Latest updates for Cve-2026-60004

Fresh curated links around CVE-2026-60004 are collected here so marketers can spot useful updates and turn timely ideas into posts faster.

Recent items include:

  • CVE-2026-55107 (kobako): kobako Sandbox Escape - guest eval reaches host RCE via method_missing → public_send (any bound
  • CVE-2026-45573 (decidim-core): Decidim - Push subscriptions can be abused for server-side requests
  • CVE-2026-66748 (camaleon_cms): Camaleon CMS (2.1.1 to 2.9.1) contains an authenticated RCE vulnerability

Post angles to try

Share the most useful takeaway for your audience.
Turn one article into a quick practical checklist.
Ask your audience how this shift affects their work.
Turn angles into scheduled posts

Fresh articles and ideas

Recent curated links from global sources. Generate one free draft from any story, then use SocialBu to schedule and refine your content calendar.

rubysec.com /2 weeks ago

CVE-2026-55107 (kobako): kobako Sandbox Escape - guest eval reaches host RCE via method_missing → public_send (any bound...

Originally appeared on RubySec.### Summary A guest mruby script running inside the Kobako sandbox can execute arbitrary Ruby in the host process, fully escaping the sandbox. ###...

Read source
rubysec.com /1 month ago

CVE-2026-45573 (decidim-core): Decidim - Push subscriptions can be abused for server-side requests

Originally appeared on RubySec.## Description The push-subscription endpoint stores an attacker-controlled delivery URL, and the notification send path becomes an outbound-request...

Read source
rubysec.com /1 month ago

CVE-2026-66748 (camaleon_cms): Camaleon CMS (2.1.1 to 2.9.1) contains an authenticated RCE vulnerability

Originally appeared on RubySec.Camaleon CMS versions 2.1.1 through 2.9.1 contains an authenticated remote code execution (RCE) vulnerability that allows users with custom_fields ma...

Read source
rubysec.com /1 month ago

CVE-2026-66066 (activestorage): Possible arbitrary file read and remote code execution in Active Storage variant process...

Originally appeared on RubySec.## Impact In its default configuration, a Rails application that displays image variants may allow an unauthenticated attacker to read arbitrary fil...

Read source
rubysec.com /1 month ago

CVE-2026-45377 (decidim-core): Decidim - Private exports can be downloaded through reusable links

Originally appeared on RubySec.## Description The normal `download_your_data` flow requires the requester to be logged in as the export owner, but the resulting Active Storage blo...

Read source
rubysec.com /1 month ago

CVE-2026-45572 (decidim-core): Decidim - HTML content blocks allow stored script execution

Originally appeared on RubySec.## Description A privileged admin user who can edit an affected landing page can store arbitrary HTML/JavaScript in an `HTML block`, and the public...

Read source
rubysec.com /4 days ago

CVE-2026-85396 (rubyzip): path traversal vulnerability in pre-3.4.0 rubyzip gem

Originally appeared on RubySec.rubyzip versions before 3.4.0 contain a path traversal vulnerability in Zip::Entry#extract that fails to properly validate extraction paths using pre...

Read source
thehackernews.com /1 month ago

Critical SharePoint RCE CVE-2026-50522 Under Active Exploitation After Public PoC

A third SharePoint Server flaw patched by Microsoft as part of its Patch Tuesday update for July 2026 has come under active exploitation, per watchTowr. The vulnerability in quest...

Read source
rubysec.com /1 month ago

CVE-2026-45415 (decidim-verifications): Decidim - CSV census record endpoints improper authorization

Originally appeared on RubySec.## Description A participant manager can access and modify the CSV census record admin forms. ## Impact Any participant admin can create, alter, o...

Read source
ahmedbns.wordpress.com /3 weeks ago

الثغرة الأمنية VMware-CVE-20026-59310

<figure class="wp-block-image size-large"><img width="1024" height="558" data-attachment-id="964" data-permalink="https://ahme...

Read source
rubysec.com /3 weeks ago

CVE-2026-73330 (camaleon_cms): CamaleonCMS 2.9.1 Server-Side Template Injection via test_email Action

Originally appeared on RubySec.CamaleonCMS 2.9.1 contains a server-side template injection vulnerability that allows authenticated administrators to execute arbitrary commands by e...

