Vulnerability Digest September 2026 Updates – Third-Party Updates
This digest explains the most serious vulnerabilities in popular software that have been patched over the past month.
CVE-2026-20303 – Cisco Catalyst SD-WAN Controller
“Critical weaknesses in a central network controller can put access controls, sensitive data, and core infrastructure at risk.”
Cisco software hardening releases address five internally discovered vulnerabilities in Catalyst SD-WAN Controller. CVE-2026-20303 has a CVSS score of 9.9, Critical severity, and involves improper input validation. CVE-2026-20304 has a CVSS score of 9.9, Critical severity, and involves improper access control. CVE-2026-20310 has a CVSS score of 9.1, Critical severity, and affects link resolution before file access.
CVE-2026-20312 has a CVSS score of 8.8, High severity, and involves cleartext storage of sensitive information. CVE-2026-20313 has a CVSS score of 7.7, High severity, and involves improper link resolution. Cisco's software hardening releases address these controller weaknesses.
CVE-2026-20272 – Cisco IOS XE Software
“Critical and high-severity weaknesses put core network devices at risk of compromise and service disruption.”
Cisco software hardening releases address eight vulnerabilities in IOS XE Software. CVE-2026-20272 has a CVSS score of 9.8, Critical severity. CVE-2026-20267 has a CVSS score of 9.0, Critical severity. CVE-2026-20263, CVE-2026-20268, CVE-2026-20269, CVE-2026-20270, CVE-2026-20271, and CVE-2026-20273 each have a CVSS score of 8.6, High severity.
The vulnerabilities span access control, memory handling, input validation, resource management, control flow, and special-element neutralization. The BEEP vulnerability can allow an unauthenticated remote attacker to force an affected device to reload, causing denial of service, while the memory-handling flaw presents code execution and privilege escalation risk.
CVE-2026-58231 – SAP Products
“Critical SAP flaws put core applications at risk of code execution, system compromise, and severe disruption.”
SAP patches address three Critical vulnerabilities across Commerce Cloud, Manufacturing Integration and Intelligence, and NetWeaver and ABAP Platform. CVE-2026-58231 has a CVSS score of 10.0, Critical severity, and can allow an unauthenticated attacker to execute arbitrary code. CVE-2026-44758 has a CVSS score of 9.1, Critical severity, and can allow a highly privileged attacker to execute arbitrary operating-system commands. CVE-2026-34265 has a CVSS score of 9.8, Critical severity, and can allow an unauthenticated attacker to trigger memory corruption, potentially exposing sensitive information or crashing the system.
These vulnerabilities can significantly affect confidentiality, integrity, and availability across critical SAP environments.
CVE-2026-62913 – Microsoft Exchange Server 2016 CU23
“Multiple Exchange flaws create paths to code execution, privilege escalation, and broader server compromise.”
Microsoft Exchange Server 2016 CU23 is affected by six vulnerabilities spanning remote code execution, privilege escalation, and other security weaknesses. CVE-2026-62913 has a CVSS score of 8.8, High severity. CVE-2026-62911 has a CVSS score of 8.0, High severity. CVE-2026-62910 has a CVSS score of 7.2, High severity. CVE-2026-62912 has a CVSS score of 6.5, Medium severity. CVE-2026-62914 has a CVSS score of 7.3, High severity. CVE-2026-62915 has a CVSS score of 6.5, Medium severity.
The patch addresses the affected Exchange Server components and reduces the risk of server compromise, unauthorized privilege gains, and disruption.
CVE-2026-10090 – Red Hat Advanced Cluster Management for Kubernetes 2
“A namespace-level user can turn a trusted deployment controller into a path to full cluster-admin control.”
CVE-2026-10090 is a Critical privilege escalation vulnerability in the Application Subscription controller. The CVSS score is 9.0, which is Critical severity. A user with namespace-scoped edit privileges can supply a controlled Helm chart containing cluster-scoped resources that the controller applies using its elevated authority.
Successful exploitation can create a ClusterRoleBinding that grants the attacker full cluster-admin privileges, allowing compromise of the Kubernetes cluster.
CVE-2026-18367 – Sophos Endpoint for macOS
“A local foothold can become full root control on vulnerable Sophos-protected Macs.”
CVE-2026-18367 is a Critical privilege escalation vulnerability affecting Sophos Endpoint for macOS before version 2026.1.1 and Sophos Home for macOS before version 10.11.6. The CVSS score is 9.3, which is Critical severity. A local user can exploit the vulnerability to execute arbitrary code with root privileges.
Sophos Endpoint for macOS 2026.1.1 and Sophos Home for macOS 10.11.6 address the vulnerability.
CVE-2026-18667 – Tenable Sensor Proxy
“A malicious connection target can turn a trusted sensor deployment into a path for elevated code execution.”
CVE-2026-18667 is a Critical vulnerability affecting Tenable Sensor Proxy. The CVSS score is 9.6, which is Critical severity. A remote attacker can execute code with elevated privileges by convincing an operator to connect the sensor to an attacker-controlled host.
The Tenable security update addresses the vulnerable connection path and prevents an attacker-controlled host from being used to achieve elevated code execution.
CVE-2026-20349 – Cisco Secure Firewall ASA Software
“Active exploitation turns a firewall availability flaw into an immediate risk of remote service disruption.”
CVE-2026-20349 is a High-severity denial-of-service vulnerability affecting the Remote Access SSL VPN service in Cisco Secure Firewall ASA and FTD Software. The CVSS score is 8.6, which is High severity. An unauthenticated remote attacker can send a crafted HTTP request that causes an affected device to reload unexpectedly, disrupting VPN and firewall availability.
The vulnerability is actively exploited, increasing the urgency for affected deployments. Cisco security updates address the insufficient HTTP request error handling that enables the attack.
CVE-2026-72898 – Metabase
“Active exploitation of a maximum-severity SQL injection flaw puts exposed Metabase instances at immediate risk of administrative takeover.”
CVE-2026-72898 is a Critical SQL injection vulnerability affecting Metabase. The CVSS score is 10.0, which is Critical severity. A remote unauthenticated attacker can inject arbitrary SQL through the /reset_password database endpoint and gain administrator access to the connected Metabase instance.
The vulnerability is actively exploited, making unpatched and externally accessible deployments a significant compromise risk.
CVE-2026-71362 – Adobe Commerce
“A critical authorization flaw can elevate attacker access, while stored scripts put customer and administrator sessions at risk.”
Adobe Commerce is affected by three vulnerabilities involving authorization and stored cross-site scripting. CVE-2026-71362 has a CVSS score of 9.1, Critical severity, and can allow privilege escalation to sensitive resources without user interaction. CVE-2026-48414 has a CVSS score of 7.7, High severity. CVE-2026-48413 has a CVSS score of 8.7, High severity. Both High-severity flaws allow malicious JavaScript to be stored in vulnerable fields and executed in a victim's browser.
The Adobe Commerce security update addresses these weaknesses, reducing the risk of unauthorized privilege gains and compromise of user accounts or sessions.
CVE-2026-59310 – VMware Cloud Foundation
“A critical vCenter flaw puts the virtualization management plane at risk of complete code execution.”
CVE-2026-59310 is a Critical directory traversal vulnerability in the vCenter Syslog server affecting VMware Cloud Foundation. An unauthenticated attacker with network access to vCenter can exploit the flaw to execute arbitrary code. The CVSS score is 9.8, which is Critical severity.
VMware has released fixed versions for affected vCenter and Cloud Foundation deployments. There is no workaround, making the security update the available remediation.
CVE-2026-71398 – Adobe Campaign Classic
“Critical authorization flaws can turn improper access into full code execution.”
Adobe Campaign Classic is affected by two critical incorrect authorization vulnerabilities that can result in arbitrary code execution in the context of the current user without user interaction. CVE-2026-71398 has a CVSS score of 10.0, Critical severity. CVE-2026-27302 has a CVSS score of 10.0, Critical severity.
Both vulnerabilities represent maximum-severity exposure and affect authorization controls within Adobe Campaign Classic.
CVE-2026-21962 – Oracle HTTP Server, Oracle WebLogic Server Proxy Plug-in
“A maximum-severity, actively exploited flaw can expose or alter critical data through unauthenticated HTTP access.”
Oracle addresses a Critical vulnerability in the WebLogic Server Proxy Plug-in for Apache HTTP Server and IIS. CVE-2026-21962 allows an unauthenticated remote attacker with HTTP access to compromise affected Oracle HTTP Server and WebLogic Server Proxy Plug-in deployments. Successful exploitation can provide unauthorized access to critical data and allow creation, deletion, or modification of protected information. The CVSS score is 10.0, which is Critical severity.
Active exploitation is confirmed. Affected versions include 12.2.1.4.0, 14.1.1.0.0, and 14.1.2.0.0, with the IIS plug-in affected at 12.2.1.4.0. Oracle addressed the issue in its January 2026 Critical Patch Update.
CVE-2026-19490 – NetScaler ADC
“A critical vulnerability puts affected NetScaler ADC and Gateway deployments at significant security risk.”
NetScaler ADC and NetScaler Gateway are affected by CVE-2026-19490. The issue affects ADC and Gateway versions 14.1 through 73.32 and 13.1 through 63.21. The CVSS score is 9.3, which is Critical severity. Active exploitation is expected.
CVE-2026-18129 – Ivanti Endpoint Manager
“Three high-impact flaws put credentials, endpoint availability, and session-storage integrity at risk.”
Ivanti Endpoint Manager before version 2024 SU7 is affected by three High-severity vulnerabilities. CVE-2026-18129 exposes external SQL credentials to a remote unauthenticated attacker in a MITM position. The CVSS score is 8.1, which is High severity. CVE-2026-18125 allows a remote unauthenticated attacker to crash the Agent service. The CVSS score is 7.5, which is High severity. CVE-2026-18127 allows a remote authenticated attacker to gain full write control over an S3 bucket used for session recording. The CVSS score is 7.7, which is High severity.
Ivanti Endpoint Manager 2024 SU7 addresses these issues across the Core and Agent components.
CVE-2026-8037 – Progress LoadMaster
“A public exploit turns an exposed LoadMaster API into a direct path for remote command execution.”
CVE-2026-8037 is a Critical OS command injection vulnerability affecting Progress LoadMaster. The flaw allows an unauthenticated remote attacker to execute arbitrary commands through vulnerable API functionality. The CVSS score is 9.6, which is Critical severity.
Progress addressed the vulnerability in updated LoadMaster releases. Public proof-of-concept exploit code is available, significantly increasing the risk to unpatched systems.
CVE-2026-53413 – Zoom Clients
“A malicious meeting participant could turn Zoom’s annotation features into a path for code execution or disruption.”
Zoom Clients are affected by three vulnerabilities in the annotator functionality. CVE-2026-53413 has a CVSS score of 8.3, High severity, and may allow a meeting participant to remotely execute code on another participant’s system through a buffer overwrite. CVE-2026-53414 has a CVSS score of 6.5, Medium severity, and may allow denial of service through a buffer over-read. CVE-2026-53415 has a CVSS score of 8.3, High severity, and may allow remote code execution through a use-after-free condition.
Updated Zoom Clients address these annotation-related vulnerabilities and reduce the risk of participant-to-participant compromise and service disruption.
CVE-2026-58048 – cPanel
“A database rename operation can expose cPanel systems to SQL execution with root-level context.”
CVE-2026-58048 is a Critical SQL injection vulnerability affecting cPanel. Improper preservation of SQL mode during database rename operations can allow SQL to execute in root context. The CVSS score is 9.4, which is Critical severity.
The cPanel security update addresses the database-handling flaw and prevents the vulnerable SQL execution path.
CVE-2026-69251 – Flowise
“Multiple paths to server-side code execution make this a high-impact Flowise update.”
