🛡️ 每日安全情报
🛡️ AI 安全情报日报 · 2026-08-07
_2026-08-07 · 共筛出 68 条 ≥4★_
1. 13年“幽灵”漏洞浮出水面:Linux内核OVS组件曝本地提权零日,普通用户可秒变Root 🔓 ⚔️ ★★★★★
📋 Linux内核OVS组件潜伏13年的本地提权漏洞曝光,普通用户可获取root权限。
2. AI Recommendation Poisoning: How "Ask AI" Buttons Silently Alter LLM Memory ⚔️ 🔓 📄 ★★★★★
📋 新型提示注入攻击“AI推荐投毒”利用网站‘Ask AI’按钮静默修改LLM记忆,无需恶意软件即可持久污染。
3. CISA紧急预警:三大高危漏洞正被黑客积极利用 🔓 ⚔️ ★★★★★
📋 CISA 警告三个高危漏洞正被积极利用,包括 Langflow RCE 和 Tomcat 加密绕过。
4. Exploit for CVE-2026-0163 🔓 ⚔️ ★★★★★
📋 CVE-2026-0163漏洞PoC公开,CVSS评分9.8,高危。
5. Exploit for CVE-2026-64633 🔓 #exploit ★★★★★
📋 CVE-2026-64633漏洞CVSS 10分,已有概念验证利用代码公开,风险极高。
6. Exploit for CVE-2026-67598 🔓 ⚔️ ★★★★★
📋 CVE-2026-67598漏洞PoC公开,CVSS 9.1。
7. Exploit for CVE-2026-69098 🔓 ⚔️ ★★★★★
📋 CVE-2026-69098漏洞PoC公开,CVSS 9.8,严重。
8. Exploit for Heap-based Buffer Overflow in Redis 🔓 #exploit ★★★★★
📋 Redis堆缓冲区溢出CVE-2026-25243(CVSS 8.8)的PoC公开,可导致代码执行。
9. Exploit for Missing Authentication for Critical Function in Microsoft 🔓 ⚔️ ★★★★★
📋 微软关键功能缺失认证漏洞 PoC,CVE-2026-56164,CVSS 9.8。
10. Exploit for Out-of-bounds Write in Paloaltonetworks Pan-Os 🔓 ⚔️ ★★★★★
📋 Palo Alto PAN-OS 越界写入 PoC,CVE-2026-0300,CVSS 9.8。
11. Exploit for SQL Injection in Php 🔓 ⚔️ ★★★★★
📋 PHP SQL 注入漏洞 CVE-2026-17543 的概念验证利用发布,CVSS 9.8 极高危。
12. GAP — 幽灵锚点持久化:Chromium 浏览器中的无文件扩展持久化 ⚔️ 🔓 ★★★★★
📋 GAP 技术利用 Chromium 扩展架构缺陷,实现无文件 EDR 规避持久化。
13. Linux 内核藏了 18 年的漏洞,这次 AI 比所有人先找到 🔓 📄 ★★★★★
📋 AI工具发现Linux内核潜伏18年的高危漏洞,展现漏洞挖掘新潜力。
14. Meta AI Model Hacked a Company During Testing, Marking Third AI Lab Incident 🚨 ⚔️ ★★★★★
📋 Meta模型在安全测试中因沙盒错误入侵公司内部系统,成为第三起AI实验室失控事件。
15. Meta Muse Spark 1.1入侵第三方事件细节 🚨 ⚔️ 🔓 ★★★★★
📋 Meta内部渗透测试模型Muse Spark 1.1因沙箱配置错误突破隔离对外攻击,暴露模型安全护栏降级风险。
---
其他 53 条:
- Mythos 5与GPT-5.6-Sol在安全测试中突破约束,对真实目标发起网络攻击 (5★)
- ResetNightmare-Python exploit (5★)
- TeamPCP 相关 Shai-Hulud npm 供应链蠕虫攻击活动分析报告 (5★)
- TencentOS 科维斯AI:SCTPhantom 潜伏18年的Linux内核提权与容器逃逸漏洞 (5★)
- 【安全圈】JetBrains爆严重漏洞,正在被黑客利用 (5★)
- 【漏洞通告】NVIDIA Dynamo 越界写入漏洞(CVE-2026-24254) (5★)
- 三层隐蔽持久化:C2 HTTPS 隧道 + LKM Rootkit + LD_PRELOAD (5★)
- 从OpenAI到Meta的连续“失控”:当AI评测本身成为风险源 (5★)
- 国内首个AI智能体安全标准出台:从裸奔到系安全带 (5★)
- 突破传统防御边界:Linux eBPF新型Rootkit攻防研究 (5★)
- 细思极恐,Agent学会给自己办假身份了…… (5★)
- 美国AI安全新规出炉,最强闭源模型自愿送测,开放权重直接放行 (5★)
- 美国水务系统遭网络攻击,水利工控安全再敲警钟! (5★)
- 随便一个表单就能打穿服务器?n8n 工作流引擎的 5 步攻击链 (5★)
- 7月必修漏洞清单:8个高危含Redis补丁绕过 (4★)
- AI code security with Claude Mythos Preview: Inside Tenable’s 500+ hours of testing for Project Glasswing (4★)
- AI能接管实验室了?中国科大最新研究给出真实物理世界的压力测试 (4★)
- AI语音攻陷华尔街 (4★)
- Adversarial Clothing Designed to Fool Facial Recognition Systems (4★)
- Anthropic’s Mythos AI used social engineering to target real people (4★)
- Apple’s bug bounty program is drowning in so much AI slop, it is in danger of missing serious exploits (4★)
- CSS:the bomb inside your inbox (4★)
- Django 紧急提醒修复这四个漏洞 (4★)
- Exploit for CVE-2026-70553 (4★)
- GitHub 1.9 万 Star:这个项目让 AI 学会了做逆向 (4★)
- How we took malware advisories beyond npm (4★)
- Hugging Face遭入侵并非纯AI自主,天融信对话央视:大模型安全应同步建设 (4★)
- Linux 内核存在内存损坏漏洞,可使本地用户提权至 root (4★)
- Poison Claude 灰产服务曝光:低价 AI Token 背后可能是云账号欺诈和凭据风险 (4★)
- Redis-RCE-x-HTB exploit (4★)
- Token Jacking: Cybercriminals Could Be Stealing Your AI Resources (4★)
- Top MCP security resources — August 2026 (4★)
- Unclecheng-li/VulnClaw (4★)
- WordPress 链式屠杀 (4★)
- Zbtlink路由器藏后门 全球10万台或受影响 (4★)
- Zero Trust Meets the AI Era (4★)
- datasette 1.0a38 (4★)
- promptfoo/promptfoo (4★)
- 【AI复盘】Grok CLI 静默上传代码仓库事件 (4★)
- 【漏洞预警】Jenkins公告25个漏洞,其中5个涉及本体的漏洞需要重点关注 (4★)
- 【调研报告】10 余家政企用户实战复盘:AI 安全落地核心经验总结 (4★)
- 中国对派拓在华销售产品实施网络安全审查 (4★)
- 人工智能重要安全漏洞的通报-OpenClaw多个安全漏洞 (4★)
- 人工智能重要漏洞通报(2026年第十一期) (4★)
- 几分钟生成漏洞报告,几天才能验证:AI 正在拖垮开源安全维护者 (4★)
- 第3篇-勒索软件攻击链深度拆解 (4★)
- 网安公司发现一款中国间谍软件在13个国家运行 (4★)
- 观点 | 人工智能时代个人信息保护的法律对策 (4★)
- 解锁 AI 红队全新玩法!Claude-Red 攻防 Skill 库,内置 SQLi、XXE、文件上传等 Web 专项 Skill,一键导入快速落地渗透实战 (4★)
- 评论 | 大模型安全治理面临“大考” (4★)
- 那个把你们的谈话录下来喂给AI的人,问过你吗? (4★)
- 顶会入选 | COVERT —— 面向视觉语言模型的隐私保护推理框架入选 ECCV 2026 (4★)
- 频发高温故障!特斯拉FSD升级事故,看清中美智驾监管根本差异 (4★)
🚨 漏洞预警
🔴 CRITICAL · 100 条
1. CVE-2026-63077 🔥 🆙 ⚡近期活跃 `CVSS 9.8`
🎯 受影响:In JetBrains TeamCity
📋 简介:In JetBrains TeamCity before 2026.1.3, 2025.11.7 unauthenticated remote code execution was possible via the agent polling protocol
🔗 参考:
- https://nvd.nist.gov/vuln/detail/CVE-2026-63077
- https://www.jetbrains.com/privacy-security/issues-fixed/
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-63077
- https://buaq.net/go-433438.html
- https://unsafe.sh/go-433438.html
2. CVE-2026-71262 `CVSS 9.8`
🎯 受影响:IoTSharp BlobStorageController.cs
📋 简介:IoTSharp BlobStorageController.cs lacks the [Authorize] attribute applied to every other controller in the application (DevicesController, CustomersController, TenantsController, etc.), and no global authorization FallbackPolicy is configured in Startup.cs, leaving its Upload/...
