Other Conventional Threats

Other conventional threat types

Showing 341–360 of 390 threats, newest first

CMSexploitationweb-shellplugin-vulnerabilityACSCvulnerability-managementpatch-now

The Australian Cyber Security Centre has warned of an ongoing global campaign in which threat actors are exploiting vulnerabilities in content management systems (CMS) and their plugins to gain unauthorized access to web servers. The campaign appears opportunistic, scanning for and exploiting unpatched or misconfigured CMS installations at scale. Organizations running public-facing CMS platforms are urged to patch immediately and audit for signs of compromise.

Updated Jul 12, 2026

ICSSiemensMendixcode-injectionbuild-pipelinelow-codelocal-attackCWE-94

Siemens Mendix Studio Pro contains a code injection vulnerability (CVE-2026-48192) in its build pipeline file parsing logic, allowing arbitrary code execution when a user opens a specially crafted malicious project. Exploitation requires user interaction and local access, limiting the attack surface but posing risk to developers and organizations using Mendix for low-code application development.

Updated Jul 12, 2026 · CVSS 5.4

ICSOTEV-chargingOCPPcritical-infrastructureauthentication-bypassdenial-of-servicetransportation-sector

Hydro-Québec's Le Circuit Electrique EV charging station backend contains three vulnerabilities—an unauthenticated websocket endpoint, lack of authentication attempt throttling, and insufficient session/connection controls—that could allow privilege escalation or denial-of-service attacks. The most severe flaw (CVSS 9.8) permits unauthenticated connections to the charging station's OCPP websocket, enabling attackers to potentially impersonate charging stations or escalate privileges. Hydro-Québec has mitigated most affected stations by disabling OCPP or adding authentication.

Updated Jul 12, 2026 · CVSS 9.8

wordpressplugin-vulnerabilityauthentication-bypassaccount-takeoveroauthotp-brute-forceadmin-takeovercms-security

The miniOrange Social Login and Register plugin for WordPress (versions up to 7.7.0) contains a critical authentication bypass allowing unauthenticated attackers to take over any account, including administrators. The flaw stems from unvalidated email input during OAuth profile completion combined with a weak, offline-crackable OTP scheme, enabling full site compromise. Given the 9.8 CVSS score and low attack complexity, mass exploitation against internet-facing WordPress sites is likely once a working exploit circulates.

Updated Jul 12, 2026 · CVSS 9.8

data-breachtelecomlaw-enforcementinvestigationnetherlands

Dutch police report strong indications that Dutch hackers were behind a February breach at telecommunications provider Odido. Details on the attack vector, data exfiltrated, and threat actor identity remain limited at this stage of the investigation.

Updated Jul 11, 2026

CISAKEVfile-uploadweb-applicationCMSpluginJoomlaactive-exploitationBOD-26-04

CISA has added two actively exploited vulnerabilities to its Known Exploited Vulnerabilities catalog: an unrestricted file upload flaw in iCagenda (CVE-2026-48939) and a similar flaw in Balbooa Forms (CVE-2026-56291). Both vulnerabilities allow attackers to upload dangerous file types, potentially leading to remote code execution on affected web servers.

Updated Jul 11, 2026

moveitfile-transferinjectiondata-exposuremanaged-file-transfer

A vulnerability in Progress MOVEit Transfer's Custom Reports module allows improper neutralization of special elements in data query logic, potentially enabling unauthorized data access or manipulation. This affects versions before 2025.0.7 and 2025.1.0 through 2025.1.3, and is reminiscent of prior MOVEit vulnerabilities that were exploited at scale for mass data theft.

Updated Jul 11, 2026 · CVSS 6.4

default-credentialsapi-securityunauthorized-accessagent-relevant

IBM API Connect versions 12.1.0.0 through 12.1.0.3 ship with default credentials that remain active until an administrator manually enforces a password change. Attackers aware of these default credentials can gain unauthorized access to the API management platform before remediation occurs, potentially compromising API gateways, backend integrations, and associated secrets.

Updated Jul 11, 2026 · CVSS 8.1

cvecisa-kevfile-uploadrceweb-applicationwordpress-pluginunauthenticated

iCagenda, a WordPress event management plugin, contains an unrestricted file upload vulnerability in its file attachment feature that allows attackers to upload malicious PHP files. This can lead to full remote code execution on the underlying web server. The vulnerability is listed in CISA's Known Exploited Vulnerabilities catalog, indicating active exploitation in the wild.

Updated Jul 11, 2026

githubreconnaissanceoauth-abuseaccount-compromisesupply-chain-reconapi-abuseagent-relevant

Datadog Security Labs identified multiple overlapping campaigns systematically enumerating corporate GitHub organizations, repositories, and user accounts via the GitHub API. Operators use dormant 'ghost' accounts and compromised OAuth tokens or personal access tokens to blend in with legitimate traffic while conducting reconnaissance, likely as a precursor to supply-chain or targeted intrusion operations.

Updated Jul 10, 2026

ICSSCADAhard-coded-credentialsSNMPcritical-infrastructureenergy-sectorprotection-relayunauthenticated-access

Schneider Electric's Easergy MiCOM Px40 Series protection relays contain hard-coded credentials (CWE-798) exposed via the SNMP protocol, allowing an unauthenticated remote attacker to access basic device identification information. The vulnerability affects a wide range of firmware versions across nearly all Px40 relay models used in medium, high, and extra high voltage protection applications worldwide.

