PULSE
LIVE35signals / 24h
FEED
ransomglobal secret group reclama a West Nova Fuels & Superline Fuels · CA · Energy & Utilitiesransomglobal secret group reclama a Sinop Energia · BR · Energy & Utilitiesransomglobal secret group reclama a Al Hayat | Pepsi · IQ · Retail & E-Commerceransomglobal secret group reclama a SPDM · BR · Healthcareransomglobal secret group reclama a Nourison | Home · US · Retail & E-Commerceransomglobal secret group reclama a Cold Front Distribution · US · Retail & E-Commerceransomglobal secret group reclama a Portman Finance Group · GB · Financial Servicesransomglobal secret group reclama a OFS · US · Manufacturingransomglobal secret group reclama a Uniview Technologies · CN · Technologyransomglobal secret group reclama a Novum Energy · US · Energy & Utilitiesransomdragonforce reclama a Syntron Bioresearch · US · Healthcareransomdragonforce reclama a Deluxe Medical Supply · US · Healthcareransomchaos reclama a remco.ca · CA · Otherransomqilin reclama a Contacto Garantido · MX · Professional Servicesransomglobal secret group reclama a West Nova Fuels & Superline Fuels · CA · Energy & Utilitiesransomglobal secret group reclama a Sinop Energia · BR · Energy & Utilitiesransomglobal secret group reclama a Al Hayat | Pepsi · IQ · Retail & E-Commerceransomglobal secret group reclama a SPDM · BR · Healthcareransomglobal secret group reclama a Nourison | Home · US · Retail & E-Commerceransomglobal secret group reclama a Cold Front Distribution · US · Retail & E-Commerceransomglobal secret group reclama a Portman Finance Group · GB · Financial Servicesransomglobal secret group reclama a OFS · US · Manufacturingransomglobal secret group reclama a Uniview Technologies · CN · Technologyransomglobal secret group reclama a Novum Energy · US · Energy & Utilitiesransomdragonforce reclama a Syntron Bioresearch · US · Healthcareransomdragonforce reclama a Deluxe Medical Supply · US · Healthcareransomchaos reclama a remco.ca · CA · Otherransomqilin reclama a Contacto Garantido · MX · Professional Services
← All CVEs
CVE WatchJul 25, 2026

CVE-2026-56160

Improper authorization in Azure Red Hat OpenShift (ARO) allows an authorized attacker to elevate privileges over a network.

CVSS

9.1

Critical

EPSS

0.7%

p47

KEV

Exploit Today

14

0-100

Published: Jul 24, 2026 · Last modified: Jul 25, 2026 · CWE-285

EPSS · 30d
0.7%EPSS · 30 days0.7%
2026-07-242026-07-25
Technical description

Improper authorization in Azure Red Hat OpenShift (ARO) allows an authorized attacker to elevate privileges over a network.

Official references
Related CVEs
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-174346.3 MED
0A flaw has been found in nanocoai NanoClaw up to 2.0.64. Affected is the function handleAddMcpServer of the file src/modules/self-mod/request.ts of the component add_mcp_server. Executing a manipulation can lead to improper authorization. The attack may be launched remotely. The exploit has been published and may be used. This patch is called e5b928783d5c485637565eb07d2967922dfbf8d8. A patch should be applied to remediate this issue.14h
CVE-2026-174335.3 MED
0A vulnerability was detected in nanocoai NanoClaw up to 2.0.64. This impacts the function createChatSdkBridge.setup of the file src/channels/chat-sdk-bridge.ts of the component MCP Server Approval. Performing a manipulation results in improper authorization. The attack needs to be approached locally. The exploit is now public and may be used. The project was informed of the problem early through an issue report but has not responded yet.15h
CVE-2026-628359.3 CRI
60.3%
18Improper authorization in Azure Portal allows an unauthorized attacker to disclose information over a network.2d
CVE-2026-625635.4 MED
0.3%
0Vulnerability in the Oracle Work in Process product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.5-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Work in Process. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Work in Process, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Work in Process accessible data as well as unauthorized read access to a subset of Oracle Work in Process accessible data. CVSS 3.1 Base Score 5.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N).3d
CVE-2026-624446.1 MED
13.4%
4Vulnerability in the Oracle Contracts Integration product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Contracts Integration. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Contracts Integration, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Contracts Integration accessible data as well as unauthorized read access to a subset of Oracle Contracts Integration accessible data. CVSS 3.1 Base Score 6.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N).3d
CVE-2026-610826.5 MED
3.8%
1Vulnerability in the MySQL Connectors product of Oracle MySQL (component: Connector/J). Supported versions that are affected are 9.7.0-9.7.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise MySQL Connectors. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all MySQL Connectors accessible data. CVSS 3.1 Base Score 6.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N).2d