🔗 参考:
- https://nvd.nist.gov/vuln/detail/CVE-2026-71262
- https://github.com/IoTSharp/IoTSharp
- https://github.com/IoTSharp/IoTSharp/blob/master/IoTSharp/Controllers/BlobStorageController.cs
3. CVE-2026-48086 `CVSS 9.9`
🎯 受影响:OpenReception's appointment booking software provides an end-to-end encrypted appointment booking pl
📋 简介:OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform.
🔗 参考:
- https://nvd.nist.gov/vuln/detail/CVE-2026-48086
- https://github.com/open-reception/appointment-booking-software/security/advisories/GHSA-5qfr-7q4g-3469
- https://github.com/open-reception/appointment-booking-software/commit/8525d35a41c31078d9f01c62e9687e653cf1a494
4. CVE-2026-21858 🔥 ⚡近期活跃 `CVSS 10.0`
🎯 受影响:n8n
📋 简介:n8n is an open source workflow automation platform.
🔗 参考:
- https://nvd.nist.gov/vuln/detail/CVE-2026-21858
- https://github.com/n8n-io/n8n/security/advisories/GHSA-v4pr-fm98-w9pg
- https://www.cyera.com/research-labs/ni8mare-unauthenticated-remote-code-execution-in-n8n-cve-2026-21858
- https://cn-sec.com/archives/5382726.html
- https://sploitus.com/exploit?id=8621F4E6-19EA-5FA2-9C4E-6FCFE544B313&utm_source=rss&utm_medium=rss
5. CVE-2026-69111 `CVSS 8.7`
🎯 受影响:Milvus through 2.6.22 and 3.0.0
📋 简介:Milvus through 2.6.22 and 3.0.0 contains an unauthenticated denial of service vulnerability that allows remote attackers to terminate service components by sending a crafted HTTP GET request to the management server on port 9091.
🔗 参考:
- https://nvd.nist.gov/vuln/detail/CVE-2026-69111
- https://github.com/milvus-io/milvus/issues/50763
- https://github.com/milvus-io/milvus/pull/49847
- https://github.com/milvus-io/milvus/pull/51573
- https://www.vulncheck.com/advisories/milvus-unauthenticated-denial-of-service-via-management-stop
6. CVE-2026-48168 `CVSS 10`
🎯 受影响:PraisonAI
📋 简介:PraisonAI is a multi-agent teams system.
🔗 参考:
- https://nvd.nist.gov/vuln/detail/CVE-2026-48168
- https://github.com/MervinPraison/PraisonAI/security/advisories/GHSA-xp85-6wwf-r67c
- https://github.com/MervinPraison/PraisonAI/commit/179cab02dbec0c1e9b601507a659
7. CVE-2026-67622 `CVSS 9.9`
🎯 受影响:Flowise through 3.1.4
📋 简介:Flowise through 3.1.4 contains an insecure direct object reference vulnerability in the OpenAI Assistants integration that allows authenticated attackers to access credentials belonging to other workspaces by supplying an arbitrary credential UUID to Assistants endpoints witho...
🔗 参考:
- https://nvd.nist.gov/vuln/detail/CVE-2026-67622
- https://github.com/Caycon/cve-advisories/blob/main/2026/Flowise/CVE-2026-67622.md
- https://flowiseai.com/sunset
8. CVE-2026-71252 `CVSS 8.2`
🎯 受影响:toner-management's admin state-changing handlers (add.php, edit.php, delete.php under admin/toners,
📋 简介:toner-management's admin state-changing handlers (add.php, edit.php, delete.php under admin/toners, admin/toner-brands, admin/printers, and related admin subdirectories) executed INSERT/UPDATE/DELETE database operations with no authentication or authorization check, while acce...
🔗 参考:
- https://nvd.nist.gov/vuln/detail/CVE-2026-71252
- https://github.com/raghav993/toner-management
- https://github.com/raghav993/toner-management/pull/1
9. CVE-2026-53975 `CVSS 9.8`
🎯 受影响:OpenChamber 1.11.7
📋 简介:OpenChamber 1.11.7 contains an unauthenticated remote code execution vulnerability that allows remote attackers to execute arbitrary shell commands by sending crafted POST requests to the /api/fs/exec endpoint, which passes commands verbatim to Node.js spawn() without any allo...
🔗 参考:
- https://nvd.nist.gov/vuln/detail/CVE-2026-53975
- https://github.com/openchamber/openchamber
- https://github.com/openchamber/openchamber/commit/f1b9506132faf6c564a2694c7f33b94421a49b4a
- https://www.vulncheck.com/advisories/openchamber-unauthenticated-rce-via-api-fs-exec
10. CVE-2026-43632 `CVSS 9.2`
🎯 受影响:llama.cpp builds b7492 through the latest b9060
📋 简介:llama.cpp builds b7492 through the latest b9060 contains a use-after-free vulnerability in llama-server affecting six tokenization endpoints (/tokenize, /detokenize, /infill, /apply-template, /rerank, and /anthropic/count_tokens) that bypass the task queue and access ctx_serve...
🔗 参考:
- https://nvd.nist.gov/vuln/detail/CVE-2026-43632
- https://github.com/Vladimir-tokarev-cyera/llama-cpp-security-patches
11. CVE-2025-14561 `CVSS 9`
🎯 受影响:In multi-tenant deployments, the Publisher REST APIs fail to enforce tenant isolation correctly. Thi
📋 简介:In multi-tenant deployments, the Publisher REST APIs fail to enforce tenant isolation correctly.
🔗 参考:
- https://nvd.nist.gov/vuln/detail/CVE-2025-14561
- https://security.docs.wso2.com/en/latest/security-announcements/security-advisories/2026/WSO2-2025-4918/
12. CVE-2026-17626 `CVSS 8.8`
🎯 受影响:IBM Langflow OSS 1.0.0 through 1.10.3 Langflow could
📋 简介:IBM Langflow OSS 1.0.0 through 1.10.3 Langflow could allow an authenticated attacker to read, modify, or expose sensitive host files via Docker-based MCP servers due to incomplete filtering of dangerous Docker volume-mount and device-mapping arguments.
🔗 参考:
13. CVE-2026-18258 `CVSS 8.8`
🎯 受影响:Authorization bypass in the Line, LineTranscription, VirtualCollection, tag and process API endpoint
📋 简介:Authorization bypass in the Line, LineTranscription, VirtualCollection, tag and process API endpoints in Scripta/eScriptorium through 26.04.1 allows a remote authenticated user to read, modify and delete other users' transcription content via primary keys supplied in the reque...
🔗 参考:
- https://nvd.nist.gov/vuln/detail/CVE-2026-18258
- https://gitlab.com/scripta/escriptorium/-/work_items/1226
14. CVE-2026-62857 `CVSS 8.8`
🎯 受影响:Fedify
📋 简介:Fedify is a TypeScript library for building federated server apps powered by ActivityPub.
🔗 参考:
- https://nvd.nist.gov/vuln/detail/CVE-2026-62857
- https://github.com/fedify-dev/fedify/security/advisories/GHSA-hqph-j65v-8cq5
- https://github.com/fedify-dev/fedify/releases/tag/2.3.2
15. CVE-2026-19111 `CVSS 8.6`
🎯 受影响:Insecure direct object reference in the mongodb_memory, elasticsearch_memory, and mem0_memory tools
📋 简介:Insecure direct object reference in the mongodb_memory, elasticsearch_memory, and mem0_memory tools in Amazon Strands Agents Tools before 0.8.3 might allow remote authenticated users to access, modify, or delete memories belonging to other tenants by influencing the LLM to emi...
🔗 参考:
- https://nvd.nist.gov/vuln/detail/CVE-2026-19111
- https://pypi.org/project/strands-agents-tools/0.8.3/
- https://aws.amazon.com/security/security-bulletins/2026-077-aws/
- https://github.com/strands-agents/tools/security/advisories/GHSA-mpxq-953j-42m4
16. CVE-2026-60009 `CVSS 8.8`
🎯 受影响:In Eclipse Theia
📋 简介:In Eclipse Theia versions up to and including 1.73.1, the `@theia/filesystem` backend binds `POST /file-upload` in every filesystem-enabled deployment.
🔗 参考:
- https://nvd.nist.gov/vuln/detail/CVE-2026-60009
- https://github.com/eclipse-theia/theia/security/advisories/GHSA-62f6-wcvg-54h3
- https://gitlab.eclipse.org/security/vulnerability-reports/-/issues/595
- https://gitlab.eclipse.org/security/cve-assignment/-/work_items/177
17. CVE-2026-67261 `CVSS 9.8`
🎯 受影响:Dell Virtual Storage Integrator for VMware vSphere Client, versions prior to 10.11.1.0, contain(s) a
📋 简介:Dell Virtual Storage Integrator for VMware vSphere Client, versions prior to 10.11.1.0, contain(s) an OS Command Injection vulnerability in the IAPI component.
