CVE-2026-58048 (CVSS 9.4): cPanel & WHM DB privilege-escalation flaw lets an authenticated MySQL user run SQL as database root, risking OS-level compromise. Affects all versions + WP Squared. Patch now. Query: technology="cPanel" or web.title~"WP Squared Login" or web.headers~"whostmgrrelogin"
Modat
@modat-io.bsky.social
European Internet Intelligence Company. Understand the intent behind internet infrastructure before it is weaponised. Check it out on https://modat.io
CVE-2026-20316 (CISA KEV): static credentials for a low-priv account in Cisco Secure FMC let an unauthenticated attacker log in & read sensitive data. Exploited as a zero-day, chainable with CVE-2026-20079 (CVSS 10.0) for root access. Patch now. Query: product="Cisco FDM"
⚠️ CVE-2026-6875 (Critical): pre-auth sandbox-escape RCE in ServiceNow AI Platform lets unauthenticated attackers run code. Patched July 13; reports of in-the-wild exploitation. Update now, prioritise self-hosted. Query: technology="ServiceNow"
⚠️ wp2shell (CVE-2026-63030, CVSS 9.8): pre-auth RCE in WordPress core via the REST batch API (batch/v1), on by default & reachable unauthenticated. Works on a stock install, no plugins. Affects 6.9.0–6.9.4 & 7.0.0–7.0.1. Update to 6.9.5/7.0.2 now. Query: technology="WordPress"
⚠️ F5 patched 3 memory-safety flaws in NGINX incl. CVE-2026-42533 (CVSS 9.2) is a heap overflow via the map directive that crafted HTTP requests can trigger, with possible code exec if ASLR is off; plus an SSI use-after-free & a slice memory leak. Upgrade now to 1.31.3. Query: technology="Nginx"
CVE-2026-56164 (CISA KEV): unauthenticated privilege escalation in on-prem Microsoft SharePoint, chained in the wild to RCE, IIS key theft & persistence. Exploited a zero-day in Microsoft's record July Patch Tuesday. Patch now & enable AMSI Full Mode. Query: technology="Microsoft SharePoint"
CVE-2026-44747 (CVSS 9.9): out-of-bounds write in SAP NetWeaver AS ABAP allows an authenticated attacker to trigger memory corruption, risking data access, modification, or DoS. Patched in SAP's July 2026 Security Patch Day. Install the fixed ABAP Kernel now. Query: product="SAP NetWeaver"
⚠️ Ubiquiti Security Advisory Bulletin 066: 25 vulnerabilities across the UniFi ecosystem (OS, Network, Protect, Access, Talk, Connect). Several critical, up to CVSS 10.0 (CVE-2026-50746, UniFi Connect). Update per advisory. Query: web.title~"UniFi OS"
⚠️ CVE-2026-45659 (CVSS 8.8, CISA KEV): deserialization flaw in Microsoft SharePoint letting an authenticated attacker with Site Member permissions run code remotely, no user interaction. Actively exploited. Affects SharePoint 2016, 2019 & Sub Edition. Query: technology="Microsoft SharePoint"
⚠️ Squidbleed (CVE-2026-47729, CVSS 6.5): a flaw in Squid's FTP parser that can leak another user's cleartext HTTP request, including credentials, to someone already using the same proxy. Upgrade and verify the patch, or disable FTP. Query: technology="Squid Proxy"
⚠️ DifyTap: 4 Dify vulnerabilities that could expose AI conversations and files across tenants under certain conditions. Two require no auth. Highest-rated is CVE-2026-41948 (CVSS 9.4). Fixed in 1.14.2, except CVE-2026-41948 (next release). Query: product=dify
𝐒𝐭𝐚𝐝𝐢𝐮𝐦 𝐨𝐟 𝐒𝐡𝐚𝐝𝐨𝐰𝐬: 𝐈𝐧𝐬𝐢𝐝𝐞 𝐭𝐡𝐞 𝐈𝐏𝐓𝐕 𝐏𝐢𝐫𝐚𝐜𝐲 𝐖𝐨𝐫𝐥𝐝 The FIFA World Cup is the largest demand event illegal IPTV has ever faced. In the days around kickoff, our research team set out to map the infrastructure behind it. Full field report on the Modat research blog: www.modat.io/post/stadium...
CVE-2026-35273: Unauthenticated RCE in Oracle PeopleSoft PeopleTools (8.61, 8.62) via the Environment Management component. Remotely exploitable with no credentials, can lead to full system compromise. Patch immediately. Query: web.html~"Please click here to PeopleSoft logon page"
⚠️ CISA added CVE-2026-42271 to KEV: Command injection in LiteLLM gateway (1.74.2–1.83.7). MCP preview endpoints spawn attacker commands on the proxy host, gated only by an API key, so any authenticated user gets command execution. Patch to 1.83.7+. Query: product="LiteLLM API" OR product="LiteLLM"
We mapped 973,819 internet-exposed video services. 8,074 were streaming live with no password: thermal sensors on high-voltage equipment, server rooms, feeds in conflict zones. Not just a camera problem. Full research: www.modat.io/post/exposed...
