2026 · High
High-severity vulnerabilities disclosed in 2026
High-rated CVEs published in 2026, with SEC.co remediation and prioritization guidance.
4140 published vulnerabilities · page 4 of 42
- CVE-2026-13870HIGH 8.8
A use-after-free memory flaw in Chrome's WebView component on Android allows attackers to run malicious code within the browser sandbox by hosting a specially crafted webpage. Any user who visits the malicious page while using an affected Chrome version could be compromised. The vulnerability affects Chrome versions before 150.0.7871.47.
- CVE-2026-13884HIGH 8.8
CVE-2026-13884 is an integer overflow vulnerability in the Chromecast component of Google Chrome. A local attacker on the same network can send malicious network traffic to trigger the overflow and achieve arbitrary code execution with no user interaction required. This is a serious local network attack, not an internet-facing threat.
- CVE-2026-13885HIGH 8.8
A use-after-free vulnerability exists in Skia, Google Chrome's graphics library, affecting Android versions prior to 150.0.7871.47. An attacker can craft a malicious HTML page that, when visited by a user, triggers code execution within Chrome's sandbox. While sandboxed, successful exploitation could allow an attacker to break out of Chrome's security boundary and access the underlying Android system, posing a significant risk to affected devices.
- CVE-2026-13888HIGH 8.8
A use-after-free memory vulnerability exists in Google Chrome's extension handling system. When a user visits a malicious webpage, an attacker can exploit this flaw to run arbitrary code within Chrome's sandboxed extension environment. The vulnerability requires user interaction (visiting a crafted webpage) but carries significant risk because it bypasses Chrome's sandbox protections, which are designed to contain extension-level exploits. All recent versions of Chrome before 150.0.7871.47 are affected across Windows, macOS, and Linux platforms.
- CVE-2026-13897HIGH 8.8
A flaw in how Google Chrome enforces security policies for Chromecast functionality allows attackers to trick users into visiting malicious web pages that escalate their browser privileges. The attacker gains access equivalent to the user's account, posing a direct risk to data and system integrity. This affects Chrome versions before 150.0.7871.47.
- CVE-2026-13898HIGH 8.8
A use-after-free vulnerability in Google Chrome's Cast Receiver component allows attackers to run arbitrary code within the browser's sandbox by tricking users into visiting a malicious webpage. The flaw affects Chrome versions prior to 150.0.7871.47 and requires user interaction (clicking a link or visiting a site). While sandboxed, successful exploitation could give an attacker significant control over the affected user's browsing session and data.
- CVE-2026-13899HIGH 8.8
A use-after-free memory flaw in Google Chrome's HTML rendering engine allows attackers to run arbitrary code within the browser's sandbox by sending a specially crafted web page. An attacker would need to trick a user into visiting a malicious website, but once there, the flaw could allow code execution with the privileges of the browser process.
- CVE-2026-13903HIGH 8.8
Google Chrome versions before 150.0.7871.47 contain a vulnerability in Bluetooth policy enforcement that allows attackers to escalate privileges on a user's system. An attacker can craft a malicious HTML page that, when visited by a user, exploits insufficient controls over Bluetooth permissions to gain elevated access. This is a remote attack requiring only user interaction—no special network conditions or authentication.
- CVE-2026-13915HIGH 8.8
A use-after-free memory flaw in Chrome for iOS allows attackers to corrupt heap memory and potentially take control of your device if you visit a malicious webpage and perform certain UI gestures, such as scrolling or tapping in specific ways. The vulnerability affects Chrome on iPhones running iOS versions prior to 150.0.7871.47. While Google rated this as medium severity internally, the CVSS score of 8.8 reflects the practical risk: no special privileges are required, the attack works over the network, and successful exploitation grants full read, write, and delete access to device memory.
- CVE-2026-13918HIGH 8.8
A use-after-free vulnerability exists in Chrome for iOS that allows attackers to corrupt memory and potentially take control of the affected device through a malicious webpage. The flaw affects Chrome versions before 150.0.7871.47 on iPhone and iPad. An attacker needs only to trick a user into visiting a crafted website—no special access or complex interaction is required beyond basic browsing.
- CVE-2026-13928HIGH 8.8
Google Chrome versions before 150.0.7871.47 contain a vulnerability that allows attackers to gain elevated privileges on a user's system by tricking them into visiting a malicious webpage. The flaw stems from inadequate checking of user-supplied input, and while Google rates the underlying issue as medium severity, the combination of remote exploitability, user interaction requirement, and high impact consequences results in a CVSS score of 8.8 (HIGH). Users who browse to a specially crafted HTML page could see their Chrome process escalate its privileges, potentially compromising the entire browser context.
- CVE-2026-13938HIGH 8.8
Google Chrome versions before 150.0.7871.47 contain an integer overflow vulnerability in the font rendering system that attackers can exploit by sending a crafted HTML page. If a user visits a malicious site, the overflow can corrupt memory in a way that lets the attacker read sensitive data, modify running code, or crash the browser. The vulnerability requires user interaction (clicking a link or visiting a page) but no special privileges.
- CVE-2026-13965HIGH 8.8
Google Chrome versions before 150.0.7871.47 contain a use-after-free vulnerability in Oilpan, Chrome's garbage collection system. An attacker can craft a malicious HTML page that, when visited, triggers unsafe memory access and executes arbitrary code within Chrome's sandbox. While the sandbox contains the impact to the browser process, the flaw still allows complete compromise of that process with full read, write, and execute access. This is a remote attack requiring only that a user visit a hostile website—no special user privileges or configuration changes are needed.
