🛡️ 每日安全情报
🛡️ AI 安全情报日报 · 2026-08-08
_2026-08-08 · 共筛出 63 条 ≥4★_
1. AI-Assisted HTTP Terminator Finds Novel HTTP Desync Techniques and Apache Zero-Day 🔓 ⚔️ 🔧 ★★★★★
📋 AI辅助工具HTTP Terminator发现新的HTTP Desync攻击方式和Apache零日漏洞,安全影响严重。
2. AI如何自主发现并利用三个Bing Images高危RCE漏洞 ⚔️ 🔓 📄 ★★★★★
📋 AI 黑客 XBOW 自主发现 Bing Images 三个高危 RCE 漏洞并利用。
3. Anthropic、谷歌和OpenAI 的编程代理严重漏洞可致RCE和供应链攻击 🔓 ⚔️ 📄 ★★★★★
📋 三大AI编程代理工具存在漏洞,可致RCE和供应链攻击。
4. ChanCms search SQL注入 🔓 ★★★★★
📋 ChanCms search接口存在SQL注入,攻击者可获取数据库信息。
5. Exploit for CVE-2026-64638 🔓 ⚔️ ★★★★★
📋 CVE-2026-64638 PoC 发布,CVSS 8.9,可远程攻击。
6. Exploit for CVE-2026-67822 🔓 ★★★★★
📋 CVE-2026-67822的PoC公开,CVSS 9.8。
7. Exploit for CVE-2026-70638 🔓 ⚔️ ★★★★★
📋 公开了CVE-2026-70638的PoC利用,CVSS 8.5分。
8. Exploit for Code Injection in Protobufjs_Project Protobufjs 🔓 ★★★★★
📋 Protobufjs项目存在代码注入漏洞CVE-2026-41242,PoC公开,CVSS 9.8。
9. Exploit for Deserialization of Untrusted Data in Facebook React 🔓 ⚔️ ★★★★★
📋 React 反序列化漏洞 CVE-2025-55182 PoC 公开,CVSS 10,严重。
10. Exploit for Deserialization of Untrusted Data in Jetbrains Teamcity 🔓 ★★★★★
📋 JetBrains TeamCity反序列化漏洞CVE-2026-63077 PoC公开,CVSS 9.8。
11. Exploit for Incorrect Authorization in Apache Polaris 🔓 ⚔️ ★★★★★
📋 公开了Apache Polaris权限不当的PoC利用,CVSS 6.5分。
12. Exploit for Missing Authentication for Critical Function in Coreweave Marimo 🔓 ★★★★★
📋 Coreweave Marimo存在严重认证缺失漏洞(CVE-2026-39987, CVSS 9.8),已有PoC利用代码。
13. Exploit for Missing Critical Step in Authentication in Apache Tomcat 🔓 ⚔️ ★★★★★
📋 Apache Tomcat 认证步骤缺失漏洞 CVE-2026-55957 PoC 发布,CVSS 7.3。
14. Exploit for PHP Remote File Inclusion in Synacor Zimbra_Collaboration_Suite 🔓 ⚔️ ★★★★★
📋 Zimbra 远程文件包含漏洞 CVE-2025-68645 PoC 发布,CVSS 8.8。
15. Fastjson2 AutoType 哈希校验绕过致RCE分析 🔓 ⚔️ 📄 ★★★★★
📋 Fastjson2 哈希校验绕过可致超级 RCE,详细技术分析。
---
其他 48 条:
- GitLab 漏洞允许攻击者在默认的 GitLab 安装上执行远程代码 (5★)
- Kimi K3模型在安全测试中逃逸出沙盒 (5★)
- Linux KVM 曝出虚拟机逃逸漏洞 嵌套虚拟化功能成攻击突破口 (5★)
- Microsoft 365 AitM Phishing Hijacks Accounts to Collect Payroll and Finance Emails (5★)
- New NatJack Attacks Hijack TCP Sessions and Spoof DNS by Manipulating NAT Tables (5★)
- OpenAI and Anthropic's models attacked real companies during safety tests, and most victims never noticed - XDA (5★)
- OpenAI等模型接连失控发动攻击,谁该承担法律责任? (5★)
- The Download: a censorship conspiracy theory and the first virus created by AI (5★)
- langgraph-agentic-research-api-poc exploit (5★)
- pocyeah exploit (5★)
- 【edu通杀刷分】CVE-2026-63030/60137-Wp2Shell命令执行+SQL注入 (5★)
- 【原创】AI时代下的国产Electron软件供应链攻击活动披露 (5★)
- 【安全圈】一个 GitHub Issue,就能黑掉 Anthropic 和 Google 的 AI 编程助手 (5★)
- 【靶场搭建+漏洞复现】Fastjson 1.2.83 RCE远程代码执行漏洞(CVE-2026-16723) (5★)
- 一个Telegram指令,460个目标:AI自主攻击时代正式开场 (5★)
- 全补丁Windows秒变SYSTEM:LegacyHive零日实测 (5★)
- 号称无法复制的通行密钥出现三类劫持攻击 (5★)
- 在 Flowise 里挖 RCE 漏洞:六种花样拿 Shell (5★)
- 失控进行时!Meta大模型在测试期间也入侵了一家公司 (5★)
- 用友U8Cloud XChangeServlet存在SQL注入漏洞 (5★)
- 通知 | 国家网信办就《大型个人信息处理者个人信息保护规定(征求意见稿)》公开征求意见(附全文) (5★)
- 400万元的惨痛教训:高危补丁不补,就是给诈骗分子留 正门 (4★)
- 600万美元损失的警示:AI驱动攻击时代,数据安全防线如何重构? (4★)
- AI教父辛顿紧急警告,各大巨头AI接连越狱入侵,人类迟早控不住 (4★)
- AI渗透测试被高估了?一篇AI测试能力评估的论文解读 (4★)
- ARTEX:自动化渗透测试 (4★)
- Agentic AI for Cyber Defenders: What Security Teams Built at Black Hat USA 2026 (4★)
- Anthropic Significantly Relaxes Safety Guardrails on Top-Tier AI 'Claude Fable 5' for Biology, Cutting Daily-Use Restrictions by 85% - finance.biggo.com (4★)
- Apache Syncope紧急发布补丁:修复RCE、SQL注入等高危漏洞 (4★)
- Fastjson @JSONType 利用工具 (4★)
- G.O.S.S.I.P 阅读推荐 2026-08-07 被丢弃的恶意前缀依然有毒? (4★)
- HNS 2026|华为面向拉美地区发布《华为AIFW技术白皮书》,夯实数字安全底座 (4★)
- Responding to the next frontier of critical cyber capabilities (4★)
- Static analyzer for Flutter/Dart AOT snapshots — recovers function names, class hierarchies, call graphs, and behavioral signals from libapp.so without embedding or executing the Dart VM. Supports ARM64 and x86_64, Dart 2.10–3.12. (4★)
- Unveiling good and bad behaviors on the Agentic Internet (4★)
- hvv 2026 - 揭秘pdf 钓鱼套路 (4★)
- 一周安全事件回顾:前沿AI突破约束,传统数据泄露隐患凸显 (4★)
- 国际 | 部分美国AI模型在测试中被发现持续实施有害行为 (4★)
- 如何衡量智能体创造的真实价值:评《北京市关于加快智能体引领发展的若干措施》之四 (4★)
- 当 human in the loop 变成“闭着眼睛点确认”,企业Agent 安全还能靠谁? (4★)
- 思科修复12个 SD-WAN 和 IOS XE 漏洞,含多个高危 (4★)
- 批量资产信息收集工具+指纹联动poc(9000+)利用工具 (4★)
- 把爱因斯坦的知识喂给大模型,它能发明相对论吗? (4★)
- 第4篇-双重勒索与三重勒索时代 (4★)
- 网络安全司法新走向:用户授权AI工具访问网站不构成《计算机欺诈与滥用法》违规;白宫推出AI自愿审查机制 | 牛览 (4★)
- 谷歌搜索意外收录Claude AI的共享聊天记录,源于配置错误 (4★)
- 银行职员分不出 GPT-4 写的钓鱼短信,你也一样 (4★)
- 高危端口暴露致学生敏感信息存泄露风险 (4★)
🚨 漏洞预警
🔴 CRITICAL · 90 条
1. CVE-2026-61808 `CVSS 9.8`
🎯 受影响:LightRAG provides simple and fast retrieval-augmented generation. Through
📋 简介:LightRAG provides simple and fast retrieval-augmented generation.
