By year
Vulnerabilities disclosed in 2026
CVEs published in 2026 with SEC.co analysis.
2772 published vulnerabilities · page 3 of 28
- CVE-2026-22055HIGH 8.8
Active IQ OneCollect version 2.7.3 contains hard-coded credentials embedded in the application. An authenticated user with basic network access can exploit these credentials to perform unauthorized AutoSupport operations—potentially exfiltrating sensitive system telemetry, configuration data, or triggering unwanted support actions. The vulnerability requires an attacker to already have valid credentials to an affected system, but once authenticated, the hard-coded secrets bypass normal access controls and allow privilege escalation to perform high-impact operations.
- CVE-2026-25559HIGH 8.8
OpenBullet2 versions up to 0.3.2 contain a critical file manipulation flaw that lets authenticated users read, write, and delete arbitrary files on the system. An attacker with valid credentials can exploit this to modify or delete system files, potentially gaining complete control of the host. The risk is particularly severe because OpenBullet2 typically runs with root privileges, meaning any file manipulation has system-wide impact.
- CVE-2026-25855HIGH 8.8
OpenBullet2 versions up to 0.3.2 contain a critical flaw that allows logged-in users to run arbitrary commands on servers hosting the application. By uploading malicious script files through the FileProxySource feature—which is meant to load proxy configurations—attackers can trick the server into executing those scripts. The server then processes the output and returns it as proxy data, effectively giving the attacker command-line control over the machine running OpenBullet2. This vulnerability requires prior authentication but poses severe risk once an attacker gains initial access.
- CVE-2026-25856HIGH 8.8
OpenBullet2 through version 0.3.2 allows authenticated users to execute arbitrary code on the hosting server. An attacker with valid credentials can modify job configurations to inject and run C# code, gaining the ability to read files, launch programs, and call any .NET function available to the application process. This is a post-authentication vulnerability, meaning the attacker must already have login access.
- CVE-2026-30650HIGH 8.8
A remote code execution flaw exists in Vivotek FD8136 network cameras that allows an authenticated attacker to take complete control of the device. The vulnerability resides in the admin interface's event task handler and can be exploited over the network without user interaction, enabling an attacker with valid credentials to execute arbitrary commands with root-level privileges.
- CVE-2026-30652HIGH 8.8
A buffer overflow flaw in Vivotek FD8136 network cameras allows authenticated users with admin access to run malicious code with root-level privileges on the device. The vulnerability exists in a specific administrative interface endpoint and affects cameras running firmware version FD8136-VVTK-0300a. An attacker would need valid credentials to exploit it, but once inside the admin panel, they could completely compromise the camera and potentially use it as a foothold into your network.
- CVE-2026-32193HIGH 8.8
Microsoft Azure Kubernetes Service contains a path traversal vulnerability that allows an authorized user to escape intended directory restrictions and execute code on the host system. Because the attacker must already have legitimate access to the cluster, this is a privilege escalation risk rather than an unauthenticated attack vector. The flaw lets someone with basic user permissions potentially gain broader control over the infrastructure.
- CVE-2026-35082HIGH 8.8
A vulnerability in MBS Solutions' universal gateway firmware and related products allows an authenticated user to read arbitrary files from the affected system. The ugw-logread method does not properly validate file path inputs, enabling attackers with legitimate user credentials to bypass access controls and retrieve sensitive data they shouldn't be able to access. This is a local file disclosure issue that requires valid user credentials to exploit.
- CVE-2026-35083HIGH 8.8
A stack buffer overflow vulnerability exists in MBS Solutions' industrial gateway and protocol converter products. An attacker with valid user credentials can send a specially crafted network request to trigger memory corruption, allowing them to execute arbitrary code with root-level privileges. This is a serious vulnerability because it requires no user interaction, operates over the network, and completely bypasses system security once exploited.
- CVE-2026-35084HIGH 8.8
A stack buffer overflow vulnerability in the dali-devconfig component affects a broad range of MBS Solutions gateway and protocol conversion devices. An attacker with basic user-level access to the network can send a specially crafted request that overwrites memory on the device, potentially achieving full root-level system compromise. This is a particularly serious issue because these devices typically operate as trusted infrastructure components in industrial and building automation networks, where an attacker gaining root access could manipulate critical system functions or pivot to downstream systems.
- CVE-2026-35085HIGH 8.8
A stack buffer overflow vulnerability in gdv-serverconfig affects a broad range of MBS Solutions gateway and interface devices. An authenticated attacker with standard user privileges can send a specially crafted network request to trigger the overflow and execute arbitrary code with root-level system access. The vulnerability requires valid user credentials to exploit but no user interaction, making it a significant risk in environments where user account compromise is possible.
- CVE-2026-35671HIGH 8.8
phpMyFAQ versions before 4.1.3 contain a privilege escalation vulnerability in the admin password management API. An authenticated administrator with low-level privileges can manipulate API requests to reset any user's password, including SuperAdmin accounts, bypassing normal authorization checks. This allows attackers to seize full control of the FAQ system.
- CVE-2026-35674HIGH 8.8
OpenClaw versions before 2026.5.18 contain a privilege escalation flaw in their chat messaging system. An attacker with basic operator permissions can bypass security controls meant to restrict high-risk actions—such as modifying plugins, configurations, or access policies—by sending commands through internal message routes. This allows someone with limited access to act as if they have full administrative privileges.
- CVE-2026-36607HIGH 8.8
A vulnerability in Mercusys AC12G (EU) V1 routers allows attackers on the same local network to repeatedly guess the administrator password without limit. Unlike the normal login interface which enforces rate limiting, the password change feature in the router's management protocol accepts unlimited guesses, giving attackers a straightforward path to full administrative access.
