Trending vulnerabilities

Trending 25
Critical 12
In KEV 1
Peak EPSS 2%
Posts 86
#1 CVE-2026-3141
CRITICAL · 9.1
hype LIKELY HACK · 72 hack

Published hours ago, high CVSS, no PoC/KEV yet, but exploitation is straightforward and inevitable.

What: FormGent WordPress plugin (≤1.9.2) allows unauthenticated arbitrary file deletion via unauth REST API endpoint; path traversal can delete wp-config.php, enabling site takeover. CVSS 9.1 CRITICAL.

Why it matters: Published today with high CVSS score and clear exploitation path (no auth required, REST endpoint exposed). NVD details confirm complete site takeover risk on default Linux installs. Not yet KEV-listed but imminent risk to thousands of WordPress sites running the plugin.

Where it's seen: Multilingual social chatter (Hebrew, Russian, Japanese) on Bluesky amplifying disclosure same-day; posts describe practical exploitation scenarios. No public PoC or in-the-wild reports visible yet, but vulnerability is trivial to exploit (REST endpoint + file deletion + no checks).

score 7 8 posts
#2 CVE-2026-66066
hype LIKELY HACK · 78 hack

Rails patching + downstream backports + credential exposure = urgent triage signal; KEV-listing pending.

What: Arbitrary file read to RCE in Rails Active Storage via libvips image processing; affects Rails applications using Active Storage with untrusted image uploads (CVSS 9.5).

Why it matters: Rails maintainers have patched; NixOS/Mastodon backports confirm real-world deployments triaging. Post #6 documents credential exposure (secret_key_base, database passwords, cloud storage credentials, API tokens). Unauthenticated attack surface (crafted image uploads). No KEV-listed status yet, but urgency reflected in vendor patching and security blog coverage.

Where it's seen: Security research writeups (Ethiack, GMO Flatt Security Blog), Hacker News coverage, GitHub patch PRs across downstream consumers (Mastodon, NixOS), social amplification on Bluesky. Posts reference both libvips and Active Storage as attack vector.

score 5 6 posts
#3 CVE-2026-48449
CRITICAL · 10.0
hype MIXED · 52 hack

Real critical vuln but no KEV, PoC, or confirmed patch availability; early-stage awareness.

What: Incorrect Authorization vulnerability in Adobe Campaign Classic enabling arbitrary code execution without user interaction; CVSS 10.0 critical severity.

Why it matters: Published yesterday with perfect CVSS score and no-interaction RCE capability across scope. However, not yet KEV-listed and no public PoC or confirmed in-the-wild exploitation reported. Social chatter reflects severity but lacks concrete exploitation signal. Adobe patch (build 9398) referenced but not yet verified as official/available.

Where it's seen: High-engagement posts on security social media highlighting CVSS 10 and RCE potential; aggregator sites republishing; calls for immediate patching. No researcher PoC drops, no defender triage reports, no advisory confirmation visible yet.

score 4 4 posts

Also trending

  1. 4 CVE-2026-20316 MEDIUM · 5.3 KEV score 4 · 5 posts
    hype LIKELY HACK · 78 hack

    What: Hardcoded low-privileged credentials in Cisco Secure Firewall Management Center (FMC) web interface allows unauthenticated remote login and sensitive data access (CVSS 5.3 MEDIUM, elevated by chaining risk).

    Why it matters: KEV-listed as of 2026-07-29; multiple sources confirm active in-the-wild exploitation. Chatter emphasizes chainability with CVE-2026-20079 (CVSS 10.0) for privilege escalation to root. Cisco issued hotfixes; CISA remediation deadline Aug 19. Defender triaging underway.

    Where it's seen: Security news aggregators, threat intel feeds, and practitioner social media all report confirmed exploitation and KEV addition within hours of advisory. No public PoC code shared, but active attacks documented by vendors and CISA.

  2. 5 CVE-2026-63077 CRITICAL · 9.8 score 4 · 5 posts
    hype MIXED · 62 hack

    What: JetBrains TeamCity unauthenticated remote code execution via the agent polling protocol (CVSS 9.8 CRITICAL). Affects versions before 2026.1.3 and 2025.11.7.

