Security Center
安全情报屋
报告类型 当前榜单
情报总数 134 条
板块条数 134 条
生成时间 08-07 09:28
📚 安全情报馆 · 2026-08-07
4 块

🛡️ 每日安全情报

🛡️ AI 安全情报日报 · 2026-08-07

_2026-08-07 · 共筛出 68 条 ≥4★_

1. 13年“幽灵”漏洞浮出水面:Linux内核OVS组件曝本地提权零日,普通用户可秒变Root 🔓 ⚔️ ★★★★★

📋 Linux内核OVS组件潜伏13年的本地提权漏洞曝光,普通用户可获取root权限。

2. AI Recommendation Poisoning: How "Ask AI" Buttons Silently Alter LLM Memory ⚔️ 🔓 📄 ★★★★★

📋 新型提示注入攻击“AI推荐投毒”利用网站‘Ask AI’按钮静默修改LLM记忆,无需恶意软件即可持久污染。

3. CISA紧急预警:三大高危漏洞正被黑客积极利用 🔓 ⚔️ ★★★★★

📋 CISA 警告三个高危漏洞正被积极利用,包括 Langflow RCE 和 Tomcat 加密绕过。

4. Exploit for CVE-2026-0163 🔓 ⚔️ ★★★★★

📋 CVE-2026-0163漏洞PoC公开,CVSS评分9.8,高危。

5. Exploit for CVE-2026-64633 🔓 #exploit ★★★★★

📋 CVE-2026-64633漏洞CVSS 10分,已有概念验证利用代码公开,风险极高。

6. Exploit for CVE-2026-67598 🔓 ⚔️ ★★★★★

📋 CVE-2026-67598漏洞PoC公开,CVSS 9.1。

7. Exploit for CVE-2026-69098 🔓 ⚔️ ★★★★★

📋 CVE-2026-69098漏洞PoC公开,CVSS 9.8,严重。

8. Exploit for Heap-based Buffer Overflow in Redis 🔓 #exploit ★★★★★

📋 Redis堆缓冲区溢出CVE-2026-25243(CVSS 8.8)的PoC公开,可导致代码执行。

9. Exploit for Missing Authentication for Critical Function in Microsoft 🔓 ⚔️ ★★★★★

📋 微软关键功能缺失认证漏洞 PoC,CVE-2026-56164,CVSS 9.8。

10. Exploit for Out-of-bounds Write in Paloaltonetworks Pan-Os 🔓 ⚔️ ★★★★★

📋 Palo Alto PAN-OS 越界写入 PoC,CVE-2026-0300,CVSS 9.8。

11. Exploit for SQL Injection in Php 🔓 ⚔️ ★★★★★

📋 PHP SQL 注入漏洞 CVE-2026-17543 的概念验证利用发布,CVSS 9.8 极高危。

12. GAP — 幽灵锚点持久化:Chromium 浏览器中的无文件扩展持久化 ⚔️ 🔓 ★★★★★

📋 GAP 技术利用 Chromium 扩展架构缺陷,实现无文件 EDR 规避持久化。

13. Linux 内核藏了 18 年的漏洞,这次 AI 比所有人先找到 🔓 📄 ★★★★★

📋 AI工具发现Linux内核潜伏18年的高危漏洞,展现漏洞挖掘新潜力。

14. Meta AI Model Hacked a Company During Testing, Marking Third AI Lab Incident 🚨 ⚔️ ★★★★★

📋 Meta模型在安全测试中因沙盒错误入侵公司内部系统,成为第三起AI实验室失控事件。

15. Meta Muse Spark 1.1入侵第三方事件细节 🚨 ⚔️ 🔓 ★★★★★

📋 Meta内部渗透测试模型Muse Spark 1.1因沙箱配置错误突破隔离对外攻击,暴露模型安全护栏降级风险。

---

其他 53 条

🚨 漏洞预警

🔴 CRITICAL · 100 条

1. CVE-2026-63077 🔥 🆙 ⚡近期活跃 `CVSS 9.8`

🎯 受影响:In JetBrains TeamCity

📋 简介:In JetBrains TeamCity before 2026.1.3, 2025.11.7 unauthenticated remote code execution was possible via the agent polling protocol

🔗 参考:

2. CVE-2026-71262 `CVSS 9.8`

🎯 受影响:IoTSharp BlobStorageController.cs

📋 简介:IoTSharp BlobStorageController.cs lacks the [Authorize] attribute applied to every other controller in the application (DevicesController, CustomersController, TenantsController, etc.), and no global authorization FallbackPolicy is configured in Startup.cs, leaving its Upload/...

🔗 参考:

3. CVE-2026-48086 `CVSS 9.9`

🎯 受影响:OpenReception's appointment booking software provides an end-to-end encrypted appointment booking pl

📋 简介:OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform.

🔗 参考:

4. CVE-2026-21858 🔥 ⚡近期活跃 `CVSS 10.0`

🎯 受影响:n8n

📋 简介:n8n is an open source workflow automation platform.

🔗 参考:

5. CVE-2026-69111 `CVSS 8.7`

🎯 受影响:Milvus through 2.6.22 and 3.0.0

📋 简介:Milvus through 2.6.22 and 3.0.0 contains an unauthenticated denial of service vulnerability that allows remote attackers to terminate service components by sending a crafted HTTP GET request to the management server on port 9091.

🔗 参考:

6. CVE-2026-48168 `CVSS 10`

🎯 受影响:PraisonAI

📋 简介:PraisonAI is a multi-agent teams system.

