Emergent Threat6
CVE-2026-55040:Rapid7 Analysis: Microsoft SharePoint JWT Token Authentication Bypass (CVE-2026-55040)
CVE-2026-63077:Rapid7 Analysis: Unauthenticated Remote Code Execution in JetBrains TeamCity (CVE-2026-63077)
CVE-2026-66066:KindaRails2Shell: CVE-2026-66066, Critical Arbitrary File Read and Possible Remote Code Execution in Ruby on Rails
| Title | EitW | Modules |
|---|
| Title | EitW | Modules | ||||
|---|---|---|---|---|---|---|
| CVE-2026-4137: Creation of Temporary File With Insecure Permissions | 7.8 High | N/A | 0% | May 18, 2026 | ||
| CVE-2026-41379: Incorrect Authorization | 7.1 High | 7.1 High | 0% | Apr 28, 2026 | ||
| CVE-2026-41378: Missing Authorization | 8.8 High | 7.7 High | 0% | Apr 28, 2026 | ||
| CVE-2026-41377: Not Failing Securely | 4.6 Medium | 5.1 Medium | 0% | Apr 28, 2026 | ||
| CVE-2026-41376: Origin Validation Error | 5.4 Medium | 2.3 Low | 0% | Apr 28, 2026 | ||
| CVE-2026-41375: Incorrect Authorization | 6.5 Medium | 7.1 High | 0% | Apr 28, 2026 | ||
| CVE-2026-41374: Incorrect Behavior Order: Early Amplification | 5.3 Medium | 6.9 Medium | 0% | Apr 28, 2026 | ||
| CVE-2026-41373: Uncontrolled Search Path Element | 6.1 Medium | 5.8 Medium | 0% | Apr 28, 2026 | ||
| CVE-2026-41372: Authorization Bypass Through User-Controlled Key | 5.8 Medium | 6.9 Medium | 0% | Apr 28, 2026 | ||
| CVE-2026-41371: Incorrect Authorization | 8.5 High | 8.4 High | 0% | Apr 28, 2026 | ||
| CVE-2026-41370: Improper Limitation of a Pathname to a Restricted Directory | 6.5 Medium | 7.1 High | 0% | Apr 28, 2026 |