{"date_iso":"2026-08-04","date_human":"Tuesday, August 4, 2026","generated_utc":"2026-08-04 21:15 UTC","read_minutes":5,"patch_tuesday":false,"top_stories":[{"title":"Google dev kit spurs first-ever agent-on-agent violence","link":"https://www.theregister.com/security/2026/08/03/google-dev-kit-spurs-first-ever-agent-on-agent-violence/5282496","reason":"Google","category":"News","sources":["Bleeping Computer","Dark Reading","Malwarebytes Labs","Proofpoint Threat Insight","SecurityWeek","The Hacker News","The Register Security"],"coverage":7,"cve_ids":[],"summary":"In what they call the first-ever real-world agent-to-agent exploitation method, Pillar Security researchers say they discovered an exploit in the repository behind Google's Agent Development Kit for Python that could\u2026","source":"The Register Security","date_rel":"23h ago","thumbnail":"https://image.theregister.com/?imageId=5282519&width=800","description":"In what they call the first-ever real-world agent-to-agent exploitation method, Pillar Security researchers say they discovered an exploit in the repository behind Google's Agent Development Kit for Python that could allow attackers to compromise supply chains. In other words, now we know that one AI agent can be used to control and compromise another one that has more privileges. The security snafu existed in google/adk-python, an open source Python toolkit with more than 90 million downloads used to build and deploy AI agents. Google has since fixed the underlying issue in the repository\u2026","related":[{"title":"AI Notetaker Lets Hackers Spy on Government, Corporate Video Calls","link":"https://www.darkreading.com/application-security/ai-notetaker-spy-government-corporate-video-calls","source":"Dark Reading","date_rel":"7h ago"},{"title":"Online backlash ends in Google rolling back Google Earth AI tool after a day","link":"https://www.malwarebytes.com/blog/news/2026/08/online-backlash-ends-in-google-rolling-back-google-earth-ai-tool-after-a-day","source":"Malwarebytes Labs","date_rel":"8h ago"},{"title":"Gemini Agent-to-Agent Attack Method Exposed Secrets, Enabled Pull Request Tampering","link":"https://www.securityweek.com/gemini-agent-to-agent-attack-exposed-secrets-enabled-pull-request-tampering/","source":"SecurityWeek","date_rel":"9h ago"},{"title":"Proofpoint Joins Google Unified Security Recommended Program to Help Organizations Defend Against Today\u2019s Most Sophisticated Threats","link":"https://www.proofpoint.com/us/newsroom/press-releases/proofpoint-joins-google-unified-security-recommended-program-help","source":"Proofpoint Threat Insight","date_rel":"9h ago"},{"title":"New Pass-ta-key attacks let malware hijack Google-synced passkeys","link":"https://www.bleepingcomputer.com/news/security/new-pass-ta-key-attacks-let-malware-hijack-google-synced-passkeys/","source":"Bleeping Computer","date_rel":"20h ago"},{"title":"Google Password Manager Attacks Could Let Malware Hijack Passkey-Protected Accounts","link":"https://thehackernews.com/2026/08/google-password-manager-attacks-could.html","source":"The Hacker News","date_rel":"3 Aug"}]},{"title":"CISA Warns of N-able N-central Authentication Bypass Vulnerability Exploited in Attacks","link":"https://cybersecuritynews.com/n-able-n-central-auth-bypass-exploited/","reason":"CVE-2026-18577","category":"News","sources":["Bleeping Computer","CISA Alerts & Advisories","Cyber Security News","Dark Reading","Rapid7 Blog","The Hacker News"],"coverage":6,"cve_ids":["CVE-2026-18577"],"summary":"CISA has warned that attackers are actively exploiting a critical authentication bypass