<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>Yazoul Security - CVE Advisories</title><description>Daily critical and high-severity CVE advisories with remediation guidance from Yazoul Security. Stay informed about the latest security vulnerabilities.</description><link>https://www.yazoul.net/advisory/</link><language>en-us</language><copyright>Copyright 2026 Yazoul Security - https://www.yazoul.net/advisory</copyright><managingEditor>contact@yazoul.net (Yazoul Security)</managingEditor><webMaster>contact@yazoul.net (Yazoul Security)</webMaster><image><url>https://www.yazoul.net/advisory/icon-128.png</url><title>Yazoul Security - CVE Advisories</title><link>https://www.yazoul.net/advisory</link></image><atom:link href="https://www.yazoul.net/advisory/rss.xml" rel="self" type="application/rss+xml" xmlns:atom="http://www.w3.org/2005/Atom"/><item><title>CVE-2026-67620: Security Advisory: CVE-2026-67620</title><link>https://www.yazoul.net/advisory/cve/cve-2026-67620-flowise-ssrf-leaks-cloud-credentials-poc/</link><guid isPermaLink="true">https://www.yazoul.net/advisory/cve/cve-2026-67620-flowise-ssrf-leaks-cloud-credentials-poc/</guid><description>&lt;p&gt;&lt;strong&gt;CVE-2026-67620&lt;/strong&gt; - HIGH severity (CVSS 7.7)&lt;/p&gt;
&lt;p&gt;Flowise through 3.1.4 contains a server-side request forgery vulnerability in the SSRF guard implemented in httpSecurity.ts, where the DEFAULT_DENY_LIST omits the Oracle Cloud Infrastructure metadata ...&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected Products:&lt;/strong&gt; Multiple systems&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;https://www.yazoul.net/advisory/cve/cve-2026-67620-flowise-ssrf-leaks-cloud-credentials-poc/&quot;&gt;Read the full security advisory on Yazoul Security&lt;/a&gt;&lt;/p&gt;
&lt;hr/&gt;
&lt;p&gt;&lt;em&gt;This advisory is published by &lt;a href=&quot;https://www.yazoul.net/advisory&quot;&gt;Yazoul Security&lt;/a&gt; - Your trusted source for CVE intelligence and remediation guidance.&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;&lt;em&gt;Generated by Yazoul AI, an automated pipeline. Not reviewed by a person before publication.&lt;/em&gt;&lt;/p&gt;</description><pubDate>Sat, 08 Aug 2026 00:00:00 GMT</pubDate><category>high</category><category>CVE</category><category>Security</category><category>Vulnerability</category><author>Yazoul Security (contact@yazoul.net)</author></item><item><title>CVE-2026-18577: Security Advisory: CVE-2026-18577</title><link>https://www.yazoul.net/advisory/cve/cve-2026-18577-n-central-auth-bypass-exploited-in-the-wild/</link><guid isPermaLink="true">https://www.yazoul.net/advisory/cve/cve-2026-18577-n-central-auth-bypass-exploited-in-the-wild/</guid><description>&lt;p&gt;&lt;strong&gt;CVE-2026-18577&lt;/strong&gt; - HIGH severity (CVSS 8.2)&lt;/p&gt;
&lt;p&gt;An incomplete patch for CVE-2026-18556 allows for authentication bypass and account takeover in N-central Versions through 2026.3.1...&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected Products:&lt;/strong&gt; Multiple systems&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;https://www.yazoul.net/advisory/cve/cve-2026-18577-n-central-auth-bypass-exploited-in-the-wild/&quot;&gt;Read the full security advisory on Yazoul Security&lt;/a&gt;&lt;/p&gt;
&lt;hr/&gt;
&lt;p&gt;&lt;em&gt;This advisory is published by &lt;a href=&quot;https://www.yazoul.net/advisory&quot;&gt;Yazoul Security&lt;/a&gt; - Your trusted source for CVE intelligence and remediation guidance.&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;&lt;em&gt;Generated by Yazoul AI, an automated pipeline. Not reviewed by a person before publication.&lt;/em&gt;&lt;/p&gt;</description><pubDate>Sun, 02 Aug 2026 00:00:00 GMT</pubDate><category>high</category><category>CVE</category><category>Security</category><category>Vulnerability</category><author>Yazoul Security (contact@yazoul.net)</author></item><item><title>CVE-2026-18556: Security Advisory: CVE-2026-18556</title><link>https://www.yazoul.net/advisory/cve/cve-2026-18556-n-central-auth-bypass-exploited/</link><guid isPermaLink="true">https://www.yazoul.net/advisory/cve/cve-2026-18556-n-central-auth-bypass-exploited/</guid><description>&lt;p&gt;&lt;strong&gt;CVE-2026-18556&lt;/strong&gt; - HIGH severity (CVSS 8.2)&lt;/p&gt;
&lt;p&gt;Authentication bypass using an alternate path or channel vulnerability in N-able N-central allows Authentication Bypass.
This issue affects N-central: through 2026.1....&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected Products:&lt;/strong&gt; N-Able N-Central&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;https://www.yazoul.net/advisory/cve/cve-2026-18556-n-central-auth-bypass-exploited/&quot;&gt;Read the full security advisory on Yazoul Security&lt;/a&gt;&lt;/p&gt;
&lt;hr/&gt;
&lt;p&gt;&lt;em&gt;This advisory is published by &lt;a href=&quot;https://www.yazoul.net/advisory&quot;&gt;Yazoul Security&lt;/a&gt; - Your trusted source for CVE intelligence and remediation guidance.&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;&lt;em&gt;Generated by Yazoul AI, an automated pipeline. Not reviewed by a person before publication.&lt;/em&gt;&lt;/p&gt;</description><pubDate>Sat, 01 Aug 2026 00:00:00 GMT</pubDate><category>high</category><category>CVE</category><category>Security</category><category>Vulnerability</category><category>N-Able N-Central</category><author>Yazoul Security (contact@yazoul.net)</author></item><item><title>CVE-2026-20316: Security Advisory: CVE-2026-20316</title><link>https://www.yazoul.net/advisory/cve/cve-2026-20316-fmc-static-credentials-leak-sensitive-data/</link><guid isPermaLink="true">https://www.yazoul.net/advisory/cve/cve-2026-20316-fmc-static-credentials-leak-sensitive-data/</guid><description>&lt;p&gt;&lt;strong&gt;CVE-2026-20316&lt;/strong&gt; - MEDIUM severity (CVSS 5.3)&lt;/p&gt;
&lt;p&gt;A vulnerability in the web interface of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated, remote attacker to log in to an affected device using a low-privileged ac...&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected Products:&lt;/strong&gt; Cisco Secure Firewall Management Center&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;https://www.yazoul.net/advisory/cve/cve-2026-20316-fmc-static-credentials-leak-sensitive-data/&quot;&gt;Read the full security advisory on Yazoul Security&lt;/a&gt;&lt;/p&gt;
&lt;hr/&gt;
&lt;p&gt;&lt;em&gt;This advisory is published by &lt;a href=&quot;https://www.yazoul.net/advisory&quot;&gt;Yazoul Security&lt;/a&gt; - Your trusted source for CVE intelligence and remediation guidance.&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;&lt;em&gt;Generated by Yazoul AI, an automated pipeline. Not reviewed by a person before publication.&lt;/em&gt;&lt;/p&gt;</description><pubDate>Wed, 29 Jul 2026 00:00:00 GMT</pubDate><category>medium</category><category>CVE</category><category>Security</category><category>Vulnerability</category><category>Cisco Secure Firewall Management Center</category><author>Yazoul Security (contact@yazoul.net)</author></item><item><title>CVE-2026-16812: Security Advisory: CVE-2026-16812</title><link>https://www.yazoul.net/advisory/cve/cve-2026-16812-vco-orchestator-unauth-access-exploited/</link><guid isPermaLink="true">https://www.yazoul.net/advisory/cve/cve-2026-16812-vco-orchestator-unauth-access-exploited/</guid><description>&lt;p&gt;&lt;strong&gt;CVE-2026-16812&lt;/strong&gt; - CRITICAL severity (CVSS 10)&lt;/p&gt;
&lt;p&gt;VeloCloud Orchestrator (VCO) on-prem has a security issue where this issue may allow a remote attacker to access privileged internal functionality and impact the VCO host. Successful exploitation may ...&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected Products:&lt;/strong&gt; Multiple systems&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;https://www.yazoul.net/advisory/cve/cve-2026-16812-vco-orchestator-unauth-access-exploited/&quot;&gt;Read the full security advisory on Yazoul Security&lt;/a&gt;&lt;/p&gt;
&lt;hr/&gt;
&lt;p&gt;&lt;em&gt;This advisory is published by &lt;a href=&quot;https://www.yazoul.net/advisory&quot;&gt;Yazoul Security&lt;/a&gt; - Your trusted source for CVE intelligence and remediation guidance.&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;&lt;em&gt;Generated by Yazoul AI, an automated pipeline. Not reviewed by a person before publication.&lt;/em&gt;&lt;/p&gt;</description><pubDate>Mon, 27 Jul 2026 00:00:00 GMT</pubDate><category>critical</category><category>CVE</category><category>Security</category><category>Vulnerability</category><author>Yazoul Security (contact@yazoul.net)</author></item><item><title>CVE-2026-55579: Security Advisory: CVE-2026-55579</title><link>https://www.yazoul.net/advisory/cve/cve-2026-55579-pheditor-hardcoded-admin-rce-poc/</link><guid isPermaLink="true">https://www.yazoul.net/advisory/cve/cve-2026-55579-pheditor-hardcoded-admin-rce-poc/</guid><description>&lt;p&gt;&lt;strong&gt;CVE-2026-55579&lt;/strong&gt; - CRITICAL severity (CVSS 9.8)&lt;/p&gt;
&lt;p&gt;Pheditor is a single-file editor and file manager written in PHP. From version 2.0.1 to before version 2.0.6, Pheditor ships with a hardcoded default password admin (SHA-512 hash stored at pheditor.ph...&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected Products:&lt;/strong&gt; Multiple systems&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;https://www.yazoul.net/advisory/cve/cve-2026-55579-pheditor-hardcoded-admin-rce-poc/&quot;&gt;Read the full security advisory on Yazoul Security&lt;/a&gt;&lt;/p&gt;
&lt;hr/&gt;
