🚨 ACTIVE EXPLOITS & INCIDENTS
- Dutch police bust investment fraud ring stealing over €100 million — BleepingComputer
Dutch authorities arrested multiple suspects in an international investment fraud scheme impacting tens of thousands of victims. The operation involved sophisticated social engineering and financial manipulation, highlighting ongoing risks in fintech and investment platforms.
🔓 VULNERABILITIES & CVEs
-
Forgotten Bootloaders Expose Secure Boot Blind Spot — Dark Reading
Nearly a dozen revoked UEFI shim bootloaders remained trusted for years, enabling attackers to bypass Secure Boot protections. This exposes a critical firmware security gap affecting endpoint integrity and trusted boot chains. -
listmonk: SQL Injection in
/api/subscribers/export— CVE ThreatInt
CVE-2026-62361 affects listmonk prior to 6.2.0, where a user-controlled query parameter in the GET/api/subscribers/exportendpoint allows SQL injection, bypassing table access controls. CVSS pending but exploitation can lead to data exfiltration. -
Multiple critical vulnerabilities in 9Router AI router & token saver:
- CVE-2026-62312: Authenticated remote code execution via unvalidated MCP plugin arguments (pre-0.5.2).
- CVE-2026-56678: Authenticated SSRF via Kiro region injection (pre-0.5.6).
- CVE-2026-56679: Mass assignment in PATCH
/api/settingsallows unauthorized persistent settings changes (pre-0.5.4). - CVE-2026-49353: Local-only access gate bypass via Host header spoofing (≤0.4.45).
- CVE-2026-49352: Hardcoded fallback JWT secret enables authentication bypass (0.2.21–0.4.44).
- CVE-2026-46339: Unauthenticated RCE via unprotected MCP custom plugins (0.4.30–0.4.37).
These collectively represent a severe risk of full system compromise; immediate patching to 0.5.6+ is critical.
-
AVideo Privilege Escalation via Unguarded Permission Parameters — CVE ThreatInt
CVE-2026-33684 allows privilege escalation in WWBN AVideo prior to 29.0 through unguarded parameters in the signUp API, enabling attackers to gain elevated access by solving a CAPTCHA. -
Resource exhaustion in Secure Access publisher — CVE ThreatInt
CVE-2026-55399 affects Secure Access publisher versions prior to 14.55, allowing authenticated attackers to cause non-persistent DoS via resource exhaustion on the tunnel. -
Multiple memory management vulnerabilities in Secure Access clients and servers (CVE-2026-55398, CVE-2026-33445, CVE-2026-33444, CVE-2026-33443) prior to 14.55 enable attackers with tunnel protocol knowledge to cause persistent or non-persistent DoS conditions.
-
NocoBase backup restore schema name command injection — CVE ThreatInt
CVE-2026-55410 affects NocoBase prior to 2.1.19, allowing command injection during PostgreSQL backup restoration via manipulated schema names. This can lead to remote code execution. -
NocoBase SQL Injection in
/api/myInAppChannels:list— CVE ThreatInt
CVE-2026-52887 allows SQL injection to PostgreSQL superuser via a filter parameter in NocoBase prior to 2.0.61, risking full database compromise. -
NocoBase Sensitive Data Exposure via SQL Blacklist Bypass — CVE ThreatInt
CVE-2026-52888 in NocoBase ≤2.0.59 bypasses SQL blacklist filters, exposing sensitive data through crafted queries. -
MCP Python SDK WebSocket transport lacks Host/Origin validation — CVE ThreatInt
CVE-2026-59950 affects MCP Python SDK prior to 1.28.1, where the deprecated WebSocket server transport accepts connections without Host/Origin validation, enabling potential cross-site WebSocket hijacking. -
MCP Python SDK experimental task handlers allow unauthorized access — CVE ThreatInt
CVE-2026-52870 impacts MCP Python SDK versions 1.23.0 to 1.27.2, where experimental task handlers expose unrestricted client access, risking unauthorized command execution.
🕵️ THREAT RESEARCH & DEEP DIVES
- None meeting strict relevance criteria.
📋 VENDOR BULLETINS & ADVISORIES
- None published in this feed cycle.
📰 LESSER-KNOWN / UNDER-REPORTED
- None meeting strict relevance criteria.