vulnerability in N-able N-central. Tracked as CVE-2026-18577 , the flaw affects N-central servers running versions earlier than\u2026","source":"Cyber Security News","date_rel":"7h ago","thumbnail":"https://cybersecuritynews.com/wp-content/uploads/2026/08/CISA-Warns-of-N-able-N-central-Authentication-Bypass-Vulnerability-Exploited-in-Attacks.webp","description":"CISA has warned that attackers are actively exploiting a critical authentication bypass vulnerability in N-able N-central. Tracked as CVE-2026-18577 , the flaw affects N-central servers running versions earlier than 2026.3.1.7. N-central is a remote monitoring and management platform widely used by managed service providers to administer customer systems. Because the platform provides centralized access to many endpoint devices, a compromise could enable attackers to move across managed environments. CVE-2026-18577 is classified as an authentication bypass vulnerability via an alternate path\u2026","related":[{"title":"CVE-2026-18577: N-able N-central Authentication Bypass Exploited in the Wild","link":"https://www.rapid7.com/blog/post/etr-cve-2026-18577-n-able-n-central-authentication-bypass-exploited-in-the-wild","source":"Rapid7 Blog","date_rel":"9h ago"},{"title":"Attackers Exploit N-able Patch Bypass Flaw on RMM Servers","link":"https://www.darkreading.com/vulnerabilities-threats/attackers-exploit-n-able-patch-bypass-flaw","source":"Dark Reading","date_rel":"23h ago"},{"title":"N-able warns of N-central auth bypass flaw exploited in attacks","link":"https://www.bleepingcomputer.com/news/security/n-able-warns-of-n-central-auth-bypass-flaw-exploited-in-attacks/","source":"Bleeping Computer","date_rel":"3 Aug"},{"title":"CISA Adds One Known Exploited Vulnerability to Catalog","link":"https://www.cisa.gov/news-events/alerts/2026/08/03/cisa-adds-one-known-exploited-vulnerability-catalog","source":"CISA Alerts & Advisories","date_rel":"3 Aug"},{"title":"N-able Says Attackers Take Over N-central Servers After Initial Fix Proves Incomplete","link":"https://thehackernews.com/2026/08/n-able-says-attackers-take-over-n.html","source":"The Hacker News","date_rel":"3 Aug"}]},{"title":"Hackers Can Weaponize Microsoft Copilot to Hijack CEO Accounts and Redirect Wire Transfers","link":"https://cybersecuritynews.com/hackers-weaponize-microsoft-copilot/","reason":"Microsoft","category":"News","sources":["404 Media","Bleeping Computer","Cyber Security News","Malwarebytes Labs","The Record","The Register Security"],"coverage":6,"cve_ids":[],"summary":"A new proof-of-concept reveals how attackers can turn Microsoft Copilot, the AI assistant embedded in Microsoft 365, into an unwitting accomplice for business email compromise (BEC) and large-scale wire fraud. The\u2026","source":"Cyber Security News","date_rel":"3h ago","thumbnail":"https://cybersecuritynews.com/wp-content/uploads/2026/08/Hackers-Weaponize-Microsoft-Copilot.webp","description":"A new proof-of-concept reveals how attackers can turn Microsoft Copilot, the AI assistant embedded in Microsoft 365, into an unwitting accomplice for business email compromise (BEC) and large-scale wire fraud. The demonstration shows that a single compromised employee account can escalate, with alarming speed, into full CEO account takeover and the theft of a quarter of a million dollars, with minimal technical effort from the attacker. The attack begins the moment threat actors gain access to a regular employee\u2019s inbox. Rather than relying on traditional \u201cliving off the land\u201d techniques like\u2026","related":[{"title":"Microsoft Tells Engineers \u2018Tokenmaxxing