{"date_iso":"2026-08-05","date_human":"Wednesday, August 5, 2026","generated_utc":"2026-08-05 13:37 UTC","read_minutes":5,"patch_tuesday":false,"top_stories":[{"title":"1-Click RCE Flaw in Cursor, VS Code, and Google Antigravity Exposes 50M Developers to Cyberattacks","link":"https://cybersecuritynews.com/1-click-rce-vulnerability-in-code-editors/","reason":"Google","category":"News","sources":["Bleeping Computer","Cyber Security News","Dark Reading","Malwarebytes Labs","Proofpoint Threat Insight","The Hacker News","The Register Security"],"coverage":7,"cve_ids":[],"summary":"A critical one-click remote code execution (RCE) vulnerability affects three of the world\u2019s most widely used code editors: Cursor, Microsoft VS Code, and Google Antigravity . The flaw, uncovered by AISLE, exposes an\u2026","source":"Cyber Security News","date_rel":"7h ago","thumbnail":"https://cybersecuritynews.com/wp-content/uploads/2026/08/1-Click-RCE-Vulnerability-in-Code-Editors.webp","description":"A critical one-click remote code execution (RCE) vulnerability affects three of the world\u2019s most widely used code editors: Cursor, Microsoft VS Code, and Google Antigravity . The flaw, uncovered by AISLE, exposes an estimated 50 million software developers at risk of silent, total system compromise with nothing more than a single click on a malicious link. The vulnerability has since been patched across all three platforms, but its discovery highlights how quickly security flaws can propagate across AI-native developer tooling. 1-Click RCE Vulnerability in Code Editors The exploit hinged on a\u2026","related":[{"title":"AI Notetaker Lets Hackers Spy on Government, Corporate Video Calls","link":"https://www.darkreading.com/application-security/ai-notetaker-spy-government-corporate-video-calls","source":"Dark Reading","date_rel":"21h ago"},{"title":"Online backlash ends in Google rolling back Google Earth AI tool after a day","link":"https://www.malwarebytes.com/blog/news/2026/08/online-backlash-ends-in-google-rolling-back-google-earth-ai-tool-after-a-day","source":"Malwarebytes Labs","date_rel":"22h ago"},{"title":"Proofpoint Joins Google Unified Security Recommended Program to Help Organizations Defend Against Today\u2019s Most Sophisticated Threats","link":"https://www.proofpoint.com/us/newsroom/press-releases/proofpoint-joins-google-unified-security-recommended-program-help","source":"Proofpoint Threat Insight","date_rel":"23h ago"},{"title":"New Pass-ta-key attacks let malware hijack Google-synced passkeys","link":"https://www.bleepingcomputer.com/news/security/new-pass-ta-key-attacks-let-malware-hijack-google-synced-passkeys/","source":"Bleeping Computer","date_rel":"3 Aug"},{"title":"Google dev kit spurs first-ever agent-on-agent violence","link":"https://www.theregister.com/security/2026/08/03/google-dev-kit-spurs-first-ever-agent-on-agent-violence/5282496","source":"The Register Security","date_rel":"3 Aug"},{"title":"Google Password Manager Attacks Could Let Malware Hijack Passkey-Protected Accounts","link":"https://thehackernews.com/2026/08/google-password-manager-attacks-could.html","source":"The Hacker News","date_rel":"3 Aug"}]},{"title":"Microsoft Defender Stops QNET Ransomware Attack in 128 Seconds With Automatic Device Isolation","link":"https://cybersecuritynews.com/microsoft-defender-stops-qnet-ransomware-attack/","reason":"Microsoft","category":"News","sources":["404 Media","Bleeping Computer","Cyber Security News","Malwarebytes Labs","The Register Security"],"coverage":5,"cve_ids":[],"summary":"Ransomware can turn one careless click into a business-wide emergency. An incident at QNET shows how quickly that risk can grow when attackers