Executive assessment
Today's brief leads with n8n Sandbox Escape Lets Workflow Editors Run OS Commands as the n8n Process. All 15 selected findings retain their own technical scope, action, observed status, and evidence limits.
Finding 01 — n8n Sandbox Escape Lets Workflow Editors Run OS Commands as the n8n Process
What changed: n8n has patched a high-severity expression-sandbox escape that could let an authenticated workflow editor execute operating-system commands on the server running the automation platform. Security Joes found the flaw while probing n8n's February fix for CVE-2026-27577 for another bypass.
Technical evidence: CVE-2026-27577; CVSS v4.0 9.4; weakness ['CWE-94']; technical confidence High.
Why it matters: The Critical priority moves this beyond routine tracking and requires exposure validation, remediation, and compromise assessment.
Observed status: Observed in-the-wild exploitation status is unknown.
Action: Map CVE-2026-27577 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.
Evidence limits: exploitation status unknown
fixed version or patch state unknown
affected product not structured
[Evidence source: thehackernews.com](<https://thehackernews.com/2026/07/n8n-sandbox-escape-lets-workflow.html>)
Finding 02 — CVE-2026-30815: An OS command injection vulnerability in the OpenVPN module of TP-Link Archer AX…
What changed: An OS command injection vulnerability in the OpenVPN module of TP-Link Archer AX53 v1.0 allows an authenticated adjacent attacker to execute system commands when a specially crafted configuration file is processed due to insufficient input validation. Successful exploitation may allow modification of configuration files, disclosure of sensitive information, or further compromise of device integrity.
Technical evidence: CVE-2026-30815; CVSS v4.0 8.5; weakness ['CWE-78']; technical confidence High.
Why it matters: The High priority moves this beyond routine tracking and requires exposure validation, remediation, and compromise assessment.
Observed status: Observed in-the-wild exploitation status is unknown.
Action: Map CVE-2026-30815 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.
Evidence limits: exploitation status unknown
fixed version or patch state unknown
[Evidence source: nvd.nist.gov](<https://nvd.nist.gov/vuln/detail/CVE-2026-30815>)
Finding 03 — CVE-2026-30814: A stack-based buffer overflow in the tmpServer module of TP-Link Archer AX53 v1.
What changed: A stack-based buffer overflow in the tmpServer module of TP-Link Archer AX53 v1.0 allows an authenticated adjacent attacker to trigger a segmentation fault and potentially execute arbitrary code via a specially crafted configuration file. Successful exploitation may cause a crash and could allow arbitrary code execution, enabling modification of device state, exposure of sensitive data, or further compromise of device integrity.
Technical evidence: CVE-2026-30814; CVSS v4.0 7.3; weakness ['CWE-121']; technical confidence High.
Why it matters: The High priority moves this beyond routine tracking and requires exposure validation, remediation, and compromise assessment.
Observed status: Observed in-the-wild exploitation status is unknown.
Action: Map CVE-2026-30814 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.
Evidence limits: exploitation status unknown
fixed version or patch state unknown
affected product not structured
[Evidence source: nvd.nist.gov](<https://nvd.nist.gov/vuln/detail/CVE-2026-30814>)
Finding 04 — CVE-2026-30818: An OS command injection vulnerability in the dnsmasq module of TP-Link Archer AX…
What changed: An OS command injection vulnerability in the dnsmasq module of TP-Link Archer AX53 v1.0 allows an authenticated adjacent attacker to execute arbitrary code when a specially crafted configuration file is processed due to insufficient input validation. Successful exploitation may allow the attacker to modify device configuration, access sensitive information, or further compromise system integrity.
Technical evidence: CVE-2026-30818; CVSS v4.0 8.5; weakness ['CWE-78']; technical confidence High.
Why it matters: The High priority moves this beyond routine tracking and requires exposure validation, remediation, and compromise assessment.
Observed status: Observed in-the-wild exploitation status is unknown.
Action: Map CVE-2026-30818 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.
Evidence limits: exploitation status unknown
fixed version or patch state unknown
affected product not structured
[Evidence source: nvd.nist.gov](<https://nvd.nist.gov/vuln/detail/CVE-2026-30818>)
Finding 05 — CVE-2025-52222: D-Link DI-8003 v16.07.26A1, DI-8500 v16.07.26A1; DI-8003G v17.12.21A1, DI-8200G…
What changed: D-Link DI-8003 v16.07.26A1, DI-8500 v16.07.26A1; DI-8003G v17.12.21A1, DI-8200G v17.12.20A1, DI-8200 v16.07.26A1, DI-8400 v16.07.26A1, DI-8004w v16.07.26A1, DI-8100 v16.07.26A1, and DI-8100G v17.12.20A1 were discovered to contain a buffer overflow via the rden, rdauth, rdacct, httphadmin, httphadminpwd, rdkey, and rdip parameters in the radiusasp function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted request.
Technical evidence: CVE-2025-52222; CVSS v3.1 7.5; weakness ['CWE-120']; technical confidence High.