&lt;p&gt;&lt;em&gt;This advisory is published by &lt;a href=&quot;https://www.yazoul.net/advisory&quot;&gt;Yazoul Security&lt;/a&gt; - Your trusted source for CVE intelligence and remediation guidance.&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;&lt;em&gt;Generated by Yazoul AI, an automated pipeline. Not reviewed by a person before publication.&lt;/em&gt;&lt;/p&gt;</description><pubDate>Mon, 27 Jul 2026 00:00:00 GMT</pubDate><category>critical</category><category>CVE</category><category>Security</category><category>Vulnerability</category><author>Yazoul Security (contact@yazoul.net)</author></item><item><title>CVE-2026-63077: Security Advisory: CVE-2026-63077</title><link>https://www.yazoul.net/advisory/cve/cve-2026-63077-teamcity-rce-exploited-in-the-wild-poc/</link><guid isPermaLink="true">https://www.yazoul.net/advisory/cve/cve-2026-63077-teamcity-rce-exploited-in-the-wild-poc/</guid><description>&lt;p&gt;&lt;strong&gt;CVE-2026-63077&lt;/strong&gt; - CRITICAL severity (CVSS 9.8)&lt;/p&gt;
&lt;p&gt;In JetBrains TeamCity before 2026.1.3, 2025.11.7 unauthenticated remote code execution was possible via the agent polling protocol...&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected Products:&lt;/strong&gt; Jetbrains Teamcity&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;https://www.yazoul.net/advisory/cve/cve-2026-63077-teamcity-rce-exploited-in-the-wild-poc/&quot;&gt;Read the full security advisory on Yazoul Security&lt;/a&gt;&lt;/p&gt;
&lt;hr/&gt;
&lt;p&gt;&lt;em&gt;This advisory is published by &lt;a href=&quot;https://www.yazoul.net/advisory&quot;&gt;Yazoul Security&lt;/a&gt; - Your trusted source for CVE intelligence and remediation guidance.&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;&lt;em&gt;Generated by Yazoul AI, an automated pipeline. Not reviewed by a person before publication.&lt;/em&gt;&lt;/p&gt;</description><pubDate>Mon, 27 Jul 2026 00:00:00 GMT</pubDate><category>critical</category><category>CVE</category><category>Security</category><category>Vulnerability</category><category>Jetbrains Teamcity</category><author>Yazoul Security (contact@yazoul.net)</author></item><item><title>CVE-2026-47668: Security Advisory: CVE-2026-47668</title><link>https://www.yazoul.net/advisory/cve/cve-2026-47668-dbgate-unauthenticated-rce-poc/</link><guid isPermaLink="true">https://www.yazoul.net/advisory/cve/cve-2026-47668-dbgate-unauthenticated-rce-poc/</guid><description>&lt;p&gt;&lt;strong&gt;CVE-2026-47668&lt;/strong&gt; - CRITICAL severity (CVSS 10)&lt;/p&gt;
&lt;p&gt;DbGate is cross-platform database manager. In versions 7.1.8 and prior, DbGate&apos;s JSON script runner (`POST /runners/start`) allows remote code execution via code injection in the `functionName` parame...&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected Products:&lt;/strong&gt; Multiple systems&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;https://www.yazoul.net/advisory/cve/cve-2026-47668-dbgate-unauthenticated-rce-poc/&quot;&gt;Read the full security advisory on Yazoul Security&lt;/a&gt;&lt;/p&gt;
&lt;hr/&gt;
&lt;p&gt;&lt;em&gt;This advisory is published by &lt;a href=&quot;https://www.yazoul.net/advisory&quot;&gt;Yazoul Security&lt;/a&gt; - Your trusted source for CVE intelligence and remediation guidance.&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;&lt;em&gt;Generated by Yazoul AI, an automated pipeline. Not reviewed by a person before publication.&lt;/em&gt;&lt;/p&gt;</description><pubDate>Thu, 23 Jul 2026 00:00:00 GMT</pubDate><category>critical</category><category>CVE</category><category>Security</category><category>Vulnerability</category><author>Yazoul Security (contact@yazoul.net)</author></item><item><title>CVE-2026-16232: Security Advisory: CVE-2026-16232</title><link>https://www.yazoul.net/advisory/cve/cve-2026-16232-check-point-smartconsole-auth-bypass-exploited/</link><guid isPermaLink="true">https://www.yazoul.net/advisory/cve/cve-2026-16232-check-point-smartconsole-auth-bypass-exploited/</guid><description>&lt;p&gt;&lt;strong&gt;CVE-2026-16232&lt;/strong&gt; - CRITICAL severity (CVSS 9.1)&lt;/p&gt;
&lt;p&gt;An authentication bypass vulnerability in the Check Point SmartConsole login process allows an unauthenticated remote attacker to obtain an application login token and use it to authenticate with full...&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected Products:&lt;/strong&gt; Multiple systems&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;https://www.yazoul.net/advisory/cve/cve-2026-16232-check-point-smartconsole-auth-bypass-exploited/&quot;&gt;Read the full security advisory on Yazoul Security&lt;/a&gt;&lt;/p&gt;
&lt;hr/&gt;
&lt;p&gt;&lt;em&gt;This advisory is published by &lt;a href=&quot;https://www.yazoul.net/advisory&quot;&gt;Yazoul Security&lt;/a&gt; - Your trusted source for CVE intelligence and remediation guidance.&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;&lt;em&gt;Generated by Yazoul AI, an automated pipeline. Not reviewed by a person before publication.&lt;/em&gt;&lt;/p&gt;</description><pubDate>Wed, 22 Jul 2026 00:00:00 GMT</pubDate><category>critical</category><category>CVE</category><category>Security</category><category>Vulnerability</category><author>Yazoul Security (contact@yazoul.net)</author></item><item><title>CVE-2026-60137: Security Advisory: CVE-2026-60137</title><link>https://www.yazoul.net/advisory/cve/cve-2026-60137-wordpress-sqli-exploited-in-the-wild-poc/</link><guid isPermaLink="true">https://www.yazoul.net/advisory/cve/cve-2026-60137-wordpress-sqli-exploited-in-the-wild-poc/</guid><description>&lt;p&gt;&lt;strong&gt;CVE-2026-60137&lt;/strong&gt; - CRITICAL severity (CVSS 9.1)&lt;/p&gt;
&lt;p&gt;WordPress 6.8.x before 6.8.6, 6.9.x before 6.9.5, and 7.0.x before 7.0.2 does not properly sanitise the author__not_in parameter of WP_Query, which could allow SQL Injection when a plugin or theme pas...&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected Products:&lt;/strong&gt; Multiple systems&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;https://www.yazoul.net/advisory/cve/cve-2026-60137-wordpress-sqli-exploited-in-the-wild-poc/&quot;&gt;Read the full security advisory on Yazoul Security&lt;/a&gt;&lt;/p&gt;
&lt;hr/&gt;
&lt;p&gt;&lt;em&gt;This advisory is published by &lt;a href=&quot;https://www.yazoul.net/advisory&quot;&gt;Yazoul Security&lt;/a&gt; - Your trusted source for CVE intelligence and remediation guidance.&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;&lt;em&gt;Generated by Yazoul AI, an automated pipeline. Not reviewed by a person before publication.&lt;/em&gt;&lt;/p&gt;</description><pubDate>Fri, 17 Jul 2026 00:00:00 GMT</pubDate><category>critical</category><category>CVE</category><category>Security</category><category>Vulnerability</category><author>Yazoul Security (contact@yazoul.net)</author></item><item><title>CVE-2026-63030: Security Advisory: CVE-2026-63030</title><link>https://www.yazoul.net/advisory/cve/cve-2026-63030-wordpress-rest-api-unauth-rce-poc/</link><guid isPermaLink="true">https://www.yazoul.net/advisory/cve/cve-2026-63030-wordpress-rest-api-unauth-rce-poc/</guid><description>&lt;p&gt;&lt;strong&gt;CVE-2026-63030&lt;/strong&gt; - CRITICAL severity (CVSS 9.8)&lt;/p&gt;
&lt;p&gt;WordPress 6.9.x before 6.9.5 and 7.0.x before 7.0.2 is affected by a REST API batch endpoint route confusion issue which, combined with the author__not_in WP_Query SQL Injection (CVE-2026-60137), coul...&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected Products:&lt;/strong&gt; Multiple systems&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;https://www.yazoul.net/advisory/cve/cve-2026-63030-wordpress-rest-api-unauth-rce-poc/&quot;&gt;Read the full security advisory on Yazoul Security&lt;/a&gt;&lt;/p&gt;
&lt;hr/&gt;
&lt;p&gt;&lt;em&gt;This advisory is published by &lt;a href=&quot;https://www.yazoul.net/advisory&quot;&gt;Yazoul Security&lt;/a&gt; - Your trusted source for CVE intelligence and remediation guidance.&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;&lt;em&gt;Generated by Yazoul AI, an automated pipeline. Not reviewed by a person before publication.&lt;/em&gt;&lt;/p&gt;</description><pubDate>Fri, 17 Jul 2026 00:00:00 GMT</pubDate><category>critical</category><category>CVE</category><category>Security</category><category>Vulnerability</category><author>Yazoul Security (contact@yazoul.net)</author></item><item><title>CVE-2026-9198: Security Advisory: CVE-2026-9198</title><link>https://www.yazoul.net/advisory/cve/cve-2026-9198-langflow-unauthenticated-rce-exploited-in-wild-poc/</link><guid isPermaLink="true">https://www.yazoul.net/advisory/cve/cve-2026-9198-langflow-unauthenticated-rce-exploited-in-wild-poc/</guid><description>&lt;p&gt;&lt;strong&gt;CVE-2026-9198&lt;/strong&gt; - CRITICAL severity (CVSS 9.8)&lt;/p&gt;
&lt;p&gt;IBM Langflow OSS 1.0.0 through 1.10.0 allows unauthenticated attackers to chain /api/v1/auto_login (mints SUPERUSER tokens to any network caller) with /api/v1/validate/code (executes user code via exe...&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected Products:&lt;/strong&gt; Langflow&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;https://www.yazoul.net/advisory/cve/cve-2026-9198-langflow-unauthenticated-rce-exploited-in-wild-poc/&quot;&gt;Read the full security advisory on Yazoul Security&lt;/a&gt;&lt;/p&gt;
&lt;hr/&gt;
&lt;p&gt;&lt;em&gt;This advisory is published by &lt;a href=&quot;https://www.yazoul.net/advisory&quot;&gt;Yazoul Security&lt;/a&gt; - Your trusted source for CVE intelligence and remediation guidance.&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;&lt;em&gt;Generated by Yazoul AI, an automated pipeline. Not reviewed by a person before publication.&lt;/em&gt;&lt;/p&gt;</description><pubDate>Fri, 17 Jul 2026 00:00:00 GMT</pubDate><category>critical</category><category>CVE</category><category>Security</category><category>Vulnerability</category><category>Langflow</category><author>Yazoul Security (contact@yazoul.net)</author></item><item><title>CVE-2021-27137: Security Advisory: CVE-2021-27137</title><link>https://www.yazoul.net/advisory/cve/cve-2021-27137-dd-wrt-upnp-overflow-exploited/</link><guid isPermaLink="true">https://www.yazoul.net/advisory/cve/cve-2021-27137-dd-wrt-upnp-overflow-exploited/</guid><description>&lt;p&gt;&lt;strong&gt;CVE-2021-27137&lt;/strong&gt; - HIGH severity (CVSS 8.1)&lt;/p&gt;
