cbcvebase.
← Exploited This Week

Exploited This Week — Jul 06–Jul 13, 2026

6 KEV · 14 newly weaponized · 1 EPSS surges

Patch now — added to CISA KEV

CVE-2026-48282
Adobe ColdFusion Path Traversal Vulnerability
CISA KEV (added 2026-07-07, due 2026-07-10) · CVSS 10 CRITICAL · EPSS 0.29 (98th pct)

ColdFusion versions 2025.9, 2023.20 and earlier are affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could lead to arbitrary code execution in the context of the current…

blogs_hackernews, vuldb, vulncheck
CVE-2026-56290
Joomlack Page Builder Improper Access Control Vulnerability
CISA KEV (added 2026-07-07, due 2026-07-10) · CVSS 9.8 CRITICAL · EPSS 0.03 (85th pct)

The Joomla extension Page Builder CK is vulnerable to an unauthenticated arbitrary file upload that allows uploading executable files and leads to full RCE.

ExploitDB PoCblogs_hackernews, vuldb, vulncheck
CVE-2026-48908
JoomShaper SP Page Builder Unrestricted Upload of File with Dangerous Type Vulnerability
CISA KEV (added 2026-07-07, due 2026-07-10) · CVSS 9.8 CRITICAL · EPSS 0.02 (72th pct)

A vulnerability in SP Page Builder for Joomla allows unauthenticated users to upload arbitrary files, ultimately resulting in the upload and execution of PHP code.

blogs_hackernews, vuldb, vulncheck
CVE-2026-48939
iCagenda Unrestricted Upload of File with Dangerous Type Vulnerability
CISA KEV (added 2026-07-10, due 2026-07-13) · CVSS 9.8 CRITICAL · EPSS 0.02 (71th pct)

A vulnerability in the iCagenda extension for Joomla allows the upload of arbitrary files in the file attachment feature, ultimately resulting in PHP code upload and execution.

vuldb, vulncheck
CVE-2026-56291
Balbooa Forms Unrestricted Upload of File with Dangerous Type Vulnerability
CISA KEV (added 2026-07-10, due 2026-07-13) · CVSS 9.8 CRITICAL · EPSS 0.01 (53th pct)

The Joomla extension Balbooa Forms is vulnerable to an unauthenticated arbitrary file upload that allows uploading executable files and leads to full RCE.

vuldb, vulncheck
CVE-2026-55255
Langflow Authorization Bypass Through User-Controlled Key Vulnerability
CISA KEV (added 2026-07-07, due 2026-07-10) · CVSS 8.4 HIGH · EPSS 0.00 (37th pct)

Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to 1.9.1, an Insecure Direct Object Reference (IDOR) vulnerability in /api/v1/responses endpoint allows an authenticated attacker to execute any flow…

blogs_checkpoint, blogs_hackernews, vuldb, vulncheck

Newly weaponized — exploit code appeared

CVE-2026-48909
Joomla Extension 4.1.4 - PHP Object injection
CVSS 9.5 CRITICAL · EPSS 0.03 (84th pct)

SP LMS (com_splms) < 4.1.4 by JoomShaper deserializes user-controlled cookie data without validation, enabling an unauthenticated remote attacker to execute arbitrary code on the server.

ExploitDB PoCvuldb
CVE-2026-44225
Pulpy 0.1.1-Beta - Filesystem Sandbox Bypass
CVSS 9.3 CRITICAL · EPSS 0.01 (62th pct)

Pulpy is a lightweight, cross-platform desktop application packager for web apps. Prior to 0.1.1, Pulpy injects a pulpy.fs JavaScript API into every packaged web application, giving it access to the host filesystem. A validateFsPath()…

ExploitDB PoCvuldb
CVE-2026-56766
hydra: Hydra: Remote Code Execution via NTLM Authentication Stack Buffer Overflow
CVSS 8.8 HIGH · EPSS 0.01 (68th pct)

Hydra through 9.7, fixed in commit 9cc84c2, contains a stack buffer overflow in NTLM authentication across SMTP, POP3, IMAP, NNTP, HTTP, HTTP-Proxy, and HTTP-Proxy-Urlenum modules when processing malicious NTLM Type-2 challenges. A…

ExploitDB PoCvuldb
CVE-2026-58057
Oracle Oracle Communications Risk Matrix: Security (Netty) —
CVSS 5 MEDIUM · EPSS 0.01 (53th pct)

Flowise before 3.1.3 validates Custom MCP stdio environment variables against a denylist using a case-sensitive comparison, so on Windows, where environment names are case-insensitive, supplying 'node_options' bypasses the NODE_OPTIONS…

ExploitDB PoCvuldb
CVE-2026-49069
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPZOOM Portfolio…
CVSS 7.1 HIGH · EPSS 0.00 (26th pct)

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPZOOM Portfolio allows Reflected XSS. This issue affects WPZOOM Portfolio: from n/a through 1.4.21.

ExploitDB PoCvuldb
CVE-2026-38526
An authenticated arbitrary file upload vulnerability in the /admin/tinymce/upload endpoint of Webkul Krayin CRM v2
CVSS 9.9 CRITICAL · EPSS 0.03 (85th pct)

An authenticated arbitrary file upload vulnerability in the /admin/tinymce/upload endpoint of Webkul Krayin CRM v2.2.x allows attackers to execute arbitrary code via uploading a crafted PHP file.

ExploitDB PoC
CVE-2026-49952
Discuz! X5.0 - Authentication Bypass
CVSS 9.1 CRITICAL · EPSS 0.01 (68th pct)

Discuz! X5.0 releases 20260320 through 20260501 contains an authentication bypass vulnerability that allows unauthenticated remote attackers to gain unauthorized access to database backup and restore functionality by exploiting a shared…

ExploitDB PoC
CVE-2026-48611
Improper authentication checks in the OAuth implementation allow account hijacking even when OAuth is not configured…
CVSS 9.8 CRITICAL · EPSS 0.03 (85th pct)

Improper authentication checks in the OAuth implementation allow account hijacking even when OAuth is not configured or enabled leading to unauthorized access in default installations.

blogs_hackernews
CVE-2026-48313
ColdFusion versions 2025.9, 2023.20 and earlier are affected by an Improper Limitation of a Pathname to a Restricted…
CVSS 9.3 CRITICAL · EPSS 0.02 (73th pct)

ColdFusion versions 2025.9, 2023.20 and earlier are affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could lead to arbitrary file system read and limited write access. An…

blogs_hackernews, vuldb
CVE-2026-36213
An issue in Microvirt MEmu Android Emulator 9.2.7.0 allows a local attacker to escalate privileges via the…
CVSS 7.8 HIGH · EPSS 0.00 (38th pct)

An issue in Microvirt MEmu Android Emulator 9.2.7.0 allows a local attacker to escalate privileges via the MemuService.exe component.

ExploitDB PoC

+3 more lower-signal CVEs gained public exploit code this week.

EPSS surges — exploitation risk jumped

CVE-2026-5027
The 'POST /api/v2/files' endpoint does not sanitize the 'filename' parameter from the multipart form data, allowing an…
CVSS 8.8 HIGH · EPSS 0.31 (98th pct) · ↑ EPSS 0.02→0.31 (+0.29) over 7d

The 'POST /api/v2/files' endpoint does not sanitize the 'filename' parameter from the multipart form data, allowing an attacker to write files to arbitrary locations on the filesystem using path traversal sequences ('../').

Nuclei templateblogs_bleepingcomputer, blogs_hackernews, vulncheck

Get this every Monday

Free weekly digest for blue teams — what got weaponized, with detection coverage.