Is Not What We Are Optimizing For\u2019","link":"https://www.404media.co/microsoft-tells-engineers-tokenmaxxing-is-not-what-we-are-optimizing-for/","source":"404 Media","date_rel":"4h ago"},{"title":"Microsoft Strengthens NuGet Supply Chain Security By Reducing API Key Lifetime","link":"https://cybersecuritynews.com/microsoft-strengthens-nuget-supply-chain-security/","source":"Cyber Security News","date_rel":"4h ago"},{"title":"AI helps Microsoft bug hunters chase a record $20M payday","link":"https://www.theregister.com/security/2026/08/04/ai-helps-microsoft-bug-hunters-chase-a-record-20m-payday/5282821","source":"The Register Security","date_rel":"5h ago"},{"title":"Swiss IT agency hacked, 200 accounts compromised, SharePoint vulns suspected","link":"https://therecord.media/swiss-bit-foitt-hacked-possibly-sharepoint-vulnerabilities","source":"The Record","date_rel":"7h ago"},{"title":"Travelers targeted when logging into hotel Wi-Fi networks","link":"https://www.malwarebytes.com/blog/news/2026/08/travelers-targeted-when-logging-into-hotel-wi-fi-networks","source":"Malwarebytes Labs","date_rel":"8h ago"},{"title":"Hotel Wi-Fi attacks use custom malware to breach Microsoft 365 accounts","link":"https://www.bleepingcomputer.com/news/security/hotel-wi-fi-attacks-use-custom-malware-to-breach-microsoft-365-accounts/","source":"Bleeping Computer","date_rel":"20h ago"}]},{"title":"Mallory Unifies Threat Intelligence, Exposure Context, and Response Into One Architecture for Security Teams","link":"https://cybersecuritynews.com/mallory-unifies-threat-intelligence-exposure-context-and-response-into-one-architecture-for-security-teams/","reason":"Teams","category":"News","sources":["Cyber Security News","Elastic Security Labs","The Hacker News","Wiz Research"],"coverage":4,"cve_ids":[],"summary":"Las Vegas, United States, August 4th, 2026, CyberNewswire As AI-assisted attackers compress exploitation timelines to hours, Mallory turns live adversary intelligence into prioritized, policy-governed action across the\u2026","source":"Cyber Security News","date_rel":"3h ago","thumbnail":"https://i3.wp.com/blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEilQYFaXQzJutaH7hl-0b-fZNl9Pj2QFfhn8y0WC8tl8petfT-OsvUOQBOGQqs-J5TihxgGHU0eLHls9Pq6UQHMGfCs10CqW7G_A93fDrInS8ydHhPGYfbK5Pts0WxUvLKUW6swCn2i9Z00hQZTZH7yiqEoz_K80W2Oy7GaElclO45TC0rgZhGEwFhjI1c/s1600/Insignary%20Launches%20Clarity%20On-Demand%20SBOMs,%20No%20Annual%20Commitment%20Required%20Toronto,%20Canada,%20July%2015th,%202026,%20CyberNewswire%20Enterprise-grade%20binary%20software%20verification%20for%20one%20project,%20one%20team,%20o%20(81).webp?ssl=1","description":"Las Vegas, United States, August 4th, 2026, CyberNewswire As AI-assisted attackers compress exploitation timelines to hours, Mallory turns live adversary intelligence into prioritized, policy-governed action across the tools security teams already run Mallory , the AI-native Threat and Exposure Management platform, today introduced a unified context and intelligence layer for security teams. The architecture has three parts: a context graph that correlates attack surface, threat, and vulnerability data; an intelligent reasoning layer that determines what matters and why; and a policy and\u2026","related":[{"title":"Wiz at Black Hat 2026: Driving AI Threat Readiness","link":"https://www.wiz.io/blog/wiz-at-black-hat-2026","source":"Wiz Research","date_rel":"7h ago"},{"title":"When Vibe Hacking Turns AI into the Junior Hacker Every Adversary Always Wanted","link":"https://thehackernews.com/2026/08/when-vibe-hacking-turns-ai-into-junior.html","source":"The