Skip to content
Signals
NVD · CVE-2026-18907 · Path Traversal in Download File Feature in com.talpa.hibrowser 2.23.1.1 on Android allows arbitrary file write via directory traversal sequences in the filenameNVD · CVE-2026-18897 · 8.8 · A vulnerability was identified in UTT HiPER 1250GW up to v3.2.7-210907-180535. The impacted element is the function strcpy of the file /goform/getOneApConfTempENVD · CVE-2026-18896 · 6.3 · A vulnerability was determined in lavkush-maurya Student-Registration-System 1.0. The affected element is an unknown function of the file /student/changepass.phNVD · CVE-2026-18895 · 8.8 · A vulnerability was found in UTT HiPER 1250GW up to 3.2.7-210907-180535. Impacted is the function strcpy of the file /goform/APSecurity_5g. Performing a manipulCISA KEV · CVE-2026-18556 · 7.4 · N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability · Added 2026-08-04 · Due 2026-08-07CISA KEV · CVE-2026-34486 · 7.5 · Apache Tomcat Missing Encryption of Sensitive Data Vulnerability · Added 2026-08-04 · Due 2026-08-07NVD · CVE-2026-18907 · Path Traversal in Download File Feature in com.talpa.hibrowser 2.23.1.1 on Android allows arbitrary file write via directory traversal sequences in the filenameNVD · CVE-2026-18897 · 8.8 · A vulnerability was identified in UTT HiPER 1250GW up to v3.2.7-210907-180535. The impacted element is the function strcpy of the file /goform/getOneApConfTempENVD · CVE-2026-18896 · 6.3 · A vulnerability was determined in lavkush-maurya Student-Registration-System 1.0. The affected element is an unknown function of the file /student/changepass.phNVD · CVE-2026-18895 · 8.8 · A vulnerability was found in UTT HiPER 1250GW up to 3.2.7-210907-180535. Impacted is the function strcpy of the file /goform/APSecurity_5g. Performing a manipulCISA KEV · CVE-2026-18556 · 7.4 · N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability · Added 2026-08-04 · Due 2026-08-07CISA KEV · CVE-2026-34486 · 7.5 · Apache Tomcat Missing Encryption of Sensitive Data Vulnerability · Added 2026-08-04 · Due 2026-08-07

Independent Intelligence Platform — Est. 2025

Signal Intelligence for AI, Tech, and Cybersecurity

Cut through the noise. Track what matters.

Signals
safepay — bnpdist.comincransom — foundationstofreedom.orgincransom — takethehop.comincransom — lantisnet.comincransom — Loyalist Collegeincransom — TRULITE GLASS & ALUMINUM SOLUTIONSsafepay — bnpdist.comincransom — foundationstofreedom.orgincransom — takethehop.comincransom — lantisnet.comincransom — Loyalist Collegeincransom — TRULITE GLASS & ALUMINUM SOLUTIONS

Advertising

Reach security teams, developers and technology leaders through research-driven media placements.

Platform Intelligence

Explore

Actively Exploited

· KEV · EPSS · PoC
CVE-2026-18577KEVHIGH 8.1

An incomplete patch for CVE-2026-18556 allows for authentication bypass and account takeover in N-central Versions through 2026.3.1

CVE-2026-18556KEVHIGH 7.4

Authentication bypass using an alternate path or channel vulnerability in N-able N-central allows Authentication Bypass. This issue affects N-central: through 2026.1.

CVE-2026-20316KEVMEDIUM 5.3

A vulnerability in the web interface of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated, remote attacker to log in to an affected device using a low-privileged ac

CVE-2026-16812KEVCRITICAL 10.0

VeloCloud Orchestrator (VCO) on-prem has a security issue where this issue may allow a remote attacker to access privileged internal functionality and impact the VCO host. Successful exploitation may

CVE-2026-16232KEVCRITICAL 9.13 PoC

An authentication bypass vulnerability in the Check Point SmartConsole login process allows an unauthenticated remote attacker to obtain an application login token and use it to authenticate with full