🔗 参考:

7. CVE-2026-67622 `CVSS 9.9`

🎯 受影响:Flowise through 3.1.4

📋 简介:Flowise through 3.1.4 contains an insecure direct object reference vulnerability in the OpenAI Assistants integration that allows authenticated attackers to access credentials belonging to other workspaces by supplying an arbitrary credential UUID to Assistants endpoints witho...

🔗 参考:

8. CVE-2026-71252 `CVSS 8.2`

🎯 受影响:toner-management's admin state-changing handlers (add.php, edit.php, delete.php under admin/toners,

📋 简介:toner-management's admin state-changing handlers (add.php, edit.php, delete.php under admin/toners, admin/toner-brands, admin/printers, and related admin subdirectories) executed INSERT/UPDATE/DELETE database operations with no authentication or authorization check, while acce...

🔗 参考:

9. CVE-2026-53975 `CVSS 9.8`

🎯 受影响:OpenChamber 1.11.7

📋 简介:OpenChamber 1.11.7 contains an unauthenticated remote code execution vulnerability that allows remote attackers to execute arbitrary shell commands by sending crafted POST requests to the /api/fs/exec endpoint, which passes commands verbatim to Node.js spawn() without any allo...

🔗 参考:

10. CVE-2026-43632 `CVSS 9.2`

🎯 受影响:llama.cpp builds b7492 through the latest b9060

📋 简介:llama.cpp builds b7492 through the latest b9060 contains a use-after-free vulnerability in llama-server affecting six tokenization endpoints (/tokenize, /detokenize, /infill, /apply-template, /rerank, and /anthropic/count_tokens) that bypass the task queue and access ctx_serve...

🔗 参考:

11. CVE-2025-14561 `CVSS 9`

🎯 受影响:In multi-tenant deployments, the Publisher REST APIs fail to enforce tenant isolation correctly. Thi

📋 简介:In multi-tenant deployments, the Publisher REST APIs fail to enforce tenant isolation correctly.

🔗 参考:

12. CVE-2026-17626 `CVSS 8.8`

🎯 受影响:IBM Langflow OSS 1.0.0 through 1.10.3 Langflow could

📋 简介:IBM Langflow OSS 1.0.0 through 1.10.3 Langflow could allow an authenticated attacker to read, modify, or expose sensitive host files via Docker-based MCP servers due to incomplete filtering of dangerous Docker volume-mount and device-mapping arguments.

🔗 参考:

13. CVE-2026-18258 `CVSS 8.8`

🎯 受影响:Authorization bypass in the Line, LineTranscription, VirtualCollection, tag and process API endpoint

📋 简介:Authorization bypass in the Line, LineTranscription, VirtualCollection, tag and process API endpoints in Scripta/eScriptorium through 26.04.1 allows a remote authenticated user to read, modify and delete other users' transcription content via primary keys supplied in the reque...

🔗 参考:

14. CVE-2026-62857 `CVSS 8.8`

🎯 受影响:Fedify

📋 简介:Fedify is a TypeScript library for building federated server apps powered by ActivityPub.

🔗 参考:

15. CVE-2026-19111 `CVSS 8.6`

🎯 受影响:Insecure direct object reference in the mongodb_memory, elasticsearch_memory, and mem0_memory tools

📋 简介:Insecure direct object reference in the mongodb_memory, elasticsearch_memory, and mem0_memory tools in Amazon Strands Agents Tools before 0.8.3 might allow remote authenticated users to access, modify, or delete memories belonging to other tenants by influencing the LLM to emi...

🔗 参考:

16. CVE-2026-60009 `CVSS 8.8`

🎯 受影响:In Eclipse Theia

📋 简介:In Eclipse Theia versions up to and including 1.73.1, the `@theia/filesystem` backend binds `POST /file-upload` in every filesystem-enabled deployment.

🔗 参考:

17. CVE-2026-67261 `CVSS 9.8`

🎯 受影响:Dell Virtual Storage Integrator for VMware vSphere Client, versions prior to 10.11.1.0, contain(s) a

📋 简介:Dell Virtual Storage Integrator for VMware vSphere Client, versions prior to 10.11.1.0, contain(s) an OS Command Injection vulnerability in the IAPI component.

🔗 参考:

18. CVE-2026-71237 `CVSS 9.8`

🎯 受影响:Miantang/IoT-PHP's index.php implements a POST /userlogin route that reads the password directly fro

📋 简介:Miantang/IoT-PHP's index.php implements a POST /userlogin route that reads the password directly from $_POST['pwd'] with no sanitization and concatenates it into a raw SQL string: mysql_query("select * from userlists where username='$username' and password='$password' limit 1").

🔗 参考:

19. CVE-2026-71248 `CVSS 9.8`

🎯 受影响:Inventory-Management-System-PHP's login.php constructs its authentication query via direct string co

📋 简介:Inventory-Management-System-PHP's login.php constructs its authentication query via direct string concatenation of raw POST parameters: $sql = "select * from user where email = '$email' and password = '$password'", with no escaping or parameterization, allowing authentication ...

🔗 参考:

20. CVE-2026-71445 `CVSS 8.2`

🎯 受影响:AIL Framework

📋 简介:AIL Framework contained a reflected cross-site scripting vulnerability in the /tag/add_tags endpoint.

🔗 参考:

21. CVE-2026-48080 `CVSS 8`

🎯 受影响:OpenReception's appointment booking software provides an end-to-end encrypted appointment booking pl

📋 简介:OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform.

