{"date_iso":"2026-10-11","date_human":"Sunday, October 11, 2026","generated_utc":"2026-10-11 12:57 UTC","read_minutes":5,"patch_tuesday":false,"top_stories":[{"title":"Why Apple Says Your Mac Is at Risk From AI | Threat Wire","link":"https://www.youtube.com/watch?v=RehNZHrGDhI","reason":"Google","category":"Podcast","sources":["Bleeping Computer","Hak5","Infosecurity Magazine","Malwarebytes Labs","SecurityWeek","The Hacker News"],"coverage":6,"cve_ids":[],"summary":"Are AI agents becoming a cybersecurity threat? From fake AI-generated bug bounty submissions overwhelming Google's vulnerability rewards program to Apple's warning about AI agents accessing sensitive Mac data, this\u2026","source":"Hak5","date_rel":"9 Oct","thumbnail":"https://i3.ytimg.com/vi/RehNZHrGDhI/hqdefault.jpg","description":"Are AI agents becoming a cybersecurity threat? From fake AI-generated bug bounty submissions overwhelming Google's vulnerability rewards program to Apple's warning about AI agents accessing sensitive Mac data, this week's ThreatWire explores how artificial intelligence is changing cybersecurity \u2014 and creating new security risks. Google has temporarily paused its open-source vulnerability rewards program, curl has shut down its bug bounty program, and Debian has announced more than 1,000 kernel CVEs. Meanwhile, Apple is tightening macOS Full Disk Access controls as concerns grow over\u2026","related":[{"title":"Hackers abuse Google Ads, Bing redirects to push Claude ClickFix attacks","link":"https://www.bleepingcomputer.com/news/security/hackers-abuse-google-ads-bing-redirects-to-push-claude-clickfix-attacks/","source":"Bleeping Computer","date_rel":"9 Oct"},{"title":"Google Domains Impacted by Recent ccTLD Hijacks","link":"https://www.securityweek.com/google-domains-impacted-by-recent-cctld-domain-hijacks/","source":"SecurityWeek","date_rel":"9 Oct"},{"title":"Three Teams Demonstrate Remote Hacks of Fully Patched Google Pixel 10 at Pwn2Own","link":"https://thehackernews.com/2026/10/three-teams-demonstrate-remote-hacks-of.html","source":"The Hacker News","date_rel":"9 Oct"},{"title":"Google Pixel 10 Exploits Earned Hackers $560,000 at Pwn2Own","link":"https://www.securityweek.com/google-pixel-10-exploits-earned-hackers-560000-at-pwn2own/","source":"SecurityWeek","date_rel":"9 Oct"},{"title":"Attackers hijack country-code domains to impersonate Google and other services","link":"https://www.malwarebytes.com/blog/news/2026/10/attackers-hijack-country-code-domains-to-impersonate-google-and-other-services","source":"Malwarebytes Labs","date_rel":"8 Oct"},{"title":"Attackers Hijack Three ccTLDs to Obtain Google Certificates","link":"https://www.infosecurity-magazine.com/news/attackers-hijack-cctlds-obtain/","source":"Infosecurity Magazine","date_rel":"8 Oct"}]},{"title":"Microsoft Teams to Warn Users About Malicious Links Hidden in QR Codes","link":"https://cybersecuritynews.com/teams-qr-code-protection/","reason":"Microsoft","category":"News","sources":["Bleeping Computer","Cyber Security News","The Hacker News"],"coverage":3,"cve_ids":[],"summary":"Microsoft is extending Teams security to detect malicious links hidden inside QR codes and warn users after a message has been delivered. The update adds QR code checks to existing Microsoft Defender for Office 365\u2026","source":"Cyber Security News","date_rel":"10 Oct","thumbnail":"https://cybersecuritynews.com/wp-content/uploads/2026/10/Teams-QR-Code-Protection.webp","description":"Microsoft is extending Teams security to detect malicious links hidden inside QR codes and warn users after a message has been delivered. The update adds QR code checks to existing Microsoft Defender for Office 365 protections, giving users clearer warnings and security teams more data to investigate suspicious messages. According to Message Center notice MC1490905 , published on October 7, worldwide rollout begins in early October 2026 and is expected to finish by early November. The feature applies to organizations using Microsoft Teams with Defender for Office 365 and requires no separate\u2026","related":[{"title":"Attackers