RedPacket Security
Online/Digital
Actions
Media Outlet details
| Scope | National |
|---|---|
| Language | English |
| Country | United Kingdom |
|
Similarweb UVM |
Request pricing |
|
Comscore UVM |
Request pricing |
Recent Articles
Search ArticlesCVE Alert: CVE-2026-108746 – Vearch – vearch
HIGHNo exploitation known Vearch 3.5.2 through 3.5.9 contains an incorrect authorization vulnerability in Role.HasPermissionForResources that ignores stored ReadOnly or None privilege levels for resources listed in a role. Authenticated non-root users can upsert and delete documents with read-only access, or call PUT /roles to grant their role WriteRead privileges, escalating toward cluster administrator access.
CVE Alert: CVE-2026-108744 – MinaSaad1 – pbi-cli
HIGHNo exploitation known pbi-cli 3.10.1 through 3.12.0 contains an OS command injection vulnerability in desktop_sync.py that passes unquoted .pbip paths to cmd /c start when reopening projects. Attackers can lure victims into opening a Power BI project from a space-free path containing & to run commands with victim privileges during report write or reload.
CVE Alert: CVE-2026-108739 – openagents-org – OpenAgents
HIGHNo exploitation known OpenAgents Workspace backend through launcher-v1.0.17 contains an information disclosure vulnerability that allows unauthenticated attackers to list all workspaces via GET /v1/workspaces. Attackers can read the unmasked browserfabric_api_key in each workspace’s settings map, along with workspace ids, slugs, creator emails and member lists.
CVE Alert: CVE-2026-108714 – modelcontextprotocol – kotlin-sdk
HIGHNo exploitation known MCP Kotlin SDK through 0.15.0 contains an uncontrolled memory allocation vulnerability that allows remote clients to exhaust server memory because Application.mcpWebSocket installs Ktor WebSockets without a maxFrameSize limit. Attackers can send small frame headers declaring payloads near 2 GiB over one or a few connections, forcing huge heap allocations and causing denial of service.
CVE Alert: CVE-2026-108571 – Xinhu – Rainrock RockOA
HIGHNo exploitation known A weakness has been identified in Xinhu Rainrock RockOA up to 2.7.6. This impacts the function kqjcmdModel::returnchuli of the file webmain/task/openapi/openkqjAction.php of the component Openkqj Action. This manipulation of the argument ID causes sql injection. The attack is possible to be carried out remotely. The exploit has been made available to the public and could be used for attacks.
CVE Alert: CVE-2026-108718 – Rill Data – rill
HIGHNo exploitation known Rill 0.77.0 through 0.90.5 contains a missing authorization vulnerability in the admin OAuth server that issues authorization codes to dynamically registered clients without user consent. Attackers can register a client with the long_lived_access_token scope and lure a user to an authorization link, obtaining a non-expiring API token with the user’s full permissions.
CVE Alert: CVE-2026-108740 – arp242 – GoatCounter
HIGHNo exploitation known GoatCounter through 2.7.0 contains a mass assignment privilege escalation vulnerability in the userPrefSave handler that allows logged-in users to modify protected account fields via form-encoded requests. Attackers with read-only access can POST user.access[all]=* and user.email_verified=true to /user/pref, bypassing readonly tags to gain superuser or admin access.
[QILIN] – Ransomware Victim: CNESTEN
Verification alert Listings attributed to QILIN have been reported as including unverified or fabricated victim claims. Treat this post as unconfirmed until corroborated with independent evidence. See further information here: BankInfoSecurity NOTE: No files or stolen information are exfiltrated, downloaded, taken, hosted, seen, reposted, or disclosed by RedPacket Security. Any legal issues relating to the content should be directed at the attackers, not RedPacket Security.
[QILIN] – Ransomware Victim: Friendship Christian School
Verification alert Listings attributed to QILIN have been reported as including unverified or fabricated victim claims. Treat this post as unconfirmed until corroborated with independent evidence. See further information here: BankInfoSecurity NOTE: No files or stolen information are exfiltrated, downloaded, taken, hosted, seen, reposted, or disclosed by RedPacket Security. Any legal issues relating to the content should be directed at the attackers, not RedPacket Security.
CVE Alert: CVE-2026-108708 – WuKongOpenSource – Wukong_HRM
HIGHNo exploitation known Wukong_HRM through commit 186115e contains a missing authorization vulnerability because EmployeeAspect assigns every caller the HR administrator role and EmployeeUtil data-scope checks return all employees. Any authenticated low-privileged employee can read payslips, salary records, bank cards and personal data, edit bank cards, and delete employees, departments and contracts company-wide.