CVE-2026-10548
A security flaw has been discovered in NousResearch hermes-agent up to 2026.4.23. This affects the function _sync_anthropic_entry_from_crede
CVSS
5.3
Medio
EPSS
0.1%
p4
KEV
—
Exploit Today
1
0-100
Publicado: 2 jun 2026 · Última mod.: 22 jul 2026 · CWE-287
0.1%EPSS · 30 días0.1%
2026-06-302026-07-26
A security flaw has been discovered in NousResearch hermes-agent up to 2026.4.23. This affects the function _sync_anthropic_entry_from_credentials_file of the file agent/credential_pool.py of the component Credential Pool Synchronization. The manipulation results in improper authentication. The attack must be initiated from a local position. The exploit has been released to the public and may be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.
CVECVSSEPSSKEVRExplotTítuloVis.
CVE-2026-12504—2.9%
——1Improper Authentication (CWE-287) in the PAM configuration in Loytec LIP-ME201C, L-INX, L-GATE, L-ROC, L-IOB, L-DALI, L-VIS and L-PAD through 8.4.16 on LINX-A64 allows a local attacker to authenticate as a uid=0 account without a password and obtain a root shell via an `/etc/passwd` entry with an empty password field.3dCVE-2026-128779.1 CRÍ15.0%
——4The Project Management, Bug and Issue Tracking Plugin WordPress plugin before 5.1.0 does not sanitise and escape user supplied input before using it in a SQL query, allowing unauthenticated attackers to perform SQL injection attacks. This is exploitable in the Project Management, Bug and Issue Tracking Plugin WordPress plugin before 5.1.0's standard front-end issue-tracker configuration.3dCVE-2026-6282510.0 CRÍ49.3%
——15Improper authentication in Azure Key Vault allows an unauthorized attacker to elevate privileges over a network.2dCVE-2026-5619110.0 CRÍ48.7%
——15Improper authentication in Microsoft Exchange Online allows an unauthorized attacker to perform tampering over a network.2dCVE-2026-159819.8 CRÍ42.6%
——13The SAML Single Sign On – SSO Login plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 5.4.4. This is due to the mo_saml_validate_signature() function performing a loose boolean check on the raw tri-state integer returned by PHP's openssl_verify(), causing an error return value of -1 to be evaluated as truthy and therefore treated as a successful signature verification. This makes it possible for unauthenticated attackers to log in as any existing WordPress user, including administrators, by submitting a crafted SAMLResponse containing an attacker-controlled NameID and a deliberately malformed signature value that triggers an OpenSSL processing error — bypassing verification entirely and resulting in wp_set_auth_cookie() being called for the targeted account.3dCVE-2026-106977.5 ALT7.8%
——2Improper Authentication vulnerability in Progress MOVEit Transfer.
This issue affects MOVEit Transfer: before 2025.1.5, from 2026.0.0 before 2026.0.3.2d