Security threats and CVE advisories

Current security advisories selected for DataHouse infrastructure contexts: Linux, Windows Server, virtualization, databases, network services and business applications.

Security feed

Recent CVE advisories selected for server infrastructure

The feed is built from NVD, CISA KEV and EPSS signals, then translated and cached for DataHouse users.

Server administration
CategorySwitch between product-focused CVE watchlists.
Showsorted by CVSS, EPSS and operational severity
CVE-2024-23108CVSS 10.0Firewall

CVE-2024-23108: fortisiem vulnerability

An improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet allows attacker to execute unauthorized code or commands via via crafted API requests.

Updated: 2026-06-17
CVE-2023-34992CVSS 10.0Firewall

CVE-2023-34992: fortisiem vulnerability

A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet allows attacker to execute unauthorized code or commands via crafted API requests.

Updated: 2026-06-17
CVE-2026-48282CVSS 10.0CISA KEVKnown Exploited

CVE-2026-48282: Adobe ColdFusion Path Traversal Vulnerability

ColdFusion versions 2025.9, 2023.20 and earlier are affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could lead to arbitrary code execution in the context of the current user. Exploitation of t...

Updated: 2026-07-08
CVE-2026-48172CVSS 10.0CISA KEVcPanel

CVE-2026-48172: LiteSpeed cPanel Plugin Privilege Escalation Vulnerability

LiteSpeed User-End cPanel Plugin before 2.4.5 allows privilege escalation (possibly to root), as exploited in the wild in May 2026. Detection is best done via a command line of grep -rE "cpanel_jsonapi_func=redisAble" /var/cpanel/logs /usr/local/cpanel/logs...

Updated: 2026-06-17
CVE-2026-45829CVSS 10.0Runtime

CVE-2026-45829

A pre-authentication, code injection vulnerability in version 1.0.0 or later of the ChromaDB Python project allows an unauthenticated attacker to run arbitrary code on the server by sending a malicious model repository and trust_remote_code set to true in t...

Updated: 2026-07-15
CVE-2026-33453CVSS 10.0Mail

CVE-2026-33453: camel vulnerability

Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Apache Camel Camel-Coap component. Apache Camel's camel-coap component is vulnerable to Camel message header injection, leading to remote code execution when ro...

Updated: 2026-07-15
CVE-2026-46339CVSS 10.0General

CVE-2026-46339

9Router is an AI router & token saver. From 0.4.30 until 0.4.37, 9Router's src/proxy.js middleware did not protect /api/cli-tools/* and /api/mcp/*, allowing unauthenticated registration of customPlugins through src/app/api/cli-tools/cowork-settings/route.js...

Updated: 2026-07-16
CVE-2026-7411CVSS 10.0General

CVE-2026-7411

In Eclipse BaSyx Java Server SDK versions prior to 2.0.0-milestone-10, inadequate path normalization in the Submodel HTTP API allows an unauthenticated remote attacker to perform a path traversal attack. By supplying a maliciously crafted fileName parameter...

Updated: 2026-06-17
CVE-2023-2163CVSS 10.0Linux

CVE-2023-2163: linux kernel vulnerability

Incorrect verifier pruning in BPF in Linux Kernel >=5.4 leads to unsafe code paths being incorrectly marked as safe, resulting in arbitrary read/write in kernel memory, lateral privilege escalation, and container escape.

Updated: 2026-06-17
CVE-2024-23109CVSS 10.0Firewall

CVE-2024-23109: fortisiem vulnerability

An improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet allows attacker to execute unauthorized code or commands via via crafted API requests.

Updated: 2026-06-17
CVE-2026-56413CVSS 10.0General

CVE-2026-56413

Storage Concentrator (SC & SCVM) contains a command injection vulnerability in the ms_service.pl service, which listens on TCP port 9000 by default and accepts custom network packets to perform device actions. An unauthenticated remote attacker can send a s...

Updated: 2026-07-01
CVE-2026-56415CVSS 10.0General

CVE-2026-56415

Storage Concentrator (SC & SCVM) contains a command injection vulnerability within the debug.pl script that is reachable without authentication. A remote attacker can submit a specially crafted HTTP request containing a malicious payload that is processed w...

