Published hours ago, high CVSS, no PoC/KEV yet, but exploitation is straightforward and inevitable.
What: FormGent WordPress plugin (≤1.9.2) allows unauthenticated arbitrary file deletion via unauth REST API endpoint; path traversal can delete wp-config.php, enabling site takeover. CVSS 9.1 CRITICAL.
Why it matters: Published today with high CVSS score and clear exploitation path (no auth required, REST endpoint exposed). NVD details confirm complete site takeover risk on default Linux installs. Not yet KEV-listed but imminent risk to thousands of WordPress sites running the plugin.
Where it's seen: Multilingual social chatter (Hebrew, Russian, Japanese) on Bluesky amplifying disclosure same-day; posts describe practical exploitation scenarios. No public PoC or in-the-wild reports visible yet, but vulnerability is trivial to exploit (REST endpoint + file deletion + no checks).
Rails patching + downstream backports + credential exposure = urgent triage signal; KEV-listing pending.
What: Arbitrary file read to RCE in Rails Active Storage via libvips image processing; affects Rails applications using Active Storage with untrusted image uploads (CVSS 9.5).
Why it matters: Rails maintainers have patched; NixOS/Mastodon backports confirm real-world deployments triaging. Post #6 documents credential exposure (secret_key_base, database passwords, cloud storage credentials, API tokens). Unauthenticated attack surface (crafted image uploads). No KEV-listed status yet, but urgency reflected in vendor patching and security blog coverage.
Where it's seen: Security research writeups (Ethiack, GMO Flatt Security Blog), Hacker News coverage, GitHub patch PRs across downstream consumers (Mastodon, NixOS), social amplification on Bluesky. Posts reference both libvips and Active Storage as attack vector.
Real critical vuln but no KEV, PoC, or confirmed patch availability; early-stage awareness.
What: Incorrect Authorization vulnerability in Adobe Campaign Classic enabling arbitrary code execution without user interaction; CVSS 10.0 critical severity.
Why it matters: Published yesterday with perfect CVSS score and no-interaction RCE capability across scope. However, not yet KEV-listed and no public PoC or confirmed in-the-wild exploitation reported. Social chatter reflects severity but lacks concrete exploitation signal. Adobe patch (build 9398) referenced but not yet verified as official/available.
Where it's seen: High-engagement posts on security social media highlighting CVSS 10 and RCE potential; aggregator sites republishing; calls for immediate patching. No researcher PoC drops, no defender triage reports, no advisory confirmation visible yet.
Also trending
- 4 CVE-2026-20316 MEDIUM · 5.3 KEV score 4 · 5 postshype LIKELY HACK · 78 hack
What: Hardcoded low-privileged credentials in Cisco Secure Firewall Management Center (FMC) web interface allows unauthenticated remote login and sensitive data access (CVSS 5.3 MEDIUM, elevated by chaining risk).
Why it matters: KEV-listed as of 2026-07-29; multiple sources confirm active in-the-wild exploitation. Chatter emphasizes chainability with CVE-2026-20079 (CVSS 10.0) for privilege escalation to root. Cisco issued hotfixes; CISA remediation deadline Aug 19. Defender triaging underway.
Where it's seen: Security news aggregators, threat intel feeds, and practitioner social media all report confirmed exploitation and KEV addition within hours of advisory. No public PoC code shared, but active attacks documented by vendors and CISA.
- 5 CVE-2026-63077 CRITICAL · 9.8 score 4 · 5 postshype MIXED · 62 hack
What: JetBrains TeamCity unauthenticated remote code execution via the agent polling protocol (CVSS 9.8 CRITICAL). Affects versions before 2026.1.3 and 2025.11.7.
Why it matters: CRITICAL severity and zero authentication requirement make this high-impact for CI/CD infrastructure. Published 2026-07-27; patches already available. Not yet KEV-listed but EPSS 0.47% reflects low current exploitation prevalence. Social chatter emphasizes urgency and patch applicability.
Where it's seen: Blog posts and social media amplifying urgency ("Patch Now"), vendor advisory coverage, debate around patch completeness and prior exploitation gaps. No PoC public in supplied posts; chatter is alarm-driven rather than proof-driven.