    Why it matters: CRITICAL severity and zero authentication requirement make this high-impact for CI/CD infrastructure. Published 2026-07-27; patches already available. Not yet KEV-listed but EPSS 0.47% reflects low current exploitation prevalence. Social chatter emphasizes urgency and patch applicability.

    Where it's seen: Blog posts and social media amplifying urgency ("Patch Now"), vendor advisory coverage, debate around patch completeness and prior exploitation gaps. No PoC public in supplied posts; chatter is alarm-driven rather than proof-driven.

  3. 6 CVE-2026-58048 score 4 · 4 posts
    hype MOSTLY HYPE · 18 hack

    What: Improper SQL mode preservation in cPanel when renaming databases allows SQL execution in root context. No CVSS/EPSS available.

    Why it matters: Published 31 July 2026; not yet KEV-listed. Social chatter consists of automated or low-effort multilingual reposts of the NVD description with no PoC, vendor advisory, or confirmed exploitation signal. Posts lack technical depth and appear to be bot-generated syndication rather than independent researcher or defender commentary.

    Where it's seen: Generic Bluesky posts repeating CVE metadata verbatim; no PoC repositories, cPanel advisory, or defender triage questions observed. Chatter is uniform, low-engagement, and recycled within hours of publication.

  4. 7 CVE-2026-15988 HIGH · 8.8 score 4 · 3 posts
    hype LIKELY HACK · 72 hack

    What: Cross-Site Request Forgery (CSRF) in AI Engine WordPress plugin (versions ≤3.6.5) enabling unauthenticated attackers to create administrator accounts via admin-click social engineering. CVSS 8.8 HIGH.

    Why it matters: Plugin deployed on 100,000+ WordPress sites; flaw requires no attacker account, only admin click on malicious link; allows full account takeover. Published today with patched version 3.6.6 available. No KEV listing yet but high-impact scope drives immediate patch urgency.

    Where it's seen: Bluesky posts echoing NVD advisory within 2 hours of publication; plugin vendor patching actively signaled; chatter emphasizes scale (100k+ sites) and ease of exploitation (social engineering + method override).

  5. 8 CVE-2026-15006 HIGH · 7.5 score 4 · 3 posts
    hype MOSTLY HYPE · 22 hack

    What: Directory traversal in Bit Integrations WordPress plugin (≤2.9.0) allowing unauthenticated attackers to read arbitrary server files; CVSS 7.5 HIGH.

    Why it matters: Published today with no KEV listing or public PoC reported yet. Social chatter is automated vulnerability feed syndication rather than exploitation signals. Plugin affects WordPress deployments widely, but no defender triage or urgent vendor patching advisories visible in the posts. Early-stage disclosure with moderate impact if exploited.

    Where it's seen: Vulnerability feeds (Patchstack radar, The Hacker Wire) republishing the NVD entry same-day; generic infosec social alerts with no exploitation context or patch availability mentioned.

  6. 9 CVE-2026-52855 CRITICAL · 9.9 score 4 · 4 posts
    hype MIXED · 48 hack

    What: Server-Side Template Injection (SSTI) in Wings (Pterodactyl game server management panel) prior to 1.12.3 allows low-privileged users to read daemon configuration secrets including API tokens and Docker registry credentials via {{config.}} placeholders in egg templates. CVSS 9.9 CRITICAL.

    Why it matters: Published 31 July 2026; patch available same day (v1.12.3). High-severity credential exposure in widely-used open-source game hosting infrastructure. Social chatter reflects immediate awareness and urgent update guidance, but no public PoC or in-the-wild exploitation reported yet.

    Where it's seen: Bluesky posts from security accounts repeating NVD advisory text and urging immediate patching. Posts in English and Japanese. No defender triage queries, no PoC repository mentions, no KEV listing observed.

  7. 10 CVE-2026-64531 score 4 · 3 posts
    hype LIKELY HACK · 72 hack

    What: Linux kernel Open vSwitch netlink attribute handling flaw allowing oversized nested action attributes to bypass validation, enabling local privilege escalation via malformed CLONE/CT actions (CVSS unavailable; EPSS 0.00161).

    Why it matters: Public PoC and patch released within hours of embargo lift; multiple distributions racing to deploy fixes. Local-only attack surface limits immediate remote risk, but kernel privilege escalation bugs warrant urgent triage in multi-tenant environments.

