[{"_id":"6a57bee97504778190e6065a","cveID":"CVE-2026-46817","dateAdded":"2026-07-15","dueDate":"2026-07-18","notes":"https://www.oracle.com/security-alerts/cspumay2026.html ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2026-46817","product":"E-Business Suite","requiredAction":"Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.","shortDescription":"Oracle E-Business Suite contains an improper privilege management vulnerability that allows an unauthenticated attacker with network access via HTTP to compromise Oracle Payments. Successful attacks of this vulnerability can result in takeover of Oracle Payments.","vendorProject":"Oracle","vulnerabilityName":"Oracle E-Business Suite Improper Privilege Management Vulnerability","nvdData":[{"attackVector":"NETWORK","attackComplexity":"LOW","baseSeverity":"CRITICAL","exploitabilityScore":3.9,"baseScore":9.8,"nvdReferences":[{"url":"https://www.oracle.com/security-alerts/cspumay2026.html","source":"secalert_us@oracle.com","tags":["Vendor Advisory"]}],"vulnStatus":"Analyzed"}],"githubPocs":["https://github.com/HORKimhab/CVE-2026-46817","https://github.com/0xBlackash/CVE-2026-46817"],"openThreatData":[{"adversaries":[],"malwareFamiles":[],"affectedIndustries":[],"communityAdversaries":[],"communityMalwareFamilies":[],"communityAffectedIndustries":[]}],"knownRansomwareCampaignUse":"Unknown"},{"_id":"6a57bee97504778190e6065b","cveID":"CVE-2023-4346","dateAdded":"2026-07-15","dueDate":"2026-07-29","notes":"https://www.cisa.gov/news-events/ics-advisories/icsa-23-236-01 ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2023-4346","product":"KNX Protocol Connection Authorization Option 1","requiredAction":"Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.","shortDescription":"KNX Association KNX Protocol Connection Authorization Option 1 contains an overly restrictive account lockout mechanism vulnerability that could allow an attacker to purge all devices without additional security options enabled and set a BCU key to lock the device. ","vendorProject":"KNX Association","vulnerabilityName":"KNX Association KNX Protocol Connection Authorization Option 1 Overly Restrictive Account Lockout Mechanism Vulnerability","nvdData":[{"attackVector":"NETWORK","attackComplexity":"LOW","baseSeverity":"HIGH","exploitabilityScore":3.9,"baseScore":7.5,"nvdReferences":[{"url":"https://www.cisa.gov/news-events/ics-advisories/icsa-23-236-01","source":"ics-cert@hq.dhs.gov","tags":["Third Party Advisory","US Government Resource"]},{"url":"https://www.cisa.gov/news-events/ics-advisories/icsa-23-236-01","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory","US Government Resource"]}],"vulnStatus":"Modified"}],"githubPocs":[],"openThreatData":[{"adversaries":[],"malwareFamiles":[],"affectedIndustries":[],"communityAdversaries":[],"communityMalwareFamilies":[],"communityAffectedIndustries":[]}],"knownRansomwareCampaignUse":"Unknown"},{"_id":"6a591e79f177f3de7ce9962c","cveID":"CVE-2026-58644","dateAdded":"2026-07-16","dueDate":"2026-07-19","notes":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-58644 ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2026-58644","product":"SharePoint","requiredAction":"Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.","shortDescription":"Microsoft SharePoint contains a deserialization of untrusted data vulnerability that allows an unauthorized attacker to execute code over a network.","vendorProject":"Microsoft","vulnerabilityName":"Microsoft SharePoint Deserialization of Untrusted Data Vulnerability","nvdData":[{"attackVector":"NETWORK","attackComplexity":"LOW","baseSeverity":"CRITICAL","exploitabilityScore":3.9,"baseScore":9.8,"nvdReferences":[{"url":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-58644","source":"secure@microsoft.com","tags":["Patch","Vendor Advisory"]},{"url":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-58644","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","tags":["US Government Resource"]}],"vulnStatus":"Analyzed"}],"githubPocs":[],"openThreatData":[{"adversaries":[],"malwareFamiles":[],"affectedIndustries":[],"communityAdversaries":[],"communityMalwareFamilies":[],"communityAffectedIndustries":[]}],"knownRansomwareCampaignUse":"Unknown"},{"_id":"6a591e79f177f3de7ce9962d","cveID":"CVE-2026-25089","dateAdded":"2026-07-16","dueDate":"2026-07-19","notes":"https://fortiguard.fortinet.com/psirt/FG-IR-26-141 ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2026-25089","product":"FortiSandbox","requiredAction":"Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.","shortDescription":"Fortinet FortiSandbox, FortiSandbox Cloud, and FortiSandbox PaaS contain an OS command injection vulnerability that allows an unauthenticated attacker to execute unauthorized commands via specifically crafted HTTP requests.","vendorProject":"Fortinet","vulnerabilityName":"Fortinet FortiSandbox OS Command Injection Vulnerability","nvdData":[{"attackVector":"NETWORK","attackComplexity":"LOW","baseSeverity":"CRITICAL","exploitabilityScore":3.9,"baseScore":9.8,"nvdReferences":[{"url":"https://fortiguard.fortinet.com/psirt/FG-IR-26-141","source":"psirt@fortinet.com","tags":["Vendor Advisory"]},{"url":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-25089","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","tags":["US Government Resource"]}],"vulnStatus":"Analyzed"}],"githubPocs":["https://github.com/0xBlackash/CVE-2026-25089","https://github.com/HORKimhab/CVE-2026-25089"],"openThreatData":[{"adversaries":[],"malwareFamiles":["Ekz infostealer","Cyberstrike harvester"],"affectedIndustries":["Healthcare","Finance","Defense","Transportation","Technology","Manufacturing","Energy","Retail","Government","Education","Telecommunications","Hospitality"],"communityAdversaries":["Operation DragonReturn, Nemesys, PamStealer, StrikeShark, JADEPUFFER, Fake Chrome and Firefox Extens"],"communityMalwareFamilies":["Ekz infostealer","Cyberstrike harvester"],"communityAffectedIndustries":["Healthcare","Finance","Defense","Transportation","Technology","Manufacturing","Energy","Critical infrastructure","Retail","Government","Education","Telecommunications","Hospitality"]}],"knownRansomwareCampaignUse":"Unknown"},{"_id":"6a591e79f177f3de7ce9962e","cveID":"CVE-2026-39808","dateAdded":"2026-07-16","dueDate":"2026-07-19","notes":"https://fortiguard.fortinet.com/psirt/FG-IR-26-100 ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2026-39808","product":"FortiSandbox","requiredAction":"Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.","shortDescription":"Fortinet FortiSandbox contains an OS command injection vulnerability that could allow an unauthenticated attacker to execute unauthorized code or commands via crafted HTTP requests.","vendorProject":"Fortinet","vulnerabilityName":"Fortinet FortiSandbox OS Command Injection Vulnerability","nvdData":[{"attackVector":"NETWORK","attackComplexity":"LOW","baseSeverity":"CRITICAL","exploitabilityScore":3.9,"baseScore":9.8,"nvdReferences":[{"url":"https://fortiguard.fortinet.com/psirt/FG-IR-26-100","source":"psirt@fortinet.com","tags":["Vendor Advisory"]},{"url":"https://github.com/samu-delucas/CVE-2026-39808","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","tags":["Exploit","Third Party Advisory"]},{"url":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-39808","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","tags":["US Government Resource"]}],"vulnStatus":"Analyzed"}],"githubPocs":["https://github.com/error-inside/CVE-2026-39808","https://github.com/HORKimhab/CVE-2026-39808","https://github.com/ynsmroztas/FortiSandbox-RCE-Exploit-CVE-2026-39808","https://github.com/0xBlackash/CVE-2026-39808","https://github.com/samu-delucas/CVE-2026-39808"],"openThreatData":[{"adversaries":[],"malwareFamiles":[],"affectedIndustries":[],"communityAdversaries":["Operation DragonReturn, Nemesys, PamStealer, StrikeShark, JADEPUFFER, Fake Chrome and Firefox Extens"],"communityMalwareFamilies":[],"communityAffectedIndustries":["Critical infrastructure"]}],"knownRansomwareCampaignUse":"Unknown"},{"_id":"6a5f8bc9e0cf1d3ecc4a916b","cveID":"CVE-2026-60137","dateAdded":"2026-07-21","dueDate":"2026-08-04","notes":"https://wordpress.org/news/2026/07/wordpress-7-0-2-release/ ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2026-60137","product":"Core","requiredAction":"Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.","shortDescription":"WordPress Core contains a SQL injection vulnerability when a plugin or theme passes untrusted input