- CVE-2026-13967HIGH 8.8
Google Chrome contains a heap buffer overflow vulnerability in its V8 JavaScript engine that could allow attackers to run malicious code within Chrome's sandbox by sending users a crafted webpage. The vulnerability requires user interaction—specifically visiting a malicious site—but once triggered, grants an attacker the ability to execute arbitrary code with the privileges of the Chrome process. This is a serious flaw because while Chrome's sandbox provides some containment, code execution within it can still lead to data theft or further system compromise.
- CVE-2026-14005HIGH 8.8
A use-after-free memory vulnerability exists in Google Chrome's address bar (Omnibox) on Android devices. An attacker can craft a malicious webpage that, when a user interacts with it in specific ways, causes Chrome to access memory that has already been freed. This can lead to heap corruption and potential code execution. The vulnerability requires user interaction and affects Chrome versions prior to 150.0.7871.47.
- CVE-2026-14006HIGH 8.8
A use-after-free vulnerability in Google Chrome's navigation feature allows attackers to execute arbitrary code on a victim's system by tricking them into visiting a malicious webpage. The flaw affects Chrome versions before 150.0.7871.47. The vulnerability requires user interaction (visiting a crafted page) but poses a significant risk because successful exploitation grants an attacker full control over the affected system.
- CVE-2026-14009HIGH 8.8
Google Chrome versions before 150.0.7871.47 contain a flaw in how the browser handles password-related operations that can allow an attacker to corrupt the application's memory. An attacker who crafts a malicious webpage and tricks a user into visiting it could potentially execute arbitrary code or crash the browser. This is not a remote code execution vulnerability that requires no user interaction; the attack requires a user to actually visit a malicious page.
- CVE-2026-14024HIGH 8.8
A use-after-free flaw in Chrome's Ozone display server component on Linux allows attackers to corrupt memory and potentially execute code if a user is tricked into performing specific UI interactions on a malicious webpage. The vulnerability affects Chrome versions before 150.0.7871.47 and requires user interaction to exploit, but once triggered can lead to full system compromise.
- CVE-2026-14025HIGH 8.8
A use-after-free vulnerability exists in Google Chrome's Views component on macOS. If a user visits a malicious webpage and interacts with the page in a specific way—such as clicking certain elements or performing gestures—an attacker could trigger memory corruption that may lead to a complete compromise of the browser process. The vulnerability requires user interaction and affects Chrome versions prior to 150.0.7871.47 on macOS.
- CVE-2026-14027HIGH 8.8
A use-after-free vulnerability in Google Chrome's sign-in functionality allows attackers to corrupt memory and potentially execute arbitrary code on a victim's machine. The attack requires convincing a user to perform specific gestures during the sign-in process on a malicious webpage. While Chromium rates this as low severity from a feature perspective, the underlying memory corruption can lead to complete system compromise if successfully exploited.
- CVE-2026-14036HIGH 8.8
Google Chrome versions prior to 150.0.7871.47 contain a vulnerability in Bluetooth policy enforcement that allows attackers to escalate privileges on affected systems. By crafting a malicious HTML page, a remote attacker can trick users into visiting the page and gain elevated system permissions. The vulnerability requires user interaction (clicking or viewing a link) but does not require the victim to be authenticated or for the attacker to be on the same network.
- CVE-2026-14040HIGH 8.8
Google Chrome versions prior to 150.0.7871.47 contain a use-after-free vulnerability in the BrowserTag component that could allow attackers to corrupt heap memory. The attack requires an attacker to first convince a user to install a malicious Chrome extension. While Chromium classifies this as low severity internally, the CVSS 3.1 score of 8.8 reflects the potential for complete system compromise if successfully exploited. Users who install untrusted extensions remain at risk until they update to the patched version.
- CVE-2026-14041HIGH 8.8
A security flaw in Google Chrome's Serial API component allows attackers to bypass security restrictions through a specially crafted webpage. When a user visits a malicious site, the attacker can escalate their privileges on the user's system without requiring any special permissions beforehand. The vulnerability affects Chrome versions prior to 150.0.7871.47 and requires user interaction (clicking or viewing the page) to be exploited.
- CVE-2026-14067HIGH 8.8
A use-after-free flaw in Chrome for iOS allows attackers to execute arbitrary code on affected iPhones when a user visits a maliciously crafted webpage. The vulnerability exists in memory management within Chrome's iOS implementation—specifically, the browser can attempt to access data that has already been freed, enabling code execution. While Chromium's internal severity rating is Low, the CVSS score of 8.8 reflects the practical risk: remote, unauthenticated exploitation via a simple link click, with full impact to confidentiality, integrity, and availability. This affects all Chrome users on iOS running versions prior to 150.0.7871.47.
- CVE-2026-14078HIGH 8.8
A weakness in how Google Chrome handles WebRTC (real-time communication) components fails to properly validate user-supplied input, allowing attackers to trick users into visiting a malicious webpage that could escalate their privileges on the system. The attacker needs the user to click through to a crafted page, but requires no special access or authentication to launch the attack.
- CVE-2026-14084HIGH 8.8
Google Chrome versions before 150.0.7871.47 contain a vulnerability in its Chromoting remote access feature that fails to properly validate untrusted input from the network. This weakness can allow an attacker to send specially crafted network traffic that corrupts the browser's memory, potentially leading to code execution. The vulnerability requires user interaction—such as establishing or accepting a remote connection—but does not require special privileges to exploit.
