2026 · Medium
Medium-severity vulnerabilities disclosed in 2026
Medium-rated CVEs published in 2026, with SEC.co remediation and prioritization guidance.
4010 published vulnerabilities · page 17 of 41
- CVE-2026-8658MEDIUM 6.0
A command injection flaw in Rapid7's InsightConnect Tcpdump Plugin allows authenticated users with high-level privileges to run arbitrary system commands on Linux servers. The vulnerability exists because user-supplied options and filter parameters aren't properly sanitized before being passed to shell commands. An attacker with administrative or equivalent access to InsightConnect could exploit this to execute malicious code with the privileges of the plugin process.
- CVE-2026-8659MEDIUM 6.0
A security flaw in Rapid7 InsightConnect's SQLmap plugin allows authenticated users with administrative privileges to run arbitrary commands on affected Linux systems. The vulnerability exists in how the plugin processes connection configuration parameters—specifically the api_host and api_port fields—without properly validating or sanitizing the input. An attacker with legitimate access to the InsightConnect platform could exploit this to execute unintended system commands on the underlying Linux host, potentially compromising system integrity or confidentiality.
- CVE-2026-8663MEDIUM 6.0
A flaw in Rapid7's InsightConnect RPM Plugin for Linux allows authenticated users to run arbitrary commands on affected systems. The vulnerability stems from the plugin's failure to properly sanitize user input when constructing shell commands—specifically in how it handles repository names, package keys, and package names. An attacker with valid credentials could exploit this to execute unauthorized operating system commands, potentially compromising system integrity or accessing sensitive data.
- CVE-2026-8664MEDIUM 6.0
A command injection flaw in the Rapid7 InsightConnect Finger Plugin allows authenticated users with high privileges to inject arbitrary operating system commands through the user or host input fields. An attacker with admin or elevated access could exploit insufficient input validation to execute unauthorized commands on the underlying Linux system, potentially compromising system integrity or accessing sensitive data.
- CVE-2017-20240MEDIUM 5.9
Crypt::PBKDF2, a Perl cryptographic library used to derive secure keys from passwords, contains a timing-based side-channel vulnerability in versions before 0.261630. The library uses a simple string comparison (eq) to verify derived keys, which executes at different speeds depending on how many characters match between the input and the correct value. An attacker on the network can measure these timing differences to gradually narrow down the correct key without needing the password itself.
- CVE-2023-52951MEDIUM 5.9
Synology Note Station Client versions before 2.2.4-703 transmit user credentials in cleartext over the network, allowing attackers positioned to intercept traffic—such as those on the same Wi-Fi network or controlling network infrastructure—to capture login credentials. This is a network-based credential theft vulnerability that does not require authentication or user interaction to exploit, though the attacker must be able to intercept the specific traffic.
- CVE-2023-5502MEDIUM 5.9
Arista EOS devices configured with 802.1x authentication on network access ports have a weakness that allows a malicious user to bypass the authentication requirement under specific conditions. The vulnerability exists when 802.1x is enabled on access or trunk ports and routing is enabled on the access VLAN. An attacker could potentially gain network access without providing valid authentication credentials, though exploitation requires specific network configuration and circumstances to be in place.
- CVE-2025-12530MEDIUM 5.9
IBM watsonx.data intelligence versions 5.2.2, 5.3.0, 5.3.1, and 5.3.1 through Patch 1 transmit sensitive data over unencrypted channels. An attacker positioned to intercept network traffic—such as on a shared network segment or through DNS/routing manipulation—could eavesdrop on communications and extract confidential information. This is a classic man-in-the-middle (MITM) vulnerability where encryption is either absent or improperly configured.
- CVE-2025-36336MEDIUM 5.9
IBM watsonx.data intelligence versions 5.2.0 through 5.3.0 transmit sensitive data without encryption, exposing it to interception by attackers positioned on the network path between clients and servers. An attacker could eavesdrop on this unencrypted traffic to steal confidential information. The vulnerability requires specific network conditions (high complexity attack) but affects a data intelligence platform where confidentiality breaches carry real business risk.
- CVE-2026-0061MEDIUM 5.9
CVE-2026-0061 is a privilege escalation vulnerability in Android's WindowState component that allows an attacker to manipulate the permission-granting UI through overlay attacks (tapjacking). By displaying a malicious overlay on top of the system permission dialog, an attacker can trick users into granting sensitive permissions without explicit awareness. The critical aspect is that this requires no special execution privileges and no user interaction in the traditional sense—the attack succeeds through visual deception rather than social engineering or code execution exploits.
- CVE-2026-0075MEDIUM 5.9
CVE-2026-0075 is a SQL injection vulnerability in Google Android's contact database access functions that allows local attackers to escalate privileges without needing special permissions or user interaction. An attacker with local access to an Android device can exploit this flaw to read, modify, or delete contact information and potentially gain elevated system privileges.
- CVE-2026-0277MEDIUM 5.9
CVE-2026-0277 is a certificate validation flaw in Palo Alto Networks' Prisma Access Agent for iOS that allows an attacker positioned on the network to intercept and potentially manipulate VPN traffic. Because the iOS agent fails to properly validate SSL/TLS certificates, an attacker can impersonate legitimate VPN endpoints and decrypt traffic, compromising the confidentiality of data meant to be protected by the VPN. The vulnerability requires network positioning (such as on a shared Wi-Fi network or compromised network infrastructure) but no user interaction or authentication. Windows, macOS, Linux, Android, and ChromeOS variants of the Prisma Access Agent are not vulnerable.
- CVE-2026-0420MEDIUM 5.9
NETGEAR's ReadyCloud client application contains a flaw in how it validates TLS certificates, the security handshakes that protect encrypted connections. An attacker positioned on the network path between a user and NETGEAR's servers could intercept and read sensitive data transmitted by the app—such as account credentials or cloud sync information—without being detected. The vulnerability requires specific network conditions to exploit but poses a real confidentiality risk for users relying on ReadyCloud for remote device management.
