View Ridge Security
Back to Cyber HoseVulnerabilities & CVEs

ComfyUI 0.23.0 vulnerable to unauthenticated remote code execution

๐Ÿ’ฅ BREACHES & INCIDENTS

  • Amgen reports cloud data breach exposing patient health and proprietary info
    Amgen suffered a cloud data breach exposing patient and corporate information.
    • Applies to Amgen, a biotechnology company in California
    • Patient protected health information and proprietary corporate data stolen
    • Data stored in multiple cloud systems operated by third-party providers
    • Attack detected in July 2026; investigation ongoing with forensic experts
    • No disclosed details on attack method, affected cloud providers, or threat actors
      ๐Ÿ“Ž Coverage: bleepingcomputer.com ยท ๐Ÿ‘ via BleepingComputer

๐Ÿ•ต๏ธ RESEARCH & DEEP DIVES

  • Adform's ad platform script compromised to steal cryptocurrency via clipboard hijacking
    Adform's advertising script was compromised to replace crypto wallet addresses with attacker-controlled ones.

    • Applies to websites using Adform's ad platform, including its DSP, SSP, and ad servers
    • Malicious script trojanized 'trackpoint-async.js' served from s2.adform.net
    • Script monitors clipboard for Bitcoin, Ethereum, or TRON wallet addresses and replaces them with attacker addresses
    • Malware also rewrites wallet addresses displayed on web pages
    • Malicious code communicated with attacker server at 84.32.102.230:7744 and was undetected by antivirus
    • Incident discovered July 27, 2026; malicious code removed shortly after
      ๐Ÿ“Ž Coverage: bleepingcomputer.com ยท ๐Ÿ‘ via BleepingComputer
  • Midnight Blizzard's Storm-2945 targets travelers via hotel captive portals for malware and credential theft
    Midnight Blizzard's Storm-2945 exploits hotel captive portals to deliver malware and steal traveler credentials.

    • Targets hospitality sector networks worldwide, including hotels and conference centers
    • Compromises captive portal sign-in systems to redirect traffic through attacker-controlled infrastructure
    • Delivers malware posing as browser or OS updates, including Windows RATs with extensive espionage capabilities
    • Uses adversary-in-the-middle phishing with doppelganger domains mimicking Microsoft services
    • Employs AI-augmented operations and ClickFix social engineering to trick users into installing malware
      ๐Ÿ“Ž Coverage: microsoft.com ยท ๐Ÿ“„ Original: microsoft.com ยท ๐Ÿ‘ via Microsoft Security Blog

๐Ÿ”“ CVEs & KEV

  • ComfyUI 0.23.0 vulnerable to unauthenticated remote code execution via pickle deserialization CVE-2026-68771
    ComfyUI 0.23.0 has an unauthenticated RCE vulnerability via unsafe pickle deserialization.

    • Applies to ComfyUI version 0.23.0
    • Vulnerability in LoadTrainingDataset node allows arbitrary Python code execution
    • Attackers upload crafted shard_*.pkl files via unauthenticated POST /upload/image endpoint
    • Arbitrary code executed when torch.load deserializes attacker-controlled pickle payload
    • No authentication required; CVSS 9.8 critical severity
      ๐Ÿ“Ž Coverage: cve.threatint.com ยท ๐Ÿ‘ via CVE ThreatInt
  • Critical RCE Vulnerability in sentence-transformers via Local Model Load Bypass CVE-2026-68770
    sentence-transformers allows arbitrary code execution when loading local models despite security flags.

    • Applies to all versions of the sentence-transformers library
    • Vulnerability in import_module_class helper allows bypass of trust_remote_code=False
    • Attackers controlling model directory can execute malicious Python code at model load
    • Exploitation requires placing crafted files like modeling_*.py referenced in modules.json
    • Critical severity with CVSS 9.8, no privileges or user interaction needed
      ๐Ÿ“Ž Coverage: cve.threatint.com ยท ๐Ÿ“„ Original: cve.threatint.com ยท ๐Ÿ‘ via CVE ThreatInt
  • Savon Ruby SOAP Client Vulnerable to Code Execution via WSDL Operation Names (CVE-2026-53510) CVE-2026-53510
    Savon Ruby SOAP client versions before 2.17.2 allow remote code execution via crafted WSDL operation names.

    • Applies to Savon Ruby SOAP client versions from 0.9.8 up to 2.17.2
    • Vulnerability in Savon::Model.all_operations method evaluating WSDL operation names as Ruby code
    • Attacker-controlled WSDL operation names are interpolated into Ruby source passed to module_eval
    • Allows remote attackers to execute arbitrary Ruby code within the application process
    • Fixed in Savon version 2.17.2
      ๐Ÿ“Ž Coverage: cve.threatint.com ยท ๐Ÿ“„ Original: cve.threatint.com ยท ๐Ÿ‘ via CVE ThreatInt
  • CVE-2026-53599 โ€” CVSS 7.5 โ€” Redaxo has a Mediapool isAllowedExtension bypass via multi-segment filename t...

  • CVE-2026-62999 โ€” CVSS 7.5 โ€” Copier: Percent-encoded dot segments in template URLs can allow trusted-prefi...

  • CVE-2026-18394 โ€” CVSS 7.4 โ€” Incorrect authorization in Strands Agents Tools http_request proxy credential...

  • CVE-2026-65981 โ€” CVSS 7.1 โ€” Coturn: MOBILITY-TICKET session-resume authorization bypass allows cross-user...

  • CVE-2026-45086 โ€” CVSS 5.4 โ€” Decidim: Forms admin question editor lacks authorizationDecidim is a particip...

  • CVE-2026-62324 โ€” CVSS 5.4 โ€” Jodit has incomplete javascript: scheme normalization in sanitizeHTMLElement ...

  • CVE-2026-55825 โ€” CVSS 3.1 โ€” Contao: Possible path traversal in job download URIsContao is an Open Source ...

  • CVE-2026-53551 โ€” CVSS โ€” โ€” free5GC AUSF: null byte injection in supiOrSuci causes HTTP 500 internal serv...

  • CVE-2026-62959 โ€” CVSS โ€” โ€” Coturn: Pre-authentication heap memory disclosure in ACME redirect (`try_acme...

  • CVE-2026-65841 โ€” CVSS โ€” โ€” Jodit has cross-site scripting (XSS) via <script> nested in SVG that bypasses...

Need help assessing your exposure?

Start with the free Posture Self-Check to see where you stand against the current threat landscape.

Free Posture Self-Check