use trusted Windows tools to launch a second stage of an intrusion. The\u2026","source":"Cyber Security News","date_rel":"2h ago","thumbnail":"https://cybersecuritynews.com/wp-content/uploads/2026/08/Microsoft-Defender-Stops-QNET-Ransomware-Attack-in-128-Seconds-With-Automatic-Device-Isolation.webp","description":"Ransomware can turn one careless click into a business-wide emergency. An incident at QNET shows how quickly that risk can grow when attackers use trusted Windows tools to launch a second stage of an intrusion. The attack began after a user opened a malicious file, likely delivered through email or a browser download. It launched mshta.exe, a legitimate Windows utility, which contacted attacker-controlled infrastructure to collect a remote payload and prepare persistent activity. Microsoft analysts noted that the operation used a living-off-the-land method, meaning it relied on a built-in\u2026","related":[{"title":"Phishing service spoofs RingCentral to steal Microsoft 365 accounts","link":"https://www.bleepingcomputer.com/news/security/phishing-service-spoofs-ringcentral-to-steal-microsoft-365-accounts/","source":"Bleeping Computer","date_rel":"12h ago"},{"title":"Hackers Can Weaponize Microsoft Copilot to Hijack CEO Accounts and Redirect Wire Transfers","link":"https://cybersecuritynews.com/hackers-weaponize-microsoft-copilot/","source":"Cyber Security News","date_rel":"17h ago"},{"title":"Microsoft Tells Engineers \u2018Tokenmaxxing Is Not What We Are Optimizing For\u2019","link":"https://www.404media.co/microsoft-tells-engineers-tokenmaxxing-is-not-what-we-are-optimizing-for/","source":"404 Media","date_rel":"18h ago"},{"title":"AI helps Microsoft bug hunters chase a record $20M payday","link":"https://www.theregister.com/security/2026/08/04/ai-helps-microsoft-bug-hunters-chase-a-record-20m-payday/5282821","source":"The Register Security","date_rel":"19h ago"},{"title":"Travelers targeted when logging into hotel Wi-Fi networks","link":"https://www.malwarebytes.com/blog/news/2026/08/travelers-targeted-when-logging-into-hotel-wi-fi-networks","source":"Malwarebytes Labs","date_rel":"22h ago"},{"title":"Hotel Wi-Fi attacks use custom malware to breach Microsoft 365 accounts","link":"https://www.bleepingcomputer.com/news/security/hotel-wi-fi-attacks-use-custom-malware-to-breach-microsoft-365-accounts/","source":"Bleeping Computer","date_rel":"4 Aug"}]},{"title":"CVE-2026-18577: N-able N-central Authentication Bypass Exploited in the Wild","link":"https://www.rapid7.com/blog/post/etr-cve-2026-18577-n-able-n-central-authentication-bypass-exploited-in-the-wild","reason":"CVE-2026-18577","category":"Research","sources":["Bleeping Computer","CISA Alerts & Advisories","Dark Reading","Rapid7 Blog","Sophos Threat Research","The Hacker News"],"coverage":6,"cve_ids":["CVE-2026-18577"],"summary":"Overview On August 2, 2026, N-able published a security advisory for CVE-2026-18577 , an authentication bypass vulnerability affecting N-central that was discovered being exploited in-the-wild after an incomplete fix\u2026","source":"Rapid7 Blog","date_rel":"23h ago","thumbnail":"https://images.contentstack.io/v3/assets/blte4f029e766e6b253/blt65a432ba319f4043/6846abddaf18306debe6cf4d/ETR.webp","description":"Overview On August 2, 2026, N-able published a security advisory for CVE-2026-18577 , an authentication bypass vulnerability affecting N-central that was discovered being exploited in-the-wild after an incomplete fix for an earlier authentication bypass issue, CVE-2026-18556 was disclosed. CVE-2026-18577 allows a remote unauthenticated attacker to bypass authentication and obtain administrative control of vulnerable N-central servers