By year
Vulnerabilities disclosed in 2026
CVEs published in 2026 with SEC.co analysis.
8541 published vulnerabilities · page 47 of 86
- CVE-2026-2381MEDIUM 6.5
The WooCommerce Stripe Payment Gateway plugin contains a flaw that allows attackers to sabotage pending orders without authentication. By exploiting a missing verification step, attackers can force orders into a failed state using a fake payment method. This attack works because the plugin only checks a security token that is publicly visible on WooCommerce checkout pages, and does not confirm the attacker actually owns or has permission to modify the order being targeted. Attackers can enumerate sequential order IDs to identify and attack multiple orders.
- CVE-2026-24717MEDIUM 6.5
A path traversal vulnerability in QNAP operating systems allows an attacker who already has administrator credentials to read files and system data they shouldn't have access to. While the attacker needs valid admin account access first, once obtained, they can bypass file access restrictions to view sensitive information. QNAP has released patched versions across multiple OS lines to fix this issue.
- CVE-2026-24720MEDIUM 6.5
File Station 6, a QNAP file management product, contains a resource exhaustion vulnerability that allows authenticated users to consume system resources without limits, potentially starving other applications and processes of critical resources. An attacker with valid credentials could trigger conditions that degrade or block access for legitimate users and services on the same system.
- CVE-2026-24753MEDIUM 6.5
Kiteworks Secure Data Forms contained an authorization flaw that allowed authenticated users to modify data forms and resources belonging to other users. The vulnerability stems from insufficient checks verifying that a user actually owns or has permission to modify a resource before allowing the action. Any authenticated user could exploit this by directly referencing another user's resource identifiers and making changes. This is categorized as an Insecure Direct Object Reference (IDOR) vulnerability. The issue is resolved in Kiteworks version 9.3.0 and later.
- CVE-2026-2508MEDIUM 6.5
The Gravity Forms Booking plugin for WordPress contains a SQL injection vulnerability affecting all versions up to 2.7.1. Attackers with Subscriber-level access or higher can inject malicious SQL commands through the 'staff_id' parameter to extract sensitive database information. The vulnerability requires authentication but poses a meaningful risk to sites that allow user registration or have internal staff accounts.
- CVE-2026-25657MEDIUM 6.5
Ericsson's Packet Core Gateway (PCG) has a vulnerability that allows an attacker on the local network to send specially crafted messages that crash or degrade the service. The good news: once the attacker stops, the system recovers automatically without manual intervention. This is a denial-of-service issue—it takes the service offline temporarily but doesn't steal data or give attackers permanent control. Organizations running PCG versions before 1.30 are at risk.
- CVE-2026-25658MEDIUM 6.5
Ericsson Packet Core Gateway versions before 1.30 contain a vulnerability where attackers can send specially crafted messages to degrade service availability. The system crashes repeatedly while the attack continues, but recovers automatically once the attacker stops. This is a network-based attack requiring no authentication or user interaction.
- CVE-2026-25659MEDIUM 6.5
Ericsson's Packet Core Gateway (PCG) has a vulnerability that allows attackers on the local network to degrade service by repeatedly sending specially crafted messages. The system becomes unresponsive while attacks continue, but recovers normally once the attacker stops. This is not a persistent damage vulnerability—it's a denial-of-service condition that requires active, ongoing attack traffic.
- CVE-2026-26355MEDIUM 6.5
Dell PowerProtect Data Domain contains a command injection flaw that allows attackers with high-level system access to execute arbitrary OS commands remotely. This vulnerability affects multiple release branches (standard, LTS2026, LTS2025, and LTS2024) across a range of versions. While the attacker must already possess elevated privileges, successful exploitation could lead to complete system compromise through command execution.
- CVE-2026-26379MEDIUM 6.5
Koha, an open-source library management system, contains a Server-Side Request Forgery (SSRF) vulnerability in its Z39.50/SRU server configuration. An authenticated attacker can exploit this flaw to scan the internal network and discover which services are running by measuring how the server responds to requests. This vulnerability affects Koha versions up to and including 25.11.
- CVE-2026-2675MEDIUM 6.5
RTI Connext Professional's security plugins contain a missing authentication check on a critical function, allowing an authenticated user to impersonate the source of data messages. This undermines the integrity of distributed data flows without requiring elevated privileges or user interaction. An attacker with valid credentials to the Connext system could inject falsified data that appears to originate from legitimate sources, potentially disrupting dependent applications that rely on data provenance.
- CVE-2026-26824MEDIUM 6.5
libxls, a widely-used library for reading Microsoft Excel files, has a memory safety issue that could allow an attacker to crash applications or potentially leak sensitive information. The vulnerability exists in how the library initializes internal data structures when parsing Excel file containers. An attacker who crafts a malicious Excel file and tricks a user or application into opening it could trigger the vulnerability. This is a moderate-severity issue affecting the library through version 1.6.3.
- CVE-2026-27145MEDIUM 6.5
Go's x509 certificate verification function contained a performance flaw where hostname validation was inefficient. When checking if a certificate's DNS Subject Alternative Names matched the requested hostname, the code repeatedly split the hostname string for each SAN entry rather than doing this work once. This created a quadratic performance problem: the cost grew exponentially with both the number of DNS SANs in the certificate and the number of labels (dot-separated parts) in the hostname itself. An attacker could craft a certificate with an extremely large SAN list to cause verification delays. Worse, this overhead occurred even when validating untrusted certificates, before the certificate chain was properly validated, making denial-of-service attacks feasible.