&lt;p&gt;An issue was discovered in router/upnp/src/ssdp.c in DD-WRT before 45724. An unsafe strcpy in the UPnP handling functionality allows an unauthenticated remote attacker to send a request that would ove...&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected Products:&lt;/strong&gt; Multiple systems&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;https://www.yazoul.net/advisory/cve/cve-2021-27137-dd-wrt-upnp-overflow-exploited/&quot;&gt;Read the full security advisory on Yazoul Security&lt;/a&gt;&lt;/p&gt;
&lt;hr/&gt;
&lt;p&gt;&lt;em&gt;This advisory is published by &lt;a href=&quot;https://www.yazoul.net/advisory&quot;&gt;Yazoul Security&lt;/a&gt; - Your trusted source for CVE intelligence and remediation guidance.&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;&lt;em&gt;Generated by Yazoul AI, an automated pipeline. Not reviewed by a person before publication.&lt;/em&gt;&lt;/p&gt;</description><pubDate>Thu, 16 Jul 2026 00:00:00 GMT</pubDate><category>high</category><category>CVE</category><category>Security</category><category>Vulnerability</category><author>Yazoul Security (contact@yazoul.net)</author></item><item><title>CVE-2026-15409: Security Advisory: CVE-2026-15409</title><link>https://www.yazoul.net/advisory/cve/cve-2026-15409-sma1000-appliance-ssrf-exploited-in-wild/</link><guid isPermaLink="true">https://www.yazoul.net/advisory/cve/cve-2026-15409-sma1000-appliance-ssrf-exploited-in-wild/</guid><description>&lt;p&gt;&lt;strong&gt;CVE-2026-15409&lt;/strong&gt; - CRITICAL severity (CVSS 10)&lt;/p&gt;
&lt;p&gt;A Server-side request forgery (SSRF) vulnerability has been identified in the SMA1000 Appliance Work Place interface. A remote unauthenticated attacker could potentially cause the appliance to make re...&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected Products:&lt;/strong&gt; Multiple systems&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;https://www.yazoul.net/advisory/cve/cve-2026-15409-sma1000-appliance-ssrf-exploited-in-wild/&quot;&gt;Read the full security advisory on Yazoul Security&lt;/a&gt;&lt;/p&gt;
&lt;hr/&gt;
&lt;p&gt;&lt;em&gt;This advisory is published by &lt;a href=&quot;https://www.yazoul.net/advisory&quot;&gt;Yazoul Security&lt;/a&gt; - Your trusted source for CVE intelligence and remediation guidance.&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;&lt;em&gt;Generated by Yazoul AI, an automated pipeline. Not reviewed by a person before publication.&lt;/em&gt;&lt;/p&gt;</description><pubDate>Tue, 14 Jul 2026 00:00:00 GMT</pubDate><category>critical</category><category>CVE</category><category>Security</category><category>Vulnerability</category><author>Yazoul Security (contact@yazoul.net)</author></item><item><title>CVE-2026-15410: Security Advisory: CVE-2026-15410</title><link>https://www.yazoul.net/advisory/cve/cve-2026-15410-sma1000-amc-code-injection-exploited-in-wild/</link><guid isPermaLink="true">https://www.yazoul.net/advisory/cve/cve-2026-15410-sma1000-amc-code-injection-exploited-in-wild/</guid><description>&lt;p&gt;&lt;strong&gt;CVE-2026-15410&lt;/strong&gt; - HIGH severity (CVSS 7.2)&lt;/p&gt;
&lt;p&gt;Post-authentication improper control of generation of code (&apos;Code Injection&apos;) vulnerability has been identified in the SMA1000 Appliance Management Console (AMC) which in specific conditions could pot...&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected Products:&lt;/strong&gt; Multiple systems&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;https://www.yazoul.net/advisory/cve/cve-2026-15410-sma1000-amc-code-injection-exploited-in-wild/&quot;&gt;Read the full security advisory on Yazoul Security&lt;/a&gt;&lt;/p&gt;
&lt;hr/&gt;
&lt;p&gt;&lt;em&gt;This advisory is published by &lt;a href=&quot;https://www.yazoul.net/advisory&quot;&gt;Yazoul Security&lt;/a&gt; - Your trusted source for CVE intelligence and remediation guidance.&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;&lt;em&gt;Generated by Yazoul AI, an automated pipeline. Not reviewed by a person before publication.&lt;/em&gt;&lt;/p&gt;</description><pubDate>Tue, 14 Jul 2026 00:00:00 GMT</pubDate><category>high</category><category>CVE</category><category>Security</category><category>Vulnerability</category><author>Yazoul Security (contact@yazoul.net)</author></item><item><title>CVE-2026-50522: Security Advisory: CVE-2026-50522</title><link>https://www.yazoul.net/advisory/cve/cve-2026-50522-sharepoint-unauthenticated-rce-actively-exploited-poc/</link><guid isPermaLink="true">https://www.yazoul.net/advisory/cve/cve-2026-50522-sharepoint-unauthenticated-rce-actively-exploited-poc/</guid><description>&lt;p&gt;&lt;strong&gt;CVE-2026-50522&lt;/strong&gt; - CRITICAL severity (CVSS 9.8)&lt;/p&gt;
&lt;p&gt;Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network....&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected Products:&lt;/strong&gt; Microsoft Sharepoint Server&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;https://www.yazoul.net/advisory/cve/cve-2026-50522-sharepoint-unauthenticated-rce-actively-exploited-poc/&quot;&gt;Read the full security advisory on Yazoul Security&lt;/a&gt;&lt;/p&gt;
&lt;hr/&gt;
&lt;p&gt;&lt;em&gt;This advisory is published by &lt;a href=&quot;https://www.yazoul.net/advisory&quot;&gt;Yazoul Security&lt;/a&gt; - Your trusted source for CVE intelligence and remediation guidance.&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;&lt;em&gt;Generated by Yazoul AI, an automated pipeline. Not reviewed by a person before publication.&lt;/em&gt;&lt;/p&gt;</description><pubDate>Tue, 14 Jul 2026 00:00:00 GMT</pubDate><category>critical</category><category>CVE</category><category>Security</category><category>Vulnerability</category><category>Microsoft Sharepoint Server</category><author>Yazoul Security (contact@yazoul.net)</author></item><item><title>CVE-2026-56155: Security Advisory: CVE-2026-56155</title><link>https://www.yazoul.net/advisory/cve/cve-2026-56155-ad-fs-privilege-escalation-exploited-in-wild/</link><guid isPermaLink="true">https://www.yazoul.net/advisory/cve/cve-2026-56155-ad-fs-privilege-escalation-exploited-in-wild/</guid><description>&lt;p&gt;&lt;strong&gt;CVE-2026-56155&lt;/strong&gt; - HIGH severity (CVSS 7.8)&lt;/p&gt;
&lt;p&gt;Insufficient granularity of access control in Active Directory Federation Services (AD FS) allows an authorized attacker to elevate privileges locally....&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected Products:&lt;/strong&gt; Microsoft Windows 10 1607, Microsoft Windows 10 1809, Microsoft Windows Server 2012, Microsoft Windows Server 2016, Microsoft Windows Server 2019&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;https://www.yazoul.net/advisory/cve/cve-2026-56155-ad-fs-privilege-escalation-exploited-in-wild/&quot;&gt;Read the full security advisory on Yazoul Security&lt;/a&gt;&lt;/p&gt;
&lt;hr/&gt;
&lt;p&gt;&lt;em&gt;This advisory is published by &lt;a href=&quot;https://www.yazoul.net/advisory&quot;&gt;Yazoul Security&lt;/a&gt; - Your trusted source for CVE intelligence and remediation guidance.&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;&lt;em&gt;Generated by Yazoul AI, an automated pipeline. Not reviewed by a person before publication.&lt;/em&gt;&lt;/p&gt;</description><pubDate>Tue, 14 Jul 2026 00:00:00 GMT</pubDate><category>high</category><category>CVE</category><category>Security</category><category>Vulnerability</category><category>Microsoft Windows 10 1607</category><category>Microsoft Windows 10 1809</category><category>Microsoft Windows Server 2012</category><author>Yazoul Security (contact@yazoul.net)</author></item><item><title>CVE-2026-56164: Security Advisory: CVE-2026-56164</title><link>https://www.yazoul.net/advisory/cve/cve-2026-56164-sharepoint-privilege-escalation-exploited/</link><guid isPermaLink="true">https://www.yazoul.net/advisory/cve/cve-2026-56164-sharepoint-privilege-escalation-exploited/</guid><description>&lt;p&gt;&lt;strong&gt;CVE-2026-56164&lt;/strong&gt; - CRITICAL severity (CVSS 9.8)&lt;/p&gt;
&lt;p&gt;Missing authentication for critical function in Microsoft Office SharePoint allows an unauthorized attacker to elevate privileges over a network....&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected Products:&lt;/strong&gt; Microsoft Sharepoint Server&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;https://www.yazoul.net/advisory/cve/cve-2026-56164-sharepoint-privilege-escalation-exploited/&quot;&gt;Read the full security advisory on Yazoul Security&lt;/a&gt;&lt;/p&gt;
&lt;hr/&gt;
&lt;p&gt;&lt;em&gt;This advisory is published by &lt;a href=&quot;https://www.yazoul.net/advisory&quot;&gt;Yazoul Security&lt;/a&gt; - Your trusted source for CVE intelligence and remediation guidance.&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;&lt;em&gt;Generated by Yazoul AI, an automated pipeline. Not reviewed by a person before publication.&lt;/em&gt;&lt;/p&gt;</description><pubDate>Tue, 14 Jul 2026 00:00:00 GMT</pubDate><category>critical</category><category>CVE</category><category>Security</category><category>Vulnerability</category><category>Microsoft Sharepoint Server</category><author>Yazoul Security (contact@yazoul.net)</author></item><item><title>CVE-2026-58644: Security Advisory: CVE-2026-58644</title><link>https://www.yazoul.net/advisory/cve/cve-2026-58644-sharepoint-unauthenticated-rce-exploited/</link><guid isPermaLink="true">https://www.yazoul.net/advisory/cve/cve-2026-58644-sharepoint-unauthenticated-rce-exploited/</guid><description>&lt;p&gt;&lt;strong&gt;CVE-2026-58644&lt;/strong&gt; - CRITICAL severity (CVSS 9.8)&lt;/p&gt;
&lt;p&gt;Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network....&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected Products:&lt;/strong&gt; Microsoft Sharepoint Server&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;https://www.yazoul.net/advisory/cve/cve-2026-58644-sharepoint-unauthenticated-rce-exploited/&quot;&gt;Read the full security advisory on Yazoul Security&lt;/a&gt;&lt;/p&gt;
