VulncastBriefing archive

Monthly Brief - 2026-08-01

· 9665 vulnerabilities · 20 min listen

▶ Listen to this briefing

CVE-2026-46738

critical · CVSS 9.1 · Dell PowerProtect Data Manager

Dell PowerProtect Data Manager, versions prior to 20.2.0.0, contain(s) an Improper Input Validation vulnerability in the REST API. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Elevation of privileges.

  • Improper Input Validation
  • rest api
  • data management

CVE-2026-60366

critical · CVSS 10 · Oracle Fusion Middleware

Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Platform Security for Java. While the vulnerability is in Oracle Platform Security for Java, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Platform Security for Java. CVSS 3.1 Base Score 10.0 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H).

  • Remote Code Execution
  • java
  • web application

CVE-2026-62144

critical · CVSS 9.1 · Check Point Security Management

An authentication bypass vulnerability in Check Point Security Management and Multi-Domain Security Management allows an unauthenticated remote attacker to execute administrative commands on the Management Server. Successful exploitation may also allow command execution on managed Security Gateways. Exploitation requires network access to the Management Server without firewall protection or a configuration that does not restrict Trusted Clients.

  • Authentication Bypass
  • Remote Code Execution
  • network appliance
  • firewall management

CVE-2026-15981

critical · CVSS 9.8 · miniOrange SAML Single Sign On – SSO Login

The SAML Single Sign On – SSO Login plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 5.4.4. This is due to the mo_saml_validate_signature() function performing a loose boolean check on the raw tri-state integer returned by PHP's openssl_verify(), causing an error return value of -1 to be evaluated as truthy and therefore treated as a successful signature verification. This makes it possible for unauthenticated attackers to log in as any existing WordPress user, including administrators, by submitting a crafted SAMLResponse containing an attacker-controlled NameID and a deliberately malformed signature value that triggers an OpenSSL processing error — bypassing verification entirely and resulting in wp_set_auth_cookie() being called for the targeted account.

  • Authentication Bypass
  • wordpress plugin
  • saml
  • authentication

CVE-2026-6516

critical · CVSS 10 · Zohocorp ManageEngine ADAudit Plus

Zohocorp ManageEngine ADAudit Plus versions before 8606 are affected by Unauthenticated Remote code execution due to the vulnerable agent API.

  • Remote Code Execution
  • web application
  • audit management

CVE-2026-65700

critical · CVSS 9.8 · h2oGPT

h2oGPT through 0.2.1 contains a path traversal vulnerability in the OpenAI-compatible files API that allows unauthenticated remote attackers to read, write, and delete arbitrary files accessible to the server process by supplying traversal sequences in the bearer token. The get_user_dir function in openai_server/backend_utils.py uses the bearer token string unsanitized as a path component via os.path.join, and because the default API key is EMPTY authentication is bypassed, enabling attackers to traverse outside the intended user directory through the file content, delete, and upload endpoints to achieve remote code execution by writing to startup hooks or application-loaded files.

  • Path Traversal
  • Authentication Bypass
  • Remote Code Execution
  • ai framework
  • web application

CVE-2026-65907

critical · CVSS 9.1 · JetBrains TeamCity

In JetBrains TeamCity before 2026.1.2, 2025.11.6 code execution in Git VCS roots was possible

  • Remote Code Execution
  • build server
  • continuous integration

CVE-2026-62825

critical · CVSS 10 · Microsoft Azure Key Vault

Improper authentication in Azure Key Vault allows an unauthorized attacker to elevate privileges over a network.

  • Improper Authentication
  • Privilege Escalation
  • cloud platform

CVE-2026-51303

critical · CVSS 9.8 · SQLite

A use-after-free (UAF) vulnerability was discovered in the core parsing component of SQLite 3.41. The flaw occurs because the program frees an ExprList object via sqlite3ExprListDelete and then subsequently accesses the dangling pointer of the released object. A remote adversary can supply specially crafted SQL queries to trigger this vulnerability during SQL statement parsing. Successful exploitation may result in application crash (denial of service), sensitive memory information leakage, and in some scenarios, arbitrary code execution on the affected host.