Exploit AhsayCBS Flaws to Deploy XMRig Miners Disguised as Microsoft Edge","link":"https://thehackernews.com/2026/10/attackers-exploit-ahsaycbs-flaws-to.html","source":"The Hacker News","date_rel":"9 Oct"},{"title":"Microsoft: Outdated Windows devices will stop receiving security updates","link":"https://www.bleepingcomputer.com/news/microsoft/microsoft-outdated-windows-devices-will-lose-security-protection-next-year/","source":"Bleeping Computer","date_rel":"9 Oct"}]},{"title":"Citrix Patches Critical NetScaler Flaw That Could Enable RCE in SAML Deployments","link":"https://thehackernews.com/2026/10/citrix-patches-critical-netscaler-flaw.html","reason":"Citrix","category":"News","sources":["Bleeping Computer","CCCS Alerts & Advisories","The Hacker News"],"coverage":3,"cve_ids":["CVE-2026-88771","CVE-2026-88772"],"summary":"Citrix has released patches for yet another critical security flaw impacting NetScaler ADC and NetScaler Gateway that could result in remote code execution or denial-of-service (DoS) under certain conditions\u2026","source":"The Hacker News","date_rel":"9 Oct","thumbnail":"https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEifRR7IQ4Ngqm8ANJ-DKwW60qeemJlrfrtvhaAwtpzW37_jAkbdctxJEqjw8k_m1KT32ryqoxa1dNYoEPG-E9xNwrbtXqbOjbzmgs3JM9RW68FZMNA8ky14QKTLpEfHop9A4xmXO46fxQaeXZMZzzMQ-qoIXLpMrr8Gbekn3cgNX5xc7bYvMRDYKjDeLf4o/s1600/cit.jpg","description":"Citrix has released patches for yet another critical security flaw impacting NetScaler ADC and NetScaler Gateway that could result in remote code execution or denial-of-service (DoS) under certain conditions. \"CVE-2026-107406 is a memory overflow vulnerability that may lead to remote code execution or denial-of-service under specific configuration conditions,\" Citrix said. The vulnerability","related":[{"title":"AL26-024 - Critical vulnerabilities affecting Citrix NetScaler ADC and NetScaler Gateway \u2013 CVE-2026-88771 and CVE-2026-88772 \u2013 Update 2","link":"https://cyber.gc.ca/en/alerts-advisories/al26-024-critical-vulnerabilities-affecting-citrix-netscaler-adc-netscaler-gateway-cve-2026-88771-cve-2026-88772","source":"CCCS Alerts & Advisories","date_rel":"9 Oct"},{"title":"Citrix security advisory (AV26-1023)","link":"https://cyber.gc.ca/en/alerts-advisories/citrix-security-advisory-av26-1023","source":"CCCS Alerts & Advisories","date_rel":"9 Oct"},{"title":"Citrix warns admins to patch new NetScaler RCE flaw immediately","link":"https://www.bleepingcomputer.com/news/security/citrix-warns-admins-to-patch-new-netscaler-rce-flaw-immediately/","source":"Bleeping Computer","date_rel":"9 Oct"}]},{"title":"One Prompt Could Hijack AWS AI Agents and Steal Cloud Credentials","link":"https://cybersecuritynews.com/agentcorruption-attack/","reason":"Amazon","category":"News","sources":["Cyber Security News","The Register Security"],"coverage":2,"cve_ids":[],"summary":"A single prompt sent to a public-facing AI agent could have exposed every Amazon Bedrock AgentCore agent in the same AWS account and region, according to new research from Zenity Labs. The attack chain, named\u2026","source":"Cyber Security News","date_rel":"10 Oct","thumbnail":"https://cybersecuritynews.com/wp-content/uploads/2026/10/AWS-AgentCorruption1.webp","description":"A single prompt sent to a public-facing AI agent could have exposed every Amazon Bedrock AgentCore agent in the same AWS account and region, according to new research from Zenity Labs. The attack chain, named AgentCorruption, gave the researchers access to private chats, source code, long-term memories, API keys, OAuth tokens, and secrets held in AWS Secrets Manager. Amazon Bedrock AgentCore is a managed service for building and running AI agents. Zenity found that an agent with a tool able to make web requests could be told to contact the local metadata endpoint at 169.254.169.254 . This\u2026","related":[{"title":"AWS AgentCore security undone by prompt requesting credentials","link":"https://www.theregister.com/security/2026/10/09/aws-agentcore-security-undone-by-prompt-requesting-credentials/5302436","source":"The Register Security","date_rel":"9 