&lt;hr/&gt;
&lt;p&gt;&lt;em&gt;This advisory is published by &lt;a href=&quot;https://www.yazoul.net/advisory&quot;&gt;Yazoul Security&lt;/a&gt; - Your trusted source for CVE intelligence and remediation guidance.&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;&lt;em&gt;Generated by Yazoul AI, an automated pipeline. Not reviewed by a person before publication.&lt;/em&gt;&lt;/p&gt;</description><pubDate>Tue, 14 Jul 2026 00:00:00 GMT</pubDate><category>critical</category><category>CVE</category><category>Security</category><category>Vulnerability</category><category>Microsoft Sharepoint Server</category><author>Yazoul Security (contact@yazoul.net)</author></item><item><title>CVE-2026-56291: Security Advisory: CVE-2026-56291</title><link>https://www.yazoul.net/advisory/cve/cve-2026-56291-balbooa-forms-unauthenticated-rce-exploited/</link><guid isPermaLink="true">https://www.yazoul.net/advisory/cve/cve-2026-56291-balbooa-forms-unauthenticated-rce-exploited/</guid><description>&lt;p&gt;&lt;strong&gt;CVE-2026-56291&lt;/strong&gt; - CRITICAL severity (CVSS 10)&lt;/p&gt;
&lt;p&gt;The Joomla extension Balbooa Forms is vulnerable to an unauthenticated arbitrary file upload that allows uploading executable files and leads to full RCE....&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected Products:&lt;/strong&gt; Balbooa Forms&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;https://www.yazoul.net/advisory/cve/cve-2026-56291-balbooa-forms-unauthenticated-rce-exploited/&quot;&gt;Read the full security advisory on Yazoul Security&lt;/a&gt;&lt;/p&gt;
&lt;hr/&gt;
&lt;p&gt;&lt;em&gt;This advisory is published by &lt;a href=&quot;https://www.yazoul.net/advisory&quot;&gt;Yazoul Security&lt;/a&gt; - Your trusted source for CVE intelligence and remediation guidance.&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;&lt;em&gt;Generated by Yazoul AI, an automated pipeline. Not reviewed by a person before publication.&lt;/em&gt;&lt;/p&gt;</description><pubDate>Thu, 09 Jul 2026 00:00:00 GMT</pubDate><category>critical</category><category>CVE</category><category>Security</category><category>Vulnerability</category><category>Balbooa Forms</category><author>Yazoul Security (contact@yazoul.net)</author></item><item><title>CVE-2026-23697: Security Advisory: CVE-2026-23697</title><link>https://www.yazoul.net/advisory/cve/cve-2026-23697-vtiger-crm-rce-via-phar-upload-poc/</link><guid isPermaLink="true">https://www.yazoul.net/advisory/cve/cve-2026-23697-vtiger-crm-rce-via-phar-upload-poc/</guid><description>&lt;p&gt;&lt;strong&gt;CVE-2026-23697&lt;/strong&gt; - HIGH severity (CVSS 8.8)&lt;/p&gt;
&lt;p&gt;Vtiger CRM before 8.4.0 contains an authenticated file upload vulnerability that allows low-privileged users to achieve remote code execution by uploading a .phar file containing arbitrary PHP code th...&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected Products:&lt;/strong&gt; Multiple systems&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;https://www.yazoul.net/advisory/cve/cve-2026-23697-vtiger-crm-rce-via-phar-upload-poc/&quot;&gt;Read the full security advisory on Yazoul Security&lt;/a&gt;&lt;/p&gt;
&lt;hr/&gt;
&lt;p&gt;&lt;em&gt;This advisory is published by &lt;a href=&quot;https://www.yazoul.net/advisory&quot;&gt;Yazoul Security&lt;/a&gt; - Your trusted source for CVE intelligence and remediation guidance.&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;&lt;em&gt;Generated by Yazoul AI, an automated pipeline. Not reviewed by a person before publication.&lt;/em&gt;&lt;/p&gt;</description><pubDate>Tue, 07 Jul 2026 00:00:00 GMT</pubDate><category>high</category><category>CVE</category><category>Security</category><category>Vulnerability</category><author>Yazoul Security (contact@yazoul.net)</author></item><item><title>CVE-2026-23698: Security Advisory: CVE-2026-23698</title><link>https://www.yazoul.net/advisory/cve/cve-2026-23698-vtiger-crm-lets-admins-upload-webshells-poc/</link><guid isPermaLink="true">https://www.yazoul.net/advisory/cve/cve-2026-23698-vtiger-crm-lets-admins-upload-webshells-poc/</guid><description>&lt;p&gt;&lt;strong&gt;CVE-2026-23698&lt;/strong&gt; - HIGH severity (CVSS 8.6)&lt;/p&gt;
&lt;p&gt;Vtiger CRM through 8.4.0 contains an authenticated remote code execution vulnerability in the admin module import feature that allows administrator-level attackers to upload arbitrary PHP files by sub...&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected Products:&lt;/strong&gt; Multiple systems&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;https://www.yazoul.net/advisory/cve/cve-2026-23698-vtiger-crm-lets-admins-upload-webshells-poc/&quot;&gt;Read the full security advisory on Yazoul Security&lt;/a&gt;&lt;/p&gt;
&lt;hr/&gt;
&lt;p&gt;&lt;em&gt;This advisory is published by &lt;a href=&quot;https://www.yazoul.net/advisory&quot;&gt;Yazoul Security&lt;/a&gt; - Your trusted source for CVE intelligence and remediation guidance.&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;&lt;em&gt;Generated by Yazoul AI, an automated pipeline. Not reviewed by a person before publication.&lt;/em&gt;&lt;/p&gt;</description><pubDate>Tue, 07 Jul 2026 00:00:00 GMT</pubDate><category>high</category><category>CVE</category><category>Security</category><category>Vulnerability</category><author>Yazoul Security (contact@yazoul.net)</author></item><item><title>CVE-2026-34038: Security Advisory: CVE-2026-34038</title><link>https://www.yazoul.net/advisory/cve/cve-2026-34038-coolify-rce-leaks-secrets-poc/</link><guid isPermaLink="true">https://www.yazoul.net/advisory/cve/cve-2026-34038-coolify-rce-leaks-secrets-poc/</guid><description>&lt;p&gt;&lt;strong&gt;CVE-2026-34038&lt;/strong&gt; - CRITICAL severity (CVSS 9.9)&lt;/p&gt;
&lt;p&gt;Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.469, an authenticated remote command injection vulnerability in application depl...&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected Products:&lt;/strong&gt; Multiple systems&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;https://www.yazoul.net/advisory/cve/cve-2026-34038-coolify-rce-leaks-secrets-poc/&quot;&gt;Read the full security advisory on Yazoul Security&lt;/a&gt;&lt;/p&gt;
&lt;hr/&gt;
&lt;p&gt;&lt;em&gt;This advisory is published by &lt;a href=&quot;https://www.yazoul.net/advisory&quot;&gt;Yazoul Security&lt;/a&gt; - Your trusted source for CVE intelligence and remediation guidance.&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;&lt;em&gt;Generated by Yazoul AI, an automated pipeline. Not reviewed by a person before publication.&lt;/em&gt;&lt;/p&gt;</description><pubDate>Mon, 06 Jul 2026 00:00:00 GMT</pubDate><category>critical</category><category>CVE</category><category>Security</category><category>Vulnerability</category><author>Yazoul Security (contact@yazoul.net)</author></item><item><title>CVE-2026-48282: Security Advisory: CVE-2026-48282</title><link>https://www.yazoul.net/advisory/cve/cve-2026-48282-coldfusion-rce-exploited-in-wild-poc/</link><guid isPermaLink="true">https://www.yazoul.net/advisory/cve/cve-2026-48282-coldfusion-rce-exploited-in-wild-poc/</guid><description>&lt;p&gt;&lt;strong&gt;CVE-2026-48282&lt;/strong&gt; - CRITICAL severity (CVSS 10)&lt;/p&gt;
&lt;p&gt;ColdFusion versions 2025.9, 2023.20 and earlier are affected by an Improper Limitation of a Pathname to a Restricted Directory (&apos;Path Traversal&apos;) vulnerability that could lead to arbitrary code execut...&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected Products:&lt;/strong&gt; Adobe Coldfusion&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;https://www.yazoul.net/advisory/cve/cve-2026-48282-coldfusion-rce-exploited-in-wild-poc/&quot;&gt;Read the full security advisory on Yazoul Security&lt;/a&gt;&lt;/p&gt;
&lt;hr/&gt;
&lt;p&gt;&lt;em&gt;This advisory is published by &lt;a href=&quot;https://www.yazoul.net/advisory&quot;&gt;Yazoul Security&lt;/a&gt; - Your trusted source for CVE intelligence and remediation guidance.&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;&lt;em&gt;Generated by Yazoul AI, an automated pipeline. Not reviewed by a person before publication.&lt;/em&gt;&lt;/p&gt;</description><pubDate>Tue, 30 Jun 2026 00:00:00 GMT</pubDate><category>critical</category><category>CVE</category><category>Security</category><category>Vulnerability</category><category>Adobe Coldfusion</category><author>Yazoul Security (contact@yazoul.net)</author></item><item><title>CVE-2026-58138: Security Advisory: CVE-2026-58138</title><link>https://www.yazoul.net/advisory/cve/cve-2026-58138-orkes-conductor-unauth-rce-poc/</link><guid isPermaLink="true">https://www.yazoul.net/advisory/cve/cve-2026-58138-orkes-conductor-unauth-rce-poc/</guid><description>&lt;p&gt;&lt;strong&gt;CVE-2026-58138&lt;/strong&gt; - CRITICAL severity (CVSS 9.8)&lt;/p&gt;
&lt;p&gt;Orkes Conductor 3.21.21 before 3.30.2 contains an unauthenticated remote code execution vulnerability that allows remote attackers to execute arbitrary OS commands by submitting inline workflow defini...&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected Products:&lt;/strong&gt; Multiple systems&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;https://www.yazoul.net/advisory/cve/cve-2026-58138-orkes-conductor-unauth-rce-poc/&quot;&gt;Read the full security advisory on Yazoul Security&lt;/a&gt;&lt;/p&gt;
&lt;hr/&gt;
