CVE
CVE-2026-57221
RabbitMQ: Passive queue/exchange declaration bypasses authorization checks, leaking queue metadata to unprivileged users
Exploitation IoCs 7
Filename .ssh/authorized_keys
Filename /dev/shm/.a
Filename /etc/cron.d/.s
Filename /etc/cron.d/.sys_monitor
Filename /tmp/.a
Filename /var/tmp/.a
GitHub Repo Cursor agent
MITRE ATT&CK TTPs 5
Source Articles
⚡ Weekly Recap: WordPress RCE, SonicWall 0-Days, AI Service Attacks, SharePoint 0-Day and More
This week's threat landscape highlights critical vulnerabilities in widely used platforms such as WordPress, SonicWall, and Microsoft SharePoint, with active exploitation observed in the wild. A pre-authenticated remote code execution flaw in WordPress Core (CVE-2026-63030 and CVE-2026-60137) enables unauthenticated attackers to execute code, posing a significant risk due to WordPress's global reach. SonicWall SMA appliances were exploited via zero-day vulnerabilities prior to patching, while CISA added a SharePoint RCE (CVE-2026-58644) to its known exploited list. Additionally, new malware frameworks like OkoBot and NadMesh target crypto assets and cloud AI services, indicating evolving attacker tactics leveraging automation and AI.
hacker-news Jul 20, 2026
RabbitMQ Flaws Could Leak OAuth Secrets and Expose Cross-Tenant Queue Metadata
Two critical vulnerabilities in RabbitMQ, CVE-2026-57219 and CVE-2026-57221, could allow unauthenticated attackers to leak OAuth client secrets and enable authenticated users to bypass tenant boundaries by accessing cross-tenant queue metadata. The flaws, present since early 2024, affect RabbitMQ versions 3.13.0 and later and have been patched in recent releases. CVE-2026-57219 exposes a misconfigured HTTP API endpoint that leaks sensitive OAuth secrets, posing high risk in cloud or multi-tenant environments with exposed management interfaces.
hacker-news Jul 14, 2026