The
Reassessment
Feed.

All ↑ Upgraded ↓ Downgraded = Unchanged
Sort
All reassessments
showing 1–20 of 1,582
2026-07-27
CVE-2026-61511
CWE-95
vBulletin < 6.2.2 Eval Injection RCE via vb5/template/runtime.php
Pre-auth eval injection RCE in internet-facing forum software — zero friction, patch or pull offline now.
CRITICAL 9.3 = CRITICAL
2026-07-27
CVE-2026-16723
CWE-20
A remote code execution (RCE) vulnerability exists in fastjson 1.2.68 through 1.2.83.
Unpatched zero-day RCE in fastjson 1.x under active exploitation — no vendor fix exists yet
CRITICAL 9.0 = CRITICAL
EPSS 0.00
2026-07-27
CVE-2026-49176
CWE-59
Improper privilege management in Windows WalletService
Local-only symlink LPE in a consumer wallet service — patch in cycle, not in a panic.
HIGH 7.8 ↓ MEDIUM
EPSS 0.00
2026-07-25
CVE-2026-58630
CWE-284
Improper access control in Azure App Service
Vendor's 10.0 assumes public Azure App Service. This only touches Azure Stack Hub — small footprint, big blast per tenant.
CRITICAL 10.0 ↓ HIGH
2026-07-25
CVE-2026-62835
CWE-285
Improper authorization in Azure Portal
Microsoft already patched this server-side. There is no package to deploy — your only job is a log review for historical exposure.
CRITICAL 9.3 ↓ LOW
2026-07-25
CVE-2026-61884
CWE-288
The web management interface of Tycon Systems TPDIN-Monitor-WEB2  does not perform server-side validation of credentials during the login p
Unauth admin bypass on an abandoned OT monitor with no patch — CRITICAL on paper, HIGH in reality because exposure is small but blast radius is physical
CRITICAL 9.8 ↓ HIGH
2026-07-24
CVE-2026-60206
CWE-287
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily
Low-priv SAML abuse with scope change on WebLogic Core — the historical bullseye of the CISA KEV catalog. Patch, don't wait.
CRITICAL 9.9 = CRITICAL
2026-07-24
CVE-2026-60199
CWE-306
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core).
Unauthenticated HTTP RCE on a middleware tier that historically lives at the edge — Oracle's 9.8 stands. Patch cycle starts now.
CRITICAL 9.8 = CRITICAL
EPSS 0.00
2026-07-24
CVE-2026-60315
CWE-400
Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: X Plugin). Supported versions that are affected are MySQL Server: 8.4.0-8.4.10, 9.7.0-9.7.1; MySQL Cluster
Unauthenticated remote DoS against MySQL 8.4/9.7 via X Plugin — a production database crash bug, not a data-theft bug.
HIGH 8.2 = HIGH
2026-07-24
CVE-2026-62825
CWE-287
Improper authentication in Azure Key Vault
Cloud-side patch by Microsoft, but the blast radius is every secret, cert, and key you ever put in a Vault. Verify tenant posture now.
CRITICAL 10.0 = CRITICAL
2026-07-24
CVE-2026-54121
CWE-285
Improper authorization in Active Directory Certificate Services (AD CS)
AD CS + improper authz + low-priv remote = certificate-based DA. Vendor's 8.8 undersells this. Patch inside the noisgate 3-day mitigation window.
HIGH 8.8 ↑ CRITICAL
EPSS 0.01
2026-07-24
CVE-2025-66376
CWE-79
Zimbra Collaboration (ZCS) 10 before 10.0.18 and 10.1 before 10.1.13
Zero-click webmail XSS, actively weaponized by Russian APT against NATO mailboxes, KEV-listed. Vendor's 7.2 undershoots reality.
HIGH 7.2 ↑ CRITICAL
EPSS 0.12 KEV
2026-07-23
tenable:80101
CWE-522
IPMI v2.0 Password Hash Disclosure
Design flaw in IPMI 2.0 spec — no patch exists. On exposed BMCs it's a straight path to lights-out root and hypervisor takeover.
HIGH 7.8 = HIGH
2026-07-23
CVE-2026-16232
CWE-287
An authentication bypass vulnerability in the Check Point SmartConsole login process
KEV-listed, actively exploited authentication bypass on a network-edge management plane — patch in hours, not days.
CRITICAL 9.1 = CRITICAL
KEV
2026-07-23
CVE-2026-7120
CWE-180
@fastify/static vulnerable to Authorization Bypass via Non-Canonical URL Paths
Vendor got this one right. MEDIUM stays MEDIUM — but only if you're actually using route guards in front of @fastify/static.
MEDIUM 5.3 = MEDIUM
2026-07-23
CVE-2026-15074
CWE-22
@fastify/static vulnerable to route guard bypass via path traversal
Route guard bypass in a Node.js static-file plugin. Only bites apps that put auth in front of @fastify/static and store secrets in the served dir.
HIGH 7.5 ↓ MEDIUM
2026-07-23
tenable:326244
CWE-416
OpenSSH < 10.4 Multiple Vulnerabilities
Eight OpenSSH bugs, zero pre-auth RCE. Worst case needs users to SSH to an attacker-controlled server. Patch on the quarterly train.
HIGH 9.4 ↓ MEDIUM
2026-07-23
tenable:316482
CWE-73
Grafana Labs < 11.6.14+security-04 / 12.2.0 < 12.2.8+security-...
Grafana RCE is real but chain needs Enterprise plugin + feature toggle + creds; DoS is unauth but 'only' DoS. Keep at HIGH.
HIGH 9.1 = HIGH
2026-07-23
tenable:297198
CWE-833
Grafana Labs 3.0.0 < 11.6.9+security-01 / 12.0.0 < 12.0.8+secu...
Goroutine leak in Grafana's Gravatar handler. DoS-only, internal-facing service, no RCE — downgrade to MEDIUM.
HIGH 7.5 ↓ MEDIUM
2026-07-23
tenable:242626
CWE-200
Grafana Labs Integration URL Exposed to Viewers (CVE-2025-3415)
A Viewer-only DingDing webhook leak in Grafana. Real risk is low unless you actually use DingDing and mistrust your Viewers.
MEDIUM 4.3 ↓ LOW