in affected deployments. N-able N-central is a widely deployed Remote Monitoring and Management (RMM) platform used by managed service providers (MSPs) and\u2026","related":[{"title":"N-able N-central exploitation results in RMM tool deployment","link":"https://www.sophos.com/en-us/blog/nable-ncentral-exploitation-results-in-rmm-tool-deployment","source":"Sophos Threat Research","date_rel":"4 Aug"},{"title":"Attackers Exploit N-able Patch Bypass Flaw on RMM Servers","link":"https://www.darkreading.com/vulnerabilities-threats/attackers-exploit-n-able-patch-bypass-flaw","source":"Dark Reading","date_rel":"3 Aug"},{"title":"N-able warns of N-central auth bypass flaw exploited in attacks","link":"https://www.bleepingcomputer.com/news/security/n-able-warns-of-n-central-auth-bypass-flaw-exploited-in-attacks/","source":"Bleeping Computer","date_rel":"3 Aug"},{"title":"CISA Adds One Known Exploited Vulnerability to Catalog","link":"https://www.cisa.gov/news-events/alerts/2026/08/03/cisa-adds-one-known-exploited-vulnerability-catalog","source":"CISA Alerts & Advisories","date_rel":"3 Aug"},{"title":"N-able Says Attackers Take Over N-central Servers After Initial Fix Proves Incomplete","link":"https://thehackernews.com/2026/08/n-able-says-attackers-take-over-n.html","source":"The Hacker News","date_rel":"3 Aug"}]},{"title":"7-Zip Mark-of-the-Web Bypass Lets Malicious Files Evade Windows SmartScreen","link":"https://cybersecuritynews.com/7-zip-mark-of-the-web-bypass/","reason":"Windows","category":"News","sources":["Bleeping Computer","Cyber Security News","Microsoft Security","The Hacker News"],"coverage":4,"cve_ids":["CVE-2026-50341"],"summary":"Windows can protect users before a suspicious download runs. But a newly documented 7-Zip behavior can remove an important warning layer and allow a malicious program to start without a Windows SmartScreen prompt. ZIP\u2026","source":"Cyber Security News","date_rel":"1h ago","thumbnail":"https://cybersecuritynews.com/wp-content/uploads/2026/08/7-Zip-Mark-of-the-Web-Bypass-Lets-Malicious-Files-Evade-Windows-SmartScreen.webp","description":"Windows can protect users before a suspicious download runs. But a newly documented 7-Zip behavior can remove an important warning layer and allow a malicious program to start without a Windows SmartScreen prompt. ZIP archives are common in phishing campaigns. The gap grows when an archive looks like an invoice, update, or shared document. An attacker sends a link or attachment that leads to an archive, persuades the recipient to extract it with 7-Zip, then relies on the unmarked file being launched. This is not a newly disclosed exploit in 7-Zip code, but a security-control gap caused by the\u2026","related":[{"title":"QuickFox Supply Chain Attack Delivers FDMTP Backdoor via Trojanized Windows Installer","link":"https://thehackernews.com/2026/08/quickfox-supply-chain-attack-delivers.html","source":"The Hacker News","date_rel":"4h ago"},{"title":"New DOUBLECUP ClickFix service hides malware in browser cache images","link":"https://www.bleepingcomputer.com/news/security/new-doublecup-clickfix-service-hides-malware-in-browser-cache-images/","source":"Bleeping Computer","date_rel":"3 Aug"},{"title":"CVE-2026-50341 Windows NTFS Information Disclosure Vulnerability","link":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50341","source":"Microsoft Security","date_rel":"3 Aug"}]},{"title":"Google Deletes 3 ADK AI Workflows After Malicious GitHub Issue Could Trigger Privileged Agent","link":"https://thehackernews.com/2026/08/google-deletes-3-adk-ai-workflows-after.html","reason":"Github","category":"News","sources":["Bleeping Computer","CyberScoop","SecurityWeek","The