- CVE-2026-10584MEDIUM 5.9
Graph Explorer versions prior to 3.0.1 contain a flaw in their proxy server that causes HTTPS connections to silently downgrade to unencrypted HTTP when certificate files are unavailable. An attacker positioned to intercept network traffic could potentially eavesdrop on sensitive information that was intended to be transmitted securely. This is a configuration-dependent issue—the vulnerability manifests only when certificates are missing—but the silent fallback behavior makes it particularly insidious because applications may not explicitly warn users that encryption has been disabled.
- CVE-2026-10637MEDIUM 5.9
A vulnerability in Zephyr's IPv6 multicast listener discovery (MLD) implementation allows a remote attacker on the local network to crash the networking stack by sending specially crafted MLD queries. The flaw stems from the code attempting to read and modify packet metadata after the packet has been freed by the network driver, creating a use-after-free condition. An attacker can trigger this without authentication by sending a valid MLDv2 General Query to the device, reliably causing a denial of service.
- CVE-2026-10638MEDIUM 5.9
A use-after-free vulnerability exists in Zephyr's ICMPv6 network stack. When the kernel sends an ICMPv6 response (such as a reply to a ping or an error message), it tries to update statistics using a packet pointer after that packet has already been freed and returned to memory. An attacker on the network can trigger this by sending a simple ICMPv6 Echo Request or crafting packets that cause IPv6 errors, causing the device to crash or potentially corrupt memory. The flaw affects Zephyr versions roughly 4.2.0 through 4.4.0 when IPv6 networking is enabled.
- CVE-2026-10852MEDIUM 5.9
IBM WebSphere Application Server and WebSphere Application Server Liberty contain a denial-of-service vulnerability in their WebServer Plug-in component. An attacker who can send specially crafted requests to a web server running this software can cause it to become unavailable or unresponsive. The vulnerability does not allow unauthorized access to data or system compromise—it is purely an availability impact. Exploitation requires network access but no special privileges or user interaction.
- CVE-2026-11199MEDIUM 5.9
Google Chrome versions before 149.0.7827.53 contain a flaw in how WebRTC handles network traffic that could allow an attacker positioned on the same network to steal sensitive information across website boundaries. The vulnerability requires the attacker to be in a privileged network position—such as on a shared Wi-Fi network or controlling network infrastructure—but does not require user interaction or special permissions. The risk is limited to information disclosure; the flaw cannot be used to modify data or crash the browser.
- CVE-2026-11238MEDIUM 5.9
Google Chrome versions before 149.0.7827.53 contain a flaw in how DevTools handles extension interactions that could allow an attacker to extract sensitive data from process memory. The attack requires social engineering—convincing a user to install a malicious Chrome extension—but if successful, an attacker gains access to potentially confidential information stored in memory that the extension can observe. This is classified as a medium-severity issue despite Chromium's internal 'Low' rating, reflecting the real-world impact of memory disclosure combined with the user-interaction barrier.
- CVE-2026-11581MEDIUM 5.9
Kali Forms, a WordPress plugin for building contact forms, contains a stored cross-site scripting (XSS) vulnerability in versions before 2.4.13. Contributors and higher-privileged users can inject malicious JavaScript into form field captions, which then executes when administrators view the form entries list. A second weakness in the plugin's duplication feature allows Contributors to publish forms without proper authorization, enabling them to distribute the malicious form to trigger the XSS in an administrator's browser session.
- CVE-2026-11788MEDIUM 5.9
A vulnerability exists in 389 Directory Server where the dereference control plugin fails to verify that memory allocation succeeded before proceeding. An attacker on the network can trigger memory exhaustion conditions to crash the LDAP server without providing credentials. The attack requires specific environmental conditions (system memory pressure) to succeed, but no authentication is required.
- CVE-2026-12352MEDIUM 5.9
CVE-2026-12352 is a medium-severity authentication bypass vulnerability that allows an attacker to gain access to restricted resources on a device without providing valid credentials. The attacker does not need to be an authenticated user to exploit this flaw, and no user interaction is required. While the vulnerability does not allow attackers to modify or disable systems, it does expose sensitive information to unauthorized parties.
- CVE-2026-12725MEDIUM 5.9
A flaw in dnsmasq allows a remote attacker to crash the DNS service by sending specially crafted DNS responses. The vulnerability only triggers when two features are active together: DNSSEC validation (which verifies DNS record authenticity) and query logging (which records DNS requests and responses). When these conditions are met, responses containing unsupported algorithm types cause dnsmasq to overflow an internal memory buffer, terminating the process. This results in denial of service—your DNS resolution stops working until the service is restarted.
- CVE-2026-14062MEDIUM 5.9
Google Chrome and ChromeOS have a weakness in how they handle certain view operations that could let an attacker steal sensitive data from your computer's memory. The attack requires two things: you'd need to install a malicious extension (add-on), and the attacker would craft that extension specifically to read data from Chrome's internal memory. This is a medium-severity issue because while memory access is serious, it requires social engineering to get you to install the extension first.
- CVE-2026-14160MEDIUM 5.9
Samsung's Escargot JavaScript engine contains a race condition vulnerability that creates a window of opportunity between when the software checks a condition and when it acts on that check. An attacker with local access could exploit this timing gap to change file or resource attributes after the initial permission check but before the actual use, potentially bypassing security controls. The vulnerability is classified as medium severity and requires local access to exploit.
- CVE-2026-14178MEDIUM 5.9
A memory safety issue exists in openGauss when processing timestamp conversion functions with locale (NLS) parameters. Specifically, when `to_timestamp()` is called with an NLS format parameter, the database stores formatting information in memory that gets freed after query execution. However, during result output, the code tries to access this already-freed memory, which can cause the database backend process to crash. An attacker with SQL execution privileges can deliberately construct such queries to trigger this crash repeatedly, leading to denial of service. The vulnerability affects RC releases 7.0.0-RC1 and 7.0.0-RC2 and has been fixed in 7.0.0-RC3 and later versions.
