๐จ CVE-2026-59688
An OS Command Injection vulnerability in Progress Software LoadMaster, ECS Connection Manager, Object Scale Connection Manager, and MOVEit WAF allows an authenticated attacker with high privileges to execute arbitrary operating system commands on the affected appliance via the backup restore functionality, potentially resulting in complete system compromise.
๐@cveNotify
An OS Command Injection vulnerability in Progress Software LoadMaster, ECS Connection Manager, Object Scale Connection Manager, and MOVEit WAF allows an authenticated attacker with high privileges to execute arbitrary operating system commands on the affected appliance via the backup restore functionality, potentially resulting in complete system compromise.
๐@cveNotify
Progress
LoadMaster Critical Security Bulletin โ July 2026 โ (CVE-2026-59686, CVE-2026-59687, CVE-2026-59688, CVE-2026-59689, CVE-2026-59690)โฆ
The Progress Kemp LoadMaster team recently confirmed a series of high-severity vulnerabilities in Progress Kemp LoadMaster, Progress ECS Connection Manager and Progress Connection Manager for ObjectScale GA v7.2.63.2 and older, Progress Kemp LoadMaster LTSFโฆ
๐จ CVE-2025-59172
Ericsson Packet Core Controller (PCC) versions prior to 1.38 contain an Improper Neutralization of Special Elements vulnerability allowing an attacker to execute arbitrary code as root.
๐@cveNotify
Ericsson Packet Core Controller (PCC) versions prior to 1.38 contain an Improper Neutralization of Special Elements vulnerability allowing an attacker to execute arbitrary code as root.
๐@cveNotify
ericsson.com
Security Bulletin-Ericsson Packet Core Controller, July 2026
Summary: Ericsson has released updates for Ericsson Packet Core Controller (PCC) to address security issues that, if exploited, may lead to escalation of...
๐จ CVE-2025-59177
Ericsson Packet Core Controller (PCC) versions prior to 1.39 contain a vulnerability in Configuration Management, allowing an attacker to execute specifically crafted commands to reveal system secret through error messages.
๐@cveNotify
Ericsson Packet Core Controller (PCC) versions prior to 1.39 contain a vulnerability in Configuration Management, allowing an attacker to execute specifically crafted commands to reveal system secret through error messages.
๐@cveNotify
ericsson.com
Security Bulletin-Ericsson Packet Core Controller, July 2026
Summary: Ericsson has released updates for Ericsson Packet Core Controller (PCC) to address security issues that, if exploited, may lead to escalation of...
๐จ CVE-2025-59178
Ericsson Packet Core Controller (PCC) versions prior to 1.39 contain an Exposure of Sensitive System Information vulnerability in Configuration Management allowing an attacker to enumerate other users on the system.
๐@cveNotify
Ericsson Packet Core Controller (PCC) versions prior to 1.39 contain an Exposure of Sensitive System Information vulnerability in Configuration Management allowing an attacker to enumerate other users on the system.
๐@cveNotify
ericsson.com
Security Bulletin-Ericsson Packet Core Controller, July 2026
Summary: Ericsson has released updates for Ericsson Packet Core Controller (PCC) to address security issues that, if exploited, may lead to escalation of...
๐จ CVE-2025-59180
Ericsson Packet Core Controller (PCC) versions prior to 1.38 contain a hardcoded credential vulnerability in the alarm system. An attacker with access to the cluster with knowledge of the hardcoded credential can read alarm and alert information.
๐@cveNotify
Ericsson Packet Core Controller (PCC) versions prior to 1.38 contain a hardcoded credential vulnerability in the alarm system. An attacker with access to the cluster with knowledge of the hardcoded credential can read alarm and alert information.
๐@cveNotify
ericsson.com
Security Bulletin-Ericsson Packet Core Controller, July 2026
Summary: Ericsson has released updates for Ericsson Packet Core Controller (PCC) to address security issues that, if exploited, may lead to escalation of...