&lt;p&gt;&lt;em&gt;This advisory is published by &lt;a href=&quot;https://www.yazoul.net/advisory&quot;&gt;Yazoul Security&lt;/a&gt; - Your trusted source for CVE intelligence and remediation guidance.&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;&lt;em&gt;Generated by Yazoul AI, an automated pipeline. Not reviewed by a person before publication.&lt;/em&gt;&lt;/p&gt;</description><pubDate>Tue, 30 Jun 2026 00:00:00 GMT</pubDate><category>critical</category><category>CVE</category><category>Security</category><category>Vulnerability</category><author>Yazoul Security (contact@yazoul.net)</author></item><item><title>CVE-2026-56290: Security Advisory: CVE-2026-56290</title><link>https://www.yazoul.net/advisory/cve/cve-2026-56290-page-builder-ck-unauth-rce-exploited-poc/</link><guid isPermaLink="true">https://www.yazoul.net/advisory/cve/cve-2026-56290-page-builder-ck-unauth-rce-exploited-poc/</guid><description>&lt;p&gt;&lt;strong&gt;CVE-2026-56290&lt;/strong&gt; - CRITICAL severity (CVSS 10)&lt;/p&gt;
&lt;p&gt;The Joomla extension Page Builder CK is vulnerable to an unauthenticated arbitrary file upload that allows uploading executable files and leads to full RCE....&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected Products:&lt;/strong&gt; Joomlack Page Builder Ck&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;https://www.yazoul.net/advisory/cve/cve-2026-56290-page-builder-ck-unauth-rce-exploited-poc/&quot;&gt;Read the full security advisory on Yazoul Security&lt;/a&gt;&lt;/p&gt;
&lt;hr/&gt;
&lt;p&gt;&lt;em&gt;This advisory is published by &lt;a href=&quot;https://www.yazoul.net/advisory&quot;&gt;Yazoul Security&lt;/a&gt; - Your trusted source for CVE intelligence and remediation guidance.&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;&lt;em&gt;Generated by Yazoul AI, an automated pipeline. Not reviewed by a person before publication.&lt;/em&gt;&lt;/p&gt;</description><pubDate>Mon, 29 Jun 2026 00:00:00 GMT</pubDate><category>critical</category><category>CVE</category><category>Security</category><category>Vulnerability</category><category>Joomlack Page Builder Ck</category><author>Yazoul Security (contact@yazoul.net)</author></item><item><title>CVE-2026-55255: Security Advisory: CVE-2026-55255</title><link>https://www.yazoul.net/advisory/cve/cve-2026-55255-langflow-idor-executes-flows-as-others/</link><guid isPermaLink="true">https://www.yazoul.net/advisory/cve/cve-2026-55255-langflow-idor-executes-flows-as-others/</guid><description>&lt;p&gt;&lt;strong&gt;CVE-2026-55255&lt;/strong&gt; - HIGH severity (CVSS 8.4)&lt;/p&gt;
&lt;p&gt;Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to 1.9.1, an Insecure Direct Object Reference (IDOR) vulnerability in /api/v1/responses endpoint allows an authenti...&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected Products:&lt;/strong&gt; Langflow&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;https://www.yazoul.net/advisory/cve/cve-2026-55255-langflow-idor-executes-flows-as-others/&quot;&gt;Read the full security advisory on Yazoul Security&lt;/a&gt;&lt;/p&gt;
&lt;hr/&gt;
&lt;p&gt;&lt;em&gt;This advisory is published by &lt;a href=&quot;https://www.yazoul.net/advisory&quot;&gt;Yazoul Security&lt;/a&gt; - Your trusted source for CVE intelligence and remediation guidance.&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;&lt;em&gt;Generated by Yazoul AI, an automated pipeline. Not reviewed by a person before publication.&lt;/em&gt;&lt;/p&gt;</description><pubDate>Tue, 23 Jun 2026 00:00:00 GMT</pubDate><category>high</category><category>CVE</category><category>Security</category><category>Vulnerability</category><category>Langflow</category><author>Yazoul Security (contact@yazoul.net)</author></item><item><title>CVE-2026-48908: Security Advisory: CVE-2026-48908</title><link>https://www.yazoul.net/advisory/cve/cve-2026-48908-sp-page-builder-unauth-file-upload-poc/</link><guid isPermaLink="true">https://www.yazoul.net/advisory/cve/cve-2026-48908-sp-page-builder-unauth-file-upload-poc/</guid><description>&lt;p&gt;&lt;strong&gt;CVE-2026-48908&lt;/strong&gt; - CRITICAL severity (CVSS 10)&lt;/p&gt;
&lt;p&gt;A vulnerability in SP Page Builder for Joomla allows unauthenticated users to upload arbitrary files, ultimately resulting in the upload and execution of PHP code....&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected Products:&lt;/strong&gt; Ollyo Sp Page Builder&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;https://www.yazoul.net/advisory/cve/cve-2026-48908-sp-page-builder-unauth-file-upload-poc/&quot;&gt;Read the full security advisory on Yazoul Security&lt;/a&gt;&lt;/p&gt;
&lt;hr/&gt;
&lt;p&gt;&lt;em&gt;This advisory is published by &lt;a href=&quot;https://www.yazoul.net/advisory&quot;&gt;Yazoul Security&lt;/a&gt; - Your trusted source for CVE intelligence and remediation guidance.&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;&lt;em&gt;Generated by Yazoul AI, an automated pipeline. Not reviewed by a person before publication.&lt;/em&gt;&lt;/p&gt;</description><pubDate>Sat, 20 Jun 2026 00:00:00 GMT</pubDate><category>critical</category><category>CVE</category><category>Security</category><category>Vulnerability</category><category>Ollyo Sp Page Builder</category><author>Yazoul Security (contact@yazoul.net)</author></item><item><title>CVE-2026-48939: Security Advisory: CVE-2026-48939</title><link>https://www.yazoul.net/advisory/cve/cve-2026-48939-icagenda-file-upload-unauth-rce-poc/</link><guid isPermaLink="true">https://www.yazoul.net/advisory/cve/cve-2026-48939-icagenda-file-upload-unauth-rce-poc/</guid><description>&lt;p&gt;&lt;strong&gt;CVE-2026-48939&lt;/strong&gt; - CRITICAL severity (CVSS 10)&lt;/p&gt;
&lt;p&gt;A vulnerability in the iCagenda extension for Joomla allows the upload of arbitrary files in the file attachment feature, ultimately resulting in PHP code upload and execution....&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected Products:&lt;/strong&gt; Joomlic Icagenda&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;https://www.yazoul.net/advisory/cve/cve-2026-48939-icagenda-file-upload-unauth-rce-poc/&quot;&gt;Read the full security advisory on Yazoul Security&lt;/a&gt;&lt;/p&gt;
&lt;hr/&gt;
&lt;p&gt;&lt;em&gt;This advisory is published by &lt;a href=&quot;https://www.yazoul.net/advisory&quot;&gt;Yazoul Security&lt;/a&gt; - Your trusted source for CVE intelligence and remediation guidance.&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;&lt;em&gt;Generated by Yazoul AI, an automated pipeline. Not reviewed by a person before publication.&lt;/em&gt;&lt;/p&gt;</description><pubDate>Sat, 20 Jun 2026 00:00:00 GMT</pubDate><category>critical</category><category>CVE</category><category>Security</category><category>Vulnerability</category><category>Joomlic Icagenda</category><author>Yazoul Security (contact@yazoul.net)</author></item><item><title>CVE-2026-12569: Security Advisory: CVE-2026-12569</title><link>https://www.yazoul.net/advisory/cve/cve-2026-12569-windchill-rce-exploited-in-the-wild/</link><guid isPermaLink="true">https://www.yazoul.net/advisory/cve/cve-2026-12569-windchill-rce-exploited-in-the-wild/</guid><description>&lt;p&gt;&lt;strong&gt;CVE-2026-12569&lt;/strong&gt; - CRITICAL severity (CVSS 9.3)&lt;/p&gt;
&lt;p&gt;A critical remote code execution (RCE) vulnerability has been reported in PTC Windchill PDMlink and PTC FlexPLM. The vulnerability may be exploited through the deserialization of untrusted data.   *  ...&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected Products:&lt;/strong&gt; Multiple systems&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;https://www.yazoul.net/advisory/cve/cve-2026-12569-windchill-rce-exploited-in-the-wild/&quot;&gt;Read the full security advisory on Yazoul Security&lt;/a&gt;&lt;/p&gt;
&lt;hr/&gt;
&lt;p&gt;&lt;em&gt;This advisory is published by &lt;a href=&quot;https://www.yazoul.net/advisory&quot;&gt;Yazoul Security&lt;/a&gt; - Your trusted source for CVE intelligence and remediation guidance.&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;&lt;em&gt;Generated by Yazoul AI, an automated pipeline. Not reviewed by a person before publication.&lt;/em&gt;&lt;/p&gt;</description><pubDate>Thu, 18 Jun 2026 00:00:00 GMT</pubDate><category>critical</category><category>CVE</category><category>Security</category><category>Vulnerability</category><author>Yazoul Security (contact@yazoul.net)</author></item><item><title>CVE-2026-20262: Security Advisory: CVE-2026-20262</title><link>https://www.yazoul.net/advisory/cve/cve-2026-20262-catalyst-sd-wan-manager-actively-exploited/</link><guid isPermaLink="true">https://www.yazoul.net/advisory/cve/cve-2026-20262-catalyst-sd-wan-manager-actively-exploited/</guid><description>&lt;p&gt;&lt;strong&gt;CVE-2026-20262&lt;/strong&gt; - MEDIUM severity (CVSS 6.5)&lt;/p&gt;
&lt;p&gt;A vulnerability in the web UI of Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, could allow an authenticated, remote attacker to create a file or overwrite any file on the filesystem of an af...&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected Products:&lt;/strong&gt; Multiple systems&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;https://www.yazoul.net/advisory/cve/cve-2026-20262-catalyst-sd-wan-manager-actively-exploited/&quot;&gt;Read the full security advisory on Yazoul Security&lt;/a&gt;&lt;/p&gt;
&lt;hr/&gt;
&lt;p&gt;&lt;em&gt;This advisory is published by &lt;a href=&quot;https://www.yazoul.net/advisory&quot;&gt;Yazoul Security&lt;/a&gt; - Your trusted source for CVE intelligence and remediation guidance.&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;&lt;em&gt;Generated by Yazoul AI, an automated pipeline. Not reviewed by a person before publication.&lt;/em&gt;&lt;/p&gt;</description><pubDate>Mon, 15 Jun 2026 00:00:00 GMT</pubDate><category>medium</category><category>CVE</category><category>Security</category><category>Vulnerability</category><author>Yazoul Security (contact@yazoul.net)</author></item><item><title>CVE-2026-54420: Security Advisory: CVE-2026-54420</title><link>https://www.yazoul.net/advisory/cve/cve-2026-54420-litespeed-cpanel-plugin-symlink-attack/</link><guid isPermaLink="true">https://www.yazoul.net/advisory/cve/cve-2026-54420-litespeed-cpanel-plugin-symlink-attack/</guid><description>&lt;p&gt;&lt;strong&gt;CVE-2026-54420&lt;/strong&gt; - HIGH severity (CVSS 8.5)&lt;/p&gt;