- CVE-2026-14406MEDIUM 5.9
A flaw in Chrome's V8 JavaScript engine allows an out-of-bounds memory read when a malicious browser extension executes. An attacker would first need to trick a user into installing a malicious extension, then use it to read sensitive data directly from the browser's memory. This is classified as a medium-severity issue because it requires social engineering to deliver the extension, but once installed, it can expose potentially sensitive information without further user interaction.
- CVE-2026-15289MEDIUM 5.9
The Booking calendar and Appointment Booking System plugin for WordPress contains a SQL injection flaw that allows unauthenticated attackers to inject malicious SQL commands. The vulnerability exists because the plugin fails to properly sanitize user input in the 'wpdevart_id' parameter. Exploitation requires the Pro version of the plugin to be installed with a specific setting ('Delete previous dates') enabled. If successfully exploited, an attacker can extract sensitive data from the WordPress database without authentication.
- CVE-2026-2379MEDIUM 5.9
Arista EOS devices with hardware-accelerated IPSec support may experience communication instability when physical network interfaces go down or certain system components restart. During these events, IPSec tunnels re-establish, but sequence numbering can become misaligned between the two endpoints of the tunnel. This mismatch can cause packets to be rejected or processed out of order, leading to dropped connections or degraded tunnel performance. The vulnerability requires network access to trigger but does not involve packet inspection or authentication bypass.
- CVE-2026-24266MEDIUM 5.9
NVIDIA's Triton Inference Server for Linux contains a use-after-free vulnerability that allows attackers to disrupt service availability. The flaw exists in memory management logic, where freed memory is accessed again, potentially causing the application to crash. While the attack requires specific network conditions to exploit reliably, the impact is limited to denial of service rather than data theft or system compromise.
- CVE-2026-25861MEDIUM 5.9
QloApps versions through 1.7.0 use MD5 to hash passwords, a cryptographic method that is computationally cheap to crack. The vulnerability is particularly severe because QloApps concatenates a static value (a cookie key) with user passwords before hashing, reducing the effective randomness of the hash. When guest accounts are automatically converted to customer accounts, the system assigns simple 8-character passwords, which are trivially recoverable through offline brute-force attacks. An attacker who gains access to the password database can extract user credentials without needing to interact with the application in real time.
- CVE-2026-28116MEDIUM 5.9
Emilia Projects Progress Planner versions 1.9.0 and earlier contain a stored cross-site scripting (XSS) vulnerability that allows authenticated administrators to inject malicious scripts into the application. When other users view affected pages, the injected code executes in their browsers, potentially enabling session hijacking, credential theft, or further lateral movement within the application environment.
- CVE-2026-31981MEDIUM 5.9
A stored HTML injection vulnerability in Nozomi Networks CMC and Guardian allows authenticated administrators to inject malicious HTML into configuration data. When other users view the affected data in the Diagram tab or Graph view, the injected HTML renders in their browsers. This can be used to conduct phishing attacks or redirect users to malicious sites. The vulnerability requires administrative access to exploit and user interaction (viewing the affected data) to trigger, limiting its scope but still warranting remediation in environments where admin accounts may be compromised or insider threats are a concern.
- CVE-2026-33794MEDIUM 5.9
Juniper Networks Junos OS Evolved on PTX Series routers contain a flaw in how they process routing updates that create unified-list ECMP (equal-cost multipath) routes. An unauthenticated attacker on the network can send specially crafted, continuous routing updates that trigger an unchecked condition in the evo-aftmand process running on the Packet Forwarding Engine (PFE). This causes internal state corruption and crashes the process, forcing the router offline or requiring manual intervention to recover. The attack depends on a sequence of network conditions outside the attacker's direct control, but represents a denial-of-service risk for affected PTX platforms.
- CVE-2026-36610MEDIUM 5.9
Mercusys AC12G (EU) V1 routers with firmware version AC12G(EU)_V1_200909 transmit Dynamic DNS (DDNS) credentials using only Base64 encoding over unencrypted HTTP connections. Base64 is not encryption—it's merely encoding and can be trivially decoded by anyone observing network traffic. Because the firmware lacks TLS/SSL support entirely, an attacker positioned on the network path can intercept and recover DDNS service credentials, potentially compromising the domain name update service tied to the affected router.
- CVE-2026-36616MEDIUM 5.9
Mercusys AC12G (EU) V1 routers contain hardcoded credentials baked directly into the firmware. A researcher can extract a WiFi driver password, RADIUS shared secret, WPS test key, and default network password from the device's production binary. This allows someone with network access to bypass WiFi protections and potentially reach internal network resources, though the attack requires being within radio range and some technical effort to extract and use these credentials.
- CVE-2026-40991MEDIUM 5.9
Spring REST Docs, a popular documentation tool used by developers to generate API documentation from tests, contains an XML External Entity (XXE) injection vulnerability when documenting remote APIs over HTTP. An attacker who gains control of an API being documented—or convinces a developer to document a malicious API—can inject malicious XML that executes during the documentation-generation process. The attack requires the developer to actively run their documentation tests, making social engineering or API compromise the likely attack vector.
- CVE-2026-41017MEDIUM 5.9
Apache Airflow's JWT authentication middleware fails to mark session cookies as secure, exposing them to interception when the API server sits behind a TLS-terminating reverse proxy—a standard cloud architecture. An attacker on a shared network (public Wi-Fi, compromised LAN, or captive portal) can intercept an authenticated user's session token and replay it to gain API access. The vulnerability only materializes in specific deployment topologies where the reverse proxy strips HTTPS before forwarding to Airflow; teams running Airflow with end-to-end encryption or without reverse proxies are not affected. Apache Airflow 3.2.2 and later patch this issue.
