π΅οΈ RESEARCH & DEEP DIVES
- Elementor Pro flaw enables unauthenticated file upload and remote code execution
Elementor Pro contains an unauthenticated file-upload flaw enabling remote code execution.- Elementor Pro users running version 4.2.1 or earlier are affected.
- The Forms moduleβs File Upload field can place executable PHP files in a public directory.
- An attacker submits two file parts for one field, starting with an empty entry and following with a PHP payload.
- The validation loop stops at the empty entry while the processing loop still moves the PHP file.
- The flaw is tracked as CVE-2026-32475 with a CVSS score of 9.0.
π Source: wordfence.com Β· π Coverage: patchstack.com Β· π via patchstack.com (discovered)
π ADVISORIES
- AWS details user-authorization propagation for Bedrock AgentCore AI agents
AWS describes a pattern for propagating user authorization context through Bedrock AgentCore agents.- Organizations using Amazon Bedrock AgentCore agents with DynamoDB, document repositories, SaaS platforms, and internal knowledge bases are affected.
- Agents that lack the requester's identity may return data the user is not authorized to access.
- The pattern passes user authorization context through the agent to infrastructure and downstream services.
- Access control is enforced outside agent code to support least-privilege access in shared-agent scenarios such as Sales and Finance CRM use.
π Coverage: aws.amazon.com Β· π via AWS Security Blog
π ADVISORIES
- π Source for search-v2-operator Assigned Cluster-Admin-Equivalent Privileges β access.redhat.com
π CVEs & KEV
-
CVE-2026-55194 β CVSS 8.7 β FreeRDPHeap-buffer-overflow write in TS Gateway RPC RESPONSE reassembly due t...
-
CVE-2026-75149 β CVSS 8.7 β marimo before 0.23.15 Code Injection via MCP Server Configurationmarimo before 0.2...
-
CVE-2026-55193 β CVSS 8.7 β FreeRDP: Heap-buffer-overflow write in TS Gateway RPC fragment receive due to...
-
CVE-2026-61518 β CVSS 8.7 β ISPConfig Authenticated SQL Injection via Remote API primary_id ParameterISPC...
-
CVE-2026-19234 β CVSS 8.2 β This Power System update is being released to addressIBM Power Firmware FW112...
-
CVE-2026-63633 β CVSS 7.7 β FreeRDP: Heap buffer overflow in Opus audio decode (
freerdp_dsp_decode_opus... -
CVE-2026-55192 β CVSS 7.2 β FreeRDP: Out-of-bounds read in H.264 YUV-to-RGB conversion due to decoder/sur...
-
CVE-2026-63652 β CVSS 7.1 β FreeRDP: Double-free of
client_formatsin the rdpsnd server channel on a ma... -
CVE-2026-63117 β CVSS 6.5 β FreeRDP: Denial of service through ADPCM frame size calculationFreeRDP is a f...
-
CVE-2026-18874 β CVSS 6.2 β Volsync-addon-controller: volsync-addon-controller: annotation values rendere...
-
CVE-2026-55648 β CVSS 6.1 β FreeRDP: Integer Overflow in
freerdp_image_copy_from_icon_dataBypasses Bou...