๐จ CVE-2025-59181
Ericsson Packet Core Controller (PCC) versions prior to 1.39 contain a directory traversal vulnerability in Configuration Management that could allow an attacker to change directory permissions, denying access to legitimate users.
๐@cveNotify
Ericsson Packet Core Controller (PCC) versions prior to 1.39 contain a directory traversal vulnerability in Configuration Management that could allow an attacker to change directory permissions, denying access to legitimate users.
๐@cveNotify
ericsson.com
Security Bulletin-Ericsson Packet Core Controller, July 2026
Summary: Ericsson has released updates for Ericsson Packet Core Controller (PCC) to address security issues that, if exploited, may lead to escalation of...
๐จ CVE-2026-10600
Mattermost versions 11.8.x <= 11.8.0, 11.7.x <= 11.7.3, 11.6.x <= 11.6.5, 10.11.x <= 10.11.20 fail to bound the time and resource consumption of server-side document content extraction which allows an authenticated user with file-upload permission to degrade file uploads for all users on the server via repeatedly uploading small documents that are cheap to upload but expensive to extract, saturating the shared extraction worker pool.. Mattermost Advisory ID: MMSA-2026-00694
๐@cveNotify
Mattermost versions 11.8.x <= 11.8.0, 11.7.x <= 11.7.3, 11.6.x <= 11.6.5, 10.11.x <= 10.11.20 fail to bound the time and resource consumption of server-side document content extraction which allows an authenticated user with file-upload permission to degrade file uploads for all users on the server via repeatedly uploading small documents that are cheap to upload but expensive to extract, saturating the shared extraction worker pool.. Mattermost Advisory ID: MMSA-2026-00694
๐@cveNotify
Mattermost.com
Security Updates
Find information about Mattermost security updates, sign up for our Security Bulletin, read our Responsible Disclosure Policy, and more.
๐จ CVE-2026-10819
Mattermost versions 11.6.x <= 11.6.5, 10.11.x <= 10.11.20, 11.8.x <= 11.8.1, 11.7.x <= 11.7.4 fail to limit the number of frames and enforce the file size cap on animated GIF uploads, which allows an authenticated attacker to cause a denial of service via a crafted animated GIF uploaded as a custom emoji.. Mattermost Advisory ID: MMSA-2026-00695
๐@cveNotify
Mattermost versions 11.6.x <= 11.6.5, 10.11.x <= 10.11.20, 11.8.x <= 11.8.1, 11.7.x <= 11.7.4 fail to limit the number of frames and enforce the file size cap on animated GIF uploads, which allows an authenticated attacker to cause a denial of service via a crafted animated GIF uploaded as a custom emoji.. Mattermost Advisory ID: MMSA-2026-00695
๐@cveNotify
Mattermost.com
Security Updates
Find information about Mattermost security updates, sign up for our Security Bulletin, read our Responsible Disclosure Policy, and more.
๐จ CVE-2026-59528
Subscriber Sensitive Data Exposure in ShipTime: Discounted Shipping Rates <= 1.1.1 versions.
๐@cveNotify
Subscriber Sensitive Data Exposure in ShipTime: Discounted Shipping Rates <= 1.1.1 versions.
๐@cveNotify
Patchstack
Sensitive Data Exposure in WordPress ShipTime: Discounted Shipping Rates Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
๐จ CVE-2026-59529
Unauthenticated Sensitive Data Exposure in Ebook Store <= 6.19 versions.
๐@cveNotify
Unauthenticated Sensitive Data Exposure in Ebook Store <= 6.19 versions.
๐@cveNotify
Patchstack
Sensitive Data Exposure in WordPress Ebook Store Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
๐จ CVE-2026-59530
Unauthenticated Broken Access Control in Stripe For WooCommerce <= 4.0.7 versions.
๐@cveNotify
Unauthenticated Broken Access Control in Stripe For WooCommerce <= 4.0.7 versions.
๐@cveNotify
Patchstack
Broken Access Control in WordPress Stripe For WooCommerce Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
๐จ CVE-2026-59534
Unauthenticated Broken Access Control in Post My CF7 Form <= 6.2.0 versions.