- CVE-2026-41696MEDIUM 5.9
Spring Data MongoDB, a widely-used persistence framework for MongoDB, contains a query injection vulnerability affecting multiple versions. When developers use the @Query annotation with regex parameter binding, the framework fails to properly validate user-supplied input. This allows an attacker to craft a malicious string that escapes the intended regex boundaries and inject arbitrary queries. The vulnerability does not currently appear on the CISA KEV catalog, but the broad version range affected and the sensitive nature of database queries make it a meaningful risk for organizations relying on Spring Data MongoDB.
- CVE-2026-41710MEDIUM 5.9
Spring Retry, a popular Java retry library used across enterprise applications, contains a vulnerability that allows attackers to disable the retry and circuit-breaker mechanisms that applications depend on for resilience. By sending many crafted requests designed to fail, an attacker can fill the application's retry cache until it stops accepting new entries. Once saturated, the cache becomes permanently unable to process any further retries or circuit-breaker decisions, effectively breaking the fault-tolerance layer of affected applications.
- CVE-2026-41711MEDIUM 5.9
Spring Data Commons, a widely-used data access library in the Spring ecosystem, contains a flaw in how it processes Sort parameters. An attacker can craft malicious Sort requests that cause applications to exhaust stack memory, crashing the service. This is a network-accessible denial-of-service vulnerability that requires no authentication or user interaction—any exposed endpoint accepting Sort parameters becomes an attack surface.
- CVE-2026-41721MEDIUM 5.9
Spring Data Commons, a widely-used data access abstraction framework, contains a vulnerability that enables remote denial-of-service attacks. When Spring Data Web Support is enabled and a controller uses the @ProjectedPayload annotation, attackers can craft specific HTTP requests that force the application to consume excessive memory, degrading or halting service availability. The vulnerability requires specific configuration conditions to be present, limiting its immediate exposure but posing real risk to affected deployments.
- CVE-2026-41840MEDIUM 5.9
Spring WebFlux applications running affected versions of Spring Framework contain a denial-of-service vulnerability triggered by specially crafted multipart requests. An unauthenticated remote attacker can exploit this to disrupt application availability without requiring special network access or user interaction. The vulnerability affects a wide range of Spring Framework versions spanning multiple release lines, making it broadly relevant to organizations using Spring-based web services.
- CVE-2026-41841MEDIUM 5.9
Spring MVC and WebFlux applications contain a vulnerability that can leak sensitive information through improper handling of static resource requests. An attacker can craft requests to bypass normal access controls and read files that should be protected, though successful exploitation requires specific conditions. The vulnerability affects multiple Spring Framework versions across several release lines.
- CVE-2026-41843MEDIUM 5.9
Spring Framework applications that serve static resources through MVC or WebFlux are vulnerable to path traversal attacks. An attacker can craft malicious requests to access files outside the intended static resource directory, potentially reading sensitive configuration files, source code, or other protected assets. This vulnerability affects multiple recent versions of Spring Framework across all actively maintained branches.
- CVE-2026-41846MEDIUM 5.9
Spring Framework contains a reflected cross-site scripting (XSS) vulnerability in its JSP form tag library. When developers use Spring MVC form tags and bind user-supplied input to the cssClass, cssErrorClass, or cssStyle attributes without proper sanitization, an attacker can inject malicious HTML and JavaScript code. This code executes in the victim's browser when they view the affected page, potentially allowing credential theft, session hijacking, or other client-side attacks. The vulnerability requires user interaction (such as clicking a malicious link) to trigger.
- CVE-2026-41973MEDIUM 5.9
CVE-2026-41973 is a permission control vulnerability affecting the calls functionality in an unspecified application. An attacker with local access to a system can exploit insufficient permission checks to read sensitive information, modify data, or disrupt service availability. The vulnerability requires no special privileges or user interaction to trigger, making it a concern for systems where local access controls are weak or where multiple users share the same machine.
- CVE-2026-42387MEDIUM 5.9
A vulnerability in DNS recursors allows a malicious authoritative nameserver to crash the resolver by sending a specially crafted zone file. The attack requires the recursor to process the zone through its caching mechanism, but lacks proper validation of the input, triggering a denial-of-service condition. An attacker would need to control or compromise an authoritative nameserver in the DNS hierarchy to exploit this.
- CVE-2026-42388MEDIUM 5.9
A vulnerability exists in how certain DNS systems validate SOA (Start of Authority) records within catalog zones. When an SOA record is not properly validated, it can cause the affected system to crash. This is a network-accessible issue that does not require authentication, though successful exploitation depends on specific conditions being in place. The crash results in a denial of service rather than data exposure or system compromise.
- CVE-2026-42655MEDIUM 5.9
A flaw in the Best Payments Plugin for WordPress (versions 4.6.19 and earlier) allows attackers to bypass authentication checks without providing valid credentials. The vulnerability is rated medium severity because while it enables unauthorized actions, the conditions required to exploit it are somewhat restricted, and it does not directly expose sensitive data or cause system unavailability. Organizations using affected versions should prioritize patching, particularly if the plugin processes payment data or integrates with payment gateways.
- CVE-2026-42766MEDIUM 5.9
A flaw in OpenSSL's CMS (Cryptographic Message Syntax) password decryption logic allows an attacker to crash applications by sending specially crafted encrypted messages. The vulnerability stems from the code not properly checking whether an optional field exists before using it, resulting in a null pointer crash and service disruption.
- CVE-2026-42767MEDIUM 5.9
An OpenSSL vulnerability allows an attacker controlling or intercepting CMP (Certificate Management Protocol) traffic to crash client applications by sending a specially crafted certificate response. The attack exploits a code defect where OpenSSL fails to properly validate a specific field in the response, causing the application to crash and become unavailable. This is a denial-of-service issue, not a data breach or unauthorized access risk.
- CVE-2026-43625MEDIUM 5.9
CodexBar versions before 0.32.0 have a vulnerability where session cookies imported from your browser can be intercepted over the network. When CodexBar redirects requests to Amp or Ollama providers, attackers positioned on your network path can capture these cookies if the redirect sends them over unencrypted HTTP. This requires the attacker to be on the network between you and the provider, but the leaked cookies could grant them access to your sessions on those services.
