๐จ ACTIVE EXPLOITATION
-
Cisco ASA and FTD VPN flaw exploited to crash firewalls
CVE-2026-20349Cisco reports active exploitation of a flaw that crashes ASA and FTD firewalls.- Cisco Secure Firewall ASA and Threat Defense (FTD) appliances are affected.
- CVE-2026-20349 is a heap inspection vulnerability causing denial of service.
- An unauthenticated remote attacker can exploit the VPN flaw to force devices to reload. ๐ Source: sec.cloudapps.cisco.com ยท ๐ Coverage: bleepingcomputer.com ยท ๐ via BleepingComputer, @campuscodi@mastodon.social (+1)
-
Metabase CVE-2026-72898 SQL injection exploited in zero-day attacks
CVE-2026-72898Attackers exploited a critical Metabase SQL injection flaw to steal customer data.- Metabase Cloud and self-hosted instances on versions 1.58 and later are affected; Framework and Tally reported breaches.
- CVE-2026-72898 enables unauthenticated SQL injection, administrator access, credential theft, and data exfiltration.
- Vulnerable branches include 0.58.0โ0.58.23, 0.59.0โ0.59.20, 0.60.0โ0.60.16, 0.61.0โ0.61.10, 0.62.0โ0.62.8, and 0.63.0โ0.63.3.
- The exploit abuses the unauthenticated /api/session/reset_password endpoint with a crafted user-id value interpreted as raw SQL.
- Observed attacks showed POST /api/session/reset_password returning 400, followed by GET /api/user/current returning 200. ๐ Source: nvd.nist.gov ยท ๐ Coverage: wiz.io ยท ๐ via CISA KEV
๐ต๏ธ RESEARCH & DEEP DIVES
-
Zoom annotation flaws enabled zero-click device hijacking during calls Zoom patched annotation flaws that could let meeting participants remotely execute code on other attendees' devices.
- Zoom users on Windows, macOS, Linux, iOS, and Android were affected.
- Zoom Workplace clients through versions 7.0.5, plus Rooms and Meeting SDK clients, were vulnerable.
- CVE-2026-53413 enabled remote code execution through a memory-corruption flaw in the annotation protocol.
- Attackers could send specially crafted annotation messages that clients automatically parsed without user interaction or visible warning.
- Fixed versions included Workplace 7.1.5 and 7.0.6, Rooms 7.1.5, and Meeting SDK 7.1.5. ๐ Source: zoom.com ยท ๐ Coverage: wired.com ยท ๐ via The Hacker News
-
electerm flaw enables command injection via crafted FTP/SFTP folders
CVE-2026-73224electerm is vulnerable to command injection through crafted FTP/SFTP folder names.- electerm versions before 3.15.120 are affected.
- A malicious FTP or SFTP server can target electerm users with downloaded folders.
- The vulnerable calcLocal function inserts folder names into a du -sh shell command without escaping single quotes.
- Execution occurs when a user opens Properties and selects Calculate Size for the crafted folder.
- CVE-2026-73224 has a CVSS score of 8.8; no public PoC was available. ๐ Source: undercode.help ยท ๐ Coverage: thehackerwire.com ยท ๐ via thehackerwire.com (discovered)
-
Expired DMARC domain exposed email reports from 86 domains An expired DMARC reporting domain began receiving reports from 86 domains.
- The reports covered more than 20 organizations, including The Toro Company, universities, school districts, education agencies, counties, and commercial domains.
- The exposed data came from DMARC aggregate-reporting addresses configured with gca-emailauth[.]org.
- The domain had been published in Global Cyber Alliance DMARC training documents since at least 2019 before expiring.
- A researcher registered gca-emailauth[.]org for $10 and received reports from 86 domains, including 56 associated with The Toro Company.
- The Toro Company's myturf[.]com distributor platform was among the domains and used a DMARC policy of p=none. ๐ Source: reddit.com ยท ๐ Coverage: sh.consulting ยท ๐ via r/netsec
-
Sub2API path traversal lets tenants relay requests through pooled credentials
CVE-2026-73079Sub2API has a high-severity path traversal vulnerability.- Sub2API AI API gateway deployments and their authenticated tenants are affected.
- Versions 0.1.135 through 0.1.168 are vulnerable to CVE-2026-73079.
- A tenant with a valid platform API key can target arbitrary upstream endpoints.
- The flaw affects POST /responses/*subpath routes that splice client input into upstream URLs.
- Requests use the operator's pooled provider credentials; CVSS 8.5. ๐ Source: github.com ยท ๐ Coverage: thehackerwire.com ยท ๐ via thehackerwire.com (discovered)
๐ CVEs & KEV
- CVE-2026-48804 โ CVSS 7.5 โ python-socketio: Binary attachment accumulation can cause denial of servicepy...
- CVE-2026-18712 โ CVSS 7.2 โ Improper Authorization in MongoDB Queryable Encryption Maintenance Operations...
- CVE-2026-18711 โ CVSS 7.1 โ Use-After-Free in MongoDB Query Execution Engine Leads to Denial of Service a...
- CVE-2026-68872 โ CVSS 6.5 โ Apache Airflow Amazon provider: amazon SSM / Secrets Manager backends: team-s...
- CVE-2026-71474 โ CVSS 6.3 โ Insights-client-rhel9: insights-client: pull-secret bearer token written to l...