- CVE-2026-36608HIGH 8.8
A vulnerability in Mercusys AC12G (EU) V1 routers running firmware version AC12G(EU)_V1_200909 allows anyone connected to the local network to use UPnP port forwarding to redirect traffic destined for the internet directly to the router's admin interface. The vulnerability exists because the router's UPnP implementation doesn't properly validate the destination address when setting up port mappings—it accepts requests to forward ports to the router's own IP address (192.168.1.1) or localhost (127.0.0.1), which should never be allowed. An attacker on the LAN can exploit this with a single SOAP request to expose the administrative panel to the public internet without authentication, bypassing all network boundary protections.
- CVE-2026-40371HIGH 8.8
Microsoft Dynamics 365 (on-premises) contains a privilege escalation vulnerability that allows an authenticated user to gain elevated permissions over the network. An attacker who already has valid credentials can exploit insufficient permission checks to escalate their access level and perform unauthorized actions within the system. This is a serious flaw because it bypasses the normal access control model that should restrict what authenticated users can do.
- CVE-2026-41236HIGH 8.8
Froxlor version 2.3.6 contains a privilege escalation vulnerability in its SSH key synchronization mechanism for FTP users. An attacker with shell access to a customer account can exploit a symlink-following flaw to redirect the root-owned SSH key provisioning process into writing unauthorized keys to the system root account, granting SSH access as root. This vulnerability requires prior authentication and file system access on the affected system but results in complete system compromise.
- CVE-2026-41860HIGH 8.8
BOSH, a widely-used Infrastructure-as-Code and deployment orchestration platform, contains a flaw in how it validates SSL/TLS certificates when communicating with internal services like the BOSH director and UAA (User Account and Authentication). Specifically, the HttpRequestHelper component explicitly disables certificate verification (VERIFY_NONE), which means an attacker with local access to the network can intercept and eavesdrop on these communications. This allows stealing Basic authentication credentials or session tokens, potentially granting unauthorized access to your deployment infrastructure. The vulnerability affects all BOSH versions up through v282.1.8; version 282.1.9 and later include the fix.
- CVE-2026-42359HIGH 8.8
Apache Airflow contains a bypass of an earlier security fix that allows authenticated users with restricted permissions to inject malicious code into deferred tasks. An attacker with legitimate write access to task metadata can craft a specially formatted request to set hidden configuration values that trigger remote code execution when the task resumes. This affects organizations where any untrusted team members have editing permissions on Airflow workflows.
- CVE-2026-42985HIGH 8.8
A use-after-free memory vulnerability exists in Microsoft's Remote Desktop Client and related Windows components. An attacker can trigger this flaw over the network by sending specially crafted packets, potentially gaining code execution on a victim's machine without requiring prior authentication. User interaction is needed for successful exploitation.
- CVE-2026-43623HIGH 8.8
microtar, a lightweight TAR archive library, contains a critical flaw in how it processes TAR file headers. When an attacker crafts a malicious TAR archive with improperly formatted header fields, the library's parsing function attempts to copy data using unsafe string operations, writing far more data than the allocated buffer can hold. This corrupts memory on the stack, potentially allowing attackers to crash applications or execute arbitrary code. Any application that uses microtar to process untrusted TAR files is at risk.
- CVE-2026-43985HIGH 8.8
Tautulli, a Python-based tool that monitors and manages Plex Media Server, contains a critical flaw in how it handles administrator settings changes. In versions before 2.17.1, an attacker can trick a logged-in administrator into visiting a malicious webpage, which silently changes the Tautulli admin username and password without the administrator's knowledge or consent. Once the credentials are changed, the attacker can log in directly and gain complete control of the Tautulli interface. This is a straightforward but dangerous type of attack that exploits the trust between a user's browser and the Tautulli server.
- CVE-2026-44238HIGH 8.8
FreePBX versions before 16.0.50 and 17.0.11 contain a SQL injection vulnerability in the CDR (Call Detail Records) Reports module. An authenticated user with CDR section access can manipulate the 'order' and 'sort' parameters to inject arbitrary SQL commands, potentially reading, modifying, or deleting sensitive database content. Unlike many vulnerabilities requiring administrative accounts, this one only needs standard CDR access, broadening the pool of potential attackers within an organization.
- CVE-2026-44239HIGH 8.8
FreePBX, a widely deployed open-source phone system platform, contains a path traversal vulnerability in its Dashboard module that allows authenticated users to execute arbitrary PHP code. By manipulating a parameter in a web request, an attacker can bypass normal file access restrictions and cause the system to load and execute specially-named PHP files from unexpected locations on the server. This is a serious issue because it grants code execution to any user with valid login credentials.
- CVE-2026-44420HIGH 8.8
FreeRDP, a widely-used open-source Remote Desktop Protocol implementation, contains a flaw in its clipboard handling that allows an authenticated attacker to crash the RDP server or potentially execute arbitrary code. A malicious RDP client can send a specially crafted clipboard message with an invalid size parameter, causing the server to write past the bounds of allocated memory. This affects FreeRDP versions prior to 3.26.0. The vulnerability requires valid RDP credentials to exploit, limiting the attack surface to authenticated threat actors.
- CVE-2026-44421HIGH 8.8
FreeRDP, an open-source Remote Desktop Protocol client, contains a memory safety flaw that can be exploited by a malicious RDP server. When a FreeRDP client connects to an attacker-controlled server with graphics acceleration enabled, the attacker can send specially crafted network packets that trigger a heap buffer overflow during graphics operations. This memory corruption can crash the client or potentially allow remote code execution on the user's machine. The vulnerability requires user interaction (initiating an RDP connection) but does not require authentication, making it a practical attack vector against organizations that rely on remote desktop functionality.