to the parameter. This vulnerability can be chained with CVE-2026-63030 to allow an unauthenticated attacker to gain remote code execution on default WordPress installations.","vendorProject":"WordPress","vulnerabilityName":"WordPress Core SQL Injection Vulnerability","nvdData":[{"attackVector":"NETWORK","attackComplexity":"HIGH","baseSeverity":"MEDIUM","exploitabilityScore":2.2,"baseScore":5.9,"nvdReferences":[{"url":"https://github.com/WordPress/wordpress-develop/security/advisories/GHSA-fpp7-x2x2-2mjf","source":"contact@wpscan.com","tags":["Vendor Advisory"]},{"url":"https://wordpress.org/news/2026/07/wordpress-7-0-2-release/","source":"contact@wpscan.com","tags":["Release Notes"]},{"url":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-60137","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","tags":["US Government Resource"]}],"vulnStatus":"Analyzed"}],"githubPocs":["https://github.com/codeb0ssx/Ultimate-wp2shell","https://github.com/ebrasha/abdal-cve-2026-60137","https://github.com/yoerivegt/wp2shell-poc","https://github.com/h4cd0c/wp2shell"],"openThreatData":[{"adversaries":[],"malwareFamiles":[],"affectedIndustries":[],"communityAdversaries":[],"communityMalwareFamilies":[],"communityAffectedIndustries":[]}],"knownRansomwareCampaignUse":"Unknown"},{"_id":"6a5f8bc9e0cf1d3ecc4a916c","cveID":"CVE-2026-63030","dateAdded":"2026-07-21","dueDate":"2026-07-24","notes":"https://wordpress.org/news/2026/07/wordpress-7-0-2-release/ ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2026-63030","product":"Core","requiredAction":"Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.","shortDescription":"WordPress Core contains an interpretation conflict vulnerability that could allow an attacker to perform SQL Injection and achieve Remote Code Execution. This vulnerability can be chained with CVE-2026-60137.","vendorProject":"WordPress","vulnerabilityName":"WordPress Core Interpretation Conflict Vulnerability","nvdData":[{"attackVector":"NETWORK","attackComplexity":"LOW","baseSeverity":"CRITICAL","exploitabilityScore":3.9,"baseScore":9.8,"nvdReferences":[{"url":"https://github.com/WordPress/wordpress-develop/security/advisories/GHSA-ff9f-jf42-662q","source":"contact@wpscan.com","tags":["Vendor Advisory"]},{"url":"https://wordpress.org/news/2026/07/wordpress-7-0-2-release/","source":"contact@wpscan.com","tags":["Release Notes"]},{"url":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-63030","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","tags":["US Government Resource"]}],"vulnStatus":"Analyzed"}],"githubPocs":["https://github.com/Ch4120N/CVE-2026-63030","https://github.com/lucifer0xf/wp2shell-Wordpress-TOWN","https://github.com/ASYquan/wp2shell-cf-WAF-bypass","https://github.com/OffByOn3/wp2shell-poc","https://github.com/SentinelXofficial/sxwp2shell","https://github.com/0xjessie21/wp2shell-checker","https://github.com/administrator-01001/CVE-2026-63030","https://github.com/Crypto-Cat/wp2shell","https://github.com/ZenithGenius/wordpress-batch-rce-lab","https://github.com/vulnquest58/PressVector","https://github.com/skelersecurity/wordpress-skelersecurity-core-security-CVE-2026-63030","https://github.com/Lukols-Dev/wp-cve-2026-63030-check","https://github.com/ananay/wp2shell-lab","https://github.com/hidden-investigations/wp2shell-scanner","https://github.com/InstaWP/wp2shell-scan","https://github.com/4B3R4M4-607D/CVE-2026-63030-POC","https://github.com/eyesecurity/wp2shell-compromise-scanner-plugin","https://github.com/bahartanir/wp2shell-scanner","https://github.com/ikow/wp2shell","https://github.com/c0gnit00/Wp2Shell","https://github.com/mhtsec/CVE-2026-63030","https://github.com/JohenLastGen-JLG/wp2shell","https://github.com/own2pwn-fr/wp2shell-detect","https://github.com/ChiefYoru/CVE-2026-63030_PoC","https://github.com/fullhunt/wp2shell-scan","https://github.com/securelayer7/WordPresShell","https://github.com/ebrasha/abdal-cve-2026-63030","https://github.com/zi3lak/wp2shell_scanner","https://github.com/0xWhoknows/wp2shell","https://github.com/0xBlackash/CVE-2026-63030","https://github.com/gbrsh/CVE-2026-63030","https://github.com/J4ck3LSyN-Gen2/CVE-2026-63030-wp2r00t","https://github.com/0xsha/wp2shell","https://github.com/mverschu/CVE-2026-63030","https://github