- CVE-2026-44733MEDIUM 5.9
OpenProject, a widely-used open-source project management platform, contains a password validation flaw that allows an attacker with an active session to change another user's password without proper authorization. The vulnerability exists in how the application handles PATCH requests to the password change API endpoint. An attacker who has already compromised a user's session can exploit this to take over that account by resetting the password, effectively locking out the legitimate user. The flaw has been patched in versions 17.3.2 and 17.4.0.
- CVE-2026-45680MEDIUM 5.9
OpenTelemetry eBPF Instrumentation versions prior to 0.9.0 contain a performance degradation vulnerability in their metrics collection pipeline. When systems experience high activity, the instrumentation replays recorded probe hits by iterating once per run count. On busy infrastructure, this run-count delta can grow very large, forcing the metrics exporter into a computationally expensive tight loop during each collection interval. The result is excessive CPU consumption that can degrade system performance. This is a denial-of-service condition rather than a confidentiality or integrity breach, but it directly impacts availability and operational efficiency.
- CVE-2026-45681MEDIUM 5.9
OpenTelemetry eBPF Instrumentation versions prior to 0.9.0 contain a memory disclosure vulnerability triggered by CPU scheduling mismatches. When the instrumentation falls back to a 256-byte buffer but retains the original payload size marker (up to 8KB), a mismatch between CPUs can cause the code to read memory beyond the buffer boundary. This leaked memory is inadvertently captured and exported as telemetry data, potentially exposing sensitive information from adjacent kernel memory to anyone consuming the telemetry stream.
- CVE-2026-45690MEDIUM 5.9
Nextcloud Server contains an authentication bypass flaw that lets attackers with a valid password defeat two-factor authentication (2FA). During login, the system temporarily grants a session token before asking for the second factor. An attacker who intercepts this token can replay it using HTTP Basic Authentication to access the account without providing the 2FA code. This affects Nextcloud Server versions 32.0.0 through 32.0.8 and 33.0.0 through 33.0.2, as well as older Enterprise Server branches. The vulnerability requires knowledge of the user's password, limiting opportunistic exploitation but creating a material risk for password-compromised accounts.
- CVE-2026-45691MEDIUM 5.9
Nextcloud Server contains a session management flaw that allows attackers to bypass two-factor authentication (2FA). When a user logs in with their password but hasn't completed TOTP verification yet, a temporary session cookie is created. An attacker with legitimate credentials can capture or reuse this intermediate cookie as a Bearer token to directly access file storage endpoints (DAV), gaining unauthorized read and write access while completely circumventing the mandatory 2FA requirement. This affects Nextcloud Server versions 32.0.0–32.0.8 and 33.0.0–33.0.2, as well as several Enterprise Server releases.
- CVE-2026-46538MEDIUM 5.9
Microsoft UFO is an open-source automation framework that lets multiple devices work together on tasks. In version 3.0.1-4-ge2626659, it has a flaw where one authenticated device can trick another device by sending a fake task completion message. When Device A receives a task from the coordinator, the system should only accept a completion message from Device A itself. Instead, the system accepts completion messages from any authenticated device as long as they use the same task ID. An attacker with legitimate access to the network can exploit this to inject false results into another device's task, potentially disrupting automated workflows.
- CVE-2026-46539MEDIUM 5.9
Nimiq, a blockchain platform built on Rust, contains a flaw in how it verifies that transactions are genuinely included in a block. Under specific conditions—when checking a block at a particular position in the blockchain—the verification code skips its cryptographic checks entirely and simply approves the block as valid. An attacker could exploit this to forge fake block headers that would be accepted by the network without proper authentication, potentially allowing invalid transactions to be recorded on the blockchain.
- CVE-2026-47205MEDIUM 5.9
Envoy, a widely-deployed open source proxy for cloud-native infrastructure, contains a use-after-free defect in its authorization filter that can cause the proxy to crash. The vulnerability occurs when a request uses dynamic per-route authorization settings and the client connection closes very quickly—such as when a user rapidly refreshes a WebSocket connection to a protected endpoint. Under these conditions, Envoy's internal authorization tracking becomes corrupted, leading to a segmentation fault that terminates the affected proxy instance. This flaw affects Envoy versions 1.36.0 through 1.36.8, 1.37.0 through 1.37.4, and 1.38.0 through 1.38.2.
- CVE-2026-47221MEDIUM 5.9
Envoy, a widely-deployed open source proxy for cloud-native applications, contains a crash vulnerability in its HTTP request routing logic. When an HTTP 303 redirect response is received on certain types of requests (POST, PUT, DELETE, PATCH without a body), Envoy attempts to process a non-existent request body, causing the entire proxy process to crash. An attacker can trigger this by sending a simple HTTP request to a vulnerable Envoy instance that is configured to handle 303 redirects internally. The result is immediate denial of service—all connections through that Envoy instance terminate. This affects versions from 1.18.0 through several recent releases, though patches are available.
- CVE-2026-47741MEDIUM 5.9
Shopper, a headless e-commerce admin panel, had a race condition in its checkout process that allowed customers to bypass discount usage limits during high-concurrency periods like Black Friday or flash sales. The system would apply a discount to an order and save it to the database before verifying whether that discount had already been used up. If multiple customers checked out simultaneously with the same coupon, the system would grant the discount to all of them even after the coupon's limit was exceeded, because the counter-increment happened too late in the process. Merchants would not receive any warning that over-redemption had occurred, leading to undetected revenue loss.
- CVE-2026-48090MEDIUM 5.9
Envoy, a widely-deployed service proxy for containerized environments, contains a memory-safety bug in its OAuth2 filter that can crash worker processes when handling concurrent token exchanges. The vulnerability occurs when an asynchronous token-verification operation completes after the downstream connection it serves has already closed, causing the filter code to access memory that is no longer valid. An attacker can trigger this condition remotely without authentication, leading to denial of service. The issue does not enable code execution but degrades service availability.