Hacker News"],"coverage":4,"cve_ids":[],"summary":"Google deleted three AI agent workflows from its Agent Development Kit (ADK) Python repository. Pillar Security showed that a public GitHub issue could manipulate a triage agent into triggering a privileged code-fixing\u2026","source":"The Hacker News","date_rel":"23h ago","thumbnail":"https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhLUUlqxE9AYL9PyFAlWMsG9czDcrU9p2kMUsumVIYx5SnlMAO0z-n_weUWeX-CiMHQBbkGK1lV-78vp003-bAeRP4gQRyGXlq5blzx5dJdd9zFttd2tjhGlNUFLNk-6ro9GfXMkRCFVLs-ex3gWHoJh-87sZifOeTKohLNoypvvqLUUPLkGUsjKXfAj7A/s1600/google.gif","description":"Google deleted three AI agent workflows from its Agent Development Kit (ADK) Python repository. Pillar Security showed that a public GitHub issue could manipulate a triage agent into triggering a privileged code-fixing agent. The researchers said the public agent could be prompt-injected into posting /adk-issue-fix as adk-bot. They identified the bot as a collaborator, so that comment satisfied","related":[{"title":"Over 400 NPM Packages Infected in ChainDrop Supply Chain Attack","link":"https://www.securityweek.com/over-400-npm-packages-infected-in-chaindrop-supply-chain-attack/","source":"SecurityWeek","date_rel":"1h ago"},{"title":"Massive supply-chain attack compromises 440 packages under four hours","link":"https://cyberscoop.com/supply-chain-attack-malware-mini-shai-hulud-teampcp/","source":"CyberScoop","date_rel":"12h ago"},{"title":"New XCSSET variant targets macOS devs via compromised Xcode projects","link":"https://www.bleepingcomputer.com/news/security/new-xcsset-variant-targets-macos-devs-via-compromised-xcode-projects/","source":"Bleeping Computer","date_rel":"15h ago"}]},{"title":"8 Best Password Managers (2026), Tested and Reviewed","link":"https://www.wired.com/story/best-password-managers/","reason":"Android","category":"Media","sources":["Bleeping Computer","Malwarebytes Labs","Wired Security"],"coverage":3,"cve_ids":[],"summary":"Keep your logins locked down with our favorite password management apps for PC, Mac, Android, iPhone, and web browsers.","source":"Wired Security","date_rel":"2 Aug","thumbnail":"https://media.wired.com/photos/690270685216e0070a31d8d0/master/pass/The%20Best%20Password%20Managers%20to%20Secure%20Your%20Digital%20Life.png","description":"","related":[{"title":"Junk Cleaner clears the clutter from your Android","link":"https://www.malwarebytes.com/blog/product/2026/08/junk-cleaner-clears-the-clutter-from-your-android","source":"Malwarebytes Labs","date_rel":"1h ago"},{"title":"Inside the Underground Business of the Android BTMOB RAT malware","link":"https://www.bleepingcomputer.com/news/security/inside-the-underground-business-of-btmob-rat/","source":"Bleeping Computer","date_rel":"3 Aug"}]},{"title":"Mallory Unifies Threat Intelligence, Exposure Context, and Response Into One Architecture for Security Teams","link":"https://cybersecuritynews.com/mallory-unifies-threat-intelligence-exposure-context-and-response-into-one-architecture-for-security-teams/","reason":"Teams","category":"News","sources":["Cyber Security News","Elastic Security Labs","The Hacker News","Wiz Research"],"coverage":4,"cve_ids":[],"summary":"Las Vegas, United States, August 4th, 2026, CyberNewswire As AI-assisted attackers compress exploitation timelines to hours, Mallory turns live adversary intelligence into prioritized, policy-governed action across the\u2026","source":"Cyber Security News","date_rel":"17h