Read source
rubysec.com /1 month ago

CVE-2026-45414 (decidim): Decidim - JWT-backed authentication can be replayed across organizations

Originally appeared on RubySec.## Description A JWT issued to an Org 1 account is accepted on the Org 2 API and can read the admin-only GraphQL `participantDetails` field for an O...

Read source
rubysec.com /1 month ago

CVE-2026-45378 (decidim-verifications): Decidim - Verification documents can be downloaded through reusable links

Originally appeared on RubySec.## Description Scanned identity-document images provided by participants and shown in the verification admin workflow are exposed through signed `/r...

Read source
thehackernews.com /1 month ago

Ruflo MCP Flaw Lets Unauthenticated Attackers Run Commands and Poison AI Memory

Cybersecurity researchers have flagged a maximum-severity security flaw in Ruflo, an open-source agent meta-harness for Anthropic Claude Code and OpenAI Codex, that could result in...

Read source
rubysec.com /1 month ago

CVE-2026-54659 (pagy): Pagy I18n locale option is not validated before being used in a file path

Originally appeared on RubySec.### Summary `Pagy::I18n.locale=` did not validate its argument before using it as a path component to load the matching dictionary file (`.yml`). An...

Read source
rubysec.com /1 week ago

CVE-2026-80213 (resolv): CVE-2026-80213 - Hostname validation bypass

Originally appeared on RubySec.An application that checks a hostname against an allow list or an SSRF filter and then resolves it can be made to look up a domain other than the one...

Read source
rubysec.com /1 month ago

CVE-2026-50276 (datadog): dd-trace-rb - Improper parsing of W3C baggage headers may lead to DoS

Originally appeared on RubySec.### Impact Datadog tracing libraries that implement W3C baggage propagation parse incoming baggage HTTP headers without enforcing item-count or byte...

Read source
rubysec.com /1 month ago

CVE-2026-45086 (decidim-demographics): Decidim - Forms admin question editor lacks authorization

Originally appeared on RubySec.## Description A participant can load the demographics questionnaire admin editor and make changes. ## Impact - Low-privilege users can access que...

Read source
rubysec.com /1 week ago

CVE-2026-81097 (rails-mcp-server): The execute_ruby tool is documented as a read-only Ruby sandbox

Originally appeared on RubySec.The execute_ruby tool is documented as a read-only Ruby sandbox and is enforced by a pattern denylist together with replacements for the process-spaw...

Read source
rubysec.com /4 weeks ago

CVE-2026-71847 (json): Ruby JSON - JSON::ResumableParser#partial_value dereferences a freed input buffer and crashes on...

Originally appeared on RubySec.### Summary Ruby's JSON native C extension clears the consumed `JSON::ResumableParser` input buffer but leaves `state.start`, `state.cursor`, and `s...

Read source
rubysec.com /1 month ago

CVE-2026-45330 (decidim-verifications): Decidim - Verification admins can access supplied IDs from other organizations

Originally appeared on RubySec.## Description The verification admin mutation flow allows accessing, verifying, and rejecting participants records from another tenant. ## Impact...

Read source
thehackernews.com /2 weeks ago

Isolated-vm Flaw Lets Sandboxed JavaScript Escape to Host for Potential RCE

Cybersecurity researchers have disclosed a critical security flaw in isolated-vm, a popular open-source sandbox with more than 2,900 stars and 190 forks on GitHub, that could allow...

Read source
gbhackers.com /3 weeks ago

Ruby 4.0 Marshal.load RCE Gadget Chain Exposes Critical Deserialization Risk

A newly disclosed universal deserialization gadget chain shows how a single unsafe Marshal.load operation can reportedly produce remote command execution in Ruby 4.0.6, underscorin...

Read source
gbhackers.com /3 weeks ago

Fortinet FortiWeb and FortiClient Flaws Let Unauthenticated Attackers Gain Access and Execute Arbitrary Code

Fortinet has released security updates to address high-severity vulnerabilities in FortiWeb and FortiClient for Windows. These vulnerabilities could allow unauthenticated attackers...

Read source

Turn fresh research into a full content calendar

Use SocialBu to discover ideas, generate post drafts, and schedule them across your social channels.

Sources covering Cve-2026-60004

rubyland.news

Recent coverage from public sources
Public source

blogs.vmware.com

Recent coverage from public sources
Public source

feeds.feedburner.com

Recent coverage from public sources
Public source

gbhackers.com

Recent coverage from public sources
Public source