🚨 ACTIVE EXPLOITATION
-
SonicWall SMA1000 Zero-Days Exploited to Deploy Custom Malware — SecurityWeek
Threat actors exploited SonicWall SMA1000 zero-days CVE-2026-15409 and CVE-2026-15410 remotely without authentication to deliver custom malware before patches were issued.- Applies to SonicWall SMA1000 secure remote access appliances
- Exploitation began around June 22, 2026, tracked by Volexity as threat actor UTA0533
- Attackers deployed custom malware 'KnuckleBall' with Java webshell 'OrangeTail' and proxy 'Suo5'
- Malware enabled root access to capture credentials and network traffic but showed limited lateral movement
-
Pre-authentication RCE in WordPress Core via CVE-2026-63030 and CVE-2026-60137 — Tenable
Two chained WordPress Core vulnerabilities enable unauthenticated remote code execution on default WordPress installs without plugins.- Applies to WordPress Core versions 6.9.0 to 6.9.4 and 7.0.0 to 7.0.1
- CVE-2026-63030 involves REST API batch-route confusion; CVE-2026-60137 is an SQL injection in WP_Query author__not_in parameter
- Exploitation involves crafted HTTP POST requests to the REST API batch endpoint /wp-json/batch/v1
- Active in-the-wild exploitation and public proof-of-concept exploits appeared within days of July 17, 2026 disclosure
🕵️ RESEARCH & DEEP DIVES
-
Russian Intelligence Hacks IP Cameras to Spy on NATO and Ukraine Military Logistics — The Hacker News
Russian intelligence hijacks internet-connected IP cameras across Europe, NATO states, and Ukraine to monitor military logistics.- Uses default passwords, obsolete firmware, and factory settings to gain access
- Employs image-recognition software to identify military vehicles and shipments
- In Ukraine, hacked cameras assist in targeting and neutralizing military personnel and equipment
- Exploits known vulnerabilities like CVE-2016-7407 and CVE-2021-39275 in camera-related services
-
SurrealDB before 2.5.0 has privilege escalation and DoS vulnerabilities — CVE ThreatInt
SurrealDB versions before 2.5.0 and 2.6.1 have privilege escalation and denial of service flaws.- Privilege escalation via confused deputy flaw allows unprivileged users to inject malicious logic executed with higher privileges
- Denial of service triggered by crafted large strings causing null pointer dereference and server crash
- DoS vulnerability exploitable by any user able to run queries, including unauthenticated guests if enabled
-
SurrealDB before 3.1.0 vulnerable to authorization bypass via KILL statement — CVE ThreatInt
Allows authenticated users to terminate other users' LIVE SELECT subscriptions without ownership verification, disrupting real-time data subscriptions. -
SurrealDB before 3.1.0 vulnerable to session hijacking via /rpc sessions endpoint — CVE ThreatInt
Unauthenticated attackers can enumerate session UUIDs and impersonate sessions to read, write, delete data and escalate privileges. -
SurrealDB before 3.1.0 Privilege Escalation via RPC Session Race Condition — CVE ThreatInt
Contains a time-of-check/time-of-use race condition allowing unauthenticated requests to inherit authenticated session state. -
SurrealDB before 3.1.0 Permission Bypass via WHERE Clause — CVE ThreatInt
Evaluates user-supplied WHERE clauses in various statements without proper authorization checks, enabling permission bypass.
🔓 CVEs & KEV
- CVE-2026-16248 — CVSS 8.8 — Tenda AC10 stack-based overflow in AdvSetLanip fromAdvSetLanip
- CVE-2026-64623 — CVSS 8.6 — Network-AI before 5.13.4 cryptographic signature verification bypass
- CVE-2026-64622 — CVSS 7.5 — Network-AI 5.12.2 through 5.13.3 missing authorization via ApprovalInbox
- CVE-2026-12080 — CVSS 7.3 — Qemu-kvm local privilege escalation via symlink attack in qemu-guest-agent
- CVE-2026-64621 — CVSS 7.3 — FreeRDP before 3.28.0 double-free via selectedmonitors
- Additional CVEs affecting Windu CMS, FreeRDP, and SurrealDB with various severity and impact.