Category Wire

Automated cyber signal feeds.

CVE-2026-87900 – WP Toolkit for cPanel Argument Injection

​CVE ID :CVE-2026-87900 Published : Sept. 23, 2026, 8:17 p.m. | 55 minutes ago Description :Argument injection in WP Toolkit for cPanel 6.11.2-10794 and earlier allows remote authenticated users to read arbitrary files and execute arbitrary code across customer accounts. Severity:…

CVE-2026-84502 – Automation-controller: automation-controller-container: automation-controller: project scm_url argument injection into `git ls-remote –upload-pack` yields rce on the controller-task control-plane pod

​CVE ID :CVE-2026-84502 Published : Sept. 23, 2026, 6:47 p.m. | 24 minutes ago Description :A flaw was found in Red Hat Ansible Automation Platform’s automation- controller. The Project scm_url field is not validated against values that begin with a dash…

CVE-2026-84474 – Automation-controller: automation-controller-container: automation-controller: view_jobtemplate to execute privilege escalation via host_config_key exposure and x-forwarded-for spoofing of provisioning-callback host match

​CVE ID :CVE-2026-84474 Published : Sept. 23, 2026, 6:41 p.m. | 30 minutes ago Description :A flaw was found in Red Hat Ansible Automation Platform’s automation- controller. The provisioning-callback secret (host_config_key) is exposed to users holding only the read-level view_jobtemplate permission…

CVE-2026-90902 – Joomla Extension – joomshaper.com – Authenticated, Privileged SQL Injection in Coupon Bulk Update in Easy Store extension 1.0.0-3.0.0

​CVE ID :CVE-2026-90902 Published : Sept. 23, 2026, 6:39 p.m. | 32 minutes ago Description :Joomla Extension – joomshaper.com – Authenticated, Privileged SQL Injection in Coupon Bulk Update in Easy Store extension 1.0.0-3.0.0 – The coupon bulk update task (administrator/index.php?option=com_easystore&task=coupon.couponBulkUpdate) took…

CVE-2026-91018 – Double Free in lwIP (lightweight IP)

​CVE ID :CVE-2026-91018 Published : Sept. 22, 2026, 8:25 p.m. | 40 minutes ago Description :lwIP (Lightweight IP) has a double free vulnerability, which could crash the system, cause a DoS, memory corruption, or allow code execution on the victim system. Severity:…