Flowise 3.1.3 fixes a broad set of vulnerabilities affecting agent nodes, record managers, sandbox controls, TypeORM configuration, Pyodide execution, and custom JavaScript handling. CVE-2026-69251, CVE-2026-73601, CVE-2026-69253, CVE-2026-73602, CVE-2026-73485, CVE-2026-73486, and CVE-2026-73487 each have a CVSS score of 9.0, Critical severity. CVE-2026-69256, CVE-2026-69259, CVE-2026-69264, and CVE-2026-69254 each have a CVSS score of 9.4, Critical severity. CVE-2026-69255 has a CVSS score of 9.2, Critical severity. CVE-2026-70477 and CVE-2026-70470 each have a CVSS score of 9.5, Critical severity. CVE-2026-73484 has a CVSS score of 8.6, High severity.
Several flaws provide remote code execution paths through crafted configuration, prompt injection, unsafe Python execution, sandbox escapes, and validator bypasses. Public proof-of-concept exploitation is confirmed for multiple issues in this group. Flowise 3.1.3 contains the fixes.
CVE-2026-11803 – Autodesk Revit
“A malicious design file can turn routine content processing into code execution, data exposure, or application failure.”
Autodesk Revit is affected by four file-processing vulnerabilities. CVE-2026-11803 has a CVSS score of 7.8, High severity, and can allow code execution, sensitive data exposure, or a crash through a malicious PDF. CVE-2026-1289 has a CVSS score of 7.8, High severity, and can trigger similar impacts through a use-after-free condition. CVE-2026-7406 has a CVSS score of 7.8, High severity, and can allow arbitrary code execution through a crafted BMP file. CVE-2026-8325 has a CVSS score of 7.8, High severity, and can cause code execution, data corruption, or a crash through a malicious PDF.
The Revit security update addresses these unsafe file-processing paths and reduces the risk from malicious PDF and BMP content.
CVE-2026-64564 – Linux Kernel
“Critical memory and networking flaws can turn routine kernel operations into crashes, corruption, and unsafe memory access.”
Linux kernel updates resolve 26 vulnerabilities across SCTP, SMB, KVM, Wi-Fi, Btrfs, BPF, XFRM, RDMA, USB, networking, FUSE, and cryptographic components. CVE-2026-64564, CVE-2026-64566, and CVE-2026-64597 each have a CVSS score of 9.8, Critical severity. The remaining vulnerabilities range from CVSS 7.0 to 8.8, all High severity.
CVE List:
CVE-2026-64564 (9.8)
CVE-2026-64566 (9.8)
CVE-2026-64597 (9.8)
CVE-2026-64561 (8.8)
CVE-2026-64562 (8.8)
CVE-2026-64578 (8.2)
CVE-2026-64586 (8.8)
CVE-2026-64598 (8.8)
CVE-2026-64563 (7.8)
CVE-2026-64567 (7.8)
CVE-2026-64568 (7.8)
CVE-2026-64570 (7.8)
CVE-2026-64574 (7.8)
CVE-2026-64575 (7.8)
CVE-2026-64576 (7.1)
CVE-2026-64577 (7.5)
CVE-2026-64580 (7.8)
CVE-2026-64581 (7.8)
CVE-2026-64582 (7.8)
CVE-2026-64583 (7.8)
CVE-2026-64584 (7.8)
CVE-2026-64585 (7.8)
CVE-2026-64587 (7.0)
CVE-2026-64588 (7.8)
CVE-2026-64599 (7.8)
CVE-2026-64601 (7.8)
The flaws include use-after-free, double-free, out-of-bounds access, race conditions, memory corruption, invalid pointer handling, and kernel panic conditions. Updated Linux kernel releases contain fixes that strengthen memory lifetime, bounds checking, synchronization, and error handling across the affected subsystems.
Three vulnerabilities carry 9.8 Critical severity scores.
The update fixes numerous kernel memory-safety and resource-lifetime weaknesses.
Several flaws can cause memory corruption, use-after-free conditions, or kernel panics.
Fixes span networking, virtualization, storage, wireless, USB, and other kernel subsystems.
CVE-2026-17626 – IBM Langflow OSS
“Multiple high-severity flaws expose Langflow to code execution, security bypasses, and sensitive data compromise.”
IBM Langflow OSS is affected by 16 High-severity vulnerabilities, primarily impacting versions 1.0.0 through 1.10.3. CVE-2026-17626, CVE-2026-17632, CVE-2026-8182, CVE-2026-8478, and CVE-2026-9201 have CVSS scores of 8.8, High severity. CVE-2026-17633 and CVE-2026-9077 have CVSS scores of 8.5, High severity. CVE-2026-9196 has a CVSS score of 8.1, High severity. The remaining eight vulnerabilities have CVSS scores ranging from 7.1 to 7.7, all High severity.
The flaws include arbitrary code and command execution, authentication and authorization bypass, host-file access, directory traversal, SSRF, weak cryptography, and cross-user information disclosure. Several vulnerabilities can expose the Langflow backend or underlying host to direct compromise.
CVE List:
CVE-2026-17626 (8.8)
CVE-2026-17632 (8.8)
CVE-2026-17633 (8.5)
CVE-2026-8182 (8.8)
CVE-2026-8478 (8.8)
CVE-2026-9077 (8.5)
CVE-2026-9196 (8.1)
CVE-2026-9201 (8.8)
CVE-2026-17625 (7.2)
CVE-2026-17630 (7.2)
CVE-2026-8183 (7.7)
CVE-2026-8446 (7.5)
CVE-2026-8470 (7.4)
CVE-2026-9081 (7.1)
CVE-2026-9130 (7.1)
CVE-2026-9205 (7.4)
The affected Langflow releases contain a broad attack surface across MCP, components, and backend validation.
CVE-2026-7329 – Progress MarkLogic Server
“Multiple critical flaws can turn limited or unauthenticated access into administrator-level control and sensitive data exposure.”
Progress MarkLogic Server before 11.3.6 and 12.0.3 is affected by ten High and Critical vulnerabilities. CVE-2026-7329, CVE-2026-8709, and CVE-2026-9193 each have a CVSS score of 9.9, Critical severity. CVE-2026-9192 has a CVSS score of 9.8, Critical severity. CVE-2026-9195 has a CVSS score of 9.3, Critical severity. CVE-2026-7557 and CVE-2026-9190 each have a CVSS score of 9.1, Critical severity. CVE-2026-9203, CVE-2026-7327, and CVE-2026-7326 have CVSS scores of 8.5, 8.1, and 7.5 respectively, all High severity.
The vulnerabilities include privilege escalation to administrator, SAML and ODBC authentication bypass, HTTP request smuggling, SSRF, cross-site scripting, and CSRF. MarkLogic Server 11.3.6 and 12.0.3 address these weaknesses.
CVE List:
CVE-2026-7329 (9.9)
CVE-2026-7557 (9.1)
CVE-2026-8709 (9.9)
CVE-2026-9190 (9.1)
CVE-2026-9192 (9.8)
CVE-2026-9193 (9.9)
CVE-2026-9195 (9.3)
CVE-2026-7327 (8.1)
CVE-2026-9203 (8.5)
CVE-2026-7326 (7.5)
CVE-2026-25289 – Qualcomm Snapdragon
“A critical wireless memory flaw leads a broader set of Snapdragon weaknesses that can threaten device security and availability.”
Qualcomm Snapdragon updates address eight vulnerabilities across wireless, authentication, fingerprint, device-driver, fastboot, and security-capability processing. CVE-2026-25289 has a CVSS score of 9.6, Critical severity, and involves memory corruption while processing malformed NAN Service Discovery frames. CVE-2026-24079 has a CVSS score of 8.1, High severity. CVE-2026-21366, CVE-2026-24080, and CVE-2026-24083 each have a CVSS score of 7.8, High severity. CVE-2026-25292, CVE-2026-24084, and CVE-2026-25288 have CVSS scores of 7.6, 7.5, and 7.4 respectively, all High severity.
The vulnerabilities include memory corruption, authentication weaknesses, and denial-of-service conditions. Several flaws present code execution or privilege escalation risk, making the Critical wireless vulnerability and High-severity memory-safety issues the primary concerns.
CVE List:
CVE-2026-25289 (9.6)
CVE-2026-24079 (8.1)
CVE-2026-21366 (7.8)
CVE-2026-24080 (7.8)
CVE-2026-24083 (7.8)
CVE-2026-24084 (7.5)
CVE-2026-25288 (7.4)
CVE-2026-25292 (7.6)
CVE-2026-44945 – SUSE Rancher
“A critical Rancher flaw can turn standard user access into administrative control across the entire managed cluster environment.”
SUSE Rancher is affected by two significant vulnerabilities. CVE-2026-44945 has a CVSS score of 9.1, Critical severity, and allows an authenticated user with the default user global role to gain full administrative access to the Rancher control plane and downstream clusters. CVE-2026-59675 has a CVSS score of 7.5, High severity, and allows an unauthenticated attacker to exhaust Rancher Manager memory through oversized login requests when API audit logging is enabled.
Fixed Rancher releases address the privilege escalation and denial-of-service paths, protecting centralized management of downstream Kubernetes clusters.
CVE-2026-70426 – Jenkins
“A critical Remoting weakness can bypass a core Jenkins security boundary, while two file-handling flaws expose the controller to arbitrary writes.”
Jenkins updates address three vulnerabilities affecting Remoting and controller file handling. CVE-2026-70426 has a CVSS score of 9.0, Critical severity, and allows agent processes, code running on agents, or users with Agent/Connect permission to bypass the JEP-200 deserialization class filter. CVE-2026-70427 and CVE-2026-70428 each have a CVSS score of 4.3, Medium severity.
The Medium-severity flaws can allow files to be written to arbitrary locations on the Jenkins controller through crafted archives or file parameter path traversal. Updated Jenkins and Remoting releases address these weaknesses.
CVE-2026-20337 – Cisco Secure Endpoint
“Crafted files can disrupt security scanning and expose vulnerable endpoints to memory corruption.”
Cisco Secure Endpoint is affected by seven high-severity ClamAV vulnerabilities involving ZIP, PESpin, GPT, PDF, Mach-O, and XAR file parsing. An unauthenticated remote attacker can submit crafted content for scanning and trigger memory handling or boundary-checking failures, causing the ClamAV scanning process to terminate and resulting in denial of service.
CVE-2026-20337, CVE-2026-20338, CVE-2026-20339, CVE-2026-20345, CVE-2026-20346, CVE-2026-20347, and CVE-2026-20348 each have a CVSS score of 7.5, High severity. Several flaws involve memory corruption conditions with potentially expanded impact.
CVE-2026-66147 – SonicWall GMS
“Critical flaws expose vulnerable GMS systems to remote compromise without authentication.”
SonicWall GMS is affected by two critical remote code execution vulnerabilities in GMS 9.5.1 and earlier versions. CVE-2026-66147 is a command injection vulnerability in the GMS Dispatcher Service that allows an unauthenticated remote attacker to execute code through specially crafted requests. CVE-2026-66147 has a CVSS score of 9.4, Critical severity.
CVE-2026-66145 allows an unauthenticated remote attacker to read sensitive data and perform arbitrary file writes through a Zip Slip condition, creating a path to remote code execution. CVE-2026-66145 has a CVSS score of 9.1, Critical severity.
CVE-2026-26035 – Fortinet FortiWeb, FortiManager, and FortiClientWindows
“Authentication failures and a remote code execution flaw put critical Fortinet security controls at risk.”
Fortinet addresses three high-severity vulnerabilities across FortiWeb, FortiManager, and FortiClientWindows. CVE-2026-26035 allows an unauthenticated remote attacker to bypass FortiWeb authentication and access the GUI or CLI using arbitrary credentials. CVE-2026-26035 has a CVSS score of 8.8, High severity.
CVE-2026-70468 is an authentication bypass affecting FortiManager and FortiManager Cloud that can result in improper access control. It has a CVSS score of 7.3, High severity. CVE-2026-70465 is a FortiClientWindows buffer overflow that can enable arbitrary code execution through malicious DNS responses. It has a CVSS score of 7.3, High severity.
CVE-2026-48397 – Adobe Lightroom Classic
“Malicious files can turn routine image workflows into a path for code execution or sensitive data exposure.”