- CVE-2026-44848HIGH 8.8
Portainer Community Edition versions 2.33.0 through 2.33.7, 2.39.x (before 2.39.2), and 2.40.x (before 2.41.0) fail to properly restrict access to Docker plugin management endpoints. This means any standard user granted access to a Docker endpoint through Portainer can perform privileged operations like installing and enabling plugins directly on the underlying Docker daemon—something normally restricted to administrators. The flaw stems from missing access control handlers on the /plugins/* endpoints, allowing RBAC bypass for a critical management function.
- CVE-2026-44849HIGH 8.8
Portainer Community Edition has a security control bypass where administrators can restrict what kinds of containers non-admin users are allowed to launch—such as preventing privileged containers or restricting device access. However, when users create containers through the Docker Swarm API instead of the standard container creation path, several of these restrictions are ignored. An authenticated attacker with basic user privileges could bypass these restrictions to launch more dangerous containers than policy allows. The issue affects versions 2.33.0 through 2.33.7, 2.39.0 through 2.39.1, and 2.40.x, with fixes available in 2.33.8, 2.39.2, and 2.41.0.
- CVE-2026-45447HIGH 8.8
OpenSSL has a critical flaw in how it handles PKCS#7 and S/MIME signed messages. When these messages contain an empty digest algorithms field, OpenSSL incorrectly frees memory that the calling application still owns and expects to use later. This causes a use-after-free condition—essentially, the application tries to use memory that OpenSSL has already released. Depending on how the application manages that memory afterward, this can cause crashes, corruption of heap data, or in worse cases, allow an attacker to execute arbitrary code remotely. The vulnerability requires an authenticated user to send a specially crafted message, but once triggered, the damage can be severe.
- CVE-2026-45484HIGH 8.8
A flaw in Microsoft SharePoint Server allows an authenticated attacker to bypass normal access controls and gain elevated privileges on the system. The vulnerability stems from improper handling of serialized data—specifically, the application accepts and processes untrusted serialized objects without adequate validation. An attacker with valid SharePoint credentials can craft malicious serialized payloads that execute with higher privileges when deserialized, effectively escalating their access level within the SharePoint environment.
- CVE-2026-45504HIGH 8.8
CVE-2026-45504 is a server-side request forgery (SSRF) vulnerability in Microsoft Exchange Server that allows an authenticated attacker to escalate their privileges across the network. Because the vulnerability requires valid credentials to exploit, the immediate risk is contained to authorized users—however, any user account (even low-privileged ones) can potentially pivot to higher access levels within the Exchange environment and potentially beyond. With a CVSS score of 8.8, this is rated HIGH severity and merits prompt patching.
- CVE-2026-45505HIGH 8.8
Apache ActiveMQ contains a code injection vulnerability that allows authenticated attackers to execute arbitrary code on the broker. The issue stems from improper validation of discovery wrapper URLs—specifically non-parenthesized formats like `masterslave:vm://...` and `static:vm://`—which bypass a previous security fix. An attacker with valid credentials can exploit the Jolokia JMX-HTTP bridge to load malicious Spring XML configurations, leading to remote code execution with broker privileges.
- CVE-2026-45578HIGH 8.8
WWBN AVideo, an open-source video streaming platform, contains a command injection vulnerability in its live streaming notification system. An authenticated attacker can inject shell commands by crafting input with special characters, allowing them to execute arbitrary code on the server. The flaw exists because the application builds system commands by concatenating user-supplied values without properly escaping shell metacharacters.
- CVE-2026-45648HIGH 8.8
A stack-based buffer overflow vulnerability exists in Active Directory Domain Services (AD DS) that allows authenticated attackers to execute arbitrary code remotely on affected Windows Server systems. An attacker with valid domain credentials can craft a malicious request that overflows a memory buffer, potentially gaining full control of the AD DS infrastructure. The vulnerability requires network access and valid authentication, but does not require user interaction to exploit.
- CVE-2026-45662HIGH 8.8
Dokploy, a self-hosted platform-as-a-service tool, contains a command injection vulnerability in its registry deletion function. When an administrator deletes a Docker registry configuration, the application fails to properly sanitize the registry URL before passing it to a system command. An attacker with legitimate platform access could craft a malicious registry URL that executes arbitrary commands on the server with the privileges of the Dokploy process. This vulnerability affects Dokploy version 0.29.0 and earlier.
- CVE-2026-46113HIGH 8.8
A use-after-free vulnerability exists in the Linux kernel's KVM (Kernel Virtual Machine) shadow page table management. The issue arises when guest page tables are modified between VM entries, causing KVM to track memory references incorrectly. This can lead to the kernel accessing freed memory structures, potentially allowing a local attacker with guest access to crash the system or execute code with elevated privileges. The vulnerability requires local access and affects systems running KVM with shadow paging enabled.
- CVE-2026-46125HIGH 8.8
CVE-2026-46125 is a memory safety bug in Linux kernel WiFi driver code that can cause system crashes or privilege escalation. When the kernel attempts to establish a multi-link WiFi connection and that setup fails, the code incorrectly retains station references that should have been cleaned up. This leaves dangling pointers in memory that can be exploited or cause the system to crash when the kernel debugfs interface tries to access them later. The vulnerability requires local network access and affects systems with WiFi enabled.