    Where it's seen: Security mailing lists and distro advisory channels; vendor patches shipped within 3 hours; social media tracks as trending CVE with PoC labeled "OVSwrap"; defenders already integrating fixes.

  8. 11 CVE-2026-68770 CRITICAL · 9.8 score 4 · 4 posts
    hype MIXED · 58 hack

    What: sentence-transformers (Hugging Face) contains a logic flaw in import_module_class that bypasses trust_remote_code=False, allowing arbitrary code execution if attackers control a local model directory. CVSS 9.8 CRITICAL.

    Why it matters: Published 31 July 2026; chatter erupted same day across security channels. The vulnerability breaks a documented security contract—developers relying on trust_remote_code=False to safely load untrusted models are exposed. No KEV listing yet, PoC status unclear from posts, but the flaw is straightforward (os.path.exists logic gate) and exploitable by anyone with filesystem access to model dirs. Real threat to ML pipelines, but patch status unknown.

    Where it's seen: Security news aggregators and threat radar platforms amplifying the NVD description; no working exploit code or active in-the-wild reports visible. Vendor advisory not yet cited in posts.

  9. 12 CVE-2026-17347 HIGH · 7.5 score 3 · 3 posts
    hype MIXED · 42 hack

    What: pgAdmin 4 command injection via unsanitized username in MASTER_PASSWORD_HOOK (7.2–9.16), CVSS 7.5 HIGH. Authenticated users exploiting external auth sources (OAuth/OIDC/Kerberos) can execute arbitrary commands as the pgAdmin service account.

    Why it matters: Real authentication bypass in a widely deployed admin tool; fix released 2026-07-31 tokenizes arguments and disables shell interpretation. Not yet KEV-listed, but NVD metadata confirms patch availability and clear attack vector requiring only authentication + shell metacharacters in username.

    Where it's seen: Aggregator posts (Bluesky, thehackerwire.com) republishing NVD summary in multiple languages within hours of publication. No public PoC, no defender triage chatter, no vendor urgency signaling yet.

  10. 13 CVE-2026-17561 CRITICAL · 9.8 score 3 · 4 posts
    hype LIKELY HACK · 72 hack

    What: Code injection vulnerability in Innotim Software Logsign SIEM (<6.4.108) enabling unauthenticated remote code execution; CVSS 9.8 CRITICAL.

    Why it matters: Published 31 July 2026 with CRITICAL severity and strong social signal on patch urgency. No KEV listing yet, and patch status remains unclear despite vendor advisory. Defenders are actively discussing containment and monitoring. High CVSS + confirmed RCE attack vector drives immediate triage priority.

    Where it's seen: Bluesky chatter across infosec community, threat radar aggregators, and news feeds (HackerWire, OffSeq Radar). Posts emphasize unauthenticated RCE, lack of confirmed patch, and mitigation guidance (access restriction, monitoring).

  11. 14 CVE-2026-17349 CRITICAL · 9.6 score 3 · 3 posts
    hype LIKELY HACK · 72 hack

    What: Cross-tenant credential theft in pgAdmin 4 Workspaces (CVE-2026-17349); non-owners can clone shared servers and inherit admin credentials via Server.clone(). CVSS 9.6 CRITICAL.

    Why it matters: Vulnerability published 31 July 2026; affects pgAdmin 4.9.0–9.16. Fix in 9.17 forces ownership/credential reset on adhoc clones. No KEV listing yet, but CVSS 9.6 and credential exposure (password, tunnel_password fields copied verbatim) signal urgent risk. pgAdmin maintainers have patched; defenders should prioritize upgrades.

    Where it's seen: Non-English social posts (Hebrew, Russian) on Bluesky summarizing the flaw; third post explicitly names pgAdmin 4 and describes credential leakage mechanics. No public PoC observed; chatter is advisory-driven, not weaponization-led.

  12. 15 CVE-2026-17351 CRITICAL · 9.0 score 3 · 3 posts
    hype MIXED · 42 hack

    What: pgAdmin 4 9.13–9.16 AI Assistant SQL injection bypass: sqlparse and psycopg3 prepare-threshold interaction allows attackers to smuggle multi-statement payloads (COMMIT, DDL, RCE) past read-only transaction wrapper via prompt injection. CVSS 9.0 CRITICAL.

