๐จ ACTIVE EXPLOITATION
- Attackers Exploit VMware vCenter CVE-2026-59310 for Persistent Access
CVE-2026-59310Attackers are actively exploiting a critical VMware vCenter vulnerability.- Organizations running Broadcom VMware vCenter and related Cloud Foundation or vSphere Foundation products are affected.
- CVE-2026-59310 is a CVSS 9.8 directory-traversal flaw in the vCenter Syslog Server that enables arbitrary code execution.
- Attackers used path traversal to compromise vCenter appliances and deploy a malicious cron job running reverse_ssh for persistence.
- QUIRSO identified 361 victim IP addresses across 47 countries, including Germany, the United States, Turkey, Iran, and France.
- Broadcom fixed the flaw in vCenter 8.0 U3k, Foundation 9.0.2.0100, and Foundation 9.1.0.0300. ๐ Source: medium.com ยท ๐ Coverage: thehackernews.com ยท ๐ via The Hacker News
๐ต๏ธ RESEARCH & DEEP DIVES
-
KVM SEV-SNP Flaw Enables Guest-to-Host Heap Out-of-Bounds Access
CVE-2026-53360Researchers disclosed a KVM SEV-SNP guest-to-host heap out-of-bounds flaw.- KVM hosts running AMD SEV-SNP virtual machines are affected.
- Guest code can trigger an out-of-bounds access in the host heap.
- The issue enables guest-to-host memory corruption.
- An upstream fix has been analyzed. ๐ Source: access.redhat.com ยท ๐ Coverage: blog.himanshuanand.com ยท ๐ via r/netsec
-
ERPNext Document Follow Feature Exposed Sensitive ERP Data ERPNext's Document Follow feature enabled unauthorized access to sensitive ERP data.
- ERPNext customers using the Document Follow feature are affected.
- Sensitive ERP data could be accessed without authorization.
- Researchers chained three vulnerabilities to exfiltrate the data. ๐ Coverage: robinroy.xyz ยท ๐ via r/netsec
-
Tracebit Finds 'Context Bombing' Can Halt AI Hacking Agents Tracebit found that prompt injections can stop guarded AI hacking agents.
- AI hacking agents accessing Amazon Web Services secrets are affected.
- Passwords, cryptographic keys, and other stored secrets can carry the injections.
- The injections command the attacking LLM to perform guardrail-forbidden actions.
- The LLM shuts down after encountering the forbidden commands; Tracebit calls this context bombing. ๐ Source: agentic.tracebit.com ยท ๐ Coverage: schneier.com ยท ๐ via Schneier on Security
๐ ADVISORIES
-
Intel and AMD Patch More Than 80 Vulnerabilities Combined Intel and AMD have patched more than 80 vulnerabilities across their products.
- Intel and AMD customers are affected.
- The flaws include high-severity vulnerabilities in Intel products.
- Successful exploitation can enable privilege escalation or code execution. ๐ Coverage: securityweek.com ยท ๐ via SecurityWeek
-
SP Page Builder 6.7.1 exposed Joomla sites to pre-auth RCE mySites.guru found a pre-authentication RCE in Joomla SP Page Builder.
- Joomla sites using JoomShaper SP Page Builder are affected.
- SP Page Builder 6.7.1 contains a PHP file-inclusion RCE and an arbitrary file-write flaw.
- An anonymous request reaches the Dynamic Content "load more" endpoint using a CSRF token issued to unauthenticated visitors.
- The endpoint derives filesystem paths from attacker-controlled addon data without traversal checks; both issues were fixed in version 6.8.0. ๐ Coverage: mysites.guru ยท ๐ via mysites.guru (discovered)
๐ CVEs & KEV
- CVE-2026-67282 โ CVSS 10.0 โ Joomla Extension - fabrikar.com - Unauthenticated remote code execution in Fa...
- CVE-2026-66659 โ CVSS 9.3 โ Essekia Tablesome Table Critical Blind SQLi
- CVE-2026-64952 โ CVSS 6.5 โ Velociraptor Hunt Deletion With Insufficient Permission CheckThe hunt_delete(...
- CVE-2026-64955 โ CVSS 6.1 โ Velociraptor CSV Formula Injection in Export PipelineWhen Microsoft Excel imp...