Daily briefing · July 5, 2026

cve-search Critical Flaw Leads July 5 Roundup Alongside Multiple PoC-Exposed Vulnerabilities

Automated Vexday summary · sources: NVD, CISA KEV, EPSS

July 5, 2026 brought 84 new vulnerabilities, with one critical disclosure standing out: an unauthenticated input validation flaw in cve-search that could expose administrative credentials directly from MongoDB. The day saw no active KEV exploitation, but six of the ten highlighted CVEs carry public proof-of-concept code, significantly narrowing the window between disclosure and real-world abuse. Several entries target Turkish public-sector software from TUBITAK BILGEM, broadening the geographic scope of concern.

Today’s brief
  • CRITICAL: CVE-2026-59509 in cve-search allows unauthenticated attackers to read MongoDB collections, including admin password hashes — patch or isolate immediately.
  • Six of ten highlighted CVEs have public PoC exploits, meaning weaponization is already within reach of low-skilled attackers.
  • Multiple TUBITAK BILGEM products (Pardus suite, Domain Joiner) are affected by privilege escalation, DNS spoofing, and credential exposure flaws.
  • Network devices and web applications (UTT HiPER router, Ruijie RG-UAC, WeChat bot) round out a diverse and practically exploitable set of targets.
1
critical
0
Actively exploited
0
Before CISA
0
Weaponized
Critical highlights
1
CVE-2026-59509CVSS 9.2PoCaffects cve-search
An unauthenticated attacker can manipulate POST parameters on the /fetch_cve_data endpoint to query arbitrary MongoDB collections in cve-search, including the mgmt_users collection containing admin usernames and password hashes. With a public PoC already available, any exposed instance should be treated as compromised until patched or isolated.
2
CVE-2026-9085HIGH 8.8affects Pardus-Parental-Control
Incorrect permission assignment in Pardus-Parental-Control (versions up to 0.5.1) allows attackers to perform DNS spoofing, potentially redirecting users to malicious infrastructure. Organizations running this parental control solution on Turkish Pardus Linux deployments should upgrade to 0.7.0 or later without delay.
3
CVE-2026-14721HIGH 8.7PoCaffects HiPER 1250GW
A stack-based buffer overflow in the UTT HiPER 1250GW router's web endpoint (via the ssid argument) can be triggered remotely, and a public exploit has already been disclosed. Routers exposed to the internet or untrusted networks are at direct risk of remote code execution.
4
CVE-2026-12250HIGH 7.9affects Pardus Domain Joiner
Pardus Domain Joiner (before 0.5.4) exposes sensitive credentials through process invocation in a way visible to local observers, enabling credential excavation by low-privileged users. Systems joined to domains using this tool should be updated and credentials rotated as a precaution.
5
CVE-2026-6509HIGH 7.8affects Pardus Update
A missing authorization check in Pardus Update (before 0.6.6) can be leveraged for local privilege escalation, allowing an attacker with limited access to gain elevated system rights. This is especially concerning in multi-user or shared environments running the Pardus Linux distribution.
6
CVE-2026-59510HIGH 7.1affects ail-framework
A path traversal vulnerability in AIL Framework's PDF object handling allows authenticated users to read files outside the intended PDF storage directory. Defenders should apply the fix from commit 14c618fce4d1df02358717c48ea903706abecdf2 and audit file access logs for anomalous path patterns.
7
CVE-2026-14714MEDIUM 6.9PoCaffects chatgpt-on-wechat CowAgent
Missing authentication on the wx endpoint's verify_server function in chatgpt-on-wechat CowAgent 2.1.0 allows remote attackers to interact with the WeChat integration without credentials, with a public PoC already available. Instances exposed to the internet should be upgraded or placed behind authentication controls immediately.
8
CVE-2026-14736MEDIUM 6.9PoCaffects RG-UAC
An unrestricted file upload vulnerability in Ruijie RG-UAC's user_auth_commit.php allows remote attackers to upload arbitrary files, a classic vector for webshell deployment and full system compromise. The public exploit makes this an urgent patching priority for any organization using this unified access controller.
9
CVE-2026-14735MEDIUM 6.9PoCaffects Smart Parking System
SQL injection via the street, city, and status parameters in the Smart Parking System 1.0 (/parkings/parkings.php) can be exploited remotely to extract or manipulate the underlying database. A public exploit is available, making any publicly accessible deployment an easy target for data theft.
10
CVE-2026-14734MEDIUM 6.9PoCaffects Class and Exam Timetabling System
A SQL injection flaw in SourceCodester Class and Exam Timetabling System 1.0 (/edit_product.php) via the ID parameter allows remote attackers to interact with the backend database. With a published exploit, educational institutions running this system should restrict access and apply available patches immediately.
Today’s recommendation: Prioritize patching or network-isolating CVE-2026-59509 in any cve-search deployment, as unauthenticated credential theft poses an immediate takeover risk; simultaneously audit all PoC-exposed entries (especially CVE-2026-14721, CVE-2026-14736, and CVE-2026-14735) and apply vendor updates or compensating controls before attackers operationalize the available exploits.
With six public exploits disclosed in a single day spanning routers, web apps, and platform tools, now is the right moment to validate which of these affected components actually exist in your environment and confirm your detection coverage can catch exploitation attempts.Find out in minutes, with a free exposure assessment, where your organization is truly exposed.Meet the Autonomous AI Pentest Agent →
Previous briefings
September 8, 2026Windows Under Active Exploit, ScreenConnect Zero-Day Detected Before CISA: September 8 Security BulletinSeptember 7, 202622 Critical CVEs Published on a Quiet Day, With Heavy Ransomware Pressure on BrazilSeptember 6, 2026Quiet Day Hides Real Risks: Tenda HG10, NEC UNIVERGE, and Brazilian Ransomware Surge Demand AttentionSeptember 5, 2026WordPress Plugin Wave and Tenda CP3 Flaws Lead a Calm But CVE-Heavy DaySeptember 4, 2026WordPress Plugins and FreeIPMI Lead a Calm but Patch-Heavy DaySeptember 3, 2026Four CVSS 10.0 Critical CVEs Headline a Calm But Dense Vulnerability DaySeptember 2, 2026WordPress Plugins Under Fire, Cisco IOS XR and NX-OS in the Crosshairs: ATTENTION Day With Active ExploitationSeptember 1, 2026Active Exploitation of Proxmox and SonicWall SMA1000 Leads a High-Alert DayAugust 31, 2026WordPress Plugins and Tenda Routers Dominate a High-Alert Day With 41 Critical CVEsAugust 30, 2026Calm Day Hides Sharp Edges: Critical Code Injection and Router Flaws Top August 30 BulletinAugust 29, 2026Ten Active-Exploitation CVEs Dominate as Ransomware Groups Hammer BrazilAugust 28, 202610 Actively Exploited CVEs Demand Immediate Action: Metabase, VMware, macOS, Cisco, and More Under FireAugust 27, 2026Router Firmware Under Active Exploitation and WordPress Wave Raises Alerts on August 27August 26, 2026Ubiquiti UniFi and Gitea Face Active Exploitation Alerts as 62 Critical CVEs Emergeview full archive →
Share