Adobe Lightroom Classic is affected by ten high-severity vulnerabilities involving unsafe deserialization, path traversal, integer overflow, and out-of-bounds writes. CVE-2026-48397 and CVE-2026-48441 each have a CVSS score of 8.6, High severity. CVE-2026-47940, CVE-2026-48404, CVE-2026-48405, CVE-2026-48406, CVE-2026-48407, CVE-2026-48408, CVE-2026-48409, and CVE-2026-48410 each have a CVSS score of 7.8, High severity.
Most of these vulnerabilities can result in arbitrary code execution in the context of the current user. The path traversal vulnerability can expose sensitive files and directories outside the intended access scope. Exploitation requires a victim to open a malicious file.
CVE-2026-62420 – Canonical LXD
“Critical LXD flaws can break project isolation and turn crafted migrations or archives into host-level compromise.”
Canonical LXD is affected by ten vulnerabilities spanning authorization bypass, symlink handling, path traversal, configuration injection, and resource-limit enforcement. CVE-2026-62420, CVE-2026-63293, CVE-2026-63294, CVE-2026-63296, CVE-2026-63297, CVE-2026-63300, and CVE-2026-66898 each have a CVSS score of 9.9, Critical severity. These flaws can bypass project restrictions, enable arbitrary host file access or modification, and, in the case of CVE-2026-63294, lead to root command execution.
CVE-2026-16033 and CVE-2026-63299 each have a CVSS score of 8.5, High severity. CVE-2026-63298 has a CVSS score of 8.7, High severity and can enable arbitrary code execution with LXD daemon privileges. Public proof-of-concept information is available for CVE-2026-63293, CVE-2026-63294, CVE-2026-63296, CVE-2026-63297, CVE-2026-63300, CVE-2026-66898, CVE-2026-16033, and CVE-2026-63298.
CVE-2026-19478 – GitLab
“A Critical GraphQL flaw can let unauthenticated attackers alter public projects, while several authorization and XSS issues weaken project and pipeline controls.”
GitLab fixes one Critical and six High-severity vulnerabilities across GitLab CE/EE. CVE-2026-19478 can allow an unauthenticated attacker to remotely modify or delete public projects and user data through a GraphQL directive. The CVSS score is 9.4, which is Critical severity.
CVE-2026-15216 and CVE-2026-15217 are analytics dashboard cross-site scripting flaws, each with a CVSS score of 8.7, High severity. CVE-2026-15423 can let a developer run CI/CD pipelines on protected branches without the required push permission, while CVE-2026-19228 can misattribute AI usage across namespaces; both score 8.5, High severity. CVE-2026-16494 scores 7.1 and can allow unauthorized project-setting changes, while CVE-2026-16627 scores 7.7 and can enable privilege escalation through unsafe HTML handling.
CVE-2026-10543 – IBM Db2
“Memory corruption and privilege escalation flaws put vulnerable Db2 environments at risk of deeper system compromise.”
IBM Db2 11.5.0 through 11.5.9 and 12.1.0 through 12.1.5 are affected by two high-severity vulnerabilities. CVE-2026-10534 is a buffer overflow in the IXF IMPORT parser that can create a path to code execution. The CVSS score is 8.4, which is High severity.
CVE-2026-10543 can allow privilege escalation through a specially crafted query. The CVSS score is 8.2, which is High severity.
CVE-2026-13361 – IBM Informix Dynamic Server
“Code execution and privilege escalation flaws can turn vulnerable database services into a path for system compromise.”
IBM Informix Dynamic Server is affected by three high-severity vulnerabilities. CVE-2026-13361 involves an unchecked SQL interface length field that can enable remote code execution and has a CVSS score of 8.8, High severity. CVE-2026-13367 affects the oninit setuid-root utility and can enable local privilege escalation. It has a CVSS score of 7.8, High severity.
CVE-2026-13476 can allow an unauthenticated attacker to execute arbitrary commands with service account privileges because of improper input validation. It has a CVSS score of 7.3, High severity.
CVE-2026-12004 – IBM Security Verify Access
“Management and access-control weaknesses can expose sensitive data, disrupt services, and expand attacker privileges.”
IBM Security Verify Access, Verify Identity Access, and Verify Identity Access Container are affected by six high-severity vulnerabilities. CVE-2026-12004 has a CVSS score of 8.7, High severity and can cause information disclosure and denial of service through a malicious HTTP request. CVE-2026-12359 and CVE-2026-13267 each have a CVSS score of 8.1, High severity and can expose sensitive information or allow an authenticated user to gain another user's privileges.
CVE-2026-11923 has a CVSS score of 7.4, High severity and involves weaker-than-expected cryptographic validation. CVE-2026-12005 and CVE-2026-12618 each have a CVSS score of 7.2, High severity and can allow privileged users to perform additional operations or commands through improper input validation.
CVE-2026-14525 – IBM WebSphere Application Server – Liberty
“Authentication and privilege-control failures can expose vulnerable Liberty environments to unauthorized access and elevated privileges.”
IBM WebSphere Application Server Liberty versions 17.0.0.3 through 26.0.0.8 are affected by two vulnerabilities. CVE-2026-14525 is an authentication bypass affecting systems where the rtcomm-1.0 or rtcommGateway-1.0 feature is enabled. CVE-2026-14525 has a CVSS score of 9.4, Critical severity.
CVE-2026-18499 affects environments using Liberty collectives and can enable privilege escalation. CVE-2026-18499 has a CVSS score of 8.1, High severity.
CVE-2026-53791 – rsync
“A broad set of rsync flaws can break access boundaries, corrupt memory, execute commands, and expose files beyond intended transfer paths.”
rsync is affected by 33 vulnerabilities, including one Critical, 18 High, and 14 Medium severity issues. CVE-2026-53791 has a CVSS score of 9.1, Critical severity and can allow unauthenticated attackers to spoof source addresses and bypass IP-based access controls. High-severity issues include command injection, out-of-bounds memory writes, authorization bypass, arbitrary file access or writes, TLS certificate validation weaknesses, path traversal, privilege escalation, and denial of service. The High CVSS scores range from 7.1 to 8.2.
The Medium vulnerabilities have CVSS scores ranging from 4.7 to 6.5 and include additional path and symlink weaknesses, memory-safety flaws, authorization bypass, resource exhaustion, and file manipulation risks. Multiple issues affect rsync releases before 3.5.0, with the patch set strengthening memory safety, filesystem confinement, authentication and authorization controls, and daemon resilience.
CVE-2026-73233 – FreeCAD
“Crafted FreeCAD files can cross filesystem boundaries, expose sensitive data, or execute attacker-controlled code.”
FreeCAD versions before 1.1.2 are affected by three vulnerabilities involving path traversal, XML external entities, and code injection. CVE-2026-73233 has a CVSS score of 8.5, High severity and can execute arbitrary Python code with the FreeCAD process's privileges through crafted FEM displacement formulas. CVE-2026-73234 has a CVSS score of 7.8, High severity and can write attacker-controlled content to arbitrary locations accessible to the FreeCAD user. Public proof-of-concept information is available for both vulnerabilities.
CVE-2026-73235 has a CVSS score of 6.1, Medium severity and can allow crafted FreeCAD documents to read local files or initiate network requests through unsafe external XML entity processing. These vulnerabilities are fixed in FreeCAD 1.1.2.
CVE-2026-56654 – Gitea Open Source Git Server
“Widespread access-control flaws can expose private repositories, elevate privileges, and break trust boundaries across Gitea.”
Gitea is affected by 48 vulnerabilities spanning privilege escalation, authorization and token-scope bypasses, SSRF, private repository and identity disclosure, denial of service, and repository security-control weaknesses. Critical vulnerabilities include CVE-2026-56654 with a CVSS score of 9.8, CVE-2026-56443 with a CVSS score of 9.6, and CVE-2026-55982, CVE-2026-58433, CVE-2026-58443, CVE-2026-58508, and CVE-2026-56750 with CVSS scores of 9.1. All are Critical severity.
High-severity vulnerabilities range from CVSS 7.1 to 8.5 and include private-resource authorization bypasses, SSRF, repository information exposure, TLS validation weaknesses, branch protection bypass, and unauthorized repository manipulation. Additional Medium and Low vulnerabilities affect token enforcement, package processing, webhooks, repository migration, information disclosure, and denial-of-service protections. Public proof-of-concept information is available for many vulnerabilities in this group.
CVE List:
CVE-2026-23603, CVE-2026-24059, CVE-2026-24791, CVE-2026-42931, CVE-2026-50105, CVE-2026-54481, CVE-2026-55982, CVE-2026-55984, CVE-2026-55986, CVE-2026-55987, CVE-2026-25714, CVE-2026-56443, CVE-2026-56654, CVE-2026-56657, CVE-2026-56750, CVE-2026-56755, CVE-2026-57886, CVE-2026-57894, CVE-2026-57897, CVE-2026-58314, CVE-2026-58416, CVE-2026-58417, CVE-2026-58420, CVE-2026-58425, CVE-2026-58427, CVE-2026-58428, CVE-2026-58429, CVE-2026-58431, CVE-2026-58432, CVE-2026-58433, CVE-2026-58434, CVE-2026-58435, CVE-2026-58436, CVE-2026-58437, CVE-2026-58438, CVE-2026-58439, CVE-2026-58440, CVE-2026-58441, CVE-2026-58442, CVE-2026-58443, CVE-2026-58444, CVE-2026-58445, CVE-2026-58507, CVE-2026-58508, CVE-2026-58510, CVE-2026-58511, CVE-2026-59763, CVE-2026-59765
CVE-2026-69112 – Hugging Face Accelerate
“A malicious checkpoint can reach beyond its intended files and expose sensitive data on the host.”
Hugging Face Accelerate through version 1.14.0 is affected by a path traversal vulnerability in checkpoint-loading functions. Crafted checkpoint indexes can use relative or absolute paths to access arbitrary files, while malicious shard references can also cause indefinite blocking and denial of service. CVE-2026-69112 has a CVSS score of 7.1, High severity.
Public proof-of-concept information is available for this vulnerability.
CVE-2026-59090 – Red Hat Enterprise Linux 6 / GIMP
“A malicious image can turn routine file handling into code execution or memory corruption.”
GIMP components distributed with Red Hat Enterprise Linux 6 are affected by four vulnerabilities involving unsafe image-file processing. CVE-2026-59090 has a CVSS score of 8.4, High severity and can lead to arbitrary code execution through a crafted PSD file. CVE-2026-59087 has a CVSS score of 7.8, High severity and can cause memory corruption, code execution, or denial of service. CVE-2026-59091 has a CVSS score of 7.3, High severity and affects PSD and PAA file processing.
CVE-2026-59088 has a CVSS score of 5.5, Medium severity and can cause denial of service when a crafted FLI file triggers an integer overflow. Public proof-of-concept information is available for CVE-2026-59090.
CVE-2026-67614 – CyberPanel
“Authentication and command-handling flaws can turn CyberPanel access into full control of the underlying server.”
CyberPanel is affected by five vulnerabilities spanning forged authentication, root-level access, command injection, arbitrary file reads, and path traversal. CVE-2026-67614 has a CVSS score of 9.8, Critical severity and can allow an unauthenticated remote attacker to forge authentication tokens and obtain an interactive root shell. CVE-2026-71965 and CVE-2026-71966 each have a CVSS score of 8.8, High severity; their impact includes persistent root SSH access and arbitrary OS command execution.
CVE-2026-71964 has a CVSS score of 6.5, Medium severity and can expose arbitrary system files through crafted ZIP archives. CVE-2026-67613 has a CVSS score of 4.9, Medium severity and can expose files readable by the CyberPanel process through path traversal. Public proof-of-concept information is available for CVE-2026-71966 and CVE-2026-71964.
CVE-2026-19696 – Wireshark
“Crafted capture files can crash vulnerable Wireshark installations and disrupt packet-analysis workflows.”
Wireshark versions 4.6.0 through 4.6.7 are affected by three file-parser vulnerabilities that can trigger denial of service. CVE-2026-19696 affects the Ixia IxVeriWave and Vector Informatik BLF parsers and has a CVSS score of 6.6, Medium severity. CVE-2026-19694 affects the TTX Logger parser and CVE-2026-19695 affects the Gammu DCT3 trace parser; each has a CVSS score of 4.7, Medium severity.
Public proof-of-concept information is available for all three vulnerabilities.