- CVE-2026-27878MEDIUM 6.5
A vulnerability in Grafana Tempo allows an authenticated user to crash the service by submitting a specially crafted TraceQL query with an extremely large exemplars hint parameter. The Tempo instance will attempt to allocate excessive memory to process the request, eventually running out of memory and becoming unavailable. This is a denial-of-service attack that requires valid credentials to execute.
- CVE-2026-28979MEDIUM 6.5
An out-of-bounds memory access vulnerability exists in Apple's Safari browser and related Apple operating systems. When a user visits a malicious website, the flaw can crash the affected application unexpectedly. The vulnerability stems from insufficient bounds checking when processing web content, allowing an attacker to read from or write to memory locations outside intended boundaries. No data theft or system compromise occurs; the impact is limited to denial of service through application crashes.
- CVE-2026-30040MEDIUM 6.5
FastStone Image Viewer version 8.3 contains a memory overflow vulnerability in its core image processing engine (FSViewer.exe) that can be triggered when opening a specially crafted JPEG 2000 file. An attacker can exploit this by distributing a malicious JP2 file that, when opened by a user, causes the application to execute arbitrary code with the privileges of the person running FastStone. This is a remote attack requiring no special permissions or user interaction beyond opening the file.
- CVE-2026-3088MEDIUM 6.5
A vulnerability in Netgear mesh router systems allows attackers on the local network to crash the router or knock it offline by sending specially designed requests. No password or authentication is required — the attacker simply needs network access. This is a denial-of-service flaw that can disrupt your home or office WiFi without leaving traditional evidence of intrusion.
- CVE-2026-31016MEDIUM 6.5
Squidex CMS versions 7.21.0 and earlier contain a Cross-Site Request Forgery (CSRF) flaw that allows an unauthenticated attacker to perform unauthorized actions on behalf of authenticated users. The vulnerability specifically targets the IdentityServer account profile endpoint, enabling privilege escalation. An attacker could trick a logged-in administrator or user into unknowingly executing malicious requests that modify account settings or elevate permissions.
- CVE-2026-3173MEDIUM 6.5
The Meta Field Block plugin for WordPress has a permission-checking flaw that lets Contributor-level users and above read sensitive data stored in WordPress metadata. An attacker with basic contributor access can specify any object ID and type—bypassing the plugin's validation—to retrieve private information like user details, customer billing addresses, or other metadata that WordPress site administrators expected to keep hidden. On sites running e-commerce or membership plugins, this can expose personally identifiable information at scale.
- CVE-2026-31978MEDIUM 6.5
motionEye, a web-based video surveillance interface, contains a path traversal vulnerability in its preview and movie API endpoints that allows authenticated users to read files they shouldn't access. An attacker with a basic motionEye account could exploit this to extract sensitive files such as system credentials, configuration files with passwords, SSH keys, and footage from other cameras. The vulnerability affects all versions before 0.44.0 and requires only user-level privileges to exploit—no special admin access is needed.
- CVE-2026-3198MEDIUM 6.5
MLflow 3.9.0, when deployed with basic authentication enabled, contains an authorization bypass affecting several gateway API endpoints. The application fails to properly verify user permissions before allowing access to sensitive operations that list gateway secrets, endpoints, and model definitions. This means any user who has logged in—even with minimal privileges—can view all gateway configuration data, including API keys and proprietary model information that should be restricted. The vulnerability is confined to the basic-auth deployment mode and affects information disclosure rather than data modification or system availability.
- CVE-2026-32682MEDIUM 6.5
NGINX Gateway Fabric can be crashed by an authenticated user who has permission to create or modify GRPCRoute resources. By submitting specially crafted GRPCRoute configurations that include certain backendRef filters, an attacker can force the control plane to shut down unexpectedly. This requires valid credentials and explicit permissions on the system, limiting but not eliminating the risk.
- CVE-2026-32718MEDIUM 6.5
Coolify, an open-source platform for managing servers, applications, and databases, contains an authorization flaw that allows read-only API tokens to perform state-changing operations. Specifically, an attacker with read-scoped credentials can validate cloud tokens and servers—operations that should require higher privileges. This circumvents the intended permission model and enables unauthorized modifications to infrastructure state. The vulnerability affects all versions prior to 4.0.0-beta.466.
- CVE-2026-33464MEDIUM 6.5
Kibana contains a denial-of-service vulnerability that allows low-privileged authenticated users to crash the service by sending an oversized request to an internal API. When exploited, Kibana becomes unresponsive to all users until manually restarted or the process recovers. This is a resource exhaustion attack that requires valid credentials but no special privileges.
- CVE-2026-33582MEDIUM 6.5
Apache Answer versions through 2.0.0 contain a vulnerability allowing authenticated users to upload specially crafted TIFF image files that trigger excessive memory consumption during processing, causing the server to crash. This is an availability issue that can disrupt service but does not compromise data confidentiality or integrity.
- CVE-2026-33800MEDIUM 6.5
Juniper Networks Junos OS on MX Series routers has a vulnerability that allows an attacker on the same network segment to crash the Forwarding Processing Card (FPC) by repeatedly triggering Micro-BFD session state changes. The vulnerability exploits the router's event processing queue, which becomes overwhelmed when sessions continuously flip between up and down states. This causes a watchdog timer to expire, forcing the FPC to crash and cutting off traffic. The attack requires network adjacency but no authentication, and affects specific hardware models in the MX lineup.