- 6 CVE-2026-58048 score 4 · 4 postshype MOSTLY HYPE · 18 hack
What: Improper SQL mode preservation in cPanel when renaming databases allows SQL execution in root context. No CVSS/EPSS available.
Why it matters: Published 31 July 2026; not yet KEV-listed. Social chatter consists of automated or low-effort multilingual reposts of the NVD description with no PoC, vendor advisory, or confirmed exploitation signal. Posts lack technical depth and appear to be bot-generated syndication rather than independent researcher or defender commentary.
Where it's seen: Generic Bluesky posts repeating CVE metadata verbatim; no PoC repositories, cPanel advisory, or defender triage questions observed. Chatter is uniform, low-engagement, and recycled within hours of publication.
- 7 CVE-2026-52855 CRITICAL · 9.9 score 4 · 4 postshype MIXED · 48 hack
What: Server-Side Template Injection (SSTI) in Wings (Pterodactyl game server management panel) prior to 1.12.3 allows low-privileged users to read daemon configuration secrets including API tokens and Docker registry credentials via
{{config.}}placeholders in egg templates. CVSS 9.9 CRITICAL.Why it matters: Published 31 July 2026; patch available same day (v1.12.3). High-severity credential exposure in widely-used open-source game hosting infrastructure. Social chatter reflects immediate awareness and urgent update guidance, but no public PoC or in-the-wild exploitation reported yet.
Where it's seen: Bluesky posts from security accounts repeating NVD advisory text and urging immediate patching. Posts in English and Japanese. No defender triage queries, no PoC repository mentions, no KEV listing observed.
- 8 CVE-2026-64531 score 4 · 3 postshype LIKELY HACK · 72 hack
What: Linux kernel Open vSwitch netlink attribute handling flaw allowing oversized nested action attributes to bypass validation, enabling local privilege escalation via malformed CLONE/CT actions (CVSS unavailable; EPSS 0.00161).
Why it matters: Public PoC and patch released within hours of embargo lift; multiple distributions racing to deploy fixes. Local-only attack surface limits immediate remote risk, but kernel privilege escalation bugs warrant urgent triage in multi-tenant environments.
Where it's seen: Security mailing lists and distro advisory channels; vendor patches shipped within 3 hours; social media tracks as trending CVE with PoC labeled "OVSwrap"; defenders already integrating fixes.
- 9 CVE-2026-68770 CRITICAL · 9.8 score 4 · 4 postshype MIXED · 58 hack
What: sentence-transformers (Hugging Face) contains a logic flaw in import_module_class that bypasses trust_remote_code=False, allowing arbitrary code execution if attackers control a local model directory. CVSS 9.8 CRITICAL.
Why it matters: Published 31 July 2026; chatter erupted same day across security channels. The vulnerability breaks a documented security contract—developers relying on trust_remote_code=False to safely load untrusted models are exposed. No KEV listing yet, PoC status unclear from posts, but the flaw is straightforward (os.path.exists logic gate) and exploitable by anyone with filesystem access to model dirs. Real threat to ML pipelines, but patch status unknown.
Where it's seen: Security news aggregators and threat radar platforms amplifying the NVD description; no working exploit code or active in-the-wild reports visible. Vendor advisory not yet cited in posts.
- 10 CVE-2026-17347 HIGH · 7.5 score 4 · 3 postshype MIXED · 42 hack
What: pgAdmin 4 command injection via unsanitized username in MASTER_PASSWORD_HOOK (7.2–9.16), CVSS 7.5 HIGH. Authenticated users exploiting external auth sources (OAuth/OIDC/Kerberos) can execute arbitrary commands as the pgAdmin service account.
Why it matters: Real authentication bypass in a widely deployed admin tool; fix released 2026-07-31 tokenizes arguments and disables shell interpretation. Not yet KEV-listed, but NVD metadata confirms patch availability and clear attack vector requiring only authentication + shell metacharacters in username.