ago","thumbnail":"https://i3.wp.com/blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEilQYFaXQzJutaH7hl-0b-fZNl9Pj2QFfhn8y0WC8tl8petfT-OsvUOQBOGQqs-J5TihxgGHU0eLHls9Pq6UQHMGfCs10CqW7G_A93fDrInS8ydHhPGYfbK5Pts0WxUvLKUW6swCn2i9Z00hQZTZH7yiqEoz_K80W2Oy7GaElclO45TC0rgZhGEwFhjI1c/s1600/Insignary%20Launches%20Clarity%20On-Demand%20SBOMs,%20No%20Annual%20Commitment%20Required%20Toronto,%20Canada,%20July%2015th,%202026,%20CyberNewswire%20Enterprise-grade%20binary%20software%20verification%20for%20one%20project,%20one%20team,%20o%20(81).webp?ssl=1","description":"Las Vegas, United States, August 4th, 2026, CyberNewswire As AI-assisted attackers compress exploitation timelines to hours, Mallory turns live adversary intelligence into prioritized, policy-governed action across the tools security teams already run Mallory , the AI-native Threat and Exposure Management platform, today introduced a unified context and intelligence layer for security teams. The architecture has three parts: a context graph that correlates attack surface, threat, and vulnerability data; an intelligent reasoning layer that determines what matters and why; and a policy and\u2026","related":[{"title":"Wiz at Black Hat 2026: Driving AI Threat Readiness","link":"https://www.wiz.io/blog/wiz-at-black-hat-2026","source":"Wiz Research","date_rel":"21h ago"},{"title":"When Vibe Hacking Turns AI into the Junior Hacker Every Adversary Always Wanted","link":"https://thehackernews.com/2026/08/when-vibe-hacking-turns-ai-into-junior.html","source":"The Hacker News","date_rel":"22h ago"},{"title":"FOMO in the SOC: Where AI Platforms like Claude Actually Fit","link":"https://thehackernews.com/2026/08/fomo-in-soc-where-ai-platforms-like.html","source":"The Hacker News","date_rel":"3 Aug"},{"title":"SOC case management and detection rule history in Elastic Security","link":"https://www.elastic.co/security-labs/soc-case-management-detection-rule-history","source":"Elastic Security Labs","date_rel":"3 Aug"}]},{"title":"Apple launches new legal challenge against UK over iCloud access","link":"https://therecord.media/apple-uk-tcn-icloud-new-legal-challenge","reason":"Apple","category":"News","sources":["Malwarebytes Labs","The Hacker News","The Record"],"coverage":3,"cve_ids":[],"summary":"Seeking to protect users' iCloud accounts, Apple is reportedly mounting a new challenge to British legal demands for ways around the company's Advanced Data Protection feature.","source":"The Record","date_rel":"21h ago","thumbnail":"http://cms.therecord.media/uploads/apple_logo_pexels_tim_gouw_be4c718ff6.jpg","description":"","related":[{"title":"Apple battles it out again with the UK over encrypted iCloud access","link":"https://www.malwarebytes.com/blog/news/2026/08/apple-battles-it-out-again-with-uk-over-encrypted-icloud-access","source":"Malwarebytes Labs","date_rel":"13h ago"},{"title":"Chinese Threat Actor Uses Leaked DarkSword Kit to Deploy GHOSTBLADE on iOS","link":"https://thehackernews.com/2026/08/chinese-threat-actor-uses-leaked.html","source":"The Hacker News","date_rel":"3 Aug"}]},{"title":"CISA Flags Langflow RCE, Tomcat, and N-central Flaws as Actively Exploited","link":"https://thehackernews.com/2026/08/cisa-flags-langflow-rce-tomcat-and-n.html","reason":"Exploited Langflow Ncentral","category":"News","sources":["SecurityWeek","The Hacker News"],"coverage":2,"cve_ids":[],"summary":"The U.S. Cybersecurity and Infrastructure Security Agency (CISA), on August 5, 2026, added three flaws to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation in the wild. The list\u2026","source":"The Hacker News","date_rel":"2h ago","thumbnail":"https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjU9CZ3zh4mWF0SVRdcylBR7IyGB6j797LrHqyND8vcsBbiE6mcDlqaufSOBg2Av4Ej_HZ_gMxbzR-KS6GvXX0hLPgSFlh5gwxKwhjx3FvcdsQ7XP65x70cxeadgTM7uETFglAUoZrxwq9Rmx6i1T4yS-E7c7Szx9igRmM_GqG-8L5xfKYk2i3fhQGEHjez/s1600/cisa.jpg","description":"The