Hacker News","date_rel":"8h ago"},{"title":"FOMO in the SOC: Where AI Platforms like Claude Actually Fit","link":"https://thehackernews.com/2026/08/fomo-in-soc-where-ai-platforms-like.html","source":"The Hacker News","date_rel":"3 Aug"},{"title":"SOC case management and detection rule history in Elastic Security","link":"https://www.elastic.co/security-labs/soc-case-management-detection-rule-history","source":"Elastic Security Labs","date_rel":"3 Aug"}]},{"title":"Fake Adobe and Zoom Updates Install ScreenConnect for Persistent Remote Access","link":"https://thehackernews.com/2026/08/fake-adobe-and-zoom-updates-install.html","reason":"Adobe","category":"News","sources":["CCCS Alerts & Advisories","The Hacker News"],"coverage":2,"cve_ids":[],"summary":"Cybersecurity researchers have disclosed details of an active, multi-wave campaign that employs social engineering lures themed around Adobe and Zoom software updates, business document reviews, and system maintenance\u2026","source":"The Hacker News","date_rel":"7h ago","thumbnail":"https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEi35nnI5-o_HtA0Eunk4tOFM1lg12NrqY7HrDNBbee-kPWR-BHHxXQtd-Tj3b7FrMlTOcWNC63XgVV9n0FEoD-G4ydCpmBv2g1PjvS-lzopLbMnODHbNL2bGMJ6nOYXST9M83vc9IYZaUOjkUqaa4Xo-LaAOtXu3bRhYAcVIUwxgDNMifc6xWI27VVca_B4/s1600/screenconnect.jpg","description":"Cybersecurity researchers have disclosed details of an active, multi-wave campaign that employs social engineering lures themed around Adobe and Zoom software updates, business document reviews, and system maintenance utilities to stealthily deploy Remote Monitoring and Management (RMM) programs like ConnectWise ScreenConnect. The campaign has been codenamed SMOKE#SCREEN by Securonix Threat","related":[{"title":"Adobe security advisory (AV26-776)","link":"https://cyber.gc.ca/en/alerts-advisories/adobe-security-advisory-av26-776","source":"CCCS Alerts & Advisories","date_rel":"43m ago"}]},{"title":"Google Deletes 3 ADK AI Workflows After Malicious GitHub Issue Could Trigger Privileged Agent","link":"https://thehackernews.com/2026/08/google-deletes-3-adk-ai-workflows-after.html","reason":"Github","category":"News","sources":["Bleeping Computer","The Hacker News"],"coverage":2,"cve_ids":[],"summary":"Google deleted three AI agent workflows from its Agent Development Kit (ADK) Python repository. Pillar Security showed that a public GitHub issue could manipulate a triage agent into triggering a privileged code-fixing\u2026","source":"The Hacker News","date_rel":"9h ago","thumbnail":"https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhLUUlqxE9AYL9PyFAlWMsG9czDcrU9p2kMUsumVIYx5SnlMAO0z-n_weUWeX-CiMHQBbkGK1lV-78vp003-bAeRP4gQRyGXlq5blzx5dJdd9zFttd2tjhGlNUFLNk-6ro9GfXMkRCFVLs-ex3gWHoJh-87sZifOeTKohLNoypvvqLUUPLkGUsjKXfAj7A/s1600/google.gif","description":"Google deleted three AI agent workflows from its Agent Development Kit (ADK) Python repository. Pillar Security showed that a public GitHub issue could manipulate a triage agent into triggering a privileged code-fixing agent. The researchers said the public agent could be prompt-injected into posting /adk-issue-fix as adk-bot. They identified the bot as a collaborator, so that comment satisfied","related":[{"title":"New XCSSET variant targets macOS devs via compromised Xcode projects","link":"https://www.bleepingcomputer.com/news/security/new-xcsset-variant-targets-macos-devs-via-compromised-xcode-projects/","source":"Bleeping Computer","date_rel":"1h ago"}]},{"title":"Bypassing AI guardrails is so easy a script kiddie can do