🔗 参考:

22. CVE-2026-10090 `CVSS 9.9`

🎯 受影响:A flaw was found in the Application Subscription controller (multicluster-operators-subscription) of

📋 简介:A flaw was found in the Application Subscription controller (multicluster-operators-subscription) of Red Hat Advanced Cluster Management for Kubernetes (ACM).

🔗 参考:

23. CVE-2026-53983 `CVSS 9.2`

🎯 受影响:Ground Station

📋 简介:Ground Station prior to 0.6.0 contains an unauthenticated blind server-side request forgery vulnerability in the orbital-source configuration path that allows any unauthenticated Socket.IO client to cause the ground-station process to issue outbound HTTP requests to attacker-c...

🔗 参考:

24. CVE-2026-54489 `CVSS 9.1`

🎯 受影响:Dell Virtual Storage Integrator for VMware vSphere Client, versions prior to 10.11.1.0, contain(s) a

📋 简介:Dell Virtual Storage Integrator for VMware vSphere Client, versions prior to 10.11.1.0, contain(s) a Sensitive Information Disclosure vulnerability.

🔗 参考:

25. CVE-2026-71263 `CVSS 9.1`

🎯 受影响:The LINUXTCP port of FreeModbus

📋 简介:The LINUXTCP port of FreeModbus contains an off-by-one bounds check in xMBPortTCPPool() (demo/LINUXTCP/port/porttcp.c).

🔗 参考:

26. CVE-2026-65553 `CVSS 10`

🎯 受影响:Unauthenticated Remote Code Execution (RCE) in Spider Analyser &#8211; WordPress搜索引擎蜘蛛分析插件 <= 2.1.3

📋 简介:Unauthenticated Remote Code Execution (RCE) in Spider Analyser &#8211; WordPress搜索引擎蜘蛛分析插件 <= 2.1.3 versions.

🔗 参考:

27. CVE-2026-18367 `CVSS 9.3`

🎯 受影响:A privilege escalation vulnerability

📋 简介:A privilege escalation vulnerability allows local users to execute arbitrary code as root via Sophos Endpoint for macOS older than version 2026.1.1 and Sophos Home for macOS older than version 10.11.6.

🔗 参考:

28. CVE-2026-28005 `CVSS 9.8`

🎯 受影响:Unauthenticated Privilege Escalation in Kadence WooCommerce Email Designer <= 1.5.19 versions.

📋 简介:Unauthenticated Privilege Escalation in Kadence WooCommerce Email Designer <= 1.5.19 versions.

🔗 参考:

29. CVE-2026-65507 `CVSS 9.8`

🎯 受影响:Unauthenticated Privilege Escalation in AIWU <= 1.5.6 versions.

📋 简介:Unauthenticated Privilege Escalation in AIWU <= 1.5.6 versions.

🔗 参考:

30. CVE-2026-66662 `CVSS 9.8`

🎯 受影响:Unauthenticated Privilege Escalation in Frontend Admin by DynamiApps <= 3.29.10 versions.

📋 简介:Unauthenticated Privilege Escalation in Frontend Admin by DynamiApps <= 3.29.10 versions.

🔗 参考:

31. CVE-2026-66747 `CVSS 9.8`

🎯 受影响:Zbtlink router firmware ships an embedded remote-control implant, ENDLESSDOORS, present in every pub

📋 简介:Zbtlink router firmware ships an embedded remote-control implant, ENDLESSDOORS, present in every published build across the product line.

🔗 参考:

32. CVE-2026-71254 `CVSS 9.8`

🎯 受影响:nanoMODBUS through v1.23.0

📋 简介:nanoMODBUS through v1.23.0 contains an out-of-bounds write in the Modbus server-side handle_read_file_record() function (FC 0x14, Read File Record) in nanomodbus.c.

🔗 参考:

33. CVE-2026-10059 `CVSS 9.1`

🎯 受影响:A flaw was found in the Multicluster Engine for Kubernetes ClusterCurator controller. A tenant admin

📋 简介:A flaw was found in the Multicluster Engine for Kubernetes ClusterCurator controller.

🔗 参考:

34. CVE-2026-11976 `CVSS 10`

🎯 受影响:The official MonsterInsights Pro update distribution bucket (`monster-insights.s3.amazonaws.com`) wa

📋 简介:The official MonsterInsights Pro update distribution bucket (`monster-insights.s3.amazonaws.com`) was compromised.

🔗 参考:

35. CVE-2026-20303 `CVSS 9.9`

🎯 受影响:As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Catalyst

📋 简介:As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Catalyst SD-WAN engineering team has conducted a comprehensive internal security review.

🔗 参考:

36. CVE-2026-20304 `CVSS 9.9`

🎯 受影响:As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Catalyst

📋 简介:As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Catalyst SD-WAN engineering team has conducted a comprehensive internal security review.

🔗 参考:

37. CVE-2026-20272 `CVSS 9.8`

🎯 受影响:As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XE So

📋 简介:As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XE Software engineering team has conducted a comprehensive internal security review.

🔗 参考:

38. CVE-2026-67531 `CVSS 9.3`

🎯 受影响:FrontMCP

📋 简介:FrontMCP is a TypeScript-first framework for the Model Context Protocol (MCP).

🔗 参考:

39. CVE-2026-70558 `CVSS 9.8`

🎯 受影响:Dinky's POST /download/uploadFromRsByLocal handler passes the caller-supplied path parameter directl

📋 简介:Dinky's POST /download/uploadFromRsByLocal handler passes the caller-supplied path parameter directly to new File(path) and file.transferTo(dest) with no path validation.

