๐ต๏ธ RESEARCH & DEEP DIVES
-
Silverstripe UserForms flaw enables code execution via email subject field
CVE-2026-54721
Silverstripe UserForms contains a high-severity arbitrary code execution vulnerability.- Silverstripe CMS sites using the UserForms visual form builder are affected.
- CVE-2026-54721 allows arbitrary code execution.
- The flaw is triggered through the email subject field.
๐ Coverage: thehackerwire.com ยท ๐ via thehackerwire.com (discovered)
-
mySites.guru adds Joomla check for backdoor files in core folders
mySites.guru introduced a Joomla audit check that identifies files absent from the CMS core distribution.- Joomla sites are covered, including versions 3.9.23, 4.4.13, 5.4.7 and 6.1.3.
- The check flags files in Joomla-owned folders that the CMS release never shipped.
- Joomla 5.4.7 and 6.1.3 each ship only index.php directly in /administrator/.
- Attackers can hide backdoors among legitimate-looking core files, such as session.php or duplicate index.php files.
- The audit compares installed files against known release file sets and reports unexpected executables.
๐ Coverage: mysites.guru ยท ๐ via mysites.guru (discovered)
๐ CVEs & KEV
-
CVE-2026-76943 โ CVSS 9.3 โ Xiiaozet LK100W Authentication Bypass Using an Alternate Path or ChannelXiiao...
-
CVE-2026-78239 โ CVSS 9.3 โ Xiiaozet LK100W Missing Authentication for Critical FunctionXiiaozet LK100W e...
-
CVE-2026-5706 โ CVSS 8.9 โ Buffer overflow in Bluetooth Mesh SDK when handling extended advertisementsIn...
-
CVE-2026-78037 โ CVSS 8.7 โ Xiiaozet LK100W OS Command InjectionXiiaozet LK100W is vulnerable to OS comma...
-
CVE-2026-77358 โ CVSS 8.2 โ cpp-httplib: Use-after-free of TLS session in WebSocketClient::shutdown_and_c...
-
CVE-2026-54083 โ CVSS 8.1 โ Wazuh: Path traversal in ip-customblock active response allows arbitrary file...
-
CVE-2026-54085 โ CVSS 7.1 โ Wazuh: Missing input validation in multiple active response scripts allows ar...
-
CVE-2026-61783 โ CVSS 7.0 โ Wazuh: RBAC permission-effect check in mask_sensitive_config allows low-privi...