CVE-2026-33264 – Apache Airflow
“Unsafe deserialization and access-control gaps can expose Airflow’s most trusted components, credentials, and workflow boundaries.”
Apache Airflow is affected by 16 vulnerabilities covering unsafe deserialization, remote code execution, secret exposure, authorization weaknesses, and cross-team access. CVE-2026-33264 has a CVSS score of 9.8, Critical severity and can allow malicious DAG content to execute code in the API Server or Scheduler. CVE-2026-58076 and CVE-2026-67587 each have a CVSS score of 8.8, High severity; CVE-2026-67260 has a CVSS score of 7.3, High severity; and CVE-2026-68968 has a CVSS score of 7.5, High severity.
The remaining Medium vulnerabilities have CVSS scores from 4.3 to 6.5 and primarily expose secrets, Variables, configuration data, XCom content, audit logs, or team-scoped resources. The fixes span Airflow 3.2.2, 3.3.0, and 3.3.1, with 3.3.1 addressing multiple residual and follow-up weaknesses from earlier fixes.
CVE-2026-16860 – IBM i
“This update closes multiple paths to code execution, privilege escalation, unauthorized access, and service disruption across IBM i.”
IBM i 7.3 through 7.6 are affected by a broad set of security flaws spanning memory corruption, command execution, authentication and authorization weaknesses, path traversal, SQL injection, information disclosure, and denial of service. The most severe issues are CVE-2026-16860 with a CVSS score of 9.9, Critical severity; CVE-2026-17083 and CVE-2026-17218 at 9.8, Critical severity; and CVE-2026-17276 at 9.6, Critical severity. These vulnerabilities can enable arbitrary code execution or privilege escalation under their respective attack conditions.
The High-severity vulnerabilities range from CVSS 7.1 to 8.9 and include additional arbitrary code and command execution, privilege escalation, authentication bypass, memory corruption, unauthorized object access, SQL injection, and denial-of-service conditions. The remaining Medium and Low issues cover information disclosure, path traversal, authorization weaknesses, memory-safety defects, injection flaws, and service disruption. No exploitation claim is included because the supplied data identifies exploitation as none.
CVE List:
CVE-2026-16860, CVE-2026-17083, CVE-2026-17218, CVE-2026-17276, CVE-2026-16674, CVE-2026-16722, CVE-2026-16815, CVE-2026-16856, CVE-2026-16867, CVE-2026-16868, CVE-2026-16904, CVE-2026-16906, CVE-2026-16908, CVE-2026-16967, CVE-2026-16975, CVE-2026-16987, CVE-2026-17029, CVE-2026-17045, CVE-2026-17069, CVE-2026-17082, CVE-2026-17095, CVE-2026-17101, CVE-2026-17110, CVE-2026-17197, CVE-2026-17206, CVE-2026-17220, CVE-2026-17223, CVE-2026-17272, CVE-2026-17417, CVE-2026-17418, CVE-2026-17445, CVE-2026-17485, CVE-2026-17502, CVE-2026-17642, CVE-2026-18098, CVE-2026-18099, CVE-2026-18101, CVE-2026-18193, CVE-2026-18235, CVE-2026-18249, CVE-2026-18509, CVE-2026-18669, CVE-2026-18683, CVE-2026-18713, CVE-2026-18847, CVE-2026-16863, CVE-2026-16887, CVE-2026-16896, CVE-2026-16898, CVE-2026-16907, CVE-2026-16931, CVE-2026-16961, CVE-2026-16982, CVE-2026-17004, CVE-2026-17099, CVE-2026-17111, CVE-2026-17199, CVE-2026-17229, CVE-2026-17248, CVE-2026-17271, CVE-2026-18071, CVE-2026-18077, CVE-2026-18511, CVE-2026-18846, CVE-2026-16692, CVE-2026-16694, CVE-2026-16853, CVE-2026-17075, CVE-2026-17266, CVE-2026-17268, CVE-2026-17419, CVE-2026-17420, CVE-2026-18250, CVE-2026-18671, CVE-2026-18715, CVE-2026-16859, CVE-2026-16861, CVE-2026-16878, CVE-2026-16929, CVE-2026-17076, CVE-2026-17077, CVE-2026-17078, CVE-2026-17212, CVE-2026-17216, CVE-2026-17226, CVE-2026-17649, CVE-2026-18020, CVE-2026-16871, CVE-2026-17088, CVE-2026-17094, CVE-2026-17109, CVE-2026-17222, CVE-2026-17438, CVE-2026-17476, CVE-2026-18068, CVE-2026-18086, CVE-2026-18106, CVE-2026-18144, CVE-2026-18148, CVE-2026-18150, CVE-2026-17043, CVE-2026-17074, CVE-2026-18246, CVE-2026-17071
Four Critical vulnerabilities create the highest risk, including code execution and privilege escalation.
Multiple High-severity flaws provide additional paths to command execution, elevated privileges, unauthorized access, and service disruption.
The affected scope spans IBM i 7.3 through 7.6, with some vulnerabilities limited to specific releases.
The patch set addresses a broad mix of memory-safety, authentication, authorization, injection, and file-access weaknesses.
CVE-2026-73268 – Red Hat Multicluster Engine for Kubernetes
“Tenant-level access can cross critical cluster boundaries and escalate into code execution or cluster-wide control.”
Red Hat Multicluster Engine for Kubernetes is affected by four vulnerabilities involving privilege boundaries, tenant isolation, and credential protection. CVE-2026-73268 has a CVSS score of 9.9, Critical severity and can allow injected jobs to execute arbitrary code with elevated controller privileges. CVE-2026-73269 has a CVSS score of 9.9, Critical severity and can escalate namespace-level access to cluster-wide control.
CVE-2026-73266 has a CVSS score of 7.1, High severity and can allow a tenant to improperly associate clusters with another tenant’s ManagedClusterSet. CVE-2026-19130 has a CVSS score of 5.8, Medium severity and can expose newly rotated provider credentials through an authorization bypass.
CVE-2026-70398 – Red Hat Advanced Cluster Management for Kubernetes 2
“Broken trust boundaries can turn tenant access into cluster-wide control, code execution, and exposure of critical credentials.”
Red Hat Advanced Cluster Management for Kubernetes 2 is affected by 15 vulnerabilities spanning tenant isolation, privilege escalation, arbitrary code execution, authentication bypass, secret exposure, and denial of service. CVE-2026-70398 has a CVSS score of 9.6, Critical severity; CVE-2026-71471 has a CVSS score of 9.0, Critical severity; and CVE-2026-72508 and CVE-2026-72526 each have a CVSS score of 9.9, Critical severity. These flaws can expose spoke-cluster tokens, deploy arbitrary images or cluster-scoped resources, and compromise managed clusters.
CVE-2026-71473 has a CVSS score of 8.5, High severity; CVE-2026-66878 and CVE-2026-73122 are 7.7, High severity; and CVE-2026-71467 and CVE-2026-71469 are 7.5, High severity. The remaining six vulnerabilities are Medium severity, with CVSS scores from 5.0 to 6.5, and include credential leakage, excessive privileges, cross-namespace secret manipulation, and federated-search authorization weaknesses.
CVE-2026-10579 – Red Hat JBoss Enterprise Application Platform 7.4.25
“Authentication bypass and unsafe server processing can expose protected applications to impersonation, code execution, and service disruption.”
Red Hat JBoss Enterprise Application Platform 7.4.25 is affected by ten vulnerabilities spanning authentication bypass, unsafe deserialization, remote class loading, privilege escalation, and denial of service. CVE-2026-10579 has a CVSS score of 9.8, Critical severity and can allow an unauthenticated attacker to forge SAML assertions and authenticate as arbitrary users with arbitrary roles. CVE-2026-15555 has a CVSS score of 8.8, High severity and can enable remote code execution through unsafe session-data deserialization.
The remaining High-severity vulnerabilities have CVSS scores from 7.4 to 8.1 and include additional SAML authentication bypass, remote class loading, forged certificate authentication, unauthenticated JNDI manipulation, and multiple remotely triggered denial-of-service conditions.
CVE-2026-20030 – Cisco Crosswork Planning
“Critical weaknesses in authentication, data handling, and credential protection can expose core Crosswork Planning security boundaries.”
Cisco Crosswork Planning is affected by four Critical vulnerabilities addressed through a software hardening release. CVE-2026-20030 has a CVSS score of 10.0, Critical severity and involves SQL command injection. CVE-2026-20357 has a CVSS score of 10.0, Critical severity and involves missing authentication for critical functionality. CVE-2026-20358 also has a CVSS score of 10.0, Critical severity and involves external control of filesystem paths.
CVE-2026-20359 has a CVSS score of 9.9, Critical severity and involves insufficient protection of credentials. Cisco identified these vulnerabilities through an internal security review and addressed them as part of its Crosswork Planning software hardening effort.
CVE-2026-20315 – Cisco Secure Workload
“Critical access and authentication weaknesses can break core security boundaries within Cisco Secure Workload.”
Cisco Secure Workload is affected by five vulnerabilities addressed through a software hardening release. CVE-2026-20315 and CVE-2026-20317 each have a CVSS score of 10.0, Critical severity and involve improper access control and authentication. CVE-2026-20231 has a CVSS score of 9.9, Critical severity and involves improper neutralization of special elements. CVE-2026-20318 has a CVSS score of 9.6, Critical severity and involves improper input validation.
CVE-2026-20319 has a CVSS score of 7.5, High severity and involves unsafe buffer management with code execution and privilege escalation risk. Cisco identified these vulnerabilities through an internal security review and addressed them as part of the Secure Workload software hardening effort.
CVE-2026-64849 – MLflow
“These flaws can expose internal services and cross user access boundaries in MLflow deployments.”
MLflow 3.15.0 fixes two serious vulnerabilities. CVE-2026-64849 is an unauthenticated server-side request forgery issue that can follow redirects to internal systems or cloud metadata services and return response content to an attacker. CVE-2026-64849 has a CVSS score of 9.3, Critical severity, and active exploitation is confirmed.
CVE-2026-69148 allows an authenticated user to reference another user’s artifact directory and retrieve files without the required read permission. CVE-2026-69148 has a CVSS score of 7.1, High severity. Public proof-of-concept material is confirmed.
CVE-2026-41907 – Bamboo Data Center and Server
“Dependency flaws can weaken request integrity, exhaust services, bypass path controls, and corrupt application memory.”
Bamboo Data Center and Server is affected by five dependency vulnerabilities. CVE-2026-41907 has a CVSS score of 8.1, High severity and involves unsafe buffer handling. CVE-2026-12143, CVE-2026-46625, and CVE-2026-56819 each have a CVSS score of 7.5, High severity and can enable multipart request manipulation, cookie attribute manipulation, or HTTP/2 memory exhaustion. Public proof-of-concept information is available for these four vulnerabilities.
CVE-2026-6321 has a CVSS score of 7.5, High severity and can allow path-based security controls to be bypassed through improper URI normalization.
CVE-2026-41907 – Bitbucket
“Dependency weaknesses can turn routine data processing into security bypasses, memory exhaustion, and application compromise.”
Bitbucket is affected by nine dependency vulnerabilities covering request manipulation, prototype hijacking, resource exhaustion, unsafe buffer handling, and path-control bypass. CVE-2026-41907 has a CVSS score of 8.1, High severity. CVE-2026-12143, CVE-2026-46625, CVE-2026-69152, CVE-2026-55831, CVE-2026-56819, CVE-2026-59869, CVE-2026-48779, and CVE-2026-6321 each have a CVSS score of 7.5, High severity.
Public proof-of-concept information is available for eight of the vulnerabilities. Impact includes manipulated multipart requests and cookies, CPU and memory exhaustion, HTTP/2 and WebSocket denial of service, unsafe buffer writes, and URI normalization weaknesses that can bypass path-based controls.
CVE-2026-59873 – Confluence
“Critical dependency flaws can turn crafted content into service disruption, unauthorized file access, and weakened security controls.”
