ioc_value,ioc_type,severity,description,product,source,url,date,tags,stix_indicator_id,section,confidence CVE-2026-59822,cve,CRITICAL,BerriAI LiteLLM contains an improper authentication vulnerability in the MCP Streamable HTTP endpoint that could allow an unauthenticated attacker to establish an authenticated MCP session using an arbitrary Bearer token.,LiteLLM (BerriAI),CISA KEV Catalog,https://www.cisa.gov/known-exploited-vulnerabilities-catalog,2026-09-02,kev;cisa;active-exploitation,indicator--00000000-00000001-0000-0000-0000-000000000000,CISA KEV (KNOWN EXPLOITED VULNERABILITY),100 CVE-2026-48710,cve,CRITICAL,"Kludex Starlette contains a HTTP request/response smuggling vulnerability that could allow attackers to inject paths into the host part, prepending the actual path leading to issues such as authentication bypass when the authentication depends on the",Starlette (Kludex),CISA KEV Catalog,https://www.cisa.gov/known-exploited-vulnerabilities-catalog,2026-09-02,kev;cisa;active-exploitation,indicator--00000000-00000002-0000-0000-0000-000000000000,CISA KEV (KNOWN EXPLOITED VULNERABILITY),100 CVE-2026-49869,cve,CRITICAL,Kestra OSS contains an OS command injection vulnerability that could allow an unauthenticated remote attacker to create and execute arbitrary workflows without credentials.,Kestra OSS (Kestra),CISA KEV Catalog,https://www.cisa.gov/known-exploited-vulnerabilities-catalog,2026-09-02,kev;cisa;active-exploitation,indicator--00000000-00000003-0000-0000-0000-000000000000,CISA KEV (KNOWN EXPLOITED VULNERABILITY),100 CVE-2026-82329,cve,CRITICAL,JFrog Artifactory contains an improper authentication vulnerability that under default configuration can allow an unauthenticated attacker with network access to obtain administrative privileges.,Artifactory (JFrog),CISA KEV Catalog,https://www.cisa.gov/known-exploited-vulnerabilities-catalog,2026-09-02,kev;cisa;active-exploitation,indicator--00000000-00000004-0000-0000-0000-000000000000,CISA KEV (KNOWN EXPLOITED VULNERABILITY),100 CVE-2026-9586,cve,CRITICAL,"Sangoma Switchvox contains a SQL injection vulnerability which allows an unauthenticated remote attacker to execute arbitrary SQL statements against the backend PostgreSQL database using a single crafted request, including database operations and rem",Switchvox (Sangoma),CISA KEV Catalog,https://www.cisa.gov/known-exploited-vulnerabilities-catalog,2026-09-02,kev;cisa;active-exploitation,indicator--00000000-00000005-0000-0000-0000-000000000000,CISA KEV (KNOWN EXPLOITED VULNERABILITY),100 CVE-2026-83548,cve,CRITICAL,SonicWall SMA1000 Appliances contains a server-side request forgery vulnerability that could allow a remote unauthenticated attacker to gain unauthorized access to sensitive functionality and perform unauthorized operations.,SMA1000 Appliances (SonicWall),CISA KEV Catalog,https://www.cisa.gov/known-exploited-vulnerabilities-catalog,2026-09-02,kev;cisa;active-exploitation,indicator--00000000-00000006-0000-0000-0000-000000000000,CISA KEV (KNOWN EXPLOITED VULNERABILITY),100 CVE-2026-83549,cve,CRITICAL,"SonicWall SMA1000 Appliances contains an OS command injection vulnerability that could enable a remote authenticated attacker as administrator to execute arbitrary OS commands, resulting in remote code execution.",SMA1000 Appliances (SonicWall),CISA KEV Catalog,https://www.cisa.gov/known-exploited-vulnerabilities-catalog,2026-09-02,kev;cisa;active-exploitation,indicator--00000000-00000007-0000-0000-0000-000000000000,CISA KEV (KNOWN EXPLOITED VULNERABILITY),100 CVE-2026-82078,cve,CRITICAL,PaperCut NG/MF contains an unsafe reflection vulnerability that allows an attacker to manipulate system configuration parameters and execute arbitrary Java bytecode residing on the application classpath under the security context of the PaperCut serv,NG/MF (PaperCut),CISA KEV Catalog,https://www.cisa.gov/known-exploited-vulnerabilities-catalog,2026-08-31,kev;cisa;active-exploitation,indicator--00000000-00000008-0000-0000-0000-000000000000,CISA KEV (KNOWN EXPLOITED VULNERABILITY),100 CVE-2026-81578,cve,CRITICAL,PaperCut NG/MF contains a missing authentication for critical function vulnerability which allows an unauthenticated remote attacker to modify certain system configurations. This vulnerability can be chained with CVE-2026-82078.,NG/MF (PaperCut),CISA KEV