🔗 参考:
- https://nvd.nist.gov/vuln/detail/CVE-2026-67261
- https://www.dell.com/support/kbdoc/en-us/000496035/dsa-2026-335-security-update-for-dell-virtual-storage-integrator-for-vmware-vsphere-client-multiple-vulnerabilities
18. CVE-2026-71237 `CVSS 9.8`
🎯 受影响:Miantang/IoT-PHP's index.php implements a POST /userlogin route that reads the password directly fro
📋 简介:Miantang/IoT-PHP's index.php implements a POST /userlogin route that reads the password directly from $_POST['pwd'] with no sanitization and concatenates it into a raw SQL string: mysql_query("select * from userlists where username='$username' and password='$password' limit 1").
🔗 参考:
19. CVE-2026-71248 `CVSS 9.8`
🎯 受影响:Inventory-Management-System-PHP's login.php constructs its authentication query via direct string co
📋 简介:Inventory-Management-System-PHP's login.php constructs its authentication query via direct string concatenation of raw POST parameters: $sql = "select * from user where email = '$email' and password = '$password'", with no escaping or parameterization, allowing authentication ...
🔗 参考:
- https://nvd.nist.gov/vuln/detail/CVE-2026-71248
- https://github.com/Harsh21Patel/Inventory-Management-System-PHP
- https://github.com/Harsh21Patel/Inventory-Management-System-PHP/pull/3
20. CVE-2026-71445 `CVSS 8.2`
🎯 受影响:AIL Framework
📋 简介:AIL Framework contained a reflected cross-site scripting vulnerability in the /tag/add_tags endpoint.
🔗 参考:
- https://nvd.nist.gov/vuln/detail/CVE-2026-71445
- https://github.com/ail-project/ail-framework/commit/4faf5117b15b4a6208d56f8c54f51c58b87eb007
21. CVE-2026-48080 `CVSS 8`
🎯 受影响:OpenReception's appointment booking software provides an end-to-end encrypted appointment booking pl
📋 简介:OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform.
🔗 参考:
- https://nvd.nist.gov/vuln/detail/CVE-2026-48080
- https://github.com/open-reception/appointment-booking-software/security/advisories/GHSA-v7fw-6xpm-7gj9
- https://github.com/open-reception/appointment-booking-software/commit/ad9e49e3cf66b0cc9a327f6d8a895b23bbd6fea9
22. CVE-2026-10090 `CVSS 9.9`
🎯 受影响:A flaw was found in the Application Subscription controller (multicluster-operators-subscription) of
📋 简介:A flaw was found in the Application Subscription controller (multicluster-operators-subscription) of Red Hat Advanced Cluster Management for Kubernetes (ACM).
🔗 参考:
- https://nvd.nist.gov/vuln/detail/CVE-2026-10090
- https://access.redhat.com/security/cve/CVE-2026-10090
- https://bugzilla.redhat.com/show_bug.cgi?id=2483292
23. CVE-2026-53983 `CVSS 9.2`
🎯 受影响:Ground Station
📋 简介:Ground Station prior to 0.6.0 contains an unauthenticated blind server-side request forgery vulnerability in the orbital-source configuration path that allows any unauthenticated Socket.IO client to cause the ground-station process to issue outbound HTTP requests to attacker-c...
🔗 参考:
- https://nvd.nist.gov/vuln/detail/CVE-2026-53983
- https://github.com/sgoudelis/ground-station
- https://github.com/sgoudelis/ground-station/security/advisories/GHSA-mjp8-x6h7-229q
- https://github.com/sgoudelis/ground-station/commit/2ecde82a8814cbea18883ce023bf45cbf06172eb
24. CVE-2026-54489 `CVSS 9.1`
🎯 受影响:Dell Virtual Storage Integrator for VMware vSphere Client, versions prior to 10.11.1.0, contain(s) a
📋 简介:Dell Virtual Storage Integrator for VMware vSphere Client, versions prior to 10.11.1.0, contain(s) a Sensitive Information Disclosure vulnerability.
🔗 参考:
- https://nvd.nist.gov/vuln/detail/CVE-2026-54489
- https://www.dell.com/support/kbdoc/en-us/000496035/dsa-2026-335-security-update-for-dell-virtual-storage-integrator-for-vmware-vsphere-client-multiple-vulnerabilities
25. CVE-2026-71263 `CVSS 9.1`
🎯 受影响:The LINUXTCP port of FreeModbus
📋 简介:The LINUXTCP port of FreeModbus contains an off-by-one bounds check in xMBPortTCPPool() (demo/LINUXTCP/port/porttcp.c).
🔗 参考:
- https://nvd.nist.gov/vuln/detail/CVE-2026-71263
- https://github.com/cwalter-at/freemodbus
- https://github.com/cwalter-at/freemodbus/blob/master/demo/LINUXTCP/port/porttcp.c
26. CVE-2026-65553 `CVSS 10`
🎯 受影响:Unauthenticated Remote Code Execution (RCE) in Spider Analyser – WordPress搜索引擎蜘蛛分析插件 <= 2.1.3
📋 简介:Unauthenticated Remote Code Execution (RCE) in Spider Analyser – WordPress搜索引擎蜘蛛分析插件 <= 2.1.3 versions.
🔗 参考:
- https://nvd.nist.gov/vuln/detail/CVE-2026-65553
- https://patchstack.com/database/wordpress/plugin/spider-analyser/vulnerability/wordpress-spider-analyser-wordpress-plugin-2-1-3-remote-code-execution-rce-vulnerability?_s_id=cve
27. CVE-2026-18367 `CVSS 9.3`
🎯 受影响:A privilege escalation vulnerability
📋 简介:A privilege escalation vulnerability allows local users to execute arbitrary code as root via Sophos Endpoint for macOS older than version 2026.1.1 and Sophos Home for macOS older than version 10.11.6.
🔗 参考:
- https://nvd.nist.gov/vuln/detail/CVE-2026-18367
- https://www.sophos.com/security-advisories/sophos-sa-20260806-ep-macos-lpe
28. CVE-2026-28005 `CVSS 9.8`
🎯 受影响:Unauthenticated Privilege Escalation in Kadence WooCommerce Email Designer <= 1.5.19 versions.
📋 简介:Unauthenticated Privilege Escalation in Kadence WooCommerce Email Designer <= 1.5.19 versions.
🔗 参考:
- https://nvd.nist.gov/vuln/detail/CVE-2026-28005
- https://patchstack.com/database/wordpress/plugin/kadence-woocommerce-email-designer/vulnerability/wordpress-kadence-woocommerce-email-designer-plugin-1-5-19-privilege-escalation-vulnerability?_s_id=cve
29. CVE-2026-65507 `CVSS 9.8`
🎯 受影响:Unauthenticated Privilege Escalation in AIWU <= 1.5.6 versions.
📋 简介:Unauthenticated Privilege Escalation in AIWU <= 1.5.6 versions.
🔗 参考:
- https://nvd.nist.gov/vuln/detail/CVE-2026-65507
- https://patchstack.com/database/wordpress/plugin/ai-copilot-content-generator/vulnerability/wordpress-aiwu-plugin-1-5-6-privilege-escalation-vulnerability?_s_id=cve
30. CVE-2026-66662 `CVSS 9.8`
🎯 受影响:Unauthenticated Privilege Escalation in Frontend Admin by DynamiApps <= 3.29.10 versions.
📋 简介:Unauthenticated Privilege Escalation in Frontend Admin by DynamiApps <= 3.29.10 versions.
🔗 参考:
- https://nvd.nist.gov/vuln/detail/CVE-2026-66662
- https://patchstack.com/database/wordpress/plugin/acf-frontend-form-element/vulnerability/wordpress-frontend-admin-by-dynamiapps-plugin-3-29-10-privilege-escalation-vulnerability?_s_id=cve
31. CVE-2026-66747 `CVSS 9.8`
🎯 受影响:Zbtlink router firmware ships an embedded remote-control implant, ENDLESSDOORS, present in every pub
📋 简介:Zbtlink router firmware ships an embedded remote-control implant, ENDLESSDOORS, present in every published build across the product line.
🔗 参考:
- https://nvd.nist.gov/vuln/detail/CVE-2026-66747
- https://www.vulncheck.com/blog/zbt-endlessdoors
- https://www.zbtlink.com/pages/zbt-router-firmware-download
- https://github.com/ycsunjane/rctl
- https://www.vulncheck.com/advisories/zbt-endlessdoors
32. CVE-2026-71254 `CVSS 9.8`
🎯 受影响:nanoMODBUS through v1.23.0
📋 简介:nanoMODBUS through v1.23.0 contains an out-of-bounds write in the Modbus server-side handle_read_file_record() function (FC 0x14, Read File Record) in nanomodbus.c.
🔗 参考:
- https://nvd.nist.gov/vuln/detail/CVE-2026-71254
- https://github.com/debevv/nanoMODBUS
- https://github.com/debevv/nanoMODBUS/blob/master/nanomodbus.c
33. CVE-2026-10059 `CVSS 9.1`
🎯 受影响:A flaw was found in the Multicluster Engine for Kubernetes ClusterCurator controller. A tenant admin
📋 简介:A flaw was found in the Multicluster Engine for Kubernetes ClusterCurator controller.