U.S. Cybersecurity and Infrastructure Security Agency (CISA), on August 5, 2026, added three flaws to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation in the wild. The list of vulnerabilities is as follows - CVE-2026-9198 (CVSS score: 9.8) - A code injection vulnerability in Langflow that allows unauthenticated attackers to achieve full remote","related":[{"title":"CISA Warns of Exploited Langflow, N-central, and Tomcat Vulnerabilities","link":"https://www.securityweek.com/cisa-warns-of-exploited-langflow-n-central-and-tomcat-vulnerabilities/","source":"SecurityWeek","date_rel":"41m ago"}]},{"title":"Fake Adobe and Zoom Updates Install ScreenConnect for Persistent Remote Access","link":"https://thehackernews.com/2026/08/fake-adobe-and-zoom-updates-install.html","reason":"Adobe","category":"News","sources":["CCCS Alerts & Advisories","The Hacker News"],"coverage":2,"cve_ids":[],"summary":"Cybersecurity researchers have disclosed details of an active, multi-wave campaign that employs social engineering lures themed around Adobe and Zoom software updates, business document reviews, and system maintenance\u2026","source":"The Hacker News","date_rel":"21h ago","thumbnail":"https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEi35nnI5-o_HtA0Eunk4tOFM1lg12NrqY7HrDNBbee-kPWR-BHHxXQtd-Tj3b7FrMlTOcWNC63XgVV9n0FEoD-G4ydCpmBv2g1PjvS-lzopLbMnODHbNL2bGMJ6nOYXST9M83vc9IYZaUOjkUqaa4Xo-LaAOtXu3bRhYAcVIUwxgDNMifc6xWI27VVca_B4/s1600/screenconnect.jpg","description":"Cybersecurity researchers have disclosed details of an active, multi-wave campaign that employs social engineering lures themed around Adobe and Zoom software updates, business document reviews, and system maintenance utilities to stealthily deploy Remote Monitoring and Management (RMM) programs like ConnectWise ScreenConnect. The campaign has been codenamed SMOKE#SCREEN by Securonix Threat","related":[{"title":"Adobe security advisory (AV26-776)","link":"https://cyber.gc.ca/en/alerts-advisories/adobe-security-advisory-av26-776","source":"CCCS Alerts & Advisories","date_rel":"14h ago"}]}],"worth_reading":[],"kev_watch":[],"vuln_watch":[{"id":"CVE-2026-16618","vendor":"WordPress","product":"Improve SEO","severity":"CRITICAL","score":9.8,"description":"The Improve SEO WordPress plugin through 2.0.11 does not properly validate uploaded files, checking only the file content type while writing the file with the attacker-supplied extension into a publicly accessible directory, allowing unauth\u2026","cwe":"CWE-434","kev":false,"kev_action":"","kev_due":"","epss":0.002,"url":"https://cve.blackmesa.ca/?q=CVE-2026-16618"},{"id":"CVE-2026-14175","vendor":"HashiCorp","product":"HUMANIST Digital Human Resources","severity":"CRITICAL","score":9.8,"description":"Unrestricted upload of file with dangerous type vulnerability in Bilin Software and Informatics Consultancy Inc. HUMANIST Digital Human Resources allows Upload a Web Shell to a Web Server.\n\nThis issue affects HUMANIST Digital Human Resource\u2026","cwe":"CWE-434","kev":false,"kev_action":"","kev_due":"","epss":0.004,"url":"https://cve.blackmesa.ca/?q=CVE-2026-14175"},{"id":"CVE-2026-15721","vendor":"HashiCorp","product":"HUMANIST Digital Human Resources","severity":"CRITICAL","score":9.8,"description":"Cleartext storage of sensitive information vulnerability in Bilin Software and Informatics Consultancy Inc. HUMANIST Digital Human Resources allows SQL Injection.