Where it's seen: Aggregator posts (Bluesky, thehackerwire.com) republishing NVD summary in multiple languages within hours of publication. No public PoC, no defender triage chatter, no vendor urgency signaling yet.
- 11 CVE-2026-17349 CRITICAL · 9.6 score 4 · 3 postshype LIKELY HACK · 72 hack
What: Cross-tenant credential theft in pgAdmin 4 Workspaces (CVE-2026-17349); non-owners can clone shared servers and inherit admin credentials via Server.clone(). CVSS 9.6 CRITICAL.
Why it matters: Vulnerability published 31 July 2026; affects pgAdmin 4.9.0–9.16. Fix in 9.17 forces ownership/credential reset on adhoc clones. No KEV listing yet, but CVSS 9.6 and credential exposure (password, tunnel_password fields copied verbatim) signal urgent risk. pgAdmin maintainers have patched; defenders should prioritize upgrades.
Where it's seen: Non-English social posts (Hebrew, Russian) on Bluesky summarizing the flaw; third post explicitly names pgAdmin 4 and describes credential leakage mechanics. No public PoC observed; chatter is advisory-driven, not weaponization-led.
- 12 CVE-2026-17351 CRITICAL · 9.0 score 4 · 3 postshype MIXED · 42 hack
What: pgAdmin 4 9.13–9.16 AI Assistant SQL injection bypass: sqlparse and psycopg3 prepare-threshold interaction allows attackers to smuggle multi-statement payloads (COMMIT, DDL, RCE) past read-only transaction wrapper via prompt injection. CVSS 9.0 CRITICAL.
Why it matters: Published 31 July 2026; not KEV-listed yet but NVD description confirms working exploit path, root-cause fix (prepare_threshold=0), and verified live PostgreSQL 18 reproduction. Chatter is multilingual FUD (Hebrew, Russian posts) with vague summaries; no PoC code or real-world exploitation reports visible. Fix exists in 9.17+; urgency driven by severity and LLM-delivery mechanism, not mass scanning.
Where it's seen: Bluesky posts (non-English, low technical depth) repeating vendor advisory summary; no researcher PoC drops, no defender triage reports, no KEV. Appears to be early-stage awareness bleed from official disclosure.
- 13 CVE-2026-17561 CRITICAL · 9.8 score 3 · 4 postshype LIKELY HACK · 72 hack
What: Code injection vulnerability in Innotim Software Logsign SIEM (<6.4.108) enabling unauthenticated remote code execution; CVSS 9.8 CRITICAL.
Why it matters: Published 31 July 2026 with CRITICAL severity and strong social signal on patch urgency. No KEV listing yet, and patch status remains unclear despite vendor advisory. Defenders are actively discussing containment and monitoring. High CVSS + confirmed RCE attack vector drives immediate triage priority.
Where it's seen: Bluesky chatter across infosec community, threat radar aggregators, and news feeds (HackerWire, OffSeq Radar). Posts emphasize unauthenticated RCE, lack of confirmed patch, and mitigation guidance (access restriction, monitoring).
- 14 CVE-2026-68771 CRITICAL · 9.8 score 3 · 3 postshype MIXED · 48 hack
What: ComfyUI v0.23.0 unsafe deserialization in LoadTrainingDataset node allows unauthenticated remote code execution via malicious pickle files (CVSS 9.8 CRITICAL).
Why it matters: Attack chain is straightforward—upload pickle via unauthenticated /upload/image endpoint, trigger deserialization in workflow queue. No authentication required. Early social chatter shows defenders discussing mitigation (restrict endpoints); published one day ago with clear technical detail suggests initial researcher/vendor disclosure phase.
Where it's seen: Security news aggregators and infosec social media repeating the CVE announcement with mitigation guidance. No public PoC observed yet; no KEV listing. Tone is urgent but signals typical post-disclosure activity, not mass exploitation.
- 15 CVE-2026-54121 HIGH · 8.8 score 3 · 3 postshype LIKELY HACK · 78 hack
What: Improper authorization in Active Directory Certificate Services (AD CS) allowing authenticated attackers to elevate privileges and potentially compromise Windows domains; CVSS 8.8 (HIGH).