- CVE-2026-48497MEDIUM 5.9
Envoy, a widely-used proxy for cloud-native applications, has a flaw in its DNS filtering that crashes the process when handling domain names of exactly 255 characters. While DNS standards allow names up to 255 octets, Envoy incorrectly requires them to be strictly shorter, causing abnormal termination when this limit is met. This affects both local and remote DNS resolution configurations. The issue is resolved in patched versions across all affected release branches.
- CVE-2026-48613MEDIUM 5.9
A SQL injection flaw exists in phpBB's profile field migration process. When forums upgrade from older versions, user-supplied profile field data is not properly validated before being used in database queries. An authenticated attacker with specific interaction conditions could craft malicious input to execute arbitrary SQL commands, potentially exposing or modifying forum data. The vulnerability affects only forums that upgraded from versions before 3.3.8 but have not yet reached version 3.3.11 or later.
- CVE-2026-48681MEDIUM 5.9
OpenStack Ironic, a bare-metal provisioning service, contains a directory traversal vulnerability that allows authenticated administrators to overwrite arbitrary files on the system during deployment when using a specially crafted ISO image. An attacker with high-level privileges can exploit this during the boot image creation process to alter critical system files or configuration, potentially compromising the integrity of deployed infrastructure.
- CVE-2026-48682MEDIUM 5.9
FastNetMon Community Edition versions up to 1.2.9 contain a flaw in how it reads and interprets network packet headers. When processing IPv4 packets, the software validates that a packet has at least a minimum header size, but then makes unsafe assumptions about header field values. Specifically, it reads past the actual packet boundary when a packet header contains an unusually large size indicator, or it misinterprets packet data when that indicator is too small. This can cause the software to read memory it shouldn't access or misidentify packet contents, potentially leading to information disclosure or unexpected behavior.
- CVE-2026-48706MEDIUM 5.9
Envoy, a widely-deployed proxy for cloud-native environments, contains a memory overflow vulnerability in its StatsD metrics sink. When Envoy formats statistics—particularly metric names derived from HTTP or gRPC request paths—it uses fixed-size 16 KB buffers. If a request path or other statistic name exceeds this size, the buffer management logic fails to safely handle the overflow, instead writing past allocated memory. An attacker sending requests with extremely long paths could crash the Envoy process or, in theory, execute arbitrary code. This affects Envoy versions 1.34.0 through 1.38.2 and requires an immediate upgrade to patched releases.
- CVE-2026-48994MEDIUM 5.9
ImageMagick, widely used for image processing across web services and automation workflows, contains a flaw in how it handles MAT image files on 32-bit systems. When processing certain MAT files, the software fails to properly validate a function's return value, allowing an attacker to write data past the intended memory boundary. This heap buffer overwrite can crash the application or potentially allow code execution, though the latter is not guaranteed due to the attack complexity required.
- CVE-2026-49267MEDIUM 5.9
Apache Airflow's EmailOperator and email utilities fail to validate the SMTP server's certificate when configured to use STARTTLS encryption without full SSL/TLS. This allows an attacker on the network between your Airflow worker and SMTP server to intercept the connection, inject a fraudulent certificate, and steal login credentials and email contents without detection. The risk is elevated in environments where the SMTP relay sits outside your trusted network perimeter.
- CVE-2026-49270MEDIUM 5.9
Apache ActiveMQ brokers with network connectors configured to sync durable subscriptions are leaking sensitive metadata to unauthenticated attackers. An attacker can request a complete list of durable topic subscriptions, including client IDs, subscription names, destination topics, and JMS selector expressions—all without needing to authenticate. This occurs because the broker responds to BrokerInfo commands before validating the connection's authentication status.
- CVE-2026-49858MEDIUM 5.9
API Platform, a popular open-source framework for building REST and GraphQL APIs, has a security flaw in how it decides what data to show to different users. The vulnerability affects versions 2.6.0 through 4.1.28, 4.2.25, and 4.3.11. When an API endpoint is protected with access rules (defined via #[ApiProperty(security: ...)] annotations), those rules should prevent lower-privileged users from seeing certain sensitive fields. However, due to a caching mechanism that doesn't properly account for per-user security settings, a less-privileged user may see the structure and names of fields they shouldn't have access to—even though they can't read the actual values. This leaks information about what properties exist in your data model that the user wasn't meant to know about.
- CVE-2026-50127MEDIUM 5.9
Weblate, a web-based localization platform, contained a network access control bypass in its VCS_RESTRICT_PRIVATE feature. Between versions 5.15 and before 2026.6, the feature failed to properly recognize certain IPv6 address ranges, IPv4 semi-private ranges, and multicast addresses as restricted. This allowed requests from those network addresses to bypass intended private-range restrictions, potentially enabling unauthorized access to internal resources or services that should have been isolated. The vulnerability has been resolved in version 2026.6.
- CVE-2026-50202MEDIUM 5.9
Steeltoe is a framework that helps developers build cloud-native applications on platforms like Cloud Foundry. A flaw in its JWT authentication libraries allows JWT signing keys to be cached and reused inappropriately. Specifically, when an application uses multiple authentication schemes pointing to different identity providers, a key validated for one provider could be mistakenly accepted for another. Additionally, keys remain cached indefinitely—even after a provider rotates or revokes them—until the application restarts. This creates a window where compromised or expired keys continue to grant access.
- CVE-2026-52690MEDIUM 5.9
A DNS resolver can be tricked into believing that a legitimate authoritative nameserver doesn't support EDNS (Extension Mechanisms for DNS), a protocol feature used to transmit larger DNS responses and security information. An attacker can send spoofed DNS replies that cause the resolver to mark a server as EDNS-incapable. When this happens, DNSSEC validation—the cryptographic mechanism that verifies DNS responses haven't been tampered with—fails for records served by that nameserver. The result is that legitimate, signed DNS records become unusable, disrupting name resolution for domains relying on that server.