- CVE-2026-33801MEDIUM 6.5
A flaw in Juniper Networks' routing daemon allows an attacker already connected to a BGP neighbor to crash the routing system by sending a malformed network update. The attacker must be directly connected to the device (adjacent network access), but does not need to authenticate. When triggered, the routing daemon restarts, causing all routes to stop working temporarily until the system recovers. The impact is contained to the affected device—malicious routes are not forwarded downstream.
- CVE-2026-33803MEDIUM 6.5
A configuration flaw in Juniper Networks Junos OS Evolved exposes an internal process to the network that should remain isolated. An attacker can reach this process over the internet without authentication, potentially gathering limited device information and degrading performance by consuming CPU resources. The vulnerability affects multiple Junos OS Evolved release branches and requires a software update to resolve.
- CVE-2026-34031MEDIUM 6.5
Apache Answer versions through 2.0.0 contain a vulnerability in how they handle user-supplied image URLs for profile pictures. The application fails to properly validate these URLs, allowing attackers to inject arbitrary external image sources. When users load their profiles or view other users' profiles, their browsers make requests to attacker-controlled servers, enabling tracking, analytics collection, or other reconnaissance activities. This is not a direct data breach, but rather a mechanism for exposing user behavior and session information to external parties.
- CVE-2026-34050MEDIUM 6.5
Coolify is a popular open-source server and application management platform. A flaw in its Settings/Updates component allows any authenticated user—not just administrators—to view and potentially alter automatic update settings or force update checks. This access control gap was present before version 4.0.0-beta.471. While an attacker would need valid login credentials, the lack of role-based authorization on this sensitive functionality creates meaningful risk in multi-user environments.
- CVE-2026-3462MEDIUM 6.5
The Frisbii Pay plugin for WordPress has a critical authorization flaw that allows low-privilege users (Subscriber level and above) to upload malicious CSV files and alter sensitive payment and order data. An attacker with basic authenticated access can overwrite WooCommerce payment tokens and customer order information without needing administrative rights, potentially compromising transaction integrity and customer payment records.
- CVE-2026-34905MEDIUM 6.5
Apache Answer versions up to 2.0.0 contain a flaw where unlisted questions—content intended to be hidden from public view—can be discovered and read by any authenticated user through direct API calls. The vulnerability bypasses the access controls meant to keep these questions private, exposing not only the questions themselves but also their answers, comments, and revision history to users who should not have permission to see them.
- CVE-2026-35049MEDIUM 6.5
Wire iOS users running versions before 4.16.0 are vulnerable to a denial-of-service attack where a specially crafted message causes the app to crash immediately upon receipt, without any user action required. The crash persists across app restarts, trapping users in a crash loop until they manually clear the app's local data. This affects authenticated users only—the attacker must have messaging access to the target.
- CVE-2026-35211MEDIUM 6.5
OpenCTI, an open-source cyber threat intelligence platform, contains a vulnerability in its GraphQL API that allows authenticated users to inject computationally expensive script code. Any user with knowledge management permissions can craft malicious search queries that consume excessive CPU resources on the Elasticsearch backend, degrading performance for all users and potentially causing service unavailability. This is a denial-of-service vulnerability that requires valid credentials but no special privileges beyond standard KNOWLEDGE capability access.
- CVE-2026-35261MEDIUM 6.5
Oracle Access Manager contains an authentication bypass vulnerability that allows attackers to gain unauthorized access to sensitive data without providing valid credentials. An attacker on a network can exploit this flaw through HTTP requests to read, modify, or delete data within the application. The vulnerability affects versions 12.2.1.4.0 and 14.1.2.1.0, and requires no special privileges or user interaction to exploit.
- CVE-2026-35673MEDIUM 6.5
OpenClaw versions before 2026.4.29 contain a Server-Side Request Forgery (SSRF) policy bypass that allows authenticated users to circumvent network security controls. The vulnerability exists in browser debug and export functionality, where attackers can reuse previously-blocked tabs to access or export content that should remain restricted by private-network SSRF policies. This is a policy evasion technique rather than a direct network breach—the attacker must already have authenticated access to these routes, but can then leverage that access to reach otherwise-protected resources.
- CVE-2026-35718MEDIUM 6.5
VIVOTEK FD8136 network cameras running firmware version 0300a contain a path traversal vulnerability in their administrative media download function. An authenticated attacker can craft requests to the vulnerable endpoint to read files anywhere on the device, potentially exposing sensitive configuration data, credentials, or system files. This requires valid login credentials but does not require user interaction to exploit.
- CVE-2026-36499MEDIUM 6.5
Open vSwitch v3.6.90 contains a flaw that allows someone with write access to its configuration database to cause the software to allocate an unreasonably large number of worker threads. By requesting more threads than the system can handle, an attacker can exhaust memory and CPU resources, effectively shutting down the switch. The vulnerability requires existing database access, limiting the immediate threat surface, but represents a significant availability risk in environments where OVSDB write permissions are not tightly controlled.