- CVE-2026-14086HIGH 8.8
Google Chrome versions before 150.0.7871.47 contain a vulnerability in its Human Interface Device (HID) handling that permits remote code execution when a user visits a malicious webpage. An attacker can craft a specially designed HTML page that exploits insufficient policy enforcement in the HID implementation, allowing them to run arbitrary code with the privileges of the Chrome process. User interaction—opening or viewing the crafted page—is required to trigger the vulnerability.
- CVE-2026-14087HIGH 8.8
A heap buffer overflow vulnerability exists in the WebNN (Web Neural Network) component of Google Chrome on Windows systems. The flaw allows a remote attacker who has already compromised the Chrome renderer process to trigger heap memory corruption by crafting a malicious HTML page. While Chromium classifies this as low severity, the CVSS 3.1 assessment reflects the potential for significant impact if exploited, including confidentiality, integrity, and availability violations.
- CVE-2026-14091HIGH 8.8
A use-after-free memory vulnerability exists in Chrome's DevTools (developer tools) that allows an attacker to execute arbitrary code within the browser's sandbox through a malicious HTML page. The vulnerability affects Chrome versions prior to 150.0.7871.47 and requires user interaction—the victim must view the crafted HTML in their browser. While Chromium rates this as low severity internally, the CVSS 3.1 assessment reflects high risk due to the combination of network delivery, lack of authentication, and potential for complete system compromise.
- CVE-2026-14099HIGH 8.8
A use-after-free memory vulnerability exists in Chrome for iOS that could allow an attacker to corrupt heap memory on your device. The attack requires you to visit a specially crafted website and perform specific UI interactions—there's no automatic exploitation. Once triggered, the memory corruption could lead to full device compromise: stealing sensitive data, modifying content, or crashing the browser. This affects Chrome on iOS versions before 150.0.7871.47.
- CVE-2026-14102HIGH 8.8
Google Chrome versions prior to 150.0.7871.47 contain a use-after-free vulnerability in the password management system. An attacker can craft a malicious HTML page that, when visited by a user, exploits this memory safety flaw to corrupt heap memory and potentially execute arbitrary code. The vulnerability requires user interaction (visiting a website) but does not require special privileges.
- CVE-2026-14107HIGH 8.8
A use-after-free vulnerability exists in Google Chrome's scheduling system that allows attackers to execute code within the Chrome sandbox by tricking users into visiting a malicious webpage. The vulnerability affects Chrome versions prior to 150.0.7871.47. While the Chromium project classified this as low severity, the CVSS score of 8.8 reflects the high-impact nature of the issue due to the combination of network accessibility, low complexity, and the requirement for user interaction.
- CVE-2026-14108HIGH 8.8
A use-after-free vulnerability in PDFium, the PDF rendering engine embedded in Google Chrome, allows attackers to execute arbitrary code within Chrome's sandboxed environment by crafting a malicious PDF file. The vulnerability requires user interaction—a victim must open the malicious PDF—but once triggered, it can bypass Chrome's sandbox protections. This affects Chrome versions prior to 150.0.7871.47 across Windows, macOS, and Linux systems.
- CVE-2026-14149HIGH 8.8
A use-after-free vulnerability exists in Google Chrome's audio processing component on Linux systems. An attacker can craft a malicious HTML page that, when visited by a user, exploits this memory safety flaw to execute arbitrary code on the victim's machine. The vulnerability requires user interaction (visiting a webpage) but needs no special privileges to trigger. Chrome versions before 150.0.7871.47 on Linux are affected.
- CVE-2026-14158HIGH 8.8
The Widget Logic Visual plugin for WordPress allows attackers with subscriber-level accounts to execute arbitrary code on a website. The vulnerability exists in the AJAX handler that manages conditional tag logic, where attackers can manipulate parameters that are directly passed to PHP's eval() function without proper validation. Because subscriber accounts are commonly created by content editors and contributors, this significantly lowers the barrier to exploitation compared to attacks requiring administrative access.
- CVE-2026-14380HIGH 8.8
DBI, a Perl database interface module, has a critical vulnerability in how it handles the Profile attribute. When this attribute receives untrusted input—from environment variables, direct code assignment, or database connection strings—DBI evaluates it as Perl code without proper validation. An attacker who controls any of these inputs can execute arbitrary commands on the affected system. The risk is particularly acute for exposed database brokers (DBI::Gofer or DBI::ProxyServer) where remote clients can inject malicious code through connection parameters.
- CVE-2026-14383HIGH 8.8
A flaw in Chrome's V8 JavaScript engine allows attackers to break out of the sandbox and run malicious code on a victim's computer by tricking them into visiting a specially crafted webpage. The vulnerability affects Chrome versions before 150.0.7871.46 and requires user interaction (clicking a link or visiting a site), but once exploited, gives an attacker full control over the browser process and potentially the underlying system.
- CVE-2026-14385HIGH 8.8
A heap buffer overflow vulnerability exists in the ANGLE graphics rendering component within Google Chrome on macOS. An attacker can exploit this by hosting a malicious HTML page—when a user visits the page, Chrome's rendering engine writes data beyond allocated memory boundaries, potentially compromising the confidentiality, integrity, and availability of the browser process. This is a remote attack requiring no special privileges, though it does require user interaction (visiting a crafted page).