🔗 参考:
- https://nvd.nist.gov/vuln/detail/CVE-2026-61808
- https://github.com/HKUDS/LightRAG/security/advisories/GHSA-mmg5-8x8q-v934
- https://github.com/HKUDS/LightRAG/commit/0bd102401b4b28a02664e5b6af476bf7a4470292
2. CVE-2026-48086 `CVSS 9.9`
🎯 受影响:OpenReception's appointment booking software provides an end-to-end encrypted appointment booking pl
📋 简介:OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform.
🔗 参考:
- https://nvd.nist.gov/vuln/detail/CVE-2026-48086
- https://github.com/open-reception/appointment-booking-software/security/advisories/GHSA-5qfr-7q4g-3469
- https://github.com/open-reception/appointment-booking-software/commit/8525d35a41c31078d9f01c62e9687e653cf1a494
3. CVE-2026-64638 🔥 `CVSS 8.9`
🎯 受影响:WordPress
📋 简介:WordPress is vulnerable to a pre-auth reflected XSS vulnerability on the login screen.
🔗 参考:
- https://nvd.nist.gov/vuln/detail/CVE-2026-64638
- https://hackerone.com/reports/3877102
- https://wordpress.org/news/2026/08/wordpress-7-0-3-release/
- https://sploitus.com/exploit?id=2A1FBABC-C218-5724-9F41-BDC644E427BA&utm_source=rss&utm_medium=rss
- https://sploitus.com/exploit?id=AE6F6022-D94F-5E89-9A0B-5D6C8C0B3E13&utm_source=rss&utm_medium=rss
4. CVE-2026-67622 `CVSS 9.9`
🎯 受影响:Flowise through 3.1.4
📋 简介:Flowise through 3.1.4 contains an insecure direct object reference vulnerability in the OpenAI Assistants integration that allows authenticated attackers to access credentials belonging to other workspaces by supplying an arbitrary credential UUID to Assistants endpoints witho...
🔗 参考:
- https://nvd.nist.gov/vuln/detail/CVE-2026-67622
- https://github.com/Caycon/cve-advisories/blob/main/2026/Flowise/CVE-2026-67622.md
- https://flowiseai.com/sunset
- https://www.vulncheck.com/advisories/flowise-idor-in-openai-assistants-integration
5. CVE-2026-53975 `CVSS 9.8`
🎯 受影响:OpenChamber 1.11.7
📋 简介:OpenChamber 1.11.7 contains an unauthenticated remote code execution vulnerability that allows remote attackers to execute arbitrary shell commands by sending crafted POST requests to the /api/fs/exec endpoint, which passes commands verbatim to Node.js spawn() without any allo...
🔗 参考:
- https://nvd.nist.gov/vuln/detail/CVE-2026-53975
- https://github.com/openchamber/openchamber
- https://github.com/openchamber/openchamber/commit/f1b9506132faf6c564a2694c7f33b94421a49b4a
- https://www.vulncheck.com/advisories/openchamber-unauthenticated-rce-via-api-fs-exec
6. CVE-2026-43632 `CVSS 9.2`
🎯 受影响:llama.cpp builds b7492 through the latest b9060
📋 简介:llama.cpp builds b7492 through the latest b9060 contains a use-after-free vulnerability in llama-server affecting six tokenization endpoints (/tokenize, /detokenize, /infill, /apply-template, /rerank, and /anthropic/count_tokens) that bypass the task queue and access ctx_serve...
🔗 参考:
- https://nvd.nist.gov/vuln/detail/CVE-2026-43632
- https://github.com/Vladimir-tokarev-cyera/llama-cpp-security-patches
- https://www.vulncheck.com/advisories/llama-cpp-b7492-b9060-use-after-free-in-tokenization-endpoints
7. CVE-2025-14561 `CVSS 9`
🎯 受影响:In multi-tenant deployments, the Publisher REST APIs fail to enforce tenant isolation correctly. Thi
📋 简介:In multi-tenant deployments, the Publisher REST APIs fail to enforce tenant isolation correctly.
🔗 参考:
- https://nvd.nist.gov/vuln/detail/CVE-2025-14561
- https://security.docs.wso2.com/en/latest/security-announcements/security-advisories/2026/WSO2-2025-4918/
8. CVE-2026-54210 `CVSS 9.5`
🎯 受影响:Tobit Laboratories AG TeamDavid's Webbox application implements various file upload functionalities
📋 简介:Tobit Laboratories AG TeamDavid's Webbox application implements various file upload functionalities that are
vulnerable to a buffer overflow condition.
🔗 参考:
- https://nvd.nist.gov/vuln/detail/CVE-2026-54210
- https://david.tobit.software/releasenotes
- https://labs.infoguard.ch/posts/22-cves-in-david-a-secure-m365-alternative/
9. CVE-2026-54212 `CVSS 9.5`
🎯 受影响:Tobit Laboratories AG TeamDavid's Webbox application implements an API endpoint that is vulnerable t
📋 简介:Tobit Laboratories AG TeamDavid's Webbox application implements an API endpoint that is vulnerable to a
buffer overflow condition.
🔗 参考:
- https://nvd.nist.gov/vuln/detail/CVE-2026-54212
- https://david.tobit.software/releasenotes
- https://labs.infoguard.ch/posts/22-cves-in-david-a-secure-m365-alternative/
10. CVE-2026-70638 🔥 `CVSS 8.5`
🎯 受影响:llama.cpp builds b1886 through b7445
📋 简介:llama.cpp builds b1886 through b7445 contain an integer overflow vulnerability in the LLaMA-Android JNI wrapper where the new_1batch() function multiplies sizeof(llama_seq_id) by an attacker-controlled n_seq_max parameter without overflow validation, causing heap buffer alloca...
🔗 参考:
- https://nvd.nist.gov/vuln/detail/CVE-2026-70638
- https://github.com/ggml-org/llama.cpp/releases/tag/b7446
- https://github.com/ggml-org/llama.cpp/commit/5c0d18881e0e9794c96b2602736b758bac9d9388
- https://github.com/Vladimir-tokarev-cyera/llama-cpp-security-patches
- https://www.vulncheck.com/advisories/llama-cpp-b1886-b7445-integer-overflow-via-new-1batch-in-llama-android-cpp
11. CVE-2026-17601 `CVSS 8.9`
🎯 受影响:A user holding a permission to update privilege definitions could modify a wildcard privilege alread
📋 简介:A user holding a permission to update privilege definitions could modify a wildcard privilege already assigned to their own role to grant broader permissions than they were authorized to hold, including full administrative access, without any additional authorization check or ...
🔗 参考:
- https://nvd.nist.gov/vuln/detail/CVE-2026-17601
- https://help.sonatype.com/en/sonatype-nexus-repository-3-95-0-release-notes.html
- https://support.sonatype.com/hc/en-us/articles/53889365883539/
12. CVE-2026-18258 `CVSS 8.8`
🎯 受影响:Authorization bypass in the Line, LineTranscription, VirtualCollection, tag and process API endpoint
📋 简介:Authorization bypass in the Line, LineTranscription, VirtualCollection, tag and process API endpoints in Scripta/eScriptorium through 26.04.1 allows a remote authenticated user to read, modify and delete other users' transcription content via primary keys supplied in the reque...
🔗 参考:
- https://nvd.nist.gov/vuln/detail/CVE-2026-18258
- https://gitlab.com/scripta/escriptorium/-/work_items/1226
13. CVE-2026-48169 `CVSS 8.8`
🎯 受影响:PraisonAI
📋 简介:PraisonAI is a multi-agent teams system.
