Emergent Threat6
CVE-2026-55040:Rapid7 Analysis: Microsoft SharePoint JWT Token Authentication Bypass (CVE-2026-55040)
CVE-2026-63077:Rapid7 Analysis: Unauthenticated Remote Code Execution in JetBrains TeamCity (CVE-2026-63077)
CVE-2026-66066:KindaRails2Shell: CVE-2026-66066, Critical Arbitrary File Read and Possible Remote Code Execution in Ruby on Rails
| Title | EitW | Modules |
|---|
| Title | EitW | Modules | ||||
|---|---|---|---|---|---|---|
| CVE-2026-4058: Missing Authorization | 4.3 Medium | N/A | 0% | Jun 9, 2026 | ||
| CVE-2026-40588: Unverified Password Change | 8.1 High | N/A | 0% | Apr 21, 2026 | ||
| CVE-2026-40587: Insufficient Session Expiration | 6.5 Medium | N/A | 0% | Apr 21, 2026 | ||
| CVE-2026-40589: Authorization Bypass Through User-Controlled Key | 7.6 High | N/A | 0% | Apr 21, 2026 | ||
| CVE-2026-40586: Improper Restriction of Excessive Authentication Attempts | 7.5 High | N/A | 0% | Apr 21, 2026 | ||
| CVE-2026-40585: Weak Password Recovery Mechanism for Forgotten Password | 7.4 High | N/A | 0% | Apr 21, 2026 | ||
| CVE-2026-40584: Exposure of Sensitive Information to an Unauthorized Actor | 7.5 High | 6.9 Medium | 0% | Apr 21, 2026 | ||
| CVE-2026-40583: Improper Cleanup on Thrown Exception | 8.2 High | 8.8 High | 0% | Apr 21, 2026 | ||
| CVE-2026-40582: Authentication Bypass Using an Alternate Path or Channel | N/A | 9.1 Critical | 1% | Apr 18, 2026 | ||
| CVE-2026-40581: Cross-Site Request Forgery (CSRF) | 8.1 High | N/A | 0% | Apr 18, 2026 |