Confluence is affected by nine dependency vulnerabilities spanning resource exhaustion, path traversal, file disclosure, cryptographic weaknesses, and improper error handling. CVE-2026-59873, CVE-2026-53434, and CVE-2025-14813 have CVSS scores of 9.2, 9.1, and 9.3 respectively, all Critical severity. CVE-2026-59874 and CVE-2026-48801 are 8.7, High severity; CVE-2026-29786 is 8.2, High severity; and CVE-2026-59887 and CVE-2026-45623 are 7.5, High severity. CVE-2026-59871 has a CVSS score of 5.3, Medium severity.
Public proof-of-concept information is available for seven vulnerabilities. Impact includes CPU and disk exhaustion, application denial of service, writes outside intended extraction directories, local file disclosure, and path-based security weaknesses.
CVE-2026-72529 – TrueConf Server
“Actively exploited flaws can give remote attackers a direct path from exposed services to arbitrary code execution.”
TrueConf Server is affected by two actively exploited Critical vulnerabilities accessible through port 4307/TCP. CVE-2026-72529 has a CVSS score of 9.8, Critical severity and allows an unauthorized remote attacker to execute arbitrary scripts through an undocumented function. CVE-2026-72530 has a CVSS score of 9.0, Critical severity and allows an unauthorized remote attacker to escape the isolated environment and execute arbitrary code on the host.
The issues affect the specified TrueConf Server 5.3.x, 5.4.x, and 5.5.x releases and earlier versions.
CVE-2026-73570 – Zimbra Collaboration
“Active exploitation turns this mail-server flaw into an immediate compromise risk.”
Zimbra Collaboration before 10.1.20 is affected by a remote code execution vulnerability when the optional zimbra-snmp package is installed and SNMP notifications are enabled. An unauthenticated attacker can send crafted SMTP requests that execute operating system commands as the Zimbra user. The CVSS score is 8.9, which is High severity.
CVE-2026-73570 is confirmed as actively exploited. Zimbra Collaboration 10.1.20 patches the command injection vulnerability in the SNMP monitoring component.
CVE-2026-63409 – Deskflow
“Malicious Deskflow servers can turn trusted connections into crashes and memory exposure.”
Deskflow fixes two remotely triggerable out-of-bounds read vulnerabilities affecting connected clients. CVE-2026-63409 allows a malicious server to crash a client using a malformed options message and is fixed in continuous build 1.26.0.296. CVE-2026-65832 can crash a client or disclose four bytes of process memory at an attacker-selected relative offset and is fixed in continuous build 1.26.0.299. CVE-2026-63409 has a CVSS score of 8.2, High severity. CVE-2026-65832 has a CVSS score of 8.2, High severity.
Public proof-of-concept material is available for both vulnerabilities. The fixes add protections around Deskflow option handling and array indexing to prevent malicious server-controlled values from causing out-of-bounds reads.
CVE-2026-55085 – Etherpad
“These flaws put pad data, administrative control, and trusted user sessions at risk.”
Etherpad fixes two Critical vulnerabilities. CVE-2026-55085 allows a user with pad write access to store malicious content that executes as cross-site scripting when another user, including an administrator, opens the pad or timeslider. It is fixed in version 3.3.1. CVE-2026-55085 has a CVSS score of 9.6, Critical severity.
CVE-2026-55089 allows a non-admin OAuth user with a valid signed token to invoke administrative API functions, enabling disclosure, modification, or deletion of pads across the instance. It is fixed in version 3.1.0. CVE-2026-55089 has a CVSS score of 9.9, Critical severity. Public proof-of-concept material is available for both vulnerabilities.
CVE-2026-76850 – LMDeploy
“A malicious peer connection can turn unsafe deserialization into full remote code execution.”
LMDeploy fixes a Critical remote code execution vulnerability affecting disaggregated serving. CVE-2026-76850 allows an unauthenticated remote attacker to direct the engine to an attacker-controlled ZMQ endpoint, where malicious serialized data can execute arbitrary code during deserialization. Deployments without disaggregated serving enabled are not affected. The CVSS score is 9.8, which is Critical severity.
The issue affects LMDeploy versions from 0.9.2 before 0.16.0 and is addressed in version 0.16.0. Public proof-of-concept exploitation is confirmed.
CVE-2026-48749 – Incus
“Multiple paths around Incus security boundaries can expose host files, elevate privileges, and reach root-level execution.”
Incus fixes a broad set of security flaws involving unsafe file handling, symlink attacks, argument injection, missing authorization checks, and project-restriction bypasses. The issues can expose sensitive instance or volume data, allow arbitrary host file access or writes, bypass container restrictions, and in several cases lead to arbitrary command execution or host compromise. Fixes are included across Incus 7.1.0, 7.2.0, and 7.3.0.
CVE-2026-48749 has a CVSS score of 9.9, Critical severity. CVE-2026-48750 has a CVSS score of 9.9, Critical severity. CVE-2026-48751 has a CVSS score of 9.9, Critical severity. CVE-2026-48752 has a CVSS score of 9.9, Critical severity. CVE-2026-48753 has a CVSS score of 9.9, Critical severity. CVE-2026-48755 has a CVSS score of 9.9, Critical severity. CVE-2026-48769 has a CVSS score of 9.9, Critical severity. CVE-2026-62867 has a CVSS score of 9.9, Critical severity. CVE-2026-62940 has a CVSS score of 9.9, Critical severity. CVE-2026-62941 has a CVSS score of 9.9, Critical severity. CVE-2026-63125 has a CVSS score of 9.9, Critical severity. CVE-2026-63343 has a CVSS score of 9.9, Critical severity. CVE-2026-55621 has a CVSS score of 7.7, High severity. CVE-2026-55622 has a CVSS score of 7.7, High severity.
Public proof-of-concept exploitation is confirmed for CVE-2026-48749, CVE-2026-48751, CVE-2026-48753, CVE-2026-48769, CVE-2026-62941, CVE-2026-63125, and CVE-2026-55622.
CVE-2026-57233 – Notepad++
“Malicious input can cross trusted boundaries and turn routine Notepad++ activity into code execution.”
Notepad++ 8.9.7 fixes two High-severity vulnerabilities. CVE-2026-57233 allows a malicious ZIP entry processed by WinGup to escape its intended plugin directory, overwrite another plugin DLL, and execute attacker-controlled code when that plugin loads. CVE-2026-57233 has a CVSS score of 8.1, High severity.
CVE-2026-54758 is a stack buffer overflow in environment-variable expansion that can corrupt memory, crash Notepad++, and potentially execute code. CVE-2026-54758 has a CVSS score of 7.8, High severity. Public proof-of-concept material is available for both vulnerabilities.
CVE-2026-77767 – Reconmap
“An anonymous attacker can enumerate sensitive penetration-testing projects and client details without logging in.”
Reconmap contains a High-severity authorization flaw in the report preview function. CVE-2026-77767 allows unauthenticated remote users to query sequential project IDs and retrieve project names, descriptions, and linked client organisation details without membership or role checks. The CVSS score is 7.5, which is High severity.
The issue exposes sensitive engagement and customer information and also reveals valid project identifiers through response behavior. Public proof-of-concept material is available.
CVE-2026-75481 – SkyPilot
“A standard authenticated user can turn a service account into full administrative control.”
SkyPilot contains a High-severity privilege escalation flaw in service account permission handling. CVE-2026-75481 allows an authenticated attacker to create a service account, assign it the administrator role without proper authorization, and use its bearer token to gain administrative access across users and workspaces. The CVSS score is 8.8, which is High severity.
Public proof-of-concept material is available for the vulnerability.
CVE-2026-75626 – SpiderFoot
“Malicious scan data can turn a routine analyst view into browser-side code execution.”
SpiderFoot contains a Critical stored cross-site scripting vulnerability in correlation results. CVE-2026-75626 allows attacker-controlled external scan data, including banners and metadata, to inject malicious HTML that executes when an operator opens the correlations view. Successful exploitation can expose sensitive browser-accessible data, including API keys. The CVSS score is 9.3, which is Critical severity.
Public proof-of-concept material is available for the vulnerability.
CVE-2026-57485 – Stirling-PDF
“A standard user can expose an internal service credential and gain access beyond normal application controls.”
Stirling-PDF before 2.9.0 contains a High-severity credential exposure and privilege escalation flaw in its pipeline endpoint. CVE-2026-57485 allows an authenticated user to retrieve the internal backend API key, impersonate the service account, bypass normal rate limits, and access internal administrative information endpoints. The CVSS score is 8.5, which is High severity.
The issue is fixed in Stirling-PDF 2.9.0. Public proof-of-concept material is available.
CVE-2026-76886 – Wireshark
“Malformed network traffic can crash Wireshark and disrupt packet analysis workflows.”
Wireshark fixes four High-severity protocol dissector vulnerabilities affecting versions 4.6.0 through 4.6.7 and 4.4.0 through 4.4.18. The flaws affect C12.22, RRC, and X.509IF packet processing and can cause Wireshark to crash when maliciously crafted traffic is parsed.
CVE-2026-76886 has a CVSS score of 8.1, High severity. CVE-2026-76879 has a CVSS score of 7.5, High severity. CVE-2026-76880 has a CVSS score of 7.5, High severity. CVE-2026-76928 has a CVSS score of 7.5, High severity. Public proof-of-concept material is available for CVE-2026-76886.
CVE-2026-15068 – IBM AIX
“This patch set closes a wide range of paths to root access, arbitrary code execution, data exposure, and service disruption.”
IBM AIX 7.2 and 7.3 and IBM PowerVM VIOS 4.1 are affected by a large set of Critical and High-severity vulnerabilities spanning remote code execution, command injection, authentication bypass, privilege escalation, arbitrary file writes, certificate-validation failures, memory corruption, information disclosure, and denial of service. Several Critical issues carry CVSS scores from 9.1 through 9.9, including remote paths to arbitrary code execution and root privileges. The High-severity issues range from CVSS 7.0 through 8.8 and include additional code execution, privilege escalation, authorization bypass, NFS access, network manipulation, file overwrite, and denial-of-service conditions.
The highest-scoring Critical issues are CVE-2026-15068, CVE-2026-16816, and CVE-2026-18835 at 9.9. CVE-2026-16656, CVE-2026-16834, CVE-2026-16840, CVE-2026-16845, CVE-2026-16862, CVE-2026-16864, CVE-2026-16872, CVE-2026-16882, CVE-2026-16885, CVE-2026-16894, CVE-2026-16913, CVE-2026-16917, CVE-2026-16919, CVE-2026-17040, CVE-2026-17118, CVE-2026-17122, CVE-2026-17136, CVE-2026-17141, CVE-2026-17142, CVE-2026-17145, CVE-2026-17152, CVE-2026-17157, and CVE-2026-17160 each have a CVSS score of 9.8, Critical severity. CVE-2026-16903 is 9.6, CVE-2026-16839 is 9.4, CVE-2026-16822 and CVE-2026-17422 are 9.3, and CVE-2026-15065 and CVE-2026-16926 are 9.1, all Critical severity.
The remaining listed vulnerabilities are High severity, with individual CVSS scores between 7.0 and 8.8. They cover remote and local memory corruption, command execution, privilege escalation, authentication and authorization failures, arbitrary file access, certificate validation weaknesses, and denial-of-service conditions across AIX and PowerVM VIOS components.
CVE-2026-75045 – JetBrains YouTrack
“Weak authorization controls can expose backups, delete data, and move projects across organizational boundaries.”
JetBrains fixes three serious YouTrack vulnerabilities. CVE-2026-75045 allows an unauthenticated attacker to download database backups through a shared draft signature. The CVSS score is 9.1, which is Critical severity. CVE-2026-75044 allows an authenticated user to delete arbitrary entities through the mailbox endpoint. CVE-2026-75044 has a CVSS score of 8.1, High severity.
CVE-2026-75051 allows an authenticated user to transfer projects between organizations without proper authorization. CVE-2026-75051 has a CVSS score of 8.1, High severity. Fixed builds vary by supported YouTrack release branch.
CVE-2026-47627 – NVIDIA Triton Inference Server
“A path traversal flaw can disrupt inference services and threaten availability.”
NVIDIA Triton Inference Server for Linux contains a Critical path traversal vulnerability. CVE-2026-47627 allows an attacker to manipulate file paths in a way that can lead to denial of service. The CVSS score is 9.8, which is Critical severity.