Updated: 2026-07-01
CVE-2026-34909CVSS 10.0CISA KEVKnown Exploited

CVE-2026-34909: Ubiquiti UniFi OS Path Traversal Vulnerability

A malicious actor with access to the network could exploit a Path Traversal vulnerability found in UniFi OS devices to access files on the underlying system that could be manipulated to access an underlying account.

Updated: 2026-06-24
CVE-2026-30302CVSS 10.0Windows

CVE-2026-30302: coderider vulnerability

The command auto-approval module in CodeRider-Kilo contains an OS Command Injection vulnerability, rendering its whitelist security mechanism ineffective. The vulnerability stems from the incorrect use of an incompatible command parser (the Unix-based shell...

Updated: 2026-06-17
CVE-2026-41679CVSS 10.0Runtime

CVE-2026-41679: paperclipai vulnerability

Paperclip is a Node.js server and React UI that orchestrates a team of AI agents to run a business. Prior to version 2026.416.0, an unauthenticated attacker can achieve full remote code execution on any network-accessible Paperclip instance running in `auth...

Updated: 2026-06-17
CVE-2026-31843CVSS 10.0Web

CVE-2026-31843

The goodoneuz/pay-uz Laravel package (<= 2.2.24) contains a critical vulnerability in the /payment/api/editable/update endpoint that allows unauthenticated attackers to overwrite existing PHP payment hook files. The endpoint is exposed via Route::any() with...

Updated: 2026-06-17
CVE-2025-12539CVSS 10.0CMS

CVE-2025-12539

The TNC Toolbox: Web Performance plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.4.2. This is due to the plugin storing cPanel API credentials (hostname, username, and API key) in files within the...

Updated: 2026-06-17
CVE-2026-49261CVSS 10.0Database

CVE-2026-49261: mariadb vulnerability

MariaDB server is a community developed fork of MySQL server. Versions 10.6.1 through 10.6.26, 10.11.1 through 10.11.17, 11.4.1 through 11.4.11, 11.8.1 through 11.8.7, and 12.3.1 with `wsrep_notify_cmd` enabled would execute shell commands embedded in the ...

Updated: 2026-07-15
CVE-2026-49869CVSS 10.0Containers

CVE-2026-49869: kestra vulnerability

Kestra is an open-source, event-driven orchestration platform. Prior to 1.0.45 and 1.3.21, AuthenticationFilter in Kestra OSS uses request.getPath().endsWith("/configs") to whitelist the public configuration endpoint from Basic Auth. Because the check is a ...

Updated: 2026-07-01
CVE-2026-40281CVSS 10.0Containers

CVE-2026-40281: gotenberg vulnerability

Gotenberg is a Docker-powered stateless API for PDF files. In versions 8.30.1 and earlier, the metadata write endpoint validates metadata keys for control characters but leaves metadata values unsanitized. A newline character in a metadata value splits the ...

Updated: 2026-06-17
CVE-2026-52887CVSS 10.0Database

CVE-2026-52887

NocoBase is an AI-powered no-code/low-code platform for building business applications and enterprise solutions. Prior to 2.0.61, NocoBase @nocobase/plugin-notification-in-app-message exposed GET /api/myInAppChannels:list, where the filter[latestMsgReceiveT...

Updated: 2026-07-16
CVE-2026-57572CVSS 10.0Containers

CVE-2026-57572: crawl4ai vulnerability

Crawl4AI is an open-source LLM-friendly web crawler and scraper. Prior to 0.9.0, the Docker API server accepted request-supplied browser_config.extra_args, which flowed into Chromium's launch arguments. An attacker could inject Chromium switches that replac...

Updated: 2026-07-08
CVE-2026-49257CVSS 10.0Web

CVE-2026-49257

mcp-pinot is a Python-based Model Context Protocol (MCP) server for interacting with Apache Pinot. In versions 3.0.1 and below, mcp-pinot defaults to running an HTTP MCP server bound to 0.0.0.0:8080 with no authentication enabled. All MCP tools, including S...