Why it matters: The High priority moves this beyond routine tracking and requires exposure validation, remediation, and compromise assessment.
Observed status: Observed in-the-wild exploitation status is unknown.
Action: Map CVE-2025-52222 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.
Evidence limits: exploitation status unknown
fixed version or patch state unknown
affected product not structured
[Evidence source: nvd.nist.gov](<https://nvd.nist.gov/vuln/detail/CVE-2025-52222>)
Finding 06 — CVE-2025-50650: A buffer overflow vulnerability exists in D-Link DI-8003 16.07.26A1…
What changed: A buffer overflow vulnerability exists in D-Link DI-8003 16.07.26A1 due to inadequate validation of input size in the routesstatic parameter in the /router.asp endpoint. CVE coverage: CVE-2025-50650.
Technical evidence: CVE-2025-50650; CVSS v3.1 7.5; weakness ['CWE-120']; technical confidence High.
Why it matters: The High priority moves this beyond routine tracking and requires exposure validation, remediation, and compromise assessment.
Observed status: Observed in-the-wild exploitation status is unknown.
Action: Map CVE-2025-50650 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.
Evidence limits: exploitation status unknown
fixed version or patch state unknown
affected product not structured
[Evidence source: nvd.nist.gov](<https://nvd.nist.gov/vuln/detail/CVE-2025-50650>)
Finding 07 — CVE-2025-50653: A buffer overflow vulnerability exists in D-Link DI-8003 16.07.26A1…
What changed: A buffer overflow vulnerability exists in D-Link DI-8003 16.07.26A1 due to improper handling of the name and mem parameters in the /timegroup.asp endpoint. CVE coverage: CVE-2025-50653.
Technical evidence: CVE-2025-50653; CVSS v3.1 7.5; weakness ['CWE-120']; technical confidence High.
Why it matters: The High priority moves this beyond routine tracking and requires exposure validation, remediation, and compromise assessment.
Observed status: Observed in-the-wild exploitation status is unknown.
Action: Map CVE-2025-50653 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.
Evidence limits: exploitation status unknown
fixed version or patch state unknown
affected product not structured
[Evidence source: nvd.nist.gov](<https://nvd.nist.gov/vuln/detail/CVE-2025-50653>)
Finding 08 — CVE-2025-50654: A buffer overflow vulnerability exists in D-Link DI-8003 16.07.26A1…
What changed: A buffer overflow vulnerability exists in D-Link DI-8003 16.07.26A1 due to improper validation of the id parameter in the /thdmember.asp endpoint. CVE coverage: CVE-2025-50654.
Technical evidence: CVE-2025-50654; CVSS v3.1 7.5; weakness ['CWE-120']; technical confidence High.
Why it matters: The High priority moves this beyond routine tracking and requires exposure validation, remediation, and compromise assessment.
Observed status: Observed in-the-wild exploitation status is unknown.
Action: Map CVE-2025-50654 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.
Evidence limits: exploitation status unknown
fixed version or patch state unknown
affected product not structured
[Evidence source: nvd.nist.gov](<https://nvd.nist.gov/vuln/detail/CVE-2025-50654>)
Finding 09 — CVE-2026-1343: IBM Verify Identity Access Container 11.0 through 11.0.2 and IBM Security Verify…
What changed: IBM Verify Identity Access Container 11.0 through 11.0.2 and IBM Security Verify Access Container 10.0 through 10.0.9.1 and IBM Verify Identity Access 11.0 through 11.0.2 and IBM Security Verify Access 10.0 through 10.0.9.1 allows an attacker to contact internal authentication endpoints which are protected by the Reverse Proxy. CVE coverage: CVE-2026-1343.
Technical evidence: CVE-2026-1343; CVSS v3.1 7.2; weakness ['CWE-918']; technical confidence High.
Why it matters: The High priority moves this beyond routine tracking and requires exposure validation, remediation, and compromise assessment.
Observed status: Observed in-the-wild exploitation status is unknown.
Action: Map CVE-2026-1343 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.
Evidence limits: exploitation status unknown
fixed version or patch state unknown
affected product not structured
[Evidence source: nvd.nist.gov](<https://nvd.nist.gov/vuln/detail/CVE-2026-1343>)
Finding 10 — CVE-2025-50652: An issue in D-Link DI-8003 16.07.26A1 related to improper handling of the id…
What changed: An issue in D-Link DI-8003 16.07.26A1 related to improper handling of the id parameter in the /saveparmusb.asp endpoint. CVE coverage: CVE-2025-50652.
Technical evidence: CVE-2025-50652; CVSS v3.1 7.5; weakness ['CWE-120']; technical confidence High.
Why it matters: The High priority moves this beyond routine tracking and requires exposure validation, remediation, and compromise assessment.
Observed status: Observed in-the-wild exploitation status is unknown.
Action: Map CVE-2025-50652 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.