&lt;p&gt;LiteSpeed cPanel plugin before 2.4.8 (as distributed in LiteSpeed WHM PlugIn before 5.3.2.0) mishandles symlinks provided by a user with FTP or web shell access on a shared hosting server running Clou...&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected Products:&lt;/strong&gt; Litespeedtech Litespeed Cpanel Plugin, Litespeedtech Litespeed Whm Plugin&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;https://www.yazoul.net/advisory/cve/cve-2026-54420-litespeed-cpanel-plugin-symlink-attack/&quot;&gt;Read the full security advisory on Yazoul Security&lt;/a&gt;&lt;/p&gt;
&lt;hr/&gt;
&lt;p&gt;&lt;em&gt;This advisory is published by &lt;a href=&quot;https://www.yazoul.net/advisory&quot;&gt;Yazoul Security&lt;/a&gt; - Your trusted source for CVE intelligence and remediation guidance.&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;&lt;em&gt;Generated by Yazoul AI, an automated pipeline. Not reviewed by a person before publication.&lt;/em&gt;&lt;/p&gt;</description><pubDate>Sun, 14 Jun 2026 00:00:00 GMT</pubDate><category>high</category><category>CVE</category><category>Security</category><category>Vulnerability</category><category>Litespeedtech Litespeed Cpanel Plugin</category><category>Litespeedtech Litespeed Whm Plugin</category><author>Yazoul Security (contact@yazoul.net)</author></item><item><title>CVE-2026-48558: Security Advisory: CVE-2026-48558</title><link>https://www.yazoul.net/advisory/cve/cve-2026-48558-simplehelp-oidc-auth-bypass-actively-exploited/</link><guid isPermaLink="true">https://www.yazoul.net/advisory/cve/cve-2026-48558-simplehelp-oidc-auth-bypass-actively-exploited/</guid><description>&lt;p&gt;&lt;strong&gt;CVE-2026-48558&lt;/strong&gt; - CRITICAL severity (CVSS 10)&lt;/p&gt;
&lt;p&gt;SimpleHelp versions 5.5.15 and prior and 6.0 pre-release versions contain an authentication bypass vulnerability in the OIDC authentication flow. When OIDC authentication is configured, identity token...&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected Products:&lt;/strong&gt; Multiple systems&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;https://www.yazoul.net/advisory/cve/cve-2026-48558-simplehelp-oidc-auth-bypass-actively-exploited/&quot;&gt;Read the full security advisory on Yazoul Security&lt;/a&gt;&lt;/p&gt;
&lt;hr/&gt;
&lt;p&gt;&lt;em&gt;This advisory is published by &lt;a href=&quot;https://www.yazoul.net/advisory&quot;&gt;Yazoul Security&lt;/a&gt; - Your trusted source for CVE intelligence and remediation guidance.&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;&lt;em&gt;Generated by Yazoul AI, an automated pipeline. Not reviewed by a person before publication.&lt;/em&gt;&lt;/p&gt;</description><pubDate>Fri, 12 Jun 2026 00:00:00 GMT</pubDate><category>critical</category><category>CVE</category><category>Security</category><category>Vulnerability</category><author>Yazoul Security (contact@yazoul.net)</author></item><item><title>CVE-2026-35273: Security Advisory: CVE-2026-35273</title><link>https://www.yazoul.net/advisory/cve/cve-2026-35273-peoplesoft-enterprise-unauth-takeover-poc/</link><guid isPermaLink="true">https://www.yazoul.net/advisory/cve/cve-2026-35273-peoplesoft-enterprise-unauth-takeover-poc/</guid><description>&lt;p&gt;&lt;strong&gt;CVE-2026-35273&lt;/strong&gt; - CRITICAL severity (CVSS 9.8)&lt;/p&gt;
&lt;p&gt;Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Updates Environment Management). Supported versions that are affected are 8.61 and 8.62. Easily exploita...&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected Products:&lt;/strong&gt; Oracle Peoplesoft Enterprise Peopletools&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;https://www.yazoul.net/advisory/cve/cve-2026-35273-peoplesoft-enterprise-unauth-takeover-poc/&quot;&gt;Read the full security advisory on Yazoul Security&lt;/a&gt;&lt;/p&gt;
&lt;hr/&gt;
&lt;p&gt;&lt;em&gt;This advisory is published by &lt;a href=&quot;https://www.yazoul.net/advisory&quot;&gt;Yazoul Security&lt;/a&gt; - Your trusted source for CVE intelligence and remediation guidance.&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;&lt;em&gt;Generated by Yazoul AI, an automated pipeline. Not reviewed by a person before publication.&lt;/em&gt;&lt;/p&gt;</description><pubDate>Thu, 11 Jun 2026 00:00:00 GMT</pubDate><category>critical</category><category>CVE</category><category>Security</category><category>Vulnerability</category><category>Oracle Peoplesoft Enterprise Peopletools</category><author>Yazoul Security (contact@yazoul.net)</author></item><item><title>CVE-2026-10520: Security Advisory: CVE-2026-10520</title><link>https://www.yazoul.net/advisory/cve/cve-2026-10520-ivanti-sentry-rce-actively-exploited-poc/</link><guid isPermaLink="true">https://www.yazoul.net/advisory/cve/cve-2026-10520-ivanti-sentry-rce-actively-exploited-poc/</guid><description>&lt;p&gt;&lt;strong&gt;CVE-2026-10520&lt;/strong&gt; - CRITICAL severity (CVSS 10)&lt;/p&gt;
&lt;p&gt;An OS Command Injection vulnerability in Ivanti Sentry before the R10.5.2, R10.6.2 and R10.7.1 versions allows a remote unauthenticated user to achieve root-level remote code execution...&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected Products:&lt;/strong&gt; Multiple systems&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;https://www.yazoul.net/advisory/cve/cve-2026-10520-ivanti-sentry-rce-actively-exploited-poc/&quot;&gt;Read the full security advisory on Yazoul Security&lt;/a&gt;&lt;/p&gt;
&lt;hr/&gt;
&lt;p&gt;&lt;em&gt;This advisory is published by &lt;a href=&quot;https://www.yazoul.net/advisory&quot;&gt;Yazoul Security&lt;/a&gt; - Your trusted source for CVE intelligence and remediation guidance.&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;&lt;em&gt;Generated by Yazoul AI, an automated pipeline. Not reviewed by a person before publication.&lt;/em&gt;&lt;/p&gt;</description><pubDate>Tue, 09 Jun 2026 00:00:00 GMT</pubDate><category>critical</category><category>CVE</category><category>Security</category><category>Vulnerability</category><author>Yazoul Security (contact@yazoul.net)</author></item><item><title>CVE-2026-11645: Security Advisory: CVE-2026-11645</title><link>https://www.yazoul.net/advisory/cve/cve-2026-11645-chrome-v8-rce-actively-exploited/</link><guid isPermaLink="true">https://www.yazoul.net/advisory/cve/cve-2026-11645-chrome-v8-rce-actively-exploited/</guid><description>&lt;p&gt;&lt;strong&gt;CVE-2026-11645&lt;/strong&gt; - HIGH severity (CVSS 8.8)&lt;/p&gt;
&lt;p&gt;Out of bounds read and write in V8 in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: H...&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected Products:&lt;/strong&gt; Google Chrome, Apple Macos, Linux Kernel, Microsoft Windows&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;https://www.yazoul.net/advisory/cve/cve-2026-11645-chrome-v8-rce-actively-exploited/&quot;&gt;Read the full security advisory on Yazoul Security&lt;/a&gt;&lt;/p&gt;
&lt;hr/&gt;
&lt;p&gt;&lt;em&gt;This advisory is published by &lt;a href=&quot;https://www.yazoul.net/advisory&quot;&gt;Yazoul Security&lt;/a&gt; - Your trusted source for CVE intelligence and remediation guidance.&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;&lt;em&gt;Generated by Yazoul AI, an automated pipeline. Not reviewed by a person before publication.&lt;/em&gt;&lt;/p&gt;</description><pubDate>Tue, 09 Jun 2026 00:00:00 GMT</pubDate><category>high</category><category>CVE</category><category>Security</category><category>Vulnerability</category><category>Google Chrome</category><category>Apple Macos</category><category>Linux Kernel</category><author>Yazoul Security (contact@yazoul.net)</author></item><item><title>CVE-2026-25089: Security Advisory: CVE-2026-25089</title><link>https://www.yazoul.net/advisory/cve/cve-2026-25089-fortisandbox-unauth-rce-poc/</link><guid isPermaLink="true">https://www.yazoul.net/advisory/cve/cve-2026-25089-fortisandbox-unauth-rce-poc/</guid><description>&lt;p&gt;&lt;strong&gt;CVE-2026-25089&lt;/strong&gt; - CRITICAL severity (CVSS 9.8)&lt;/p&gt;
&lt;p&gt;A improper neutralization of special elements used in an os command (&apos;os command injection&apos;) vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.5, FortiSandbox 4.4.0 through 4.4.8, FortiSandbox ...&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected Products:&lt;/strong&gt; Multiple systems&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;https://www.yazoul.net/advisory/cve/cve-2026-25089-fortisandbox-unauth-rce-poc/&quot;&gt;Read the full security advisory on Yazoul Security&lt;/a&gt;&lt;/p&gt;
&lt;hr/&gt;
&lt;p&gt;&lt;em&gt;This advisory is published by &lt;a href=&quot;https://www.yazoul.net/advisory&quot;&gt;Yazoul Security&lt;/a&gt; - Your trusted source for CVE intelligence and remediation guidance.&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;&lt;em&gt;Generated by Yazoul AI, an automated pipeline. Not reviewed by a person before publication.&lt;/em&gt;&lt;/p&gt;</description><pubDate>Tue, 09 Jun 2026 00:00:00 GMT</pubDate><category>critical</category><category>CVE</category><category>Security</category><category>Vulnerability</category><author>Yazoul Security (contact@yazoul.net)</author></item><item><title>CVE-2026-50751: Security Advisory: CVE-2026-50751</title><link>https://www.yazoul.net/advisory/cve/cve-2026-50751-remote-access-vpn-bypass-exploited-in-wild-poc/</link><guid isPermaLink="true">https://www.yazoul.net/advisory/cve/cve-2026-50751-remote-access-vpn-bypass-exploited-in-wild-poc/</guid><description>&lt;p&gt;&lt;strong&gt;CVE-2026-50751&lt;/strong&gt; - CRITICAL severity (CVSS 9.3)&lt;/p&gt;
&lt;p&gt;A logic flow weakness in Remote Access and Mobile Access certificate validation in deprecated IKEv1 key exchange allows an unauthenticated remote attacker to bypass user authentication and establish a...&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected Products:&lt;/strong&gt; Multiple systems&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;https://www.yazoul.net/advisory/cve/cve-2026-50751-remote-access-vpn-bypass-exploited-in-wild-poc/&quot;&gt;Read the full security advisory on Yazoul Security&lt;/a&gt;&lt;/p&gt;
