VulncastBriefing archive

Weekly Brief - 2026-07-27

· 3263 vulnerabilities · 11 min listen

▶ Listen to this briefing

CVE-2026-28304

critical · CVSS 9.1 · SolarWinds Serv-U

SolarWinds Serv-U is affected by a remote code execution vulnerability that, when exploited, can allow the arbitrary execution of code remotely as root. The impact is lower in Windows deployments.

  • Remote Code Execution
  • file transfer software

CVE-2026-61211

critical · CVSS 9.9 · Oracle RDBMS

Vulnerability in the RDBMS component of Oracle Database Server. Supported versions that are affected are 19.3-19.31 and 23.4.0-23.26.2. Easily exploitable vulnerability allows low privileged attacker having Execute DBMS_CLOUD privilege with network access via Oracle Net to compromise RDBMS. While the vulnerability is in RDBMS, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of RDBMS. CVSS 3.1 Base Score 9.9 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H).

  • Remote Code Execution
  • Unauthorized Access
  • database server
  • oracle net

CVE-2026-46738

critical · CVSS 9.1 · Dell PowerProtect Data Manager

Dell PowerProtect Data Manager, versions prior to 20.2.0.0, contain(s) an Improper Input Validation vulnerability in the REST API. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Elevation of privileges.

  • Improper Input Validation
  • rest api
  • data management

CVE-2026-60366

critical · CVSS 10 · Oracle Fusion Middleware

Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Platform Security for Java. While the vulnerability is in Oracle Platform Security for Java, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Platform Security for Java. CVSS 3.1 Base Score 10.0 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H).

  • Remote Code Execution
  • java
  • web application

CVE-2026-62144

critical · CVSS 9.1 · Check Point Security Management

An authentication bypass vulnerability in Check Point Security Management and Multi-Domain Security Management allows an unauthenticated remote attacker to execute administrative commands on the Management Server. Successful exploitation may also allow command execution on managed Security Gateways. Exploitation requires network access to the Management Server without firewall protection or a configuration that does not restrict Trusted Clients.

  • Authentication Bypass
  • Remote Code Execution
  • network appliance
  • firewall management

CVE-2026-15981

critical · CVSS 9.8 · miniOrange SAML Single Sign On – SSO Login

The SAML Single Sign On – SSO Login plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 5.4.4. This is due to the mo_saml_validate_signature() function performing a loose boolean check on the raw tri-state integer returned by PHP's openssl_verify(), causing an error return value of -1 to be evaluated as truthy and therefore treated as a successful signature verification. This makes it possible for unauthenticated attackers to log in as any existing WordPress user, including administrators, by submitting a crafted SAMLResponse containing an attacker-controlled NameID and a deliberately malformed signature value that triggers an OpenSSL processing error — bypassing verification entirely and resulting in wp_set_auth_cookie() being called for the targeted account.

  • Authentication Bypass
  • wordpress plugin
  • saml
  • authentication

CVE-2026-6516

critical · CVSS 10 · Zohocorp ManageEngine ADAudit Plus

Zohocorp ManageEngine ADAudit Plus versions before 8606 are affected by Unauthenticated Remote code execution due to the vulnerable agent API.

  • Remote Code Execution
  • web application
  • audit management

CVE-2026-65700

critical · CVSS 9.8 · h2oGPT

h2oGPT through 0.2.1 contains a path traversal vulnerability in the OpenAI-compatible files API that allows unauthenticated remote attackers to read, write, and delete arbitrary files accessible to the server process by supplying traversal sequences in the bearer token. The get_user_dir function in openai_server/backend_utils.py uses the bearer token string unsanitized as a path component via os.path.join, and because the default API key is EMPTY authentication is bypassed, enabling attackers to traverse outside the intended user directory through the file content, delete, and upload endpoints to achieve remote code execution by writing to startup hooks or application-loaded files.

  • Path Traversal
  • Authentication Bypass
  • Remote Code Execution
  • ai framework
  • web application

CVE-2026-65907

critical · CVSS 9.1 · JetBrains TeamCity

In JetBrains TeamCity before 2026.1.2, 2025.11.6 code execution in Git VCS roots was possible

  • Remote Code Execution
  • build server
  • continuous integration

CVE-2026-62825

critical · CVSS 10 · Microsoft Azure Key Vault

Improper authentication in Azure Key Vault allows an unauthorized attacker to elevate privileges over a network.

  • Improper Authentication
  • Privilege Escalation
  • cloud platform