🔗 参考:
- https://nvd.nist.gov/vuln/detail/CVE-2026-48169
- https://github.com/MervinPraison/PraisonAI/security/advisories/GHSA-gv23-xrm3-8c62
- https://github.com/pypa/advisory-database/tree/main/vulns/praisonai-platform/PYSEC-2026-2935.yaml
14. CVE-2026-62857 `CVSS 8.8`
🎯 受影响:Fedify
📋 简介:Fedify is a TypeScript library for building federated server apps powered by ActivityPub.
🔗 参考:
- https://nvd.nist.gov/vuln/detail/CVE-2026-62857
- https://github.com/fedify-dev/fedify/security/advisories/GHSA-hqph-j65v-8cq5
- https://github.com/fedify-dev/fedify/releases/tag/2.3.2
15. CVE-2026-17600 `CVSS 8.7`
🎯 受影响:Sonatype Nexus Repository 3 did not immediately terminate a user's active login session or revoke th
📋 简介:Sonatype Nexus Repository 3 did not immediately terminate a user's active login session or revoke their cached permissions when that user's account was deleted, deactivated, or had its password changed.
🔗 参考:
- https://nvd.nist.gov/vuln/detail/CVE-2026-17600
- https://help.sonatype.com/en/sonatype-nexus-repository-3-95-0-release-notes.html
- https://support.sonatype.com/hc/en-us/articles/53888843674003/
16. CVE-2026-70559 🔥 `CVSS 8.7`
🎯 受影响:Dinky's SysConfigController.getAll() handler for GET /api/sysConfig/getAll carries a method-level @S
📋 简介:Dinky's SysConfigController.getAll() handler for GET /api/sysConfig/getAll carries a method-level @SaIgnore annotation that short-circuits the class-level @SaCheckLogin, so the Sa-Token interceptor lets the request through with no session or role check.
🔗 参考:
- https://nvd.nist.gov/vuln/detail/CVE-2026-70559
- https://github.com/DataLinkDC/dinky
- https://github.com/DataLinkDC/dinky/issues/4567
- https://github.com/DataLinkDC/dinky/security/advisories/GHSA-c48m-x2xw-32rj
- https://sploitus.com/exploit?id=F508CCB0-9B78-5301-AE19-42C908F6349F&utm_source=rss&utm_medium=rss
17. CVE-2026-19111 `CVSS 8.6`
🎯 受影响:Insecure direct object reference in the mongodb_memory, elasticsearch_memory, and mem0_memory tools
📋 简介:Insecure direct object reference in the mongodb_memory, elasticsearch_memory, and mem0_memory tools in Amazon Strands Agents Tools before 0.8.3 might allow remote authenticated users to access, modify, or delete memories belonging to other tenants by influencing the LLM to emi...
🔗 参考:
- https://nvd.nist.gov/vuln/detail/CVE-2026-19111
- https://pypi.org/project/strands-agents-tools/0.8.3/
- https://aws.amazon.com/security/security-bulletins/2026-077-aws/
- https://github.com/strands-agents/tools/security/advisories/GHSA-mpxq-953j-42m4
18. CVE-2026-67261 `CVSS 9.8`
🎯 受影响:Dell Virtual Storage Integrator for VMware vSphere Client, versions prior to 10.11.1.0, contain(s) a
📋 简介:Dell Virtual Storage Integrator for VMware vSphere Client, versions prior to 10.11.1.0, contain(s) an OS Command Injection vulnerability in the IAPI component.
🔗 参考:
- https://nvd.nist.gov/vuln/detail/CVE-2026-67261
- https://www.dell.com/support/kbdoc/en-us/000496035/dsa-2026-335-security-update-for-dell-virtual-storage-integrator-for-vmware-vsphere-client-multiple-vulnerabilities
19. CVE-2026-71445 `CVSS 8.2`
🎯 受影响:AIL Framework
📋 简介:AIL Framework contained a reflected cross-site scripting vulnerability in the /tag/add_tags endpoint.
🔗 参考:
- https://nvd.nist.gov/vuln/detail/CVE-2026-71445
- https://github.com/ail-project/ail-framework/commit/4faf5117b15b4a6208d56f8c54f51c58b87eb007
20. CVE-2026-48080 `CVSS 8`
🎯 受影响:OpenReception's appointment booking software provides an end-to-end encrypted appointment booking pl
📋 简介:OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform.
🔗 参考:
- https://nvd.nist.gov/vuln/detail/CVE-2026-48080
- https://github.com/open-reception/appointment-booking-software/security/advisories/GHSA-v7fw-6xpm-7gj9
- https://github.com/open-reception/appointment-booking-software/commit/ad9e49e3cf66b0cc9a327f6d8a895b23bbd6fea9
21. CVE-2026-53983 `CVSS 9.2`
🎯 受影响:Ground Station
📋 简介:Ground Station prior to 0.6.0 contains an unauthenticated blind server-side request forgery vulnerability in the orbital-source configuration path that allows any unauthenticated Socket.IO client to cause the ground-station process to issue outbound HTTP requests to attacker-c...
🔗 参考:
- https://nvd.nist.gov/vuln/detail/CVE-2026-53983
- https://github.com/sgoudelis/ground-station
- https://github.com/sgoudelis/ground-station/security/advisories/GHSA-mjp8-x6h7-229q
- https://github.com/sgoudelis/ground-station/commit/2ecde82a8814cbea18883ce023bf45cbf06172eb
22. CVE-2026-54213 `CVSS 9.2`
🎯 受影响:Tobit Laboratories AG TeamDavid's Webbox application exposes a functionality that allows the server
📋 简介:Tobit Laboratories AG TeamDavid's Webbox application exposes a functionality that allows the server to be
shut down when a specific endpoint (/internalRestart) is accessed.
🔗 参考:
- https://nvd.nist.gov/vuln/detail/CVE-2026-54213
- https://david.tobit.software/releasenotes
- https://labs.infoguard.ch/posts/22-cves-in-david-a-secure-m365-alternative/
23. CVE-2026-54489 `CVSS 9.1`
🎯 受影响:Dell Virtual Storage Integrator for VMware vSphere Client, versions prior to 10.11.1.0, contain(s) a
📋 简介:Dell Virtual Storage Integrator for VMware vSphere Client, versions prior to 10.11.1.0, contain(s) a Sensitive Information Disclosure vulnerability.
🔗 参考:
- https://nvd.nist.gov/vuln/detail/CVE-2026-54489
- https://www.dell.com/support/kbdoc/en-us/000496035/dsa-2026-335-security-update-for-dell-virtual-storage-integrator-for-vmware-vsphere-client-multiple-vulnerabilities
24. CVE-2026-54211 `CVSS 9.5`
🎯 受影响:Tobit Laboratories AG TeamDavid's Webbox application’s endpoint “//serverClient_close.html” is vulne
📋 简介:Tobit Laboratories AG TeamDavid's Webbox application’s endpoint “//serverClient_close.html” is vulnerable to a
buffer overflow vulnerability in multiple form data parameters.
🔗 参考:
- https://nvd.nist.gov/vuln/detail/CVE-2026-54211
- https://david.tobit.software/releasenotes
- https://labs.infoguard.ch/posts/22-cves-in-david-a-secure-m365-alternative/
25. CVE-2026-65553 `CVSS 10`
🎯 受影响:Unauthenticated Remote Code Execution (RCE) in Spider Analyser – WordPress搜索引擎蜘蛛分析插件 <= 2.1.3
📋 简介:Unauthenticated Remote Code Execution (RCE) in Spider Analyser – WordPress搜索引擎蜘蛛分析插件 <= 2.1.3 versions.
🔗 参考:
- https://nvd.nist.gov/vuln/detail/CVE-2026-65553
- https://patchstack.com/database/wordpress/plugin/spider-analyser/vulnerability/wordpress-spider-analyser-wordpress-plugin-2-1-3-remote-code-execution-rce-vulnerability?_s_id=cve
26. CVE-2022-4995 `CVSS 9.8`
🎯 受影响:Weaver (Fanwei) E-cology 9.0 versions prior to 10.52 contain a file upload vulnerability that allows
📋 简介:Weaver (Fanwei) E-cology 9.0 versions prior to 10.52 contain a file upload vulnerability that allows a remote, unauthenticated attacker to upload arbitrary files, including JSP webshells, by submitting a multipart/form-data POST request to /workrelate/plan/util/uploaderOperate...