- CVE-2026-14393HIGH 8.8
A use-after-free vulnerability in Google Chrome's V8 JavaScript engine (prior to version 150.0.7871.46) allows attackers to execute arbitrary code within the browser's sandbox by tricking users into visiting a malicious webpage. While the Chromium team rated this as medium severity internally, the CVSS score of 8.8 reflects the practical risk: an attacker needs only to craft a deceptive HTML page and convince a user to visit it—no special privileges or complex conditions required. The attack lands inside the sandbox, limiting but not eliminating post-exploitation impact.
- CVE-2026-14394HIGH 8.8
A use-after-free vulnerability exists in Google Chrome's V8 JavaScript engine that could allow an attacker to corrupt heap memory by tricking a user into visiting a malicious webpage. The flaw affects Chrome versions before 150.0.7871.46 and requires user interaction (clicking or viewing the page) to trigger. While Chromium rates the severity as Low, the CVSS 3.1 score of 8.8 reflects the potential for complete system compromise through memory corruption.
- CVE-2026-14395HIGH 8.8
Google Chrome versions before 150.0.7871.46 contain an out-of-bounds write vulnerability in the V8 JavaScript engine that allows attackers to run malicious code within the browser's sandbox. An attacker can exploit this by crafting a malicious HTML page and tricking a user into visiting it. Once triggered, the vulnerability permits arbitrary code execution inside the sandboxed environment. While the sandbox provides a containment boundary, successful exploitation still represents a serious security risk.
- CVE-2026-14403HIGH 8.8
A use-after-free memory vulnerability exists in Google Chrome's V8 JavaScript engine that could allow an attacker to run malicious code within the browser's sandbox by tricking a user into visiting a specially crafted webpage. While the Chromium team rated this internally as low severity, the CVSS assessment reflects high risk due to the combination of remote exploitability, low attack complexity, and potential for code execution.
- CVE-2026-14407HIGH 8.8
A flaw in Google Chrome's V8 JavaScript engine allows attackers to run malicious code inside the browser's sandbox by tricking users into visiting a specially crafted webpage. The vulnerability requires user interaction (clicking a link or visiting a site) but does not require any special privileges. Once exploited, an attacker gains the ability to read sensitive data, modify information, or disrupt browser functionality from within the sandboxed environment.
- CVE-2026-14415HIGH 8.8
A flaw in Google Chrome's V8 JavaScript engine allows heap memory corruption when a user interacts with a malicious webpage through specific UI gestures. An attacker crafts an HTML page that, when visited and engaged with in particular ways, corrupts the heap—a critical memory region—potentially leading to code execution or application crash. Chrome versions before 150.0.7871.46 are vulnerable. The attack requires user interaction, not silent exploitation.
- CVE-2026-14422HIGH 8.8
A memory safety vulnerability exists in Chrome's Tint rendering component that allows attackers to read and write beyond allocated memory boundaries. When a user visits a malicious website, the attacker can craft HTML that triggers out-of-bounds memory access, potentially compromising confidentiality, integrity, and availability. The vulnerability requires user interaction (visiting a malicious page) but no special privileges, making it a significant risk for typical browsing scenarios.
- CVE-2026-14430HIGH 8.8
A flaw in Google Chrome's V8 JavaScript engine allows attackers to crash the browser or run malicious code within Chrome's sandbox by sending a specially crafted webpage. The vulnerability affects Chrome versions before 150.0.7871.46 and requires only that a user visit a malicious site—no special privileges needed. While the code runs inside Chrome's sandbox (limiting system-wide damage), the sandbox can sometimes be bypassed, making this a serious threat to anyone browsing the web.
- CVE-2026-14431HIGH 8.8
A type confusion flaw in Chrome's V8 JavaScript engine allows attackers to run malicious code within the browser's sandbox by serving a specially crafted webpage. The vulnerability requires user interaction (visiting a malicious site) but carries high risk because it bypasses the sandbox's isolation protections and can lead to full browser compromise.
- CVE-2026-14432HIGH 8.8
Google Chrome contains a use-after-free vulnerability in its V8 JavaScript engine that can allow attackers to run malicious code within Chrome's sandbox by tricking users into visiting a specially crafted website. The flaw affects Chrome versions before 150.0.7871.46 and requires user interaction (clicking a link or visiting a site) but no special privileges. While sandboxing limits direct system access, a successful exploit could still compromise browser data and potentially serve as a stepping stone for further attacks.
- CVE-2026-14459HIGH 8.8
CVE-2026-14459 is a command argument injection flaw in pardus-software versions 1.0.4 and earlier. An attacker with local access can inject malicious arguments into commands, potentially gaining elevated privileges or executing arbitrary code. The vulnerability has been patched in version 1.0.5.
- CVE-2026-14460HIGH 8.8
A missing authorization flaw in pardus-software versions up to and including 1.0.4 allows local users with standard privileges to inject arbitrary arguments into the application, potentially gaining elevated access or capabilities. The vulnerability requires an authenticated local account but does not require user interaction to exploit, making it a practical risk in multi-user or shared-system environments.
- CVE-2026-14474HIGH 8.8
SSSD (System Security Services Daemon) contains a privilege escalation vulnerability in its LDAP sudo provider. When administrators don't explicitly configure where SSSD should search for sudo rules in LDAP (the ldap_sudo_search_base option), the daemon searches the entire directory tree by default. An attacker with write permissions to any part of the LDAP directory can exploit this by injecting a malicious sudo rule that grants root-level privileges across all machines using SSSD for authentication. This transforms a limited directory write capability into full system compromise on enrolled hosts.