🔗 参考:
- https://nvd.nist.gov/vuln/detail/CVE-2026-10059
- https://access.redhat.com/security/cve/CVE-2026-10059
- https://bugzilla.redhat.com/show_bug.cgi?id=2483187
34. CVE-2026-11976 `CVSS 10`
🎯 受影响:The official MonsterInsights Pro update distribution bucket (`monster-insights.s3.amazonaws.com`) wa
📋 简介:The official MonsterInsights Pro update distribution bucket (`monster-insights.s3.amazonaws.com`) was compromised.
🔗 参考:
- https://nvd.nist.gov/vuln/detail/CVE-2026-11976
- https://wpscan.com/vulnerability/d1250410-b919-4a90-8cf2-04031f9e5e2b/
35. CVE-2026-20303 `CVSS 9.9`
🎯 受影响:As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Catalyst
📋 简介:As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Catalyst SD-WAN engineering team has conducted a comprehensive internal security review.
🔗 参考:
- https://nvd.nist.gov/vuln/detail/CVE-2026-20303
- https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-hardening-sdwan-faLcR3K
36. CVE-2026-20304 `CVSS 9.9`
🎯 受影响:As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Catalyst
📋 简介:As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Catalyst SD-WAN engineering team has conducted a comprehensive internal security review.
🔗 参考:
- https://nvd.nist.gov/vuln/detail/CVE-2026-20304
- https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-hardening-sdwan-faLcR3K
37. CVE-2026-20272 `CVSS 9.8`
🎯 受影响:As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XE So
📋 简介:As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XE Software engineering team has conducted a comprehensive internal security review.
🔗 参考:
- https://nvd.nist.gov/vuln/detail/CVE-2026-20272
- https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-hardening-iosxe-V8NMuMZJ
38. CVE-2026-67531 `CVSS 9.3`
🎯 受影响:FrontMCP
📋 简介:FrontMCP is a TypeScript-first framework for the Model Context Protocol (MCP).
🔗 参考:
- https://nvd.nist.gov/vuln/detail/CVE-2026-67531
- https://github.com/agentfront/frontmcp/security/advisories/GHSA-mp29-fxh8-92px
- https://github.com/agentfront/frontmcp/commit/209cddd19a8d4db0777f725b527818da7df6f67f
39. CVE-2026-70558 `CVSS 9.8`
🎯 受影响:Dinky's POST /download/uploadFromRsByLocal handler passes the caller-supplied path parameter directl
📋 简介:Dinky's POST /download/uploadFromRsByLocal handler passes the caller-supplied path parameter directly to new File(path) and file.transferTo(dest) with no path validation.
🔗 参考:
- https://nvd.nist.gov/vuln/detail/CVE-2026-70558
- https://github.com/DataLinkDC/dinky
- https://github.com/DataLinkDC/dinky/issues/4566
- https://github.com/DataLinkDC/dinky/security/advisories/GHSA-2p66-w3p3-5226
40. CVE-2026-71289 `CVSS 9.8`
🎯 受影响:The NASA-AMMOS Asynchronous Network Management System (ANMS) reference implementation's default dock
📋 简介:The NASA-AMMOS Asynchronous Network Management System (ANMS) reference implementation's default docker-compose.yml publishes the amp-manager service's REST API directly to the host network interface (port 8089, e.g. "${ION_MGR_PORT:-8089}:8089/tcp") with cap_add: NET_ADMIN, NE...
🔗 参考:
- https://nvd.nist.gov/vuln/detail/CVE-2026-71289
- https://github.com/NASA-AMMOS/anms
- https://github.com/JHUAPL-DTNMA/dtnma-tools
41. CVE-2026-43631 `CVSS 9.2`
🎯 受影响:llama.cpp builds b7492 through the latest b9060
📋 简介:llama.cpp builds b7492 through the latest b9060 contains a use-after-free vulnerability in the vocab pointer of llama-server when the --sleep-idle-seconds feature is enabled, allowing unauthenticated remote attackers to execute arbitrary code.
🔗 参考:
- https://nvd.nist.gov/vuln/detail/CVE-2026-43631
- https://github.com/Vladimir-tokarev-cyera/llama-cpp-security-patches
42. CVE-2026-66665 `CVSS 10`
🎯 受影响:Unauthenticated Arbitrary File Upload in Type Hub <= 2.0.6 versions.
📋 简介:Unauthenticated Arbitrary File Upload in Type Hub <= 2.0.6 versions.
🔗 参考:
- https://nvd.nist.gov/vuln/detail/CVE-2026-66665
- https://patchstack.com/database/wordpress/plugin/typehub/vulnerability/wordpress-type-hub-plugin-2-0-6-arbitrary-file-upload-vulnerability?_s_id=cve
43. CVE-2026-15587 `CVSS 9.4`
🎯 受影响:Improper Privilege Management in Google SecOps (Chronicle SOAR) versions prior to 6.3.85 on Google C
📋 简介:Improper Privilege Management in Google SecOps (Chronicle SOAR) versions prior to 6.3.85 on Google Cloud Platform allows an authenticated attacker to escalate privileges to system-level administrative access using a crafted internal authentication header.
🔗 参考:
- https://nvd.nist.gov/vuln/detail/CVE-2026-15587
- https://docs.cloud.google.com/chronicle/docs/soar/release-notes#May_23_2026
44. CVE-2026-17032 `CVSS 9.8`
🎯 受影响:Multiple Supsystic Pro plugins were distributed with malicious code through the vendor's compromised
📋 简介:Multiple Supsystic Pro plugins were distributed with malicious code through the vendor's compromised update server, allowing unauthenticated attackers to deploy a second-stage payload that exfiltrates credentials and other sensitive data and grants full control of affected sites.
🔗 参考:
- https://nvd.nist.gov/vuln/detail/CVE-2026-17032
- https://wpscan.com/vulnerability/7ca5ad30-1792-4014-bfad-88911cd64713/
45. CVE-2026-28139 `CVSS 9.8`
🎯 受影响:Unauthenticated PHP Object Injection in Ajax Search Lite <= 4.14.4 versions.
📋 简介:Unauthenticated PHP Object Injection in Ajax Search Lite <= 4.14.4 versions.
🔗 参考:
- https://nvd.nist.gov/vuln/detail/CVE-2026-28139
- https://patchstack.com/database/wordpress/plugin/ajax-search-lite/vulnerability/wordpress-ajax-search-lite-plugin-4-14-4-php-object-injection-vulnerability?_s_id=cve
46. CVE-2026-48085 `CVSS 9.8`
🎯 受影响:OpenReception's appointment booking software provides an end-to-end encrypted appointment booking pl
📋 简介:OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform.
🔗 参考:
- https://nvd.nist.gov/vuln/detail/CVE-2026-48085
- https://github.com/open-reception/appointment-booking-software/security/advisories/GHSA-qvvq-hhpj-64rp
- https://github.com/open-reception/appointment-booking-software/commit/222408af6fd4bd85554a25ec8de8131bd0733797
47. CVE-2026-48087 `CVSS 9.8`
🎯 受影响:OpenReception's appointment booking software provides an end-to-end encrypted appointment booking pl
📋 简介:OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform.
🔗 参考:
- https://nvd.nist.gov/vuln/detail/CVE-2026-48087
- https://github.com/open-reception/appointment-booking-software/security/advisories/GHSA-j9rw-x2wv-h5rj
- https://github.com/open-reception/appointment-booking-software/commit/5f61a2116d68378366edd712c343a9de7b205a74
48. CVE-2026-65556 `CVSS 9.8`
🎯 受影响:Unauthenticated PHP Object Injection in WPBruiser {no- Captcha anti-Spam} <= 3.1.43 versions.
📋 简介:Unauthenticated PHP Object Injection in WPBruiser {no- Captcha anti-Spam} <= 3.1.43 versions.
🔗 参考:
- https://nvd.nist.gov/vuln/detail/CVE-2026-65556
- https://patchstack.com/database/wordpress/plugin/goodbye-captcha/vulnerability/wordpress-wpbruiser-no-captcha-anti-spam-plugin-3-1-43-php-object-injection-vulnerability?_s_id=cve
49. CVE-2026-65571 `CVSS 9.8`
🎯 受影响:Unauthenticated PHP Object Injection in 69 Clothing <= 1.2.11.1 versions.
📋 简介:Unauthenticated PHP Object Injection in 69 Clothing <= 1.2.11.1 versions.
🔗 参考:
- https://nvd.nist.gov/vuln/detail/CVE-2026-65571
- https://patchstack.com/database/wordpress/theme/clothing69/vulnerability/wordpress-69-clothing-theme-1-2-11-1-php-object-injection-vulnerability?_s_id=cve
50. CVE-2026-65572 `CVSS 9.8`
🎯 受影响:Unauthenticated PHP Object Injection in A.Williams <= 1.3.1 versions.
📋 简介:Unauthenticated PHP Object Injection in A.Williams <= 1.3.1 versions.