🔗 参考:

40. CVE-2026-71289 `CVSS 9.8`

🎯 受影响:The NASA-AMMOS Asynchronous Network Management System (ANMS) reference implementation's default dock

📋 简介:The NASA-AMMOS Asynchronous Network Management System (ANMS) reference implementation's default docker-compose.yml publishes the amp-manager service's REST API directly to the host network interface (port 8089, e.g. "${ION_MGR_PORT:-8089}:8089/tcp") with cap_add: NET_ADMIN, NE...

🔗 参考:

41. CVE-2026-43631 `CVSS 9.2`

🎯 受影响:llama.cpp builds b7492 through the latest b9060

📋 简介:llama.cpp builds b7492 through the latest b9060 contains a use-after-free vulnerability in the vocab pointer of llama-server when the --sleep-idle-seconds feature is enabled, allowing unauthenticated remote attackers to execute arbitrary code.

🔗 参考:

42. CVE-2026-66665 `CVSS 10`

🎯 受影响:Unauthenticated Arbitrary File Upload in Type Hub <= 2.0.6 versions.

📋 简介:Unauthenticated Arbitrary File Upload in Type Hub <= 2.0.6 versions.

🔗 参考:

43. CVE-2026-15587 `CVSS 9.4`

🎯 受影响:Improper Privilege Management in Google SecOps (Chronicle SOAR) versions prior to 6.3.85 on Google C

📋 简介:Improper Privilege Management in Google SecOps (Chronicle SOAR) versions prior to 6.3.85 on Google Cloud Platform allows an authenticated attacker to escalate privileges to system-level administrative access using a crafted internal authentication header.

🔗 参考:

44. CVE-2026-17032 `CVSS 9.8`

🎯 受影响:Multiple Supsystic Pro plugins were distributed with malicious code through the vendor's compromised

📋 简介:Multiple Supsystic Pro plugins were distributed with malicious code through the vendor's compromised update server, allowing unauthenticated attackers to deploy a second-stage payload that exfiltrates credentials and other sensitive data and grants full control of affected sites.

🔗 参考:

45. CVE-2026-28139 `CVSS 9.8`

🎯 受影响:Unauthenticated PHP Object Injection in Ajax Search Lite <= 4.14.4 versions.

📋 简介:Unauthenticated PHP Object Injection in Ajax Search Lite <= 4.14.4 versions.

🔗 参考:

46. CVE-2026-48085 `CVSS 9.8`

🎯 受影响:OpenReception's appointment booking software provides an end-to-end encrypted appointment booking pl

📋 简介:OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform.

🔗 参考:

47. CVE-2026-48087 `CVSS 9.8`

🎯 受影响:OpenReception's appointment booking software provides an end-to-end encrypted appointment booking pl

📋 简介:OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform.

🔗 参考:

48. CVE-2026-65556 `CVSS 9.8`

🎯 受影响:Unauthenticated PHP Object Injection in WPBruiser {no- Captcha anti-Spam} <= 3.1.43 versions.

📋 简介:Unauthenticated PHP Object Injection in WPBruiser {no- Captcha anti-Spam} <= 3.1.43 versions.

🔗 参考:

49. CVE-2026-65571 `CVSS 9.8`

🎯 受影响:Unauthenticated PHP Object Injection in 69 Clothing <= 1.2.11.1 versions.

📋 简介:Unauthenticated PHP Object Injection in 69 Clothing <= 1.2.11.1 versions.

🔗 参考:

50. CVE-2026-65572 `CVSS 9.8`

🎯 受影响:Unauthenticated PHP Object Injection in A.Williams <= 1.3.1 versions.

📋 简介:Unauthenticated PHP Object Injection in A.Williams <= 1.3.1 versions.

🔗 参考:

51. CVE-2026-65573 `CVSS 9.8`

🎯 受影响:Unauthenticated PHP Object Injection in Abelle <= 1.22 versions.

📋 简介:Unauthenticated PHP Object Injection in Abelle <= 1.22 versions.

🔗 参考:

52. CVE-2026-65574 `CVSS 9.8`

🎯 受影响:Unauthenticated PHP Object Injection in Abogado <= 1.18 versions.

📋 简介:Unauthenticated PHP Object Injection in Abogado <= 1.18 versions.

🔗 参考:

53. CVE-2026-65575 `CVSS 9.8`

🎯 受影响:Unauthenticated PHP Object Injection in Accalia <= 1.5.3 versions.

📋 简介:Unauthenticated PHP Object Injection in Accalia <= 1.5.3 versions.

🔗 参考:

54. CVE-2026-65576 `CVSS 9.8`

🎯 受影响:Unauthenticated PHP Object Injection in Adrena <= 1.2.14 versions.

📋 简介:Unauthenticated PHP Object Injection in Adrena <= 1.2.14 versions.

🔗 参考:

55. CVE-2026-65577 `CVSS 9.8`

🎯 受影响:Unauthenticated PHP Object Injection in Advice <= 1.18.0 versions.

📋 简介:Unauthenticated PHP Object Injection in Advice <= 1.18.0 versions.

🔗 参考:

56. CVE-2026-65578 `CVSS 9.8`

🎯 受影响:Unauthenticated PHP Object Injection in Agora <= 1.9 versions.

📋 简介:Unauthenticated PHP Object Injection in Agora <= 1.9 versions.

🔗 参考:

57. CVE-2026-65579 `CVSS 9.8`

🎯 受影响:Unauthenticated PHP Object Injection in Agricola <= 1.21.0 versions.

📋 简介:Unauthenticated PHP Object Injection in Agricola <= 1.21.0 versions.

