🚨 Critical Joomla Easy Store SQL Injection Exposes Databases
Joomla administrators running affected Easy Store versions should patch immediately. Because the flaw requires no authentication and can expose sensitive database contents, affected sites should be prioritized for remediation.
CVE-2026-65761 affects the Joomla Easy Store extension from joomshaper.com versions 1.0.0-2.0.1 due to improper validation of order parameters. The unauthenticated SQL injection vulnerability allows attackers to read the full database, including credentials and session data. The issue is rated CRITICAL with a CVSS score of 9.3.
🔗 Read more 🔗
Source: NVD
🔓 Joomla Easy Store Flaw Reveals Other Customers’ Orders
Organizations using Easy Store should update as soon as possible. Sites handling customer orders or personal data should treat this as urgent because authenticated users may access other customers’ information.
CVE-2026-65760 affects Joomla Easy Store extension versions 1.0.0-2.0.1 from joomshaper.com. Improper access checks allow logged in users to retrieve order and customer information belonging to other users. The vulnerability is rated CRITICAL with a CVSS score of 9.2.
🔗 Read more 🔗
Source: NVD
💳 Joomla Easy Store Payment Forgery Bug Enables Order Manipulation
Ecommerce operators should patch affected Easy Store deployments quickly and review orders for suspicious changes. The ability for unauthenticated users to alter payment states creates a serious business-impact risk.
CVE-2026-65759 affects Joomla Easy Store extension versions 1.0.0-2.0.1 from joomshaper.com. Critical payment and order states are processed from client-side input, allowing unauthenticated attackers to manipulate arbitrary orders. The issue is rated HIGH with a CVSS score of 8.7.
🔗 Read more 🔗
Source: NVD
🌐 Proxygen HTTP/2 Bug Can Trigger Memory Exhaustion DoS
Teams running Proxygen-based services should apply fixes promptly, especially for internet-facing systems. Prioritize exposed services because attackers can trigger denial of service remotely without authentication.
CVE-2026-44909 affects Proxygen versions v2017.01.16.00 through v2026.07.20.00 due to missing generalized slow-consumer detection in the HTTP session layer. A remote unauthenticated attacker can abuse HTTP/2 flow control behavior to cause unbounded memory growth and service degradation. The vulnerability is rated HIGH with a CVSS score of 7.5.
🔗 Read more 🔗
Source: NVD
🗄️ CyberPanel Backup IDOR Lets Users Access Other Tenants
CyberPanel administrators should upgrade immediately and review tenant backup activity. Multi-tenant environments are especially at risk because authenticated users may impact other customers’ data.
CVE-2026-65917 affects CyberPanel through version 1.9.1 and involves an insecure direct object reference in IncBackups handlers. Authenticated panel users can access or manipulate other tenants’ backup resources, including deleting backups or triggering unauthorized restores with root privileges. The vulnerability is rated HIGH with a CVSS score of 8.8.
🔗 Read more 🔗
Source: NVD
☁️ AWS API MCP Server Policy Bypass Fixed in Update
Users of affected AWS API MCP Server versions should upgrade to version 1.3.47 immediately. Environments relying on configured policy restrictions should prioritize remediation because denied actions may bypass intended controls.
CVE-2026-16584 affects AWS API MCP Server versions 0.2.13 through 1.3.46. An initialization failure can cause security policy enforcement to be skipped, allowing blocked AWS API operations to execute while IAM permissions remain unchanged. The vulnerability is rated HIGH with a CVSS score of 7.0.
🔗 Read more 🔗
Source: NVD
🧼 DOMPurify XSS Flaw Allows Trusted Content Bypass
Developers using affected DOMPurify versions should update to the fixed release and review custom sanitizer hooks. Applications processing untrusted HTML should treat this as a priority security update.
CVE-2026-65898 affects DOMPurify before version 3.4.11 due to improper handling of the ALLOWED_ATTR allowlist during setConfig() use with an uponSanitizeAttribute hook. Attackers can cause dangerous attributes to be permitted, leading to stored XSS in affected applications. The vulnerability is rated HIGH with a CVSS score of 7.2.
🔗 Read more 🔗
Source: NVD
📁 Bold Reports Upload Bug Enables Server Command Execution
Administrators should update Bold Reports immediately, especially where authenticated users have access to report design features. Review access controls because exploitation can lead to server compromise.
CVE-2026-65690 affects Bold Reports Standalone Report Designer before version 14.1.12. A missing filepath validation issue in file uploads allows authenticated attackers to perform path traversal and execute arbitrary commands with high privileges. The vulnerability is rated HIGH with a CVSS score of 8.8.
🔗 Read more 🔗
Source: NVD
🚨 Bold Reports Critical File Read Bug Exposes Credentials
Bold Reports deployments should be patched urgently because no authentication is required for exploitation. Teams should also investigate whether sensitive files or credentials were accessed.
CVE-2026-65689 affects Bold Reports Standalone Report Designer before version 14.1.12. An unauthenticated path traversal vulnerability in the database download feature allows attackers to read arbitrary files from the server filesystem, including authentication credentials. The vulnerability is rated CRITICAL with a CVSS score of 9.8.
🔗 Read more 🔗
Source: NVD
🚨 Bold Reports Font Processing Flaw Leaks Server Files
Patch affected Bold Reports systems immediately, particularly internet-facing deployments. Because exploitation does not require authentication, organizations should check for signs of unauthorized file access.
CVE-2026-65688 affects Bold Reports Standalone Report Designer before version 14.1.12. A missing filepath validation vulnerability in font processing allows unauthenticated attackers to read arbitrary server files and potentially obtain authentication credentials. The vulnerability is rated CRITICAL with a CVSS score of 9.8.
🔗 Read more 🔗
Source: NVD
🚨 Bold Reports SVG Parser Bug Allows Sensitive File Theft
Apply the Bold Reports update as soon as possible, especially on publicly reachable systems. Organizations should monitor for suspicious requests targeting file processing features.
CVE-2026-65687 affects Bold Reports Standalone Report Designer before version 14.1.12. A missing filepath validation issue in SVG processing allows unauthenticated attackers to read arbitrary files from the server filesystem. The vulnerability is rated CRITICAL with a CVSS score of 9.8.
🔗 Read more 🔗
Source: NVD
💥 brace-expansion Memory Bug Can Crash Node.js Apps
Developers should upgrade to brace-expansion 5.0.8 and review dependencies such as minimatch or glob that may include it. Prioritize applications that process attacker-controlled pattern input.
CVE-2026-14257 affects brace-expansion through version 5.0.7 and allows denial of service through memory exhaustion. Attackers can supply crafted brace patterns that cause excessive memory use and crash Node.js processes using the vulnerable functionality. The vulnerability is rated HIGH with a CVSS score of 7.5.
🔗 Read more 🔗
Source: NVD