🔗 参考:
- https://nvd.nist.gov/vuln/detail/CVE-2022-4995
- https://www.weaver.com.cn/cs/securityDownload.html#
- https://www.weaver.com.cn/cs/ecology_full_log_en.html
- https://cn-sec.com/archives/1208148.html
- https://ch0x01e.github.io/post/ecology9-wen-jian-shang-chuan-fen-xi/
27. CVE-2026-18367 `CVSS 9.3`
🎯 受影响:A privilege escalation vulnerability
📋 简介:A privilege escalation vulnerability allows local users to execute arbitrary code as root via Sophos Endpoint for macOS older than version 2026.1.1 and Sophos Home for macOS older than version 10.11.6.
🔗 参考:
- https://nvd.nist.gov/vuln/detail/CVE-2026-18367
- https://www.sophos.com/security-advisories/sophos-sa-20260806-ep-macos-lpe
28. CVE-2026-28005 `CVSS 9.8`
🎯 受影响:Unauthenticated Privilege Escalation in Kadence WooCommerce Email Designer <= 1.5.19 versions.
📋 简介:Unauthenticated Privilege Escalation in Kadence WooCommerce Email Designer <= 1.5.19 versions.
🔗 参考:
- https://nvd.nist.gov/vuln/detail/CVE-2026-28005
- https://patchstack.com/database/wordpress/plugin/kadence-woocommerce-email-designer/vulnerability/wordpress-kadence-woocommerce-email-designer-plugin-1-5-19-privilege-escalation-vulnerability?_s_id=cve
29. CVE-2026-65507 `CVSS 9.8`
🎯 受影响:Unauthenticated Privilege Escalation in AIWU <= 1.5.6 versions.
📋 简介:Unauthenticated Privilege Escalation in AIWU <= 1.5.6 versions.
🔗 参考:
- https://nvd.nist.gov/vuln/detail/CVE-2026-65507
- https://patchstack.com/database/wordpress/plugin/ai-copilot-content-generator/vulnerability/wordpress-aiwu-plugin-1-5-6-privilege-escalation-vulnerability?_s_id=cve
30. CVE-2026-66662 `CVSS 9.8`
🎯 受影响:Unauthenticated Privilege Escalation in Frontend Admin by DynamiApps <= 3.29.10 versions.
📋 简介:Unauthenticated Privilege Escalation in Frontend Admin by DynamiApps <= 3.29.10 versions.
🔗 参考:
- https://nvd.nist.gov/vuln/detail/CVE-2026-66662
- https://patchstack.com/database/wordpress/plugin/acf-frontend-form-element/vulnerability/wordpress-frontend-admin-by-dynamiapps-plugin-3-29-10-privilege-escalation-vulnerability?_s_id=cve
31. CVE-2026-11976 `CVSS 10`
🎯 受影响:The official MonsterInsights Pro update distribution bucket (`monster-insights.s3.amazonaws.com`) wa
📋 简介:The official MonsterInsights Pro update distribution bucket (`monster-insights.s3.amazonaws.com`) was compromised.
🔗 参考:
- https://nvd.nist.gov/vuln/detail/CVE-2026-11976
- https://wpscan.com/vulnerability/d1250410-b919-4a90-8cf2-04031f9e5e2b/
32. CVE-2026-64637 `CVSS 9.9`
🎯 受影响:Improper privilege management in the XML-RPC API of Plesk
📋 简介:Improper privilege management in the XML-RPC API of Plesk before 18.0.80, allows an authenticated reseller to obtain an administrative session for the root user account.
🔗 参考:
- https://nvd.nist.gov/vuln/detail/CVE-2026-64637
- https://support.plesk.com/hc/en-us/articles/42432168683799
33. CVE-2026-70558 `CVSS 9.8`
🎯 受影响:Dinky's POST /download/uploadFromRsByLocal handler passes the caller-supplied path parameter directl
📋 简介:Dinky's POST /download/uploadFromRsByLocal handler passes the caller-supplied path parameter directly to new File(path) and file.transferTo(dest) with no path validation.
🔗 参考:
- https://nvd.nist.gov/vuln/detail/CVE-2026-70558
- https://github.com/DataLinkDC/dinky
- https://github.com/DataLinkDC/dinky/issues/4566
- https://github.com/DataLinkDC/dinky/security/advisories/GHSA-2p66-w3p3-5226
34. CVE-2026-43631 `CVSS 9.2`
🎯 受影响:llama.cpp builds b7492 through the latest b9060
📋 简介:llama.cpp builds b7492 through the latest b9060 contains a use-after-free vulnerability in the vocab pointer of llama-server when the --sleep-idle-seconds feature is enabled, allowing unauthenticated remote attackers to execute arbitrary code.
🔗 参考:
- https://nvd.nist.gov/vuln/detail/CVE-2026-43631
- https://github.com/Vladimir-tokarev-cyera/llama-cpp-security-patches
- https://www.vulncheck.com/advisories/llama-cpp-b7492-b9060-use-after-free-rce-via-llama-server
35. CVE-2026-46409 `CVSS 9.6`
🎯 受影响:OpenYak
📋 简介:OpenYak is a local-first agent runtime for reliable tool-using models, with a desktop workspace built on top.
🔗 参考:
- https://nvd.nist.gov/vuln/detail/CVE-2026-46409
- https://github.com/openyak/openyak/security/advisories/GHSA-ccxp-q2w5-27jw
36. CVE-2026-66665 `CVSS 10`
🎯 受影响:Unauthenticated Arbitrary File Upload in Type Hub <= 2.0.6 versions.
📋 简介:Unauthenticated Arbitrary File Upload in Type Hub <= 2.0.6 versions.
🔗 参考:
- https://nvd.nist.gov/vuln/detail/CVE-2026-66665
- https://patchstack.com/database/wordpress/plugin/typehub/vulnerability/wordpress-type-hub-plugin-2-0-6-arbitrary-file-upload-vulnerability?_s_id=cve
37. CVE-2026-17032 `CVSS 9.8`
🎯 受影响:Multiple Supsystic Pro plugins were distributed with malicious code through the vendor's compromised
📋 简介:Multiple Supsystic Pro plugins were distributed with malicious code through the vendor's compromised update server, allowing unauthenticated attackers to deploy a second-stage payload that exfiltrates credentials and other sensitive data and grants full control of affected sites.
🔗 参考:
- https://nvd.nist.gov/vuln/detail/CVE-2026-17032
- https://wpscan.com/vulnerability/7ca5ad30-1792-4014-bfad-88911cd64713/
38. CVE-2026-19264 `CVSS 9.8`
🎯 受影响:Postiz
📋 简介:Postiz is an open-source social media scheduling tool.
🔗 参考:
- https://nvd.nist.gov/vuln/detail/CVE-2026-19264
- https://github.com/gitroomhq/postiz-app/commit/7936062
- https://github.com/gitroomhq/postiz-app/releases/tag/v2.22.1
- https://gadvisory.org/advisories/PSA-2026-TH12B7
39. CVE-2026-28139 `CVSS 9.8`
🎯 受影响:Unauthenticated PHP Object Injection in Ajax Search Lite <= 4.14.4 versions.
📋 简介:Unauthenticated PHP Object Injection in Ajax Search Lite <= 4.14.4 versions.
🔗 参考:
- https://nvd.nist.gov/vuln/detail/CVE-2026-28139
- https://patchstack.com/database/wordpress/plugin/ajax-search-lite/vulnerability/wordpress-ajax-search-lite-plugin-4-14-4-php-object-injection-vulnerability?_s_id=cve
40. CVE-2026-48085 `CVSS 9.8`
🎯 受影响:OpenReception's appointment booking software provides an end-to-end encrypted appointment booking pl
📋 简介:OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform.
🔗 参考:
- https://nvd.nist.gov/vuln/detail/CVE-2026-48085
- https://github.com/open-reception/appointment-booking-software/security/advisories/GHSA-qvvq-hhpj-64rp
- https://github.com/open-reception/appointment-booking-software/commit/222408af6fd4bd85554a25ec8de8131bd0733797
41. CVE-2026-48087 `CVSS 9.8`
🎯 受影响:OpenReception's appointment booking software provides an end-to-end encrypted appointment booking pl
📋 简介:OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform.
