View Ridge Security
Back to Cyber HoseThreat Research & Deep Dives

Critical Citrix NetScaler auth bypass now leveraged in attacks

πŸ•΅οΈ RESEARCH & DEEP DIVES

  • LearnDash LMS through 5.1.5 vulnerable to subscriber-level arbitrary file upload (CVE-2026-12483) The LearnDash LMS WordPress plugin versions up to 5.1.5 allow authenticated users to upload arbitrary disallowed files, including PHP, via the assignment upload handler.

    • Affects WordPress sites running StellarWP LearnDash LMS plugin versions up to and including 5.1.5 with assignment uploads enabled.
    • Insufficient validation in the 'learndash_fileupload_process' function validates only the first file in an array, allowing upload of disallowed files including PHP to wp-content/uploads/learndash/assignments/.
    • Attackers need subscriber-level access or above and must be enrolled in a course with assignment uploads enabled.
    • Remote Code Execution is possible only if server configuration has been changed to allow execution of uploaded files.
    • CVSS 3.1 score 7.5 High (AV:N/AC:H/PR:L/UI:N); CWE-434, assigned by Wordfence, credited to Nguyen Ngoc Duc (duc193). πŸ“„ Source: wordfence.com Β· πŸ“Ž Coverage: cve.threatint.com Β· πŸ‘ via CVE ThreatInt
  • Critical Citrix NetScaler auth bypass now leveraged in attacks β€” BleepingComputer

  • Microsoft says some users can’t open the Teams desktop client β€” BleepingComputer

  • 39 New Methods That Compromise Passkey Authentication β€” BleepingComputer

  • Nvidia’s $12.9B Hugging Face deal could benefit enterprises β€” Cybersecurity Dive

  • OpenAI pledges $1 billion to provide resources, training for frontline cyber defenders β€” Cybersecurity Dive

  • New Ted Backdoor Hides Inside Victims' Own HAProxy Builds to Intercept Web Traffic β€” The Hacker News

  • Possible XSS in the SNS web administration panelIt’s possible to run a stored... β€” CVE ThreatInt

  • Langflow is vulnerable to arbitrary file write and arbitrary file deletion du... β€” CVE ThreatInt

  • Langflow is vulnerable to stored cross-site scripting and IP spoofing due to ... β€” CVE ThreatInt

  • User Enumeration in GastroMenum's GastroMenum Web PanelObservable response di... β€” CVE ThreatInt

  • HTML Injection via Improper Input Sanitization in Yordam Informatics's Librar... β€” CVE ThreatInt

  • Missing Authorization Allows Unauthorized Access to Critical POS Functions in... β€” CVE ThreatInt

  • Stored XSS in Gastromenum's Gastromenum Ticket and QR Menu SystemImproper neu... β€” CVE ThreatInt

  • valkey-io valkey Slot Migration cluster_migrateslots.c createSlotImportJob ou... β€” CVE ThreatInt

  • Reflected HTML Injection via Form Hijacking in Yordam Informatics's Library A... β€” CVE ThreatInt

  • Apache Griffin Hive Metastore Module: SQL Injection Vulnerability in Hive Met... β€” CVE ThreatInt

  • code-projects Vehicle Management System SQL Database Backup File vehicle_mana... β€” CVE ThreatInt

  • code-projects Vehicle Management System busprofile.php sql injectionA vulnera... β€” CVE ThreatInt

  • (Holloway) Chew, Kean Ho's Actualizer v1.2.0 and earlier contains a fail-open... β€” CVE ThreatInt

  • StackStorm st2 API Key auth.py privileges managementA security vulnerability ... β€” CVE ThreatInt

  • StackStorm st2 NoOp RBAC backend actionexecutions.py privileges managementA w... β€” CVE ThreatInt

  • GFI Exinda AI before 7.6.5 Argument Injection via Tools Iperf ClientGFI Exinda AI ... β€” CVE ThreatInt

  • GFI Exinda AI before 7.6.5 Path Traversal via Diagnostic File Deletion HandlerGFI ... β€” CVE ThreatInt

  • GFI Exinda AI before 7.6.5 Path Traversal via Configuration Download HandlerGFI Ex... β€” CVE ThreatInt

  • Hackers Use Popular Messaging Services to Control New Windows Backdoors β€” Cyber Security News

  • NodeStealer Can Now Record Everything Victims Type and Steal Their Screenshots β€” Cyber Security News

  • Hackers Use Invisible Unicode Characters to Evade Phishing Detection in Millions of Emails β€” Cyber Security News

  • Self-hosted Coder: check whether you pulled a registry module on Aug 31. no CVE, so nothing will flag it for you β€” r/netsec

  • Getting Agents to tell on themselves β€” r/netsec

  • 153 Million Reasons Document Verification Isn’t Identity Assurance β€” securityboulevard.com (discovered)

  • OpenAI Pledges $1 Billion in AI Cybersecurity Tools to Protect Critical Infrastructure β€” securityboulevard.com (discovered)

  • Researcher Releases Exploit of Claimed CrowdStrike Falcon Zero-Day β€” securityboulevard.com (discovered)

  • How Much Does ISO 27001 Certification Cost for a Startup? β€” securityboulevard.com (discovered)

  • Before you head out for the last true weekend of summer in the Northern Hemisphere, don't miss today's Metacurity for... β€” @metacurity@infosec.exchange

Need help assessing your exposure?

Start with the free Posture Self-Check to see where you stand against the current threat landscape.

Free Posture Self-Check