- CVE-2026-52714MEDIUM 5.9
Squirrly SEO, a WordPress SEO plugin, contains a flaw that allows unauthenticated attackers to modify content or settings without proper authorization. An attacker does not need login credentials to perform certain privileged actions, bypassing the plugin's access controls. The vulnerability affects versions 12.4.16 and earlier. While the attack requires specific conditions to succeed (reflected in the CVSS score of 5.9), any unauthenticated modification capability represents a meaningful risk to site integrity.
- CVE-2026-53462MEDIUM 5.9
ImageMagick, a widely-used open-source tool for image manipulation, contains a memory safety flaw that can crash applications processing certain malformed images. When the software attempts to allocate memory during image validation and that allocation fails, it may continue to use memory that has already been freed, leading to a denial of service. The issue affects ImageMagick versions prior to 6.9.13-50 (legacy branch) and 7.1.2-25 (current branch).
- CVE-2026-54040MEDIUM 5.9
LibreChat versions before 0.8.4-rc1 contain a flaw in their two-factor authentication (2FA) backup code regeneration process. An attacker who obtains a victim's session token can regenerate that user's 2FA backup codes without needing to verify the user's identity through any authentication method. The attacker can then use the newly generated codes to bypass 2FA entirely or disable it altogether. This is a silent attack—the victim receives no notification that their backup codes have been replaced.
- CVE-2026-54068MEDIUM 5.9
SiYuan, an open-source personal knowledge management system, contains an authentication bypass vulnerability in its icon retrieval API endpoint. The /api/icon/getDynamicIcon endpoint is intentionally excluded from authentication checks but executes server-side Go templates that can query the underlying SQLite database. An attacker without login credentials can exploit this by sending a specially crafted request with a known block ID to extract all of a user's notes, tags, file references, and metadata. The vulnerability affects all versions before 3.7.0 and is resolved in that release.
- CVE-2026-54286MEDIUM 5.9
Hono, a JavaScript web framework, contains a path traversal vulnerability on Windows systems that allows attackers to bypass file access restrictions. When a request contains an encoded backslash (%5C), Windows path resolution converts it to a literal backslash character, which Windows treats as a path separator. This causes Hono's static file serving functionality to interpret a single URL segment as a nested file path, potentially exposing protected files. An attacker can craft requests to read static files that should be restricted by middleware-based access controls. The vulnerability requires specific conditions—Windows hosting and unprotected static file serving—but poses a confidentiality risk. Hono 4.12.25 and later patch this issue.
- CVE-2026-54291MEDIUM 5.9
pgjdbc, the official PostgreSQL JDBC driver, contains a flaw in versions 42.7.4 through 42.7.11 where connections explicitly configured to require channel binding security (channelBinding=require) can be silently downgraded to a weaker authentication method. An attacker positioned to intercept TLS traffic can force this downgrade by presenting a certificate with an unsupported signature algorithm, causing the driver to drop the man-in-the-middle protection that channel binding provides. The vulnerability stems from incomplete validation: the driver checks only that the server advertises a secure mechanism but fails to reject empty or missing channel-binding data. Version 42.7.12 and later fix this issue.
- CVE-2026-54323MEDIUM 5.9
Daytona, a platform for executing AI-generated code and running agent workflows, had a flaw in how it validated TLS certificates when cloning Git repositories. Before version 0.185.0, the daemon would accept any certificate presented by a server, even if it was forged. When a developer provided Git credentials for authentication, those credentials were sent in an HTTP Basic Authorization header over this unvalidated connection. An attacker positioned on the network could intercept the clone request, present a fake certificate, capture the credentials, and inject malicious code into the cloned repository—all transparently from the developer's perspective.
- CVE-2026-54411MEDIUM 5.9
Linux-PAM versions up to 1.7.2 contain a timing-based weakness in the pam_userdb authentication module that allows attackers to gradually recover user passwords through careful measurement of how long authentication attempts take to fail. When pam_userdb is configured to compare passwords without encryption (plaintext mode), the module's character-by-character comparison inadvertently reveals password length and individual characters by responding faster or slower depending on where the first mismatch occurs. An attacker with repeated access to an authentication service—either locally or from the network—can exploit this to systematically guess passwords one byte at a time.
- CVE-2026-54590MEDIUM 5.9
AsyncSSH, a Python library for SSH protocol implementation, contains a path traversal vulnerability in version 2.23.0 that allows attackers to read SSH authorized keys files from outside their intended directory. The vulnerability exists because the code blocks certain path traversal characters (/, comma, and double dots) before substitution, but fails to block tilde (~) and environment variable syntax (${ENV}), which are expanded later in the process. This allows an attacker with network access to potentially retrieve sensitive key data by crafting specially formatted authorized keys file paths. The issue has been patched in version 2.23.1.
- CVE-2026-54753MEDIUM 5.9
Nx, a popular build and monorepo tool used by TypeScript and polyglot development teams, contains a cross-origin information disclosure vulnerability in its local development server. When developers run `nx graph` to visualize their project structure, the HTTP server it spawns returns overly permissive CORS headers that allow any website the developer visits to read sensitive data from that server—including the full project graph topology and command outputs. In rare configurations, this could escalate to arbitrary command execution. The issue affects versions 17.0.4 through 22.7.1 and early 23.0.0 beta releases.
- CVE-2026-54773MEDIUM 5.9
CoreWCF, a .NET Core implementation of Windows Communication Foundation, contains a signature verification flaw that allows unauthenticated attackers to bypass message authenticity checks. An attacker can inject a SOAP header before the security header and trick the system into validating a forged signature instead of the legitimate one. This affects versions before 1.8.1 and 1.9.x before 1.9.1, and is primarily a message integrity issue rather than a confidentiality risk.