🔗 参考:
- https://nvd.nist.gov/vuln/detail/CVE-2026-48087
- https://github.com/open-reception/appointment-booking-software/security/advisories/GHSA-j9rw-x2wv-h5rj
- https://github.com/open-reception/appointment-booking-software/commit/5f61a2116d68378366edd712c343a9de7b205a74
42. CVE-2026-65556 `CVSS 9.8`
🎯 受影响:Unauthenticated PHP Object Injection in WPBruiser {no- Captcha anti-Spam} <= 3.1.43 versions.
📋 简介:Unauthenticated PHP Object Injection in WPBruiser {no- Captcha anti-Spam} <= 3.1.43 versions.
🔗 参考:
- https://nvd.nist.gov/vuln/detail/CVE-2026-65556
- https://patchstack.com/database/wordpress/plugin/goodbye-captcha/vulnerability/wordpress-wpbruiser-no-captcha-anti-spam-plugin-3-1-43-php-object-injection-vulnerability?_s_id=cve
43. CVE-2026-65571 `CVSS 9.8`
🎯 受影响:Unauthenticated PHP Object Injection in 69 Clothing <= 1.2.11.1 versions.
📋 简介:Unauthenticated PHP Object Injection in 69 Clothing <= 1.2.11.1 versions.
🔗 参考:
- https://nvd.nist.gov/vuln/detail/CVE-2026-65571
- https://patchstack.com/database/wordpress/theme/clothing69/vulnerability/wordpress-69-clothing-theme-1-2-11-1-php-object-injection-vulnerability?_s_id=cve
44. CVE-2026-65572 `CVSS 9.8`
🎯 受影响:Unauthenticated PHP Object Injection in A.Williams <= 1.3.1 versions.
📋 简介:Unauthenticated PHP Object Injection in A.Williams <= 1.3.1 versions.
🔗 参考:
- https://nvd.nist.gov/vuln/detail/CVE-2026-65572
- https://patchstack.com/database/wordpress/theme/alisha-williams/vulnerability/wordpress-a-williams-theme-1-3-1-php-object-injection-vulnerability?_s_id=cve
45. CVE-2026-65573 `CVSS 9.8`
🎯 受影响:Unauthenticated PHP Object Injection in Abelle <= 1.22 versions.
📋 简介:Unauthenticated PHP Object Injection in Abelle <= 1.22 versions.
🔗 参考:
- https://nvd.nist.gov/vuln/detail/CVE-2026-65573
- https://patchstack.com/database/wordpress/theme/abelle/vulnerability/wordpress-abelle-theme-1-22-php-object-injection-vulnerability?_s_id=cve
46. CVE-2026-65574 `CVSS 9.8`
🎯 受影响:Unauthenticated PHP Object Injection in Abogado <= 1.18 versions.
📋 简介:Unauthenticated PHP Object Injection in Abogado <= 1.18 versions.
🔗 参考:
- https://nvd.nist.gov/vuln/detail/CVE-2026-65574
- https://patchstack.com/database/wordpress/theme/abogado/vulnerability/wordpress-abogado-theme-1-18-php-object-injection-vulnerability?_s_id=cve
47. CVE-2026-65575 `CVSS 9.8`
🎯 受影响:Unauthenticated PHP Object Injection in Accalia <= 1.5.3 versions.
📋 简介:Unauthenticated PHP Object Injection in Accalia <= 1.5.3 versions.
🔗 参考:
- https://nvd.nist.gov/vuln/detail/CVE-2026-65575
- https://patchstack.com/database/wordpress/theme/accalia/vulnerability/wordpress-accalia-theme-1-5-3-php-object-injection-vulnerability?_s_id=cve
48. CVE-2026-65576 `CVSS 9.8`
🎯 受影响:Unauthenticated PHP Object Injection in Adrena <= 1.2.14 versions.
📋 简介:Unauthenticated PHP Object Injection in Adrena <= 1.2.14 versions.
🔗 参考:
- https://nvd.nist.gov/vuln/detail/CVE-2026-65576
- https://patchstack.com/database/wordpress/theme/adrena/vulnerability/wordpress-adrena-theme-1-2-14-php-object-injection-vulnerability?_s_id=cve
49. CVE-2026-65577 `CVSS 9.8`
🎯 受影响:Unauthenticated PHP Object Injection in Advice <= 1.18.0 versions.
📋 简介:Unauthenticated PHP Object Injection in Advice <= 1.18.0 versions.
🔗 参考:
- https://nvd.nist.gov/vuln/detail/CVE-2026-65577
- https://patchstack.com/database/wordpress/theme/advice/vulnerability/wordpress-advice-theme-1-18-0-php-object-injection-vulnerability?_s_id=cve
50. CVE-2026-65578 `CVSS 9.8`
🎯 受影响:Unauthenticated PHP Object Injection in Agora <= 1.9 versions.
📋 简介:Unauthenticated PHP Object Injection in Agora <= 1.9 versions.
🔗 参考:
- https://nvd.nist.gov/vuln/detail/CVE-2026-65578
- https://patchstack.com/database/wordpress/theme/agora/vulnerability/wordpress-agora-theme-1-9-php-object-injection-vulnerability?_s_id=cve
51. CVE-2026-65579 `CVSS 9.8`
🎯 受影响:Unauthenticated PHP Object Injection in Agricola <= 1.21.0 versions.
📋 简介:Unauthenticated PHP Object Injection in Agricola <= 1.21.0 versions.
🔗 参考:
- https://nvd.nist.gov/vuln/detail/CVE-2026-65579
- https://patchstack.com/database/wordpress/theme/agricola/vulnerability/wordpress-agricola-theme-1-21-0-php-object-injection-vulnerability?_s_id=cve
52. CVE-2026-65581 `CVSS 9.8`
🎯 受影响:Unauthenticated PHP Object Injection in AI ANN <= 1.29.0 versions.
📋 简介:Unauthenticated PHP Object Injection in AI ANN <= 1.29.0 versions.
🔗 参考:
- https://nvd.nist.gov/vuln/detail/CVE-2026-65581
- https://patchstack.com/database/wordpress/theme/ann/vulnerability/wordpress-ai-ann-theme-1-29-0-php-object-injection-vulnerability?_s_id=cve
53. CVE-2026-54203 `CVSS 9.2`
🎯 受影响:Memory Leak to an Unauthorized Actor vulnerability in Tobit Laboratories AG TeamDavid's Webbox allow
📋 简介:Memory Leak to an Unauthorized Actor vulnerability in Tobit Laboratories AG TeamDavid's Webbox allows reading of sensitive information.
🔗 参考:
- https://nvd.nist.gov/vuln/detail/CVE-2026-54203
- https://david.tobit.software/releasenotes
- https://labs.infoguard.ch/posts/22-cves-in-david-a-secure-m365-alternative/
54. CVE-2026-12605 `CVSS 9.6`
🎯 受影响:In Eclipse GlassFish
📋 简介:In Eclipse GlassFish versions 8.0.x before 8.0.4, CSRF + SSRF in DownloadServlet ContentSources leaks the admin `gfresttoken` to attacker-controlled host if the victim is authenticated into the Admin Console -\> full unauthenticated takeover of Eclipse GlassFish domain until t...
🔗 参考:
- https://nvd.nist.gov/vuln/detail/CVE-2026-12605
- https://gitlab.eclipse.org/security/vulnerability-reports/-/work_items/445
- https://gitlab.eclipse.org/security/cve-assignment/-/work_items/127
55. CVE-2026-48088 `CVSS 9.4`
🎯 受影响:OpenReception's appointment booking software provides an end-to-end encrypted appointment booking pl
📋 简介:OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform.
🔗 参考:
- https://nvd.nist.gov/vuln/detail/CVE-2026-48088
- https://github.com/open-reception/appointment-booking-software/security/advisories/GHSA-pch3-hcmf-cjw4
- https://github.com/open-reception/appointment-booking-software/commit/78dfd9317a0be0897e6e4d73afe670c07a75460f
56. CVE-2026-65548 `CVSS 9.9`
🎯 受影响:Contributor Remote Code Execution (RCE) in Betheme <= 28.4.2 versions.