Updated: 2026-06-23
CVE-2026-53576CVSS 10.0Containers

CVE-2026-53576: kestra vulnerability

Kestra is an open-source, event-driven orchestration platform. Prior to 1.0.45 and 1.3.21, the authentication filter for the REST API (@Filter("/api/v1/**")) treats any request whose path ends in /configs as the public instance-config endpoint and forwards ...

Updated: 2026-07-01
CVE-2026-44181CVSS 10.0Linux

CVE-2026-44181

Jupyter Enterprise Gateway launches remote Jupyter Notebook kernels across distributed clusters like Apache Spark, Kubernetes, and Docker Swarm. In versions 2.0.0rc2 and above, prior to 3.3.0, the environment variables (KERNEL_XXX) used during the rendering...

Updated: 2026-07-17
CVE-2026-59726CVSS 10.0Containers

CVE-2026-59726

Ruflo is an agent meta-harness for Claude Code and Codex. Prior to 3.16.3, ruflo's default docker-compose deployment exposed the MCP bridge POST /mcp and POST /mcp/:group endpoints without authentication, allowing an unauthenticated network attacker to invo...

Updated: 2026-07-10
CVE-2026-41070CVSS 10.0Linux

CVE-2026-41070

openvpn-auth-oauth2 is a plugin/management interface client for OpenVPN server to handle an OIDC based single sign-on (SSO) auth flows. From version 1.26.3 to before version 1.27.3, when openvpn-auth-oauth2 is deployed in the experimental plugin mode (share...

Updated: 2026-06-17
CVE-2026-12848CVSS 10.0Web

CVE-2026-12848

GV-I/O Box 4E is a smart embedded device with 4 input and 4 relays output that can be controlled over Ethernet and RS-485. DVRSearch is a service running by default on the IOBox listening for UDP messages on port 10001. Any user on the network can send mes...

Updated: 2026-06-25
CVE-2026-44182CVSS 10.0Linux

CVE-2026-44182

Jupyter Enterprise Gateway launches remote Jupyter Notebook kernels across distributed clusters like Apache Spark, Kubernetes, and Docker Swarm. In versions prior to 3.3.0, the server interpolates untrusted environment variables (e.g., KERNEL_XXX) into Kube...

Updated: 2026-07-17
CVE-2026-9508CVSS 10.0Web

CVE-2026-9508

Incorrect permission settings on a critical resource in Suprema BioStar 2 (versions 2.9.3 through 2.9.11) that allow backup files to be publicly exposed when the administrator configures their path within the NGINX webroot. This vulnerability allows an atta...

Updated: 2026-06-17
CVE-2026-46695CVSS 10.0Linux

CVE-2026-46695

Boxlite is a sandbox service that allows users to create lightweight virtual machines (Boxes) and launch OCI containers within them to run untrusted code. Prior to version 0.9.0, Boxlite does not restrict the kernel capabilities available inside the contain...

Updated: 2026-06-17
CVE-2025-61481CVSS 10.0MikroTik

CVE-2025-61481

An issue in MikroTik RouterOS v.7.14.2 and SwOS v.2.18 exposes the WebFig management interface over cleartext HTTP by default, allowing an on-path attacker to execute injected JavaScript in the administrator’s browser and intercept credentials.

Updated: 2026-06-17
CVE-2026-54782CVSS 10.0Windows

CVE-2026-54782

CoreWCF is a port of the service side of Windows Communication Foundation (WCF) to .NET Core. Prior to 1.8.1 and 1.9.1, CoreWCF SAML 1.1 and SAML 2.0 token validation does not correctly resolve the issuer signing key or require signed tokens when IdentityCo...

Updated: 2026-07-10
CVE-2026-48772CVSS 10.0Database

CVE-2026-48772

ProxySQL is a proxy for MySQL and its forks, as well as PostgreSQL. In versions 2.0.0 through 3.0.8, the ProxySQL MySQL frontend accepts the `PROXY UNKNOWN <addr> <addr> <port> <port>\r\n` PP1 frame as a well-formed PROXY protocol header. The HAProxy PROXY ...

