Tenda routers ship a hidden backdoor password — CVE-2026-11405 unpatched
CERT/CC disclosed CVE-2026-11405 on July 6: five Tenda firmware images ship a plaintext strcmp() backdoor in /bin/httpd. Tenda didn't respond and no patch is available.
CERT/CC disclosed CVE-2026-11405 on July 6: five Tenda firmware images ship a plaintext strcmp() backdoor in /bin/httpd. Tenda didn't respond and no patch is available.
Ubiquiti's SAB-066 patches 25 UniFi flaws led by CVE-2026-50746 — an unauthenticated command injection in Connect ≤3.4.16 (CVSS 10.0). Fix ships in Connect 3.4.20.
CISA added CVE-2026-48908 (JoomShaper SP Page Builder) and CVE-2026-56290 (Page Builder CK) to KEV on July 7. Both CVSS 10.0, unauth file-upload to RCE. FCEB deadline: July 10.
Gitea's Docker template shipped REVERSE_PROXY_TRUSTED_PROXIES=* — any client can send X-WEBAUTH-USER: admin and impersonate any account. CVSS 9.8. Patched in 1.26.3, skip to 1.26.4.
Microsoft shipped Malware Protection Engine 1.1.26060.3008 on July 9 to close a race condition in mpengine.dll that hands SYSTEM to any local user. Public PoC has been circulating for a month.
A shadow-MMU use-after-free in KVM/x86 lets a root guest reach into the host on Intel VMX and AMD SVM. Stable kernels shipped the fix on July 4; embargo lifted July 6 with a public PoC.
CISA added the Langflow /api/v1/responses IDOR (CVE-2026-55255, CVSS 9.9) to KEV on July 7. Sysdig first observed exploitation on June 25. Third Langflow flaw to hit KEV in seven months.
KEVIntel logged in-the-wild exploitation of Adobe ColdFusion CVE-2026-48282 within two hours of watchTowr's July 2 technical writeup. Path traversal → RCE, pre-auth, CVSS 10.
Cisco advisory cisco-sa-catc-file-read-wLH2vf8X patches CVE-2026-20191, a CVSS 7.5 pre-auth path traversal in Catalyst Center. Fixed in 3.1.6 GSMU200 and 2.3.7.11-VA GSMU100. No workaround.