Catalog,https://www.cisa.gov/known-exploited-vulnerabilities-catalog,2026-08-31,kev;cisa;active-exploitation,indicator--00000000-00000009-0000-0000-0000-000000000000,CISA KEV (KNOWN EXPLOITED VULNERABILITY),100 CVE-2023-49105,cve,CRITICAL,"ownCloud contains an improper authentication vulnerability that allows an attacker to access, modify, or delete any file without authentication if the username of a victim is known, and the victim has no signing-key configured.",ownCloud (ownCloud),CISA KEV Catalog,https://www.cisa.gov/known-exploited-vulnerabilities-catalog,2026-08-27,kev;cisa;active-exploitation,indicator--00000000-00000010-0000-0000-0000-000000000000,DOMAIN,100 evil-tokens[.]com,other,CRITICAL,EvilTokens PhaaS platform domain - OAuth device-code phishing targeting Microsoft 365,,Threat intelligence analysis - EvilTokens campaign,,2026-07-29,eviltokens;phaas;oauth;device-code;microsoft,indicator--00000000-00000011-0000-0000-0000-000000000000,DOMAIN,100 oauth-steal[.]net,other,CRITICAL,EvilTokens OAuth credential harvesting infrastructure,,Threat intelligence analysis - EvilTokens campaign,,2026-07-29,eviltokens;oauth;credential-harvesting,indicator--00000000-00000012-0000-0000-0000-000000000000,DOMAIN,100 mfa-phish[.]org,other,CRITICAL,EvilTokens MFA interception proxy,,Threat intelligence analysis - EvilTokens campaign,,2026-07-29,eviltokens;mfa;proxy,indicator--00000000-00000013-0000-0000-0000-000000000000,DOMAIN,100 token-harvest[.]io,other,CRITICAL,EvilTokens token capture infrastructure,,Threat intelligence analysis - EvilTokens campaign,,2026-07-29,eviltokens;token-stealing,indicator--00000000-00000014-0000-0000-0000-000000000000,DOMAIN,100 azure-phish[.]cc,other,CRITICAL,EvilTokens Azure AD phishing subdomain,,Threat intelligence analysis - EvilTokens campaign,,2026-07-29,eviltokens;azure;m365,indicator--00000000-00000015-0000-0000-0000-000000000000,DOMAIN,100 incron-c2[.]onion[.]to,other,CRITICAL,INCRON ransomware C2 infrastructure,,CISA/FBI joint advisory,https://www.cisa.gov,2026-07-15,incron;ransomware;c2;darkweb,indicator--00000000-00000016-0000-0000-0000-000000000000,DOMAIN,100 blackcat-leak[.]ru,other,HIGH,BlackCat/ALPHV ransomware leak site,,Threat intelligence analysis,,2026-07-20,blackcat;alphv;ransomware;leak,indicator--00000000-00000017-0000-0000-0000-000000000000,DOMAIN,80 login-auth[.]online,other,HIGH,Known phishing domain - Microsoft/M365 impersonation,,Phishing intelligence,,2026-07-25,phishing;microsoft;m365,indicator--00000000-00000018-0000-0000-0000-000000000000,EMAIL ADDRESS,80 noreply@office365-verify[.]com,email-addr,CRITICAL,Phishing email sender - Microsoft 365 credential harvesting,,Email security analysis,,2026-07-28,phishing;m365;credential-harvesting,indicator--00000000-00000019-0000-0000-0000-000000000000,EMAIL ADDRESS,100 support@docusign-review[.]net,email-addr,CRITICAL,Phishing email sender - DocuSign impersonation (EvilTokens campaign),,Email security analysis,,2026-07-30,phishing;docusign;eviltokens,indicator--00000000-00000020-0000-0000-0000-000000000000,FILE HASH (SHA256),100 3a7b8c0e1234567890abcdef1234567890abcdef1234567890abcdef12345678,file-hash:sha256,CRITICAL,EvilTokens OAuth phishing tool sample,,Malware analysis - VirusTotal/HybridAnalysis,https://www.virustotal.com,2026-07-29,malware;eviltokens;oauth,indicator--00000000-00000021-0000-0000-0000-000000000000,FILE HASH (SHA256),100 a1b2c3d4e5f6a1b2c3d4e5f6a1b2c3d4e5f6a1b2c3d4e5f6a1b2c3d4e5f6a1b2,file-hash:sha256,CRITICAL,Fake Adobe/Zoom installer - installs ScreenConnect remote access tool,,Malware analysis - VirusTotal,https://www.virustotal.com,2026-07-30,trojan;screenconnect;fake-installer,indicator--00000000-00000022-0000-0000-0000-000000000000,FILE HASH (SHA256),100 f1e2d3c4b5a6f1e2d3c4b5a6f1e2d3c4b5a6f1e2d3c4b5a6f1e2d3c4b5a6f1e2,file-hash:sha256,CRITICAL,INCRON ransomware payload sample,,Malware analysis - incident response,,2026-07-20,incron;ransomware;encryptor,indicator--00000000-00000023-0000-0000-0000-000000000000,IP ADDRESS,100 185[.]220[.]101[.]xx,other,HIGH,Malware C2 infrastructure - data exfiltration campaigns,,Network traffic analysis - CISA/FBI threat intel,,2026-07-25,malware;c2;exfiltration,indicator--00000000-00000024-0000-0000-0000-000000000000,IP ADDRESS,80 45[.]153[.]240[.]xx,other,CRITICAL,Phishing infrastructure - OAuth credential harvesting,,CISA alert analysis,,2026-07-28,phishing;oauth;credential-harvesting,indicator--00000000-00000025-0000-0000-0000-000000000000,IP ADDRESS,100