DMZ//THREAT INTEL
FEED ACTIVELAST SYNC: 05:07:52ZSOURCES: 14CRITICAL: 34
⚠ ACTIVE ALERTS
@AlvieriD CRITICAL — CORRELATED | Actor '888' listing on PwnForums: claims 35GB of Accenture source code,… /// @DarkWebInformer CRITICAL — CORRELATED | Prinz Eugen ransomware operation — actor ROOTBOY (aka avtokz / GERMANIA)… /// @MalwareHunterTeam CRITICAL — CORRELATED | PolinRider (DPRK / Famous Chollima / Contagious Interview) supply chain… /// @GossiTheDog CRITICAL — CORRELATED | CVE-2026-8037 Progress Kemp LoadMaster pre-auth RCE — exploitation attempts… /// @FalconFeedsio CRITICAL — CORRELATED | Tracking '888' forum listing for Accenture data (July 6, 2026). Dataset:…
34Critical Threats
19Active CVEs
10IOCs Tracked
7New Advisories
SHOWING 50 OF 50
34CRITICAL
13HIGH
3MEDIUM
0LOW
26KEV LISTED
1NO PATCH
CVE IDVULNERABILITYVENDORCVSSSEVERITYPATCHEXPLOITPUBLISHED
CVE-2026-50746Ubiquiti UniFi Connect Application Improper Access Control / Command InjectionUbiquiti10CRITICALAVAILABLENONE2026-07-02
CVE-2026-48286Adobe Campaign Classic Incorrect Authorization Unauthenticated RCEAdobe10CRITICALAVAILABLENONE2026-07-01
CVE-2026-48282KEVAdobe ColdFusion RDS Path Traversal / Unauthenticated RCEAdobe10CRITICALAVAILABLEPUBLIC2026-06-30
CVE-2026-48908KEVJoomShaper SP Page Builder Unauthenticated File Upload / RCE (Zero-Day)JoomShaper10CRITICALAVAILABLEPUBLIC2026-06-20
CVE-2026-56290KEVJoomlack Page Builder CK Unauthenticated Arbitrary File Upload / RCEJoomlack10CRITICALAVAILABLEPUBLIC2026-07-07
CVE-2026-48558KEVSimpleHelp RMM OIDC Authentication BypassSimpleHelp10CRITICALAVAILABLELIMITED2026-06-05
CVE-2026-34908KEVUbiquiti UniFi OS NGINX Auth Bypass + Command Injection Chain (CVSS 10.0 Trio)Ubiquiti10CRITICALAVAILABLEPUBLIC2026-05-22
CVE-2026-34910KEVUbiquiti UniFi OS Unauthenticated RCE Chain (Command Injection)Ubiquiti10CRITICALAVAILABLEPUBLIC2026-05-21
CVE-2026-48907KEVJoomla JCE Editor Unauthenticated RCE via Profile ImportWidget Factory10CRITICALAVAILABLEPUBLIC2026-06-03
CVE-2026-10520KEVIvanti Sentry Pre-Auth OS Command Injection Root RCEIvanti10CRITICALAVAILABLEPUBLIC2026-06-09
CVE-2026-10523Ivanti Sentry Pre-Auth Authentication Bypass — Arbitrary Admin Account CreationIvanti9.9CRITICALAVAILABLEPOC2026-06-09
CVE-2026-53359Januscape Linux KVM x86 Guest-to-Host Escape (Use-After-Free)Linux9.9CRITICALAVAILABLEPOC2026-07-06
CVE-2026-44748SAP NetWeaver SAML XML Signature Wrapping Authentication BypassSAP9.9CRITICALAVAILABLENONE2026-06-09
CVE-2026-48939KEViCagenda Joomla Extension Unauthenticated Arbitrary File Upload RCEicagenda.com (JoomliC)9.8CRITICALAVAILABLEPUBLIC2026-06-20
CVE-2026-56291KEVBalbooa Forms Joomla Extension Unauthenticated File Upload RCE (Zero-Day)Balbooa9.8CRITICALAVAILABLELIMITED2026-07-09
CVE-2026-20896Gitea Docker Reverse-Proxy Authentication BypassGitea9.8CRITICALAVAILABLEPUBLIC2026-07-03
CVE-2026-12569KEVPTC Windchill / FlexPLM Unauthenticated RCE via DeserializationPTC9.8CRITICALAVAILABLELIMITED2026-06-18
CVE-2025-67038KEVLantronix EDS5000 Unauthenticated OS Command Injection (BRIDGE:BREAK)Lantronix9.8CRITICALAVAILABLEPUBLIC2026-04-01
CVE-2026-20253KEVSplunk Enterprise Pre-Auth RCE via PostgreSQL Sidecar Missing AuthenticationSplunk (Cisco)9.8CRITICALAVAILABLEPUBLIC2026-06-10
CVE-2026-35273KEVOracle PeopleSoft PeopleTools Unauthenticated RCE (ShinyHunters Zero-Day)Oracle9.8CRITICALPARTIALLIMITED2026-06-10
CVE-2026-25089Fortinet FortiSandbox Unauthenticated OS Command InjectionFortinet9.8CRITICALAVAILABLEPOC2026-06-09
CVE-2026-26142Nuance PowerScribe Deserialization of Untrusted Data RCE (Healthcare Critical)Microsoft / Nuance9.8CRITICALAVAILABLENONE2026-06-09
