CVE-2026-16812: OS Command injection in VeloCloud Orchestrator, 10.0 rating 🔥
A new vulnerability in Arista VeloCloud Orchestrator (VCO) allows an unauthenticated remote attacker run OS commands on the VCO host. A compromise can also expose managed devices. This vulnerability is already being actively exploited in the wild!
Search at Netlas.io:
👉 Link: https://nt.ls/PkM4n
👉 Dork: http.body:"single-spa-application:@velocloud/vco-header" OR http.body:"vco/branding.css" OR http.body:"vco/favicon"
Vendor's advisory:
https://www.arista.com/en/support/advisories-notices/security-advisory/24364-security-advisory-0144
A new vulnerability in Arista VeloCloud Orchestrator (VCO) allows an unauthenticated remote attacker run OS commands on the VCO host. A compromise can also expose managed devices. This vulnerability is already being actively exploited in the wild!
Search at Netlas.io:
👉 Link: https://nt.ls/PkM4n
👉 Dork: http.body:"single-spa-application:@velocloud/vco-header" OR http.body:"vco/branding.css" OR http.body:"vco/favicon"
Vendor's advisory:
https://www.arista.com/en/support/advisories-notices/security-advisory/24364-security-advisory-0144
❤4🔥4
Command injection in Mittel MiCollab, no CVE assigned yet, 9.8 rating 🔥
A command injection vulnerability has been discovered in the AWV component of Mitel MiCollab. A successful exploit of this vulnerability could allow an attacker to execute arbitrary commands and potentially gain control of the system.
Search at Netlas.io:
👉 Link: https://nt.ls/t8Tk9
👉 Dork: tag.name:"micollab"
Vendor's advisory:
https://www.mitel.com/support/security-advisories/mitel-product-security-advisory-misa-2026-0006
A command injection vulnerability has been discovered in the AWV component of Mitel MiCollab. A successful exploit of this vulnerability could allow an attacker to execute arbitrary commands and potentially gain control of the system.
Search at Netlas.io:
👉 Link: https://nt.ls/t8Tk9
👉 Dork: tag.name:"micollab"
Vendor's advisory:
https://www.mitel.com/support/security-advisories/mitel-product-security-advisory-misa-2026-0006
❤3🔥3🕊2
CVE-2026-56846, CVE-2026-56848 & CVE-2026-58043 and other: 3 high-severity and 8 medium or low vulnerabilities in Node.js 🔥
Recently disclosed vulnerabilities in Node.js touch HTTP/2, the Permission Model, and several core modules.
Search at Netlas.io:
👉 Link: https://nt.ls/AAg1f
👉 Dork: tag.name:"node_js"
Vendor's advisory:
https://nodejs.org/en/blog/vulnerability/july-2026-security-releases
Recently disclosed vulnerabilities in Node.js touch HTTP/2, the Permission Model, and several core modules.
Search at Netlas.io:
👉 Link: https://nt.ls/AAg1f
👉 Dork: tag.name:"node_js"
Vendor's advisory:
https://nodejs.org/en/blog/vulnerability/july-2026-security-releases
❤4🔥4👍2
CVE-2026-16347: Possible brute-force attack in Mikrotik RouterOS, 8.8 rating 🔥
MikroTik RouterOS contains a weakness in its API authentication handling that allows attackers to brute-force logins for unauthorized system access.
Search at Netlas.io:
👉 Link: https://nt.ls/mMq91
👉 Dork: http.favicon.hash_sha256:6e08f1f90e778da22f07537040dfcdab9c29ac443d8386ba5be71fcbc418ff47 OR http.title:"RouterOS" OR http.body:"img src=\"mikrotik_logo.svg"
Read more:
https://www.cisa.gov/news-events/ics-advisories/icsa-26-209-05
MikroTik RouterOS contains a weakness in its API authentication handling that allows attackers to brute-force logins for unauthorized system access.