- CVE-2026-46152HIGH 8.8
A vulnerability in the Linux kernel's WiFi driver (mac80211) allows concurrent network packet processing threads to interfere with each other. The issue stems from a shared variable that should have been unique to each processing thread. When multiple packets arrive simultaneously, one thread's processing result can be overwritten by another, causing packets to be misrouted or incorrectly marked as already processed. This can lead to dropped packets, incorrect packet handling, or exposure of network data.
- CVE-2026-46166HIGH 8.8
A memory safety flaw exists in the Linux kernel's Wi-Fi driver subsystem (mac80211). When the kernel performs radar detection checks on wireless channels, it can inadvertently access memory that has already been freed, potentially causing a system crash or enabling privilege escalation. The issue stems from unsafe iteration over a list of wireless channel contexts that can be modified during the operation.
- CVE-2026-46174HIGH 8.8
CVE-2026-46174 is a high-severity vulnerability in the Linux kernel that affects AMD Zen2 processors. The issue involves improper isolation of shared resources within the processor's op cache, which can allow instructions to become corrupted when resources are improperly shared between processes or virtual machines. An attacker with local access could potentially exploit this to gain unauthorized access, modify data, or disrupt system availability. This is a privilege escalation and isolation bypass issue that requires local code execution capability to trigger.
- CVE-2026-46198HIGH 8.8
A flaw in the Linux kernel's batman-adv (Better Approach To Mobile Ad-hoc Networking) module allows an attacker on the network to trigger an integer overflow that leads to reading memory beyond intended bounds. The vulnerability stems from a type mismatch: a size validation uses a larger integer type (int) while the actual buffer position is stored in a smaller signed type (s16), creating a window where the validation passes but the buffer position can still exceed safe limits. An attacker with network access could exploit this to read sensitive kernel memory.
- CVE-2026-46212HIGH 8.8
A use-after-free vulnerability exists in the Linux kernel's batman-adv module, specifically in the B.A.T.M.A.N. advanced mesh networking layer. When removing backbone claims from a network topology, the code attempts to free a claim object before it has finished using it, creating a window where the freed memory could be accessed or overwritten. This can lead to system crashes, data corruption, or privilege escalation in mesh-networked Linux systems running the affected code.
- CVE-2026-46238HIGH 8.8
A memory management flaw in the Linux kernel's B.A.T.M.A.N. (Better Approach To Mobile Ad-hoc Networking) advanced routing implementation allows an attacker on the local network to crash the system or potentially execute code with high privileges. The vulnerability stems from the protocol caching a pointer to routing data that can become invalid after the system cleans up stale entries, leading to use-after-free conditions when that stale pointer is later accessed.
- CVE-2026-46264HIGH 8.8
A flaw in the Linux kernel's display driver (xe) for Intel GPUs causes a crash during system initialization. When the driver sets up user-facing controls (sysfs), a cleanup routine may run on an uninitialized object, leading to memory corruption and system instability. This occurs specifically in SR-IOV (virtualization) configurations where one GPU is shared among multiple virtual machines. The issue affects driver initialization sequences and can trigger kernel warnings and potential use-after-free conditions.
- CVE-2026-46317HIGH 8.8
A race condition in the Linux kernel's KVM (virtualization) subsystem on ARM64 systems allows a local, unprivileged user to cause a use-after-free memory error. The vulnerability exists in how the kernel manages nested virtual machine memory structures during reallocation. When the kernel reallocates its internal data structure for nested virtual machines, it frees the old memory while another part of the kernel may still be trying to access it, leading to a crash or potential privilege escalation. This requires local access and affects systems running vulnerable kernel versions with KVM nested virtualization enabled.
- CVE-2026-46414HIGH 8.8
Microsoft UFO, an open-source framework for intelligent automation across devices and platforms, contains a critical authentication bypass in version 3.0.1-4-ge2626659. The vulnerability allows any authenticated client to impersonate higher-privilege roles and send malicious automation tasks to other connected devices. An attacker with valid credentials to the WebSocket control plane can register as a normal device, then switch to a privileged 'constellation' role mid-session and direct tasks to victim systems. Additionally, the client registry allows duplicate registrations that overwrite and disconnect legitimate devices from the network.
- CVE-2026-46444HIGH 8.8
Flowise versions prior to 3.1.2 contain a critical authentication flaw in the OpenAI Assistants Vector Store endpoints. Any authenticated user with a valid API key can perform unrestricted create, read, update, and delete operations on vector store data without additional permission checks. This means a low-privileged user or compromised API key can manipulate vector stores that should only be accessible to specific users or administrative roles.
- CVE-2026-46475HIGH 8.8
Flowise, a platform for building customized LLM workflows through a drag-and-drop interface, contains a privilege escalation vulnerability in its assistant management features. Prior to version 3.1.2, an authenticated attacker can exploit mass-assignment flaws in the create and update endpoints to take over assistants belonging to other workspaces, potentially accessing or modifying shared LLM configurations across organizational boundaries.
- CVE-2026-46476HIGH 8.8
Flowise, a visual tool for building customized large language model workflows, contains a vulnerability in how it handles template creation and updates. Attackers with user access can exploit mass-assignment flaws to take control of templates across different workspaces—essentially hijacking template configurations that should be isolated from one another. The vulnerability affects all versions prior to 3.1.2 and has been resolved in that release.
- CVE-2026-46477HIGH 8.8
Flowise, a visual interface for building and customizing language model workflows, contains a mass-assignment vulnerability in its dataset management functions. Before version 3.1.2, an authenticated attacker could exploit weak input validation during dataset creation or updates to access and modify datasets across different workspaces—effectively taking over datasets belonging to other users or teams. The vulnerability requires a valid user account to exploit but poses a serious risk to multi-tenant Flowise deployments where data isolation is critical.