it","link":"https://www.theregister.com/security/2026/08/04/bypassing-ai-guardrails-is-so-easy-a-script-kiddie-can-do-it/5282973","reason":"Talos","category":"News","sources":["Infosecurity Magazine","The Register Security"],"coverage":2,"cve_ids":[],"summary":"If you want to bypass AI guardrails designed to stop models from assisting with cyberattacks, you often just have to ask the right way, according to researchers from Cisco Talos. Simply claiming you own the servers\u2026","source":"The Register Security","date_rel":"3h ago","thumbnail":"https://image.theregister.com/?imageId=5283021&width=800","description":"If you want to bypass AI guardrails designed to stop models from assisting with cyberattacks, you often just have to ask the right way, according to researchers from Cisco Talos. Simply claiming you own the servers you're targeting or that you're taking part in a capture-the-flag or bug bounty exercise was often enough to persuade models to cooperate. Talos researchers have been poring over prompt logs and artifacts recovered from threat-actor endpoints running tools such as Claude Code, Codex, Cursor, and Gemini to learn how suspected threat actors are abusing LLMs. The big takeaway from\u2026","related":[{"title":"Cybercriminals Bypass AI Safety Controls by Splitting Malicious Tasks Across Multiple Sessions","link":"https://www.infosecurity-magazine.com/news/talos-attackers-split-tasks-evade/","source":"Infosecurity Magazine","date_rel":"7h ago"}]},{"title":"CISA Adds Three Known Exploited Vulnerabilities to Catalog","link":"https://www.cisa.gov/news-events/alerts/2026/08/04/cisa-adds-three-known-exploited-vulnerabilities-catalog","reason":"Ibm","category":"Advisory","sources":["CCCS Alerts & Advisories","CISA Alerts & Advisories"],"coverage":2,"cve_ids":["CVE-2026-18556","CVE-2026-9198"],"summary":"CISA has added three new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog , based on evidence of active exploitation. CVE-2026-9198 IBM Langflow Code Injection Vulnerability CVE-2026-18556 N-able\u2026","source":"CISA Alerts & Advisories","date_rel":"8h ago","thumbnail":"","description":"CISA has added three new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog , based on evidence of active exploitation. CVE-2026-9198 IBM Langflow Code Injection Vulnerability CVE-2026-18556 N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability CVE-2026-34486 Apache Tomcat Missing Encryption of Sensitive Data Vulnerability These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risks to the federal enterprise. Binding Operational Directive (BOD) 26-04: Prioritizing Security Updates Based on\u2026","related":[{"title":"IBM security advisory (AV26-770)","link":"https://cyber.gc.ca/en/alerts-advisories/ibm-security-advisory-av26-770","source":"CCCS Alerts & Advisories","date_rel":"5h ago"}]},{"title":"Apple launches new legal challenge against UK over iCloud access","link":"https://therecord.media/apple-uk-tcn-icloud-new-legal-challenge","reason":"Apple","category":"News","sources":["The Hacker News","The Record"],"coverage":2,"cve_ids":[],"summary":"Seeking to protect users' iCloud accounts, Apple is reportedly mounting a new challenge to British legal demands for ways around the company's Advanced Data Protection feature.","source":"The Record","date_rel":"7h ago","thumbnail":"http://cms.therecord.media/uploads/apple_logo_pexels_tim_gouw_be4c718ff6.jpg","description":"","related":[{"title":"Chinese Threat Actor Uses Leaked DarkSword Kit to Deploy GHOSTBLADE on iOS","link":"https://thehackernews.com/2026/08/chinese-threat-actor-uses-leaked.html","source":"The Hacker News","date_rel":"3 