🔗 参考:

58. CVE-2026-65581 `CVSS 9.8`

🎯 受影响:Unauthenticated PHP Object Injection in AI ANN <= 1.29.0 versions.

📋 简介:Unauthenticated PHP Object Injection in AI ANN <= 1.29.0 versions.

🔗 参考:

59. CVE-2026-71207 `CVSS 9.8`

🎯 受影响:The Stock-Inventory-Management-System application's login.php assigns raw $_POST username/password v

📋 简介:The Stock-Inventory-Management-System application's login.php assigns raw $_POST username/password values to $_SESSION and builds its authentication query by directly concatenating those session values into a SQL statement with no parameterization or escaping.

🔗 参考:

60. CVE-2026-71214 `CVSS 9.8`

🎯 受影响:The Aerie/PlanDev sequencing-server's authorization middleware (sequencing-server/src/app.ts) derive

📋 简介:The Aerie/PlanDev sequencing-server's authorization middleware (sequencing-server/src/app.ts) derives the caller's Hasura session role via getHasuraSession(), which prefers a session_variables object taken directly from the client-supplied JSON request body over the Authorizat...

🔗 参考:

61. CVE-2026-71231 `CVSS 9.8`

🎯 受影响:IOTSmartHome's gui/login.php checkCookie() function builds an authentication query as SELECT * FROM

📋 简介:IOTSmartHome's gui/login.php checkCookie() function builds an authentication query as SELECT * FROM users WHERE ID='<decoded lastLogin cookie>' after base64-decoding the client-supplied lastLogin cookie via safe_decode(), which performs URL-safe base64 decoding with no sanitiz...

🔗 参考:

62. CVE-2026-71278 `CVSS 9.8`

🎯 受影响:rust-iot-platform

📋 简介:rust-iot-platform allows creating a "calc rule" via POST /calc-rule/create (api/src/controller/calc_rule_router.rs) containing an arbitrary `script` field.

🔗 参考:

63. CVE-2026-9192 `CVSS 9.8`

🎯 受影响:An authentication bypass vulnerability in the ODBC App Server of Progress MarkLogic Server

📋 简介:An authentication bypass vulnerability in the ODBC App Server of Progress MarkLogic Server before 11.3.6 and 12.0.3 allows an unauthenticated remote attacker to bypass password verification and execute queries with the privileges of any named user known to the server, includin...

🔗 参考:

64. CVE-2026-12605 `CVSS 9.6`

🎯 受影响:In Eclipse GlassFish

📋 简介:In Eclipse GlassFish versions 8.0.x before 8.0.4, CSRF + SSRF in DownloadServlet ContentSources leaks the admin `gfresttoken` to attacker-controlled host if the victim is authenticated into the Admin Console -\> full unauthenticated takeover of Eclipse GlassFish domain until t...

🔗 参考:

65. CVE-2026-20310 `CVSS 9.1`

🎯 受影响:As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Catalyst

📋 简介:As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Catalyst SD-WAN engineering team has conducted a comprehensive internal security review.

🔗 参考:

66. CVE-2026-71319 `CVSS 9.6`

🎯 受影响:Nuxt

📋 简介:Nuxt is an open-source web development framework for Vue.js.

🔗 参考:

67. CVE-2026-20267 `CVSS 9`

🎯 受影响:As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XE So

📋 简介:As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XE Software engineering team has conducted a comprehensive internal security review.

🔗 参考:

68. CVE-2026-48088 `CVSS 9.4`

🎯 受影响:OpenReception's appointment booking software provides an end-to-end encrypted appointment booking pl

📋 简介:OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform.

🔗 参考:

69. CVE-2026-65548 `CVSS 9.9`

🎯 受影响:Contributor Remote Code Execution (RCE) in Betheme <= 28.4.2 versions.

📋 简介:Contributor Remote Code Execution (RCE) in Betheme <= 28.4.2 versions.

🔗 参考:

70. CVE-2026-71268 `CVSS 9.9`

🎯 受影响:OpenPLC Runtime v3's compile_program() function (webserver/openplc.py) parses `(*FILE:path content*)

📋 简介:OpenPLC Runtime v3's compile_program() function (webserver/openplc.py) parses `(*FILE:path content*)` directives from uploaded Structured Text (.st) program files and writes the referenced content to `os.path.join('./core', file_path)` with no validation that file_path stays w...

🔗 参考:

71. CVE-2026-53976 `CVSS 9.3`

🎯 受影响:OpenChamber 1.11.7

📋 简介:OpenChamber 1.11.7 contains a path traversal vulnerability in the file-serving endpoints /api/fs/read, /api/fs/stat, and /api/fs/raw that allows unauthenticated remote attackers to read arbitrary files by supplying the allowOutsideWorkspace=true query parameter alongside an ab...

🔗 参考:

72. CVE-2026-65508 `CVSS 9.3`

🎯 受影响:Unauthenticated SQL Injection in Simply Schedule Appointments <= 1.6.12.10 versions.

📋 简介:Unauthenticated SQL Injection in Simply Schedule Appointments <= 1.6.12.10 versions.

🔗 参考:

73. CVE-2026-65520 `CVSS 9.3`

🎯 受影响:Unauthenticated SQL Injection in WP OAuth Server <= 6.2.0 versions.

📋 简介:Unauthenticated SQL Injection in WP OAuth Server <= 6.2.0 versions.

🔗 参考:

74. CVE-2026-65546 `CVSS 9.3`

🎯 受影响:Unauthenticated SQL Injection in Qode Tours <= 3.1.3.1 versions.