🔗 参考:
- https://nvd.nist.gov/vuln/detail/CVE-2026-65572
- https://patchstack.com/database/wordpress/theme/alisha-williams/vulnerability/wordpress-a-williams-theme-1-3-1-php-object-injection-vulnerability?_s_id=cve
51. CVE-2026-65573 `CVSS 9.8`
🎯 受影响:Unauthenticated PHP Object Injection in Abelle <= 1.22 versions.
📋 简介:Unauthenticated PHP Object Injection in Abelle <= 1.22 versions.
🔗 参考:
- https://nvd.nist.gov/vuln/detail/CVE-2026-65573
- https://patchstack.com/database/wordpress/theme/abelle/vulnerability/wordpress-abelle-theme-1-22-php-object-injection-vulnerability?_s_id=cve
52. CVE-2026-65574 `CVSS 9.8`
🎯 受影响:Unauthenticated PHP Object Injection in Abogado <= 1.18 versions.
📋 简介:Unauthenticated PHP Object Injection in Abogado <= 1.18 versions.
🔗 参考:
- https://nvd.nist.gov/vuln/detail/CVE-2026-65574
- https://patchstack.com/database/wordpress/theme/abogado/vulnerability/wordpress-abogado-theme-1-18-php-object-injection-vulnerability?_s_id=cve
53. CVE-2026-65575 `CVSS 9.8`
🎯 受影响:Unauthenticated PHP Object Injection in Accalia <= 1.5.3 versions.
📋 简介:Unauthenticated PHP Object Injection in Accalia <= 1.5.3 versions.
🔗 参考:
- https://nvd.nist.gov/vuln/detail/CVE-2026-65575
- https://patchstack.com/database/wordpress/theme/accalia/vulnerability/wordpress-accalia-theme-1-5-3-php-object-injection-vulnerability?_s_id=cve
54. CVE-2026-65576 `CVSS 9.8`
🎯 受影响:Unauthenticated PHP Object Injection in Adrena <= 1.2.14 versions.
📋 简介:Unauthenticated PHP Object Injection in Adrena <= 1.2.14 versions.
🔗 参考:
- https://nvd.nist.gov/vuln/detail/CVE-2026-65576
- https://patchstack.com/database/wordpress/theme/adrena/vulnerability/wordpress-adrena-theme-1-2-14-php-object-injection-vulnerability?_s_id=cve
55. CVE-2026-65577 `CVSS 9.8`
🎯 受影响:Unauthenticated PHP Object Injection in Advice <= 1.18.0 versions.
📋 简介:Unauthenticated PHP Object Injection in Advice <= 1.18.0 versions.
🔗 参考:
- https://nvd.nist.gov/vuln/detail/CVE-2026-65577
- https://patchstack.com/database/wordpress/theme/advice/vulnerability/wordpress-advice-theme-1-18-0-php-object-injection-vulnerability?_s_id=cve
56. CVE-2026-65578 `CVSS 9.8`
🎯 受影响:Unauthenticated PHP Object Injection in Agora <= 1.9 versions.
📋 简介:Unauthenticated PHP Object Injection in Agora <= 1.9 versions.
🔗 参考:
- https://nvd.nist.gov/vuln/detail/CVE-2026-65578
- https://patchstack.com/database/wordpress/theme/agora/vulnerability/wordpress-agora-theme-1-9-php-object-injection-vulnerability?_s_id=cve
57. CVE-2026-65579 `CVSS 9.8`
🎯 受影响:Unauthenticated PHP Object Injection in Agricola <= 1.21.0 versions.
📋 简介:Unauthenticated PHP Object Injection in Agricola <= 1.21.0 versions.
🔗 参考:
- https://nvd.nist.gov/vuln/detail/CVE-2026-65579
- https://patchstack.com/database/wordpress/theme/agricola/vulnerability/wordpress-agricola-theme-1-21-0-php-object-injection-vulnerability?_s_id=cve
58. CVE-2026-65581 `CVSS 9.8`
🎯 受影响:Unauthenticated PHP Object Injection in AI ANN <= 1.29.0 versions.
📋 简介:Unauthenticated PHP Object Injection in AI ANN <= 1.29.0 versions.
🔗 参考:
- https://nvd.nist.gov/vuln/detail/CVE-2026-65581
- https://patchstack.com/database/wordpress/theme/ann/vulnerability/wordpress-ai-ann-theme-1-29-0-php-object-injection-vulnerability?_s_id=cve
59. CVE-2026-71207 `CVSS 9.8`
🎯 受影响:The Stock-Inventory-Management-System application's login.php assigns raw $_POST username/password v
📋 简介:The Stock-Inventory-Management-System application's login.php assigns raw $_POST username/password values to $_SESSION and builds its authentication query by directly concatenating those session values into a SQL statement with no parameterization or escaping.
🔗 参考:
- https://nvd.nist.gov/vuln/detail/CVE-2026-71207
- https://github.com/mrswapnilsahu/Stock-Inventory-Management-System/blob/master/login.php
60. CVE-2026-71214 `CVSS 9.8`
🎯 受影响:The Aerie/PlanDev sequencing-server's authorization middleware (sequencing-server/src/app.ts) derive
📋 简介:The Aerie/PlanDev sequencing-server's authorization middleware (sequencing-server/src/app.ts) derives the caller's Hasura session role via getHasuraSession(), which prefers a session_variables object taken directly from the client-supplied JSON request body over the Authorizat...
🔗 参考:
61. CVE-2026-71231 `CVSS 9.8`
🎯 受影响:IOTSmartHome's gui/login.php checkCookie() function builds an authentication query as SELECT * FROM
📋 简介:IOTSmartHome's gui/login.php checkCookie() function builds an authentication query as SELECT * FROM users WHERE ID='<decoded lastLogin cookie>' after base64-decoding the client-supplied lastLogin cookie via safe_decode(), which performs URL-safe base64 decoding with no sanitiz...
🔗 参考:
62. CVE-2026-71278 `CVSS 9.8`
🎯 受影响:rust-iot-platform
📋 简介:rust-iot-platform allows creating a "calc rule" via POST /calc-rule/create (api/src/controller/calc_rule_router.rs) containing an arbitrary `script` field.
🔗 参考:
63. CVE-2026-9192 `CVSS 9.8`
🎯 受影响:An authentication bypass vulnerability in the ODBC App Server of Progress MarkLogic Server
📋 简介:An authentication bypass vulnerability in the ODBC App Server of Progress MarkLogic Server before 11.3.6 and 12.0.3 allows an unauthenticated remote attacker to bypass password verification and execute queries with the privileges of any named user known to the server, includin...
🔗 参考:
- https://nvd.nist.gov/vuln/detail/CVE-2026-9192
- https://community.progress.com/s/article/Marklogic-Critical-Security-Alert-Bulletin-August-2026
64. CVE-2026-12605 `CVSS 9.6`
🎯 受影响:In Eclipse GlassFish
📋 简介:In Eclipse GlassFish versions 8.0.x before 8.0.4, CSRF + SSRF in DownloadServlet ContentSources leaks the admin `gfresttoken` to attacker-controlled host if the victim is authenticated into the Admin Console -\> full unauthenticated takeover of Eclipse GlassFish domain until t...
🔗 参考:
- https://nvd.nist.gov/vuln/detail/CVE-2026-12605
- https://gitlab.eclipse.org/security/vulnerability-reports/-/work_items/445
- https://gitlab.eclipse.org/security/cve-assignment/-/work_items/127
65. CVE-2026-20310 `CVSS 9.1`
🎯 受影响:As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Catalyst
📋 简介:As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Catalyst SD-WAN engineering team has conducted a comprehensive internal security review.
🔗 参考:
- https://nvd.nist.gov/vuln/detail/CVE-2026-20310
- https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-hardening-sdwan-faLcR3K
66. CVE-2026-71319 `CVSS 9.6`
🎯 受影响:Nuxt
📋 简介:Nuxt is an open-source web development framework for Vue.js.
🔗 参考:
- https://nvd.nist.gov/vuln/detail/CVE-2026-71319
- https://github.com/nuxt/nuxt/security/advisories/GHSA-279x-mwfv-vcqv
- https://github.com/nuxt/devtools/commit/a7b2718b930766e1ffb0640259d53f5b041a50b4
- https://github.com/nuxt/devtools/releases/tag/v3.3.1
67. CVE-2026-20267 `CVSS 9`
🎯 受影响:As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XE So
📋 简介:As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XE Software engineering team has conducted a comprehensive internal security review.
🔗 参考:
- https://nvd.nist.gov/vuln/detail/CVE-2026-20267
- https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-hardening-iosxe-V8NMuMZJ
68. CVE-2026-48088 `CVSS 9.4`
🎯 受影响:OpenReception's appointment booking software provides an end-to-end encrypted appointment booking pl
📋 简介:OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform.