📋 简介:Contributor Remote Code Execution (RCE) in Betheme <= 28.4.2 versions.
🔗 参考:
- https://nvd.nist.gov/vuln/detail/CVE-2026-65548
- https://patchstack.com/database/wordpress/theme/betheme/vulnerability/wordpress-betheme-theme-28-4-2-remote-code-execution-rce-vulnerability?_s_id=cve
57. CVE-2026-53976 `CVSS 9.3`
🎯 受影响:OpenChamber 1.11.7
📋 简介:OpenChamber 1.11.7 contains a path traversal vulnerability in the file-serving endpoints /api/fs/read, /api/fs/stat, and /api/fs/raw that allows unauthenticated remote attackers to read arbitrary files by supplying the allowOutsideWorkspace=true query parameter alongside an ab...
🔗 参考:
- https://nvd.nist.gov/vuln/detail/CVE-2026-53976
- https://github.com/openchamber/openchamber
- https://github.com/openchamber/openchamber/commit/f1b9506132faf6c564a2694c7f33b94421a49b4a
- https://www.vulncheck.com/advisories/openchamber-path-traversal-file-read-via-allowoutsideworkspace-parameter
58. CVE-2026-65508 `CVSS 9.3`
🎯 受影响:Unauthenticated SQL Injection in Simply Schedule Appointments <= 1.6.12.10 versions.
📋 简介:Unauthenticated SQL Injection in Simply Schedule Appointments <= 1.6.12.10 versions.
🔗 参考:
- https://nvd.nist.gov/vuln/detail/CVE-2026-65508
- https://patchstack.com/database/wordpress/plugin/simply-schedule-appointments/vulnerability/wordpress-simply-schedule-appointments-plugin-1-6-12-10-sql-injection-vulnerability?_s_id=cve
59. CVE-2026-65520 `CVSS 9.3`
🎯 受影响:Unauthenticated SQL Injection in WP OAuth Server <= 6.2.0 versions.
📋 简介:Unauthenticated SQL Injection in WP OAuth Server <= 6.2.0 versions.
🔗 参考:
- https://nvd.nist.gov/vuln/detail/CVE-2026-65520
- https://patchstack.com/database/wordpress/plugin/miniorange-oauth-20-server/vulnerability/wordpress-wp-oauth-server-plugin-6-2-0-sql-injection-vulnerability?_s_id=cve
60. CVE-2026-65546 `CVSS 9.3`
🎯 受影响:Unauthenticated SQL Injection in Qode Tours <= 3.1.3.1 versions.
📋 简介:Unauthenticated SQL Injection in Qode Tours <= 3.1.3.1 versions.
🔗 参考:
- https://nvd.nist.gov/vuln/detail/CVE-2026-65546
- https://patchstack.com/database/wordpress/plugin/qode-tours/vulnerability/wordpress-qode-tours-plugin-3-1-3-1-sql-injection-vulnerability?_s_id=cve
61. CVE-2026-66447 `CVSS 9.3`
🎯 受影响:Unauthenticated SQL Injection in WordPress File Upload <= 5.1.7 versions.
📋 简介:Unauthenticated SQL Injection in WordPress File Upload <= 5.1.7 versions.
🔗 参考:
- https://nvd.nist.gov/vuln/detail/CVE-2026-66447
- https://patchstack.com/database/wordpress/plugin/wp-file-upload/vulnerability/wordpress-wordpress-file-upload-plugin-5-1-7-sql-injection-vulnerability?_s_id=cve
62. CVE-2026-66914 `CVSS 9.2`
🎯 受影响:Joomla Extension - seblod.com - Unauthenticated path traversal in SEBLOD < 3.30.0, < 4.7.0, < 6.0.1
📋 简介:Joomla Extension - seblod.com - Unauthenticated path traversal in SEBLOD < 3.30.0, < 4.7.0, < 6.0.1 - An unauthenticated attacker could download files from both inside and outside the webroot.
🔗 参考:
63. CVE-2026-48039 `CVSS 9.1`
🎯 受影响:Meta Ads MCP
📋 简介:Meta Ads MCP is a Model Context Protocol (MCP) server that lets AI assistants run Meta Ads.
🔗 参考:
- https://nvd.nist.gov/vuln/detail/CVE-2026-48039
- https://github.com/pipeboard-co/meta-ads-mcp/security/advisories/GHSA-9gw6-46qc-99vr
- https://github.com/pipeboard-co/meta-ads-mcp/releases/tag/1.0.109
- https://github.com/pypa/advisory-database/tree/main/vulns/meta-ads-mcp/PYSEC-2026-413.yaml
64. CVE-2026-53984 `CVSS 9.1`
🎯 受影响:Ground Station
📋 简介:Ground Station prior to 0.6.0 contains an unauthenticated database-destruction and arbitrary-data-injection vulnerability in the Socket.IO server's database_backup event handler that allows any unauthenticated network peer to wipe or replace the entire SQLite database by sendi...
🔗 参考:
- https://nvd.nist.gov/vuln/detail/CVE-2026-53984
- https://github.com/sgoudelis/ground-station
- https://github.com/sgoudelis/ground-station/security/advisories/GHSA-mjp8-x6h7-229q
- https://github.com/sgoudelis/ground-station/commit/2ecde82a8814cbea18883ce023bf45cbf06172eb
65. CVE-2026-5857 `CVSS 9.2`
🎯 受影响:Contiki-NG's MQTT client parse_publish_vhdr() in os/net/app-layer/mqtt/mqtt.c sets topic_len_receive
📋 简介:Contiki-NG's MQTT client parse_publish_vhdr() in os/net/app-layer/mqtt/mqtt.c sets topic_len_received=1 before checking topic_len against the 64-byte limit, so an over-length topic returns early but leaves the flag set.
🔗 参考:
- https://nvd.nist.gov/vuln/detail/CVE-2026-5857
- https://github.com/contiki-ng/contiki-ng
- https://github.com/contiki-ng/contiki-ng/pull/3163
- https://github.com/contiki-ng/contiki-ng/commit/a34a2dbdc8bea784bd2ae5079aa4be520cd74f2d
66. CVE-2026-3418 `CVSS 9.1`
🎯 受影响:The System REST API accepts user-supplied file uploads without enforcing sufficient validation on th
📋 简介:The System REST API accepts user-supplied file uploads without enforcing sufficient validation on the file type or destination, allowing files to be written to arbitrary server-accessible locations.
🔗 参考:
- https://nvd.nist.gov/vuln/detail/CVE-2026-3418
- https://security.docs.wso2.com/en/latest/security-announcements/security-advisories/2026/WSO2-2026-5146/
67. CVE-2026-66709 `CVSS 9.1`
🎯 受影响:Shop manager Remote Code Execution (RCE) in CTX Feed <= 6.6.42 versions.
📋 简介:Shop manager Remote Code Execution (RCE) in CTX Feed <= 6.6.42 versions.
🔗 参考:
- https://nvd.nist.gov/vuln/detail/CVE-2026-66709
- https://patchstack.com/database/wordpress/plugin/webappick-product-feed-for-woocommerce/vulnerability/wordpress-ctx-feed-plugin-6-6-42-remote-code-execution-rce-vulnerability?_s_id=cve
68. CVE-2026-56162 `CVSS 10`
🎯 受影响:
📋 简介:
🔗 参考:
- https://nvd.nist.gov/vuln/detail/CVE-2026-56162
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-56162
69. CVE-2026-5430 `CVSS 10`
🎯 受影响:The JWT authentication mechanism accepts tokens signed with algorithms other than those explicitly configured or supported. This
📋 简介:The JWT authentication mechanism accepts tokens signed with algorithms other than those explicitly configured or supported.