- CVE-2026-46478HIGH 8.8
Flowise, a popular drag-and-drop interface for building customized language model workflows, contains a privilege escalation flaw in its DatasetRow functionality. Before version 3.1.2, an authenticated attacker could manipulate how new dataset rows are created or updated, allowing them to inject or modify rows belonging to other workspaces. This mass-assignment vulnerability effectively grants an attacker control over another organization's data within the same Flowise deployment, provided they have valid login credentials.
- CVE-2026-46479HIGH 8.8
Flowise, a no-code platform for building customized LLM workflows, contains a privilege escalation vulnerability in its evaluation management system. Attackers with valid user credentials can modify evaluation records in ways that bypass workspace isolation, allowing them to view, edit, or delete evaluations belonging to other teams or organizations. The vulnerability stems from improper input validation in the create and update endpoints—a classic mass-assignment flaw. Version 3.1.2 and later patch this issue.
- CVE-2026-46480HIGH 8.8
Flowise, a no-code platform for building customized large language model workflows, contains a privilege escalation vulnerability in its evaluator management feature. An authenticated attacker can exploit improper input validation during evaluator creation or updates to gain unauthorized access to evaluators across different workspaces. This allows an attacker to take over evaluators belonging to other users or teams, potentially manipulating AI workflow logic and data without authorization. The vulnerability requires an existing login but no elevated privileges to exploit.
- CVE-2026-46490HIGH 8.8
A flaw in samlify, a Node.js SAML authentication library, allows attackers to inject malicious XML into SAML assertions. When user attributes (like email or display name) are processed during single sign-on, an attacker can add fake authorization attributes that get signed by the identity provider and trusted by the service provider. This can lead to privilege escalation if the application relies on SAML attributes for access control decisions.
- CVE-2026-46656HIGH 8.8
Bludit, a content management system, has a critical flaw in how it manages user sessions. When an administrator deletes a user account from the database, the system fails to invalidate that user's active login sessions. This means a deleted user can continue accessing the CMS with full privileges as if their account still existed—a "ghost session" vulnerability. The flaw affects all Bludit versions before 3.22.0 and is fixed in that release.
- CVE-2026-46746HIGH 8.8
SINEC INS, a Siemens industrial networking application, contains a command injection vulnerability in its file upload functionality. An authenticated user can craft malicious directory names that bypass input validation, plant shell commands, and trigger their execution when the application later retrieves directory listings. The attacker gains command execution at the privilege level of the service account, potentially compromising the entire system. All versions before 1.0 SP2 Update 6 are affected.
- CVE-2026-46748HIGH 8.8
CVE-2026-46748 affects Siemens SINEC INS installations running versions prior to V1.0 SP2 Update 6. A binary within the system has been granted excessive Linux kernel capabilities (specifically cap_dac_override), which allows it to bypass normal file permission checks. A local attacker who gains access to the system can exploit this to read, modify, or delete any file and escalate privileges to root, gaining complete control of the host. This is a serious flaw in privilege isolation that compounds the risk of any initial compromise.
- CVE-2026-46826HIGH 8.8
CVE-2026-46826 is a high-severity vulnerability in Oracle Payroll (part of Oracle E-Business Suite) that allows attackers with valid user credentials to gain complete control over the payroll system via the network. The vulnerability affects versions 12.2.3 through 12.2.15 and stems from insufficient access control mechanisms. An attacker needs only a low-privileged account to exploit it remotely—no special tools or user interaction required—making it a material threat to organizations relying on Oracle payroll processing.
- CVE-2026-46827HIGH 8.8
CVE-2026-46827 is a high-severity vulnerability in Oracle E-Business Suite's Payroll module that allows a low-privileged network attacker to gain full control over the payroll system. An authenticated user with minimal permissions can exploit this flaw remotely via HTTP to read sensitive data, modify payroll records, or disrupt service availability. This represents a complete compromise of the affected payroll component.
- CVE-2026-46837HIGH 8.8
A vulnerability exists in Oracle Flow Manufacturing (part of Oracle E-Business Suite) that allows a low-privileged user with network access to gain complete control over the affected system. An attacker who already has valid credentials can exploit a flaw in the security component via SQL to read, modify, or delete data—or disrupt system operations entirely. The vulnerability affects Oracle E-Business Suite versions 12.2.9 through 12.2.15.
- CVE-2026-47125HIGH 8.8
Arcane, a Docker container management interface, has a critical flaw in how it protects global environment variables. Any logged-in user—not just administrators—can modify system-wide configuration values that affect every containerized project. An attacker could inject malicious registry URLs, database credentials, or other secrets into these shared variables, poisoning deployments across the entire system. The vulnerability exists in versions prior to 1.19.2 and requires only basic authentication to exploit.
- CVE-2026-47289HIGH 8.8
A heap-based buffer overflow vulnerability exists in Remote Desktop Client that could allow an attacker to run malicious code on a user's computer over the network. The flaw requires user interaction (such as connecting to a malicious RDP server or opening a crafted file) but does not require any authentication. If exploited, an attacker could gain full control of the affected system.
- CVE-2026-47653HIGH 8.8
A use-after-free vulnerability in Microsoft's Remote Desktop Client allows an attacker to execute arbitrary code on a victim's computer over the network. The attacker does not need valid credentials, but the user must interact with the application (such as clicking a link or opening a file) for the attack to succeed. This is a serious flaw affecting many versions of Windows 10, Windows 11, and Windows Server editions.
