π VULNERABILITIES & CVEs
-
TDengine: Authenticated Out-of-Bounds Read in SQL Lexer tGetToken() β CVE-2026-62353
TDengine (β€3.4.1.14), a time-series DB for IoT, has an out-of-bounds read triggered by SQL lexer mishandling trailing backslashes. Could lead to info disclosure or crash. -
TDengine: Unauthenticated Remote Denial of Service via Out-of-Bounds Read β CVE-2026-62351
Unauthenticated attackers can cause DoS by exploiting out-of-bounds read in transDecompressMsg() prior to 3.4.1.15. High risk for exposed IoT DB instances. -
TDengine: Missing Authorization on KILL SSMIGRATE Command β CVE-2026-62348
Low-privilege authenticated users can execute KILL SSMIGRATE commands without proper authorization, enabling unauthorized process termination on TDengine Enterprise β€3.4.1.15. -
TDengine: Off-by-One Buffer Overflow β CVE-2026-62349
Versions β€3.4.1.6 have a buffer overflow in trimString() due to improper space checking, potentially exploitable for memory corruption. -
TDengine: Remote Code Execution via UDF Upload β CVE-2026-62350
Authenticated users with create udf privilege can upload crafted shared libraries leading to RCE prior to 3.4.1.15. Critical for environments allowing UDFs. -
Supply Chain Compromise in SAP CAP-js/cds-dbs Packages β CVE-2026-46421
Malicious package versions published April 2026 in SAP Cloud Application Programming Modelβs SQL DB services monorepo. Potential supply chain risk for enterprise cloud apps. -
Apache Ivy: PackagerResolver Path Traversal β CVE-2026-26032
Ant script-based repackaging in Apache Ivy allows path traversal via crafted packager.xml, enabling arbitrary file write/download. Affects artifact management workflows. -
Credential Disclosure in Strands Agents elasticsearch_memory Tool β CVE-2026-15746
Strands Agents Tools leak credentials via elasticsearch_memory, risking sensitive data exposure in AI agent SDK environments. -
Gravity Forms β€2.10.4: Unauthenticated Arbitrary File Read β CVE-2026-12997
Directory traversal via βgform_uploaded_filesβ parameter allows unauthenticated attackers to read arbitrary files on WordPress servers. -
Dashy RSS Widget XSS via Unsanitized RSS Item Links β CVE-2026-54443
Dashy versions 1.9.4β3.2.0 fail to sanitize RSS feed item links, enabling stored XSS attacks in personal dashboard deployments. -
Dashy OIDC Config Write Bypass β CVE-2026-46485
Prior to 4.0.8, unauthenticated or non-admin users can write to main config.yaml via OIDC misconfiguration, risking persistent config tampering. -
Repomix RCE via
--remote-branchArgument Injection β CVE-2026-49987
Versions <1.14.1 allow command injection through unsanitized git fetch/checkout commands, enabling remote code execution in repository packaging workflows. -
Repomix Secret Scanning Bypass via attach_packed_output β CVE-2026-49988
Prior to 1.14.1, arbitrary local .js files can be read by MCP server flows, bypassing secret scanning protections. -
OpenWrt: ACL Bypass and Arbitrary Root File Read via cgi-download β CVE-2026-62947
OpenWrt β€25.12.5 cgi-io cgi-download handler improperly authorizes paths, allowing attackers to bypass ACLs and read root files. -
OpenWrt odhcpd/LuCI: Unauthenticated DHCPv6 Client Lease-File Injection β CVE-2026-62948
DHCPv6 clients can inject malicious lease-file lines leading to potential code execution or config corruption in OpenWrt β€25.12.5. -
Cherry Studio RCE via SearchService nodeIntegration Misconfiguration β CVE-2026-40501
Versions 1.2.2β1.9.12 allow remote attackers to execute arbitrary code by delivering malicious payloads to SearchService. Patch available. -
Zephyr ADIN2111/ADIN1110 Ethernet Driver Out-of-Bounds Write β CVE-2026-10673
Ethernet driver mishandles frame reassembly, risking memory corruption on embedded devices using OA SPI mode. -
Better Auth OAuth Provider: Refresh Token Rotation Race Condition β CVE-2026-53517
Versions 1.4.8-beta.7β1.6.11 vulnerable to token refresh race condition allowing concurrent refreshes and potential token misuse.
π΅οΈ THREAT RESEARCH & DEEP DIVES
- AIDR: CrowdStrikeβs Next-Gen Cybersecurity Framework
CrowdStrike outlines their Adaptive Incident Detection and Response (AIDR) approach, emphasizing AI-driven detection, automation, and integrated threat intelligence to accelerate response times and reduce analyst fatigue. Relevant for SOC modernization strategies.
π° LESSER-KNOWN / UNDER-REPORTED
- Ogma: Open-Source Next-Gen Web Security Proxy Seeking Pentesters
New Rust/Vue.js based proxy tool for pentesters and bug bounty hunters offers HTTP/WebSocket interception, Intruder-style automation, and AI-assisted pentesting copilot. Potential alternative to Burp Suite with plugin ecosystem. Early testing and review encouraged.