Evidence limits: exploitation status unknown
fixed version or patch state unknown
affected product not structured
[Evidence source: nvd.nist.gov](<https://nvd.nist.gov/vuln/detail/CVE-2025-50652>)
Finding 11 — CVE-2026-30923: ModSecurity is an open source, cross platform web application firewall (WAF)…
What changed: ModSecurity is an open source, cross platform web application firewall (WAF) engine for Apache, IIS and Nginx. Libmodsecurity is one component of the ModSecurity v3 project.
Technical evidence: CVE-2026-30923; CVSS v4.0 8.2; weakness ['CWE-125']; technical confidence High.
Why it matters: The High priority moves this beyond routine tracking and requires exposure validation, remediation, and compromise assessment.
Observed status: Observed in-the-wild exploitation status is unknown.
Action: Map CVE-2026-30923 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.
Evidence limits: exploitation status unknown
fixed version or patch state unknown
affected product not structured
[Evidence source: nvd.nist.gov](<https://nvd.nist.gov/vuln/detail/CVE-2026-30923>)
Finding 12 — Hackers target US firms in FastJson RCE zero-day attacks
What changed: Hackers are actively exploiting a vulnerability in the FastJson open-source Java library, allowing remote code execution without user interaction or elevated privileges. [...] Sources: - https://www.bleepingcomputer.com/news/security/hackers-target-us-firms-in-fastjson-rce-zero-day-attacks/
Why it matters: Reported active exploitation elevates this above routine patching: validate exposure immediately, remediate, and assess for prior compromise.
Observed status: The cited source reports active in-the-wild exploitation; independent corroboration (CISA KEV or grounded vendor data) is not yet available.
Action: Review the cited source, validate exposure of the affected technology in owned environments, apply available vendor guidance, and retain evidence of the exposure decision.
Evidence limits: grounded severity unavailable
exploitation status unknown
fixed version or patch state unknown
affected product not structured
[Evidence source: www.bleepingcomputer.com](<https://www.bleepingcomputer.com/news/security/hackers-target-us-firms-in-fastjson-rce-zero-day-attacks/>)
Finding 13 — Arista patches VeloCloud Orchestrator zero-day exploited in attacks
What changed: Arista has patched a maximum-severity command injection vulnerability in on-premises VeloCloud Orchestrator deployments that is being actively exploited in attacks. [...] Sources: - https://www.bleepingcomputer.com/news/security/arista-patches-velocloud-orchestrator-zero-day-exploited-in-attacks/
Why it matters: Reported active exploitation elevates this above routine patching: validate exposure immediately, remediate, and assess for prior compromise.
Observed status: The cited source reports active in-the-wild exploitation; independent corroboration (CISA KEV or grounded vendor data) is not yet available.
Action: Review the cited source, validate exposure of the affected technology in owned environments, apply available vendor guidance, and retain evidence of the exposure decision.
Evidence limits: grounded severity unavailable
exploitation status unknown
fixed version or patch state unknown
affected product not structured
[Evidence source: www.bleepingcomputer.com](<https://www.bleepingcomputer.com/news/security/arista-patches-velocloud-orchestrator-zero-day-exploited-in-attacks/>)
Finding 14 — New Certighost PoC exploit lets attackers hijack Windows domains
What changed: A proof-of-concept exploit for "Certighost," a Windows Active Directory Certificate Services vulnerability, has been released that can allow authenticated attackers to potentially compromise a Windows domain. [...] Sources: - https://www.bleepingcomputer.com/news/security/new-certighost-poc-exploit-lets-attackers-hijack-windows-domains/
Why it matters: Public exploit code is available, so weaponisation is low-effort; prioritise exposure validation and patching ahead of routine cycles.
Observed status: Observed in-the-wild exploitation status is unknown.
Action: Review the cited source, validate exposure of the affected technology in owned environments, apply available vendor guidance, and retain evidence of the exposure decision.
Evidence limits: grounded severity unavailable
exploitation status unknown
fixed version or patch state unknown
affected product not structured
[Evidence source: www.bleepingcomputer.com](<https://www.bleepingcomputer.com/news/security/new-certighost-poc-exploit-lets-attackers-hijack-windows-domains/>)
Finding 15 — Public Exploit Released for Patched vBulletin Pre-Auth Code Execution Flaw
What changed: Public exploit details released on July 27 show how an unauthenticated request can reach PHP's eval() function inside vBulletin and execute code on an unpatched forum server. The attack requires no account, administrative access, or interaction from another user.
Why it matters: Public exploit code is available, so weaponisation is low-effort; prioritise exposure validation and patching ahead of routine cycles.
Observed status: Observed in-the-wild exploitation status is unknown.
Action: Review the cited source, validate exposure of the affected technology in owned environments, apply available vendor guidance, and retain evidence of the exposure decision.
Evidence limits: grounded severity unavailable
exploitation status unknown
fixed version or patch state unknown
affected product not structured
[Evidence source: thehackernews.com](<https://thehackernews.com/2026/07/public-exploit-released-for-patched.html>)