NVD / NIST CVE
Aug 3, 2026
A security flaw has been discovered in langgenius dify up to 1.14.2. This issue affects the function jinja2.Template of the file api/core/helper/code_executor/jinja2/jinja2_transformer.py of the component Jinja2 Handler. The manipulation results in improper neutralization of special elements used in a template engine. The attack may be launched …
NVD / NIST CVE
Aug 3, 2026
A vulnerability was determined in Sangfor Operation and Maintenance Security Management System up to 3.0.13. Affected by this vulnerability is the function com.sbr.fort.foreignDP.DpLoginController of the file /fort/portal_login of the component Login Endpoint. This manipulation causes os command injection. The attack can be initiated remotely. T…
Bleeping Computer
Aug 3, 2026
A new Russian loader-as-a-service named DOUBLECUP uses ClickFix attacks to hide malicious code in PNG images cached by victims' browsers, ultimately delivering CountLoader to Windows and macOS devices and a new remote access trojan named DeviceManager to Windows systems. [...]
Bleeping Computer
Aug 3, 2026
Fake Xeno Executor installers are infecting unsuspecting Roblox players with malware that provides remote access and steals sensitive information. [...]
NVD / NIST CVE
Aug 3, 2026
Dell Display and Peripheral Manager (DDPM Mac), versions prior to 2.3.0.1005, contain an Improper Access Control vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of privileges and arbitrary code execution.
NVD / NIST CVE
Aug 3, 2026
Dell Display and Peripheral Manager (DDPM Mac), versions prior to 2.3.0.1005, contain a Missing Authentication for Critical Function vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of privileges.
NVD / NIST CVE
Aug 3, 2026
osTicket v1.18.3 is vulnerable to Stored Cross-Site Scripting (XSS) via the email From-header display name. The value is extracted without sanitization in include/class.mailparse.php and stored raw in the poster field of ost_thread_entry. When an unauthenticated attacker sends a reply email to an existing ticket from an unregistered address with…
NVD / NIST CVE
Aug 3, 2026
A stored cross-site scripting (XSS) vulnerability exists in osTicket 1.18.3 due to improper sanitization of the thread entry title field. User-controlled input in the title is stored without adequate HTML escaping and later rendered in multiple staff-facing templates without proper output encoding. An attacker can inject arbitrary JavaScript by …
NVD / NIST CVE
Aug 3, 2026
osTicket 1.18.3 generates API keys using a predictable construction based on MD5 hashing. The use of MD5, combined with predictable inputs such as the current timestamp and client IP address, significantly reduces entropy. An attacker can approximate the key generation time and brute-force the key space within a feasible time window.
NVD / NIST CVE
Aug 3, 2026
A vulnerability was found in GL-iNet GL-MT3000 up to 4.4.5. Impacted is the function s2s.enable_echo_server of the file /cgi-bin/glc of the component s2s.so Native Plugin. Performing a manipulation of the argument port results in command injection. The attack may be initiated remotely. The exploit has been made public and could be used. The vend…
NVD / NIST CVE
Aug 3, 2026
A vulnerability was determined in GL-iNet GL-MT3000 up to 4.4.5. The affected element is the function wg-server.generate_publickey of the file /cgi-bin/glc of the component wg-server.so Native Plugin. Executing a manipulation of the argument private_key can lead to command injection. The attack may be launched remotely. The exploit has been publ…
NVD / NIST CVE
Aug 3, 2026
A vulnerability was identified in GL-iNet GL-MT3000 up to 4.4.5. The impacted element is the function server.set_peer of the file /cgi-bin/glc of the component wg-server.so Native Plugin. The manipulation of the argument public_key leads to command injection. Remote exploitation of the attack is possible. The exploit is publicly available and mi…
NVD / NIST CVE
Aug 3, 2026
A
cryptographic weakness exists in affected Omada devices where site credentials
are protected using a legacy hashing algorithm that does not provide sufficient
protection.
An attacker
who obtains access to stored credential data may be able to recover valid credentials
to gain unauthorized access to affected devices or management envir…
NVD / NIST CVE
Aug 3, 2026
A cryptographic
weakness exists in the Omada adoption protocol.
The protocol relies on hard-coded cryptographic keys to establish trust and
protect authentication exchanges between controllers and managed devices during
device adoption.
An attacker may
be able to impersonate trusted controllers or managed devices and gain access
to se…
NVD / NIST CVE
Aug 3, 2026
Affected
Omada devices rely on embedded certificates that are shared across deployments
to establish trust between controllers and managed devices.
An attacker
who obtains the embedded certificates may be able to impersonate trusted
controllers or devices and intercept affected communications.
NVD / NIST CVE
Aug 3, 2026
A cryptographic
weakness exists in the Omada adoption protocol where session encryption keys
used to protect communications between controllers and managed devices may be
predictable due to insufficient entropy in session key generation.
An attacker
who successfully intercepts adoption-related communications may be able to recover
sessi…
NVD / NIST CVE
Aug 3, 2026
A race
condition exists in the cloud-based Omada device adoption process when an
attacker may be able to interact with the adoption workflow before a legitimate
device completes registration, resulting in provisioning information being
delivered to an attacker.
Successful
exploitation may allow disclosure of provisioning information int…
NVD / NIST CVE
Aug 3, 2026
A cryptographic
weakness exists in the Omada device adoption process. During adoption, authentication credentials associated
with site management are transmitted using a weak hashing algorithm that does
not provide sufficient protection.
An attacker who
successfully intercepts adoption-related authentication traffic may be able to
re…
The Hacker News
Aug 3, 2026
Cybersecurity researchers have discovered a new set of malicious npm packages that target users of Alibaba developer tools with a cross-platform remote access trojan (RAT) as part of a sophisticated, targeted software supply chain attack targeting Chinese-speaking environments.
One of the packages in question is "lib-mtop," an unscoped package …
NVD / NIST CVE
Aug 3, 2026
WebsiteBaker CMS before 2.13.10 contains a code injection vulnerability in the Droplets editor that allows authenticated administrators to inject arbitrary PHP code by submitting malicious content through the droplet Code field, which is written verbatim to a publicly accessible PHP file with no content sanitization. Attackers can save a PHP web…