- CVE-2026-36604MEDIUM 6.5
A Mercusys AC12G (EU) V1 router running firmware version AC12G(EU)_V1_200909 fails to validate the HTTP Host header in requests, creating an opening for DNS rebinding attacks. When an attacker controls a domain, they can redirect that domain to the router's internal IP address. The router's existing CORS misconfiguration (which already allows requests from any origin) amplifies this weakness, permitting the attacker to extract sensitive information from the router's web interface as if the request came from a trusted source. This vulnerability requires user interaction—typically visiting a malicious website—but does not require authentication.
- CVE-2026-36605MEDIUM 6.5
Mercusys AC12G (EU) V1 routers running firmware version AC12G(EU)_V1_200909 contain a denial-of-service vulnerability where an attacker on the local network can send a small number of specially crafted incomplete HTTP requests to crash the router. The device becomes unresponsive and requires a physical power cycle to restore function. This affects network availability for all connected devices.
- CVE-2026-36724MEDIUM 6.5
FastapiAdmin version 2.2.0 contains a flaw in its scheduled task management endpoint that allows authenticated users with appropriate permissions to crash the application by submitting malformed task data. An attacker who has legitimate access and the module_task:job:update permission can trigger an unhandled exception that disrupts service availability.
- CVE-2026-36772MEDIUM 6.5
Tenda W3 wireless routers running firmware version 1.0.0.3(2204) contain a stack overflow vulnerability in how they process the wl_radio parameter during SSID configuration requests. An attacker on the local network can send a specially crafted input to crash the router, causing a denial of service. The vulnerability requires no authentication and no user interaction to trigger.
- CVE-2026-36773MEDIUM 6.5
A stack overflow vulnerability has been identified in Tenda W3 Wireless Router version 1.0.0.3(2204). The flaw exists in how the device processes the 'Go' parameter within its reboot function, allowing an attacker on the local network to send specially crafted input that causes the router to crash or become unresponsive. This is a denial-of-service issue—attackers cannot steal data or gain control, but they can disrupt network availability.
- CVE-2026-36777MEDIUM 6.5
A stack overflow vulnerability exists in Tenda W3 wireless routers (version 1.0.0.3 Build 2204) that can be triggered via a specially crafted HTTP request. An attacker on the same network can send malicious input to crash the router, causing a temporary denial of service. The vulnerability does not compromise confidentiality or allow unauthorized access—it purely impacts availability.
- CVE-2026-36798MEDIUM 6.5
A vulnerability exists in Tenda G0 router firmware version 15.11.0.5 where an attacker can crash the device by sending specially crafted HTTP requests that exploit multiple stack overflow conditions. The vulnerability requires user interaction—specifically, someone must click a malicious link or visit an attacker-controlled website—but does not require authentication. Once triggered, it causes a denial of service that prevents the router from functioning until it is rebooted.
- CVE-2026-37737MEDIUM 6.5
A flaw in sanic-cors version 2.2.0 and earlier allows attackers to circumvent CORS (Cross-Origin Resource Sharing) origin restrictions. The vulnerability stems from improper validation of allowed origins: an attacker can register a domain name that starts with a trusted origin string to trick the library into allowing cross-origin requests that should have been blocked. For example, if a site trusts 'trusted.com', an attacker registering 'trusted.com.attacker.com' could bypass the allowlist. This exposes authenticated resources to unauthorized cross-origin access.
- CVE-2026-38142MEDIUM 6.5
Tenda AC18 routers running version 15.03.05.05 contain a vulnerability that allows unauthenticated attackers to execute arbitrary commands on the device. The flaw exists in a web interface endpoint used for internet configuration settings and can be exploited by sending a specially crafted request without requiring any authentication. An attacker on the network—or potentially from the internet if the router's web interface is exposed—could inject malicious commands through a parameter meant to hold MAC addresses, gaining the ability to run code with router-level privileges.
- CVE-2026-3870MEDIUM 6.5
Zyxel VMG4005-B50B routers with firmware up to version 5.13(ABRL.5.4)C0 contain a buffer overflow flaw in their UPnP port-mapping feature. An attacker on the same local network can exploit this to crash the UPnP service temporarily, preventing legitimate port-forwarding operations until the service recovers or the device is rebooted.
- CVE-2026-3871MEDIUM 6.5
Zyxel VMG4005-B50B gateway devices running firmware version 5.13(ABRL.5.4)C0 and earlier contain a buffer overflow flaw in the UPnP DeletePortMapping command. An attacker on the same local network can exploit this to crash the UPnP service, temporarily disabling port mapping features. The vulnerability requires network adjacency and does not enable data theft or system compromise, but does degrade device functionality.
- CVE-2026-39197MEDIUM 6.5
Vector v0.54.0, Datadog's lightweight observability pipeline tool, contains a vulnerability in its HTTP utility module that allows authenticated attackers to send specially crafted requests that crash or hang the service, disrupting data collection and processing. An attacker with valid credentials can trigger a denial-of-service condition without needing special privileges or user interaction.
- CVE-2026-39229MEDIUM 6.5
Bolt CMS versions up to 3.7.0 contain a SQL injection vulnerability in how it processes the 'order' parameter on content listing pages. An attacker who has legitimate user credentials—even with minimal permissions—can craft malicious input to extract sensitive data from the database. The vulnerability is triggered through the OrderDirective component during normal sorting operations. This is an information disclosure risk; attackers cannot modify or delete data, but they can read information they shouldn't access.