Search at Netlas.io:
👉 Link: https://nt.ls/mMq91
👉 Dork: http.favicon.hash_sha256:6e08f1f90e778da22f07537040dfcdab9c29ac443d8386ba5be71fcbc418ff47 OR http.title:"RouterOS" OR http.body:"img src=\"mikrotik_logo.svg"
Read more:
https://www.cisa.gov/news-events/ics-advisories/icsa-26-209-05
🔥4❤1
CVE-2026-15307: Server-side file-write and request forgery via spatial lookups in Django, 8.8 rating 🔥
Recently disclosed Django vulnerability allows an attacker to write a file to disk (in some cases enabling remote code execution) or issue a network request as the Django process user. This flaw is reachable by staff users with view permissions on any registered model containing a spatial field.
Search at Netlas.io:
👉 Link: https://nt.ls/xa9dB
👉 Dork: tag.name:"django"
Vendor's advisory:
https://www.djangoproject.com/weblog/2026/aug/04/security-releases/
Recently disclosed Django vulnerability allows an attacker to write a file to disk (in some cases enabling remote code execution) or issue a network request as the Django process user. This flaw is reachable by staff users with view permissions on any registered model containing a spatial field.
Search at Netlas.io:
👉 Link: https://nt.ls/xa9dB
👉 Dork: tag.name:"django"
Vendor's advisory:
https://www.djangoproject.com/weblog/2026/aug/04/security-releases/
❤2🔥1
🤖 Desktop AI Supercomputers and Automated Cyberattacks
AI supercomputers now fit on a desk. Combine them with uncensored open models and autonomous agents, and cyberattacks become cheaper, faster, and far easier to scale.
✔ Why local AI changes the economics of offensive operations
✔ How model guardrails can be removed or bypassed
✔ How agents automate reconnaissance, exploitation, and retries
✔ Why defenders must prepare for same-day, machine-speed attacks
⏱ 12 min read
👉 https://netlas.io/blog/desktop_ai_supercomputers_and_automated_attacks/
AI supercomputers now fit on a desk. Combine them with uncensored open models and autonomous agents, and cyberattacks become cheaper, faster, and far easier to scale.
✔ Why local AI changes the economics of offensive operations
✔ How model guardrails can be removed or bypassed
✔ How agents automate reconnaissance, exploitation, and retries
✔ Why defenders must prepare for same-day, machine-speed attacks
⏱ 12 min read
👉 https://netlas.io/blog/desktop_ai_supercomputers_and_automated_attacks/
netlas.io
Desktop AI Supercomputers and Automated Cyberattacks - Netlas Blog
How local AI hardware, uncensored open models, and agent frameworks are lowering the cost and accelerating the scale of automated cyberattacks.
❤5🔥5
CVE-2026-64638: Pre-auth reflected XSS in WordPress, 8.9 rating 🔥
WordPress is vulnerable to a pre-auth reflected cross-site scripting (XSS) on the login screen, which can be escalated to RCE.
Search at Netlas.io:
👉 Link: https://nt.ls/SjACB
👉 Dork: tag.name:"wordpress"
Vendor's advisory:
https://github.com/WordPress/wordpress-develop/security/advisories/GHSA-52p2-r8wf-jcrf
WordPress is vulnerable to a pre-auth reflected cross-site scripting (XSS) on the login screen, which can be escalated to RCE.
Search at Netlas.io:
👉 Link: https://nt.ls/SjACB
👉 Dork: tag.name:"wordpress"
Vendor's advisory:
https://github.com/WordPress/wordpress-develop/security/advisories/GHSA-52p2-r8wf-jcrf
🔥3❤2
0-day SQL Injection in Metabase, no CVE assigned yet, 10.0 rating 🔥🔥🔥
Recently disclosed vulnerability in Metabase allows an unauthenticated remote attacker to inject arbitrary SQL into the Metabase application database, which can give them administrator access to the instance. This vulnerability is already being actively exploited in the wild!