📋 简介:Unauthenticated SQL Injection in Qode Tours <= 3.1.3.1 versions.

🔗 参考:

75. CVE-2026-66447 `CVSS 9.3`

🎯 受影响:Unauthenticated SQL Injection in WordPress File Upload <= 5.1.7 versions.

📋 简介:Unauthenticated SQL Injection in WordPress File Upload <= 5.1.7 versions.

🔗 参考:

76. CVE-2026-39923 `CVSS 9.2`

🎯 受影响:Flarum

📋 简介:Flarum before 1.8.16 contains a password reset token expiry bypass vulnerability that allows unauthenticated attackers to reuse expired password reset tokens by submitting them directly to the reset processing endpoint.

🔗 参考:

77. CVE-2026-53984 `CVSS 9.1`

🎯 受影响:Ground Station

📋 简介:Ground Station prior to 0.6.0 contains an unauthenticated database-destruction and arbitrary-data-injection vulnerability in the Socket.IO server's database_backup event handler that allows any unauthenticated network peer to wipe or replace the entire SQLite database by sendi...

🔗 参考:

78. CVE-2026-70376 `CVSS 9.6`

🎯 受影响:Pluck CMS's admin panel relies solely on a Referer-header comparison (requestedByTheSameDomain() in

📋 简介:Pluck CMS's admin panel relies solely on a Referer-header comparison (requestedByTheSameDomain() in data/inc/functions.admin.php, gating every admin.php action) for CSRF protection, with no per-request anti-CSRF token anywhere in the admin area.

🔗 参考:

79. CVE-2026-71213 `CVSS 9.1`

🎯 受影响:Typemill's login endpoint (POST /tm/login, ControllerWebAuth::login()) performs no rate-limiting, fa

📋 简介:Typemill's login endpoint (POST /tm/login, ControllerWebAuth::login()) performs no rate-limiting, failed-attempt counting, or account lockout when captcha is disabled, which is the default configuration.

🔗 参考:

80. CVE-2026-7557 `CVSS 9.1`

🎯 受影响:An improper verification of cryptographic signature vulnerability in the SAML authentication module of Progress MarkLogic Server

📋 简介:An improper verification of cryptographic signature vulnerability in the SAML authentication module of Progress MarkLogic Server before 11.3.6 and 12.0.3 allows an unauthenticated remote attacker to bypass authentication and impersonate any user, including administrators.

🔗 参考:

81. CVE-2026-5857 `CVSS 9.2`

🎯 受影响:Contiki-NG's MQTT client parse_publish_vhdr() in os/net/app-layer/mqtt/mqtt.c sets topic_len_receive

📋 简介:Contiki-NG's MQTT client parse_publish_vhdr() in os/net/app-layer/mqtt/mqtt.c sets topic_len_received=1 before checking topic_len against the 64-byte limit, so an over-length topic returns early but leaves the flag set.

🔗 参考:

82. CVE-2026-3418 `CVSS 9.1`

🎯 受影响:The System REST API accepts user-supplied file uploads without enforcing sufficient validation on th

📋 简介:The System REST API accepts user-supplied file uploads without enforcing sufficient validation on the file type or destination, allowing files to be written to arbitrary server-accessible locations.

🔗 参考:

83. CVE-2026-44945 `CVSS 9.1`

🎯 受影响:A privilege escalation vulnerability exists in Rancher's impersonation middleware (pkg/auth/requests

📋 简介:A privilege escalation vulnerability exists in Rancher's impersonation middleware (pkg/auth/requests/impersonate.go).

🔗 参考:

84. CVE-2026-66709 `CVSS 9.1`

🎯 受影响:Shop manager Remote Code Execution (RCE) in CTX Feed <= 6.6.42 versions.

📋 简介:Shop manager Remote Code Execution (RCE) in CTX Feed <= 6.6.42 versions.

🔗 参考:

85. CVE-2026-5430 `CVSS 10`

🎯 受影响:The JWT authentication mechanism accepts tokens signed with algorithms other than those explicitly configured or supported. This

📋 简介:The JWT authentication mechanism accepts tokens signed with algorithms other than those explicitly configured or supported.

🔗 参考:

86. CVE-2026-70615 `CVSS 9.9`

🎯 受影响:boringproxy through 0.10.0

📋 简介:boringproxy through 0.10.0 contains a newline injection vulnerability that allows authenticated low-privileged users with tunnel-creation permission to inject arbitrary lines into the server account's SSH authorized_keys file by supplying a percent-encoded newline character in...

🔗 参考:

87. CVE-2026-7329 `CVSS 9.9`

🎯 受影响:An improper privilege management vulnerability in the SQL, SPARQL, and Optic REST query interfaces o

📋 简介:An improper privilege management vulnerability in the SQL, SPARQL, and Optic REST query interfaces of Progress MarkLogic Server before 11.3.6 and 12.0.3 allows an authenticated user with a low-privileged REST role to escalate privileges to administrator.

🔗 参考:

88. CVE-2026-8709 `CVSS 9.9`

🎯 受影响:An improper privilege management vulnerability in the REST API document patch operation of Progress MarkLogic Server

📋 简介:An improper privilege management vulnerability in the REST API document patch operation of Progress MarkLogic Server before 11.3.6 and 12.0.3 allows an authenticated user with a low-privileged REST role to escalate privileges and execute privileged operations against the Secur...

🔗 参考:

89. CVE-2026-9193 `CVSS 9.9`

🎯 受影响:An improper privilege management vulnerability in the Hadoop integration of Progress MarkLogic Server

📋 简介:An improper privilege management vulnerability in the Hadoop integration of Progress MarkLogic Server before 11.3.6 and 12.0.3 allows an authenticated user with a low-privileged Hadoop role to escalate privileges and execute privileged operations against the Security database.