๐@cveNotify
Unauthenticated Broken Access Control in Post My CF7 Form <= 6.2.0 versions.
๐@cveNotify
Patchstack
Broken Access Control in WordPress Post My CF7 Form Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
๐จ CVE-2026-59535
Unauthenticated Broken Access Control in Thrive Product Manager <= 10.9.2 versions.
๐@cveNotify
Unauthenticated Broken Access Control in Thrive Product Manager <= 10.9.2 versions.
๐@cveNotify
Patchstack
Broken Access Control in WordPress Thrive Product Manager Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
๐จ CVE-2026-59536
Unauthenticated Broken Access Control in CoCart โ Headless ecommerce <= 4.8.4 versions.
๐@cveNotify
Unauthenticated Broken Access Control in CoCart โ Headless ecommerce <= 4.8.4 versions.
๐@cveNotify
Patchstack
Broken Access Control in WordPress CoCart โ Headless ecommerce Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
๐จ CVE-2026-59546
Subscriber Broken Authentication in Hide My WP Ghost <= 7.0.06 versions.
๐@cveNotify
Subscriber Broken Authentication in Hide My WP Ghost <= 7.0.06 versions.
๐@cveNotify
Patchstack
Broken Authentication in WordPress Hide My WP Ghost Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
๐จ CVE-2026-59548
Unauthenticated Sensitive Data Exposure in Byteflows Travel & Hotel Booking <= 1.0.0 versions.
๐@cveNotify
Unauthenticated Sensitive Data Exposure in Byteflows Travel & Hotel Booking <= 1.0.0 versions.
๐@cveNotify
Patchstack
Sensitive Data Exposure in WordPress Byteflows Travel & Hotel Booking Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
๐จ CVE-2026-59549
Unauthenticated SQL Injection in rtMedia for WordPress, BuddyPress and bbPress <= 4.7.10 versions.
๐@cveNotify
Unauthenticated SQL Injection in rtMedia for WordPress, BuddyPress and bbPress <= 4.7.10 versions.
๐@cveNotify
Patchstack
SQL Injection in WordPress rtMedia for WordPress, BuddyPress and bbPress Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
๐จ CVE-2026-59556
Unauthenticated Cross Site Scripting (XSS) in Dynamic Pricing With Discount Rules for WooCommerce <= 4.5.11 versions.
๐@cveNotify
Unauthenticated Cross Site Scripting (XSS) in Dynamic Pricing With Discount Rules for WooCommerce <= 4.5.11 versions.
๐@cveNotify
Patchstack
Cross Site Scripting (XSS) in WordPress Dynamic Pricing With Discount Rules for WooCommerce Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
๐จ CVE-2026-59557
Unauthenticated Broken Access Control in Events Made Easy <= 3.1.3 versions.
๐@cveNotify
Unauthenticated Broken Access Control in Events Made Easy <= 3.1.3 versions.
๐@cveNotify
Patchstack
Broken Access Control in WordPress Events Made Easy Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
๐จ CVE-2026-65433
Subscriber Broken Access Control in RT Mega Menu โ Mega Menu Builder for Elementor & Gutenberg <= 1.5.1 versions.
๐@cveNotify
Subscriber Broken Access Control in RT Mega Menu โ Mega Menu Builder for Elementor & Gutenberg <= 1.5.1 versions.
๐@cveNotify
Patchstack
Broken Access Control in WordPress RT Mega Menu โ Mega Menu Builder for Elementor & Gutenberg Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
๐จ CVE-2026-65434
Subscriber Sensitive Data Exposure in ะฎKassa ะดะปั WooCommerce <= 2.16.1 versions.
๐@cveNotify
Subscriber Sensitive Data Exposure in ะฎKassa ะดะปั WooCommerce <= 2.16.1 versions.
๐@cveNotify
Patchstack
Sensitive Data Exposure in WordPress ะฎKassa ะดะปั WooCommerce Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.