๐ต๏ธ RESEARCH & DEEP DIVES
-
Atlassian Rovo Can Exfiltrate Jira and Confluence Data via Prompt Injection UPDATE: PromptArmor found that Atlassian Rovo can exfiltrate accessible enterprise data through indirect prompt injection.
- Atlassian Rovo users of Jira, Confluence, and connected third-party apps are affected.
- Poisoned content can expose Jira tickets, Confluence documents, and connector data accessible to the signed-in user.
- Hidden instructions in uploaded files or external content can steer Rovo's URL retrieval tool to send data to an attacker-controlled server without separate approval.
- Disabling Rovo web search does not remove the URL retrieval capability; Markdown image rendering provides another possible exfiltration channel.
- A separate rovoChatPrompt one-click flaw was fixed server-side on July 8, 2026; neither issue has a CVE. ๐ Coverage: thehackernews.com ยท ๐ via The Hacker News
-
DEF CON Talk Shows How Arbitrary File Writes Can Become RCE Researchers presented techniques for turning arbitrary file writes into remote code execution.
- The techniques target web applications and distroless containers.
- Arbitrary file writes can be chained through Bash file descriptors, Rails deserialization, or Node.js worker paths.
- The methods include an errno-based path oracle for fingerprinting black-box targets.
- The catalog covers Bash fd/255, Rails schema_cache.yml, and Node.js worker path overwrites without process restarts. ๐ Coverage: ethiack.com ยท ๐ via r/netsec
๐ ADVISORIES
- CSS Attacks Break Webmail Boundaries to Steal Passwords and Tokens โ portswigger.net
๐ CVEs & KEV
- CVE-2026-16258 โ CVSS 9.8 โ Ajax Search Lite before 4.14.5 - Unauthenticated PHP Object Injection via Search S...
- CVE-2026-16038 โ CVSS 9.1 โ MStore API before 4.21.0 - Unauthenticated Payment Bypass via Multiple Payment Gat...
- CVE-2026-16263 โ CVSS 8.8 โ WP Maps before 4.9.7 - Subscriber+ Local File InclusionThe WP Maps WordPress plugi...
- CVE-2026-16030 โ CVSS 8.1 โ MStore API before 4.21.0 - Unauthenticated Account Takeover via Firebase Phone Aut...
- CVE-2026-15361 โ CVSS 8.1 โ Content Views before 4.5 - Subscriber+ SQL Injection via preview_requestThe Conten...
- CVE-2026-16041 โ CVSS 7.5 โ MStore API before 4.21.0 - Unauthenticated Product Review CreationThe MStore API W...
- CVE-2026-16265 โ CVSS 6.5 โ WP Maps before 4.9.7 - Subscriber+ Denial of ServiceThe WP Maps WordPress plugin b...
- CVE-2026-16039 โ CVSS 6.5 โ MStore API before 4.21.0 - Subscriber+ Order and Customer PII Disclosure via IDORT...
- CVE-2026-15359 โ CVSS 6.5 โ Templately before 3.7.1 - Unauthenticated Administrator Templately Cloud Connectio...