CVE-2026-60137KEVMEDIUM 5.98 PoC

WordPress 6.8.x before 6.8.6, 6.9.x before 6.9.5, and 7.0.x before 7.0.2 does not properly sanitise the author__not_in parameter of WP_Query, which could allow SQL Injection when a plugin or theme pas

CVE-2026-9198KEVCRITICAL 9.8

IBM Langflow OSS 1.0.0 through 1.10.0 allows unauthenticated attackers to chain /api/v1/auto_login (mints SUPERUSER tokens to any network caller) with /api/v1/validate/code (executes user code via exe

CVE-2026-56291KEVCRITICAL 9.84 PoC

Joomla Extension - balbooa.com - Unauthenticated file upload in Balbooa Forms extension < 2.4.1 - The Joomla extension Balbooa Forms is vulnerable to an unauthenticated arbitrary file upload that allo

Briefings

· Latest

Research Library

· Guides

Latest CVEs

· NVD Live
CVE-2026-18907

Path Traversal in Download File Feature in com.talpa.hibrowser 2.23.1.1 on Android allows arbitrary file write via directory traversal sequences in the filename.

CVE-2026-18897HIGH 8.8

A vulnerability was identified in UTT HiPER 1250GW up to v3.2.7-210907-180535. The impacted element is the function strcpy of the file /goform/getOneApConfTempEntry. The manipulation of the argument tempName leads to stack-based buffer overflow. The attack can be initiated remotely. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2026-18896MEDIUM 6.3

A vulnerability was determined in lavkush-maurya Student-Registration-System 1.0. The affected element is an unknown function of the file /student/changepass.php. Executing a manipulation of the argument oldpass can lead to sql injection. It is possible to launch the attack remotely. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2026-18895HIGH 8.8

A vulnerability was found in UTT HiPER 1250GW up to 3.2.7-210907-180535. Impacted is the function strcpy of the file /goform/APSecurity_5g. Performing a manipulation of the argument cipher results in stack-based buffer overflow. It is possible to initiate the attack remotely. The exploit has been made public and could be used. The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2026-18859HIGH 7.3

A vulnerability was identified in ESAFENET CDG up to 20260615. Affected is an unknown function of the file /CDGServer3/ukey/usbkey;logindojojs. Such manipulation of the argument keyid leads to sql injection. The attack may be performed from remote. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2026-18856MEDIUM 4.7

A vulnerability was determined in Poesis Rhymix CMS up to 2.1.33. This impacts the function procImporterAdminCheckXmlFile of the file modules/importer/importer.admin.controller.php of the component Data Import Module. This manipulation of the argument filename causes server-side request forgery. The attack is possible to be carried out remotely. The exploit has been publicly disclosed and may be utilized. Upgrading to version 2.1.34 will fix this issue. It is recommended to upgrade the affected component.

Ransomware Activity

· Tracker Live

bnpdist.com

Aug 5

safepay · US

foundationstofreedom.org

Aug 5

incransom · US

takethehop.com

Aug 5

incransom · US

lantisnet.com

Aug 5

incransom · US

Loyalist College

Aug 5

incransom · CA

TRULITE GLASS & ALUMINUM SOLUTIONS

Aug 4

incransom · US

AI Intelligence

· 45 models · 67 apps & agents

Threat Actors

· ATT&CK

Membership

Intelligence Without Compromise

Free

$0

  • Public briefings
  • CVE feed — limited
  • Weekly digest

Pro· Popular

$29/mo

  • All briefings
  • Alert watchlists
  • CVE notifications
  • Threat feed access

Pro+

$79/mo

  • Restricted intelligence
  • Dark web reports
  • Data exports
  • API access

Enterprise

Custom

  • Full API
  • Team workflows
  • Integrations
  • Dedicated support

7-day free trial on Pro plans · No credit card required

Advertising

Reach security teams, developers and technology leaders through research-driven media placements.

Daily Brief

Intelligence Digest

CVEs, threat signals and analysis delivered each morning. No spam, unsubscribe anytime.

Preference center·Sign in