- CVE-2026-14482HIGH 8.8
A security flaw in the 多说社会化评论框 (Duoshuo) WordPress plugin allows unauthenticated attackers to gain full administrator access to any affected WordPress site. The vulnerability stems from an unprotected API endpoint that accepts attacker-controlled WordPress options without proper validation. By exploiting weak signature verification and missing permission checks, an attacker can change critical site settings—such as allowing new user registration and setting the default role to administrator—then sign up with admin privileges. Any WordPress site running the plugin version 1.2 or earlier is at immediate risk.
- CVE-2026-14489HIGH 8.8
The WHMCS Bridge plugin for WordPress has a critical vulnerability that allows attackers with certain user permissions to upload files without proper validation. An attacker who has been granted 'Custom-level' access or higher can upload malicious files to your server, potentially gaining the ability to run arbitrary code and take full control of the WordPress installation.
- CVE-2026-14495HIGH 8.8
The DoLogin Security plugin for WordPress contains a critical flaw in how it generates passwordless login tokens. The plugin uses a weak random number generator seeded with insufficient entropy—essentially a 20-bit seed derived only from microseconds, discarding the stable seconds component of the system clock. This means an attacker can predict the entire 32-character magic-link token if they know or can guess the numeric account ID. Because the login verification bypasses normal WordPress authentication safeguards and doesn't enforce login attempt lockouts, a malicious user can brute-force the limited seed space (~1 million possibilities) in seconds and log in as any targeted account, including administrators, without needing a password. The attack requires that a valid passwordless login link currently exists for the victim's account.
- CVE-2026-14534HIGH 8.8
Fickling, a Python library designed to detect malicious pickle payloads before they execute, fails to block code execution via three standard library modules: _posixsubprocess, site, and atexit. An attacker can craft a specially formatted pickle file that exploits these blind spots, causing fickling's safety check to incorrectly report the payload as safe. When a developer uses fickling to load the pickle, the malicious code runs anyway. This is particularly dangerous because fickling is explicitly marketed as a security gate, so users trust its verdicts.
- CVE-2026-14535HIGH 8.8
Trail of Bits fickling is a Python library designed to safely deserialize pickle files by analyzing them for dangerous imports before unpickling. A logic flaw in versions up to 0.1.11 breaks one of its two main safety checks. When fickling examines a pickle file, it runs two separate inspection passes: one flags obviously dangerous imports, and a second one (MLAllowlist) is supposed to catch sneaky imports from non-ML libraries that the first pass missed. However, the first pass leaves markers in shared memory that trick the second pass into skipping its checks entirely. As a result, any import from Python's standard library—except those on a small blocklist—gets a green light, even if it's dangerous. Because fickling's public API treats a green light as permission to actually deserialize and run the pickle, an attacker can craft a pickle file that imports and executes arbitrary standard library code, bypassing the security gate entirely.
- CVE-2026-14536HIGH 8.8
Devolutions Server 2026.2.9.0 contains a flaw that allows attackers with valid login credentials to skip multi-factor authentication (MFA) and gain full access to the system. The vulnerability occurs when the server encounters an invalid default MFA configuration, creating a gap in the authentication enforcement mechanism. An attacker who has already compromised a user's password can exploit this to bypass the MFA requirement entirely, gaining the same level of access as if they had completed the second factor.
- CVE-2026-14721HIGH 8.8
A stack-based buffer overflow vulnerability exists in UTT HiPER 1250GW wireless gateway devices up to firmware version 3.2.7-210907-180535. An authenticated attacker can overflow a buffer in the 5GHz wireless configuration endpoint by supplying a specially crafted SSID parameter, potentially achieving remote code execution. Public exploit code is available, elevating the practical risk.
- CVE-2026-15067HIGH 8.8
Snowflake Terraform Provider versions before 2.18.0 contain two critical injection flaws. An attacker who can modify workspace variables in a Terraform pipeline could execute arbitrary SQL commands under the provider's Snowflake session privileges, potentially stealing sensitive data or creating persistent access credentials. A second vulnerability allows attackers to inject DDL commands into user creation statements, enabling account creation with attacker-controlled passwords that bypass your configured security policies. Both require initial access to your Terraform workflow or pipeline configuration.
- CVE-2026-15070HIGH 8.8
The Salon Booking System plugin for WordPress contains a critical flaw that allows attackers to execute malicious code on vulnerable websites. An attacker can craft a deceptive link that, when clicked by a site administrator, injects harmful PHP code into a plugin file. This happens because the plugin fails to properly validate requests before making changes, and its input filtering doesn't block the special characters needed to break out of safe code boundaries. No authentication is required from the attacker's side—only social engineering to get an admin to click the link.
- CVE-2026-15107HIGH 8.8
Google Chrome contains a use-after-free vulnerability in its IndexedDB implementation that allows attackers to execute arbitrary code within the Chrome sandbox by convincing users to visit a malicious website. The flaw affects Chrome versions prior to 150.0.7871.115 and requires user interaction (clicking a link or visiting a page) to trigger. While the vulnerability is sandboxed, successful exploitation could allow an attacker to read sensitive data, modify browser state, or crash the application.
- CVE-2026-15110HIGH 8.8
A use-after-free vulnerability exists in Google Chrome's extension handling mechanism. An attacker could craft a malicious Chrome extension that, when installed by a user, triggers memory corruption on the victim's system. This flaw affects Chrome versions prior to 150.0.7871.115 and requires user interaction (convincing someone to install the extension), but once exploited could compromise the confidentiality, integrity, and availability of the affected system.
