VulncastBriefing archive

Daily Brief - 2026-07-08

· 5 vulnerabilities · 6 min listen

▶ Listen to this briefing

CVE-2026-12375

critical · CVSS 9.8 · Uncanny Automator Pro

The uncanny-automator-pro WordPress plugin before 7.3.0.6 was distributed with malicious code after the vendor's uncanny-automator-pro WordPress plugin before 7.3.0.6 update/distribution infrastructure was compromised; the injected backdoor grants unauthenticated attackers an administrator session on affected sites and beacons the site's secret keys and administrator details to attacker-controlled servers.

  • Backdoor
  • Remote Code Execution
  • cms plugin
  • php

CVE-2026-13019

critical · CVSS 9.8 · Esri Portal for ArcGIS

Esri Portal for ArcGIS versions 12.1 and earlier on Windows, Linux and Kubernetes have a missing authentication for critical function vulnerability allows a remote, unauthenticated attacker to access an unprotected API.

  • Broken Access Control
  • web application
  • server software

CVE-2026-14476

high · CVSS 8 · Red Hat SSSD

A path traversal flaw was found in SSSD's AD GPO provider. The ad_gpo_extract_smb_components() function does not sanitize .. sequences in the gPCFileSysPath LDAP attribute, allowing an attacker with AD GPO management access to write files outside the GPO cache directory as root. On default RHEL configurations with SELinux enforcing, this can be used to inject Kerberos configuration leading to authentication bypass.

  • Path Traversal
  • Authentication Bypass
  • linux
  • authentication

CVE-2026-33264

critical · CVSS 9.8 · Apache Airflow

A bug in `BaseSerialization.deserialize()` allowed unrestricted `import_string()` of attacker-controlled class paths when the Scheduler / API Server loaded a serialized DAG: a DAG author could embed a malicious trigger into a DAG to gain remote code execution on the API Server / Scheduler process, crossing the Airflow security boundary that DAG-author code must never execute in those processes. Users are advised to upgrade to `apache-airflow` 3.3.0 or later. As a defense-in-depth mitigation, deployments where DAG-author trust is limited can restrict the `[core] allowed_deserialization_classes` config to a narrow allowlist.

  • Remote Code Execution
  • scheduler
  • api server

CVE-2026-53483

critical · CVSS 9.8 · Dell PowerProtect Data Domain

Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.7, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS2025 release version 8.3.1.0 through 8.3.1.30, LTS2024 release versions 7.13.1.0 through 7.13.1.70 an improper authentication vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to unauthorized access. This is a critical severity vulnerability as it allows an attacker to take complete control of system; so Dell recommends customers to upgrade at the earliest opportunity.

  • Authentication Bypass
  • backup appliance
  • networking