Oct"}]},{"title":"CastleStealer Malware Uses Browser Protection Bypass and Remote Shell to Expand Attacker Access","link":"https://cybersecuritynews.com/castlestealer-malware/","reason":"Windows","category":"News","sources":["Cyber Security News","Microsoft Security"],"coverage":2,"cve_ids":["CVE-2026-62744","CVE-2026-68875","CVE-2026-68878"],"summary":"CastleStealer, an emerging C#-based information stealer, has added browser protection bypass and remote shell features that give its operators a wider path into compromised Windows systems. The newer malware samples can\u2026","source":"Cyber Security News","date_rel":"9 Oct","thumbnail":"https://cybersecuritynews.com/wp-content/uploads/2026/10/CastleStealer-Malware-Uses-Browser-Protection-Bypass-and-Remote-Shell-to-Expand-Attacker-Access.webp","description":"CastleStealer, an emerging C#-based information stealer, has added browser protection bypass and remote shell features that give its operators a wider path into compromised Windows systems. The newer malware samples can collect browser data protected by Chromium\u2019s App-Bound Encryption, run commands on a victim device, download extra payloads, and move stolen information through small encrypted network transmissions rather than one large archive. Flashpoint\u2019s analysis shows that the malware is becoming more capable even though it has not yet reached the broad use seen with major established\u2026","related":[{"title":"CVE-2026-62744 Microsoft Windows Media Foundation Remote Code Execution Vulnerability","link":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62744","source":"Microsoft Security","date_rel":"9 Oct"},{"title":"CVE-2026-68875 Windows NTFS Remote Code Execution Vulnerability","link":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-68875","source":"Microsoft Security","date_rel":"9 Oct"},{"title":"CVE-2026-68878 Windows Fast FAT Driver Elevation of Privilege Vulnerability","link":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-68878","source":"Microsoft Security","date_rel":"9 Oct"}]},{"title":"$10 million bounty offered for Chinese Hafnium hacker accused of Microsoft Exchange Server mega-attack","link":"https://www.bitdefender.com/en-us/blog/hotforsecurity/10-million-bounty-chinese-hafnium-hacker-microsoft-exchange-server-mega-attack","reason":"Exchange","category":"News","sources":["Graham Cluley","Microsoft Security"],"coverage":2,"cve_ids":["CVE-2026-50696"],"summary":"The US State Department is offering up to US $10 million for information about the whereabouts of Zhang Yu, a 44-year-old Chinese national who is accused of being a key figure in China's state-sponsored hacking group\u2026","source":"Graham Cluley","date_rel":"9 Oct","thumbnail":"","description":"","related":[{"title":"CVE-2026-50696 Internet Key Exchange (IKE) Protocol Denial of Service Vulnerability","link":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50696","source":"Microsoft Security","date_rel":"9 Oct"}]},{"title":"Credential-Stealing GitHub Actions Workflows Planted in Tens of Thousands of Repositories","link":"https://thehackernews.com/2026/10/credential-stealing-github-actions.html","reason":"Github","category":"News","sources":["Cyber Security News","The Hacker News"],"coverage":2,"cve_ids":[],"summary":"Cybersecurity researchers have disclosed details of an ongoing credential-theft campaign that has compromised two high-profile open-source maintainer accounts to push a malicious workflow into over 340 repositories\u2026","source":"The Hacker News","date_rel":"9 Oct","thumbnail":"https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjoJXBEAVVijhwsYs32WSejvp0sG3ej-Qoi7Z6qHDp8rY5IZENkKOpexrbbU1BNyiCbbB0ZXHjEDL-UYqu7CDpPpoYLiGXkuLCZJTItgP5XeLD_Sb1galPzOGtrFZigEM5CGUbwi9gcL_-XCYY6NKu9j5FiakIWn5s66DZE-OjrLZO3sMGka3YNFvGUecJT/s1600/gitworm.jpg","description":"Cybersecurity researchers have disclosed details of an ongoing credential-theft campaign that has compromised two high-profile open-source maintainer accounts to push a malicious workflow into over 340 repositories. \"Using the account of Takashi