Vulnerability intelligence

Updated 19 minutes ago

Feeds

Trending now

CVEs trending on social media within the last 24 hours

Hypemeter

220100

Current score

Not much to see here

  1. 1

    CVE-2026-88779 Published Oct 4, 2026

    Hype score

    22

    high 8.7

    Exploit known

    CVE-2026-88779 is a memory buffer overflow vulnerability affecting Citrix NetScaler ADC and NetScaler Gateway appliances. The flaw, classified under CWE-119, occurs within the SAML authentication code path. It specifically impacts customer-managed deployments configured as either a SAML Service Provider (SAML SP) or a SAML Identity Provider (SAML IdP). When triggered, the vulnerability causes the authentication daemon (`nsaaad`) to crash, leading to repeated appliance reboots and a denial-of-service (DoS) condition. Although Citrix officially lists the primary impact as a denial of service, cybersecurity researchers have observed activity suggesting the vulnerability may also be leveraged for remote code execution, including attempts to execute fileless shell scripts and drop payloads. The flaw has been actively exploited in the wild as a zero-day, prompting the Cybersecurity and Infrastructure Security Agency (CISA) to add it to its Known Exploited Vulnerabilities (KEV) catalog. Citrix has released security updates, urging administrators to upgrade to patched versions such as 14.1-73.41 and 13.1-64.28 or later.

  2. 2

    CVE-2026-100520 Published Sep 26, 2026

    Hype score

    16

    high 8.7

    CVE-2026-100520 is a path traversal vulnerability affecting Laranode, a multi-tenant application, in versions prior to 1.2.1. The issue resides in the `POST /filemanager/upload-file` endpoint, which is used for file management operations. It allows authenticated users to write arbitrary files outside of their designated home directory by manipulating the file upload path. To exploit this vulnerability, an attacker can input directory traversal sequences into the `path` parameter during a file upload. This allows them to write PHP files into the web roots of other tenants, leading to arbitrary code execution under the context of those tenants. The vulnerability has been resolved in Laranode version 1.2.1.

  3. 3

    CVE-2026-63030 Published Jul 17, 2026

    Hype score

    12

    critical 9.8

    Exploit known

    WordPressUbuntuweb applicationZero-dayOpen sourceAPISQL injectionwp2shell

    CVE-2026-63030 is an unauthenticated remote code execution (RCE) vulnerability affecting WordPress versions 6.9 and later. This flaw allows an attacker to execute arbitrary code through the batch endpoint of the REST API. Exploitation of CVE-2026-63030 does not require any user interaction or authentication, and it is specifically possible when a persistent object cache is not in use. The vulnerability is related to a REST API batch-route confusion and SQL injection issue. Fixes for this vulnerability have been released in WordPress 7.0.2 and 6.9.5.

See more

Known exploited

Sourced from CISA's Known Exploited Vulnerability (KEV) catalog.

  1. CVE-2026-88779 Published Oct 4, 2026

    Hype score

    22

    high 8.7

    Exploit known

    CVE-2026-88779 is a memory buffer overflow vulnerability affecting Citrix NetScaler ADC and NetScaler Gateway appliances. The flaw, classified under CWE-119, occurs within the SAML authentication code path. It specifically impacts customer-managed deployments configured as either a SAML Service Provider (SAML SP) or a SAML Identity Provider (SAML IdP). When triggered, the vulnerability causes the authentication daemon (`nsaaad`) to crash, leading to repeated appliance reboots and a denial-of-service (DoS) condition. Although Citrix officially lists the primary impact as a denial of service, cybersecurity researchers have observed activity suggesting the vulnerability may also be leveraged for remote code execution, including attempts to execute fileless shell scripts and drop payloads. The flaw has been actively exploited in the wild as a zero-day, prompting the Cybersecurity and Infrastructure Security Agency (CISA) to add it to its Known Exploited Vulnerabilities (KEV) catalog. Citrix has released security updates, urging administrators to upgrade to patched versions such as 14.1-73.41 and 13.1-64.28 or later.