Aug"}]},{"title":"New DOUBLECUP ClickFix service hides malware in browser cache images","link":"https://www.bleepingcomputer.com/news/security/new-doublecup-clickfix-service-hides-malware-in-browser-cache-images/","reason":"Macos","category":"News","sources":["Bleeping Computer","SANS Internet Storm Center"],"coverage":2,"cve_ids":[],"summary":"A new Russian loader-as-a-service named DOUBLECUP uses ClickFix attacks to hide malicious code in PNG images cached by victims' browsers, ultimately delivering CountLoader to Windows and macOS devices and a new remote\u2026","source":"Bleeping Computer","date_rel":"3 Aug","thumbnail":"","description":"A new Russian loader-as-a-service named DOUBLECUP uses ClickFix attacks to hide malicious code in PNG images cached by victims' browsers, ultimately delivering CountLoader to Windows and macOS devices and a new remote access trojan named DeviceManager to Windows systems.","related":[{"title":"Atomic MacOS (AMOS) stealer infection, (Sun, Aug 2nd)","link":"https://isc.sans.edu/diary/rss/33208","source":"SANS Internet Storm Center","date_rel":"2 Aug"}]}],"worth_reading":[{"title":"8 Best Password Managers (2026), Tested and Reviewed","link":"https://www.wired.com/story/best-password-managers/","reason":"Android","category":"Media","sources":["Bleeping Computer","Wired Security"],"coverage":2,"cve_ids":[],"summary":"Keep your logins locked down with our favorite password management apps for PC, Mac, Android, iPhone, and web browsers.","source":"Wired Security","date_rel":"2 Aug","thumbnail":"https://media.wired.com/photos/690270685216e0070a31d8d0/master/pass/The%20Best%20Password%20Managers%20to%20Secure%20Your%20Digital%20Life.png","description":"","related":[{"title":"Inside the Underground Business of the Android BTMOB RAT malware","link":"https://www.bleepingcomputer.com/news/security/inside-the-underground-business-of-btmob-rat/","source":"Bleeping Computer","date_rel":"3 Aug"}]}],"kev_watch":[],"vuln_watch":[{"id":"CVE-2026-48323","vendor":"Adobe","product":"Adobe Campaign Classic","severity":"CRITICAL","score":10.0,"description":"Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements Used in a Template Engine vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit t\u2026","cwe":"CWE-1336","kev":false,"kev_action":"","kev_due":"","epss":0.0062,"url":"https://cve.blackmesa.ca/?q=CVE-2026-48323"},{"id":"CVE-2026-48330","vendor":"Adobe","product":"Adobe Campaign Classic","severity":"CRITICAL","score":10.0,"description":"Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability that could result in arbitrary code execution in the context of the current user. An attacker \u2026","cwe":"CWE-89","kev":false,"kev_action":"","kev_due":"","epss":0.0068,"url":"https://cve.blackmesa.ca/?q=CVE-2026-48330"},{"id":"CVE-2026-48331","vendor":"Adobe","product":"Adobe Campaign Classic","severity":"CRITICAL","score":10.0,"description":"Adobe Campaign Classic (ACC) is affected by a Server-Side Request Forgery (SSRF) vulnerability that could result in privilege escalation. Exploitation of this issue does not require user interaction. Scope is changed.","cwe":"CWE-918","kev":false,"kev_action":"","kev_due":"","epss":0.0047,"url":"https://cve.blackmesa.ca/?q=CVE-2026-48331"},{"id":"CVE-2026-48326","vendor":"Adobe","product":"Adobe Campaign Classic","severity":"CRITICAL","score":9.9,"description":"Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability that could result in arbitrary code execution in the context of the current user. A