Kitao, author of the 18,400-star game engine pyxel, the attacker pushed a malicious workflow to 27 repositories starting at 13:20 UTC,\" StepSecurity","related":[{"title":"New GhostAction Attack Compromises Hundreds of GitHub Repos to Steal Secrets","link":"https://cybersecuritynews.com/ghostaction-github-repo-attack/","source":"Cyber Security News","date_rel":"9 Oct"}]},{"title":"AnyDesk Linux Flaw Lets Remote Attackers Execute Code as Root Without Authentication","link":"https://cybersecuritynews.com/anydesk-linux-vulnerability/","reason":"Linux","category":"News","sources":["Cyber Security News","The Hacker News"],"coverage":2,"cve_ids":[],"summary":"A working proof-of-concept for a serious AnyDesk Linux vulnerability that can let remote attackers run commands as root without authentication or user approval. The issue, named AnyPwn, affects AnyDesk Linux 8.0.2 and\u2026","source":"Cyber Security News","date_rel":"9 Oct","thumbnail":"https://cybersecuritynews.com/wp-content/uploads/2026/10/AnyDesk-Linux-Flaw.webp","description":"A working proof-of-concept for a serious AnyDesk Linux vulnerability that can let remote attackers run commands as root without authentication or user approval. The issue, named AnyPwn, affects AnyDesk Linux 8.0.2 and was fixed in version 8.0.3. Organizations using AnyDesk for Linux should update immediately and check whether TCP port 7070 is exposed to untrusted networks. The flaw was discovered by Rick de Jager of the V12 security team using V12, an AI-powered security review platform. V12 first disclosed the issue publicly in June and described it as a pre-authentication, zero-click remote\u2026","related":[{"title":"Researchers Publish Working Exploit for Pre-Auth AnyDesk Linux Flaw That Gives Root Access","link":"https://thehackernews.com/2026/10/researchers-publish-working-exploit-for.html","source":"The Hacker News","date_rel":"9 Oct"}]},{"title":"Threat Actors Exploit Critical AhsayCBS Flaws to Drop Webshells and XMRig Cryptominer","link":"https://www.huntress.com/blog/ahsaycbs-flaws-exploit","reason":"CVE-2026-105133","category":"Threat Intel","sources":["Huntress","SecurityWeek"],"coverage":2,"cve_ids":["CVE-2026-105133","CVE-2026-105134"],"summary":"Threat actors are exploiting AhsayCBS flaws, including CVE-2026-105133 and CVE-2026-105134, to deploy webshells and XMRig cryptominers. Update to 10.3.4 and restrict access now.","source":"Huntress","date_rel":"8 Oct","thumbnail":"https://cdn.builder.io/api/v1/image/assets%2F3eb6f92aedf74f109c7b4b0897ec39a8%2F266936e4b61b4dd6821599adf741b9db","description":"","related":[{"title":"Unpatched AhsayCBS Vulnerabilities Exploited in the Wild","link":"https://www.securityweek.com/unpatched-ahsaycbs-vulnerabilities-exploited-in-the-wild/","source":"SecurityWeek","date_rel":"9 Oct"}]},{"title":"Citrix gives NetScaler admins another critical reason to patch","link":"https://www.theregister.com/security/2026/10/09/citrix-gives-netscaler-admins-another-critical-reason-to-patch/5302212","reason":"CVE-2026-107406","category":"News","sources":["SecurityWeek","The Register Security"],"coverage":2,"cve_ids":["CVE-2026-107406"],"summary":"Citrix is urging customers to patch another critical NetScaler vulnerability after weeks of disclosures involving actively exploited flaws. CVE-2026-107406 affects NetScaler ADC and NetScaler Gateway and can lead to\u2026","source":"The Register Security","date_rel":"9 Oct","thumbnail":"https://image.theregister.com/?imageId=5302230&width=800","description":"Citrix is urging customers to patch another critical NetScaler vulnerability after weeks of disclosures involving actively exploited flaws. CVE-2026-107406 affects NetScaler ADC and NetScaler Gateway and can lead to remote code execution (RCE) or denial of service (DoS). It carries a CVSS v4.0 score of 9.5. The affected configurations depend on the software version. Older builds are vulnerable when configured as a SAML (Security Assertion Markup Language) service provider (SP) or identity provider (IdP); some more recent builds are affected only in the identity provider configuration\u2026","related":[{"title":"Citrix