Related Threat Clusters
-
Critical SQL Injection and XSS Vulnerabilities in RoundcubeMail Affect Fedora Users
Recent updates to RoundcubeMail for Fedora 43 and 44 revealed critical vulnerabilities, including SQL injection and cross-site scripting (XSS) issues. CVE-2026-48842 details a pre-auth SQL injection in the…
2 articles · Updated June 4, 2026 -
Critical Vulnerabilities in pgAdmin 4 Expose Databases to Remote Code Execution
pgAdmin 4 version 9.16 was released to patch seven vulnerabilities, including critical issues tracked as CVE-2026-12044 to CVE-2026-12050. These vulnerabilities could allow attackers to execute arbitrary commands, gain…
9 articles · Updated June 22, 2026 -
Critical Authentication Bypass Vulnerability in Spring Authorization Server
A critical vulnerability, CVE-2026-22752, has been identified in Spring Authorization Server, affecting versions 1.3.0 to 1.3.10, 1.4.0 to 1.4.9, 1.5.0 to 1.5.6, and 7.0.0 to 7.0.4. The flaw allows attackers with a…
2 articles · Updated July 18, 2026 -
AI Discovers 38 Vulnerabilities in OpenEMR Healthcare Software
An AI analysis by Aisle revealed 38 security vulnerabilities in OpenEMR, a widely used electronic health record platform. These vulnerabilities, which include critical SQL injection flaws, could have allowed attackers…
2 articles · Updated April 29, 2026 -
Critical SAP Vulnerabilities Require Immediate Patching
SAP has released security updates addressing 15 vulnerabilities, including four critical ones affecting SAP NetWeaver and SAP Commerce Cloud. The vulnerabilities include CVE-2026-44748, allowing authenticated attackers…
8 articles · Updated June 9, 2026 -
SAP Addresses Critical Vulnerabilities in Commerce Cloud and S/4HANA
On May 12, 2026, SAP released security updates for 15 vulnerabilities, including two critical flaws in Commerce Cloud and S/4HANA. The first critical vulnerability (CVE-2026-34263) allows unauthenticated attackers to…
6 articles · Updated May 12, 2026 -
Multiple Vulnerabilities Discovered in Splunk Products Affecting Security Integrity
Splunk has disclosed several vulnerabilities affecting its products, including Splunk Enterprise, SOAR, and AI Toolkit. Key vulnerabilities include CVE-2026-76338, CVE-2026-76352, CVE-2026-76362, CVE-2026-76364, and…
8 articles · Updated August 20, 2026 -
Critical Vulnerabilities Found in Thousands of MCP Servers
A large-scale analysis revealed that 5,832 out of 9,695 Model Context Protocol (MCP) servers are vulnerable to critical security flaws, including arbitrary file access, command injection, and SQL injection. These…
13 articles · Updated July 7, 2026 -
Vulnerabilities in Vibe-Coded Applications Highlighted
Recent analyses of vibe-coded applications reveal common security vulnerabilities due to the nature of AI coding agents. Tenzai's research identified 69 vulnerabilities across five popular coding agents, focusing on…
2 articles · Updated June 1, 2026 -
AI-Driven Threats and Supply Chain Risks Highlighted at AppSec Summit 2026
The San Francisco Secure Software and AppSec Summit 2026 gathered over 150 security professionals to address emerging threats in application security, particularly those posed by AI-driven technologies. Key discussions…
2 articles · Updated May 18, 2026
Recent Intelligence Reports
- SVD-2026-0804: Security Hardening Release for Splunk SOAR - August 2026 Splunk Security Announcements / 19h In Splunk SOAR versions below 8.6.0, an authenticated user with no role assigned could submit a crafted file path to the Representational State Transfer (REST) API and execute arbitrary code. In Splunk SOAR versions below 8.6.0, a user who holds the Administrator role could use path traversal in the Universal Forwarder installer’s archive extraction to write files outside the intended inst — advisory.splunk.com · August 20, 2026
- 74 — cwe.mitre.org · August 17, 2026
- Microsoft open — Feeds.4Sysops · July 20, 2026
- Cve 2026 22752 — spring.io · July 18, 2026
- Thousands of MCP Servers Found Vulnerable to File Access and Injection Attacks — Gbhackers · July 7, 2026
- pgAdmin 4 Released with Patches for Seven Vulnerabilities and Feature Enhancements — Gbhackers · June 22, 2026
- How Hackers Operate: The Tools Behind Real — Analyticsinsight · June 21, 2026
- SAP fixes critical flaws in NetWeaver and Commerce Cloud — Bleepingcomputer · June 9, 2026