CVE-2026-44747: Memory corruption in SAP NetWeaver AS ABAP, 9.9 rating 🔥
New vulnerability in SAP NetWeaver AS ABAP allows an authenticated attacker to abuse logical errors in memory management. This could lead to unauthorized data access, data modification, or system downtime.
Search at Netlas.io:
👉 Link: https://nt.ls/4m05i
👉 Dork: http.headers.server:"NetWeaver Application Server / ABAP"
Vendor's advisory:
https://support.sap.com/en/my-support/knowledge-base/security-notes-news/july-2026.html
New vulnerability in SAP NetWeaver AS ABAP allows an authenticated attacker to abuse logical errors in memory management. This could lead to unauthorized data access, data modification, or system downtime.
Search at Netlas.io:
👉 Link: https://nt.ls/4m05i
👉 Dork: http.headers.server:"NetWeaver Application Server / ABAP"
Vendor's advisory:
https://support.sap.com/en/my-support/knowledge-base/security-notes-news/july-2026.html
❤4🔥4👾4
CVE-2026-56164 and other: EoP and another exploitable vulnerabilities in Microsoft SharePoint Server, 5.3 rating 🔥
A new Elevation of Privilege vulnerability in Microsoft SharePoint Server has been added to the CISA KEV, along with two previously disclosed vulnerabilities (CVE-2026-45659 & CVE-2026-32201). Attackers can chain them to gain access to SharePoint Server instances, steal IIS machine keys, and deploy malware.
🔥 All three are being actively exploited in the wild!
Search at Netlas.io:
👉 Link: https://nt.ls/oGZ1j
👉 Dork: tag.name:"microsoft_sharepoint"
Vendor's advisory:
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-56164
A new Elevation of Privilege vulnerability in Microsoft SharePoint Server has been added to the CISA KEV, along with two previously disclosed vulnerabilities (CVE-2026-45659 & CVE-2026-32201). Attackers can chain them to gain access to SharePoint Server instances, steal IIS machine keys, and deploy malware.
🔥 All three are being actively exploited in the wild!
Search at Netlas.io:
👉 Link: https://nt.ls/oGZ1j
👉 Dork: tag.name:"microsoft_sharepoint"
Vendor's advisory:
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-56164
🔥5👾4❤3
CVE-2026-15409 & CVE-2026-15410: Two exploited in the wild vulnerabilities in SonicWall SMA1000, up to 10.0 rating 🔥
Recently disclosed vulnerabilities in SonicWall SMA1000 allow an unauthenticated attacker to open a websocket-based tunnel to arbitrary localhost-only services and subsequently execute arbitrary operating system commands as root.
These flaws are being actively exploited in the wild! PoC exists!
Search at Netlas.io:
👉 Link: https://nt.ls/I9q7F
👉 Dork: http.favicon.hash_sha256:6bb6f64adaa6a7ed4da10a2fe4edf4cb4d9914aa742c7ad607ca4ca678dcd3f1 OR certificate.subject_dn:"HTTPS Management Certificate for SonicWALL (self-signed)"
Vendor's advisory:
https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2026-0008
Recently disclosed vulnerabilities in SonicWall SMA1000 allow an unauthenticated attacker to open a websocket-based tunnel to arbitrary localhost-only services and subsequently execute arbitrary operating system commands as root.
These flaws are being actively exploited in the wild! PoC exists!
Search at Netlas.io:
👉 Link: https://nt.ls/I9q7F
👉 Dork: http.favicon.hash_sha256:6bb6f64adaa6a7ed4da10a2fe4edf4cb4d9914aa742c7ad607ca4ca678dcd3f1 OR certificate.subject_dn:"HTTPS Management Certificate for SonicWALL (self-signed)"
Vendor's advisory:
https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2026-0008
🔥6❤4👍3
CVE-2026-63030: Pre-Auth RCE in WordPress Core, 9.8 rating 🔥
Recently disclosed WordPress pre authentication RCE vulnerability can be exploited by an anonymous user in a stock install of WordPress with no plugins. PoC exists!
Search at Netlas.io:
👉 Link: https://nt.ls/Yvd0s
👉 Dork: tag.name:"wordpress"
Read more:
https://slcyber.io/research-center/wp2shell-pre-authentication-rce-in-wordpress-core
Recently disclosed WordPress pre authentication RCE vulnerability can be exploited by an anonymous user in a stock install of WordPress with no plugins. PoC exists!
Search at Netlas.io:
👉 Link: https://nt.ls/Yvd0s
👉 Dork: tag.name:"wordpress"
Read more:
https://slcyber.io/research-center/wp2shell-pre-authentication-rce-in-wordpress-core
🔥4❤3👍2
HollowByte: DoS vulnerability in OpenSSL, no CVE assigned yet 🤷
By sending a malicious payload of just 11 bytes, a remote, unauthenticated attacker can freeze server memory and to crush a host.
Search at Netlas.io:
👉 Link: https://nt.ls/be55E
👉 Dork: tag.name:"openssl"
Read more:
https://sec.okta.com/articles/2026/06/openssl-hollowbtye-a-dos-hiding-in-11-bytes/
By sending a malicious payload of just 11 bytes, a remote, unauthenticated attacker can freeze server memory and to crush a host.
Search at Netlas.io:
👉 Link: https://nt.ls/be55E
👉 Dork: tag.name:"openssl"
Read more:
https://sec.okta.com/articles/2026/06/openssl-hollowbtye-a-dos-hiding-in-11-bytes/
🔥4❤2👍1
CVE-2026-60291, CVE-2026-60292, CVE-2026-60294 and other: A lot of vulnerabilities in Oracle Weblogic Server, 9.8 rating 🔥
Recently disclosed easily exploitable vulnerabilities in Oracle Weblogic Server allow unauthenticated attacker to compromise Oracle WebLogic Server.