  • Use-After-Free
  • Denial Of Service
  • Remote Code Execution
  • database engine
  • sql

CVE-2026-63077

critical · CVSS 9.8 · JetBrains TeamCity

In JetBrains TeamCity before 2026.1.3, 2025.11.7 unauthenticated remote code execution was possible via the agent polling protocol

  • Remote Code Execution
  • ci/cd pipeline

CVE-2026-11756

critical · CVSS 10 · Dassault Systèmes 3DEXPERIENCE

A Deserialization of Untrusted Data vulnerability affecting Station Launcher App in 3DEXPERIENCE platform from Release 3DEXPERIENCE R2023x through Release 3DEXPERIENCE R2026x could lead to an unauthenticated remote code execution.

  • Deserialization of Untrusted Data
  • Remote Code Execution
  • desktop application
  • enterprise software

CVE-2026-14512

critical · CVSS 9.8 · IBM WebSphere Application Server

IBM WebSphere Application Server 9.0, and 8.5 traditional is vulnerable to pre-authentication unsafe deserialization which could allow a remote attacker to bypass authentication or execute arbitrary code.

  • Remote Code Execution
  • Insecure Deserialization
  • application server

CVE-2026-66713

critical · CVSS 9.8 · Apache Software Foundation Apache Axis2

Deserialization of Untrusted Data (CWE-502) in the Tribes-based clustering component  in Apache Software Foundation Apache Axis2/Java through 2.0.0 on Apache Tomcat  (only when Tribes clustering is enabled, which is off by default) allows an  unauthenticated remote attacker with network access to the clustering port to  execute arbitrary code via a crafted serialized Java object delivered to the cluster  channel and deserialized in  org.apache.axis2.clustering.tribes.Axis2ChannelListener#messageReceived. Users are  recommended to upgrade to version 2.0.1, which fixes this issue by removing the  clustering feature entirely.

  • Insecure Deserialization
  • Remote Code Execution
  • java
  • application server

CVE-2026-14529

critical · CVSS 9.4 · IBM WebSphere Application Server

IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8 traditional is vulnerable to server-side request forgery (SSRF) when the SIP container feature (sipServlet-1.1) is enabled.

  • Server Side Request Forgery
  • application server

CVE-2026-41939

critical · CVSS 9.8 · Epic Care Everywhere Gateway

Care Everywhere Gateway 14.3.10 contains a hard-coded credentials vulnerability in the bundled WildFly 8.2.0.Final management interface that allows unauthenticated remote attackers to gain administrative access by using default credentials identical across all installations. Attackers can authenticate to the exposed WildFly management console on port 20990 and deploy a malicious Web Application Archive file through the Deployments interface to achieve remote code execution as the Windows machine account. Version 14.x.x was declared end-of-life (EOL) in 2017 and future releases have addressed the vulnerable finding.

  • Hard-coded Credentials
  • Remote Code Execution
  • web application
  • java

CVE-2026-51992

critical · CVSS 9.1 · ClickHouse Server

SQL Injection vulnerability in ClickHouse Server Versions <= 26.3.9.8 allows a remote attacker to execute arbitrary code via the create dictionaries function.

  • SQL Injection
  • Remote Code Execution
  • database
  • web application

CVE-2026-58150

critical · CVSS 10 · Apache Traffic Server

Apache Traffic Server does not reject Transfer-Encoding in HTTP/2 requests, allowing downgrade request smuggling. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the issue.

  • Request Smuggling
  • proxy server
  • http server

CVE-2026-59309

critical · CVSS 9.8 · VMware vCenter

VMware vCenter contains an authentication bypass vulnerability in the VMware Directory Service. A malicious actor with network access to vCenter may exploit this issue to bypass authentication and gain unauthorized access to the system.

  • Authentication Bypass
  • virtualization platform
  • directory service

CVE-2026-66803

critical · CVSS 10 · Microsoft Azure Cosmos DB

Improper access control in Azure Cosmos DB allows an unauthorized attacker to execute code over a network.

  • Remote Code Execution
  • database
  • cloud platform

CVE-2026-7849

critical · CVSS 9.8 · Unknown

Due to improper neutralization of special elements, an unauthenticated remote attacker is able to inject a command into the system configuration which is subsequently executed as root.

  • Command Injection
  • unknown