Search at Netlas.io:
👉 Link: https://nt.ls/q4U1I
👉 Dork: http.favicon.hash_sha256:61c0353e2bde23f74f7febc277df979fbc1017186de060fd9bd8d07b65bcac13 OR http.headers.set_cookie:"metabase.DEVICE" OR http.title:"Metabase"
Vendor's advisory:
https://github.com/metabase/metabase/security/advisories/GHSA-vwf4-m7j8-wcjf
Recently disclosed vulnerability in Metabase allows an unauthenticated remote attacker to inject arbitrary SQL into the Metabase application database, which can give them administrator access to the instance. This vulnerability is already being actively exploited in the wild!
Search at Netlas.io:
👉 Link: https://nt.ls/q4U1I
👉 Dork: http.favicon.hash_sha256:61c0353e2bde23f74f7febc277df979fbc1017186de060fd9bd8d07b65bcac13 OR http.headers.set_cookie:"metabase.DEVICE" OR http.title:"Metabase"
Vendor's advisory:
https://github.com/metabase/metabase/security/advisories/GHSA-vwf4-m7j8-wcjf
🔥4❤2👍2
CVE-2026-44945: A privilege escalation vulnerability in Rancher, 9.1 rating 🔥
An authenticated Rancher low-privileged user can gain full administrative access to the Rancher control plane and transitively to all downstream clusters it manages.
Search at Netlas.io:
👉 Link: https://nt.ls/FGN75
👉 Dork: http.favicon.hash_sha256:2d7adbc74e7c8941927d04e702acbff577d219fef8617c8c3014d34ae395525b OR http.body:"<title>Rancher</title>" OR http.unknown_headers.key:"x_api_cattle_auth"
Vendor's advisory:
https://github.com/rancher/rancher/security/advisories/GHSA-v584-7w32-jwpq
An authenticated Rancher low-privileged user can gain full administrative access to the Rancher control plane and transitively to all downstream clusters it manages.
Search at Netlas.io:
👉 Link: https://nt.ls/FGN75
👉 Dork: http.favicon.hash_sha256:2d7adbc74e7c8941927d04e702acbff577d219fef8617c8c3014d34ae395525b OR http.body:"<title>Rancher</title>" OR http.unknown_headers.key:"x_api_cattle_auth"
Vendor's advisory:
https://github.com/rancher/rancher/security/advisories/GHSA-v584-7w32-jwpq
🔥4❤3
CVE-2026-44901 and other: Critical bugs in Wazuh Manager, up to 9.1 rating 🔥
Recently disclosed vulnerabilities in Wazuh Manager allow an attacker to execute arbitrary code, read and write arbitrary files. PoCs exist for all of them!
Search at Netlas.io:
👉 Link: https://nt.ls/COx2Y
👉 Dork: certificate.issuer_dn:"Wazuh" OR http.headers.server:"Wazuh" OR raw.banner:"Unable to add agent"
Vendor's advisory:
https://github.com/wazuh/wazuh/security/advisories/GHSA-8c6v-7g3w-prrq
Recently disclosed vulnerabilities in Wazuh Manager allow an attacker to execute arbitrary code, read and write arbitrary files. PoCs exist for all of them!
Search at Netlas.io:
👉 Link: https://nt.ls/COx2Y
👉 Dork: certificate.issuer_dn:"Wazuh" OR http.headers.server:"Wazuh" OR raw.banner:"Unable to add agent"
Vendor's advisory:
https://github.com/wazuh/wazuh/security/advisories/GHSA-8c6v-7g3w-prrq
❤2👍2🔥2
Chaining two vulnerabilities could allow RCE in MariaDB, no CVE assigned yet 🔥
Recently disclosed vulnerabilities in MariaDB allow a low-privileged attacker to run arbitrary commands as the mariadb process. PoC is already available!