    Why it matters: Published 31 July 2026; not KEV-listed yet but NVD description confirms working exploit path, root-cause fix (prepare_threshold=0), and verified live PostgreSQL 18 reproduction. Chatter is multilingual FUD (Hebrew, Russian posts) with vague summaries; no PoC code or real-world exploitation reports visible. Fix exists in 9.17+; urgency driven by severity and LLM-delivery mechanism, not mass scanning.

    Where it's seen: Bluesky posts (non-English, low technical depth) repeating vendor advisory summary; no researcher PoC drops, no defender triage reports, no KEV. Appears to be early-stage awareness bleed from official disclosure.

  13. 16 CVE-2026-68771 CRITICAL · 9.8 score 3 · 3 posts
    hype MIXED · 48 hack

    What: ComfyUI v0.23.0 unsafe deserialization in LoadTrainingDataset node allows unauthenticated remote code execution via malicious pickle files (CVSS 9.8 CRITICAL).

    Why it matters: Attack chain is straightforward—upload pickle via unauthenticated /upload/image endpoint, trigger deserialization in workflow queue. No authentication required. Early social chatter shows defenders discussing mitigation (restrict endpoints); published one day ago with clear technical detail suggests initial researcher/vendor disclosure phase.

    Where it's seen: Security news aggregators and infosec social media repeating the CVE announcement with mitigation guidance. No public PoC observed yet; no KEV listing. Tone is urgent but signals typical post-disclosure activity, not mass exploitation.

  14. 17 CVE-2026-54121 HIGH · 8.8 score 3 · 3 posts
    hype LIKELY HACK · 78 hack

    What: Improper authorization in Active Directory Certificate Services (AD CS) allowing authenticated attackers to elevate privileges and potentially compromise Windows domains; CVSS 8.8 (HIGH).

    Why it matters: Public PoC released 24 July 2026 by H0j3n and Aniq F; Microsoft patched on 14 July; Microsoft Defender already detecting exploitation attempts (malicious certificate requests). Social signal shows working exploitation in lab environments and active defender alerting—not theoretical.

    Where it's seen: PoC posted to GitHub gist; security news outlets (HelpNetSecurity) covering; defenders reporting successful lab reproduction; Microsoft Defender generating detection alerts for AD CS abuse; domain-takeover impact framing driving urgency.

  15. 18 CVE-2026-53510 HIGH · 8.1 score 3 · 3 posts
    hype MIXED · 58 hack

    What: Savon Ruby SOAP client (versions 0.9.8–2.17.2) allows remote code execution via unsafe interpolation of WSDL operation names into module_eval, enabling arbitrary Ruby code execution. CVSS 8.1 (HIGH).

    Why it matters: Published 31 July 2026; researcher disclosed discovery with working methodology (Claude + Scrutineer). Fix available in 2.17.2. No KEV listing yet, but RCE severity and patched release signal legitimate vulnerability requiring immediate triage by Ruby/SOAP users.

    Where it's seen: Researcher disclosure on social media, technical summaries circulating, vulnerability aggregators picking it up same day. Early-stage chatter with confirmation of patch availability.

  16. 19 CVE-2026-54725 CRITICAL · 9.6 score 3 · 3 posts
    hype LIKELY HACK · 72 hack

    What: SSRF in vault-secrets-webhook (Kubernetes mutating webhook) allows attackers to redirect Vault client connections to attacker-controlled addresses and exfiltrate ServiceAccount JWTs. CVSS 9.6 CRITICAL.

    Why it matters: Fresh disclosure (today); affects Kubernetes clusters using bank-vaults for secret injection up to v1.22.2. Requires only ConfigMap/Secret creation (low privilege), enabling ServiceAccount token theft and Vault credential compromise. Patch available immediately in v1.23.1.

    Where it's seen: Social posts flagging urgent upgrade requirement; threat radar coverage; no KEV listing yet but real advisory chain present (vendor patch exists same day as publication).

  17. 20 CVE-2026-15964 CRITICAL · 9.8 score 3 · 2 posts
    hype LIKELY HACK · 72 hack

    What: Single Sign On For TNG WordPress plugin (≤2.0.0) allows unauthenticated password reset of any account, including admin, via publicly-scrappable nonce in AJAX endpoint (CVSS 9.8 CRITICAL).