- CVE-2026-15112HIGH 8.8
Google Chrome versions before 150.0.7871.115 contain a use-after-free memory defect in the Ozone component that an attacker can trigger by hosting a malicious web page. If a user visits such a page, the flaw can corrupt the browser's heap memory, potentially allowing the attacker to read sensitive data, modify running processes, or crash the browser. This is a network-based attack requiring only that a user click a link or visit a compromised site—no special user privileges or system access needed.
- CVE-2026-15114HIGH 8.8
A memory safety vulnerability in Google Chrome's video codec processing allows attackers to corrupt heap memory by tricking users into opening a specially crafted video file. The flaw combines an out-of-bounds read with an out-of-bounds write, potentially enabling arbitrary code execution on affected systems. Users must update to Chrome 150.0.7871.115 or later to patch the issue.
- CVE-2026-15116HIGH 8.8
Google Chrome contains a use-after-free vulnerability in its Actor component that could allow attackers to run malicious code within Chrome's sandbox by tricking users into visiting a specially crafted webpage. The flaw affects Chrome versions before 150.0.7871.115 and requires user interaction (clicking a link or visiting a malicious site) but no special privileges to exploit.
- CVE-2026-15118HIGH 8.8
Google Chrome versions before 150.0.7871.115 contain a use-after-free flaw in the Input component that can be exploited by a remote attacker. An attacker can craft a malicious HTML page that, when visited by a user, triggers the vulnerability and executes arbitrary code within Chrome's sandbox environment. This is a memory safety issue where the browser attempts to access input data after it has already been freed, allowing code injection with high impact to confidentiality, integrity, and availability.
- CVE-2026-15121HIGH 8.8
A use-after-free vulnerability in Google Chrome's WebRTC implementation allows attackers to run malicious code within the browser's sandbox by tricking users into visiting a crafted website. The vulnerability affects Chrome versions before 150.0.7871.115. While the code executes in a sandbox (limiting direct system impact), successful exploitation could lead to data theft, credential capture, or lateral movement to other browser contexts.
- CVE-2026-15123HIGH 8.8
Google Chrome versions before 150.0.7871.115 contain a flaw in how the browser handles the Document Object Model (DOM) that could allow attackers to corrupt memory on your system. An attacker could craft a malicious web page that, when visited, exploits this vulnerability to gain control over sensitive data, modify web content, or crash your browser. The vulnerability requires user interaction—you must visit the malicious page—but no special user privileges are needed, and the attacker doesn't need network access beyond hosting the page.
- CVE-2026-15125HIGH 8.8
Google Chrome versions before 150.0.7871.115 contain a vulnerability in the Forms implementation that allows attackers to execute arbitrary code within Chrome's sandbox through a malicious HTML page. An attacker would need to trick a user into visiting or interacting with a crafted webpage, but once clicked or loaded, the vulnerability could allow code execution with the privileges of the browser process.
- CVE-2026-15126HIGH 8.8
A use-after-free vulnerability exists in Google Chrome's Forms component that allows an attacker to execute arbitrary code within Chrome's sandbox environment. An attacker would need to trick a user into visiting a specially crafted webpage. If successful, the attacker gains code execution inside the sandbox, which provides some isolation but can still lead to data theft, credential harvesting, or lateral movement depending on the victim's system configuration. Google has assigned this a High severity rating. The vulnerability affects Chrome versions prior to 150.0.7871.115.
- CVE-2026-15129HIGH 8.8
A use-after-free flaw in Google Chrome's Views component could allow an attacker to corrupt browser memory and take control of your system when you visit a malicious website. The vulnerability affects Chrome versions before 150.0.7871.115. No user interaction beyond visiting a crafted page is required to trigger the flaw, making it a serious risk for any organization relying on Chrome.
- CVE-2026-15132HIGH 8.8
A vulnerability in Google Chrome's V8 JavaScript engine allows attackers to execute malicious code within the browser's sandbox by tricking users into visiting a specially crafted webpage. The flaw stems from improper handling of uninitialized variables, creating a memory safety issue that can be exploited without requiring special user permissions or authentication. This is a remote code execution (RCE) vulnerability that affects Chrome versions prior to 150.0.7871.115.
- CVE-2026-15133HIGH 8.8
Google Chrome versions before 150.0.7871.115 contain a use-after-free vulnerability in the InterestGroups feature. An attacker can craft a malicious HTML page that, when opened in an affected browser, triggers the flaw to execute arbitrary code within the Chrome sandbox. The vulnerability requires user interaction (visiting a malicious page) but poses a high risk due to the ease of exploitation and the potential for sandbox escape or data theft.
- CVE-2026-1784HIGH 8.8
A flaw in OpenShift's Route resource allows users with low-level cluster access to inject malicious HAProxy configuration through the spec.path field. Because validation of this field is insufficient, an attacker can bypass intended restrictions and alter how traffic is routed, potentially redirecting requests or exposing sensitive data. This is a local privilege escalation risk requiring existing cluster access but delivering high-impact consequences.
- CVE-2026-1829HIGH 8.8
The Content Visibility for Divi Builder plugin for WordPress contains a critical flaw that allows attackers with basic WordPress user access to run arbitrary code on affected servers. The vulnerability exists in how the plugin processes a specific shortcode parameter without proper validation, creating a direct path to server compromise. Any WordPress installation using this plugin up to version 4.02 is at risk if it has users with Contributor access or higher privileges.