Updated Jul 10, 2026 · CVSS 5.3

ICSSCADAschneider-electricpath-traversalcrlf-injectionlog-injectionauthentication-bypassdenial-of-serviceindustrial-control-systemsCISA-advisory

Schneider Electric PowerChute Serial Shutdown versions 1.4 and earlier contain seven distinct vulnerabilities spanning path traversal, CRLF injection, weak authentication throttling, uncontrolled resource consumption, and sensitive information logging. Successful exploitation could allow attackers to overwrite critical files, forge log data, exhaust system resources, or expose sensitive information, though no public exploitation has been reported. Schneider Electric has released version 1.5 to remediate all identified issues.

Updated Jul 10, 2026 · CVSS 6.1

moveitpath-traversalfile-uploadvulnerabilityprogress-software

A path equivalence vulnerability has been identified in Progress MOVEit Transfer's File Upload modules, affecting versions before 2025.0.8 and 2025.1.0 before 2025.1.4. The flaw carries a low CVSS score of 3.5, indicating limited exploitability or impact compared to prior MOVEit vulnerabilities, but it warrants patching given the product's history as a target for mass exploitation.

Updated Jul 10, 2026 · CVSS 3.5

account-takeoverauthentication-bypasspassword-recoveryesriarcgisgisweb-application

CVE-2026-13020 is a weak password recovery mechanism vulnerability in Esri Portal for ArcGIS (versions 12.1 and earlier) that allows a remote, unauthenticated attacker to hijack a user's account by manipulating the forgotten-password flow. Organizations running ArcGIS Enterprise on Windows, Linux, or Kubernetes are at risk of unauthorized account access without prior credentials.

Updated Jul 10, 2026 · CVSS 8.1

zero-day-brokerexploit-marketfraudvendor-risksupply-chaintrust-and-safetydisinformation

Krebs on Security reports that a startup soliciting zero-day vulnerabilities in popular software for large payouts is operated by individuals with histories of fraud, fake intelligence companies, and a defunct AI-based lobbying platform run under assumed identities. This raises significant vendor-trust and supply-chain risk concerns for any organization considering selling vulnerabilities to, or purchasing exploit intelligence from, this entity. There is no confirmed active exploitation tied to this report, but the operators' background suggests elevated risk of exploit misuse, data misrepresentation, or fraudulent business practices.

Updated Jul 9, 2026

data-breachextortionhigher-educationfile-storagecredential-theft

Mount Royal University in Calgary confirmed that attackers breached its network and exfiltrated data from file storage systems before deleting it, with threat actors publicly claiming responsibility for the attack. The incident reflects an ongoing trend of threat actors targeting higher-education institutions for data theft and extortion rather than traditional ransomware encryption.

Updated Jul 9, 2026

icsotauthentication-bypassxssend-of-lifecisa-advisory

CISA disclosed two vulnerabilities in Digi International's PortServer TS and Digi One SP/SP IA/IA serial-to-network devices: an authentication bypass allowing unauthenticated access to restricted web resources, and a stored XSS flaw exploitable by authenticated administrators. These are legacy, end-of-life industrial devices used across critical manufacturing, communications, IT, and transportation sectors, with no vendor firmware fix planned for the XSS issue.

Updated Jul 9, 2026 · CVSS 8.2

ICSOTenergy-sectorinsecure-transmissioncredential-theftsession-hijackingHitachi-EnergyPROMOD-V

Hitachi Energy PROMOD V versions 1.0.10 and prior rely on insecure HTTP communication instead of HTTPS due to a lack of TLS support in the third-party Digipede grid server component. This flaw could allow an attacker with network access to intercept or manipulate data in transit, potentially leading to credential theft, session hijacking, or unauthorized access to industrial engineering workstations.

Updated Jul 9, 2026 · CVSS 7.1

xssspoofingdynamics-365customer-voicemicrosoftweb-vulnerabilityinput-validation

CVE-2026-47646 is a cross-site scripting (XSS) vulnerability in Microsoft Dynamics 365 Customer Voice that allows an unauthorized, unauthenticated attacker to inject malicious scripts and perform spoofing attacks over a network. With a CVSS score of 9.3, this flaw could enable attackers to impersonate legitimate users or interfaces, potentially harvesting credentials or session data submitted through survey forms.

Updated Jul 9, 2026 · CVSS 9.3

wordpressplugin-vulnerabilityfile-uploadrceunauthenticatedcms-security

The Blocksy Companion Pro WordPress plugin (versions before 2.1.47) contains a critical unauthenticated arbitrary file upload vulnerability in its Advanced Reviews and Custom Fonts feature, allowing attackers to achieve remote code execution without any authentication. Exploitation involves bypassing a weak extension validation check using double-extension filenames, enabling attackers to upload and execute malicious PHP web shells. Given the CVSS score of 9.8 and ease of exploitation, this vulnerability poses severe risk to any WordPress site running the affected plugin version.

Updated Jul 9, 2026 · CVSS 9.8