Updated: 2026-06-23
CVE-2026-10523CVSS 9.9VPN

CVE-2026-10523: standalone sentry vulnerability

An Authentication Bypass vulnerability (CWE-288) in Ivanti Sentry before the R10.5.2, R10.6.2 and R10.7.1 versions allows a remote unauthenticated attacker to create arbitrary administrative accounts and obtain full administrative access

Updated: 2026-06-22
CVE-2026-34156CVSS 9.9Runtime

CVE-2026-34156: nocobase vulnerability

NocoBase is an AI-powered no-code/low-code platform for building business applications and enterprise solutions. Prior to version 2.0.28, NocoBase's Workflow Script Node executes user-supplied JavaScript inside a Node.js vm sandbox with a custom require all...

Updated: 2026-06-17
CVE-2024-57726CVSS 9.9CISA KEVWindows

CVE-2024-57726: SimpleHelp Missing Authorization Vulnerability

SimpleHelp remote support software v5.5.7 and before has a vulnerability that allows low-privileges technicians to create API keys with excessive permissions. These API keys can be used to escalate privileges to the server admin role.

Updated: 2026-06-17
CVE-2026-48318CVSS 9.9General

CVE-2026-48318: coldfusion vulnerability

ColdFusion is affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could lead to arbitrary file system read. An attacker could exploit this vulnerability to access sensitive files and directories o...

Updated: 2026-07-15
CVE-2026-20180CVSS 9.9Network

CVE-2026-20180: identity services engine vulnerability

A vulnerability in Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to execute arbitrary commands on the underlying operating system of an affected device. To exploit this vulnerability, the attacker must have at least Read...

Updated: 2026-07-08
CVE-2026-20186CVSS 9.9Network

CVE-2026-20186: identity services engine vulnerability

A vulnerability in Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to execute arbitrary commands on the underlying operating system of an affected device. To exploit this vulnerability, the attacker must have at least Read...

Updated: 2026-06-29
CVE-2026-38526CVSS 9.9Web

CVE-2026-38526

An authenticated arbitrary file upload vulnerability in the /admin/tinymce/upload endpoint of Webkul Krayin CRM v2.2.x allows attackers to execute arbitrary code via uploading a crafted PHP file.

Updated: 2026-06-17
CVE-2026-34038CVSS 9.9Containers

CVE-2026-34038

Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.469, an authenticated remote command injection vulnerability in application deployment handling allows users with application write permi...

Updated: 2026-07-07
CVE-2026-45744CVSS 9.9SSH

CVE-2026-45744: termix vulnerability

Termix is a web-based server management platform with SSH terminal, tunneling, and file editing capabilities. Prior to version 2.3.2, the GET /ssh/file_manager/ssh/resolvePath endpoint in Termix is vulnerable to OS command injection. The endpoint uses doubl...

Updated: 2026-06-17
CVE-2026-40933CVSS 9.9General

CVE-2026-40933: flowise vulnerability

Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, due to unsafe serialization of stdio commands in the MCP adapter, an authenticated attacker can add an MCP stdio server with an arbitrary command, achie...

Updated: 2026-06-17
CVE-2026-42364CVSS 9.9Web

CVE-2026-42364: gv-lpc2011 firmware vulnerability

An os command injection vulnerability exists in the DdnsSetting.cgi functionality of GeoVision LPC2011/LPC2211 1.10. A specially crafted DDNS configuration can lead to arbitrary command execution. An attacker can modify a configuration value to trigger this...

Updated: 2026-06-17
CVE-2026-45633CVSS 9.9Containers

CVE-2026-45633

Dokploy is a free, self-hostable Platform as a Service (PaaS). In 0.26.6 and earlier, Dokploy contains a command injection vulnerability in the /docker-container-logs WebSocket endpoint. The tail and since parameters are not validated and are directly conca...

Updated: 2026-06-17

Security newsletter

Get new CVE alerts before they become an incident

We send selected infrastructure threats in English, with practical notes for DataHouse environments.

  • DataHouse: server administration and secure cloud
  • Hostilla.pl: hosting and mail services
  • SecDNS.pl: free DNS security layer