Atlassian Rovo Can Be Tricked Into Sending Jira and Confluence Data to Attackers

2026-08-08T13:23:59Z39618b13c6421eb5977862ab2651e7b94f5430ee659f380c1908784129d6badb
CVE-2026-64561CVE-2026-64638CVE-2026-8037active-exploitationai-securityaitmcisa-kevcloud-securitycommand-injectioncryptocurrency-theftinfostealerkemp-loadmasterkvm-escapelinux-kernelmacosmalwaremetabasenpm-supply-chainphishingprompt-injectionratrcesaas-compromisesql-injectionvishingwordpressxsszero-day

What happened

The document aggregates cybersecurity news covering actively exploited vulnerabilities, zero-days, cloud and SaaS account compromise, AI prompt-injection risks, malware and supply-chain campaigns, phishing, container and VM escapes, network attacks, exposed industrial control systems, and cryptographic weaknesses. The most urgent items include a Metabase unauthenticated SQL injection exploited in the wild, a CISA KEV-listed Progress Kemp LoadMaster command injection flaw (CVE-2026-8037), a WordPress pre-authentication XSS leading to possible PHP code execution (CVE-2026-64638), and multiple R5

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
the_hacker_news
Record identifier
39618b13c6421eb5977862ab2651e7b94f5430ee659f380c1908784129d6badb
Enrichment time
2026-08-08T13:23:59Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.