View Ridge Security
Back to Cyber HoseThreat Research & Deep Dives

FeatherPanel subuser privilege escalation flaw CVE-2026-84715 affects

πŸ•΅οΈ RESEARCH & DEEP DIVES

  • FeatherPanel subuser privilege escalation flaw CVE-2026-84715 affects versions before 1.3.7.10
    A high-severity privilege escalation vulnerability, CVE-2026-84715, has been disclosed in FeatherPanel.

  • Security Boulevard outlines 9 enterprise identity trends defining 2026 and beyond
    Security Boulevard identifies nine enterprise identity trends expected to shape 2026 and beyond.

    • Applies to enterprises running identity and access management (IAM) programs as AI agents enter production use.
    • Trend one: agentic identity becomes a first-class citizen in IAM, with AI agents already operating in production environments.
    • These agents read emails, write code, query databases, post to Slack, file tickets, and call APIs across dozens of enterprise systems.
      πŸ“Ž Coverage: securityboulevard.com Β· πŸ‘ via securityboulevard.com (discovered)
  • Sality botnet infrastructure dismantled in joint global takedown β€” BleepingComputer

  • 23-Year-Old Sality P2P Botnet Disrupted β€” SecurityWeek

  • Researchers Use Claude to Port Pre-Auth RCE Exploit From One PLC Model to Another β€” The Hacker News

  • Attackers Exploit Critical Switchvox Flaw to Deploy Reverse Shells Without Credentials β€” The Hacker News

  • Authorities Turn Sality's P2P Network Against Itself, Cutting Off New Malware Payloads β€” The Hacker News

  • OAuth Single Sign On 6.25.0 - 7.0.0 - Unauthenticated Account Takeover via Un... β€” CVE ThreatInt

  • WPvivid Backup & Migration before 0.9.133 - Admin+ SQLi via Upload Cleaner Isolati... β€” CVE ThreatInt

  • Simple Ajax Chat before 20260827 - Unauthenticated Stored XSS via Chat Message Lin... β€” CVE ThreatInt

  • FAQ Builder AYS 1.6.3 - 1.8.4 - Unauthenticated Stored XSS via ays_get_user_i... β€” CVE ThreatInt

  • Theme My Login 7.0 - 7.1.15 - Subscriber+ Unauthorised Multisite Site Creatio... β€” CVE ThreatInt

  • JetStyleManager before 1.3.9 - Skin Deletion and Modification via CSRFThe JetStyle... β€” CVE ThreatInt

  • WC Vendors before 2.7.2.1 - Vendor+ Cross-Vendor Product and Arbitrary Post Modifi... β€” CVE ThreatInt

  • WC Vendors before 2.7.2.1 - Vendor+ Cross-Vendor Order Shipment Status ChangeThe W... β€” CVE ThreatInt

  • WC Vendors before 2.7.2.1 - Order Shipment Status Change via CSRFThe WC Vendors Wo... β€” CVE ThreatInt

  • MasterStudy LMS before 3.7.46 - Unauthenticated Student Statistics Disclosure via ... β€” CVE ThreatInt

  • MasterStudy LMS before 3.7.46 - Instructor+ Cross-Course Curriculum Deletion and T... β€” CVE ThreatInt

  • MasterStudy LMS before 3.7.46 - Unauthenticated Unpublished Course Title Disclosur... β€” CVE ThreatInt

  • MasterStudy LMS before 3.7.46 - Instructor+ Quiz Answer Disclosure via IDORThe Mas... β€” CVE ThreatInt

  • MasterStudy LMS before 3.7.46 - Unauthenticated Student Enrollment Disclosure via ... β€” CVE ThreatInt

  • MasterStudy LMS before 3.7.46 - Subscriber+ Cross-Instructor Order Data Disclosure... β€” CVE ThreatInt

  • Advanced Custom Fields: Extended 0.9.2.2 - 0.9.2.6 - Unauthenticated Privileg... β€” CVE ThreatInt

  • CatalogX before 6.1.3 - Unauthenticated Email Content Injection via Shared Transie... β€” CVE ThreatInt

  • FormLayer before 1.0.9 - Unauthenticated Form Configuration Disclosure via Form Su... β€” CVE ThreatInt

  • RegistrationMagic before 6.0.9.9 - Unauthenticated Stored XSS via Rating FieldThe ... β€” CVE ThreatInt

  • Critical SonicWall Remote Code Execution Vulnerabilities Actively Exploited in Attacks β€” Cyber Security News

  • Critical HPE Fabric Composer Flaws Let Unauthenticated Attackers Execute Code and Take Over Systems β€” Cyber Security News

  • Hackers Hide a Full Remote Access Trojan Inside a Real Exodus Crypto Wallet β€” Cyber Security News

  • Google Fixes 26 Chrome Vulnerabilities, Including 2 Critical Use-After-Free Flaws β€” Cyber Security News

  • Hugging Face Flaw Lets Malicious AI Models Plant Python Code on User Systems β€” Cyber Security News

  • OpenAI’s New Astra AI Can Discover Zero-Day Security Flaws and Build Exploits β€” Cyber Security News

  • -SuperProxy evolves from proxy botnet to loader -UNC3886's FireAnt campaign evolves -Mirage Kitten targets fintech with... β€” @campuscodi@mastodon.social

  • -BlueSky adds a feature for less visibility -Rust gets perma-maintainers -SweepLED can find hidden cameras -US... β€” @campuscodi@mastodon.social

  • -BGP hijack delivers malicious Virtualizor updates -Indian authorities take down Telegram doxing bot -Composer packages... β€” @campuscodi@mastodon.social

  • Coolify RCE via Environment Variable Key Injection β€” thehackerwire.com (discovered)

  • What Is MCP in Software Development and Why Does It Matter β€” securityboulevard.com (discovered)

  • Testing systems for high load and denial-of-service conditions β€” securityboulevard.com (discovered)

  • Best High-Risk Merchant Account Providers for Secure Online Businesses β€” securityboulevard.com (discovered)

Need help assessing your exposure?

Start with the free Posture Self-Check to see where you stand against the current threat landscape.

Free Posture Self-Check