&lt;hr/&gt;
&lt;p&gt;&lt;em&gt;This advisory is published by &lt;a href=&quot;https://www.yazoul.net/advisory&quot;&gt;Yazoul Security&lt;/a&gt; - Your trusted source for CVE intelligence and remediation guidance.&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;&lt;em&gt;Generated by Yazoul AI, an automated pipeline. Not reviewed by a person before publication.&lt;/em&gt;&lt;/p&gt;</description><pubDate>Mon, 08 Jun 2026 00:00:00 GMT</pubDate><category>critical</category><category>CVE</category><category>Security</category><category>Vulnerability</category><author>Yazoul Security (contact@yazoul.net)</author></item><item><title>CVE-2026-48907: Security Advisory: CVE-2026-48907</title><link>https://www.yazoul.net/advisory/cve/cve-2026-48907-jce-editor-unauth-rce-exploited-poc/</link><guid isPermaLink="true">https://www.yazoul.net/advisory/cve/cve-2026-48907-jce-editor-unauth-rce-exploited-poc/</guid><description>&lt;p&gt;&lt;strong&gt;CVE-2026-48907&lt;/strong&gt; - CRITICAL severity (CVSS 10)&lt;/p&gt;
&lt;p&gt;A vulnerability in the JCE editor extension for Joomla allows the creation of new editor profiles for unauthenticated users, ultimately resulting in PHP code upload and execution....&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected Products:&lt;/strong&gt; Multiple systems&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;https://www.yazoul.net/advisory/cve/cve-2026-48907-jce-editor-unauth-rce-exploited-poc/&quot;&gt;Read the full security advisory on Yazoul Security&lt;/a&gt;&lt;/p&gt;
&lt;hr/&gt;
&lt;p&gt;&lt;em&gt;This advisory is published by &lt;a href=&quot;https://www.yazoul.net/advisory&quot;&gt;Yazoul Security&lt;/a&gt; - Your trusted source for CVE intelligence and remediation guidance.&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;&lt;em&gt;Generated by Yazoul AI, an automated pipeline. Not reviewed by a person before publication.&lt;/em&gt;&lt;/p&gt;</description><pubDate>Fri, 05 Jun 2026 00:00:00 GMT</pubDate><category>critical</category><category>CVE</category><category>Security</category><category>Vulnerability</category><author>Yazoul Security (contact@yazoul.net)</author></item><item><title>CVE-2026-7473: Security Advisory: CVE-2026-7473</title><link>https://www.yazoul.net/advisory/cve/cve-2026-7473-arista-eos-tunnel-decap-bypass/</link><guid isPermaLink="true">https://www.yazoul.net/advisory/cve/cve-2026-7473-arista-eos-tunnel-decap-bypass/</guid><description>&lt;p&gt;&lt;strong&gt;CVE-2026-7473&lt;/strong&gt; - MEDIUM severity (CVSS 6.9)&lt;/p&gt;
&lt;p&gt;On affected platforms running Arista EOS where a tunnel decapsulation configuration—such as VXLAN (Virtual Extensible LAN), decap-groups, or a GRE (Generic Routing Encapsulation) tunnel interface—is p...&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected Products:&lt;/strong&gt; Arista Eos, Arista 7020Sr-24C2, Arista 7020Sr-32C2, Arista 7020Srg-24C2, Arista 7020Tr-48&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;https://www.yazoul.net/advisory/cve/cve-2026-7473-arista-eos-tunnel-decap-bypass/&quot;&gt;Read the full security advisory on Yazoul Security&lt;/a&gt;&lt;/p&gt;
&lt;hr/&gt;
&lt;p&gt;&lt;em&gt;This advisory is published by &lt;a href=&quot;https://www.yazoul.net/advisory&quot;&gt;Yazoul Security&lt;/a&gt; - Your trusted source for CVE intelligence and remediation guidance.&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;&lt;em&gt;Generated by Yazoul AI, an automated pipeline. Not reviewed by a person before publication.&lt;/em&gt;&lt;/p&gt;</description><pubDate>Fri, 05 Jun 2026 00:00:00 GMT</pubDate><category>medium</category><category>CVE</category><category>Security</category><category>Vulnerability</category><category>Arista Eos</category><category>Arista 7020Sr-24C2</category><category>Arista 7020Sr-32C2</category><author>Yazoul Security (contact@yazoul.net)</author></item><item><title>CVE-2026-20245: Security Advisory: CVE-2026-20245</title><link>https://www.yazoul.net/advisory/cve/cve-2026-20245-cisco-sd-wan-cli-rce-actively-exploited-poc/</link><guid isPermaLink="true">https://www.yazoul.net/advisory/cve/cve-2026-20245-cisco-sd-wan-cli-rce-actively-exploited-poc/</guid><description>&lt;p&gt;&lt;strong&gt;CVE-2026-20245&lt;/strong&gt; - HIGH severity (CVSS 7.8)&lt;/p&gt;
&lt;p&gt;A vulnerability in the CLI of Cisco Catalyst SD-WAN Controller, formerly SD-WAN vSmart, Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, and Cisco Catalyst SD-WAN Validator, formerly SD-WAN vBo...&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected Products:&lt;/strong&gt; Multiple systems&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;https://www.yazoul.net/advisory/cve/cve-2026-20245-cisco-sd-wan-cli-rce-actively-exploited-poc/&quot;&gt;Read the full security advisory on Yazoul Security&lt;/a&gt;&lt;/p&gt;
&lt;hr/&gt;
&lt;p&gt;&lt;em&gt;This advisory is published by &lt;a href=&quot;https://www.yazoul.net/advisory&quot;&gt;Yazoul Security&lt;/a&gt; - Your trusted source for CVE intelligence and remediation guidance.&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;&lt;em&gt;Generated by Yazoul AI, an automated pipeline. Not reviewed by a person before publication.&lt;/em&gt;&lt;/p&gt;</description><pubDate>Thu, 04 Jun 2026 00:00:00 GMT</pubDate><category>high</category><category>CVE</category><category>Security</category><category>Vulnerability</category><author>Yazoul Security (contact@yazoul.net)</author></item><item><title>CVE-2026-28318: Security Advisory: CVE-2026-28318</title><link>https://www.yazoul.net/advisory/cve/cve-2026-28318-serv-u-crash-via-unauth-post/</link><guid isPermaLink="true">https://www.yazoul.net/advisory/cve/cve-2026-28318-serv-u-crash-via-unauth-post/</guid><description>&lt;p&gt;&lt;strong&gt;CVE-2026-28318&lt;/strong&gt; - HIGH severity (CVSS 7.5)&lt;/p&gt;
&lt;p&gt;SolarWinds Serv-U is susceptible to specially crafted POST requests that crash the Serv-U service without authentication using Content-Encoding: deflate. Mitigation steps are provided to secure custom...&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected Products:&lt;/strong&gt; Solarwinds Serv-U&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;https://www.yazoul.net/advisory/cve/cve-2026-28318-serv-u-crash-via-unauth-post/&quot;&gt;Read the full security advisory on Yazoul Security&lt;/a&gt;&lt;/p&gt;
&lt;hr/&gt;
&lt;p&gt;&lt;em&gt;This advisory is published by &lt;a href=&quot;https://www.yazoul.net/advisory&quot;&gt;Yazoul Security&lt;/a&gt; - Your trusted source for CVE intelligence and remediation guidance.&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;&lt;em&gt;Generated by Yazoul AI, an automated pipeline. Not reviewed by a person before publication.&lt;/em&gt;&lt;/p&gt;</description><pubDate>Thu, 04 Jun 2026 00:00:00 GMT</pubDate><category>high</category><category>CVE</category><category>Security</category><category>Vulnerability</category><category>Solarwinds Serv-U</category><author>Yazoul Security (contact@yazoul.net)</author></item><item><title>CVE-2026-8037: Security Advisory: CVE-2026-8037</title><link>https://www.yazoul.net/advisory/cve/cve-2026-8037-progress-adc-exploited-for-unauthenticated-rce-poc/</link><guid isPermaLink="true">https://www.yazoul.net/advisory/cve/cve-2026-8037-progress-adc-exploited-for-unauthenticated-rce-poc/</guid><description>&lt;p&gt;&lt;strong&gt;CVE-2026-8037&lt;/strong&gt; - CRITICAL severity (CVSS 9.8)&lt;/p&gt;
&lt;p&gt;OS Command Injection Remote Code Execution Vulnerability in API in Progress ADC Products allows an un-authenticated attacker to execute arbitrary commands on the LoadMaster appliance by exploiting uns...&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected Products:&lt;/strong&gt; Progress Connection Manager For Objectscale, Progress Ecs Connection Manager, Progress Loadmaster&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;https://www.yazoul.net/advisory/cve/cve-2026-8037-progress-adc-exploited-for-unauthenticated-rce-poc/&quot;&gt;Read the full security advisory on Yazoul Security&lt;/a&gt;&lt;/p&gt;
&lt;hr/&gt;
&lt;p&gt;&lt;em&gt;This advisory is published by &lt;a href=&quot;https://www.yazoul.net/advisory&quot;&gt;Yazoul Security&lt;/a&gt; - Your trusted source for CVE intelligence and remediation guidance.&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;&lt;em&gt;Generated by Yazoul AI, an automated pipeline. Not reviewed by a person before publication.&lt;/em&gt;&lt;/p&gt;</description><pubDate>Thu, 04 Jun 2026 00:00:00 GMT</pubDate><category>critical</category><category>CVE</category><category>Security</category><category>Vulnerability</category><category>Progress Connection Manager For Objectscale</category><category>Progress Ecs Connection Manager</category><category>Progress Loadmaster</category><author>Yazoul Security (contact@yazoul.net)</author></item><item><title>CVE-2026-20230: Security Advisory: CVE-2026-20230</title><link>https://www.yazoul.net/advisory/cve/cve-2026-20230-cisco-ssrf-writes-files-to-root-poc/</link><guid isPermaLink="true">https://www.yazoul.net/advisory/cve/cve-2026-20230-cisco-ssrf-writes-files-to-root-poc/</guid><description>&lt;p&gt;&lt;strong&gt;CVE-2026-20230&lt;/strong&gt; - HIGH severity (CVSS 8.6)&lt;/p&gt;
&lt;p&gt;A vulnerability in Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communications Manager Session Management Edition (Unified CM SME) could allow an unauthenticated, remote attacke...&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected Products:&lt;/strong&gt; Multiple systems&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;https://www.yazoul.net/advisory/cve/cve-2026-20230-cisco-ssrf-writes-files-to-root-poc/&quot;&gt;Read the full security advisory on Yazoul Security&lt;/a&gt;&lt;/p&gt;
&lt;hr/&gt;