    Why it matters: Published today with full technical details. No KEV listing yet, but attack is trivial: attacker grabs nonce from homepage, calls unguarded ssoprocess_ajax() endpoint, resets admin password, owns site. Immediate threat to all unpatched installations.

    Where it's seen: Security news aggregators and threat-tracking platforms publishing NVD details same-day. Chatter emphasizes criticality and disable/restrict guidance. No PoC code yet, but none needed — vulnerability is straightforward and public.

  18. 21 CVE-2026-16635 HIGH · 8.8 score 3 · 2 posts
    hype MOSTLY HYPE · 32 hack

    What: Pronamic Pay WordPress plugin (≤10.1.0) privilege escalation via unvalidated role assignment in Gravity Forms integration; CVSS 8.8 (HIGH).

    Why it matters: Authenticated subscriber-level users can escalate to Administrator if admin has configured the "Update User Role" feature. No KEV listing yet, but CVE published same-day with technical details; no public PoC or in-the-wild reports confirmed in social chatter yet.

    Where it's seen: Vulnerability aggregators (Hacker Wire, Patchstack) and security news feeds amplifying the NVD advisory within hours of publication; no vendor urgency signaling, defender triage questions, or PoC links observed yet.

  19. 22 CVE-2026-15450 HIGH · 8.1 score 3 · 2 posts
    hype MIXED · 38 hack

    What: Nex Forms WordPress plugin (≤9.2.3) allows authenticated admin-level attackers to delete arbitrary server files via path traversal in the delete_file() AJAX handler. CVSS 8.1 (HIGH).

    Why it matters: Same-day disclosure with full NVD description detailing exploitation chain (insert_record + delete_file handlers). No KEV listing or public PoC yet, but vulnerability is straightforward and affects widely-deployed form plugin. WordPress site operators with Nex Forms should patch immediately.

    Where it's seen: Initial vendor advisory and security feed republication on day of publication. Chatter limited to automated CVE aggregators and news wires; no defender triage reports or exploitation signals yet.

  20. 23 CVE-2026-17346 HIGH · 8.8 score 3 · 2 posts
    hype MOSTLY HYPE · 18 hack

    What: pgAdmin 4 vulnerability (CVE-2026-17346); component, severity, and patch status unknown due to missing NVD enrichment.
    Why it matters: No KEV listing, no published CVSS/EPSS, no advisory metadata, and NVD not yet populated. Posts are in Hebrew and Russian with non-authoritative domains, lacking PoC, vendor confirmation, or defender signals.
    Where it's seen: Two social posts in non-English languages on Bluesky; no vendor advisory, no public PoC, no security researcher corroboration detected.

  21. 24 CVE-2026-61311 HIGH · 8.8 score 3 · 2 posts
    hype PURE HYPE · 8 hack

    What: CVE-2026-61311 — a claimed critical vulnerability in Oracle Product Hub; component and attack vector unspecified; CVSS/EPSS unavailable.

    Why it matters: NVD metadata not yet enriched; no KEV listing, no vendor advisory found, no public PoC identified. Posts are in Hebrew and Russian from low-engagement accounts linking to non-official domains (khesef.xyz, kripta.biz), suggesting SEO spam or FUD rather than authoritative disclosure.

    Where it's seen: Two low-reach social posts in non-English languages; no corresponding Oracle security bulletin, researcher advisories, or defender triage activity detected.

  22. 25 CVE-2026-61196 CRITICAL · 9.8 score 3 · 2 posts
    hype MOSTLY HYPE · 28 hack

    What: Unauthenticated remote code execution in Oracle Identity Manager (OIM Legacy UI, versions 12.2.1.4.0 and 14.1.2.1.0) via HTTP; CVSS 9.8 CRITICAL.

    Why it matters: No KEV listing yet; EPSS 0.38% suggests low current exploit prevalence. No PoC or in-the-wild exploitation confirmed in supplied chatter. Oracle patch status unclear from posts. High CVSS reflects severity if exploited, but absence of active weaponization signal limits immediate risk.

    Where it's seen: Multilingual social media posts (Hebrew, Russian, English) on Bluesky and generic cybersecurity blogs repeating NVD description; no vendor advisories, researcher PoCs, or defender triage reports cited.