- CVE-2026-39540MEDIUM 6.5
A cross-site scripting (XSS) vulnerability exists in Shipment Tracker for WooCommerce versions 1.5.3.2 and earlier. The flaw allows an authenticated subscriber to inject malicious scripts that execute in the browsers of other users viewing affected pages. Exploitation requires user interaction (such as clicking a link or visiting a compromised page) and the attacker must already have subscriber-level access to the WooCommerce site. The impact is limited to the web application's context—an attacker could steal session tokens, redirect users, or deface content.
- CVE-2026-39872MEDIUM 6.5
CVE-2026-39872 is a memory handling flaw in Apple's Safari browser and related operating systems that can crash the application when processing malicious web content. An attacker would need to trick a user into visiting a crafted webpage, but no additional privileges or special conditions are required. The crash itself does not compromise data confidentiality or integrity—it simply denies availability of the browser temporarily. This is a moderate-severity issue affecting Safari, iOS, iPadOS, macOS, tvOS, visionOS, and watchOS.
- CVE-2026-39904MEDIUM 6.5
Gophish version 0.12.1 and earlier contains a denial of service vulnerability accessible to authenticated users with the User role. An attacker can upload a specially crafted Office document as an email template attachment that tricks the server into decompressing a massive file in memory, ultimately crashing the service. This works because the application doesn't limit how much an Office document (which is really a ZIP file) can expand when unpacked.
- CVE-2026-39908MEDIUM 6.5
OpenBullet2 versions up to 0.3.2 running on Windows contain a flaw that leaks the Windows NTLM password hash of the user running the application. An attacker with access to the application can trick it into connecting to a malicious SMB server by providing a fake network path (UNC path) as a proxy source. When OpenBullet2 tries to load proxy settings from that path, Windows automatically attempts to authenticate, and the attacker captures the resulting NTLMv2 hash. That hash can be used in relay attacks or cracked offline to recover credentials.
- CVE-2026-40009MEDIUM 6.5
Apache IoTDB contains a privilege escalation vulnerability where authenticated users can rename themselves to a special internal system account (__internal_auditor) to gain unrestricted access to all data in the system's tree structure. This vulnerability affects versions 2.0.8 through 2.0.9 and has been patched in version 2.0.10. The vulnerability requires an attacker to already have valid login credentials, so it represents an insider risk or a secondary exploit path following initial compromise.
- CVE-2026-40084MEDIUM 6.5
Cacti versions 1.2.30 and earlier contain a path traversal vulnerability in the report functionality that allows authenticated users to read arbitrary files from the server. The flaw stems from insufficient validation of user-supplied file paths when generating reports. An attacker with valid Cacti credentials can craft a malicious report format parameter to escape the intended directory and access sensitive system files.
- CVE-2026-40724MEDIUM 6.5
A vulnerability in CP Client's Portal (Pro) version 5.6.2 and earlier allows authenticated users to download arbitrary files from the server without proper authorization. An attacker with valid login credentials can bypass access controls to retrieve sensitive files that should be restricted, potentially exposing confidential business data, configuration files, or other protected assets. This is a path traversal vulnerability that does not require special privileges beyond basic authentication.
- CVE-2026-40773MEDIUM 6.5
A broken access control vulnerability exists in rtMedia for WordPress, BuddyPress, and bbPress versions 4.7.9 and earlier. The flaw allows authenticated subscribers to modify or access content they should not have permission to change, such as other users' media or metadata. While an attacker needs a valid account to exploit this, the vulnerability poses a significant risk to multi-user WordPress installations where subscriber-level access is commonly granted.
- CVE-2026-40809MEDIUM 6.5
Rara Themes' Metro Magazine contains a missing authorization flaw that allows unauthenticated attackers to modify content and disrupt service availability. The vulnerability stems from incorrectly configured access controls that fail to properly validate user permissions before processing sensitive operations. Attackers can exploit this over the network without requiring any special setup or user interaction.
- CVE-2026-40861MEDIUM 6.5
CVE-2026-40861 is a path traversal vulnerability in Apache Airflow that allows a DAG (Directed Acyclic Graph) author to read or write arbitrary files on the system when the worker and API server share a log directory. An attacker with DAG authoring privileges can either create symbolic links in their task's log folder to access sensitive files like `/etc/passwd` or `airflow.cfg`, or inject path traversal sequences (`..`) in task IDs to escape the intended log directory. The vulnerability exposes confidential configuration data and could enable file overwrites on the API server's filesystem.
- CVE-2026-40941MEDIUM 6.5
Cacti, a widely-used open-source framework for monitoring network performance and managing faults, contains a flaw in how it validates digitally signed package files. The vulnerability allows an attacker with authenticated access to import packages signed with self-signed certificates—essentially forging package authenticity—without proper validation. This means malicious or compromised packages could be installed without detection, potentially allowing code execution or system compromise. The issue affects Cacti versions 1.2.30 and earlier; upgrading to 1.2.31 or later resolves it.
- CVE-2026-4096MEDIUM 6.5
IBM DevOps Plan versions 3.0.0 through 3.0.6 contain a flaw in how they validate HTTP HOST headers, allowing attackers to inject malicious header content. This could lead to several attack vectors including stealing user session data, poisoning cached content, or executing code in users' browsers through cross-site scripting (XSS). The vulnerability requires network access but no authentication or user interaction to exploit.