&lt;p&gt;&lt;em&gt;This advisory is published by &lt;a href=&quot;https://www.yazoul.net/advisory&quot;&gt;Yazoul Security&lt;/a&gt; - Your trusted source for CVE intelligence and remediation guidance.&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;&lt;em&gt;Generated by Yazoul AI, an automated pipeline. Not reviewed by a person before publication.&lt;/em&gt;&lt;/p&gt;</description><pubDate>Wed, 03 Jun 2026 00:00:00 GMT</pubDate><category>high</category><category>CVE</category><category>Security</category><category>Vulnerability</category><author>Yazoul Security (contact@yazoul.net)</author></item><item><title>CVE-2025-48595: Security Advisory: CVE-2025-48595</title><link>https://www.yazoul.net/advisory/cve/cve-2025-48595-android-local-code-exec-exploited-in-the-wild/</link><guid isPermaLink="true">https://www.yazoul.net/advisory/cve/cve-2025-48595-android-local-code-exec-exploited-in-the-wild/</guid><description>&lt;p&gt;&lt;strong&gt;CVE-2025-48595&lt;/strong&gt; - HIGH severity (CVSS 8.4)&lt;/p&gt;
&lt;p&gt;In multiple locations, there is a possible way to achieve code execution due to an integer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. Us...&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected Products:&lt;/strong&gt; Multiple systems&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;https://www.yazoul.net/advisory/cve/cve-2025-48595-android-local-code-exec-exploited-in-the-wild/&quot;&gt;Read the full security advisory on Yazoul Security&lt;/a&gt;&lt;/p&gt;
&lt;hr/&gt;
&lt;p&gt;&lt;em&gt;This advisory is published by &lt;a href=&quot;https://www.yazoul.net/advisory&quot;&gt;Yazoul Security&lt;/a&gt; - Your trusted source for CVE intelligence and remediation guidance.&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;&lt;em&gt;Generated by Yazoul AI, an automated pipeline. Not reviewed by a person before publication.&lt;/em&gt;&lt;/p&gt;</description><pubDate>Mon, 01 Jun 2026 00:00:00 GMT</pubDate><category>high</category><category>CVE</category><category>Security</category><category>Vulnerability</category><author>Yazoul Security (contact@yazoul.net)</author></item><item><title>CVE-2026-46817: Security Advisory: CVE-2026-46817</title><link>https://www.yazoul.net/advisory/cve/cve-2026-46817-oracle-e-business-suite-takeover-poc/</link><guid isPermaLink="true">https://www.yazoul.net/advisory/cve/cve-2026-46817-oracle-e-business-suite-takeover-poc/</guid><description>&lt;p&gt;&lt;strong&gt;CVE-2026-46817&lt;/strong&gt; - CRITICAL severity (CVSS 9.8)&lt;/p&gt;
&lt;p&gt;Vulnerability in the Oracle Payments product of Oracle E-Business Suite (component: File Transmission).  Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allow...&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected Products:&lt;/strong&gt; Oracle E-Business Suite&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;https://www.yazoul.net/advisory/cve/cve-2026-46817-oracle-e-business-suite-takeover-poc/&quot;&gt;Read the full security advisory on Yazoul Security&lt;/a&gt;&lt;/p&gt;
&lt;hr/&gt;
&lt;p&gt;&lt;em&gt;This advisory is published by &lt;a href=&quot;https://www.yazoul.net/advisory&quot;&gt;Yazoul Security&lt;/a&gt; - Your trusted source for CVE intelligence and remediation guidance.&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;&lt;em&gt;Generated by Yazoul AI, an automated pipeline. Not reviewed by a person before publication.&lt;/em&gt;&lt;/p&gt;</description><pubDate>Thu, 28 May 2026 00:00:00 GMT</pubDate><category>critical</category><category>CVE</category><category>Security</category><category>Vulnerability</category><category>Oracle E-Business Suite</category><author>Yazoul Security (contact@yazoul.net)</author></item><item><title>CVE-2026-44590: Security Advisory: CVE-2026-44590</title><link>https://www.yazoul.net/advisory/cve/cve-2026-44590-sherlock-leaks-ci-tokens-via-command-inj-poc/</link><guid isPermaLink="true">https://www.yazoul.net/advisory/cve/cve-2026-44590-sherlock-leaks-ci-tokens-via-command-inj-poc/</guid><description>&lt;p&gt;&lt;strong&gt;CVE-2026-44590&lt;/strong&gt; - CRITICAL severity (CVSS 9.3)&lt;/p&gt;
&lt;p&gt;Sherlock hunts down social media accounts by username across social networks. Prior to 0.16.1, the GitHub Actions workflow validate_modified_targets.yml is vulnerable to command injection via the pull...&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected Products:&lt;/strong&gt; Multiple systems&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;https://www.yazoul.net/advisory/cve/cve-2026-44590-sherlock-leaks-ci-tokens-via-command-inj-poc/&quot;&gt;Read the full security advisory on Yazoul Security&lt;/a&gt;&lt;/p&gt;
&lt;hr/&gt;
&lt;p&gt;&lt;em&gt;This advisory is published by &lt;a href=&quot;https://www.yazoul.net/advisory&quot;&gt;Yazoul Security&lt;/a&gt; - Your trusted source for CVE intelligence and remediation guidance.&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;&lt;em&gt;Generated by Yazoul AI, an automated pipeline. Not reviewed by a person before publication.&lt;/em&gt;&lt;/p&gt;</description><pubDate>Wed, 27 May 2026 00:00:00 GMT</pubDate><category>critical</category><category>CVE</category><category>Security</category><category>Vulnerability</category><author>Yazoul Security (contact@yazoul.net)</author></item><item><title>CVE-2026-48027: Security Advisory: CVE-2026-48027</title><link>https://www.yazoul.net/advisory/cve/cve-2026-48027-nx-console-supply-chain-attack-actively-exploited/</link><guid isPermaLink="true">https://www.yazoul.net/advisory/cve/cve-2026-48027-nx-console-supply-chain-attack-actively-exploited/</guid><description>&lt;p&gt;&lt;strong&gt;CVE-2026-48027&lt;/strong&gt; - CRITICAL severity (CVSS 9.8)&lt;/p&gt;
&lt;p&gt;Nx Console is the user interface for Nx &amp; Lerna. On 19 May 2026, a malicious version of Nx Console, 18.95.0, was published at 12:30 PM UTC and removed soon after at 12:48 PM UTC, leaving it available ...&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected Products:&lt;/strong&gt; Nx Console&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;https://www.yazoul.net/advisory/cve/cve-2026-48027-nx-console-supply-chain-attack-actively-exploited/&quot;&gt;Read the full security advisory on Yazoul Security&lt;/a&gt;&lt;/p&gt;
&lt;hr/&gt;
&lt;p&gt;&lt;em&gt;This advisory is published by &lt;a href=&quot;https://www.yazoul.net/advisory&quot;&gt;Yazoul Security&lt;/a&gt; - Your trusted source for CVE intelligence and remediation guidance.&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;&lt;em&gt;Generated by Yazoul AI, an automated pipeline. Not reviewed by a person before publication.&lt;/em&gt;&lt;/p&gt;</description><pubDate>Wed, 27 May 2026 00:00:00 GMT</pubDate><category>critical</category><category>CVE</category><category>Security</category><category>Vulnerability</category><category>Nx Console</category><author>Yazoul Security (contact@yazoul.net)</author></item><item><title>CVE-2026-45247: Security Advisory: CVE-2026-45247</title><link>https://www.yazoul.net/advisory/cve/cve-2026-45247-mirasvit-fpc-warmer-rce-exploited-in-wild/</link><guid isPermaLink="true">https://www.yazoul.net/advisory/cve/cve-2026-45247-mirasvit-fpc-warmer-rce-exploited-in-wild/</guid><description>&lt;p&gt;&lt;strong&gt;CVE-2026-45247&lt;/strong&gt; - CRITICAL severity (CVSS 9.8)&lt;/p&gt;
&lt;p&gt;Mirasvit Full Page Cache Warmer for Magento 2 before version 1.11.12 contains a PHP object injection vulnerability that allows unauthenticated attackers to achieve remote code execution by supplying a...&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected Products:&lt;/strong&gt; Multiple systems&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;https://www.yazoul.net/advisory/cve/cve-2026-45247-mirasvit-fpc-warmer-rce-exploited-in-wild/&quot;&gt;Read the full security advisory on Yazoul Security&lt;/a&gt;&lt;/p&gt;
&lt;hr/&gt;
&lt;p&gt;&lt;em&gt;This advisory is published by &lt;a href=&quot;https://www.yazoul.net/advisory&quot;&gt;Yazoul Security&lt;/a&gt; - Your trusted source for CVE intelligence and remediation guidance.&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;&lt;em&gt;Generated by Yazoul AI, an automated pipeline. Not reviewed by a person before publication.&lt;/em&gt;&lt;/p&gt;</description><pubDate>Tue, 26 May 2026 00:00:00 GMT</pubDate><category>critical</category><category>CVE</category><category>Security</category><category>Vulnerability</category><author>Yazoul Security (contact@yazoul.net)</author></item><item><title>CVE-2026-45659: Security Advisory: CVE-2026-45659</title><link>https://www.yazoul.net/advisory/cve/cve-2026-45659-sharepoint-rce-exploited-in-the-wild-poc/</link><guid isPermaLink="true">https://www.yazoul.net/advisory/cve/cve-2026-45659-sharepoint-rce-exploited-in-the-wild-poc/</guid><description>&lt;p&gt;&lt;strong&gt;CVE-2026-45659&lt;/strong&gt; - HIGH severity (CVSS 8.8)&lt;/p&gt;
&lt;p&gt;Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network....&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected Products:&lt;/strong&gt; Microsoft Sharepoint Server&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;https://www.yazoul.net/advisory/cve/cve-2026-45659-sharepoint-rce-exploited-in-the-wild-poc/&quot;&gt;Read the full security advisory on Yazoul Security&lt;/a&gt;&lt;/p&gt;
&lt;hr/&gt;
&lt;p&gt;&lt;em&gt;This advisory is published by &lt;a href=&quot;https://www.yazoul.net/advisory&quot;&gt;Yazoul Security&lt;/a&gt; - Your trusted source for CVE intelligence and remediation guidance.&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;&lt;em&gt;Generated by Yazoul AI, an automated pipeline. Not reviewed by a person before publication.&lt;/em&gt;&lt;/p&gt;</description><pubDate>Fri, 22 May 2026 00:00:00 GMT</pubDate><category>high</category><category>CVE</category><category>Security</category><category>Vulnerability</category><category>Microsoft Sharepoint Server</category><author>Yazoul Security (contact@yazoul.net)</author></item></channel></rss>