Xentrika Blog
Security insights, straight from the field.
Practical knowledge on penetration testing, cybersecurity, and digital defense from the Xentrika team.
Latest
CVE-2026-64633: Veeam ONE Agent RCE Needs No Password
Published August 6, 2026
A CVSS 10.0 code-injection vulnerability in Veeam ONE allows a remote, unauthenticated attacker to execute code on the agent host. No active exploitation is known, but affected systems should be upgraded to 13.1.0.7034 immediately.
CVE-2026-68771: ComfyUI Pickled Its Way to Unauthenticated RCE
Published August 3, 2026
An unsafe PyTorch deserialization path in ComfyUI allows unauthenticated attackers to execute arbitrary commands using a malicious pickle shard. CVSS 9.3; no public PoC or confirmed successful exploitation, although exploitation attempts are reportedly being tracked.
CVE-2026-63030 (wp2shell): One Bad REST Batch, One WordPress Shell
Published July 19, 2026
A CVSS 9.8 WordPress Core vulnerability chain lets unauthenticated attackers turn REST route confusion and SQL injection into remote code execution. Public PoCs are available, with early signs of in-the-wild activity reported.
CVE-2026-53359 (Januscape): The 16-Year-Old KVM Bug That Lets a Guest Own the Host
Published July 13, 2026
Januscape is a Linux KVM/x86 use-after-free that can turn nested virtualization into host-root code execution. Red Hat scores it CVSS 7.8; a host-crash PoC is public, while the full escape exploit remains withheld.
CVE-2026-48908: Joomla's Page Builder Handed Attackers the Keys, No Knock Required
Published June 26, 2026
A missing access check in SP Page Builder's icon-upload endpoint gave unauthenticated attackers direct RCE on every Joomla site running the extension. CVSS 10.0, actively exploited, patch available.
CVE-2026-36537: ThingsBoard OAuth Login Lets Attackers Become Any User
Published June 19, 2026
A CVSS 9.8 authentication bypass in ThingsBoard's Apple OAuth 2.0 flow lets a remote attacker impersonate an existing user and take over the account. A public PoC exists, while active exploitation has not been reported.
CVE-2026-20253: Splunk's PostgreSQL Sidecar Hands Out Shells. No Credentials Required
Published June 18, 2026
A CVSS 9.8 pre-authentication RCE in Splunk Enterprise's PostgreSQL sidecar service lets any network-reachable attacker chain file-write primitives into full code execution, with active exploitation reported within five days of disclosure.
CVE-2026-10520: Ivanti Sentry's Internal Config API Was Open to the Whole Internet
Published June 11, 2026
A perfect 10.0 pre-authenticated OS command injection in Ivanti Sentry lets any unauthenticated attacker execute arbitrary commands as root. Public PoC released June 10, 2026. Patch immediately.
CVE-2026-32625: LibreChat MCP Server Leaks Your Entire Secret Vault to Any Logged-In User
Published June 7, 2026
A critical (CVSS 9.6) information-disclosure flaw in LibreChat lets any authenticated user exfiltrate JWT signing keys, AES encryption keys, and database credentials by injecting environment-variable placeholders into a malicious MCP server URL. Patched in v0.8.4-rc1.
CVE-2026-0073: Zero-Click RCE in Android's Wireless ADB Authentication
Published May 9, 2026
A logic error in Android's ADB daemon lets an adjacent-network attacker bypass mutual TLS authentication and open a remote shell on any unpatched Android 14–16 device, no user interaction required.