Urges Immediate Patching of Critical NetScaler Vulnerability","link":"https://www.securityweek.com/citrix-urges-immediate-patching-of-critical-netscaler-vulnerability/","source":"SecurityWeek","date_rel":"9 Oct"}]}],"worth_reading":[],"kev_watch":[],"vuln_watch":[{"id":"CVE-2026-42696","vendor":"Royal Plugins","product":"SiteVault \u2013 Backup, Restore, Migration & Cloning","severity":"CRITICAL","score":10.0,"description":"Unauthenticated Remote Code Execution (RCE) in SiteVault \u2013 Backup, Restore, Migration &amp; Cloning <= 1.5.19 versions.","cwe":"CWE-94","kev":false,"kev_action":"","kev_due":"","kev_added":"","epss":null,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H","fix":false,"fix_url":"","refs":["https://patchstack.com/database/wordpress/plugin/sitevault-backup-restore-migration/vulnerability/wordpress-sitevault-backup-restore-migration-cloning-plugin-1-5-18-remote-code-execution-rce-vulnerability?_s_id=cve"],"url":"https://cve.blackmesa.ca/?q=CVE-2026-42696"},{"id":"CVE-2026-62024","vendor":"CodeBard","product":"CodeBard Help Desk","severity":"CRITICAL","score":9.9,"description":"Subscriber Arbitrary File Upload in CodeBard Help Desk <= 1.1.2 versions.","cwe":"CWE-434","kev":false,"kev_action":"","kev_due":"","kev_added":"","epss":null,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H","fix":false,"fix_url":"","refs":["https://patchstack.com/database/wordpress/plugin/codebard-help-desk/vulnerability/wordpress-codebard-help-desk-plugin-1-1-2-arbitrary-file-upload-vulnerability?_s_id=cve"],"url":"https://cve.blackmesa.ca/?q=CVE-2026-62024"},{"id":"CVE-2026-62129","vendor":"WPFunnels","product":"Creator LMS","severity":"CRITICAL","score":9.9,"description":"Contributor Arbitrary File Upload in Creator LMS <= 1.2.21 versions.","cwe":"CWE-434","kev":false,"kev_action":"","kev_due":"","kev_added":"","epss":null,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H","fix":false,"fix_url":"","refs":["https://patchstack.com/database/wordpress/plugin/creatorlms/vulnerability/wordpress-creator-lms-plugin-1-2-21-arbitrary-file-upload-vulnerability?_s_id=cve"],"url":"https://cve.blackmesa.ca/?q=CVE-2026-62129"},{"id":"CVE-2026-108540","vendor":"OpenSpug","product":"Spug","severity":"CRITICAL","score":9.9,"description":"A flaw has been found in OpenSpug Spug up to 3.4.0/4.0.1. This impacts an unknown function of the file /exec/transfer of the component File Transfer. Executing a manipulation can lead to os command injection. The attack may be launched remo\u2026","cwe":"CWE-77","kev":false,"kev_action":"","kev_due":"","kev_added":"","epss":null,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H","fix":false,"fix_url":"","refs":["https://github.com/SECWG/CVE/issues/10","https://vuldb.com/cve/CVE-2026-108540","https://vuldb.com/submit/948328"],"url":"https://cve.blackmesa.ca/?q=CVE-2026-108540"},{"id":"CVE-2026-104803","vendor":"WordPress","product":"WPCOM Member","severity":"CRITICAL","score":9.8,"description":"The WPCOM Member plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 1.7.27 via the `uuid` and `code` parameters of the social-login callback handler registered on the `init` hook. The vulnerabi\u2026","cwe":"CWE-287","kev":false,"kev_action":"","kev_due":"","kev_added":"","epss":0.0045,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","fix":false,"fix_url":"","refs":["https://plugins.trac.wordpress.org/browser/wpcom-member/tags/1.7.27/includes/class-sesstion.php#L13","https://plugins.trac.wordpress.org/browser/wpcom-member/tags/1.7.27/includes/social-login.php#L1235","https://plugins.trac.wordpress.org/browser/wpcom-member/tags/1.7.27/includes/social-login.php#L674"],"url":"https://cve.blackmesa.ca/?q=CVE-2026-104803"},{"id":"CVE-2026-62045","vendor":"ThemeREX Group","product":"Booklovers","severity":"CRITICAL","score":9.8,"description":"Deserialization of Untrusted Data vulnerability in ThemeREX Group Booklovers booklovers allows Object Injection.This issue affects Booklovers: from n/a through 2.13.0.","cwe":"CWE-502","kev":false,"kev_action":"","kev_due":"","kev_added":"","epss":0.0032,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","fix":false,"fix_url":"","refs":["https://patchstack.com/database/wordpress/theme/booklovers/vulnerability/wordpress-booklovers-theme-2-13-0-php-object-injection-vulnerability?