- CVE-2026-41141MEDIUM 6.5
EspoCRM versions before 9.3.5 contain an access control bypass in the email template preparation endpoint. An authenticated user with basic EmailTemplate read permissions can extract sensitive field data from any Contact, Lead, Account, or User record by providing the target's email address—effectively circumventing role-based visibility restrictions. This allows lower-privileged users to read information they should not have access to, such as financial details, personal fields, or team-restricted records.
- CVE-2026-41184MEDIUM 6.5
Calico's CNI installer container accidentally logs Kubernetes ServiceAccount tokens to standard output during deployment, specifically when using Canal or Flannel-Calico configurations. Any user with permission to view pod logs in the affected namespace can retrieve this token, which grants the ability to modify pod annotations—a vector for attacking workloads in your cluster. The vulnerability is a regression of a previously fixed issue and does not affect deployments using the default kubeconfig authentication method.
- CVE-2026-41185MEDIUM 6.5
Calico, a widely-used open-source networking plugin for Kubernetes, logs sensitive authentication credentials to plaintext files when deployed with Azure's IPAM plugin and token-based Kubernetes authentication. The vulnerability occurs because the Calico CNI binary adds subnet information to the configuration before forwarding it to Azure IPAM for processing. During this handoff, the entire configuration—including Kubernetes ServiceAccount tokens, client keys, and certificate authority data—is logged at INFO level to /var/log/calico/cni/cni.log. This happens on every pod scheduling or termination, creating a high-frequency credential leak. Any user or process with read access to node-level logs can extract cluster-wide Calico networking administrator credentials without triggering alarms.
- CVE-2026-41726MEDIUM 6.5
Spring for Apache Kafka applications that have enabled DelegatingDeserializer are vulnerable to a resource exhaustion attack where an authenticated attacker can send specially crafted Kafka messages containing random header values. The application will consume increasing amounts of heap memory without releasing it, eventually exhausting available memory and causing the application to crash or become unresponsive.
- CVE-2026-41727MEDIUM 6.5
Spring for Apache Kafka contains a vulnerability in how it validates header information when processing message retries. An authenticated user can craft a malicious Kafka message with an artificially high or invalid retry attempt count in a header, causing the retry routing system to become confused about where that message sits in the retry sequence. This confusion can disrupt message delivery logic and potentially cause the system to become unavailable, though attackers need valid Kafka producer credentials to exploit it.
- CVE-2026-41899MEDIUM 6.5
Coolify, an open-source server and application management tool, contains an unauthenticated endpoint that accepts user-submitted feedback and forwards it to a Discord webhook without validation or rate limiting. Before version 4.0.0-beta.474, an attacker could send malicious or spam content through this endpoint, poisoning the webhook with arbitrary payloads. This could disrupt operational communications, inject unauthorized messages into monitoring systems, or abuse the webhook service itself. The fix in beta.474 adds proper authentication, input validation, and rate limiting to the endpoint.
- CVE-2026-42073MEDIUM 6.5
OpenClaude, an open-source command-line tool for interacting with cloud and local AI models, has a flaw in how it handles user login. When you authenticate using OAuth, the software runs a temporary web server locally to catch the login response. To prevent attackers from hijacking this process, the server checks a security token called a 'state parameter.' However, due to a bug in how the code checks this token, an attacker can bypass the security check entirely and crash the server without even knowing what the token is. This has been fixed in version 0.5.1 and later.
- CVE-2026-42357MEDIUM 6.5
Apache DolphinScheduler contains an authorization flaw that allows authenticated users to view workflow instance data from projects they should not have access to. An attacker with valid credentials could browse sensitive workflow information across project boundaries, exposing task execution details, logs, and operational data without proper permission checks. The vulnerability requires an existing user account but does not require elevated privileges, making it a significant information disclosure risk in multi-tenant or shared environments.
- CVE-2026-42358MEDIUM 6.5
Apache Airflow's secret-masking feature, which is supposed to hide sensitive values in Variables when they're accessed through the UI or API, has a flaw that lets authenticated users read plaintext secrets stored in deeply nested JSON structures. The masking tool gives up checking for sensitive key names (like 'password', 'token', 'secret', 'api_key') once it reaches a certain nesting depth, so secrets buried deeper than that limit slip through unmasked. Any user with permission to read Variables can exploit this. This is a follow-up to an earlier fix; that patch addressed shallow nesting, but didn't raise the depth limit itself, leaving the same bypass hole for deeper structures.
- CVE-2026-42360MEDIUM 6.5
Apache Airflow has a flaw in how it protects sensitive information embedded within complex data structures (like JSON templates). When a workflow template is large enough to exceed Airflow's size limit for storing template data, the system converts it to plain text before masking secrets—a process that loses track of nested sensitive fields like passwords, tokens, and API keys. An authenticated user with access to read stored template fields could then retrieve these unmasked secrets. The issue affects Airflow deployments where workflow authors pass structured data containing nested sensitive values to operators. Even organizations that patched a related vulnerability (CVE-2025-68438) last year need to apply this additional update, as that earlier fix did not address this specific nested-key masking gap.
- CVE-2026-42399MEDIUM 6.5
A vulnerability in Kibana allows authenticated users with basic access to crash the application by uploading specially crafted visualizations. An attacker submits a Timelion visualization with deeply nested function calls that causes Kibana to allocate memory without limit, eventually consuming all available RAM and taking the service offline for everyone. This is a denial-of-service attack that requires valid credentials but no administrative privileges.