🔗 参考:
- https://nvd.nist.gov/vuln/detail/CVE-2026-5430
- https://security.docs.wso2.com/en/latest/security-announcements/security-advisories/2026/WSO2-2026-5328/
70. CVE-2026-63508 `CVSS 10`
🎯 受影响:
📋 简介:
🔗 参考:
- https://nvd.nist.gov/vuln/detail/CVE-2026-63508
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-63508
71. CVE-2026-65667 `CVSS 10`
🎯 受影响:
📋 简介:
🔗 参考:
- https://nvd.nist.gov/vuln/detail/CVE-2026-65667
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-65667
72. CVE-2026-50481 `CVSS 9.9`
🎯 受影响:
📋 简介:
🔗 参考:
- https://nvd.nist.gov/vuln/detail/CVE-2026-50481
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50481
73. CVE-2026-50515 `CVSS 9.9`
🎯 受影响:
📋 简介:
🔗 参考:
- https://nvd.nist.gov/vuln/detail/CVE-2026-50515
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50515
74. CVE-2026-59115 `CVSS 9.9`
🎯 受影响:
📋 简介:
🔗 参考:
- https://nvd.nist.gov/vuln/detail/CVE-2026-59115
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-59115
75. CVE-2026-62830 `CVSS 9.9`
🎯 受影响:
📋 简介:
🔗 参考:
- https://nvd.nist.gov/vuln/detail/CVE-2026-62830
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62830
76. CVE-2026-1728 `CVSS 9.8`
🎯 受影响:Tokens issued to a low-privileged user are not sufficiently restricted, allowing them to be used to
📋 简介:Tokens issued to a low-privileged user are not sufficiently restricted, allowing them to be used to access product-level Admin REST APIs.
🔗 参考:
- https://nvd.nist.gov/vuln/detail/CVE-2026-1728
- https://security.docs.wso2.com/en/latest/security-announcements/security-advisories/2026/WSO2-2026-5077/
77. CVE-2026-5134 `CVSS 9.8`
🎯 受影响:Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability i
📋 简介:Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Loca Software Informatics Technology Ltd.
🔗 参考:
- https://nvd.nist.gov/vuln/detail/CVE-2026-5134
- https://siberguvenlik.gov.tr/guvenlik-bildirimleri/detay/tr-26-0771
78. CVE-2026-62873 `CVSS 9.8`
🎯 受影响:
📋 简介:
🔗 参考:
- https://nvd.nist.gov/vuln/detail/CVE-2026-62873
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62873
79. CVE-2026-65552 `CVSS 9.8`
🎯 受影响:Subscriber PHP Object Injection in Export User Data <= 2.2.6 versions.
📋 简介:Subscriber PHP Object Injection in Export User Data <= 2.2.6 versions.
🔗 参考:
- https://nvd.nist.gov/vuln/detail/CVE-2026-65552
- https://patchstack.com/database/wordpress/plugin/export-user-data/vulnerability/wordpress-export-user-data-plugin-2-2-6-php-object-injection-vulnerability?_s_id=cve
80. CVE-2026-50540 `CVSS 9.6`
🎯 受影响:Kata Containers
📋 简介:Kata Containers is an open source project focusing on a standard implementation of lightweight Virtual Machines (VMs) that perform like containers.
🔗 参考:
- https://nvd.nist.gov/vuln/detail/CVE-2026-50540
- https://github.com/kata-containers/kata-containers/security/advisories/GHSA-mp2j-xm59-qfgw
- https://github.com/kata-containers/kata-containers/commit/03cc670076099530f4e1e9cb22849afdafb20f65
81. CVE-2026-56161 `CVSS 9.6`
🎯 受影响:
📋 简介:
🔗 参考:
- https://nvd.nist.gov/vuln/detail/CVE-2026-56161
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-56161
82. CVE-2026-62896 `CVSS 9.6`
🎯 受影响:
📋 简介:
🔗 参考:
- https://nvd.nist.gov/vuln/detail/CVE-2026-62896
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62896
83. CVE-2026-70332 `CVSS 9.6`
🎯 受影响:
📋 简介:
🔗 参考:
- https://nvd.nist.gov/vuln/detail/CVE-2026-70332
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-70332
84. CVE-2025-15039 `CVSS 9.4`
🎯 受影响:The Conditional Authentication (Adaptive Authentication) script does not correctly enforce the compl
📋 简介:The Conditional Authentication (Adaptive Authentication) script does not correctly enforce the completion of all required authentication steps when a specific multi-step pattern involving certain authenticators is configured.
🔗 参考:
- https://nvd.nist.gov/vuln/detail/CVE-2025-15039
- https://security.docs.wso2.com/en/latest/security-announcements/security-advisories/2026/WSO2-2025-4973/
85. CVE-2026-59118 `CVSS 9.3`
🎯 受影响:
📋 简介:
🔗 参考:
- https://nvd.nist.gov/vuln/detail/CVE-2026-59118
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-59118
86. CVE-2026-43629 `CVSS 9.2`
🎯 受影响:llama.cpp builds b4882 through b9058
📋 简介:llama.cpp builds b4882 through b9058 contain a heap buffer overflow vulnerability in the KV cache state restore path where the state_read_data() function computes write size without overflow checking, allowing attackers with write access to the slot_save_path directory to corr...
🔗 参考:
- https://nvd.nist.gov/vuln/detail/CVE-2026-43629
- https://github.com/Vladimir-tokarev-cyera/llama-cpp-security-patches
- https://www.vulncheck.com/advisories/llama-cpp-b4882-b9058-buffer-overflow-in-kv-cache-state-restore
87. CVE-2026-47243 `CVSS 9.2`
🎯 受影响:Kata Containers
📋 简介:Kata Containers is an open source project focusing on a standard implementation of lightweight Virtual Machines (VMs) that perform like containers.
🔗 参考:
- https://nvd.nist.gov/vuln/detail/CVE-2026-47243
- https://github.com/kata-containers/kata-containers/security/advisories/GHSA-2gv2-cffp-j227
88. CVE-2026-48170 `CVSS 9.1`
🎯 受影响:`scim-patch`, a library to perform SCIM patch, prior to version 0.9.1 performs prototype pollution w
📋 简介:`scim-patch`, a library to perform SCIM patch, prior to version 0.9.1 performs prototype pollution when applying a SCIM PATCH operation whose `value` object contains a key like `"__proto__.someProp"`.
🔗 参考:
- https://nvd.nist.gov/vuln/detail/CVE-2026-48170
- https://github.com/thomaspoignant/scim-patch/security/advisories/GHSA-9m6g-wc8r-q59c
- https://github.com/thomaspoignant/scim-patch/commit/260f9cd2ac5ceac3976978850bb47dcb391720f6
89. CVE-2026-68823 `CVSS 9.1`
🎯 受影响:
📋 简介:
🔗 参考:
- https://nvd.nist.gov/vuln/detail/CVE-2026-68823
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-68823
90. CVE-2026-71851 `CVSS 9`
🎯 受影响:crypto-js
📋 简介:crypto-js is a JavaScript library of crypto standards.
🔗 参考:
- https://nvd.nist.gov/vuln/detail/CVE-2026-71851
- https://github.com/brix/crypto-js/security/advisories/GHSA-rg76-677x-56q9
- https://github.com/brix/crypto-js/commit/b405ff597fb3ac76a7bdfbc72dca10ba1079b1d5
- https://www.coinspect.com/blog/ill-bloom-investigation
🟠 HIGH · 10 条
1. CVE-2021-3156 🔥 ⚡近期活跃 `CVSS 7.8`
🎯 受影响:Sudo
📋 简介:Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege escalation to root via "sudoedit -s" and a command-line argument that ends with a single backslash character.
🔗 参考:
- https://nvd.nist.gov/vuln/detail/CVE-2021-3156
- http://packetstormsecurity.com/files/161160/Sudo-Heap-Based-Buffer-Overflow.html
- http://packetstormsecurity.com/files/161230/Sudo-Buffer-Overflow-Privilege-Escalation.html
- http://packetstormsecurity.com/files/161270/Sudo-1.9.5p1-Buffer-Overflow-Privilege-Escalation.html
- http://packetstormsecurity.com/files/161293/Sudo-1.8.31p2-1.9.5p1-Buffer-Overflow.html
2. CVE-2026-67621 `CVSS 7.6`
🎯 受影响:Flowise through 3.1.4
📋 简介:Flowise through 3.1.4 contains a missing authorization vulnerability that allows authenticated workspace members to perform unauthorized document store operations by accessing unprotected mutation endpoints.