- CVE-2026-48095HIGH 8.8
7-Zip, the widely used file compression utility, contains a critical flaw in how it handles NTFS compressed disk images. When a specially crafted image is opened—even with an innocuous file extension—the application miscalculates memory buffer sizes, leading to a situation where attackers can write massive amounts of data into a tiny allocated space. This memory corruption can overwrite the application's internal control structures, giving attackers the ability to execute arbitrary code on the affected system. Versions 26.00 and earlier are vulnerable; version 26.01 and later have been patched.
- CVE-2026-48557HIGH 8.8
Spatie's Laravel Media Library, a widely-used file management plugin for Laravel applications, has a vulnerability in its file upload filtering that allows authenticated attackers to upload files with names like shell.php.jpg that appear safe but retain executable code. Versions before 11.23.0 fail to properly block dangerous file extensions, and under specific Apache server configurations, these uploads can be executed as PHP scripts, potentially giving attackers full control of the application.
- CVE-2026-49143HIGH 8.8
BrowserStack Runner versions up to 0.9.5 contain a critical remote code execution flaw in its /_log HTTP handler. An unauthenticated attacker on the local network can send specially crafted JSON requests to execute arbitrary code on the server without providing credentials. The vulnerability stems from unsafe use of Node.js sandbox features combined with eval(), which allows attackers to break out of the sandbox and gain full system access.
- CVE-2026-49157HIGH 8.8
Apache ActiveMQ contains a permissions misconfiguration in its Jolokia interface that allows low-privilege web users to perform high-level broker management operations. Specifically, non-admin accounts can execute commands like addQueue and removeQueue that should be restricted to administrators only. This violates the principle of least privilege and can lead to unauthorized service disruption or configuration tampering. Affected versions are ActiveMQ 5.x before 5.19.7 and 6.x before 6.2.6.
- CVE-2026-49190HIGH 8.8
A flaw in Acer Connect M6E 5G firmware fails to properly enforce access controls when processing internal system instructions, allowing authenticated users to install unauthorized applications or execute arbitrary commands on the device. The vulnerability requires valid login credentials but provides no other barriers once an attacker gains initial access.
- CVE-2026-49194HIGH 8.8
A debugging function called SCREEN_CLICK(5053) in certain Acer Connect M6E 5G devices allows an authenticated user to bypass the normal login process and gain direct access to an interactive shell. This circumvents device security controls and could enable an attacker with valid credentials to take full control of the device without standard authentication checks.
- CVE-2026-49195HIGH 8.8
A debug service running on Acer Predator Connect W6X devices exposes a command interface on port 9000 without requiring any authentication. Any device with network access to an affected device can send arbitrary commands to this service, potentially taking complete control of the device. This is a local network vulnerability, meaning the attacker must be on the same network segment as the target.
- CVE-2026-49298HIGH 8.8
Apache Airflow's KubernetesExecutor has a credential exposure bug where JWT tokens used by worker pods to authenticate against the Execution API are inadvertently visible in Kubernetes pod specifications. An attacker with read-only access to the Airflow namespace in Kubernetes (a common access level) can retrieve these tokens from standard `kubectl describe pod` commands and then use them to execute privileged API operations—such as triggering DAG runs, clearing runs, or modifying Variables, Connections, and XComs—without needing direct task execution privileges. This vulnerability only affects deployments using the KubernetesExecutor. The fix requires upgrading both the airflow-providers-cncf-kubernetes package (if not already done per CVE-2026-27173) and the core apache-airflow package to close complementary attack surfaces.
- CVE-2026-4944HIGH 8.8
vLLM version 0.14.1 contains a critical vulnerability in its model loading mechanism that forces remote code execution to be enabled, regardless of user security settings. Specifically, two model implementation files (NemotronVL and KimiK25) have hardcoded parameters that override a user's explicit decision to disable remote code execution. An attacker can exploit this by hosting a malicious model on HuggingFace and triggering code execution on systems that load these specific models, even when administrators thought they had disabled this risky feature.
- CVE-2026-49443HIGH 8.8
A critical authentication flaw in authentik—an open-source identity provider—allows attackers to hijack user accounts across the platform. If an attacker has the ability to modify a source connection (such as an external authentication provider) and controls an account in one of those sources, they can log in as any other user in the system. This is a privilege escalation vulnerability requiring two preconditions: administrative access to source configuration and an existing account in a connected source. The flaw affects authentik versions prior to 2025.12.6, 2026.2.4, and 2026.5.1.
- CVE-2026-49492HIGH 8.8
Markdown Preview Enhanced, a popular tool for rendering markdown documents with enhanced features, contains a critical flaw in how it handles external content. When you preview a markdown file, the extension can be tricked into executing system commands hidden within the document—specifically through diagram filenames, imported file paths, and LaTeX code attributes. On Windows systems, an attacker can craft a malicious markdown file that runs arbitrary operating system commands the moment you open it for preview. This happens because the tool passes unsanitized user input directly to the system shell without proper validation. The vulnerability was fixed in version 0.8.28 by changing how these inputs are processed and adding validation checks.
- CVE-2026-49493HIGH 8.8
Markdown Preview Enhanced versions before 0.8.28 contain a critical flaw in how they process bitfield code blocks embedded in markdown documents. When a user opens or exports a markdown file containing a malicious bitfield block, the application executes arbitrary code with the privileges of the user running the preview. An attacker can craft a seemingly innocent markdown document that, when rendered, runs malicious commands on the victim's system. This is a code injection vulnerability triggered by user interaction with a document.
