This day 02:00 06:00 10:01 14:01 18:01 22:01
Info  2026-07-26 10:01Z · last 4h · 6 findings · glm-5.2:cloud

Threat Brief — 2026-07-26 — Patches That Don't Patch

Two critical patch-management failures dominate today: GitLab sat on an RCE for 1.5 months disguised as a routine update while a working exploit circulated, and Redis shipped fixes that attackers bypassed trivially—leaving thousands of servers exposed. Meanwhile, the AFX Trade bridge-drain campaign continues to escalate, and the Pentagon is belatedly waking up to the absence of protection for undersea internet cables.

Top items

Themes

Patch fatigue is becoming an attack surface. Both GitLab and Redis demonstrate that the gap between "patched" and "actually fixed" is weaponisable. GitLab's concealment and Redis's broken fixes show that organisations cannot assume a vendor patch cycle equals remediation—verify independently, and treat unpatched-but-"fixed" software as still vulnerable until confirmed.

Bridges remain the soft underbelly of DeFi. The AFX Trade drain is the latest in a sustained campaign against cross-chain bridges, and notably the attack succeeded through human error rather than a smart-contract exploit. Operational controls, key management, and multi-sig discipline matter as much as code audits.

Public exploits · latest from the exploit feed

ArcadeDB < 26.7.2 Cross-Database Authorization Bypass (IDOR) 2026-08-02 15:45Z · RSS:cxsecurity-wlb Linux Kernel 7.0-7.0.8 & 7.0-rc-7.0-rc7 - Use After Free Exploit 2026-08-02 15:45Z · RSS:cxsecurity-wlb MODX.3.2.1 TLS cookie without secure flag set - COOKIE PHPSESSID HIJACK 2026-08-02 15:45Z · RSS:cxsecurity-wlb Linux Kernel 7.0 DRM UAF LPE Exploit published for CVE-2026-46215 CVE-2026-46215 2026-07-22 14:05Z · CXSecurity / Exploit-DB (RSS) ZTE ZXHN H188A V6 Authentication Bypass 2026-07-22 13:28Z · RSS:cxsecurity-wlb OpenEMR 7.0.2 Arbitrary File Read 2026-07-22 13:28Z · RSS:cxsecurity-wlb PHP Link Directory (phpLD) 2.1.3 - SQL Injection, IDOR, CSRF 2026-07-22 13:28Z · RSS:cxsecurity-wlb KNX visualisering - Broken Access Control 2026-07-22 13:28Z · RSS:cxsecurity-wlb D-Link DSL2600U rom-0 Admin Password Disclosure 2026-07-22 13:28Z · RSS:cxsecurity-wlb Windows Defender (MsMpEng.exe) Race Condition -> LPE / SYSTEM / Use-After-Free -> Crash 2026-07-22 13:28Z · RSS:cxsecurity-wlb