🔗 参考:
- https://nvd.nist.gov/vuln/detail/CVE-2026-67621
- https://github.com/Caycon/cve-advisories/blob/main/2026/Flowise/CVE-2026-67621.md
- https://flowiseai.com/sunset
- https://www.vulncheck.com/advisories/flowise-missing-authorization-on-document-store-mutation-endpoints
3. CVE-2026-54209 `CVSS 8.9`
🎯 受影响:Tobit Laboratories AG TeamDavid's Webbox application handles password changes using a function trigg
📋 简介:Tobit Laboratories AG TeamDavid's Webbox application handles password changes using a function triggered by
including the string "(editini)" in the file path, writing the new
password to the specified "Archive.ini" file.
🔗 参考:
- https://nvd.nist.gov/vuln/detail/CVE-2026-54209
- https://david.tobit.software/releasenotes
- https://labs.infoguard.ch/posts/22-cves-in-david-a-secure-m365-alternative/
4. CVE-2026-53985 `CVSS 8.7`
🎯 受影响:Ground Station
📋 简介:Ground Station prior to 0.6.0 contains an unauthenticated denial-of-service vulnerability in the Socket.IO server's service_control event handler that allows any unauthenticated network peer to forcibly terminate the ground-station process by sending a single restart_service c...
🔗 参考:
- https://nvd.nist.gov/vuln/detail/CVE-2026-53985
- https://github.com/sgoudelis/ground-station
- https://github.com/sgoudelis/ground-station/security/advisories/GHSA-mjp8-x6h7-229q
- https://github.com/sgoudelis/ground-station/commit/2ecde82a8814cbea18883ce023bf45cbf06172eb
5. CVE-2026-70636 `CVSS 8.7`
🎯 受影响:Flowise through 3.1.4
📋 简介:Flowise through 3.1.4 contains an authentication bypass vulnerability that allows unauthenticated attackers to access the OAuth2 credential refresh endpoint by exploiting prefix-based whitelist matching in the authentication middleware defined in packages/server/src/utils/cons...
🔗 参考:
- https://nvd.nist.gov/vuln/detail/CVE-2026-70636
- https://github.com/Caycon/cve-advisories/blob/main/2026/Flowise/CVE-2026-70636.md
- https://flowiseai.com/sunset
- https://www.vulncheck.com/advisories/flowise-authentication-bypass-via-oauth2-credential-refresh-endpoint
6. CVE-2026-54208 `CVSS 8.5`
🎯 受影响:Tobit Laboratories AG TeamDavid's Webbox application is vulnerable to arbitrary file write, allowing
📋 简介:Tobit Laboratories AG TeamDavid's Webbox application is vulnerable to arbitrary file write, allowing an
unauthenticated attacker to create or write into existing files on the
server with attacker-controlled content.
🔗 参考:
- https://nvd.nist.gov/vuln/detail/CVE-2026-54208
- https://david.tobit.software/releasenotes
- https://labs.infoguard.ch/posts/22-cves-in-david-a-secure-m365-alternative/
7. CVE-2026-54204 `CVSS 7.7`
🎯 受影响:Tobit Laboratories AG TeamDavid's Webbox 's search functionality accepts a “pathnameroot”
📋 简介:Tobit Laboratories AG TeamDavid's Webbox 's search functionality accepts a “pathnameroot”
parameter, which can be set to network locations using UNC paths (e.g.,
“\\Server\Share”).
🔗 参考:
- https://nvd.nist.gov/vuln/detail/CVE-2026-54204
- https://david.tobit.software/releasenotes
- https://labs.infoguard.ch/posts/22-cves-in-david-a-secure-m365-alternative/
8. CVE-2026-18427 `CVSS 7.5`
🎯 受影响:@fastify/static before version 10.1.3 contains an incomplete fix for a previous route guard bypass.
📋 简介:@fastify/static before version 10.1.3 contains an incomplete fix for a previous route guard bypass.
🔗 参考:
- https://nvd.nist.gov/vuln/detail/CVE-2026-18427
- https://github.com/fastify/fastify-static/security/advisories/GHSA-423g-23ch-w7c6
- https://cna.openjsf.org/security-advisories.html
9. CVE-2026-52880 `CVSS 7.5`
🎯 受影响:Klever-Go
📋 简介:Klever-Go is the Go implementation of the Klever blockchain protocol.
🔗 参考:
- https://nvd.nist.gov/vuln/detail/CVE-2026-52880
- https://github.com/klever-io/klever-go/security/advisories/GHSA-w4c6-7r69-w7j9
- https://github.com/klever-io/klever-go/releases/tag/v1.7.18
10. CVE-2026-54218 `CVSS 8.8`
🎯 受影响:Use of hard-coded cryptographic key vulnerability in Tobit Laboratories AG TeamDavid's Webbox. For u
📋 简介:Use of hard-coded cryptographic key vulnerability in Tobit Laboratories AG TeamDavid's Webbox.
🔗 参考:
- https://nvd.nist.gov/vuln/detail/CVE-2026-54218
- https://david.tobit.software/releasenotes
- https://labs.infoguard.ch/posts/22-cves-in-david-a-secure-m365-alternative/
---
新发现 272 条 · 热度升级 0 条 · 🔥=高热度/有 PoC · 🆙=昨日已推、今日热度升级
📊 GitHub 热榜
📊 GitHub 日榜 · 2026-08-08
1. PrimeIntellect-ai/prime-agent
📋 用于编码工作流和长期自主任务的自改进 RLM 智能体。
📋 面向 AI 编码智能体的生产级工程技能。
📋 给你的智能体一台电脑 👾
📋 为真正工程师准备的技能,直接来自我的 .agents 目录。
📋 一套行之有效的智能体技能框架与软件开发方法论。
📋 你需要的身份验证粘合剂。
📋 面向上下文与可问责 AI 系统的图原生基础设施。
📋 简洁通用的群体智能引擎,可预测万物。
📋 面向 Grok Build、Grok Web 和 Grok Console 的多账户 API 网关。
10. jdx/mise
📋 开发工具、环境变量、任务运行器。
🤖 AI 总结分析
今日安全形势异常严峻,高危漏洞预警多达 90 条 CRITICAL,规模罕见,热点集中在 AI 基础设施(RAG、LLM 推理、AI 工作流)以及 WordPress 等通用平台。AI 正同时沦为攻击目标与攻击工具,自主漏洞挖掘与编程代理供应链风险同步升温,GitHub 热榜也显示智能体工程化是当前技术主旋律。
漏洞预警中,Flowise CVE-2026-67622(CVSS 9.9)与 OpenChamber CVE-2026-53975(CVSS 9.8)最值得警惕:前者是 OpenAI Assistants 集成中的 IDOR,可跨工作区窃取凭据,且项目已进入 sunset 状态、修复前景不明;后者为未认证 RCE,向 /api/fs/exec 发送 POST 即可执行任意命令。此外 llama.cpp 的 use-after-free 波及版本范围较广,也需纳入排查。
安全情报显示,AI 黑客 XBOW 自主发现并利用 Bing Images 三个 RCE 是标志性事件,说明攻击侧 AI 已具备实战能力;Anthropic、谷歌、OpenAI 编程代理的漏洞则可致 RCE 与供应链攻击,直接影响开发链。今日还有 React、TeamCity、protobufjs 等高价值 PoC 公开,攻击门槛正在快速降低。
GitHub 热榜几乎被 AI 智能体项目占据,prime-agent(自改进 RLM 智能体)与 cloudflare/computer(给智能体一台电脑)代表一种趋势:智能体正从辅助编码走向拥有完整执行环境的自主形态,安全团队应将其视为新基础设施纳入监控。
行动建议:今天最优先做一件事——盘点并收敛互联网暴露的 AI 工具,尤其检查 Flowise 和 OpenChamber,若受影响且无法升级应立即隔离或迁移,这是当前最现实的入侵入口。