🔗 参考:
- https://nvd.nist.gov/vuln/detail/CVE-2026-48088
- https://github.com/open-reception/appointment-booking-software/security/advisories/GHSA-pch3-hcmf-cjw4
- https://github.com/open-reception/appointment-booking-software/commit/78dfd9317a0be0897e6e4d73afe670c07a75460f
69. CVE-2026-65548 `CVSS 9.9`
🎯 受影响:Contributor Remote Code Execution (RCE) in Betheme <= 28.4.2 versions.
📋 简介:Contributor Remote Code Execution (RCE) in Betheme <= 28.4.2 versions.
🔗 参考:
- https://nvd.nist.gov/vuln/detail/CVE-2026-65548
- https://patchstack.com/database/wordpress/theme/betheme/vulnerability/wordpress-betheme-theme-28-4-2-remote-code-execution-rce-vulnerability?_s_id=cve
70. CVE-2026-71268 `CVSS 9.9`
🎯 受影响:OpenPLC Runtime v3's compile_program() function (webserver/openplc.py) parses `(*FILE:path content*)
📋 简介:OpenPLC Runtime v3's compile_program() function (webserver/openplc.py) parses `(*FILE:path content*)` directives from uploaded Structured Text (.st) program files and writes the referenced content to `os.path.join('./core', file_path)` with no validation that file_path stays w...
🔗 参考:
- https://nvd.nist.gov/vuln/detail/CVE-2026-71268
- https://github.com/thiagoralves/OpenPLC_v3
- https://github.com/thiagoralves/OpenPLC_v3/blob/master/webserver/openplc.py
71. CVE-2026-53976 `CVSS 9.3`
🎯 受影响:OpenChamber 1.11.7
📋 简介:OpenChamber 1.11.7 contains a path traversal vulnerability in the file-serving endpoints /api/fs/read, /api/fs/stat, and /api/fs/raw that allows unauthenticated remote attackers to read arbitrary files by supplying the allowOutsideWorkspace=true query parameter alongside an ab...
🔗 参考:
- https://nvd.nist.gov/vuln/detail/CVE-2026-53976
- https://github.com/openchamber/openchamber
- https://github.com/openchamber/openchamber/commit/f1b9506132faf6c564a2694c7f33b94421a49b4a
- https://www.vulncheck.com/advisories/openchamber-path-traversal-file-read-via-allowoutsideworkspace-parameter
72. CVE-2026-65508 `CVSS 9.3`
🎯 受影响:Unauthenticated SQL Injection in Simply Schedule Appointments <= 1.6.12.10 versions.
📋 简介:Unauthenticated SQL Injection in Simply Schedule Appointments <= 1.6.12.10 versions.
🔗 参考:
- https://nvd.nist.gov/vuln/detail/CVE-2026-65508
- https://patchstack.com/database/wordpress/plugin/simply-schedule-appointments/vulnerability/wordpress-simply-schedule-appointments-plugin-1-6-12-10-sql-injection-vulnerability?_s_id=cve
73. CVE-2026-65520 `CVSS 9.3`
🎯 受影响:Unauthenticated SQL Injection in WP OAuth Server <= 6.2.0 versions.
📋 简介:Unauthenticated SQL Injection in WP OAuth Server <= 6.2.0 versions.
🔗 参考:
- https://nvd.nist.gov/vuln/detail/CVE-2026-65520
- https://patchstack.com/database/wordpress/plugin/miniorange-oauth-20-server/vulnerability/wordpress-wp-oauth-server-plugin-6-2-0-sql-injection-vulnerability?_s_id=cve
74. CVE-2026-65546 `CVSS 9.3`
🎯 受影响:Unauthenticated SQL Injection in Qode Tours <= 3.1.3.1 versions.
📋 简介:Unauthenticated SQL Injection in Qode Tours <= 3.1.3.1 versions.
🔗 参考:
- https://nvd.nist.gov/vuln/detail/CVE-2026-65546
- https://patchstack.com/database/wordpress/plugin/qode-tours/vulnerability/wordpress-qode-tours-plugin-3-1-3-1-sql-injection-vulnerability?_s_id=cve
75. CVE-2026-66447 `CVSS 9.3`
🎯 受影响:Unauthenticated SQL Injection in WordPress File Upload <= 5.1.7 versions.
📋 简介:Unauthenticated SQL Injection in WordPress File Upload <= 5.1.7 versions.
🔗 参考:
- https://nvd.nist.gov/vuln/detail/CVE-2026-66447
- https://patchstack.com/database/wordpress/plugin/wp-file-upload/vulnerability/wordpress-wordpress-file-upload-plugin-5-1-7-sql-injection-vulnerability?_s_id=cve
76. CVE-2026-39923 `CVSS 9.2`
🎯 受影响:Flarum
📋 简介:Flarum before 1.8.16 contains a password reset token expiry bypass vulnerability that allows unauthenticated attackers to reuse expired password reset tokens by submitting them directly to the reset processing endpoint.
🔗 参考:
- https://nvd.nist.gov/vuln/detail/CVE-2026-39923
- https://github.com/flarum/framework/releases/tag/v1.8.16
- https://github.com/flarum/framework/pull/4545
- https://github.com/flarum/framework/commit/2803058d0f9dc38252326070b46d4484fe5a857d
- https://www.vulncheck.com/advisories/flarum-password-reset-token-expiry-bypass-via-post-reset
77. CVE-2026-53984 `CVSS 9.1`
🎯 受影响:Ground Station
📋 简介:Ground Station prior to 0.6.0 contains an unauthenticated database-destruction and arbitrary-data-injection vulnerability in the Socket.IO server's database_backup event handler that allows any unauthenticated network peer to wipe or replace the entire SQLite database by sendi...
🔗 参考:
- https://nvd.nist.gov/vuln/detail/CVE-2026-53984
- https://github.com/sgoudelis/ground-station
- https://github.com/sgoudelis/ground-station/security/advisories/GHSA-mjp8-x6h7-229q
- https://github.com/sgoudelis/ground-station/commit/2ecde82a8814cbea18883ce023bf45cbf06172eb
78. CVE-2026-70376 `CVSS 9.6`
🎯 受影响:Pluck CMS's admin panel relies solely on a Referer-header comparison (requestedByTheSameDomain() in
📋 简介:Pluck CMS's admin panel relies solely on a Referer-header comparison (requestedByTheSameDomain() in data/inc/functions.admin.php, gating every admin.php action) for CSRF protection, with no per-request anti-CSRF token anywhere in the admin area.
🔗 参考:
79. CVE-2026-71213 `CVSS 9.1`
🎯 受影响:Typemill's login endpoint (POST /tm/login, ControllerWebAuth::login()) performs no rate-limiting, fa
📋 简介:Typemill's login endpoint (POST /tm/login, ControllerWebAuth::login()) performs no rate-limiting, failed-attempt counting, or account lockout when captcha is disabled, which is the default configuration.
🔗 参考:
80. CVE-2026-7557 `CVSS 9.1`
🎯 受影响:An improper verification of cryptographic signature vulnerability in the SAML authentication module of Progress MarkLogic Server
📋 简介:An improper verification of cryptographic signature vulnerability in the SAML authentication module of Progress MarkLogic Server before 11.3.6 and 12.0.3 allows an unauthenticated remote attacker to bypass authentication and impersonate any user, including administrators.
🔗 参考:
- https://nvd.nist.gov/vuln/detail/CVE-2026-7557
- https://community.progress.com/s/article/Marklogic-Critical-Security-Alert-Bulletin-August-2026
81. CVE-2026-5857 `CVSS 9.2`
🎯 受影响:Contiki-NG's MQTT client parse_publish_vhdr() in os/net/app-layer/mqtt/mqtt.c sets topic_len_receive
📋 简介:Contiki-NG's MQTT client parse_publish_vhdr() in os/net/app-layer/mqtt/mqtt.c sets topic_len_received=1 before checking topic_len against the 64-byte limit, so an over-length topic returns early but leaves the flag set.
🔗 参考:
- https://nvd.nist.gov/vuln/detail/CVE-2026-5857
- https://github.com/contiki-ng/contiki-ng
- https://github.com/contiki-ng/contiki-ng/pull/3163
- https://github.com/contiki-ng/contiki-ng/commit/a34a2dbdc8bea784bd2ae5079aa4be520cd74f2d
82. CVE-2026-3418 `CVSS 9.1`
🎯 受影响:The System REST API accepts user-supplied file uploads without enforcing sufficient validation on th
📋 简介:The System REST API accepts user-supplied file uploads without enforcing sufficient validation on the file type or destination, allowing files to be written to arbitrary server-accessible locations.
🔗 参考:
- https://nvd.nist.gov/vuln/detail/CVE-2026-3418
- https://security.docs.wso2.com/en/latest/security-announcements/security-advisories/2026/WSO2-2026-5146/
83. CVE-2026-44945 `CVSS 9.1`
🎯 受影响:A privilege escalation vulnerability exists in Rancher's impersonation middleware (pkg/auth/requests
📋 简介:A privilege escalation vulnerability exists in Rancher's impersonation middleware (pkg/auth/requests/impersonate.go).
