๐ต๏ธ RESEARCH & DEEP DIVES
-
Metasploit adds 13 exploit modules, HTTP profiles and ARM shells Rapid7 has added 13 modules and new payload features to Metasploit.
- Metasploit users gain modules targeting WordPress, Ghost CMS, Joomla, Langflow, OpenCATS, Pterodactyl, SonicWall, Ray and WooCommerce.
- The additions include Pterodactyl Panel versions before 1.11.11, SonicWall SMA1000 WorkPlace and Linux systems affected by CVE-2026-46300.
- Pterodactyl CVE-2025-49132 enables unauthenticated RCE through locale-file path traversal and arbitrary file creation.
- New capabilities include HTTP malleable profiles, MCP support, Linux multi-fetch payloads and inline or staged AArch64 reverse-TCP shells. ๐ Source: github.com ยท ๐ Coverage: rapid7.com ยท ๐ via rapid7.com (discovered)
-
Semaphore Git URL Handling Enables OS Command Injection
CVE-2026-73682Semaphore is vulnerable to OS command injection through git_url repository handling.- Semaphore users with Manager or Owner privileges are affected.
- Versions before 2.18.20 are vulnerable.
- Attackers can inject commands through repository git_url handling.
- CVE-2026-73682 has a CVSS score of 8.8. ๐ Coverage: thehackerwire.com ยท ๐ via CVE ThreatInt, thehackerwire.com (discovered)
-
Cockpit CMS Flaw Enables Authenticated Command Injection via FFmpeg
CVE-2026-73680Cockpit CMS contains an authenticated command-injection vulnerability.- Cockpit CMS users with the assets/upload permission are affected.
- Versions 2.14.0 and earlier are vulnerable to arbitrary command execution.
- Attackers inject commands through filenames processed by the FFmpeg integration.
- CVE-2026-73680 carries a CVSS score of 8.8. ๐ Coverage: thehackerwire.com ยท ๐ via CVE ThreatInt, thehackerwire.com (discovered)
๐ CVEs & KEV
- CVE-2026-73683 โ CVSS 9.2 โ Laravel Socialite Facebook Provider Authentication Bypass via Nonce ReplayLar...
- CVE-2026-67365 โ CVSS 9.2 โ Joomla Extension - icagenda.com - Unauthenticated SQL injection in iCagenda <...
- CVE-2026-73682 โ CVSS 8.7 โ Semaphore prior to version 2.18.20 OS Command Injection via git_url Repositor...
- CVE-2026-73680 โ CVSS 8.7 โ Cockpit CMS 2.14.0 Authenticated Command Injection via FFmpeg FilenameCockpit...
- CVE-2026-71571 โ CVSS 8.6 โ Joomla Extension - icagenda.com - Authenticated SQL injection via unescaped n...
- CVE-2026-56865 โ CVSS 8.4 โ Fix transparency log tile verification bypass in golang.org/x/mod/sumdb/tlogA...
- CVE-2026-50523 โ CVSS 7.8 โ Microsoft PowerShell Remote Code Execution VulnerabilityImproper neutralizati...
- CVE-2026-56864 โ CVSS 7.5 โ Ignore unrelated, unauthenticated hashes in Lookup in golang.org/x/mod/sumdbA...
- [CVE-