Skip to content
THREATWIRE

Index

Search

Search the public record. Drafts and scheduled notes are not included.

High

news

Apache Struts 7.4.0 fixes four security flaws

On 5 October 2026 Apache published S2-075 through S2-078 for Struts, covering OGNL injection in the legacy RESTful mapper, BigDecimal response expansion, an unbounded REST body read, and a shared date/time message formatter. Fixes ship in 7.4.0 and 6.12.0. No CVSS scores or CISA KEV listings yet.

Published 53m ago

Critical

news

Visual Composer LFI is CVE-2026-12227

Wordfence disclosed an unauthenticated local file inclusion in the Visual Composer Website Builder WordPress plugin up to 45.16.0, CVSS 9.8. A public PoC repository exists. Exploitation in the wild and CISA KEV listing are not confirmed.

Published 2h ago

Critical

threats

The Gitea diffpatch bug is listed by CISA

CVE-2026-60004 lets a user with repository write access run commands as the Gitea service account. Fixed in 1.27.1 on 27 July 2026. CISA listed it on 25 August 2026. NVD scores it 9.8 and does not mention the write-access requirement.

Published 2h ago

Critical

threats

NetScaler command execution is CVE-2026-88771

Citrix bulletin CTX697096 confirms unauthenticated command execution on NetScaler in the default configuration. CISA listed CVE-2026-88771 on 27 September 2026. A later alert with no CVE id is this bulletin, not a new unnumbered bug.

Published 2h ago

High

news

The PostgreSQL fuzzystrmatch bug needs a database login

CVE-2026-15742 can run code as the PostgreSQL operating-system user. The vendor score is 8.8 and the vector requires a database account. Fixed builds shipped on 13 August 2026. A public PoC path exists. CISA has not listed it.

Published 2h ago

High

research

The Roundcube SQL injection is not in the CISA catalog

CVE-2026-48842 is a pre-authentication SQL injection in Roundcube virtuser_query, fixed in May 2026. A public PoC exists. CISA has not listed it, so ThreatWire does not mark Active Exploitation.

Published 2h ago

Critical

research

Three Authlib signature bugs are not one patch

CVE-2026-28802, CVE-2026-27962, and CVE-2026-96760 are separate Authlib signature failures. Two have releases. The newest, through 1.7.2, does not.

Published 2h ago

High

research

Two MongoDB driver bugs are not confirmed code execution

CVE-2026-96748 lets an untrusted hostname add a server to a PyMongo client. CVE-2026-96746 can crash the C driver. Both are scored 8.3. Neither NVD text is arbitrary code execution, and neither is in the CISA catalog.

Published 2h ago