Search at Netlas.io:
👉 Link: https://nt.ls/NdCqq
👉 Dork: tag.name:"weblogic"
Vendor's advisory:
https://www.oracle.com/security-alerts/cpujul2026.html#AppendixFMW
Recently disclosed easily exploitable vulnerabilities in Oracle Weblogic Server allow unauthenticated attacker to compromise Oracle WebLogic Server.
Search at Netlas.io:
👉 Link: https://nt.ls/NdCqq
👉 Dork: tag.name:"weblogic"
Vendor's advisory:
https://www.oracle.com/security-alerts/cpujul2026.html#AppendixFMW
🔥6❤4👍3
High-severity LPE in Exim, no CVE assigned yet 🤷
A new vulnerability in Exim allows a local attacker to read files outside the mail spool. This could lead to privilege escalation.
Search at Netlas.io:
👉 Link: https://nt.ls/qEnbs
👉 Dork: tag.name:"exim"
Vendor's advisory:
https://www.exim.org/static/doc/security/EXIM-Security-2026-06-22.1/EXIM-Security-2026-06-22.1.txt
A new vulnerability in Exim allows a local attacker to read files outside the mail spool. This could lead to privilege escalation.
Search at Netlas.io:
👉 Link: https://nt.ls/qEnbs
👉 Dork: tag.name:"exim"
Vendor's advisory:
https://www.exim.org/static/doc/security/EXIM-Security-2026-06-22.1/EXIM-Security-2026-06-22.1.txt
🔥6❤5😱2👍1
CVE-2026-61511: Pre-auth RCE vulnerability in vBulletin, 9.3 rating 🔥
The vulnerability allows unauthenticated attacker to run arbitrary PHP code as the web server, which can mean full site takeover. PoC is now available!
Search at Netlas.io:
👉 Link: https://nt.ls/c7BPf
👉 Dork: tag.name:"vbulletin"
Read more: https://ssd-disclosure.com/vbulletin-runtime-template-runmaths-preauth-rce/
The vulnerability allows unauthenticated attacker to run arbitrary PHP code as the web server, which can mean full site takeover. PoC is now available!
Search at Netlas.io:
👉 Link: https://nt.ls/c7BPf
👉 Dork: tag.name:"vbulletin"
Read more: https://ssd-disclosure.com/vbulletin-runtime-template-runmaths-preauth-rce/
🔥6👍4❤2
CVE-2026-16812: OS Command injection in VeloCloud Orchestrator, 10.0 rating 🔥
A new vulnerability in Arista VeloCloud Orchestrator (VCO) allows an unauthenticated remote attacker run OS commands on the VCO host. A compromise can also expose managed devices. This vulnerability is already being actively exploited in the wild!
Search at Netlas.io:
👉 Link: https://nt.ls/PkM4n
👉 Dork: http.body:"single-spa-application:@velocloud/vco-header" OR http.body:"vco/branding.css" OR http.body:"vco/favicon"
Vendor's advisory:
https://www.arista.com/en/support/advisories-notices/security-advisory/24364-security-advisory-0144
A new vulnerability in Arista VeloCloud Orchestrator (VCO) allows an unauthenticated remote attacker run OS commands on the VCO host. A compromise can also expose managed devices. This vulnerability is already being actively exploited in the wild!
Search at Netlas.io:
👉 Link: https://nt.ls/PkM4n
👉 Dork: http.body:"single-spa-application:@velocloud/vco-header" OR http.body:"vco/branding.css" OR http.body:"vco/favicon"
Vendor's advisory:
https://www.arista.com/en/support/advisories-notices/security-advisory/24364-security-advisory-0144
❤4🔥4
Command injection in Mittel MiCollab, no CVE assigned yet, 9.8 rating 🔥
A command injection vulnerability has been discovered in the AWV component of Mitel MiCollab. A successful exploit of this vulnerability could allow an attacker to execute arbitrary commands and potentially gain control of the system.
Search at Netlas.io:
👉 Link: https://nt.ls/t8Tk9
👉 Dork: tag.name:"micollab"
Vendor's advisory:
https://www.mitel.com/support/security-advisories/mitel-product-security-advisory-misa-2026-0006
A command injection vulnerability has been discovered in the AWV component of Mitel MiCollab. A successful exploit of this vulnerability could allow an attacker to execute arbitrary commands and potentially gain control of the system.
Search at Netlas.io:
👉 Link: https://nt.ls/t8Tk9
👉 Dork: tag.name:"micollab"
Vendor's advisory:
https://www.mitel.com/support/security-advisories/mitel-product-security-advisory-misa-2026-0006
❤3🔥3🕊2
CVE-2026-56846, CVE-2026-56848 & CVE-2026-58043 and other: 3 high-severity and 8 medium or low vulnerabilities in Node.js 🔥
Recently disclosed vulnerabilities in Node.js touch HTTP/2, the Permission Model, and several core modules.
Search at Netlas.io:
👉 Link: https://nt.ls/AAg1f
👉 Dork: tag.name:"node_js"
Vendor's advisory:
https://nodejs.org/en/blog/vulnerability/july-2026-security-releases
Recently disclosed vulnerabilities in Node.js touch HTTP/2, the Permission Model, and several core modules.
Search at Netlas.io:
👉 Link: https://nt.ls/AAg1f
👉 Dork: tag.name:"node_js"
Vendor's advisory:
https://nodejs.org/en/blog/vulnerability/july-2026-security-releases
🔥4❤3👍2