🚨 ACTIVE EXPLOITS & INCIDENTS
- Two SonicWall SMA 1000 Zero-Days Exploited, One Could Enable Admin Commands — The Hacker News
SonicWall warns of active exploitation targeting SMA 1000 series appliances via two zero-days, including CVE-2026-15409 (CVSS 10.0), a critical SSRF vulnerability enabling remote unauthenticated attackers to execute arbitrary commands. Immediate patching or mitigation is critical to prevent full system compromise.
🔓 VULNERABILITIES & CVEs
-
<https://cve.threatint.eu/CVE/CVE-2026-12512?utm_campaign=info&utm_medium=rss&utm_source=website%7CQuotes Llama < 3.1.6 - Unauthenticated SQL Injection via sc Parameter> — CVE ThreatInt
The Quotes Llama WordPress plugin prior to 3.1.6 suffers from an unauthenticated SQL injection vulnerability allowing UNION-based attacks through an unsanitizedscparameter. Exploitation could lead to data leakage or database compromise. Upgrade recommended. -
<https://cve.threatint.eu/CVE/CVE-2026-12281?utm_campaign=info&utm_medium=rss&utm_source=website%7CShibboleth < 2.5.4 - Unauthenticated Administrator Account Creation via Identity Header Spoofing> — CVE ThreatInt
Shibboleth WordPress plugin versions before 2.5.4 improperly trust HTTP identity headers without anti-spoofing keys, enabling attackers to create admin accounts without authentication. Patch to 2.5.4 or later to close this critical privilege escalation vector. -
<https://cve.threatint.eu/CVE/CVE-2026-11580?utm_campaign=info&utm_medium=rss&utm_source=website%7CKali Forms < 2.4.17 - Contributor+ Arbitrary Post Metadata Disclosure via IDO> — CVE ThreatInt
Kali Forms plugin before 2.4.17 lacks per-object capability checks on post duplication AJAX actions, allowing users with Contributor+ roles to access sensitive post metadata. Update to 2.4.17 to enforce proper authorization. -
<https://cve.threatint.eu/CVE/CVE-2026-11579?utm_campaign=info&utm_medium=rss&utm_source=website%7CKali Forms < 2.4.17 - Unauthenticated Media Upload> — CVE ThreatInt
An unauthenticated file upload vulnerability exists in Kali Forms before 2.4.17 due to missing validation that uploads correspond to configured forms with file-upload fields. This could lead to arbitrary file upload and potential remote code execution. Immediate patching advised.