Emergent Threat6
CVE-2026-55040:Rapid7 Analysis: Microsoft SharePoint JWT Token Authentication Bypass (CVE-2026-55040)
CVE-2026-63077:Rapid7 Analysis: Unauthenticated Remote Code Execution in JetBrains TeamCity (CVE-2026-63077)
CVE-2026-66066:KindaRails2Shell: CVE-2026-66066, Critical Arbitrary File Read and Possible Remote Code Execution in Ruby on Rails
| Title | EitW | Modules |
|---|
| Title | EitW | Modules | ||||
|---|---|---|---|---|---|---|
| CVE-2026-4035: Insertion of Sensitive Information Into Sent Data | 7.7 High | N/A | 0% | Jun 3, 2026 | ||
| CVE-2026-40359: Use After Free | 7.8 High | N/A | 0% | May 12, 2026 | ||
| CVE-2026-40358: Use After Free | 8.4 High | N/A | 0% | May 12, 2026 | ||
| CVE-2026-40357: Deserialization of Untrusted Data | 8.8 High | N/A | 2% | May 12, 2026 | ||
| CVE-2026-40356: Integer Underflow (Wrap or Wraparound) | 7.5 High | N/A | 1% | Apr 28, 2026 | ||
| CVE-2026-40355: NULL Pointer Dereference | 7.5 High | N/A | 1% | Apr 28, 2026 | ||
| CVE-2026-40350: Incorrect Authorization | 8.8 High | N/A | 0% | Apr 18, 2026 | ||
| CVE-2026-40353: Improper Neutralization of Input During Web Page Generation | 5.4 Medium | 5.1 Medium | 0% | Apr 17, 2026 | ||
| CVE-2026-40352: Improper Neutralization of Special Elements in Data Query Logic | 8.8 High | N/A | 0% | Apr 17, 2026 | ||
| CVE-2026-40351: Improper Neutralization of Special Elements in Data Query Logic | 9.8 Critical | N/A | 1% | Apr 17, 2026 | ||
| CVE-2026-40354: UNIX Symbolic Link (Symlink) Following | 2.9 Low | N/A | 0% | Apr 11, 2026 |