Deep Security Center

RULE UPDATE: 26-042 (August 11, 2026)
* indicates a new version of an existing rule

Deep Packet Inspection Rules:

Web Server Common
1012626 - Foundation Agents MetaGPT Code Injection Vulnerability (CVE-2026-0761)


Integrity Monitoring Rules:

There are no new or updated Integrity Monitoring Rules in this Security Update.


Log Inspection Rules:

There are no new or updated Log Inspection Rules in this Security Update.
RULE UPDATE: 26-041 (August 6, 2026)
* indicates a new version of an existing rule

Deep Packet Inspection Rules:

Paperclip AI
1012622 - PaperclipAI Paperclip Code Injection Vulnerability (CVE-2026-41679)


Web Application Common
1009350* - Telerik UI for ASP.NET AJAX Multiple Arbitrary File Upload Vulnerabilities (CVE-2017-11357 and CVE-2017-11317)


Web Server Common
1012617 - Jenkins Deserialization Vulnerability (CVE-2026-53435)


Web Server HTTPS
1012605 - Cacti Command Injection Vulnerability (CVE-2024-29895)


Integrity Monitoring Rules:

There are no new or updated Integrity Monitoring Rules in this Security Update.


Log Inspection Rules:

There are no new or updated Log Inspection Rules in this Security Update.
RULE UPDATE: 26-040 (August 4, 2026)
* indicates a new version of an existing rule

Deep Packet Inspection Rules:

ActiveMQ OpenWire
1011897* - Apache ActiveMQ Insecure Deserialization Vulnerability (CVE-2023-46604)


Integrity Monitoring Rules:

There are no new or updated Integrity Monitoring Rules in this Security Update.


Log Inspection Rules:

There are no new or updated Log Inspection Rules in this Security Update.
RULE UPDATE: 26-039 (July 30, 2026)
* indicates a new version of an existing rule

Deep Packet Inspection Rules:

Oracle PeopleSoft PIA
1012580* - Oracle PeopleSoft PeopleTools SSRF Vulnerability (CVE-2026-35273)


Web Server Common
1012621 - SolarWinds Serv-U Denial Of Service Vulnerability (CVE-2026-28318)


Web Server HTTPS
1012620 - Heimdall Data Database Proxy Vulnerability (CVE-2025-12357)


Integrity Monitoring Rules:

There are no new or updated Integrity Monitoring Rules in this Security Update.


Log Inspection Rules:

There are no new or updated Log Inspection Rules in this Security Update.
RULE UPDATE: 26-038 (July 28, 2026)
* indicates a new version of an existing rule

Deep Packet Inspection Rules:

Splunk API
1012615 - Splunk Secure Gateway Deserialization Vulnerability (CVE-2026-20251)


Web Server Adobe ColdFusion
1012602 - Adobe ColdFusion Path Traversal Vulnerability (CVE-2026-48282)


Web Server Common
1012618 - Dolibarr ERP/CRM PHP Code Injection Vulnerability (CVE-2023-30253)


Integrity Monitoring Rules:

There are no new or updated Integrity Monitoring Rules in this Security Update.


Log Inspection Rules:

There are no new or updated Log Inspection Rules in this Security Update.
RULE UPDATE: 26-037 (July 23, 2026)
* indicates a new version of an existing rule

Deep Packet Inspection Rules:

Ivanti Endpoint Manager
1012616 - Ivanti Endpoint Manager Mobile Authentication Bypass Vulnerability (CVE-2026-5786)


JetBrains TeamCity
1012612 - JetBrains TeamCity Command Injection Vulnerability (CVE-2026-49373)


Web Application PHP Based
1012611 - ThinkPHP Framework Local File Inclusion Vulnerability (CVE-2022-47945)


Zimbra Proxy
1012607 - Zimbra Collaboration Local File Inclusion Vulnerability (CVE-2025-68645)


Integrity Monitoring Rules:

There are no new or updated Integrity Monitoring Rules in this Security Update.


Log Inspection Rules:

There are no new or updated Log Inspection Rules in this Security Update.
RULE UPDATE: 26-036 (July 21, 2026)
* indicates a new version of an existing rule

Deep Packet Inspection Rules:

Git Push
1012584* - GitHub Enterprise Server Command Injection Vulnerability (CVE-2026-3854)


Tomcat Tribes NioReceiver
1012610 - Apache Tomcat EncryptInterceptor Bypass Vulnerability (CVE-2026-34486)


Web Server Common
1012596* - Microsoft Exchange Server HTTP NTLM Password Spray


Web Server HTTPS
1012592* - Allegra Cross-Site Scripting Authentication Bypass Vulnerability(CVE-2026-11443)
1012613 - WordPress REST API Batch Route Confusion SQL Injection Vulnerability (CVE-2026-63030)


Web Server Nagios
1012614 - Nagios Log Server Command Injection Vulnerability (CVE-2025-34322)


Integrity Monitoring Rules:

There are no new or updated Integrity Monitoring Rules in this Security Update.


Log Inspection Rules:

There are no new or updated Log Inspection Rules in this Security Update.
RULE UPDATE: 26-035 (July 16, 2026)
* indicates a new version of an existing rule

Deep Packet Inspection Rules:

Linux Kernel Netfilter
1012603 - Linux Kernel Netfilter Nf_Conntrack_H323 Out-Of-Bounds Read Vulnerability (CVE-2026-23455)


Web Application PHP Based
1012606 - JoomShaper Helix3 Improper Access Control Vulnerability (CVE-2026-49049)
1012604 - Tassos Novarain Framework Improper Access Control Vulnerability (CVE-2026-21627)


Web Server Common
1012591 - Ivanti Sentry OS Command Injection Vulnerability (CVE-2026-10520)


Web Server HTTPS
1012599 - Cacti Unauthenticated Local File Inclusion Vulnerability (CVE-2026-39938)


Web Server SharePoint
1012609 - Microsoft SharePoint Remote Code Execution Vulnerability (CVE-2026-50522)
1012608 - Microsoft SharePoint Remote Code Execution Vulnerability (CVE-2026-56164)


Integrity Monitoring Rules:

There are no new or updated Integrity Monitoring Rules in this Security Update.


Log Inspection Rules:

There are no new or updated Log Inspection Rules in this Security Update.
RULE UPDATE: 26-034 (July 14, 2026)
* indicates a new version of an existing rule

Deep Packet Inspection Rules:

Oracle E-Business Suite Web Interface
1012600 - Oracle E-Business Suite Payments Authentication Bypass Vulnerability (CVE-2026-46817)


Web Server Common
1012590 - Apache Ofbiz Code Injection Vulnerability (CVE-2026-46586)


Integrity Monitoring Rules:

There are no new or updated Integrity Monitoring Rules in this Security Update.


Log Inspection Rules:

There are no new or updated Log Inspection Rules in this Security Update.
RULE UPDATE: 26-033 (July 9, 2026)
* indicates a new version of an existing rule

Deep Packet Inspection Rules:

Web Server HTTPS
1012598 - ATEN Unizon uploadSSL Directory Traversal Arbitrary File Deletion Vulnerability (CVE-2026-9775)


Integrity Monitoring Rules:

There are no new or updated Integrity Monitoring Rules in this Security Update.


Log Inspection Rules:

There are no new or updated Log Inspection Rules in this Security Update.