Skip to content
Signals
NVD · CVE-2026-70553 · 9.8 · MaxSite CMS contains a remote code execution vulnerability that allows unauthenticated attackers to inject arbitrary PHP code into the application configurationNVD · CVE-2026-70552 · 9.8 · MaxSite CMS 109.5 and earlier contains an authentication bypass vulnerability in the AJAX dispatcher that allows unauthenticated attackers to access admin-gatedNVD · CVE-2026-70486 · 8.2 · Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.9.0 until 0.11.0, the terminal file-preview serveUrl iframe branch NVD · CVE-2026-70485 · 7.1 · Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.9.0 until 0.11.0, Open WebUI checked whether a user-supplied URL deCISA KEV · CVE-2026-18556 · 7.4 · N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability · Added 2026-08-04 · Due 2026-08-07CISA KEV · CVE-2026-34486 · 7.5 · Apache Tomcat Missing Encryption of Sensitive Data Vulnerability · Added 2026-08-04 · Due 2026-08-07NVD · CVE-2026-70553 · 9.8 · MaxSite CMS contains a remote code execution vulnerability that allows unauthenticated attackers to inject arbitrary PHP code into the application configurationNVD · CVE-2026-70552 · 9.8 · MaxSite CMS 109.5 and earlier contains an authentication bypass vulnerability in the AJAX dispatcher that allows unauthenticated attackers to access admin-gatedNVD · CVE-2026-70486 · 8.2 · Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.9.0 until 0.11.0, the terminal file-preview serveUrl iframe branch NVD · CVE-2026-70485 · 7.1 · Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.9.0 until 0.11.0, Open WebUI checked whether a user-supplied URL deCISA KEV · CVE-2026-18556 · 7.4 · N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability · Added 2026-08-04 · Due 2026-08-07CISA KEV · CVE-2026-34486 · 7.5 · Apache Tomcat Missing Encryption of Sensitive Data Vulnerability · Added 2026-08-04 · Due 2026-08-07

Independent Intelligence Platform — Est. 2025

Signal Intelligence for AI, Tech, and Cybersecurity

Cut through the noise. Track what matters.

Signals
incransom — TRULITE GLASS & ALUMINUM SOLUTIONSchaos — healthcarehighways.commorpheus — SBCTANZANIAmorpheus — GGImorpheus — BAYTECH A/Smorpheus — 3I INFOTECHincransom — TRULITE GLASS & ALUMINUM SOLUTIONSchaos — healthcarehighways.commorpheus — SBCTANZANIAmorpheus — GGImorpheus — BAYTECH A/Smorpheus — 3I INFOTECH

Advertising

Reach security teams, developers and technology leaders through research-driven media placements.

Platform Intelligence

Explore

Actively Exploited

· KEV · EPSS · PoC
CVE-2026-18577KEVHIGH 8.1

An incomplete patch for CVE-2026-18556 allows for authentication bypass and account takeover in N-central Versions through 2026.3.1

CVE-2026-18556KEVHIGH 7.4

Authentication bypass using an alternate path or channel vulnerability in N-able N-central allows Authentication Bypass. This issue affects N-central: through 2026.1.

CVE-2026-20316KEVMEDIUM 5.3

A vulnerability in the web interface of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated, remote attacker to log in to an affected device using a low-privileged ac

CVE-2026-16812KEVCRITICAL 10.0

VeloCloud Orchestrator (VCO) on-prem has a security issue where this issue may allow a remote attacker to access privileged internal functionality and impact the VCO host. Successful exploitation may

CVE-2026-16232KEVCRITICAL 9.13 PoC

An authentication bypass vulnerability in the Check Point SmartConsole login process allows an unauthenticated remote attacker to obtain an application login token and use it to authenticate with full

CVE-2026-60137KEVMEDIUM 5.98 PoC

WordPress 6.8.x before 6.8.6, 6.9.x before 6.9.5, and 7.0.x before 7.0.2 does not properly sanitise the author__not_in parameter of WP_Query, which could allow SQL Injection when a plugin or theme pas

CVE-2026-9198KEVCRITICAL 9.8

IBM Langflow OSS 1.0.0 through 1.10.0 allows unauthenticated attackers to chain /api/v1/auto_login (mints SUPERUSER tokens to any network caller) with /api/v1/validate/code (executes user code via exe