- CVE-2026-20251HIGH 8.8
A vulnerability in Splunk Enterprise, Splunk Cloud Platform, and Splunk Secure Gateway allows low-privileged users without admin or power roles to execute arbitrary code remotely. The flaw stems from unsafe deserialization of data stored in Splunk's KV Store (key-value store) component. An attacker only needs basic user credentials to potentially compromise the entire Splunk environment. This is a serious issue because privilege escalation to code execution typically requires administrative access; this vulnerability bypasses that requirement entirely.
- CVE-2026-21837HIGH 8.8
HCL Digital Experience contains an OS command injection flaw in its Digital Asset Management API that allows authenticated attackers to run arbitrary commands on the underlying system. Because the API typically executes with application-level privileges, successful exploitation could grant an attacker a foothold to pivot deeper into your infrastructure or exfiltrate sensitive data. This is a post-authentication vulnerability, meaning an attacker needs valid credentials to exploit it.
- CVE-2026-22054HIGH 8.8
NetApp Active IQ Config Advisor version 6.7.3 contains hard-coded credentials embedded in the application code. An attacker with valid login credentials—even with minimal user privileges—can exploit these hard-coded credentials to perform AutoSupport operations without authorization. AutoSupport is a critical diagnostic and support feature that transmits sensitive system configuration and performance data to NetApp; unauthorized use could lead to data exfiltration, system misconfiguration, or support channel manipulation.
- CVE-2026-22055HIGH 8.8
Active IQ OneCollect version 2.7.3 contains hard-coded credentials embedded in the application. An authenticated user with basic network access can exploit these credentials to perform unauthorized AutoSupport operations—potentially exfiltrating sensitive system telemetry, configuration data, or triggering unwanted support actions. The vulnerability requires an attacker to already have valid credentials to an affected system, but once authenticated, the hard-coded secrets bypass normal access controls and allow privilege escalation to perform high-impact operations.
- CVE-2026-22342HIGH 8.8
A vulnerability in WordPress Dating Theme versions 11.2.0 and earlier allows attackers to perform unwanted actions on behalf of site visitors without their knowledge or consent. An attacker can craft a malicious webpage that, when visited by an authenticated site administrator or user, triggers hidden requests that modify site settings, create accounts, or alter content. No special privileges are required to launch the attack, but it does depend on tricking a user into visiting a compromised or attacker-controlled page while logged into their WordPress site.
- CVE-2026-23697HIGH 8.8
Vtiger CRM versions before 8.4.0 allow authenticated users with basic access rights to upload malicious files that execute as code on the server. An attacker first logs in as a low-privileged user, then uses the Documents module to upload a specially crafted .phar file containing PHP code. Because Vtiger's file-type blocklist doesn't include .phar, the upload succeeds. The file lands in a web-accessible folder where a misconfigured Apache security rule fails to block it, enabling anyone to trigger the malicious code remotely without authentication.
- CVE-2026-2398HIGH 8.8
A security flaw in Adam Retail Automation Ltd.'s MobilMen 20T point-of-sale system allows authenticated users to bypass authorization controls and escalate their privileges. An attacker with valid login credentials could exploit a user-controlled key mechanism to gain elevated access, potentially compromising sensitive retail data, transaction records, or system administration functions. The vulnerability affects versions 3 through 10072026 of the software.
- CVE-2026-25268HIGH 8.8
A memory corruption vulnerability exists in multiple Qualcomm wireless chipsets and firmware when they process invalid 40 MHz channel (HT40) configurations during dynamic channel switching. An attacker with local access could exploit this flaw to corrupt memory, potentially gaining elevated privileges or crashing the system. The vulnerability affects a wide range of Qualcomm networking and wireless components used in routers, access points, fixed wireless gateways, and embedded systems.
- CVE-2026-25559HIGH 8.8
OpenBullet2 versions up to 0.3.2 contain a critical file manipulation flaw that lets authenticated users read, write, and delete arbitrary files on the system. An attacker with valid credentials can exploit this to modify or delete system files, potentially gaining complete control of the host. The risk is particularly severe because OpenBullet2 typically runs with root privileges, meaning any file manipulation has system-wide impact.
- CVE-2026-25707HIGH 8.8
libzypp, the package management library used by openSUSE systems, contains a flaw in how it processes repository metadata that could allow an attacker to trick a user into downloading a malicious repository. When this happens, files anywhere on the system can be overwritten, potentially crashing the system or gaining administrative control. The vulnerability requires user interaction—someone must add or update a repository—but once triggered, the impact is severe.
- CVE-2026-25855HIGH 8.8
OpenBullet2 versions up to 0.3.2 contain a critical flaw that allows logged-in users to run arbitrary commands on servers hosting the application. By uploading malicious script files through the FileProxySource feature—which is meant to load proxy configurations—attackers can trick the server into executing those scripts. The server then processes the output and returns it as proxy data, effectively giving the attacker command-line control over the machine running OpenBullet2. This vulnerability requires prior authentication but poses severe risk once an attacker gains initial access.
- CVE-2026-25856HIGH 8.8
OpenBullet2 through version 0.3.2 allows authenticated users to execute arbitrary code on the hosting server. An attacker with valid credentials can modify job configurations to inject and run C# code, gaining the ability to read files, launch programs, and call any .NET function available to the application process. This is a post-authentication vulnerability, meaning the attacker must already have login access.