_s_id=cve"],"url":"https://cve.blackmesa.ca/?q=CVE-2026-62045"},{"id":"CVE-2026-62046","vendor":"ThemeREX Group","product":"Gutentype","severity":"CRITICAL","score":9.8,"description":"Deserialization of Untrusted Data vulnerability in ThemeREX Group Gutentype gutentype allows Object Injection.This issue affects Gutentype: from n/a through 2.1.12.","cwe":"CWE-502","kev":false,"kev_action":"","kev_due":"","kev_added":"","epss":0.0032,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","fix":false,"fix_url":"","refs":["https://patchstack.com/database/wordpress/theme/gutentype/vulnerability/wordpress-gutentype-theme-2-1-12-php-object-injection-vulnerability?_s_id=cve"],"url":"https://cve.blackmesa.ca/?q=CVE-2026-62046"},{"id":"CVE-2026-93927","vendor":"Axiomthemes","product":"Veto","severity":"CRITICAL","score":9.8,"description":"Deserialization of Untrusted Data vulnerability in Axiomthemes Veto veto allows Object Injection.This issue affects Veto: from n/a through 1.6.0.","cwe":"CWE-502","kev":false,"kev_action":"","kev_due":"","kev_added":"","epss":0.0032,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","fix":false,"fix_url":"","refs":["https://patchstack.com/database/wordpress/theme/veto/vulnerability/wordpress-veto-theme-1-6-0-php-object-injection-vulnerability?_s_id=cve"],"url":"https://cve.blackmesa.ca/?q=CVE-2026-93927"},{"id":"CVE-2026-93929","vendor":"ThemeREX Group","product":"Travesia","severity":"CRITICAL","score":9.8,"description":"Deserialization of Untrusted Data vulnerability in ThemeREX Group Travesia travesia allows Object Injection.This issue affects Travesia: from n/a through 1.1.16.","cwe":"CWE-502","kev":false,"kev_action":"","kev_due":"","kev_added":"","epss":0.0032,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","fix":false,"fix_url":"","refs":["https://patchstack.com/database/wordpress/theme/travesia/vulnerability/wordpress-travesia-theme-1-1-16-php-object-injection-vulnerability?_s_id=cve"],"url":"https://cve.blackmesa.ca/?q=CVE-2026-93929"},{"id":"CVE-2026-93930","vendor":"ThemeREX Group","product":"Tantra","severity":"CRITICAL","score":9.8,"description":"Deserialization of Untrusted Data vulnerability in ThemeREX Group Tantra tantra allows Object Injection.This issue affects Tantra: from n/a through 2.9.0.","cwe":"CWE-502","kev":false,"kev_action":"","kev_due":"","kev_added":"","epss":0.0031,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","fix":false,"fix_url":"","refs":["https://patchstack.com/database/wordpress/theme/tantra/vulnerability/wordpress-tantra-theme-2-9-0-php-object-injection-vulnerability?_s_id=cve"],"url":"https://cve.blackmesa.ca/?q=CVE-2026-93930"}],"vendor_spikes":[{"vendor":"WordPress","count":101,"critical_count":7},{"vendor":"jeecgboot","count":70,"critical_count":0},{"vendor":"ThemeREX Group","count":18,"critical_count":17},{"vendor":"ThemeREX","count":17,"critical_count":16},{"vendor":"Microsoft","count":12,"critical_count":1},{"vendor":"kutethemes","count":12,"critical_count":0},{"vendor":"Unknown","count":6,"critical_count":0},{"vendor":"1Panel-dev","count":6,"critical_count":0},{"vendor":"bPlugins","count":5,"critical_count":0},{"vendor":"AncoraThemes","count":5,"critical_count":4}],"epss_risers":[],"developing_map":{},"trending_count":10,"new_cve_count":397,"has_news_data":true,"has_cve_data":true,"news_for_cve":{"CVE-2026-88771":{"anchor":"#dev-3","rank":3,"coverage":3},"CVE-2026-88772":{"anchor":"#dev-3","rank":3,"coverage":3},"CVE-2026-62744":{"anchor":"#dev-5","rank":5,"coverage":2},"CVE-2026-68875":{"anchor":"#dev-5","rank":5,"coverage":2},"CVE-2026-68878":{"anchor":"#dev-5","rank":5,"coverage":2},"CVE-2026-50696":{"anchor":"#dev-6","rank":6,"coverage":2},"CVE-2026-105133":{"anchor":"#dev-9","rank":9,"coverage":2},"CVE-2026-105134":{"anchor":"#dev-9","rank":9,"coverage":2},"CVE-2026-107406":{"anchor":"#dev-10","rank":10,"coverage":2}}}