⚠️CVE-2024-21182: Oracle WebLogic Server unauthenticated access via T3/IIOP now actively exploited & added to CISA KEV. Affects 12.2.1.4.0 & 14.1.1.0.0. Patch immediately or block port 7001. Query: web.headers~"WebLogic Server" magnify.modat.io
⚠️ Drupal announced an upcoming highly critical core security release (PSA-2026-05-18) affecting supported Drupal 10 & 11 branches. Details remain undisclosed, but exploits may emerge within hours of release. Reserve emergency patching time for May 20. Query: technology="Drupal"
⚠️ CVE-2026-42945 (CVSS 9.2): NGINX heap overflow in ngx_http_rewrite_module (≤1.30.0) is actively being exploited in the wild. Crafted HTTP requests via rewrite/if/set PCRE “?” can crash workers and may lead to RCE (ASLR off). Patch now to Nginx 1.31.0 or 1.30.1. Query: technology="Nginx"
⚠️ CVE-2026-44578: SSRF in self-hosted Next.js via the WebSocket upgrade handler allows unauthenticated access to internal services & cloud metadata endpoints using crafted absolute-form HTTP requests. Affected: 13.4.13+ to <15.5.16 / <16.2.5. Query: technology="Next.js" Platform: magnify.modat.io
️⚠ CVE-2026-7482: Critical heap out-of-bounds read in Ollama via crafted GGUF uploads to /api/create may leak API keys, prompts, credentials & conversation data from process memory. Affected: <0.17.1. Patch now. Query: product="Ollama" The platform: magnify.modat.io
⚠️ CVE-2026-23918: Double free in Apache HTTP Server 2.4.66 HTTP/2 may allow unauth RCE via crafted requests, risking full server compromise. Update to 2.4.67 or disable HTTP/2/restrict access. Query: web.headers="Server: Apache/2.4.66" The platform: magnify.modat.io
⚠️CVE-2025-71284 Synway SMG RCE via en/9-2radius.php(CVSS 9.8). Sed injection via radius_address+POST params enables unauth RCE. No patch. Query: (web.title="IPPBX" or web.html~"synwayjs") OR (web.html~"text ml10 mr20" and (web.title="网关管理软件" or web.title~"Gateway Management")) and tag!="Honeypot"
‼️CVE-2026-41940: cPanel & WHM Authentication Bypass (CVSS 9.8 Critical) A critical authentication bypass has been discovered in cPanel & WHM. Modat Magnify Query: (technology="cPanel" or web.html~"/cPanel_magic_revision_" or web.headers~"whostmgrrelogin") and tag!=honeypot
New Modat research: Belastingdienst-themed phishing hitting Dutch taxpayers, mostly aimed at crypto wallets. Notable shift: attackers ditching backends for direct Telegram bot exfil. Full research: www.modat.io/post/phishin...
Focusing on Iran's "blackout" misses the bigger picture. New research across 8 countries. Three strategies: mediation, deception, stabilisation. None of them silence. Read full research: www.modat.io/post/beyond-...
⚠️CVE-2026-34486: Fail-open regression in Tomcat Tribes may lead to unauth RCE. If TCP/4000 is reachable & gadget classes exist on the classpath, unencrypted packets can trigger code execution via bypassed encryption. Affected: 11.0.20, 10.1.53, 9.0.116. Update now! Query: technology="Apache Tomcat"
New research by Modat & Recorded Future reveals how attackers automate defense evasion in a modular cryptomining campaign. Explore the findings: www.modat.io/post/neutral...
⚠️ CVE-2026-33032 (CVSS 9.8) in Nginx UI ≤2.3.5 allows unauthenticated takeover via exposed /mcp_message endpoint (missing auth + fail-open IP whitelist). Attackers can control configs & service. No patch, restrict access now. Query: web.title~"nginx ui"
Citrix fixed CVE-2026-3055 (9.3) & CVE-2026-4368 (7.7) in NetScaler ADC/Gateway. A memory overread may leak data and a race condition can cause session mix-up. Check - (SAML IdP / Gateway / AAA). Query: product="Citrix Gateway" OR product="Citrix ADC" OR web.title~"NetScaler Gateway" tag!=honeypot
⚠️ CISA added CVE-2025-66376 to KEV after active exploitation of Zimbra Collaboration Suite. A stored XSS in the Classic UI allows script injection via HTML emails; opening them can trigger in-session execution and enable mailbox access or session hijacking. Query: product="Zimbra Collaboration"