image_url":188},11,"Types of pentest: a complete guide to choosing the right penetration test","Web, API, DNS, OSINT, cloud, mobile, subdomain takeover: a complete guide to 18 types of penetration tests, what each approach covers, and how to choose based on your operational and regulatory context.","2026-06-23T00:00:00Z","https:\u002F\u002Fpatrowl.io\u002Fen\u002Fblog\u002Fpenetration-testing-types","https:\u002F\u002Fpatrowl.io\u002Fmedia\u002Fsite\u002Fb4d89de5a0-1781878397\u002Ftypes-of-penetration-testing.png"]