View Ridge Security
Back to Cyber HoseThreat Research & Deep Dives

Attackers Target CI/CD Pipelines in SDLC Supply Chains

๐Ÿ•ต๏ธ RESEARCH & DEEP DIVES

๐Ÿ”“ CVEs & KEV

  • CVE-2026-53528 โ€” CVSS 8.8 โ€” FileWiki has path traversal in RenameAsset via unsanitized oldFilename parame...

  • CVE-2026-53527 โ€” CVSS 8.8 โ€” LeafWiki Vulnerable to Privilege Escalation via User Self-Service UpdateLeafW...

  • CVE-2026-33240 โ€” CVSS 8.8 โ€” Combodo iTop: Reflected XSS in foreign key search criteriaCombodo iTop is a w...

  • CVE-2026-31936 โ€” CVSS 8.8 โ€” Combodo iTop: Unauthorized access to object information via search operationC...

  • CVE-2026-34741 โ€” CVSS 8.6 โ€” Combodo iTop: Authentication bypass in exec.php allows PHP file executionComb...

  • CVE-2026-34836 โ€” CVSS 6.5 โ€” Combodo iTop: Improper access control in ajax.render.php and ajax.document.ph...

  • CVE-2026-77811 โ€” CVSS 6.2 โ€” OpenSearch Dashboards Plugin XSS (CVE-2026-77811)

Need help assessing your exposure?

Start with the free Posture Self-Check to see where you stand against the current threat landscape.

Free Posture Self-Check