Search at Netlas.io:
👉 Link: https://nt.ls/Dp2Ed
👉 Dork: tag.name:"mariadb"
Read more:
https://github.com/v12-security/pocs/tree/main/mariadb
Recently disclosed vulnerabilities in MariaDB allow a low-privileged attacker to run arbitrary commands as the mariadb process. PoC is already available!
Search at Netlas.io:
👉 Link: https://nt.ls/Dp2Ed
👉 Dork: tag.name:"mariadb"
Read more:
https://github.com/v12-security/pocs/tree/main/mariadb
🔥4❤3👍2
CVE-2026-65640: Authenticated RCE in WordPress, 8.8 rating 🔥
A recently disclosed vulnerability in WordPress allows an attacker with an Author-level privileges to upload malicious Postscript files, which could lead to RCE. This issue affects sites that use Imagick and Ghostscript.
Search at Netlas.io:
👉 Link: https://nt.ls/LrDYt
👉 Dork: tag.name:"wordpress"
Vendor's advisory:
https://github.com/WordPress/wordpress-develop/security/advisories/GHSA-8vr3-7mxf-gx8w
A recently disclosed vulnerability in WordPress allows an attacker with an Author-level privileges to upload malicious Postscript files, which could lead to RCE. This issue affects sites that use Imagick and Ghostscript.
Search at Netlas.io:
👉 Link: https://nt.ls/LrDYt
👉 Dork: tag.name:"wordpress"
Vendor's advisory:
https://github.com/WordPress/wordpress-develop/security/advisories/GHSA-8vr3-7mxf-gx8w
❤1🔥1
CVE-2026-71479: Integer overflow in New API, 9.1 rating 🔥
A recently disclosed integer overflow vulnerability in New API allows low-privileged accounts with a positive balance or an active subscription to credit themselves an arbitrarily large amount. This vulnerability is already being actively exploited in the wild!
Search at Netlas.io:
👉 Link: https://nt.ls/XoA0U
👉 Dork: http.favicon.hash_sha256:32132a307cad98d7f93b0384de87411f087bb34c148c932dcd5eea92101cbec3 OR http.unknown_headers.key:"x_new_api_version" OR http.title:"New API"
Vendor's advisory:
https://github.com/QuantumNous/new-api/security/advisories/GHSA-8r8v-xf7q-rcpr
A recently disclosed integer overflow vulnerability in New API allows low-privileged accounts with a positive balance or an active subscription to credit themselves an arbitrarily large amount. This vulnerability is already being actively exploited in the wild!
Search at Netlas.io:
👉 Link: https://nt.ls/XoA0U
👉 Dork: http.favicon.hash_sha256:32132a307cad98d7f93b0384de87411f087bb34c148c932dcd5eea92101cbec3 OR http.unknown_headers.key:"x_new_api_version" OR http.title:"New API"
Vendor's advisory:
https://github.com/QuantumNous/new-api/security/advisories/GHSA-8r8v-xf7q-rcpr
❤2🔥2
CVE-2026-60702 and other: Vulnerabilities in Oracle WebLogic Server, up to 9.9 rating 🔥
A recently disclosed vulnerabilities in Oracle WebLogic Server allow low-privileged or unauthenticated attacker to compromise the server.
Search at Netlas.io:
👉 Link: https://nt.ls/jX2A4
👉 Dork: tag.name:"weblogic"
Vendor's advisory:
https://www.oracle.com/security-alerts/cspuaug2026.html#AppendixFMW
A recently disclosed vulnerabilities in Oracle WebLogic Server allow low-privileged or unauthenticated attacker to compromise the server.
Search at Netlas.io:
👉 Link: https://nt.ls/jX2A4
👉 Dork: tag.name:"weblogic"
Vendor's advisory:
https://www.oracle.com/security-alerts/cspuaug2026.html#AppendixFMW
❤2🔥2👍1