.com/4minx/CVE-2026-63030","https://github.com/kulichr/wp2shell","https://github.com/NULL200OK/WP2Shell","https://github.com/ekomsSavior/wp2shell","https://github.com/Lutfifakee-Project/wp2shell","https://github.com/47Cid/wp2shell-lab","https://github.com/dinosn/wp2shell-lab","https://github.com/Senanfurkan/wordpress-cve-2026-63030","https://github.com/ZephrFish/wp2shell-scanner","https://github.com/attackercan/wp2shell-poc2","https://github.com/Icex0/wp2shell-poc"],"openThreatData":[{"adversaries":[],"malwareFamiles":[],"affectedIndustries":[],"communityAdversaries":[],"communityMalwareFamilies":[],"communityAffectedIndustries":[]}],"knownRansomwareCampaignUse":"Unknown"},{"_id":"6a5f8bc9e0cf1d3ecc4a916d","cveID":"CVE-2026-0770","dateAdded":"2026-07-21","dueDate":"2026-07-24","notes":"https://github.com/langflow-ai/langflow/releases/tag/v1.9.0 ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2026-0770 ","product":"Langflow","requiredAction":"Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.","shortDescription":"Langflow contains an inclusion of functionality from untrusted control sphere vulnerability that allows remote attackers to execute arbitrary code on affected installations. ","vendorProject":"Langflow","vulnerabilityName":"Langflow Inclusion of Functionality from Untrusted Control Sphere Vulnerability","nvdData":[],"githubPocs":["https://github.com/diamorphine666/CVE-2026-0770","https://github.com/Ez4rd1x1/CVE-2026-0770","https://github.com/0xBlackash/CVE-2026-0770","https://github.com/0xgh057r3c0n/CVE-2026-0770","https://github.com/affix/CVE-2026-0770-PoC"],"openThreatData":[{"adversaries":[],"malwareFamiles":[],"affectedIndustries":[],"communityAdversaries":[],"communityMalwareFamilies":[],"communityAffectedIndustries":["Iot"]}],"knownRansomwareCampaignUse":"Unknown"},{"_id":"6a5f8bc9e0cf1d3ecc4a916e","cveID":"CVE-2021-27137","dateAdded":"2026-07-21","dueDate":"2026-07-24","notes":"This vulnerability affects a common open-source component, third-party library, proprietary implementation, or a protocol used by different products. Please check with specific vendors for information on patching status. For more information, please see: https://svn.dd-wrt.com/changeset/45724 ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2021-27137","product":"DD-WRT","requiredAction":"Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.","shortDescription":"DD-WRT contains a stack-based buffer overflow vulnerability that could allow an unauthenticated attacker to overflow an internal buffer used by UPnP and trigger a code execution vulnerability.","vendorProject":"DD-WRT","vulnerabilityName":"DD-WRT Stack-Based Buffer Overflow Vulnerability","nvdData":[{"attackVector":"NETWORK","attackComplexity":"HIGH","baseSeverity":"HIGH","exploitabilityScore":2.2,"baseScore":8.1,"nvdReferences":[{"url":"https://securityaffairs.com/193290/uncategorized/iot-botnet-c0xmo-adds-competitor-killing-capability.html","source":"cve@mitre.org","tags":["Exploit","Third Party Advisory"]},{"url":"https://ssd-disclosure.com/ssd-advisory-dd-wrt-upnp-buffer-overflow/","source":"cve@mitre.org","tags":["Exploit","Third Party Advisory"]},{"url":"https://svn.dd-wrt.com/changeset/45724","source":"cve@mitre.org","tags":["Patch"]},{"url":"https://www.bleepingcomputer.com/news/security/c0xmo-botnet-spreads-via-dd-wrt-router-flaw-kills-rival-malware/","source":"cve@mitre.org","tags":["Exploit","Third Party Advisory"]},{"url":"https://www.fortinet.com/blog/threat-research/inside-cross-platform-propagation-of-new-gafgyt-variant-c0xmo","source":"cve@mitre.org","tags":["Exploit"]},{"url":"https://ssd-disclosure.com/ssd-advisory-dd-wrt-upnp-buffer-overflow/","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","tags":["Exploit","Third Party Advisory"]},{"url":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2021-27137","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","tags":["US Government Resource"]}],"vulnStatus":"Analyzed"}],"githubPocs":[],"openThreatData":[{"adversaries":[],"malwareFamiles":["Gafgyt","C0xmo"],"affectedIndustries":["Technology"],"communityAdversaries":[],"communityMalwareFamilies":["Gafgyt","C0xmo"],"communityAffectedIndustries":["Technology"]}],"knownRansomwareCampaignUse":"Unknown"}]