CVE-2026-61272 – Oracle JD Edwards EnterpriseOne Tools
“An unauthenticated network attacker can fully compromise affected EnterpriseOne Tools environments.”
Oracle addresses a Critical vulnerability in the Web Runtime SEC component of JD Edwards EnterpriseOne Tools. CVE-2026-61272 is remotely exploitable over HTTP without authentication and can result in high confidentiality, integrity, and availability impact. Affected versions include 9.2.0.0 through 9.2.26.4. The CVSS score is 9.8, which is Critical severity.
The issue is addressed in Oracle’s August 2026 Critical Security Patch Update.
CVE-2026-70905 – Oracle Access Manager
“An unauthenticated SAML attack can fully compromise confidentiality, integrity, and availability.”
Oracle addresses a Critical vulnerability in the Agent Infrastructure component of Oracle Access Manager. CVE-2026-70905 is remotely exploitable over SAML without authentication and can result in high impact to confidentiality, integrity, and availability. The CVSS score is 9.8, which is Critical severity.
Affected versions include Oracle Access Manager 12.2.1.4.0 and 14.1.2.1.0. The issue is addressed in Oracle’s August 2026 Critical Security Patch Update.
CVE-2026-71040 – Oracle Agile PLM
“An unauthenticated network attacker can fully compromise confidentiality, integrity, and availability.”
Oracle addresses a Critical vulnerability in the Security component of Oracle Agile PLM. CVE-2026-71040 is remotely exploitable over HTTP without authentication and can result in high impact to confidentiality, integrity, and availability. The CVSS score is 9.8, which is Critical severity.
Oracle Agile PLM version 9.3.6 is affected. The issue is addressed in Oracle’s August 2026 Critical Security Patch Update.
CVE-2026-71059 – Oracle BI Publisher
“A low-privileged authenticated attacker can reach a Critical compromise path through the BI Publisher web service API.”
Oracle addresses a Critical vulnerability in the Web Service API component of Oracle BI Publisher. CVE-2026-71059 is remotely exploitable over SOAP by a low-privileged authenticated attacker and can result in high impact to confidentiality, integrity, and availability. The CVSS score is 9.9, which is Critical severity.
Affected versions include Oracle BI Publisher 8.2.0.0.0 and 26.1.0.0.0. The issue is addressed in Oracle’s August 2026 Critical Security Patch Update.
CVE-2026-70953 – Oracle Commerce Platform
“Unauthenticated network attacks can lead to complete takeover of affected Oracle Commerce environments.”
Oracle addresses two Critical vulnerabilities in the Dynamo Application Framework component of Oracle Commerce Platform 11.4.0. CVE-2026-70953 is remotely exploitable without authentication over TCP, while CVE-2026-70954 is remotely exploitable without authentication over HTTP. Successful exploitation can result in takeover of Oracle Commerce Platform.
CVE-2026-70953 has a CVSS score of 9.8, Critical severity. CVE-2026-70954 has a CVSS score of 9.8, Critical severity. Both issues are addressed in Oracle’s August 2026 Critical Security Patch Update.
CVE-2026-71063 – Oracle Database Server
“Critical Portable Clusterware flaws can enable takeover, destructive data changes, and complete service disruption.”
Oracle addresses three Critical vulnerabilities in the Portable Clusterware component of Oracle Database Server. CVE-2026-71063 and CVE-2026-71064 allow unauthenticated attackers on the adjacent physical network segment to compromise and take over Portable Clusterware. Each has a CVSS score of 9.6, Critical severity.
CVE-2026-71102 is remotely exploitable without authentication over HTTP and can allow unauthorized modification or deletion of critical data and cause complete denial of service. Its CVSS score is 9.1, Critical severity. Affected releases include Oracle Database Server 19.3–19.32, 21.3–21.23, and 23.4.0–23.26.3.
CVE-2026-70689 – Oracle Essbase
“An unauthenticated HTTP request can lead to full takeover of the affected Essbase environment.”
Oracle addresses a Critical vulnerability in the Infrastructure component of Oracle Essbase. CVE-2026-70689 allows an unauthenticated attacker with network access over HTTP to compromise Oracle Essbase, with successful exploitation resulting in takeover of the application. The CVSS score is 9.8, which is Critical severity.
Oracle Essbase 21.8.1.0.0 is affected. The issue is addressed in Oracle’s August 2026 Critical Security Patch Update.
CVE-2026-70921 – Oracle Hyperion Financial Management
“Multiple Critical flaws create paths to severe compromise across affected Hyperion Financial Management environments.”
Oracle addresses four Critical vulnerabilities in Oracle Hyperion Financial Management. CVE-2026-70921 has a CVSS score of 10.0, Critical severity. CVE-2026-70920 has a CVSS score of 9.9, Critical severity. CVE-2026-70817 has a CVSS score of 9.8, Critical severity. CVE-2026-70854 has a CVSS score of 9.1, Critical severity.
The issues are addressed through Oracle’s August 2026 Critical Security Patch Update.
CVE-2026-60720 – Oracle Identity Manager
“Four Critical flaws create multiple paths to severe compromise in affected identity-management environments.”
Oracle addresses four Critical vulnerabilities in Oracle Identity Manager. CVE-2026-60720 has a CVSS score of 9.9, Critical severity. CVE-2026-60721 has a CVSS score of 9.8, Critical severity. CVE-2026-60727 has a CVSS score of 9.8, Critical severity. CVE-2026-61066 has a CVSS score of 9.9, Critical severity.
The issues are addressed through Oracle’s August 2026 Critical Security Patch Update.
CVE-2026-60782 – Oracle Payments
“An unauthenticated HTTP request can result in complete takeover of Oracle Payments.”
Oracle addresses a Critical vulnerability in the File Transmission component of Oracle Payments within Oracle E-Business Suite. CVE-2026-60782 allows an unauthenticated attacker with network access over HTTP to compromise Oracle Payments, with successful exploitation resulting in takeover of the application. The CVSS score is 9.8, which is Critical severity.
Affected releases are Oracle E-Business Suite 12.2.3 through 12.2.15. The issue is addressed in Oracle’s August 2026 Critical Security Patch Update.
CVE-2026-61317 – Siebel CRM Cloud Applications
“Four Critical flaws create severe compromise risk across affected Siebel CRM environments.”
Oracle addresses four Critical vulnerabilities in Siebel CRM Cloud Applications. CVE-2026-61317 has a CVSS score of 9.9, Critical severity. CVE-2026-61318 has a CVSS score of 9.8, Critical severity. CVE-2026-62452 has a CVSS score of 9.9, Critical severity. CVE-2026-62512 has a CVSS score of 9.9, Critical severity.
The issues are addressed through Oracle’s August 2026 Critical Security Patch Update.
CVE-2026-12564 – Red Hat Ansible Automation Platform 2
“A crafted Vault credential can expose the controller’s Kubernetes identity and open access to sensitive control-plane resources.”
Red Hat addresses a Critical server-side request forgery vulnerability in the Ansible Automation Platform Controller HashiCorp Vault credential plugin. CVE-2026-12564 allows an authenticated attacker with credential-creation privileges to send the controller pod’s Kubernetes service account token to an attacker-controlled endpoint. The stolen token can provide Kubernetes API access to control-plane namespaces, including pod management and access to sensitive secrets such as database credentials and the Django SECRET_KEY. The CVSS score is 9.6, which is Critical severity.
Red Hat has released security updates for affected Ansible Automation Platform branches, including versions 2.6 and 2.7.
CVE-2026-11861 – Red Hat Enterprise Linux 10
“This update closes paths to domain privilege escalation, arbitrary code execution, credential theft, and root-level file overwrite.”
Red Hat Enterprise Linux 10 is affected by one Critical and seven High-severity vulnerabilities across FreeIPA, NetworkManager, RPM, sos, Emacs TRAMP, BlueZ, and libvirt. CVE-2026-11861 can let an authenticated Active Directory user bypass FreeIPA trust protections and escalate privileges inside the FreeIPA domain. The CVSS score is 9.6, which is Critical severity. CVE-2026-13097 can enable Kerberos service impersonation and potentially full domain compromise; its CVSS score is 8.7, High severity.
The remaining High-severity issues include WPA-Enterprise credential theft, arbitrary code execution during RPM build processing, root-context file creation or overwrite through sos clean, local shell command execution in Emacs TRAMP, Bluetooth-triggered memory corruption, and libvirt heap corruption. CVE-2026-19685 scores 7.1; CVE-2026-78367 scores 7.0; CVE-2026-79655, CVE-2026-79992, and CVE-2026-18917 each score 7.8; and CVE-2026-80186 scores 7.6. Public proof-of-concept material is available for CVE-2026-78367 and CVE-2026-79655.
CVE-2026-76310 – Splunk Enterprise
“Weak authorization boundaries can expose session material, elevate low-privileged users, and open multiple paths to code execution.”
Splunk Enterprise fixes three Critical and fourteen High-severity vulnerabilities affecting embedded reports, scheduled searches, distributed and federated search, Splunk Web Manager configuration, scripted lookups, authentication tokens, SPL2 modules, Edge Processor, and related REST APIs. The most severe issues allow unauthenticated users with embedded report access to recover session material and access data or administrative capabilities belonging to the report owner. CVE-2026-76310, CVE-2026-76311, and CVE-2026-76312 each have a CVSS score of 9.4, Critical severity.
Multiple High-severity issues can enable privilege escalation or remote code execution by lower-privileged users. CVE-2026-76314, CVE-2026-76315, and CVE-2026-76335 allow arbitrary code or operating-system command execution through Splunk Web Manager configuration, while CVE-2026-76313 and CVE-2026-76319 provide additional RCE paths through distributed or federated search workflows. CVE-2026-76253, CVE-2026-76259, CVE-2026-76350, and CVE-2026-76352 can expose credentials or run actions with elevated privileges. Most fixes are included in Splunk Enterprise 10.4.2, 10.2.6, 10.0.9, and 9.4.14, with some version-specific exceptions.
CVE-2026-79090 – Chrome
“Crafted web content or network traffic can break out of the browser sandbox and execute attacker-controlled code.”
Google Chrome 152 fixes 327 Critical and High-severity vulnerabilities across V8, ANGLE, Media, Views, Aura, ServiceWorker, WebGL, Safe Browsing, Extensions, Network, Bluetooth, FileSystem, Passwords, DevTools, and other components. CVE-2026-79090 has a CVSS score of 9.8, Critical severity. Most of the remaining critical issues have CVSS scores of 9.6, while CVE-2026-79058 and CVE-2026-79148 are 9.1, Critical severity. CVE-2026-85046 has a CVSS score of 8.8, High severity. CVE-2026-85046 with a score of 8.8 is actively exploited.
Many of these vulnerabilities can lead to arbitrary code execution outside the browser sandbox, privilege escalation, memory corruption, or security-control bypass through crafted HTML content or malicious extensions. CVE-2026-85046 is listed as actively exploited and affects Chrome prior to 152.0.7977.82. The remaining listed issues affect earlier Chrome releases, primarily versions prior to 152.0.7977.65, with CVE-2026-76035 affecting versions prior to 151.0.7922.169.
CVE-2026-85046, CVE-2026-79090, CVE-2026-76035, CVE-2026-78900, CVE-2026-78904, CVE-2026-78909, CVE-2026-78939, CVE-2026-78945, CVE-2026-78948, CVE-2026-78951, CVE-2026-78964, CVE-2026-78985, CVE-2026-78989, CVE-2026-79012, CVE-2026-79019, CVE-2026-79026, CVE-2026-79043, CVE-2026-79047, CVE-2026-79052, CVE-2026-79056, CVE-2026-79064, CVE-2026-79078, CVE-2026-79091, CVE-2026-79111, CVE-2026-79128, CVE-2026-79130, CVE-2026-79131, CVE-2026-79138, CVE-2026-79140, CVE-2026-79149, CVE-2026-79150, CVE-2026-79188, CVE-2026-79189, CVE-2026-79200, CVE-2026-79232, CVE-2026-79235, CVE-2026-79257, CVE-2026-79275, CVE-2026-79290, CVE-2026-79058, CVE-2026-79148) 8.8, 9.8, 9.6, 9.6, 9.6, 9.6, 9.6, 9.6, 9.6, 9.6, 9.6, 9.6, 9.6, 9.6, 9.6, 9.6, 9.6, 9.6, 9.6, 9.6, 9.6, 9.6, 9.6, 9.6, 9.6, 9.6, 9.6, 9.6, 9.6, 9.6, 9.6, 9.6, 9.6, 9.6, 9.6, 9.6, 9.6, 9.6, 9.6, 9.1, 9.1
CVE-2026-75874 – Mozilla Firefox
“A sandbox escape and a critical WebAssembly memory flaw create severe browser compromise risk.”