- CVE-2026-42400MEDIUM 6.5
CVE-2026-42400 is a denial-of-service vulnerability in Kibana that allows an authenticated user to crash or freeze a Kibana instance by sending a malicious compressed request. The vulnerability exists because Kibana processes and decompresses incoming requests before fully validating user permissions, meaning an attacker can consume excessive memory and CPU resources on the server before authorization checks can stop them. While this requires valid credentials to exploit, the impact is straightforward: a Kibana instance can become unresponsive or crash entirely, disrupting visibility and analysis capabilities that teams depend on.
- CVE-2026-42490MEDIUM 6.5
CVE-2026-42490 is a vulnerability in Xen's domain control logic where a system-wide lock used to serialize guest management operations is acquired before permission checks are performed when XSM/Flask security policies are enabled. This means an authenticated attacker could potentially exploit the ordering flaw to trigger denial-of-service conditions or access control bypasses in virtualized environments running Xen with Flask mandatory access controls.
- CVE-2026-42539MEDIUM 6.5
IRIS is a web-based platform used by incident response teams to collaborate and share technical details during security investigations. A vulnerability in versions before 2.4.28 causes the platform to leak sensitive information to authenticated users that those users should not have access to. This happens because the application returns unnecessary data in responses, exposing information beyond what the client application actually needs to function. An attacker with valid IRIS credentials can exploit this to view restricted incident data.
- CVE-2026-42671MEDIUM 6.5
Paolo GeoDirectory versions up to 2.8.157 contain a missing authorization flaw that allows attackers to bypass access controls. Without needing credentials or user interaction, an attacker on the network can exploit misconfigured security levels to gain unauthorized access to sensitive operations, potentially modifying data or causing service disruption.
- CVE-2026-42676MEDIUM 6.5
myCred, a gamification and community engagement plugin, contains a stored cross-site scripting (XSS) vulnerability that allows authenticated users to inject malicious scripts into web pages. Unlike reflected XSS attacks that require victims to click a link, stored XSS persists in the application's database, meaning any user—including administrators—who views the affected content will execute the attacker's code. The vulnerability affects myCred versions up to and including 3.0.4. An authenticated attacker could exploit this to steal session tokens, redirect users, deface content, or perform actions on behalf of legitimate users.
- CVE-2026-42679MEDIUM 6.5
CVE-2026-42679 is a path traversal vulnerability in Mamunur Rashid Classified Listing that allows authenticated users to read sensitive files outside the application's intended directory structure. An attacker with valid login credentials can craft specially formatted file path requests to access restricted files on the server, potentially exposing configuration data, database backups, or other confidential information. The vulnerability affects Classified Listing versions up through 5.3.8.
- CVE-2026-42688MEDIUM 6.5
Modula Image Gallery versions up to and including 2.14.23 contain a cross-site scripting (XSS) vulnerability that allows authenticated subscribers to inject malicious scripts into the application. When other users interact with affected content, their browsers execute these scripts, potentially exposing their session data or enabling account compromise. The vulnerability requires an authenticated attacker and user interaction to trigger, limiting but not eliminating real-world risk.
- CVE-2026-42824MEDIUM 6.5
Microsoft Copilot contains a command injection vulnerability that allows an attacker to craft malicious input and execute unintended commands through the application. An attacker can exploit this flaw to extract sensitive information from a user's system or data accessible through Copilot, but only if the user interacts with the malicious input. The vulnerability does not allow the attacker to modify data or disrupt service availability.
- CVE-2026-42853MEDIUM 6.5
A command injection flaw exists in the ApostropheCMS CLI tool (versions up to 3.6.0) that allows an authenticated user with local access to execute arbitrary system commands by injecting malicious input through the password prompt during the `apos create` command. The vulnerability requires an attacker to already have administrative privileges on the machine where the CLI is running and user interaction (entering a password) to trigger, limiting its scope but making it a concern for organizations where system administrators or developers may be compromised or malicious.
- CVE-2026-42867MEDIUM 6.5
Langflow, a platform for building AI-powered agents and workflows, contains a path traversal vulnerability in its Knowledge Bases API that allows authenticated users to write files anywhere on the server. The flaw exists because user-provided knowledge base names are not properly validated before being used to construct file paths. An attacker with valid credentials can exploit this to create arbitrary directories and files, potentially compromising server integrity. The issue is resolved in version 1.9.0.
- CVE-2026-42895MEDIUM 6.5
A command injection vulnerability in Microsoft Copilot allows attackers to manipulate the system's behavior through specially crafted input delivered over the network. The attacker does not need valid credentials or special access, but does require user interaction to trigger the exploit. The vulnerability enables tampering with data or system operations, though it does not expose sensitive information or cause service disruption.
- CVE-2026-42903MEDIUM 6.5
A flaw in Windows Kerberos authentication can be triggered by an authorized network user to crash or hang critical services. The vulnerability requires valid domain credentials to exploit, limiting its attack surface to insider threats or compromised accounts within an organization. While it does not expose data or allow privilege escalation, denial-of-service impact can disrupt authentication infrastructure and dependent business operations.
- CVE-2026-42907MEDIUM 6.5
CVE-2026-42907 is a medium-severity information disclosure vulnerability in Windows Shell that allows an authorized user to leak sensitive data over the network. The flaw requires valid credentials to exploit but does not need user interaction, making it a concern for organizations where user trust boundaries are weak or privilege separation is inadequate. No code execution or system damage occurs; the risk is purely confidentiality loss.