- CVE-2026-50733HIGH 8.8
Markdown Preview Enhanced, a popular markdown editor extension, contains a critical flaw in how it renders WaveDrom diagrams—a type of digital waveform visualization. Versions before 0.8.28 use JavaScript's eval() function to process diagram code, which means maliciously crafted markdown files can trick the software into executing arbitrary code on your machine. An attacker only needs to get you to open or export a booby-trapped markdown document; no interaction beyond that is required. The vulnerability works across all rendering modes: live preview, presentation slides, and HTML export. A patch is available that replaces the unsafe eval() with proper JSON parsing, eliminating the risk.
- CVE-2026-5228HIGH 8.8
WriteUp Mobile App versions 1.3.0 through 04062026 contain an access control flaw that allows authenticated users to perform actions they should not have permission to execute. An attacker with legitimate credentials can bypass the application's authorization checks to access or modify restricted functionality. This is a post-authentication vulnerability—the attacker must have a valid account, but once logged in, the broken permission system fails to prevent unauthorized operations.
- CVE-2026-5411HIGH 8.8
WP Captcha PRO, a WordPress security plugin, contains a flaw that allows attackers with basic user accounts to upload and execute malicious code on affected websites. The vulnerability stems from insufficient validation when the plugin downloads and extracts files as part of its cloud protection feature. An attacker can trick the plugin into downloading a malicious archive, which it will extract into a publicly accessible folder, enabling remote code execution. This requires the attacker to have at least Subscriber-level access to WordPress and depends on certain PHP server configurations being enabled.
- CVE-2026-5415HIGH 8.8
WP Captcha PRO, a WordPress plugin used for reCAPTCHA integration, contains a critical flaw that allows attackers with basic user access to impersonate any account on the site, including administrators. The vulnerability chains together three separate weaknesses: the plugin exposes a security token to low-privilege users, uses that token in an unprotected function that generates passwordless login links, and then automatically logs in visitors using those links without verifying they should have access. An attacker with even Subscriber-level access (the lowest user role) can exploit this to take over any account and gain full control of the WordPress installation.
- CVE-2026-5768HIGH 8.8
The Frontier X2 wearable device has a critical Bluetooth security flaw that allows attackers within radio range to control the device and manipulate health data without any authentication. An attacker can start or stop activities, trigger unwanted vibrations, inject fake health readings like heart rate and breathing data into the companion mobile app, or disrupt the device entirely. The mobile app itself also fails to properly authenticate Frontier X2 devices, enabling attackers to create fake devices that the app will trust, further expanding the attack surface.
- CVE-2026-6226HIGH 8.8
The Frontend Admin plugin for WordPress, maintained by DynamiApps, contains a critical flaw that allows attackers to create administrator accounts without authentication. The vulnerability exists because the plugin accepts form definitions directly from user input rather than retrieving them securely from the database. By crafting a malicious form submission, an attacker can bypass role validation and create a new administrator account, gaining complete control of the WordPress site.
- CVE-2026-6657HIGH 8.8
A flaw in Jupyter Server allows attackers to bypass its cross-origin request (CORS) validation by exploiting how the software validates the `Origin` header. When administrators configure allowed origins using the `allow_origin_pat` setting, the validation logic uses a partial string match rather than a complete one. This means an attacker can craft a domain like `trusted.example.com.evil.com` that will pass validation meant only for `trusted.example.com`. The vulnerability affects versions 1.12.0 through 2.17.0 and impacts CORS headers, WebSocket connections, referer checking, and login redirects, potentially enabling phishing, code execution, and unauthorized access to APIs.
- CVE-2026-7195HIGH 8.8
A flaw in Progress Sitefinity's web services allows an unauthenticated attacker to compromise user accounts—stealing login credentials and modifying account data—by exploiting improper input validation. The attack requires tricking a user into interacting with a malicious request and relies on non-standard site configuration, making it a credible but not universally threatening risk. Multiple versions from 14.1 through 15.4 are affected.
- CVE-2026-7201HIGH 8.8
A flaw in Progress Sitefinity's web services allows authenticated users to modify account properties belonging to other users, potentially compromising those accounts. An attacker with valid login credentials can exploit an authorization bypass to access and alter settings or data for accounts that should be restricted from their access level. The vulnerability requires the attacker to know certain user identifiers or properties not typically visible to standard users, which raises the bar somewhat but remains exploitable with reconnaissance.
- CVE-2026-7465HIGH 8.8
Spectra Gutenberg Blocks, a WordPress plugin used for building websites with the block editor, contains a critical flaw that allows authenticated contributors and above to execute arbitrary code on the web server. The attack exploits the plugin's block rendering system: an attacker creates a custom block type with a malicious callback function, then triggers it through a second block in the same post, causing the server to run the attacker's code. This affects all versions up to 2.19.25.
- CVE-2026-7654HIGH 8.8
The Admin Columns plugin for WordPress contains a critical flaw that allows authenticated users—including those with basic contributor permissions—to execute arbitrary code on a website. The vulnerability stems from insecure handling of serialized PHP data in post metadata. An attacker with contributor-level access or higher can craft a malicious serialized object and inject it into a post's custom field, triggering code execution with the privileges of the web server. This affects all versions up to and including 7.0.18.
- CVE-2026-7770HIGH 8.8
IBM i Access Client Solutions (ACS) versions 1.1.5.0 through 1.1.9.12 contain a remote code execution vulnerability when the software is configured to receive requests from IBM i Navigator. An authenticated attacker can exploit this flaw to execute arbitrary code on the affected system, potentially compromising the entire environment. This is a serious vulnerability affecting a core IBM i administration tool.