\n\nThis issue affects HUMANIST Digital Human Resources: from 26.0 before 26.1.","cwe":"CWE-312","kev":false,"kev_action":"","kev_due":"","epss":0.0023,"url":"https://cve.blackmesa.ca/?q=CVE-2026-15721"},{"id":"CVE-2026-61514","vendor":"Puwell Technology Inc.","product":"IP Camera","severity":"CRITICAL","score":9.8,"description":"Puwell IP Camera firmware versions 2.x through 4.x contains an authentication bypass vulnerability that allows unauthenticated attackers to access device functions by sending protocol-conforming packets over TCP port 23456 without credentia\u2026","cwe":"CWE-306","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-61514"},{"id":"CVE-2026-61515","vendor":"Puwell Technology Inc.","product":"IP Camera","severity":"CRITICAL","score":9.8,"description":"Puwell IP Camera firmware versions 2.x through 4.x contains an unauthenticated command injection vulnerability that allows remote attackers to execute arbitrary operating system commands by sending a crafted JSON payload to the DebugShell i\u2026","cwe":"CWE-912","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-61515"},{"id":"CVE-2026-69098","vendor":"Cinnamon","product":"kotaemon","severity":"CRITICAL","score":9.8,"description":"kotaemon through 0.12.0 contains an insecure deserialization vulnerability in the check_connection endpoint that allows unauthenticated attackers to instantiate arbitrary Python classes by supplying crafted YAML/JSON input with a __type__ f\u2026","cwe":"CWE-502","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-69098"},{"id":"CVE-2025-29296","vendor":"Unknown","product":"","severity":"CRITICAL","score":9.8,"description":"H3C Magic BE18000 V200R007, H3C NX400 V100R015, H3C Magic NX30 Pro V100R0011, H3C Magic R3010 V100R009, H3C Magic NX15 V100R017, H3C Magic R1510 V100R016, and H3C NE36 Pro V100R002 contain multiple command injection vulnerabilities in the /\u2026","cwe":"CWE-77","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2025-29296"},{"id":"CVE-2026-63455","vendor":"HP","product":"EdgeConnect SD-WAN Orchestrator","severity":"CRITICAL","score":9.8,"description":"Multiple vulnerabilities in the REST API interface of HPE Networking SD-WAN Orchestrator could allow an unauthenticated remote attacker to bypass web authentication mechanisms and access system functions. Successful exploitation could allow\u2026","cwe":"CWE-306","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-63455"},{"id":"CVE-2026-63456","vendor":"HP","product":"EdgeConnect SD-WAN Orchestrator","severity":"CRITICAL","score":9.8,"description":"Multiple vulnerabilities in the REST API interface of HPE Networking SD-WAN Orchestrator could allow an unauthenticated remote attacker to bypass web authentication mechanisms and access system functions. Successful exploitation could allow\u2026","cwe":"CWE-287","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-63456"},{"id":"CVE-2026-24254","vendor":"NVIDIA","product":"Dynamo","severity":"CRITICAL","score":9.8,"description":"NVIDIA Dynamo for Linux contains a vulnerability in the multimodal serving topology, where an attacker could cause an out-of-bounds write. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, da\u2026","cwe":"CWE-288","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-24254"}],"vendor_spikes":[{"vendor":"WordPress","count":32,"critical_count":3},{"vendor":"FlowiseAI","count":18,"critical_count":0},{"vendor":"Unknown","count":17,"critical_count":1},{"vendor":"NVIDIA","count":16,"critical_count":1},{"vendor":"HashiCorp","count":14,"critical_count":3},{"vendor":"open-webui","count":12,"critical_count":0},{"vendor":"Qualcomm","count":11,"critical_count":1},{"vendor":"Veeam","count":10,"critical_count":0},{"vendor":"H3C","count":8,"critical_count":0},{"vendor":"Apache","count":8,"critical_count":0}],"epss_risers":[],"developing_map":{},"trending_count":12,"new_cve_count":285,"has_news_data":true,"has_cve_data":true}