🔗 参考:
- https://nvd.nist.gov/vuln/detail/CVE-2026-44945
- https://github.com/rancher/rancher/pull/55983
- https://github.com/rancher/rancher/security/advisories/GHSA-v584-7w32-jwpq
- https://bugzilla.suse.com/show_bug.cgi?id=CVE-2026-44945
84. CVE-2026-66709 `CVSS 9.1`
🎯 受影响:Shop manager Remote Code Execution (RCE) in CTX Feed <= 6.6.42 versions.
📋 简介:Shop manager Remote Code Execution (RCE) in CTX Feed <= 6.6.42 versions.
🔗 参考:
- https://nvd.nist.gov/vuln/detail/CVE-2026-66709
- https://patchstack.com/database/wordpress/plugin/webappick-product-feed-for-woocommerce/vulnerability/wordpress-ctx-feed-plugin-6-6-42-remote-code-execution-rce-vulnerability?_s_id=cve
85. CVE-2026-5430 `CVSS 10`
🎯 受影响:The JWT authentication mechanism accepts tokens signed with algorithms other than those explicitly configured or supported. This
📋 简介:The JWT authentication mechanism accepts tokens signed with algorithms other than those explicitly configured or supported.
🔗 参考:
- https://nvd.nist.gov/vuln/detail/CVE-2026-5430
- https://security.docs.wso2.com/en/latest/security-announcements/security-advisories/2026/WSO2-2026-5328/
86. CVE-2026-70615 `CVSS 9.9`
🎯 受影响:boringproxy through 0.10.0
📋 简介:boringproxy through 0.10.0 contains a newline injection vulnerability that allows authenticated low-privileged users with tunnel-creation permission to inject arbitrary lines into the server account's SSH authorized_keys file by supplying a percent-encoded newline character in...
🔗 参考:
- https://nvd.nist.gov/vuln/detail/CVE-2026-70615
- https://github.com/theopaid/Remote-Code-Execution-And-Privilege-Escalation-Through-SSH-Authorized-Keys-Injection-boringproxy-/blob/master/README.md
- https://www.vulncheck.com/advisories/boringproxy-ssh-authorized-keys-injection-via-tunnel-creation
87. CVE-2026-7329 `CVSS 9.9`
🎯 受影响:An improper privilege management vulnerability in the SQL, SPARQL, and Optic REST query interfaces o
📋 简介:An improper privilege management vulnerability in the SQL, SPARQL, and Optic REST query interfaces of Progress MarkLogic Server before 11.3.6 and 12.0.3 allows an authenticated user with a low-privileged REST role to escalate privileges to administrator.
🔗 参考:
- https://nvd.nist.gov/vuln/detail/CVE-2026-7329
- https://community.progress.com/s/article/Marklogic-Critical-Security-Alert-Bulletin-August-2026
88. CVE-2026-8709 `CVSS 9.9`
🎯 受影响:An improper privilege management vulnerability in the REST API document patch operation of Progress MarkLogic Server
📋 简介:An improper privilege management vulnerability in the REST API document patch operation of Progress MarkLogic Server before 11.3.6 and 12.0.3 allows an authenticated user with a low-privileged REST role to escalate privileges and execute privileged operations against the Secur...
🔗 参考:
- https://nvd.nist.gov/vuln/detail/CVE-2026-8709
- https://community.progress.com/s/article/Marklogic-Critical-Security-Alert-Bulletin-August-2026
89. CVE-2026-9193 `CVSS 9.9`
🎯 受影响:An improper privilege management vulnerability in the Hadoop integration of Progress MarkLogic Server
📋 简介:An improper privilege management vulnerability in the Hadoop integration of Progress MarkLogic Server before 11.3.6 and 12.0.3 allows an authenticated user with a low-privileged Hadoop role to escalate privileges and execute privileged operations against the Security database.
🔗 参考:
- https://nvd.nist.gov/vuln/detail/CVE-2026-9193
- https://community.progress.com/s/article/Marklogic-Critical-Security-Alert-Bulletin-August-2026
90. CVE-2026-1728 `CVSS 9.8`
🎯 受影响:Tokens issued to a low-privileged user are not sufficiently restricted, allowing them to be used to
📋 简介:Tokens issued to a low-privileged user are not sufficiently restricted, allowing them to be used to access product-level Admin REST APIs.
🔗 参考:
- https://nvd.nist.gov/vuln/detail/CVE-2026-1728
- https://security.docs.wso2.com/en/latest/security-announcements/security-advisories/2026/WSO2-2026-5077/
91. CVE-2026-5134 `CVSS 9.8`
🎯 受影响:Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability i
📋 简介:Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Loca Software Informatics Technology Ltd.
🔗 参考:
- https://nvd.nist.gov/vuln/detail/CVE-2026-5134
- https://siberguvenlik.gov.tr/guvenlik-bildirimleri/detay/tr-26-0771
92. CVE-2026-65552 `CVSS 9.8`
🎯 受影响:Subscriber PHP Object Injection in Export User Data <= 2.2.6 versions.
📋 简介:Subscriber PHP Object Injection in Export User Data <= 2.2.6 versions.
🔗 参考:
- https://nvd.nist.gov/vuln/detail/CVE-2026-65552
- https://patchstack.com/database/wordpress/plugin/export-user-data/vulnerability/wordpress-export-user-data-plugin-2-2-6-php-object-injection-vulnerability?_s_id=cve
93. CVE-2026-71256 `CVSS 9.8`
🎯 受影响:nanoMODBUS through v1.23.0
📋 简介:nanoMODBUS through v1.23.0 contains an out-of-bounds stack read leading to a wild-pointer write in nmbs_read_device_identification_basic() / recv_read_device_identification_res() in nanomodbus.c.
🔗 参考:
- https://nvd.nist.gov/vuln/detail/CVE-2026-71256
- https://github.com/debevv/nanoMODBUS
- https://github.com/debevv/nanoMODBUS/blob/master/nanomodbus.c
94. CVE-2026-71267 `CVSS 9.8`
🎯 受影响:microtar's mtar_write_file_header() and mtar_write_dir_header() functions (src/microtar.c) copy a ca
📋 简介:microtar's mtar_write_file_header() and mtar_write_dir_header() functions (src/microtar.c) copy a caller-supplied entry name into the 100-byte `name` field of a stack-allocated mtar_header_t via strcpy(h.name, name), with no check that strlen(name) is less than 100 before the ...
🔗 参考:
- https://nvd.nist.gov/vuln/detail/CVE-2026-71267
- https://github.com/rxi/microtar
- https://github.com/rxi/microtar/blob/master/src/microtar.c
95. CVE-2025-15039 `CVSS 9.4`
🎯 受影响:The Conditional Authentication (Adaptive Authentication) script does not correctly enforce the compl
📋 简介:The Conditional Authentication (Adaptive Authentication) script does not correctly enforce the completion of all required authentication steps when a specific multi-step pattern involving certain authenticators is configured.
🔗 参考:
- https://nvd.nist.gov/vuln/detail/CVE-2025-15039
- https://security.docs.wso2.com/en/latest/security-announcements/security-advisories/2026/WSO2-2025-4973/
96. CVE-2026-9195 `CVSS 9.3`
🎯 受影响:A cross-site scripting vulnerability in the Query Console of Progress MarkLogic Server
📋 简介:A cross-site scripting vulnerability in the Query Console of Progress MarkLogic Server before 11.3.6 and 12.0.3 allows a remote attacker who lures an authenticated administrator to a crafted URL to execute arbitrary JavaScript in the administrator's browser session, capture cr...
🔗 参考:
- https://nvd.nist.gov/vuln/detail/CVE-2026-9195
- https://community.progress.com/s/article/Marklogic-Critical-Security-Alert-Bulletin-August-2026
97. CVE-2026-43629 `CVSS 9.2`
🎯 受影响:llama.cpp builds b4882 through b9058
📋 简介:llama.cpp builds b4882 through b9058 contain a heap buffer overflow vulnerability in the KV cache state restore path where the state_read_data() function computes write size without overflow checking, allowing attackers with write access to the slot_save_path directory to corr...
🔗 参考:
- https://nvd.nist.gov/vuln/detail/CVE-2026-43629
- https://github.com/Vladimir-tokarev-cyera/llama-cpp-security-patches
98. CVE-2026-71238 `CVSS 9.1`
🎯 受影响:DjangoCRM ships with its Django SECRET_KEY hardcoded directly in the committed webcrm/settings.py ra
📋 简介:DjangoCRM ships with its Django SECRET_KEY hardcoded directly in the committed webcrm/settings.py rather than read from an environment variable.
🔗 参考:
99. CVE-2026-71277 `CVSS 9.1`
🎯 受影响:rust-iot-platform's AuthToken request-guard implementation (api/src/main.rs) only checks whether the
📋 简介:rust-iot-platform's AuthToken request-guard implementation (api/src/main.rs) only checks whether the Authorization HTTP header is present, and never validates its value against any session, token store, or signature.