low-privil\u2026","cwe":"CWE-89","kev":false,"kev_action":"","kev_due":"","epss":0.0048,"url":"https://cve.blackmesa.ca/?q=CVE-2026-48326"},{"id":"CVE-2026-18602","vendor":"GL.iNet","product":"GL-MT3000","severity":"CRITICAL","score":9.8,"description":"A vulnerability was determined in GL.iNet GL-MT3000 up to 4.4.5. Affected is the function ovpn-client.get_recommend_config of the file /cgi-bin/glc of the component ovpn-client.so Native Plugin. Executing a manipulation of the argument Host\u2026","cwe":"CWE-74","kev":false,"kev_action":"","kev_due":"","epss":0.0199,"url":"https://cve.blackmesa.ca/?q=CVE-2026-18602"},{"id":"CVE-2026-41452","vendor":"krayin","product":"laravel-crm","severity":"CRITICAL","score":9.8,"description":"Krayin CRM 2.2.4 contains a missing authentication vulnerability in the installer middleware that allows unauthenticated remote attackers to overwrite the primary administrator account by sending a crafted HTTP POST request with the X-Reque\u2026","cwe":"CWE-306","kev":false,"kev_action":"","kev_due":"","epss":0.0066,"url":"https://cve.blackmesa.ca/?q=CVE-2026-41452"},{"id":"CVE-2026-18612","vendor":"GL-iNet","product":"GL-MT3000","severity":"CRITICAL","score":9.8,"description":"A flaw has been found in GL-iNet GL-MT3000 up to 4.4.5. This vulnerability affects the function plugins.remove_package/plugins.install_package of the file /cgi-bin/glc of the component plugins.so Native Plugin. This manipulation causes comm\u2026","cwe":"CWE-74","kev":false,"kev_action":"","kev_due":"","epss":0.0216,"url":"https://cve.blackmesa.ca/?q=CVE-2026-18612"},{"id":"CVE-2026-18613","vendor":"GL-iNet","product":"GL-MT3000","severity":"CRITICAL","score":9.8,"description":"A vulnerability has been found in GL-iNet GL-MT3000 up to 4.4.5. This issue affects the function plugins.set_config of the file /cgi-bin/glc of the component plugins.so Native Plugin. Such manipulation leads to injection. The attack can be \u2026","cwe":"CWE-74","kev":false,"kev_action":"","kev_due":"","epss":0.0055,"url":"https://cve.blackmesa.ca/?q=CVE-2026-18613"},{"id":"CVE-2026-18614","vendor":"GL-iNet","product":"GL-MT3000","severity":"CRITICAL","score":9.8,"description":"A vulnerability was found in GL-iNet GL-MT3000 up to 4.4.5. Impacted is the function s2s.enable_echo_server of the file /cgi-bin/glc of the component s2s.so Native Plugin. Performing a manipulation of the argument port results in command in\u2026","cwe":"CWE-74","kev":false,"kev_action":"","kev_due":"","epss":0.0201,"url":"https://cve.blackmesa.ca/?q=CVE-2026-18614"},{"id":"CVE-2026-18615","vendor":"GL-iNet","product":"GL-MT3000","severity":"CRITICAL","score":9.8,"description":"A vulnerability was determined in GL-iNet GL-MT3000 up to 4.4.5. The affected element is the function wg-server.generate_publickey of the file /cgi-bin/glc of the component wg-server.so Native Plugin. Executing a manipulation of the argumen\u2026","cwe":"CWE-74","kev":false,"kev_action":"","kev_due":"","epss":0.0199,"url":"https://cve.blackmesa.ca/?q=CVE-2026-18615"}],"vendor_spikes":[{"vendor":"WordPress","count":22,"critical_count":0},{"vendor":"Microsoft","count":21,"critical_count":1},{"vendor":"Unknown","count":19,"critical_count":1},{"vendor":"HashiCorp","count":12,"critical_count":3},{"vendor":"Red Hat","count":10,"critical_count":0},{"vendor":"TP-Link Systems Inc.","count":7,"critical_count":0},{"vendor":"Adobe","count":7,"critical_count":6},{"vendor":"Eclipse Foundation","count":7,"critical_count":0},{"vendor":"Apache","count":5,"critical_count":0},{"vendor":"GL-iNet","count":5,"critical_count":5}],"epss_risers":[],"developing_map":{},"trending_count":12,"new_cve_count":231,"has_news_data":true,"has_cve_data":true}