Mozilla fixes two Critical Firefox vulnerabilities. CVE-2026-75874 is a sandbox escape in the Remote Settings Client component and is fixed in Firefox 154. The CVSS score is 10.0, which is Critical severity. Firefox 155 fixes 29 other issues.
CVE-2026-74936 is a use-after-free vulnerability in the JavaScript WebAssembly component. It is fixed in Firefox 154, Firefox ESR 140.14, and Firefox ESR 153.1. The CVSS score is 9.8, which is Critical severity. Thunderbird 154, 140.14, and 153.1 also contain the corresponding fix.
CVE-2026-40144 – BeyondTrust Endpoint Privilege Management (Windows deployments)
“A kernel-level memory flaw creates a path to serious endpoint compromise.”
BeyondTrust fixed a memory-corruption vulnerability in the Windows kernel-mode component of Endpoint Privilege Management. CVE-2026-40144 affects versions prior to 26.1.2 and stems from insufficient validation that can cause memory access outside intended bounds. The CVSS score is 7.3, which is High severity.
The vulnerability is associated with remote code execution impact and is addressed by upgrading to version 26.1.2.
CVE-2026-60004 – Gitea
“A vulnerable diffpatch workflow can turn repository operations into remote code execution.”
Gitea before 1.27.1 contains a Critical remote code execution vulnerability in the diffpatch API. CVE-2026-60004 allows an attacker to achieve code execution through Git hook installation. The CVSS score is 9.8, which is Critical severity.
The issue is fixed in Gitea 1.27.1.
CVE-2026-77537 – Ubiquiti UniFi
“Three maximum-severity flaws expose UniFi environments to command execution and authentication bypass from the network.”
Ubiquiti fixes three Critical vulnerabilities across UniFi Protect, UniFi OS, and UniFi Talk. CVE-2026-77537 allows a network-accessible attacker to inject commands on devices running vulnerable UniFi Protect versions. CVE-2026-77550 allows authentication bypass on affected UniFi OS devices or instances through improper CRLF handling. CVE-2026-77554 allows command injection on devices running vulnerable UniFi Talk versions.
CVE-2026-77537 has a CVSS score of 10.0, Critical severity. CVE-2026-77550 has a CVSS score of 10.0, Critical severity. CVE-2026-77554 has a CVSS score of 10.0, Critical severity. UniFi Protect 7.2.105 and UniFi Talk 5.3.2 contain the respective application fixes, with Ubiquiti security updates addressing the affected UniFi OS platforms.
CVE-2026-81578 – PaperCut MF/NG
“Active exploitation can turn exposed PaperCut administration paths into configuration compromise and server-side code execution.”
PaperCut MF and PaperCut NG are affected by two actively exploited vulnerabilities. CVE-2026-81578 allows unauthenticated remote requests to reach administrative backend actions before access checks complete, enabling unauthorized modification of system configuration. The CVSS score is 8.8, which is High severity.
CVE-2026-82078 is a Critical unsafe dynamic class loading flaw. An attacker able to manipulate configuration parameters can cause PaperCut to load attacker-selected Java classes from the application classpath and execute bytecode under the PaperCut server process. The CVSS score is 9.4, which is Critical severity. Active exploitation is confirmed for both vulnerabilities.
CVE-2026-18885 – ServiceNow AI Platform and Now Platform
“Three maximum-severity flaws can expose ServiceNow instances to unauthenticated code execution, privilege escalation, and database compromise.”
ServiceNow fixes three Critical vulnerabilities in the ServiceNow AI Platform. CVE-2026-18885 can allow an unauthenticated attacker to execute arbitrary code and access or modify instance data. CVE-2026-18886 can allow unauthenticated creation or modification of instance data resulting in privilege escalation. CVE-2026-74820 can allow an unauthenticated attacker to execute arbitrary SQL statements against the underlying database. Each has a CVSS score of 10.0, Critical severity.
CVE-2026-6876 affects the Now Platform and can allow an unauthenticated attacker to escape a sandbox and execute arbitrary code within the platform. The CVSS score is 8.7, which is High severity. ServiceNow deployed security updates to hosted instances and provided updates for partners and self-hosted customers.
CVE-2026-66066 – Rails
“A crafted image upload can expose application secrets and open the door to deeper compromise.”
Rails fixed a critical Active Storage vulnerability affecting applications that use libvips and accept untrusted image uploads. CVE-2026-66066 allows an unauthenticated attacker to trigger unsafe libvips processing and read arbitrary files accessible to the Rails process, including environment variables and application secrets. The CVSS score is 9.5, which is Critical severity.
Public proof-of-concept material is available. The issue is fixed in Rails versions 7.2.3.2, 8.0.5.1, and 8.1.3.1.
CVE-2026-77776 – Headroom
“A trusted identity header can expose one user’s AI memory to another.”
Headroom fixed a critical authorization flaw in its LLM proxy that allowed clients to supply another user’s identifier and read or modify that user’s stored LLM memory. CVE-2026-77776 affects versions before 0.36.1. The CVSS score is 9.1, which is Critical severity.
The fix strengthens memory identity handling by restricting when the user-supplied header is trusted and otherwise binding identity to the authenticated caller or local operating system user.
CVE-2026-59568 – Client Connector
“These flaws can turn an exposed endpoint into a path for code execution or elevated control.”
Zscaler Client Connector contains two serious vulnerabilities. CVE-2026-59568 allows an unauthenticated, unprivileged user to execute arbitrary code in the Client Connector context. CVE-2026-59568 has a CVSS score of 9.1, Critical severity. CVE-2026-59567 allows a local unprivileged user to execute arbitrary code in a privileged context. CVE-2026-59567 has a CVSS score of 8.8, High severity.
The update addresses both remote code execution and local privilege-escalation risk across affected Client Connector versions.
CVE-2026-19313 – Watchguard Fireware OS
“Three pre-authentication flaws put exposed Fireboxes at risk of full remote compromise.”
WatchGuard fixed three critical vulnerabilities in the Fireware OS iked process. CVE-2026-19313 is a heap overflow, CVE-2026-19318 is a stack-based buffer overflow, and CVE-2026-19315 is a type confusion flaw. Each can allow a remote, unauthenticated attacker to execute arbitrary code using specially crafted network traffic. Each CVE has a CVSS score of 9.3, Critical severity.
The fixes are included in Fireware OS 2026.2.2, 12.12.2, and 12.5.20 for applicable systems.
CVE-2026-78174 – Watchguard Dimension
“A leaked administrator session token can turn limited access into full control.”
WatchGuard fixed a critical privilege-escalation flaw in Dimension that exposed unredacted session identifiers in diagnostic logs. CVE-2026-78174 allows a low-privileged Dimension Administrator to retrieve a logged-in Super Administrator’s session token and take over that account. The CVSS score is 9.3, which is Critical severity.
The issue affects Dimension versions 2.0 through versions before 2.3.1. Dimension 2.3.1 contains the fix.
CVE-2026-82329 – Artifactory
“An authentication weakness can turn network access into full administrative control.”
JFrog Artifactory contains a critical authentication weakness that, under default configuration, may allow an unauthenticated attacker with network access to obtain administrative privileges. CVE-2026-82329 has a CVSS score of 9.8, Critical severity.
Active exploitation is confirmed, making this vulnerability a high-priority security risk for exposed Artifactory deployments.
CVE-2026-79787 – Alluxio
“A forged S3 identity can turn unauthenticated access into full control over stored data.”
Alluxio contains a Critical authentication bypass in its S3 REST proxy. CVE-2026-79787 allows an unauthenticated attacker to spoof AWS Signature Version 4 identity information, impersonate arbitrary users or service accounts, and read, modify, or delete data. The CVSS score is 9.8, which is Critical severity.
Public proof-of-concept material is available for the vulnerability.
CVE-2026-45018 – Chainlit
“An exposed MCP endpoint can turn a crafted command into unauthenticated server takeover.”
Chainlit versions from 2.4.0rc0 before 2.12.0 contain a Critical command injection vulnerability when MCP is enabled. CVE-2026-45018 allows an unauthenticated attacker to abuse the /mcp endpoint and pass malicious arguments to an allowed executable, resulting in arbitrary shell command execution with the privileges of the Chainlit process. The CVSS score is 9.8, which is Critical severity.
The issue is fixed in Chainlit 2.12.0. Public proof-of-concept material is available.
CVE-2026-82639 – NextChat
“A weak proxy validation check can expose the server’s OpenAI API key to an unauthenticated attacker.”
NextChat versions 2.15.8 through 2.16.1 contain a High-severity URL validation flaw in the proxy endpoint. CVE-2026-82639 allows an unauthenticated attacker to supply a malicious x-base-url value that passes substring validation and causes the server’s OpenAI API key to be forwarded to an attacker-controlled endpoint. The CVSS score is 7.5, which is High severity.
Public proof-of-concept material is available for the vulnerability. No confirmed patched release is listed in the supplied vulnerability record.
CVE-2026-82281 – Kotaemon
“Weak conversation ownership checks can expose private chats and let attackers alter or delete other users’ conversations.”
Kotaemon through version 0.12.0 contains a High-severity authorization vulnerability in conversation management functions. CVE-2026-82281 allows an attacker to supply arbitrary conversation identifiers and access another user’s chat history, rename conversations, or delete them without proper ownership validation. The CVSS score is 7.4, which is High severity.
Public proof-of-concept material is available for the vulnerability.
CVE-2026-82278 – BISHENG
“Workflow features can become a direct path to code execution and internal network exposure.”
BISHENG is affected by two High-severity vulnerabilities. CVE-2026-82278 allows an authenticated user to submit crafted Code nodes to the workflow run_once endpoint and execute arbitrary Python code without sandboxing, exposing the host filesystem, credentials, and internal network resources. The CVSS score is 8.8, which is High severity.
CVE-2026-82285 is an unauthenticated server-side request forgery flaw in the workflow callback endpoint. Attackers can target internal services or cloud metadata endpoints and retrieve captured responses from object storage. The CVSS score is 8.2, which is High severity. Public proof-of-concept material is available for both vulnerabilities.
CVE-2026-19889 – GitLab AI Gateway
“Crafted AI model routing can redirect trusted requests and expose cloud credentials and signing material.”
GitLab fixes two High-severity server-side request forgery vulnerabilities in the AI Gateway. CVE-2026-19889 allows an authenticated Duo Agent Platform user to redirect model requests to an attacker-controlled endpoint through crafted model metadata, potentially exposing Google Vertex AI or AWS Bedrock credentials. The CVSS score is 8.2, which is High severity.
CVE-2026-75871 allows a similar redirect through crafted inline flow configuration and Host header manipulation, potentially exposing Google Cloud Vertex credentials and private signing keys. The CVSS score is 8.2, which is High severity. Public proof-of-concept material is available for both vulnerabilities.
CVE-2026-77652 – GNOME Dia
“Crafted diagram files can corrupt memory and potentially turn routine file opening into code execution.”
GNOME Dia is affected by two High-severity memory corruption vulnerabilities. CVE-2026-77652 is a heap-based buffer overflow in the WPG file importer that can be triggered by a malicious WPG file and may cause crashes or potentially arbitrary code execution. The CVSS score is 7.8, which is High severity.
CVE-2026-77658 is a stack-based buffer overflow in Network Bus object handling within Dia project files. An attacker can supply an excessive handle count and trigger stack exhaustion or memory corruption when the object is manipulated. The CVSS score is 7.8, which is High severity. Public proof-of-concept material is available for both vulnerabilities.