  2. CVE-2026-102490 Published Sep 30, 2026

    Hype score

    3

    critical 9.4

    Exploit known

    CVE-2026-102490 is a local privilege escalation vulnerability affecting Zammad, an open-source helpdesk and ticketing system. The flaw is present in all versions of the software, including the latest alpha releases, and allows a local user with access to the `zammad` account to bypass permission checks and escalate their privileges to `root`. This unauthorized access enables the execution of privileged operations, allowing an attacker to modify system files, install software, or access other parts of the host system. The vulnerability was highlighted in reports after being chained with CVE-2026-102489 in an attack against the Dutch Institute for Vulnerability Disclosure (DIVD). In that incident, attackers utilized an autonomous, agentic AI to exploit both flaws, allowing them to hijack sessions, execute code remotely, and escalate privileges to root within seconds. Following evidence of active exploitation in the wild, the Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-102490 to its Known Exploited Vulnerabilities (KEV) catalog, requiring organizations to apply the necessary updates.

  3. CVE-2026-102489 Published Sep 30, 2026

    Hype score

    3

    critical 9.4

    Exploit known

    CVE-2026-102489 is a session hijacking and remote code execution vulnerability affecting Zammad, an open-source helpdesk and customer support ticketing system. The flaw allows unauthenticated attackers to leak user sessions and remotely execute malicious code as the local `zammad` user. It affects Zammad versions 6.3.0 through 6.5.4 in an exploitable state. While the vulnerability is present in versions 7.0.0 through 7.1.3, environmental conditions prevent its exploitation in those later releases. The vulnerability gained public attention after being exploited as a zero-day alongside CVE-2026-102490, a local privilege escalation flaw, in an automated, agentic AI-powered attack against the Dutch Institute for Vulnerability Disclosure (DIVD) in September 2026. By chaining these two vulnerabilities, the automated agent was able to hijack sessions, execute code, and escalate privileges to root within seconds. To mitigate the issue, users are advised to upgrade to Zammad version 7 or take vulnerable instances offline.

See more

Insights

See more

Our Security Team's most recent CVE analysis

  1. Link to CVE page

    Intruder Insights

    Updated Sep 10, 2026

    This is a serious vulnerability affecting all supported WordPress versions. It can be exploited by any unauthenticated attacker, and a working proof of concept is available. However, to achieve remote code execution an attacker must trick a WordPress admin into opening a malicious link as part of a social engineering attack. This vulnerability is patched in WordPress 7.0.3 (released Aug 6, 2026).

    WordPress is vulnerable to a pre-auth reflected XSS vulnerability on the login screen. Via a specially crafted malicious third-party website hosted by an attacker, it is possible for this to be escalated to an RCE vulnerability with conditions outside of the attackers control. This requires successful social engineering of and explicit interaction by the target victim. This issue affects all versions of WordPress. Version 7.0.3 has been released, containing a fix for the vulnerability, and as a courtesy to users on older branches the fix has been backported to all branches back to 4.7. Discovered and responsibly disclosed by [the team at pwn.ai](https://pwn.ai/).

  2. CVE-2026-50522

    critical 9.8

    Exploit known

    Link to CVE page

    Intruder Insights

    Updated Jul 21, 2026

    This vulnerability allows an unauthenticated attacker who can access a Sharepoint instance to gain code execution. A patch has been available since July 14th in Microsofts 'Patch Tuesday' security rollup.

    A proof of concept exploit has recently been published and this makes patching more urgent as attacks have now been seen in the wild.

    Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network.

  3. CVE-2026-63030

    critical 9.8

    Exploit known

    Link to CVE page

    Intruder Insights

    Updated Jul 21, 2026

    This is one of two vulnerabilities in a combined chain that allows remote code execution on any stock WordPress installation. CVE-2026-63030 is the entry point — a route confusion bug in the REST API batch endpoint that bypasses authentication, allowing an attacker to invoke internal handlers without any permission check. When combined with CVE-2026-60137, the attacker gains the ability to read any data from the WordPress database with a single HTTP request. An exploit chain has been demonstrated which combines both of these bugs to achieve code execution.

    WordPress 6.9.0–6.9.4 and 7.0.0–7.0.1 are affected. Update to WordPress 6.9.5 or 7.0.2 immediately. No plugins, user interaction, or non-default configuration is required to exploit. Given WordPress powers approximately 43% of all websites, the attack surface is enormous.

    WordPress Core contains a pre-authentication route confusion vulnerability in the REST API batch endpoint that, combined with CVE-2026-60137, allows remote code execution.

    WordPress 6.9.x before 6.9.5 and 7.0.x before 7.0.2 is affected by a REST API batch endpoint route confusion issue which, combined with the author__not_in WP_Query SQL Injection (CVE-2026-60137), could allow an attacker to perform SQL Injection and achieve Remote Code Execution.