Why it matters: Public PoC released 24 July 2026 by H0j3n and Aniq F; Microsoft patched on 14 July; Microsoft Defender already detecting exploitation attempts (malicious certificate requests). Social signal shows working exploitation in lab environments and active defender alerting—not theoretical.
Where it's seen: PoC posted to GitHub gist; security news outlets (HelpNetSecurity) covering; defenders reporting successful lab reproduction; Microsoft Defender generating detection alerts for AD CS abuse; domain-takeover impact framing driving urgency.
- 16 CVE-2026-15964 CRITICAL · 9.8 score 3 · 2 postshype LIKELY HACK · 72 hack
What: Single Sign On For TNG WordPress plugin (≤2.0.0) allows unauthenticated password reset of any account, including admin, via publicly-scrappable nonce in AJAX endpoint (CVSS 9.8 CRITICAL).
Why it matters: Published today with full technical details. No KEV listing yet, but attack is trivial: attacker grabs nonce from homepage, calls unguarded
ssoprocess_ajax()endpoint, resets admin password, owns site. Immediate threat to all unpatched installations.Where it's seen: Security news aggregators and threat-tracking platforms publishing NVD details same-day. Chatter emphasizes criticality and disable/restrict guidance. No PoC code yet, but none needed — vulnerability is straightforward and public.
- 17 CVE-2026-53510 HIGH · 8.1 score 3 · 3 postshype MIXED · 58 hack
What: Savon Ruby SOAP client (versions 0.9.8–2.17.2) allows remote code execution via unsafe interpolation of WSDL operation names into module_eval, enabling arbitrary Ruby code execution. CVSS 8.1 (HIGH).
Why it matters: Published 31 July 2026; researcher disclosed discovery with working methodology (Claude + Scrutineer). Fix available in 2.17.2. No KEV listing yet, but RCE severity and patched release signal legitimate vulnerability requiring immediate triage by Ruby/SOAP users.
Where it's seen: Researcher disclosure on social media, technical summaries circulating, vulnerability aggregators picking it up same day. Early-stage chatter with confirmation of patch availability.
- 18 CVE-2026-54725 CRITICAL · 9.6 score 3 · 3 postshype LIKELY HACK · 72 hack
What: SSRF in vault-secrets-webhook (Kubernetes mutating webhook) allows attackers to redirect Vault client connections to attacker-controlled addresses and exfiltrate ServiceAccount JWTs. CVSS 9.6 CRITICAL.
Why it matters: Fresh disclosure (today); affects Kubernetes clusters using bank-vaults for secret injection up to v1.22.2. Requires only ConfigMap/Secret creation (low privilege), enabling ServiceAccount token theft and Vault credential compromise. Patch available immediately in v1.23.1.
Where it's seen: Social posts flagging urgent upgrade requirement; threat radar coverage; no KEV listing yet but real advisory chain present (vendor patch exists same day as publication).
- 19 CVE-2026-16635 HIGH · 8.8 score 3 · 2 postshype MOSTLY HYPE · 32 hack
What: Pronamic Pay WordPress plugin (≤10.1.0) privilege escalation via unvalidated role assignment in Gravity Forms integration; CVSS 8.8 (HIGH).
Why it matters: Authenticated subscriber-level users can escalate to Administrator if admin has configured the "Update User Role" feature. No KEV listing yet, but CVE published same-day with technical details; no public PoC or in-the-wild reports confirmed in social chatter yet.
Where it's seen: Vulnerability aggregators (Hacker Wire, Patchstack) and security news feeds amplifying the NVD advisory within hours of publication; no vendor urgency signaling, defender triage questions, or PoC links observed yet.
- 20 CVE-2026-15450 HIGH · 8.1 score 3 · 2 postshype MIXED · 38 hack
What: Nex Forms WordPress plugin (≤9.2.3) allows authenticated admin-level attackers to delete arbitrary server files via path traversal in the delete_file() AJAX handler. CVSS 8.1 (HIGH).