CVE-2026-78465 – GNOME GIMP
“A crafted PCX image can corrupt memory in 32-bit GIMP builds and potentially lead to code execution.”
GIMP is affected by a High-severity integer overflow in the PCX image plugin on 32-bit builds. CVE-2026-78465 allows a crafted PCX file to trigger an undersized heap allocation, followed by a heap-based buffer overflow when image data is written. This can cause memory corruption, denial of service, or potentially arbitrary code execution. The CVSS score is 7.0, which is High severity.
Public proof-of-concept material is available for the vulnerability.
CVE-2026-40575 – OAuth2 Proxy
“A spoofed forwarded URI can turn an authentication exception into direct access to protected routes.”
OAuth2 Proxy is affected by two Critical authentication bypass vulnerabilities involving X-Forwarded-Uri handling in reverse-proxy deployments. CVE-2026-40575 allows an unauthenticated attacker to spoof the forwarded request path so skip-auth rules are evaluated against an attacker-controlled URI rather than the protected upstream route. The CVSS score is 9.1, which is Critical severity.
CVE-2026-76835 shows that the original protection can remain ineffective when reverse-proxy mode uses the default trusted-proxy configuration, allowing all clients to be treated as trusted proxies and bypass authentication with a crafted header. The CVSS score is 9.1, which is Critical severity. Public proof-of-concept material is available for CVE-2026-76835. OAuth2 Proxy 7.15.2 contains the fix for CVE-2026-40575.
CVE-2026-80350 – OneUptime
“A crafted webhook target can bypass SSRF protections and expose internal services or cloud metadata.”
OneUptime contains a High-severity server-side request forgery vulnerability in webhook target validation. CVE-2026-80350 allows an authenticated project member to use IPv4-mapped IPv6 addresses to bypass protections that normally block loopback, private network, and link-local destinations. This can make the OneUptime server connect to internal services or metadata endpoints and expose returned responses. The CVSS score is 7.1, which is High severity.
The issue is fixed in OneUptime 12.0.7. Public proof-of-concept material is available.
CVE-2026-47665 – Penpot
“Malicious shared content can execute in collaborators’ browsers and expose trusted Penpot sessions.”
Penpot fixes two High-severity stored cross-site scripting vulnerabilities. CVE-2026-47665 allows a team member to inject malicious HTML through file comments, causing JavaScript to execute when another collaborator opens the comments panel. The CVSS score is 8.7, which is High severity.
CVE-2026-47666 allows malicious custom font-family names to break out of generated style content and execute JavaScript when affected files are rendered. The CVSS score is 7.6, which is High severity. Public proof-of-concept material is available for both vulnerabilities. Penpot 2.15.3 contains the fixes.
CVE-2026-82268 – Qwen-Agent
“An exposed document parser can become a direct path to internal services and sensitive server files.”
Qwen-Agent through version 0.0.34 contains two High-severity vulnerabilities in its unauthenticated Gradio document parsing interface. CVE-2026-82268 allows server-side request forgery by treating attacker-supplied paths as unrestricted URLs, enabling access to internal services and metadata endpoints. The CVSS score is 7.5, which is High severity.
CVE-2026-82275 allows path traversal through absolute file paths, exposing arbitrary files readable by the Qwen-Agent server process. The CVSS score is 7.5, which is High severity. Public proof-of-concept material is available for both vulnerabilities.
CVE-2026-81934 – Redis
“A TLS memory-safety flaw can turn unauthenticated network access into command execution on the Redis host.”
Redis contains a High-severity use-after-free vulnerability in tlsProcessPendingData() when TLS support is enabled. CVE-2026-81934 may allow a remote unauthenticated attacker to execute arbitrary commands with the privileges of the Redis server. The CVSS score is 7.1, which is High severity.
Public proof-of-concept material is available for the vulnerability.
CVE-2026-80346 – StarRocks
“A missing authorization check lets any authenticated user delete materialized views they do not own.”
StarRocks contains a High-severity authorization flaw affecting legacy synchronous materialized views. CVE-2026-80346 allows any authenticated account to drop a legacy synchronous materialized view in any database without privileges on the view, base table, or database. The CVSS score is 7.1, which is High severity.
Public proof-of-concept material is available for the vulnerability.
CVE-2026-53580 – Trilium
“Trusted note features can expose server files, crash the application, and reveal protected shared content.”
Trilium fixes two High-severity vulnerabilities. CVE-2026-53580 allows an authenticated user to abuse automatic image downloading with file:// URLs to read arbitrary files accessible to the Trilium process. The same flaw can also exhaust memory and crash the server. The CVSS score is 8.1, which is High severity.
CVE-2026-77438 allows unauthenticated users to bypass protection on shared notes through the public share-search endpoint, exposing titles, paths, and potentially complete note content. The CVSS score is 7.5, which is High severity. Public proof-of-concept material is available for both vulnerabilities. Trilium 0.104.0 contains the fixes.
CVE-2026-56705 – Adminer
“Multiple file-handling flaws can turn database administration features into code execution and destructive file access.”
Adminer before 5.4.3 is affected by one Critical and three High-severity vulnerabilities. CVE-2026-56705 allows an unauthenticated attacker to inject ODBC parameters into the server field and write PHP code to a web-accessible path, potentially leading to remote code execution. The CVSS score is 9.8, which is Critical severity.
CVE-2026-56702 allows authenticated users to upload executable PHP files through the AdminerFileUpload plugin and has a CVSS score of 8.8, High severity. CVE-2026-34968 allows arbitrary file deletion in SQLite mode and scores 8.1, High severity. CVE-2026-56703 allows authenticated attackers to abuse SQLite VACUUM INTO to write executable PHP content and scores 7.2, High severity. Public proof-of-concept material is available for all four vulnerabilities. Adminer 5.4.3 contains the fixes.
CVE-2026-70419 – Dell Cloud Disaster Recovery
“High-privileged remote access can be turned into operating-system command execution on affected disaster recovery systems.”
Dell Cloud Disaster Recovery 20.2 and earlier contain two OS command injection vulnerabilities. CVE-2026-70419 allows a high-privileged remote attacker to execute commands on the affected system. The CVSS score is 9.1, which is Critical severity.
CVE-2026-71171 affects the REST API and can also allow a high-privileged remote attacker to achieve remote command execution. The CVSS score is 7.2, which is High severity.
CVE-2026-42007 – OX Dovecot Pro
“Mail processing and OAuth trust flaws can expose memory, enable code execution, and bypass intended authentication controls.”
OX Dovecot Pro addresses two serious vulnerabilities. CVE-2026-42007 is a Sieve editheader use-after-free that can corrupt memory during mail delivery, crash the delivery process, and potentially allow arbitrary code execution. The CVSS score is 9.1, which is Critical severity.
CVE-2026-73208 is an OAuth2 authentication flaw that can accept a token intended for another purpose when the scope claim is missing and the audience value matches a required scope. This can grant access that should have been denied. The CVSS score is 7.4, which is High severity.
CVE-2026-59270 – Spring Security
“Exposed LDAP administration and replayable DPoP proofs can undermine authentication boundaries in affected applications.”
Spring Security is affected by one Critical and one High-severity vulnerability. CVE-2026-59270 affects the embedded UnboundID LDAP server, which registers an administrative credential and binds its listener to all network interfaces. The CVSS score is 9.4, which is Critical severity.
CVE-2026-41707 affects DPoP proof replay protection. Attackers can flood the bounded replay cache, evict valid JWT ID entries, and then replay previously captured DPoP proofs. The CVSS score is 7.4, which is High severity.
CVE-2026-83548 – SonicWall SMA1000
“Active exploitation combines a pre-authentication access path with post-authentication command execution on exposed SMA1000 appliances.”
SonicWall addresses two actively exploited vulnerabilities in the SMA1000 series. CVE-2026-83548 is a Critical pre-authentication SSRF flaw in the Appliance Work Place interface that can allow an unauthenticated remote attacker to reach sensitive functionality and perform unauthorized operations. The CVSS score is 10.0, which is Critical severity.
CVE-2026-83549 is a High-severity OS command injection flaw in the Appliance Management Console that can allow a remote authenticated administrator to execute arbitrary operating-system commands. The CVSS score is 7.8, which is High severity. Active exploitation is confirmed for both vulnerabilities. Fixed hotfixes include 12.4.3-03526 and 12.5.0-02952.
CVE-2026-59822 – litellm
“A forged authorization path can turn failed authentication into unintended access.”
BerriAI fixed an authentication bypass in LiteLLM prior to version 1.84.0. CVE-2026-59822 affects the MCP Streamable HTTP endpoint, where a fabricated Authorization header could trigger an OAuth2 passthrough fallback and allow requests to reach MCP tooling without a valid LiteLLM key. The CVSS score is 8.8, which is High severity.
Active exploitation is confirmed. The issue is fixed in LiteLLM 1.84.0.
CVE-2026-6471 – PostgreSQL
“Replication privileges can become a path to arbitrary code execution.”
PostgreSQL patched a missing authorization vulnerability in logical decoding. CVE-2026-6471 allows a non-superuser with REPLICATION privileges to load an arbitrary file accessible to the PostgreSQL operating system account, resulting in arbitrary code execution under that account. The CVSS score is 7.2, which is High severity.
Affected versions are those before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24. These releases contain the fix.
CVE-2026-73749 – AOS-CX
“Multiple attack paths put network infrastructure, privileged access, and system integrity at risk.”
HPE patched multiple AOS-CX vulnerabilities covering unauthenticated and authenticated remote code execution, command injection, arbitrary file writes, authentication bypass, privilege escalation, stored XSS, CSRF, and unauthorized administrative access. CVE-2026-73749 has a CVSS score of 9.8, Critical severity. CVE-2026-73750, CVE-2026-73751, CVE-2026-73752, CVE-2026-73753, and CVE-2026-73782 each have a CVSS score of 8.8, High severity. CVE-2026-73781 is 8.4, CVE-2026-73780 is 8.3, CVE-2026-73779 is 8.2, and CVE-2026-73778 and CVE-2026-73777 are 8.1; all are High severity.
The updates are available in AOS-CX 10.18.1002, 10.17.1030, 10.16.1060, 10.13.1190, and applicable 10.10.1181 releases. The 10.10 branch is end-of-maintenance and does not receive the full set of fixes.
CVE-2026-14894 – Super Forms – Drag & Drop Form Builder
“An unauthenticated file upload flaw can turn a public WordPress form into a path for full server compromise.”
WebRehab patched a critical arbitrary file upload vulnerability affecting Super Forms – Drag & Drop Form Builder through version 6.3.313. CVE-2026-14894 allows an unauthenticated attacker to obtain a valid nonce, upload potentially executable files, and achieve remote code execution. The CVSS score is 9.8, which is Critical severity.
Public proof-of-concept material and real-world exploitation have been reported. The issue is fixed in version 6.3.314.
CVE-2026-20212 – Cisco NX-OS Software
“Exposed management ports can turn a network switch into a path for root-level code execution.”
Cisco NX-OS Software contains a critical vulnerability in the Silicon One integration for Nexus 9000 Series Switches. CVE-2026-20212 allows an unauthenticated remote attacker to send crafted input through TCP ports 43210 or 43211 and execute code with root privileges. The CVSS score is 9.8, which is Critical severity.
Successful exploitation can also crash the S1HAL process and force the affected device to reload, creating both system-compromise and availability risk.
CVE-2026-63219 – core-geonetwork
“An exposed upload path and unsafe XSLT processing can combine into a route from file write to command execution.”
GeoNetwork patched two vulnerabilities affecting formatter handling. CVE-2026-63219 allows an unauthenticated attacker to upload arbitrary .xsl or .zip formatter files into the GeoNetwork formatter directory. It has a CVSS score of 8.6, High severity. CVE-2026-58400 allows uploaded XSLT stylesheets to invoke Java functionality and execute arbitrary operating-system commands as the GeoNetwork process user. It has a CVSS score of 9.1, Critical severity.
Both issues are fixed in GeoNetwork versions 4.4.12 and 4.2.17.
No updates match the selected filters.