- CVE-2026-7802HIGH 8.8
The Frontend Admin plugin for WordPress contains a critical flaw that allows low-privilege attackers to hijack administrator accounts. Any authenticated user—even with basic subscriber permissions—can change an admin's password, email address, and other profile information by manipulating a form parameter. This transforms a subscriber account into a full site compromise. The vulnerability only affects configurations where the plugin's 'Roles' setting is left unconfigured; properly configured instances with a defined roles list block this attack.
- CVE-2026-8365HIGH 8.8
The Blocksy WordPress theme contains a critical flaw that allows authenticated users with contributor-level permissions (or higher) to execute arbitrary code on affected websites. The vulnerability stems from two weaknesses: the theme's REST API endpoint accepts serialized PHP objects without proper validation, and the database migration process automatically deserializes these objects without safety restrictions. An attacker with contributor access can craft a malicious object that triggers unintended code execution when the site is upgraded, effectively giving them full control over the website.
- CVE-2026-8697HIGH 8.8
A vulnerability in TP-Link Archer C64 v1 routers allows attackers on the local network to repeatedly guess administrative passwords without restriction. The device runs a debug SSH service that shares login credentials with the web interface but fails to limit failed authentication attempts. An attacker who gains valid credentials through brute force can take complete control of the router, potentially redirecting traffic, stealing data, or disrupting network connectivity.
- CVE-2026-8915HIGH 8.8
A critical buffer overflow vulnerability exists in Samsung's Escargot JavaScript engine that allows an attacker to write data beyond the boundaries of allocated memory. The vulnerability can be triggered through user interaction (such as opening a malicious webpage or file) and could lead to complete system compromise, including unauthorized data access, system modification, and denial of service. This is a high-severity issue affecting the open-source Escargot project at commit 36f5fb58366a67b713c02f6fd985e924fcc09e31.
- CVE-2026-9009HIGH 8.8
A critical flaw in the Crawlomatic Multipage Scraper Post Generator WordPress plugin allows authenticated users with author-level permissions or higher to run arbitrary code on websites using affected versions. The vulnerability stems from a shortcode that accepts user input and passes it directly to PHP's call_user_func() function without proper validation, enabling attackers to invoke dangerous PHP commands like system() and shell_exec(). All versions up to and including 2.7.2 are vulnerable.
- CVE-2026-9227HIGH 8.8
The GutenBee – Gutenberg Blocks WordPress plugin contains a file upload validation flaw that allows authenticated users with author-level permissions to upload executable files to a WordPress site. The vulnerability exists because the plugin checks whether a filename contains '.json' anywhere in it, rather than verifying the filename actually ends with '.json'. An attacker could upload a malicious PHP file named 'shell.json.php', which would pass validation but execute as PHP code on the server, leading to remote code execution. All versions up to and including 2.20.1 are affected.
- CVE-2026-9614HIGH 8.8
Ivanti Neurons for ITSM contains an access control flaw that lets a logged-in user escalate their privileges to admin level. This affects both cloud and on-premises deployments. An attacker who already has valid credentials can exploit this to gain full administrative control without needing to bypass additional authentication steps.
- CVE-2026-9873HIGH 8.8
A use-after-free memory defect in Google Chrome's Network component allows attackers to run malicious code within the browser sandbox by sending a specially crafted HTML page. The vulnerability requires user interaction—the victim must visit or be directed to the malicious page—but no special browser configuration or privileges are needed to exploit it. Google has rated this as Critical severity due to code execution capabilities, though the CVSS 3.1 score of 8.8 reflects the HIGH severity classification.
- CVE-2026-9878HIGH 8.8
A use-after-free vulnerability exists in the ANGLE graphics library component of Google Chrome versions before 148.0.7778.216. An attacker can craft a malicious webpage that, when visited, exploits this flaw to execute arbitrary code within Chrome's sandbox environment. The vulnerability requires user interaction (clicking a link or visiting a site) but does not require any special privileges. While the code runs in a sandbox, successful exploitation could allow attackers to steal sensitive data or cause denial of service.
- CVE-2026-9879HIGH 8.8
A memory safety bug in Chrome's graphics rendering engine (ANGLE) allows attackers to write data outside of allocated memory boundaries. An attacker can craft a malicious HTML page that, when opened in vulnerable versions of Chrome, triggers this out-of-bounds write to execute arbitrary code on the user's system. The vulnerability requires user interaction—specifically, the victim must visit or be directed to the malicious webpage—but no special privileges are needed and the attack works over the network.
- CVE-2026-9883HIGH 8.8
Google Chrome contains a use-after-free memory safety flaw in its Base component that allows attackers to execute arbitrary code on a user's system when they visit a malicious webpage. The vulnerability requires user interaction (viewing the crafted HTML) but no special privileges, and the attacker can read sensitive data, modify files, or crash the browser. Chrome versions prior to 148.0.7778.216 are affected across Windows, macOS, and Linux platforms.
- CVE-2026-9884HIGH 8.8
A use-after-free vulnerability in Google Chrome on macOS allows an attacker to run malicious code on a victim's computer by tricking them into visiting a specially crafted website. The vulnerability affects Chrome versions before 148.0.7778.216 on Mac and requires user interaction (clicking a link or viewing a page) but no special privileges to exploit. Google has classified this as a critical security issue in the Chromium project.
- CVE-2026-9887HIGH 8.8
A memory safety bug in Google Chrome's proxy handling system allows an attacker to craft a malicious Proxy Auto-Config (PAC) script that, when processed by the browser, causes the application to reference memory that has already been freed. This use-after-free condition can be leveraged to execute arbitrary code on a user's system. The vulnerability requires user interaction—specifically, the victim must visit a website or be directed to load a PAC script—but no special privileges are needed from the attacker's perspective. Chrome versions prior to 148.0.7778.216 are affected.