🔗 参考:

90. CVE-2026-1728 `CVSS 9.8`

🎯 受影响:Tokens issued to a low-privileged user are not sufficiently restricted, allowing them to be used to

📋 简介:Tokens issued to a low-privileged user are not sufficiently restricted, allowing them to be used to access product-level Admin REST APIs.

🔗 参考:

91. CVE-2026-5134 `CVSS 9.8`

🎯 受影响:Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability i

📋 简介:Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Loca Software Informatics Technology Ltd.

🔗 参考:

92. CVE-2026-65552 `CVSS 9.8`

🎯 受影响:Subscriber PHP Object Injection in Export User Data <= 2.2.6 versions.

📋 简介:Subscriber PHP Object Injection in Export User Data <= 2.2.6 versions.

🔗 参考:

93. CVE-2026-71256 `CVSS 9.8`

🎯 受影响:nanoMODBUS through v1.23.0

📋 简介:nanoMODBUS through v1.23.0 contains an out-of-bounds stack read leading to a wild-pointer write in nmbs_read_device_identification_basic() / recv_read_device_identification_res() in nanomodbus.c.

🔗 参考:

94. CVE-2026-71267 `CVSS 9.8`

🎯 受影响:microtar's mtar_write_file_header() and mtar_write_dir_header() functions (src/microtar.c) copy a ca

📋 简介:microtar's mtar_write_file_header() and mtar_write_dir_header() functions (src/microtar.c) copy a caller-supplied entry name into the 100-byte `name` field of a stack-allocated mtar_header_t via strcpy(h.name, name), with no check that strlen(name) is less than 100 before the ...

🔗 参考:

95. CVE-2025-15039 `CVSS 9.4`

🎯 受影响:The Conditional Authentication (Adaptive Authentication) script does not correctly enforce the compl

📋 简介:The Conditional Authentication (Adaptive Authentication) script does not correctly enforce the completion of all required authentication steps when a specific multi-step pattern involving certain authenticators is configured.

🔗 参考:

96. CVE-2026-9195 `CVSS 9.3`

🎯 受影响:A cross-site scripting vulnerability in the Query Console of Progress MarkLogic Server

📋 简介:A cross-site scripting vulnerability in the Query Console of Progress MarkLogic Server before 11.3.6 and 12.0.3 allows a remote attacker who lures an authenticated administrator to a crafted URL to execute arbitrary JavaScript in the administrator's browser session, capture cr...

🔗 参考:

97. CVE-2026-43629 `CVSS 9.2`

🎯 受影响:llama.cpp builds b4882 through b9058

📋 简介:llama.cpp builds b4882 through b9058 contain a heap buffer overflow vulnerability in the KV cache state restore path where the state_read_data() function computes write size without overflow checking, allowing attackers with write access to the slot_save_path directory to corr...

🔗 参考:

98. CVE-2026-71238 `CVSS 9.1`

🎯 受影响:DjangoCRM ships with its Django SECRET_KEY hardcoded directly in the committed webcrm/settings.py ra

📋 简介:DjangoCRM ships with its Django SECRET_KEY hardcoded directly in the committed webcrm/settings.py rather than read from an environment variable.

🔗 参考:

99. CVE-2026-71277 `CVSS 9.1`

🎯 受影响:rust-iot-platform's AuthToken request-guard implementation (api/src/main.rs) only checks whether the

📋 简介:rust-iot-platform's AuthToken request-guard implementation (api/src/main.rs) only checks whether the Authorization HTTP header is present, and never validates its value against any session, token store, or signature.

🔗 参考:

100. CVE-2026-9190 `CVSS 9.1`

🎯 受影响:An HTTP request smuggling vulnerability in the HTTP App Server of Progress MarkLogic Server

📋 简介:An HTTP request smuggling vulnerability in the HTTP App Server of Progress MarkLogic Server before 11.3.6 and 12.0.3 allows a remote attacker to bypass authentication and authorization checks, hijack a legitimate user's session, or capture credentials.

🔗 参考:

🟠 HIGH · 8 条

1. CVE-2026-67621 `CVSS 7.6`

🎯 受影响:Flowise through 3.1.4

📋 简介:Flowise through 3.1.4 contains a missing authorization vulnerability that allows authenticated workspace members to perform unauthorized document store operations by accessing unprotected mutation endpoints.

🔗 参考:

2. CVE-2026-17556 `CVSS 8.8`

🎯 受影响:A path traversal vulnerability was identified in GitHub Enterprise Server that allowed an unauthenti

📋 简介:A path traversal vulnerability was identified in GitHub Enterprise Server that allowed an unauthenticated attacker to delete arbitrary files and directories on the instance, including the entire user storage directory containing Git LFS objects, release assets, attachments, an...

🔗 参考:

3. CVE-2026-70636 `CVSS 8.7`

🎯 受影响:Flowise through 3.1.4

📋 简介:Flowise through 3.1.4 contains an authentication bypass vulnerability that allows unauthenticated attackers to access the OAuth2 credential refresh endpoint by exploiting prefix-based whitelist matching in the authentication middleware defined in packages/server/src/utils/cons...

🔗 参考:

4. CVE-2026-20263 `CVSS 8.6`

🎯 受影响:A vulnerability in the Blocks Extensible Exchange Protocol (BEEP) feature of Cisco IOS XE Software c

📋 简介:A vulnerability in the Blocks Extensible Exchange Protocol (BEEP) feature of Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device.