CVE-2026-56291KEVCRITICAL 9.84 PoC

Joomla Extension - balbooa.com - Unauthenticated file upload in Balbooa Forms extension < 2.4.1 - The Joomla extension Balbooa Forms is vulnerable to an unauthenticated arbitrary file upload that allo

Briefings

· Latest

Research Library

· Guides

Latest CVEs

· NVD Live
CVE-2026-70553CRITICAL 9.8

MaxSite CMS contains a remote code execution vulnerability that allows unauthenticated attackers to inject arbitrary PHP code into the application configuration file by submitting crafted POST requests to the install endpoint after installation is complete. Attackers can supply a malicious db_dbprefix value containing a single quote to break out of a PHP string literal in application/config/database.php, appending attacker-controlled PHP statements that are executed by the web server on every subsequent request, resulting in persistent unauthenticated remote code execution as the web-server process user.

CVE-2026-70552CRITICAL 9.8

MaxSite CMS 109.5 and earlier contains an authentication bypass vulnerability in the AJAX dispatcher that allows unauthenticated attackers to access admin-gated endpoints by supplying any X-Requested-With header and requesting a base64-encoded path resolving to any *-ajax.php file in the codebase. Attackers can exploit this dispatcher bypass to reach privileged plugin endpoints without credentials, enabling actions such as manipulating poll states and vote counts, and amplifying the impact of any dangerous operation performed by admin-only ajax files across the plugin tree.

CVE-2026-70486HIGH 8.2

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.9.0 until 0.11.0, the terminal file-preview serveUrl iframe branch always granted allow-same-origin together with allow-scripts for HTML files served from the application origin. Any authenticated user with access to a configured terminal server could cause script in a previewed file to run in the Open WebUI origin, read the victim's session token from localStorage, and take over the account, with possible server-side code execution if the victim was an admin or held workspace.functions. This issue is fixed in 0.11.0.

CVE-2026-70485HIGH 7.1

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.9.0 until 0.11.0, Open WebUI checked whether a user-supplied URL destination was globally routable by applying ipaddress.is_global to the literal IPv6 address without examining IPv4 addresses embedded in transition encodings. On a deployment with a NAT64 gateway, any verified user could wrap an internal or cloud-metadata IPv4 address in the NAT64 well-known prefix, pass the filter, and receive the internal response body through RAG URL ingestion, URL-to-markdown conversion, or web-search content retrieval. This issue is fixed in 0.11.0.

CVE-2026-70484MEDIUM 4.3

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.7.0 until 0.11.0, the legacy chat-completions features block trusted a client-supplied image_generation flag and did not re-check the features.image_generation permission that the direct image routes and native function-calling path enforce. An authenticated user whose image-generation permission had been revoked could still consume the operator's configured image provider through chat completions, spending API credits and provider quota and writing generated files to operator storage, without exposing provider credentials or other users' data. This issue is fixed in 0.11.0.

CVE-2026-70483LOW 3.1

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.9.6 until 0.11.0, DELETE /api/v1/chats/{id} cancelled a chat's in-flight tasks before checking whether the caller could delete that chat. Any authenticated user who knew another user's chat id could abort that user's running model response, title generation, or tag generation, even though the delete was refused and no chat data was deleted, modified, or disclosed. This issue is fixed in 0.11.0.

Ransomware Activity

· Tracker Live

TRULITE GLASS & ALUMINUM SOLUTIONS

Aug 4

incransom · US

healthcarehighways.com

Aug 4

chaos

SBCTANZANIA

Aug 4

morpheus

GGI

Aug 4

morpheus

BAYTECH A/S

Aug 4

morpheus

3I INFOTECH

Aug 4

morpheus

AI Intelligence

· 45 models · 67 apps & agents

Threat Actors

· ATT&CK

Membership

Intelligence Without Compromise

Free

$0

  • Public briefings
  • CVE feed — limited
  • Weekly digest

Pro· Popular

$29/mo

  • All briefings
  • Alert watchlists
  • CVE notifications
  • Threat feed access

Pro+

$79/mo

  • Restricted intelligence
  • Dark web reports
  • Data exports
  • API access

Enterprise

Custom

  • Full API
  • Team workflows
  • Integrations
  • Dedicated support

7-day free trial on Pro plans · No credit card required

Advertising

Reach security teams, developers and technology leaders through research-driven media placements.

Daily Brief

Intelligence Digest

CVEs, threat signals and analysis delivered each morning. No spam, unsubscribe anytime.

Preference center·Sign in