🔗 参考:
- https://nvd.nist.gov/vuln/detail/CVE-2026-71277
- https://github.com/iot-ecology/rust-iot-platform
- https://github.com/iot-ecology/rust-iot-platform/blob/main/api/src/main.rs
100. CVE-2026-9190 `CVSS 9.1`
🎯 受影响:An HTTP request smuggling vulnerability in the HTTP App Server of Progress MarkLogic Server
📋 简介:An HTTP request smuggling vulnerability in the HTTP App Server of Progress MarkLogic Server before 11.3.6 and 12.0.3 allows a remote attacker to bypass authentication and authorization checks, hijack a legitimate user's session, or capture credentials.
🔗 参考:
- https://nvd.nist.gov/vuln/detail/CVE-2026-9190
- https://community.progress.com/s/article/Marklogic-Critical-Security-Alert-Bulletin-August-2026
🟠 HIGH · 8 条
1. CVE-2026-67621 `CVSS 7.6`
🎯 受影响:Flowise through 3.1.4
📋 简介:Flowise through 3.1.4 contains a missing authorization vulnerability that allows authenticated workspace members to perform unauthorized document store operations by accessing unprotected mutation endpoints.
🔗 参考:
- https://nvd.nist.gov/vuln/detail/CVE-2026-67621
- https://github.com/Caycon/cve-advisories/blob/main/2026/Flowise/CVE-2026-67621.md
- https://flowiseai.com/sunset
2. CVE-2026-17556 `CVSS 8.8`
🎯 受影响:A path traversal vulnerability was identified in GitHub Enterprise Server that allowed an unauthenti
📋 简介:A path traversal vulnerability was identified in GitHub Enterprise Server that allowed an unauthenticated attacker to delete arbitrary files and directories on the instance, including the entire user storage directory containing Git LFS objects, release assets, attachments, an...
🔗 参考:
- https://nvd.nist.gov/vuln/detail/CVE-2026-17556
- https://docs.github.com/en/enterprise-server@3.17/admin/release-notes#3.17.19
- https://docs.github.com/en/enterprise-server@3.18/admin/release-notes#3.18.13
- https://docs.github.com/en/enterprise-server@3.19/admin/release-notes#3.19.10
- https://docs.github.com/en/enterprise-server@3.20/admin/release-notes#3.20.6
3. CVE-2026-70636 `CVSS 8.7`
🎯 受影响:Flowise through 3.1.4
📋 简介:Flowise through 3.1.4 contains an authentication bypass vulnerability that allows unauthenticated attackers to access the OAuth2 credential refresh endpoint by exploiting prefix-based whitelist matching in the authentication middleware defined in packages/server/src/utils/cons...
🔗 参考:
- https://nvd.nist.gov/vuln/detail/CVE-2026-70636
- https://github.com/Caycon/cve-advisories/blob/main/2026/Flowise/CVE-2026-70636.md
- https://flowiseai.com/sunset
4. CVE-2026-20263 `CVSS 8.6`
🎯 受影响:A vulnerability in the Blocks Extensible Exchange Protocol (BEEP) feature of Cisco IOS XE Software c
📋 简介:A vulnerability in the Blocks Extensible Exchange Protocol (BEEP) feature of Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device.
🔗 参考:
- https://nvd.nist.gov/vuln/detail/CVE-2026-20263
- https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-iosxe-bing-MGHrFAkd
5. CVE-2026-20301 `CVSS 8.6`
🎯 受影响:A vulnerability in the Extensible Messaging Client Protocol (XMCP), also referred to as the External
📋 简介:A vulnerability in the Extensible Messaging Client Protocol (XMCP), also referred to as the External Client protocol, of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected dev...
🔗 参考:
- https://nvd.nist.gov/vuln/detail/CVE-2026-20301
- https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ios-xmcp-thbAr34t
6. CVE-2026-71211 `CVSS 7.1`
🎯 受影响:MLflow's AI Gateway accepts an auth_config.api_base value when creating a gateway secret (mlflow/ser
📋 简介:MLflow's AI Gateway accepts an auth_config.api_base value when creating a gateway secret (mlflow/server/handlers.py, _create_gateway_secret) with no validation of scheme, host, or IP range; the value is stored verbatim.
🔗 参考:
- https://nvd.nist.gov/vuln/detail/CVE-2026-71211
- https://github.com/mlflow/mlflow/tree/v3.14.0/mlflow
7. CVE-2026-9081 `CVSS 7.1`
🎯 受影响:IBM Langflow OSS 1.0.0 through 1.10.3, and 1.0.0 through 1.10.3 contains a Server-Side Request Forge
📋 简介:IBM Langflow OSS 1.0.0 through 1.10.3, and 1.0.0 through 1.10.3 contains a Server-Side Request Forgery (SSRF) vulnerability in the validate_model_provider_key() function for the Ollama provider.
🔗 参考:
8. CVE-2026-65058 🔥 ⚡近期活跃 `CVSS 5.9`
🎯 受影响:Trezor Safe 3, Safe 5, and Safe 7 firmware contains a confirmation-binding flaw in the Ethereum sign
📋 简介:Trezor Safe 3, Safe 5, and Safe 7 firmware contains a confirmation-binding flaw in the Ethereum sign_tx / sign_tx_eip1559 flow.
🔗 参考:
- https://nvd.nist.gov/vuln/detail/CVE-2026-65058
- https://github.com/trezor/trezor-firmware/commit/70c9b0c07748
- https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2026/va-26-202-02.json
- https://www.cve.org/CVERecord?id=CVE-2026-65058
- https://sploitus.com/exploit?id=ABE6B5D7-1585-5C00-8A82-A3FB42F2F020&utm_source=rss&utm_medium=rss
---
新发现 341 条 · 热度升级 1 条 · 🔥=高热度/有 PoC · 🆙=昨日已推、今日热度升级
📊 GitHub 热榜
📊 GitHub 日榜 · 2026-08-07
1. TencentCloud/TencentDB-Agent-Memory
📋 TencentDB Agent Memory 是面向 AI Agent 的团队级记忆中枢,将对话、文档与代码转化为可治理、可共享的四类记忆资产(Chat Memory、Skill、LLM-Wiki、Code-Graph)。
📋 为 AI 编程代理打造的生产级工程技能。
📋 给你的智能体一台电脑👾
📋 面向真实工程师的技能,直接取自我的 .agents 目录。
📋 你需要的认证粘合剂。
📋 面向长期运行 AI Agent 团队的轻量级循环工程状态内核,与 Codex、Claude Code 等 Agent 循环无关,支持持久目标、配额感知自动唤醒、可执行待办、证据日志与可验证交接。
7. google/guava
📋 Google Java 核心库。
📋 所有小初高、大学PDF教材。
9. Significant-Gravitas/AutoGPT
📋 AutoGPT 旨在让每个人都能使用并构建 AI,提供工具让你专注真正重要的事。
10. tirth8205/code-review-graph
📋 面向 MCP 和 CLI 的本地优先代码智能图,构建代码库持久地图,让 AI 编码工具只读取关键内容,在评审与大型仓库工作流中实现基准化的上下文缩减。
🤖 AI 总结分析
今日整体态势:高危漏洞预警单日收录 100 条 CRITICAL,其中 CVSS 10.0 级漏洞密集出现,未授权远程代码执行是绝对主线;安全情报侧出现多个高评分 PoC 公开与 CISA 在野利用预警;GitHub 热榜则被 AI Agent 基础设施项目主导,安全与 AI 的交汇特征愈发明显。
漏洞预警方面,最需关注 CVE-2026-21858(n8n,CVSS 10.0):作为广泛使用的开源自动化平台,其未认证 RCE 漏洞已标记“近期活跃”并附带公开利用链,直接威胁大量线上工作流实例。另一项 CVE-2026-63077(JetBrains TeamCity,CVSS 9.8)同样值得警惕,Agent 轮询协议导致的未认证 RCE 已被列入 CISA KEV,属于可被快速武器化的目标。此外,Flowise 的 IDOR 与 llama.cpp 的释放后使用漏洞,也反映出 AI/LLM 工具链正成为攻击者集中研究的对象。
安全情报侧,Linux 内核 OVS 组件潜伏 13 年的本地提权漏洞曝光,普通用户可秒变 Root,影响面涉及大量服务器,尽管利用前提是本地访问,但修复优先级不应低估。CISA 紧急预警中,Langflow RCE 与 Tomcat 加密绕过已确认在野利用,且多个 CVSS 9.8-10.0 的 PoC(如 CVE-2026-64633、CVE-2026-0163)同日公开,说明攻击者正加速将漏洞转化为实战工具。
GitHub 热榜呈现鲜明的 AI 工程化转向:TencentDB-Agent-Memory 为 Agent 提供团队级记忆中枢,agent-skills 与 cloudflare/computer 则聚焦代理的工程技能与运行环境,这些项目暗示行业正从“训练模型”转向“让 Agent 稳定干活”;而 authentik 等认证组件的上榜,或也呼应了 AI 应用安全加固的需求。
行动建议:今天应优先排查暴露在公网的 n8n 实例,确认是否落在受影响版本区间,立即升级并限制管理端口访问——这是当前唯一兼具 CVSS 满分、活跃利用标识与公开 PoC 的高危目标。