ELEVATED 1 min read 14 Jul 2026

AcyMailing Leads Today's Intel Queue

Today’s intelligence renders 87 source-linked findings (74 NEW, 13 UPDATED), prioritised by grounded severity and operational priority, led by the AcyMailing (Joomla) SQL injection CVE-2026-56292, then developer supply-chain, identity, platform, and infrastructure owner queues. 74 further items tracked below.

Key findings
01
NEW - A SQLi vulnerability in AcyMailing component < 10.11.1 for Joomla was discovered [NEW]
HIGH
[High] Classification: NEW; severity: CRITICAL; confidence: HIGH; identifiers: CVE-2026-56292. Identifiers: CVE-2026-56292. Severity: CRITICAL.
02
NEW - Metabase is an open-source business intelligence and embedded analytics tool. Pr [NEW]
HIGH
[High] Classification: NEW; severity: CRITICAL; confidence: HIGH; identifiers: CVE-2026-59827. Identifiers: CVE-2026-59827. Severity: CRITICAL.
03
UPDATED - UPDATE(severity_changed) - Officials once again warn defenders that Russian hackers are targeting network devices [UPDATED]
MEDIUM
[Medium] STATUS CHANGE: severity_changed. Classification: UPDATED; severity: CRITICAL; confidence: MEDIUM; identifiers: url:9c57461c27a0. Identifiers: none. Severity: CRITICAL.
04
NEW - [NEU] [hoch] Google Cloud Platform (BigQuery, Dataform, Colab Enterprise): Schwachstelle ermöglicht Privilegieneskalation [NEW]
HIGH
[High] Classification: NEW; severity: CRITICAL; confidence: HIGH; identifiers: WID-SEC-2026-2297, CVE-2026-14934. Identifiers: CVE-2026-14934. Severity: CRITICAL.
05
NEW - DIRAC is vulnerable to RCE in RequestManager due to eval on untrusted input [NEW]
MEDIUM
[Medium] Candidate retained with source-linked advisory metadata. Identifiers: CVE-2026-45579. Severity: CRITICAL.
06
NEW - Crawl4AI before 0.8.7 contains a server-side request forgery (SSRF) vulnerabilit [NEW]
HIGH
[High] Classification: NEW; severity: CRITICAL; confidence: HIGH; identifiers: CVE-2026-56261. Identifiers: CVE-2026-56261. Severity: CRITICAL.
07
NEW - DIRAC is vulnerable to RCE in FileCatalog DatasetManager via SQL injection + eva [NEW]
MEDIUM
[Medium] Candidate retained with source-linked advisory metadata. Identifiers: CVE-2026-61667. Severity: CRITICAL.
08
UPDATED - UPDATE(supplychainreach_expanded) - Hackers backdoor Jscrambler npm package with infostealer malware [UPDATED]
MEDIUM
[Medium] STATUS CHANGE: supplychainreach_expanded. Candidate retained with source-linked advisory metadata. Identifiers: none. Severity: HIGH.
09
NEW - The Booking Package plugin for WordPress is vulnerable to generic SQL Injection [NEW]
HIGH
[High] Candidate retained with source-linked advisory metadata. Identifiers: CVE-2026-15335. Severity: HIGH.
10
NEW - The LA-Studio Element Kit for Elementor plugin for WordPress is vulnerable to Lo [NEW]
HIGH
[High] Candidate retained with source-linked advisory metadata. Identifiers: CVE-2026-15338. Severity: HIGH.
11
NEW - The SureCart plugin for WordPress is vulnerable to privilege escalation via acco [NEW]
HIGH
[High] Candidate retained with source-linked advisory metadata. Identifiers: CVE-2026-7655. Severity: HIGH.
12
NEW - Discourse is an open-source discussion platform. Prior to 2026.6.0, 2026.5.1, 20 [NEW]
HIGH
[High] Classification: NEW; severity: HIGH; confidence: HIGH; identifiers: CVE-2026-55420. Identifiers: CVE-2026-55420. Severity: HIGH.
13
UPDATED - UPDATE(new_victim) - OAuth Client ID Spoofing: Why Fake Client IDs Are Gaining Traction for Stealthy Enumeration [UPDATED]
MEDIUM
[Medium] STATUS CHANGE: new_victim. Classification: UPDATE(scope); severity: HIGH; confidence: MEDIUM; identifiers: url:bc6768d5aeb4. Identifiers: none. Severity: HIGH.

Situation report

Findings 01-13 cover the release candidate queue: Finding 01 covers CVE-2026-56292; Finding 02 covers CVE-2026-59827; Finding 03 covers Russian FSB-linked targeting of Cisco network devices; Finding 04 covers CVE-2026-14934; Finding 05 covers CVE-2026-45579; Finding 06 covers CVE-2026-56261; Finding 07 covers CVE-2026-61667; Finding 08 covers the Jscrambler npm package backdoor report; Finding 09 covers CVE-2026-15335; Finding 10 covers CVE-2026-15338; Finding 11 covers CVE-2026-7655; Finding 12 covers CVE-2026-55420; Finding 13 covers OAuth client ID spoofing activity.

The Critical queue splits across internet-facing application risk, administrative cloud surfaces, scientific workload platforms, AI-adjacent tooling, and network-device attention from state-linked reporting. Route those first to owners who can confirm exposure, version state, authentication boundaries, and whether the affected component sits on a public or privileged path.

The High queue should move through dependency, CMS, forum, commerce, and identity teams without being collapsed into one generic patch lane. Jscrambler needs package, cache, CI, and workstation checks; the WordPress and SureCart items need site inventory ownership; Discourse needs platform maintainers; OAuth client ID spoofing belongs with identity monitoring and tenant-abuse detection.

cve-2026-14934cve-2026-15335cve-2026-15338cve-2026-45579cve-2026-55420cve-2026-56261cve-2026-56292cve-2026-59827cve-2026-61667cve-2026-7655

Act on this brief

Map detection coverage gaps for the techniques above, or generate Sigma rules from the named CVEs.