CVE-2026-45657Windows Kernel Use-After-Free Remote Code Execution (Wormable)Microsoft9.8CRITICALAVAILABLENONE2026-06-09
CVE-2026-47291Windows HTTP.sys Unauthenticated RCE via Integer/Heap OverflowMicrosoft9.8CRITICALAVAILABLEPOC2026-06-10
CVE-2026-44815Windows DHCP Client Service Unauthenticated Stack-Based Buffer Overflow RCEMicrosoft9.8CRITICALAVAILABLENONE2026-06-10
CVE-2026-27671SAP NetWeaver ABAP Kernel Unauthenticated Memory Corruption RCESAP9.8CRITICALAVAILABLENONE2026-06-09
CVE-2026-8732WP Maps Pro Unauthenticated Admin Account CreationWP Maps Pro (Envato/CodeCanyon)9.8CRITICALAVAILABLEPUBLIC2026-05-29
CVE-2026-45321KEVTanStack Router Supply Chain – Credential-Stealing npm MalwareTanStack9.8CRITICALAVAILABLEPUBLIC2026-05-27
CVE-2026-59792JetBrains IntelliJ IDEA Path Traversal Code Execution via Project Workspace IDJetBrains9.6CRITICALAVAILABLENONE2026-07-10
CVE-2026-11634Google Chrome Gamepad Use-After-Free Sandbox Escape (Windows)Google9.6CRITICALAVAILABLENONE2026-06-08
CVE-2026-11697Google Chrome UI Untrusted Input Validation Sandbox EscapeGoogle9.6CRITICALAVAILABLENONE2026-06-08
CVE-2026-50751KEVCheck Point VPN IKEv1 Authentication Bypass Zero-DayCheck Point9.3CRITICALAVAILABLELIMITED2026-06-08
CVE-2026-48027KEVNx Console VS Code Extension Embedded Malicious Code (Supply Chain)Nrwl / Nx9.3CRITICALAVAILABLEPUBLIC2026-05-29
CVE-2026-42530F5 NGINX HTTP/3 QPACK Use-After-Free RCE (NGINX Rift Follow-On)F5 / NGINX9.2CRITICALAVAILABLENONE2026-06-17
CVE-PENDING-ZIMBRA-2026Zimbra Collaboration Classic Web Client Critical Stored XSS (No CVE Assigned Yet)Zimbra (Synacor)8.8HIGHAVAILABLENONE2026-07-11
CVE-2026-43503Linux Kernel 'DirtyClone' LPE via Cloned Packet Page-Cache Write (DirtyFrag Family)Linux Kernel8.8HIGHAVAILABLEPOC2026-05-23
CVE-2026-42271KEVBerriAI LiteLLM MCP Command Injection (Chains to CVSS 10.0 Unauth RCE)BerriAI8.8HIGHAVAILABLEPUBLIC2026-05-08
CVE-2026-11645KEVGoogle Chrome V8 Out-of-Bounds Read/Write (Sandbox Escape)Google8.8HIGHAVAILABLELIMITED2026-06-09
CVE-2026-46748Siemens SINEC INS cap_dac_override Privilege EscalationSiemens8.8HIGHAVAILABLENONE2026-06-09
CVE-2026-20230KEVCisco Unified CM WebDialer SSRF to Root File WriteCisco8.6HIGHAVAILABLEPUBLIC2026-06-03
CVE-2026-55255KEVLangflow Cross-Tenant IDOR — AI Flow Execution Authorization BypassLangflow8.4HIGHAVAILABLELIMITED2026-06-23
CVE-2025-48595KEVAndroid Framework Integer Overflow Zero-Day (June 2026 Bulletin)Google8.4HIGHAVAILABLELIMITED2026-06-01
CVE-2026-44728Babel JavaScript Compiler Arbitrary Code Execution via Malicious InputOpenJS Foundation (Babel)8.2HIGHAVAILABLEPOC2026-05-26
CVE-2026-46331Linux Kernel 'pedit COW' Local Privilege Escalation via Page-Cache CorruptionLinux Kernel7.8HIGHAVAILABLEPOC2026-06-16
CVE-2026-50656Microsoft Defender 'RoguePlanet' — Malware Protection Engine LPE to SYSTEMMicrosoft7.8HIGHAVAILABLEPUBLIC2026-06-10
CVE-2026-20245KEVCisco Catalyst SD-WAN Manager CLI Command Injection Zero-Day (Root Escalation)Cisco7.8HIGHAVAILABLELIMITED2026-06-04
CVE-2026-28318KEVSolarWinds Serv-U Unauthenticated DoS via Deflate HeaderSolarWinds7.5HIGHAVAILABLELIMITED2026-06-04
CVE-2026-7473KEVArista EOS Tunnel Decapsulation Protocol Bypass – No Patch PlannedArista Networks6.9MEDIUMNO PATCHPUBLIC2026-05-05
CVE-2026-47729Squidbleed — Squid Proxy FTP Gateway Heap Overread Credential LeakSquid-cache.org6.5MEDIUMAVAILABLEPOC2026-06-12
CVE-2026-20262KEVCisco Catalyst SD-WAN Manager Arbitrary File Write / Path Traversal (Zero-Day, KEV)Cisco6.5MEDIUMAVAILABLELIMITED2026-06-15