- CVE-2026-4339MEDIUM 6.5
Mattermost has a flaw in its Agents plugin that fails to block requests to private or internal network addresses. An authenticated attacker with access to the MCP (Model Context Protocol) server in stdio mode can exploit this to retrieve sensitive data from internal services by crafting attachment URLs pointing to internal IP ranges. The vulnerability affects Mattermost versions 10.11.x up to 10.11.18, 11.5.x up to 11.5.6, and 11.6.x up to 11.6.3.
- CVE-2026-43663MEDIUM 6.5
CVE-2026-43663 is a memory handling vulnerability affecting Safari and multiple Apple operating systems. When a user visits or interacts with a maliciously crafted website, the affected application can crash unexpectedly. While the crash itself prevents normal operation, the vulnerability does not enable attackers to steal data or take control of the device—it is primarily a denial-of-service issue triggered by user interaction with hostile web content.
- CVE-2026-43676MEDIUM 6.5
An out-of-bounds memory access flaw in Apple's Safari browser and related operating systems can cause unexpected crashes when users visit websites containing malicious content. The vulnerability affects Safari on Mac, iPhone, and iPad, as well as visionOS and watchOS. While the issue results in denial of service rather than data theft or system compromise, it degrades user experience and could be chained with other exploits in targeted attacks. Apple has patched the vulnerability across its ecosystem.
- CVE-2026-43699MEDIUM 6.5
A use-after-free memory vulnerability affects Apple's Safari browser and iOS/iPadOS/macOS platforms. An attacker can craft malicious web content that, when processed by a vulnerable browser, causes unexpected crashes. The vulnerability requires user interaction—specifically, visiting a malicious website—but does not enable data theft or system compromise beyond denial of service. Apple has released patched versions addressing the underlying memory management flaw.
- CVE-2026-43700MEDIUM 6.5
Apple has patched a cross-origin security issue affecting Safari and multiple Apple operating systems. The vulnerability allows attackers to craft malicious web content that, when visited by a user, can leak sensitive information by bypassing browser security controls that normally isolate websites from each other. The flaw was in how the browser tracked which origin (website) was responsible for data, making it possible to exfiltrate user data without the victim's knowledge beyond visiting a compromised or attacker-controlled page.
- CVE-2026-43703MEDIUM 6.5
CVE-2026-43703 is a memory handling flaw in Apple's operating systems that can cause an application to crash when processing specially crafted web content. An attacker would need to trick a user into visiting a malicious website or viewing attacker-controlled web content; the crash itself does not expose data or allow unauthorized access, but it does disrupt availability. Apple has patched this issue across iOS, iPadOS, macOS variants, tvOS, visionOS, and watchOS.
- CVE-2026-43706MEDIUM 6.5
Apple released security updates to fix a double free memory vulnerability affecting iOS, iPadOS, macOS, tvOS, visionOS, and watchOS. The flaw could crash applications when users interact with specially crafted web content, but does not enable data theft or system compromise. This is a medium-severity availability issue requiring user interaction to trigger.
- CVE-2026-43707MEDIUM 6.5
Apple has patched a memory corruption vulnerability affecting Safari, iOS, iPadOS, macOS, tvOS, visionOS, and watchOS. An attacker can craft a malicious web page that, when visited, crashes the affected application. The vulnerability requires user interaction—specifically, visiting a compromised or attacker-controlled website—but poses no risk of data theft or system compromise beyond the denial of service from the crash itself.
- CVE-2026-43709MEDIUM 6.5
Apple has patched a use-after-free memory vulnerability in Safari and multiple operating systems that could crash applications when processing malicious web content. An attacker would need to trick a user into visiting a crafted website, but no user interaction beyond standard browsing is required to trigger the crash. The vulnerability does not enable data theft or system compromise—only denial of service through application termination.
- CVE-2026-43712MEDIUM 6.5
A memory handling flaw in Safari and related Apple platforms can cause a web browser to crash when processing specially crafted web content. An attacker would need to trick a user into visiting a malicious website, but no special access or user privileges are required beyond normal browsing. The issue affects Safari on macOS and iOS/iPadOS devices, as well as Apple TV, Vision Pro, and Watch.
- CVE-2026-43713MEDIUM 6.5
Apple has patched a permissions flaw that could allow website visits to leak sensitive user data. The vulnerability affects Safari, iOS, iPadOS, and macOS. An attacker does not need special privileges—only the ability to host a website and trick a user into visiting it. Once a victim lands on the malicious page, the flaw can expose confidential information. The fix involves tightening permission checks to prevent unauthorized data access.
- CVE-2026-43716MEDIUM 6.5
A memory handling flaw in Apple's Safari browser and related Apple platforms can crash the browser when processing specially crafted web content. An attacker would need to trick a user into visiting a malicious website; the crash itself does not enable data theft or system compromise, but it does disrupt service. Apple has released patches addressing the underlying memory issue across Safari, iOS, iPadOS, and macOS.
- CVE-2026-43717MEDIUM 6.5
A use-after-free memory vulnerability exists in Apple's Safari browser and related operating systems. An attacker can craft a malicious webpage that, when visited, causes Safari to crash unexpectedly. The vulnerability does not enable data theft or system compromise—it is limited to availability impact (denial of service via crash). Exploitation requires user interaction: the victim must visit or be directed to the malicious web content.