- CVE-2026-27060HIGH 8.8
ARMember Premium versions before 7.6 contain a deserialization vulnerability that allows authenticated users to inject malicious objects into the application. An attacker with valid login credentials can exploit this flaw to execute arbitrary code, access sensitive data, or disrupt service availability. The vulnerability requires authentication but poses significant risk because it grants full system compromise once exploited.
- CVE-2026-27775HIGH 8.8
Gitea 1.25.5 contains a privilege-escalation flaw in how it manages write permissions during git operations. When a user with limited write access to a specific branch executes a push, Gitea incorrectly caches their permission level and reuses it for all other branches and refs in the same operation. An attacker with per-branch maintainer permissions can exploit this to gain full repository write access, potentially modifying code, deleting branches, or corrupting the entire repository.
- CVE-2026-27957HIGH 8.8
Coolify, an open-source platform for managing servers and applications, contains a command injection flaw in its certificate management feature that allows any authenticated user to run arbitrary system commands on managed servers. Because Coolify typically runs with elevated privileges (root or docker group membership), successful exploitation grants complete control over the server and all its containerized applications. The vulnerability affects all versions before 4.0.0-beta.464.
- CVE-2026-30650HIGH 8.8
A remote code execution flaw exists in Vivotek FD8136 network cameras that allows an authenticated attacker to take complete control of the device. The vulnerability resides in the admin interface's event task handler and can be exploited over the network without user interaction, enabling an attacker with valid credentials to execute arbitrary commands with root-level privileges.
- CVE-2026-30652HIGH 8.8
A buffer overflow flaw in Vivotek FD8136 network cameras allows authenticated users with admin access to run malicious code with root-level privileges on the device. The vulnerability exists in a specific administrative interface endpoint and affects cameras running firmware version FD8136-VVTK-0300a. An attacker would need valid credentials to exploit it, but once inside the admin panel, they could completely compromise the camera and potentially use it as a foothold into your network.
- CVE-2026-32193HIGH 8.8
Microsoft Azure Kubernetes Service contains a path traversal vulnerability that allows an authorized user to escape intended directory restrictions and execute code on the host system. Because the attacker must already have legitimate access to the cluster, this is a privilege escalation risk rather than an unauthenticated attack vector. The flaw lets someone with basic user permissions potentially gain broader control over the infrastructure.
- CVE-2026-32208HIGH 8.8
A cross-site scripting (XSS) vulnerability in Microsoft Entra ID permits an authenticated attacker to inject malicious scripts into web pages viewed by other users. The vulnerability requires the attacker to already have valid credentials, but once exploited, allows them to spoof content, steal session tokens, redirect users, or perform actions on behalf of victims without additional interaction required from those victims.
- CVE-2026-32833HIGH 8.8
The Cudy LT300 router running firmware versions before 2.5.12 contains a command injection flaw in its time-configuration interface. An attacker who has gained valid credentials to the device can inject shell commands through the NTP settings, allowing them to execute arbitrary code with system privileges. This transforms a low-barrier authenticated access point into a full device compromise.
- CVE-2026-33760HIGH 8.8
Langflow, a platform for building AI workflows and agents, contains a critical authorization flaw in its monitoring API. Any logged-in user can read, modify, or delete another user's data—including chat messages, workflow sessions, build artifacts, and LLM logs—simply by knowing or guessing the target user's resource identifiers. The vulnerability affects seven API endpoints that fail to verify ownership before granting access, a pattern known as broken object-level authorization (BOLA). While the codebase demonstrates that correct ownership checks are technically feasible (one endpoint implements them properly), the pattern was not consistently applied, leaving six others vulnerable. This flaw was introduced well before version 1.9.0 and is patched in that release.
- CVE-2026-34034HIGH 8.8
Coolify, a popular open-source platform for managing servers, applications, and databases, contains a command injection vulnerability in how it handles the Sentinel token setting. An authenticated user with access to server Sentinel configuration can inject malicious shell commands that execute with full privileges on the host system when Sentinel restarts. The vulnerability affects all versions prior to 4.0.0-beta.466 and requires both authentication and access to Sentinel settings, but poses a significant risk to self-hosted deployments where administrators may grant broad access to trusted team members.
- CVE-2026-34035HIGH 8.8
Coolify, an open-source platform for managing servers and applications, contains a command injection vulnerability in its log drain feature. Authenticated users can inject arbitrary shell commands by manipulating log drain secrets and environment variables, which are not properly encoded before being executed on the host system. This affects all versions before 4.0.0-beta.466. An attacker with valid Coolify credentials can achieve full compromise of the underlying server.
- CVE-2026-34057HIGH 8.8
Coolify, a self-hosted application deployment and infrastructure management platform, contains a command injection vulnerability in its database import feature. An authenticated user can inject arbitrary shell commands by manipulating the container name during database import operations, potentially gaining full control over the underlying system. The vulnerability exists because user-supplied input is passed directly to shell commands without sanitization or validation. This has been fixed in version 4.0.0-beta.471.
- CVE-2026-34058HIGH 8.8
Coolify, an open-source server and application management platform, contains a command injection vulnerability in its web interface that allows authenticated users to execute arbitrary system commands on managed servers. The vulnerability exists in the Server Resources component where user-supplied container IDs are passed directly into SSH commands without proper validation. Any team member with access to Coolify can exploit this to run unauthorized commands with the privileges of the Coolify service account on remote systems. This is fixed in version 4.0.0-beta.471.