- CVE-2026-54779MEDIUM 5.9
CoreWCF, a .NET Core implementation of Windows Communication Foundation, contains a flaw in its SAML token replay protection mechanism. When replay detection is enabled, the system fails to reject tokens that have already been used, allowing an attacker who intercepts a valid token to replay it multiple times. This undermines the security guarantee that tokens should only be valid once, potentially allowing unauthorized access even after the original user's session should have expired.
- CVE-2026-55199MEDIUM 5.9
libssh2 versions through 1.11.1 contain a vulnerability that allows a malicious SSH server to exhaust CPU resources on a connecting client. During the SSH handshake, an attacker can send specially crafted data that causes the client library to enter an intense processing loop lasting over 60 seconds, effectively freezing the application. This occurs because the library doesn't properly validate server responses and timeout protections don't apply to CPU-intensive operations. The attacker must control the SSH server being connected to, which limits exposure but is significant for organizations connecting to untrusted or compromised servers.
- CVE-2026-55568MEDIUM 5.9
Guzzle, a widely-used PHP HTTP client library, contains a flaw that causes proxy credentials and encrypted connection metadata to be transmitted unencrypted under specific conditions. When an application configures an HTTPS proxy expecting end-to-end encryption to that proxy, older versions of the underlying libcurl library (prior to 7.50.2) silently downgrade the connection to plain HTTP instead of raising an error. This means proxy usernames, passwords, and the details of HTTPS requests being tunneled through the proxy are exposed in cleartext on the network. The vulnerability only affects applications using Guzzle's built-in cURL handlers (the default) with https:// proxy configurations and outdated libcurl versions.
- CVE-2026-55577MEDIUM 5.9
ImageMagick, a widely used open-source image manipulation library, contains a heap buffer overflow vulnerability in its MVG (Magick Vector Graphics) decoder. When processing specially crafted images, the decoder can write data beyond allocated memory boundaries, potentially causing the application to crash or become unstable. This flaw affects versions before 6.9.13-51 (legacy branch) and 7.1.2-26 (current branch).
- CVE-2026-55761MEDIUM 5.9
Portainer Community Edition has a security gap that allows unauthenticated attackers to set up a malicious administrator account or restore a backup file during the initial five-minute setup window on fresh installations. An attacker with network access can exploit this window to gain full administrative control over containerized environments managed by the vulnerable Portainer instance.
- CVE-2026-55950MEDIUM 5.9
Erlang/OTP's DTLS (Datagram Transport Layer Security) implementation contains a race condition that allows an unauthenticated attacker to crash all active DTLS connections on a server listener by sending rapid reconnection attempts from the same network address. The vulnerability exploits a timing gap in how the shared connection router (demux process) handles concurrent client reconnections, causing it to crash in a way that brings down every session on that listener, not just the attacker's connection. This creates a denial of service affecting all clients simultaneously.
- CVE-2026-56007MEDIUM 5.9
A stored cross-site scripting (XSS) vulnerability exists in OceanWP's Ocean Product Sharing plugin through version 2.2.2. An attacker with administrative privileges can inject malicious scripts into product sharing features that persist in the database and execute in the browsers of other users who view the affected content. This allows the attacker to steal session tokens, deface pages, or perform actions on behalf of legitimate users.
- CVE-2026-56009MEDIUM 5.9
Bricksable, a plugin for the Bricks Builder page builder, contains a stored cross-site scripting (XSS) vulnerability that allows authenticated users with elevated privileges to inject malicious scripts. These scripts are then executed in the browsers of other users who view the affected pages or content. The vulnerability affects Bricksable versions up to and including 1.6.83.
- CVE-2026-56016MEDIUM 5.9
CGI::Session::ID::md5 versions before 4.49 contain a critical flaw in how session identifiers are generated. Instead of using cryptographically secure random sources, the library constructs session IDs from three predictable inputs: the process ID, the current time, and Perl's built-in rand() function. An attacker who understands this algorithm can predict valid session IDs and hijack user sessions without knowing credentials, effectively bypassing authentication entirely.
- CVE-2026-57022MEDIUM 5.9
Juniper Networks Junos OS running on certain MX and SRX platforms contains a flaw in how the Packet Forwarding Engine handles exceptional network conditions. An attacker on the network can send a specially crafted packet to an affected device, causing the forwarding engine to crash and restart. During this restart, all traffic and services stop working until the system recovers automatically. This vulnerability requires the device to initiate an outbound connection to the attacker first, which limits exploitability but remains a concern for devices that perform active network operations like traffic inspection or probing.
- CVE-2026-57030MEDIUM 5.9
Juniper SRX Series firewalls contain a race condition in their packet forwarding engine that can be exploited by sending specially crafted network traffic to cause denial of service. The bug occurs during flow session cleanup—normally flows are removed after 3 seconds of inactivity, but a timing issue can cause the timeout to be set to over 10,000 seconds instead. This prevents flows from being cleaned up properly, causing session tables to accumulate stale entries until the device either stops forwarding traffic entirely or crashes and reboots.
- CVE-2026-57082MEDIUM 5.9
Net::BitTorrent, a Perl library for BitTorrent protocol support, uses Perl's standard random number generator to create encryption keys for the Message Stream Encryption (MSE) handshake. This is a cryptographic mistake: Perl's rand() is designed for non-security purposes and is entirely predictable once an attacker observes a single connection. An attacker passively listening to the network handshake can recover the encryption key used to protect the subsequent traffic, allowing them to decrypt communications that should be obfuscated from passive observation.
- CVE-2026-57722MEDIUM 5.9
ShortPixel's Enable Media Replace plugin contains a stored cross-site scripting (XSS) vulnerability that allows authenticated users with elevated privileges to inject malicious scripts into web pages. Unlike reflected XSS, stored XSS persists in the application, meaning the attack payload remains in the database and executes automatically whenever affected pages are viewed. This affects all versions through 4.2.1. An attacker would need administrative or editor-level access to inject the payload, but once stored, any user—including site visitors—viewing the compromised content could be affected.