Why it matters: Same-day disclosure with full NVD description detailing exploitation chain (insert_record + delete_file handlers). No KEV listing or public PoC yet, but vulnerability is straightforward and affects widely-deployed form plugin. WordPress site operators with Nex Forms should patch immediately.
Where it's seen: Initial vendor advisory and security feed republication on day of publication. Chatter limited to automated CVE aggregators and news wires; no defender triage reports or exploitation signals yet.
- 21 CVE-2026-17346 HIGH · 8.8 score 3 · 2 postshype MOSTLY HYPE · 18 hack
What: pgAdmin 4 vulnerability (CVE-2026-17346); component, severity, and patch status unknown due to missing NVD enrichment.
Why it matters: No KEV listing, no published CVSS/EPSS, no advisory metadata, and NVD not yet populated. Posts are in Hebrew and Russian with non-authoritative domains, lacking PoC, vendor confirmation, or defender signals.
Where it's seen: Two social posts in non-English languages on Bluesky; no vendor advisory, no public PoC, no security researcher corroboration detected. - 22 CVE-2026-61311 HIGH · 8.8 score 3 · 2 postshype PURE HYPE · 8 hack
What: CVE-2026-61311 — a claimed critical vulnerability in Oracle Product Hub; component and attack vector unspecified; CVSS/EPSS unavailable.
Why it matters: NVD metadata not yet enriched; no KEV listing, no vendor advisory found, no public PoC identified. Posts are in Hebrew and Russian from low-engagement accounts linking to non-official domains (khesef.xyz, kripta.biz), suggesting SEO spam or FUD rather than authoritative disclosure.
Where it's seen: Two low-reach social posts in non-English languages; no corresponding Oracle security bulletin, researcher advisories, or defender triage activity detected.
- 23 CVE-2026-61196 CRITICAL · 9.8 score 3 · 2 postshype MOSTLY HYPE · 28 hack
What: Unauthenticated remote code execution in Oracle Identity Manager (OIM Legacy UI, versions 12.2.1.4.0 and 14.1.2.1.0) via HTTP; CVSS 9.8 CRITICAL.
Why it matters: No KEV listing yet; EPSS 0.38% suggests low current exploit prevalence. No PoC or in-the-wild exploitation confirmed in supplied chatter. Oracle patch status unclear from posts. High CVSS reflects severity if exploited, but absence of active weaponization signal limits immediate risk.
Where it's seen: Multilingual social media posts (Hebrew, Russian, English) on Bluesky and generic cybersecurity blogs repeating NVD description; no vendor advisories, researcher PoCs, or defender triage reports cited.
- 24 CVE-2026-61184 CRITICAL · 9.1 score 3 · 2 postshype MOSTLY HYPE · 28 hack
What: Unauthenticated remote code/data access in Oracle Agile PLM for Process v6.2.4 via HTTP; allows unauthorized creation, deletion, or modification of critical supply-chain data (CVSS 9.1 CRITICAL).
Why it matters: High CVSS and zero authentication requirement makes this immediately actionable for Oracle PLM customers. However, no KEV listing, no public PoC, and no vendor advisory urgency signals observed yet. Social chatter is multilingual aggregation of NVD description only—no exploitation reports or defender triage activity.
Where it's seen: Generic CVE tracking posts in multiple languages on Bluesky, linking to blog indexers and aggregators. No technical deep-dives, PoC repos, or defender questions visible.
- 25 CVE-2026-61188 HIGH · 7.5 score 3 · 2 postshype MOSTLY HYPE · 22 hack
What: Oracle Agile Product Lifecycle Management for Process 6.2.4 allows low-privileged network attackers to gain full system compromise via HTTP; CVSS 7.5 HIGH.
Why it matters: CVE published 11 days ago with no KEV listing, no confirmed PoC, and no urgent vendor advisories in the chatter. Posts are in Hebrew and Russian on smaller platforms, suggesting repackaged vulnerability announcements rather than active exploitation signals or coordinated defender response.
Where it's seen: Low-engagement social posts on alternative platforms (Bluesky) linking to non-canonical sources; no mainstream security researcher coverage, no vendor emergency patches, no defender triage questions observed.