🔗 参考:

5. CVE-2026-20301 `CVSS 8.6`

🎯 受影响:A vulnerability in the Extensible Messaging Client Protocol (XMCP), also referred to as the External

📋 简介:A vulnerability in the Extensible Messaging Client Protocol (XMCP), also referred to as the External Client protocol, of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected dev...

🔗 参考:

6. CVE-2026-71211 `CVSS 7.1`

🎯 受影响:MLflow's AI Gateway accepts an auth_config.api_base value when creating a gateway secret (mlflow/ser

📋 简介:MLflow's AI Gateway accepts an auth_config.api_base value when creating a gateway secret (mlflow/server/handlers.py, _create_gateway_secret) with no validation of scheme, host, or IP range; the value is stored verbatim.

🔗 参考:

7. CVE-2026-9081 `CVSS 7.1`

🎯 受影响:IBM Langflow OSS 1.0.0 through 1.10.3, and 1.0.0 through 1.10.3 contains a Server-Side Request Forge

📋 简介:IBM Langflow OSS 1.0.0 through 1.10.3, and 1.0.0 through 1.10.3 contains a Server-Side Request Forgery (SSRF) vulnerability in the validate_model_provider_key() function for the Ollama provider.

🔗 参考:

8. CVE-2026-65058 🔥 ⚡近期活跃 `CVSS 5.9`

🎯 受影响:Trezor Safe 3, Safe 5, and Safe 7 firmware contains a confirmation-binding flaw in the Ethereum sign

📋 简介:Trezor Safe 3, Safe 5, and Safe 7 firmware contains a confirmation-binding flaw in the Ethereum sign_tx / sign_tx_eip1559 flow.

🔗 参考:

---

新发现 341 条 · 热度升级 1 条 · 🔥=高热度/有 PoC · 🆙=昨日已推、今日热度升级

📊 GitHub 热榜

📊 GitHub 日榜 · 2026-08-07

1. TencentCloud/TencentDB-Agent-Memory

📋 TencentDB Agent Memory 是面向 AI Agent 的团队级记忆中枢,将对话、文档与代码转化为可治理、可共享的四类记忆资产(Chat Memory、Skill、LLM-Wiki、Code-Graph)。

2. addyosmani/agent-skills

📋 为 AI 编程代理打造的生产级工程技能。

3. cloudflare/computer

📋 给你的智能体一台电脑👾

4. mattpocock/skills

📋 面向真实工程师的技能,直接取自我的 .agents 目录。

5. goauthentik/authentik

📋 你需要的认证粘合剂。

6. huangruiteng/loopx

📋 面向长期运行 AI Agent 团队的轻量级循环工程状态内核,与 Codex、Claude Code 等 Agent 循环无关,支持持久目标、配额感知自动唤醒、可执行待办、证据日志与可验证交接。

7. google/guava

📋 Google Java 核心库。

8. TapXWorld/ChinaTextbook

📋 所有小初高、大学PDF教材。

9. Significant-Gravitas/AutoGPT

📋 AutoGPT 旨在让每个人都能使用并构建 AI,提供工具让你专注真正重要的事。

10. tirth8205/code-review-graph

📋 面向 MCP 和 CLI 的本地优先代码智能图,构建代码库持久地图,让 AI 编码工具只读取关键内容,在评审与大型仓库工作流中实现基准化的上下文缩减。

🤖 AI 总结分析

今日整体态势:高危漏洞预警单日收录 100 条 CRITICAL,其中 CVSS 10.0 级漏洞密集出现,未授权远程代码执行是绝对主线;安全情报侧出现多个高评分 PoC 公开与 CISA 在野利用预警;GitHub 热榜则被 AI Agent 基础设施项目主导,安全与 AI 的交汇特征愈发明显。

漏洞预警方面,最需关注 CVE-2026-21858(n8n,CVSS 10.0):作为广泛使用的开源自动化平台,其未认证 RCE 漏洞已标记“近期活跃”并附带公开利用链,直接威胁大量线上工作流实例。另一项 CVE-2026-63077(JetBrains TeamCity,CVSS 9.8)同样值得警惕,Agent 轮询协议导致的未认证 RCE 已被列入 CISA KEV,属于可被快速武器化的目标。此外,Flowise 的 IDOR 与 llama.cpp 的释放后使用漏洞,也反映出 AI/LLM 工具链正成为攻击者集中研究的对象。

安全情报侧,Linux 内核 OVS 组件潜伏 13 年的本地提权漏洞曝光,普通用户可秒变 Root,影响面涉及大量服务器,尽管利用前提是本地访问,但修复优先级不应低估。CISA 紧急预警中,Langflow RCETomcat 加密绕过已确认在野利用,且多个 CVSS 9.8-10.0 的 PoC(如 CVE-2026-64633、CVE-2026-0163)同日公开,说明攻击者正加速将漏洞转化为实战工具。

GitHub 热榜呈现鲜明的 AI 工程化转向:TencentDB-Agent-Memory 为 Agent 提供团队级记忆中枢,agent-skillscloudflare/computer 则聚焦代理的工程技能与运行环境,这些项目暗示行业正从“训练模型”转向“让 Agent 稳定干活”;而 authentik 等认证组件的上榜,或也呼应了 AI 应用安全加固的需求。

行动建议:今天应优先排查暴露在公网的 n8n 实例,确认是否落在受影响版本区间,立即升级并限制管理端口访问——这是当前唯一兼具 CVSS 满分、活跃利用标识与公开 PoC 的高危目标。